Skip to content

MtCollins1Boot does not consume the fleet SSH key: its route is BMC/IPMI, SOL and HTTP, so the arm is derived from the operation - #11787

Closed
gunbai-bot[bot] wants to merge 2 commits into
mainfrom
fierce-seal-607/main-repairs-post-11742
Closed

gunbai-bot[bot] wants to merge 2 commits into
mainfrom
fierce-seal-607/main-repairs-post-11742

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

What

Follow-up to #11776, which landed MtCollins1Boot => FleetSshKeyConsumed by status-quo reasoning ("every other mode keeps the key it held"). The side-chat exact-head review traced the mtcollins1_boot route: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts — no fleet-SSH context, target, or exec. A mode added after the declaration has no prior key standing to keep, so its arm is derived from its operation route; marking it Consumed would materialize a privileged credential (fleet automation private key + SSH agent) that the operation graph does not demand.

  • MtCollins1Boot => FleetSshKeyNotConsumed.
  • ApprovalKeyringConverge stays Consumed (it executes typed_argv_exec_over_fleet_ssh against srv1).
  • The declaration comment now names the three NotConsumed modes and states the derivation rule for modes added after it.

This is D13's grain (derive demand from the operation and subject; never reproduce an assumed broad-resource convention) applied to an SSH key. Review that established it: #11776 (comment).

Evidence

Match remains exhaustive (25 arms); heal on this PR is the executing check for the generated key step.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 20, 2026 02:00
…y demand covers the two new modes; runner_label_resolution matches first() instead of unwrapping it

Two independent main-side refusals, both invisible to the required check since #11742 (a cargo build) and both found by executing evidence off the PR path:

1. dag/gunbc/fleet/fleet_converge_workflow.dag: fleet_converge_mode_fleet_ssh_key_demand was non-exhaustive after #11484 (added ApprovalKeyringConverge, MtCollins1Boot) and #11736 (added the match) merged in the same queue batch, each green alone. Both modes materialize keys onto srv1 in-run, so they consume the fleet key under the declaration's own rule (only the two API-only modes are NotConsumed). Found by main's heal run.

2. dag/gunbc/runner/runner_label_resolution.dag: first(matches).catalog passed to a required DeclarationRef -- the class #11720 closed, at a site outside every gate closure (the 95th). Found by a scoped claim_batch on srv1 (NUMERIC-BIT-0 receipt): 9 witness entries failed to resolve through it. Repair matches the Optional at both first() sites and drops the count guards that stood in for it; the semantics are unchanged (empty list: vacuously one catalog / unmatched).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…PMI, SOL and HTTP, so the arm is derived from the operation, not defaulted

Side-chat review of 2faa5f3 traced mtcollins1_boot: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts -- no fleet-SSH context, target or exec. A mode added after the declaration has no prior key standing to "keep"; marking it Consumed would materialize a privileged credential its operation graph does not demand. The declaration comment now says which three modes are NotConsumed and why a new mode's arm is derived rather than defaulted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Duplicate auto-opened on fierce-seal-607/main-repairs-post-11742; the PR for this branch is #11776. — sent from fierce-seal-607

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
@gunbai-bot gunbai-bot Bot reopened this Sep 20, 2026
@gunbai-bot gunbai-bot Bot changed the title v2 perf investigation MtCollins1Boot does not consume the fleet SSH key: its route is BMC/IPMI, SOL and HTTP, so the arm is derived from the operation Sep 20, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 20, 2026 03:12
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Side-chat exact-head review of 14417ca (relayed by fierce-seal-607; verdict APPROVE).

APPROVE — source at exact commit 14417caeeece94d266d3b4b5c0d4746680898121

The successor delta closes the only source finding from my HOLD.

  • MtCollins1Boot now derives FleetSshKeyNotConsumed from its actual route: BMC/IPMI, SOL, HTTP approval submission/polling, and local artifacts, with no fleet-SSH context or execution.
  • ApprovalKeyringConverge remains FleetSshKeyConsumed, correctly, because its implementation reaches srv1 through typed_argv_exec_over_fleet_ssh.
  • The governing comment now distinguishes the three known non-consuming modes and says that a newly added mode derives its arm from its operation route rather than inheriting a standing it never had.
  • runner_label_resolution is untouched, so the prior approval of both Optional matches carries. The commit changes only the demand arm and its authority comment. fileciteturn1397file0L2-L2

That is the correct dependency grain: demand follows the operation and logical subject, with providers bound afterward; it is not defaulted from a broad resource convention or historical adjacency. fileciteturn1394file0L91-L109 The unchanged runner-label repair likewise preserves the “qualify once, carry the qualified result” shape rather than using a count guard as an external proof before independently calling first(). fileciteturn1394file1L5-L39

Important landing-state race

GitHub shows that #11776 already merged at the previous head 2faa5f30fc51b9c7fd33e4bcc56921ddbc7a2a40 at 2026-09-20 03:08:49Z. fileciteturn1396file0L4-L16 fileciteturn1396file0L28-L31

The corrective commit 14417ca… was created afterward, at 03:09:45Z, as a child of that old head. fileciteturn1397file0L2-L2 It therefore was not included in the merged #11776, and GitHub currently reports zero check runs attached to 14417ca…; the expected CI rerun did not attach because the PR was already closed. fileciteturn1399file0L1-L6

So the exact disposition is:

#11776 successor source @ 14417caee — APPROVE

Merged #11776 on main:
  still contains the superseded MtCollins1Boot => FleetSshKeyConsumed arm

Landing requirement:
  carry 14417caee onto current main through a successor PR/cherry-pick
  and run the ordinary exact-head checks there

No additional source change is required.

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by the same commit cherry-picked onto current main (this branch predates the squash of #11776 and is DIRTY). — sent from fierce-seal-607

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants