Skip to content

feat(relay): authenticate registered alternate poll shims - #1

Closed
derickdsouza wants to merge 2 commits into
mainfrom
fm/harbor-hitl-trust-binding
Closed

derickdsouza wants to merge 2 commits into
mainfrom
fm/harbor-hitl-trust-binding

Conversation

@derickdsouza

@derickdsouza derickdsouza commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Add an explicit bin/fm-x-watch-register.sh binding so a registered alternate Relay poll shim (harbor-style wrapper) is authenticated as a first-class X-mode poll path.
  • Watcher dispatch and bootstrap regeneration honor a still-valid binding; a stale exec target falls back to the stock shim; unregistered rewrites stay rejected.
  • Homes without a registration keep today's stock generation and byte-static validation.

What Changed

  • Add bin/fm-x-watch-register.sh, the sole writer of a state/x-watch.poll-trust binding record (mode 0600, never auto-created) that pins the current shim bytes plus the absolute path and sha256 of its exec target.
  • The watcher's check dispatch and fm-bootstrap.sh's x_mode_setup now resolve the poll exec target through the new fmx_poll_exec_target/fmx_poll_shim_registered_valid helpers: a still-matching registration is preserved across bootstrap regeneration and dispatched by the watcher, while stale or tampered bindings are rejected exactly like unregistered rewrites, with the rejection message naming the re-register command as the remedy.
  • Replace the dead composite validator fmx_poll_shim_valid with the split fmx_poll_shim_stock_valid, and document the registration path in the docs/configuration.md Relay section, docs/scripts.md, and AGENTS.md, with colocated tests in tests/fm-x-watch-register.test.sh covering stock, registered, unregistered, and tampered-target variants.

Testing

  • tests/fm-x-watch-register.test.sh: stock watcher, registered watcher, unregistered reject, tampered target named, bootstrap preserve, bootstrap stale→stock, register refuses stock.

Pipeline

Updates from git push no-mistakes

✅ **intent** - completed

Step completed on run that validated this head.

✅ **Rebase** - completed

Step completed on run that validated this head.

✅ **Review** - completed

Step completed on run that validated this head.

✅ **Test** - completed

Step completed on run that validated this head.

✅ **Document** - completed

Step completed on run that validated this head.

✅ **Lint** - completed

Step completed on run that validated this head.

✅ **Push** - completed

Pushed to fork derickdsouza/firstmate.

An explicit binding of the current x-watch shim bytes plus exec-target identity lets a harbor-style wrapper stay armed across bootstrap, while homes without a registration keep the stock byte-static path.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant