Skip to content

PXE-FABRIC 0C: site UEFI ARM64 DHCP/ProxyDHCP edge + reachability - #11604

Merged
gunbai-bot[bot] merged 81 commits into
mainfrom
session/fierce-ferret-123
Sep 19, 2026
Merged

gunbai-bot[bot] merged 81 commits into
mainfrom
session/fierce-ferret-123

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

PXE-FABRIC 0C (parent: sleek-carp-159). Depends on #11602: this branch merges session/sleek-carp-159, which carries SitePxeEdge, site_pxe_edge_standing and extdeps.firmware.ipxe. Land #11602 first. After that, this diff is only the three files below.

What this adds

  • gunbc.site_uefi_arm64_pxe_edge consumes gunbc.network_boot_delivery site_pxe_edge_standing:
    • Discovery standing comes from an observed offer (SiteDhcpOfferObservation). A native DHCP, ProxyDHCP or relay mode counts only when an observed offer carries the chainloader filename. An address-only offer is what mtcollins1's segment gives today (no option 67), and it maps to SiteDiscoveryUnobserved.
    • Reachability from the boot network is three separate probes: DNS resolution, default route and global HTTPS fetch. GlobalHttpsEndpointReachable is created only when all three succeed, and any refusal names the missing axes.
    • Admission refuses unknown architectures and unknown machines. An option-93 code other than 11 is refused as read and is never mapped to an Architecture. A MAC that is not on the roster is refused before the edge's standing is evaluated.
    • ProxyDHCP config is rendered through extdeps.formats.dnsmasq, which is used only as a format. The rendered config is not evidence. It has one dhcp-boot, gated on both the efi-arm64 tag and the known-machine tag, and it cites extdeps.firmware.ipxe ipxe_chainloading_authority.
  • extdeps.formats.dnsmasq gains dhcp-host=<mac>,set:<tag> (DnsmasqDhcpHostSetTag). DnsmasqDhcpBootTag becomes the multi-tag DnsmasqDhcpBootTags, which matches upstream's repeatable tag: syntax. The old variant had no constructors anywhere.
  • The measured client fact is consumed unchanged: mtcollins1_host_nic_mac and mtcollins1_pxe_arch_code. No UefiPxe is authored.

Evidence

  • test.claim.site_uefi_arm64_pxe_edge_witness: 10 hermetic witnesses. One of them runs the real route: mtcollins1's measured MAC and arch code, on its measured address-only segment, is refused on discovery, not on identity.
  • I ran them locally through /cargo-target/release/gunbc run with a scratch driver: exit 0. A mutation control (roster check forced to true, and the reachability requirement loosened) exited 1 and named exactly unknown_machine_gets_no_boot, dns_failure_alone… and missing_default_route_alone….
  • v1_src_dag_parse: parse-clean.

Not touched: mtcollins1_boot, approval_*, srv1 roadmap.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 18, 2026 12:54
…s carrier.

NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary.

Co-authored-by: Cursor <cursoragent@cursor.com>
…boot-network reachability

gunbc.site_uefi_arm64_pxe_edge consumes gunbc.network_boot_delivery
site_pxe_edge_standing. Discovery (native DHCP / ProxyDHCP / relay) comes
from an observed offer carrying the chainloader filename, never from
authored config. Global HTTPS reachability comes from three independent
boot-network probes (DNS, default route, HTTPS fetch). Unknown option-93
codes and machines not on the roster are refused before any standing is
computed. The ProxyDHCP config is rendered through extdeps.formats.dnsmasq,
which gains dhcp-host set-tag and multi-tag dhcp-boot. It boots only the
aarch64 iPXE chainloader and only for known machines.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 18, 2026 13:08
gunbc-ci-auto-heal and others added 4 commits September 18, 2026 13:28
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tKey.

Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback.
Co-authored-by: Cursor <cursoragent@cursor.com>
…tion (review 67714 finding 1)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Re review 67714:

  1. Fixed in the latest commit. gunbc.site_uefi_arm64_pxe_edge uefi_arm64_client_arch_code is now extdeps.provisioning.dhcp_client_arch dhcp_processor_architecture_code(a: UefiArm64). That is the same authority network_boot_delivery observed_client_is_uefi_arm64 uses, so the dhcp-match rendering and the admission check both read the RFC 4578 value. The mtcollins1 observation is now only compared against it, in the mtcollins1_on_its_measured_segment_is_not_yet_admitted witness. All 10 edge witnesses pass again locally.

2 and 3 (gunbc.network_boot_predecessor_census and its witness, extdeps.firmware.ipxe ipxe_https_authority, extdeps.cloudflare.r2 r2_custom_domain_citation) are not in this lane's diff. They come from #11602 (PXE-FABRIC 0A), which this branch merges because it depends on SitePxeEdge. I've sent the findings to that PR's owner. Once #11602 lands, this PR's diff is only the dnsmasq format, the edge module and its witness.

— sent from fierce-ferret-123

Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev
prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join
observation names a non-client predecessor.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbc-ci-auto-heal and others added 4 commits September 18, 2026 13:52
Resolve failed: some is not in scope; the corpus uses Present { value } / none.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Re review 67725: none of its three findings touch this lane's files. They are in gunbc.network_boot_predecessor_census (CitedUpstreamShape) and gunbc.network_boot_delivery (the join refusal location, and the WET acceptance subject), which this branch carries from #11602 (PXE-FABRIC 0A). I have sent them to that PR's owner and will merge the fix into this branch when it lands.

— sent from fierce-ferret-123

gunbc-ci-auto-heal and others added 2 commits September 18, 2026 14:11
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture
on the observed client. Name the refused join axis. 0WET stays an annotation on the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
…th a consumed build target

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Re review 67736: every finding is in gunbc.network_boot_predecessor_census, its join gate in gunbc.network_boot_delivery, and their witness. All of those come from #11602 (PXE-FABRIC 0A), which this branch carries, not from this lane's edge files. I have sent them to that PR's owner and will merge the fix here when it lands.

— sent from fierce-ferret-123

The join is the single admission walk; a denylist census cannot be the gate
because an unrostered authored plan would establish. Predecessor evidence is
now unwritable as a measured fact, and a refused observation is not reported
as a missing axis.

Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both
std.string_type and v2.std.text, and std.types is not a declaring source.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 6 commits September 18, 2026 15:00
An unsigned SignedBootManifestIdentified, or a verified identity observed
at or after expiry, cannot join. 0D maps BootManifestAuthentic onto
SignedBootManifestVerified; the join does not import the broker (cycle).

Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the
join now answers NetworkBootDeliveryArchitectureRefused with the architecture
the site layer named, and a witness drives that arm through the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ontier.

BootManifestRefused must not become SignedBootManifestAbsent. Join maps
SignedBootManifestVerificationRefused to EvidenceRefused on artifacts.
The join's production mint waits on an intake assembler that holds every
receipt — 0C/0D landing is not that trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
A DHCP client that is not UefiArm64, a target mismatch, an unsigned
identity, and a verified ticket that fails digest/window/unit/attempt
are NetworkBootDelivery*Refused arms. Verification refusals carry
NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry
distinct on the standing.

Co-authored-by: Cursor <cursoragent@cursor.com>
firmware_https_trust_refusal and secure_boot_trust_refusal returned the
Absent pattern constructor from an if branch, which resolves as
Coproduct(Optional) against the Present branch's payload type; the corpus
idiom is none (CI run on 6d5ad44: 'if branches resolve to incompatible
types').

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
…uses an unparseable one) and the chainloader tftp_root

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 2 commits September 18, 2026 23:28
…onfig comment cites; no free filename parameter (review 67980)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Re review 67980: fixed in 220766a. site_edge_proxy_dhcp_config and site_edge_proxy_dhcp_directives no longer take a free filename. The dhcp-boot target is ipxe_arm64_efi_snponly.image, the same extdeps.firmware.ipxe row the rendered comment cites, so the config cannot name one image and serve another. That also means IpxeBuildTarget now reaches the program through the boot line, not only through comment text.

ArchitectureChainloader.filename_hint is the observed-side counterpart: site_discovery_outcome compares the filename an offer actually carried against the transport. It is an observation compared with a declaration, not a third authoring of the image. In #11607 the converge gate already refuses a pinned transport whose filename is not ipxe_arm64_efi_snponly.image.

v1_src_dag_parse is clean. Local witness runs are blocked by #11602's type error in network_boot_delivery (reported to its owner), so CI is the first execution.

— sent from fierce-ferret-123

gunbc-ci-auto-heal and others added 4 commits September 18, 2026 23:43
…ounded arm; drop producerless verification classes

- The trust helpers returned an optional refusal from if branches, which
  does not resolve (CI on 35c32bc: 'if branches resolve to incompatible
  types'). They now return NetworkBootTrustAdmission = TrustAdmitted |
  TrustNotAdmitted { cause }, built by match.
- Review 67983: NetworkBootDeliveryEstablishment.trust was a
  BootstrapTrustStanding, so an established delivery could carry
  BootstrapTrustUnestablished. It is now EstablishedBootstrapTrust
  (EstablishedProductionTrust | EstablishedControlledNetwork), built by
  the join from the grounds it admitted rather than copied from the
  input; the witnesses' dead Unestablished arms are gone.
- Review 67981: ManifestVerificationWrongTarget, WrongFirmwareClass and
  Digest had no producer; the join refuses those facts through its own
  ManifestJoin* causes. Deleted.

Resolved and executed locally before push: four_receipts_join_to_established
evaluates true on this tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… config renders the roster admission gates on (review 67995)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Re review 67995: fixed in fcee9bf.

  • The boot filename has one source. SiteEdgeRoster no longer carries a bootstrap_transport; it carries only what the edge authors, chainloader_digest and tftp_root. The ARM64 transport comes from site_edge_arm64_chainloader_transport, whose filename_hint is ipxe_arm64_efi_snponly.image. Admission checks observed offers against that derived transport, and the rendered dhcp-boot target reads the same value through site_edge_offered_filename. Changing the build target now changes both, and the roster cannot re-spell the name.
  • The config renders the roster admission gates on. site_edge_proxy_dhcp_config(network_address, roster) takes its known-machine tags from roster.known_client_macs and its boot line from the roster's derived transport.
  • Witnesses: the fixture's chainloader_filename is now ipxe_arm64_efi_snponly.image rather than a literal, and the config witness renders healthy_roster(). A non-aarch64 chainloader can no longer be constructed at this interface, so a_non_arm64_chainloader_is_refused_by_architecture is removed: its red is no longer authorable. The client-architecture refusal keeps its own witness.

All edge witnesses pass locally with gunbc run on this head (with #11602 15a2efc merged), and v1_src_dag_parse is clean.

— sent from fierce-ferret-123

gunbc-ci-auto-heal and others added 12 commits September 19, 2026 00:09
…rvation; the config renders only what the edge authors

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e one place the boot-network axes are enumerated (review 68004)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nifest window adjudicator (review 67998)

Review 67992: eight refusal arms had no executed red, and the join has no
production caller, so the witness is their only executor. Added one case
per arm, each varying one input from complete_inputs() and asserting that
exact arm (and its payload): FirmwareHttpsTrustForOtherEndpoint,
SecureBootTrustForOtherTarget, SecureBootTrustForOtherChainloader,
ControlledNetworkTrustForOtherSite, RouteArtifactOrigin,
RouteBundleServedFrom, ManifestJoinNotYetValid, ManifestJoinWrongAttempt.

Review 67998: the validity window was spelled inline in the join and again
in the broker. signed_boot_manifest_window_refusal(identity, at) ->
NetworkBootManifestVerificationClass? now lives here (the broker imports
this module; the join cannot import the broker); the join maps its result
to the located ManifestJoinNotYetValid / ManifestJoinExpired, and any other
class to ManifestVerificationRefused rather than passing it.

Executed locally on this tree with a seed gunbc built in-session: all 8 new
witnesses, expired_verified_manifest_does_not_establish_artifacts and
four_receipts_join_to_established evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…usals are refused, not missing (review 68011)

Review 68020: signed_boot_manifest_window_refusal returned the full
NetworkBootManifestVerificationClass?, forcing the join to carry an
'any other class' arm whose red cannot be authored (DESIGN 4b). It is now
signed_boot_manifest_window -> SignedBootManifestWindow = ManifestWindowOpen
| ManifestWindowNotYetValid | ManifestWindowExpired, and the join's mapping
is total by construction. The annotation no longer asserts a co-consumer
that is not in this tree: the broker (0D, #11605) is named as the later
consumer.

Review 68011: BootBundleAvailabilityStanding folded every shortfall into
BootBundleUnobserved, reported as a missing artifacts axis. An observed
read-back that disagrees is a different fact with a different remedy:
BootBundleRefused { member, cause: BootBundleObservedRefusal, observation }
-> NetworkBootDeliveryBundleRefused, carried by boot_artifact_delivery as
CandidateNetworkBootBundleRefused. New witness
bundle_read_back_serving_other_bytes_is_refused_not_missing.

Executed locally on this tree: the new witness, both window witnesses,
four_receipts_join_to_established and the boot_artifact_delivery
establishment witness evaluate true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… declared frontier (review 68042)

Nothing in this tree mints BootBundleAvailable or BootBundleRefused; the
join consumes the standing and witnesses supply it. Declared as a typed
FrontierRow naming 0B's gunbc.cloudflare.boot_origin boot_bundle_availability
(#11603) as the producer, with a trigger that only a producer emitting
BootBundleRefused for observed disagreements satisfies.

Executed locally: cloudflare_frontier_rows_are_in_the_census evaluates true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Boot (CI red on 656bf7a)

controlled_network_is_not_production_trust pinned production_trust() to a
FirmwareHttpsTrusted ground. 6d5ad44 deliberately moved that fixture to the
Secure Boot ground (firmware HTTPS trust alone is refused for UefiPxe), so
the witness failed on the fixture's ground, not on the join. Its claim is
unchanged: the controlled standing is not production, and the production
fixture is production.

Executed locally with claim_batch over both whole witness files:
network_boot_delivery_join_witness 46/46 PASS,
boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nded (review 68100)

FleetBootServiceReceipt.signing_key_identity and
SignedBootManifestIdentity.signing_key_identity re-spelled the MAC key
identity as a bare NonEmptyStr beside extdeps.crypto.mac MacKeyId, which
already brands it; the join then compared them through 'as String'. Both
fields are MacKeyId and the join compares the branded values directly, as
gunbc.auth.approval_capability does. Fixtures brand their literals.

Executed locally with claim_batch: network_boot_delivery_join_witness
46/46 PASS, boot_artifact_delivery_witness 33/33 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…-123

# Conflicts:
#	dag/gunbc/census_closure_frontier.dag
…is derived from that same address (review 68314)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Re review 68314: fixed in c43c87c.

  • Upstream grammar: extdeps.formats.dnsmasq DnsmasqDhcpBootTags now carries server_name and server_address, rendering dnsmasq's dhcp-boot=[tag:...,]file,servername,serveraddress.
  • One source for the TFTP server: SiteEdgeRoster no longer carries a free tftp_root: Uri. It carries tftp_server_name and tftp_server_address: Ipv4Address. The transport's tftp_root, which the join compares to the manifest's UefiPxe root, is derived from that address by site_edge_tftp_root, and the rendered dhcp-boot line names the same server and address. The route the model checks is now the route the config directs firmware to.
  • Witnesses: the config witness pins dhcp-boot=tag:efi-arm64,tag:onboarding-known,snponly.efi,srv4,192.168.1.196, and a new admitted_edge_tftp_route_is_the_rendered_server asserts that an admitted edge's transport tftp_root is tftp://192.168.1.196/, the address the config renders.

All edge witnesses pass locally with gunbc run on this head.

— sent from fierce-ferret-123

…8331)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Re review 68331: fixed in 0a54d18. extdeps.formats.dnsmasq DnsmasqDhcpBootTags now carries first_tag: String plus more_tags: List<String>, so a tagged dhcp-boot has at least one tag by construction. The renderer always emits tag:<first_tag>, before any further tags. An untagged boot line, which applies to every client on the segment, is no longer writable through this arm. If one is ever needed it would have to be a separate, deliberately named variant. The edge builds it as first_tag: site_edge_arm64_tag, more_tags: [site_edge_known_tag], and the rendered line is unchanged. All edge witnesses pass locally.

— sent from fierce-ferret-123

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SOURCE SIGN-OFF — 0a54d18a0b052290d4e27304e5f1d5199b72a939

Verified the live PR head matches this full SHA. Approved for enqueue pinned to this head.

  1. Route identity is independent of the fleet expectation. BootNetworkReachabilityObservation carries the broker endpoint and artifact origin that the site probes targeted, and global_https_reachability_from_boot_network copies those observed fields into GlobalHttpsEndpointReachable; no FleetBootServiceReceipt is an input to the site fold. The TFTP route is likewise not copied from the fleet: site_edge_tftp_root derives it from the site roster's TFTP server address, and both ArchitectureChainloader.tftp_root and the rendered dhcp-boot line consume that same address. Therefore 0A can refuse a foreign broker, artifact origin, or manifest TFTP route. The wet claim that srv4 actually realizes this roster remains the separately stacked #11607 route, not a claim of this model-only PR.

  2. Review 68004 is discharged. boot_network_reachability_missing(obs) is the one axis partition. global_https_reachability_from_boot_network mints GlobalHttpsEndpointReachable only when that list is empty; it does not restate DNS/default-route/HTTPS success as an independent conjunction. Failure and unobserved remain distinct typed deficits.

  3. Site identity is not compared through inline string casts. The site model carries SiteIdentity; the inherited 0A join performs both edge-site and client-site joins through site_identity_eq.

  4. 0A is inherited byte-for-byte from main. dag/gunbc/network_boot_delivery.dag has blob 24d497e8faf4f17d0511561c99f401b268a20ceb on both this head and main, and dag/test/claim/network_boot_delivery_join_witness_test.dag has blob f857db303180e1d8ab2de7bbdebf057ecd628303 on both. Neither file is in this PR's five-file changed set.

  5. The two production routes this module provides but does not execute are typed frontiers: site_edge_client_admission requires a real observed boot offer bound into NetworkBootJoinInputs.site, explicitly excluding witness-supplied offers; site_edge_proxy_dhcp_config requires the #11607 fleet-converge writer to realize the config on srv4. site_uefi_arm64_pxe_edge_frontier_rows is imported and included once in census_closure_frontier_row_groups.

Exact-head CI run 35435372091 is green for required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and witnesses.

This source sign-off is void if the head moves.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 19, 2026
Merged via the queue into main with commit 3ee97a8 Sep 19, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/fierce-ferret-123 branch September 19, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant