Merge nucleic/nimble-umber-toad-20h7 into dev

This commit is contained in:
2026-08-11 20:11:26 -07:00
parent 50e2b9030b
commit 05d993d83b
5 changed files with 24 additions and 24 deletions
+3 -3
View File
@@ -168,7 +168,7 @@ for, and nothing above it should move. These three are different:
| `Container` has no `Name`, `Session` has no `GetContainers()` | Sharper than "no enumeration": a container is reachable ONLY through the handle `CreateContainer` returned, so the broker keeps its own name→handle roster — which dies with the process. A restarted broker sees an empty sandbox (§13.2). |
| No create-or-attach on `Session` | `IWSLCSessionManager::OpenSessionByName` / `EnterSession` — same gate as above. Until then `session.ensure` fails `session_exists` and names `wsl --shutdown` as the remedy. |
| No gateway address anywhere on the API | **Gateway TCP stays primary.** The hvsocket alternative needed a VMID from `IWSLCVirtualMachine::GetId`, and that interface is unreachable from a client — retracted in §13.1. The address comes from `GetAdaptersAddresses` over `vEthernet (WSL)`. |
| No uid on `ProcessSettings` | Recoverable, and already planned for: exec wraps argv in `setpriv`/`su agent -c`. Interceptors and nash don't care about the numeric uid (§3.2). |
| No uid on `ProcessSettings` | Recoverable, and already planned for: exec wraps argv in `setpriv`/`su agent -c`. Interceptors and hydrashell don't care about the numeric uid (§3.2). |
---
@@ -190,7 +190,7 @@ dotnet build windows\NucleicBroker\NucleicBroker.csproj -p:UseWslc=true # the
dotnet run --project windows\spikes\WslcSpike -- --repo C:\src\nucleic
```
Options: `--image` (default `ghcr.io/abkslm/naros-agent:26.07`), `--container`, `--session-name`,
Options: `--image` (default `ghcr.io/abkslm/hydrangeaos-agent:26.07`), `--container`, `--session-name`,
`--iterations` (timing runs, default 5), `--broker <path>` if autodiscovery fails,
`--no-recovery` to skip the crash test.
@@ -213,7 +213,7 @@ It answers four open questions:
4. **Can the guest reach the host at the gateway? (M1 b)** The last thing M2 waits on. It binds a
listener on the WSL-facing address only — never `0.0.0.0`, which is the posture §5 requires —
and has the container open a TCP round trip to it. Every agent session rides this: approvals,
the git/gh interceptors, nash's shell reports. On failure it prints the `New-NetFirewallRule`
the git/gh interceptors, hydrashell's shell reports. On failure it prints the `New-NetFirewallRule`
remediation §5 step 5 calls for, and notes that the AF_HYPERV fallback needs a VM GUID that
§13.2 found no client route to — so gateway TCP is not merely preferred, it is the only path
currently available.