Repository navigation
Spark usage-stats: narrow typed observation at the host boundary; raw inspect never reaches policy - #11441
Spark usage-stats: narrow typed observation at the host boundary; raw inspect never reaches policy#11441gunbai-bot[bot] wants to merge 31 commits into
Conversation
… rest of Config.Env. InspectServingContainer already authorizes docker container inspect; this decoder projects only VLLM_NO_USAGE_STATS, DO_NOT_TRACK and VLLM_USAGE_STATS_SERVER so first-party admission can resolve telemetry instead of treating every launch as unread. Co-authored-by: Cursor <cursoragent@cursor.com>
…permanently-green Env-name check. Declarations still claimed UsageStatsLaunchUnread on every arm and that no producer reads a running container; both are false once serving_usage_stats_observe exists. The decoder already refuses unrequested names, so a second filter could not go red. Co-authored-by: Cursor <cursoragent@cursor.com>
…lation. Empty inspect Env now witnesses ProviderPathLocated and first-party admit through the enrolled drop, plus RED without that enrollment. The first-party unread suite no longer claims the drop has no producer. Co-authored-by: Cursor <cursoragent@cursor.com>
…fail-closed inspect Env. Enabled standing no longer locates or admits. Incomplete Config/Env is unreadable, marker unread is unread, a present-empty server is malformed, and VLLM_DO_NOT_TRACK or-falls through to DO_NOT_TRACK exactly as envs.py at vllm_source_revision_read. Co-authored-by: Cursor <cursoragent@cursor.com>
…ed for enabled telemetry. The typed row already had population []; the markdown ledger and sanctions/data_subject bases still described a Located enabled arm this PR refuses. Co-authored-by: Cursor <cursoragent@cursor.com>
Inspect of a matching container Id must not Absent telemetry for a readback that disagrees with the declared pair-serving path. unread_cause runs first; a GLM fixture with VLLM_NO_USAGE_STATS=1 now refuses admission. Co-authored-by: Cursor <cursoragent@cursor.com>
The remedy row listed three env names while vllm_usage_stats_inspect_env_names projects four. It now cites that roster. Co-authored-by: Cursor <cursoragent@cursor.com>
…n obligation. namespace-wave-admission refused NewUnresolvedness on spark_serving_incarnation_unobserved_obligation after the inspect import replaced serving_offer. The name still belongs to gunbc.spark.serving_offer. Co-authored-by: Cursor <cursoragent@cursor.com>
Docker inspect and registry image-config were two copies of one array-of-strings reader; both now consume the same accessor. Co-authored-by: Cursor <cursoragent@cursor.com>
The hoist rebinds one spelling in registry image-config; the consumed #11214 token-realizer rows come due on this roster touch and are deleted with it. Co-authored-by: Cursor <cursoragent@cursor.com>
…ion. Telemetry was attributing inspect to observation.launch without the endpoint and host join serving_offer already owns; both consumers now share spark_incarnation_observation_agreement. Co-authored-by: Cursor <cursoragent@cursor.com>
json_string_list is already admitted; the floor refused because those SCM rows were due the moment this file changed. Co-authored-by: Cursor <cursoragent@cursor.com>
…tdout stops at the host boundary Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…due and are deleted
…16; the json_string_list row stands alone)
…rn runtime component deleted by #11410; the host join moved to first_party_serving)
…due and are deleted
…ept side by side; the realization annotation carries both facts
…y of .dag rows (#11250); the json_string_list row moves there
…s the observation through admission (review 66882) The observer's grant reads no do-not-track marker file, so a caller-supplied DoNotTrackMarkerPresent was an unobserved disable that could green provider-use admission; the parameter is gone and the marker is Unread by construction, with a RED that the observer never disables without an observed env term. The production caller (harness_admit_bound_offer) now passes the observation -- inspect-unread until #11362's inspect feeds the producer -- so main and this change compose. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 66882: both findings fixed at 0e56511. (1) The production caller now composes: — sent from merry-eagle-325 |
…ted only by the observer, and policy joins it to the incarnation with same_launch (side-chat hold) A directly constructible Observed arm let a caller hand policy a Disabled standing it never observed; ServingUsageStatsEvidence is a sole-constructor record whose only mint is spark_serving_usage_stats_observe. The launch join was launch_wire + container id -- group, invocation and container only -- so two readings contradicting each other about one launch's unit or image digest could still Absent the path; the join is now gunbc.spark.vllm_serving_launch same_launch, with contradiction and turnover both Unread. REDs for both. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… decoder is unsealed; policy folds at the subject grain (side-chat hold) spark_serving_usage_stats_observe(launch, stdout, receipt) was an unrestricted alternate mint over caller-authored JSON. The sealed ServingUsageStatsEvidence now lives in gunbc.spark.serving_incarnation_observe and is constructed there from the same authorized inspect stdout the identity projection reads, beside the EndpointIncarnationObservation; the harness carries both from one read per launch per bind. gunbc.spark.serving_usage_stats_observe keeps only the unsealed decoder. Policy delegates its join to a subject-grain fold so the refusal arms stay claimable with authored subjects; the admitted positive control is a stated live-only frontier; a source probe shows caller-authored evidence refuses to compile. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Side-chat hold (unrestricted alternate mint) addressed at 22c24ed. — sent from merry-eagle-325 |
…arried beside the declared-unit roster; spark_service_from_observation keeps the shared agreement join over the sealed digest
… due on this roster touch)
|
Transition-admission migration for gunbc#11704. No action until the operator sequences #11704's landing. gunbc#11704 moves namespace transition admissions out of the tree. Once it lands, any file under To migrate (paste + delete), after #11704 is on main and merged into this branch: git rm \
dag/gunbc/namespace/transition_admission/gunbc_container_registry_image_config_container_image_config_env_from_json_json_string_list.dag
git commit -F msg.txt # msg.txt = the text below, verbatim
msg.txt |
Supersedes #11419 (carries its commits) and repairs the SOURCE HOLD: raw
docker container inspectstdout no longer reaches first-party policy.Boundary
gunbc.spark.serving_usage_stats_observespark_serving_usage_stats_observe(launch, inspect_stdout, marker, receipt)is the single consumer of raw stdout. It returns onlyServingUsageStatsObservation = ServingUsageStatsObserved { launch, container_id, standing: VllmUsageStatsLaunchStanding, receipt: ObservationReceiptRef } | ServingUsageStatsUnobserved { obligation }. The raw document is discarded there.spark_first_party_admission(realization, usage_stats, scope, offer),spark_serving_usage_stats_standing,spark_usage_stats_telemetry_pathandspark_first_party_route_factstake the typed observation. The raw carrierServingContainerInspectStdoutis deleted. The fold keeps thespark_incarnation_observation_agreementjoin, and it also requires the observation's launch and container to equal the agreed incarnation's. If they don't, the result is Unread (spark_usage_stats_observation_names_another_launch_obligation).std.observation. ItsObservationSubjectis a compiler-run containment path and cannot name a live container. Instead the observation follows the lane's existingEndpointIncarnationObservationshape (launch +ObservationReceiptRef), and it reuses upstream'sVllmUsageStatsLaunchStandingrather than minting a second standing.Semantics kept
The decoder projects four env names:
VLLM_NO_USAGE_STATS,VLLM_DO_NOT_TRACK,DO_NOT_TRACK,VLLM_USAGE_STATS_SERVER."1"disables, andVLLM_DO_NOT_TRACK or DO_NOT_TRACKfollows Python-or precedence.Every one of those witness controls is kept.
Grant
Authorized by
gunbc.spark.managed_access_bootstrapInspectServingContainer. No new grant.Test plan
spark_serving_usage_stats_observe_witness_testarms now go through the typed observation. Admission and telemetry calls receivet_observe(...), never stdout.an_observation_of_another_launch_does_not_absent_the_path.observe_witness_mainat 3076736 under a cgroupmemory.maxexited 0 (a first run without a cgroup limit refused with HostBudgetUnreadable before evaluating anything)🤖 Generated with Claude Code