feat: authenticate Windows command launcher and signal helper
This commit is contained in:
+10
-3
@@ -61,9 +61,16 @@ that command text is accepted once, output is journaled, lifecycle/terminal
|
||||
events are durable, and a script cannot launch before its contiguous upload is
|
||||
committed. The Windows build uses the same executor contract with the
|
||||
platform-native adapter: a verified token is selected, the child is created
|
||||
suspended, assigned to a kill-on-close Job, and only then released. The
|
||||
durable `launch_phase` barrier is recovered as `interrupted` after a daemon
|
||||
restart, so an uncertain release is never redispatched.
|
||||
suspended, assigned to a kill-on-close Job, and held behind an authenticated
|
||||
per-command launcher pipe. The daemon records `launch_prepared`, then the
|
||||
durable `launch_authorized` transition sends the launcher's release frame; the
|
||||
launcher resumes the shell only after that acknowledgement. The durable
|
||||
`launch_phase` barrier is recovered as `interrupted` after a daemon restart, so
|
||||
an uncertain release is never redispatched.
|
||||
|
||||
The Windows artifact is linked with the GUI subsystem (`-H=windowsgui`) so
|
||||
service, launcher, and tray startup do not flash a console. Human-facing modes
|
||||
still attach to a parent console explicitly when one exists.
|
||||
|
||||
Suite output is capped at 1 MiB and stored as `artifacts/suite.log`. A failed
|
||||
run remains inspectable and can be moved back to `ready` with `recover`, then
|
||||
|
||||
Reference in New Issue
Block a user