Mark 8D.7 Implemented Scope Validated

This commit is contained in:
2026-09-07 19:04:49 +02:00
parent fe1e2d98b4
commit 93d8d1e5ca
5 changed files with 51 additions and 8 deletions
+5 -3
View File
@@ -1,6 +1,6 @@
# Phase 8D — Incremental web administration plan
Status: **8D.08D.6 and M1 validated by explicit user sign-off. 8D.7 first stop/reboot and second certificate slices implemented, host-tested, build-verified and reviewed; target validation and M2 acceptance pending. User explicitly authorized stacking the next bounded credential/account slice, not target sign-off. Other owner slices remain; 8D.88D.22 are not authorized by that continuation. Numeric reserve gates remain open.** See the [8D.6 implementation record](phase8d6_implementation.md), [8D.5 implementation record](phase8d5_implementation.md), [8D.4 implementation record](phase8d4_implementation.md), [8D.3 implementation record](phase8d3_implementation.md) and [8D.0 baseline/M1 contract](phase8d_baseline.md).
Status: **8D.08D.6 and M1 validated by explicit user sign-off. 8D.7 implemented scope validated by explicit user sign-off on 2026-09-07, superseding historical target-pending and continuation instructions below. Full browser parity is not claimed: self/generated/key/legacy-credential and other owner-specific restrictions remain deferred; bootstrap/recovery remain UART0-only. Numeric reserve gates and M2 acceptance remain open. No new implementation is authorized.** See the [8D.7 sign-off and evidence](phase8d7_implementation.md), [8D.6 implementation record](phase8d6_implementation.md), [8D.5 implementation record](phase8d5_implementation.md), [8D.4 implementation record](phase8d4_implementation.md), [8D.3 implementation record](phase8d3_implementation.md) and [8D.0 baseline/M1 contract](phase8d_baseline.md).
This is the execution plan for [roadmap Phase 8D](roadmap.md#phase-8--role-based-users-and-administrative-access). The roadmap retains the feature/security requirements; this document defines small work units, dependencies, and release gates. The [administration test matrix](user_administration_tests.md#planned-phase-8d-integrated-web-administration) remains the final acceptance checklist.
@@ -138,6 +138,8 @@ If 8D.3 exceeds the work-unit limit, first split out inert login-page rendering
### 8D.7 — Web-shell lifecycle parity and M2 acceptance
**Target sign-off (2026-09-07), implemented scope:** User explicitly requests marking 8D.7 validated after thorough testing. Certificate rotation and web start/stop were verified, with lifecycle via UART0/SSH admin/web admin and restart after browser stop via another route. Full mix without broker drops up to 230400 baud after external adapter baud correction is user-reported. Intermittent supported two serial + one admin admission failures have recently not recurred and are accepted nonblocking, not fixed. [Evidence and limits](phase8d7_implementation.md). No detailed reboot/individual mutation checklist passes are inferred. This supersedes pending status and next-slice instructions in the historical checkpoints below for all three implemented slices, including other-account operations. Remaining self/generated/key/legacy-credential and other owner parity stays deferred/restricted; numeric reserves and M2 acceptance remain open. Wait for a separate implementation request.
**Second bounded certificate slice:** [Implementation, separate slice histories and pending target checklist](phase8d7_implementation.md). Exact parsed browser `web certificate rotate --force` uses a typed request-queue union and immutable owner `dispatcher_actions` mask: bounded drain/200 ms then nonblocking handoff to the existing 12 KiB dispatcher, not 4 KiB control. Pending input gating, token/principal/session revalidation and executing-slot reservation persist through execution. Transactional certificate commit → stop → start short-circuits errors and retains ownership on failed stop; SSH/UART0 unchanged. No new tasks/depth/routes/assets/stacks; target owner-mask/local-scratch accounting and stack margins unknown, host sizeof is not proof. Parent final `pio run` PASS **26.32 s, 95,580 B RAM / 1,648,061 B flash**: **0 / +1,036 B** vs first slice, **0 / +1,572 B** vs 8D.6, **+1,048 / +48,088 B** vs 8D.0. Implementer focused suites pass (transport **25**/tickets **12**, server **11**, boundary including certificate, lifecycle/policy/cookie-admin/store-serial/diff); independent reviewer reports no actionable findings. Sanitizers unavailable (missing libasan/libubsan); no hardware validation. User explicitly authorized stacking the next bounded slice: credential/account, then other owner slices. Other mutations remain blocked; target/M2 acceptance and numeric reserves pending. This supersedes the first-slice next-step/continuation-pending statement below.
**First bounded increment history (2026-09-06):** [Implementation, restrictions and target checklist](phase8d7_implementation.md). Browser `reboot` and `web stop` now use existing deferred control with final WEB session/currentness checks and discard of pending input. Other identity/network/account/SSH restrictions remain explicit. Host suites/review/build pass: **95,580 B RAM / 1,647,025 B flash**, **0 / +536 B** versus 8D.6, final build **12.44 s**. No new task/route/capacity. Target regression or explicit continuation decision pending; this is not completed 8D.7/M2. Next slice remains HTTPS identity/certificate handling, not settings. Prior sign-offs stand; numeric reserves remain open.
@@ -183,11 +185,11 @@ Update the roadmap and user/command documentation to distinguish completed featu
## Progress and next-request template
Progress: **8D.08D.6 and M1 validated by user sign-off; numeric reserves remain open. 8D.7 stop/reboot and certificate slices implemented/host-tested/build-verified/reviewed, target/M2 acceptance pending. User authorized the next bounded credential/account slice, then other owner slices; settings remain out of scope.** Record incremental results in `docs/agent/current-state.md`, retaining the [baseline](phase8d_baseline.md) and cumulative resource measurements as work proceeds. The baseline records user-provided evidence and sign-off; this does not imply completion of later browser-authentication acceptance checks.
Progress: **8D.08D.6 and M1 validated by user sign-off; 8D.7 implemented scope explicitly user-validated on 2026-09-07. Deferred parity restrictions remain; numeric reserves and M2 acceptance remain open. No new implementation is authorized.** Record incremental results in `docs/agent/current-state.md`, retaining the [baseline](phase8d_baseline.md) and cumulative resource measurements as work proceeds.
Suggested next request:
> Continue the explicitly authorized next bounded 8D.7 credential/account slice. Preserve unsupported restrictions until safe owner handling exists, UART0-only bootstrap/recovery, secret-safe one-time credential policy and existing resource bounds. Use the second-certificate-slice handoff; do not treat continuation as target sign-off. Other owner slices and the full target/browser M2 acceptance checkpoint remain before settings.
> Wait for a separate implementation request. Preserve the 8D.7 implemented-scope sign-off, deferred parity restrictions, UART0-only bootstrap/recovery and existing resource bounds. Do not infer M2 acceptance, numeric reserve approval or authorization for settings or another owner slice.
For later chunks: