Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
190dcae
test: require observed Windows preflight signals
lawrencecchen Aug 17, 2026
e11b788
fix: fail closed on unavailable Windows evidence
lawrencecchen Aug 17, 2026
3fb1a57
test: distinguish unavailable Windows claims from failures
lawrencecchen Aug 17, 2026
e66ef58
fix: classify unavailable Windows claims explicitly
lawrencecchen Aug 17, 2026
8b4221a
test: require explicit skipped Windows benchmark claims
lawrencecchen Aug 17, 2026
154a708
fix: publish explicit skipped Windows startup claims
lawrencecchen Aug 17, 2026
f549ddf
test: reject core failures as skipped Windows claims
lawrencecchen Aug 17, 2026
50bc684
test: define shared startup preflight contract
lawrencecchen Aug 17, 2026
218ca5b
test: cover startup evidence contract edge cases
lawrencecchen Aug 17, 2026
c1c8f1e
test: reject false optional Windows observations
lawrencecchen Aug 17, 2026
4d86e2c
test: accept optional Windows child observation
lawrencecchen Aug 17, 2026
f25516f
fix: enforce shared startup preflight evidence contract
lawrencecchen Aug 17, 2026
7a36ba0
fix: link preflight claims to attested inputs
lawrencecchen Aug 17, 2026
2db91e1
test: keep missing grandchild claims unverified
lawrencecchen Aug 17, 2026
3c414be
fix: require observed Windows child membership for verification
lawrencecchen Aug 17, 2026
e914371
style: apply hosted rustfmt to startup benchmark tests
lawrencecchen Aug 17, 2026
55628cf
test: reject unlinked Windows AppContainer skips
lawrencecchen Aug 17, 2026
3107dd2
fix: classify Windows staging capability failures explicitly
lawrencecchen Aug 17, 2026
3bc275c
fix: attest account probe before Windows skip
lawrencecchen Aug 17, 2026
89604b8
style: apply hosted rustfmt to AppContainer probe
lawrencecchen Aug 17, 2026
3f3883a
test: attest account-process AppContainer probe state
lawrencecchen Aug 17, 2026
2493af0
fix: attest Windows account-process staging failures
lawrencecchen Aug 17, 2026
e488456
style: apply hosted rustfmt to account-process probe
lawrencecchen Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/cmux-tui-spec.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,12 @@ jobs:
- name: Test inventory checker
run: python3 cmux-tui/scripts/test_check_spec_inventory.py

- name: Test startup benchmark evidence contract
run: >-
python3 -m unittest -v
cmux-tui/scripts/test_startup_benchmark_contract.py
cmux-tui/scripts/test_startup_benchmark_claim.py

- name: Check protocol and TUI action inventory
run: python3 cmux-tui/scripts/check-spec-inventory.py

Expand Down
83 changes: 72 additions & 11 deletions .github/workflows/cmux-tui-startup-benchmark.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1267,16 +1267,45 @@ jobs:
fi
"$preflight" "${args[@]}"
}
claim_status="verified"
claim_reason=""
if [[ "$RUNNER_OS" == "Windows" ]]; then
appcontainer_evidence="$ARTIFACT_DIR/windows-appcontainer-feasibility.json"
"$preflight" \
--appcontainer-feasibility \
--fixture-parent "$PREFLIGHT_PARENT" \
--output "$appcontainer_evidence"
"$PYTHON_CMD" "$TRUSTED_SOURCE/cmux-tui/scripts/verify-startup-benchmark.py" \
--appcontainer-feasibility "$appcontainer_evidence"
fi
if [[ "$RUNNER_OS" == "Linux" ]]; then
if "$preflight" \
--appcontainer-feasibility \
--fixture-parent "$PREFLIGHT_PARENT" \
--output "$appcontainer_evidence"; then
"$PYTHON_CMD" "$TRUSTED_SOURCE/cmux-tui/scripts/verify-startup-benchmark.py" \
--appcontainer-feasibility "$appcontainer_evidence"
else
appcontainer_status=$?
if [[ "$appcontainer_status" -ne 78 ]]; then
echo "trusted Windows AppContainer feasibility failed with exit $appcontainer_status" >&2
exit "$appcontainer_status"
fi
"$PYTHON_CMD" "$TRUSTED_SOURCE/cmux-tui/scripts/verify-startup-benchmark.py" \
--appcontainer-feasibility "$appcontainer_evidence"
claim_status="unverified"
claim_reason="Windows AppContainer staging-readability capability was unavailable; no restricted-token broker run was started"
printf '%s\n' "$claim_reason" > "$ARTIFACT_DIR/windows-appcontainer-unavailable.txt"
fi
if run_preflight "$evidence"; then
:
else
preflight_status=$?
if [[ "$preflight_status" -ne 78 ]]; then
echo "trusted Windows preflight failed with exit $preflight_status" >&2
exit "$preflight_status"
fi
if [[ "$claim_status" != "unverified" ]]; then
claim_status="unverified"
claim_reason="trusted Windows preflight could not observe all required native security signals"
fi
{
printf '%s\n' "$claim_reason"
} >> "$ARTIFACT_DIR/windows-preflight-unverified.txt"
fi
elif [[ "$RUNNER_OS" == "Linux" ]]; then
unprivileged_evidence="$ARTIFACT_DIR/sandbox-preflight-unprivileged.json"
if run_preflight "$unprivileged_evidence"; then
mv "$unprivileged_evidence" "$evidence"
Expand Down Expand Up @@ -1320,10 +1349,39 @@ jobs:
bootstrap_sha256="$("$PYTHON_CMD" -c 'import hashlib,sys; print(hashlib.sha256(open(sys.argv[1], "rb").read()).hexdigest())' "$WINDOWS_BOOTSTRAP_BINARY")"
test "$bootstrap_sha256" = "$WINDOWS_BOOTSTRAP_SHA256"
fi
printf 'evidence=%s\n' "$evidence" >> "$GITHUB_OUTPUT"
printf 'evidence_sha256=%s\n' "$preflight_sha256" >> "$GITHUB_OUTPUT"
{
printf 'evidence=%s\n' "$evidence"
printf 'evidence_sha256=%s\n' "$preflight_sha256"
printf 'claim_status=%s\n' "$claim_status"
if [[ -n "$claim_reason" ]]; then
printf 'claim_reason=%s\n' "$claim_reason"
fi
} >> "$GITHUB_OUTPUT"

- name: Write skipped Windows benchmark claim
if: runner.os == 'Windows' && steps.sandbox-preflight.outputs.claim_status == 'unverified'
shell: bash
env:
PYTHON_CMD: ${{ steps.trusted-python.outputs.command }}
CLAIM_REASON: ${{ steps.sandbox-preflight.outputs.claim_reason }}
PREFLIGHT_SHA256: ${{ steps.sandbox-preflight.outputs.evidence_sha256 }}
SUPERVISOR_SHA256: ${{ steps.trusted-build.outputs.supervisor_sha256 }}
run: |
set -euo pipefail
"$PYTHON_CMD" "$TRUSTED_SOURCE/cmux-tui/scripts/startup_benchmark_claim.py" \
--output-dir "$ARTIFACT_DIR" \
--fixture-parent-name "$(basename "$FIXTURE_PARENT")" \
--platform-label "$PLATFORM_LABEL" \
--backend "$SANDBOX_BACKEND" \
--trusted-sha "$TRUSTED_SHA" \
--baseline-sha "$BASELINE_SHA" \
--candidate-sha "$CANDIDATE_SHA" \
--supervisor-sha256 "$SUPERVISOR_SHA256" \
--preflight-sha256 "$PREFLIGHT_SHA256" \
--reason "$CLAIM_REASON"

- name: Package profile attribution binaries
if: steps.sandbox-preflight.outputs.claim_status != 'unverified'
shell: bash
env:
PYTHON_CMD: ${{ steps.trusted-python.outputs.command }}
Expand Down Expand Up @@ -1437,6 +1495,8 @@ jobs:
"trusted_supervisor": release("TRUSTED_TARGET_ROOT") / "examples" / f"startup_benchmark_supervisor{suffix}",
"trusted_preflight": release("TRUSTED_TARGET_ROOT") / "examples" / f"startup_benchmark_preflight{suffix}",
"trusted_verifier": pathlib.Path(os.environ["TRUSTED_SOURCE"]) / "cmux-tui/scripts/verify-startup-benchmark.py",
"trusted_evidence_contract": pathlib.Path(os.environ["TRUSTED_SOURCE"]) / "cmux-tui/scripts/startup_benchmark_contract.py",
"trusted_claim_helper": pathlib.Path(os.environ["TRUSTED_SOURCE"]) / "cmux-tui/scripts/startup_benchmark_claim.py",
"trusted_workflow": pathlib.Path(os.environ["TRUSTED_SOURCE"]) / ".github/workflows/cmux-tui-startup-benchmark.yml",
"candidate_manifest": pathlib.Path(os.environ["ARTIFACT_DIR"]) / "candidate-product-manifest.json",
"candidate_validation": pathlib.Path(os.environ["ARTIFACT_DIR"]) / "candidate-product-validation.json",
Expand Down Expand Up @@ -1560,6 +1620,7 @@ jobs:
)

- name: Run paired startup benchmark
if: steps.sandbox-preflight.outputs.claim_status != 'unverified'
shell: bash
env:
BASELINE_BINARY_SHA256: ${{ steps.trusted-build.outputs.binary_sha256 }}
Expand Down Expand Up @@ -1898,7 +1959,7 @@ jobs:
exit 0

- name: Capture Windows startup profiles
if: ${{ always() && runner.os == 'Windows' }}
if: ${{ always() && runner.os == 'Windows' && steps.sandbox-preflight.outcome == 'success' && steps.sandbox-preflight.outputs.claim_status != 'unverified' }}
continue-on-error: true
shell: pwsh
env:
Expand Down
63 changes: 52 additions & 11 deletions .github/workflows/cmux-tui.yml
Original file line number Diff line number Diff line change
Expand Up @@ -902,18 +902,55 @@ jobs:
evidence="$RUNNER_TEMP/startup-containment/preflight.json"
appcontainer_evidence="$RUNNER_TEMP/startup-containment/windows-appcontainer-feasibility.json"
test -f "$CMUX_BENCH_TEST_WINDOWS_BOOTSTRAP"
"$preflight" \
--appcontainer-feasibility \
--fixture-parent "$CMUX_BENCH_TEST_FIXTURE_PARENT" \
--output "$appcontainer_evidence"
appcontainer_unavailable=0
if "$preflight" \
--appcontainer-feasibility \
--fixture-parent "$CMUX_BENCH_TEST_FIXTURE_PARENT" \
--output "$appcontainer_evidence"; then
python3 scripts/verify-startup-benchmark.py \
--appcontainer-feasibility "$appcontainer_evidence"
else
appcontainer_status=$?
if [[ "$appcontainer_status" -ne 78 ]]; then
echo "Windows AppContainer feasibility failed with exit $appcontainer_status" >&2
exit "$appcontainer_status"
fi
python3 scripts/verify-startup-benchmark.py \
--appcontainer-feasibility "$appcontainer_evidence"
appcontainer_unavailable=1
fi
test -s "$appcontainer_evidence"
"$preflight" \
--supervisor "$supervisor" \
--windows-bootstrap-binary "$CMUX_BENCH_TEST_WINDOWS_BOOTSTRAP" \
--windows-bootstrap-sha256 "$CMUX_BENCH_TEST_WINDOWS_BOOTSTRAP_SHA256" \
--fixture-parent "$CMUX_BENCH_TEST_FIXTURE_PARENT" \
--output "$evidence" \
--backend windows-restricted-token-job
if "$preflight" \
--supervisor "$supervisor" \
--windows-bootstrap-binary "$CMUX_BENCH_TEST_WINDOWS_BOOTSTRAP" \
--windows-bootstrap-sha256 "$CMUX_BENCH_TEST_WINDOWS_BOOTSTRAP_SHA256" \
--fixture-parent "$CMUX_BENCH_TEST_FIXTURE_PARENT" \
--output "$evidence" \
--backend windows-restricted-token-job; then
if [[ "$appcontainer_unavailable" -eq 1 ]]; then
printf 'claim_status=unverified\n' >> "$GITHUB_OUTPUT"
printf '%s\n' 'Windows AppContainer staging-readability capability was unavailable; no restricted-token broker run was started' \
> "$RUNNER_TEMP/startup-containment/windows-preflight-unverified.txt"
else
printf 'claim_status=verified\n' >> "$GITHUB_OUTPUT"
fi
else
preflight_status=$?
if [[ "$preflight_status" -ne 78 ]]; then
echo "Windows startup containment preflight failed with exit $preflight_status" >&2
exit "$preflight_status"
fi
printf 'claim_status=unverified\n' >> "$GITHUB_OUTPUT"
if [[ "$appcontainer_unavailable" -eq 1 ]]; then
printf '%s\n' 'Windows AppContainer staging-readability capability was unavailable; no restricted-token broker run was started' \
> "$RUNNER_TEMP/startup-containment/windows-preflight-unverified.txt"
else
printf '%s\n' 'trusted Windows preflight could not observe all required native security signals' \
> "$RUNNER_TEMP/startup-containment/windows-preflight-unverified.txt"
fi
printf '%s\n' 'Windows startup containment claim skipped: required native security signals were unavailable.' \
>> "$GITHUB_STEP_SUMMARY"
fi
test -s "$evidence"
printf 'CMUX_BENCH_TEST_SUPERVISOR=%s\n' "$supervisor" >> "$GITHUB_ENV"

Expand All @@ -927,6 +964,7 @@ jobs:
${{ runner.temp }}/startup-containment/*-bootstrap-hang.json
${{ runner.temp }}/startup-containment/*-bootstrap-hang.dmp
${{ runner.temp }}/startup-containment/windows-appcontainer-feasibility-failure.json
${{ runner.temp }}/startup-containment/windows-appcontainer-unavailable.txt
if-no-files-found: warn
retention-days: 7

Expand All @@ -938,10 +976,13 @@ jobs:
path: |
${{ runner.temp }}/startup-containment/windows-appcontainer-feasibility.json
${{ runner.temp }}/startup-containment/windows-appcontainer-feasibility-failure.json
${{ runner.temp }}/startup-containment/windows-appcontainer-unavailable.txt
${{ runner.temp }}/startup-containment/windows-preflight-unverified.txt
if-no-files-found: warn
retention-days: 7

- name: Run release startup harness gate
if: steps.windows-startup-containment-preflight.outputs.claim_status != 'unverified'
working-directory: cmux-tui
shell: bash
env:
Expand Down
Loading
Loading