Repository navigation
mtcollins1_boot: narrow the fleet-key demand, or establish it cannot be - #11828
Conversation
… and reproject the key step MtCollins1Boot => FleetSshKeyNotConsumed in gunbc.fleet_converge_workflow fleet_converge_mode_fleet_ssh_key_demand, with the regenerated .github/workflows/fleet-converge.yml carrying the reprojected key-step `if:` in the same commit. #11777 gave this mode FleetSshKeyConsumed as the STATUS QUO under repair pressure, not as a finding that it needs the key. This is the walk that settles it. THE COUNTER-ARGUMENT, ANSWERED. SOL is a host session, so the mode plainly touches a machine; the question is whether it resolves the FLEET KEY to do so. Every transport reached from mtcollins1_boot_wet, enumerated from the REACHED SYMBOLS rather than the module import closure (which is a superset and does contain ssh-reaching modules this entry never calls into), with the credential each presents: Filesystem.Read/Write/WriteOwnerOnly/WriteCreateNew/Delete local, none http.Client.GetLocalhostBounded, PostJsonFromFile loopback, approval submission MAC key megarac.Media.{OpenSession,GetRemoteConfigurations, GetRemoteImages,StartMedia,CloseSession, ProbeSessionOnMediaRoute} HTTPS to BMC, pinned BMC credential file ipmi.Tool.{ChassisBootDevWithOptions,ChassisBootParamGet, ChassisPowerControl,SolDeactivate}, sol_hold.ActivateHeld ipmitool -I lanplus to BMC, same credential via -f shell.Env.Get, sleep.Delay.Seconds, Clock.Now none The SOL session is carried by IPMI to the BMC, not by an ssh channel to the host, so it presents the BMC credential and never an identity from the agent. No reached symbol resolves fleet_ssh_locus, constructs an SshTarget, or calls typed_argv_exec over fleet SSH, on the first attempt or on any retry or fallback arm; gunbc.remote_shell_command, gunbc.fleet_ssh_access and gunbc.fleet_reach are outside the reached set entirely. The two imports that could suggest otherwise take one inert symbol each -- host_reset_bmc_credential_path_env (an env-var NAME) and operator_host_srv1 (a host record). The ungated steps of the fleet-converge job (checkout, artifact download, unpack+verify, WIF auth, agent teardown) open no ssh session either. WHAT LANDS: for a mtcollins1_boot dispatch the pinned fleet key version is no longer fetched, no 0600 key file is written under RUNNER_TEMP, and no ssh-agent is loaded. ApprovalKeyringConverge is untouched and stays Consumed -- it really does reach typed_argv_exec_over_fleet_ssh against srv1. EXECUTED (not a CI check): claim_batch mtcollins1_boot_does_not_materialize_the_fleet_key -> PASS the same claim with the arm flipped back to FleetSshKeyConsumed -> FAIL (the discriminating red; the control assertion that 'approval_keyring_converge' is still PRESENT in the same string keeps the negative from being satisfiable by an empty condition) claim_batch api_only_org_modes_do_not_materialize_the_fleet_key -> PASS tools.generated_artifact_gate main -> exit 0 (committed artifacts agree) tools.generated_artifact_gate main_wet -> wrote every registry artifact; the only resulting diff is the one key-step `if:` line NOT executed: a wet run of the mode. That is the acceptance evidence the brief names and it needs an operator dispatch of fleet-converge mode=mtcollins1_boot at this head. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/fleet/fleet_converge_workflow.dag
|
Merged
What remains — and the reason I did not just close this:
Re-ran after the merge: The outstanding acceptance evidence is unchanged and is now against main, not against this PR: a wet dispatch of — sent from witty-swift-173 |
|
On review 69061's non-blocking note — it is correct, and I want to state the gap precisely rather than paper over it. What the witness establishes: that the arm is What only the annotation asserts: that Why I am not closing it in this PR. The missing capability is a reachability lens over the So: the next-rung trigger for this class is a service-operation reachability lens over an entry's closure, and until it exists the closure fact is a walked argument recorded in the quarantine channel where §4c puts it, with the arm's consumption held at rung 2 by the witness. I would rather say that plainly than let the annotation read as proof. — sent from witty-swift-173 |
# Conflicts: # dag/test/claim/machine_intake/mtcollins1_boot_run_witness_test.dag
Auto-opened by session-dashboard for session
witty-swift-173.Pushing to
session/witty-swift-173advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan