Skip to content

Add transactional service control security boundary - #9

Merged
pschildgen87-code merged 53 commits into
mainfrom
feature/transactional-service-control-v1alpha1
Sep 4, 2026
Merged

pschildgen87-code merged 53 commits into
mainfrom
feature/transactional-service-control-v1alpha1

Conversation

@pschildgen87-code

@pschildgen87-code pschildgen87-code commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Completes Quantum Control Issue #8 as the first confirmation-gated privileged mutation milestone and advances Quantum Control to 0.3.0-alpha.1.

Closes #8.

Implemented

  • typed service.start, service.stop and service.restart operations
  • compile-time mutation target initially limited to quantum-runtime.service
  • root-controlled deployment policy may narrow but never broaden the compiled allowlist
  • fixed direct systemctl <verb> -- <unit> argv with no shell
  • root-owned durable confirmation-grant state moved into qcored
  • qcored independently authenticates human approvers and mutation executors
  • distinct operations.confirm and operations.execute.mutate permissions
  • approver and mutator roles separated
  • TCI actors structurally denied approval and mutation execution authority
  • immutable plan schema/digest/time/policy revalidation inside qcored
  • exact actor, session, action and parameter binding through plan + grant contracts
  • grant consumption before privileged execution with durable replay rejection after success, failure or broker restart
  • service precondition and postcondition capture
  • fixed loopback Quantum Runtime health verification for active postconditions
  • deterministic transaction timeout and polling
  • one defined recovery action toward the observed precondition when policy permits
  • public POST /v1/operations/execute-approved mutation route
  • durable audit of proposal/plan, approval, attempt, final result and recovery status
  • ambiguous post-submission transport results are recorded as unknown and never automatically retried
  • root-only quantum-control-broker systemd state directory
  • qcored hardening updated to permit only AF_UNIX plus AF_INET required for the fixed Runtime loopback health probe
  • versioned service-mutation policy schema, OpenAPI and deployment examples
  • README, API, architecture, security, audit, deployment, roadmap and changelog documentation updated for 0.3

Current mutation surface

Allowed operations:

service.start
service.stop
service.restart

Allowed mutation unit:

quantum-runtime.service

Still rejected:

quantum-control.service
ollama.service
apache/nginx
databases
packages
containers
domains/TLS
arbitrary systemd units
shell.exec

Verification

  • Quantum Control CI: passed on final head
  • legal/version checks: passed
  • gofmt: passed
  • go vet ./...: passed
  • race-enabled tests: passed
  • production binaries: passed
  • systemd verification: passed
  • Linux amd64 release archive build: passed
  • Linux arm64 release archive build: passed
  • release-package validation: passed

The release workflow intentionally skips publication on the pull request. After merge to main, the existing release workflow can publish v0.3.0-alpha.1 and trigger the connected Zenodo archive.

@pschildgen87-code
pschildgen87-code marked this pull request as ready for review September 4, 2026 08:22
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@pschildgen87-code
pschildgen87-code merged commit 292bffe into main Sep 4, 2026
2 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-04T08:24:58.403419Z be1f91d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[0.3] Add transactional service management with structured grant verification

1 participant