Skip to content

9/19 - #11892

Closed
briansrls wants to merge 21 commits into
mainfrom
sharp-ant-fix
Closed

9/19#11892
briansrls wants to merge 21 commits into
mainfrom
sharp-ant-fix

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session still-owl-744.
Pushing to sharp-ant-fix advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 21 commits September 19, 2026 15:17
… purpose

gunbc.cloudflare.r2_bucket_ensure observes, per allocated BucketPurpose, the bucket
through cloudflare.R2Buckets.Get (extdeps.cloudflare.r2), classifies with
std.upsert_decision, creates an established-absent default-jurisdiction bucket and
reads it back with a second Get. An unentitled account (403/10042) refuses with the
dashboard checkout step: Cloudflare publishes no API route to an R2 subscription
(cited readings). Wired as fleet-converge mode r2_bucket_ensure; witness
test.claim.cloudflare_r2_bucket_ensure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… on std.upsert_decision

Operator ruling (option B): the bootstrap token is not widened. A third mint profile,
R2AccountBucketAdmin, mints an account-scoped token holding only the observed
Workers R2 Storage Write group into its own custody container
(cloudflare-r2-bucket-admin-token, three IAM cells in r2_mint_secret_access);
r2_bucket_ensure signs with it and refuses naming run_bucket_admin until it is pinned.
The R2 buckets service moves to extdeps.cloudflare.r2_buckets so its cloudflare.*
service namespace no longer shadows the vendor value in modules importing r2.

Review 68490: upsert_decision_label is generic over the plan and ObservationVerdict
gains its one wire spelling on the sum; the roster witness drops the transcribed count.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…n mint

observe_r2_mint_custody_container now creates an absent container (automatic
replication) as the running identity before any Cloudflare effect; an identity
without the project-level secretmanager.secrets.create (the fleet SA) refuses naming
that permission, and an ambiguous create is not retried (operator direction).

Executed live 2026-09-19: run_bucket_admin created cloudflare-r2-bucket-admin-token,
minted token 6f287fde…, stored v1 (verified); pinned in r2_origin. ensure then
nooped the durable origin and created the absent boot-origin bucket with converged
readback; a second run nooped both. Frontier rows for admit_r2_bucket_admin_api_mint
and r2_account_resource_name retire on that execution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… 68550)

observe_r2_mint_custody_container -> ensure_r2_mint_custody_container,
ObserveCustodyContainer -> EnsureCustodyContainer, R2MintCustodyContainerUnobserved ->
R2MintCustodyContainerNotEnsured, and the refusal texts with them: the step now creates
an absent container, so the observation names were a meaning fork (DESIGN 3).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…iew 68589)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…pile)

main #11736 made fleet_converge_mode_fleet_ssh_key_demand exhaustive over the mode
sum; the merge that added R2BucketEnsure and R2BucketAdminMint left them without an
arm, so the corpus did not resolve and no regeneration of fleet-converge.yml could
succeed -- which is why heal-generated-artifacts failed rather than repairing it.
Both reach api.cloudflare.com and secretmanager.googleapis.com over HTTPS as the
run's own federated identity and open no host session, so neither consumes the key.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The merge kept our side of the hunk carrying fleet_converge_mode_fleet_ssh_key_demand,
which lost main's ApprovalKeyringConverge and MtCollins1Boot arms, so the match stayed
non-exhaustive after 854e773 fixed the other half. Both are restored with main's own
classification (FleetSshKeyConsumed). Swept every mode in the sum against main's copy:
per-mode occurrence counts now agree, and each of the four R2 modes appears in the same
six constructs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The main merge took the ours side of this generated file, dropping the
r2_bucket_ensure and r2_bucket_admin_mint modes the model at this head declares.
Regenerated through gunbc.instruments.generated_artifact_gate main_wet_one on a
host with the admitted memory budget (session containers and BuildBuddy runners
both refuse it), not hand-edited.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…on/sharp-ant-20

# Conflicts:
#	.github/workflows/fleet-converge.yml
parse_r2_jurisdiction re-spelled the five wire tokens r2_jurisdiction_wire already
owns, so a corrected spelling in one would have left the other silently
unrecognising. It now folds over r2_jurisdictions() and compares through
r2_jurisdiction_wire -- one grammar read backward (DESIGN 4) -- and lives beside the
table it inverts in extdeps.cloudflare.r2 rather than in the operation module.
No declared-fork row is needed because the fork is gone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
… merge

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Duplicate: local working branch for the #11721 conflict resolution, auto-pushed by the session. Its commits are on #11721. — sent from still-owl-744

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
@gunbai-bot
gunbai-bot Bot deleted the sharp-ant-fix branch September 20, 2026 18:40
@briansrls
briansrls restored the sharp-ant-fix branch September 20, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant