The PR-310 restricted boundary work adds installed socket/maintenance/native adapters but remains implementation-incomplete. The observer/workload UID and storage split is missing, new supervisor execution is blocked, and the mandatory disposable service/UID positive lane has not executed. Its installer and offline tests do not establish a deployed protected host or reduce the retained 49 mandatory / 47 unresolved Phase 12 assessment. Hosted selected-federation maintenance guards remain in force.
This runbook describes the original reference, detached approval, preselection, and scoped runtime comparison boundaries introduced for PR-308.
This is Phase 12 remediation. A resource comparison does not complete the shared app-network-budget case matrix, the nine maintenance rows, a release, or Phase 12. The retained repository-only assessment remains 49 mandatory requirements and 47 unresolved at 2026-09-13T10:30:00Z; preserve its exact cutoff and historical reports when evaluating a successor.
The original Phase 12 open-items tracker is an immutable historical statement pinned by the acceptance policy. Its bytes remain unchanged; current successor scope belongs here and in operational closeout. Older statements that selected federation or encrypted maintenance was unimplemented do not reopen implemented work.
Selected-federation projection and encrypted maintenance transport have implemented successors; see PR-307's exact scope and residual boundary. The hosted private path remains blocked until a restricted worker and immutable resolver isolate provisioned keys from the unrestricted-sudo job account. This is a current execution prerequisite, not an absent encryption implementation or permission to weaken private-key isolation.
PR-306 supplies actual bounded scheduler pressure/resource observations. PR-308 adds original-reference admission, complete attempt accounting, detached actual approval, pre-execution baseline selection, and scoped comparison consumption. Original production reference observations, actual authorized approval, protected candidate execution, and default-profile or long-duration claims remain separate unperformed operations. Full app budgets, Mail/migration, durations, independent review and publication retain their existing owners and requirement IDs.
The initial comparison scope is a daemon regression with the same selected app cohort, workload, corpus, effective configuration, collector semantics, and environment. Different daemon product/source identities are permitted by the existing pure comparator. Same-product execution is repeatability or calibration, not cross-version regression.
The checked-in synthetic policy is test-only. Its repetition count, windows, and thresholds are not an approved production experiment. Approval of an operational experiment requires a separately reviewed policy and actual authorized decision about its exact proposal bytes.
Use Python 3 and the supported Java 25+ Gradle graph for local packaged tests. The task does not authorize managed-node mutation, public-network experiments, protected workflow dispatch, reviewer impersonation, signing-key provisioning, publication, or long-duration campaigns.
Keep the following order in original observed events:
reference plan and complete attempts
-> immutable unreviewed baseline candidate
-> actual approval of candidate, policy, and scope
-> candidate plan and activation select baseline and approval
-> candidate workload and observation
-> recomputed comparison at the explicit evaluation cutoff
The final comparison is never an input to its own pre-execution selection. Do not amend or backdate a completed run to add a baseline. A changed plan, policy, cohort, collector, reference, or private recipient context requires the corresponding new controlled selection. Keep earlier failures and cancelled attempts in their original history.
The baseline produced by runtime_baseline.collect() retains review=None. Its exact file digest and canonical semantic digest are different kinds of identity. A detached original approval binds both; no final signed record includes its own digest. The old local reviewed view remains a calculator compatibility format and has releaseEligible=False.
The protected runtime baseline admission owner provides the finite operations: authenticate_observation verifies original observations; prepare_proposal builds the exact unreviewed candidate and complete attempt ledger; authenticate_selected reconstructs the proposal from retained original references and authenticates its detached decision; admit_candidate binds the original candidate to that selection. The resulting AuthenticatedRuntimeBaseline exposes the narrow recomputed comparison needed by the owning consumer. Supplying serialized assertion fields does not construct this capability.
The existing scheduler lane owns process launch or borrows an already authenticated supervisor-owned process. Its private runtime-series-<epoch>.json files contain bounded raw numeric observations with original epoch and interval accounting. plan.json, the original journal/checkpoints, cleanup outcome, and complete attempt ledger supply separate execution context. A renamed series or a different runId cannot establish a new original repetition.
Plan the required repetitions and permitted attempts before results exist. Preserve failed, invalid, timed-out, and cancelled attempts with their predeclared dispositions. Only valid, distinct, nonoverlapping original executions enter the numerical reference set. A valid replacement does not erase its failed predecessor; arbitrary best-subset selection is not admission.
scheduler_pressure_runtime also retains runtime-input-snapshot.json under the owned private run root. The closed 64-KiB snapshot includes the selected daemon's observed JVM configuration, effective scheduler/budget/pressure configuration, and source-owned environment observation. That observation contains JDK identity, hardware class, visible cgroup CPU and memory restrictions, process CPU mask, storage class, and network topology scope. Raw process command lines and credential material are excluded.
lane.input_snapshot() returns detached values. derive_snapshot_fingerprints(snapshot) recomputes the environment and configuration fingerprints offline; it does not authenticate source ownership. The original artifact verifier must authenticate the exact snapshot bytes and compare the derived values with the original series. A plausible hash supplied by a caller is insufficient. Missing or unavailable snapshots block applicability.
The standalone snapshot uses standalone-v1; the borrowed lane uses borrowed-v2. The latter's declared daemon-regression topology scope binds role, product family, package target, API contract version, and runtime identity while keeping changing daemon artifact/source identities in their own subject fields. App-cohort equality remains mandatory. Historical topology hashes and collector fingerprints are not aliases for the prospective scope.
For local source-build packages, input-package-members.json freezes the original selected file/link roster before launch. After cleanup the collector rechecks those exact members. Newly created logs can change the writable full tree while all original package members remain intact. Never report the modified full tree as byte-identical to the original package. A published predecessor still requires original archive/product admission; this local manifest does not supply release provenance.
The protected approval producer consumes a frozen proposal and the exact versioned decision request. Its verifier authenticates the original artifact, fixed workflow revision, original run/attempt/job, and actual environment-review decision. The actual reviewer must have the required repository role and satisfy non-self-approval separation. A configured reviewer list, environment name, attestation on unrelated bytes, or uploaded JSON does not establish that decision.
Approval accepts the scoped experiment and limits. It does not prove universal performance, measurement honesty, security, or independent review. Authenticate references and candidate observations separately. Protected execution of synthetic inputs remains synthetic. Historical raw series may retain their original operational label when the old protected-long schema requires it; the new scoped public baseline admission explicitly reports the fixed synthetic workload's classification and cannot promote that historical label to real-user/default-profile evidence.
Evaluate approval applicability and active status at the selected cutoff, including expiry, revocation, and supersession. Historic valid measurements remain historical facts after expiry; expired or revoked approval cannot authorize a new run or fresh release decision. A copied report or relocated file does not renew approval. Retries must preserve the original selected baseline; reselection starts a new controlled campaign.
Terminal evidence capture remains available when an approval expires or is revoked after the
candidate has executed. The stopped supervisor retains the exact private observation before
comparison and emits the original terminal checkpoint, including failed/cancelled outcomes.
Without current approval authority it performs no baseline comparison and preserves the
reviewed-runtime-baseline-missing blocker. Where the prospective measurement contract applies,
its public component says measured-but-uncompared and not-observed, and omits private input
commitments. Original attestation or selection-integrity failures remain errors. This exception
applies only to evidence collection; authorize/start still require current approval, and retrying
finish cannot renew approval or change retained bytes.
Original-evidence consumers dispatch these uncompared reports separately from reports that claim an authenticated comparison. They authenticate the retained original candidate capsule, private selection, terminal checkpoint, and supervisor chain, then exactly recompute the blocked public projection. They do not reacquire baseline approval or admit a failed/cancelled execution as a valid numerical candidate. Missing private context remains a blocker; altered component fields or a rebound observation fail verification. Sealed reports retain private-product verification.
Approval authentication checks preparation ordering and independently fetched versus original
job-completion timestamps before current applicability. An inconsistency raises
runtime-approval-original-job-integrity-invalid; even simultaneous expiry cannot convert it
into an eligibility fallback or a successful terminal report.
Revocation and supersession markers are checked only after original integrity and selected-scope verification. Private proposal reads verify retained bytes without deciding current eligibility; this permits full reference recomputation and original approval authentication before a terminal fallback. Both approval production and current-use authentication still enforce the markers. A marker cannot hide invalid references, substituted proposal bytes, mismatched policy/context, or inconsistent original job timestamps. Regressions exercise both marker types, including simultaneous denial and invalid original evidence.
The terminal-lifecycle regression reproduced the original expiry failure before the fix. The
focused baseline suite now passes 52 tests, with 14 ledger, 12 sealed handoff/measurement, and 23
projection tests passing separately. Lifecycle tests exercise real terminal file ownership,
journal/checkpoint checks, retention, projection, and retry while isolating original-provider
approval responses. No protected execution or external approval is implied. The fixed-cutoff
successor assessments are retained separately in build/pr308-phase12-terminal-fix and
build/pr308-phase12-terminal-consumer-fix. Original-consumer tests reproduce complete, failed,
and cancelled report consumption through actual original member verification and exact projection,
with synthetic network-provider responses. The new consumer and approval-integrity regressions
both failed against the pre-fix code and pass with the corrections.
The further revocation-ordering assessment is retained at
build/pr308-phase12-revocation-integrity-fix, using the same original cutoff.
Online original authentication is an explicit protected step. Pure arithmetic performs no network fetch. Offline verification requires the verified original inputs and private context; absent proofs yield a blocker rather than a substituted public assertion.
These operations require a separately approved restricted runner with the exact reviewed helper
installed at /opt/cryptad-cross-version/current. Installation, configuration, and environment
approval are operational prerequisites; the local tests neither provision them nor approve them.
The PR-307 hosted restricted-worker blocker remains in force.
- Select the closed
runtime-reference-campaignbefore collecting references. It fixes the evidence class, comparison scope, exact reference fingerprint and analysis policy, serial execution, timeout, ordered attempt IDs, required repetitions, replacement outcomes and maximum replacements. Supply it asauthorization.runtimeReferencewithprivate.runtimePolicyto the existing fixed supervisor authorize/start path. Each reference must use its originally planned attempt ID and the original admitted product/cohort. Reference mode and candidate-baseline mode are mutually exclusive. - Finish each original reference through its owning supervisor. The stopped terminal context
produces the private observation capsule under
/var/lib/cryptad-runtime-baselines/observations/<experimentId>.json. It binds the exact selected raw input bytes, original journal/checkpoint, activation, private authorization, and bounded input snapshot. Its corresponding original supervisor artifact remains separately authenticated. - Install the private, root-owned
/etc/cryptad-certification/runtime-baseline-preparation.json. Its closed fields arecampaignPath,policyPath,observations, andrequestPath. Every observation entry has onlycoordinatesandbundlePath; the fixed producer reauthenticates those original coordinates and capsule bytes and checks the complete planned roster.requestPathcontains onlystatus,effectiveAt, andexpiresAt; the producer derives the proposal, scope and policy bindings. - The
prepare-runtime-baselinejob in environmentruntime-baseline-preparationinvokes the installedruntime_baseline_approval.py prepareoperation. It runs actual observation authentication andprepare_proposal, freezes exact proposal/request files as exclusive0400files in the private store, and emits a random opaqueapprovalContextanchor. No reference or selection hashes are exposed in the public anchor. - Retain the preparation artifact's original coordinates in
/etc/cryptad-certification/runtime-baseline-approval-origin.json. An authorized maintainer reviews the exact privately retained proposal and request, then approves the separateruntime-baseline-approvalenvironment with the exact commentapprove-runtime-baseline:<approvalContext>. Theapprove-runtime-baselinejob runs the fixedruntime_baseline_approval.py approveproducer; it authenticates the preparation artifact and actual exact-comment review. Both operations permit only the original first workflow attempt. The original approval job's completion is an upper bound on completion of review, not an invented timestamp for the human decision. - Before candidate work, install the private
runtimeBaselineselection containing its exact proposal/baseline/policy identities, opaque approval context, original approval coordinates, scope, role and selection time. The existing supervisor reauthenticates selection at authorize and start, fixes it in root-owned activation/private state, and exposes only the selected policy to the tokenless service. Candidate results cannot select different references after execution. - Finish through the owning supervisor. It recomputes the complete original reference proposal, current approval eligibility, original candidate series, and exact selected comparison. The prospective runtime and maintenance consumers receive the authenticated capability and bounded public result; they do not accept a caller-written successful comparison.
The fixed installed operations have no generic command, arbitrary URL, or CLI-selected file path mode. Calling the helper outside its original installed workflow/job identity fails. Never create replacement GitHub environment variables or synthetic reviewer receipts to make that check pass.
Failure/cancellation accounting uses original terminal evidence. An original failed checkpoint with the controller's failure fault and cleanup remains failed; an original partial checkpoint with the controller's interruption fault and cleanup is cancelled. The stopped finish report must authenticate that context. An arbitrary partial checkpoint, absent fault, or missing cleanup is not a terminal attempt. The proposal retains these outcomes and enforces the campaign's allowed replacement dispositions without rewriting raw journal history.
Reference start preparation retains a root-private runtime-reference-start.json intent before
marking the attempt. The intent fixes the original activation, authorization, boot, product
selection and monotonic deadline. New ledger marker v2 binds its activation digest; historical v1
markers retain their original non-resumable meaning. A retry of the same current attempt verifies
the intent, completes only missing matching root records, and preserves the marker and activation
bytes. Another attempt cannot skip the pending one, and retry does not extend any execution clock.
This retry guarantee requires complete, valid retained intent/marker records. A torn record or
orphaned staging file from a hard process/machine crash remains an explicit reconciliation error;
the helper does not delete accounting state or guess the missing original bytes.
After an interrupted preparation or a failed systemd command, retry the existing fixed start
operation with the same selected authorization. A fresh launch is allowed only within the original
boot/deadline when systemd reports a fully inactive/failed unit with no main/control/cgroup processes,
no private/public experiment roots exist, and systemd records no service launch since the intent.
An already running selected service only recovers its start report; it is not launched again.
For a stopped service with a retained execution root, recovery verifies and retains the original
terminal evidence before returning a stopped start report for the normal finish handoff. A prior
launch with missing or invalid terminal evidence remains a reconciliation error, never an inferred
empty successful run or permission to replay workload. Do not delete immutable marker/intent files.
After a completed reference's original finish handoff is durably retained, include its start intent
with the activation/private records in the existing operator reconciliation before preparing a new
reference. Preserve the campaign ledger and retained observation capsules throughout; a new attempt
must not reuse the previous global activation or intent.
The native reference-start/ledger suite covers interrupted intent, root-record and activation
writes, failed pre-launch systemd calls, lost running-service handoffs, exact-byte substitution,
deadline expiry, changed original authorization, transitions and prior launches. These are isolated
synthetic original/systemd providers with real root-owned files, not protected workflow dispatches.
The focused retry/ledger suite passes 24 tests; the reproduced pre-fix systemd failure instead
rejected every retry with protected-start-reuse-requires-reconciliation. The successor assessment
is retained under build/pr308-phase12-reference-start-fix at the original cutoff.
Keep private proposal and observation files at their original identities. A root-owned
<approvalContext>.revoked or <approvalContext>.superseded marker in the private store denies
current use without altering historical evidence; marker removal is not an approval or automatic
renewal. Review a new proposal and obtain a new actual decision when the method or scope changes.
The version dispatch preserves report v5/sealed measurement v4 and adds prospective report v6,
measurement v5 and the independently versioned runtimeBaselineAdmission schema v1 with explicit
historical-base dispatch. These contracts must travel together; an old measurement never acquires
the new assertion from local review data.
The arithmetic owner remains runtime_baseline.py. Original authentication and approval belong to protected code; the runtime/maintenance consumers receive an immutable authenticated context and recompute the candidate comparison.
A prospective component may observe only the narrow runtime-within-reviewed-bounds assertion when provenance, actual approval, original preselection, candidate observation, compatible inputs, useful progress, and numerical bounds all pass. Missing proof, incompatibility, insufficient data, and numerical regression retain distinct results. fullAppBudgets remains not-observed until its complete operations are implemented and observed by the owning code.
Historical v1 local components and measurement v1/v2/v3/v4 preserve their existing meanings. Sealed PR-307 authorization, measurement, and report contexts retain original authentication before opening and private-context verification. Do not add arbitrary members to its closed five-member runtime transport.
Keep the baseline, approval, reference coordinates, app/cohort/environment/selection fingerprints, and raw numbers in private evidence. Public output requires the owning allowlisted projection. Hashes can disclose private experiment commitments. An unavailable private root is an actionable blocker; it is not authenticated empty data.
Build the supported packaged prerequisites, then run the owned isolated synthetic lane:
./gradlew :platform-devtools:installDist assembleCryptadDist
CRYPTAD_SCHEDULER_RETAIN_TEST_OUTPUT=1 \
PYTHONPATH=tools/interop:tools/release-certification:tools/release-certification/protected \
python3 -m unittest discover -s tools/interop -p 'test_scheduler_pressure_packaged.py'The standalone test executes two reference runs and a distinct candidate run, each in a fresh execution package/root, with a shared synthetic signed fixture and identical JDK input. It calls the actual collect and compare, retains immutable unreviewed reference bytes, verifies distinct epochs/nonoverlap, and checks exact comparable fingerprints. Its explicitly synthetic local reviewed view exercises the historical calculator seam; it is not an original approval. The separate protected integration suite owns approval-consumption coverage.
The packaged test reports the actual numerical status under unchanged fixture limits. Numerical failure or insufficient data can remain visible while proving collector and comparator execution. Never change thresholds or relabel those outcomes to make the test claim operational acceptance.
The private runs are retained under build/pr306-private-runs/; the private root inventory is build/pr306-packaged-private-roots.json. These inherited local names are not publication paths. Do not upload those directories as public CI artifacts. The console summary contains fixed labels, counts, numerical classification, and reason codes.
On 2026-09-14, the initial packaged execution ran both test methods in 513.958 seconds with Java 25.0.4.1, Python 3.13.5, and Node 24.21.0. The borrowed-supervisor case passed. All three standalone executions completed, with 68, 88, and 76 samples respectively including their separate restart epochs. The actual candidate comparison returned within-reviewed-local-bounds, no findings or regressions, and releaseEligible=False.
The initial test command nevertheless failed a stale assertion that expected runtime-baseline-comparable=not-observed even after local baseline selection. That assertion was corrected while preserving runtime-within-reviewed-bounds=not-observed. A separate retained-input verification successfully reran exact collection, snapshot derivation, distinct-epoch/nonoverlap checks, and comparison against the original bytes. This distinction preserves both the real collection outcome and the original failed test result.
The complete packaged suite was then rerun after the collector/helper integrations stabilized:
both tests passed in 515.611 seconds, without skips. The fresh two-reference/one-candidate
comparison again returned within-reviewed-local-bounds, no findings, and releaseEligible=False.
This is actual same-product synthetic repeatability execution. It is separate from the test-only
original-provider seams that exercise protected approval and consumer authentication.
Final focused verification passed 42 protected baseline tests (22 admission, 12 approval, and 8 consumer), 14 native attempt-ledger tests, 23 maintenance projection tests, and 185 Phase 12 self-tests. The composed admission test authenticates two original reference artifacts, recomputes the proposal, executes the approval producer/verifier, authenticates a distinct original candidate, and reaches the owning consumer. Its original-provider network seam is explicitly synthetic; original member, context, lineage, approval-content, and final numerical checks run. Historical cross-version and maintenance self-tests passed 114 and 247 tests respectively; the unchanged pure comparator passed 19 tests. Both changed workflows passed actionlint.
Subsequent review exposed a missing approval scratch directory in authenticate_selected.
A new composed selection regression reproduced FileNotFoundError in the real approval member
verifier before the fix. Selection now creates its dedicated private directory with mode 0700
before approval authentication. The protected baseline suite then passed 43 tests. This new test
isolates already-verified reference inputs and ledger accounting while exercising actual proposal
recomputation and approval member, attestation, reviewer, and private-file checks. It supplies no
production approval. Review-fix assessments are retained separately under
build/pr308-phase12-review-fix at the same original cutoff.
The supported Gradle prerequisite graph completed successfully. It emitted existing Error Prone warnings in untouched Java sources; no Java sources changed, and no separate SonarLint/SpotBugs cleanliness claim is made. No full native suite or protected hosted CI run was performed for this uncommitted implementation. The retained predecessor head's CI is historical evidence only.
Before/after repository assessments use the same 2026-09-13T10:30:00Z cutoff and retain separate
outputs under build/pr308-phase12-before and build/pr308-phase12-final. The before assessment
was independently verified in a detached checkout of its original integration source. Both retain
49 mandatory requirements, 47 unresolved, and phaseComplete=false. Interim source-pin drift
remains in separate local outputs; it was corrected by updating actual implementation identities,
without changing requirements, historical tracker bytes, or evaluation clocks.
Run focused offline input checks:
PYTHONPATH=tools/interop:tools/release-certification:tools/release-certification/protected \
python3 -m unittest discover -s tools/interop -p 'test_scheduler_runtime_inputs.py'
PYTHONPATH=tools/interop:tools/release-certification:tools/release-certification/protected \
python3 -m unittest discover -s tools/interop -p 'test_cross_version_scheduler_environment.py'
python3 tools/perf/test_runtime_baseline.py| Dimension | Implementation or test evidence | Operational evidence |
|---|---|---|
| Original input snapshots and package member checks | Implemented; focused offline checks pass | No protected original reference campaign performed by this task |
| Repeated packaged collection | Two references and one candidate exercised by the owned synthetic test | Not a published-predecessor or default-profile baseline |
| Detached approval adapter | Implemented fixed producer and original reviewer/decision verifier; positive and adversarial synthetic integration pass | No actual authorized production approval supplied |
| Preselection and scoped consumption | Implemented original activation binding and recomputation; scoped accepted component reached in tests | No protected candidate campaign performed |
| Statistical scope | Existing resource arithmetic and fixture thresholds preserved | No universal confidence or 24/72-hour stability claim |
| Parent maintenance/Phase 12 | Existing blockers and historical clocks remain authoritative | Shared budget matrix, durations, Mail/migration, independent review and publication remain separate |
The next provisional slice is the complete shared app-network-budget cohort, especially Trust Graph import-by-URI reservation, fetch, commit, failure, restart, and scoped accounting. Reassess dependency order from the final implementation; do not fold Mail lifecycle work or scheduler redesign into that slice.
The prospective shared-budget implementation
adds composed Trust Graph accounting work. It preserves this runbook's historical
fullAppBudgets=not-observed resource-comparison contract. Changed app/cohort/collector fingerprints
need their own later authorized baseline collection and approval; existing approvals cannot be
rebound. The restricted private-resolver/key execution prerequisite remains unresolved.