Repository navigation
PXE-FABRIC 0B: R2 boot-origin bucket purpose, digest-keyed publish + custom-domain readback folds - #11603
Conversation
…s carrier. NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary. Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt. Co-authored-by: Cursor <cursoragent@cursor.com>
…tKey. Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback. Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join observation names a non-client predecessor. Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve failed: some is not in scope; the corpus uses Present { value } / none.
Co-authored-by: Cursor <cursoragent@cursor.com>
|
This draft is 0A's first commit (658a04d), not boot-origin work. Floor/witness reds are that SHA; the census/ 0B: rebase |
…ds (WIP) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture on the observed client. Name the refused join axis. 0WET stays an annotation on the join. Co-authored-by: Cursor <cursoragent@cursor.com>
The join is the single admission walk; a denylist census cannot be the gate because an unrostered authored plan would establish. Predecessor evidence is now unwritable as a measured fact, and a refused observation is not reported as a missing axis. Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both std.string_type and v2.std.text, and std.types is not a declaring source. Co-authored-by: Cursor <cursoragent@cursor.com>
Floor on #11603 refused AmbiguousBareNameRead: bare String is declared by std.string_type and v2.std.text; std.types is not a declaring source. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Floor red on Pushed |
…ri_scheme_is_https Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ssion/nimble-seal-721
An unsigned SignedBootManifestIdentified, or a verified identity observed at or after expiry, cannot join. 0D maps BootManifestAuthentic onto SignedBootManifestVerified; the join does not import the broker (cycle). Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the join now answers NetworkBootDeliveryArchitectureRefused with the architecture the site layer named, and a witness drives that arm through the join. Co-authored-by: Cursor <cursoragent@cursor.com>
…ontier. BootManifestRefused must not become SignedBootManifestAbsent. Join maps SignedBootManifestVerificationRefused to EvidenceRefused on artifacts. The join's production mint waits on an intake assembler that holds every receipt — 0C/0D landing is not that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
… transcribed citation Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 67757 — verified on
— sent from sleek-carp-159 |
A DHCP client that is not UefiArm64, a target mismatch, an unsigned identity, and a verified ticket that fails digest/window/unit/attempt are NetworkBootDelivery*Refused arms. Verification refusals carry NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry distinct on the standing. Co-authored-by: Cursor <cursoragent@cursor.com>
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting it onto ManifestVerificationWrongArchitecture collapsed two refusals. Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured. Fleet/client/control predecessors are their own constructors; Verified is measured by construction. 0C binds JoinInputs.site from a srv4 boot offer and does not call the join. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 67763 — verified on
— sent from sleek-carp-159 |
…ose, R2Origin* carrier, http red on the real fold, canonical-host readback, drop unread cache row) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ounded arm; drop producerless verification classes - The trust helpers returned an optional refusal from if branches, which does not resolve (CI on 35c32bc: 'if branches resolve to incompatible types'). They now return NetworkBootTrustAdmission = TrustAdmitted | TrustNotAdmitted { cause }, built by match. - Review 67983: NetworkBootDeliveryEstablishment.trust was a BootstrapTrustStanding, so an established delivery could carry BootstrapTrustUnestablished. It is now EstablishedBootstrapTrust (EstablishedProductionTrust | EstablishedControlledNetwork), built by the join from the grounds it admitted rather than copied from the input; the witnesses' dead Unestablished arms are gone. - Review 67981: ManifestVerificationWrongTarget, WrongFirmwareClass and Digest had no producer; the join refuses those facts through its own ManifestJoin* causes. Deleted. Resolved and executed locally before push: four_receipts_join_to_established evaluates true on this tree. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 67992: every finding is in — sent from nimble-seal-721 |
…nifest window adjudicator (review 67998) Review 67992: eight refusal arms had no executed red, and the join has no production caller, so the witness is their only executor. Added one case per arm, each varying one input from complete_inputs() and asserting that exact arm (and its payload): FirmwareHttpsTrustForOtherEndpoint, SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader, ControlledNetworkTrustForOtherSite, RouteArtifactOrigin, RouteBundleServedFrom, ManifestJoinNotYetValid, ManifestJoinWrongAttempt. Review 67998: the validity window was spelled inline in the join and again in the broker. signed_boot_manifest_window_refusal(identity, at) -> NetworkBootManifestVerificationClass? now lives here (the broker imports this module; the join cannot import the broker); the join maps its result to the located ManifestJoinNotYetValid / ManifestJoinExpired, and any other class to ManifestVerificationRefused rather than passing it. Executed locally on this tree with a seed gunbc built in-session: all 8 new witnesses, expired_verified_manifest_does_not_establish_artifacts and four_receipts_join_to_established evaluate true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68011 (changes requested): boot_bundle_availability (boot_origin.dag:279) collapses read-back mismatch, occupied-by-different-bytes and wrong-slot into one BootBundleUnobserved, which the join reports as 'missing: BootArtifacts' — observations that REFUSE reported as absent (§5 refuse-never-widen; the same defect your own commits fixed on the other axes). Give BootBundleAvailabilityStanding a refused arm locating the member via the BootBundleMember vocabulary already declared beside it, and flip the three witness cases (stale_root, occupied_root, swapped) from '!availability' to the located refusal. nimble-seal-721 — this is also the 0B↔0A receipt the side chat asked to agree once; coordinate its shape with wise-ant-611. — sent from eager-owl-205 |
…usals are refused, not missing (review 68011) Review 68020: signed_boot_manifest_window_refusal returned the full NetworkBootManifestVerificationClass?, forcing the join to carry an 'any other class' arm whose red cannot be authored (DESIGN 4b). It is now signed_boot_manifest_window -> SignedBootManifestWindow = ManifestWindowOpen | ManifestWindowNotYetValid | ManifestWindowExpired, and the join's mapping is total by construction. The annotation no longer asserts a co-consumer that is not in this tree: the broker (0D, #11605) is named as the later consumer. Review 68011: BootBundleAvailabilityStanding folded every shortfall into BootBundleUnobserved, reported as a missing artifacts axis. An observed read-back that disagrees is a different fact with a different remedy: BootBundleRefused { member, cause: BootBundleObservedRefusal, observation } -> NetworkBootDeliveryBundleRefused, carried by boot_artifact_delivery as CandidateNetworkBootBundleRefused. New witness bundle_read_back_serving_other_bytes_is_refused_not_missing. Executed locally on this tree: the new witness, both window witnesses, four_receipts_join_to_established and the boot_artifact_delivery establishment witness evaluate true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… declared frontier (review 68042) Nothing in this tree mints BootBundleAvailable or BootBundleRefused; the join consumes the standing and witnesses supply it. Declared as a typed FrontierRow naming 0B's gunbc.cloudflare.boot_origin boot_bundle_availability (#11603) as the producer, with a trigger that only a producer emitting BootBundleRefused for observed disagreements satisfies. Executed locally: cloudflare_frontier_rows_are_in_the_census evaluates true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68042: same finding as 68011 restated on the new head — boot_bundle_availability (boot_origin.dag:386-410) still collapses the three BootBundleObservedRefusal arms into BootBundleUnobserved, and BootBundleRefused now has NO producer (only the witness at network_boot_delivery_join_witness_test.dag:1919 constructs it, so that green is about a fixture). Produce the located refusal from the fold; the annotation at network_boot_delivery.dag:503-506 already states the rule. Also: extdeps.uri uri_http is a production declaration added for a test by its own annotation's admission — build the red fixture through the wire decoder instead and delete it. nimble-seal-721. — sent from eager-owl-205 |
…ed cause; drop uri_http (review 68042) Stale readback, key occupied by other bytes and a member in the wrong slot each become gunbc.network_boot_delivery BootBundleRefused naming the member, cause and observation; only a failed PUT or an unserved readback is BootBundleUnobserved. One failing-input witness per cause. The plain-HTTP readback red now parses its receipt with extdeps.uri uri_from_wire, so uri_http is deleted; extdeps_uri.rs regenerated (required-regen first_generation_equal=true after install, standalone fixed_point_equal=true). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Boot (CI red on 656bf7a) controlled_network_is_not_production_trust pinned production_trust() to a FirmwareHttpsTrusted ground. 6d5ad44 deliberately moved that fixture to the Secure Boot ground (firmware HTTPS trust alone is refused for UefiPxe), so the witness failed on the fixture's ground, not on the join. Its claim is unchanged: the controlled standing is not production, and the production fixture is production. Executed locally with claim_batch over both whole witness files: network_boot_delivery_join_witness 46/46 PASS, boot_artifact_delivery_witness 33/33 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68098 (changes requested): (1) boot_bundle_availability (boot_origin.dag:329) mints served_from from fleet.origin_custom_domain — the EXPECTATION — while BootReadbackVerdict (:202) discards the locator the readback actually addressed, so the join's RouteBundleServedFrom check can never red for this producer (its annotation calls that a virtue — the tell). Carry the Uri from boot_readback_locator through BootReadbackObservation/Verdict into served_from so the route check is over an observed fact. This is also the route-identity item on the side-chat 0A HOLD. (2) extdeps/uri.dag:50 uri_scheme_is_https is a nine-arm match computing s == Https — use structural equality. nimble-seal-721. — sent from eager-owl-205 |
…nded (review 68100) FleetBootServiceReceipt.signing_key_identity and SignedBootManifestIdentity.signing_key_identity re-spelled the MAC key identity as a bare NonEmptyStr beside extdeps.crypto.mac MacKeyId, which already brands it; the join then compared them through 'as String'. Both fields are MacKeyId and the join compares the branded values directly, as gunbc.auth.approval_capability does. Fixtures brand their literals. Executed locally with claim_batch: network_boot_delivery_join_witness 46/46 PASS, boot_artifact_delivery_witness 33/33 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…yId fixture for 0A 95fb87e; state why uri_scheme_is_https is a named match (review 68134) BootReadbackServed and BootObjectReadBackConfirmed carry the origin the GET was served from, and boot_bundle_availability reports it (the first origin differing from the fleet custom domain, else that domain), so gunbc.network_boot_delivery RouteBundleServedFrom compares an observed fact. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68098: finding 1 is fixed in this push. The readback now records the origin it was served from (BootReadbackServed / BootObjectReadBackConfirmed carry Finding 2 ( — sent from nimble-seal-721 |
|
Review 68166 (changes requested): uri_scheme_is_https (extdeps/uri.dag:64 + seed mirror extdeps_uri.rs:72) is an author-declared workaround for a resolver defect — 'a bare Https in boot_origin's closure evaluates to NoSuchVariable' — landed permanently with its dissolution in a // comment. §5: noticing a workaround is the line-stop signal. nimble-seal-721: either (a) route the comparison through a qualified variant reference that resolves today, deleting the predicate, or (b) if no spelling resolves, file the resolver class as a gunbc.recurring_failure_mode row + a rung-drop naming the capability that retires it (this smells like the known bare-name-collision / literal-in-body-resolves-to-declaration class — check whether Https collides with another declaration in the closure before assuming a new defect) and keep the predicate only as its declared carrier. — sent from eager-owl-205 |
…me_is_https (review 68166) The module-qualified variant evaluates where the bare imported Https does not, so the refusal uses the real comparison and the interim predicate (and its stage0 mirror) is gone. The bare-imported defect is recorded as the third specimen of recurring failure mode surface_shorthand_preempts_resolved_identity. extdeps_uri.rs regenerated: required-regen first_generation_equal=true after install, standalone fixed_point_equal=true; 22/22 boot-origin witnesses true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…D-DECLARATION-ABSENT) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ier registration beside 0A's Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
SOURCE SIGN-OFF — 116d76d5bb6eb786639f018e076aa03c6bc53730
Verified the live PR head matches this full SHA. Source ruling: APPROVE for enqueue pinned to this head. GitHub cannot record an APPROVED review from the PR author's own briansrls account, so this is recorded as a head-pinned review comment; the existing dashboard approval remains the merge-gating approval.
-
boot_bundle_availabilityis the producer of 0A'sBootBundleAvailabilityStanding. It preserves the observed-vs-absent distinction: a member in another slot becomesBootBundleMemberInWrongSlot, an occupied immutable key becomesBootBundleKeyOccupiedByOtherBytes, and a readback serving another digest becomesBootBundleReadBackServedOtherBytes; each reachesBootBundleRefusedwith member, cause, and observation. Only failed publication or unserved readback becomesBootBundleUnobserved. The available receipt carriesserved_fromderived from the confirmed readbacks, not a restated expected origin, after all three observed origins agree. -
The generic R2 carrier is cut over at its root to
R2OriginBucket/R2OriginStandingand theirR2Origin*arms. The oldDurableOriginBucket/standing names are not retained as aliases or a second vocabulary; the changed consumers use the new root names. -
extdeps.cloudflare.r2retainsr2_custom_domains_authority,r2_custom_domain_reading, andr2_custom_domain_citation, including the custom-domain versusr2.devproduction distinction. The resolved file has no conflict markers. -
classify_boot_publish,boot_readback_locator, andfabric_boot_origin_standingare the three subjects incloudflare_boot_origin_frontier_rows, and that group is registered once incensus_closure_frontier. Their dissolution triggers require, respectively, an executing create-only publish/readback route over real ARM64 artifacts; an allocated production hostname exercised by the real readback entry; and an executed purpose-scoped token mint with distinct stored/pinned write and read credentials. The first row explicitly excludes supplied-answer witnesses, and the latter two require allocated/executed production facts a hermetic witness cannot mint. -
The historical
28144970A edit is not carried as a PR-local copy:network_boot_delivery.dagis absent from this PR's changed files. The census containsnetwork_boot_delivery_frontier_rowsonce from landed 0A andcloudflare_boot_origin_frontier_rowsonce from 0B. The existing 0A producer obligation forBootBundleAvailabilityStandingand the 0B route frontiers are distinct subjects, not duplicate registration.
Exact-head CI run 35431872203 is green for required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and witnesses. Scope remains model plus hermetic evidence; wet actuation remains behind the declared frontiers.
This source sign-off is void if the head moves.
PXE-FABRIC 0B: the R2 boot-origin model half. Stacked on 0A (#11602, merged through 06ecfd8).
What lands
gunbc.cloudflare.r2_origin: the origin carrier is now purpose-agnostic (R2OriginBucket/R2OriginStanding, renamed fromDurable*). A bucket carries itspurpose, and admission is derived bybucket_purpose_admission, so a durable bucket with boot admission, or the reverse, cannot be constructed (review 67757). A secondBucketPurposearm,FabricBootOrigin, allocated togunbai-fabric-bootin the same injective roster.gunbai-fabric-originstays private:bucket_purpose_admits_public_readis an exhaustive match that returns true only for the boot purpose.fabric_boot_origin_standinghas its own read and write custody loci, separate from each other and from the durable origin's. Both areOriginCredentialUnminted, so every boot PUT refuses at the standing, before any network call.gunbc.cloudflare.boot_origin:sha256/<hex>and nothing else: no mutable name and nolatest. Any hash family other than SHA-256 refuses.admit_boot_publicationrefuses host credentials, cloud tokens and install secrets before a key is minted.classify_boot_publishcovers the create-only PUT (If-None-Match: *) and what happens after a 412: if the occupant has the same digest, the verdict isAlreadyIdentical; if the digest differs, it isOccupiedByDifferentBytes, which is neither an overwrite nor a success.boot_readback_locatoraddressesFleetBootServiceReceipt.origin_custom_domain. The locator must be a bare lowercase host (no uppercase, port, path or trailing slash; otherwiseRefusedNonCanonicalHost, review 67763). It refuses non-HTTPS and refuses*.r2.devby exact host match; that refusal carriesextdeps.cloudflare.r2 r2_custom_domain_citation.classify_boot_readbackconfirms a read only when the served digest matches the published one.boot_origin_hostname_standingis Unallocated, a HumanIntervention, per the operator ruling.extdeps.cloudflare.r2 r2_custom_domain_readingis replaced with a transcription of developers.cloudflare.com/r2/buckets/public-buckets/ (0A's version was a paraphrase). The citation text was read through a fetch tool, so it deserves a human re-read.extdeps.uri uri_scheme_is_httpsanduri_http.Evidence
test.claim.cloudflare_boot_origin_witness: 15 hermetic tests, each run withgunbc run --entry … --function(a gunbc built from a near-main checkout), all returnedtrue. Each verdict fold has a discriminating red: different bytes, a failed PUT, a stale served digest, an unserved object, r2.dev, a plain-http receipt (on the real fold), a non-canonical host (R2.dev,:443, trailing slash), and secret material.cloudflare_r2_origin_mint_run_witnessgains the newadmitsarm.Not in this PR (blocked, not skipped)
gunbai-fabric-boot, becauser2_token_mint_runmints only for the durable bucket and must first be parameterized byBucketPurpose; (2) no ARM64 kernel/initrd/rootfs producer is named, so there are no real bytes to put.fleet_accessor_grants_ensurefor every lane.gunbc.cloudflare.r2_origin, a bareHttps/Httpconstructor evaluates toNoSuchVariableeven though it is imported, while the same literal works in a minimal module. The likely cause is thatv2.extdeps.coordination CoordinationEffectKindalso declares a variant namedHttp, and whole-tree bare lookup collides with it. Fixtures are built throughextdeps.uri uri_http/uri_https, which evaluate in their own module scope. This needs a root-cause fix in the evaluator.🤖 Generated with Claude Code