Skip to content

RFM: second specimen of wet_witness_premise_read_from_the_runner (ntfy readback on srv1-09) - #12649

Merged
gunbai-bot[bot] merged 1 commit into
mainfrom
session/gentle-ibex-115
Sep 30, 2026
Merged

gunbai-bot[bot] merged 1 commit into
mainfrom
session/gentle-ibex-115

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Root cause of the srv1-09 red of test.claim.approval_ntfy_access_readback_wet_witness_test the_root_refuses_before_minting_on_this_host_by_real_execution (#12434 floor, run 36597893469 attempt 2).

The sudo failures aren't the cause. sudo: a password is required (and the sibling's /proc/<pid>/environ: Permission denied) are failed reads. The verb turns them into AclRefused before minting anything (approval_ntfy_channel_verdict / first_failed_read). That refusal is the verdict the claim expects on every host, and the sibling claim that hit the environ denial passed.

What actually failed is the claim's !path_exists(approval_device_store_root) conjunct. That was a host premise, and srv1 falsified it once the store root existed there. gunbc#12614 already repaired it on main: the claim now compares the store's existence before and after the call. The run judged #12434's head e45e0c2393, which does not contain #12614 (git merge-base --is-ancestor 178fb76c719 e45e0c2393 → false), so the PR still had the old premise. Remedy for #12434: merge main.

On brief items: (1) no sudoers inventory is needed, because on main the verdict doesn't depend on the grant. (2) No claim change is needed: #12614 is repair (a), and the real sudo route still runs on every runner. (3) This PR adds the specimen and the tell (don't blame the loudest log line when a refusal is the expected verdict) to the RFM row. It's data only.

🤖 Generated with Claude Code

…on srv1-09 was the store-absence premise #12614 already removed; the sudo refusals are the expected verdict)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 29, 2026

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — 863346b

The added ledger specimen matches the current source and separates the loud diagnostics from the failed assertion correctly.

The sudo: a password is required and /proc/<pid>/environ: Permission denied lines are failed reads that drive the verb to the refusal the wet claim expects. The host-dependent !path_exists(approval_device_store_root) conjunct was the actual red on srv1. The cited #12614 repair is present: the claim now captures the store's existence before the call, requires refusal before minting, and requires the call to leave that existence unchanged. The added evidence reference resolves to that declaration.

This is a data-only RFM addition, with no route or claim behavior change. Exact-head workflow 36611065587 completed successfully.

APPROVE-MERGE at this exact SHA through normal merge-queue gates.

Merged via the queue into main with commit 918b7e8 Sep 30, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/gentle-ibex-115 branch September 30, 2026 00:37
@briansrls
briansrls restored the session/gentle-ibex-115 branch September 30, 2026 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant