floors provenance: loop_protection, arp_table, vlans, auto_disable, ip_restrict, signal_contact ssh=pass - #386
Merged
Conversation
…s, auto_disable, ip_restrict, signal_contact
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ssh=passfor 6 methods after the Σ Resolve re-prove on main6b71a1e. Each was all-green: mops/snmp/sshok, ssh n equal to the floor,parity_diffs == [].get_loop_protection: schema(#299): SSH get_loop_protection enabled/mode/action/loop_detected maps #376 / get_loop_protection.read: SSH fail (no cli; invent-wrong scalars) #299get_arp_table: schema(#295): get_arp_table interface value_map ifindex (ifName align) #377 / get_arp_table.read: SSH no-cli (empty cli+raw vs MOPS n=35) #295get_vlans: schema(#290): get_vlans membership key_map bridge_port (ports ifName keys) #378 / get_vlans.read: SSH close-format (port membership vs MOPS) #290get_auto_disable: schema(#292): SSH get_auto_disable brief column_overflow strict (ifName keys) #379 / get_auto_disable.read: SSH fail (raw empty; only show port) #292get_ip_restrict: schema(#217): SSH get_ip_restrict rules paired_rows lines_per_record 2 #380 / get_ip_restrict.read: SSH parse remainder (rules row/prefix; timeout cleared) #217get_signal_contact: schema(#293): get_signal_contact sense_ps_state per-PSU dict {psid: bool} #384 / get_signal_contact.read: SSH no-cli (protocol absent vs MOPS) #293get_port_security(schema(#227): SSH get_port_security enabled paired_rows lpr 2 (port-name keys) #381 / get_port_security.read: SSH parse remainder (ports 56 vs 28; mode shape) #227) andget_router(schema(#228): SSH get_router ports pk bind + key_column 0 #382 / get_router.read: SSH parse remainder (ports/vri n=0; cli listed) #228). Both still have leftovers.docs/FLOORS_BOARD.md: Σ 240→246 / 300 (80.0% → 82.0%); ssh pass 40→46.docs/status.htmlonly had a date-line change, so it's not included (same as floors provenance: sflow poller/sampler + ipsource bindings ssh=pass #375).Evidence (sidecar
<method>.readwithtrace:true, tip6b71a1e, 2026-09-25)get_loop_protection[]show loop-protection interface,show loop-protection global,show portget_arp_table[]show ip arp table,show portget_vlans[]show vlan brief,show vlan port,show portget_auto_disable[]show auto-disable brief,show portget_ip_restrict[]show network management access global,show network management access rulesget_signal_contact[]Beyond the harness verdict, I also compared the full field-by-field output of ssh against mops and snmp: it is identical for 5 methods.
Caveats:
get_vlans: on this lab every transport shows U-only membership (PVID). T/F is never exercised, so the T/Fshow vlan memberremainder stays parked onhitl-engine-park.md. This pass covers the current floor only.get_signal_contact:sense_ps_stateis{'1': True, '2': True}on all 3 transports.sense_fan,sense_humidityandsense_stp_port_blockare mopsNonevs ssh/snmpFalse. The harness doesn't count None vs False, and schema(#293): get_signal_contact sense_ps_state per-PSU dict {psid: bool} #384 leaves these out of scope.cliis empty because the per-contact loop doesn't record commands (get_interfaces.read: SSH parse remainder (cli listed; n=1 vs mops 36) #226 class). Declared command:show signal-contact {entity} allfor contacts 1–2.section: 1PS-table index is not raw-verified. Live keys rule out the case "PS table at separator 0 followed by another table"; they don't rule out "PS table is the only separator" (fallback to separator 0).get_arp_table: n=33 on all three transports on this run. The ARP table is live, and n matches across transports.Named proof
python3 scripts/generate_floors_board.pypython3 scripts/generate_status.py --check→ PASS/tmp/sigma/provenance20260925/receipt.txtIssues
Test plan
/tmp/sigma/provenance20260925/