diff --git a/dag/gunbc/roadmap/roadmap_authority.dag b/dag/gunbc/roadmap/roadmap_authority.dag index 77220464627..9299852bbdc 100644 --- a/dag/gunbc/roadmap/roadmap_authority.dag +++ b/dag/gunbc/roadmap/roadmap_authority.dag @@ -2304,7 +2304,7 @@ fn declared_roadmap_nodes() -> List { id: "fleet-mtcollins1-first-host", owner: "fleet", path: "dag/gunbc/machine_intake/mtcollins1_expansion_observation.dag", - t: fields( + t: updated(t: fields( headline: "Bring Mt. Collins unit 1 into service as our first owned host, from observation rather than assumption", boundary: "Every fact the unit's intake depends on is either bound to a git-tracked observation consumed at mint time, or stays in its typed unobserved arm and refuses. The remaining facts: OCP bay occupancy and riser fitment observed from the unit interior; the bring-up evidence captures bound onto an executing consumer rather than stored beside it; one PCI identity authority with its superseded namespace admissions deleted; pre-OS assessment derived from SEL and captured inventory with its absence and indexed-replay controls executed; live pre-OS acquisition; supervision-to-envelope realization; PCI address cross-rendering equivalence between firmware and kernel renderings; and one meaning for AttachmentVerdict, since mtcollins1_expansion_attachment attachment_against_evidence discards the OCP standing (ocp: _) and so admits installability on the PCIe path but only interface compatibility on the OCP path (either match the OCP standing before the generation comparison with typed occupied and unobserved refusals, or split the verdict). Zero offers, over-reports and populated bays refuse rather than answer.", displaced_cost: "Hardware bought against an assumed slot, riser or bay costs a returned part and a lost week; a credential believed rotated but readable on another controller address is a silent exposure.", @@ -2312,7 +2312,7 @@ fn declared_roadmap_nodes() -> List { red_control: "An unobserved OCP variant, an unfitted riser, a populated bay, or a credential rotation evidenced on a single controller address refuses rather than reporting an attachment point or a secured controller.", out_of_scope: "Not fleet-wide firmware or cooling policy (fleet-bmc-policy-convergence) and not classification of what we manage on machines generally (fleet-state-frontier).", handback: "Each fact above is bound to a consumed artifact or refusing in its unobserved arm, and the unit mints a BmcSecureStanding." - ) + ), on: "2026-09-20", note: "WIND-DOWN POSITION 2026-09-20 (operator: all lanes winding down to prioritize v1 performance and v2 migration; recorded here so the program resumes from the record). DONE, on main: the approval-gated boot pipeline (#11483 C, #11484 D, #11768 follow-up) -- operator taps APPROVE on the phone, the run redeems the capability, mints the BMC credential, attaches the ISO over MegaRAC, power-cycles, holds SOL; boot 22 (run 35447067113) booted Ubuntu 24.04.3 on the unit through that path. MegaRAC facts modeled: GET /api/session is not served (404 with a live cookie), release is a present->absent re-observation on the remote-media route, 401/403 after a succeeding probe is absence, sentinel-CSRF refuses. HW1-QUAL landed (#11722): the runner-throughput qualification consumes a selected sanction/offer, seals its run record, joins the subject first; its boot/image/registration/dispatch legs are declared frontiers awaiting authority. PXE 0A-0D landed (#11602 #11603 #11607 #11605) fail-closed: nothing PXE-boots until an iPXE snponly.efi is built at a recorded revision and pinned as SitePxeEdgeChainloaderBuildReceipt on srv4; do not soften the gate. Mt. Jade class facts landed (#11529). REMAINING, in order: (1) boot 23 = the EDAC-pass/nproc-160 census run, blocked on the census ISO (#11731; the side-chat hold 5260468481's three walls -- workload pass-status + full chunk coverage, one bounded same-run envelope, and the claim renamed a compatible replacement producer bound to attempt 3's bytes via HistoricalCaptureIdentity + a 19-stage HistoricalStageDisposition map -- are built as of 2026-09-20; awaiting the exact-head read and merge; publish to srv2 stays a declared frontier, nothing written to hosts). (2) rewire mtcollins1_boot_run's capture parser onto gunbc.machine_intake_host_capture_envelope -- its substring workload match is a FALSE GREEN under the new census program; carry the verdict REDs there; bind the derived media identity (census 0D). (3) approval broker (#11667): split of the approval routes off roadmap_serve onto 127.0.0.1:8085 in its own slice; stage A dark install on srv1 NOT yet run -- dispatch shape: gh workflow run fleet-converge.yml --ref -f mode=approval_broker_dark_install -f host=srv1 -f expected_revision=; the job self-adjudicates via /livez + the tree receipt; then stages B-E and the device routes onto the broker route table. (4) approval app P-256 in .dag (#11645): the iOS app landed (#11590); one interpreted verify peaks at 13.5 GiB and 192-734 s, so the floor budget-refuses all 8 real verifications -- decision: a dedicated P-256 gunbc test row over the emitted native build (side-chat ruling 5260787321: a budget row is not evidence, the terminal verdict is). (5) PXE 0B wet half needs the boot-origin DNS zone + FQDN from the operator (bucket-create, custom domain, cache rules). (6) Mt. Jade first contact (#11758 draft, model only, its seven witnesses UNVERIFIED -- claim_batch ended with no verdict lines under memory pressure; re-run before review, command and count assertion at the top of the PR body): BMC on factory static 10.0.7.2/29 gw 10.0.7.1 + link-local 169.254.0.17, MAC 70:e2:84:95:33:6b, same L2 as srv1 (its ARP broadcasts received on enP3p3s0f1); 16 DIMMs installed; nothing has authenticated to the controller yet; remaining steps: decode a Manager response into ManagerIdentityObservation, the converge entry, the arping-no-reply witness, a wet window. (7) fan policy (#11623): product.fan_policy_standing with #11529's Jade fan concepts consolidated onto it in the same PR (mtjade1_fan_standing consumes it, fleet_acoustic_intent and fleet_fan_converge_routes); a fail-open in the chassis power parse (unreadable wording read as POWERED OFF -> FailsafeBeforeHostTelemetry) was found by review 69156 and fixed with a red control before landing. Collins measured (run 35402673990, six read-only rounds through the fleet-converge mode): posted and publishing host thermals, 16 system fans flat at 5552-5802 RPM, 34 fan sensors all RPM and zero duty sensors, so every sample is RpmWithoutDutyTelemetry by construction; whether the controller is commanding a curve needs PWM/duty telemetry (absent on this SDR), a documented MegaRAC fan-mode readback, or a measured duty-to-RPM curve. PSU2_FAN_SPEED read 0 RPM with status ok in all six rounds (second supply unpopulated/not drawing, or a dead tach -- a receipt, not a diagnosis). The Collins fan part is unmodeled (CatalogMaximumUnknown); duty_ceiling_for_fan / fan_policy_against_ceiling have no production consumer (declared frontier: a stated dB(A) ceiling at a named position AND a modeled fan part). (8) MachineWidth compile-time reification (#11819 parked draft; its walls are NOT yet honest: review 69187 found two merge-blocking GateBlocking refusals with no enrolled RED or positive control, and src/v1/04_resolve.dag type_arg_kind_inhabitance declares four admitting arms while the hand-patched seed v1_compiler_infer_resolve.rs carries a different algorithm -- the compiler that refuses p4 is the seed and it does not carry the .dag's logic; next step is a multi_module_compile_fixture witness with two REDs and a control, modeled on dag/test/claim/type_argument_arity_witness_test.dag). (9) approval app server routes: the six device routes (enrol, redeem, two reads, push-update) belong on gunbc.auth.approval_broker_serve as six flat handler arms with per-route markers, paths staying in gunbc.auth.approval_device_wire; blocked on the broker's stage 6. APP ATTEST HAS NO REALIZATION: extdeps.apple.app_attest mints VerifiedAttestation only through attestation_verification_from_implementation, nothing on main supplies it (the host-Rust escape-hatch PRs #11588/#11592 were closed per the operator's refusal), and enrolment_admission matches AttestationVerified -- so device enrolment REFUSES, correctly, until CBOR decode and X.509 parsing exist in .dag; that is the real distance between 'merged' and 'enrol a phone'. (10) floor coverage follow-ups: lift deferred_followup.patch from #11865's body (compiler_gate_workflow disposition-TSV upload step + the rung-drop population/trigger sentence) and regenerate witnesses.yml and docs/design-rung-drops.md; run claim_batch on the three sibling witness modules #11865 repaired without executing (fabric_control_plane, altra_memory_controller, nbd_proxy_virtual_media_install); the declared drop for required lanes not resolving product-layer modules is #11860: gunbc.rung_drop.required_lanes_do_not_resolve_product_layer_modules (LostAsPassenger of the strict preparation #11742 cut; trigger = every admitted module's source reaches compile_to_resolved on every landing revision), with its population by identity from the instrument gunbc test //gunbc/instruments:required-lane-resolution-census (at that head: admitted=6292, reached=2022, unreached=4270, list committed under docs/rung-drops/) and the two instrument failure-mode rows (exit status through a pipe; a red control positioned where it cannot fire); the restoring capability -- a required job resolving every witness root's closure -- needs the operator (job roster closed to growth); the seed defect where adding one import edge to a leaf makes gunbc.harness.harness_backend stop resolving (adhoc-3bd6c9ef-59c; route-around annotated in runner_throughput_qualification) is localized but unfixed: the entry closure is the REFERENCE-PULL closure (cli_run reference_pull_paths_for_source pulls every dotted module path in a file plus its import closure, and build_both_closure_edge_index adds bare-name providers for stripped modules), NOT the ^import BFS -- the edge adds 21 modules (claim_batch --print-entry-closure: 273 vs 294), so 'closure invariant, only edge shape differs' was false; cheapest repro on main = one unused import of gunbc.build_cache_instance in runner_throughput_qualification + entry dag/test/claim/serving/engine_progress_witness_test.dag --function an_idle_engine_is_idle_however_long_its_counter_stands_still (PASS without, the harness_backend:581/585 split/last errors with); the break is v2.std.algebra filter's element type at harness_backend:576 (a pass-through over lines makes it PASS), split/last are only the first bare template calls downstream; the closure-counted uniqueness gates (corpus_item_name_counts_nodes, symbol_index_insert_unique_disj_variant_aliases, symbol_index_track_global_bare) do not flip for any name; the live remaining candidate is schedule_batches_from_edges emitting a cycle residue batch that reconcile_with_typed_cache dispatches in slot order while typecheck_module returns None silently for a not-yet-dispatched import -- the one fail-open found. Next rung, on a quiet host: bisect the 21 modules to the minimal reddening set and check whether the schedule acquires a residue batch containing harness_backend; only then write the mechanism, the discriminating red (the Fixture harness in cli_run closure_edge_demand_tests is the right shape) and the failure-mode row. The route-around annotations on the qualification leaf and gunbc.runner_throughput_selection STAY until then. --print-entry-closure on the full 831-module entry did not finish in 52 min (the whole-pool bare-reference edge index is built lazily with no warm phase); use the 273-module harness. (12) two latent defects on main, written down by the Jade lane: the content_digest carrier fork ('sha256:' vs 'sha256 ' across 13 literals in the Collins/Jade/contract standards -- the fix is typing the field Sha256Digest), and NamespaceStep0CanaryV1HistoricalStanding, a nullary coproduct declaring no constructor that breaks the day anything imports it; also, extdeps service OPERATIONS are invisible to the frontier census (it reads only data and fn declarations), so the roster's silence on the three new BMC/iproute2/arping operations is a census gap, not coverage. (11) approval app operator-owned items, unstarted: Apple team id and bundle id, the .p8 APNs key and key id, Xcode on the MacBook, a phone as an internal TestFlight tester; then xcodegen generate, fill Config/Team.xcconfig, run ApproveTests against the committed vectors (the first execution of any Swift in this project). STANDING RULES LEARNED THIS WEEK, binding on resumption: PR CI green is NOT claim evidence for .dag -- the required lanes resolve only the generated_artifact_gate closure, product-layer modules are reached by strings not imports, and the floor is a nominal one-subject fold (#11607 reached queue position 1 not resolving); every .dag PR carries a local claim_batch receipt at exact head + binary sha + one control that goes red. fleet_converge_mode_fleet_ssh_key_demand is exhaustive by design and bit three mode-adding PRs composed; any new FleetConvergeWorkflowMode owes its arm and the regenerated fleet-converge.yml in the same head. fleet_converge_workflow_modes is a ยง2 contention surface: four independent lanes appended to it in one day, each collision costing another lane a whole-closure regen (~15 min) plus a CI cycle -- landing decision adopted: enqueue on the first head where the four lanes are green and let the queue prove the composed revision. Local .dag runs in session containers die on restarts and slice contention; BuildBuddy applies the worktree DIFF to its own checkout (not exact-head evidence), pages git diff, and hard-kills at 1h. The witness floor RUNS BUT DOES NOT GATE as of 2026-09-20: claim_executor computes FloorRefused and exits nonzero, the workflow step swallows it under set +e, and the aggregating job reads only needs.floor.result -- so no green check entails that any witness produced a verdict; and the approval-device witnesses match no required_gate_prefixes row, so the round-trip witnesses that are the only wall against the wire decoders' hand-typed allowed rosters drifting are real and unenrolled. Roadmap serve on srv1 must have belt/publication services and timers stopped for a boot window; slice 26 GiB, no swap.") ), active( identity: "rn_PEH90XVR97GYYA5FXGDJXZ70PF",