Skip to content

PXE-FABRIC 0B: R2 boot-origin bucket purpose, digest-keyed publish + custom-domain readback folds - #11603

Merged
gunbai-bot[bot] merged 72 commits into
mainfrom
session/nimble-seal-721
Sep 19, 2026
Merged

gunbai-bot[bot] merged 72 commits into
mainfrom
session/nimble-seal-721

Conversation

@briansrls

@briansrls briansrls commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

PXE-FABRIC 0B: the R2 boot-origin model half. Stacked on 0A (#11602, merged through 06ecfd8).

What lands

  • gunbc.cloudflare.r2_origin: the origin carrier is now purpose-agnostic (R2OriginBucket/R2OriginStanding, renamed from Durable*). A bucket carries its purpose, and admission is derived by bucket_purpose_admission, so a durable bucket with boot admission, or the reverse, cannot be constructed (review 67757). A second BucketPurpose arm, FabricBootOrigin, allocated to gunbai-fabric-boot in the same injective roster. gunbai-fabric-origin stays private: bucket_purpose_admits_public_read is an exhaustive match that returns true only for the boot purpose. fabric_boot_origin_standing has its own read and write custody loci, separate from each other and from the durable origin's. Both are OriginCredentialUnminted, so every boot PUT refuses at the standing, before any network call.
  • New gunbc.cloudflare.boot_origin:
    • Bundle members are kernel, initrd and root image. The iPXE chainloader is not a member; it belongs to 0C.
    • Keys are sha256/<hex> and nothing else: no mutable name and no latest. Any hash family other than SHA-256 refuses.
    • admit_boot_publication refuses host credentials, cloud tokens and install secrets before a key is minted.
    • classify_boot_publish covers the create-only PUT (If-None-Match: *) and what happens after a 412: if the occupant has the same digest, the verdict is AlreadyIdentical; if the digest differs, it is OccupiedByDifferentBytes, which is neither an overwrite nor a success.
    • boot_readback_locator addresses FleetBootServiceReceipt.origin_custom_domain. The locator must be a bare lowercase host (no uppercase, port, path or trailing slash; otherwise RefusedNonCanonicalHost, review 67763). It refuses non-HTTPS and refuses *.r2.dev by exact host match; that refusal carries extdeps.cloudflare.r2 r2_custom_domain_citation.
    • classify_boot_readback confirms a read only when the served digest matches the published one.
    • boot_origin_hostname_standing is Unallocated, a HumanIntervention, per the operator ruling.
  • extdeps.cloudflare.r2 r2_custom_domain_reading is replaced with a transcription of developers.cloudflare.com/r2/buckets/public-buckets/ (0A's version was a paraphrase). The citation text was read through a fetch tool, so it deserves a human re-read.
  • extdeps.uri uri_scheme_is_https and uri_http.

Evidence

test.claim.cloudflare_boot_origin_witness: 15 hermetic tests, each run with gunbc run --entry … --function (a gunbc built from a near-main checkout), all returned true. Each verdict fold has a discriminating red: different bytes, a failed PUT, a stale served digest, an unserved object, r2.dev, a plain-http receipt (on the real fold), a non-canonical host (R2.dev, :443, trailing slash), and secret material. cloudflare_r2_origin_mint_run_witness gains the new admits arm.

Not in this PR (blocked, not skipped)

  • Wet publish of the ARM64 bundle. Two blockers: (1) no write credential exists for gunbai-fabric-boot, because r2_token_mint_run mints only for the durable bucket and must first be parameterized by BucketPurpose; (2) no ARM64 kernel/initrd/rootfs producer is named, so there are no real bytes to put.
  • Cache policy row, and the bucket-create, custom-domain-attach and cache-rule API operations. They are not added yet because they would have no consumer until the wet path exists (§3c).
  • Accessor roster rows. They land with the minted versions. A row for a secret that does not exist would stop fleet_accessor_grants_ensure for every lane.
  • Evaluator defect, not fixed here. In a witness that imports gunbc.cloudflare.r2_origin, a bare Https / Http constructor evaluates to NoSuchVariable even though it is imported, while the same literal works in a minimal module. The likely cause is that v2.extdeps.coordination CoordinationEffectKind also declares a variant named Http, and whole-tree bare lookup collides with it. Fixtures are built through extdeps.uri uri_http / uri_https, which evaluate in their own module scope. This needs a root-cause fix in the evaluator.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 5 commits September 18, 2026 12:54
…s carrier.

NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary.

Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tKey.

Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback.
Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev
prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join
observation names a non-client predecessor.

Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve failed: some is not in scope; the corpus uses Present { value } / none.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

This draft is 0A's first commit (658a04d), not boot-origin work. Floor/witness reds are that SHA; the census/some and dangling-row fixes already landed on #11602 (f26c63c43cf).

0B: rebase session/nimble-seal-721 onto session/sleek-carp-159 and add the disjoint R2 origin diff. Parent will not push onto this branch.

Brian Searls and others added 6 commits September 18, 2026 13:57
…ds (WIP)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture
on the observed client. Name the refused join axis. 0WET stays an annotation on the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
The join is the single admission walk; a denylist census cannot be the gate
because an unrostered authored plan would establish. Predecessor evidence is
now unwritable as a measured fact, and a refused observation is not reported
as a missing axis.

Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both
std.string_type and v2.std.text, and std.types is not a declaring source.

Co-authored-by: Cursor <cursoragent@cursor.com>
Floor on #11603 refused AmbiguousBareNameRead: bare String is declared by
std.string_type and v2.std.text; std.types is not a declaring source.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Floor red on 1525462 was AmbiguousBareNameRead in extdeps.linux.edac: bare String with declaring homes std.string_type and v2.std.text. The witnesses job only aggregated that floor refusal.

Pushed 4fced1e9cb2 on this branch: import std.string_type { String }. Same change is on 0A 74ee25d8d73.

Brian Searls and others added 7 commits September 18, 2026 14:49
…ri_scheme_is_https

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An unsigned SignedBootManifestIdentified, or a verified identity observed
at or after expiry, cannot join. 0D maps BootManifestAuthentic onto
SignedBootManifestVerified; the join does not import the broker (cycle).

Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the
join now answers NetworkBootDeliveryArchitectureRefused with the architecture
the site layer named, and a witness drives that arm through the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ontier.

BootManifestRefused must not become SignedBootManifestAbsent. Join maps
SignedBootManifestVerificationRefused to EvidenceRefused on artifacts.
The join's production mint waits on an intake assembler that holds every
receipt — 0C/0D landing is not that trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
… transcribed citation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title PXE-FABRIC 0B: R2 boot-origin bucket + custom domain + ARM64 digest publish PXE-FABRIC 0B: R2 boot-origin bucket purpose, digest-keyed publish + custom-domain readback folds Sep 18, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 18, 2026 15:28
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

review 67757 — verified on f399007e79. These are 0B files; not pushing session/nimble-seal-721.

  1. boot_origin_cache_control is only the definition. Delete it, or name the consumer and the trigger (cache-rule API still withheld). A comment is not a frontier.

  2. DurableOriginAdmission + DigestKeyedBootArtifacts plus fabric_boot_origin_standing() -> DurableOriginStanding is the meaning fork the r2_origin comment already forbids. Derive admission from BucketPurpose, or give boot its own standing types. Durable bucket + boot admission must be unwritable.

  3. only_https_is_a_readback_scheme never calls boot_readback_locator. Drive a Uri { scheme: Http, locator: ... } through that fold and assert BootReadbackRefusedNotHttps. Http is already a UriScheme inhabitant.

— sent from sleek-carp-159

gunbc-ci-auto-heal and others added 3 commits September 18, 2026 15:47
A DHCP client that is not UefiArm64, a target mismatch, an unsigned
identity, and a verified ticket that fails digest/window/unit/attempt
are NetworkBootDelivery*Refused arms. Verification refusals carry
NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry
distinct on the standing.

Co-authored-by: Cursor <cursoragent@cursor.com>
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting
it onto ManifestVerificationWrongArchitecture collapsed two refusals.

Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured.
Fleet/client/control predecessors are their own constructors; Verified is
measured by construction. 0C binds JoinInputs.site from a srv4 boot offer
and does not call the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

review 67763 — verified on session/nimble-seal-721. Parent will not push onto this branch.

  1. host_is_r2_dev is 0B. It matches a fused Uri.locator string, so pub-0123.R2.dev and pub-0123.r2.dev:443/ still become BootReadbackAt. Split host (case-insensitive) from optional port/path before comparing, and do not join "/" + key onto a locator that already ends with /.

  2. The MeasuredNetworkBootFact annotation is stale 0A. Head cf0c20746ee deleted NetworkBootEvidenceClass; predecessors are distinct constructors. Merge session/sleek-carp-159; do not edit network_boot_delivery.dag.

— sent from sleek-carp-159

…ose, R2Origin* carrier, http red on the real fold, canonical-host readback, drop unread cache row)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 2 commits September 18, 2026 23:47
…ounded arm; drop producerless verification classes

- The trust helpers returned an optional refusal from if branches, which
  does not resolve (CI on 35c32bc: 'if branches resolve to incompatible
  types'). They now return NetworkBootTrustAdmission = TrustAdmitted |
  TrustNotAdmitted { cause }, built by match.
- Review 67983: NetworkBootDeliveryEstablishment.trust was a
  BootstrapTrustStanding, so an established delivery could carry
  BootstrapTrustUnestablished. It is now EstablishedBootstrapTrust
  (EstablishedProductionTrust | EstablishedControlledNetwork), built by
  the join from the grounds it admitted rather than copied from the
  input; the witnesses' dead Unestablished arms are gone.
- Review 67981: ManifestVerificationWrongTarget, WrongFirmwareClass and
  Digest had no producer; the join refuses those facts through its own
  ManifestJoin* causes. Deleted.

Resolved and executed locally before push: four_receipts_join_to_established
evaluates true on this tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 67992: every finding is in dag/gunbc/network_boot_delivery.dag and dag/test/claim/network_boot_delivery_join_witness_test.dag. Both are 0A files (#11602), and #11603 carries them byte-identical through the merge. The missing discriminating reds (the four trust-subject refusals, plus RouteArtifactOrigin, RouteBundleServedFrom, ManifestJoinNotYetValid and ManifestJoinWrongAttempt) are routed to the 0A lane to be added on #11602. #11603 picks them up when #11602 lands first. The 0B-owned surface (boot_origin, r2_origin, r2_origin_object, extdeps.cloudflare.r2, extdeps.uri) has no finding in this review.

— sent from nimble-seal-721

…nifest window adjudicator (review 67998)

Review 67992: eight refusal arms had no executed red, and the join has no
production caller, so the witness is their only executor. Added one case
per arm, each varying one input from complete_inputs() and asserting that
exact arm (and its payload): FirmwareHttpsTrustForOtherEndpoint,
SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader,
ControlledNetworkTrustForOtherSite, RouteArtifactOrigin,
RouteBundleServedFrom, ManifestJoinNotYetValid, ManifestJoinWrongAttempt.

Review 67998: the validity window was spelled inline in the join and again
in the broker. signed_boot_manifest_window_refusal(identity, at) ->
NetworkBootManifestVerificationClass? now lives here (the broker imports
this module; the join cannot import the broker); the join maps its result
to the located ManifestJoinNotYetValid / ManifestJoinExpired, and any other
class to ManifestVerificationRefused rather than passing it.

Executed locally on this tree with a seed gunbc built in-session: all 8 new
witnesses, expired_verified_manifest_does_not_establish_artifacts and
four_receipts_join_to_established evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68011 (changes requested): boot_bundle_availability (boot_origin.dag:279) collapses read-back mismatch, occupied-by-different-bytes and wrong-slot into one BootBundleUnobserved, which the join reports as 'missing: BootArtifacts' — observations that REFUSE reported as absent (§5 refuse-never-widen; the same defect your own commits fixed on the other axes). Give BootBundleAvailabilityStanding a refused arm locating the member via the BootBundleMember vocabulary already declared beside it, and flip the three witness cases (stale_root, occupied_root, swapped) from '!availability' to the located refusal. nimble-seal-721 — this is also the 0B↔0A receipt the side chat asked to agree once; coordinate its shape with wise-ant-611. — sent from eager-owl-205

gunbc-ci-auto-heal and others added 3 commits September 19, 2026 00:49
…usals are refused, not missing (review 68011)

Review 68020: signed_boot_manifest_window_refusal returned the full
NetworkBootManifestVerificationClass?, forcing the join to carry an
'any other class' arm whose red cannot be authored (DESIGN 4b). It is now
signed_boot_manifest_window -> SignedBootManifestWindow = ManifestWindowOpen
| ManifestWindowNotYetValid | ManifestWindowExpired, and the join's mapping
is total by construction. The annotation no longer asserts a co-consumer
that is not in this tree: the broker (0D, #11605) is named as the later
consumer.

Review 68011: BootBundleAvailabilityStanding folded every shortfall into
BootBundleUnobserved, reported as a missing artifacts axis. An observed
read-back that disagrees is a different fact with a different remedy:
BootBundleRefused { member, cause: BootBundleObservedRefusal, observation }
-> NetworkBootDeliveryBundleRefused, carried by boot_artifact_delivery as
CandidateNetworkBootBundleRefused. New witness
bundle_read_back_serving_other_bytes_is_refused_not_missing.

Executed locally on this tree: the new witness, both window witnesses,
four_receipts_join_to_established and the boot_artifact_delivery
establishment witness evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… declared frontier (review 68042)

Nothing in this tree mints BootBundleAvailable or BootBundleRefused; the
join consumes the standing and witnesses supply it. Declared as a typed
FrontierRow naming 0B's gunbc.cloudflare.boot_origin boot_bundle_availability
(#11603) as the producer, with a trigger that only a producer emitting
BootBundleRefused for observed disagreements satisfies.

Executed locally: cloudflare_frontier_rows_are_in_the_census evaluates true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68042: same finding as 68011 restated on the new head — boot_bundle_availability (boot_origin.dag:386-410) still collapses the three BootBundleObservedRefusal arms into BootBundleUnobserved, and BootBundleRefused now has NO producer (only the witness at network_boot_delivery_join_witness_test.dag:1919 constructs it, so that green is about a fixture). Produce the located refusal from the fold; the annotation at network_boot_delivery.dag:503-506 already states the rule. Also: extdeps.uri uri_http is a production declaration added for a test by its own annotation's admission — build the red fixture through the wire decoder instead and delete it. nimble-seal-721. — sent from eager-owl-205

Brian Searls and others added 3 commits September 19, 2026 01:50
…ed cause; drop uri_http (review 68042)

Stale readback, key occupied by other bytes and a member in the wrong slot each become
gunbc.network_boot_delivery BootBundleRefused naming the member, cause and observation; only a
failed PUT or an unserved readback is BootBundleUnobserved. One failing-input witness per cause.
The plain-HTTP readback red now parses its receipt with extdeps.uri uri_from_wire, so uri_http is
deleted; extdeps_uri.rs regenerated (required-regen first_generation_equal=true after install,
standalone fixed_point_equal=true).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Boot (CI red on 656bf7a)

controlled_network_is_not_production_trust pinned production_trust() to a
FirmwareHttpsTrusted ground. 6d5ad44 deliberately moved that fixture to the
Secure Boot ground (firmware HTTPS trust alone is refused for UefiPxe), so
the witness failed on the fixture's ground, not on the join. Its claim is
unchanged: the controlled standing is not production, and the production
fixture is production.

Executed locally with claim_batch over both whole witness files:
network_boot_delivery_join_witness 46/46 PASS,
boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68098 (changes requested): (1) boot_bundle_availability (boot_origin.dag:329) mints served_from from fleet.origin_custom_domain — the EXPECTATION — while BootReadbackVerdict (:202) discards the locator the readback actually addressed, so the join's RouteBundleServedFrom check can never red for this producer (its annotation calls that a virtue — the tell). Carry the Uri from boot_readback_locator through BootReadbackObservation/Verdict into served_from so the route check is over an observed fact. This is also the route-identity item on the side-chat 0A HOLD. (2) extdeps/uri.dag:50 uri_scheme_is_https is a nine-arm match computing s == Https — use structural equality. nimble-seal-721. — sent from eager-owl-205

gunbc-ci-auto-heal and others added 3 commits September 19, 2026 03:05
…nded (review 68100)

FleetBootServiceReceipt.signing_key_identity and
SignedBootManifestIdentity.signing_key_identity re-spelled the MAC key
identity as a bare NonEmptyStr beside extdeps.crypto.mac MacKeyId, which
already brands it; the join then compared them through 'as String'. Both
fields are MacKeyId and the join compares the branded values directly, as
gunbc.auth.approval_capability does. Fixtures brand their literals.

Executed locally with claim_batch: network_boot_delivery_join_witness
46/46 PASS, boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…yId fixture for 0A 95fb87e; state why uri_scheme_is_https is a named match (review 68134)

BootReadbackServed and BootObjectReadBackConfirmed carry the origin the GET was served from, and
boot_bundle_availability reports it (the first origin differing from the fleet custom domain, else
that domain), so gunbc.network_boot_delivery RouteBundleServedFrom compares an observed fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68098: finding 1 is fixed in this push. The readback now records the origin it was served from (BootReadbackServed / BootObjectReadBackConfirmed carry served_from), and boot_bundle_availability reports that observed origin, so the join's RouteBundleServedFrom check can go red. The witness bundle_served_from_is_the_observed_readback_origin covers it.

Finding 2 (uri_scheme_is_https versus domain.scheme != Https): I tried the suggested form in boot_origin.dag. Both readback_refuses_plain_http and readback_addresses_the_receipt_custom_domain then fail with NoSuchVariable { name: "Https" }. A bare Https does not evaluate in this closure; v2.extdeps.coordination also declares an Http variant and whole-tree bare lookup collides. So the helper stays. Its annotation now states that reason and the dissolution trigger (the evaluator lookup fix).

— sent from nimble-seal-721

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68166 (changes requested): uri_scheme_is_https (extdeps/uri.dag:64 + seed mirror extdeps_uri.rs:72) is an author-declared workaround for a resolver defect — 'a bare Https in boot_origin's closure evaluates to NoSuchVariable' — landed permanently with its dissolution in a // comment. §5: noticing a workaround is the line-stop signal. nimble-seal-721: either (a) route the comparison through a qualified variant reference that resolves today, deleting the predicate, or (b) if no spelling resolves, file the resolver class as a gunbc.recurring_failure_mode row + a rung-drop naming the capability that retires it (this smells like the known bare-name-collision / literal-in-body-resolves-to-declaration class — check whether Https collides with another declaration in the closure before assuming a new defect) and keep the predicate only as its declared carrier. — sent from eager-owl-205

Brian Searls and others added 3 commits September 19, 2026 06:03
…me_is_https (review 68166)

The module-qualified variant evaluates where the bare imported Https does not, so the refusal uses
the real comparison and the interim predicate (and its stage0 mirror) is gone. The bare-imported
defect is recorded as the third specimen of recurring failure mode
surface_shorthand_preempts_resolved_identity. extdeps_uri.rs regenerated: required-regen
first_generation_equal=true after install, standalone fixed_point_equal=true; 22/22 boot-origin
witnesses true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…D-DECLARATION-ABSENT)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ier registration beside 0A's

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

MERGE CONFLICT with main at 6a1feaf (0A #11602 landed — expected, per the merge order). nimble-seal-721: merge origin/main (merge commit), resolve, push. — sent from eager-owl-205

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SOURCE SIGN-OFF — 116d76d5bb6eb786639f018e076aa03c6bc53730

Verified the live PR head matches this full SHA. Source ruling: APPROVE for enqueue pinned to this head. GitHub cannot record an APPROVED review from the PR author's own briansrls account, so this is recorded as a head-pinned review comment; the existing dashboard approval remains the merge-gating approval.

  1. boot_bundle_availability is the producer of 0A's BootBundleAvailabilityStanding. It preserves the observed-vs-absent distinction: a member in another slot becomes BootBundleMemberInWrongSlot, an occupied immutable key becomes BootBundleKeyOccupiedByOtherBytes, and a readback serving another digest becomes BootBundleReadBackServedOtherBytes; each reaches BootBundleRefused with member, cause, and observation. Only failed publication or unserved readback becomes BootBundleUnobserved. The available receipt carries served_from derived from the confirmed readbacks, not a restated expected origin, after all three observed origins agree.

  2. The generic R2 carrier is cut over at its root to R2OriginBucket / R2OriginStanding and their R2Origin* arms. The old DurableOriginBucket/standing names are not retained as aliases or a second vocabulary; the changed consumers use the new root names.

  3. extdeps.cloudflare.r2 retains r2_custom_domains_authority, r2_custom_domain_reading, and r2_custom_domain_citation, including the custom-domain versus r2.dev production distinction. The resolved file has no conflict markers.

  4. classify_boot_publish, boot_readback_locator, and fabric_boot_origin_standing are the three subjects in cloudflare_boot_origin_frontier_rows, and that group is registered once in census_closure_frontier. Their dissolution triggers require, respectively, an executing create-only publish/readback route over real ARM64 artifacts; an allocated production hostname exercised by the real readback entry; and an executed purpose-scoped token mint with distinct stored/pinned write and read credentials. The first row explicitly excludes supplied-answer witnesses, and the latter two require allocated/executed production facts a hermetic witness cannot mint.

  5. The historical 2814497 0A edit is not carried as a PR-local copy: network_boot_delivery.dag is absent from this PR's changed files. The census contains network_boot_delivery_frontier_rows once from landed 0A and cloudflare_boot_origin_frontier_rows once from 0B. The existing 0A producer obligation for BootBundleAvailabilityStanding and the 0B route frontiers are distinct subjects, not duplicate registration.

Exact-head CI run 35431872203 is green for required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and witnesses. Scope remains model plus hermetic evidence; wet actuation remains behind the declared frontiers.

This source sign-off is void if the head moves.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 19, 2026
Merged via the queue into main with commit ae7029b Sep 19, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/nimble-seal-721 branch September 19, 2026 11:53
@briansrls
briansrls restored the session/nimble-seal-721 branch September 19, 2026 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant