Validate independently signed campaign witnesses #100

Merged
ams-tech merged 2 commits from codex/task1-reviewed-witnesses into main 2026-10-02 16:44:03 -04:00
ams-tech commented 2026-10-02 14:15:44 -04:00 (Migrated from github.com)

The existing campaign checker establishes consistency but cannot authenticate claim closure. Add a separate qualification library and CLI that derive expectations from the actual campaign inputs, materialized payloads and layout, then require scoped collector and independent-reviewer signatures over complete supporting evidence. Sessions bind the board, profile, campaign, run and capture; durable nonce admission rejects replay. The legacy consistency interface retains its fail-closed contract.

The library reviews the fixed 33 runs and 37 claims. Its assurance is authenticated independent-review testimony: reviewers remain responsible for physical provenance, complete observations and authentic authority exchanges. It does not provide hardware attestation, authorize device operations, or set security_applied or fleet readiness.

The task record and public inventory/export helpers document the recovered September 15 candidate. All four payloads, the original plan and artifact-set digests match; the first two materializations validate. A fresh read-only NVMe GPT capture requires storage-identity reconciliation before staging. Raw artifacts and observations remain in protected retention outside Git; ownership completion, SD capture, durable recovery backups, complete staging packages and setup qualification remain open.

The native-package fix in PR #99 was merged with explicit software merge/export authorization. Native export 37048987102 succeeded from its exact main commit. Independent validation matched the GitHub archive digest, committed descriptor, final executable manifest and all three exported NAR hashes/sizes. The protected export retains this validation; its component closure still requires complete runtime assembly. No physical execution was authorized or performed.

Validation:

  • Focused qualification, CLI, packet, campaign and media Go tests passed.
  • Qualification/CLI race tests and Go vet passed.
  • Nix qualification-package build and real-byte packet integration passed against current main.
  • Nix formatting, diff checks, export-script syntax and descriptive-record gate checks passed.
  • PR CI for implementation revision 42ae388 passed the full x86, native ARM and Hydra checks; the input-isolation workflow also passed. The subsequent export-record update changes only the descriptive JSON and Markdown, with its new CI run pending.

Negative tests cover missing, truncated, altered, wrong-run, wrong-board/profile/capture, forged or incorrectly scoped signatures, session expiry, replay/FDT/command-line mismatches, file-boundary errors and concurrent durable admission. Synthetic fixtures are labeled and do not represent device acceptance.

The existing campaign checker establishes consistency but cannot authenticate claim closure. Add a separate qualification library and CLI that derive expectations from the actual campaign inputs, materialized payloads and layout, then require scoped collector and independent-reviewer signatures over complete supporting evidence. Sessions bind the board, profile, campaign, run and capture; durable nonce admission rejects replay. The legacy consistency interface retains its fail-closed contract. The library reviews the fixed 33 runs and 37 claims. Its assurance is authenticated independent-review testimony: reviewers remain responsible for physical provenance, complete observations and authentic authority exchanges. It does not provide hardware attestation, authorize device operations, or set `security_applied` or fleet readiness. The task record and public inventory/export helpers document the recovered September 15 candidate. All four payloads, the original plan and artifact-set digests match; the first two materializations validate. A fresh read-only NVMe GPT capture requires storage-identity reconciliation before staging. Raw artifacts and observations remain in protected retention outside Git; ownership completion, SD capture, durable recovery backups, complete staging packages and setup qualification remain open. The native-package fix in [PR #99](https://github.com/PseudoDesign/kaiba-provisioning/pull/99) was merged with explicit software merge/export authorization. [Native export 37048987102](https://github.com/PseudoDesign/kaiba-provisioning/actions/runs/37048987102) succeeded from its exact main commit. Independent validation matched the GitHub archive digest, committed descriptor, final executable manifest and all three exported NAR hashes/sizes. The protected export retains this validation; its component closure still requires complete runtime assembly. No physical execution was authorized or performed. Validation: - Focused qualification, CLI, packet, campaign and media Go tests passed. - Qualification/CLI race tests and Go vet passed. - Nix qualification-package build and real-byte packet integration passed against current main. - Nix formatting, diff checks, export-script syntax and descriptive-record gate checks passed. - [PR CI for implementation revision `42ae388`](https://github.com/PseudoDesign/kaiba-provisioning/actions/runs/37046242346) passed the full x86, native ARM and Hydra checks; the input-isolation workflow also passed. The subsequent export-record update changes only the descriptive JSON and Markdown, with its new CI run pending. Negative tests cover missing, truncated, altered, wrong-run, wrong-board/profile/capture, forged or incorrectly scoped signatures, session expiry, replay/FDT/command-line mismatches, file-boundary errors and concurrent durable admission. Synthetic fixtures are labeled and do not represent device acceptance.
Sign in to join this conversation.
No description provided.