Repository navigation
Conversation
…adback, workspace staging gate
- runner_microvm_network: tap-scoped egress rules in the forward chain (established; v6 drop;
private/link-local/multicast denials above the grants; DNS and TCP 443; final tap drop). Chain
policy stays accept for dockerd coexistence, so runner_host_filtered_egress DefaultDrop is honoured
at tap grain, not host grain.
- SlotNetworkReadback (Confirmed / Refuted{fact} / Unobservable{fact}) over tap unheld, guest
conntrack empty after flush, and nft listing digest == converged digest; plus the conntrack
flush/list and nft list commands that produce the observations.
- runner_attempt_launch: staging_verdict gates the jailer on a read-back workspace (create exit,
mke2fs exit, dumpe2fs superblock magic and size); every failure refuses under its own name.
- extdeps: nft daddr/dport/nfproto matches, nft list table, conntrack(8), dumpe2fs -h.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he present-tense consumption claim Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ector instead of two singleton-list folds Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…booted resolver; filtered-egress consumes the policy Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…es in their own direction Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ts through content_hash_eq_cryptographic Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nverge as its installer Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…v4 authority Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d chain Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d image; denials precede every guest-side accept; tap v6 refused before conntrack Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…etwork receipt; v6 disabled on tap and guest; neighbour and expectation readbacks; helper standing over the effective host policy Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pelling on every host Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rection each v6 rule covers Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…me drop on the shared hosts Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng, then read the host back into a receipt Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/fleet/fleet_converge_workflow.dag
…s its ssh-key demand Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…croVM network mode Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…establish Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e requested host, and persist the whole receipt Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…elper probes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unread Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ke the receipt a parseable value, and give ip_forward and the slot probes their own unread arms Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sification Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…bytes the converge writes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…code the fabric lifetime sample's digests through their optionals Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… observes and records The install+restart pair over a grantee-writable staged path was root-equivalent: the job user stages these files and also executes job steps, so it could write its own ExecStart= and have root run it (review 69104). The roster now carries the readbacks only, the mutating half waits on a principal the job user cannot impersonate, and the mode is named for what it does. Also fixes two latent defects on main that its own newly landed Optional checker refuses: fabric_required_build_cell's lifetime-sample digests and workflow_dispatch_input's trigger index. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/extdeps/systemd/unit_file.dag # dag/gunbc/fabric/fabric_required_build_cell.dag # dag/gunbc/fleet/fleet_converge_workflow.dag
…ncipal, not a standing fact Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he grant fold drops its unused slot roster Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rm list My merge resolution moved the RemainAfterExit annotation above the type and left a second two-arm header below, orphaning ~25 arms of a widely consumed coproduct (review 69165). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the workflow Three conflicts, each resolved at the authority rather than in the bytes. fleet_converge_workflow_modes: both sides appended. Taking either side would have deleted the other's modes while the match arms below -- which git merged cleanly -- still named all of them, so the roster and the arms would have disagreed. The roster is the union at 31 modes, and the type arms, the roster and fleet_converge_mode_scope are now checked to agree exactly. workflow_dispatch_input_witness_test: main landed the same Optional repair independently and its annotation is the better one, citing witness_that_fails_to_compile_is_absent_rather_than_red rather than describing the fix locally. Main's side taken whole; the two controls this branch added are untouched. fleet-converge.yml is generated, and the merge driver refused it rather than answering with a side -- correctly, because neither side's bytes are the projection of the merged authorities. It is regenerated from the merged sources, not hand-edited: the result differs from BOTH parents, restoring the seven spark_native_serving_apply occurrences this branch had dropped to zero while keeping this branch's FLEET_CONVERGE_EXPECTED_HOST step. Re-running the gate changes nothing, so it is at its fixed point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ge and regenerate Same two paths as the previous merge and the same resolution, because they are the program's shared spine: #11765 and #11679 are sibling microVM lanes editing fleet_converge_workflow.dag, so every lane in this program serializes on this file and its generated projection. Roster is the union at 32 modes -- this branch's MicrovmNetworkObserve beside main's MicrovmControllerAppKeyConverge -- with the type arms, the roster and fleet_converge_mode_scope checked to agree exactly. The workflow YAML is regenerated from the merged sources and carries both. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Third merge of the same two paths in one session, same resolution: the roster is the union at 33 modes (this branch's MicrovmNetworkObserve beside main's AppKeyVersionVerify), with the type arms, the roster and fleet_converge_mode_scope checked to agree exactly, and the workflow YAML regenerated from the merged sources rather than resolved as bytes. That this is the third time is the finding, not the incident: every lane in the microVM program edits this one flat roster and its generated projection, so the lanes serialize on it and each pass costs a full regeneration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…generate Fourth merge of the same two paths. Roster is the union at 34 modes, with the type arms, the roster and fleet_converge_mode_scope checked to agree, and the workflow YAML regenerated from the merged sources. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 69448 is right: parse_converged_slot_network and the eleven folds around it have no production consumer -- git grep finds only the definition, one prose comment and the witness file -- while the render half beside them is genuinely consumed by receipt_text. Every other unconsumed surface in this module already states that in a typed DissolutionCondition row (host_ruleset_installer_frontier, converged_slot_network_producer_frontier, slot_network_readback_consumer_frontier, guest_resolver_configuration_frontier); the parse half rested on a // annotation, and DESIGN section 4c is explicit that an annotation is never evidence that a machine claim holds, because no Accepted program can read one. So the gap now carries the same row shape the module already uses: it names the consumer and why that consumer cannot avoid the parse (the lifecycle controller runs in a LATER PROCESS than the converge that wrote the receipt, so it cannot hold the in-memory value and must recover it from the artifact), enumerates the twelve folds it covers, and states a trigger in the capability form section 4b(3) requires, with an explicit NOT-satisfied-by clause that rules out the three ways this could be declared discharged without the controller existing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
sunny-ant-606.Pushing to
fix/11751-merge-mainadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan