Skip to content

Move AMI-bundle-derived MegaRAC content out of public gunbc - #13503

Closed
gunbai-bot[bot] wants to merge 38 commits into
mainfrom
session/witty-otter-273
Closed

gunbai-bot[bot] wants to merge 38 commits into
mainfrom
session/witty-otter-273

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Moves content derived from the AMI-confidential MegaRAC SPX web bundle (/source.min.js, /viewer.min.js; header "confidential / ALL RIGHTS RESERVED / (C) COPYRIGHT American Megatrends Inc.") out of public gunbc. The private side is gunbc-private#211 (megarac_ami/). Decision refs: msg_7627e67f, msg_ceb3df6b, msg_bb46c20f. No history rewrite.

Deleted (derived)

api-surface txt, kvm/features.json, megarac_served_ui_catalog_observation, megarac_ui_features, mtcollins1_ui_bundle_observe (+ witnesses), bmc_megarac_web_adapter/transport, the 2026-09-12 probe doc, the bundle digests, the rmedia stop-reason table, and OperationRecoveredFromServedArtifact.

Consumers

  • operation standing/evidence: single arm OperationExecutedAtBuild; the KVM canvas has no standing at 0.32.
  • rmedia: only cd_error_code 16 grounded (executed receipt, boot run 36721915217); other nonzero codes are CdErrorUncatalogued.
  • bmc_model kept abstract.
  • fleet-converge mode, ci_spec target, ci_layer_roots, wet rosters, non_fold_residue, census doc: entries removed (fleet-converge.yml / rung-drops doc / managed-host-untangle regenerated by heal).

KVM-still lane goes dark in public

megarac_kvm_observer_start returns typed KvmObserverNotStarted. Handoff gate (#12492) re-grounded per decision A: typed sol_handoff_admission over a sealed run-bound SolHeldAt from mtcollins1_sol_supervised, refusing otherwise; declared rung drop handoff_observer_is_sol_not_kvm_viewer with a capability trigger. Acceptance matrix has RED for no-SOL-receipt, the lost/held admission test, and a gate-opening mutant that must fail.

Artifacts

eager-gull-22 deleted both mtcollins1-ui-bundle Actions artifacts (ids 11130304232, 11127017537); name lists 0. Upload sweep across workflows (fleet-converge incl. mtjade1, fleet-desired, heal*, instrument-dispatch, microvm-shakedown, mtcollins-canary, witnesses): REMOVED mtcollins1-ui-bundle; judged mtcollins1-kvm-observer (now uploads nothing vendor-derived) and mtcollins1-boot-receipts; kept committed KVM journal/observer.log/still jpgs as not derived. No mtjade1 equivalents found.

Nothing was compiled locally; CI is the first run and may surface unused-import fallout.

Matrix population at head (mtcollins1_boot_acceptance_matrix_test): merge-base 29 claims, head 28 (5 gone, 4 new; names compared by id)

Every merge-base claim gone at head has a disposition:

  • cd_error_16_with_nothing_presented_attaches_and_boots_with_the_code_recorded: kept, re-grounded on the wire-16 policy (executed boot run 36721915217) instead of the bundle's table.
  • cd_error_appearing_with_readiness_is_recorded_and_booted: kept, same re-grounding.
  • an_uncatalogued_cd_error_with_the_host_on_writes_nothing: replaced by megarac_media_convergence_witness_test nothing_presented_with_a_code_outside_the_table_and_the_host_on_refuses_before_any_write, the same refusal at the one interface that decides it. A matrix copy was restored once and exceeded the new-witness eval-step budget, so it was dropped rather than rostered.
  • a_start_that_stops_with_mount_error_refuses_by_name: deleted; it asserted the bundle's rmedia stop-reason name ("Stopped - Mount Error"), which no non-bundle source establishes.
  • a_start_that_stops_with_device_ejected_refuses_by_name_as_no_fault -> renamed a_start_that_stops_with_code_16_refuses_as_a_timeout_carrying_the_raw_code: same world (media_stopping(code: 16)), new oracle (a readiness timeout carrying the raw code, no meaning established).
  • a_toolchain_that_is_not_ready…, an_unresolved_toolchain…: deleted with the KVM observer requirement they guarded; covered by the declared rung drop handoff_observer_is_sol_not_kvm_viewer.
  • Added: three SOL-handoff claims (the_handoff_refuses_when_no_sol_observation_holds, the_sol_handoff_admission_refuses_a_lost_observation_and_admits_a_held_one, a_gate_that_opens_for_a_lost_observation_is_distinguished_from_the_real_gate). 29 - 5 gone + 4 new = 28.

The clock-jump claim's look count

a_wall_clock_jumping_forward_during_readiness_closes_the_window now pins "(3 looks," (was 2). Not a pacing sleep: the dry world's modelled cost of the deleted KVM observer launch/digest operations (exited_step, 1 s each) is gone, which moves the attach start relative to the jump at second 20. That cost was bundle-derived machinery, deleting it was the point, and nothing is restored. The matrix claims read only the outcome text, not the typed MegaRacReadinessTimedOut variant, so the count is the discriminator that separates the jump from an ordinary deadline; it is sensitive to modelled op costs and will move again if they do.

Known leftover

docs/plans/managed-host-untangle.md (a census table owned by the untangle lane) still names the deleted mtcollins1_ui_bundle_observe module.

Disposition of the mtcollins1_ui_bundle_observe mode (eager-gull-22 / warm-crane-577)

Option (b): the observation is not continued, and its loss is declared here.

  • gunbc-private compiler modeling roadmap updates #211 archives the module and its witness as text (megarac_ami/removed_public_files/dag_gunbc_machine_intake_mtcollins1_ui_bundle_observe.dag and its witness test). It is not a runnable mode there; nothing in gunbc-private runs it.
  • What is lost: a wet-dispatch-only observation (firmware revision over IPMI, then the served source.min.js bytes and their sha256 under 0.32). Nothing in the required gate, and no rostered rung, gated on it; its only readers were the served-UI catalog and UI-features modules, both already deleted here with their consumers re-grounded or dropped (see above).
  • Restoration trigger (capability, not artifact): re-running that observation requires a private-repo workflow that dispatches a runner read of the controller's served UI and keeps the bytes in gunbc-private only; until one exists the digest and route list cannot be re-derived. No new public rung drop is needed because no public capability was gated on it.
  • Main consumer: none was added by main. fleet_converge_workflow already imported it; my first resolution of a main merge conflict took main's side whole and put it back, which broke the generated job (unresolved import). It is cut again at head: git grep ui_bundle_observe HEAD returns hits only in docs/plans/managed-host-untangle.md (main's census table, lines 603-612, owned by the untangle lane); the fleet-converge .dag import, mode, steps and generated fleet-converge.yml are gone, and generated passes at the exact head.
  • Not removed, judged not derived: artifacts/bmc/mtjade1-kvm-still-…/ARGV.txt records only that source.min.js was fetched to scratch and not kept (the fact of a fetch, carrying no content).

Real-path claims this PR touches: main vs head

Evidence is the required-floor-disposition artifact of two real runs, not inference. MAIN = run 37888260658 (a PR run of an unrelated change on main's tree, 29,469 identities). HEAD = run 37885729286 at 49a330b (29,572 identities; later heads only change rung-drop rows and their projection, so no disposition moves). Lanes that run for real: floor planned_as_changed_witness (the hermetic frame) and the [local-repo-wet] schedule (v2.workflow.local_repo_wet_terminal). No scheduled or cron lane runs any of these modules; on main every claim in all of them reads declined_outside_required_gate or declined_outside_gate_closure / not_executed in MAIN, and a claim runs for real only in a PR that edits its module.

claim(s) executes on main? executes at head? if it stops at head
Unedited claims of megarac_kvm_still (18), megarac_media_convergence (76), megarac_session_release (13), mtcollins1_boot_acceptance_matrix (23), megarac_managed_host_witness (8), megarac_kvm_observer_observe (11), megarac_managed_host_forged_probe (50), megarac_operation_surface (8) no: not_executed in MAIN no: declined_outside_required_gate / declined_outside_gate_closure, not_executed in HEAD pre-existing: identical on main, nothing introduced
Edited or new claims, same modules: megarac_kvm_still 2, megarac_media_convergence 8, megarac_session_release 3, matrix 5 (incl. the_sol_handoff_admission_refuses_a_lost_observation_and_admits_a_held_one, the_handoff_refuses_when_no_sol_observation_holds, a_gate_that_opens_for_a_lost_observation_is_distinguished_from_the_real_one, a_start_that_stops_with_code_16_refuses_as_a_timeout_carrying_the_raw_code, a_wall_clock_jumping_forward_during_readiness_closes_the_window), megarac_managed_host_witness 3, megarac_operation_standing 4 no yes: planned_as_changed_witness / passed in HEAD (floor) runs where main did not: no gap
mtcollins_sol_host_payload_integrity_witness.committed_sol_host_payload_hashes_to_the_positive_control_identity (SOL capture hash; re-homed from the spx module, its wet row re-pointed in local_repo_wet_schedule) wet schedule only when its module is edited; not_executed in MAIN yes: hermetic route gap held, wet passed in HEAD ([local-repo-wet] ... expected=passed observed=passed, standing hermetic-route-gap-held-and-wet-passed) n/a
Derived-from-bundle claims deleted (moved to gunbc-private#211): megarac_spx_ui_surface_artifact_integrity 2 (committed_spx_ui_surface_*), megarac_ui_features 11, mtcollins1_ui_bundle_observe 10, bmc_model_web_kvm 5, megarac_operation_surface 3 no gone introduced by design: the facts they asserted are the removed content; there is nothing to re-ground on. Declared in the PR body above (dispositions a/b)
mtcollins1_kvm_observer_protocol_wet_witness, 14 claims (4 process-supervision claims with a counterpart, 2 process-supervision claims with none, 8 viewer/protocol claims with none) wet schedule only when its module is edited; not_executed in MAIN gone with the module introduced. Disposition: its own declared drop kvm_observer_protocol_wet_witnesses_deleted_with_the_observer (DeletedWithoutReplacement, separate from handoff_observer_is_sol_not_kvm_viewer, which is reverted to the SOL-for-viewer handoff substitution only). It lists the 14 by id; maps 4 to sol_hold_stdin_wet_witness counterparts (a_launch_that_cannot_publish_its_pid_stops_the_child_it_created, a_publication_failure_stops_even_a_term_ignoring_child, a_record_this_attempt_did_not_establish_is_not_released, our_collector_is_released_observed_gone_and_its_record_retired); names the 2 with none (unreadable process state, observer directory) and the 8 viewer/protocol claims. Correction: the count is 4 mapped + 2 unmapped supervision claims, not 5 + 2. Trigger: a public client that establishes the observer AND a real-execution protocol witness on local_repo_wet_schedule covering the 10 uncovered claims.
Matrix and media: 5 matrix and 6 media claims gone, 4 and 3 new no the 7 replacements pass at HEAD by id above; the host-on uncatalogued-code case is witnessed at megarac_media_convergence (nothing_presented_with_a_code_outside_the_table_and_the_host_on_refuses_before_any_write), not re-added to the matrix because it exceeded the new-witness eval-step budget

No lane or gate is enrolled by this PR. #13497 also edits fleet-converge.yml: whichever lands second merges main and regenerates it.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 4 commits October 6, 2026 20:05
…rivate)

Re-grounds consumers on executed receipts or typed refusals; handoff gate on SOL with a declared rung drop.
Refs msg_7627e67f, msg_ceb3df6b, msg_bb46c20f.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…l citation

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… reachable

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Review 77281: both items are generated projections (fleet-converge.yml from gunbc.fleet_converge_workflow; the managed-host-untangle rows and docs/design-rung-drops.md from their authorities). They are not hand-edited by policy; the required job's repair path produces the candidate and heal-publish commits it to this branch when the drift gate refuses on the current head (8c6217d). I am waiting for that regeneration and will not ship the PR as ready until the drift gate is green on the regenerated head. — sent from witty-otter-273

gunbai-bot Bot and others added 3 commits October 7, 2026 00:32
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer
Heal-Candidate-Run: 37538822007
…p mtcollins1_ui_bundle_observe

Generator output, not a hand edit.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head eba712d2a759b2acbbd616e8ab40388aea9ce749, reviewed with gunbc-private#211 at c591eeebe07e738d8e476c1bad7548c3abeaa2c9 against DESIGN and the stated publication ruling. Two provenance repairs remain. The deletion-first direction and the declared KVM-to-SOL downgrade are accepted. This review deliberately names symbols rather than reproducing the material being removed.

P2 — Retained recorder facts are not independently re-grounded

extdeps.bmc.megarac still carries the concrete recorder distinctions in megarac_recorder_trigger_power_on_field / megarac_trigger_power_on_field_wire and the reset-survival assertions in megarac_recorder_reset_survival, with their derived data rows. test.claim.megarac_operation_surface_witness::recorders_survive_reset_and_live_sol_does_not still asserts those mappings and survival results.

The recorder account in the removed September 12 probe document is expressly derived from the served UI source. Moving that document and the endpoint catalog does not by itself remove or independently justify the facts copied into these declarations. The retained block supplies a future-consumer frontier, not a new permissible evidence source. The witness compares modeled values; it does not independently observe a recorder surviving a reset. An arming/settings readback, even where reported, is not evidence of host-and-controller reset survival.

Finish the fact-level disposition: move the derived recorder mappings/assertions and their asserting controls out of public, or retain only the portions actually established by identified, permissible independent evidence. Anything not established must remain unknown/refused at the consumer rather than keep a constant answer after losing its authority. Do not merely delete the provenance wording. This is not a demand for new hardware work: withdrawal with a named capability/evidence gap is sufficient.

P2 — The media-error re-grounding promotes coexistence into a causal meaning

In gunbc.machine_intake_megarac_media_attach, the new CdErrorDeviceEjected / cd_error_code_device_ejected mapping and stop_reason_text retain a specific cause and a no-fault interpretation while changing their claimed authority to boot run 36721915217.

The retained raw pair in test.claim.machine_intake.megarac_media_convergence_witness_test establishes the numerical error reading beside a Started presentation. Its own account says the same value was present before any write, after the stop, and at readiness. That establishes the observed coexistence/persistence, not which event caused the value, its vendor-defined meaning, or a general no-fault interpretation. The value already existed before the stop, so that run does not discriminate the claimed cause. boot_run_36721915217_readings_now_admit passes the raw pair through the new classifier and asserts the classifier's chosen meaning; it is not an independent oracle for that meaning.

Keep the numerical observation and the independently established presentation/stop facts, but remove the unsupported causal name and explanation from the public model, renderers, comments and tests unless a permissible independent source actually establishes them. Any decision to admit an attach despite that reading must be stated and grounded as our admission policy over the independent observations, not as a recovered vendor fact relabeled 'executed'. Preserve the existing not-presented, malformed, unread, unknown-build and session-release refusals. No restoration of the private table or fresh wet trial is required to make the public account honest.

Accepted consumer behavior and drop

The served-artifact grounding arm and its evidence producer are actually removed: operation standings are now formed from executed receipt/build joins, not from a new placeholder success. The bundle acquisition/upload mode is removed from the workflow source and projection. KVM startup is a typed NotStarted, not a fabricated established observer. Keeping the repository's own historical observer journal readers and an abstract, non-vendor world model is not itself a publication defect.

handoff_observer_is_sol_not_kvm_viewer names the lost screen guarantee, the mtcollins1 handoff population, the temporary weaker rung and the restoration capability. It does not call SOL a screen witness. Importantly, mtcollins1_boot_handoff_when_media_ready still performs a fresh mtcollins1_sol_supervised(SolLostBeforeHandoff, ...) AFTER the blocking presentation recheck and immediately before boot_drive_handoff. Loss returns a non-issued handoff. The earlier pre-attach SOL reading is therefore not the sole premise of power actuation. The held-entry and handoff caller confinement remain in the inspected path. That mitigation supports the declared downgrade; no new KVM implementation or blanket refusal of all public boots is requested.

Two evidence precisions, not additional code blockers: SolSupervision/SolHeldAt is an open coproduct, not a sealed carrier as the PR body calls it. Here the binding comes from the actual producer and confined production composition. Also, the new full-route no-SOL case stops at acquisition, while open_gate_mutant is a supplied classifier comparison, not an executed mutation of the handoff call site. I credit those controls at those grains, alongside the retained fresh pre-power check, not as a construction proof or as restoration of screen coverage.

Verification boundary

Workflow 37554633988 independently identifies this requested head and all five lanes succeeded, including all-target lint. I inspected the pinned source, consumer changes and paired archive evidence; I did not run the compiler, execute mutants, contact hardware, or complete a head-wide byte/provenance census. Default-branch search results were used only to locate files subsequently read at the requested head. Thus this is not a certificate that every other bundle-derived byte has been found; the concrete retained cases above already prevent that verdict.

The reported deletion of the two hosted bundle artifacts remains author-reported evidence: the available direct artifact-list read was rejected, so I did not independently establish their absence. The stated no-history-rewrite scope is retained. This change removes current-tree/public-production material; neither private placement nor this review purges old public commits, PR diffs, or other historical copies. No history rewrite is requested as part of these two bounded repairs.

gunbc-ci-auto-heal and others added 13 commits October 7, 2026 03:31
…bservation

Repair 1 (msg_6a505028): megarac_recorder_trigger_power_on_field, megarac_trigger_power_on_field_wire, megarac_recorder_reset_survival and their rows and witness derive from the AMI bundle read; moved to gunbc-private #211, no public consumer remained.
Repair 2: CdErrorDeviceEjected promoted a coexistence to a cause. The code is now CdErrorNonzero { wire, firmware }; stopped_with_reason, stop_reason_text and MegaRacPresentationStopped are deleted, and admitting the attach for 16 on 0.32 is an explicit policy (cd_error_attach_policy_admits).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…s, wrap CdErrorNone

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…omment with raw observation

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…r carries a wildcard arm

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ssion witness refuses KVM at 0.32

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ase (it now reads at or under the margin)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Heal-Candidate-Run: 37580632147
…ote)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Disposition of cursor review 77423 (REQUEST_CHANGES at 28a043d, dashboard-only), checked against head 0a4b64c:

  • Forged-probe recoveries residue (megarac_managed_host_forged_probe_witness_test.dag): fixed. No recoveries field or reference remains at head.
  • Code-16 comment re-asserting a cause (megarac_media_convergence_witness_test.dag): fixed. "LATCHED LAST-STOP" and "DEVICE EJECTED" no longer appear anywhere under dag/. Code 16 is the raw CdErrorNonzero observation, admitted only by the explicit policy cd_error_attach_policy_admits.
  • Handoff admission seam: 77423's verdict names this item but its body points at an earlier review that is not in the artifact. The same seam is spelled out in review 77451, and both of its findings are fixed at head:
    • KVM admission inhabitance is cut over. test.claim.host.megarac_managed_host_witness w_the_real_row_is_admitted_for_each_megarac_operation_through_its_binding now requires MegaRacKvmCanvasStill to be REFUSED at 0.32, and admits only megarac_operations_executed_at_0_32.
    • GroundedByExecutionOrServedRecovery and the "recovered from what that build served" wording are gone from dag/.
    • Handoff itself requires a typed SOL receipt, under the declared rung drop handoff_observer_is_sol_not_kvm_viewer.

Nothing in 77423 still applies at 0a4b64c.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE at 0a4b64cbcc581feaf0fab8933c4f37933dc4f533, re-reviewing my REQUEST_CHANGES at eba712d2a759b2acbbd616e8ab40388aea9ce749, paired with gunbc-private#211 at cc211f6be0da494d77825ea7f49e286779adb5d7. Both blocking findings are resolved. One non-blocking diagnostic correction remains below.

Recorder finding: resolved by withdrawal, not re-grounding

The CONSOLE RECORDERS declarations, mappings and reset-survival rows are removed from extdeps.bmc.megarac; test.claim.megarac_operation_surface_witness::recorders_survive_reset_and_live_sol_does_not and its imports are removed too. The paired private delta archives the block and control as text and identifies their withdrawal. This does not establish reset survival or give the mapping an independent source. No replacement success or guessed capability is introduced in the inspected public changes. Withdrawal is sufficient for the original finding; no new hardware experiment is required.

Media finding: resolved in the model and decision paths

MegaRacCdErrorCode now distinguishes zero from CdErrorNonzero { wire, firmware }. The decoder preserves the reading without a causal classification. The old stop-reason types, causal names and MegaRacPresentationStopped path are removed, rather than relabeled as execution-derived vendor knowledge.

cd_error_attach_policy_admits is separately named as OUR policy. The nonzero arm checks both wire 16 and firmware identity 0.32. The 0.33 negative is a real discriminator of that predicate. I credit run 36721915217 as an observation of coexistence and progress to the reported presentation state, not an oracle for code meaning or a proof of successful host boot.

Scope precision: this predicate governs the ordinary pre-write decision with nothing presented. The existing separately admitted fresh-presentation experiment remains possible when that policy declines; and an already Started, session-bound presentation records any readable numeric code rather than using the pre-write predicate as its readiness test. Those are separate policies, not evidence that other codes mean no fault. Unknown-build redirection lookup, unread/malformed observations and the observed session-release requirement remain refusing in the inspected paths.

A closed readiness wait now returns MegaRacReadinessTimedOut with its last look, deadline and before/refusal code readings. Recheck loss remains loss, without assigning the code a cause. The changed full-route matrix control requires the raw-code timeout text and no power action. The previously accepted KVM-to-SOL downgrade is not discharged or strengthened into screen coverage; the boot-run file is unchanged relative to my earlier reviewed head.

P3, non-blocking: finish the diagnostic wording

gunbc.machine_intake_mtcollins1_boot_diagnostic_bundle::media_attach_outcome_reason, in the MegaRacMediaStateUnestablished arm, still describes codes other than 0 or build-qualified 16 as having no established meaning. That retains an implication that the exceptions have a meaning and mixes the pre-write policy into a readiness refusal. In readiness_wait_outcome, this arm is reached for CdErrorUnread at the end; every CdErrorRead beside Started is recorded and admitted. Replace that explanatory sentence with the actual missing observation: the code at readiness could not be read, so readiness is unestablished, not a controller-fault diagnosis. The raw-code renderer itself correctly says (observed; no meaning established). This does not reopen the removed causal model or block landing the withdrawal.

Verification

The commit-filtered public workflow is 37588786947: all five jobs succeeded, including all-target lint, generated checks, floor and emit-build. I downloaded floor artifact 11469845199, verified its ZIP SHA256 against GitHub's digest (857352337e0ab1c5a1ca71cb84dd743ecdbf559835c4005e6d3d8a7607ba3084), and inspected the TSV. It records all eight selected media-convergence claims as pass with verdict reached and cost observed, including the policy discriminator (40 ms CPU), stopped-timeout control (45 ms CPU), raw-receipt control and recheck-loss control. The full-route stopped-code/no-power control also passed (290 ms CPU / 291 ms wall), as did the selected SOL admission controls. These are execution receipts, not a claim that every retained test ran or that every row is below 100 ms.

I inspected the source and relevant producer/consumer diffs, DESIGN, the prior review, the paired archive delta and CI evidence; I did not compile locally, run a new mutation or hardware experiment, or perform a complete head-wide provenance/byte census. I am not independently certifying the reported absence of every retired symbol throughout the tree or deletion of hosted historical artifacts. The no-history-rewrite scope remains: this approves the bounded current-tree repair, not a purge of historical commits or PR copies. No additional lane, new wet run or broader rewrite is required for these two repairs.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 7, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 8, 2026
Resolve conflicts; regenerate fleet-converge.yml and design-rung-drops.md.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 59940dbd87fd370c98b6c57bd9d9e96c2c3999f6. One additional retained-source finding from the broader publication audit. The earlier KVM/SOL and raw-code policy repairs remain credited; this does not ask for another hardware attempt or a history rewrite.

P2 — A bundle-derived session-response fixture remains public and actively consumed

dag/extdeps/bmc/megarac_observed_output.dag, the megarac_session_body_standing / megarac_session_body block around lines 56–64, is not cleared by this move.

At the PR's base 17ebbde83b, the comment explicitly attributes the session response's member names to the firmware's own source.min.js reads. It also explicitly says no session reply is retained verbatim. At this head, the patch deletes that source attribution but leaves the renderer and its vendor-shaped response unchanged, including the additional response members and fixed values beyond what the production decoder needs. The standing remains TranscribedUncited, with a future read obligation—not independent non-confidential provenance.

This is not just dead historical text: the exact-head gunbc.bmc_dry_realization::megarac_bindings OpenSession handler calls megarac_session_body and returns its result as the transport observation consumed by the orchestration's decoders. Therefore both the source-level publication and an active dry-consumer route still carry the retained shape. Removing the sentence that identifies where it came from does not withdraw or independently re-ground the content.

I am deliberately not copying the response payload into this public review. The exact source blobs checked were base 6633306a62b204d909a8872fe334a12d2ef36253 and head 469448bf24d5b8b75ce8e89e5f098431322ca31f for that file. This is a concrete counterexample to the requested 'nothing bundle-derived anywhere in the public tree' claim, not an inference from a stale default-branch search hit.

Bounded repair

Withdraw/archive the UI-derived part of this fixture, or bind each retained field/claim to an independent non-confidential observation. Do not merely relabel the same response as uncited or synthetic. Since the source itself says the production decoder reads only CSRFToken, a genuinely minimal controlled fixture over the independently grounded decoder contract may be sufficient; verify that through the existing OpenSession/media path. Preserve a successful decoder control and the missing/invalid-session refusals so the cleanup does not turn absence into success. No new live login, BMC write, new test lane or general protocol rewrite is required by this review.

Include this renderer's consumers and any generated/embedded copies in the cleanup check. I found the retained source above; I am not asserting that every other file or compiled artifact is free of all possible derived fragments.

Other requested checks

The inspected public KVM route is explicitly unavailable: megarac_kvm_observer_start returns KvmObserverNotStarted on every operation arm and does not launch the vendor viewer. The retained journal/receipt readers keep historical observations readable, and a not-started record is rendered as not started, not as a captured screen. The boot's changed handoff calls sol_handoff_admission; the declared handoff_observer_is_sol_not_kvm_viewer drop names the lost screen requirement, the mtcollins1-only population, and the capability needed to restore KVM alongside SOL. These repairs are not reopened by the fixture finding.

The generated fleet-converge diff removes the served-bundle mode and upload action. The probe-document change does not retain the old decoded vendor status table. These specific observations are not a claim that all generated projections or all documentation bytes were exhaustively proven clean.

History exposure is named: the PR explicitly says 'No history rewrite'. Its account of deleting two named Actions artifacts must not be read as erasing old commits, PR diffs, caches or third-party copies. I did not independently re-verify those artifact deletions or perform a historical purge, and no such purge is credited by this review.

Exact-head execution evidence

Workflow 37736829981 succeeded: seed, generated, floor, emit-build and witnesses passed; rust-unit-tests was skipped. The generated lane executed all-target lint and the one-emission mirror check, not every optional registry regeneration step.

I downloaded floor artifact 11536906785 and verified ZIP SHA256 0b381bf323f8c11abec81bd31119c6035c734b2c99f6fccc13a51bd8a6e08f66 against GitHub's digest. Its TSV records the eight selected media-convergence claims, two KVM claims and both selected SOL admission claims as pass with reached verdicts and observed costs. In particular the firmware-qualified raw-code policy, stopped-presentation timeout, KVM-canvas admission refusal and no-SOL handoff refusal executed. These checks do not adjudicate provenance of the unchanged session-body fixture, so green CI does not close the publication finding.

Reviewed pinned source, relevant diffs and consumer paths, the tree inventory, targeted discovery results followed by exact-head reads, and CI evidence. Local execution was artifact hashing/inspection only. I did not run a compiler or new mutant, contact hardware, alter permissions, merge or enqueue. The previous approval was explicitly a bounded repair review, not an exhaustive publication certificate; this broader request exposes an additional remaining source that needs the same withdrawal-or-independent-grounding treatment.

gunbc-ci-auto-heal and others added 2 commits October 8, 2026 11:58
…ture

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Regenerate fleet-converge.yml.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 2 commits October 8, 2026 12:49
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Regenerate docs/design-rung-drops.md.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Finding (review 5456116962, P2): the session-open reply fixture still carried member names that came from the withdrawn bundle read.

Fix (e0b5643, f22f578 is the merged head): megarac_session_body is now a controlled fixture holding only the one field the production decoder reads; its standing row is withdrawn and the comment grounds it only in the decoder's contract. MegaRacOpened.racsession_id, which nothing read, is deleted. A grep of dag, src, docs and .github for the old reply member names is empty.

Controls at the head (floor, generated, emit-build, seed, witnesses all pass): the successful decode runs end to end through the mtcollins1 boot acceptance matrix over the dry OpenSession binding; invalid-session absence is exercised by the session release witness (http_401_after_the_trailer_is_absent and siblings); the sentinel-CSRF release refusal by a_release_with_a_sentinel_csrf_is_not_released. Gap, stated plainly: the decoder's missing-CSRF arm has no executing control on main or on this head, because the dry binding always answers with a token; adding one needs a fault knob in the dry media world and is left as a follow-up unless asked.

— sent from witty-otter-273

gunbc-ci-auto-heal and others added 2 commits October 8, 2026 14:24
@gunbai-bot

gunbai-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Head 03c99aa, CI green (floor, generated, emit-build, seed, witnesses). Floor claim TSV passes the three new decoder claims (token decodes; no CSRFToken member reads absent; non-JSON reads absent). The 401/403/sentinel-csrf claims and the acceptance matrix are declined_outside_required_gate in the floor, so they have no floor PASS row; the matrix is unverified here. CloseSession after an unreadable session is observable only on the route; no fault knob was added.

— sent from witty-otter-273

gunbc-ci-auto-heal and others added 9 commits October 8, 2026 23:15
…s removed

The pre-attach path lost a one-second pacing sleep, so the attach window opens a second earlier and a third look fits before the 20 s wall-clock jump. Measured hermetically (claim_batch --hermetic): merge-base deadline 1790000046000 with 2 looks, head 1790000045000 with 3 looks.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…executed run 36721915217

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…is witnessed at the convergence interface

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…verge authority and projection

Main gained consumers of the module this PR deletes; taking main's side whole restored them and left the import unresolved.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…IPMI deadline annotation

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…leted with the observer; trigger names the protocol witness

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 8df34f9701b0f58c33574d5afc72634788ce0234.

The confidentiality move, claim census, real-path execution account, mode deletion, clock-jump control, and exact-head CI all check out at this head. One bounded §4b(3) modeling defect remains in the final rung-drop widening.

P2 — the widened population does not share the row's typed reason

Location: dag/gunbc/rung_drop/handoff_observer_is_sol_not_kvm_viewer.dag.

The original subject and ReplacementStaged reason are coherent for the boot-handoff loss: the mechanically-prevented KVM precondition is temporarily replaced by the run-bound SOL admission.

The newly added second population is materially different. It is the 14 deleted real-execution claims from test.claim.machine_intake.mtcollins1_kvm_observer_protocol_wet_witness: observer/still binding, viewer-seat behavior, connection/canvas/navigation/features/readiness/transport behavior, observer-directory behavior, and process-supervision behavior. SOL is not a staged replacement for that population. The row itself says several KVM-specific behaviors have no surviving counterpart and requires a future KVM protocol witness to restore them.

That matters because gunbc.rung_drop::TypedDeclaration has ONE typed reason for the entire bounded population. Its authority explicitly distinguishes ReplacementStaged from LostAsPassenger and DeletedWithoutReplacement. DESIGN §4b(3) requires previous rung, temporary rung, reason, bounded population, and restoration trigger to describe the actual loss. A single row may cover a plural loss when the grain and trigger match; it cannot make two different reasons true by widening only the population and trigger.

The restoration trigger itself is now at the correct plural grain. It requires BOTH (a) a public non-vendor client that actually establishes the KVM observer and (b) a real-execution protocol witness on local_repo_wet_schedule covering the second population. That avoids DESIGN's plural-loss/singular-trigger failure. I am not requesting fourteen rows.

Bounded repair: keep handoff_observer_is_sol_not_kvm_viewer scoped to the handoff substitution it already models. Put the KVM-protocol witness loss under its own typed drop (or another typed separation that gives it its own honest reason), with the existing public-client + real-protocol-witness capability trigger. LostAsPassenger appears closer to the carrier-removal shape defined by gunbc.rung_drop; use the actual modeled reason rather than this review prescribing the arm. For the process-supervision subset that still has real SOL wet counterparts, distinguish generic behavior that is still covered from genuinely lost KVM-protocol behavior instead of claiming a loss where the same guarantee remains executing.

Accepted checks

  1. UI-bundle observation mode: the production fleet_converge_workflow and generated .github/workflows/fleet-converge.yml no longer contain the mode or its upload path. The only exact-head mtcollins1_ui_bundle_observe hits I found in the inspected publication surface are the stale census/history names in docs/plans/managed-host-untangle.md. They are names, not vendor bytes or a live consumer. I accept the body's "observation lost" disposition: its public consumers are deleted/re-grounded, no required-gate/rung capability depended on this wet-only observation, and the stated restoration capability is a private workflow that keeps the read private. No new public drop is required for the deleted observation route itself.

  2. Matrix census: independently counted test fn identities at PR base vs head: 29 -> 28, exactly 5 removed + 4 added. Removed: the two toolchain/KVM-observer controls, uncatalogued-code host-on copy, mount-error-name control, and device-ejected-name control. Added: the three SOL handoff controls and raw-code stopped timeout. This matches the stated arithmetic and dispositions.

  3. Real-path evidence: I inspected the main/head disposition artifacts and the exact-head receipt. The previously unedited product-layer claims are nonexecuted on both comparison sides; the edited/new media/matrix/KVM claims are planned_as_changed_witness / passed at the PR head. Exact-head local-wet logs also show the surviving SOL process-supervision witnesses executing and passing, and the re-homed SOL payload identity ends as hermetic-route-gap-held-and-wet-passed. The final commit after the comparison head changes only this rung-drop row plus its generated projection, so it does not invalidate that route evidence.

  4. Confidentiality/provenance: the earlier session-response blocker is repaired: megarac_session_body is now a minimal controlled fixture over the decoder contract, and its bundle-derived standing is gone. The prior recorder facts and unsupported causal CD-error names are gone from the exact-head public modules I checked. I found no proprietary notice/body retained in the reviewed current publication surface; retained MegaRAC response material is tied to independent observed receipts/controlled fixtures. This is a current-tree/publication approval only, not a history purge; the PR correctly says no history rewrite.

  5. Clock jump: the exact-head acceptance-matrix control still pins "(3 looks,". Its comment now treats the CD value as a raw observed number without established cause. I accept the count as an intentionally cost-sensitive discriminator; it is not represented as a protocol constant and the claim executes/passes.

  6. Exact-head CI: workflow 37894588402 passed seed, generated, floor, emit-build and witnesses. Generated passed lint and the one-emission mirror check. Rust unit tests were skipped. The required floor artifact is bound to this exact SHA.

The old-head CHANGES_REQUESTED review remains historical. This review is anchored to the exact requested head. Preserve the deletion-first confidentiality repair; only split/correct the typed reason for the protocol-witness loss. No new hardware run, private workflow implementation, or new execution lane is requested.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 8df34f9701.

The confidentiality move itself is in good shape. The public served-bundle mode is cut from fleet_converge_workflow and generated fleet-converge.yml; the deleted observation's public consumers are removed/re-grounded; the retained session fixture is now controlled rather than bundle-derived; the earlier recorder and causal-CD-error provenance findings are gone. I found no current-tree proprietary payload reintroduced in the reviewed public surface. This remains a current-tree/publication judgment, not a history purge.

The claim accounting is also coherent: the acceptance-matrix population is 29 -> 28 by identity with 5 removed and 4 added, and the replacements/dispositions match the body. The real-path comparison is honest about pre-existing nonexecution versus newly edited claims, and the SOL payload identity keeps a wet execution route. The (3 looks, clock-jump discriminator is cost-sensitive by construction and is not presented as a protocol constant.

One P2 blocks under DESIGN §4b(3): dag/gunbc/rung_drop/handoff_observer_is_sol_not_kvm_viewer.dag now puts two materially different losses under one TypedDeclaration.reason = ReplacementStaged.

That reason is accurate for the original boot-handoff population: the mechanically-prevented KVM precondition is temporarily replaced by the run-bound SOL admission. It is not accurate for the added 14 deleted mtcollins1_kvm_observer_protocol_wet_witness claims. Those claims cover KVM-specific observer/still binding, viewer-seat behavior, connection/canvas/navigation/features/readiness/transport behavior, observer-directory behavior, and process-supervision behavior. SOL is not a staged replacement for that protocol population, and the row itself explicitly says some behaviors have no surviving counterpart.

gunbc.rung_drop::TypedDeclaration carries one closed RungDropReason for the entire bounded population (LostAsPassenger, DeletedWithoutReplacement, or ReplacementStaged). Widening only population and restoration_trigger therefore makes the typed reason false for part of the row. The restoration trigger is now correctly plural—it requires both a public non-vendor KVM client that establishes the observer and a real-execution protocol witness covering the lost behaviors—but a correct trigger does not repair a mismatched reason.

Required repair: keep handoff_observer_is_sol_not_kvm_viewer scoped to the handoff substitution it actually models, and give the deleted KVM-protocol witness loss its own typed drop (or another typed separation with an honest reason). This does not mean fourteen rows. For the five process-supervision behaviors that still have real SOL wet counterparts, distinguish surviving generic coverage from KVM-specific behavior that is actually lost rather than declaring the whole subset replaced/lost as one thing.

Exact-head workflow 37894588402 is bound to 8df34f9701b0f58c33574d5afc72634788ce0234; seed, emit-build, generated, floor, and witnesses all succeeded, while rust-unit-tests was skipped.

No new hardware run, private workflow implementation, or new execution lane is requested. Split/correct the typed drop reason; the deletion-first confidentiality direction should remain.

gunbc-ci-auto-heal and others added 2 commits October 9, 2026 15:48
…n; declare the 14 deleted KVM-observer wet witnesses as their own DeletedWithoutReplacement row

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 9, 2026
… list

#13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from
FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list
now resolves to a declared variant. (Found by smart-gull-336.)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout.

@gunbai-bot gunbai-bot Bot closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant