Repository navigation
Conversation
gunbc.bmc_netboot_serve carried srv4 as hand-spelled constants. It now derives each host's plan from one BmcNetbootHostRow (controller address, serve location, console password hash), and the plan consumes the shared gunbc.boot_artifact_delivery BmcHostedServeLocation instead of duplicating serve_port / serve_dir / host_boot_interface. BmcHostedShellBootParams is split into that location plus the artifact digest, so a roster row names where the bootstrap is served without inventing a bootstrap digest. Hostname comes from gunbc.hostname_allocation; keys from the fleet; the install payload from one constructor (bmc_netboot_autoinstall_of). bmc_netboot_plan_for_host refuses a host with no row or no allocated hostname by name, and bmc_netboot_provision_for_host replaces srv4_bmc_netboot_provision. srv4 is the only row; srv13-srv16 get rows at first contact, when their addresses are observed. srv4 serves the same bytes: srv4_roster_plan_equals_the_literal_plan_it_replaced pins the derived plan equal, as a value and in its grub config and seed, to the literal plan it replaced (built on srv4_ubuntu_autoinstall_on_iso). Two frontier rows, registered in census_closure_frontier: the fleet runner user has no autoinstall carrier (the payload models one identity), and nothing reads back that the host came back from its NVMe after install (homes named: HostInstalledOsStanding, HostReturnObservation). The BmcHostedShellBootStanding row is narrowed to say the serve is roster-driven but observes nothing back. Witnesses run with a fresh claim_batch, every file importing a changed module: bmc_netboot_serve 12/12, bmc_netboot_shell_boot 2/2, bmc_netboot_typed_staging 7/7, boot_artifact_delivery 34/34, no_fallback_plan_ineligibility_wall 4/4, network_boot_manifest_broker 23/23, dissolution_census 5/5, bmc_capability_solve 5/5, bmc_firmware_evidence_install_mechanism 11/11, annotation_carrier 7/7, arm_ci_seller_census 11/11, ebay_browse 13/13, job_admission 12/12, runner_canary_receipt 19/19. cloudflare_r2_token (17) does not resolve: its own unchanged line 213 compares an optional Map get with a string, which the current seed refuses; not touched here. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 627aecb12d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| Present { value: _ } => acc | ||
| Absent => if (r.host as String) == (host as String) { Present { value: r } } else { none } |
There was a problem hiding this comment.
Reject duplicate hosts in the netboot roster
When the planned additional host rows are added, accidentally listing one host twice is silently accepted: after the first match this fold preserves it and ignores every later matching row. bmc_netboot_provision_for_host would consequently SSH, copy files, and launch the server using whichever BMC configuration appears first, even if another row contains the intended address or password. Build the list through duplicate-refusing admission such as std.allocation_roster, or return an ambiguity refusal before provisioning.
Useful? React with 👍 / 👎.
gunbc.bmc_netboot_serve carried srv4 as hand-spelled constants. It now
derives each host's plan from one BmcNetbootHostRow (controller address,
serve location, console password hash), and the plan consumes the shared
gunbc.boot_artifact_delivery BmcHostedServeLocation instead of duplicating
serve_port / serve_dir / host_boot_interface. BmcHostedShellBootParams is
split into that location plus the artifact digest, so a roster row names
where the bootstrap is served without inventing a bootstrap digest.
Hostname comes from gunbc.hostname_allocation; keys from the fleet; the
install payload from one constructor (bmc_netboot_autoinstall_of).
bmc_netboot_plan_for_host refuses a host with no row or no allocated
hostname by name, and bmc_netboot_provision_for_host replaces
srv4_bmc_netboot_provision. srv4 is the only row; srv13-srv16 get rows at
first contact, when their addresses are observed.
srv4 serves the same bytes: srv4_roster_plan_equals_the_literal_plan_it_replaced
pins the derived plan equal, as a value and in its grub config and seed,
to the literal plan it replaced (built on srv4_ubuntu_autoinstall_on_iso).
Two frontier rows, registered in census_closure_frontier: the fleet runner
user has no autoinstall carrier (the payload models one identity), and
nothing reads back that the host came back from its NVMe after install
(homes named: HostInstalledOsStanding, HostReturnObservation). The
BmcHostedShellBootStanding row is narrowed to say the serve is roster-driven
but observes nothing back.
Witnesses run with a fresh claim_batch, every file importing a changed
module: bmc_netboot_serve 12/12, bmc_netboot_shell_boot 2/2,
bmc_netboot_typed_staging 7/7, boot_artifact_delivery 34/34,
no_fallback_plan_ineligibility_wall 4/4, network_boot_manifest_broker 23/23,
dissolution_census 5/5, bmc_capability_solve 5/5,
bmc_firmware_evidence_install_mechanism 11/11, annotation_carrier 7/7,
arm_ci_seller_census 11/11, ebay_browse 13/13, job_admission 12/12,
runner_canary_receipt 19/19. cloudflare_r2_token (17) does not resolve:
its own unchanged line 213 compares an optional Map get with a string,
which the current seed refuses; not touched here.
🤖 Generated with Claude Code