Repository navigation
Authenticate retained attribution and enforce aggregate egress budgets - #409
Merged
Merged
Conversation
added 15 commits
October 7, 2026 14:04
# Conflicts: # api/openapi.yaml # api/spec.go
# Conflicts: # internal/storagecheck/policy.go # protocol/protocol.pb.go
# Conflicts: # protocol/protocol.pb.go
Keep the Python tag-algorithm reference separate from authenticated evidence checks in the CLI and Go client. Companion support must be established by its own change. Refs #73.
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Historical attribution exports now authenticate the complete dated lookup and the enrolled executor’s schedule. Offline verification accepts independently pinned dispatcher keys, historical executor certificates and capture-clock observations; replayed query metadata and tampered exports are rejected. Optional client-identity TLS remains explicitly unsigned.
Aggregate application-egress grants reserve user, node and every matching target-group budget atomically. Grants cover payload volume, rate/burst, connection attempts and pinned targets; unresolved execution authority continues to consume capacity across later windows until authenticated retirement. The host applies the same grant across guest sockets and accepted TCP replies.
Adds observed ingress/egress TCX_DROP verdict and SKB-byte totals with explicit unavailable states. These observations describe the active counter instance; they do not establish complete wire coverage or independently verified enforcement. Actual independent cross-host clock measurement remains a separate acceptance requirement.
This advances the additive HTTP API to 1.21 and requires explicit state upgrade to dispatcher schema 30/executor schema 9. Guest experiment messages use a dependency-free shared package, preserving the wire aliases and keeping five-participant requests below the existing envelope limit. Installed upgrade fixtures preserve the actual released schema before exercising the upgrade.
Validation: pinned protocol/SQL generation and schema checks; native package compilation; focused race tests for durable grants, real TCP/TLS/UDP/ICMP sockets, DNS changes, authenticated retirement, signed history, TLS proxy/optional identity, clock records and metrics. The drop observation source passed the controlled kernel race suite without skips, including delivered/denied UDP and detached-hook observations. All 17 candidate checks passed on
e5f6927, including installed five-executor experiments, released upgrades, compatibility and the complete test/race/kernel suites. The normal merge preserves the exact tested tree.Related: #66, #71, #72, #73 and #116.