Repository navigation
Fabric store: owner/group/mode derived from its two writers (CI claim principal can write) - #12294
Merged
Merged
Conversation
…+ CI claim principal)
The srv1 deploy ensured /opt/gunbc/fabric-storage/{,objects,heads} as briansrls:briansrls 0755,
but the host-effect claim writes those files directly as the CI job principal (ghrunner), so
fleet-converge run 36139624393 refused `object publication refused: permission_denied`.
- gunbc.managed_directory: ManagedDirectory carries group_principal (the capability its frontier
note named); class derivation compares against that gid; setgid derived iff group != owner's;
managed_directory_admit refuses a writer outside owner+group instead of deriving o+w.
- gunbc.fabric_storage_placement fabric_storage_store_directories: declares both writers
(service principal owner, ghrunner primary group) -> objects/heads 2770, root 2710.
- gunbc.live_deploy: EnsuredManagedHostDirectory arm; ensure lowers the admission to
install -d -m/-o/-g (re-applies on existing dirs) or a __GUNBC_DEPLOY_REFUSED__ marker.
- Witnesses: RED (uncovered writer refuses, would have been 0772), positive 2770 control, and the
srv1 spec's lowered ensure for objects/heads carries 2770 briansrls/ghrunner.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Re: group write on files (proud-deer-538). Checked in the store code: heads are never rewritten in place, and no principal rewrites or deletes another's file. That makes directory write (2770) sufficient, and files keep the umask's 0644.
So when writer B advances a head writer A created, B creates |
…'admission') Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… 0772 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rants other-write (0707), not a hand-computed octal Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The srv1 deploy ensured /opt/gunbc/fabric-storage/{,objects,heads} as briansrls:briansrls 0755,
but the host-effect claim writes those files directly as the CI job principal (ghrunner), so
fleet-converge run 36139624393 refused
object publication refused: permission_denied.note named); class derivation compares against that gid; setgid derived iff group != owner's;
managed_directory_admit refuses a writer outside owner+group instead of deriving o+w.
(service principal owner, ghrunner primary group) -> objects/heads 2770, root 2710.
install -d -m/-o/-g (re-applies on existing dirs) or a GUNBC_DEPLOY_REFUSED marker.
srv1 spec's lowered ensure for objects/heads carries 2770 briansrls/ghrunner.
Why a group and not a new shared group: with one owner and exactly one other writer, the smallest group that admits it is that writer's own primary group. No groupadd, no membership edit, no new sudo grant. A third writer with its own gid refuses at admission, and that is when a shared group gets modeled.
Local evaluation: the remote runner refused to evaluate (
HostBudgetUnreadable: no cgroup memory bound) and the emit test was OOM-killed, so these witnesses have not run yet. The required floor lane on this PR will be their first execution.Noted, not changed: the roster row
fleet_posix_ci_runner_usersays uid 1001, but srv1's observedghrunneris uid 999. The emitted ensure uses names, and the class check only compares against gid 1000, so this change doesn't depend on it.After merge: the srv1 dashboard deploy re-applies ownership (install -d on existing dirs). Wet control: rerun fleet-converge spark_v41_runtime_image_build host=srv1 target=srv8; the host-effect claim should land.
🤖 Generated with Claude Code