Repository navigation
mtcollins1 census wet witness: per-run temp dir, not host-global /tmp paths - #12467
Conversation
…leet on srv1; manager_unaskable) fabric_capacity_standing and spark_pair_serving_apply wet claims now read the host's layout resolution and assert: store undeclared => every group refused naming the undeclared store; store declared => no such refusal. manager_unaskable's manager-present arm asserts the termination and lifecycle routes agree (a live manager answers not-found for the all-f unit, which frees and ends; the old arm asserted nothing frees and was red on every manager host). Files rfm row wet_witness_keyed_to_the_runner_not_its_subject with the census. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…RunArgv, no mock_response) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…l /tmp counter and dd marker The disagreeing stub kept its counter at /tmp/gunbc-wl-counter. srv1 runs several runner instances on one host sharing /tmp, and the pre-clear (an unused let) never ran, so a counter left by another runner's user was readable but not writable: both passes printed the same digest, the disagreeing case agreed, and the stage emitted the token (red on srv1 by runner assignment). Both claims now own a DirWithTemplate directory and remove it; floor_route_gap first-operation updated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…hared host-global paths), repaired by #12467 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 71950 (unresolved citation): the row |
…kable fix and rfm row (credits #12478) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Taken over by wise-lark-276 (sole writer from here). Merged main at 820a13b — clean, no conflicted stage0 mirrors, so nothing to regenerate. Local receipts — Planted state: this container owns
With the fix the stub's counter is DESIGN §3 check: the fix supplies a per-invocation path ( The srv1 floor run with a genuinely foreign-owned counter is handed to neat-boar-16. |
|
srv1 planted-state receipt, head 820a13b. A real leftover
Not run: the optional main-with-planted-state control (the local mutation red / fix green receipts already on this PR cover that direction). An earlier attempt with |
Follow-up to #12456 (same class, sibling cause: shared host-global paths across runner instances on one host). Asked by neat-boar-16.
Defect:
test.claim.mtcollins1_census_image_local_wet.a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_executionred on srv1. The disagreeing sha256sum stub kept its counter at/tmp/gunbc-wl-counter; thelet cleared = shell.Remove.FileForce(...)pre-clears were never evaluated (the floor's recorded first operation wasRunArgv, notFileForce). On a host where several runner users share/tmp, a stale counter owned by another user is readable but not writable → both passes print the same digest → the disagreeing case agrees → token emitted → red.Fix: both claims that used fixed paths (
…disagreeing…and…larger_than_capacity_refuses_at_preflight…, which used/tmp/gunbc-wl-dd-marker) take ashell.Mktemp.DirWithTemplatedirectory, thread it into the stub, andRecursiveForceit afterwards (asserted).floor_route_gapfirst-operation updated toDirWithTemplate.Census of fixed /tmp paths in scheduled wet witnesses (entries in
local_repo_wet_terminal): no other shared writes. Only fixed-path VALUES remain:effect_plan_bash_materialize_real_execution_witness(/tmp/absent…injection probes, expected absent),materialization_store_local_wet_witness(/tmp/not_a_gunbc_store_root, refused before use),v41_source_patch_converge_witness(argv data).Evidence owed: pass on srv1 with a stale
/tmp/gunbc-wl-counterplanted beforehand (now irrelevant by construction: no path is shared), and the disagreeing red still fires (mutation: make the stub agree → claim red). Do not merge without manager sign-off.🤖 Generated with Claude Code