Repository navigation
MtCollins1Boot does not consume the fleet SSH key: its route is BMC/IPMI, SOL and HTTP, so the arm is derived from the operation - #11788
Conversation
…PMI, SOL and HTTP, so the arm is derived from the operation, not defaulted Side-chat review of 2faa5f3 traced mtcollins1_boot: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts -- no fleet-SSH context, target or exec. A mode added after the declaration has no prior key standing to "keep"; marking it Consumed would materialize a privileged credential its operation graph does not demand. The declaration comment now says which three modes are NotConsumed and why a new mode's arm is derived rather than defaulted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fierce-seal-607: #11776 (374d0ce) already adds both arms on main, and #11788 corrects MtCollins1Boot to FleetSshKeyNotConsumed -- its route is BMC/IPMI/SOL plus HTTP and opens no fleet-SSH op. Keeping my FleetSshKeyConsumed arm would both conflict with that PR and carry the wrong value, so the repair comes from main rather than from this branch. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md namespace_wave_admission_wall_removed Heal-Candidate-Run: 35486168956
|
Side-chat exact-head reviews (relayed by fierce-seal-607). #11788 — APPROVEExact head: This is now the correction-only successor requested in the prior HOLD:
The semantic ruling is correct. Mt. Collins boot’s modeled route is BMC/IPMI, SOL, HTTP approval submission/polling, and local artifacts; granting the fleet automation SSH key would introduce authority the operation does not demand. Approval-keyring convergence does execute through fleet SSH against srv1 and therefore remains consumed. This is exactly the previously ruled D13 grain: derive demand from the reached operation and logical subject, then bind a provider, rather than manufacturing or inheriting a broad resource claim. fileciteturn1400file0L91-L109 The branch also no longer replays At the latest inspection, compiler, clippy, and witnesses were green; No residual source finding. Ordinary merge condition: let the exact-head heal check finish green. #11790 — APPROVEExact head: I reviewed this now as well. The PR is a pure deletion transaction: 11 changed files, zero additions, deleting exactly the 11 transition admissions named in the submitted batch-floor receipt. fileciteturn1405file0L8-L16 fileciteturn1405file0L32-L35 The deleted rows have the required consumed-transition shape: The patch contains precisely:
No replacement row is owed. Their The deletion does not sweep the directory. The exact head still contains the other six transition-admission files, so unrelated, unconsumed rows remain enrolled. fileciteturn1408file0L1-L6 The repository search is also consistent with the stated discovery model: before deletion, the namespace search returned 17 occurrences corresponding to the 17 row modules, rather than showing a second explicit import roster; after deleting 11, six files remain. That supports the claim that the directory walk—not hand imports—is the enrollment authority. fileciteturn1410file0L1-L6 The PR-path checks cannot execute the main-only At the latest inspection, compiler, clippy, and witnesses were green; heal was still running. fileciteturn1413file0L1-L2 No blocking source finding. Ordinary merge condition: exact-head heal must complete successfully. |
…lins1-boot-no-fleet-ssh
…longer names mtcollins1_boot Projection of the corrected fleet_converge_mode_fleet_ssh_key_demand arm via generated_artifact_gate main_wet_one (single artifact). One line changes: the key step's if: drops github.event.inputs.mode == 'mtcollins1_boot'. Review 68878 found the branch's projection still granting the key to the mode the .dag says does not consume it; heal on the PR path repairs only floor-declared drift and declared none. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
What
Follow-up to #11776, which landed
MtCollins1Boot => FleetSshKeyConsumedby status-quo reasoning ("every other mode keeps the key it held"). The side-chat exact-head review traced themtcollins1_bootroute: BMC credential, IPMI/SOL, HTTP approval submission and polling, local artifacts — no fleet-SSH context, target, or exec. A mode added after the declaration has no prior key standing to keep, so its arm is derived from its operation route; marking itConsumedwould materialize a privileged credential (fleet automation private key + SSH agent) that the operation graph does not demand.MtCollins1Boot => FleetSshKeyNotConsumed.ApprovalKeyringConvergestaysConsumed(it executestyped_argv_exec_over_fleet_sshagainst srv1).NotConsumedmodes and states the derivation rule for modes added after it.This is D13's grain (derive demand from the operation and subject; never reproduce an assumed broad-resource convention) applied to an SSH key. Review that established it: #11776 (comment).
Evidence
Match remains exhaustive (25 arms);
healon this PR is the executing check for the generated key step.🤖 Generated with Claude Code
Carried onto current main from #11787 (whose branch predated the squash of #11776 and went DIRTY); source identical to 14417ca, side-chat APPROVE at #11787 (comment).