feat: prepare device-secret execution and recovery #37

Merged
ams-tech merged 4 commits from codex/device-secret-execution-packet into main 2026-09-17 04:39:06 -04:00
ams-tech commented 2026-09-17 04:03:00 -04:00 (Migrated from github.com)

Adds the preparation and media-recovery tooling for the two-boot device-secret experiment. A generated packet binds the authenticated native signing handoff, experiment configuration, capture plan, host/disk/enclosure identity and three review documents. It adds a 65 MiB disposable partition and lists the exact six write spans and backup scope.

The packet-specific executor supports backup, stage, verify and explicit restoration. It requires separate root-owned, expiring media authority; checks device inactivity and guards; records one-use intents; backs up every affected byte; restores read-only protection around the write window; and verifies through an independent full-span readback. Interrupted actions cannot be repeated automatically. The private report projector checks retained capture hashes, omits raw/device-identifying fields and preserves simulation labels.

Includes the Nix constructors, an unsigned-to-authenticated composition example and an operator runbook. Signing/secret execution remains separately authorized. Slot suitability, allowed older/recovery images, the selected physical packet and hardware feasibility remain pending. No actual hardware configuration, private backup/evidence, signing grant or physical operation is included.

Validation:

  • 14 regular-file tests passed: GPT bindings/checksums, complete restoration, untouched gaps, expired/mismatched authority, consumed intents, corrupt backups, changed prestate, short writes, readback failures and report projection.
  • The complete local x86_64 Nix suite passed on f624eeb, including real Linux loop-device exclusive writes/readback, read-only restoration, mounted-media rejection, restart refusal and recovery of a pre-existing ext4 filesystem/test record.
  • Formatting, 70 local documentation links/anchors, inert signing-host deployment and all 33 release/provenance tests passed.
  • Required CI is running. Native ARM CI additionally builds the experiment signing plan and runs the software/VM checks. No software result is reported as physical qualification.
Adds the preparation and media-recovery tooling for the two-boot device-secret experiment. A generated packet binds the authenticated native signing handoff, experiment configuration, capture plan, host/disk/enclosure identity and three review documents. It adds a 65 MiB disposable partition and lists the exact six write spans and backup scope. The packet-specific executor supports backup, stage, verify and explicit restoration. It requires separate root-owned, expiring media authority; checks device inactivity and guards; records one-use intents; backs up every affected byte; restores read-only protection around the write window; and verifies through an independent full-span readback. Interrupted actions cannot be repeated automatically. The private report projector checks retained capture hashes, omits raw/device-identifying fields and preserves simulation labels. Includes the Nix constructors, an unsigned-to-authenticated composition example and an operator runbook. Signing/secret execution remains separately authorized. Slot suitability, allowed older/recovery images, the selected physical packet and hardware feasibility remain pending. No actual hardware configuration, private backup/evidence, signing grant or physical operation is included. Validation: - 14 regular-file tests passed: GPT bindings/checksums, complete restoration, untouched gaps, expired/mismatched authority, consumed intents, corrupt backups, changed prestate, short writes, readback failures and report projection. - The complete local x86_64 Nix suite passed on `f624eeb`, including real Linux loop-device exclusive writes/readback, read-only restoration, mounted-media rejection, restart refusal and recovery of a pre-existing ext4 filesystem/test record. - Formatting, 70 local documentation links/anchors, inert signing-host deployment and all 33 release/provenance tests passed. - Required CI is running. Native ARM CI additionally builds the experiment signing plan and runs the software/VM checks. No software result is reported as physical qualification.
Sign in to join this conversation.
No description provided.