Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
71a9a1c
extdeps.systemd.systemd_run: typed options, one projection, ArgvComma…
Oct 4, 2026
bd2cd6d
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
2ab5f7c
floor-union fixes for the typed cutover: enrolment witness migrates t…
Oct 4, 2026
78cd059
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
bb7cbf8
floor-union cutover fixes: the enrolment witness re-points at the typ…
Oct 4, 2026
ebf385f
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
74eec69
restore attempt_jailer_at_launch, lost in the moved-main conflict res…
Oct 4, 2026
dc666b6
cardinality probes: negative sentinels spelled 0 - N per tree convent…
Oct 4, 2026
f342997
cardinality probe family: designed-red standing documented at the def…
Oct 4, 2026
a78f65c
merge origin/main into the systemd-run cutover before review (trial l…
Oct 4, 2026
546b230
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
529775c
runner_host_unit_slot re-pointed at the typed ephemeral_slot_command;…
Oct 4, 2026
bcfae75
cardinality controls restructured: every floor claim returns TRUE; ne…
Oct 4, 2026
6d01965
review fixes 1,2,3,4,5a: local transports take the argument tail; ret…
Oct 4, 2026
8e28d6f
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
c2108c0
review fixes 4-6 groundwork: every ComputeExec match names the refusa…
Oct 4, 2026
ee21d9c
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 4, 2026
56affb0
review fix 6: typed-builder wet claims on LocalRepoWetLane — retained…
Oct 4, 2026
4f0c70a
Move in-body comments to module-item grain (declaration errors: body …
Oct 4, 2026
e2dd286
witness test: use the merged SystemdUnitProperty variant MemoryMax (p…
Oct 4, 2026
e230ee0
user-wait byte-identity control: the retired builder emitted -p and t…
Oct 5, 2026
87466b6
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 5, 2026
2723f94
argv_exact_token_equal: move the cardinality rationale to module grai…
Oct 5, 2026
a795eea
floor diagnostics at 2723f94faf: import std.algebra trim in the wet t…
Oct 5, 2026
4ef7e8f
merge origin/main (#13208 dispatch identity, #13073 metering) into ty…
Oct 5, 2026
aae91ac
add the audit and supervisor provider-events path helpers main's mete…
Oct 5, 2026
1d33e40
belt: take main's metering tick plumbing wholesale and transplant the…
Oct 5, 2026
81b75aa
belt: transplant the worker session-container launch onto the typed b…
Oct 5, 2026
1afb9ae
review 76279: refusal causes are a typed sum (SystemdRunOptionWordsRe…
Oct 5, 2026
4607706
reset rationale to module grain
Oct 5, 2026
fbdfd1d
import lists do not admit a leading/trailing stray comma: fold the in…
Oct 5, 2026
b986e1b
floor at fbdfd1d621: the detail fn is extdeps.systemd's (belt imports…
Oct 5, 2026
5bbf8db
review 76406: SystemdSummaryPrintingWait is minted in exactly one pla…
Oct 5, 2026
66dac70
review 76430: RunTransientRetained deleted (identical contract to Run…
Oct 5, 2026
916752e
review 76455: comments cite live symbols (systemd_run_user_wait_comma…
Oct 5, 2026
ecb3bce
review 76468: ComputeExecRefused dropped from the shared ComputeExec …
Oct 5, 2026
395effc
compute_run_unit: bind the exec before constructing the executed read…
Oct 5, 2026
5175c6f
compute_run_unit returns ComputeUnitRunReading (the signature kept th…
Oct 5, 2026
7255cbb
typed_builder_wet enrolment row: the declared gap in full -- what CI …
Oct 5, 2026
04ff6fe
blocker 6 per parent decision: the wet claims no lane can execute are…
Oct 5, 2026
90f5480
review 76599: the argv-matches-authority predicates are narrow by con…
Oct 5, 2026
ec44083
side-chat blockers at 90f5480d88: (1) the manual wet receipt's start_…
Oct 5, 2026
b04ba3d
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 5, 2026
559477e
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 5, 2026
2b5b988
floor NonFoldResidueRosterDiverged remedy: the four work_provider_loc…
Oct 5, 2026
56eccaf
actuator merge casualties, per review 76810 and main's updated witnes…
Oct 6, 2026
568e828
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 6, 2026
dc09693
review 76841: spell both SystemdServiceResult projections exhaustivel…
Oct 6, 2026
6b9bbda
Merge origin/main: #13456 restores the regen fixed point (deletes ct_…
Oct 6, 2026
5a1d9d0
review 76879: the slot-controller witness comment names the live proj…
Oct 6, 2026
2e809b7
review 76883: rewire work_request witness to the typed property list …
Oct 6, 2026
cf3e87f
work_request witness: the kill-mode needle is the WIRE spelling (syst…
Oct 6, 2026
e5b33aa
side-chat blocker: the promised manager-side standing carrier actuall…
Oct 6, 2026
cb185c1
review 76953: HostUnitSlot.argv carries the full typed ArgvCommand ag…
Oct 6, 2026
29e6708
review 76958: the kill-mode value is projected, not stored — compute_…
Oct 6, 2026
c6ce015
side chat: the manager-side gap names the real manager and the real t…
Oct 6, 2026
1c268a0
Merge origin/main: re-home of v2.std.optional to std.optional (#13388…
Oct 6, 2026
75e6eaa
re-point the surviving v2.std.optional imports to std.optional — #133…
Oct 6, 2026
7464013
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 6, 2026
cd5b627
the '==' refusal rule: compare the tmux-ls first-entry through Presen…
Oct 7, 2026
cd49bd2
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 7, 2026
7a8ede1
the optional-equality refusal rule: match arms bind by name; the bare…
Oct 7, 2026
f4c164a
Merge remote-tracking branch 'origin/main' into session/witty-tern-54…
Oct 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion dag/extdeps/exec/command.dag
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,7 @@ fn argv_command(program: ProgramIdentity, arguments: List<String>) -> ArgvComman
decl_ref(module_path: "extdeps.iproute2.ip_show", decl_name: "ip_route_show_command"),
decl_ref(module_path: "extdeps.tools.uname", decl_name: "uname_release_command"),
decl_ref(module_path: "extdeps.tools.make", decl_name: "make_command"),
decl_ref(module_path: "extdeps.systemd.systemd_run", decl_name: "systemd_run_user_scope_command"),
decl_ref(module_path: "extdeps.systemd.systemd_run", decl_name: "systemd_run_command_of"),
decl_ref(module_path: "extdeps.package_managers.pip", decl_name: "pip_install_pinned_command"),
decl_ref(module_path: "extdeps.package_managers.conda_forge", decl_name: "micromamba_create_command"),
decl_ref(module_path: "extdeps.printing.orca_slicer", decl_name: "orca_slice_to_project_command"),
Expand Down
14 changes: 14 additions & 0 deletions dag/extdeps/systemd/systemd.dag
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,13 @@ type SystemdUnitProperty
| WantsProperty
| InvocationIDProperty
| FragmentPathProperty
| StandardOutputProperty
| StandardErrorProperty
| ProtectSystemProperty
| ProtectHomeProperty
| PrivateTmpProperty
| ReadWritePathsProperty
| RemainAfterExitProperty
| JobProperty

// THE WIRE SPELLING AS A SEALED WORD, SO THE CLOSED TYPE SURVIVES ALL THE WAY TO THE ARGV.
Expand Down Expand Up @@ -158,6 +165,13 @@ fn systemd_unit_property_wire(property: SystemdUnitProperty) -> NonEmptyStr {
WantsProperty => "Wants" as NonEmptyStr
InvocationIDProperty => "InvocationID" as NonEmptyStr
FragmentPathProperty => "FragmentPath" as NonEmptyStr
StandardOutputProperty => "StandardOutput" as NonEmptyStr
StandardErrorProperty => "StandardError" as NonEmptyStr
ProtectSystemProperty => "ProtectSystem" as NonEmptyStr
ProtectHomeProperty => "ProtectHome" as NonEmptyStr
PrivateTmpProperty => "PrivateTmp" as NonEmptyStr
ReadWritePathsProperty => "ReadWritePaths" as NonEmptyStr
RemainAfterExitProperty => "RemainAfterExit" as NonEmptyStr
JobProperty => "Job" as NonEmptyStr
}
}
Expand Down
406 changes: 271 additions & 135 deletions dag/extdeps/systemd/systemd_run.dag

Large diffs are not rendered by default.

41 changes: 31 additions & 10 deletions dag/gunbc/auth/approval_device_enrolment_code_issue.dag
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,12 @@ import std.process { ProcessExit, ExitSuccess, ExitFailure, exit_failure }
import std.resources { Network }
import gunbc.cli_wire { CliWireResponse, CliWirePrintable, CliWireUnprintable }
import extdeps.sudo.elevation { sudo_elevate }
import extdeps.systemd.systemd_run { SystemdRunProperty, systemd_run_system_scope_argv }
import extdeps.systemd.systemd_run {
SystemdRunProperty, SystemdRunCommandReading, SystemdRunCommandReady, SystemdRunCommandRefused,
systemd_run_system_scope_command,
systemd_run_option_words_refused_cause_detail,
}
import extdeps.exec.command { ArgvCommand, argv_words }
import extdeps.tools.util_linux_setpriv { setpriv_reuid_regid_argv }
import extdeps.systemd { MemoryMax, MemoryHigh }
import std.measure { byte_size_count }
Expand Down Expand Up @@ -79,7 +84,7 @@ fn enrolment_code_issue_ssh_target() -> SshTarget {
// typed-module cache cap is derived from the cgroup's memory.high/memory.max, and with neither bound
// it refuses HostBudgetUnreadable rather than guessing (fleet-converge run 36556990543). An SSH
// session binds no such limit. The scope is a system-manager transient scope (extdeps.systemd.systemd_run
// systemd_run_system_scope_argv) around the account drop below. A user
// systemd_run_system_scope_command) around the account drop below. A user
// scope would need that account's session bus, which the elevated command lacks. The bounds are the
// broker's own slice rows (gunbc.live_deploy.slice_bounds approval_broker_slice_memory_max and _high).
// The verb resolves the broker's routes closure, the same program the broker boots, so the same
Expand All @@ -97,7 +102,7 @@ fn enrolment_code_issue_scope_properties() -> List<SystemdRunProperty> {
// supplementary groups; systemd-run's own --uid/--gid did not, and every code was minted and then
// refused delivery (fleet-converge run 37098981121). The drop sits inside the scope so the bound
// still covers the whole verb.
fn enrolment_code_issue_remote_argv(revision: ReleaseRevisionBinding) -> List<String> {
fn enrolment_code_issue_remote_command(revision: ReleaseRevisionBinding) -> SystemdRunCommandReading {
let root = srv1_gunbc_approval_broker_root as String
let release_dir = approval_broker_release_dir(root: root, revision: revision)
let account = fleet_posix_operator_user.name
Expand All @@ -113,30 +118,46 @@ fn enrolment_code_issue_remote_argv(revision: ReleaseRevisionBinding) -> List<St
"--arg", "revision=" + release_revision_execstart_text(binding: revision),
])
let as_account = setpriv_reuid_regid_argv(user: account, group: account, init_groups: true, command_argv: verb)
let inv = sudo_elevate(command: systemd_run_system_scope_argv(properties: enrolment_code_issue_scope_properties(), command_argv: as_account))
concat([inv.bin_path], inv.args)
systemd_run_system_scope_command(properties: enrolment_code_issue_scope_properties(), command_argv: as_account)
}

fn enrolment_code_issue_refuses_off_srv1(host: String) -> ProcessExit {
if host == (operator_host_srv1 as String) { ExitSuccess }
else { exit_failure(reason: "approval device enrolment code: refuses host '" + host + "': the store lives on the machine that serves /approve, which is " + (operator_host_srv1 as String)) }
}

// The projection refuses a word the wire cannot carry, and the invocation the transport would have
// run is never minted: the caller sees the refusal's reason, not a command that failed to run --
// because it IS one.
fn enrolment_code_issue_remote(revision: ReleaseRevisionBinding) -> CliWireResponse
uses net: Network
{
match prepare_fleet_ssh_agent_context(attempt_raw: approval_device_enrolment_code_issue_attempt_raw) {
FleetSshContextRefused { cause: c } => CliWireUnprintable { cause: ("approval device enrolment code: " + c) as NonEmptyStr }
FleetSshContextReady { context: context, receipt: _ } =>
match typed_argv_exec_over_fleet_ssh(target: enrolment_code_issue_ssh_target(), context: context, argv: enrolment_code_issue_remote_argv(revision: revision)) {
TypedArgvExecRefused { reason: why } => CliWireUnprintable { cause: ("approval device enrolment code: remote invocation refused: " + why) as NonEmptyStr }
TypedArgvExecConverged { result: r } =>
if r.success { CliWirePrintable { bytes: r.stdout, exit: ExitSuccess } }
else { CliWireUnprintable { cause: ("approval device enrolment code: remote exit=" + to_string(r.exit_code) + " " + trim(s: r.stderr)) as NonEmptyStr } }
match enrolment_code_issue_remote_command(revision: revision) {
SystemdRunCommandRefused { cause: why } =>
CliWireUnprintable { cause: ("approval device enrolment code: remote invocation refused: " + systemd_run_option_words_refused_cause_detail(cause: why)) as NonEmptyStr }
SystemdRunCommandReady { command: command } =>
match typed_argv_exec_over_fleet_ssh(
target: enrolment_code_issue_ssh_target(),
context: context,
argv: sudo_elevate_words(command: command),
) {
TypedArgvExecRefused { reason: why } => CliWireUnprintable { cause: ("approval device enrolment code: remote invocation refused: " + why) as NonEmptyStr }
TypedArgvExecConverged { result: r } =>
if r.success { CliWirePrintable { bytes: r.stdout, exit: ExitSuccess } }
else { CliWireUnprintable { cause: ("approval device enrolment code: remote exit=" + to_string(r.exit_code) + " " + trim(s: r.stderr)) as NonEmptyStr } }
}
}
}
}

fn sudo_elevate_words(command: ArgvCommand) -> List<String> {
let inv = sudo_elevate(command: argv_words(command: command))
concat([inv.bin_path], inv.args)
}

// THE STEP ENTRY: one host per run, named by the dispatch and required to be srv1; one release,
// named by the dispatch.
fn approval_device_enrolment_code_issue_wet() -> CliWireResponse
Expand Down
29 changes: 19 additions & 10 deletions dag/gunbc/compute/unit_bounds.dag
Original file line number Diff line number Diff line change
@@ -1,9 +1,11 @@
module gunbc.compute.unit_bounds

import std.types { String, List }
import std.types { String, List, NonEmptyStr }
import std.nat { Nat }
import std.measure { Kibibyte, kibibyte_to_byte_size, byte_size_count, Millicore, millicore_count }
import extdeps.systemd.systemd_run { systemd_run_property }
import extdeps.systemd { SystemdUnitProperty, MemoryMax, WorkingDirectoryProperty, KillModeProperty, CPUQuota, TasksMax }
import extdeps.systemd.systemd_run { SystemdRunProperty }
import extdeps.systemd.unit_file { KillModeControlGroup, systemd_kill_mode_wire }

// THE ONE FOLD FROM A CAPACITY GRANT TO THE PROPERTIES OF THE UNIT THAT HOLDS IT. It used to live in
// gunbc.compute.work_provider_local as compute_unit_properties, and it moved here rather than being
Expand All @@ -22,8 +24,7 @@ import extdeps.systemd.systemd_run { systemd_run_property }
// declaration -- a drop-in or a future default could change it, and a provider would keep treating
// a completed wait as an empty cgroup (side-chat review at 773825cf). Binding it makes the policy a
// fact of the invocation, and an agent session releases its seat on the same reading.
data compute_kill_mode_property: String = "KillMode"
data compute_kill_mode_value: String = "control-group"
data compute_kill_mode_property: SystemdUnitProperty = KillModeProperty

// WHAT A GRANT DOES NOT CARRY, NAMED RATHER THAN INVENTED. product.capacity.pool grants MEMORY: the
// lease is an encumbrance over a Memory pool and nothing else, so a CPU quota or a task ceiling is
Expand All @@ -44,19 +45,27 @@ fn unit_cpu_quota_percent(m: Millicore) -> Nat {
millicore_count(m: m) / 10
}

fn compute_grant_unit_properties(granted: Kibibyte, working_directory: String, process_bounds: UnitProcessBounds?) -> List<String> {
fn compute_grant_unit_properties(granted: Kibibyte, working_directory: String, process_bounds: UnitProcessBounds?) -> List<SystemdRunProperty> {
concat(
[
systemd_run_property(name: "MemoryMax", value: to_string(value: byte_size_count(b: kibibyte_to_byte_size(k: granted)))),
systemd_run_property(name: compute_kill_mode_property, value: compute_kill_mode_value),
systemd_run_property(name: "WorkingDirectory", value: working_directory),
SystemdRunProperty { property: MemoryMax, value: to_string(value: byte_size_count(b: kibibyte_to_byte_size(k: granted))) as NonEmptyStr },
SystemdRunProperty { property: compute_kill_mode_property, value: compute_kill_mode_value() },
SystemdRunProperty { property: WorkingDirectoryProperty, value: working_directory as NonEmptyStr },
],
match process_bounds {
Absent => []
Present { value: b } => [
systemd_run_property(name: "CPUQuota", value: join([to_string(value: unit_cpu_quota_percent(m: b.cpu_quota)), "%"], "")),
systemd_run_property(name: "TasksMax", value: to_string(value: b.tasks_max)),
SystemdRunProperty { property: CPUQuota, value: join([to_string(value: unit_cpu_quota_percent(m: b.cpu_quota)), "%"], "") as NonEmptyStr },
SystemdRunProperty { property: TasksMax, value: to_string(value: b.tasks_max) as NonEmptyStr },
]
},
)
}

// THE kill mode the release decision relies on is the closed systemd fact KillModeControlGroup;
// its wire spelling is owned by systemd_kill_mode_wire. This layer projects, it does not store a
// second copy of the spelling (review 76958: the stored "control-group" was a parallel wire for a
// closed upstream fact).
fn compute_kill_mode_value() -> NonEmptyStr {
systemd_kill_mode_wire(mode: KillModeControlGroup) as NonEmptyStr
}
Loading
Loading