Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 0 additions & 32 deletions dag/gunbc/fleet/fleet_host_key_enrollment.dag
Original file line number Diff line number Diff line change
Expand Up @@ -132,38 +132,6 @@ data fleet_host_key_enrollments: List<KnownHostKeyRow> = [
sha256_fingerprint: "SHA256:nU6X9fCjhRYdvvvuKCbS7egf9CJMbJI6vYJ/Wgf5zxI",
provenance: ScannedFirstContact { scanned_from: "srv4 via ssh-keyscan -t ed25519 from the LAN probe position; host address still a DHCP lease (not reserved), no cited external key authority" as NonEmptyStr },
},
KnownHostKeyRow {
host: "srv9" as HostIdentity,
endpoint: "192.168.1.236",
key_type: "ssh-ed25519",
public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIG+Vyj4wf23aaS4HANYxhVmNIM/JoI/VkbGXCurnf2a1",
sha256_fingerprint: "SHA256:8tObL+Kc0eYVceiRbap8TwqqmOian1NbGfSeZ9G7Erw",
provenance: ScannedFirstContact { scanned_from: "192.168.1.236 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.236 cited in fleet_intent_network); key distinct across the fleet" as NonEmptyStr },
},
KnownHostKeyRow {
host: "srv10" as HostIdentity,
endpoint: "192.168.1.237",
key_type: "ssh-ed25519",
public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAII2M9X3utDqEch8AdHd9RN2fYAE2ZM/SlBkG5vA4P4IO",
sha256_fingerprint: "SHA256:6qfKjmplvxlMcgxsnz5x4LZp9uXw/x8HoOpazKdULTU",
provenance: ScannedFirstContact { scanned_from: "192.168.1.237 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.237 cited in fleet_intent_network); key distinct across the fleet; unit is the defective RMA row in dgx_procurement and is enrolled for bootstrap only" as NonEmptyStr },
},
KnownHostKeyRow {
host: "srv11" as HostIdentity,
endpoint: "192.168.1.238",
key_type: "ssh-ed25519",
public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIAJgeR78lC8yVqBnOvRh0K6AuL9pGNw9HxZm9rDgaRod",
sha256_fingerprint: "SHA256:YT7DxbMuiqEtnnYJ05MFaGwvjfTml3ffhsiOfVM+9RY",
provenance: ScannedFirstContact { scanned_from: "192.168.1.238 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05 (router reservation 192.168.1.238 cited in fleet_intent_network); SHARED HOST KEY: srv7, srv8 and srv11 present this one identical ED25519 key, so the three units were imaged from one setup image that never regenerated /etc/ssh host keys; the key authenticates the image, not the unit, and these three are mutually indistinguishable by host key until spark_bootstrap regenerates host keys (ssh-keygen -A) and this row is re-scanned" as NonEmptyStr },
},
KnownHostKeyRow {
host: "srv12" as HostIdentity,
endpoint: "192.168.1.239",
key_type: "ssh-ed25519",
public_key_base64: "AAAAC3NzaC1lZDI1NTE5AAAAIPe9KmAy71Yzkbs+RnWRguTJhDgVumAo6ujERo4B5beS",
sha256_fingerprint: "SHA256:bxxSNGz99ATMZeSAAED01LQFUeeLmhxLNp81QnSwkA4",
provenance: ScannedFirstContact { scanned_from: "192.168.1.239 via ssh-keyscan -t ed25519 from the srv2 LAN probe position on 2026-09-05; key distinct across the fleet; accepts the version-1 administrator credential" as NonEmptyStr },
},
]

fn enrolled_fingerprint_for(host: String) -> String? {
Expand Down
4 changes: 0 additions & 4 deletions dag/gunbc/fleet/fleet_intent_network.dag
Original file line number Diff line number Diff line change
Expand Up @@ -276,10 +276,6 @@ data fleet_intent_network: NetworkTopology = NetworkTopology {
srv2_host_lan_endpoint,
srv3_host_lan_endpoint,
srv4_host_lan_endpoint,
srv9_host_lan_endpoint,
srv10_host_lan_endpoint,
srv11_host_lan_endpoint,
srv12_host_lan_endpoint,
srv1_bmc_endpoint,
srv2_bmc_endpoint,
srv3_bmc_endpoint,
Expand Down
8 changes: 1 addition & 7 deletions dag/gunbc/fleet/fleet_wireless_link.dag
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,6 @@ import extdeps.netplan.netplan {
import extdeps.systemd.journalctl { journalctl_kernel_current_boot_argv, journalctl_unit_current_boot_argv }
import gunbc.spark.dgx_procurement { dgx_spark_procurement_intent }
import gunbc.spark.host_effect_quiescence { ArgvRun, ArgvRan, ArgvLegDidNotRun, ArgvLegMayHaveRun }
import gunbc.fleet_host_identity {
operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12,
}

// ── DESIRED ──────────────────────────────────────────────────────────────────────────────────
//
Expand Down Expand Up @@ -123,10 +120,7 @@ fn spark_wireless_link_desired(host: HostIdentity) -> WirelessLinkDesired {
// /run/NetworkManager/system-connections/netplan-NM-a653b65d-...; an nmcli modify is written back to
// /etc/netplan/90-NM-a653b65d-....yaml, so it persists). The radio is now measured, so it has a row,
// and wireless_link_uncovered_spark_hosts keeps the next omission from being silent.
data wireless_link_desired_rows: List<WirelessLinkDesired> = map(
[operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12],
h => spark_wireless_link_desired(host: h),
)
data wireless_link_desired_rows: List<WirelessLinkDesired> = []

fn wireless_link_desired_for(host: HostIdentity) -> WirelessLinkDesired? {
first(filter(wireless_link_desired_rows, d => host_identity_eq(a: d.host, b: host)))
Expand Down
42 changes: 42 additions & 0 deletions dag/gunbc/rung_drop/serving_fixtures_name_sold_group_b_hosts.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
module gunbc.rung_drop.serving_fixtures_name_sold_group_b_hosts

import std.types { NonEmptyStr }
import gunbc.rung_drop { RungDrop, Standing, TypedDeclaration, LostAsPassenger }
import gunbc.guarantee_rung { StructurallyGuaranteed, Mitigatable }

// OPERATOR-RULED (2026-10-10): every one of the eight procured DGX Sparks is sold, Group B (srv9-srv12)
// included. The scoped cut removed srv9-srv12 from everything that can reach real hardware: the
// operator host roster, the host-key enrolment roster, the endpoint list of gunbc.fleet_intent_network, the
// router bindings and observed reservations of gunbc.spark.dgx_procurement (so no reserved identity
// remains), the wireless-link desired rows, and the administrator credential roster that
// spark_converge_target_selection resolves against. gunbc.spark.dgx_procurement dgx_spark_disposed_units
// records all eight units as sold.
//
// WHAT FALLS. The witnesses that use FabricGroupB or the srv9-srv12 identity symbols (and the
// srv9 endpoint literal) purely as TEST DATA were not re-fixtured: they still name sold hosts. The
// identity and endpoint data symbols are retained for exactly that population and for
// gunbc.spark.glm_serving_load; nothing rostered reaches them.
//
// WHAT DOES NOT FALL. No fleet-converge target, host roster, enrolment, binding, reservation or LAN
// endpoint list names a sold unit, so no mode can dispatch to one.
data serving_fixtures_name_sold_group_b_hosts: RungDrop = RungDrop {
identity: "serving_fixtures_name_sold_group_b_hosts" as NonEmptyStr,

subject: "serving, harness and fabric witnesses whose fixtures name FabricGroupB and the sold hosts srv9-srv12 as test data rather than a live host population",

declared: "2026-10-10",

standing: Standing,

declaration: TypedDeclaration {
previous: StructurallyGuaranteed,
temporary: Mitigatable,
reason: LostAsPassenger { carrier: "the live Group B host population (srv9-srv12) that the serving and fabric witnesses' fixtures were authored against" },
population: [
"witness fixtures under dag/test/claim that name FabricGroupB or operator_host_srv9 through operator_host_srv12 as inputs",
"gunbc.spark.glm_serving_load, which still addresses srv9_host_lan_endpoint",
"no rostered fleet target, enrolment, binding, reservation or endpoint list: those are removed, not dropped",
],
restoration_trigger: "serving re-fixtured onto a live host population: the serving, harness and fabric witnesses and gunbc.spark.glm_serving_load take their hosts from a live roster (hosts that exist and are reachable) instead of the sold srv9-srv12 symbols, SUFFICIENT FOR the srv9-srv12 identity and endpoint data symbols to be deleted without a witness or serving module resolving them",
},
}
7 changes: 2 additions & 5 deletions dag/gunbc/spark/credential_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@ module gunbc.spark.credential_workflow

import std.types { String, NonEmptyStr, Secret, List, Bool }
import product.host_identity { HostIdentity }
import gunbc.fleet_host_identity { operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12 }
import std.process { ProcessExit, exit_failure }
import extdeps.cloud.gcp.secret_ref {
SecretRef,
Expand Down Expand Up @@ -321,11 +320,9 @@ type SparkAdministratorCredentialVersion {
data spark_administrator_credential_enrolled_version: String = "1"


// Empty since 2026-10-10: srv5-srv12 (every Spark) are sold, so no administrator credential is rostered and
// spark_converge_target_selection resolves no host.
data spark_administrator_credential_roster: List<SparkAdministratorCredentialVersion> = [
SparkAdministratorCredentialVersion { host: operator_host_srv9, version: spark_administrator_credential_enrolled_version },
SparkAdministratorCredentialVersion { host: operator_host_srv10, version: spark_administrator_credential_enrolled_version },
SparkAdministratorCredentialVersion { host: operator_host_srv11, version: spark_administrator_credential_enrolled_version },
SparkAdministratorCredentialVersion { host: operator_host_srv12, version: spark_administrator_credential_enrolled_version },
]

type SparkAdministratorCredentialLookup
Expand Down
87 changes: 13 additions & 74 deletions dag/gunbc/spark/dgx_procurement.dag
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,6 @@ import extdeps.systems.nvidia { nvidia_dgx_spark_4tb_catalog }
import extdeps.dhcp.v4 { MacAddress, StaticDhcpReservation, Active }
import extdeps.network.ipv4 { Ipv4Address, ipv4_address }
import extdeps.router.verizon_cr1000a { Cr1000aDhcpLeaseRow }
import gunbc.fleet_host_identity { operator_host_srv9, operator_host_srv10, operator_host_srv11, operator_host_srv12 }

// SPARK-0 (2026-08-05). Three deliberately separate fact classes: (1) the vendor catalog (extdeps.systems.nvidia) -- what NVIDIA documents the product to be; (2) operator procurement intent (this module) -- that two units were ordered and that srv5/srv6 are RESERVED identities for them; (3) deployment observation -- physical binding evidence that must never be fabricated. A reserved identity is explicitly NOT enrollment: srv5/srv6 do not appear in gunbc.fleet_intent_network's endpoint list, gunbc.fleet_intent's ComputeHost list, or any phase matrix/compute offer.
// SPARK-LANE-A (2026-08-06) moved the identities to gunbc.fleet_intent_network, the single authority for a host's fleet identity (§3 -- SPARK-0 forked them privately here only because that file was mid-refactor at the time).
Expand All @@ -60,48 +59,7 @@ type HardwareProcurementIntent {
// MACs become ordinary retired-attachment rows keyed by (host, interface) rather than a sentence --
// Phase 0/1 of docs/plans/host-network-attachment-converge-design.md.

data spark_0c75_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow {
mac_address: "58:02:05:F6:13:26" as MacAddress,
ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 236),
lease: StaticDhcpReservation {
reservation_label: "spark-0c75" as NonEmptyStr,
status: Active,
},
}

data spark_3336_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow {
mac_address: "F8:3D:C6:B7:1C:94" as MacAddress,
ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 237),
lease: StaticDhcpReservation {
reservation_label: "spark-3336" as NonEmptyStr,
status: Active,
},
}

data spark_b66c_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow {
mac_address: "F0:68:E3:B3:1F:0C" as MacAddress,
ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 238),
lease: StaticDhcpReservation {
reservation_label: "spark-b66c" as NonEmptyStr,
status: Active,
},
}

data spark_2196_reservation: Cr1000aDhcpLeaseRow = Cr1000aDhcpLeaseRow {
mac_address: "F8:3D:C6:6C:FE:98" as MacAddress,
ipv4_address: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 239),
lease: StaticDhcpReservation {
reservation_label: "spark-2196" as NonEmptyStr,
status: Active,
},
}

data observed_dgx_spark_router_reservations: List<Cr1000aDhcpLeaseRow> = [
spark_0c75_reservation,
spark_3336_reservation,
spark_b66c_reservation,
spark_2196_reservation,
]
data observed_dgx_spark_router_reservations: List<Cr1000aDhcpLeaseRow> = []

// SPARK-LANE-A. The router-side half of a slot: a DHCP static reservation is the act that turns "a slot we intend to use" into "an address the fleet can reach", and gunbc.fleet_intent_network's endpoint note recorded that this act had no carrier anywhere in the tree. It has one here. The reservation is NOT re-modeled: it is the cited extdeps.router.verizon_cr1000a Cr1000aDhcpLeaseRow, the same row gunbc.network_identity_subsumption consumes for srv3 -- minting a second mac/address pair beside it would be the §3 nickname failure.
//
Expand Down Expand Up @@ -163,36 +121,7 @@ data dgx_spark_router_binding_batch_allocation_2026_09_05_fourth: OperatorAlloca
basis: "srv12 takes spark-2196 (192.168.1.239, F8:3D:C6:6C:FE:98), the eighth unit, by the same ascending-address rule; it was observed on switch lane qsfp56-dd-2-3 with the other three of group B",
}

data srv9_router_binding: DgxSparkRouterBinding = SlotAssigned {
identity: operator_host_srv9,
reservation: spark_0c75_reservation,
allocation: dgx_spark_router_binding_batch_allocation_2026_09_05,
}

data srv10_router_binding: DgxSparkRouterBinding = SlotAssigned {
identity: operator_host_srv10,
reservation: spark_3336_reservation,
allocation: dgx_spark_router_binding_batch_allocation_2026_09_05,
}

data srv11_router_binding: DgxSparkRouterBinding = SlotAssigned {
identity: operator_host_srv11,
reservation: spark_b66c_reservation,
allocation: dgx_spark_router_binding_batch_allocation_2026_09_05,
}

data srv12_router_binding: DgxSparkRouterBinding = SlotAssigned {
identity: operator_host_srv12,
reservation: spark_2196_reservation,
allocation: dgx_spark_router_binding_batch_allocation_2026_09_05_fourth,
}

data dgx_spark_router_bindings: List<DgxSparkRouterBinding> = [
srv9_router_binding,
srv10_router_binding,
srv11_router_binding,
srv12_router_binding,
]
data dgx_spark_router_bindings: List<DgxSparkRouterBinding> = []

// ── WHAT BECAME OF A PROCURED UNIT: RETAINED, OR DISPOSED BY AN ATTRIBUTABLE DECISION ───────────────────
//
Expand Down Expand Up @@ -223,11 +152,21 @@ data dgx_spark_group_a_sale_2026_10_07: OperatorAllocation = OperatorAllocation
basis: "Group A (fabric cage 1: srv5-srv8) is turned down and the units are sold and wiped; remove them from fleet config and convergence.",
}

data dgx_spark_group_b_sale_2026_10_10: OperatorAllocation = OperatorAllocation {
decided_by: "operator (confirmed 2026-10-10 to neat-wolf-604 via the closeout dashboard)",
decided_on: "2026-10-10",
basis: "Group B (srv9-srv12) is sold too: every one of the eight procured units is now sold, and none may remain a reachable fleet host.",
}

data dgx_spark_disposed_units: List<DgxSparkDisposedUnit> = [
DgxSparkDisposedUnit { router_label: "spark-a3ee" as NonEmptyStr, former_slot: "srv5" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } },
DgxSparkDisposedUnit { router_label: "spark-3bd5" as NonEmptyStr, former_slot: "srv6" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } },
DgxSparkDisposedUnit { router_label: "spark-c2b1" as NonEmptyStr, former_slot: "srv7" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } },
DgxSparkDisposedUnit { router_label: "spark-ac79" as NonEmptyStr, former_slot: "srv8" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_a_sale_2026_10_07 } },
DgxSparkDisposedUnit { router_label: "spark-0c75" as NonEmptyStr, former_slot: "srv9" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } },
DgxSparkDisposedUnit { router_label: "spark-3336" as NonEmptyStr, former_slot: "srv10" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } },
DgxSparkDisposedUnit { router_label: "spark-b66c" as NonEmptyStr, former_slot: "srv11" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } },
DgxSparkDisposedUnit { router_label: "spark-2196" as NonEmptyStr, former_slot: "srv12" as NonEmptyStr, disposition: DgxSparkAssetSold { decision: dgx_spark_group_b_sale_2026_10_10 } },
]

// Arrival is DERIVED, never stored beside its evidence: a stored "arrived" flag is a second
Expand Down Expand Up @@ -263,7 +202,7 @@ data dgx_spark_procurement_intent: HardwareProcurementIntent = HardwareProcureme
vendor_catalog: nvidia_dgx_spark_4tb_catalog,
unit_count: 8,
reserved_identities: dgx_spark_reserved_identities(),
ordered_note: "8x NVIDIA DGX Spark ordered across four batches (2 + 2 + 3 + 1); all eight arrived and were live on the operator LAN by 2026-09-05. Four are retained (srv9-srv12, each with a Static, Active CR1000A reservation and a router binding); the four of fabric cage 1 (spark-a3ee srv5, spark-3bd5 srv6, spark-c2b1 srv7, spark-ac79 srv8) were sold on 2026-10-07 by operator decision and are typed in dgx_spark_disposed_units. Arrival is derived by dgx_spark_arrival_standing from both.",
ordered_note: "8x NVIDIA DGX Spark ordered across four batches (2 + 2 + 3 + 1); all eight arrived and were live on the operator LAN by 2026-09-05. All eight were sold: the four of Group B (spark-0c75 srv9, spark-3336 srv10, spark-b66c srv11, spark-2196 srv12) on 2026-10-10 and the four of fabric cage 1 (spark-a3ee srv5, spark-3bd5 srv6, spark-c2b1 srv7, spark-ac79 srv8) on 2026-10-07, each by operator decision, and are typed in dgx_spark_disposed_units. Arrival is derived by dgx_spark_arrival_standing from the disposed rows.",
}

type DgxSparkDeployment {
Expand Down
Loading