From db7b7d19fe986ad34f90054235fe3f1da3a1ead6 Mon Sep 17 00:00:00 2001 From: rldyourmnd Date: Wed, 7 Oct 2026 06:37:53 +0500 Subject: [PATCH] docs: reconcile current validation and capability boundaries --- crates/rds-net/src/resolve.rs | 5 ++- docs/capability-matrix.md | 4 +- docs/path-selection.md | 11 ++--- docs/remediation-progress.md | 42 +++++++++---------- docs/reports/rds-drain-rtt-budget-20261007.md | 10 ++++- 5 files changed, 40 insertions(+), 32 deletions(-) diff --git a/crates/rds-net/src/resolve.rs b/crates/rds-net/src/resolve.rs index 93f0e44..fd62aa7 100644 --- a/crates/rds-net/src/resolve.rs +++ b/crates/rds-net/src/resolve.rs @@ -11,8 +11,9 @@ //! resolved `EndpointAddr` is authenticated by the record signature, //! and the QUIC handshake re-authenticates the key anyway. A hostile //! directory cannot substitute a different key for a verified name. Name -//! freshness is lifetime-bounded with a volatile client anti-rollback cache; -//! durable revisions and authority rotation remain remediation W1.4. +//! freshness is lifetime-bounded. Configured durable name trust shares revision +//! and authenticated rotation acceptance across client processes; the explicit +//! in-memory trust constructor has only process-lifetime anti-rollback state. use anyhow::{Context, bail}; diff --git a/docs/capability-matrix.md b/docs/capability-matrix.md index b6d4497..e926818 100644 --- a/docs/capability-matrix.md +++ b/docs/capability-matrix.md @@ -37,8 +37,8 @@ only what is actually served. `ping`/`info` are the always-on control plane. | service:audio | stub | no codec; wire shape reserved in v2 | `ServiceKind::Audio` variant only | | service:sync-read | implemented | grant scope on sync root; optional grant `sync_paths` subtree | grant/scope tests | | service:sync-write | implemented | grant scope on sync root; optional grant `sync_paths` subtree | grant/scope tests | -| service:desktop-view | implemented | grant scope; usable capture backend | scope tests; headless path only | -| service:desktop-control | experimental | desktop-view + control scope; X11 input sink | input contract tests; real-session injection unqualified | +| service:desktop-view | implemented | grant scope; usable capture backend | view/control scope separation and desktop contract tests | +| service:desktop-control | experimental | desktop-view + control scope; X11 input sink | native Xvfb input/lifecycle tests; installed causal pixels retain a separate gate | ## Transports diff --git a/docs/path-selection.md b/docs/path-selection.md index aa15841..f401677 100644 --- a/docs/path-selection.md +++ b/docs/path-selection.md @@ -50,11 +50,12 @@ events preceding subscription lack a complete state-resynchronization API in the current noq surface. Candidate-address reconciliation is not path-validation reconciliation and does not establish complete tracking after lost path events. -Logical path closure is not physical NIC/NAT failure. Native macOS, interface -changes, relay failure isolation, global resource/churn bounds and service -interruption budgets remain open. Facade metrics still require full path -enumeration and correct selected/relay attribution. No remediation wave or -owned-backend promotion is closed by these checks. +Logical path closure is not physical NIC/NAT failure. Physical interface changes, +native interactive acceptance, complete resource/churn bounds and service +interruption budgets remain open. Facade snapshots report their coverage: +Iroh's backend snapshot or Noq's policy-observed validated paths, with event-loss +and driver-running state. Complete reconciliation after lost Noq events remains +open. No remediation wave or owned-backend promotion is closed by these checks. ## Temporary path-credit exhaustion diff --git a/docs/remediation-progress.md b/docs/remediation-progress.md index 727d00b..d7d9b71 100644 --- a/docs/remediation-progress.md +++ b/docs/remediation-progress.md @@ -7,25 +7,25 @@ this file records implementation progress rather than rewriting that evidence. ## Current state -All waves remain open. W1.1–W1.4 and W1.6–W1.8 passed the local Linux check -matrix; other tasks remain planned unless listed below. No deployment or owned-backend -promotion has occurred. Native macOS checks still require their platform lane. - -The historical readiness review at source `ec48d75` found an external SSH-client -requirement; the later [native Rust SSH increment](ssh.md) removes that local -requirement while retaining a configured remote SSH server. The repository is -still not a completed remote access product. Frame presentation returns unavailable; -ScreenCaptureKit, image-copy and PipeWire capture probes remain placeholders. -The historical throughput scenario stopped timing at sender finish; the later -[verified transfer increment](benchmark-transfer.md) adds a receiver byte/digest -receipt and EOF barrier. Known-rate and phase calibration remain W0.2. The other -implementation gaps remain in W5 and W6/W7 alongside the open plan tasks. That Linux -receipt records 431 workspace, 238 expanded and 2 isolated iroh tests passing; -those results do not establish missing functionality or native platform/network -qualification. The O1 observability foundation recorded 444 workspace and 239 expanded -tests plus the opt-in infrastructure pipeline. The subsequent authenticated -admin/source-metrics increment is described below and in its own receipt. -Neither increment closes these product gaps or any wave. +All product waves remain open. The task rows below distinguish landed increments +from their remaining acceptance. Current software CI covers Linux x86_64 and +macOS arm64, including default/Noq and desktop lanes; dated test counts in later +sections describe their original increments, not the current inventory. +The owned backend remains experimental. + +The current [capability matrix](capability-matrix.md) and +[continuation plan](continuation-plan.md) govern present capability claims. +Native Rust SSH, the shared session manager, resumable single-file transfer, +X11 capture/input and bounded native wgpu presentation are implemented. +ScreenCaptureKit, image-copy/PipeWire serving, audio and recursive/two-way sync +remain unavailable or stubs as listed in the matrix. Native input-to-visible, +physical topology and release acceptance retain their own gates. + +The [verified transfer contract](benchmark-transfer.md) includes receiver +byte/digest completion, EOF barriers and phase/known-rate calibration. Real +topology/load qualification remains open. The observability/admin increments +and their dated validation appear below. Installed identities, endpoint policy +and rollout evidence belong to the private estate, independently of public CI. | Task | State | Evidence / remaining scope | |---|---|---| @@ -37,7 +37,7 @@ Neither increment closes these product gaps or any wave. | W0.6 | Implemented; receipts cover reports + history backfilled | `docs/receipts/rds-receipts.jsonl` is append-only JSONL, one receipt per gate/report: full commit SHA, dirty flag, bench-binary and Cargo.lock digests, toolchain channel, features, OS/arch, topology class, repetitions/failures/skips, budgets and cited-report digests — no host identifiers. `prev_hash`/`hash` chaining rejects tampered, reordered or mid-deleted lines with the offending line number; `rds-bench receipt`/`validate-receipts` are the writer/reader and `write_checkpoint` now records every gate run. Gate receipts now digest-cite every bench artifact the gate produced (not just the checkpoint file); a `report-backfill` receipt anchors all 135 historical report files by content digest. Release-gate consumption remains open. | | W1.1 | Implemented; Linux checks passed | Denylist replacement retains its value without observers; atomic modification preserves concurrent revocations. Subscribe-before-check and initial watchdog snapshot check remove missed-update windows. Durable feed freshness remains W1.4. | | W1.2 | Implemented; Linux checks passed | One authorization state owns admission, replay reservation and watchdog. ACK failure/cancellation closes the connection and releases the grant. Service admission checks live validity/revocation. Connection future teardown runs RAII cleanup. | -| W1.3 | Implemented; Linux checks passed | Client trust anchor, per-name domain-separated signatures, exact name/record binding, current validity and volatile anti-rollback. Native directory HTTPS/DNS added; durable revision linkage stays W1.4 and native macOS verification remains open. | +| W1.3 | Implemented; software lanes | Client trust anchor, per-name domain-separated signatures, exact name/record binding and current validity. Directory HTTPS/DNS and configured durable name trust are implemented; W1.4 owns revision/rotation acceptance. Physical rollback/power-loss and external GDS anchoring remain separate qualification. | | W1.4 | Implemented; Linux checks passed | Shared durable policy acceptance, positive epochs/revisions, domain-separated signatures, bounded revocation leases, restart/boot rules, dual-signed rotation, atomic feed ownership and live closure. Name trust persists across CLI processes. Native macOS/power-loss qualification and external GDS rollback anchoring remain open. | | W1.5 | Partial | Transactional bounded disk store, tombstones, generation anchor, publisher revisions, exact retry, durable announce, leased expiry, retained floors, bounded collection, configured enrollment, fair write admission, strict HTTP framing and explicit format-2 offline migration are implemented. A 4096-identity Linux capacity/churn/reopen run passed. Legacy cutover, release-load/startup profiling, physical failure and native macOS qualification remain open; see validation below. | | W1.6 | Implemented; Linux checks passed | Reused bytes are verified and stored before `have`; edits, insertions, deletions, repeated chunks and destination removal/restart are tested. | @@ -58,7 +58,7 @@ Neither increment closes these product gaps or any wave. | W4.4 | Partial; directional service boundaries | Real iroh/noq agents refuse writes with `SyncRead` and reads with `SyncWrite`, permit authorized transfers, and remain usable after refusal/cancellation. A view-only desktop never calls its input sink; failed injection never emits a success ACK. Linux/macOS account isolation, per-path policy, native seat/focus boundaries, consent and concurrent-role qualification remain open. See [receipt](reports/rds-service-scopes-20260926.md). | | W5.1/W5.3/W5.5 | Partial; native SSH client and standard PTY | `rds-ssh` uses russh 0.63.3 over pinned managed/direct streams. Explicit host pins, key/agent authentication, PTY/exec acknowledgements, terminal restoration, resize, cancellation and complete exit/output handling have Linux regression coverage and an OpenSSH interop fixture. SSH-specific fixed telemetry names are accepted by Vector; JSON uses a separate private file and terminal console logging pauses during SSH. GDS host/account provisioning, certificates/MFA, native macOS, broker/reattachment and mixed-load/network qualification remain open. See [contract](ssh.md). | | W6.1 | Partial; sender byte correctness and reference recovery | Pinned writes preserve progress; deltas finish before dependent successors and may be replaced by an independent keyframe. Queue loss requests IDR, and a sender sequence guard refuses broken delta chains after selection/pacing. Failure/cancellation resets streams under one deadline; serving owns child tasks. Failing-before byte/lifecycle regressions, native codec recovery and real iroh/noq RESET coverage pass. Real-codec network/overload qualification, wire session IDs and native presentation gates remain open; see [contract](desktop-frame-delivery.md). | -| W6.2 | Partial; client receive ownership and limits | Four encoded frames per session/eight per process, two blocking decoder calls, owned task groups and cancellation, full handshake deadlines, dimension/sequence checks and rate-limited keyframe recovery are implemented. Real iroh/noq lifecycle and native codec regressions passed locally. Per-session wire IDs, global decoded/native memory accounting, renderer and native platform/network acceptance remain open; see [contract](desktop-client-lifecycle.md). | +| W6.2 | Partial; client receive ownership, limits and native renderer | Four encoded frames per session/eight per process, two blocking decoder calls, owned task groups and cancellation, handshake deadlines, dimension/sequence checks, repair discipline and bounded newest-frame wgpu presentation are implemented. Iroh/Noq lifecycle and codec regressions pass. Per-session wire IDs, complete global decoded/native memory accounting and native platform/network acceptance remain open; see [client contract](desktop-client-lifecycle.md) and [viewer contract](native-viewer.md). | | W6.4 | Partial; ACK semantics and native X11 mapping | ACK follows successful backend acceptance. A bounded session-owned input worker reuses its sink. X11 maps evdev keys/buttons, bounds coordinates and fractional scroll, uses relative motion correctly, selects the explicit screen, checks native errors and releases owned holds on drop. Four failing-before native regressions and two-screen Xvfb checks cover the increment; the Linux CI lane requires actual native execution. Exclusive seat/controller ownership, focus races, custom layouts/IME, dynamic geometry and input-to-visible qualification remain open; see [contract](x11-input.md). | | W10.1/W10.2 | Partial; O1 foundation and O2 admin/source increment | Shared bounded Rust telemetry and Vector/OpenObserve pipeline; opt-in authenticated loopback metrics on agent/relay/server, aggregate source observations and old public metrics removal. Durable policy/catalog observations and effective agent revocation revision/lease are implemented. Finer queue/task and upstream adapter coverage, phase/reason correlation, support bundles, private rollout, independent liveness and overhead/platform qualification remain O2–O6; see [contract](observability.md). | diff --git a/docs/reports/rds-drain-rtt-budget-20261007.md b/docs/reports/rds-drain-rtt-budget-20261007.md index ce14772..2ced64f 100644 --- a/docs/reports/rds-drain-rtt-budget-20261007.md +++ b/docs/reports/rds-drain-rtt-budget-20261007.md @@ -18,8 +18,14 @@ callback with a controlled runtime clock. Three seconds of pending work on a It failed with the former conflated value and passes with separate values. All 111 Mac net/Noq library tests pass, including actual original-stream blackhole recovery, standby restoration and independent backup ACK routing. -Strict all-target Noq Clippy and broader/platform qualification are being -collected. No installed owned-backend improvement is asserted from these tests. +Source `c1960a5` passed all 18 public CI checks (16 successful checks and two +ordinary skips), covering both OS software lanes. Linux net/Noq integration, +strict workspace desktop/Noq Clippy and X11 Clippy also pass. Mac net/Noq +integration and runtime unit/integration tests pass; the initial Rustdoc +compilation failed while another qualification reused the same target directory. +The retained failure is followed by passing serialized Rustdoc compilation and +strict workspace desktop/Noq Clippy. Shared-target qualification phases are now +serialized. No installed owned-backend improvement is asserted from these tests. [RFC 9002 §5](https://www.rfc-editor.org/rfc/rfc9002.html#section-5) defines RTT estimation from transport timing. An administrative selection penalty is not