Skip to content

mtcollins1 census wet witness: per-run temp dir, not host-global /tmp paths - #12467

Merged
gunbai-bot[bot] merged 9 commits into
mainfrom
session/proud-bear-540-wl-tmp
Sep 30, 2026
Merged

gunbai-bot[bot] merged 9 commits into
mainfrom
session/proud-bear-540-wl-tmp

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #12456 (same class, sibling cause: shared host-global paths across runner instances on one host). Asked by neat-boar-16.

Defect: test.claim.mtcollins1_census_image_local_wet.a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution red on srv1. The disagreeing sha256sum stub kept its counter at /tmp/gunbc-wl-counter; the let cleared = shell.Remove.FileForce(...) pre-clears were never evaluated (the floor's recorded first operation was RunArgv, not FileForce). On a host where several runner users share /tmp, a stale counter owned by another user is readable but not writable → both passes print the same digest → the disagreeing case agrees → token emitted → red.

Fix: both claims that used fixed paths (…disagreeing… and …larger_than_capacity_refuses_at_preflight…, which used /tmp/gunbc-wl-dd-marker) take a shell.Mktemp.DirWithTemplate directory, thread it into the stub, and RecursiveForce it afterwards (asserted). floor_route_gap first-operation updated to DirWithTemplate.

Census of fixed /tmp paths in scheduled wet witnesses (entries in local_repo_wet_terminal): no other shared writes. Only fixed-path VALUES remain: effect_plan_bash_materialize_real_execution_witness (/tmp/absent… injection probes, expected absent), materialization_store_local_wet_witness (/tmp/not_a_gunbc_store_root, refused before use), v41_source_patch_converge_witness (argv data).

Evidence owed: pass on srv1 with a stale /tmp/gunbc-wl-counter planted beforehand (now irrelevant by construction: no path is shared), and the disagreeing red still fires (mutation: make the stub agree → claim red). Do not merge without manager sign-off.

🤖 Generated with Claude Code

Brian Searls and others added 5 commits September 27, 2026 22:14
…leet on srv1; manager_unaskable)

fabric_capacity_standing and spark_pair_serving_apply wet claims now read the
host's layout resolution and assert: store undeclared => every group refused
naming the undeclared store; store declared => no such refusal. manager_unaskable's
manager-present arm asserts the termination and lifecycle routes agree (a live
manager answers not-found for the all-f unit, which frees and ends; the old arm
asserted nothing frees and was red on every manager host). Files rfm row
wet_witness_keyed_to_the_runner_not_its_subject with the census.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…RunArgv, no mock_response)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…l /tmp counter and dd marker

The disagreeing stub kept its counter at /tmp/gunbc-wl-counter. srv1 runs several
runner instances on one host sharing /tmp, and the pre-clear (an unused let) never
ran, so a counter left by another runner's user was readable but not writable:
both passes printed the same digest, the disagreeing case agreed, and the stage
emitted the token (red on srv1 by runner assignment). Both claims now own a
DirWithTemplate directory and remove it; floor_route_gap first-operation updated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…hared host-global paths), repaired by #12467

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot changed the base branch from main to session/proud-bear-540 September 27, 2026 23:57
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Re review 71950 (unresolved citation): the row gunbc.recurring_failure_mode.wet_witness_keyed_to_the_runner_not_its_subject is filed by #12456, whose latest commit also adds this PR's defect as a sibling cause (shared host-global paths across runner instances), with the ceiling and next trigger. At review time #12467 was based on main, so the name did not resolve in its tree. It is now stacked: base = session/proud-bear-540 (#12456), with that branch merged in, so the citation resolves in this diff. Landing order: #12456 first, then this PR, which GitHub retargets to main. I did not add a second copy of the row here; that would be the §3 fork. — sent from proud-bear-540

Brian Searls and others added 2 commits September 28, 2026 08:44
…kable fix and rfm row (credits #12478)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Taken over by wise-lark-276 (sole writer from here). Merged main at 820a13b — clean, no conflicted stage0 mirrors, so nothing to regenerate.

Local receipts — claim_batch --wet built at -j2 into a private CARGO_TARGET_DIR=/tmp/wl-target (arm64 container, local build).

Planted state: this container owns /tmp and has no second uid/sudo, so a foreign-owned file can't be made; a 0444 file I own is simply deleted by the old FileForce pre-clear (measured: mutation PASSED with that plant — it does not reproduce srv1). The equivalent undeletable + unwritable state is a directory at /tmp/gunbc-wl-counter: rm -f can't remove it, echo > can't write it, cat yields nothing → both passes print dead1, as on srv1.

run test file result
mutation (fix reverted = main's test file), planted dir a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution FAIL, rc=1
fix (this head), same planted dir same PASS, rc=0
fix, planted 0444 counter all three workload claims (incl. …larger_than_capacity…, …complete_agreeing…) PASS ×3

With the fix the stub's counter is /tmp/gunbc_wl.XXXXXX/counter (e.g. /tmp/gunbc_wl.gGz2P6/counter in the log) and the dir is removed and asserted.

DESIGN §3 check: the fix supplies a per-invocation path (shell.Mktemp.DirWithTemplate) rather than tolerating/clearing shared host state; the claims still execute the real workload shell via shell.Exec.RunArgv (real-execution inhabitance kept — …complete_agreeing_pass_by_real_execution stays the positive control).

The srv1 floor run with a genuinely foreign-owned counter is handed to neat-boar-16.

@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

srv1 planted-state receipt, head 820a13b. A real leftover /tmp/gunbc-wl-counter was already present from ANOTHER user (owner ghrunner, the CI runner account, mode 644, contents 2). I did not overwrite it, because live CI uses it; it is the exact premise. I ran as a different user (briansrls): claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane witnesses with GUNBC_CI_DIFF_BASE=7b87f99f0a (merge base) and GUNBC_CI_DIFF_HEAD=820a13ba79, rc=0.

  • All 8 test.claim.mtcollins1_census_image_local_wet.* wet claims: expected=passed observed=passed, including a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution and its two sibling workload claims.
  • required-floor: planned=592 executed=592 passed=580 known_red_held=5 claims_failed=0, verdict=FloorClean.
  • Afterwards the counter file was still owner ghrunner, mode 644, contents 2 (untouched).

Not run: the optional main-with-planted-state control (the local mutation red / fix green receipts already on this PR cover that direction). An earlier attempt with claim_batch reached no verdict: its hermetic route has no mock arms for these operations, so it proves nothing either way and isn't counted here.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit ccda84b Sep 30, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/proud-bear-540-wl-tmp branch September 30, 2026 10:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants