fix: bind task evidence and recover interrupted OCI operations - #56
Merged
Merged
Conversation
Signed-off-by: David Ahmann <46606159+davidahmann@users.noreply.github.com>
Signed-off-by: David Ahmann <46606159+davidahmann@users.noreply.github.com>
Signed-off-by: David Ahmann <46606159+davidahmann@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Expert tasks could omit declared outcome acceptance, and passing commands could
certify human or external scenarios. Interrupted Docker operations lost resource
ownership, while release reconstruction could accept contradictory evidence.
This change enforces the missing bindings and prepares the 0.7.1 maintenance
release.
Changes
execution and closure. Admit first packets for approved outcomes, require valid
successor packets, and allow preservation-only work.
removal to the observed container and daemon, and preserve uncertain state.
Qualification scripts retain failed fixtures instead of deleting recovery records.
identities. Retry registry reads after publication and retain final npm and
GitHub Latest observations.
before tagging. Preserve the original historical live-worker qualification.
Acceptance and scenarios
Approved scope:
product/admission-evidence-hardening.md, AH-01 through AH-08.Negative cases include exact-digest task undercoverage, incorrect oracle owner,
missing/wrong next tasks, foreign container ownership, changed Docker daemon,
interrupted removal, contradictory qualification and missing release channels.
Five new admission regressions fail on the previous source and pass here.
Validation
4f20caf47873bf9765302fc9fd03f2c32b681847.recovery and security passed.
foreign ownership remains untouched. No probe containers remain.
reconstruction matrix. Its budget is now 60 seconds; every assertion and the
per-process 10-second bound remain unchanged.
Risk, authority, and residual limitations
The owner authorized this maintainer repair, merge and fresh latest release.
Publication still requires the protected exact-tag candidate/publish workflow.
Deadlines require a live controller; this is not a daemon-independent watchdog.
Never-observed ambiguous Docker launches remain blocked. The retained live-agent
qualification describes September 5 and its original tool versions; fresh
package tests do not renew that observation. Downstream customer gates remain
separate from these software checks.
Assistance disclosure