redirector: commit stamp + shared build-identity verifier that REFUSES

The binary records only the commit it was built from -- no dirty-tree flag.
Cargo will not re-run a build script because another crate's source changed, so
a compiled-in 'clean' claim can be stale and is not a safeguard; that was
verified on the Blaze host.

scripts/verify-build-identity.sh establishes both facts at LAUNCH, where they
cannot go stale: the stamped commit equals HEAD, and the migration crates are
clean. It REFUSES rather than warns, because for a migration gate a warning on
stderr is something to scroll past.

--identity prints the stamp without valid configuration. The launcher must be
able to establish which commit a binary came from BEFORE deciding whether to
run it; requiring a correct environment first would invert the check.

redirector.sh mirrors sidecar.sh: refuses to start with an orphan present or
the port busy, matches the resolved executable rather than the command line
(pgrep -f matches any shell mentioning the name), and stop PROVES the process
is gone and the port free.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
funman300
2026-08-11 03:46:07 +00:00
parent 89f77470f3
commit c03702707b
5 changed files with 249 additions and 10 deletions
+9
View File
@@ -3,6 +3,15 @@
use openfut_redirector_host::{serve, RedirectorConfig};
fn main() {
// Identity must be readable WITHOUT valid configuration: the launcher has
// to verify which commit a binary came from before deciding whether to run
// it at all, and refusing to reveal that until the environment is right
// would invert the check.
if std::env::args().any(|a| a == "--identity") {
println!("{}", openfut_redirector_host::identity());
return;
}
let cfg = match RedirectorConfig::from_env() {
Ok(c) => c,
Err(e) => {