Skip to content

DSV41-6 enroll sshpass as a host_cli_dependency for password-session runners (srv3/srv4 lack it) - #11096

Merged
gunbai-bot[bot] merged 7 commits into
mainfrom
session/merry-lark-687-dsv41-6b
Sep 12, 2026
Merged

gunbai-bot[bot] merged 7 commits into
mainfrom
session/merry-lark-687-dsv41-6b

Conversation

@briansrls

@briansrls briansrls commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Converge sshpass on password-session runners (srv3/srv4) through the existing srv3_ensure_apt_tool installer over FleetSsh. Package identity comes from extdeps.tools apt_package_of (Optional, never a default). Dispatch is a step on fleet_converge_workflow, not a new job and not a new HostEffect.

Review 64038

Unobserved receipts render unobserved:<cause>. The apt_package_of witness commentary is a // annotation, not a String row.

Scaffold probes

src/v2/test/claim/manual/dsv41_6_probe.dag and dsv41_6b_probe.dag are not on this branch. They are session probes, not consumers.

Mode witness (not a census literal)

fleet_converge_workflow_modes still re-enumerates the coproduct (roster_re_enumerates_its_own_rows_stall). A hand-updated count == N is a change detector: bumping N when a mode lands is measure() == measure(). This PR does not keep that convention. The witness joins identities: RunnerPasswordSessionToolConverge is on the roster, wires are unique, and every dispatch option is a rostered wire (and the reverse).

FleetSsh presence is path-presence, not PATH presence

posix_command_v_check_argv is not portable (sh -c payload). FleetSsh therefore uses shell.Test.IsExecutable over extdeps.apt apt_installed_bin_path (apt_bin_dir + binary): executable at FHS /usr/bin/<binary>, not present on PATH. LocalShell and SshShell still use command -v. A tool installed outside apt_bin_dir (diverted path, /usr/sbin, a local build) now reads absent and the ensure takes the install arm; apt no-ops if the package is already recorded, so the host is not harmed, but the receipt can report an install for a host that already had the binary elsewhere.

Path-presence is the right question for an apt-acquired tool: the installer places the binary at that FHS path, and the password-session exec is that argv0. PATH search would accept a shadow apt does not own.

The FleetSsh arm of srv3_tool_bin_path answers the same path-presence question (it returns apt_installed_bin_path, not PATH stdout). It is in this change because srv3_apt_tool_version_ok resolves the binary through that function; leaving FleetSsh on posix_command_v_check_argv would make version_ok Unobserved after a successful presence probe.

srv3_toolchain_rows production callers are unaffected: host_toolchain_ensure uses host_identity_ssh_access (SshShell); seeded-install-media toolchain ensure uses ci_deploy_srv1_access (LocalShell). Neither uses FleetSsh. Both still rely on PATH presence on those transports.

Test plan

Hermetic rows in dag/test/claim/runner/runner_password_session_tool_converge_witness_test.dag and dag/test/claim/extdeps/apt_package_of_witness_test.dag.

Wet fleet-converge.yml --ref session/merry-lark-687-dsv41-6b mode=runner_password_session_tool_converge host=srv4:

  • Run 34654220131 conclusion=success: test -x /usr/bin/sshpass exit=1 (absent) → install (~9s) → reprobe → receipt sshpass=present.
  • Run 34655262495 conclusion=success: one probe (~737ms), no apt-get, receipt sshpass=present.

@briansrls
briansrls marked this pull request as ready for review September 11, 2026 20:47
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-11T20:53:45.546071Z a7e455e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a7e455ec36

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -214,7 +216,7 @@ fn fleet_converge_spark_target_description() -> String {
], "")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Raise the workflow mode-count oracle

Adding this twentieth mode makes both enrolled assertions in dag/test/claim/workflow_dispatch_input_witness_test.dag fail: lines 362–363 still require 19 vocabulary entries and line 371 still requires 19 dispatch options. The required witness lane will therefore be red for every build of this commit until those independent count oracles are updated to 20.

Useful? React with 👍 / 👎.

run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/runner/runner_password_session_tool_converge.dag --function runner_password_session_tool_converge_ci_wet
cat "$ROOT/target/runner-password-session-tool-converge-receipt.txt"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Upload the new convergence receipt

When runner_password_session_tool_converge runs, this is the only exposure of target/runner-password-session-tool-converge-receipt.txt; the following upload step points at the runner-host-file receipt and is gated exclusively to the two runner_host_file_* modes. Consequently this mode never publishes its receipt as an artifact, including on the failure path for which the new entry explicitly writes the receipt before returning, so a dedicated always()-gated upload is needed.

Useful? React with 👍 / 👎.

match outcome.verdict {
Srv3PredicateHolds => "present"
Srv3PredicateFails => "absent"
Srv3PredicateUnobserved { reason: _ } => "unobserved"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the unobserved reason in the receipt

When a Fleet SSH probe is refused or an enrolled tool has no apt source, converge_one_password_session_tool stores an actionable reason in Srv3PredicateUnobserved, but this renderer discards it. Because runner_password_session_tool_converge_ci_wet returns only the rendered body on a failed outcome, operators receive merely sshpass=unobserved and cannot distinguish a transport/authentication failure from an acquisition-model gap.

Useful? React with 👍 / 👎.

…y String.

Review 64038: the failing diagnostic must name why a tool is unobserved, and
apt_package_of_witness_test's witness_note is an annotation, not program data.
The dispatch-mode count follows the twentieth mode so the witness lane is not
vacuously red, and the receipt uploads on failure because FailFast never cats it.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Addressed review 64038 on af8a680864.

  1. password_session_tool_receipt_entry no longer discards Srv3PredicateUnobserved.reason. Unobserved renders as unobserved:<cause> (witness now asserts sshpass=unobserved:probe could not run), so the receipt and the failing diagnostic name why, not only sshpass=unobserved.
  2. apt_package_of_witness_test dropped the witness_note: String row; that commentary is a leading // annotation on the first test (§4c).

Also raised the fleet-converge mode-count oracle 19→20 (twentieth mode would have reddened the required witness lane) and added an always()-gated upload of target/runner-password-session-tool-converge-receipt.txt so FailFast does not hide the cause on refusal.

They are uncommitted session probes, not consumers of the convergence
model. Leave them on disk; do not hand-edit the generated gitignore.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Dropped the session-scaffold probes from the branch (7e89e4da8b): src/v2/test/claim/manual/dsv41_6_probe.dag and dsv41_6b_probe.dag. They stay on disk locally and are not in .gitignore (that file is generated from gunbc.repo_workspace).

A hand-updated count against the live roster is a change detector: bumping
N when a mode is added collapses the assertion to measure() == measure().
The new mode must be on the roster, wires must be unique, and options join
the roster both ways.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Addendum from the manager, on 25896c48c2:

  1. Scaffold probes dsv41_6_probe.dag / dsv41_6b_probe.dag are not on the branch (7e89e4da8b).
  2. The fleet-converge mode witness is no longer count == N. That literal was a change detector. It now joins identities: the new mode is on the roster, wires are unique, options and roster wires match both ways.
  3. Evidence for this head: remote CARGO_TARGET_DIR=/tmp/cool-pike-654-evidence gunbc sha256 26b0b07c2ec57a941dabe3bccfdd41a1775d1fe6ee1230b969da0afbfce3f45a (release -p v1-compiler --bin gunbc). Source commit 25896c48c28940dfa1973d9af4fa2c31806c4870. Interpreting the hermetic rows on that BuildBuddy VM: HostBudgetUnreadable with no cgroup; after memory.max=6442450944 the first gunbc run was SIGKILL 137. Local rustc on this session still fails to spawn threads (EAGAIN). CI remains the executing consumer for those rows.

Brian Searls and others added 3 commits September 11, 2026 22:29
posix_command_v_check_argv is not a PortableRemoteWord vector, so the
password-session ensure refused before contacting srv4.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
version_ok would otherwise stay Unobserved after a present probe.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot merged commit ea08225 into main Sep 12, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/merry-lark-687-dsv41-6b branch September 12, 2026 01:13
briansrls pushed a commit that referenced this pull request Sep 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant