docs(prd): require cleanup execution integrity
test / image-input-builds (pull_request) Failing after 14m11s
test / unit (pull_request) Failing after 14m19s
prd-number-check / require-numbered-prds (pull_request) Failing after 14m25s
test / integration-docker (pull_request) Has been cancelled
test / coverage (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Failing after 12m36s
test / image-input-builds (pull_request) Failing after 14m11s
test / unit (pull_request) Failing after 14m19s
prd-number-check / require-numbered-prds (pull_request) Failing after 14m25s
test / integration-docker (pull_request) Has been cancelled
test / coverage (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Failing after 12m36s
This commit is contained in:
@@ -45,6 +45,12 @@ misleading behavior:
|
|||||||
8. Firecracker artifact downloads and registry publication have no network
|
8. Firecracker artifact downloads and registry publication have no network
|
||||||
deadline, so an unresponsive registry can hold setup or release work
|
deadline, so an unresponsive registry can hold setup or release work
|
||||||
indefinitely.
|
indefinitely.
|
||||||
|
9. Authenticated secret blobs select the unauthenticated legacy decoder when
|
||||||
|
their in-band version prefix is changed, allowing storage tampering to
|
||||||
|
bypass tag verification.
|
||||||
|
10. Cleanup executes the entire post-confirmation snapshot rather than the
|
||||||
|
intersection with what the operator saw, and mutation failures are not
|
||||||
|
reflected in the command result.
|
||||||
|
|
||||||
These are one design problem: state used to authorize deletion, replacement,
|
These are one design problem: state used to authorize deletion, replacement,
|
||||||
or resource allocation must be authoritative at the point of use.
|
or resource allocation must be authoritative at the point of use.
|
||||||
@@ -73,6 +79,12 @@ or resource allocation must be authoritative at the point of use.
|
|||||||
as completion while preserving diagnostics for unexpected failures.
|
as completion while preserving diagnostics for unexpected failures.
|
||||||
- Artifact pull, existence-check, and publication requests use explicit
|
- Artifact pull, existence-check, and publication requests use explicit
|
||||||
network deadlines.
|
network deadlines.
|
||||||
|
- Persisted secrets accept only the authenticated format. The schema migration
|
||||||
|
intentionally clears legacy rows; local agents are reprovisioned rather
|
||||||
|
than retaining a ciphertext-controlled downgrade path.
|
||||||
|
- Cleanup executes only resources present in both the displayed and current
|
||||||
|
authoritative plans, attempts every approved mutation, and returns failure
|
||||||
|
when any mutation does not complete.
|
||||||
- Unit tests cover PID/path reuse, partial backend enumeration, transient
|
- Unit tests cover PID/path reuse, partial backend enumeration, transient
|
||||||
policy resolution failure, slow bodies, concurrency saturation, and stream
|
policy resolution failure, slow bodies, concurrency saturation, and stream
|
||||||
closure races.
|
closure races.
|
||||||
@@ -146,6 +158,8 @@ reported through the supervisor's normal diagnostic channel.
|
|||||||
7. Gateway shutdown log-pump closure handling.
|
7. Gateway shutdown log-pump closure handling.
|
||||||
8. Lossless Firecracker process identities, authoritative Docker cleanup
|
8. Lossless Firecracker process identities, authoritative Docker cleanup
|
||||||
queries, and bounded Firecracker artifact transfers.
|
queries, and bounded Firecracker artifact transfers.
|
||||||
|
9. Mandatory authenticated secret storage, shared cleanup-plan intersection
|
||||||
|
and mutation accounting, and contained Git backend process failures.
|
||||||
|
|
||||||
## Open questions
|
## Open questions
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user