ARCH-04 — Global nodes, volume incarnations, exclusion domains, and isolation proofs #833

Open
opened 2026-07-22 19:48:33 -05:00 by jcwalker3 · 0 comments
Owner

Candidate architecture requiring executable validation; not yet approved, production-ready, or certified.

Parents: #820, #832. Depends on: #822 (principals/supervisor authority), #826 (evidence for isolation proofs).

1. Summary / objective

Implement global identity for nodes, node incarnations, shared volumes, volume incarnations, and exclusion domains, with isolation proofs and a membership generation — registered under platform/supervisor authority only.

2. Security/correctness problem

Workspace mutation safety rests on exclusion domains and their membership. If a project administrator could manufacture or retire global identity, or claim isolation without proof, overlapping workspaces could both verify and two runtimes could act on one storage.

3. Threat model / failure modes

project.admin manufacturing/retiring global identity; unproven isolation between domains; alias across domains (bind mount / alternate mount); stale membership generation; direct-write of global rows; concurrent lifecycle transitions.

4. In-scope behavior

  • nodes, node_incarnations, shared_volumes, volume_incarnations, workspace_exclusion_domains, isolation_proofs. [SCHEMA] keys/lifecycle.
  • Global registration authority = platform/supervisor.register; a project administrator may attach eligible verified global identities but may not manufacture verification or authority. [SCHEMA] actor/authority triggers.
  • Isolation proofs: supervisor-verified, evidence-backed, ordered pair, boundary-kind ordering (process<container<vm<host), at least as strong as both domains. [SCHEMA] + [RUNTIME-ADAPTER] (physical isolation observation).
  • Cross-domain alias detection; domain_membership_generation and the exact events that increment it (workspace add/remove, storage change, domain split/merge/retire). [SCHEMA].
  • Registration/replacement/retirement + immutable historical retention; direct-write prevention; concurrent lifecycle serialization.

5. Exclusions

No workspace bindings/config generations (→ next child), no probing (→ probing child), no fencing cascade (→ lifecycle child).

6. Schema/operation contracts

Tables above + domain_membership (workspace↔domain). Operations: register_node, register_node_incarnation, register_shared_volume, register_volume_incarnation, register_exclusion_domain, record_isolation_proof, retire_*.

7. SQLite behavior

Partial unique indexes for active identities; membership-generation bump within BEGIN IMMEDIATE; immutable-history triggers.

8. PostgreSQL behavior

Same; SELECT … FOR UPDATE on the domain row for lifecycle transitions; SERIALIZABLE retry.

9. Concurrency / transaction requirements

Concurrent domain lifecycle changes serialize on the domain row; membership generation is monotonic; an isolation proof is invalidated when a referenced boundary changes.

10. Structured results

REGISTERED, ATTACHED, ISOLATION_UNPROVEN, AUTHORITY_REQUIRED, ALIAS_DETECTED, RETIRED, SERIALIZATION_RETRY.

11. Enforcement classification

Authority/keys/immutability/membership-generation [SCHEMA]; physical isolation [RUNTIME-ADAPTER]; canonicalization of storage identity [TRUSTED-SERVICE].

12. Acceptance criteria

  1. Global identity registration requires platform/supervisor authority; project.admin cannot register/verify/retire.
  2. Isolation decided only from a recorded supervisor-verified proof of sufficient boundary strength.
  3. Alias across domains detected; overlapping storage collapses to one domain unless isolation proven.
  4. Membership generation increments on the defined events.
  5. Global rows immutable except via sanctioned lifecycle ops.
  6. Concurrent lifecycle transitions serialize.

13. Named tests

t_admin_register_global(−), t_isolation_unproven(−), t_isolation_weak_boundary(−), t_cross_domain_alias(−), t_membership_generation(+), t_global_immutable(raw-bypass), t_concurrent_domain_lifecycle(concurrency).

14. Audit events / evidence

node_registered, volume_registered, domain_registered, isolation_proof_recorded, global_retired. Test output evidence.

15. Dependencies / parent

Parents #820, #832; depends #822, #826.

16. Definition of done

Executable SQLite (+PG); ACs pass incl. authority + raw-bypass + concurrency; bounded PR; no self-review/merge.

17. Known limitations / deferred

Physical isolation cannot be schema-proven (adapter). Fencing of dependent workspaces on retirement is the lifecycle child.

**Candidate architecture requiring executable validation; not yet approved, production-ready, or certified.** Parents: #820, #832. Depends on: #822 (principals/supervisor authority), #826 (evidence for isolation proofs). ## 1. Summary / objective Implement global identity for nodes, node incarnations, shared volumes, volume incarnations, and exclusion domains, with isolation proofs and a membership generation — registered under platform/supervisor authority only. ## 2. Security/correctness problem Workspace mutation safety rests on exclusion domains and their membership. If a project administrator could manufacture or retire global identity, or claim isolation without proof, overlapping workspaces could both verify and two runtimes could act on one storage. ## 3. Threat model / failure modes project.admin manufacturing/retiring global identity; unproven isolation between domains; alias across domains (bind mount / alternate mount); stale membership generation; direct-write of global rows; concurrent lifecycle transitions. ## 4. In-scope behavior - `nodes`, `node_incarnations`, `shared_volumes`, `volume_incarnations`, `workspace_exclusion_domains`, `isolation_proofs`. `[SCHEMA]` keys/lifecycle. - Global registration authority = platform/`supervisor.register`; a project administrator may **attach** eligible verified global identities but may not manufacture verification or authority. `[SCHEMA]` actor/authority triggers. - Isolation proofs: supervisor-verified, evidence-backed, ordered pair, boundary-kind ordering (`process<container<vm<host`), at least as strong as both domains. `[SCHEMA]` + `[RUNTIME-ADAPTER]` (physical isolation observation). - Cross-domain alias detection; `domain_membership_generation` and the exact events that increment it (workspace add/remove, storage change, domain split/merge/retire). `[SCHEMA]`. - Registration/replacement/retirement + immutable historical retention; direct-write prevention; concurrent lifecycle serialization. ## 5. Exclusions No workspace bindings/config generations (→ next child), no probing (→ probing child), no fencing cascade (→ lifecycle child). ## 6. Schema/operation contracts Tables above + `domain_membership` (workspace↔domain). Operations: `register_node`, `register_node_incarnation`, `register_shared_volume`, `register_volume_incarnation`, `register_exclusion_domain`, `record_isolation_proof`, `retire_*`. ## 7. SQLite behavior Partial unique indexes for active identities; membership-generation bump within `BEGIN IMMEDIATE`; immutable-history triggers. ## 8. PostgreSQL behavior Same; `SELECT … FOR UPDATE` on the domain row for lifecycle transitions; `SERIALIZABLE` retry. ## 9. Concurrency / transaction requirements Concurrent domain lifecycle changes serialize on the domain row; membership generation is monotonic; an isolation proof is invalidated when a referenced boundary changes. ## 10. Structured results `REGISTERED`, `ATTACHED`, `ISOLATION_UNPROVEN`, `AUTHORITY_REQUIRED`, `ALIAS_DETECTED`, `RETIRED`, `SERIALIZATION_RETRY`. ## 11. Enforcement classification Authority/keys/immutability/membership-generation `[SCHEMA]`; physical isolation `[RUNTIME-ADAPTER]`; canonicalization of storage identity `[TRUSTED-SERVICE]`. ## 12. Acceptance criteria 1. Global identity registration requires platform/supervisor authority; project.admin cannot register/verify/retire. 2. Isolation decided only from a recorded supervisor-verified proof of sufficient boundary strength. 3. Alias across domains detected; overlapping storage collapses to one domain unless isolation proven. 4. Membership generation increments on the defined events. 5. Global rows immutable except via sanctioned lifecycle ops. 6. Concurrent lifecycle transitions serialize. ## 13. Named tests `t_admin_register_global`(−), `t_isolation_unproven`(−), `t_isolation_weak_boundary`(−), `t_cross_domain_alias`(−), `t_membership_generation`(+), `t_global_immutable`(raw-bypass), `t_concurrent_domain_lifecycle`(concurrency). ## 14. Audit events / evidence `node_registered`, `volume_registered`, `domain_registered`, `isolation_proof_recorded`, `global_retired`. Test output evidence. ## 15. Dependencies / parent Parents #820, #832; depends #822, #826. ## 16. Definition of done Executable SQLite (+PG); ACs pass incl. authority + raw-bypass + concurrency; bounded PR; no self-review/merge. ## 17. Known limitations / deferred Physical isolation cannot be schema-proven (adapter). Fencing of dependent workspaces on retirement is the lifecycle child.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Scaled-Tech-Consulting/Gitea-Tools#833