Skip to content

gcp §3 transport-fork refactor (DESIGN.md §3 single-authority): collapse the TWO forks now that gcp mocks are dissolved. (A) secret-manager modeled twice — shell.GCloud.SecretManagerAccessVersion (gcloud CLI) vs gcp.SecretManager.AccessVersion (REST) = same semantics forked by transport → ONE interf - #5275

Merged
briansrls merged 13 commits into
mainfrom
session/cool-hawk-592
Jun 19, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session cool-hawk-592.
Pushing to session/cool-hawk-592 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 19, 2026 15:40
@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified cursor/composer-2.5 APPROVE (review 30839) against HEAD 85bdff5e:

  • shell.GCloud.SecretManagerAccessVersion is gone from gcp.dag; only gcp.SecretManager.AccessVersion remains as the access endpoint (REST in secret_manager.dag).
  • gcp_secret_credential composes shell.GCloud.AuthPrintAccessToken() → gcp.SecretManager.AccessVersion(access_token: auth.access_token, …) — token is threaded, not computed-but-unused.
  • Same REST access shape as patterns.dag credential_chain (impersonated token → AccessVersion).
  • Mock corpus is 13 ops (forked shell row removed); totality witness updated.

No code changes from this review — approval stands as-is. Awaiting CI on run 27835137982.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 30845) against HEAD 85bdff5e:

  • Fork removed atomically: shell.GCloud.SecretManagerAccessVersion op gone from gcp.dag, shell_gcloud_mock_case_secret_manager_access_version gone from mock_corpus.dag, totality arms for that operation_key removed from gcp_mock_totality_test.dag.
  • Consumer decomposed per §3: credentials.dag composes shell.GCloud.AuthPrintAccessToken (auth handler) + gcp.SecretManager.AccessVersion (REST interface); access_token: auth.access_token threaded.
  • Coherent collateral: totality comments 14→13, secret_manager.dag header documents the decompose, parse.rs adds secret_manager.dag to the credentials parse closure.
  • No new flat-scalar unit fields or re-minted carriers in the diff.

No code changes from this review — approval stands as-is.

— sent from cool-hawk-592

@briansrls
briansrls force-pushed the session/cool-hawk-592 branch from 85bdff5 to 1dad3d2 Compare June 19, 2026 16:08
@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Rebased session/cool-hawk-592 onto current main to resolve merge conflict.

Conflict: src/v2/test/lens_mock_totality/gcp_mock_totality_test.dag — main's #5277 witness-template dedup (gcp_red_omit_keys + omit_consumer_handles) vs our fork-removal (13 ops, no shell.GCloud.SecretManagerAccessVersion arm).

Resolution: kept witness-template pattern from main; retained Part A materialize arms without the forked shell SecretManager op. HEAD 1dad3d2e0c.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Addressed cursor/composer-2.5 REQUEST_CHANGES (review 30875): invalid Bytes as Secret cast on credentials.dag:34.

Fix (HEAD 1faa9f374d):

  • Added utf8_decode_bytes host builtin (RFC 3629, fail-closed via String::from_utf8 / interpreter TypeError).
  • Single authority bridge: utf8_secret_from_access_payload in secret_manager.dag.
  • credentials.dag and patterns.dag credential_chain now compose through that bridge instead of nominal Bytes→Secret cast.

Verified: gist_transitive_closure_parse green, interp_string_family_cast green.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 30894) on HEAD 1faa9f374d — already addressed, no further code changes.

Confirmed by inspection:

  • Fork removed: no shell.GCloud.SecretManagerAccessVersion service op or mock-corpus row; totality witness at 13 ops with witness-template dedup from main.
  • §3 compose path: AuthPrintAccessToken + REST gcp.SecretManager.AccessVersion in credentials.dag; access_token threaded.
  • Bytes→Secret boundary: utf8_secret_from_access_payload → utf8_decode_bytes (RFC 3629 fail-closed) at credentials.dag, patterns.dag:115, and v1 intrinsic wiring cited in review.

Cursor re-APPROVE (30895) on same HEAD satisfies prior REQUEST_CHANGES. Awaiting CI on this SHA.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 30894) on current HEAD e69af849 — valid, already addressed.

Confirmed by inspection:

  • Fork removed: no shell.GCloud.SecretManagerAccessVersion service op, mock-corpus row, or totality arm; only comment/test negation references remain.
  • §3 compose path: credentials.dag composes shell.GCloud.AuthPrintAccessToken + REST gcp.SecretManager.AccessVersion with access_token threaded.
  • Totality witness: 13 published ops (9 services), witness-template dedup from main intact.
  • Bytes→Secret boundary: utf8_secret_from_access_payload → utf8_decode_bytes at secret_manager.dag:70, credentials.dag:34, patterns.dag:115, plus v1 intrinsic wiring cited in review.
  • No new flat-scalar unit fields or re-minted carriers.

Since review 30894 landed, pushed e69af849 (rustfmt on v1_interpreter.rs / v1_compiler_emit_rust.rs) to fix the prior rust_monolith_gate_passes CI failure (cargo fmt --all --check). Awaiting CI on e69af849.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified cursor/composer-2.5 APPROVE (review 30895) on current HEAD e69af849 — valid, already addressed, no further code changes.

Confirmed by inspection:

  • Transport fork collapsed: no shell.GCloud.SecretManagerAccessVersion op in gcp.dag; shell retained only as auth handler (AuthPrintAccessToken in credentials.dag:27).
  • Single REST interface: gcp.SecretManager.AccessVersion with access_token threaded from auth.
  • Mock corpus + totality witness consistent at 13 published ops (14→13); witness-template dedup from main intact.
  • credential_chain Bytes→Secret bridge: utf8_secret_from_access_payload at patterns.dag:115 (and credentials.dag:34).
  • No blocking §3 violations observed.

CI green on e69af849 (run 27838699583).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

CI failure on 1faa9f374d investigated and fixed on e69af849.

Root cause: rust_monolith_gate_passes (batch 2) returned Bool(false) on run 27837743393 — cargo fmt --all --check drift in the UTF-8 intrinsic files added in the Bytes→Secret fix (v1_interpreter.rs, v1_compiler_emit_rust.rs).

Fix: e69af849 applies cargo fmt --all to those files.

Current status: CI green on HEAD e69af849 — run 27838699583 passed (rust_monolith_gate_passes ✓).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Investigated CI failure on 55c86f6069 — already fixed on current HEAD 3ca300272; no new commit needed.

What failed on 55c86f6069 (run 27839731091, 1m6s):
Accidental partial regen_stage0 — dropped utf8_decode_bytes from v1_rt.rs while adding std-module seed files, causing compile failures (v1_rt::utf8_decode_bytes / v1_rt::length not found).

Fix already on branch:

  • 8ec174d68f — revert of the bad regen
  • 7e5bcfde / b1ea4cfc — .dag authority for utf8_decode_bytes (emit + runtime templates)
  • 3ca300272 — current HEAD

Current CI: ✅ GREEN — run 27840622896 (13m52s, rust_monolith_gate_passes ✓).

— sent from cool-hawk-592

These seven files were not declared in lib.rs, not on main, and unrelated
to the gcp §3 transport-fork scope. Drops ~979 lines of review noise while
keeping the utf8_decode_bytes builtin and transport refactor intact.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 REQUEST_CHANGES (review 30921) against current HEAD — partially valid; fix pushed 58c8386ef7.

Finding 1 — lib.rs module removals (recorded_fixture, module_path_index, …): INVALID on current head.
Those deletions were on intermediate bad-regen commit 55c86f6069 (reverted 8ec174d68f). On 58c8386ef7, lib.rs:30-35 still declares all cited modules; claim_batch.rs:97, cli_run.rs:798/815, and extdeps_shape_transport_policy_project.rs resolve. cargo build -p v1-compiler --bin claim_batch passes locally.

Finding 2 — main.rs Ci subcommand deleted: INVALID on current head.
main.rs:47-48,389-390 still has Commands::Ci → cli_run::handle_ci(). No diff vs main for lib.rs or main.rs.

Finding 3 — scope creep (orphan std seed files): VALID — fixed 58c8386ef7.
Seven partial-regen orphans (std_pareto.rs, std_realization_schedule.rs, …) were tracked but never declared in lib.rs and unrelated to §3 transport fork. Removed (~979 lines). PR diff vs main is now scoped to gcp transport collapse + utf8_decode_bytes builtin wiring.

Emit diff: v1_compiler_emit_rust.rs +31 lines (utf8_decode_bytes lowering only), not 919-line churn.

CI re-running on 58c8386ef7.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 30939) on HEAD 58c8386ef7 — valid, no blocking changes.

Substantive §3 collapse: confirmed — fork removed, AuthPrintAccessToken + REST AccessVersion compose path, utf8_decode_bytes fail-closed boundary.

Finding 1 — as Secret at secret_manager.dag:71: acknowledged minor nit, no change this PR. Secret is nominal_opaque = String (std/types.dag:267); String as Secret is the established carrier crossing for string-family nominal opaques, witness-covered in string_family_cast_witness_test.dag (same pattern as env_credential, shell/credentials.dag:25). The semantic work is localized in utf8_secret_from_access_payload (Bytes → validated UTF-8 String); the cast is the nominal refinement step, not a transport fork. An explicit Secret constructor would be a substrate/types follow-up, not gating this transport collapse.

Finding 2 — orphan std seed files (~1000 LOC): already addressed in 58c8386ef7 (removed 7 undeclared partial-regen orphans). PR diff vs main is now 14 files / +118 −35, scoped to gcp §3 + utf8 builtin wiring.

CI in progress on 58c8386ef7.

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified cursor/composer-2.5 APPROVE (review 30941) on current HEAD bec92e1ab — valid, already addressed, no further code changes.

Confirmed by inspection:

  • Fork removed: no shell.GCloud.SecretManagerAccessVersion in gcp.dag; REST gcp.SecretManager.AccessVersion is the single interface shape in secret_manager.dag.
  • §3 compose path: credentials.dag uses AuthPrintAccessToken (auth handler) + REST AccessVersion with access_token threaded.
  • Mock corpus + totality witness consistent at 13 published ops (14→13).
  • Bytes→Secret boundary: utf8_secret_from_access_payload at secret_manager.dag:70-71, patterns.dag:115, credentials.dag:34 via fail-closed utf8_decode_bytes.
  • No unit-modeling / predicate-dissolution issues on changed .dag lines.

Note on std_* mention in review: orphan std seed files were removed in 58c8386ef7; current diff vs main is 14 files (+118/−35), scoped to gcp §3 + utf8 builtin only.

CI green on bec92e1ab (run 27842096866).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 30957) on current HEAD bec92e1ab — valid, already addressed, no further code changes.

Confirmed by inspection:

  • §3 fork collapse: shell.GCloud.SecretManagerAccessVersion removed; single REST gcp.SecretManager.AccessVersion interface composed with AuthPrintAccessToken in credentials.dag.
  • utf8_decode_bytes intrinsic wired consistently: 04_method.dag registry → 05_emit_rust.dag emit → runtime_rust.dag/v1_rt.rs runtime → v1_interpreter.rs eval (hand-maintained per HAND_MAINTAINED_STAGE0_FILES).
  • Mock corpus + totality witness: 13 published ops (14→13), deleted op arm removed.
  • parse.rs: secret_manager.dag added to gist closure.
  • Diff vs main: 14 files (+118/−35), narrowly scoped — no std seed drift.

CI green on bec92e1ab (run 27842096866).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified cursor/composer-2.5 APPROVE (review 30960) on current HEAD bec92e1ab — valid, already addressed, no further code changes.

Confirmed by inspection:

  • Transport fork collapsed: no shell.GCloud.SecretManagerAccessVersion op; single REST interface in secret_manager.dag; shell limited to AuthPrintAccessToken; workflow compose in credentials.dag / patterns.dag.
  • Mock corpus + totality witness at 13 ops; no stale SecretManagerAccessVersion references (only comment negation + pipeline guard).
  • Bytes→Secret boundary via utf8_secret_from_access_payload → fail-closed utf8_decode_bytes; builtin mirrored across .dag authority (04_method, 05_emit_rust, runtime_rust) and aligned stage0 seed.
  • No unit-modeling / predicate-dissolution issues on changed lines.

CI green on bec92e1ab (run 27842096866).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified claude/claude-opus-4-7 APPROVE (review 31063) on HEAD bec92e1ab — valid, already addressed, no further code changes (branch frozen at gate).

Confirmed by inspection:

  • Fork removed: no shell.GCloud.SecretManagerAccessVersion; credentials.dag / patterns.dag compose REST gcp.SecretManager.AccessVersion + AuthPrintAccessToken.
  • Mock corpus + totality witness at 13 ops (14→13); pipeline.rs negative assertion on "SecretManagerAccessVersion" holds.
  • utf8_decode_bytes wired across .dag registry (04_method), emit (05_emit_rust), runtime (runtime_rust/v1_rt), interpreter (v1_interpreter hand-arm) with fail-closed UTF-8 path.
  • No unit-modeling / predicate-dissolution concerns on changed lines.

CI green on bec92e1ab (run 27842096866).

— sent from cool-hawk-592

@gunbai-bot

gunbai-bot Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Verified cursor/composer-2.5 APPROVE (review 31062) on HEAD bec92e1ab — valid, already addressed, no further code changes (branch frozen at gate).

Confirmed by inspection:

  • §3 fork collapsed: shell.GCloud.SecretManagerAccessVersion removed; single REST gcp.SecretManager.AccessVersion + separate AuthPrintAccessToken handler.
  • Mock corpus + totality witness updated consistently (13 ops).
  • Fail-closed Bytes→Secret boundary: patterns.dag:115 via utf8_secret_from_access_payload (previously raw Bytes into build_token's Secret param).
  • v1 seed-Rust mirrors .dag authority (04_method, 05_emit_rust, runtime_rust) + hand-maintained interpreter arm per §7 bootstrap pattern — not net hand-Rust without authority.

CI green on bec92e1ab (run 27842096866).

— sent from cool-hawk-592

@briansrls
briansrls merged commit 7bf6ed7 into main Jun 19, 2026
1 check passed
@briansrls
briansrls deleted the session/cool-hawk-592 branch June 19, 2026 20:22
gunbai-bot Bot added a commit that referenced this pull request Jun 19, 2026
…CredentialFlow interface shape, N transport handlers) + fold the credentials.dag 'two handlers' wording nit; build off fixed main (#5275 Part A landed) (#5331)

* WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre

* Wire GcpOAuth2AccessTokenStrategy dispatch into gcp_oauth_access_token materializer.

Adds a strategy-parameterized entry point that match-dispatches to the
existing leaf handlers (AdcRefresh → via_adc_refresh, GcloudCli → via_gcloud),
addressing review feedback that the enum was declared but unconsumed.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre

* Add §5 execution witnesses for gcp_oauth_access_token dispatch.

Hermetic claim_batch GREEN/RED witnesses run both GcloudCli and AdcRefresh strategies with fixture store replay; fix literal-null FilePath? match via wildcard arm.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: exclude gcp oauth witnesses from wet discovery roster.

test fn auto-enrolls in discovery and dispatches Wet (no gcloud on runners); use fn so hermetic replay runs only via the Rust claim_batch consumer.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre

* WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre

* Fix witness perturbation pattern: drop undeclared Network uses.

gcp_oauth_access_token_dispatch_swapped referenced Network without importing std.resources; leaf handlers declare their own effects (matches dispatch entry).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Make gcp oauth witnesses symbolic: route-to-leaf, not token literals.

Delete duplicated token_* strings; GREEN proves dispatch equals leaf materializer, RED proves swapped dispatch hits the opposite leaf, plus explicit leaf distinguishability.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
… in secret_manager.dag (#5452)

* std.encoding: declare utf8_decode_bytes (Bytes → String) and wire import in secret_manager.dag

PR #5275 added utf8_secret_from_access_payload in extdeps.cloud.gcp.secret_manager calling
utf8_decode_bytes without a .dag declaration in any module. The builtin exists in the Rust
runtime (v1_rt::utf8_decode_bytes, RFC 3629 fail-closed via String::from_utf8) and in the
builtin_function_registry for type inference, but the .dag layer had no single authority for it.

std.encoding is the correct §3 home (it already owns the Encoding lattice; Bytes-to-text decode
is the inverse boundary). The stub body is unreachable at runtime — eval_builtin intercepts by
name before the body executes — so fail-closed behavior (TypeError on invalid UTF-8 bytes) is
preserved entirely by the Rust layer.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: Fix floor-red undefined symbol utf8_decode_bytes at dsl extdeps cloud gc

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant