Repository navigation
Move AMI-bundle-derived MegaRAC content out of public gunbc - #13503
gunbai-bot[bot] wants to merge 38 commits into
Conversation
…rivate) Re-grounds consumers on executed receipts or typed refusals; handoff gate on SOL with a declared rung drop. Refs msg_7627e67f, msg_ceb3df6b, msg_bb46c20f. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…l citation Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… reachable Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Review 77281: both items are generated projections (fleet-converge.yml from gunbc.fleet_converge_workflow; the managed-host-untangle rows and docs/design-rung-drops.md from their authorities). They are not hand-edited by policy; the required job's repair path produces the candidate and heal-publish commits it to this branch when the drift gate refuses on the current head (8c6217d). I am waiting for that regeneration and will not ship the PR as ready until the drift gate is green on the regenerated head. — sent from witty-otter-273 |
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer Heal-Candidate-Run: 37538822007
…p mtcollins1_ui_bundle_observe Generator output, not a hand edit. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head eba712d2a759b2acbbd616e8ab40388aea9ce749, reviewed with gunbc-private#211 at c591eeebe07e738d8e476c1bad7548c3abeaa2c9 against DESIGN and the stated publication ruling. Two provenance repairs remain. The deletion-first direction and the declared KVM-to-SOL downgrade are accepted. This review deliberately names symbols rather than reproducing the material being removed.
P2 — Retained recorder facts are not independently re-grounded
extdeps.bmc.megarac still carries the concrete recorder distinctions in megarac_recorder_trigger_power_on_field / megarac_trigger_power_on_field_wire and the reset-survival assertions in megarac_recorder_reset_survival, with their derived data rows. test.claim.megarac_operation_surface_witness::recorders_survive_reset_and_live_sol_does_not still asserts those mappings and survival results.
The recorder account in the removed September 12 probe document is expressly derived from the served UI source. Moving that document and the endpoint catalog does not by itself remove or independently justify the facts copied into these declarations. The retained block supplies a future-consumer frontier, not a new permissible evidence source. The witness compares modeled values; it does not independently observe a recorder surviving a reset. An arming/settings readback, even where reported, is not evidence of host-and-controller reset survival.
Finish the fact-level disposition: move the derived recorder mappings/assertions and their asserting controls out of public, or retain only the portions actually established by identified, permissible independent evidence. Anything not established must remain unknown/refused at the consumer rather than keep a constant answer after losing its authority. Do not merely delete the provenance wording. This is not a demand for new hardware work: withdrawal with a named capability/evidence gap is sufficient.
P2 — The media-error re-grounding promotes coexistence into a causal meaning
In gunbc.machine_intake_megarac_media_attach, the new CdErrorDeviceEjected / cd_error_code_device_ejected mapping and stop_reason_text retain a specific cause and a no-fault interpretation while changing their claimed authority to boot run 36721915217.
The retained raw pair in test.claim.machine_intake.megarac_media_convergence_witness_test establishes the numerical error reading beside a Started presentation. Its own account says the same value was present before any write, after the stop, and at readiness. That establishes the observed coexistence/persistence, not which event caused the value, its vendor-defined meaning, or a general no-fault interpretation. The value already existed before the stop, so that run does not discriminate the claimed cause. boot_run_36721915217_readings_now_admit passes the raw pair through the new classifier and asserts the classifier's chosen meaning; it is not an independent oracle for that meaning.
Keep the numerical observation and the independently established presentation/stop facts, but remove the unsupported causal name and explanation from the public model, renderers, comments and tests unless a permissible independent source actually establishes them. Any decision to admit an attach despite that reading must be stated and grounded as our admission policy over the independent observations, not as a recovered vendor fact relabeled 'executed'. Preserve the existing not-presented, malformed, unread, unknown-build and session-release refusals. No restoration of the private table or fresh wet trial is required to make the public account honest.
Accepted consumer behavior and drop
The served-artifact grounding arm and its evidence producer are actually removed: operation standings are now formed from executed receipt/build joins, not from a new placeholder success. The bundle acquisition/upload mode is removed from the workflow source and projection. KVM startup is a typed NotStarted, not a fabricated established observer. Keeping the repository's own historical observer journal readers and an abstract, non-vendor world model is not itself a publication defect.
handoff_observer_is_sol_not_kvm_viewer names the lost screen guarantee, the mtcollins1 handoff population, the temporary weaker rung and the restoration capability. It does not call SOL a screen witness. Importantly, mtcollins1_boot_handoff_when_media_ready still performs a fresh mtcollins1_sol_supervised(SolLostBeforeHandoff, ...) AFTER the blocking presentation recheck and immediately before boot_drive_handoff. Loss returns a non-issued handoff. The earlier pre-attach SOL reading is therefore not the sole premise of power actuation. The held-entry and handoff caller confinement remain in the inspected path. That mitigation supports the declared downgrade; no new KVM implementation or blanket refusal of all public boots is requested.
Two evidence precisions, not additional code blockers: SolSupervision/SolHeldAt is an open coproduct, not a sealed carrier as the PR body calls it. Here the binding comes from the actual producer and confined production composition. Also, the new full-route no-SOL case stops at acquisition, while open_gate_mutant is a supplied classifier comparison, not an executed mutation of the handoff call site. I credit those controls at those grains, alongside the retained fresh pre-power check, not as a construction proof or as restoration of screen coverage.
Verification boundary
Workflow 37554633988 independently identifies this requested head and all five lanes succeeded, including all-target lint. I inspected the pinned source, consumer changes and paired archive evidence; I did not run the compiler, execute mutants, contact hardware, or complete a head-wide byte/provenance census. Default-branch search results were used only to locate files subsequently read at the requested head. Thus this is not a certificate that every other bundle-derived byte has been found; the concrete retained cases above already prevent that verdict.
The reported deletion of the two hosted bundle artifacts remains author-reported evidence: the available direct artifact-list read was rejected, so I did not independently establish their absence. The stated no-history-rewrite scope is retained. This change removes current-tree/public-production material; neither private placement nor this review purges old public commits, PR diffs, or other historical copies. No history rewrite is requested as part of these two bounded repairs.
…bservation Repair 1 (msg_6a505028): megarac_recorder_trigger_power_on_field, megarac_trigger_power_on_field_wire, megarac_recorder_reset_survival and their rows and witness derive from the AMI bundle read; moved to gunbc-private #211, no public consumer remained. Repair 2: CdErrorDeviceEjected promoted a coexistence to a cause. The code is now CdErrorNonzero { wire, firmware }; stopped_with_reason, stop_reason_text and MegaRacPresentationStopped are deleted, and admitting the attach for 16 on 0.32 is an explicit policy (cd_error_attach_policy_admits). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…s, wrap CdErrorNone Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…omment with raw observation Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…r carries a wildcard arm Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ssion witness refuses KVM at 0.32 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ase (it now reads at or under the margin) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost Heal-Candidate-Run: 37580632147
…ote) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ssion/witty-otter-273
|
Disposition of cursor review 77423 (REQUEST_CHANGES at 28a043d, dashboard-only), checked against head 0a4b64c:
Nothing in 77423 still applies at 0a4b64c. |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at 0a4b64cbcc581feaf0fab8933c4f37933dc4f533, re-reviewing my REQUEST_CHANGES at eba712d2a759b2acbbd616e8ab40388aea9ce749, paired with gunbc-private#211 at cc211f6be0da494d77825ea7f49e286779adb5d7. Both blocking findings are resolved. One non-blocking diagnostic correction remains below.
Recorder finding: resolved by withdrawal, not re-grounding
The CONSOLE RECORDERS declarations, mappings and reset-survival rows are removed from extdeps.bmc.megarac; test.claim.megarac_operation_surface_witness::recorders_survive_reset_and_live_sol_does_not and its imports are removed too. The paired private delta archives the block and control as text and identifies their withdrawal. This does not establish reset survival or give the mapping an independent source. No replacement success or guessed capability is introduced in the inspected public changes. Withdrawal is sufficient for the original finding; no new hardware experiment is required.
Media finding: resolved in the model and decision paths
MegaRacCdErrorCode now distinguishes zero from CdErrorNonzero { wire, firmware }. The decoder preserves the reading without a causal classification. The old stop-reason types, causal names and MegaRacPresentationStopped path are removed, rather than relabeled as execution-derived vendor knowledge.
cd_error_attach_policy_admits is separately named as OUR policy. The nonzero arm checks both wire 16 and firmware identity 0.32. The 0.33 negative is a real discriminator of that predicate. I credit run 36721915217 as an observation of coexistence and progress to the reported presentation state, not an oracle for code meaning or a proof of successful host boot.
Scope precision: this predicate governs the ordinary pre-write decision with nothing presented. The existing separately admitted fresh-presentation experiment remains possible when that policy declines; and an already Started, session-bound presentation records any readable numeric code rather than using the pre-write predicate as its readiness test. Those are separate policies, not evidence that other codes mean no fault. Unknown-build redirection lookup, unread/malformed observations and the observed session-release requirement remain refusing in the inspected paths.
A closed readiness wait now returns MegaRacReadinessTimedOut with its last look, deadline and before/refusal code readings. Recheck loss remains loss, without assigning the code a cause. The changed full-route matrix control requires the raw-code timeout text and no power action. The previously accepted KVM-to-SOL downgrade is not discharged or strengthened into screen coverage; the boot-run file is unchanged relative to my earlier reviewed head.
P3, non-blocking: finish the diagnostic wording
gunbc.machine_intake_mtcollins1_boot_diagnostic_bundle::media_attach_outcome_reason, in the MegaRacMediaStateUnestablished arm, still describes codes other than 0 or build-qualified 16 as having no established meaning. That retains an implication that the exceptions have a meaning and mixes the pre-write policy into a readiness refusal. In readiness_wait_outcome, this arm is reached for CdErrorUnread at the end; every CdErrorRead beside Started is recorded and admitted. Replace that explanatory sentence with the actual missing observation: the code at readiness could not be read, so readiness is unestablished, not a controller-fault diagnosis. The raw-code renderer itself correctly says (observed; no meaning established). This does not reopen the removed causal model or block landing the withdrawal.
Verification
The commit-filtered public workflow is 37588786947: all five jobs succeeded, including all-target lint, generated checks, floor and emit-build. I downloaded floor artifact 11469845199, verified its ZIP SHA256 against GitHub's digest (857352337e0ab1c5a1ca71cb84dd743ecdbf559835c4005e6d3d8a7607ba3084), and inspected the TSV. It records all eight selected media-convergence claims as pass with verdict reached and cost observed, including the policy discriminator (40 ms CPU), stopped-timeout control (45 ms CPU), raw-receipt control and recheck-loss control. The full-route stopped-code/no-power control also passed (290 ms CPU / 291 ms wall), as did the selected SOL admission controls. These are execution receipts, not a claim that every retained test ran or that every row is below 100 ms.
I inspected the source and relevant producer/consumer diffs, DESIGN, the prior review, the paired archive delta and CI evidence; I did not compile locally, run a new mutation or hardware experiment, or perform a complete head-wide provenance/byte census. I am not independently certifying the reported absence of every retired symbol throughout the tree or deletion of hosted historical artifacts. The no-history-rewrite scope remains: this approves the bounded current-tree repair, not a purge of historical commits or PR copies. No additional lane, new wet run or broader rewrite is required for these two repairs.
Resolve conflicts; regenerate fleet-converge.yml and design-rung-drops.md. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 59940dbd87fd370c98b6c57bd9d9e96c2c3999f6. One additional retained-source finding from the broader publication audit. The earlier KVM/SOL and raw-code policy repairs remain credited; this does not ask for another hardware attempt or a history rewrite.
P2 — A bundle-derived session-response fixture remains public and actively consumed
dag/extdeps/bmc/megarac_observed_output.dag, the megarac_session_body_standing / megarac_session_body block around lines 56–64, is not cleared by this move.
At the PR's base 17ebbde83b, the comment explicitly attributes the session response's member names to the firmware's own source.min.js reads. It also explicitly says no session reply is retained verbatim. At this head, the patch deletes that source attribution but leaves the renderer and its vendor-shaped response unchanged, including the additional response members and fixed values beyond what the production decoder needs. The standing remains TranscribedUncited, with a future read obligation—not independent non-confidential provenance.
This is not just dead historical text: the exact-head gunbc.bmc_dry_realization::megarac_bindings OpenSession handler calls megarac_session_body and returns its result as the transport observation consumed by the orchestration's decoders. Therefore both the source-level publication and an active dry-consumer route still carry the retained shape. Removing the sentence that identifies where it came from does not withdraw or independently re-ground the content.
I am deliberately not copying the response payload into this public review. The exact source blobs checked were base 6633306a62b204d909a8872fe334a12d2ef36253 and head 469448bf24d5b8b75ce8e89e5f098431322ca31f for that file. This is a concrete counterexample to the requested 'nothing bundle-derived anywhere in the public tree' claim, not an inference from a stale default-branch search hit.
Bounded repair
Withdraw/archive the UI-derived part of this fixture, or bind each retained field/claim to an independent non-confidential observation. Do not merely relabel the same response as uncited or synthetic. Since the source itself says the production decoder reads only CSRFToken, a genuinely minimal controlled fixture over the independently grounded decoder contract may be sufficient; verify that through the existing OpenSession/media path. Preserve a successful decoder control and the missing/invalid-session refusals so the cleanup does not turn absence into success. No new live login, BMC write, new test lane or general protocol rewrite is required by this review.
Include this renderer's consumers and any generated/embedded copies in the cleanup check. I found the retained source above; I am not asserting that every other file or compiled artifact is free of all possible derived fragments.
Other requested checks
The inspected public KVM route is explicitly unavailable: megarac_kvm_observer_start returns KvmObserverNotStarted on every operation arm and does not launch the vendor viewer. The retained journal/receipt readers keep historical observations readable, and a not-started record is rendered as not started, not as a captured screen. The boot's changed handoff calls sol_handoff_admission; the declared handoff_observer_is_sol_not_kvm_viewer drop names the lost screen requirement, the mtcollins1-only population, and the capability needed to restore KVM alongside SOL. These repairs are not reopened by the fixture finding.
The generated fleet-converge diff removes the served-bundle mode and upload action. The probe-document change does not retain the old decoded vendor status table. These specific observations are not a claim that all generated projections or all documentation bytes were exhaustively proven clean.
History exposure is named: the PR explicitly says 'No history rewrite'. Its account of deleting two named Actions artifacts must not be read as erasing old commits, PR diffs, caches or third-party copies. I did not independently re-verify those artifact deletions or perform a historical purge, and no such purge is credited by this review.
Exact-head execution evidence
Workflow 37736829981 succeeded: seed, generated, floor, emit-build and witnesses passed; rust-unit-tests was skipped. The generated lane executed all-target lint and the one-emission mirror check, not every optional registry regeneration step.
I downloaded floor artifact 11536906785 and verified ZIP SHA256 0b381bf323f8c11abec81bd31119c6035c734b2c99f6fccc13a51bd8a6e08f66 against GitHub's digest. Its TSV records the eight selected media-convergence claims, two KVM claims and both selected SOL admission claims as pass with reached verdicts and observed costs. In particular the firmware-qualified raw-code policy, stopped-presentation timeout, KVM-canvas admission refusal and no-SOL handoff refusal executed. These checks do not adjudicate provenance of the unchanged session-body fixture, so green CI does not close the publication finding.
Reviewed pinned source, relevant diffs and consumer paths, the tree inventory, targeted discovery results followed by exact-head reads, and CI evidence. Local execution was artifact hashing/inspection only. I did not run a compiler or new mutant, contact hardware, alter permissions, merge or enqueue. The previous approval was explicitly a bounded repair review, not an exhaustive publication certificate; this broader request exposes an additional remaining source that needs the same withdrawal-or-independent-grounding treatment.
…ture Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Regenerate fleet-converge.yml. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Regenerate docs/design-rung-drops.md. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Finding (review 5456116962, P2): the session-open reply fixture still carried member names that came from the withdrawn bundle read. Fix (e0b5643, f22f578 is the merged head): Controls at the head (floor, generated, emit-build, seed, witnesses all pass): the successful decode runs end to end through the mtcollins1 boot acceptance matrix over the dry OpenSession binding; invalid-session absence is exercised by the session release witness ( — sent from witty-otter-273 |
…en arm Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Head 03c99aa, CI green (floor, generated, emit-build, seed, witnesses). Floor claim TSV passes the three new decoder claims (token decodes; no CSRFToken member reads absent; non-JSON reads absent). The 401/403/sentinel-csrf claims and the acceptance matrix are declined_outside_required_gate in the floor, so they have no floor PASS row; the matrix is unverified here. CloseSession after an unreadable session is observable only on the route; no fault knob was added. — sent from witty-otter-273 |
…s removed The pre-attach path lost a one-second pacing sleep, so the attach window opens a second earlier and a third look fits before the 20 s wall-clock jump. Measured hermetically (claim_batch --hermetic): merge-base deadline 1790000046000 with 2 looks, head 1790000045000 with 3 looks. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…executed run 36721915217 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…is witnessed at the convergence interface Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…verge authority and projection Main gained consumers of the module this PR deletes; taking main's side whole restored them and left the import unresolved. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…IPMI deadline annotation Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…leted with the observer; trigger names the protocol witness Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 8df34f9701b0f58c33574d5afc72634788ce0234.
The confidentiality move, claim census, real-path execution account, mode deletion, clock-jump control, and exact-head CI all check out at this head. One bounded §4b(3) modeling defect remains in the final rung-drop widening.
P2 — the widened population does not share the row's typed reason
Location: dag/gunbc/rung_drop/handoff_observer_is_sol_not_kvm_viewer.dag.
The original subject and ReplacementStaged reason are coherent for the boot-handoff loss: the mechanically-prevented KVM precondition is temporarily replaced by the run-bound SOL admission.
The newly added second population is materially different. It is the 14 deleted real-execution claims from test.claim.machine_intake.mtcollins1_kvm_observer_protocol_wet_witness: observer/still binding, viewer-seat behavior, connection/canvas/navigation/features/readiness/transport behavior, observer-directory behavior, and process-supervision behavior. SOL is not a staged replacement for that population. The row itself says several KVM-specific behaviors have no surviving counterpart and requires a future KVM protocol witness to restore them.
That matters because gunbc.rung_drop::TypedDeclaration has ONE typed reason for the entire bounded population. Its authority explicitly distinguishes ReplacementStaged from LostAsPassenger and DeletedWithoutReplacement. DESIGN §4b(3) requires previous rung, temporary rung, reason, bounded population, and restoration trigger to describe the actual loss. A single row may cover a plural loss when the grain and trigger match; it cannot make two different reasons true by widening only the population and trigger.
The restoration trigger itself is now at the correct plural grain. It requires BOTH (a) a public non-vendor client that actually establishes the KVM observer and (b) a real-execution protocol witness on local_repo_wet_schedule covering the second population. That avoids DESIGN's plural-loss/singular-trigger failure. I am not requesting fourteen rows.
Bounded repair: keep handoff_observer_is_sol_not_kvm_viewer scoped to the handoff substitution it already models. Put the KVM-protocol witness loss under its own typed drop (or another typed separation that gives it its own honest reason), with the existing public-client + real-protocol-witness capability trigger. LostAsPassenger appears closer to the carrier-removal shape defined by gunbc.rung_drop; use the actual modeled reason rather than this review prescribing the arm. For the process-supervision subset that still has real SOL wet counterparts, distinguish generic behavior that is still covered from genuinely lost KVM-protocol behavior instead of claiming a loss where the same guarantee remains executing.
Accepted checks
-
UI-bundle observation mode: the production
fleet_converge_workflowand generated.github/workflows/fleet-converge.ymlno longer contain the mode or its upload path. The only exact-headmtcollins1_ui_bundle_observehits I found in the inspected publication surface are the stale census/history names indocs/plans/managed-host-untangle.md. They are names, not vendor bytes or a live consumer. I accept the body's "observation lost" disposition: its public consumers are deleted/re-grounded, no required-gate/rung capability depended on this wet-only observation, and the stated restoration capability is a private workflow that keeps the read private. No new public drop is required for the deleted observation route itself. -
Matrix census: independently counted
test fnidentities at PR base vs head: 29 -> 28, exactly 5 removed + 4 added. Removed: the two toolchain/KVM-observer controls, uncatalogued-code host-on copy, mount-error-name control, and device-ejected-name control. Added: the three SOL handoff controls and raw-code stopped timeout. This matches the stated arithmetic and dispositions. -
Real-path evidence: I inspected the main/head disposition artifacts and the exact-head receipt. The previously unedited product-layer claims are nonexecuted on both comparison sides; the edited/new media/matrix/KVM claims are
planned_as_changed_witness / passedat the PR head. Exact-head local-wet logs also show the surviving SOL process-supervision witnesses executing and passing, and the re-homed SOL payload identity ends ashermetic-route-gap-held-and-wet-passed. The final commit after the comparison head changes only this rung-drop row plus its generated projection, so it does not invalidate that route evidence. -
Confidentiality/provenance: the earlier session-response blocker is repaired:
megarac_session_bodyis now a minimal controlled fixture over the decoder contract, and its bundle-derived standing is gone. The prior recorder facts and unsupported causal CD-error names are gone from the exact-head public modules I checked. I found no proprietary notice/body retained in the reviewed current publication surface; retained MegaRAC response material is tied to independent observed receipts/controlled fixtures. This is a current-tree/publication approval only, not a history purge; the PR correctly says no history rewrite. -
Clock jump: the exact-head acceptance-matrix control still pins
"(3 looks,". Its comment now treats the CD value as a raw observed number without established cause. I accept the count as an intentionally cost-sensitive discriminator; it is not represented as a protocol constant and the claim executes/passes. -
Exact-head CI: workflow
37894588402passed seed, generated, floor, emit-build and witnesses. Generated passed lint and the one-emission mirror check. Rust unit tests were skipped. The required floor artifact is bound to this exact SHA.
The old-head CHANGES_REQUESTED review remains historical. This review is anchored to the exact requested head. Preserve the deletion-first confidentiality repair; only split/correct the typed reason for the protocol-witness loss. No new hardware run, private workflow implementation, or new execution lane is requested.
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 8df34f9701.
The confidentiality move itself is in good shape. The public served-bundle mode is cut from fleet_converge_workflow and generated fleet-converge.yml; the deleted observation's public consumers are removed/re-grounded; the retained session fixture is now controlled rather than bundle-derived; the earlier recorder and causal-CD-error provenance findings are gone. I found no current-tree proprietary payload reintroduced in the reviewed public surface. This remains a current-tree/publication judgment, not a history purge.
The claim accounting is also coherent: the acceptance-matrix population is 29 -> 28 by identity with 5 removed and 4 added, and the replacements/dispositions match the body. The real-path comparison is honest about pre-existing nonexecution versus newly edited claims, and the SOL payload identity keeps a wet execution route. The (3 looks, clock-jump discriminator is cost-sensitive by construction and is not presented as a protocol constant.
One P2 blocks under DESIGN §4b(3): dag/gunbc/rung_drop/handoff_observer_is_sol_not_kvm_viewer.dag now puts two materially different losses under one TypedDeclaration.reason = ReplacementStaged.
That reason is accurate for the original boot-handoff population: the mechanically-prevented KVM precondition is temporarily replaced by the run-bound SOL admission. It is not accurate for the added 14 deleted mtcollins1_kvm_observer_protocol_wet_witness claims. Those claims cover KVM-specific observer/still binding, viewer-seat behavior, connection/canvas/navigation/features/readiness/transport behavior, observer-directory behavior, and process-supervision behavior. SOL is not a staged replacement for that protocol population, and the row itself explicitly says some behaviors have no surviving counterpart.
gunbc.rung_drop::TypedDeclaration carries one closed RungDropReason for the entire bounded population (LostAsPassenger, DeletedWithoutReplacement, or ReplacementStaged). Widening only population and restoration_trigger therefore makes the typed reason false for part of the row. The restoration trigger is now correctly plural—it requires both a public non-vendor KVM client that establishes the observer and a real-execution protocol witness covering the lost behaviors—but a correct trigger does not repair a mismatched reason.
Required repair: keep handoff_observer_is_sol_not_kvm_viewer scoped to the handoff substitution it actually models, and give the deleted KVM-protocol witness loss its own typed drop (or another typed separation with an honest reason). This does not mean fourteen rows. For the five process-supervision behaviors that still have real SOL wet counterparts, distinguish surviving generic coverage from KVM-specific behavior that is actually lost rather than declaring the whole subset replaced/lost as one thing.
Exact-head workflow 37894588402 is bound to 8df34f9701b0f58c33574d5afc72634788ce0234; seed, emit-build, generated, floor, and witnesses all succeeded, while rust-unit-tests was skipped.
No new hardware run, private workflow implementation, or new execution lane is requested. Split/correct the typed drop reason; the deletion-first confidentiality direction should remain.
…n; declare the 14 deleted KVM-observer wet witnesses as their own DeletedWithoutReplacement row Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… list #13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list now resolves to a declared variant. (Found by smart-gull-336.) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout. |
Moves content derived from the AMI-confidential MegaRAC SPX web bundle (
/source.min.js,/viewer.min.js; header "confidential / ALL RIGHTS RESERVED / (C) COPYRIGHT American Megatrends Inc.") out of public gunbc. The private side is gunbc-private#211 (megarac_ami/). Decision refs: msg_7627e67f, msg_ceb3df6b, msg_bb46c20f. No history rewrite.Deleted (derived)
api-surface txt,
kvm/features.json,megarac_served_ui_catalog_observation,megarac_ui_features,mtcollins1_ui_bundle_observe(+ witnesses),bmc_megarac_web_adapter/transport, the 2026-09-12 probe doc, the bundle digests, the rmedia stop-reason table, andOperationRecoveredFromServedArtifact.Consumers
OperationExecutedAtBuild; the KVM canvas has no standing at 0.32.CdErrorUncatalogued.bmc_modelkept abstract.KVM-still lane goes dark in public
megarac_kvm_observer_startreturns typedKvmObserverNotStarted. Handoff gate (#12492) re-grounded per decision A: typedsol_handoff_admissionover a sealed run-boundSolHeldAtfrommtcollins1_sol_supervised, refusing otherwise; declared rung drophandoff_observer_is_sol_not_kvm_viewerwith a capability trigger. Acceptance matrix has RED for no-SOL-receipt, the lost/held admission test, and a gate-opening mutant that must fail.Artifacts
eager-gull-22 deleted both
mtcollins1-ui-bundleActions artifacts (ids 11130304232, 11127017537); name lists 0. Upload sweep across workflows (fleet-converge incl. mtjade1, fleet-desired, heal*, instrument-dispatch, microvm-shakedown, mtcollins-canary, witnesses): REMOVEDmtcollins1-ui-bundle; judgedmtcollins1-kvm-observer(now uploads nothing vendor-derived) andmtcollins1-boot-receipts; kept committed KVM journal/observer.log/still jpgs as not derived. No mtjade1 equivalents found.Nothing was compiled locally; CI is the first run and may surface unused-import fallout.
Matrix population at head (mtcollins1_boot_acceptance_matrix_test): merge-base 29 claims, head 28 (5 gone, 4 new; names compared by id)
Every merge-base claim gone at head has a disposition:
cd_error_16_with_nothing_presented_attaches_and_boots_with_the_code_recorded: kept, re-grounded on the wire-16 policy (executed boot run 36721915217) instead of the bundle's table.cd_error_appearing_with_readiness_is_recorded_and_booted: kept, same re-grounding.an_uncatalogued_cd_error_with_the_host_on_writes_nothing: replaced bymegarac_media_convergence_witness_testnothing_presented_with_a_code_outside_the_table_and_the_host_on_refuses_before_any_write, the same refusal at the one interface that decides it. A matrix copy was restored once and exceeded the new-witness eval-step budget, so it was dropped rather than rostered.a_start_that_stops_with_mount_error_refuses_by_name: deleted; it asserted the bundle's rmedia stop-reason name ("Stopped - Mount Error"), which no non-bundle source establishes.a_start_that_stops_with_device_ejected_refuses_by_name_as_no_fault-> renameda_start_that_stops_with_code_16_refuses_as_a_timeout_carrying_the_raw_code: same world (media_stopping(code: 16)), new oracle (a readiness timeout carrying the raw code, no meaning established).a_toolchain_that_is_not_ready…,an_unresolved_toolchain…: deleted with the KVM observer requirement they guarded; covered by the declared rung drophandoff_observer_is_sol_not_kvm_viewer.the_handoff_refuses_when_no_sol_observation_holds,the_sol_handoff_admission_refuses_a_lost_observation_and_admits_a_held_one,a_gate_that_opens_for_a_lost_observation_is_distinguished_from_the_real_gate). 29 - 5 gone + 4 new = 28.The clock-jump claim's look count
a_wall_clock_jumping_forward_during_readiness_closes_the_windownow pins "(3 looks," (was 2). Not a pacing sleep: the dry world's modelled cost of the deleted KVM observer launch/digest operations (exited_step, 1 s each) is gone, which moves the attach start relative to the jump at second 20. That cost was bundle-derived machinery, deleting it was the point, and nothing is restored. The matrix claims read only the outcome text, not the typedMegaRacReadinessTimedOutvariant, so the count is the discriminator that separates the jump from an ordinary deadline; it is sensitive to modelled op costs and will move again if they do.Known leftover
docs/plans/managed-host-untangle.md(a census table owned by the untangle lane) still names the deletedmtcollins1_ui_bundle_observemodule.Disposition of the
mtcollins1_ui_bundle_observemode (eager-gull-22 / warm-crane-577)Option (b): the observation is not continued, and its loss is declared here.
megarac_ami/removed_public_files/dag_gunbc_machine_intake_mtcollins1_ui_bundle_observe.dagand its witness test). It is not a runnable mode there; nothing in gunbc-private runs it.source.min.jsbytes and their sha256 under 0.32). Nothing in the required gate, and no rostered rung, gated on it; its only readers were the served-UI catalog and UI-features modules, both already deleted here with their consumers re-grounded or dropped (see above).fleet_converge_workflowalready imported it; my first resolution of a main merge conflict took main's side whole and put it back, which broke thegeneratedjob (unresolved import). It is cut again at head:git grep ui_bundle_observe HEADreturns hits only indocs/plans/managed-host-untangle.md(main's census table, lines 603-612, owned by the untangle lane); the fleet-converge.dagimport, mode, steps and generatedfleet-converge.ymlare gone, andgeneratedpasses at the exact head.artifacts/bmc/mtjade1-kvm-still-…/ARGV.txtrecords only thatsource.min.jswas fetched to scratch and not kept (the fact of a fetch, carrying no content).Real-path claims this PR touches: main vs head
Evidence is the
required-floor-dispositionartifact of two real runs, not inference. MAIN = run 37888260658 (a PR run of an unrelated change on main's tree, 29,469 identities). HEAD = run 37885729286 at 49a330b (29,572 identities; later heads only change rung-drop rows and their projection, so no disposition moves). Lanes that run for real:floorplanned_as_changed_witness(the hermetic frame) and the[local-repo-wet]schedule (v2.workflow.local_repo_wet_terminal). No scheduled or cron lane runs any of these modules; on main every claim in all of them readsdeclined_outside_required_gateordeclined_outside_gate_closure/not_executedin MAIN, and a claim runs for real only in a PR that edits its module.megarac_kvm_still(18),megarac_media_convergence(76),megarac_session_release(13),mtcollins1_boot_acceptance_matrix(23),megarac_managed_host_witness(8),megarac_kvm_observer_observe(11),megarac_managed_host_forged_probe(50),megarac_operation_surface(8)not_executedin MAINdeclined_outside_required_gate/declined_outside_gate_closure,not_executedin HEADmegarac_kvm_still2,megarac_media_convergence8,megarac_session_release3, matrix 5 (incl.the_sol_handoff_admission_refuses_a_lost_observation_and_admits_a_held_one,the_handoff_refuses_when_no_sol_observation_holds,a_gate_that_opens_for_a_lost_observation_is_distinguished_from_the_real_one,a_start_that_stops_with_code_16_refuses_as_a_timeout_carrying_the_raw_code,a_wall_clock_jumping_forward_during_readiness_closes_the_window),megarac_managed_host_witness3,megarac_operation_standing4planned_as_changed_witness/passedin HEAD (floor)mtcollins_sol_host_payload_integrity_witness.committed_sol_host_payload_hashes_to_the_positive_control_identity(SOL capture hash; re-homed from the spx module, its wet row re-pointed inlocal_repo_wet_schedule)not_executedin MAIN[local-repo-wet] ... expected=passed observed=passed, standinghermetic-route-gap-held-and-wet-passed)megarac_spx_ui_surface_artifact_integrity2 (committed_spx_ui_surface_*),megarac_ui_features11,mtcollins1_ui_bundle_observe10,bmc_model_web_kvm5,megarac_operation_surface3mtcollins1_kvm_observer_protocol_wet_witness, 14 claims (4 process-supervision claims with a counterpart, 2 process-supervision claims with none, 8 viewer/protocol claims with none)not_executedin MAINkvm_observer_protocol_wet_witnesses_deleted_with_the_observer(DeletedWithoutReplacement, separate fromhandoff_observer_is_sol_not_kvm_viewer, which is reverted to the SOL-for-viewer handoff substitution only). It lists the 14 by id; maps 4 tosol_hold_stdin_wet_witnesscounterparts (a_launch_that_cannot_publish_its_pid_stops_the_child_it_created,a_publication_failure_stops_even_a_term_ignoring_child,a_record_this_attempt_did_not_establish_is_not_released,our_collector_is_released_observed_gone_and_its_record_retired); names the 2 with none (unreadable process state, observer directory) and the 8 viewer/protocol claims. Correction: the count is 4 mapped + 2 unmapped supervision claims, not 5 + 2. Trigger: a public client that establishes the observer AND a real-execution protocol witness onlocal_repo_wet_schedulecovering the 10 uncovered claims.megarac_media_convergence(nothing_presented_with_a_code_outside_the_table_and_the_host_on_refuses_before_any_write), not re-added to the matrix because it exceeded the new-witness eval-step budgetNo lane or gate is enrolled by this PR. #13497 also edits
fleet-converge.yml: whichever lands second merges main and regenerates it.🤖 Generated with Claude Code