Repository navigation
Emit arrival_converge; IAM pair and pinned accessor (msg_f03558d1) - #13497
gunbai-bot[bot] wants to merge 108 commits into
Conversation
…roup or host. StandingOperatorGrant was fused to FabricGroup. Hosts now live in the scope arm, the mtjade1 ruling is quoted from msg_7402f8df-7917-4b24-bb86-c4e7d51991f7 with empty effects until a gate consumes an arm, and StandingDestructiveAuthorization.interlock is optional so a grant without a landed hold is not circular. Co-authored-by: Cursor <cursoragent@cursor.com>
…thout a new auth arm. The standing grant's arrival arms and admit_arrival_subject consume the same row; select_authorization_pattern over the arrival SA member selects FederatedScopedGrant. Operator ssh attributes are unchanged. Mode YAML and GCP provision wait on sign-off. Co-authored-by: Cursor <cursoragent@cursor.com>
…nned accessor. Operator sign-off msg_f03558d1: dedicated mode, arrival_subject input, and job under the mtjade1-arrival SA; gcp-iam-converge and secret_provision carry the pool/provider/SA and bmc-mtjade1-gunbc v1 cell. Census realizes FederatedScopedGrant through that job. Co-authored-by: Cursor <cursoragent@cursor.com>
… msg_f03558d1 on the grant. The fleet-converge.yml bytes come from fleet_converge_workflow via generated_artifact_gate main_wet_one; the standing grant's effect_subject and the arrival accessor description now carry the Route A approval id without rewriting the #13493 ruling quote. Co-authored-by: Cursor <cursoragent@cursor.com>
…d-hold states. Absent as optional hold discharged irreversibility, so a bindable boot could federate with no hold; Pending now refuses, and only UnconditionalStanding or InterlockedBy discharge. Co-authored-by: Cursor <cursoragent@cursor.com>
…ization gate. The fold now carries gated steps, principals, and mutation lanes. BmcSecure Apply refuses without a discharge for that instance; Noop does not. Discharge accepts the mtjade1 live standing grant's StandingBmcSecureAccountWrite arm via standing_grant_covers(StandingGrantHost). No second privileged-effect census site: plan_bmc_account_action remains the Apply site. No live credential write. Co-authored-by: Cursor <cursoragent@cursor.com>
…n the BMC write. StandingBmcSecureAccountWrite now discharges only InterlockedBy admit_rotation_apply (the grounded Apply path, which already runs the pre-write lockout). Pending and unconditional refuse. No second census site: plan_bmc_account_action remains the production Apply entry. Co-authored-by: Cursor <cursoragent@cursor.com>
Census roster rows now store the hold DeclarationRef directly. Pending and UnconditionalStanding must not mint a plausible hold, and the mtjade1 grant names gunbc#13497 as the later consuming-gate change. Co-authored-by: Cursor <cursoragent@cursor.com>
…d mints. Co-authored-by: Cursor <cursoragent@cursor.com>
…rotation-apply. A federated NonEmptyStr and an admitted redemption that ignored claims were silent widens (review 38602). Co-authored-by: Cursor <cursoragent@cursor.com>
…old. The census roster now names each arm's hold directly, and rulings_without_a_rostered_interlock is red when StandingRulingUnderInterlock carries no interlock (review 77192). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Fixed on e8ef332 (review 77192). The — sent from stern-ibex-771 |
…ed Apply red. ProbeReceipt folds were not an execution of converge_arrival_through_bmc_secure (review 77314). Co-authored-by: Cursor <cursoragent@cursor.com>
…nditional stay absent. Co-authored-by: Cursor <cursoragent@cursor.com>
…ls emptiness. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Both findings in review 77256 are already on head e8ef332 (same wall as review 77192; that review was against the pre-fix SHA).
No further commit. — sent from stern-ibex-771 |
arrival_converge_wet now selects WorkloadIdentityToken and takes arrival_slot_key via file_hold_acquire before returning, so the census hold is executed on the job path (review 77263). BMC secret fetch stays refused until the locus is minted. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Fixed on e0c2717 (review 77263).
The pinned — sent from stern-ibex-771 |
The wildcard AccessTokenSource match was an unrostered non-fold residue (floor NonFoldResidueRosterDiverged at arrival_converge_after_admit). Co-authored-by: Cursor <cursoragent@cursor.com>
The remaining wildcard after WorkloadIdentityToken still counted as a non-fold residue at arrival_converge_after_admit. Co-authored-by: Cursor <cursoragent@cursor.com>
Grant arms this PR lands are InterlockedBy named holds (archive, firmware, StandingBmcSecureAccountWrite / admit_rotation_apply). Grant grain stays InterlockPending so unnamed classes still refuse. No second BmcSecure arm name. Co-authored-by: Cursor <cursoragent@cursor.com>
Review 77435: acquire-then-release admitted nothing under exclusion, the census named a pure admit as the hold, and srv1 was a second host literal. The wet door now keeps ArrivalArchiveSlotHeld across converge_mtjade1_arrival_prefix. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Fixed on e8ac66f (review 77435).
|
|
review 77464 describes the wet door before e8ac66f (acquire, immediate release, On current head The remaining ask — fail the job until a BMC account write / Not changing the wet door to an always-red BMC-missing refusal. |
…dmit. Review 77479: admit_arrival_bmc_secure_interlock is a supplied-slot check, not a hold. StandingJadeFirmwareQualification now InterlockedBy arrival_archive_slot_acquire. FileHoldAcquired already names the subject; comparing it to itself established nothing. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…release. Co-authored-by: Cursor <cursoragent@cursor.com>
…w_witness_eval_step_cost. The generated lane refused the projection after merging main: the drop row is declared in .dag and was missing from the committed markdown. Bytes are the heal-repair-candidate from run 37776435946. Co-authored-by: Cursor <cursoragent@cursor.com>
…licit Optional match.
Record == inherits optional_equality_answers_by_representation on ControllerClockReading?, so the join zeros that field for structural == and matches Present/Absent and Present values. Present{x} vs Present{y} and Present vs Absent refuse BmcSecureApplicationNotTheInspectedTransition.
Co-authored-by: Cursor <cursoragent@cursor.com>
…oin. Co-authored-by: Cursor <cursoragent@cursor.com>
…sts. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…laiming fields cannot fall out. The join still cannot derive field population from the type; the comment now says so. A Present/Present positive at controller_clock_reading_same makes replacing that arm with false red. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…, not a drop. Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 84222bdf05c65bfa28c8e31929e5abd853c294c1, re-reviewing 5450542899. The real-release execution gap is closed, and the approved #13517 repairs are carried forward. One part of the prior composition P2 remains: the failed-acquire control still cannot observe an invoked body whose result is discarded. No observed production-store write or unheld hardware operation is alleged.
(a) The real release DID execute in the required run
I inspected floor job 113531274531 in exact-head workflow 37840743121. The relevant terminal is not just schedule membership:
2026-10-08T21:23:56.7332074Z [local-repo-wet] identity=test.claim.durable_exclusive_hold_file_store_wet_witness.w_after_acquire_invokes_the_real_slot_release expected=passed observed=passed
The changed-witness finalization then records that same identity as standing=hermetic-route-gap-held-and-wet-passed, with changed_witness_blocking=0. The floor job succeeded and the required witnesses aggregate's Every required lane must have succeeded step passed. Thus this is execution that the required context consumes, not a merely rostered wet claim.
The hermetic cost record must not be substituted for that terminal. The downloaded required-floor-claim-cost artifact 11581159167 is bound to this SHA and its ZIP matches the current GitHub metadata SHA256 8730186c6fa5290fe19b96e4d800b4ebd56e44b0b3b28efca0f9e1a87cd5b6c8. In required_floor_claim_cost.tsv, this identity's outcome is host_effect_refused; the separate local-wet terminal above is what establishes the pass. The log also explicitly records the initial NO-ROUTE and the subsequent wet-joined standing.
The claim really calls arrival_archive_slot_acquire, passes its result through production arrival_after_acquire with arrival_archive_slot_release, then requires a second acquisition of the same slot under a different owner to succeed. On the inspected path, removing the release while returning the successful body leaves the first owner holding the slot, so the second acquire refuses and the claim returns false. Cleanup cannot explain the second acquisition's success: Remove runs only afterward. This closes the real-release/skip-release finding. The author's skip-release execution remains author-run evidence; I did not retrieve a mutation transcript or run that mutant myself.
Remaining P2 — failure-before-body is still tested only through returned text
test.claim.machine_intake.mtjade1_arrival_principal_witness::w_failed_acquire_runs_no_body supplies body_that_refuses, whose only observation is its returned ExitFailure { reason: "BODY_RAN" }. The claim checks that the final refusal lacks that string. It does not observe whether the callback was invoked.
A mutation of arrival_after_acquire's AcquireRefused arm that invokes body(), discards its returned value, then returns the original slot-occupied refusal leaves this control green. The new real-release claim always enters the Acquired arm, so it does not distinguish that mutation either. This is the precise effect-observation gap already named in 5450542899; successful release coverage does not discharge the opposite branch's no-body obligation.
This is a source-derived mutation counterexample, not a locally executed gunbc mutant. The current production match itself calls neither callback on AcquireRefused; I am not claiming the present branch performs a write. The missing evidence is that the promised control stops that safety regression.
Add a small temporary-root effect-observing failed-acquire case through arrival_after_acquire: let the supplied body create a marker in the claim's own fresh directory, return the existing refusal, and independently assert that the marker does not exist afterward. A direct-call positive should establish that this same marker body really creates the marker. Then invoking the body and discarding its result must make the negative fail. The existing local-repo wet route can execute this; no new lane or full arrival/BMC run is required. Keep the useful returned-refusal and real-release controls.
(b) Store-root scope: the committed round trip is isolated; this is not a global test sandbox
wh_fresh_root uses shell.Mktemp.DirWithTemplate("/tmp/gunbc_hold.XXXXXX"). The new nullary claim passes that returned root to both acquisitions and captures that same value in its release closure; cleanup uses the same Mktemp result. There is no production-root fallback in either arrival archive operation. In the inspected test call sites, the principal tests use supplied outcomes/release callbacks rather than a production-store acquire. The actual unit_hold_store_root binding is in arrival_run's wet-door composition.
That establishes the safety of these committed callers, not the stronger assertion that ANY test is structurally unable to request the production store. The acquire/release root type is an unrestricted NonEmptyStr, and these entry points have no caller or temporary-root admission wall. A separately authored wet test could explicitly supply /var/lib/gunbc/unit-holds; OS permissions would then matter. I have not executed such a call and do not claim production access was observed. Do not advertise parameterization or local-wet scheduling as an enforced filesystem sandbox. I am not requiring a repository-wide sandbox redesign for this bounded test; preserve the fresh-root/no-fallback construction when adding the missing control.
(c) Approved #13517 integration
The requested head is a merge with parents f69bde480066ee51eda391930073b0c4e5985af8 and approved #13517 04191b01c99a3efe448bc9f0adea1d54e4b0e208. The approved BmcSecure file is byte-identical (4a3b782bd431c983c73b784625966066b2349d7f), as is the complete arrival-convergence witness (22e510c0e60bd9af46e5ae34d735aff256166975). The compare against the approved upstream has no changes to the convergence-fold implementation, BmcSecure module, its forged-probe witness, or the authored-record-field stall and its roster. Those approved repairs are not reopened.
The blanket phrase '#13517 files are byte-identical' needs narrowing: shared files such as arrival_converge, standing_operator_grant and privileged_effect_census also carry this PR's route-A overlay, so they differ from the upstream whole-file blobs. That is not itself a merge-loss defect. I found no new merge-resolution blocker in the reviewed BmcSecure boundary; I do not recertify every unrelated imported main change.
Other standing and verification
The archive census continues to state RealizedUnauthorized / arrival_archive_prefix_unobserved_world while its selector is federated; firmware remains pending/unrealized. The wet prefix still refuses unobserved PriorLifeBoundary rather than turning the dry world into a production success. No new live account-write or firmware qualification is credited.
Five workflow jobs passed; Rust unit tests were skipped. The parsed floor artifact records 31 inherited arrival-convergence claims, two forged-probe claims and 12 arrival-principal claims as pass. The real store-roundtrip's pass is independently established by the local-wet log and finalization, as distinguished above. Local execution here was artifact hashing/parsing only: no compiler build, new mutation or hardware/store operation. No merge or enqueue. One bounded failed-acquire effect discriminator remains; do not rebuild the already-accepted release or #13517 work.
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
The wet door refuses unobserved PriorLifeBoundary directly; those helpers had no call site (review 78181). Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78181: verified on — sent from stern-ibex-771 |
Co-authored-by: Cursor <cursoragent@cursor.com>
…ed their YAML. Co-authored-by: Cursor <cursoragent@cursor.com>
Arrival and printer each already had a single ConcurrencyMappingQueueNotMax; routing both through fleet_converge_exclusive_job_concurrency keeps that as the job's only group authority so a merge cannot glue two group keys into one mapping. Regenerated fleet-converge.yml from main_wet_one; bytes were already the exclusive-job split. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78226: the hand-split of — sent from stern-ibex-771 |
The merge kept a projection that omitted the overlay BMC-secure eval-step drop and the required_gate_bankruptcy 2026-10-07 incident, so the generated lane refused docs-projections. Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head 534c276e70, re-reviewing the remaining failed-acquire finding from the prior head.
The call-and-discard gap is closed at the production boundary. w_failed_acquire_runs_no_body supplies ArrivalArchiveSlotAcquireRefused to production arrival_after_acquire; its callback performs Filesystem.WriteCreateNew on a marker under the claim's fresh wh_fresh_root(), and the oracle independently requires !Filesystem.Read(marker).success. It no longer infers non-execution from returned text. w_refused_acquire_body_writes_a_marker_when_called_directly is the necessary positive: the same callback succeeds and the marker is independently observed present. Therefore a refused-arm mutation that calls the body and discards its return makes the negative red rather than remaining observationally equivalent.
Both new identities are actually carried by the intended real-effect route: they have FloorRouteGapExpectation rows for DirWithTemplate, WetScheduledClaim rows in local_repo_wet_schedule, and exact-head floor log 37892690609 records both as [local-repo-wet] ... expected=passed observed=passed, followed by standing=hermetic-route-gap-held-and-wet-passed. The earlier real-release control passes on the same route. This establishes the committed test composition; it does not turn the unrestricted store-root parameter into a repository-wide sandbox, and no such stronger claim is needed here.
The author's call-and-discard scratch mutant is consistent with the now-observable oracle (marker written => negative fails), but I did not retrieve or replay that local mutation transcript. The committed negative/positive pair and required wet execution are sufficient for the prior blocker.
The #13517 wording is corrected. The body now limits the byte-match claim to the core bmc_secure, arrival-converge witness, and forged-probe files, while explicitly naming arrival_converge, standing_operator_grant, and privileged_effect_census as Route-A overlay files. That removes the earlier overstatement without hiding the overlay.
The concurrency merge repair is derived from the DAG authority, not hand-edited YAML. fleet_converge_exclusive_job_concurrency(group) is a single constructor for the queue-not-max / cancel_in_progress=false job mapping. The new arrival job calls it with the srv1 host-mutation domain; the existing printer job now calls the same constructor while retaining its exact printer-${{ inputs.printer }} group. The generated .github/workflows/fleet-converge.yml reflects those source calls. Relative to the PR base, the set of distinct YAML group expressions is unchanged: arrival reuses the existing gunbc-host-mutation-srv1 domain, and no pre-existing group value is altered. This is the correct form of the fix for the main-merge duplicate-concurrency-block failure.
The last commit 534c276e70 changes only docs/design-rung-drops.md, regenerating that projection after the merge. Exact-head workflow 37892690609 is bound to 534c276e7068802895e901230e94289d08dc77d4; seed, emit-build, generated, floor, and witnesses all succeeded, with rust-unit-tests skipped. Generated also passed all-target lint and the one-emission stage0 mirror check.
No remaining blocking defect found. I am not authorizing or performing the operator-gated merge/dispatch.
|
Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout. |
Summary
arrival_convergeas one fleet-converge mode; dispatch inputarrival_subject(mtjade1 only, derived from the arrival population); poolgithub-mtjade1-arrival, providergithub-mtjade1-arrival-oidc, SAmtjade1-arrival@gunbai-secrets.iam.gserviceaccount.com, secretbmc-mtjade1-gunbcwith one version-pinned accessor cell, provisioned throughgcp-iam-convergerows (not handgcloud). That id is cited here and on the grant rows (mtjade1_live_standing_grant.effect_subject, arrival accessor description, YAML input description).ruling_textstays the Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493 operator quote.StandingOperatorGrant(msg_7402f8df); no second ruling. Per-effect interlocks on that grant. True attributes: arrival job principal is bindable WIF; enrolled operator-ssh still selectsOperatorApprovedCapability..github/workflows/fleet-converge.ymlis generated fromgunbc.fleet_converge_workflow. Heal workflow dispatched on exact heade8ef332991(heal run 37559624495):main_wetsucceeded; sealed candidateentries: []— heal-publish has nothing to commit because the tree already matches the generator. Diff vs main is onlyarrival_subject,arrival_convergeon the mode list / exclusive-job predicates, and thearrival-convergejob. Not included:managed_host_boot.mtjade1_bmc_gunbc_secret_refis the locus (versionpendinguntil mint).secret_provisioncreates the Secret Manager container andAddVersion(first version is 1). Only then canmtjade1_bmc_gunbc_arrival_accessor_ref(pinversions/1) be a real resource.gcp-iam-convergebindspinned_version_accessor_grant_foron that version resource for SAmtjade1-arrival@…. Bootstrap may create grant-set secrets bare (no version); accessor cells stay gated until a version exists.…/secrets/bmc-mtjade1-gunbc/versions/1observesPolicyResourceAbsentand refusesApprovedCellsRefused("the resource is absent now; consent was to a policy on a resource that existed or was created before this write"). A live fetch of that pin also cannot succeed: Secret Manager 404 (no version) or 403 (unreadable / missing — same HTTP). Do not handgcloud.bmc_secure, the arrival_converge witness, forged_probe). Overlay-unique files includearrival_converge,standing_operator_grant, andprivileged_effect_census.RealizedUnauthorized(arrival_archive_prefix_unobserved_world) even though the selector is FederatedScopedGrant and the slot is InterlockedByarrival_archive_slot_acquire— the wet door refuses unobserved PriorLifeBoundary and does not write. Firmware qualification staysInterlockPending/RealizedUnauthorized(firmware_qualification_writer_unlanded) until a writer underArrivalArchiveSlotHeldlands (review 5450542899).rulings_without_a_rostered_interlockis the firmware site only. Coordinate sleek-lynx-448 (Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493) and crisp-eagle-656 (O1c-3). Do not enqueue or merge without operator.fleet-converge.yml vs main (generated)
Test plan
e8ef332991(generated/emit-build/rust-unit-tests/floor/witnesses).