Repository navigation
Fabric served door refuses unrostered writers (roster derived from writer-identity readings) - #12451
Merged
Merged
Conversation
…e writer-identity readings, FabricWriterRefused The served handler admits put/advance only for a login in gunbc.fabric_writer_roster's roster, derived from fabric_writer_identity_observe receipts (today none grounds a login: srv1 unproxied, srv3/srv4 cannot resolve the door), so the door refuses every served write. The drop row stays: the loopback listener and the in-process binding are the second half (unix-socket PR next). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…915, DESIGN §3c) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Addressed review 71915 in 5fa60e8: the uncalled |
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused Heal-Candidate-Run: 36353985246
…st roster rung (review 71929); schedule the new wet claims
- FabricWriterRefused carries FabricWriterRefusal (WriterLoginAbsent | WriterLoginUnrostered { login })
through the handler, the wire and the fault rendering, instead of prose in a principal field.
- Receipt rows derive their binding from the placement (fabric_storage_binding_for); no re-minted URL.
- The roster is stated as an authored roster of recorded readings: the row-to-run correspondence is
review diligence (rung 1), next trigger a typed receipt store the observe mode writes.
- The four new wet claims are scheduled in local_repo_wet_terminal and floor_route_gap.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/jolly-owl-158
Contributor
Author
|
Review 71929 is addressed in 1cd3e24; all three findings were valid.
The same commit also schedules the four new wet claims in Executed locally at this head, all |
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 28, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Sep 28, 2026
…iter-identity readings) (#12451) * Fabric served door refuses unrostered writers: roster derived from the writer-identity readings, FabricWriterRefused The served handler admits put/advance only for a login in gunbc.fabric_writer_roster's roster, derived from fabric_writer_identity_observe receipts (today none grounds a login: srv1 unproxied, srv3/srv4 cannot resolve the door), so the door refuses every served write. The drop row stays: the loopback listener and the in-process binding are the second half (unix-socket PR next). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Delete the uncalled fabric_served_writer_admission wrapper (review 71915, DESIGN §3c) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused Heal-Candidate-Run: 36353985246 * Typed writer refusal, placement-derived receipt bindings, and an honest roster rung (review 71929); schedule the new wet claims - FabricWriterRefused carries FabricWriterRefusal (WriterLoginAbsent | WriterLoginUnrostered { login }) through the handler, the wire and the fault rendering, instead of prose in a principal field. - Receipt rows derive their binding from the placement (fabric_storage_binding_for); no re-minted URL. - The roster is stated as an authored roster of recorded readings: the row-to-run correspondence is review diligence (rung 1), next trigger a typed receipt store the observe mode writes. - The four new wet claims are scheduled in local_repo_wet_terminal and floor_route_gap. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First half of the fabric write wall (gunbc.rung_drop
fabric_storage_append_principal_unrefused). The drop row stays standing. Per the operator ruling relayed by proud-deer-538 on 2026-09-27, a second PR retires it by moving srv1's backend to a group-restricted unix socket and retiringFabricStorageLocalFiles.What this changes
std.fabric_storage: adds a new fault arm,FabricWriterRefused { principal }, with its wire encode and decode ingunbc.fabric_storage_wire.gunbc.fabric_writer_roster(new): holds the served door's roster of tailnet USER principals. The roster is derived fromgunbc.fabric_writer_identity_observereceipts, and each receipt carries the run that took it. Nobody types a login into it.gunbc.fabric_storage_serve:putandadvanceare admitted only for a rostered login. An outsider login and an absent login both get a typedFabricWriterRefusedand no file is touched. Reads andidentityare unchanged. The roster is a parameter offabric_storage_serve_handle_over, and the served entry binds the derived roster.The readings (2026-09-27, fleet-converge
fabric_writer_identity_observe)Could not resolve host: srv1.tailecbe08.ts.netNo reading grounds a login, so the derived roster is empty and the door refuses every served put and advance. This breaks no writer that works today, because no fleet host can reach the door. A host joins the roster only when a new reading is appended.
Evidence
All claims below were executed locally with
gunbc runat uid 1000, and each returnedtrue:a_put_or_advance_from_a_login_outside_the_roster_is_refused_at_the_served_door_by_real_executiona_put_or_advance_with_no_presented_login_is_refused_at_the_served_door_by_real_executiona_rostered_login_puts_and_advances_through_the_served_door_by_real_execution(positive control)fabric_storage_respondwith an unconditionalFabricServedWriterAdmittedmakes the outsider claim returnfalse. The unmutated tree returnstrue.a_put_or_advance_by_a_principal_the_store_areas_do_not_admit_is_refused_by_the_real_file_store. The real file store gives a typed refusal when the kernel denies write, and nothing is created.test.claim.fabric.fabric_writer_roster_witness, which covers four things:Why the row does not retire here
127.0.0.1:18090. Any srv1 local account can present a forgedTailscale-User-Loginthere, and the login roster cannot tell. The drop row now lists that as a population.FabricStorageLocalFileswriters never reach the door.Both are what the unix-socket PR closes. Separately,
pair_serving_d0 d0_store_operation_wallis a missing construction outside this lane.🤖 Generated with Claude Code