Skip to content

onboard nemotron ultra - #13651

Closed
briansrls wants to merge 58 commits into
mainfrom
integration/swift-ibex-601
Closed

briansrls wants to merge 58 commits into
mainfrom
integration/swift-ibex-601

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session swift-ibex-601.
Pushing to integration/swift-ibex-601 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 30 commits October 5, 2026 04:43
…ss backend

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ugh admitted_model

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the site in the privileged-effect census

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…13004) beside the OpenRouter row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eview 76210)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex (operator ruling: subscription/chatgpt mode, option B):
- extdeps.llm.codex_auth: record the refresh path read from codex-rs source
  at a pinned revision (hourly proactive refresh, persist_tokens write-back,
  refresh_token_reused handling, no cross-process lock) beside the existing
  codex-cli 0.145.0 observation; rotation stays Unobserved.
- gunbc.codex_harness_credential: lease codex-auth-harness (durable hold),
  admit the auth.json payload (chatgpt mode only), materialize a 0600
  per-turn CODEX_HOME, run the turn, and add a secret version when the
  refresh token rotated and the account is unchanged. End-of-turn write-back;
  residual window = one turn.

Cursor:
- gunbc.cursor_harness_credential: cursor-api-key-harness (exact version 1)
  bound as CURSOR_API_KEY through with_materialized_secret, liveness from
  `cursor-agent status --format json` (ProbeInert, observed on 2026.10.01).
- dispatch_selection: the declared srv2 Cursor offer and default request
  carry the harness secret instead of CursorLocalLoginRef, which the
  SDK-local binding refuses.

Witnesses: 8 Codex + 9 Cursor, including the route claim over the declared
srv2 inventory.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kenCount (review 76237)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; explicit arms

Operator rulings (via swift-ibex-601, 2026-10-05): host custody, no per-turn
Secret Manager access; codex-auth-harness on exactly one custody host.

- host_credential_custody_converge: CursorWorkerTurnApiKey and
  CodexWorkerTurnAuth rows on srv2. CustodyAuthority makes the codex row
  host-authoritative after placement: a differing host file is never
  overwritten; it is left (only short-lived tokens moved) or written back
  to the store as a new version (refresh token rotated); another account
  refuses. Placement refuses a host-authoritative row scoped to many hosts.
- codex_harness_credential: the per-turn SM bracket is deleted (replaced,
  not kept beside); the turn side is a durable hold over the custody
  CODEX_HOME. Frontier B (turn-host workload identity) declared with trigger.
- fleet_secret_accessor_roster: accessor rows for both secrets and a
  secretVersionAdder row for codex-auth-harness, folded by the converge and
  approval entries. Census custody row covers the write-back.
- fleet-converge.yml regenerated (custody credential options).
- Floor fix: no wildcard arms over closed coproducts in new code.
- gcp_secret_access witness: name fabric_state_key_accessor_row (the
  roster identity join was red on main).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…licit executor request

An operator dispatch may name ?executor=claude; the harness stays the default.
The explicit Claude draw runs one stream-json trip under the custodied
setup-token, projects the CLI's own rate_limit_event/result lines onto
per-credential provider standing, selects over srv1's live inventory (which now
offers Claude, discharging the "until the WorkerTurn PR" deferral), and spawns
claude with CLAUDE_CODE_OAUTH_TOKEN exported from the srv1 custody file into the
child's environment only. Delivery is the existing WIF custody converge under a
new accessor grant. Attempts record their spawn's process fingerprint so
observation and stop judge a Claude pane against its own fingerprint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/auth/fleet_secret_accessor_roster.dag
#	dag/gunbc/auth/privileged_effect_census.dag
#	dag/gunbc/fleet/host_credential_custody_converge.dag
#	dag/test/claim/gcp_secret_access_witness_test.dag
…lare the sh-string scaffold (review 76293)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… refusal

Builds on #13367 (merged into this branch): dispatch_provider_inner_argv_for_instance.
- Cursor: on its custody host (srv2) the turn runs cursor-agent --print
  stream-json --force --sandbox enabled --trust in the attempt worktree, with
  CURSOR_API_KEY exported from the custody file inside the child through the
  shared extdeps.posix.sh_invocation wrapper; elsewhere CursorProviderOffCustodyHost.
- Codex: on its custody host the turn runs codex exec with CODEX_HOME = the
  custody directory, under an exclusive non-blocking flock (conflict exit 75);
  elsewhere CodexProviderOffCustodyHost. Replaces the durable-hold bracket.
- extdeps.tools.util_linux_flock (new); extdeps.llm.cursor_cli splits the run
  shape from the credential so the argv has one authority.
- Witnesses over the production spawn fold for srv1 and srv2 instances.
- Parse: move annotations out of declaration bodies (floor parse phase).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nesses

- extdeps.exec.program: flock_program joins the uncataloged_program caller
  roster (constructor call admission refused it).
- roadmap_dispatch_actuator witnesses: codex worker turns are pinned to the
  custody host (srv2), so the codex tmux shape is shown on the srv2 lab
  instance; the srv1 lab's repo/tmux/state witness uses the Claude spawn and
  adds the control that a codex spawn there refuses at
  codex-credential-custody-host; the continuation-origin witness uses Claude.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… wrapper (review 76372)

PosixShellName is a sole_constructor carrier minted only by admit_posix_shell_name
(XBD 3.235, posix_name_ok); the sh builder takes it, so a name holding ;, $() or
a space cannot become shell text. State why the builder is homed in extdeps.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- cursor_worker_turn_argv admits CURSOR_API_KEY through admit_posix_shell_name
  and builds the argv from posix_sh_export_from_file_then_exec_command via
  argv_words (the _words builder was deleted upstream, review 76293).
- New CursorProviderCredentialUnbound arm for a refused name, distinct from
  the custody-host refusal.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… scaffold (review 76385)

posix_sh_export_from_file_then_exec_program builds the program from
v2.extdeps.languages.bash_build constructors and serializes it with
v2.workflow.bash_emit bash_emit_stmts; an emitter refusal is a typed arm.
The string-joined script, its Scaffold row and its dissolution trigger are
deleted: the capability they waited on already exists.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…efusal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…w-end terms; seed the day pool from the upstream's remaining

P1: the response deadline (2348 s) was the lease term for both pools, and a lapsing 60 s window refuses
any lease that outlives it (LeaseCrossesLapse), so no request could ever be sent. Each pool is now
leased to the end of its own window (gunbc.fabric_quota QuotaTermToWindowEnd, read off the same clock
reading) and settled at one before the POST, so the charge no longer depends on the response lifetime;
a request whose fate is unknown stays charged.

P2: the day pool started from the tier ceiling and ignored free_model_daily_requests.remaining. The
bind now records that reading on the day partition as the existing PoolUpstreamObserved event
(gunbc.fabric_quota fabric_quota_observe_upstream), so observe_upstream_remaining holds the shortfall.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the dispatched instance

Each Claude attempt copies the custody bytes once, owner-only, to a path derived
from the attempt identity; the standing trip reads it and the child's
grammar-emitted wrapper reads and removes it before exec, so a custody
replacement between admission and spawn cannot reach the child and a missing
snapshot refuses the launch (exit 78). Executed A->B control: child got A,
relaunch refused, B never seen. Explicit vendor selection now runs on the
dispatching HostDashboardInstance (dispatch_actuator_selection_for_provider_on);
inventory_with_observed_standing generalizes the standing join to all providers.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/roadmap/roadmap_dispatch_actuator.dag
…n optional lock

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…carry the charge's deadline to a send admission at the transport boundary

P1: settlement and upstream observation went through the unchecked fabric_pool_event_append, so a
settle whose lease lapsed at rollover, or two same-second readings with one hold reference, were
appended and reported as success while making the partition unfoldable. New gunbc.fabric_event_log
fabric_pool_transition folds, applies the transition with the replay's own pool_apply_payload, and
compare-and-set appends only an advancing transition. Observation holds are keyed by the reading's
event identity, not its second.

P2: the hosted round now prepares the request before charging, the charge carries the earlier of its
two leases' window ends, and the send is admitted against that deadline (plus a connect allowance the
transport enforces) immediately before the POST; a lapsed admission refuses the send and keeps the charge.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…every non-launch exit

PosixShRemoveFileAfterRead now emits rm -f -- "$0" || exit 79, so a snapshot that
cannot be removed refuses the launch instead of exporting and execing (measured:
non-writable parent dir -> exit 79 twice, command never ran). After selection,
belt_snapshot_owned_outcome discards the attempt's credential snapshot for every
outcome except Spawned (preflight refusal, no route, supervisor, placement
refusal, any SpawnFailed); a failed discard becomes a typed SpawnFailed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t control

- Cursor selection refusal reports a failed snapshot removal, as Claude's does.
- witness: the path the belt discards for a Cursor attempt is the one the
  Cursor spawn loads, an abandoned outcome requires the discard, and the spawn
  refuses exec (exit 79) when it cannot remove the snapshot.
- inherited Claude witness matches the current DispatchProviderInnerArgv arms.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 27 commits October 6, 2026 02:39
# Conflicts:
#	.github/workflows/fleet-converge.yml
…icit custody arm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…options)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ck that only chased exactness

Operator decision B (escalation msg_46a417a3): the local quota stays a close, conservative pre-check and
OpenRouter's 429 covers the boundary cases it cannot, revising the 2026-09-06 refuse-before-429 ruling for
this route. A 429 body plus its curl -D header dump decodes to OpenRouterRateLimitRefusal carrying
Retry-After (seconds only when all digits, else carried as text) and X-RateLimit-* verbatim (the reset's
unit is undocumented), ends the turn as TurnHostedRateLimited, and is never retried. The in-flight seats
stay. The transport-boundary send admission (send_by, connect allowance, --connect-timeout) is removed.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…auses, consume the access wire, close two witness pairing holes

- TurnHostedQuotaFull no longer claims the upstream would have answered 429; it says the local ledger refused.
- hosted_secret_text returns HostedKeyFetch: a missing access token, an access upsert, a refused read, an
  undecodable response and a version mismatch each carry their own cause into the bind refusal.
- harness_hosted_access_wire is consumed: the hosted probe writes the route standing (tier, counters, quota
  rows, NVIDIA trial terms) beside the events before the turn runs, and refuses to run if it cannot.
- Witnesses: hosted_access_from_key is asked directly on uncapped, positive-cap, unpublished-tier and safe keys;
  the production charge runs through the real fabric_quota_lease_for for an undeclared host. fabric_quota gains
  fabric_quota_lease_at / fabric_quota_settle_at seams (consumed by the host-resolving entries).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…nal and suffixed values are carried as text

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…Retry-After (review 76930)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Conflicts, both sides kept:
- dag/gunbc/auth/fleet_secret_accessor_roster.dag: the OpenRouter free-tier key accessor row and main's claude_code_oauth_harness accessor row both stay, in the row definitions and in fleet_accessor_grant_roster.
- dag/test/claim/gcp_secret_access_witness_test.dag: named_accessor_rows names fabric_state_key, openrouter_free_tier_key and claude_code_oauth_harness rows.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…v arms

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…h create-only

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ead-write arm (review 77214)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… imports to std.optional

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…optional .first() fields (floor: optional vs required '==')

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…2.std.optional was re-homed by #13388)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Conflicts, union (both sides kept):
- dag/gunbc/auth/fleet_secret_accessor_roster.dag: the OpenRouter free-tier key row and the oracle OCI API signing key row are both rows and both roster entries.
- dag/test/claim/gcp_secret_access_witness_test.dag: named_accessor_rows names the openrouter and oracle rows beside the existing ones; my duplicate fabric_state_key import is dropped now that main imports it.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…egenerate fleet-converge.yml

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…or roster rows

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ness form

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… in the main merge; cover BearerHeaderFile in the cursor witness binding_marker

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…-ibex-601

fleet-converge.yml provisionally taken from #13359; regenerated from its generator in the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Closing as a duplicate. The dashboard re-opened this integration branch's PR when its manager was archived. Its content is in the v1 closeout mega branch #13641 (for qwen-argv, #13626 is in and #13632 is deliberately left out). Branch kept. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant