Skip to content

Hold enrolled workloads until Phantom Engine is enforce-ready - #151

Merged
zacharybalicki merged 2 commits into
mainfrom
cursor/fd-reboot-1-early-boot-hold-b6f0
Oct 1, 2026
Merged

zacharybalicki merged 2 commits into
mainfrom
cursor/fd-reboot-1-early-boot-hold-b6f0

Conversation

@zacharybalicki

@zacharybalicki zacharybalicki commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

After a reboot, an enrolled workload can run while the Phantom Engine loader is down and the BPF pins are empty. This change closes that gap in open-core with an enrolled-only early hold plus a start gate. The hold is on by default. It does not drop the host default route, so SSH, DHCP, DNS, and unenrolled processes keep working.

vantio-install apply installs and enables the hold before the observe container starts. A trusted root opt-out file is left alone, so apply does not turn the hold back on. The opt-out is logged and shown on vantio-boot-hold status and in installer HEALTH.json.

vantio-boot-hold.service runs before Docker and containerd. It drops egress only for vantio-enrolled.slice and for the enrolled subnet 10.250.250.0/24. Release waits for more than a running loader: pins present, policy loaded, cgroup_skb_egress_enforce attached to the enrolled slice, loader health OK, and a live deny check (enrolled connect fails, the same connect outside the slice succeeds). A loader that is running but not attached keeps the hold. If that check fails, enrolled workloads stay held and status shows HELD / DEGRADED.

Break-glass is one root command, vantio-boot-hold release --break-glass --i-am-root-operator. It removes the packet hold, clears the file hold, and drops the systemd Requires= start gates for enrolled units. The audit log lists what was released. An enrolled workload cannot run it.

Plain Docker, Compose, and systemd each have a start unit that requires enforce-ready when ordering is on. Enroll refuses a Docker restart policy other than no. A workload missing from the registry is UNPROTECTED in status.

The reboot row stays NOT_PROVED. This PR does not mark B1-REBOOT-EXPOSURE as passed, does not retro-claim seal e0b19d55…, and does not invent a new seal. GAP-BH-002 and GAP-BH-005 through GAP-BH-009 stay open. The companion note is docs/planning/boot-hold/PE-COMPANION.md. The Free-plan lab procedure is docs/planning/boot-hold/FD-REBOOT-1-LAB-PROCEDURE.md (account 960577828987, expected out-of-pocket $0). That procedure is not run from this PR.

Test plan

  • python3 -m unittest discover -s tests -t . in packages/vantio-install (172 tests, OK)
  • Fixture vantio-install apply writes and enables vantio-boot-hold.service and records HELD on HEALTH.json without turning enforcement on
  • A trusted opt-out survives apply and shows OPTED_OUT in health
  • A running loader with the program loaded but not attached stays held
  • Break-glass clears packet hold and Requires= and the audit lists the released gates
  • Release refuses a non-root caller, a caller outside the host init namespace, and a caller in vantio-enrolled.slice
  • Host reproof of the reboot matrix (not this PR; row stays NOT_PROVED)

No EC2, no publish, no Paid, no soak, fleet, or k3s.

Open in Web Open in Cursor 

@zacharybalicki
zacharybalicki requested a review from a team October 1, 2026 03:59

Copy link
Copy Markdown
Member Author

FOUNDER_OVERRIDE_MERGE deferred — merge conflicts

Exact tip 89a02ae2bb1b882c2ed91d207fbb1415ddf5faa2 cannot squash onto main after #149/#146/#148 landed.

Rebase onto 0f33dce… in progress on phantom-box. After new tip + CI green + re-council, Founder override may proceed. Reboot row stays NOT_PROVED.

After reboot an enrolled workload can run while the loader and BPF pins are still down. This adds an enrolled-only early hold and a start gate, and leaves the reboot row NOT_PROVED until a host reproof.
…eck.

Ordinary apply now enables the hold. A running loader that is not attached keeps enrolled workloads held. Break-glass clears the packet hold and the start gate in one root action.
@zacharybalicki
zacharybalicki force-pushed the cursor/fd-reboot-1-early-boot-hold-b6f0 branch from 89a02ae to a492097 Compare October 1, 2026 05:24
@zacharybalicki
zacharybalicki merged commit 8c94ab1 into main Oct 1, 2026
8 checks passed
@zacharybalicki

Copy link
Copy Markdown
Member Author

FOUNDER_OVERRIDE_MERGE by Founder bypass (zacharybalicki, pull-request bypass on ruleset 24281604). This is not a Kate review. It is not a kvantio approval. It is not code-review-kate.

Squash merge SHA: 8c94ab1c1b16b177bd3bb13250f98116ed8e56a7
Authorized head that was merged: a492097fe213e0bf7fa63413f66e6ad7d57fa385
Base: 0f33dce12062efdb5a2e6768dd92c20c4cc0b359
Superseded tip, not merged: 89a02ae2bb1b882c2ed91d207fbb1415ddf5faa2

Council on a492097fe213e0bf7fa63413f66e6ad7d57fa385: PASS_WITH_NONBLOCKING_NOTES. Founder-required gaps 001, 003, and 004 stay closed. GAP-BH-002 and GAP-BH-005 through GAP-BH-009 stay open.

main now points at 8c94ab1c1b16b177bd3bb13250f98116ed8e56a7. The squash parent is 0f33dce12062efdb5a2e6768dd92c20c4cc0b359. The squash tree matches the authorized head.

The reboot exposure row stays NOT_PROVED. A clean-host reproof is still required. This merge does not mark B1-REBOOT-EXPOSURE passed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant