Repository navigation
Conversation
gunbc.apply (Plan) and gunbc.runner_capacity_realize now plan from
gunbc.fleet.organization_runner_roster_read organization_runner_roster_live_read:
GET /orgs/{org}/actions/runners through the gh CLI under the in-run gunbai-ci
installation token (gunbc_ci_org_admin_app_token_prelude), following RFC 8288
Link pages via std.page_fold, accounting by distinct runner id against
total_count. A failed later page keeps earlier members as RosterObservedPartial;
no credential answers RosterReadUnavailable, never the pinned corpus, which
survives only as the dated witness fixture incident_2026_08_06_roster_fixture.
Adds the org-scoped per-ID read (present / absent / unobserved), with 404 read
as absent only after a same-org listing answered 200. Adds fleet-converge mode
org_runner_roster_observe. GitHubSelfHostedRunnerRegistration.ephemeral and
.version become Optional, matching the upstream schema.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
OR-1: a rel=next target is admitted only as this organization's runners
listing (orgs/<login>/..., or organizations/<id>/... when the id was read
from GET /orgs/{org}); any other org, repo or resource refuses before fetch.
OR-2: visibility evidence carries its org and admitted route (GH_TOKEN from
the org-admin prelude); a 404 is absence only for that same org.
OR-3: repeated runner ids are reconciled over their full reading; a
disagreement withholds the id and makes the roster Partial.
Witnesses now drive the real pump through std.page_fold over scripted
responses. The page bound is re-grounded as a policy budget with the
receipt as its instrument; the observe mode probes captured ids from the
new runner_ids input, consuming the per-ID read.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Per-ID absence now joins visibility derived from the roster walk the observe entry already performed, instead of a second first-page listing; the unused single-id wrapper is deleted; an unparsable runner_ids token refuses the step rather than being dropped. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/fleet/fleet_runner_connectivity.dag # dag/test/claim/runner/runner_capacity_plan_witness_test.dag # dag/test/claim/runner/runner_capacity_realize_witness_test.dag
…es; fail on unobserved probes OR-2: the route is admitted only when GH_TOKEN and GUNBC_ORG_ADMIN_TOKEN are both bound and agree; a mismatch or a missing binding refuses before any read. OR-3: repeated ids are compared field by field (optional presence as presence, labels through runner_label_sets_equal), not through a joined rendering. OR-4: the observe command exits non-zero when any requested probe is unobserved; negative and non-integer ids refuse. Adds a roster_page_size dispatch input (admitted by std.page_fold admit_page_size) and per-page receipt lines (target, total_count, Link field, ids). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 62b8dd70b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| OrganizationRunnerRosterReport { | ||
| evidence: organization_runner_roster_from_page(observed_on: observed_on, registrations: regs, authority_total: total), |
There was a problem hiding this comment.
Require a stable snapshot before accepting the roster
When registrations change during a multi-page walk, equal total_count values and a matching union size do not prove that every registration was observed. For example, with two registrations and one row per page, page 1 can return A, then A can be replaced by C before page 2 returns C; both pages report total 2 and the code promotes {A,C} to RosterObserved, even though B was omitted and A no longer exists. Because this evidence now drives capacity planning, normal runner churn can produce incorrect additions; require a stable repeated scan or otherwise keep such paginated reads partial.
Useful? React with 👍 / 👎.
|
Duplicate: this is session/swift-moth-559's pre-squash branch, whose content landed as #11711 (squashed to cf66aa2 on main). Reopened automatically after that merge; nothing here is unlanded. The follow-ups from that lane are tracked separately: #11736 (gh as an executor prerequisite) and #11737 (typed ShellSpawnRefused). — sent from deep-owl-720 |
Auto-opened by session-dashboard for session
swift-moth-559.Pushing to
session/swift-moth-559advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan