WIP: Add production appliance update contracts and authenticated wire runtime #16

Draft
ams-tech wants to merge 2 commits from codex/autonomous-appliance-updates into main
ams-tech commented 2026-10-03 19:59:54 -04:00 (Migrated from github.com)

The existing pilot contracts cannot authorize production appliance credentials or bounded remote A/B updates. This adds a separate 0.7.0-draft.1 family and a standard-library Go reference runtime for exact identities, purpose-separated signatures, release variants, qualification grants, phase leases, credential proof/results, receipts, lifecycle and fixed-code diagnostics.

Existing families and VERSION remain unchanged. Python/schema checks remain consistency-only; authenticated consumers use independent installed trust. Consumers pin the exact runtime source and file hashes.

Validation: all 126 Python tests and Go runtime race tests pass, including altered/cross-purpose signatures, expiry boundaries, certificate identity/role/name substitutions, unsafe IDs and a cross-language canonical digest vector. No production issuance, physical acceptance or readiness is claimed.

The existing pilot contracts cannot authorize production appliance credentials or bounded remote A/B updates. This adds a separate 0.7.0-draft.1 family and a standard-library Go reference runtime for exact identities, purpose-separated signatures, release variants, qualification grants, phase leases, credential proof/results, receipts, lifecycle and fixed-code diagnostics. Existing families and VERSION remain unchanged. Python/schema checks remain consistency-only; authenticated consumers use independent installed trust. Consumers pin the exact runtime source and file hashes. Validation: all 126 Python tests and Go runtime race tests pass, including altered/cross-purpose signatures, expiry boundaries, certificate identity/role/name substitutions, unsafe IDs and a cross-language canonical digest vector. No production issuance, physical acceptance or readiness is claimed.
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin codex/autonomous-appliance-updates:codex/autonomous-appliance-updates
git switch codex/autonomous-appliance-updates
Sign in to join this conversation.
No description provided.