Skip to content

evidence: land honey-backbone preflight packets (2026-07-14) - #574

Draft
Jesssullivan wants to merge 1 commit into
mainfrom
evidence/honey-backbone-preflight-rescue-20260714
Draft

evidence: land honey-backbone preflight packets (2026-07-14)#574
Jesssullivan wants to merge 1 commit into
mainfrom
evidence/honey-backbone-preflight-rescue-20260714

Conversation

@Jesssullivan

Copy link
Copy Markdown
Owner

Summary

Lands 10 honey-backbone preflight evidence packets generated during the
2026-07-14 honey-backbone preflight runs (docs/release/evidence/honey-backbone-preflight-20260714T*).
These packets were generated on the facet6 primary checkout and sat untracked
in the working tree since; landing them now per the repo's immutable-evidence
convention (docs/release/evidence/README.md) so they don't get lost to a
worktree cleanup.

  • 10 timestamped packets, 2026-07-14T16:20Z through 2026-07-14T18:41Z
  • Each packet: result.env, summary.md, device list/status transcripts
    (local + honey via ssh), redacted config TOML, tcfs status output, and
    NATS endpoint probes
  • 7 of 10 packets report proof=blocked-g2 (neo-side storage/NATS not OK);
    3 report proof=honey-backbone-preflight-complete
  • Content is unmodified from what was generated; reviewed for secret-shaped
    material (tokens, keys, passwords) before landing — only public age1...
    recipient keys and internal tailnet endpoints appear, consistent with the
    *-config.redacted.toml naming
  • No changes to docs/release/evidence/README.md — the "Current promoted
    proofs" table is untouched; these are blocker/partial packets per the
    ledger's own claim rules, not stronger proofs that would warrant a
    promotion

Test plan

  • Diffed copied packets against the original untracked directories
    (byte-identical)
  • Grepped all 120 files for secret-shaped patterns (token/secret/password/
    BEGIN/age1/AKIA/ghp_/github_pat) — only public age recipient keys and one
    stack-trace symbol name (connect_daemon_with_token) matched, no actual
    secret material
  • Operator review of packet placement/naming

Not merging — opening for operator review per the immutable-evidence rescue
convention.

@Jesssullivan

Copy link
Copy Markdown
Owner Author

[authority and failure hold — 2026-07-30]

Exact head remains 4629179a721fb3f1bd37a3cd7306732b37d4919c on base e7bfc1f01c3298c5ed6ad25254f6cc67d2a59213. The current run set is not sanctioned merge authority: every assigned job in runs 30506968079, 30506968108, and 30506968120 is in the GitHub Actions group on ubuntu-latest, macos-14, or windows-latest.

The red Build + Lint + Test job 90758735147 is a runner-capability failure, not an evidence-packet source failure: both real-FUSE tests reached /usr/local/bin/fusermount3: mount failed: Operation not permitted, then timed out waiting for mounted=true. Do not rerun on hosted capacity. Keep the PR held for the GF-owned runner authority correction and fresh natural exact-head CI on sanctioned tinyland-* labels.

@Jesssullivan
Jesssullivan marked this pull request as draft July 30, 2026 02:45
@Jesssullivan

Copy link
Copy Markdown
Owner Author

[source-integrity fence — 2026-07-30]

The sole commit 4629179a721fb3f1bd37a3cd7306732b37d4919c is unsigned (verification.reason=unsigned). The PR is now draft in addition to the existing hosted-runner and FUSE-capability hold.

Keep this history unmergeable. Preserve the rescued 120-file evidence tree, but replace it through a signed composition path after CI authority is corrected; no force-push or hosted rerun is authorized here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant