Skip to content

TR-02-QF: quiet-flag header matches gate rows in TRUST-1/M5 receipt [host self-test PASS] - #231

Merged
aien-dev merged 1 commit into
mainfrom
hive/TR-02-QF-quietflag-header
Oct 1, 2026
Merged

aien-dev merged 1 commit into
mainfrom
hive/TR-02-QF-quietflag-header

Conversation

@aien-dev

@aien-dev aien-dev commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

What

scripts/trust1_m5_qualify.sh wrote quiet_flag_present by sampling the quiet flag only when the receipt was written, while the QEMU gates check the flag when each gate is evaluated. A run with the flag up during the gates and down at write time produced a header saying false next to six NOT_RUN "quiet flag" rows (TR-02 inspector report, fix item 3).

Change

  • evaluate_gate records quiet_flag_seen_at_gates=true when it refuses a QEMU gate for the flag.
  • write_receipt: quiet_flag_present (same field name) is now true if the flag was up at gate evaluation, OR any row is NOT_RUN with a "quiet flag" reason, OR the flag is up at write time.
  • New fields (no repurposing): quiet_flag_present_at_write (the old write-time sample) and quiet_flag_refused_gates (count of rows refused for the flag).
  • tpm2_getcap / tpm2_pcrread lines untouched.

Self-test mutation

New --self-test case: flag up while a QEMU gate is evaluated, removed before write_receipt. Expected header: quiet_flag_present: true, quiet_flag_present_at_write: false, quiet_flag_refused_gates: 1. The old code writes false here, so the case fails on the old behaviour and passes on the new. Also added: a row-only case (gate-time sample cleared, refused row still forces true) and a never-up control (false).

Status

Host self-test PASS at 174ecbb (bash scripts/trust1_m5_qualify.sh --self-test, log TR-02-QF-190053.log, ends TRUST1_M5_QUALIFY_SELF_TEST: PASS). QEMU NOT_RUN. Hardware NOT_RUN.

Known limit (UNVERIFIED, medium confidence, from the inspector report): a child QEMU script refusal not worded "quiet flag" falls back to the write-time sample.

🤖 Generated with Claude Code

quiet_flag_present was sampled only when the receipt was written, while
the QEMU gates check the flag when they are evaluated. A run with the flag
up during the gates and down at write time produced "false" next to
NOT_RUN "quiet flag" rows (TR-02 inspector, fix item 3).

Now quiet_flag_present is true if the flag was up when any QEMU gate was
evaluated, if any row was refused for it, or at write time. New fields
quiet_flag_present_at_write and quiet_flag_refused_gates keep the raw
samples. Self-test adds the mutation case (flag up at gates, down at
write -> header must be true), a row-only case, and a never-up control.

NOT_RUN: self-test not run by the builder; queued for the forge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aien-dev aien-dev added host-only Host-side change, no hardware NOT_RUN Tests not yet run by the forge labels Oct 1, 2026
@aien-dev aien-dev changed the title [NOT_RUN] TR-02-QF: quiet-flag header matches gate rows in TRUST-1/M5 receipt TR-02-QF: quiet-flag header matches gate rows in TRUST-1/M5 receipt [host self-test PASS] Oct 1, 2026
@aien-dev
aien-dev marked this pull request as ready for review October 1, 2026 19:49
@aien-dev
aien-dev merged commit 2c737aa into main Oct 1, 2026
4 of 5 checks passed
@aien-dev
aien-dev deleted the hive/TR-02-QF-quietflag-header branch October 1, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

host-only Host-side change, no hardware NOT_RUN Tests not yet run by the forge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant