Yocto + QEMU EDU Lab · Engineering note

Yocto separates repository trust policy from live compliance

M9 adds a versioned desired-state contract and deterministic evaluator. Collected observations, hosting-service enforcement and continuous attestation remain separate responsibilities.

PR #17 implements a tracked policy, a fixed ignored observation input and a deterministic sanitized output. The exact policy bytes are identified by SHA-256. The evaluator has no network or mutation interface and does not collect GitHub settings itself.

A conflict outranks unavailable information, and unavailable information outranks a pass. Exit codes distinguish matching observations, conflicts, invalid input and missing facts. Closed keys, bounded values and a 64 KiB input limit constrain the observation boundary.

This is implemented desired-state evaluation, not a claim that live GitHub settings comply. A passing snapshot cannot establish collector authenticity, continuous enforcement or certification. No live-settings collection or new Yocto image execution was performed for this portfolio update.

Explore the topic

Follow the evidence

Explore Yocto + QEMU EDU Lab

Read source evidence ↗ (opens in a new tab)

Related reading