26 lines
1.2 KiB
Markdown
26 lines
1.2 KiB
Markdown
# Phase 1.0AN: offline service lifecycle and copy audit
|
|
|
|
Status: `FAIL_STOP_PRESENT_RESTART_AND_BOUNDED_COPY_UNPROVEN_TARGET_CODE_BLOCKED`
|
|
|
|
Date: 2026-07-29
|
|
|
|
The hardened elfldr fork has a real fail-stop for its ptrace credential scope.
|
|
If restoration of the temporary auth ID fails, a process-global latch rejects
|
|
all later ptrace calls. After the current request and its cleanup attempt, the
|
|
socket service calls `_exit(125)`.
|
|
|
|
That proves process termination, not safe recovery. No reviewed source owns a
|
|
bounded restart, verifies the identity of a replacement service, or proves
|
|
cleanup when startup-level credential restoration fails. Automatic restart is
|
|
therefore forbidden.
|
|
|
|
The alternative `pt_copyin` route is also insufficient. It issues one blocking
|
|
`PT_IO` request and does not validate returned descriptor progress. The source
|
|
has neither a hard deadline/preemption mechanism for that call nor proof that a
|
|
successful return means the exact requested byte count. It cannot replace the
|
|
unsafe SDK `mdbg_copyin` merely because it changes fewer credentials.
|
|
|
|
The next work may only design a host-only preemption and service-owner
|
|
architecture. No target source, build, connection, transfer, restart or device
|
|
execution is authorized.
|