Repository navigation
Conversation
…adback, workspace staging gate
- runner_microvm_network: tap-scoped egress rules in the forward chain (established; v6 drop;
private/link-local/multicast denials above the grants; DNS and TCP 443; final tap drop). Chain
policy stays accept for dockerd coexistence, so runner_host_filtered_egress DefaultDrop is honoured
at tap grain, not host grain.
- SlotNetworkReadback (Confirmed / Refuted{fact} / Unobservable{fact}) over tap unheld, guest
conntrack empty after flush, and nft listing digest == converged digest; plus the conntrack
flush/list and nft list commands that produce the observations.
- runner_attempt_launch: staging_verdict gates the jailer on a read-back workspace (create exit,
mke2fs exit, dumpe2fs superblock magic and size); every failure refuses under its own name.
- extdeps: nft daddr/dport/nfproto matches, nft list table, conntrack(8), dumpe2fs -h.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he present-tense consumption claim Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ector instead of two singleton-list folds Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…booted resolver; filtered-egress consumes the policy Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…es in their own direction Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ts through content_hash_eq_cryptographic Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nverge as its installer Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…v4 authority Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d chain Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d image; denials precede every guest-side accept; tap v6 refused before conntrack Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…etwork receipt; v6 disabled on tap and guest; neighbour and expectation readbacks; helper standing over the effective host policy Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pelling on every host Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rection each v6 rule covers Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…me drop on the shared hosts Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng, then read the host back into a receipt Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/fleet/fleet_converge_workflow.dag
…s its ssh-key demand Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…croVM network mode Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…establish Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e requested host, and persist the whole receipt Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…elper probes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unread Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ke the receipt a parseable value, and give ip_forward and the slot probes their own unread arms Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sification Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…bytes the converge writes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…code the fabric lifetime sample's digests through their optionals Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… observes and records The install+restart pair over a grantee-writable staged path was root-equivalent: the job user stages these files and also executes job steps, so it could write its own ExecStart= and have root run it (review 69104). The roster now carries the readbacks only, the mutating half waits on a principal the job user cannot impersonate, and the mode is named for what it does. Also fixes two latent defects on main that its own newly landed Optional checker refuses: fabric_required_build_cell's lifetime-sample digests and workflow_dispatch_input's trigger index. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/extdeps/systemd/unit_file.dag # dag/gunbc/fabric/fabric_required_build_cell.dag # dag/gunbc/fleet/fleet_converge_workflow.dag
…ncipal, not a standing fact Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he grant fold drops its unused slot roster Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rm list My merge resolution moved the RemainAfterExit annotation above the type and left a second two-arm header below, orphaning ~25 arms of a widely consumed coproduct (review 69165). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e the workflow Three conflicts, each resolved at the authority rather than in the bytes. fleet_converge_workflow_modes: both sides appended. Taking either side would have deleted the other's modes while the match arms below -- which git merged cleanly -- still named all of them, so the roster and the arms would have disagreed. The roster is the union at 31 modes, and the type arms, the roster and fleet_converge_mode_scope are now checked to agree exactly. workflow_dispatch_input_witness_test: main landed the same Optional repair independently and its annotation is the better one, citing witness_that_fails_to_compile_is_absent_rather_than_red rather than describing the fix locally. Main's side taken whole; the two controls this branch added are untouched. fleet-converge.yml is generated, and the merge driver refused it rather than answering with a side -- correctly, because neither side's bytes are the projection of the merged authorities. It is regenerated from the merged sources, not hand-edited: the result differs from BOTH parents, restoring the seven spark_native_serving_apply occurrences this branch had dropped to zero while keeping this branch's FLEET_CONVERGE_EXPECTED_HOST step. Re-running the gate changes nothing, so it is at its fixed point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ge and regenerate Same two paths as the previous merge and the same resolution, because they are the program's shared spine: #11765 and #11679 are sibling microVM lanes editing fleet_converge_workflow.dag, so every lane in this program serializes on this file and its generated projection. Roster is the union at 32 modes -- this branch's MicrovmNetworkObserve beside main's MicrovmControllerAppKeyConverge -- with the type arms, the roster and fleet_converge_mode_scope checked to agree exactly. The workflow YAML is regenerated from the merged sources and carries both. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Third merge of the same two paths in one session, same resolution: the roster is the union at 33 modes (this branch's MicrovmNetworkObserve beside main's AppKeyVersionVerify), with the type arms, the roster and fleet_converge_mode_scope checked to agree exactly, and the workflow YAML regenerated from the merged sources rather than resolved as bytes. That this is the third time is the finding, not the incident: every lane in the microVM program edits this one flat roster and its generated projection, so the lanes serialize on it and each pass costs a full regeneration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…generate Fourth merge of the same two paths. Roster is the union at 34 modes, with the type arms, the roster and fleet_converge_mode_scope checked to agree, and the workflow YAML regenerated from the merged sources. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 69448 is right: parse_converged_slot_network and the eleven folds around it have no production consumer -- git grep finds only the definition, one prose comment and the witness file -- while the render half beside them is genuinely consumed by receipt_text. Every other unconsumed surface in this module already states that in a typed DissolutionCondition row (host_ruleset_installer_frontier, converged_slot_network_producer_frontier, slot_network_readback_consumer_frontier, guest_resolver_configuration_frontier); the parse half rested on a // annotation, and DESIGN section 4c is explicit that an annotation is never evidence that a machine claim holds, because no Accepted program can read one. So the gap now carries the same row shape the module already uses: it names the consumer and why that consumer cannot avoid the parse (the lifecycle controller runs in a LATER PROCESS than the converge that wrote the receipt, so it cannot hold the in-memory value and must recover it from the artifact), enumerates the twelve folds it covers, and states a trigger in the capability form section 4b(3) requires, with an explicit NOT-satisfied-by clause that rules out the three ways this could be declared discharged without the controller existing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Four conflicts, resolved at the authority rather than in the artifacts. gunbc.fleet_converge_workflow fleet_converge_workflow_modes was a union conflict: this branch adds MicrovmNetworkObserve, main added R2BucketEnsure and R2BucketAdminMint. Resolved as the union, which is what both sides intended -- neither removed a mode. The other three paths are GENERATED artifacts and were not hand-merged. They reached the low-level merge driver, which refuses rather than answering: it leaves the ours side in the worktree with no conflict markers and marks the path unmerged, so accepting what was there would have silently dropped main's authority-derived bytes. Regenerated instead, through tools.generated_artifact_gate main_wet, from the merged authority. Verified the regenerated emission carries BOTH sides rather than either: .github/workflows/fleet-converge.yml now contains microvm_network_observe (this branch), r2_bucket_ensure and r2_bucket_admin_mint (main), and main's org_actions_inspection entry-point rename; the srv3/srv4 sudoers carry main's fabric-cell grants alongside this branch's rows. Hand-merging could not have produced that -- main had moved entry points and added steps this branch never saw. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…route capture All three findings verified against the merged head and all three hold. The lane that authored this PR has archived, so these are mine. 1. MISSING IMPORT. runner_microvm_network_converge declared microvm_network_host_mutation_principal_frontier using DissolutionCondition and unbound_dissolution with no `import std.dissolution`. It bound anyway, because the required floor no longer refuses a cross-module reference whose module is not imported -- so this was a new row added to the population of a DECLARED 4b(3) drop that calls itself bounded and under repair. Silently growing a population declared bounded is the same move the drop exists to make visible. 330 other dag/ files carry the import; this one was the outlier. One line. 2. TWO NICKNAMES (DESIGN 3). addr_reading_carries and route_reading_carries had byte-identical bodies -- one predicate under two names. Consolidated to reading_carries_cidr, with the distinction stated where it actually lives: what differs between the call sites is the CIDR SUPPLIED, not the test applied. slot_field was a pure pass-through to wire_value; deleted, its 7 call sites re-pointed to wire_value. 3. THE RAW ROUTE CAPTURE. guest_route carried the whole stdout of `ip -o -4 route show dev <tap>`, and `ip -o` guarantees one line per ROUTE OBJECT rather than one per device. A tap with a second route therefore made the slot record span two wire lines, and parse_converged_slot_line returned ConvergedSlotNetworkMalformed for a correctly converged host -- failing closed, so nothing fabricated, but making the receipt unparseable for a LEGAL host state. The field now carries the matched route line. This NARROWS an existing fallback rather than adding one: the whole-capture value was previously used unconditionally and is now used only when no line carries the expected prefix, which slot_refusal has already established cannot happen on a reading that reaches this function -- it refuses with SlotRouteNotHeld first. EVIDENCE: the corpus typechecks clean with all three edits applied (gunbc run over --source-root dag --source-root src/v2 reaches evaluation, so every module resolved and typechecked). Witness execution is NOT available from this container -- claim_batch page-thrashes here and srv1 refuses this session's key -- so the witnesses are owed against CI rather than claimed here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
Closing: Its commit — sent from sunny-ant-606 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
sunny-ant-606.Pushing to
fix/11751-review-69484advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan