Skip to content

convergence: live org runner roster producer (dissolve pinned-corpus scaffold) - #11752

Closed
briansrls wants to merge 9 commits into
mainfrom
session/swift-moth-559
Closed

briansrls wants to merge 9 commits into
mainfrom
session/swift-moth-559

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session swift-moth-559.
Pushing to session/swift-moth-559 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 9 commits September 19, 2026 14:00
gunbc.apply (Plan) and gunbc.runner_capacity_realize now plan from
gunbc.fleet.organization_runner_roster_read organization_runner_roster_live_read:
GET /orgs/{org}/actions/runners through the gh CLI under the in-run gunbai-ci
installation token (gunbc_ci_org_admin_app_token_prelude), following RFC 8288
Link pages via std.page_fold, accounting by distinct runner id against
total_count. A failed later page keeps earlier members as RosterObservedPartial;
no credential answers RosterReadUnavailable, never the pinned corpus, which
survives only as the dated witness fixture incident_2026_08_06_roster_fixture.

Adds the org-scoped per-ID read (present / absent / unobserved), with 404 read
as absent only after a same-org listing answered 200. Adds fleet-converge mode
org_runner_roster_observe. GitHubSelfHostedRunnerRegistration.ephemeral and
.version become Optional, matching the upstream schema.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
OR-1: a rel=next target is admitted only as this organization's runners
listing (orgs/<login>/..., or organizations/<id>/... when the id was read
from GET /orgs/{org}); any other org, repo or resource refuses before fetch.
OR-2: visibility evidence carries its org and admitted route (GH_TOKEN from
the org-admin prelude); a 404 is absence only for that same org.
OR-3: repeated runner ids are reconciled over their full reading; a
disagreement withholds the id and makes the roster Partial.
Witnesses now drive the real pump through std.page_fold over scripted
responses. The page bound is re-grounded as a policy budget with the
receipt as its instrument; the observe mode probes captured ids from the
new runner_ids input, consuming the per-ID read.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Per-ID absence now joins visibility derived from the roster walk the observe
entry already performed, instead of a second first-page listing; the unused
single-id wrapper is deleted; an unparsable runner_ids token refuses the
step rather than being dropped.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/fleet/fleet_runner_connectivity.dag
#	dag/test/claim/runner/runner_capacity_plan_witness_test.dag
#	dag/test/claim/runner/runner_capacity_realize_witness_test.dag
…es; fail on unobserved probes

OR-2: the route is admitted only when GH_TOKEN and GUNBC_ORG_ADMIN_TOKEN are
both bound and agree; a mismatch or a missing binding refuses before any read.
OR-3: repeated ids are compared field by field (optional presence as presence,
labels through runner_label_sets_equal), not through a joined rendering.
OR-4: the observe command exits non-zero when any requested probe is unobserved;
negative and non-integer ids refuse. Adds a roster_page_size dispatch input
(admitted by std.page_fold admit_page_size) and per-page receipt lines
(target, total_count, Link field, ids).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review September 20, 2026 00:01
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-20T00:05:15.521561Z 62b8dd7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 62b8dd70b9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +575 to +576
OrganizationRunnerRosterReport {
evidence: organization_runner_roster_from_page(observed_on: observed_on, registrations: regs, authority_total: total),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Require a stable snapshot before accepting the roster

When registrations change during a multi-page walk, equal total_count values and a matching union size do not prove that every registration was observed. For example, with two registrations and one row per page, page 1 can return A, then A can be replaced by C before page 2 returns C; both pages report total 2 and the code promotes {A,C} to RosterObserved, even though B was omitted and A no longer exists. Because this evidence now drives capacity planning, normal runner churn can produce incorrect additions; require a stable repeated scan or otherwise keep such paginated reads partial.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Duplicate: this is session/swift-moth-559's pre-squash branch, whose content landed as #11711 (squashed to cf66aa2 on main). Reopened automatically after that merge; nothing here is unlanded. The follow-ups from that lane are tracked separately: #11736 (gh as an executor prerequisite) and #11737 (typed ShellSpawnRefused).

— sent from deep-owl-720

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant