Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
81 commits
Select commit Hold shift + click to select a range
658a04d
Establish fleet HTTPS network-boot as a join of the existing four-axi…
Sep 18, 2026
7e6ed21
PXE-FABRIC 0C: site UEFI ARM64 discovery edge with observed DHCP and …
Sep 18, 2026
041ccc9
Bind network-boot join to existing architecture and DHCP authorities.
Sep 18, 2026
2a64d22
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
a09d8af
Keep the 0WET subject a parameter: propose Mt. Jade, not a minted Uni…
Sep 18, 2026
8722188
Edge admission reads the RFC 4578 arch code, not mtcollins1's observa…
Sep 18, 2026
a3bbed8
Consume the predecessor census in the network-boot join.
Sep 18, 2026
e2a2bf3
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
f26c63c
Spell the census optional as Present, not some.
Sep 18, 2026
9754417
Restore ipxe_chainloading_authority: the edge config cites it
Sep 18, 2026
0f5f9ce
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
4abce24
Address review 67724: locate join refusals, consume DHCP arch coproduct.
Sep 18, 2026
d8dec87
Merge #11602 head 4abce24b661; extdeps.firmware.ipxe is now edge-owne…
Sep 18, 2026
3920838
Address review 67731: evidence kind on receipts, refuse as its own arm.
Sep 18, 2026
74ee25d
Import String from std.string_type in extdeps.linux.edac.
Sep 18, 2026
2871513
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
3572a10
Establish artifacts only from a verified ticket, against observed time.
Sep 18, 2026
e18a3eb
Keep site architecture refusal located on the delivery join.
Sep 18, 2026
0784b71
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
926e897
Locate MAC-refused tickets on the artifacts axis; restate the join fr…
Sep 18, 2026
5ef8028
Refuse observed join mismatches; do not report them as missing axes.
Sep 18, 2026
44cfccf
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
73e18ae
Distinguish HMAC firmware-class refusal from architecture.
Sep 18, 2026
90b0d9e
Locate the edge architecture refusal; state consumers and triggers fo…
Sep 18, 2026
cf0c207
Make predecessor observations a distinct standing, not a field.
Sep 18, 2026
307b65e
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
53e1fb1
Keep why discovery did not answer: typed, located discovery refusals …
Sep 18, 2026
c98dad9
Join the site chainloader and fleet signing key, and return both witn…
Sep 18, 2026
4e85b0d
Join bootstrap trust and locate a missing site separately from missin…
Sep 18, 2026
0c20ad1
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
3093291
Drop join architecture refusals that first_slice already makes unwrit…
Sep 18, 2026
a3bff13
Read the HTTPS fetch probe once in boot-network reachability (review …
Sep 18, 2026
06ecfd8
Stop re-deriving DHCP class after the join has already required UefiA…
Sep 18, 2026
b8df6e4
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
42c877a
Delete unused discovery-hint and join-architecture constructors.
Sep 18, 2026
5117280
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
2e63728
Drop the deleted PresignedUrlAvailabilityFence arm
Sep 18, 2026
c01af8b
Split client, chainloader, and ticket architecture refusals.
Sep 18, 2026
f93470d
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
3f61bec
Split the edge architecture refusal into client-not-admitted and chai…
Sep 18, 2026
c9d199a
Keep site, fleet, manifest identity, and trust grade on an establishe…
Sep 18, 2026
c6fcc87
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
33d4b6c
Fix extra whitespace in the controlled-trust join witness.
Sep 18, 2026
7207225
Consume DhcpBootDirection for site discovery instead of renaming Nati…
Sep 18, 2026
32c9b6f
Reachability deficits carry their cause: failed with its observation,…
Sep 18, 2026
9b65125
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
925fd86
Witness uses SiteAnsweredDhcp { direction: ProxyDhcp } after 0A's dis…
Sep 18, 2026
3dc0ce0
Put ClientNetworkBootMode on the signed ticket identity and join it t…
Sep 18, 2026
8632d66
Mint bootstrap trust from independent HTTPS and Secure Boot observati…
Sep 18, 2026
7e02e27
Ground production bootstrap trust in a grounds coproduct and derive t…
Sep 18, 2026
a16ed27
Restore the extdeps.uri import that the axis-refusal commit overwrote
Sep 18, 2026
92f828b
network_boot_delivery: compare SiteIdentity through site_identity_eq …
Sep 18, 2026
2adc557
Edge ProxyDHCP config takes an extdeps.network.ipv4 Ipv4Address and r…
Sep 18, 2026
733dce9
network_boot_delivery: ObservedDhcpPxeClient annotation states what t…
Sep 18, 2026
014b358
network_boot_delivery: the join's unexecuted production route is a ty…
Sep 18, 2026
ac525e6
network_boot_delivery: manifest receipt on the establishment; site mi…
Sep 18, 2026
8d8edfb
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
6d5ad44
0A: trust grounds bound to boot mode and subject; route identity; bun…
Sep 18, 2026
3cce12a
Edge MACs are Eui48Address parsed from the measured observation; unex…
Sep 18, 2026
05fa7ba
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
9d71a89
Merge #11602 6d5ad44: edge chainloader carries tftp_root; boot-networ…
Sep 18, 2026
35c32bc
network_boot_delivery: optional if-branches return none, not Absent
Sep 18, 2026
0f3d01c
Merge branches 'main' and 'session/fierce-ferret-123' of https://gith…
Sep 18, 2026
220766a
dhcp-boot target derives from ipxe_arm64_efi_snponly, the image the c…
Sep 18, 2026
a9c0a88
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
15a2efc
0A: trust admission as a closed result; established trust has no ungr…
Sep 18, 2026
06e8c10
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 18, 2026
fcee9bf
Edge chainloader transport is derived from the iPXE build target; the…
Sep 19, 2026
87efd14
Split the authored SiteEdgeRoster from the per-admission SiteEdgeObse…
Sep 19, 2026
f541c32
GlobalHttpsEndpointReachable is minted from an empty deficit fold, th…
Sep 19, 2026
76253ce
0A: one discriminating witness per refusal arm (review 67992); one ma…
Sep 19, 2026
c3ad4cc
0A: closed manifest window result (review 68020); observed bundle ref…
Sep 19, 2026
656bf7a
network_boot_delivery: BootBundleAvailabilityStanding's producer is a…
Sep 19, 2026
5cfdea1
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 19, 2026
bee93bc
network_boot_delivery witness: production fixture's ground is Secure …
Sep 19, 2026
409e473
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 19, 2026
95fb87e
network_boot_delivery: signing_key_identity is MacKeyId, compared bra…
Sep 19, 2026
188f727
Merge remote-tracking branch 'origin/session/sleek-carp-159' into ses…
Sep 19, 2026
db84c3d
Merge remote-tracking branch 'origin/main' into session/fierce-ferret…
Sep 19, 2026
c43c87c
dhcp-boot names the TFTP server; the edge's tftp_root route identity …
Sep 19, 2026
0a54d18
A tagged dhcp-boot carries at least one tag by construction (review 6…
Sep 19, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions dag/extdeps/firmware/ipxe.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
module extdeps.firmware.ipxe

import std.types { NonEmptyStr }
import extdeps.uri { Uri, Https }
import extdeps.external_authority { ExternalAuthority }

data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "ipxe.org/docs"
}
}

data ipxe_chainloading_authority: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "ipxe.org/howto/chainloading"
}
}

// iPXE's own build grammar: `make <platform>/<image>` from src/, e.g. bin-arm64-efi/snponly.efi.
// snponly.efi drives the NIC through the firmware's SNP protocol instead of a native iPXE driver,
// which is the image the chainloading how-to names for UEFI.
type IpxeBuildTarget {
platform: NonEmptyStr
image: NonEmptyStr
}

data ipxe_arm64_efi_snponly: IpxeBuildTarget = IpxeBuildTarget {
platform: "bin-arm64-efi",
image: "snponly.efi",
}

fn ipxe_build_target_path(target: IpxeBuildTarget) -> NonEmptyStr {
join([target.platform as String, "/", target.image as String], "") as NonEmptyStr
}
16 changes: 13 additions & 3 deletions dag/extdeps/formats/dnsmasq.dag
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,17 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
}
}

// A TAGGED dhcp-boot CARRIES AT LEAST ONE TAG BY CONSTRUCTION (first_tag): an untagged dhcp-boot
// applies to every client on the segment, so an empty tag list would silently invert a restricted
// boot line into a permissive one.
type DnsmasqDirective =
DnsmasqComment { text: String }
| DnsmasqPort { value: Int }
| DnsmasqDhcpRangeProxy { network_address: String }
| DnsmasqDhcpMatchSet { tag: String, option: String, value: String }
| DnsmasqDhcpOptionForceTag { tag: String, option: String, value: String }
| DnsmasqDhcpBootTag { tag: String, target: String }
| DnsmasqDhcpHostSetTag { mac: String, tag: String }
| DnsmasqDhcpBootTags { first_tag: String, more_tags: List<String>, target: String, server_name: String, server_address: String }

data dnsmasq_protocol: LayoutProtocol = LayoutProtocol { indent_unit: "" }

Expand All @@ -36,8 +40,14 @@ fn dnsmasq_directive_line(d: DnsmasqDirective) -> String {
concat(concat(concat("dhcp-match=set:", tag), concat(",", option)), concat(",", value))
DnsmasqDhcpOptionForceTag { tag: tag, option: option, value: value } =>
concat(concat(concat("dhcp-option-force=tag:", tag), concat(",", option)), concat(",", value))
DnsmasqDhcpBootTag { tag: tag, target: target } =>
concat(concat("dhcp-boot=tag:", tag), concat(",", target))
DnsmasqDhcpHostSetTag { mac: mac, tag: tag } =>
concat(concat("dhcp-host=", mac), concat(",set:", tag))
DnsmasqDhcpBootTags { first_tag: first, more_tags: more, target: target, server_name: name, server_address: address } =>
join([
"dhcp-boot=tag:", first, ",",
fold(more, init: "", f: (acc, t) => concat(acc, concat(concat("tag:", t), ","))),
target, ",", name, ",", address,
], "")
}
}

Expand Down
2 changes: 2 additions & 0 deletions dag/gunbc/census_closure_frontier.dag
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ import gunbc.cloudflare.r2_token_mint { cloudflare_r2_token_mint_frontier_rows }
import extdeps.cloudflare.account_api_tokens { cloudflare_account_api_tokens_frontier_rows }
import extdeps.cloudflare.r2 { cloudflare_r2_frontier_rows }
import gunbc.network_boot_delivery { network_boot_delivery_frontier_rows }
import gunbc.site_uefi_arm64_pxe_edge { site_uefi_arm64_pxe_edge_frontier_rows }
import product.supplier.cloudflare_r2 { cloudflare_r2_supplier_frontier_rows }
import extdeps.backblaze.b2 { backblaze_b2_frontier_rows }
import extdeps.cloud.gcp.storage { gcs_storage_frontier_rows }
Expand Down Expand Up @@ -112,6 +113,7 @@ fn census_closure_frontier_row_groups() -> List<List<FrontierRow>> {
cloudflare_account_api_tokens_frontier_rows,
cloudflare_r2_frontier_rows,
network_boot_delivery_frontier_rows,
site_uefi_arm64_pxe_edge_frontier_rows,
cloudflare_r2_supplier_frontier_rows,
backblaze_b2_frontier_rows,
gcs_storage_frontier_rows,
Expand Down
Loading