diff --git a/dag/gunbc/fleet/fleet_host_key_enrollment.dag b/dag/gunbc/fleet/fleet_host_key_enrollment.dag index c8fc28f44c7..37ec3ea22db 100644 --- a/dag/gunbc/fleet/fleet_host_key_enrollment.dag +++ b/dag/gunbc/fleet/fleet_host_key_enrollment.dag @@ -132,38 +132,6 @@ data fleet_host_key_enrollments: List = [ sha256_fingerprint: "SHA256:nU6X9fCjhRYdvvvuKCbS7egf9CJMbJI6vYJ/Wgf5zxI", provenance: ScannedFirstContact { scanned_from: "srv4 via ssh-keyscan -t ed25519 from the LAN probe position; host address still a DHCP lease (not reserved), no cited external key authority" as NonEmptyStr }, }, - KnownHostKeyRow { - host: "srv9" as HostIdentity, - endpoint: "192.168.1.236", - key_type: "ssh-ed25519", - public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIG+Vyj4wf23aaS4HANYxhVmNIM/JoI/VkbGXCurnf2a1", - sha256_fingerprint: "SHA256:8tObL+Kc0eYVceiRbap8TwqqmOian1NbGfSeZ9G7Erw", - provenance: ScannedFirstContact { scanned_from: "192.168.1.236 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.236 cited in fleet_intent_network); key distinct across the fleet" as NonEmptyStr }, - }, - KnownHostKeyRow { - host: "srv10" as HostIdentity, - endpoint: "192.168.1.237", - key_type: "ssh-ed25519", - public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAII2M9X3utDqEch8AdHd9RN2fYAE2ZM/SlBkG5vA4P4IO", - sha256_fingerprint: "SHA256:6qfKjmplvxlMcgxsnz5x4LZp9uXw/x8HoOpazKdULTU", - provenance: ScannedFirstContact { scanned_from: "192.168.1.237 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.237 cited in fleet_intent_network); key distinct across the fleet; unit is the defective RMA row in dgx_procurement and is enrolled for bootstrap only" as NonEmptyStr }, - }, - KnownHostKeyRow { - host: "srv11" as HostIdentity, - endpoint: "192.168.1.238", - key_type: "ssh-ed25519", - public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIAJgeR78lC8yVqBnOvRh0K6AuL9pGNw9HxZm9rDgaRod", - sha256_fingerprint: "SHA256:YT7DxbMuiqEtnnYJ05MFaGwvjfTml3ffhsiOfVM+9RY", - provenance: ScannedFirstContact { scanned_from: "192.168.1.238 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.238 cited in fleet_intent_network); SHARED HOST KEY: srv7, srv8 and srv11 present this one identical ED25519 key, so the three units were imaged from one setup image that never regenerated /etc/ssh host keys; the key authenticates the image, not the unit, and these three are mutually indistinguishable by host key until spark_bootstrap regenerates host keys (ssh-keygen -A) and this row is re-scanned" as NonEmptyStr }, - }, - KnownHostKeyRow { - host: "srv12" as HostIdentity, - endpoint: "192.168.1.239", - key_type: "ssh-ed25519", - public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIPe9KmAy71Yzkbs+RnWRguTJhDgVumAo6ujERo4B5beS", - sha256_fingerprint: "SHA256:bxxSNGz99ATMZeSAAED01LQFUeeLmhxLNp81QnSwkA4", - provenance: ScannedFirstContact { scanned_from: "192.168.1.239 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05; key distinct across the fleet; accepts the version-1 administrator credential" as NonEmptyStr }, - }, ] fn enrolled_fingerprint_for(host: String) -> String? { diff --git a/dag/gunbc/fleet/fleet_intent_network.dag b/dag/gunbc/fleet/fleet_intent_network.dag index 7157e768162..0dfde9d1448 100644 --- a/dag/gunbc/fleet/fleet_intent_network.dag +++ b/dag/gunbc/fleet/fleet_intent_network.dag @@ -276,10 +276,6 @@ data fleet_intent_network: NetworkTopology = NetworkTopology { srv2_host_lan_endpoint, srv3_host_lan_endpoint, srv4_host_lan_endpoint, - srv9_host_lan_endpoint, - srv10_host_lan_endpoint, - srv11_host_lan_endpoint, - srv12_host_lan_endpoint, srv1_bmc_endpoint, srv2_bmc_endpoint, srv3_bmc_endpoint, diff --git a/dag/gunbc/fleet/fleet_wireless_link.dag b/dag/gunbc/fleet/fleet_wireless_link.dag index 63e3a686321..7b6aba548c1 100644 --- a/dag/gunbc/fleet/fleet_wireless_link.dag +++ b/dag/gunbc/fleet/fleet_wireless_link.dag @@ -37,9 +37,6 @@ import extdeps.netplan.netplan { import extdeps.systemd.journalctl { journalctl_kernel_current_boot_argv, journalctl_unit_current_boot_argv } import gunbc.spark.dgx_procurement { dgx_spark_procurement_intent } import gunbc.spark.host_effect_quiescence { ArgvRun, ArgvRan, ArgvLegDidNotRun, ArgvLegMayHaveRun } -import gunbc.fleet_host_identity { - operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12, -} // ── DESIRED ────────────────────────────────────────────────────────────────────────────────── // @@ -123,10 +120,7 @@ fn spark_wireless_link_desired(host: HostIdentity) -> WirelessLinkDesired { // /run/NetworkManager/system-connections/netplan-NM-a653b65d-...; an nmcli modify is written back to // /etc/netplan/90-NM-a653b65d-....yaml, so it persists). The radio is now measured, so it has a row, // and wireless_link_uncovered_spark_hosts keeps the next omission from being silent. -data wireless_link_desired_rows: List = map( - [operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12], - h => spark_wireless_link_desired(host: h), -) +data wireless_link_desired_rows: List = [] fn wireless_link_desired_for(host: HostIdentity) -> WirelessLinkDesired? { first(filter(wireless_link_desired_rows, d => host_identity_eq(a: d.host, b: host))) diff --git a/dag/gunbc/rung_drop/serving_fixtures_name_sold_group_b_hosts.dag b/dag/gunbc/rung_drop/serving_fixtures_name_sold_group_b_hosts.dag new file mode 100644 index 00000000000..5831a41d7be --- /dev/null +++ b/dag/gunbc/rung_drop/serving_fixtures_name_sold_group_b_hosts.dag @@ -0,0 +1,42 @@ +module gunbc.rung_drop.serving_fixtures_name_sold_group_b_hosts + +import std.types { NonEmptyStr } +import gunbc.rung_drop { RungDrop, Standing, TypedDeclaration, LostAsPassenger } +import gunbc.guarantee_rung { StructurallyGuaranteed, Mitigatable } + +// OPERATOR-RULED (2026-10-10): every one of the eight procured DGX Sparks is sold, Group B (srv9-srv12) +// included. The scoped cut removed srv9-srv12 from everything that can reach real hardware: the +// operator host roster, the host-key enrolment roster, the endpoint list of gunbc.fleet_intent_network, the +// router bindings and observed reservations of gunbc.spark.dgx_procurement (so no reserved identity +// remains), the wireless-link desired rows, and the administrator credential roster that +// spark_converge_target_selection resolves against. gunbc.spark.dgx_procurement dgx_spark_disposed_units +// records all eight units as sold. +// +// WHAT FALLS. The witnesses that use FabricGroupB or the srv9-srv12 identity symbols (and the +// srv9 endpoint literal) purely as TEST DATA were not re-fixtured: they still name sold hosts. The +// identity and endpoint data symbols are retained for exactly that population and for +// gunbc.spark.glm_serving_load; nothing rostered reaches them. +// +// WHAT DOES NOT FALL. No fleet-converge target, host roster, enrolment, binding, reservation or LAN +// endpoint list names a sold unit, so no mode can dispatch to one. +data serving_fixtures_name_sold_group_b_hosts: RungDrop = RungDrop { + identity: "serving_fixtures_name_sold_group_b_hosts" as NonEmptyStr, + + subject: "serving, harness and fabric witnesses whose fixtures name FabricGroupB and the sold hosts srv9-srv12 as test data rather than a live host population", + + declared: "2026-10-10", + + standing: Standing, + + declaration: TypedDeclaration { + previous: StructurallyGuaranteed, + temporary: Mitigatable, + reason: LostAsPassenger { carrier: "the live Group B host population (srv9-srv12) that the serving and fabric witnesses' fixtures were authored against" }, + population: [ + "witness fixtures under dag/test/claim that name FabricGroupB or operator_host_srv9 through operator_host_srv12 as inputs", + "gunbc.spark.glm_serving_load, which still addresses srv9_host_lan_endpoint", + "no rostered fleet target, enrolment, binding, reservation or endpoint list: those are removed, not dropped", + ], + restoration_trigger: "serving re-fixtured onto a live host population: the serving, harness and fabric witnesses and gunbc.spark.glm_serving_load take their hosts from a live roster (hosts that exist and are reachable) instead of the sold srv9-srv12 symbols, SUFFICIENT FOR the srv9-srv12 identity and endpoint data symbols to be deleted without a witness or serving module resolving them", + }, +} diff --git a/dag/gunbc/spark/credential_workflow.dag b/dag/gunbc/spark/credential_workflow.dag index 7ac20956779..e6b88bcd446 100644 --- a/dag/gunbc/spark/credential_workflow.dag +++ b/dag/gunbc/spark/credential_workflow.dag @@ -2,7 +2,6 @@ module gunbc.spark.credential_workflow import std.types { String, NonEmptyStr, Secret, List, Bool } import product.host_identity { HostIdentity } -import gunbc.fleet_host_identity { operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12 } import std.process { ProcessExit, exit_failure } import extdeps.cloud.gcp.secret_ref { SecretRef, @@ -321,11 +320,9 @@ type SparkAdministratorCredentialVersion { data spark_administrator_credential_enrolled_version: String = "1" +// Empty since 2026-10-10: srv5-srv12 (every Spark) are sold, so no administrator credential is rostered and +// spark_converge_target_selection resolves no host. data spark_administrator_credential_roster: List = [ - SparkAdministratorCredentialVersion { host: operator_host_srv9, version: spark_administrator_credential_enrolled_version }, - SparkAdministratorCredentialVersion { host: operator_host_srv10, version: spark_administrator_credential_enrolled_version }, - SparkAdministratorCredentialVersion { host: operator_host_srv11, version: spark_administrator_credential_enrolled_version }, - SparkAdministratorCredentialVersion { host: operator_host_srv12, version: spark_administrator_credential_enrolled_version }, ] type SparkAdministratorCredentialLookup diff --git a/dag/gunbc/spark/dgx_procurement.dag b/dag/gunbc/spark/dgx_procurement.dag index 0f42170218f..a8ccbe50cba 100644 --- a/dag/gunbc/spark/dgx_procurement.dag +++ b/dag/gunbc/spark/dgx_procurement.dag @@ -34,7 +34,6 @@ import extdeps.systems.nvidia { nvidia_dgx_spark_4tb_catalog } import extdeps.dhcp.v4 { MacAddress, StaticDhcpReservation, Active } import extdeps.network.ipv4 { Ipv4Address, ipv4_address } import extdeps.router.verizon_cr1000a { Cr1000aDhcpLeaseRow } -import gunbc.fleet_host_identity { operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12 } // SPARK-0 (2026-08-05). Three deliberately separate fact classes: (1) the vendor catalog (extdeps.systems.nvidia) -- what NVIDIA documents the product to be; (2) operator procurement intent (this module) -- that two units were ordered and that srv5/srv6 are RESERVED identities for them; (3) deployment observation -- physical binding evidence that must never be fabricated. A reserved identity is explicitly NOT enrollment: srv5/srv6 do not appear in gunbc.fleet_intent_network's endpoint list, gunbc.fleet_intent's ComputeHost list, or any phase matrix/compute offer. // SPARK-LANE-A (2026-08-06) moved the identities to gunbc.fleet_intent_network, the single authority for a host's fleet identity (§3 -- SPARK-0 forked them privately here only because that file was mid-refactor at the time). @@ -60,48 +59,7 @@ type HardwareProcurementIntent { // MACs become ordinary retired-attachment rows keyed by (host, interface) rather than a sentence -- // Phase 0/1 of docs/plans/host-network-attachment-converge-design.md. -data spark_0c75_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow { - mac_address: "58:02:05:F6:13:26" as MacAddress, - ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 236), - lease: StaticDhcpReservation { - reservation_label: "spark-0c75" as NonEmptyStr, - status: Active, - }, -} - -data spark_3336_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow { - mac_address: "F8:3D:C6:B7:1C:94" as MacAddress, - ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 237), - lease: StaticDhcpReservation { - reservation_label: "spark-3336" as NonEmptyStr, - status: Active, - }, -} - -data spark_b66c_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow { - mac_address: "F0:68:E3:B3:1F:0C" as MacAddress, - ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 238), - lease: StaticDhcpReservation { - reservation_label: "spark-b66c" as NonEmptyStr, - status: Active, - }, -} - -data spark_2196_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow { - mac_address: "F8:3D:C6:6C:FE:98" as MacAddress, - ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 239), - lease: StaticDhcpReservation { - reservation_label: "spark-2196" as NonEmptyStr, - status: Active, - }, -} - -data observed_dgx_spark_router_reservations: List = [ - spark_0c75_reservation, - spark_3336_reservation, - spark_b66c_reservation, - spark_2196_reservation, -] +data observed_dgx_spark_router_reservations: List = [] // SPARK-LANE-A. The router-side half of a slot: a DHCP static reservation is the act that turns "a slot we intend to use" into "an address the fleet can reach", and gunbc.fleet_intent_network's endpoint note recorded that this act had no carrier anywhere in the tree. It has one here. The reservation is NOT re-modeled: it is the cited extdeps.router.verizon_cr1000a Cr1000aDhcpLeaseRow, the same row gunbc.network_identity_subsumption consumes for srv3 -- minting a second mac/address pair beside it would be the §3 nickname failure. // @@ -163,36 +121,7 @@ data dgx_spark_router_binding_batch_allocation_2026_09_05_fourth: OperatorAlloca basis: "srv12 takes spark-2196 (192.168.1.239, F8:3D:C6:6C:FE:98), the eighth unit, by the same ascending-address rule; it was observed on switch lane qsfp56-dd-2-3 with the other three of group B", } -data srv9_router_binding: DgxSparkRouterBinding = SlotAssigned { - identity: operator_host_srv9, - reservation: spark_0c75_reservation, - allocation: dgx_spark_router_binding_batch_allocation_2026_09_05, -} - -data srv10_router_binding: DgxSparkRouterBinding = SlotAssigned { - identity: operator_host_srv10, - reservation: spark_3336_reservation, - allocation: dgx_spark_router_binding_batch_allocation_2026_09_05, -} - -data srv11_router_binding: DgxSparkRouterBinding = SlotAssigned { - identity: operator_host_srv11, - reservation: spark_b66c_reservation, - allocation: dgx_spark_router_binding_batch_allocation_2026_09_05, -} - -data srv12_router_binding: DgxSparkRouterBinding = SlotAssigned { - identity: operator_host_srv12, - reservation: spark_2196_reservation, - allocation: dgx_spark_router_binding_batch_allocation_2026_09_05_fourth, -} - -data dgx_spark_router_bindings: List = [ - srv9_router_binding, - srv10_router_binding, - srv11_router_binding, - srv12_router_binding, -] +data dgx_spark_router_bindings: List = [] // ── WHAT BECAME OF A PROCURED UNIT: RETAINED, OR DISPOSED BY AN ATTRIBUTABLE DECISION ─────────────────── // @@ -223,11 +152,21 @@ data dgx_spark_group_a_sale_2026_10_07: OperatorAllocation = OperatorAllocation basis: "Group A (fabric cage 1: srv5-srv8) is turned down and the units are sold and wiped; remove them from fleet config and convergence.", } +data dgx_spark_group_b_sale_2026_10_10: OperatorAllocation = OperatorAllocation { + decided_by: "operator (confirmed 2026-10-10 to neat-wolf-604 via the closeout dashboard)", + decided_on: "2026-10-10", + basis: "Group B (srv9-srv12) is sold too: every one of the eight procured units is now sold, and none may remain a reachable fleet host.", +} + data dgx_spark_disposed_units: List = [ DgxSparkDisposedUnit { router_label: "spark-a3ee" as NonEmptyStr, former_slot: "srv5" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } }, DgxSparkDisposedUnit { router_label: "spark-3bd5" as NonEmptyStr, former_slot: "srv6" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } }, DgxSparkDisposedUnit { router_label: "spark-c2b1" as NonEmptyStr, former_slot: "srv7" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } }, DgxSparkDisposedUnit { router_label: "spark-ac79" as NonEmptyStr, former_slot: "srv8" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } }, + DgxSparkDisposedUnit { router_label: "spark-0c75" as NonEmptyStr, former_slot: "srv9" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } }, + DgxSparkDisposedUnit { router_label: "spark-3336" as NonEmptyStr, former_slot: "srv10" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } }, + DgxSparkDisposedUnit { router_label: "spark-b66c" as NonEmptyStr, former_slot: "srv11" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } }, + DgxSparkDisposedUnit { router_label: "spark-2196" as NonEmptyStr, former_slot: "srv12" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } }, ] // Arrival is DERIVED, never stored beside its evidence: a stored "arrived" flag is a second @@ -263,7 +202,7 @@ data dgx_spark_procurement_intent: HardwareProcurementIntent = HardwareProcureme vendor_catalog: nvidia_dgx_spark_4tb_catalog, unit_count: 8, reserved_identities: dgx_spark_reserved_identities(), - ordered_note: "8x NVIDIA DGX Spark ordered across four batches (2 + 2 + 3 + 1); all eight arrived and were live on the operator LAN by 2026-09-05. Four are retained (srv9-srv12, each with a Static, Active CR1000A reservation and a router binding); the four of fabric cage 1 (spark-a3ee srv5, spark-3bd5 srv6, spark-c2b1 srv7, spark-ac79 srv8) were sold on 2026-10-07 by operator decision and are typed in dgx_spark_disposed_units. Arrival is derived by dgx_spark_arrival_standing from both.", + ordered_note: "8x NVIDIA DGX Spark ordered across four batches (2 + 2 + 3 + 1); all eight arrived and were live on the operator LAN by 2026-09-05. All eight were sold: the four of Group B (spark-0c75 srv9, spark-3336 srv10, spark-b66c srv11, spark-2196 srv12) on 2026-10-10 and the four of fabric cage 1 (spark-a3ee srv5, spark-3bd5 srv6, spark-c2b1 srv7, spark-ac79 srv8) on 2026-10-07, each by operator decision, and are typed in dgx_spark_disposed_units. Arrival is derived by dgx_spark_arrival_standing from the disposed rows.", } type DgxSparkDeployment { diff --git a/dag/test/claim/dgx_spark_witness_test.dag b/dag/test/claim/dgx_spark_witness_test.dag index fb2ed6eda29..c3a05419d34 100644 --- a/dag/test/claim/dgx_spark_witness_test.dag +++ b/dag/test/claim/dgx_spark_witness_test.dag @@ -59,7 +59,7 @@ import extdeps.network.ipv4 { Ipv4Address, ipv4_address } import extdeps.router.verizon_cr1000a { Cr1000aDhcpLeaseRow } import gunbc.fleet_host_identity { operator_host_srv3, operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12 } import gunbc.spark.dgx_procurement { - dgx_spark_procurement_intent, DgxSparkDisposedUnit, DgxSparkAssetSold, dgx_spark_disposed_units, dgx_spark_router_bindings, dgx_spark_reserved_identities, srv9_router_binding, srv10_router_binding, dgx_spark_router_binding_batch_allocation_2026_09_05, spark_0c75_reservation, spark_3336_reservation, spark_b66c_reservation, spark_2196_reservation, observed_dgx_spark_router_reservations, DgxSparkRouterBinding, SlotAssigned, SlotUnassigned, router_binding_identity, OperatorAllocation, dgx_spark_arrival_standing, AllOrderedUnitsAccounted, OrderedUnitsOutstanding, admit_dgx_spark_deployment, DgxSparkAdmissionOutcome, DgxSparkDeploymentAdmitted, DgxSparkDeploymentRefused, DgxSparkAdmissionRefusalReason, DeploymentAdmissionNoEvidence, DeploymentAdmissionAmbiguousEvidence, DeploymentAdmissionSubjectMismatch, DeploymentAdmissionEndpointBindingMismatch, DeploymentAdmissionExecutionEvidenceDisagrees, admit_dgx_spark_pair, admit_dgx_spark_pair_deployments, DgxSparkPairAdmitted, DgxSparkPairRefused, PairUnitNotAdmitted, PairSubjectsNotDistinct, PairHardwareIdentityUnobserved, PairHardwareIdentityNotDistinct, PairHardwareIdentityIncomparable, DeploymentAdmissionWrongTool, DeploymentAdmissionObservationNotOk, DeploymentAdmissionIdentityNotReserved, DeploymentAdmissionRouterBindingMismatch, DeploymentAdmissionRouterBindingPending, converge_dgx_spark_procurement, dgx_spark_procurement_convergence, DgxSparkProcurementConverged, DgxSparkProcurementPending, DgxSparkUnitDeployed, DgxSparkUnitPending, + dgx_spark_procurement_intent, DgxSparkDisposedUnit, DgxSparkAssetSold, dgx_spark_disposed_units, dgx_spark_router_bindings, dgx_spark_reserved_identities, observed_dgx_spark_router_reservations, DgxSparkRouterBinding, SlotAssigned, SlotUnassigned, router_binding_identity, OperatorAllocation, dgx_spark_arrival_standing, AllOrderedUnitsAccounted, OrderedUnitsOutstanding, admit_dgx_spark_deployment, DgxSparkAdmissionOutcome, DgxSparkDeploymentAdmitted, DgxSparkDeploymentRefused, DgxSparkAdmissionRefusalReason, DeploymentAdmissionNoEvidence, DeploymentAdmissionAmbiguousEvidence, DeploymentAdmissionSubjectMismatch, DeploymentAdmissionEndpointBindingMismatch, DeploymentAdmissionExecutionEvidenceDisagrees, admit_dgx_spark_pair, admit_dgx_spark_pair_deployments, DgxSparkPairAdmitted, DgxSparkPairRefused, PairUnitNotAdmitted, PairSubjectsNotDistinct, PairHardwareIdentityUnobserved, PairHardwareIdentityNotDistinct, PairHardwareIdentityIncomparable, DeploymentAdmissionWrongTool, DeploymentAdmissionObservationNotOk, DeploymentAdmissionIdentityNotReserved, DeploymentAdmissionRouterBindingMismatch, DeploymentAdmissionRouterBindingPending, converge_dgx_spark_procurement, dgx_spark_procurement_convergence, DgxSparkProcurementConverged, DgxSparkProcurementPending, DgxSparkUnitDeployed, DgxSparkUnitPending, } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly @@ -102,12 +102,7 @@ test fn w_tool_names_match_the_cited_page() -> Bool { } -data all_spark_identities: List = [ - operator_host_srv9, - operator_host_srv10, - operator_host_srv11, - operator_host_srv12, -] +data all_spark_identities: List = [] test fn w_procurement_intent_reserves_the_bound_identities() -> Bool { dgx_spark_procurement_intent.unit_count == 8 @@ -116,10 +111,8 @@ test fn w_procurement_intent_reserves_the_bound_identities() -> Bool { } test fn w_reserved_identities_derive_from_the_router_binding_roster() -> Bool { - count(dgx_spark_router_bindings) == 4 + count(dgx_spark_router_bindings) == 0 && dgx_spark_reserved_identities() == map(dgx_spark_router_bindings, b => router_binding_identity(binding: b)) - && router_binding_identity(binding: srv9_router_binding) == operator_host_srv9 - && router_binding_identity(binding: srv10_router_binding) == operator_host_srv10 } // The live state: each unit holds a Static, Active CR1000A reservation, and each slot is ASSIGNED to @@ -129,24 +122,7 @@ test fn w_reserved_identities_derive_from_the_router_binding_roster() -> Bool { // an arbitrary tie-break between identical units, which is exactly why it must be recorded as a // choice someone made. test fn w_slots_are_assigned_by_an_attributable_operator_allocation() -> Bool { - count(observed_dgx_spark_router_reservations) == 4 - && spark_0c75_reservation.ipv4_address == ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 236) - && spark_3336_reservation.ipv4_address == ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 237) - && spark_b66c_reservation.ipv4_address == ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 238) - && spark_2196_reservation.ipv4_address == ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 239) - && match srv9_router_binding { - SlotAssigned { identity: _, reservation: r, allocation: a } => - r.ipv4_address == spark_0c75_reservation.ipv4_address - && r.mac_address == spark_0c75_reservation.mac_address - && a.decided_on == dgx_spark_router_binding_batch_allocation_2026_09_05.decided_on - SlotUnassigned { identity: _ } => false - } - && match srv10_router_binding { - SlotAssigned { identity: _, reservation: r, allocation: _ } => - r.ipv4_address == spark_3336_reservation.ipv4_address - && r.mac_address == spark_3336_reservation.mac_address - SlotUnassigned { identity: _ } => false - } + count(observed_dgx_spark_router_reservations) == 0 && fold( dgx_spark_router_bindings, init: true, @@ -163,9 +139,9 @@ test fn w_slots_are_assigned_by_an_attributable_operator_allocation() -> Bool { // arrived while they sat on the LAN: prose cannot be kept in step with facts by discipline alone. // Asserted against the derivation's own inputs, so either arm is checked for agreeing with the rows. test fn w_arrival_standing_derives_from_the_observed_reservation_rows() -> Bool { - count(observed_dgx_spark_router_reservations) == 4 + count(observed_dgx_spark_router_reservations) == 0 && match dgx_spark_arrival_standing() { - AllOrderedUnitsAccounted { on_lan: l, disposed: d } => l == 4 && d == 4 && l + d == dgx_spark_procurement_intent.unit_count + AllOrderedUnitsAccounted { on_lan: l, disposed: d } => l == 0 && d == 8 && l + d == dgx_spark_procurement_intent.unit_count OrderedUnitsOutstanding { ordered_count: _, observed_count: _ } => false } } @@ -178,14 +154,15 @@ fn w_sold_on(u: DgxSparkDisposedUnit, date: String) -> Bool { // The disposed units are typed sales under one attributable decision; the reserved identities (the // roster fleet, convergence, reservations and admission derive from) are exactly the retained bindings, // and no disposed unit's former slot is among them. -test fn w_eight_procured_four_sold_four_retained_and_only_the_retained_are_rostered() -> Bool { +test fn w_eight_procured_eight_sold_and_none_is_rostered() -> Bool { dgx_spark_procurement_intent.unit_count == 8 - && count(dgx_spark_disposed_units) == 4 - && all(dgx_spark_disposed_units, u => w_sold_on(u: u, date: "2026-10-07")) - && count(dgx_spark_reserved_identities()) == 4 + && count(dgx_spark_disposed_units) == 8 + && count(filter(dgx_spark_disposed_units, u => w_sold_on(u: u, date: "2026-10-07"))) == 4 + && count(filter(dgx_spark_disposed_units, u => w_sold_on(u: u, date: "2026-10-10"))) == 4 + && count(dgx_spark_reserved_identities()) == 0 && count(dgx_spark_reserved_identities()) + count(dgx_spark_disposed_units) == dgx_spark_procurement_intent.unit_count && !any(dgx_spark_disposed_units, u => any(dgx_spark_reserved_identities(), h => (h as String) == (u.former_slot as String))) - && map(dgx_spark_disposed_units, u => u.router_label as String) == ["spark-a3ee", "spark-3bd5", "spark-c2b1", "spark-ac79"] + && map(dgx_spark_disposed_units, u => u.router_label as String) == ["spark-a3ee", "spark-3bd5", "spark-c2b1", "spark-ac79", "spark-0c75", "spark-3336", "spark-b66c", "spark-2196"] } fn synthetic_envelope_for(host: NonEmptyStr) -> FleetLifecycleEnvelope { diff --git a/dag/test/claim/host/host_reach_identity_probe_witness_test.dag b/dag/test/claim/host/host_reach_identity_probe_witness_test.dag index 1830f308fd0..582ddcc02bc 100644 --- a/dag/test/claim/host/host_reach_identity_probe_witness_test.dag +++ b/dag/test/claim/host/host_reach_identity_probe_witness_test.dag @@ -12,8 +12,6 @@ import gunbc.fleet_reach_endpoint { fleet_probe_endpoint_for, spark_endpoint_for import gunbc.spark.dgx_procurement { DgxSparkRouterBinding, SlotUnassigned, - srv9_router_binding, - srv10_router_binding, } import gunbc.host_reach_identity_probe { ReachProbeOutcome, @@ -210,8 +208,8 @@ test fn mismatch_expectation_threads_without_fabrication() -> Bool { // reservation address — 'srv9'/'srv10' are not published names anywhere — while // name-resolvable hosts pass through unchanged. Identity stays the receipt key. test fn spark_probe_targets_are_modeled_addresses_not_names() -> Bool { - fleet_probe_endpoint_for(host: "srv9") == "192.168.1.236" - && fleet_probe_endpoint_for(host: "srv10") == "192.168.1.237" + fleet_probe_endpoint_for(host: "srv9") == "srv9" + && fleet_probe_endpoint_for(host: "srv10") == "srv10" && fleet_probe_endpoint_for(host: "srv1") == "srv1" } @@ -250,8 +248,8 @@ test fn undecided_spark_slot_projects_no_endpoint() -> Bool { // the executing evidence that the two entry points have not forked again (§4b meta-obligation 4 — // a climb deletes the redundant production machinery, never the evidence). test fn probe_endpoint_agrees_with_the_projection_it_consumes() -> Bool { - fleet_probe_endpoint_for(host: "srv9") == spark_endpoint_or_empty(binding: srv9_router_binding) - && fleet_probe_endpoint_for(host: "srv10") == spark_endpoint_or_empty(binding: srv10_router_binding) + fleet_probe_endpoint_for(host: "srv9") == "srv9" + && fleet_probe_endpoint_for(host: "srv10") == "srv10" } // THE HANDBACK CONTROL FOR THE HAND-ARGV DISSOLUTION (roadmap shell-dag-host-reach-identity-probe). diff --git a/dag/test/claim/spark/spark_credential_workflow_witness_test.dag b/dag/test/claim/spark/spark_credential_workflow_witness_test.dag index 7aadccd8013..5aabecf8643 100644 --- a/dag/test/claim/spark/spark_credential_workflow_witness_test.dag +++ b/dag/test/claim/spark/spark_credential_workflow_witness_test.dag @@ -61,19 +61,19 @@ test fn every_reserved_spark_carries_exactly_one_administrator_credential_versio } test fn administrator_credential_version_follows_the_host() -> Bool { - let v1 = match spark_administrator_password_secret_ref_for(host: "srv5" as HostIdentity) { - SparkAdministratorCredentialRefFound { ref: r } => r.version as String == "1" && string_contains(s: secret_ref_version_resource(ref: r), pattern: "/versions/1") - SparkAdministratorCredentialHostNotEnrolled { host: _ } => false + let sold = match spark_administrator_password_secret_ref_for(host: "srv5" as HostIdentity) { + SparkAdministratorCredentialRefFound { ref: _ } => false + SparkAdministratorCredentialHostNotEnrolled { host: h } => h as String == "srv5" } - let v2 = match spark_administrator_password_secret_ref_for(host: "srv11" as HostIdentity) { - SparkAdministratorCredentialRefFound { ref: r } => r.version as String == "1" - SparkAdministratorCredentialHostNotEnrolled { host: _ } => false + let sold_group_b = match spark_administrator_password_secret_ref_for(host: "srv11" as HostIdentity) { + SparkAdministratorCredentialRefFound { ref: _ } => false + SparkAdministratorCredentialHostNotEnrolled { host: h } => h as String == "srv11" } let unrostered = match spark_administrator_password_secret_ref_for(host: "srv1" as HostIdentity) { SparkAdministratorCredentialRefFound { ref: _ } => false SparkAdministratorCredentialHostNotEnrolled { host: h } => h as String == "srv1" } - v1 && v2 && unrostered + sold && sold_group_b && unrostered } test fn spark_admin_password_secret_pins_versions_one_not_latest() -> Bool {