Repository navigation
Spark remote legs carry a liveness deadline; a leg that never began is typed dark-or-down undecided - #13204
Merged
Conversation
…s typed dark-or-down undecided Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ng readback for LegNeverBegan Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…run and projects to ArgvLegMayHaveRun (review of #13204) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sumed by pair_serving_apply and spark_remote_run (review 75397) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…vider gate) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ayHaveRun Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
…the generic load runner; SparkRemoteRun RemoteUnreachable gained reach (#13204), this branch's matches name it; fleet-converge.yml regenerated next Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lessons A1 and A3 from the 2026-10-03/04 Spark Group A bring-up (
node://adhoc-f0195bdb-ef2).A1 — every fleet ssh leg carries a liveness bound, not only a connect bound.
ServerAliveIntervalandServerAliveCountMaxinextdeps.ssh.client_options, cited from ssh_config(5).gunbc.fleet_known_hosts_anchorfleet_ssh_leg_deadline(connect 10 s, keepalive 15 s × 4).fleet_ssh_leg_deadline_optionsis the one source of the deadline words for both fleet shapers (shape_fleet_ssh_execandfleet_ssh_password_client_options). The inlineConnectTimeout=10is deleted.gunbc.spark.model_snapshot_materializespark_remote_run→gunbc.fleet_bootstrap_principal_session→ the shapers.A3 — "LAN leg dark" vs "host down", typed honestly, and no "did not run" for a leg that may have run.
SparkRemoteRun.RemoteUnreachablenow carriesreach: SparkLegUnreachability, with two arms:LegNotAttempted: nothing was sent. This is the only arm that projects toArgvLegDidNotRun.LegBeginUnobserved: ssh exited with its own 255 and the in-band began-line never ARRIVED.gunbc.spark.host_effect_quiescenceArgvRungains a third arm,ArgvLegMayHaveRun.spark_argv_run_of_unreachableis the one projection. It sendsLegBeginUnobservedtoArgvLegMayHaveRun, never toArgvLegDidNotRun.ArgvRunconsumer handles the new arm:host_effect_quiescenceandgunbc.compute.host_occupancytreat it as unread (newHostOperationResultUnreceived), andfleet_wireless_linkrefuses with "read back before retrying".host_occupancy_admissionnow goes through the same projection.HostDownarm. From one ssh leg the executor cannot tell a dark wlP9s9 from a host that is off, so the cause text says "the command MAY HAVE RUN; management LAN leg dark or host down, UNDECIDED".gunbc.spark.pair_serving_applyinto newgunbc.spark.remote_leg_began. Bothpair_serving_applyandspark_remote_runconsume it, so there is one marker string and one parser (no stderr-sniffing, pergunbc.command_runnerssh_exit_255_conflation_dissolution). It is stripped before any consumer sees stdout.RemoteRanwith 255.Witnesses (claim_batch on BuildBuddy, all PASS):
test.claim.spark.spark_remote_leg_deadline_witness_test, 10 claims:LegBeginUnobserved;LegBeginUnobservedprojects toArgvLegMayHaveRun, neverArgvLegDidNotRun(reverting the projection reds it);LegNotAttemptedprojects toArgvLegDidNotRun;native_serving_resumable_apply_witness_test(22, thepair_serving_applyconsumer of the shared protocol) passes after the lift. Re-run after the repair and passing:host_occupancy_admission_witness_test(15),fleet_wireless_link_witness_test(16),pair_serving_d0_release_witness_test(22). Earlier on this branch:ssh_client_options_witness_test(8),serving_load_probe_witness_test(40, includes the updatedRemoteUnreachableconstruction),spark_bootstrap_password_session_witness_test(2).Ledger:
gunbc.recurring_failure_modea_dark_management_lan_leg_hangs_and_reads_as_a_down_host.an_unreached_effect_leg_reads_as_one_that_ran_and_refusedrecordsspark_remote_run's progress, and that the same may-have-run residue applies to its own Unreached reading.Residue, stated:
extdeps.bmc.openbmc_password_ssh_transportandextdeps.ssh.password_sessionCopyFile still carryConnectTimeoutonly, as transport literals. They are the new row's next-rung trigger. They are not Spark legs.🤖 Generated with Claude Code