Repository navigation
power-on account slice B2: pre-power hpm check firmware readback bound to the admitted attempt - #13302
Conversation
….32) Verbatim stdout of 'ipmitool -I lanplus -H 192.168.1.228 hpm check', taken on 2026-10-02 by eager-gull-22 from srv1 as the baseline before the vendor-set reflash (srv1 ~/mtc-fw/baseline/hpm_check.txt, mtime 2026-10-02T23:02Z). It is the only full hpm-check table captured: Active/Backup/Deferred per component (BOOT 0.32, APP 0.32 01112100, BIOS 0.00, CPLD 0.32 9D380300, BOOTFW 0.00). It shows the BMC's state BEFORE the 0.45.3 reflash, so it is not the current reading. Its consumer is slice B2's hpm-check parser (calm-lynx-884), as the layout fixture. A current post-reflash capture is owed when the BMC is reachable again. sha256 689624b261a32784a3a7d0373b1f05cfd7a46c1cff63e1ff761736cd9184a590 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…endor-set reflash Verbatim stdout of the four 'ipmitool hpm upgrade' runs eager-gull-22 made from srv1 on 2026-10-02 (BMC 23:07Z, BIOS 23:19Z, SCP 23:25Z, MB CPLD 23:54Z), from srv1 ~/mtc-fw/*-flash.log. They are evidence for the per-component row names the BMC prints. The CPLD run came after the BMC moved to 0.45, and its row is '|* 5|CPLD | 4.00 ... | 6.00 ...', not 'MB CPLD', the name the firmware converge's readback route uses. The consumer is calm-lynx-884's CPLD readback-name fix, which adds the hpm-check reader; it is the named first reader. 21acbc7132f918dd5165a6aa0e302d35e70b074f5d9b61eba33310d14794ecfa mtcollins1-bios-hpm-upgrade-2026-10-02.log 82db1295e7f188107649be8c33dcbb907f81e59745571c1db3677ce2c3c7f056 mtcollins1-bmc-hpm-upgrade-2026-10-02.log 9c0e240c42fa342c5c03f39b3f19104b3f92a1d13861668d3239a8b186556cb7 mtcollins1-cpld-hpm-upgrade-2026-10-02.log cf278412634514bab9d44c34b592f916914ff92779ae294915639d2917cb116e mtcollins1-scp-hpm-upgrade-2026-10-02.log Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…github.com/gunb-ai/gunbc into session/calm-lynx-884-cpld-name
…ntroller prints (CPLD), read through a typed hpm check selection that refuses an unlisted name Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…from aux byte 0, never invented); strict cell grammar and duplicate refusals; consumer-frontier row for the missing production hpm check read Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… attempt Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ower read joined (3 -> 2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head b36381e55c8ea4d01b7d6a93c889586f0867cfcc, against DESIGN.md §§3, 3d, 4b and 5 and power-on-sequence-model.md §12's explicit cross-attempt guarantee.
The production call ordering is right: admission precedes HpmCheck, which precedes the baseline and actuation. The operation is authenticated/deadline-bounded/read-only, failed reads preserve their cause, active cells keep their uninterpreted auxiliary bytes, and the dry BMC capture is honestly a layout fixture. B3 is explicitly deferred; I am not asking B2 to discharge #13254's separate post-flash FirmwareConverged frontier.
The remaining blocker is that the new 'join' does not bind the read to an attempt. PrePowerFirmwareRead contains only caller-authorable source text and rows. mtcollins1_boot_hpm_check receives no admitted attempt or subject carrier. attempt_configuration_with_pre_power then unconditionally copies c.attempt onto whichever rows it is supplied. A genuine reading obtained during A can be passed with B's genuine configuration and becomes FirmwareReadBeforeActuation { attempt: B, ... } without a read for B. Authored/fixture rows can take the same route. configuration_questions then treats that arm as recorded without consulting the attempt/source fields.
This contradicts §12: a readback from another attempt cannot fill this one. The new control checks that the copied output label equals n42; it does not discriminate the cross-attempt substitution.
Bind the successful read at its real producer to the admitted subject/attempt (or confine the complete read-and-join so an independently supplied successful population cannot enter it). Preserve that bound identity through the join and reject a mismatch instead of assigning a new identity. Supplied table controls should remain pure projections/classifiers rather than exporting the production observed standing. Add a RED using A's otherwise valid reading with B's configuration, alongside the B-with-B positive and unread refusal. No need for an additional provider-effect path or a B3 implementation.
Source/receipt review only; no controller reads, power actions, or local tests were performed by this reviewer.
…n refuses another attempt's reading instead of relabelling it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 615927d85b565e6f2580e608e36593c5ad8079bb, against DESIGN.md §§3, 4b and 5 and power-on-sequence-model.md §12. One remaining construction bypass; the join repair itself is accepted.
Accepted: PrePowerFirmwareReading is sealed; the production read passes its clearance into the restricted pre_power_firmware_observed; the admitted receipt nonce (or the no-receipt run identity) labels the reading at that producer; the join checks both host and attempt and preserves the reading's own identity rather than assigning the configuration's. hpm_firmware_projection is a pure table projection. The B-with-B, A-with-B and unread control now discriminates the relabel defect. The existing admission → read → baseline → actuation ordering remains intact.
Remaining blocker: test.claim.host_boot_attempt_admission_witness::observed_for is an unrestricted sanctioned-constructor proxy. pre_power_firmware_minted admits it, and it returns PrePowerFirmware containing the sealed production reading from the retained 0.32 fixture for ANY supplied attempt. An outside caller holding B's mtcollins1 configuration can therefore call:
attempt_configuration_with_pre_power(
c: b,
firmware: observed_for(attempt: b.attempt),
)
That reaches FirmwareReadBeforeActuation without a clearance or an HpmCheck for B. No forged record literal or direct call to either restricted mint is needed. The new equality check correctly rejects an A-labelled value; it cannot reject a fixture that the public helper has already minted with B's label. Thus the earlier requirement that supplied controls not export the production observed standing remains unmet.
Minimal repair: delete observed_for, admit the exact Bool-returning test a_firmware_reading_joins_only_the_attempt_it_was_taken_for to pre_power_firmware_minted, and make the two fixture mints inside that test. Alternatively, confine the helper to that exact test, with no unrestricted carrier-returning wrapper above it. Keep the repaired join and its relabel mutation control. Add an outside-caller compiler RED for the surviving fixture-mint/helper boundary, paired with the admitted internal control; testing only a sealed record literal would miss this path.
No B3 implementation, new live operation, or separate post-flash FirmwareConverged work is requested. This is limited to closing the exported fixture carrier.
Reviewed the complete PR diff, the one-commit correction from b36381e55c8ea4d01b7d6a93c889586f0867cfcc, exact-head DESIGN, the admission producer and the witness helper. The reported 15/15, 29/29, 35/35 and 71/71 results and relabel mutant are author-reported; I did not execute local tests or any controller/power action. Exact-head witnesses run 37248246259 is still in progress; the finding is independent of its result.
… one join claim; compile-time RED for an outside caller Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head 147963d547aff5b5b19a5b43f88fca8be304e177, against DESIGN.md §§3, 4b and 5 and power-on-sequence-model.md §12. The remaining fixture-constructor bypass from review 5409013978 is closed.
Reviewed the complete one-commit, three-file delta from 615927d85b565e6f2580e608e36593c5ad8079bb. DESIGN.md and the previously accepted production read, host/attempt join, refusal behavior and ordering are unchanged.
observed_for is deleted. The only admitted test caller of pre_power_firmware_minted is now a_firmware_reading_joins_only_the_attempt_it_was_taken_for, and both supplied readings are minted and consumed inside that Bool-returning claim. No fixture reading escapes through a carrier-returning witness facade. The production caller remains pre_power_firmware_observed, itself confined to the actual HpmCheck reader.
The new enrolled compiler probe calls the surviving mint from an outside module and requires a blocking ConstructorCallAdmissionRefused keyed to pre_power_firmware_minted, not merely a closure-wide diagnostic count. The public classifier/join control requires zero of that same refusal, and CensusNotRunnable cannot satisfy either assertion. The reported admit-list-removal mutant makes the outside-call RED fail. The existing B-with-B positive, A-with-B refusal and unread case remain intact; the join still preserves the reading's own identity instead of relabelling it.
This approves B2's bounded firmware-read implementation. It does not discharge B3, establish current hardware firmware from the dry 0.32 fixture, or retire the separate post-flash FirmwareConverged frontier.
Source/delta review only: admission 15/15, seal 2/2 and the mutation result are author-reported; I did not execute local tests or controller/power actions. Exact-head witnesses run 37249531401 remains in progress. No semantic blocker remains; land after required exact-head CI passes. The requested head was unchanged immediately before submission.
Slice B2 of
docs/plans/power-on-sequence-model.md§12: the firmware readback before power-on, tied to the attempt admission admitted. This is the firmware-only scope agreed with eager-gull-22; the controller-population reading (B3) waits on a retained mtcollins1 Redfish capture. Main already has B1 (#13230) and thehpm checkparser (#13254).What it adds
extdeps.bmc.ipmiHpmCheck, a read-only, deadline-boundedipmitool hpm check.gunbc.machine_intake_mtcollins1_boot_diagnostic_bundlemtcollins1_boot_hpm_checkreads the table throughextdeps.bmc.ipmitool_hpm_check. A failed read carries the controller's own cause.gunbc.host_boot_attempt_admissionpre_power_firmware_of_hpm_checkandattempt_configuration_with_pre_powerjoin the reading to the frozen configuration asFirmwareReadBeforeActuation { attempt, source, rows }.attemptis the attempt admission bound.NotRecordedwith its cause.gunbc.machine_intake_mtcollins1_boot_run,mtcollins1_boot_pre_powerruns afterBootAttemptClearedand before actuation, beside the SDR/SEL baseline. A refused receipt reads nothing.gunbc.bmc_dry_realization) answersHpmCheckwith the retained BMC 0.32 capture, as a layout fixture.Evidence (local
claim_batch)the_hpm_check_table_is_bound_to_the_admitted_attempt_and_an_unread_one_stays_not_recorded)🤖 Generated with Claude Code