Repository navigation
Conversation
…type path-joined to std.primitives.PrimitiveContract), written once in symbol_index_fill, read by resolve and infer; 10 claims Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…egration/swift-ibex-601
…-ibex-601 fleet-converge.yml provisionally taken from #13359; regenerated from its generator in the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs
# Conflicts: # dag/gunbc/instruments/native_emission_controls.dag
# Conflicts: # dag/gunbc/auth/privileged_effect_census.dag
# Conflicts: # src/v2/std/symbol_index.dag
# Conflicts: # dag/gunbc/instruments/native_emission_controls.dag
# Conflicts: # dag/gunbc/instruments/native_emission_controls.dag
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…eptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…generated next) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status -> host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories -> roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory; the carrier, the directory list and the owned-directory witness import it from there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… eligibility and disjointness controls run over supplied members Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- managed_host: HostnameAllocation no longer carries canonical_hostname; read it through allocated_canonical_hostname (hostname_allocation's name scheme, #13625). - host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own account lookup does: the standing still decides the BMC route. - mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation. - fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of #13607 and #13625). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ay outside the closeout) deep-cat-540 recuts it onto main after #13641. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… on 5c0d9d5 The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around. First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs. Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here. Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…he administrator roster is empty; refuse an empty choice at emission (port of ffe8a90) The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes. What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name. The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha. Co-authored-by: Cursor <cursoragent@cursor.com>
Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose. Co-authored-by: Cursor <cursoragent@cursor.com>
Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence. Co-authored-by: Cursor <cursoragent@cursor.com>
…drop. The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout. Co-authored-by: Cursor <cursoragent@cursor.com>
branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation. Co-authored-by: Cursor <cursoragent@cursor.com>
Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin. Co-authored-by: Cursor <cursoragent@cursor.com>
… main. GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production. Co-authored-by: Cursor <cursoragent@cursor.com>
…ndary. A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha. Co-authored-by: Cursor <cursoragent@cursor.com>
…fleet-converge.yml. HEAD had kept the dispatch-input merge markers and a four-argument WIF call that closeout's five-argument signature refuses. Emission now matches checkout github.sha, srv1-production on root-mutation jobs, and omitted Spark target. Co-authored-by: Cursor <cursoragent@cursor.com>
GET /environments/srv1-production is 404; emitting those jobs would let GitHub mint an unprotected environment (review 78418). Dispatch modes and jobs land only when standing is Holds. Co-authored-by: Cursor <cursoragent@cursor.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 489d957789
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| witnesses: | ||
| runs-on: [self-hosted, linux, arm64] | ||
| timeout-minutes: 90 | ||
| if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository |
There was a problem hiding this comment.
Fail fork checks instead of skipping the required job
On a fork pull request this predicate is false, so the sole job named witnesses is skipped. GitHub documents that a conditionally skipped job reports success and does not prevent merging even when it is required (GitHub Docs); consequently, a fork head can satisfy the ruleset without either retained compiler product being emitted or run, contrary to the new no-verdict contract. Use a mechanism that leaves the required check unsatisfied or explicitly fails it rather than a job-level skip.
Useful? React with 👍 / 👎.
| workflow_run: | ||
| workflows: [fleet-converge] | ||
| branches: ["**"] | ||
| types: [requested] |
There was a problem hiding this comment.
Broker grants for rerun attempts
When an operator reruns a failed hetzner_cloud_server_read workflow, GitHub increments run_attempt, and the requesting job consequently waits for a new <run-id>-<attempt> grant. However, GitHub explicitly documents that the workflow_run requested activity does not occur for reruns (GitHub Docs), so this broker never dispatches that attempt's grant; branch_run_grant_await then polls for 2,400 seconds and fails. Trigger the broker from an activity that also occurs on reruns, with deduplication as needed.
Useful? React with 👍 / 👎.
| fn branch_run_expires_at(run: BranchRunFacts) -> Timestamp { | ||
| approval_expires_at(issued: run.created_at, window: branch_run_grant_window) |
There was a problem hiding this comment.
Refuse grants whose run-scoped cell has already expired
If the requesting run spends over an hour queued or building—allowed by the generated workflow's 95-minute build timeout—this computes an IAM condition whose deadline is already in the past. The request/apply path never compares that deadline with the current time, so an operator can approve the request, the expired cell can be written and read back, and the grant workflow reports success; the requester then treats that success as readiness before WIF authentication fails because request.time < timestamp(...) is false. Refuse an elapsed grant before filing/applying it, or choose a window that guarantees usable time after approval.
Useful? React with 👍 / 👎.
|
Auto-opened from the closed lane snappy-stag-26's working branch. Its content is #13660, which was folded into the closeout composition (60c9457 at dbdc9d2) and landed with #13641 on main (fa44b98); #13660 itself was closed as superseded by #13641 with its parser receipt. Nothing here is left to land, so closing as a duplicate; the branch stays for archaeology. — sent from smart-gull-336 |
Auto-opened by session-dashboard for session
snappy-stag-26.Pushing to
session/snappy-stag-26advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan