Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
198 commits
Select commit Hold shift + click to select a range
484e24d
test(infrastructure): add deterministic component harnesses
kvinwang Jul 31, 2026
386a0c1
test(plan): define core component acceptance coverage
kvinwang Jul 31, 2026
fab7310
test(results): promote verified component coverage
kvinwang Jul 31, 2026
691d89a
docs(testing): account for split product commits
kvinwang Jul 31, 2026
1e23338
docs(testing): record product PR split audit
kvinwang Jul 31, 2026
868304c
docs(testing): account for simulator PR split
kvinwang Jul 31, 2026
d2219c2
docs(testing): retain merged PRs in split inventory
kvinwang Jul 31, 2026
8befd32
test(simulator): enforce configured TPM node ownership
kvinwang Jul 31, 2026
f840509
docs(testing): account for TPM ownership correction
kvinwang Jul 31, 2026
e78558f
Revert "test(simulator): enforce configured TPM node ownership"
kvinwang Jul 31, 2026
6b51195
docs(testing): reject TPM node race tolerance
kvinwang Jul 31, 2026
c1665b8
docs(testing): add simulator retest watchlist
kvinwang Jul 31, 2026
e822ca0
test(gateway): use existing health and dashboard routes
kvinwang Aug 3, 2026
3cf9e55
test(verifier): assert simulator trust-root isolation
kvinwang Aug 4, 2026
ac6ad7f
test(verifier): validate embedded cache versions
kvinwang Aug 4, 2026
66954af
docs(testing): align rewritten PR accounting
kvinwang Aug 4, 2026
2576259
test(guest): validate normal swap boot lifecycle
kvinwang Aug 4, 2026
3225004
docs(testing): record closed supervisor socket PR
kvinwang Aug 4, 2026
d03b282
test(supervisor): validate UDS auto-start lifecycle
kvinwang Aug 4, 2026
2100057
test(util): validate certificate outputs independently
kvinwang Aug 4, 2026
4336246
test(supervisor): separate client lifecycle coverage
kvinwang Aug 4, 2026
bae8ab3
test(gateway): drop DNS credential encryption assumptions
kvinwang Aug 4, 2026
a65037a
test(gateway): cover app-address DNS failover
kvinwang Aug 5, 2026
12265d5
test(guest): pin wg-checker timing to a uniform 10s clock
kvinwang Aug 5, 2026
3893d91
test(vmm): cover filesystem-only CID reload
kvinwang Aug 5, 2026
b4fb098
test(gateway): register upgrade domain through admin API
kvinwang Aug 5, 2026
12266d2
test(gateway): provision upgrade domain through certbot
kvinwang Aug 5, 2026
e38e891
test(vmm): preserve stopped VM CID on reload
kvinwang Aug 5, 2026
19d3e66
test(guest): retarget tc-gos-observabil-003 at the gateway checker
kvinwang Aug 5, 2026
ce6f23d
test(gateway): cover ACME credential rotation
kvinwang Aug 5, 2026
c8b49c6
test(kms): cover CA persistence and renewal
kvinwang Aug 5, 2026
88dd497
test(vmm): retarget tc-vmm-serial-006 at log rotation
kvinwang Aug 6, 2026
f36bcf9
test(vmm): cover libvirt network filter lifecycle
kvinwang Aug 6, 2026
3cbb4f6
test(vmm): wait for restarted netd listener
kvinwang Aug 6, 2026
517db0b
test(vmm): avoid destructive netd readiness probe
kvinwang Aug 6, 2026
871cfe6
test(vmm): read generated NIC MACs from launch plan
kvinwang Aug 6, 2026
266c15c
test(vmm): isolate secondary host API port
kvinwang Aug 6, 2026
f96ab95
test(vmm): inject spoof traffic on the host interface
kvinwang Aug 6, 2026
1702ad0
test(vmm): preserve failure evidence and force cleanup
kvinwang Aug 6, 2026
c6b7a3f
test(vmm): verify filtered network survives QEMU restart
kvinwang Aug 6, 2026
384a96c
test(kms): restore sign-cert fixture binary
kvinwang Aug 7, 2026
df7be73
test: follow current guest and VMM configuration
kvinwang Aug 7, 2026
b8a742a
test(runner): retain sweep failure diagnostics
kvinwang Aug 7, 2026
de210c5
test(tdxlab): prepare deterministic run prerequisites
kvinwang Aug 7, 2026
561c625
test(tdxlab): provision pinned Foundry tools
kvinwang Aug 7, 2026
431914a
chore(kms): refresh authorization Bun locks
kvinwang Aug 7, 2026
8db4365
test(kms): resolve prepared startup binary
kvinwang Aug 7, 2026
b0782e7
test(tdxlab): resolve user toolchain paths
kvinwang Aug 7, 2026
b9ff2a5
test(kms): accept canonical empty Finish response
kvinwang Aug 7, 2026
0f3ac12
test(tdxlab): document prepared execution path
kvinwang Aug 7, 2026
98f1623
test(runner): fail sweeps with nonpassing cases
kvinwang Aug 7, 2026
87aac80
test(gateway): follow current debug config
kvinwang Aug 7, 2026
6dc9840
test(attestation): prepare legacy TDX image verification
kvinwang Aug 7, 2026
338b92b
test(attestation): refresh NitroTPM replay fixture
kvinwang Aug 7, 2026
2d64eae
test(guest): retain gateway checker failure context
kvinwang Aug 7, 2026
04456ca
test(tdxlab): build candidate guest prerequisites
kvinwang Aug 7, 2026
c8705b5
test(tdxlab): build images from a clean worktree
kvinwang Aug 7, 2026
dc192f1
test(tdxlab): discover flavor-specific mkosi outputs
kvinwang Aug 7, 2026
67ddb31
test(gateway): follow current public RPC route
kvinwang Aug 7, 2026
428af63
test(tdxlab): prepare current GCP TPM replay
kvinwang Aug 7, 2026
6696404
test(guest): capture gateway checker exit codes safely
kvinwang Aug 7, 2026
0f6054b
test(mkosi): prepare ephemeral OpenSSH host keys
kvinwang Aug 7, 2026
ac51074
test(guest): use deterministic quote output fault
kvinwang Aug 7, 2026
f1bb8bc
test(guest): use deterministic app-key output fault
kvinwang Aug 7, 2026
5062bd1
test(guest): follow atomic random output replacement
kvinwang Aug 7, 2026
47350a1
test(guest): use deterministic attestation output fault
kvinwang Aug 7, 2026
3c0b36a
test(guest): use deterministic get-keys output fault
kvinwang Aug 7, 2026
ed59cfa
test(simulator): prepare platform replay fixtures
kvinwang Aug 7, 2026
c7351c4
test(gateway): follow current RPC response contracts
kvinwang Aug 7, 2026
0a5abda
test(kms): accept current Empty JSON encoding
kvinwang Aug 7, 2026
f8e915f
test(kms): follow cloned shutdown handle
kvinwang Aug 7, 2026
1e66f8f
test(verifier): follow certificate profile validation
kvinwang Aug 7, 2026
4306551
test(verifier): use a valid oneshot config port
kvinwang Aug 7, 2026
4e41f2f
test(vmm): follow missing log response contract
kvinwang Aug 7, 2026
4a3f06f
test(vmm): materialize mutable image fixtures
kvinwang Aug 7, 2026
7ee5f29
test(kms): follow current root-key handover
kvinwang Aug 7, 2026
8b20c37
test(gateway): isolate fixture WireGuard subnets
kvinwang Aug 7, 2026
adfc1c4
test(gateway): follow current public info route
kvinwang Aug 7, 2026
9ce8197
test(gateway): accept current Empty exit response
kvinwang Aug 7, 2026
2f16948
test(gateway): verify malformed Empty framing
kvinwang Aug 7, 2026
b7f298d
test(gateway): follow current debug configuration
kvinwang Aug 7, 2026
4f7a1b8
test(gateway): follow on-demand TLS key generation
kvinwang Aug 7, 2026
c72dba0
test(gateway): edit prepared TLS paths by section
kvinwang Aug 7, 2026
751bf4e
test(gateway): accept current DNS Empty responses
kvinwang Aug 7, 2026
456413e
test(gateway): follow current certificate store suite
kvinwang Aug 7, 2026
3dfd108
test(vmm): follow private CID state contract
kvinwang Aug 7, 2026
ba4dcc5
test(vmm): stage reload fixtures across filesystems
kvinwang Aug 7, 2026
72b953b
test(vmm): prepare management port for config checks
kvinwang Aug 7, 2026
48f45ab
test(vmm): follow current UI RPC diagnostics
kvinwang Aug 7, 2026
6ff499a
test(vmm): follow current internal source matrices
kvinwang Aug 7, 2026
40cb233
test(guest): prepare a shell-capable log fixture image
kvinwang Aug 7, 2026
85aadd7
test(guest): capture log fixture preparation diagnostics
kvinwang Aug 7, 2026
97333a4
test(tdxlab): prepare dashboard log workload image
kvinwang Aug 7, 2026
88efa0d
test(tdxlab): bind dashboard preparation to case identity
kvinwang Aug 7, 2026
4603f64
test(kms): prepare finalized Ethereum head
kvinwang Aug 7, 2026
680cf61
test(integration): follow current gateway admin contract
kvinwang Aug 7, 2026
f5b5b5c
test(tdxlab): preserve guest image integrity
kvinwang Aug 7, 2026
bdbbf90
test(integration): bound gateway DNS fixture waits
kvinwang Aug 7, 2026
245f86b
test(integration): accept compatible Exit request evolution
kvinwang Aug 7, 2026
4082a7e
style(test): format integration matrix
kvinwang Aug 7, 2026
0fee423
test(integration): use mock DNS listener port
kvinwang Aug 7, 2026
6f9db7f
test(fixtures): bind cleanup to prepared state root
kvinwang Aug 7, 2026
fdf1e8c
test(integration): pin mock DNS zone
kvinwang Aug 7, 2026
9a6d69f
test(tdxlab): preflight Docker daemon
kvinwang Aug 7, 2026
e4f4a19
test(integration): model Cloudflare zone discovery
kvinwang Aug 7, 2026
f86044e
test(tdxlab): prepare user namespaces
kvinwang Aug 7, 2026
8755b93
test(integration): bridge legacy Gateway contracts
kvinwang Aug 7, 2026
e21a02a
test: fix mixed-version gateway failover harness
kvinwang Aug 8, 2026
adb4e66
test: select live KMS for failover preparation
kvinwang Aug 8, 2026
c275f94
test: prepare identity matrix alternate image
kvinwang Aug 8, 2026
ba06453
test: remove unused collateral prerequisite
kvinwang Aug 8, 2026
525e67b
test: restore PCCS collateral lifecycle matrix
kvinwang Aug 8, 2026
63d3f40
test: cover guest configuration entry matrix
kvinwang Aug 8, 2026
bc2a87a
test: update KMS compatibility certificate config
kvinwang Aug 8, 2026
db52b2a
test: restore KMS provider failover matrix
kvinwang Aug 8, 2026
b2f4558
test: restore gateway registration failover matrix
kvinwang Aug 8, 2026
c426ec5
test: follow split VMM restart policy tests
kvinwang Aug 8, 2026
68301b5
test: resolve Cargo for gateway refresh harness
kvinwang Aug 8, 2026
917d692
test: align VMM QEMU platform matrix
kvinwang Aug 8, 2026
f160651
test: follow current VMM networking contract
kvinwang Aug 8, 2026
9d15dc3
test: shorten VMM networking runtime paths
kvinwang Aug 8, 2026
bb4bc0a
test: start bridge VM before launch inspection
kvinwang Aug 8, 2026
3121cf0
test: prepare VMM hugepage prerequisites
kvinwang Aug 8, 2026
d246c26
test: exercise VMM hugepage lifecycle
kvinwang Aug 8, 2026
ef7eca8
test: explicitly start user network VM
kvinwang Aug 8, 2026
c7c9087
test: detach networking case supervisor
kvinwang Aug 8, 2026
a752d92
test: preserve VMM placement command evidence
kvinwang Aug 8, 2026
77bffd6
test: inspect supervised QEMU launch spec
kvinwang Aug 8, 2026
89b888b
test: follow attestation suite growth
kvinwang Aug 8, 2026
783271c
test: follow current mock attestation CLI
kvinwang Aug 8, 2026
e7ee5cd
test: require both cloud quote matrices
kvinwang Aug 8, 2026
2cebf53
test: replace removed verifier matrix selectors
kvinwang Aug 8, 2026
9dcb86d
test: align verifier coverage with current suites
kvinwang Aug 8, 2026
88a8b08
test: prepare isolated Docker subnet pool
kvinwang Aug 8, 2026
d49886e
test: preserve CAA concurrency diagnostics
kvinwang Aug 8, 2026
f51cabe
test: follow Gateway CAA operation locking
kvinwang Aug 8, 2026
66e30d6
test: restore current Certbot and auth regressions
kvinwang Aug 8, 2026
502d36e
test: follow current Gateway unit matrices
kvinwang Aug 8, 2026
d0e1f4d
test: follow current Gateway port-policy matrix
kvinwang Aug 8, 2026
e6cd898
test: make Gateway DNS routing fixture deterministic
kvinwang Aug 8, 2026
f802525
test: follow removed KMS certificate-log surface
kvinwang Aug 8, 2026
026db2e
test: execute current KMS binary test target
kvinwang Aug 8, 2026
0ba6c17
test: prepare seed-matched guest compatibility evidence
kvinwang Aug 8, 2026
c066b28
test: cover KMS signatures and injected Gateway outages
kvinwang Aug 8, 2026
3fffc50
test: select prepared TDX simulator explicitly
kvinwang Aug 8, 2026
7bad63f
test: run compatibility evidence without hardware TDX
kvinwang Aug 8, 2026
f5a9851
test: follow verifier certificate profile ownership
kvinwang Aug 8, 2026
e335d7a
build: record verifier test dependency
kvinwang Aug 8, 2026
3721fdc
test: prepare lease-owned attestation VMM
kvinwang Aug 8, 2026
6865037
test: separate physical and simulator collateral
kvinwang Aug 8, 2026
f1c3368
test: observe app identity during Gateway outage
kvinwang Aug 8, 2026
2dc46f9
test: separate Gateway boot and registration probes
kvinwang Aug 8, 2026
4e8ce94
test: exercise Gateway identity fallback
kvinwang Aug 8, 2026
2328d91
test: decouple identity probe from Gateway cache
kvinwang Aug 8, 2026
20ed724
test: allow clients without Gateway endpoints
kvinwang Aug 8, 2026
6e295d4
test: run guest compatibility on physical TDX
kvinwang Aug 8, 2026
79050d0
test: prepare physical compatibility collateral
kvinwang Aug 8, 2026
f40e787
test(verifier): avoid fixed cc-eventlog test count
kvinwang Aug 8, 2026
9af59b1
test: prepare simulator collateral before guest boot
kvinwang Aug 8, 2026
f1ab8d1
test: prepare simulated identity image variant
kvinwang Aug 8, 2026
48106f7
test(simulator): restore SEV-SNP ABI regression coverage
kvinwang Aug 8, 2026
19203b9
test(kms): prepare nested contract dependencies
kvinwang Aug 8, 2026
b1feb20
test(kms): probe event audit contract fixtures
kvinwang Aug 8, 2026
5c516f0
test(kms): probe runtime contract fixtures
kvinwang Aug 8, 2026
4fbac6d
test(guest): wait for bind conflict cleanup
kvinwang Aug 9, 2026
cdc87ba
test(gateway): synchronize concurrent renewal requests
kvinwang Aug 9, 2026
c57aa10
test(guest): cancel bind conflict restart jobs
kvinwang Aug 9, 2026
43a0778
test(gateway): prepare allocation wireguard fixture
kvinwang Aug 9, 2026
5b175bd
test(gateway): establish distributed renewal contention
kvinwang Aug 9, 2026
94c2b5f
test(gateway): isolate allocation recycle phase
kvinwang Aug 9, 2026
802565d
test(integration): retry rolling KMS metadata probes
kvinwang Aug 9, 2026
edeb90f
test(platform): wait for sealing provider recovery
kvinwang Aug 9, 2026
476267b
test(harness): probe lifecycle readiness deterministically
kvinwang Aug 9, 2026
15ea758
test(gateway): align allocation and renewal invariants
kvinwang Aug 9, 2026
dbbcb90
test(integration): await bounded KMS boot failure
kvinwang Aug 10, 2026
39dad3a
test(gateway): recheck distributed renewal freshness
kvinwang Aug 10, 2026
2bea72d
test(provider): retry transient sealing startup
kvinwang Aug 10, 2026
2a2d465
test(harness): harden runtime readiness probes
kvinwang Aug 10, 2026
8d8e77a
test(vmm): probe the browser endpoint directly
kvinwang Aug 10, 2026
4d98882
test(plan): cover post-baseline merged regressions
kvinwang Aug 14, 2026
60418e6
test(plan): refresh post-merge harness expectations
kvinwang Aug 14, 2026
0d19990
test(plan): align ACPI measurement matrix
kvinwang Aug 14, 2026
59f7de6
test(plan): harden dependency-backed harnesses
kvinwang Aug 14, 2026
260691d
test(plan): run prepared Playwright offline
kvinwang Aug 14, 2026
a757461
test(plan): make UI browser execution deterministic
kvinwang Aug 14, 2026
77da0a1
test(plan): preserve expected stargz failures
kvinwang Aug 14, 2026
6d63aaf
test(plan): unmount stale stargz snapshots
kvinwang Aug 14, 2026
e703e42
test(plan): use persistent stargz storage
kvinwang Aug 14, 2026
c87e77f
test(plan): wait for stargz unmounts
kvinwang Aug 14, 2026
fb2af5a
test(plan): preserve concurrent pull failures
kvinwang Aug 14, 2026
52c5b7d
test(plan): deterministically corrupt stargz layer
kvinwang Aug 14, 2026
9526f18
test(plan): accept truncated stargz diagnostics
kvinwang Aug 14, 2026
2810d2b
test(plan): assert corrupt stargz rejection by status
kvinwang Aug 14, 2026
0fcd4bd
test(plan): assert stargz outages by status
kvinwang Aug 14, 2026
062f481
test(plan): force remote stargz corruption path
kvinwang Aug 14, 2026
ec7e0cc
test(plan): zero corrupt stargz layer
kvinwang Aug 14, 2026
f687c17
test(plan): clear stargz cache before corruption
kvinwang Aug 14, 2026
a5f54d1
test(plan): restart registry after layer corruption
kvinwang Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
23 changes: 23 additions & 0 deletions REUSE.toml
Original file line number Diff line number Diff line change
Expand Up @@ -265,3 +265,26 @@ SPDX-License-Identifier = "CC0-1.0"
path = "dstack/crates/qemu-acpi/fixtures/*.bin"
SPDX-FileCopyrightText = "NONE"
SPDX-License-Identifier = "CC0-1.0"

[[annotations]]
path = [
"docs/test-plans/core-components-full/index.json",
"docs/test-plans/core-components-full/source-inventory.json",
]
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "docs/test-plans/core-components-full/configuration-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "docs/test-plans/core-components-full/api-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "docs/test-plans/core-components-full/source-coverage-map.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="tc-gos-tappd-001"></a>
# TC-GOS-TAPPD-001: Tappd.DeriveKey

## Metadata

- Priority: P1
- Type: Functional, API, Security, Regression
- Minimum environment: SIMULATOR
- Automation: Yes
- Requirements: [req-gos-tappd-001](../../../feature-audit.md#req-gos-tappd-001)
- Risks: [risk-gos-tappd-001](../../../feature-audit.md#risk-gos-tappd-001)
- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:15`

## Prepared execution knowledge

- Read and obey [`automation/execution-guide.md`](../../../automation/execution-guide.md) before executing Step 1.
- Read `DSTACK_TEST_RUNTIME_MANIFEST` once and use its prepared binaries, shared Cargo target, fixture paths, commit, and toolchain as authoritative. Do not rediscover them from processes, old sessions, or broad source searches.
- Runtime state and evidence remain case-scoped even though immutable build outputs are shared.
- Prepared RPC contract: `Tappd.DeriveKey` takes `DeriveKeyArgs` (`path: string`, `subject: string`, `alt_names: string`, `usage_ra_tls: bool`, `usage_server_auth: bool`, `usage_client_auth: bool`, `random_seed: bool`) and returns `GetTlsKeyResponse` (`key: string`, `certificate_chain: string`). The authoritative field matrix is the matching entry in [`api-inventory.json`](../../../api-inventory.json); do not reconstruct it from implementation source.
- For the candidate guest-agent target, use `automation/start-simulator.sh` and the recorded service socket/route, then `automation/stop-simulator.sh`. Do not compile or design another simulator launcher.
- Exercise the case-prescribed absent/default/valid/boundary-invalid/unknown-field and JSON/protobuf representations with a checked-in helper when available. Keep secret response material in memory and record only structural checks, public material, and hashes.
- If a mismatch occurs, write the provisional result first. Perform narrow source-level root-cause analysis only when failure investigation is enabled.

## Objective

Verify the complete request, response, authorization, state transition, and error contract of `Tappd.DeriveKey`.

## Preconditions

1. The shared plan prerequisites are healthy and the target listener is reachable.
2. Commands use isolated test data and preserve native request and response output.

## Test Data

The `Tappd.DeriveKey` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit.

Use a unique run-scoped identifier and non-production credentials.

## Steps

<a id="tc-gos-tappd-001-step-01"></a>
### Step 1: Inspect the effective prerequisite

Query the relevant health, configuration, and baseline state for tappd.derivekey.

**Expected results:**

- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object.

<a id="tc-gos-tappd-001-step-02"></a>
### Step 2: Exercise the behavior

Invoke `Tappd.DeriveKey` with a valid `DeriveKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential.

**Expected results:**

- The valid call returns `GetTlsKeyResponse` with every documented field and exhibits the documented `DeriveKey` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials.

<a id="tc-gos-tappd-001-step-03"></a>
### Step 3: Verify state, isolation, and diagnostics

Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface.

**Expected results:**

- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability.

## Postconditions

Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts.
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="tc-gos-tappd-002"></a>
# TC-GOS-TAPPD-002: Tappd.DeriveK256Key

## Metadata

- Priority: P1
- Type: Functional, API, Security, Regression
- Minimum environment: SIMULATOR
- Automation: Yes
- Requirements: [req-gos-tappd-002](../../../feature-audit.md#req-gos-tappd-002)
- Risks: [risk-gos-tappd-002](../../../feature-audit.md#risk-gos-tappd-002)
- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:18`

## Prepared execution knowledge

- Read and obey [`automation/execution-guide.md`](../../../automation/execution-guide.md) before executing Step 1.
- Read `DSTACK_TEST_RUNTIME_MANIFEST` once and use its prepared binaries, shared Cargo target, fixture paths, commit, and toolchain as authoritative. Do not rediscover them from processes, old sessions, or broad source searches.
- Runtime state and evidence remain case-scoped even though immutable build outputs are shared.
- Prepared RPC contract: `Tappd.DeriveK256Key` takes `GetKeyArgs` (`path: string`, `purpose: string`, `algorithm: string`) and returns `DeriveK256KeyResponse` (`k256_key: bytes`, `k256_signature_chain: bytes`). The authoritative field matrix is the matching entry in [`api-inventory.json`](../../../api-inventory.json); do not reconstruct it from implementation source.
- For the candidate guest-agent target, use `automation/start-simulator.sh` and the recorded service socket/route, then `automation/stop-simulator.sh`. Do not compile or design another simulator launcher.
- Exercise the case-prescribed absent/default/valid/boundary-invalid/unknown-field and JSON/protobuf representations with a checked-in helper when available. Keep secret response material in memory and record only structural checks, public material, and hashes.
- If a mismatch occurs, write the provisional result first. Perform narrow source-level root-cause analysis only when failure investigation is enabled.

## Objective

Verify the complete request, response, authorization, state transition, and error contract of `Tappd.DeriveK256Key`.

## Preconditions

1. The shared plan prerequisites are healthy and the target listener is reachable.
2. Commands use isolated test data and preserve native request and response output.

## Test Data

The `Tappd.DeriveK256Key` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit.

Use a unique run-scoped identifier and non-production credentials.

## Steps

<a id="tc-gos-tappd-002-step-01"></a>
### Step 1: Inspect the effective prerequisite

Query the relevant health, configuration, and baseline state for tappd.derivek256key.

**Expected results:**

- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object.

<a id="tc-gos-tappd-002-step-02"></a>
### Step 2: Exercise the behavior

Invoke `Tappd.DeriveK256Key` with a valid `GetKeyArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential.

**Expected results:**

- The valid call returns `DeriveK256KeyResponse` with every documented field and exhibits the documented `DeriveK256Key` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials.

<a id="tc-gos-tappd-002-step-03"></a>
### Step 3: Verify state, isolation, and diagnostics

Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface.

**Expected results:**

- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability.

## Postconditions

Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts.
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="tc-gos-tappd-003"></a>
# TC-GOS-TAPPD-003: Tappd.TdxQuote

## Metadata

- Priority: P1
- Type: Functional, API, Security, Regression
- Minimum environment: SIMULATOR
- Automation: Yes
- Requirements: [req-gos-tappd-003](../../../feature-audit.md#req-gos-tappd-003)
- Risks: [risk-gos-tappd-003](../../../feature-audit.md#risk-gos-tappd-003)
- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:21`

## Prepared execution knowledge

- Read and obey [`automation/execution-guide.md`](../../../automation/execution-guide.md) before executing Step 1.
- Read `DSTACK_TEST_RUNTIME_MANIFEST` once and use its prepared binaries, shared Cargo target, fixture paths, commit, and toolchain as authoritative. Do not rediscover them from processes, old sessions, or broad source searches.
- Runtime state and evidence remain case-scoped even though immutable build outputs are shared.
- Prepared RPC contract: `Tappd.TdxQuote` takes `TdxQuoteArgs` (`report_data: bytes`, `hash_algorithm: string`, `prefix: string`) and returns `TdxQuoteResponse` (`quote: bytes`, `event_log: string`, `hash_algorithm: string`, `prefix: string`). The authoritative field matrix is the matching entry in [`api-inventory.json`](../../../api-inventory.json); do not reconstruct it from implementation source.
- For the candidate guest-agent target, use `automation/start-simulator.sh` and the recorded service socket/route, then `automation/stop-simulator.sh`. Do not compile or design another simulator launcher.
- Exercise the case-prescribed absent/default/valid/boundary-invalid/unknown-field and JSON/protobuf representations with a checked-in helper when available. Keep secret response material in memory and record only structural checks, public material, and hashes.
- If a mismatch occurs, write the provisional result first. Perform narrow source-level root-cause analysis only when failure investigation is enabled.

## Objective

Verify the complete request, response, authorization, state transition, and error contract of `Tappd.TdxQuote`.

## Preconditions

1. The shared plan prerequisites are healthy and the target listener is reachable.
2. Commands use isolated test data and preserve native request and response output.

## Test Data

The `Tappd.TdxQuote` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit.

Use a unique run-scoped identifier and non-production credentials.

## Steps

<a id="tc-gos-tappd-003-step-01"></a>
### Step 1: Inspect the effective prerequisite

Query the relevant health, configuration, and baseline state for tappd.tdxquote.

**Expected results:**

- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object.

<a id="tc-gos-tappd-003-step-02"></a>
### Step 2: Exercise the behavior

Invoke `Tappd.TdxQuote` with a valid `TdxQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential.

**Expected results:**

- The valid call returns `TdxQuoteResponse` with every documented field and exhibits the documented `TdxQuote` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials.

<a id="tc-gos-tappd-003-step-03"></a>
### Step 3: Verify state, isolation, and diagnostics

Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface.

**Expected results:**

- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability.

## Postconditions

Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts.
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="tc-gos-tappd-004"></a>
# TC-GOS-TAPPD-004: Tappd.RawQuote

## Metadata

- Priority: P1
- Type: Functional, API, Security, Regression
- Minimum environment: SIMULATOR
- Automation: Yes
- Requirements: [req-gos-tappd-004](../../../feature-audit.md#req-gos-tappd-004)
- Risks: [risk-gos-tappd-004](../../../feature-audit.md#risk-gos-tappd-004)
- Source: `dstack/guest-agent/rpc/proto/agent_rpc.proto:28`

## Prepared execution knowledge

- Read and obey [`automation/execution-guide.md`](../../../automation/execution-guide.md) before executing Step 1.
- Read `DSTACK_TEST_RUNTIME_MANIFEST` once and use its prepared binaries, shared Cargo target, fixture paths, commit, and toolchain as authoritative. Do not rediscover them from processes, old sessions, or broad source searches.
- Runtime state and evidence remain case-scoped even though immutable build outputs are shared.
- Prepared RPC contract: `Tappd.RawQuote` takes `RawQuoteArgs` (`report_data: bytes`) and returns `TdxQuoteResponse` (`quote: bytes`, `event_log: string`, `hash_algorithm: string`, `prefix: string`). The authoritative field matrix is the matching entry in [`api-inventory.json`](../../../api-inventory.json); do not reconstruct it from implementation source.
- For the candidate guest-agent target, use `automation/start-simulator.sh` and the recorded service socket/route, then `automation/stop-simulator.sh`. Do not compile or design another simulator launcher.
- Exercise the case-prescribed absent/default/valid/boundary-invalid/unknown-field and JSON/protobuf representations with a checked-in helper when available. Keep secret response material in memory and record only structural checks, public material, and hashes.
- If a mismatch occurs, write the provisional result first. Perform narrow source-level root-cause analysis only when failure investigation is enabled.

## Objective

Verify the complete request, response, authorization, state transition, and error contract of `Tappd.RawQuote`.

## Preconditions

1. The shared plan prerequisites are healthy and the target listener is reachable.
2. Commands use isolated test data and preserve native request and response output.

## Test Data

The `Tappd.RawQuote` entry in [`api-inventory.json`](../../../api-inventory.json) is mandatory test data. Exercise every request field and every recursively referenced message field as absent/default, valid, boundary-invalid and combined with an unknown field; validate every response field, nested message field, and presence bit.

Use a unique run-scoped identifier and non-production credentials.

## Steps

<a id="tc-gos-tappd-004-step-01"></a>
### Step 1: Inspect the effective prerequisite

Query the relevant health, configuration, and baseline state for tappd.rawquote.

**Expected results:**

- The target component is healthy, the intended listener and policy are effective, and the baseline contains no run-scoped test object.

<a id="tc-gos-tappd-004-step-02"></a>
### Step 2: Exercise the behavior

Invoke `Tappd.RawQuote` with a valid `RawQuoteArgs` request using valid service-specific authentication and attestation context; capture the binary and JSON pRPC representations. Then send a schema-invalid request and, where protected, omit the credential.

**Expected results:**

- The valid call returns `TdxQuoteResponse` with every documented field and exhibits the documented `RawQuote` state and side effects; invalid framing or fields return a structured error, and protected calls reject missing credentials.

<a id="tc-gos-tappd-004-step-03"></a>
### Step 3: Verify state, isolation, and diagnostics

Re-query the public status/state interfaces, inspect component and peer logs, and repeat the request with one invalid or unauthorized input appropriate to this interface.

**Expected results:**

- Repeated observations match the method’s documented persistence, determinism, and idempotency semantics and remain scoped to the caller or run-scoped object; invalid or unauthorized input is rejected without secret disclosure, partial mutation, or loss of service availability.

## Postconditions

Remove run-scoped objects and restore changed configuration. Preserve logs and responses in the result artifacts.
Loading
Loading