Skip to content

orphan - #11939

Closed
briansrls wants to merge 48 commits into
mainfrom
fix/11751-review-69484
Closed

orphan#11939
briansrls wants to merge 48 commits into
mainfrom
fix/11751-review-69484

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session sunny-ant-606.
Pushing to fix/11751-review-69484 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 30 commits September 19, 2026 02:32
…adback, workspace staging gate

- runner_microvm_network: tap-scoped egress rules in the forward chain (established; v6 drop;
  private/link-local/multicast denials above the grants; DNS and TCP 443; final tap drop). Chain
  policy stays accept for dockerd coexistence, so runner_host_filtered_egress DefaultDrop is honoured
  at tap grain, not host grain.
- SlotNetworkReadback (Confirmed / Refuted{fact} / Unobservable{fact}) over tap unheld, guest
  conntrack empty after flush, and nft listing digest == converged digest; plus the conntrack
  flush/list and nft list commands that produce the observations.
- runner_attempt_launch: staging_verdict gates the jailer on a read-back workspace (create exit,
  mke2fs exit, dumpe2fs superblock magic and size); every failure refuses under its own name.
- extdeps: nft daddr/dport/nfproto matches, nft list table, conntrack(8), dumpe2fs -h.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he present-tense consumption claim

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ector instead of two singleton-list folds

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…booted resolver; filtered-egress consumes the policy

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…es in their own direction

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ts through content_hash_eq_cryptographic

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nverge as its installer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…v4 authority

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d chain

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d image; denials precede every guest-side accept; tap v6 refused before conntrack

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…etwork receipt; v6 disabled on tap and guest; neighbour and expectation readbacks; helper standing over the effective host policy

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pelling on every host

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rection each v6 rule covers

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…me drop on the shared hosts

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng, then read the host back into a receipt

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…s its ssh-key demand

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…croVM network mode

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…establish

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e requested host, and persist the whole receipt

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…elper probes

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unread

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ke the receipt a parseable value, and give ip_forward and the slot probes their own unread arms

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sification

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 18 commits September 20, 2026 10:23
…bytes the converge writes

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…code the fabric lifetime sample's digests through their optionals

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… observes and records

The install+restart pair over a grantee-writable staged path was root-equivalent: the job user
stages these files and also executes job steps, so it could write its own ExecStart= and have
root run it (review 69104). The roster now carries the readbacks only, the mutating half waits on
a principal the job user cannot impersonate, and the mode is named for what it does.

Also fixes two latent defects on main that its own newly landed Optional checker refuses:
fabric_required_build_cell's lifetime-sample digests and workflow_dispatch_input's trigger index.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/extdeps/systemd/unit_file.dag
#	dag/gunbc/fabric/fabric_required_build_cell.dag
#	dag/gunbc/fleet/fleet_converge_workflow.dag
…ncipal, not a standing fact

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he grant fold drops its unused slot roster

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rm list

My merge resolution moved the RemainAfterExit annotation above the type and left a second
two-arm header below, orphaning ~25 arms of a widely consumed coproduct (review 69165).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the workflow

Three conflicts, each resolved at the authority rather than in the bytes.

fleet_converge_workflow_modes: both sides appended. Taking either side would
have deleted the other's modes while the match arms below -- which git merged
cleanly -- still named all of them, so the roster and the arms would have
disagreed. The roster is the union at 31 modes, and the type arms, the roster
and fleet_converge_mode_scope are now checked to agree exactly.

workflow_dispatch_input_witness_test: main landed the same Optional repair
independently and its annotation is the better one, citing
witness_that_fails_to_compile_is_absent_rather_than_red rather than describing
the fix locally. Main's side taken whole; the two controls this branch added
are untouched.

fleet-converge.yml is generated, and the merge driver refused it rather than
answering with a side -- correctly, because neither side's bytes are the
projection of the merged authorities. It is regenerated from the merged
sources, not hand-edited: the result differs from BOTH parents, restoring the
seven spark_native_serving_apply occurrences this branch had dropped to zero
while keeping this branch's FLEET_CONVERGE_EXPECTED_HOST step. Re-running the
gate changes nothing, so it is at its fixed point.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ge and regenerate

Same two paths as the previous merge and the same resolution, because they are
the program's shared spine: #11765 and #11679 are sibling microVM lanes editing
fleet_converge_workflow.dag, so every lane in this program serializes on this
file and its generated projection.

Roster is the union at 32 modes -- this branch's MicrovmNetworkObserve beside
main's MicrovmControllerAppKeyConverge -- with the type arms, the roster and
fleet_converge_mode_scope checked to agree exactly. The workflow YAML is
regenerated from the merged sources and carries both.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Third merge of the same two paths in one session, same resolution: the roster
is the union at 33 modes (this branch's MicrovmNetworkObserve beside main's
AppKeyVersionVerify), with the type arms, the roster and
fleet_converge_mode_scope checked to agree exactly, and the workflow YAML
regenerated from the merged sources rather than resolved as bytes.

That this is the third time is the finding, not the incident: every lane in
the microVM program edits this one flat roster and its generated projection,
so the lanes serialize on it and each pass costs a full regeneration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…generate

Fourth merge of the same two paths. Roster is the union at 34 modes, with the
type arms, the roster and fleet_converge_mode_scope checked to agree, and the
workflow YAML regenerated from the merged sources.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 69448 is right: parse_converged_slot_network and the eleven folds
around it have no production consumer -- git grep finds only the definition,
one prose comment and the witness file -- while the render half beside them is
genuinely consumed by receipt_text. Every other unconsumed surface in this
module already states that in a typed DissolutionCondition row
(host_ruleset_installer_frontier, converged_slot_network_producer_frontier,
slot_network_readback_consumer_frontier, guest_resolver_configuration_frontier);
the parse half rested on a // annotation, and DESIGN section 4c is explicit
that an annotation is never evidence that a machine claim holds, because no
Accepted program can read one.

So the gap now carries the same row shape the module already uses: it names
the consumer and why that consumer cannot avoid the parse (the lifecycle
controller runs in a LATER PROCESS than the converge that wrote the receipt,
so it cannot hold the in-memory value and must recover it from the artifact),
enumerates the twelve folds it covers, and states a trigger in the
capability form section 4b(3) requires, with an explicit NOT-satisfied-by
clause that rules out the three ways this could be declared discharged
without the controller existing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Four conflicts, resolved at the authority rather than in the artifacts.

gunbc.fleet_converge_workflow fleet_converge_workflow_modes was a union
conflict: this branch adds MicrovmNetworkObserve, main added R2BucketEnsure
and R2BucketAdminMint. Resolved as the union, which is what both sides
intended -- neither removed a mode.

The other three paths are GENERATED artifacts and were not hand-merged. They
reached the low-level merge driver, which refuses rather than answering: it
leaves the ours side in the worktree with no conflict markers and marks the
path unmerged, so accepting what was there would have silently dropped main's
authority-derived bytes. Regenerated instead, through
tools.generated_artifact_gate main_wet, from the merged authority.

Verified the regenerated emission carries BOTH sides rather than either:
.github/workflows/fleet-converge.yml now contains microvm_network_observe
(this branch), r2_bucket_ensure and r2_bucket_admin_mint (main), and main's
org_actions_inspection entry-point rename; the srv3/srv4 sudoers carry main's
fabric-cell grants alongside this branch's rows. Hand-merging could not have
produced that -- main had moved entry points and added steps this branch
never saw.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…route capture

All three findings verified against the merged head and all three hold. The
lane that authored this PR has archived, so these are mine.

1. MISSING IMPORT. runner_microvm_network_converge declared
   microvm_network_host_mutation_principal_frontier using DissolutionCondition
   and unbound_dissolution with no `import std.dissolution`. It bound anyway,
   because the required floor no longer refuses a cross-module reference whose
   module is not imported -- so this was a new row added to the population of
   a DECLARED 4b(3) drop that calls itself bounded and under repair. Silently
   growing a population declared bounded is the same move the drop exists to
   make visible. 330 other dag/ files carry the import; this one was the
   outlier. One line.

2. TWO NICKNAMES (DESIGN 3). addr_reading_carries and route_reading_carries
   had byte-identical bodies -- one predicate under two names. Consolidated to
   reading_carries_cidr, with the distinction stated where it actually lives:
   what differs between the call sites is the CIDR SUPPLIED, not the test
   applied. slot_field was a pure pass-through to wire_value; deleted, its 7
   call sites re-pointed to wire_value.

3. THE RAW ROUTE CAPTURE. guest_route carried the whole stdout of
   `ip -o -4 route show dev <tap>`, and `ip -o` guarantees one line per ROUTE
   OBJECT rather than one per device. A tap with a second route therefore made
   the slot record span two wire lines, and parse_converged_slot_line returned
   ConvergedSlotNetworkMalformed for a correctly converged host -- failing
   closed, so nothing fabricated, but making the receipt unparseable for a
   LEGAL host state. The field now carries the matched route line.

   This NARROWS an existing fallback rather than adding one: the whole-capture
   value was previously used unconditionally and is now used only when no line
   carries the expected prefix, which slot_refusal has already established
   cannot happen on a reading that reaches this function -- it refuses with
   SlotRouteNotHeld first.

EVIDENCE: the corpus typechecks clean with all three edits applied (gunbc run
over --source-root dag --source-root src/v2 reaches evaluation, so every
module resolved and typechecked). Witness execution is NOT available from this
container -- claim_batch page-thrashes here and srv1 refuses this session's
key -- so the witnesses are owed against CI rather than claimed here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Closing: fix/11751-review-69484 was a scratch branch for addressing review 69484 on #11751, not a change of its own. The dashboard auto-opened a PR for it.

Its commit 2b33365473 is already the head of session/merry-ibex-866, so the work is carried by #11751 where the review lives.

— sent from sunny-ant-606

@gunbai-bot gunbai-bot Bot closed this Sep 21, 2026
@gunbai-bot
gunbai-bot Bot deleted the fix/11751-review-69484 branch September 21, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant