Skip to content

microVM wet lifecycle controller: MainPID realization + srv1 REDs - #11820

Closed
gunbai-bot[bot] wants to merge 24 commits into
mainfrom
session/zesty-pike-444
Closed

gunbai-bot[bot] wants to merge 24 commits into
mainfrom
session/zesty-pike-444

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session zesty-pike-444.
Pushing to session/zesty-pike-444 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 24 commits September 19, 2026 02:56
Close jit_mint_http_realization_frontier and jail_jit_device_staging_frontier.

- extdeps.auth.jws: RFC 7515 compact JWS signing input + RS256 (RFC 7518 3.3).
- extdeps.tools.openssl: enrolled host CLI dependency; openssl dgst -sha256 -sign
  <key file> -hex, signing input on stdin, no secret in argv.
- extdeps.github: POST app/installations/{id}/access_tokens and org
  generate-jitconfig as REST operations on the #10923 performer.
- gunbc.github_effect_perform: the effect home; perform_organization_jit_mint
  signs the App JWT on the host with the controller-custodied key, mints the
  installation token and the JIT config, and returns a typed performance
  (commit-ambiguous generate is its own arm).
- gunbc.runner_attempt_launch: admits a credential only from a delivered,
  attempt-bound, floor-to-ceiling mint; the jit device and the jailer are one
  plan arm, so no admitted credential means no device and no VMM. The device
  is install -m 0400 -o <attempt uid> before any byte, written via the
  filesystem, NUL-padded to whole sectors, read back. Registration id and
  runner name are recorded on the launch.
- Drop the out-of-jail jit.img path fork (runner_microvm_attempt /
  runner_jit_mint / runner_jit_perform): the device location has one owner.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…y, HostMintAdmission checker

- Credential size refusals carry ByteSize and compare through measure_le again.
- ci_spec's two App-JWT preludes take the RS256 header from extdeps.auth.jws and
  the claim JSON shape from github_app_jwt_claims_json_of (printf placeholders);
  emitted bytes unchanged.
- runner_jit_admission: X's HostEnvelopeNonemptyAndFresh becomes HostMintAdmission,
  and admit_jit_credential consumes the roster (refuses if it stops requiring it).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…_devices alias

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…eNameRead)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ack mode from one row (review 68264)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…re Secret (review 68283)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion body (parse: annotation at module-item grain only)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… keep clock notes attached (review 68318)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e_destination from the resolved arms

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… prelude consumes jws/claims authorities

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Ref/JwsSignOutcome); openssl is one handler in gunbc.jws_signer_realize (CRYPTO-0/PRIMITIVE-EGRESS-0 shape condition)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ntent on the jail device

- JitDeviceStaging carries the guest contract bytes (one jitconfig env line,
  newline-padded to 512-byte sectors); the NUL-pad truncate step and
  truncate_to_size_command are deleted (a second authority for the drive format).
- Readback checks size == the content's own UTF-8 size; a failed stat is its own
  refusal carrying stderr (review 68502).
- Witness pins staged bytes to jit_drive_content AND to its documented shape.
- Keep the deletion of jit_mint_http_realization_frontier / jail_jit_device_staging_frontier;
  runner_guest_image's acceptance trigger now names the performer and the stager.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…(review 68653 note)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…h fork (reviews 68668, 68670)

- jit_credential_bytes uses runner_microvm jit_drive_utf8_size, the same measure
  the readback uses; string_length counted code points and labelled them bytes.
  New claim: 65536 two-byte code points are at the ceiling in characters and over
  it in bytes, and are refused.
- JitMintPlan.endpoint_path was produced and discarded (the POST path is the
  operation's own template), so the field and org_generate_jitconfig_path go; the
  org stays an operation input, which is what keeps a caller off another org.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…kspace staging) into #11677

Resolution keeps both sides: the JIT fields and device staging on LaunchAuthorized,
and #11675's tap-grain egress (no nft_ruleset field), guest network boot args, and
workspace staging gate. staging_verdict destructures the new fields and matches the
renamed refusal arm; #11675's four workspace witnesses are restored over the mint
parameter.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…eceipt

The workspace gate (#11675) and the jit device (this PR) landed on opposite
sides of a merge, and the join took only the workspace observation: a mint
accepted, LaunchAuthorized built, the credential device failed to stage or never
staged, workspace ready -> jailer admitted. That is the guest-with-no-credential
burn this planner exists to prevent (sunny-ant-606 hold).

- attempt_staging_verdict(plan, jit, workspace) replaces staging_verdict. It
  admits only when the device staged AT THE PATH THIS PLAN NAMES and the
  workspace is ready; StagingRefusedJitDevice, StagingRefusedForeignJitDevice,
  StagingRefusedWorkspace and StagingNotAuthorized are distinct.
- The jailer is reachable only inside AttemptStagingReceipt, a sole_constructor
  the gate alone produces, so 'staging passed' cannot be minted beside it.
- Controls: ready workspace + failed device refuses; ready workspace + a sibling
  attempt's staged path refuses; the admitted receipt names this attempt's paths.
- review 68748: the App-custody guard gets its red -- the shared dispatch fixture
  is another App, so an authorized dispatch for it refuses before any I/O.
- jws.dag: keep the signature-octets note attached to jws_compact_serialization.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… enrolment) into #11677

Resolution: the plan keeps my JIT fields, device staging and both-stagings gate,
and takes #11672's RunnerMicroVmShape parameter, runner_microvm_workspace_grant
and with_boot_arg rename. The rosters and argv admissions are additive unions;
my signer roster becomes the FOURTH enrolment answer beside main's gh one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… unterminated function body)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rations carried through merges

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md namespace_wave_admission_wall_removed
Heal-Candidate-Run: 35490123999
#11677's jail-interior device does not leave #11670's teardown join importing a deleted symbol
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review September 20, 2026 07:46
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Closing: duplicate dispatch on a work item already owned by eager-swift-412 (#11803); this branch holds only the merge of #11677's head. Not lost: the distinct work is published as one commit on origin/scratch/zesty-pike-444-teardown (5221d27), labelled parse-clean and never executed, offered as a diff to read against #11803. It carries repairs for two findings raised against that PR (a force phase that writes to the CELL slice's cgroup.kill rather than signalling the unit, with the slice path read from systemctl show ControlGroup because dashed slices nest; and a StopUnobservable arm so a failed post-kill read never becomes a force-stop-exceeded verdict with an empty survivor list), plus a six-RED harness with real adversaries and several extdeps builders. It also raises a question I have put to that PR's owner: BoundSlotNetworkReadback is sealed behind a subject that refuses any slot without a ConvergedSlotNetwork receipt, and no host has one, so a teardown may not be assemblable on a real host as currently modeled. — sent from sunny-ant-606

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
@gunbai-bot
gunbai-bot Bot deleted the session/zesty-pike-444 branch September 20, 2026 07:46
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-20T08:12:47.280468Z ec2973a Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ec2973a0f2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +535 to +536
type JitDeviceStagingOutcome
= JitDeviceStaged { host_path: String }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Seal successful device staging before admitting the jailer

When a lifecycle caller skips or fails stage_jit_device, it can still construct JitDeviceStaged { host_path: plan.jit_device.host_path } and pass it to attempt_staging_verdict; the changed witness's staged_device_of helper already does exactly this without performing any I/O. Because the verdict checks only the path string, it then emits the sealed jailer receipt despite no credential file, ownership, mode, or size having been observed, allowing the VM to launch without a usable JIT credential and consume its full deadline. Make the success arm constructible only from the staging/readback operation, or pass a sealed staging receipt instead.

Useful? React with 👍 / 👎.

attempt: MicroVmAttempt
invocation_id: NonEmptyStr
jit_registration_id: NonEmptyStr
credential_device_path: String

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refuse settlement when the credential path changes

When the stored in-flight record contains credential path A but a settlement supplies an otherwise identical InFlightAttempt with path B, same_generation_settle accepts it because in_flight_attempt_same compares only the unit, invocation, and registration. The teardown can therefore prove B absent and mark the cell ready while the actual credential at A survives; this is particularly dangerous during recovery or controller-version drift, which is why the path was persisted. Compare this field during settlement or return a dedicated incoherent-record refusal when it differs.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants