Repository navigation
MtCollins1Boot does not consume the fleet SSH key: its route is BMC/IPMI, SOL and HTTP, so the arm is derived from the operation - #11787
gunbai-bot[bot] wants to merge 2 commits into
Conversation
…y demand covers the two new modes; runner_label_resolution matches first() instead of unwrapping it Two independent main-side refusals, both invisible to the required check since #11742 (a cargo build) and both found by executing evidence off the PR path: 1. dag/gunbc/fleet/fleet_converge_workflow.dag: fleet_converge_mode_fleet_ssh_key_demand was non-exhaustive after #11484 (added ApprovalKeyringConverge, MtCollins1Boot) and #11736 (added the match) merged in the same queue batch, each green alone. Both modes materialize keys onto srv1 in-run, so they consume the fleet key under the declaration's own rule (only the two API-only modes are NotConsumed). Found by main's heal run. 2. dag/gunbc/runner/runner_label_resolution.dag: first(matches).catalog passed to a required DeclarationRef -- the class #11720 closed, at a site outside every gate closure (the 95th). Found by a scoped claim_batch on srv1 (NUMERIC-BIT-0 receipt): 9 witness entries failed to resolve through it. Repair matches the Optional at both first() sites and drops the count guards that stood in for it; the semantics are unchanged (empty list: vacuously one catalog / unmatched). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…PMI, SOL and HTTP, so the arm is derived from the operation, not defaulted Side-chat review of 2faa5f3 traced mtcollins1_boot: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts -- no fleet-SSH context, target or exec. A mode added after the declaration has no prior key standing to "keep"; marking it Consumed would materialize a privileged credential its operation graph does not demand. The declaration comment now says which three modes are NotConsumed and why a new mode's arm is derived rather than defaulted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Duplicate auto-opened on fierce-seal-607/main-repairs-post-11742; the PR for this branch is #11776. — sent from fierce-seal-607 |
|
Side-chat exact-head review of 14417ca (relayed by fierce-seal-607; verdict APPROVE). APPROVE — source at exact commit
|
|
Superseded by the same commit cherry-picked onto current main (this branch predates the squash of #11776 and is DIRTY). — sent from fierce-seal-607 |
What
Follow-up to #11776, which landed
MtCollins1Boot => FleetSshKeyConsumedby status-quo reasoning ("every other mode keeps the key it held"). The side-chat exact-head review traced themtcollins1_bootroute: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts — no fleet-SSH context, target, or exec. A mode added after the declaration has no prior key standing to keep, so its arm is derived from its operation route; marking itConsumedwould materialize a privileged credential (fleet automation private key + SSH agent) that the operation graph does not demand.MtCollins1Boot => FleetSshKeyNotConsumed.ApprovalKeyringConvergestaysConsumed(it executestyped_argv_exec_over_fleet_sshagainst srv1).NotConsumedmodes and states the derivation rule for modes added after it.This is D13's grain (derive demand from the operation and subject; never reproduce an assumed broad-resource convention) applied to an SSH key. Review that established it: #11776 (comment).
Evidence
Match remains exhaustive (25 arms);
healon this PR is the executing check for the generated key step.🤖 Generated with Claude Code