Require runtime marker before receipt protection

Co-authored-by: npub1jh9wn95s0472h86ahapupaf7m6kx4v9sx2n0atj2hltcfer8k06s5n3pyf <95cae996907d7cab9f5dbf43c0f53edeac6ab0b032a6feae4abfd784e467b3f5@sprout-oss.stage.blox.sqprod.co>
Signed-off-by: npub1jh9wn95s0472h86ahapupaf7m6kx4v9sx2n0atj2hltcfer8k06s5n3pyf <95cae996907d7cab9f5dbf43c0f53edeac6ab0b032a6feae4abfd784e467b3f5@sprout-oss.stage.blox.sqprod.co>

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
This commit is contained in:
npub1jh9wn95s0472h86ahapupaf7m6kx4v9sx2n0atj2hltcfer8k06s5n3pyf
2026-07-19 11:01:39 -04:00
co-authored by Tyler Longwell
parent 671ed6f424
commit 0a1f5dd46a
2 changed files with 8 additions and 4 deletions
@@ -129,7 +129,11 @@ pub async fn restore_managed_agents_on_launch(
(canonical == receipt.key
&& receipt.desktop_instance_id == super::current_instance_id(app)
&& super::process_is_running(receipt.pid)
&& super::process_belongs_to_us(receipt.pid))
&& super::process_belongs_to_us(receipt.pid)
&& super::process_has_buzz_marker(
receipt.pid,
&receipt.desktop_instance_id,
))
.then_some(receipt.pid)
}),
)
@@ -169,7 +169,7 @@ fn buzz_marker_entry(instance_id: &str) -> Vec<u8> {
/// is this desktop instance's id. A process stamped with a *different* instance
/// id belongs to another live Buzz app and must never be reaped here.
#[cfg(target_os = "macos")]
fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
pub(crate) fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
let marker = buzz_marker_entry(instance_id);
let Some(buf) = sweep::procargs2_buffer(pid) else {
return false;
@@ -213,7 +213,7 @@ fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
}
#[cfg(all(unix, not(target_os = "macos")))]
fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
pub(crate) fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
let marker = buzz_marker_entry(instance_id);
let Ok(data) = std::fs::read(format!("/proc/{pid}/environ")) else {
return false;
@@ -222,7 +222,7 @@ fn process_has_buzz_marker(pid: u32, instance_id: &str) -> bool {
}
#[cfg(not(unix))]
fn process_has_buzz_marker(_pid: u32, _instance_id: &str) -> bool {
pub(crate) fn process_has_buzz_marker(_pid: u32, _instance_id: &str) -> bool {
false
}