From 7b78cf2739634cb340dbde05c5a5f6010cec468b Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 23 Jul 2026 04:37:22 -0700 Subject: [PATCH 1/4] test: add full core components test plan --- REUSE.toml | 23 + .../01-rpc-tappd/tc-gos-tappd-001/case.md | 62 + .../01-rpc-tappd/tc-gos-tappd-002/case.md | 62 + .../01-rpc-tappd/tc-gos-tappd-003/case.md | 62 + .../01-rpc-tappd/tc-gos-tappd-004/case.md | 62 + .../01-rpc-tappd/tc-gos-tappd-005/case.md | 62 + .../01-rpc-tappd/tc-gos-tappd-006/case.md | 62 + .../tc-gos-dstackguest-001/case.md | 62 + .../tc-gos-dstackguest-002/case.md | 62 + .../tc-gos-dstackguest-003/case.md | 62 + .../tc-gos-dstackguest-004/case.md | 62 + .../tc-gos-dstackguest-005/case.md | 62 + .../tc-gos-dstackguest-006/case.md | 62 + .../tc-gos-dstackguest-007/case.md | 62 + .../tc-gos-dstackguest-008/case.md | 62 + .../tc-gos-dstackguest-009/case.md | 62 + .../03-rpc-worker/tc-gos-worker-001/case.md | 62 + .../03-rpc-worker/tc-gos-worker-002/case.md | 62 + .../03-rpc-worker/tc-gos-worker-003/case.md | 62 + .../tc-gos-guestapi-001/case.md | 62 + .../tc-gos-guestapi-002/case.md | 62 + .../tc-gos-guestapi-003/case.md | 62 + .../tc-gos-guestapi-004/case.md | 62 + .../tc-gos-guestapi-005/case.md | 62 + .../tc-gos-proxiedguestapi-001/case.md | 62 + .../tc-gos-proxiedguestapi-002/case.md | 62 + .../tc-gos-proxiedguestapi-003/case.md | 62 + .../tc-gos-proxiedguestapi-004/case.md | 62 + .../tc-gos-proxiedguestapi-005/case.md | 62 + .../tc-gos-boot-and-i-001/case.md | 60 + .../tc-gos-boot-and-i-002/case.md | 60 + .../tc-gos-boot-and-i-003/case.md | 60 + .../tc-gos-boot-and-i-004/case.md | 60 + .../tc-gos-boot-and-i-005/case.md | 60 + .../tc-gos-compose-006/case.md | 60 + .../tc-gos-storage-an-001/case.md | 60 + .../tc-gos-storage-an-002/case.md | 60 + .../tc-gos-storage-an-003/case.md | 60 + .../tc-gos-storage-an-004/case.md | 62 + .../tc-gos-storage-an-005/case.md | 60 + .../tc-gos-attestatio-001/case.md | 60 + .../tc-gos-attestatio-002/case.md | 60 + .../tc-gos-attestatio-003/case.md | 60 + .../tc-gos-attestatio-004/case.md | 60 + .../tc-gos-attestatio-005/case.md | 60 + .../tc-gos-attestatio-006/case.md | 60 + .../tc-gos-gpupolicy-007/case.md | 60 + .../tc-gos-observabil-001/case.md | 60 + .../tc-gos-observabil-002/case.md | 60 + .../tc-gos-observabil-003/case.md | 60 + .../tc-gos-observabil-004/case.md | 60 + .../tc-gos-observabil-005/case.md | 60 + .../tc-gos-platform-001/case.md | 69 + .../tc-gos-platform-002/case.md | 69 + .../tc-gos-platform-003/case.md | 69 + .../tc-gos-platform-004/case.md | 69 + .../tc-gos-platform-005/case.md | 69 + .../tc-gos-platform-006/case.md | 69 + .../tc-gos-platform-007/case.md | 69 + .../tc-gos-platform-008/case.md | 69 + .../tc-gos-platform-009/case.md | 69 + .../tc-gos-platform-010/case.md | 69 + .../tc-gos-entry-001/case.md | 71 + .../tc-gos-entry-002/case.md | 69 + .../tc-gos-entry-003/case.md | 69 + .../tc-gos-entry-004/case.md | 69 + .../tc-gos-setup-001/case.md | 60 + .../tc-gos-setup-002/case.md | 60 + .../tc-gos-setup-003/case.md | 60 + .../tc-gos-setup-004/case.md | 60 + .../tc-gos-setup-005/case.md | 60 + .../tc-gos-setup-006/case.md | 60 + .../tc-gos-setup-007/case.md | 60 + .../tc-gos-setup-008/case.md | 60 + .../tc-gos-setup-009/case.md | 60 + .../tc-gos-setup-010/case.md | 60 + .../tc-gos-setup-011/case.md | 60 + .../tc-gos-setup-012/case.md | 62 + .../tc-gos-setup-013/case.md | 60 + .../tc-gos-setup-014/case.md | 60 + .../tc-gos-setup-015/case.md | 60 + .../tc-gos-setup-016/case.md | 60 + .../tc-gos-setup-017/case.md | 60 + .../tc-gos-setup-018/case.md | 60 + .../tc-gos-setup-019/case.md | 60 + .../tc-gos-setup-020/case.md | 60 + .../tc-gos-setup-021/case.md | 60 + .../tc-gos-setup-022/case.md | 60 + .../tc-gos-setup-023/case.md | 60 + .../tc-gos-setup-024/case.md | 60 + .../tc-gos-yocto-001/case.md | 60 + .../tc-gos-yocto-002/case.md | 60 + .../tc-gos-yocto-003/case.md | 60 + .../tc-gos-yocto-004/case.md | 60 + .../tc-gos-yocto-005/case.md | 60 + .../tc-gos-yocto-006/case.md | 60 + .../tc-gos-yocto-007/case.md | 60 + .../tc-gos-yocto-008/case.md | 60 + .../14-gos-build/tc-gos-build-001/case.md | 60 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md | 62 + .../02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md | 62 + .../02-rpc-hostapi/tc-vmm-hostapi-001/case.md | 62 + .../02-rpc-hostapi/tc-vmm-hostapi-002/case.md | 62 + .../02-rpc-hostapi/tc-vmm-hostapi-003/case.md | 62 + .../tc-vmm-configurat-001/case.md | 62 + .../tc-vmm-configurat-002/case.md | 60 + .../tc-vmm-configurat-003/case.md | 60 + .../tc-vmm-configurat-004/case.md | 60 + .../tc-vmm-tdxvariant-005/case.md | 60 + .../tc-vmm-vm-lifecyc-001/case.md | 60 + .../tc-vmm-vm-lifecyc-002/case.md | 60 + .../tc-vmm-vm-lifecyc-003/case.md | 60 + .../tc-vmm-vm-lifecyc-004/case.md | 60 + .../tc-vmm-vm-lifecyc-005/case.md | 60 + .../tc-vmm-vm-lifecyc-006/case.md | 60 + .../tc-vmm-compute-ne-001/case.md | 60 + .../tc-vmm-compute-ne-002/case.md | 60 + .../tc-vmm-compute-ne-003/case.md | 60 + .../tc-vmm-compute-ne-004/case.md | 60 + .../tc-vmm-compute-ne-005/case.md | 60 + .../tc-vmm-compute-ne-006/case.md | 60 + .../tc-vmm-compute-ne-007/case.md | 60 + .../tc-vmm-volume-008/case.md | 60 + .../tc-vmm-serial-006/case.md | 60 + .../tc-vmm-ui-observa-001/case.md | 60 + .../tc-vmm-ui-observa-002/case.md | 60 + .../tc-vmm-ui-observa-003/case.md | 60 + .../tc-vmm-ui-observa-004/case.md | 60 + .../tc-vmm-ui-observa-005/case.md | 60 + .../tc-vmm-manifest-001/case.md | 69 + .../tc-vmm-manifest-002/case.md | 69 + .../tc-vmm-internal-001/case.md | 69 + .../tc-vmm-internal-002/case.md | 69 + .../tc-vmm-internal-003/case.md | 69 + .../tc-vmm-internal-004/case.md | 69 + .../tc-vmm-internal-005/case.md | 69 + .../tc-vmm-internal-006/case.md | 69 + .../tc-vmm-internal-007/case.md | 69 + .../tc-vmm-internal-008/case.md | 69 + .../09-vmm-build/tc-vmm-build-001/case.md | 60 + .../03-kms/01-rpc-kms/tc-kms-kms-001/case.md | 62 + .../03-kms/01-rpc-kms/tc-kms-kms-002/case.md | 62 + .../03-kms/01-rpc-kms/tc-kms-kms-003/case.md | 62 + .../03-kms/01-rpc-kms/tc-kms-kms-004/case.md | 62 + .../03-kms/01-rpc-kms/tc-kms-kms-005/case.md | 62 + .../03-kms/01-rpc-kms/tc-kms-kms-006/case.md | 62 + .../02-rpc-admin/tc-kms-admin-001/case.md | 62 + .../03-rpc-onboard/tc-kms-onboard-001/case.md | 62 + .../03-rpc-onboard/tc-kms-onboard-002/case.md | 62 + .../03-rpc-onboard/tc-kms-onboard-003/case.md | 62 + .../03-rpc-onboard/tc-kms-onboard-004/case.md | 62 + .../tc-kms-bootstrap--001/case.md | 60 + .../tc-kms-bootstrap--002/case.md | 60 + .../tc-kms-bootstrap--003/case.md | 60 + .../tc-kms-bootstrap--004/case.md | 60 + .../tc-kms-attestatio-001/case.md | 60 + .../tc-kms-attestatio-002/case.md | 60 + .../tc-kms-attestatio-003/case.md | 60 + .../tc-kms-attestatio-004/case.md | 60 + .../tc-kms-attestatio-005/case.md | 62 + .../tc-kms-platform-006/case.md | 60 + .../tc-kms-apiver-011/case.md | 60 + .../tc-kms-keys-certs-001/case.md | 60 + .../tc-kms-keys-certs-002/case.md | 60 + .../tc-kms-keys-certs-003/case.md | 60 + .../tc-kms-keys-certs-004/case.md | 60 + .../tc-kms-keys-certs-005/case.md | 60 + .../tc-kms-keys-certs-006/case.md | 60 + .../tc-kms-keys-certs-007/case.md | 62 + .../tc-kms-keys-certs-008/case.md | 60 + .../tc-kms-keys-certs-009/case.md | 60 + .../tc-kms-release-010/case.md | 60 + .../tc-kms-auth-001/case.md | 69 + .../tc-kms-auth-002/case.md | 69 + .../tc-kms-auth-003/case.md | 69 + .../tc-kms-auth-004/case.md | 69 + .../tc-kms-auth-005/case.md | 69 + .../tc-kms-auth-006/case.md | 69 + .../tc-kms-auth-007/case.md | 69 + .../tc-kms-auth-008/case.md | 69 + .../tc-kms-auth-009/case.md | 69 + .../tc-kms-auth-010/case.md | 69 + .../tc-kms-upgrade-001/case.md | 71 + .../tc-kms-upgrade-002/case.md | 71 + .../tc-kms-upgrade-003/case.md | 71 + .../tc-kms-upgrade-004/case.md | 71 + .../tc-kms-upgrade-005/case.md | 71 + .../tc-kms-upgrade-006/case.md | 71 + .../tc-kms-upgrade-007/case.md | 71 + .../tc-kms-upgrade-008/case.md | 71 + .../tc-kms-upgrade-009/case.md | 71 + .../tc-kms-upgrade-010/case.md | 71 + .../tc-kms-upgrade-011/case.md | 71 + .../tc-kms-upgrade-012/case.md | 71 + .../tc-kms-ct-001/case.md | 69 + .../tc-kms-startup-001/case.md | 71 + .../tc-kms-runtime-001/case.md | 60 + .../tc-kms-runtime-002/case.md | 60 + .../tc-kms-runtime-003/case.md | 60 + .../tc-kms-runtime-004/case.md | 60 + .../tc-kms-runtime-005/case.md | 60 + .../12-kms-build/tc-kms-build-001/case.md | 60 + .../01-rpc-gateway/tc-gw-gateway-001/case.md | 62 + .../01-rpc-gateway/tc-gw-gateway-002/case.md | 62 + .../01-rpc-gateway/tc-gw-gateway-003/case.md | 62 + .../01-rpc-gateway/tc-gw-gateway-004/case.md | 62 + .../02-rpc-debug/tc-gw-debug-001/case.md | 62 + .../02-rpc-debug/tc-gw-debug-002/case.md | 62 + .../02-rpc-debug/tc-gw-debug-003/case.md | 62 + .../02-rpc-debug/tc-gw-debug-004/case.md | 62 + .../03-rpc-admin/tc-gw-admin-001/case.md | 62 + .../03-rpc-admin/tc-gw-admin-002/case.md | 62 + .../03-rpc-admin/tc-gw-admin-003/case.md | 62 + .../03-rpc-admin/tc-gw-admin-004/case.md | 62 + .../03-rpc-admin/tc-gw-admin-005/case.md | 62 + .../03-rpc-admin/tc-gw-admin-006/case.md | 62 + .../03-rpc-admin/tc-gw-admin-007/case.md | 62 + .../03-rpc-admin/tc-gw-admin-008/case.md | 62 + .../03-rpc-admin/tc-gw-admin-009/case.md | 62 + .../03-rpc-admin/tc-gw-admin-010/case.md | 62 + .../03-rpc-admin/tc-gw-admin-011/case.md | 62 + .../03-rpc-admin/tc-gw-admin-012/case.md | 62 + .../03-rpc-admin/tc-gw-admin-013/case.md | 62 + .../03-rpc-admin/tc-gw-admin-014/case.md | 62 + .../03-rpc-admin/tc-gw-admin-015/case.md | 62 + .../03-rpc-admin/tc-gw-admin-016/case.md | 62 + .../03-rpc-admin/tc-gw-admin-017/case.md | 62 + .../03-rpc-admin/tc-gw-admin-018/case.md | 62 + .../03-rpc-admin/tc-gw-admin-019/case.md | 62 + .../03-rpc-admin/tc-gw-admin-020/case.md | 62 + .../03-rpc-admin/tc-gw-admin-021/case.md | 62 + .../03-rpc-admin/tc-gw-admin-022/case.md | 62 + .../03-rpc-admin/tc-gw-admin-023/case.md | 62 + .../03-rpc-admin/tc-gw-admin-024/case.md | 62 + .../03-rpc-admin/tc-gw-admin-025/case.md | 62 + .../03-rpc-admin/tc-gw-admin-026/case.md | 62 + .../03-rpc-admin/tc-gw-admin-027/case.md | 62 + .../03-rpc-admin/tc-gw-admin-028/case.md | 62 + .../03-rpc-admin/tc-gw-admin-029/case.md | 62 + .../03-rpc-admin/tc-gw-admin-030/case.md | 62 + .../03-rpc-admin/tc-gw-admin-031/case.md | 62 + .../03-rpc-admin/tc-gw-admin-032/case.md | 62 + .../03-rpc-admin/tc-gw-admin-033/case.md | 62 + .../tc-gw-registrati-001/case.md | 60 + .../tc-gw-registrati-002/case.md | 60 + .../tc-gw-registrati-003/case.md | 60 + .../tc-gw-registrati-004/case.md | 60 + .../tc-gw-proxy-prot-001/case.md | 60 + .../tc-gw-proxy-prot-002/case.md | 60 + .../tc-gw-proxy-prot-003/case.md | 60 + .../tc-gw-proxy-prot-004/case.md | 60 + .../tc-gw-proxy-prot-005/case.md | 60 + .../tc-gw-proxy-prot-006/case.md | 60 + .../tc-gw-select-007/case.md | 60 + .../tc-gw-certificat-001/case.md | 60 + .../tc-gw-certificat-002/case.md | 60 + .../tc-gw-certificat-003/case.md | 60 + .../tc-gw-certificat-004/case.md | 60 + .../tc-gw-certificat-005/case.md | 60 + .../tc-gw-certificat-006/case.md | 60 + .../tc-gw-certificat-007/case.md | 60 + .../tc-gw-cluster-ad-001/case.md | 60 + .../tc-gw-cluster-ad-002/case.md | 60 + .../tc-gw-cluster-ad-003/case.md | 60 + .../tc-gw-cluster-ad-004/case.md | 60 + .../tc-gw-cluster-ad-005/case.md | 62 + .../tc-gw-cluster-ad-006/case.md | 60 + .../tc-gw-cluster-ad-007/case.md | 60 + .../tc-gw-cluster-ad-008/case.md | 62 + .../tc-gw-kv-009/case.md | 60 + .../tc-gw-internal-001/case.md | 71 + .../tc-gw-internal-002/case.md | 69 + .../tc-gw-internal-003/case.md | 69 + .../tc-gw-internal-004/case.md | 69 + .../tc-gw-internal-005/case.md | 69 + .../tc-gw-internal-006/case.md | 69 + .../tc-gw-internal-007/case.md | 69 + .../tc-gw-internal-008/case.md | 69 + .../tc-gw-certbot-001/case.md | 60 + .../tc-gw-certbot-002/case.md | 60 + .../tc-gw-certbot-003/case.md | 60 + .../tc-gw-certbot-004/case.md | 60 + .../tc-gw-certbot-005/case.md | 60 + .../tc-gw-certbot-006/case.md | 60 + .../10-gw-build/tc-gw-build-001/case.md | 60 + .../tc-ver-input-plat-001/case.md | 60 + .../tc-ver-input-plat-002/case.md | 60 + .../tc-ver-input-plat-003/case.md | 60 + .../tc-ver-input-plat-004/case.md | 60 + .../tc-ver-input-plat-005/case.md | 60 + .../tc-ver-input-plat-006/case.md | 60 + .../tc-ver-input-plat-007/case.md | 60 + .../tc-ver-nitro-008/case.md | 60 + .../tc-ver-image-meas-001/case.md | 60 + .../tc-ver-image-meas-002/case.md | 60 + .../tc-ver-image-meas-003/case.md | 60 + .../tc-ver-image-meas-004/case.md | 60 + .../tc-ver-image-meas-005/case.md | 60 + .../tc-ver-strategy-006/case.md | 60 + .../tc-ver-cli-cert-o-001/case.md | 60 + .../tc-ver-cli-cert-o-002/case.md | 60 + .../tc-ver-cli-cert-o-003/case.md | 60 + .../tc-ver-cli-cert-o-004/case.md | 60 + .../tc-ver-cli-cert-o-005/case.md | 60 + .../tc-ver-cli-cert-o-006/case.md | 60 + .../03-cli-cert-output/tc-ver-tcb-007/case.md | 60 + .../tc-ver-tools-001/case.md | 69 + .../tc-ver-tools-002/case.md | 69 + .../tc-ver-tools-003/case.md | 69 + .../tc-ver-tools-004/case.md | 69 + .../tc-ver-tools-005/case.md | 69 + .../tc-ver-tools-006/case.md | 69 + .../tc-ver-build-001/case.md | 60 + .../tc-ver-build-002/case.md | 62 + .../tc-ver-buildall-001/case.md | 60 + .../tc-int-end-to-end-001/case.md | 60 + .../tc-int-end-to-end-002/case.md | 60 + .../tc-int-end-to-end-003/case.md | 60 + .../tc-int-end-to-end-004/case.md | 60 + .../tc-int-end-to-end-005/case.md | 60 + .../tc-int-compatibil-001/case.md | 60 + .../tc-int-compatibil-002/case.md | 60 + .../tc-int-compatibil-003/case.md | 60 + .../tc-int-compatibil-004/case.md | 60 + .../tc-int-compatibil-005/case.md | 60 + .../tc-int-compatibil-006/case.md | 60 + .../tc-int-failure-se-001/case.md | 60 + .../tc-int-failure-se-002/case.md | 60 + .../tc-int-failure-se-003/case.md | 60 + .../tc-int-failure-se-004/case.md | 60 + .../tc-int-failure-se-005/case.md | 60 + .../tc-int-failure-se-006/case.md | 60 + .../tc-int-failure-se-007/case.md | 60 + .../tc-int-failure-se-008/case.md | 60 + .../tc-int-mixed-001/case.md | 71 + .../tc-int-mixed-002/case.md | 71 + .../tc-int-mixed-003/case.md | 71 + .../tc-int-mixed-004/case.md | 71 + .../tc-int-mixed-005/case.md | 71 + .../tc-int-mixed-006/case.md | 71 + .../tc-int-mixed-007/case.md | 71 + .../test-plans/core-components-full/README.md | 167 + .../core-components-full/api-inventory.json | 9256 +++++++++++++++++ .../configuration-inventory.json | 350 + .../core-components-full/feature-audit.md | 716 ++ .../core-components-full/index.json | 8086 ++++++++++++++ .../source-coverage-map.json | 7747 ++++++++++++++ .../source-inventory.json | 6520 ++++++++++++ tools/dstack-test/web.py | 5 + 370 files changed, 55423 insertions(+) create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-007/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-008/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-009/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-010/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md create mode 100644 docs/test-plans/core-components-full/01-guest-os/14-gos-build/tc-gos-build-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md create mode 100644 docs/test-plans/core-components-full/02-vmm/09-vmm-build/tc-vmm-build-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-006/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/02-rpc-admin/tc-kms-admin-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-platform-006/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-release-010/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-006/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-007/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-008/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-009/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-010/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/10-service-startup/tc-kms-startup-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md create mode 100644 docs/test-plans/core-components-full/03-kms/12-kms-build/tc-kms-build-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-007/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-008/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-009/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-010/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-011/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-012/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-013/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-014/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-015/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-016/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-017/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-018/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-019/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-020/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-021/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-022/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-023/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-024/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-025/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-026/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-027/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-028/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-029/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-030/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-031/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-032/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-033/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md create mode 100644 docs/test-plans/core-components-full/04-gateway/10-gw-build/tc-gw-build-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-strategy-006/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-002/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-003/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-004/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-005/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-006/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-001/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-002/case.md create mode 100644 docs/test-plans/core-components-full/05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-001/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-002/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-003/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-004/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-005/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-001/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-002/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-003/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-004/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-005/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-006/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-007/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-008/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md create mode 100644 docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md create mode 100644 docs/test-plans/core-components-full/README.md create mode 100644 docs/test-plans/core-components-full/api-inventory.json create mode 100644 docs/test-plans/core-components-full/configuration-inventory.json create mode 100644 docs/test-plans/core-components-full/feature-audit.md create mode 100644 docs/test-plans/core-components-full/index.json create mode 100644 docs/test-plans/core-components-full/source-coverage-map.json create mode 100644 docs/test-plans/core-components-full/source-inventory.json diff --git a/REUSE.toml b/REUSE.toml index 240cc30da..e7281ac38 100644 --- a/REUSE.toml +++ b/REUSE.toml @@ -246,3 +246,26 @@ path = [ ] SPDX-FileCopyrightText = "NONE" SPDX-License-Identifier = "CC0-1.0" + +[[annotations]] +path = [ + "docs/test-plans/core-components-full/index.json", + "docs/test-plans/core-components-full/source-inventory.json", +] +SPDX-FileCopyrightText = "© 2026 Phala Network " +SPDX-License-Identifier = "Apache-2.0" + +[[annotations]] +path = "docs/test-plans/core-components-full/configuration-inventory.json" +SPDX-FileCopyrightText = "© 2026 Phala Network " +SPDX-License-Identifier = "Apache-2.0" + +[[annotations]] +path = "docs/test-plans/core-components-full/api-inventory.json" +SPDX-FileCopyrightText = "© 2026 Phala Network " +SPDX-License-Identifier = "Apache-2.0" + +[[annotations]] +path = "docs/test-plans/core-components-full/source-coverage-map.json" +SPDX-FileCopyrightText = "© 2026 Phala Network " +SPDX-License-Identifier = "Apache-2.0" diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md new file mode 100644 index 000000000..553a7ebd9 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-001: Tappd.DeriveKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-001](../../../feature-audit.md#req-gos-tappd-001) +- Risks: [risk-gos-tappd-001](../../../feature-audit.md#risk-gos-tappd-001) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:15` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.DeriveKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.DeriveKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.derivekey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.DeriveKey` with a valid `DeriveKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetTlsKeyResponse` with every documented field and exhibits the documented `DeriveKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md new file mode 100644 index 000000000..d0a2fa71a --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-002: Tappd.DeriveK256Key + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-002](../../../feature-audit.md#req-gos-tappd-002) +- Risks: [risk-gos-tappd-002](../../../feature-audit.md#risk-gos-tappd-002) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:18` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.DeriveK256Key`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.DeriveK256Key` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.derivek256key. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.DeriveK256Key` with a valid `GetKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DeriveK256KeyResponse` with every documented field and exhibits the documented `DeriveK256Key` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md new file mode 100644 index 000000000..93f4e126e --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-003: Tappd.TdxQuote + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-003](../../../feature-audit.md#req-gos-tappd-003) +- Risks: [risk-gos-tappd-003](../../../feature-audit.md#risk-gos-tappd-003) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:21` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.TdxQuote`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.TdxQuote` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.tdxquote. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.TdxQuote` with a valid `TdxQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `TdxQuoteResponse` with every documented field and exhibits the documented `TdxQuote` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md new file mode 100644 index 000000000..fd46b4fd5 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-004: Tappd.RawQuote + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-004](../../../feature-audit.md#req-gos-tappd-004) +- Risks: [risk-gos-tappd-004](../../../feature-audit.md#risk-gos-tappd-004) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:28` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.RawQuote`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.RawQuote` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.rawquote. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.RawQuote` with a valid `RawQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `TdxQuoteResponse` with every documented field and exhibits the documented `RawQuote` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md new file mode 100644 index 000000000..38277ecad --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-005: Tappd.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-005](../../../feature-audit.md#req-gos-tappd-005) +- Risks: [risk-gos-tappd-005](../../../feature-audit.md#risk-gos-tappd-005) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:31` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AppInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md new file mode 100644 index 000000000..609bd8614 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-TAPPD-006: Tappd.Version + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-tappd-006](../../../feature-audit.md#req-gos-tappd-006) +- Risks: [risk-gos-tappd-006](../../../feature-audit.md#risk-gos-tappd-006) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:34` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Tappd.Version`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Tappd.Version` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tappd.version. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Tappd.Version` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `WorkerVersion` with every documented field and exhibits the documented `Version` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md new file mode 100644 index 000000000..7ca09436d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-001: DstackGuest.GetTlsKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-001](../../../feature-audit.md#req-gos-dstackguest-001) +- Risks: [risk-gos-dstackguest-001](../../../feature-audit.md#risk-gos-dstackguest-001) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:41` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.GetTlsKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.GetTlsKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.gettlskey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.GetTlsKey` with a valid `GetTlsKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetTlsKeyResponse` with every documented field and exhibits the documented `GetTlsKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md new file mode 100644 index 000000000..4757488ed --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-002: DstackGuest.GetKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-002](../../../feature-audit.md#req-gos-dstackguest-002) +- Risks: [risk-gos-dstackguest-002](../../../feature-audit.md#risk-gos-dstackguest-002) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:44` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.GetKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.GetKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.getkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.GetKey` with a valid `GetKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetKeyResponse` with every documented field and exhibits the documented `GetKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md new file mode 100644 index 000000000..2a087ed7c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-003: DstackGuest.GetQuote + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-003](../../../feature-audit.md#req-gos-dstackguest-003) +- Risks: [risk-gos-dstackguest-003](../../../feature-audit.md#risk-gos-dstackguest-003) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:47` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.GetQuote`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.GetQuote` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.getquote. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.GetQuote` with a valid `RawQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetQuoteResponse` with every documented field and exhibits the documented `GetQuote` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md new file mode 100644 index 000000000..23bcdc3bf --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-004: DstackGuest.Attest + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-004](../../../feature-audit.md#req-gos-dstackguest-004) +- Risks: [risk-gos-dstackguest-004](../../../feature-audit.md#risk-gos-dstackguest-004) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:51` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.Attest`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.Attest` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.attest. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.Attest` with a valid `RawQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AttestResponse` with every documented field and exhibits the documented `Attest` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md new file mode 100644 index 000000000..8f89522b4 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-005: DstackGuest.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-005](../../../feature-audit.md#req-gos-dstackguest-005) +- Risks: [risk-gos-dstackguest-005](../../../feature-audit.md#risk-gos-dstackguest-005) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:54` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AppInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md new file mode 100644 index 000000000..ebeccbf8c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-006: DstackGuest.GpuInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-006](../../../feature-audit.md#req-gos-dstackguest-006) +- Risks: [risk-gos-dstackguest-006](../../../feature-audit.md#risk-gos-dstackguest-006) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:57` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.GpuInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.GpuInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.gpuinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.GpuInfo` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GpuInfoResponse` with every documented field and exhibits the documented `GpuInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md new file mode 100644 index 000000000..2a399b95f --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-007: DstackGuest.Sign + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-007](../../../feature-audit.md#req-gos-dstackguest-007) +- Risks: [risk-gos-dstackguest-007](../../../feature-audit.md#risk-gos-dstackguest-007) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:60` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.Sign`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.Sign` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.sign. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.Sign` with a valid `SignRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `SignResponse` with every documented field and exhibits the documented `Sign` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md new file mode 100644 index 000000000..a8136f115 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-008: DstackGuest.Verify + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-008](../../../feature-audit.md#req-gos-dstackguest-008) +- Risks: [risk-gos-dstackguest-008](../../../feature-audit.md#risk-gos-dstackguest-008) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:63` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.Verify`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.Verify` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.verify. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.Verify` with a valid `VerifyRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `VerifyResponse` with every documented field and exhibits the documented `Verify` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md new file mode 100644 index 000000000..ee7cbc38b --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-DSTACKGUEST-009: DstackGuest.Version + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-dstackguest-009](../../../feature-audit.md#req-gos-dstackguest-009) +- Risks: [risk-gos-dstackguest-009](../../../feature-audit.md#risk-gos-dstackguest-009) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:66` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `DstackGuest.Version`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `DstackGuest.Version` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dstackguest.version. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `DstackGuest.Version` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `WorkerVersion` with every documented field and exhibits the documented `Version` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md new file mode 100644 index 000000000..b42ebae23 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-WORKER-001: Worker.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-worker-001](../../../feature-audit.md#req-gos-worker-001) +- Risks: [risk-gos-worker-001](../../../feature-audit.md#risk-gos-worker-001) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:255` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Worker.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Worker.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for worker.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Worker.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AppInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md new file mode 100644 index 000000000..3ceeffe0a --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-WORKER-002: Worker.Version + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-worker-002](../../../feature-audit.md#req-gos-worker-002) +- Risks: [risk-gos-worker-002](../../../feature-audit.md#risk-gos-worker-002) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:257` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Worker.Version`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Worker.Version` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for worker.version. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Worker.Version` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `WorkerVersion` with every documented field and exhibits the documented `Version` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md new file mode 100644 index 000000000..61e0b6761 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-WORKER-003: Worker.GetAttestationForAppKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-worker-003](../../../feature-audit.md#req-gos-worker-003) +- Risks: [risk-gos-worker-003](../../../feature-audit.md#risk-gos-worker-003) +- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:259` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Worker.GetAttestationForAppKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Worker.GetAttestationForAppKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for worker.getattestationforappkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Worker.GetAttestationForAppKey` with a valid `GetAttestationForAppKeyRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetQuoteResponse` with every documented field and exhibits the documented `GetAttestationForAppKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md new file mode 100644 index 000000000..f36c0e4f5 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-GUESTAPI-001: GuestApi.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-guestapi-001](../../../feature-audit.md#req-gos-guestapi-001) +- Risks: [risk-gos-guestapi-001](../../../feature-audit.md#risk-gos-guestapi-001) +- Source: `dstack/guest-api/proto/guest_api.proto:135` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `GuestApi.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `GuestApi.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guestapi.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `GuestApi.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GuestInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md new file mode 100644 index 000000000..c3f5781f8 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-GUESTAPI-002: GuestApi.SysInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-guestapi-002](../../../feature-audit.md#req-gos-guestapi-002) +- Risks: [risk-gos-guestapi-002](../../../feature-audit.md#risk-gos-guestapi-002) +- Source: `dstack/guest-api/proto/guest_api.proto:137` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `GuestApi.SysInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `GuestApi.SysInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guestapi.sysinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `GuestApi.SysInfo` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `SystemInfo` with every documented field and exhibits the documented `SysInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md new file mode 100644 index 000000000..b33d111a5 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-GUESTAPI-003: GuestApi.NetworkInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-guestapi-003](../../../feature-audit.md#req-gos-guestapi-003) +- Risks: [risk-gos-guestapi-003](../../../feature-audit.md#risk-gos-guestapi-003) +- Source: `dstack/guest-api/proto/guest_api.proto:139` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `GuestApi.NetworkInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `GuestApi.NetworkInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guestapi.networkinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `GuestApi.NetworkInfo` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `NetworkInformation` with every documented field and exhibits the documented `NetworkInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md new file mode 100644 index 000000000..c9888aae6 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-GUESTAPI-004: GuestApi.ListContainers + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-guestapi-004](../../../feature-audit.md#req-gos-guestapi-004) +- Risks: [risk-gos-guestapi-004](../../../feature-audit.md#risk-gos-guestapi-004) +- Source: `dstack/guest-api/proto/guest_api.proto:141` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `GuestApi.ListContainers`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `GuestApi.ListContainers` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guestapi.listcontainers. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `GuestApi.ListContainers` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListContainersResponse` with every documented field and exhibits the documented `ListContainers` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md new file mode 100644 index 000000000..bdc3f2701 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-GUESTAPI-005: GuestApi.Shutdown + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-guestapi-005](../../../feature-audit.md#req-gos-guestapi-005) +- Risks: [risk-gos-guestapi-005](../../../feature-audit.md#risk-gos-guestapi-005) +- Source: `dstack/guest-api/proto/guest_api.proto:143` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `GuestApi.Shutdown`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `GuestApi.Shutdown` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guestapi.shutdown. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `GuestApi.Shutdown` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `Shutdown` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md new file mode 100644 index 000000000..a8d61a103 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-PROXIEDGUESTAPI-001: ProxiedGuestApi.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-proxiedguestapi-001](../../../feature-audit.md#req-gos-proxiedguestapi-001) +- Risks: [risk-gos-proxiedguestapi-001](../../../feature-audit.md#risk-gos-proxiedguestapi-001) +- Source: `dstack/guest-api/proto/guest_api.proto:148` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `ProxiedGuestApi.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `ProxiedGuestApi.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for proxiedguestapi.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `ProxiedGuestApi.Info` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GuestInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md new file mode 100644 index 000000000..17b43af21 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-PROXIEDGUESTAPI-002: ProxiedGuestApi.SysInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-proxiedguestapi-002](../../../feature-audit.md#req-gos-proxiedguestapi-002) +- Risks: [risk-gos-proxiedguestapi-002](../../../feature-audit.md#risk-gos-proxiedguestapi-002) +- Source: `dstack/guest-api/proto/guest_api.proto:149` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `ProxiedGuestApi.SysInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `ProxiedGuestApi.SysInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for proxiedguestapi.sysinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `ProxiedGuestApi.SysInfo` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `SystemInfo` with every documented field and exhibits the documented `SysInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md new file mode 100644 index 000000000..ce52571fd --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-PROXIEDGUESTAPI-003: ProxiedGuestApi.NetworkInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-proxiedguestapi-003](../../../feature-audit.md#req-gos-proxiedguestapi-003) +- Risks: [risk-gos-proxiedguestapi-003](../../../feature-audit.md#risk-gos-proxiedguestapi-003) +- Source: `dstack/guest-api/proto/guest_api.proto:150` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `ProxiedGuestApi.NetworkInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `ProxiedGuestApi.NetworkInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for proxiedguestapi.networkinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `ProxiedGuestApi.NetworkInfo` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `NetworkInformation` with every documented field and exhibits the documented `NetworkInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md new file mode 100644 index 000000000..eccf64bb7 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-PROXIEDGUESTAPI-004: ProxiedGuestApi.ListContainers + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-proxiedguestapi-004](../../../feature-audit.md#req-gos-proxiedguestapi-004) +- Risks: [risk-gos-proxiedguestapi-004](../../../feature-audit.md#risk-gos-proxiedguestapi-004) +- Source: `dstack/guest-api/proto/guest_api.proto:151` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `ProxiedGuestApi.ListContainers`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `ProxiedGuestApi.ListContainers` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for proxiedguestapi.listcontainers. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `ProxiedGuestApi.ListContainers` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListContainersResponse` with every documented field and exhibits the documented `ListContainers` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md new file mode 100644 index 000000000..245062863 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-PROXIEDGUESTAPI-005: ProxiedGuestApi.Shutdown + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-proxiedguestapi-005](../../../feature-audit.md#req-gos-proxiedguestapi-005) +- Risks: [risk-gos-proxiedguestapi-005](../../../feature-audit.md#risk-gos-proxiedguestapi-005) +- Source: `dstack/guest-api/proto/guest_api.proto:152` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `ProxiedGuestApi.Shutdown`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `ProxiedGuestApi.Shutdown` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for proxiedguestapi.shutdown. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `ProxiedGuestApi.Shutdown` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `Shutdown` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md new file mode 100644 index 000000000..bb65dcb37 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BOOT-AND-I-001: Measured boot and prepare ordering + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-boot-and-i-001](../../../feature-audit.md#req-gos-boot-and-i-001) +- Risks: [risk-gos-boot-and-i-001](../../../feature-audit.md#risk-gos-boot-and-i-001) +- Source: `os/common/rootfs/dstack-prepare.service` + +## Objective + +Verify measured boot and prepare ordering across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for measured boot and prepare ordering. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot through systemd preparation and app-compose startup. + +**Expected results:** + +- Preparation completes once before Docker/app startup; identity, measurements, and configuration files exist before consumers start. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md new file mode 100644 index 000000000..ba1d9ddee --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BOOT-AND-I-002: No-TEE simulator early host share + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-boot-and-i-002](../../../feature-audit.md#req-gos-boot-and-i-002) +- Risks: [risk-gos-boot-and-i-002](../../../feature-audit.md#risk-gos-boot-and-i-002) +- Source: `docs/development-without-tee.md` + +## Objective + +Verify no-tee simulator early host share across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for no-tee simulator early host share. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot a development image with only the simulator host-share configuration present. + +**Expected results:** + +- The early read-only share is mounted before simulator startup, config is consumed, then unmounted without a reboot loop. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md new file mode 100644 index 000000000..424e151a3 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BOOT-AND-I-003: System and user configuration materialization + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-boot-and-i-003](../../../feature-audit.md#req-gos-boot-and-i-003) +- Risks: [risk-gos-boot-and-i-003](../../../feature-audit.md#risk-gos-boot-and-i-003) +- Source: `os/common/rootfs/dstack-prepare.sh` + +## Objective + +Verify system and user configuration materialization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for system and user configuration materialization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Provide sys-config, user-config, compose, encrypted environment, and optional simulator config. + +**Expected results:** + +- Each file is copied to its documented location with restrictive ownership; missing optional files do not corrupt required state. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md new file mode 100644 index 000000000..aee39a7ae --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BOOT-AND-I-004: Stable app, instance, device, and compose identity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-boot-and-i-004](../../../feature-audit.md#req-gos-boot-and-i-004) +- Risks: [risk-gos-boot-and-i-004](../../../feature-audit.md#risk-gos-boot-and-i-004) +- Source: `dstack/guest-agent/src/backend.rs` + +## Objective + +Verify stable app, instance, device, and compose identity across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for stable app, instance, device, and compose identity. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot identical and changed compose/image/instance combinations. + +**Expected results:** + +- Stable inputs reproduce their identifiers; changing each bound input changes only the identifiers and measurements defined by the identity model. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md new file mode 100644 index 000000000..19b7a6d73 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BOOT-AND-I-005: Host notification boot and shutdown events + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-boot-and-i-005](../../../feature-audit.md#req-gos-boot-and-i-005) +- Risks: [risk-gos-boot-and-i-005](../../../feature-audit.md#risk-gos-boot-and-i-005) +- Source: `dstack/guest-agent/src/guest_api_service.rs` + +## Objective + +Verify host notification boot and shutdown events across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for host notification boot and shutdown events. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Complete boot and graceful shutdown while recording HostApi.Notify. + +**Expected results:** + +- Ordered progress events contain valid timestamps and payloads and terminal shutdown is reported once. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md new file mode 100644 index 000000000..9ade61d7e --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-COMPOSE-006: App manifest version feature and launch-requirement policy + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-compose-006](../../../feature-audit.md#req-gos-compose-006) +- Risks: [risk-gos-compose-006](../../../feature-audit.md#risk-gos-compose-006) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify app manifest version feature and launch-requirement policy using the complete source-defined decision matrix and independently observable output. + +## Preconditions + +1. Record candidate and pinned historical image/compose/config versions plus baseline identity, measurements, processes, files and public status. +2. Use isolated run-scoped inputs and retain native redacted output. + +## Test Data + +Build a table with one row for every condition named in Step 1, including each condition alone and security-relevant conflicting combinations. + +## Steps + + +### Step 1: Execute the full decision matrix + +Exercise manifest versions and maximum supported version; OS semver ranges; platform list omitted/empty/matching/mismatching/invalid; `tdx_measure_acpi_tables`; launch-token hash/user token; runner/snapshotter compatibility; empty and unknown requirements. + +**Expected results:** + +- V1/V2/V3 gates match documented feature introduction, OS/platform/ACPI/token requirements fail closed exactly, runner/snapshotter combinations are enforced, and accepted policy is measured into app identity as defined. + + +### Step 2: Verify the selected state end to end + +Compare parser/validation output, persisted manifest/config, generated measurement inputs, launch arguments, guest-visible state and public status for every accepted row. + +**Expected results:** + +- Every representation agrees with the selected row, no rejected value is partially persisted or launched, and unrelated inputs do not change measured identity. + + +### Step 3: Verify failure recovery and version compatibility + +Restart after accepted/rejected rows, replay applicable v0.5.4/v0.5.8/v0.5.11 inputs, and retry after correcting one invalid field. + +**Expected results:** + +- Supported historical defaults remain stable, unsupported combinations fail before secret/device consumption, restart reconstructs the same decision and corrected retry succeeds without stale state. + +## Postconditions + +Remove run-scoped VMs/files/devices and verify baseline restoration. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md new file mode 100644 index 000000000..1b33badb0 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-STORAGE-AN-001: Encrypted root/data volume provisioning + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-storage-an-001](../../../feature-audit.md#req-gos-storage-an-001) +- Risks: [risk-gos-storage-an-001](../../../feature-audit.md#risk-gos-storage-an-001) +- Source: `os/common/rootfs/dstack-prepare.sh` + +## Objective + +Verify encrypted root/data volume provisioning across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for encrypted root/data volume provisioning. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Provision a fresh encrypted application disk and reboot with the same key. + +**Expected results:** + +- Filesystem is created and mounted without exposing the key; reboot unlocks existing data; a wrong key cannot mount it. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md new file mode 100644 index 000000000..bc1741728 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-STORAGE-AN-002: Ephemeral Docker storage lifecycle + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-storage-an-002](../../../feature-audit.md#req-gos-storage-an-002) +- Risks: [risk-gos-storage-an-002](../../../feature-audit.md#risk-gos-storage-an-002) +- Source: `os/common/rootfs/ephemeral-docker.sh` + +## Objective + +Verify ephemeral docker storage lifecycle across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for ephemeral docker storage lifecycle. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Start with ephemeral Docker enabled, create data, and reboot. + +**Expected results:** + +- Docker uses the ephemeral mount and transient data is absent after reboot while persistent application volumes follow policy. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md new file mode 100644 index 000000000..2a3c31b76 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-STORAGE-AN-003: Compose validation and startup + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-storage-an-003](../../../feature-audit.md#req-gos-storage-an-003) +- Risks: [risk-gos-storage-an-003](../../../feature-audit.md#risk-gos-storage-an-003) +- Source: `os/common/rootfs/app-compose.sh` + +## Objective + +Verify compose validation and startup across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for compose validation and startup. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Supply valid multi-service compose and malformed/unsupported compose inputs. + +**Expected results:** + +- Valid services start in dependency order; invalid compose fails with actionable diagnostics and no partial stale deployment. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md new file mode 100644 index 000000000..7660d3a0a --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-STORAGE-AN-004: Supervisor lifecycle and restart policy + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-storage-an-004](../../../feature-audit.md#req-gos-storage-an-004) +- Risks: [risk-gos-storage-an-004](../../../feature-audit.md#risk-gos-storage-an-004) +- Source: `dstack/supervisor/src` + +## Objective + +Verify supervisor lifecycle and restart policy across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `supervisor` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for supervisor lifecycle and restart policy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Crash, stop, and update a supervised application container. + +**Expected results:** + +- Restart limits, backoff, stop, log capture, and exit status match the compose policy without restarting unrelated services. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md new file mode 100644 index 000000000..17d4fdf70 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-STORAGE-AN-005: Volume encryption and persistence semantics + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-storage-an-005](../../../feature-audit.md#req-gos-storage-an-005) +- Risks: [risk-gos-storage-an-005](../../../feature-audit.md#risk-gos-storage-an-005) +- Source: `dstack/crates/dstack-volume` + +## Objective + +Verify volume encryption and persistence semantics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for volume encryption and persistence semantics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise dstack volume declarations across restart and instance replacement. + +**Expected results:** + +- Persistent and ephemeral volumes retain or discard data exactly as declared and cannot be read by another app identity. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md new file mode 100644 index 000000000..303da7c29 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-001: Quote report-data binding and hash algorithms + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-attestatio-001](../../../feature-audit.md#req-gos-attestatio-001) +- Risks: [risk-gos-attestatio-001](../../../feature-audit.md#risk-gos-attestatio-001) +- Source: `dstack/guest-agent/src/rpc_service.rs` + +## Objective + +Verify quote report-data binding and hash algorithms across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for quote report-data binding and hash algorithms. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request quotes with every documented hash, prefix, raw 64-byte data, boundary lengths, and unknown algorithms. + +**Expected results:** + +- Report data matches the documented prefix/hash transform; raw length is enforced and unsupported algorithms are rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md new file mode 100644 index 000000000..f0ad957ee --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-002: Cross-platform versioned attestation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-attestatio-002](../../../feature-audit.md#req-gos-attestatio-002) +- Risks: [risk-gos-attestatio-002](../../../feature-audit.md#risk-gos-attestatio-002) +- Source: `dstack/dstack-attest/src` + +## Objective + +Verify cross-platform versioned attestation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for cross-platform versioned attestation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request Attest on TDX, TDX-lite, SEV-SNP, GCP TDX, and Nitro TPM fixtures or hardware. + +**Expected results:** + +- The encoded variant, report-data binding, platform evidence, and vm_config are internally consistent for each platform. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md new file mode 100644 index 000000000..5a6867b7c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-003: Deterministic key derivation and purpose separation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-attestatio-003](../../../feature-audit.md#req-gos-attestatio-003) +- Risks: [risk-gos-attestatio-003](../../../feature-audit.md#risk-gos-attestatio-003) +- Source: `dstack/guest-agent/src/rpc_service.rs` + +## Objective + +Verify deterministic key derivation and purpose separation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for deterministic key derivation and purpose separation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Derive secp256k1 and Ed25519 keys across paths, purposes, apps, and repeated calls. + +**Expected results:** + +- Same identity/path/purpose is stable; different app, path, purpose, or algorithm is cryptographically separated; signature chains verify. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md new file mode 100644 index 000000000..c12979176 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-004: TLS key and certificate usage extensions + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-attestatio-004](../../../feature-audit.md#req-gos-attestatio-004) +- Risks: [risk-gos-attestatio-004](../../../feature-audit.md#risk-gos-attestatio-004) +- Source: `dstack/guest-agent/src/rpc_service.rs` + +## Objective + +Verify tls key and certificate usage extensions across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tls key and certificate usage extensions. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request TLS keys with SANs, RA-TLS, client/server usage, app info, and validity overrides. + +**Expected results:** + +- Key matches leaf cert; SAN, EKU, validity, quote/app-info extensions and CA chain match the request and policy. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md new file mode 100644 index 000000000..4d60e102f --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-005: Signing verification and negative inputs + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-attestatio-005](../../../feature-audit.md#req-gos-attestatio-005) +- Risks: [risk-gos-attestatio-005](../../../feature-audit.md#risk-gos-attestatio-005) +- Source: `dstack/guest-agent/src/rpc_service.rs` + +## Objective + +Verify signing verification and negative inputs across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for signing verification and negative inputs. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Sign and verify message/prehashed data with supported algorithms and altered keys/signatures. + +**Expected results:** + +- Valid signatures verify; altered inputs, wrong algorithm, and invalid prehash length fail without leaking private material. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md new file mode 100644 index 000000000..0f63e828f --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-ATTESTATIO-006: GPU boot attestation exposure + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-attestatio-006](../../../feature-audit.md#req-gos-attestatio-006) +- Risks: [risk-gos-attestatio-006](../../../feature-audit.md#risk-gos-attestatio-006) +- Source: `dstack/guest-agent/src/rpc_service.rs` + +## Objective + +Verify gpu boot attestation exposure across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gpu boot attestation exposure. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot with and without supported GPUs and query GpuInfo. + +**Expected results:** + +- Collected nvattest JSON is returned unchanged for GPUs; the no-GPU response is empty and does not fail guest startup. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md new file mode 100644 index 000000000..5033a54c1 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-GPUPOLICY-007: GPU attestation proxy nonce claim and Rego policy enforcement + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-gpupolicy-007](../../../feature-audit.md#req-gos-gpupolicy-007) +- Risks: [risk-gos-gpupolicy-007](../../../feature-audit.md#risk-gos-gpupolicy-007) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify gpu attestation proxy nonce claim and rego policy enforcement using the complete source-defined decision matrix and independently observable output. + +## Preconditions + +1. Record candidate and pinned historical image/compose/config versions plus baseline identity, measurements, processes, files and public status. +2. Use isolated run-scoped inputs and retain native redacted output. + +## Test Data + +Build a table with one row for every condition named in Step 1, including each condition alone and security-relevant conflicting combinations. + +## Steps + + +### Step 1: Execute the full decision matrix + +Exercise NVIDIA/non-NVIDIA inventory, OCSP/RIM proxy routing, fresh/replayed/wrong nonce, incomplete/multiple GPU claims, devtools and CC claims, basic policy opt-ins, custom Rego true/false/error/timeout and raw policy measurement. + +**Expected results:** + +- Every expected NVIDIA GPU supplies a fresh validated claim, proxy only reaches allowed evidence endpoints, basic/custom policy must explicitly pass within timeout, and complete raw evidence is measured without accepting missing/extra devices. + + +### Step 2: Verify the selected state end to end + +Compare parser/validation output, persisted manifest/config, generated measurement inputs, launch arguments, guest-visible state and public status for every accepted row. + +**Expected results:** + +- Every representation agrees with the selected row, no rejected value is partially persisted or launched, and unrelated inputs do not change measured identity. + + +### Step 3: Verify failure recovery and version compatibility + +Restart after accepted/rejected rows, replay applicable v0.5.4/v0.5.8/v0.5.11 inputs, and retry after correcting one invalid field. + +**Expected results:** + +- Supported historical defaults remain stable, unsupported combinations fail before secret/device consumption, restart reconstructs the same decision and corrected retry succeeds without stale state. + +## Postconditions + +Remove run-scoped VMs/files/devices and verify baseline restoration. diff --git a/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md new file mode 100644 index 000000000..04bc121a7 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-OBSERVABIL-001: Dashboard metrics and container log filtering + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-observabil-001](../../../feature-audit.md#req-gos-observabil-001) +- Risks: [risk-gos-observabil-001](../../../feature-audit.md#risk-gos-observabil-001) +- Source: `dstack/guest-agent/src/http_routes.rs` + +## Objective + +Verify dashboard metrics and container log filtering across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dashboard metrics and container log filtering. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Query dashboard, metrics, and logs with since/until/follow/tail/text/timestamps/bare/ANSI combinations. + +**Expected results:** + +- Metrics reflect live resources; log filtering and streaming boundaries are exact and container-name traversal is rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md new file mode 100644 index 000000000..0c6f11426 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-OBSERVABIL-002: Socket activation and listener isolation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-observabil-002](../../../feature-audit.md#req-gos-observabil-002) +- Risks: [risk-gos-observabil-002](../../../feature-audit.md#risk-gos-observabil-002) +- Source: `dstack/guest-agent/src/socket_activation.rs` + +## Objective + +Verify socket activation and listener isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for socket activation and listener isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise systemd socket activation, internal Unix/vsock, external HTTPS, and GuestApi listeners. + +**Expected results:** + +- Each API appears only on its configured transport, accepts expected clients, and does not expose internal methods externally. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md new file mode 100644 index 000000000..2c5800bcd --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-OBSERVABIL-003: WireGuard configuration and checker recovery + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gos-observabil-003](../../../feature-audit.md#req-gos-observabil-003) +- Risks: [risk-gos-observabil-003](../../../feature-audit.md#risk-gos-observabil-003) +- Source: `os/common/rootfs/wg-checker.sh` + +## Objective + +Verify wireguard configuration and checker recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for wireguard configuration and checker recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Register with gateway, apply wg.conf, disrupt the tunnel, and restore connectivity. + +**Expected results:** + +- Addresses, peers, routes, DNS, handshake monitoring, and recovery converge without duplicate interfaces or leaked keys. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md new file mode 100644 index 000000000..52bf209f0 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-OBSERVABIL-004: System network and resource telemetry + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-observabil-004](../../../feature-audit.md#req-gos-observabil-004) +- Risks: [risk-gos-observabil-004](../../../feature-audit.md#risk-gos-observabil-004) +- Source: `dstack/guest-agent/src/guest_api_service.rs` + +## Objective + +Verify system network and resource telemetry across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for system network and resource telemetry. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Change interfaces, routes, DNS, load, memory, disk, swap, and container set. + +**Expected results:** + +- GuestApi reports complete current values with correct units, prefixes, counters, and disappearance of removed resources. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md new file mode 100644 index 000000000..df74e330c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-OBSERVABIL-005: Guest-agent watchdog recovery + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-observabil-005](../../../feature-audit.md#req-gos-observabil-005) +- Risks: [risk-gos-observabil-005](../../../feature-audit.md#risk-gos-observabil-005) +- Source: `dstack/guest-agent/src/server.rs` + +## Objective + +Verify guest-agent watchdog recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for guest-agent watchdog recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Make the watched external endpoint unresponsive and then healthy. + +**Expected results:** + +- The watchdog detects the failure within policy, triggers the configured recovery, and stops intervening after health returns. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-001/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-001/case.md new file mode 100644 index 000000000..cb56ea0da --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-001: Local key provider TPM mode and PCCS lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-platform-001](../../../feature-audit.md#req-gos-platform-001) +- Risks: [risk-gos-platform-001](../../../feature-audit.md#risk-gos-platform-001) +- Source: `dstack/local-key-provider/src` + +## Objective + +Verify local key provider tpm mode and pccs lifecycle with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Provision TPM mode against a fresh local PCCS cache, restart offline, then refresh collateral and compare with public-PCCS behavior. + +**Expected results:** + +- Initial registration/collateral acquisition succeeds through the configured local PCCS; cached collateral supports later verification within validity; expiry requires refresh and cannot silently fall back to an incompatible public service. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-002/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-002/case.md new file mode 100644 index 000000000..6a9780474 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-002: Local key provider sealing and identity isolation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-platform-002](../../../feature-audit.md#req-gos-platform-002) +- Risks: [risk-gos-platform-002](../../../feature-audit.md#risk-gos-platform-002) +- Source: `dstack/local-key-provider/src` + +## Objective + +Verify local key provider sealing and identity isolation with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Request sealing material for valid quotes from two app/device identities and altered/replayed quotes. + +**Expected results:** + +- Each encrypted key is bound to verified identity/evidence, stable under its documented scope, unusable by the other identity, and replay/tampering returns no key. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-003/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-003/case.md new file mode 100644 index 000000000..2b3d00848 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-003: Host-shared mount and unmount command + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-platform-003](../../../feature-audit.md#req-gos-platform-003) +- Risks: [risk-gos-platform-003](../../../feature-audit.md#risk-gos-platform-003) +- Source: `dstack/dstack-util/src/host_shared.rs` + +## Objective + +Verify host-shared mount and unmount command with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Exercise dstack-util host-shared mount/unmount with labeled disk, 9p fallback, already-mounted, absent, read-only, and cleanup paths. + +**Expected results:** + +- The correct source mounts read-only once, fallback is logged, unmount is idempotent, and failure never leaves a writable or leaked mount. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-004/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-004/case.md new file mode 100644 index 000000000..d5ddb7189 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-004: Guest image reproducible assembly and manifest + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-platform-004](../../../feature-audit.md#req-gos-platform-004) +- Risks: [risk-gos-platform-004](../../../feature-audit.md#risk-gos-platform-004) +- Source: `os/image` + +## Objective + +Verify guest image reproducible assembly and manifest with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Build the same image twice, assemble OCI/image artifacts, and compare manifests, authenticode hashes, measurements, and permitted nondeterminism. + +**Expected results:** + +- Published artifacts and declared hashes are reproducible, schema-valid, and every measured input is accounted for. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-005/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-005/case.md new file mode 100644 index 000000000..bcce29cf2 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-005/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-005: Guest kernel and userspace hardening + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-platform-005](../../../feature-audit.md#req-gos-platform-005) +- Risks: [risk-gos-platform-005](../../../feature-audit.md#risk-gos-platform-005) +- Source: `os/common/rootfs/sysctl.d/99-dstack.conf` + +## Objective + +Verify guest kernel and userspace hardening with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Audit kernel config, sysctl, mounts, capabilities, device nodes, SSH/accounts, network discovery, and writable executable paths. + +**Expected results:** + +- The image exposes only required devices/services, applies hardening settings, has no default credential, and application containers cannot modify measured/privileged host state. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-006/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-006/case.md new file mode 100644 index 000000000..bfc5b28b1 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-006/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-006: Systemd dependency and failure-action graph + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-platform-006](../../../feature-audit.md#req-gos-platform-006) +- Risks: [risk-gos-platform-006](../../../feature-audit.md#risk-gos-platform-006) +- Source: `os/common/rootfs` + +## Objective + +Verify systemd dependency and failure-action graph with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Start, fail, timeout, and restart prepare, simulator, guest-agent, Docker, app-compose, and WireGuard checker units. + +**Expected results:** + +- Ordering requirements prevent early consumers; optional absence does not reboot-loop; fatal failure follows documented action once with useful console diagnostics. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-007/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-007/case.md new file mode 100644 index 000000000..6d8a07749 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-007/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-007: Journal persistence rotation and redaction + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-platform-007](../../../feature-audit.md#req-gos-platform-007) +- Risks: [risk-gos-platform-007](../../../feature-audit.md#risk-gos-platform-007) +- Source: `os/common/rootfs/journald.conf` + +## Objective + +Verify journal persistence rotation and redaction with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Generate boot, application, RPC, Docker, and failure logs through size/time rotation and restart. + +**Expected results:** + +- Required logs remain queryable within retention, rotation bounds disk use, unprivileged apps cannot read host-only logs, and secrets are absent. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-008/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-008/case.md new file mode 100644 index 000000000..42dfa2283 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-008/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-008: Docker daemon and container privilege boundary + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-platform-008](../../../feature-audit.md#req-gos-platform-008) +- Risks: [risk-gos-platform-008](../../../feature-audit.md#risk-gos-platform-008) +- Source: `os/common/rootfs/docker.service.d` + +## Objective + +Verify docker daemon and container privilege boundary with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Launch normal and malicious compose services requesting host mounts, devices, privileged mode, namespaces, capabilities, and resource limits. + +**Expected results:** + +- Allowed workloads honor limits; forbidden host access is rejected by policy and cannot reach guest-agent sockets, keys, measured files, or other containers. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-009/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-009/case.md new file mode 100644 index 000000000..afa4606df --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-009/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-009: NVIDIA device initialization and attestation failure + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-platform-009](../../../feature-audit.md#req-gos-platform-009) +- Risks: [risk-gos-platform-009](../../../feature-audit.md#risk-gos-platform-009) +- Source: `os/yocto/layers/meta-nvidia` + +## Objective + +Verify nvidia device initialization and attestation failure with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Boot supported GPU assignment, missing driver/device, altered attestation output, and partial multi-GPU failure. + +**Expected results:** + +- Only assigned devices appear, driver and evidence match inventory, and failed attestation is explicit without exposing device to an untrusted workload. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-010/case.md b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-010/case.md new file mode 100644 index 000000000..526383129 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/10-platform-services/tc-gos-platform-010/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-PLATFORM-010: Guest configuration backward and forward compatibility + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-platform-010](../../../feature-audit.md#req-gos-platform-010) +- Risks: [risk-gos-platform-010](../../../feature-audit.md#risk-gos-platform-010) +- Source: `dstack/dstack-types/src` + +## Objective + +Verify guest configuration backward and forward compatibility with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Boot previous/current agents with previous/current sys-config, vm_config, compose, user config, and unknown optional fields. + +**Expected results:** + +- Supported older fields preserve semantics, unknown optional fields do not crash, missing required fields fail clearly, and development simulator fields never enter production SysConfig. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md new file mode 100644 index 000000000..fe038a43b --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md @@ -0,0 +1,71 @@ + + + +# TC-GOS-ENTRY-001: Guest-agent configuration precedence and compose deserialization + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-entry-001](../../../feature-audit.md#req-gos-entry-001) +- Risks: [risk-gos-entry-001](../../../feature-audit.md#risk-gos-entry-001) +- Source: `dstack/guest-agent/src/config.rs` + +## Objective + +Verify guest-agent configuration precedence and compose deserialization exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +The `guest-agent` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Load embedded defaults, explicit file, environment overrides, Unix/TCP/vsock binds, valid compose, unknown fields, malformed compose, and absent optional values. + +**Expected results:** + +- Precedence and bind parsing are deterministic; valid compose is preserved losslessly and malformed required data fails before listeners start. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md new file mode 100644 index 000000000..ccc331a2d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-ENTRY-002: Guest-agent startup modes and partial listener failure + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-entry-002](../../../feature-audit.md#req-gos-entry-002) +- Risks: [risk-gos-entry-002](../../../feature-audit.md#risk-gos-entry-002) +- Source: `dstack/guest-agent/src/main.rs` + +## Objective + +Verify guest-agent startup modes and partial listener failure exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Start internal v0/current, external, GuestApi, socket-activated and watchdog modes alone and together; occupy one bind and fail one TLS dependency. + +**Expected results:** + +- Configured listeners start with correct services, partial startup cannot expose an unintended insecure surface, and shutdown joins all tasks. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md new file mode 100644 index 000000000..689f92c27 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-ENTRY-003: Dashboard and metrics model escaping and units + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-entry-003](../../../feature-audit.md#req-gos-entry-003) +- Risks: [risk-gos-entry-003](../../../feature-audit.md#risk-gos-entry-003) +- Source: `dstack/guest-agent/src/models.rs` + +## Objective + +Verify dashboard and metrics model escaping and units exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Populate names, labels and app fields with HTML/control/Unicode data and boundary byte sizes/counters, then render dashboard and metrics. + +**Expected results:** + +- All untrusted text is escaped, sizes/hex/optional names and metric labels are correct, and high-cardinality input is bounded. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md new file mode 100644 index 000000000..85885532d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-GOS-ENTRY-004: Guest-agent library initialization reuse + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-entry-004](../../../feature-audit.md#req-gos-entry-004) +- Risks: [risk-gos-entry-004](../../../feature-audit.md#risk-gos-entry-004) +- Source: `dstack/guest-agent/src/lib.rs` + +## Objective + +Verify guest-agent library initialization reuse exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Construct service state repeatedly for tests, socket activation and full daemon paths with missing and complete dependencies. + +**Expected results:** + +- Initialization produces identical security configuration across entry points, owns each resource once, and teardown leaves no background task. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md new file mode 100644 index 000000000..0d5ddf2f0 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-001: Environment JSON allowlist parsing + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-setup-001](../../../feature-audit.md#req-gos-setup-001) +- Risks: [risk-gos-setup-001](../../../feature-audit.md#risk-gos-setup-001) +- Source: `dstack/dstack-util/src/parse_env_file.rs` + +## Objective + +Verify environment json allowlist parsing for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Parse string/number/bool/null/nested/duplicate/Unicode/oversized environment JSON with empty, partial and full allowlists; convert accepted values to the Docker env file. + +**Expected results:** + +- Only allowed scalar keys appear once with exact documented conversion and escaping; disallowed/nested/ambiguous values are rejected and no injection creates another variable. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md new file mode 100644 index 000000000..f30f5aa92 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-002: Encrypted environment ECDH decryption + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-setup-002](../../../feature-audit.md#req-gos-setup-002) +- Risks: [risk-gos-setup-002](../../../feature-audit.md#risk-gos-setup-002) +- Source: `dstack/dstack-util/src/crypto.rs` + +## Objective + +Verify encrypted environment ecdh decryption for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Decrypt valid X25519-derived ciphertext, wrong app key/peer key, altered nonce/tag/body, empty and oversized payloads. + +**Expected results:** + +- Only authentic ciphertext decrypts to exact bytes; every alteration returns no plaintext and key-agreement inputs are domain-isolated. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md new file mode 100644 index 000000000..f54fe7e1a --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-003: Compose inspection and orphan removal + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-003](../../../feature-audit.md#req-gos-setup-003) +- Risks: [risk-gos-setup-003](../../../feature-audit.md#risk-gos-setup-003) +- Source: `dstack/dstack-util/src/docker_compose.rs` + +## Objective + +Verify compose inspection and orphan removal for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Parse v2 compose services/networks/volumes/profiles and malformed files; detect/remove run-scoped orphan containers in dry-run and active modes. + +**Expected results:** + +- Parsed identity matches Docker Compose semantics, dry-run mutates nothing, active mode removes only true orphans and never another project container. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md new file mode 100644 index 000000000..e59f08d1c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-004: Staged system setup idempotence and config identity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-004](../../../feature-audit.md#req-gos-setup-004) +- Risks: [risk-gos-setup-004](../../../feature-audit.md#risk-gos-setup-004) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify staged system setup idempotence and config identity for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run stage0/filesystem/stage1 setup twice, force and non-force, with identical and changed config IDs and an interrupted stage boundary. + +**Expected results:** + +- Identical rerun is idempotent, changed security config is verified/reprovisioned according to policy, and incomplete stages cannot be mistaken for ready. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md new file mode 100644 index 000000000..ab10ae3b2 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-005: MR config ID verification before provisioning + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-005](../../../feature-audit.md#req-gos-setup-005) +- Risks: [risk-gos-setup-005](../../../feature-audit.md#risk-gos-setup-005) +- Source: `dstack/dstack-util/src/system_setup/config_id_verifier.rs` + +## Objective + +Verify mr config id verification before provisioning for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Verify matching/mismatching/malformed MR config IDs across TDX/SNP and changed compose, image, GPU, CPU and vm_config inputs. + +**Expected results:** + +- Only the exact expected ID permits provisioning; mismatch identifies bound input and no KMS/local key is consumed. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md new file mode 100644 index 000000000..4da0976ff --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-006: KMS URL selection failover and local-provider orthogonality + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-006](../../../feature-audit.md#req-gos-setup-006) +- Risks: [risk-gos-setup-006](../../../feature-audit.md#risk-gos-setup-006) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify kms url selection failover and local-provider orthogonality for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Request app keys across ordered healthy/timeout/wrong-cert/deny KMS URLs, then independently select local key provider and TPM requirements. + +**Expected results:** + +- Remote failover preserves one verified app identity; local-provider selection does not change simulated-TEE choice, and neither path silently falls back to plaintext/random keys. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md new file mode 100644 index 000000000..449583177 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-007: Data disk encryption filesystem repair and mount + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-007](../../../feature-audit.md#req-gos-setup-007) +- Risks: [risk-gos-setup-007](../../../feature-audit.md#risk-gos-setup-007) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify data disk encryption filesystem repair and mount for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Provision fresh/existing encrypted data disks, wrong key, corrupt filesystem, failed fsck, full disk, device replacement, remount and reboot. + +**Expected results:** + +- Correct key mounts the intended filesystem with data continuity; wrong/corrupt devices fail before app start, repair policy is explicit, and keys never enter process lists/logs. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md new file mode 100644 index 000000000..17c44017d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-008: Swap file and ZFS zvol setup + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-008](../../../feature-audit.md#req-gos-setup-008) +- Risks: [risk-gos-setup-008](../../../feature-audit.md#risk-gos-setup-008) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify swap file and zfs zvol setup for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Configure disabled/file/zvol swap at size boundaries, repeat setup, exhaust disk, use existing wrong-size object and reboot. + +**Expected results:** + +- Exactly the configured encrypted-safe swap becomes active, duplicate setup is idempotent, invalid storage fails clearly and no stale swap remains. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md new file mode 100644 index 000000000..fad2878aa --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-009: Gateway registration refresh and key-store persistence + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gos-setup-009](../../../feature-audit.md#req-gos-setup-009) +- Risks: [risk-gos-setup-009](../../../feature-audit.md#risk-gos-setup-009) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify gateway registration refresh and key-store persistence for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Register and refresh across multiple gateway URLs, persisted WireGuard key store, changed instance policy, gateway outage, wrong identity and repeated boot. + +**Expected results:** + +- Stable key material and instance identity are reused securely, configuration updates atomically, and invalid gateway responses never replace working state. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md new file mode 100644 index 000000000..51daf6091 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-010: Host API notify and sealing-key client + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-010](../../../feature-audit.md#req-gos-setup-010) +- Risks: [risk-gos-setup-010](../../../feature-audit.md#risk-gos-setup-010) +- Source: `dstack/dstack-util/src/host_api.rs` + +## Objective + +Verify host api notify and sealing-key client for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Load explicit/default host URL and PCCS URL, send queued/direct events and request sealing key under timeout, malformed, wrong quote and recovery paths. + +**Expected results:** + +- Events preserve ordering/payload and queue semantics; only verified key provision is accepted and transport/PCCS failures return no usable key. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md new file mode 100644 index 000000000..2efe29b20 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-011: GPU measurement in system setup + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-011](../../../feature-audit.md#req-gos-setup-011) +- Risks: [risk-gos-setup-011](../../../feature-audit.md#risk-gos-setup-011) +- Source: `dstack/dstack-util/src/system_setup.rs` + +## Objective + +Verify gpu measurement in system setup for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Measure no GPU, one/multiple GPUs, reordered inventory, failed nvattest, altered result and device removal during setup. + +**Expected results:** + +- GPU measurement is deterministic and bound to assigned inventory; no-GPU has defined value and failed/tampered attestation blocks the required trust transition. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md new file mode 100644 index 000000000..4af3dac62 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md @@ -0,0 +1,62 @@ + + + +# TC-GOS-SETUP-012: Supervisor client full API and auto-start + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-012](../../../feature-audit.md#req-gos-setup-012) +- Risks: [risk-gos-setup-012](../../../feature-audit.md#risk-gos-setup-012) +- Source: `dstack/supervisor/client/src` + +## Objective + +Verify supervisor client full api and auto-start for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +The `supervisor` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Use async/sync clients to spawn/connect/probe, deploy/start/stop/remove/list/info/clear/shutdown with unknown IDs, daemon delay and socket replacement. + +**Expected results:** + +- Client preserves server response/error and timeout semantics, auto-start creates one daemon, and a replaced/untrusted socket is not accepted. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md new file mode 100644 index 000000000..63e719c9c --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-013: TDX simulator device ABI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-013](../../../feature-audit.md#req-gos-setup-013) +- Risks: [risk-gos-setup-013](../../../feature-audit.md#risk-gos-setup-013) +- Source: `dstack/tee-simulator/src/tdx.rs` + +## Objective + +Verify tdx simulator device abi for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Exercise report/quote/event-log device paths, offsets, permissions, repeated/concurrent reads and invalid ioctls/data using configured seed and vm_config. + +**Expected results:** + +- Filesystem/device ABI matches a TDX guest, evidence binds report data/config deterministically, and invalid access is bounded without host writes. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md new file mode 100644 index 000000000..324275e28 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-014: SEV-SNP simulator device ABI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-014](../../../feature-audit.md#req-gos-setup-014) +- Risks: [risk-gos-setup-014](../../../feature-audit.md#risk-gos-setup-014) +- Source: `dstack/tee-simulator/src/sev_snp.rs` + +## Objective + +Verify sev-snp simulator device abi for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Exercise guest request/response, cert table, measurement, report data, malformed request, short buffers and repeated/concurrent access. + +**Expected results:** + +- SNP ABI structures and cert chain encode correctly, measurement binds vm_config, and malformed/undersized operations return platform-compatible errors. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md new file mode 100644 index 000000000..6bb347857 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-015: TPM simulator command proxy and lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-015](../../../feature-audit.md#req-gos-setup-015) +- Risks: [risk-gos-setup-015](../../../feature-audit.md#risk-gos-setup-015) +- Source: `dstack/tee-simulator/src/tpm.rs` + +## Objective + +Verify tpm simulator command proxy and lifecycle for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Send startup, PCR, quote, random, malformed/oversized commands; disconnect/reconnect proxy and restart simulator with/without persistent TPM state. + +**Expected results:** + +- TPM framing and responses match expected ABI, PCR/evidence policy is deterministic, invalid commands cannot hang proxy, and persistence follows configuration. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md new file mode 100644 index 000000000..42e54e57e --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-016: Nitro NSM simulator request ABI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-016](../../../feature-audit.md#req-gos-setup-016) +- Risks: [risk-gos-setup-016](../../../feature-audit.md#risk-gos-setup-016) +- Source: `dstack/tee-simulator/src/nsm.rs` + +## Objective + +Verify nitro nsm simulator request abi for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Send DescribePCR, ExtendPCR, LockPCR, GetAttestationDoc, GetRandom and invalid CBOR/unknown/oversized requests concurrently. + +**Expected results:** + +- CBOR request/response and NSM state transitions match Nitro semantics, attestation binds nonce/user/public-key/PCRs, and errors are encoded without panic. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md new file mode 100644 index 000000000..a9cbc875d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-017: Simulator platform selection config and mount safety + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gos-setup-017](../../../feature-audit.md#req-gos-setup-017) +- Risks: [risk-gos-setup-017](../../../feature-audit.md#risk-gos-setup-017) +- Source: `dstack/tee-simulator/src/main.rs` + +## Objective + +Verify simulator platform selection config and mount safety for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Start every simulated TeeVariant via config and explicit CLI, missing/malformed config, mountpoint override, already-mounted path, signal and backend failure. + +**Expected results:** + +- Config is required and authoritative unless explicit override is allowed, correct backend mounts once, ready/unmount lifecycle is clean, and production TEE detection is not used as the enable condition. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md new file mode 100644 index 000000000..682fbd787 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-018: TDX event-log extend show and replay CLI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-018](../../../feature-audit.md#req-gos-setup-018) +- Risks: [risk-gos-setup-018](../../../feature-audit.md#risk-gos-setup-018) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify tdx event-log extend show and replay cli including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `eventlog`, `extend`, `show`, and `replay-imr` with valid ordered events plus invalid index, malformed hex, duplicate/reordered events, concurrent extension and device failure. + +**Expected results:** + +- Live RTMR changes equal SHA-384 extend semantics, event log records exact digest/preimage/order, replay equals hardware state, and invalid input does not extend. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md new file mode 100644 index 000000000..2f1b4c02f --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-019: Quote and quote-report CLI bindings + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-019](../../../feature-audit.md#req-gos-setup-019) +- Risks: [risk-gos-setup-019](../../../feature-audit.md#risk-gos-setup-019) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify quote and quote-report cli bindings including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `quote` and `quote-report` with empty/boundary/64-byte/oversized report data, sys-config variants, debug/output modes and unavailable TEE device. + +**Expected results:** + +- Quote report data and packaged report bind exact requested/config inputs, output encoding is valid, oversize is rejected and debug cannot weaken verification or leak secrets. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md new file mode 100644 index 000000000..0f13c8624 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-020: RA CA and app key generation CLI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-020](../../../feature-audit.md#req-gos-setup-020) +- Risks: [risk-gos-setup-020](../../../feature-audit.md#risk-gos-setup-020) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify ra ca and app key generation cli including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `gen-ra-cert`, `gen-ca-cert`, and `gen-app-keys` across CA levels, SAN/usage inputs, existing outputs, unsafe paths/permissions, mismatched CA key and interrupted write. + +**Expected results:** + +- Generated keys match certificates/chains and intended CA constraints, private files are restrictive/atomic, mismatch fails and existing trusted output is not overwritten. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md new file mode 100644 index 000000000..22c031287 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-021: Random and hexadecimal utility CLI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-021](../../../feature-audit.md#req-gos-setup-021) +- Risks: [risk-gos-setup-021](../../../feature-audit.md#risk-gos-setup-021) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify random and hexadecimal utility cli including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `rand` and `hex` at zero/default/maximum sizes to stdout/file/hex, with short writes, existing file, entropy failure and binary/empty input. + +**Expected results:** + +- Random output has exact requested length and encoding without reuse, hex is exact lowercase documented form, errors do not leave partial output and no random bytes enter logs. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md new file mode 100644 index 000000000..517ce7667 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-022: vTPM attest quote and verify CLI suite + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-022](../../../feature-audit.md#req-gos-setup-022) +- Risks: [risk-gos-setup-022](../../../feature-audit.md#risk-gos-setup-022) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify vtpm attest quote and verify cli suite including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `vtpm-attest`, `tpm-quote`, and `tpm-verify` using RSA/ECC/auto, nonce/data/hash variants, correct/wrong root, altered PCR/signature/event log, replay and expected OS hash. + +**Expected results:** + +- Valid chain/signature/nonce/PCR replay/OS hash verify together; every altered or replayed field fails the corresponding assertion and no unsupported algorithm is accepted. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md new file mode 100644 index 000000000..6326e07d0 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-023: Versioned attestation create inspect JSON and strip CLI + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-023](../../../feature-audit.md#req-gos-setup-023) +- Risks: [risk-gos-setup-023](../../../feature-audit.md#risk-gos-setup-023) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify versioned attestation create inspect json and strip cli including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `attest`, `attest-info`, `attest-json`, and `attest-strip` for every platform/version with boundary report data/app ID, truncated/unknown/oversized encoding and round trips. + +**Expected results:** + +- Info sizes and JSON exactly describe authenticated envelope, strip removes only permitted certificate payload while preserving verification, and malformed/unknown versions fail without downgrade. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md new file mode 100644 index 000000000..4106311dd --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-SETUP-024: KMS GetKeys CLI transport and output safety + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-setup-024](../../../feature-audit.md#req-gos-setup-024) +- Risks: [risk-gos-setup-024](../../../feature-audit.md#risk-gos-setup-024) +- Source: `dstack/dstack-util/src/main.rs` + +## Objective + +Verify kms getkeys cli transport and output safety including exact cryptographic binding, CLI encoding, file safety, negative inputs, and dependency recovery. + +## Preconditions + +1. Run on isolated hardware and simulator environments as applicable; simulator results do not confirm hardware assertions. +2. Capture command argv, exit status, redacted stdout/stderr, output hashes/permissions, and independently decoded cryptographic evidence. + +## Test Data + +Use run-scoped non-secret inputs plus separately generated valid and one-field-mutated evidence fixtures. + +## Steps + + +### Step 1: Exercise all CLI modes and boundaries + +Run `get-keys` against valid/multiple/timeout/wrong-cert/deny KMS URLs with valid/altered vm_config and output paths, then repeat/restart. + +**Expected results:** + +- Only attestation-authorized response is accepted, failover preserves one key identity, output is atomic/restrictive and no key material appears on stdout/logs unless explicitly documented. + + +### Step 2: Verify independent decoding and failure atomicity + +Decode or verify output with an independent library/tool, inject device/network/filesystem failure before output commit, restore it, and retry. + +**Expected results:** + +- Independent results match, invalid/failing operations return nonzero with actionable redacted error, no partial trusted output remains, and retry succeeds exactly once. + + +### Step 3: Verify isolation permissions and repeatability + +Repeat under another app/device identity and after restart; inspect outputs, logs and temporary files. + +**Expected results:** + +- Deterministic values are stable only within documented identity scope, random values do not repeat, cross-identity evidence/keys fail, permissions are restrictive, and no private material is logged. + +## Postconditions + +Securely remove generated private material and restore device, mount, network and filesystem state. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md new file mode 100644 index 000000000..603f7bdf9 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-001: Development versus production image package boundary + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-yocto-001](../../../feature-audit.md#req-gos-yocto-001) +- Risks: [risk-gos-yocto-001](../../../feature-audit.md#risk-gos-yocto-001) +- Source: `os/yocto/layers/meta-dstack` + +## Objective + +Verify development versus production image package boundary for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Build dev/prod multiconfig images and diff packages, units, users, ports, simulator/mock credentials and debug tools. + +**Expected results:** + +- Production excludes simulator/debug/mock secrets and unnecessary tools/listeners; dev additions are explicit and both retain required runtime dependencies. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md new file mode 100644 index 000000000..a2448b08b --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-002: OpenSSH account and password-auth hardening + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-yocto-002](../../../feature-audit.md#req-gos-yocto-002) +- Risks: [risk-gos-yocto-002](../../../feature-audit.md#risk-gos-yocto-002) +- Source: `os/yocto/layers/meta-dstack/recipes-connectivity/openssh` + +## Objective + +Verify openssh account and password-auth hardening for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Inspect config and attempt password, empty/default account, root, unauthorized key, authorized key and forwarding modes. + +**Expected results:** + +- Password/default access is disabled, only provisioned keys/policy work, and SSH exposure matches image type without weakening container isolation. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md new file mode 100644 index 000000000..50922067e --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-003: Chrony synchronization and clock recovery + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-yocto-003](../../../feature-audit.md#req-gos-yocto-003) +- Risks: [risk-gos-yocto-003](../../../feature-audit.md#risk-gos-yocto-003) +- Source: `os/yocto/layers/meta-dstack/recipes-core/chrony` + +## Objective + +Verify chrony synchronization and clock recovery for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Boot with good/bad/unreachable sources, large forward/backward skew, network recovery and restart while observing certificate/attestation consumers. + +**Expected results:** + +- Time converges within policy, unsafe jumps are controlled, readiness does not falsely claim valid time, and dependent services recover after synchronization. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md new file mode 100644 index 000000000..be671140f --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-004: Containerd stargz snapshotter integrity and fallback + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gos-yocto-004](../../../feature-audit.md#req-gos-yocto-004) +- Risks: [risk-gos-yocto-004](../../../feature-audit.md#risk-gos-yocto-004) +- Source: `os/yocto/layers/meta-dstack/recipes-containers` + +## Objective + +Verify containerd stargz snapshotter integrity and fallback for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Pull/run signed normal, lazy, corrupt, unavailable-registry and altered-layer images with snapshotter restart and cache pressure. + +**Expected results:** + +- Verified content runs with correct snapshotter, corrupt layers never execute, fallback follows config, and cache/restart preserves isolation. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md new file mode 100644 index 000000000..fdf72a676 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-005: Sysbox runtime services and nested-container boundary + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-yocto-005](../../../feature-audit.md#req-gos-yocto-005) +- Risks: [risk-gos-yocto-005](../../../feature-audit.md#risk-gos-yocto-005) +- Source: `os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox` + +## Objective + +Verify sysbox runtime services and nested-container boundary for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Start/stop/restart sysbox services and run nested workloads requesting host mounts, proc/sys, devices, cgroups and privilege escalation. + +**Expected results:** + +- Supported nested containers work while host kernel/files/devices/agent sockets remain protected; service failure affects only selected workloads. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md new file mode 100644 index 000000000..ed626d5f8 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-006: Docker daemon CPU/GPU configuration variants + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-yocto-006](../../../feature-audit.md#req-gos-yocto-006) +- Risks: [risk-gos-yocto-006](../../../feature-audit.md#risk-gos-yocto-006) +- Source: `os/yocto/layers/meta-dstack/recipes-core/images/files` + +## Objective + +Verify docker daemon cpu/gpu configuration variants for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Validate normal/NVIDIA daemon JSON, runtimes, default runtime, cgroups, logging, restart and malformed override. + +**Expected results:** + +- Each image selects only installed runtime, GPU workloads receive assigned devices, normal image does not advertise NVIDIA, and bad config fails before apps. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md new file mode 100644 index 000000000..5f33f7a2d --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-007: Reproducible Yocto build and artifact export + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-yocto-007](../../../feature-audit.md#req-gos-yocto-007) +- Risks: [risk-gos-yocto-007](../../../feature-audit.md#risk-gos-yocto-007) +- Source: `os/yocto/repro-build` + +## Objective + +Verify reproducible yocto build and artifact export for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Build twice in clean environments, export artifacts/SBOM/manifests, compare hashes and run the reproducibility checker with one changed source. + +**Expected results:** + +- Unchanged outputs are reproducible or documented nondeterminism is normalized; changed source changes declared artifacts and all exports match manifests. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md new file mode 100644 index 000000000..a04aa40e3 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-YOCTO-008: AWS image hardening audit + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gos-yocto-008](../../../feature-audit.md#req-gos-yocto-008) +- Risks: [risk-gos-yocto-008](../../../feature-audit.md#risk-gos-yocto-008) +- Source: `os/yocto/tools/aws/audit-aws-ec2-image-hardening.sh` + +## Objective + +Verify aws image hardening audit for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run audit against compliant candidate and controlled violations for accounts, SSH, services, permissions, network and logging. + +**Expected results:** + +- Compliant image passes every named control, each injected violation is detected specifically, and audit itself does not alter the image. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/01-guest-os/14-gos-build/tc-gos-build-001/case.md b/docs/test-plans/core-components-full/01-guest-os/14-gos-build/tc-gos-build-001/case.md new file mode 100644 index 000000000..3c7199e93 --- /dev/null +++ b/docs/test-plans/core-components-full/01-guest-os/14-gos-build/tc-gos-build-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GOS-BUILD-001: Guest OS Build and Existing Regression Suite + +## Metadata + +- Priority: P0 +- Type: Build, Regression, Supply Chain, Security +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gos-build-001](../../../feature-audit.md#req-gos-build-001) +- Risks: [risk-gos-build-001](../../../feature-audit.md#risk-gos-build-001) +- Source: `os/build.sh` + +## Objective + +Verify the complete component build, generated-interface, packaging, existing-test, and supply-chain baseline before product-level cases rely on the candidate. + +## Preconditions + +1. Use a clean checkout, empty component build caches, pinned toolchains, and recorded dependency mirrors. +2. Do not update locks or generated files during the test; capture any dirty working-tree diff. + +## Test Data + +Use the candidate commit, committed fixtures, lock files, image recipes, generated protobuf/OpenAPI sources, and all component-native test configurations. + +## Steps + + +### Step 1: Build from clean state + +Build the production and development guest artifacts, run Rust/shell/Yocto configuration and reproducibility checks, and execute existing guest-agent, supervisor, util, local-key-provider and simulator tests. + +**Expected results:** + +- All pinned dependencies and generated APIs build from clean state; every existing test passes; dev/prod artifacts and manifests match the audited package boundary. + + +### Step 2: Verify generated and packaged artifacts + +Regenerate interfaces into a temporary tree, compare with committed output, inspect licenses/SBOM/locks/image contents and repeat the build with network disabled after dependency fetch. + +**Expected results:** + +- Generated output has no unexplained diff, offline rebuild succeeds from pins, required licenses are present, and packages contain only declared runtime/test content. + + +### Step 3: Verify failure detection + +Introduce one temporary source/test-fixture/schema/config mismatch outside the committed tree and confirm the relevant build/test/generation gate fails, then restore and rerun. + +**Expected results:** + +- The gate detects the controlled regression with a specific error and returns to a clean passing result after restoration. + +## Postconditions + +Remove temporary build/output trees and verify the candidate checkout remains clean. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md new file mode 100644 index 000000000..92d323740 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-001: Vmm.CreateVm + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-001](../../../feature-audit.md#req-vmm-vmm-001) +- Risks: [risk-vmm-vmm-001](../../../feature-audit.md#risk-vmm-vmm-001) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:339` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.CreateVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.CreateVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.createvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.CreateVm` with a valid `VmConfiguration` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `Id` with every documented field and exhibits the documented `CreateVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md new file mode 100644 index 000000000..e89aa72a0 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-002: Vmm.StartVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-002](../../../feature-audit.md#req-vmm-vmm-002) +- Risks: [risk-vmm-vmm-002](../../../feature-audit.md#risk-vmm-vmm-002) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:341` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.StartVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.StartVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.startvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.StartVm` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `StartVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md new file mode 100644 index 000000000..7d467949f --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-003: Vmm.StopVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-003](../../../feature-audit.md#req-vmm-vmm-003) +- Risks: [risk-vmm-vmm-003](../../../feature-audit.md#risk-vmm-vmm-003) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:343` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.StopVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.StopVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.stopvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.StopVm` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `StopVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md new file mode 100644 index 000000000..e73411bf0 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-004: Vmm.RemoveVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-004](../../../feature-audit.md#req-vmm-vmm-004) +- Risks: [risk-vmm-vmm-004](../../../feature-audit.md#risk-vmm-vmm-004) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:345` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.RemoveVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.RemoveVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.removevm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.RemoveVm` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `RemoveVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md new file mode 100644 index 000000000..1a8b0714e --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-005: Vmm.UpgradeApp + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-005](../../../feature-audit.md#req-vmm-vmm-005) +- Risks: [risk-vmm-vmm-005](../../../feature-audit.md#risk-vmm-vmm-005) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:347` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.UpgradeApp`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.UpgradeApp` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.upgradeapp. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.UpgradeApp` with a valid `UpdateVmRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `Id` with every documented field and exhibits the documented `UpgradeApp` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md new file mode 100644 index 000000000..eb569f4ca --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-006: Vmm.UpdateVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-006](../../../feature-audit.md#req-vmm-vmm-006) +- Risks: [risk-vmm-vmm-006](../../../feature-audit.md#risk-vmm-vmm-006) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:349` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.UpdateVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.UpdateVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.updatevm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.UpdateVm` with a valid `UpdateVmRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `Id` with every documented field and exhibits the documented `UpdateVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md new file mode 100644 index 000000000..20fbf30f7 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-007: Vmm.ShutdownVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-007](../../../feature-audit.md#req-vmm-vmm-007) +- Risks: [risk-vmm-vmm-007](../../../feature-audit.md#risk-vmm-vmm-007) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:351` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ShutdownVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ShutdownVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.shutdownvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ShutdownVm` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ShutdownVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md new file mode 100644 index 000000000..93a99a461 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-008: Vmm.ResizeVm + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-008](../../../feature-audit.md#req-vmm-vmm-008) +- Risks: [risk-vmm-vmm-008](../../../feature-audit.md#risk-vmm-vmm-008) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:353` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ResizeVm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ResizeVm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.resizevm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ResizeVm` with a valid `ResizeVmRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ResizeVm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md new file mode 100644 index 000000000..a64245d78 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-009: Vmm.GetComposeHash + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-009](../../../feature-audit.md#req-vmm-vmm-009) +- Risks: [risk-vmm-vmm-009](../../../feature-audit.md#risk-vmm-vmm-009) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:355` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.GetComposeHash`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.GetComposeHash` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.getcomposehash. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.GetComposeHash` with a valid `VmConfiguration` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ComposeHash` with every documented field and exhibits the documented `GetComposeHash` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md new file mode 100644 index 000000000..b7838e691 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-010: Vmm.Status + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-010](../../../feature-audit.md#req-vmm-vmm-010) +- Risks: [risk-vmm-vmm-010](../../../feature-audit.md#risk-vmm-vmm-010) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:358` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.Status`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.Status` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.status. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.Status` with a valid `StatusRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `StatusResponse` with every documented field and exhibits the documented `Status` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md new file mode 100644 index 000000000..c4e7d4b75 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-011: Vmm.ListImages + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-011](../../../feature-audit.md#req-vmm-vmm-011) +- Risks: [risk-vmm-vmm-011](../../../feature-audit.md#risk-vmm-vmm-011) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:360` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ListImages`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ListImages` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.listimages. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ListImages` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ImageListResponse` with every documented field and exhibits the documented `ListImages` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md new file mode 100644 index 000000000..6e666e103 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-012: Vmm.GetAppEnvEncryptPubKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-012](../../../feature-audit.md#req-vmm-vmm-012) +- Risks: [risk-vmm-vmm-012](../../../feature-audit.md#risk-vmm-vmm-012) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:363` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.GetAppEnvEncryptPubKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.GetAppEnvEncryptPubKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.getappenvencryptpubkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.GetAppEnvEncryptPubKey` with a valid `AppId` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `PublicKeyResponse` with every documented field and exhibits the documented `GetAppEnvEncryptPubKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md new file mode 100644 index 000000000..9f4106a59 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-013: Vmm.GetInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-013](../../../feature-audit.md#req-vmm-vmm-013) +- Risks: [risk-vmm-vmm-013](../../../feature-audit.md#risk-vmm-vmm-013) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:366` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.GetInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.GetInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.getinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.GetInfo` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetInfoResponse` with every documented field and exhibits the documented `GetInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md new file mode 100644 index 000000000..d12cdc808 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-014: Vmm.Version + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-014](../../../feature-audit.md#req-vmm-vmm-014) +- Risks: [risk-vmm-vmm-014](../../../feature-audit.md#risk-vmm-vmm-014) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:369` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.Version`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.Version` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.version. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.Version` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `VersionResponse` with every documented field and exhibits the documented `Version` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md new file mode 100644 index 000000000..b3c09e5e8 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-015: Vmm.GetMeta + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-015](../../../feature-audit.md#req-vmm-vmm-015) +- Risks: [risk-vmm-vmm-015](../../../feature-audit.md#risk-vmm-vmm-015) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:372` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.GetMeta`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.GetMeta` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.getmeta. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.GetMeta` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetMetaResponse` with every documented field and exhibits the documented `GetMeta` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md new file mode 100644 index 000000000..3c8ea1ba3 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-016: Vmm.ListGpus + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-016](../../../feature-audit.md#req-vmm-vmm-016) +- Risks: [risk-vmm-vmm-016](../../../feature-audit.md#risk-vmm-vmm-016) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:375` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ListGpus`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ListGpus` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.listgpus. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ListGpus` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListGpusResponse` with every documented field and exhibits the documented `ListGpus` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md new file mode 100644 index 000000000..17f378815 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-017: Vmm.ReloadVms + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-017](../../../feature-audit.md#req-vmm-vmm-017) +- Risks: [risk-vmm-vmm-017](../../../feature-audit.md#risk-vmm-vmm-017) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:378` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ReloadVms`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ReloadVms` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.reloadvms. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ReloadVms` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ReloadVmsResponse` with every documented field and exhibits the documented `ReloadVms` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md new file mode 100644 index 000000000..1a776b81e --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-018: Vmm.SvList + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-018](../../../feature-audit.md#req-vmm-vmm-018) +- Risks: [risk-vmm-vmm-018](../../../feature-audit.md#risk-vmm-vmm-018) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:381` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.SvList`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.SvList` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.svlist. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.SvList` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `SvListResponse` with every documented field and exhibits the documented `SvList` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md new file mode 100644 index 000000000..933fffbbe --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-019: Vmm.SvStop + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-019](../../../feature-audit.md#req-vmm-vmm-019) +- Risks: [risk-vmm-vmm-019](../../../feature-audit.md#risk-vmm-vmm-019) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:383` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.SvStop`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.SvStop` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.svstop. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.SvStop` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SvStop` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md new file mode 100644 index 000000000..0f7496137 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-020: Vmm.SvRemove + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-020](../../../feature-audit.md#req-vmm-vmm-020) +- Risks: [risk-vmm-vmm-020](../../../feature-audit.md#risk-vmm-vmm-020) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:385` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.SvRemove`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.SvRemove` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.svremove. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.SvRemove` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SvRemove` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md new file mode 100644 index 000000000..39ce42611 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-021: Vmm.ListRegistryImages + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-021](../../../feature-audit.md#req-vmm-vmm-021) +- Risks: [risk-vmm-vmm-021](../../../feature-audit.md#risk-vmm-vmm-021) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:388` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.ListRegistryImages`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.ListRegistryImages` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.listregistryimages. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.ListRegistryImages` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `RegistryImageListResponse` with every documented field and exhibits the documented `ListRegistryImages` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md new file mode 100644 index 000000000..bc28eb82b --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-022: Vmm.PullRegistryImage + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-022](../../../feature-audit.md#req-vmm-vmm-022) +- Risks: [risk-vmm-vmm-022](../../../feature-audit.md#risk-vmm-vmm-022) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:390` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.PullRegistryImage`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.PullRegistryImage` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.pullregistryimage. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.PullRegistryImage` with a valid `PullRegistryImageRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `PullRegistryImage` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md new file mode 100644 index 000000000..e75baeecc --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-VMM-023: Vmm.DeleteImage + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vmm-023](../../../feature-audit.md#req-vmm-vmm-023) +- Risks: [risk-vmm-vmm-023](../../../feature-audit.md#risk-vmm-vmm-023) +- Source: `dstack/vmm/rpc/proto/vmm_rpc.proto:392` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Vmm.DeleteImage`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Vmm.DeleteImage` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm.deleteimage. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Vmm.DeleteImage` with a valid `Id` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `DeleteImage` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md new file mode 100644 index 000000000..9a58d5ea5 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-HOSTAPI-001: HostApi.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-hostapi-001](../../../feature-audit.md#req-vmm-hostapi-001) +- Risks: [risk-vmm-hostapi-001](../../../feature-audit.md#risk-vmm-hostapi-001) +- Source: `dstack/host-api/proto/host_api.proto:31` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `HostApi.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `HostApi.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for hostapi.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `HostApi.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `HostInfo` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md new file mode 100644 index 000000000..4565746fc --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-HOSTAPI-002: HostApi.Notify + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-hostapi-002](../../../feature-audit.md#req-vmm-hostapi-002) +- Risks: [risk-vmm-hostapi-002](../../../feature-audit.md#risk-vmm-hostapi-002) +- Source: `dstack/host-api/proto/host_api.proto:32` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `HostApi.Notify`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `HostApi.Notify` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for hostapi.notify. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `HostApi.Notify` with a valid `Notification` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `Notify` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md new file mode 100644 index 000000000..ec8664a69 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-HOSTAPI-003: HostApi.GetSealingKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-hostapi-003](../../../feature-audit.md#req-vmm-hostapi-003) +- Risks: [risk-vmm-hostapi-003](../../../feature-audit.md#risk-vmm-hostapi-003) +- Source: `dstack/host-api/proto/host_api.proto:33` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `HostApi.GetSealingKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `HostApi.GetSealingKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for hostapi.getsealingkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `HostApi.GetSealingKey` with a valid `GetSealingKeyRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetSealingKeyResponse` with every documented field and exhibits the documented `GetSealingKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md new file mode 100644 index 000000000..861743b6b --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-VMM-CONFIGURAT-001: Configuration defaults and validation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-configurat-001](../../../feature-audit.md#req-vmm-configurat-001) +- Risks: [risk-vmm-configurat-001](../../../feature-audit.md#risk-vmm-configurat-001) +- Source: `dstack/vmm/src/config.rs` + +## Objective + +Verify configuration defaults and validation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `vmm` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for configuration defaults and validation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Load minimal, full, unknown, conflicting, and invalid vmm.toml settings. + +**Expected results:** + +- Defaults are documented and stable; invalid platform, networking, key-provider, GPU, listener, and path combinations fail before serving. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md new file mode 100644 index 000000000..688b7358c --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-CONFIGURAT-002: External API authentication and listener separation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-configurat-002](../../../feature-audit.md#req-vmm-configurat-002) +- Risks: [risk-vmm-configurat-002](../../../feature-audit.md#risk-vmm-configurat-002) +- Source: `dstack/vmm/src/main.rs` + +## Objective + +Verify external api authentication and listener separation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for external api authentication and listener separation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Call public VMM, host, UI, and log endpoints with valid, missing, expired, and wrong credentials. + +**Expected results:** + +- Only the intended surfaces are public; protected calls reject invalid credentials and host APIs remain bound to their private transport. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md new file mode 100644 index 000000000..68ca97ad9 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-CONFIGURAT-003: Per-instance simulated TEE selection + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-vmm-configurat-003](../../../feature-audit.md#req-vmm-configurat-003) +- Risks: [risk-vmm-configurat-003](../../../feature-audit.md#risk-vmm-configurat-003) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify per-instance simulated tee selection across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for per-instance simulated tee selection. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Deploy simulated and real-TEE instances concurrently with different simulated_tee values. + +**Expected results:** + +- Only selected instances receive simulator config/no-TEE QEMU mode; production schema and other instances remain unaffected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md new file mode 100644 index 000000000..9c41a84a1 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-CONFIGURAT-004: TPM attachment decision materialization + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-vmm-configurat-004](../../../feature-audit.md#req-vmm-configurat-004) +- Risks: [risk-vmm-configurat-004](../../../feature-audit.md#risk-vmm-configurat-004) +- Source: `dstack/vmm/src/main_service.rs` + +## Objective + +Verify tpm attachment decision materialization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tpm attachment decision materialization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Deploy key_provider=tpm across simulated platforms that do and do not provide TPM. + +**Expected results:** + +- The deployment-time swtpm boolean is correct, persisted in vm_config, and QEMU attaches swtpm only when true. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md new file mode 100644 index 000000000..3d001f3a7 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-TDXVARIANT-005: TDX legacy lite and auto variant resolution matrix + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-vmm-tdxvariant-005](../../../feature-audit.md#req-vmm-tdxvariant-005) +- Risks: [risk-vmm-tdxvariant-005](../../../feature-audit.md#risk-vmm-tdxvariant-005) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify tdx legacy lite and auto variant resolution matrix using the complete source-defined decision matrix and independently observable output. + +## Preconditions + +1. Record candidate and pinned historical image/compose/config versions plus baseline identity, measurements, processes, files and public status. +2. Use isolated run-scoped inputs and retain native redacted output. + +## Test Data + +Build a table with one row for every condition named in Step 1, including each condition alone and security-relevant conflicting combinations. + +## Steps + + +### Step 1: Execute the full decision matrix + +Cross explicit legacy/lite/auto with memory below/equal/above 2 GiB, image lite capability, `requirements.tdx_measure_acpi_tables` true/false/omitted, pinned old images and KMS-onboard mode. + +**Expected results:** + +- Explicit requirements take documented precedence, auto chooses lite only for supported 2-GiB-compatible rows, otherwise legacy; vm_config/event expectations match, and old-source KMS targets remain forced legacy. + + +### Step 2: Verify the selected state end to end + +Compare parser/validation output, persisted manifest/config, generated measurement inputs, launch arguments, guest-visible state and public status for every accepted row. + +**Expected results:** + +- Every representation agrees with the selected row, no rejected value is partially persisted or launched, and unrelated inputs do not change measured identity. + + +### Step 3: Verify failure recovery and version compatibility + +Restart after accepted/rejected rows, replay applicable v0.5.4/v0.5.8/v0.5.11 inputs, and retry after correcting one invalid field. + +**Expected results:** + +- Supported historical defaults remain stable, unsupported combinations fail before secret/device consumption, restart reconstructs the same decision and corrected retry succeeds without stale state. + +## Postconditions + +Remove run-scoped VMs/files/devices and verify baseline restoration. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md new file mode 100644 index 000000000..69ad0dad0 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-001: Create/start/stop/remove idempotency + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-001](../../../feature-audit.md#req-vmm-vm-lifecyc-001) +- Risks: [risk-vmm-vm-lifecyc-001](../../../feature-audit.md#risk-vmm-vm-lifecyc-001) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify create/start/stop/remove idempotency across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for create/start/stop/remove idempotency. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise each lifecycle transition twice and concurrently. + +**Expected results:** + +- Valid transitions converge once; duplicate/conflicting operations return deterministic errors without orphan QEMU, disks, taps, or workdirs. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md new file mode 100644 index 000000000..23435bfa6 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-002: Graceful shutdown versus forced stop + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-002](../../../feature-audit.md#req-vmm-vm-lifecyc-002) +- Risks: [risk-vmm-vm-lifecyc-002](../../../feature-audit.md#risk-vmm-vm-lifecyc-002) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify graceful shutdown versus forced stop across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for graceful shutdown versus forced stop. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Compare guest ShutdownVm with StopVm under responsive and hung guests. + +**Expected results:** + +- Graceful shutdown emits ordered events and preserves state; timeout falls back according to policy without killing another VM. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md new file mode 100644 index 000000000..8cfde84ad --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-003: Update and upgrade identity semantics + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-003](../../../feature-audit.md#req-vmm-vm-lifecyc-003) +- Risks: [risk-vmm-vm-lifecyc-003](../../../feature-audit.md#risk-vmm-vm-lifecyc-003) +- Source: `dstack/vmm/src/main_service.rs` + +## Objective + +Verify update and upgrade identity semantics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for update and upgrade identity semantics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Update mutable fields and upgrade compose with/without app_id and KMS. + +**Expected results:** + +- Update preserves app identity; upgrade follows app_id/KMS rules, recalculates compose hash, and rejects identity mismatch. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md new file mode 100644 index 000000000..aca8e1f41 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-004: Resize CPU memory and disk + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-004](../../../feature-audit.md#req-vmm-vm-lifecyc-004) +- Risks: [risk-vmm-vm-lifecyc-004](../../../feature-audit.md#risk-vmm-vm-lifecyc-004) +- Source: `dstack/vmm/src/main_service.rs` + +## Objective + +Verify resize cpu memory and disk across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for resize cpu memory and disk. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Resize running/stopped VMs at minimum, growth, unsupported shrink, and invalid values. + +**Expected results:** + +- Supported changes persist and appear in status/guest; disk data remains intact and unsupported changes are rejected atomically. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md new file mode 100644 index 000000000..50b397f15 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-005: Reload and crash recovery + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-005](../../../feature-audit.md#req-vmm-vm-lifecyc-005) +- Risks: [risk-vmm-vm-lifecyc-005](../../../feature-audit.md#risk-vmm-vm-lifecyc-005) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify reload and crash recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for reload and crash recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Restart VMM with running, stopped, exited, partially-created, and stale workdirs. + +**Expected results:** + +- Reload reconstructs accurate state, reconciles stale resources, and does not duplicate or auto-start stopped VMs. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md new file mode 100644 index 000000000..caa15bdad --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VM-LIFECYC-006: Auto-restart policy and backoff + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-vm-lifecyc-006](../../../feature-audit.md#req-vmm-vm-lifecyc-006) +- Risks: [risk-vmm-vm-lifecyc-006](../../../feature-audit.md#risk-vmm-vm-lifecyc-006) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify auto-restart policy and backoff across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for auto-restart policy and backoff. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Crash eligible and ineligible VMs repeatedly around configured thresholds. + +**Expected results:** + +- Only eligible VMs restart; retry limits/backoff/reset windows and events match config without a hot loop. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md new file mode 100644 index 000000000..5448fd3fe --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-001: User bridge and custom networking + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-compute-ne-001](../../../feature-audit.md#req-vmm-compute-ne-001) +- Risks: [risk-vmm-compute-ne-001](../../../feature-audit.md#risk-vmm-compute-ne-001) +- Source: `dstack/vmm/src/app/network.rs` + +## Objective + +Verify user bridge and custom networking across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for user bridge and custom networking. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Deploy singular and multiple networks using user, bridge, defaults, and overrides. + +**Expected results:** + +- Resolved interfaces, MACs, taps, bridges, netdev IDs, routes, and status match precedence rules and clean up on removal. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md new file mode 100644 index 000000000..818f4fa38 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-002: Port mapping protocols and conflicts + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-compute-ne-002](../../../feature-audit.md#req-vmm-compute-ne-002) +- Risks: [risk-vmm-compute-ne-002](../../../feature-audit.md#risk-vmm-compute-ne-002) +- Source: `dstack/vmm/src/config.rs` + +## Objective + +Verify port mapping protocols and conflicts across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for port mapping protocols and conflicts. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Map TCP/UDP, wildcard/specific host addresses, duplicate ports, disabled mapping, and update/reset. + +**Expected results:** + +- Valid forwarding reaches the correct VM; conflicts are rejected before launch and stale rules disappear after update/removal. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md new file mode 100644 index 000000000..4f954f033 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-003: NUMA pinning hugepages and resource isolation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-vmm-compute-ne-003](../../../feature-audit.md#req-vmm-compute-ne-003) +- Risks: [risk-vmm-compute-ne-003](../../../feature-audit.md#risk-vmm-compute-ne-003) +- Source: `dstack/vmm/src/app/qemu.rs` + +## Objective + +Verify numa pinning hugepages and resource isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for numa pinning hugepages and resource isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Launch VMs with pin_numa/hugepages across valid and insufficient host resources. + +**Expected results:** + +- QEMU CPU/memory placement matches policy; exhaustion fails cleanly and other VMs retain resources. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md new file mode 100644 index 000000000..bf4111432 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-004: GPU discovery attach modes and ownership + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-vmm-compute-ne-004](../../../feature-audit.md#req-vmm-compute-ne-004) +- Risks: [risk-vmm-compute-ne-004](../../../feature-audit.md#risk-vmm-compute-ne-004) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify gpu discovery attach modes and ownership across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gpu discovery attach modes and ownership. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +List and attach valid, duplicate, busy, absent, and multi-GPU slots using supported modes. + +**Expected results:** + +- IOMMU/device binding and QEMU args are correct; exclusive ownership is enforced and restored on stop/failure. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md new file mode 100644 index 000000000..a19618b30 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-005: Local image discovery metadata and deletion + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-compute-ne-005](../../../feature-audit.md#req-vmm-compute-ne-005) +- Risks: [risk-vmm-compute-ne-005](../../../feature-audit.md#risk-vmm-compute-ne-005) +- Source: `dstack/vmm/src/discovery.rs` + +## Objective + +Verify local image discovery metadata and deletion across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for local image discovery metadata and deletion. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Discover valid/invalid image directories, list metadata, delete unused/used images. + +**Expected results:** + +- Only valid manifests appear; deletion is safe, rejects in-use images, and cannot escape configured roots. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md new file mode 100644 index 000000000..1e673e471 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-006: Registry authentication pull and extraction + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-compute-ne-006](../../../feature-audit.md#req-vmm-compute-ne-006) +- Risks: [risk-vmm-compute-ne-006](../../../feature-audit.md#risk-vmm-compute-ne-006) +- Source: `dstack/vmm/src/app/registry.rs` + +## Objective + +Verify registry authentication pull and extraction across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for registry authentication pull and extraction. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +List/pull public and bearer-token registries with multilayer images and malicious paths. + +**Expected results:** + +- Tags and manifests resolve, layers verify/extract atomically, traversal is rejected, and interrupted downloads do not become usable. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md new file mode 100644 index 000000000..3590b2e4c --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-COMPUTE-NE-007: QEMU command and platform matrix + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-vmm-compute-ne-007](../../../feature-audit.md#req-vmm-compute-ne-007) +- Risks: [risk-vmm-compute-ne-007](../../../feature-audit.md#risk-vmm-compute-ne-007) +- Source: `dstack/vmm/src/app/qemu.rs` + +## Objective + +Verify qemu command and platform matrix across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for qemu command and platform matrix. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Generate launches for TDX full/lite, SNP, GCP TDX, Nitro TPM, no-TEE, swtpm, GPU, and networking combinations. + +**Expected results:** + +- Machine type, firmware, devices, confidential-guest objects, shares, and vm_config measurements agree for every supported matrix row. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md new file mode 100644 index 000000000..7f9473352 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-VOLUME-008: Measured verity volume extraction resolution and path safety + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-volume-008](../../../feature-audit.md#req-vmm-volume-008) +- Risks: [risk-vmm-volume-008](../../../feature-audit.md#risk-vmm-volume-008) +- Source: `dstack/vmm/src/main_service.rs` + +## Objective + +Verify measured verity volume extraction resolution and path safety using the complete source-defined decision matrix and independently observable output. + +## Preconditions + +1. Record candidate and pinned historical image/compose/config versions plus baseline identity, measurements, processes, files and public status. +2. Use isolated run-scoped inputs and retain native redacted output. + +## Test Data + +Build a table with one row for every condition named in Step 1, including each condition alone and security-relevant conflicting combinations. + +## Steps + + +### Step 1: Execute the full decision matrix + +Exercise zero/one/multiple/duplicate verity volumes, relative and absolute sources, symlink escape, `..`, QEMU metacharacters, missing/wrong hash, update and rollback. + +**Expected results:** + +- Only measured sources inside configured volume roots attach once, volume count/content bind measurement config, traversal/metachar/missing/hash mismatch fails before QEMU, and unrelated compose fields remain opaque. + + +### Step 2: Verify the selected state end to end + +Compare parser/validation output, persisted manifest/config, generated measurement inputs, launch arguments, guest-visible state and public status for every accepted row. + +**Expected results:** + +- Every representation agrees with the selected row, no rejected value is partially persisted or launched, and unrelated inputs do not change measured identity. + + +### Step 3: Verify failure recovery and version compatibility + +Restart after accepted/rejected rows, replay applicable v0.5.4/v0.5.8/v0.5.11 inputs, and retry after correcting one invalid field. + +**Expected results:** + +- Supported historical defaults remain stable, unsupported combinations fail before secret/device consumption, restart reconstructs the same decision and corrected retry succeeds without stale state. + +## Postconditions + +Remove run-scoped VMs/files/devices and verify baseline restoration. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md new file mode 100644 index 000000000..b09cd7900 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-SERIAL-006: Serial log separator rotation history and follow continuity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-serial-006](../../../feature-audit.md#req-vmm-serial-006) +- Risks: [risk-vmm-serial-006](../../../feature-audit.md#risk-vmm-serial-006) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify serial log separator rotation history and follow continuity using the complete source-defined decision matrix and independently observable output. + +## Preconditions + +1. Record candidate and pinned historical image/compose/config versions plus baseline identity, measurements, processes, files and public status. +2. Use isolated run-scoped inputs and retain native redacted output. + +## Test Data + +Build a table with one row for every condition named in Step 1, including each condition alone and security-relevant conflicting combinations. + +## Steps + + +### Step 1: Execute the full decision matrix + +Boot/reboot/crash until serial history exceeds configured maximum; read current/history/tail/follow during rotation, partial lines, ANSI/binary bytes and concurrent readers. + +**Expected results:** + +- Each boot separator occurs once, rotation bounds storage without corrupting current log, history ordering is preserved, follow has no gap/duplication and reader input cannot alter paths/files. + + +### Step 2: Verify the selected state end to end + +Compare parser/validation output, persisted manifest/config, generated measurement inputs, launch arguments, guest-visible state and public status for every accepted row. + +**Expected results:** + +- Every representation agrees with the selected row, no rejected value is partially persisted or launched, and unrelated inputs do not change measured identity. + + +### Step 3: Verify failure recovery and version compatibility + +Restart after accepted/rejected rows, replay applicable v0.5.4/v0.5.8/v0.5.11 inputs, and retry after correcting one invalid field. + +**Expected results:** + +- Supported historical defaults remain stable, unsupported combinations fail before secret/device consumption, restart reconstructs the same decision and corrected retry succeeds without stale state. + +## Postconditions + +Remove run-scoped VMs/files/devices and verify baseline restoration. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md new file mode 100644 index 000000000..0618d512a --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-UI-OBSERVA-001: Status filtering pagination and event history + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-ui-observa-001](../../../feature-audit.md#req-vmm-ui-observa-001) +- Risks: [risk-vmm-ui-observa-001](../../../feature-audit.md#risk-vmm-ui-observa-001) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify status filtering pagination and event history across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for status filtering pagination and event history. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +List by IDs, keyword, brief/full, pages, and status during lifecycle changes. + +**Expected results:** + +- Totals/pages/filters are stable; brief omits config; uptime, progress, errors, interfaces, image version, and ordered events are correct. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md new file mode 100644 index 000000000..fcb1a8c89 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-UI-OBSERVA-002: Console log channels follow and ANSI handling + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-ui-observa-002](../../../feature-audit.md#req-vmm-ui-observa-002) +- Risks: [risk-vmm-ui-observa-002](../../../feature-audit.md#risk-vmm-ui-observa-002) +- Source: `dstack/vmm/src/main_routes.rs` + +## Objective + +Verify console log channels follow and ansi handling across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for console log channels follow and ansi handling. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Read stdout/stderr/serial logs with lines/follow/ANSI and invalid VM/channel. + +**Expected results:** + +- Historical tail and live continuation have no gap/duplication; ANSI policy works and cross-VM/path access is rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md new file mode 100644 index 000000000..adb235e5a --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-UI-OBSERVA-003: Host sealing-key provider integration + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-vmm-ui-observa-003](../../../feature-audit.md#req-vmm-ui-observa-003) +- Risks: [risk-vmm-ui-observa-003](../../../feature-audit.md#risk-vmm-ui-observa-003) +- Source: `dstack/vmm/src/host_api_service.rs` + +## Objective + +Verify host sealing-key provider integration across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for host sealing-key provider integration. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request sealing keys with valid/invalid quotes and provider failure. + +**Expected results:** + +- Encrypted key binds to verified evidence, provider quote is returned, and failures never return plaintext or stale keys. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md new file mode 100644 index 000000000..a58962658 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-UI-OBSERVA-004: Supervisor passthrough operations + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-ui-observa-004](../../../feature-audit.md#req-vmm-ui-observa-004) +- Risks: [risk-vmm-ui-observa-004](../../../feature-audit.md#risk-vmm-ui-observa-004) +- Source: `dstack/vmm/src/main_service.rs` + +## Objective + +Verify supervisor passthrough operations across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for supervisor passthrough operations. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +List, stop, and remove supervisor workloads through VMM. + +**Expected results:** + +- Operations target the requested workload, reflect terminal state, and reject unknown IDs without affecting CVMs. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md new file mode 100644 index 000000000..ac1f0356d --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-UI-OBSERVA-005: Web UI deployment workflows + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-ui-observa-005](../../../feature-audit.md#req-vmm-ui-observa-005) +- Risks: [risk-vmm-ui-observa-005](../../../feature-audit.md#risk-vmm-ui-observa-005) +- Source: `dstack/vmm/ui/src` + +## Objective + +Verify web ui deployment workflows across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for web ui deployment workflows. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Use UI to create, inspect, update, start/stop, resize, view logs, select simulated platform, networking, GPU, and images. + +**Expected results:** + +- UI payloads match RPC schema, display server errors/status accurately, preserve unset-vs-default fields, and remain keyboard usable. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md b/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md new file mode 100644 index 000000000..af0c1c805 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-MANIFEST-001: Proxied GuestApi transport and VM targeting + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-manifest-001](../../../feature-audit.md#req-vmm-manifest-001) +- Risks: [risk-vmm-manifest-001](../../../feature-audit.md#risk-vmm-manifest-001) +- Source: `dstack/vmm/src/guest_api_service.rs` + +## Objective + +Verify proxied guestapi transport and vm targeting with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Call Info/SysInfo/NetworkInfo/ListContainers/Shutdown for running, stopped, unknown, and concurrently removed VM IDs through VMM. + +**Expected results:** + +- Every request reaches only the selected guest, preserves response/error semantics and deadlines, and a disappearing VM cannot redirect the request to another socket. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md b/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md new file mode 100644 index 000000000..162974fcc --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-MANIFEST-002: Manifest persistence and QEMU/vm_config agreement + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-manifest-002](../../../feature-audit.md#req-vmm-manifest-002) +- Risks: [risk-vmm-manifest-002](../../../feature-audit.md#risk-vmm-manifest-002) +- Source: `dstack/vmm/src/app/workdir.rs` + +## Objective + +Verify manifest persistence and qemu/vm_config agreement with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Compare requested RPC configuration, persisted manifest, generated sys/simulator config, QEMU argv, verifier measurement inputs, and Status after create/update/reload. + +**Expected results:** + +- Every security-relevant effective value has one consistent representation; defaults and presence-sensitive fields do not drift across restart or serialization. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md new file mode 100644 index 000000000..04f1ae570 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-001: Host-share disk creation and content bounds + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-internal-001](../../../feature-audit.md#req-vmm-internal-001) +- Risks: [risk-vmm-internal-001](../../../feature-audit.md#risk-vmm-internal-001) +- Source: `dstack/vmm/src/app/host_share.rs` + +## Objective + +Verify host-share disk creation and content bounds exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Create the 128 MiB shared disk with normal, maximum, oversized, sparse, symlinked, missing and permission-denied content. + +**Expected results:** + +- Filesystem content and labels are deterministic, cannot escape source root or exceed capacity, and failed creation is not attached. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md new file mode 100644 index 000000000..f175e7fb0 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-002: Numeric ID pool allocation reuse and exhaustion + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-internal-002](../../../feature-audit.md#req-vmm-internal-002) +- Risks: [risk-vmm-internal-002](../../../feature-audit.md#risk-vmm-internal-002) +- Source: `dstack/vmm/src/app/id_pool.rs` + +## Objective + +Verify numeric id pool allocation reuse and exhaustion exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Allocate/occupy/free/clear boundary IDs, duplicates, exhausted ranges and concurrent VM/network allocations. + +**Expected results:** + +- IDs are unique and range-bounded, occupied IDs cannot be reused, free is safe, and restart reconstruction prevents live collisions. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md new file mode 100644 index 000000000..ff609c194 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-003: Image metadata parsing and firmware selection + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-internal-003](../../../feature-audit.md#req-vmm-internal-003) +- Risks: [risk-vmm-internal-003](../../../feature-audit.md#risk-vmm-internal-003) +- Source: `dstack/vmm/src/app/image.rs` + +## Objective + +Verify image metadata parsing and firmware selection exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Load full/minimal metadata, version naming fallbacks, missing artifacts, invalid versions, TDX/SNP firmware choices and symlink/path attacks. + +**Expected results:** + +- Only complete trusted images load; semantic version and platform firmware selection are correct and paths remain inside the image root. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md new file mode 100644 index 000000000..5f844497c --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-004: MR config and SNP host-data construction + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-internal-004](../../../feature-audit.md#req-vmm-internal-004) +- Risks: [risk-vmm-internal-004](../../../feature-audit.md#risk-vmm-internal-004) +- Source: `dstack/vmm/src/app/mr_config.rs` + +## Objective + +Verify mr config and snp host-data construction exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Generate TDX MR config IDs and SNP host_data across compose/image/app/GPU changes and repeated identical inputs. + +**Expected results:** + +- Outputs are deterministic, bind every documented input, match KMS/verifier computation, and a changed security input changes the expected digest. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md new file mode 100644 index 000000000..09e0f23ac --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-005: VM status protobuf projection and URL construction + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-internal-005](../../../feature-audit.md#req-vmm-internal-005) +- Risks: [risk-vmm-internal-005](../../../feature-audit.md#risk-vmm-internal-005) +- Source: `dstack/vmm/src/app/vm_info.rs` + +## Objective + +Verify vm status protobuf projection and url construction exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Project running/stopped/exited/brief/full VMs, empty optionals, custom/default gateway URLs, multiple networks and event timestamps. + +**Expected results:** + +- Every status field, optional presence, networking backend, app URL, uptime and event is correct without stale or empty-present values. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md new file mode 100644 index 000000000..708b60c63 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-006: One-shot VM execution and cleanup + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-vmm-internal-006](../../../feature-audit.md#req-vmm-internal-006) +- Risks: [risk-vmm-internal-006](../../../feature-audit.md#risk-vmm-internal-006) +- Source: `dstack/vmm/src/one_shot.rs` + +## Objective + +Verify one-shot vm execution and cleanup exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Run a valid one-shot workload plus compose parse, launch, guest failure, timeout and signal interruption. + +**Expected results:** + +- Exit status reflects workload/tool failure, temporary VM/resources are removed on every path, and no daemon-managed VM is affected. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md new file mode 100644 index 000000000..22d1aa370 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-007: Generated OpenAPI contract fidelity + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-internal-007](../../../feature-audit.md#req-vmm-internal-007) +- Risks: [risk-vmm-internal-007](../../../feature-audit.md#risk-vmm-internal-007) +- Source: `dstack/vmm/src/openapi.rs` + +## Objective + +Verify generated openapi contract fidelity exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Generate OpenAPI at the candidate version and compare every RPC route, schema field, optionality, enum, auth and error representation to protobuf/runtime. + +**Expected results:** + +- Documented and runtime contracts match, version is current, and incompatible schema drift is detected by the test. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md new file mode 100644 index 000000000..0745c9254 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md @@ -0,0 +1,69 @@ + + + +# TC-VMM-INTERNAL-008: Launcher QEMU and swtpm coupled lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-vmm-internal-008](../../../feature-audit.md#req-vmm-internal-008) +- Risks: [risk-vmm-internal-008](../../../feature-audit.md#risk-vmm-internal-008) +- Source: `dstack/vmm/src/vm_launcher.rs` + +## Objective + +Verify launcher qemu and swtpm coupled lifecycle exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Launch QEMU alone and with swtpm; delay/miss socket readiness; crash either process; exceed startup/shutdown deadlines; send termination. + +**Expected results:** + +- Readiness gates QEMU correctly, either child failure terminates/reaps the other, sockets are removed, and no PID or process-group leak remains. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/02-vmm/09-vmm-build/tc-vmm-build-001/case.md b/docs/test-plans/core-components-full/02-vmm/09-vmm-build/tc-vmm-build-001/case.md new file mode 100644 index 000000000..e93001712 --- /dev/null +++ b/docs/test-plans/core-components-full/02-vmm/09-vmm-build/tc-vmm-build-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VMM-BUILD-001: VMM Build, CLI, UI, and Existing Regression Suite + +## Metadata + +- Priority: P0 +- Type: Build, Regression, Supply Chain, Security +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-vmm-build-001](../../../feature-audit.md#req-vmm-build-001) +- Risks: [risk-vmm-build-001](../../../feature-audit.md#risk-vmm-build-001) +- Source: `dstack/vmm` + +## Objective + +Verify the complete component build, generated-interface, packaging, existing-test, and supply-chain baseline before product-level cases rely on the candidate. + +## Preconditions + +1. Use a clean checkout, empty component build caches, pinned toolchains, and recorded dependency mirrors. +2. Do not update locks or generated files during the test; capture any dirty working-tree diff. + +## Test Data + +Use the candidate commit, committed fixtures, lock files, image recipes, generated protobuf/OpenAPI sources, and all component-native test configurations. + +## Steps + + +### Step 1: Build from clean state + +Build Rust RPC/server, Python CLI and TypeScript UI from clean generated protobuf/OpenAPI inputs; run all unit/integration/UI checks and smoke every vmm-cli operation against isolated VMM. + +**Expected results:** + +- Generated clients/docs match protobuf, packages lock dependencies, all tests pass, and CLI/UI produce the same requests, errors and presence semantics as direct RPC. + + +### Step 2: Verify generated and packaged artifacts + +Regenerate interfaces into a temporary tree, compare with committed output, inspect licenses/SBOM/locks/image contents and repeat the build with network disabled after dependency fetch. + +**Expected results:** + +- Generated output has no unexplained diff, offline rebuild succeeds from pins, required licenses are present, and packages contain only declared runtime/test content. + + +### Step 3: Verify failure detection + +Introduce one temporary source/test-fixture/schema/config mismatch outside the committed tree and confirm the relevant build/test/generation gate fails, then restore and rerun. + +**Expected results:** + +- The gate detects the controlled regression with a specific error and returns to a clean passing result after restoration. + +## Postconditions + +Remove temporary build/output trees and verify the candidate checkout remains clean. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-001/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-001/case.md new file mode 100644 index 000000000..f16b49f2a --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-001: KMS.GetAppKey + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-001](../../../feature-audit.md#req-kms-kms-001) +- Risks: [risk-kms-kms-001](../../../feature-audit.md#risk-kms-kms-001) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:97` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.GetAppKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.GetAppKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.getappkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.GetAppKey` with a valid `GetAppKeyRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AppKeyResponse` with every documented field and exhibits the documented `GetAppKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-002/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-002/case.md new file mode 100644 index 000000000..7c7b1dc7e --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-002: KMS.GetKmsKey + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-002](../../../feature-audit.md#req-kms-kms-002) +- Risks: [risk-kms-kms-002](../../../feature-audit.md#risk-kms-kms-002) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:99` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.GetKmsKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.GetKmsKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.getkmskey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.GetKmsKey` with a valid `GetKmsKeyRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `KmsKeyResponse` with every documented field and exhibits the documented `GetKmsKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-003/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-003/case.md new file mode 100644 index 000000000..42b22d380 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-003: KMS.GetAppEnvEncryptPubKey + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-003](../../../feature-audit.md#req-kms-kms-003) +- Risks: [risk-kms-kms-003](../../../feature-audit.md#risk-kms-kms-003) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:101` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.GetAppEnvEncryptPubKey`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.GetAppEnvEncryptPubKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.getappenvencryptpubkey. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.GetAppEnvEncryptPubKey` with a valid `AppId` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `PublicKeyResponse` with every documented field and exhibits the documented `GetAppEnvEncryptPubKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-004/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-004/case.md new file mode 100644 index 000000000..5b394fbe0 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-004: KMS.GetMeta + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-004](../../../feature-audit.md#req-kms-kms-004) +- Risks: [risk-kms-kms-004](../../../feature-audit.md#risk-kms-kms-004) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:103` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.GetMeta`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.GetMeta` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.getmeta. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.GetMeta` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetMetaResponse` with every documented field and exhibits the documented `GetMeta` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-005/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-005/case.md new file mode 100644 index 000000000..7e6a67da9 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-005: KMS.GetTempCaCert + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-005](../../../feature-audit.md#req-kms-kms-005) +- Risks: [risk-kms-kms-005](../../../feature-audit.md#risk-kms-kms-005) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:105` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.GetTempCaCert`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.GetTempCaCert` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.gettempcacert. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.GetTempCaCert` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetTempCaCertResponse` with every documented field and exhibits the documented `GetTempCaCert` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-006/case.md b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-006/case.md new file mode 100644 index 000000000..770d10dbf --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/01-rpc-kms/tc-kms-kms-006/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KMS-006: KMS.SignCert + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-kms-006](../../../feature-audit.md#req-kms-kms-006) +- Risks: [risk-kms-kms-006](../../../feature-audit.md#risk-kms-kms-006) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:107` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `KMS.SignCert`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `KMS.SignCert` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms.signcert. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `KMS.SignCert` with a valid `SignCertRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `SignCertResponse` with every documented field and exhibits the documented `SignCert` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/02-rpc-admin/tc-kms-admin-001/case.md b/docs/test-plans/core-components-full/03-kms/02-rpc-admin/tc-kms-admin-001/case.md new file mode 100644 index 000000000..417111110 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/02-rpc-admin/tc-kms-admin-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ADMIN-001: Admin.ClearImageCache + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-admin-001](../../../feature-audit.md#req-kms-admin-001) +- Risks: [risk-kms-admin-001](../../../feature-audit.md#risk-kms-admin-001) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:116` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ClearImageCache`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ClearImageCache` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.clearimagecache. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ClearImageCache` with a valid `ClearImageCacheRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ClearImageCache` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md new file mode 100644 index 000000000..e0e7976de --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ONBOARD-001: Onboard.Bootstrap + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-onboard-001](../../../feature-audit.md#req-kms-onboard-001) +- Risks: [risk-kms-onboard-001](../../../feature-audit.md#risk-kms-onboard-001) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:167` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Onboard.Bootstrap`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Onboard.Bootstrap` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for onboard.bootstrap. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Onboard.Bootstrap` with a valid `BootstrapRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `BootstrapResponse` with every documented field and exhibits the documented `Bootstrap` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md new file mode 100644 index 000000000..cc56c79bd --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ONBOARD-002: Onboard.Onboard + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-onboard-002](../../../feature-audit.md#req-kms-onboard-002) +- Risks: [risk-kms-onboard-002](../../../feature-audit.md#risk-kms-onboard-002) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:169` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Onboard.Onboard`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Onboard.Onboard` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for onboard.onboard. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Onboard.Onboard` with a valid `OnboardRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `OnboardResponse` with every documented field and exhibits the documented `Onboard` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md new file mode 100644 index 000000000..44cb4e94f --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ONBOARD-003: Onboard.GetAttestationInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-onboard-003](../../../feature-audit.md#req-kms-onboard-003) +- Risks: [risk-kms-onboard-003](../../../feature-audit.md#risk-kms-onboard-003) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:171` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Onboard.GetAttestationInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Onboard.GetAttestationInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for onboard.getattestationinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Onboard.GetAttestationInfo` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AttestationInfoResponse` with every documented field and exhibits the documented `GetAttestationInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md new file mode 100644 index 000000000..343199b1e --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ONBOARD-004: Onboard.Finish + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-onboard-004](../../../feature-audit.md#req-kms-onboard-004) +- Risks: [risk-kms-onboard-004](../../../feature-audit.md#risk-kms-onboard-004) +- Source: `dstack/kms/rpc/proto/kms_rpc.proto:173` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Onboard.Finish`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Onboard.Finish` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for onboard.finish. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Onboard.Finish` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `Finish` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md new file mode 100644 index 000000000..e8d7ecdce --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-BOOTSTRAP--001: Fresh bootstrap key hierarchy + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-bootstrap--001](../../../feature-audit.md#req-kms-bootstrap--001) +- Risks: [risk-kms-bootstrap--001](../../../feature-audit.md#risk-kms-bootstrap--001) +- Source: `dstack/kms/src/onboard_service.rs` + +## Objective + +Verify fresh bootstrap key hierarchy across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for fresh bootstrap key hierarchy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Bootstrap a fresh KMS domain once and attempt duplicate/concurrent bootstrap. + +**Expected results:** + +- CA/k256 keys and attestation are generated once, stored securely, and duplicate bootstrap cannot replace the trust root. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md new file mode 100644 index 000000000..9aab129af --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-BOOTSTRAP--002: Onboard from existing KMS + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-bootstrap--002](../../../feature-audit.md#req-kms-bootstrap--002) +- Risks: [risk-kms-bootstrap--002](../../../feature-audit.md#risk-kms-bootstrap--002) +- Source: `dstack/kms/src/onboard_service.rs` + +## Objective + +Verify onboard from existing kms across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for onboard from existing kms. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Onboard a new KMS from a trusted source with valid and altered source evidence/domain. + +**Expected results:** + +- The new node inherits the expected root public key only after verification; tampering or wrong domain leaves it uninitialized. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md new file mode 100644 index 000000000..d451a252e --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-BOOTSTRAP--003: Finish onboarding and listener transition + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-bootstrap--003](../../../feature-audit.md#req-kms-bootstrap--003) +- Risks: [risk-kms-bootstrap--003](../../../feature-audit.md#risk-kms-bootstrap--003) +- Source: `dstack/kms/src/onboard_service.rs` + +## Objective + +Verify finish onboarding and listener transition across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for finish onboarding and listener transition. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Call Finish before/after valid bootstrap/onboard and restart service. + +**Expected results:** + +- Finish atomically persists keys/certs, disables onboarding exposure, enables main service, and survives restart. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md new file mode 100644 index 000000000..025ce4369 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-BOOTSTRAP--004: On-chain attestation information + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-bootstrap--004](../../../feature-audit.md#req-kms-bootstrap--004) +- Risks: [risk-kms-bootstrap--004](../../../feature-audit.md#risk-kms-bootstrap--004) +- Source: `dstack/kms/src/onboard_service.rs` + +## Objective + +Verify on-chain attestation information across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for on-chain attestation information. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Query provisioning identity for every supported TEE/auth configuration. + +**Expected results:** + +- Device ID, measurement, image hash, variant, PPID, site, chain, contract, and RPC URL match verified local state without secrets. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md new file mode 100644 index 000000000..b64240e57 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-ATTESTATIO-001: TDX full and lite app authorization + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-attestatio-001](../../../feature-audit.md#req-kms-attestatio-001) +- Risks: [risk-kms-attestatio-001](../../../feature-audit.md#risk-kms-attestatio-001) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify tdx full and lite app authorization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tdx full and lite app authorization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request app keys with valid and altered quote/event log/vm_config/image/compose inputs. + +**Expected results:** + +- Only evidence whose measurements and policy match is authorized; every altered binding is rejected before key derivation. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md new file mode 100644 index 000000000..4754dccd2 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-ATTESTATIO-002: SEV-SNP app authorization + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-attestatio-002](../../../feature-audit.md#req-kms-attestatio-002) +- Risks: [risk-kms-attestatio-002](../../../feature-audit.md#risk-kms-attestatio-002) +- Source: `dstack/kms/src/main_service/amd_attest.rs` + +## Objective + +Verify sev-snp app authorization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for sev-snp app authorization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise valid fixture/hardware plus altered measurement, report data, chip TCB, image and config. + +**Expected results:** + +- Certificate chain and report bind to expected app/image/config; tampering is rejected without cache poisoning. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md new file mode 100644 index 000000000..2d1f3a1ec --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-ATTESTATIO-003: GCP TDX and Nitro TPM authorization + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-attestatio-003](../../../feature-audit.md#req-kms-attestatio-003) +- Risks: [risk-kms-attestatio-003](../../../feature-audit.md#risk-kms-attestatio-003) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify gcp tdx and nitro tpm authorization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gcp tdx and nitro tpm authorization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise cloud-specific attestation, measured boot, vendor/product, and TPM evidence. + +**Expected results:** + +- Cloud identity and measurements are verified with platform-specific policy; cross-platform evidence is not accepted. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md new file mode 100644 index 000000000..0efbacc37 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-ATTESTATIO-004: Upgrade authority and allow_any_upgrade + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-attestatio-004](../../../feature-audit.md#req-kms-attestatio-004) +- Risks: [risk-kms-attestatio-004](../../../feature-audit.md#risk-kms-attestatio-004) +- Source: `dstack/kms/src/main_service/upgrade_authority.rs` + +## Objective + +Verify upgrade authority and allow_any_upgrade across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for upgrade authority and allow_any_upgrade. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Test same app, allowed image/config transition, unauthorized transition, and development override. + +**Expected results:** + +- Production follows authority responses and hashes; allow_any_upgrade applies only when configured and cannot authorize KMS self-upgrade incorrectly. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md new file mode 100644 index 000000000..053963743 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-ATTESTATIO-005: Authorization backend matrix + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-attestatio-005](../../../feature-audit.md#req-kms-attestatio-005) +- Risks: [risk-kms-attestatio-005](../../../feature-audit.md#risk-kms-attestatio-005) +- Source: `dstack/kms/auth-simple/index.ts` + +## Objective + +Verify authorization backend matrix across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `kms` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for authorization backend matrix. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Run mock, simple, Ethereum/Bun, and contract-backed authorization allow/deny/error/timeouts. + +**Expected results:** + +- Each backend maps identical app/KMS facts consistently, fails closed on malformed/timeout responses, and reports configured metadata. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-platform-006/case.md b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-platform-006/case.md new file mode 100644 index 000000000..024857c82 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/05-attestation-authorization/tc-kms-platform-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-PLATFORM-006: Nitro Enclave app and KMS authorization + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-platform-006](../../../feature-audit.md#req-kms-platform-006) +- Risks: [risk-kms-platform-006](../../../feature-audit.md#risk-kms-platform-006) +- Source: `dstack/kms/src/main_service/amd_attest.rs` + +## Objective + +Verify nitro enclave app and kms authorization against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Exercise production and debug Nitro Enclave documents with valid/altered AWS chain, module ID, timestamp, nonce/user/public-key data, PCR0/1/2/4, vm_config image/app/config binding and authorization allow/deny. + +**Expected results:** + +- Only a non-debug fresh document with trusted AWS chain, expected PCR/image/config/app bindings and positive policy is authorized; debug zero-PCR or any mutation receives no app/KMS key. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md new file mode 100644 index 000000000..dec820efc --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-APIVER-011: GetAppKey and SignCert API-version compatibility + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-apiver-011](../../../feature-audit.md#req-kms-apiver-011) +- Risks: [risk-kms-apiver-011](../../../feature-audit.md#risk-kms-apiver-011) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify getappkey and signcert api-version compatibility against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Call GetAppKey api_version 0/1/2/maximum and SignCert v1/v2/unknown using valid and cross-version encoded CSR/signatures; compare v1→v2 conversion, chain and legacy gateway fields. + +**Expected results:** + +- GetAppKey accepts only documented versions, SignCert v1/v2 yield equivalent authorized certificate semantics, unknown/cross-encoded versions fail, and legacy/current gateway fields remain consistent. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md new file mode 100644 index 000000000..d279eaa3f --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-001: Per-app key hierarchy isolation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-keys-certs-001](../../../feature-audit.md#req-kms-keys-certs-001) +- Risks: [risk-kms-keys-certs-001](../../../feature-audit.md#risk-kms-keys-certs-001) +- Source: `dstack/kms/src/crypto.rs` + +## Objective + +Verify per-app key hierarchy isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for per-app key hierarchy isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Retrieve app keys across apps, instances, upgrades, and repeated boots. + +**Expected results:** + +- Disk/env/k256 keys are stable or rotated exactly by policy, signature verifies under root, and no app receives another app key. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md new file mode 100644 index 000000000..c62db84ce --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-002: Environment public-key freshness signatures + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-keys-certs-002](../../../feature-audit.md#req-kms-keys-certs-002) +- Risks: [risk-kms-keys-certs-002](../../../feature-audit.md#risk-kms-keys-certs-002) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify environment public-key freshness signatures across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for environment public-key freshness signatures. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request env encryption public keys repeatedly and verify legacy and timestamped signatures. + +**Expected results:** + +- Public key matches app decryption key; timestamp is current; both domain-separated signatures verify and replay policy rejects stale responses. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md new file mode 100644 index 000000000..5c26d2abb --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-003: KMS key handover and rotation chain + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-keys-certs-003](../../../feature-audit.md#req-kms-keys-certs-003) +- Risks: [risk-kms-keys-certs-003](../../../feature-audit.md#risk-kms-keys-certs-003) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify kms key handover and rotation chain across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms key handover and rotation chain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Request GetKmsKey from authorized/unauthorized KMS across current and historical keys. + +**Expected results:** + +- Temporary CA wrapping and ordered key set allow authorized continuity; app callers and altered configs receive no root material. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md new file mode 100644 index 000000000..3655e6da1 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-004: Certificate signing CSR and app binding + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-keys-certs-004](../../../feature-audit.md#req-kms-keys-certs-004) +- Risks: [risk-kms-keys-certs-004](../../../feature-audit.md#risk-kms-keys-certs-004) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify certificate signing csr and app binding across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for certificate signing csr and app binding. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Submit valid CSR/signature/vm_config plus altered CSR, key, app, usages, and validity. + +**Expected results:** + +- Issued chain binds CSR key and authorized app under CA constraints; invalid proof is rejected and CA private key never leaves KMS. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md new file mode 100644 index 000000000..4dfa641e9 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-005: Temporary CA lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-keys-certs-005](../../../feature-audit.md#req-kms-keys-certs-005) +- Risks: [risk-kms-keys-certs-005](../../../feature-audit.md#risk-kms-keys-certs-005) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify temporary ca lifecycle across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for temporary ca lifecycle. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Retrieve temporary CA credentials during permitted onboarding and after finish/restart. + +**Expected results:** + +- Returned certificate/key match and chain to root only in the intended phase; exposure closes after transition according to policy. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md new file mode 100644 index 000000000..0e90c3594 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-006: Image measurement cache clear and refill + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-keys-certs-006](../../../feature-audit.md#req-kms-keys-certs-006) +- Risks: [risk-kms-keys-certs-006](../../../feature-audit.md#risk-kms-keys-certs-006) +- Source: `dstack/kms/src/admin_service.rs` + +## Objective + +Verify image measurement cache clear and refill across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for image measurement cache clear and refill. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Populate positive/negative image/config cache, clear specific/all selectors with admin auth, then reverify. + +**Expected results:** + +- Only selected entries disappear, next verification recomputes, and unauthorized clear has no effect. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md new file mode 100644 index 000000000..f61a7d6a9 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md @@ -0,0 +1,62 @@ + + + +# TC-KMS-KEYS-CERTS-007: Admin authentication transports + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-keys-certs-007](../../../feature-audit.md#req-kms-keys-certs-007) +- Risks: [risk-kms-keys-certs-007](../../../feature-audit.md#risk-kms-keys-certs-007) +- Source: `dstack/kms/src/admin_auth.rs` + +## Objective + +Verify admin authentication transports across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `kms` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin authentication transports. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Call admin endpoint with Authorization bearer, X-Admin-Token, conflicting, missing, and malformed credentials. + +**Expected results:** + +- Accepted forms follow constant-time policy; conflicts/missing/wrong tokens are rejected without body logging or timing-visible prefix matches. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md new file mode 100644 index 000000000..09c2ad350 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-008: Metrics metadata and failure diagnostics + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-keys-certs-008](../../../feature-audit.md#req-kms-keys-certs-008) +- Risks: [risk-kms-keys-certs-008](../../../feature-audit.md#risk-kms-keys-certs-008) +- Source: `dstack/kms/src/config.rs` + +## Objective + +Verify metrics metadata and failure diagnostics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for metrics metadata and failure diagnostics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise GetMeta/health and metrics before/after authorization success, denial, cache use, and backend failure. + +**Expected results:** + +- Non-secret configuration and counters are accurate; error classes are actionable without evidence, key, token, or CSR secret leakage. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md new file mode 100644 index 000000000..82bcc111e --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-KEYS-CERTS-009: Crash consistency and backup recovery + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-keys-certs-009](../../../feature-audit.md#req-kms-keys-certs-009) +- Risks: [risk-kms-keys-certs-009](../../../feature-audit.md#risk-kms-keys-certs-009) +- Source: `dstack/kms/src/onboard_service.rs` + +## Objective + +Verify crash consistency and backup recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for crash consistency and backup recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Interrupt bootstrap/onboard/key persistence and restore from supported backup. + +**Expected results:** + +- Atomic files never expose partial keys; restart either resumes safely or fails closed; restored identity matches original trust anchors. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-release-010/case.md b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-release-010/case.md new file mode 100644 index 000000000..b185a8918 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/06-keys-certs-operations/tc-kms-release-010/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RELEASE-010: Platform-specific key-release feature gates + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-release-010](../../../feature-audit.md#req-kms-release-010) +- Risks: [risk-kms-release-010](../../../feature-audit.md#risk-kms-release-010) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify platform-specific key-release feature gates against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +For SEV-SNP and AWS Nitro TPM app, KMS and temp-CA requests, toggle `sev_snp_key_release` and `aws_nitro_tpm_key_release` independently; include TDX, GCP TDX and Nitro Enclave controls. + +**Expected results:** + +- SNP and Nitro-TPM private material is released only when its explicit gate and all authorization checks pass; one platform gate never affects another and disabling never returns partial key fields. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-001/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-001/case.md new file mode 100644 index 000000000..b87d46e55 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-001: Simple authorization configuration rules + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-001](../../../feature-audit.md#req-kms-auth-001) +- Risks: [risk-kms-auth-001](../../../feature-audit.md#risk-kms-auth-001) +- Source: `dstack/kms/auth-simple` + +## Objective + +Verify simple authorization configuration rules with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Load allow/deny entries, defaults, duplicate/conflicting app/image/config rules, hot update, malformed file, and missing file. + +**Expected results:** + +- The documented most-specific rule is deterministic, malformed/conflicting state fails closed, and reload is atomic without transient allow. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-002/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-002/case.md new file mode 100644 index 000000000..648f97f1c --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-002: Mock authorization safety boundary + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-kms-auth-002](../../../feature-audit.md#req-kms-auth-002) +- Risks: [risk-kms-auth-002](../../../feature-audit.md#risk-kms-auth-002) +- Source: `dstack/kms/auth-mock` + +## Objective + +Verify mock authorization safety boundary with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Run mock auth in development and attempt the same configuration in a production-marked deployment. + +**Expected results:** + +- Mock decisions are deterministic for tests, visibly identify development mode, and production startup or policy rejects mock authorization. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-003/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-003/case.md new file mode 100644 index 000000000..2190ce018 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-003: Ethereum authorization request signatures and replay + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-003](../../../feature-audit.md#req-kms-auth-003) +- Risks: [risk-kms-auth-003](../../../feature-audit.md#risk-kms-auth-003) +- Source: `dstack/kms/auth-eth-bun/index.ts` + +## Objective + +Verify ethereum authorization request signatures and replay with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Submit valid and altered app/KMS authorization payloads, signer, chain ID, contract address, nonce/timestamp, duplicate, and replayed requests. + +**Expected results:** + +- Only domain-separated fresh authorized signatures are accepted and replay/cross-chain/cross-contract substitutions fail. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-004/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-004/case.md new file mode 100644 index 000000000..a4ddd0af0 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-004: KMS contract ownership roles and upgrade controls + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-004](../../../feature-audit.md#req-kms-auth-004) +- Risks: [risk-kms-auth-004](../../../feature-audit.md#risk-kms-auth-004) +- Source: `dstack/kms/auth-eth/contracts` + +## Objective + +Verify kms contract ownership roles and upgrade controls with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Exercise owner/admin/operator actions, role transfer/revocation, pause, implementation upgrade, initialization, and unauthorized callers. + +**Expected results:** + +- Only assigned roles mutate policy; initialization is single-use; upgrades preserve storage and cannot bypass authorization or seize ownership. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-005/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-005/case.md new file mode 100644 index 000000000..ff649f329 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-005/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-005: KMS node registration and authorization lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-auth-005](../../../feature-audit.md#req-kms-auth-005) +- Risks: [risk-kms-auth-005](../../../feature-audit.md#risk-kms-auth-005) +- Source: `dstack/kms/auth-eth/contracts` + +## Objective + +Verify kms node registration and authorization lifecycle with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Register, approve, revoke, and replace KMS device/measurement/image identities and query before/after confirmations. + +**Expected results:** + +- Only fully authorized current node identity receives handover; revocation is effective at the defined confirmation point and stale nodes fail. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-006/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-006/case.md new file mode 100644 index 000000000..b32aa1021 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-006/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-006: Application boot policy image and config matrix + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-006](../../../feature-audit.md#req-kms-auth-006) +- Risks: [risk-kms-auth-006](../../../feature-audit.md#risk-kms-auth-006) +- Source: `dstack/kms/auth-eth/contracts` + +## Objective + +Verify application boot policy image and config matrix with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Create app policies across image/config allowlists, wildcard/upgrade flags, duplicate hashes, revocation, and rollback. + +**Expected results:** + +- Contract and API return the same deterministic decision and unauthorized image/config/rollback cannot obtain app keys. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-007/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-007/case.md new file mode 100644 index 000000000..24a8bc820 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-007/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-007: Ethereum RPC failure reorg and finality handling + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-007](../../../feature-audit.md#req-kms-auth-007) +- Risks: [risk-kms-auth-007](../../../feature-audit.md#risk-kms-auth-007) +- Source: `dstack/kms/auth-eth-bun/index.ts` + +## Objective + +Verify ethereum rpc failure reorg and finality handling with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Inject timeout, malformed response, wrong chain, stale head, short/deep reorg, and delayed confirmations around authorization. + +**Expected results:** + +- Authorization fails closed when state is uncertain, waits configured finality, invalidates reorged cache entries, and recovers on canonical state. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-008/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-008/case.md new file mode 100644 index 000000000..94c861ed5 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-008/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-008: Authorization API schema and error compatibility + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-008](../../../feature-audit.md#req-kms-auth-008) +- Risks: [risk-kms-auth-008](../../../feature-audit.md#risk-kms-auth-008) +- Source: `dstack/kms/auth-eth-bun/openapi.json` + +## Objective + +Verify authorization api schema and error compatibility with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Cross-call Rust KMS with previous/current mock/simple/Ethereum API implementations using optional/unknown fields and structured errors. + +**Expected results:** + +- Supported versions agree on facts and decisions; unknown required versions fail explicitly and backend details do not leak credentials. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-009/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-009/case.md new file mode 100644 index 000000000..55171b882 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-009/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-009: Contract event audit completeness + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-009](../../../feature-audit.md#req-kms-auth-009) +- Risks: [risk-kms-auth-009](../../../feature-audit.md#risk-kms-auth-009) +- Source: `dstack/kms/auth-eth/contracts` + +## Objective + +Verify contract event audit completeness with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Perform every policy mutation and reconstruct effective authorization solely from ordered finalized events. + +**Expected results:** + +- Events include actor, affected identity and new state without secrets; reconstructed state equals contract queries across upgrade/reorg. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-010/case.md b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-010/case.md new file mode 100644 index 000000000..75da396d5 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/07-authorization-implementations/tc-kms-auth-010/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-AUTH-010: Authorization cache scope and invalidation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-auth-010](../../../feature-audit.md#req-kms-auth-010) +- Risks: [risk-kms-auth-010](../../../feature-audit.md#risk-kms-auth-010) +- Source: `dstack/kms/src/main_service/upgrade_authority.rs` + +## Objective + +Verify authorization cache scope and invalidation with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Authorize multiple apps/nodes, change contract/config policy, revoke one identity, expire TTL, and restart KMS. + +**Expected results:** + +- Cache keys include chain/contract/app/node/image/config and policy version; targeted changes invalidate affected decisions without cross-app reuse. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md new file mode 100644 index 000000000..1d39b8374 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-001: 0.5.4 to 0.6.0 through 0.5.7 bridge + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-001](../../../feature-audit.md#req-kms-upgrade-001) +- Risks: [risk-kms-upgrade-001](../../../feature-audit.md#risk-kms-upgrade-001) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove the required two-hop root-transfer path from a 0.5.4 source to the 0.6.0 candidate without disabling verification. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Boot a 0.5.7 bridge on dstack-0.5.7 in legacy TDX mode, onboard it from 0.5.4, then boot a 0.6.0 target in legacy mode and onboard it from the bridge. + +**Expected results:** + +- Both hops pass strict quote/measurement verification and the 0.6.0 target inherits the unchanged CA/root and existing application keys. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md new file mode 100644 index 000000000..486d1e7a5 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-002: Direct 0.5.4 to 0.6.0 incompatibility is explicit + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-002](../../../feature-audit.md#req-kms-upgrade-002) +- Risks: [risk-kms-upgrade-002](../../../feature-audit.md#risk-kms-upgrade-002) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Confirm the known RA-TLS OID boundary is rejected for the documented reason and cannot be bypassed. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Attempt direct onboard of a legacy-mode 0.6.0 target from 0.5.4 with otherwise correct allowlists and artifacts. + +**Expected results:** + +- Onboard fails before key transfer with the old source unable to extract the versioned attestation (`No attestation provided` or its structured equivalent); source state and target uninitialized state remain unchanged. + + +### Step 3: Verify rejection leaves both sides unchanged + +Repeat the source metadata and key-fingerprint probes, inspect the target certificate directory and bootstrap state, and confirm clients continue using the retained 0.5.4 endpoints. + +**Expected results:** + +- The source CA/root and app-derived outputs are byte-for-byte unchanged, the target has not stored transferred root material, and existing clients remain healthy through the retained source endpoints. + + +### Step 4: Prove the documented bridge is required + +Remove the rejected target, then execute `tc-kms-upgrade-001` with the pinned 0.5.7 bridge and the same 0.5.4 source root. Do not weaken RA-TLS verification, patch OID handling, or copy key files manually. + +**Expected results:** + +- The bridge path succeeds with normal attested key transfer and preserves the recorded source identity, demonstrating that direct rejection is the compatibility boundary rather than a transient deployment failure. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md new file mode 100644 index 000000000..aff82701a --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-003: 0.5.8 direct onboard to 0.6.0 + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-003](../../../feature-audit.md#req-kms-upgrade-003) +- Risks: [risk-kms-upgrade-003](../../../feature-audit.md#risk-kms-upgrade-003) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove a 0.5.8 source can directly onboard the 0.6.0 candidate under production verification. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Boot the 0.6.0 target on its matching OS with legacy TDX attestation and onboard directly from 0.5.8. + +**Expected results:** + +- Strict verification succeeds in one hop and root, CA, app-key, signing, and authorization continuity are preserved. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md new file mode 100644 index 000000000..a5f32aae9 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-004: kms-v0.5.11 direct onboard to 0.6.0 + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-004](../../../feature-audit.md#req-kms-upgrade-004) +- Risks: [risk-kms-upgrade-004](../../../feature-audit.md#risk-kms-upgrade-004) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove the selected 0.5.11 artifact can directly onboard the 0.6.0 candidate across OVMF-variant handling. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Record whether the source includes PR #693 metadata-version resolution, diagnose its OVMF path, then onboard a legacy-mode 0.6.0 target directly. + +**Expected results:** + +- The source resolves the target firmware/measurement inputs, strict onboard succeeds, and continuity matches the source. Any unpatched-artifact limitation is explicit rather than bypassed. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md new file mode 100644 index 000000000..201db9b77 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-005: Old source rejects 0.6.0 target in TDX-lite mode + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-005](../../../feature-audit.md#req-kms-upgrade-005) +- Risks: [risk-kms-upgrade-005](../../../feature-audit.md#risk-kms-upgrade-005) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove legacy-only source KMS nodes cannot accidentally authorize a lite-attestation target. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +For 0.5.4, 0.5.8, and 0.5.11 sources, boot an otherwise authorized 0.6.0 target with `tdx_attestation_variant=lite` (and separately `auto` resolving to lite) and attempt onboard. + +**Expected results:** + +- Every old source rejects the target before root transfer due to unreproducible legacy measurements; no fallback or verification-disable path is used. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md new file mode 100644 index 000000000..837ebbdd7 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-006: Legacy mode is forced throughout mixed-source cutover + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-006](../../../feature-audit.md#req-kms-upgrade-006) +- Risks: [risk-kms-upgrade-006](../../../feature-audit.md#risk-kms-upgrade-006) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify VMM and persisted target configuration cannot silently resolve `auto` to lite while any old source remains. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Deploy target candidates at boundary memory/image capabilities using explicit legacy and auto; inspect VMM manifest, QEMU arguments, vm_config, quote/event log and KMS diagnostics. + +**Expected results:** + +- The approved upgrade deployment explicitly records legacy end to end; auto/lite variants are detected and blocked from cutover while a pre-0.6 source verifies peers. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md new file mode 100644 index 000000000..4eb62cc4e --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-007: 0.5.4 age-matched ACPI diagnosis + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-007](../../../feature-audit.md#req-kms-upgrade-007) +- Risks: [risk-kms-upgrade-007](../../../feature-audit.md#risk-kms-upgrade-007) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove 0.5.4 bridge pre-flight uses its QEMU 9.1.50-era ACPI-table computation rather than the 0.6.0 tool. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Run `dstack-mr diagnose` on the same 0.5.4/bridge quote and vm_config with age-matched and 0.6.0 `dstack-acpi-tables`. + +**Expected results:** + +- The age-matched tool reports RTMR0 MATCH; the incompatible tool exposes the first divergent ACPI event and is not accepted as upgrade evidence. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md new file mode 100644 index 000000000..936c5fe83 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-008: Source and target allowlist completeness + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-008](../../../feature-audit.md#req-kms-upgrade-008) +- Risks: [risk-kms-upgrade-008](../../../feature-audit.md#risk-kms-upgrade-008) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify source/target mutual authorization and target-image availability are independently required. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Remove in turn the source MR, target MR, target image hash, and target archive reachability before onboard from 0.5.8/0.5.11; restore each and retry. + +**Expected results:** + +- Each omission fails closed at its corresponding pre-flight/onboard stage without key transfer; complete authorization succeeds and does not require global allow-any-upgrade. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md new file mode 100644 index 000000000..293281512 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-009: Mixed-version KMS endpoint service consistency + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-009](../../../feature-audit.md#req-kms-upgrade-009) +- Risks: [risk-kms-upgrade-009](../../../feature-audit.md#risk-kms-upgrade-009) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Operate 0.5.4, 0.5.7 bridge, 0.5.8, 0.5.11 and successfully onboarded 0.6.0 nodes as applicable behind client URL lists. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Route GetMeta, existing/new GetAppKey, env public key, SignCert and permitted handover traffic to each compatible endpoint, including endpoint failure and recovery. + +**Expected results:** + +- Compatible endpoints expose the same root/CA and app identity; clients fail over without rekey, replay, or schema confusion; operations unsupported by an old endpoint fail explicitly. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md new file mode 100644 index 000000000..9d2fed82c --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-010: KMS replacement cutover and rollback window + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-010](../../../feature-audit.md#req-kms-upgrade-010) +- Risks: [risk-kms-upgrade-010](../../../feature-audit.md#risk-kms-upgrade-010) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify client routing can move to 0.6.0 and return to retained old sources without identity change. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Shift guest and gateway KMS URL order gradually to 0.6.0, inject target outage, roll back to old endpoints, restore target, and cut over again. + +**Expected results:** + +- Key/certificate operations remain continuous, retry is bounded, no client generates a new trust root, and old nodes are retired only after the rollback window. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md new file mode 100644 index 000000000..4937837e5 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-011: Measurement cache across KMS upgrade boundaries + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-011](../../../feature-audit.md#req-kms-upgrade-011) +- Risks: [risk-kms-upgrade-011](../../../feature-audit.md#risk-kms-upgrade-011) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify old and new measurement caches cannot authorize evidence under stale computation rules. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Populate caches before each bridge/direct hop, change OVMF/image/config inputs, upgrade verifier cache version, and repeat onboard/app authorization. + +**Expected results:** + +- Cache keys/version invalidate incompatible entries, recomputation uses the active release rules, and stale positive or negative results never cross the boundary. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md new file mode 100644 index 000000000..4d4aef3dd --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-UPGRADE-012: Post-KMS gateway 0.6.0 upgrade order + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-kms-upgrade-012](../../../feature-audit.md#req-kms-upgrade-012) +- Risks: [risk-kms-upgrade-012](../../../feature-audit.md#risk-kms-upgrade-012) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Prove gateway is upgraded only after KMS root continuity and new key/cert operations are healthy. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Complete KMS cutover, deploy a new 0.6.0 gateway against 0.6.0 KMS, issue a certificate, register old/new guests, pass traffic, cut DNS/LB, then test rollback. + +**Expected results:** + +- Gateway observes unchanged CA/root, certificate and app traffic succeed before cutover, old gateway remains a working rollback target, and no gateway participates in KMS root transfer. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md b/docs/test-plans/core-components-full/03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md new file mode 100644 index 000000000..315d06a11 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-KMS-CT-001: Concurrent certificate log append and iteration + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-ct-001](../../../feature-audit.md#req-kms-ct-001) +- Risks: [risk-kms-ct-001](../../../feature-audit.md#risk-kms-ct-001) +- Source: `dstack/kms/src/ct_log.rs` + +## Objective + +Verify concurrent certificate log append and iteration exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Write certificates for identical/different app IDs concurrently across filename collisions, restart, permissions, full disk, malformed existing names and iteration. + +**Expected results:** + +- Each issued certificate has one immutable ordered file, collision allocation is race-safe, iteration excludes unrelated/malformed files, and logging failure follows certificate-issuance policy without overwrite. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/03-kms/10-service-startup/tc-kms-startup-001/case.md b/docs/test-plans/core-components-full/03-kms/10-service-startup/tc-kms-startup-001/case.md new file mode 100644 index 000000000..6bba0057b --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/10-service-startup/tc-kms-startup-001/case.md @@ -0,0 +1,71 @@ + + + +# TC-KMS-STARTUP-001: Onboard, main, admin, metrics, and health listener startup + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-startup-001](../../../feature-audit.md#req-kms-startup-001) +- Risks: [risk-kms-startup-001](../../../feature-audit.md#risk-kms-startup-001) +- Source: `dstack/kms/src/main.rs` + +## Objective + +Verify KMS starts only the listeners allowed by its initialized/onboarding state and transitions atomically to the main service. + +## Preconditions + +1. Prepare separate fresh-uninitialized, partially initialized, fully initialized, and corrupted-state directories. +2. Reserve and monitor all configured public, onboard, admin, metrics, and health addresses. + +## Test Data + +The `kms` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use valid/minimal/full configuration plus bind conflicts, missing TLS files, invalid admin configuration, and an interrupted Finish transition. + +## Steps + + +### Step 1: Start an uninitialized KMS + +Start against fresh state and probe every configured listener and representative RPC. + +**Expected results:** + +- Only the onboarding and intended health surfaces are available; app-key, key-handover, signing, and admin operations cannot be reached before initialization. + + +### Step 2: Complete onboarding and transition + +Bootstrap or onboard with valid evidence, call Finish, and continuously probe listener availability through the transition. + +**Expected results:** + +- State commits once, onboarding closes, main/admin/metrics listeners open with correct authentication, and there is no interval exposing both unrestricted onboarding and initialized key service. + + +### Step 3: Exercise startup failures and restart + +Repeat with each bind/TLS/config/state failure, interrupt Finish, then restart from fully committed and partial state. + +**Expected results:** + +- Startup failure is explicit and releases all binds; committed state restarts in main mode with the same CA/root; partial/corrupt state fails closed and never generates a replacement root. + + +### Step 4: Verify listener isolation and redaction + +Call each method on every wrong listener with missing/wrong credentials and inspect logs, metrics, and process arguments. + +**Expected results:** + +- Methods are available only on their intended listener, auth is consistent, and no root key, temporary CA key, token, or onboarding secret appears in observability output. + +## Postconditions + +Remove test state and confirm all listeners and processes have stopped. diff --git a/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md new file mode 100644 index 000000000..4ea9095fd --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RUNTIME-001: Ethereum authorization HTTP server schema and listener + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-runtime-001](../../../feature-audit.md#req-kms-runtime-001) +- Risks: [risk-kms-runtime-001](../../../feature-audit.md#risk-kms-runtime-001) +- Source: `dstack/kms/auth-eth/src` + +## Objective + +Verify ethereum authorization http server schema and listener for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Start with valid/invalid chain/contract/RPC config and call health, app/KMS authorization and metadata with malformed/oversized bodies. + +**Expected results:** + +- Server validates startup config, implements declared schema/status codes, bounds input, fails closed on backend uncertainty and exposes no wallet/RPC credential. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md new file mode 100644 index 000000000..5206399f3 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RUNTIME-002: Bun and Node authorization implementation parity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-runtime-002](../../../feature-audit.md#req-kms-runtime-002) +- Risks: [risk-kms-runtime-002](../../../feature-audit.md#risk-kms-runtime-002) +- Source: `dstack/kms/auth-eth-bun` + +## Objective + +Verify bun and node authorization implementation parity for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Replay an identical boot-info allow/deny/error corpus through Bun and Node implementations against one chain snapshot. + +**Expected results:** + +- Decisions, reasons, chain/contract metadata and error classes are identical for every corpus entry. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md new file mode 100644 index 000000000..d8acc68df --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RUNTIME-003: Authorization deployment and management scripts + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-runtime-003](../../../feature-audit.md#req-kms-runtime-003) +- Risks: [risk-kms-runtime-003](../../../feature-audit.md#risk-kms-runtime-003) +- Source: `dstack/kms/auth-eth/script` + +## Objective + +Verify authorization deployment and management scripts for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run deploy/manage/query/upgrade scripts on clean and existing deployments with missing/wrong env, wrong chain, unauthorized signer and dry-run checks. + +**Expected results:** + +- Scripts target the recorded chain/contracts, validate signer/state/storage layout, are idempotent where documented and cannot partially mutate on preflight failure. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md new file mode 100644 index 000000000..36a7a4d54 --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RUNTIME-004: Authorization service container deployment + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-runtime-004](../../../feature-audit.md#req-kms-runtime-004) +- Risks: [risk-kms-runtime-004](../../../feature-audit.md#risk-kms-runtime-004) +- Source: `dstack/kms/dstack-app` + +## Objective + +Verify authorization service container deployment for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Deploy simple/dev/production compose and entrypoint under missing secrets, delayed chain, restart, health and upgrade. + +**Expected results:** + +- Only intended auth implementation starts, secrets use protected injection, health reflects dependency readiness and restart/upgrade preserves policy endpoint identity. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md new file mode 100644 index 000000000..92dd075fc --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-RUNTIME-005: DstackApp device compose TCB and upgrade-disable policy + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-kms-runtime-005](../../../feature-audit.md#req-kms-runtime-005) +- Risks: [risk-kms-runtime-005](../../../feature-audit.md#risk-kms-runtime-005) +- Source: `dstack/kms/auth-eth/contracts/DstackApp.sol` + +## Objective + +Verify dstackapp device compose tcb and upgrade-disable policy for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Exercise compose/device add/remove, allowAnyDevice, requireTcbUpToDate, advisory/TCB states, ownership, disableUpgrades and attempted later UUPS upgrade. + +**Expected results:** + +- Authorization is the conjunction defined by contract, only owner mutates, emitted events match state, and disableUpgrades is irreversible and blocks implementation change. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/03-kms/12-kms-build/tc-kms-build-001/case.md b/docs/test-plans/core-components-full/03-kms/12-kms-build/tc-kms-build-001/case.md new file mode 100644 index 000000000..9ef7d8a7a --- /dev/null +++ b/docs/test-plans/core-components-full/03-kms/12-kms-build/tc-kms-build-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-KMS-BUILD-001: KMS Build, Image, Auth, Contract, and Existing Regression Suite + +## Metadata + +- Priority: P0 +- Type: Build, Regression, Supply Chain, Security +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-kms-build-001](../../../feature-audit.md#req-kms-build-001) +- Risks: [risk-kms-build-001](../../../feature-audit.md#risk-kms-build-001) +- Source: `dstack/kms` + +## Objective + +Verify the complete component build, generated-interface, packaging, existing-test, and supply-chain baseline before product-level cases rely on the candidate. + +## Preconditions + +1. Use a clean checkout, empty component build caches, pinned toolchains, and recorded dependency mirrors. +2. Do not update locks or generated files during the test; capture any dirty working-tree diff. + +## Test Data + +Use the candidate commit, committed fixtures, lock files, image recipes, generated protobuf/OpenAPI sources, and all component-native test configurations. + +## Steps + + +### Step 1: Build from clean state + +Build KMS/RPC/container plus mock/simple/Node/Bun authorization and Solidity contracts; run Rust, Vitest/Jest, Foundry, storage-layout and static-security suites. + +**Expected results:** + +- All artifacts build reproducibly with pinned dependencies, generated schemas match, every test/security gate passes, and container entrypoint starts the selected implementation without embedded secrets. + + +### Step 2: Verify generated and packaged artifacts + +Regenerate interfaces into a temporary tree, compare with committed output, inspect licenses/SBOM/locks/image contents and repeat the build with network disabled after dependency fetch. + +**Expected results:** + +- Generated output has no unexplained diff, offline rebuild succeeds from pins, required licenses are present, and packages contain only declared runtime/test content. + + +### Step 3: Verify failure detection + +Introduce one temporary source/test-fixture/schema/config mismatch outside the committed tree and confirm the relevant build/test/generation gate fails, then restore and rerun. + +**Expected results:** + +- The gate detects the controlled regression with a specific error and returns to a clean passing result after restoration. + +## Postconditions + +Remove temporary build/output trees and verify the candidate checkout remains clean. diff --git a/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md new file mode 100644 index 000000000..62fef07bd --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-GATEWAY-001: Gateway.RegisterCvm + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-gateway-001](../../../feature-audit.md#req-gw-gateway-001) +- Risks: [risk-gw-gateway-001](../../../feature-audit.md#risk-gw-gateway-001) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:209` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Gateway.RegisterCvm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Gateway.RegisterCvm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway.registercvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Gateway.RegisterCvm` with a valid `RegisterCvmRequest` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `RegisterCvmResponse` with every documented field and exhibits the documented `RegisterCvm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md new file mode 100644 index 000000000..778da9fd4 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-GATEWAY-002: Gateway.AcmeInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-gateway-002](../../../feature-audit.md#req-gw-gateway-002) +- Risks: [risk-gw-gateway-002](../../../feature-audit.md#risk-gw-gateway-002) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:211` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Gateway.AcmeInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Gateway.AcmeInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway.acmeinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Gateway.AcmeInfo` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `AcmeInfoResponse` with every documented field and exhibits the documented `AcmeInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md new file mode 100644 index 000000000..22d05861d --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-GATEWAY-003: Gateway.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-gateway-003](../../../feature-audit.md#req-gw-gateway-003) +- Risks: [risk-gw-gateway-003](../../../feature-audit.md#risk-gw-gateway-003) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:213` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Gateway.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Gateway.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Gateway.Info` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `InfoResponse` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md new file mode 100644 index 000000000..e80ef0a4a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-GATEWAY-004: Gateway.GetPeers + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-gateway-004](../../../feature-audit.md#req-gw-gateway-004) +- Risks: [risk-gw-gateway-004](../../../feature-audit.md#risk-gw-gateway-004) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:215` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Gateway.GetPeers`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Gateway.GetPeers` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway.getpeers. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Gateway.GetPeers` with a valid `google.protobuf.Empty` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetPeersResponse` with every documented field and exhibits the documented `GetPeers` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-001/case.md b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-001/case.md new file mode 100644 index 000000000..db6bc1bac --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-DEBUG-001: Debug.RegisterCvm + +## Metadata + +- Priority: P0 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-debug-001](../../../feature-audit.md#req-gw-debug-001) +- Risks: [risk-gw-debug-001](../../../feature-audit.md#risk-gw-debug-001) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:221` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Debug.RegisterCvm`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Debug.RegisterCvm` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for debug.registercvm. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Debug.RegisterCvm` with a valid `DebugRegisterCvmRequest` request using debug mode enabled on an isolated test deployment; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `RegisterCvmResponse` with every documented field and exhibits the documented `RegisterCvm` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-002/case.md b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-002/case.md new file mode 100644 index 000000000..609be80b2 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-DEBUG-002: Debug.Info + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-debug-002](../../../feature-audit.md#req-gw-debug-002) +- Risks: [risk-gw-debug-002](../../../feature-audit.md#risk-gw-debug-002) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:223` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Debug.Info`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Debug.Info` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for debug.info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Debug.Info` with a valid `google.protobuf.Empty` request using debug mode enabled on an isolated test deployment; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `InfoResponse` with every documented field and exhibits the documented `Info` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-003/case.md b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-003/case.md new file mode 100644 index 000000000..3d1ca0adf --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-DEBUG-003: Debug.GetSyncData + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-debug-003](../../../feature-audit.md#req-gw-debug-003) +- Risks: [risk-gw-debug-003](../../../feature-audit.md#risk-gw-debug-003) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:225` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Debug.GetSyncData`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Debug.GetSyncData` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for debug.getsyncdata. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Debug.GetSyncData` with a valid `google.protobuf.Empty` request using debug mode enabled on an isolated test deployment; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DebugSyncDataResponse` with every documented field and exhibits the documented `GetSyncData` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-004/case.md b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-004/case.md new file mode 100644 index 000000000..226e1e3a2 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/02-rpc-debug/tc-gw-debug-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-DEBUG-004: Debug.GetProxyState + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-debug-004](../../../feature-audit.md#req-gw-debug-004) +- Risks: [risk-gw-debug-004](../../../feature-audit.md#risk-gw-debug-004) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:227` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Debug.GetProxyState`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Debug.GetProxyState` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for debug.getproxystate. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Debug.GetProxyState` with a valid `google.protobuf.Empty` request using debug mode enabled on an isolated test deployment; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DebugProxyStateResponse` with every documented field and exhibits the documented `GetProxyState` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-001/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-001/case.md new file mode 100644 index 000000000..1462acc37 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-001/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-001: Admin.Status + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-001](../../../feature-audit.md#req-gw-admin-001) +- Risks: [risk-gw-admin-001](../../../feature-audit.md#risk-gw-admin-001) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:377` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.Status`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.Status` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.status. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.Status` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `StatusResponse` with every documented field and exhibits the documented `Status` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-002/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-002/case.md new file mode 100644 index 000000000..190627ddc --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-002: Admin.GetInfo + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-002](../../../feature-audit.md#req-gw-admin-002) +- Risks: [risk-gw-admin-002](../../../feature-audit.md#risk-gw-admin-002) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:379` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetInfo`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetInfo` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getinfo. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetInfo` with a valid `GetInfoRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetInfoResponse` with every documented field and exhibits the documented `GetInfo` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-003/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-003/case.md new file mode 100644 index 000000000..1f53451e4 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-003/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-003: Admin.Exit + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-003](../../../feature-audit.md#req-gw-admin-003) +- Risks: [risk-gw-admin-003](../../../feature-audit.md#risk-gw-admin-003) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:381` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.Exit`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.Exit` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.exit. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.Exit` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `Exit` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-004/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-004/case.md new file mode 100644 index 000000000..b8fdc59d0 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-004/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-004: Admin.RenewCert + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-004](../../../feature-audit.md#req-gw-admin-004) +- Risks: [risk-gw-admin-004](../../../feature-audit.md#risk-gw-admin-004) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:383` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.RenewCert`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.RenewCert` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.renewcert. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.RenewCert` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `RenewCertResponse` with every documented field and exhibits the documented `RenewCert` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-005/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-005/case.md new file mode 100644 index 000000000..8f1d5a6f7 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-005: Admin.ReloadCert + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-005](../../../feature-audit.md#req-gw-admin-005) +- Risks: [risk-gw-admin-005](../../../feature-audit.md#risk-gw-admin-005) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:385` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ReloadCert`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ReloadCert` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.reloadcert. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ReloadCert` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ReloadCert` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-006/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-006/case.md new file mode 100644 index 000000000..6d45ae62e --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-006/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-006: Admin.SetCaa + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-006](../../../feature-audit.md#req-gw-admin-006) +- Risks: [risk-gw-admin-006](../../../feature-audit.md#risk-gw-admin-006) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:387` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetCaa`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetCaa` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setcaa. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetCaa` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetCaa` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-007/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-007/case.md new file mode 100644 index 000000000..42c1a60f3 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-007/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-007: Admin.GetMeta + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-007](../../../feature-audit.md#req-gw-admin-007) +- Risks: [risk-gw-admin-007](../../../feature-audit.md#risk-gw-admin-007) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:389` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetMeta`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetMeta` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getmeta. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetMeta` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetMetaResponse` with every documented field and exhibits the documented `GetMeta` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-008/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-008/case.md new file mode 100644 index 000000000..7be9dbd39 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-008/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-008: Admin.SetNodeUrl + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-008](../../../feature-audit.md#req-gw-admin-008) +- Risks: [risk-gw-admin-008](../../../feature-audit.md#risk-gw-admin-008) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:391` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetNodeUrl`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetNodeUrl` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setnodeurl. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetNodeUrl` with a valid `SetNodeUrlRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetNodeUrl` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-009/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-009/case.md new file mode 100644 index 000000000..c9b944017 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-009/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-009: Admin.SetNodeStatus + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-009](../../../feature-audit.md#req-gw-admin-009) +- Risks: [risk-gw-admin-009](../../../feature-audit.md#risk-gw-admin-009) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:393` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetNodeStatus`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetNodeStatus` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setnodestatus. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetNodeStatus` with a valid `SetNodeStatusRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetNodeStatus` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-010/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-010/case.md new file mode 100644 index 000000000..5ca795dde --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-010/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-010: Admin.WaveKvStatus + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-010](../../../feature-audit.md#req-gw-admin-010) +- Risks: [risk-gw-admin-010](../../../feature-audit.md#risk-gw-admin-010) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:395` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.WaveKvStatus`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.WaveKvStatus` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.wavekvstatus. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.WaveKvStatus` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `WaveKvStatusResponse` with every documented field and exhibits the documented `WaveKvStatus` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-011/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-011/case.md new file mode 100644 index 000000000..7790434e5 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-011/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-011: Admin.GetInstanceHandshakes + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-011](../../../feature-audit.md#req-gw-admin-011) +- Risks: [risk-gw-admin-011](../../../feature-audit.md#risk-gw-admin-011) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:397` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetInstanceHandshakes`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetInstanceHandshakes` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getinstancehandshakes. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetInstanceHandshakes` with a valid `GetInstanceHandshakesRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetInstanceHandshakesResponse` with every documented field and exhibits the documented `GetInstanceHandshakes` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-012/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-012/case.md new file mode 100644 index 000000000..c1885ef5c --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-012/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-012: Admin.GetGlobalConnections + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-012](../../../feature-audit.md#req-gw-admin-012) +- Risks: [risk-gw-admin-012](../../../feature-audit.md#risk-gw-admin-012) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:399` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetGlobalConnections`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetGlobalConnections` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getglobalconnections. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetGlobalConnections` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GlobalConnectionsStats` with every documented field and exhibits the documented `GetGlobalConnections` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-013/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-013/case.md new file mode 100644 index 000000000..8ee7f7a1d --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-013/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-013: Admin.GetNodeStatuses + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-013](../../../feature-audit.md#req-gw-admin-013) +- Risks: [risk-gw-admin-013](../../../feature-audit.md#risk-gw-admin-013) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:401` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetNodeStatuses`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetNodeStatuses` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getnodestatuses. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetNodeStatuses` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetNodeStatusesResponse` with every documented field and exhibits the documented `GetNodeStatuses` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-014/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-014/case.md new file mode 100644 index 000000000..1a3a2089a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-014/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-014: Admin.ListDnsCredentials + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-014](../../../feature-audit.md#req-gw-admin-014) +- Risks: [risk-gw-admin-014](../../../feature-audit.md#risk-gw-admin-014) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:405` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ListDnsCredentials`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ListDnsCredentials` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.listdnscredentials. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ListDnsCredentials` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListDnsCredentialsResponse` with every documented field and exhibits the documented `ListDnsCredentials` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-015/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-015/case.md new file mode 100644 index 000000000..dd5b7c96b --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-015/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-015: Admin.GetDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-015](../../../feature-audit.md#req-gw-admin-015) +- Risks: [risk-gw-admin-015](../../../feature-audit.md#risk-gw-admin-015) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:407` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getdnscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetDnsCredential` with a valid `GetDnsCredentialRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DnsCredentialInfo` with every documented field and exhibits the documented `GetDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-016/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-016/case.md new file mode 100644 index 000000000..ff6a7bc26 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-016/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-016: Admin.CreateDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-016](../../../feature-audit.md#req-gw-admin-016) +- Risks: [risk-gw-admin-016](../../../feature-audit.md#risk-gw-admin-016) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:409` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.CreateDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.CreateDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.creatednscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.CreateDnsCredential` with a valid `CreateDnsCredentialRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DnsCredentialInfo` with every documented field and exhibits the documented `CreateDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-017/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-017/case.md new file mode 100644 index 000000000..e1a999f12 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-017/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-017: Admin.UpdateDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-017](../../../feature-audit.md#req-gw-admin-017) +- Risks: [risk-gw-admin-017](../../../feature-audit.md#risk-gw-admin-017) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:411` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.UpdateDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.UpdateDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.updatednscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.UpdateDnsCredential` with a valid `UpdateDnsCredentialRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `DnsCredentialInfo` with every documented field and exhibits the documented `UpdateDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-018/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-018/case.md new file mode 100644 index 000000000..f88e53626 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-018/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-018: Admin.DeleteDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-018](../../../feature-audit.md#req-gw-admin-018) +- Risks: [risk-gw-admin-018](../../../feature-audit.md#risk-gw-admin-018) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:413` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.DeleteDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.DeleteDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.deletednscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.DeleteDnsCredential` with a valid `DeleteDnsCredentialRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `DeleteDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-019/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-019/case.md new file mode 100644 index 000000000..d512b859e --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-019/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-019: Admin.GetDefaultDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-019](../../../feature-audit.md#req-gw-admin-019) +- Risks: [risk-gw-admin-019](../../../feature-audit.md#risk-gw-admin-019) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:415` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetDefaultDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetDefaultDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getdefaultdnscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetDefaultDnsCredential` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetDefaultDnsCredentialResponse` with every documented field and exhibits the documented `GetDefaultDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-020/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-020/case.md new file mode 100644 index 000000000..f08e77bd9 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-020/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-020: Admin.SetDefaultDnsCredential + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-020](../../../feature-audit.md#req-gw-admin-020) +- Risks: [risk-gw-admin-020](../../../feature-audit.md#risk-gw-admin-020) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:417` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetDefaultDnsCredential`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetDefaultDnsCredential` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setdefaultdnscredential. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetDefaultDnsCredential` with a valid `SetDefaultDnsCredentialRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetDefaultDnsCredential` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-021/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-021/case.md new file mode 100644 index 000000000..d4c8cb388 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-021/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-021: Admin.ListZtDomains + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-021](../../../feature-audit.md#req-gw-admin-021) +- Risks: [risk-gw-admin-021](../../../feature-audit.md#risk-gw-admin-021) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:421` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ListZtDomains`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ListZtDomains` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.listztdomains. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ListZtDomains` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListZtDomainsResponse` with every documented field and exhibits the documented `ListZtDomains` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-022/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-022/case.md new file mode 100644 index 000000000..cdf134dbe --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-022/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-022: Admin.GetZtDomain + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-022](../../../feature-audit.md#req-gw-admin-022) +- Risks: [risk-gw-admin-022](../../../feature-audit.md#risk-gw-admin-022) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:423` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetZtDomain`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetZtDomain` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getztdomain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetZtDomain` with a valid `GetZtDomainRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ZtDomainInfo` with every documented field and exhibits the documented `GetZtDomain` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-023/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-023/case.md new file mode 100644 index 000000000..b7bf6d5f4 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-023/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-023: Admin.AddZtDomain + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-023](../../../feature-audit.md#req-gw-admin-023) +- Risks: [risk-gw-admin-023](../../../feature-audit.md#risk-gw-admin-023) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:425` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.AddZtDomain`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.AddZtDomain` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.addztdomain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.AddZtDomain` with a valid `ZtDomainConfig` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ZtDomainInfo` with every documented field and exhibits the documented `AddZtDomain` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-024/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-024/case.md new file mode 100644 index 000000000..d395074d7 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-024/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-024: Admin.UpdateZtDomain + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-024](../../../feature-audit.md#req-gw-admin-024) +- Risks: [risk-gw-admin-024](../../../feature-audit.md#risk-gw-admin-024) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:427` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.UpdateZtDomain`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.UpdateZtDomain` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.updateztdomain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.UpdateZtDomain` with a valid `ZtDomainConfig` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ZtDomainInfo` with every documented field and exhibits the documented `UpdateZtDomain` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-025/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-025/case.md new file mode 100644 index 000000000..e4fec6834 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-025/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-025: Admin.DeleteZtDomain + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-025](../../../feature-audit.md#req-gw-admin-025) +- Risks: [risk-gw-admin-025](../../../feature-audit.md#risk-gw-admin-025) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:429` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.DeleteZtDomain`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.DeleteZtDomain` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.deleteztdomain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.DeleteZtDomain` with a valid `DeleteZtDomainRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `DeleteZtDomain` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-026/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-026/case.md new file mode 100644 index 000000000..3b1bd3841 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-026/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-026: Admin.RenewZtDomainCert + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-026](../../../feature-audit.md#req-gw-admin-026) +- Risks: [risk-gw-admin-026](../../../feature-audit.md#risk-gw-admin-026) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:431` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.RenewZtDomainCert`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.RenewZtDomainCert` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.renewztdomaincert. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.RenewZtDomainCert` with a valid `RenewZtDomainCertRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `RenewZtDomainCertResponse` with every documented field and exhibits the documented `RenewZtDomainCert` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-027/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-027/case.md new file mode 100644 index 000000000..c09271c55 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-027/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-027: Admin.ForceReleaseCertLock + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-027](../../../feature-audit.md#req-gw-admin-027) +- Risks: [risk-gw-admin-027](../../../feature-audit.md#risk-gw-admin-027) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:433` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ForceReleaseCertLock`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ForceReleaseCertLock` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.forcereleasecertlock. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ForceReleaseCertLock` with a valid `ForceReleaseCertLockRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ForceReleaseCertLock` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-028/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-028/case.md new file mode 100644 index 000000000..de137ef8c --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-028/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-028: Admin.ListCertAttestations + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-028](../../../feature-audit.md#req-gw-admin-028) +- Risks: [risk-gw-admin-028](../../../feature-audit.md#risk-gw-admin-028) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:435` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ListCertAttestations`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ListCertAttestations` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.listcertattestations. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ListCertAttestations` with a valid `ListCertAttestationsRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `ListCertAttestationsResponse` with every documented field and exhibits the documented `ListCertAttestations` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-029/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-029/case.md new file mode 100644 index 000000000..6c03a0ebb --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-029/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-029: Admin.GetCertbotConfig + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-029](../../../feature-audit.md#req-gw-admin-029) +- Risks: [risk-gw-admin-029](../../../feature-audit.md#risk-gw-admin-029) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:439` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetCertbotConfig`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetCertbotConfig` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getcertbotconfig. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetCertbotConfig` with a valid `google.protobuf.Empty` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `CertbotConfigResponse` with every documented field and exhibits the documented `GetCertbotConfig` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-030/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-030/case.md new file mode 100644 index 000000000..259f13cc5 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-030/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-030: Admin.SetCertbotConfig + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-030](../../../feature-audit.md#req-gw-admin-030) +- Risks: [risk-gw-admin-030](../../../feature-audit.md#risk-gw-admin-030) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:441` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetCertbotConfig`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetCertbotConfig` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setcertbotconfig. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetCertbotConfig` with a valid `SetCertbotConfigRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetCertbotConfig` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-031/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-031/case.md new file mode 100644 index 000000000..4fb5eb064 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-031/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-031: Admin.SetInstancePortPolicy + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-031](../../../feature-audit.md#req-gw-admin-031) +- Risks: [risk-gw-admin-031](../../../feature-audit.md#risk-gw-admin-031) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:447` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.SetInstancePortPolicy`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.SetInstancePortPolicy` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.setinstanceportpolicy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.SetInstancePortPolicy` with a valid `SetInstancePortPolicyRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `SetInstancePortPolicy` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-032/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-032/case.md new file mode 100644 index 000000000..213755881 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-032/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-032: Admin.ClearInstancePortPolicy + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-032](../../../feature-audit.md#req-gw-admin-032) +- Risks: [risk-gw-admin-032](../../../feature-audit.md#risk-gw-admin-032) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:450` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.ClearInstancePortPolicy`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.ClearInstancePortPolicy` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.clearinstanceportpolicy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.ClearInstancePortPolicy` with a valid `ClearInstancePortPolicyRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `google.protobuf.Empty` with every documented field and exhibits the documented `ClearInstancePortPolicy` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-033/case.md b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-033/case.md new file mode 100644 index 000000000..bccd35783 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/03-rpc-admin/tc-gw-admin-033/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-ADMIN-033: Admin.GetInstancePortPolicy + +## Metadata + +- Priority: P1 +- Type: Functional, API, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-admin-033](../../../feature-audit.md#req-gw-admin-033) +- Risks: [risk-gw-admin-033](../../../feature-audit.md#risk-gw-admin-033) +- Source: `dstack/gateway/rpc/proto/gateway_rpc.proto:453` + +## Objective + +Verify the complete request, response, authorization, state transition, and error contract of `Admin.GetInstancePortPolicy`. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `Admin.GetInstancePortPolicy` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin.getinstanceportpolicy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Invoke `Admin.GetInstancePortPolicy` with a valid `GetInstancePortPolicyRequest` request using a valid admin credential on the dedicated admin listener; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential. + +**Expected results:** + +- The valid call returns `GetInstancePortPolicyResponse` with every documented field and exhibits the documented `GetInstancePortPolicy` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md new file mode 100644 index 000000000..3f073a502 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-REGISTRATI-001: Attested CVM registration and re-registration + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gw-registrati-001](../../../feature-audit.md#req-gw-registrati-001) +- Risks: [risk-gw-registrati-001](../../../feature-audit.md#risk-gw-registrati-001) +- Source: `dstack/gateway/src/main_service.rs` + +## Objective + +Verify attested cvm registration and re-registration across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for attested cvm registration and re-registration. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Register valid, tampered, duplicate-key, duplicate-instance, and changed-port-policy CVMs. + +**Expected results:** + +- Valid identity receives deterministic allocation/config; tampering fails; re-registration updates intended fields without duplicate leases. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md new file mode 100644 index 000000000..61c8f6782 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-REGISTRATI-002: WireGuard IP allocation and peer lifecycle + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-registrati-002](../../../feature-audit.md#req-gw-registrati-002) +- Risks: [risk-gw-registrati-002](../../../feature-audit.md#risk-gw-registrati-002) +- Source: `dstack/gateway/src/main_service/handshakes.rs` + +## Objective + +Verify wireguard ip allocation and peer lifecycle across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for wireguard ip allocation and peer lifecycle. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Register many CVMs/nodes through address boundaries, handshakes, expiry, and recycle. + +**Expected results:** + +- Addresses are unique/in range, peers route correctly, online state follows handshake policy, and recycled addresses are not concurrently reused. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md new file mode 100644 index 000000000..905b1309a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-REGISTRATI-003: Restrict-mode port enforcement + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-registrati-003](../../../feature-audit.md#req-gw-registrati-003) +- Risks: [risk-gw-registrati-003](../../../feature-audit.md#risk-gw-registrati-003) +- Source: `dstack/gateway/src/main_service.rs` + +## Objective + +Verify restrict-mode port enforcement across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for restrict-mode port enforcement. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise listed/unlisted ports, empty-reported policy, old guest missing policy, and admin override. + +**Expected results:** + +- Restrict mode allows only listed ports, absence follows compatibility fetch/fail-closed policy, and audited override precedence is exact. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md new file mode 100644 index 000000000..992d5311a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-REGISTRATI-004: Port policy fetch fallback compatibility + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-registrati-004](../../../feature-audit.md#req-gw-registrati-004) +- Risks: [risk-gw-registrati-004](../../../feature-audit.md#risk-gw-registrati-004) +- Source: `dstack/gateway/src/main_service.rs` + +## Objective + +Verify port policy fetch fallback compatibility across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for port policy fetch fallback compatibility. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Register old and new guest agents with reported, empty, unavailable, and malformed compose policies. + +**Expected results:** + +- New reported policy wins; old guests use Info fallback; timeout/cache semantics are bounded and never silently open unknown restricted ports. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md new file mode 100644 index 000000000..3b0fec13a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-001: Inbound Proxy Protocol v1/v2 parsing + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-proxy-prot-001](../../../feature-audit.md#req-gw-proxy-prot-001) +- Risks: [risk-gw-proxy-prot-001](../../../feature-audit.md#risk-gw-proxy-prot-001) +- Source: `dstack/gateway/src/pp.rs` + +## Objective + +Verify inbound proxy protocol v1/v2 parsing across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for inbound proxy protocol v1/v2 parsing. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Send valid IPv4/IPv6/UNKNOWN v1/v2 and truncated, oversized, slow, spoofed, and absent headers. + +**Expected results:** + +- Configured listeners preserve the authenticated source/destination; invalid headers fail within limits and untrusted paths cannot spoof identity. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md new file mode 100644 index 000000000..76560678f --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-002: Outbound Proxy Protocol per-port opt-in + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-proxy-prot-002](../../../feature-audit.md#req-gw-proxy-prot-002) +- Risks: [risk-gw-proxy-prot-002](../../../feature-audit.md#risk-gw-proxy-prot-002) +- Source: `dstack/gateway/src/proxy.rs` + +## Objective + +Verify outbound proxy protocol per-port opt-in across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for outbound proxy protocol per-port opt-in. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Route PP and non-PP application ports through TLS termination and passthrough. + +**Expected results:** + +- Exactly one correct header precedes application bytes only on pp=true ports; non-PP traffic is byte-identical. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md new file mode 100644 index 000000000..4c02f93ab --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-003: TLS passthrough SNI address resolution + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-proxy-prot-003](../../../feature-audit.md#req-gw-proxy-prot-003) +- Risks: [risk-gw-proxy-prot-003](../../../feature-audit.md#risk-gw-proxy-prot-003) +- Source: `dstack/gateway/src/proxy/tls_passthough.rs` + +## Objective + +Verify tls passthrough sni address resolution across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tls passthrough sni address resolution. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Connect valid app/instance domains, malformed SNI, unknown app, multiple hosts, IPv6, and backend failure. + +**Expected results:** + +- SNI maps to the correct online instance, failover is bounded, and unknown/malformed names cannot reach arbitrary addresses. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md new file mode 100644 index 000000000..00814ac64 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-004: TLS termination routing and HTTP semantics + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-proxy-prot-004](../../../feature-audit.md#req-gw-proxy-prot-004) +- Risks: [risk-gw-proxy-prot-004](../../../feature-audit.md#risk-gw-proxy-prot-004) +- Source: `dstack/gateway/src/proxy.rs` + +## Objective + +Verify tls termination routing and http semantics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tls termination routing and http semantics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise HTTP/1.1, HTTP/2, WebSocket/upgrade, large streaming bodies, disconnects, and backend errors. + +**Expected results:** + +- TLS policy and Host routing are correct; streaming/backpressure preserve bytes and errors do not leak internal topology. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md new file mode 100644 index 000000000..39aa56298 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-005: App-address namespace and content-addressed HTTPS + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gw-proxy-prot-005](../../../feature-audit.md#req-gw-proxy-prot-005) +- Risks: [risk-gw-proxy-prot-005](../../../feature-audit.md#risk-gw-proxy-prot-005) +- Source: `dstack/gateway/src/main_service.rs` + +## Objective + +Verify app-address namespace and content-addressed https across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for app-address namespace and content-addressed https. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Resolve app/instance/content addresses with valid and altered identifiers/certificates. + +**Expected results:** + +- Names bind to the intended app/instance and certificate attestation; collision, wrong app, or stale mapping is rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md new file mode 100644 index 000000000..e97985bd6 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-PROXY-PROT-006: Connection limits timeouts and recycling + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-proxy-prot-006](../../../feature-audit.md#req-gw-proxy-prot-006) +- Risks: [risk-gw-proxy-prot-006](../../../feature-audit.md#risk-gw-proxy-prot-006) +- Source: `dstack/gateway/src/proxy/io_bridge.rs` + +## Objective + +Verify connection limits timeouts and recycling across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for connection limits timeouts and recycling. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exhaust global/per-host connections, idle/handshake timeouts, half-close, and recycle intervals. + +**Expected results:** + +- Limits reject excess predictably, counters return to baseline, half-close drains correctly, and no task/socket leak remains. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md new file mode 100644 index 000000000..70a395750 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-SELECT-007: Top-N backend selection DNS cache and failover + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-select-007](../../../feature-audit.md#req-gw-select-007) +- Risks: [risk-gw-select-007](../../../feature-audit.md#risk-gw-select-007) +- Source: `dstack/gateway/src/main_service.rs` + +## Objective + +Verify top-n backend selection dns cache and failover against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Register many same-app instances across nodes with controlled DNS/handshake/connection state; exercise connect_top_n/cache_top_n, repeated selection, stale/down/full hosts, concurrent removal and recovery. + +**Expected results:** + +- Candidate sets contain only matching allowed healthy instances, cache and randomization remain bounded/fair, stale/full/removed hosts are excluded promptly and retry never crosses app or port policy. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md new file mode 100644 index 000000000..9f5a5a50a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-001: ACME account bootstrap and persistence + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-001](../../../feature-audit.md#req-gw-certificat-001) +- Risks: [risk-gw-certificat-001](../../../feature-audit.md#risk-gw-certificat-001) +- Source: `dstack/gateway/src/distributed_certbot.rs` + +## Objective + +Verify acme account bootstrap and persistence across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for acme account bootstrap and persistence. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Initialize account, restart nodes, and attempt invalid directory/account/key state. + +**Expected results:** + +- Account URI/key persist and cluster agrees; corruption fails safely without silently creating a conflicting production account. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md new file mode 100644 index 000000000..de3e68e4f --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-002: Distributed certificate issue renew and lock + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-002](../../../feature-audit.md#req-gw-certificat-002) +- Risks: [risk-gw-certificat-002](../../../feature-audit.md#risk-gw-certificat-002) +- Source: `dstack/gateway/src/distributed_certbot.rs` + +## Objective + +Verify distributed certificate issue renew and lock across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for distributed certificate issue renew and lock. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Issue/renew concurrently across nodes, before/after threshold, force renew, crash lock holder, and release lock. + +**Expected results:** + +- One valid certificate is published, lock fencing prevents duplicates, recovery releases stale locks, and all nodes reload the same chain. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md new file mode 100644 index 000000000..7bea4e7f5 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-003: DNS credential CRUD and default selection + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-003](../../../feature-audit.md#req-gw-certificat-003) +- Risks: [risk-gw-certificat-003](../../../feature-audit.md#risk-gw-certificat-003) +- Source: `dstack/gateway/src/admin_service.rs` + +## Objective + +Verify dns credential crud and default selection across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for dns credential crud and default selection. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Create/read/update/delete supported provider credentials and change default with in-use/missing/invalid secrets. + +**Expected results:** + +- Secrets are encrypted/redacted, referential integrity holds, default selection is atomic, and deletion cannot strand active domains. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md new file mode 100644 index 000000000..77e7d8a6e --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-004: ZT domain CRUD and certificate lifecycle + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-004](../../../feature-audit.md#req-gw-certificat-004) +- Risks: [risk-gw-certificat-004](../../../feature-audit.md#risk-gw-certificat-004) +- Source: `dstack/gateway/src/admin_service.rs` + +## Objective + +Verify zt domain crud and certificate lifecycle across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for zt domain crud and certificate lifecycle. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Add/update/list/get/delete domains with wildcard/SAN/provider/credential changes and invalid names. + +**Expected results:** + +- Normalized unique domains map to correct DNS/ACME config; cert state follows changes and invalid/dependent deletion is rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md new file mode 100644 index 000000000..aeea905f9 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-005: CAA publication and validation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-005](../../../feature-audit.md#req-gw-certificat-005) +- Risks: [risk-gw-certificat-005](../../../feature-audit.md#risk-gw-certificat-005) +- Source: `dstack/gateway/src/admin_service.rs` + +## Objective + +Verify caa publication and validation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for caa publication and validation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Set CAA for configured domains across supported DNS providers and conflicting existing records. + +**Expected results:** + +- Required issuer records converge without deleting unrelated records; provider errors are reported and retry remains idempotent. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md new file mode 100644 index 000000000..bb1dbe71d --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-006: Certificate store SNI wildcard and hot reload + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certificat-006](../../../feature-audit.md#req-gw-certificat-006) +- Risks: [risk-gw-certificat-006](../../../feature-audit.md#risk-gw-certificat-006) +- Source: `dstack/gateway/src/cert_store.rs` + +## Objective + +Verify certificate store sni wildcard and hot reload across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for certificate store sni wildcard and hot reload. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Load exact/wildcard chains, overlapping names, expired/mismatched/corrupt keys, then reload under traffic. + +**Expected results:** + +- Most-specific valid cert is selected; bad updates retain prior cert; reload is atomic with no handshake interruption. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md new file mode 100644 index 000000000..64fc1b63d --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTIFICAT-007: Certificate attestation history and ACME info + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-gw-certificat-007](../../../feature-audit.md#req-gw-certificat-007) +- Risks: [risk-gw-certificat-007](../../../feature-audit.md#risk-gw-certificat-007) +- Source: `dstack/gateway/src/distributed_certbot.rs` + +## Objective + +Verify certificate attestation history and acme info across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for certificate attestation history and acme info. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Rotate certificate keys/accounts and query attestations and public ACME info. + +**Expected results:** + +- Ordered history contains verifiable quote/attestation bound to each public key/account URI without private keys. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md new file mode 100644 index 000000000..00357a41c --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-001: WaveKV bootstrap replication and convergence + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-001](../../../feature-audit.md#req-gw-cluster-ad-001) +- Risks: [risk-gw-cluster-ad-001](../../../feature-audit.md#risk-gw-cluster-ad-001) +- Source: `dstack/gateway/src/kv/sync_service.rs` + +## Objective + +Verify wavekv bootstrap replication and convergence across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for wavekv bootstrap replication and convergence. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Bootstrap 1→3 nodes, partition, concurrent updates, reconnect, and restart. + +**Expected results:** + +- Peer/node/instance/domain/cert state converges deterministically, tombstones prevent resurrection, and self identity remains stable. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md new file mode 100644 index 000000000..006e97bd1 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-002: WaveKV sync endpoint authentication and replay + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-002](../../../feature-audit.md#req-gw-cluster-ad-002) +- Risks: [risk-gw-cluster-ad-002](../../../feature-audit.md#risk-gw-cluster-ad-002) +- Source: `dstack/gateway/src/web_routes/wavekv_sync.rs` + +## Objective + +Verify wavekv sync endpoint authentication and replay across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for wavekv sync endpoint authentication and replay. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Send authenticated, unauthenticated, tampered, replayed, out-of-order, and oversized sync payloads. + +**Expected results:** + +- Only authenticated fresh peer updates apply; replay/order/size controls fail closed without blocking later valid synchronization. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md new file mode 100644 index 000000000..6a92c9ee9 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-003: Node URL and status administration + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-003](../../../feature-audit.md#req-gw-cluster-ad-003) +- Risks: [risk-gw-cluster-ad-003](../../../feature-audit.md#risk-gw-cluster-ad-003) +- Source: `dstack/gateway/src/admin_service.rs` + +## Objective + +Verify node url and status administration across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for node url and status administration. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Change node URL/status through valid/invalid transitions while peers observe. + +**Expected results:** + +- Canonical URL and status replicate, routing excludes disabled/stale nodes, and invalid self/peer transitions are rejected atomically. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md new file mode 100644 index 000000000..4806ce127 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-004: Connection handshake and node statistics + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-004](../../../feature-audit.md#req-gw-cluster-ad-004) +- Risks: [risk-gw-cluster-ad-004](../../../feature-audit.md#risk-gw-cluster-ad-004) +- Source: `dstack/gateway/src/admin_service.rs` + +## Objective + +Verify connection handshake and node statistics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for connection handshake and node statistics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Generate connections/handshakes across instances and nodes, then close and age them. + +**Expected results:** + +- Status, global counters, per-instance handshakes, online counts, and node status timestamps match observed traffic. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md new file mode 100644 index 000000000..65e86e7e6 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-CLUSTER-AD-005: Admin authentication and listener isolation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-005](../../../feature-audit.md#req-gw-cluster-ad-005) +- Risks: [risk-gw-cluster-ad-005](../../../feature-audit.md#risk-gw-cluster-ad-005) +- Source: `dstack/gateway/src/admin_auth.rs` + +## Objective + +Verify admin authentication and listener isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `gateway` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for admin authentication and listener isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise every Admin RPC with correct/missing/wrong/conflicting token on public/admin listeners. + +**Expected results:** + +- Admin methods exist only on admin listener, authenticate consistently, redact secrets, and public traffic remains available. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md new file mode 100644 index 000000000..c606f1705 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-006: Debug service isolation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gw-cluster-ad-006](../../../feature-audit.md#req-gw-cluster-ad-006) +- Risks: [risk-gw-cluster-ad-006](../../../feature-audit.md#risk-gw-cluster-ad-006) +- Source: `dstack/gateway/src/debug_service.rs` + +## Objective + +Verify debug service isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for debug service isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Start production/debug configurations and call debug registration/sync/proxy state. + +**Expected results:** + +- Debug listener and bypass registration are absent in production; isolated debug mode exposes accurate test state only on configured address. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md new file mode 100644 index 000000000..a57b50bca --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CLUSTER-AD-007: Health dashboard and graceful exit + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-007](../../../feature-audit.md#req-gw-cluster-ad-007) +- Risks: [risk-gw-cluster-ad-007](../../../feature-audit.md#risk-gw-cluster-ad-007) +- Source: `dstack/gateway/src/web_routes.rs` + +## Objective + +Verify health dashboard and graceful exit across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for health dashboard and graceful exit. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Query /health/dashboard during startup, traffic, degraded peers, cert failure, and admin Exit. + +**Expected results:** + +- Health distinguishes readiness/liveness, dashboard escapes data, Exit drains connections and persists cluster state before termination. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md new file mode 100644 index 000000000..9588a55c4 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md @@ -0,0 +1,62 @@ + + + +# TC-GW-CLUSTER-AD-008: TLS crypto provider and protocol matrix + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-cluster-ad-008](../../../feature-audit.md#req-gw-cluster-ad-008) +- Risks: [risk-gw-cluster-ad-008](../../../feature-audit.md#risk-gw-cluster-ad-008) +- Source: `dstack/gateway/src/config.rs` + +## Objective + +Verify tls crypto provider and protocol matrix across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +The `gateway` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tls crypto provider and protocol matrix. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Run configured crypto providers, TLS minimum versions, ciphers, mutual TLS, invalid chains, expiry, and revocation policy. + +**Expected results:** + +- Only configured protocol/client identities succeed, public/admin/peer trust stores remain separated, and downgrade is impossible. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md new file mode 100644 index 000000000..5d76af2fa --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-KV-009: WaveKV key encoding corruption persistence and watch semantics + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-kv-009](../../../feature-audit.md#req-gw-kv-009) +- Risks: [risk-gw-kv-009](../../../feature-audit.md#risk-gw-kv-009) +- Source: `dstack/gateway/src/kv/mod.rs` + +## Objective + +Verify wavekv key encoding corruption persistence and watch semantics against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Write/read/delete every instance/node/status/connection/handshake/peer/DNS/domain/cert/lock/attestation key family; inject malformed encoded values, partial persistence, tombstones, duplicate timestamps and watcher bursts. + +**Expected results:** + +- Key namespaces parse without collision, malformed values are isolated/reported, persistent and ephemeral data follow policy, tombstones prevent resurrection, locks/history order correctly and watchers coalesce without missing final state. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md new file mode 100644 index 000000000..6cc32ab08 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md @@ -0,0 +1,71 @@ + + + +# TC-GW-INTERNAL-001: Gateway startup certificate mode and resource limits + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-internal-001](../../../feature-audit.md#req-gw-internal-001) +- Risks: [risk-gw-internal-001](../../../feature-audit.md#risk-gw-internal-001) +- Source: `dstack/gateway/src/main.rs` + +## Objective + +Verify gateway startup certificate mode and resource limits exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +The `gateway` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Start production/debug cert generation, existing/missing/mismatched files, alternate names, crypto providers, low file limits and bind conflicts. + +**Expected results:** + +- Production obtains attested certificates, debug keys never enter production, permissions are restrictive, limits are raised or fail clearly, and no partial listener remains. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md new file mode 100644 index 000000000..1e27e3420 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-002: Gateway debug key generation artifact safety + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-gw-internal-002](../../../feature-audit.md#req-gw-internal-002) +- Risks: [risk-gw-internal-002](../../../feature-audit.md#risk-gw-internal-002) +- Source: `dstack/gateway/src/gen_debug_key.rs` + +## Objective + +Verify gateway debug key generation artifact safety exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Generate debug key data twice with target existing, unsafe permissions/path, interrupted write and production-config consumption attempt. + +**Expected results:** + +- Output is atomic, restricted, explicitly debug-labeled, not silently overwritten, and production startup refuses it. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md new file mode 100644 index 000000000..b3cf1f463 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-003: Gateway authorization client allow deny and outage + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-internal-003](../../../feature-audit.md#req-gw-internal-003) +- Risks: [risk-gw-internal-003](../../../feature-audit.md#risk-gw-internal-003) +- Source: `dstack/gateway/src/main_service/auth_client.rs` + +## Objective + +Verify gateway authorization client allow deny and outage exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Authorize valid/denied apps and inject malformed response, wrong TLS identity, timeout, stale response and recovery during registration. + +**Expected results:** + +- Only a fresh authenticated allow permits registration; every uncertain/deny path fails closed and recovered authorization does not reuse stale cross-app state. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md new file mode 100644 index 000000000..1404ec96d --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-004: Raw TLS ClientHello SNI parser boundaries + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gw-internal-004](../../../feature-audit.md#req-gw-internal-004) +- Risks: [risk-gw-internal-004](../../../feature-audit.md#risk-gw-internal-004) +- Source: `dstack/gateway/src/proxy/sni.rs` + +## Objective + +Verify raw tls clienthello sni parser boundaries exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Feed fragmented/coalesced TLS records, TLS versions, IPv4/IPv6 names, multiple/empty SNI extensions, truncation, oversized lengths and non-TLS bytes. + +**Expected results:** + +- The exact first valid host_name is returned only from a complete valid ClientHello; malformed input is bounded and never produces an attacker-controlled partial name. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md new file mode 100644 index 000000000..41344fea2 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-005: TLS termination local routes and stream bridge + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-internal-005](../../../feature-audit.md#req-gw-internal-005) +- Risks: [risk-gw-internal-005](../../../feature-audit.md#risk-gw-internal-005) +- Source: `dstack/gateway/src/proxy/tls_terminate.rs` + +## Objective + +Verify tls termination local routes and stream bridge exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Exercise local health/node routes and proxied traffic with ALPN, EOF/half-close, vectored writes, large/slow streams, backend reset and cert reload. + +**Expected results:** + +- Local routes never proxy, response schemas/status are exact, application bytes and backpressure are preserved, expected EOF is handled, and unexpected errors are visible. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md new file mode 100644 index 000000000..1abafb389 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-006: Port-policy filtering fetch retry and PP decision + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-internal-006](../../../feature-audit.md#req-gw-internal-006) +- Risks: [risk-gw-internal-006](../../../feature-audit.md#risk-gw-internal-006) +- Source: `dstack/gateway/src/proxy/port_policy.rs` + +## Objective + +Verify port-policy filtering fetch retry and pp decision exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Filter multi-address backends under reported/unknown/restrict/admin policies; trigger fetch retry, stale compose hash, agent timeout, empty reported policy and PP lookup. + +**Expected results:** + +- Only allowed addresses remain, unknown restricted policy fails closed, retry is bounded/deduplicated, cache updates atomically, and PP follows effective per-port policy. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md new file mode 100644 index 000000000..dba1fc269 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-007: Dashboard connection counters and policy provenance + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gw-internal-007](../../../feature-audit.md#req-gw-internal-007) +- Risks: [risk-gw-internal-007](../../../feature-audit.md#risk-gw-internal-007) +- Source: `dstack/gateway/src/models.rs` + +## Objective + +Verify dashboard connection counters and policy provenance exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Open/close concurrent connections and render instances with reported/fetched/admin/unknown policy, Unicode IDs, and disappearing entries. + +**Expected results:** + +- RAII counters never underflow/leak, effective policy and source label are correct, maps are stable, and rendered values are escaped. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md new file mode 100644 index 000000000..edc6ce97a --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md @@ -0,0 +1,69 @@ + + + +# TC-GW-INTERNAL-008: Combined route index RPC exposure + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-internal-008](../../../feature-audit.md#req-gw-internal-008) +- Risks: [risk-gw-internal-008](../../../feature-audit.md#risk-gw-internal-008) +- Source: `dstack/gateway/src/web_routes/route_index.rs` + +## Objective + +Verify combined route index rpc exposure exactly matches the source-defined behavior across normal, boundary, concurrent, failure, and restart paths. + +## Preconditions + +1. Use an isolated deployment with the relevant effective configuration and a clean run-scoped baseline. +2. Enable redacted process, file, RPC, and lifecycle evidence collection. + +## Test Data + +Include minimum, maximum, duplicate, missing, malformed, and cross-instance values appropriate to the behavior. + +## Steps + + +### Step 1: Record effective inputs and baseline + +Capture effective configuration, input files/requests, existing processes/resources, and public status before the operation. + +**Expected results:** + +- Inputs resolve unambiguously to the intended test identity and no run-scoped output or resource exists. + + +### Step 2: Exercise behavior and boundaries + +Query route index under normal, missing context, public/admin auth and malformed protocol requests. + +**Expected results:** + +- Only intended RPC handlers are mounted, construction failure returns bounded error, and admin methods cannot be reached through the public route index. + + +### Step 3: Inject failure and concurrency + +Interrupt the primary dependency at its commit boundary, issue a conflicting concurrent operation, restore it, and retry once. + +**Expected results:** + +- At most one operation commits, failure cleanup releases all temporary resources, diagnostics identify the failed phase, and retry converges without duplicate state. + + +### Step 4: Verify restart, isolation, and redaction + +Restart the owning service where permitted and inspect state for this and an adjacent identity plus all collected output. + +**Expected results:** + +- Persisted and transient state follow policy, adjacent identities are unchanged, and no private material or credential appears in output. + +## Postconditions + +Remove run-scoped state and verify processes, files, devices, listeners, and allocations match baseline. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md new file mode 100644 index 000000000..5a56e887b --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-001: ACME account creation load and credential persistence + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-001](../../../feature-audit.md#req-gw-certbot-001) +- Risks: [risk-gw-certbot-001](../../../feature-audit.md#risk-gw-certbot-001) +- Source: `dstack/certbot/src/acme_client.rs` + +## Objective + +Verify acme account creation load and credential persistence for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Create/load account against staging, restart, use wrong/corrupt credentials/directory, concurrent creation and account-server errors. + +**Expected results:** + +- One account identity persists with restrictive files, concurrent start does not fork accounts, and corrupt/wrong state fails without overwrite. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md new file mode 100644 index 000000000..04739b991 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-002: DNS-01 authorization propagation and cleanup + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-002](../../../feature-audit.md#req-gw-certbot-002) +- Risks: [risk-gw-certbot-002](../../../feature-audit.md#risk-gw-certbot-002) +- Source: `dstack/certbot/src/acme_client.rs` + +## Objective + +Verify dns-01 authorization propagation and cleanup for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Issue single/SAN/wildcard orders with delayed/split DNS propagation, challenge failure, timeout, cancellation and retry. + +**Expected results:** + +- Exact TXT values propagate before validation, all created records are cleaned on success/failure, retries do not delete unrelated records and certificate covers requested names. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md new file mode 100644 index 000000000..6cb70dbbf --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-003: Cloudflare DNS record API boundaries + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-003](../../../feature-audit.md#req-gw-certbot-003) +- Risks: [risk-gw-certbot-003](../../../feature-audit.md#risk-gw-certbot-003) +- Source: `dstack/certbot/src/dns01_client/cloudflare.rs` + +## Objective + +Verify cloudflare dns record api boundaries for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Add/list/remove TXT and CAA using valid/wrong-scope/expired token, multiple zones, Unicode/punycode, pagination, rate limit and API errors. + +**Expected results:** + +- Correct zone/record is mutated once, credentials remain redacted, normalization is exact, and rate/error handling is bounded and retry-safe. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md new file mode 100644 index 000000000..d63983227 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-004: Certificate renewal threshold force and hook + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-004](../../../feature-audit.md#req-gw-certbot-004) +- Risks: [risk-gw-certbot-004](../../../feature-audit.md#risk-gw-certbot-004) +- Source: `dstack/certbot/src/bot.rs` + +## Objective + +Verify certificate renewal threshold force and hook for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run before/at/after threshold, force, concurrent renew, timeout, failed issuance, invalid live cert/key and successful renewed hook/failing hook. + +**Expected results:** + +- Renewal occurs only when required/forced, publication is atomic, old valid cert survives failure, one process wins concurrency and hook runs only after commit. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md new file mode 100644 index 000000000..58554ad5f --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-005: Certbot workdir archive live and rollback layout + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-005](../../../feature-audit.md#req-gw-certbot-005) +- Risks: [risk-gw-certbot-005](../../../feature-audit.md#risk-gw-certbot-005) +- Source: `dstack/certbot/src/workdir.rs` + +## Objective + +Verify certbot workdir archive live and rollback layout for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Create successive cert generations, inspect live/archive links/permissions, interrupt each write/rename, corrupt current link and recover. + +**Expected results:** + +- Generations are immutable and ordered, live points atomically to complete matching key/cert, private files are restricted and prior valid generation supports rollback. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md new file mode 100644 index 000000000..a2a80f660 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-CERTBOT-006: Certbot CLI once daemon config and signal lifecycle + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-gw-certbot-006](../../../feature-audit.md#req-gw-certbot-006) +- Risks: [risk-gw-certbot-006](../../../feature-audit.md#risk-gw-certbot-006) +- Source: `dstack/certbot/cli/src/main.rs` + +## Objective + +Verify certbot cli once daemon config and signal lifecycle for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run request/renew once and daemon modes with interval/expiry/timeout/hook boundaries, malformed config, SIGTERM and dependency outage. + +**Expected results:** + +- CLI exit/status and scheduling match mode, daemon does not overlap renewals, termination is graceful and restart resumes from persisted workdir. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/04-gateway/10-gw-build/tc-gw-build-001/case.md b/docs/test-plans/core-components-full/04-gateway/10-gw-build/tc-gw-build-001/case.md new file mode 100644 index 000000000..5bf1496b4 --- /dev/null +++ b/docs/test-plans/core-components-full/04-gateway/10-gw-build/tc-gw-build-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-GW-BUILD-001: Gateway, Certbot, Cluster Harness, and Existing Regression Suite + +## Metadata + +- Priority: P0 +- Type: Build, Regression, Supply Chain, Security +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-gw-build-001](../../../feature-audit.md#req-gw-build-001) +- Risks: [risk-gw-build-001](../../../feature-audit.md#risk-gw-build-001) +- Source: `dstack/gateway` + +## Objective + +Verify the complete component build, generated-interface, packaging, existing-test, and supply-chain baseline before product-level cases rely on the candidate. + +## Preconditions + +1. Use a clean checkout, empty component build caches, pinned toolchains, and recorded dependency mirrors. +2. Do not update locks or generated files during the test; capture any dirty working-tree diff. + +## Test Data + +Use the candidate commit, committed fixtures, lock files, image recipes, generated protobuf/OpenAPI sources, and all component-native test configurations. + +## Steps + + +### Step 1: Build from clean state + +Build gateway/RPC/certbot/container artifacts, run Rust tests and the isolated Pebble/Cloudflare/three-node cluster suites, and validate generated templates/configs. + +**Expected results:** + +- All tests pass from clean state, cluster harness proves sync/cert/proxy basics, templates render valid restricted configs, and production image contains no test key or debug bypass. + + +### Step 2: Verify generated and packaged artifacts + +Regenerate interfaces into a temporary tree, compare with committed output, inspect licenses/SBOM/locks/image contents and repeat the build with network disabled after dependency fetch. + +**Expected results:** + +- Generated output has no unexplained diff, offline rebuild succeeds from pins, required licenses are present, and packages contain only declared runtime/test content. + + +### Step 3: Verify failure detection + +Introduce one temporary source/test-fixture/schema/config mismatch outside the committed tree and confirm the relevant build/test/generation gate fails, then restore and rerun. + +**Expected results:** + +- The gate detects the controlled regression with a specific error and returns to a clean passing result after restoration. + +## Postconditions + +Remove temporary build/output trees and verify the candidate checkout remains clean. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md new file mode 100644 index 000000000..e260c5cdd --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-001: Verification input precedence and canonicalization + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-input-plat-001](../../../feature-audit.md#req-ver-input-plat-001) +- Risks: [risk-ver-input-plat-001](../../../feature-audit.md#risk-ver-input-plat-001) +- Source: `dstack/verifier/src/types.rs` + +## Objective + +Verify verification input precedence and canonicalization across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for verification input precedence and canonicalization. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Supply attestation-contained and conflicting top-level quote/event/vm/config/image inputs. + +**Expected results:** + +- Authenticated attestation fields take precedence, canonical decoding is deterministic, and ambiguous duplicate inputs are rejected. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md new file mode 100644 index 000000000..5bda38091 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-002: TDX quote signature collateral and TCB + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-input-plat-002](../../../feature-audit.md#req-ver-input-plat-002) +- Risks: [risk-ver-input-plat-002](../../../feature-audit.md#risk-ver-input-plat-002) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify tdx quote signature collateral and tcb across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tdx quote signature collateral and tcb. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify current/outdated/revoked/malformed quotes with collateral success, expiry, and network failure. + +**Expected results:** + +- Signature, QE/TCB/collateral validity and policy status are explicit; unverified or stale evidence never becomes PASS. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md new file mode 100644 index 000000000..e6123e69c --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-003: TDX event log replay and RTMR status + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-input-plat-003](../../../feature-audit.md#req-ver-input-plat-003) +- Risks: [risk-ver-input-plat-003](../../../feature-audit.md#risk-ver-input-plat-003) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify tdx event log replay and rtmr status across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tdx event log replay and rtmr status. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Replay valid logs plus reordered, missing, duplicate, malformed, digest/preimage-mismatched runtime events. + +**Expected results:** + +- RTMR replay equals quote values, event status identifies exact mismatch, and v2 digest preimages verify before use. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md new file mode 100644 index 000000000..fbb534c1a --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-004: TDX-lite measurement verification + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-input-plat-004](../../../feature-audit.md#req-ver-input-plat-004) +- Risks: [risk-ver-input-plat-004](../../../feature-audit.md#risk-ver-input-plat-004) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify tdx-lite measurement verification across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for tdx-lite measurement verification. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify fixture/hardware with correct and altered MRTD/RTMR/config/image plus unsupported requirements. + +**Expected results:** + +- Lite measurements bind image/config as defined; unsupported full-TDX claims fail rather than being assumed. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md new file mode 100644 index 000000000..efdc9e510 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-005: SEV-SNP certificate and report verification + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-input-plat-005](../../../feature-audit.md#req-ver-input-plat-005) +- Risks: [risk-ver-input-plat-005](../../../feature-audit.md#risk-ver-input-plat-005) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify sev-snp certificate and report verification across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for sev-snp certificate and report verification. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify fixture/hardware across VCEK chain, chip ID, TCB, policy, measurement, report data, and debug/migration flags. + +**Expected results:** + +- Trusted AMD chain and policy are enforced and each altered field produces a specific non-PASS result. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md new file mode 100644 index 000000000..e8e872a3d --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-006: Cloud TDX and Nitro TPM verification + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-input-plat-006](../../../feature-audit.md#req-ver-input-plat-006) +- Risks: [risk-ver-input-plat-006](../../../feature-audit.md#risk-ver-input-plat-006) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify cloud tdx and nitro tpm verification across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for cloud tdx and nitro tpm verification. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify GCP TDX and AWS Nitro TPM evidence with cloud metadata, measured boot, PCR/event logs, nonce, and vendor/product. + +**Expected results:** + +- Cloud chain, freshness, identity, PCR replay and config binding are all required; cross-cloud substitution fails. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md new file mode 100644 index 000000000..1f6bc618c --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-INPUT-PLAT-007: Simulated attestation labeling + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: SIMULATOR +- Automation: Yes +- Requirements: [req-ver-input-plat-007](../../../feature-audit.md#req-ver-input-plat-007) +- Risks: [risk-ver-input-plat-007](../../../feature-audit.md#risk-ver-input-plat-007) +- Source: `dstack/crates/mock-attestation` + +## Objective + +Verify simulated attestation labeling across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for simulated attestation labeling. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify every mock platform and attempt to present it as hardware evidence. + +**Expected results:** + +- Simulation validates only under explicit development policy and output clearly records simulated=true; production policy rejects it. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md new file mode 100644 index 000000000..fbb830648 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-VER-NITRO-008: Nitro Enclave document verification and debug rejection + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-nitro-008](../../../feature-audit.md#req-ver-nitro-008) +- Risks: [risk-ver-nitro-008](../../../feature-audit.md#risk-ver-nitro-008) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify nitro enclave document verification and debug rejection against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Verify valid/expired/future/debug Nitro Enclave documents with trusted/wrong chain, altered COSE signature, module ID, nonce/user/public key and PCR0/1/2/4; compare claimed os_image_hash. + +**Expected results:** + +- Trusted fresh non-debug documents bind expected PCR/image/report data and return Nitro variant; zero debug PCRs, chain/signature/time or binding mutations fail explicitly. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md new file mode 100644 index 000000000..f860cfce0 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-IMAGE-MEAS-001: Image download digest and extraction security + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-ver-image-meas-001](../../../feature-audit.md#req-ver-image-meas-001) +- Risks: [risk-ver-image-meas-001](../../../feature-audit.md#risk-ver-image-meas-001) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify image download digest and extraction security across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for image download digest and extraction security. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Download known image, wrong digest, truncated/multilayer/malicious archive, redirect, timeout, and retry. + +**Expected results:** + +- Content hash is verified before use, extraction cannot traverse roots, failures leave no trusted cache entry, and retry is bounded. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md new file mode 100644 index 000000000..91fe56fe0 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-IMAGE-MEAS-002: Measurement computation determinism + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-image-meas-002](../../../feature-audit.md#req-ver-image-meas-002) +- Risks: [risk-ver-image-meas-002](../../../feature-audit.md#risk-ver-image-meas-002) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify measurement computation determinism across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for measurement computation determinism. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Compute measurements repeatedly for identical and changed image/kernel/initrd/cmdline/config inputs. + +**Expected results:** + +- Identical inputs reproduce all registers; each changed measured input changes the defined register and reports its source. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md new file mode 100644 index 000000000..859a999e8 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-IMAGE-MEAS-003: ACPI table measurement and swtpm policy + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-image-meas-003](../../../feature-audit.md#req-ver-image-meas-003) +- Risks: [risk-ver-image-meas-003](../../../feature-audit.md#risk-ver-image-meas-003) +- Source: `dstack/dstack-mr/src` + +## Objective + +Verify acpi table measurement and swtpm policy across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for acpi table measurement and swtpm policy. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Compute/verify ACPI tables for swtpm false/true and supported QEMU/platform versions. + +**Expected results:** + +- Tables match VMM launch configuration; swtpm=true is explicitly unsupported by dstack-mr until implemented and fails clearly. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md new file mode 100644 index 000000000..c9a63b23f --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-IMAGE-MEAS-004: Artifact manifest and image hash binding + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-image-meas-004](../../../feature-audit.md#req-ver-image-meas-004) +- Risks: [risk-ver-image-meas-004](../../../feature-audit.md#risk-ver-image-meas-004) +- Source: `os/spec/artifact-manifest.schema.json` + +## Objective + +Verify artifact manifest and image hash binding across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for artifact manifest and image hash binding. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify artifact manifest schema, component digests, authenticode hash, image hash, and missing/extra artifacts. + +**Expected results:** + +- Only schema-valid complete manifests whose component and aggregate hashes match are accepted. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md new file mode 100644 index 000000000..648cb6fc4 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-IMAGE-MEAS-005: Measurement cache correctness and concurrency + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-ver-image-meas-005](../../../feature-audit.md#req-ver-image-meas-005) +- Risks: [risk-ver-image-meas-005](../../../feature-audit.md#risk-ver-image-meas-005) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify measurement cache correctness and concurrency across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for measurement cache correctness and concurrency. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify same/different image/config concurrently, corrupt cache, clear/retry, and change verifier version. + +**Expected results:** + +- Cache keys include every measurement input/version; writes are atomic and corruption triggers safe recomputation. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-strategy-006/case.md b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-strategy-006/case.md new file mode 100644 index 000000000..84c3e5d63 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/02-image-measurements/tc-ver-strategy-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-VER-STRATEGY-006: Platform-specific OS image verification and download strategy + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-strategy-006](../../../feature-audit.md#req-ver-strategy-006) +- Risks: [risk-ver-strategy-006](../../../feature-audit.md#risk-ver-strategy-006) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify platform-specific os image verification and download strategy against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Verify TDX full, TDX-lite, SEV-SNP, GCP TDX, Nitro Enclave and Nitro TPM with image server online/offline and altered platform-specific signed measurement/PCR/CBOR inputs. + +**Expected results:** + +- Full TDX downloads and replays measured image; lite and SNP use authenticated measurement material without download; GCP validates signed CBOR/image relation; Nitro variants validate required PCR mapping; no platform silently uses another strategy. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md new file mode 100644 index 000000000..69003790f --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-001: One-shot JSON verification interface + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-001](../../../feature-audit.md#req-ver-cli-cert-o-001) +- Risks: [risk-ver-cli-cert-o-001](../../../feature-audit.md#risk-ver-cli-cert-o-001) +- Source: `dstack/verifier/src/main.rs` + +## Objective + +Verify one-shot json verification interface across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for one-shot json verification interface. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Run verifier on valid, invalid, missing, oversized, and malformed JSON files and stdin/output modes. + +**Expected results:** + +- Exit status and structured output distinguish verified, unverified, and tool error; no panic or partial success occurs. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md new file mode 100644 index 000000000..54bf61898 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-002: Certificate RA extension verification + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-002](../../../feature-audit.md#req-ver-cli-cert-o-002) +- Risks: [risk-ver-cli-cert-o-002](../../../feature-audit.md#risk-ver-cli-cert-o-002) +- Source: `dstack/verifier/src/main.rs` + +## Objective + +Verify certificate ra extension verification across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for certificate ra extension verification. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify valid guest/gateway RA certificates and altered chain, validity, SAN, key usage, quote, app info, and image hash. + +**Expected results:** + +- PKI and attestation both verify and bind to the leaf key/app; any altered critical component fails. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md new file mode 100644 index 000000000..4cc61a3e2 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-003: OS image hash verification modes + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-003](../../../feature-audit.md#req-ver-cli-cert-o-003) +- Risks: [risk-ver-cli-cert-o-003](../../../feature-audit.md#risk-ver-cli-cert-o-003) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify os image hash verification modes across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for os image hash verification modes. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise strict image verification, configured allowlists, absent image, and download-disabled/offline modes. + +**Expected results:** + +- Output states computed/claimed/allowed hashes; strict mismatch fails and offline behavior never silently skips required checks. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md new file mode 100644 index 000000000..bc0ca95d0 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-004: Result schema completeness and diagnostics + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-004](../../../feature-audit.md#req-ver-cli-cert-o-004) +- Risks: [risk-ver-cli-cert-o-004](../../../feature-audit.md#risk-ver-cli-cert-o-004) +- Source: `dstack/verifier/src/types.rs` + +## Objective + +Verify result schema completeness and diagnostics across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for result schema completeness and diagnostics. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Inspect success and every major failure response field, status, measurements, properties, and warnings. + +**Expected results:** + +- Machine-readable output is stable, internally consistent, free of secrets, and identifies the exact failed trust assertion. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md new file mode 100644 index 000000000..568791b44 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-005: Configuration validation and trust roots + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-005](../../../feature-audit.md#req-ver-cli-cert-o-005) +- Risks: [risk-ver-cli-cert-o-005](../../../feature-audit.md#risk-ver-cli-cert-o-005) +- Source: `dstack/verifier/src/main.rs` + +## Objective + +Verify configuration validation and trust roots across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for configuration validation and trust roots. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Load custom/default trust roots, image sources, PCCS/collateral, timeouts, proxies, and conflicting settings. + +**Expected results:** + +- Valid config controls only intended verifier behavior; missing/invalid roots and unsafe conflicts fail at startup. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md new file mode 100644 index 000000000..e8c880159 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-CLI-CERT-O-006: Offline fixtures regression suite + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-cli-cert-o-006](../../../feature-audit.md#req-ver-cli-cert-o-006) +- Risks: [risk-ver-cli-cert-o-006](../../../feature-audit.md#risk-ver-cli-cert-o-006) +- Source: `dstack/verifier/fixtures` + +## Objective + +Verify offline fixtures regression suite across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for offline fixtures regression suite. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify all committed TDX-lite and SEV-SNP fixtures plus one-field mutation corpus. + +**Expected results:** + +- Known fixtures retain expected verdicts and each mutation fails at the corresponding verification stage. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md new file mode 100644 index 000000000..b3e8def75 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-VER-TCB-007: Canonical TCB status advisory and auth-policy projection + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-tcb-007](../../../feature-audit.md#req-ver-tcb-007) +- Risks: [risk-ver-tcb-007](../../../feature-audit.md#risk-ver-tcb-007) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify canonical tcb status advisory and auth-policy projection against each source-defined branch and trust assertion. + +## Preconditions + +1. Prepare isolated valid evidence and one-field mutations for each named platform/version/state. +2. Record trust roots, image/config/app identifiers, policy and dependency baseline without private material. + +## Test Data + +Use a decision table containing every condition in Step 1, relevant conflicting combinations, boundary lengths and a pinned historical-format row. + +## Steps + + +### Step 1: Execute the decision table + +Feed TDX/SNP/Nitro-TPM/Nitro-Enclave/GCP evidence with UpToDate, out-of-date, revoked, advisory lists, empty/no-TCB and conflicting top-level values; compare VerificationDetails and BootInfo. + +**Expected results:** + +- Canonical platform report is the sole source, TDX/SNP status/advisories propagate identically to auth, Nitro TPM uses defined UpToDate, no-TCB platforms remain empty/fail-closed, and conflicting unauthenticated fields are ignored/rejected. + + +### Step 2: Verify independent trust bindings and side effects + +Independently decode/verify evidence and compare policy inputs, cache/state mutation, returned public material and persisted artifacts for each row. + +**Expected results:** + +- Every accepted row satisfies all named bindings, rejected rows create no trusted cache/key/cert/route state, and output identifies the exact failed assertion. + + +### Step 3: Verify outage, restart, and cross-identity isolation + +Interrupt the external verifier/auth/image/network dependency, restart after accepted/rejected rows, and replay evidence under another app/node identity. + +**Expected results:** + +- Uncertainty fails closed, recovery does not reuse stale decisions, accepted state survives only as documented, and cross-identity replay or substitution fails. + +## Postconditions + +Remove run-scoped evidence/state and restore trust, cache, routing and dependency baselines. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-001/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-001/case.md new file mode 100644 index 000000000..43ea6bc20 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-001/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-001: dstack-mr supported platform CLI matrix + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-tools-001](../../../feature-audit.md#req-ver-tools-001) +- Risks: [risk-ver-tools-001](../../../feature-audit.md#risk-ver-tools-001) +- Source: `dstack/dstack-mr/cli` + +## Objective + +Verify dstack-mr supported platform cli matrix with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Run measurement CLI for every supported platform/image/config combination and the explicitly unsupported swtpm=true input. + +**Expected results:** + +- Supported outputs are deterministic and labeled by platform; swtpm=true fails immediately with an actionable unsupported message and no guessed measurement. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-002/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-002/case.md new file mode 100644 index 000000000..a4dbdfd5c --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-002/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-002: dstack-mr boot artifact and cmdline boundaries + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-tools-002](../../../feature-audit.md#req-ver-tools-002) +- Risks: [risk-ver-tools-002](../../../feature-audit.md#risk-ver-tools-002) +- Source: `dstack/dstack-mr/src` + +## Objective + +Verify dstack-mr boot artifact and cmdline boundaries with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Vary firmware, kernel, initrd, rootfs, cmdline ordering/quoting, CPU/QEMU version, and missing artifact inputs. + +**Expected results:** + +- Only measured changes alter defined registers; canonical cmdline rules match VMM and missing/ambiguous artifacts fail. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-003/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-003/case.md new file mode 100644 index 000000000..b35f72a4b --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-003/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-003: Attestation encode decode round trip and versioning + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-tools-003](../../../feature-audit.md#req-ver-tools-003) +- Risks: [risk-ver-tools-003](../../../feature-audit.md#risk-ver-tools-003) +- Source: `dstack/dstack-attest/src` + +## Objective + +Verify attestation encode decode round trip and versioning with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Round-trip each attestation variant through JSON/SCALE/msgpack and previous/current library versions, then mutate tag/length/required fields. + +**Expected results:** + +- Canonical round trips preserve authenticated bytes; supported old versions decode; unknown/truncated/oversized data fails without downgrade. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-004/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-004/case.md new file mode 100644 index 000000000..f7c09f185 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-004/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-004: Verifier library concurrent API isolation + +## Metadata + +- Priority: P1 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-tools-004](../../../feature-audit.md#req-ver-tools-004) +- Risks: [risk-ver-tools-004](../../../feature-audit.md#risk-ver-tools-004) +- Source: `dstack/verifier/src/lib.rs` + +## Objective + +Verify verifier library concurrent api isolation with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Call compute/verify/download from concurrent tasks with different trust roots, images, platforms, cancellations, and timeouts. + +**Expected results:** + +- Results remain request-scoped, cancellation releases resources, caches do not mix policies, and no task observes another request input. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-005/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-005/case.md new file mode 100644 index 000000000..e1894a682 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-005/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-005: Collateral and trust-root update lifecycle + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-ver-tools-005](../../../feature-audit.md#req-ver-tools-005) +- Risks: [risk-ver-tools-005](../../../feature-audit.md#risk-ver-tools-005) +- Source: `dstack/verifier/src/verification.rs` + +## Objective + +Verify collateral and trust-root update lifecycle with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Replace Intel/AMD/cloud/TPM roots and collateral before/at/after expiry while verification is concurrent. + +**Expected results:** + +- Atomic update uses the intended generation, retains auditable root identity, rejects rollback/untrusted roots, and never creates a verification gap. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-006/case.md b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-006/case.md new file mode 100644 index 000000000..a351484a9 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/04-measurement-tools/tc-ver-tools-006/case.md @@ -0,0 +1,69 @@ + + + +# TC-VER-TOOLS-006: Verifier denial-of-service input limits + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-ver-tools-006](../../../feature-audit.md#req-ver-tools-006) +- Risks: [risk-ver-tools-006](../../../feature-audit.md#risk-ver-tools-006) +- Source: `dstack/verifier/src/main.rs` + +## Objective + +Verify verifier denial-of-service input limits with explicit success, boundary, failure, restart, and isolation observations. + +## Preconditions + +1. The target runs in an isolated environment with effective configuration and synchronized evidence capture. +2. Baseline service, file, process, device, listener, and secret-redaction state has been recorded. + +## Test Data + +Use run-scoped identities and sentinel secrets that can be detected by hash without being retained in evidence. + +## Steps + + +### Step 1: Establish the baseline + +Query the effective configuration, service dependencies, listener/device state, and persisted files involved in this behavior. + +**Expected results:** + +- Required dependencies are healthy, ownership and permissions match policy, and no run-scoped object or sentinel is present before the action. + + +### Step 2: Exercise supported and boundary paths + +Submit deeply nested, oversized, compressed, event-heavy, certificate-chain-heavy, and slow image/evidence inputs concurrently. + +**Expected results:** + +- Configured size/time/concurrency limits bound CPU, memory, disk, and network while health and later valid verification remain available. + + +### Step 3: Exercise failure and recovery + +Inject one invalid input and one dependency interruption appropriate to the behavior, restore the dependency, and repeat the valid operation. + +**Expected results:** + +- Failure is bounded, fails closed, produces actionable redacted diagnostics, leaves no partial trusted state, and the repeated valid operation succeeds exactly once after recovery. + + +### Step 4: Verify isolation and persistence + +Restart the affected service or VM when permitted, re-query state, and check adjacent app/instance/node identities. + +**Expected results:** + +- Documented state persists, transient state disappears, adjacent identities are unchanged, and no private key, credential, or plaintext sentinel appears in APIs, metrics, dashboards, journals, or artifacts. + +## Postconditions + +Remove run-scoped state, undo fault injection, and verify services and devices returned to their recorded baseline. diff --git a/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-001/case.md b/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-001/case.md new file mode 100644 index 000000000..0e8402fcc --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VER-BUILD-001: Verifier image build pinning and runtime contents + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-build-001](../../../feature-audit.md#req-ver-build-001) +- Risks: [risk-ver-build-001](../../../feature-audit.md#risk-ver-build-001) +- Source: `dstack/verifier/builder/build-image.sh` + +## Objective + +Verify verifier image build pinning and runtime contents for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Build verifier image twice, inspect pinned tools/trust roots/QEMU data/users/entrypoint/SBOM, then change one pin and rebuild. + +**Expected results:** + +- Runtime contains exactly required verified artifacts, runs non-root where designed, unchanged build is reproducible and changed pin changes manifest/digest. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-002/case.md b/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-002/case.md new file mode 100644 index 000000000..cec2f6c92 --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/05-build-deployment/tc-ver-build-002/case.md @@ -0,0 +1,62 @@ + + + +# TC-VER-BUILD-002: Verifier default configuration and CLI override precedence + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-build-002](../../../feature-audit.md#req-ver-build-002) +- Risks: [risk-ver-build-002](../../../feature-audit.md#risk-ver-build-002) +- Source: `dstack/verifier/dstack-verifier.toml` + +## Objective + +Verify verifier default configuration and cli override precedence for documented success, boundary, failure, concurrency, and recovery behavior. + +## Preconditions + +1. Prepare isolated run-scoped inputs and capture effective configuration, service state, files, mounts, processes, network endpoints, and public status. +2. Use sentinel credentials only; evidence records hashes/presence and never the secret value. + +## Test Data + +The `verifier` portion of [`configuration-inventory.json`](../../../configuration-inventory.json) is mandatory test data. Exercise every listed field at its implicit default, an explicit valid value, boundary-invalid values, an unknown sibling field, and after restart. + +Include valid values, empty/minimum/maximum values, malformed input, duplicate invocation, a dependency outage, and an adjacent app or node identity. + +## Steps + + +### Step 1: Exercise the complete behavior matrix + +Run default/file/environment/CLI combinations for image URL/cache/trust/collateral/ACPI/timeouts, with unknown and invalid values. + +**Expected results:** + +- Precedence is deterministic and observable, unsafe/missing required trust config fails at startup, and overrides cannot silently disable required verification. + + +### Step 2: Verify failure atomicity and recovery + +Interrupt each external dependency before and after its commit point, issue a duplicate/concurrent request, restore the dependency, and retry. + +**Expected results:** + +- Uncertain input fails closed, no partial trusted output is consumed, resources are released, retry converges once, and diagnostics identify the exact phase without secrets. + + +### Step 3: Verify persistence, isolation, and cleanup + +Restart the owning service or VM where permitted, re-query all affected state, test the adjacent identity, and perform documented cleanup. + +**Expected results:** + +- Persistent/transient state follows policy, the adjacent identity is unchanged, no credential is exposed, and files, mounts, devices, processes, listeners, and counters return to baseline. + +## Postconditions + +Remove run-scoped inputs and faults; preserve redacted native outputs and required attachments. diff --git a/docs/test-plans/core-components-full/05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md b/docs/test-plans/core-components-full/05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md new file mode 100644 index 000000000..fc8e88a6e --- /dev/null +++ b/docs/test-plans/core-components-full/05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-VER-BUILDALL-001: Verifier and Measurement Tool Existing Regression Suite + +## Metadata + +- Priority: P0 +- Type: Build, Regression, Supply Chain, Security +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-ver-buildall-001](../../../feature-audit.md#req-ver-buildall-001) +- Risks: [risk-ver-buildall-001](../../../feature-audit.md#risk-ver-buildall-001) +- Source: `dstack/verifier/test.sh` + +## Objective + +Verify the complete component build, generated-interface, packaging, existing-test, and supply-chain baseline before product-level cases rely on the candidate. + +## Preconditions + +1. Use a clean checkout, empty component build caches, pinned toolchains, and recorded dependency mirrors. +2. Do not update locks or generated files during the test; capture any dirty working-tree diff. + +## Test Data + +Use the candidate commit, committed fixtures, lock files, image recipes, generated protobuf/OpenAPI sources, and all component-native test configurations. + +## Steps + + +### Step 1: Build from clean state + +Build verifier, dstack-mr and dstack-attest from clean state; run unit tests, committed fixture script, mutation tests and candidate container smoke test. + +**Expected results:** + +- All existing known-good fixtures verify, known-bad/mutated fixtures fail at expected stages, generated outputs are stable, and build pins/trust artifacts match the recorded candidate. + + +### Step 2: Verify generated and packaged artifacts + +Regenerate interfaces into a temporary tree, compare with committed output, inspect licenses/SBOM/locks/image contents and repeat the build with network disabled after dependency fetch. + +**Expected results:** + +- Generated output has no unexplained diff, offline rebuild succeeds from pins, required licenses are present, and packages contain only declared runtime/test content. + + +### Step 3: Verify failure detection + +Introduce one temporary source/test-fixture/schema/config mismatch outside the committed tree and confirm the relevant build/test/generation gate fails, then restore and rerun. + +**Expected results:** + +- The gate detects the controlled regression with a specific error and returns to a clean passing result after restoration. + +## Postconditions + +Remove temporary build/output trees and verify the candidate checkout remains clean. diff --git a/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-001/case.md b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-001/case.md new file mode 100644 index 000000000..d52cbb963 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-END-TO-END-001: New application deployment trust chain + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-end-to-end-001](../../../feature-audit.md#req-int-end-to-end-001) +- Risks: [risk-int-end-to-end-001](../../../feature-audit.md#risk-int-end-to-end-001) +- Source: `dstack/tests/e2e` + +## Objective + +Verify new application deployment trust chain across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for new application deployment trust chain. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Create VM, boot guest, obtain KMS keys, register gateway, serve TLS, and independently verify evidence. + +**Expected results:** + +- One app/instance identity links compose/image/vm config, keys, certificate, route, and verifier result end to end. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-002/case.md b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-002/case.md new file mode 100644 index 000000000..c6dc55748 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-END-TO-END-002: Application upgrade trust continuity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-end-to-end-002](../../../feature-audit.md#req-int-end-to-end-002) +- Risks: [risk-int-end-to-end-002](../../../feature-audit.md#risk-int-end-to-end-002) +- Source: `dstack/tests/e2e` + +## Objective + +Verify application upgrade trust continuity across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for application upgrade trust continuity. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Upgrade compose/image through authorized policy while retaining protected data and rotating derived artifacts as specified. + +**Expected results:** + +- Authorized continuity works without exposing old secrets; unauthorized rollback/cross-app upgrade is rejected at VMM/KMS/gateway/verifier boundaries. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-003/case.md b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-003/case.md new file mode 100644 index 000000000..0b5f4783a --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-END-TO-END-003: Encrypted environment delivery + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-end-to-end-003](../../../feature-audit.md#req-int-end-to-end-003) +- Risks: [risk-int-end-to-end-003](../../../feature-audit.md#risk-int-end-to-end-003) +- Source: `dstack/tests/e2e` + +## Objective + +Verify encrypted environment delivery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for encrypted environment delivery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Fetch signed env public key, encrypt secrets, deploy, decrypt in guest, and attempt replay/wrong-app substitution. + +**Expected results:** + +- Only intended app decrypts exact secrets; signatures/timestamp verify and plaintext never appears in VMM/gateway logs or metadata. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-004/case.md b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-004/case.md new file mode 100644 index 000000000..cefedcc81 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-END-TO-END-004: Gateway certificate attestation verification + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-end-to-end-004](../../../feature-audit.md#req-int-end-to-end-004) +- Risks: [risk-int-end-to-end-004](../../../feature-audit.md#risk-int-end-to-end-004) +- Source: `dstack/tests/e2e` + +## Objective + +Verify gateway certificate attestation verification across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway certificate attestation verification. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Issue gateway certificate, retrieve its history, and verify chain/attestation/image using verifier. + +**Expected results:** + +- Public certificate key and domain bind to valid gateway evidence and current trusted image across rotation. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-005/case.md b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-005/case.md new file mode 100644 index 000000000..079b587a0 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/01-end-to-end/tc-int-end-to-end-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-END-TO-END-005: Multi-instance load balancing and isolation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-end-to-end-005](../../../feature-audit.md#req-int-end-to-end-005) +- Risks: [risk-int-end-to-end-005](../../../feature-audit.md#risk-int-end-to-end-005) +- Source: `dstack/tests/e2e` + +## Objective + +Verify multi-instance load balancing and isolation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for multi-instance load balancing and isolation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Run multiple instances of same/different apps, remove/fail/re-register nodes, and send concurrent traffic. + +**Expected results:** + +- Routing selects only matching healthy app instances, drains failures, and never crosses app identity or port policy. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md new file mode 100644 index 000000000..e94ecea89 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-001: Persisted state migration from v0.5.4, v0.5.8, and v0.5.11 + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-compatibil-001](../../../feature-audit.md#req-int-compatibil-001) +- Risks: [risk-int-compatibil-001](../../../feature-audit.md#risk-int-compatibil-001) +- Source: `docs/test-plans` + +## Objective + +Verify candidate components read, migrate, preserve, and where supported roll back persisted state created independently by v0.5.4, v0.5.8, and v0.5.11. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for latest services with previous and latest guest images. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Create VMM workdirs/manifests, KMS onboard/key metadata, gateway WaveKV/certificate/DNS state, certbot workdirs and verifier caches with each pinned release. Copy each snapshot before first candidate start; start the candidate, exercise read and one mutation, restart, and attempt supported rollback using the untouched copy. + +**Expected results:** + +- The candidate detects each source schema, applies documented serde/default/cache migration without changing trust identity, preserves unknown/rollback-critical data, writes atomically, and either supports rollback or explicitly marks the migration one-way before mutation. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md new file mode 100644 index 000000000..68bcb7715 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-002: Rolling VMM upgrade with running mixed guests + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-compatibil-002](../../../feature-audit.md#req-int-compatibil-002) +- Risks: [risk-int-compatibil-002](../../../feature-audit.md#risk-int-compatibil-002) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify rolling vmm upgrade with running mixed guests across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for rolling vmm upgrade with running mixed guests. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Upgrade VMM around running/stopped previous/new guests and persisted workdirs. + +**Expected results:** + +- Running service impact matches policy, reload preserves state/config, and all supported control operations remain compatible. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md new file mode 100644 index 000000000..73d0cd21f --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-003: Rolling KMS cluster upgrade and key continuity + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-compatibil-003](../../../feature-audit.md#req-int-compatibil-003) +- Risks: [risk-int-compatibil-003](../../../feature-audit.md#risk-int-compatibil-003) +- Source: `dstack/kms/src/main_service.rs` + +## Objective + +Verify rolling kms cluster upgrade and key continuity across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for rolling kms cluster upgrade and key continuity. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Upgrade KMS nodes one at a time while old/new guests request app/cert/handover operations. + +**Expected results:** + +- Trust roots and app keys remain continuous, quorum/auth policy stays enforced, and new metadata fields are backward compatible. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md new file mode 100644 index 000000000..d15bcb2f0 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-004: Rolling gateway cluster upgrade + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-compatibil-004](../../../feature-audit.md#req-int-compatibil-004) +- Risks: [risk-int-compatibil-004](../../../feature-audit.md#risk-int-compatibil-004) +- Source: `dstack/gateway/src/kv` + +## Objective + +Verify rolling gateway cluster upgrade across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for rolling gateway cluster upgrade. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Mix previous/current gateway nodes while registering old/new guests, proxying traffic, syncing state, and renewing certificates. + +**Expected results:** + +- WireGuard, registration fallback, WaveKV protocol, port policy, traffic, and certificate locks interoperate without split brain. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md new file mode 100644 index 000000000..402f0d713 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-005: Verifier compatibility across evidence versions + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: UNIT +- Automation: Yes +- Requirements: [req-int-compatibil-005](../../../feature-audit.md#req-int-compatibil-005) +- Risks: [risk-int-compatibil-005](../../../feature-audit.md#risk-int-compatibil-005) +- Source: `dstack/verifier/src/types.rs` + +## Objective + +Verify verifier compatibility across evidence versions across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for verifier compatibility across evidence versions. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Verify old/current attestation envelopes, event logs, vm_config, image manifests, and certificates. + +**Expected results:** + +- Documented old formats remain accepted, unknown required versions fail clearly, and no downgrade bypasses new checks. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md new file mode 100644 index 000000000..1ac6e95ad --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-COMPATIBIL-006: RPC unknown-field and optional-field compatibility + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-compatibil-006](../../../feature-audit.md#req-int-compatibil-006) +- Risks: [risk-int-compatibil-006](../../../feature-audit.md#risk-int-compatibil-006) +- Source: `dstack/*/rpc/proto` + +## Objective + +Verify rpc unknown-field and optional-field compatibility across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for rpc unknown-field and optional-field compatibility. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Cross-call previous/current clients and servers for every protobuf service with new optional fields omitted/present/unknown. + +**Expected results:** + +- Defaults preserve old semantics, presence-sensitive fields remain distinguishable, and unknown fields do not crash or weaken policy. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-001/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-001/case.md new file mode 100644 index 000000000..da4cefc1c --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-001/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-001: KMS unavailable during boot and recovery + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-failure-se-001](../../../feature-audit.md#req-int-failure-se-001) +- Risks: [risk-int-failure-se-001](../../../feature-audit.md#risk-int-failure-se-001) +- Source: `os/common/rootfs/dstack-prepare.sh` + +## Objective + +Verify kms unavailable during boot and recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for kms unavailable during boot and recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot with all/some KMS URLs unavailable, slow, wrong-cert, and later restored. + +**Expected results:** + +- Guest retries/fails according to policy without reboot hot loop or plaintext fallback and resumes safely after trust is restored. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-002/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-002/case.md new file mode 100644 index 000000000..5ddb2517c --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-002/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-002: Gateway unavailable registration and recovery + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-failure-se-002](../../../feature-audit.md#req-int-failure-se-002) +- Risks: [risk-int-failure-se-002](../../../feature-audit.md#risk-int-failure-se-002) +- Source: `dstack/guest-agent/src/backend.rs` + +## Objective + +Verify gateway unavailable registration and recovery across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for gateway unavailable registration and recovery. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Boot and run while gateway URLs fail, return wrong identity, partition, and recover. + +**Expected results:** + +- Application/KMS function according to independence policy, registration retries are bounded, and recovered routing has one current peer mapping. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-003/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-003/case.md new file mode 100644 index 000000000..71576d606 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-003/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-003: VMM crash during every lifecycle transaction + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-failure-se-003](../../../feature-audit.md#req-int-failure-se-003) +- Risks: [risk-int-failure-se-003](../../../feature-audit.md#risk-int-failure-se-003) +- Source: `dstack/vmm/src/app.rs` + +## Objective + +Verify vmm crash during every lifecycle transaction across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for vmm crash during every lifecycle transaction. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Inject termination during create/start/update/resize/stop/remove and restart VMM. + +**Expected results:** + +- Atomic state recovery yields either previous or complete new state with no leaked device, port, key, disk, or process resources. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-004/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-004/case.md new file mode 100644 index 000000000..633aa7749 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-004/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-004: Certificate and clock boundary behavior + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-failure-se-004](../../../feature-audit.md#req-int-failure-se-004) +- Risks: [risk-int-failure-se-004](../../../feature-audit.md#risk-int-failure-se-004) +- Source: `dstack/tests/e2e` + +## Objective + +Verify certificate and clock boundary behavior across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for certificate and clock boundary behavior. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Skew clocks across guest/KMS/gateway/verifier around certificate, signature timestamp, ACME, and collateral boundaries. + +**Expected results:** + +- Defined tolerance is consistent; expired/not-yet-valid material fails and recovery after time correction requires no trust reset. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-005/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-005/case.md new file mode 100644 index 000000000..0b7d070d6 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-005/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-005: Credential and secret redaction audit + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-failure-se-005](../../../feature-audit.md#req-int-failure-se-005) +- Risks: [risk-int-failure-se-005](../../../feature-audit.md#risk-int-failure-se-005) +- Source: `dstack/tests/e2e` + +## Objective + +Verify credential and secret redaction audit across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for credential and secret redaction audit. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exercise failures with admin tokens, private keys, encrypted env, disk keys, DNS credentials, quotes, and CSRs. + +**Expected results:** + +- No secret appears in API errors, dashboards, metrics, journals, agent sessions, crash dumps, or packaged reports. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-006/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-006/case.md new file mode 100644 index 000000000..daf9a86bb --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-006/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-006: Resource exhaustion and backpressure + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-failure-se-006](../../../feature-audit.md#req-int-failure-se-006) +- Risks: [risk-int-failure-se-006](../../../feature-audit.md#risk-int-failure-se-006) +- Source: `dstack/tests/e2e` + +## Objective + +Verify resource exhaustion and backpressure across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for resource exhaustion and backpressure. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Exhaust disk, memory, file descriptors, connections, RPC body size, logs, and concurrent operations across components. + +**Expected results:** + +- Components enforce limits, remain responsive for health/admin recovery, preserve committed state, and recover without restart loops. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-007/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-007/case.md new file mode 100644 index 000000000..c1cfdd3f4 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-007/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-007: Network partition consistency matrix + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-failure-se-007](../../../feature-audit.md#req-int-failure-se-007) +- Risks: [risk-int-failure-se-007](../../../feature-audit.md#risk-int-failure-se-007) +- Source: `dstack/tests/e2e` + +## Objective + +Verify network partition consistency matrix across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for network partition consistency matrix. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Partition every pair among VMM, guest, KMS, gateway nodes, verifier/image source, then heal. + +**Expected results:** + +- Safety properties fail closed, independent local functions continue where specified, and healed state converges without stale authorization. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-008/case.md b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-008/case.md new file mode 100644 index 000000000..9b40de77f --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/03-failure-security/tc-int-failure-se-008/case.md @@ -0,0 +1,60 @@ + + + +# TC-INT-FAILURE-SE-008: Simulator versus hardware evidence separation + +## Metadata + +- Priority: P0 +- Type: Functional, Security, Regression, Compatibility +- Minimum environment: HARDWARE +- Automation: Yes +- Requirements: [req-int-failure-se-008](../../../feature-audit.md#req-int-failure-se-008) +- Risks: [risk-int-failure-se-008](../../../feature-audit.md#risk-int-failure-se-008) +- Source: `docs/development-without-tee.md` + +## Objective + +Verify simulator versus hardware evidence separation across success, boundary, failure, security, and recovery conditions. + +## Preconditions + +1. The shared plan prerequisites are healthy and the target listener is reachable. +2. Commands use isolated test data and preserve native request and response output. + +## Test Data + +Use a unique run-scoped identifier and non-production credentials. + +## Steps + + +### Step 1: Inspect the effective prerequisite + +Query the relevant health, configuration, and baseline state for simulator versus hardware evidence separation. + +**Expected results:** + +- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object. + + +### Step 2: Exercise the behavior + +Run equivalent core flows under no-TEE simulation and supported hardware. + +**Expected results:** + +- Reports label simulation and list hardware-unconfirmed assertions; production endpoints reject simulated credentials/evidence. + + +### Step 3: Verify state, isolation, and diagnostics + +Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface. + +**Expected results:** + +- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability. + +## Postconditions + +Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md new file mode 100644 index 000000000..13e2617cf --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-001: Latest VMM hosts the full pinned guest matrix + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-001](../../../feature-audit.md#req-int-mixed-001) +- Risks: [risk-int-mixed-001](../../../feature-audit.md#risk-int-mixed-001) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify candidate VMM can concurrently host guest images v0.5.4, v0.5.8, v0.5.11, and candidate. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Deploy one isolated app/instance per pinned image on the same candidate VMM pool, then exercise boot/status/key/registration/traffic/stop/start/remove operations. + +**Expected results:** + +- All documented images run concurrently; per-version fallback and unsupported fields remain instance-scoped and VMM control of one generation does not regress another. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md new file mode 100644 index 000000000..39920fb30 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-002: Mixed KMS versions remain online during application operations + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-002](../../../feature-audit.md#req-int-mixed-002) +- Risks: [risk-int-mixed-002](../../../feature-audit.md#risk-int-mixed-002) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify applications can operate while compatible KMS nodes at v0.5.4, v0.5.8, v0.5.11, bridge where required, and candidate coexist. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +After executing valid onboard paths, distribute client URL ordering across versions and perform existing/new app boot, key, env-public-key and certificate operations during node loss. + +**Expected results:** + +- Requests reaching a compatible node preserve one root/app identity; retry/failover is safe and version-specific unsupported calls are explicit. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Also insert an independently bootstrapped KMS with a different CA/root into the client URL list and direct requests to it. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, and repeated onboarding is safe. The foreign-root endpoint is rejected or quarantined before its keys/certificates are accepted and cannot split application identity. Retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md new file mode 100644 index 000000000..1bd7f21e6 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-003: Mixed gateway versions route old and new guests + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-003](../../../feature-audit.md#req-int-mixed-003) +- Risks: [risk-int-mixed-003](../../../feature-audit.md#risk-int-mixed-003) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify gateway v0.5.4, v0.5.8, v0.5.11 and candidate nodes can coexist only in the combinations/protocols documented as supported. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Register each pinned guest generation, synchronize/reroute traffic across gateway versions, exercise old missing port-policy fields and candidate policies, then fail nodes. + +**Expected results:** + +- Supported routing remains app-isolated with correct WireGuard/certificate identity; incompatible cluster-sync or policy combinations are detected and handled by deployment/cutover rather than silently weakening enforcement. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md new file mode 100644 index 000000000..ada29e5a0 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-004: Gateway replacement matrix after KMS cutover + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-004](../../../feature-audit.md#req-int-mixed-004) +- Risks: [risk-int-mixed-004](../../../feature-audit.md#risk-int-mixed-004) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify each pinned old gateway can remain a traffic rollback target while candidate gateway is introduced after KMS 0.6.0 health. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +For v0.5.4, v0.5.8 and v0.5.11 gateway sources, deploy rather than in-place mutate candidate gateway, smoke-test cert issuance and traffic, shift load, and roll back. + +**Expected results:** + +- Candidate and retained old gateway use the preserved KMS CA/root, serve expected guest generations, and DNS/LB cutover does not expose an untested certificate or route. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md new file mode 100644 index 000000000..ab01f1e00 --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-005: Verifier evidence compatibility for pinned releases + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-005](../../../feature-audit.md#req-int-mixed-005) +- Risks: [risk-int-mixed-005](../../../feature-audit.md#risk-int-mixed-005) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify candidate verifier and pinned old consumers against evidence/certificates/images produced by v0.5.4, v0.5.8, v0.5.11 and candidate. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Build a labeled corpus from each version and run candidate verification plus old verifier/consumer paths only where their capability matrix claims support. + +**Expected results:** + +- Candidate accepts every documented historical format with correct measurements; old tools reject new OID/lite/OVMF inputs explicitly and no downgrade is classified as successful verification. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md new file mode 100644 index 000000000..6f895797d --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-006: Rolling restart under four-version online mix + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-006](../../../feature-audit.md#req-int-mixed-006) +- Risks: [risk-int-mixed-006](../../../feature-audit.md#risk-int-mixed-006) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify state and identity survive sequential restart of old/new KMS and gateway nodes while candidate VMM keeps all guest generations running. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Maintain continuous key/cert/traffic probes while restarting one node at a time in v0.5.4→v0.5.8→v0.5.11→candidate order and reverse. + +**Expected results:** + +- Quorum/availability remain within policy, one trust identity persists, cluster state converges, and probes reveal no version-dependent data loss or cross-app routing. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md new file mode 100644 index 000000000..ac5aec52b --- /dev/null +++ b/docs/test-plans/core-components-full/06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md @@ -0,0 +1,71 @@ + + + +# TC-INT-MIXED-007: Optional and unknown protobuf fields across pinned versions + +## Metadata + +- Priority: P0 +- Type: Compatibility, Upgrade, Security, Regression +- Minimum environment: INTEGRATION +- Automation: Yes +- Requirements: [req-int-mixed-007](../../../feature-audit.md#req-int-mixed-007) +- Risks: [risk-int-mixed-007](../../../feature-audit.md#risk-int-mixed-007) +- Source: [PR #705 upgrade plan](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md) + +## Objective + +Verify exact presence semantics at v0.5.4, v0.5.8, v0.5.11 and candidate service/client boundaries. + +## Preconditions + +1. The latest candidate VMM is installed with `qemu_single_pass_add_pages=true` and `qemu_pic=true`. +2. Source KMS root/CA and test-app derived-key fingerprints are recorded without exporting private keys. +3. Source and target `mrAggregated` plus the target image hash are authorized, and the source can download the target verifier archive. +4. At least two source KMS nodes remain available for rollback; destructive retirement is deferred until validation finishes. + +## Test Data + +Use pinned, digest-recorded images and binaries. “0.6.0” means the candidate under test. Record exact 0.5.x artifact tags/commits and QEMU/OVMF/ACPI-table versions in result overrides. + +## Steps + + +### Step 1: Run pre-flight measurement and trust checks + +Capture source/target metadata, allowlists, image availability, `vm_config`, quote, CA and k256 public-key fingerprints. Run the age-appropriate `dstack-mr diagnose` when applicable. + +**Expected results:** + +- Both endpoint identities and the target image are authorized, target artifacts are downloadable, expected measurements reproduce the target quote, and no root or private key is exported. + + +### Step 2: Execute the compatibility path + +Replay captured requests with candidate fields omitted, unknown to old servers, explicitly empty, and populated across KMS/gateway/guest/VMM APIs. + +**Expected results:** + +- Old-compatible defaults preserve historical behavior, reported-empty remains distinct from not-reported where required, and unknown fields never crash or weaken authorization/port policy. + + +### Step 3: Verify key, CA, application, and service continuity + +Compare `GetMeta`, CA chain, root k256 public key, existing-app key/signature fingerprints, new-app provisioning, certificate signing, and authorization decisions through every surviving old/new KMS endpoint. + +**Expected results:** + +- All successfully onboarded nodes retain the original CA/root identity and return identical app-scoped material and policy decisions; old and new endpoints remain usable according to the stated matrix. + + +### Step 4: Exercise failure, rollback, and retirement boundaries + +Interrupt one hop before and after key transfer, remove the incomplete target, restore client routing to retained source nodes, then repeat successfully. Retire an old node only after all continuity checks pass. + +**Expected results:** + +- A failed hop does not alter the source root, clients can immediately use retained sources, repeated onboarding is safe, and retirement leaves at least two verified 0.6.0 root holders. + +## Postconditions + +Keep the old nodes for the configured rollback window, remove failed bridge/target instances, and retain only redacted fingerprints, quotes, configs, and diagnostics. diff --git a/docs/test-plans/core-components-full/README.md b/docs/test-plans/core-components-full/README.md new file mode 100644 index 000000000..80fc11792 --- /dev/null +++ b/docs/test-plans/core-components-full/README.md @@ -0,0 +1,167 @@ + + + +# dstack Core Components Full Test Plan + +## 1. Objective and scope + +This plan is a source-derived, full functional audit of the dstack guest OS, VMM, KMS, gateway, verifier, and their trust and compatibility boundaries. It covers every protobuf RPC method present at authoring time plus non-RPC boot, configuration, storage, networking, cryptographic, measurement, proxy, certificate, cluster, UI, operational, recovery, upgrade, and security behavior found in the component source trees. + +The authoritative execution order is `index.json`. Traceability is in +`feature-audit.md`; the raw repository scan is `source-inventory.json` and the +mandatory 214-field configuration matrix is `configuration-inventory.json`, the complete protobuf field matrix is `api-inventory.json`, and reverse file-to-case traceability is `source-coverage-map.json`. +A source reference means the case must be reviewed when that implementation +surface changes. Passing existing unit tests is evidence for a step only when +the case explicitly runs them; it never substitutes for product-level expected +results. + +## 2. Repository scope + +| Chapter | Primary source roots | +|---|---| +| Guest OS | `os/`, `dstack/guest-agent`, `guest-api`, `supervisor`, `dstack-util`, `local-key-provider`, `tee-simulator` | +| VMM | `dstack/vmm`, `dstack/host-api` | +| KMS | `dstack/kms` including mock/simple/Ethereum authorization implementations | +| Gateway | `dstack/gateway`, `dstack/certbot` | +| Verifier | `dstack/verifier`, `dstack-mr`, `dstack-attest`, image artifact specification | +| Integration | `dstack/tests/e2e`, all cross-component protocols and persisted state | + +Before a release run, update `source-inventory.json`, compare RPC/config/source changes with this plan, and add or amend cases before execution. + +## 3. Required topology + +Prepare isolated namespaces and credentials for: + +1. one control host with the candidate repository and `dstack-test`; +2. at least two VMM nodes when cluster/failover behavior is tested; +3. at least three KMS/gateway nodes for rolling-upgrade and partition cases; +4. pinned `v0.5.4`, `v0.5.8`, `v0.5.11`, and candidate guest images; +5. a private OCI registry capable of bearer authentication and fault injection; +6. DNS zones and an ACME staging account, never a production ACME account; +7. controllable HTTP/TCP/TLS/Proxy-Protocol capture backends; +8. an Ethereum development chain and deployed test authorization contract; +9. a fault-injection network supporting latency, loss, partition, and clock-control; +10. a log/artifact sink with secrets redaction. + +Use unique run-scoped domains, ports, app IDs, instance names, DNS records, registry tags, and storage paths. Never point destructive Admin, Exit, Clear, Remove, Delete, or certificate cases at production. + +## 4. Environment levels + +- `UNIT`: repository build/test tools and committed fixtures only. +- `SIMULATOR`: follow `docs/development-without-tee.md`. The local key provider may use TPM mode when its default mode cannot start. +- `INTEGRATION`: deployed multi-component environment; a TEE simulator is allowed only when the case does not claim hardware properties. +- `HARDWARE`: supported physical TDX/TDX-lite, SEV-SNP, GCP TDX, Nitro TPM, or GPU hardware as named by the case. + +Simulation is not confirmation of measured boot, quote/certificate collateral, physical device isolation, sealing, TPM/PCR behavior, GPU attestation, or platform firmware measurements. A simulator result must be labeled simulated. If a hardware case is run only under simulation, report it separately as unconfirmed; do not mark the hardware case PASS. + +## 5. Common setup and context + +Record actual component commits, image digests, firmware/QEMU/kernel versions, authorization implementation and contract, registry, DNS provider, ACME directory, TEE hardware, and topology once in the run context: + +```json +{ + "software_under_test": { + "repository": "Dstack-TEE/dstack", + "candidate": "", + "compatibility_releases": ["v0.5.4", "v0.5.8", "v0.5.11"], + "guest_images": { + "v0.5.4": "", "v0.5.8": "", + "v0.5.11": "", "candidate": "" + }, + "vmm": "", "kms": "", "gateway": "", "verifier": "" + }, + "environment": { + "level": "HARDWARE", + "simulated": false, + "topology": "" + } +} +``` + +Use the generated pRPC clients or a pinned generic pRPC helper. Preserve request and response bodies after redacting credentials. Capture effective TOML, systemd unit state, QEMU command line, VM configuration, image/compose hashes, component health, and synchronized clocks before case execution. + +## 6. Execution rules + +1. Read this guide, `index.json`, and the current case before acting. +2. Execute cases in index order unless the orchestrator proves a recorded dependency makes a later case meaningless. +3. Every executed case gets an independent Agent session. Commands and raw outputs remain in `session.jsonl`. +4. A case is PASS only when every expected result is fully observed. There is no separate failure criterion. +5. Use BLOCKED only when an external prerequisite prevents the tested behavior from starting. +6. Use SKIPPED only for an authorized omission or a proven dependency consequence, with causal case IDs. +7. Do not change a product configuration merely to force an expected result unless the case instructs that change. +8. Do not restart physical hosts; cases requiring it must use VM/service/device-level recovery or be reported unconfirmed. +9. Stop a destructive case immediately if its target identity is not the isolated run-scoped environment. +10. Continue independent chapters after failures. + +Run with the live dashboard: + +```bash +tools/dstack-test/dstack-test run-plan \ + --plan docs/test-plans/core-components-full \ + --context run-context.json \ + --web \ + -- "Do not restart physical hosts" +``` + +Resume an interrupted run with its printed run ID: + +```bash +tools/dstack-test/dstack-test run-plan \ + --plan docs/test-plans/core-components-full \ + --run-id --resume --web +``` + +## 7. Evidence and redaction + +Each logical step must have at least one observed command/tool result in the native Agent session. Attach packet captures, screenshots, QEMU arguments, measurement calculations, certificates, manifests, synchronized cluster snapshots, or long logs under the case result `artifacts/` directory. + +Never retain admin tokens, private keys, disk/env plaintext keys, DNS secrets, ACME account keys, Ethereum private keys, reusable cookies, or decrypted application secrets. Quotes, public certificates, public keys, hashes, and redacted configuration may be retained. For a redaction test, record hashes or sentinel-presence checks rather than the secret itself. + +## 8. Compatibility policy + +Compatibility cases keep VMM on the candidate release by default. Guest images +and online KMS, gateway, and verifier consumers may simultaneously include +`v0.5.4`, `v0.5.8`, `v0.5.11`, and the candidate. Test request distribution, +node loss, restart, state synchronization, old/new client-server directions, +protobuf optional and unknown fields, persisted old state, rolling cutover and +explicit rejection of unsupported combinations. Record the exact tag, commit, +image digest, QEMU, firmware, and backported patch set for every historical +node as a case-level override. + +### 8.1 KMS onboarding to the 0.6.0 candidate + +Follow the validated matrix in [PR #705](https://github.com/Dstack-TEE/dstack/blob/203e09bcbce27e566f157d2b6ed4657eb949459a/docs/operations/kms-upgrade-plan.md): + +| Source KMS | Required path to the 0.6.0 candidate | +|---|---| +| `v0.5.4` | `0.5.4 → 0.5.7 bridge → 0.6.0` | +| `v0.5.8` | direct to `0.6.0` | +| `kms-v0.5.11` | direct to `0.6.0`; record whether PR #693 is included | + +The candidate target must boot on its matching candidate OS with **legacy TDX +attestation**, never lite or an `auto` decision that resolves to lite, while an +old source verifies it. The latest VMM must use +`qemu_single_pass_add_pages=true` and `qemu_pic=true`. Both source and target +`mrAggregated` values and the target image hash must be authorized; the source +must download the target verifier archive. A healthy onboard preserves the CA, +root k256 public key, existing application keys, and certificate trust. + +Direct `0.5.4 → 0.6.0` is a required negative test: it must fail before key +transfer because 0.5.4 cannot extract the versioned RA-TLS attestation OID. +Use QEMU 9.1.50-era `dstack-acpi-tables` when diagnosing 0.5.4 measurements. +Upgrade gateway only after KMS 0.6.0 key and certificate operations pass, and +retain old KMS/gateway nodes for a tested rollback window. + +## 9. Cleanup + +Delete run-scoped VMs, workdirs, taps, port mappings, GPU bindings, registry artifacts, DNS records, ACME staging orders, WaveKV objects, authorization contracts/state, temporary KMS nodes, certificates, storage volumes, firewall rules, and fault-injection rules. Verify host devices and services returned to their baseline. Preserve only redacted report artifacts. + +## 10. Finalization + +```bash +tools/dstack-test/dstack-test validate --plan docs/test-plans/core-components-full --run-id +tools/dstack-test/dstack-test render --plan docs/test-plans/core-components-full --run-id --output report.html +tools/dstack-test/dstack-test package --plan docs/test-plans/core-components-full --run-id --output report.tar.gz +``` + +The release summary must list every FAIL, BLOCKED, SKIPPED, NOT_RUN, simulation-only result, hardware-unconfirmed item, compatibility gap, and deviation from this plan. diff --git a/docs/test-plans/core-components-full/api-inventory.json b/docs/test-plans/core-components-full/api-inventory.json new file mode 100644 index 000000000..d9ebce091 --- /dev/null +++ b/docs/test-plans/core-components-full/api-inventory.json @@ -0,0 +1,9256 @@ +{ + "schema_version": "1.0", + "description": "Every RPC case must exercise every request field and validate every response field listed here, including absent/default/present, boundary-invalid, unknown-field and authorization behavior.", + "components": { + "guest-os": { + "rpc_methods": [ + { + "service": "Tappd", + "method": "DeriveKey", + "request": "DeriveKeyArgs", + "response": "GetTlsKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 15, + "case_id": "tc-gos-tappd-001", + "request_fields": [ + { + "type": "string", + "name": "path", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "subject", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "alt_names", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "usage_ra_tls", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_server_auth", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_client_auth", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "random_seed", + "number": 7, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "certificate_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Tappd", + "method": "DeriveK256Key", + "request": "GetKeyArgs", + "response": "DeriveK256KeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 18, + "case_id": "tc-gos-tappd-002", + "request_fields": [ + { + "type": "string", + "name": "path", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "purpose", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "algorithm", + "number": 3, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "k256_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_signature_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Tappd", + "method": "TdxQuote", + "request": "TdxQuoteArgs", + "response": "TdxQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 21, + "case_id": "tc-gos-tappd-003", + "request_fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "hash_algorithm", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "prefix", + "number": 3, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "hash_algorithm", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "prefix", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Tappd", + "method": "RawQuote", + "request": "RawQuoteArgs", + "response": "TdxQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 28, + "case_id": "tc-gos-tappd-004", + "request_fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "hash_algorithm", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "prefix", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Tappd", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 31, + "case_id": "tc-gos-tappd-005", + "request_fields": [], + "response_fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "key_provider_info", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "compose_hash", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_vendor", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_product", + "number": 16, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Tappd", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 34, + "case_id": "tc-gos-tappd-006", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "GetTlsKey", + "request": "GetTlsKeyArgs", + "response": "GetTlsKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 41, + "case_id": "tc-gos-dstackguest-001", + "request_fields": [ + { + "type": "string", + "name": "subject", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "alt_names", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "usage_ra_tls", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_server_auth", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_client_auth", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "not_before", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "not_after", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "with_app_info", + "number": 8, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "certificate_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "DstackGuest", + "method": "GetKey", + "request": "GetKeyArgs", + "response": "GetKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 44, + "case_id": "tc-gos-dstackguest-002", + "request_fields": [ + { + "type": "string", + "name": "path", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "purpose", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "algorithm", + "number": 3, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "DstackGuest", + "method": "GetQuote", + "request": "RawQuoteArgs", + "response": "GetQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 47, + "case_id": "tc-gos-dstackguest-003", + "request_fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "report_data", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "attestation", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "Attest", + "request": "RawQuoteArgs", + "response": "AttestResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 51, + "case_id": "tc-gos-dstackguest-004", + "request_fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "attestation", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 54, + "case_id": "tc-gos-dstackguest-005", + "request_fields": [], + "response_fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "key_provider_info", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "compose_hash", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_vendor", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_product", + "number": 16, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "GpuInfo", + "request": "google.protobuf.Empty", + "response": "GpuInfoResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 57, + "case_id": "tc-gos-dstackguest-006", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "attestation", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "Sign", + "request": "SignRequest", + "response": "SignResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 60, + "case_id": "tc-gos-dstackguest-007", + "request_fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "data", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "signature", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_chain", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "public_key", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "Verify", + "request": "VerifyRequest", + "response": "VerifyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 63, + "case_id": "tc-gos-dstackguest-008", + "request_fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "data", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "public_key", + "number": 4, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bool", + "name": "valid", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "DstackGuest", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 66, + "case_id": "tc-gos-dstackguest-009", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Worker", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 255, + "case_id": "tc-gos-worker-001", + "request_fields": [], + "response_fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "key_provider_info", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "compose_hash", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_vendor", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_product", + "number": 16, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Worker", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 257, + "case_id": "tc-gos-worker-002", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Worker", + "method": "GetAttestationForAppKey", + "request": "GetAttestationForAppKeyRequest", + "response": "GetQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 259, + "case_id": "tc-gos-worker-003", + "request_fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "report_data", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "attestation", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "GuestApi", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "GuestInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 135, + "case_id": "tc-gos-guestapi-001", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "GuestApi", + "method": "SysInfo", + "request": "google.protobuf.Empty", + "response": "SystemInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 137, + "case_id": "tc-gos-guestapi-002", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "os_name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "os_version", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kernel_version", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cpu_model", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "num_cpus", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_memory", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "available_memory", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_memory", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_memory", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_swap", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_swap", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_swap", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "uptime", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_one", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_five", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_fifteen", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "DiskInfo", + "name": "disks", + "number": 17, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "GuestApi", + "method": "NetworkInfo", + "request": "google.protobuf.Empty", + "response": "NetworkInformation", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 139, + "case_id": "tc-gos-guestapi-003", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "dns_servers", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "Gateway", + "name": "gateways", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "Interface", + "name": "interfaces", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "wg_info", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "GuestApi", + "method": "ListContainers", + "request": "google.protobuf.Empty", + "response": "ListContainersResponse", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 141, + "case_id": "tc-gos-guestapi-004", + "request_fields": [], + "response_fields": [ + { + "type": "Container", + "name": "containers", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "GuestApi", + "method": "Shutdown", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 143, + "case_id": "tc-gos-guestapi-005", + "request_fields": [], + "response_fields": [] + }, + { + "service": "ProxiedGuestApi", + "method": "Info", + "request": "Id", + "response": "GuestInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 148, + "case_id": "tc-gos-proxiedguestapi-001", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "ProxiedGuestApi", + "method": "SysInfo", + "request": "Id", + "response": "SystemInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 149, + "case_id": "tc-gos-proxiedguestapi-002", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "os_name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "os_version", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kernel_version", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cpu_model", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "num_cpus", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_memory", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "available_memory", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_memory", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_memory", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_swap", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_swap", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_swap", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "uptime", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_one", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_five", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_fifteen", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "DiskInfo", + "name": "disks", + "number": 17, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "ProxiedGuestApi", + "method": "NetworkInfo", + "request": "Id", + "response": "NetworkInformation", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 150, + "case_id": "tc-gos-proxiedguestapi-003", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "dns_servers", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "Gateway", + "name": "gateways", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "Interface", + "name": "interfaces", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "wg_info", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "ProxiedGuestApi", + "method": "ListContainers", + "request": "Id", + "response": "ListContainersResponse", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 151, + "case_id": "tc-gos-proxiedguestapi-004", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "Container", + "name": "containers", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "ProxiedGuestApi", + "method": "Shutdown", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 152, + "case_id": "tc-gos-proxiedguestapi-005", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + } + ], + "message_schemas": [ + { + "name": "GetTlsKeyArgs", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "subject", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "alt_names", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "usage_ra_tls", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_server_auth", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_client_auth", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "not_before", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "not_after", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "with_app_info", + "number": 8, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DeriveKeyArgs", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "path", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "subject", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "alt_names", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "usage_ra_tls", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_server_auth", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "usage_client_auth", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "random_seed", + "number": 7, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetTlsKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "certificate_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GetKeyArgs", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "path", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "purpose", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "algorithm", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DeriveK256KeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "k256_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_signature_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GetKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_chain", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "TdxQuoteArgs", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "hash_algorithm", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "prefix", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "RawQuoteArgs", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "report_data", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "TdxQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "hash_algorithm", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "prefix", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AttestResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "attestation", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GpuInfoResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "attestation", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "event_log", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "report_data", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "attestation", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "key_provider_info", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "compose_hash", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_vendor", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cloud_product", + "number": 16, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SignRequest", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "data", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SignResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "signature", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_chain", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "public_key", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "VerifyRequest", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "data", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "public_key", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "VerifyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "valid", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetAttestationForAppKeyRequest", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "fields": [ + { + "type": "string", + "name": "algorithm", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "Id", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GuestInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "instance_id", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_cert", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tcb_info", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "device_id", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "IpAddress", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "address", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "prefix", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "Interface", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "IpAddress", + "name": "addresses", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "uint64", + "name": "rx_bytes", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "tx_bytes", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "rx_errors", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "tx_errors", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "Gateway", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "address", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "NetworkInformation", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "dns_servers", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "Gateway", + "name": "gateways", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "Interface", + "name": "interfaces", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "wg_info", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListContainersResponse", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "Container", + "name": "containers", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "Container", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "names", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "image", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "image_id", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "int64", + "name": "created", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "state", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 8, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SystemInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "os_name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "os_version", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kernel_version", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cpu_model", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "num_cpus", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_memory", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "available_memory", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_memory", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_memory", + "number": 9, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_swap", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "used_swap", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_swap", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "uptime", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_one", + "number": 14, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_five", + "number": 15, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "loadavg_fifteen", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "DiskInfo", + "name": "disks", + "number": 17, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "DiskInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "mount_point", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "total_size", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "free_size", + "number": 5, + "optional": false, + "repeated": false + } + ] + } + ] + }, + "vmm": { + "rpc_methods": [ + { + "service": "Vmm", + "method": "CreateVm", + "request": "VmConfiguration", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 339, + "case_id": "tc-vmm-vmm-001", + "request_fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 9, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "hugepages", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "pin_numa", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 14, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "gateway_urls", + "number": 15, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "stopped", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 17, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networking", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 19, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "simulated_tee", + "number": 21, + "optional": true, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "StartVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 341, + "case_id": "tc-vmm-vmm-002", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "StopVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 343, + "case_id": "tc-vmm-vmm-003", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "RemoveVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 345, + "case_id": "tc-vmm-vmm-004", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "UpgradeApp", + "request": "UpdateVmRequest", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 347, + "case_id": "tc-vmm-vmm-005", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "update_ports", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_kms_urls", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 9, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_gateway_urls", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_urls", + "number": 11, + "optional": false, + "repeated": true + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 14, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 15, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 16, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 17, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "update_networking", + "number": 19, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 20, + "optional": false, + "repeated": true + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "UpdateVm", + "request": "UpdateVmRequest", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 349, + "case_id": "tc-vmm-vmm-006", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "update_ports", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_kms_urls", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 9, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_gateway_urls", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_urls", + "number": 11, + "optional": false, + "repeated": true + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 14, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 15, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 16, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 17, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "update_networking", + "number": 19, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 20, + "optional": false, + "repeated": true + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "ShutdownVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 351, + "case_id": "tc-vmm-vmm-007", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "ResizeVm", + "request": "ResizeVmRequest", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 353, + "case_id": "tc-vmm-vmm-008", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 5, + "optional": true, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "GetComposeHash", + "request": "VmConfiguration", + "response": "ComposeHash", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 355, + "case_id": "tc-vmm-vmm-009", + "request_fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 9, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "hugepages", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "pin_numa", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 14, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "gateway_urls", + "number": 15, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "stopped", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 17, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networking", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 19, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "simulated_tee", + "number": 21, + "optional": true, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "hash", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "Status", + "request": "StatusRequest", + "response": "StatusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 358, + "case_id": "tc-vmm-vmm-010", + "request_fields": [ + { + "type": "string", + "name": "ids", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "brief", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "keyword", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "page", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "page_size", + "number": 5, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "VmInfo", + "name": "vms", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "port_mapping_enabled", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "total", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "ListImages", + "request": "google.protobuf.Empty", + "response": "ImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 360, + "case_id": "tc-vmm-vmm-011", + "request_fields": [], + "response_fields": [ + { + "type": "ImageInfo", + "name": "images", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Vmm", + "method": "GetAppEnvEncryptPubKey", + "request": "AppId", + "response": "PublicKeyResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 363, + "case_id": "tc-vmm-vmm-012", + "request_fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_v1", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "GetInfo", + "request": "Id", + "response": "GetInfoResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 366, + "case_id": "tc-vmm-vmm-013", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bool", + "name": "found", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "VmInfo", + "name": "info", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "VersionResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 369, + "case_id": "tc-vmm-vmm-014", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 372, + "case_id": "tc-vmm-vmm-015", + "request_fields": [], + "response_fields": [ + { + "type": "KmsSettings", + "name": "kms", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "GatewaySettings", + "name": "gateway", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "ResourcesSettings", + "name": "resources", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingCapabilities", + "name": "networking", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "ListGpus", + "request": "google.protobuf.Empty", + "response": "ListGpusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 375, + "case_id": "tc-vmm-vmm-016", + "request_fields": [], + "response_fields": [ + { + "type": "GpuInfo", + "name": "gpus", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "allow_attach_all", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "ReloadVms", + "request": "google.protobuf.Empty", + "response": "ReloadVmsResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 378, + "case_id": "tc-vmm-vmm-017", + "request_fields": [], + "response_fields": [ + { + "type": "uint32", + "name": "loaded", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "updated", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "removed", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Vmm", + "method": "SvList", + "request": "google.protobuf.Empty", + "response": "SvListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 381, + "case_id": "tc-vmm-vmm-018", + "request_fields": [], + "response_fields": [ + { + "type": "SvProcessInfo", + "name": "processes", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Vmm", + "method": "SvStop", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 383, + "case_id": "tc-vmm-vmm-019", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "SvRemove", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 385, + "case_id": "tc-vmm-vmm-020", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "ListRegistryImages", + "request": "google.protobuf.Empty", + "response": "RegistryImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 388, + "case_id": "tc-vmm-vmm-021", + "request_fields": [], + "response_fields": [ + { + "type": "RegistryImageInfo", + "name": "images", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Vmm", + "method": "PullRegistryImage", + "request": "PullRegistryImageRequest", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 390, + "case_id": "tc-vmm-vmm-022", + "request_fields": [ + { + "type": "string", + "name": "tag", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Vmm", + "method": "DeleteImage", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 392, + "case_id": "tc-vmm-vmm-023", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "HostApi", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "HostInfo", + "source": "dstack/host-api/proto/host_api.proto", + "line": 31, + "case_id": "tc-vmm-hostapi-001", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "HostApi", + "method": "Notify", + "request": "Notification", + "response": "google.protobuf.Empty", + "source": "dstack/host-api/proto/host_api.proto", + "line": 32, + "case_id": "tc-vmm-hostapi-002", + "request_fields": [ + { + "type": "string", + "name": "event", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "payload", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "HostApi", + "method": "GetSealingKey", + "request": "GetSealingKeyRequest", + "response": "GetSealingKeyResponse", + "source": "dstack/host-api/proto/host_api.proto", + "line": 33, + "case_id": "tc-vmm-hostapi-003", + "request_fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "encrypted_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "provider_quote", + "number": 2, + "optional": false, + "repeated": false + } + ] + } + ], + "message_schemas": [ + { + "name": "HostInfo", + "source": "dstack/host-api/proto/host_api.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "Notification", + "source": "dstack/host-api/proto/host_api.proto", + "fields": [ + { + "type": "string", + "name": "event", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "payload", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetSealingKeyRequest", + "source": "dstack/host-api/proto/host_api.proto", + "fields": [ + { + "type": "bytes", + "name": "quote", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetSealingKeyResponse", + "source": "dstack/host-api/proto/host_api.proto", + "fields": [ + { + "type": "bytes", + "name": "encrypted_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "provider_quote", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "VmInfo", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "uptime", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_url", + "number": 5, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "instance_id", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "VmConfiguration", + "name": "configuration", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "exited_at", + "number": 9, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "boot_progress", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "boot_error", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "shutdown_progress", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "image_version", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "GuestEvent", + "name": "events", + "number": 14, + "optional": false, + "repeated": true + }, + { + "type": "NetworkInterfaceStatus", + "name": "interfaces", + "number": 15, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "NetworkInterfaceStatus", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "mode", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "backend", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "mac", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "bridge_name", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "netdev_id", + "number": 5, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "GuestEvent", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "event", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "body", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ComposeHash", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "hash", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "VmConfiguration", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 9, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "hugepages", + "number": 11, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "pin_numa", + "number": 12, + "optional": false, + "repeated": false + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 14, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "gateway_urls", + "number": 15, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "stopped", + "number": 16, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 17, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networking", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 19, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "simulated_tee", + "number": 21, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "NetworkingConfig", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "mode", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "bridge_name", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GpuConfig", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "GpuSpec", + "name": "gpus", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "attach_mode", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GpuSpec", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "slot", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PortMapping", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "protocol", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "host_port", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vm_port", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "host_address", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "UpdateVmRequest", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "compose_file", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "encrypted_env", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "user_config", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "update_ports", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "PortMapping", + "name": "ports", + "number": 7, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_kms_urls", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_urls", + "number": 9, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "update_gateway_urls", + "number": 10, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_urls", + "number": 11, + "optional": false, + "repeated": true + }, + { + "type": "GpuConfig", + "name": "gpus", + "number": 13, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 14, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 15, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 16, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 17, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "no_tee", + "number": 18, + "optional": true, + "repeated": false + }, + { + "type": "bool", + "name": "update_networking", + "number": 19, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingConfig", + "name": "networks", + "number": 20, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "StatusRequest", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "ids", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "brief", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "keyword", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "page", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "page_size", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "StatusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "VmInfo", + "name": "vms", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "port_mapping_enabled", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "total", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "ImageInfo", + "name": "images", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "ImageInfo", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "description", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "is_dev", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AppId", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PublicKeyResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_v1", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInfoResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "found", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "VmInfo", + "name": "info", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "ResizeVmRequest", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "vcpu", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "memory", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "disk_size", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "image", + "number": 5, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "KmsSettings", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "url", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "urls", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GatewaySettings", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "url", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "base_domain", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "port", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "agent_port", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "urls", + "number": 5, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "ResourcesSettings", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "max_cvm_number", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "max_allocable_vcpu", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "max_allocable_memory_in_mb", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "NetworkingCapabilities", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "supported_modes", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "default_mode", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "default_bridge", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetMetaResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "KmsSettings", + "name": "kms", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "GatewaySettings", + "name": "gateway", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "ResourcesSettings", + "name": "resources", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "NetworkingCapabilities", + "name": "networking", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "VersionResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "rev", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListGpusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "GpuInfo", + "name": "gpus", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "allow_attach_all", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ReloadVmsResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "loaded", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "updated", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "removed", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GpuInfo", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "slot", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "product_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "description", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "is_free", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SvListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "SvProcessInfo", + "name": "processes", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "RegistryImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "RegistryImageInfo", + "name": "images", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "RegistryImageInfo", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "tag", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "local", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "pulling", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "error", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PullRegistryImageRequest", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "tag", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SvProcessInfo", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "pid", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "command", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "note", + "number": 6, + "optional": false, + "repeated": false + } + ] + } + ] + }, + "kms": { + "rpc_methods": [ + { + "service": "KMS", + "method": "GetAppKey", + "request": "GetAppKeyRequest", + "response": "AppKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 97, + "case_id": "tc-kms-kms-001", + "request_fields": [ + { + "type": "uint32", + "name": "api_version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "disk_crypt_key", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "env_crypt_key", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_key", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_signature", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tproxy_app_id", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_app_id", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 8, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "KMS", + "method": "GetKmsKey", + "request": "GetKmsKeyRequest", + "response": "KmsKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 99, + "case_id": "tc-kms-kms-002", + "request_fields": [ + { + "type": "string", + "name": "vm_config", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "temp_ca_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "KmsKeys", + "name": "keys", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "KMS", + "method": "GetAppEnvEncryptPubKey", + "request": "AppId", + "response": "PublicKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 101, + "case_id": "tc-kms-kms-003", + "request_fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_v1", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "KMS", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 103, + "case_id": "tc-kms-kms-004", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "allow_any_upgrade", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_pubkey", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "BootstrapResponse", + "name": "bootstrap_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "is_dev", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_app_id", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "kms_contract_address", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "chain_id", + "number": 8, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "app_auth_implementation", + "number": 9, + "optional": true, + "repeated": false + } + ] + }, + { + "service": "KMS", + "method": "GetTempCaCert", + "request": "google.protobuf.Empty", + "response": "GetTempCaCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 105, + "case_id": "tc-kms-kms-005", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "temp_ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "temp_ca_key", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ca_cert", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "KMS", + "method": "SignCert", + "request": "SignCertRequest", + "response": "SignCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 107, + "case_id": "tc-kms-kms-006", + "request_fields": [ + { + "type": "uint32", + "name": "api_version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "csr", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 4, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "certificate_chain", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "ClearImageCache", + "request": "ClearImageCacheRequest", + "response": "google.protobuf.Empty", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 116, + "case_id": "tc-kms-admin-001", + "request_fields": [ + { + "type": "string", + "name": "image_hash", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "config_hash", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Onboard", + "method": "Bootstrap", + "request": "BootstrapRequest", + "response": "BootstrapResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 167, + "case_id": "tc-kms-onboard-001", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "ca_pubkey", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_pubkey", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "attestation", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Onboard", + "method": "Onboard", + "request": "OnboardRequest", + "response": "OnboardResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 169, + "case_id": "tc-kms-onboard-002", + "request_fields": [ + { + "type": "string", + "name": "source_url", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "domain", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bytes", + "name": "k256_pubkey", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Onboard", + "method": "GetAttestationInfo", + "request": "google.protobuf.Empty", + "response": "AttestationInfoResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 171, + "case_id": "tc-kms-onboard-003", + "request_fields": [], + "response_fields": [ + { + "type": "bytes", + "name": "device_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tee_variant", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "site_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "eth_rpc_url", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_contract_address", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "ppid", + "number": 8, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Onboard", + "method": "Finish", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 173, + "case_id": "tc-kms-onboard-004", + "request_fields": [], + "response_fields": [] + } + ], + "message_schemas": [ + { + "name": "GetAppKeyRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "api_version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AppId", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "app_id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PublicKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature_v1", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AppKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "disk_crypt_key", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "env_crypt_key", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_key", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_signature", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tproxy_app_id", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_app_id", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 8, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetMetaResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "allow_any_upgrade", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_pubkey", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "BootstrapResponse", + "name": "bootstrap_info", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "is_dev", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "gateway_app_id", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "kms_contract_address", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "chain_id", + "number": 8, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "app_auth_implementation", + "number": 9, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "GetKmsKeyRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "vm_config", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "KmsKeys", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "ca_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_key", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "KmsKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "temp_ca_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "KmsKeys", + "name": "keys", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GetTempCaCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "temp_ca_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "temp_ca_key", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ca_cert", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SignCertRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "api_version", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "csr", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "signature", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "vm_config", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SignCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "certificate_chain", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "ClearImageCacheRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "image_hash", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "config_hash", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "BootstrapRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "BootstrapResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "ca_pubkey", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "k256_pubkey", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "attestation", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "OnboardRequest", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "string", + "name": "source_url", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "domain", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "OnboardResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "k256_pubkey", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AttestationInfoResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "device_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "mr_aggregated", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "os_image_hash", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "tee_variant", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "site_name", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "eth_rpc_url", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "kms_contract_address", + "number": 7, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "ppid", + "number": 8, + "optional": false, + "repeated": false + } + ] + } + ] + }, + "gateway": { + "rpc_methods": [ + { + "service": "Gateway", + "method": "RegisterCvm", + "request": "RegisterCvmRequest", + "response": "RegisterCvmResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 209, + "case_id": "tc-gw-gateway-001", + "request_fields": [ + { + "type": "string", + "name": "client_public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "port_policy", + "number": 2, + "optional": true, + "repeated": false + } + ], + "response_fields": [ + { + "type": "WireGuardConfig", + "name": "wg", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "GuestAgentConfig", + "name": "agent", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "GatewayNodeInfo", + "name": "gateways", + "number": 3, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Gateway", + "method": "AcmeInfo", + "request": "google.protobuf.Empty", + "response": "AcmeInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 211, + "case_id": "tc-gw-gateway-002", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "account_uri", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "QuotedPublicKey", + "name": "quoted_hist_keys", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "account_quote", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "account_attestation", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Gateway", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "InfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 213, + "case_id": "tc-gw-gateway-003", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "base_domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "external_port", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_address_ns_prefix", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Gateway", + "method": "GetPeers", + "request": "google.protobuf.Empty", + "response": "GetPeersResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 215, + "case_id": "tc-gw-gateway-004", + "request_fields": [], + "response_fields": [ + { + "type": "uint32", + "name": "my_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "my_url", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "PeerInfo", + "name": "peers", + "number": 3, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Debug", + "method": "RegisterCvm", + "request": "DebugRegisterCvmRequest", + "response": "RegisterCvmResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 221, + "case_id": "tc-gw-debug-001", + "request_fields": [ + { + "type": "string", + "name": "client_public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "instance_id", + "number": 3, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "WireGuardConfig", + "name": "wg", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "GuestAgentConfig", + "name": "agent", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "GatewayNodeInfo", + "name": "gateways", + "number": 3, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Debug", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "InfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 223, + "case_id": "tc-gw-debug-002", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "base_domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "external_port", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_address_ns_prefix", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Debug", + "method": "GetSyncData", + "request": "google.protobuf.Empty", + "response": "DebugSyncDataResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 225, + "case_id": "tc-gw-debug-003", + "request_fields": [], + "response_fields": [ + { + "type": "uint64", + "name": "my_node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PeerAddrEntry", + "name": "peer_addrs", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "NodeInfoEntry", + "name": "nodes", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "InstanceEntry", + "name": "instances", + "number": 4, + "optional": false, + "repeated": true + }, + { + "type": "uint64", + "name": "persistent_keys", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "ephemeral_keys", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Debug", + "method": "GetProxyState", + "request": "google.protobuf.Empty", + "response": "DebugProxyStateResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 227, + "case_id": "tc-gw-debug-004", + "request_fields": [], + "response_fields": [ + { + "type": "ProxyStateInstance", + "name": "instances", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "allocated_addresses", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "Status", + "request": "google.protobuf.Empty", + "response": "StatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 377, + "case_id": "tc-gw-admin-001", + "request_fields": [], + "response_fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "bootnode_url", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "num_connections", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "HostInfo", + "name": "hosts", + "number": 5, + "optional": false, + "repeated": true + }, + { + "type": "GatewayNodeInfo", + "name": "nodes", + "number": 6, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "uuid", + "number": 7, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "GetInfo", + "request": "GetInfoRequest", + "response": "GetInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 379, + "case_id": "tc-gw-admin-002", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bool", + "name": "found", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "HostInfo", + "name": "info", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "Exit", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 381, + "case_id": "tc-gw-admin-003", + "request_fields": [], + "response_fields": [] + }, + { + "service": "Admin", + "method": "RenewCert", + "request": "google.protobuf.Empty", + "response": "RenewCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 383, + "case_id": "tc-gw-admin-004", + "request_fields": [], + "response_fields": [ + { + "type": "bool", + "name": "renewed", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "ReloadCert", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 385, + "case_id": "tc-gw-admin-005", + "request_fields": [], + "response_fields": [] + }, + { + "service": "Admin", + "method": "SetCaa", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 387, + "case_id": "tc-gw-admin-006", + "request_fields": [], + "response_fields": [] + }, + { + "service": "Admin", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 389, + "case_id": "tc-gw-admin-007", + "request_fields": [], + "response_fields": [ + { + "type": "uint32", + "name": "registered", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "online", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "SetNodeUrl", + "request": "SetNodeUrlRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 391, + "case_id": "tc-gw-admin-008", + "request_fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "SetNodeStatus", + "request": "SetNodeStatusRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 393, + "case_id": "tc-gw-admin-009", + "request_fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "WaveKvStatus", + "request": "google.protobuf.Empty", + "response": "WaveKvStatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 395, + "case_id": "tc-gw-admin-010", + "request_fields": [], + "response_fields": [ + { + "type": "bool", + "name": "enabled", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "StoreSyncStatus", + "name": "persistent", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "StoreSyncStatus", + "name": "ephemeral", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "GetInstanceHandshakes", + "request": "GetInstanceHandshakesRequest", + "response": "GetInstanceHandshakesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 397, + "case_id": "tc-gw-admin-011", + "request_fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "HandshakeEntry", + "name": "handshakes", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "GetGlobalConnections", + "request": "google.protobuf.Empty", + "response": "GlobalConnectionsStats", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 399, + "case_id": "tc-gw-admin-012", + "request_fields": [], + "response_fields": [ + { + "type": "uint64", + "name": "total_connections", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "GetNodeStatuses", + "request": "google.protobuf.Empty", + "response": "GetNodeStatusesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 401, + "case_id": "tc-gw-admin-013", + "request_fields": [], + "response_fields": [ + { + "type": "NodeStatusEntry", + "name": "statuses", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "ListDnsCredentials", + "request": "google.protobuf.Empty", + "response": "ListDnsCredentialsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 405, + "case_id": "tc-gw-admin-014", + "request_fields": [], + "response_fields": [ + { + "type": "DnsCredentialInfo", + "name": "credentials", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "default_id", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "GetDnsCredential", + "request": "GetDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 407, + "case_id": "tc-gw-admin-015", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "created_at", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "updated_at", + "number": 9, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "CreateDnsCredential", + "request": "CreateDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 409, + "case_id": "tc-gw-admin-016", + "request_fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_zone_id", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "set_as_default", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 8, + "optional": true, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "created_at", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "updated_at", + "number": 9, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "UpdateDnsCredential", + "request": "UpdateDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 411, + "case_id": "tc-gw-admin-017", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_zone_id", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": true, + "repeated": false + } + ], + "response_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "created_at", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "updated_at", + "number": 9, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "DeleteDnsCredential", + "request": "DeleteDnsCredentialRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 413, + "case_id": "tc-gw-admin-018", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "GetDefaultDnsCredential", + "request": "google.protobuf.Empty", + "response": "GetDefaultDnsCredentialResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 415, + "case_id": "tc-gw-admin-019", + "request_fields": [], + "response_fields": [ + { + "type": "string", + "name": "default_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "DnsCredentialInfo", + "name": "credential", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "SetDefaultDnsCredential", + "request": "SetDefaultDnsCredentialRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 417, + "case_id": "tc-gw-admin-020", + "request_fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "ListZtDomains", + "request": "google.protobuf.Empty", + "response": "ListZtDomainsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 421, + "case_id": "tc-gw-admin-021", + "request_fields": [], + "response_fields": [ + { + "type": "ZtDomainInfo", + "name": "domains", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "GetZtDomain", + "request": "GetZtDomainRequest", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 423, + "case_id": "tc-gw-admin-022", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "ZtDomainConfig", + "name": "config", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "ZtDomainCertStatus", + "name": "cert_status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "AddZtDomain", + "request": "ZtDomainConfig", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 425, + "case_id": "tc-gw-admin-023", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "dns_cred_id", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "port", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "node", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "int32", + "name": "priority", + "number": 5, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "ZtDomainConfig", + "name": "config", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "ZtDomainCertStatus", + "name": "cert_status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "UpdateZtDomain", + "request": "ZtDomainConfig", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 427, + "case_id": "tc-gw-admin-024", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "dns_cred_id", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "port", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "node", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "int32", + "name": "priority", + "number": 5, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "ZtDomainConfig", + "name": "config", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "ZtDomainCertStatus", + "name": "cert_status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "DeleteZtDomain", + "request": "DeleteZtDomainRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 429, + "case_id": "tc-gw-admin-025", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "RenewZtDomainCert", + "request": "RenewZtDomainCertRequest", + "response": "RenewZtDomainCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 431, + "case_id": "tc-gw-admin-026", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "force", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "bool", + "name": "renewed", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "not_after", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "ForceReleaseCertLock", + "request": "ForceReleaseCertLockRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 433, + "case_id": "tc-gw-admin-027", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "ListCertAttestations", + "request": "ListCertAttestationsRequest", + "response": "ListCertAttestationsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 435, + "case_id": "tc-gw-admin-028", + "request_fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "limit", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "CertAttestationInfo", + "name": "latest", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "CertAttestationInfo", + "name": "history", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "service": "Admin", + "method": "GetCertbotConfig", + "request": "google.protobuf.Empty", + "response": "CertbotConfigResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 439, + "case_id": "tc-gw-admin-029", + "request_fields": [], + "response_fields": [ + { + "type": "uint64", + "name": "renew_interval_secs", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_before_expiration_secs", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_timeout_secs", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "acme_url", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "service": "Admin", + "method": "SetCertbotConfig", + "request": "SetCertbotConfigRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 441, + "case_id": "tc-gw-admin-030", + "request_fields": [ + { + "type": "uint64", + "name": "renew_interval_secs", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_before_expiration_secs", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_timeout_secs", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "acme_url", + "number": 4, + "optional": true, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "SetInstancePortPolicy", + "request": "SetInstancePortPolicyRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 447, + "case_id": "tc-gw-admin-031", + "request_fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "policy", + "number": 2, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "ClearInstancePortPolicy", + "request": "ClearInstancePortPolicyRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 450, + "case_id": "tc-gw-admin-032", + "request_fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [] + }, + { + "service": "Admin", + "method": "GetInstancePortPolicy", + "request": "GetInstancePortPolicyRequest", + "response": "GetInstancePortPolicyResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 453, + "case_id": "tc-gw-admin-033", + "request_fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ], + "response_fields": [ + { + "type": "PortPolicy", + "name": "effective", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "source", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "instance_reported", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "admin_override", + "number": 4, + "optional": true, + "repeated": false + } + ] + } + ], + "message_schemas": [ + { + "name": "RegisterCvmRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "client_public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "port_policy", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "PortPolicy", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "PortAttrs", + "name": "ports", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "bool", + "name": "restrict_mode", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PortAttrs", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "port", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "pp", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DebugRegisterCvmRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "client_public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "instance_id", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "RegisterCvmResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "WireGuardConfig", + "name": "wg", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "GuestAgentConfig", + "name": "agent", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "GatewayNodeInfo", + "name": "gateways", + "number": 3, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "WireGuardPeer", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "pk", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ip", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "endpoint", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "WireGuardConfig", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "client_ip", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "WireGuardPeer", + "name": "servers", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GuestAgentConfig", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "external_port", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "internal_port", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "domain", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_address_ns_prefix", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "StatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "bootnode_url", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "num_connections", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "HostInfo", + "name": "hosts", + "number": 5, + "optional": false, + "repeated": true + }, + { + "type": "GatewayNodeInfo", + "name": "nodes", + "number": 6, + "optional": false, + "repeated": true + }, + { + "type": "bytes", + "name": "uuid", + "number": 7, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "HostInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ip", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "base_domain", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "latest_handshake", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "num_connections", + "number": 7, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "QuotedPublicKey", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "quote", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "attestation", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "AcmeInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "account_uri", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "QuotedPublicKey", + "name": "quoted_hist_keys", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "account_quote", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "account_attestation", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInfoRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "found", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "HostInfo", + "name": "info", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "GetMetaResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "registered", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "online", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GatewayNodeInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bytes", + "name": "uuid", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "last_seen", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_public_key", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_ip", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_endpoint", + "number": 7, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "InfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "base_domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "external_port", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_address_ns_prefix", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "version", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PeerInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetPeersResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "my_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "my_url", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "PeerInfo", + "name": "peers", + "number": 3, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "PeerAddrEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "NodeInfoEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_public_key", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_endpoint", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "wg_ip", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "InstanceEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ip", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "public_key", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DebugSyncDataResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "my_node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PeerAddrEntry", + "name": "peer_addrs", + "number": 2, + "optional": false, + "repeated": true + }, + { + "type": "NodeInfoEntry", + "name": "nodes", + "number": 3, + "optional": false, + "repeated": true + }, + { + "type": "InstanceEntry", + "name": "instances", + "number": 4, + "optional": false, + "repeated": true + }, + { + "type": "uint64", + "name": "persistent_keys", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "ephemeral_keys", + "number": 6, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ProxyStateInstance", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "app_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "ip", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "public_key", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "reg_time", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DebugProxyStateResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "ProxyStateInstance", + "name": "instances", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "allocated_addresses", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "RenewCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "renewed", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SetNodeUrlRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "url", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SetNodeStatusRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "PeerSyncStatus", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "local_ack", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "peer_ack", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "buffered_logs", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "LastSeenEntry", + "name": "last_seen", + "number": 5, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "LastSeenEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "StoreSyncStatus", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "node_id", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "n_keys", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "next_seq", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "dirty", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "wal_enabled", + "number": 6, + "optional": false, + "repeated": false + }, + { + "type": "PeerSyncStatus", + "name": "peers", + "number": 7, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "WaveKvStatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "enabled", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "StoreSyncStatus", + "name": "persistent", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "StoreSyncStatus", + "name": "ephemeral", + "number": 3, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "HandshakeEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "observer_node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "timestamp", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInstanceHandshakesRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInstanceHandshakesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "HandshakeEntry", + "name": "handshakes", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GlobalConnectionsStats", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "total_connections", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "NodeStatusEntry", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint32", + "name": "node_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetNodeStatusesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "NodeStatusEntry", + "name": "statuses", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "created_at", + "number": 8, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "updated_at", + "number": 9, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListDnsCredentialsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "DnsCredentialInfo", + "name": "credentials", + "number": 1, + "optional": false, + "repeated": true + }, + { + "type": "string", + "name": "default_id", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "GetDnsCredentialRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "CreateDnsCredentialRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "name", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "provider_type", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_zone_id", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "set_as_default", + "number": 5, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 6, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "dns_txt_ttl", + "number": 7, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "max_dns_wait", + "number": 8, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "UpdateDnsCredentialRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "name", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_token", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_zone_id", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "cf_api_url", + "number": 5, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "DeleteDnsCredentialRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetDefaultDnsCredentialResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "default_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "DnsCredentialInfo", + "name": "credential", + "number": 2, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "SetDefaultDnsCredentialRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ZtDomainConfig", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "dns_cred_id", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint32", + "name": "port", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "node", + "number": 4, + "optional": true, + "repeated": false + }, + { + "type": "int32", + "name": "priority", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "ZtDomainConfig", + "name": "config", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "ZtDomainCertStatus", + "name": "cert_status", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ZtDomainCertStatus", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "has_cert", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "not_after", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "issued_by", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "issued_at", + "number": 4, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "loaded_in_memory", + "number": 5, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListZtDomainsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "ZtDomainInfo", + "name": "domains", + "number": 1, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "GetZtDomainRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "DeleteZtDomainRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "RenewZtDomainCertRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "bool", + "name": "force", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "RenewZtDomainCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bool", + "name": "renewed", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "not_after", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ForceReleaseCertLockRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "CertAttestationInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "bytes", + "name": "public_key", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "quote", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "generated_by", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "generated_at", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListCertAttestationsRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "domain", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint32", + "name": "limit", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ListCertAttestationsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "CertAttestationInfo", + "name": "latest", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "CertAttestationInfo", + "name": "history", + "number": 2, + "optional": false, + "repeated": true + } + ] + }, + { + "name": "CertbotConfigResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "renew_interval_secs", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_before_expiration_secs", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_timeout_secs", + "number": 3, + "optional": false, + "repeated": false + }, + { + "type": "string", + "name": "acme_url", + "number": 4, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "SetCertbotConfigRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "uint64", + "name": "renew_interval_secs", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_before_expiration_secs", + "number": 2, + "optional": true, + "repeated": false + }, + { + "type": "uint64", + "name": "renew_timeout_secs", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "acme_url", + "number": 4, + "optional": true, + "repeated": false + } + ] + }, + { + "name": "SetInstancePortPolicyRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "policy", + "number": 2, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "ClearInstancePortPolicyRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInstancePortPolicyRequest", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "string", + "name": "instance_id", + "number": 1, + "optional": false, + "repeated": false + } + ] + }, + { + "name": "GetInstancePortPolicyResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "fields": [ + { + "type": "PortPolicy", + "name": "effective", + "number": 1, + "optional": true, + "repeated": false + }, + { + "type": "string", + "name": "source", + "number": 2, + "optional": false, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "instance_reported", + "number": 3, + "optional": true, + "repeated": false + }, + { + "type": "PortPolicy", + "name": "admin_override", + "number": 4, + "optional": true, + "repeated": false + } + ] + } + ] + } + } +} diff --git a/docs/test-plans/core-components-full/configuration-inventory.json b/docs/test-plans/core-components-full/configuration-inventory.json new file mode 100644 index 000000000..d8d1562de --- /dev/null +++ b/docs/test-plans/core-components-full/configuration-inventory.json @@ -0,0 +1,350 @@ +{ + "schema_version": "1.0", + "description": "Every example configuration leaf and every source-only configuration field listed here must be exercised at default, explicit valid, boundary-invalid, unknown-field, restart, and redaction paths by the mapped cases.", + "components": { + "guest-agent": { + "source": "dstack/guest-agent/dstack.toml", + "case_ids": [ + "tc-gos-entry-001" + ], + "fields": [ + "default.workers", + "default.max_blocking", + "default.ident", + "default.temp_dir", + "default.keep_alive", + "default.log_level", + "default.core.keys_file", + "default.core.compose_file", + "default.core.sys_config_file", + "default.core.data_disks", + "internal-v0.address", + "internal-v0.reuse", + "internal.address", + "internal.reuse", + "external.address", + "external.port", + "guest-api.address", + "guest-api.port" + ] + }, + "vmm": { + "source": "dstack/vmm/vmm.toml", + "case_ids": [ + "tc-vmm-configurat-001" + ], + "fields": [ + "workers", + "max_blocking", + "ident", + "temp_dir", + "keep_alive", + "log_level", + "address", + "reuse", + "kms_url", + "event_buffer_size", + "node_name", + "image.registry", + "cvm.platform", + "cvm.qemu_path", + "cvm.kms_urls", + "cvm.gateway_urls", + "cvm.pccs_url", + "cvm.docker_registry", + "cvm.volumes_dir", + "cvm.cid_start", + "cvm.cid_pool_size", + "cvm.max_allocable_vcpu", + "cvm.max_allocable_memory_in_mb", + "cvm.qmp_socket", + "cvm.user", + "cvm.use_mrconfigid", + "cvm.qemu_pci_hole64_size", + "cvm.qemu_hotplug_off", + "cvm.tdx_attestation_variant", + "cvm.host_share_mode", + "cvm.qgs_port", + "cvm.product.sys_vendor", + "cvm.product.product_name", + "cvm.networking.mode", + "cvm.networking.net", + "cvm.networking.dhcp_start", + "cvm.networking.restrict", + "cvm.port_mapping.enabled", + "cvm.port_mapping.address", + "cvm.port_mapping.range[].protocol", + "cvm.port_mapping.range[].from", + "cvm.port_mapping.range[].to", + "cvm.auto_restart.enabled", + "cvm.auto_restart.interval", + "cvm.gpu.enabled", + "cvm.gpu.listing", + "cvm.gpu.exclude", + "cvm.gpu.include", + "cvm.gpu.allow_attach_all", + "gateway.base_domain", + "gateway.port", + "gateway.agent_port", + "auth.enabled", + "auth.tokens", + "auth.htpasswd_file", + "supervisor.exe", + "supervisor.sock", + "supervisor.pid_file", + "supervisor.log_file", + "supervisor.detached", + "supervisor.auto_start", + "host_api.ident", + "host_api.address", + "host_api.port", + "key_provider.enabled", + "key_provider.address", + "key_provider.port" + ] + }, + "kms": { + "source": "dstack/kms/kms.toml", + "case_ids": [ + "tc-kms-startup-001", + "tc-kms-keys-certs-007", + "tc-kms-attestatio-005" + ], + "fields": [ + "default.workers", + "default.max_blocking", + "default.ident", + "default.temp_dir", + "default.keep_alive", + "default.log_level", + "rpc.address", + "rpc.port", + "rpc.tls.key", + "rpc.tls.certs", + "rpc.tls.mutual.ca_certs", + "rpc.tls.mutual.mandatory", + "core.cert_dir", + "core.subject_postfix", + "core.site_name", + "core.enforce_self_authorization", + "core.sev_snp_key_release", + "core.aws_nitro_tpm_key_release", + "core.attestation.insecure_allow_external_trust_anchors", + "core.image.verify", + "core.image.cache_dir", + "core.image.download_url", + "core.image.download_timeout", + "core.admin.enabled", + "core.admin.address", + "core.admin.port", + "core.admin.auth_token", + "core.admin.htpasswd_file", + "core.admin.insecure_no_auth", + "core.metrics.enabled", + "core.auth_api.type", + "core.auth_api.webhook.url", + "core.auth_api.dev.gateway_app_id", + "core.onboard.enabled", + "core.onboard.auto_bootstrap_domain", + "core.onboard.address", + "core.onboard.port" + ] + }, + "gateway": { + "source": "dstack/gateway/gateway.toml", + "case_ids": [ + "tc-gw-internal-001", + "tc-gw-cluster-ad-008", + "tc-gw-cluster-ad-005" + ], + "fields": [ + "workers", + "max_blocking", + "ident", + "temp_dir", + "keep_alive", + "log_level", + "address", + "core.kms_url", + "core.set_ulimit", + "core.rpc_domain", + "core.attestation.insecure_allow_external_trust_anchors", + "core.auth.enabled", + "core.auth.url", + "core.auth.timeout", + "core.admin.enabled", + "core.admin.address", + "core.admin.auth_token", + "core.admin.htpasswd_file", + "core.admin.insecure_no_auth", + "core.debug.insecure_enable_debug_rpc", + "core.debug.insecure_skip_attestation", + "core.debug.key_file", + "core.debug.address", + "core.wg.public_key", + "core.wg.private_key", + "core.wg.listen_port", + "core.wg.ip", + "core.wg.reserved_net", + "core.wg.client_ip_range", + "core.wg.config_path", + "core.wg.interface", + "core.wg.endpoint", + "core.proxy.tls_crypto_provider", + "core.proxy.tls_versions", + "core.proxy.listen_addr", + "core.proxy.listen_port", + "core.proxy.agent_port", + "core.proxy.buffer_size", + "core.proxy.connect_top_n", + "core.proxy.localhost_enabled", + "core.proxy.app_address_ns_prefix", + "core.proxy.app_address_ns_compat", + "core.proxy.workers", + "core.proxy.external_port", + "core.proxy.max_connections_per_app", + "core.proxy.inbound_pp_enabled", + "core.proxy.port_policy_fetch.timeout", + "core.proxy.port_policy_fetch.max_retries", + "core.proxy.port_policy_fetch.backoff_initial", + "core.proxy.port_policy_fetch.backoff_max", + "core.proxy.timeouts.connect", + "core.proxy.timeouts.handshake", + "core.proxy.timeouts.cache_top_n", + "core.proxy.timeouts.dns_resolve", + "core.proxy.timeouts.data_timeout_enabled", + "core.proxy.timeouts.idle", + "core.proxy.timeouts.write", + "core.proxy.timeouts.shutdown", + "core.proxy.timeouts.total", + "core.proxy.timeouts.pp_header", + "core.recycle.enabled", + "core.recycle.interval", + "core.recycle.timeout", + "core.recycle.node_timeout", + "core.sync.enabled", + "core.sync.node_id", + "core.sync.my_url", + "core.sync.interval", + "core.sync.timeout", + "core.sync.bootnode", + "core.sync.data_dir", + "core.sync.persist_interval", + "core.sync.sync_connections_enabled", + "core.sync.sync_connections_interval" + ] + }, + "verifier": { + "source": "dstack/verifier/dstack-verifier.toml", + "case_ids": [ + "tc-ver-build-002" + ], + "fields": [ + "address", + "port", + "image_cache_dir", + "image_download_url", + "image_download_timeout_secs", + "attestation.insecure_allow_external_trust_anchors" + ] + }, + "supervisor": { + "source": "dstack/supervisor/supervisor.toml", + "case_ids": [ + "tc-gos-storage-an-004", + "tc-gos-setup-012" + ], + "fields": [ + "default.workers", + "default.max_blocking", + "default.ident", + "default.temp_dir", + "default.keep_alive", + "default.log_level", + "default.address", + "default.reuse", + "default.shutdown.ctrlc", + "default.shutdown.signals", + "default.shutdown.grace", + "default.shutdown.mercy" + ] + } + }, + "rust_only_fields": { + "guest-agent": { + "source": "dstack/guest-agent/src/config.rs", + "fields": [ + "app_compose", + "raw" + ], + "case_ids": [ + "tc-gos-entry-001" + ] + }, + "vmm": { + "source": "dstack/vmm/src/config.rs", + "fields": [ + "bios_date", + "bios_release", + "bios_vendor", + "bios_version", + "board_asset_tag", + "board_name", + "board_serial", + "board_vendor", + "board_version", + "bridge", + "chassis_asset_tag", + "chassis_serial", + "chassis_vendor", + "chassis_version", + "from", + "kind", + "live_for", + "mac_prefix", + "netdev", + "nvidia_attestation_proxy_url", + "path", + "product_family", + "product_serial", + "product_sku", + "product_uuid", + "product_version", + "protocol", + "qemu_pic", + "qemu_single_pass_add_pages", + "qemu_version", + "run_path", + "serial_history_max_bytes", + "tee_simulator", + "to" + ], + "case_ids": [ + "tc-vmm-configurat-001", + "tc-vmm-configurat-003", + "tc-vmm-compute-ne-001", + "tc-vmm-compute-ne-004", + "tc-vmm-compute-ne-007", + "tc-vmm-serial-006", + "tc-vmm-manifest-002" + ] + }, + "gateway": { + "source": "dstack/gateway/src/config.rs", + "fields": [ + "base_domain", + "ca_certs", + "cert_chain", + "cert_key", + "certs", + "key", + "mutual" + ], + "case_ids": [ + "tc-gw-cluster-ad-008", + "tc-gw-internal-001", + "tc-gw-certificat-006" + ] + } + } +} diff --git a/docs/test-plans/core-components-full/feature-audit.md b/docs/test-plans/core-components-full/feature-audit.md new file mode 100644 index 000000000..ae961e85e --- /dev/null +++ b/docs/test-plans/core-components-full/feature-audit.md @@ -0,0 +1,716 @@ + + + +# Core Component Feature and Risk Audit + +This audit is derived from the repository source inventory and is the traceability authority for the full test plan. Each requirement and risk maps to exactly one indexed case. + + +## Guest OS + + +### Tappd RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-tappd-001` | `risk-gos-tappd-001` | [tc-gos-tappd-001](01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md#tc-gos-tappd-001) — Tappd.DeriveKey | P1 | +| `req-gos-tappd-002` | `risk-gos-tappd-002` | [tc-gos-tappd-002](01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md#tc-gos-tappd-002) — Tappd.DeriveK256Key | P1 | +| `req-gos-tappd-003` | `risk-gos-tappd-003` | [tc-gos-tappd-003](01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md#tc-gos-tappd-003) — Tappd.TdxQuote | P1 | +| `req-gos-tappd-004` | `risk-gos-tappd-004` | [tc-gos-tappd-004](01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md#tc-gos-tappd-004) — Tappd.RawQuote | P1 | +| `req-gos-tappd-005` | `risk-gos-tappd-005` | [tc-gos-tappd-005](01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md#tc-gos-tappd-005) — Tappd.Info | P1 | +| `req-gos-tappd-006` | `risk-gos-tappd-006` | [tc-gos-tappd-006](01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md#tc-gos-tappd-006) — Tappd.Version | P1 | + + +### DstackGuest RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-dstackguest-001` | `risk-gos-dstackguest-001` | [tc-gos-dstackguest-001](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md#tc-gos-dstackguest-001) — DstackGuest.GetTlsKey | P1 | +| `req-gos-dstackguest-002` | `risk-gos-dstackguest-002` | [tc-gos-dstackguest-002](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md#tc-gos-dstackguest-002) — DstackGuest.GetKey | P1 | +| `req-gos-dstackguest-003` | `risk-gos-dstackguest-003` | [tc-gos-dstackguest-003](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md#tc-gos-dstackguest-003) — DstackGuest.GetQuote | P0 | +| `req-gos-dstackguest-004` | `risk-gos-dstackguest-004` | [tc-gos-dstackguest-004](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md#tc-gos-dstackguest-004) — DstackGuest.Attest | P0 | +| `req-gos-dstackguest-005` | `risk-gos-dstackguest-005` | [tc-gos-dstackguest-005](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md#tc-gos-dstackguest-005) — DstackGuest.Info | P1 | +| `req-gos-dstackguest-006` | `risk-gos-dstackguest-006` | [tc-gos-dstackguest-006](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md#tc-gos-dstackguest-006) — DstackGuest.GpuInfo | P1 | +| `req-gos-dstackguest-007` | `risk-gos-dstackguest-007` | [tc-gos-dstackguest-007](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md#tc-gos-dstackguest-007) — DstackGuest.Sign | P1 | +| `req-gos-dstackguest-008` | `risk-gos-dstackguest-008` | [tc-gos-dstackguest-008](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md#tc-gos-dstackguest-008) — DstackGuest.Verify | P1 | +| `req-gos-dstackguest-009` | `risk-gos-dstackguest-009` | [tc-gos-dstackguest-009](01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md#tc-gos-dstackguest-009) — DstackGuest.Version | P1 | + + +### Worker RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-worker-001` | `risk-gos-worker-001` | [tc-gos-worker-001](01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md#tc-gos-worker-001) — Worker.Info | P1 | +| `req-gos-worker-002` | `risk-gos-worker-002` | [tc-gos-worker-002](01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md#tc-gos-worker-002) — Worker.Version | P1 | +| `req-gos-worker-003` | `risk-gos-worker-003` | [tc-gos-worker-003](01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md#tc-gos-worker-003) — Worker.GetAttestationForAppKey | P1 | + + +### GuestApi RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-guestapi-001` | `risk-gos-guestapi-001` | [tc-gos-guestapi-001](01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md#tc-gos-guestapi-001) — GuestApi.Info | P1 | +| `req-gos-guestapi-002` | `risk-gos-guestapi-002` | [tc-gos-guestapi-002](01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md#tc-gos-guestapi-002) — GuestApi.SysInfo | P1 | +| `req-gos-guestapi-003` | `risk-gos-guestapi-003` | [tc-gos-guestapi-003](01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md#tc-gos-guestapi-003) — GuestApi.NetworkInfo | P1 | +| `req-gos-guestapi-004` | `risk-gos-guestapi-004` | [tc-gos-guestapi-004](01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md#tc-gos-guestapi-004) — GuestApi.ListContainers | P1 | +| `req-gos-guestapi-005` | `risk-gos-guestapi-005` | [tc-gos-guestapi-005](01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md#tc-gos-guestapi-005) — GuestApi.Shutdown | P1 | + + +### ProxiedGuestApi RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-proxiedguestapi-001` | `risk-gos-proxiedguestapi-001` | [tc-gos-proxiedguestapi-001](01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md#tc-gos-proxiedguestapi-001) — ProxiedGuestApi.Info | P1 | +| `req-gos-proxiedguestapi-002` | `risk-gos-proxiedguestapi-002` | [tc-gos-proxiedguestapi-002](01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md#tc-gos-proxiedguestapi-002) — ProxiedGuestApi.SysInfo | P1 | +| `req-gos-proxiedguestapi-003` | `risk-gos-proxiedguestapi-003` | [tc-gos-proxiedguestapi-003](01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md#tc-gos-proxiedguestapi-003) — ProxiedGuestApi.NetworkInfo | P1 | +| `req-gos-proxiedguestapi-004` | `risk-gos-proxiedguestapi-004` | [tc-gos-proxiedguestapi-004](01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md#tc-gos-proxiedguestapi-004) — ProxiedGuestApi.ListContainers | P1 | +| `req-gos-proxiedguestapi-005` | `risk-gos-proxiedguestapi-005` | [tc-gos-proxiedguestapi-005](01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md#tc-gos-proxiedguestapi-005) — ProxiedGuestApi.Shutdown | P1 | + + +### Boot And Identity + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-boot-and-i-001` | `risk-gos-boot-and-i-001` | [tc-gos-boot-and-i-001](01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md#tc-gos-boot-and-i-001) — Measured boot and prepare ordering | P0 | +| `req-gos-boot-and-i-002` | `risk-gos-boot-and-i-002` | [tc-gos-boot-and-i-002](01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md#tc-gos-boot-and-i-002) — No-TEE simulator early host share | P1 | +| `req-gos-boot-and-i-003` | `risk-gos-boot-and-i-003` | [tc-gos-boot-and-i-003](01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md#tc-gos-boot-and-i-003) — System and user configuration materialization | P1 | +| `req-gos-boot-and-i-004` | `risk-gos-boot-and-i-004` | [tc-gos-boot-and-i-004](01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md#tc-gos-boot-and-i-004) — Stable app, instance, device, and compose identity | P0 | +| `req-gos-boot-and-i-005` | `risk-gos-boot-and-i-005` | [tc-gos-boot-and-i-005](01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md#tc-gos-boot-and-i-005) — Host notification boot and shutdown events | P1 | + + +### Storage And Containers + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-storage-an-001` | `risk-gos-storage-an-001` | [tc-gos-storage-an-001](01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md#tc-gos-storage-an-001) — Encrypted root/data volume provisioning | P0 | +| `req-gos-storage-an-002` | `risk-gos-storage-an-002` | [tc-gos-storage-an-002](01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md#tc-gos-storage-an-002) — Ephemeral Docker storage lifecycle | P1 | +| `req-gos-storage-an-003` | `risk-gos-storage-an-003` | [tc-gos-storage-an-003](01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md#tc-gos-storage-an-003) — Compose validation and startup | P1 | +| `req-gos-storage-an-004` | `risk-gos-storage-an-004` | [tc-gos-storage-an-004](01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md#tc-gos-storage-an-004) — Supervisor lifecycle and restart policy | P1 | +| `req-gos-storage-an-005` | `risk-gos-storage-an-005` | [tc-gos-storage-an-005](01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md#tc-gos-storage-an-005) — Volume encryption and persistence semantics | P0 | +| `req-gos-compose-006` | `risk-gos-compose-006` | [tc-gos-compose-006](01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md#tc-gos-compose-006) — App manifest version feature and launch-requirement policy | P0 | + + +### Attestation And Crypto + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-attestatio-001` | `risk-gos-attestatio-001` | [tc-gos-attestatio-001](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md#tc-gos-attestatio-001) — Quote report-data binding and hash algorithms | P0 | +| `req-gos-attestatio-002` | `risk-gos-attestatio-002` | [tc-gos-attestatio-002](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md#tc-gos-attestatio-002) — Cross-platform versioned attestation | P0 | +| `req-gos-attestatio-003` | `risk-gos-attestatio-003` | [tc-gos-attestatio-003](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md#tc-gos-attestatio-003) — Deterministic key derivation and purpose separation | P1 | +| `req-gos-attestatio-004` | `risk-gos-attestatio-004` | [tc-gos-attestatio-004](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md#tc-gos-attestatio-004) — TLS key and certificate usage extensions | P0 | +| `req-gos-attestatio-005` | `risk-gos-attestatio-005` | [tc-gos-attestatio-005](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md#tc-gos-attestatio-005) — Signing verification and negative inputs | P1 | +| `req-gos-attestatio-006` | `risk-gos-attestatio-006` | [tc-gos-attestatio-006](01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md#tc-gos-attestatio-006) — GPU boot attestation exposure | P0 | +| `req-gos-gpupolicy-007` | `risk-gos-gpupolicy-007` | [tc-gos-gpupolicy-007](01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md#tc-gos-gpupolicy-007) — GPU attestation proxy nonce claim and Rego policy enforcement | P0 | + + +### Observability And Network + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-observabil-001` | `risk-gos-observabil-001` | [tc-gos-observabil-001](01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md#tc-gos-observabil-001) — Dashboard metrics and container log filtering | P1 | +| `req-gos-observabil-002` | `risk-gos-observabil-002` | [tc-gos-observabil-002](01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md#tc-gos-observabil-002) — Socket activation and listener isolation | P1 | +| `req-gos-observabil-003` | `risk-gos-observabil-003` | [tc-gos-observabil-003](01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md#tc-gos-observabil-003) — WireGuard configuration and checker recovery | P1 | +| `req-gos-observabil-004` | `risk-gos-observabil-004` | [tc-gos-observabil-004](01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md#tc-gos-observabil-004) — System network and resource telemetry | P1 | +| `req-gos-observabil-005` | `risk-gos-observabil-005` | [tc-gos-observabil-005](01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md#tc-gos-observabil-005) — Guest-agent watchdog recovery | P1 | + + +### Platform Services and Image Integrity + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-platform-001` | `risk-gos-platform-001` | [tc-gos-platform-001](01-guest-os/10-platform-services/tc-gos-platform-001/case.md#tc-gos-platform-001) — Local key provider TPM mode and PCCS lifecycle | P0 | +| `req-gos-platform-002` | `risk-gos-platform-002` | [tc-gos-platform-002](01-guest-os/10-platform-services/tc-gos-platform-002/case.md#tc-gos-platform-002) — Local key provider sealing and identity isolation | P0 | +| `req-gos-platform-003` | `risk-gos-platform-003` | [tc-gos-platform-003](01-guest-os/10-platform-services/tc-gos-platform-003/case.md#tc-gos-platform-003) — Host-shared mount and unmount command | P1 | +| `req-gos-platform-004` | `risk-gos-platform-004` | [tc-gos-platform-004](01-guest-os/10-platform-services/tc-gos-platform-004/case.md#tc-gos-platform-004) — Guest image reproducible assembly and manifest | P0 | +| `req-gos-platform-005` | `risk-gos-platform-005` | [tc-gos-platform-005](01-guest-os/10-platform-services/tc-gos-platform-005/case.md#tc-gos-platform-005) — Guest kernel and userspace hardening | P0 | +| `req-gos-platform-006` | `risk-gos-platform-006` | [tc-gos-platform-006](01-guest-os/10-platform-services/tc-gos-platform-006/case.md#tc-gos-platform-006) — Systemd dependency and failure-action graph | P0 | +| `req-gos-platform-007` | `risk-gos-platform-007` | [tc-gos-platform-007](01-guest-os/10-platform-services/tc-gos-platform-007/case.md#tc-gos-platform-007) — Journal persistence rotation and redaction | P1 | +| `req-gos-platform-008` | `risk-gos-platform-008` | [tc-gos-platform-008](01-guest-os/10-platform-services/tc-gos-platform-008/case.md#tc-gos-platform-008) — Docker daemon and container privilege boundary | P0 | +| `req-gos-platform-009` | `risk-gos-platform-009` | [tc-gos-platform-009](01-guest-os/10-platform-services/tc-gos-platform-009/case.md#tc-gos-platform-009) — NVIDIA device initialization and attestation failure | P0 | +| `req-gos-platform-010` | `risk-gos-platform-010` | [tc-gos-platform-010](01-guest-os/10-platform-services/tc-gos-platform-010/case.md#tc-gos-platform-010) — Guest configuration backward and forward compatibility | P0 | + + +### Configuration, Entry Points, and Presentation Models + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-entry-001` | `risk-gos-entry-001` | [tc-gos-entry-001](01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md#tc-gos-entry-001) — Guest-agent configuration precedence and compose deserialization | P0 | +| `req-gos-entry-002` | `risk-gos-entry-002` | [tc-gos-entry-002](01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md#tc-gos-entry-002) — Guest-agent startup modes and partial listener failure | P0 | +| `req-gos-entry-003` | `risk-gos-entry-003` | [tc-gos-entry-003](01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md#tc-gos-entry-003) — Dashboard and metrics model escaping and units | P1 | +| `req-gos-entry-004` | `risk-gos-entry-004` | [tc-gos-entry-004](01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md#tc-gos-entry-004) — Guest-agent library initialization reuse | P1 | + + +### System Setup Utilities and TEE Simulator + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-setup-001` | `risk-gos-setup-001` | [tc-gos-setup-001](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md#tc-gos-setup-001) — Environment JSON allowlist parsing | P0 | +| `req-gos-setup-002` | `risk-gos-setup-002` | [tc-gos-setup-002](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md#tc-gos-setup-002) — Encrypted environment ECDH decryption | P0 | +| `req-gos-setup-003` | `risk-gos-setup-003` | [tc-gos-setup-003](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md#tc-gos-setup-003) — Compose inspection and orphan removal | P1 | +| `req-gos-setup-004` | `risk-gos-setup-004` | [tc-gos-setup-004](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md#tc-gos-setup-004) — Staged system setup idempotence and config identity | P0 | +| `req-gos-setup-005` | `risk-gos-setup-005` | [tc-gos-setup-005](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md#tc-gos-setup-005) — MR config ID verification before provisioning | P0 | +| `req-gos-setup-006` | `risk-gos-setup-006` | [tc-gos-setup-006](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md#tc-gos-setup-006) — KMS URL selection failover and local-provider orthogonality | P0 | +| `req-gos-setup-007` | `risk-gos-setup-007` | [tc-gos-setup-007](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md#tc-gos-setup-007) — Data disk encryption filesystem repair and mount | P0 | +| `req-gos-setup-008` | `risk-gos-setup-008` | [tc-gos-setup-008](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md#tc-gos-setup-008) — Swap file and ZFS zvol setup | P1 | +| `req-gos-setup-009` | `risk-gos-setup-009` | [tc-gos-setup-009](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md#tc-gos-setup-009) — Gateway registration refresh and key-store persistence | P0 | +| `req-gos-setup-010` | `risk-gos-setup-010` | [tc-gos-setup-010](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md#tc-gos-setup-010) — Host API notify and sealing-key client | P0 | +| `req-gos-setup-011` | `risk-gos-setup-011` | [tc-gos-setup-011](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md#tc-gos-setup-011) — GPU measurement in system setup | P0 | +| `req-gos-setup-012` | `risk-gos-setup-012` | [tc-gos-setup-012](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md#tc-gos-setup-012) — Supervisor client full API and auto-start | P1 | +| `req-gos-setup-013` | `risk-gos-setup-013` | [tc-gos-setup-013](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md#tc-gos-setup-013) — TDX simulator device ABI | P0 | +| `req-gos-setup-014` | `risk-gos-setup-014` | [tc-gos-setup-014](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md#tc-gos-setup-014) — SEV-SNP simulator device ABI | P0 | +| `req-gos-setup-015` | `risk-gos-setup-015` | [tc-gos-setup-015](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md#tc-gos-setup-015) — TPM simulator command proxy and lifecycle | P0 | +| `req-gos-setup-016` | `risk-gos-setup-016` | [tc-gos-setup-016](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md#tc-gos-setup-016) — Nitro NSM simulator request ABI | P0 | +| `req-gos-setup-017` | `risk-gos-setup-017` | [tc-gos-setup-017](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md#tc-gos-setup-017) — Simulator platform selection config and mount safety | P0 | +| `req-gos-setup-018` | `risk-gos-setup-018` | [tc-gos-setup-018](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md#tc-gos-setup-018) — TDX event-log extend show and replay CLI | P0 | +| `req-gos-setup-019` | `risk-gos-setup-019` | [tc-gos-setup-019](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md#tc-gos-setup-019) — Quote and quote-report CLI bindings | P0 | +| `req-gos-setup-020` | `risk-gos-setup-020` | [tc-gos-setup-020](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md#tc-gos-setup-020) — RA CA and app key generation CLI | P0 | +| `req-gos-setup-021` | `risk-gos-setup-021` | [tc-gos-setup-021](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md#tc-gos-setup-021) — Random and hexadecimal utility CLI | P0 | +| `req-gos-setup-022` | `risk-gos-setup-022` | [tc-gos-setup-022](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md#tc-gos-setup-022) — vTPM attest quote and verify CLI suite | P0 | +| `req-gos-setup-023` | `risk-gos-setup-023` | [tc-gos-setup-023](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md#tc-gos-setup-023) — Versioned attestation create inspect JSON and strip CLI | P0 | +| `req-gos-setup-024` | `risk-gos-setup-024` | [tc-gos-setup-024](01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md#tc-gos-setup-024) — KMS GetKeys CLI transport and output safety | P0 | + + +### Yocto Image, Runtime, and Hardening + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-yocto-001` | `risk-gos-yocto-001` | [tc-gos-yocto-001](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md#tc-gos-yocto-001) — Development versus production image package boundary | P0 | +| `req-gos-yocto-002` | `risk-gos-yocto-002` | [tc-gos-yocto-002](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md#tc-gos-yocto-002) — OpenSSH account and password-auth hardening | P0 | +| `req-gos-yocto-003` | `risk-gos-yocto-003` | [tc-gos-yocto-003](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md#tc-gos-yocto-003) — Chrony synchronization and clock recovery | P0 | +| `req-gos-yocto-004` | `risk-gos-yocto-004` | [tc-gos-yocto-004](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md#tc-gos-yocto-004) — Containerd stargz snapshotter integrity and fallback | P0 | +| `req-gos-yocto-005` | `risk-gos-yocto-005` | [tc-gos-yocto-005](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md#tc-gos-yocto-005) — Sysbox runtime services and nested-container boundary | P0 | +| `req-gos-yocto-006` | `risk-gos-yocto-006` | [tc-gos-yocto-006](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md#tc-gos-yocto-006) — Docker daemon CPU/GPU configuration variants | P0 | +| `req-gos-yocto-007` | `risk-gos-yocto-007` | [tc-gos-yocto-007](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md#tc-gos-yocto-007) — Reproducible Yocto build and artifact export | P0 | +| `req-gos-yocto-008` | `risk-gos-yocto-008` | [tc-gos-yocto-008](01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md#tc-gos-yocto-008) — AWS image hardening audit | P0 | + + +### Guest OS Build and Existing Regression Suite + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gos-build-001` | `risk-gos-build-001` | [tc-gos-build-001](01-guest-os/14-gos-build/tc-gos-build-001/case.md#tc-gos-build-001) — Guest OS Build and Existing Regression Suite | P0 | + + +## VMM + + +### Vmm RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-vmm-001` | `risk-vmm-vmm-001` | [tc-vmm-vmm-001](02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md#tc-vmm-vmm-001) — Vmm.CreateVm | P0 | +| `req-vmm-vmm-002` | `risk-vmm-vmm-002` | [tc-vmm-vmm-002](02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md#tc-vmm-vmm-002) — Vmm.StartVm | P1 | +| `req-vmm-vmm-003` | `risk-vmm-vmm-003` | [tc-vmm-vmm-003](02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md#tc-vmm-vmm-003) — Vmm.StopVm | P1 | +| `req-vmm-vmm-004` | `risk-vmm-vmm-004` | [tc-vmm-vmm-004](02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md#tc-vmm-vmm-004) — Vmm.RemoveVm | P1 | +| `req-vmm-vmm-005` | `risk-vmm-vmm-005` | [tc-vmm-vmm-005](02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md#tc-vmm-vmm-005) — Vmm.UpgradeApp | P1 | +| `req-vmm-vmm-006` | `risk-vmm-vmm-006` | [tc-vmm-vmm-006](02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md#tc-vmm-vmm-006) — Vmm.UpdateVm | P1 | +| `req-vmm-vmm-007` | `risk-vmm-vmm-007` | [tc-vmm-vmm-007](02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md#tc-vmm-vmm-007) — Vmm.ShutdownVm | P1 | +| `req-vmm-vmm-008` | `risk-vmm-vmm-008` | [tc-vmm-vmm-008](02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md#tc-vmm-vmm-008) — Vmm.ResizeVm | P1 | +| `req-vmm-vmm-009` | `risk-vmm-vmm-009` | [tc-vmm-vmm-009](02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md#tc-vmm-vmm-009) — Vmm.GetComposeHash | P1 | +| `req-vmm-vmm-010` | `risk-vmm-vmm-010` | [tc-vmm-vmm-010](02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md#tc-vmm-vmm-010) — Vmm.Status | P1 | +| `req-vmm-vmm-011` | `risk-vmm-vmm-011` | [tc-vmm-vmm-011](02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md#tc-vmm-vmm-011) — Vmm.ListImages | P1 | +| `req-vmm-vmm-012` | `risk-vmm-vmm-012` | [tc-vmm-vmm-012](02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md#tc-vmm-vmm-012) — Vmm.GetAppEnvEncryptPubKey | P1 | +| `req-vmm-vmm-013` | `risk-vmm-vmm-013` | [tc-vmm-vmm-013](02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md#tc-vmm-vmm-013) — Vmm.GetInfo | P1 | +| `req-vmm-vmm-014` | `risk-vmm-vmm-014` | [tc-vmm-vmm-014](02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md#tc-vmm-vmm-014) — Vmm.Version | P1 | +| `req-vmm-vmm-015` | `risk-vmm-vmm-015` | [tc-vmm-vmm-015](02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md#tc-vmm-vmm-015) — Vmm.GetMeta | P1 | +| `req-vmm-vmm-016` | `risk-vmm-vmm-016` | [tc-vmm-vmm-016](02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md#tc-vmm-vmm-016) — Vmm.ListGpus | P1 | +| `req-vmm-vmm-017` | `risk-vmm-vmm-017` | [tc-vmm-vmm-017](02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md#tc-vmm-vmm-017) — Vmm.ReloadVms | P1 | +| `req-vmm-vmm-018` | `risk-vmm-vmm-018` | [tc-vmm-vmm-018](02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md#tc-vmm-vmm-018) — Vmm.SvList | P1 | +| `req-vmm-vmm-019` | `risk-vmm-vmm-019` | [tc-vmm-vmm-019](02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md#tc-vmm-vmm-019) — Vmm.SvStop | P1 | +| `req-vmm-vmm-020` | `risk-vmm-vmm-020` | [tc-vmm-vmm-020](02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md#tc-vmm-vmm-020) — Vmm.SvRemove | P1 | +| `req-vmm-vmm-021` | `risk-vmm-vmm-021` | [tc-vmm-vmm-021](02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md#tc-vmm-vmm-021) — Vmm.ListRegistryImages | P1 | +| `req-vmm-vmm-022` | `risk-vmm-vmm-022` | [tc-vmm-vmm-022](02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md#tc-vmm-vmm-022) — Vmm.PullRegistryImage | P1 | +| `req-vmm-vmm-023` | `risk-vmm-vmm-023` | [tc-vmm-vmm-023](02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md#tc-vmm-vmm-023) — Vmm.DeleteImage | P1 | + + +### HostApi RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-hostapi-001` | `risk-vmm-hostapi-001` | [tc-vmm-hostapi-001](02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md#tc-vmm-hostapi-001) — HostApi.Info | P1 | +| `req-vmm-hostapi-002` | `risk-vmm-hostapi-002` | [tc-vmm-hostapi-002](02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md#tc-vmm-hostapi-002) — HostApi.Notify | P1 | +| `req-vmm-hostapi-003` | `risk-vmm-hostapi-003` | [tc-vmm-hostapi-003](02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md#tc-vmm-hostapi-003) — HostApi.GetSealingKey | P1 | + + +### Configuration And Security + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-configurat-001` | `risk-vmm-configurat-001` | [tc-vmm-configurat-001](02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md#tc-vmm-configurat-001) — Configuration defaults and validation | P1 | +| `req-vmm-configurat-002` | `risk-vmm-configurat-002` | [tc-vmm-configurat-002](02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md#tc-vmm-configurat-002) — External API authentication and listener separation | P1 | +| `req-vmm-configurat-003` | `risk-vmm-configurat-003` | [tc-vmm-configurat-003](02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md#tc-vmm-configurat-003) — Per-instance simulated TEE selection | P1 | +| `req-vmm-configurat-004` | `risk-vmm-configurat-004` | [tc-vmm-configurat-004](02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md#tc-vmm-configurat-004) — TPM attachment decision materialization | P1 | +| `req-vmm-tdxvariant-005` | `risk-vmm-tdxvariant-005` | [tc-vmm-tdxvariant-005](02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md#tc-vmm-tdxvariant-005) — TDX legacy lite and auto variant resolution matrix | P0 | + + +### Vm Lifecycle + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-vm-lifecyc-001` | `risk-vmm-vm-lifecyc-001` | [tc-vmm-vm-lifecyc-001](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md#tc-vmm-vm-lifecyc-001) — Create/start/stop/remove idempotency | P1 | +| `req-vmm-vm-lifecyc-002` | `risk-vmm-vm-lifecyc-002` | [tc-vmm-vm-lifecyc-002](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md#tc-vmm-vm-lifecyc-002) — Graceful shutdown versus forced stop | P1 | +| `req-vmm-vm-lifecyc-003` | `risk-vmm-vm-lifecyc-003` | [tc-vmm-vm-lifecyc-003](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md#tc-vmm-vm-lifecyc-003) — Update and upgrade identity semantics | P1 | +| `req-vmm-vm-lifecyc-004` | `risk-vmm-vm-lifecyc-004` | [tc-vmm-vm-lifecyc-004](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md#tc-vmm-vm-lifecyc-004) — Resize CPU memory and disk | P1 | +| `req-vmm-vm-lifecyc-005` | `risk-vmm-vm-lifecyc-005` | [tc-vmm-vm-lifecyc-005](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md#tc-vmm-vm-lifecyc-005) — Reload and crash recovery | P1 | +| `req-vmm-vm-lifecyc-006` | `risk-vmm-vm-lifecyc-006` | [tc-vmm-vm-lifecyc-006](02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md#tc-vmm-vm-lifecyc-006) — Auto-restart policy and backoff | P1 | + + +### Compute Network Image + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-compute-ne-001` | `risk-vmm-compute-ne-001` | [tc-vmm-compute-ne-001](02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md#tc-vmm-compute-ne-001) — User bridge and custom networking | P1 | +| `req-vmm-compute-ne-002` | `risk-vmm-compute-ne-002` | [tc-vmm-compute-ne-002](02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md#tc-vmm-compute-ne-002) — Port mapping protocols and conflicts | P1 | +| `req-vmm-compute-ne-003` | `risk-vmm-compute-ne-003` | [tc-vmm-compute-ne-003](02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md#tc-vmm-compute-ne-003) — NUMA pinning hugepages and resource isolation | P0 | +| `req-vmm-compute-ne-004` | `risk-vmm-compute-ne-004` | [tc-vmm-compute-ne-004](02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md#tc-vmm-compute-ne-004) — GPU discovery attach modes and ownership | P0 | +| `req-vmm-compute-ne-005` | `risk-vmm-compute-ne-005` | [tc-vmm-compute-ne-005](02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md#tc-vmm-compute-ne-005) — Local image discovery metadata and deletion | P1 | +| `req-vmm-compute-ne-006` | `risk-vmm-compute-ne-006` | [tc-vmm-compute-ne-006](02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md#tc-vmm-compute-ne-006) — Registry authentication pull and extraction | P1 | +| `req-vmm-compute-ne-007` | `risk-vmm-compute-ne-007` | [tc-vmm-compute-ne-007](02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md#tc-vmm-compute-ne-007) — QEMU command and platform matrix | P0 | +| `req-vmm-volume-008` | `risk-vmm-volume-008` | [tc-vmm-volume-008](02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md#tc-vmm-volume-008) — Measured verity volume extraction resolution and path safety | P0 | + + +### Ui Observability Host + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-ui-observa-001` | `risk-vmm-ui-observa-001` | [tc-vmm-ui-observa-001](02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md#tc-vmm-ui-observa-001) — Status filtering pagination and event history | P1 | +| `req-vmm-ui-observa-002` | `risk-vmm-ui-observa-002` | [tc-vmm-ui-observa-002](02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md#tc-vmm-ui-observa-002) — Console log channels follow and ANSI handling | P1 | +| `req-vmm-ui-observa-003` | `risk-vmm-ui-observa-003` | [tc-vmm-ui-observa-003](02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md#tc-vmm-ui-observa-003) — Host sealing-key provider integration | P0 | +| `req-vmm-ui-observa-004` | `risk-vmm-ui-observa-004` | [tc-vmm-ui-observa-004](02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md#tc-vmm-ui-observa-004) — Supervisor passthrough operations | P1 | +| `req-vmm-ui-observa-005` | `risk-vmm-ui-observa-005` | [tc-vmm-ui-observa-005](02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md#tc-vmm-ui-observa-005) — Web UI deployment workflows | P1 | +| `req-vmm-serial-006` | `risk-vmm-serial-006` | [tc-vmm-serial-006](02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md#tc-vmm-serial-006) — Serial log separator rotation history and follow continuity | P0 | + + +### Guest Proxy and Manifest Fidelity + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-manifest-001` | `risk-vmm-manifest-001` | [tc-vmm-manifest-001](02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md#tc-vmm-manifest-001) — Proxied GuestApi transport and VM targeting | P0 | +| `req-vmm-manifest-002` | `risk-vmm-manifest-002` | [tc-vmm-manifest-002](02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md#tc-vmm-manifest-002) — Manifest persistence and QEMU/vm_config agreement | P0 | + + +### Internal State, Measurement, and Launch Helpers + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-internal-001` | `risk-vmm-internal-001` | [tc-vmm-internal-001](02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md#tc-vmm-internal-001) — Host-share disk creation and content bounds | P0 | +| `req-vmm-internal-002` | `risk-vmm-internal-002` | [tc-vmm-internal-002](02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md#tc-vmm-internal-002) — Numeric ID pool allocation reuse and exhaustion | P1 | +| `req-vmm-internal-003` | `risk-vmm-internal-003` | [tc-vmm-internal-003](02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md#tc-vmm-internal-003) — Image metadata parsing and firmware selection | P0 | +| `req-vmm-internal-004` | `risk-vmm-internal-004` | [tc-vmm-internal-004](02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md#tc-vmm-internal-004) — MR config and SNP host-data construction | P0 | +| `req-vmm-internal-005` | `risk-vmm-internal-005` | [tc-vmm-internal-005](02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md#tc-vmm-internal-005) — VM status protobuf projection and URL construction | P1 | +| `req-vmm-internal-006` | `risk-vmm-internal-006` | [tc-vmm-internal-006](02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md#tc-vmm-internal-006) — One-shot VM execution and cleanup | P1 | +| `req-vmm-internal-007` | `risk-vmm-internal-007` | [tc-vmm-internal-007](02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md#tc-vmm-internal-007) — Generated OpenAPI contract fidelity | P1 | +| `req-vmm-internal-008` | `risk-vmm-internal-008` | [tc-vmm-internal-008](02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md#tc-vmm-internal-008) — Launcher QEMU and swtpm coupled lifecycle | P0 | + + +### VMM Build, CLI, UI, and Existing Regression Suite + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-vmm-build-001` | `risk-vmm-build-001` | [tc-vmm-build-001](02-vmm/09-vmm-build/tc-vmm-build-001/case.md#tc-vmm-build-001) — VMM Build, CLI, UI, and Existing Regression Suite | P0 | + + +## KMS + + +### KMS RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-kms-001` | `risk-kms-kms-001` | [tc-kms-kms-001](03-kms/01-rpc-kms/tc-kms-kms-001/case.md#tc-kms-kms-001) — KMS.GetAppKey | P0 | +| `req-kms-kms-002` | `risk-kms-kms-002` | [tc-kms-kms-002](03-kms/01-rpc-kms/tc-kms-kms-002/case.md#tc-kms-kms-002) — KMS.GetKmsKey | P0 | +| `req-kms-kms-003` | `risk-kms-kms-003` | [tc-kms-kms-003](03-kms/01-rpc-kms/tc-kms-kms-003/case.md#tc-kms-kms-003) — KMS.GetAppEnvEncryptPubKey | P1 | +| `req-kms-kms-004` | `risk-kms-kms-004` | [tc-kms-kms-004](03-kms/01-rpc-kms/tc-kms-kms-004/case.md#tc-kms-kms-004) — KMS.GetMeta | P1 | +| `req-kms-kms-005` | `risk-kms-kms-005` | [tc-kms-kms-005](03-kms/01-rpc-kms/tc-kms-kms-005/case.md#tc-kms-kms-005) — KMS.GetTempCaCert | P1 | +| `req-kms-kms-006` | `risk-kms-kms-006` | [tc-kms-kms-006](03-kms/01-rpc-kms/tc-kms-kms-006/case.md#tc-kms-kms-006) — KMS.SignCert | P0 | + + +### Admin RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-admin-001` | `risk-kms-admin-001` | [tc-kms-admin-001](03-kms/02-rpc-admin/tc-kms-admin-001/case.md#tc-kms-admin-001) — Admin.ClearImageCache | P1 | + + +### Onboard RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-onboard-001` | `risk-kms-onboard-001` | [tc-kms-onboard-001](03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md#tc-kms-onboard-001) — Onboard.Bootstrap | P1 | +| `req-kms-onboard-002` | `risk-kms-onboard-002` | [tc-kms-onboard-002](03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md#tc-kms-onboard-002) — Onboard.Onboard | P1 | +| `req-kms-onboard-003` | `risk-kms-onboard-003` | [tc-kms-onboard-003](03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md#tc-kms-onboard-003) — Onboard.GetAttestationInfo | P1 | +| `req-kms-onboard-004` | `risk-kms-onboard-004` | [tc-kms-onboard-004](03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md#tc-kms-onboard-004) — Onboard.Finish | P1 | + + +### Bootstrap Onboard + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-bootstrap--001` | `risk-kms-bootstrap--001` | [tc-kms-bootstrap--001](03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md#tc-kms-bootstrap--001) — Fresh bootstrap key hierarchy | P0 | +| `req-kms-bootstrap--002` | `risk-kms-bootstrap--002` | [tc-kms-bootstrap--002](03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md#tc-kms-bootstrap--002) — Onboard from existing KMS | P0 | +| `req-kms-bootstrap--003` | `risk-kms-bootstrap--003` | [tc-kms-bootstrap--003](03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md#tc-kms-bootstrap--003) — Finish onboarding and listener transition | P0 | +| `req-kms-bootstrap--004` | `risk-kms-bootstrap--004` | [tc-kms-bootstrap--004](03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md#tc-kms-bootstrap--004) — On-chain attestation information | P0 | + + +### Attestation Authorization + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-attestatio-001` | `risk-kms-attestatio-001` | [tc-kms-attestatio-001](03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md#tc-kms-attestatio-001) — TDX full and lite app authorization | P0 | +| `req-kms-attestatio-002` | `risk-kms-attestatio-002` | [tc-kms-attestatio-002](03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md#tc-kms-attestatio-002) — SEV-SNP app authorization | P0 | +| `req-kms-attestatio-003` | `risk-kms-attestatio-003` | [tc-kms-attestatio-003](03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md#tc-kms-attestatio-003) — GCP TDX and Nitro TPM authorization | P0 | +| `req-kms-attestatio-004` | `risk-kms-attestatio-004` | [tc-kms-attestatio-004](03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md#tc-kms-attestatio-004) — Upgrade authority and allow_any_upgrade | P0 | +| `req-kms-attestatio-005` | `risk-kms-attestatio-005` | [tc-kms-attestatio-005](03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md#tc-kms-attestatio-005) — Authorization backend matrix | P1 | +| `req-kms-platform-006` | `risk-kms-platform-006` | [tc-kms-platform-006](03-kms/05-attestation-authorization/tc-kms-platform-006/case.md#tc-kms-platform-006) — Nitro Enclave app and KMS authorization | P0 | + + +### Keys Certs Operations + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-keys-certs-001` | `risk-kms-keys-certs-001` | [tc-kms-keys-certs-001](03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md#tc-kms-keys-certs-001) — Per-app key hierarchy isolation | P0 | +| `req-kms-keys-certs-002` | `risk-kms-keys-certs-002` | [tc-kms-keys-certs-002](03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md#tc-kms-keys-certs-002) — Environment public-key freshness signatures | P1 | +| `req-kms-keys-certs-003` | `risk-kms-keys-certs-003` | [tc-kms-keys-certs-003](03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md#tc-kms-keys-certs-003) — KMS key handover and rotation chain | P0 | +| `req-kms-keys-certs-004` | `risk-kms-keys-certs-004` | [tc-kms-keys-certs-004](03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md#tc-kms-keys-certs-004) — Certificate signing CSR and app binding | P0 | +| `req-kms-keys-certs-005` | `risk-kms-keys-certs-005` | [tc-kms-keys-certs-005](03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md#tc-kms-keys-certs-005) — Temporary CA lifecycle | P0 | +| `req-kms-keys-certs-006` | `risk-kms-keys-certs-006` | [tc-kms-keys-certs-006](03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md#tc-kms-keys-certs-006) — Image measurement cache clear and refill | P1 | +| `req-kms-keys-certs-007` | `risk-kms-keys-certs-007` | [tc-kms-keys-certs-007](03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md#tc-kms-keys-certs-007) — Admin authentication transports | P1 | +| `req-kms-keys-certs-008` | `risk-kms-keys-certs-008` | [tc-kms-keys-certs-008](03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md#tc-kms-keys-certs-008) — Metrics metadata and failure diagnostics | P1 | +| `req-kms-keys-certs-009` | `risk-kms-keys-certs-009` | [tc-kms-keys-certs-009](03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md#tc-kms-keys-certs-009) — Crash consistency and backup recovery | P0 | +| `req-kms-release-010` | `risk-kms-release-010` | [tc-kms-release-010](03-kms/06-keys-certs-operations/tc-kms-release-010/case.md#tc-kms-release-010) — Platform-specific key-release feature gates | P0 | +| `req-kms-apiver-011` | `risk-kms-apiver-011` | [tc-kms-apiver-011](03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md#tc-kms-apiver-011) — GetAppKey and SignCert API-version compatibility | P0 | + + +### Authorization Implementations and Contract + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-auth-001` | `risk-kms-auth-001` | [tc-kms-auth-001](03-kms/07-authorization-implementations/tc-kms-auth-001/case.md#tc-kms-auth-001) — Simple authorization configuration rules | P0 | +| `req-kms-auth-002` | `risk-kms-auth-002` | [tc-kms-auth-002](03-kms/07-authorization-implementations/tc-kms-auth-002/case.md#tc-kms-auth-002) — Mock authorization safety boundary | P0 | +| `req-kms-auth-003` | `risk-kms-auth-003` | [tc-kms-auth-003](03-kms/07-authorization-implementations/tc-kms-auth-003/case.md#tc-kms-auth-003) — Ethereum authorization request signatures and replay | P0 | +| `req-kms-auth-004` | `risk-kms-auth-004` | [tc-kms-auth-004](03-kms/07-authorization-implementations/tc-kms-auth-004/case.md#tc-kms-auth-004) — KMS contract ownership roles and upgrade controls | P0 | +| `req-kms-auth-005` | `risk-kms-auth-005` | [tc-kms-auth-005](03-kms/07-authorization-implementations/tc-kms-auth-005/case.md#tc-kms-auth-005) — KMS node registration and authorization lifecycle | P0 | +| `req-kms-auth-006` | `risk-kms-auth-006` | [tc-kms-auth-006](03-kms/07-authorization-implementations/tc-kms-auth-006/case.md#tc-kms-auth-006) — Application boot policy image and config matrix | P0 | +| `req-kms-auth-007` | `risk-kms-auth-007` | [tc-kms-auth-007](03-kms/07-authorization-implementations/tc-kms-auth-007/case.md#tc-kms-auth-007) — Ethereum RPC failure reorg and finality handling | P0 | +| `req-kms-auth-008` | `risk-kms-auth-008` | [tc-kms-auth-008](03-kms/07-authorization-implementations/tc-kms-auth-008/case.md#tc-kms-auth-008) — Authorization API schema and error compatibility | P1 | +| `req-kms-auth-009` | `risk-kms-auth-009` | [tc-kms-auth-009](03-kms/07-authorization-implementations/tc-kms-auth-009/case.md#tc-kms-auth-009) — Contract event audit completeness | P1 | +| `req-kms-auth-010` | `risk-kms-auth-010` | [tc-kms-auth-010](03-kms/07-authorization-implementations/tc-kms-auth-010/case.md#tc-kms-auth-010) — Authorization cache scope and invalidation | P0 | + + +### Upgrade and Onboard Compatibility to 0.6.0 + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-upgrade-001` | `risk-kms-upgrade-001` | [tc-kms-upgrade-001](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md#tc-kms-upgrade-001) — 0.5.4 to 0.6.0 through 0.5.7 bridge | P0 | +| `req-kms-upgrade-002` | `risk-kms-upgrade-002` | [tc-kms-upgrade-002](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md#tc-kms-upgrade-002) — Direct 0.5.4 to 0.6.0 incompatibility is explicit | P0 | +| `req-kms-upgrade-003` | `risk-kms-upgrade-003` | [tc-kms-upgrade-003](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md#tc-kms-upgrade-003) — 0.5.8 direct onboard to 0.6.0 | P0 | +| `req-kms-upgrade-004` | `risk-kms-upgrade-004` | [tc-kms-upgrade-004](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md#tc-kms-upgrade-004) — kms-v0.5.11 direct onboard to 0.6.0 | P0 | +| `req-kms-upgrade-005` | `risk-kms-upgrade-005` | [tc-kms-upgrade-005](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md#tc-kms-upgrade-005) — Old source rejects 0.6.0 target in TDX-lite mode | P0 | +| `req-kms-upgrade-006` | `risk-kms-upgrade-006` | [tc-kms-upgrade-006](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md#tc-kms-upgrade-006) — Legacy mode is forced throughout mixed-source cutover | P0 | +| `req-kms-upgrade-007` | `risk-kms-upgrade-007` | [tc-kms-upgrade-007](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md#tc-kms-upgrade-007) — 0.5.4 age-matched ACPI diagnosis | P0 | +| `req-kms-upgrade-008` | `risk-kms-upgrade-008` | [tc-kms-upgrade-008](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md#tc-kms-upgrade-008) — Source and target allowlist completeness | P0 | +| `req-kms-upgrade-009` | `risk-kms-upgrade-009` | [tc-kms-upgrade-009](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md#tc-kms-upgrade-009) — Mixed-version KMS endpoint service consistency | P0 | +| `req-kms-upgrade-010` | `risk-kms-upgrade-010` | [tc-kms-upgrade-010](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md#tc-kms-upgrade-010) — KMS replacement cutover and rollback window | P0 | +| `req-kms-upgrade-011` | `risk-kms-upgrade-011` | [tc-kms-upgrade-011](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md#tc-kms-upgrade-011) — Measurement cache across KMS upgrade boundaries | P0 | +| `req-kms-upgrade-012` | `risk-kms-upgrade-012` | [tc-kms-upgrade-012](03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md#tc-kms-upgrade-012) — Post-KMS gateway 0.6.0 upgrade order | P0 | + + +### Certificate Transparency Log Files + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-ct-001` | `risk-kms-ct-001` | [tc-kms-ct-001](03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md#tc-kms-ct-001) — Concurrent certificate log append and iteration | P0 | + + +### Service Startup and Mode Transition + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-startup-001` | `risk-kms-startup-001` | [tc-kms-startup-001](03-kms/10-service-startup/tc-kms-startup-001/case.md#tc-kms-startup-001) — Onboard, main, admin, metrics, and health listener startup | P0 | + + +### Authorization Service Runtime and Deployment + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-runtime-001` | `risk-kms-runtime-001` | [tc-kms-runtime-001](03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md#tc-kms-runtime-001) — Ethereum authorization HTTP server schema and listener | P0 | +| `req-kms-runtime-002` | `risk-kms-runtime-002` | [tc-kms-runtime-002](03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md#tc-kms-runtime-002) — Bun and Node authorization implementation parity | P0 | +| `req-kms-runtime-003` | `risk-kms-runtime-003` | [tc-kms-runtime-003](03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md#tc-kms-runtime-003) — Authorization deployment and management scripts | P0 | +| `req-kms-runtime-004` | `risk-kms-runtime-004` | [tc-kms-runtime-004](03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md#tc-kms-runtime-004) — Authorization service container deployment | P1 | +| `req-kms-runtime-005` | `risk-kms-runtime-005` | [tc-kms-runtime-005](03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md#tc-kms-runtime-005) — DstackApp device compose TCB and upgrade-disable policy | P0 | + + +### KMS Build, Image, Auth, Contract, and Existing Regression Suite + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-kms-build-001` | `risk-kms-build-001` | [tc-kms-build-001](03-kms/12-kms-build/tc-kms-build-001/case.md#tc-kms-build-001) — KMS Build, Image, Auth, Contract, and Existing Regression Suite | P0 | + + +## Gateway + + +### Gateway RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-gateway-001` | `risk-gw-gateway-001` | [tc-gw-gateway-001](04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md#tc-gw-gateway-001) — Gateway.RegisterCvm | P0 | +| `req-gw-gateway-002` | `risk-gw-gateway-002` | [tc-gw-gateway-002](04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md#tc-gw-gateway-002) — Gateway.AcmeInfo | P1 | +| `req-gw-gateway-003` | `risk-gw-gateway-003` | [tc-gw-gateway-003](04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md#tc-gw-gateway-003) — Gateway.Info | P1 | +| `req-gw-gateway-004` | `risk-gw-gateway-004` | [tc-gw-gateway-004](04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md#tc-gw-gateway-004) — Gateway.GetPeers | P1 | + + +### Debug RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-debug-001` | `risk-gw-debug-001` | [tc-gw-debug-001](04-gateway/02-rpc-debug/tc-gw-debug-001/case.md#tc-gw-debug-001) — Debug.RegisterCvm | P0 | +| `req-gw-debug-002` | `risk-gw-debug-002` | [tc-gw-debug-002](04-gateway/02-rpc-debug/tc-gw-debug-002/case.md#tc-gw-debug-002) — Debug.Info | P1 | +| `req-gw-debug-003` | `risk-gw-debug-003` | [tc-gw-debug-003](04-gateway/02-rpc-debug/tc-gw-debug-003/case.md#tc-gw-debug-003) — Debug.GetSyncData | P1 | +| `req-gw-debug-004` | `risk-gw-debug-004` | [tc-gw-debug-004](04-gateway/02-rpc-debug/tc-gw-debug-004/case.md#tc-gw-debug-004) — Debug.GetProxyState | P1 | + + +### Admin RPC + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-admin-001` | `risk-gw-admin-001` | [tc-gw-admin-001](04-gateway/03-rpc-admin/tc-gw-admin-001/case.md#tc-gw-admin-001) — Admin.Status | P1 | +| `req-gw-admin-002` | `risk-gw-admin-002` | [tc-gw-admin-002](04-gateway/03-rpc-admin/tc-gw-admin-002/case.md#tc-gw-admin-002) — Admin.GetInfo | P1 | +| `req-gw-admin-003` | `risk-gw-admin-003` | [tc-gw-admin-003](04-gateway/03-rpc-admin/tc-gw-admin-003/case.md#tc-gw-admin-003) — Admin.Exit | P1 | +| `req-gw-admin-004` | `risk-gw-admin-004` | [tc-gw-admin-004](04-gateway/03-rpc-admin/tc-gw-admin-004/case.md#tc-gw-admin-004) — Admin.RenewCert | P1 | +| `req-gw-admin-005` | `risk-gw-admin-005` | [tc-gw-admin-005](04-gateway/03-rpc-admin/tc-gw-admin-005/case.md#tc-gw-admin-005) — Admin.ReloadCert | P1 | +| `req-gw-admin-006` | `risk-gw-admin-006` | [tc-gw-admin-006](04-gateway/03-rpc-admin/tc-gw-admin-006/case.md#tc-gw-admin-006) — Admin.SetCaa | P1 | +| `req-gw-admin-007` | `risk-gw-admin-007` | [tc-gw-admin-007](04-gateway/03-rpc-admin/tc-gw-admin-007/case.md#tc-gw-admin-007) — Admin.GetMeta | P1 | +| `req-gw-admin-008` | `risk-gw-admin-008` | [tc-gw-admin-008](04-gateway/03-rpc-admin/tc-gw-admin-008/case.md#tc-gw-admin-008) — Admin.SetNodeUrl | P1 | +| `req-gw-admin-009` | `risk-gw-admin-009` | [tc-gw-admin-009](04-gateway/03-rpc-admin/tc-gw-admin-009/case.md#tc-gw-admin-009) — Admin.SetNodeStatus | P1 | +| `req-gw-admin-010` | `risk-gw-admin-010` | [tc-gw-admin-010](04-gateway/03-rpc-admin/tc-gw-admin-010/case.md#tc-gw-admin-010) — Admin.WaveKvStatus | P1 | +| `req-gw-admin-011` | `risk-gw-admin-011` | [tc-gw-admin-011](04-gateway/03-rpc-admin/tc-gw-admin-011/case.md#tc-gw-admin-011) — Admin.GetInstanceHandshakes | P1 | +| `req-gw-admin-012` | `risk-gw-admin-012` | [tc-gw-admin-012](04-gateway/03-rpc-admin/tc-gw-admin-012/case.md#tc-gw-admin-012) — Admin.GetGlobalConnections | P1 | +| `req-gw-admin-013` | `risk-gw-admin-013` | [tc-gw-admin-013](04-gateway/03-rpc-admin/tc-gw-admin-013/case.md#tc-gw-admin-013) — Admin.GetNodeStatuses | P1 | +| `req-gw-admin-014` | `risk-gw-admin-014` | [tc-gw-admin-014](04-gateway/03-rpc-admin/tc-gw-admin-014/case.md#tc-gw-admin-014) — Admin.ListDnsCredentials | P1 | +| `req-gw-admin-015` | `risk-gw-admin-015` | [tc-gw-admin-015](04-gateway/03-rpc-admin/tc-gw-admin-015/case.md#tc-gw-admin-015) — Admin.GetDnsCredential | P1 | +| `req-gw-admin-016` | `risk-gw-admin-016` | [tc-gw-admin-016](04-gateway/03-rpc-admin/tc-gw-admin-016/case.md#tc-gw-admin-016) — Admin.CreateDnsCredential | P1 | +| `req-gw-admin-017` | `risk-gw-admin-017` | [tc-gw-admin-017](04-gateway/03-rpc-admin/tc-gw-admin-017/case.md#tc-gw-admin-017) — Admin.UpdateDnsCredential | P1 | +| `req-gw-admin-018` | `risk-gw-admin-018` | [tc-gw-admin-018](04-gateway/03-rpc-admin/tc-gw-admin-018/case.md#tc-gw-admin-018) — Admin.DeleteDnsCredential | P1 | +| `req-gw-admin-019` | `risk-gw-admin-019` | [tc-gw-admin-019](04-gateway/03-rpc-admin/tc-gw-admin-019/case.md#tc-gw-admin-019) — Admin.GetDefaultDnsCredential | P1 | +| `req-gw-admin-020` | `risk-gw-admin-020` | [tc-gw-admin-020](04-gateway/03-rpc-admin/tc-gw-admin-020/case.md#tc-gw-admin-020) — Admin.SetDefaultDnsCredential | P1 | +| `req-gw-admin-021` | `risk-gw-admin-021` | [tc-gw-admin-021](04-gateway/03-rpc-admin/tc-gw-admin-021/case.md#tc-gw-admin-021) — Admin.ListZtDomains | P1 | +| `req-gw-admin-022` | `risk-gw-admin-022` | [tc-gw-admin-022](04-gateway/03-rpc-admin/tc-gw-admin-022/case.md#tc-gw-admin-022) — Admin.GetZtDomain | P1 | +| `req-gw-admin-023` | `risk-gw-admin-023` | [tc-gw-admin-023](04-gateway/03-rpc-admin/tc-gw-admin-023/case.md#tc-gw-admin-023) — Admin.AddZtDomain | P1 | +| `req-gw-admin-024` | `risk-gw-admin-024` | [tc-gw-admin-024](04-gateway/03-rpc-admin/tc-gw-admin-024/case.md#tc-gw-admin-024) — Admin.UpdateZtDomain | P1 | +| `req-gw-admin-025` | `risk-gw-admin-025` | [tc-gw-admin-025](04-gateway/03-rpc-admin/tc-gw-admin-025/case.md#tc-gw-admin-025) — Admin.DeleteZtDomain | P1 | +| `req-gw-admin-026` | `risk-gw-admin-026` | [tc-gw-admin-026](04-gateway/03-rpc-admin/tc-gw-admin-026/case.md#tc-gw-admin-026) — Admin.RenewZtDomainCert | P1 | +| `req-gw-admin-027` | `risk-gw-admin-027` | [tc-gw-admin-027](04-gateway/03-rpc-admin/tc-gw-admin-027/case.md#tc-gw-admin-027) — Admin.ForceReleaseCertLock | P1 | +| `req-gw-admin-028` | `risk-gw-admin-028` | [tc-gw-admin-028](04-gateway/03-rpc-admin/tc-gw-admin-028/case.md#tc-gw-admin-028) — Admin.ListCertAttestations | P1 | +| `req-gw-admin-029` | `risk-gw-admin-029` | [tc-gw-admin-029](04-gateway/03-rpc-admin/tc-gw-admin-029/case.md#tc-gw-admin-029) — Admin.GetCertbotConfig | P1 | +| `req-gw-admin-030` | `risk-gw-admin-030` | [tc-gw-admin-030](04-gateway/03-rpc-admin/tc-gw-admin-030/case.md#tc-gw-admin-030) — Admin.SetCertbotConfig | P1 | +| `req-gw-admin-031` | `risk-gw-admin-031` | [tc-gw-admin-031](04-gateway/03-rpc-admin/tc-gw-admin-031/case.md#tc-gw-admin-031) — Admin.SetInstancePortPolicy | P1 | +| `req-gw-admin-032` | `risk-gw-admin-032` | [tc-gw-admin-032](04-gateway/03-rpc-admin/tc-gw-admin-032/case.md#tc-gw-admin-032) — Admin.ClearInstancePortPolicy | P1 | +| `req-gw-admin-033` | `risk-gw-admin-033` | [tc-gw-admin-033](04-gateway/03-rpc-admin/tc-gw-admin-033/case.md#tc-gw-admin-033) — Admin.GetInstancePortPolicy | P1 | + + +### Registration Wireguard Policy + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-registrati-001` | `risk-gw-registrati-001` | [tc-gw-registrati-001](04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md#tc-gw-registrati-001) — Attested CVM registration and re-registration | P0 | +| `req-gw-registrati-002` | `risk-gw-registrati-002` | [tc-gw-registrati-002](04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md#tc-gw-registrati-002) — WireGuard IP allocation and peer lifecycle | P1 | +| `req-gw-registrati-003` | `risk-gw-registrati-003` | [tc-gw-registrati-003](04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md#tc-gw-registrati-003) — Restrict-mode port enforcement | P1 | +| `req-gw-registrati-004` | `risk-gw-registrati-004` | [tc-gw-registrati-004](04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md#tc-gw-registrati-004) — Port policy fetch fallback compatibility | P1 | + + +### Proxy Protocol Routing + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-proxy-prot-001` | `risk-gw-proxy-prot-001` | [tc-gw-proxy-prot-001](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md#tc-gw-proxy-prot-001) — Inbound Proxy Protocol v1/v2 parsing | P1 | +| `req-gw-proxy-prot-002` | `risk-gw-proxy-prot-002` | [tc-gw-proxy-prot-002](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md#tc-gw-proxy-prot-002) — Outbound Proxy Protocol per-port opt-in | P1 | +| `req-gw-proxy-prot-003` | `risk-gw-proxy-prot-003` | [tc-gw-proxy-prot-003](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md#tc-gw-proxy-prot-003) — TLS passthrough SNI address resolution | P1 | +| `req-gw-proxy-prot-004` | `risk-gw-proxy-prot-004` | [tc-gw-proxy-prot-004](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md#tc-gw-proxy-prot-004) — TLS termination routing and HTTP semantics | P1 | +| `req-gw-proxy-prot-005` | `risk-gw-proxy-prot-005` | [tc-gw-proxy-prot-005](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md#tc-gw-proxy-prot-005) — App-address namespace and content-addressed HTTPS | P0 | +| `req-gw-proxy-prot-006` | `risk-gw-proxy-prot-006` | [tc-gw-proxy-prot-006](04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md#tc-gw-proxy-prot-006) — Connection limits timeouts and recycling | P1 | +| `req-gw-select-007` | `risk-gw-select-007` | [tc-gw-select-007](04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md#tc-gw-select-007) — Top-N backend selection DNS cache and failover | P0 | + + +### Certificates Dns + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-certificat-001` | `risk-gw-certificat-001` | [tc-gw-certificat-001](04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md#tc-gw-certificat-001) — ACME account bootstrap and persistence | P1 | +| `req-gw-certificat-002` | `risk-gw-certificat-002` | [tc-gw-certificat-002](04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md#tc-gw-certificat-002) — Distributed certificate issue renew and lock | P1 | +| `req-gw-certificat-003` | `risk-gw-certificat-003` | [tc-gw-certificat-003](04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md#tc-gw-certificat-003) — DNS credential CRUD and default selection | P1 | +| `req-gw-certificat-004` | `risk-gw-certificat-004` | [tc-gw-certificat-004](04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md#tc-gw-certificat-004) — ZT domain CRUD and certificate lifecycle | P1 | +| `req-gw-certificat-005` | `risk-gw-certificat-005` | [tc-gw-certificat-005](04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md#tc-gw-certificat-005) — CAA publication and validation | P1 | +| `req-gw-certificat-006` | `risk-gw-certificat-006` | [tc-gw-certificat-006](04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md#tc-gw-certificat-006) — Certificate store SNI wildcard and hot reload | P1 | +| `req-gw-certificat-007` | `risk-gw-certificat-007` | [tc-gw-certificat-007](04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md#tc-gw-certificat-007) — Certificate attestation history and ACME info | P0 | + + +### Cluster Admin Observability + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-cluster-ad-001` | `risk-gw-cluster-ad-001` | [tc-gw-cluster-ad-001](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md#tc-gw-cluster-ad-001) — WaveKV bootstrap replication and convergence | P1 | +| `req-gw-cluster-ad-002` | `risk-gw-cluster-ad-002` | [tc-gw-cluster-ad-002](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md#tc-gw-cluster-ad-002) — WaveKV sync endpoint authentication and replay | P1 | +| `req-gw-cluster-ad-003` | `risk-gw-cluster-ad-003` | [tc-gw-cluster-ad-003](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md#tc-gw-cluster-ad-003) — Node URL and status administration | P1 | +| `req-gw-cluster-ad-004` | `risk-gw-cluster-ad-004` | [tc-gw-cluster-ad-004](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md#tc-gw-cluster-ad-004) — Connection handshake and node statistics | P1 | +| `req-gw-cluster-ad-005` | `risk-gw-cluster-ad-005` | [tc-gw-cluster-ad-005](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md#tc-gw-cluster-ad-005) — Admin authentication and listener isolation | P1 | +| `req-gw-cluster-ad-006` | `risk-gw-cluster-ad-006` | [tc-gw-cluster-ad-006](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md#tc-gw-cluster-ad-006) — Debug service isolation | P1 | +| `req-gw-cluster-ad-007` | `risk-gw-cluster-ad-007` | [tc-gw-cluster-ad-007](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md#tc-gw-cluster-ad-007) — Health dashboard and graceful exit | P1 | +| `req-gw-cluster-ad-008` | `risk-gw-cluster-ad-008` | [tc-gw-cluster-ad-008](04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md#tc-gw-cluster-ad-008) — TLS crypto provider and protocol matrix | P1 | +| `req-gw-kv-009` | `risk-gw-kv-009` | [tc-gw-kv-009](04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md#tc-gw-kv-009) — WaveKV key encoding corruption persistence and watch semantics | P0 | + + +### Startup, Authorization, and Routing Internals + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-internal-001` | `risk-gw-internal-001` | [tc-gw-internal-001](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md#tc-gw-internal-001) — Gateway startup certificate mode and resource limits | P0 | +| `req-gw-internal-002` | `risk-gw-internal-002` | [tc-gw-internal-002](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md#tc-gw-internal-002) — Gateway debug key generation artifact safety | P0 | +| `req-gw-internal-003` | `risk-gw-internal-003` | [tc-gw-internal-003](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md#tc-gw-internal-003) — Gateway authorization client allow deny and outage | P0 | +| `req-gw-internal-004` | `risk-gw-internal-004` | [tc-gw-internal-004](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md#tc-gw-internal-004) — Raw TLS ClientHello SNI parser boundaries | P0 | +| `req-gw-internal-005` | `risk-gw-internal-005` | [tc-gw-internal-005](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md#tc-gw-internal-005) — TLS termination local routes and stream bridge | P0 | +| `req-gw-internal-006` | `risk-gw-internal-006` | [tc-gw-internal-006](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md#tc-gw-internal-006) — Port-policy filtering fetch retry and PP decision | P0 | +| `req-gw-internal-007` | `risk-gw-internal-007` | [tc-gw-internal-007](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md#tc-gw-internal-007) — Dashboard connection counters and policy provenance | P1 | +| `req-gw-internal-008` | `risk-gw-internal-008` | [tc-gw-internal-008](04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md#tc-gw-internal-008) — Combined route index RPC exposure | P0 | + + +### Certbot ACME and DNS Engine + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-certbot-001` | `risk-gw-certbot-001` | [tc-gw-certbot-001](04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md#tc-gw-certbot-001) — ACME account creation load and credential persistence | P0 | +| `req-gw-certbot-002` | `risk-gw-certbot-002` | [tc-gw-certbot-002](04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md#tc-gw-certbot-002) — DNS-01 authorization propagation and cleanup | P0 | +| `req-gw-certbot-003` | `risk-gw-certbot-003` | [tc-gw-certbot-003](04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md#tc-gw-certbot-003) — Cloudflare DNS record API boundaries | P0 | +| `req-gw-certbot-004` | `risk-gw-certbot-004` | [tc-gw-certbot-004](04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md#tc-gw-certbot-004) — Certificate renewal threshold force and hook | P0 | +| `req-gw-certbot-005` | `risk-gw-certbot-005` | [tc-gw-certbot-005](04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md#tc-gw-certbot-005) — Certbot workdir archive live and rollback layout | P0 | +| `req-gw-certbot-006` | `risk-gw-certbot-006` | [tc-gw-certbot-006](04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md#tc-gw-certbot-006) — Certbot CLI once daemon config and signal lifecycle | P1 | + + +### Gateway, Certbot, Cluster Harness, and Existing Regression Suite + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-gw-build-001` | `risk-gw-build-001` | [tc-gw-build-001](04-gateway/10-gw-build/tc-gw-build-001/case.md#tc-gw-build-001) — Gateway, Certbot, Cluster Harness, and Existing Regression Suite | P0 | + + +## Verifier + + +### Input Platform Verification + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-input-plat-001` | `risk-ver-input-plat-001` | [tc-ver-input-plat-001](05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md#tc-ver-input-plat-001) — Verification input precedence and canonicalization | P1 | +| `req-ver-input-plat-002` | `risk-ver-input-plat-002` | [tc-ver-input-plat-002](05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md#tc-ver-input-plat-002) — TDX quote signature collateral and TCB | P0 | +| `req-ver-input-plat-003` | `risk-ver-input-plat-003` | [tc-ver-input-plat-003](05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md#tc-ver-input-plat-003) — TDX event log replay and RTMR status | P0 | +| `req-ver-input-plat-004` | `risk-ver-input-plat-004` | [tc-ver-input-plat-004](05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md#tc-ver-input-plat-004) — TDX-lite measurement verification | P0 | +| `req-ver-input-plat-005` | `risk-ver-input-plat-005` | [tc-ver-input-plat-005](05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md#tc-ver-input-plat-005) — SEV-SNP certificate and report verification | P0 | +| `req-ver-input-plat-006` | `risk-ver-input-plat-006` | [tc-ver-input-plat-006](05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md#tc-ver-input-plat-006) — Cloud TDX and Nitro TPM verification | P0 | +| `req-ver-input-plat-007` | `risk-ver-input-plat-007` | [tc-ver-input-plat-007](05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md#tc-ver-input-plat-007) — Simulated attestation labeling | P1 | +| `req-ver-nitro-008` | `risk-ver-nitro-008` | [tc-ver-nitro-008](05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md#tc-ver-nitro-008) — Nitro Enclave document verification and debug rejection | P0 | + + +### Image Measurements + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-image-meas-001` | `risk-ver-image-meas-001` | [tc-ver-image-meas-001](05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md#tc-ver-image-meas-001) — Image download digest and extraction security | P1 | +| `req-ver-image-meas-002` | `risk-ver-image-meas-002` | [tc-ver-image-meas-002](05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md#tc-ver-image-meas-002) — Measurement computation determinism | P1 | +| `req-ver-image-meas-003` | `risk-ver-image-meas-003` | [tc-ver-image-meas-003](05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md#tc-ver-image-meas-003) — ACPI table measurement and swtpm policy | P1 | +| `req-ver-image-meas-004` | `risk-ver-image-meas-004` | [tc-ver-image-meas-004](05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md#tc-ver-image-meas-004) — Artifact manifest and image hash binding | P1 | +| `req-ver-image-meas-005` | `risk-ver-image-meas-005` | [tc-ver-image-meas-005](05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md#tc-ver-image-meas-005) — Measurement cache correctness and concurrency | P1 | +| `req-ver-strategy-006` | `risk-ver-strategy-006` | [tc-ver-strategy-006](05-verifier/02-image-measurements/tc-ver-strategy-006/case.md#tc-ver-strategy-006) — Platform-specific OS image verification and download strategy | P0 | + + +### Cli Cert Output + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-cli-cert-o-001` | `risk-ver-cli-cert-o-001` | [tc-ver-cli-cert-o-001](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md#tc-ver-cli-cert-o-001) — One-shot JSON verification interface | P1 | +| `req-ver-cli-cert-o-002` | `risk-ver-cli-cert-o-002` | [tc-ver-cli-cert-o-002](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md#tc-ver-cli-cert-o-002) — Certificate RA extension verification | P0 | +| `req-ver-cli-cert-o-003` | `risk-ver-cli-cert-o-003` | [tc-ver-cli-cert-o-003](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md#tc-ver-cli-cert-o-003) — OS image hash verification modes | P1 | +| `req-ver-cli-cert-o-004` | `risk-ver-cli-cert-o-004` | [tc-ver-cli-cert-o-004](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md#tc-ver-cli-cert-o-004) — Result schema completeness and diagnostics | P1 | +| `req-ver-cli-cert-o-005` | `risk-ver-cli-cert-o-005` | [tc-ver-cli-cert-o-005](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md#tc-ver-cli-cert-o-005) — Configuration validation and trust roots | P1 | +| `req-ver-cli-cert-o-006` | `risk-ver-cli-cert-o-006` | [tc-ver-cli-cert-o-006](05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md#tc-ver-cli-cert-o-006) — Offline fixtures regression suite | P1 | +| `req-ver-tcb-007` | `risk-ver-tcb-007` | [tc-ver-tcb-007](05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md#tc-ver-tcb-007) — Canonical TCB status advisory and auth-policy projection | P0 | + + +### Measurement Tools and Library APIs + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-tools-001` | `risk-ver-tools-001` | [tc-ver-tools-001](05-verifier/04-measurement-tools/tc-ver-tools-001/case.md#tc-ver-tools-001) — dstack-mr supported platform CLI matrix | P0 | +| `req-ver-tools-002` | `risk-ver-tools-002` | [tc-ver-tools-002](05-verifier/04-measurement-tools/tc-ver-tools-002/case.md#tc-ver-tools-002) — dstack-mr boot artifact and cmdline boundaries | P0 | +| `req-ver-tools-003` | `risk-ver-tools-003` | [tc-ver-tools-003](05-verifier/04-measurement-tools/tc-ver-tools-003/case.md#tc-ver-tools-003) — Attestation encode decode round trip and versioning | P0 | +| `req-ver-tools-004` | `risk-ver-tools-004` | [tc-ver-tools-004](05-verifier/04-measurement-tools/tc-ver-tools-004/case.md#tc-ver-tools-004) — Verifier library concurrent API isolation | P1 | +| `req-ver-tools-005` | `risk-ver-tools-005` | [tc-ver-tools-005](05-verifier/04-measurement-tools/tc-ver-tools-005/case.md#tc-ver-tools-005) — Collateral and trust-root update lifecycle | P0 | +| `req-ver-tools-006` | `risk-ver-tools-006` | [tc-ver-tools-006](05-verifier/04-measurement-tools/tc-ver-tools-006/case.md#tc-ver-tools-006) — Verifier denial-of-service input limits | P0 | + + +### Verifier Build and Deployment + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-build-001` | `risk-ver-build-001` | [tc-ver-build-001](05-verifier/05-build-deployment/tc-ver-build-001/case.md#tc-ver-build-001) — Verifier image build pinning and runtime contents | P0 | +| `req-ver-build-002` | `risk-ver-build-002` | [tc-ver-build-002](05-verifier/05-build-deployment/tc-ver-build-002/case.md#tc-ver-build-002) — Verifier default configuration and CLI override precedence | P0 | + + +### Verifier and Measurement Tool Existing Regression Suite + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-ver-buildall-001` | `risk-ver-buildall-001` | [tc-ver-buildall-001](05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md#tc-ver-buildall-001) — Verifier and Measurement Tool Existing Regression Suite | P0 | + + +## Cross-component and Compatibility + + +### End To End + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-int-end-to-end-001` | `risk-int-end-to-end-001` | [tc-int-end-to-end-001](06-integration/01-end-to-end/tc-int-end-to-end-001/case.md#tc-int-end-to-end-001) — New application deployment trust chain | P0 | +| `req-int-end-to-end-002` | `risk-int-end-to-end-002` | [tc-int-end-to-end-002](06-integration/01-end-to-end/tc-int-end-to-end-002/case.md#tc-int-end-to-end-002) — Application upgrade trust continuity | P0 | +| `req-int-end-to-end-003` | `risk-int-end-to-end-003` | [tc-int-end-to-end-003](06-integration/01-end-to-end/tc-int-end-to-end-003/case.md#tc-int-end-to-end-003) — Encrypted environment delivery | P0 | +| `req-int-end-to-end-004` | `risk-int-end-to-end-004` | [tc-int-end-to-end-004](06-integration/01-end-to-end/tc-int-end-to-end-004/case.md#tc-int-end-to-end-004) — Gateway certificate attestation verification | P0 | +| `req-int-end-to-end-005` | `risk-int-end-to-end-005` | [tc-int-end-to-end-005](06-integration/01-end-to-end/tc-int-end-to-end-005/case.md#tc-int-end-to-end-005) — Multi-instance load balancing and isolation | P0 | + + +### Compatibility Upgrade + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-int-compatibil-001` | `risk-int-compatibil-001` | [tc-int-compatibil-001](06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md#tc-int-compatibil-001) — Persisted state migration from v0.5.4, v0.5.8, and v0.5.11 | P0 | +| `req-int-compatibil-002` | `risk-int-compatibil-002` | [tc-int-compatibil-002](06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md#tc-int-compatibil-002) — Rolling VMM upgrade with running mixed guests | P0 | +| `req-int-compatibil-003` | `risk-int-compatibil-003` | [tc-int-compatibil-003](06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md#tc-int-compatibil-003) — Rolling KMS cluster upgrade and key continuity | P0 | +| `req-int-compatibil-004` | `risk-int-compatibil-004` | [tc-int-compatibil-004](06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md#tc-int-compatibil-004) — Rolling gateway cluster upgrade | P0 | +| `req-int-compatibil-005` | `risk-int-compatibil-005` | [tc-int-compatibil-005](06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md#tc-int-compatibil-005) — Verifier compatibility across evidence versions | P0 | +| `req-int-compatibil-006` | `risk-int-compatibil-006` | [tc-int-compatibil-006](06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md#tc-int-compatibil-006) — RPC unknown-field and optional-field compatibility | P0 | + + +### Failure Security + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-int-failure-se-001` | `risk-int-failure-se-001` | [tc-int-failure-se-001](06-integration/03-failure-security/tc-int-failure-se-001/case.md#tc-int-failure-se-001) — KMS unavailable during boot and recovery | P0 | +| `req-int-failure-se-002` | `risk-int-failure-se-002` | [tc-int-failure-se-002](06-integration/03-failure-security/tc-int-failure-se-002/case.md#tc-int-failure-se-002) — Gateway unavailable registration and recovery | P0 | +| `req-int-failure-se-003` | `risk-int-failure-se-003` | [tc-int-failure-se-003](06-integration/03-failure-security/tc-int-failure-se-003/case.md#tc-int-failure-se-003) — VMM crash during every lifecycle transaction | P0 | +| `req-int-failure-se-004` | `risk-int-failure-se-004` | [tc-int-failure-se-004](06-integration/03-failure-security/tc-int-failure-se-004/case.md#tc-int-failure-se-004) — Certificate and clock boundary behavior | P0 | +| `req-int-failure-se-005` | `risk-int-failure-se-005` | [tc-int-failure-se-005](06-integration/03-failure-security/tc-int-failure-se-005/case.md#tc-int-failure-se-005) — Credential and secret redaction audit | P0 | +| `req-int-failure-se-006` | `risk-int-failure-se-006` | [tc-int-failure-se-006](06-integration/03-failure-security/tc-int-failure-se-006/case.md#tc-int-failure-se-006) — Resource exhaustion and backpressure | P0 | +| `req-int-failure-se-007` | `risk-int-failure-se-007` | [tc-int-failure-se-007](06-integration/03-failure-security/tc-int-failure-se-007/case.md#tc-int-failure-se-007) — Network partition consistency matrix | P0 | +| `req-int-failure-se-008` | `risk-int-failure-se-008` | [tc-int-failure-se-008](06-integration/03-failure-security/tc-int-failure-se-008/case.md#tc-int-failure-se-008) — Simulator versus hardware evidence separation | P0 | + + +### Pinned Mixed-Version Online Matrix + +| Requirement | Risk | Case | Priority | +|---|---|---|---| +| `req-int-mixed-001` | `risk-int-mixed-001` | [tc-int-mixed-001](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md#tc-int-mixed-001) — Latest VMM hosts the full pinned guest matrix | P0 | +| `req-int-mixed-002` | `risk-int-mixed-002` | [tc-int-mixed-002](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md#tc-int-mixed-002) — Mixed KMS versions remain online during application operations | P0 | +| `req-int-mixed-003` | `risk-int-mixed-003` | [tc-int-mixed-003](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md#tc-int-mixed-003) — Mixed gateway versions route old and new guests | P0 | +| `req-int-mixed-004` | `risk-int-mixed-004` | [tc-int-mixed-004](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md#tc-int-mixed-004) — Gateway replacement matrix after KMS cutover | P0 | +| `req-int-mixed-005` | `risk-int-mixed-005` | [tc-int-mixed-005](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md#tc-int-mixed-005) — Verifier evidence compatibility for pinned releases | P0 | +| `req-int-mixed-006` | `risk-int-mixed-006` | [tc-int-mixed-006](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md#tc-int-mixed-006) — Rolling restart under four-version online mix | P0 | +| `req-int-mixed-007` | `risk-int-mixed-007` | [tc-int-mixed-007](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md#tc-int-mixed-007) — Optional and unknown protobuf fields across pinned versions | P0 | + diff --git a/docs/test-plans/core-components-full/index.json b/docs/test-plans/core-components-full/index.json new file mode 100644 index 000000000..d2ede72d4 --- /dev/null +++ b/docs/test-plans/core-components-full/index.json @@ -0,0 +1,8086 @@ +{ + "schema_version": "1.0", + "id": "dstack-core-components-full", + "title": "dstack Core Components Full Test Plan", + "guide": { + "path": "README.md", + "anchor": "core-components-test-guide" + }, + "chapters": [ + { + "id": "chapter-guest-os", + "title": "Guest OS", + "order": 1, + "path": "01-guest-os", + "sections": [ + { + "id": "section-guest-os-rpc-tappd", + "title": "Tappd RPC", + "order": 1, + "path": "01-guest-os/01-rpc-tappd", + "cases": [ + { + "id": "tc-gos-tappd-001", + "title": "Tappd.DeriveKey", + "order": 1, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-001", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-001/case.md", + "anchor": "tc-gos-tappd-001" + }, + "requirements": [ + "req-gos-tappd-001" + ], + "risks": [ + "risk-gos-tappd-001" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + }, + { + "id": "tc-gos-tappd-002", + "title": "Tappd.DeriveK256Key", + "order": 2, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-002", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-002/case.md", + "anchor": "tc-gos-tappd-002" + }, + "requirements": [ + "req-gos-tappd-002" + ], + "risks": [ + "risk-gos-tappd-002" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + }, + { + "id": "tc-gos-tappd-003", + "title": "Tappd.TdxQuote", + "order": 3, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-003", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-003/case.md", + "anchor": "tc-gos-tappd-003" + }, + "requirements": [ + "req-gos-tappd-003" + ], + "risks": [ + "risk-gos-tappd-003" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + }, + { + "id": "tc-gos-tappd-004", + "title": "Tappd.RawQuote", + "order": 4, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-004", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-004/case.md", + "anchor": "tc-gos-tappd-004" + }, + "requirements": [ + "req-gos-tappd-004" + ], + "risks": [ + "risk-gos-tappd-004" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + }, + { + "id": "tc-gos-tappd-005", + "title": "Tappd.Info", + "order": 5, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-005", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-005/case.md", + "anchor": "tc-gos-tappd-005" + }, + "requirements": [ + "req-gos-tappd-005" + ], + "risks": [ + "risk-gos-tappd-005" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + }, + { + "id": "tc-gos-tappd-006", + "title": "Tappd.Version", + "order": 6, + "priority": "P1", + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-006", + "spec": { + "path": "01-guest-os/01-rpc-tappd/tc-gos-tappd-006/case.md", + "anchor": "tc-gos-tappd-006" + }, + "requirements": [ + "req-gos-tappd-006" + ], + "risks": [ + "risk-gos-tappd-006" + ], + "tags": [ + "guest", + "tappd-rpc" + ] + } + ] + }, + { + "id": "section-guest-os-rpc-dstackguest", + "title": "DstackGuest RPC", + "order": 2, + "path": "01-guest-os/02-rpc-dstackguest", + "cases": [ + { + "id": "tc-gos-dstackguest-001", + "title": "DstackGuest.GetTlsKey", + "order": 1, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-001/case.md", + "anchor": "tc-gos-dstackguest-001" + }, + "requirements": [ + "req-gos-dstackguest-001" + ], + "risks": [ + "risk-gos-dstackguest-001" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-002", + "title": "DstackGuest.GetKey", + "order": 2, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-002/case.md", + "anchor": "tc-gos-dstackguest-002" + }, + "requirements": [ + "req-gos-dstackguest-002" + ], + "risks": [ + "risk-gos-dstackguest-002" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-003", + "title": "DstackGuest.GetQuote", + "order": 3, + "priority": "P0", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-003/case.md", + "anchor": "tc-gos-dstackguest-003" + }, + "requirements": [ + "req-gos-dstackguest-003" + ], + "risks": [ + "risk-gos-dstackguest-003" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-004", + "title": "DstackGuest.Attest", + "order": 4, + "priority": "P0", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-004/case.md", + "anchor": "tc-gos-dstackguest-004" + }, + "requirements": [ + "req-gos-dstackguest-004" + ], + "risks": [ + "risk-gos-dstackguest-004" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-005", + "title": "DstackGuest.Info", + "order": 5, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-005/case.md", + "anchor": "tc-gos-dstackguest-005" + }, + "requirements": [ + "req-gos-dstackguest-005" + ], + "risks": [ + "risk-gos-dstackguest-005" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-006", + "title": "DstackGuest.GpuInfo", + "order": 6, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-006/case.md", + "anchor": "tc-gos-dstackguest-006" + }, + "requirements": [ + "req-gos-dstackguest-006" + ], + "risks": [ + "risk-gos-dstackguest-006" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-007", + "title": "DstackGuest.Sign", + "order": 7, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-007/case.md", + "anchor": "tc-gos-dstackguest-007" + }, + "requirements": [ + "req-gos-dstackguest-007" + ], + "risks": [ + "risk-gos-dstackguest-007" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-008", + "title": "DstackGuest.Verify", + "order": 8, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-008/case.md", + "anchor": "tc-gos-dstackguest-008" + }, + "requirements": [ + "req-gos-dstackguest-008" + ], + "risks": [ + "risk-gos-dstackguest-008" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + }, + { + "id": "tc-gos-dstackguest-009", + "title": "DstackGuest.Version", + "order": 9, + "priority": "P1", + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009", + "spec": { + "path": "01-guest-os/02-rpc-dstackguest/tc-gos-dstackguest-009/case.md", + "anchor": "tc-gos-dstackguest-009" + }, + "requirements": [ + "req-gos-dstackguest-009" + ], + "risks": [ + "risk-gos-dstackguest-009" + ], + "tags": [ + "guest", + "dstackguest-rpc" + ] + } + ] + }, + { + "id": "section-guest-os-rpc-worker", + "title": "Worker RPC", + "order": 3, + "path": "01-guest-os/03-rpc-worker", + "cases": [ + { + "id": "tc-gos-worker-001", + "title": "Worker.Info", + "order": 1, + "priority": "P1", + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-001", + "spec": { + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-001/case.md", + "anchor": "tc-gos-worker-001" + }, + "requirements": [ + "req-gos-worker-001" + ], + "risks": [ + "risk-gos-worker-001" + ], + "tags": [ + "guest", + "worker-rpc" + ] + }, + { + "id": "tc-gos-worker-002", + "title": "Worker.Version", + "order": 2, + "priority": "P1", + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-002", + "spec": { + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-002/case.md", + "anchor": "tc-gos-worker-002" + }, + "requirements": [ + "req-gos-worker-002" + ], + "risks": [ + "risk-gos-worker-002" + ], + "tags": [ + "guest", + "worker-rpc" + ] + }, + { + "id": "tc-gos-worker-003", + "title": "Worker.GetAttestationForAppKey", + "order": 3, + "priority": "P1", + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-003", + "spec": { + "path": "01-guest-os/03-rpc-worker/tc-gos-worker-003/case.md", + "anchor": "tc-gos-worker-003" + }, + "requirements": [ + "req-gos-worker-003" + ], + "risks": [ + "risk-gos-worker-003" + ], + "tags": [ + "guest", + "worker-rpc" + ] + } + ] + }, + { + "id": "section-guest-os-rpc-guestapi", + "title": "GuestApi RPC", + "order": 4, + "path": "01-guest-os/04-rpc-guestapi", + "cases": [ + { + "id": "tc-gos-guestapi-001", + "title": "GuestApi.Info", + "order": 1, + "priority": "P1", + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001", + "spec": { + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-001/case.md", + "anchor": "tc-gos-guestapi-001" + }, + "requirements": [ + "req-gos-guestapi-001" + ], + "risks": [ + "risk-gos-guestapi-001" + ], + "tags": [ + "guest", + "guestapi-rpc" + ] + }, + { + "id": "tc-gos-guestapi-002", + "title": "GuestApi.SysInfo", + "order": 2, + "priority": "P1", + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002", + "spec": { + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-002/case.md", + "anchor": "tc-gos-guestapi-002" + }, + "requirements": [ + "req-gos-guestapi-002" + ], + "risks": [ + "risk-gos-guestapi-002" + ], + "tags": [ + "guest", + "guestapi-rpc" + ] + }, + { + "id": "tc-gos-guestapi-003", + "title": "GuestApi.NetworkInfo", + "order": 3, + "priority": "P1", + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003", + "spec": { + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-003/case.md", + "anchor": "tc-gos-guestapi-003" + }, + "requirements": [ + "req-gos-guestapi-003" + ], + "risks": [ + "risk-gos-guestapi-003" + ], + "tags": [ + "guest", + "guestapi-rpc" + ] + }, + { + "id": "tc-gos-guestapi-004", + "title": "GuestApi.ListContainers", + "order": 4, + "priority": "P1", + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004", + "spec": { + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-004/case.md", + "anchor": "tc-gos-guestapi-004" + }, + "requirements": [ + "req-gos-guestapi-004" + ], + "risks": [ + "risk-gos-guestapi-004" + ], + "tags": [ + "guest", + "guestapi-rpc" + ] + }, + { + "id": "tc-gos-guestapi-005", + "title": "GuestApi.Shutdown", + "order": 5, + "priority": "P1", + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005", + "spec": { + "path": "01-guest-os/04-rpc-guestapi/tc-gos-guestapi-005/case.md", + "anchor": "tc-gos-guestapi-005" + }, + "requirements": [ + "req-gos-guestapi-005" + ], + "risks": [ + "risk-gos-guestapi-005" + ], + "tags": [ + "guest", + "guestapi-rpc" + ] + } + ] + }, + { + "id": "section-guest-os-rpc-proxiedguestapi", + "title": "ProxiedGuestApi RPC", + "order": 5, + "path": "01-guest-os/05-rpc-proxiedguestapi", + "cases": [ + { + "id": "tc-gos-proxiedguestapi-001", + "title": "ProxiedGuestApi.Info", + "order": 1, + "priority": "P1", + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001", + "spec": { + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-001/case.md", + "anchor": "tc-gos-proxiedguestapi-001" + }, + "requirements": [ + "req-gos-proxiedguestapi-001" + ], + "risks": [ + "risk-gos-proxiedguestapi-001" + ], + "tags": [ + "guest", + "proxiedguestapi-rpc" + ] + }, + { + "id": "tc-gos-proxiedguestapi-002", + "title": "ProxiedGuestApi.SysInfo", + "order": 2, + "priority": "P1", + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002", + "spec": { + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-002/case.md", + "anchor": "tc-gos-proxiedguestapi-002" + }, + "requirements": [ + "req-gos-proxiedguestapi-002" + ], + "risks": [ + "risk-gos-proxiedguestapi-002" + ], + "tags": [ + "guest", + "proxiedguestapi-rpc" + ] + }, + { + "id": "tc-gos-proxiedguestapi-003", + "title": "ProxiedGuestApi.NetworkInfo", + "order": 3, + "priority": "P1", + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003", + "spec": { + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-003/case.md", + "anchor": "tc-gos-proxiedguestapi-003" + }, + "requirements": [ + "req-gos-proxiedguestapi-003" + ], + "risks": [ + "risk-gos-proxiedguestapi-003" + ], + "tags": [ + "guest", + "proxiedguestapi-rpc" + ] + }, + { + "id": "tc-gos-proxiedguestapi-004", + "title": "ProxiedGuestApi.ListContainers", + "order": 4, + "priority": "P1", + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004", + "spec": { + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-004/case.md", + "anchor": "tc-gos-proxiedguestapi-004" + }, + "requirements": [ + "req-gos-proxiedguestapi-004" + ], + "risks": [ + "risk-gos-proxiedguestapi-004" + ], + "tags": [ + "guest", + "proxiedguestapi-rpc" + ] + }, + { + "id": "tc-gos-proxiedguestapi-005", + "title": "ProxiedGuestApi.Shutdown", + "order": 5, + "priority": "P1", + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005", + "spec": { + "path": "01-guest-os/05-rpc-proxiedguestapi/tc-gos-proxiedguestapi-005/case.md", + "anchor": "tc-gos-proxiedguestapi-005" + }, + "requirements": [ + "req-gos-proxiedguestapi-005" + ], + "risks": [ + "risk-gos-proxiedguestapi-005" + ], + "tags": [ + "guest", + "proxiedguestapi-rpc" + ] + } + ] + }, + { + "id": "section-guest-os-boot-and-identity", + "title": "Boot And Identity", + "order": 6, + "path": "01-guest-os/06-boot-and-identity", + "cases": [ + { + "id": "tc-gos-boot-and-i-001", + "title": "Measured boot and prepare ordering", + "order": 1, + "priority": "P0", + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001", + "spec": { + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-001/case.md", + "anchor": "tc-gos-boot-and-i-001" + }, + "requirements": [ + "req-gos-boot-and-i-001" + ], + "risks": [ + "risk-gos-boot-and-i-001" + ], + "tags": [ + "guest", + "boot-and-identity" + ] + }, + { + "id": "tc-gos-boot-and-i-002", + "title": "No-TEE simulator early host share", + "order": 2, + "priority": "P1", + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002", + "spec": { + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-002/case.md", + "anchor": "tc-gos-boot-and-i-002" + }, + "requirements": [ + "req-gos-boot-and-i-002" + ], + "risks": [ + "risk-gos-boot-and-i-002" + ], + "tags": [ + "guest", + "boot-and-identity" + ] + }, + { + "id": "tc-gos-boot-and-i-003", + "title": "System and user configuration materialization", + "order": 3, + "priority": "P1", + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003", + "spec": { + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-003/case.md", + "anchor": "tc-gos-boot-and-i-003" + }, + "requirements": [ + "req-gos-boot-and-i-003" + ], + "risks": [ + "risk-gos-boot-and-i-003" + ], + "tags": [ + "guest", + "boot-and-identity" + ] + }, + { + "id": "tc-gos-boot-and-i-004", + "title": "Stable app, instance, device, and compose identity", + "order": 4, + "priority": "P0", + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004", + "spec": { + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-004/case.md", + "anchor": "tc-gos-boot-and-i-004" + }, + "requirements": [ + "req-gos-boot-and-i-004" + ], + "risks": [ + "risk-gos-boot-and-i-004" + ], + "tags": [ + "guest", + "boot-and-identity" + ] + }, + { + "id": "tc-gos-boot-and-i-005", + "title": "Host notification boot and shutdown events", + "order": 5, + "priority": "P1", + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005", + "spec": { + "path": "01-guest-os/06-boot-and-identity/tc-gos-boot-and-i-005/case.md", + "anchor": "tc-gos-boot-and-i-005" + }, + "requirements": [ + "req-gos-boot-and-i-005" + ], + "risks": [ + "risk-gos-boot-and-i-005" + ], + "tags": [ + "guest", + "boot-and-identity" + ] + } + ] + }, + { + "id": "section-guest-os-storage-and-containers", + "title": "Storage And Containers", + "order": 7, + "path": "01-guest-os/07-storage-and-containers", + "cases": [ + { + "id": "tc-gos-storage-an-001", + "title": "Encrypted root/data volume provisioning", + "order": 1, + "priority": "P0", + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-001", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-001/case.md", + "anchor": "tc-gos-storage-an-001" + }, + "requirements": [ + "req-gos-storage-an-001" + ], + "risks": [ + "risk-gos-storage-an-001" + ], + "tags": [ + "guest", + "storage-and-containers" + ] + }, + { + "id": "tc-gos-storage-an-002", + "title": "Ephemeral Docker storage lifecycle", + "order": 2, + "priority": "P1", + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-002", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-002/case.md", + "anchor": "tc-gos-storage-an-002" + }, + "requirements": [ + "req-gos-storage-an-002" + ], + "risks": [ + "risk-gos-storage-an-002" + ], + "tags": [ + "guest", + "storage-and-containers" + ] + }, + { + "id": "tc-gos-storage-an-003", + "title": "Compose validation and startup", + "order": 3, + "priority": "P1", + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-003", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-003/case.md", + "anchor": "tc-gos-storage-an-003" + }, + "requirements": [ + "req-gos-storage-an-003" + ], + "risks": [ + "risk-gos-storage-an-003" + ], + "tags": [ + "guest", + "storage-and-containers" + ] + }, + { + "id": "tc-gos-storage-an-004", + "title": "Supervisor lifecycle and restart policy", + "order": 4, + "priority": "P1", + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-004", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-004/case.md", + "anchor": "tc-gos-storage-an-004" + }, + "requirements": [ + "req-gos-storage-an-004" + ], + "risks": [ + "risk-gos-storage-an-004" + ], + "tags": [ + "guest", + "storage-and-containers" + ] + }, + { + "id": "tc-gos-storage-an-005", + "title": "Volume encryption and persistence semantics", + "order": 5, + "priority": "P0", + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-005", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-storage-an-005/case.md", + "anchor": "tc-gos-storage-an-005" + }, + "requirements": [ + "req-gos-storage-an-005" + ], + "risks": [ + "risk-gos-storage-an-005" + ], + "tags": [ + "guest", + "storage-and-containers" + ] + }, + { + "id": "tc-gos-compose-006", + "title": "App manifest version feature and launch-requirement policy", + "order": 6, + "priority": "P0", + "path": "01-guest-os/07-storage-and-containers/tc-gos-compose-006", + "spec": { + "path": "01-guest-os/07-storage-and-containers/tc-gos-compose-006/case.md", + "anchor": "tc-gos-compose-006" + }, + "requirements": [ + "req-gos-compose-006" + ], + "risks": [ + "risk-gos-compose-006" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-guest-os-attestation-and-crypto", + "title": "Attestation And Crypto", + "order": 8, + "path": "01-guest-os/08-attestation-and-crypto", + "cases": [ + { + "id": "tc-gos-attestatio-001", + "title": "Quote report-data binding and hash algorithms", + "order": 1, + "priority": "P0", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-001/case.md", + "anchor": "tc-gos-attestatio-001" + }, + "requirements": [ + "req-gos-attestatio-001" + ], + "risks": [ + "risk-gos-attestatio-001" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-attestatio-002", + "title": "Cross-platform versioned attestation", + "order": 2, + "priority": "P0", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-002/case.md", + "anchor": "tc-gos-attestatio-002" + }, + "requirements": [ + "req-gos-attestatio-002" + ], + "risks": [ + "risk-gos-attestatio-002" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-attestatio-003", + "title": "Deterministic key derivation and purpose separation", + "order": 3, + "priority": "P1", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-003/case.md", + "anchor": "tc-gos-attestatio-003" + }, + "requirements": [ + "req-gos-attestatio-003" + ], + "risks": [ + "risk-gos-attestatio-003" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-attestatio-004", + "title": "TLS key and certificate usage extensions", + "order": 4, + "priority": "P0", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-004/case.md", + "anchor": "tc-gos-attestatio-004" + }, + "requirements": [ + "req-gos-attestatio-004" + ], + "risks": [ + "risk-gos-attestatio-004" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-attestatio-005", + "title": "Signing verification and negative inputs", + "order": 5, + "priority": "P1", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-005/case.md", + "anchor": "tc-gos-attestatio-005" + }, + "requirements": [ + "req-gos-attestatio-005" + ], + "risks": [ + "risk-gos-attestatio-005" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-attestatio-006", + "title": "GPU boot attestation exposure", + "order": 6, + "priority": "P0", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-attestatio-006/case.md", + "anchor": "tc-gos-attestatio-006" + }, + "requirements": [ + "req-gos-attestatio-006" + ], + "risks": [ + "risk-gos-attestatio-006" + ], + "tags": [ + "guest", + "attestation-and-crypto" + ] + }, + { + "id": "tc-gos-gpupolicy-007", + "title": "GPU attestation proxy nonce claim and Rego policy enforcement", + "order": 7, + "priority": "P0", + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007", + "spec": { + "path": "01-guest-os/08-attestation-and-crypto/tc-gos-gpupolicy-007/case.md", + "anchor": "tc-gos-gpupolicy-007" + }, + "requirements": [ + "req-gos-gpupolicy-007" + ], + "risks": [ + "risk-gos-gpupolicy-007" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-guest-os-observability-and-network", + "title": "Observability And Network", + "order": 9, + "path": "01-guest-os/09-observability-and-network", + "cases": [ + { + "id": "tc-gos-observabil-001", + "title": "Dashboard metrics and container log filtering", + "order": 1, + "priority": "P1", + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-001", + "spec": { + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-001/case.md", + "anchor": "tc-gos-observabil-001" + }, + "requirements": [ + "req-gos-observabil-001" + ], + "risks": [ + "risk-gos-observabil-001" + ], + "tags": [ + "guest", + "observability-and-network" + ] + }, + { + "id": "tc-gos-observabil-002", + "title": "Socket activation and listener isolation", + "order": 2, + "priority": "P1", + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-002", + "spec": { + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-002/case.md", + "anchor": "tc-gos-observabil-002" + }, + "requirements": [ + "req-gos-observabil-002" + ], + "risks": [ + "risk-gos-observabil-002" + ], + "tags": [ + "guest", + "observability-and-network" + ] + }, + { + "id": "tc-gos-observabil-003", + "title": "WireGuard configuration and checker recovery", + "order": 3, + "priority": "P1", + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-003", + "spec": { + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-003/case.md", + "anchor": "tc-gos-observabil-003" + }, + "requirements": [ + "req-gos-observabil-003" + ], + "risks": [ + "risk-gos-observabil-003" + ], + "tags": [ + "guest", + "observability-and-network" + ] + }, + { + "id": "tc-gos-observabil-004", + "title": "System network and resource telemetry", + "order": 4, + "priority": "P1", + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-004", + "spec": { + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-004/case.md", + "anchor": "tc-gos-observabil-004" + }, + "requirements": [ + "req-gos-observabil-004" + ], + "risks": [ + "risk-gos-observabil-004" + ], + "tags": [ + "guest", + "observability-and-network" + ] + }, + { + "id": "tc-gos-observabil-005", + "title": "Guest-agent watchdog recovery", + "order": 5, + "priority": "P1", + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-005", + "spec": { + "path": "01-guest-os/09-observability-and-network/tc-gos-observabil-005/case.md", + "anchor": "tc-gos-observabil-005" + }, + "requirements": [ + "req-gos-observabil-005" + ], + "risks": [ + "risk-gos-observabil-005" + ], + "tags": [ + "guest", + "observability-and-network" + ] + } + ] + }, + { + "id": "section-guest-os-platform-services", + "title": "Platform Services and Image Integrity", + "order": 10, + "path": "01-guest-os/10-platform-services", + "cases": [ + { + "id": "tc-gos-platform-001", + "title": "Local key provider TPM mode and PCCS lifecycle", + "order": 1, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-001", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-001/case.md", + "anchor": "tc-gos-platform-001" + }, + "requirements": [ + "req-gos-platform-001" + ], + "risks": [ + "risk-gos-platform-001" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-002", + "title": "Local key provider sealing and identity isolation", + "order": 2, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-002", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-002/case.md", + "anchor": "tc-gos-platform-002" + }, + "requirements": [ + "req-gos-platform-002" + ], + "risks": [ + "risk-gos-platform-002" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-003", + "title": "Host-shared mount and unmount command", + "order": 3, + "priority": "P1", + "path": "01-guest-os/10-platform-services/tc-gos-platform-003", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-003/case.md", + "anchor": "tc-gos-platform-003" + }, + "requirements": [ + "req-gos-platform-003" + ], + "risks": [ + "risk-gos-platform-003" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-004", + "title": "Guest image reproducible assembly and manifest", + "order": 4, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-004", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-004/case.md", + "anchor": "tc-gos-platform-004" + }, + "requirements": [ + "req-gos-platform-004" + ], + "risks": [ + "risk-gos-platform-004" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-005", + "title": "Guest kernel and userspace hardening", + "order": 5, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-005", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-005/case.md", + "anchor": "tc-gos-platform-005" + }, + "requirements": [ + "req-gos-platform-005" + ], + "risks": [ + "risk-gos-platform-005" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-006", + "title": "Systemd dependency and failure-action graph", + "order": 6, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-006", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-006/case.md", + "anchor": "tc-gos-platform-006" + }, + "requirements": [ + "req-gos-platform-006" + ], + "risks": [ + "risk-gos-platform-006" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-007", + "title": "Journal persistence rotation and redaction", + "order": 7, + "priority": "P1", + "path": "01-guest-os/10-platform-services/tc-gos-platform-007", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-007/case.md", + "anchor": "tc-gos-platform-007" + }, + "requirements": [ + "req-gos-platform-007" + ], + "risks": [ + "risk-gos-platform-007" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-008", + "title": "Docker daemon and container privilege boundary", + "order": 8, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-008", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-008/case.md", + "anchor": "tc-gos-platform-008" + }, + "requirements": [ + "req-gos-platform-008" + ], + "risks": [ + "risk-gos-platform-008" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-009", + "title": "NVIDIA device initialization and attestation failure", + "order": 9, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-009", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-009/case.md", + "anchor": "tc-gos-platform-009" + }, + "requirements": [ + "req-gos-platform-009" + ], + "risks": [ + "risk-gos-platform-009" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + }, + { + "id": "tc-gos-platform-010", + "title": "Guest configuration backward and forward compatibility", + "order": 10, + "priority": "P0", + "path": "01-guest-os/10-platform-services/tc-gos-platform-010", + "spec": { + "path": "01-guest-os/10-platform-services/tc-gos-platform-010/case.md", + "anchor": "tc-gos-platform-010" + }, + "requirements": [ + "req-gos-platform-010" + ], + "risks": [ + "risk-gos-platform-010" + ], + "tags": [ + "gos", + "platform-services-and-image-integrity" + ] + } + ] + }, + { + "id": "section-guest-os-configuration-entry-models", + "title": "Configuration, Entry Points, and Presentation Models", + "order": 11, + "path": "01-guest-os/11-configuration-entry-models", + "cases": [ + { + "id": "tc-gos-entry-001", + "title": "Guest-agent configuration precedence and compose deserialization", + "order": 1, + "priority": "P0", + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-001", + "spec": { + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-001/case.md", + "anchor": "tc-gos-entry-001" + }, + "requirements": [ + "req-gos-entry-001" + ], + "risks": [ + "risk-gos-entry-001" + ], + "tags": [ + "gos", + "configuration-entry-points-and-presentation-models" + ] + }, + { + "id": "tc-gos-entry-002", + "title": "Guest-agent startup modes and partial listener failure", + "order": 2, + "priority": "P0", + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-002", + "spec": { + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-002/case.md", + "anchor": "tc-gos-entry-002" + }, + "requirements": [ + "req-gos-entry-002" + ], + "risks": [ + "risk-gos-entry-002" + ], + "tags": [ + "gos", + "configuration-entry-points-and-presentation-models" + ] + }, + { + "id": "tc-gos-entry-003", + "title": "Dashboard and metrics model escaping and units", + "order": 3, + "priority": "P1", + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-003", + "spec": { + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-003/case.md", + "anchor": "tc-gos-entry-003" + }, + "requirements": [ + "req-gos-entry-003" + ], + "risks": [ + "risk-gos-entry-003" + ], + "tags": [ + "gos", + "configuration-entry-points-and-presentation-models" + ] + }, + { + "id": "tc-gos-entry-004", + "title": "Guest-agent library initialization reuse", + "order": 4, + "priority": "P1", + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-004", + "spec": { + "path": "01-guest-os/11-configuration-entry-models/tc-gos-entry-004/case.md", + "anchor": "tc-gos-entry-004" + }, + "requirements": [ + "req-gos-entry-004" + ], + "risks": [ + "risk-gos-entry-004" + ], + "tags": [ + "gos", + "configuration-entry-points-and-presentation-models" + ] + } + ] + }, + { + "id": "section-guest-os-setup-utilities-simulator", + "title": "System Setup Utilities and TEE Simulator", + "order": 12, + "path": "01-guest-os/12-setup-utilities-simulator", + "cases": [ + { + "id": "tc-gos-setup-001", + "title": "Environment JSON allowlist parsing", + "order": 1, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-001/case.md", + "anchor": "tc-gos-setup-001" + }, + "requirements": [ + "req-gos-setup-001" + ], + "risks": [ + "risk-gos-setup-001" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-002", + "title": "Encrypted environment ECDH decryption", + "order": 2, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-002/case.md", + "anchor": "tc-gos-setup-002" + }, + "requirements": [ + "req-gos-setup-002" + ], + "risks": [ + "risk-gos-setup-002" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-003", + "title": "Compose inspection and orphan removal", + "order": 3, + "priority": "P1", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-003/case.md", + "anchor": "tc-gos-setup-003" + }, + "requirements": [ + "req-gos-setup-003" + ], + "risks": [ + "risk-gos-setup-003" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-004", + "title": "Staged system setup idempotence and config identity", + "order": 4, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-004/case.md", + "anchor": "tc-gos-setup-004" + }, + "requirements": [ + "req-gos-setup-004" + ], + "risks": [ + "risk-gos-setup-004" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-005", + "title": "MR config ID verification before provisioning", + "order": 5, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-005/case.md", + "anchor": "tc-gos-setup-005" + }, + "requirements": [ + "req-gos-setup-005" + ], + "risks": [ + "risk-gos-setup-005" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-006", + "title": "KMS URL selection failover and local-provider orthogonality", + "order": 6, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-006/case.md", + "anchor": "tc-gos-setup-006" + }, + "requirements": [ + "req-gos-setup-006" + ], + "risks": [ + "risk-gos-setup-006" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-007", + "title": "Data disk encryption filesystem repair and mount", + "order": 7, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-007/case.md", + "anchor": "tc-gos-setup-007" + }, + "requirements": [ + "req-gos-setup-007" + ], + "risks": [ + "risk-gos-setup-007" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-008", + "title": "Swap file and ZFS zvol setup", + "order": 8, + "priority": "P1", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-008/case.md", + "anchor": "tc-gos-setup-008" + }, + "requirements": [ + "req-gos-setup-008" + ], + "risks": [ + "risk-gos-setup-008" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-009", + "title": "Gateway registration refresh and key-store persistence", + "order": 9, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-009/case.md", + "anchor": "tc-gos-setup-009" + }, + "requirements": [ + "req-gos-setup-009" + ], + "risks": [ + "risk-gos-setup-009" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-010", + "title": "Host API notify and sealing-key client", + "order": 10, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-010/case.md", + "anchor": "tc-gos-setup-010" + }, + "requirements": [ + "req-gos-setup-010" + ], + "risks": [ + "risk-gos-setup-010" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-011", + "title": "GPU measurement in system setup", + "order": 11, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-011/case.md", + "anchor": "tc-gos-setup-011" + }, + "requirements": [ + "req-gos-setup-011" + ], + "risks": [ + "risk-gos-setup-011" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-012", + "title": "Supervisor client full API and auto-start", + "order": 12, + "priority": "P1", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-012/case.md", + "anchor": "tc-gos-setup-012" + }, + "requirements": [ + "req-gos-setup-012" + ], + "risks": [ + "risk-gos-setup-012" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-013", + "title": "TDX simulator device ABI", + "order": 13, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-013/case.md", + "anchor": "tc-gos-setup-013" + }, + "requirements": [ + "req-gos-setup-013" + ], + "risks": [ + "risk-gos-setup-013" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-014", + "title": "SEV-SNP simulator device ABI", + "order": 14, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-014/case.md", + "anchor": "tc-gos-setup-014" + }, + "requirements": [ + "req-gos-setup-014" + ], + "risks": [ + "risk-gos-setup-014" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-015", + "title": "TPM simulator command proxy and lifecycle", + "order": 15, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-015/case.md", + "anchor": "tc-gos-setup-015" + }, + "requirements": [ + "req-gos-setup-015" + ], + "risks": [ + "risk-gos-setup-015" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-016", + "title": "Nitro NSM simulator request ABI", + "order": 16, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-016/case.md", + "anchor": "tc-gos-setup-016" + }, + "requirements": [ + "req-gos-setup-016" + ], + "risks": [ + "risk-gos-setup-016" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-017", + "title": "Simulator platform selection config and mount safety", + "order": 17, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-017/case.md", + "anchor": "tc-gos-setup-017" + }, + "requirements": [ + "req-gos-setup-017" + ], + "risks": [ + "risk-gos-setup-017" + ], + "tags": [ + "gos", + "system-setup-utilities-and-tee-simulator" + ] + }, + { + "id": "tc-gos-setup-018", + "title": "TDX event-log extend show and replay CLI", + "order": 18, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-018/case.md", + "anchor": "tc-gos-setup-018" + }, + "requirements": [ + "req-gos-setup-018" + ], + "risks": [ + "risk-gos-setup-018" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-019", + "title": "Quote and quote-report CLI bindings", + "order": 19, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-019/case.md", + "anchor": "tc-gos-setup-019" + }, + "requirements": [ + "req-gos-setup-019" + ], + "risks": [ + "risk-gos-setup-019" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-020", + "title": "RA CA and app key generation CLI", + "order": 20, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-020/case.md", + "anchor": "tc-gos-setup-020" + }, + "requirements": [ + "req-gos-setup-020" + ], + "risks": [ + "risk-gos-setup-020" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-021", + "title": "Random and hexadecimal utility CLI", + "order": 21, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-021/case.md", + "anchor": "tc-gos-setup-021" + }, + "requirements": [ + "req-gos-setup-021" + ], + "risks": [ + "risk-gos-setup-021" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-022", + "title": "vTPM attest quote and verify CLI suite", + "order": 22, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-022/case.md", + "anchor": "tc-gos-setup-022" + }, + "requirements": [ + "req-gos-setup-022" + ], + "risks": [ + "risk-gos-setup-022" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-023", + "title": "Versioned attestation create inspect JSON and strip CLI", + "order": 23, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-023/case.md", + "anchor": "tc-gos-setup-023" + }, + "requirements": [ + "req-gos-setup-023" + ], + "risks": [ + "risk-gos-setup-023" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + }, + { + "id": "tc-gos-setup-024", + "title": "KMS GetKeys CLI transport and output safety", + "order": 24, + "priority": "P0", + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024", + "spec": { + "path": "01-guest-os/12-setup-utilities-simulator/tc-gos-setup-024/case.md", + "anchor": "tc-gos-setup-024" + }, + "requirements": [ + "req-gos-setup-024" + ], + "risks": [ + "risk-gos-setup-024" + ], + "tags": [ + "guest-os", + "dstack-util" + ] + } + ] + }, + { + "id": "section-guest-os-yocto-runtime-hardening", + "title": "Yocto Image, Runtime, and Hardening", + "order": 13, + "path": "01-guest-os/13-yocto-runtime-hardening", + "cases": [ + { + "id": "tc-gos-yocto-001", + "title": "Development versus production image package boundary", + "order": 1, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-001/case.md", + "anchor": "tc-gos-yocto-001" + }, + "requirements": [ + "req-gos-yocto-001" + ], + "risks": [ + "risk-gos-yocto-001" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-002", + "title": "OpenSSH account and password-auth hardening", + "order": 2, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-002/case.md", + "anchor": "tc-gos-yocto-002" + }, + "requirements": [ + "req-gos-yocto-002" + ], + "risks": [ + "risk-gos-yocto-002" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-003", + "title": "Chrony synchronization and clock recovery", + "order": 3, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-003/case.md", + "anchor": "tc-gos-yocto-003" + }, + "requirements": [ + "req-gos-yocto-003" + ], + "risks": [ + "risk-gos-yocto-003" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-004", + "title": "Containerd stargz snapshotter integrity and fallback", + "order": 4, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-004/case.md", + "anchor": "tc-gos-yocto-004" + }, + "requirements": [ + "req-gos-yocto-004" + ], + "risks": [ + "risk-gos-yocto-004" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-005", + "title": "Sysbox runtime services and nested-container boundary", + "order": 5, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-005/case.md", + "anchor": "tc-gos-yocto-005" + }, + "requirements": [ + "req-gos-yocto-005" + ], + "risks": [ + "risk-gos-yocto-005" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-006", + "title": "Docker daemon CPU/GPU configuration variants", + "order": 6, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-006/case.md", + "anchor": "tc-gos-yocto-006" + }, + "requirements": [ + "req-gos-yocto-006" + ], + "risks": [ + "risk-gos-yocto-006" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-007", + "title": "Reproducible Yocto build and artifact export", + "order": 7, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-007/case.md", + "anchor": "tc-gos-yocto-007" + }, + "requirements": [ + "req-gos-yocto-007" + ], + "risks": [ + "risk-gos-yocto-007" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + }, + { + "id": "tc-gos-yocto-008", + "title": "AWS image hardening audit", + "order": 8, + "priority": "P0", + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008", + "spec": { + "path": "01-guest-os/13-yocto-runtime-hardening/tc-gos-yocto-008/case.md", + "anchor": "tc-gos-yocto-008" + }, + "requirements": [ + "req-gos-yocto-008" + ], + "risks": [ + "risk-gos-yocto-008" + ], + "tags": [ + "gos", + "yocto-image-runtime-and-hardening" + ] + } + ] + }, + { + "id": "section-gos-build", + "title": "Guest OS Build and Existing Regression Suite", + "order": 14, + "path": "01-guest-os/14-gos-build", + "cases": [ + { + "id": "tc-gos-build-001", + "title": "Guest OS Build and Existing Regression Suite", + "order": 1, + "priority": "P0", + "path": "01-guest-os/14-gos-build/tc-gos-build-001", + "spec": { + "path": "01-guest-os/14-gos-build/tc-gos-build-001/case.md", + "anchor": "tc-gos-build-001" + }, + "requirements": [ + "req-gos-build-001" + ], + "risks": [ + "risk-gos-build-001" + ], + "tags": [ + "build", + "regression" + ] + } + ] + } + ] + }, + { + "id": "chapter-vmm", + "title": "VMM", + "order": 2, + "path": "02-vmm", + "sections": [ + { + "id": "section-vmm-rpc-vmm", + "title": "Vmm RPC", + "order": 1, + "path": "02-vmm/01-rpc-vmm", + "cases": [ + { + "id": "tc-vmm-vmm-001", + "title": "Vmm.CreateVm", + "order": 1, + "priority": "P0", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-001", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-001/case.md", + "anchor": "tc-vmm-vmm-001" + }, + "requirements": [ + "req-vmm-vmm-001" + ], + "risks": [ + "risk-vmm-vmm-001" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-002", + "title": "Vmm.StartVm", + "order": 2, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-002", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-002/case.md", + "anchor": "tc-vmm-vmm-002" + }, + "requirements": [ + "req-vmm-vmm-002" + ], + "risks": [ + "risk-vmm-vmm-002" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-003", + "title": "Vmm.StopVm", + "order": 3, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-003", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-003/case.md", + "anchor": "tc-vmm-vmm-003" + }, + "requirements": [ + "req-vmm-vmm-003" + ], + "risks": [ + "risk-vmm-vmm-003" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-004", + "title": "Vmm.RemoveVm", + "order": 4, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-004", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-004/case.md", + "anchor": "tc-vmm-vmm-004" + }, + "requirements": [ + "req-vmm-vmm-004" + ], + "risks": [ + "risk-vmm-vmm-004" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-005", + "title": "Vmm.UpgradeApp", + "order": 5, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-005", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-005/case.md", + "anchor": "tc-vmm-vmm-005" + }, + "requirements": [ + "req-vmm-vmm-005" + ], + "risks": [ + "risk-vmm-vmm-005" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-006", + "title": "Vmm.UpdateVm", + "order": 6, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-006", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-006/case.md", + "anchor": "tc-vmm-vmm-006" + }, + "requirements": [ + "req-vmm-vmm-006" + ], + "risks": [ + "risk-vmm-vmm-006" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-007", + "title": "Vmm.ShutdownVm", + "order": 7, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-007", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-007/case.md", + "anchor": "tc-vmm-vmm-007" + }, + "requirements": [ + "req-vmm-vmm-007" + ], + "risks": [ + "risk-vmm-vmm-007" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-008", + "title": "Vmm.ResizeVm", + "order": 8, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-008", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-008/case.md", + "anchor": "tc-vmm-vmm-008" + }, + "requirements": [ + "req-vmm-vmm-008" + ], + "risks": [ + "risk-vmm-vmm-008" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-009", + "title": "Vmm.GetComposeHash", + "order": 9, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-009", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-009/case.md", + "anchor": "tc-vmm-vmm-009" + }, + "requirements": [ + "req-vmm-vmm-009" + ], + "risks": [ + "risk-vmm-vmm-009" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-010", + "title": "Vmm.Status", + "order": 10, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-010", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-010/case.md", + "anchor": "tc-vmm-vmm-010" + }, + "requirements": [ + "req-vmm-vmm-010" + ], + "risks": [ + "risk-vmm-vmm-010" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-011", + "title": "Vmm.ListImages", + "order": 11, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-011", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-011/case.md", + "anchor": "tc-vmm-vmm-011" + }, + "requirements": [ + "req-vmm-vmm-011" + ], + "risks": [ + "risk-vmm-vmm-011" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-012", + "title": "Vmm.GetAppEnvEncryptPubKey", + "order": 12, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-012", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-012/case.md", + "anchor": "tc-vmm-vmm-012" + }, + "requirements": [ + "req-vmm-vmm-012" + ], + "risks": [ + "risk-vmm-vmm-012" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-013", + "title": "Vmm.GetInfo", + "order": 13, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-013", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-013/case.md", + "anchor": "tc-vmm-vmm-013" + }, + "requirements": [ + "req-vmm-vmm-013" + ], + "risks": [ + "risk-vmm-vmm-013" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-014", + "title": "Vmm.Version", + "order": 14, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-014", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-014/case.md", + "anchor": "tc-vmm-vmm-014" + }, + "requirements": [ + "req-vmm-vmm-014" + ], + "risks": [ + "risk-vmm-vmm-014" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-015", + "title": "Vmm.GetMeta", + "order": 15, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-015", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-015/case.md", + "anchor": "tc-vmm-vmm-015" + }, + "requirements": [ + "req-vmm-vmm-015" + ], + "risks": [ + "risk-vmm-vmm-015" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-016", + "title": "Vmm.ListGpus", + "order": 16, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-016", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-016/case.md", + "anchor": "tc-vmm-vmm-016" + }, + "requirements": [ + "req-vmm-vmm-016" + ], + "risks": [ + "risk-vmm-vmm-016" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-017", + "title": "Vmm.ReloadVms", + "order": 17, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-017", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-017/case.md", + "anchor": "tc-vmm-vmm-017" + }, + "requirements": [ + "req-vmm-vmm-017" + ], + "risks": [ + "risk-vmm-vmm-017" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-018", + "title": "Vmm.SvList", + "order": 18, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-018", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-018/case.md", + "anchor": "tc-vmm-vmm-018" + }, + "requirements": [ + "req-vmm-vmm-018" + ], + "risks": [ + "risk-vmm-vmm-018" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-019", + "title": "Vmm.SvStop", + "order": 19, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-019", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-019/case.md", + "anchor": "tc-vmm-vmm-019" + }, + "requirements": [ + "req-vmm-vmm-019" + ], + "risks": [ + "risk-vmm-vmm-019" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-020", + "title": "Vmm.SvRemove", + "order": 20, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-020", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-020/case.md", + "anchor": "tc-vmm-vmm-020" + }, + "requirements": [ + "req-vmm-vmm-020" + ], + "risks": [ + "risk-vmm-vmm-020" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-021", + "title": "Vmm.ListRegistryImages", + "order": 21, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-021", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-021/case.md", + "anchor": "tc-vmm-vmm-021" + }, + "requirements": [ + "req-vmm-vmm-021" + ], + "risks": [ + "risk-vmm-vmm-021" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-022", + "title": "Vmm.PullRegistryImage", + "order": 22, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-022", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-022/case.md", + "anchor": "tc-vmm-vmm-022" + }, + "requirements": [ + "req-vmm-vmm-022" + ], + "risks": [ + "risk-vmm-vmm-022" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + }, + { + "id": "tc-vmm-vmm-023", + "title": "Vmm.DeleteImage", + "order": 23, + "priority": "P1", + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-023", + "spec": { + "path": "02-vmm/01-rpc-vmm/tc-vmm-vmm-023/case.md", + "anchor": "tc-vmm-vmm-023" + }, + "requirements": [ + "req-vmm-vmm-023" + ], + "risks": [ + "risk-vmm-vmm-023" + ], + "tags": [ + "vmm", + "vmm-rpc" + ] + } + ] + }, + { + "id": "section-vmm-rpc-hostapi", + "title": "HostApi RPC", + "order": 2, + "path": "02-vmm/02-rpc-hostapi", + "cases": [ + { + "id": "tc-vmm-hostapi-001", + "title": "HostApi.Info", + "order": 1, + "priority": "P1", + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001", + "spec": { + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-001/case.md", + "anchor": "tc-vmm-hostapi-001" + }, + "requirements": [ + "req-vmm-hostapi-001" + ], + "risks": [ + "risk-vmm-hostapi-001" + ], + "tags": [ + "vmm", + "hostapi-rpc" + ] + }, + { + "id": "tc-vmm-hostapi-002", + "title": "HostApi.Notify", + "order": 2, + "priority": "P1", + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002", + "spec": { + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-002/case.md", + "anchor": "tc-vmm-hostapi-002" + }, + "requirements": [ + "req-vmm-hostapi-002" + ], + "risks": [ + "risk-vmm-hostapi-002" + ], + "tags": [ + "vmm", + "hostapi-rpc" + ] + }, + { + "id": "tc-vmm-hostapi-003", + "title": "HostApi.GetSealingKey", + "order": 3, + "priority": "P1", + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003", + "spec": { + "path": "02-vmm/02-rpc-hostapi/tc-vmm-hostapi-003/case.md", + "anchor": "tc-vmm-hostapi-003" + }, + "requirements": [ + "req-vmm-hostapi-003" + ], + "risks": [ + "risk-vmm-hostapi-003" + ], + "tags": [ + "vmm", + "hostapi-rpc" + ] + } + ] + }, + { + "id": "section-vmm-configuration-and-security", + "title": "Configuration And Security", + "order": 3, + "path": "02-vmm/03-configuration-and-security", + "cases": [ + { + "id": "tc-vmm-configurat-001", + "title": "Configuration defaults and validation", + "order": 1, + "priority": "P1", + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-001", + "spec": { + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-001/case.md", + "anchor": "tc-vmm-configurat-001" + }, + "requirements": [ + "req-vmm-configurat-001" + ], + "risks": [ + "risk-vmm-configurat-001" + ], + "tags": [ + "vmm", + "configuration-and-security" + ] + }, + { + "id": "tc-vmm-configurat-002", + "title": "External API authentication and listener separation", + "order": 2, + "priority": "P1", + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-002", + "spec": { + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-002/case.md", + "anchor": "tc-vmm-configurat-002" + }, + "requirements": [ + "req-vmm-configurat-002" + ], + "risks": [ + "risk-vmm-configurat-002" + ], + "tags": [ + "vmm", + "configuration-and-security" + ] + }, + { + "id": "tc-vmm-configurat-003", + "title": "Per-instance simulated TEE selection", + "order": 3, + "priority": "P1", + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-003", + "spec": { + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-003/case.md", + "anchor": "tc-vmm-configurat-003" + }, + "requirements": [ + "req-vmm-configurat-003" + ], + "risks": [ + "risk-vmm-configurat-003" + ], + "tags": [ + "vmm", + "configuration-and-security" + ] + }, + { + "id": "tc-vmm-configurat-004", + "title": "TPM attachment decision materialization", + "order": 4, + "priority": "P1", + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-004", + "spec": { + "path": "02-vmm/03-configuration-and-security/tc-vmm-configurat-004/case.md", + "anchor": "tc-vmm-configurat-004" + }, + "requirements": [ + "req-vmm-configurat-004" + ], + "risks": [ + "risk-vmm-configurat-004" + ], + "tags": [ + "vmm", + "configuration-and-security" + ] + }, + { + "id": "tc-vmm-tdxvariant-005", + "title": "TDX legacy lite and auto variant resolution matrix", + "order": 5, + "priority": "P0", + "path": "02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005", + "spec": { + "path": "02-vmm/03-configuration-and-security/tc-vmm-tdxvariant-005/case.md", + "anchor": "tc-vmm-tdxvariant-005" + }, + "requirements": [ + "req-vmm-tdxvariant-005" + ], + "risks": [ + "risk-vmm-tdxvariant-005" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-vmm-vm-lifecycle", + "title": "Vm Lifecycle", + "order": 4, + "path": "02-vmm/04-vm-lifecycle", + "cases": [ + { + "id": "tc-vmm-vm-lifecyc-001", + "title": "Create/start/stop/remove idempotency", + "order": 1, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-001/case.md", + "anchor": "tc-vmm-vm-lifecyc-001" + }, + "requirements": [ + "req-vmm-vm-lifecyc-001" + ], + "risks": [ + "risk-vmm-vm-lifecyc-001" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + }, + { + "id": "tc-vmm-vm-lifecyc-002", + "title": "Graceful shutdown versus forced stop", + "order": 2, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-002/case.md", + "anchor": "tc-vmm-vm-lifecyc-002" + }, + "requirements": [ + "req-vmm-vm-lifecyc-002" + ], + "risks": [ + "risk-vmm-vm-lifecyc-002" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + }, + { + "id": "tc-vmm-vm-lifecyc-003", + "title": "Update and upgrade identity semantics", + "order": 3, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-003/case.md", + "anchor": "tc-vmm-vm-lifecyc-003" + }, + "requirements": [ + "req-vmm-vm-lifecyc-003" + ], + "risks": [ + "risk-vmm-vm-lifecyc-003" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + }, + { + "id": "tc-vmm-vm-lifecyc-004", + "title": "Resize CPU memory and disk", + "order": 4, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-004/case.md", + "anchor": "tc-vmm-vm-lifecyc-004" + }, + "requirements": [ + "req-vmm-vm-lifecyc-004" + ], + "risks": [ + "risk-vmm-vm-lifecyc-004" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + }, + { + "id": "tc-vmm-vm-lifecyc-005", + "title": "Reload and crash recovery", + "order": 5, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-005/case.md", + "anchor": "tc-vmm-vm-lifecyc-005" + }, + "requirements": [ + "req-vmm-vm-lifecyc-005" + ], + "risks": [ + "risk-vmm-vm-lifecyc-005" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + }, + { + "id": "tc-vmm-vm-lifecyc-006", + "title": "Auto-restart policy and backoff", + "order": 6, + "priority": "P1", + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006", + "spec": { + "path": "02-vmm/04-vm-lifecycle/tc-vmm-vm-lifecyc-006/case.md", + "anchor": "tc-vmm-vm-lifecyc-006" + }, + "requirements": [ + "req-vmm-vm-lifecyc-006" + ], + "risks": [ + "risk-vmm-vm-lifecyc-006" + ], + "tags": [ + "vmm", + "vm-lifecycle" + ] + } + ] + }, + { + "id": "section-vmm-compute-network-image", + "title": "Compute Network Image", + "order": 5, + "path": "02-vmm/05-compute-network-image", + "cases": [ + { + "id": "tc-vmm-compute-ne-001", + "title": "User bridge and custom networking", + "order": 1, + "priority": "P1", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-001", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-001/case.md", + "anchor": "tc-vmm-compute-ne-001" + }, + "requirements": [ + "req-vmm-compute-ne-001" + ], + "risks": [ + "risk-vmm-compute-ne-001" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-002", + "title": "Port mapping protocols and conflicts", + "order": 2, + "priority": "P1", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-002", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-002/case.md", + "anchor": "tc-vmm-compute-ne-002" + }, + "requirements": [ + "req-vmm-compute-ne-002" + ], + "risks": [ + "risk-vmm-compute-ne-002" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-003", + "title": "NUMA pinning hugepages and resource isolation", + "order": 3, + "priority": "P0", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-003", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-003/case.md", + "anchor": "tc-vmm-compute-ne-003" + }, + "requirements": [ + "req-vmm-compute-ne-003" + ], + "risks": [ + "risk-vmm-compute-ne-003" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-004", + "title": "GPU discovery attach modes and ownership", + "order": 4, + "priority": "P0", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-004", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-004/case.md", + "anchor": "tc-vmm-compute-ne-004" + }, + "requirements": [ + "req-vmm-compute-ne-004" + ], + "risks": [ + "risk-vmm-compute-ne-004" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-005", + "title": "Local image discovery metadata and deletion", + "order": 5, + "priority": "P1", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-005", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-005/case.md", + "anchor": "tc-vmm-compute-ne-005" + }, + "requirements": [ + "req-vmm-compute-ne-005" + ], + "risks": [ + "risk-vmm-compute-ne-005" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-006", + "title": "Registry authentication pull and extraction", + "order": 6, + "priority": "P1", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-006", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-006/case.md", + "anchor": "tc-vmm-compute-ne-006" + }, + "requirements": [ + "req-vmm-compute-ne-006" + ], + "risks": [ + "risk-vmm-compute-ne-006" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-compute-ne-007", + "title": "QEMU command and platform matrix", + "order": 7, + "priority": "P0", + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-007", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-compute-ne-007/case.md", + "anchor": "tc-vmm-compute-ne-007" + }, + "requirements": [ + "req-vmm-compute-ne-007" + ], + "risks": [ + "risk-vmm-compute-ne-007" + ], + "tags": [ + "vmm", + "compute-network-image" + ] + }, + { + "id": "tc-vmm-volume-008", + "title": "Measured verity volume extraction resolution and path safety", + "order": 8, + "priority": "P0", + "path": "02-vmm/05-compute-network-image/tc-vmm-volume-008", + "spec": { + "path": "02-vmm/05-compute-network-image/tc-vmm-volume-008/case.md", + "anchor": "tc-vmm-volume-008" + }, + "requirements": [ + "req-vmm-volume-008" + ], + "risks": [ + "risk-vmm-volume-008" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-vmm-ui-observability-host", + "title": "Ui Observability Host", + "order": 6, + "path": "02-vmm/06-ui-observability-host", + "cases": [ + { + "id": "tc-vmm-ui-observa-001", + "title": "Status filtering pagination and event history", + "order": 1, + "priority": "P1", + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-001/case.md", + "anchor": "tc-vmm-ui-observa-001" + }, + "requirements": [ + "req-vmm-ui-observa-001" + ], + "risks": [ + "risk-vmm-ui-observa-001" + ], + "tags": [ + "vmm", + "ui-observability-host" + ] + }, + { + "id": "tc-vmm-ui-observa-002", + "title": "Console log channels follow and ANSI handling", + "order": 2, + "priority": "P1", + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-002/case.md", + "anchor": "tc-vmm-ui-observa-002" + }, + "requirements": [ + "req-vmm-ui-observa-002" + ], + "risks": [ + "risk-vmm-ui-observa-002" + ], + "tags": [ + "vmm", + "ui-observability-host" + ] + }, + { + "id": "tc-vmm-ui-observa-003", + "title": "Host sealing-key provider integration", + "order": 3, + "priority": "P0", + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-003/case.md", + "anchor": "tc-vmm-ui-observa-003" + }, + "requirements": [ + "req-vmm-ui-observa-003" + ], + "risks": [ + "risk-vmm-ui-observa-003" + ], + "tags": [ + "vmm", + "ui-observability-host" + ] + }, + { + "id": "tc-vmm-ui-observa-004", + "title": "Supervisor passthrough operations", + "order": 4, + "priority": "P1", + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-004/case.md", + "anchor": "tc-vmm-ui-observa-004" + }, + "requirements": [ + "req-vmm-ui-observa-004" + ], + "risks": [ + "risk-vmm-ui-observa-004" + ], + "tags": [ + "vmm", + "ui-observability-host" + ] + }, + { + "id": "tc-vmm-ui-observa-005", + "title": "Web UI deployment workflows", + "order": 5, + "priority": "P1", + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-ui-observa-005/case.md", + "anchor": "tc-vmm-ui-observa-005" + }, + "requirements": [ + "req-vmm-ui-observa-005" + ], + "risks": [ + "risk-vmm-ui-observa-005" + ], + "tags": [ + "vmm", + "ui-observability-host" + ] + }, + { + "id": "tc-vmm-serial-006", + "title": "Serial log separator rotation history and follow continuity", + "order": 6, + "priority": "P0", + "path": "02-vmm/06-ui-observability-host/tc-vmm-serial-006", + "spec": { + "path": "02-vmm/06-ui-observability-host/tc-vmm-serial-006/case.md", + "anchor": "tc-vmm-serial-006" + }, + "requirements": [ + "req-vmm-serial-006" + ], + "risks": [ + "risk-vmm-serial-006" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-vmm-guest-proxy-and-manifest", + "title": "Guest Proxy and Manifest Fidelity", + "order": 7, + "path": "02-vmm/07-guest-proxy-and-manifest", + "cases": [ + { + "id": "tc-vmm-manifest-001", + "title": "Proxied GuestApi transport and VM targeting", + "order": 1, + "priority": "P0", + "path": "02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001", + "spec": { + "path": "02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-001/case.md", + "anchor": "tc-vmm-manifest-001" + }, + "requirements": [ + "req-vmm-manifest-001" + ], + "risks": [ + "risk-vmm-manifest-001" + ], + "tags": [ + "vmm", + "guest-proxy-and-manifest-fidelity" + ] + }, + { + "id": "tc-vmm-manifest-002", + "title": "Manifest persistence and QEMU/vm_config agreement", + "order": 2, + "priority": "P0", + "path": "02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002", + "spec": { + "path": "02-vmm/07-guest-proxy-and-manifest/tc-vmm-manifest-002/case.md", + "anchor": "tc-vmm-manifest-002" + }, + "requirements": [ + "req-vmm-manifest-002" + ], + "risks": [ + "risk-vmm-manifest-002" + ], + "tags": [ + "vmm", + "guest-proxy-and-manifest-fidelity" + ] + } + ] + }, + { + "id": "section-vmm-internal-state-and-launch", + "title": "Internal State, Measurement, and Launch Helpers", + "order": 8, + "path": "02-vmm/08-internal-state-and-launch", + "cases": [ + { + "id": "tc-vmm-internal-001", + "title": "Host-share disk creation and content bounds", + "order": 1, + "priority": "P0", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-001", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-001/case.md", + "anchor": "tc-vmm-internal-001" + }, + "requirements": [ + "req-vmm-internal-001" + ], + "risks": [ + "risk-vmm-internal-001" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-002", + "title": "Numeric ID pool allocation reuse and exhaustion", + "order": 2, + "priority": "P1", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-002", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-002/case.md", + "anchor": "tc-vmm-internal-002" + }, + "requirements": [ + "req-vmm-internal-002" + ], + "risks": [ + "risk-vmm-internal-002" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-003", + "title": "Image metadata parsing and firmware selection", + "order": 3, + "priority": "P0", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-003", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-003/case.md", + "anchor": "tc-vmm-internal-003" + }, + "requirements": [ + "req-vmm-internal-003" + ], + "risks": [ + "risk-vmm-internal-003" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-004", + "title": "MR config and SNP host-data construction", + "order": 4, + "priority": "P0", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-004", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-004/case.md", + "anchor": "tc-vmm-internal-004" + }, + "requirements": [ + "req-vmm-internal-004" + ], + "risks": [ + "risk-vmm-internal-004" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-005", + "title": "VM status protobuf projection and URL construction", + "order": 5, + "priority": "P1", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-005", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-005/case.md", + "anchor": "tc-vmm-internal-005" + }, + "requirements": [ + "req-vmm-internal-005" + ], + "risks": [ + "risk-vmm-internal-005" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-006", + "title": "One-shot VM execution and cleanup", + "order": 6, + "priority": "P1", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-006", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-006/case.md", + "anchor": "tc-vmm-internal-006" + }, + "requirements": [ + "req-vmm-internal-006" + ], + "risks": [ + "risk-vmm-internal-006" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-007", + "title": "Generated OpenAPI contract fidelity", + "order": 7, + "priority": "P1", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-007", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-007/case.md", + "anchor": "tc-vmm-internal-007" + }, + "requirements": [ + "req-vmm-internal-007" + ], + "risks": [ + "risk-vmm-internal-007" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + }, + { + "id": "tc-vmm-internal-008", + "title": "Launcher QEMU and swtpm coupled lifecycle", + "order": 8, + "priority": "P0", + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-008", + "spec": { + "path": "02-vmm/08-internal-state-and-launch/tc-vmm-internal-008/case.md", + "anchor": "tc-vmm-internal-008" + }, + "requirements": [ + "req-vmm-internal-008" + ], + "risks": [ + "risk-vmm-internal-008" + ], + "tags": [ + "vmm", + "internal-state-measurement-and-launch-helpers" + ] + } + ] + }, + { + "id": "section-vmm-build", + "title": "VMM Build, CLI, UI, and Existing Regression Suite", + "order": 9, + "path": "02-vmm/09-vmm-build", + "cases": [ + { + "id": "tc-vmm-build-001", + "title": "VMM Build, CLI, UI, and Existing Regression Suite", + "order": 1, + "priority": "P0", + "path": "02-vmm/09-vmm-build/tc-vmm-build-001", + "spec": { + "path": "02-vmm/09-vmm-build/tc-vmm-build-001/case.md", + "anchor": "tc-vmm-build-001" + }, + "requirements": [ + "req-vmm-build-001" + ], + "risks": [ + "risk-vmm-build-001" + ], + "tags": [ + "build", + "regression" + ] + } + ] + } + ] + }, + { + "id": "chapter-kms", + "title": "KMS", + "order": 3, + "path": "03-kms", + "sections": [ + { + "id": "section-kms-rpc-kms", + "title": "KMS RPC", + "order": 1, + "path": "03-kms/01-rpc-kms", + "cases": [ + { + "id": "tc-kms-kms-001", + "title": "KMS.GetAppKey", + "order": 1, + "priority": "P0", + "path": "03-kms/01-rpc-kms/tc-kms-kms-001", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-001/case.md", + "anchor": "tc-kms-kms-001" + }, + "requirements": [ + "req-kms-kms-001" + ], + "risks": [ + "risk-kms-kms-001" + ], + "tags": [ + "kms", + "kms-rpc" + ] + }, + { + "id": "tc-kms-kms-002", + "title": "KMS.GetKmsKey", + "order": 2, + "priority": "P0", + "path": "03-kms/01-rpc-kms/tc-kms-kms-002", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-002/case.md", + "anchor": "tc-kms-kms-002" + }, + "requirements": [ + "req-kms-kms-002" + ], + "risks": [ + "risk-kms-kms-002" + ], + "tags": [ + "kms", + "kms-rpc" + ] + }, + { + "id": "tc-kms-kms-003", + "title": "KMS.GetAppEnvEncryptPubKey", + "order": 3, + "priority": "P1", + "path": "03-kms/01-rpc-kms/tc-kms-kms-003", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-003/case.md", + "anchor": "tc-kms-kms-003" + }, + "requirements": [ + "req-kms-kms-003" + ], + "risks": [ + "risk-kms-kms-003" + ], + "tags": [ + "kms", + "kms-rpc" + ] + }, + { + "id": "tc-kms-kms-004", + "title": "KMS.GetMeta", + "order": 4, + "priority": "P1", + "path": "03-kms/01-rpc-kms/tc-kms-kms-004", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-004/case.md", + "anchor": "tc-kms-kms-004" + }, + "requirements": [ + "req-kms-kms-004" + ], + "risks": [ + "risk-kms-kms-004" + ], + "tags": [ + "kms", + "kms-rpc" + ] + }, + { + "id": "tc-kms-kms-005", + "title": "KMS.GetTempCaCert", + "order": 5, + "priority": "P1", + "path": "03-kms/01-rpc-kms/tc-kms-kms-005", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-005/case.md", + "anchor": "tc-kms-kms-005" + }, + "requirements": [ + "req-kms-kms-005" + ], + "risks": [ + "risk-kms-kms-005" + ], + "tags": [ + "kms", + "kms-rpc" + ] + }, + { + "id": "tc-kms-kms-006", + "title": "KMS.SignCert", + "order": 6, + "priority": "P0", + "path": "03-kms/01-rpc-kms/tc-kms-kms-006", + "spec": { + "path": "03-kms/01-rpc-kms/tc-kms-kms-006/case.md", + "anchor": "tc-kms-kms-006" + }, + "requirements": [ + "req-kms-kms-006" + ], + "risks": [ + "risk-kms-kms-006" + ], + "tags": [ + "kms", + "kms-rpc" + ] + } + ] + }, + { + "id": "section-kms-rpc-admin", + "title": "Admin RPC", + "order": 2, + "path": "03-kms/02-rpc-admin", + "cases": [ + { + "id": "tc-kms-admin-001", + "title": "Admin.ClearImageCache", + "order": 1, + "priority": "P1", + "path": "03-kms/02-rpc-admin/tc-kms-admin-001", + "spec": { + "path": "03-kms/02-rpc-admin/tc-kms-admin-001/case.md", + "anchor": "tc-kms-admin-001" + }, + "requirements": [ + "req-kms-admin-001" + ], + "risks": [ + "risk-kms-admin-001" + ], + "tags": [ + "kms", + "admin-rpc" + ] + } + ] + }, + { + "id": "section-kms-rpc-onboard", + "title": "Onboard RPC", + "order": 3, + "path": "03-kms/03-rpc-onboard", + "cases": [ + { + "id": "tc-kms-onboard-001", + "title": "Onboard.Bootstrap", + "order": 1, + "priority": "P1", + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-001", + "spec": { + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-001/case.md", + "anchor": "tc-kms-onboard-001" + }, + "requirements": [ + "req-kms-onboard-001" + ], + "risks": [ + "risk-kms-onboard-001" + ], + "tags": [ + "kms", + "onboard-rpc" + ] + }, + { + "id": "tc-kms-onboard-002", + "title": "Onboard.Onboard", + "order": 2, + "priority": "P1", + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-002", + "spec": { + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-002/case.md", + "anchor": "tc-kms-onboard-002" + }, + "requirements": [ + "req-kms-onboard-002" + ], + "risks": [ + "risk-kms-onboard-002" + ], + "tags": [ + "kms", + "onboard-rpc" + ] + }, + { + "id": "tc-kms-onboard-003", + "title": "Onboard.GetAttestationInfo", + "order": 3, + "priority": "P1", + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-003", + "spec": { + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-003/case.md", + "anchor": "tc-kms-onboard-003" + }, + "requirements": [ + "req-kms-onboard-003" + ], + "risks": [ + "risk-kms-onboard-003" + ], + "tags": [ + "kms", + "onboard-rpc" + ] + }, + { + "id": "tc-kms-onboard-004", + "title": "Onboard.Finish", + "order": 4, + "priority": "P1", + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-004", + "spec": { + "path": "03-kms/03-rpc-onboard/tc-kms-onboard-004/case.md", + "anchor": "tc-kms-onboard-004" + }, + "requirements": [ + "req-kms-onboard-004" + ], + "risks": [ + "risk-kms-onboard-004" + ], + "tags": [ + "kms", + "onboard-rpc" + ] + } + ] + }, + { + "id": "section-kms-bootstrap-onboard", + "title": "Bootstrap Onboard", + "order": 4, + "path": "03-kms/04-bootstrap-onboard", + "cases": [ + { + "id": "tc-kms-bootstrap--001", + "title": "Fresh bootstrap key hierarchy", + "order": 1, + "priority": "P0", + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001", + "spec": { + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--001/case.md", + "anchor": "tc-kms-bootstrap--001" + }, + "requirements": [ + "req-kms-bootstrap--001" + ], + "risks": [ + "risk-kms-bootstrap--001" + ], + "tags": [ + "kms", + "bootstrap-onboard" + ] + }, + { + "id": "tc-kms-bootstrap--002", + "title": "Onboard from existing KMS", + "order": 2, + "priority": "P0", + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002", + "spec": { + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--002/case.md", + "anchor": "tc-kms-bootstrap--002" + }, + "requirements": [ + "req-kms-bootstrap--002" + ], + "risks": [ + "risk-kms-bootstrap--002" + ], + "tags": [ + "kms", + "bootstrap-onboard" + ] + }, + { + "id": "tc-kms-bootstrap--003", + "title": "Finish onboarding and listener transition", + "order": 3, + "priority": "P0", + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003", + "spec": { + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--003/case.md", + "anchor": "tc-kms-bootstrap--003" + }, + "requirements": [ + "req-kms-bootstrap--003" + ], + "risks": [ + "risk-kms-bootstrap--003" + ], + "tags": [ + "kms", + "bootstrap-onboard" + ] + }, + { + "id": "tc-kms-bootstrap--004", + "title": "On-chain attestation information", + "order": 4, + "priority": "P0", + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004", + "spec": { + "path": "03-kms/04-bootstrap-onboard/tc-kms-bootstrap--004/case.md", + "anchor": "tc-kms-bootstrap--004" + }, + "requirements": [ + "req-kms-bootstrap--004" + ], + "risks": [ + "risk-kms-bootstrap--004" + ], + "tags": [ + "kms", + "bootstrap-onboard" + ] + } + ] + }, + { + "id": "section-kms-attestation-authorization", + "title": "Attestation Authorization", + "order": 5, + "path": "03-kms/05-attestation-authorization", + "cases": [ + { + "id": "tc-kms-attestatio-001", + "title": "TDX full and lite app authorization", + "order": 1, + "priority": "P0", + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-001", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-001/case.md", + "anchor": "tc-kms-attestatio-001" + }, + "requirements": [ + "req-kms-attestatio-001" + ], + "risks": [ + "risk-kms-attestatio-001" + ], + "tags": [ + "kms", + "attestation-authorization" + ] + }, + { + "id": "tc-kms-attestatio-002", + "title": "SEV-SNP app authorization", + "order": 2, + "priority": "P0", + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-002", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-002/case.md", + "anchor": "tc-kms-attestatio-002" + }, + "requirements": [ + "req-kms-attestatio-002" + ], + "risks": [ + "risk-kms-attestatio-002" + ], + "tags": [ + "kms", + "attestation-authorization" + ] + }, + { + "id": "tc-kms-attestatio-003", + "title": "GCP TDX and Nitro TPM authorization", + "order": 3, + "priority": "P0", + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-003", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-003/case.md", + "anchor": "tc-kms-attestatio-003" + }, + "requirements": [ + "req-kms-attestatio-003" + ], + "risks": [ + "risk-kms-attestatio-003" + ], + "tags": [ + "kms", + "attestation-authorization" + ] + }, + { + "id": "tc-kms-attestatio-004", + "title": "Upgrade authority and allow_any_upgrade", + "order": 4, + "priority": "P0", + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-004", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-004/case.md", + "anchor": "tc-kms-attestatio-004" + }, + "requirements": [ + "req-kms-attestatio-004" + ], + "risks": [ + "risk-kms-attestatio-004" + ], + "tags": [ + "kms", + "attestation-authorization" + ] + }, + { + "id": "tc-kms-attestatio-005", + "title": "Authorization backend matrix", + "order": 5, + "priority": "P1", + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-005", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-attestatio-005/case.md", + "anchor": "tc-kms-attestatio-005" + }, + "requirements": [ + "req-kms-attestatio-005" + ], + "risks": [ + "risk-kms-attestatio-005" + ], + "tags": [ + "kms", + "attestation-authorization" + ] + }, + { + "id": "tc-kms-platform-006", + "title": "Nitro Enclave app and KMS authorization", + "order": 6, + "priority": "P0", + "path": "03-kms/05-attestation-authorization/tc-kms-platform-006", + "spec": { + "path": "03-kms/05-attestation-authorization/tc-kms-platform-006/case.md", + "anchor": "tc-kms-platform-006" + }, + "requirements": [ + "req-kms-platform-006" + ], + "risks": [ + "risk-kms-platform-006" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-kms-keys-certs-operations", + "title": "Keys Certs Operations", + "order": 6, + "path": "03-kms/06-keys-certs-operations", + "cases": [ + { + "id": "tc-kms-keys-certs-001", + "title": "Per-app key hierarchy isolation", + "order": 1, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-001", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-001/case.md", + "anchor": "tc-kms-keys-certs-001" + }, + "requirements": [ + "req-kms-keys-certs-001" + ], + "risks": [ + "risk-kms-keys-certs-001" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-002", + "title": "Environment public-key freshness signatures", + "order": 2, + "priority": "P1", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-002", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-002/case.md", + "anchor": "tc-kms-keys-certs-002" + }, + "requirements": [ + "req-kms-keys-certs-002" + ], + "risks": [ + "risk-kms-keys-certs-002" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-003", + "title": "KMS key handover and rotation chain", + "order": 3, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-003", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-003/case.md", + "anchor": "tc-kms-keys-certs-003" + }, + "requirements": [ + "req-kms-keys-certs-003" + ], + "risks": [ + "risk-kms-keys-certs-003" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-004", + "title": "Certificate signing CSR and app binding", + "order": 4, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-004", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-004/case.md", + "anchor": "tc-kms-keys-certs-004" + }, + "requirements": [ + "req-kms-keys-certs-004" + ], + "risks": [ + "risk-kms-keys-certs-004" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-005", + "title": "Temporary CA lifecycle", + "order": 5, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-005", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-005/case.md", + "anchor": "tc-kms-keys-certs-005" + }, + "requirements": [ + "req-kms-keys-certs-005" + ], + "risks": [ + "risk-kms-keys-certs-005" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-006", + "title": "Image measurement cache clear and refill", + "order": 6, + "priority": "P1", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-006", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-006/case.md", + "anchor": "tc-kms-keys-certs-006" + }, + "requirements": [ + "req-kms-keys-certs-006" + ], + "risks": [ + "risk-kms-keys-certs-006" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-007", + "title": "Admin authentication transports", + "order": 7, + "priority": "P1", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-007", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-007/case.md", + "anchor": "tc-kms-keys-certs-007" + }, + "requirements": [ + "req-kms-keys-certs-007" + ], + "risks": [ + "risk-kms-keys-certs-007" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-008", + "title": "Metrics metadata and failure diagnostics", + "order": 8, + "priority": "P1", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-008", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-008/case.md", + "anchor": "tc-kms-keys-certs-008" + }, + "requirements": [ + "req-kms-keys-certs-008" + ], + "risks": [ + "risk-kms-keys-certs-008" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-keys-certs-009", + "title": "Crash consistency and backup recovery", + "order": 9, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-009", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-keys-certs-009/case.md", + "anchor": "tc-kms-keys-certs-009" + }, + "requirements": [ + "req-kms-keys-certs-009" + ], + "risks": [ + "risk-kms-keys-certs-009" + ], + "tags": [ + "kms", + "keys-certs-operations" + ] + }, + { + "id": "tc-kms-release-010", + "title": "Platform-specific key-release feature gates", + "order": 10, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-release-010", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-release-010/case.md", + "anchor": "tc-kms-release-010" + }, + "requirements": [ + "req-kms-release-010" + ], + "risks": [ + "risk-kms-release-010" + ], + "tags": [ + "semantic-review" + ] + }, + { + "id": "tc-kms-apiver-011", + "title": "GetAppKey and SignCert API-version compatibility", + "order": 11, + "priority": "P0", + "path": "03-kms/06-keys-certs-operations/tc-kms-apiver-011", + "spec": { + "path": "03-kms/06-keys-certs-operations/tc-kms-apiver-011/case.md", + "anchor": "tc-kms-apiver-011" + }, + "requirements": [ + "req-kms-apiver-011" + ], + "risks": [ + "risk-kms-apiver-011" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-kms-authorization-implementations", + "title": "Authorization Implementations and Contract", + "order": 7, + "path": "03-kms/07-authorization-implementations", + "cases": [ + { + "id": "tc-kms-auth-001", + "title": "Simple authorization configuration rules", + "order": 1, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-001", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-001/case.md", + "anchor": "tc-kms-auth-001" + }, + "requirements": [ + "req-kms-auth-001" + ], + "risks": [ + "risk-kms-auth-001" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-002", + "title": "Mock authorization safety boundary", + "order": 2, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-002", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-002/case.md", + "anchor": "tc-kms-auth-002" + }, + "requirements": [ + "req-kms-auth-002" + ], + "risks": [ + "risk-kms-auth-002" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-003", + "title": "Ethereum authorization request signatures and replay", + "order": 3, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-003", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-003/case.md", + "anchor": "tc-kms-auth-003" + }, + "requirements": [ + "req-kms-auth-003" + ], + "risks": [ + "risk-kms-auth-003" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-004", + "title": "KMS contract ownership roles and upgrade controls", + "order": 4, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-004", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-004/case.md", + "anchor": "tc-kms-auth-004" + }, + "requirements": [ + "req-kms-auth-004" + ], + "risks": [ + "risk-kms-auth-004" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-005", + "title": "KMS node registration and authorization lifecycle", + "order": 5, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-005", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-005/case.md", + "anchor": "tc-kms-auth-005" + }, + "requirements": [ + "req-kms-auth-005" + ], + "risks": [ + "risk-kms-auth-005" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-006", + "title": "Application boot policy image and config matrix", + "order": 6, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-006", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-006/case.md", + "anchor": "tc-kms-auth-006" + }, + "requirements": [ + "req-kms-auth-006" + ], + "risks": [ + "risk-kms-auth-006" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-007", + "title": "Ethereum RPC failure reorg and finality handling", + "order": 7, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-007", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-007/case.md", + "anchor": "tc-kms-auth-007" + }, + "requirements": [ + "req-kms-auth-007" + ], + "risks": [ + "risk-kms-auth-007" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-008", + "title": "Authorization API schema and error compatibility", + "order": 8, + "priority": "P1", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-008", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-008/case.md", + "anchor": "tc-kms-auth-008" + }, + "requirements": [ + "req-kms-auth-008" + ], + "risks": [ + "risk-kms-auth-008" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-009", + "title": "Contract event audit completeness", + "order": 9, + "priority": "P1", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-009", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-009/case.md", + "anchor": "tc-kms-auth-009" + }, + "requirements": [ + "req-kms-auth-009" + ], + "risks": [ + "risk-kms-auth-009" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + }, + { + "id": "tc-kms-auth-010", + "title": "Authorization cache scope and invalidation", + "order": 10, + "priority": "P0", + "path": "03-kms/07-authorization-implementations/tc-kms-auth-010", + "spec": { + "path": "03-kms/07-authorization-implementations/tc-kms-auth-010/case.md", + "anchor": "tc-kms-auth-010" + }, + "requirements": [ + "req-kms-auth-010" + ], + "risks": [ + "risk-kms-auth-010" + ], + "tags": [ + "kms", + "authorization-implementations-and-contract" + ] + } + ] + }, + { + "id": "section-kms-upgrade-onboard-compatibility", + "title": "Upgrade and Onboard Compatibility to 0.6.0", + "order": 8, + "path": "03-kms/08-upgrade-onboard-compatibility", + "cases": [ + { + "id": "tc-kms-upgrade-001", + "title": "0.5.4 to 0.6.0 through 0.5.7 bridge", + "order": 1, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-001/case.md", + "anchor": "tc-kms-upgrade-001" + }, + "requirements": [ + "req-kms-upgrade-001" + ], + "risks": [ + "risk-kms-upgrade-001" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-002", + "title": "Direct 0.5.4 to 0.6.0 incompatibility is explicit", + "order": 2, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-002/case.md", + "anchor": "tc-kms-upgrade-002" + }, + "requirements": [ + "req-kms-upgrade-002" + ], + "risks": [ + "risk-kms-upgrade-002" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-003", + "title": "0.5.8 direct onboard to 0.6.0", + "order": 3, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-003/case.md", + "anchor": "tc-kms-upgrade-003" + }, + "requirements": [ + "req-kms-upgrade-003" + ], + "risks": [ + "risk-kms-upgrade-003" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-004", + "title": "kms-v0.5.11 direct onboard to 0.6.0", + "order": 4, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-004/case.md", + "anchor": "tc-kms-upgrade-004" + }, + "requirements": [ + "req-kms-upgrade-004" + ], + "risks": [ + "risk-kms-upgrade-004" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-005", + "title": "Old source rejects 0.6.0 target in TDX-lite mode", + "order": 5, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-005/case.md", + "anchor": "tc-kms-upgrade-005" + }, + "requirements": [ + "req-kms-upgrade-005" + ], + "risks": [ + "risk-kms-upgrade-005" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-006", + "title": "Legacy mode is forced throughout mixed-source cutover", + "order": 6, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-006/case.md", + "anchor": "tc-kms-upgrade-006" + }, + "requirements": [ + "req-kms-upgrade-006" + ], + "risks": [ + "risk-kms-upgrade-006" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-007", + "title": "0.5.4 age-matched ACPI diagnosis", + "order": 7, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-007/case.md", + "anchor": "tc-kms-upgrade-007" + }, + "requirements": [ + "req-kms-upgrade-007" + ], + "risks": [ + "risk-kms-upgrade-007" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-008", + "title": "Source and target allowlist completeness", + "order": 8, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-008/case.md", + "anchor": "tc-kms-upgrade-008" + }, + "requirements": [ + "req-kms-upgrade-008" + ], + "risks": [ + "risk-kms-upgrade-008" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-009", + "title": "Mixed-version KMS endpoint service consistency", + "order": 9, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-009/case.md", + "anchor": "tc-kms-upgrade-009" + }, + "requirements": [ + "req-kms-upgrade-009" + ], + "risks": [ + "risk-kms-upgrade-009" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-010", + "title": "KMS replacement cutover and rollback window", + "order": 10, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-010/case.md", + "anchor": "tc-kms-upgrade-010" + }, + "requirements": [ + "req-kms-upgrade-010" + ], + "risks": [ + "risk-kms-upgrade-010" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-011", + "title": "Measurement cache across KMS upgrade boundaries", + "order": 11, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-011/case.md", + "anchor": "tc-kms-upgrade-011" + }, + "requirements": [ + "req-kms-upgrade-011" + ], + "risks": [ + "risk-kms-upgrade-011" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-kms-upgrade-012", + "title": "Post-KMS gateway 0.6.0 upgrade order", + "order": 12, + "priority": "P0", + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012", + "spec": { + "path": "03-kms/08-upgrade-onboard-compatibility/tc-kms-upgrade-012/case.md", + "anchor": "tc-kms-upgrade-012" + }, + "requirements": [ + "req-kms-upgrade-012" + ], + "risks": [ + "risk-kms-upgrade-012" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + } + ] + }, + { + "id": "section-kms-certificate-transparency-log", + "title": "Certificate Transparency Log Files", + "order": 9, + "path": "03-kms/09-certificate-transparency-log", + "cases": [ + { + "id": "tc-kms-ct-001", + "title": "Concurrent certificate log append and iteration", + "order": 1, + "priority": "P0", + "path": "03-kms/09-certificate-transparency-log/tc-kms-ct-001", + "spec": { + "path": "03-kms/09-certificate-transparency-log/tc-kms-ct-001/case.md", + "anchor": "tc-kms-ct-001" + }, + "requirements": [ + "req-kms-ct-001" + ], + "risks": [ + "risk-kms-ct-001" + ], + "tags": [ + "kms", + "certificate-transparency-log-files" + ] + } + ] + }, + { + "id": "section-kms-service-startup", + "title": "Service Startup and Mode Transition", + "order": 10, + "path": "03-kms/10-service-startup", + "cases": [ + { + "id": "tc-kms-startup-001", + "title": "Onboard, main, admin, metrics, and health listener startup", + "order": 1, + "priority": "P0", + "path": "03-kms/10-service-startup/tc-kms-startup-001", + "spec": { + "path": "03-kms/10-service-startup/tc-kms-startup-001/case.md", + "anchor": "tc-kms-startup-001" + }, + "requirements": [ + "req-kms-startup-001" + ], + "risks": [ + "risk-kms-startup-001" + ], + "tags": [ + "kms", + "startup" + ] + } + ] + }, + { + "id": "section-kms-auth-service-runtime", + "title": "Authorization Service Runtime and Deployment", + "order": 11, + "path": "03-kms/11-auth-service-runtime", + "cases": [ + { + "id": "tc-kms-runtime-001", + "title": "Ethereum authorization HTTP server schema and listener", + "order": 1, + "priority": "P0", + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-001", + "spec": { + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-001/case.md", + "anchor": "tc-kms-runtime-001" + }, + "requirements": [ + "req-kms-runtime-001" + ], + "risks": [ + "risk-kms-runtime-001" + ], + "tags": [ + "kms", + "authorization-service-runtime-and-deployment" + ] + }, + { + "id": "tc-kms-runtime-002", + "title": "Bun and Node authorization implementation parity", + "order": 2, + "priority": "P0", + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-002", + "spec": { + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-002/case.md", + "anchor": "tc-kms-runtime-002" + }, + "requirements": [ + "req-kms-runtime-002" + ], + "risks": [ + "risk-kms-runtime-002" + ], + "tags": [ + "kms", + "authorization-service-runtime-and-deployment" + ] + }, + { + "id": "tc-kms-runtime-003", + "title": "Authorization deployment and management scripts", + "order": 3, + "priority": "P0", + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-003", + "spec": { + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-003/case.md", + "anchor": "tc-kms-runtime-003" + }, + "requirements": [ + "req-kms-runtime-003" + ], + "risks": [ + "risk-kms-runtime-003" + ], + "tags": [ + "kms", + "authorization-service-runtime-and-deployment" + ] + }, + { + "id": "tc-kms-runtime-004", + "title": "Authorization service container deployment", + "order": 4, + "priority": "P1", + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-004", + "spec": { + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-004/case.md", + "anchor": "tc-kms-runtime-004" + }, + "requirements": [ + "req-kms-runtime-004" + ], + "risks": [ + "risk-kms-runtime-004" + ], + "tags": [ + "kms", + "authorization-service-runtime-and-deployment" + ] + }, + { + "id": "tc-kms-runtime-005", + "title": "DstackApp device compose TCB and upgrade-disable policy", + "order": 5, + "priority": "P0", + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-005", + "spec": { + "path": "03-kms/11-auth-service-runtime/tc-kms-runtime-005/case.md", + "anchor": "tc-kms-runtime-005" + }, + "requirements": [ + "req-kms-runtime-005" + ], + "risks": [ + "risk-kms-runtime-005" + ], + "tags": [ + "kms", + "authorization-service-runtime-and-deployment" + ] + } + ] + }, + { + "id": "section-kms-build", + "title": "KMS Build, Image, Auth, Contract, and Existing Regression Suite", + "order": 12, + "path": "03-kms/12-kms-build", + "cases": [ + { + "id": "tc-kms-build-001", + "title": "KMS Build, Image, Auth, Contract, and Existing Regression Suite", + "order": 1, + "priority": "P0", + "path": "03-kms/12-kms-build/tc-kms-build-001", + "spec": { + "path": "03-kms/12-kms-build/tc-kms-build-001/case.md", + "anchor": "tc-kms-build-001" + }, + "requirements": [ + "req-kms-build-001" + ], + "risks": [ + "risk-kms-build-001" + ], + "tags": [ + "build", + "regression" + ] + } + ] + } + ] + }, + { + "id": "chapter-gateway", + "title": "Gateway", + "order": 4, + "path": "04-gateway", + "sections": [ + { + "id": "section-gateway-rpc-gateway", + "title": "Gateway RPC", + "order": 1, + "path": "04-gateway/01-rpc-gateway", + "cases": [ + { + "id": "tc-gw-gateway-001", + "title": "Gateway.RegisterCvm", + "order": 1, + "priority": "P0", + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-001", + "spec": { + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-001/case.md", + "anchor": "tc-gw-gateway-001" + }, + "requirements": [ + "req-gw-gateway-001" + ], + "risks": [ + "risk-gw-gateway-001" + ], + "tags": [ + "gateway", + "gateway-rpc" + ] + }, + { + "id": "tc-gw-gateway-002", + "title": "Gateway.AcmeInfo", + "order": 2, + "priority": "P1", + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-002", + "spec": { + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-002/case.md", + "anchor": "tc-gw-gateway-002" + }, + "requirements": [ + "req-gw-gateway-002" + ], + "risks": [ + "risk-gw-gateway-002" + ], + "tags": [ + "gateway", + "gateway-rpc" + ] + }, + { + "id": "tc-gw-gateway-003", + "title": "Gateway.Info", + "order": 3, + "priority": "P1", + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-003", + "spec": { + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-003/case.md", + "anchor": "tc-gw-gateway-003" + }, + "requirements": [ + "req-gw-gateway-003" + ], + "risks": [ + "risk-gw-gateway-003" + ], + "tags": [ + "gateway", + "gateway-rpc" + ] + }, + { + "id": "tc-gw-gateway-004", + "title": "Gateway.GetPeers", + "order": 4, + "priority": "P1", + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-004", + "spec": { + "path": "04-gateway/01-rpc-gateway/tc-gw-gateway-004/case.md", + "anchor": "tc-gw-gateway-004" + }, + "requirements": [ + "req-gw-gateway-004" + ], + "risks": [ + "risk-gw-gateway-004" + ], + "tags": [ + "gateway", + "gateway-rpc" + ] + } + ] + }, + { + "id": "section-gateway-rpc-debug", + "title": "Debug RPC", + "order": 2, + "path": "04-gateway/02-rpc-debug", + "cases": [ + { + "id": "tc-gw-debug-001", + "title": "Debug.RegisterCvm", + "order": 1, + "priority": "P0", + "path": "04-gateway/02-rpc-debug/tc-gw-debug-001", + "spec": { + "path": "04-gateway/02-rpc-debug/tc-gw-debug-001/case.md", + "anchor": "tc-gw-debug-001" + }, + "requirements": [ + "req-gw-debug-001" + ], + "risks": [ + "risk-gw-debug-001" + ], + "tags": [ + "gateway", + "debug-rpc" + ] + }, + { + "id": "tc-gw-debug-002", + "title": "Debug.Info", + "order": 2, + "priority": "P1", + "path": "04-gateway/02-rpc-debug/tc-gw-debug-002", + "spec": { + "path": "04-gateway/02-rpc-debug/tc-gw-debug-002/case.md", + "anchor": "tc-gw-debug-002" + }, + "requirements": [ + "req-gw-debug-002" + ], + "risks": [ + "risk-gw-debug-002" + ], + "tags": [ + "gateway", + "debug-rpc" + ] + }, + { + "id": "tc-gw-debug-003", + "title": "Debug.GetSyncData", + "order": 3, + "priority": "P1", + "path": "04-gateway/02-rpc-debug/tc-gw-debug-003", + "spec": { + "path": "04-gateway/02-rpc-debug/tc-gw-debug-003/case.md", + "anchor": "tc-gw-debug-003" + }, + "requirements": [ + "req-gw-debug-003" + ], + "risks": [ + "risk-gw-debug-003" + ], + "tags": [ + "gateway", + "debug-rpc" + ] + }, + { + "id": "tc-gw-debug-004", + "title": "Debug.GetProxyState", + "order": 4, + "priority": "P1", + "path": "04-gateway/02-rpc-debug/tc-gw-debug-004", + "spec": { + "path": "04-gateway/02-rpc-debug/tc-gw-debug-004/case.md", + "anchor": "tc-gw-debug-004" + }, + "requirements": [ + "req-gw-debug-004" + ], + "risks": [ + "risk-gw-debug-004" + ], + "tags": [ + "gateway", + "debug-rpc" + ] + } + ] + }, + { + "id": "section-gateway-rpc-admin", + "title": "Admin RPC", + "order": 3, + "path": "04-gateway/03-rpc-admin", + "cases": [ + { + "id": "tc-gw-admin-001", + "title": "Admin.Status", + "order": 1, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-001", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-001/case.md", + "anchor": "tc-gw-admin-001" + }, + "requirements": [ + "req-gw-admin-001" + ], + "risks": [ + "risk-gw-admin-001" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-002", + "title": "Admin.GetInfo", + "order": 2, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-002", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-002/case.md", + "anchor": "tc-gw-admin-002" + }, + "requirements": [ + "req-gw-admin-002" + ], + "risks": [ + "risk-gw-admin-002" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-003", + "title": "Admin.Exit", + "order": 3, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-003", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-003/case.md", + "anchor": "tc-gw-admin-003" + }, + "requirements": [ + "req-gw-admin-003" + ], + "risks": [ + "risk-gw-admin-003" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-004", + "title": "Admin.RenewCert", + "order": 4, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-004", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-004/case.md", + "anchor": "tc-gw-admin-004" + }, + "requirements": [ + "req-gw-admin-004" + ], + "risks": [ + "risk-gw-admin-004" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-005", + "title": "Admin.ReloadCert", + "order": 5, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-005", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-005/case.md", + "anchor": "tc-gw-admin-005" + }, + "requirements": [ + "req-gw-admin-005" + ], + "risks": [ + "risk-gw-admin-005" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-006", + "title": "Admin.SetCaa", + "order": 6, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-006", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-006/case.md", + "anchor": "tc-gw-admin-006" + }, + "requirements": [ + "req-gw-admin-006" + ], + "risks": [ + "risk-gw-admin-006" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-007", + "title": "Admin.GetMeta", + "order": 7, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-007", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-007/case.md", + "anchor": "tc-gw-admin-007" + }, + "requirements": [ + "req-gw-admin-007" + ], + "risks": [ + "risk-gw-admin-007" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-008", + "title": "Admin.SetNodeUrl", + "order": 8, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-008", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-008/case.md", + "anchor": "tc-gw-admin-008" + }, + "requirements": [ + "req-gw-admin-008" + ], + "risks": [ + "risk-gw-admin-008" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-009", + "title": "Admin.SetNodeStatus", + "order": 9, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-009", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-009/case.md", + "anchor": "tc-gw-admin-009" + }, + "requirements": [ + "req-gw-admin-009" + ], + "risks": [ + "risk-gw-admin-009" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-010", + "title": "Admin.WaveKvStatus", + "order": 10, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-010", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-010/case.md", + "anchor": "tc-gw-admin-010" + }, + "requirements": [ + "req-gw-admin-010" + ], + "risks": [ + "risk-gw-admin-010" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-011", + "title": "Admin.GetInstanceHandshakes", + "order": 11, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-011", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-011/case.md", + "anchor": "tc-gw-admin-011" + }, + "requirements": [ + "req-gw-admin-011" + ], + "risks": [ + "risk-gw-admin-011" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-012", + "title": "Admin.GetGlobalConnections", + "order": 12, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-012", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-012/case.md", + "anchor": "tc-gw-admin-012" + }, + "requirements": [ + "req-gw-admin-012" + ], + "risks": [ + "risk-gw-admin-012" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-013", + "title": "Admin.GetNodeStatuses", + "order": 13, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-013", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-013/case.md", + "anchor": "tc-gw-admin-013" + }, + "requirements": [ + "req-gw-admin-013" + ], + "risks": [ + "risk-gw-admin-013" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-014", + "title": "Admin.ListDnsCredentials", + "order": 14, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-014", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-014/case.md", + "anchor": "tc-gw-admin-014" + }, + "requirements": [ + "req-gw-admin-014" + ], + "risks": [ + "risk-gw-admin-014" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-015", + "title": "Admin.GetDnsCredential", + "order": 15, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-015", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-015/case.md", + "anchor": "tc-gw-admin-015" + }, + "requirements": [ + "req-gw-admin-015" + ], + "risks": [ + "risk-gw-admin-015" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-016", + "title": "Admin.CreateDnsCredential", + "order": 16, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-016", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-016/case.md", + "anchor": "tc-gw-admin-016" + }, + "requirements": [ + "req-gw-admin-016" + ], + "risks": [ + "risk-gw-admin-016" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-017", + "title": "Admin.UpdateDnsCredential", + "order": 17, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-017", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-017/case.md", + "anchor": "tc-gw-admin-017" + }, + "requirements": [ + "req-gw-admin-017" + ], + "risks": [ + "risk-gw-admin-017" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-018", + "title": "Admin.DeleteDnsCredential", + "order": 18, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-018", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-018/case.md", + "anchor": "tc-gw-admin-018" + }, + "requirements": [ + "req-gw-admin-018" + ], + "risks": [ + "risk-gw-admin-018" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-019", + "title": "Admin.GetDefaultDnsCredential", + "order": 19, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-019", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-019/case.md", + "anchor": "tc-gw-admin-019" + }, + "requirements": [ + "req-gw-admin-019" + ], + "risks": [ + "risk-gw-admin-019" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-020", + "title": "Admin.SetDefaultDnsCredential", + "order": 20, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-020", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-020/case.md", + "anchor": "tc-gw-admin-020" + }, + "requirements": [ + "req-gw-admin-020" + ], + "risks": [ + "risk-gw-admin-020" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-021", + "title": "Admin.ListZtDomains", + "order": 21, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-021", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-021/case.md", + "anchor": "tc-gw-admin-021" + }, + "requirements": [ + "req-gw-admin-021" + ], + "risks": [ + "risk-gw-admin-021" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-022", + "title": "Admin.GetZtDomain", + "order": 22, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-022", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-022/case.md", + "anchor": "tc-gw-admin-022" + }, + "requirements": [ + "req-gw-admin-022" + ], + "risks": [ + "risk-gw-admin-022" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-023", + "title": "Admin.AddZtDomain", + "order": 23, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-023", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-023/case.md", + "anchor": "tc-gw-admin-023" + }, + "requirements": [ + "req-gw-admin-023" + ], + "risks": [ + "risk-gw-admin-023" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-024", + "title": "Admin.UpdateZtDomain", + "order": 24, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-024", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-024/case.md", + "anchor": "tc-gw-admin-024" + }, + "requirements": [ + "req-gw-admin-024" + ], + "risks": [ + "risk-gw-admin-024" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-025", + "title": "Admin.DeleteZtDomain", + "order": 25, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-025", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-025/case.md", + "anchor": "tc-gw-admin-025" + }, + "requirements": [ + "req-gw-admin-025" + ], + "risks": [ + "risk-gw-admin-025" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-026", + "title": "Admin.RenewZtDomainCert", + "order": 26, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-026", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-026/case.md", + "anchor": "tc-gw-admin-026" + }, + "requirements": [ + "req-gw-admin-026" + ], + "risks": [ + "risk-gw-admin-026" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-027", + "title": "Admin.ForceReleaseCertLock", + "order": 27, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-027", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-027/case.md", + "anchor": "tc-gw-admin-027" + }, + "requirements": [ + "req-gw-admin-027" + ], + "risks": [ + "risk-gw-admin-027" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-028", + "title": "Admin.ListCertAttestations", + "order": 28, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-028", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-028/case.md", + "anchor": "tc-gw-admin-028" + }, + "requirements": [ + "req-gw-admin-028" + ], + "risks": [ + "risk-gw-admin-028" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-029", + "title": "Admin.GetCertbotConfig", + "order": 29, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-029", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-029/case.md", + "anchor": "tc-gw-admin-029" + }, + "requirements": [ + "req-gw-admin-029" + ], + "risks": [ + "risk-gw-admin-029" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-030", + "title": "Admin.SetCertbotConfig", + "order": 30, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-030", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-030/case.md", + "anchor": "tc-gw-admin-030" + }, + "requirements": [ + "req-gw-admin-030" + ], + "risks": [ + "risk-gw-admin-030" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-031", + "title": "Admin.SetInstancePortPolicy", + "order": 31, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-031", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-031/case.md", + "anchor": "tc-gw-admin-031" + }, + "requirements": [ + "req-gw-admin-031" + ], + "risks": [ + "risk-gw-admin-031" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-032", + "title": "Admin.ClearInstancePortPolicy", + "order": 32, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-032", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-032/case.md", + "anchor": "tc-gw-admin-032" + }, + "requirements": [ + "req-gw-admin-032" + ], + "risks": [ + "risk-gw-admin-032" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + }, + { + "id": "tc-gw-admin-033", + "title": "Admin.GetInstancePortPolicy", + "order": 33, + "priority": "P1", + "path": "04-gateway/03-rpc-admin/tc-gw-admin-033", + "spec": { + "path": "04-gateway/03-rpc-admin/tc-gw-admin-033/case.md", + "anchor": "tc-gw-admin-033" + }, + "requirements": [ + "req-gw-admin-033" + ], + "risks": [ + "risk-gw-admin-033" + ], + "tags": [ + "gateway", + "admin-rpc" + ] + } + ] + }, + { + "id": "section-gateway-registration-wireguard-policy", + "title": "Registration Wireguard Policy", + "order": 4, + "path": "04-gateway/04-registration-wireguard-policy", + "cases": [ + { + "id": "tc-gw-registrati-001", + "title": "Attested CVM registration and re-registration", + "order": 1, + "priority": "P0", + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001", + "spec": { + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-001/case.md", + "anchor": "tc-gw-registrati-001" + }, + "requirements": [ + "req-gw-registrati-001" + ], + "risks": [ + "risk-gw-registrati-001" + ], + "tags": [ + "gateway", + "registration-wireguard-policy" + ] + }, + { + "id": "tc-gw-registrati-002", + "title": "WireGuard IP allocation and peer lifecycle", + "order": 2, + "priority": "P1", + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002", + "spec": { + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-002/case.md", + "anchor": "tc-gw-registrati-002" + }, + "requirements": [ + "req-gw-registrati-002" + ], + "risks": [ + "risk-gw-registrati-002" + ], + "tags": [ + "gateway", + "registration-wireguard-policy" + ] + }, + { + "id": "tc-gw-registrati-003", + "title": "Restrict-mode port enforcement", + "order": 3, + "priority": "P1", + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003", + "spec": { + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-003/case.md", + "anchor": "tc-gw-registrati-003" + }, + "requirements": [ + "req-gw-registrati-003" + ], + "risks": [ + "risk-gw-registrati-003" + ], + "tags": [ + "gateway", + "registration-wireguard-policy" + ] + }, + { + "id": "tc-gw-registrati-004", + "title": "Port policy fetch fallback compatibility", + "order": 4, + "priority": "P1", + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004", + "spec": { + "path": "04-gateway/04-registration-wireguard-policy/tc-gw-registrati-004/case.md", + "anchor": "tc-gw-registrati-004" + }, + "requirements": [ + "req-gw-registrati-004" + ], + "risks": [ + "risk-gw-registrati-004" + ], + "tags": [ + "gateway", + "registration-wireguard-policy" + ] + } + ] + }, + { + "id": "section-gateway-proxy-protocol-routing", + "title": "Proxy Protocol Routing", + "order": 5, + "path": "04-gateway/05-proxy-protocol-routing", + "cases": [ + { + "id": "tc-gw-proxy-prot-001", + "title": "Inbound Proxy Protocol v1/v2 parsing", + "order": 1, + "priority": "P1", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-001/case.md", + "anchor": "tc-gw-proxy-prot-001" + }, + "requirements": [ + "req-gw-proxy-prot-001" + ], + "risks": [ + "risk-gw-proxy-prot-001" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-proxy-prot-002", + "title": "Outbound Proxy Protocol per-port opt-in", + "order": 2, + "priority": "P1", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-002/case.md", + "anchor": "tc-gw-proxy-prot-002" + }, + "requirements": [ + "req-gw-proxy-prot-002" + ], + "risks": [ + "risk-gw-proxy-prot-002" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-proxy-prot-003", + "title": "TLS passthrough SNI address resolution", + "order": 3, + "priority": "P1", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-003/case.md", + "anchor": "tc-gw-proxy-prot-003" + }, + "requirements": [ + "req-gw-proxy-prot-003" + ], + "risks": [ + "risk-gw-proxy-prot-003" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-proxy-prot-004", + "title": "TLS termination routing and HTTP semantics", + "order": 4, + "priority": "P1", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-004/case.md", + "anchor": "tc-gw-proxy-prot-004" + }, + "requirements": [ + "req-gw-proxy-prot-004" + ], + "risks": [ + "risk-gw-proxy-prot-004" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-proxy-prot-005", + "title": "App-address namespace and content-addressed HTTPS", + "order": 5, + "priority": "P0", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-005/case.md", + "anchor": "tc-gw-proxy-prot-005" + }, + "requirements": [ + "req-gw-proxy-prot-005" + ], + "risks": [ + "risk-gw-proxy-prot-005" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-proxy-prot-006", + "title": "Connection limits timeouts and recycling", + "order": 6, + "priority": "P1", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-proxy-prot-006/case.md", + "anchor": "tc-gw-proxy-prot-006" + }, + "requirements": [ + "req-gw-proxy-prot-006" + ], + "risks": [ + "risk-gw-proxy-prot-006" + ], + "tags": [ + "gateway", + "proxy-protocol-routing" + ] + }, + { + "id": "tc-gw-select-007", + "title": "Top-N backend selection DNS cache and failover", + "order": 7, + "priority": "P0", + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-select-007", + "spec": { + "path": "04-gateway/05-proxy-protocol-routing/tc-gw-select-007/case.md", + "anchor": "tc-gw-select-007" + }, + "requirements": [ + "req-gw-select-007" + ], + "risks": [ + "risk-gw-select-007" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-gateway-certificates-dns", + "title": "Certificates Dns", + "order": 6, + "path": "04-gateway/06-certificates-dns", + "cases": [ + { + "id": "tc-gw-certificat-001", + "title": "ACME account bootstrap and persistence", + "order": 1, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-001", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-001/case.md", + "anchor": "tc-gw-certificat-001" + }, + "requirements": [ + "req-gw-certificat-001" + ], + "risks": [ + "risk-gw-certificat-001" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-002", + "title": "Distributed certificate issue renew and lock", + "order": 2, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-002", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-002/case.md", + "anchor": "tc-gw-certificat-002" + }, + "requirements": [ + "req-gw-certificat-002" + ], + "risks": [ + "risk-gw-certificat-002" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-003", + "title": "DNS credential CRUD and default selection", + "order": 3, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-003", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-003/case.md", + "anchor": "tc-gw-certificat-003" + }, + "requirements": [ + "req-gw-certificat-003" + ], + "risks": [ + "risk-gw-certificat-003" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-004", + "title": "ZT domain CRUD and certificate lifecycle", + "order": 4, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-004", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-004/case.md", + "anchor": "tc-gw-certificat-004" + }, + "requirements": [ + "req-gw-certificat-004" + ], + "risks": [ + "risk-gw-certificat-004" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-005", + "title": "CAA publication and validation", + "order": 5, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-005", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-005/case.md", + "anchor": "tc-gw-certificat-005" + }, + "requirements": [ + "req-gw-certificat-005" + ], + "risks": [ + "risk-gw-certificat-005" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-006", + "title": "Certificate store SNI wildcard and hot reload", + "order": 6, + "priority": "P1", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-006", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-006/case.md", + "anchor": "tc-gw-certificat-006" + }, + "requirements": [ + "req-gw-certificat-006" + ], + "risks": [ + "risk-gw-certificat-006" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + }, + { + "id": "tc-gw-certificat-007", + "title": "Certificate attestation history and ACME info", + "order": 7, + "priority": "P0", + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-007", + "spec": { + "path": "04-gateway/06-certificates-dns/tc-gw-certificat-007/case.md", + "anchor": "tc-gw-certificat-007" + }, + "requirements": [ + "req-gw-certificat-007" + ], + "risks": [ + "risk-gw-certificat-007" + ], + "tags": [ + "gateway", + "certificates-dns" + ] + } + ] + }, + { + "id": "section-gateway-cluster-admin-observability", + "title": "Cluster Admin Observability", + "order": 7, + "path": "04-gateway/07-cluster-admin-observability", + "cases": [ + { + "id": "tc-gw-cluster-ad-001", + "title": "WaveKV bootstrap replication and convergence", + "order": 1, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-001/case.md", + "anchor": "tc-gw-cluster-ad-001" + }, + "requirements": [ + "req-gw-cluster-ad-001" + ], + "risks": [ + "risk-gw-cluster-ad-001" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-002", + "title": "WaveKV sync endpoint authentication and replay", + "order": 2, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-002/case.md", + "anchor": "tc-gw-cluster-ad-002" + }, + "requirements": [ + "req-gw-cluster-ad-002" + ], + "risks": [ + "risk-gw-cluster-ad-002" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-003", + "title": "Node URL and status administration", + "order": 3, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-003/case.md", + "anchor": "tc-gw-cluster-ad-003" + }, + "requirements": [ + "req-gw-cluster-ad-003" + ], + "risks": [ + "risk-gw-cluster-ad-003" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-004", + "title": "Connection handshake and node statistics", + "order": 4, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-004/case.md", + "anchor": "tc-gw-cluster-ad-004" + }, + "requirements": [ + "req-gw-cluster-ad-004" + ], + "risks": [ + "risk-gw-cluster-ad-004" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-005", + "title": "Admin authentication and listener isolation", + "order": 5, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-005/case.md", + "anchor": "tc-gw-cluster-ad-005" + }, + "requirements": [ + "req-gw-cluster-ad-005" + ], + "risks": [ + "risk-gw-cluster-ad-005" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-006", + "title": "Debug service isolation", + "order": 6, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-006/case.md", + "anchor": "tc-gw-cluster-ad-006" + }, + "requirements": [ + "req-gw-cluster-ad-006" + ], + "risks": [ + "risk-gw-cluster-ad-006" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-007", + "title": "Health dashboard and graceful exit", + "order": 7, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-007/case.md", + "anchor": "tc-gw-cluster-ad-007" + }, + "requirements": [ + "req-gw-cluster-ad-007" + ], + "risks": [ + "risk-gw-cluster-ad-007" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-cluster-ad-008", + "title": "TLS crypto provider and protocol matrix", + "order": 8, + "priority": "P1", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-cluster-ad-008/case.md", + "anchor": "tc-gw-cluster-ad-008" + }, + "requirements": [ + "req-gw-cluster-ad-008" + ], + "risks": [ + "risk-gw-cluster-ad-008" + ], + "tags": [ + "gateway", + "cluster-admin-observability" + ] + }, + { + "id": "tc-gw-kv-009", + "title": "WaveKV key encoding corruption persistence and watch semantics", + "order": 9, + "priority": "P0", + "path": "04-gateway/07-cluster-admin-observability/tc-gw-kv-009", + "spec": { + "path": "04-gateway/07-cluster-admin-observability/tc-gw-kv-009/case.md", + "anchor": "tc-gw-kv-009" + }, + "requirements": [ + "req-gw-kv-009" + ], + "risks": [ + "risk-gw-kv-009" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-gateway-startup-auth-routing-internals", + "title": "Startup, Authorization, and Routing Internals", + "order": 8, + "path": "04-gateway/08-startup-auth-routing-internals", + "cases": [ + { + "id": "tc-gw-internal-001", + "title": "Gateway startup certificate mode and resource limits", + "order": 1, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-001/case.md", + "anchor": "tc-gw-internal-001" + }, + "requirements": [ + "req-gw-internal-001" + ], + "risks": [ + "risk-gw-internal-001" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-002", + "title": "Gateway debug key generation artifact safety", + "order": 2, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-002/case.md", + "anchor": "tc-gw-internal-002" + }, + "requirements": [ + "req-gw-internal-002" + ], + "risks": [ + "risk-gw-internal-002" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-003", + "title": "Gateway authorization client allow deny and outage", + "order": 3, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-003/case.md", + "anchor": "tc-gw-internal-003" + }, + "requirements": [ + "req-gw-internal-003" + ], + "risks": [ + "risk-gw-internal-003" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-004", + "title": "Raw TLS ClientHello SNI parser boundaries", + "order": 4, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-004/case.md", + "anchor": "tc-gw-internal-004" + }, + "requirements": [ + "req-gw-internal-004" + ], + "risks": [ + "risk-gw-internal-004" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-005", + "title": "TLS termination local routes and stream bridge", + "order": 5, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-005/case.md", + "anchor": "tc-gw-internal-005" + }, + "requirements": [ + "req-gw-internal-005" + ], + "risks": [ + "risk-gw-internal-005" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-006", + "title": "Port-policy filtering fetch retry and PP decision", + "order": 6, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-006/case.md", + "anchor": "tc-gw-internal-006" + }, + "requirements": [ + "req-gw-internal-006" + ], + "risks": [ + "risk-gw-internal-006" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-007", + "title": "Dashboard connection counters and policy provenance", + "order": 7, + "priority": "P1", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-007/case.md", + "anchor": "tc-gw-internal-007" + }, + "requirements": [ + "req-gw-internal-007" + ], + "risks": [ + "risk-gw-internal-007" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + }, + { + "id": "tc-gw-internal-008", + "title": "Combined route index RPC exposure", + "order": 8, + "priority": "P0", + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008", + "spec": { + "path": "04-gateway/08-startup-auth-routing-internals/tc-gw-internal-008/case.md", + "anchor": "tc-gw-internal-008" + }, + "requirements": [ + "req-gw-internal-008" + ], + "risks": [ + "risk-gw-internal-008" + ], + "tags": [ + "gw", + "startup-authorization-and-routing-internals" + ] + } + ] + }, + { + "id": "section-gateway-certbot-engine", + "title": "Certbot ACME and DNS Engine", + "order": 9, + "path": "04-gateway/09-certbot-engine", + "cases": [ + { + "id": "tc-gw-certbot-001", + "title": "ACME account creation load and credential persistence", + "order": 1, + "priority": "P0", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-001", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-001/case.md", + "anchor": "tc-gw-certbot-001" + }, + "requirements": [ + "req-gw-certbot-001" + ], + "risks": [ + "risk-gw-certbot-001" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + }, + { + "id": "tc-gw-certbot-002", + "title": "DNS-01 authorization propagation and cleanup", + "order": 2, + "priority": "P0", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-002", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-002/case.md", + "anchor": "tc-gw-certbot-002" + }, + "requirements": [ + "req-gw-certbot-002" + ], + "risks": [ + "risk-gw-certbot-002" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + }, + { + "id": "tc-gw-certbot-003", + "title": "Cloudflare DNS record API boundaries", + "order": 3, + "priority": "P0", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-003", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-003/case.md", + "anchor": "tc-gw-certbot-003" + }, + "requirements": [ + "req-gw-certbot-003" + ], + "risks": [ + "risk-gw-certbot-003" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + }, + { + "id": "tc-gw-certbot-004", + "title": "Certificate renewal threshold force and hook", + "order": 4, + "priority": "P0", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-004", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-004/case.md", + "anchor": "tc-gw-certbot-004" + }, + "requirements": [ + "req-gw-certbot-004" + ], + "risks": [ + "risk-gw-certbot-004" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + }, + { + "id": "tc-gw-certbot-005", + "title": "Certbot workdir archive live and rollback layout", + "order": 5, + "priority": "P0", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-005", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-005/case.md", + "anchor": "tc-gw-certbot-005" + }, + "requirements": [ + "req-gw-certbot-005" + ], + "risks": [ + "risk-gw-certbot-005" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + }, + { + "id": "tc-gw-certbot-006", + "title": "Certbot CLI once daemon config and signal lifecycle", + "order": 6, + "priority": "P1", + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-006", + "spec": { + "path": "04-gateway/09-certbot-engine/tc-gw-certbot-006/case.md", + "anchor": "tc-gw-certbot-006" + }, + "requirements": [ + "req-gw-certbot-006" + ], + "risks": [ + "risk-gw-certbot-006" + ], + "tags": [ + "gw", + "certbot-acme-and-dns-engine" + ] + } + ] + }, + { + "id": "section-gw-build", + "title": "Gateway, Certbot, Cluster Harness, and Existing Regression Suite", + "order": 10, + "path": "04-gateway/10-gw-build", + "cases": [ + { + "id": "tc-gw-build-001", + "title": "Gateway, Certbot, Cluster Harness, and Existing Regression Suite", + "order": 1, + "priority": "P0", + "path": "04-gateway/10-gw-build/tc-gw-build-001", + "spec": { + "path": "04-gateway/10-gw-build/tc-gw-build-001/case.md", + "anchor": "tc-gw-build-001" + }, + "requirements": [ + "req-gw-build-001" + ], + "risks": [ + "risk-gw-build-001" + ], + "tags": [ + "build", + "regression" + ] + } + ] + } + ] + }, + { + "id": "chapter-verifier", + "title": "Verifier", + "order": 5, + "path": "05-verifier", + "sections": [ + { + "id": "section-verifier-input-platform-verification", + "title": "Input Platform Verification", + "order": 1, + "path": "05-verifier/01-input-platform-verification", + "cases": [ + { + "id": "tc-ver-input-plat-001", + "title": "Verification input precedence and canonicalization", + "order": 1, + "priority": "P1", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-001", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-001/case.md", + "anchor": "tc-ver-input-plat-001" + }, + "requirements": [ + "req-ver-input-plat-001" + ], + "risks": [ + "risk-ver-input-plat-001" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-002", + "title": "TDX quote signature collateral and TCB", + "order": 2, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-002", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-002/case.md", + "anchor": "tc-ver-input-plat-002" + }, + "requirements": [ + "req-ver-input-plat-002" + ], + "risks": [ + "risk-ver-input-plat-002" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-003", + "title": "TDX event log replay and RTMR status", + "order": 3, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-003", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-003/case.md", + "anchor": "tc-ver-input-plat-003" + }, + "requirements": [ + "req-ver-input-plat-003" + ], + "risks": [ + "risk-ver-input-plat-003" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-004", + "title": "TDX-lite measurement verification", + "order": 4, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-004", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-004/case.md", + "anchor": "tc-ver-input-plat-004" + }, + "requirements": [ + "req-ver-input-plat-004" + ], + "risks": [ + "risk-ver-input-plat-004" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-005", + "title": "SEV-SNP certificate and report verification", + "order": 5, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-005", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-005/case.md", + "anchor": "tc-ver-input-plat-005" + }, + "requirements": [ + "req-ver-input-plat-005" + ], + "risks": [ + "risk-ver-input-plat-005" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-006", + "title": "Cloud TDX and Nitro TPM verification", + "order": 6, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-006", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-006/case.md", + "anchor": "tc-ver-input-plat-006" + }, + "requirements": [ + "req-ver-input-plat-006" + ], + "risks": [ + "risk-ver-input-plat-006" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-input-plat-007", + "title": "Simulated attestation labeling", + "order": 7, + "priority": "P1", + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-007", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-input-plat-007/case.md", + "anchor": "tc-ver-input-plat-007" + }, + "requirements": [ + "req-ver-input-plat-007" + ], + "risks": [ + "risk-ver-input-plat-007" + ], + "tags": [ + "verifier", + "input-platform-verification" + ] + }, + { + "id": "tc-ver-nitro-008", + "title": "Nitro Enclave document verification and debug rejection", + "order": 8, + "priority": "P0", + "path": "05-verifier/01-input-platform-verification/tc-ver-nitro-008", + "spec": { + "path": "05-verifier/01-input-platform-verification/tc-ver-nitro-008/case.md", + "anchor": "tc-ver-nitro-008" + }, + "requirements": [ + "req-ver-nitro-008" + ], + "risks": [ + "risk-ver-nitro-008" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-verifier-image-measurements", + "title": "Image Measurements", + "order": 2, + "path": "05-verifier/02-image-measurements", + "cases": [ + { + "id": "tc-ver-image-meas-001", + "title": "Image download digest and extraction security", + "order": 1, + "priority": "P1", + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-001", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-001/case.md", + "anchor": "tc-ver-image-meas-001" + }, + "requirements": [ + "req-ver-image-meas-001" + ], + "risks": [ + "risk-ver-image-meas-001" + ], + "tags": [ + "verifier", + "image-measurements" + ] + }, + { + "id": "tc-ver-image-meas-002", + "title": "Measurement computation determinism", + "order": 2, + "priority": "P1", + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-002", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-002/case.md", + "anchor": "tc-ver-image-meas-002" + }, + "requirements": [ + "req-ver-image-meas-002" + ], + "risks": [ + "risk-ver-image-meas-002" + ], + "tags": [ + "verifier", + "image-measurements" + ] + }, + { + "id": "tc-ver-image-meas-003", + "title": "ACPI table measurement and swtpm policy", + "order": 3, + "priority": "P1", + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-003", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-003/case.md", + "anchor": "tc-ver-image-meas-003" + }, + "requirements": [ + "req-ver-image-meas-003" + ], + "risks": [ + "risk-ver-image-meas-003" + ], + "tags": [ + "verifier", + "image-measurements" + ] + }, + { + "id": "tc-ver-image-meas-004", + "title": "Artifact manifest and image hash binding", + "order": 4, + "priority": "P1", + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-004", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-004/case.md", + "anchor": "tc-ver-image-meas-004" + }, + "requirements": [ + "req-ver-image-meas-004" + ], + "risks": [ + "risk-ver-image-meas-004" + ], + "tags": [ + "verifier", + "image-measurements" + ] + }, + { + "id": "tc-ver-image-meas-005", + "title": "Measurement cache correctness and concurrency", + "order": 5, + "priority": "P1", + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-005", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-image-meas-005/case.md", + "anchor": "tc-ver-image-meas-005" + }, + "requirements": [ + "req-ver-image-meas-005" + ], + "risks": [ + "risk-ver-image-meas-005" + ], + "tags": [ + "verifier", + "image-measurements" + ] + }, + { + "id": "tc-ver-strategy-006", + "title": "Platform-specific OS image verification and download strategy", + "order": 6, + "priority": "P0", + "path": "05-verifier/02-image-measurements/tc-ver-strategy-006", + "spec": { + "path": "05-verifier/02-image-measurements/tc-ver-strategy-006/case.md", + "anchor": "tc-ver-strategy-006" + }, + "requirements": [ + "req-ver-strategy-006" + ], + "risks": [ + "risk-ver-strategy-006" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-verifier-cli-cert-output", + "title": "Cli Cert Output", + "order": 3, + "path": "05-verifier/03-cli-cert-output", + "cases": [ + { + "id": "tc-ver-cli-cert-o-001", + "title": "One-shot JSON verification interface", + "order": 1, + "priority": "P1", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-001/case.md", + "anchor": "tc-ver-cli-cert-o-001" + }, + "requirements": [ + "req-ver-cli-cert-o-001" + ], + "risks": [ + "risk-ver-cli-cert-o-001" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-cli-cert-o-002", + "title": "Certificate RA extension verification", + "order": 2, + "priority": "P0", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-002/case.md", + "anchor": "tc-ver-cli-cert-o-002" + }, + "requirements": [ + "req-ver-cli-cert-o-002" + ], + "risks": [ + "risk-ver-cli-cert-o-002" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-cli-cert-o-003", + "title": "OS image hash verification modes", + "order": 3, + "priority": "P1", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-003/case.md", + "anchor": "tc-ver-cli-cert-o-003" + }, + "requirements": [ + "req-ver-cli-cert-o-003" + ], + "risks": [ + "risk-ver-cli-cert-o-003" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-cli-cert-o-004", + "title": "Result schema completeness and diagnostics", + "order": 4, + "priority": "P1", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-004/case.md", + "anchor": "tc-ver-cli-cert-o-004" + }, + "requirements": [ + "req-ver-cli-cert-o-004" + ], + "risks": [ + "risk-ver-cli-cert-o-004" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-cli-cert-o-005", + "title": "Configuration validation and trust roots", + "order": 5, + "priority": "P1", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-005/case.md", + "anchor": "tc-ver-cli-cert-o-005" + }, + "requirements": [ + "req-ver-cli-cert-o-005" + ], + "risks": [ + "risk-ver-cli-cert-o-005" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-cli-cert-o-006", + "title": "Offline fixtures regression suite", + "order": 6, + "priority": "P1", + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-cli-cert-o-006/case.md", + "anchor": "tc-ver-cli-cert-o-006" + }, + "requirements": [ + "req-ver-cli-cert-o-006" + ], + "risks": [ + "risk-ver-cli-cert-o-006" + ], + "tags": [ + "verifier", + "cli-cert-output" + ] + }, + { + "id": "tc-ver-tcb-007", + "title": "Canonical TCB status advisory and auth-policy projection", + "order": 7, + "priority": "P0", + "path": "05-verifier/03-cli-cert-output/tc-ver-tcb-007", + "spec": { + "path": "05-verifier/03-cli-cert-output/tc-ver-tcb-007/case.md", + "anchor": "tc-ver-tcb-007" + }, + "requirements": [ + "req-ver-tcb-007" + ], + "risks": [ + "risk-ver-tcb-007" + ], + "tags": [ + "semantic-review" + ] + } + ] + }, + { + "id": "section-verifier-measurement-tools", + "title": "Measurement Tools and Library APIs", + "order": 4, + "path": "05-verifier/04-measurement-tools", + "cases": [ + { + "id": "tc-ver-tools-001", + "title": "dstack-mr supported platform CLI matrix", + "order": 1, + "priority": "P0", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-001", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-001/case.md", + "anchor": "tc-ver-tools-001" + }, + "requirements": [ + "req-ver-tools-001" + ], + "risks": [ + "risk-ver-tools-001" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + }, + { + "id": "tc-ver-tools-002", + "title": "dstack-mr boot artifact and cmdline boundaries", + "order": 2, + "priority": "P0", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-002", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-002/case.md", + "anchor": "tc-ver-tools-002" + }, + "requirements": [ + "req-ver-tools-002" + ], + "risks": [ + "risk-ver-tools-002" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + }, + { + "id": "tc-ver-tools-003", + "title": "Attestation encode decode round trip and versioning", + "order": 3, + "priority": "P0", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-003", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-003/case.md", + "anchor": "tc-ver-tools-003" + }, + "requirements": [ + "req-ver-tools-003" + ], + "risks": [ + "risk-ver-tools-003" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + }, + { + "id": "tc-ver-tools-004", + "title": "Verifier library concurrent API isolation", + "order": 4, + "priority": "P1", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-004", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-004/case.md", + "anchor": "tc-ver-tools-004" + }, + "requirements": [ + "req-ver-tools-004" + ], + "risks": [ + "risk-ver-tools-004" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + }, + { + "id": "tc-ver-tools-005", + "title": "Collateral and trust-root update lifecycle", + "order": 5, + "priority": "P0", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-005", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-005/case.md", + "anchor": "tc-ver-tools-005" + }, + "requirements": [ + "req-ver-tools-005" + ], + "risks": [ + "risk-ver-tools-005" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + }, + { + "id": "tc-ver-tools-006", + "title": "Verifier denial-of-service input limits", + "order": 6, + "priority": "P0", + "path": "05-verifier/04-measurement-tools/tc-ver-tools-006", + "spec": { + "path": "05-verifier/04-measurement-tools/tc-ver-tools-006/case.md", + "anchor": "tc-ver-tools-006" + }, + "requirements": [ + "req-ver-tools-006" + ], + "risks": [ + "risk-ver-tools-006" + ], + "tags": [ + "ver", + "measurement-tools-and-library-apis" + ] + } + ] + }, + { + "id": "section-verifier-build-deployment", + "title": "Verifier Build and Deployment", + "order": 5, + "path": "05-verifier/05-build-deployment", + "cases": [ + { + "id": "tc-ver-build-001", + "title": "Verifier image build pinning and runtime contents", + "order": 1, + "priority": "P0", + "path": "05-verifier/05-build-deployment/tc-ver-build-001", + "spec": { + "path": "05-verifier/05-build-deployment/tc-ver-build-001/case.md", + "anchor": "tc-ver-build-001" + }, + "requirements": [ + "req-ver-build-001" + ], + "risks": [ + "risk-ver-build-001" + ], + "tags": [ + "ver", + "verifier-build-and-deployment" + ] + }, + { + "id": "tc-ver-build-002", + "title": "Verifier default configuration and CLI override precedence", + "order": 2, + "priority": "P0", + "path": "05-verifier/05-build-deployment/tc-ver-build-002", + "spec": { + "path": "05-verifier/05-build-deployment/tc-ver-build-002/case.md", + "anchor": "tc-ver-build-002" + }, + "requirements": [ + "req-ver-build-002" + ], + "risks": [ + "risk-ver-build-002" + ], + "tags": [ + "ver", + "verifier-build-and-deployment" + ] + } + ] + }, + { + "id": "section-ver-buildall", + "title": "Verifier and Measurement Tool Existing Regression Suite", + "order": 6, + "path": "05-verifier/06-ver-buildall", + "cases": [ + { + "id": "tc-ver-buildall-001", + "title": "Verifier and Measurement Tool Existing Regression Suite", + "order": 1, + "priority": "P0", + "path": "05-verifier/06-ver-buildall/tc-ver-buildall-001", + "spec": { + "path": "05-verifier/06-ver-buildall/tc-ver-buildall-001/case.md", + "anchor": "tc-ver-buildall-001" + }, + "requirements": [ + "req-ver-buildall-001" + ], + "risks": [ + "risk-ver-buildall-001" + ], + "tags": [ + "build", + "regression" + ] + } + ] + } + ] + }, + { + "id": "chapter-integration", + "title": "Cross-component and Compatibility", + "order": 6, + "path": "06-integration", + "sections": [ + { + "id": "section-integration-end-to-end", + "title": "End To End", + "order": 1, + "path": "06-integration/01-end-to-end", + "cases": [ + { + "id": "tc-int-end-to-end-001", + "title": "New application deployment trust chain", + "order": 1, + "priority": "P0", + "path": "06-integration/01-end-to-end/tc-int-end-to-end-001", + "spec": { + "path": "06-integration/01-end-to-end/tc-int-end-to-end-001/case.md", + "anchor": "tc-int-end-to-end-001" + }, + "requirements": [ + "req-int-end-to-end-001" + ], + "risks": [ + "risk-int-end-to-end-001" + ], + "tags": [ + "integration", + "end-to-end" + ] + }, + { + "id": "tc-int-end-to-end-002", + "title": "Application upgrade trust continuity", + "order": 2, + "priority": "P0", + "path": "06-integration/01-end-to-end/tc-int-end-to-end-002", + "spec": { + "path": "06-integration/01-end-to-end/tc-int-end-to-end-002/case.md", + "anchor": "tc-int-end-to-end-002" + }, + "requirements": [ + "req-int-end-to-end-002" + ], + "risks": [ + "risk-int-end-to-end-002" + ], + "tags": [ + "integration", + "end-to-end" + ] + }, + { + "id": "tc-int-end-to-end-003", + "title": "Encrypted environment delivery", + "order": 3, + "priority": "P0", + "path": "06-integration/01-end-to-end/tc-int-end-to-end-003", + "spec": { + "path": "06-integration/01-end-to-end/tc-int-end-to-end-003/case.md", + "anchor": "tc-int-end-to-end-003" + }, + "requirements": [ + "req-int-end-to-end-003" + ], + "risks": [ + "risk-int-end-to-end-003" + ], + "tags": [ + "integration", + "end-to-end" + ] + }, + { + "id": "tc-int-end-to-end-004", + "title": "Gateway certificate attestation verification", + "order": 4, + "priority": "P0", + "path": "06-integration/01-end-to-end/tc-int-end-to-end-004", + "spec": { + "path": "06-integration/01-end-to-end/tc-int-end-to-end-004/case.md", + "anchor": "tc-int-end-to-end-004" + }, + "requirements": [ + "req-int-end-to-end-004" + ], + "risks": [ + "risk-int-end-to-end-004" + ], + "tags": [ + "integration", + "end-to-end" + ] + }, + { + "id": "tc-int-end-to-end-005", + "title": "Multi-instance load balancing and isolation", + "order": 5, + "priority": "P0", + "path": "06-integration/01-end-to-end/tc-int-end-to-end-005", + "spec": { + "path": "06-integration/01-end-to-end/tc-int-end-to-end-005/case.md", + "anchor": "tc-int-end-to-end-005" + }, + "requirements": [ + "req-int-end-to-end-005" + ], + "risks": [ + "risk-int-end-to-end-005" + ], + "tags": [ + "integration", + "end-to-end" + ] + } + ] + }, + { + "id": "section-integration-compatibility-upgrade", + "title": "Compatibility Upgrade", + "order": 2, + "path": "06-integration/02-compatibility-upgrade", + "cases": [ + { + "id": "tc-int-compatibil-001", + "title": "Persisted state migration from v0.5.4, v0.5.8, and v0.5.11", + "order": 1, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-001", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-001/case.md", + "anchor": "tc-int-compatibil-001" + }, + "requirements": [ + "req-int-compatibil-001" + ], + "risks": [ + "risk-int-compatibil-001" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + }, + { + "id": "tc-int-compatibil-002", + "title": "Rolling VMM upgrade with running mixed guests", + "order": 2, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-002", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-002/case.md", + "anchor": "tc-int-compatibil-002" + }, + "requirements": [ + "req-int-compatibil-002" + ], + "risks": [ + "risk-int-compatibil-002" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + }, + { + "id": "tc-int-compatibil-003", + "title": "Rolling KMS cluster upgrade and key continuity", + "order": 3, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-003", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-003/case.md", + "anchor": "tc-int-compatibil-003" + }, + "requirements": [ + "req-int-compatibil-003" + ], + "risks": [ + "risk-int-compatibil-003" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + }, + { + "id": "tc-int-compatibil-004", + "title": "Rolling gateway cluster upgrade", + "order": 4, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-004", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-004/case.md", + "anchor": "tc-int-compatibil-004" + }, + "requirements": [ + "req-int-compatibil-004" + ], + "risks": [ + "risk-int-compatibil-004" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + }, + { + "id": "tc-int-compatibil-005", + "title": "Verifier compatibility across evidence versions", + "order": 5, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-005", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-005/case.md", + "anchor": "tc-int-compatibil-005" + }, + "requirements": [ + "req-int-compatibil-005" + ], + "risks": [ + "risk-int-compatibil-005" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + }, + { + "id": "tc-int-compatibil-006", + "title": "RPC unknown-field and optional-field compatibility", + "order": 6, + "priority": "P0", + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-006", + "spec": { + "path": "06-integration/02-compatibility-upgrade/tc-int-compatibil-006/case.md", + "anchor": "tc-int-compatibil-006" + }, + "requirements": [ + "req-int-compatibil-006" + ], + "risks": [ + "risk-int-compatibil-006" + ], + "tags": [ + "integration", + "compatibility-upgrade" + ] + } + ] + }, + { + "id": "section-integration-failure-security", + "title": "Failure Security", + "order": 3, + "path": "06-integration/03-failure-security", + "cases": [ + { + "id": "tc-int-failure-se-001", + "title": "KMS unavailable during boot and recovery", + "order": 1, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-001", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-001/case.md", + "anchor": "tc-int-failure-se-001" + }, + "requirements": [ + "req-int-failure-se-001" + ], + "risks": [ + "risk-int-failure-se-001" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-002", + "title": "Gateway unavailable registration and recovery", + "order": 2, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-002", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-002/case.md", + "anchor": "tc-int-failure-se-002" + }, + "requirements": [ + "req-int-failure-se-002" + ], + "risks": [ + "risk-int-failure-se-002" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-003", + "title": "VMM crash during every lifecycle transaction", + "order": 3, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-003", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-003/case.md", + "anchor": "tc-int-failure-se-003" + }, + "requirements": [ + "req-int-failure-se-003" + ], + "risks": [ + "risk-int-failure-se-003" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-004", + "title": "Certificate and clock boundary behavior", + "order": 4, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-004", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-004/case.md", + "anchor": "tc-int-failure-se-004" + }, + "requirements": [ + "req-int-failure-se-004" + ], + "risks": [ + "risk-int-failure-se-004" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-005", + "title": "Credential and secret redaction audit", + "order": 5, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-005", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-005/case.md", + "anchor": "tc-int-failure-se-005" + }, + "requirements": [ + "req-int-failure-se-005" + ], + "risks": [ + "risk-int-failure-se-005" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-006", + "title": "Resource exhaustion and backpressure", + "order": 6, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-006", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-006/case.md", + "anchor": "tc-int-failure-se-006" + }, + "requirements": [ + "req-int-failure-se-006" + ], + "risks": [ + "risk-int-failure-se-006" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-007", + "title": "Network partition consistency matrix", + "order": 7, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-007", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-007/case.md", + "anchor": "tc-int-failure-se-007" + }, + "requirements": [ + "req-int-failure-se-007" + ], + "risks": [ + "risk-int-failure-se-007" + ], + "tags": [ + "integration", + "failure-security" + ] + }, + { + "id": "tc-int-failure-se-008", + "title": "Simulator versus hardware evidence separation", + "order": 8, + "priority": "P0", + "path": "06-integration/03-failure-security/tc-int-failure-se-008", + "spec": { + "path": "06-integration/03-failure-security/tc-int-failure-se-008/case.md", + "anchor": "tc-int-failure-se-008" + }, + "requirements": [ + "req-int-failure-se-008" + ], + "risks": [ + "risk-int-failure-se-008" + ], + "tags": [ + "integration", + "failure-security" + ] + } + ] + }, + { + "id": "section-integration-pinned-mixed-version-matrix", + "title": "Pinned Mixed-Version Online Matrix", + "order": 4, + "path": "06-integration/04-pinned-mixed-version-matrix", + "cases": [ + { + "id": "tc-int-mixed-001", + "title": "Latest VMM hosts the full pinned guest matrix", + "order": 1, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-001/case.md", + "anchor": "tc-int-mixed-001" + }, + "requirements": [ + "req-int-mixed-001" + ], + "risks": [ + "risk-int-mixed-001" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-002", + "title": "Mixed KMS versions remain online during application operations", + "order": 2, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-002/case.md", + "anchor": "tc-int-mixed-002" + }, + "requirements": [ + "req-int-mixed-002" + ], + "risks": [ + "risk-int-mixed-002" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-003", + "title": "Mixed gateway versions route old and new guests", + "order": 3, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-003/case.md", + "anchor": "tc-int-mixed-003" + }, + "requirements": [ + "req-int-mixed-003" + ], + "risks": [ + "risk-int-mixed-003" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-004", + "title": "Gateway replacement matrix after KMS cutover", + "order": 4, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-004/case.md", + "anchor": "tc-int-mixed-004" + }, + "requirements": [ + "req-int-mixed-004" + ], + "risks": [ + "risk-int-mixed-004" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-005", + "title": "Verifier evidence compatibility for pinned releases", + "order": 5, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md", + "anchor": "tc-int-mixed-005" + }, + "requirements": [ + "req-int-mixed-005" + ], + "risks": [ + "risk-int-mixed-005" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-006", + "title": "Rolling restart under four-version online mix", + "order": 6, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md", + "anchor": "tc-int-mixed-006" + }, + "requirements": [ + "req-int-mixed-006" + ], + "risks": [ + "risk-int-mixed-006" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + }, + { + "id": "tc-int-mixed-007", + "title": "Optional and unknown protobuf fields across pinned versions", + "order": 7, + "priority": "P0", + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007", + "spec": { + "path": "06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md", + "anchor": "tc-int-mixed-007" + }, + "requirements": [ + "req-int-mixed-007" + ], + "risks": [ + "risk-int-mixed-007" + ], + "tags": [ + "kms", + "upgrade", + "compatibility" + ] + } + ] + } + ] + } + ] +} diff --git a/docs/test-plans/core-components-full/source-coverage-map.json b/docs/test-plans/core-components-full/source-coverage-map.json new file mode 100644 index 000000000..f641ee88a --- /dev/null +++ b/docs/test-plans/core-components-full/source-coverage-map.json @@ -0,0 +1,7747 @@ +{ + "schema_version": "1.0", + "description": "Reverse traceability from every inventoried non-vendor repository file to one or more test cases. A generic build mapping is used only for manifests/generated/support files without independent runtime behavior.", + "entries": [ + { + "component": "gateway", + "source": "dstack/certbot/.gitignore", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/Cargo.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "gateway", + "source": "dstack/certbot/cli/Cargo.toml", + "case_ids": [ + "tc-gw-certbot-006", + "tc-gw-build-001" + ], + "rationale": "certbot CLI behavior; component build/generated/existing-test gate" + }, + { + "component": "gateway", + "source": "dstack/certbot/cli/src/main.rs", + "case_ids": [ + "tc-gw-certbot-006" + ], + "rationale": "direct source reference; certbot CLI behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/acme_client.rs", + "case_ids": [ + "tc-gw-certbot-002", + "tc-gw-certbot-001", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "direct source reference; certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/acme_client/tests.rs", + "case_ids": [ + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/bot.rs", + "case_ids": [ + "tc-gw-certbot-004", + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-005" + ], + "rationale": "direct source reference; certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/bot/tests.rs", + "case_ids": [ + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/dns01_client.rs", + "case_ids": [ + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/dns01_client/cloudflare.rs", + "case_ids": [ + "tc-gw-certbot-003", + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "direct source reference; certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/http_client.rs", + "case_ids": [ + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/lib.rs", + "case_ids": [ + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004", + "tc-gw-certbot-005" + ], + "rationale": "certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/certbot/src/workdir.rs", + "case_ids": [ + "tc-gw-certbot-005", + "tc-gw-certbot-001", + "tc-gw-certbot-002", + "tc-gw-certbot-003", + "tc-gw-certbot-004" + ], + "rationale": "direct source reference; certbot engine behavior" + }, + { + "component": "gateway", + "source": "dstack/ct_monitor/Cargo.toml", + "case_ids": [ + "tc-gw-certificat-007", + "tc-gw-build-001" + ], + "rationale": "certificate transparency monitoring" + }, + { + "component": "gateway", + "source": "dstack/ct_monitor/src/main.rs", + "case_ids": [ + "tc-gw-certificat-007", + "tc-gw-build-001" + ], + "rationale": "certificate transparency monitoring" + }, + { + "component": "gateway", + "source": "dstack/gateway/Cargo.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "gateway", + "source": "dstack/gateway/assets/cert.key", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/assets/cert.pem", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/docs/cluster-deployment.md", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/.gitignore", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/bootstrap-cluster.sh", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/Dockerfile", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/README.md", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/build-image.sh", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/entrypoint.sh", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/shared/builder-pinned-packages.txt", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/builder/shared/pinned-packages.txt", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/deploy-to-vmm.sh", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/dstack-app/docker-compose.yaml", + "case_ids": [ + "tc-gw-build-001", + "tc-int-mixed-004" + ], + "rationale": "direct source reference; gateway packaging and deployment" + }, + { + "component": "gateway", + "source": "dstack/gateway/gateway.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/rpc/Cargo.toml", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-gateway-001", + "tc-gw-gateway-002", + "tc-gw-gateway-003", + "tc-gw-gateway-004", + "tc-gw-debug-001", + "tc-gw-debug-002", + "tc-gw-debug-003", + "tc-gw-debug-004", + "tc-gw-admin-001", + "tc-gw-admin-002", + "tc-gw-admin-003", + "tc-gw-admin-004", + "tc-gw-admin-005", + "tc-gw-admin-006", + "tc-gw-admin-007", + "tc-gw-admin-008", + "tc-gw-admin-009", + "tc-gw-admin-010", + "tc-gw-admin-011", + "tc-gw-admin-012", + "tc-gw-admin-013", + "tc-gw-admin-014", + "tc-gw-admin-015", + "tc-gw-admin-016", + "tc-gw-admin-017", + "tc-gw-admin-018", + "tc-gw-admin-019", + "tc-gw-admin-020", + "tc-gw-admin-021", + "tc-gw-admin-022", + "tc-gw-admin-023", + "tc-gw-admin-024", + "tc-gw-admin-025", + "tc-gw-admin-026", + "tc-gw-admin-027", + "tc-gw-admin-028", + "tc-gw-admin-029", + "tc-gw-admin-030", + "tc-gw-admin-031", + "tc-gw-admin-032", + "tc-gw-admin-033" + ], + "rationale": "direct source reference; gateway RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "gateway", + "source": "dstack/gateway/rpc/build.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-gateway-001", + "tc-gw-gateway-002", + "tc-gw-gateway-003", + "tc-gw-gateway-004", + "tc-gw-debug-001", + "tc-gw-debug-002", + "tc-gw-debug-003", + "tc-gw-debug-004", + "tc-gw-admin-001", + "tc-gw-admin-002", + "tc-gw-admin-003", + "tc-gw-admin-004", + "tc-gw-admin-005", + "tc-gw-admin-006", + "tc-gw-admin-007", + "tc-gw-admin-008", + "tc-gw-admin-009", + "tc-gw-admin-010", + "tc-gw-admin-011", + "tc-gw-admin-012", + "tc-gw-admin-013", + "tc-gw-admin-014", + "tc-gw-admin-015", + "tc-gw-admin-016", + "tc-gw-admin-017", + "tc-gw-admin-018", + "tc-gw-admin-019", + "tc-gw-admin-020", + "tc-gw-admin-021", + "tc-gw-admin-022", + "tc-gw-admin-023", + "tc-gw-admin-024", + "tc-gw-admin-025", + "tc-gw-admin-026", + "tc-gw-admin-027", + "tc-gw-admin-028", + "tc-gw-admin-029", + "tc-gw-admin-030", + "tc-gw-admin-031", + "tc-gw-admin-032", + "tc-gw-admin-033" + ], + "rationale": "direct source reference; gateway RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "gateway", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-debug-001", + "tc-gw-debug-004", + "tc-gw-debug-003", + "tc-gw-debug-002", + "tc-gw-admin-013", + "tc-gw-admin-026", + "tc-gw-admin-022", + "tc-gw-admin-015", + "tc-gw-admin-024", + "tc-gw-admin-023", + "tc-gw-admin-018", + "tc-gw-admin-020", + "tc-gw-admin-012", + "tc-gw-admin-025", + "tc-gw-admin-030", + "tc-gw-admin-003", + "tc-gw-admin-014", + "tc-gw-admin-021", + "tc-gw-admin-017", + "tc-gw-admin-004", + "tc-gw-admin-007", + "tc-gw-admin-002", + "tc-gw-admin-016", + "tc-gw-admin-006", + "tc-gw-admin-001", + "tc-gw-admin-009", + "tc-gw-admin-029", + "tc-gw-admin-031", + "tc-gw-admin-008", + "tc-gw-admin-033", + "tc-gw-admin-010", + "tc-gw-admin-027", + "tc-gw-admin-011", + "tc-gw-admin-032", + "tc-gw-admin-028", + "tc-gw-admin-005", + "tc-gw-admin-019", + "tc-gw-gateway-003", + "tc-gw-gateway-001", + "tc-gw-gateway-002", + "tc-gw-gateway-004" + ], + "rationale": "direct source reference; gateway RPC generated contract" + }, + { + "component": "gateway", + "source": "dstack/gateway/rpc/src/generated.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-gateway-001", + "tc-gw-gateway-002", + "tc-gw-gateway-003", + "tc-gw-gateway-004", + "tc-gw-debug-001", + "tc-gw-debug-002", + "tc-gw-debug-003", + "tc-gw-debug-004", + "tc-gw-admin-001", + "tc-gw-admin-002", + "tc-gw-admin-003", + "tc-gw-admin-004", + "tc-gw-admin-005", + "tc-gw-admin-006", + "tc-gw-admin-007", + "tc-gw-admin-008", + "tc-gw-admin-009", + "tc-gw-admin-010", + "tc-gw-admin-011", + "tc-gw-admin-012", + "tc-gw-admin-013", + "tc-gw-admin-014", + "tc-gw-admin-015", + "tc-gw-admin-016", + "tc-gw-admin-017", + "tc-gw-admin-018", + "tc-gw-admin-019", + "tc-gw-admin-020", + "tc-gw-admin-021", + "tc-gw-admin-022", + "tc-gw-admin-023", + "tc-gw-admin-024", + "tc-gw-admin-025", + "tc-gw-admin-026", + "tc-gw-admin-027", + "tc-gw-admin-028", + "tc-gw-admin-029", + "tc-gw-admin-030", + "tc-gw-admin-031", + "tc-gw-admin-032", + "tc-gw-admin-033" + ], + "rationale": "direct source reference; gateway RPC generated contract" + }, + { + "component": "gateway", + "source": "dstack/gateway/rpc/src/lib.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-gateway-001", + "tc-gw-gateway-002", + "tc-gw-gateway-003", + "tc-gw-gateway-004", + "tc-gw-debug-001", + "tc-gw-debug-002", + "tc-gw-debug-003", + "tc-gw-debug-004", + "tc-gw-admin-001", + "tc-gw-admin-002", + "tc-gw-admin-003", + "tc-gw-admin-004", + "tc-gw-admin-005", + "tc-gw-admin-006", + "tc-gw-admin-007", + "tc-gw-admin-008", + "tc-gw-admin-009", + "tc-gw-admin-010", + "tc-gw-admin-011", + "tc-gw-admin-012", + "tc-gw-admin-013", + "tc-gw-admin-014", + "tc-gw-admin-015", + "tc-gw-admin-016", + "tc-gw-admin-017", + "tc-gw-admin-018", + "tc-gw-admin-019", + "tc-gw-admin-020", + "tc-gw-admin-021", + "tc-gw-admin-022", + "tc-gw-admin-023", + "tc-gw-admin-024", + "tc-gw-admin-025", + "tc-gw-admin-026", + "tc-gw-admin-027", + "tc-gw-admin-028", + "tc-gw-admin-029", + "tc-gw-admin-030", + "tc-gw-admin-031", + "tc-gw-admin-032", + "tc-gw-admin-033" + ], + "rationale": "direct source reference; gateway RPC generated contract" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/admin_auth.rs", + "case_ids": [ + "tc-gw-cluster-ad-005", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/admin_service.rs", + "case_ids": [ + "tc-gw-certificat-005", + "tc-gw-certificat-003", + "tc-gw-certificat-004", + "tc-gw-cluster-ad-003", + "tc-gw-cluster-ad-004", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/cert_store.rs", + "case_ids": [ + "tc-gw-certificat-006", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/config.rs", + "case_ids": [ + "tc-gw-cluster-ad-008", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/debug_service.rs", + "case_ids": [ + "tc-gw-cluster-ad-006", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/distributed_certbot.rs", + "case_ids": [ + "tc-gw-certificat-002", + "tc-gw-certificat-001", + "tc-gw-certificat-007", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/gen_debug_key.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-002" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/kv/https_client.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-int-compatibil-004" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/kv/mod.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-int-compatibil-004" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/kv/sync_service.rs", + "case_ids": [ + "tc-gw-cluster-ad-001", + "tc-gw-build-001", + "tc-int-compatibil-004" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service.rs", + "case_ids": [ + "tc-gw-proxy-prot-005", + "tc-gw-build-001", + "tc-gw-registrati-001", + "tc-gw-registrati-003", + "tc-gw-registrati-004" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/auth_client.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-003" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/handshakes.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-registrati-002" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config-2.snap", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config-3.snap", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config.snap", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__empty_config.snap", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/main_service/tests.rs", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/models.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-007" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/pp.rs", + "case_ids": [ + "tc-gw-proxy-prot-001", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy.rs", + "case_ids": [ + "tc-gw-proxy-prot-002", + "tc-gw-proxy-prot-004", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy/io_bridge.rs", + "case_ids": [ + "tc-gw-proxy-prot-006", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy/port_policy.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-006" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy/sni.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-004" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy/tls_passthough.rs", + "case_ids": [ + "tc-gw-proxy-prot-003", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/proxy/tls_terminate.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-005" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/web_routes.rs", + "case_ids": [ + "tc-gw-cluster-ad-007", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/web_routes/route_index.rs", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-internal-008" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/src/web_routes/wavekv_sync.rs", + "case_ids": [ + "tc-gw-cluster-ad-002", + "tc-gw-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "gateway", + "source": "dstack/gateway/templates/dashboard.html", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-registrati-002", + "tc-gw-proxy-prot-004" + ], + "rationale": "direct source reference; gateway WireGuard/reverse-proxy templates" + }, + { + "component": "gateway", + "source": "dstack/gateway/templates/rproxy.yaml", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-registrati-002", + "tc-gw-proxy-prot-004" + ], + "rationale": "direct source reference; gateway WireGuard/reverse-proxy templates" + }, + { + "component": "gateway", + "source": "dstack/gateway/templates/wg.conf", + "case_ids": [ + "tc-gw-build-001", + "tc-gw-registrati-002", + "tc-gw-proxy-prot-004" + ], + "rationale": "direct source reference; gateway WireGuard/reverse-proxy templates" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/.env.example", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/.gitignore", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/TESTING.md", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/cluster.sh", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/docker-compose.yml", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/pebble-config.json", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/run-e2e.sh", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/e2e/test.sh", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/test_certbot.sh", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "gateway", + "source": "dstack/gateway/test-run/test_suite.sh", + "case_ids": [ + "tc-gw-build-001" + ], + "rationale": "direct source reference; gateway native integration harness" + }, + { + "component": "guest-os", + "source": "dstack/cert-client/Cargo.toml", + "case_ids": [ + "tc-gos-attestatio-004", + "tc-kms-keys-certs-004" + ], + "rationale": "certificate request and chain client" + }, + { + "component": "guest-os", + "source": "dstack/cert-client/src/lib.rs", + "case_ids": [ + "tc-gos-attestatio-004", + "tc-kms-keys-certs-004" + ], + "rationale": "certificate request and chain client" + }, + { + "component": "guest-os", + "source": "dstack/crates/dstack-volume/Cargo.toml", + "case_ids": [ + "tc-gos-storage-an-005" + ], + "rationale": "volume declaration encryption/persistence" + }, + { + "component": "guest-os", + "source": "dstack/crates/dstack-volume/src/bin/dstack-volume.rs", + "case_ids": [ + "tc-gos-storage-an-005" + ], + "rationale": "volume declaration encryption/persistence" + }, + { + "component": "guest-os", + "source": "dstack/crates/dstack-volume/src/lib.rs", + "case_ids": [ + "tc-gos-storage-an-005" + ], + "rationale": "volume declaration encryption/persistence" + }, + { + "component": "guest-os", + "source": "dstack/crates/dstack-volume/src/volume.rs", + "case_ids": [ + "tc-gos-storage-an-005" + ], + "rationale": "volume declaration encryption/persistence" + }, + { + "component": "guest-os", + "source": "dstack/crates/dstack-volume/src/volume_format.rs", + "case_ids": [ + "tc-gos-storage-an-005" + ], + "rationale": "volume declaration encryption/persistence" + }, + { + "component": "guest-os", + "source": "dstack/dstack-types/Cargo.toml", + "case_ids": [ + "tc-gos-platform-010", + "tc-gos-compose-006", + "tc-vmm-manifest-002" + ], + "rationale": "compose, VM, attestation and compatibility schemas" + }, + { + "component": "guest-os", + "source": "dstack/dstack-types/src/lib.rs", + "case_ids": [ + "tc-gos-platform-010", + "tc-gos-compose-006", + "tc-vmm-manifest-002" + ], + "rationale": "compose, VM, attestation and compatibility schemas" + }, + { + "component": "guest-os", + "source": "dstack/dstack-types/src/mr_config.rs", + "case_ids": [ + "tc-gos-platform-010", + "tc-gos-compose-006", + "tc-vmm-manifest-002" + ], + "rationale": "compose, VM, attestation and compatibility schemas" + }, + { + "component": "guest-os", + "source": "dstack/dstack-types/src/shared_filenames.rs", + "case_ids": [ + "tc-gos-platform-010", + "tc-gos-compose-006", + "tc-vmm-manifest-002" + ], + "rationale": "compose, VM, attestation and compatibility schemas" + }, + { + "component": "guest-os", + "source": "dstack/dstack-types/src/version.rs", + "case_ids": [ + "tc-gos-platform-010", + "tc-gos-compose-006", + "tc-vmm-manifest-002" + ], + "rationale": "compose, VM, attestation and compatibility schemas" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/Cargo.toml", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/crypto.rs", + "case_ids": [ + "tc-gos-setup-002" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/docker_compose.rs", + "case_ids": [ + "tc-gos-setup-003" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/host_api.rs", + "case_ids": [ + "tc-gos-setup-010" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/host_shared.rs", + "case_ids": [ + "tc-gos-platform-003" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/main.rs", + "case_ids": [ + "tc-gos-setup-024", + "tc-gos-setup-018", + "tc-gos-setup-021", + "tc-gos-setup-020", + "tc-gos-setup-023", + "tc-gos-setup-019", + "tc-gos-setup-022" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/parse_env_file.rs", + "case_ids": [ + "tc-gos-setup-001" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/system_setup.rs", + "case_ids": [ + "tc-gos-setup-008", + "tc-gos-setup-004", + "tc-gos-setup-006", + "tc-gos-setup-007", + "tc-gos-setup-011", + "tc-gos-setup-009" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/system_setup/config_id_verifier.rs", + "case_ids": [ + "tc-gos-setup-005" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/src/utils.rs", + "case_ids": [ + "tc-gos-setup-004", + "tc-gos-build-001" + ], + "rationale": "system setup JSON/file hashing support and component regression gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/fixtures/gpu_attestation_h100.json", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/fixtures/luks_header_cipher_null", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/fixtures/luks_header_cipher_null.license", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/fixtures/luks_header_good", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/fixtures/luks_header_good.license", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/dstack-util/tests/test_remove_orphans.sh", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/Cargo.toml", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/dstack.toml", + "case_ids": [ + "tc-gos-entry-001" + ], + "rationale": "guest-agent mandatory configuration matrix" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/fixtures/attestation.bin", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-cli-cert-o-006" + ], + "rationale": "attestation CLI and verifier fixture regression" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/rpc/Cargo.toml", + "case_ids": [ + "tc-gos-tappd-001", + "tc-gos-tappd-002", + "tc-gos-tappd-003", + "tc-gos-tappd-004", + "tc-gos-tappd-005", + "tc-gos-tappd-006", + "tc-gos-dstackguest-001", + "tc-gos-dstackguest-002", + "tc-gos-dstackguest-003", + "tc-gos-dstackguest-004", + "tc-gos-dstackguest-005", + "tc-gos-dstackguest-006", + "tc-gos-dstackguest-007", + "tc-gos-dstackguest-008", + "tc-gos-dstackguest-009", + "tc-gos-worker-001", + "tc-gos-worker-002", + "tc-gos-worker-003", + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-005", + "tc-gos-build-001" + ], + "rationale": "guest-agent RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/rpc/build.rs", + "case_ids": [ + "tc-gos-tappd-001", + "tc-gos-tappd-002", + "tc-gos-tappd-003", + "tc-gos-tappd-004", + "tc-gos-tappd-005", + "tc-gos-tappd-006", + "tc-gos-dstackguest-001", + "tc-gos-dstackguest-002", + "tc-gos-dstackguest-003", + "tc-gos-dstackguest-004", + "tc-gos-dstackguest-005", + "tc-gos-dstackguest-006", + "tc-gos-dstackguest-007", + "tc-gos-dstackguest-008", + "tc-gos-dstackguest-009", + "tc-gos-worker-001", + "tc-gos-worker-002", + "tc-gos-worker-003", + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-005", + "tc-gos-build-001" + ], + "rationale": "guest-agent RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "case_ids": [ + "tc-gos-worker-002", + "tc-gos-worker-001", + "tc-gos-worker-003", + "tc-gos-tappd-001", + "tc-gos-tappd-004", + "tc-gos-tappd-005", + "tc-gos-tappd-002", + "tc-gos-tappd-003", + "tc-gos-tappd-006", + "tc-gos-dstackguest-005", + "tc-gos-dstackguest-001", + "tc-gos-dstackguest-008", + "tc-gos-dstackguest-002", + "tc-gos-dstackguest-006", + "tc-gos-dstackguest-003", + "tc-gos-dstackguest-004", + "tc-gos-dstackguest-007", + "tc-gos-dstackguest-009", + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-005" + ], + "rationale": "direct source reference; guest-agent RPC generated contract" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/rpc/src/generated.rs", + "case_ids": [ + "tc-gos-tappd-001", + "tc-gos-tappd-002", + "tc-gos-tappd-003", + "tc-gos-tappd-004", + "tc-gos-tappd-005", + "tc-gos-tappd-006", + "tc-gos-dstackguest-001", + "tc-gos-dstackguest-002", + "tc-gos-dstackguest-003", + "tc-gos-dstackguest-004", + "tc-gos-dstackguest-005", + "tc-gos-dstackguest-006", + "tc-gos-dstackguest-007", + "tc-gos-dstackguest-008", + "tc-gos-dstackguest-009", + "tc-gos-worker-001", + "tc-gos-worker-002", + "tc-gos-worker-003", + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-005" + ], + "rationale": "guest-agent RPC generated contract" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/rpc/src/lib.rs", + "case_ids": [ + "tc-gos-tappd-001", + "tc-gos-tappd-002", + "tc-gos-tappd-003", + "tc-gos-tappd-004", + "tc-gos-tappd-005", + "tc-gos-tappd-006", + "tc-gos-dstackguest-001", + "tc-gos-dstackguest-002", + "tc-gos-dstackguest-003", + "tc-gos-dstackguest-004", + "tc-gos-dstackguest-005", + "tc-gos-dstackguest-006", + "tc-gos-dstackguest-007", + "tc-gos-dstackguest-008", + "tc-gos-dstackguest-009", + "tc-gos-worker-001", + "tc-gos-worker-002", + "tc-gos-worker-003", + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-005" + ], + "rationale": "guest-agent RPC generated contract" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/backend.rs", + "case_ids": [ + "tc-int-failure-se-002", + "tc-gos-boot-and-i-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/config.rs", + "case_ids": [ + "tc-gos-entry-001" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/guest_api_service.rs", + "case_ids": [ + "tc-gos-observabil-004", + "tc-gos-boot-and-i-005" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/http_routes.rs", + "case_ids": [ + "tc-gos-observabil-001" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/lib.rs", + "case_ids": [ + "tc-gos-entry-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/main.rs", + "case_ids": [ + "tc-gos-entry-002" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/models.rs", + "case_ids": [ + "tc-gos-entry-003" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/rpc_service.rs", + "case_ids": [ + "tc-gos-attestatio-006", + "tc-gos-attestatio-003", + "tc-gos-attestatio-001", + "tc-gos-attestatio-004", + "tc-gos-attestatio-005" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/server.rs", + "case_ids": [ + "tc-gos-observabil-005" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/src/socket_activation.rs", + "case_ids": [ + "tc-gos-observabil-002" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/templates/dashboard.html", + "case_ids": [ + "tc-gos-entry-003", + "tc-gos-observabil-001" + ], + "rationale": "dashboard escaping and observability" + }, + { + "component": "guest-os", + "source": "dstack/guest-agent/templates/metrics.tpl", + "case_ids": [ + "tc-gos-entry-003", + "tc-gos-observabil-001" + ], + "rationale": "metrics formatting and observability" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/Cargo.toml", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-vmm-manifest-001", + "tc-gos-build-001" + ], + "rationale": "guest API direct/proxied contract; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/build.rs", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-vmm-manifest-001", + "tc-gos-build-001" + ], + "rationale": "guest API direct/proxied contract; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/proto/guest_api.proto", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-gos-guestapi-003", + "tc-gos-guestapi-002", + "tc-gos-proxiedguestapi-001", + "tc-gos-proxiedguestapi-004", + "tc-gos-proxiedguestapi-003", + "tc-gos-proxiedguestapi-002", + "tc-gos-proxiedguestapi-005", + "tc-vmm-manifest-001" + ], + "rationale": "direct source reference; guest API direct/proxied contract" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/src/client.rs", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-vmm-manifest-001" + ], + "rationale": "guest API direct/proxied contract" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/src/generated/mod.rs", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-vmm-manifest-001", + "tc-gos-build-001" + ], + "rationale": "guest API direct/proxied contract; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/guest-api/src/lib.rs", + "case_ids": [ + "tc-gos-guestapi-001", + "tc-gos-guestapi-002", + "tc-gos-guestapi-003", + "tc-gos-guestapi-004", + "tc-gos-guestapi-005", + "tc-vmm-manifest-001" + ], + "rationale": "guest API direct/proxied contract" + }, + { + "component": "guest-os", + "source": "dstack/key-provider-client/Cargo.toml", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002", + "tc-gos-setup-006" + ], + "rationale": "key-provider transport and identity" + }, + { + "component": "guest-os", + "source": "dstack/key-provider-client/src/host.rs", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002", + "tc-gos-setup-006" + ], + "rationale": "key-provider transport and identity" + }, + { + "component": "guest-os", + "source": "dstack/key-provider-client/src/lib.rs", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002", + "tc-gos-setup-006" + ], + "rationale": "key-provider transport and identity" + }, + { + "component": "guest-os", + "source": "dstack/load_config/Cargo.toml", + "case_ids": [ + "tc-gos-entry-001", + "tc-vmm-configurat-001", + "tc-kms-startup-001" + ], + "rationale": "configuration loading precedence" + }, + { + "component": "guest-os", + "source": "dstack/load_config/src/lib.rs", + "case_ids": [ + "tc-gos-entry-001", + "tc-vmm-configurat-001", + "tc-kms-startup-001" + ], + "rationale": "configuration loading precedence" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/Cargo.toml", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002", + "tc-gos-build-001" + ], + "rationale": "local key-provider mode and sealing; component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/README.md", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/Dockerfile.aesmd", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/Dockerfile.key-provider", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/Makefile", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/docker-compose.yaml", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/entrypoint-aesmd.sh", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/entrypoint-local-key-provider.sh", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/local-key-provider.manifest.template", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/build/run.sh", + "case_ids": [ + "tc-gos-platform-001", + "tc-gos-platform-002" + ], + "rationale": "local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/crypto.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/error.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/gramine.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/main.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/protocol.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/provider.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/local-key-provider/src/server.rs", + "case_ids": [ + "tc-gos-platform-002", + "tc-gos-platform-001" + ], + "rationale": "direct source reference; local key-provider mode and sealing" + }, + { + "component": "guest-os", + "source": "dstack/lspci/Cargo.toml", + "case_ids": [ + "tc-gos-setup-011", + "tc-vmm-compute-ne-004" + ], + "rationale": "GPU/PCI inventory" + }, + { + "component": "guest-os", + "source": "dstack/lspci/src/lib.rs", + "case_ids": [ + "tc-gos-setup-011", + "tc-vmm-compute-ne-004" + ], + "rationale": "GPU/PCI inventory" + }, + { + "component": "guest-os", + "source": "dstack/lspci/src/snapshots/lspci__lspci.snap", + "case_ids": [ + "tc-gos-setup-011", + "tc-vmm-compute-ne-004" + ], + "rationale": "GPU/PCI inventory" + }, + { + "component": "guest-os", + "source": "dstack/nsm-attest/Cargo.toml", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-016", + "tc-ver-nitro-008" + ], + "rationale": "Nitro evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/nsm-attest/src/lib.rs", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-016", + "tc-ver-nitro-008" + ], + "rationale": "Nitro evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/nsm-attest/src/types.rs", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-016", + "tc-ver-nitro-008" + ], + "rationale": "Nitro evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/nsm-attest/tests/attestation_test.rs", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-016", + "tc-ver-nitro-008" + ], + "rationale": "Nitro evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/nsm-attest/tests/nitro_attestation.bin", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-016", + "tc-ver-nitro-008" + ], + "rationale": "Nitro evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/rocket-vsock-listener/Cargo.toml", + "case_ids": [ + "tc-gos-observabil-002", + "tc-vmm-manifest-001" + ], + "rationale": "vsock listener and proxied transport" + }, + { + "component": "guest-os", + "source": "dstack/rocket-vsock-listener/src/lib.rs", + "case_ids": [ + "tc-gos-observabil-002", + "tc-vmm-manifest-001" + ], + "rationale": "vsock listener and proxied transport" + }, + { + "component": "guest-os", + "source": "dstack/serde-duration/Cargo.toml", + "case_ids": [ + "tc-vmm-configurat-001", + "tc-gw-internal-001" + ], + "rationale": "duration configuration parsing" + }, + { + "component": "guest-os", + "source": "dstack/serde-duration/src/lib.rs", + "case_ids": [ + "tc-vmm-configurat-001", + "tc-gw-internal-001" + ], + "rationale": "duration configuration parsing" + }, + { + "component": "guest-os", + "source": "dstack/sev-snp-attest/Cargo.toml", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-014", + "tc-ver-input-plat-005" + ], + "rationale": "SEV-SNP evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/sev-snp-attest/src/lib.rs", + "case_ids": [ + "tc-gos-attestatio-002", + "tc-gos-setup-014", + "tc-ver-input-plat-005" + ], + "rationale": "SEV-SNP evidence generation" + }, + { + "component": "guest-os", + "source": "dstack/size-parser/Cargo.toml", + "case_ids": [ + "tc-gos-setup-007", + "tc-vmm-vm-lifecyc-004" + ], + "rationale": "storage/resource size parsing" + }, + { + "component": "guest-os", + "source": "dstack/size-parser/README.md", + "case_ids": [ + "tc-gos-setup-007", + "tc-vmm-vm-lifecyc-004" + ], + "rationale": "storage/resource size parsing" + }, + { + "component": "guest-os", + "source": "dstack/size-parser/src/lib.rs", + "case_ids": [ + "tc-gos-setup-007", + "tc-vmm-vm-lifecyc-004" + ], + "rationale": "storage/resource size parsing" + }, + { + "component": "guest-os", + "source": "dstack/sodiumbox/Cargo.toml", + "case_ids": [ + "tc-gos-setup-002", + "tc-int-end-to-end-003" + ], + "rationale": "encrypted environment authenticated box" + }, + { + "component": "guest-os", + "source": "dstack/sodiumbox/README.md", + "case_ids": [ + "tc-gos-setup-002", + "tc-int-end-to-end-003" + ], + "rationale": "encrypted environment authenticated box" + }, + { + "component": "guest-os", + "source": "dstack/sodiumbox/src/lib.rs", + "case_ids": [ + "tc-gos-setup-002", + "tc-int-end-to-end-003" + ], + "rationale": "encrypted environment authenticated box" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/Cargo.toml", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/client/Cargo.toml", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/client/src/lib.rs", + "case_ids": [ + "tc-gos-setup-012" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/client/src/main.rs", + "case_ids": [ + "tc-gos-setup-012" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/src/lib.rs", + "case_ids": [ + "tc-gos-storage-an-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/src/main.rs", + "case_ids": [ + "tc-gos-storage-an-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/src/process.rs", + "case_ids": [ + "tc-gos-storage-an-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/src/supervisor.rs", + "case_ids": [ + "tc-gos-storage-an-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/src/web_api.rs", + "case_ids": [ + "tc-gos-storage-an-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/supervisor.toml", + "case_ids": [ + "tc-gos-storage-an-004", + "tc-gos-setup-012" + ], + "rationale": "supervisor lifecycle and mandatory configuration matrix" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/tests/test-cli.sh", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/supervisor/tests/test.sh", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/Cargo.toml", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/examples/test_tdx.rs", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/src/dummy.rs", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/src/lib.rs", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/src/linux.rs", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/src/snapshots/tdx_attest__eventlog__tests__parse_ccel-2.snap", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tdx-attest/src/snapshots/tdx_attest__eventlog__tests__parse_ccel.snap", + "case_ids": [ + "tc-gos-attestatio-001", + "tc-gos-setup-018", + "tc-ver-input-plat-002" + ], + "rationale": "TDX evidence generation and binding" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/Cargo.toml", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/src/main.rs", + "case_ids": [ + "tc-gos-setup-017" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/src/nsm.rs", + "case_ids": [ + "tc-gos-setup-016" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/src/sev_snp.rs", + "case_ids": [ + "tc-gos-setup-014" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/src/tdx.rs", + "case_ids": [ + "tc-gos-setup-013" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/src/tpm.rs", + "case_ids": [ + "tc-gos-setup-015" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "dstack/tee-simulator/tests/process_e2e.rs", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/Cargo.toml", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/src/esapi.rs", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/src/gcp_ak.rs", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/src/lib.rs", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/tests/tpm_quote_sample.README.md", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-attest/tests/tpm_quote_sample.bin", + "case_ids": [ + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote generation and verification" + }, + { + "component": "guest-os", + "source": "dstack/tpm-types/Cargo.toml", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM wire and evidence types" + }, + { + "component": "guest-os", + "source": "dstack/tpm-types/src/lib.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022", + "tc-ver-input-plat-006" + ], + "rationale": "TPM wire and evidence types" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/Cargo.toml", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/bin/tpm2-test.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/commands.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/constants.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/device.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/lib.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/marshal.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/session.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "dstack/tpm2/src/types.rs", + "case_ids": [ + "tc-gos-setup-015", + "tc-gos-setup-022" + ], + "rationale": "TPM command and quote operations" + }, + { + "component": "guest-os", + "source": "os/README.md", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "guest-os", + "source": "os/build.sh", + "case_ids": [ + "tc-gos-build-001", + "tc-gos-yocto-007" + ], + "rationale": "direct source reference; guest image build" + }, + { + "component": "guest-os", + "source": "os/common/README.md", + "case_ids": [ + "tc-gos-build-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/app-compose.service", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/app-compose.sh", + "case_ids": [ + "tc-gos-platform-006", + "tc-gos-storage-an-003" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/containerd.service.d/dstack-prepare.conf", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/docker.service.d/dstack-guest-agent.conf", + "case_ids": [ + "tc-gos-platform-008", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/docker.service.d/dstack-prepare.conf", + "case_ids": [ + "tc-gos-platform-008", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/dstack-guest-agent.service", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/dstack-guest-agent.socket", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/dstack-prepare.service", + "case_ids": [ + "tc-gos-boot-and-i-001", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/dstack-prepare.sh", + "case_ids": [ + "tc-int-failure-se-001", + "tc-gos-boot-and-i-003", + "tc-gos-platform-006", + "tc-gos-storage-an-001" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/ephemeral-docker.sh", + "case_ids": [ + "tc-gos-platform-006", + "tc-gos-storage-an-002" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/journald.conf", + "case_ids": [ + "tc-gos-platform-007", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/llmnr.conf", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/sysctl.d/99-dstack.conf", + "case_ids": [ + "tc-gos-platform-005", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/tdx-attest.conf", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/wg-checker.service", + "case_ids": [ + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/common/rootfs/wg-checker.sh", + "case_ids": [ + "tc-gos-observabil-003", + "tc-gos-platform-006" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/image/README.md", + "case_ids": [ + "tc-gos-platform-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/image/assemble.sh", + "case_ids": [ + "tc-gos-platform-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/image/authenticode_hash.py", + "case_ids": [ + "tc-gos-platform-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/image/dstack-image-oci.sh", + "case_ids": [ + "tc-gos-platform-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/image/mk-image-mr.sh", + "case_ids": [ + "tc-gos-platform-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/spec/artifact-manifest.schema.json", + "case_ids": [ + "tc-ver-image-meas-004" + ], + "rationale": "direct source reference" + }, + { + "component": "guest-os", + "source": "os/yocto/.gitignore", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/Makefile", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/README.md", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/build.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/dev-setup", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/distro/dstack.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/layer.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/local.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/machine/dstack.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/multiconfig/dev.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/conf/multiconfig/prod.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-connectivity/openssh/files/disable-password-auth.conf", + "case_ids": [ + "tc-gos-yocto-002", + "tc-gos-yocto-001", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-connectivity/openssh/openssh_%.bbappend", + "case_ids": [ + "tc-gos-yocto-002", + "tc-gos-yocto-001", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/containerd-config_1.1.0.bb", + "case_ids": [ + "tc-gos-yocto-004", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml", + "case_ids": [ + "tc-gos-yocto-004", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-containers/stargz-snapshotter/files/containerd-stargz-grpc.service", + "case_ids": [ + "tc-gos-yocto-004", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-containers/stargz-snapshotter/stargz-snapshotter_0.18.2.bb", + "case_ids": [ + "tc-gos-yocto-004", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/base-files/base-files%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/base-files/files/dstack-motd", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/busybox/busybox%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/busybox/files/fragment.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/chrony/chrony%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-003", + "tc-gos-yocto-002", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/chrony/files/chrony.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-003", + "tc-gos-yocto-002", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/docker/docker-moby%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/docker/files/docker.service.d_override.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-guest/dstack-guest.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0001-Update-path-to-native-BaseTools.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0002-BaseTools-makefile-adjust-to-build-in-under-bitbake.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0003-Debug-prefix-map.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0004-Reproduciable.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0005-UefiCpuPkg-CpuExceptionHandlerLib-fix-push-instructi.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0006-OvmfPkg-AmdSev-drop-embedded-grub.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf_git.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/dstack-sysbox_0.6.7.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/50-sysbox-mod.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/99-sysbox-sysctl.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox-fs.service", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox-mgr.service", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox.service", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysboxFsProtobuf.pb.go", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysboxMgrProtobuf.pb.go", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-005", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/dstack-tee-simulator.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/files/dstack-tee-simulator.service", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/files/tee-simulator.conf", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-zfs/dstack-zfs/0001-Define-strndupa-if-it-does-not-exist.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/dstack-zfs/dstack-zfs_2.4.0.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initramfs.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initscript.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initscript/init", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-base.inc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-dev.inc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-nvidia.inc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-prod.inc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/dstack-uki.bb", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/files/docker-daemon-nvidia.json", + "case_ids": [ + "tc-gos-yocto-006", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/images/files/docker-daemon.json", + "case_ids": [ + "tc-gos-yocto-006", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/ovmf/ovmf%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/systemd/files/0001-core-suppress-ephemeral-status-output.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-core/systemd/systemd_%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-devtools/fdisk/gptfdisk_%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-devtools/gcc/libgcc-initial_%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-devtools/gptfdisk/gptfdisk_%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/0001-x86-tdx-select-dma-direct-remap.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/0002-acpi-sandbox-block-aml-systemmemory-ram-access.patch", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-aws.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-aws.scc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-docker.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-docker.scc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-sysbox.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-sysbox.scc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-tdx.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-tdx.scc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack.cfg", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack.scc", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-dstack/recipes-kernel/linux/linux-yocto%.bbappend", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/README.md", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/artwork/loaded_modules.png", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/conf/layer.conf", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/custom-licenses/NVIDIA-Proprietary", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/containerd-config_1.0.0.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/ldconfig-compatibility-symlink/ldconfig-compatibility-symlink_1.0.0.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container.inc", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0001-build-fix.patch", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0002-secomp-fix.patch", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0003-fix-remove-buildpath-for-package-qa.patch", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container_1.00.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libtirpc134_1.3.4.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/0001-validate-ocsp-response-freshness.patch", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/10-nvidia-gpu-ordering.conf", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/regorus-ffi-Cargo.lock", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/nvattest_2026.06.09.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/0001-Fix-cgo-LDFLAGS-for-go-1.21-and-later.patch", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/nvidia-container-toolkit.inc", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/nvidia-container-toolkit_1.00.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-fabricmanager-nvswitch-condition.conf", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-gpu-detect", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-persistenced.service", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia.conf", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_580.105.08.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_580.95.05.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_595.58.03.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_%.bbappend", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_580.105.08.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_580.95.05.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_595.58.03.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-gpu-detect_1.0.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-kernel-module.inc", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-libs.inc", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-modprobe-config_1.0.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-persistenced_1.0.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_580.105.08.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_580.95.05.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_595.58.03.bb", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-kernel/linux/files/nvidia.cfg", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-kernel/linux/files/nvidia.scc", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/layers/meta-nvidia/recipes-kernel/linux/linux-yocto%.bbappend", + "case_ids": [ + "tc-gos-platform-009", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/mk.d/.gitignore", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/mkimage.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/repro-build/.gitignore", + "case_ids": [ + "tc-gos-yocto-007", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/repro-build/Dockerfile.repro", + "case_ids": [ + "tc-gos-yocto-007", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/repro-build/check.sh", + "case_ids": [ + "tc-gos-yocto-007", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/repro-build/repro-build.sh", + "case_ids": [ + "tc-gos-yocto-007", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-008" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/scripts/docker-check-config.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/scripts/export-artifacts.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/setup.d/.gitignore", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/setup.d/nvidia-layer.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/tools/README.md", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/tools/aws/audit-aws-ec2-image-hardening.sh", + "case_ids": [ + "tc-gos-yocto-008", + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007" + ], + "rationale": "direct source reference; Yocto image/runtime/hardening" + }, + { + "component": "guest-os", + "source": "os/yocto/tools/fix-self-uid-map.sh", + "case_ids": [ + "tc-gos-yocto-001", + "tc-gos-yocto-002", + "tc-gos-yocto-003", + "tc-gos-yocto-004", + "tc-gos-yocto-005", + "tc-gos-yocto-006", + "tc-gos-yocto-007", + "tc-gos-yocto-008" + ], + "rationale": "Yocto image/runtime/hardening" + }, + { + "component": "kms", + "source": "dstack/cached-cell/Cargo.toml", + "case_ids": [ + "tc-kms-keys-certs-006", + "tc-kms-auth-010" + ], + "rationale": "cached authorization/measurement state" + }, + { + "component": "kms", + "source": "dstack/cached-cell/src/lib.rs", + "case_ids": [ + "tc-kms-keys-certs-006", + "tc-kms-auth-010" + ], + "rationale": "cached authorization/measurement state" + }, + { + "component": "kms", + "source": "dstack/http-client/Cargo.toml", + "case_ids": [ + "tc-kms-attestatio-005", + "tc-kms-auth-007" + ], + "rationale": "KMS authorization/image HTTP transport" + }, + { + "component": "kms", + "source": "dstack/http-client/src/hyper_vsock.rs", + "case_ids": [ + "tc-kms-attestatio-005", + "tc-kms-auth-007" + ], + "rationale": "KMS authorization/image HTTP transport" + }, + { + "component": "kms", + "source": "dstack/http-client/src/lib.rs", + "case_ids": [ + "tc-kms-attestatio-005", + "tc-kms-auth-007" + ], + "rationale": "KMS authorization/image HTTP transport" + }, + { + "component": "kms", + "source": "dstack/http-client/src/prpc.rs", + "case_ids": [ + "tc-kms-attestatio-005", + "tc-kms-auth-007" + ], + "rationale": "KMS authorization/image HTTP transport" + }, + { + "component": "kms", + "source": "dstack/kms/Cargo.toml", + "case_ids": [ + "tc-kms-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/README.md", + "case_ids": [ + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/.oxlintrc.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/bun.lock", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/index.test.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/index.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002", + "tc-kms-auth-003", + "tc-kms-auth-007" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/openapi.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002", + "tc-kms-auth-008" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/package.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth-bun/vitest.config.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/.env.example", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/.gitignore", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/.openzeppelin/unknown-2035.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/TESTING.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/DstackApp.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-005", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/DstackKms.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/IAppAuth.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/IAppAuthBasicManagement.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/test-utils/DstackAppV2.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/contracts/test-utils/DstackKmsV2.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-009", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-003", + "tc-kms-auth-007", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/docs/formal-verification.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/docs/specification.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/foundry.toml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/jest.config.js", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/package-lock.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/package.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/run-tests.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/script/Deploy.s.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-003", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/script/Manage.s.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-003", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/script/Query.s.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-003", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/script/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-003", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/script/Upgrade.s.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-003", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/scripts/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/scripts/cleanup.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/scripts/run-tests.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/scripts/setup-local-chain.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/scripts/test-all.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/slither.config.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/src/ethereum.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/src/main.test.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/src/main.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/src/server.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/src/types.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/test/DstackApp.symbolic.t.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/test/DstackApp.t.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/test/DstackKms.symbolic.t.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/test/DstackKms.t.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/test/UpgradesWithPlugin.t.sol", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling" + }, + { + "component": "kms", + "source": "dstack/kms/auth-eth/tsconfig.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-003", + "tc-kms-auth-004", + "tc-kms-auth-005", + "tc-kms-auth-006", + "tc-kms-auth-007", + "tc-kms-auth-009", + "tc-kms-runtime-001", + "tc-kms-runtime-003", + "tc-kms-runtime-005" + ], + "rationale": "direct source reference; Ethereum authorization runtime/contract/tooling; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/.oxlintrc.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/Dockerfile", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/bun.lock", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/index.test.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/index.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/openapi.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/package.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-mock/vitest.config.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/.oxlintrc.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/auth-config.example.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/bun.lock", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/index.test.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/index.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001", + "tc-kms-attestatio-005" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/package.json", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/auth-simple/vitest.config.ts", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/.gitignore", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/builder/Dockerfile", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/builder/README.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/builder/build-image.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/builder/shared/builder-pinned-packages.txt", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/builder/shared/qemu-pinned-packages.txt", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/compose-dev.yaml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/compose-simple.yaml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/deploy-simple.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/deploy-to-vmm.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/docker-compose.yaml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/dstack-app/entrypoint.sh", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-runtime-004" + ], + "rationale": "direct source reference; KMS application packaging" + }, + { + "component": "kms", + "source": "dstack/kms/kms.toml", + "case_ids": [ + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/Cargo.toml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004", + "tc-kms-kms-005", + "tc-kms-kms-006", + "tc-kms-admin-001", + "tc-kms-onboard-001", + "tc-kms-onboard-002", + "tc-kms-onboard-003", + "tc-kms-onboard-004" + ], + "rationale": "direct source reference; KMS RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/build.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004", + "tc-kms-kms-005", + "tc-kms-kms-006", + "tc-kms-admin-001", + "tc-kms-onboard-001", + "tc-kms-onboard-002", + "tc-kms-onboard-003", + "tc-kms-onboard-004" + ], + "rationale": "direct source reference; KMS RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "case_ids": [ + "tc-kms-admin-001", + "tc-kms-build-001", + "tc-kms-onboard-002", + "tc-kms-onboard-004", + "tc-kms-onboard-003", + "tc-kms-onboard-001", + "tc-kms-kms-001", + "tc-kms-kms-006", + "tc-kms-kms-005", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004" + ], + "rationale": "direct source reference; KMS RPC generated contract" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/src/.gitignore", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004", + "tc-kms-kms-005", + "tc-kms-kms-006", + "tc-kms-admin-001", + "tc-kms-onboard-001", + "tc-kms-onboard-002", + "tc-kms-onboard-003", + "tc-kms-onboard-004" + ], + "rationale": "direct source reference; KMS RPC generated contract" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/src/generated.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004", + "tc-kms-kms-005", + "tc-kms-kms-006", + "tc-kms-admin-001", + "tc-kms-onboard-001", + "tc-kms-onboard-002", + "tc-kms-onboard-003", + "tc-kms-onboard-004" + ], + "rationale": "direct source reference; KMS RPC generated contract" + }, + { + "component": "kms", + "source": "dstack/kms/rpc/src/lib.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-kms-002", + "tc-kms-kms-003", + "tc-kms-kms-004", + "tc-kms-kms-005", + "tc-kms-kms-006", + "tc-kms-admin-001", + "tc-kms-onboard-001", + "tc-kms-onboard-002", + "tc-kms-onboard-003", + "tc-kms-onboard-004" + ], + "rationale": "direct source reference; KMS RPC generated contract" + }, + { + "component": "kms", + "source": "dstack/kms/src/admin_auth.rs", + "case_ids": [ + "tc-kms-keys-certs-007", + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/admin_service.rs", + "case_ids": [ + "tc-kms-keys-certs-006", + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/config.rs", + "case_ids": [ + "tc-kms-keys-certs-008", + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/crypto.rs", + "case_ids": [ + "tc-kms-keys-certs-001", + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/ct_log.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-ct-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/main.rs", + "case_ids": [ + "tc-kms-startup-001", + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/main_service.rs", + "case_ids": [ + "tc-kms-keys-certs-004", + "tc-kms-keys-certs-005", + "tc-kms-keys-certs-003", + "tc-kms-keys-certs-002", + "tc-kms-build-001", + "tc-kms-attestatio-003", + "tc-kms-attestatio-001", + "tc-int-compatibil-003" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/main_service/amd_attest.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/main_service/upgrade_authority.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-auth-010", + "tc-kms-attestatio-004" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/onboard_service.rs", + "case_ids": [ + "tc-kms-keys-certs-009", + "tc-kms-build-001", + "tc-kms-bootstrap--002", + "tc-kms-bootstrap--003", + "tc-kms-bootstrap--001", + "tc-kms-bootstrap--004" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/kms/src/www/onboard.html", + "case_ids": [ + "tc-kms-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/Cargo.toml", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/prpc-openapi.md", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/src/client.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/src/lib.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/src/openapi.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "kms", + "source": "dstack/ra-rpc/src/rocket_helper.rs", + "case_ids": [ + "tc-kms-build-001", + "tc-kms-kms-001", + "tc-kms-onboard-002" + ], + "rationale": "RA RPC transport and attested channel" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/Cargo.toml", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/samples/ccel.bin", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/samples/tpm_eventlog.bin", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/codecs.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/lib.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/runtime_events.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/snapshots/cc_eventlog__tests__parse_ccel-2.snap", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/snapshots/cc_eventlog__tests__parse_ccel.snap", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/tcg.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/tdx.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/cc-eventlog/src/tpm.rs", + "case_ids": [ + "tc-ver-input-plat-003", + "tc-gos-setup-018" + ], + "rationale": "event-log parsing and replay" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/Cargo.toml", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/amd_sev_snp.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/attestation.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/aws_nitro_tpm.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/lib.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/sev_snp.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/src/v1.rs", + "case_ids": [ + "tc-ver-tools-003", + "tc-gos-attestatio-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/nitro_attestation.bin", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/nitro_attestation_dbg.bin", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/nitro_verify.rs", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/sev_snp_ask.pem", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/sev_snp_attestation.bin", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/sev_snp_fixture.README.md", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/sev_snp_vcek.pem", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/sev_snp_verify.rs", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/snapshots/nitro_verify__app_info.snap", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-attest/tests/snapshots/nitro_verify__nitro_report.snap", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/.gitignore", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/Cargo.toml", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/cli/Cargo.toml", + "case_ids": [ + "tc-ver-tools-001", + "tc-ver-buildall-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/cli/src/main.rs", + "case_ids": [ + "tc-ver-tools-001" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/acpi.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/kernel.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/lib.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/machine.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/main.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/measurement.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/num.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/sev.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/tdvf.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/tdx.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/src/util.rs", + "case_ids": [ + "tc-ver-tools-002", + "tc-ver-image-meas-003" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/dstack-mr/tests/tdvf_parse.rs", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/Cargo.toml", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/certs/AWS_NitroEnclaves_Root-G1.pem", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/src/collateral.rs", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/src/lib.rs", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/src/verify.rs", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/tests/nitro_attestation.README.md", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/tests/nitro_attestation.bin", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/nsm-qvl/tests/verify_test.rs", + "case_ids": [ + "tc-ver-nitro-008" + ], + "rationale": "Nitro document verification" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/Cargo.toml", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/assets/tdx_quote", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/attestation.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/cert.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/kdf.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/lib.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/oids.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/ra-tls/src/traits.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-kms-upgrade-002", + "tc-gos-attestatio-004" + ], + "rationale": "RA-TLS certificate/evidence binding" + }, + { + "component": "verifier", + "source": "dstack/sev-snp-qvl/Cargo.toml", + "case_ids": [ + "tc-ver-input-plat-005" + ], + "rationale": "SEV-SNP report/certificate verification" + }, + { + "component": "verifier", + "source": "dstack/sev-snp-qvl/src/lib.rs", + "case_ids": [ + "tc-ver-input-plat-005" + ], + "rationale": "SEV-SNP report/certificate verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/Cargo.toml", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/certs/AWS_NitroEnclaves_Root-G1.pem", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/certs/gcp-root-ca.pem", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/src/collateral.rs", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/src/lib.rs", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/tpm-qvl/src/verify.rs", + "case_ids": [ + "tc-ver-input-plat-006" + ], + "rationale": "TPM quote verification" + }, + { + "component": "verifier", + "source": "dstack/verifier/Cargo.toml", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/generated/existing-test gate" + }, + { + "component": "verifier", + "source": "dstack/verifier/README.md", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/verifier/builder/Dockerfile", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/verifier/builder/build-image.sh", + "case_ids": [ + "tc-ver-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/builder/shared/builder-pinned-packages.txt", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/verifier/builder/shared/pinned-packages.txt", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/verifier/builder/shared/qemu-pinned-packages.txt", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "component build/package inventory gate; no independent runtime behavior" + }, + { + "component": "verifier", + "source": "dstack/verifier/dstack-verifier.toml", + "case_ids": [ + "tc-ver-build-002" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/quote-report.json", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/sev-snp-attestation.json", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/sev-snp.README.md", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/tdx-lite-attestation.json", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/tdx-lite-getquote.json", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/fixtures/tdx-lite.README.md", + "case_ids": [ + "tc-ver-cli-cert-o-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/src/lib.rs", + "case_ids": [ + "tc-ver-tools-004" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/src/main.rs", + "case_ids": [ + "tc-ver-cli-cert-o-002", + "tc-ver-cli-cert-o-001", + "tc-ver-cli-cert-o-005", + "tc-ver-tools-006" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/src/types.rs", + "case_ids": [ + "tc-ver-input-plat-001", + "tc-ver-cli-cert-o-004", + "tc-int-compatibil-005" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/src/verification.rs", + "case_ids": [ + "tc-ver-input-plat-002", + "tc-ver-input-plat-003", + "tc-ver-input-plat-006", + "tc-ver-input-plat-005", + "tc-ver-input-plat-004", + "tc-ver-cli-cert-o-003", + "tc-ver-tools-005", + "tc-ver-image-meas-001", + "tc-ver-image-meas-002", + "tc-ver-image-meas-005" + ], + "rationale": "direct source reference" + }, + { + "component": "verifier", + "source": "dstack/verifier/test.sh", + "case_ids": [ + "tc-ver-buildall-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/crates/api-auth/Cargo.toml", + "case_ids": [ + "tc-vmm-configurat-002" + ], + "rationale": "external API authentication" + }, + { + "component": "vmm", + "source": "dstack/crates/api-auth/README.md", + "case_ids": [ + "tc-vmm-configurat-002" + ], + "rationale": "external API authentication" + }, + { + "component": "vmm", + "source": "dstack/crates/api-auth/src/lib.rs", + "case_ids": [ + "tc-vmm-configurat-002" + ], + "rationale": "external API authentication" + }, + { + "component": "vmm", + "source": "dstack/crates/build-info/Cargo.toml", + "case_ids": [ + "tc-vmm-vmm-014", + "tc-gos-dstackguest-009", + "tc-gw-gateway-003" + ], + "rationale": "version/build metadata" + }, + { + "component": "vmm", + "source": "dstack/crates/build-info/src/lib.rs", + "case_ids": [ + "tc-vmm-vmm-014", + "tc-gos-dstackguest-009", + "tc-gw-gateway-003" + ], + "rationale": "version/build metadata" + }, + { + "component": "vmm", + "source": "dstack/crates/dstack-auth/Cargo.toml", + "case_ids": [ + "tc-vmm-configurat-002", + "tc-gw-cluster-ad-005", + "tc-kms-keys-certs-007" + ], + "rationale": "shared authentication policy" + }, + { + "component": "vmm", + "source": "dstack/crates/dstack-auth/src/main.rs", + "case_ids": [ + "tc-vmm-configurat-002", + "tc-gw-cluster-ad-005", + "tc-kms-keys-certs-007" + ], + "rationale": "shared authentication policy" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/Cargo.toml", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/README.md", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/lib.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/main.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/nsm.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/server.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/sev_snp.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/tdx.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/crates/mock-attestation/src/tpm.rs", + "case_ids": [ + "tc-vmm-configurat-003", + "tc-ver-input-plat-007" + ], + "rationale": "per-instance simulated attestation" + }, + { + "component": "vmm", + "source": "dstack/host-api/Cargo.toml", + "case_ids": [ + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003", + "tc-vmm-build-001" + ], + "rationale": "host API contract and clients; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/host-api/build.rs", + "case_ids": [ + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003", + "tc-vmm-build-001" + ], + "rationale": "host API contract and clients; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/host-api/proto/host_api.proto", + "case_ids": [ + "tc-vmm-hostapi-003", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023" + ], + "rationale": "direct source reference; host API contract and clients" + }, + { + "component": "vmm", + "source": "dstack/host-api/src/client.rs", + "case_ids": [ + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "host API contract and clients" + }, + { + "component": "vmm", + "source": "dstack/host-api/src/generated/mod.rs", + "case_ids": [ + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003", + "tc-vmm-build-001" + ], + "rationale": "host API contract and clients; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/host-api/src/lib.rs", + "case_ids": [ + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "host API contract and clients" + }, + { + "component": "vmm", + "source": "dstack/vmm/Cargo.toml", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/build.rs", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/requirements.txt", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/Cargo.toml", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/build.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/proto/prpc.proto", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "case_ids": [ + "tc-vmm-vmm-023", + "tc-vmm-vmm-016", + "tc-vmm-vmm-021", + "tc-vmm-vmm-006", + "tc-vmm-vmm-010", + "tc-vmm-vmm-003", + "tc-vmm-vmm-012", + "tc-vmm-vmm-020", + "tc-vmm-vmm-008", + "tc-vmm-vmm-018", + "tc-vmm-vmm-004", + "tc-vmm-vmm-019", + "tc-vmm-vmm-013", + "tc-vmm-vmm-007", + "tc-vmm-vmm-015", + "tc-vmm-vmm-002", + "tc-vmm-vmm-005", + "tc-vmm-vmm-014", + "tc-vmm-vmm-001", + "tc-vmm-vmm-009", + "tc-vmm-vmm-017", + "tc-vmm-vmm-011", + "tc-vmm-vmm-022", + "tc-vmm-build-001", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/src/generated.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract" + }, + { + "component": "vmm", + "source": "dstack/vmm/rpc/src/lib.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-vmm-001", + "tc-vmm-vmm-002", + "tc-vmm-vmm-003", + "tc-vmm-vmm-004", + "tc-vmm-vmm-005", + "tc-vmm-vmm-006", + "tc-vmm-vmm-007", + "tc-vmm-vmm-008", + "tc-vmm-vmm-009", + "tc-vmm-vmm-010", + "tc-vmm-vmm-011", + "tc-vmm-vmm-012", + "tc-vmm-vmm-013", + "tc-vmm-vmm-014", + "tc-vmm-vmm-015", + "tc-vmm-vmm-016", + "tc-vmm-vmm-017", + "tc-vmm-vmm-018", + "tc-vmm-vmm-019", + "tc-vmm-vmm-020", + "tc-vmm-vmm-021", + "tc-vmm-vmm-022", + "tc-vmm-vmm-023", + "tc-vmm-hostapi-001", + "tc-vmm-hostapi-002", + "tc-vmm-hostapi-003" + ], + "rationale": "direct source reference; VMM RPC generated contract" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app.rs", + "case_ids": [ + "tc-int-failure-se-003", + "tc-int-compatibil-002", + "tc-vmm-configurat-003", + "tc-vmm-vm-lifecyc-001", + "tc-vmm-vm-lifecyc-006", + "tc-vmm-vm-lifecyc-002", + "tc-vmm-vm-lifecyc-005", + "tc-vmm-ui-observa-001", + "tc-vmm-compute-ne-004", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/host_share.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/id_pool.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-002" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/image.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-003" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/mr_config.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-004" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/network.rs", + "case_ids": [ + "tc-vmm-compute-ne-001", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/qemu.rs", + "case_ids": [ + "tc-vmm-compute-ne-007", + "tc-vmm-compute-ne-003", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/registry.rs", + "case_ids": [ + "tc-vmm-compute-ne-006", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/vm_info.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-005" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/app/workdir.rs", + "case_ids": [ + "tc-vmm-manifest-002", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/config.rs", + "case_ids": [ + "tc-vmm-configurat-001", + "tc-vmm-compute-ne-002", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/discovery.rs", + "case_ids": [ + "tc-vmm-compute-ne-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/guest_api_service.rs", + "case_ids": [ + "tc-vmm-manifest-001", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/host_api_service.rs", + "case_ids": [ + "tc-vmm-ui-observa-003", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/main.rs", + "case_ids": [ + "tc-vmm-configurat-002", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/main_routes.rs", + "case_ids": [ + "tc-vmm-ui-observa-002", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/main_service.rs", + "case_ids": [ + "tc-vmm-configurat-004", + "tc-vmm-vm-lifecyc-003", + "tc-vmm-vm-lifecyc-004", + "tc-vmm-ui-observa-004", + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/one_shot.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-006" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/openapi.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-007" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/setup-user.sh", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/tests/test-compose.sh", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/tests/test-deployment.sh", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/tests/test_vmm_cli.py", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/vm_launcher.rs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-internal-008" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/vmm-cli.py", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/src/x25519.js", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/.gitignore", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/README.md", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/build.mjs", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/package-lock.json", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/package.json", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/scripts/build_proto.sh", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/App.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/CreateVmDialog.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/EncryptedEnvEditor.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/ForkVmDialog.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/GpuConfigEditor.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/PortMappingEditor.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/components/UpdateVmDialog.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/composables/useVmManager.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/index.html", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/lib/vmmRpcClient.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/lib/x25519.js", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/main.ts", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/styles/main.css", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/src/templates/app.html", + "case_ids": [ + "tc-vmm-ui-observa-005", + "tc-vmm-build-001" + ], + "rationale": "direct source reference; VMM UI workflow and build" + }, + { + "component": "vmm", + "source": "dstack/vmm/ui/tsconfig.json", + "case_ids": [ + "tc-vmm-build-001", + "tc-vmm-ui-observa-005" + ], + "rationale": "direct source reference; VMM UI workflow and build; component build/generated/existing-test gate" + }, + { + "component": "vmm", + "source": "dstack/vmm/venv.sh", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + }, + { + "component": "vmm", + "source": "dstack/vmm/vmm.toml", + "case_ids": [ + "tc-vmm-build-001" + ], + "rationale": "direct source reference" + } + ] +} diff --git a/docs/test-plans/core-components-full/source-inventory.json b/docs/test-plans/core-components-full/source-inventory.json new file mode 100644 index 000000000..1575ede87 --- /dev/null +++ b/docs/test-plans/core-components-full/source-inventory.json @@ -0,0 +1,6520 @@ +{ + "schema_version": "1.0", + "generated_from": "repository source tree", + "components": { + "guest-os": { + "roots": [ + "os", + "dstack/guest-agent", + "dstack/guest-api", + "dstack/supervisor", + "dstack/dstack-util", + "dstack/local-key-provider", + "dstack/tee-simulator", + "dstack/dstack-types", + "dstack/crates/dstack-volume", + "dstack/key-provider-client", + "dstack/cert-client", + "dstack/tdx-attest", + "dstack/tpm-attest", + "dstack/sev-snp-attest", + "dstack/nsm-attest", + "dstack/tpm2", + "dstack/tpm-types", + "dstack/rocket-vsock-listener", + "dstack/load_config", + "dstack/lspci", + "dstack/sodiumbox", + "dstack/serde-duration", + "dstack/size-parser" + ], + "files": [ + "dstack/cert-client/Cargo.toml", + "dstack/cert-client/src/lib.rs", + "dstack/crates/dstack-volume/Cargo.toml", + "dstack/crates/dstack-volume/src/bin/dstack-volume.rs", + "dstack/crates/dstack-volume/src/lib.rs", + "dstack/crates/dstack-volume/src/volume.rs", + "dstack/crates/dstack-volume/src/volume_format.rs", + "dstack/dstack-types/Cargo.toml", + "dstack/dstack-types/src/lib.rs", + "dstack/dstack-types/src/mr_config.rs", + "dstack/dstack-types/src/shared_filenames.rs", + "dstack/dstack-types/src/version.rs", + "dstack/dstack-util/Cargo.toml", + "dstack/dstack-util/src/crypto.rs", + "dstack/dstack-util/src/docker_compose.rs", + "dstack/dstack-util/src/host_api.rs", + "dstack/dstack-util/src/host_shared.rs", + "dstack/dstack-util/src/main.rs", + "dstack/dstack-util/src/parse_env_file.rs", + "dstack/dstack-util/src/system_setup.rs", + "dstack/dstack-util/src/system_setup/config_id_verifier.rs", + "dstack/dstack-util/src/utils.rs", + "dstack/dstack-util/tests/fixtures/gpu_attestation_h100.json", + "dstack/dstack-util/tests/fixtures/luks_header_cipher_null", + "dstack/dstack-util/tests/fixtures/luks_header_cipher_null.license", + "dstack/dstack-util/tests/fixtures/luks_header_good", + "dstack/dstack-util/tests/fixtures/luks_header_good.license", + "dstack/dstack-util/tests/test_remove_orphans.sh", + "dstack/guest-agent/Cargo.toml", + "dstack/guest-agent/dstack.toml", + "dstack/guest-agent/fixtures/attestation.bin", + "dstack/guest-agent/rpc/Cargo.toml", + "dstack/guest-agent/rpc/build.rs", + "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "dstack/guest-agent/rpc/src/generated.rs", + "dstack/guest-agent/rpc/src/lib.rs", + "dstack/guest-agent/src/backend.rs", + "dstack/guest-agent/src/config.rs", + "dstack/guest-agent/src/guest_api_service.rs", + "dstack/guest-agent/src/http_routes.rs", + "dstack/guest-agent/src/lib.rs", + "dstack/guest-agent/src/main.rs", + "dstack/guest-agent/src/models.rs", + "dstack/guest-agent/src/rpc_service.rs", + "dstack/guest-agent/src/server.rs", + "dstack/guest-agent/src/socket_activation.rs", + "dstack/guest-agent/templates/dashboard.html", + "dstack/guest-agent/templates/metrics.tpl", + "dstack/guest-api/Cargo.toml", + "dstack/guest-api/build.rs", + "dstack/guest-api/proto/guest_api.proto", + "dstack/guest-api/src/client.rs", + "dstack/guest-api/src/generated/mod.rs", + "dstack/guest-api/src/lib.rs", + "dstack/key-provider-client/Cargo.toml", + "dstack/key-provider-client/src/host.rs", + "dstack/key-provider-client/src/lib.rs", + "dstack/load_config/Cargo.toml", + "dstack/load_config/src/lib.rs", + "dstack/local-key-provider/Cargo.toml", + "dstack/local-key-provider/README.md", + "dstack/local-key-provider/build/Dockerfile.aesmd", + "dstack/local-key-provider/build/Dockerfile.key-provider", + "dstack/local-key-provider/build/Makefile", + "dstack/local-key-provider/build/docker-compose.yaml", + "dstack/local-key-provider/build/entrypoint-aesmd.sh", + "dstack/local-key-provider/build/entrypoint-local-key-provider.sh", + "dstack/local-key-provider/build/local-key-provider.manifest.template", + "dstack/local-key-provider/build/run.sh", + "dstack/local-key-provider/src/crypto.rs", + "dstack/local-key-provider/src/error.rs", + "dstack/local-key-provider/src/gramine.rs", + "dstack/local-key-provider/src/main.rs", + "dstack/local-key-provider/src/protocol.rs", + "dstack/local-key-provider/src/provider.rs", + "dstack/local-key-provider/src/server.rs", + "dstack/lspci/Cargo.toml", + "dstack/lspci/src/lib.rs", + "dstack/lspci/src/snapshots/lspci__lspci.snap", + "dstack/nsm-attest/Cargo.toml", + "dstack/nsm-attest/src/lib.rs", + "dstack/nsm-attest/src/types.rs", + "dstack/nsm-attest/tests/attestation_test.rs", + "dstack/nsm-attest/tests/nitro_attestation.bin", + "dstack/rocket-vsock-listener/Cargo.toml", + "dstack/rocket-vsock-listener/src/lib.rs", + "dstack/serde-duration/Cargo.toml", + "dstack/serde-duration/src/lib.rs", + "dstack/sev-snp-attest/Cargo.toml", + "dstack/sev-snp-attest/src/lib.rs", + "dstack/size-parser/Cargo.toml", + "dstack/size-parser/README.md", + "dstack/size-parser/src/lib.rs", + "dstack/sodiumbox/Cargo.toml", + "dstack/sodiumbox/README.md", + "dstack/sodiumbox/src/lib.rs", + "dstack/supervisor/Cargo.toml", + "dstack/supervisor/client/Cargo.toml", + "dstack/supervisor/client/src/lib.rs", + "dstack/supervisor/client/src/main.rs", + "dstack/supervisor/src/lib.rs", + "dstack/supervisor/src/main.rs", + "dstack/supervisor/src/process.rs", + "dstack/supervisor/src/supervisor.rs", + "dstack/supervisor/src/web_api.rs", + "dstack/supervisor/supervisor.toml", + "dstack/supervisor/tests/test-cli.sh", + "dstack/supervisor/tests/test.sh", + "dstack/tdx-attest/Cargo.toml", + "dstack/tdx-attest/examples/test_tdx.rs", + "dstack/tdx-attest/src/dummy.rs", + "dstack/tdx-attest/src/lib.rs", + "dstack/tdx-attest/src/linux.rs", + "dstack/tdx-attest/src/snapshots/tdx_attest__eventlog__tests__parse_ccel-2.snap", + "dstack/tdx-attest/src/snapshots/tdx_attest__eventlog__tests__parse_ccel.snap", + "dstack/tee-simulator/Cargo.toml", + "dstack/tee-simulator/src/main.rs", + "dstack/tee-simulator/src/nsm.rs", + "dstack/tee-simulator/src/sev_snp.rs", + "dstack/tee-simulator/src/tdx.rs", + "dstack/tee-simulator/src/tpm.rs", + "dstack/tee-simulator/tests/process_e2e.rs", + "dstack/tpm-attest/Cargo.toml", + "dstack/tpm-attest/src/esapi.rs", + "dstack/tpm-attest/src/gcp_ak.rs", + "dstack/tpm-attest/src/lib.rs", + "dstack/tpm-attest/tests/tpm_quote_sample.README.md", + "dstack/tpm-attest/tests/tpm_quote_sample.bin", + "dstack/tpm-types/Cargo.toml", + "dstack/tpm-types/src/lib.rs", + "dstack/tpm2/Cargo.toml", + "dstack/tpm2/src/bin/tpm2-test.rs", + "dstack/tpm2/src/commands.rs", + "dstack/tpm2/src/constants.rs", + "dstack/tpm2/src/device.rs", + "dstack/tpm2/src/lib.rs", + "dstack/tpm2/src/marshal.rs", + "dstack/tpm2/src/session.rs", + "dstack/tpm2/src/types.rs", + "os/README.md", + "os/build.sh", + "os/common/README.md", + "os/common/rootfs/app-compose.service", + "os/common/rootfs/app-compose.sh", + "os/common/rootfs/containerd.service.d/dstack-prepare.conf", + "os/common/rootfs/docker.service.d/dstack-guest-agent.conf", + "os/common/rootfs/docker.service.d/dstack-prepare.conf", + "os/common/rootfs/dstack-guest-agent.service", + "os/common/rootfs/dstack-guest-agent.socket", + "os/common/rootfs/dstack-prepare.service", + "os/common/rootfs/dstack-prepare.sh", + "os/common/rootfs/ephemeral-docker.sh", + "os/common/rootfs/journald.conf", + "os/common/rootfs/llmnr.conf", + "os/common/rootfs/sysctl.d/99-dstack.conf", + "os/common/rootfs/tdx-attest.conf", + "os/common/rootfs/wg-checker.service", + "os/common/rootfs/wg-checker.sh", + "os/image/README.md", + "os/image/assemble.sh", + "os/image/authenticode_hash.py", + "os/image/dstack-image-oci.sh", + "os/image/mk-image-mr.sh", + "os/spec/artifact-manifest.schema.json", + "os/yocto/.gitignore", + "os/yocto/Makefile", + "os/yocto/README.md", + "os/yocto/build.sh", + "os/yocto/dev-setup", + "os/yocto/layers/meta-dstack/conf/distro/dstack.conf", + "os/yocto/layers/meta-dstack/conf/layer.conf", + "os/yocto/layers/meta-dstack/conf/local.conf", + "os/yocto/layers/meta-dstack/conf/machine/dstack.conf", + "os/yocto/layers/meta-dstack/conf/multiconfig/dev.conf", + "os/yocto/layers/meta-dstack/conf/multiconfig/prod.conf", + "os/yocto/layers/meta-dstack/recipes-connectivity/openssh/files/disable-password-auth.conf", + "os/yocto/layers/meta-dstack/recipes-connectivity/openssh/openssh_%.bbappend", + "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/containerd-config_1.1.0.bb", + "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml", + "os/yocto/layers/meta-dstack/recipes-containers/stargz-snapshotter/files/containerd-stargz-grpc.service", + "os/yocto/layers/meta-dstack/recipes-containers/stargz-snapshotter/stargz-snapshotter_0.18.2.bb", + "os/yocto/layers/meta-dstack/recipes-core/base-files/base-files%.bbappend", + "os/yocto/layers/meta-dstack/recipes-core/base-files/files/dstack-motd", + "os/yocto/layers/meta-dstack/recipes-core/busybox/busybox%.bbappend", + "os/yocto/layers/meta-dstack/recipes-core/busybox/files/fragment.cfg", + "os/yocto/layers/meta-dstack/recipes-core/chrony/chrony%.bbappend", + "os/yocto/layers/meta-dstack/recipes-core/chrony/files/chrony.conf", + "os/yocto/layers/meta-dstack/recipes-core/docker/docker-moby%.bbappend", + "os/yocto/layers/meta-dstack/recipes-core/docker/files/docker.service.d_override.conf", + "os/yocto/layers/meta-dstack/recipes-core/dstack-guest/dstack-guest.bb", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0001-Update-path-to-native-BaseTools.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0002-BaseTools-makefile-adjust-to-build-in-under-bitbake.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0003-Debug-prefix-map.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0004-Reproduciable.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0005-UefiCpuPkg-CpuExceptionHandlerLib-fix-push-instructi.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf/0006-OvmfPkg-AmdSev-drop-embedded-grub.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-ovmf/dstack-ovmf_git.bb", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/dstack-sysbox_0.6.7.bb", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/50-sysbox-mod.conf", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/99-sysbox-sysctl.conf", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox-fs.service", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox-mgr.service", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysbox.service", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysboxFsProtobuf.pb.go", + "os/yocto/layers/meta-dstack/recipes-core/dstack-sysbox/files/sysboxMgrProtobuf.pb.go", + "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/dstack-tee-simulator.bb", + "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/files/dstack-tee-simulator.service", + "os/yocto/layers/meta-dstack/recipes-core/dstack-tee-simulator/files/tee-simulator.conf", + "os/yocto/layers/meta-dstack/recipes-core/dstack-zfs/dstack-zfs/0001-Define-strndupa-if-it-does-not-exist.patch", + "os/yocto/layers/meta-dstack/recipes-core/dstack-zfs/dstack-zfs_2.4.0.bb", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initramfs.bb", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initscript.bb", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-initscript/init", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-base.inc", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-dev.inc", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-nvidia.inc", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs-prod.inc", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-rootfs.bb", + "os/yocto/layers/meta-dstack/recipes-core/images/dstack-uki.bb", + "os/yocto/layers/meta-dstack/recipes-core/images/files/docker-daemon-nvidia.json", + "os/yocto/layers/meta-dstack/recipes-core/images/files/docker-daemon.json", + "os/yocto/layers/meta-dstack/recipes-core/ovmf/ovmf%.bbappend", + "os/yocto/layers/meta-dstack/recipes-core/systemd/files/0001-core-suppress-ephemeral-status-output.patch", + "os/yocto/layers/meta-dstack/recipes-core/systemd/systemd_%.bbappend", + "os/yocto/layers/meta-dstack/recipes-devtools/fdisk/gptfdisk_%.bbappend", + "os/yocto/layers/meta-dstack/recipes-devtools/gcc/libgcc-initial_%.bbappend", + "os/yocto/layers/meta-dstack/recipes-devtools/gptfdisk/gptfdisk_%.bbappend", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/0001-x86-tdx-select-dma-direct-remap.patch", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/0002-acpi-sandbox-block-aml-systemmemory-ram-access.patch", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-aws.cfg", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-aws.scc", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-docker.cfg", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-docker.scc", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-sysbox.cfg", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-sysbox.scc", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-tdx.cfg", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack-tdx.scc", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack.cfg", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/files/dstack.scc", + "os/yocto/layers/meta-dstack/recipes-kernel/linux/linux-yocto%.bbappend", + "os/yocto/layers/meta-nvidia/README.md", + "os/yocto/layers/meta-nvidia/artwork/loaded_modules.png", + "os/yocto/layers/meta-nvidia/conf/layer.conf", + "os/yocto/layers/meta-nvidia/custom-licenses/NVIDIA-Proprietary", + "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/containerd-config_1.0.0.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml", + "os/yocto/layers/meta-nvidia/recipes-graphics/ldconfig-compatibility-symlink/ldconfig-compatibility-symlink_1.0.0.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container.inc", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0001-build-fix.patch", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0002-secomp-fix.patch", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container/0003-fix-remove-buildpath-for-package-qa.patch", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libnvidia-container_1.00.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/libnvidia-container/libtirpc134_1.3.4.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/0001-validate-ocsp-response-freshness.patch", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/10-nvidia-gpu-ordering.conf", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/files/regorus-ffi-Cargo.lock", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvattest/nvattest_2026.06.09.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/0001-Fix-cgo-LDFLAGS-for-go-1.21-and-later.patch", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/nvidia-container-toolkit.inc", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/nvidia-container-toolkit_1.00.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-fabricmanager-nvswitch-condition.conf", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-gpu-detect", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia-persistenced.service", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/files/nvidia.conf", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_580.105.08.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_580.95.05.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/libnvidia-nscq_595.58.03.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_%.bbappend", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_580.105.08.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_580.95.05.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-fabricmanager_595.58.03.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-gpu-detect_1.0.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-kernel-module.inc", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-libs.inc", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-modprobe-config_1.0.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia-persistenced_1.0.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_580.105.08.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_580.95.05.bb", + "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia/nvidia_595.58.03.bb", + "os/yocto/layers/meta-nvidia/recipes-kernel/linux/files/nvidia.cfg", + "os/yocto/layers/meta-nvidia/recipes-kernel/linux/files/nvidia.scc", + "os/yocto/layers/meta-nvidia/recipes-kernel/linux/linux-yocto%.bbappend", + "os/yocto/mk.d/.gitignore", + "os/yocto/mkimage.sh", + "os/yocto/repro-build/.gitignore", + "os/yocto/repro-build/Dockerfile.repro", + "os/yocto/repro-build/check.sh", + "os/yocto/repro-build/repro-build.sh", + "os/yocto/scripts/docker-check-config.sh", + "os/yocto/scripts/export-artifacts.sh", + "os/yocto/setup.d/.gitignore", + "os/yocto/setup.d/nvidia-layer.sh", + "os/yocto/tools/README.md", + "os/yocto/tools/aws/audit-aws-ec2-image-hardening.sh", + "os/yocto/tools/fix-self-uid-map.sh" + ], + "rpc_methods": [ + { + "service": "Tappd", + "method": "DeriveKey", + "request": "DeriveKeyArgs", + "response": "GetTlsKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 15 + }, + { + "service": "Tappd", + "method": "DeriveK256Key", + "request": "GetKeyArgs", + "response": "DeriveK256KeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 18 + }, + { + "service": "Tappd", + "method": "TdxQuote", + "request": "TdxQuoteArgs", + "response": "TdxQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 21 + }, + { + "service": "Tappd", + "method": "RawQuote", + "request": "RawQuoteArgs", + "response": "TdxQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 28 + }, + { + "service": "Tappd", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 31 + }, + { + "service": "Tappd", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 34 + }, + { + "service": "DstackGuest", + "method": "GetTlsKey", + "request": "GetTlsKeyArgs", + "response": "GetTlsKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 41 + }, + { + "service": "DstackGuest", + "method": "GetKey", + "request": "GetKeyArgs", + "response": "GetKeyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 44 + }, + { + "service": "DstackGuest", + "method": "GetQuote", + "request": "RawQuoteArgs", + "response": "GetQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 47 + }, + { + "service": "DstackGuest", + "method": "Attest", + "request": "RawQuoteArgs", + "response": "AttestResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 51 + }, + { + "service": "DstackGuest", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 54 + }, + { + "service": "DstackGuest", + "method": "GpuInfo", + "request": "google.protobuf.Empty", + "response": "GpuInfoResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 57 + }, + { + "service": "DstackGuest", + "method": "Sign", + "request": "SignRequest", + "response": "SignResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 60 + }, + { + "service": "DstackGuest", + "method": "Verify", + "request": "VerifyRequest", + "response": "VerifyResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 63 + }, + { + "service": "DstackGuest", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 66 + }, + { + "service": "Worker", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "AppInfo", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 255 + }, + { + "service": "Worker", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "WorkerVersion", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 257 + }, + { + "service": "Worker", + "method": "GetAttestationForAppKey", + "request": "GetAttestationForAppKeyRequest", + "response": "GetQuoteResponse", + "source": "dstack/guest-agent/rpc/proto/agent_rpc.proto", + "line": 259 + }, + { + "service": "GuestApi", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "GuestInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 135 + }, + { + "service": "GuestApi", + "method": "SysInfo", + "request": "google.protobuf.Empty", + "response": "SystemInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 137 + }, + { + "service": "GuestApi", + "method": "NetworkInfo", + "request": "google.protobuf.Empty", + "response": "NetworkInformation", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 139 + }, + { + "service": "GuestApi", + "method": "ListContainers", + "request": "google.protobuf.Empty", + "response": "ListContainersResponse", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 141 + }, + { + "service": "GuestApi", + "method": "Shutdown", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 143 + }, + { + "service": "ProxiedGuestApi", + "method": "Info", + "request": "Id", + "response": "GuestInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 148 + }, + { + "service": "ProxiedGuestApi", + "method": "SysInfo", + "request": "Id", + "response": "SystemInfo", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 149 + }, + { + "service": "ProxiedGuestApi", + "method": "NetworkInfo", + "request": "Id", + "response": "NetworkInformation", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 150 + }, + { + "service": "ProxiedGuestApi", + "method": "ListContainers", + "request": "Id", + "response": "ListContainersResponse", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 151 + }, + { + "service": "ProxiedGuestApi", + "method": "Shutdown", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/guest-api/proto/guest_api.proto", + "line": 152 + } + ], + "http_routes": [ + { + "method": "GET", + "path": "/", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "method": "GET", + "path": "/metrics", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "method": "GET", + "path": "/logs/?&&&&&&&", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "method": "POST", + "path": "/deploy", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "POST", + "path": "/start/", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "POST", + "path": "/stop/", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "DELETE", + "path": "/remove/", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "GET", + "path": "/list", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "GET", + "path": "/info/", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "GET", + "path": "/ping", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "POST", + "path": "/clear", + "source": "dstack/supervisor/src/web_api.rs" + }, + { + "method": "POST", + "path": "/shutdown", + "source": "dstack/supervisor/src/web_api.rs" + } + ], + "toml_keys": [ + { + "key": "version", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "type", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "address", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "root", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "enable_remote_snapshot_annotations", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "platform", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "snapshotter", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "platform", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "snapshotter", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "privileged_without_host_devices", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "runtime_engine", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "runtime_root", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "runtime_type", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "BinaryName", + "source": "os/yocto/layers/meta-dstack/recipes-containers/containerd-config/files/config.toml" + }, + { + "key": "version", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "privileged_without_host_devices", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "runtime_engine", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "runtime_root", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "runtime_type", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "BinaryName", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/containerd-config/files/config.toml" + }, + { + "key": "environment", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "load-kmods", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "no-cgroups", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "ldconfig", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "log-level", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "runtimes", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "mode", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "mount-spec-path", + "source": "os/yocto/layers/meta-nvidia/recipes-graphics/nvidia-container-toolkit/files/config.toml" + }, + { + "key": "name", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "rocket.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "rcgen.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tokio.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "bollard.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "chrono.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "base64.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "rinja.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "dstack-build-info.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "ra-rpc", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "dstack-guest-agent-rpc.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "ra-tls", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tdx-attest.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tpm-attest.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "guest-api", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "host-api", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "sysinfo.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "default-net.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "rocket-vsock-listener.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "sd-notify.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "reqwest.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "cmd_lib.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "figment", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "load_config.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "k256", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "sha3.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "strip-ansi-escapes.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "cert-client.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "dstack-attest.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "ring.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "ed25519-dalek.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "listenfd.workspace", + "source": "dstack/guest-agent/Cargo.toml" + }, + { + "key": "workers", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "max_blocking", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "ident", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "temp_dir", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "keep_alive", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "log_level", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "keys_file", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "compose_file", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "sys_config_file", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "data_disks", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "address", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "reuse", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "address", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "reuse", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "address", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "port", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "address", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "port", + "source": "dstack/guest-agent/dstack.toml" + }, + { + "key": "name", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "scale.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/guest-agent/rpc/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "http-client", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "default", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "client", + "source": "dstack/guest-api/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "bon.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "clap", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "dashmap.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "dstack-build-info.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "libc.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "load_config.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "nix", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "notify.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "rocket", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/supervisor/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "required-features", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "clap", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "tokio.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "hyperlocal.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "hyper.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "http.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "hyper-util.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "http-body-util.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "log.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "futures.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "supervisor.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "http-client.workspace", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "cli", + "source": "dstack/supervisor/client/Cargo.toml" + }, + { + "key": "workers", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "max_blocking", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "ident", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "temp_dir", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "keep_alive", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "log_level", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "address", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "reuse", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "ctrlc", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "signals", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "grace", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "mercy", + "source": "dstack/supervisor/supervisor.toml" + }, + { + "key": "name", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "aes-gcm.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "curve25519-dalek.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "getrandom", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "hex_fmt.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "regex.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "scale", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "schnorrkel.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "semver.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "url.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "x25519-dalek.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "dstack-kms-rpc.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "ra-rpc", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "ra-tls", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "dstack-gateway-rpc.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tdx-attest.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tpm-attest.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tpm2.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tpm-qvl", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "host-api", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "cmd_lib.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "toml.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "dcap-qvl.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "k256", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "regorus.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "sha3.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "dstack-attest.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "cert-client.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "x509-parser.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "yaml-rust2.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "bollard.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "sodiumbox.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "libc.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "luks2.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "nvml-wrapper.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "scopeguard.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "ez-hash.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "safe-write.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "errify.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/dstack-util/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "homepage.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "repository.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "description", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "blake2.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "dcap-qvl.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "rand_core.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "salsa20.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "thiserror.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "x25519-dalek.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "xsalsa20poly1305.workspace", + "source": "dstack/local-key-provider/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "dstack-mr.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "fuser.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "libc.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "sd-notify.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "mock-attestation", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "libloading", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "pem.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "aws-nitro-enclaves-nsm-api", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "serde_cbor", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "dcap-qvl.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "reqwest.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "sev-snp-qvl.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tpm-qvl.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "tpm-types.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + }, + { + "key": "nsm-qvl.workspace", + "source": "dstack/tee-simulator/Cargo.toml" + } + ], + "existing_tests": [ + { + "name": "test_verify_ed25519_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_verify_secp256k1_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_ed25519_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_secp256k1_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_secp256k1_prehashed_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_secp256k1_prehashed_invalid_length_fails", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_unsupported_algorithm_fails", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_attestation_for_app_key_ed25519_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_attestation_for_app_key_secp256k1_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_attestation_for_app_key_unsupported_algorithm_fails", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_normalize_algorithm", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_key_k256_alias", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_key_secp256k1_prehashed_rejected", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_key_ed25519_success", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_key_default_algorithm", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_get_key_unsupported_algorithm_fails", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_version", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_sign_k256_alias", + "source": "dstack/guest-agent/src/rpc_service.rs" + }, + { + "name": "test_parse_duration_empty", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "name": "test_parse_duration_numeric", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "name": "test_parse_duration_units", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "name": "test_parse_duration_errors", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "name": "test_parse_duration_large_values", + "source": "dstack/guest-agent/src/http_routes.rs" + }, + { + "name": "test_yaml_anchor_parsing", + "source": "dstack/dstack-util/src/docker_compose.rs" + }, + { + "name": "test_yaml_simple_anchor_alias", + "source": "dstack/dstack-util/src/docker_compose.rs" + }, + { + "name": "test_yaml_without_anchors", + "source": "dstack/dstack-util/src/docker_compose.rs" + }, + { + "name": "test_parse_real_compose_file", + "source": "dstack/dstack-util/src/docker_compose.rs" + }, + { + "name": "test_validate_luks2_header", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_validate_luks2_header_rejects_out_of_range_keyslot_area", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_app_compose", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_manifest_version_policy_rejects_above_guest_max", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_os_version_requirement_requires_v3_manifest", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_nerdctl_compose_requires_v3_manifest", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_snapshotter_is_rejected_for_other_runners", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_os_version_requirement_rejects_too_old_os", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_os_version_requirement_accepts_semver_requirement_ranges", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_os_version_requirement_rejects_invalid_semver_strings", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_accept_matching_platform", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_reject_non_matching_platform", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_require_v3_manifest", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_empty_requirements_require_v3_manifest", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_omitted_accepts_any_platform", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_explicit_empty_rejects_all_platforms", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_platform_requirements_reject_invalid_platform_value", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_tdx_measure_acpi_tables_requirement_matches_vm_config", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_tdx_measure_acpi_tables_requirement_ignored_on_non_tdx", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_requirement_accepts_matching_token", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_requirement_rejects_wrong_token", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_requirement_rejects_short_token", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_requirement_rejects_invalid_hash", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_from_user_config_extracts_token", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_launch_token_from_user_config_rejects_missing_or_invalid_token", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_os_release_value_parses_quoted_version_id", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_unquote_os_release_value_handles_quoting_styles", + "source": "dstack/dstack-util/src/system_setup.rs" + }, + { + "name": "test_dh_agree", + "source": "dstack/dstack-util/src/crypto.rs" + }, + { + "name": "test_dh_decrypt_invalid_input", + "source": "dstack/dstack-util/src/crypto.rs" + }, + { + "name": "test_dh_decrypt", + "source": "dstack/dstack-util/src/crypto.rs" + }, + { + "name": "test_escape_value", + "source": "dstack/dstack-util/src/parse_env_file.rs" + }, + { + "name": "test_parse_standard", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_two_segments", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_with_extra_parts", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_with_prerelease", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_git_describe", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_with_build_metadata", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_mixed", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_with_whitespace", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_empty", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_parse_invalid", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_comparison", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_display", + "source": "dstack/dstack-types/src/version.rs" + }, + { + "name": "test_pcr_selection_to_string", + "source": "dstack/tpm-attest/src/lib.rs" + }, + { + "name": "test_sealed_blob_split", + "source": "dstack/tpm-attest/src/lib.rs" + }, + { + "name": "test_default_pcr_policy", + "source": "dstack/tpm-attest/src/lib.rs" + }, + { + "name": "test_dir", + "source": "dstack/sev-snp-attest/src/lib.rs" + }, + { + "name": "test_parse_versioned_attestation_and_extract_nsm_quote", + "source": "dstack/nsm-attest/tests/attestation_test.rs" + }, + { + "name": "test_attestation_document_structure", + "source": "dstack/nsm-attest/tests/attestation_test.rs" + }, + { + "name": "test_command_builder", + "source": "dstack/tpm2/src/device.rs" + }, + { + "name": "test_response_parse", + "source": "dstack/tpm2/src/device.rs" + }, + { + "name": "test_pcr_selection", + "source": "dstack/tpm2/src/commands.rs" + }, + { + "name": "test_info", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_random", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_pcr_read", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_primary_key", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_nv_operations", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_quote_rsa", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_quote_ecc", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_pcr_extend", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_nv_full", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_evict_control", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_seal_unseal", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_seal_unseal_with_pcr", + "source": "dstack/tpm2/src/bin/tpm2-test.rs" + }, + { + "name": "test_vsock_endpoint_deserialization", + "source": "dstack/rocket-vsock-listener/src/lib.rs" + }, + { + "name": "test_vsock_listener_bind", + "source": "dstack/rocket-vsock-listener/src/lib.rs" + }, + { + "name": "test_display_format", + "source": "dstack/rocket-vsock-listener/src/lib.rs" + }, + { + "name": "test_load_config_file_json", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_load_config_file_toml", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_load_config_in_dir", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_search_load_config", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_search_load_config2", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_load_config_file_json_nested", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_load_config_file_toml_nested", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_search_load_config_nested", + "source": "dstack/load_config/src/lib.rs" + }, + { + "name": "test_lspci", + "source": "dstack/lspci/src/lib.rs" + }, + { + "name": "test_open_sealed_box_with_test_vectors", + "source": "dstack/sodiumbox/src/lib.rs" + }, + { + "name": "test_open_sealed_box_with_wrong_key", + "source": "dstack/sodiumbox/src/lib.rs" + }, + { + "name": "test_open_sealed_box_with_corrupted_data", + "source": "dstack/sodiumbox/src/lib.rs" + }, + { + "name": "test_generate_and_open", + "source": "dstack/sodiumbox/src/lib.rs" + }, + { + "name": "test_seal_and_open", + "source": "dstack/sodiumbox/src/lib.rs" + }, + { + "name": "test_parse_plain_numbers", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_parse_hexadecimal", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_parse_with_suffixes", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_parse_errors", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_format_human", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_conversions", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_from_str", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_display", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_compatibility_function", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_serde_json", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_generic_human_size_field_attribute", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_human_size_overflow_handling", + "source": "dstack/size-parser/src/lib.rs" + }, + { + "name": "test_human_size_json_number_support", + "source": "dstack/size-parser/src/lib.rs" + } + ] + }, + "vmm": { + "roots": [ + "dstack/vmm", + "dstack/host-api", + "dstack/crates/api-auth", + "dstack/crates/dstack-auth", + "dstack/crates/build-info", + "dstack/crates/mock-attestation" + ], + "files": [ + "dstack/crates/api-auth/Cargo.toml", + "dstack/crates/api-auth/README.md", + "dstack/crates/api-auth/src/lib.rs", + "dstack/crates/build-info/Cargo.toml", + "dstack/crates/build-info/src/lib.rs", + "dstack/crates/dstack-auth/Cargo.toml", + "dstack/crates/dstack-auth/src/main.rs", + "dstack/crates/mock-attestation/Cargo.toml", + "dstack/crates/mock-attestation/README.md", + "dstack/crates/mock-attestation/src/lib.rs", + "dstack/crates/mock-attestation/src/main.rs", + "dstack/crates/mock-attestation/src/nsm.rs", + "dstack/crates/mock-attestation/src/server.rs", + "dstack/crates/mock-attestation/src/sev_snp.rs", + "dstack/crates/mock-attestation/src/tdx.rs", + "dstack/crates/mock-attestation/src/tpm.rs", + "dstack/host-api/Cargo.toml", + "dstack/host-api/build.rs", + "dstack/host-api/proto/host_api.proto", + "dstack/host-api/src/client.rs", + "dstack/host-api/src/generated/mod.rs", + "dstack/host-api/src/lib.rs", + "dstack/vmm/Cargo.toml", + "dstack/vmm/build.rs", + "dstack/vmm/requirements.txt", + "dstack/vmm/rpc/Cargo.toml", + "dstack/vmm/rpc/build.rs", + "dstack/vmm/rpc/proto/prpc.proto", + "dstack/vmm/rpc/proto/vmm_rpc.proto", + "dstack/vmm/rpc/src/generated.rs", + "dstack/vmm/rpc/src/lib.rs", + "dstack/vmm/src/app.rs", + "dstack/vmm/src/app/host_share.rs", + "dstack/vmm/src/app/id_pool.rs", + "dstack/vmm/src/app/image.rs", + "dstack/vmm/src/app/mr_config.rs", + "dstack/vmm/src/app/network.rs", + "dstack/vmm/src/app/qemu.rs", + "dstack/vmm/src/app/registry.rs", + "dstack/vmm/src/app/vm_info.rs", + "dstack/vmm/src/app/workdir.rs", + "dstack/vmm/src/config.rs", + "dstack/vmm/src/discovery.rs", + "dstack/vmm/src/guest_api_service.rs", + "dstack/vmm/src/host_api_service.rs", + "dstack/vmm/src/main.rs", + "dstack/vmm/src/main_routes.rs", + "dstack/vmm/src/main_service.rs", + "dstack/vmm/src/one_shot.rs", + "dstack/vmm/src/openapi.rs", + "dstack/vmm/src/setup-user.sh", + "dstack/vmm/src/tests/test-compose.sh", + "dstack/vmm/src/tests/test-deployment.sh", + "dstack/vmm/src/tests/test_vmm_cli.py", + "dstack/vmm/src/vm_launcher.rs", + "dstack/vmm/src/vmm-cli.py", + "dstack/vmm/src/x25519.js", + "dstack/vmm/ui/.gitignore", + "dstack/vmm/ui/README.md", + "dstack/vmm/ui/build.mjs", + "dstack/vmm/ui/package-lock.json", + "dstack/vmm/ui/package.json", + "dstack/vmm/ui/scripts/build_proto.sh", + "dstack/vmm/ui/src/App.ts", + "dstack/vmm/ui/src/components/CreateVmDialog.ts", + "dstack/vmm/ui/src/components/EncryptedEnvEditor.ts", + "dstack/vmm/ui/src/components/ForkVmDialog.ts", + "dstack/vmm/ui/src/components/GpuConfigEditor.ts", + "dstack/vmm/ui/src/components/PortMappingEditor.ts", + "dstack/vmm/ui/src/components/UpdateVmDialog.ts", + "dstack/vmm/ui/src/composables/useVmManager.ts", + "dstack/vmm/ui/src/index.html", + "dstack/vmm/ui/src/lib/vmmRpcClient.ts", + "dstack/vmm/ui/src/lib/x25519.js", + "dstack/vmm/ui/src/main.ts", + "dstack/vmm/ui/src/styles/main.css", + "dstack/vmm/ui/src/templates/app.html", + "dstack/vmm/ui/tsconfig.json", + "dstack/vmm/venv.sh", + "dstack/vmm/vmm.toml" + ], + "rpc_methods": [ + { + "service": "Vmm", + "method": "CreateVm", + "request": "VmConfiguration", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 339 + }, + { + "service": "Vmm", + "method": "StartVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 341 + }, + { + "service": "Vmm", + "method": "StopVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 343 + }, + { + "service": "Vmm", + "method": "RemoveVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 345 + }, + { + "service": "Vmm", + "method": "UpgradeApp", + "request": "UpdateVmRequest", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 347 + }, + { + "service": "Vmm", + "method": "UpdateVm", + "request": "UpdateVmRequest", + "response": "Id", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 349 + }, + { + "service": "Vmm", + "method": "ShutdownVm", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 351 + }, + { + "service": "Vmm", + "method": "ResizeVm", + "request": "ResizeVmRequest", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 353 + }, + { + "service": "Vmm", + "method": "GetComposeHash", + "request": "VmConfiguration", + "response": "ComposeHash", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 355 + }, + { + "service": "Vmm", + "method": "Status", + "request": "StatusRequest", + "response": "StatusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 358 + }, + { + "service": "Vmm", + "method": "ListImages", + "request": "google.protobuf.Empty", + "response": "ImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 360 + }, + { + "service": "Vmm", + "method": "GetAppEnvEncryptPubKey", + "request": "AppId", + "response": "PublicKeyResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 363 + }, + { + "service": "Vmm", + "method": "GetInfo", + "request": "Id", + "response": "GetInfoResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 366 + }, + { + "service": "Vmm", + "method": "Version", + "request": "google.protobuf.Empty", + "response": "VersionResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 369 + }, + { + "service": "Vmm", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 372 + }, + { + "service": "Vmm", + "method": "ListGpus", + "request": "google.protobuf.Empty", + "response": "ListGpusResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 375 + }, + { + "service": "Vmm", + "method": "ReloadVms", + "request": "google.protobuf.Empty", + "response": "ReloadVmsResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 378 + }, + { + "service": "Vmm", + "method": "SvList", + "request": "google.protobuf.Empty", + "response": "SvListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 381 + }, + { + "service": "Vmm", + "method": "SvStop", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 383 + }, + { + "service": "Vmm", + "method": "SvRemove", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 385 + }, + { + "service": "Vmm", + "method": "ListRegistryImages", + "request": "google.protobuf.Empty", + "response": "RegistryImageListResponse", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 388 + }, + { + "service": "Vmm", + "method": "PullRegistryImage", + "request": "PullRegistryImageRequest", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 390 + }, + { + "service": "Vmm", + "method": "DeleteImage", + "request": "Id", + "response": "google.protobuf.Empty", + "source": "dstack/vmm/rpc/proto/vmm_rpc.proto", + "line": 392 + }, + { + "service": "HostApi", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "HostInfo", + "source": "dstack/host-api/proto/host_api.proto", + "line": 31 + }, + { + "service": "HostApi", + "method": "Notify", + "request": "Notification", + "response": "google.protobuf.Empty", + "source": "dstack/host-api/proto/host_api.proto", + "line": 32 + }, + { + "service": "HostApi", + "method": "GetSealingKey", + "request": "GetSealingKeyRequest", + "response": "GetSealingKeyResponse", + "source": "dstack/host-api/proto/host_api.proto", + "line": 33 + } + ], + "http_routes": [ + { + "method": "GET", + "path": "/", + "source": "dstack/vmm/src/main_routes.rs" + }, + { + "method": "GET", + "path": "/v1", + "source": "dstack/vmm/src/main_routes.rs" + }, + { + "method": "GET", + "path": "/beta", + "source": "dstack/vmm/src/main_routes.rs" + }, + { + "method": "GET", + "path": "/res/", + "source": "dstack/vmm/src/main_routes.rs" + }, + { + "method": "GET", + "path": "/logs?&&&&", + "source": "dstack/vmm/src/main_routes.rs" + }, + { + "method": "POST", + "path": "/bootAuth/app", + "source": "dstack/crates/dstack-auth/src/main.rs" + }, + { + "method": "POST", + "path": "/bootAuth/kms", + "source": "dstack/crates/dstack-auth/src/main.rs" + }, + { + "method": "GET", + "path": "/", + "source": "dstack/crates/dstack-auth/src/main.rs" + } + ], + "toml_keys": [ + { + "key": "name", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "rocket", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "rocket-vsock-listener", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tracing-subscriber", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "libc.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "shared_child.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "bon.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "uuid", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "getrandom", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "nix", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dirs.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "which.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "clap", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "humantime.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "strip-ansi-escapes.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tailf.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-api-auth.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-build-info.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "serde_ini.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "supervisor-client.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "ra-rpc", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-vmm-rpc.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-kms-rpc.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "path-absolutize.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "host-api.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "safe-write.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "guest-api", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "load_config.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "key-provider-client.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "dstack-mr.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "mock-attestation", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "hex_fmt.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "lspci.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "base64.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "size-parser", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "fatfs.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "fscommon.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "url.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "reqwest.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "flate2.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tar.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "insta.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/vmm/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "scale", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/vmm/rpc/Cargo.toml" + }, + { + "key": "workers", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "max_blocking", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "ident", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "temp_dir", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "keep_alive", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "log_level", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "address", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "reuse", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "kms_url", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "event_buffer_size", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "node_name", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "registry", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "platform", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "qemu_path", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "kms_urls", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "gateway_urls", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "pccs_url", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "docker_registry", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "volumes_dir", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "cid_start", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "cid_pool_size", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "max_allocable_vcpu", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "max_allocable_memory_in_mb", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "qmp_socket", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "user", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "use_mrconfigid", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "qemu_pci_hole64_size", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "qemu_hotplug_off", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "tdx_attestation_variant", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "host_share_mode", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "qgs_port", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "sys_vendor", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "product_name", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "mode", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "net", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "dhcp_start", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "restrict", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "enabled", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "address", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "range", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "enabled", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "interval", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "enabled", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "listing", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "exclude", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "include", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "allow_attach_all", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "base_domain", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "port", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "agent_port", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "enabled", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "tokens", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "htpasswd_file", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "exe", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "sock", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "pid_file", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "log_file", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "detached", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "auto_start", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "ident", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "address", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "port", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "enabled", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "address", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "port", + "source": "dstack/vmm/vmm.toml" + }, + { + "key": "name", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "http-client", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "default", + "source": "dstack/host-api/Cargo.toml" + }, + { + "key": "client", + "source": "dstack/host-api/Cargo.toml" + } + ], + "existing_tests": [ + { + "name": "test_cvm_config", + "source": "dstack/vmm/src/main_service.rs" + }, + { + "name": "test_vm_configuration", + "source": "dstack/vmm/src/main_service.rs" + }, + { + "name": "test_parse_qemu_version_debian_format", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_parse_qemu_version_simple_format", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_parse_qemu_version_old_debian_format", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_parse_qemu_version_with_rc", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_parse_qemu_version_fallback", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_parse_qemu_version_invalid", + "source": "dstack/vmm/src/config.rs" + }, + { + "name": "test_manifest", + "source": "dstack/vmm/src/app.rs" + }, + { + "name": "test_tdx_image", + "source": "dstack/vmm/src/app.rs" + }, + { + "name": "test_tdx_config", + "source": "dstack/vmm/src/app.rs" + }, + { + "name": "test_parse_image_ref_private_registry", + "source": "dstack/vmm/src/app/registry.rs" + }, + { + "name": "test_parse_image_ref_docker_hub", + "source": "dstack/vmm/src/app/registry.rs" + }, + { + "name": "test_parse_image_ref_with_scheme", + "source": "dstack/vmm/src/app/registry.rs" + }, + { + "name": "test_parse_www_authenticate", + "source": "dstack/vmm/src/app/registry.rs" + } + ] + }, + "kms": { + "roots": [ + "dstack/kms", + "dstack/ra-rpc", + "dstack/http-client", + "dstack/cached-cell" + ], + "files": [ + "dstack/cached-cell/Cargo.toml", + "dstack/cached-cell/src/lib.rs", + "dstack/http-client/Cargo.toml", + "dstack/http-client/src/hyper_vsock.rs", + "dstack/http-client/src/lib.rs", + "dstack/http-client/src/prpc.rs", + "dstack/kms/Cargo.toml", + "dstack/kms/README.md", + "dstack/kms/auth-eth-bun/.oxlintrc.json", + "dstack/kms/auth-eth-bun/README.md", + "dstack/kms/auth-eth-bun/bun.lock", + "dstack/kms/auth-eth-bun/index.test.ts", + "dstack/kms/auth-eth-bun/index.ts", + "dstack/kms/auth-eth-bun/openapi.json", + "dstack/kms/auth-eth-bun/package.json", + "dstack/kms/auth-eth-bun/vitest.config.ts", + "dstack/kms/auth-eth/.env.example", + "dstack/kms/auth-eth/.gitignore", + "dstack/kms/auth-eth/.openzeppelin/unknown-2035.json", + "dstack/kms/auth-eth/README.md", + "dstack/kms/auth-eth/TESTING.md", + "dstack/kms/auth-eth/contracts/DstackApp.sol", + "dstack/kms/auth-eth/contracts/DstackKms.sol", + "dstack/kms/auth-eth/contracts/IAppAuth.sol", + "dstack/kms/auth-eth/contracts/IAppAuthBasicManagement.sol", + "dstack/kms/auth-eth/contracts/test-utils/DstackAppV2.sol", + "dstack/kms/auth-eth/contracts/test-utils/DstackKmsV2.sol", + "dstack/kms/auth-eth/docs/formal-verification.md", + "dstack/kms/auth-eth/docs/specification.md", + "dstack/kms/auth-eth/foundry.toml", + "dstack/kms/auth-eth/jest.config.js", + "dstack/kms/auth-eth/package-lock.json", + "dstack/kms/auth-eth/package.json", + "dstack/kms/auth-eth/run-tests.sh", + "dstack/kms/auth-eth/script/Deploy.s.sol", + "dstack/kms/auth-eth/script/Manage.s.sol", + "dstack/kms/auth-eth/script/Query.s.sol", + "dstack/kms/auth-eth/script/README.md", + "dstack/kms/auth-eth/script/Upgrade.s.sol", + "dstack/kms/auth-eth/scripts/README.md", + "dstack/kms/auth-eth/scripts/cleanup.sh", + "dstack/kms/auth-eth/scripts/run-tests.sh", + "dstack/kms/auth-eth/scripts/setup-local-chain.sh", + "dstack/kms/auth-eth/scripts/test-all.sh", + "dstack/kms/auth-eth/slither.config.json", + "dstack/kms/auth-eth/src/ethereum.ts", + "dstack/kms/auth-eth/src/main.test.ts", + "dstack/kms/auth-eth/src/main.ts", + "dstack/kms/auth-eth/src/server.ts", + "dstack/kms/auth-eth/src/types.ts", + "dstack/kms/auth-eth/test/DstackApp.symbolic.t.sol", + "dstack/kms/auth-eth/test/DstackApp.t.sol", + "dstack/kms/auth-eth/test/DstackKms.symbolic.t.sol", + "dstack/kms/auth-eth/test/DstackKms.t.sol", + "dstack/kms/auth-eth/test/UpgradesWithPlugin.t.sol", + "dstack/kms/auth-eth/tsconfig.json", + "dstack/kms/auth-mock/.oxlintrc.json", + "dstack/kms/auth-mock/Dockerfile", + "dstack/kms/auth-mock/README.md", + "dstack/kms/auth-mock/bun.lock", + "dstack/kms/auth-mock/index.test.ts", + "dstack/kms/auth-mock/index.ts", + "dstack/kms/auth-mock/openapi.json", + "dstack/kms/auth-mock/package.json", + "dstack/kms/auth-mock/vitest.config.ts", + "dstack/kms/auth-simple/.oxlintrc.json", + "dstack/kms/auth-simple/README.md", + "dstack/kms/auth-simple/auth-config.example.json", + "dstack/kms/auth-simple/bun.lock", + "dstack/kms/auth-simple/index.test.ts", + "dstack/kms/auth-simple/index.ts", + "dstack/kms/auth-simple/package.json", + "dstack/kms/auth-simple/vitest.config.ts", + "dstack/kms/dstack-app/.gitignore", + "dstack/kms/dstack-app/builder/Dockerfile", + "dstack/kms/dstack-app/builder/README.md", + "dstack/kms/dstack-app/builder/build-image.sh", + "dstack/kms/dstack-app/builder/shared/builder-pinned-packages.txt", + "dstack/kms/dstack-app/builder/shared/qemu-pinned-packages.txt", + "dstack/kms/dstack-app/compose-dev.yaml", + "dstack/kms/dstack-app/compose-simple.yaml", + "dstack/kms/dstack-app/deploy-simple.sh", + "dstack/kms/dstack-app/deploy-to-vmm.sh", + "dstack/kms/dstack-app/docker-compose.yaml", + "dstack/kms/dstack-app/entrypoint.sh", + "dstack/kms/kms.toml", + "dstack/kms/rpc/Cargo.toml", + "dstack/kms/rpc/build.rs", + "dstack/kms/rpc/proto/kms_rpc.proto", + "dstack/kms/rpc/src/.gitignore", + "dstack/kms/rpc/src/generated.rs", + "dstack/kms/rpc/src/lib.rs", + "dstack/kms/src/admin_auth.rs", + "dstack/kms/src/admin_service.rs", + "dstack/kms/src/config.rs", + "dstack/kms/src/crypto.rs", + "dstack/kms/src/ct_log.rs", + "dstack/kms/src/main.rs", + "dstack/kms/src/main_service.rs", + "dstack/kms/src/main_service/amd_attest.rs", + "dstack/kms/src/main_service/upgrade_authority.rs", + "dstack/kms/src/onboard_service.rs", + "dstack/kms/src/www/onboard.html", + "dstack/ra-rpc/Cargo.toml", + "dstack/ra-rpc/prpc-openapi.md", + "dstack/ra-rpc/src/client.rs", + "dstack/ra-rpc/src/lib.rs", + "dstack/ra-rpc/src/openapi.rs", + "dstack/ra-rpc/src/rocket_helper.rs" + ], + "rpc_methods": [ + { + "service": "KMS", + "method": "GetAppKey", + "request": "GetAppKeyRequest", + "response": "AppKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 97 + }, + { + "service": "KMS", + "method": "GetKmsKey", + "request": "GetKmsKeyRequest", + "response": "KmsKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 99 + }, + { + "service": "KMS", + "method": "GetAppEnvEncryptPubKey", + "request": "AppId", + "response": "PublicKeyResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 101 + }, + { + "service": "KMS", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 103 + }, + { + "service": "KMS", + "method": "GetTempCaCert", + "request": "google.protobuf.Empty", + "response": "GetTempCaCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 105 + }, + { + "service": "KMS", + "method": "SignCert", + "request": "SignCertRequest", + "response": "SignCertResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 107 + }, + { + "service": "Admin", + "method": "ClearImageCache", + "request": "ClearImageCacheRequest", + "response": "google.protobuf.Empty", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 116 + }, + { + "service": "Onboard", + "method": "Bootstrap", + "request": "BootstrapRequest", + "response": "BootstrapResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 167 + }, + { + "service": "Onboard", + "method": "Onboard", + "request": "OnboardRequest", + "response": "OnboardResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 169 + }, + { + "service": "Onboard", + "method": "GetAttestationInfo", + "request": "google.protobuf.Empty", + "response": "AttestationInfoResponse", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 171 + }, + { + "service": "Onboard", + "method": "Finish", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/kms/rpc/proto/kms_rpc.proto", + "line": 173 + } + ], + "http_routes": [], + "toml_keys": [ + { + "key": "name", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "chrono.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-build-info.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "hex_fmt.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "rocket.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "x25519-dalek.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "yasna.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-kms-rpc.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "ra-rpc", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "ra-tls.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "load_config.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "reqwest", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "sha3.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "k256.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-guest-agent-rpc.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "http-client", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "scale.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "x509-parser", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "ring.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "safe-write.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "serde-duration.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-verifier", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-mr.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-attest.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "dstack-api-auth.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "default", + "source": "dstack/kms/Cargo.toml" + }, + { + "key": "src", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "out", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "libs", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "remappings", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "solc_version", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "optimizer", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "optimizer_runs", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "via_ir", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "ast", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "build_info", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "extra_output", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "fuzz", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "bracket_spacing", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "int_types", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "line_length", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "multiline_func_header", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "number_underscore", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "quote_style", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "tab_width", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "wrap_comments", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "anvil", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "phala", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "sepolia", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "base", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "phala", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "sepolia", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "base", + "source": "dstack/kms/auth-eth/foundry.toml" + }, + { + "key": "workers", + "source": "dstack/kms/kms.toml" + }, + { + "key": "max_blocking", + "source": "dstack/kms/kms.toml" + }, + { + "key": "ident", + "source": "dstack/kms/kms.toml" + }, + { + "key": "temp_dir", + "source": "dstack/kms/kms.toml" + }, + { + "key": "keep_alive", + "source": "dstack/kms/kms.toml" + }, + { + "key": "log_level", + "source": "dstack/kms/kms.toml" + }, + { + "key": "address", + "source": "dstack/kms/kms.toml" + }, + { + "key": "port", + "source": "dstack/kms/kms.toml" + }, + { + "key": "key", + "source": "dstack/kms/kms.toml" + }, + { + "key": "certs", + "source": "dstack/kms/kms.toml" + }, + { + "key": "ca_certs", + "source": "dstack/kms/kms.toml" + }, + { + "key": "mandatory", + "source": "dstack/kms/kms.toml" + }, + { + "key": "cert_dir", + "source": "dstack/kms/kms.toml" + }, + { + "key": "subject_postfix", + "source": "dstack/kms/kms.toml" + }, + { + "key": "site_name", + "source": "dstack/kms/kms.toml" + }, + { + "key": "enforce_self_authorization", + "source": "dstack/kms/kms.toml" + }, + { + "key": "sev_snp_key_release", + "source": "dstack/kms/kms.toml" + }, + { + "key": "aws_nitro_tpm_key_release", + "source": "dstack/kms/kms.toml" + }, + { + "key": "insecure_allow_external_trust_anchors", + "source": "dstack/kms/kms.toml" + }, + { + "key": "verify", + "source": "dstack/kms/kms.toml" + }, + { + "key": "cache_dir", + "source": "dstack/kms/kms.toml" + }, + { + "key": "download_url", + "source": "dstack/kms/kms.toml" + }, + { + "key": "download_timeout", + "source": "dstack/kms/kms.toml" + }, + { + "key": "enabled", + "source": "dstack/kms/kms.toml" + }, + { + "key": "address", + "source": "dstack/kms/kms.toml" + }, + { + "key": "port", + "source": "dstack/kms/kms.toml" + }, + { + "key": "auth_token", + "source": "dstack/kms/kms.toml" + }, + { + "key": "htpasswd_file", + "source": "dstack/kms/kms.toml" + }, + { + "key": "insecure_no_auth", + "source": "dstack/kms/kms.toml" + }, + { + "key": "enabled", + "source": "dstack/kms/kms.toml" + }, + { + "key": "type", + "source": "dstack/kms/kms.toml" + }, + { + "key": "url", + "source": "dstack/kms/kms.toml" + }, + { + "key": "gateway_app_id", + "source": "dstack/kms/kms.toml" + }, + { + "key": "enabled", + "source": "dstack/kms/kms.toml" + }, + { + "key": "auto_bootstrap_domain", + "source": "dstack/kms/kms.toml" + }, + { + "key": "address", + "source": "dstack/kms/kms.toml" + }, + { + "key": "port", + "source": "dstack/kms/kms.toml" + }, + { + "key": "name", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "scale.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/kms/rpc/Cargo.toml" + } + ], + "existing_tests": [ + { + "name": "test_binary_search_simple", + "source": "dstack/kms/src/ct_log.rs" + }, + { + "name": "test_mr_config", + "source": "dstack/kms/src/main_service/amd_attest.rs" + }, + { + "name": "test_snp_measurement_document", + "source": "dstack/kms/src/main_service/amd_attest.rs" + }, + { + "name": "test_os_image_hash", + "source": "dstack/kms/src/main_service/amd_attest.rs" + }, + { + "name": "test_snp_measurement_document_json", + "source": "dstack/kms/src/main_service/amd_attest.rs" + }, + { + "name": "test_vm_config", + "source": "dstack/kms/src/main_service/amd_attest.rs" + }, + { + "name": "test_descriptor", + "source": "dstack/ra-rpc/src/openapi.rs" + }, + { + "name": "test_vsock_uri_parsing", + "source": "dstack/http-client/src/lib.rs" + } + ] + }, + "gateway": { + "roots": [ + "dstack/gateway", + "dstack/certbot", + "dstack/ct_monitor" + ], + "files": [ + "dstack/certbot/.gitignore", + "dstack/certbot/Cargo.toml", + "dstack/certbot/cli/Cargo.toml", + "dstack/certbot/cli/src/main.rs", + "dstack/certbot/src/acme_client.rs", + "dstack/certbot/src/acme_client/tests.rs", + "dstack/certbot/src/bot.rs", + "dstack/certbot/src/bot/tests.rs", + "dstack/certbot/src/dns01_client.rs", + "dstack/certbot/src/dns01_client/cloudflare.rs", + "dstack/certbot/src/http_client.rs", + "dstack/certbot/src/lib.rs", + "dstack/certbot/src/workdir.rs", + "dstack/ct_monitor/Cargo.toml", + "dstack/ct_monitor/src/main.rs", + "dstack/gateway/Cargo.toml", + "dstack/gateway/assets/cert.key", + "dstack/gateway/assets/cert.pem", + "dstack/gateway/docs/cluster-deployment.md", + "dstack/gateway/dstack-app/.gitignore", + "dstack/gateway/dstack-app/bootstrap-cluster.sh", + "dstack/gateway/dstack-app/builder/Dockerfile", + "dstack/gateway/dstack-app/builder/README.md", + "dstack/gateway/dstack-app/builder/build-image.sh", + "dstack/gateway/dstack-app/builder/entrypoint.sh", + "dstack/gateway/dstack-app/builder/shared/builder-pinned-packages.txt", + "dstack/gateway/dstack-app/builder/shared/pinned-packages.txt", + "dstack/gateway/dstack-app/deploy-to-vmm.sh", + "dstack/gateway/dstack-app/docker-compose.yaml", + "dstack/gateway/gateway.toml", + "dstack/gateway/rpc/Cargo.toml", + "dstack/gateway/rpc/build.rs", + "dstack/gateway/rpc/proto/gateway_rpc.proto", + "dstack/gateway/rpc/src/generated.rs", + "dstack/gateway/rpc/src/lib.rs", + "dstack/gateway/src/admin_auth.rs", + "dstack/gateway/src/admin_service.rs", + "dstack/gateway/src/cert_store.rs", + "dstack/gateway/src/config.rs", + "dstack/gateway/src/debug_service.rs", + "dstack/gateway/src/distributed_certbot.rs", + "dstack/gateway/src/gen_debug_key.rs", + "dstack/gateway/src/kv/https_client.rs", + "dstack/gateway/src/kv/mod.rs", + "dstack/gateway/src/kv/sync_service.rs", + "dstack/gateway/src/main.rs", + "dstack/gateway/src/main_service.rs", + "dstack/gateway/src/main_service/auth_client.rs", + "dstack/gateway/src/main_service/handshakes.rs", + "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config-2.snap", + "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config-3.snap", + "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__config.snap", + "dstack/gateway/src/main_service/snapshots/dstack_gateway__main_service__tests__empty_config.snap", + "dstack/gateway/src/main_service/tests.rs", + "dstack/gateway/src/models.rs", + "dstack/gateway/src/pp.rs", + "dstack/gateway/src/proxy.rs", + "dstack/gateway/src/proxy/io_bridge.rs", + "dstack/gateway/src/proxy/port_policy.rs", + "dstack/gateway/src/proxy/sni.rs", + "dstack/gateway/src/proxy/tls_passthough.rs", + "dstack/gateway/src/proxy/tls_terminate.rs", + "dstack/gateway/src/web_routes.rs", + "dstack/gateway/src/web_routes/route_index.rs", + "dstack/gateway/src/web_routes/wavekv_sync.rs", + "dstack/gateway/templates/dashboard.html", + "dstack/gateway/templates/rproxy.yaml", + "dstack/gateway/templates/wg.conf", + "dstack/gateway/test-run/.env.example", + "dstack/gateway/test-run/.gitignore", + "dstack/gateway/test-run/TESTING.md", + "dstack/gateway/test-run/cluster.sh", + "dstack/gateway/test-run/e2e/configs/gateway-1.toml", + "dstack/gateway/test-run/e2e/configs/gateway-2.toml", + "dstack/gateway/test-run/e2e/configs/gateway-3.toml", + "dstack/gateway/test-run/e2e/docker-compose.yml", + "dstack/gateway/test-run/e2e/pebble-config.json", + "dstack/gateway/test-run/e2e/run-e2e.sh", + "dstack/gateway/test-run/e2e/test.sh", + "dstack/gateway/test-run/test_certbot.sh", + "dstack/gateway/test-run/test_suite.sh" + ], + "rpc_methods": [ + { + "service": "Gateway", + "method": "RegisterCvm", + "request": "RegisterCvmRequest", + "response": "RegisterCvmResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 209 + }, + { + "service": "Gateway", + "method": "AcmeInfo", + "request": "google.protobuf.Empty", + "response": "AcmeInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 211 + }, + { + "service": "Gateway", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "InfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 213 + }, + { + "service": "Gateway", + "method": "GetPeers", + "request": "google.protobuf.Empty", + "response": "GetPeersResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 215 + }, + { + "service": "Debug", + "method": "RegisterCvm", + "request": "DebugRegisterCvmRequest", + "response": "RegisterCvmResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 221 + }, + { + "service": "Debug", + "method": "Info", + "request": "google.protobuf.Empty", + "response": "InfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 223 + }, + { + "service": "Debug", + "method": "GetSyncData", + "request": "google.protobuf.Empty", + "response": "DebugSyncDataResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 225 + }, + { + "service": "Debug", + "method": "GetProxyState", + "request": "google.protobuf.Empty", + "response": "DebugProxyStateResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 227 + }, + { + "service": "Admin", + "method": "Status", + "request": "google.protobuf.Empty", + "response": "StatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 377 + }, + { + "service": "Admin", + "method": "GetInfo", + "request": "GetInfoRequest", + "response": "GetInfoResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 379 + }, + { + "service": "Admin", + "method": "Exit", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 381 + }, + { + "service": "Admin", + "method": "RenewCert", + "request": "google.protobuf.Empty", + "response": "RenewCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 383 + }, + { + "service": "Admin", + "method": "ReloadCert", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 385 + }, + { + "service": "Admin", + "method": "SetCaa", + "request": "google.protobuf.Empty", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 387 + }, + { + "service": "Admin", + "method": "GetMeta", + "request": "google.protobuf.Empty", + "response": "GetMetaResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 389 + }, + { + "service": "Admin", + "method": "SetNodeUrl", + "request": "SetNodeUrlRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 391 + }, + { + "service": "Admin", + "method": "SetNodeStatus", + "request": "SetNodeStatusRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 393 + }, + { + "service": "Admin", + "method": "WaveKvStatus", + "request": "google.protobuf.Empty", + "response": "WaveKvStatusResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 395 + }, + { + "service": "Admin", + "method": "GetInstanceHandshakes", + "request": "GetInstanceHandshakesRequest", + "response": "GetInstanceHandshakesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 397 + }, + { + "service": "Admin", + "method": "GetGlobalConnections", + "request": "google.protobuf.Empty", + "response": "GlobalConnectionsStats", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 399 + }, + { + "service": "Admin", + "method": "GetNodeStatuses", + "request": "google.protobuf.Empty", + "response": "GetNodeStatusesResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 401 + }, + { + "service": "Admin", + "method": "ListDnsCredentials", + "request": "google.protobuf.Empty", + "response": "ListDnsCredentialsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 405 + }, + { + "service": "Admin", + "method": "GetDnsCredential", + "request": "GetDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 407 + }, + { + "service": "Admin", + "method": "CreateDnsCredential", + "request": "CreateDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 409 + }, + { + "service": "Admin", + "method": "UpdateDnsCredential", + "request": "UpdateDnsCredentialRequest", + "response": "DnsCredentialInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 411 + }, + { + "service": "Admin", + "method": "DeleteDnsCredential", + "request": "DeleteDnsCredentialRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 413 + }, + { + "service": "Admin", + "method": "GetDefaultDnsCredential", + "request": "google.protobuf.Empty", + "response": "GetDefaultDnsCredentialResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 415 + }, + { + "service": "Admin", + "method": "SetDefaultDnsCredential", + "request": "SetDefaultDnsCredentialRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 417 + }, + { + "service": "Admin", + "method": "ListZtDomains", + "request": "google.protobuf.Empty", + "response": "ListZtDomainsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 421 + }, + { + "service": "Admin", + "method": "GetZtDomain", + "request": "GetZtDomainRequest", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 423 + }, + { + "service": "Admin", + "method": "AddZtDomain", + "request": "ZtDomainConfig", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 425 + }, + { + "service": "Admin", + "method": "UpdateZtDomain", + "request": "ZtDomainConfig", + "response": "ZtDomainInfo", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 427 + }, + { + "service": "Admin", + "method": "DeleteZtDomain", + "request": "DeleteZtDomainRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 429 + }, + { + "service": "Admin", + "method": "RenewZtDomainCert", + "request": "RenewZtDomainCertRequest", + "response": "RenewZtDomainCertResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 431 + }, + { + "service": "Admin", + "method": "ForceReleaseCertLock", + "request": "ForceReleaseCertLockRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 433 + }, + { + "service": "Admin", + "method": "ListCertAttestations", + "request": "ListCertAttestationsRequest", + "response": "ListCertAttestationsResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 435 + }, + { + "service": "Admin", + "method": "GetCertbotConfig", + "request": "google.protobuf.Empty", + "response": "CertbotConfigResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 439 + }, + { + "service": "Admin", + "method": "SetCertbotConfig", + "request": "SetCertbotConfigRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 441 + }, + { + "service": "Admin", + "method": "SetInstancePortPolicy", + "request": "SetInstancePortPolicyRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 447 + }, + { + "service": "Admin", + "method": "ClearInstancePortPolicy", + "request": "ClearInstancePortPolicyRequest", + "response": "google.protobuf.Empty", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 450 + }, + { + "service": "Admin", + "method": "GetInstancePortPolicy", + "request": "GetInstancePortPolicyRequest", + "response": "GetInstancePortPolicyResponse", + "source": "dstack/gateway/rpc/proto/gateway_rpc.proto", + "line": 453 + } + ], + "http_routes": [ + { + "method": "GET", + "path": "/", + "source": "dstack/gateway/src/web_routes.rs" + }, + { + "method": "GET", + "path": "/health", + "source": "dstack/gateway/src/web_routes.rs" + }, + { + "method": "POST", + "path": "/wavekv/sync/", + "source": "dstack/gateway/src/web_routes/wavekv_sync.rs" + } + ], + "toml_keys": [ + { + "key": "name", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-attest.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "arc-swap.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "rocket", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "ipnet", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "clap", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "shared_child.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "rustls.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tokio-rustls", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "rinja.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "parcelona.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "hickory-resolver.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "pin-project.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-build-info.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "ra-rpc", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-gateway-rpc.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "certbot.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "bytes.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "safe-write.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "smallvec.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "futures.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "cmd_lib.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "load_config.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-kms-rpc.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "ra-tls.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-guest-agent-rpc.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "http-client", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "serde-duration.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "reqwest", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "hyper", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "hyper-util", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "hyper-rustls.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "http-body-util.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "x509-parser.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "jemallocator.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "proxy-protocol.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "wavekv.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tdx-attest.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "flate2.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "uuid", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "rmp-serde.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "base64.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "dstack-api-auth.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "cached-cell.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "nix", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "insta.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/gateway/Cargo.toml" + }, + { + "key": "workers", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "max_blocking", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "ident", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "temp_dir", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "keep_alive", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "log_level", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "address", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "kms_url", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "set_ulimit", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "rpc_domain", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "insecure_allow_external_trust_anchors", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "url", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "address", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "auth_token", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "htpasswd_file", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "insecure_no_auth", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "insecure_enable_debug_rpc", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "insecure_skip_attestation", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "key_file", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "address", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "public_key", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "private_key", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "ip", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "reserved_net", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "client_ip_range", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "config_path", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "interface", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "endpoint", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "tls_crypto_provider", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "tls_versions", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "listen_addr", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "agent_port", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "buffer_size", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "connect_top_n", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "localhost_enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "app_address_ns_prefix", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "app_address_ns_compat", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "workers", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "external_port", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "max_connections_per_app", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "inbound_pp_enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "max_retries", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "backoff_initial", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "backoff_max", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "connect", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "handshake", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "cache_top_n", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "dns_resolve", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "data_timeout_enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "idle", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "write", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "shutdown", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "total", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "pp_header", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "interval", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "node_timeout", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "node_id", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "my_url", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "interval", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "bootnode", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "data_dir", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "persist_interval", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "sync_connections_enabled", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "sync_connections_interval", + "source": "dstack/gateway/gateway.toml" + }, + { + "key": "name", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "prpc.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "prost.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "scale", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "prpc-build.workspace", + "source": "dstack/gateway/rpc/Cargo.toml" + }, + { + "key": "log_level", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "ca_certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "mandatory", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "kms_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "rpc_domain", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "auth_token", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "insecure_enable_debug_rpc", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "insecure_skip_attestation", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "interval", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "my_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "bootnode", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "node_id", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "data_dir", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "private_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "public_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "ip", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "reserved_net", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "client_ip_range", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "config_path", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "interface", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "endpoint", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "listen_addr", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "tappd_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "external_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-1.toml" + }, + { + "key": "log_level", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "ca_certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "mandatory", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "kms_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "rpc_domain", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "auth_token", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "insecure_enable_debug_rpc", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "insecure_skip_attestation", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "interval", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "my_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "bootnode", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "node_id", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "data_dir", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "private_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "public_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "ip", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "reserved_net", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "client_ip_range", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "config_path", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "interface", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "endpoint", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "listen_addr", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "tappd_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "external_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-2.toml" + }, + { + "key": "log_level", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "ca_certs", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "mandatory", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "kms_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "rpc_domain", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "auth_token", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "insecure_enable_debug_rpc", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "insecure_skip_attestation", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "address", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "enabled", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "interval", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "timeout", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "my_url", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "bootnode", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "node_id", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "data_dir", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "private_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "public_key", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "ip", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "reserved_net", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "client_ip_range", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "config_path", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "interface", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "endpoint", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "listen_addr", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "listen_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "tappd_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "external_port", + "source": "dstack/gateway/test-run/e2e/configs/gateway-3.toml" + }, + { + "key": "name", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "bon.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "bytes.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "enum_dispatch.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "hickory-resolver.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "http.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "http-body-util.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "instant-acme.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "path-absolutize.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "rcgen.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "reqwest.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "time.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "tokio.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "x509-parser.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "rand.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/certbot/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "certbot.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "documented.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "toml_edit.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "rustls.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/certbot/cli/Cargo.toml" + } + ], + "existing_tests": [ + { + "name": "test_validate", + "source": "dstack/gateway/src/config.rs" + }, + { + "name": "test_cert_store_basic", + "source": "dstack/gateway/src/cert_store.rs" + }, + { + "name": "test_cert_store_builder", + "source": "dstack/gateway/src/cert_store.rs" + }, + { + "name": "test_cert_store_wildcard", + "source": "dstack/gateway/src/cert_store.rs" + }, + { + "name": "test_parse_destination", + "source": "dstack/gateway/src/proxy.rs" + }, + { + "name": "test_resolve_app_address", + "source": "dstack/gateway/src/proxy/tls_passthough.rs" + }, + { + "name": "test_empty_config", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_port_policy_restrict_mode_allows_listed_only", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_port_policy_disabled_allows_all", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_port_policy_unknown_fails_closed", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_port_policy_unknown_instance_bypasses_check", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_admin_override_takes_precedence", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_admin_override_can_open_what_instance_restricts", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_clear_admin_override_reverts_to_instance_policy", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_admin_override_unknown_instance_errors", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_admin_override_survives_compose_hash_change", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_config", + "source": "dstack/gateway/src/main_service/tests.rs" + }, + { + "name": "test_certbot", + "source": "dstack/certbot/src/bot/tests.rs" + }, + { + "name": "test_request_new_certificate", + "source": "dstack/certbot/src/acme_client/tests.rs" + } + ] + }, + "verifier": { + "roots": [ + "dstack/verifier", + "dstack/dstack-mr", + "dstack/dstack-attest", + "dstack/ra-tls", + "dstack/cc-eventlog", + "dstack/tpm-qvl", + "dstack/sev-snp-qvl", + "dstack/nsm-qvl" + ], + "files": [ + "dstack/cc-eventlog/Cargo.toml", + "dstack/cc-eventlog/samples/ccel.bin", + "dstack/cc-eventlog/samples/tpm_eventlog.bin", + "dstack/cc-eventlog/src/codecs.rs", + "dstack/cc-eventlog/src/lib.rs", + "dstack/cc-eventlog/src/runtime_events.rs", + "dstack/cc-eventlog/src/snapshots/cc_eventlog__tests__parse_ccel-2.snap", + "dstack/cc-eventlog/src/snapshots/cc_eventlog__tests__parse_ccel.snap", + "dstack/cc-eventlog/src/tcg.rs", + "dstack/cc-eventlog/src/tdx.rs", + "dstack/cc-eventlog/src/tpm.rs", + "dstack/dstack-attest/Cargo.toml", + "dstack/dstack-attest/src/amd_sev_snp.rs", + "dstack/dstack-attest/src/attestation.rs", + "dstack/dstack-attest/src/aws_nitro_tpm.rs", + "dstack/dstack-attest/src/lib.rs", + "dstack/dstack-attest/src/sev_snp.rs", + "dstack/dstack-attest/src/v1.rs", + "dstack/dstack-attest/tests/nitro_attestation.bin", + "dstack/dstack-attest/tests/nitro_attestation_dbg.bin", + "dstack/dstack-attest/tests/nitro_verify.rs", + "dstack/dstack-attest/tests/sev_snp_ask.pem", + "dstack/dstack-attest/tests/sev_snp_attestation.bin", + "dstack/dstack-attest/tests/sev_snp_fixture.README.md", + "dstack/dstack-attest/tests/sev_snp_vcek.pem", + "dstack/dstack-attest/tests/sev_snp_verify.rs", + "dstack/dstack-attest/tests/snapshots/nitro_verify__app_info.snap", + "dstack/dstack-attest/tests/snapshots/nitro_verify__nitro_report.snap", + "dstack/dstack-mr/.gitignore", + "dstack/dstack-mr/Cargo.toml", + "dstack/dstack-mr/cli/Cargo.toml", + "dstack/dstack-mr/cli/src/main.rs", + "dstack/dstack-mr/src/acpi.rs", + "dstack/dstack-mr/src/kernel.rs", + "dstack/dstack-mr/src/lib.rs", + "dstack/dstack-mr/src/machine.rs", + "dstack/dstack-mr/src/main.rs", + "dstack/dstack-mr/src/measurement.rs", + "dstack/dstack-mr/src/num.rs", + "dstack/dstack-mr/src/sev.rs", + "dstack/dstack-mr/src/tdvf.rs", + "dstack/dstack-mr/src/tdx.rs", + "dstack/dstack-mr/src/util.rs", + "dstack/dstack-mr/tests/tdvf_parse.rs", + "dstack/nsm-qvl/Cargo.toml", + "dstack/nsm-qvl/certs/AWS_NitroEnclaves_Root-G1.pem", + "dstack/nsm-qvl/src/collateral.rs", + "dstack/nsm-qvl/src/lib.rs", + "dstack/nsm-qvl/src/verify.rs", + "dstack/nsm-qvl/tests/nitro_attestation.README.md", + "dstack/nsm-qvl/tests/nitro_attestation.bin", + "dstack/nsm-qvl/tests/verify_test.rs", + "dstack/ra-tls/Cargo.toml", + "dstack/ra-tls/assets/tdx_quote", + "dstack/ra-tls/src/attestation.rs", + "dstack/ra-tls/src/cert.rs", + "dstack/ra-tls/src/kdf.rs", + "dstack/ra-tls/src/lib.rs", + "dstack/ra-tls/src/oids.rs", + "dstack/ra-tls/src/traits.rs", + "dstack/sev-snp-qvl/Cargo.toml", + "dstack/sev-snp-qvl/src/lib.rs", + "dstack/tpm-qvl/Cargo.toml", + "dstack/tpm-qvl/certs/AWS_NitroEnclaves_Root-G1.pem", + "dstack/tpm-qvl/certs/gcp-root-ca.pem", + "dstack/tpm-qvl/src/collateral.rs", + "dstack/tpm-qvl/src/lib.rs", + "dstack/tpm-qvl/src/verify.rs", + "dstack/verifier/Cargo.toml", + "dstack/verifier/README.md", + "dstack/verifier/builder/Dockerfile", + "dstack/verifier/builder/build-image.sh", + "dstack/verifier/builder/shared/builder-pinned-packages.txt", + "dstack/verifier/builder/shared/pinned-packages.txt", + "dstack/verifier/builder/shared/qemu-pinned-packages.txt", + "dstack/verifier/dstack-verifier.toml", + "dstack/verifier/fixtures/quote-report.json", + "dstack/verifier/fixtures/sev-snp-attestation.json", + "dstack/verifier/fixtures/sev-snp.README.md", + "dstack/verifier/fixtures/tdx-lite-attestation.json", + "dstack/verifier/fixtures/tdx-lite-getquote.json", + "dstack/verifier/fixtures/tdx-lite.README.md", + "dstack/verifier/src/lib.rs", + "dstack/verifier/src/main.rs", + "dstack/verifier/src/types.rs", + "dstack/verifier/src/verification.rs", + "dstack/verifier/test.sh" + ], + "rpc_methods": [], + "http_routes": [ + { + "method": "POST", + "path": "/verify", + "source": "dstack/verifier/src/main.rs" + }, + { + "method": "GET", + "path": "/health", + "source": "dstack/verifier/src/main.rs" + } + ], + "toml_keys": [ + { + "key": "name", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "homepage.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "repository.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "required-features", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "clap", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "figment", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "rocket", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tracing-subscriber", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "reqwest.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tempfile.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "ra-tls.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "dstack-attest.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "dstack-mr.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "dcap-qvl.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tpm-qvl.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "tpm-types.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "nsm-attest.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "ez-hash.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "hex-literal.workspace", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "default", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "binary", + "source": "dstack/verifier/Cargo.toml" + }, + { + "key": "address", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "port", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "image_cache_dir", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "image_download_url", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "image_download_timeout_secs", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "insecure_allow_external_trust_anchors", + "source": "dstack/verifier/dstack-verifier.toml" + }, + { + "key": "name", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "description", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "serde", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "serde_json", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "hex", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "thiserror.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "binrw.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "object.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "hex-literal.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "bon.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "log.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "scale.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "reqwest", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "flate2.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "tar.workspace", + "source": "dstack/dstack-mr/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "version", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "edition", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "path", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "clap.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "dstack-mr.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "hex", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "serde_json", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "tracing-subscriber.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "size-parser.workspace", + "source": "dstack/dstack-mr/cli/Cargo.toml" + }, + { + "key": "name", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "version.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "authors.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "edition.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "license.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "anyhow.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "cc-eventlog.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "rmp-serde.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "dcap-qvl.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "dstack-types.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "ez-hash.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "fs-err.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "safe-write.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "rustix.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "hex.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "hex_fmt.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "or-panic.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "pem.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "scale", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "sev-snp-attest.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "sev-snp-qvl.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "serde.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "serde-human-bytes.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "serde_json.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "sha2.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "sha3.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tdx-attest.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tpm-attest.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "nsm-attest.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "nsm-qvl.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tpm-qvl.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tpm-types.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tracing.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "x509-parser.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "insta.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "errify.workspace", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "aws-nitro-enclaves-nsm-api", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "ciborium", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "hmac", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "rand", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "rsa", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tpm2", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "quote", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "futures", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "tokio", + "source": "dstack/dstack-attest/Cargo.toml" + }, + { + "key": "dstack-mr", + "source": "dstack/dstack-attest/Cargo.toml" + } + ], + "existing_tests": [ + { + "name": "test_verifier", + "source": "dstack/verifier/src/verification.rs" + }, + { + "name": "test_attestation_verifier", + "source": "dstack/verifier/src/verification.rs" + }, + { + "name": "test_tdvf_parse_produces_correct_measurements", + "source": "dstack/dstack-mr/tests/tdvf_parse.rs" + }, + { + "name": "test_to_report_data_with_hash", + "source": "dstack/dstack-attest/src/attestation.rs" + }, + { + "name": "test_mr_config_document", + "source": "dstack/dstack-attest/src/v1.rs" + }, + { + "name": "test_derive_key32", + "source": "dstack/ra-tls/src/kdf.rs" + }, + { + "name": "test_derive_key256", + "source": "dstack/ra-tls/src/kdf.rs" + }, + { + "name": "test_derive_key_pair", + "source": "dstack/ra-tls/src/kdf.rs" + }, + { + "name": "test_derive_dh_secret_stable_output", + "source": "dstack/ra-tls/src/kdf.rs" + }, + { + "name": "test_csr_signing_and_verification", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_invalid_confirm_word", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_cert_request_parses_ip_alt_names_as_ip_sans", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_event_log_compression", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_event_log_compression_ratio", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_csr_v2_scale_encoding_stable", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_csr_v2_scale_encoding_stable_with_tdx_quote", + "source": "dstack/ra-tls/src/cert.rs" + }, + { + "name": "test_decode_empty", + "source": "dstack/cc-eventlog/src/tpm.rs" + }, + { + "name": "test_decode_gcp_tpm_eventlog", + "source": "dstack/cc-eventlog/src/tpm.rs" + }, + { + "name": "test_filter_by_pcr", + "source": "dstack/cc-eventlog/src/tpm.rs" + }, + { + "name": "test_pcr2_uki_hash_extraction", + "source": "dstack/cc-eventlog/src/tpm.rs" + }, + { + "name": "test_parse_cose_sign1", + "source": "dstack/nsm-qvl/tests/verify_test.rs" + }, + { + "name": "test_parse_attestation_document", + "source": "dstack/nsm-qvl/tests/verify_test.rs" + }, + { + "name": "test_verify_attestation_full", + "source": "dstack/nsm-qvl/tests/verify_test.rs" + }, + { + "name": "test_root_ca_parsing", + "source": "dstack/nsm-qvl/src/verify.rs" + } + ] + } + } +} diff --git a/tools/dstack-test/web.py b/tools/dstack-test/web.py index a796cfbde..a13b19656 100644 --- a/tools/dstack-test/web.py +++ b/tools/dstack-test/web.py @@ -27,6 +27,8 @@ def __init__( host: str, port: int, ): + """Create a dashboard bound to *host* and *port*.""" + class Handler(http.server.BaseHTTPRequestHandler): def log_message(self, _format: str, *_args: Any) -> None: pass @@ -70,13 +72,16 @@ def do_GET(self) -> None: @property def address(self) -> tuple[str, int]: + """Return the effective listening address.""" host, port = self.server.server_address[:2] return str(host), int(port) def start(self) -> None: + """Start serving the dashboard in the background.""" self.thread.start() def close(self) -> None: + """Stop the dashboard and release its listening socket.""" self.server.shutdown() self.server.server_close() self.thread.join() From 8d9fa09968a155f73069f631213034f02e42f86e Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 23 Jul 2026 04:57:42 -0700 Subject: [PATCH 2/4] feat(testing): add hierarchical case browser --- .../core-components-full/feature-audit.md | 1 - tools/dstack-test/dstack-test | 40 ++++++++++++++++++- tools/dstack-test/tests/test_dstack_test.py | 6 +++ tools/dstack-test/web.py | 23 ++++++++--- 4 files changed, 63 insertions(+), 7 deletions(-) diff --git a/docs/test-plans/core-components-full/feature-audit.md b/docs/test-plans/core-components-full/feature-audit.md index ae961e85e..57e3feb15 100644 --- a/docs/test-plans/core-components-full/feature-audit.md +++ b/docs/test-plans/core-components-full/feature-audit.md @@ -713,4 +713,3 @@ This audit is derived from the repository source inventory and is the traceabili | `req-int-mixed-005` | `risk-int-mixed-005` | [tc-int-mixed-005](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-005/case.md#tc-int-mixed-005) — Verifier evidence compatibility for pinned releases | P0 | | `req-int-mixed-006` | `risk-int-mixed-006` | [tc-int-mixed-006](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-006/case.md#tc-int-mixed-006) — Rolling restart under four-version online mix | P0 | | `req-int-mixed-007` | `risk-int-mixed-007` | [tc-int-mixed-007](06-integration/04-pinned-mixed-version-matrix/tc-int-mixed-007/case.md#tc-int-mixed-007) — Optional and unknown protobuf fields across pinned versions | P0 | - diff --git a/tools/dstack-test/dstack-test b/tools/dstack-test/dstack-test index d9a1a6a89..6e30668cb 100755 --- a/tools/dstack-test/dstack-test +++ b/tools/dstack-test/dstack-test @@ -566,6 +566,9 @@ def dashboard_state(plan: render.Plan, run_id: str) -> dict[str, Any]: run = render.load_json(run_path) if run_path.is_file() else {} counts = {status: 0 for status in (*TERMINAL_STATUS, "RUNNING", "PENDING")} cases = [] + chapters: list[dict[str, Any]] = [] + chapter_by_id: dict[str, dict[str, Any]] = {} + section_by_id: dict[str, dict[str, Any]] = {} for case in plan.cases: result_path = case.path / "results" / run_id / "result.json" session_path = case.path / "results" / run_id / "session.jsonl" @@ -574,7 +577,27 @@ def dashboard_state(plan: render.Plan, run_id: str) -> dict[str, Any]: else: status = "RUNNING" if session_path.is_file() else "PENDING" counts[status] = counts.get(status, 0) + 1 - cases.append({"id": case.id, "title": case.title, "status": status}) + case_value = {"id": case.id, "title": case.title, "status": status} + cases.append(case_value) + chapter = chapter_by_id.get(case.chapter_id) + if chapter is None: + chapter = { + "id": case.chapter_id, + "title": case.chapter_title, + "sections": [], + } + chapter_by_id[case.chapter_id] = chapter + chapters.append(chapter) + section = section_by_id.get(case.section_id) + if section is None: + section = { + "id": case.section_id, + "title": case.section_title, + "cases": [], + } + section_by_id[case.section_id] = section + chapter["sections"].append(section) + section["cases"].append(case_value) orchestrator = plan.root / "results" / run_id / "orchestrator.jsonl" return { "title": plan.index.get("title", plan.index["id"]), @@ -585,6 +608,19 @@ def dashboard_state(plan: render.Plan, run_id: str) -> dict[str, Any]: else ("RUNNING" if orchestrator.is_file() else "PENDING"), "counts": counts, "cases": cases, + "chapters": chapters, + } + + +def dashboard_case(plan: render.Plan, case_id: str) -> dict[str, Any]: + """Return a rendered test-case specification for the live dashboard.""" + case = find_case(plan, case_id) + return { + "id": case.id, + "title": case.title, + "chapter": case.chapter_title, + "section": case.section_title, + "html": render.markdown_to_html(case.spec_path.read_text(encoding="utf-8")), } @@ -975,6 +1011,7 @@ def main(argv: list[str] | None = None) -> int: dashboard = web.Dashboard( lambda: dashboard_state(plan, args.run_id), lambda agent, offset: dashboard_log(plan, args.run_id, agent, offset), + lambda case_id: dashboard_case(plan, case_id), args.web_host, args.web_port, ) @@ -1051,6 +1088,7 @@ def main(argv: list[str] | None = None) -> int: dashboard = web.Dashboard( lambda: dashboard_state(plan, args.run_id), lambda agent, offset: dashboard_log(plan, args.run_id, agent, offset), + lambda case_id: dashboard_case(plan, case_id), args.host, args.port, ) diff --git a/tools/dstack-test/tests/test_dstack_test.py b/tools/dstack-test/tests/test_dstack_test.py index faa2a6c6f..5037efa4c 100644 --- a/tools/dstack-test/tests/test_dstack_test.py +++ b/tools/dstack-test/tests/test_dstack_test.py @@ -85,6 +85,12 @@ def test_dashboard_exposes_historical_status_and_log(self) -> None: plan = render.load_plan(FIXTURE) state = dstack_test.dashboard_state(plan, "run-demo") self.assertEqual(state["cases"][0]["status"], "PASS") + self.assertEqual( + state["chapters"][0]["sections"][0]["cases"][0]["id"], "tc-gw-pp-001" + ) + case = dstack_test.dashboard_case(plan, "tc-gw-pp-001") + self.assertEqual(case["chapter"], "Gateway") + self.assertIn("

Steps

", case["html"]) log = dstack_test.dashboard_log(plan, "run-demo", "case:tc-gw-pp-001", 0) self.assertGreater(log["next_offset"], 0) self.assertIn("thread.started", log["text"]) diff --git a/tools/dstack-test/web.py b/tools/dstack-test/web.py index a13b19656..865d08079 100644 --- a/tools/dstack-test/web.py +++ b/tools/dstack-test/web.py @@ -9,11 +9,17 @@ from typing import Any, Callable HTML = r"""dstack test

dstack test

Connecting…
Plan orchestrator
""" @@ -24,6 +30,7 @@ def __init__( self, state: Callable[[], dict[str, Any]], log: Callable[[str, int], dict[str, Any]], + case: Callable[[str], dict[str, Any]], host: str, port: int, ): @@ -64,6 +71,12 @@ def do_GET(self) -> None: ) except Exception as error: # noqa: BLE001 - API boundary self.reply({"error": str(error)}, 400) + elif parsed.path == "/api/case": + query = urllib.parse.parse_qs(parsed.query) + try: + self.reply(case(query.get("id", [""])[0])) + except Exception as error: # noqa: BLE001 - API boundary + self.reply({"error": str(error)}, 400) else: self.send_error(404) From c0e723459b34fdb08447ea5029342ab91e846d5f Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 23 Jul 2026 06:24:21 -0700 Subject: [PATCH 3/4] refactor(testing): extract dashboard HTML --- tools/dstack-test/dashboard.html | 15 +++++++++++++++ tools/dstack-test/web.py | 15 ++------------- 2 files changed, 17 insertions(+), 13 deletions(-) create mode 100644 tools/dstack-test/dashboard.html diff --git a/tools/dstack-test/dashboard.html b/tools/dstack-test/dashboard.html new file mode 100644 index 000000000..93527c076 --- /dev/null +++ b/tools/dstack-test/dashboard.html @@ -0,0 +1,15 @@ + + +dstack test

dstack test

Connecting…
Select a test case to view its complete specification and steps.
Plan orchestrator output
diff --git a/tools/dstack-test/web.py b/tools/dstack-test/web.py index 865d08079..8dfb06b3c 100644 --- a/tools/dstack-test/web.py +++ b/tools/dstack-test/web.py @@ -6,21 +6,10 @@ import json import threading import urllib.parse +from pathlib import Path from typing import Any, Callable -HTML = r"""dstack test

dstack test

Connecting…
Select a test case to view its complete specification and steps.
Plan orchestrator output
""" +HTML = (Path(__file__).with_name("dashboard.html")).read_text(encoding="utf-8") class Dashboard: From 458f253d89d84cda7b208a8f5af18d8d664ebeaa Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 23 Jul 2026 06:25:08 -0700 Subject: [PATCH 4/4] fix(testing): reload dashboard HTML per request --- tools/dstack-test/web.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tools/dstack-test/web.py b/tools/dstack-test/web.py index 8dfb06b3c..f61c068b3 100644 --- a/tools/dstack-test/web.py +++ b/tools/dstack-test/web.py @@ -9,7 +9,7 @@ from pathlib import Path from typing import Any, Callable -HTML = (Path(__file__).with_name("dashboard.html")).read_text(encoding="utf-8") +DASHBOARD_HTML = Path(__file__).with_name("dashboard.html") class Dashboard: @@ -41,7 +41,7 @@ def reply(self, value: Any, status: int = 200) -> None: def do_GET(self) -> None: parsed = urllib.parse.urlparse(self.path) if parsed.path == "/": - data = HTML.encode() + data = DASHBOARD_HTML.read_bytes() self.send_response(200) self.send_header("Content-Type", "text/html; charset=utf-8") self.send_header("Content-Length", str(len(data)))