Skip to content

Retire fleet-desired: admitted revision is landed main - #13703

Merged
gunbai-bot[bot] merged 12 commits into
mainfrom
session/smart-boar-904
Oct 11, 2026
Merged

gunbai-bot[bot] merged 12 commits into
mainfrom
session/smart-boar-904

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Replacement migration cut at the root: delete refs/fleet/desired admission, advance, candidate fetch, and .github/workflows/fleet-desired.yml. The admitted revision is now what has landed on origin/main (every landing already passed the required witnesses job on its PR).
  • The observation module is gunbc.origin_main_revision_observe (was gunbc.fleet_desired_observe). Keeping the old name after the contract became origin/main would have been a §3 meaning fork.
  • Production consumers re-pointed, not just deleted:
    • Belt dispatch (gunbc.roadmap_belt_actuate) refuses a tree that has not landed on the instance's admitted ref. For fleet hosts that ref is origin / refs/heads/main. Ancestry: equal-to-main or ancestor-of-main lands; ahead / diverged / unrelated refuses (LaunchRevisionNotLanded). Discriminating red + positive control: witness_landed_gate_refuses_a_tree_not_on_main_and_passes_a_landed_tree.
    • Deployed-tree report compares the deployed revision with observe_origin_main_revision (git ls-remote origin refs/heads/main).
    • Converge CLI standing and launch-deployment receipt read the same origin/main observation (revision_hex / origin_main_hex).
  • gunbc.fleet_revision_acceptance survives (Required CI + default-branch join). Accepting wildcards refuse instead of widening: arrow-contract walls, neutral verdicts, and the wet-step exit gates (re-derives #13382, #13383, #13411) #13694 Neutral-verdict claims live in fleet_revision_acceptance_merge_queue_witness_test.dag.

Consumer census (disposition)

Consumer Disposition
gunbc.fleet_desired_admission / _workflow / _candidate deleted (X)
.github/workflows/fleet-desired.yml + FleetDesiredAdmissionYamlArtifact deleted with authority
decide_fleet_desired_advance and advance types deleted
gunbc.fleet_desired_observe renamed to gunbc.origin_main_revision_observe (same observation edge, origin/main)
gunbc.roadmap_belt_actuate dispatch revision gate replaced: landed-on-main ancestry
gunbc.live_deploy.deployed_tree_report replaced: compare to origin/main head
gunbc.fleet_converge_cli fleet_revision_standing same fold, now vs origin/main
gunbc.dispatch_preflight re-pointed at origin_main_revision_observe
gunbc.roadmap_dashboard_instance fleet_admitted_revision_source refs/heads/main
gunbc.roadmap_launch_deployment_cli one origin/main read
gunbc.fleet_revision_acceptance retained (independent Required-CI/default-branch join)
Admission/expectation witnesses deleted with X
Merge-queue / Neutral claims (#13694) kept as fleet_revision_acceptance_merge_queue_witness_test
Workflow action-use / toolchain / qualification claims retargeted at remaining generated workflows
v1_consumer_census desired-workflow rows retired (consumer gone)
srv1_paths_becoming_tracked_wire path entry now origin_main_revision_observe.dag

Replacement

Standing collapses to: a revision is on origin/main iff it equals or is an ancestor of origin/main head, observed through the same git object store. Tip equality remains the deployed-tree / converge question (is the host at main head). Dispatch uses the weaker landed check so a host one merge behind still admits — that is the 2026-09-05 deploy-lag refusal, preserved without a second ref.

Receipts

  • Seed built locally (CTRL_BUILD_MODE=local, CARGO_TARGET_DIR=/tmp/cargo-target-smart-boar-904).
  • Required witnesses job on each head of this PR.

Operator step (first post-merge step)

After this lands, delete refs/fleet/desired on origin. This PR does not push or delete that ref.

Test plan

gunbc-ci-auto-heal and others added 2 commits October 10, 2026 21:45
Delete the refs/fleet/desired admission, advance, observation and workflow, and re-point the belt dispatch gate and deployed-tree report at landed main so a tree not on main still refuses.

Co-authored-by: Cursor <cursoragent@cursor.com>
Review 78488: the rung-drop population and the queue-max failure-mode receipt named gunbc.fleet_desired_admission_workflow after its deletion. Repoint those rows, and the live receipt strings that still spelled refs/fleet/desired, at landed origin/main.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

review 78488: fixed. The two typed rows now stop citing the deleted workflow — v1_required_lanes_withdrawn population says fleet-desired admission is withdrawn and admission is landed origin/main; pending_run_cancelled_by_a_later_dispatch_with_no_signal grounds queue: max on extdeps.github.actions ConcurrencyMappingQueueMax. Also rewrote the live launch-deployment receipt/window strings that still spelled refs/fleet/desired, and the present-tense comments that still treated the workflow as running.

After fleet-desired retirement the dual main/desired hexes were one fact under two names; the belt comment now names launch_gate_landed instead of claiming only UNREADABLE refuses.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78491: collapsed DesiredRevisionObserved and WindowSnapshot to one origin/main hex (revision_hex / origin_main_hex). Deleted read_desired_hex; the receipt now fills that slot from read_remote_main_hex only. The dual-hex incomplete check is now witness_origin_main_behind_r_is_incomplete_at_desired_revision (origin/main != R). Rewrote the belt comment at roadmap_belt_actuate.dag so it names launch_gate_landed and the preserved not-landed refusal instead of claiming only UNREADABLE refuses.

Head: d39ffca

An unreadable or undecodable origin/main is unobserved, not "no ref"; an unverifiable merge-base is unobserved, not "not landed".

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78503: landed_on_admitted_standing now matches each observe_admitted_revision arm (same causes as admitted_revision_standing) instead of collapsing Absent to "advertises no landed ref". classify_landed_on_main maps RelationUnverifiable to RevisionLandedUnobserved, and that arm becomes TreeLandedUnobserved (already LaunchRevisionUnobserved at the launch gate). The former unverifiable_is_not_landed witness is now unverifiable_is_unobserved_not_a_landing_verdict.

Head: after this push.

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78488, checked against current head 20fc78b (the review ran on b311e76):

Typed rows it named are already rewritten. dag/gunbc/rung_drop/v1_required_lanes_withdrawn.dag population line no longer lists gunbc.fleet_desired_admission_workflow as a live consumer; it says fleet-desired admission is withdrawn and the admitted revision is landed origin/main, with gunbc.fleet_revision_acceptance named as not the production path. dag/gunbc/recurring_failure_mode/pending_run_cancelled_by_a_later_dispatch_with_no_signal.dag points the queue: max measurement at extdeps.github.actions ConcurrencyMappingQueueMax; the withdrawn workflow is only the first measurement site. extdeps/github/actions.dag already says the same. Those land in 6efc69f. No further commit for the §3 / §4b typed-citation defect.

The // mentions it listed are §4c quarantine, not Node-tree citations. On this head: ci_spec.dag already records the admission module withdrawn; actions.dag and toolchain_home no longer name the workflow as live. Remaining present-tense notes (witness_floor_workflow.dag on the name hoist, fleet_revision_acceptance.dag on the old merge-queue premise, workflow_runs.dag listing the old caller, and ci_spec.dag still naming fleet-desired.yml among workflows that survived the earlier ci.yml cut) are history in comments. I am not resetting a green floor to edit them.

v1 consumer-census rows still name gunbc.fleet_desired_admission_workflow under retired(...) — that is the census of a deleted consumer, not a live import.

No commit for this review.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78491, checked against current head 20fc78b (the review ran on 6efc69f):

The dual observation is gone. read_desired_hex is deleted. DesiredRevisionObserved is { revision_hex: String }; WindowSnapshot carries origin_main_hex only. Production fills both from read_remote_main_hex (one ls-remote of refs/heads/main). desired_revision_blockers compares that one hex to R. The old main_hex != desired_hex control is witness_origin_main_behind_r_is_incomplete_at_desired_revision (origin/main != R). That lands in d39ffca.

The belt block at roadmap_belt_actuate.dag no longer says only UNREADABLE refuses. It names launch_gate_landed and LaunchRevisionNotLanded. One leftover wording: that rewrite still listed unverifiable as not-landed; review 78503 then moved unverifiable to RevisionLandedUnobserved / TreeLandedUnobserved on this head. Not resetting the floor to change that sentence.

No commit for this review.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78503, checked against current head 20fc78b (the review ran on d39ffca):

Both arms are already split. landed_on_admitted_standing matches observe_admitted_revision the same way admitted_revision_standing does: RemoteRevisionUnobserved keeps its cause, RemoteRevisionAbsent says the remote advertises no ref, RemoteRevisionUndecodable keeps the advertisement. It no longer folds those through converge_target_revision's Absent.

classify_landed_on_main maps RelationUnverifiable to RevisionLandedUnobserved { cause }, and that arm becomes TreeLandedUnobserved (launch already refuses that as LaunchRevisionUnobserved). Ahead / unrelated / diverged stay RevisionNotLandedOnMain. Witness: unverifiable_is_unobserved_not_a_landing_verdict. That lands in 20fc78b.

No commit for this review.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Review 78512: leaving gunbc.fleet_desired_observe as the module name. Renaming it would retarget every remaining importer of the live observation edge (belt, launch admission, deployed-tree, converge, preflight, and their witnesses) and reset a green floor for a spelling change. Diagnostics already say fleet_landed_observe. A rename can be its own cut after this lands.

— sent from smart-boar-904

gunbc-ci-auto-heal and others added 3 commits October 10, 2026 23:24
The replacement module was still gunbc.fleet_desired_observe after its contract became origin/main; that is a meaning fork. Importers and the srv1 tracked-path entry follow the new name.

Co-authored-by: Cursor <cursoragent@cursor.com>
Refresh before landing so srv1 deploy fixes and the fleet-desired cut keep both intents.
Review 78527: those notes still named deleted admission symbols as live callers and publishers.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78527: rewrote the present-tense notes in fleet_revision_acceptance.dag, workflow_runs.dag, and fleet_release_bins_key.dag so they name the withdrawn admission rather than a live caller or publisher.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78527, checked against current head 429a1c2 (the review ran on 2070e5d):

Those sites are already rewritten. fleet_revision_acceptance.dag names the withdrawn admission workflow and no longer cites admit_fleet_desired_from_push_wet. workflow_runs.dag no longer lists gunbc.fleet_desired_admission as a caller. fleet_release_bins_key.dag says the candidate publish/download end is withdrawn. That is 429a1c2.

No commit for this review.

— sent from smart-boar-904

gunbc-ci-auto-heal and others added 2 commits October 11, 2026 00:52
Fleet-desired was its only downloader. The pair product stays for fleet-converge hw boot, which builds it in-job.

Co-authored-by: Cursor <cursoragent@cursor.com>
Regenerate design-rung-drops.md from the ledger so the withdrawn-admission population matches the dag, and emit the srv1 tailnet-door sudoers line the merged deploy owns.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78538: read_remote_main_hex now wraps observe_origin_main_revision (no second ls-remote/decode). docs/design-rung-drops.md regenerated from expected_design_rung_drops_md. The srv1 sudoers regen also picked up the tailnet-door path from the merged deploy.

— sent from smart-boar-904

The observe module still spoke in the present tense about the withdrawn ref and prefixed causes fleet_landed_observe.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78544: rewrote origin_main_revision_observe annotations to describe ls-remote of origin/main and landed ancestry. Cause prefix is origin_main_revision_observe:. The one-line srv1 sudoers add for /opt/gunbc/tailnet-door is a main_wet projection of the merged deploy (#13705), not part of the fleet-desired cut.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78538, checked against current head 0868b20 (the review ran on 752ed3e):

Both items are already on this head. docs/design-rung-drops.md was regenerated from expected_design_rung_drops_md and carries the same population sentence as v1_required_lanes_withdrawn.dag (Fleet-desired admission withdrawn; admitted revision is landed origin/main). read_remote_main_hex wraps observe_origin_main_revision; main_ref_name and the hand-rolled ls-remote are gone. That is cb8cb08.

No commit for this review.

— sent from smart-boar-904

@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 78544, checked against current head 0868b20 (the review ran on cb8cb08):

Those paragraphs are gone. The module now describes ls-remote of a named ref, production-bound to origin/main, and landed ancestry vs tip equality. Cause strings are prefixed origin_main_revision_observe:. None of the quoted present-tense fleet-desired sentences remain. That is 0868b20.

No commit for this review.

— sent from smart-boar-904

gunbc-ci-auto-heal and others added 2 commits October 11, 2026 02:16
Refresh for G1 belt claim verification (#13690) and the error-primitives seam (#13686).
The belt gate witness still supplies standing; a pair of wet rows now
drive landed_on_admitted_standing against the revision-relation fixture
so deleting that producer fails a control.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

review 78554: the supplied launch_gate_landed polarity witness remains; inhabitance of the producer is now on the revision-relation fixture graph.

landed_standing_inhabits_an_ancestor_as_landed and landed_standing_inhabits_a_sibling_as_not_landed in dag/test/claim/fleet/fleet_revision_relation_wet_matrix_test.dag call landed_on_admitted_standing (ls-remote of the fixture as . + classify). Ancestor A of advertised main B is TreeLandedOnAdmitted; sibling C is TreeNotLandedOnAdmitted. Deleting that producer, or collapsing it to a constant landed arm, fails those rows. Wet record PASS; fixtures under dag/test/fixture/fleet_revision_relation/.

Head a2c52f7.

— sent from smart-boar-904

@gunbai-bot
gunbai-bot Bot merged commit d876b97 into main Oct 11, 2026
1 check passed
@gunbai-bot
gunbai-bot Bot deleted the session/smart-boar-904 branch October 11, 2026 03:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants