From 45dd45fe29bbde8e30a88801ccef517b4512b6ee Mon Sep 17 00:00:00 2001 From: rcourtman <8825017+rcourtman@users.noreply.github.com> Date: Tue, 1 Sep 2026 22:09:22 +0100 Subject: [PATCH] Record rootless runtime qualification evidence --- docs/AGENT_SECURITY.md | 4 +- .../internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md | 45 ++++++++--- ...tless-v1-local-qualification-2026-09-01.md | 81 +++++++++++++++++++ docs/release-control/v6/internal/status.json | 5 ++ .../v6/internal/subsystems/agent-lifecycle.md | 19 ++++- .../subsystems/deployment-installability.md | 19 ++++- frontend-modern/public/docs/AGENT_SECURITY.md | 4 +- 7 files changed, 155 insertions(+), 22 deletions(-) create mode 100644 docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md diff --git a/docs/AGENT_SECURITY.md b/docs/AGENT_SECURITY.md index c7bbc8e01..eecc89f11 100644 --- a/docs/AGENT_SECURITY.md +++ b/docs/AGENT_SECURITY.md @@ -272,8 +272,8 @@ or generic command path. | Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; signed updates cross the fixed helper protocol and commit only after an authoritative report | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `22fd662fb794f63efb9d3ca2158de73c4e07e1b8`** across the schema-v6 twenty-scenario run. It covers install, migration, explicit/automatic rollback, helper protocol and resource boundaries, effective-unit override rejection, reporting continuity, authoritative executable-digest commit, watchdog rollback, helper-restart recovery, and last-known-good restoration. It remains opt-in pending exact-RC reproduction, representative provider/appliance parity, and external review | `deployment-installability` and `security-privacy`: reproduce the same helper transaction from trusted release artifacts on representative hosts and accept the external boundary review | | Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases | | Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions | -| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | Unit and installer regressions cover the boundary, but no representative live Docker/Podman qualification exists. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record fresh install, migration, restart, helper loss/recovery, bounds, and summary parity on representative rootful Docker and Podman; decide explicitly whether reduced telemetry is sufficient | -| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Implemented, unqualified live. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | A separate opt-in `secure-runtime-rootless-v1` harness and fail-closed receipt validator define disposable nested Ubuntu/systemd Docker and Podman proof without changing immutable schema v7. No complete retained receipt exists yet, so this does not justify container-runtime parity or a default change | `deployment-installability`: run and retain the exact source/artifact-bound fresh-install, migration, restart, socket-loss, ambiguity, helper/direct recovery, cleanup, and telemetry-parity packet for both rootless Docker and rootless Podman | +| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | The standalone rootless packet exercises live same-family rootful Docker and Podman helper fallback plus summary-inventory semantic parity during socket loss. It does not qualify the complete standalone rootful fresh-install, migration, restart, helper-loss/recovery, and bounds matrix. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record the remaining standalone lifecycle matrix on representative rootful Docker and Podman and decide explicitly whether reduced telemetry is sufficient | +| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Qualified locally for the exact source-bound monitoring path. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | **Qualified on distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts at commit `60041ad9e60c282c892f944e04f777b874991a5d`.** All eleven canonical scenarios passed for Docker and all eleven for Podman. Receipt SHA-256: `7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`; local attestation SHA-256: `566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. This is local opt-in artifact-bound self-attestation, not published-RC provenance, action/update qualification, external review, or authorization for a default change | `deployment-installability`: reproduce the exact packet from published release artifacts; separately qualify any desired rootless image-update/action surface; retain the opt-in default until the remaining provider, appliance, and review conditions pass | | Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v6 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, effective-unit override rejection, exact credential rotation, bodyless self-revocation, and collector/helper continuity. A separate production Router regression exercises HTTPS issuance, WSS admission, encrypted token persistence, failed-rotation rollback, exact socket invalidation, two server restarts, old-secret rejection, and durable self-revoke | Qualified for the exercised systemd fixture paths and focused production Router lifecycle. Focused installer tests also cover atomic pending cancellation and fail-closed credential retention. The evidence does not cover every runner operation, representative providers, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce the combined systemd and production Router path from trusted RC artifacts with representative package-update success/failure/cancellation evidence | | Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets. Focused protocol tests prove expired requests are not dispatched, timeout/caller abandonment sends one request-bound cancellation across every typed mutation family, and a canceled Proxmox mutation persists an indeterminate terminal receipt that survives runner reconnect and replays without a second mutation | This is local protocol/durability proof only: it makes no live-provider action-parity claim and does not change the default | `agent-lifecycle`: record target-bound success, stale-state refusal, provider-handoff cancellation, reconnect/replay, and independent postconditions on disposable real targets | | Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported | diff --git a/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md b/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md index 7b1a43c82..2daff59f2 100644 --- a/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md +++ b/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md @@ -175,9 +175,10 @@ migration, helper restart continuity, and helper-loss/recovery scenarios. The release workflow creates its daemon inside the disposable systemd host, seeds an offline source-bound fixture image, exposes only the root-owned Unix socket, and never mounts the hosted runner's Docker socket. V7 narrows only the -rootful-Docker summary-inventory residual; Podman, rootless-runtime parity, -container metrics, image-update checks, typed container actions, appliance -coverage, and external review remain open. No schema-v7 receipt exists until +rootful-Docker summary-inventory residual; rootful Podman, standalone rootless +runtime proof, container metrics, image-update checks, typed container actions, +appliance coverage, and external review remain outside that schema. No +schema-v7 receipt exists until an exact immutable prerelease packet successfully completes that workflow, so this contract does not change the product default or upgrade the current v6 evidence classification. @@ -245,9 +246,12 @@ query before proving ancestry. `HEAD`, a local branch, or an arbitrary ref can never receive the committed-main label. The repository still needs a fresh exact committed release-candidate run, -representative Proxmox, SMART, Docker and rootless Podman telemetry/action -parity, appliance profiles, and the external security review. Until those -proofs are recorded, the safe profile remains opt-in and provider degradation +representative Proxmox and SMART proof, the complete standalone rootful +Docker/Podman lifecycle matrix, any separately authorized rootless update or +action proof, appliance profiles, and the external security review. The local +rootless Docker/Podman monitoring and lifecycle matrix described below is now +qualified for its exact source-bound packet, but it does not satisfy those +remaining proofs. The safe profile remains opt-in and provider degradation remains an explicit residual rather than evidence that the candidate lane is complete. @@ -265,9 +269,10 @@ and the running collector can transition between direct rootless monitoring and typed-helper summary fallback without restarting or enabling collector actions. Legacy Docker report-response commands, registry update scans, and orphan-backup cleanup are disabled statically whenever the helper-backed safe -profile is configured. This is implementation proof only; the live fresh-install, restart, -ambiguity, loss, bidirectional recovery, and telemetry-parity matrix remains -the qualification residual. +profile is configured. The standalone packet below now binds this +implementation to a live local fresh-install, migration, restart, ambiguity, +loss, recovery, authority-isolation, cleanup, and telemetry-parity exercise for +both runtime families. The standalone `secure-runtime-rootless-v1` packet now owns that residual without changing the immutable schema-v7 systemd contract. Its opt-in wrapper @@ -276,9 +281,25 @@ collector-owned rootless Docker and Podman daemons, separate same-family rootful helper baselines, exact installer pins, runtime loss and recovery, and cleanup before its independent validator can emit a local artifact-bound self-attestation. A checked-in harness or locally passing ordinary tests are -not qualification. Until a complete secret-free receipt and attestation are -retained, the matrix row remains implemented-but-unqualified and the safe -profile remains opt-in. +not qualification. + +The exact packet at source commit +`60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical +scenarios for Docker and all eleven for Podman on distinct disposable hosts. +The secret-free receipt SHA-256 is +`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and +the local artifact-bound attestation SHA-256 is +`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. +The validator matched 418 governed source files, both runtime-specific socket +profiles, distinct host and daemon identities, and all twenty-two scenario +records. The sanitized evidence record is +`internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`. +This closes the local live-proof residual only for the exercised rootless +monitoring, migration, fallback, recovery, ambiguity, parity, authority, and +cleanup paths. Its classification remains local, opt-in, artifact-bound +self-attestation; it is not published-release provenance, default-profile +authorization, rootless action/update qualification, or independent security +review. The safe profile therefore remains opt-in. ## Target Architecture diff --git a/docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md b/docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md new file mode 100644 index 000000000..562be40a5 --- /dev/null +++ b/docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md @@ -0,0 +1,81 @@ +# Secure rootless runtime v1 local qualification (2026-09-01) + +## Classification + +The standalone `secure-runtime-rootless-v1` packet passed from exact source +commit `60041ad9e60c282c892f944e04f777b874991a5d`. The independent validator +classified it as +`local-opt-in-rootless-runtime-artifact-bound-self-attestation` and verified +all 418 governed source hashes plus the exact collector, helper, installer, and +qualification-test artifact bindings. + +The secret-free receipt has SHA-256 +`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`. +The separate attestation has SHA-256 +`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. +Its source manifest has SHA-256 +`cae1c8c53ff7019ad0fa82c39e90635ed0290a97a2055c3978005cbda1bca497`. +The full receipt and attestation remain retained local evidence rather than +published release assets; this record intentionally stores only their +secret-free identifiers and qualification scope. + +## Exercised runtime matrix + +Two distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts completed the +canonical eleven scenarios for each runtime, for twenty-two passing scenario +records in total: + +1. `fresh_install` +2. `legacy_migration` +3. `collector_restart` +4. `daemon_restart` +5. `socket_loss_helper_fallback` +6. `direct_recovery` +7. `dual_socket_ambiguity_refusal` +8. `exact_pin_recovery` +9. `telemetry_parity` +10. `authority_isolation` +11. `cleanup` + +The Docker host reported machine identity +`9050518de741748dc8bf3a1d04861e58`, Docker 29.7.2, rootless daemon identity +`1fb49913-d54b-41bc-864f-42e1e33f88ab`, and collector-owned socket +`/run/user/996/docker.sock` with mode `0660`. The Podman host reported machine +identity `c063c32387eafbfd6abec6e939256b59`, Podman 4.9.3, rootless daemon +identity `ecec4fdfedced3b59b47048cb1be54c14901d3f41b0aee6e28f6bc84446c6631`, +and collector-owned socket `/run/user/996/podman/podman.sock` with mode `0600`. +The distinct machine and daemon identities prevent one shared fixture from +standing in for both runtime families. + +The packet proved fresh safe-profile installation, legacy authority-reducing +migration, collector and daemon restart continuity, same-family rootful typed- +helper summary fallback during rootless socket loss, direct recovery without +collector restart, fail-closed dual-socket ambiguity handling, root-owned exact +pin recovery, and direct telemetry parity against a root client of the same +rootless daemon. Direct telemetry included complete inventory, stats, full +fields, and secondary inventory. Authority isolation proved that the non-root +collector had no command session or command transport, no rootful socket +access, and no container action or update authority. Strict teardown removed +the fixture containers, stopped both runtimes, removed their sockets and +delegated state, and left no labeled qualification containers behind. + +## Boundaries and remaining work + +This packet closes the local live-proof residual for the exact exercised +rootless Docker and Podman monitoring, migration, fallback, recovery, +ambiguity, parity, authority, and cleanup paths. It does not extend or +reinterpret the schema-v7 systemd contract. + +The attestation records four explicit limitations: + +- `not-published-release-provenance` +- `not-default-profile-authorization` +- `not-independent-security-review` +- `production-exact-scope-proof-is-external-prior` + +It does not qualify rootless container image-update checks or typed container +actions, which remain disabled in the safe collector. It does not qualify the +complete standalone rootful Docker/Podman lifecycle matrix, Proxmox or SMART +provider parity, appliance profiles, or an exact published release candidate. +The safe profile therefore remains explicit opt-in, and this record does not +complete or accept the proposed secure-agent-runtime-separation lane. diff --git a/docs/release-control/v6/internal/status.json b/docs/release-control/v6/internal/status.json index 112e433bc..530246447 100644 --- a/docs/release-control/v6/internal/status.json +++ b/docs/release-control/v6/internal/status.json @@ -9834,6 +9834,11 @@ "path": "docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v6-2026-08-31.json", "kind": "file" }, + { + "repo": "pulse", + "path": "docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md", + "kind": "file" + }, { "repo": "pulse", "path": "internal/api/agenttokens/install.go", diff --git a/docs/release-control/v6/internal/subsystems/agent-lifecycle.md b/docs/release-control/v6/internal/subsystems/agent-lifecycle.md index d44532067..d9f8ad823 100644 --- a/docs/release-control/v6/internal/subsystems/agent-lifecycle.md +++ b/docs/release-control/v6/internal/subsystems/agent-lifecycle.md @@ -7375,9 +7375,22 @@ the durable daemon identity. Dual-socket ambiguity evidence validates Docker and Podman against their respective recorded socket ownership and modes; it must not project the selected runtime's permissions onto the other socket. Its classification is local, opt-in, -artifact-bound self-attestation only. No receipt exists merely because the -harness is checked in, so rootless Docker and Podman remain live-unqualified -and cannot change the product default. +artifact-bound self-attestation only. The exact packet at source commit +`60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical +scenarios for Docker and all eleven for Podman on distinct disposable hosts. +Its secret-free receipt SHA-256 is +`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and +its attestation SHA-256 is +`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. +The validator matched 418 governed source hashes, exact artifacts, the two +runtime-specific socket profiles, distinct host and daemon identities, and all +twenty-two scenario records. The sanitized evidence record is +`docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`. +This qualifies only the exercised local rootless monitoring, migration, +fallback, recovery, ambiguity, parity, authority, and cleanup paths. It is not +published-release provenance, default-profile authorization, rootless +action/update qualification, or independent security review and cannot change +the product default. ### Command and durable typed dispatch are context-honest and canceled when abandoned diff --git a/docs/release-control/v6/internal/subsystems/deployment-installability.md b/docs/release-control/v6/internal/subsystems/deployment-installability.md index 3fbaa522f..95a2463c4 100644 --- a/docs/release-control/v6/internal/subsystems/deployment-installability.md +++ b/docs/release-control/v6/internal/subsystems/deployment-installability.md @@ -299,9 +299,22 @@ authority, and cleanup evidence before the independent validator can emit a local artifact-bound self-attestation. All three Go artifacts require explicit VCS stamping at build time; unavailable revision or clean-worktree metadata is a build failure rather than an attestable omission. Checking in the harness or passing its -ordinary contract tests is not live qualification. Until a complete -secret-free receipt and attestation are retained, this surface remains -implemented-but-unqualified and cannot change the opt-in safe-profile default. +ordinary contract tests is not live qualification. The exact packet at source +commit `60041ad9e60c282c892f944e04f777b874991a5d` passed all eleven canonical +scenarios for Docker and all eleven for Podman on distinct disposable hosts. +Its secret-free receipt SHA-256 is +`7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5` and +its local artifact-bound attestation SHA-256 is +`566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. +The validator matched 418 governed source hashes, exact artifacts, the two +runtime-specific socket profiles, distinct host and daemon identities, and all +twenty-two scenario records. The sanitized evidence record is +`docs/release-control/v6/internal/records/secure-runtime-rootless-v1-local-qualification-2026-09-01.md`. +This qualifies only the exercised local rootless monitoring, migration, +fallback, recovery, ambiguity, parity, authority, and cleanup paths. It is not +published-release provenance, default-profile authorization, rootless +action/update qualification, or independent security review, so the safe +profile remains opt-in. When both runtime sockets are present for ambiguity refusal, the validator checks each entry against that runtime's own recorded GID and mode while using the current disposable host's collector UID and canonical socket path. diff --git a/frontend-modern/public/docs/AGENT_SECURITY.md b/frontend-modern/public/docs/AGENT_SECURITY.md index c7bbc8e01..eecc89f11 100644 --- a/frontend-modern/public/docs/AGENT_SECURITY.md +++ b/frontend-modern/public/docs/AGENT_SECURITY.md @@ -272,8 +272,8 @@ or generic command path. | Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; signed updates cross the fixed helper protocol and commit only after an authoritative report | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `22fd662fb794f63efb9d3ca2158de73c4e07e1b8`** across the schema-v6 twenty-scenario run. It covers install, migration, explicit/automatic rollback, helper protocol and resource boundaries, effective-unit override rejection, reporting continuity, authoritative executable-digest commit, watchdog rollback, helper-restart recovery, and last-known-good restoration. It remains opt-in pending exact-RC reproduction, representative provider/appliance parity, and external review | `deployment-installability` and `security-privacy`: reproduce the same helper transaction from trusted release artifacts on representative hosts and accept the external boundary review | | Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases | | Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions | -| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | Unit and installer regressions cover the boundary, but no representative live Docker/Podman qualification exists. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record fresh install, migration, restart, helper loss/recovery, bounds, and summary parity on representative rootful Docker and Podman; decide explicitly whether reduced telemetry is sufficient | -| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Implemented, unqualified live. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | A separate opt-in `secure-runtime-rootless-v1` harness and fail-closed receipt validator define disposable nested Ubuntu/systemd Docker and Podman proof without changing immutable schema v7. No complete retained receipt exists yet, so this does not justify container-runtime parity or a default change | `deployment-installability`: run and retain the exact source/artifact-bound fresh-install, migration, restart, socket-loss, ambiguity, helper/direct recovery, cleanup, and telemetry-parity packet for both rootless Docker and rootless Podman | +| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | Implemented as a typed-helper summary-only fallback. Migration preserves container ID/name/image/state/status/creation inventory and marks the report `typed-helper-summary`; stats, secondary inventories, update checks, and actions remain unavailable | The standalone rootless packet exercises live same-family rootful Docker and Podman helper fallback plus summary-inventory semantic parity during socket loss. It does not qualify the complete standalone rootful fresh-install, migration, restart, helper-loss/recovery, and bounds matrix. Full rootful parity remains an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: record the remaining standalone lifecycle matrix on representative rootful Docker and Podman and decide explicitly whether reduced telemetry is sufficient | +| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID whose daemon also attests rootless mode | Qualified locally for the exact source-bound monitoring path. Discovery is deferred until the collector account exists and accepts exactly one readable/writable, non-symlink socket owned by that UID across Docker and Podman. Cross-user, root-owned, remote, unreadable, non-rootless-daemon, or ambiguous endpoints are rejected. An installer-owned exact pin survives daemon loss and update; the running collector can move between direct rootless monitoring and rootful typed-helper summary without regaining action authority | **Qualified on distinct disposable Ubuntu 24.04/systemd 255 arm64 hosts at commit `60041ad9e60c282c892f944e04f777b874991a5d`.** All eleven canonical scenarios passed for Docker and all eleven for Podman. Receipt SHA-256: `7a116d63ab0cd1560482165055f0a8c9158ce0a8333a27bd9e8256582a52dfb5`; local attestation SHA-256: `566279ecd7d7dfa89c92f24243e9fcd5ae3e295d4284bd559d4be42f1e83b3b5`. This is local opt-in artifact-bound self-attestation, not published-RC provenance, action/update qualification, external review, or authorization for a default change | `deployment-installability`: reproduce the exact packet from published release artifacts; separately qualify any desired rootless image-update/action surface; retain the opt-in default until the remaining provider, appliance, and review conditions pass | | Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v6 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, effective-unit override rejection, exact credential rotation, bodyless self-revocation, and collector/helper continuity. A separate production Router regression exercises HTTPS issuance, WSS admission, encrypted token persistence, failed-rotation rollback, exact socket invalidation, two server restarts, old-secret rejection, and durable self-revoke | Qualified for the exercised systemd fixture paths and focused production Router lifecycle. Focused installer tests also cover atomic pending cancellation and fail-closed credential retention. The evidence does not cover every runner operation, representative providers, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce the combined systemd and production Router path from trusted RC artifacts with representative package-update success/failure/cancellation evidence | | Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets. Focused protocol tests prove expired requests are not dispatched, timeout/caller abandonment sends one request-bound cancellation across every typed mutation family, and a canceled Proxmox mutation persists an indeterminate terminal receipt that survives runner reconnect and replays without a second mutation | This is local protocol/durability proof only: it makes no live-provider action-parity claim and does not change the default | `agent-lifecycle`: record target-bound success, stale-state refusal, provider-handoff cancellation, reconnect/replay, and independent postconditions on disposable real targets | | Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported |