Skip to content

Model printer LAN access as a two-locus SecretRef roster - #10376

Merged
briansrls merged 6 commits into
mainfrom
session/still-hawk-593
Sep 4, 2026
Merged

briansrls merged 6 commits into
mainfrom
session/still-hawk-593

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replace the temporary srv2 credential-file locus with one roster keyed by the shared physical asset identities for printer-01 and printer-02. Each row carries a pinned GCP Secret Manager version for machine retrieval and the observed auth-gated Google Drive resource for human retrieval; lookup of an unknown printer refuses rather than fabricating a secret id.

The source access-code files were verified on srv2 as mode 0600 without printing or copying their values into this public repository. Live creation of printer-01-lan-access-code and printer-02-lan-access-code version 1 remains an operator action: no authenticated GCP write route exists in this session or on the reachable hosts, and the parent has escalated the writes. The model deliberately provides no fallback to the srv2 files, so an absent Secret Manager version remains visible at the existing typed materialization boundary.

This PR is stacked on #10344, which introduces gunbc.fleet_asset_identity and the printer access module.

Test plan

  • git diff --cached --check — passed before commit
  • pre-push cargo fmt --all --check — passed
  • ctrl-build --remote -- bash -lc 'export GUNBC_MEMORY_BUDGET_BYTES=4294967296; cargo run -q -p v1-compiler --bin gunbc -- run --source-root dag --source-root src/v2 --entry dag/test/claim/fleet/fleet_printer_access_witness_test.dag --function fleet_printer_access_witnesses_hold --claim-run' — PASS\n\n## Worker attestation\n\n- [x] Title describes the change.\n- [x] Summary states what and why.\n- [x] Tests and results are named above.\n- [x] No GitHub issue is closed by this dashboard work item.\n- [x] The only stacked commits are the declared PRINT-6: register printer-01 as a fleet intent row, and give the AMS Lite its own feed-path authority #10344 dependency.\n- [x] No secrets, credentials, or large binaries are present.

Network follow-up

The operator subsequently confirmed both live static router bindings. This PR now also registers printer-02 as a physical asset (serial 0300CA660400324), adds its asset-bound 192.168.1.235 LAN endpoint, and models both printers’ active static IP/MAC reservations. Targeted reservation witness: PASS.

@gunbai-bot gunbai-bot Bot changed the title Store printer-01/02 LAN access codes in GCP Secret Manager and model the locus roster Model printer LAN access as a two-locus SecretRef roster Sep 4, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 4, 2026 08:40
gunbc-ci-auto-heal added 2 commits September 4, 2026 10:06
Replace the temporary srv2 file locus with one roster keyed by the shared physical asset identities. Each printer carries a pinned Secret Manager version for machine retrieval and its auth-gated Drive resource for human retrieval; unknown printers refuse instead of fabricating a secret name. Add printer-02's identity and executable witnesses for exact membership, resource binding, human loci, and the refusal arm.\n\nThe two 0600 source files were verified on srv2 without printing their values. Live Secret Manager provisioning remains pending because no authenticated GCP write route is available in this session; the model names that gap and permits no file fallback.
Add printer-02's received asset row and serial, its asset-bound 192.168.1.235 endpoint, and the observed active static reservation for MAC 68:EE:8F:60:AC:14. Record printer-01's supplied reservation alongside it so both current printer address bindings share one shape. Extend the topology identity join, endpoint binding witness, and owned manufacturing inventory.
@gunbai-bot
gunbai-bot Bot force-pushed the session/still-hawk-593 branch from 702b589 to 48b69cd Compare September 4, 2026 10:07
gunbc-ci-auto-heal and others added 4 commits September 4, 2026 12:45
The direct entry closure exposed Active transitively, but required-floor resolves this witness independently and correctly refused the unbound constructor. Import it explicitly from the DHCP authority.
Make the resolver count matching roster rows before selecting one. Zero matches remains the typed unknown-printer refusal, one returns the locus, and multiple bindings now return a typed conflict instead of silently taking the last row. Enroll a duplicate-row witness that flips under the prior fold behavior.
…efusing it

MAIN IS RED AND IT BLOCKS THE WHOLE QUEUE. 97345e5 carries 21 lines of source
annotation after the final declaration of emit_copy_qualification_witness_test.dag.
An annotation there names no module item, so the parse refuses -- 16 errors -- and
because CI evaluates a synthetic merge with main, it fails EVERY open PR rather
than one branch.

Reproduced by compiling main's own copy from a clean checkout of 97345e5,
because the natural assumption is the opposite. A sibling session reported that
merging main FIXED their identical failure; it cannot, and the report is worth
contradicting explicitly: main is where the errors come from, and a branch that
appears fixed by merging main is a branch whose CI has not finished.

The change that landed this deleted the three declarations the text described and
kept the text. That instinct is right -- the account of WHY rows were removed is
exactly what a later reader needs, and deleting it would have been the easy repair
that loses the thing worth keeping. It only needed a subject.

The content is a statement about the MODULE's standing, not about any one
declaration, so it moves to the module header. Verified word-for-word identical to
main's, declaration count unchanged at 42, and the file now compiles with 0
blocking errors.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TuCmz2HjuYzP6GWLgw11E4
@briansrls
briansrls merged commit 8b6c46c into main Sep 4, 2026
2 of 4 checks passed
@briansrls
briansrls deleted the session/still-hawk-593 branch September 4, 2026 15:22
@briansrls
briansrls restored the session/still-hawk-593 branch September 4, 2026 15:24
gunbai-bot Bot added a commit that referenced this pull request Sep 4, 2026
…deictics that no gate can see (#10434)

`dag/test/claim/emit_copy_qualification_witness_test.dag` on main holds THREE copies of the
same block, at lines 2, 74 and 99. Only the first is #10425's repair. The other two are the
PRE-REPAIR text, and their deictics are now false at their positions:

    "Three rows stood HERE ..."          the rows were deleted by #10390
    "calibration mutants BELOW ..."      points at rows that are not below it
    "the rows ABOVE THIS COMMENT ..."    points at rows that do not exist

#10425 rewrote exactly those words for exactly this reason, recording that "a relocated
pointer that still says below is a false citation of exactly the kind this repository files."
Two stale copies then landed beside its corrected one.

HOW IT ARRIVED, and it is not #10425's fault. Two PRs cut BEFORE the repair (#10408, #10376)
carried their own copy of the block and landed after it. Neither contested a line, so the
merge UNIONED rather than refused and both sides' bytes survived. This is
`gunbc.recurring_failure_mode` `append_only_carrier_whose_serialization_shares_a_merge_region`
on ordinary source rather than on a roster: THE UNIT OF MERGE IS COARSER THAN THE UNIT OF EDIT.

WHY NOTHING CAUGHT IT. All three copies are leading blocks attached to declarations, so §4c is
satisfied and the parse phase is silent. The defect we spent the afternoon on announced itself
in 16 errors; this one is the same class, from the same commit family, and is invisible to
every gate we have. A green main is not evidence this did not happen.

This deletes copies B (74-91) and C (99-116) and keeps A at the module head — the one whose
deictics name the module. Result: one copy, zero false deictics, no unattached block, and the
file still ends at its last declaration.


Claude-Session: https://claude.ai/code/session_01LSzWg5t7F22xEtbd83fzQ6

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant