Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
108 commits
Select commit Hold shift + click to select a range
9ad18b1
Record the mtjade1 standing live-ops grant; scope a grant as fabric-g…
Oct 6, 2026
a5cd57c
Bind mtjade1 arrival effects to a modeled fleet-converge principal wi…
Oct 6, 2026
b052beb
Emit arrival_converge from fleet-converge; roster the IAM pair and pi…
Oct 6, 2026
f819f07
Commit the generated arrival_converge YAML and cite operator sign-off…
Oct 6, 2026
61dc44a
Merge remote-tracking branch 'origin/main' into session/sleek-lynx-448
Oct 6, 2026
a5c923f
Split standing-ruling interlock into pending, unconditional, and name…
Oct 6, 2026
f0dbf95
Managed-host cut O1c-3b: BmcSecure through the fold behind its author…
Oct 6, 2026
d7bdcef
Merge #13493 interlock states into O1c-3b and require InterlockedBy o…
Oct 6, 2026
bb2fba6
Stop inventing interlock holds when a ruling does not name one.
Oct 6, 2026
d545a36
Admit the pending-interlock and foreign-key discharge REDs at the fol…
Oct 6, 2026
682143b
Refuse BMC-write discharge unless the capability names this host and …
Oct 7, 2026
e8ef332
Refuse an Absent standing-ruling interlock instead of fabricating a h…
Oct 7, 2026
d027ede
Run BmcSecure through the real arrival prefix: Noop green, undischarg…
Oct 7, 2026
919d120
Roster a hold only when the ruling is InterlockedBy; pending and unco…
Oct 7, 2026
f1a7f22
Drop the always-green PrincipalUnbound check; NonEmptyStr already wal…
Oct 7, 2026
e0c2717
Run the arrival archive interlock and require WIF on the wet door.
Oct 7, 2026
cc0e918
Exhaust the access-token arms on the arrival wet door.
Oct 7, 2026
824c843
Exhaust ArrivalSubjectAdmission on the arrival wet door.
Oct 7, 2026
ac718b0
Merge #13493 (bb2fba6bee) three-state interlock into Route A.
Oct 7, 2026
e8ac66f
Hold the arrival slot across the prefix, and name that live acquire.
Oct 7, 2026
cc27c0c
Merge #13517 (f1a7f22d70) so StandingBmcSecureAccountWrite has one au…
Oct 7, 2026
dea7361
Roster firmware on the live arrival slot, and drop the tautological a…
Oct 7, 2026
d68c535
Restore the projection-seal RED at the new mint arity.
Oct 7, 2026
4aaa402
Align the mtjade1 quote witness with grant-grain InterlockPending.
Oct 7, 2026
a84139d
Join BmcSecure Apply to the bound instance and the canonical rotation…
Oct 7, 2026
554fa4d
Keep firmware pending until a held writer lands, and enroll release R…
Oct 7, 2026
ecaad04
Merge #13517 (a84139d192) Apply-instance join into the arrival overlay.
Oct 7, 2026
527e777
Cite the wet-door function in the firmware dissolution, not a bracket…
Oct 7, 2026
38feedd
Keep #13517 Apply-join REDs at the bound-host and grant overlay, with…
Oct 7, 2026
26dd63f
Drop the duplicate bound-host Apply converge and stop returning the s…
Oct 7, 2026
4f1fa10
Merge #13517 (26dd63f53f) cost follow-up into the arrival overlay.
Oct 7, 2026
64f30c8
Restore #13517's arrival witness files and enroll a hermetic failed-a…
Oct 7, 2026
3c1acb5
Keep new BmcSecure Apply witnesses under the floor eval-step budget.
Oct 7, 2026
9e1a2c3
Restore the three-argument projection forge RED and refuse an empty W…
Oct 7, 2026
db38aa0
Run the one BmcSecure Apply-positive inhabitance through the fold; ke…
Oct 7, 2026
352f403
Merge #13517 (db38aa00c0, includes 3c1acb5690) into the arrival overlay.
Oct 7, 2026
4d00893
Start BmcSecure Apply inhabitance after the PriorLife prefix already …
Oct 7, 2026
0e53de1
Merge #13517 (4d008934bd) into the arrival overlay.
Oct 7, 2026
a260cb1
Leave #13517's forged-probe file at 4d008934bd.
Oct 7, 2026
b4088a7
Delete unused MutationLane projection instead of mapping a plan refus…
Oct 7, 2026
a820fde
Merge #13517 (b4088a7ffb) into the arrival overlay.
Oct 7, 2026
7cc10c4
Drop unread ConvergenceStep principal and mutation fields; the fold a…
Oct 7, 2026
06da1d7
Run foreign BmcSecure Apply through the production bound step and dro…
Oct 7, 2026
1793c5a
Merge #13517 (06da1d7608) into the arrival overlay.
Oct 7, 2026
7dcc83e
Roster the BmcSecure rotation site under the mtjade1 standing ruling …
Oct 7, 2026
4ac52ae
Merge #13517 (7dcc83ef70) into the arrival overlay.
Oct 7, 2026
c8fd3c5
Fall through an uncovered grant to the capability arm; mint foreign A…
Oct 7, 2026
524d586
Merge #13517 (c8fd3c5a83) into the arrival overlay.
Oct 7, 2026
faeab49
Discharge BmcSecure census from the arm overlay, not grant-grain pend…
Oct 7, 2026
cb03747
Merge origin/main into the arrival overlay.
Oct 7, 2026
3b74dfd
Refuse undischarged BmcSecure Apply on the production bound step, and…
Oct 7, 2026
19abab4
Merge #13517 (3b74dfda67) into the arrival overlay.
Oct 7, 2026
87db66f
Delete unused UnconditionalStanding and join BmcSecure grant hosts to…
Oct 7, 2026
01c90b5
Merge #13517 (87db66f8b5) into the arrival overlay.
Oct 7, 2026
2d316e9
Discharge capability in one function and resolve BmcSecure grant host…
Oct 7, 2026
13584e6
Merge #13517 (2d316e9679) into the arrival overlay.
Oct 7, 2026
48f1e97
Merge origin/main into the arrival overlay.
Oct 7, 2026
e2dda3b
Merge origin/main into session/crisp-eagle-656-o1c3b.
Oct 7, 2026
d1dc996
Merge PR #13517 (e2dda3bfea) into the arrival overlay.
Oct 7, 2026
2011f18
Inhabit BmcSecure Apply through converge_arrival_through_bmc_secure.
Oct 7, 2026
0a57e6b
Merge origin/main into session/crisp-eagle-656-o1c3b.
Oct 7, 2026
7c070f2
Merge PR #13517 (0a57e6b4fd) into the arrival overlay.
Oct 7, 2026
5490580
Merge origin/main into the arrival overlay.
Oct 7, 2026
ae0e61c
BmcSecure arm interlock promotes only the production pending grain.
Oct 7, 2026
96fd213
Merge origin/main into the arrival overlay.
Oct 7, 2026
2dfe590
Project #13517's declared eval-step drops into design-rung-drops.md.
Oct 7, 2026
2946586
Refuse the wet arrival door on an unobserved PriorLifeBoundary world.
Oct 7, 2026
951bf69
Regenerate docs/design-rung-drops.md from the new eval-step drop.
Oct 7, 2026
5d70989
Merge PR #13517 (951bf69006) into the arrival overlay.
Oct 7, 2026
6fb0e20
Mint a BmcSecure fold discharge only when Apply is supplied.
Oct 7, 2026
0ff0d74
Merge PR #13517 (6fb0e2095c) into the arrival overlay.
Oct 7, 2026
d9103b0
Merge origin/main into session/crisp-eagle-656-o1c3b.
Oct 7, 2026
ac94a28
Move Noop-discharge annotation above converge_arrival_through_bmc_sec…
Oct 7, 2026
46d61db
Merge PR #13517 (d9103b0dbd) into the arrival overlay.
Oct 7, 2026
8ddd880
Attach the BmcSecure discharge comment to the function, not its body.
Oct 7, 2026
29889bc
Merge PR #13517 (8ddd880b31) into the arrival overlay.
Oct 7, 2026
724a8d7
Drop converge_arrival_through_bmc_secure from instance_authorization'…
Oct 7, 2026
fd8c7e6
Census the wet archive door as unauthorized until an observed prefix …
Oct 7, 2026
fb5fc06
Merge PR #13517 (724a8d7e1a) into the arrival overlay.
Oct 7, 2026
cacc769
Bind BmcSecure Apply to the inspected instance and confine discharge …
Oct 8, 2026
2cf6d60
Observe acquire/body/release by callee invocation counts, not the exi…
Oct 8, 2026
6dd755e
Merge PR #13517 (cacc76937f) into the arrival overlay.
Oct 8, 2026
e7df599
Drop in-witness acquire/release mutants; keep the production oracles.
Oct 8, 2026
7e260ff
Bind production release at the one arrival_after_acquire call site.
Oct 8, 2026
dc70119
Inhabit arrival_after_acquire through the real slot release.
Oct 8, 2026
69aaa7e
Merge origin/main into session/crisp-eagle-656-o1c3b.
Oct 8, 2026
79ca915
Bind BmcSecure Apply to the whole inspected observation, not its read…
Oct 8, 2026
b8bd86d
Merge origin/main into the arrival overlay.
Oct 8, 2026
deb3a5e
Bind the archive hold-store root at the wet door, not inside acquire/…
Oct 8, 2026
3360b1c
Heal docs/design-rung-drops.md to render bmc_secure_apply_converge_ne…
Oct 8, 2026
6c26b02
Discriminate BmcSecure observation join on controller_clock by an exp…
Oct 8, 2026
0eaaabe
Fix controller_clock_reading_same argument names at the observation j…
Oct 8, 2026
aa42662
Stamp controller-clock fixtures as EpochMs literals instead of Int ca…
Oct 8, 2026
208ef0e
Apply the generated-lane heal of docs/design-rung-drops.md.
Oct 8, 2026
23dd26c
Keep arrival-subject refusal causes on the admit-executor exit.
Oct 8, 2026
11bbcdd
Merge PR #13517 (aa42662175) into the arrival overlay.
Oct 8, 2026
1d1b7ee
Merge origin/main into session/crisp-eagle-656-o1c3b.
Oct 8, 2026
73a419a
Admit a matching-Present controller_clock equality control and stop c…
Oct 8, 2026
f69bde4
Apply the generated-lane heal of docs/design-rung-drops.md.
Oct 8, 2026
04191b0
Record the authored observation-join field lists as a guarantee stall…
Oct 8, 2026
84222bd
Merge PR #13517 (04191b01c9) into the arrival overlay.
Oct 8, 2026
4e331a6
Observe failed-acquire body absence through a filesystem marker.
Oct 8, 2026
cb67815
Merge origin/main into the arrival overlay.
Oct 9, 2026
8e116a7
Delete unused dry-world constructor and prefix-to-exit mapper.
Oct 9, 2026
8653f65
Merge origin/main into the arrival overlay.
Oct 9, 2026
a8145eb
Separate arrival-converge and printer jobs after the main merge smash…
Oct 9, 2026
c317c49
Give exclusive fleet-converge jobs one concurrency constructor.
Oct 9, 2026
534c276
Regenerate design-rung-drops.md from its DAG authority.
Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
149 changes: 140 additions & 9 deletions .github/workflows/fleet-converge.yml

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions dag/gunbc/actions_run_binding.dag
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,8 @@ data rlm_expected_revision_env_name: String = "RLM_EXPECTED_REVISION"

data fleet_converge_expected_host_env_name: String = "FLEET_CONVERGE_EXPECTED_HOST"

data fleet_converge_arrival_subject_env_name: String = "FLEET_CONVERGE_ARRIVAL_SUBJECT"

type ExpectedRevisionRead
= ExpectedRevisionPresent { revision: String }
| ExpectedRevisionAbsent { variable: String, detail: String }
Expand Down
12 changes: 5 additions & 7 deletions dag/gunbc/auth/authorization_pattern_selection.dag
Original file line number Diff line number Diff line change
Expand Up @@ -111,14 +111,14 @@ type BillingConsequence
// (gunbc.auth.privileged_effect_census rulings_without_a_rostered_interlock), and the site's
// realization must take that hold before any write.
//
// THREE INTERLOCK STATES, NOT AN OPTIONAL HOLD. InterlockPending is a hold not yet named: it must
// TWO INTERLOCK STATES, NOT AN OPTIONAL HOLD. InterlockPending is a hold not yet named: it must
// refuse, never discharge (a bindable irreversible effect under a pending ruling still owes a
// witness). UnconditionalStanding is an intentional no-hold discharge, with its reason. InterlockedBy
// is a named hold the census must roster against the site. Only UnconditionalStanding and
// InterlockedBy discharge the irreversibility ground.
// witness). InterlockedBy is a named hold the census must roster against the site; only that arm
// discharges the irreversibility ground. A grant arm that writes BMC credentials must be InterlockedBy
// the grounded Apply admission (admit_rotation_apply), never pending. Route A overlays that hold per
// arm (standing_grant_arm_interlock); grant grain may stay InterlockPending for unnamed classes.
type StandingRulingInterlock
= InterlockPending { obligation: NonEmptyStr }
| UnconditionalStanding { reason: NonEmptyStr }
| InterlockedBy { hold: DeclarationRef }

type StandingDestructiveAuthorization {
Expand All @@ -130,7 +130,6 @@ type StandingDestructiveAuthorization {
fn standing_ruling_discharges_irreversibility(r: StandingDestructiveAuthorization) -> Bool {
match r.interlock {
InterlockPending { obligation: _ } => false
UnconditionalStanding { reason: _ } => true
InterlockedBy { hold: _ } => true
}
}
Expand Down Expand Up @@ -574,7 +573,6 @@ fn minted_reach_text(m: MintedCredentialReach) -> String {
fn standing_ruling_interlock_label(r: StandingDestructiveAuthorization) -> String {
match r.interlock {
InterlockPending { obligation: o } => join(["InterlockPending: ", o as String], "")
UnconditionalStanding { reason: s } => join(["UnconditionalStanding: ", s as String], "")
InterlockedBy { hold: i } => declaration_ref_display_key(ref: i)
}
}
Expand Down
6 changes: 5 additions & 1 deletion dag/gunbc/auth/gcp_iam_converge.dag
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ import gunbc.namecheap.federation_provision { namecheap_dedicated_federation }
import gunbc.native_product_federation { native_product_federations }
import gunbc.auth.fleet_convergence_federation { fleet_convergence_federation }
import gunbc.auth.managed_host_boot_federation_provision { boot_dedicated_federation }
import gunbc.auth.mtjade1_arrival_federation_provision { mtjade1_arrival_dedicated_federation }
import gunbc.auth.managed_host_boot_federation { pinned_version_accessor_grant_for, provisioned_boot_federations }
import gunbc.auth.approval_request_submission { approval_submission_mac_key_secret_ref }
import gunbc.cloudflare.r2_mint_secret_access { r2_mint_custody_grants }
Expand Down Expand Up @@ -219,7 +220,10 @@ data gcp_iam_converge_targets: List<DedicatedFederation> = concat(
[heal_publisher_dedicated_federation(), private_heal_publisher_dedicated_federation()],
map(provisioned_boot_federations(), f => boot_dedicated_federation(f: f)),
),
concat([namecheap_dedicated_federation(), fleet_convergence_federation(), printer_dedicated_federation()], native_product_federations()),
concat(
concat([namecheap_dedicated_federation(), fleet_convergence_federation(), printer_dedicated_federation()], native_product_federations()),
[mtjade1_arrival_dedicated_federation()],
),
)

fn service_account_resource(email: ServiceAccountEmail) -> String {
Expand Down
48 changes: 48 additions & 0 deletions dag/gunbc/auth/mtjade1_arrival_federation.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
module gunbc.auth.mtjade1_arrival_federation

import std.types { NonEmptyStr }
import gunbc.auth.mtjade1_arrival_pair { mtjade1_arrival_principal_member }
import gunbc.auth.authorization_pattern_selection {
PrivilegedEffect, ApiSurface, WorkloadIdentityBindable, WorkloadIdentityStanding,
MintsNoCredential, IrreversibleEffect, ReversibleByReapply,
NoBillingConsequence, StandingRulingUnderInterlock,
}
import std.human_intervention { DeviceOnce }
import gunbc.auth.standing_operator_grant {
mtjade1_live_standing_grant, StandingJadeArrivalArchive, StandingJadeFirmwareQualification,
standing_ruling_with_arm_interlock,
}

fn mtjade1_arrival_bindable_identity() -> WorkloadIdentityStanding {
WorkloadIdentityBindable { member: mtjade1_arrival_principal_member() as NonEmptyStr }
}

fn mtjade1_arrival_archive_effect() -> PrivilegedEffect {
PrivilegedEffect {
subject: "mtjade1 PriorLifeBoundary archive: content-addressed evidence of BMC carriers, cursor derived from the archive, nothing cleared" as NonEmptyStr,
frequency: DeviceOnce,
reversibility: ReversibleByReapply,
surface: ApiSurface,
workload_identity: mtjade1_arrival_bindable_identity(),
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: StandingRulingUnderInterlock {
ruling: standing_ruling_with_arm_interlock(g: mtjade1_live_standing_grant, e: StandingJadeArrivalArchive),
},
}
}

fn mtjade1_arrival_firmware_qualification_effect() -> PrivilegedEffect {
PrivilegedEffect {
subject: "mtjade1 MegaRAC per-build operation qualification write under the arrival job principal" as NonEmptyStr,
frequency: DeviceOnce,
reversibility: IrreversibleEffect { what_is_lost: "a controller write at a firmware build is not undone by a reapply of a different build's evidence" as NonEmptyStr },
surface: ApiSurface,
workload_identity: mtjade1_arrival_bindable_identity(),
minted_reach: MintsNoCredential,
billing: NoBillingConsequence,
witness_discharge: StandingRulingUnderInterlock {
ruling: standing_ruling_with_arm_interlock(g: mtjade1_live_standing_grant, e: StandingJadeFirmwareQualification),
},
}
}
27 changes: 27 additions & 0 deletions dag/gunbc/auth/mtjade1_arrival_federation_provision.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
module gunbc.auth.mtjade1_arrival_federation_provision

import gunbc.auth.heal_publisher_provision { DedicatedFederation }
import gunbc.auth.mtjade1_arrival_pair {
mtjade1_arrival_pool_id, mtjade1_arrival_pool_display_name, mtjade1_arrival_provider_id,
mtjade1_arrival_wif_attribute_mapping, mtjade1_arrival_claim_pins, mtjade1_arrival_principal_set,
mtjade1_arrival_service_account, mtjade1_arrival_service_account_id, mtjade1_arrival_principal_member,
mtjade1_arrival_secret_grants,
}
import gunbc.auth.oidc_claim_pins { claim_pins_attribute_condition }

fn mtjade1_arrival_dedicated_federation() -> DedicatedFederation {
DedicatedFederation {
label: "mtjade1 arrival federation",
pool_id: mtjade1_arrival_pool_id,
pool_display_name: mtjade1_arrival_pool_display_name,
provider_id: mtjade1_arrival_provider_id,
attribute_mapping: mtjade1_arrival_wif_attribute_mapping,
attribute_condition: claim_pins_attribute_condition(pins: mtjade1_arrival_claim_pins()),
principal_set: mtjade1_arrival_principal_set(),
service_account: mtjade1_arrival_service_account,
service_account_id: mtjade1_arrival_service_account_id,
service_account_display_name: "Mt. Jade arrival (one job)",
service_account_member: mtjade1_arrival_principal_member(),
secret_grants: mtjade1_arrival_secret_grants(),
}
}
76 changes: 76 additions & 0 deletions dag/gunbc/auth/mtjade1_arrival_pair.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
module gunbc.auth.mtjade1_arrival_pair

import std.types { List, Map, NonEmptyStr, String }
import std.optional { Present }
import extdeps.cloud.gcp.gcp {
ServiceAccountEmail, WifPool, WifProvider, wif_provider_resource, wif_pool_resource,
}
import gunbc.auth.github_gcp_federation {
fleet_secrets_project_id, fleet_secrets_project_number, github_wif_issuer_uri, federated_service_account_member,
}
import gunbc.auth.gcp_secret_access { SecretAccessGrant }
import gunbc.auth.managed_host_boot_federation { pinned_version_accessor_grant_for }
import gunbc.auth.oidc_claim_pins { OidcClaimPin, claim_pins_attribute_condition, fleet_converge_job_claim_pins }
import gunbc.secret_provision { mtjade1_bmc_gunbc_arrival_accessor_ref }

// Names, WIF pair and the one version-pinned accessor. PrivilegedEffect rows live in
// gunbc.auth.mtjade1_arrival_federation so gcp-iam-converge and fleet-converge.yml do not
// close over the selection fold.

data mtjade1_arrival_pool_id: NonEmptyStr = "github-mtjade1-arrival"
data mtjade1_arrival_pool_display_name: NonEmptyStr = "Mt. Jade arrival (one job)"
data mtjade1_arrival_provider_id: NonEmptyStr = "github-mtjade1-arrival-oidc"
data mtjade1_arrival_service_account_id: NonEmptyStr = "mtjade1-arrival"
data mtjade1_arrival_service_account: ServiceAccountEmail = "mtjade1-arrival@gunbai-secrets.iam.gserviceaccount.com"
data mtjade1_arrival_environment: NonEmptyStr = "mtjade1-arrival"

data mtjade1_arrival_wif_pool: WifPool = WifPool {
name: mtjade1_arrival_pool_id
project: fleet_secrets_project_id as String
display_name: Present { value: mtjade1_arrival_pool_display_name }
disabled: false
}

fn mtjade1_arrival_claim_pins() -> List<OidcClaimPin> {
fleet_converge_job_claim_pins(environment: mtjade1_arrival_environment)
}

data mtjade1_arrival_wif_attribute_mapping: Map<String, String> = {
"google.subject": "assertion.sub",
"attribute.repository_id": "assertion.repository_id",
"attribute.workflow_ref": "assertion.workflow_ref"
}

fn mtjade1_arrival_wif_provider() -> WifProvider {
WifProvider {
name: mtjade1_arrival_provider_id
pool: mtjade1_arrival_pool_id
issuer_uri: github_wif_issuer_uri
attribute_mapping: Present { value: mtjade1_arrival_wif_attribute_mapping }
attribute_condition: Present { value: claim_pins_attribute_condition(pins: mtjade1_arrival_claim_pins()) }
}
}

fn mtjade1_arrival_provider_resource() -> String {
wif_provider_resource(project_number: fleet_secrets_project_number, provider: mtjade1_arrival_wif_provider())
}

fn mtjade1_arrival_principal_set() -> String {
join([
"principalSet://iam.googleapis.com/",
wif_pool_resource(project_number: fleet_secrets_project_number, pool_id: mtjade1_arrival_pool_id as String),
"/*"
], "")
}

fn mtjade1_arrival_principal_member() -> String {
federated_service_account_member(email: mtjade1_arrival_service_account)
}

fn mtjade1_arrival_secret_grants() -> List<SecretAccessGrant> {
[pinned_version_accessor_grant_for(
title_prefix: "mtjade1-arrival",
description: "gunbc.auth.mtjade1_arrival_pair: the one version the arrival job may read for BmcSecure (signed off msg_f03558d1)",
target: mtjade1_bmc_gunbc_arrival_accessor_ref,
)]
}
Loading
Loading