Skip to content

R15B: add Windows TPM TBS backend with fail-closed custody recovery - #202

Merged
bitmaster162 merged 5 commits into
masterfrom
agent/r15b-windows-tbs-backend-dpapi-primer-r1
Sep 19, 2026
Merged

bitmaster162 merged 5 commits into
masterfrom
agent/r15b-windows-tbs-backend-dpapi-primer-r1

Conversation

@bitmaster162

@bitmaster162 bitmaster162 commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

R15B — Windows TPM TBS backend + DPAPI custody + crash-resumable provisioning

Base: 57c90dd4c7f8ec2a47a9d8b8a48e7d9fb1a11eaa
Head: d465e7520fb047aa4a83fa0dfc524f59263984b2
Tree: dfb7a0486823973d40c101b955c232e3ada11819

PR patch SHA-256: 5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105B
Patch bytes: 78460
Changed files: 5
Additions/deletions: +2047 / -0

What R15B adds

  • Windows TBS TPM 2.0 runtime backend with a narrow command allowlist
  • DPAPI-bound custody for the NV index authValue
  • read-only verified NV discovery/public identity binding
  • authenticated NV_Read + NV_Extend runtime path
  • offline crash-resumable provisioning state machine
  • strict TPM password-session response parsing
  • fail-closed public/Name/digest verification
  • bounded state transitions and prevention of accidental repeat Define/primer Extend
  • documentation and hardware-free regression coverage

Clear/deletion fail-closed remediation

A semantic review found that stale DPAPI custody plus an absent NV handle after an external TPM Clear/deletion could previously be classified as CUSTODY_ONLY and auto-resume Define.

That blocker is closed:

  • pre-existing CUSTODY_ONLY is now a hard HOLD
  • external Clear/deletion with stale custody performs zero TPM mutation
  • EMPTY may create custody and attempt Define only within the same explicitly authorized invocation
  • lost Define response still recovers from the observed exact definition public area without repeating Define
  • lost primer response remains verification-only without repeating primer
  • deterministic hardware-write token is documented as plan-bound confirmation, not a secret/authentication credential
  • duplicate shadowed test was removed
  • explicit external Clear/deletion regression was added

Focused exact-head remediation review on 3737b04e4b632b8cc7a2c6b869c1497ee31f0fda:

  • VERDICT: PASS
  • BLOCKERS: none
  • HIGH/MEDIUM/LOW: none
  • authority assessment: NARROWED, NOT EXPANDED

Current-master synchronization

Current origin/master was merged into the feature branch using a normal merge commit:

  • merge commit: d465e7520fb047aa4a83fa0dfc524f59263984b2
  • parent 1: 3737b04e4b632b8cc7a2c6b869c1497ee31f0fda
  • parent 2: 57c90dd4c7f8ec2a47a9d8b8a48e7d9fb1a11eaa
  • pre-merge file overlap with master: 0
  • merge-tree conflict markers: none
  • no rebase or force-push

Post-sync equivalence proof:

  • pre-sync reviewed R15B patch SHA-256: 5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105B
  • post-sync PR patch SHA-256: 5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105B
  • patch bytes: 78460 before and after
  • patch comparison: byte-for-byte identical
  • master changed none of the 5 R15B files

Post-sync reviewer attempts that failed because of external model/provider limits are not counted as evidence.

Exact post-merge validation

On d465e7520fb047aa4a83fa0dfc524f59263984b2:

  • targeted R15B runtime/provisioning suite: 23 passed
  • full repository: 2307 passed, 2 skipped, 19 subtests passed
  • release hardening: 10/10 PASS
  • compileall: PASS
  • governance regression corpus: PASS
  • git diff --check: PASS
  • worktree: clean
  • remote head equals local head

Provider CI

Natural exact-head checks on d465e7520fb047aa4a83fa0dfc524f59263984b2:

  • P0 Unified Shadow Continuity: SUCCESS
  • CodeQL: SUCCESS
  • review-gates / Ubuntu Python 3.11: SUCCESS
  • review-gates / Windows Python 3.11: SUCCESS
  • manual rerun: none

Review state

  • GitHub reviews: 0
  • open review threads: 0
  • mergeable: true
  • PR is ready for human merge authorization after this metadata gate

Hardware / qualification boundary

No TPM/PPI/NV mutation was performed by remediation, master-sync, CI, or this PR metadata gate.

This PR does not authorize or perform:

  • TPM Clear/reset
  • reboot
  • NV_DefineSpace / NV_Extend / NV_UndefineSpace
  • provisioning/re-enrollment
  • bind_genesis
  • deploy/runtime activation
  • trading/wallet/capital actions

Authority boundary

can_trade=false
capital_permission=DENY
deploy_permission=DENY

Marking this PR Ready does not authorize merge.

Actual merge to master requires a new exact Human merge authorization token tied to the frozen base/head/tree/check state.

@bitmaster162
bitmaster162 marked this pull request as ready for review September 19, 2026 15:28
@bitmaster162
bitmaster162 merged commit 1f3cc0f into master Sep 19, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant