Skip to content

Delete the 13 consumed #11681 namespace admission rows - #11696

Merged
briansrls merged 18 commits into
mainfrom
fleet-health-0-admission-cleanup
Sep 20, 2026
Merged

briansrls merged 18 commits into
mainfrom
fleet-health-0-admission-cleanup

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Deletion follow-up for the 13 TargetChanged admission rows #11681 adds, which admit the bindings that move to gunbc.bmc_custody_read. Retarget to main and land it after #11681 merges.

🤖 Generated with Claude Code

Brian Searls and others added 17 commits September 18, 2026 15:02
…ent password, typed custody-read refusal

srv1 and srv2 were brought up by hand on an operator-chosen BMC root password, so neither the
factory probe nor custody could authenticate to them. This adds the route that takes such a BMC
into custody, and ran it on both on 2026-09-18.

- gunbc.bmc_onboarding: srv1/srv2 onboarding plans, BMC endpoints read from the fleet intent.
- gunbc.secret_provision_actuator: create_secret_container split out of create_secret_for_attempt
  (which now delegates), for flows whose payload is minted after custody is established.
- gunbc.tools.bmc_onboard:
  - the custody container is observed, and created once on a pre-mutation 404, before the first
    version is written and before the BMC is touched; an unknown create outcome stops for a human;
  - bmc_takeover_credential proves an operator-supplied current password (file named by
    GUNBC_BMC_TAKEOVER_PASSWORD_FILE, never source) against the BMC, then mints, stores, reads
    back, rotates FROM that password and re-authenticates; rotation now takes the current password
    as a parameter instead of assuming the factory one;
  - a failed custody read in the credential probe is classified before its payload is decoded
    (it crashed the interpreter on a null when no bmc-srv1-admin existed);
  - srv1/srv2 entries select the run's token source (WIF or GUNBC_GCP_ACCESS_TOKEN_FILE).

Receipt (2026-09-18, operator token, run from srv1): both takeovers exited 0 with version 1
written and read back; independently, the stored bmc-srvN-admin secret authenticates (200) and the
old demo password is refused (401) on both BMCs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… in its own custody secret

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…atError, srv1)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unreadable, never absent (review 67794)

Members are read through gunbc.scm.json_member rather than a local optional-collapsing
lookup; a skipped member used to shorten the membership and let an unread reader read as
absent, authorizing a create. RoleId/Enabled go through the same authority.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the reader login; per-host body path refused on failed removal (review 67817)

- bmc_custody_refused / bmc_custody_refusal_reason deleted: the accessor fabricated "" for an
  unreachable arm. bmc_store_credential_verified, bmc_store_and_rotate and the reader create now
  match BmcCustodyContainer directly; the witness that locked the predicate pair in is deleted
  (the tool module stays typechecked through the reader witness's import).
- The reader create is its own function: POST, then the administrator role read-back is matched,
  and only in its converged arm does the reader login repoint the shared netrc.
- The create body path is per host, and a failed removal refuses before the POST outcome is read.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…w 67836)

- bmc_custody_credential answers Held | Absent (404 only) | Unreadable { cause }; a refused
  status or an unreached call no longer reads as a secret that is not in custody.
- bmc_login_attempt answers Accepted | Rejected { body } | NotAttempted { reason }; a netrc that
  could not be written keeps netrc_failure_reason's located cause instead of reading as a
  refused password.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sifier (review 67848)

CustodyCredentialRead / custody_read_refusal_cause / bmc_custody_credential move down into
gunbc.tools.bmc_onboard, and bmc_probe_credential_phase uses them: a 404 says custody holds no
credential, every other failed read carries its cause, instead of one fixed sentence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- BmcOnboardingPlan carries the fleet HostIdentity; altra_onboarding_plan derives the admin
  secret name from it and takes the endpoint from that host's fleet_intent baseboard, for all
  four hosts. The reader converge takes only the plan: the reader secret and body path derive
  from plan.host, so one host's secret cannot be paired with another host's BMC.
- bmc_stored_credential_read_succeeded is deleted; custody_read_refusal_cause answers none for a
  success and bmc_custody_credential matches once, with no unreachable arm.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…stake (review 67874)

They land with the HEALTH-0 collector that produces HostHealthObserved, not before it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…for both BMC images

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d split out

- product.host_health: pure host/fleet assessment over std.goal_assessment (signals: memory
  counters, processor/platform, fans via product.fan_tach_health, temperatures, BMC event window).
- product.fan_tach fan_tach_window_of: the window's one producer from samples.
- extdeps.bmc.http: readonly GetManager, GetChassisThermal, GetChassisSensor, GetSystemEventLogEntries.
- extdeps.bmc.openbmc_message_registry: MemoryECCCorrectable/Uncorrectable ids.
- gunbc.fleet_health_observe: closed FleetHealthRedfishRead vocabulary, surface derived from the live
  firmware through the board catalog, sampled fan/temperature windows, event log window with
  wrap/clear continuity, private per-run netrc shredded on every path.
- gunbc.bmc_custody_read: the custody read, split out of gunbc.tools.bmc_onboard so a read-only
  consumer need not import the minting tool.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…roster; board secondary tach headers declared

- gunbc.fleet_health: goals derived from fleet_intent_known_hosts (fan expectation rows, the board's
  20-sensor temperature roster with no cited limit, NoPriorBaseline); reader credential from custody;
  one keyed observation per rostered host; assess_fleet_health; receipt rendered as the exit reason
  and written to GUNBC_FLEET_HEALTH_RECEIPT when set.
- gunbc.fleet_fan_tach_expectation: FAN1_1..FAN5_1, which both images publish and no host wires,
  declared tach-not-expected on all four hosts; the two fan witnesses that count judged headers
  updated with the reason beside them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…wave admission)

The custody read moved out of gunbc.tools.bmc_onboard into its own read-only module; each
consumer's binding of CustodyCredential{Held,Absent,Unreadable}, bmc_custody_credential and
custody_read_refusal_cause now resolves to gunbc.bmc_custody_read. One TargetChanged row per
binding, owner gunbc#11681; the rows are consumed on landing and owe deletion then.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
They admitted the bindings that moved to gunbc.bmc_custody_read; once #11681 lands they are
consumed and owe deletion.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ws; delete the 40 consumed #11587 rows

Touching the roster makes its consumed rows due: the 40 ACTION-USE admissions (owner #11587) were
already satisfied at the base. The 13 custody-read rows now name gunbc#11696, which deletes them
once #11681 lands.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…h-0-admission-cleanup

# Conflicts:
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_bmc_custody_credential.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialabsent.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialheld.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialunreadable.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_bmc_custody_credential.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialabsent.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialheld.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialunreadable.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_bmc_custody_credential.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialabsent.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialheld.dag
#	dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialunreadable.dag
#	dag/gunbc/namespace/transition_admission/test_claim_bmc_health_reader_witness_only_a_404_reads_as_absent_custody_custody_read_refusal_cause.dag
Base automatically changed from fleet-health-0 to main September 20, 2026 16:34
The branch had already deleted these rows while they lived on its parent
branch. #11681 then merged, so main carries them again -- which is the
correct merge result, not a conflict artifact: they are new on main relative
to this branch's base, so the merge re-adds them.

The transition they admit is now consumed (the bindings moved to
gunbc.bmc_custody_read when #11681 landed), so the rows owe deletion. They
are deleted again here, against main.

The six add/add conflicts in the health closure resolve to main's side in
full: every branch-only line was the superseded earlier form of what #11681
finished landing (MemoryErrorEventsLogged and the DIMM_HOT classification),
so main is strictly newer there and this branch had nothing unique to keep.
The ten spark rows in the same directory belong to another lane and are
untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 20, 2026 17:09
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Merged main and re-applied the deletion at 8e5af33460; taking this out of draft now that #11681 has landed.

The conflict was not a conflict in the interesting sense. This branch deleted the 13 rows while they still lived on its parent branch; #11681 then merged, so main carries them again. Relative to this branch's merge base those rows are new on main, so re-adding them is the correct merge result. The rows are now genuinely consumed — the bindings they admit moved to gunbc.bmc_custody_read when #11681 landed — so they are deleted again, against main.

Two resolutions worth stating rather than burying:

  • The six add/add conflicts in the health closure take main's side in full. I checked every branch-only line before doing it: each one was the superseded earlier form of what HEALTH-0: an out-of-band, read-only fleet health check #11681 finished landing (MemoryErrorEventLogged → MemoryErrorEventsLogged, and the DIMM_HOT classification). Main is strictly newer there, so nothing unique was dropped.
  • The ten spark rows in the same directory are untouched. They belong to another lane; only the 13 BMC rows this PR names are deleted.

The diff against main is now exactly the claim in the title: 13 files, 247 deletions, nothing else.

— sent from swift-newt-222

@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 20, 2026
6 tasks
@briansrls
briansrls added this pull request to the merge queue Sep 20, 2026
Merged via the queue into main with commit 3c13dc7 Sep 20, 2026
4 checks passed
@briansrls
briansrls deleted the fleet-health-0-admission-cleanup branch September 20, 2026 19:33
gunbai-bot Bot pushed a commit that referenced this pull request Sep 24, 2026
…rovenance

The six transition_admission paths go back into
v2.compiler.reference_conservation_census reference_conservation_stratified_sample_paths.
The sample is pinned to fec339d and declared byte-for-byte rerunnable, with at least six
paths per stratum. The census renders an unreadable path as its own `unreadable` line, never
an omission, so a deleted path belongs in that rendering, not in a shrunken list. Recomputing
the sample is not this change's work.

CORRECTION to the first commit's message, which named the wrong landing PRs and a wrong count.
The 56 surviving rows came from gunbc#11625 (32), #11565 (10), #11667 (10) and #11689 (4).
#11681 contributed none: its 13 rows were already deleted by #11696. #11771 removed 23 rows,
not 17.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant