Repository navigation
CONTROL (do not merge): #13211 head + union-emit begin line - #13620
Closed
gunbai-bot[bot] wants to merge 48 commits into
Closed
gunbai-bot[bot] wants to merge 48 commits into
gunbai-bot[bot] wants to merge 48 commits into
Conversation
…inding (leg 2) One JIT mint over a slot sum (microVM cell | transient systemd unit on a gunbc.managed_host host); ensure-style deregistration with org-listing readback and typed refusal on every exit; teardown inventory generalized to a host-unit arm; census row for deregistration (pre-approved, ruling 2026-10-03); route legs registration/deregistration bound. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttempt label as input; collect the run back (leg 3) Generalizes extdeps.github.workflows CreateDispatch from the heal-only expected_healed_sha key to the upstream's own inputs object, and dissolves create_dispatch_unconsumed_frontier_rows with a production caller. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ack's subject is the dispatched run Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e the carrier-returning helper (constructor proxy) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pt, token check, workflow compare; split RouteLegStanding
(1) post-delete listing consumes the delete receipts (readback_after_deletes)
(2) JitRegistration sole_constructor, minted only by jit_registration_of
(3) refuse a token or authority for another App/installation
(4) JitDeregistrationReceipt sealed, built only from a GitHub listing
(OrganizationRunnerListRead sealed); pure classifier kept
(5) slots carry their workflow; mint refuses a group restricted to another
RouteLegStanding = LegWired | LegAuthorityImplemented | LegAwaitingAuthority;
route_is_executable requires LegWired; registration/deregistration are
LegAuthorityImplemented with the wiring they owe.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mplemented with the fleet-converge wiring owed Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… derived runner image until the untangle 4a runner medium Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion/jolly-bat-898
…ambiguous standing, App-token credential, runner-id floor join, attempt-1 binding, ruling+interpretation+interlock - QualificationDispatchSubject (sole_constructor) minted only from the route's JIT registration and its delivered credential, the slot's workflow == the generated fleet-converge workflow, and a floor job whose runs-on is exactly the declared attempt input; REDs for other workflows and labels - dispatch classified through RestMutationExchange: 4xx refused, transport/5xx/undecodable ambiguous - CreateDispatch takes its bearer as an input; dispatch runs under the gunbai-ci installation token, credential checked against DispatchWorkflow; takes the host-generic UnitHoldProof (interlock) - collection: attempt-scoped jobs, run_attempt == 1, revision pinned, workflow path, and the floor job's runner_id == the minted runner id; collected payload keeps the sealed dispatch + WorkflowRun - WorkflowJobRun gains runner_id/runner_name (upstream job resource fields) - census: IrreversibleEffect, discharged by the 2026-10-03 ruling (verbatim) through a separate scope interpretation (eager-gull-22, 2026-10-04); interlock rostered; narrowed-interpretation RED Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n_ref_in_list arity, no panic) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the minted JitRegistration name); drop runner_id; fix witness braces Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mplate expression (floor NonFoldResidueRosterDiverged) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uery subject (side-chat RC on #13206) (1) JitMintDispatchAuthorized { dispatch: AuthorizedJitMintDispatch } sole_constructor, minted only by dispatch_jit_mint; dispatch_jit_mint, attempt_dispatch and the witness helper `dispatched` are admit_callers-sealed so no admitted caller returns it onward. (2) OrganizationRunnerListRead carries organization, name, App and installation; readback_subject_refusal runs before the answer is read; conclude_from_readback, its inner step and readback_after_deletes admit only ensure_jit_runner_deregistered. REDs: compile probe test.probe.jit_deregistration_forged_probe (victim-runner forgeries of all four sealed records + unadmitted conclusion) enrolled by test.claim.jit_deregistration_forged_probe_witness; pure readback-subject RED. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion/jolly-bat-898
… subject consumes the sealed authorized dispatch; witness claims mint in place, admitted by name Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nt case (floor COMPLETED-OVER-COST-REQUIREMENT 604048 > 72300) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pure scope checks, run expectation, hold), ONE real-path claim through the mint The scope checks and the run decision take values: qualification_slot_refusal, qualification_floor_admission, QualificationRunExpectation, hold_covers_slot_host. The subject mint composes them; collect derives the expectation from the sealed subject. Only the_real_mint_admits_the_attempt_and_refuses_todays_workflow runs dispatch_jit_mint and the subject mint (admit lists trimmed to it). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rop the fleet_converge_workflow evaluation (~600k eval steps, a fact about generated data) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ts own claim in the long tier, with its measured cost declared (~600k eval steps building the generated model) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…_slot_controller resolved as the union) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ep leg-2's added imports) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t_converge_workflow (a shape fix: the ~600k-step jobs were built and never read); its refusal claim returns to the module witness Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…h authority bound to the token's installation; runner_id join with name corroboration and a unique floor display name - JitCredentialBoundToAttempt gains dispatch: AuthorizedJitMintDispatch (set in receive_jit_mint; an edit to #13206's type made here per quiet-stag-623); the subject refuses a delivery from another dispatch (SubjectDeliveryForAnotherDispatch), RED with two authorized mints for one slot - dispatch_authority_refusal: the authority must project to the registration's App/installation; an ActionsJobCredential refuses (REDs for other App, other installation, job token) - WorkflowJobRun regains runner_id; the subject carries the delivered runner_id and collection joins on it, runner_name corroborating; the floor's display name must be unique at the subject mint Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lification/<attempt> at the revision, the dedicated group pinned to it, removal by readback on every exit GitHub selects a dispatched (non-reusable) workflow in a runner group only at a branch (docs cited in extdeps.github.org_actions), so the pin is a branch, not a SHA or tag. New: - extdeps.github.git_database CreateRef/DeleteRef (+ auth_input beside GITHUB_TOKEN; heal unchanged) - extdeps.github.org_actions UpdateOrganizationRunnerGroupWorkflows - gunbc.runner.runner_qualification_ref_pin: QualificationBranchName (one segment under the prefix), QualificationGroupWriteTarget (dedicated group only), sealed QualificationRefPin, ensure + removal - the dispatch subject carries the pin; dispatch ref = the pin branch; mint must be into the pinned group; collection refuses a run on another branch (RunOnAnotherBranch) - census rows + interpretation extension (eager-gull-22, 2026-10-04) - witnesses: out-of-prefix, pre-existing branch, another group, removal readback, no push workflow fires on qualification/**, run on another branch Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…not the sealed dispatch); fixtures build it as a value The sealed fixture mint (test.claim.github_app_registry dispatched) admits named callers only, so carrying the sealed dispatch on the open delivery variant would make every hand-built delivery a proxy. The identity is what the subject's comparison needs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ranch' resolved to another module's declaration; floor UnimportedBareProvider) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s leg-2 content plus this branch's additions, resolved to keep the additions Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… NonFoldResidueRosterDiverged) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…orkflowRuns auth_input
1. JitCredentialBoundToAttempt { bound: BoundJitCredential } -- sole_constructor, built only by
receive_jit_mint, carrying the complete AuthorizedJitMintDispatch with the credential and runner id
(JitMintIdentity deleted). The subject requires bound.dispatch == its dispatch: the complete request
(App, installation, organization, name, runner group, labels, work folder). REDs: same slot/App/
installation/org/name with another runner group refuses; a rewrapped delivery refuses at
BoundJitCredential (compiler probe, test.claim.runner_qualification_delivery_rewrap_witness).
The two hand-built delivery fixtures now mint for their own attempt (admitted helpers).
3. github.WorkflowRuns declares auth_input: auth_token beside GITHUB_TOKEN (callers passing "" keep
the fallback); collect_qualification_run refuses a token for another App/installation before either
read (RunCollectedUnderAnotherInstallation), RED in the real-path claim.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…git/info/exclude 'probe/' rule kept it out of the earlier commit) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ob checks out inputs.qualification_revision first and refuses on a mismatch; the residual declared - qualification_revision_dispatch_input; the dispatch sends both the attempt label and the revision - qualification_floor_revision_guard_step: fetch + checkout the revision, exit 1 unless HEAD equals it; the floor contract (qualification_floor_admission) requires it as the FIRST step and refuses any step or job that runs past a failure (if:, continue-on-error); emission is the dispatch leg's wiring_owed - REDs: revision input undeclared, no guard, guard not first, later step with if: always(), later step with continue-on-error; the guard compares HEAD to the input and exits 1; post-run head_sha refusal remains RunRevisionNotPinned - RFM qualification_floor_guard_skippable_by_a_workflow_file_edit: a rewritten workflow file on the qualification branch can drop the guard (needs repo push); rung, ceiling, next trigger Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…admit only the response-bound path and Bool claims; the delivery fixture hands back a plan, not a delivery; collection reads live inside the token join (no _under); three executed REDs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ollection over the dispatched subject and the token); collect performs only the planned reads; foreign-token RED inside the real-mint claim Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…9b76) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… conflict resolved keeping both sides' imports and claims Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s; covers is the single source of which rows take its discharge (branch-pin sites dropped: federated on their own parameters); claim pins the iff Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion msg_5756a200) recorded as its own row beside the verbatim 10-03 ruling, replacing the agent interpretation; dispatch and branch pins back in covers and every covered row derives its discharge from it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… row takes it only if covers names it); covered sites the selection federates on their own parameters -- registration, deregistration, the reversible branch pins -- do not consume it and owe no interlock Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ts own federated standing, not by the 10-03/10-05 rulings; covers lists ensure_qualification_ref_pin for its branch create only Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…me field, no RestExchangePerformance) Conflicts: github_effect_perform.dag (imports; the generate fold takes main's RestResult and keeps this branch's admit_callers seal) and github_effect_perform_witness_test.dag (main's RestAnswered call, this branch's sealed BoundJitCredential pattern). Beyond the conflicts, the port touches logic: this branch's REST ops drop their outcome fields (CreateDispatch's body is now result: WorkflowDispatchReceipt), the qualification performers carry RestResult<T>, and the dispatch, run collection, ref pin and branch removal decisions match RestAnswered/RestRefused and classify only the refusal (classify_rest_refusal, read or mutation). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dispatch fold The collection-relabel probe is a fixture; its closure reached gunbc.fleet_converge_workflow through the dispatch module's production wrapper, and from there extdeps.gunbc (WitnessBin.Run), which the fixture-closure union emit refuses for target rust. The wrapper moves to gunbc.runner.runner_qualification_production_subject, the only importer of fleet_converge_workflow; the fold's closure no longer reaches extdeps.gunbc. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…STAYS DELETED prose (review 77507) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…llected (review 77511) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…s row and witness read InterlockedBy Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…' declarations Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… outside_prepared) before the union compile Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Contributor
Author
|
Control reading delivered to deep-ram-343: union-emit begin members=768 outside_prepared=1 prepared_paths=3259 fixture_compiles=252. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Measurement control: #13211 head 7fddcd2 plus only b99d9af (prints fixture-closure-union-emit state=begin with members/outside_prepared before the union compile). Purpose: read the identity join between union members and the prepared subject on #13211's large union. Close after the run.
🤖 Generated with Claude Code