Skip to content

Authenticate retained attribution and enforce aggregate egress budgets - #409

Merged
ctfbruce merged 15 commits into
mainfrom
feat/authenticated-history-and-budgets
Oct 7, 2026
Merged

ctfbruce merged 15 commits into
mainfrom
feat/authenticated-history-and-budgets

Conversation

@ctfbruce

@ctfbruce ctfbruce commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Historical attribution exports now authenticate the complete dated lookup and the enrolled executor’s schedule. Offline verification accepts independently pinned dispatcher keys, historical executor certificates and capture-clock observations; replayed query metadata and tampered exports are rejected. Optional client-identity TLS remains explicitly unsigned.

Aggregate application-egress grants reserve user, node and every matching target-group budget atomically. Grants cover payload volume, rate/burst, connection attempts and pinned targets; unresolved execution authority continues to consume capacity across later windows until authenticated retirement. The host applies the same grant across guest sockets and accepted TCP replies.

Adds observed ingress/egress TCX_DROP verdict and SKB-byte totals with explicit unavailable states. These observations describe the active counter instance; they do not establish complete wire coverage or independently verified enforcement. Actual independent cross-host clock measurement remains a separate acceptance requirement.

This advances the additive HTTP API to 1.21 and requires explicit state upgrade to dispatcher schema 30/executor schema 9. Guest experiment messages use a dependency-free shared package, preserving the wire aliases and keeping five-participant requests below the existing envelope limit. Installed upgrade fixtures preserve the actual released schema before exercising the upgrade.

Validation: pinned protocol/SQL generation and schema checks; native package compilation; focused race tests for durable grants, real TCP/TLS/UDP/ICMP sockets, DNS changes, authenticated retirement, signed history, TLS proxy/optional identity, clock records and metrics. The drop observation source passed the controlled kernel race suite without skips, including delivered/denied UDP and detached-hook observations. All 17 candidate checks passed on e5f6927, including installed five-executor experiments, released upgrades, compatibility and the complete test/race/kernel suites. The normal merge preserves the exact tested tree.

Related: #66, #71, #72, #73 and #116.

TheodorAdrienIsaak Mattli added 15 commits October 7, 2026 14:04
# Conflicts:
#	api/openapi.yaml
#	api/spec.go
# Conflicts:
#	internal/storagecheck/policy.go
#	protocol/protocol.pb.go
Keep the stored-state reference aligned with authenticated schedule history and durable aggregate grants. Refs #66 and #71.
# Conflicts:
#	protocol/protocol.pb.go
Keep the Python tag-algorithm reference separate from authenticated evidence checks in the CLI and Go client. Companion support must be established by its own change. Refs #73.
Keep guest experiment messages in a dependency-free package while preserving wire aliases. Read released database fields before the installed upgrade and compare the full retained rows afterward.

GitHub issues #7, #66 and #73.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant