Files
2026-07-13 22:21:12 +08:00

1.5 KiB

ADDED Requirements

Requirement: Host can submit a goal task only for itself

The internal Host Agent API SHALL allow an authenticated Host to submit a goal-based task that the Cloud Control Plane irrevocably targets to that same Host, with an optional Device target owned by that Host.

Scenario: Host submits a goal for one of its Devices

  • WHEN Host A presents valid Host A credentials and submits a valid goal naming one of Host A's enrolled Devices
  • THEN the control plane creates a queued task targeted to Host A and that Device without granting Host A public task-submission authority

Scenario: Host omits a Device target

  • WHEN an authenticated Host submits a valid goal without a Device target
  • THEN the control plane creates a queued task targeted to that Host and lets the scheduler select only an eligible Device owned by it

Requirement: Host self-submission preserves host isolation

The internal Host task-submission operation SHALL reject a foreign Host, foreign Device, workflow reference, or disabled self-submission policy before creating any task.

Scenario: Host attempts a foreign target

  • WHEN Host A submits a request naming Host B or a Device not owned by A
  • THEN the control plane rejects the request and does not create a task

Scenario: Host self-submission is disabled

  • WHEN a Host policy disables Host self-submission
  • THEN the control plane rejects that Host's self-submission request