feat: add guided station campaigns #65

Merged
ams-tech merged 1 commit from codex/guided-station-campaign into codex/protected-enrollment-state 2026-09-22 21:47:05 -04:00
ams-tech commented 2026-09-22 20:30:55 -04:00 (Migrated from github.com)

The read-only station cannot guide an operator through a durable development campaign. This adds a separate touchscreen mode that shows the current step, recorded result, required input and allowed action, with diagnostic history available through report export.

The new kaiba-provision-campaign service owns one immutable plan and a private persistent journal. The existing loopback station relays closed actions over station/lane-scoped mTLS. Automatic steps stop at required operator input; duplicate taps and lost replies recover recorded progress. Interrupted execution requires a separately pinned reconciler, and blocked or quarantined outcomes cannot be bypassed from the UI.

Execution is limited to digest-pinned Nix-store packet wrappers. The browser supplies no commands, paths or secrets. Wrappers retain their own execution authorization, target checks, one-use intent and evidence handling. Acknowledging an input does not authorize an operation. Raw executor output never enters the screen or journal; only reviewed result codes, bounded failure categories and diagnostic hashes are retained.

This PR is stacked on #64 (codex/protected-enrollment-state), which is stacked on #63. It delivers the guided controller and UI with a working software demonstration. The reviewed Pi packet/wrappers and isolated real-device fleet eligibility policy remain to be connected. It does not perform hardware operations or change fleet-admission rules. Every exported FA condition remains not_evaluated; completing a campaign cannot claim hardware qualification or production enrollment. The observer, disabled foundation and public simulation retain their behavior.

Validation passed locally:

  • nix develop --command scripts/check.sh fast: complete Go suite, station UI checks, Nix formatting, inert deployment smoke test and CI-selection regressions.
  • Focused Go race tests for the campaign engine, mTLS relay, live station and station CLI; seven new browser tests cover rendering, polling, stale state, lost replies, token renewal and export.
  • Native x86_64 guided-station-campaign check: real packaged controller/station, disposable mTLS, real enrollment client using disposable process-mode state, restart/outage recovery, access denial and secret-free report export. Six fixed executor failure cases cover digest mismatch, stderr, overflow, malformed result, timeout and nonzero exit.
  • All 78 local documentation link targets in the changed guides exist; diff whitespace checks pass.

The native check initializes and reopens a disposable client identity; it does not issue a certificate, activate fleet membership or establish encrypted cold-boot behavior. Required x86_64 and native ARM CI remain the merge gate. The runbook documents deployment inputs, authority boundaries, recovery and the remaining Pi integration.

The read-only station cannot guide an operator through a durable development campaign. This adds a separate touchscreen mode that shows the current step, recorded result, required input and allowed action, with diagnostic history available through report export. The new `kaiba-provision-campaign` service owns one immutable plan and a private persistent journal. The existing loopback station relays closed actions over station/lane-scoped mTLS. Automatic steps stop at required operator input; duplicate taps and lost replies recover recorded progress. Interrupted execution requires a separately pinned reconciler, and blocked or quarantined outcomes cannot be bypassed from the UI. Execution is limited to digest-pinned Nix-store packet wrappers. The browser supplies no commands, paths or secrets. Wrappers retain their own execution authorization, target checks, one-use intent and evidence handling. Acknowledging an input does not authorize an operation. Raw executor output never enters the screen or journal; only reviewed result codes, bounded failure categories and diagnostic hashes are retained. This PR is stacked on #64 (`codex/protected-enrollment-state`), which is stacked on #63. It delivers the guided controller and UI with a working software demonstration. The reviewed Pi packet/wrappers and isolated real-device fleet eligibility policy remain to be connected. It does not perform hardware operations or change fleet-admission rules. Every exported FA condition remains `not_evaluated`; completing a campaign cannot claim hardware qualification or production enrollment. The observer, disabled foundation and public simulation retain their behavior. Validation passed locally: - `nix develop --command scripts/check.sh fast`: complete Go suite, station UI checks, Nix formatting, inert deployment smoke test and CI-selection regressions. - Focused Go race tests for the campaign engine, mTLS relay, live station and station CLI; seven new browser tests cover rendering, polling, stale state, lost replies, token renewal and export. - Native x86_64 `guided-station-campaign` check: real packaged controller/station, disposable mTLS, real enrollment client using disposable process-mode state, restart/outage recovery, access denial and secret-free report export. Six fixed executor failure cases cover digest mismatch, stderr, overflow, malformed result, timeout and nonzero exit. - All 78 local documentation link targets in the changed guides exist; diff whitespace checks pass. The native check initializes and reopens a disposable client identity; it does not issue a certificate, activate fleet membership or establish encrypted cold-boot behavior. Required x86_64 and native ARM CI remain the merge gate. The runbook documents deployment inputs, authority boundaries, recovery and the remaining Pi integration.
Sign in to join this conversation.
No description provided.