Skip to content

D-114 storage observation dimensionality, Defect A collection truth, and gate-coverage reconciliation - #17

Merged
itcmsgr merged 2 commits into
mainfrom
rc/d114-defect-a-and-gate-accounting
Sep 20, 2026
Merged

itcmsgr merged 2 commits into
mainfrom
rc/d114-defect-a-and-gate-accounting

Conversation

@itcmsgr

@itcmsgr itcmsgr commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Scope

Two changes, deliberately kept as two commits.

a1ae509 — product/architecture. D-114 block storage observation dimensionality, and Defect A in machine identity collection truth. Both are about the same thing: recording what Linux actually exposes and refusing to report confidence the evidence has not earned.

b2fdf9e — release integrity. The coverage gate could report complete coverage while live gate scripts were absent from its authority file. That is a correctness defect in the proof mechanism itself, so it is isolated rather than folded into the product change.

D-111, D-112 and D-113 are already on main and are unchanged here.

D-114 — the retired storage type

type carried one of ROTATIONAL, SOLID_STATE, OPTICAL, REMOVABLE, VIRTUAL, NVME. Every one was a physical claim assembled from things that do not establish one. Four fields replace it, each named after the kernel attribute it came from:

field source what it does not mean
kernel_subsystem device/subsystem, read lexically not a transport: scsi ≠ SATA/SAS/USB/iSCSI/FC
queue_rotational queue/rotational false ≠ SSD, true ≠ HDD
kernel_removable the removable flag under its own name, not folded into a class
scsi_peripheral_type device/type, SCSI family only null outside SCSI rather than a fabricated value

Keys are stable and hold null when the source is absent. No physical_medium, no transport, no is_aggregate — nothing in /sys supports them. Report column headers name their source and state that neither a subsystem nor a rotational flag establishes the physical storage medium.

Defect A — incomplete collection reported as complete

Machine identity reported COLLECTED with vendor and product both null whenever DMI was absent but a hypervisor was detected, because status was decided by counting non-null values across the subdomain and virtualization facts counted toward the threshold. Status is now decided per source: both identity fields are required for COLLECTED; anything less is PARTIAL with a reason naming the fields actually missing and stating that virtualization detection does not establish machine identity.

The withdrawn sample report

The published sample described a device as ROTATIONAL and another as OPTICAL, under a column headed Class — the retired inference, published as the example of what this tool claims, three schema versions after the field was gone.

It is withdrawn, not corrected. It was real output from a disposable lab VM that no longer exists, and the four replacement fields were never collected from that host, so it cannot be re-rendered. Writing plausible values would be inventing evidence for a machine nobody can re-observe. IQ-011 records the gap and requires the replacement to come from reproducible bytes or a new reproducible collection source.

Gate coverage reconciliation

check_gate_coverage iterated over gate_coverage.json, so its answer was only ever about gates that file already named. An undeclared gate was not reported as uncovered — it was not reported at all, while the summary still said every gate was accounted for.

Reconciling the declaration against scripts/ci/ in both directions found seven live gate scripts that had never been declared: the meta-gate, five release-time gates needing built artifacts, and the private provider alignment gate. None was dead; none was accounted for. A check_* script must now appear either in gates or in gates_outside_make_check with its invoker and the reason it is not aggregated, and a declared script that no longer exists is rejected too.

Falsification

Five new injections, all firing. On the public checkout of this branch:

104 executed and detected
  8 declared skips (subject not present in a public checkout)
  0 unexpected non-firing
  0 harness errors

A HARNESS_ERROR is never a detection and is counted separately.

Open anomaly — merge condition

During development, one private harness run reported MUTATION_EXECUTED_BUT_NOT_DETECTED for the bytecode injection (D-17/D-86 committed bytecode). It did not reproduce in subsequent controlled runs or in two hand-built sandboxes, and the root cause is unknown.

This is not erased by the later passing runs. Merge requires the public runner to produce CI_EXECUTED_AND_DETECTED for that same injection. If the runner produces another non-detection: do not merge — root-cause it first.

Provenance

Generated from private engineering 410a405 via scripts/ci/release_export.sh. The tracked tree of this branch is byte-identical to that export. Preflight confirms no ARM64, Raspberry Pi, Alpine, W1-D control population, NIST/NIS2/DORA/CIS/SCF/ISO mapping, BYOL code, provider crypto, unrelated cleanup, or private planning/governance content.

No tag. No release.

Antonios Voulvoulis added 2 commits September 20, 2026 12:51
D-114 retires the block storage `type` field. Its values - ROTATIONAL,
SOLID_STATE, OPTICAL, REMOVABLE, VIRTUAL, NVME - were a physical claim
assembled from things that do not establish one. `queue/rotational` is a
scheduler hint, not a medium; a subsystem is a driver family, not a transport;
a block device is not necessarily one physical disk.

Four fields replace it, each named after the kernel attribute it came from:

  kernel_subsystem       basename of device/subsystem, read lexically
  queue_rotational       queue/rotational, recorded, interpreted as nothing
  kernel_removable       the removable flag, under its own name
  scsi_peripheral_type   device/type, only within the SCSI family

Keys are stable and hold null when the source is absent, so a missing
attribute is visible rather than silently dropped. There is no
physical_medium, no transport and no is_aggregate: nothing in /sys supports
them. Report columns name their source, and say that neither a subsystem nor a
rotational flag establishes the physical storage medium.

Defect A, in the same area of collection truth. Machine identity reported
COLLECTED with vendor and product both null whenever DMI was absent but a
hypervisor was detected, because status was decided by counting non-null
values across the subdomain and virtualization facts counted toward the
threshold. An incomplete collection reported as complete is the one thing an
evidence engine cannot be wrong about. Status is now decided per source: both
identity fields are required for COLLECTED, and anything less is PARTIAL with
a reason naming the fields actually missing and stating that virtualization
detection is reported separately and does not establish machine identity.

The published sample report is withdrawn rather than corrected. It described a
device as ROTATIONAL and another as OPTICAL, under a column headed "Class", as
the example of what this tool claims. It was real output from a disposable lab
VM that no longer exists, and the four replacement fields were never collected
from that host, so it cannot be re-rendered. Writing plausible values would be
inventing evidence for a machine nobody can re-observe. IQ-011 records the gap
and requires the replacement to come from reproducible bytes or a new
reproducible collection source.

check_storage_vocabulary reads the whole published surface, not just the
source: a device record carrying a retired value, a device table whose column
header hides which kernel attribute it came from, and the retired enum
constants. Ten files may write the words in order to forbid them; the four
that actually produce storage output are not among them. The sample had been
wrong for three schema versions because every gate read the source and none
read the documentation.

Implements: D-114, STORAGE-SEMANTICS-001, STORAGE-SEMANTICS-002, SCOPE-045
Assisted-by: Claude (implementation, gate authoring, consumer audit)
check_gate_coverage reports that every gate is wired into `make check`,
reached by CI and falsifiable. It established that by iterating over
gate_coverage.json - so its answer was only ever about gates that file already
named. A gate nobody declared was not reported as uncovered. It was not
reported at all, and the summary line still said every gate was accounted for.

That is the failure this repository exists to prevent, one level up: an absence
that reads as a pass. It surfaced when a new gate was added, wired into the
Makefile, given falsification injections, and still passed coverage without
ever being mentioned in the authority file.

Reconciling the declaration against scripts/ci/ in both directions found seven
live gate scripts that had never been declared: the meta-gate itself, five
release-time gates that need built artifacts, and the private provider
alignment gate. None was dead - every one is invoked by the Makefile, the
release workflow or the falsification harness - but none was accounted for, and
nothing would have noticed if one had been orphaned or deleted.

A check_* script must now appear either in `gates`, aggregated into
`make check`, or in `gates_outside_make_check` with the thing that runs it and
the reason it is not aggregated. A declared script that no longer exists is
also rejected, so the authority file cannot drift from the directory in either
direction.

Two injections prove both directions fire: an undeclared gate script appearing
in scripts/ci/, and a declared gate script disappearing from the tree.

Implements: GOV-001, GOV-002
Assisted-by: Claude (defect identification, implementation)
@itcmsgr
itcmsgr merged commit 14c169b into main Sep 20, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant