Skip to content

Pin the R2 origin write credential minted by run_object_write - #11713

Merged
briansrls merged 4 commits into
mainfrom
session/still-owl-744
Sep 20, 2026
Merged

briansrls merged 4 commits into
mainfrom
session/still-owl-744

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Pins the R2 durable origin's write credential in gunbc.cloudflare.r2_origin fabric_durable_origin_standing. Until now it was OriginCredentialUnminted, so every write to the origin refused.

What ran, 2026-09-19 (with the operator's GCP token):

  1. The Cloudflare account's R2 subscription was activated, and the bucket gunbai-fabric-origin was created in the dashboard. Neither existed before today, even though the private plan's storage-provider-accounts note read as though the account was ready.
  2. tools.fabric_m0_origin_object_probe fetch_absent exited 0. R2 answered a signed GET for a never-written key with 404, which proves the whole read signing chain.
  3. gunbc.cloudflare.r2_token_mint_run run_object_write first refused, correctly, because the custody container was missing and nothing had been created at Cloudflare. I created the empty cloudflare-r2-origin-write-token secret in gunbai-secrets with automatic replication, the same as the read token. On rerun the mint minted Cloudflare token f70d656b5e9d20044c3c16ff4d75736e and stored it as secret version 1.
  4. With this pin applied, tools.fabric_m0_origin_object_probe roundtrip exited 0. It PUT the committed fixture, read it back with the read credential, and matched its digest against the fixture.

Not done: the four converge entries in gunbc.cloudflare.r2_mint_secret_access call gcloud, which the session container doesn't have. The mint ran as the operator, so it didn't need them. The fleet service account's grants on the new secret are therefore unconverged, and a fleet-principal run of the write path would fail until they are applied from a host that has gcloud.

🤖 Generated with Claude Code

Brian Searls and others added 2 commits September 19, 2026 14:37
The durable origin's write credential was OriginCredentialUnminted, so
tools.fabric_m0_origin_object_probe roundtrip refused at put_origin_object.
run_object_write executed 2026-09-19 (Cloudflare token f70d656b..., stored as
version 1 of cloudflare-r2-origin-write-token); pin both the same way the read
credential is pinned.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…arged

Review 68467: pinning the write credential left three consumers asserting the old
state. r2_origin_bucket_write_credential_is_unminted_and_names_its_mint_entry and
origin_write_target_refuses_until_the_write_credential_is_pinned are retired into
the write twins their own annotations named; the two frontier rows whose
dissolution this PR fires are removed and the frontier test flipped to assert
their absence.

The unminted-write refusal is now unreachable from the declarations, so
resolve_origin_target takes the origin through resolve_origin_target_under and
the refusal stays enrolled on a supplied origin (DESIGN 4b(4)).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 68467 in ed83253:

  • r2_origin_bucket_write_credential_is_unminted_and_names_its_mint_entry retired into its write twin r2_origin_bucket_write_credential_is_the_minted_container (secret, project, exact non-latest version, access-key-id join, and distinct from the read key).
  • Also caught: origin_write_target_refuses_until_the_write_credential_is_pinned (test.claim.cloudflare_r2_origin_object) would have gone red the same way; retired into origin_write_target_resolves_to_the_declared_bucket_and_write_credential.
  • The unminted-write refusal is now unreachable from the declarations, so resolve_origin_target delegates to resolve_origin_target_under(origin:) and origin_write_target_refuses_while_the_write_credential_is_unminted keeps the refusal enrolled on a supplied origin (DESIGN §4b(4)).
  • Both frontier rows whose dissolution this PR fires are removed (gunbc.cloudflare.r2_token_mint, gunbc.cloudflare.r2_permission_group_observe), their prose updated, and r2_origin_object_frontier_rows_reflect_the_executed_evidence now asserts their absence.

Executed locally against this head's files: the seven affected claims all hold; with the write pin reverted to OriginCredentialUnminted exactly the two write-pin claims go red and the supplied-origin refusal stays green. — sent from still-owl-744

Brian Searls and others added 2 commits September 19, 2026 15:53
Review 68498: the annotation still said the write entry would refuse once its pin
lands; this PR landed it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 20, 2026
Merged via the queue into main with commit c87e74e Sep 20, 2026
4 checks passed
@briansrls
briansrls deleted the session/still-owl-744 branch September 20, 2026 23:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant