Skip to content

Fleet-desired withdrawal; fleet-converge kept only if used, and branch-agnostic - #13677

Closed
briansrls wants to merge 2044 commits into
mainfrom
session/snappy-stag-26
Closed

briansrls wants to merge 2044 commits into
mainfrom
session/snappy-stag-26

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session snappy-stag-26.
Pushing to session/snappy-stag-26 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 30 commits October 9, 2026 17:09
…type path-joined to std.primitives.PrimitiveContract), written once in symbol_index_fill, read by resolve and infer; 10 claims

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…-ibex-601

fleet-converge.yml provisionally taken from #13359; regenerated from its generator in the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
# Conflicts:
#	dag/gunbc/auth/privileged_effect_census.dag
# Conflicts:
#	src/v2/std/symbol_index.dag
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
gunbc-ci-auto-heal and others added 25 commits October 10, 2026 03:18
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
#13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…generated next)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one
directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect
import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status ->
host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories ->
roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet
refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory;
the carrier, the directory list and the owned-directory witness import it from there.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… eligibility and disjointness controls run over supplied members

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- managed_host: HostnameAllocation no longer carries canonical_hostname; read it through
  allocated_canonical_hostname (hostname_allocation's name scheme, #13625).
- host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own
  account lookup does: the standing still decides the BMC route.
- mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became
  impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation.
- fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of
  #13607 and #13625).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ay outside the closeout)

deep-cat-540 recuts it onto main after #13641.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… on 5c0d9d5

The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around.

First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs.

Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here.

Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…he administrator roster is empty; refuse an empty choice at emission (port of ffe8a90)

The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes.

What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name.

The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
's body (review 5474794145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose.

Co-authored-by: Cursor <cursoragent@cursor.com>
Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence.

Co-authored-by: Cursor <cursoragent@cursor.com>
…drop.

The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout.

Co-authored-by: Cursor <cursoragent@cursor.com>
branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation.

Co-authored-by: Cursor <cursoragent@cursor.com>
Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin.

Co-authored-by: Cursor <cursoragent@cursor.com>
… main.

GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ndary.

A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha.

Co-authored-by: Cursor <cursoragent@cursor.com>
…fleet-converge.yml.

HEAD had kept the dispatch-input merge markers and a four-argument WIF call that closeout's five-argument signature refuses. Emission now matches checkout github.sha, srv1-production on root-mutation jobs, and omitted Spark target.

Co-authored-by: Cursor <cursoragent@cursor.com>
GET /environments/srv1-production is 404; emitting those jobs would let GitHub mint an unprotected environment (review 78418). Dispatch modes and jobs land only when standing is Holds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls marked this pull request as ready for review October 10, 2026 08:34
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T08:48:08.260399Z 489d957 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 489d957789

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

witnesses:
runs-on: [self-hosted, linux, arm64]
timeout-minutes: 90
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Fail fork checks instead of skipping the required job

On a fork pull request this predicate is false, so the sole job named witnesses is skipped. GitHub documents that a conditionally skipped job reports success and does not prevent merging even when it is required (GitHub Docs); consequently, a fork head can satisfy the ruleset without either retained compiler product being emitted or run, contrary to the new no-verdict contract. Use a mechanism that leaves the required check unsatisfied or explicitly fails it rather than a job-level skip.

Useful? React with 👍 / 👎.

workflow_run:
workflows: [fleet-converge]
branches: ["**"]
types: [requested]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Broker grants for rerun attempts

When an operator reruns a failed hetzner_cloud_server_read workflow, GitHub increments run_attempt, and the requesting job consequently waits for a new <run-id>-<attempt> grant. However, GitHub explicitly documents that the workflow_run requested activity does not occur for reruns (GitHub Docs), so this broker never dispatches that attempt's grant; branch_run_grant_await then polls for 2,400 seconds and fails. Trigger the broker from an activity that also occurs on reruns, with deduplication as needed.

Useful? React with 👍 / 👎.

Comment on lines +141 to +142
fn branch_run_expires_at(run: BranchRunFacts) -> Timestamp {
approval_expires_at(issued: run.created_at, window: branch_run_grant_window)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refuse grants whose run-scoped cell has already expired

If the requesting run spends over an hour queued or building—allowed by the generated workflow's 95-minute build timeout—this computes an IAM condition whose deadline is already in the past. The request/apply path never compares that deadline with the current time, so an operator can approve the request, the expired cell can be written and read back, and the grant workflow reports success; the requester then treats that success as readiness before WIF authentication fails because request.time < timestamp(...) is false. Refuse an elapsed grant before filing/applying it, or choose a window that guarantees usable time after approval.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Auto-opened from the closed lane snappy-stag-26's working branch. Its content is #13660, which was folded into the closeout composition (60c9457 at dbdc9d2) and landed with #13641 on main (fa44b98); #13660 itself was closed as superseded by #13641 with its parser receipt. Nothing here is left to land, so closing as a duplicate; the branch stays for archaeology.

— sent from smart-gull-336

@gunbai-bot gunbai-bot Bot closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants