Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion .github/workflows/fleet-converge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,11 @@ on:
required: false
type: string
transaction_nonce:
description: Operator-minted unique nonce for one RLM transaction; echoed into run-name so each dispatched run is API-selectable by its displayTitle, closing the run-id correlation gap (review 5062738052 B4). Not consumed by any step
description: "Operator-minted unique nonce for one RLM transaction; echoed into run-name so each dispatched run is API-selectable by its displayTitle, closing the run-id correlation gap (review 5062738052 B4). mtcollins1_boot only, when attempt_receipt is named: it is the boot attempt's identity, joined to the receipt's attempt and consumed once (gunbc.host_boot_attempt_admission), so a nonce admits one boot; [A-Za-z0-9_-] only"
required: false
type: string
attempt_receipt:
description: "mtcollins1_boot only: a committed artifacts/receipts/*.json naming this attempt's plan and the operator's inspection (gunbc.host_boot_attempt_admission). Empty records the configuration as not recorded; a named receipt that fails any check refuses the boot before power-on. Requires transaction_nonce"
required: false
type: string
jobs:
Expand Down Expand Up @@ -2341,6 +2345,8 @@ jobs:
env:
WIF_ACCESS_TOKEN: ${{ steps.wif_auth.outputs.access_token }}
FLEET_CONVERGE_EXPECTED_HOST: ${{ github.event.inputs.host }}
GUNBC_BOOT_ATTEMPT_RECEIPT: ${{ github.event.inputs.attempt_receipt }}
GUNBC_BOOT_ATTEMPT_NONCE: ${{ github.event.inputs.transaction_nonce }}
if: github.event.inputs.mode == 'mtcollins1_boot'
timeout-minutes: 134
- name: Upload Mt. Collins unit 1 boot SOL capture and receipts
Expand Down
19 changes: 19 additions & 0 deletions dag/extdeps/git/inspect.dag
Original file line number Diff line number Diff line change
Expand Up @@ -148,6 +148,9 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
// later stage -- and it carries the object id, so a population read out of a revision can name each
// member by content identity instead of by path alone.
//
// ListTreeEntryAtPath is the same record for ONE path: a consumer that needs one file's mode and
// object id at a revision asks for that path rather than enumerating the tree.
//
// BOTH OPERATIONS SURVIVE. A consumer that only needs paths pays neither the wider output nor the
// parse, and asking for identity when you wanted names is the same collapse ResolveRefCommit and
// ShowTree are kept apart to prevent. The record separator is NUL and the fields are separated by
Expand Down Expand Up @@ -361,6 +364,22 @@ service git.Inspect {
}
}

operation ListTreeEntryAtPath {
requires opaque
input { ref: GitRef, path: String }
output {
entries_nul: String from "stdout"
success: Bool from "exit_success"
stderr: String from "stderr"
}
readonly
transport shell { argv: ["git", "ls-tree", "-z", "{ref}", "--", "{path}"] }
exit {
0 => Unit
128 => String "Invalid ref or not a git repository"
}
}

operation GrepMatchesAtRevision {
requires opaque
input { pattern: String, ref: GitRef, pathspec: String }
Expand Down
5 changes: 5 additions & 0 deletions dag/gunbc/ci/ci_layer_roots.dag
Original file line number Diff line number Diff line change
Expand Up @@ -1089,6 +1089,11 @@ data witness_exclusion_frontier: List<WitnessExclusionRow> = [
classification: LocalRepoWetLane,
reason: excl_local_repo_wet_tempdir_write_reason,
dissolution: excl_local_repo_wet_dissolve},
WitnessExclusionRow {
pattern: "host_boot_attempt_admission_wet_witness_test.dag",
classification: LocalRepoWetLane,
reason: excl_local_repo_wet_tempdir_write_reason,
dissolution: excl_local_repo_wet_dissolve},
WitnessExclusionRow {
pattern: "durable_cas_file_store_wet_witness_test.dag",
classification: LocalRepoWetLane,
Expand Down
12 changes: 11 additions & 1 deletion dag/gunbc/fleet/fleet_converge_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,7 @@ import gunbc.auth.ci_app_key_rotation {
app_key_verify_receipt_path,
}
import gunbc.machine_intake_mtcollins1_boot_run { mtcollins1_boot_artifact_glob, mtcollins1_boot_step_timeout_minutes }
import gunbc.host_boot_attempt_admission { boot_attempt_receipt_env_name, boot_attempt_nonce_env_name }
import gunbc.runner_group_restriction_ensure_run { microvm_runner_group_ensure_artifact_glob, microvm_runner_group_step_timeout_minutes }
import gunbc.ci_spec {
site_pxe_edge_converge_receipt_path,
Expand Down Expand Up @@ -2807,6 +2808,8 @@ fn fleet_converge_mtcollins1_boot_step() -> Step {
env: Present { value: [
kv(key: "WIF_ACCESS_TOKEN", value: yaml_string(s: "${{ steps.wif_auth.outputs.access_token }}")),
kv(key: fleet_converge_expected_host_env_name, value: yaml_string(s: "${{ github.event.inputs.host }}")),
kv(key: boot_attempt_receipt_env_name as String, value: yaml_string(s: "${{ github.event.inputs.attempt_receipt }}")),
kv(key: boot_attempt_nonce_env_name as String, value: yaml_string(s: "${{ github.event.inputs.transaction_nonce }}")),
] },
working_directory: none,
if_condition: Present { value: fleet_converge_mtcollins1_boot_step_if },
Expand Down Expand Up @@ -4493,7 +4496,14 @@ data fleet_converge_dispatch_inputs: List<DispatchInput> = [
},
DispatchInput {
name: "transaction_nonce",
description: Present { value: "Operator-minted unique nonce for one RLM transaction; echoed into run-name so each dispatched run is API-selectable by its displayTitle, closing the run-id correlation gap (review 5062738052 B4). Not consumed by any step" },
description: Present { value: "Operator-minted unique nonce for one RLM transaction; echoed into run-name so each dispatched run is API-selectable by its displayTitle, closing the run-id correlation gap (review 5062738052 B4). mtcollins1_boot only, when attempt_receipt is named: it is the boot attempt's identity, joined to the receipt's attempt and consumed once (gunbc.host_boot_attempt_admission), so a nonce admits one boot; [A-Za-z0-9_-] only" },
required: false,
default: none,
type: InputString,
},
DispatchInput {
name: "attempt_receipt",
description: Present { value: "mtcollins1_boot only: a committed artifacts/receipts/*.json naming this attempt's plan and the operator's inspection (gunbc.host_boot_attempt_admission). Empty records the configuration as not recorded; a named receipt that fails any check refuses the boot before power-on. Requires transaction_nonce" },
required: false,
default: none,
type: InputString,
Expand Down
Loading