Skip to content

Validate a release with an independently operated external node #21

Description

@ctfbruce

Problem

All current runtime evidence is local. ETH testbed compatibility and other externally operated deployments remain unconfirmed.

Proposed change

After explicit authorization names a release, host and operator, run a bounded external installation/enrollment/recovery and opt-out pilot with agreed destinations and support measurements.

Acceptance criteria

  • The operator installs the exact signed release using the published instructions and demonstrates enrollment, a controlled measurement and restore.
  • Observed version/proxy/TLS/SCION capabilities and deviations are recorded rather than inferred from local tests.
  • The pilot measures time to first result, support effort and recovery behavior; no outside-host connection or deployment occurs before authorization.

Current evidence

unimplemented requirement. Backlog classification is based on source inspection; this issue does not claim a new runtime reproduction.

Dependencies

  • #15 — Define maintainers, review ownership and a private security reporting route
  • #19 — Document and rehearse abuse response and destination opt-out handling
  • #89 — Enforce ownership and role authorization on every HTTP operation
  • #90 — Enroll executor identities and bind them to both control channels
  • #67 — Measure and validate packet-counter enforcement for supported paths
  • #112 — Restore a verified backup into separate state without replaying measurements
  • #138 — Verify trusted release signatures before executing an installer

Activation

This work is deferred. External operation or publication requires explicit authorization for the named target and exact release; existing ETH testbed compatibility and deployment remain unconfirmed.

Validation must use owned local fixtures on supported Linux environments. Record the implementing merge request and relevant test results before closing this issue.


Imported from GitLab issue 20. Originally opened 2026-09-10. Historical GitLab links may require access to the original project.

Activity

  1. added this to the Project maintenance milestone on Sep 24, 2026
  2. added
    DeferredIntentionally deferred; see the issue for its activation condition.
    External validation unconfirmedExternal deployment or compatibility evidence is required for the environment named in the issue.
    P2Follow-on improvement or optional expansion after core requirements.
    Project maintenanceMaintainer responsibilities, support policy, contribution documentation and publication preparation.
    Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.
    TestA specific missing validation gate or reproducible test harness.
    on Sep 24, 2026
  3. ctfbruce commented on Oct 7, 2026

    @ctfbruce
    CollaboratorAuthor

    The external-pilot procedure was tightened in #407. It requires an exact signed release, an actual fresh-snapshot restore with the original stopped throughout, and separate API/control/proxy/TLS observations. A restart or local TEST drill does not substitute for the independent-node acceptance. Historical signing-state rollback is not established by that restore procedure.

    The procedure correction is merged, and all 16 main checks passed.

    This issue remains open for the authorized signed release, named independent operator/node and permitted destinations, and the actual installation, enrollment, measurement, restore and support observations. The filesystem-specific restore method must be agreed and validated before the rehearsal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    DeferredIntentionally deferred; see the issue for its activation condition.External validation unconfirmedExternal deployment or compatibility evidence is required for the environment named in the issue.P2Follow-on improvement or optional expansion after core requirements.Project maintenanceMaintainer responsibilities, support policy, contribution documentation and publication preparation.Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.TestA specific missing validation gate or reproducible test harness.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions