Repository navigation
Fabric door on a group-restricted unix socket with kernel-attested peers; placed host writes through it; retire fabric_storage_append_principal_unrefused - #12482
Merged
Conversation
…e writer-identity readings, FabricWriterRefused The served handler admits put/advance only for a login in gunbc.fabric_writer_roster's roster, derived from fabric_writer_identity_observe receipts (today none grounds a login: srv1 unproxied, srv3/srv4 cannot resolve the door), so the door refuses every served write. The drop row stays: the loopback listener and the in-process binding are the second half (unix-socket PR next). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…915, DESIGN §3c) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused Heal-Candidate-Run: 36353985246
…st roster rung (review 71929); schedule the new wet claims
- FabricWriterRefused carries FabricWriterRefusal (WriterLoginAbsent | WriterLoginUnrostered { login })
through the handler, the wire and the fault rendering, instead of prose in a principal field.
- Receipt rows derive their binding from the placement (fabric_storage_binding_for); no re-minted URL.
- The roster is stated as an authored roster of recorded readings: the row-to-run correspondence is
review diligence (rung 1), next trigger a typed receipt store the observe mode writes.
- The four new wet claims are scheduled in local_repo_wet_terminal and floor_route_gap.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/jolly-owl-158
…y its trigger; schedule the local-peer wet claims Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…refusal gains its peer arms Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…into v2.compiler.target_serialize Pure move: target_serialize_source_from_model and the 84 declarations it reaches (none touch infer/resolve/ingest) now live in their own module, which translate imports. Every renderer of target text -- the bash command fold behind gunbc.shell_command_text, ci_failure_class, the yaml/sql folds -- no longer compiles the pipeline stages. 59 importers and 12 qualified-name citations repointed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Review 72010: added a |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eceipt claim reads it, not the whole script (floor budget) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…usal arms Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rs the real script and asserts the route (DESIGN §3, proud-deer-538) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Every bash command the fold serializes rebuilt the constant fold grammar inside its own demand: bash_fold_serialize_leaf_node rebuilt the production catalog, encoded it to a catalog node, rebuilt lex rules and transform maps, derived its relation row twice, and handed v2.compiler.target_serialize a rules node that the generic entry walked for its recursion budget and re-selected the same row from, then validated against a serialize source spelled from that same row. That is ~40k evaluator steps per one-word command, and ~1.4M for the 7 KB approval-broker dark-install script (DESIGN 6b: a constant re-derived in subject-local demand; 2: demand minimisation, not a cache). - extdeps.languages.bash_command_fold: the catalog, its node, its subtree count, lex rules, binding spellings and emit transforms are data; the target model, serialize source and rules node are built from one derived row. - target_serialize: target_serialize_source_from_selected_row serializes a row the caller established, with the same recursion budget and refusal as the generic entry; nonterminal items still go through the generic selection. - workflow.bash_command_fold_serialize: the leaf derives the row once and uses that entry. Emitted bytes are unchanged: dark-install + apply + retract scripts and a quoting-edge argv compare byte-identical against the base (32,557 bytes). Two claims pin the new route: the carried budget equals the rules node's count, and the selected-row route spells what the generic route spells; each goes red under a one-token mutation. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e socket branch Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…socket edits re-applied) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 28, 2026
briansrls
added a commit
that referenced
this pull request
Sep 28, 2026
…transport Integrates the transport-specific changes from sibling PR #12482 at 6c6a238, excluding its unrelated compiler/bash-fold performance changes. Retains the allocation branch protocol split and cookie/response-header support. Protected state requires socket principal admission plus its signed envelope; production protected service writers retain their HTTPS proxy route. This is isolated draft integration, not deployment or approval of the dependency.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 28, 2026
… 2026-09-29) One identity, its own list in v2.workflow.floor_eval_step_cost_drop and its own gunbc.rung_drop row: the first reader of witness_approval_broker_dark_script_text is billed the generic bash emit path's per-step overhead, inherited from main (script bytes identical) and re-judged only because deployment_spec_srv1 changed. Measured by floor run 36490489535. Trigger: that overhead reduced so the first reader fits the new-witness budget; moving the bill does not retire it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 29, 2026
…option claim_executor --required-regen at 78c2e4c drifted the two CLI mirrors (the compiled-in surface lacked the unix_socket row, so its first generation dropped the option from the dispatch). Installed the surface candidate, rebuilt: first_generation_equal=true (0 drift); standalone --required-regen-fixed-point: fixed_point_equal=true. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 29, 2026
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 29, 2026
…drop projection regenerated floor_eval_step_cost_drop keeps the boot-matrix rows and main's dark-install render rows side by side, and floor_eval_step_cost_drop_all_rows concatenates both. docs/design-rung-drops.md is regenerated by generated_artifact_gate main_wet over a build of the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 29, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #12451. This branch contains #12451. Until that lands, the diff against main includes it; review the commits after
5fa60e86a9.This PR retires gunbc.rung_drop
fabric_storage_append_principal_unrefusedby its trigger. The retirement is carried in the row'sstanding: Retired { trigger_fired }receipt, the same way every other retired drop records it. It implements the operator ruling relayed by proud-deer-538 on 2026-09-27: the fabric backend moves to a group-restricted unix socket, andFabricStorageLocalFilesis retired for the placed host, so the placed host also writes through the door.The door
gunbc serve --unix-socket <path>is added to the modeled CLI surface (gunbc.cli_dispatch_surface) and to the seed.SO_PEERCRED→ account name) and passes it to the handler aspeer_user. TCP attests nothing, sopeer_useris""there.cli_run serve_unix_socket_door_tests, 3 tests passing.fabric_storage_door_socketinsidefabric_storage_door_directory: owner is the service account, group is ghrunner, and the group can only traverse.gunbc.fabric_writer_roster,fabric_door_principal_ofsorts every connection into one of three cases:FabricWriterRefusalarms:WriterLoginAbsent,WriterLoginUnrostered,WriterPeerUnrostered,WriterPeerUnattested.fabric_storage_binding_forbinds the placed host toFabricStorageDoorSocket, which usescurl --unix-socketthrough the newextdeps.http.client PostStdinWithinUnixSocket. No placement derivesFabricStorageLocalFilesany more; it remains only for the door's own realization and for fixtures and instruments over their own roots.--unix-socketand binds no--host/--port. The tailscale route targetsunix:<socket>. That target form is in upstreamipn/serve.go(ExpandProxyTargetValue), and since v1.98.9 only root may configure it (TS-2026-005); our apply already runs it privileged.local <user>through the socket (FabricIdentityLocalPeer).Evidence (executed locally, all
true)a_put_or_advance_from_an_unrostered_local_account_is_refused_even_with_a_rostered_login_by_real_execution(forged header from a local account);a_put_or_advance_on_an_unattested_connection_is_refused_by_real_execution;test.claim.live_deploy.emit: the unit binds the socket, the route proxies to it, the areas and the door directory have the expected modes, the entry mode is 0400, and no entry repair is emitted.pair_serving_d0_witness the_wet_door_refuses_while_the_fabric_storage_write_wall_drop_stands: with the row Retired, D0 still refuses, now ond0_store_operation_wall.Not walled, stated
fabric_storage_directory).dashboard_deployapplies this revision. After deploy, check:tailscale versionis recent enough for unix targets;d0_store_operation_wall(lively-dove-256).🤖 Generated with Claude Code