Skip to content

Recertify: uncertified in-place change to deployed deploy_forge.sh (build #39297) + missing product-readiness report #22

Description

@echoomegaprime

Summary

The deployed Certification Forge release 795ca1a927b8af649c91bfe74b84f55dc2e5c852 was modified in place on the production host on 2026-09-24 (~11:44 UTC) by an autonomous build (build prompt #39297, "echo-certforge-dispatcher restart storm / giveup"). The change never went through this repository or a CertForge certification run.

What changed

deploy/deploy_forge.sh (dispatcher unit template), and the same line in the live dispatcher systemd unit:

 [Unit]
 Description=echo-certification-forge - durable subscriber run dispatcher
 After=network.target $SERVICE.service
-Requires=$SERVICE.service
+Wants=$SERVICE.service

Assessment

Benign. With Requires=, every restart or crash of the API service was propagated to the dispatcher. That cascade pushed the dispatcher into start-limit-hit during the #39297 incident. With Wants=, the dispatcher keeps its ordering after the API service and still starts it, but a failure of the API service no longer takes the dispatcher down. No code, policy, signing or evidence paths were touched. The pre-change copy was kept next to the modified file, so we left the change in place instead of reverting it.

Why this needs follow-up

  • The running release no longer matches its certified source tree. This is the kind of uncertified drift the platform is supposed to prevent.
  • /v1/status currently reports NOT_READY with product_readiness_report_missing. The signed exact-source readiness report for 795ca1a is no longer present on the host. scripts/master_acceptance.py cannot regenerate it from the committed artifacts/ alone, because the committed P4 evidence (artifacts/p4_forge_acceptance.json, source 8ccfa65) has no completed_phase_gate: "P4" field. P1-P3, P5 (adapter gate GO), P6 (p6_acceptance.summary.json, 12/12) and P7 validate. A fresh P4 hostile acceptance run is required. Hosted CI for 795ca1a is green (run 33543830708).

Recommended actions

  1. Upstream the Requires= → Wants= change as a normal PR against main (with a test covering the unit template).
  2. Cut a new exact-SHA release from that PR's merge commit and re-run the full release pipeline: P4 hostile acceptance, scripts/master_acceptance.py, and the deploy gate. This recertifies the product and restores a signed product-readiness report.
  3. Treat any future in-place edit of a deployed release as an incident. Autonomous builders are now gated on a CertForge verdict before any merge, but direct edits to live files bypass that gate.

Filed by the ECHO ops pass on 2026-09-24.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions