Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
011c076
Cut D D0 transaction on the re-rooted main (second rewrite): the whol…
Sep 20, 2026
044d80a
Merge remote-tracking branch 'origin/main' into plan/dsv41-cut-d-2b
Sep 20, 2026
8523c9e
Hoist three body-scope annotations main carries to module grain (floo…
Sep 20, 2026
a1256be
Drop the 24 transition-admission row files: the namespace-wave-admiss…
Sep 20, 2026
9617468
Keep main's transition-admission rows as main has them
Sep 20, 2026
ecdab91
Merge remote-tracking branch 'origin/main' into plan/dsv41-cut-d-2b
Sep 20, 2026
dbc27b9
Hoist the body-scope annotations main's #11731 and #11765 left in hos…
Sep 20, 2026
d62c1e1
Hoist the body-scope annotation in mtcollins1_census_image_local_wet_…
Sep 20, 2026
956baf4
floor_route_gap: join the split `tail:` / `Cons {` lines main's #1173…
Sep 20, 2026
e3af06b
chore: regenerate drifted generated artifacts (ci auto-heal)
gunbai-bot[bot] Sep 20, 2026
62c9274
D0 rework 22 (review 69399): a live worker rank makes the occupancy n…
Sep 20, 2026
c724b9f
Merge remote-tracking branch 'origin/main' into plan/dsv41-cut-d-2b
Sep 20, 2026
6059815
Merge remote-tracking branch 'origin/plan/dsv41-cut-d-2b' into plan/d…
Sep 20, 2026
b545d05
Merge remote-tracking branch 'origin/main' into plan/dsv41-cut-d-2b
Sep 21, 2026
6e3d64b
Cut 0 (two of three axes): the V4.1 weight manifest (48 shard sha256s…
Sep 21, 2026
4182749
Merge remote-tracking branch 'origin/main' into plan/dsv41-cut-0
Sep 21, 2026
12f0e55
Cut 0 + the D0 authorization producer: one DeepseekV41PublishedFile r…
Sep 21, 2026
ffe688b
Cut 0 + D0 door rework: the filing is frozen on the fabric log before…
Sep 21, 2026
01f93a2
Cut 0 + D0 door, round 3: the admitted index file is a row in the wei…
Sep 21, 2026
3401f4b
Cut 0 + D0 door, round 4: the gate's refusals have their own carrier …
Sep 21, 2026
0c0c736
Cut 0 + D0 door, round 5: a pending filing expires by the window the …
Sep 21, 2026
74b5937
Merge origin/main into plan/dsv41-cut-0 (census stage 0D medium readb…
Sep 21, 2026
95a3a4a
Cut 0 + D0 door, round 6: the poll's expiry boundary is the capabilit…
Sep 21, 2026
c475d44
D0 door: the claim-absent rerun branch matched the read's retired car…
Sep 21, 2026
62183e9
D0 door: the claim-absent step is pure (d0_absent_claim_step over the…
Sep 21, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
360 changes: 360 additions & 0 deletions dag/extdeps/deepseek/deepseek_v4_1_flash.dag

Large diffs are not rendered by default.

286 changes: 286 additions & 0 deletions dag/gunbc/auth/approval_gate.dag

Large diffs are not rendered by default.

37 changes: 18 additions & 19 deletions dag/gunbc/auth/approval_request_client.dag
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ import extdeps.crypto.mac {
import gunbc.auth.approval_status_wire {
FiledApprovalStatus, StatusNotFiled, StatusPending, StatusApproved, StatusDenied, StatusUnreadable,
}
import gunbc.auth.approval_capability { utc_instant_before }
import gunbc.auth.approval_decision_store {
StoredApprovalRequest, request_revision_of, approval_mac_key_id,
}
Expand Down Expand Up @@ -90,29 +91,27 @@ type ApprovalPollStanding
| PollNotFiled
| PollUnreadable { detail: NonEmptyStr }

// THE BOUNDARY IS THE CAPABILITY'S: expires_at is the instant a request STOPS being decidable
// (gunbc.auth.approval_capability admits only observed_at < expires_at), so equality is expired
// here too -- a client that still called the operator's request pending at the very second the
// broker can no longer redeem the capability would wait for a decision that cannot land.
// THE FILED REQUEST'S OWN WINDOW GOVERNS A PENDING STANDING. A pending status carries the
// expires_at the broker filed (the one the operator was shown); the caller's expires_at is the
// window it would file under and governs only a request that is NOT filed. A rerun that computes
// a fresh window may therefore not extend a pending filing past what was filed, and a decision is
// a decision whenever it is read.
fn approval_poll_standing(
status: FiledApprovalStatus,
observed_at: Timestamp,
expires_at: Timestamp,
) -> ApprovalPollStanding {
if observed_at > expires_at {
match status {
StatusApproved { revision: r, decided_by: by, decided_at: at, execute_by: until } =>
PollApproved { revision: r, decided_by: by, decided_at: at, execute_by: until }
StatusDenied { revision: r, decided_by: by, decided_at: at, reason: why } =>
PollDenied { revision: r, decided_by: by, decided_at: at, reason: why }
StatusUnreadable { detail: d } => PollUnreadable { detail: d }
_ => PollExpired
}
} else {
match status {
StatusNotFiled => PollNotFiled
StatusPending { expires_at: _ } => PollStillPending
StatusApproved { revision: r, decided_by: by, decided_at: at, execute_by: until } =>
PollApproved { revision: r, decided_by: by, decided_at: at, execute_by: until }
StatusDenied { revision: r, decided_by: by, decided_at: at, reason: why } =>
PollDenied { revision: r, decided_by: by, decided_at: at, reason: why }
StatusUnreadable { detail: d } => PollUnreadable { detail: d }
}
match status {
StatusApproved { revision: r, decided_by: by, decided_at: at, execute_by: until } =>
PollApproved { revision: r, decided_by: by, decided_at: at, execute_by: until }
StatusDenied { revision: r, decided_by: by, decided_at: at, reason: why } =>
PollDenied { revision: r, decided_by: by, decided_at: at, reason: why }
StatusUnreadable { detail: d } => PollUnreadable { detail: d }
StatusPending { expires_at: filed } => if utc_instant_before(a: observed_at, b: filed) { PollStillPending } else { PollExpired }
StatusNotFiled => if utc_instant_before(a: observed_at, b: expires_at) { PollNotFiled } else { PollExpired }
}
}
71 changes: 6 additions & 65 deletions dag/gunbc/machine_intake/mtcollins1_boot_authorization.dag
Original file line number Diff line number Diff line change
@@ -1,27 +1,13 @@
module gunbc.machine_intake_mtcollins1_boot_authorization

import std.types { Bool, List, NonEmptyStr, String, Timestamp }
import std.types { Bool, List, NonEmptyStr, String }
import std.content_hash { ContentHash, content_hash_of_value }
import std.effect_grant { NamespacePosition, ServiceOpTree, Write }
import std.scoped_authorization {
AuthorizedAction,
AttemptIdentity,
AuthorizationScope,
AuthorizationRequest,
ScopedAuthorization,
AuthorizationGranted,
AuthorizationDenied,
authorize,
AuthorizationPermitted,
AuthorizationRefused,
}
import gunbc.auth.approval_decision_store {
grant_from_approved_decision, GrantDerived, GrantForAnotherIntent,
request_revision_of,
}
import gunbc.auth.approval_request_client {
ApprovalPollStanding, PollApproved, PollDenied, PollExpired, PollStillPending,
PollNotFiled, PollUnreadable,
}
import gunbc.machine_intake_mtcollins1_boot_artifact { mtcollins1_diskless_image_name, mtcollins1_boot_export_dir }
import gunbc.machine_intake_mtcollins1_boot_image_fetch { mtcollins1_boot_image_sha256 }
Expand Down Expand Up @@ -199,54 +185,9 @@ fn mtcollins1_boot_authorization_request(
}
}

type MtCollins1BootGate
= BootGateAdmitted { authorization: ScopedAuthorization<MtCollins1BootSubject> }
| BootGatePending { escalation_id: NonEmptyStr }
| BootGateDenied { reason: NonEmptyStr }
| BootGateExpired
| BootGateNotFiled { escalation_id: NonEmptyStr }
| BootGateIntentMismatch { requested_revision: NonEmptyStr, decided_revision: NonEmptyStr }
| BootGateStoreUnreadable { detail: NonEmptyStr }
| BootGateAuthorizeRefused { detail: NonEmptyStr }

fn mtcollins1_boot_gate_from_poll(
poll: ApprovalPollStanding,
request: AuthorizationRequest<MtCollins1BootSubject>,
observed_at: Timestamp,
) -> MtCollins1BootGate {
match poll {
PollStillPending => BootGatePending { escalation_id: request.escalation_id }
PollNotFiled => BootGateNotFiled { escalation_id: request.escalation_id }
PollExpired => BootGateExpired
PollUnreadable { detail: d } => BootGateStoreUnreadable { detail: d }
PollDenied { revision: r, decided_by: _, decided_at: _, reason: why } =>
if r != request_revision_of(request: request) {
BootGateIntentMismatch {
requested_revision: request_revision_of(request: request),
decided_revision: r,
}
} else {
BootGateDenied { reason: why }
}
PollApproved { revision: r, decided_by: by, decided_at: at, execute_by: until } =>
match grant_from_approved_decision(
request: request,
revision: r,
decided_by: by,
decided_at: at,
execute_by: until,
) {
GrantForAnotherIntent { requested_revision: a, decided_revision: b } =>
BootGateIntentMismatch { requested_revision: a, decided_revision: b }
GrantDerived { authorization: auth } =>
match authorize(authorization: auth, request: request, observed_at: observed_at) {
AuthorizationPermitted { grant: _ } => BootGateAdmitted { authorization: auth }
AuthorizationRefused { cause: _ } =>
BootGateAuthorizeRefused { detail: "scoped authorization refused the HTTP grant for this request" as NonEmptyStr }
}
_ =>
BootGateStoreUnreadable { detail: "approved GET standing did not yield a grant" as NonEmptyStr }
}
}
}
// THE GATE IS THE SHARED ONE. The operator's decision over this subject is read through
// gunbc.auth.approval_gate, generic over the subject: ApprovalGate<MtCollins1BootSubject> and
// approval_gate_from_poll, admitted live at the observed instant. Nothing about the gate is a fact
// about Mt. Collins, so nothing about it is declared here.


Loading