Load checked installations independently of the running compiler (WI-16)

Keep compiler-dependent checks in Nix builds; load stored plans and programs with original provenance and runtime artifact validation. Allow an identical executable world to receive a new activation epoch after a toolchain rebuild.

Compiler-update/altered-program regression, coordinator and full sandboxed integration checks pass; lint and formatting pass. Default platform/source wiring remains the next task.
This commit is contained in:
Timothy J. Aveni
2026-09-21 21:49:52 -07:00
parent daa20ca79f
commit 0d7d5daea6
+9 -5
View File
@@ -43,16 +43,20 @@ workspace authentication and explicit file registry; it never interprets an HTTP
path as a Nix store path. Applications cannot import Replicache through the SDK. path as a Nix store path. Applications cannot import Replicache through the SDK.
`checked-artifacts.nix` evaluates a package's `checkedArtifacts` output without `checked-artifacts.nix` evaluates a package's `checkedArtifacts` output without
activation. `loadCheckedArtifactWorld` then verifies manifest bytes, the trusted activation. During the checked Nix build, `loadCheckedArtifactWorld` verifies manifest bytes, the selected
generator identity, and exact regenerated binding sources. Receipts are consistency generator identity, and exact regenerated binding sources. Receipts are consistency
evidence from a trusted Nix build, not cryptographic attestations of remote builds. evidence from a trusted Nix build, not cryptographic attestations of remote builds.
The separate manifest-only loader is useful for candidate diagnostics; activation The build stores the checked plan, kernel/query programs, their digests and original
must use the checked loader. compiler provenance in its immutable candidate output. Runtime loading validates
that output's identities, artifact contents and supported runtime contracts. It
does not regenerate bindings or programs with the currently running compiler.
Nix owns rebuilding and cache reuse when a toolchain input changes.
The root `camino-artifact-builds` check exercises actual reader/service outputs, The root `camino-artifact-builds` check exercises actual reader/service outputs,
module and process execution, browser shared imports, rejection recovery, and module and process execution, browser shared imports, rejection recovery, and
altered receipt rejection. The managed workspace host verifies these receipts altered receipt rejection at the build boundary. The managed workspace host loads
before activation. No adapter pretends this ABI works in the old server dispatcher. the resulting checked candidate before activation. No adapter pretends this ABI
works in the old server dispatcher.
Component packages add `components = { inherit (react) sdk runtime; entries; }`. Component packages add `components = { inherit (react) sdk runtime; entries; }`.
The ordinary execution candidate checker supplies the selected React build inputs The ordinary execution candidate checker supplies the selected React build inputs