diff --git a/dag/gunbc/auth/privileged_effect_census.dag b/dag/gunbc/auth/privileged_effect_census.dag index 23783399c78..c0cc7f34fde 100644 --- a/dag/gunbc/auth/privileged_effect_census.dag +++ b/dag/gunbc/auth/privileged_effect_census.dag @@ -6,7 +6,7 @@ import std.dissolution { DissolutionCondition, DissolutionStatus, DissolutionFired, DissolutionPending, DissolutionUnbound, dissolution_status, unbound_dissolution, retires_dissolution, } -import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision } +import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision, BreakGlassOnly } import std.roster_frontier { FrontierRow, frontier_row_decl } import gunbc.spark.bootstrap_provision { fleet_cloud_principal_standing, @@ -56,6 +56,9 @@ import gunbc.auth.authorization_pattern_selection { // resolve_access_token: the federated arm in a dispatched run, the operator's file in a session. // Classified as the federated pattern, because that is the arm that executes unattended and the // file arm is the operator's own workstation realization of the same entry. +// RealizedUnauthorized -- the site performs the effect under no credential that names it: the +// write reaches its store on the executor's host access alone. It matches no pattern, so a row +// realizing it is red unless it states why and what retires the reason. type OperatorSessionArm = GcloudInteractive | OperatorTokenFile @@ -66,6 +69,7 @@ type RealizedAuthorization | RealizedApprovalCapability | RealizedHumanStep | RealizedOperatorSession { arm: OperatorSessionArm } + | RealizedUnauthorized // A REASON IS A STATEMENT PLUS THE CONDITION UNDER WHICH IT STOPS BEING ONE. A bare string moved a // site out of the debt roster for as long as anyone left it there (review 68720): no bound, no @@ -109,6 +113,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedApprovalCapability => false RealizedHumanStep => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } OperatorApprovedCapability => match realized { @@ -117,6 +122,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedHumanStep => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } HumanOnlyStep { step: _ } => match realized { @@ -125,6 +131,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedApprovalCapability => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } OperatorOwnSession => match realized { @@ -133,6 +140,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedApprovalCapability => false RealizedHumanStep => false + RealizedUnauthorized => false } PastedOperatorToken => false } @@ -419,6 +427,23 @@ data eager_bootstrap_fork_declared: DivergenceReason = DivergenceReason { dissolution: retires_dissolution(ref: decl_ref(module_path: "gunbc.auth.access_token_source", decl_name: "ensure_access_token_eager_bootstrap_fork_dissolve_on")), } +// THE FABRIC STORE'S PROTECTED HEADS ARE WRITTEN UNDER HOST ACCESS ALONE (operator ruling A, +// 2026-09-27, relayed by proud-deer-538). The pair-serving authority partitions, the host-placement +// partition and the D0 consent slots are advanced by whoever reaches the fabric DB -- the placed +// host in process, every other host through the served door -- and the store verifies no grant for +// the operation. The rows below carry what each writer's selection asks for, so the door that +// verifies it has a derived answer per writer rather than one grant vocabulary for all of them. +// D0's door does gate on an approval before it writes, but the effect a row counts is the STORE +// write, and the store does not see that approval: any writer reaching the DB performs the same +// advance without it, so D0's row realizes RealizedUnauthorized like the rest (review 71933). +// THE DISSOLUTION IS UNBOUND ON PURPOSE. d0_store_operation_wall is not retired when the capability +// lands -- it is flipped to StoreOperationWallRestored -- so retires_dissolution over it would fire +// on the row's deletion, an artifact, while the capability stayed dead (§4b(3)). +data fabric_store_write_unverified: DivergenceReason = DivergenceReason { + statement: "the fabric DB admits an advance of a pair-serving authority partition, the host-placement partition or a D0 consent slot on the writer's host access alone: the placed host writes in process (FabricStorageLocalFiles) and the served door carries no grant, so the pattern selected for this writer is not the one the store enforces" as NonEmptyStr, + dissolution: unbound_dissolution(description: "one fabric store door every writer passes, the placed host included, that admits an advance of a protected head only under the credential this writer's selected pattern names, verified by the store for that operation -- the capability gunbc.spark.pair_serving_d0 d0_store_operation_wall names" as NonEmptyStr), +} + // THE DECLARATIONS THE BOUND TRIGGERS NAME, PRESENT BY CITATION. Each decl_ref here is checked by // the required floor against the corpus, so a trigger whose subject was deleted cannot stay in this // list. dissolution_status over it therefore answers Pending for every bound reason while its @@ -802,6 +827,111 @@ data privileged_effect_census: List = [ realized: RealizedFederatedGrant, divergence_reason: Present { value: gcp_iam_approval_enforced_in_reviewed_code }, }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_d0_door", decl_name: "pair_serving_d0_ci_wet"), + effect: PrivilegedEffect { + subject: "D0: suspend a group's pair-serving authority for a keyed successor -- claim the consent slot, move the authority partition twice and finalize the host-placement preparation on the fabric DB" as NonEmptyStr, + frequency: FleetOnce, + reversibility: IrreversibleEffect { what_is_lost: "the incumbent pair's serving authority: a suspended authority is not restored by re-applying, only by a further authority transition" as NonEmptyStr }, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "claim_host_effect_live"), + effect: PrivilegedEffect { + subject: "admit a bounded host effect on the host-placement partition of the fabric DB for a v41 lane" as NonEmptyStr, + frequency: EveryProvision, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "settle_host_effect_live_over"), + effect: PrivilegedEffect { + subject: "release a bounded host effect on the host-placement partition of the fabric DB when its lane settles" as NonEmptyStr, + frequency: EveryProvision, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "host_effect_recover_wet"), + effect: PrivilegedEffect { + subject: "release a host effect whose lane died, on the host-placement partition of the fabric DB, under an operator-stated receipt" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "pair_serving_authority_establish_wet"), + effect: PrivilegedEffect { + subject: "establish a group's pair-serving authority on its fabric DB partition from the source row, once per group" as NonEmptyStr, + frequency: FleetOnce, + reversibility: IrreversibleEffect { what_is_lost: "the group's establishment: an established authority is never re-established, only transitioned" as NonEmptyStr }, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_finalize_wet"), + effect: PrivilegedEffect { + subject: "finalize a host-placement preparation whose saga died after its authority event landed" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_abort_wet"), + effect: PrivilegedEffect { + subject: "abort a host-placement preparation whose saga died before its authority event landed" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, ] // ── THE FOLLOW-UPS, RANKED, AS A MONOTONE DEBT CONTRACT AT IDENTITY GRAIN ──────────────────── diff --git a/dag/test/claim/authorization_pattern_selection_witness_test.dag b/dag/test/claim/authorization_pattern_selection_witness_test.dag index 7e1699b0ff1..4132fcb84a6 100644 --- a/dag/test/claim/authorization_pattern_selection_witness_test.dag +++ b/dag/test/claim/authorization_pattern_selection_witness_test.dag @@ -201,6 +201,42 @@ test fn each_witness_ground_fires_alone() -> Bool { && witness_required(e: break_glass) } +// THE FABRIC STORE'S PROTECTED-HEAD WRITERS (operator ruling A, 2026-09-27). Each writer's +// selection is the credential the store door will verify for it; asserting it here is what makes +// the tap count the operator was told a derived fact. D0's door gates on the approval it selects, +// but the store does not verify it, so its store write diverges like every other writer's. The recurring host-effect lanes select the workload's own identity -- no human per run -- and the +// operator's recovery and establishment entries select one approval each; all diverge today under +// the one stated reason, because the store verifies nothing for any of them. +// THE ROW'S OWN VERDICT through the real per-row fold (site_verdict), not the whole census folded +// and then filtered: each claim is about one site, and the census fold is already run by the +// roster claims above (§3: a witness discriminates at one interface). +fn fabric_writer_verdict(key: String, want_approval: Bool) -> Bool { + any(map(filter(privileged_effect_census, row => declaration_ref_display_key(ref: row.site) == key), row => site_verdict(row: row)), v => + (if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) }) + && match v.conformance { + Conforms => false + DivergesWithReason { reason: _ } => true + Diverges => false + SiteNotDecidable { standing: _ } => false + }) +} + +test fn the_d0_door_selects_operator_approval_and_states_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.pair_serving_d0_door::pair_serving_d0_ci_wet", want_approval: true) +} + +test fn the_host_effect_lanes_select_workload_identity_and_state_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.host_commitment::claim_host_effect_live", want_approval: false) + && fabric_writer_verdict(key: "gunbc.spark.host_commitment::settle_host_effect_live_over", want_approval: false) +} + +test fn the_fabric_operator_entries_select_one_approval_each_and_state_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.host_commitment::host_effect_recover_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::pair_serving_authority_establish_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_finalize_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_abort_wet", want_approval: true) +} + // ── The census, run through the real fold ──────────────────────────────────────────────────── test fn every_census_site_is_decidable() -> Bool { (undecidable_sites() |> count) == 0