Skip to content

[OTHER][RELEASE] Complete S6 external-controller trust binding and live release evidence #357

Description

@Joncallim

Execution mode: implementation
Parent release Epic: #181 / #172
Depends on: #348, #352

Issue Type

Project Setup / Release Governance

Context

Repository-side S6 scaffolding is already substantial on main: the canonical S6 manifest has five partitions (contract, postgres, operator-desktop, operator-mobile, host-boundary) driven by four S6 suite commands plus a separate signed host preflight. Historical integrated review explicitly removed a duplicate issuance S6 partition because packet issuance belongs to #179/S4 and is already proven there.

The S6 controller surface defaults fail closed with externalControllerRequired: true, host evidence untrusted locally, ingress/issuance disabled and live activation disabled. Repository code cannot itself provide the required independent external trust.

The remaining release-critical work is operational: bind the independently installed controller GitHub App/check identity, protected repository rules, supported isolated host/root harness, signer/attestation material and final signed evidence chain to an exact reviewed commit.

Desired Outcome

An independently controlled supported-host release lane executes S6 against an exact reviewed SHA, produces externally signed preflight/suite/output/teardown/destruction evidence, publishes the exact-App-pinned forge/host-boundary-controller Check Run, and allows final Epic-172 readiness only when all required predecessor/authorization/lease/evidence predicates are satisfied.

Repository Actions/checkout code cannot counterfeit the required controller identity/evidence.

Tasks

  • Consume [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348's effective base ruleset/break-glass policy and [BUG][P1][SECURITY] Pin GitHub Actions dependencies to immutable commit SHAs #352's immutable external Action identities.
  • Provision/verify dedicated external controller GitHub App identity and immutable App ID/fingerprint outside checkout control.
  • Add the release-specific forge/host-boundary-controller required Check Run binding only for the applicable S6 release path/ruleset, without weakening base [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348 checks or deadlocking unrelated changes.
  • Provision/verify supported ephemeral host image/kernel/cgroup-v2/identity layout, root-owned harness/services, protected sockets/keys, PostgreSQL TLS fixture and zero-egress checkout namespace.
  • Ensure controller prefetches/digest-pins exact reviewed SHA, external Actions/dependencies/cache/image/fixtures/harness before checkout code executes.
  • Install/verify attestation public key + controller challenge path required by npm run preflight:mcp:host-boundary.
  • Run exact current S6 set: preflight + test:mcp:contract + test:mcp:postgres + e2e:mcp-operator + test:mcp:host-boundary; do not resurrect a separate S6 issuance suite.
  • Verify manifest identity/count and zero skip/retry/missing scenario behavior.
  • Produce signed evidence bound to exact SHA/build/image/App/check/epoch for preflight, suite results, output allowlist/scan, teardown/quiescence and VM destruction/trusted reimage.
  • Exercise wrong App/check identity, wrong SHA/moving ref, stale/replayed signature/authorization, controller loss/lease expiry, runner loss, suite timeout/failure, output quarantine violation and missing destruction receipt.
  • Run canonical inspect/disable/retry/key-rotation operator commands and prove fail-closed behavior under wrong identity/fingerprint/state.
  • Execute final enabled-build proof only inside allowed provisional window/lease and verify final readiness consumes required enablement + enabled-build receipts atomically.
  • Record release-closeout receipt/report containing only approved sanitized/path-free evidence metadata; no raw quarantined artifact upload.

Implementation Sequence

  1. External authority inventory — re-read current [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348 ruleset, [BUG][P1][SECURITY] Pin GitHub Actions dependencies to immutable commit SHAs #352 pins, S6 manifest/adapter/operator docs and exact controller/check requirements on current main; produce one immutable external-dependency manifest before provisioning.
  2. Controller App/check provisioning — create/verify dedicated GitHub App, least-privilege installation, exact App ID/key lifecycle and release-specific Check Run/ruleset binding; same-name Actions check negative test.
  3. Supported host bootstrap — immutable/ephemeral host image, kernel/cgroup/runtime prerequisites, root-owned controller/harness users/files/sockets, TLS database fixture, local-only attestation material and zero-egress checkout identity.
  4. Prefetch/attestation chain — controller resolves exact 40-char reviewed SHA and digest-pins checkout dependencies/cache/actions/image/harness/fixtures before untrusted checkout execution; generate one-time challenge/attestation envelope.
  5. Preflight proof — run signed preflight from exact checkout; wrong host/image/key/challenge/SHA/dependency digest fails before suites.
  6. Suite proof — execute current four commands/five manifest partitions with fixed ordering/limits, no skip/retry, isolated fixtures and exact scenario identity/count assertions.
  7. Quarantine/output proof — scan/allow only schema-validated sanitized path-free evidence; prove raw Playwright reports/logs/traces/screenshots/videos/dumps/diffs/archives/prompts/credentials cannot leave disposable host.
  8. Teardown/destruction proof — signed quiescence/process/resource teardown plus controller-owned VM destruction/trusted reimage receipt outside checkout authority.
  9. Failure/replay/controller-loss matrix — wrong/replayed signatures, stale authorization, lease expiry, controller/runner loss, timeout/failing suite/quarantine/destruction loss; every path fails closed with no readiness promotion.
  10. Provisional activation/final readiness — exercise controlled activation window with live controller lease/heartbeat and atomically consume exact enablement + enabled-build green receipts before deadline.
  11. Key rotation/disable/retry/recovery — canonical operator commands and signer/controller lifecycle evidence; no stale key/receipt promotion.
  12. Release closeout — exact build/App/image/manifest/receipt identities and residual uncertainty recorded; [EPIC] MCP S6 release proof and external-controller finalization #181/[EPIC] MCP admission, bounded context, and release-readiness trust boundary #172 tracking Epics can close only after independent evidence review.

Primary Code / Control Seams To Inspect First

  • docs/operators/host-boundary-controller-v2.md
  • docs/architecture/issue-181-e2e-admission-regression.md
  • docs/architecture/issue-181-review-amendments.md
  • .github/workflows/mcp-host-boundary-trusted.yml
  • web/test-contracts/mcp-admission-v2.json
  • web/lib/mcps/epic-172-s6-release-adapter.ts
  • S6/preflight/release scripts referenced from web/package.json
  • Epic-172 signer/transition/lease/release-evidence tables and operator scripts
  • external GitHub App/ruleset and host/root configuration (kept outside repo; do not copy secrets into issue/CI artifacts)

Orthogonal Checkpoints

  1. Repository/App authority: base [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348 checks remain mandatory; exact external App/check cannot be spoofed by Actions/checkout/bot; break-glass cannot silently satisfy S6 proof.
  2. Supply chain: exact SHA, Action/dependency/cache/image/harness/fixture digests, moving-ref and poisoned-cache attempts.
  3. Host containment: untrusted checkout cannot access root/controller users, sockets, keys, secrets, network egress or privileged services; process/cgroup/mount/user namespace assumptions tested.
  4. Cryptographic freshness: signer/key generation, domain separation, nonce/replay/cross-build/cross-App/cross-epoch/cross-check substitution and retirement.
  5. Suite identity: exact five partitions/four commands, no accidental duplicate issuance partition, manifest/scenario identity/count/skip/retry rules.
  6. Output privacy: hostile sentinel secrets/paths in stdout/stderr/test artifacts; quarantine allows only contract-approved status/evidence.
  7. Failure ownership: controller vs runner loss, DB/host/suite timeout, lease/heartbeat expiry, partial evidence, teardown/destruction failure.
  8. Activation race: provisional deadline/lease/current owner/build changes between preflight/suites/enablement/final evidence consumption.
  9. Recovery/rotation: disable, retry and key rotation cannot lower epoch/reuse stale evidence or strand unsafe enabled state.
  10. Independent release review: controller evidence is inspected outside the checkout that produced test output; no self-verifying path.

Acceptance Criteria

  • [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348 and [BUG][P1][SECURITY] Pin GitHub Actions dependencies to immutable commit SHAs #352 are closed before this release provisioning begins.
  • Base main protections remain intact and S6 adds an exact external App/check requirement only where applicable; ordinary PRs are not deadlocked.
  • Controller/root harness/key material lives outside checkout and cannot be read/replaced by checkout/test identities.
  • Reviewed input is an exact immutable 40-character commit SHA, never a branch/tag/moving ref.
  • Checkout/test code runs in supported zero-egress confinement and cannot access controller credentials/privileged identities/root commands.
  • S6 topology is verified as five manifest partitions / four commands plus preflight; issuance remains owned by [FEATURE] S4 — Specialist prompt and bounded context packet assembly with run evidence #179/S4.
  • Every required suite runs first-attempt with no skip/retry and exact manifest identities/counts.
  • Signed evidence covers preflight, exact suite result, output scan/manifest, teardown/quiescence and VM destruction/reimage bound to exact build/image/App/check identity.
  • Wrong/stale/replayed/cross-build/cross-App evidence or controller/lease loss fails closed before activation/final readiness.
  • Output quarantine permits only schema-validated sanitized path-free status/evidence; raw reports/logs/traces/screenshots/videos/dumps/diffs/archives/prompts/credentials do not leave disposable environment.
  • Final readiness occurs only while same provisional owner/lease/deadline is valid and consumes required receipts atomically.
  • Unsupported hosts remain activation-ineligible without corrupting epoch/evidence/state.
  • Operator inspect/disable/retry/key-rotation/rollback behavior is proven against the live configured lane.
  • Closeout contains no raw controller private key/token/credential and is independently reviewable.

Out of Scope

  • Reimplementing S1-S5 admission/grant/packet policy.
  • Reintroducing a standalone S6 packet-issuance suite.
  • Letting repository code own the privileged controller/harness.
  • Weakening output quarantine for debugging.

Implementation Scope

Very Large / release-critical infrastructure - repository-side changes may be small, but host/App/ruleset provisioning and evidence exercises require multiple independently reviewable operational checkpoints.

Technical Notes

This work necessarily includes external GitHub/host mutations and secret material. Implementation agents may prepare/configure through available authorized interfaces, but every consequential change must retain operator-visible evidence and never expose raw keys/tokens in ordinary GitHub issues/Actions artifacts.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependency-blockedREADINESS PROJECTION — Issue is blocked by unresolved dependencies. This label is a cache.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions