feat: integrate protected enrollment storage for malak CLI #67

Merged
ams-tech merged 2 commits from codex/malak-cli-enrollment into main 2026-09-22 22:30:37 -04:00
ams-tech commented 2026-09-22 22:22:25 -04:00 (Migrated from github.com)

Protected enrollment storage was merged in #64 onto a feature branch after its parent had already reached main. Main therefore still lacks the protected-mount guard and bounded storage helper. Integrate that reviewed commit directly, and use malak's CLI procedures for the first Ace admission.

The runtime, packaging and test changes match 0d13ccb exactly: boot-based enrollment requires the expected LUKS2/ext4 mount with protective flags and no swap, and the development helper supports the bounded create/close/restart/reopen/close experiment. Its hardware and production qualification flags remain false.

Update the Ace plan and linked scope/admission/handoff documents to defer touchscreen/GUI provisioning and the development-Pi station. Preserve durable CLI intent, reconciliation, diagnostic reporting and all FA-01–FA-08 acceptance conditions. The guided controller and browser work from #65 is excluded; existing station/UI code is unchanged.

Validation:

  • GOFLAGS=-buildvcs=false nix develop --command scripts/check.sh fast passed. The first local run could not obtain Git metadata in two go list dependency checks; disabling only VCS stamping resolved that environment issue.
  • Native x86 enrollment-storage and enrollment-storage-vm checks passed, including credential continuity across restart and rejection of unprotected storage.
  • Complete native x86 nix flake check -L is running; native ARM and required repository CI will run on this PR.
  • All 137 local links/anchors across the nine changed Markdown files resolve; the eight FA acceptance rows are unchanged.
  • Confirmed every changed non-documentation file matches reviewed storage commit 0d13ccb; no guided-campaign/controller or touchscreen changes are present.
  • git diff --check passed. No physical device, deployment or production signing operation was performed.
Protected enrollment storage was merged in #64 onto a feature branch after its parent had already reached main. Main therefore still lacks the protected-mount guard and bounded storage helper. Integrate that reviewed commit directly, and use malak's CLI procedures for the first Ace admission. The runtime, packaging and test changes match `0d13ccb` exactly: boot-based enrollment requires the expected LUKS2/ext4 mount with protective flags and no swap, and the development helper supports the bounded create/close/restart/reopen/close experiment. Its hardware and production qualification flags remain false. Update the Ace plan and linked scope/admission/handoff documents to defer touchscreen/GUI provisioning and the development-Pi station. Preserve durable CLI intent, reconciliation, diagnostic reporting and all FA-01–FA-08 acceptance conditions. The guided controller and browser work from #65 is excluded; existing station/UI code is unchanged. Validation: - `GOFLAGS=-buildvcs=false nix develop --command scripts/check.sh fast` passed. The first local run could not obtain Git metadata in two `go list` dependency checks; disabling only VCS stamping resolved that environment issue. - Native x86 `enrollment-storage` and `enrollment-storage-vm` checks passed, including credential continuity across restart and rejection of unprotected storage. - Complete native x86 `nix flake check -L` is running; native ARM and required repository CI will run on this PR. - All 137 local links/anchors across the nine changed Markdown files resolve; the eight FA acceptance rows are unchanged. - Confirmed every changed non-documentation file matches reviewed storage commit `0d13ccb`; no guided-campaign/controller or touchscreen changes are present. - `git diff --check` passed. No physical device, deployment or production signing operation was performed.
Sign in to join this conversation.
No description provided.