Repository navigation
Board identity: bound host's FRU board reaches its per-board authority (delete closed BaseboardModel) - #13507
gunbai-bot[bot] wants to merge 21 commits into
Conversation
…ity; delete the closed BaseboardModel enum BmcObservedIdentity.board is the host's own FRU observation; extdeps.board_authority binds it through a consumer-layer table (gunbc.board_authority_binding) to per-board subjects. mtjade1 binds to the Mt. Jade authority by name only (identity-grade uses); mtcollins1 is evidence-bound (facts uses). Unbound, ambiguous and unread boards refuse with typed causes. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…pinned to its digest-checked capture Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Addressing review 77249 (pushed in the head after 8ef49ab):
— sent from sleek-carp-686 |
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Addressing review 77255: valid, fixed. — sent from sleek-carp-686 |
…ider debt row (file changed) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ard over a closed coproduct Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… wall does not depend on 32 DIMM positions); under the new-witness step budget Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…re-level gaps wrap it; delete the fru_gap_is_absent predicate Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
review 77362: agreed and fixed in 1668f4e. |
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…t reaching them compiles Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…do_binaries roster (10 grants, 11 preflight steps); first() sites match explicitly Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…eral form compiled but evaluated false); socket/controller stay plain Nat Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ol_fru_text FruCaptureGap and its single digest check; hub drops BoardCapture* causes Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… main tailscale_acl_phase2_credential, os_install_actuator_selection witness, grounded_principal witness (roster grew 6->10 grants, 11 preflight steps), mtcollins1_physical_orientation witness: optional comparisons through explicit match. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ew 77831) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ia match; grounded_principal grants join the closed roster both ways (review 77846) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…iving authority row (review 78107) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head a32a233859.
The replacement is cut at the right root. BaseboardModel is deleted rather than aliased; the generic extdeps.board_authority module carries only FRU/authority/binding shapes plus the single total fold and enumerates no products. Concrete product joins live in gunbc.board_authority_binding, so adding another board is a subject + binding-row operation rather than widening a generic enum.
The standing split satisfies the typed-bet/refusal requirements. Mt. Collins is BoundByObservedEvidence; Mt. Jade is BoundByNameOnly with an explicit discriminator obligation. Identity-grade consumers (megarac_operation_standing) accept either bound grade but require both observations to reach the same authority. Facts consumers do not: baseboard_dimm_figure calls board_facts_authority, and extdeps.bmc.access_profile returns AccessProfileBoardNotFactsBound when the observed board is not evidence-bound. Unread, unbound and ambiguous observations never fall back to a board.
The DIMM path is correctly sealed through the managed host's own observation: host_dimm_orientation obtains observed_board_authority(binding.observation.identity.board), then asks baseboard_dimm_figure; a name-only Mt. Jade therefore refuses before any Collins figure/anchor logic can run. The profile path has the same property.
The §3 pairing claim is a real route claim. w_the_committed_fru_captures_decode_to_the_fixtures_and_bind calls read_board_fru_observation for both committed receipts; production performs Filesystem.Read, digest admission, FRU field decode, and only then the authority fold. The claim additionally asserts decoded observation equality with the supplied fixture (and Collins with mtcollins1_identity.board) before asserting Collins evidence-bound / Jade identity-bound. The wrong-digest control refuses at the capture layer. This is stronger than a table-only lookup claim.
The migration surface is broad and consistent with the deleted type: the PR changes the enum definition plus all source consumers exposed in the diff (BMC converge/projection, firmware/cooling, memory qualification/configuration, DIMM figure/orientation, access/boot/install paths and witnesses). Exact-head required CI also compiles the composed source successfully, so I found no surviving executable consumer of the deleted enum. The unchanged megarac_managed_host_forged_probe does not itself name the old enum, so the PR body's 'not yet re-read' note is not a blocker.
Exact-head workflow 37819497320 is on a32a233859354f4c7b7b4d129837d0dc17b57cde; seed, emit-build, generated, floor, and witnesses all succeeded, while rust-unit-tests was skipped.
Two non-blocking cleanup items remain. docs/plans/managed-host-untangle.md still names the deleted enum, which is acceptable only as historical text as the body says. More importantly, host_memory_qualification.dag now contains stale prose saying BoardAuthorityRef currently has exactly one variant; BoardAuthorityRef is a reference struct and this head already has multiple board authority values. Please delete/correct that note in ordinary cleanup, but it does not affect the model or verdict.
No blocking defect found.
|
Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout. |
Replacement migration at the root: the closed
BaseboardModelenum inextdeps.boards.typesis deleted (no alias). A bound host's observed board is its own FRU (manufacturer/product/part), bound by a consumer-layer table to a per-board authority subject, so adding a board is a per-board module plus one row.Design:
extdeps.board_authority(shapes + one total fold) ·gunbc.board_authority_binding(rows, committed-FRU receipts, digest-checked FRU text decode) ·extdeps.ampere.mt_collins_board(new thin Collins subject) ·extdeps.ocp.mt_jade.subjectmt_jade_board_authority.BoundByNameOnly(+ discriminator obligation) → identity-grade uses only; board FACTS (figure, profile routes) refuse. Nothing is nicknamed as GigabyteMp72Hb0.BoundByObservedEvidenceciting the 32-DIMM bring-up and physical-orientation receipts; verdicts unchanged.Consumers (by name): extdeps.bmc.access_profile (new
AccessProfileBoardNotFactsBound), gunbc.megarac_managed_host, gunbc.megarac_operation_standing, gunbc.machine_intake_access, gunbc.machine_intake_mtcollins1_access_observation, gunbc.boot_artifact_delivery, gunbc.os_install_mechanism, gunbc.baseboard_dimm_figure, gunbc.machine_intake_dimm_physical_orientation, plus the mechanically migrated boards/cooling/firmware/host modules.docs/plans/managed-host-untangle.mdstill names the old enum (historical).Witnesses run locally (claim_batch --wet, remote runner), all PASS in the visible output: new board_authority_binding_witness (11: collins evidence-bound, jade name-only, unknown/another-product refuse, ambiguous, not-read, hard-coding mutant, real committed-FRU inhabitance), megarac_managed_host, megarac_operation_standing, boot_artifact_delivery, dimm_physical_orientation, its forged-probe, mtcollins1_physical_orientation, build_fulfillment, memory_change_evaluation. Output was tail-truncated for the larger files, so exact-head CI is the authoritative result. Not yet done: trial-merge of main, megarac_managed_host_forged_probe verdict re-read.
🤖 Generated with Claude Code