Repository navigation
Pin the R2 origin write credential minted by run_object_write - #11713
Merged
Merged
Conversation
The durable origin's write credential was OriginCredentialUnminted, so tools.fabric_m0_origin_object_probe roundtrip refused at put_origin_object. run_object_write executed 2026-09-19 (Cloudflare token f70d656b..., stored as version 1 of cloudflare-r2-origin-write-token); pin both the same way the read credential is pinned. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…arged Review 68467: pinning the write credential left three consumers asserting the old state. r2_origin_bucket_write_credential_is_unminted_and_names_its_mint_entry and origin_write_target_refuses_until_the_write_credential_is_pinned are retired into the write twins their own annotations named; the two frontier rows whose dissolution this PR fires are removed and the frontier test flipped to assert their absence. The unminted-write refusal is now unreachable from the declarations, so resolve_origin_target takes the origin through resolve_origin_target_under and the refusal stays enrolled on a supplied origin (DESIGN 4b(4)). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Addressed review 68467 in ed83253:
Executed locally against this head's files: the seven affected claims all hold; with the write pin reverted to |
Review 68498: the annotation still said the write entry would refuse once its pin lands; this PR landed it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the R2 durable origin's write credential in
gunbc.cloudflare.r2_originfabric_durable_origin_standing. Until now it wasOriginCredentialUnminted, so every write to the origin refused.What ran, 2026-09-19 (with the operator's GCP token):
gunbai-fabric-originwas created in the dashboard. Neither existed before today, even though the private plan'sstorage-provider-accountsnote read as though the account was ready.tools.fabric_m0_origin_object_probe fetch_absentexited 0. R2 answered a signed GET for a never-written key with 404, which proves the whole read signing chain.gunbc.cloudflare.r2_token_mint_run run_object_writefirst refused, correctly, because the custody container was missing and nothing had been created at Cloudflare. I created the emptycloudflare-r2-origin-write-tokensecret ingunbai-secretswith automatic replication, the same as the read token. On rerun the mint minted Cloudflare tokenf70d656b5e9d20044c3c16ff4d75736eand stored it as secret version 1.tools.fabric_m0_origin_object_probe roundtripexited 0. It PUT the committed fixture, read it back with the read credential, and matched its digest against the fixture.Not done: the four converge entries in
gunbc.cloudflare.r2_mint_secret_accesscallgcloud, which the session container doesn't have. The mint ran as the operator, so it didn't need them. The fleet service account's grants on the new secret are therefore unconverged, and a fleet-principal run of the write path would fail until they are applied from a host that hasgcloud.🤖 Generated with Claude Code