feat: persist supervised process PID evidence

This commit is contained in:
2026-09-06 14:09:25 +00:00
parent 3f08950415
commit 1527f561b5
4 changed files with 16 additions and 2 deletions
+3
View File
@@ -130,6 +130,9 @@ func windowsExecutionContext(value string) (rvboxv1.WindowsExecutionContext, boo
type Process interface {
IssueUUID() domain.UUID
Identity() EffectiveIdentity
// PID is immutable process evidence used only for diagnostics/recovery
// correlation; callers must never signal a process by PID alone.
PID() uint32
// Release crosses the durable launch-authorized barrier. A native Windows
// process is created suspended and must not execute before this call.
Release(context.Context) error
@@ -116,6 +116,13 @@ func (process *execProcess) IssueUUID() domain.UUID { return process.issue }
func (process *execProcess) Identity() supervisor.EffectiveIdentity { return process.identity }
func (process *execProcess) PID() uint32 {
if process == nil {
return 0
}
return process.pid
}
// Release is the second half of the durable launch barrier. The portable
// adapter has no suspended native handle, so its release is intentionally a
// no-op; the Windows adapter supplies a ResumeThread closure.
@@ -48,6 +48,9 @@ func TestPortableSupervisorCapturesOutputAndSupportsStdin_HP_SUPERVISOR_03(t *te
if err != nil {
t.Fatal(err)
}
if process.PID() == 0 {
t.Fatal("portable supervisor did not expose process identity PID")
}
if err := process.WriteStdin(context.Background(), []byte("hello"), true); err != nil {
t.Fatal(err)
}