fix(honesty): labels computed from checks [host PASS @226c695e][QEMU NOT_RUN][hardware NOT_RUN] - #243
Merged
Merged
Conversation
…pped A skipped check no longer prints PASS. Each fix has a --self-test or mutant that proves the label flips (same style as #213). - verify_recovery_tools.sh, test_trust1_key_ceremony.sh: skipped checks exit 3 and say NOT_RUN; m5 qualify table maps exit 3 to NOT_RUN - verify_all.sh: the unconditional "HOST VERIFICATIONS PASSED" banner is gone; new lib_verify_summary.sh ends with PASS or NOT_RUN from what actually ran - trust1_gate7_preflight.sh: a NOT_RUN recovery-tool check is not a PASS - qemu_security_suite.sh: corrupt-image rejection now needs the firmware banner - qemu_native_rollback_test.sh: BOOTNEXT_CONSUMED and DEFAULT_UNCHANGED are each judged from their own guest evidence in both Default boots - ck_gates.sh: tree_clean_before computed from the tree state, jq skip noted - gate1 receipt: addendum marks its four literal true invariants NOT_RUN; new check_receipt_labels.sh lint (wired into verify_all) keeps it that way - docs and native-suites.yml comment: stale newest-receipt text, soak NOT_RUN, ci.yml is disabled Host only. QEMU, cargo, make and hardware paths are NOT_RUN. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this fixes (plain English)
Several test scripts printed PASS (or a "PASSED" banner) even when a check inside them had been skipped, or when the check behind a label never looked at the thing the label names. Each one now computes its label from a real check, or says NOT_RUN with a reason. Every fix has a self-test or mutant (a deliberately broken input) that shows the label flips.
Fixes
Evidence (host)
Self-tests run on the host, all exit 0: verify_recovery_tools, lib_verify_summary, qemu_security_suite, qemu_native_rollback_test, ck_gates, check_receipt_labels, trust1_m5_qualify (mutant killed). The real lint passes with the addendum and fails without it.
NOT_RUN
QEMU runs, cargo, make (blocked by the quiet flag) and all hardware. verify_all.sh was syntax-checked, not run end to end.
🤖 Generated with Claude Code