Repository navigation
Standing mtjade1 live-ops grant; grant scope is fabric-group or host - #13493
Conversation
…roup or host. StandingOperatorGrant was fused to FabricGroup. Hosts now live in the scope arm, the mtjade1 ruling is quoted from msg_7402f8df-7917-4b24-bb86-c4e7d51991f7 with empty effects until a gate consumes an arm, and StandingDestructiveAuthorization.interlock is optional so a grant without a landed hold is not circular. Co-authored-by: Cursor <cursoragent@cursor.com>
… msg_f03558d1 on the grant. The fleet-converge.yml bytes come from fleet_converge_workflow via generated_artifact_gate main_wet_one; the standing grant's effect_subject and the arrival accessor description now carry the Route A approval id without rewriting the #13493 ruling quote. Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 9ad18b1d40b77f13ded41f5d18ba507e335169ff, against DESIGN.md's §3 meaning/authority rule and boundary-discrimination rule. One bounded P2 remains in the new optional-interlock semantics. The standing permission itself is accepted; this is not a request for another operator approval or a blanket mtjade1 hold.
Accepted
StandingGrantScope is the right decomposition: the fabric-group arm owns its group and host list, while the host arm owns exactly one host and derives its singleton population. Group A's three consumed effects, nonempty requested-host subset check and group distinction are preserved. A host-scoped grant does not accidentally become a fabric grant, and mtcollins1 remains outside mtjade1's scope.
mtjade1_live_standing_grant.effects = [] is an honest staged declaration. Keeping effect arms with their consuming gates, and adding no census sites for an unlanded reader, is correct. Naming operator_host_mtjade1 without adding it to managed_hosts() does not pretend the unit is provisioned or qualified. The operator-session selection witness is also accurate for its stated WorkloadIdentityUnbindable inputs: recurring boot has no admissible pattern, and the two DeviceOnce effects select OperatorApprovedCapability, with or without the ruling. That is not evidence of a working route A, and the PR correctly does not call it one.
[P2] Separate an as-yet-unnamed effect hold from an already-discharged witness
The new comment on StandingDestructiveAuthorization explicitly assigns Absent the meaning that no consuming effect arm has named a hold yet. But its consumers give that same value the meaning that the irreversibility witness is already discharged:
authorization_pattern_selection.witness_requiredstill maps everyStandingRulingUnderInterlock { ruling: _ }tofalsefor the irreversibility ground, without inspecting the newly optionalruling.interlock.privileged_effect_census.rulings_without_a_rostered_interlocknow returns no finding forAbsent, even though it is iterating an actualPrivilegedEffectSite, not the dormant grant roster.
Before this change, this conditional-discharge arm necessarily named a DeclarationRef, and an active census site had to roster that same hold. The new representation admits a pending condition while both judgments treat it as sufficient. The empty mtjade1 effect roster does not enforce a condition in either judgment: neither consults standing_grant_covers.
A bounded source-derived counterexample uses the new witness's mtjade1_boot_effect, changing only its workload identity to WorkloadIdentityBindable with a named member. Keep EveryProvision, IrreversibleEffect, ApiSurface, MintsNoCredential and NoBillingConsequence. With NoWitnessDischarge the witnessed/unattended constraints admit no candidate. With the witness's StandingRulingUnderInterlock { ruling: mtjade1_live_standing_grant.ruling }, whose interlock is absent, the witness obligation disappears and FederatedScopedGrant survives. An active census row carrying that ruling likewise bypasses the interlock join through Absent => []. I derived this from the selection and census code; I have not executed that counterexample.
The current Unbindable control cannot distinguish this defect: identity_bound independently rejects federation in both cases. Binding route A's principal is exactly what removes that masking constraint.
Please give the pending and discharged states distinct semantics. The dormant grant may remain without a per-grant interlock. A consuming effect can bind its own real hold before using the conditional discharge. Alternatively, where the operator's authorization truly has no interlock condition, represent that as an explicit unconditional standing rather than overloading the same absence that means 'not named yet'; preserve the conditional meaning for Mt. Collins and Group A. No new authorization-pattern candidate or fresh human confirmation is required. What must not remain is an active conditional/pending discharge silently passing both judgments because its hold is absent.
Retain a cheap supplied-input discriminator through select_authorization_pattern over the bindable recurring irreversible effect, and through the actual census judgment for an active site. It should distinguish pending from valid discharge and retain the existing correctly interlocked positive. Keep the faithful current-session control too. This needs no hardware execution, host enrollment, placeholder effect arms, or implementation of #13497/O1c-3 in this PR.
Evidence and scope
The requested head remained unchanged and mergeable when checked. Its associated witnesses workflow 37512432328 is completed/success. Green CI does not distinguish the bindable/absent combination above; the current new control deliberately exercises the unbindable seam. I did not run a compiler, clippy, mutants or wet operations locally, and I have not independently fetched the originating dashboard message. This is a modeling finding in the shared selector/census, not an allegation that this empty grant already caused an unauthorized live write.
…d-hold states. Absent as optional hold discharged irreversibility, so a bindable boot could federate with no hold; Pending now refuses, and only UnconditionalStanding or InterlockedBy discharge. Co-authored-by: Cursor <cursoragent@cursor.com>
…n the BMC write. StandingBmcSecureAccountWrite now discharges only InterlockedBy admit_rotation_apply (the grounded Apply path, which already runs the pre-write lockout). Pending and unconditional refuse. No second census site: plan_bmc_account_action remains the production Apply entry. Co-authored-by: Cursor <cursoragent@cursor.com>
Census roster rows now store the hold DeclarationRef directly. Pending and UnconditionalStanding must not mint a plausible hold, and the mtjade1 grant names gunbc#13497 as the later consuming-gate change. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing review 77287 (dashboard artifact Roster fallback holds. Agreed. mtjade1 grant / host-only scope as dangling. Not dangling under §3c's middle arm. The operator request is to record the standing permission with empty effects until a consuming gate exists; parent accepted that standing ( |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head bb2fba6beea5b0d90b413f21f7edd8e77494c4ee. The P2 in review 5435086432 is resolved. No new blocking code findings. This is semantic approval; landing still requires successful required checks on the requested head.
The ambiguous optional hold has been replaced, not patched around. StandingRulingInterlock gives pending, intentionally unconditional, and named-hold conditions distinct meanings. standing_ruling_discharges_irreversibility returns false for InterlockPending; witness_required consumes that result. Pending therefore retains the irreversibility witness obligation even when the workload identity is bindable. The independent wide-credential, billing and break-glass witness grounds remain unchanged.
The census agrees with that meaning. ruling_discharge_interlock_defect returns the supplied site as a defect for Pending, permits an explicitly unconditional standing, and requires both the exact site and the exact hold to match privileged_effect_interlocks for InterlockedBy. rulings_without_a_rostered_interlock calls this same function on its actual census rows and retains each defect. The former Absent => no finding escape and fabricated default-hold matches are gone.
The requested discriminators are at the production interfaces:
w_bindable_boot_pending_interlock_refusesandw_bindable_boot_interlocked_selects_federationcall the real selector over recurring irreversible bindable boot effects. Unlike the retained operator-session control, identity binding no longer masks the witness-discharge distinction.w_census_pending_interlock_is_a_defectcalls the production census judgment with the actual pending mtjade1 ruling;w_census_interlocked_rostered_is_not_a_defectkeeps the real mtcollins1 boot-site/ruling/roster positive.
These are supplied-input controls at the relevant boundary, not alternate selection or census implementations. I checked that the actual census fold consumes the judgment they exercise. The D0 hold used in the bindable fixture is evidence about selection semantics, not a claim that D0's hold is mtjade1's physical interlock.
Group A and mtcollins1 retain their existing named holds through InterlockedBy. The previously accepted host/fabric scope decomposition, Group A effect and host coverage, and identity-only mtjade1 addition remain intact. mtjade1 remains InterlockPending with an empty effects list and no premature census site. The faithful Unbindable operator-session control remains. This approval neither establishes route A nor supplies J4's eventual hold: #13497/#13517 must bind the consuming effect to its real interlock. No blanket mtjade1 hold, new operator confirmation, hardware run or downstream route implementation is requested here.
CI correction: the supplied green run 37540563425 has workflow head_sha=a5c923fccc9f5ec8b7b75c0d2fa5880571af819d, not this requested head. Its success is predecessor evidence, not exact-head green. The latest commit-filtered lookup for bb2fba6bee returned witnesses run 37548188149 as QUEUED. Do not enqueue/land on the predecessor's status; require the current head's required checks to succeed. The requested PR head remains unchanged and mergeable when checked.
I inspected the exact-head source, controls and CI metadata; I did not execute a compiler, individual claims, mutants or wet operations locally. No further semantic changes requested.
Grant arms this PR lands are InterlockedBy named holds (archive, firmware, StandingBmcSecureAccountWrite / admit_rotation_apply). Grant grain stays InterlockPending so unnamed classes still refuse. No second BmcSecure arm name. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com> #13493 is now on main; keep O1c-3 consumption: InterlockedBy admit_rotation_apply, StandingBmcSecureAccountWrite, no UnconditionalStanding.
Co-authored-by: Cursor <cursoragent@cursor.com> #13493 is on main; O1c-3 stays the consuming BmcSecure gate (InterlockedBy admit_rotation_apply, StandingBmcSecureAccountWrite).
…s row and witness read InterlockedBy Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Summary
StandingOperatorGrantscope asStandingGrantFabricGroup { group, hosts }|StandingGrantHost { host }so an mtjade1 grant is not fused to a SparkFabricGroup. Hosts are derived from the arm; Group A callers wrap the same group and host lists.msg_7402f8df-7917-4b24-bb86-c4e7d51991f7) asmtjade1_live_standing_grantwith empty effects until consuming gates land. Prior-life archive has no arm. Namesoperator_host_mtjade1without enrolling it inmanaged_hosts().StandingDestructiveAuthorization.interlockoptional (one interlock per grant cannot serve per-effect holds). mtjade1 isAbsent; Group A and mtcollins1 stayPresent. No newprivileged_effect_censussites in this PR (no consuming gates yet). Witnesses show mtcollins1 and off-arm effects are not covered, and Group A coverage is unchanged.Route A (decided): mtjade1's effects run under a bindable runner principal via fleet-converge, with this standing ruling as the grant behind it. There is no new selection arm, and no per-run approvals as a standing mode. Effect arms (
StandingGrantEffectrows on this grant, plus census sites that carry the ruling) land with route A's consumers, not in this PR. A sibling is designing that route; this grant's coverage API isstanding_grant_coversoverStandingGrantHost { host: operator_host_mtjade1 }.Today's fold witness still records the true current attributes (
WorkloadIdentityUnbindable, operator session over ssh to srv1): bootNoAdmissiblePattern; credential write / MegaRAC qualificationOperatorApprovedCapability. That is the pre-route-A standing, not the destination.Test plan
test.claim.auth.standing_operator_grant_mtjade1_witnessandtest.claim.spark.pair_serving_d0_release_witnessNoAdmissiblePatternand credential/MegaRACOperatorApprovedCapabilityDo not enqueue or merge from this lane.