Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion dag/extdeps/filesystem/filesystem_io.dag
Original file line number Diff line number Diff line change
Expand Up @@ -208,7 +208,7 @@ fn filesystem_link_create_new(
}
}

data filesystem_read_outcome_adoption_standing: String ="RUNG: mitigatable. filesystem_read_outcome provides the single modeled fold from Filesystem.Read's scalar transport observation into FilesystemReadSucceeded | FilesystemReadRefused, but nothing forces callers through it. gunbc.ci_yaml_validate is the first converted consumer and preserves read refusal separately from YAML parse refusal. The raw operation remains directly consumed elsewhere, so content+success+error nonsense combinations remain writable at those sites. SUBJECT: an unconverted consumption site is a Filesystem Read call whose bound result has any success, error, or content projection outside the three arguments of filesystem_read_outcome. The call and those three projections remain after conversion because they supply the fold; adoption changes where they are consumed, not whether they exist. BASELINE measured on origin/main b21b710d5378387ae0c841f07323292c5d72faba: 92 unconverted consumption sites across 48 .dag files. REMAINDER after the first conversion: 91 unconverted consumption sites across 47 files. RE-DERIVATION: enumerate Filesystem Read assignment calls in tracked .dag source, excluding this adoption-standing data declaration so the instrument cannot count its own prose; for each bound result, classify it converted only when every success, error, and content projection is an argument of filesystem_read_outcome, otherwise classify it unconverted; count unconverted rows and distinct paths. NEXT-RUNG TRIGGER: the unconverted population reaches zero -- every Filesystem Read result projection occurs only as an argument to filesystem_read_outcome. The compiler-only filesystem_read intrinsic is a separate replacement migration and is not part of this population or this fold."
data filesystem_read_outcome_adoption_standing: String ="RUNG: mitigatable. filesystem_read_outcome provides the single modeled fold from Filesystem.Read's scalar transport observation into FilesystemReadSucceeded | FilesystemReadRefused, but nothing forces callers through it. gunbc.ci_yaml_validate is the first converted consumer and preserves read refusal separately from YAML parse refusal. The raw operation remains directly consumed elsewhere, so content+success+error nonsense combinations remain writable at those sites. SUBJECT: an unconverted consumption site is a Filesystem Read call whose bound result has any success, error, or content projection outside the three arguments of filesystem_read_outcome. The call and those three projections remain after conversion because they supply the fold; adoption changes where they are consumed, not whether they exist. CLASSES EXCLUDED FROM THE TARGET POPULATION, recorded so exclusion is a decision and not a blind spot: a site whose read projections already flow through this fold's own typed shape is exact_read_typed and is not a target; a site that routes a raw read through a domain-specific fold of the same shape -- gunbc.machine_intake proc_read_outcome into ProcRead | ProcReadRefused, which additionally carries error_kind -- is domain_read_fold: it is a typed outcome, not a silent default, but a second read-outcome fold beside this one is a DESIGN 3 fork, recorded to be unified later by growing the shared fold, and those sites are targets of that unification, not of this lane. BASELINE measured on origin/main b21b710d5378387ae0c841f07323292c5d72faba: 92 unconverted consumption sites across 48 .dag files. REMAINDER after the first conversion: 91 unconverted consumption sites across 47 files. RE-DERIVATION: enumerate Filesystem Read assignment calls in tracked .dag source, excluding this adoption-standing data declaration so the instrument cannot count its own prose; for each bound result, classify it converted only when every success, error, and content projection is an argument of filesystem_read_outcome, otherwise classify it unconverted; count unconverted rows and distinct paths. NEXT-RUNG TRIGGER: the unconverted population reaches zero -- every Filesystem Read result projection occurs only as an argument to filesystem_read_outcome. The compiler-only filesystem_read intrinsic is a separate replacement migration and is not part of this population or this fold."

data filesystem_absence_establishment_adoption_standing: String = "RUNG: structurally guaranteed for the consumers that route through filesystem_file_observation, on the source-to-.dag acceptance path only, and MITIGATABLE NOWHERE ELSE -- the raw Filesystem.Read and Filesystem.List operations stay callable, so a module that has not adopted the carrier can still write the conflation. This row states the unconverted population at identity grain rather than as a count, because a count is not a plan and a one-sided ratchet over a number measured on the current tree is the oracle section 5 rejects. SUBJECT: a site that concludes ABSENCE, NOT-PRESENT or a dropped element from a FAILED read or a FAILED boolean path test, rather than from a listing that succeeded. It is not every Filesystem.Read consumer -- most read a file they already know exists, and those are the separate filesystem_read_outcome adoption population above. ENUMERATED SITES, each one read rather than pattern-matched: the roster is EMPTY as of this row's restoration. The six identities the row carried on origin/main 6305a5174c all route through the carrier now -- gunbc.host_effect_nbd_proxy_serve host_effect_nbd_proxy_serve_read_session_token, v2.workflow.product_receipt_stage run_product_receipt_stage, tools.merge_admission_walk read_tested_subject and read_floor_receipt, gunbc.codex_supervised_turn codex_supervised_turn_generation_observation, and tools.opaque_realization_census declaration_body_standing -- the five converted by the change that empties this roster -- each preserving could-not-look as its own typed refusal rather than an absence, and gunbc.fleet_converge_plan_cli observe_cap_members_wet already converted on main -- so a could-not-look at any of them can no longer masquerade as an established absence. THE ROW STAYS NONE THE LESS, and an empty roster is not a deleted row: the raw operations remain callable outside this module, so the class shape can be re-spelled at a new site at any time, and what the row guards is the CLASS, not its former members. A site of this shape found anywhere is a defect to repair by adoption, not a row to add. The mistake this restoration repairs was deleting the row because its enumeration emptied rather than because the trigger below expired, which is exactly the failure the NEXT-RUNG TRIGGER paragraph exists to prevent. WHAT IS DELIBERATELY NOT ON THE LIST: gunbc.roadmap_belt_actuate belt_read_or_empty, whose collapse is scoped and argued in the annotation above its definition -- both branches take the same action at every remaining caller -- and gunbc.fabric_cell_acquire, which already establishes absence from the parent enumeration through its own four-state observation and would gain nothing but a second spelling. MONOTONE DIRECTION: the roster above may only shrink. A row leaves it when the site routes through filesystem_file_observation or filesystem_entry_presence, or when the site is deleted; a NEW site of this shape is a defect to repair rather than a row to add. NEXT-RUNG TRIGGER, and it names the capability rather than an artifact: the raw List and Read result projections cease to be reachable outside this module's folds, so a consumer cannot spell the conflation at all -- at which point the enumeration above has no subject and this row is deleted. That is the same trigger filesystem_read_outcome_adoption_standing carries, one question further in: it asks that every read projection be folded, this asks that every ABSENCE be established."

Expand Down
34 changes: 21 additions & 13 deletions dag/gunbc/auth/access_token_source.dag
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,13 @@ import std.upsert_decision {
UpsertClassification,
}
import extdeps.shell
import extdeps.filesystem.filesystem_io { Filesystem }
import extdeps.filesystem.filesystem_io {
Filesystem,
FilesystemReadOutcome,
FilesystemReadRefused,
FilesystemReadSucceeded,
filesystem_read_outcome,
}
import extdeps.cloud.gcp.auth_print_access_token {
gcloud_stderr_auth_deficit,
}
Expand Down Expand Up @@ -202,19 +208,21 @@ type SuppliedTokenResolution
= SuppliedTokenReady { token: Secret }
| SuppliedTokenUnavailable { cause: NonEmptyStr }

fn classify_supplied_token(success: Bool, error: String, content: String) -> SuppliedTokenResolution {
if success == false {
SuppliedTokenUnavailable {
cause: join(["the access token file could not be read: ", error], "") as NonEmptyStr,
}
} else {
let token = trim(s: content)
if token == "" {
fn classify_supplied_token(read: FilesystemReadOutcome) -> SuppliedTokenResolution {
match read {
FilesystemReadRefused { error } =>
SuppliedTokenUnavailable {
cause: "the access token file is empty, which is never a usable bearer token" as NonEmptyStr,
cause: join(["the access token file could not be read: ", error], "") as NonEmptyStr,
}
FilesystemReadSucceeded { content } => {
let token = trim(s: content)
if token == "" {
SuppliedTokenUnavailable {
cause: "the access token file is empty, which is never a usable bearer token" as NonEmptyStr,
}
} else {
SuppliedTokenReady { token: token as Secret }
}
} else {
SuppliedTokenReady { token: token as Secret }
}
}
}
Expand All @@ -238,7 +246,7 @@ fn read_supplied_access_token() -> SuppliedTokenResolution {
}
} else {
let read = Filesystem.Read(path: path)
classify_supplied_token(success: read.success, error: read.error, content: read.content)
classify_supplied_token(read: filesystem_read_outcome(content: read.content, success: read.success, error: read.error))
}
}
}
Expand Down
19 changes: 13 additions & 6 deletions dag/gunbc/auth/approval_gate.dag
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,13 @@ import std.scoped_authorization {
AuthorizationRequest, ScopedAuthorization, authorize, AuthorizationPermitted, AuthorizationRefused, authorization_refusal_reason,
}
import extdeps.clock { Clock }
import extdeps.filesystem.filesystem_io { Filesystem }
import extdeps.filesystem.filesystem_io {
Filesystem,
FilesystemReadOutcome,
FilesystemReadRefused,
FilesystemReadSucceeded,
filesystem_read_outcome,
}
import extdeps.http.client
import extdeps.tools.sleep { sleep_delay_seconds_second_carrier_projection }
import extdeps.github.actions_environment { github_runner_temp_variable_name }
Expand Down Expand Up @@ -252,10 +258,11 @@ fn approval_file_stored_request(stored: StoredApprovalRequest, body_file_name: S
ApprovalFilingRefused { reason: join([approval_submission_mac_key_path_env as String, " is unset; the request cannot be filed"], "") }
} else {
let key_read = Filesystem.Read(path: sub_path)
if !key_read.success {
ApprovalFilingRefused { reason: join(["submission MAC key unreadable: ", key_read.error], "") }
} else {
match sign_stored_request(key_material: trim(s: key_read.content), request: stored) {
match filesystem_read_outcome(content: key_read.content, success: key_read.success, error: key_read.error) {
FilesystemReadRefused { error } =>
ApprovalFilingRefused { reason: join(["submission MAC key unreadable: ", error], "") }
FilesystemReadSucceeded { content } =>
match sign_stored_request(key_material: trim(s: content), request: stored) {
SubmissionMacKeyNotHex { key_id: k } => ApprovalFilingRefused { reason: join(["submission MAC key is not hex: ", k as String], "") }
SubmissionMacReady { tag_hex: tag } => {
let tmp = actions_variable_trimmed(name: github_runner_temp_variable_name as NonEmptyStr)
Expand All @@ -274,6 +281,6 @@ fn approval_file_stored_request(stored: StoredApprovalRequest, body_file_name: S
}
}
}
}
}
}
}
Loading