Repository navigation
Delete the 13 consumed #11681 namespace admission rows - #11696
Merged
Merged
Conversation
…ent password, typed custody-read refusal
srv1 and srv2 were brought up by hand on an operator-chosen BMC root password, so neither the
factory probe nor custody could authenticate to them. This adds the route that takes such a BMC
into custody, and ran it on both on 2026-09-18.
- gunbc.bmc_onboarding: srv1/srv2 onboarding plans, BMC endpoints read from the fleet intent.
- gunbc.secret_provision_actuator: create_secret_container split out of create_secret_for_attempt
(which now delegates), for flows whose payload is minted after custody is established.
- gunbc.tools.bmc_onboard:
- the custody container is observed, and created once on a pre-mutation 404, before the first
version is written and before the BMC is touched; an unknown create outcome stops for a human;
- bmc_takeover_credential proves an operator-supplied current password (file named by
GUNBC_BMC_TAKEOVER_PASSWORD_FILE, never source) against the BMC, then mints, stores, reads
back, rotates FROM that password and re-authenticates; rotation now takes the current password
as a parameter instead of assuming the factory one;
- a failed custody read in the credential probe is classified before its payload is decoded
(it crashed the interpreter on a null when no bmc-srv1-admin existed);
- srv1/srv2 entries select the run's token source (WIF or GUNBC_GCP_ACCESS_TOKEN_FILE).
Receipt (2026-09-18, operator token, run from srv1): both takeovers exited 0 with version 1
written and read back; independently, the stored bmc-srvN-admin secret authenticates (200) and the
old demo password is refused (401) on both BMCs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… in its own custody secret Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…atError, srv1) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unreadable, never absent (review 67794) Members are read through gunbc.scm.json_member rather than a local optional-collapsing lookup; a skipped member used to shorten the membership and let an unread reader read as absent, authorizing a create. RoleId/Enabled go through the same authority. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the reader login; per-host body path refused on failed removal (review 67817) - bmc_custody_refused / bmc_custody_refusal_reason deleted: the accessor fabricated "" for an unreachable arm. bmc_store_credential_verified, bmc_store_and_rotate and the reader create now match BmcCustodyContainer directly; the witness that locked the predicate pair in is deleted (the tool module stays typechecked through the reader witness's import). - The reader create is its own function: POST, then the administrator role read-back is matched, and only in its converged arm does the reader login repoint the shared netrc. - The create body path is per host, and a failed removal refuses before the POST outcome is read. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…w 67836)
- bmc_custody_credential answers Held | Absent (404 only) | Unreadable { cause }; a refused
status or an unreached call no longer reads as a secret that is not in custody.
- bmc_login_attempt answers Accepted | Rejected { body } | NotAttempted { reason }; a netrc that
could not be written keeps netrc_failure_reason's located cause instead of reading as a
refused password.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sifier (review 67848) CustodyCredentialRead / custody_read_refusal_cause / bmc_custody_credential move down into gunbc.tools.bmc_onboard, and bmc_probe_credential_phase uses them: a 404 says custody holds no credential, every other failed read carries its cause, instead of one fixed sentence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- BmcOnboardingPlan carries the fleet HostIdentity; altra_onboarding_plan derives the admin secret name from it and takes the endpoint from that host's fleet_intent baseboard, for all four hosts. The reader converge takes only the plan: the reader secret and body path derive from plan.host, so one host's secret cannot be paired with another host's BMC. - bmc_stored_credential_read_succeeded is deleted; custody_read_refusal_cause answers none for a success and bmc_custody_credential matches once, with no unreachable arm. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…stake (review 67874) They land with the HEALTH-0 collector that produces HostHealthObserved, not before it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…for both BMC images Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d split out - product.host_health: pure host/fleet assessment over std.goal_assessment (signals: memory counters, processor/platform, fans via product.fan_tach_health, temperatures, BMC event window). - product.fan_tach fan_tach_window_of: the window's one producer from samples. - extdeps.bmc.http: readonly GetManager, GetChassisThermal, GetChassisSensor, GetSystemEventLogEntries. - extdeps.bmc.openbmc_message_registry: MemoryECCCorrectable/Uncorrectable ids. - gunbc.fleet_health_observe: closed FleetHealthRedfishRead vocabulary, surface derived from the live firmware through the board catalog, sampled fan/temperature windows, event log window with wrap/clear continuity, private per-run netrc shredded on every path. - gunbc.bmc_custody_read: the custody read, split out of gunbc.tools.bmc_onboard so a read-only consumer need not import the minting tool. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…roster; board secondary tach headers declared - gunbc.fleet_health: goals derived from fleet_intent_known_hosts (fan expectation rows, the board's 20-sensor temperature roster with no cited limit, NoPriorBaseline); reader credential from custody; one keyed observation per rostered host; assess_fleet_health; receipt rendered as the exit reason and written to GUNBC_FLEET_HEALTH_RECEIPT when set. - gunbc.fleet_fan_tach_expectation: FAN1_1..FAN5_1, which both images publish and no host wires, declared tach-not-expected on all four hosts; the two fan witnesses that count judged headers updated with the reason beside them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…wave admission)
The custody read moved out of gunbc.tools.bmc_onboard into its own read-only module; each
consumer's binding of CustodyCredential{Held,Absent,Unreadable}, bmc_custody_credential and
custody_read_refusal_cause now resolves to gunbc.bmc_custody_read. One TargetChanged row per
binding, owner gunbc#11681; the rows are consumed on landing and owe deletion then.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
They admitted the bindings that moved to gunbc.bmc_custody_read; once #11681 lands they are consumed and owe deletion. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ws; delete the 40 consumed #11587 rows Touching the roster makes its consumed rows due: the 40 ACTION-USE admissions (owner #11587) were already satisfied at the base. The 13 custody-read rows now name gunbc#11696, which deletes them once #11681 lands. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…h-0-admission-cleanup # Conflicts: # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_bmc_custody_credential.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialabsent.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialheld.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_as_admin_custodycredentialunreadable.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_bmc_custody_credential.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialabsent.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialheld.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_health_reader_converge_bmc_health_reader_converge_custodycredentialunreadable.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_bmc_custody_credential.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialabsent.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialheld.dag # dag/gunbc/namespace/transition_admission/gunbc_tools_bmc_onboard_bmc_probe_credential_phase_custodycredentialunreadable.dag # dag/gunbc/namespace/transition_admission/test_claim_bmc_health_reader_witness_only_a_404_reads_as_absent_custody_custody_read_refusal_cause.dag
The branch had already deleted these rows while they lived on its parent branch. #11681 then merged, so main carries them again -- which is the correct merge result, not a conflict artifact: they are new on main relative to this branch's base, so the merge re-adds them. The transition they admit is now consumed (the bindings moved to gunbc.bmc_custody_read when #11681 landed), so the rows owe deletion. They are deleted again here, against main. The six add/add conflicts in the health closure resolve to main's side in full: every branch-only line was the superseded earlier form of what #11681 finished landing (MemoryErrorEventsLogged and the DIMM_HOT classification), so main is strictly newer there and this branch had nothing unique to keep. The ten spark rows in the same directory belong to another lane and are untouched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Merged main and re-applied the deletion at The conflict was not a conflict in the interesting sense. This branch deleted the 13 rows while they still lived on its parent branch; #11681 then merged, so main carries them again. Relative to this branch's merge base those rows are new on main, so re-adding them is the correct merge result. The rows are now genuinely consumed — the bindings they admit moved to Two resolutions worth stating rather than burying:
The diff against main is now exactly the claim in the title: 13 files, 247 deletions, nothing else. — sent from swift-newt-222 |
briansrls
added this pull request to the merge queue
Sep 20, 2026
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 24, 2026
…rovenance The six transition_admission paths go back into v2.compiler.reference_conservation_census reference_conservation_stratified_sample_paths. The sample is pinned to fec339d and declared byte-for-byte rerunnable, with at least six paths per stratum. The census renders an unreadable path as its own `unreadable` line, never an omission, so a deleted path belongs in that rendering, not in a shrunken list. Recomputing the sample is not this change's work. CORRECTION to the first commit's message, which named the wrong landing PRs and a wrong count. The 56 surviving rows came from gunbc#11625 (32), #11565 (10), #11667 (10) and #11689 (4). #11681 contributed none: its 13 rows were already deleted by #11696. #11771 removed 23 rows, not 17. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deletion follow-up for the 13
TargetChangedadmission rows #11681 adds, which admit the bindings that move togunbc.bmc_custody_read. Retarget to main and land it after #11681 merges.🤖 Generated with Claude Code