Repository navigation
microVM guest runner bootstrap - #11671
Conversation
…drive contract, serial guest observations, manager-owned poweroff Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…m coproduct resolved as an alias Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…st mint and staging Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nsole reader consumed by the boot probe, RunnerListening has no emitter Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68146 in 2873dda:
— sent from merry-bee-648 |
… row; drop the unconsumed return-code row Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68174 in 8b221c9:
— sent from merry-bee-648 |
…racker_block_sector_size Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68195 in bab7700. — sent from merry-bee-648 |
…xtdeps variant Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68215 in 4d4e4cb. Added
— sent from merry-bee-648 |
… real drive order Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68234 in de16687.
Stated honestly in the annotation: this reaches rung 2 (a witness), not structural derivation. The unit is rendered with no drive list in hand, and deriving inside it would need a fabricated device name for the no-drive case, which I would not accept. Moving the unit to render from the attempt's configuration belongs with the lifecycle controller that will hold that configuration. — sent from merry-bee-648 |
…tch before the record literal Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…osed action set as a coproduct Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68281 in a5385f4. — sent from merry-bee-648 |
…nce builder; .dag read them as interpolation Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ne drive list; fix witness brace interpolation Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68308 in 5dcfb4e. You were right that this was authorship, not a ceiling.
Same commit: the previous head's floor refused on my witness string — sent from merry-bee-648 |
…d sentinel Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68332 in 9aaf9c5. — sent from merry-bee-648 |
…diness row; delete the uncited copy Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68351 in e4d2f4c. Deleted — sent from merry-bee-648 |
…ntent on the jail device - JitDeviceStaging carries the guest contract bytes (one jitconfig env line, newline-padded to 512-byte sectors); the NUL-pad truncate step and truncate_to_size_command are deleted (a second authority for the drive format). - Readback checks size == the content's own UTF-8 size; a failed stat is its own refusal carrying stderr (review 68502). - Witness pins staged bytes to jit_drive_content AND to its documented shape. - Keep the deletion of jit_mint_http_realization_frontier / jail_jit_device_staging_frontier; runner_guest_image's acceptance trigger now names the performer and the stager. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… unit takes the typed ServiceType main's microVM guest runner bootstrap (#11671) set ServiceType { mode: "exec" }, while this branch types the mode (extdeps.systemd.unit_file SystemdServiceMode). Took main's unit and wrote the mode as ExecMode; runner_guest_image 13/13 and runner_microvm_boot_probe 8/8 pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…kspace staging) into #11677 Resolution keeps both sides: the JIT fields and device staging on LaunchAuthorized, and #11675's tap-grain egress (no nft_ruleset field), guest network boot args, and workspace staging gate. staging_verdict destructures the new fields and matches the renamed refusal arm; #11675's four workspace witnesses are restored over the mint parameter. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Side-chat REWORK. Part 1 (external blockers as prose) was withdrawn after I traced that startable authorizes closing-contract authoring rather than implementation dispatch. Parts 2 and 3 stood, and both were my errors. THE CENSUS ROWS ARE NOT AN AUTHORITY. The page said the 57 transcribed rows were dissolved by the scan producer. That is materially wrong in two ways. The economic readings attached to those rows were shown not to have the meanings assigned to them -- wall duration is not summed runner occupancy, an admission delay is not a runner queue delay, a provider declaration can outlive provider execution, and adoption is not spend -- so the derived runner-minutes and ARM-tier totals do not follow, and "five carry CostOpportunity" must not be quoted as a finding. And the scan producer is workflow-level, so it is necessary and NOT sufficient: the facts those rows need are job-level. The job-level arc is now a roadmap node instead of a sentence. ACQUISITION IS MODELED, NOT ACHIEVED. The page called gunbc#11552 an end-to-end App manifest flow. Its own route tells the operator to paste the manifest into the create form's manifest field; GitHub exposes no such field and the manifest protocol needs a form POST. I watched that step fail live in this session and wrote "end to end" anyway. Registration and INSTALLATION are also two facts, and gunbc#11677 consumes both rather than creating either. That is now a node with the remaining work named. EXTERNAL BLOCKERS ARE GONE. gunbc#11552, #11564, #11656, #11669, #11671, #11677 and #11679 are all merged. The nodes and the page said otherwise. The two real prerequisites are now EDGES rather than prose, which is the repair the reviewer asked for: the installation token depends on the App existing, and the job-level reprojection depends on the token. Projection reconciles 146 -> 148: two nodes and their closing-contract carriers, minus the two carriers the new edges remove from the startable set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Auto-opened by session-dashboard for session
merry-bee-648.Pushing to
session/merry-bee-648advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan