Skip to content

PR #11602 rework (network boot join) - #11655

Closed
gunbai-bot[bot] wants to merge 27 commits into
mainfrom
pr11602
Closed

gunbai-bot[bot] wants to merge 27 commits into
mainfrom
pr11602

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session silent-carp-100.
Pushing to pr11602 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 27 commits September 18, 2026 12:54
…s carrier.

NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary.

Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tKey.

Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback.
Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev
prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join
observation names a non-client predecessor.

Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve failed: some is not in scope; the corpus uses Present { value } / none.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture
on the observed client. Name the refused join axis. 0WET stays an annotation on the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
The join is the single admission walk; a denylist census cannot be the gate
because an unrostered authored plan would establish. Predecessor evidence is
now unwritable as a measured fact, and a refused observation is not reported
as a missing axis.

Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both
std.string_type and v2.std.text, and std.types is not a declaring source.

Co-authored-by: Cursor <cursoragent@cursor.com>
An unsigned SignedBootManifestIdentified, or a verified identity observed
at or after expiry, cannot join. 0D maps BootManifestAuthentic onto
SignedBootManifestVerified; the join does not import the broker (cycle).

Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the
join now answers NetworkBootDeliveryArchitectureRefused with the architecture
the site layer named, and a witness drives that arm through the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ontier.

BootManifestRefused must not become SignedBootManifestAbsent. Join maps
SignedBootManifestVerificationRefused to EvidenceRefused on artifacts.
The join's production mint waits on an intake assembler that holds every
receipt — 0C/0D landing is not that trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
A DHCP client that is not UefiArm64, a target mismatch, an unsigned
identity, and a verified ticket that fails digest/window/unit/attempt
are NetworkBootDelivery*Refused arms. Verification refusals carry
NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry
distinct on the standing.

Co-authored-by: Cursor <cursoragent@cursor.com>
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting
it onto ManifestVerificationWrongArchitecture collapsed two refusals.

Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured.
Fleet/client/control predecessors are their own constructors; Verified is
measured by construction. 0C binds JoinInputs.site from a srv4 boot offer
and does not call the join.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ess matches.

An Established edge can still name a different architecture or digest than the
ticket; the join now refuses those and a signing-key mismatch. The wrong-unit
witness binds both matches so ManifestJoinWrongTarget actually gates.

Co-authored-by: Cursor <cursoragent@cursor.com>
…g fleet.

Unestablished trust cannot mint Established. SitePxeEdgeUnestablished is
NetworkBootDeliverySiteUnestablished, not the same missing-serving list as
an unbound fleet receipt.

Co-authored-by: Cursor <cursoragent@cursor.com>
…able.

Aarch64-only is first_slice_admitted_architectures. Repeating it as
loader_arch != ticket and architecture_is_aarch64 could never go red.

Co-authored-by: Cursor <cursoragent@cursor.com>
…rm64.

first_slice admits only Aarch64, and only UefiArm64 reaches this fold, so
uefi_processor_architecture Absent and mapped != client could not go red.

Co-authored-by: Cursor <cursoragent@cursor.com>
PresignedUrlAvailabilityFence was never inhabited. ManifestJoinWrongArchitecture
duplicated NetworkBootDeliveryArchitectureRefused after the slice membership check.

Co-authored-by: Cursor <cursoragent@cursor.com>
Site standing names the subject: client not admitted versus loader mismatch.
Join standing names loader-vs-slice, ticket-vs-edge, and ticket-vs-slice
separately instead of one Architecture value.

Co-authored-by: Cursor <cursoragent@cursor.com>
…d delivery.

GitHub review on #11602: Established had discarded the site receipt, had no
target↔site join, and could not tell ProductionTrustedBootstrap from
ControlledNetworkBootstrap. The mint now carries the four receipts plus the
verified ticket, refuses a foreign SiteIdentity, and maps that refusal through
pxe_chain_candidate.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ve/Proxy.

review 67826 finding 3: SiteNativeDhcp/SiteProxyDhcp were a second vocabulary
for who answers DHCP. SiteAnsweredDhcp wraps the existing coproduct; relay
and unobserved stay extra because they are not answering-server directions.

Co-authored-by: Cursor <cursoragent@cursor.com>
…o DHCP class.

review 67849: architecture + firmware class is one identity field. The join
projects boot_mode through dhcp_client_processor_architecture and refuses when
that is Absent or disagrees with the observed client (HttpBoot vs UefiArm64).

Co-authored-by: Cursor <cursoragent@cursor.com>
…ons.

review 67862: a fused Bool hid two firmware grounds and left Established.trust
uncited. Production carries optional observations for each ground; Controlled
carries the isolated-network observation; Unestablished is neither.

Co-authored-by: Cursor <cursoragent@cursor.com>
…he establishment's axes from its receipts

review 67869: ProductionTrustedBootstrap carried two independent optionals, so a
production standing with both grounds Absent was writable and join_verified_ticket
accepted it. The grounds are now a coproduct of the three inhabited combinations
(ProductionTrustGrounds), so the ungrounded state has no constructor (DESIGN §4b
rung 4) and bootstrap_trust_standing folds as one match — dissolving the
production_trust_ground_observed Bool-over-optional predicate and its duplicated arm.

review 67880/67908: NetworkBootDeliveryEstablishment carried the four
NetworkBootRequirementEvidence rows and artifact_digest as projections of receipts
stored on the same record — a second writable source for one fact (DESIGN §2/§3).
The axis rows, their carrier type and join_evidence are deleted; pxe_chain_candidate
reads manifest.root_digest, which the join has already proved equal to the requested
digest.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The required floor refused namespace-wave-admission with two unadjudicated
NewUnresolvedness binding deltas: `Uri` in gunbc.boot_artifact_delivery's
RedfishImageOffer and UefiHttpBootParams went from {extdeps.uri} at the base to
{} at head. The import line was replaced rather than added to when
product.placement_supply and extdeps.provisioning.dhcp_client_arch arrived;
both spellings are still authored, so the declaring source is restored rather
than the uses removed.

Also reverts a stray blank-line deletion in extdeps.cloudflare.r2 left over
from a row deletion that was itself restored — it is not this PR's subject.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review September 18, 2026 19:38
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T19:43:37.962734Z a16ed27 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a16ed27b5a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

CandidateIneligible { cause: CandidateEvidenceForOtherTarget { evidence_target: e.target } }
} else {
staged_digest_standing(offered: e.artifact_digest, requested: request.artifact.digest)
staged_digest_standing(offered: e.manifest.root_digest, requested: request.artifact.digest)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Match the request architecture before selecting PXE

When two BootArtifact rows share a digest but declare different architectures—a case IntakeArtifactSet explicitly permits—an AArch64 network-boot establishment can satisfy an x86_64 request because this branch compares only the root digest. The resulting plan selects an AArch64 chainloader and manifest for an x86_64 artifact request; compare e.manifest.architecture with request.artifact.architecture and refuse a mismatch before marking the candidate eligible.

Useful? React with 👍 / 👎.

Comment on lines +285 to +288
type BootstrapTrustObservation {
observation: DeclarationRef
observed_at: EpochMs
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind bootstrap trust evidence to the target or site

When trust observed for host/site A is supplied while joining target/site B, BootstrapTrustObservation has no target or site identity and the join accepts any non-unestablished trust arm without a binding check. Firmware HTTPS and Secure-Boot trust are host-specific, while controlled-network trust is site-specific, so this permits unrelated evidence to authorize the current network boot; the corresponding trust receipt needs an explicit target/site scope that the join verifies.

Useful? React with 👍 / 👎.

Comment on lines +155 to +157
type GlobalHttpsReachability
= GlobalHttpsEndpointReachable { observation: DeclarationRef, observed_at: EpochMs }
| GlobalHttpsEndpointUnreachable

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Tie reachability evidence to the fleet boot endpoint

When a site probe establishes reachability to endpoint A but the fleet receipt names endpoint B, this arm carries no URI, so the join cannot prove that fleet.https_boot_endpoint is the endpoint the site reached and will still return NetworkBootDeliveryEstablished. Carry the observed endpoint in the reachability receipt and compare it with the fleet endpoint; otherwise an unrelated reachable HTTPS service can satisfy the serving path while the actual boot endpoint remains unreachable.

Useful? React with 👍 / 👎.

site: site,
client: client,
boot_control: control,
manifest: id,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the manifest verification receipt in the establishment

After a successful join, the manifest_obs and manifest_at from SignedBootManifestVerified are discarded here and only the unsigned identity fields remain in the establishment carried into the delivery plan. Downstream consumers therefore cannot identify or audit the observation that established MAC, replay, and validity verification, despite the establishment being documented as retaining each axis's receipt; store the verified-manifest receipt rather than just id.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Closing as duplicate: head a16ed27 is identical to #11602, which survives; review 67925's finding is carried onto #11602.

@gunbai-bot gunbai-bot Bot closed this Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants