Repository navigation
WO29 Slice A: trusted-local file reads (items 1+4+5+6), grant-first - #59
Merged
Merged
Conversation
Implements decision 0029 Option D slice A on the file-read path: per-invocation, per-path --trust-locality operator attestation (CLI-only, no env/config), proof-aware admission, and single-stderr evidence emission. - New crates/linux-drive-locality: Linux mountinfo classifier with octal-escape decoding, longest-component topology selection (numeric mount ID never breaks ties; ambiguity fails closed as p1_ambiguous_mount_topology_v0), dm/md/loop never promote through slave recursion. The positive P1 promotion rule (guest-visible PCIe/NVMe, allowlisted HBA, non-removable MMC/SD -> Proven) is carried as a DISPUTED unresolved specification dependency: the Proven construction site is annotated, disputed_promotion_* tests pin as-implemented behavior (not accepted policy), and item 1's Linux positive-proof admission is inseparable from the dispute. - crates/windows-drive-locality: ClassifiedDrive with backing disk numbers, volume serial, and handle-derived file identity; admission policy unchanged. - Read pipeline: checked open split from opened-object read; file-object identity binding; ordered consent/classification/open/bind/read/emission. Trust never waives identity, ordinary-file, or path checks. New errors MissingProofEvidence (proof_evidence_missing_before_read_v0) and ContradictoryBackingEvidence (backing_evidence_contradicts_opened_object_v0); missing and contradictory evidence stay distinct. - CLI: hum run --format human|json, authority-event JSON projection with proof/external-trust evidence bundles, non-Unicode attestation support, freshness checks, and production-connected tests/cli_wo29_trust_locality.rs (provability-aware probe branch). - Unix Session AG (tools/check_all.ps1) corrected to exercise trust when proof is unavailable; Windows Session AG unchanged. Invoke-HumCompilerCorpusChecks digest mechanically updated. Local gates on the exact candidate tree: cargo test --workspace 708 passed / 0 failed; cargo fmt --check clean; cargo clippy --workspace --all-targets -D warnings clean; tools/test_ci_policy.ps1 436 assertions (no Full execution credit); tools/check_text_hygiene.ps1 and tools/check_public_readiness.ps1 657 files each. Windows cfg-gated code is locally unexecuted (CI gap); fixture evidence is deterministic, not hardware proof.
…oved) Adapt the Slice A implementation to the independently accepted PR #58 grant-first specification (decision 0029 section 14, WORKORDER_29.md): - linux-drive-locality: demote the nvme+pcie, allowlisted-HBA, and non-removable-mmcblk positive rules to observed-fact extraction with Unproven and the new insufficient-evidence reason; re-bucket dm/md/loop/nbd/rbd/drbd out of guest-invisible; the nbd/rbd name alone never yields the known-network reason. Proven stays defined but unreachable; the disputed predecessor is preserved as quarantined evidence only, with a structural pin that no live path calls it. - windows-drive-locality: demote the ATA/SATA/NVMe FixedLocal admission to Unproven with observed facts and a verbatim insufficient-evidence reason; the bus-type gate is unchanged (Item 2 stays out of scope). FixedLocal stays defined but unreachable. - run/native_path: the no-grant refusal carries the selected classifier's exact Unproven reason verbatim (no normalization); the superseded Windows gate reason becomes the grant-first shape; the proof path is documented as defined-but-unreachable with its code shape kept; the evidence bundle threads observed facts; Windows file identity (volume serial + file index) and device identity (backing disk numbers) stay separate lines. - check_all.ps1: remove the Linux provability-aware branch; both platforms assert the grant-first pins (denied / unavailable / external-trust with trusted-not-proven); add the Windows trust-flag run. test_ci_policy.ps1 digest refreshed mechanically. Gates on the exact candidate: cargo fmt clean; cargo clippy --workspace --all-targets -D warnings clean; cargo test --workspace 719 passed, 0 failed; tools/test_ci_policy.ps1 436 assertions; check_text_hygiene 657 files; check_public_readiness 657 files; git diff --check clean. Windows-only code paths were not executed on this Linux host; Windows CI is the authority.
…le gate BDFL-authorized corrections (2026-09-27) for two disclosed Linux classifier gaps, implemented in the real classify_with path through the FakeSysfs seam. CORRECTION 1: inspect the upward sysfs driver chain instead of only the immediate <device>/driver symlink, and recognize an exact set of iSCSI initiator drivers anywhere in the chain (iscsi_tcp, ib_iser, qla4xxx, bnx2i, be2iscsi, cxgb3i, cxgb4i) as known-network evidence. An immediate 'sd' upper driver no longer hides ancestor evidence. Priority: iSCSI > guest-invisible driver > nearest driver gates the observed-fact extraction. Every route stays Unproven; the chain is recorded as an observed fact. No driver at any level fails closed guest-invisible with no fabricated facts. CORRECTION 2: three-way 'removable' classification. '0' proceeds; '1' is Unproven with the removability-naming reason 'p1_removable_media_v0' (the builder's literal choice; the accepted spec names no literal); missing/unreadable keeps 'p1_block_device_unresolved_v0'; any other value fails closed with the non-observation 'p1_unrecognized_storage_stack_v0'. Fixture controls: - iscsi_ancestor_recognized_as_known_network_not_hidden_by_sd: sd device plus iscsi_tcp ancestor yields p1_known_network_backing_v0; unreachable under the old immediate-driver-only code (which yielded p1_unrecognized_storage_stack_v0). - missing_driver_chain_fails_closed_guest_invisible: no driver at any level yields guest-invisible with zero fabricated facts. - unreadable_mid_chain_driver_is_skipped_not_fabricated: a non-symlink driver entry is skipped without stopping the upward walk. - removable_mmc_backing_names_removability and removable_backing_names_removability: removable=1 yields p1_removable_media_v0 (Unproven either way). - removable_malformed_value_fails_closed_without_removability_reason: removable=2 yields p1_unrecognized_storage_stack_v0, never the removability reason. The 37 crate tests stay green (existing matrix, no-proved-emission sweep, quarantine structural pin); fact-extraction routes now prepend the driver-chain fact (fact counts 6 -> 7). The new reason joins the native_path smoke vocabulary. linux-drive-locality gains read_driver_chain, is_iscsi_initiator_driver, and REASON_REMOVABLE_MEDIA; FakeSysfs gains set_chain_driver. Gates: cargo fmt --check, clippy -D warnings, cargo test --workspace (723 passed, 0 failed), test_ci_policy.ps1 (436 assertions), text hygiene + public readiness (657 files), git diff --check: all clean. Nothing published.
…SCSI evidence Adds the production-connected fixture control for the BDFL clarification that 'nearest-first' describes traversal order only: an allowlisted HBA (ahci) at the device level with iscsi_tcp one level up must still yield p1_known_network_backing_v0 with the full chain retained in observed facts, never the HBA observed-fact path. The audit found the implementation already compliant (the walk always completes; iSCSI recognition scans the entire collected chain via .any()); no production code changed.
P1-1 (Windows walked/opened identity): bind_walked_to_opened requires exact volume/file-index equality; missing walked identity or family mismatch rejects fail-closed. Production consumer wired; test double honestly fabricates walked from opened (documented). P1-2 (live contradictory observation binding): bind_observed_backing_evidence runs on the live external-trust path before any payload read (not only under proved). Linux compares classifier-observed (major,minor) via shared decode_dev to opened dev_t; Windows compares volume serials. Contradiction yields ContradictoryBackingEvidence with zero payload bytes. Missing observation proceeds under exact external trust. P1-3 (consent ordering): authority -> exact-grant -> classification. Denied, trust-without-allow, and outside-grant reject before the locality adapter runs (locality.calls == 0 proves no mountinfo/stat/classifier). P1-4 (Linux classifier): userspace dev_t decode (not kernel MINORBITS); strict mount-ID topology with hidden-child exclusion and fail-closed ambiguity; known-network/host-shared/fuse filesystem categories; iSCSI highest-priority driver chain; MMC/SD requires device/type=MMC|SD; structured LinuxLocality::Unproven.device via observed_device(). P1-5 (JSON replay parity): run_command_capture_json honors supplied replay ticks identically to human path; parity test proves byte-identical output for the same ticks. P1-6 (Windows integration): x86_64-pc-windows-msvc workspace check passes. Unsafe-block inventory pin corrected 6->10 (P1-1 added 2); fixed regex already correct; test_ci_policy.ps1 digest updated and verified (436 assertions). P2-7 (evidence output): external-trust evidence carries no P1-P4 lines (CLI contract); bound_identity set only on bind success; exactly one evidence line per classified exercise. P2-8 (D5): not identifiable from available context; noted as open. Test counts: linux-drive-locality 50 passed; hum-lang 621 passed; windows-drive-locality 17 passed; CLI integration 3 passed. Preserved failed evidence: PR #59 CI run 36370226404.
Codex P2-8 follow-up: the infallible envelope constructor (build_run_json_envelope -> String) was already pinned; this adds the missing actual-command evidence through the real `hum run --format json` binary: - empty program output: empty program_output_bytes, exit 0, stdout carries only the envelope line - trailing newline: byte-exact preservation, neither stripped nor added - partial output on ordinary failure: partial bytes preserved with authoritative exit_code 1 (outcome app_failure) - write-less failure: envelope exit_code equals the process exit code Tests: 4 new json_envelope_* tests in tests/cli_wo29_trust_locality.rs (7/7 CLI tests pass). Gates: cargo fmt --check, clippy --workspace --all-targets -D warnings, cargo test -p hum-lang (621+19+7), test_ci_policy.ps1 (436 assertions), text hygiene (657 files), public readiness (657 files), git diff --check -- all clean.
Linux drive locality: - Duplicate mount IDs now reject (fail closed) - Self-parent namespace roots are valid - Multi-level same-mountpoint overmount stacks handled - Genuine cycles and ambiguities fail closed - Added p1_mountinfo_stat_contradiction_v0: mountinfo/stat device mismatch is a typed fail-closed rejection preserving the selected mountinfo device and st_dev - Missing mountinfo remains p1_no_mountinfo_entry_v0 Windows drive locality: - Replace legacy file-index identity with GetFileInformationByHandleEx FileIdInfo (class 18): 64-bit volume serial + 128-bit file ID - 24-byte FILE_ID_INFO layout control; zero IDs/API failures are unavailable (no legacy fallback) - Identity renders as volume_serial=<n> file_id=<32 hex>; exact serial/full-ID equality required for the walked-to-opened bind - Live backing bind via GetFinalPathNameByHandleW and IOCTL_VOLUME_GET_VOLUME_DISK_EXTENTS; opened serial and complete sorted/deduplicated disk list compared - Missing classifier disk evidence is attestation-coverable; contradictions reject Evidence consistency: - Structured and textual bound identity share one bound value; an opened-but-unbound identity is never labeled bound - External-trust evidence carries honest P1-P4 observation/enforcement outcomes (P1 classifier unproven, P2 bind verdict, P3 walk, P4 ordinary-file); no proof claim is emitted - Open failures report P3/P4 as not completed/not run Tests and CI policy: - CLI trust integration handles coherent and contradictory backing - check_all.ps1 Session AG: Windows assertions require the 128-bit file_id shape and exactly one honest P1-P4 outcome each; unix trust-flag admission accepts coherent admission or typed contradiction rejection - Source audit inventories production symbols, pins IOCTLs and unsafe blocks; digest pins updated
Windows volume/backing coherence:
- volume_serial is Option<u64>; GetVolumeInformationW removed, the
full 64-bit FILE_ID_INFO serial is read from the same opened volume
device handle the extent inspection queries (one open, one coherent
observation).
- Backing bind consumes OpenedVolumeObservation and enforces
opened-serial == identity-serial, classifier-serial == opened-serial,
and classifier topology == opened extent set when recorded.
- Every post-volume-open exit closes the handle explicitly.
Failure-progress honesty:
- FileReadAdapter::open_checked returns OpenCheckedFailure { error,
progress }; OpenProgress { NONE, WALK_ONLY, COMPLETE } is explicit —
never inferred from opened.is_some().
- P3 reports progress.walk_completed, P4 reports
progress.ordinary_file_check_ran. Late IdentityUnavailable after a
completed walk+check is reported as such, never as an open failure.
Linux contradictions are non-waivable:
- LinuxLocality::is_contradiction() marks
p1_mountinfo_stat_contradiction_v0; both proof and observed-backing
consumers reject independently of the opened device, before any read.
Grant-first Windows tests:
- fixed_local_for_test -> unproven_for_test; InjectedLocality::Fixed ->
InjectedLocality::Unproven; evidence uses Unproven with
REASON_INSUFFICIENT_EVIDENCE; non-zero upper 32 bits in the serial
fixture; serial/topology/coherence mismatch controls.
Session AA help pin: check_all.ps1 usage line updated to the live CLI.
Validation: cargo test --workspace green (hum bin 623, windows-drive-locality
55, linux-drive-locality 21); fmt/clippy clean; test_ci_policy.ps1 436
assertions; hygiene/readiness clean; Windows cross-target check clean.
Preserved: D5 controls, consent-before-classification, replay-tick parity,
grant-first, full 128-bit Windows file identity.
…hain Repair the file-handle -> containing-volume -> identity/extents -> binding chain in windows-drive-locality: - opened_volume_observation now reads the full 64-bit volume serial from FILE_ID_INFO on the opened FILE handle (same handle and unit as the opened file identity), instead of the unreliable volume-device-handle query. - containing_volume_device_path replaces the root-only volume_device_path: the real GetFinalPathNameByHandleW VOLUME_NAME_GUID form is a full file path, so the GUID root is extracted through the closing brace. The old parser rejected every real producer output. - New production-connected native control opened_volume_observation_traverses_real_producers_coherently traverses the real producers on one live handle and asserts the observation serial equals the file identity serial with a complete disk-number set. Late-failure evidence honesty (src/run.rs): a late IdentityUnavailable (COMPLETE progress) no longer renders 'P2: open failed before identity bind'; it reports the succeeded open explicitly, and the NotFile case reports the non-file rejection. Controls pin the exact P2 lines for the open-failure path. Also a mechanical Clippy collapsible_match repair in the cfg(windows) serial-bind arm (pre-existing; host Clippy never compiles that arm). Validation: cargo fmt and clippy clean on host and x86_64-pc-windows-msvc, 757 tests pass (cargo test --workspace), test_ci_policy 436 assertions, text hygiene and public readiness clean. Windows cross-target is compile-only; native corroboration is the reviewer's.
…K_ONLY P2 Finding A: the nine-test Windows fixture group failed because the fixtures did not match the trust-locality gate they exercise. - operator_grant: the attestation fixtures inserted two separators after C: (lexically invalid); use one valid Windows root separator. - main.rs: the trust-locality parse tests used Unix-only /hum-session-ab payloads, which Windows lexical validation rejects before command dispatch; use a cfg-gated platform-correct absolute path helper. Production validation untouched. - run.rs: the success/read-error/replay/adapter fixtures injected Unproven while granting only --allow, so missing attestation denied before the intended owner. Give the Windows fixtures whose intended owner is admission the matching per-invocation per-path attestation (new trusted_file_policy; integrated_policy attests too). The authority-precedence negatives stay on the untrusted exact_file_policy: deny/outside-grant still reject before locality. No global trust is added and production path validation is unchanged. Finding B: an open that succeeds and then fails metadata() returns WALK_ONLY, which rendered as P2 open failed. WALK_ONLY now renders a neutral line where the open phase is not established: P2: component walk completed; open phase not established before identity bind. A new control case pins the wording and that no evidence claims the open failed. Gates: cargo fmt clean; cargo clippy --workspace --all-targets clean (host) and --target x86_64-pc-windows-msvc clean (compile-only); cargo test --workspace 757 passed 0 failed; test_ci_policy.ps1 436 assertions; check_text_hygiene.ps1 and check_public_readiness.ps1 657 files; git diff --check clean.
…forensic test
The Windows-only selector exact_file_read_writes_checked_utf8_and_joins_forensic_events
asserted locality_status == Some("external-trust"); the production contract places
the classifier status ("locality_unclassified" for the injected Unproven locality)
in locality_status (src/run.rs:87; native_path.rs Self::Unclassified) and the
"external-trust" attestation classification in locality_classification
(src/run.rs:89, LocalityBundle.classification). Replace the wrong-field assertion
with the two correct separate assertions. All surrounding assertions
(successful-output, adapter counts, path, consent, event links, byte counts,
forensic fields) are unchanged. No production semantics, path validation,
attestation policy, or volume-producer changes.
Codex native Windows CI: 8 of the 9 previously failing selectors now pass;
this selector was the one remaining failure.
undergroundrap
added a commit
that referenced
this pull request
Sep 28, 2026
Record the accepted BDFL P4 resolution: file-object ordinariness is non-waivable; fixed-volume backing classification is not a separate P4 admission requirement. Preserve capability consent, exact-path matching, component/reparse safeguards, pre-read file identity binding, contradictory-evidence rejection, read bounds, and UTF-8 validation. Correct the source-description ordering and mapping distinctions without runtime changes. Reviewed head: ce56ff1 PR validation: 36491169799 attempt 1, Language on Windows and Ubuntu; Ubuntu exhaustive canonical-seal evidence passed. This documentation merge does not itself accept or integrate PR #59.
Integration-only refresh: merge accepted main ab01a8e (PR #60's documented P4 resolution, Codex-accepted) into wip/wo29-slice-a. Exactly two files changed, matching main blobs: - docs/decisions/0029-what-storage-counts-as-trusted-local-for-file-reads.md blob 9b72442 - workorders/active/WORKORDER_29.md blob c46b470 All thirteen Slice A implementation files are untouched: their blobs match 5d508f0 exactly, preserving the reviewed source and all prior validation evidence. No production change, no new semantics, no rebase.
undergroundrap
marked this pull request as ready for review
September 29, 2026 00:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WO29 Slice A — implementation for Codex review (DRAFT)
Implements WO29 Slice A (Items 1 + 4 + 5 + 6 grant-first pins) per the merged specification at
d0a4af83(PR #58, Codex-accepted).Grant-first posture: no classifier in this WO version emits
proved. Guest-visible transport, HBA, bus, driver, and removable-media observations are facts only; locality admission is grant-first on Linux and Windows (macOS grant-only). Every classification remainsUnprovenwith a named reason.Scope: Linux P1 observed-fact classifier (mountinfo oracle, fstype matrix, upward sysfs driver-chain inspection, three-way removable gate), Windows classifier demotion to grant-first with observed backing-device identity,
--trust-localityoperator attestation (per-path, per-invocation, CLI-only), human (trusted-not-proven) and JSON (external-trust) evidence surfaces, Session AG grant-first pins on both platforms with the byte-exact 28-byte wordfreq stdout. Item 2 bus-list widening, macOS Item 3, and Slice B are untouched.D5 is reserved for Codex's independent review: the defensive-seam
Result/ deadErrarm in the JSON envelope construction path is intentionally unchanged; this PR does not claim its acceptance. Specification acceptance is not implementation acceptance.Evidence (final-tree gates on the exact candidate):
cargo fmt --all -- --check— cleancargo clippy --workspace --all-targets -- -D warnings— cleancargo test --workspace— 724 passed, 0 failedtools/test_ci_policy.ps1— 436 assertions passedtools/check_text_hygiene.ps1— 657 filestools/check_public_readiness.ps1— 657 filesgit diff --check— clean22897be7e6c2af4c41d13f9a94313956cc7601f9, treef5d413614d9298ca53addc3befb61fb7cf5b3bf3, 4 commits ond0a4af83(single parent chain preserved)Windows cfg-gated production paths were not executed on the Linux host; Windows CI is authoritative for those. Fixture evidence is deterministic, not native-hardware proof.