Skip to content

fix(honesty): labels computed from checks [host PASS @226c695e][QEMU NOT_RUN][hardware NOT_RUN] - #243

Merged
aien-dev merged 1 commit into
mainfrom
hive/HD-01b-honesty-labels
Oct 2, 2026
Merged

aien-dev merged 1 commit into
mainfrom
hive/HD-01b-honesty-labels

Conversation

@aien-dev

@aien-dev aien-dev commented Oct 2, 2026

Copy link
Copy Markdown
Owner

What this fixes (plain English)

Several test scripts printed PASS (or a "PASSED" banner) even when a check inside them had been skipped, or when the check behind a label never looked at the thing the label names. Each one now computes its label from a real check, or says NOT_RUN with a reason. Every fix has a self-test or mutant (a deliberately broken input) that shows the label flips.

Fixes

  • verify_recovery_tools.sh and test_trust1_key_ceremony.sh: a skipped check exits 3 and prints NOT_RUN, never PASS. The M5 qualify table maps exit 3 to NOT_RUN.
  • verify_all.sh: removed the unconditional "HOST VERIFICATIONS PASSED" banner. New lib_verify_summary.sh prints PASS or NOT_RUN from what actually ran.
  • trust1_gate7_preflight.sh: a NOT_RUN recovery-tool check no longer reads as a PASS.
  • qemu_security_suite.sh: corrupt-image rejection now needs the firmware banner, not just the absence of "kernel: alive".
  • qemu_native_rollback_test.sh: BOOTNEXT_CONSUMED and DEFAULT_UNCHANGED are each judged from their own guest evidence in both Default boots (the old grep never checked the boot order).
  • ck_gates.sh: tree_clean_before is computed (was a literal true); jq skip is noted.
  • evidence/gate1_zero_disk_recovery_receipt: addendum marks its four literal true invariants NOT_RUN. New scripts/check_receipt_labels.sh lint (wired into verify_all) keeps hardcoded invariants from reappearing unamended.
  • docs/TRUST-1-M5-GATE-MATRIX.md and native-suites.yml comment: stale newest-receipt text, soak status, and the note that ci.yml is disabled.

Evidence (host)

Self-tests run on the host, all exit 0: verify_recovery_tools, lib_verify_summary, qemu_security_suite, qemu_native_rollback_test, ck_gates, check_receipt_labels, trust1_m5_qualify (mutant killed). The real lint passes with the addendum and fails without it.

NOT_RUN

QEMU runs, cargo, make (blocked by the quiet flag) and all hardware. verify_all.sh was syntax-checked, not run end to end.

🤖 Generated with Claude Code

…pped

A skipped check no longer prints PASS. Each fix has a --self-test or mutant
that proves the label flips (same style as #213).

- verify_recovery_tools.sh, test_trust1_key_ceremony.sh: skipped checks exit 3
  and say NOT_RUN; m5 qualify table maps exit 3 to NOT_RUN
- verify_all.sh: the unconditional "HOST VERIFICATIONS PASSED" banner is gone;
  new lib_verify_summary.sh ends with PASS or NOT_RUN from what actually ran
- trust1_gate7_preflight.sh: a NOT_RUN recovery-tool check is not a PASS
- qemu_security_suite.sh: corrupt-image rejection now needs the firmware banner
- qemu_native_rollback_test.sh: BOOTNEXT_CONSUMED and DEFAULT_UNCHANGED are each
  judged from their own guest evidence in both Default boots
- ck_gates.sh: tree_clean_before computed from the tree state, jq skip noted
- gate1 receipt: addendum marks its four literal true invariants NOT_RUN;
  new check_receipt_labels.sh lint (wired into verify_all) keeps it that way
- docs and native-suites.yml comment: stale newest-receipt text, soak NOT_RUN,
  ci.yml is disabled

Host only. QEMU, cargo, make and hardware paths are NOT_RUN.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@aien-dev
aien-dev merged commit 3156c33 into main Oct 2, 2026
24 of 25 checks passed
@aien-dev
aien-dev deleted the hive/HD-01b-honesty-labels branch October 2, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant