Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
132 changes: 131 additions & 1 deletion dag/gunbc/auth/privileged_effect_census.dag
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ import std.dissolution {
DissolutionCondition, DissolutionStatus, DissolutionFired, DissolutionPending, DissolutionUnbound,
dissolution_status, unbound_dissolution, retires_dissolution,
}
import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision }
import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision, BreakGlassOnly }
import std.roster_frontier { FrontierRow, frontier_row_decl }
import gunbc.spark.bootstrap_provision {
fleet_cloud_principal_standing,
Expand Down Expand Up @@ -56,6 +56,9 @@ import gunbc.auth.authorization_pattern_selection {
// resolve_access_token: the federated arm in a dispatched run, the operator's file in a session.
// Classified as the federated pattern, because that is the arm that executes unattended and the
// file arm is the operator's own workstation realization of the same entry.
// RealizedUnauthorized -- the site performs the effect under no credential that names it: the
// write reaches its store on the executor's host access alone. It matches no pattern, so a row
// realizing it is red unless it states why and what retires the reason.
type OperatorSessionArm
= GcloudInteractive
| OperatorTokenFile
Expand All @@ -66,6 +69,7 @@ type RealizedAuthorization
| RealizedApprovalCapability
| RealizedHumanStep
| RealizedOperatorSession { arm: OperatorSessionArm }
| RealizedUnauthorized

// A REASON IS A STATEMENT PLUS THE CONDITION UNDER WHICH IT STOPS BEING ONE. A bare string moved a
// site out of the debt roster for as long as anyone left it there (review 68720): no bound, no
Expand Down Expand Up @@ -109,6 +113,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat
RealizedApprovalCapability => false
RealizedHumanStep => false
RealizedOperatorSession { arm: _ } => false
RealizedUnauthorized => false
}
OperatorApprovedCapability =>
match realized {
Expand All @@ -117,6 +122,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat
RealizedRunSelected => false
RealizedHumanStep => false
RealizedOperatorSession { arm: _ } => false
RealizedUnauthorized => false
}
HumanOnlyStep { step: _ } =>
match realized {
Expand All @@ -125,6 +131,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat
RealizedRunSelected => false
RealizedApprovalCapability => false
RealizedOperatorSession { arm: _ } => false
RealizedUnauthorized => false
}
OperatorOwnSession =>
match realized {
Expand All @@ -133,6 +140,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat
RealizedRunSelected => false
RealizedApprovalCapability => false
RealizedHumanStep => false
RealizedUnauthorized => false
}
PastedOperatorToken => false
}
Expand Down Expand Up @@ -419,6 +427,23 @@ data eager_bootstrap_fork_declared: DivergenceReason = DivergenceReason {
dissolution: retires_dissolution(ref: decl_ref(module_path: "gunbc.auth.access_token_source", decl_name: "ensure_access_token_eager_bootstrap_fork_dissolve_on")),
}

// THE FABRIC STORE'S PROTECTED HEADS ARE WRITTEN UNDER HOST ACCESS ALONE (operator ruling A,
// 2026-09-27, relayed by proud-deer-538). The pair-serving authority partitions, the host-placement
// partition and the D0 consent slots are advanced by whoever reaches the fabric DB -- the placed
// host in process, every other host through the served door -- and the store verifies no grant for
// the operation. The rows below carry what each writer's selection asks for, so the door that
// verifies it has a derived answer per writer rather than one grant vocabulary for all of them.
// D0's door does gate on an approval before it writes, but the effect a row counts is the STORE
// write, and the store does not see that approval: any writer reaching the DB performs the same
// advance without it, so D0's row realizes RealizedUnauthorized like the rest (review 71933).
// THE DISSOLUTION IS UNBOUND ON PURPOSE. d0_store_operation_wall is not retired when the capability
// lands -- it is flipped to StoreOperationWallRestored -- so retires_dissolution over it would fire
// on the row's deletion, an artifact, while the capability stayed dead (§4b(3)).
data fabric_store_write_unverified: DivergenceReason = DivergenceReason {
statement: "the fabric DB admits an advance of a pair-serving authority partition, the host-placement partition or a D0 consent slot on the writer's host access alone: the placed host writes in process (FabricStorageLocalFiles) and the served door carries no grant, so the pattern selected for this writer is not the one the store enforces" as NonEmptyStr,
dissolution: unbound_dissolution(description: "one fabric store door every writer passes, the placed host included, that admits an advance of a protected head only under the credential this writer's selected pattern names, verified by the store for that operation -- the capability gunbc.spark.pair_serving_d0 d0_store_operation_wall names" as NonEmptyStr),
}

// THE DECLARATIONS THE BOUND TRIGGERS NAME, PRESENT BY CITATION. Each decl_ref here is checked by
// the required floor against the corpus, so a trigger whose subject was deleted cannot stay in this
// list. dissolution_status over it therefore answers Pending for every bound reason while its
Expand Down Expand Up @@ -802,6 +827,111 @@ data privileged_effect_census: List<PrivilegedEffectSite> = [
realized: RealizedFederatedGrant,
divergence_reason: Present { value: gcp_iam_approval_enforced_in_reviewed_code },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.pair_serving_d0_door", decl_name: "pair_serving_d0_ci_wet"),
effect: PrivilegedEffect {
subject: "D0: suspend a group's pair-serving authority for a keyed successor -- claim the consent slot, move the authority partition twice and finalize the host-placement preparation on the fabric DB" as NonEmptyStr,
frequency: FleetOnce,
reversibility: IrreversibleEffect { what_is_lost: "the incumbent pair's serving authority: a suspended authority is not restored by re-applying, only by a further authority transition" as NonEmptyStr },
surface: ApiSurface,
workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.host_commitment", decl_name: "claim_host_effect_live"),
effect: PrivilegedEffect {
subject: "admit a bounded host effect on the host-placement partition of the fabric DB for a v41 lane" as NonEmptyStr,
frequency: EveryProvision,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.host_commitment", decl_name: "settle_host_effect_live_over"),
effect: PrivilegedEffect {
subject: "release a bounded host effect on the host-placement partition of the fabric DB when its lane settles" as NonEmptyStr,
frequency: EveryProvision,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.host_commitment", decl_name: "host_effect_recover_wet"),
effect: PrivilegedEffect {
subject: "release a host effect whose lane died, on the host-placement partition of the fabric DB, under an operator-stated receipt" as NonEmptyStr,
frequency: BreakGlassOnly,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "pair_serving_authority_establish_wet"),
effect: PrivilegedEffect {
subject: "establish a group's pair-serving authority on its fabric DB partition from the source row, once per group" as NonEmptyStr,
frequency: FleetOnce,
reversibility: IrreversibleEffect { what_is_lost: "the group's establishment: an established authority is never re-established, only transitioned" as NonEmptyStr },
surface: ApiSurface,
workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_finalize_wet"),
effect: PrivilegedEffect {
subject: "finalize a host-placement preparation whose saga died after its authority event landed" as NonEmptyStr,
frequency: BreakGlassOnly,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
PrivilegedEffectSite {
site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_abort_wet"),
effect: PrivilegedEffect {
subject: "abort a host-placement preparation whose saga died before its authority event landed" as NonEmptyStr,
frequency: BreakGlassOnly,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr },
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: NoWitnessDischarge,
},
realized: RealizedUnauthorized,
divergence_reason: Present { value: fabric_store_write_unverified },
},
]

// ── THE FOLLOW-UPS, RANKED, AS A MONOTONE DEBT CONTRACT AT IDENTITY GRAIN ────────────────────
Expand Down
36 changes: 36 additions & 0 deletions dag/test/claim/authorization_pattern_selection_witness_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -201,6 +201,42 @@ test fn each_witness_ground_fires_alone() -> Bool {
&& witness_required(e: break_glass)
}

// THE FABRIC STORE'S PROTECTED-HEAD WRITERS (operator ruling A, 2026-09-27). Each writer's
// selection is the credential the store door will verify for it; asserting it here is what makes
// the tap count the operator was told a derived fact. D0's door gates on the approval it selects,
// but the store does not verify it, so its store write diverges like every other writer's. The recurring host-effect lanes select the workload's own identity -- no human per run -- and the
// operator's recovery and establishment entries select one approval each; all diverge today under
// the one stated reason, because the store verifies nothing for any of them.
// THE ROW'S OWN VERDICT through the real per-row fold (site_verdict), not the whole census folded
// and then filtered: each claim is about one site, and the census fold is already run by the
// roster claims above (§3: a witness discriminates at one interface).
fn fabric_writer_verdict(key: String, want_approval: Bool) -> Bool {
any(map(filter(privileged_effect_census, row => declaration_ref_display_key(ref: row.site) == key), row => site_verdict(row: row)), v =>
(if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) })
&& match v.conformance {
Conforms => false
DivergesWithReason { reason: _ } => true
Diverges => false
SiteNotDecidable { standing: _ } => false
})
}

test fn the_d0_door_selects_operator_approval_and_states_the_unverified_store() -> Bool {
fabric_writer_verdict(key: "gunbc.spark.pair_serving_d0_door::pair_serving_d0_ci_wet", want_approval: true)
}

test fn the_host_effect_lanes_select_workload_identity_and_state_the_unverified_store() -> Bool {
fabric_writer_verdict(key: "gunbc.spark.host_commitment::claim_host_effect_live", want_approval: false)
&& fabric_writer_verdict(key: "gunbc.spark.host_commitment::settle_host_effect_live_over", want_approval: false)
}

test fn the_fabric_operator_entries_select_one_approval_each_and_state_the_unverified_store() -> Bool {
fabric_writer_verdict(key: "gunbc.spark.host_commitment::host_effect_recover_wet", want_approval: true)
&& fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::pair_serving_authority_establish_wet", want_approval: true)
&& fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_finalize_wet", want_approval: true)
&& fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_abort_wet", want_approval: true)
}

// ── The census, run through the real fold ────────────────────────────────────────────────────
test fn every_census_site_is_decidable() -> Bool {
(undecidable_sites() |> count) == 0
Expand Down