Repository navigation
extdeps gcp.SecretManager: wire types carry GCP's real JSON keys (native broker class D) - #13147
Merged
Merged
Conversation
…response shapes
Native emission projects typed REST outputs through the declared 200 body, and
five paths did not resolve because the model disagreed with the upstream
(Secret Manager v1): createTime, destroyTime, nextPageToken and totalSize had
no camelCase from-keys, and AccessVersion declared its 200 body as the bare
SecretPayload { data: Bytes } where GCP returns AccessSecretVersionResponse
{ name, payload { data: base64 string } }. ListVersions.next_page_token and
DestroyVersion.destroy_time become Optional, because GCP omits them (last page,
delayed destruction); neither has a consumer.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
approved these changes
Oct 3, 2026
briansrls
left a comment
Contributor
There was a problem hiding this comment.
LGTM. The wire model now matches Secret Manager's REST shape: camelCase JSON keys, the AccessSecretVersionResponse envelope, base64 text at payload.data, and Optional outputs where the response can omit destroyTime or nextPageToken. This fixes the model at its owning boundary rather than weakening the emitter.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Native broker wave 2D (program: gentle-dove-36), class D, part 1 of 2.
Re-derivation (DESIGN §6b)
Class D on the broker probe is
REST typed response path could not be resolved against declared 200 body(v1.compiler.emit_rustemit_typed_wire_field_assign). Reading the slice shows it is two defects:frompath through it. Only a wire field's ownfromkey names its JSON key, and the rest ofextdeps.cloud.gcpalready carries camelCase keys (gcp.dag,iam.dag). Insecret_manager,GcpSecret.create_time,GcpSecretVersion.create_time/destroy_timeandListSecretVersionsResponse.next_page_token/total_sizecarried none, so serde would read"create_time"from a body that says"createTime".AccessVersiondeclared its 200 body as the bareSecretPayload { data: Bytes }, where the API returnsAccessSecretVersionResponse { name, payload: { data } }anddatais base64 text. The earliest unjustified boundary is the extdeps model (DESIGN §3: model what the API actually returns). The emitter is not touched.outcome: RestOutcomehas no native lowering at all. Ruled model-first by gentle-dove-36 and staffed as lane 2R (gentle-bee-744), with this lane's trace handed over.Change (
dag/extdeps/cloud/gcp/secret_manager.dagonly)from "createTime",from "destroyTime",from "nextPageToken",from "totalSize"on the wire fields.AccessSecretVersionResponse { name, payload: SecretPayload }is AccessVersion's 200 body.SecretPayload.dataisString(base64 on the JSON wire; decoding stays indecode_sm_access_version_payload_wire).SecretPayloadhad no other consumer.ListVersions.next_page_tokenandDestroyVersion.destroy_timeoutputs becomeString?. GCP omits the token on the last page anddestroyTimeunder delayed destruction; the wire already declared both Optional. Neither output has a consumer.SmRotationSchedule.rotation_period_seconds. GCP'srotationPeriodis a Duration string ("86400s"), so afromkey there would assert a false wire fact. It is unconsumed and left as is.Evidence (broker probe, one remote dispatch, local-only 1B hoist)
gunbc compile --entry dag/gunbc/auth/approval_broker_serve.dag --target rustthencargo check, at fd30a50 with and without this model change (measured together with #13154, whose files are disjoint):createTime,destroyTime,nextPageToken,payload/data,name).expected String, found Option<String>at DestroyVersion. The model fix above (destroy_time: String?) landed after that measurement and is not yet re-probed.GetVersionetag: Stringvs wireetag: String?E0308. Settling it needs a citation for whether GCP always returns a version etag, so it is left out of this PR.Interpreter route:
map_response_to_value_jsonwalks the outputfrompaths over the JSON body, and the declared 200 type does not enter it. The access/rotation witnesses construct output fields directly, so none of them reads a changed declaration.🤖 Generated with Claude Code