feat: implement v0.6.0 mutation engine and db_type runtime selection
Rust / build (push) Canceled after 0s
Rust / build (push) Canceled after 0s
This commit is contained in:
1 parent
217dc5f92b
commit
ba768da58e
27 files changed
+2615
-158
No files matched your search
@@ -32,6 +32,9 @@ ChronoSeal establishes a continuous cryptographic proof-of-runtime continuity us
|
||||
|
||||
while remaining completely invisible and frictionless to legitimate human users.
|
||||
|
||||
v0.6.0 adds a deterministic synthetic gene mutation chain (hybrid `Vec<u8>` gene + bounded environment records) to strengthen anti-replay continuity with server/WASM parity.
|
||||
See [docs/REFRACTORING-v0.6.0.md](docs/REFRACTORING-v0.6.0.md) for the full refactoring details.
|
||||
|
||||
---
|
||||
|
||||
# Features
|
||||
@@ -47,8 +50,11 @@ while remaining completely invisible and frictionless to legitimate human users.
|
||||
* Ed25519 + Blake3 cryptographic chaining
|
||||
* Behavioral entropy validation
|
||||
* Randomized stack-machine verification
|
||||
* Deterministic synthetic gene mutation chain
|
||||
* Server/WASM mutation parity checks
|
||||
* Silent rejection model
|
||||
* SQLite-backed ephemeral sessions
|
||||
* Configurable runtime DB backend selection (`db_type`)
|
||||
* Connection-pooled runtime architecture
|
||||
* Lightweight deployment footprint
|
||||
* Docker and native deployment support
|
||||
@@ -104,6 +110,7 @@ chronoseal --help
|
||||
| `health` | Perform daemon health probe |
|
||||
| `config` | Validate and print effective configuration |
|
||||
| `generate` | Generate operational material |
|
||||
| `db-type` | List database backend support status |
|
||||
| `metrics` | Output Prometheus metrics |
|
||||
| `stats` | Print runtime statistics |
|
||||
| `completion` | Generate shell completions |
|
||||
@@ -144,18 +151,24 @@ Browser Server
|
||||
│ Private key never leaves WASM memory │
|
||||
│ │
|
||||
├──── POST /init { public_key } ──────────►│
|
||||
│◄─── { session_id, salt, opcodes, H0 } ────┤
|
||||
│◄─── { session_id, salt, opcodes_b64, H0, │
|
||||
│ mutation_step, mutation_order_b64 } ──┤
|
||||
│ │
|
||||
│ Every 12–25s (randomized): │
|
||||
│ ┌─ Collect behavioral entropy │
|
||||
│ ├─ Execute VM opcode program │
|
||||
│ ├─ Execute verification VM opcodes │
|
||||
│ ├─ Preview mutation commitment │
|
||||
│ ├─ Attach mutation_step + commitment │
|
||||
│ ├─ Advance Blake3 hash chain │
|
||||
│ └─ Sign payload using Ed25519 │
|
||||
│ │
|
||||
├──── POST /heartbeat { signed_payload } ─►│
|
||||
│◄─── { status, next_salt } ────────────────┤
|
||||
├──── POST /hb { signed_payload } ────────►│
|
||||
│◄─── { status, next_salt, │
|
||||
│ next_mutation_step, │
|
||||
│ next_mutation_order_b64 } ────────────┤
|
||||
│ │
|
||||
│ Invalid sessions silently rejected │
|
||||
│ (`status=ok` without next_* fields) │
|
||||
```
|
||||
|
||||
The server validates:
|
||||
@@ -163,6 +176,8 @@ The server validates:
|
||||
* signature authenticity
|
||||
* heartbeat continuity
|
||||
* replay resistance
|
||||
* mutation step parity
|
||||
* mutation commitment parity
|
||||
* behavioral entropy
|
||||
* timestamp validity
|
||||
* fingerprint sanity
|
||||
@@ -229,10 +244,10 @@ The goal is to make automation:
|
||||
|
||||
```text
|
||||
chronoseal-rs/
|
||||
├── shared/ Shared types, constants, hash-chain logic
|
||||
├── shared/ Shared types, hash chain, gene + mutation engine
|
||||
├── server/ Axum HTTP daemon
|
||||
│ ├── routes/ API routes
|
||||
│ ├── session.rs Session lifecycle management
|
||||
│ ├── session.rs Session lifecycle + mutation parity checks
|
||||
│ ├── crypto.rs Ed25519 verification
|
||||
│ ├── trust.rs Behavioral validation
|
||||
│ ├── fingerprint/ Browser sanity validation
|
||||
@@ -242,7 +257,8 @@ chronoseal-rs/
|
||||
│ └── metrics.rs Prometheus metrics
|
||||
├── wasm/ Rust → WASM runtime
|
||||
│ ├── crypto.rs Signing + hash chaining
|
||||
│ └── vm.rs Stack-machine executor
|
||||
│ ├── vm.rs Stack-machine executor
|
||||
│ └── vm_extensions.rs Gene mutation preview/commit
|
||||
├── frontend/ Lightweight JS integration
|
||||
├── scripts/ Build/install/dev scripts
|
||||
└── docs/ Project documentation
|
||||
@@ -275,6 +291,21 @@ This makes heartbeat payloads structurally dynamic.
|
||||
| `0x08` | NOT | Unary inversion |
|
||||
| `0x09` | HASH | Blake3 stack hash |
|
||||
|
||||
## Mutation Opcodes (v0.6.0)
|
||||
|
||||
| Opcode | Mnemonic | Effect |
|
||||
| ------ | -------------------- | ------ |
|
||||
| `0x23` | GENE_LOAD | Push `gene[idx]` |
|
||||
| `0x24` | GENE_STORE | Pop and store at `gene[idx]` |
|
||||
| `0x25` | MUTATE_POINT | Apply wrapping byte delta at index |
|
||||
| `0x26` | INSERT | Insert popped byte at index |
|
||||
| `0x27` | DELETE | Delete byte at index and push removed value |
|
||||
| `0x28` | TRANSCRIBE | Push deterministic transcription hash |
|
||||
| `0x29` | APPLY_MUTAGEN | Mix environment symbol quantity into gene byte |
|
||||
| `0x2A` | FINALIZE_GENE_HASH | Push commitment-derived `u32` |
|
||||
| `0x2B` | CONSUME | Pop amount, subtract environment quantity |
|
||||
| `0x2C` | PRODUCE | Pop amount, add environment quantity |
|
||||
|
||||
---
|
||||
|
||||
# Hash Chain
|
||||
@@ -330,14 +361,18 @@ This prevents:
|
||||
|
||||
```sql
|
||||
CREATE TABLE IF NOT EXISTS sessions (
|
||||
session_id TEXT PRIMARY KEY,
|
||||
public_key BLOB NOT NULL,
|
||||
salt BLOB NOT NULL,
|
||||
last_hash BLOB NOT NULL,
|
||||
chain_length INTEGER NOT NULL DEFAULT 1,
|
||||
created_at INTEGER NOT NULL,
|
||||
last_seen INTEGER NOT NULL,
|
||||
expires_at INTEGER NOT NULL
|
||||
session_id TEXT PRIMARY KEY,
|
||||
public_key BLOB NOT NULL,
|
||||
salt BLOB NOT NULL,
|
||||
last_hash BLOB NOT NULL,
|
||||
chain_length INTEGER NOT NULL DEFAULT 1,
|
||||
created_at INTEGER NOT NULL,
|
||||
last_seen INTEGER NOT NULL,
|
||||
expires_at INTEGER NOT NULL,
|
||||
gene BLOB NOT NULL DEFAULT X'',
|
||||
environment BLOB NOT NULL DEFAULT X'',
|
||||
pending_mutation BLOB NOT NULL DEFAULT X'',
|
||||
pending_mutation_step INTEGER NOT NULL DEFAULT 0
|
||||
);
|
||||
```
|
||||
|
||||
@@ -354,7 +389,8 @@ Session continuity is designed to reset transparently.
|
||||
* Rust
|
||||
* Axum
|
||||
* Tokio
|
||||
* SQLite
|
||||
* SQLite (`sqlite-in-memory` / `sqlite-in-disk`)
|
||||
* `db_type=valkey` compatibility mode (falls back to in-memory in v0.6.0)
|
||||
* `r2d2`
|
||||
* `thiserror`
|
||||
|
||||
@@ -464,6 +500,20 @@ $XDG_CONFIG_HOME/chronoseal/config.toml
|
||||
~/.local/state/chronoseal/
|
||||
```
|
||||
|
||||
## Database Backend Selection (v0.6.0)
|
||||
|
||||
Choose backend with config, env var, or CLI flag:
|
||||
|
||||
* Config: `db_type = "sqlite-in-memory" | "sqlite-in-disk" | "valkey"`
|
||||
* Env: `CHRONOSEAL_DB_TYPE=...`
|
||||
* CLI: `chronoseal run --db-type sqlite-in-disk --db-path /var/lib/chronoseal/chronoseal.sqlite`
|
||||
|
||||
Inspect backend status:
|
||||
|
||||
```bash
|
||||
chronoseal db-type --format text
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Observability
|
||||
|
||||
Reference in new issue
Block a user