feat(rawsync): add hosted raw custody core - #1396
Merged
Merged
Conversation
salmonumbrella
force-pushed
the
feat/hosted-raw-custody-core
branch
from
August 13, 2026 21:39
c4f7465 to
4ea6428
Compare
3 of 7 tasks
roborev: Combined Review (
|
Member
|
looking at this |
roborev: Combined Review (
|
Member
|
looking |
- fix(rawsync): key raw custody indexes by fixed-size digests - fix(rawsync): reject noncanonical manifest structs during validation
wesm
force-pushed
the
feat/hosted-raw-custody-core
branch
from
August 18, 2026 16:33
66863c0 to
4b0d043
Compare
roborev: Combined Review (
|
…oles Reject unknown and RemoteSyncExcluded providers in manifest validation and require a validated provider on object uploads and missing-object checks, so excluded stores never reach custody. Skip raw custody DDL on the schema-current pg push fast path when the role lacks CREATE (SQLSTATE 42501) instead of failing the push.
roborev: Combined Review (
|
An object longer than MaxFileBytes can never be referenced by an accepted manifest, so uploads and missing-object negotiation now reject it before custody instead of retaining an orphan.
roborev: Combined Review (
|
wesm
pushed a commit
that referenced
this pull request
Aug 20, 2026
Adds the server-side device authentication boundary for hosted raw custody. Devices enroll once and keep a random credential; PostgreSQL stores only its SHA-256 digest. Active devices exchange that credential for short-lived opaque tokens scoped to negotiation, upload, commit, and status. Authentication derives tenant and device identity from server-side records, and revocation invalidates outstanding tokens. This remains an internal foundation. #1459 does not add HTTP enrollment or upload routes, the laptop uploader, server parsing, or server embeddings, so the authenticated raw transport item in #1352 remains incomplete. The Zensical guide now documents the completed raw custody foundation from #1396, this authentication boundary, their security guarantees, the current delivery status, and the unchanged `pg push` workflow. Co-authored-by: Rusty Shackleford <salmonumbrella@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the storage layer for raw-first hosted sync (#1352): the server keeps the
original agent session files, not just the parsed rows. With the source files
on hand, the server can re-parse after a parser fix or rebuild lost data.
Nothing calls this yet. There is no upload API, no server-side parsing, and no
change to local sync or
pg push. Those come in later PRs.How it works
A client uploads content-addressed objects, then a manifest that lists one
source (for example one Codex session file), its files, and the SHA-256 and
length of every piece.
internal/rawsync/manifest.govalidates the manifest and produces onecanonical JSON document. Its SHA-256 is the manifest ID. Tenant and device
IDs are embedded, so it cannot be replayed under another identity. Unknown
providers and
RemoteSyncExcludedproviders (Omnigent, Trae) are rejected.internal/rawsync/object_store*.gostores objects and manifests immutablyin the existing artifact store under a per-tenant prefix. Same content
again is a no-op; different content under the same digest is a conflict.
internal/postgres/raw_ingest_*.gorecords verified objects, acceptedmanifests, each source's current head, and a parse job per manifest, all in
one transaction. Same capture ID returns the same receipt. A manifest must
name the current head as its parent (compare-and-swap), and every object it
references must already be verified. Accepted rows are append-only.
internal/rawsync/service.gois the single entry point for later uploadhandlers. It rejects excluded providers and oversized objects before
accepting bytes.
Notes for reviewers
text (see
rawIngestDDL).pg pushfast path, a role withoutCREATEskipsthe raw custody DDL with a log line instead of failing the push.
internal/postgres/raw_ingest_custody_pgtest_test.go.Refs #1352