Repository navigation
onboard nemotron ultra - #13651
Closed
briansrls wants to merge 58 commits into
Closed
onboard nemotron ultra#13651briansrls wants to merge 58 commits into
briansrls wants to merge 58 commits into
Conversation
…ss backend Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ugh admitted_model Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the site in the privileged-effect census Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…13004) beside the OpenRouter row Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eview 76210) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex (operator ruling: subscription/chatgpt mode, option B): - extdeps.llm.codex_auth: record the refresh path read from codex-rs source at a pinned revision (hourly proactive refresh, persist_tokens write-back, refresh_token_reused handling, no cross-process lock) beside the existing codex-cli 0.145.0 observation; rotation stays Unobserved. - gunbc.codex_harness_credential: lease codex-auth-harness (durable hold), admit the auth.json payload (chatgpt mode only), materialize a 0600 per-turn CODEX_HOME, run the turn, and add a secret version when the refresh token rotated and the account is unchanged. End-of-turn write-back; residual window = one turn. Cursor: - gunbc.cursor_harness_credential: cursor-api-key-harness (exact version 1) bound as CURSOR_API_KEY through with_materialized_secret, liveness from `cursor-agent status --format json` (ProbeInert, observed on 2026.10.01). - dispatch_selection: the declared srv2 Cursor offer and default request carry the harness secret instead of CursorLocalLoginRef, which the SDK-local binding refuses. Witnesses: 8 Codex + 9 Cursor, including the route claim over the declared srv2 inventory. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kenCount (review 76237) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; explicit arms Operator rulings (via swift-ibex-601, 2026-10-05): host custody, no per-turn Secret Manager access; codex-auth-harness on exactly one custody host. - host_credential_custody_converge: CursorWorkerTurnApiKey and CodexWorkerTurnAuth rows on srv2. CustodyAuthority makes the codex row host-authoritative after placement: a differing host file is never overwritten; it is left (only short-lived tokens moved) or written back to the store as a new version (refresh token rotated); another account refuses. Placement refuses a host-authoritative row scoped to many hosts. - codex_harness_credential: the per-turn SM bracket is deleted (replaced, not kept beside); the turn side is a durable hold over the custody CODEX_HOME. Frontier B (turn-host workload identity) declared with trigger. - fleet_secret_accessor_roster: accessor rows for both secrets and a secretVersionAdder row for codex-auth-harness, folded by the converge and approval entries. Census custody row covers the write-back. - fleet-converge.yml regenerated (custody credential options). - Floor fix: no wildcard arms over closed coproducts in new code. - gcp_secret_access witness: name fabric_state_key_accessor_row (the roster identity join was red on main). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…licit executor request An operator dispatch may name ?executor=claude; the harness stays the default. The explicit Claude draw runs one stream-json trip under the custodied setup-token, projects the CLI's own rate_limit_event/result lines onto per-credential provider standing, selects over srv1's live inventory (which now offers Claude, discharging the "until the WorkerTurn PR" deferral), and spawns claude with CLAUDE_CODE_OAUTH_TOKEN exported from the srv1 custody file into the child's environment only. Delivery is the existing WIF custody converge under a new accessor grant. Attempts record their spawn's process fingerprint so observation and stop judge a Claude pane against its own fingerprint. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/auth/fleet_secret_accessor_roster.dag # dag/gunbc/auth/privileged_effect_census.dag # dag/gunbc/fleet/host_credential_custody_converge.dag # dag/test/claim/gcp_secret_access_witness_test.dag
…lare the sh-string scaffold (review 76293) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… refusal Builds on #13367 (merged into this branch): dispatch_provider_inner_argv_for_instance. - Cursor: on its custody host (srv2) the turn runs cursor-agent --print stream-json --force --sandbox enabled --trust in the attempt worktree, with CURSOR_API_KEY exported from the custody file inside the child through the shared extdeps.posix.sh_invocation wrapper; elsewhere CursorProviderOffCustodyHost. - Codex: on its custody host the turn runs codex exec with CODEX_HOME = the custody directory, under an exclusive non-blocking flock (conflict exit 75); elsewhere CodexProviderOffCustodyHost. Replaces the durable-hold bracket. - extdeps.tools.util_linux_flock (new); extdeps.llm.cursor_cli splits the run shape from the credential so the argv has one authority. - Witnesses over the production spawn fold for srv1 and srv2 instances. - Parse: move annotations out of declaration bodies (floor parse phase). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nesses - extdeps.exec.program: flock_program joins the uncataloged_program caller roster (constructor call admission refused it). - roadmap_dispatch_actuator witnesses: codex worker turns are pinned to the custody host (srv2), so the codex tmux shape is shown on the srv2 lab instance; the srv1 lab's repo/tmux/state witness uses the Claude spawn and adds the control that a codex spawn there refuses at codex-credential-custody-host; the continuation-origin witness uses Claude. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… wrapper (review 76372) PosixShellName is a sole_constructor carrier minted only by admit_posix_shell_name (XBD 3.235, posix_name_ok); the sh builder takes it, so a name holding ;, $() or a space cannot become shell text. State why the builder is homed in extdeps. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- cursor_worker_turn_argv admits CURSOR_API_KEY through admit_posix_shell_name and builds the argv from posix_sh_export_from_file_then_exec_command via argv_words (the _words builder was deleted upstream, review 76293). - New CursorProviderCredentialUnbound arm for a refused name, distinct from the custody-host refusal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… scaffold (review 76385) posix_sh_export_from_file_then_exec_program builds the program from v2.extdeps.languages.bash_build constructors and serializes it with v2.workflow.bash_emit bash_emit_stmts; an emitter refusal is a typed arm. The string-joined script, its Scaffold row and its dissolution trigger are deleted: the capability they waited on already exists. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…efusal Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…w-end terms; seed the day pool from the upstream's remaining P1: the response deadline (2348 s) was the lease term for both pools, and a lapsing 60 s window refuses any lease that outlives it (LeaseCrossesLapse), so no request could ever be sent. Each pool is now leased to the end of its own window (gunbc.fabric_quota QuotaTermToWindowEnd, read off the same clock reading) and settled at one before the POST, so the charge no longer depends on the response lifetime; a request whose fate is unknown stays charged. P2: the day pool started from the tier ceiling and ignored free_model_daily_requests.remaining. The bind now records that reading on the day partition as the existing PoolUpstreamObserved event (gunbc.fabric_quota fabric_quota_observe_upstream), so observe_upstream_remaining holds the shortfall. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the dispatched instance Each Claude attempt copies the custody bytes once, owner-only, to a path derived from the attempt identity; the standing trip reads it and the child's grammar-emitted wrapper reads and removes it before exec, so a custody replacement between admission and spawn cannot reach the child and a missing snapshot refuses the launch (exit 78). Executed A->B control: child got A, relaunch refused, B never seen. Explicit vendor selection now runs on the dispatching HostDashboardInstance (dispatch_actuator_selection_for_provider_on); inventory_with_observed_standing generalizes the standing join to all providers. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/roadmap/roadmap_dispatch_actuator.dag
…n optional lock Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…carry the charge's deadline to a send admission at the transport boundary P1: settlement and upstream observation went through the unchecked fabric_pool_event_append, so a settle whose lease lapsed at rollover, or two same-second readings with one hold reference, were appended and reported as success while making the partition unfoldable. New gunbc.fabric_event_log fabric_pool_transition folds, applies the transition with the replay's own pool_apply_payload, and compare-and-set appends only an advancing transition. Observation holds are keyed by the reading's event identity, not its second. P2: the hosted round now prepares the request before charging, the charge carries the earlier of its two leases' window ends, and the send is admitted against that deadline (plus a connect allowance the transport enforces) immediately before the POST; a lapsed admission refuses the send and keeps the charge. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…every non-launch exit PosixShRemoveFileAfterRead now emits rm -f -- "$0" || exit 79, so a snapshot that cannot be removed refuses the launch instead of exporting and execing (measured: non-writable parent dir -> exit 79 twice, command never ran). After selection, belt_snapshot_owned_outcome discards the attempt's credential snapshot for every outcome except Spawned (preflight refusal, no route, supervisor, placement refusal, any SpawnFailed); a failed discard becomes a typed SpawnFailed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t control - Cursor selection refusal reports a failed snapshot removal, as Claude's does. - witness: the path the belt discards for a Cursor attempt is the one the Cursor spawn loads, an abandoned outcome requires the discard, and the spawn refuses exec (exit 79) when it cannot remove the snapshot. - inherited Claude witness matches the current DispatchProviderInnerArgv arms. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml
…icit custody arm Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…options) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ck that only chased exactness Operator decision B (escalation msg_46a417a3): the local quota stays a close, conservative pre-check and OpenRouter's 429 covers the boundary cases it cannot, revising the 2026-09-06 refuse-before-429 ruling for this route. A 429 body plus its curl -D header dump decodes to OpenRouterRateLimitRefusal carrying Retry-After (seconds only when all digits, else carried as text) and X-RateLimit-* verbatim (the reset's unit is undocumented), ends the turn as TurnHostedRateLimited, and is never retried. The in-flight seats stay. The transport-boundary send admission (send_by, connect allowance, --connect-timeout) is removed. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…auses, consume the access wire, close two witness pairing holes - TurnHostedQuotaFull no longer claims the upstream would have answered 429; it says the local ledger refused. - hosted_secret_text returns HostedKeyFetch: a missing access token, an access upsert, a refused read, an undecodable response and a version mismatch each carry their own cause into the bind refusal. - harness_hosted_access_wire is consumed: the hosted probe writes the route standing (tier, counters, quota rows, NVIDIA trial terms) beside the events before the turn runs, and refuses to run if it cannot. - Witnesses: hosted_access_from_key is asked directly on uncapped, positive-cap, unpublished-tier and safe keys; the production charge runs through the real fabric_quota_lease_for for an undeclared host. fabric_quota gains fabric_quota_lease_at / fabric_quota_settle_at seams (consumed by the host-resolving entries). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…nal and suffixed values are carried as text Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…Retry-After (review 76930) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Conflicts, both sides kept: - dag/gunbc/auth/fleet_secret_accessor_roster.dag: the OpenRouter free-tier key accessor row and main's claude_code_oauth_harness accessor row both stay, in the row definitions and in fleet_accessor_grant_roster. - dag/test/claim/gcp_secret_access_witness_test.dag: named_accessor_rows names fabric_state_key, openrouter_free_tier_key and claude_code_oauth_harness rows. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…v arms Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…h create-only Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ead-write arm (review 77214) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… imports to std.optional Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…optional .first() fields (floor: optional vs required '==') Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…2.std.optional was re-homed by #13388) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Conflicts, union (both sides kept): - dag/gunbc/auth/fleet_secret_accessor_roster.dag: the OpenRouter free-tier key row and the oracle OCI API signing key row are both rows and both roster entries. - dag/test/claim/gcp_secret_access_witness_test.dag: named_accessor_rows names the openrouter and oracle rows beside the existing ones; my duplicate fabric_state_key import is dropped now that main imports it. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…egenerate fleet-converge.yml Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…or roster rows Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ness form Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… in the main merge; cover BearerHeaderFile in the cursor witness binding_marker Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…egration/swift-ibex-601
…-ibex-601 fleet-converge.yml provisionally taken from #13359; regenerated from its generator in the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
swift-ibex-601.Pushing to
integration/swift-ibex-601advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan