Repository navigation
Census the fabric store's protected-head writers (d0_store_operation_wall PR 1/5) - #12458
Conversation
…on selection per writer Operator ruling A (2026-09-27): the fabric DB door verifies a per-operation grant on every protected advance. Which grant is a DESIGN §3b selection, so each writer is a gunbc.auth.privileged_effect_census row and the selection decides: D0 selects and realizes operator approval (conforms); the recurring host-effect lanes select workload identity; the operator's establish, finalize, abort and recover entries select one approval each. Adds RealizedUnauthorized for sites that write under host access alone, and one stated reason (fabric_store_write_unverified) whose dissolution is the store door d0_store_operation_wall names. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…view 71933) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressing review 71933 (commit 3cb234c):
— sent from lively-dove-256 |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…loor over-cost 111ms/100ms) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PR 1 of the d0_store_operation_wall sequence (operator ruling A, 2026-09-27, relayed by proud-deer-538): the fabric DB door verifies a per-operation grant on every advance of a protected head (pair-serving authority partitions, host-placement, D0 consent slots).
What this PR does. Which grant each writer presents is a DESIGN §3b / §3d selection, so every writer of a protected head becomes a
gunbc.auth.privileged_effect_censusrow, andselect_authorization_patterndecides:gunbc.spark.pair_serving_d0_doorpair_serving_d0_ci_wetgunbc.spark.host_commitmentclaim_host_effect_live,settle_host_effect_live_overhost_commitmenthost_effect_recover_wet;pair_serving_authority_logpair_serving_authority_establish_wet,host_placement_finalize_wet,host_placement_abort_wetRealizedUnauthorized, the honest arm for a site that writes under host access alone. It matches no pattern, so a row realizing it is red unless it states a reason.fabric_store_write_unverified. Its unbound dissolution names the capability, a single store door that verifies each writer's selected credential per operation, which is the wallgunbc.spark.pair_serving_d0d0_store_operation_wallnames.test.claim.authorization_pattern_selection_witnessrun the real census fold and assert selection and conformance per writer.Writer set.
pair_serving_applyandv41_group_a_launchonly read these heads, andharness_seatwrites its own partition, so none of them are rows.Sequence.
gunbc.fabric_storage_serve, on top of Fabric served door refuses unrostered writers (roster derived from writer-identity readings) #12451, with the in-process binding retired by jolly-owl-158's PR 2.d0_store_operation_walltoStoreOperationWallRestored.Evidence. The selections were derived by hand from the gate and axis functions. Three remote
claim_batchdispatches that loaded the census closure were OOM-killed on BuildBuddy, so the witnesses here have not executed yet; CI's witness lane is their first run.🤖 Generated with Claude Code