docs: finalize v1 design and Windows service model

This commit is contained in:
2026-08-28 11:00:58 +00:00
parent a89253be96
commit 85f4d5d2a0
11 changed files with 833 additions and 241 deletions
+1
View File
@@ -40,6 +40,7 @@ message ClientHello {
string daemon_version = 3;
Platform platform = 4;
string architecture = 5;
// Omitted-CWD default on Unix; protected per-identity work root on Windows.
string daemon_cwd = 6;
repeated ShellType supported_shells = 7;
// Generated once and persisted in the client state directory.
+36
View File
@@ -35,6 +35,16 @@ enum ShellType {
SHELL_POWERSHELL = 4;
}
// Effective Windows process token/session context selected by the client.
enum WindowsExecutionContext {
WINDOWS_EXECUTION_CONTEXT_UNSPECIFIED = 0;
WINDOWS_EXECUTION_CONTEXT_LOCAL_SERVICE = 1;
WINDOWS_EXECUTION_CONTEXT_LOCAL_SYSTEM = 2;
WINDOWS_EXECUTION_CONTEXT_ACTIVE_USER = 3;
WINDOWS_EXECUTION_CONTEXT_ACTIVE_USER_ELEVATED = 4;
WINDOWS_EXECUTION_CONTEXT_ACTIVE_SYSTEM = 5;
}
enum Compression {
COMPRESSION_UNSPECIFIED = 0;
COMPRESSION_NONE = 1;
@@ -101,6 +111,24 @@ message ExecutionSpec {
string command_text = 5;
ScriptDescriptor script = 6;
}
// Requests the platform's elevated execution policy. False is the normal
// least-privilege policy. Non-Windows clients reject true in v1.
bool elevated = 7;
}
// Effective Windows identity captured at launch. session_id and
// session_user_sid are absent for Session 0 contexts. effective_user_sid is
// the actual process-token user, not the owner of the target desktop session.
message WindowsExecutionIdentity {
// Absent when every allowed context failed before launch preparation.
optional WindowsExecutionContext effective_context = 1;
optional uint32 session_id = 2;
string session_user_sid = 3;
string effective_user_sid = 4;
// Ordered contexts considered during pre-launch selection, including the
// effective final context. This is never a record of process retries.
repeated WindowsExecutionContext attempted_contexts = 5;
string selection_detail = 6;
}
message CommandRecord {
@@ -121,6 +149,9 @@ message CommandRecord {
ControlError rejection = 14;
uint64 command_revision = 15;
bool late_after_expiry = 16;
// Present after Windows context selection was attempted, including a
// pre-launch rejection for which effective_context is absent.
WindowsExecutionIdentity windows_execution_identity = 17;
}
message LifecycleChange {
@@ -128,6 +159,9 @@ message LifecycleChange {
optional int32 exit_code = 2;
string detail = 3;
uint64 command_revision = 4;
// Set on a Windows context-selection rejection or RUNNING, then repeated
// unchanged on later lifecycle events.
WindowsExecutionIdentity windows_execution_identity = 5;
}
// data is compressed according to compression. uncompressed_size is mandatory
@@ -235,6 +269,8 @@ message ControlError {
TRANSIENT = 8;
INTERNAL = 9;
CODE_ALREADY_EXECUTED = 10;
CODE_EXECUTION_CONTEXT_UNAVAILABLE = 11;
CODE_ELEVATION_UNAVAILABLE = 12;
}
Code code = 1;
string message = 2;
+1
View File
@@ -35,6 +35,7 @@ message ClientSummary {
Platform platform = 7;
string architecture = 8;
string daemon_version = 9;
// Omitted-CWD default on Unix; protected per-identity work root on Windows.
string daemon_cwd = 10;
repeated ShellType supported_shells = 11;
string client_instance_id = 12;