Skip to content

orphan - #11938

Closed
briansrls wants to merge 46 commits into
mainfrom
fix/11751-merge-main
Closed

orphan#11938
briansrls wants to merge 46 commits into
mainfrom
fix/11751-merge-main

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session sunny-ant-606.
Pushing to fix/11751-merge-main advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 30 commits September 19, 2026 02:32
…adback, workspace staging gate

- runner_microvm_network: tap-scoped egress rules in the forward chain (established; v6 drop;
  private/link-local/multicast denials above the grants; DNS and TCP 443; final tap drop). Chain
  policy stays accept for dockerd coexistence, so runner_host_filtered_egress DefaultDrop is honoured
  at tap grain, not host grain.
- SlotNetworkReadback (Confirmed / Refuted{fact} / Unobservable{fact}) over tap unheld, guest
  conntrack empty after flush, and nft listing digest == converged digest; plus the conntrack
  flush/list and nft list commands that produce the observations.
- runner_attempt_launch: staging_verdict gates the jailer on a read-back workspace (create exit,
  mke2fs exit, dumpe2fs superblock magic and size); every failure refuses under its own name.
- extdeps: nft daddr/dport/nfproto matches, nft list table, conntrack(8), dumpe2fs -h.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he present-tense consumption claim

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ector instead of two singleton-list folds

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…booted resolver; filtered-egress consumes the policy

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…es in their own direction

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ts through content_hash_eq_cryptographic

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nverge as its installer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…v4 authority

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d chain

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d image; denials precede every guest-side accept; tap v6 refused before conntrack

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…etwork receipt; v6 disabled on tap and guest; neighbour and expectation readbacks; helper standing over the effective host policy

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pelling on every host

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rection each v6 rule covers

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…me drop on the shared hosts

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng, then read the host back into a receipt

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…s its ssh-key demand

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…croVM network mode

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…establish

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e requested host, and persist the whole receipt

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…elper probes

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unread

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ke the receipt a parseable value, and give ip_forward and the slot probes their own unread arms

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sification

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 16 commits September 20, 2026 10:23
…bytes the converge writes

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…code the fabric lifetime sample's digests through their optionals

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… observes and records

The install+restart pair over a grantee-writable staged path was root-equivalent: the job user
stages these files and also executes job steps, so it could write its own ExecStart= and have
root run it (review 69104). The roster now carries the readbacks only, the mutating half waits on
a principal the job user cannot impersonate, and the mode is named for what it does.

Also fixes two latent defects on main that its own newly landed Optional checker refuses:
fabric_required_build_cell's lifetime-sample digests and workflow_dispatch_input's trigger index.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/extdeps/systemd/unit_file.dag
#	dag/gunbc/fabric/fabric_required_build_cell.dag
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…ncipal, not a standing fact

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he grant fold drops its unused slot roster

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rm list

My merge resolution moved the RemainAfterExit annotation above the type and left a second
two-arm header below, orphaning ~25 arms of a widely consumed coproduct (review 69165).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the workflow

Three conflicts, each resolved at the authority rather than in the bytes.

fleet_converge_workflow_modes: both sides appended. Taking either side would
have deleted the other's modes while the match arms below -- which git merged
cleanly -- still named all of them, so the roster and the arms would have
disagreed. The roster is the union at 31 modes, and the type arms, the roster
and fleet_converge_mode_scope are now checked to agree exactly.

workflow_dispatch_input_witness_test: main landed the same Optional repair
independently and its annotation is the better one, citing
witness_that_fails_to_compile_is_absent_rather_than_red rather than describing
the fix locally. Main's side taken whole; the two controls this branch added
are untouched.

fleet-converge.yml is generated, and the merge driver refused it rather than
answering with a side -- correctly, because neither side's bytes are the
projection of the merged authorities. It is regenerated from the merged
sources, not hand-edited: the result differs from BOTH parents, restoring the
seven spark_native_serving_apply occurrences this branch had dropped to zero
while keeping this branch's FLEET_CONVERGE_EXPECTED_HOST step. Re-running the
gate changes nothing, so it is at its fixed point.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ge and regenerate

Same two paths as the previous merge and the same resolution, because they are
the program's shared spine: #11765 and #11679 are sibling microVM lanes editing
fleet_converge_workflow.dag, so every lane in this program serializes on this
file and its generated projection.

Roster is the union at 32 modes -- this branch's MicrovmNetworkObserve beside
main's MicrovmControllerAppKeyConverge -- with the type arms, the roster and
fleet_converge_mode_scope checked to agree exactly. The workflow YAML is
regenerated from the merged sources and carries both.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Third merge of the same two paths in one session, same resolution: the roster
is the union at 33 modes (this branch's MicrovmNetworkObserve beside main's
AppKeyVersionVerify), with the type arms, the roster and
fleet_converge_mode_scope checked to agree exactly, and the workflow YAML
regenerated from the merged sources rather than resolved as bytes.

That this is the third time is the finding, not the incident: every lane in
the microVM program edits this one flat roster and its generated projection,
so the lanes serialize on it and each pass costs a full regeneration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…generate

Fourth merge of the same two paths. Roster is the union at 34 modes, with the
type arms, the roster and fleet_converge_mode_scope checked to agree, and the
workflow YAML regenerated from the merged sources.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 69448 is right: parse_converged_slot_network and the eleven folds
around it have no production consumer -- git grep finds only the definition,
one prose comment and the witness file -- while the render half beside them is
genuinely consumed by receipt_text. Every other unconsumed surface in this
module already states that in a typed DissolutionCondition row
(host_ruleset_installer_frontier, converged_slot_network_producer_frontier,
slot_network_readback_consumer_frontier, guest_resolver_configuration_frontier);
the parse half rested on a // annotation, and DESIGN section 4c is explicit
that an annotation is never evidence that a machine claim holds, because no
Accepted program can read one.

So the gap now carries the same row shape the module already uses: it names
the consumer and why that consumer cannot avoid the parse (the lifecycle
controller runs in a LATER PROCESS than the converge that wrote the receipt,
so it cannot hold the in-memory value and must recover it from the artifact),
enumerates the twelve folds it covers, and states a trigger in the
capability form section 4b(3) requires, with an explicit NOT-satisfied-by
clause that rules out the three ways this could be declared discharged
without the controller existing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Closing: this branch was a scratch branch for resolving #11751's merge conflict, not a change of its own. The dashboard auto-opened a PR for it.

The resolution is now on session/merry-ibex-866 at fa7b6faff12, so it is carried by #11751 where it belongs.

— sent from sunny-ant-606

@gunbai-bot gunbai-bot Bot closed this Sep 21, 2026
@gunbai-bot
gunbai-bot Bot deleted the fix/11751-merge-main branch September 21, 2026 03:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant