Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,9 @@ jobs:
- run: python -m ruff format --check src tools/check_distribution.py tools/check_tribe_provenance.py tools/generate_dm021_vectors.py tools/generate_dm022_vectors.py tools/generate_dm030_vectors.py tools/generate_dm031_vectors.py tools/generate_dm032_vectors.py tools/generate_dm033_vectors.py tools/generate_dm034_vectors.py tools/generate_dm035_vectors.py tools/generate_dm040_vectors.py tools/generate_dm041_vectors.py tools/generate_dm061_vectors.py tools/generate_dm079_vectors.py tools/generate_dm081_vectors.py tools/reproducible_build.py tools/scan_secrets.py tests/test_package_scaffold.py tests/test_dm021_identity.py tests/test_dm021_keystore.py tests/test_dm021_process.py tests/test_dm021_vectors.py tests/test_dm022_ledger.py tests/test_dm023_sync.py tests/test_dm024_service.py tests/test_dm024_runtime.py tests/test_dm025_client.py tests/test_dm025_cli_mcp.py tests/test_dm026_conformance.py tests/test_dm030_memory_policy.py tests/test_dm031_curator.py tests/test_dm032_curator_worker.py tests/test_dm033_human_review.py tests/test_dm034_memory_projection.py tests/test_dm035_publication.py tests/test_dm037_cluster_effects.py tests/test_dm040_codex_body.py tests/test_dm041_hermes_body.py tests/test_dm050_tribe_provenance.py tests/test_dm051_sealed.py tests/test_dm052_communication.py tests/test_dm053_routes.py tests/test_dm054_scopes.py tests/test_dm055_peer_transport.py tests/test_dm060_synthetic_birth.py tests/test_dm061_species.py tests/test_dm079_authority_epochs.py tests/test_dm081_sources.py tests/test_dm083_dogfood.py
- run: python -m ruff check src tools/check_distribution.py tools/check_tribe_provenance.py tools/generate_dm021_vectors.py tools/generate_dm022_vectors.py tools/generate_dm030_vectors.py tools/generate_dm031_vectors.py tools/generate_dm032_vectors.py tools/generate_dm033_vectors.py tools/generate_dm034_vectors.py tools/generate_dm035_vectors.py tools/generate_dm040_vectors.py tools/generate_dm041_vectors.py tools/generate_dm061_vectors.py tools/generate_dm079_vectors.py tools/generate_dm081_vectors.py tools/reproducible_build.py tools/scan_secrets.py tests/test_package_scaffold.py tests/test_dm021_identity.py tests/test_dm021_keystore.py tests/test_dm021_process.py tests/test_dm021_vectors.py tests/test_dm022_ledger.py tests/test_dm023_sync.py tests/test_dm024_service.py tests/test_dm024_runtime.py tests/test_dm025_client.py tests/test_dm025_cli_mcp.py tests/test_dm026_conformance.py tests/test_dm030_memory_policy.py tests/test_dm031_curator.py tests/test_dm032_curator_worker.py tests/test_dm033_human_review.py tests/test_dm034_memory_projection.py tests/test_dm035_publication.py tests/test_dm037_cluster_effects.py tests/test_dm040_codex_body.py tests/test_dm041_hermes_body.py tests/test_dm050_tribe_provenance.py tests/test_dm051_sealed.py tests/test_dm052_communication.py tests/test_dm053_routes.py tests/test_dm054_scopes.py tests/test_dm055_peer_transport.py tests/test_dm060_synthetic_birth.py tests/test_dm061_species.py tests/test_dm079_authority_epochs.py tests/test_dm081_sources.py tests/test_dm083_dogfood.py
- run: MYPYPATH=src python -m mypy src tools/check_distribution.py tools/check_tribe_provenance.py tools/generate_dm021_vectors.py tools/generate_dm022_vectors.py tools/generate_dm030_vectors.py tools/generate_dm031_vectors.py tools/generate_dm032_vectors.py tools/generate_dm033_vectors.py tools/generate_dm034_vectors.py tools/generate_dm035_vectors.py tools/generate_dm040_vectors.py tools/generate_dm041_vectors.py tools/generate_dm061_vectors.py tools/generate_dm079_vectors.py tools/generate_dm081_vectors.py tools/reproducible_build.py tools/scan_secrets.py tests/test_package_scaffold.py tests/test_dm021_identity.py tests/test_dm021_keystore.py tests/test_dm021_process.py tests/test_dm021_vectors.py tests/test_dm022_ledger.py tests/test_dm023_sync.py tests/test_dm024_service.py tests/test_dm024_runtime.py tests/test_dm025_client.py tests/test_dm025_cli_mcp.py tests/test_dm026_conformance.py tests/test_dm030_memory_policy.py tests/test_dm031_curator.py tests/test_dm032_curator_worker.py tests/test_dm033_human_review.py tests/test_dm034_memory_projection.py tests/test_dm035_publication.py tests/test_dm037_cluster_effects.py tests/test_dm040_codex_body.py tests/test_dm041_hermes_body.py tests/test_dm050_tribe_provenance.py tests/test_dm051_sealed.py tests/test_dm052_communication.py tests/test_dm053_routes.py tests/test_dm054_scopes.py tests/test_dm055_peer_transport.py tests/test_dm060_synthetic_birth.py tests/test_dm061_species.py tests/test_dm079_authority_epochs.py tests/test_dm081_sources.py tests/test_dm083_dogfood.py
- run: python -m ruff format --check tests/test_operator_first_embodiment.py
- run: python -m ruff check tests/test_operator_first_embodiment.py
- run: MYPYPATH=src python -m mypy tests/test_operator_first_embodiment.py
- run: python -m ruff format --check tools/build_cross_being_canary_preflight.py tests/test_cross_being_canary_preflight.py
- run: python -m ruff check tools/build_cross_being_canary_preflight.py tests/test_cross_being_canary_preflight.py
- run: MYPYPATH=src python -m mypy tools/build_cross_being_canary_preflight.py tests/test_cross_being_canary_preflight.py
Expand Down Expand Up @@ -167,6 +170,7 @@ jobs:
"${RUNNER_TEMP}/dm020-wheel/bin/python" -W error::ResourceWarning -m unittest tests.test_dm036_collective_memory.DM036ContractTests -q
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-matrixd" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-genesis" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-first-embodiment" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-rebirth" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-conformance" --help
Expand All @@ -177,6 +181,14 @@ jobs:
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-reviewer" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-synthetic-species" --help
"${RUNNER_TEMP}/dm020-wheel/bin/daimon-synthetic-sources" --help
dm087_fifo="${RUNNER_TEMP}/dm087-genesis.fifo"
mkfifo "${dm087_fifo}"
set +e
timeout 2 "${RUNNER_TEMP}/dm020-wheel/bin/daimon-first-embodiment" prepare --genesis "${dm087_fifo}" --profile README.md --password-fd 0 --output "${RUNNER_TEMP}/dm087-forbidden-output" </dev/null
dm087_status="$?"
set -e
test "${dm087_status}" -eq 2
test ! -e "${RUNNER_TEMP}/dm087-forbidden-output"
"${RUNNER_TEMP}/dm020-wheel/bin/python" -W error::ResourceWarning -m unittest tests.test_dm040_codex_body -q
"${RUNNER_TEMP}/dm020-wheel/bin/python" -W error::ResourceWarning -m unittest tests.test_dm041_hermes_body -q
"${RUNNER_TEMP}/dm020-wheel/bin/python" -W error::ResourceWarning -m unittest tests.test_dm042_local_we -q
Expand Down
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,8 @@ python tools/reproducible_build.py --output dist

The reproducible build and clean-wheel workflow are documented in
[docs/packaging.md](docs/packaging.md). Delivery order is in
[PLAN.md](PLAN.md) and [ROADMAP.md](ROADMAP.md).
[PLAN.md](PLAN.md) and [ROADMAP.md](ROADMAP.md). The production-shaped path from
distributed genesis through plural synchronized embodiments is documented in
[docs/runbooks/distributed-first-embodiment.md](docs/runbooks/distributed-first-embodiment.md).

Official repository: `AlterMundi/daimon-matrix`. License: MIT.
32 changes: 23 additions & 9 deletions docs/dm078-fresh-host-rebirth.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,11 @@ No process or artifact in this flow requires root seeds and embodiment private
keys together. Root custody cannot impersonate the embodiment acceptance or
transport proof; target custody cannot reach the root threshold.

The installed-module interface keeps that boundary executable even before a
dedicated console alias is published. `prepare` runs on the target and writes
only target custody; `authorize` runs at the offline root and receives only the
public request. Passwords use inherited descriptors and neither command accepts
private key bytes through arguments or environment:
The installed `daimon-rebirth` interface keeps that boundary executable.
`prepare` runs on the target and writes only target custody. Each
`enrollment-share` invocation opens exactly one holder package; the intent and
aggregation steps are keyless. Passwords use inherited descriptors and no
command accepts private key bytes through arguments or environment:

```bash
python -m daimon_matrix.operator_rebirth prepare \
Expand All @@ -51,12 +51,26 @@ python -m daimon_matrix.operator_rebirth prepare \
--output /target-owner/rebirth-preparation \
--password-fd 3 3</target-owner/password

python -m daimon_matrix.operator_rebirth authorize \
daimon-rebirth create-enrollment-intent \
--authority /public/current-authority.json \
--request /public/enrollment-request.json \
--root-custody /offline/root-custody.json \
--root-password-fd 3 \
--output /public/activation.json 3</offline/root-password
--output /public/enrollment-intent.json

daimon-rebirth enrollment-share \
--authority /public/current-authority.json \
--request /public/enrollment-request.json \
--intent /public/enrollment-intent.json \
--holder /offline/root-a \
--password-fd 3 \
--output /public/root-a.share.json 3</offline/root-a.password

daimon-rebirth aggregate-enrollment \
--authority /public/current-authority.json \
--request /public/enrollment-request.json \
--intent /public/enrollment-intent.json \
--share /public/root-a.share.json \
--share /public/root-b.share.json \
--output /public/activation.json

python -m daimon_matrix.operator_rebirth activate \
--base-runtime /public/current-runtime.json \
Expand Down
134 changes: 134 additions & 0 deletions docs/runbooks/distributed-first-embodiment.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,134 @@
# Distributed first embodiment and plural continuity

This is the operational path from a threshold-separated genesis to the first
runnable embodiment, then to additional embodiments. No process opens more than
one root holder package, and no target host receives a root seed.

The holder labels describe independent encrypted packages and process
invocations. They do not require different people. One operator may execute all
steps while preserving the cryptographic 2-of-3 separation, provided each
password and package remains separately controlled.

## First embodiment

Create the target profile as canonical JSON using schema
`dm.operator.rebirth-target-profile/v1`. For the first embodiment its `targets`
array is empty. The advertised endpoint must end in `/dm-peer/v1`.

```bash
daimon-first-embodiment prepare \
--genesis /public/genesis.json \
--profile /public/first-profile.json \
--password-fd 3 \
--output /target/first-preparation 3</target/first.password

daimon-first-embodiment root-share \
--genesis /public/genesis.json \
--request /target/first-preparation/request.json \
--holder /offline/root-a \
--password-fd 3 \
--output /public/first-root-a.share.json 3</offline/root-a.password

daimon-first-embodiment root-share \
--genesis /public/genesis.json \
--request /target/first-preparation/request.json \
--holder /offline/root-b \
--password-fd 3 \
--output /public/first-root-b.share.json 3</offline/root-b.password

daimon-first-embodiment aggregate \
--genesis /public/genesis.json \
--request /target/first-preparation/request.json \
--share /public/first-root-a.share.json \
--share /public/first-root-b.share.json \
--output /public/first-activation.json

daimon-first-embodiment activate \
--genesis /public/genesis.json \
--preparation-dir /target/first-preparation \
--request /target/first-preparation/request.json \
--activation /public/first-activation.json \
--password-fd 3 \
--output /target/first-package 3</target/first.password
```

The output contains a V7 runtime with manifest revision 1 and one active
embodiment. The target custody contains fresh embodiment, transport and
least-authority capability keys only. The root-share outputs and activation are
public canonical artifacts. The aggregator is keyless.

## Additional embodiment

Export the current public authority document from the running release. The new
target profile lists every current active embodiment and its configured
endpoint. Prepare the target, freeze the exact successor, collect one paired
share from each required root holder, then aggregate without keys:

```bash
daimon-rebirth prepare \
--authority /public/current-authority.json \
--profile /public/new-target-profile.json \
--output /target/new-preparation \
--password-fd 3 3</target/new.password

daimon-rebirth create-enrollment-intent \
--authority /public/current-authority.json \
--request /target/new-preparation/request.json \
--output /public/new-enrollment-intent.json

daimon-rebirth enrollment-share \
--authority /public/current-authority.json \
--request /target/new-preparation/request.json \
--intent /public/new-enrollment-intent.json \
--holder /offline/root-a \
--password-fd 3 \
--output /public/new-root-a.share.json 3</offline/root-a.password

daimon-rebirth enrollment-share \
--authority /public/current-authority.json \
--request /target/new-preparation/request.json \
--intent /public/new-enrollment-intent.json \
--holder /offline/root-b \
--password-fd 3 \
--output /public/new-root-b.share.json 3</offline/root-b.password

daimon-rebirth aggregate-enrollment \
--authority /public/current-authority.json \
--request /target/new-preparation/request.json \
--intent /public/new-enrollment-intent.json \
--share /public/new-root-a.share.json \
--share /public/new-root-b.share.json \
--output /public/new-activation.json

daimon-rebirth activate \
--base-runtime /public/current-runtime.json \
--preparation-dir /target/new-preparation \
--request /target/new-preparation/request.json \
--activation /public/new-activation.json \
--output /target/new-package \
--password-fd 3 3</target/new.password
```

Generate a forward-only candidate for each existing peer before an atomic,
quiesced deployment of that public file:

```bash
daimon-rebirth advance-bundle \
--authority /public/current-authority.json \
--base-runtime /existing/runtime.json \
--request /target/new-preparation/request.json \
--activation /public/new-activation.json \
--target-endpoint https://new-target.example/dm-peer/v1 \
--output /existing/runtime.next.json
```

`advance-bundle` does not modify the running runtime or its writable stores. It
verifies the request and activation, appends the signed authority epoch and
writes a new candidate only. Host orchestration must stop or quiesce the daemon,
atomically install the candidate and restart it; Cluster owns that transaction.

Historical events keep their original manifest hashes. The successor bundle
contains the prior manifest and signed transition in `authority_history`, so a
new empty embodiment can authenticate and ingest events created before it
existed. Peer pull is encrypted, replay-safe and additive; it never copies
another embodiment's private custody or adopts its local decisions.
Loading
Loading