Validate independently signed campaign witnesses #100
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!100
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/task1-reviewed-witnesses"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The existing campaign checker establishes consistency but cannot authenticate claim closure. Add a separate qualification library and CLI that derive expectations from the actual campaign inputs, materialized payloads and layout, then require scoped collector and independent-reviewer signatures over complete supporting evidence. Sessions bind the board, profile, campaign, run and capture; durable nonce admission rejects replay. The legacy consistency interface retains its fail-closed contract.
The library reviews the fixed 33 runs and 37 claims. Its assurance is authenticated independent-review testimony: reviewers remain responsible for physical provenance, complete observations and authentic authority exchanges. It does not provide hardware attestation, authorize device operations, or set
security_appliedor fleet readiness.The task record and public inventory/export helpers document the recovered September 15 candidate. All four payloads, the original plan and artifact-set digests match; the first two materializations validate. A fresh read-only NVMe GPT capture requires storage-identity reconciliation before staging. Raw artifacts and observations remain in protected retention outside Git; ownership completion, SD capture, durable recovery backups, complete staging packages and setup qualification remain open.
The native-package fix in PR #99 was merged with explicit software merge/export authorization. Native export 37048987102 succeeded from its exact main commit. Independent validation matched the GitHub archive digest, committed descriptor, final executable manifest and all three exported NAR hashes/sizes. The protected export retains this validation; its component closure still requires complete runtime assembly. No physical execution was authorized or performed.
Validation:
42ae388passed the full x86, native ARM and Hydra checks; the input-isolation workflow also passed. The subsequent export-record update changes only the descriptive JSON and Markdown, with its new CI run pending.Negative tests cover missing, truncated, altered, wrong-run, wrong-board/profile/capture, forged or incorrectly scoped signatures, session expiry, replay/FDT/command-line mismatches, file-boundary errors and concurrent durable admission. Synthetic fixtures are labeled and do not represent device acceptance.