Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 8 additions & 3 deletions dag/gunbc/fleet/fleet_converge_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -312,9 +312,12 @@ fn fleet_converge_any_mode_step_if(modes: List<FleetConvergeWorkflowMode>) -> St
// inherit the fleet key by omission. The fleet-converge job materializes the fleet key only for a
// dispatch whose mode consumes it: an API-only read (the org credential observe and the org runner
// roster read, both of which reach GitHub over gh and open no host session) must not hold host SSH
// authority it never uses. Only those two modes are established API-only by this declaration;
// every other mode keeps the key it held before, which is the status quo rather than a finding
// that it needs it.
// authority it never uses. Three modes are established as not consuming it: the two API-only reads,
// and the Mt. Collins boot, whose route is BMC/IPMI, SOL and HTTP approval submission with no fleet
// SSH operation. Every mode that predates this declaration keeps the key it held before, which is
// the status quo rather than a finding that it needs it; a mode added AFTER it has no prior standing
// to keep, so its arm is derived from its operation route (the approval keyring converge executes
// over fleet SSH to srv1 and consumes it).
type FleetSshKeyDemand = FleetSshKeyConsumed | FleetSshKeyNotConsumed

fn fleet_converge_mode_fleet_ssh_key_demand(mode: FleetConvergeWorkflowMode) -> FleetSshKeyDemand {
Expand Down Expand Up @@ -342,6 +345,8 @@ fn fleet_converge_mode_fleet_ssh_key_demand(mode: FleetConvergeWorkflowMode) ->
RunnerPasswordSessionToolConverge => FleetSshKeyConsumed
R2MintPreflight => FleetSshKeyConsumed
R2ObjectWriteMint => FleetSshKeyConsumed
ApprovalKeyringConverge => FleetSshKeyConsumed
MtCollins1Boot => FleetSshKeyNotConsumed
}
}

Expand Down
15 changes: 9 additions & 6 deletions dag/gunbc/runner/runner_label_resolution.dag
Original file line number Diff line number Diff line change
Expand Up @@ -150,8 +150,11 @@ fn catalog_matches(catalog: RunnerLabelCatalog, label: String) -> List<LabelMatc
// provider's projection when the join is in the survey: the right destination reached by a false
// statement, sending the reader to the wrong module to repair it.
fn matches_share_one_catalog(matches: List<LabelMatch>) -> Bool {
let first_catalog = first(matches).catalog
count(filter(matches, m => declaration_ref_eq(a: m.catalog, b: first_catalog) == false)) == 0
match first(matches) {
Present { value: head } =>
count(filter(matches, m => declaration_ref_eq(a: m.catalog, b: head.catalog) == false)) == 0
Absent => true
}
}

fn surveyed_matches(label: String) -> List<LabelMatch> {
Expand Down Expand Up @@ -215,11 +218,11 @@ fn resolve_from_matches(
" DIFFERENT surveyed catalogs. One label on one selection surface is one authority's fact, so there is no answer to give: taking either row would make the result depend on which catalog is enrolled first. The repair is to gunbc.runner_provider_survey's roster, not to any provider module."], ""),
}
}
} else if count(matches) > 0 {
let hit = first(matches)
RunnerLabelResolved { row: hit.row, snapshot: hit.snapshot }
} else {
unmatched_resolution(label: label, observed_at: observed_at)
match first(matches) {
Present { value: hit } => RunnerLabelResolved { row: hit.row, snapshot: hit.snapshot }
Absent => unmatched_resolution(label: label, observed_at: observed_at)
}
}
}

Expand Down