Skip to content

approval_device_enrolment_code_issue: release dir as the verb's checkout root; resolve-sized step timeout - #12531

Merged
gunbai-bot[bot] merged 1 commit into
mainfrom
session/fierce-deer-555-enrolment-root
Sep 28, 2026
Merged

gunbai-bot[bot] merged 1 commit into
mainfrom
session/fierce-deer-555-enrolment-root

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Fixes fleet-converge approval_device_enrolment_code_issue (run 36415852659, main 3be8a53, release 6b6c35d). It refused before minting:
remote exit=2 error: no workspace root: none of the current directory /home/ubuntu's ancestors is a git checkout ...

Root cause (DESIGN §6b). The seed resolves its workspace root before any verb runs. It reads gunbc.cli_run_workspace_root_scaffold gunbc_workspace_root_env_name (GUNBC_WORKSPACE_ROOT) when set, and otherwise walks up from the working directory. The remote argv in gunbc.auth.approval_device_enrolment_code_issue enrolment_code_issue_remote_argv passed absolute --source-roots, but those are read after the root is resolved. Over SSH the working directory is the login principal's home, and the release locus is not a checkout either. Every other process that execs a gunbc binary from a release locus (the broker's serve unit, the microVM slot unit) receives the root at spawn from that same row via gunbc.live_deploy.emit release_locus_workspace_root_environment. This verb is one more such process and did not.

On /home/ubuntu: that is the SSH login's (executor_bootstrap_principal, ubuntu) working directory, which sudo keeps. The verb is elevated to fleet_posix_operator_user (briansrls) as modeled, so the principal was right. Only the root was missing.

Change:

  • enrolment_code_issue_remote_argv now runs sudo -n -u <operator> /usr/bin/env GUNBC_WORKSPACE_ROOT=<release dir> <release binary> run ..., built with extdeps.tools.env env_prefixed_argv and the existing row. It goes inside the elevation because sudo's env_reset would drop a variable set outside it. The bootstrap principal's grant is (ALL) NOPASSWD: ALL, so /usr/bin/env is covered.
  • test.claim.approval_device_enrolment_code_witness the_remote_argv_runs_the_release_verb_as_the_operator_user now pins the whole prefix, sudo → env binding → release binary. Dropping the binding turns it red.
  • Step timeout: aux 5m → gunbc_ci_gunbc_run_resolve_step_timeout_minutes (15m). The step pays the job's own resolve plus the remote verb's resolve of the broker-routes closure, which took about 3m at the broker's measured boot. The fleet job backstop doesn't move: this is one gated step with no upload, below the spark_grants worst case, and the note now says so. The generated .github/workflows/fleet-converge.yml is updated to match (5 → 15). CI's generated-artifact gate checks that edit against the emitter.

Not evaluated locally. The real check is the next approval_device_enrolment_code_issue dispatch with expected_revision naming an installed release.

🤖 Generated with Claude Code

…ir as its checkout root; step pays two resolves

fleet-converge run 36415852659 refused before minting: the seed resolves its workspace root from
GUNBC_WORKSPACE_ROOT or by walking up from cwd, and over SSH cwd is the login's home (/home/ubuntu;
the elevation itself is to the modeled operator user, sudo just keeps cwd). Every other process
that execs a gunbc binary from a release locus gets the root at spawn from
gunbc_workspace_root_env_name; this verb now does too, via env(1) inside the elevation (sudo
env_reset would drop it outside).

The step moves from the aux 5m to gunbc_ci_gunbc_run_resolve_step_timeout_minutes (15m): it pays
the job's own resolve plus the remote routes-closure resolve (~3m on srv1). Fleet job backstop is
unmoved (one step, no upload, below the spark_grants worst case).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit a009f95 Sep 28, 2026
15 of 16 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/fierce-deer-555-enrolment-root branch September 28, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants