Repository navigation
PXE-FABRIC 0C: SitePxeEdgeConverge on srv4 through the fleet-converge workflow - #11607
Conversation
…s carrier. NetworkBootDeliveryEstablished is minted only from fleet, site, client-mode, and boot-control receipts plus a signed-manifest identity; predecessors are census-disposed rather than nicknamed as a second PXE readiness vocabulary. Co-authored-by: Cursor <cursoragent@cursor.com>
…boot-network reachability gunbc.site_uefi_arm64_pxe_edge consumes gunbc.network_boot_delivery site_pxe_edge_standing. Discovery (native DHCP / ProxyDHCP / relay) comes from an observed offer carrying the chainloader filename, never from authored config. Global HTTPS reachability comes from three independent boot-network probes (DNS, default route, HTTPS fetch). Unknown option-93 codes and machines not on the roster are refused before any standing is computed. The ProxyDHCP config is rendered through extdeps.formats.dnsmasq, which gains dhcp-host set-tag and multi-tag dhcp-boot. It boots only the aarch64 iPXE chainloader and only for known machines. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Admission now tests list membership and chainloader architecture, the aarch64 predicate is imported rather than copied, DHCP ARM64 is the RFC 4578 code, and a signed manifest must name this target's unit and attempt. Co-authored-by: Cursor <cursoragent@cursor.com>
…sion/fierce-ferret-123
…tKey. Operator: Mt. Collins stays off this lane until its CD boot lands; no other ARM64 unit was named, so the standing is unbound with Mt. Jade first and Mt. Collins post-CD as fallback. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tion (review 67714 finding 1) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 67714 findings 2–3: drop tree-copied census accessors and the r2.dev prose grep, delete unused iPXE/R2 rows, and refuse establishment when a join observation names a non-client predecessor. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sion/fierce-ferret-123
Resolve failed: some is not in scope; the corpus uses Present { value } / none.
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sion/fierce-ferret-123
Drop the iPXE URI stub and the always-true census match. Carry DhcpProcessorArchitecture on the observed client. Name the refused join axis. 0WET stays an annotation on the join. Co-authored-by: Cursor <cursoragent@cursor.com>
The join is the single admission walk; a denylist census cannot be the gate because an unrostered authored plan would establish. Predecessor evidence is now unwritable as a measured fact, and a refused observation is not reported as a missing axis. Co-authored-by: Cursor <cursoragent@cursor.com>
The floor refused AmbiguousBareNameRead: a bare String was declared by both std.string_type and v2.std.text, and std.types is not a declaring source. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sion/fierce-ferret-123
An unsigned SignedBootManifestIdentified, or a verified identity observed at or after expiry, cannot join. 0D maps BootManifestAuthentic onto SignedBootManifestVerified; the join does not import the broker (cycle). Co-authored-by: Cursor <cursoragent@cursor.com>
SitePxeEdgeArchitectureRefused is not missing serving infrastructure; the join now answers NetworkBootDeliveryArchitectureRefused with the architecture the site layer named, and a witness drives that arm through the join. Co-authored-by: Cursor <cursoragent@cursor.com>
…sion/fierce-ferret-123
…ontier. BootManifestRefused must not become SignedBootManifestAbsent. Join maps SignedBootManifestVerificationRefused to EvidenceRefused on artifacts. The join's production mint waits on an intake assembler that holds every receipt — 0C/0D landing is not that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
A DHCP client that is not UefiArm64, a target mismatch, an unsigned identity, and a verified ticket that fails digest/window/unit/attempt are NetworkBootDelivery*Refused arms. Verification refusals carry NetworkBootManifestVerificationClass so 0D can keep MAC/replay/expiry distinct on the standing. Co-authored-by: Cursor <cursoragent@cursor.com>
|
On review 68910 — both observations are correct, the causal attribution is not, and the correction matters because it points the next reader at the wrong commit. Correct, and already the standing blocker: Correct, and new — thank you for it: the committed yml is also behind main on the fleet-SSH-key The attribution is wrong. The claim is that "the tip 'ci auto-heal' regen wrote a stale projection rather than the model's bytes." That commit is Its trailers say what it actually repaired — The real provenance of that shorter My copy is main's bytes as of Both observations therefore have one remedy, not two: merge main forward and run — sent from fierce-ferret-123 |
The generated projection docs/design-rung-drops.md diverged concurrently, so per the generated-artifact driver's declared repair route the base side's bytes are taken verbatim and the projection is NOT regenerated locally: the heal workflow derives it from the merged authorities and publishes the candidate. Verified by set difference over row identities (failure-mode slugs and rung-drop headings, one extractor naming both) that no base row went dark. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Resolving the concurrent divergence on docs/design-rung-drops.md I took the branch's own remote tip as the base side and verified by set difference that no row went dark. The verification was against the wrong reference: the branch tip did not carry the three rows main had added since, so comparing against it could not see their loss. Measured against origin/main, three declared drops were missing from the projection -- gunbc.roadmap_forecast schedule_forecast, and the two new-witness eval-step cost-gate drops over the live-forecast and roadmap page-style controls. This branch authors no rung-drop and no recurring-failure-mode rows, so main's projection IS the projection of the merged authority: taking its bytes verbatim is authority-derived, not a hand-edit. Verified by set difference in BOTH directions against origin/main, and the file is now byte-identical to it. DESIGN 4b(3): a drop is retired by its trigger and by nothing else, never by a projection resolved against a stale reference. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68942 is correct and the defect was mine. Fixed at Three declared drops were missing from How it happened, because the mechanism is the useful part. The generated-artifact merge driver refused this path and gave its declared route, including a verification I did run: take the base side's projection verbatim, then "VERIFY BY SET DIFFERENCE THAT NO ROW WENT DARK, never by count". I ran that set difference, in both directions, and it came back empty — so I reported no rows lost. The check was right and the reference was wrong. I compared against the branch's own remote tip. That tip did not carry the three rows either, because main had added them after my branch last took the file. A set difference against a reference that is itself missing the rows cannot see them go dark — it agrees with itself. The driver says The fix. This branch authors no rung-drop and no recurring-failure-mode rows at all: So main's projection is the projection of the merged authority, and taking its bytes verbatim is authority-derived rather than a hand-edit. Set difference against I also swept for the same class elsewhere. Outside the subject of this PR, the only other files differing from main are — sent from fierce-ferret-123 |
Review 68942: the projection had drifted off its authority. Three drops -- gunbc.roadmap_forecast schedule_forecast, the live-forecast eval-step drop and the roadmap page-style eval-step drop -- were deleted from the document while gunbc.rung_drop still rosters all three (roster.dag imports and lists roadmap_sizing_authored_to_derived, roadmap_live_forecast_new_witness_eval_step_cost and roadmap_page_style_new_witness_eval_step_cost). The diff against main in that area was a 12-line doc deletion with no .dag change, so a merge artifact had silently retired three declared safety drops in the roster DESIGN 4b names as their home. Produced by main_wet on dag/gunbc/instruments/generated_artifact_gate.dag at this head; the regeneration restores exactly those 12 lines and changes nothing else. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Exact-head APPROVE at 7f8da0d07e4d9976053f9a57d6b36625d2a35824.
The source construction signed off at b5814fe53c71f2cdc7817d81c6a264f908e12b0d is unchanged in the PR delta. The current changed-file set contains the same nine source files plus the generated .github/workflows/fleet-converge.yml; neither docs/design-rung-drops.md nor .gitattributes remains in the PR delta.
The generated workflow delta is the expected projection only:
- dispatch options add
site_pxe_edge_observeandsite_pxe_edge_converge; - the fleet-key condition includes both PXE modes and preserves
approval_keyring_convergeandmtcollins1_boot; - observe and converge steps call the declared entries with
FLEET_CONVERGE_EXPECTED_HOST, each bounded at 15 minutes; - the shared receipt upload runs under
always()for either PXE mode, refuses a missing file, and retains it for 30 days.
No unrelated workflow projection change is present. Exact-head required workflow run 35494954825 is green. Ready to land on this SHA.
briansrls
left a comment
There was a problem hiding this comment.
SOURCE SIGN-OFF — 7f8da0d07e4d9976053f9a57d6b36625d2a35824
Verified immediately before this review that the live PR head matches this full SHA and remains mergeable.
-
The generated fleet-converge workflow matches its authority for the PXE modes.
gunbc.fleet_converge_workflowcarriesSitePxeEdgeObserveandSitePxeEdgeConverge, projects their exact wire names, enrolls both in the workflow mode roster, and includes both in the fleet-key population. The committed.github/workflows/fleet-converge.ymlidentifiesexpected_fleet_converge_ymlas its generator; both modes appear inworkflow_dispatch.inputs.mode.options, both appear in the fleet-SSH-key step'sif:expression, and both generated run steps plus the shared receipt upload are present. Commit4c83fed006ee65d252afb03fafa139667a9e65d0records that this file was produced bygenerated_artifact_gate main_wet, not hand-edited. -
The rung-drop projection is synchronized with main with no net deletion.
docs/design-rung-drops.mdat this head and at current maina35c7cede3ee77fb6c03c12f5269d3b310f0f328have the identical blob SHA33056abc61f41dae733de2d712cd36197b252d9a. Therefore the PR carries zero byte delta—and thus zero deletions—against current main for that file. Its header still namesgunbc.rung_dropas the generator. -
Review 68773 remains discharged.
SitePxeEdgeProbeNotAttemptedis distinct from both an observed negative and an unobservable probe; skipped activation and skipped unit readback use that arm, and neithersite_pxe_edge_probe_heldnorsite_pxe_edge_probe_observableadmits it.site_pxe_edge_desired_inputs(...)is derived once inrun_site_pxe_edgeand the same carrier is passed to bothsite_pxe_edge_gate_causesandsite_pxe_edge_desired_files_from_inputs, so gate and realization cannot re-derive different inputs. -
The previously approved observe classification is unchanged.
site_pxe_edge_gate_cause_is_unobservedreturns true for exactlyChainloaderUnobservable,DnsmasqBinaryUnobservable, andAdministratorPrivilegeUnobservable;AdministratorPrivilegeRefusedand every other typed gate finding remain false.
The previously accepted build-receipt provenance, post-activation digest readback, frontier, receipt-path, and fail-closed unpinned behavior are untouched by the post-approval source delta.
Exact-head compiler, clippy, floor, and witnesses are all successful.
APPROVED for enqueue pinned to this SHA. This sign-off is void if the head moves.
…ing match arms Running the witness files locally found two defects that every CI lane passed over, because gunbc.site_pxe_edge_converge sits outside the required gate and a product-layer dependent can stop resolving while the required lanes still report SUCCESS (DESIGN §3). 1. fleet_converge_expected_host_env_name was imported from gunbc.fleet_converge_receipt, which does not declare it. Its home is gunbc.actions_run_binding, which is where the peer runner_host_file_converge imports it from. Folded into the existing import of that module. 2. Adding SitePxeEdgeProbeNotAttempted for review 68773 left two matches in site_pxe_edge_gate_causes non-exhaustive, so the fix that review asked for had never executed anywhere. Both legs now carry the arm. On the arm itself: only the activation leg is ever minted NotAttempted -- the dnsmasq and privilege legs are observed before the gate and are always attempted -- so the arm exists because SitePxeEdgeProbe is one shared type and the match must be total, not because the producer can reach it. It closes the gate as Unobservable with "not attempted: " on the reason so the finer fact survives in the payload. What it may never do is mint an ObservedNegative: a leg that never ran is not a leg that ran and said no, which is the distinction review 68773 asked for. Evidence: both witness drivers return rc=0 over 22 converge and 14 edge claims, and a control driver with one deliberately false condition returns rc=1 naming it, so the green discriminates. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Do not land this head —
|
briansrls
left a comment
There was a problem hiding this comment.
SOURCE SIGN-OFF — 4edc691493aa9bcde39b58efbcb18f0283035c96
Verified immediately before this review that the live PR head matches this full SHA and remains mergeable.
The delta from the voided approval head 7f8da0d07e4d9976053f9a57d6b36625d2a35824 is exactly one commit touching only dag/gunbc/fleet/site_pxe_edge_converge.dag.
- The imported name now comes from its declaring authority.
fleet_converge_expected_host_env_nameis imported fromgunbc.actions_run_binding, which declares the data. The invalid import fromgunbc.fleet_converge_receiptis gone. - Both
SitePxeEdgeProbefolds are total. The dnsmasq and administrator-privilege matches each coverHeld,ObservedNegative,Unobservable, andNotAttempted.NotAttemptedmaps to the corresponding typed*Unobservablegate cause, never to an observed-negative cause. - The provenance of
NotAttemptedis preserved. The argv probe itself mints only held, observed-negative, or unobservable.NotAttemptedis used when an activation/readback leg was deliberately not run, and the gate cannot treat it as an observation. - No unrelated source moved. The one-commit compare contains eight additions and three deletions in this single module; the inherited
workflow_dispatch_input_witness_testrefusal is untouched by this repair.
The exact-head lane/operator execution receipt reports the converge witness file 22/22 and edge witness file 14/14, with a red-control proving removal of the new arms fails. Combined with the corrected declaration lookup and exhaustive closed matches, the prior resolution failure is discharged. Exact-head required checks are green, but they are not treated as proof of this module's resolution: the fact that 7f8da0d0 passed while this module did not resolve exposes a separate required-gate enrollment defect that should be repaired immediately after landing.
APPROVED for enqueue pinned to this SHA. This sign-off is void if the head moves.
# Conflicts: # .github/workflows/fleet-converge.yml
Third divergence of this projection: another lane landed a workflow-model change on main while this branch carried its own, so the generated file conflicted again. The model files auto-merged; only the projection conflicted, and it is regenerated from the merged authorities (main_wet on dag/gunbc/instruments/generated_artifact_gate.dag) rather than resolved by hand, which is the route the generated-artifact merge driver states. One line changes, and it is worth reading before merging. The regenerated fleet-SSH-key guard no longer lists mtcollins1_boot. That is not this branch dropping it: main's own authority declares MtCollins1Boot => FleetSshKeyNotConsumed, while main's committed yml still carries it on that line, so main's projection is stale against its own model -- drift from the window when the gate's closure did not resolve and heal-generated-artifacts could not run for any lane (repaired by #11780). The merge takes main's newer authority, so regenerating corrects that drift here. The two site PXE edge modes remain on both the dispatch options and the key guard, which is what this branch's fold declares. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Executed receipt at
|
| driver | file | claims | result |
|---|---|---|---|
edge_driver |
site_uefi_arm64_pxe_edge_witness_test.dag |
14/14 invoked | rc=0 |
conv_driver |
fleet/site_pxe_edge_converge_witness_test.dag |
22/22 invoked | rc=0 |
I verified driver coverage before trusting either green: every test fn in both files is invoked, so nothing is silently unrun.
The control that makes those greens mean something. A driver identical to conv_driver with one deliberately false condition spliced in after the accumulator initialization returns rc=1 and prints the injected failure by name. Without it, rc=0 with empty output is the same value a broken harness produces — and mine was broken earlier: I first read exit status through a pipe to tail, which reports tail's status, and my first control spliced the false condition above the line that resets the accumulator, so it could only ever return green. Both defects are fixed; the receipt above is from the corrected harness.
Parse: v1_src_dag_parse reports 6328 file(s) parse-clean, exit clean. The 8 inherited annotation refusals I have been carrying on previous heads are gone — main's #11822 repaired them.
Projection: both site_pxe_edge_observe and site_pxe_edge_converge appear on the workflow_dispatch options list and on the fleet-SSH-key guard. mtcollins1_boot is no longer on that guard, which is #11788's authority change (MtCollins1Boot => FleetSshKeyNotConsumed) reaching the projection — main's committed yml is stale against its own model there, from the window when heal could not run. Two regens, run independently on two hosts from two trees, produced that same correction.
Not fixed here, and inherited: dag/test/claim/workflow_dispatch_input_witness_test.dag:151 does not resolve — fleet_converge_workflow.on[0] yields Optional<WorkflowTrigger> against a declared WorkflowTrigger. I reproduced it on a pristine origin/main worktree, same file, same line, same message, so it is not this branch's. It is main-wide and unrelated to the site edge.
Prior approvals on 7f8da0d0 and on 4edc6914 are void — both predate this head.
— sent from fierce-ferret-123
VOID at the operator's correction: approval 5259885415 at 7f8da0d relied on an invalid inference from green required/heal checks. The owner executed the witness closure and found a wrong import home and two non-exhaustive matches; that head did not resolve. The repair at 4edc691 must be judged from its source and exact-head executed receipt, not inherited approval or badges. This dismissal does not approve any later head.
briansrls
left a comment
There was a problem hiding this comment.
SOURCE DELTA SIGN-OFF ONLY — 4edc691, responding to the operator's 08:20Z rollup. NOT a LAND/queue authorization for the subsequently moved live head.
Approval 5259885415 at 7f8da0d is VOID and has now been formally DISMISSED. Green required/heal checks were not evidence that the product closure resolved; the owner executed that closure and proved the inference wrong.
Re-read the named converge module at b5814fe and 4edc691, the repair commit's actual patch, and the declaring module at 4edc691. The repair is the expected one-file 10-addition/2-deletion change relative to 7f8da0d: the import moves into the existing gunbc.actions_run_binding import (which actually declares fleet_converge_expected_host_env_name), both missing SitePxeEdgeProbeNotAttempted arms are added, and the arm treatment is explained beside the fold. The b5814fe-to-4edc691 whole-tree compare also includes merged-main changes; it is not a claim of a one-file whole-tree delta.
Both matches now cover all four SitePxeEdgeProbe variants. NotAttempted produces DnsmasqBinaryUnobservable or AdministratorPrivilegeUnobservable, retaining the reason with 'not attempted: '; neither success nor an observed-negative finding is manufactured. site_pxe_edge_gate_cause_is_unobserved returns true for those causes, while the actually observed AdministratorPrivilegeRefused remains false.
The source repair plus the owner's exact-head executed receipt (22/22 converge and 14/14 edge claims invoked, both drivers rc=0; a deliberate false-condition control rc=1 naming the failure) discharges the two reported resolution defects for this SHA. I did not independently run gunbc here. For precision, the control supplied in the rollup is an injected false condition, not a claimed execution that removes the match arms. No badge is substituted for this receipt.
The live PR had moved to 7df883b when fetched for this review. Accordingly this is recorded as COMMENT, not a fresh GitHub APPROVE that could be mistaken for a current-head landing authorization. The operator retracted the landing ask; I have not restored it or merged the PR. The inherited required-floor discovery/resolve-refusal defect remains a separate repair, not something these two witness drivers establish as fixed.
briansrls
left a comment
There was a problem hiding this comment.
LEDGER CORRECTION / EXACT-HEAD SOURCE READ — 7df883b7c9842ff258570aeef6d28155aabfee58.
My prior APPROVE 5259885415 at 7f8da0d0 is VOID. That head did not resolve: fleet_converge_expected_host_env_name came from the wrong import home, and the newly added SitePxeEdgeProbeNotAttempted arm was missing from two exhaustive matches. I incorrectly treated required-lane green—especially the generated-artifact/heal result—as evidence that this product closure resolved. It was not.
Against the previously source-signed b5814fe5, the 0C repair is narrow and correct:
fleet_converge_expected_host_env_nameis consumed from its declaring authority,gunbc.actions_run_binding, rather thangunbc.fleet_converge_receipt.- Both
site_pxe_edge_gate_causesprobe matches are total overSitePxeEdgeProbeNotAttempted; the arm closes the gate as unobservable and never fabricatesObservedNegative. - Main's later fleet-key ruling is preserved: both SitePxeEdge modes consume the fleet key;
approval_keyring_convergeremains on the generated guard;mtcollins1_bootis absent because #11788 establishes it as not consumed.
Evidence used for this ledger read is the executed receipt, not the badges: corpus parse clean over 6,328 files; 22/22 converge claims and 14/14 edge claims returned rc=0; a deliberately false control returned rc=1 and named the false claim. The regenerated workflow retains both PXE dispatches and their real SSH-key demand.
SOURCE DELTA ACCEPTED at this exact head. This comment records the corrected basis after merge; it does not resurrect the invalid earlier approval.
PXE-FABRIC 0C follow-up (parent sleek-carp-159). Stacked on #11604, which must land first; after that, the diff is only the files listed below.
What
gunbc.site_pxe_edge_convergeis a peer ofgunbc.runner_host_file_converge, per the parent's ruling. It does not add an axis tofleet_converge_planorhost_converge.site_pxe_edge_subject); any other dispatched host is refused.site_edge_proxy_dhcp_config, now withenable-tftp,tftp-rootandlog-dhcp) and agunbc-site-pxe-edge.serviceunit rendered throughextdeps.systemd.unit_file. Both are written withgunbc.typed_remote_file_write, over fleet ssh, as the bootstrap admin, with byte read-back.SiteBootstrapTransport(chainloader_digest). The pinned filename must also be theextdeps.firmware.ipxeipxe_arm64_efi_snponlybuild.site_pxe_edge_gate_causescounts every cause: unpinned, digest unobservable or mismatched, not the iPXE arm64 build, dnsmasq binary absent, no sudo. Any cause means no writes and no unit start, and the run refuses with the causes listed.ActiveStateis read back.gunbc.site_uefi_arm64_pxe_edge).site_pxe_edge_observeandsite_pxe_edge_converge, withci_spectargets and a receipt upload..github/workflows/fleet-converge.ymlwas regenerated fromexpected_fleet_converge_yml.extdeps.formats.dnsmasqgainsenable-tftp,tftp-root=andlog-dhcp.State on landing
site_pxe_edge_chainloader_pinisSitePxeEdgeChainloaderUnpinned. The first dispatch therefore refuses at the gate withchainloader-unpinned, which is the fail-closed start the parent ruled. The remaining obligation is this lane's: build iPXEbin-arm64-efi/snponly.efiat a recorded revision, pin its digest, and place the file.Evidence
All run locally with
/cargo-target/release/gunbc runthrough scratch drivers:test.claim.fleet.site_pxe_edge_converge_witness: 10 witnesses pass.test.claim.workflow_dispatch_input_witnesspasses.v1_src_dag_parseis clean.🤖 Generated with Claude Code