Skip to content

dusk qwen 2 - #13656

Closed
briansrls wants to merge 2 commits into
mainfrom
session/deep-crab-89-followup
Closed

briansrls wants to merge 2 commits into
mainfrom
session/deep-crab-89-followup

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session deep-crab-89.
Pushing to session/deep-crab-89-followup advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls added 2 commits October 9, 2026 11:06
…s tool module, not hand-typed

Replace the two hand argv literals in the fleet reach/identity probe with
home-module builders, dissolving the last hand argv in that module (roadmap
shell-dag-host-reach-identity-probe; Lane B of the transport-argv anemia
dissolution).

- extdeps.tools.id: id_user_name_argv() -> [id, -un] (login name, no operand:
  id(1) with no operand answers from the calling process's own credentials,
  which is exactly the account the SSH session IS).
- extdeps.tools.hostname: hostname_read_argv() -> [hostname] (bare, full
  configured name). The -s decision the row's first_slice names resolves to
  the bare read: the probe compares its output for exact equality against the
  enrolled short slot label, so -s (first label) would re-derive a label.
- host_reach_identity_probe: probe_reachable_with_principal and
  probe_ready_target_once now call id_user_name_argv() and hostname_read_argv()
  instead of the literal [id,-un] and [hostname].
- witness: the_probe_argv_is_spelled_by_its_tool_module_builders pins each
  builder's materialized argv to the exact words the probe has always executed,
  so the flags cannot drift out from under the builder.
…626 review

WIP per operator wind-down — NOT a finished slice. Folding stern-boar-596's
5-point review of 13626 into a follow-up, stopped mid-edit.

Done in this WIP (points 1,2,4 + half of 3):
- point 1: the probe's hostname read moves from the bare hostname_read_argv
  (possibly-FQDN) to the existing hostname_short_read_argv (hostname -s). The
  grain is short: enrolled slot labels are short (srv1,...) and the model's
  short-hostname read (HostIdentityShortHostnameRead) is hostname -s; a bare
  read of an FQDN-configured host (srv1.example.com) exact-equality-fails the
  short slot label srv1 -> fail-closed identity refusal against a host whose
  short name IS enrolled. The bare hostname_read_argv row is deleted (dead;
  the bare FULL read stays alive only as hostname_read_command).
- point 2: id.dag -u/-n comment corrected (u selects the effective-user FIELD,
  n renders it as the NAME).
- point 4: hostname_short_read_argv now [hostname_program().invocation, -s].
- point 3 (partial): probe_ready_target_argv / probe_principal_argv expose
  each op's argv and *_route_argv the seam's wire form (shape_ssh_shell_exec).

NOT done (stopped): the route-asserting witness (point 3) and the witness
test still imports the now-deleted hostname_read_argv, so that witness module
does NOT typecheck at this head. Not interpreter-verified. Next step: rewrite
the witness to assert probe argv == builder and the route.
@briansrls
briansrls marked this pull request as ready for review October 9, 2026 18:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T18:43:50.721816Z 8255a8f Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8255a8f1bd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

import gunbc.network_identity_subsumption { srv3_post_install_lease_table_fixture }
import gunbc.srv3_os_install_diagnostic { srv3_install_hang_no_router_lease_ms }
import extdeps.tools.id { id_user_name_argv }
import extdeps.tools.hostname { hostname_read_argv }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Update the witness to use the surviving hostname builder

The commit deletes hostname_read_argv from extdeps.tools.hostname, but this changed witness still imports and calls it, so loading this witness fails during name resolution and prevents its claims from running. Import hostname_short_read_argv (or the probe-facing projection) instead and update the assertion to expect ["hostname", "-s"], matching the production probe introduced in this commit.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Closing in the v1 closeout. This is a wind-down WIP push (8255a8f) of the #13626 follow-up on FQDN vs short-hostname identity. That decision is still open, and review 78372 shows the WIP contradicts itself: the probe calls hostname_short_read_argv (-s), the witness pins the bare hostname_read_argv, the two comments argue opposite positions, and the new *_route_argv functions have no consumer. It's recorded as outstanding work in docs/plans/v1-closeout-pr-accounting.md on #13641. Decide short vs bare first, then one comment, a witness over probe_ready_target_argv()/probe_principal_argv(), and no unconsumed route fns. Branch kept. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant