Record bounded Ace NVMe power-loss and offline tests #95
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!95
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/offline-qualification-evidence"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Prepare an isolated NVMe installation and operator workflow for Ace's pending offline-start, interrupted-write and restore tests. Program a spare on Malak, keep the original pilot NVMe disconnected throughout the campaign, then restore it: two planned swaps, with an extra reflash round trip only if the test disk becomes unbootable.
The kit includes a pinned Pi 5 ARM64 image with a read-only recovery system, separate synthetic test state, an exact-drive guarded writer with full readback verification, and console/SSH operations for clock refusal, retained SPIRE identity, Fleet revocation crash boundaries and backup restoration. Independent receipts on Malak distinguish an acknowledged revocation from an interrupted transaction. Old-backup detection uses an external expectation and does not claim hardware rollback prevention.
The earlier inventory, temporary SPIRE smoke and persistent-pilot observations remain as historical evidence. This new image contains synthetic identities and no live pilot private state. The operator programmed the spare with full image readback and completed the bounded physical campaign on Ace. Both PoE crash boundaries, retained identities, synthetic backup/restore, external stale-backup detection, and offline clock refusal followed by online recovery passed. Both planned swaps are complete, with no reflash round trip. Ace returned to its original encrypted NVMe and booted generation 14; all 17 protected services, retained identity/state, current workload credentials, authenticated device access, 12 Ace/Mako DNS queries and boot-order/tmpfiles checks passed. Mako renewed its node and recovered its scheduled workload probe automatically; Malak remains fenced.
Validation:
Full hardware qualification remains false. Spare-drive durability will not qualify the original pilot drive, protected keys, secure boot, rollback prevention or trusted offline time.
Operator runbook:
deploy/nvme-qualification/README.md. Build evidence:docs/observations/2026-09-30-nvme-qualification-preparation.json. Physical observations:docs/observations/2026-09-30-nvme-physical-qualification.json. One physical cut was performed per transaction boundary; exact cut timing and duration were operator-controlled, not independently instrumented.Stacked on #94. Companion plan: https://github.com/PseudoDesign/kaiba-infra/pull/6. Fleet runtime remains pinned to
0bd55c576536c29825aada2f7ce6fa052a877402.