Skip to content

WO29 Slice A: trusted-local file reads (items 1+4+5+6), grant-first - #59

Merged
undergroundrap merged 12 commits into
mainfrom
wip/wo29-slice-a
Sep 29, 2026
Merged

undergroundrap merged 12 commits into
mainfrom
wip/wo29-slice-a

Conversation

@undergroundrap

Copy link
Copy Markdown
Owner

WO29 Slice A — implementation for Codex review (DRAFT)

Implements WO29 Slice A (Items 1 + 4 + 5 + 6 grant-first pins) per the merged specification at d0a4af83 (PR #58, Codex-accepted).

Grant-first posture: no classifier in this WO version emits proved. Guest-visible transport, HBA, bus, driver, and removable-media observations are facts only; locality admission is grant-first on Linux and Windows (macOS grant-only). Every classification remains Unproven with a named reason.

Scope: Linux P1 observed-fact classifier (mountinfo oracle, fstype matrix, upward sysfs driver-chain inspection, three-way removable gate), Windows classifier demotion to grant-first with observed backing-device identity, --trust-locality operator attestation (per-path, per-invocation, CLI-only), human (trusted-not-proven) and JSON (external-trust) evidence surfaces, Session AG grant-first pins on both platforms with the byte-exact 28-byte wordfreq stdout. Item 2 bus-list widening, macOS Item 3, and Slice B are untouched.

D5 is reserved for Codex's independent review: the defensive-seam Result / dead Err arm in the JSON envelope construction path is intentionally unchanged; this PR does not claim its acceptance. Specification acceptance is not implementation acceptance.

Evidence (final-tree gates on the exact candidate):

  • cargo fmt --all -- --check — clean
  • cargo clippy --workspace --all-targets -- -D warnings — clean
  • cargo test --workspace — 724 passed, 0 failed
  • tools/test_ci_policy.ps1 — 436 assertions passed
  • tools/check_text_hygiene.ps1 — 657 files
  • tools/check_public_readiness.ps1 — 657 files
  • git diff --check — clean
  • Commit: 22897be7e6c2af4c41d13f9a94313956cc7601f9, tree f5d413614d9298ca53addc3befb61fb7cf5b3bf3, 4 commits on d0a4af83 (single parent chain preserved)

Windows cfg-gated production paths were not executed on the Linux host; Windows CI is authoritative for those. Fixture evidence is deterministic, not native-hardware proof.

Implements decision 0029 Option D slice A on the file-read path:
per-invocation, per-path --trust-locality operator attestation
(CLI-only, no env/config), proof-aware admission, and single-stderr
evidence emission.

- New crates/linux-drive-locality: Linux mountinfo classifier with
  octal-escape decoding, longest-component topology selection
  (numeric mount ID never breaks ties; ambiguity fails closed as
  p1_ambiguous_mount_topology_v0), dm/md/loop never promote through
  slave recursion. The positive P1 promotion rule (guest-visible
  PCIe/NVMe, allowlisted HBA, non-removable MMC/SD -> Proven) is
  carried as a DISPUTED unresolved specification dependency: the
  Proven construction site is annotated, disputed_promotion_* tests
  pin as-implemented behavior (not accepted policy), and item 1's
  Linux positive-proof admission is inseparable from the dispute.
- crates/windows-drive-locality: ClassifiedDrive with backing disk
  numbers, volume serial, and handle-derived file identity;
  admission policy unchanged.
- Read pipeline: checked open split from opened-object read;
  file-object identity binding; ordered
  consent/classification/open/bind/read/emission. Trust never waives
  identity, ordinary-file, or path checks. New errors
  MissingProofEvidence (proof_evidence_missing_before_read_v0) and
  ContradictoryBackingEvidence
  (backing_evidence_contradicts_opened_object_v0); missing and
  contradictory evidence stay distinct.
- CLI: hum run --format human|json, authority-event JSON projection
  with proof/external-trust evidence bundles, non-Unicode
  attestation support, freshness checks, and production-connected
  tests/cli_wo29_trust_locality.rs (provability-aware probe branch).
- Unix Session AG (tools/check_all.ps1) corrected to exercise trust
  when proof is unavailable; Windows Session AG unchanged.
  Invoke-HumCompilerCorpusChecks digest mechanically updated.

Local gates on the exact candidate tree: cargo test --workspace 708
passed / 0 failed; cargo fmt --check clean; cargo clippy
--workspace --all-targets -D warnings clean;
tools/test_ci_policy.ps1 436 assertions (no Full execution credit);
tools/check_text_hygiene.ps1 and tools/check_public_readiness.ps1
657 files each. Windows cfg-gated code is locally unexecuted (CI
gap); fixture evidence is deterministic, not hardware proof.
…oved)

Adapt the Slice A implementation to the independently accepted PR #58
grant-first specification (decision 0029 section 14, WORKORDER_29.md):

- linux-drive-locality: demote the nvme+pcie, allowlisted-HBA, and
  non-removable-mmcblk positive rules to observed-fact extraction with
  Unproven and the new insufficient-evidence reason; re-bucket
  dm/md/loop/nbd/rbd/drbd out of guest-invisible; the nbd/rbd name alone
  never yields the known-network reason. Proven stays defined but
  unreachable; the disputed predecessor is preserved as quarantined
  evidence only, with a structural pin that no live path calls it.
- windows-drive-locality: demote the ATA/SATA/NVMe FixedLocal admission
  to Unproven with observed facts and a verbatim insufficient-evidence
  reason; the bus-type gate is unchanged (Item 2 stays out of scope).
  FixedLocal stays defined but unreachable.
- run/native_path: the no-grant refusal carries the selected
  classifier's exact Unproven reason verbatim (no normalization); the
  superseded Windows gate reason becomes the grant-first shape; the
  proof path is documented as defined-but-unreachable with its code
  shape kept; the evidence bundle threads observed facts; Windows file
  identity (volume serial + file index) and device identity (backing
  disk numbers) stay separate lines.
- check_all.ps1: remove the Linux provability-aware branch; both
  platforms assert the grant-first pins (denied / unavailable /
  external-trust with trusted-not-proven); add the Windows trust-flag
  run. test_ci_policy.ps1 digest refreshed mechanically.

Gates on the exact candidate: cargo fmt clean; cargo clippy
--workspace --all-targets -D warnings clean; cargo test --workspace
719 passed, 0 failed; tools/test_ci_policy.ps1 436 assertions;
check_text_hygiene 657 files; check_public_readiness 657 files;
git diff --check clean. Windows-only code paths were not executed on
this Linux host; Windows CI is the authority.
…le gate

BDFL-authorized corrections (2026-09-27) for two disclosed Linux
classifier gaps, implemented in the real classify_with path through the
FakeSysfs seam.

CORRECTION 1: inspect the upward sysfs driver chain instead of only the
immediate <device>/driver symlink, and recognize an exact set of iSCSI
initiator drivers anywhere in the chain (iscsi_tcp, ib_iser, qla4xxx,
bnx2i, be2iscsi, cxgb3i, cxgb4i) as known-network evidence. An immediate
'sd' upper driver no longer hides ancestor evidence. Priority:
iSCSI > guest-invisible driver > nearest driver gates the observed-fact
extraction. Every route stays Unproven; the chain is recorded as an
observed fact. No driver at any level fails closed guest-invisible with
no fabricated facts.

CORRECTION 2: three-way 'removable' classification. '0' proceeds; '1' is
Unproven with the removability-naming reason 'p1_removable_media_v0'
(the builder's literal choice; the accepted spec names no literal);
missing/unreadable keeps 'p1_block_device_unresolved_v0'; any other
value fails closed with the non-observation
'p1_unrecognized_storage_stack_v0'.

Fixture controls:
- iscsi_ancestor_recognized_as_known_network_not_hidden_by_sd: sd device
  plus iscsi_tcp ancestor yields p1_known_network_backing_v0; unreachable
  under the old immediate-driver-only code (which yielded
  p1_unrecognized_storage_stack_v0).
- missing_driver_chain_fails_closed_guest_invisible: no driver at any
  level yields guest-invisible with zero fabricated facts.
- unreadable_mid_chain_driver_is_skipped_not_fabricated: a non-symlink
  driver entry is skipped without stopping the upward walk.
- removable_mmc_backing_names_removability and
  removable_backing_names_removability: removable=1 yields
  p1_removable_media_v0 (Unproven either way).
- removable_malformed_value_fails_closed_without_removability_reason:
  removable=2 yields p1_unrecognized_storage_stack_v0, never the
  removability reason.

The 37 crate tests stay green (existing matrix, no-proved-emission
sweep, quarantine structural pin); fact-extraction routes now prepend
the driver-chain fact (fact counts 6 -> 7). The new reason joins the
native_path smoke vocabulary. linux-drive-locality gains
read_driver_chain, is_iscsi_initiator_driver, and
REASON_REMOVABLE_MEDIA; FakeSysfs gains set_chain_driver.

Gates: cargo fmt --check, clippy -D warnings, cargo test --workspace
(723 passed, 0 failed), test_ci_policy.ps1 (436 assertions), text
hygiene + public readiness (657 files), git diff --check: all clean.
Nothing published.
…SCSI evidence

Adds the production-connected fixture control for the BDFL clarification
that 'nearest-first' describes traversal order only: an allowlisted HBA
(ahci) at the device level with iscsi_tcp one level up must still yield
p1_known_network_backing_v0 with the full chain retained in observed
facts, never the HBA observed-fact path. The audit found the
implementation already compliant (the walk always completes; iSCSI
recognition scans the entire collected chain via .any()); no production
code changed.
P1-1 (Windows walked/opened identity): bind_walked_to_opened requires
exact volume/file-index equality; missing walked identity or family
mismatch rejects fail-closed. Production consumer wired; test double
honestly fabricates walked from opened (documented).

P1-2 (live contradictory observation binding): bind_observed_backing_evidence
runs on the live external-trust path before any payload read (not only
under proved). Linux compares classifier-observed (major,minor) via shared
decode_dev to opened dev_t; Windows compares volume serials. Contradiction
yields ContradictoryBackingEvidence with zero payload bytes. Missing
observation proceeds under exact external trust.

P1-3 (consent ordering): authority -> exact-grant -> classification.
Denied, trust-without-allow, and outside-grant reject before the locality
adapter runs (locality.calls == 0 proves no mountinfo/stat/classifier).

P1-4 (Linux classifier): userspace dev_t decode (not kernel MINORBITS);
strict mount-ID topology with hidden-child exclusion and fail-closed
ambiguity; known-network/host-shared/fuse filesystem categories; iSCSI
highest-priority driver chain; MMC/SD requires device/type=MMC|SD;
structured LinuxLocality::Unproven.device via observed_device().

P1-5 (JSON replay parity): run_command_capture_json honors supplied
replay ticks identically to human path; parity test proves byte-identical
output for the same ticks.

P1-6 (Windows integration): x86_64-pc-windows-msvc workspace check passes.
Unsafe-block inventory pin corrected 6->10 (P1-1 added 2); fixed regex
already correct; test_ci_policy.ps1 digest updated and verified (436
assertions).

P2-7 (evidence output): external-trust evidence carries no P1-P4 lines
(CLI contract); bound_identity set only on bind success; exactly one
evidence line per classified exercise.

P2-8 (D5): not identifiable from available context; noted as open.

Test counts: linux-drive-locality 50 passed; hum-lang 621 passed;
windows-drive-locality 17 passed; CLI integration 3 passed.
Preserved failed evidence: PR #59 CI run 36370226404.
Codex P2-8 follow-up: the infallible envelope constructor
(build_run_json_envelope -> String) was already pinned; this adds the
missing actual-command evidence through the real
`hum run --format json` binary:

- empty program output: empty program_output_bytes, exit 0, stdout
  carries only the envelope line
- trailing newline: byte-exact preservation, neither stripped nor added
- partial output on ordinary failure: partial bytes preserved with
  authoritative exit_code 1 (outcome app_failure)
- write-less failure: envelope exit_code equals the process exit code

Tests: 4 new json_envelope_* tests in tests/cli_wo29_trust_locality.rs
(7/7 CLI tests pass). Gates: cargo fmt --check, clippy --workspace
--all-targets -D warnings, cargo test -p hum-lang (621+19+7),
test_ci_policy.ps1 (436 assertions), text hygiene (657 files), public
readiness (657 files), git diff --check -- all clean.
Linux drive locality:
- Duplicate mount IDs now reject (fail closed)
- Self-parent namespace roots are valid
- Multi-level same-mountpoint overmount stacks handled
- Genuine cycles and ambiguities fail closed
- Added p1_mountinfo_stat_contradiction_v0: mountinfo/stat device
  mismatch is a typed fail-closed rejection preserving the selected
  mountinfo device and st_dev
- Missing mountinfo remains p1_no_mountinfo_entry_v0

Windows drive locality:
- Replace legacy file-index identity with GetFileInformationByHandleEx
  FileIdInfo (class 18): 64-bit volume serial + 128-bit file ID
- 24-byte FILE_ID_INFO layout control; zero IDs/API failures are
  unavailable (no legacy fallback)
- Identity renders as volume_serial=<n> file_id=<32 hex>; exact
  serial/full-ID equality required for the walked-to-opened bind
- Live backing bind via GetFinalPathNameByHandleW and
  IOCTL_VOLUME_GET_VOLUME_DISK_EXTENTS; opened serial and complete
  sorted/deduplicated disk list compared
- Missing classifier disk evidence is attestation-coverable;
  contradictions reject

Evidence consistency:
- Structured and textual bound identity share one bound value; an
  opened-but-unbound identity is never labeled bound
- External-trust evidence carries honest P1-P4 observation/enforcement
  outcomes (P1 classifier unproven, P2 bind verdict, P3 walk, P4
  ordinary-file); no proof claim is emitted
- Open failures report P3/P4 as not completed/not run

Tests and CI policy:
- CLI trust integration handles coherent and contradictory backing
- check_all.ps1 Session AG: Windows assertions require the 128-bit
  file_id shape and exactly one honest P1-P4 outcome each; unix
  trust-flag admission accepts coherent admission or typed
  contradiction rejection
- Source audit inventories production symbols, pins IOCTLs and unsafe
  blocks; digest pins updated
Windows volume/backing coherence:
- volume_serial is Option<u64>; GetVolumeInformationW removed, the
  full 64-bit FILE_ID_INFO serial is read from the same opened volume
  device handle the extent inspection queries (one open, one coherent
  observation).
- Backing bind consumes OpenedVolumeObservation and enforces
  opened-serial == identity-serial, classifier-serial == opened-serial,
  and classifier topology == opened extent set when recorded.
- Every post-volume-open exit closes the handle explicitly.

Failure-progress honesty:
- FileReadAdapter::open_checked returns OpenCheckedFailure { error,
  progress }; OpenProgress { NONE, WALK_ONLY, COMPLETE } is explicit —
  never inferred from opened.is_some().
- P3 reports progress.walk_completed, P4 reports
  progress.ordinary_file_check_ran. Late IdentityUnavailable after a
  completed walk+check is reported as such, never as an open failure.

Linux contradictions are non-waivable:
- LinuxLocality::is_contradiction() marks
  p1_mountinfo_stat_contradiction_v0; both proof and observed-backing
  consumers reject independently of the opened device, before any read.

Grant-first Windows tests:
- fixed_local_for_test -> unproven_for_test; InjectedLocality::Fixed ->
  InjectedLocality::Unproven; evidence uses Unproven with
  REASON_INSUFFICIENT_EVIDENCE; non-zero upper 32 bits in the serial
  fixture; serial/topology/coherence mismatch controls.

Session AA help pin: check_all.ps1 usage line updated to the live CLI.

Validation: cargo test --workspace green (hum bin 623, windows-drive-locality
55, linux-drive-locality 21); fmt/clippy clean; test_ci_policy.ps1 436
assertions; hygiene/readiness clean; Windows cross-target check clean.
Preserved: D5 controls, consent-before-classification, replay-tick parity,
grant-first, full 128-bit Windows file identity.
…hain

Repair the file-handle -> containing-volume -> identity/extents -> binding
chain in windows-drive-locality:

- opened_volume_observation now reads the full 64-bit volume serial from
  FILE_ID_INFO on the opened FILE handle (same handle and unit as the
  opened file identity), instead of the unreliable volume-device-handle
  query.
- containing_volume_device_path replaces the root-only volume_device_path:
  the real GetFinalPathNameByHandleW VOLUME_NAME_GUID form is a full file
  path, so the GUID root is extracted through the closing brace. The old
  parser rejected every real producer output.
- New production-connected native control
  opened_volume_observation_traverses_real_producers_coherently traverses
  the real producers on one live handle and asserts the observation serial
  equals the file identity serial with a complete disk-number set.

Late-failure evidence honesty (src/run.rs): a late IdentityUnavailable
(COMPLETE progress) no longer renders 'P2: open failed before identity
bind'; it reports the succeeded open explicitly, and the NotFile case
reports the non-file rejection. Controls pin the exact P2 lines for the
open-failure path.

Also a mechanical Clippy collapsible_match repair in the cfg(windows)
serial-bind arm (pre-existing; host Clippy never compiles that arm).

Validation: cargo fmt and clippy clean on host and
x86_64-pc-windows-msvc, 757 tests pass (cargo test --workspace),
test_ci_policy 436 assertions, text hygiene and public readiness clean.
Windows cross-target is compile-only; native corroboration is the
reviewer's.
…K_ONLY P2

Finding A: the nine-test Windows fixture group failed because the
fixtures did not match the trust-locality gate they exercise.
- operator_grant: the attestation fixtures inserted two separators
  after C: (lexically invalid); use one valid Windows root separator.
- main.rs: the trust-locality parse tests used Unix-only
  /hum-session-ab payloads, which Windows lexical validation rejects
  before command dispatch; use a cfg-gated platform-correct absolute
  path helper. Production validation untouched.
- run.rs: the success/read-error/replay/adapter fixtures injected
  Unproven while granting only --allow, so missing attestation denied
  before the intended owner. Give the Windows fixtures whose intended
  owner is admission the matching per-invocation per-path attestation
  (new trusted_file_policy; integrated_policy attests too). The
  authority-precedence negatives stay on the untrusted exact_file_policy:
  deny/outside-grant still reject before locality.
No global trust is added and production path validation is unchanged.

Finding B: an open that succeeds and then fails metadata() returns
WALK_ONLY, which rendered as P2 open failed. WALK_ONLY now renders a
neutral line where the open phase is not established:
P2: component walk completed; open phase not established before
identity bind. A new control case pins the wording and that no
evidence claims the open failed.

Gates: cargo fmt clean; cargo clippy --workspace --all-targets clean
(host) and --target x86_64-pc-windows-msvc clean (compile-only);
cargo test --workspace 757 passed 0 failed; test_ci_policy.ps1 436
assertions; check_text_hygiene.ps1 and check_public_readiness.ps1 657
files; git diff --check clean.
…forensic test

The Windows-only selector exact_file_read_writes_checked_utf8_and_joins_forensic_events
asserted locality_status == Some("external-trust"); the production contract places
the classifier status ("locality_unclassified" for the injected Unproven locality)
in locality_status (src/run.rs:87; native_path.rs Self::Unclassified) and the
"external-trust" attestation classification in locality_classification
(src/run.rs:89, LocalityBundle.classification). Replace the wrong-field assertion
with the two correct separate assertions. All surrounding assertions
(successful-output, adapter counts, path, consent, event links, byte counts,
forensic fields) are unchanged. No production semantics, path validation,
attestation policy, or volume-producer changes.

Codex native Windows CI: 8 of the 9 previously failing selectors now pass;
this selector was the one remaining failure.
undergroundrap added a commit that referenced this pull request Sep 28, 2026
Record the accepted BDFL P4 resolution: file-object ordinariness is non-waivable; fixed-volume backing classification is not a separate P4 admission requirement.

Preserve capability consent, exact-path matching, component/reparse safeguards, pre-read file identity binding, contradictory-evidence rejection, read bounds, and UTF-8 validation. Correct the source-description ordering and mapping distinctions without runtime changes.

Reviewed head: ce56ff1
PR validation: 36491169799 attempt 1, Language on Windows and Ubuntu; Ubuntu exhaustive canonical-seal evidence passed.
This documentation merge does not itself accept or integrate PR #59.
Integration-only refresh: merge accepted main ab01a8e (PR #60's
documented P4 resolution, Codex-accepted) into wip/wo29-slice-a.

Exactly two files changed, matching main blobs:
- docs/decisions/0029-what-storage-counts-as-trusted-local-for-file-reads.md
  blob 9b72442
- workorders/active/WORKORDER_29.md
  blob c46b470

All thirteen Slice A implementation files are untouched: their blobs
match 5d508f0 exactly, preserving the
reviewed source and all prior validation evidence. No production change,
no new semantics, no rebase.
@undergroundrap
undergroundrap marked this pull request as ready for review September 29, 2026 00:25
@undergroundrap
undergroundrap merged commit 037f62b into main Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant