Record rootless runtime qualification evidence

This commit is contained in:
rcourtman
2026-09-01 22:09:22 +01:00
parent 152ef86d33
commit 45dd45fe29
7 changed files with 155 additions and 22 deletions
+2 -2
View File
@@ -272,8 +272,8 @@ or generic command path.
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; signed updates cross the fixed helper protocol and commit only after an authoritative report | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `22fd662fb794f63efb9d3ca2158de73c4e07e1b8`** across the schema-v6 twenty-scenario run. It covers install, migration, explicit/automatic rollback, helper protocol and resource boundaries, effective-unit override rejection, reporting continuity, authoritative executable-digest commit, watchdog rollback, helper-restart recovery, and last-known-good restoration. It remains opt-in pending exact-RC reproduction, representative provider/appliance parity, and external review | `deployment-installability` and `security-privacy`: reproduce the same helper transaction from trusted release artifacts on representative hosts and accept the external boundary review |
| Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases |
| Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | Unit and installer regressions cover the boundary, but no representative live Docker/Podman qualification exists. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record fresh install, migration, restart, helper loss/recovery, bounds, and summary parity on representative rootful Docker and Podman; decide explicitly whether reduced telemetry is sufficient |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Implemented, unqualified live. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | A separate opt-in `secure-runtime-rootless-v1` harness and fail-closed receipt validator define disposable nested Ubuntu/systemd Docker and Podman proof without changing immutable schema v7. No complete retained receipt exists yet, so this does not justify container-runtime parity or a default change | `deployment-installability`: run and retain the exact source/artifact-bound fresh-install, migration, restart, socket-loss, ambiguity, helper/direct recovery, cleanup, and telemetry-parity packet for both rootless Docker and rootless Podman |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | The standalone rootless packet exercises live same-family rootful Docker and Podman helper fallback plus summary-inventory semantic parity during socket loss. It does not qualify the complete standalone rootful fresh-install, migration, restart, helper-loss/recovery, and bounds matrix. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record the remaining standalone lifecycle matrix on representative rootful Docker and Podman and decide explicitly whether reduced telemetry is sufficient |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Qualified locally for the exact source-bound monitoring path. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | **Qualified on distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts at commit `60041ad9e60c282c892f944e04f777b874991a5d`.** All eleven canonical scenarios passed for Docker and all eleven for Podman. Receipt SHA-256: `7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`; local attestation SHA-256: `566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. This is local opt-in artifact-bound self-attestation, not published-RC provenance, action/update qualification, external review, or authorization for a default change | `deployment-installability`: reproduce the exact packet from published release artifacts; separately qualify any desired rootless image-update/action surface; retain the opt-in default until the remaining provider, appliance, and review conditions pass |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v6 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, effective-unit override rejection, exact credential rotation, bodyless self-revocation, and collector/helper continuity. A separate production Router regression exercises HTTPS issuance, WSS admission, encrypted token persistence, failed-rotation rollback, exact socket invalidation, two server restarts, old-secret rejection, and durable self-revoke | Qualified for the exercised systemd fixture paths and focused production Router lifecycle. Focused installer tests also cover atomic pending cancellation and fail-closed credential retention. The evidence does not cover every runner operation, representative providers, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce the combined systemd and production Router path from trusted RC artifacts with representative package-update success/failure/cancellation evidence |
| Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets. Focused protocol tests prove expired requests are not dispatched, timeout/caller abandonment sends one request-bound cancellation across every typed mutation family, and a canceled Proxmox mutation persists an indeterminate terminal receipt that survives runner reconnect and replays without a second mutation | This is local protocol/durability proof only: it makes no live-provider action-parity claim and does not change the default | `agent-lifecycle`: record target-bound success, stale-state refusal, provider-handoff cancellation, reconnect/replay, and independent postconditions on disposable real targets |
| Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported |
@@ -175,9 +175,10 @@ migration, helper restart continuity, and helper-loss/recovery scenarios. The
release workflow creates its daemon inside the disposable systemd host, seeds
an offline source-bound fixture image, exposes only the root-owned Unix socket,
and never mounts the hosted runner's Docker socket. V7 narrows only the
rootful-Docker summary-inventory residual; Podman, rootless-runtime parity,
container metrics, image-update checks, typed container actions, appliance
coverage, and external review remain open. No schema-v7 receipt exists until
rootful-Docker summary-inventory residual; rootful Podman, standalone rootless
runtime proof, container metrics, image-update checks, typed container actions,
appliance coverage, and external review remain outside that schema. No
schema-v7 receipt exists until
an exact immutable prerelease packet successfully completes that workflow, so
this contract does not change the product default or upgrade the current v6
evidence classification.
@@ -245,9 +246,12 @@ query before proving ancestry. `HEAD`, a local branch, or an arbitrary ref can
never receive the committed-main label.
The repository still needs a fresh exact committed release-candidate run,
representative Proxmox, SMART, Docker and rootless Podman telemetry/action
parity, appliance profiles, and the external security review. Until those
proofs are recorded, the safe profile remains opt-in and provider degradation
representative Proxmox and SMART proof, the complete standalone rootful
Docker/Podman lifecycle matrix, any separately authorized rootless update or
action proof, appliance profiles, and the external security review. The local
rootless Docker/Podman monitoring and lifecycle matrix described below is now
qualified for its exact source-bound packet, but it does not satisfy those
remaining proofs. The safe profile remains opt-in and provider degradation
remains an explicit residual rather than evidence that the candidate lane is
complete.
@@ -265,9 +269,10 @@ and the running collector can transition between direct rootless monitoring
and typed-helper summary fallback without restarting or enabling collector
actions. Legacy Docker report-response commands, registry update scans, and
orphan-backup cleanup are disabled statically whenever the helper-backed safe
profile is configured. This is implementation proof only; the live fresh-install, restart,
ambiguity, loss, bidirectional recovery, and telemetry-parity matrix remains
the qualification residual.
profile is configured. The standalone packet below now binds this
implementation to a live local fresh-install, migration, restart, ambiguity,
loss, recovery, authority-isolation, cleanup, and telemetry-parity exercise for
both runtime families.
The standalone `secure-runtime-rootless-v1` packet now owns that residual
without changing the immutable schema-v7 systemd contract. Its opt-in wrapper
@@ -276,9 +281,25 @@ collector-owned rootless Docker and Podman daemons, separate same-family
rootful helper baselines, exact installer pins, runtime loss and recovery, and
cleanup before its independent validator can emit a local artifact-bound
self-attestation. A checked-in harness or locally passing ordinary tests are
not qualification. Until a complete secret-free receipt and attestation are
retained, the matrix row remains implemented-but-unqualified and the safe
profile remains opt-in.
not qualification.
The exact packet at source commit
`60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical
scenarios for Docker and all eleven for Podman on distinct disposable hosts.
The secret-free receipt SHA-256 is
`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and
the local artifact-bound attestation SHA-256 is
`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`.
The validator matched 418 governed source files, both runtime-specific socket
profiles, distinct host and daemon identities, and all twenty-two scenario
records. The sanitized evidence record is
`internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`.
This closes the local live-proof residual only for the exercised rootless
monitoring, migration, fallback, recovery, ambiguity, parity, authority, and
cleanup paths. Its classification remains local, opt-in, artifact-bound
self-attestation; it is not published-release provenance, default-profile
authorization, rootless action/update qualification, or independent security
review. The safe profile therefore remains opt-in.
## Target Architecture
@@ -0,0 +1,81 @@
# Secure rootless runtime v1 local qualification (2026-09-01)
## Classification
The standalone `secure-runtime-rootless-v1` packet passed from exact source
commit `60041ad9e60c282c892f944e04f777b874991a5d`. The independent validator
classified it as
`local-opt-in-rootless-runtime-artifact-bound-self-attestation` and verified
all 418 governed source hashes plus the exact collector, helper, installer, and
qualification-test artifact bindings.
The secret-free receipt has SHA-256
`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`.
The separate attestation has SHA-256
`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`.
Its source manifest has SHA-256
`cae1c8c53ff7019ad0fa82c39e90635ed0290a97a2055c3978005cbda1bca497`.
The full receipt and attestation remain retained local evidence rather than
published release assets; this record intentionally stores only their
secret-free identifiers and qualification scope.
## Exercised runtime matrix
Two distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts completed the
canonical eleven scenarios for each runtime, for twenty-two passing scenario
records in total:
1. `fresh_install`
2. `legacy_migration`
3. `collector_restart`
4. `daemon_restart`
5. `socket_loss_helper_fallback`
6. `direct_recovery`
7. `dual_socket_ambiguity_refusal`
8. `exact_pin_recovery`
9. `telemetry_parity`
10. `authority_isolation`
11. `cleanup`
The Docker host reported machine identity
`9050518de741748dc8bf3a1d04861e58`, Docker 29.7.2, rootless daemon identity
`1fb49913-d54b-41bc-864f-42e1e33f88ab`, and collector-owned socket
`/run/user/996/docker.sock` with mode `0660`. The Podman host reported machine
identity `c063c32387eafbfd6abec6e939256b59`, Podman 4.9.3, rootless daemon
identity `ecec4fdfedced3b59b47048cb1be54c14901d3f41b0aee6e28f6bc84446c6631`,
and collector-owned socket `/run/user/996/podman/podman.sock` with mode `0600`.
The distinct machine and daemon identities prevent one shared fixture from
standing in for both runtime families.
The packet proved fresh safe-profile installation, legacy authority-reducing
migration, collector and daemon restart continuity, same-family rootful typed-
helper summary fallback during rootless socket loss, direct recovery without
collector restart, fail-closed dual-socket ambiguity handling, root-owned exact
pin recovery, and direct telemetry parity against a root client of the same
rootless daemon. Direct telemetry included complete inventory, stats, full
fields, and secondary inventory. Authority isolation proved that the non-root
collector had no command session or command transport, no rootful socket
access, and no container action or update authority. Strict teardown removed
the fixture containers, stopped both runtimes, removed their sockets and
delegated state, and left no labeled qualification containers behind.
## Boundaries and remaining work
This packet closes the local live-proof residual for the exact exercised
rootless Docker and Podman monitoring, migration, fallback, recovery,
ambiguity, parity, authority, and cleanup paths. It does not extend or
reinterpret the schema-v7 systemd contract.
The attestation records four explicit limitations:
- `not-published-release-provenance`
- `not-default-profile-authorization`
- `not-independent-security-review`
- `production-exact-scope-proof-is-external-prior`
It does not qualify rootless container image-update checks or typed container
actions, which remain disabled in the safe collector. It does not qualify the
complete standalone rootful Docker/Podman lifecycle matrix, Proxmox or SMART
provider parity, appliance profiles, or an exact published release candidate.
The safe profile therefore remains explicit opt-in, and this record does not
complete or accept the proposed secure-agent-runtime-separation lane.
@@ -9834,6 +9834,11 @@
"path": "docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v6-2026-08-31.json",
"kind": "file"
},
{
"repo": "pulse",
"path": "docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md",
"kind": "file"
},
{
"repo": "pulse",
"path": "internal/api/agenttokens/install.go",
@@ -7375,9 +7375,22 @@ the durable daemon identity. Dual-socket ambiguity evidence validates Docker
and Podman against their respective recorded socket ownership and modes; it
must not project the selected runtime's permissions onto the other socket.
Its classification is local, opt-in,
artifact-bound self-attestation only. No receipt exists merely because the
harness is checked in, so rootless Docker and Podman remain live-unqualified
and cannot change the product default.
artifact-bound self-attestation only. The exact packet at source commit
`60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical
scenarios for Docker and all eleven for Podman on distinct disposable hosts.
Its secret-free receipt SHA-256 is
`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and
its attestation SHA-256 is
`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`.
The validator matched 418 governed source hashes, exact artifacts, the two
runtime-specific socket profiles, distinct host and daemon identities, and all
twenty-two scenario records. The sanitized evidence record is
`docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`.
This qualifies only the exercised local rootless monitoring, migration,
fallback, recovery, ambiguity, parity, authority, and cleanup paths. It is not
published-release provenance, default-profile authorization, rootless
action/update qualification, or independent security review and cannot change
the product default.
### Command and durable typed dispatch are context-honest and canceled when abandoned
@@ -299,9 +299,22 @@ authority, and cleanup evidence before the independent validator can emit a
local artifact-bound self-attestation. All three Go artifacts require explicit
VCS stamping at build time; unavailable revision or clean-worktree metadata is
a build failure rather than an attestable omission. Checking in the harness or passing its
ordinary contract tests is not live qualification. Until a complete
secret-free receipt and attestation are retained, this surface remains
implemented-but-unqualified and cannot change the opt-in safe-profile default.
ordinary contract tests is not live qualification. The exact packet at source
commit `60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical
scenarios for Docker and all eleven for Podman on distinct disposable hosts.
Its secret-free receipt SHA-256 is
`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and
its local artifact-bound attestation SHA-256 is
`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`.
The validator matched 418 governed source hashes, exact artifacts, the two
runtime-specific socket profiles, distinct host and daemon identities, and all
twenty-two scenario records. The sanitized evidence record is
`docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`.
This qualifies only the exercised local rootless monitoring, migration,
fallback, recovery, ambiguity, parity, authority, and cleanup paths. It is not
published-release provenance, default-profile authorization, rootless
action/update qualification, or independent security review, so the safe
profile remains opt-in.
When both runtime sockets are present for ambiguity refusal, the validator
checks each entry against that runtime's own recorded GID and mode while using
the current disposable host's collector UID and canonical socket path.
@@ -272,8 +272,8 @@ or generic command path.
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; signed updates cross the fixed helper protocol and commit only after an authoritative report | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `22fd662fb794f63efb9d3ca2158de73c4e07e1b8`** across the schema-v6 twenty-scenario run. It covers install, migration, explicit/automatic rollback, helper protocol and resource boundaries, effective-unit override rejection, reporting continuity, authoritative executable-digest commit, watchdog rollback, helper-restart recovery, and last-known-good restoration. It remains opt-in pending exact-RC reproduction, representative provider/appliance parity, and external review | `deployment-installability` and `security-privacy`: reproduce the same helper transaction from trusted release artifacts on representative hosts and accept the external boundary review |
| Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases |
| Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | Unit and installer regressions cover the boundary, but no representative live Docker/Podman qualification exists. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record fresh install, migration, restart, helper loss/recovery, bounds, and summary parity on representative rootful Docker and Podman; decide explicitly whether reduced telemetry is sufficient |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Implemented, unqualified live. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | A separate opt-in `secure-runtime-rootless-v1` harness and fail-closed receipt validator define disposable nested Ubuntu/systemd Docker and Podman proof without changing immutable schema v7. No complete retained receipt exists yet, so this does not justify container-runtime parity or a default change | `deployment-installability`: run and retain the exact source/artifact-bound fresh-install, migration, restart, socket-loss, ambiguity, helper/direct recovery, cleanup, and telemetry-parity packet for both rootless Docker and rootless Podman |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | The standalone rootless packet exercises live same-family rootful Docker and Podman helper fallback plus summary-inventory semantic parity during socket loss. It does not qualify the complete standalone rootful fresh-install, migration, restart, helper-loss/recovery, and bounds matrix. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record the remaining standalone lifecycle matrix on representative rootful Docker and Podman and decide explicitly whether reduced telemetry is sufficient |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Qualified locally for the exact source-bound monitoring path. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | **Qualified on distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts at commit `60041ad9e60c282c892f944e04f777b874991a5d`.** All eleven canonical scenarios passed for Docker and all eleven for Podman. Receipt SHA-256: `7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`; local attestation SHA-256: `566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. This is local opt-in artifact-bound self-attestation, not published-RC provenance, action/update qualification, external review, or authorization for a default change | `deployment-installability`: reproduce the exact packet from published release artifacts; separately qualify any desired rootless image-update/action surface; retain the opt-in default until the remaining provider, appliance, and review conditions pass |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v6 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, effective-unit override rejection, exact credential rotation, bodyless self-revocation, and collector/helper continuity. A separate production Router regression exercises HTTPS issuance, WSS admission, encrypted token persistence, failed-rotation rollback, exact socket invalidation, two server restarts, old-secret rejection, and durable self-revoke | Qualified for the exercised systemd fixture paths and focused production Router lifecycle. Focused installer tests also cover atomic pending cancellation and fail-closed credential retention. The evidence does not cover every runner operation, representative providers, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce the combined systemd and production Router path from trusted RC artifacts with representative package-update success/failure/cancellation evidence |
| Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets. Focused protocol tests prove expired requests are not dispatched, timeout/caller abandonment sends one request-bound cancellation across every typed mutation family, and a canceled Proxmox mutation persists an indeterminate terminal receipt that survives runner reconnect and replays without a second mutation | This is local protocol/durability proof only: it makes no live-provider action-parity claim and does not change the default | `agent-lifecycle`: record target-bound success, stale-state refusal, provider-handoff cancellation, reconnect/replay, and independent postconditions on disposable real targets |
| Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported |