Skip to content

WO29 Slice B: Windows observed-bus widening + macOS declared-unproven - #61

Merged
undergroundrap merged 7 commits into
mainfrom
wip/wo29-slice-b
Sep 29, 2026
Merged

undergroundrap merged 7 commits into
mainfrom
wip/wo29-slice-b

Conversation

@undergroundrap

Copy link
Copy Markdown
Owner

WO29 Items 2 + 3 (Slice B) implementation, on top of merged Slice A (037f62b2).

Item 2 — Windows: widen observed local-bus facts to fixed, non-removable eMMC/SD

  • crates/windows-drive-locality: SD (12) and MMC (13) join the observed local-bus list alongside ATA/SATA/NVMe. Observation only — no bus independently earns proved; the Slice A grant-first demotion is unchanged.
  • Cause-specific observed-but-unproven verdicts with named reasons instead of reasonless Unknown:
    • windows_locality_unproven_removable_media_v0 (removable backing disk)
    • windows_locality_unproven_unsupported_bus_v0 (bus not on the observed list)
    • windows_locality_unproven_removable_status_unreadable_v0 (disk-descriptor query failed on a complete extent topology)
  • Complete observed-fact record on every Unproven path: dependency walk, each extent, each disk numeric+name bus type and RemovableMedia value with query provenance, before/after observation and equality, the configured observed-bus list, one-line P1–P4 mapping, classification with provenance. Unavailable facts recorded as unavailable, never dropped.
  • All other closed paths (dependency/extent/close/topology-record failures) stay closed Unknown; FixedLocal stays unreachable from the live classifier.

Item 3 — macOS: declared unprovable (grant only)

  • macOS classifier entry point declares Unproven by policy with the named reason macos_locality_unproven_declared_v0; no Linux mountinfo probing on macOS; never fixed-local. Matching trust admission and P2–P4 enforcement unchanged.
  • run.rs binds treat the declared verdict as missing observation (trust-coverable), never proof and never a contradiction; evidence lines and the trust bundle carry the reason/facts verbatim.

Evidence

  • Linux host: windows-drive-locality 25/25; hum bin 625/625 incl. 2 new macOS entry-point/consumer tests.
  • cargo fmt --check clean, cargo clippy --workspace --all-targets -- -D warnings clean, tools/test_ci_policy.ps1 436 assertions, text hygiene + public readiness clean.
  • Windows cross-target compile (x86_64-pc-windows-msvc, crate tests + bin) clean — compile-only credit; native Windows execution, physical SD/MMC hardware, and native macOS execution unavailable here and left to CI.

Ready for independent Codex review. Draft until CI Full is green.

…unproven

WO29 Items 2 + 3 (Slice B), on top of merged Slice A (037f62b).

Windows (crates/windows-drive-locality):
- Widen the observed local-bus list with SD (12) and MMC (13) alongside
  ATA/SATA/NVMe (Item 2: the widening is observation-only; no bus type
  independently earns proved — the Slice A grant-first demotion is
  unchanged).
- Cause-specific observed-but-unproven verdicts with named reasons
  instead of reasonless Unknown:
  - windows_locality_unproven_removable_media_v0 (removable backing disk)
  - windows_locality_unproven_unsupported_bus_v0 (bus not on observed list)
  - windows_locality_unproven_removable_status_unreadable_v0 (disk
    descriptor query failed on a complete extent topology)
- Complete observed-fact record on every Unproven path: dependency walk,
  each extent, each disk's numeric+name bus type and RemovableMedia value
  with query provenance, before/after observation and equality, the
  configured observed-bus list, one-line P1-P4 mapping, classification
  with provenance. Unavailable facts recorded as unavailable, never
  silently dropped.
- All other closed paths (dependency/extent/close/topology-record
  failures) stay closed Unknown; FixedLocal stays unreachable from the
  live classifier.

macOS (src/native_path.rs, src/run.rs):
- Item 3: the macOS classifier entry point declares Unproven by policy
  with the named reason macos_locality_unproven_declared_v0; no Linux
  mountinfo probing on macOS; never fixed-local. Matching trust
  admission and P2-P4 enforcement are unchanged.
- run.rs binds treat the declared verdict as missing observation
  (trust-coverable), never proof and never a contradiction; evidence
  lines and the trust bundle carry the reason and facts verbatim.

Tests (Linux host): windows-drive-locality 25 passed; hum bin 625
passed including 2 new macOS entry-point/consumer tests. Windows native
execution, physical SD/MMC hardware, and native macOS execution are
unavailable here; Windows coverage is Linux-host fixtures plus
cross-target compile, with native execution left to CI.

Also records the Slice A merge in WORKORDER_29.md (PR #59 squash-merged
as 037f62b; main-push run 36503074709 terminal success 2026-09-28).
…k query outcomes, membership-before-cause)

Corrections per independent-review findings (Ocean-authorized bounded
consolidation on draft PR #61):

- native_path.rs: add the missing test-only Windows match arm for
  LocalityEvidence::MacOS in is_fixed_local (was E0004 under
  --tests --target x86_64-pc-windows-msvc; production
  cross-compilation never exercised it). Declared-unproven macOS is
  never fixed-local. New Windows-test-config test pins it.

- windows-drive-locality: replace the all-or-nothing
  QueryState<Vec<DiskObservation>> descriptor walk with per-disk
  DiskQueryRecord { disk_number, outcome } where outcome is
  Observed/Failed/Undecodable/NotAttempted. The walk aborts after the
  first non-observed disk; later disks are NotAttempted, never failed.

- Reducer validates exact disk-record membership (sorted record
  numbers == sorted/deduplicated required disks) BEFORE cause
  selection: missing/extraneous/duplicate records fail closed
  (Unknown), never reach removable/unsupported cause paths.

- Partial descriptor-query outcomes yield cause-specific Unproven with
  the unreadable reason, preserving all available per-disk facts --
  never reasonless Unknown.

Tests: crate 28 pass (3 new: membership adversarial cases + valid
multi-disk controls + partial-outcome fact preservation); bin 625
pass (incl. macos selectors); cli_wo29_trust_locality 7 pass;
Windows test-target and production cross-compilation checks clean;
fmt/clippy -D warnings/text hygiene/public readiness clean.

Not covered here: native Windows execution of the new
Windows-test-config test (CI/Codex), native macOS execution
(unavailable), physical SD/MMC hardware (fixtures only).
…turned-locality path

The returned locality evidence (Windows producer -> reducer ->
runtime external-trust binder) conflated distinct per-disk outcomes
and wiped available observations on the cleanup and
topology-contradiction paths.

Producer (crates/windows-drive-locality):
- New DiskQueryOutcome::OpenFailed: a device that never opened is
  not a descriptor query that ran and failed (previously `Failed`),
  so the evidence never claims a query ran that never ran.
- A failed CloseHandle no longer discards a successful observation:
  the observation is kept, the walk continues to later disks, and
  the cleanup failure is carried as a named fact instead of
  replacing the observation with `Failed`.

Reducer:
- A known before/after contradiction now returns a closed `Unknown`
  carrying a structured contradiction marker plus the before/after
  facts (new `ClassifiedDrive::contradiction`), instead of an empty
  closed verdict that erased the contradiction.
- Cleanup failure no longer wipes the observed-fact record: it is a
  named `cleanup:` fact line and the verdict follows the observed
  matrix.
- Inner identity validation: an `Observed` record whose inner
  `DiskObservation.disk_number` disagrees with the record's outer
  `disk_number` fails closed before cause selection (outer
  membership validation is unchanged).

Runtime binder (src/run.rs):
- `bind_observed_backing_evidence` rejects a contradicted bundle
  with `ContradictoryBackingEvidence` before payload consumption,
  even when serials and disk topology would otherwise agree:
  matching trust covers missing evidence, never contradictory
  evidence.

Controls (production-connected, injected controls labelled in
comments): open-failure vs descriptor-query-failure distinction,
cleanup-failure observation retention, before/after contradiction
marker through the reducer (contradiction vs missing-evidence
`Unknown`), contradiction rejection through the actual binder
(Windows-native), inner/outer disk-identity mismatch rejection with
a valid multi-disk control, and the preliminary removable path
through the actual reducer; the existing missing/duplicate-record
regressions are preserved unchanged.

Evidence: windows-drive-locality 31/31, hum binary 625/625,
`cargo fmt --all -- --check`, `cargo clippy --workspace
--all-targets -- -D warnings`, text hygiene, and public readiness
clean; x86_64-pc-windows-msvc test-target and production
cross-compilation clean. Native Windows execution of the new binder
control rides CI; native macOS execution remains unavailable.
…for invalid/contradictory evidence

- Thread volume-close outcome through classify_full preliminary/dependency
  early returns; cleanup facts preserved including close failure
- Render close/extent bundles honestly: complete-after shown as available
  observation; ApiFailure/Partial as unavailable, never contradiction;
  not-attempted named only when the query genuinely never ran
- Inner disk-identity mismatch (outer disk 0 / Observed inner disk 99)
  now carries the contradiction marker and rejects through the actual
  external-trust binder before payload consumption
- Distinguish unavailable after-queries from observed disagreements;
  genuine contradiction still rejects
- Production-used injection seam controls exercise orchestration,
  early returns, and cleanup; new Windows binder test through actual
  bind_observed_backing_evidence

Tests: windows-drive-locality 46/46, hum 625/625;
x86_64-pc-windows-msvc test+production configs clean.
…when after mapping is unavailable

Finding P1: classify_evidence_detail returned a closed verdict
immediately on after.mapping ApiFailure/Partial, bypassing the
disk-record and contradiction validation below it — and clearing
backing_device_identity, so the runtime binder admitted inconsistent
evidence as trust-coverable.

The unavailable after mapping is now carried as a flag through the
full validation chain:
- dependency, extents, exact outer disk-record membership, inner
  observed-disk identity, and per-disk outcomes all validate first;
- the drive type is checked independently of the mapping query: a
  positively observed Fixed -> Remote change is a genuine
  contradiction even when the after mapping itself is unavailable
  (unobserved drive types stay missing evidence, never disagreement);
- the final verdict stays closed Unknown with no contradiction marker
  for genuinely unavailable after mappings, but retains the VALIDATED
  disk identities so the actual binder compares them against the
  opened observation (mismatch rejects; agreement stays
  trust-coverable);
- cause-specific Unproven paths still run when the disk query
  genuinely failed, with the unavailable after named as unavailable
  in the facts — never 'mismatch'.

Tests: 52/52 windows-drive-locality lib (6 new combined-cause
controls covering ApiFailure and Partial: retained identities,
inner/outer record invalidity, independent drive-type disagreement,
cause-specific Unproven preservation), 625/625 hum bin (2 new
binder controls: retained identities bind against the opened
observation; drive-type contradiction rejects before payload).
cargo fmt --check, clippy -D warnings, text hygiene (657 files),
public readiness (657 files), Windows test-target and production
compilations all pass.
… Unproven causes

Codex accept-with-required-fix, two findings.

Finding 1 (complete after mapping, classify_evidence_detail): the
before/after check compared the whole preliminary record, so before
Fixed + after DRIVE_UNKNOWN + identical complete mapping + matching
disk evidence set contradiction=true and the binder rejected.
DRIVE_UNKNOWN means undetermined, not an observed different drive
type. The mapping and the drive type are now compared
independently: unequal complete mappings contradict; a positively
observed different after drive type (e.g. Fixed -> Remote)
contradicts; DRIVE_NO_ROOT_DIR keeps its existing rejecting
handling (separately documented meaning, never treated as
missing). An undetermined after drive type with an otherwise
consistent record is trust-coverable: the verdict takes the
observed-but-unproven path with the validated disk identities
retained for the binder, and the facts render
'undetermined (drive type)' instead of 'mismatch'.

Finding 2 (unavailable after mapping): the final branch computed
the cause-specific determination (removable SD, unsupported bus)
but discarded it, returning unproven_reason=None. With complete
removable-SD or unsupported-bus observations and after
ApiFailure/Partial, the named Unproven cause is now preserved
alongside the unavailable-query facts and the retained binding
identity (new closed_retained_unproven verdict). The after query
is still recorded as unavailable — never claimed succeeded — and
the verdict stays closed Unknown with no contradiction marker.

Controls: 5 new injected orchestration controls through the real
production seam (undetermined drive type trust-coverable;
MissingRoot and observed Remote still reject; removable and
unsupported-bus causes preserved under ApiFailure AND Partial)
plus 2 run.rs binder controls passing the actual returned verdicts
into the actual external-trust binder (matching opened evidence
admits; mismatched disk identity rejects). Genuine missingness
stays trust-coverable; every unavailable query is not rejected.

Gates on the exact candidate: windows-drive-locality 57/57,
hum bin 625/625, x86_64-pc-windows-msvc test + production
configurations compile clean, fmt/clippy/-D warnings/text
hygiene/public readiness clean. No local Full campaign.
…pping state

Remaining P1 from independent review: drive_type_observed_changed treated
DRIVE_NO_ROOT_DIR as missing evidence on the unavailable-after path, so an
observed Fixed->DRIVE_NO_ROOT_DIR transition was trust-covered when the
after mapping was ApiFailure/Partial. DRIVE_NO_ROOT_DIR means the root path
is invalid - an observed invalid-root disagreement, not undetermined (Unknown)
and not missing.

The shared comparison helper now names MissingRoot as an observed
disagreement, so the invalid-root transition carries the rejecting
contradiction marker identically in all three after-mapping states
(Complete, ApiFailure, Partial). The complete-mapping branch drops its
explicit MissingRoot clause (now covered by the helper); unrelated Other
handling is unchanged. The invalid-root observation is preserved alongside
the unavailable-mapping facts; the after query is never claimed succeeded.
Matching trust still cannot waive the marker.

Controls: new orchestration test covers ApiFailure AND Partial through the
real production seam; existing complete-mapping test re-passes; new
cfg(windows) binder test proves the actual external-trust binder refuses the
marked verdict before payload consumption even with matching serial.
DRIVE_UNKNOWN trust-coverable controls, mapping/Remote contradictions, named
causes, and disk-identity binding preserved.

Tests: windows-drive-locality 58/58; hum bin 625/625; Windows test and
production targets cross-compile clean; fmt/clippy/hygiene/readiness clean.
No local Full campaign.
@undergroundrap
undergroundrap marked this pull request as ready for review September 29, 2026 06:03
@undergroundrap
undergroundrap merged commit 0cd5e46 into main Sep 29, 2026
4 checks passed
undergroundrap added a commit that referenced this pull request Sep 29, 2026
…fresh)

Merge base 037f62b (Codex-accepted docs head 7562839) with main
0cd5e46 (WO29 Slice B, PR #61). Both reviewed documentation blobs
preserved exactly; no wording changes in this refresh.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant