Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
33a6800
WIP: source snapshot capture/materialize over the fabric object store…
Sep 21, 2026
f25f258
Source snapshot handoff: capture, materialize elsewhere, and run one …
Sep 21, 2026
d19becc
Root-cause the executor's workspace root: bind it from the request, d…
Sep 21, 2026
f203259
Workspace-root selection: discovery first, request second, refuse oth…
Sep 21, 2026
5ab6c5f
Snapshot containment, exact membership, and separated workspace-root …
Sep 21, 2026
3585940
The destination is provider-allocated, not a caller-named path; and f…
Sep 21, 2026
a55f3e4
Name the residual exactly and state its trigger at capability grain
Sep 21, 2026
391bc98
Admit the allocation root; restore the real escape fixture; consume t…
Sep 21, 2026
c56a37c
Ancestry admission: every level, trusted owner, and the base is provi…
Sep 21, 2026
8493e4a
Merge main: a4f949154c7 re-derives the six capacity witnesses failing…
Sep 21, 2026
8ce6029
Correct the failure-mode row to what the code establishes, not more
Sep 21, 2026
74b69fd
The walk terminates on the root, and an alias never survives admission
Sep 21, 2026
93528ef
The provider owns one fixed base; stop admitting arbitrary paths
Sep 21, 2026
353e6bd
Cite the existing authority for non-short-circuit rather than claimin…
Sep 21, 2026
7ce3129
Delete the withdrawn walk's residue: two dangling shell operations an…
Sep 22, 2026
428cc38
Construct the runtime base from the observed uid; stop reading the en…
Sep 22, 2026
fdb1921
Create the provider base at its final mode; no second pathname operat…
Sep 22, 2026
4060ca2
Check the ancestry before the first mutation; derive base and ancestr…
Sep 22, 2026
f43cb0e
One principal observation; delete the second dangling mkdir operation
Sep 22, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
119 changes: 119 additions & 0 deletions dag/extdeps/shell.dag
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,12 @@ fn posix_command_v_check_argv(command: NonEmptyStr) -> List<String> {
["sh", "-c", "command -v \"$1\"", "sh", command as String]
}

// IsSticky IS POSIX `test -k`, AND ITS RATIONALE SITS HERE because only module-item grain is
// modeled (DESIGN section 4c) -- an operation lives inside this service's body, so the reason for
// one attaches to the declaration that contains it. On a directory the sticky bit is the rule that
// stops a principal renaming or removing an entry it does not own, which is the whole reason a
// shared temporary directory is safe to allocate in at all. It is a different question from the
// mode digits and gets its own operation rather than being parsed out of them.
service shell.Test {
operation IsExecutable {
input { path: FilePath }
Expand Down Expand Up @@ -240,6 +246,17 @@ service shell.Test {
}
}

operation IsSticky {
input { path: FilePath }
output { is_sticky: Bool from "exit_success" }
readonly
transport shell { argv: ["test", "-k", "{path}"] }
exit {
0 => Unit "The sticky bit is set on the path"
1 => Unit "The path is missing or its sticky bit is not set"
}
}

operation IsWritable {
input { path: FilePath }
output { writable: Bool from "exit_success" }
Expand All @@ -256,6 +273,62 @@ fn shell_test_is_executable_argv(path: FilePath) -> List<String> {
["test", "-x", path as String]
}

// `id -un` names the principal this process runs as. It is a separate service from Stat because it
// is a fact about the PROCESS rather than about a path, and the two are joined by the consumer
// deciding whether a path's owner is trusted; folding the process identity into a path observation
// would make one operation answer two questions.
// Canonical resolves every symlink and `..` ONCE, so a consumer that then uses only the canonical
// spelling never re-traverses an alias somebody else owns -- which is what lets a caller establish
// that the location it named is the location it got.
service shell.Path {
operation Canonical {
input { path: FilePath }
output {
success: Bool from "exit_success"
stdout: String from "stdout"
stderr: String from "stderr"
}
readonly
transport shell { argv: ["realpath", "-e", "--", "{path}"] }
exit {
0 => Unit "the path exists and its canonical spelling is on stdout"
nonzero => String "realpath could not resolve the path"
}
}
}

service shell.Id {
operation UserId {
input {}
output {
success: Bool from "exit_success"
stdout: String from "stdout"
stderr: String from "stderr"
}
readonly
transport shell { argv: ["id", "-u"] }
exit {
0 => Unit "the effective numeric user id is on stdout"
nonzero => String "id could not name the effective user id"
}
}

operation UserName {
input {}
output {
success: Bool from "exit_success"
stdout: String from "stdout"
stderr: String from "stderr"
}
readonly
transport shell { argv: ["id", "-un"] }
exit {
0 => Unit "the effective user name is on stdout"
nonzero => String "id could not name the effective user"
}
}
}

service shell.Uname {
operation KernelName {
input {}
Expand Down Expand Up @@ -310,7 +383,23 @@ service shell.Mktemp {
}
}

// NewOwnerOnly FAILS WHEN THE NAME ALREADY EXISTS -- including when it exists as a symlink -- and
// its rationale sits here for the module-item-grain reason the Test service records. That failure
// is the point rather than an inconvenience: a caller that must know whether it CREATED a directory
// cannot learn it from `mkdir -p`, which succeeds either way, and adopting an existing directory at
// a predictable name is how a squatted path gets reused. The mode is applied AT CREATION, so the
// name never exists at a wider one and no second pathname operation is needed to narrow it.
service shell.Mkdir {
operation NewOwnerOnly {
input { path: FilePath }
output { success: Bool from "exit_success" }
transport shell { argv: ["mkdir", "-m", "0700", "--", "{path}"] }
exit {
0 => Unit "Directory created AT 0700; fails if the name exists at all, so success is proof this process created it"
nonzero => String "mkdir -m 0700 failed"
}
}

operation Parents {
input { path: FilePath }
output { success: Bool from "exit_success" }
Expand Down Expand Up @@ -375,7 +464,27 @@ service shell.Remove {
// WHY IT IS `readonly` AND WHY THAT IS TRUE. It opens nothing for write and creates nothing; unlike
// git.Inspect.ReadTreeIntoIndex, which was declared readonly while writing the file GIT_INDEX_FILE
// names, this one genuinely only reads inode metadata.
// ModeOf RETURNS THE OCTAL PERMISSION DIGITS AS `stat` RENDERS THEM -- "700", "1777" -- and its
// rationale sits above the service for the module-item-grain reason the Test service records. The
// consumer compares the WHOLE STRING against declared spellings; nothing extracts a digit, because
// the substrate has no string indexing and a hand-rolled scan would be a parser standing where a
// comparison was available.
service shell.Stat {
operation ModeOf {
input { path: FilePath }
output {
success: Bool from "exit_success"
stdout: String from "stdout"
stderr: String from "stderr"
}
readonly
transport shell { argv: ["stat", "-c", "%a", "--", "{path}"] }
exit {
0 => Unit "the path exists and its octal mode is on stdout"
nonzero => String "stat could not read the path"
}
}

operation OwnerOf {
input { path: FilePath }
output {
Expand Down Expand Up @@ -425,6 +534,16 @@ service shell.Chmod {
}
}

operation WorldWritableDirectory {
input { path: FilePath }
output { success: Bool from "exit_success" }
transport shell { argv: ["chmod", "0777", "{path}"] }
exit {
0 => Unit
nonzero => String "chmod 0777 failed"
}
}

operation OwnerReadWriteFile {
input { path: FilePath }
output { success: Bool from "exit_success" }
Expand Down
21 changes: 21 additions & 0 deletions dag/gunbc/cli_run_workspace_root_scaffold.dag
Original file line number Diff line number Diff line change
Expand Up @@ -40,3 +40,24 @@ data cli_run_source_root_anchor_loc_delta_net: Int = 43
data cli_run_source_root_anchor_test_discriminator_present_root: String = "try_anchor_source_root_resolves_declared_present_root"

data cli_run_source_root_anchor_test_discriminator_absent_root: String = "try_anchor_source_root_skips_declared_absent_root"

data cli_run_workspace_root_selection_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
module_path: "v1_compiler.cli_run",
decl_name: "bind_process_workspace_root",
field: WholeDeclaration
}
}

data cli_run_workspace_root_selection_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: bind_process_workspace_root — the two-rule workspace-root SELECTION (discovery is the incumbent authority; where no checkout exists the request names the base, strictly, and neither rule applying refuses at exit 2) is authored in HAND-Rust beside the discovery walk it wraps, and a selection is policy rather than plumbing, so it owes a .dag authority that the walk alone did not. It exists because discovery cannot answer for an executor handed an immutable source snapshot by content identity (gunbc.fabric_source_snapshot) — it panicked there, so source without a repository was unrunnable rather than unsupported. DISSOLVES WHEN the workspace root reaches the compiler as a MODELED FIELD OF THE REQUEST decided in .dag — v2.cli.compile_cli's plan naming the base the way it already names the source roots and the verb — at which point this selection is a fold over that plan and the Rust retains no rule. NOT dissolved by the discovery walk moving, by the refusal being reworded, or by Chunk F landing the roots walk without carrying the root itself: the trigger is the CAPABILITY of a request-carried root, not any artifact that would contribute to one")

data cli_run_workspace_root_selection_receipt_plan_anchor: String = "docs/plans/cli-run-reconcile-defork.md#interim-workspace-root-scaffold"

data cli_run_workspace_root_selection_loc_delta_measure: String = "code lines -- comments, blank lines and tests excluded -- of the declarations this scaffold binds: declared_workspace_root, declared_workspace_root_from, bind_process_workspace_root, try_resolve_process_workspace_root, bind_checkout_root, WorkspaceRootBasis and its impl, and the verb's binding in main.rs. It INCLUDES the 25 lines of the discovery walk relocated into try_resolve_process_workspace_root, which are not net-new to the seed: the measure is stated so the figure can be checked rather than trusted, because a bare count invites a reader to compare it with the rows above, whose measure is not recorded"

data cli_run_workspace_root_selection_loc_delta_net: Int = 107

data cli_run_workspace_root_selection_test_discriminator_declared: String = "declared_workspace_root_names_cwd_when_every_root_is_under_it"

data cli_run_workspace_root_selection_test_discriminator_escapes_cwd: String = "declared_workspace_root_refuses_a_root_that_escapes_cwd"
Loading