abc1b56d241f259326e06a46ca7daede9e6703a2
Stamp owner_local_user on records written via prog/write and gate the mutating paths (prog, write, del — both live and buffered txn) so a session may only create or overwrite a record whose owner_local_user matches its HELLO-declared identity. Design (logical + expedient for the whole project): - Owner is the durable record-level CubeHeader.owner_local_user field, so enforcement is replay-safe and works across daemon restart. - Enforcement is opt-in/non-breaking: gated only when the session has a stamped identity AND the record has an owner. First write by an owner claims an unowned coord; a session with no identity (tests, legacy) writes freely. - COMMIT re-checks owner on each buffered op before applying, so a concurrent cross-owner commit between BEGIN and COMMIT is rejected (txn is restored for retry, not silently dropped). - seal/open (encrypted raw put/del) left ungated for now: their headers are not owner-stamped yet — tracked as follow-up. Verification: - ./check quick: EXIT=0, fmt+clippy clean, 26 cubesys tests (added owner_enforcement_blocks_cross_owner_overwrite, owner_enforcement_allows_first_claim_and_same_owner, for_tenant_carries_identity). - Ad-hoc daemon verifier over real cube-server socket (LE framing): cross-owner overwrite + delete rejected, same-owner + first-claim allowed, no-HELLO legacy writes allowed. ALL PASS.
Description
No description provided
536 KiB
Languages
Rust
94.5%
Python
2.8%
Shell
2.7%