Skip to content

Activation witness: forbid enable fused with --now, not the flag itself - #12347

Merged
briansrls merged 1 commit into
mainfrom
fix/activation-witness-enable-now
Sep 27, 2026
Merged

briansrls merged 1 commit into
mainfrom
fix/activation-witness-enable-now

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Part of the latent-red triage from #12339. This PR covers one root cause: emitted_activation_is_never_the_fused_enable_now (test.claim.runner_service_activation_witness).

Red on main f17c19a. Probed per conjunct:

  • the apply text contains no '--now' (holds)
  • the apply text contains a bare --now (so the second conjunct fails)
  • the fused builder does contain '--now' (holds)

The bare --now is the runner-slot family header, gunbc.fleet_converge_plan runner_slot_apply_family_header: "retirement inhibition (systemctl mask --now)". That text first appeared in #11204 (1d5c804).

Re-derivation (§6b, and §4d's over-prohibition arm). The row exists to stop activation from being the fused systemctl enable --now that ignores readiness. mask --now on an authorized surplus unit is a different verb, and there stopping the unit now is the point. So the fold is right and the claim prohibited more than its subject. The prohibition is now the enable verb followed by --now, in both renderings ('enable' '--now' and enable --now), built from systemctl_enable_verb. The positive pole asserts the same pattern does match the fused builder, so it is not a pattern that can never match.

Evidence. Local claim_batch, every function in the file on this head: all PASS except grants_carry_one_enable_and_one_start_per_desired_slot, which is a different cause, fixed in #12343.

🤖 Generated with Claude Code

emitted_activation_is_never_the_fused_enable_now refused any --now in the apply text; #11204
added retirement inhibition (systemctl mask --now) to the runner family header, so the row was red
on text carrying no activation. The prohibition is now the enable verb followed by --now.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit df39444 Sep 27, 2026
5 checks passed
@briansrls
briansrls deleted the fix/activation-witness-enable-now branch September 27, 2026 04:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant