893 lines
35 KiB
Python
893 lines
35 KiB
Python
"""ARCH-01 Foundation Slice A — atomic platform installation + authority kernel (#822).
|
|
|
|
Parents: #820, #821. **First implementation leaf of the ARCH-01 program.**
|
|
|
|
This module implements the smallest executable ARCH-01 foundation:
|
|
|
|
* a connection-bound authenticated actor context (``cp_actor_*`` /
|
|
``cp_operation_mode`` / ``cp_context_epoch`` SQLite scalar functions that SQL
|
|
may *read* but can never *set* — ``[TRUSTED-SERVICE]`` authenticity);
|
|
* an immutable authority-dominance lattice with an exact seeded tuple set
|
|
(``[SCHEMA]``);
|
|
* the principal-equivalence root (a class exists *before* its first principal;
|
|
``principals.current_class_id`` is ``NOT NULL``; ``[SCHEMA]``);
|
|
* a single-transaction platform installation that seeds the initial
|
|
``platform.bootstrap`` grant and an immutable ``installed`` marker, validated
|
|
by a fail-closed ``install_state`` ``BEFORE INSERT`` trigger (``[SCHEMA]``).
|
|
|
|
Everything else in the ARCH-01/02/04 program (evidence stores, repository
|
|
bindings, workspaces, PostgreSQL parity, full grant succession, full principal
|
|
merge) is out of scope here and tracked in its own issue — see #822 §5/§17.
|
|
|
|
**Readiness / production posture.** This subsystem is *disabled by default*.
|
|
Nothing in the running MCP server imports or enables it. It becomes a security
|
|
boundary only once its readiness checks (the ACs in #822) pass in the target
|
|
environment. Instantiating :class:`PlatformKernel` creates an isolated SQLite
|
|
database and never touches the operational control-plane store.
|
|
|
|
Enforcement classification (per #820 vocabulary):
|
|
|
|
* ``[TRUSTED-SERVICE]`` — actor-context authenticity: the scalar functions are
|
|
registered by the trusted Python process; SQL cannot define or redefine them.
|
|
* ``[SCHEMA]`` — fail-closed aborts, the dominance/immutability/NOT-NULL-class/
|
|
last-active-grant invariants, enforced by CHECK/FK/trigger.
|
|
* ``[RUNTIME-ADAPTER]`` — *none* in this slice.
|
|
|
|
SQLite-first. ``BEGIN IMMEDIATE`` serializes concurrent installs and concurrent
|
|
grant/revoke on the singleton invariant row. PostgreSQL parity is a distinct
|
|
issue (#827); this module does **not** claim it.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
import sqlite3
|
|
import threading
|
|
from contextlib import contextmanager
|
|
from dataclasses import dataclass
|
|
from datetime import datetime, timezone
|
|
from typing import Iterator, Optional
|
|
|
|
# --------------------------------------------------------------------------- #
|
|
# Closed enumerations (#822 §4).
|
|
# --------------------------------------------------------------------------- #
|
|
|
|
ACTOR_KINDS = ("operator", "supervisor", "service", "installer")
|
|
OPERATION_MODES = ("normal", "install", "merge", "internal_service")
|
|
|
|
# Exact seeded authority-dominance tuple set (#822 §4). This set is normative:
|
|
# the install-state trigger rejects any missing, additional, or malformed tuple.
|
|
DOMINANCE_TUPLES = (
|
|
("platform.bootstrap", "platform.bootstrap"),
|
|
("platform.bootstrap", "project.admin"),
|
|
("platform.bootstrap", "supervisor.root.establish"),
|
|
("supervisor.root", "supervisor.register"),
|
|
("supervisor.root", "supervisor.verify"),
|
|
("supervisor.root", "supervisor.recover"),
|
|
)
|
|
|
|
# The distinguished operator-key issuer seeded during install.
|
|
DISTINGUISHED_ISSUER_KIND = "operator-key"
|
|
DISTINGUISHED_ISSUER_ID = "platform.bootstrap.operator-key"
|
|
|
|
# Structured result codes (#822 §10).
|
|
INSTALLED = "INSTALLED"
|
|
ALREADY_INSTALLED = "ALREADY_INSTALLED"
|
|
INVALID_ACTOR_CONTEXT = "INVALID_ACTOR_CONTEXT"
|
|
INVALID_BOOTSTRAP_STATE = "INVALID_BOOTSTRAP_STATE"
|
|
DOMINANCE_SET_MISMATCH = "DOMINANCE_SET_MISMATCH"
|
|
AUTHORIZATION_DENIED = "AUTHORIZATION_DENIED"
|
|
CONCURRENT_INSTALLATION_LOST = "CONCURRENT_INSTALLATION_LOST"
|
|
|
|
# Required audit events (#822 §14).
|
|
EVT_PLATFORM_INSTALLED = "platform_installed"
|
|
EVT_GRANT_CREATED = "platform_grant_created"
|
|
EVT_GRANT_REVOKED = "platform_grant_revoked"
|
|
EVT_PRINCIPAL_REGISTERED = "principal_registered"
|
|
|
|
SCHEMA_VERSION = 1
|
|
|
|
DB_PATH_ENV = "ARCH01_PLATFORM_DB"
|
|
|
|
|
|
class PlatformKernelError(RuntimeError):
|
|
"""Base class for structured, code-bearing kernel failures."""
|
|
|
|
def __init__(self, code: str, message: str = "") -> None:
|
|
super().__init__(message or code)
|
|
self.code = code
|
|
|
|
|
|
class ActorContextError(PlatformKernelError):
|
|
"""Raised when a mutation is attempted without a valid actor context."""
|
|
|
|
|
|
# --------------------------------------------------------------------------- #
|
|
# Schema (#822 §6). Tables + fail-closed triggers.
|
|
#
|
|
# Every *mutating* trigger opens with the actor protocol: read the context
|
|
# epoch, read the actor fields, and abort unless the context is present,
|
|
# non-null, mode/kind well-formed, and epoch-consistent with the active
|
|
# transaction. The scalar functions ``cp_*`` are registered from Python only;
|
|
# SQL has no statement that can set them, which is the trusted-service boundary.
|
|
# --------------------------------------------------------------------------- #
|
|
|
|
_ACTOR_KINDS_SQL = ", ".join("'%s'" % k for k in ACTOR_KINDS)
|
|
_OP_MODES_SQL = ", ".join("'%s'" % m for m in OPERATION_MODES)
|
|
|
|
# Actor-protocol predicate: TRUE when the context is INVALID and the trigger
|
|
# must abort. ``cp_actor_context_valid()`` folds "present + non-expired +
|
|
# live-epoch == bound-epoch" (the read/re-read epoch equality of #822 §4) into
|
|
# one trusted-service answer; the remaining reads assert field well-formedness.
|
|
_INVALID_ACTOR = (
|
|
"cp_actor_context_valid() IS NOT 1 "
|
|
"OR cp_context_epoch() IS NULL "
|
|
"OR cp_actor_principal() IS NULL "
|
|
"OR cp_actor_kind() NOT IN (%s) "
|
|
"OR cp_operation_mode() NOT IN (%s)" % (_ACTOR_KINDS_SQL, _OP_MODES_SQL)
|
|
)
|
|
|
|
_ACTOR_GUARD = (
|
|
"SELECT CASE WHEN (%s) "
|
|
"THEN RAISE(ABORT, 'INVALID_ACTOR_CONTEXT') END;" % _INVALID_ACTOR
|
|
)
|
|
|
|
# require_installed: abort a privileged mutation when there is no install
|
|
# marker and we are not currently installing (#822 §4).
|
|
_REQUIRE_INSTALLED = (
|
|
"SELECT CASE WHEN ((SELECT COUNT(*) FROM install_state) = 0 "
|
|
"AND cp_operation_mode() <> 'install') "
|
|
"THEN RAISE(ABORT, 'NOT_INSTALLED') END;"
|
|
)
|
|
|
|
_SCHEMA_SQL = f"""
|
|
PRAGMA foreign_keys = ON;
|
|
|
|
CREATE TABLE IF NOT EXISTS arch01_meta (
|
|
key TEXT PRIMARY KEY,
|
|
value TEXT NOT NULL
|
|
);
|
|
|
|
-- Equivalence classes are created BEFORE their first principal (#822 §4).
|
|
CREATE TABLE IF NOT EXISTS principal_equivalence_classes (
|
|
class_id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
created_at TEXT NOT NULL
|
|
);
|
|
|
|
CREATE TABLE IF NOT EXISTS authoritative_issuers (
|
|
issuer_id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
issuer_kind TEXT NOT NULL,
|
|
issuer_ref TEXT NOT NULL,
|
|
created_at TEXT NOT NULL,
|
|
UNIQUE (issuer_kind, issuer_ref)
|
|
);
|
|
|
|
-- current_class_id is NOT NULL: a principal cannot exist without a class
|
|
-- (#822 AC6). issuer_id is nullable ONLY for the installer during install
|
|
-- (#822 AC7), enforced by trg_principals_null_issuer below.
|
|
CREATE TABLE IF NOT EXISTS principals (
|
|
principal_id TEXT PRIMARY KEY,
|
|
actor_kind TEXT NOT NULL CHECK (actor_kind IN ({_ACTOR_KINDS_SQL})),
|
|
current_class_id INTEGER NOT NULL REFERENCES principal_equivalence_classes(class_id),
|
|
issuer_id INTEGER REFERENCES authoritative_issuers(issuer_id),
|
|
registered_by TEXT REFERENCES principals(principal_id),
|
|
created_at TEXT NOT NULL
|
|
);
|
|
|
|
CREATE TABLE IF NOT EXISTS authority_dominance (
|
|
dominant TEXT NOT NULL,
|
|
subordinate TEXT NOT NULL,
|
|
PRIMARY KEY (dominant, subordinate)
|
|
);
|
|
|
|
CREATE TABLE IF NOT EXISTS platform_bootstrap_seed (
|
|
seed_id INTEGER PRIMARY KEY CHECK (seed_id = 1),
|
|
installer_principal_id TEXT NOT NULL REFERENCES principals(principal_id),
|
|
created_at TEXT NOT NULL
|
|
);
|
|
|
|
CREATE TABLE IF NOT EXISTS platform_bootstrap_grants (
|
|
grant_id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
grantee_principal_id TEXT NOT NULL REFERENCES principals(principal_id),
|
|
granted_by TEXT REFERENCES principals(principal_id),
|
|
active INTEGER NOT NULL DEFAULT 1 CHECK (active IN (0, 1)),
|
|
created_at TEXT NOT NULL,
|
|
revoked_at TEXT
|
|
);
|
|
|
|
-- Singleton row; active_count floored at 1 by CHECK so the last active grant
|
|
-- can never be revoked (#822 AC11).
|
|
CREATE TABLE IF NOT EXISTS platform_active_invariant (
|
|
id INTEGER PRIMARY KEY CHECK (id = 1),
|
|
active_count INTEGER NOT NULL CHECK (active_count >= 1)
|
|
);
|
|
|
|
-- The immutable install marker; inserted LAST in the install transaction.
|
|
CREATE TABLE IF NOT EXISTS install_state (
|
|
id INTEGER PRIMARY KEY CHECK (id = 1),
|
|
marker TEXT NOT NULL CHECK (marker = 'installed'),
|
|
installed_at TEXT NOT NULL
|
|
);
|
|
|
|
-- Append-only (#822 AC14).
|
|
CREATE TABLE IF NOT EXISTS audit_records (
|
|
audit_id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
event TEXT NOT NULL,
|
|
principal_id TEXT,
|
|
detail TEXT,
|
|
created_at TEXT NOT NULL
|
|
);
|
|
|
|
-- ------------------------------------------------------------------------- --
|
|
-- Actor protocol on every mutating trigger (#822 §4, [SCHEMA] fail-closed).
|
|
-- ------------------------------------------------------------------------- --
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_classes_actor
|
|
BEFORE INSERT ON principal_equivalence_classes
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_issuers_actor
|
|
BEFORE INSERT ON authoritative_issuers
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_principals_actor
|
|
BEFORE INSERT ON principals
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_dominance_actor
|
|
BEFORE INSERT ON authority_dominance
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_seed_actor
|
|
BEFORE INSERT ON platform_bootstrap_seed
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_grants_actor_insert
|
|
BEFORE INSERT ON platform_bootstrap_grants
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
{_REQUIRE_INSTALLED}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_grants_actor_update
|
|
BEFORE UPDATE ON platform_bootstrap_grants
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_invariant_actor_insert
|
|
BEFORE INSERT ON platform_active_invariant
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_invariant_actor_update
|
|
BEFORE UPDATE ON platform_active_invariant
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_audit_actor
|
|
BEFORE INSERT ON audit_records
|
|
BEGIN
|
|
{_ACTOR_GUARD}
|
|
END;
|
|
|
|
-- ------------------------------------------------------------------------- --
|
|
-- NOT-NULL-issuer exception for the installer only (#822 AC7).
|
|
-- A NULL issuer_id is accepted solely for an installer principal during
|
|
-- install mode, before the marker exists; any other NULL-issuer principal is
|
|
-- rejected. install-time issuer linkage (installer -> distinguished issuer)
|
|
-- is applied by a later UPDATE, permitted while no marker exists.
|
|
-- ------------------------------------------------------------------------- --
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_principals_null_issuer
|
|
BEFORE INSERT ON principals
|
|
WHEN NEW.issuer_id IS NULL
|
|
BEGIN
|
|
SELECT CASE WHEN NOT (
|
|
NEW.actor_kind = 'installer'
|
|
AND cp_operation_mode() = 'install'
|
|
AND (SELECT COUNT(*) FROM install_state) = 0
|
|
AND (SELECT COUNT(*) FROM principals WHERE issuer_id IS NULL) = 0
|
|
) THEN RAISE(ABORT, 'INVALID_BOOTSTRAP_STATE') END;
|
|
END;
|
|
|
|
-- ------------------------------------------------------------------------- --
|
|
-- Post-install immutability of the authority root (#822 §4, AC9).
|
|
-- Registration fields freeze only AFTER the marker exists, so the install
|
|
-- transaction's own installer issuer-linkage UPDATE is permitted.
|
|
-- ------------------------------------------------------------------------- --
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_principals_frozen_update
|
|
BEFORE UPDATE ON principals
|
|
WHEN (SELECT COUNT(*) FROM install_state) > 0
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_PRINCIPAL');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_principals_frozen_delete
|
|
BEFORE DELETE ON principals
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_PRINCIPAL');
|
|
END;
|
|
|
|
-- Distinguished issuer identity is immutable once written.
|
|
CREATE TRIGGER IF NOT EXISTS trg_issuers_immutable_update
|
|
BEFORE UPDATE ON authoritative_issuers
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_ISSUER');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_issuers_immutable_delete
|
|
BEFORE DELETE ON authoritative_issuers
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_ISSUER');
|
|
END;
|
|
|
|
-- The dominance lattice is immutable once seeded.
|
|
CREATE TRIGGER IF NOT EXISTS trg_dominance_immutable_update
|
|
BEFORE UPDATE ON authority_dominance
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_DOMINANCE');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_dominance_immutable_delete
|
|
BEFORE DELETE ON authority_dominance
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_DOMINANCE');
|
|
END;
|
|
|
|
-- The bootstrap seed is immutable once written.
|
|
CREATE TRIGGER IF NOT EXISTS trg_seed_immutable_update
|
|
BEFORE UPDATE ON platform_bootstrap_seed
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_SEED');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_seed_immutable_delete
|
|
BEFORE DELETE ON platform_bootstrap_seed
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_SEED');
|
|
END;
|
|
|
|
-- The install marker is immutable once written.
|
|
CREATE TRIGGER IF NOT EXISTS trg_install_state_immutable_update
|
|
BEFORE UPDATE ON install_state
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_INSTALL_STATE');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_install_state_immutable_delete
|
|
BEFORE DELETE ON install_state
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_INSTALL_STATE');
|
|
END;
|
|
|
|
-- Grants: identity is immutable; the ONLY permitted mutation is a single
|
|
-- active 1 -> 0 revocation (#822 §4 initial-grant identity immutability +
|
|
-- grant/revoke). Reactivation and identity edits are rejected.
|
|
CREATE TRIGGER IF NOT EXISTS trg_grants_identity_frozen
|
|
BEFORE UPDATE ON platform_bootstrap_grants
|
|
WHEN NOT (
|
|
NEW.grant_id = OLD.grant_id
|
|
AND NEW.grantee_principal_id = OLD.grantee_principal_id
|
|
AND NEW.granted_by IS OLD.granted_by
|
|
AND NEW.created_at = OLD.created_at
|
|
AND OLD.active = 1
|
|
AND NEW.active = 0
|
|
)
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_GRANT');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_grants_no_delete
|
|
BEFORE DELETE ON platform_bootstrap_grants
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_GRANT');
|
|
END;
|
|
|
|
-- audit_records is append-only.
|
|
CREATE TRIGGER IF NOT EXISTS trg_audit_immutable_update
|
|
BEFORE UPDATE ON audit_records
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_AUDIT');
|
|
END;
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_audit_immutable_delete
|
|
BEFORE DELETE ON audit_records
|
|
BEGIN
|
|
SELECT RAISE(ABORT, 'IMMUTABLE_AUDIT');
|
|
END;
|
|
|
|
-- ------------------------------------------------------------------------- --
|
|
-- install_state BEFORE INSERT: validate the whole bootstrap atomically
|
|
-- (#822 §4, AC4). Each dominance tuple is checked individually; a missing,
|
|
-- additional, or malformed tuple -> DOMINANCE_SET_MISMATCH. The seed<->installer
|
|
-- link, the single active NULL-grantor installer grant, the installer's
|
|
-- non-NULL issuer, the active invariant, and "no extra principal created under
|
|
-- the NULL-issuer exception" -> INVALID_BOOTSTRAP_STATE.
|
|
-- ------------------------------------------------------------------------- --
|
|
|
|
CREATE TRIGGER IF NOT EXISTS trg_install_state_validate
|
|
BEFORE INSERT ON install_state
|
|
BEGIN
|
|
SELECT CASE WHEN NOT (
|
|
(SELECT COUNT(*) FROM authority_dominance) = {len(DOMINANCE_TUPLES)}
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='platform.bootstrap' AND subordinate='platform.bootstrap')
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='platform.bootstrap' AND subordinate='project.admin')
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='platform.bootstrap' AND subordinate='supervisor.root.establish')
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='supervisor.root' AND subordinate='supervisor.register')
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='supervisor.root' AND subordinate='supervisor.verify')
|
|
AND EXISTS (SELECT 1 FROM authority_dominance WHERE dominant='supervisor.root' AND subordinate='supervisor.recover')
|
|
) THEN RAISE(ABORT, 'DOMINANCE_SET_MISMATCH') END;
|
|
|
|
SELECT CASE WHEN NOT (
|
|
(SELECT COUNT(*) FROM platform_bootstrap_seed) = 1
|
|
AND (SELECT COUNT(*) FROM principals) = 1
|
|
AND (SELECT actor_kind FROM principals
|
|
WHERE principal_id = (SELECT installer_principal_id FROM platform_bootstrap_seed WHERE seed_id = 1)
|
|
) = 'installer'
|
|
AND (SELECT issuer_id FROM principals
|
|
WHERE principal_id = (SELECT installer_principal_id FROM platform_bootstrap_seed WHERE seed_id = 1)
|
|
) IS NOT NULL
|
|
AND (SELECT COUNT(*) FROM platform_bootstrap_grants
|
|
WHERE granted_by IS NULL AND active = 1
|
|
AND grantee_principal_id = (SELECT installer_principal_id FROM platform_bootstrap_seed WHERE seed_id = 1)
|
|
) = 1
|
|
AND (SELECT COUNT(*) FROM platform_bootstrap_grants) = 1
|
|
AND (SELECT active_count FROM platform_active_invariant WHERE id = 1) = 1
|
|
) THEN RAISE(ABORT, 'INVALID_BOOTSTRAP_STATE') END;
|
|
END;
|
|
"""
|
|
|
|
|
|
def default_db_path() -> str:
|
|
return os.environ.get(
|
|
DB_PATH_ENV,
|
|
os.path.expanduser("~/.cache/gitea-tools/arch01/platform.sqlite3"),
|
|
)
|
|
|
|
|
|
def _utc_now_iso() -> str:
|
|
return datetime.now(timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ")
|
|
|
|
|
|
@dataclass(frozen=True)
|
|
class OperationResult:
|
|
"""Structured result of a kernel operation (#822 §10)."""
|
|
|
|
code: str
|
|
detail: str = ""
|
|
|
|
@property
|
|
def ok(self) -> bool:
|
|
return self.code in (INSTALLED, ALREADY_INSTALLED)
|
|
|
|
|
|
@dataclass
|
|
class _ActorContext:
|
|
principal: str
|
|
kind: str
|
|
mode: str
|
|
session: Optional[str]
|
|
bound_epoch: int
|
|
live_epoch: int
|
|
expired: bool = False
|
|
|
|
|
|
class PlatformKernel:
|
|
"""ARCH-01 authority kernel over a single SQLite connection.
|
|
|
|
The connection carries the trusted-service actor context: the ``cp_*``
|
|
scalar functions read the context this object holds. Only Python code here
|
|
can bind or clear it, so no SQL statement can assert an actor identity — the
|
|
trusted-service authenticity boundary of #822 §4.
|
|
"""
|
|
|
|
def __init__(self, db_path: Optional[str] = None, *, busy_timeout_ms: int = 5000) -> None:
|
|
self.db_path = db_path or default_db_path()
|
|
if self.db_path != ":memory:":
|
|
parent = os.path.dirname(self.db_path)
|
|
if parent:
|
|
os.makedirs(parent, exist_ok=True)
|
|
self._ctx: Optional[_ActorContext] = None
|
|
self._epoch_seq = 0
|
|
self._lock = threading.Lock()
|
|
# check_same_thread=False is safe: every mutation path is serialized
|
|
# by self._lock, so the connection is never used concurrently even when
|
|
# callers drive the kernel from different threads (concurrency tests).
|
|
self._conn = sqlite3.connect(
|
|
self.db_path, isolation_level=None, check_same_thread=False
|
|
)
|
|
self._conn.execute("PRAGMA foreign_keys = ON")
|
|
self._conn.execute(f"PRAGMA busy_timeout = {int(busy_timeout_ms)}")
|
|
self._register_actor_functions()
|
|
self._migrate()
|
|
|
|
# -- trusted-service actor functions ---------------------------------- #
|
|
|
|
def _register_actor_functions(self) -> None:
|
|
c = self._conn
|
|
c.create_function("cp_actor_principal", 0, lambda: self._ctx.principal if self._ctx else None)
|
|
c.create_function("cp_actor_kind", 0, lambda: self._ctx.kind if self._ctx else None)
|
|
c.create_function("cp_operation_mode", 0, lambda: self._ctx.mode if self._ctx else None)
|
|
c.create_function("cp_service_session", 0, lambda: self._ctx.session if self._ctx else None)
|
|
c.create_function("cp_context_epoch", 0, self._fn_context_epoch)
|
|
# Trusted-service helper: folds present + non-expired + epoch-consistent
|
|
# into the read/re-read epoch equality of #822 §4.
|
|
c.create_function("cp_actor_context_valid", 0, self._fn_context_valid)
|
|
|
|
def _fn_context_epoch(self) -> Optional[int]:
|
|
if self._ctx is None or self._ctx.expired:
|
|
return None
|
|
return self._ctx.live_epoch
|
|
|
|
def _fn_context_valid(self) -> int:
|
|
ctx = self._ctx
|
|
if ctx is None or ctx.expired:
|
|
return 0
|
|
# read/re-read epoch equality: a context whose live epoch has drifted
|
|
# from the epoch it was bound to (a stale/replaced connection context)
|
|
# is not bound to the active transaction and fails closed.
|
|
if ctx.live_epoch != ctx.bound_epoch:
|
|
return 0
|
|
if ctx.principal is None:
|
|
return 0
|
|
if ctx.kind not in ACTOR_KINDS or ctx.mode not in OPERATION_MODES:
|
|
return 0
|
|
return 1
|
|
|
|
# -- context lifecycle ------------------------------------------------ #
|
|
|
|
@contextmanager
|
|
def actor_context(
|
|
self, principal: str, kind: str, mode: str, session: Optional[str] = None
|
|
) -> Iterator[None]:
|
|
"""Bind a trusted actor context for the duration of the block."""
|
|
prev = self._ctx
|
|
self._epoch_seq += 1
|
|
epoch = self._epoch_seq
|
|
self._ctx = _ActorContext(
|
|
principal=principal, kind=kind, mode=mode, session=session,
|
|
bound_epoch=epoch, live_epoch=epoch,
|
|
)
|
|
try:
|
|
yield
|
|
finally:
|
|
self._ctx = prev
|
|
|
|
def _clear_context(self) -> None:
|
|
self._ctx = None
|
|
|
|
# -- migration -------------------------------------------------------- #
|
|
|
|
def _migrate(self) -> None:
|
|
self._conn.executescript(_SCHEMA_SQL)
|
|
self._conn.execute(
|
|
"INSERT OR IGNORE INTO arch01_meta(key, value) VALUES ('schema_version', ?)",
|
|
(str(SCHEMA_VERSION),),
|
|
)
|
|
self._conn.execute(
|
|
"INSERT OR IGNORE INTO arch01_meta(key, value) VALUES "
|
|
"('architecture', 'ARCH-01 Slice A: atomic install + authority kernel (#822); "
|
|
"disabled by default until readiness checks pass')"
|
|
)
|
|
|
|
# -- introspection ---------------------------------------------------- #
|
|
|
|
def is_installed(self) -> bool:
|
|
row = self._conn.execute("SELECT COUNT(*) FROM install_state").fetchone()
|
|
return bool(row[0])
|
|
|
|
def active_grant_count(self) -> int:
|
|
row = self._conn.execute(
|
|
"SELECT active_count FROM platform_active_invariant WHERE id = 1"
|
|
).fetchone()
|
|
return int(row[0]) if row else 0
|
|
|
|
def audit_events(self) -> list[str]:
|
|
return [
|
|
r[0]
|
|
for r in self._conn.execute(
|
|
"SELECT event FROM audit_records ORDER BY audit_id"
|
|
).fetchall()
|
|
]
|
|
|
|
def close(self) -> None:
|
|
self._conn.close()
|
|
|
|
# -- operations ------------------------------------------------------- #
|
|
|
|
def install_platform(
|
|
self,
|
|
installer_principal_id: str = "platform.installer",
|
|
*,
|
|
session: Optional[str] = None,
|
|
) -> OperationResult:
|
|
"""Single atomic install transaction (#822 §4/§7).
|
|
|
|
``BEGIN IMMEDIATE`` serializes concurrent installs; the loser rechecks
|
|
the marker and returns ``ALREADY_INSTALLED``, or — if it never acquires
|
|
the write lock — ``CONCURRENT_INSTALLATION_LOST``. On any stage failure
|
|
the whole transaction rolls back leaving no partial rows (AC3/AC5).
|
|
"""
|
|
now = _utc_now_iso()
|
|
with self._lock:
|
|
try:
|
|
self._conn.execute("BEGIN IMMEDIATE")
|
|
except sqlite3.OperationalError as exc:
|
|
if "locked" in str(exc).lower() or "busy" in str(exc).lower():
|
|
return OperationResult(CONCURRENT_INSTALLATION_LOST, str(exc))
|
|
raise
|
|
try:
|
|
if self.is_installed():
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(ALREADY_INSTALLED, "install marker already present")
|
|
|
|
with self.actor_context(installer_principal_id, "installer", "install", session):
|
|
c = self._conn
|
|
# class -> installer principal (temporary NULL issuer)
|
|
cur = c.execute(
|
|
"INSERT INTO principal_equivalence_classes(created_at) VALUES (?)",
|
|
(now,),
|
|
)
|
|
class_id = cur.lastrowid
|
|
c.execute(
|
|
"INSERT INTO principals"
|
|
"(principal_id, actor_kind, current_class_id, issuer_id, registered_by, created_at) "
|
|
"VALUES (?, 'installer', ?, NULL, ?, ?)",
|
|
(installer_principal_id, class_id, installer_principal_id, now),
|
|
)
|
|
# distinguished operator-key issuer
|
|
cur = c.execute(
|
|
"INSERT INTO authoritative_issuers(issuer_kind, issuer_ref, created_at) "
|
|
"VALUES (?, ?, ?)",
|
|
(DISTINGUISHED_ISSUER_KIND, DISTINGUISHED_ISSUER_ID, now),
|
|
)
|
|
issuer_id = cur.lastrowid
|
|
# link installer -> issuer (permitted pre-marker)
|
|
c.execute(
|
|
"UPDATE principals SET issuer_id = ? WHERE principal_id = ?",
|
|
(issuer_id, installer_principal_id),
|
|
)
|
|
# dominance tuples
|
|
c.executemany(
|
|
"INSERT INTO authority_dominance(dominant, subordinate) VALUES (?, ?)",
|
|
DOMINANCE_TUPLES,
|
|
)
|
|
# seed
|
|
c.execute(
|
|
"INSERT INTO platform_bootstrap_seed(seed_id, installer_principal_id, created_at) "
|
|
"VALUES (1, ?, ?)",
|
|
(installer_principal_id, now),
|
|
)
|
|
# initial grant (granted_by NULL, active)
|
|
c.execute(
|
|
"INSERT INTO platform_bootstrap_grants"
|
|
"(grantee_principal_id, granted_by, active, created_at) "
|
|
"VALUES (?, NULL, 1, ?)",
|
|
(installer_principal_id, now),
|
|
)
|
|
# active invariant
|
|
c.execute(
|
|
"INSERT INTO platform_active_invariant(id, active_count) VALUES (1, 1)"
|
|
)
|
|
# audit rows for the security-sensitive operation
|
|
c.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_PRINCIPAL_REGISTERED, installer_principal_id, "installer", now),
|
|
)
|
|
c.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_GRANT_CREATED, installer_principal_id, "initial platform.bootstrap grant", now),
|
|
)
|
|
# install marker LAST -> fires the whole-bootstrap validator
|
|
c.execute(
|
|
"INSERT INTO install_state(id, marker, installed_at) VALUES (1, 'installed', ?)",
|
|
(now,),
|
|
)
|
|
c.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_PLATFORM_INSTALLED, installer_principal_id, "platform installed", now),
|
|
)
|
|
self._conn.execute("COMMIT")
|
|
return OperationResult(INSTALLED, "platform installed")
|
|
except sqlite3.Error as exc:
|
|
self._safe_rollback()
|
|
return OperationResult(self._classify(exc), str(exc))
|
|
|
|
def register_principal(
|
|
self,
|
|
principal_id: str,
|
|
actor_kind: str,
|
|
issuer_ref: str,
|
|
*,
|
|
actor_principal: str,
|
|
actor_kind_ctx: str = "operator",
|
|
session: Optional[str] = None,
|
|
) -> OperationResult:
|
|
"""Atomically create an equivalence class and its first principal.
|
|
|
|
The class is inserted *before* the principal, and ``current_class_id``
|
|
is ``NOT NULL`` (#822 AC6): a principal can never exist classless.
|
|
The principal references an existing issuer (non-NULL); the temporary
|
|
NULL-issuer exception is reserved for the installer during install
|
|
(AC7).
|
|
"""
|
|
if actor_kind not in ACTOR_KINDS:
|
|
return OperationResult(INVALID_BOOTSTRAP_STATE, f"bad actor_kind {actor_kind!r}")
|
|
now = _utc_now_iso()
|
|
with self._lock:
|
|
try:
|
|
self._conn.execute("BEGIN IMMEDIATE")
|
|
except sqlite3.OperationalError as exc:
|
|
return OperationResult(AUTHORIZATION_DENIED, str(exc))
|
|
try:
|
|
if not self.is_installed():
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(INVALID_BOOTSTRAP_STATE, "platform not installed")
|
|
row = self._conn.execute(
|
|
"SELECT issuer_id FROM authoritative_issuers WHERE issuer_ref = ?",
|
|
(issuer_ref,),
|
|
).fetchone()
|
|
if row is None:
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(INVALID_BOOTSTRAP_STATE, f"unknown issuer {issuer_ref!r}")
|
|
issuer_id = row[0]
|
|
with self.actor_context(actor_principal, actor_kind_ctx, "normal", session):
|
|
cur = self._conn.execute(
|
|
"INSERT INTO principal_equivalence_classes(created_at) VALUES (?)",
|
|
(now,),
|
|
)
|
|
class_id = cur.lastrowid
|
|
self._conn.execute(
|
|
"INSERT INTO principals"
|
|
"(principal_id, actor_kind, current_class_id, issuer_id, registered_by, created_at) "
|
|
"VALUES (?, ?, ?, ?, ?, ?)",
|
|
(principal_id, actor_kind, class_id, issuer_id, actor_principal, now),
|
|
)
|
|
self._conn.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_PRINCIPAL_REGISTERED, principal_id, actor_kind, now),
|
|
)
|
|
self._conn.execute("COMMIT")
|
|
return OperationResult(INSTALLED, f"registered {principal_id}")
|
|
except sqlite3.Error as exc:
|
|
self._safe_rollback()
|
|
return OperationResult(self._classify(exc), str(exc))
|
|
|
|
def grant_platform_bootstrap(
|
|
self,
|
|
grantee_principal_id: str,
|
|
granted_by: str,
|
|
*,
|
|
actor_kind_ctx: str = "operator",
|
|
session: Optional[str] = None,
|
|
) -> OperationResult:
|
|
"""Create an additional active platform.bootstrap grant.
|
|
|
|
Serialized on the singleton invariant row via ``BEGIN IMMEDIATE``.
|
|
"""
|
|
now = _utc_now_iso()
|
|
with self._lock:
|
|
try:
|
|
self._conn.execute("BEGIN IMMEDIATE")
|
|
except sqlite3.OperationalError as exc:
|
|
return OperationResult(AUTHORIZATION_DENIED, str(exc))
|
|
try:
|
|
if not self.is_installed():
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(INVALID_BOOTSTRAP_STATE, "platform not installed")
|
|
with self.actor_context(granted_by, actor_kind_ctx, "normal", session):
|
|
self._conn.execute(
|
|
"INSERT INTO platform_bootstrap_grants"
|
|
"(grantee_principal_id, granted_by, active, created_at) "
|
|
"VALUES (?, ?, 1, ?)",
|
|
(grantee_principal_id, granted_by, now),
|
|
)
|
|
self._conn.execute(
|
|
"UPDATE platform_active_invariant SET active_count = active_count + 1 WHERE id = 1"
|
|
)
|
|
self._conn.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_GRANT_CREATED, grantee_principal_id, f"granted_by={granted_by}", now),
|
|
)
|
|
self._conn.execute("COMMIT")
|
|
return OperationResult(INSTALLED, f"granted to {grantee_principal_id}")
|
|
except sqlite3.Error as exc:
|
|
self._safe_rollback()
|
|
return OperationResult(self._classify(exc), str(exc))
|
|
|
|
def revoke_platform_bootstrap(
|
|
self,
|
|
grant_id: int,
|
|
*,
|
|
actor_principal: str,
|
|
actor_kind_ctx: str = "operator",
|
|
session: Optional[str] = None,
|
|
) -> OperationResult:
|
|
"""Revoke an active grant, floored so the last one can never drop.
|
|
|
|
The ``active_count >= 1`` CHECK plus ``BEGIN IMMEDIATE`` serialization
|
|
make two concurrent revocations unable to remove the final active grant
|
|
(#822 AC11): the decrement that would reach zero fails and rolls back.
|
|
"""
|
|
now = _utc_now_iso()
|
|
with self._lock:
|
|
try:
|
|
self._conn.execute("BEGIN IMMEDIATE")
|
|
except sqlite3.OperationalError as exc:
|
|
return OperationResult(AUTHORIZATION_DENIED, str(exc))
|
|
try:
|
|
if not self.is_installed():
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(INVALID_BOOTSTRAP_STATE, "platform not installed")
|
|
row = self._conn.execute(
|
|
"SELECT active, grantee_principal_id FROM platform_bootstrap_grants WHERE grant_id = ?",
|
|
(grant_id,),
|
|
).fetchone()
|
|
if row is None or row[0] != 1:
|
|
self._conn.execute("ROLLBACK")
|
|
return OperationResult(AUTHORIZATION_DENIED, "grant absent or already inactive")
|
|
grantee = row[1]
|
|
with self.actor_context(actor_principal, actor_kind_ctx, "normal", session):
|
|
# Decrement first: the CHECK floor rejects dropping below 1,
|
|
# aborting the whole revoke before the grant flips inactive.
|
|
self._conn.execute(
|
|
"UPDATE platform_active_invariant SET active_count = active_count - 1 WHERE id = 1"
|
|
)
|
|
self._conn.execute(
|
|
"UPDATE platform_bootstrap_grants SET active = 0, revoked_at = ? WHERE grant_id = ?",
|
|
(now, grant_id),
|
|
)
|
|
self._conn.execute(
|
|
"INSERT INTO audit_records(event, principal_id, detail, created_at) "
|
|
"VALUES (?, ?, ?, ?)",
|
|
(EVT_GRANT_REVOKED, grantee, f"grant_id={grant_id}", now),
|
|
)
|
|
self._conn.execute("COMMIT")
|
|
return OperationResult(INSTALLED, f"revoked grant {grant_id}")
|
|
except sqlite3.Error as exc:
|
|
self._safe_rollback()
|
|
return OperationResult(self._classify(exc), str(exc))
|
|
|
|
# -- helpers ---------------------------------------------------------- #
|
|
|
|
def _safe_rollback(self) -> None:
|
|
try:
|
|
self._conn.execute("ROLLBACK")
|
|
except sqlite3.Error:
|
|
pass
|
|
|
|
@staticmethod
|
|
def _classify(exc: sqlite3.Error) -> str:
|
|
msg = str(exc)
|
|
if "INVALID_ACTOR_CONTEXT" in msg:
|
|
return INVALID_ACTOR_CONTEXT
|
|
if "DOMINANCE_SET_MISMATCH" in msg:
|
|
return DOMINANCE_SET_MISMATCH
|
|
if "active_count" in msg or "CHECK constraint failed: platform_active_invariant" in msg:
|
|
# last-active-grant floor tripped
|
|
return AUTHORIZATION_DENIED
|
|
if any(tag in msg for tag in (
|
|
"INVALID_BOOTSTRAP_STATE", "IMMUTABLE_", "NOT_INSTALLED",
|
|
)):
|
|
return INVALID_BOOTSTRAP_STATE
|
|
return INVALID_BOOTSTRAP_STATE
|