git: object model, packfiles, clone and push over https #16
Open
nonos-sync
wants to merge 24 commits from
nonos-sync/gh-435 into main
AGit
pull from: nonos-sync/gh-435
merge into: NON-OS:main
NON-OS:main
NON-OS:ci/dark-features
NON-OS:crypto/out-of-ring-zero
NON-OS:attest/ak-public
NON-OS:syscall/reachability
NON-OS:asm/entry-surface
NON-OS:vault/keyring-wallet
NON-OS:drivers/conformance
NON-OS:attest/receipt
NON-OS:fs/blockfs-dirs
NON-OS:process/inbox-names
NON-OS:smp/bring-up
NON-OS:feat/files-backend
NON-OS:shell-backoff-and-ipc-bench
NON-OS:desktop-ui-and-measurement
NON-OS:release/trust-reuse
NON-OS:feat/about-redesign
NON-OS:fix/release-gates
NON-OS:tools/guided-build
NON-OS:feat/terminal-rail-and-blocks
NON-OS:feat/proof-carrying-installer
NON-OS:release/inherit-secrets
NON-OS:release/attestation-surface
NON-OS:build/self-verifying
NON-OS:crown/net-desktop
NON-OS:stark/mount-unified
NON-OS:attest/export-and-dev-roots
NON-OS:stark/subgroup-closed-form
NON-OS:feat/nonos-docs-document-core
NON-OS:feat/calculator-restyle
NON-OS:feat/snake-arcade
NON-OS:arch/iommu-smp-gpu
NON-OS:consolidate/all-to-main
NON-OS:integration/production
NON-OS:feat/launchpad-restyle
NON-OS:feat/process-manager-restyle
NON-OS:feat/settings-restyle
NON-OS:caps/service-gate-binding
NON-OS:feat/paint-primitive-layer
NON-OS:feat/video-player-mvp
NON-OS:feat/display-fidelity-w2
NON-OS:abi/syscall-contract
NON-OS:libc/drop-retired-graphics
NON-OS:sdk/declared-capabilities
NON-OS:tls/certificate-basic-constraints
NON-OS:feat/display-fidelity-w1-desktop-aa
NON-OS:browser-engine
NON-OS:dependabot/cargo/bitflags-2.13.0
NON-OS:dependabot/cargo/ed25519-dalek-3.0.0
NON-OS:fix/third-party-app-launch-unblock
NON-OS:dependabot/github_actions/softprops/action-gh-release-3.0.2
NON-OS:nym-bring-up
NON-OS:git-in-terminal
NON-OS:aarch64-capsule-boot
NON-OS:dependabot/github_actions/actions/upload-artifact-7.0.1
NON-OS:dependabot/github_actions/actions/download-artifact-8.0.1
NON-OS:aarch64-bringup
NON-OS:Launchpad-Boot-Fixes
NON-OS:feat/hda-audio-playback
NON-OS:dependabot/github_actions/actions/checkout-7.0.1
NON-OS:security/trusted-path-audit
NON-OS:ci-benchmark-disk
NON-OS:send-live-fees
NON-OS:shell-launch-toast
NON-OS:fix-multiwindow-drain
NON-OS:iwlwifi-gen3-prph-scratch
NON-OS:wallet-qr-receive
NON-OS:browser-layout-fixes
NON-OS:terminal-builtins-driver-probe
NON-OS:browser-image-keepalive-fix
NON-OS:stark-parallel-prover
NON-OS:std-pal-unmodified-tokio
NON-OS:stark-parallel-periodic-commit
NON-OS:feat/nox-pull-http-transfer
NON-OS:lean-verification
NON-OS:stark-recursion-assembly
NON-OS:stark-preprocessed-periodic
NON-OS:feat/wallet-nonos-design-reskin
NON-OS:stark-enrollment-tool
NON-OS:quickjs-browser-engine
NON-OS:dependabot/github_actions/actions/attest-build-provenance-4.1.1
NON-OS:wifi-stack-and-browser-engine
NON-OS:dependabot/cargo/smallvec-1.15.2
NON-OS:stark-shared-crate
NON-OS:stark-recursion-prod
NON-OS:lean-stark-attestation-proofs
NON-OS:feat/wifi-core
NON-OS:feat/image-viewer-capsule
NON-OS:wifi-mlme-supplicant
NON-OS:pr-device-bringup
NON-OS:iwlwifi-mlme-frames
NON-OS:mechanism-code-binding
NON-OS:Lean-Kernel-Proofs-To-Main
NON-OS:sync-primitives-proofs
NON-OS:dependabot/cargo/volatile-0.6.1
NON-OS:dependabot/cargo/halo2curves-0.10.0
NON-OS:repo-hardening
NON-OS:fix/installer-endpoint-collision
NON-OS:fix/installer-spawnbroker-cap
NON-OS:hardening/desktop-graphics
NON-OS:hardening/verification
NON-OS:hardening/apps
NON-OS:hardening/drivers-net
NON-OS:stark-poseidon-recursion
NON-OS:stark-money-grade
NON-OS:feat/terminal-shell-core
NON-OS:stark-lean-degree-bound
NON-OS:Stark-Kernel-Gate
NON-OS:Contributing-ZK-Refresh
NON-OS:Stark-300-Port
NON-OS:Stark-Land
NON-OS:Lean-Evidence
NON-OS:readme-proven-section
NON-OS:Stark-Per-Layer
NON-OS:Lean-Expand-To-Main
NON-OS:Stark-Wiring-Fuzz
NON-OS:Extraction-Regen
NON-OS:Lean-Spec-Coverage
NON-OS:Stark-Whole-Proof
NON-OS:Extraction-To-Main
NON-OS:Lean-Proofs
NON-OS:Stark-Monolith
NON-OS:Lean-Proofs-Expand
NON-OS:Stark-Recursive-Verifier-v2
NON-OS:Stark-Wired-Multi
NON-OS:Stark-Lookup
NON-OS:Stark-Fused
NON-OS:Stark-Multi-Trace-Api
NON-OS:Stark-Fri-Query
NON-OS:verify-proof-gates-main
NON-OS:Stark-Recursive-Verifier
NON-OS:Stark-Poseidon-Fri
NON-OS:Stark-Air-Sponge
NON-OS:Stark-Fri-Fold
NON-OS:revert-270-verification-foundation
NON-OS:Stark-Deep
NON-OS:Stark-Air-Poseidon
NON-OS:ci-verify-main
NON-OS:Fs-Hardening
NON-OS:Deps-Crossbeam-Advisory
NON-OS:verification-foundation
NON-OS:Stark-Fri-Proofs
NON-OS:Extraction-Proofs
NON-OS:Virtio-Net-Proofs
NON-OS:Stark-Proofs
NON-OS:Crypto-Proofs
NON-OS:Kernel-Isolation-Proofs
NON-OS:fix/crossbeam-advisory
NON-OS:Rtl8139-Proofs
NON-OS:Usb-Msc-Proofs
NON-OS:browser-render-fixes
NON-OS:Kernel-Proofs
NON-OS:Xhci-Proofs
NON-OS:E1000-Proofs
NON-OS:Verification-Docs
NON-OS:feat/clock-app
NON-OS:Virtio-Blk-Proofs
NON-OS:Nvme-Proofs
NON-OS:Usb-Proofs
NON-OS:Driver-Proofs
NON-OS:Net-Proofs
NON-OS:Boot-Proofs
NON-OS:browser-full-render
NON-OS:feat/ntp-time-sync
NON-OS:fix/prod-readiness-p0-p1
NON-OS:browser-ui-hardening
NON-OS:kernel-release-attestation
NON-OS:browser-network-hardening
NON-OS:network-browser-hardening
NON-OS:kernel-hardening
NON-OS:feat/netsurf-relibc-fork
NON-OS:ci/benchmark-artifacts
NON-OS:feat/net-core-smoltcp
NON-OS:feat/capsule-browser
NON-OS:bootloader-menu-policy
NON-OS:bootloader-anti-rollback
NON-OS:bootloader-tpm-status
NON-OS:bootloader-tpm-counter
NON-OS:bootloader-hardening
NON-OS:chore/bump-nonos-sign-v2
NON-OS:fix/wallet-tls-live-handshake
NON-OS:integrate/wallet-tls-into-main
NON-OS:feat/terminal-restyle
NON-OS:dev-enroll-bootstrap
NON-OS:bootloader-nonos
NON-OS:feat/terminal-tabs-and-blocks
NON-OS:feat/terminal-prod-readiness
NON-OS:feat/terminal-vt100
NON-OS:nonos-hardening
NON-OS:nonos/surface-vblank-phase-grid
NON-OS:nonos/syscall-bound-user-lengths
NON-OS:fix/preempt-transport-lock-deadlock
NON-OS:nonos/syscall-sleep-ms-getcwd
NON-OS:fix/net-dhcp-dns-crypto-cap
NON-OS:nonos/smp-apic-x2apic-ipi
NON-OS:nonos/input-key-release-target
NON-OS:nonos/mm-fault-budget-heap-guard
NON-OS:nonos/sched-percpu-correctness
NON-OS:perf/desktop-drop-demo-embeds
NON-OS:feat/net-control-op-auth
NON-OS:feat/net-security-wave1
NON-OS:feat/tcp-reliability-core
NON-OS:fix/net-l2-arp-eviction
NON-OS:fix/net-ip-reject-fragments
NON-OS:nonos/crypto-aead-wallet-tls
NON-OS:fix/virtio-net-rx-refill
NON-OS:fix/tcp-ack-acceptability
NON-OS:fix/net-l2-learns-ip
NON-OS:fix/microkernel-syscall-union-merge
NON-OS:nonos/kernel-thread-spawn
NON-OS:feat/dock-hover-reveal
NON-OS:nonos/std-platform-layer-complete
NON-OS:feat/tcp-rfc793-p0-p1
NON-OS:nonos/docs
NON-OS:nonos/desktop-shell
NON-OS:nonos/wallet
NON-OS:nonos/proof-capsules-v2
NON-OS:nonos/proof-capsules
NON-OS:nonos/std-library-expansion
NON-OS:nonos/kernel-process-args
NON-OS:nonos/std-platform-layer
NON-OS:feat/snake-game
NON-OS:nonos/runtime-stack
NON-OS:ek_gpu_scanout_clamp
NON-OS:ek_qemu_widescreen
NON-OS:ek_terminal_shell
NON-OS:feat/alive-system
NON-OS:ek_zk_production_enforce
NON-OS:feat/vfs-real-work-loop
NON-OS:fix/capsule-integrity-fixes
NON-OS:feat/boot-experience-splash
NON-OS:fix/keyboard-hvf-ps2
NON-OS:input-probe-harness
NON-OS:ek_boot_and_capsules_init/spawn
No reviewers
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
NON-OS/nonos-micro-kernel!16
Loading…
Reference in a new issue
No description provided.
Delete branch "nonos-sync/gh-435"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Git in the NONOS terminal, from the object model up to
cloneandpushover HTTPS. The protocol layers are checked against real git rather than against themselves, and the paths that read remote bytes have been through a hardening pass. What has not happened is a run on a booted image, so this stays open until it has.What is here
The object model,
no_std, written from scratch:<type> <size>\0<content>framing objects are named byHEADand the branch filesDIRCversion 2 indexPackfiles, read, written, and stored as packs. The reader resolves offset and reference deltas. The writer emits whole objects with a SHA-1 trailer. A fetched pack is kept whole with a version 2 index beside it, the way git does it, and the object store reads through that index: the first byte of an id picks a range out of the fanout, a binary search covers only that range, then the entry is inflated at its offset and its delta chain followed.
The wire protocol. pkt-line framing both ways, the ref advertisement, the want, deepen and done body, and the receive-pack command list.
Clone and push, over a
Transportthe crate does not implement.Three crates the transport needed, none of which existed:
nonos_httpnonos_socketnet.sockets, aTcpStreamthat closes on dropnonos_tlsIn the terminal:
git init,clone,add,status,commit -m,log,push,remote.How it is checked
Nothing is graded by its own assertions where real git could grade it instead.
A repository built by this crate alone, with git never invoked to create any part of it, is then handed to git:
There is also a repository whose objects exist only inside a pack and an index this wrote. Git then resolves them:
verify-packaccepts the index,cat-filereturns the right type and bytes,fsck --strictis clean. Those answers have nowhere else to come from.The pack reader was run against 3980 objects from rust-lang/log, 2222 of them deltas, every recomputed id matching git's
verify-packlisting. Swapping one id made the test fail, so the pass is not vacuous.Clone runs end to end on bytes github.com actually sent. Push runs against real git, driven through
--advertise-refsand--stateless-rpc, which is what smart HTTP is a shell around. Chunked decoding is checked against a raw TLS payload captured withopenssl s_clientrather than through a client that would have decoded it first.On a real depth-1 pack of this kernel, 33 MB and 18,264 objects: every id and offset matches git's own listing, object by object. A clone of it writes 17,456 files rather than 35,718, because the pack is stored rather than exploded. Peak memory is 157 MB, dominated by a single 33.8 MB object inside the pack rather than by how many objects there are.
95 tests.
no_stdbuilds,clippy -D warningsclean.Bugs this found
Every one came from handing the result to git, or from asking what a hostile server could do, rather than from grading our own work.
Correctness:
capabilities^{}entry that names no object. It was read as a branch, so a first push to a fresh remote took garbage as the ref's current value..git/shallow, the parents a depth-1 fetch never sent are reported as broken links andfsckfails..gitignoreexcludes*.bin, so the recorded fixtures were never committed. CI on a clean checkout would have failed.Security, from two hardening passes:
PackError::Checksumexisted and nothing could produce it, so a pack altered in transit was parsed anyway.Vec::with_capacity, so a delta claiming four gigabytes allocated four gigabytes to produce nothing. Its varint also had no bound on the shift./..wrote beside the working directory rather than inside it.And two in
capsule_terminal, which was notclippy -D warningsclean and had not been, fourteen findings, none from this work:JobEnvsnapshots aliases andmerge_backnever restored them, so an alias defined inside a foreground job was silently lost.pid,ipand args through every call by hand.What is not done
This has never run on a booted image. Every layer is proven separately and the whole thing compiles for the real target, but the first live run is still ahead. That is why this is open rather than ready.
No credentials. A push to a private repository gets 401, and the failure says so.
No
fetchorpullcommand. The machinery is built and tested in the library, but nothing in the terminal reaches it, so an existing clone cannot be updated.Memory still scales with the largest object in a pack, since reconstructing one means holding it. That is inherent rather than a leak, but it is the ceiling on what will clone.
Notes for review
Reading order is
sha1andobject, thenzlib,treeandcommit, thenodb,refs,indexandrepo, thenpack,wireandremote. The interop test is the one to read first if you only read one thing.Parsers refuse what git would not have written. A tree entry named
..or holding a slash is rejected, and so is an index path that is absolute, because both become paths on checkout. An object read from a pack is framed and hashed before it is returned, so the index claiming an offset holds an id is checked rather than believed. A commit writes its object before moving the ref, so a failure leaves an unreferenced object rather than a branch naming one that is not there.A response body is sized from its headers, never from how much arrived. A truncated pack reaching the pack reader would look like repository corruption rather than a network fault.
The TLS session refuses to send if the chain does not verify. Handing the payload to whoever answered is the failure that matters here.
The wallet's TLS copy was deliberately left alone. It is not drift, it is a different trust policy: it pins one anchor where the shared crate carries a root store. Widening it to remove a duplicate would be a security regression.
Also here: the keyboard third level. Scancode
0x56, the ISO key between left shift and Z, fell in a range the set 1 table returnedNonefor, so<and>were unreachable on IT, DE, FR and ES, and USB had the same hole at usage0x64. There was no AltGr level at all, so braces and brackets could not be typed. Right alt now carries its own modifier instead of doubling as alt. Nine tests across five layouts, each expectation taken from what the physical key prints.Opened on GitHub by eKisNonos as pull request 435. Review and merge happen there while this repository is kept in step from GitHub; this copy follows it, and is marked merged or closed when it is.
View command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.