Skip to content

MtCollins1Boot does not consume the fleet SSH key: its route is BMC/IPMI, SOL and HTTP, so the arm is derived from the operation - #11788

Merged
gunbai-bot[bot] merged 4 commits into
mainfrom
fierce-seal-607/mtcollins1-boot-no-fleet-ssh
Sep 20, 2026
Merged

gunbai-bot[bot] merged 4 commits into
mainfrom
fierce-seal-607/mtcollins1-boot-no-fleet-ssh

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

What

Follow-up to #11776, which landed MtCollins1Boot => FleetSshKeyConsumed by status-quo reasoning ("every other mode keeps the key it held"). The side-chat exact-head review traced the mtcollins1_boot route: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts — no fleet-SSH context, target, or exec. A mode added after the declaration has no prior key standing to keep, so its arm is derived from its operation route; marking it Consumed would materialize a privileged credential (fleet automation private key + SSH agent) that the operation graph does not demand.

  • MtCollins1Boot => FleetSshKeyNotConsumed.
  • ApprovalKeyringConverge stays Consumed (it executes typed_argv_exec_over_fleet_ssh against srv1).
  • The declaration comment now names the three NotConsumed modes and states the derivation rule for modes added after it.

This is D13's grain (derive demand from the operation and subject; never reproduce an assumed broad-resource convention) applied to an SSH key. Review that established it: #11776 (comment).

Evidence

Match remains exhaustive (25 arms); heal on this PR is the executing check for the generated key step.

🤖 Generated with Claude Code

Carried onto current main from #11787 (whose branch predated the squash of #11776 and went DIRTY); source identical to 14417ca, side-chat APPROVE at #11787 (comment).

…PMI, SOL and HTTP, so the arm is derived from the operation, not defaulted

Side-chat review of 2faa5f3 traced mtcollins1_boot: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts -- no fleet-SSH context, target or exec. A mode added after the declaration has no prior key standing to "keep"; marking it Consumed would materialize a privileged credential its operation graph does not demand. The declaration comment now says which three modes are NotConsumed and why a new mode's arm is derived rather than defaulted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Sep 20, 2026
fierce-seal-607: #11776 (374d0ce) already adds both arms on main, and #11788
corrects MtCollins1Boot to FleetSshKeyNotConsumed -- its route is BMC/IPMI/SOL
plus HTTP and opens no fleet-SSH op. Keeping my FleetSshKeyConsumed arm would
both conflict with that PR and carry the wrong value, so the repair comes from
main rather than from this branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md namespace_wave_admission_wall_removed
Heal-Candidate-Run: 35486168956
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Side-chat exact-head reviews (relayed by fierce-seal-607).

#11788 — APPROVE

Exact head: 0de1788b891cdc31f22377fc0f2df8ed6c35670a

This is now the correction-only successor requested in the prior HOLD:

  • one commit;
  • one changed file;
  • MtCollins1Boot changes from FleetSshKeyConsumed to FleetSshKeyNotConsumed;
  • ApprovalKeyringConverge remains consumed;
  • the comment names the three non-consuming modes and requires future modes to derive their standing from their actual operation route. fileciteturn1401file0L8-L16 fileciteturn1401file0L32-L35

The semantic ruling is correct. Mt. Collins boot’s modeled route is BMC/IPMI, SOL, HTTP approval submission/polling, and local artifacts; granting the fleet automation SSH key would introduce authority the operation does not demand. Approval-keyring convergence does execute through fleet SSH against srv1 and therefore remains consumed. This is exactly the previously ruled D13 grain: derive demand from the reached operation and logical subject, then bind a provider, rather than manufacturing or inheriting a broad resource claim. fileciteturn1400file0L91-L109

The branch also no longer replays runner_label_resolution; that qualified-Optional repair is already on main. Structurally, that earlier repair follows the same construct-once-and-carry discipline used by the validated resolution context rather than retaining a raw value plus an external convention that it was checked. fileciteturn1400file1L35-L39

At the latest inspection, compiler, clippy, and witnesses were green; heal-generated-artifacts was still running. fileciteturn1414file0L1-L2

#11788 @ 0de1788b891cdc31f22377fc0f2df8ed6c35670a
APPROVE

No residual source finding. Ordinary merge condition: let the exact-head heal check finish green.


#11790 — APPROVE

Exact head: 6baebfcaae3a02dd3034b445d9d0b955b9bf73b8

I reviewed this now as well.

The PR is a pure deletion transaction: 11 changed files, zero additions, deleting exactly the 11 transition admissions named in the submitted batch-floor receipt. fileciteturn1405file0L8-L16 fileciteturn1405file0L32-L35

The deleted rows have the required consumed-transition shape:

disposition: TargetChanged
deletion_follow_up: NotAuthored
owner_pull_request: 11529 or 11484

The patch contains precisely:

No replacement row is owed. Their TargetChanged transition has already been consumed by the landed target binding; retaining the admission after that point is the stale state the floor is reporting.

The deletion does not sweep the directory. The exact head still contains the other six transition-admission files, so unrelated, unconsumed rows remain enrolled. fileciteturn1408file0L1-L6

The repository search is also consistent with the stated discovery model: before deletion, the namespace search returned 17 occurrences corresponding to the 17 row modules, rather than showing a second explicit import roster; after deleting 11, six files remain. That supports the claim that the directory walk—not hand imports—is the enrollment authority. fileciteturn1410file0L1-L6

The PR-path checks cannot execute the main-only namespace-wave-admission phase under the current build-only gate, so the definitive confirming receipt remains the next batch floor on main. That does not block this source deletion: the patch is exactly the remedy named by the prior floor result and introduces no semantic replacement.

At the latest inspection, compiler, clippy, and witnesses were green; heal was still running. fileciteturn1413file0L1-L2

#11790 @ 6baebfcaae3a02dd3034b445d9d0b955b9bf73b8
APPROVE

No blocking source finding. Ordinary merge condition: exact-head heal must complete successfully.

…longer names mtcollins1_boot

Projection of the corrected fleet_converge_mode_fleet_ssh_key_demand arm via generated_artifact_gate main_wet_one (single artifact). One line changes: the key step's if: drops github.event.inputs.mode == 'mtcollins1_boot'. Review 68878 found the branch's projection still granting the key to the mode the .dag says does not consume it; heal on the PR path repairs only floor-declared drift and declared none.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 20, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 20, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 20, 2026
Merged via the queue into main with commit cdb6079 Sep 20, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the fierce-seal-607/mtcollins1-boot-no-fleet-ssh branch September 20, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants