Private hosted principal package discovery by joshuajbouw · Pull Request #1820 · astrid-runtime/astrid · GitHub
Skip to content

Private hosted principal package discovery - #1820

Draft
joshuajbouw wants to merge 1 commit into
os/universalfrom
codex/hosted-package-read-1802
Draft

Private hosted principal package discovery#1820
joshuajbouw wants to merge 1 commit into
os/universalfrom
codex/hosted-package-read-1802

Conversation

@joshuajbouw

@joshuajbouw joshuajbouw commented Sep 1, 2026

Copy link
Copy Markdown
Member

Linked Issue

Tracking #1802.

Summary

Adds private hosted, principal-owned package read/discovery against the package-service model landed by #1800.

This candidate is limited to authenticated inventory discovery. It does not add package writes, activation, publication, public WIT/API, Station authority, or native process-storage composition. Review is intentionally deferred while the OS campaign is drained.

Changes

  • Derives hosted package visibility from authenticated principal identity.
  • Adds private package inventory and principal-introspection paths.
  • Rejects path, config, hint, and raw owner bytes as identity sources.

Verification

  • The commit is signed and the branch is based on the landed package-service trunk.
  • Required CI and independent review are incomplete.
  • No merge or release claim is made.

AI / Tool Assistance

Assisted-by: Codex:GLM-5.3 Flash

AI assistance was used for implementation and tests. The maintainer owns the authority boundary and public PR description.

Checklist

  • Tracking issue identified
  • Claim boundary documented
  • Required CI complete
  • Independent review complete
  • Ready to merge

Bind private package reads to the authenticated admitted principal UID, verify durable package summaries and exact generations, and stop deriving hosted inventory from aliases or host discovery paths.

Tracking #1802

Assisted-by: Codex

Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant