Repository navigation
machine intake: MachineOperatingEnvironment -> MachineQualificationPolicy { admits: DeploymentRiskClass } - #13285
Merged
Merged
Conversation
…ication bootstrap The family-keyed rotation answer (gunbc.bmc_implementation_dispatch rotation_route_for_family, BmcRotationRoute, megarac_rotation_route_frontier) is deleted. Its replacement is a sealed BmcRotationRouteStanding bound to one controller endpoint, one firmware build and the evidence that grounds it, with the plan's bootstrap crossed only by the separately authorized route-qualification effect (census row, dry realization over gunbc.bmc_model BmcWorld). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (annotation inside a list literal refuses) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t; type every refusal (review 75181) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…frontier retires with O1b's Apply Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ssion/lively-eagle-811
…bject; structural request identity; mtjade1 historical - RouteQualificationLiveResponse (sealed, no mint in this cut) is the only input qualify_rotation_route grounds from; the dry realization mints a distinct ModeledRouteQualificationResponse whose classifier verdict carries no standing. - Both responses carry the exact RouteQualificationSubject bound at the mint; a response for another subject refuses. - account_write_request_eq is structural (canonical DeclarationRef equality); the approval identity is an injective length-prefixed encoding of every field. - mtjade1's capture yields a HistoricalRotationRouteObservation at its factory address, not a standing; O1c-1 AccessDiscover mints the current one (mtjade1_current_route_standing_frontier). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… carriers, sealed phase receipt (cut O1b) State-shaped BmcSecure in gunbc.machine_intake_bmc_secure, routed through gunbc.host_convergence_protocol (observe/assess/decide) with its census row; the existing conjunction and census join are reused unchanged. The Apply is admitted per write by admit_rotation_apply (retires O1a's rotation_route_consumption_frontier), requires stored + exact-fetched generations, and mints a sealed BmcSecurePhaseReceipt only after an independent readback ordered on the observer clock (gunbc.clock_read ObserverClockInstant). Dry realization over gunbc.bmc_model BmcWorld. Operator ruling C: mtcollins1's cut-over and the rotation-event path's deletion are HELD (bmc_secure_state_cutover_frontier), with the declared rung drop mtcollins1_bmc_secure_standing_predates_reflash. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…field-route RED ObservedCredentialProbe arms now carry a sealed ObservedReading and ObservedPublishedAccount is sealed, each minted by a function taking the instant as a parameter, so the record-field gap (record_field_admits_a_distinct_product_value) is closed by the seal for these carriers. Forged-probe witness adds the field-route refusal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ssion/lively-eagle-811
…n no longer grounds) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/design-rung-drops.md
…rojection at merged head Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…to grounded_route, outside-caller RED Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…generation, channel-access deviations refuse 1. BmcAccountStateObservation carries the firmware the controller reported; plan_bmc_account_action has no build argument. 2. BmcSecureGoal names the exact break-glass generation; the plan refuses any other published replacement; a retained break-glass account must be it. 3. Unaddressed-LAN, channel-access-not-closed and factory-not-retained causes refuse with the missing operation named (ChannelAccessWrite / PublishedFactoryCredentialRestore) instead of planning a password write. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/auth/privileged_effect_census.dag # dag/gunbc/machine_intake/bmc_rotation_route.dag
…r's code, not its production route Its trigger is restated as the held O1b transition (the planner on the production path with the rotation-event path deleted); DESIGN 4b(3): retired by its trigger and nothing else. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/rung_drop/roster.dag # docs/design-rung-drops.md
BmcAccountStateObservation carries break_glass + break_glass_probe; the assessment requires the exact goal generation accepted at or after the read floor, so an arbitrary replacement is not a Noop and an Apply whose post-read fails the goal generation mints no BmcSecurePhaseReceipt. Findings get their own type (BmcSecureStateFinding). The live-read frontier names the probe. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/design-rung-drops.md
…licy { admits: DeploymentRiskClass }
One-motion replacement (operator ruling 2026-10-03). The policy names the
gunbc.deployment_risk class a machine ADMITS; no machine-level environment
vocabulary remains. The retained-credential decision is unchanged: a
TestRisk-admitting policy retains a break-glass credential, a
ProdRisk-admitting policy requires it closed. Digest preimages change with
the vocabulary; no witness carries a digest literal.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/rung_drop/roster.dag # docs/design-rung-drops.md
…ession/gentle-dove-262 # Conflicts: # docs/design-rung-drops.md
This was referenced Oct 4, 2026
# Conflicts: # dag/gunbc/machine_intake/bmc_secure.dag # dag/test/claim/machine_intake/machine_intake_bmc_secure_state_witness_test.dag
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 5, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deployment-risk conformance deliverable 1b (
docs/plans/deployment-risk-conformance.md).Reading this diff: this PR targets main and includes a merge of main after #13221 landed. That merge's only conflicts were this PR's new names against main's old text, in
bmc_secure.dagandmachine_intake_bmc_secure_state_witness_test.dag, and this PR's side was kept hunk by hunk. The evidence below was taken at heade9bd547d.What changes
gunbc.machine_intake_phaseMachineOperatingEnvironment = DevelopmentAndTest | Productionis deleted. In one motion, with no parallel vocabulary:MachineOperatingEnvironmentgunbc.deployment_riskDeploymentRiskClass(consumed, not re-coined)IntakeQualificationPolicy { environment }MachineQualificationPolicy { admits }intake_qualification_policy(environment:)machine_qualification_policy(admits:)production_qualification_policy()prod_risk_admitting_qualification_policy()intake_qualification_policy_digestmachine_qualification_policy_digestenvironment_of_qualification_digestadmitted_class_of_qualification_digestFleetAdmissionReceipt.environment.admitsPublishedCredentialRetainedNotAdmittedForProductionPublishedCredentialRetainedNotAdmittedByProdRiskPolicyA machine only ADMITS a class. It is never itself ProdRisk and never confers the prod role.
Preserved exactly
published_account_requires_published_closedis untouched.adjudicate_published_censusis the same match with renamed arms:TestRiskadmission retains a break-glass credential,ProdRiskadmission refuses it.mtcollins1_bmc_secure_observation(frozen under Managed-host cut O1b: BmcSecure as a desired state (shadow), observer clock, secret-order carriers, sealed phase receipt #13221's rung drop): import and one constructor argument renamed, nothing else.Digest preimage: CHANGED
"intake-qualification-policy:development-and-test"/":production"become"machine-qualification-policy:admits-test-risk"/":admits-prod-risk". The old preimages are gone, so no old digest is accepted anywhere. No witness carries a digest literal (every one is computed throughmachine_qualification_policy_digest), so no literal needed updating. Nothing outside the tree persists the digest.The four
policy_bar_mismatch_causerefusal strings also change wording; the two witness literals that assert them are updated here.Controls, one positive and one RED per arm
machine_intake_bmc_secure_witness_test)machine_intake_bmc_secure_state_witness_test)break_glass_retention_secures_under_test_risk_admissiona_retained_credential_must_be_the_goal_bound_generationretained_credential_refuses_under_prod_risk_admissiona_goal_bound_retention_refuses_a_prod_risk_admitting_goal_and_a_closed_account_satisfies_itclosed_published_credential_secures_under_prod_risk_admissionThe ProdRisk arm had a RED but no positive control before this PR, on either path.
Not changed, flagged
derive_fleet_admissionstill requires the ledger digest to EQUAL the bar's, so a ledger derived under a ProdRisk-admitting policy refuses a TestRisk-admitting bar (prod_risk_ledger_under_test_risk_bar_names_the_bar_not_bmc_secure). The ruling says a prod-admitting machine may host a TestRisk deployment; whether that should make a ProdRisk-qualified ledger satisfy a TestRisk bar is a behaviour change and an operator choice, so it is left as it was.Evidence
Run at head
e9bd547d(the script refuses any other head), onectrl-build --remotedispatch on anEstimatedMemory=24GBrunner, with the process bound to a 20 GiB memory cgroup and an explicit--functionsroster generated from everytest fnin the five files.Baseline: 168 PASS, 0 FAIL, exit 0. Rosters: bmc_secure 45, bmc_secure_state 15, disposition 35, mtcollins1 standing 4, mtcollins_firmware_converge 69.
Mutant: the two arms of
match admitsinadjudicate_published_censusswapped (TestRisk refuses, ProdRisk retains). Rerun of the two BMC witness files: 52 PASS, 8 FAIL, exit 1. The eight:break_glass_retention_secures_under_test_risk_admissionretained_credential_refuses_under_prod_risk_admissionpublished_factory_retention_secures_under_test_risk_admission_only_when_explicitpublished_factory_retention_refuses_under_prod_risk_admissionfactory_retention_test_risk_ledger_is_not_fleet_admissible_under_prod_risk_barfactory_retention_without_acceptance_is_not_retaineda_retained_credential_must_be_the_goal_bound_generationa_goal_bound_retention_refuses_a_prod_risk_admitting_goal_and_a_closed_account_satisfies_itBoth arms go red on both paths.
closed_published_credential_secures_under_prod_risk_admissionstays green under the mutant, as it should: a closed credential never reaches the retention match.Zero remaining at
e9bd547d:git grep -E 'MachineOperatingEnvironment|DevelopmentAndTest|IntakeQualificationPolicy|production_qualification_policy|intake_qualification_policy' -- dag srcreturns nothing.🤖 Generated with Claude Code