Skip to content

Spark wireless link: auth-retries 0, disconnected-no-secrets named, srv12 rostered with a coverage join - #13199

Merged
gunbai-bot[bot] merged 2 commits into
mainfrom
session/clever-deer-249-wireless
Oct 4, 2026
Merged

gunbai-bot[bot] merged 2 commits into
mainfrom
session/clever-deer-249-wireless

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Lessons A2 and B from the 2026-10-03/04 Spark Group A bring-up, turned into facts that code actually reads (node://adhoc-f0195bdb-ef2).

A2 — a failed handshake or activation keeps retrying instead of stopping.

  • extdeps.networkmanager.nmcli NmRetryBudget is one decoding (-1 global default, 0 without limit, n a count) used by two properties, both cited from nm-settings-nmcli(5), read 2026-10-04:
    • connection.auth-retries: the default is 3 attempts, and "Connections using a pre-shared key to authenticate will only prompt for a new key during the last authentication attempt". A headless host has no agent to answer that prompt, which matches the "no secrets: No agents were available" seen on srv8 and spark-3336 on 2026-10-03. With 0 there is no last attempt.
    • connection.autoconnect-retries: the default is 4 autoactivation attempts "before giving up", after which autoconnect is blocked until a timeout. "Zero means forever."
  • Both are desired values on every row (spark_wireless_auth_retries, spark_wireless_autoconnect_retries). Each goes through the full chain: observed → planned (WirelessLinkPlan.auth_retries / .autoconnect_retries) → applied (nmcli connection modify <uuid> connection.<prop> 0) → read back and re-decided, inside the existing spark_wireless_link_converge mode.
  • Observe names LinkDisconnectedNoSecrets. It comes from nmcli -g GENERAL.STATE device show (30 = disconnected) combined with the count of "no secrets" lines in journalctl -u NetworkManager -b, and appears in the receipt as standing=DISCONNECTED-NO-SECRETS(...).

The governing profile is read from the device (review of this PR).

  • observe_wireless_link first reads nmcli -t -f UUID,DEVICE,NAME connection show --active (nm_active_connection_on). It then reads every persisted setting (powersave, auth-retries, autoconnect-retries) from the profile ACTIVE on wlP9s9, by UUID, never from the desired profile's name.
  • The plan names that UUID, and every modify lands on it.
  • No active profile, a different active profile, or an unreadable listing → the decision refuses, by name. A profile other than the governing one can no longer read as converged.

B — the spark-2196 power-save "regression" was a roster gap, not drift.

  • spark-2196 is srv12. wireless_link_desired_rows left it out ("radio not measured"), so no converge ever ran there.
  • Its profile never carried 802-11-wireless.powersave, so Ubuntu's conf.d/default-wifi-powersave-on.conf (wifi.powersave = 3) applied. Latency was 165 ms vs 11 ms after the fix.
  • Host read on spark-2196, 2026-10-04 ~03:20Z, by valiant-crab-775:
    • wlP9s9, active profile Verizon_39TTYV uuid a653b65d-…, netplan-generated in /run.
    • auth-retries and autoconnect-retries both -1.
    • An nmcli modify is written back to /etc/netplan/90-NM-…yaml, so it persists.
  • srv12 now has a row. wireless_link_uncovered_spark_hosts joins the rows against gunbc.spark.dgx_procurement dgx_spark_procurement_intent.reserved_identities by identity.

Witnesses: test.claim.fleet.fleet_wireless_link_witness, 27/27 PASS via claim_batch on BuildBuddy.

  • witness_desired_profile_correct_active_profile_drifting_is_drift: the name lookup answers disable, the active UUID answers enable. It must not read as converged, and it refuses at readback because the pure runner cannot change state.
  • witness_default_autoconnect_retries_is_drift_planned_to_zero and witness_default_auth_retries_is_drift_planned_to_zero: still at the upstream default -1 → planned to 0 on the governing UUID.
  • witness_a_different_active_profile_refuses, witness_no_active_profile_refuses, and the active-listing parser (interface row picked, \: unescaped, two profiles on one device unreadable).
  • witness_every_procured_spark_has_a_wireless_row (deleting srv12's row reds it), the no-secrets standing and its negatives, and the existing converge-route claims rewired to the UUID reads.

Ledger: gunbc.recurring_failure_mode a_host_absent_from_a_converge_roster_silently_keeps_the_upstream_default, including the read-by-name sibling found in review.

Not done here, stated:

🤖 Generated with Claude Code

Brian Searls and others added 2 commits October 4, 2026 03:26
…sconnected-no-secrets named, srv12 rostered with a coverage join

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s read from the profile active on the interface (review of #13199)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 5446743 Oct 4, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/clever-deer-249-wireless branch October 4, 2026 08:52
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
…ayHaveRun

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants