Skip to content

MAIN REPAIR: two missing arms in fleet_converge_mode_fleet_ssh_key_demand - #11775

Closed
gunbai-bot[bot] wants to merge 1 commit into
mainfrom
session/wise-heron-27
Closed

gunbai-bot[bot] wants to merge 1 commit into
mainfrom
session/wise-heron-27

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Main is red on 348a2f79bc: resolving dag/gunbc/instruments/generated_artifact_gate.dag refuses with fleet_converge_workflow.dag:321:3: non-exhaustive match: missing variant(s) ApprovalKeyringConverge, MtCollins1Boot. #11736 added the total match over the modes on its base; #11484 added two modes without an arm. Merge skew on an exhaustive match — this PR adds the two arms and nothing else.

Both arms are FleetSshKeyConsumed: the declaration's rule is that only the two API-only org modes are NotConsumed and every other mode keeps the key it held before, which before #11736 was every mode. approval_keyring_converge is a real demand (fleet SSH to srv1 via typed_argv_exec_over_fleet_ssh); mtcollins1_boot reaches its host over BMC only (IPMI SOL + HTTP media attach, no fleet_ssh_locus in its closure), so Consumed there is status quo — moving it is a follow-up with its own evidence, not this repair.

What I ran (required CI no longer executes the floor, per #11742 — the check is not evidence)

Binary: cargo build --release -p v1-compiler --bin gunbc from this tree, local, sha256 fa1beb35…31bf.

  • Red on origin/main (detached checkout of 348a2f79bc): gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main → exit 1, non-exhaustive match: missing variant(s) ApprovalKeyringConverge, MtCollins1Boot (602 s).
  • Green on this branch, scoped: gunbc run … --entry dag/gunbc/fleet/fleet_converge_workflow.dag --function fleet_converge_fleet_ssh_key_step_if resolves and evaluates; the value now ends … || github.event.inputs.mode == 'approval_keyring_converge' || github.event.inputs.mode == 'mtcollins1_boot' (the only refusal is the host's "a String is not a ProcessExit" exit-code rule, exit 2).
  • The full generated_artifact_gate entry on this branch refused locally with MemoryStallRefusedPageThrash (host slice at 96/125 GiB) after 5 modules — an infra refusal, not a verdict; the same entry ran to its structural verdict on main above. The heal job is the execution for the full entry.

Generated projection

.github/workflows/fleet-converge.yml is NOT hand-edited. Its committed fleet-key gate (if: on "Materialize fleet key in-run", 21 modes) is missing the two new modes, so the heal job's regeneration should change exactly that one line, appending approval_keyring_converge and mtcollins1_boot. Any other yml delta from heal is unexpected and worth reading.

🤖 Generated with Claude Code

… dropped

Main is red: resolving dag/gunbc/instruments/generated_artifact_gate.dag
refuses with "fleet_converge_workflow.dag:321:3: non-exhaustive match:
missing variant(s) ApprovalKeyringConverge, MtCollins1Boot". #11736 added
the total match over the 23 modes that existed on its base; #11484 added
two modes without an arm. Each was green against its own base; the pair is
red, which is exactly what an exhaustive match exists to catch.

Both arms are FleetSshKeyConsumed. The declaration's own rule: only
OrgActionsObserve and OrgRunnerRosterObserve are established API-only;
every other mode keeps the key it held before, and before #11736 the key
step had no gate at all, so both held it. FleetSshKeyNotConsumed would be
a new credential claim with no evidence behind it.

What the two closures actually do, read for this change (two independent
readings agree):
- approval_keyring_converge imports prepare_fleet_ssh_agent_context and
  typed_argv_exec_over_fleet_ssh and writes the MAC keys onto srv1 over
  fleet SSH -- Consumed is a real demand there.
- mtcollins1_boot runs on the srv1-pinned runner, POSTs to loopback
  /approvals, and drives the target over its BMC (extdeps.bmc.ipmi SOL +
  HTTP media attach); nothing in its closure imports fleet_ssh_locus or
  typed_argv_exec. Consumed there is status quo, not an established
  demand. Whether it can move to NotConsumed is a follow-up with its own
  evidence (the parent lane is filing it), not this main-repair.

The committed .github/workflows/fleet-converge.yml fleet-key gate (the
`if:` on "Materialize fleet key in-run") lists 21 modes; this change makes
fleet_converge_fleet_ssh_key_step_if append approval_keyring_converge and
mtcollins1_boot, so the heal job's regeneration should change that one
line and nothing else. The projection is not hand-edited here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Duplicate of #11777 (identical two-arm diff). The dashboard spawned several lanes on one work item; #11777 is the bound assignment and is based on the current main tip, so it is the one to land. Closing this to keep one repair in flight. — sent from lively-wren-426

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants