feat: add pilot client diagnostics and reference submission #73

Merged
ams-tech merged 1 commit from codex/pilot-device-diagnostics into main 2026-09-25 04:08:43 -04:00
ams-tech commented 2026-09-25 02:57:55 -04:00 (Migrated from github.com)

The pilot client previously reported transport failures and HTTP denials as the same reconciliation error and lacked a command for the existing diagnostic-reference endpoint. This adds bounded request classifications and structured CLI errors, plus submit-diagnostic with an explicit idempotency key, bounded input and receipt verification against the existing enrollment and canonical request.

Failures still match ErrReconcile through errors.Is and never trigger automatic retries. Diagnostic submission leaves credential state unchanged and never fetches the referenced URI. No fleet API or persisted credential-state schema changes.

Validation: nix develop --command scripts/check.sh fast and nix build --no-link .#checks.x86_64-linux.unit passed. Synthetic mTLS tests cover HTTP errors, timeouts/cancellation, trust failures, redirects, invalid responses, lost-reply explicit retry, substituted receipts, input rejection and unchanged credential state. CLI tests verify bounded error output without underlying error text.

Software only: deployment, live diagnostic submission and real negative-result evidence remain pending. No device operations, policy extensions, private evidence or credentials are included. Leave unmerged for review and required CI.

The pilot client previously reported transport failures and HTTP denials as the same reconciliation error and lacked a command for the existing diagnostic-reference endpoint. This adds bounded request classifications and structured CLI errors, plus `submit-diagnostic` with an explicit idempotency key, bounded input and receipt verification against the existing enrollment and canonical request. Failures still match `ErrReconcile` through `errors.Is` and never trigger automatic retries. Diagnostic submission leaves credential state unchanged and never fetches the referenced URI. No fleet API or persisted credential-state schema changes. Validation: `nix develop --command scripts/check.sh fast` and `nix build --no-link .#checks.x86_64-linux.unit` passed. Synthetic mTLS tests cover HTTP errors, timeouts/cancellation, trust failures, redirects, invalid responses, lost-reply explicit retry, substituted receipts, input rejection and unchanged credential state. CLI tests verify bounded error output without underlying error text. Software only: deployment, live diagnostic submission and real negative-result evidence remain pending. No device operations, policy extensions, private evidence or credentials are included. Leave unmerged for review and required CI.
Sign in to join this conversation.
No description provided.