D-114 storage observation dimensionality, Defect A collection truth, and gate-coverage reconciliation - #17
Merged
Conversation
added 2 commits
September 20, 2026 12:51
D-114 retires the block storage `type` field. Its values - ROTATIONAL, SOLID_STATE, OPTICAL, REMOVABLE, VIRTUAL, NVME - were a physical claim assembled from things that do not establish one. `queue/rotational` is a scheduler hint, not a medium; a subsystem is a driver family, not a transport; a block device is not necessarily one physical disk. Four fields replace it, each named after the kernel attribute it came from: kernel_subsystem basename of device/subsystem, read lexically queue_rotational queue/rotational, recorded, interpreted as nothing kernel_removable the removable flag, under its own name scsi_peripheral_type device/type, only within the SCSI family Keys are stable and hold null when the source is absent, so a missing attribute is visible rather than silently dropped. There is no physical_medium, no transport and no is_aggregate: nothing in /sys supports them. Report columns name their source, and say that neither a subsystem nor a rotational flag establishes the physical storage medium. Defect A, in the same area of collection truth. Machine identity reported COLLECTED with vendor and product both null whenever DMI was absent but a hypervisor was detected, because status was decided by counting non-null values across the subdomain and virtualization facts counted toward the threshold. An incomplete collection reported as complete is the one thing an evidence engine cannot be wrong about. Status is now decided per source: both identity fields are required for COLLECTED, and anything less is PARTIAL with a reason naming the fields actually missing and stating that virtualization detection is reported separately and does not establish machine identity. The published sample report is withdrawn rather than corrected. It described a device as ROTATIONAL and another as OPTICAL, under a column headed "Class", as the example of what this tool claims. It was real output from a disposable lab VM that no longer exists, and the four replacement fields were never collected from that host, so it cannot be re-rendered. Writing plausible values would be inventing evidence for a machine nobody can re-observe. IQ-011 records the gap and requires the replacement to come from reproducible bytes or a new reproducible collection source. check_storage_vocabulary reads the whole published surface, not just the source: a device record carrying a retired value, a device table whose column header hides which kernel attribute it came from, and the retired enum constants. Ten files may write the words in order to forbid them; the four that actually produce storage output are not among them. The sample had been wrong for three schema versions because every gate read the source and none read the documentation. Implements: D-114, STORAGE-SEMANTICS-001, STORAGE-SEMANTICS-002, SCOPE-045 Assisted-by: Claude (implementation, gate authoring, consumer audit)
check_gate_coverage reports that every gate is wired into `make check`, reached by CI and falsifiable. It established that by iterating over gate_coverage.json - so its answer was only ever about gates that file already named. A gate nobody declared was not reported as uncovered. It was not reported at all, and the summary line still said every gate was accounted for. That is the failure this repository exists to prevent, one level up: an absence that reads as a pass. It surfaced when a new gate was added, wired into the Makefile, given falsification injections, and still passed coverage without ever being mentioned in the authority file. Reconciling the declaration against scripts/ci/ in both directions found seven live gate scripts that had never been declared: the meta-gate itself, five release-time gates that need built artifacts, and the private provider alignment gate. None was dead - every one is invoked by the Makefile, the release workflow or the falsification harness - but none was accounted for, and nothing would have noticed if one had been orphaned or deleted. A check_* script must now appear either in `gates`, aggregated into `make check`, or in `gates_outside_make_check` with the thing that runs it and the reason it is not aggregated. A declared script that no longer exists is also rejected, so the authority file cannot drift from the directory in either direction. Two injections prove both directions fire: an undeclared gate script appearing in scripts/ci/, and a declared gate script disappearing from the tree. Implements: GOV-001, GOV-002 Assisted-by: Claude (defect identification, implementation)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Two changes, deliberately kept as two commits.
a1ae509— product/architecture. D-114 block storage observation dimensionality, and Defect A in machine identity collection truth. Both are about the same thing: recording what Linux actually exposes and refusing to report confidence the evidence has not earned.b2fdf9e— release integrity. The coverage gate could report complete coverage while live gate scripts were absent from its authority file. That is a correctness defect in the proof mechanism itself, so it is isolated rather than folded into the product change.D-111, D-112 and D-113 are already on
mainand are unchanged here.D-114 — the retired storage
typetypecarried one ofROTATIONAL,SOLID_STATE,OPTICAL,REMOVABLE,VIRTUAL,NVME. Every one was a physical claim assembled from things that do not establish one. Four fields replace it, each named after the kernel attribute it came from:kernel_subsystemdevice/subsystem, read lexicallyscsi≠ SATA/SAS/USB/iSCSI/FCqueue_rotationalqueue/rotationalfalse≠ SSD,true≠ HDDkernel_removableremovableflagscsi_peripheral_typedevice/type, SCSI family onlynulloutside SCSI rather than a fabricated valueKeys are stable and hold
nullwhen the source is absent. Nophysical_medium, notransport, nois_aggregate— nothing in/syssupports them. Report column headers name their source and state that neither a subsystem nor a rotational flag establishes the physical storage medium.Defect A — incomplete collection reported as complete
Machine identity reported
COLLECTEDwithvendorandproductbothnullwhenever DMI was absent but a hypervisor was detected, because status was decided by counting non-null values across the subdomain and virtualization facts counted toward the threshold. Status is now decided per source: both identity fields are required forCOLLECTED; anything less isPARTIALwith a reason naming the fields actually missing and stating that virtualization detection does not establish machine identity.The withdrawn sample report
The published sample described a device as
ROTATIONALand another asOPTICAL, under a column headed Class — the retired inference, published as the example of what this tool claims, three schema versions after the field was gone.It is withdrawn, not corrected. It was real output from a disposable lab VM that no longer exists, and the four replacement fields were never collected from that host, so it cannot be re-rendered. Writing plausible values would be inventing evidence for a machine nobody can re-observe.
IQ-011records the gap and requires the replacement to come from reproducible bytes or a new reproducible collection source.Gate coverage reconciliation
check_gate_coverageiterated overgate_coverage.json, so its answer was only ever about gates that file already named. An undeclared gate was not reported as uncovered — it was not reported at all, while the summary still said every gate was accounted for.Reconciling the declaration against
scripts/ci/in both directions found seven live gate scripts that had never been declared: the meta-gate, five release-time gates needing built artifacts, and the private provider alignment gate. None was dead; none was accounted for. Acheck_*script must now appear either ingatesor ingates_outside_make_checkwith its invoker and the reason it is not aggregated, and a declared script that no longer exists is rejected too.Falsification
Five new injections, all firing. On the public checkout of this branch:
A
HARNESS_ERRORis never a detection and is counted separately.Open anomaly — merge condition
During development, one private harness run reported
MUTATION_EXECUTED_BUT_NOT_DETECTEDfor the bytecode injection (D-17/D-86 committed bytecode). It did not reproduce in subsequent controlled runs or in two hand-built sandboxes, and the root cause is unknown.This is not erased by the later passing runs. Merge requires the public runner to produce
CI_EXECUTED_AND_DETECTEDfor that same injection. If the runner produces another non-detection: do not merge — root-cause it first.Provenance
Generated from private engineering
410a405viascripts/ci/release_export.sh. The tracked tree of this branch is byte-identical to that export. Preflight confirms no ARM64, Raspberry Pi, Alpine, W1-D control population, NIST/NIS2/DORA/CIS/SCF/ISO mapping, BYOL code, provider crypto, unrelated cleanup, or private planning/governance content.No tag. No release.