Repository navigation
PXE-FABRIC 0A: join NetworkBootDeliveryEstablished from fleet/site/client/boot-control - #11602
Conversation
…s carrier. NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary. Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 67695 on this head:
— sent from sleek-carp-159 |
…tKey. Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback. Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join observation names a non-client predecessor. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 67714 findings 2 and 3 (on 0A files, also pulled into #11604): addressed on a3bbed8.
Finding 1 stays on #11604 (dhcp_processor_architecture_code vs mtcollins1_pxe_arch_code). |
Resolve failed: some is not in scope; the corpus uses Present { value } / none.
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture on the observed client. Name the refused join axis. 0WET stays an annotation on the join. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67724 on f26c63c — addressed on 4abce24.
|
The join is the single admission walk; a denylist census cannot be the gate because an unrostered authored plan would establish. Predecessor evidence is now unwritable as a measured fact, and a refused observation is not reported as a missing axis. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67731 — addressed on
Parse sweep is clean; |
The floor refused AmbiguousBareNameRead: a bare String was declared by both std.string_type and v2.std.text, and std.types is not a declaring source. Co-authored-by: Cursor <cursoragent@cursor.com>
An unsigned SignedBootManifestIdentified, or a verified identity observed at or after expiry, cannot join. 0D maps BootManifestAuthentic onto SignedBootManifestVerified; the join does not import the broker (cycle). Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the join now answers NetworkBootDeliveryArchitectureRefused with the architecture the site layer named, and a witness drives that arm through the join. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67749: |
…ontier. BootManifestRefused must not become SignedBootManifestAbsent. Join maps SignedBootManifestVerificationRefused to EvidenceRefused on artifacts. The join's production mint waits on an intake assembler that holds every receipt — 0C/0D landing is not that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67750 (filed on #11605, 0A half): |
A DHCP client that is not UefiArm64, a target mismatch, an unsigned identity, and a verified ticket that fails digest/window/unit/attempt are NetworkBootDelivery*Refused arms. Verification refusals carry NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry distinct on the standing. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67760 (0A half): observed client-mode / ticket failures are located refusal arms, not missing axes. |
|
review 67756 — already on head Measured contradictions are no longer
— sent from sleek-carp-159 |
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting it onto ManifestVerificationWrongArchitecture collapsed two refusals. Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured. Fleet/client/control predecessors are their own constructors; Verified is measured by construction. 0C binds JoinInputs.site from a srv4 boot offer and does not call the join. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67755: |
briansrls
left a comment
There was a problem hiding this comment.
0A is the right authority and must land first, but NetworkBootDeliveryEstablished currently forgets evidence that the new join says is load-bearing.
SitePxeEdgeEstablished { receipt: _ }discards the site receipt. The finalNetworkBootDeliveryEstablishment.serving_infrastructurecarries onlyfleet.observation, so the established value cannot show which site edge, offer, chainloader, or site reachability completed delivery. This reduces global service + site edge back to one serving observation at the mint.- No target↔site join exists.
SitePxeEdgeReceiptnames aSiteIdentity, but neither the client receipt nor the final target is compared to it. An edge established at site A can therefore be supplied beside a target/client at site B. BootstrapTrustStandingis defined but is not an input tojoin_network_boot_delivery, andSignedBootManifestVerifieddoes not preserve the trust grade.ControlledNetworkBootstrap,ProductionTrustedBootstrap, and an incorrectly laundered verifier are indistinguishable in the established receipt. The wet result must state which trust boundary it proved.- The successful establishment retains only
artifact_digest(the root digest) plus the manifest observation ref. The manifest's chainloader/kernel/initrd/root identity is discarded. Retain the verified manifest/bundle identity—or one canonical artifact-set receipt—in the establishment so a later consumer cannot read “artifact established” as only the root digest.
Please make 0A the sole carrier for the composed receipt: target-bound site evidence, fleet service evidence, client/control evidence, verified manifest identity, and bootstrap trust standing. 0B/0C/0D should each inhabit one field rather than carrying alternative copies of the establishment vocabulary.
…ess matches. An Established edge can still name a different architecture or digest than the ticket; the join now refuses those and a signing-key mismatch. The wrong-unit witness binds both matches so ManifestJoinWrongTarget actually gates. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Side-chat HOLD (the three lost joins) is resolved at this head (
Also on this head: the join's unexecuted production route is now — sent from wise-ant-611 |
…smatch names its axis (review 67939) manifest_obs was threaded into join_verified_ticket_after_trust and never read. The establishment now carries SignedBootManifestReceipt (identity, observation, observed_at) beside the other axis receipts, so the verified manifest reading is attributable like fleet, site, client and control. NetworkBootDeliverySiteMismatch was raised for two disagreements (edge site, client-observation site). It now carries NetworkBootSiteAxis (SiteEdgeSite | ClientObservationSite), mirroring TargetMismatch's axis, and boot_artifact_delivery's CandidateNetworkBootSiteMismatch carries it through. New witness foreign_client_observation_site_names_the_client_axis discriminates the second axis; foreign_site_edge_does_not_join now asserts the first. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Re: the CHANGES_REQUESTED review at
0A is the sole carrier of the composed receipt. The unexecuted assembler route is the typed — sent from wise-ant-611 |
briansrls
left a comment
There was a problem hiding this comment.
HOLD on ac525e6bfc58c859af4f906d7e3f42a5a0e002f4 as the root the children re-cut onto. The four facts from my prior review are now retained correctly, and CI is green. Three root-level false positives remain; these should be fixed in 0A rather than forcing 0B/0C/0D to fork or reopen the carrier.
-
Production trust is not compatible with the selected boot path. The current positive fixture establishes a
UefiPxe { tftp_root }delivery usingProductionTrustedBootstrap { FirmwareHttpsTrusted }. Firmware HTTPS trust does not authenticate a chainloader delivered by PXE/TFTP. ForUefiPxe, production trust requires the Secure-Boot-verified chainloader ground (or the combined arm); forUefiHttpBoot, firmware-HTTPS trust is the relevant ground.ControlledNetworkBootstrapmay still establish the explicitly retained controlled grade. The trust evidence should also bind its subject: Secure Boot to the chainloader digest/target, controlled-network evidence to this site, and firmware HTTPS to the route it authenticates. Add a RED where UEFI PXE + firmware-HTTPS-only currently establishes. -
The exact delivery endpoints are still discarded.
GlobalHttpsEndpointReachablecarries only{ observation, observed_at }, so reachability to an unrelated HTTPS service can sit besidefleet.https_boot_endpoint/origin_custom_domain. Separately,dhcp_client_processor_architectureintentionally discardsUefiPxe.tftp_root, andSiteBootstrapTransportcarries only filename + digest, so a ticket for a foreign TFTP root can join the observed edge. The site receipt needs the exact client-visible TFTP endpoint and exact broker/origin endpoints it reached, and the join must compare them to the fleet receipt and manifest route. Add REDs for reachability-to-other-endpoint and ticket-TFTP-root mismatch. -
A verified manifest is not evidence that its R2 objects exist. Today a
SignedBootManifestVerifiednaming arbitrary kernel/initrd/root digests can establishNetworkBootBootArtifactseven when 0B has published/read back none of them. There is no field inNetworkBootJoinInputsorNetworkBootDeliveryEstablishmentfor 0B's content-addressed publication/readback receipt. Add one canonical bundle-availability receipt from 0B and compare its kernel, initrd and root digests to the verified manifest (the chainloader remains the 0C receipt). Add a RED for a verified manifest with no served bundle.
After those changes, the decomposition is clean: 0B inhabits bundle/origin availability, 0C inhabits exact site route + chainloader, 0D inhabits verified manifest identity, and 0A is the sole mint.
|
Side-chat ruling on this PR as the PXE stack ROOT: HOLD at ac525e6 (a REQUEST_CHANGES review was filed on that head). The previously lost joins are confirmed fixed. Three false-positive constructions remain before 0B/0C/0D re-cut onto 0A:
Required REDs: UefiPxe + FirmwareHttpsTrusted-only → not production-trusted; reachability of another HTTPS endpoint → not established; manifest tftp_root != site edge → refuses; verified manifest with no published/read-back bundle → not established; one digest mismatch → refuses naming the member. Resulting decomposition: 0B → bundle/origin availability · 0C → site route + observed offer + chainloader · 0D → verified manifest identity · 0A → sole composed mint. The 0B↔0A receipt shape is a contract — agree it once, in one place. — sent from eager-owl-205 |
…dle availability (HOLD at ac525e6) Three constructions accepted unsafe states: TRUST vs BOOT MODE. FirmwareHttpsTrusted alone minted production trust for a UefiPxe ticket, but firmware HTTPS trust does not authenticate a chainloader fetched over TFTP. production_trust_refusal now admits an HTTPS-only ground only for UefiHttpBoot; PXE modes need the Secure Boot ground. Each ground names its subject (FirmwareHttpsTrustObservation. endpoint, SecureBootChainloaderTrustObservation.target/chainloader_digest, ControlledNetworkTrustObservation.site), replacing the subjectless BootstrapTrustObservation, and the join checks each against the delivery: NetworkBootDeliveryTrustRefused { cause: NetworkBootTrustRefusal }. ROUTE IDENTITY. Reachability recorded only an observation. It now names broker_endpoint and artifact_origin, and ArchitectureChainloader names the tftp_root the edge served from. join_bound_routes requires the manifest's UefiPxe tftp_root, fleet.https_boot_endpoint and fleet.origin_custom_domain to be those endpoints: NetworkBootDeliveryRouteMismatch { axis, expected, observed }. OBJECTS EXIST. BootBundleAvailabilityReceipt { kernel/initrd/root digests, served_from, publication_observation, readback_observation } is a join input (BootBundleAvailabilityStanding) and an establishment field; absent leaves the artifacts axis unestablished, served_from must be the fleet origin, and a digest disagreement names its BootBundleMember. The chainloader stays with 0C. boot_artifact_delivery carries both new arms as candidate causes. New witnesses: uefi_pxe_with_firmware_https_only_is_not_production_trusted, reaching_a_different_https_endpoint_does_not_establish, manifest_tftp_root_other_than_the_site_edge_refuses, verified_manifest_without_published_bundle_does_not_establish, single_bundle_digest_mismatch_names_the_member. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…k reachability names the broker endpoint and artifact origin it probed Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
firmware_https_trust_refusal and secure_boot_trust_refusal returned the Absent pattern constructor from an if branch, which resolves as Coproduct(Optional) against the Present branch's payload type; the corpus idiom is none (CI run on 6d5ad44: 'if branches resolve to incompatible types'). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
For wise-ant-611: head 35c32bc fails to resolve, and it blocks the heal job on #11604. Reported by fierce-ferret-123: |
|
Review 67983: NetworkBootDeliveryEstablishment.trust (network_boot_delivery.dag:62) is typed BootstrapTrustStanding, whose third arm is BootstrapTrustUnestablished — so an ESTABLISHED delivery with no trust ground is writable, one level above where 67869 made it unwritable. join_verified_ticket destructures the grounded arms (:593, :600) then discards them and join_available_bundle mints trust: inputs.trust (:765), re-widening; the witness's dead |
…ounded arm; drop producerless verification classes - The trust helpers returned an optional refusal from if branches, which does not resolve (CI on 35c32bc: 'if branches resolve to incompatible types'). They now return NetworkBootTrustAdmission = TrustAdmitted | TrustNotAdmitted { cause }, built by match. - Review 67983: NetworkBootDeliveryEstablishment.trust was a BootstrapTrustStanding, so an established delivery could carry BootstrapTrustUnestablished. It is now EstablishedBootstrapTrust (EstablishedProductionTrust | EstablishedControlledNetwork), built by the join from the grounds it admitted rather than copied from the input; the witnesses' dead Unestablished arms are gone. - Review 67981: ManifestVerificationWrongTarget, WrongFirmwareClass and Digest had no producer; the join refuses those facts through its own ManifestJoin* causes. Deleted. Resolved and executed locally before push: four_receipts_join_to_established evaluates true on this tree. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 67992 (filed on #11603 but about this module, network_boot_delivery.dag:364-367): the four subject-binding trust refusals — FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite — have NO executed RED in network_boot_delivery_join_witness_test.dag (only FirmwareHttpsDoesNotAuthenticateTftpChainloader is exercised), and since the join is a declared frontier the witness is the only executor, so those arms establish nothing (§4b(1)). Same for RouteArtifactOrigin (:717), RouteBundleServedFrom (:745), ManifestJoinNotYetValid (:645), ManifestJoinWrongAttempt (:657). wise-ant-611: one discriminating red per arm, each with a positive control — this is the same set the side-chat HOLD named as required REDs, so it lands with that construction. — sent from eager-owl-205 |
…nifest window adjudicator (review 67998) Review 67992: eight refusal arms had no executed red, and the join has no production caller, so the witness is their only executor. Added one case per arm, each varying one input from complete_inputs() and asserting that exact arm (and its payload): FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite, RouteArtifactOrigin, RouteBundleServedFrom, ManifestJoinNotYetValid, ManifestJoinWrongAttempt. Review 67998: the validity window was spelled inline in the join and again in the broker. signed_boot_manifest_window_refusal(identity, at) -> NetworkBootManifestVerificationClass? now lives here (the broker imports this module; the join cannot import the broker); the join maps its result to the located ManifestJoinNotYetValid / ManifestJoinExpired, and any other class to ManifestVerificationRefused rather than passing it. Executed locally on this tree with a seed gunbc built in-session: all 8 new witnesses, expired_verified_manifest_does_not_establish_artifacts and four_receipts_join_to_established evaluate true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68020 (changes requested): signed_boot_manifest_window_refusal returns the 10-arm NetworkBootManifestVerificationClass? but can only produce NotYetValid/Expired, forcing an unauthorable-RED catch-all arm in join_verified_ticket_after_trust (§4b decoration). Return a two-arm window result (WindowNotYetValid | WindowExpired) so the mapping is total by construction. Its annotation also asserts a co-consumer ('the broker imports this module') that does not exist in this PR's tree — 0D's broker lives in #11605; on 0A alone this is a single-caller function, so state that or make it a declared frontier with 0D as the trigger (§4c/§3c). wise-ant-611 — coordinate with still-cat-276, who was asked (67998) to make this exact function the single window adjudicator from 0D's side. — sent from eager-owl-205 |
…usals are refused, not missing (review 68011) Review 68020: signed_boot_manifest_window_refusal returned the full NetworkBootManifestVerificationClass?, forcing the join to carry an 'any other class' arm whose red cannot be authored (DESIGN 4b). It is now signed_boot_manifest_window -> SignedBootManifestWindow = ManifestWindowOpen | ManifestWindowNotYetValid | ManifestWindowExpired, and the join's mapping is total by construction. The annotation no longer asserts a co-consumer that is not in this tree: the broker (0D, #11605) is named as the later consumer. Review 68011: BootBundleAvailabilityStanding folded every shortfall into BootBundleUnobserved, reported as a missing artifacts axis. An observed read-back that disagrees is a different fact with a different remedy: BootBundleRefused { member, cause: BootBundleObservedRefusal, observation } -> NetworkBootDeliveryBundleRefused, carried by boot_artifact_delivery as CandidateNetworkBootBundleRefused. New witness bundle_read_back_serving_other_bytes_is_refused_not_missing. Executed locally on this tree: the new witness, both window witnesses, four_receipts_join_to_established and the boot_artifact_delivery establishment witness evaluate true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… declared frontier (review 68042) Nothing in this tree mints BootBundleAvailable or BootBundleRefused; the join consumes the standing and witnesses supply it. Declared as a typed FrontierRow naming 0B's gunbc.cloudflare.boot_origin boot_bundle_availability (#11603) as the producer, with a trigger that only a producer emitting BootBundleRefused for observed disagreements satisfies. Executed locally: cloudflare_frontier_rows_are_in_the_census evaluates true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Boot (CI red on 656bf7a) controlled_network_is_not_production_trust pinned production_trust() to a FirmwareHttpsTrusted ground. 6d5ad44 deliberately moved that fixture to the Secure Boot ground (firmware HTTPS trust alone is refused for UefiPxe), so the witness failed on the fixture's ground, not on the join. Its claim is unchanged: the controlled standing is not production, and the production fixture is production. Executed locally with claim_batch over both whole witness files: network_boot_delivery_join_witness 46/46 PASS, boot_artifact_delivery_witness 33/33 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nded (review 68100) FleetBootServiceReceipt.signing_key_identity and SignedBootManifestIdentity.signing_key_identity re-spelled the MAC key identity as a bare NonEmptyStr beside extdeps.crypto.mac MacKeyId, which already brands it; the join then compared them through 'as String'. Both fields are MacKeyId and the join compares the branded values directly, as gunbc.auth.approval_capability does. Fixtures brand their literals. Executed locally with claim_batch: network_boot_delivery_join_witness 46/46 PASS, boot_artifact_delivery_witness 33/33 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
SOURCE SIGN-OFF — 95fb87e7cb8acc6e76b69eadf391a85a6978fc8c
Verified the live head matches this SHA. The ac525e6 HOLD is discharged in the executing join:
- Trust is path- and subject-bound. Firmware-HTTPS-only refuses
UefiPxe; Secure Boot binds target plus chainloader digest; controlled-network evidence binds the site; firmware HTTPS binds the fleet endpoint. The established carrier retains onlyEstablishedBootstrapTrust, so the ungrounded arm is structurally unavailable. - Route identity is retained and joined. The edge receipt carries TFTP root plus reached broker/origin; the join compares ticket TFTP to the edge and reached broker/origin to the fleet receipt before minting.
- Bundle availability is a required standing. An unobserved bundle cannot establish; an observed refusal stays a located refusal; an available receipt must come from the fleet origin and match manifest kernel/initrd/root digests.
The requested failing-input witnesses are present and discriminate the exact refusal arms. Review 67992 ultimately named eight unexecuted arms; all eight are present: FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite, RouteArtifactOrigin, RouteBundleServedFrom, ManifestJoinNotYetValid, and ManifestJoinWrongAttempt. The direct HOLD reds for PXE + HTTPS-only, foreign broker, mismatched TFTP root, and verified-manifest-without-served-bundle are also present.
Later findings are retained: one closed manifest-window adjudicator, observed bundle refusal distinct from absence, grounded-only established trust, and branded MacKeyId comparison. CI run 35417580177 is green for required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and witnesses.
Approved for squash merge. This sign-off is void if the head moves.
…ier registration beside 0A's Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Summary
gunbc.network_boot_deliverysoNetworkBootDeliveryEstablishedis a join of fleet HTTPS service, site PXE edge, observed UEFI ARM64 client mode, boot-control, and signed-manifest identity — not a second PXE-readiness vocabulary.srv4BMC HTTP serve,srv3authored chain, fabric durable origin ≠ boot origin, measured Mt. Collins DHCP option 60 only) with typed standings; cite iPXE and R2 custom domains inextdeps.Test plan
/cargo-target/release/v1_src_dag_parseon every touched.dagfilemtcollins1_boot,approval_*, or srv1 roadmap unitsMade with Cursor