feat: prepare device-secret execution and recovery #37
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!37
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/device-secret-execution-packet"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds the preparation and media-recovery tooling for the two-boot device-secret experiment. A generated packet binds the authenticated native signing handoff, experiment configuration, capture plan, host/disk/enclosure identity and three review documents. It adds a 65 MiB disposable partition and lists the exact six write spans and backup scope.
The packet-specific executor supports backup, stage, verify and explicit restoration. It requires separate root-owned, expiring media authority; checks device inactivity and guards; records one-use intents; backs up every affected byte; restores read-only protection around the write window; and verifies through an independent full-span readback. Interrupted actions cannot be repeated automatically. The private report projector checks retained capture hashes, omits raw/device-identifying fields and preserves simulation labels.
Includes the Nix constructors, an unsigned-to-authenticated composition example and an operator runbook. Signing/secret execution remains separately authorized. Slot suitability, allowed older/recovery images, the selected physical packet and hardware feasibility remain pending. No actual hardware configuration, private backup/evidence, signing grant or physical operation is included.
Validation:
f624eeb, including real Linux loop-device exclusive writes/readback, read-only restoration, mounted-media rejection, restart refusal and recovery of a pre-existing ext4 filesystem/test record.