Repository navigation
MAIN REPAIR: two missing arms in fleet_converge_mode_fleet_ssh_key_demand - #11775
Closed
gunbai-bot[bot] wants to merge 1 commit into
Closed
gunbai-bot[bot] wants to merge 1 commit into
gunbai-bot[bot] wants to merge 1 commit into
Conversation
… dropped Main is red: resolving dag/gunbc/instruments/generated_artifact_gate.dag refuses with "fleet_converge_workflow.dag:321:3: non-exhaustive match: missing variant(s) ApprovalKeyringConverge, MtCollins1Boot". #11736 added the total match over the 23 modes that existed on its base; #11484 added two modes without an arm. Each was green against its own base; the pair is red, which is exactly what an exhaustive match exists to catch. Both arms are FleetSshKeyConsumed. The declaration's own rule: only OrgActionsObserve and OrgRunnerRosterObserve are established API-only; every other mode keeps the key it held before, and before #11736 the key step had no gate at all, so both held it. FleetSshKeyNotConsumed would be a new credential claim with no evidence behind it. What the two closures actually do, read for this change (two independent readings agree): - approval_keyring_converge imports prepare_fleet_ssh_agent_context and typed_argv_exec_over_fleet_ssh and writes the MAC keys onto srv1 over fleet SSH -- Consumed is a real demand there. - mtcollins1_boot runs on the srv1-pinned runner, POSTs to loopback /approvals, and drives the target over its BMC (extdeps.bmc.ipmi SOL + HTTP media attach); nothing in its closure imports fleet_ssh_locus or typed_argv_exec. Consumed there is status quo, not an established demand. Whether it can move to NotConsumed is a follow-up with its own evidence (the parent lane is filing it), not this main-repair. The committed .github/workflows/fleet-converge.yml fleet-key gate (the `if:` on "Materialize fleet key in-run") lists 21 modes; this change makes fleet_converge_fleet_ssh_key_step_if append approval_keyring_converge and mtcollins1_boot, so the heal job's regeneration should change that one line and nothing else. The projection is not hand-edited here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Main is red on
348a2f79bc: resolvingdag/gunbc/instruments/generated_artifact_gate.dagrefuses withfleet_converge_workflow.dag:321:3: non-exhaustive match: missing variant(s) ApprovalKeyringConverge, MtCollins1Boot. #11736 added the total match over the modes on its base; #11484 added two modes without an arm. Merge skew on an exhaustive match — this PR adds the two arms and nothing else.Both arms are
FleetSshKeyConsumed: the declaration's rule is that only the two API-only org modes areNotConsumedand every other mode keeps the key it held before, which before #11736 was every mode.approval_keyring_convergeis a real demand (fleet SSH to srv1 viatyped_argv_exec_over_fleet_ssh);mtcollins1_bootreaches its host over BMC only (IPMI SOL + HTTP media attach, nofleet_ssh_locusin its closure), soConsumedthere is status quo — moving it is a follow-up with its own evidence, not this repair.What I ran (required CI no longer executes the floor, per #11742 — the check is not evidence)
Binary:
cargo build --release -p v1-compiler --bin gunbcfrom this tree, local,sha256 fa1beb35…31bf.348a2f79bc):gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main→ exit 1,non-exhaustive match: missing variant(s) ApprovalKeyringConverge, MtCollins1Boot(602 s).gunbc run … --entry dag/gunbc/fleet/fleet_converge_workflow.dag --function fleet_converge_fleet_ssh_key_step_ifresolves and evaluates; the value now ends… || github.event.inputs.mode == 'approval_keyring_converge' || github.event.inputs.mode == 'mtcollins1_boot'(the only refusal is the host's "aStringis not aProcessExit" exit-code rule, exit 2).generated_artifact_gateentry on this branch refused locally withMemoryStallRefusedPageThrash(host slice at 96/125 GiB) after 5 modules — an infra refusal, not a verdict; the same entry ran to its structural verdict on main above. The heal job is the execution for the full entry.Generated projection
.github/workflows/fleet-converge.ymlis NOT hand-edited. Its committed fleet-key gate (if:on "Materialize fleet key in-run", 21 modes) is missing the two new modes, so the heal job's regeneration should change exactly that one line, appendingapproval_keyring_convergeandmtcollins1_boot. Any other yml delta from heal is unexpected and worth reading.🤖 Generated with Claude Code