Repository navigation
runner browser toolchain: the readiness-label converge executes typed argv steps -- the retained-shell text leaves the module - #13401
Conversation
…argv steps over the host-effect transport -- the retained-shell text and its wall are gone from this module; the witness reads the plan's steps hermetically
… typed gap -- the witness reads the plans hermetically, CI cannot execute the elevated systemd legs, the removed shell path had the same posture; trigger = parameterized destination root + elevation posture (typed-argv checklist round)
…yer_roots into the route module as a typed DissolutionCondition -- review 76632: the witness file's hermetic claims stay in the discovery corpus, no LocalRepoWetLane fork for a file with no schedule entries
|
Fixed at c3477f0 — all three findings, by moving the declaration rather than defending it:
The dissolve text's now-moot ci_layer_roots/schedule references went with the deleted row. CI is running on the new head; I'll report when it lands. — sent from witty-wren-554 |
|
On the §3c question review 76654 left open: |
briansrls
left a comment
There was a problem hiding this comment.
One blocking integration defect remains.
The production caller cannot execute either new plan. browser_toolchain_admin_transport always returns FleetSsh, and runner_browser_toolchain_converge_ci_wet passes that transport to browser_ready_labels_converge_wet. But both new runners deliberately refuse that arm: run_argv_over_host_effect_transport returns RunArgvTransportRefused for FleetSsh, and run_argv_stdin_over_host_effect_transport does the same. Therefore grant refuses before tee, revoke refuses before rm, neither reload runs, and the outer converge cannot succeed once it reaches readiness-label convergence.
The old run_shell_transport also refused FleetSsh, so this does not create the dead route; it exposes that the debt was moved rather than dissolved. The new typed declaration is consequently inaccurate: it says the module's real runner-bootstrap converge executes these steps and declares only CI execution withheld, while the live production route executes none of them. Its trigger also does not close the actual capability: parameterizing the destination root and elevation posture neither supplies typed argv/argv+stdin over FleetSsh nor isolates systemctl daemon-reload from the real system manager.
Preferred repair: wire both FleetSsh cells as part of this cut. The non-stdin authority already exists as typed_argv_exec_over_fleet_ssh; the stdin substrate also already exists as exec_as_fleet_principal_with_stdin, so add the corresponding typed-argv FleetSsh sibling and map both outcomes into RunArgvTransportOutcome without fabricating exits. Then execute controls for grant and revoke through the production transport boundary.
If live realization is intentionally out of scope, the current row must instead become an explicit production-route stall naming both missing FleetSsh capabilities, and it must stop claiming the runner bootstrap executes the steps. Its restoration trigger must include a safe system-manager/reload realization, not only a scratch destination and no-sudo posture.
What passes: ArgvCommand keeps the outer program separate from arguments; sudo_elevate_command does not duplicate /usr/bin/sudo; transport refusal remains distinct from an observed nonzero exit; the grant payload stays on stdin; the revoke type has no content-write leg; and the retained-shell/text-builder imports and calls are gone. Exact-head CI is green, but it does not traverse the live FleetSsh seam.
…elevation posture -- production keeps the privileged constant under sudo, the new real-path receipts execute grant and revoke for real over LocalShell against a mktemp scratch root with the unprivileged posture (reload skipped typed); the production fleet route's FleetSsh refusal is now a declared stall (browser_ready_labels_fleet_route_stall); tee_program identity minted and the posture wrapper admitted to argv_command -- review round + manager ruling (no module-local dispatch)
…ublish realizer) stays, the browser ready-label receipts enroll as chunk_41
|
Built per the manager's ruling — no module-local dispatch, no new FleetSsh capability, the shared runners untouched. Pushed as a009c43 + c15d482 (merge of main; main's chunk_40 stays, the receipts enroll as chunk_41):
CI is queued on the new head (run 37363085250). — sent from witty-wren-554 |
…view 76729 (the revoke plan's program identity must resolve)
…at :271 stays; the admit_callers entry and the import keep resolving
…m_model's concat_lists -- '++' is comment-only spelling in this language; the emit-build Plus diagnostics and the orphaned-annotation cascade clear
…ue and splits the posture decision into its own exhaustive match -- a nested variant pattern inside a field leaves the ReadyLabelsReloadRun grant case uncovered (floor structural, witness_test.dag:89)
…roster as an AuthoredProse row with its own LegacyProseIdentity arm -- review 76839: the module-local DissolutionCondition had no fold reading it; the roster fold is the consumer, and the five-field statement carries the manager's trigger (shared FleetSsh arm admitted by the fleet_subsumption arc, no per-consumer bypass)
…er row -- the floor chunk comment, the hermetic witness's standing note, and the receipt header now name gunbc.rung_drop.browser_ready_labels_fleet_route_stall
…entry point -- the stall-row removal's line search overshot the one data row and cut the nine declarations after it (converge, admin transport, ci_wet entry, attempt/receipt rows); the module is rebuilt from a009c43 with exactly the three intended deltas (rm_program import, concat_lists, the stall moved to the rung_drop roster) -- review 76839
|
Both findings fixed and pushed:
CI is queued on 1836ee6 (run 37401007139); the deleted-slow-tests merge (#13452) should also end the rust-unit-tests 40-minute timeouts that hit two earlier runs. — sent from witty-wren-554 |
…rowser_ready_labels_fleet_route_stall row's section (sealed repair candidate from run 37401007139, base_blob 3d81b4b verified, drift is exactly the new row)
briansrls
left a comment
There was a problem hiding this comment.
One blocker remains: browser_ready_labels_fleet_route_stall is a section 4b(2) GuaranteeStall, not a section 4b(3) RungDrop.
The row's own account proves that no rung fell: the FleetSsh route never executed before this PR, the old retained-shell route refused at the same transport boundary, and the paragraph literally says PREVIOUS RUNG: none to lower. gunbc.rung_drop defines a drop as an event in which something that held stopped holding, and explicitly says a pre-existing class sitting below its attainable ceiling belongs in gunbc.guarantee_stall; forcing previous/temporary/reason onto it fabricates an event. The new row does exactly that through AuthoredProse.
AuthoredProse is also the legacy debt arm, not the right way to author a new fact. This head adds the coproduct arm and renderer but not the required legacy_prose_identity_roster member, so the supposedly closed prose universe does not even quantify over this new arm. Moving the row to the typed stall carrier deletes that problem rather than adding the missing legacy entry.
Please replace it with a rostered GuaranteeStall, using AwaitsOneGrounding for the shared FleetSsh argv + argv/stdin realization (and safe reload realization), a one-route bounded population, and a next-rung trigger that requires the shared fleet_subsumption admission plus an executing fleet receipt. Remove the rung-drop legacy arm/renderer addition and regenerate the drop projection.
The rest now passes review. The production row no longer claims bootstrap execution: it says FleetSsh grant, revoke, and reload execute nowhere and names the shared-arm trigger rather than scratch-root/no-sudo. The destination and elevation posture parameterization did land. Both LocalRepoWet claims call browser_ready_labels_converge_wet itself over LocalShell with ReadyLabelsUnprivileged and a mktemp target; grant executes tee twice and checks stable readback, revoke executes rm -f and checks failed readback. They are enrolled in local_repo_wet_schedule, the CI-layer exclusion, and floor-route-gap chunk 41. The typed reload skip is honest: these receipts prove the write/remove folds, not FleetSsh or daemon-reload. Exact-head run 37416005001 is green.
…nteeStall awaiting one grounding -- the side chat's ruling (review 5424411035): a pre-existing below-ceiling class is a stall, not an event; the rung_drop AuthoredProse row, its LegacyProseIdentity arm and the renderer section are deleted (doc regenerated back to main's state), and the GuaranteeStall (blocker AwaitsOneGrounding, population bounded at the converge over the production target, next_rung_trigger = fleet_subsumption admits the arm + safe reload + an executing fleet receipt) enrolls in gunbc.guarantee_stall.roster after the #13424 worked example
…nstead of minting words -- review 76927: tee_overwrite_command mints in extdeps.tools.gnu_coreutils next to tee_append_command (same stdin payload, same -- option-list end), revoke wraps rm_force_command, reload wraps systemctl_daemon_reload_command, elevation is sudo_elevate_command(command: argv_words(command: ...)); the argv_command admit row is dropped and the duplicated tee_program admission deduped; the receipts cast the host from the imported fleet identity instead of a raw literal
…on_reload_command as-is -- review 76937: that builder already carries the elevation (sudo -n systemctl daemon-reload), so re-wrapping spelled the privilege fact twice (sudo -n sudo -n ...); the write/remove legs still elevate their unelevated builders once
…tted-callers roster -- floor run 37427436934 refused the mint; the roster's admitted class is typed per-tool builders in each tool's own extdeps module (tee_append_command, rm_force_command, install_file_owned_command, ...), and this sibling carries its overwrite flag fact (-- option-list end, no -a) in gnu_coreutils beside the append sibling; no existing admitted builder writes a stdin payload to a named path (tee_append_command appends and would silently flip the write semantics), so the roster row is the intended route, not a workaround
briansrls
left a comment
There was a problem hiding this comment.
The stall-carrier blocker is closed. browser_ready_labels_fleet_route_stall is now a typed, rostered GuaranteeStall: it uses AwaitsOneGrounding, bounds the population to the production converge over browser_ready_labels_production_target, names the shared FleetSsh argv + argv/stdin realization plus safe reload, and requires an executing fleet receipt. The old rung-drop/legacy-prose additions are absent from the PR delta.
One blocker remains in the new argv_command admission. The premise for minting tee_overwrite_command is false: extdeps.tools.gnu_coreutils already owns and argv_command already admits dd_overwrite_path_command(path), which takes the payload on stdin, truncates the named path, and suppresses command output with status=none.
That existing builder's authority comment makes the distinction load-bearing: it deliberately uses dd rather than tee because tee echoes the payload to stdout, which carries the file contents into the command log. The deleted shell route explicitly redirected tee's stdout to /dev/null; the new typed route invokes bare tee -- PATH, so it both creates a second spelling of the same stdin-to-path overwrite operation and loses the old output-suppression behavior.
Please use dd_overwrite_path_command(path: target.dropin as String) for the grant leg, still wrapped by browser_ready_labels_posture_argv and sent through run_argv_stdin_over_host_effect_transport. Then delete tee_overwrite_command and its new argv_command admission, and update the plan/real-path word controls from tee -- PATH to dd of=PATH status=none. tee_append_command remains the distinct append operation.
All five exact-head lanes are green; they do not detect this duplicated authority/output-semantics fork.
…command -- side-chat review 5428660024: gnu_coreutils already owns and argv_command already admits dd of=PATH status=none (stdin payload, named path, truncate, exact bytes); its authority comment prefers dd over tee because tee echoes the payload to stdout, which would carry the file contents into the command log -- the deleted shell route suppressed that with >/dev/null and a bare typed tee would have lost it; tee_overwrite_command and its argv_command admission are deleted (second spelling of a modeled operation), tee_append_command remains the distinct append op; the plan witness's word control asserts dd of= + status=none (reds on a revert to bare tee)
…w 77040: excl_local_repo_wet_browser_ready_label_reason still said the wet write is tee while the converge it classifies now writes through dd_overwrite_path_command; one admitted-effect description naming two tools is the nicknaming fork (DESIGN 3) and hid the load-bearing tee-echoes-the-payload point; 'tee -a' in the neighbour enrolment-code row stays -- that is the distinct append operation
…4-pr5 # Conflicts: # dag/gunbc/ci/ci_layer_roots.dag
briansrls
left a comment
There was a problem hiding this comment.
Approved at af1b8a0.
The prior blocker is closed. The grant plan now reuses the existing extdeps.tools.gnu_coreutils.dd_overwrite_path_command: the payload still crosses on stdin through run_argv_stdin_over_host_effect_transport, while the argv is dd of=PATH status=none. That preserves overwrite/truncate semantics and the deleted shell route's stdout-suppression property without minting a second write authority.
tee_overwrite_command and its argv_command admission are absent from the exact head; tee_append_command remains the distinct append operation. The hermetic plan control pins both dd of= and status=none, and the LocalRepoWet receipts still execute the production converge twice/read back the exact file and then execute revoke/removal.
The ci-layer description now says dd, and the merge resolution retains both the browser-ready-label exclusion and main's roadmap_belt_base_advance_wet_witness_test.dag exclusion. All five exact-head lanes in run 37475519356 are green.
Nonblocking body cleanup: the opening summary and checklist item (3) still contain earlier tee/bootstrap-exec wording; the later explicitly superseding sections state the correct dd + FleetSsh-stall posture. Please remove the stale passages before merge so the body has one reading.
DP-M2 srvN tail (the manager-ordered follow-up to #13234).
What dissolved.
browser_ready_labels_grant_plan/browser_ready_labels_revoke_planwere already typed intents (shell_command_intentlists) — but they were rendered to a script STRING viashell_command_text_of_stmts, shipped throughretained_srvn, and executed byrun_shell_transport. The text was a lossy projection of something the type system already held. The plans now ARE the typed steps:dd of=PATH status=none(dd_overwrite_path_command, elevated per posture) on STDIN (run_argv_stdin_over_host_effect_transport), then the elevateddaemon-reload(run_argv_over_host_effect_transport) — the same overwrite the deletedprintf | sudo tee >/dev/nullperformed (dd over tee because tee would echo the payload into the command log, which the deleted route suppressed with>/dev/null), with the unit bytes crossing as data, never as script text.rm -f, then the samedaemon-reload.set -eis modeled by the converge's own fold: each leg runs only if the previous succeeded; a failed leg is the failed outcome, with one failure shape for every leg (the wall's admission text on refusal, the real exit+stderr on observation).Witnesses.
runner_browser_ready_label_witness_testreads the plan's STEPS hermetically (elevated write words, the payload on stdin, the reload, the removal). The revoke's no-write property is now typed: aRevokeReadycarries no write leg, so a revoke that rewrites rather than removes cannot be constructed.Census delta.
retained_srvncall sites in production dag: this removes the runner_browser_toolchain site (import + call). Note: the emit_host_transport.dag:192 foreign-heredoc site from the DP-M2 census is GONE on current main — main dissolved it itself (the go/ts smoke fns are typed now), so no design choice is needed there.Witnesses: the changed witness is hermetic (pure over the rendered plan, no transport).
Typed-argv checklist (review round)
argv_commandwhose head is the program and only the head:sudo_elevate_command(dag/extdeps/sudo/elevation.dag) producesargv_command(program: sudo_program(), arguments: elevated.args), and the host-effect transport reads the program exactly once (run_argv_over_host_effect_transport->run_argv_parameters_of->shell.Exec.RunArgv(program: params.program, arguments: params.arguments)). No step places the program in its arguments where the transport already owns the head.RunArgvTransportRefused { reason }(the FleetSsh authority refusal), which carries no exit code;run_argv_transport_succeeded/ the converge'sstep_failedmatch the observed and refused arms distinctly, so a refusal is never reported as an executed non-zero exit.run_shell_transportover the retained wall, and the old witness only searched the rendered script text — so no CI lane executed the route then either. The evidence posture does not regress. What executes the converge for real is item (4): the LocalRepoWet scratch receipts over LocalShell, enrolled in the wet schedule and the CI lanes; the production FLEET route remains unexecuted and is the declared stall, not an execution claim.BrowserReadyLabelsTarget { dropin, posture }): production passesbrowser_ready_labels_production_target(the privileged system constant,ReadyLabelsSudoElevated), and the two new LocalRepoWet receipts (dag/test/claim/runner/browser_ready_label_real_path_witness_test.dag) drive the production converge itself for real over LocalShell withReadyLabelsUnprivilegedagainst a mktemp scratch root — grant writes the label bytes (read back from the scratch drop-in, second grant a no-op), revoke removes them (read-back fails after). Under the unprivileged posture the daemon-reload leg is a typed posture skip (ReadyLabelsReloadPostureSkipped), not a fabricated success. The receipts are triple-enrolled (WetScheduledClaim rows in local_repo_wet_schedule, the ci_layer_roots LocalRepoWetLane row, floor_route_gap chunk_41). The production FLEET route is declared as a stall:browser_ready_labels_fleet_route_stallingunbc.runner_browser_toolchain— both shared host-effect runners refuse FleetSsh before any leg (the arm's own fail-closed note demands its own named change), so the converge executes nowhere over fleet until the fleet_subsumption arc admits that arm, with no per-consumer bypass; the receipts' executions over LocalShell are unaffected.Roster admission forSUPERSEDED — see the dd section below (floor run 37427436934)tee_overwrite_commandThe floor refused
argv_commandcalled fromextdeps.tools.gnu_coreutils.tee_overwrite_command. Route chosen: add an admitted-callers row, because that is exactly the class the roster admits: its existing entries are typed per-tool builders in each tool's own extdeps module (install_file_owned_command,cp_command,mktemp_directory_command,rm_force_command, and the siblingtee_append_command). The roster's note states its purpose — typed builders that derive an argv from a cited authority, so "which flags does this tool take" is answered in the tool's own module and nowhere else.tee_overwrite_commandis that: a per-tool builder minted ingnu_coreutils.dagbesidetee_append_command, carrying the overwrite-vs-append flag fact (--ends the option list; no-a) next to the append sibling's (-a,--), sametee_program, same stdin-carried payload. The alternative route — reusing an existing admitted builder — does not exist:tee_append_commandappends (-a) and would silently change the converge's write semantics, and no other admitted builder writes a stdin payload to a named path. The row sits directly aftertee_append_command's indag/extdeps/exec/command.dag.(The side-chat blocker from review 5424411035 was already addressed at db062c1: the fleet-route gap is a typed
GuaranteeStallwith anAwaitsOneGroundingblocker, enrolled ingunbc.guarantee_stall.rosterper the #13424 worked-example shape; the rung_drop prose row, itsLegacyProseIdentityarm and the renderer section are deleted.)Grant leg switched to
dd_overwrite_path_command(side-chat review 5428660024)The side chat blocked the tee route and the premise was false:
extdeps.tools.gnu_coreutilsalready owns, andargv_commandalready admits,dd_overwrite_path_command(path)—dd of=PATH status=none, stdin payload, named path, truncate, exact bytes, no append. The reviewer's load-bearing point: its authority comment usesddoverteeprecisely becauseteeechoes the payload to stdout, which carries the file contents into the command log — the deleted shell route suppressed that with>/dev/null, and a bare typedtee -- PATHwould have lost the suppression while minting a second spelling of the same modeled operation.Applied: the grant plan is now
browser_ready_labels_posture_argv(posture, dd_overwrite_path_command(path: target.dropin as String)), still payload-on-stdin throughrun_argv_stdin_over_host_effect_transport.tee_overwrite_commandand itsargv_commandadmission row are DELETED (the roster section above is void),tee_append_commandremains the distinct append operation. The plan witness's word control now assertsdd of=+status=none(both go red if anything reverts to bare tee); the real-path receipts assert outcomes, not words, and needed no change. The roster route documentation above is retained only as the record of the floor run and its supersession.