Newer
Older
openstack-caracal-dc-dc / docs / audit / container-elim-pass / pass3-admin-report.md

Pass 3 -- ADMINISTRATOR REPORT: tests review (container-layer elimination)

Author: the Phase-3 administrator (multi-agent pass, SCOPE-AND-EXECUTION-PLAN.md Section 4). Date: 2026-08-09. Inputs: pass3-w1-harnesses-gauntlet.md, pass3-w2-gates.md, pass3-w3-new-tests.md -- read in full, adversarially cross-checked against repo ground truth (checks logged in Section 1). Baseline consumed: pass0-admin-report.md incl. Section 7a (Option 1 CONFIRMED; cross-DC handling (a) CONFIRMED; MAAS region stays on vr1-dcN-maas-01), pass1-admin-report.md (planning change-set; the (a)-control consolidated spec, Section 3), pass2-admin-report.md (tools change-set; the THREE isolation concerns, Section 2; the 13 owed artifacts, Section 5). READ-ONLY synthesis; no mutation; findings are LOGGED, not executed. All dispositions are proposals feeding Phase 4 (GA-R5); contingent items are marked with their blocking ruling, never pre-picked.

Repo discipline governing every row: an assertion must be provably able to FAIL (GA-R6, SKILL.md:321-333); assert on CONTENT not existence; REFUSE on unrecognised input, never pass silently; a fix that makes an assertion stale gets REPLACED with the new invariant, never deleted to go green.


1. Reconciliation / adversarial-check results (run against repo ground truth this session)

  1. The two harness universes UNIFY cleanly -- with two count corrections, no contradictions.

    • W3.1's "13 of 103 affected" needs granularity: its own verdict line ("2 clean RETIRE, 2 contingent RETIRE, 6 CHANGE, 1 contingent CHANGE") sums to 11 verdict-blocks; the survey table names 14 harnesses (one, netem-link, a declared grep false-positive). Reconciled: 13 harnesses carried a survey hit; 8 of them carry CHANGE/RETIRE verdicts; 5 are graded STAY. The unified table (Section 2) is presented at verdict-block granularity so the counts fall out of it.
    • W3.3's summary line "6 new + 5 extend-existing + 2 ride" does not decompose against its own rows -- CORRECTED. By its own per-artifact dispositions: 7 new-build (#12 dc-site, #2 (a) control, #1 teardown primitive, #11 power-key mitigation, #13 D-131 evidence, #4 R7 checklist, #5 MAAS record release/delete), 3 extend-existing (#3 SEC-010 successor -> tests/site-headend-install (conditional: new harness if the extraction becomes its own script), #7 FIT extension -> tests/dc-dc-whole-host-budget, #9 NetBox migration -> tests/dc-rack-mgmt-import), 3 ride (#6 rides #1's harness, #8 rides dc-site's MAC invariant, #10 rides geneve-encap-assert unchanged). 7+3+3 = 13; all owed artifacts accounted for. (The phase prompt inherited the 6/5/2 figure from W3.3's own summary line -- this is a worker-count correction.)
    • Overlap check (the load-bearing one): of the 3 extend-existing, #3 and #9 map INTO W3.1's affected set (site-headend-install Section-8 SEC-010 sub-case; dc-rack-mgmt-import vvr1 pins) -- the same edit seen from two sides, MERGED in Section 2, not double-counted. #7 crosses the universe boundary knowingly: dc-dc-whole-host-budget sits OUTSIDE W3.1's 13 (its Sec 3.4 supplementary note routes it to W3.2/W3.3 explicitly), and W3.3 #7 picks it up -- the one clean boundary crossing, now inside the unified set (Section 2 row C8). No worker contradicts another anywhere in the two universes.
  2. The power-key (#11) critical-path dependency is CONSISTENT across all three workers -- W3.1 (edit-list item 4: dc-selector + maas-region-power-key edited ONLY together with #11's ship, from the ruled URI/key shape), W3.2 (P4's power-address assertion and P5's new register row BLOCKED on #11's mechanism; Sec 4 risk 1), W3.3 (Sec 2.4: the harness + artifact are a stated PRECONDITION for the lib-hosts.sh re-derivation and every call-site literal). Stated plainly as the sequencing constraint in Section 4: owed artifact #11 blocks a six-item cluster of test edits, and the interim RED those harnesses will show once lib-hosts.sh changes is the DESIRED fail-loud state, not a defect to green out.

  3. Gate homes are COHERENT and each assertion is failable (Section 3 verified row-by-row against W3.2 Sec 1-3 and W3.3 Sec 2): (i) Stage-1 gate + cloud-assert A11a -- enumerates the live bridge set and REFUSES if fewer than the full plane count resolves (SEC-010's fail-open lesson generalized), plus W3.3's no-host-address-on-bridge and does-not-globalize failing fixtures; (ii) preflight P10 (P10 confirmed the next free slot; P6 is the reserved non-executing reminder block) -- host-bound --check on the P7 model, REFUSE off-host, REFUSE on an absent transit interface; (iii) P4-dependency + A11b -- the pass verdict is tied to a NEGATIVE test (the key CANNOT reach the wrong domains) plus W3.3's positive-coverage diff against the DC's own roster and a must-not-over-restrict control. None is an existence-only check; none is a checker-that-cannot-fail. One administrator spec amendment (recommendation grade): P8's root enumeration must come from a DECLARED root list, not a filesystem glob -- a glob loop is a checker-that-cannot-fail for a missing/renamed root (it silently drops out of coverage instead of FAIL/WARN). Section 3 carries it.

  4. Two coverage gaps the workers left dangling -- CLOSED BY MEASUREMENT this session:

    • scripts/pre-flight-checks.sh body sweep (W3.2 Sec 4 risk 3 flagged it read by neither worker): grep for W3.1's exact term set (vvr1|qemu+ssh|172.31|host-nodes|expose_nested|inner root|bootstrap gate|Model B| node_host) returned zero hits (rc=1). Its container-layer exposure is entirely INDIRECT via sourced lib-hosts.sh (pre-flight-checks.sh:44-45) -- the dc-selector-covered surface. No direct edit owed to its body; the NEW post-#11 content assertion (Section 3) is net-new, homed in tests/pre-flight-checks (harness exists, verified ls tests/).
    • lib-identity.sh harness status (pass2 Section 6's unclosed worker handoff): ANSWERED by W3.1's no-hit list -- tests/lib-validate exercises the lib-hosts/lib-net/lib-identity plumbing generically. Closed.
  5. One pass2 Phase-3 handoff was addressed by NO worker -- carried OPEN, not dropped: the maas-fabric-prune.sh/maas_fabric_classify.py harness gap (pre-existing; pass2 Section 6 routed "build vs accept-as-named-exception" to this phase). Verified this session: tests/maas-fabric-prune does not exist. None of W3.1/W3.2/W3.3 mentions it. Routed to Phase 4 as a named decision exactly as pass2 framed it (Section 7 open item 8). It is container-elim-ADJACENT only (a pre-existing gap), so parking it there loses nothing from this change-set.

  6. Next-free SEC number: SEC-034 CONFIRMED -- with the verification shape stated honestly. ledger-scan.sh computes next-free for D/DOCFIX/BUNDLEFIX only (run this session: D next-free=144, DOCFIX=214, BUNDLEFIX=059), NOT for SEC rows; the SEC confirmation rests on the direct ledger grep: highest row in docs/security-ledger.md = SEC-033, and the sole repo-wide SEC-034 mention is W3.2's own doc. 2-or-3 new SEC rows are owed ((a) control; #11 mitigation; and concern (ii)'s row, which pass2 deliberately left as a "SEC-row disposition" -- it may land as a SEC-010 amendment rather than a new number). Nothing assigned here; delivery greps next-free at mint time per repo numbering discipline.

  7. Denominator + doc-currency: tests/HARNESS-MANIFEST lists 103 harnesses (tests/ holds 104 entries including the manifest itself) -- W3.1's denominator confirmed. CLAUDE.md's "98 harnesses" line is stale vs 103 -- logged as a doc-currency nit OUTSIDE this pass's change-set (rides the next CLAUDE.md touch; no action here).

  8. No inferred-value violations found in the three worker docs. Spot-checked load-bearing cites (preflight.sh P8 root literal :284,298; cloud-assert.sh A0-A10 shape; site-headend-install.sh SEC-010 writer/check line ranges; node-vm/variables.tf:38-62 MAC validation; security-ledger.md:21 fail-open hardening note; the changelog cites for D-131 asymmetry) resolved to the cited lines. Every unknown (root naming, #11 mechanism, (a) rule set, P10's body, D-127's client-VM autostart value) is marked OWED in the source docs rather than guessed.


2. THE UNIFIED TESTS CHANGE-SET (one table, three dispositions, no double-counting)

Blocker legend: ready = editable/buildable at delivery with no ruling owed; #11 = blocked on the power-key mitigation design (Section 4); root-naming, rack-ret (rack-controller retirement + owed live re-measure), D-131 (retirement ratification + owed live re-measure), netbox (NetBox migration design, owed #9), mechanism (the artifact's own Phase-4 mechanism choice), root-fork (root-topology ratification).

A. EXISTING -- CHANGE (9 verdict-blocks across 9 harnesses)

# Harness (cases) Edit Blocker Failing-direction fixture
A1 opentofu-validate T14/T15 Re-point autostart pins at the flat root's file; ADD a new case for the vr1-dcN-client VM's autostart value (D-127's table predates the client VM -- value is an OWED ruling, not inferred) root-naming (+ the D-127 client-VM ruling for the new case) Keep exact-value asserts (edge=true / node=false); a flipped bool or wrong path must redden
A2 node-vm T8-T11 Re-point hardcoded INNER= path at the flat root's file; count invariant likely unchanged (12 macs=[ / 72 MACs -- the client VM is cloudinit-vm, not node-vm) -- confirm at build, do not assume root-naming Wrong count or missing MAC list must still redden (this harness has gone red twice before, tests/node-vm/run-tests.sh:68-81)
A3 site-headend-install Section-8 SEC-010 sub-case = owed #3's harness half (MERGED W3.1/W3.3 row) Re-target the extracted role-agnostic installer subcommand (both ends: client VM + voffice1); MIGRATE every proven SEC-010 assertion (transit-if existence check, br_netfilter never-global, idempotent declare-then-delete reload) -- a migration-completeness grep of the new location for every old trap-string is itself a required test ready once #3's extraction shape is picked (subcommand -> extend this harness; own script -> new harness inheriting all of it) Both-ends fixture (fake client role + fake voffice1 role, BOTH get the drop); wrong-role interface-name fixture must FAIL; NIC-naming trap carried (dc0 live was enp1s0, not mgmt)
A4 dc-selector power-address rows (:204-247) New values dial vcloud's own libvirtd -- URI shape + whether the FROM_OFFICE1/FROM_DCREGION split survives are #11 design outputs #11 Edit ONLY together with A5, from the ruled URI shape; interim RED once lib-hosts.sh changes is correct fail-loud, not a defect
A5 maas-region-power-key URI assertions (:67,82,102,108) Same dependency, same ruled shape, same edit session as A4 (or they silently diverge) #11 Same as A4
A6 dc-rack-mgmt-import vvr1 pins (:77-78) = owed #9's harness half (MERGED W3.1/W3.3 row) Rename-in-place vs full-concept retirement is the NetBox-migration design's call -- do not pre-pick; when it lands, add the decommission-completeness assertion netbox (+ rack-ret for the concept question) A stale vvr1-dcN device record surviving import must FAIL; the D-124 transit-scheme pins (:73,79 + d124-transit-seed) STAY -- mesh facts, not containment facts
A7 maas-profile-assert office1-profile fixture (:41,68,72,80) Drop the two vvr1-dcN rows from the simulated machine list; the client VM does NOT replace them (not MAAS-carved, pass2 3.2) rack-ret Post-retirement roster fixture; lowest-risk of the CHANGE set, independent of the #11 cluster
A8 dc-dc-whole-host-budget (W3.3 #7; the one universe-boundary crossing -- outside W3.1's 13 by its own routing) Extend with the 3 utility-node classes + the artifact-service disk-sizing branch + the flat model; the old Model-A/B comparison cases must not remain the only coverage (they stay green forever against a retired topology) ready (spec = owed #7; capacity re-measure owed at delivery) A roster total EXCEEDING the measured host budget must FAIL, not round/omit a class
A9 tests/pre-flight-checks -- NEW case post-#11 Assert the LIVE power-address in use matches the mitigation's issued form (restricted-key/wrapper shape), not a raw containment-shaped URI -- the regression detector for concern (iii) #11 A containment-shaped (qemu+ssh://...@172.31.0.2-class) or unrestricted URI fixture must FAIL

B. EXISTING -- RETIRE (5 verdict-blocks across 3 harnesses)

# Harness (cases) Disposition Blocker Failing-direction handling (retire rows still need one)
B1 opentofu-validate T13 (D-127 containment autostart pin) RETIRE -- object deleted, not renamed; D-127 boot-matrix comment block updated in the same edit ready Recommend the negative-assertion case ("no vvr1 domain block exists in opentofu/main.tf") over W3.1's accept-residual-gap alternative -- a stray re-add then still reddens; grep-checkable comment-currency fixture rides along
B2 site-headend-install --host-nodes block (~15 cases: node_host_setup()/node_host_check(), D-125 WAN-bridge asserts, hint-neutrality) RETIRE wholesale (dead code, D-125 has no successor) -- EXCEPT the SEC-010 sub-case, which is A3 ready (when the code deletion ships) Re-derive every surviving arg-contract rc from the NEW parse contract (hazard H2) -- do not let a stale -> 2 case pass on an unrecognized-flag coincidence
B3 site-headend-install Section 6 (--role rack) CONTINGENT retire; if ratified, a new case asserts --role rack is REFUSED/removed; if rejected, stays as-is rack-ret The REFUSE case IS the replacement failing-direction fixture -- hold unedited until the ruling lands
B4 dc-rack-net LEGS cases (T3,T5,T13,T15,T17) RETIRE (stronger-settled: structural consequence of Option 1 itself -- no flat VM is a libvirt host with own bridges) ready at script retirement Append-only bias: file stays in git history; removal via --record-manifest + changelog with revert
B5 dc-rack-net DNS-forwarder cases (T4,T9,T16) + its 8 hygiene cases CONTINGENT retire wholesale with dc-rack-net.sh if D-131 retirement ratifies; if D-131 is kept for a DC, the DNS half survives re-targeted D-131 Same manifest/changelog discipline as B4; note DNS_UPSTREAM="10.10.0.20" is a pre-existing stale defect either way

STAY, named so they are not re-litigated: opentofu-validate T8-T10 (S3 module-body cases); node-vm T1-T7/T12-T15; site-headend-install Sections 1-5,7; maas-node-power (URI fixture is an opaque pass-through arg -- cosmetic refresh optional); preflight pending-change fixture; geneve-encap-assert (all cases -- its post-build live re-run is a new INVOCATION, owed #10, not a harness edit); site-baseleg (guard already forward-compatible; comment re-cite is doc-currency); cloudinit-vm; d124-transit-seed; netem-link (declared grep false-positive); the 90 no-hit harnesses.

C. NEW-BUILD (7 harnesses, one per owed artifact; specs in pass3-w3-new-tests.md Sec 2-3)

# Owed artifact Harness (model) Blocker Signature failing-direction fixture
C1 #12 modules/dc-site tests/dc-site/run-tests.sh, static fixture .tf trees (opentofu-validate --static-only model) module build (spec ready) 5-plane tree FAILS count; 11/13-node roster FAILS; 2 client-VM calls FAILS exactly-one; empty interface_macs on post-apply tree FAILS; v4-only CIDR on a D-139 v6 plane FAILS; mtu=1500 FAILS; hardcoded DC literal FAILS site-token check
C2 #2 the (a) cross-DC host isolation control offline fixture-file (geneve-encap-assert model); name minted with its SEC row mechanism Forward-accept between a dc0 and a dc1 bridge FAILS; a host ADDRESS on a plane bridge FAILS (distinct failure mode); empty/missing ruleset FAILS (never clean); absent-interface-name rule FAILS (SEC-010 fail-open lesson); bare policy drop FAILS does-not-globalize
C3 #1 teardown primitive (+#6 emergency lever rides the same fixture library) stateful-fakebin (phase-00-teardown-d061 model) root-fork A dc1 domain in a dc0-targeted set FAILS before any destroy; a shared-outer object leaking in FAILS; a missing expected domain FAILS completeness; EMPTY resolved set REFUSES (rc=2), never "nothing to do" success; failed canary blocks the group destroy
C4 #11 power-key mitigation offline rendered-ACL/authorized_keys/polkit parsing (site-headend-install grep-the-artifact model) mechanism -- and this harness is itself the precondition for the A4/A5/A9 cluster dc0 key reaching a dc1 domain FAILS; reaching voffice1 FAILS; mirror both directions; a wildcard matching nothing FAILS as under-specified; excluding a dc0-own domain FAILS the must-not-over-restrict control
C5 #13 D-131 retire-evidence checker offline dig-capture fixtures; region IPs read from lib-hosts/lib-net, never duplicated ready (fixtures exist in the two cited changelogs) Resolution that SUCCEEDS via the forwarder alias IP FAILS (resolver IDENTITY asserted, not mere success); dc0's measured evidence PASSES; dc1's current config is a standing-RED case until the live retirement happens
C6 #4 R7 credential-revocation checklist offline; mock vm-secret-locations rows ready An unlisted/orphan row for the retiring host class that enumeration misses FAILS (SEC-027's "an unlisted location is not audited")
C7 #5 MAAS record release/delete (+ rack-controller decommission) fakebin maas (dc-egress-check/phase-00 model) ready A surviving machine record OR the surviving rack-controller/primary_rack/DHCP reference after "release" must not report clean

Rides (no build): #6 -> C3's fixture library; #8 MAC re-measure -> C1's MAC invariant;

#10 geneve/jumbo -> existing geneve-encap-assert verbatim, new invocation point in the runbook only.


3. GATE-HOME MAP -- the three isolation controls + preflight/cloud-assert changes

Control / gate Home(s) Failable assertion (content-based, REFUSE-on-unrecognised)
(i) cross-DC host isolation (the (a) control) NEW Stage-1 gate (host-scoped -- NOT a DC=-scoped preflight gate, which would double-run or silently check only the last DC); re-run at each per-DC apply's close and at cloud-assert A11a (periodic: post-deploy/restart/pre-change/post-incident) --check on vcloud enumerates the live bridge set for BOTH DCs' six planes (from lib-hosts.sh conventions), asserts FORWARD denial between every dc0-tagged/dc1-tagged bridge pair, and REFUSES if fewer than the full plane count resolves to a live interface; rule COUNT/hash matched against the artifact's own expected state, not "a table named X exists". Ordering invariant: installed + verified before the first flat apply of EITHER root
(ii) SEC-010 transit-drop successor NEW preflight P10 (P10 confirmed next free; P6 reserved), DC-scoped, host-bound on the P7/node_host_check() model; one role-agnostic installer/checker covers BOTH ends (client VM + voffice1) nft table present keyed to the CLIENT VM'S OWN re-measured transit interface (NIC-naming trap: dc0 live was enp1s0); mirrored voffice1 check; REFUSE if the keyed interface does not exist
(iii) power-key mitigation Split home: (a) P4 dependency -- before P4 trusts a power-address literal, verify it matches the mitigation's issued shape (the A9 case); (b) cloud-assert A11b -- standing re-verification (the exposure exists whenever libvirtd is up, not only at deploy) Verdict tied to a NEGATIVE test: connecting with either DC's region key CANNOT enumerate/control domains outside that DC's own roster (mechanism-dependent concrete form: forced-command rejects raw virsh list --all, or polkit ACL covers exactly the vr1-dcN-* roster); an existence-only key check is explicitly ruled out (GA-R6)
rack-retirement / D-131 evidence ONE-TIME build-step evidence capture inside the promoted Part-A release/delete step (owed #5/#13) -- NOT a standing gate The C5 checker: resolver-identity dig per fresh 10.13 region, captured into the build changelog; dc1's asymmetry is a standing-red case until closed
P8 substrate drift Extend from the single hardcoded opentofu/ path (preflight.sh:284,298) to loop over every post-flatten root (shared-outer + each per-DC-flat root under (B)), each printing which root it evaluated; the voffice1 "inner state lives elsewhere" WARN branch goes dead for the DC half Existing pending-FAILs/refresh-WARNs logic is already content-based and stays. Administrator amendment: the root list must be DECLARED, not globbed -- a glob loop cannot fail on a missing/renamed root (it silently drops coverage); a declared list FAILS/WARNs. Blocked on root-naming ratification
P5 creds-matrix DATA change, not code: rack-class register rows re-point to the client class; NEW rows owed for #3/#11 key material when minted -- else P5 silently stops covering the new credential-bearing hosts (SEC-022's exact coverage-gap class) Already failable by construction (D-137 ruling 1); flagged as a delivery dependency on #3/#5/#11, not a script edit
P4 / P9 / A11 placement P4: no body edit owed (measured clean, check 4) -- the A9 case is the net-new half. P9 (dc-egress-check): invocation-host literal only, re-points to the ruled B.5 host (client VM the structural candidate). A11's home (cloud-assert vs a dedicated isolation-assert.sh) is recommendation-grade -- Phase 4 confirms --
Unchanged P1, P2 (D-143 axis only), P3, P6, P7 (already host-indirect via host-identity -- the pattern P4/P5 should imitate), cloud-assert A0-A10 (zero container-layer assumptions, verified by W3.2 full read) --

SEC rows: next-free SEC-034 (check 6); 2-or-3 rows owed ((a) control, #11, and concern (ii)'s disposition -- possibly a SEC-010 amendment); minted at delivery, next-free re-grepped then.


4. THE CRITICAL-PATH SEQUENCING CONSTRAINT (stated plainly)

Owed artifact #11 (the power-key blast-radius mitigation) is a BLOCKER for a six-item cluster of test work. Until its mechanism is chosen (Phase 4) and its artifact

  • C4 harness ship, NONE of the following may be written -- a guessed URI/key value here is the false-green mint this repo's inferred-value rule exists to prevent:

  • lib-hosts.sh VIRSH_POWER_ADDRESS_FROM_OFFICE1/_FROM_DCREGION re-derivation (the tools-side edit the tests then pin);

  • dc-selector power-address rows (A4);
  • maas-region-power-key URI assertions (A5) -- A4/A5 edited TOGETHER, same session, same ruled shape;
  • the new tests/pre-flight-checks P4 content case (A9);
  • cloud-assert A11b's concrete body;
  • the P5 register row for the mitigation's key material.

Order: Phase-4 mechanism choice -> #11 artifact + C4 harness -> then the cluster, as one delivery unit. Interim state is deliberate: A4/A5 go honestly RED the moment lib-hosts.sh changes -- that fail-loud RED is wanted; do not "fix" it early. Independent of this cluster (may proceed in parallel once their own blockers clear): A1/A2 (root-naming), A7 (rack-ret), B1/B2 (ready), C1/C5/C6/C7 (ready/spec-ready).


5. HARNESS-EDIT HAZARDS (delivery-time warnings, consolidated from W3.1 Sec 3)

  • H1 -- the plausible-URI swap (sharpest risk in the survey): swapping a plausible-looking new power URI into A4/A5 ("just point it at vcloud") before #11's mechanism exists produces a harness GREEN against a value nothing enforces -- worse than the current honest RED. Only the ruled shape, only both harnesses together.
  • H2 -- the rc=2 coincidence: if --host-nodes is REMOVED as a flag, a stale case like --host-nodes without --role rack -> 2 can keep passing on the unrecognized-flag exit code, silently changing what the assertion proves. Re-derive every expected rc from the NEW arg-parse contract; never assume rc=2 still means what it meant.
  • H3 -- delete-to-go-green: a stale hardcoded path in A1/A2 fails LOUD (safe); the hazard is a sloppy fix that deletes the case instead of re-pointing it, quietly dropping D-127 autostart-drift / MAC-count regression coverage (this class has gone red twice before, tests/node-vm/run-tests.sh:68-81). Replace, never delete to go green.
  • H4 -- the harness that stays green against a dead topology: dc-dc-whole-host-budget's Model-A/B math keeps passing indefinitely after the topology it models is gone; nothing forces a re-run until #7 ships. A8's extension must land WITH the redeploy, and the old cases must not remain the sole coverage.
  • H5 -- the retirement residual gap: retiring T13 leaves a stray vvr1 autostart re-add uncaught unless B1's negative-assertion case is added (recommended over accept-and-declare).
  • H6 -- glob-based gate enumeration (administrator addition): P8's root loop -- and any future multi-root/multi-host gate -- must iterate a declared list; a glob cannot fail on an absent member.

6. THE PER-MODULE HARNESS CONTRACT (adopted from W3.3 Sec 4 -- the template every

Section-2 row follows)

Adopted unchanged as the Phase-4 backbone; every principle grounded in an existing repo precedent (cited in pass3-w3-new-tests.md Sec 4): prove-it-can-fail (every assertion ships a fixture engineered to redden it); assert the ARTIFACT, not the intent (the installed rule / rendered file / deployed value, never a comment or self-report); stage-assert-then-promote (mutating subjects write to staging, assert staged, then promote); join the workspace to the deploy input (byte/value equality between generator output and what the consumer actually reads); fail-closed on absent/empty/unreachable input (incl. the interface-name fail-open class); offline/fixture-driven by default (fakebin or captured text; a separately-named LIVE gate re-run proves the deployed state -- two tiers, never conflated); $SITE/$DC-parameterized (fixtures exercise both DCs or a synthetic site); standard exit contract (lib-validate.sh 0/1/2/3/4); delivery discipline (own tests/<name>/run-tests.sh, changelog with revert, repo-lint clean -- no new-module exception).


7. Settled vs OPEN

SETTLED at this phase (do not re-open): the unified change-set decomposition (9 existing-change / 5 existing-retire verdict-blocks / 7 new-build harnesses / 3 rides; count corrections in check 1); the gate-home map (Stage-1 for (i), P10 for (ii), P4+A11b split for (iii), P8 declared-list loop, rack-evidence as one-time); the #11 sequencing constraint (Section 4); SEC-034 next-free; the harness contract template; pre-flight-checks.sh measured clean of direct container-layer literals; the lib-identity handoff (covered by tests/lib-validate); geneve-encap-assert and cloud-assert A0-A10 confirmed topology-agnostic.

OPEN -- carried to Phase 4 (rulings; operator rules, GA-R5):

  1. Root NAMING (blocks A1/A2 path re-points; pass2 Section 6 item 2).
  2. Rack-controller retirement ratification + the owed live re-measure (blocks A7, B3; shapes A6's concept question).
  3. D-131 retirement ratification + live re-measure (blocks B5; C5's dc1 case stands RED until the live retirement).
  4. The #11 mechanism choice (restricted key / wrapper / polkit ACL) -- unblocks the Section-4 cluster; its SEC row minted with it.
  5. The (a) control's concrete nftables rule set + SEC number (C2's fixtures are mechanism-agnostic until then).
  6. A11's home: fold into cloud-assert vs a dedicated isolation-assert.sh (W3.2 Sec 4 risk 5 -- recommendation-grade either way).
  7. NetBox-migration design (owed #9) -- rename-in-place vs concept retirement for A6.
  8. maas-fabric-prune harness gap (pre-existing; no Phase-3 worker addressed it, check 5): build vs accept-as-named-exception -- a named Phase-4 decision.
  9. D-127 client-VM autostart value (A1's new case needs the ruled value).
  10. The teardown primitive's fixture shape rides the root-fork ratification (C3).

Doc-currency nits (ride other edits, no action here): CLAUDE.md "98 harnesses" vs 103; opentofu-validate header "416 GiB" comment; maas-node-power cosmetic URI fixture refresh.


8. Verification note

Author = "the administrator" (no model name asserted, operator instruction). Direct measurements this session: grep -oE 'SEC-[0-9]{3}' docs/security-ledger.md (highest = SEC-033) + repo-wide SEC-034 grep (sole hit = W3.2's own doc) + bash scripts/ledger-scan.sh (D/DOCFIX/BUNDLEFIX next-free; confirms it does not compute SEC); grep -nE '<W3.1 term set>' scripts/pre-flight-checks.sh -> zero hits (rc=1) + lib-hosts sourcing at :44-45; ls tests/ + wc -l tests/HARNESS-MANIFEST (103; 104 entries incl. the manifest); tests/maas-fabric-prune absent; tests/pre-flight-checks and tests/preflight both exist (distinct). The three worker docs and three prior admin reports were read in full; worker citations were spot-checked at their load-bearing points, not re-derived wholesale. READ-ONLY; findings LOGGED only; nothing executed.