Repository navigation
Model printer LAN access as a two-locus SecretRef roster - #10376
Merged
Merged
Conversation
added 2 commits
September 4, 2026 10:06
Replace the temporary srv2 file locus with one roster keyed by the shared physical asset identities. Each printer carries a pinned Secret Manager version for machine retrieval and its auth-gated Drive resource for human retrieval; unknown printers refuse instead of fabricating a secret name. Add printer-02's identity and executable witnesses for exact membership, resource binding, human loci, and the refusal arm.\n\nThe two 0600 source files were verified on srv2 without printing their values. Live Secret Manager provisioning remains pending because no authenticated GCP write route is available in this session; the model names that gap and permits no file fallback.
Add printer-02's received asset row and serial, its asset-bound 192.168.1.235 endpoint, and the observed active static reservation for MAC 68:EE:8F:60:AC:14. Record printer-01's supplied reservation alongside it so both current printer address bindings share one shape. Extend the topology identity join, endpoint binding witness, and owned manufacturing inventory.
gunbai-bot
Bot
force-pushed
the
session/still-hawk-593
branch
from
September 4, 2026 10:07
702b589 to
48b69cd
Compare
The direct entry closure exposed Active transitively, but required-floor resolves this witness independently and correctly refused the unbound constructor. Import it explicitly from the DHCP authority.
Make the resolver count matching roster rows before selecting one. Zero matches remains the typed unknown-printer refusal, one returns the locus, and multiple bindings now return a typed conflict instead of silently taking the last row. Enroll a duplicate-row witness that flips under the prior fold behavior.
…efusing it MAIN IS RED AND IT BLOCKS THE WHOLE QUEUE. 97345e5 carries 21 lines of source annotation after the final declaration of emit_copy_qualification_witness_test.dag. An annotation there names no module item, so the parse refuses -- 16 errors -- and because CI evaluates a synthetic merge with main, it fails EVERY open PR rather than one branch. Reproduced by compiling main's own copy from a clean checkout of 97345e5, because the natural assumption is the opposite. A sibling session reported that merging main FIXED their identical failure; it cannot, and the report is worth contradicting explicitly: main is where the errors come from, and a branch that appears fixed by merging main is a branch whose CI has not finished. The change that landed this deleted the three declarations the text described and kept the text. That instinct is right -- the account of WHY rows were removed is exactly what a later reader needs, and deleting it would have been the easy repair that loses the thing worth keeping. It only needed a subject. The content is a statement about the MODULE's standing, not about any one declaration, so it moves to the module header. Verified word-for-word identical to main's, declaration count unchanged at 42, and the file now compiles with 0 blocking errors. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TuCmz2HjuYzP6GWLgw11E4
gunbai-bot Bot
added a commit
that referenced
this pull request
Sep 4, 2026
…deictics that no gate can see (#10434) `dag/test/claim/emit_copy_qualification_witness_test.dag` on main holds THREE copies of the same block, at lines 2, 74 and 99. Only the first is #10425's repair. The other two are the PRE-REPAIR text, and their deictics are now false at their positions: "Three rows stood HERE ..." the rows were deleted by #10390 "calibration mutants BELOW ..." points at rows that are not below it "the rows ABOVE THIS COMMENT ..." points at rows that do not exist #10425 rewrote exactly those words for exactly this reason, recording that "a relocated pointer that still says below is a false citation of exactly the kind this repository files." Two stale copies then landed beside its corrected one. HOW IT ARRIVED, and it is not #10425's fault. Two PRs cut BEFORE the repair (#10408, #10376) carried their own copy of the block and landed after it. Neither contested a line, so the merge UNIONED rather than refused and both sides' bytes survived. This is `gunbc.recurring_failure_mode` `append_only_carrier_whose_serialization_shares_a_merge_region` on ordinary source rather than on a roster: THE UNIT OF MERGE IS COARSER THAN THE UNIT OF EDIT. WHY NOTHING CAUGHT IT. All three copies are leading blocks attached to declarations, so §4c is satisfied and the parse phase is silent. The defect we spent the afternoon on announced itself in 16 errors; this one is the same class, from the same commit family, and is invisible to every gate we have. A green main is not evidence this did not happen. This deletes copies B (74-91) and C (99-116) and keeps A at the module head — the one whose deictics name the module. Result: one copy, zero false deictics, no unattached block, and the file still ends at its last declaration. Claude-Session: https://claude.ai/code/session_01LSzWg5t7F22xEtbd83fzQ6 Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replace the temporary srv2 credential-file locus with one roster keyed by the shared physical asset identities for printer-01 and printer-02. Each row carries a pinned GCP Secret Manager version for machine retrieval and the observed auth-gated Google Drive resource for human retrieval; lookup of an unknown printer refuses rather than fabricating a secret id.
The source access-code files were verified on srv2 as mode 0600 without printing or copying their values into this public repository. Live creation of
printer-01-lan-access-codeandprinter-02-lan-access-codeversion 1 remains an operator action: no authenticated GCP write route exists in this session or on the reachable hosts, and the parent has escalated the writes. The model deliberately provides no fallback to the srv2 files, so an absent Secret Manager version remains visible at the existing typed materialization boundary.This PR is stacked on #10344, which introduces
gunbc.fleet_asset_identityand the printer access module.Test plan
git diff --cached --check— passed before commitcargo fmt --all --check— passedctrl-build --remote -- bash -lc 'export GUNBC_MEMORY_BUDGET_BYTES=4294967296; cargo run -q -p v1-compiler --bin gunbc -- run --source-root dag --source-root src/v2 --entry dag/test/claim/fleet/fleet_printer_access_witness_test.dag --function fleet_printer_access_witnesses_hold --claim-run'— PASS\n\n## Worker attestation\n\n- [x] Title describes the change.\n- [x] Summary states what and why.\n- [x] Tests and results are named above.\n- [x] No GitHub issue is closed by this dashboard work item.\n- [x] The only stacked commits are the declared PRINT-6: register printer-01 as a fleet intent row, and give the AMS Lite its own feed-path authority #10344 dependency.\n- [x] No secrets, credentials, or large binaries are present.Network follow-up
The operator subsequently confirmed both live static router bindings. This PR now also registers printer-02 as a physical asset (serial
0300CA660400324), adds its asset-bound192.168.1.235LAN endpoint, and models both printers’ active static IP/MAC reservations. Targeted reservation witness: PASS.