Repository navigation
PR #11602 rework (network boot join) - #11655
gunbai-bot[bot] wants to merge 27 commits into
Conversation
…s carrier. NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary. Co-authored-by: Cursor <cursoragent@cursor.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt. Co-authored-by: Cursor <cursoragent@cursor.com>
…tKey. Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback. Co-authored-by: Cursor <cursoragent@cursor.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join observation names a non-client predecessor. Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve failed: some is not in scope; the corpus uses Present { value } / none.
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture on the observed client. Name the refused join axis. 0WET stays an annotation on the join. Co-authored-by: Cursor <cursoragent@cursor.com>
The join is the single admission walk; a denylist census cannot be the gate because an unrostered authored plan would establish. Predecessor evidence is now unwritable as a measured fact, and a refused observation is not reported as a missing axis. Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both std.string_type and v2.std.text, and std.types is not a declaring source. Co-authored-by: Cursor <cursoragent@cursor.com>
An unsigned SignedBootManifestIdentified, or a verified identity observed at or after expiry, cannot join. 0D maps BootManifestAuthentic onto SignedBootManifestVerified; the join does not import the broker (cycle). Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the join now answers NetworkBootDeliveryArchitectureRefused with the architecture the site layer named, and a witness drives that arm through the join. Co-authored-by: Cursor <cursoragent@cursor.com>
…ontier. BootManifestRefused must not become SignedBootManifestAbsent. Join maps SignedBootManifestVerificationRefused to EvidenceRefused on artifacts. The join's production mint waits on an intake assembler that holds every receipt — 0C/0D landing is not that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
A DHCP client that is not UefiArm64, a target mismatch, an unsigned identity, and a verified ticket that fails digest/window/unit/attempt are NetworkBootDelivery*Refused arms. Verification refusals carry NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry distinct on the standing. Co-authored-by: Cursor <cursoragent@cursor.com>
0D's ManifestWrongFirmwareClass is a separate HMAC-bound fact; projecting it onto ManifestVerificationWrongArchitecture collapsed two refusals. Co-authored-by: Cursor <cursoragent@cursor.com>
Measured receipts have no evidence_class flag a plan can set to Measured. Fleet/client/control predecessors are their own constructors; Verified is measured by construction. 0C binds JoinInputs.site from a srv4 boot offer and does not call the join. Co-authored-by: Cursor <cursoragent@cursor.com>
…ess matches. An Established edge can still name a different architecture or digest than the ticket; the join now refuses those and a signing-key mismatch. The wrong-unit witness binds both matches so ManifestJoinWrongTarget actually gates. Co-authored-by: Cursor <cursoragent@cursor.com>
…g fleet. Unestablished trust cannot mint Established. SitePxeEdgeUnestablished is NetworkBootDeliverySiteUnestablished, not the same missing-serving list as an unbound fleet receipt. Co-authored-by: Cursor <cursoragent@cursor.com>
…able. Aarch64-only is first_slice_admitted_architectures. Repeating it as loader_arch != ticket and architecture_is_aarch64 could never go red. Co-authored-by: Cursor <cursoragent@cursor.com>
…rm64. first_slice admits only Aarch64, and only UefiArm64 reaches this fold, so uefi_processor_architecture Absent and mapped != client could not go red. Co-authored-by: Cursor <cursoragent@cursor.com>
PresignedUrlAvailabilityFence was never inhabited. ManifestJoinWrongArchitecture duplicated NetworkBootDeliveryArchitectureRefused after the slice membership check. Co-authored-by: Cursor <cursoragent@cursor.com>
Site standing names the subject: client not admitted versus loader mismatch. Join standing names loader-vs-slice, ticket-vs-edge, and ticket-vs-slice separately instead of one Architecture value. Co-authored-by: Cursor <cursoragent@cursor.com>
…d delivery. GitHub review on #11602: Established had discarded the site receipt, had no target↔site join, and could not tell ProductionTrustedBootstrap from ControlledNetworkBootstrap. The mint now carries the four receipts plus the verified ticket, refuses a foreign SiteIdentity, and maps that refusal through pxe_chain_candidate. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ve/Proxy. review 67826 finding 3: SiteNativeDhcp/SiteProxyDhcp were a second vocabulary for who answers DHCP. SiteAnsweredDhcp wraps the existing coproduct; relay and unobserved stay extra because they are not answering-server directions. Co-authored-by: Cursor <cursoragent@cursor.com>
…o DHCP class. review 67849: architecture + firmware class is one identity field. The join projects boot_mode through dhcp_client_processor_architecture and refuses when that is Absent or disagrees with the observed client (HttpBoot vs UefiArm64). Co-authored-by: Cursor <cursoragent@cursor.com>
…ons. review 67862: a fused Bool hid two firmware grounds and left Established.trust uncited. Production carries optional observations for each ground; Controlled carries the isolated-network observation; Unestablished is neither. Co-authored-by: Cursor <cursoragent@cursor.com>
…he establishment's axes from its receipts review 67869: ProductionTrustedBootstrap carried two independent optionals, so a production standing with both grounds Absent was writable and join_verified_ticket accepted it. The grounds are now a coproduct of the three inhabited combinations (ProductionTrustGrounds), so the ungrounded state has no constructor (DESIGN §4b rung 4) and bootstrap_trust_standing folds as one match — dissolving the production_trust_ground_observed Bool-over-optional predicate and its duplicated arm. review 67880/67908: NetworkBootDeliveryEstablishment carried the four NetworkBootRequirementEvidence rows and artifact_digest as projections of receipts stored on the same record — a second writable source for one fact (DESIGN §2/§3). The axis rows, their carrier type and join_evidence are deleted; pxe_chain_candidate reads manifest.root_digest, which the join has already proved equal to the requested digest. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The required floor refused namespace-wave-admission with two unadjudicated
NewUnresolvedness binding deltas: `Uri` in gunbc.boot_artifact_delivery's
RedfishImageOffer and UefiHttpBootParams went from {extdeps.uri} at the base to
{} at head. The import line was replaced rather than added to when
product.placement_supply and extdeps.provisioning.dhcp_client_arch arrived;
both spellings are still authored, so the declaring source is restored rather
than the uses removed.
Also reverts a stray blank-line deletion in extdeps.cloudflare.r2 left over
from a row deletion that was itself restored — it is not this PR's subject.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a16ed27b5a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| CandidateIneligible { cause: CandidateEvidenceForOtherTarget { evidence_target: e.target } } | ||
| } else { | ||
| staged_digest_standing(offered: e.artifact_digest, requested: request.artifact.digest) | ||
| staged_digest_standing(offered: e.manifest.root_digest, requested: request.artifact.digest) |
There was a problem hiding this comment.
Match the request architecture before selecting PXE
When two BootArtifact rows share a digest but declare different architectures—a case IntakeArtifactSet explicitly permits—an AArch64 network-boot establishment can satisfy an x86_64 request because this branch compares only the root digest. The resulting plan selects an AArch64 chainloader and manifest for an x86_64 artifact request; compare e.manifest.architecture with request.artifact.architecture and refuse a mismatch before marking the candidate eligible.
Useful? React with 👍 / 👎.
| type BootstrapTrustObservation { | ||
| observation: DeclarationRef | ||
| observed_at: EpochMs | ||
| } |
There was a problem hiding this comment.
Bind bootstrap trust evidence to the target or site
When trust observed for host/site A is supplied while joining target/site B, BootstrapTrustObservation has no target or site identity and the join accepts any non-unestablished trust arm without a binding check. Firmware HTTPS and Secure-Boot trust are host-specific, while controlled-network trust is site-specific, so this permits unrelated evidence to authorize the current network boot; the corresponding trust receipt needs an explicit target/site scope that the join verifies.
Useful? React with 👍 / 👎.
| type GlobalHttpsReachability | ||
| = GlobalHttpsEndpointReachable { observation: DeclarationRef, observed_at: EpochMs } | ||
| | GlobalHttpsEndpointUnreachable |
There was a problem hiding this comment.
Tie reachability evidence to the fleet boot endpoint
When a site probe establishes reachability to endpoint A but the fleet receipt names endpoint B, this arm carries no URI, so the join cannot prove that fleet.https_boot_endpoint is the endpoint the site reached and will still return NetworkBootDeliveryEstablished. Carry the observed endpoint in the reachability receipt and compare it with the fleet endpoint; otherwise an unrelated reachable HTTPS service can satisfy the serving path while the actual boot endpoint remains unreachable.
Useful? React with 👍 / 👎.
| site: site, | ||
| client: client, | ||
| boot_control: control, | ||
| manifest: id, |
There was a problem hiding this comment.
Preserve the manifest verification receipt in the establishment
After a successful join, the manifest_obs and manifest_at from SignedBootManifestVerified are discarded here and only the unsigned identity fields remain in the establishment carried into the delivery plan. Downstream consumers therefore cannot identify or audit the observation that established MAC, replay, and validity verification, despite the establishment being documented as retaining each axis's receipt; store the verified-manifest receipt rather than just id.
Useful? React with 👍 / 👎.
Auto-opened by session-dashboard for session
silent-carp-100.Pushing to
pr11602advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan