Repository navigation
R2 If-Match race probe: the instrument that grounds r2_conditional_put_linearizability - #13398
Conversation
From the federated mint runs 37291106411 (read) and 37292959180 (write): secret version 1 of
cloudflare-r2-workspace-{read,write}-token, access key ids = token ids from the receipts
(r2_s3_access_key_is_created_token_id_citation). fabric_workspace_standing is now
OriginCredentialPinned for both; witness asserts the exact pins. 32/32, 18/18, 8/8.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t_linearizability extdeps.tools.curl models -Z/--parallel-immediate (one invocation, two labelled transfers sharing one netrc, per-transfer status and timing) and DeleteObject; gunbc.cloudflare.r2_conditional_put_race_probe seeds a probe key, races two If-Match PUTs on its tag per round, folds the answers into passed / falsified / inconclusive (non-overlapping splits prove nothing), deletes the key and writes a receipt. Fleet-converge mode r2_conditional_put_race_probe runs it and uploads the receipt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77021:
— sent from cool-wren-269 |
…do not fit the aux 5m) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…_one) for r2_conditional_put_race_probe Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he path actually spells (review 77032) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… durations; gate on the read curl version
The per-transfer %{time_*} offsets share no origin (each is relative to its own easy handle's start),
so the duration predicate could pass sequential pairs. The parallel invocation now writes
--trace-ascii --trace-time --trace-ids into the round's private directory; extdeps.tools.curl reads
it as events on one process clock (monotone over every stamped line, header bytes dropped), and the
probe derives RaceOverlap from the bodies' sends and the first answers. curl --version is read and
compared against curl_trace_ids_cli_tool's 8.2 floor via extdeps.version.semver before any round, and
the observed version and the client-side limit are in the receipt.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…latest send is optional, not -1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…omparison; number rounds by enumerate (review 77083) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77083:
— sent from cool-wren-269 |
…-compile cannot resolve (Present/Absent are prelude there, as in extdeps.tools.curl) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…probe's optional imports to std.optional Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dential options; review 77168) and the extdeps_version_semver.rs stage0 mirror Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77168: correct, and fixed in 5ec34ab. The merge commit had kept the branch's side of the generated fleet-converge.yml, which predated main's ClaudeCodeOauthHarnessToken option. The file is now regenerated on the merged head through — sent from cool-wren-269 |
…rl_trace_kind_is (review 77176) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77176:
— sent from cool-wren-269 |
…eview 77181) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77181: correct, fixed in c6867d4. — sent from cool-wren-269 |
…and-rolled accumulator (review 77183) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
On review 77183: changed in 83b5369. — sent from cool-wren-269 |
…semver-precedence Conflict: main's #13398 added semver_core_of_dotted / semver_dotted_part / semver_minimum_of_constraint building SemVerVersion with NonNegativeInt fields, against this branch's retype of the fields to confined SemVerNumericField records. The port keeps main's semantics and tightens them where the confined constructor is the authority: parts are admitted through semver_numeric_field (an empty patch is the single digit 0), so a fourth part, a non-digit, a leading zero, or a negative is absent, never coerced. curl.dag and the r2 probe consume the Optional/label surfaces only, so they are type-transparent. Parse-check 0 blocking on curl, the r2 entry, and the semver witness entry.
What this builds. The discriminating run that
extdeps.cloudflare.r2r2_conditional_put_linearizability's read_obligation names. This PR does NOT change that row. A follow-up flips it only on a passing receipt, and only if the receipt shows: curl >= 8.2 observed, declared_rounds=200, rounds=200, verdict=passed, and zero inconclusive rounds.How a round works (
gunbc.cloudflare.r2_conditional_put_race_probe, loop in.dag, run in-process bygunbc run):probe/r2-conditional-put-race/headin the workspace bucket, never a head) with an unconditional PUT and read back its ETag.-Z --parallel-immediate). Both transfers read the one netrc placed throughgunbc.cloudflare.r2_s3_netrcfromfabric_workspace_standing's pinned write credential, which is shredded after.Overlap is a fact read on one clock (route 3), never inferred from durations. curl's per-transfer
%{time_*}values are offsets from each transfer's own start and share no origin, so they cannot show overlap. Instead the same invocation writes--trace-ascii --trace-time --trace-idsinto the round's private directory.extdeps.tools.curlcurl_trace_readingparses it into events stamped by the one process clock.RaceOverlapis Established only if both writers' last body send precedes both first response headers.Verdict, a pure fold (
race_probe_verdict):Version gate. A new row,
curl_trace_ids_cli_tool(>= 8.2, for--trace-ids), joins the existing curl pin family. The run readscurl --versionand compares it to that row's own floor throughextdeps.version.semver, which gainssemver_core_of_dottedandsemver_minimum_of_constraint, the latter admitting only a>=floor. A version below the floor, or one that cannot be read, refuses before any credential or round, and the observed version still goes into the receipt.Run route. Fleet-converge mode
r2_conditional_put_race_probe: shared job, no host scope, its own concurrency group, and its own 30-minuteDurationstep budget. It is defined ingunbc.fleet.fleet_converge_workflowandgunbc.ci.ci_spec, withfleet-converge.ymlregenerated throughtools.generated_artifact_gate main_wet_one. The receipt artifact isr2-conditional-put-race-probe-receipt. It names the transport version, the limit, each round's statuses plus its overlap fact and verdict, the cleanup result, and the final verdict.Evidence.
test.claim.r2_conditional_put_race_probe: 17/17 PASS (claim_batch on BuildBuddy). Its controls:>=constraint names a floor.extdeps.version.semver: 13/13 PASS.🤖 Generated with Claude Code