orchestrator: Move the cursor off a component gated mid-walk

A cascade can gate the component currently under verification. Only
chain[cursor] can be released, so leaving the cursor on that component let its
in-flight verdict take it back out of reset. handle_corruption_advancing gates
by policy and then moves the cursor to the next ungated component. The two
states that release only chain[cursor], PreSupervision and AwaitingReady, route
CorruptionDetected through it.

It is not called from handle_supervising. Recovering's cursor is stale, since
VerificationFailed leaves it on the failed component, so advancing there would
verify mid-recovery or reach Ready instead of re-walking.

The release property now randomizes the chain shape as well as the event
sequence. The AwaitingReady race needs a gateable component after an active
one, which the old fixed chain never had.

Also adds the missing test for the Chain::try_from length bound. cursor is a u8
using chain.len() as its past-the-end sentinel, so a 256-entry chain would
truncate that sentinel to 0 and the walk would never read as done.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Christina Quast <christina.quast@9elements.com>
2 files changed
tree: 7e8ed0cab9ba571db29341082bc5d90e4ee95f85
  1. .github/
  2. docs/
  3. drivers/
  4. hal/
  5. openprot/
  6. platform/
  7. presubmit/
  8. services/
  9. target/
  10. third_party/
  11. tools/
  12. util/
  13. .bazelignore
  14. .bazelrc
  15. .bazelversion
  16. .clang-format
  17. .gitignore
  18. .semgrepignore
  19. BUILD.bazel
  20. CONTRIBUTING.md
  21. LICENSE
  22. MODULE.bazel
  23. MODULE.bazel.lock
  24. pw
  25. README.md
  26. rust-toolchain.toml
  27. workflows.json
README.md

OpenPRoT

Technical Charter

The OpenPRoT Technical Charter can be found at https://github.com/OpenPRoT/.github/blob/main/GOVERNANCE.md

Getting Started

NOTE: We are converting our build system to bazel. We recommend installing bazelisk to automatically manage bazel versions.

Available Tasks

You can run tasks using the Pigweed workflow launcher pw or bazel.

  • ./pw presubmit - Run presubmit checks: formatting, license checks, C/C++ header checks and clippy.
  • ./pw format - Run the code formatters.
  • bazel test //... - Run all tests.
  • bazel build //docs - Build documentation.

Development

The project is structured as a bazel module.

Requirements

  • Bazel. We recommend installing bazelisk to automatically manage bazel versions.

No additional tools are required - all dependencies are managed by bazel.