Skip to content
Merged
Original file line number Diff line number Diff line change
Expand Up @@ -351,7 +351,19 @@ data workload_stub_both_empty: String = "sha256sum() { return 1; };"
data workload_stub_partial: String = "sha256sum() { for f in \"$@\"; do case \"$f\" in *chunk1) continue;; esac; echo \"deadbeef $f\"; done; };"

// Complete passes that DISAGREE: the genuine instability this stage exists to detect.
data workload_stub_disagree: String = "sha256sum() { n=$(cat /tmp/gunbc-wl-counter 2>/dev/null || echo 0); n=$((n+1)); echo $n > /tmp/gunbc-wl-counter; for f in \"$@\"; do echo \"dead$n $f\"; done; };"
//
// THE COUNTER LIVES IN A DIRECTORY THIS CLAIM OWNS, never at a host-global path. It was
// /tmp/gunbc-wl-counter: several runner instances share one host's /tmp (srv1), so a counter left by
// another runner's user could be read but not rewritten, both passes then printed the same digest,
// the "disagreeing" case agreed, and the stage emitted the token -- red by which runner ran it
// (gunbc.recurring_failure_mode wet_witness_keyed_to_the_runner_not_its_subject, shared host path).
fn workload_scratch() -> String {
shell.Mktemp.DirWithTemplate(template: "/tmp/gunbc_wl.XXXXXX").path
}

fn workload_stub_disagree(dir: String) -> String {
concat("sha256sum() { n=$(cat ", dir, "/counter 2>/dev/null || echo 0); n=$((n+1)); echo $n > ", dir, "/counter; for f in \"$@\"; do echo \"dead$n $f\"; done; };")
}

test fn the_workload_emits_its_token_only_on_a_complete_agreeing_pass_by_real_execution() -> Bool {
let complete = workload_case(stubs: concat(workload_stub_dd, workload_stub_complete))
Expand All @@ -371,17 +383,18 @@ test fn the_workload_emits_its_token_only_on_a_complete_agreeing_pass_by_real_ex
// claim -- it also rules out the token appearing with anything appended -- and a RED may not be
// weakened to share a helper with the positive case.
test fn a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution() -> Bool {
let cleared = shell.Remove.FileForce(path: "/tmp/gunbc-wl-counter")
let dir = workload_scratch()
let empty = workload_case(stubs: concat(workload_stub_dd, workload_stub_both_empty))
let partial = workload_case(stubs: concat(workload_stub_dd, workload_stub_partial))
let cleared_again = shell.Remove.FileForce(path: "/tmp/gunbc-wl-counter")
let disagree = workload_case(stubs: concat(workload_stub_dd, workload_stub_disagree))
let disagree = workload_case(stubs: concat(workload_stub_dd, workload_stub_disagree(dir: dir)))
let removed = shell.Remove.RecursiveForce(path: dir)
string_contains(s: empty.stdout, pattern: "workload-digest-stable=yes") == false
&& empty.exit_code != 0
&& string_contains(s: partial.stdout, pattern: "workload-digest-stable=yes") == false
&& partial.exit_code != 0
&& string_contains(s: disagree.stdout, pattern: "workload-digest-stable=yes") == false
&& disagree.exit_code != 0
&& removed.success
}


Expand All @@ -390,15 +403,18 @@ test fn a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execu
// writes; the dual-socket profile's 64 GiB -- the shape run 35808203121 wrote into this machine --
// prints the refused token, exits nonzero, and never reaches dd (its stub leaves a marker that must
// stay absent). Only the declared shape varies, so the refusal is the preflight's and nothing else's.
data workload_stub_dd_marks: String = "dd() { echo dd-ran > /tmp/gunbc-wl-dd-marker; }; rm() { :; }; mkdir() { :; };"
fn workload_stub_dd_marks(marker: String) -> String {
concat("dd() { echo dd-ran > ", marker, "; }; rm() { :; }; mkdir() { :; };")
}

test fn a_workload_larger_than_capacity_refuses_at_preflight_by_real_execution() -> Bool {
let cleared = shell.Remove.FileForce(path: "/tmp/gunbc-wl-dd-marker")
let big = workload_case_of(stubs: concat(workload_stub_dd_marks, workload_stub_capacity_16gib, workload_stub_complete), workload: mtcollins1_dual_socket_workload)
let dd_after_big = Filesystem.Read(path: "/tmp/gunbc-wl-dd-marker").success
let small = workload_case_of(stubs: concat(workload_stub_dd_marks, workload_stub_capacity_16gib, workload_stub_complete), workload: mtcollins1_one_socket_workload)
let dd_after_small = Filesystem.Read(path: "/tmp/gunbc-wl-dd-marker").success
let cleaned = shell.Remove.FileForce(path: "/tmp/gunbc-wl-dd-marker")
let dir = workload_scratch()
let marker = concat(dir, "/dd-marker")
let big = workload_case_of(stubs: concat(workload_stub_dd_marks(marker: marker), workload_stub_capacity_16gib, workload_stub_complete), workload: mtcollins1_dual_socket_workload)
let dd_after_big = Filesystem.Read(path: marker).success
let small = workload_case_of(stubs: concat(workload_stub_dd_marks(marker: marker), workload_stub_capacity_16gib, workload_stub_complete), workload: mtcollins1_one_socket_workload)
let dd_after_small = Filesystem.Read(path: marker).success
let removed = shell.Remove.RecursiveForce(path: dir)
string_contains(s: concat("\n", big.stdout, "\n"), pattern: "\nworkload-preflight=refused\n")
&& string_contains(s: big.stdout, pattern: "workload-bytes=68719476736")
&& string_contains(s: big.stdout, pattern: "workload-write-rc=") == false
Expand All @@ -409,6 +425,7 @@ test fn a_workload_larger_than_capacity_refuses_at_preflight_by_real_execution()
&& string_contains(s: small.stdout, pattern: "workload-bytes=4294967296")
&& workload_emitted_the_token(o: small) && small.exit_code == 0
&& dd_after_small
&& removed.success
}

// AN UNREADABLE CAPACITY REFUSES, it is not read as room: df printing no figure must not fit.
Expand Down
4 changes: 2 additions & 2 deletions src/v2/workflow/floor_route_gap.dag
Original file line number Diff line number Diff line change
Expand Up @@ -1526,9 +1526,9 @@ fn floor_route_gap_expectation_chunk_20() -> List<FloorRouteGapExpectation> {
tail: Cons {
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.the_workload_emits_its_token_only_on_a_complete_agreeing_pass_by_real_execution", operation: "RunArgv", ground: NoMockResponse {} },
tail: Cons {
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution", operation: "RunArgv", ground: NoMockResponse {} },
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.a_failed_or_partial_or_disagreeing_workload_emits_no_token_by_real_execution", operation: "DirWithTemplate", ground: NoMockResponse {} },
tail: Cons {
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.a_workload_larger_than_capacity_refuses_at_preflight_by_real_execution", operation: "FileForce", ground: NoMockResponse {} },
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.a_workload_larger_than_capacity_refuses_at_preflight_by_real_execution", operation: "DirWithTemplate", ground: NoMockResponse {} },
tail: Cons {
head: FloorRouteGapExpectation { identity: "test.claim.mtcollins1_census_image_local_wet.an_unreadable_capacity_refuses_at_preflight_by_real_execution", operation: "RunArgv", ground: NoMockResponse {} },
tail: Cons {
Expand Down
Loading