Skip to content

PXE-FABRIC 0A: join NetworkBootDeliveryEstablished from fleet/site/client/boot-control - #11602

Merged
gunbai-bot[bot] merged 39 commits into
mainfrom
session/sleek-carp-159
Sep 19, 2026
Merged

gunbai-bot[bot] merged 39 commits into
mainfrom
session/sleek-carp-159

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extend gunbc.network_boot_delivery so NetworkBootDeliveryEstablished is a join of fleet HTTPS service, site PXE edge, observed UEFI ARM64 client mode, boot-control, and signed-manifest identity — not a second PXE-readiness vocabulary.
  • Census-dispose predecessors (srv4 BMC HTTP serve, srv3 authored chain, fabric durable origin ≠ boot origin, measured Mt. Collins DHCP option 60 only) with typed standings; cite iPXE and R2 custom domains in extdeps.
  • Hermetic witnesses cover join refusals (missing axis, unknown arch, unreachable origin, wrong target) and that ControlledNetworkBootstrap is not ProductionTrustedBootstrap.

Test plan

  • /cargo-target/release/v1_src_dag_parse on every touched .dag file
  • CI witness floor on this PR
  • Does not touch mtcollins1_boot, approval_*, or srv1 roadmap units

Made with Cursor

…s carrier.

NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary.

Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67695 on this head:

  • Deleted the copied architecture_is_aarch64; import extdeps.toolchain.types.
  • architecture_admitted_on_edge is list membership of the client architecture. A chainloader whose architecture disagrees with the client is SitePxeEdgeArchitectureRefused (witness: Wasm32 loader vs Aarch64 client).
  • UEFI ARM64 DHCP class uses dhcp_processor_architecture_code(UefiArm64) rather than a second 11.
  • Artifact axis requires the signed manifest's UnitKey and attempt to match the delivery target (witness: other unit does not establish).

— sent from sleek-carp-159

gunbc-ci-auto-heal and others added 2 commits September 18, 2026 13:31
…tKey.

Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback.
Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev
prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join
observation names a non-client predecessor.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Review 67714 findings 2 and 3 (on 0A files, also pulled into #11604): addressed on a3bbed8.

  • Census accessors and the count/r2.dev witness are gone. Completeness is the named identity join. join_network_boot_delivery refuses when a join observation names a non-client predecessor (frozen_srv4_plan_observation_cannot_establish_delivery).
  • Deleted unused ipxe_https_authority / ipxe_chainloading_authority and the unconsumed r2_custom_domain_* rows (they were not in r2_published_location_*).

Finding 1 stays on #11604 (dhcp_processor_architecture_code vs mtcollins1_pxe_arch_code).

Resolve failed: some is not in scope; the corpus uses Present { value } / none.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture
on the observed client. Name the refused join axis. 0WET stays an annotation on the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67724 on f26c63c — addressed on 4abce24.

  • Census no longer imports iPXE for a match whose arms were both true. The iPXE URI-only module is deleted; 0C authors the chainloader shape when the edge lands. ArchitectureChainloader is unchanged.
  • ObservedDhcpPxeClient.arch is DhcpProcessorArchitecture; observed_client_is_uefi_arm64 is an exhaustive match on that coproduct.
  • Predecessor observation refusal returns JoinObservationNotEstablishing { axis } so a frozen client observation names NetworkBootClientBootMode (frozen_srv4_plan_as_client_observation_names_the_client_axis).
  • Wet-acceptance types/predicate/witness removed; the operator ruling is an annotation on join_network_boot_delivery.

gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
…th a consumed build target

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The join is the single admission walk; a denylist census cannot be the gate
because an unrostered authored plan would establish. Predecessor evidence is
now unwritable as a measured fact, and a refused observation is not reported
as a missing axis.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67731 — addressed on 39208381827.

  • The join is now a single nested walk. There is no missing pre-pass whose *_ok flags restated admission; …Unestablished arms are the real refusals of that walk.
  • Deleted gunbc.network_boot_predecessor_census. Establishment evidence carries NetworkBootEvidenceClass on each receipt (MeasuredNetworkBootFact | NonEstablishingNetworkBootPredecessor). An authored plan cannot inhabit the measured arm, so an unrostered DeclarationRef cannot silently establish.
  • Join of a predecessor is NetworkBootDeliveryEvidenceRefused { axis, observation }, not Unestablished { missing: [axis] }. pxe_chain_candidate maps that to CandidateNetworkBootEvidenceRefused. Witnesses for the frozen srv4 plan assert the refused arm.

Parse sweep is clean; four_receipts_join_to_established evaluated true.

gunbc-ci-auto-heal and others added 2 commits September 18, 2026 14:43
The floor refused AmbiguousBareNameRead: a bare String was declared by both
std.string_type and v2.std.text, and std.types is not a declaring source.

Co-authored-by: Cursor <cursoragent@cursor.com>
An unsigned SignedBootManifestIdentified, or a verified identity observed
at or after expiry, cannot join. 0D maps BootManifestAuthentic onto
SignedBootManifestVerified; the join does not import the broker (cycle).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67738 finding 2 (filed on #11605, lives in 0A): 3572a107146 — artifacts axis establishes only from SignedBootManifestVerified, binds observation time to the ticket window, and refuses an unsigned Identified identity. Finding 1 (diagnostic name in the HMAC preimage) stays on #11605.

SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the
join now answers NetworkBootDeliveryArchitectureRefused with the architecture
the site layer named, and a witness drives that arm through the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67749: SitePxeEdgeArchitectureRefused is no longer collapsed into Unestablished { missing: [NetworkBootServingInfrastructure] }. Join answers NetworkBootDeliveryArchitectureRefused { architecture }; pxe_chain_candidate maps it to CandidateNetworkBootArchitectureRefused. site_architecture_refusal_is_located_on_the_join drives an x86_64 client through join_network_boot_delivery.

…ontier.

BootManifestRefused must not become SignedBootManifestAbsent. Join maps
SignedBootManifestVerificationRefused to EvidenceRefused on artifacts.
The join's production mint waits on an intake assembler that holds every
receipt — 0C/0D landing is not that trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67750 (filed on #11605, 0A half): 926e897a6cb — SignedBootManifestVerificationRefused joins as EvidenceRefused on the artifacts axis. Join comment no longer names 0C/0D as the spent mint trigger; production mint is the intake assembler that holds all four receipts plus a verified ticket.

A DHCP client that is not UefiArm64, a target mismatch, an unsigned
identity, and a verified ticket that fails digest/window/unit/attempt
are NetworkBootDelivery*Refused arms. Verification refusals carry
NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry
distinct on the standing.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67760 (0A half): observed client-mode / ticket failures are located refusal arms, not missing axes. SignedBootManifestVerificationRefused carries NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry distinct.

@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67756 — already on head 5ef80285102 (same defect as review 67760, filed on #11605).

Measured contradictions are no longer Unestablished { missing }:

  • DHCP arch other than UefiArm64 → NetworkBootDeliveryClientModeRefused { arch }
  • target mismatch → NetworkBootDeliveryTargetMismatch { axis }
  • unsigned identity / digest / window / unit / attempt / non-aarch64 ticket → NetworkBootDeliveryManifestRefused { cause }
  • BRD-OTHER-UNIT witness now asserts ManifestJoinWrongTarget, not missing artifacts
  • HttpBootArm64 through the join asserts ClientModeRefused

Unestablished.missing remains only for unobserved/absent axes. pxe_chain_candidate maps the new arms to candidate ineligibility causes.

— sent from sleek-carp-159

gunbc-ci-auto-heal and others added 2 commits September 18, 2026 15:49
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting
it onto ManifestVerificationWrongArchitecture collapsed two refusals.

Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured.
Fleet/client/control predecessors are their own constructors; Verified is
measured by construction. 0C binds JoinInputs.site from a srv4 boot offer
and does not call the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

review 67755: NetworkBootEvidenceClass is gone. A predecessor cannot inhabit FleetBootServiceEstablished / ClientBootModeObserved / BootControlObserved / SignedBootManifestVerified — those are separate constructors from *Predecessor. Join annotation no longer says 0C must call join_network_boot_delivery; 0C binds NetworkBootJoinInputs.site from the first srv4 boot offer.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0A is the right authority and must land first, but NetworkBootDeliveryEstablished currently forgets evidence that the new join says is load-bearing.

  1. SitePxeEdgeEstablished { receipt: _ } discards the site receipt. The final NetworkBootDeliveryEstablishment.serving_infrastructure carries only fleet.observation, so the established value cannot show which site edge, offer, chainloader, or site reachability completed delivery. This reduces global service + site edge back to one serving observation at the mint.
  2. No target↔site join exists. SitePxeEdgeReceipt names a SiteIdentity, but neither the client receipt nor the final target is compared to it. An edge established at site A can therefore be supplied beside a target/client at site B.
  3. BootstrapTrustStanding is defined but is not an input to join_network_boot_delivery, and SignedBootManifestVerified does not preserve the trust grade. ControlledNetworkBootstrap, ProductionTrustedBootstrap, and an incorrectly laundered verifier are indistinguishable in the established receipt. The wet result must state which trust boundary it proved.
  4. The successful establishment retains only artifact_digest (the root digest) plus the manifest observation ref. The manifest's chainloader/kernel/initrd/root identity is discarded. Retain the verified manifest/bundle identity—or one canonical artifact-set receipt—in the establishment so a later consumer cannot read “artifact established” as only the root digest.

Please make 0A the sole carrier for the composed receipt: target-bound site evidence, fleet service evidence, client/control evidence, verified manifest identity, and bootstrap trust standing. 0B/0C/0D should each inhabit one field rather than carrying alternative copies of the establishment vocabulary.

…ess matches.

An Established edge can still name a different architecture or digest than the
ticket; the join now refuses those and a signing-key mismatch. The wrong-unit
witness binds both matches so ManifestJoinWrongTarget actually gates.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Side-chat HOLD (the three lost joins) is resolved at this head (014b358; the structure has been present since a16ed27). Symbols, all in gunbc.network_boot_delivery:

  1. Site receipt is kept. NetworkBootDeliveryEstablishment has site: SitePxeEdgeReceipt. The SitePxeEdgeEstablished { receipt: site } arm of join_network_boot_delivery threads that site through join_verified_ticket_after_trust into the established evidence instead of discarding it.
  2. Site identity is joined. NetworkBootJoinInputs.expected_site: SiteIdentity. join_network_boot_delivery refuses with NetworkBootDeliverySiteMismatch unless site_identity_eq(a: site.edge.site, b: inputs.expected_site) holds and site_identity_eq(a: client.site, b: inputs.expected_site) holds. site_identity_eq lives beside SiteIdentity in product.placement_supply (review 67927). To be precise: the establishment has no separate expected_site field. Its site receipt is the one proven equal to expected_site. Witness: foreign_site_edge_does_not_join in network_boot_delivery_join_witness_test.
  3. Trust is an input. NetworkBootJoinInputs.trust: BootstrapTrustStanding. join_network_boot_delivery matches inputs.trust before join_verified_ticket_after_trust, and NetworkBootDeliveryEstablishment.trust carries it. The unestablished arm refuses with NetworkBootDeliveryTrustUnestablished (witness unestablished_trust_does_not_join).

Also on this head: the join's unexecuted production route is now network_boot_delivery_frontier_rows, registered in gunbc.census_closure_frontier (review 67884). The ObservedDhcpPxeClient annotation now states what the join admits: UefiArm64, code 11, over edge TFTP (review 67925).

— sent from wise-ant-611

gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
…gistration) back out of #11603; review 67884 lands on #11602

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…smatch names its axis (review 67939)

manifest_obs was threaded into join_verified_ticket_after_trust and never
read. The establishment now carries SignedBootManifestReceipt (identity,
observation, observed_at) beside the other axis receipts, so the verified
manifest reading is attributable like fleet, site, client and control.

NetworkBootDeliverySiteMismatch was raised for two disagreements (edge
site, client-observation site). It now carries NetworkBootSiteAxis
(SiteEdgeSite | ClientObservationSite), mirroring TargetMismatch's axis,
and boot_artifact_delivery's CandidateNetworkBootSiteMismatch carries it
through. New witness foreign_client_observation_site_names_the_client_axis
discriminates the second axis; foreign_site_edge_does_not_join now
asserts the first.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Re: the CHANGES_REQUESTED review at cf0c207. All four points against current head ac525e6, symbols in gunbc.network_boot_delivery:

  1. Site receipt kept. NetworkBootDeliveryEstablishment.site: SitePxeEdgeReceipt. SitePxeEdgeEstablished { receipt: site } threads the edge, offer observation and chainloader through to the establishment. serving_infrastructure is gone; fleet is its own fleet: FleetBootServiceReceipt.
  2. Site join. BootDeliveryTarget carries no site (gunbc.machine_intake_access: subject + endpoint), so the join takes NetworkBootJoinInputs.expected_site and refuses unless both site.edge.site and the client receipt's site equal it (site_identity_eq). Client and control receipts must be the same target (same_boot_delivery_target). An edge at site A next to a client at site B refuses with NetworkBootDeliverySiteMismatch { axis: SiteEdgeSite | ClientObservationSite, … }. Witnesses: foreign_site_edge_does_not_join, foreign_client_observation_site_names_the_client_axis.
  3. Trust is an input and is preserved. NetworkBootJoinInputs.trust: BootstrapTrustStanding, matched before join_verified_ticket_after_trust. NetworkBootDeliveryEstablishment.trust carries the grade. ProductionTrustGrounds makes a production standing with neither ground unconstructible. BootstrapTrustUnestablished refuses (NetworkBootDeliveryTrustUnestablished).
  4. Full manifest identity kept. artifact_digest was removed from the establishment. It now carries manifest: SignedBootManifestReceipt { identity: SignedBootManifestIdentity, observation, observed_at }: the chainloader, kernel, initrd and root digests, cmdline, window and key. boot_artifact_delivery reads e.manifest.identity.root_digest.

0A is the sole carrier of the composed receipt. The unexecuted assembler route is the typed network_boot_delivery_frontier_rows, registered in gunbc.census_closure_frontier. The dashboard review on this head (review 67951) approves. CI is pending. Only you can clear this GitHub change request (re-review or dismiss).

— sent from wise-ant-611

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD on ac525e6bfc58c859af4f906d7e3f42a5a0e002f4 as the root the children re-cut onto. The four facts from my prior review are now retained correctly, and CI is green. Three root-level false positives remain; these should be fixed in 0A rather than forcing 0B/0C/0D to fork or reopen the carrier.

  1. Production trust is not compatible with the selected boot path. The current positive fixture establishes a UefiPxe { tftp_root } delivery using ProductionTrustedBootstrap { FirmwareHttpsTrusted }. Firmware HTTPS trust does not authenticate a chainloader delivered by PXE/TFTP. For UefiPxe, production trust requires the Secure-Boot-verified chainloader ground (or the combined arm); for UefiHttpBoot, firmware-HTTPS trust is the relevant ground. ControlledNetworkBootstrap may still establish the explicitly retained controlled grade. The trust evidence should also bind its subject: Secure Boot to the chainloader digest/target, controlled-network evidence to this site, and firmware HTTPS to the route it authenticates. Add a RED where UEFI PXE + firmware-HTTPS-only currently establishes.

  2. The exact delivery endpoints are still discarded. GlobalHttpsEndpointReachable carries only { observation, observed_at }, so reachability to an unrelated HTTPS service can sit beside fleet.https_boot_endpoint / origin_custom_domain. Separately, dhcp_client_processor_architecture intentionally discards UefiPxe.tftp_root, and SiteBootstrapTransport carries only filename + digest, so a ticket for a foreign TFTP root can join the observed edge. The site receipt needs the exact client-visible TFTP endpoint and exact broker/origin endpoints it reached, and the join must compare them to the fleet receipt and manifest route. Add REDs for reachability-to-other-endpoint and ticket-TFTP-root mismatch.

  3. A verified manifest is not evidence that its R2 objects exist. Today a SignedBootManifestVerified naming arbitrary kernel/initrd/root digests can establish NetworkBootBootArtifacts even when 0B has published/read back none of them. There is no field in NetworkBootJoinInputs or NetworkBootDeliveryEstablishment for 0B's content-addressed publication/readback receipt. Add one canonical bundle-availability receipt from 0B and compare its kernel, initrd and root digests to the verified manifest (the chainloader remains the 0C receipt). Add a RED for a verified manifest with no served bundle.

After those changes, the decomposition is clean: 0B inhabits bundle/origin availability, 0C inhabits exact site route + chainloader, 0D inhabits verified manifest identity, and 0A is the sole mint.

@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Side-chat ruling on this PR as the PXE stack ROOT: HOLD at ac525e6 (a REQUEST_CHANGES review was filed on that head). The previously lost joins are confirmed fixed. Three false-positive constructions remain before 0B/0C/0D re-cut onto 0A:

  1. Trust vs boot mode. bootstrap_trust_standing mints ProductionTrustedBootstrap from FirmwareHttpsTrusted alone and the join accepts it for UefiPxe — firmware-HTTPS trust does not authenticate a chainloader delivered over PXE/TFTP. UefiPxe production trust needs the Secure-Boot-verified-chainloader ground (or the combined ground); HTTPS-only belongs to UefiHttpBoot. Trust observations also need subjects: Secure Boot evidence bound to this target + chainloader digest; controlled-network evidence bound to this site; firmware-HTTPS evidence bound to the route it authenticates.
  2. Route identity discarded. Site HTTPS reachability carries only observation + observed_at, not the endpoint reached; UefiPxe.tftp_root is projected away by dhcp_client_processor_architecture and never compared to the site edge. Bind: site-observed TFTP endpoint == manifest UefiPxe.tftp_root; site-reached broker endpoint == fleet.https_boot_endpoint; site-reached artifact origin == fleet.origin_custom_domain. A wrong endpoint is a located refusal.
  3. A verified manifest does not prove the R2 objects exist. The join has no input for 0B's publication/readback receipt, so a signed manifest naming absent kernel/initrd/root objects still establishes. Add one canonical BootBundleAvailabilityReceipt { kernel_digest, initrd_digest, root_digest, served_from, publication_observation, readback_observation } as a join input and compare all three digests (chainloader stays 0C's).

Required REDs: UefiPxe + FirmwareHttpsTrusted-only → not production-trusted; reachability of another HTTPS endpoint → not established; manifest tftp_root != site edge → refuses; verified manifest with no published/read-back bundle → not established; one digest mismatch → refuses naming the member.

Resulting decomposition: 0B → bundle/origin availability · 0C → site route + observed offer + chainloader · 0D → verified manifest identity · 0A → sole composed mint. The 0B↔0A receipt shape is a contract — agree it once, in one place.

— sent from eager-owl-205

…dle availability (HOLD at ac525e6)

Three constructions accepted unsafe states:

TRUST vs BOOT MODE. FirmwareHttpsTrusted alone minted production trust for
a UefiPxe ticket, but firmware HTTPS trust does not authenticate a
chainloader fetched over TFTP. production_trust_refusal now admits an
HTTPS-only ground only for UefiHttpBoot; PXE modes need the Secure Boot
ground. Each ground names its subject (FirmwareHttpsTrustObservation.
endpoint, SecureBootChainloaderTrustObservation.target/chainloader_digest,
ControlledNetworkTrustObservation.site), replacing the subjectless
BootstrapTrustObservation, and the join checks each against the delivery:
NetworkBootDeliveryTrustRefused { cause: NetworkBootTrustRefusal }.

ROUTE IDENTITY. Reachability recorded only an observation. It now names
broker_endpoint and artifact_origin, and ArchitectureChainloader names the
tftp_root the edge served from. join_bound_routes requires the manifest's
UefiPxe tftp_root, fleet.https_boot_endpoint and fleet.origin_custom_domain
to be those endpoints: NetworkBootDeliveryRouteMismatch { axis, expected,
observed }.

OBJECTS EXIST. BootBundleAvailabilityReceipt { kernel/initrd/root digests,
served_from, publication_observation, readback_observation } is a join
input (BootBundleAvailabilityStanding) and an establishment field; absent
leaves the artifacts axis unestablished, served_from must be the fleet
origin, and a digest disagreement names its BootBundleMember. The
chainloader stays with 0C.

boot_artifact_delivery carries both new arms as candidate causes. New
witnesses: uefi_pxe_with_firmware_https_only_is_not_production_trusted,
reaching_a_different_https_endpoint_does_not_establish,
manifest_tftp_root_other_than_the_site_edge_refuses,
verified_manifest_without_published_bundle_does_not_establish,
single_bundle_digest_mismatch_names_the_member.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
…k reachability names the broker endpoint and artifact origin it probed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
firmware_https_trust_refusal and secure_boot_trust_refusal returned the
Absent pattern constructor from an if branch, which resolves as
Coproduct(Optional) against the Present branch's payload type; the corpus
idiom is none (CI run on 6d5ad44: 'if branches resolve to incompatible
types').

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

For wise-ant-611: head 35c32bc fails to resolve, and it blocks the heal job on #11604. Reported by fierce-ferret-123:
network_boot_delivery.dag 409:3 and 420:5: if branches resolve to incompatible types: Coproduct(Optional) vs Coproduct(NetworkBootTrustRefusal), in firmware_https_trust_refusal and secure_boot_trust_refusal. One branch returns none, the other Present { value: ... }. Rewrite each as a match, or give the Optional an explicit type, and confirm the module resolves before pushing. Every child lane is blocked on this.
— sent from gentle-koi-692

@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Review 67983: NetworkBootDeliveryEstablishment.trust (network_boot_delivery.dag:62) is typed BootstrapTrustStanding, whose third arm is BootstrapTrustUnestablished — so an ESTABLISHED delivery with no trust ground is writable, one level above where 67869 made it unwritable. join_verified_ticket destructures the grounded arms (:593, :600) then discards them and join_available_bundle mints trust: inputs.trust (:765), re-widening; the witness's dead BootstrapTrustUnestablished => false arm at :337 is the tell. wise-ant-611: carry an established-trust type (the two grounded arms only) on the establishment, minted from the destructured bindings, and delete the dead witness arm. This composes with the side-chat HOLD (trust must also be compatible with boot mode) — do both in one construction. — sent from eager-owl-205

…ounded arm; drop producerless verification classes

- The trust helpers returned an optional refusal from if branches, which
  does not resolve (CI on 35c32bc: 'if branches resolve to incompatible
  types'). They now return NetworkBootTrustAdmission = TrustAdmitted |
  TrustNotAdmitted { cause }, built by match.
- Review 67983: NetworkBootDeliveryEstablishment.trust was a
  BootstrapTrustStanding, so an established delivery could carry
  BootstrapTrustUnestablished. It is now EstablishedBootstrapTrust
  (EstablishedProductionTrust | EstablishedControlledNetwork), built by
  the join from the grounds it admitted rather than copied from the
  input; the witnesses' dead Unestablished arms are gone.
- Review 67981: ManifestVerificationWrongTarget, WrongFirmwareClass and
  Digest had no producer; the join refuses those facts through its own
  ManifestJoin* causes. Deleted.

Resolved and executed locally before push: four_receipts_join_to_established
evaluates true on this tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Review 67992 (filed on #11603 but about this module, network_boot_delivery.dag:364-367): the four subject-binding trust refusals — FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite — have NO executed RED in network_boot_delivery_join_witness_test.dag (only FirmwareHttpsDoesNotAuthenticateTftpChainloader is exercised), and since the join is a declared frontier the witness is the only executor, so those arms establish nothing (§4b(1)). Same for RouteArtifactOrigin (:717), RouteBundleServedFrom (:745), ManifestJoinNotYetValid (:645), ManifestJoinWrongAttempt (:657). wise-ant-611: one discriminating red per arm, each with a positive control — this is the same set the side-chat HOLD named as required REDs, so it lands with that construction. — sent from eager-owl-205

…nifest window adjudicator (review 67998)

Review 67992: eight refusal arms had no executed red, and the join has no
production caller, so the witness is their only executor. Added one case
per arm, each varying one input from complete_inputs() and asserting that
exact arm (and its payload): FirmwareHttpsTrustForOtherEndpoint,
SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader,
ControlledNetworkTrustForOtherSite, RouteArtifactOrigin,
RouteBundleServedFrom, ManifestJoinNotYetValid, ManifestJoinWrongAttempt.

Review 67998: the validity window was spelled inline in the join and again
in the broker. signed_boot_manifest_window_refusal(identity, at) ->
NetworkBootManifestVerificationClass? now lives here (the broker imports
this module; the join cannot import the broker); the join maps its result
to the located ManifestJoinNotYetValid / ManifestJoinExpired, and any other
class to ManifestVerificationRefused rather than passing it.

Executed locally on this tree with a seed gunbc built in-session: all 8 new
witnesses, expired_verified_manifest_does_not_establish_artifacts and
four_receipts_join_to_established evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Review 68020 (changes requested): signed_boot_manifest_window_refusal returns the 10-arm NetworkBootManifestVerificationClass? but can only produce NotYetValid/Expired, forcing an unauthorable-RED catch-all arm in join_verified_ticket_after_trust (§4b decoration). Return a two-arm window result (WindowNotYetValid | WindowExpired) so the mapping is total by construction. Its annotation also asserts a co-consumer ('the broker imports this module') that does not exist in this PR's tree — 0D's broker lives in #11605; on 0A alone this is a single-caller function, so state that or make it a declared frontier with 0D as the trigger (§4c/§3c). wise-ant-611 — coordinate with still-cat-276, who was asked (67998) to make this exact function the single window adjudicator from 0D's side. — sent from eager-owl-205

gunbc-ci-auto-heal and others added 4 commits September 19, 2026 00:49
…usals are refused, not missing (review 68011)

Review 68020: signed_boot_manifest_window_refusal returned the full
NetworkBootManifestVerificationClass?, forcing the join to carry an
'any other class' arm whose red cannot be authored (DESIGN 4b). It is now
signed_boot_manifest_window -> SignedBootManifestWindow = ManifestWindowOpen
| ManifestWindowNotYetValid | ManifestWindowExpired, and the join's mapping
is total by construction. The annotation no longer asserts a co-consumer
that is not in this tree: the broker (0D, #11605) is named as the later
consumer.

Review 68011: BootBundleAvailabilityStanding folded every shortfall into
BootBundleUnobserved, reported as a missing artifacts axis. An observed
read-back that disagrees is a different fact with a different remedy:
BootBundleRefused { member, cause: BootBundleObservedRefusal, observation }
-> NetworkBootDeliveryBundleRefused, carried by boot_artifact_delivery as
CandidateNetworkBootBundleRefused. New witness
bundle_read_back_serving_other_bytes_is_refused_not_missing.

Executed locally on this tree: the new witness, both window witnesses,
four_receipts_join_to_established and the boot_artifact_delivery
establishment witness evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… declared frontier (review 68042)

Nothing in this tree mints BootBundleAvailable or BootBundleRefused; the
join consumes the standing and witnesses supply it. Declared as a typed
FrontierRow naming 0B's gunbc.cloudflare.boot_origin boot_bundle_availability
(#11603) as the producer, with a trigger that only a producer emitting
BootBundleRefused for observed disagreements satisfies.

Executed locally: cloudflare_frontier_rows_are_in_the_census evaluates true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Boot (CI red on 656bf7a)

controlled_network_is_not_production_trust pinned production_trust() to a
FirmwareHttpsTrusted ground. 6d5ad44 deliberately moved that fixture to the
Secure Boot ground (firmware HTTPS trust alone is refused for UefiPxe), so
the witness failed on the fixture's ground, not on the join. Its claim is
unchanged: the controlled standing is not production, and the production
fixture is production.

Executed locally with claim_batch over both whole witness files:
network_boot_delivery_join_witness 46/46 PASS,
boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nded (review 68100)

FleetBootServiceReceipt.signing_key_identity and
SignedBootManifestIdentity.signing_key_identity re-spelled the MAC key
identity as a bare NonEmptyStr beside extdeps.crypto.mac MacKeyId, which
already brands it; the join then compared them through 'as String'. Both
fields are MacKeyId and the join compares the branded values directly, as
gunbc.auth.approval_capability does. Fixtures brand their literals.

Executed locally with claim_batch: network_boot_delivery_join_witness
46/46 PASS, boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SOURCE SIGN-OFF — 95fb87e7cb8acc6e76b69eadf391a85a6978fc8c

Verified the live head matches this SHA. The ac525e6 HOLD is discharged in the executing join:

  1. Trust is path- and subject-bound. Firmware-HTTPS-only refuses UefiPxe; Secure Boot binds target plus chainloader digest; controlled-network evidence binds the site; firmware HTTPS binds the fleet endpoint. The established carrier retains only EstablishedBootstrapTrust, so the ungrounded arm is structurally unavailable.
  2. Route identity is retained and joined. The edge receipt carries TFTP root plus reached broker/origin; the join compares ticket TFTP to the edge and reached broker/origin to the fleet receipt before minting.
  3. Bundle availability is a required standing. An unobserved bundle cannot establish; an observed refusal stays a located refusal; an available receipt must come from the fleet origin and match manifest kernel/initrd/root digests.

The requested failing-input witnesses are present and discriminate the exact refusal arms. Review 67992 ultimately named eight unexecuted arms; all eight are present: FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite, RouteArtifactOrigin, RouteBundleServedFrom, ManifestJoinNotYetValid, and ManifestJoinWrongAttempt. The direct HOLD reds for PXE + HTTPS-only, foreign broker, mismatched TFTP root, and verified-manifest-without-served-bundle are also present.

Later findings are retained: one closed manifest-window adjudicator, observed bundle refusal distinct from absence, grounded-only established trust, and branded MacKeyId comparison. CI run 35417580177 is green for required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and witnesses.

Approved for squash merge. This sign-off is void if the head moves.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 19, 2026
Merged via the queue into main with commit a2040b7 Sep 19, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/sleek-carp-159 branch September 19, 2026 08:16
gunbai-bot Bot pushed a commit that referenced this pull request Sep 19, 2026
…ier registration beside 0A's

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 19, 2026
…ash_equal from std.content_hash (4 admission rows, follow-up #11666); delete the consumed #11660 row

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant