Skip to content

Emit arrival_converge; IAM pair and pinned accessor (msg_f03558d1) - #13497

Closed
gunbai-bot[bot] wants to merge 108 commits into
mainfrom
session/stern-ibex-771
Closed

gunbai-bot[bot] wants to merge 108 commits into
mainfrom
session/stern-ibex-771

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Operator escalation msg_f03558d1 (relayed by eager-gull-22) approves Route A: arrival_converge as one fleet-converge mode; dispatch input arrival_subject (mtjade1 only, derived from the arrival population); pool github-mtjade1-arrival, provider github-mtjade1-arrival-oidc, SA mtjade1-arrival@gunbai-secrets.iam.gserviceaccount.com, secret bmc-mtjade1-gunbc with one version-pinned accessor cell, provisioned through gcp-iam-converge rows (not hand gcloud). That id is cited here and on the grant rows (mtjade1_live_standing_grant.effect_subject, arrival accessor description, YAML input description). ruling_text stays the Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493 operator quote.
  • Consumes the Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493 mtjade1 StandingOperatorGrant (msg_7402f8df); no second ruling. Per-effect interlocks on that grant. True attributes: arrival job principal is bindable WIF; enrolled operator-ssh still selects OperatorApprovedCapability.
  • .github/workflows/fleet-converge.yml is generated from gunbc.fleet_converge_workflow. Heal workflow dispatched on exact head e8ef332991 (heal run 37559624495): main_wet succeeded; sealed candidate entries: [] — heal-publish has nothing to commit because the tree already matches the generator. Diff vs main is only arrival_subject, arrival_converge on the mode list / exclusive-job predicates, and the arrival-converge job. Not included: managed_host_boot.
  • bmc-mtjade1-gunbc v1 mint order: mtjade1_bmc_gunbc_secret_ref is the locus (version pending until mint). secret_provision creates the Secret Manager container and AddVersion (first version is 1). Only then can mtjade1_bmc_gunbc_arrival_accessor_ref (pin versions/1) be a real resource. gcp-iam-converge binds pinned_version_accessor_grant_for on that version resource for SA mtjade1-arrival@…. Bootstrap may create grant-set secrets bare (no version); accessor cells stay gated until a version exists.
  • If version 1 does not exist yet: the converge write against …/secrets/bmc-mtjade1-gunbc/versions/1 observes PolicyResourceAbsent and refuses ApprovedCellsRefused ("the resource is absent now; consent was to a policy on a resource that existed or was created before this write"). A live fetch of that pin also cannot succeed: Secret Manager 404 (no version) or 403 (unreadable / missing — same HTTP). Do not hand gcloud.
  • Stacked on Managed-host cut O1c-3b: BmcSecure gated through the convergence fold #13517. Core Managed-host cut O1c-3b: BmcSecure gated through the convergence fold #13517 files match that PR (bmc_secure, the arrival_converge witness, forged_probe). Overlay-unique files include arrival_converge, standing_operator_grant, and privileged_effect_census.
  • Census: archive is RealizedUnauthorized (arrival_archive_prefix_unobserved_world) even though the selector is FederatedScopedGrant and the slot is InterlockedBy arrival_archive_slot_acquire — the wet door refuses unobserved PriorLifeBoundary and does not write. Firmware qualification stays InterlockPending / RealizedUnauthorized (firmware_qualification_writer_unlanded) until a writer under ArrivalArchiveSlotHeld lands (review 5450542899). rulings_without_a_rostered_interlock is the firmware site only. Coordinate sleek-lynx-448 (Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493) and crisp-eagle-656 (O1c-3). Do not enqueue or merge without operator.

fleet-converge.yml vs main (generated)

diff --git a/.github/workflows/fleet-converge.yml b/.github/workflows/fleet-converge.yml
index 891570deec..d79119b344 100644
--- a/.github/workflows/fleet-converge.yml
+++ b/.github/workflows/fleet-converge.yml
@@ -10,10 +10,15 @@ on:
         required: true
         options: [srv1, srv2, srv3, srv4]
         type: choice
+      arrival_subject:
+        description: "arrival_converge only: the arrival-population unit (not executor host, not managed_host). Options are gunbc.machine_intake_arrival_subject arrival_converge_subject_options. Names signed off msg_f03558d1"
+        required: false
+        options: [mtjade1]
+        type: choice
       mode:
         description: "plan shows membership hunks; apply executes a prior plan artifact; org_actions_observe validates the org credential and refuses on runner-group drift; org_runner_roster_observe reads the organization's self-hosted runner registrations to exhaustion under the same token and refuses unless the roster is complete; app_control_plane_observe reads the gunbai-ci App registration and webhook config with a short-lived App JWT and refuses on hook-config drift; app_key_version_verify reads the gunbai-ci App private key at the EXACT Secret Manager version named by app_key_version, mints an installation token with it, and refuses unless GitHub accepts it and the key's rotation deadline has not passed -- no add, disable or destroy; runner_browser_toolchain_converge installs the declared Playwright/Chromium toolchain (apt host libraries as the administrator, digest-pinned node, Playwright and Chromium archives into the job user's root) on the selected host, which must be in the pool that runs the floor job, and refuses unless every digest, version and host library reads back and headless Chromium renders a local page; microvm_host_converge installs the cited Firecracker release on the selected host and reads the kvm grant back, refusing by name when the grant has not landed (the grant itself is applied by the full-host apply spine); microvm_network_apply stages the slot and host network files the model renders at the named expected_revision as root:root 0600 in a root-only directory over the fleet SSH edge as the host's ADMINISTRATOR, installs them with the modeled operations, reloads networkd, systemd-sysctl and the nft loader unit, and reads the ruleset back -- the job user is granted none of it, because install plus systemctl over content that principal can write is arbitrary root for any pull request; guest_image_observe reports the micro-VM base artifacts and their measured digests on the selected host and builds nothing; guest_image_converge builds the runner guest image there; microvm_boot_probe boots that image and reads its serial console; spark_grants and spark_bootstrap prepare the selected Spark; spark_serving_apply applies the promoted fabric groups' pair vLLM units over the password session, workers before heads; spark_native_serving_apply relaunches group B's native four-rank arm as ONE BOUNDED TRANSACTION -- an all-host preflight that mutates nothing and refuses on any unresolved artifact from an earlier run, the incumbent UNIT preserved (plus a diagnostic inspect of the incumbent container -- the container itself cannot outlive its unit, because these run --rm in the foreground under systemd), the head applied BEFORE the workers so every rank joins the head's new rendezvous store, then a readback of the COMPLETE realization through each container's own inspect -- every field the create spec states, the effective --node-rank off that container's argv, and NCCL's typed transport verdict on that incarnation -- plus the head's front door answering with this arm's served model, and then commit or a rollback of the whole arm -- and it is a separate mode because it reloads a 328 GB arm and nobody should reach it by asking for the pair units; spark_runtime_image_probe pulls the pinned runtime image on the selected Spark and reads its capabilities from inside its own digest, changing nothing; spark_wireless_link_converge reads the selected Spark's Wi-Fi power save (runtime via iw, persisted via the NetworkManager profile), link and kernel disconnect count, sets whichever realization differs from the declared intent, and refuses unless the readback decides Noop; spark_grants_observe reads every procured Spark's sudo grant listing as gunbc-automation and the bootstrap principal, and its sudoers drop-in shape, and writes nothing; spark_v41_checkpoint_materialize fetches the admitted published DeepSeek V4.1 files onto the selected Group A Spark (about 510 GB; spark_v41_row_store_encode encodes the eight Engram row stores from the verified shards on the selected Group A Spark and reads each store's sha256; spark_v41_row_store_readback reads those stores back at their header, first and last record and every rank seam, with the published source rows at the same rows, and writes nothing; spark_v41_engram_differential compares upstream's Engram lookup kernel with the design-B file-backed lookup over sampled real rows of every row store, byte for byte, and writes nothing; it states the requirement and refuses before fetching when the disk cannot hold it), publishes each only after its sha256 matches the manifest, leaves a present file with the right digest alone and refuses one with the wrong digest, and reads the storage-backed Engram spans from the verified shards; a transfer runs detached and a rerun reattaches; spark_v41_runtime_image_build PRODUCES the DeepSeek V4.1 image on the selected Spark -- it verifies the candidate's three FlashInfer wheels against the digests the candidate keys, converges the patched source tree, builds from it, reads the produced configuration digest back from inside the image through the probe route, and admits that digest against the candidate's own recipe, refusing a digest that does not recompute from it -- and it is a separate mode from the probe because it occupies one host for hours where the probe occupies it for minutes; spark_v41_runtime_image_distribute moves that produced image, named by the configuration digest its production receipt read back, from the host that receipt names to the selected Group A Spark -- save into its fabric blob root, pulled by the target straight over the fabric rail, load -- after stating its size against every filesystem a copy lands on, leaves a target already holding the digest untouched, refuses a target holding a different image under the tag, and refuses unless the target's image inspect Id reads back as that digest; spark_v41_group_a_launch reads the production image back under its tag on every Group A host, reads its registry inside its digest and every host's occupancy, and only when Group A is suspended for this candidate with every host held and vacant stages the Engram manifest and applies the V4.1 four-rank arm as one transaction at the capacity measurement's shape -- the target names only the session host; spark_v41_serving_load runs the shared serving-load runner against the V4.1 head (target must be srv6): one vllm bench serve step per capacity-measurement concurrency, metrics scraped around each, host pressure read on every Group A rank, and the staircase stop rules applied over the worst rank; it changes no unit and writes only its receipt; host_reset_return drives a rostered reset subject through its controller and measures the return FROM A PEER, and takes reset_observer rather than host because the observer must not be the subject; runner_host_file_observe reads the runner teardown drop-in, the needrestart deferral and the loaded teardown on the selected host as its administrator and writes nothing; runner_host_file_converge writes whichever of those two files differs, reloads systemd only if the drop-in changed, and refuses unless the manager then reports the declared teardown; microvm_controller_install writes the microVM slot controller's root-owned release locus (gunbc + sources + Firecracker + jailer) and the gunbc-microvm-slot@ template unit and the gunbc-microvm-slot-reserve broker unit on srv1 and starts neither; microvm_slot_reserve starts that broker unit once on srv1, which reserves the shakedown cell through the fabric broker route from inside the root process (slot, demand and offer derived from the model, never inputs), and uploads that invocation's reservation receipt, failing unless the reservation committed; microvm_slot_start starts the shakedown slot's controller unit once on srv1 (the instance is derived from the model, never an input), waits for it bounded by the unit's own stop timeout, and uploads that invocation's controller receipt; microvm_runner_group_ensure (srv1 only) reads the organization's runner groups and, only when the microvm-shakedown group is absent, files ONE operator approval, creates it restricted to the shakedown workflow on the default branch, and refuses unless the readback holds that restriction; mtcollins1_census_qemu_host_observe reads the selected host's KVM device and, under the job user's census QEMU root, the qemu-system-aarch64 build, its ldd libraries and the AAVMF images against their pins, and writes nothing; mtcollins1_census_qemu_toolchain_converge places that root as the job user (digest-pinned noble .debs unpacked with dpkg-deb -x, no apt, no Recommends) and refuses unless the same observe reads it ready; workspace_source_pack (host=srv1) enumerates the operator workspace as the job user, drops every path the credential exclusion row names and every build output, tars exactly the remainder, reads the archive back and refuses if any member is excluded, and puts it into the workspace bucket under its SHA-256, refusing by name when the runner cannot read a source root; workspace_checkpoint_measure (host=srv3, workspace_source_object = that SHA-256) refuses unless the job user's home is on btrfs, then times a read-only subvolume snapshot, a pinned kopia scan of it, the content-addressed chunk upload and the gated revision commit, and receipts every time with the 10 s / 60 s / 10 GB draft verdicts; workspace_checkpoint_restore (host=srv3) commits a small authored workspace, puts one chunk with no head advance, destroys the directory, restores it from the head closure and requires byte-equality with the uncommitted chunk absent -- both srv3 modes refuse their commit while the R2 head's CAS ground is uncited"
         required: true
-        options: [plan, launch_environment_plan, allocation_store_plan, workspace_commissioning_plan, apply, org_actions_observe, app_control_plane_observe, microvm_host_converge, microvm_network_observe, microvm_network_apply, guest_image_observe, guest_image_converge, microvm_boot_probe, spark_grants, spark_bootstrap, spark_serving_apply, spark_native_serving_apply, spark_runtime_image_probe, spark_wireless_link_converge, spark_grants_observe, spark_v41_checkpoint_materialize, spark_v41_row_store_encode, spark_v41_row_store_readback, spark_v41_engram_differential, spark_runtime_image_produce, spark_runtime_image_distribute, spark_arm_group_load, spark_arm_checkpoint_materialize, spark_arm_group_observe, spark_arm_group_launch_plan, spark_arm_group_launch, spark_v41_serving_load, dashboard_deploy, approval_broker_dark_install, microvm_controller_install, microvm_slot_reserve, microvm_slot_start, rlm_launch_deployment_receipt, host_reset_return, runner_host_file_observe, runner_host_file_converge, site_pxe_edge_observe, site_pxe_edge_converge, runner_password_session_tool_converge, runner_browser_toolchain_converge, r2_mint_preflight, r2_object_write_mint, org_runner_roster_observe, approval_keyring_converge, approval_device_enrolment_code_issue, mtcollins1_boot, mtcollins1_fan_observe, mtcollins1_ui_bundle_observe, mtcollins1_kvm_observer_observe, mtcollins1_census_image_publish, mtcollins1_census_member_readback, mtcollins1_census_qemu_host_observe, mtcollins1_census_qemu_toolchain_converge, host_credential_custody_converge, app_key_version_verify, r2_bucket_ensure, r2_bucket_admin_mint, r2_workspace_object_read_mint, r2_workspace_object_write_mint, workspace_source_pack, workspace_checkpoint_measure, workspace_checkpoint_restore, fabric_writer_identity_observe, pair_serving_d0, microvm_runner_group_ensure, gcp_iam_converge, namecheap_observe]
+        options: [plan, launch_environment_plan, allocation_store_plan, workspace_commissioning_plan, apply, org_actions_observe, app_control_plane_observe, microvm_host_converge, microvm_network_observe, microvm_network_apply, guest_image_observe, guest_image_converge, microvm_boot_probe, spark_grants, spark_bootstrap, spark_serving_apply, spark_native_serving_apply, spark_runtime_image_probe, spark_wireless_link_converge, spark_grants_observe, spark_v41_checkpoint_materialize, spark_v41_row_store_encode, spark_v41_row_store_readback, spark_v41_engram_differential, spark_runtime_image_produce, spark_runtime_image_distribute, spark_arm_group_load, spark_arm_checkpoint_materialize, spark_arm_group_observe, spark_arm_group_launch_plan, spark_arm_group_launch, spark_v41_serving_load, dashboard_deploy, approval_broker_dark_install, microvm_controller_install, microvm_slot_reserve, microvm_slot_start, rlm_launch_deployment_receipt, host_reset_return, runner_host_file_observe, runner_host_file_converge, site_pxe_edge_observe, site_pxe_edge_converge, runner_password_session_tool_converge, runner_browser_toolchain_converge, r2_mint_preflight, r2_object_write_mint, org_runner_roster_observe, approval_keyring_converge, approval_device_enrolment_code_issue, mtcollins1_boot, mtcollins1_fan_observe, mtcollins1_ui_bundle_observe, mtcollins1_kvm_observer_observe, mtcollins1_census_image_publish, mtcollins1_census_member_readback, mtcollins1_census_qemu_host_observe, mtcollins1_census_qemu_toolchain_converge, host_credential_custody_converge, app_key_version_verify, r2_bucket_ensure, r2_bucket_admin_mint, r2_workspace_object_read_mint, r2_workspace_object_write_mint, workspace_source_pack, workspace_checkpoint_measure, workspace_checkpoint_restore, fabric_writer_identity_observe, pair_serving_d0, microvm_runner_group_ensure, gcp_iam_converge, namecheap_observe, arrival_converge]
         type: choice
       target:
         description: "Spark target host for the spark_* modes, naming the administrator credential the run materializes (any rostered Spark: srv5, srv6, srv7, srv8, srv9, srv10, srv11, srv12); apply reads the subject off the plan artifact"
@@ -118,7 +123,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Isolate toolchain dirs
         run: |-
           rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo"
@@ -585,7 +590,7 @@ jobs:
     runs-on: ${{ fromJSON(format('["self-hosted","linux","arm64","{0}"]', github.event.inputs.host)) }}
     needs: [build]
     timeout-minutes: 295
-    if: github.event.inputs.mode != 'mtcollins1_boot' && github.event.inputs.mode != 'gcp_iam_converge' && github.event.inputs.mode != 'namecheap_observe'
+    if: github.event.inputs.mode != 'mtcollins1_boot' && github.event.inputs.mode != 'gcp_iam_converge' && github.event.inputs.mode != 'namecheap_observe' && github.event.inputs.mode != 'arrival_converge'
     permissions:
       contents: read
       actions: read
@@ -598,7 +603,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -2661,7 +2666,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -2774,7 +2779,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -2908,7 +2913,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -3007,7 +3012,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -3110,7 +3115,7 @@ jobs:
         uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
         with:
           fetch-depth: 0
-          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe') && github.sha || github.event.inputs.expected_revision || github.sha }}
+          ref: ${{ (github.event.inputs.mode == 'mtcollins1_boot' || github.event.inputs.mode == 'gcp_iam_converge' || github.event.inputs.mode == 'namecheap_observe' || github.event.inputs.mode == 'arrival_converge') && github.sha || github.event.inputs.expected_revision || github.sha }}
       - name: Download release-bins artifact
         uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
         with:
@@ -3552,3 +3557,129 @@ jobs:
           compression-level: 0
         if: success()
         timeout-minutes: 10
+  arrival-converge:
+    runs-on: [self-hosted, linux, arm64, srv1]
+    needs: [build]
+    environment: mtjade1-arrival
+    timeout-minutes: 25
+    if: github.event.inputs.mode == 'arrival_converge'
+    permissions:
+      contents: read
+      actions: read
+      id-token: write
+    concurrency:
+      group: gunbc-host-mutation-srv1
+      cancel-in-progress: false
+    steps:
+      - name: Checkout (the event sha only; no dispatch input selects these bytes)
+        uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
+        with:
+          fetch-depth: 0
+          ref: ${{ github.sha }}
+      - name: Download release-bins artifact
+        uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131
+        with:
+          name: release-bins
+          path: ${{ runner.temp }}/release-bins-download
+        timeout-minutes: 10
+      - name: Verify the handed-off release bins against the build key, then promote and run --verify-build-artifacts (fail-closed)
+        id: release_bins
+        run: |
+          set -e
+          ROOT=$('git' 'rev-parse' '--show-toplevel')
+          '[' '-n' "$RELEASE_BINS_KEY" ']' || ('echo' '::error title=release-bins ConsumerKeyMissing::the build job published no release-bins key'; exit 1)
+          '[' '-f' "$RUNNER_TEMP"'/release-bins-download/release-bins.preimage' ']' || ('echo' '::error title=release-bins ConsumerFileMissing::the release-bins artifact is missing release-bins.preimage'; exit 1)
+          '[' '-f' "$RUNNER_TEMP"'/release-bins-download/release-bins.manifest' ']' || ('echo' '::error title=release-bins ConsumerFileMissing::the release-bins artifact is missing release-bins.manifest'; exit 1)
+          '[' '-f' "$RUNNER_TEMP"'/release-bins-download/release-bins.tgz' ']' || ('echo' '::error title=release-bins ConsumerFileMissing::the release-bins artifact is missing release-bins.tgz'; exit 1)
+          'sha256sum' "$RUNNER_TEMP"'/release-bins-download/release-bins.preimage' > "$RUNNER_TEMP"'/DOWNLOADED_DIGEST.out'
+          DOWNLOADED_DIGEST=$('cut' '-d' ' ' '-f' '1' "$RUNNER_TEMP"'/DOWNLOADED_DIGEST.out')
+          '[' 'release-bins-'"$DOWNLOADED_DIGEST" '=' "$RELEASE_BINS_KEY" ']' || ('echo' '::error title=release-bins ConsumerPreimageKeyMismatch::the downloaded preimage does not hash to the build job'\''s key'; exit 1)
+          OBJECT_FORMAT=$('git' '-C' "$ROOT" 'rev-parse' '--show-object-format')
+          SOURCE_TREE=$('git' '-C' "$ROOT" 'rev-parse' 'HEAD^{tree}')
+          '[' '-n' "$OBJECT_FORMAT" ']' || ('echo' '::error title=release-bins AxisValueUnread::the key input OBJECT_FORMAT read back empty, so the key would not name the build; refusing to key'; exit 1)
+          '[' '-n' "$SOURCE_TREE" ']' || ('echo' '::error title=release-bins AxisValueUnread::the key input SOURCE_TREE read back empty, so the key would not name the build; refusing to key'; exit 1)
+          SOURCE_CLOSURE='tree:'"$OBJECT_FORMAT"':'"$SOURCE_TREE"
+          'grep' '-qxF' 'source_closure='"$SOURCE_CLOSURE" "$RUNNER_TEMP"'/release-bins-download/release-bins.preimage' || ('echo' '::error title=release-bins ConsumerSourceTreeMismatch::the pack was keyed on a different source tree than this job'\''s checkout'; exit 1)
+          'printf' '%s' 'claim_executor
+          gunbc
+          discover_source_root_ingest
+          claim_batch
+          interp_recorded_fixture_witness
+          v1_src_dag_parse
+          auth_declared_but_unwired_witness
+          bootstrap_witness
+          dag_collect_fingerprint_witness
+          diagnostics_witness
+          effects_rest_transport_witness
+          infer_semantics_witness
+          parse_witness
+          cssl_assemble
+          namespace_structural_root_exposure_generated_witness
+          codex_app_server_stdio_session
+          ' > "$RUNNER_TEMP"'/release-bins.roster'
+          'tar' '-tzf' "$RUNNER_TEMP"'/release-bins-download/release-bins.tgz' > "$RUNNER_TEMP"'/pack-listing.out'
+          'cmp' '-s' "$RUNNER_TEMP"'/pack-listing.out' "$RUNNER_TEMP"'/release-bins.roster' || ('echo' '::error title=release-bins PackListingNotRoster::the downloaded pack'\''s archive listing is not exactly the roster (an extra, duplicate, directory or escaping entry)'; exit 1)
+          'cut' '-c' '67-' "$RUNNER_TEMP"'/release-bins-download/release-bins.manifest' > "$RUNNER_TEMP"'/manifest-names.out'
+          'cmp' '-s' "$RUNNER_TEMP"'/manifest-names.out' "$RUNNER_TEMP"'/release-bins.roster' || ('echo' '::error title=release-bins ManifestRosterMismatch::the downloaded manifest does not name exactly the gunbc.ci_release_bins roster in order'; exit 1)
+          if 'grep' '-qvE' '^[0-9a-f]{64}  [A-Za-z0-9_]+$' "$RUNNER_TEMP"'/release-bins-download/release-bins.manifest'; then ('echo' '::error title=release-bins ManifestMalformed::the downloaded manifest has a line that is not one well-formed sha256 record for a roster member'; exit 1); fi
+          'rm' '-rf' "$RUNNER_TEMP"'/release-bins-check'
+          'mkdir' '-p' "$RUNNER_TEMP"'/release-bins-check'
+          'tar' '-xzf' "$RUNNER_TEMP"'/release-bins-download/release-bins.tgz' '-C' "$RUNNER_TEMP"'/release-bins-check' '--no-same-owner'
+          'printf' '%s' 'claim_executor:regular file:1
+          gunbc:regular file:1
+          discover_source_root_ingest:regular file:1
+          claim_batch:regular file:1
+          interp_recorded_fixture_witness:regular file:1
+          v1_src_dag_parse:regular file:1
+          auth_declared_but_unwired_witness:regular file:1
+          bootstrap_witness:regular file:1
+          dag_collect_fingerprint_witness:regular file:1
+          diagnostics_witness:regular file:1
+          effects_rest_transport_witness:regular file:1
+          infer_semantics_witness:regular file:1
+          parse_witness:regular file:1
+          cssl_assemble:regular file:1
+          namespace_structural_root_exposure_generated_witness:regular file:1
+          codex_app_server_stdio_session:regular file:1
+          ' > "$RUNNER_TEMP"'/member-types.expected'
+          ('cd' "$RUNNER_TEMP"'/release-bins-check' && 'stat' '-c' '%n:%F:%h' 'claim_executor' 'gunbc' 'discover_source_root_ingest' 'claim_batch' 'interp_recorded_fixture_witness' 'v1_src_dag_parse' 'auth_declared_but_unwired_witness' 'bootstrap_witness' 'dag_collect_fingerprint_witness' 'diagnostics_witness' 'effects_rest_transport_witness' 'infer_semantics_witness' 'parse_witness' 'cssl_assemble' 'namespace_structural_root_exposure_generated_witness' 'codex_app_server_stdio_session') > "$RUNNER_TEMP"'/member-types.out'
+          'cmp' '-s' "$RUNNER_TEMP"'/member-types.out' "$RUNNER_TEMP"'/member-types.expected' || ('diff' "$RUNNER_TEMP"'/member-types.expected' "$RUNNER_TEMP"'/member-types.out' || ':' 'no-op'; ('echo' '::error title=release-bins MemberNotRegularFile::the downloaded pack has a member that is not a self-contained regular file (a link, special file or hard-link dependency; the report above names it)'; exit 1))
+          ('cd' "$RUNNER_TEMP"'/release-bins-check' && 'find' 'claim_executor' 'gunbc' 'discover_source_root_ingest' 'claim_batch' 'interp_recorded_fixture_witness' 'v1_src_dag_parse' 'auth_declared_but_unwired_witness' 'bootstrap_witness' 'dag_collect_fingerprint_witness' 'diagnostics_witness' 'effects_rest_transport_witness' 'infer_semantics_witness' 'parse_witness' 'cssl_assemble' 'namespace_structural_root_exposure_generated_witness' 'codex_app_server_stdio_session' '-maxdepth' '0' '!' '-perm' '-u+x') > "$RUNNER_TEMP"'/member-nonexec.out'
+          '[' '!' '-s' "$RUNNER_TEMP"'/member-nonexec.out' ']' || ('cat' "$RUNNER_TEMP"'/member-nonexec.out'; ('echo' '::error title=release-bins MemberNotExecutable::the downloaded pack has a member that is not executable (listed above)'; exit 1))
+          ('cd' "$RUNNER_TEMP"'/release-bins-check' && 'sha256sum' '--strict' '--quiet' '-c' "$RUNNER_TEMP"'/release-bins-download/release-bins.manifest') || ('echo' '::error title=release-bins MemberDigestMismatch::the downloaded member bytes do not match the manifest under strict checking; refusing before any member is promoted or run'; exit 1)
+          'mkdir' '-p' "$ROOT"'/target/release'
+          ('cd' "$ROOT"'/target/release' && 'rm' '-f' 'claim_executor' 'gunbc' 'discover_source_root_ingest' 'claim_batch' 'interp_recorded_fixture_witness' 'v1_src_dag_parse' 'auth_declared_but_unwired_witness' 'bootstrap_witness' 'dag_collect_fingerprint_witness' 'diagnostics_witness' 'effects_rest_transport_witness' 'infer_semantics_witness' 'parse_witness' 'cssl_assemble' 'namespace_structural_root_exposure_generated_witness' 'codex_app_server_stdio_session')
+          ('cd' "$RUNNER_TEMP"'/release-bins-check' && 'cp' '-p' 'claim_executor' 'gunbc' 'discover_source_root_ingest' 'claim_batch' 'interp_recorded_fixture_witness' 'v1_src_dag_parse' 'auth_declared_but_unwired_witness' 'bootstrap_witness' 'dag_collect_fingerprint_witness' 'diagnostics_witness' 'effects_rest_transport_witness' 'infer_semantics_witness' 'parse_witness' 'cssl_assemble' 'namespace_structural_root_exposure_generated_witness' 'codex_app_server_stdio_session' "$ROOT"'/target/release/')
+          'rm' '-rf' "$RUNNER_TEMP"'/release-bins-check'
+          "$ROOT"'/target/release/claim_executor' '--verify-build-artifacts' "$ROOT"'/target/release/claim_executor' "$ROOT"'/target/release/gunbc' "$ROOT"'/target/release/discover_source_root_ingest' "$ROOT"'/target/release/claim_batch' "$ROOT"'/target/release/interp_recorded_fixture_witness' "$ROOT"'/target/release/v1_src_dag_parse' "$ROOT"'/target/release/auth_declared_but_unwired_witness' "$ROOT"'/target/release/bootstrap_witness' "$ROOT"'/target/release/dag_collect_fingerprint_witness' "$ROOT"'/target/release/diagnostics_witness' "$ROOT"'/target/release/effects_rest_transport_witness' "$ROOT"'/target/release/infer_semantics_witness' "$ROOT"'/target/release/parse_witness' "$ROOT"'/target/release/cssl_assemble' "$ROOT"'/target/release/namespace_structural_root_exposure_generated_witness' "$ROOT"'/target/release/codex_app_server_stdio_session'
+        env:
+          RELEASE_BINS_KEY: ${{ needs.build.outputs.release_bins_key }}
+        timeout-minutes: 5
+      - name: "Arrival admission (credential-free): store host srv1 and a population arrival_subject"
+        id: arrival_admit
+        run: |-
+          ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
+          "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/machine_intake/arrival_admission.dag --function arrival_admit_executor
+        env:
+          FLEET_CONVERGE_EXPECTED_HOST: ${{ github.event.inputs.host }}
+          FLEET_CONVERGE_ARRIVAL_SUBJECT: ${{ github.event.inputs.arrival_subject }}
+        timeout-minutes: 5
+      - name: WIF auth (OIDC -> dedicated mtjade1-arrival pool -> mtjade1-arrival SA, access token only)
+        id: wif_auth
+        uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093
+        with:
+          workload_identity_provider: projects/582015116396/locations/global/workloadIdentityPools/github-mtjade1-arrival/providers/github-mtjade1-arrival-oidc
+          service_account: mtjade1-arrival@gunbai-secrets.iam.gserviceaccount.com
+          token_format: access_token
+          create_credentials_file: false
+        timeout-minutes: 5
+      - name: arrival_converge under the standing grant and arrival interlock
+        id: arrival_converge
+        run: |-
+          ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
+          "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/machine_intake/arrival_run.dag --function arrival_converge_wet
+        env:
+          WIF_ACCESS_TOKEN: ${{ steps.wif_auth.outputs.access_token }}
+          FLEET_CONVERGE_EXPECTED_HOST: ${{ github.event.inputs.host }}
+          FLEET_CONVERGE_ARRIVAL_SUBJECT: ${{ github.event.inputs.arrival_subject }}
+        timeout-minutes: 5

Test plan

  • Heal.yml on exact head: candidate empty (already generated).
  • Exact-head witnesses SUCCESS on e8ef332991 (generated/emit-build/rust-unit-tests/floor/witnesses).
  • YAML diff is arrival mode + arrival_subject + arrival-converge job; no managed_host_boot.

Brian Searls and others added 3 commits October 6, 2026 18:34
…roup or host.

StandingOperatorGrant was fused to FabricGroup. Hosts now live in the scope arm, the mtjade1 ruling is quoted from msg_7402f8df-7917-4b24-bb86-c4e7d51991f7 with empty effects until a gate consumes an arm, and StandingDestructiveAuthorization.interlock is optional so a grant without a landed hold is not circular.

Co-authored-by: Cursor <cursoragent@cursor.com>
…thout a new auth arm.

The standing grant's arrival arms and admit_arrival_subject consume the same row; select_authorization_pattern over the arrival SA member selects FederatedScopedGrant. Operator ssh attributes are unchanged. Mode YAML and GCP provision wait on sign-off.

Co-authored-by: Cursor <cursoragent@cursor.com>
…nned accessor.

Operator sign-off msg_f03558d1: dedicated mode, arrival_subject input, and job under the mtjade1-arrival SA; gcp-iam-converge and secret_provision carry the pool/provider/SA and bmc-mtjade1-gunbc v1 cell. Census realizes FederatedScopedGrant through that job.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot gunbai-bot Bot changed the title Route A: bindable mtjade1 arrival principal (federation modeled, no new auth arm) Emit arrival_converge; IAM pair and pinned accessor (msg_f03558d1) Oct 6, 2026
… msg_f03558d1 on the grant.

The fleet-converge.yml bytes come from fleet_converge_workflow via generated_artifact_gate main_wet_one; the standing grant's effect_subject and the arrival accessor description now carry the Route A approval id without rewriting the #13493 ruling quote.

Co-authored-by: Cursor <cursoragent@cursor.com>
Brian Searls and others added 3 commits October 6, 2026 22:25
…d-hold states.

Absent as optional hold discharged irreversibility, so a bindable boot could federate with no hold; Pending now refuses, and only UnconditionalStanding or InterlockedBy discharge.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ization gate.

The fold now carries gated steps, principals, and mutation lanes. BmcSecure Apply refuses without a discharge for that instance; Noop does not. Discharge accepts the mtjade1 live standing grant's StandingBmcSecureAccountWrite arm via standing_grant_covers(StandingGrantHost). No second privileged-effect census site: plan_bmc_account_action remains the Apply site. No live credential write.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbc-ci-auto-heal and others added 5 commits October 6, 2026 23:38
…n the BMC write.

StandingBmcSecureAccountWrite now discharges only InterlockedBy admit_rotation_apply (the grounded Apply path, which already runs the pre-write lockout). Pending and unconditional refuse. No second census site: plan_bmc_account_action remains the production Apply entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
Census roster rows now store the hold DeclarationRef directly. Pending and UnconditionalStanding must not mint a plausible hold, and the mtjade1 grant names gunbc#13497 as the later consuming-gate change.

Co-authored-by: Cursor <cursoragent@cursor.com>
…d mints.

Co-authored-by: Cursor <cursoragent@cursor.com>
…rotation-apply.

A federated NonEmptyStr and an admitted redemption that ignored claims were silent widens (review 38602).

Co-authored-by: Cursor <cursoragent@cursor.com>
…old.

The census roster now names each arm's hold directly, and rulings_without_a_rostered_interlock is red when StandingRulingUnderInterlock carries no interlock (review 77192).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Fixed on e8ef332 (review 77192).

The privileged_effect_interlocks hold: fields no longer match with an Absent => decl_ref(...) default. Each row names the arm's hold directly (d0_claim_grant, UnitHoldProof, admit_arrival_archive_interlock / admit_arrival_bmc_secure_interlock). rulings_without_a_rostered_interlock now reports the site when StandingRulingUnderInterlock carries Absent instead of skipping. Grant-level mtjade1_live_standing_grant.ruling.interlock stays none because holds differ per arm; discharge still goes through standing_ruling_with_arm_interlock, which is Present.

— sent from stern-ibex-771

gunbc-ci-auto-heal and others added 3 commits October 7, 2026 00:35
…ed Apply red.

ProbeReceipt folds were not an execution of converge_arrival_through_bmc_secure (review 77314).

Co-authored-by: Cursor <cursoragent@cursor.com>
…nditional stay absent.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ls emptiness.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Both findings in review 77256 are already on head e8ef332 (same wall as review 77192; that review was against the pre-fix SHA).

  • rulings_without_a_rostered_interlock: StandingRulingUnderInterlock with Absent is [row.site], not []. Grant-level mtjade1_live_standing_grant.ruling.interlock stays none because holds differ per arm; census discharge goes through standing_ruling_with_arm_interlock, which is Present. Copying the grant-level none onto a census effect would now fail the wall.
  • Roster hold: fields no longer match with an Absent => decl_ref(...) default. Each row names the arm hold directly (d0_claim_grant, UnitHoldProof, admit_arrival_archive_interlock / admit_arrival_bmc_secure_interlock).

No further commit.

— sent from stern-ibex-771

arrival_converge_wet now selects WorkloadIdentityToken and takes arrival_slot_key via file_hold_acquire before returning, so the census hold is executed on the job path (review 77263). BMC secret fetch stays refused until the locus is minted.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Fixed on e0c2717 (review 77263).

arrival_converge_wet is no longer admit-only. After the credential-free admit it requires select_access_token_source = WorkloadIdentityToken (the job's WIF bearer, in-process) and calls arrival_archive_interlock_from_live_slot, which file_hold_acquires arrival_slot_key on unit_hold_store_root and then admit_arrival_archive_interlock. Occupied/store faults refuse.

The pinned bmc-mtjade1-gunbc v1 accessor is still not fetched on this path: JadeManagedBmcSecretStanding is SecretLocusReservedNotOnAccessorRoster until FamilyObserved, and version 1 does not exist until secret_provision mints it. BmcSecure/firmware remain behind that frontier; their interlock still needs a grounded rotation route.

— sent from stern-ibex-771

gunbc-ci-auto-heal and others added 4 commits October 7, 2026 04:27
The wildcard AccessTokenSource match was an unrostered non-fold residue (floor NonFoldResidueRosterDiverged at arrival_converge_after_admit).

Co-authored-by: Cursor <cursoragent@cursor.com>
The remaining wildcard after WorkloadIdentityToken still counted as a non-fold residue at arrival_converge_after_admit.

Co-authored-by: Cursor <cursoragent@cursor.com>
Grant arms this PR lands are InterlockedBy named holds (archive, firmware, StandingBmcSecureAccountWrite / admit_rotation_apply). Grant grain stays InterlockPending so unnamed classes still refuse. No second BmcSecure arm name.

Co-authored-by: Cursor <cursoragent@cursor.com>
Review 77435: acquire-then-release admitted nothing under exclusion, the census
named a pure admit as the hold, and srv1 was a second host literal. The wet door
now keeps ArrivalArchiveSlotHeld across converge_mtjade1_arrival_prefix.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Fixed on e8ac66f (review 77435).

  • The archive interlock no longer acquires and immediately releases. arrival_archive_slot_acquire returns ArrivalArchiveSlotHeld; arrival_converge_under_archive_interlock runs converge_mtjade1_arrival_prefix while that value is in hand, then arrival_archive_slot_release. Census hold: for the archive effect is now arrival_archive_slot_acquire, with an InterlockRoot on arrival_converge_wet.
  • admit_arrival_bmc_secure_interlock remains a supplied-slot check. The firmware census row says that explicitly: no live file_hold wraps firmware qualification yet (that effect is not in the wet prefix). Grant overlay for firmware still names that admit so the roster join stays true.
  • Deleted the second srv1 row (arrival_interlock_store_host). Runner labels and the concurrency group cite operator_host_srv1.

@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

review 77464 describes the wet door before e8ac66f (acquire, immediate release, ArrivalArchiveInterlockAdmitted → ExitSuccess with no prefix). That shape is gone.

On current head arrival_converge_under_archive_interlock takes arrival_archive_slot_acquire, runs converge_mtjade1_arrival_prefix while ArrivalArchiveSlotHeld is in hand, then arrival_archive_slot_release. ExitSuccess is only ArrivalRunFolded { RunConverged }. A dispatch of mode: arrival_converge / arrival_subject: mtjade1 therefore converges the modeled prefix (AccessDiscover, IdentityBindProvisional, PriorLifeBoundary dry archive) under exclusion; it does not mint a green from an empty hold.

The remaining ask — fail the job until a BMC account write / bmc-mtjade1-gunbc v1 exists — would refuse a completed archive prefix. Route A’s job is that prefix; BMC account writes stay behind this door (SecretLocusReservedNotOnAccessorRoster until FamilyObserved), which is #13517’s StandingBmcSecureAccountWrite, not this mode. The module comment still says that. Census RealizedFederatedGrant on the archive/firmware effects is the bindable WIF principal’s selected pattern, not a claim that firmware qualification already executed under the hold (the firmware interlock premise already says it does not).

Not changing the wet door to an always-red BMC-missing refusal.

gunbc-ci-auto-heal and others added 2 commits October 7, 2026 07:54
…rity.

#13497 consumes that arm on the mtjade1 effects list and overlay; J4 still reads
grant_discharges_bmc_secure_account_write. Grant grain stays InterlockPending.

Co-authored-by: Cursor <cursoragent@cursor.com>
…dmit.

Review 77479: admit_arrival_bmc_secure_interlock is a supplied-slot check, not a
hold. StandingJadeFirmwareQualification now InterlockedBy arrival_archive_slot_acquire.
FileHoldAcquired already names the subject; comparing it to itself established nothing.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbc-ci-auto-heal and others added 14 commits October 8, 2026 12:30
Co-authored-by: Cursor <cursoragent@cursor.com>
…release.

Co-authored-by: Cursor <cursoragent@cursor.com>
…w_witness_eval_step_cost.

The generated lane refused the projection after merging main: the drop row is declared in .dag and was missing from the committed markdown. Bytes are the heal-repair-candidate from run 37776435946.

Co-authored-by: Cursor <cursoragent@cursor.com>
…licit Optional match.

Record == inherits optional_equality_answers_by_representation on ControllerClockReading?, so the join zeros that field for structural == and matches Present/Absent and Present values. Present{x} vs Present{y} and Present vs Absent refuse BmcSecureApplicationNotTheInspectedTransition.

Co-authored-by: Cursor <cursoragent@cursor.com>
…oin.

Co-authored-by: Cursor <cursoragent@cursor.com>
…sts.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…laiming fields cannot fall out.

The join still cannot derive field population from the type; the comment now says so. A Present/Present positive at controller_clock_reading_same makes replacing that arm with false red.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…, not a drop.

Co-authored-by: Cursor <cursoragent@cursor.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 84222bdf05c65bfa28c8e31929e5abd853c294c1, re-reviewing 5450542899. The real-release execution gap is closed, and the approved #13517 repairs are carried forward. One part of the prior composition P2 remains: the failed-acquire control still cannot observe an invoked body whose result is discarded. No observed production-store write or unheld hardware operation is alleged.

(a) The real release DID execute in the required run

I inspected floor job 113531274531 in exact-head workflow 37840743121. The relevant terminal is not just schedule membership:

2026-10-08T21:23:56.7332074Z [local-repo-wet] identity=test.claim.durable_exclusive_hold_file_store_wet_witness.w_after_acquire_invokes_the_real_slot_release expected=passed observed=passed

The changed-witness finalization then records that same identity as standing=hermetic-route-gap-held-and-wet-passed, with changed_witness_blocking=0. The floor job succeeded and the required witnesses aggregate's Every required lane must have succeeded step passed. Thus this is execution that the required context consumes, not a merely rostered wet claim.

The hermetic cost record must not be substituted for that terminal. The downloaded required-floor-claim-cost artifact 11581159167 is bound to this SHA and its ZIP matches the current GitHub metadata SHA256 8730186c6fa5290fe19b96e4d800b4ebd56e44b0b3b28efca0f9e1a87cd5b6c8. In required_floor_claim_cost.tsv, this identity's outcome is host_effect_refused; the separate local-wet terminal above is what establishes the pass. The log also explicitly records the initial NO-ROUTE and the subsequent wet-joined standing.

The claim really calls arrival_archive_slot_acquire, passes its result through production arrival_after_acquire with arrival_archive_slot_release, then requires a second acquisition of the same slot under a different owner to succeed. On the inspected path, removing the release while returning the successful body leaves the first owner holding the slot, so the second acquire refuses and the claim returns false. Cleanup cannot explain the second acquisition's success: Remove runs only afterward. This closes the real-release/skip-release finding. The author's skip-release execution remains author-run evidence; I did not retrieve a mutation transcript or run that mutant myself.

Remaining P2 — failure-before-body is still tested only through returned text

test.claim.machine_intake.mtjade1_arrival_principal_witness::w_failed_acquire_runs_no_body supplies body_that_refuses, whose only observation is its returned ExitFailure { reason: "BODY_RAN" }. The claim checks that the final refusal lacks that string. It does not observe whether the callback was invoked.

A mutation of arrival_after_acquire's AcquireRefused arm that invokes body(), discards its returned value, then returns the original slot-occupied refusal leaves this control green. The new real-release claim always enters the Acquired arm, so it does not distinguish that mutation either. This is the precise effect-observation gap already named in 5450542899; successful release coverage does not discharge the opposite branch's no-body obligation.

This is a source-derived mutation counterexample, not a locally executed gunbc mutant. The current production match itself calls neither callback on AcquireRefused; I am not claiming the present branch performs a write. The missing evidence is that the promised control stops that safety regression.

Add a small temporary-root effect-observing failed-acquire case through arrival_after_acquire: let the supplied body create a marker in the claim's own fresh directory, return the existing refusal, and independently assert that the marker does not exist afterward. A direct-call positive should establish that this same marker body really creates the marker. Then invoking the body and discarding its result must make the negative fail. The existing local-repo wet route can execute this; no new lane or full arrival/BMC run is required. Keep the useful returned-refusal and real-release controls.

(b) Store-root scope: the committed round trip is isolated; this is not a global test sandbox

wh_fresh_root uses shell.Mktemp.DirWithTemplate("/tmp/gunbc_hold.XXXXXX"). The new nullary claim passes that returned root to both acquisitions and captures that same value in its release closure; cleanup uses the same Mktemp result. There is no production-root fallback in either arrival archive operation. In the inspected test call sites, the principal tests use supplied outcomes/release callbacks rather than a production-store acquire. The actual unit_hold_store_root binding is in arrival_run's wet-door composition.

That establishes the safety of these committed callers, not the stronger assertion that ANY test is structurally unable to request the production store. The acquire/release root type is an unrestricted NonEmptyStr, and these entry points have no caller or temporary-root admission wall. A separately authored wet test could explicitly supply /var/lib/gunbc/unit-holds; OS permissions would then matter. I have not executed such a call and do not claim production access was observed. Do not advertise parameterization or local-wet scheduling as an enforced filesystem sandbox. I am not requiring a repository-wide sandbox redesign for this bounded test; preserve the fresh-root/no-fallback construction when adding the missing control.

(c) Approved #13517 integration

The requested head is a merge with parents f69bde480066ee51eda391930073b0c4e5985af8 and approved #13517 04191b01c99a3efe448bc9f0adea1d54e4b0e208. The approved BmcSecure file is byte-identical (4a3b782bd431c983c73b784625966066b2349d7f), as is the complete arrival-convergence witness (22e510c0e60bd9af46e5ae34d735aff256166975). The compare against the approved upstream has no changes to the convergence-fold implementation, BmcSecure module, its forged-probe witness, or the authored-record-field stall and its roster. Those approved repairs are not reopened.

The blanket phrase '#13517 files are byte-identical' needs narrowing: shared files such as arrival_converge, standing_operator_grant and privileged_effect_census also carry this PR's route-A overlay, so they differ from the upstream whole-file blobs. That is not itself a merge-loss defect. I found no new merge-resolution blocker in the reviewed BmcSecure boundary; I do not recertify every unrelated imported main change.

Other standing and verification

The archive census continues to state RealizedUnauthorized / arrival_archive_prefix_unobserved_world while its selector is federated; firmware remains pending/unrealized. The wet prefix still refuses unobserved PriorLifeBoundary rather than turning the dry world into a production success. No new live account-write or firmware qualification is credited.

Five workflow jobs passed; Rust unit tests were skipped. The parsed floor artifact records 31 inherited arrival-convergence claims, two forged-probe claims and 12 arrival-principal claims as pass. The real store-roundtrip's pass is independently established by the local-wet log and finalization, as distinguished above. Local execution here was artifact hashing/parsing only: no compiler build, new mutation or hardware/store operation. No merge or enqueue. One bounded failed-acquire effect discriminator remains; do not rebuild the already-accepted release or #13517 work.

gunbc-ci-auto-heal and others added 3 commits October 8, 2026 22:32
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
The wet door refuses unobserved PriorLifeBoundary directly; those helpers had no call site (review 78181).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78181: verified on cb67815322f — mtjade1_unobserved_prior_life_world and arrival_prefix_process_exit had no call site. Deleted on 8e116a70d6b. The wet door still refuses via arrival_wet_prefix_from_unobserved_world; witnesses still supply DryPriorLifeWorld into converge_mtjade1_arrival_prefix.

— sent from stern-ibex-771

gunbc-ci-auto-heal and others added 3 commits October 9, 2026 02:10
Co-authored-by: Cursor <cursoragent@cursor.com>
…ed their YAML.

Co-authored-by: Cursor <cursoragent@cursor.com>
Arrival and printer each already had a single ConcurrencyMappingQueueNotMax; routing both through fleet_converge_exclusive_job_concurrency keeps that as the job's only group authority so a merge cannot glue two group keys into one mapping. Regenerated fleet-converge.yml from main_wet_one; bytes were already the exclusive-job split.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78226: the hand-split of fleet-converge.yml after the merge smash is superseded. Exclusive jobs take one group through fleet_converge_exclusive_job_concurrency; main_wet_one regenerated the YAML (byte-equal to the split). HEAD c317c497842. Existing job concurrency groups vs main are unchanged.

— sent from stern-ibex-771

The merge kept a projection that omitted the overlay BMC-secure eval-step drop and the required_gate_bankruptcy 2026-10-07 incident, so the generated lane refused docs-projections.

Co-authored-by: Cursor <cursoragent@cursor.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE at exact head 534c276e70, re-reviewing the remaining failed-acquire finding from the prior head.

The call-and-discard gap is closed at the production boundary. w_failed_acquire_runs_no_body supplies ArrivalArchiveSlotAcquireRefused to production arrival_after_acquire; its callback performs Filesystem.WriteCreateNew on a marker under the claim's fresh wh_fresh_root(), and the oracle independently requires !Filesystem.Read(marker).success. It no longer infers non-execution from returned text. w_refused_acquire_body_writes_a_marker_when_called_directly is the necessary positive: the same callback succeeds and the marker is independently observed present. Therefore a refused-arm mutation that calls the body and discards its return makes the negative red rather than remaining observationally equivalent.

Both new identities are actually carried by the intended real-effect route: they have FloorRouteGapExpectation rows for DirWithTemplate, WetScheduledClaim rows in local_repo_wet_schedule, and exact-head floor log 37892690609 records both as [local-repo-wet] ... expected=passed observed=passed, followed by standing=hermetic-route-gap-held-and-wet-passed. The earlier real-release control passes on the same route. This establishes the committed test composition; it does not turn the unrestricted store-root parameter into a repository-wide sandbox, and no such stronger claim is needed here.

The author's call-and-discard scratch mutant is consistent with the now-observable oracle (marker written => negative fails), but I did not retrieve or replay that local mutation transcript. The committed negative/positive pair and required wet execution are sufficient for the prior blocker.

The #13517 wording is corrected. The body now limits the byte-match claim to the core bmc_secure, arrival-converge witness, and forged-probe files, while explicitly naming arrival_converge, standing_operator_grant, and privileged_effect_census as Route-A overlay files. That removes the earlier overstatement without hiding the overlay.

The concurrency merge repair is derived from the DAG authority, not hand-edited YAML. fleet_converge_exclusive_job_concurrency(group) is a single constructor for the queue-not-max / cancel_in_progress=false job mapping. The new arrival job calls it with the srv1 host-mutation domain; the existing printer job now calls the same constructor while retaining its exact printer-${{ inputs.printer }} group. The generated .github/workflows/fleet-converge.yml reflects those source calls. Relative to the PR base, the set of distinct YAML group expressions is unchanged: arrival reuses the existing gunbc-host-mutation-srv1 domain, and no pre-existing group value is altered. This is the correct form of the fix for the main-merge duplicate-concurrency-block failure.

The last commit 534c276e70 changes only docs/design-rung-drops.md, regenerating that projection after the merge. Exact-head workflow 37892690609 is bound to 534c276e7068802895e901230e94289d08dc77d4; seed, emit-build, generated, floor, and witnesses all succeeded, with rust-unit-tests skipped. Generated also passed all-target lint and the one-emission stage0 mirror check.

No remaining blocking defect found. I am not authorizing or performing the operator-gated merge/dispatch.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 9, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 9, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout.

@gunbai-bot gunbai-bot Bot closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant