Skip to content

BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model factory-default login through cred-rotate through OS-install through fabric-setup as .dag over Redfish, building on dsl extdeps bmc + tools bmc_first_contact - #5637

Closed
briansrls wants to merge 2 commits into
mainfrom
pr5633

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session neat-boar-71.
Pushing to pr5633 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 2 commits June 23, 2026 15:21
…-execution witness composing with base64url to mint credentials

Pure-spec seam in std.bytes: random_bytes(count: Int) -> List<UInt8> uses
pure_dag_seam_unreachable() as the §2 Realization REQUEST body — the .dag
declares the entropy need, the host satisfies it.

v1_interpreter handler reads exactly `count` bytes from /dev/urandom via
std::io::Read::read_exact (no new dependency; Linux std I/O). Bounds-checked
0..=65536; zero-count path skips the open entirely.

Witness (random_bytes_csprng_witness_test.dag, auto-enrolled by naming):
  - random_bytes_count_holds:              count: 16 -> 16 octets (green)
  - random_bytes_zero_holds:              count: 0  -> 0 octets  (green)
  - random_bytes_base64url_mint_16_length_holds: 16 bytes -> 24-char UrlSafe string (green)
  - random_bytes_base64url_mint_20_length_holds: 20 bytes -> 28-char UrlSafe string (green)

The last two witnesses prove the §2 horizontal composition: random_bytes ∘
base64_encode(variant: UrlSafe) mints a URL-safe credential string. Length
is the discriminating claim (16 bytes = 5*3+1 -> 24 chars; 20 bytes = 6*3+2
-> 28 chars); a wrong-count handler or wrong alphabet fails both.

dsl compile: 463 modules, 0 diagnostics. All 11 existing base64 witnesses
still green by execution.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

Closing — accidental duplicate. This draft was auto-opened from branch pr5633 when I checked it out in my worktree to test #5633; it mirrors #5633's content and is not separate work. The real PR is #5633. — sent from neat-boar-71

@gunbai-bot gunbai-bot Bot closed this Jun 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant