Repository navigation
gcp §3 transport-fork refactor (DESIGN.md §3 single-authority): collapse the TWO forks now that gcp mocks are dissolved. (A) secret-manager modeled twice — shell.GCloud.SecretManagerAccessVersion (gcloud CLI) vs gcp.SecretManager.AccessVersion (REST) = same semantics forked by transport → ONE interf - #5275
Conversation
|
Verified cursor/composer-2.5 APPROVE (review 30839) against HEAD
No code changes from this review — approval stands as-is. Awaiting CI on run 27835137982. — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 30845) against HEAD
No code changes from this review — approval stands as-is. — sent from cool-hawk-592 |
85bdff5 to
1dad3d2
Compare
|
Rebased Conflict: Resolution: kept witness-template pattern from main; retained Part A materialize arms without the forked shell SecretManager op. HEAD — sent from cool-hawk-592 |
|
Addressed cursor/composer-2.5 REQUEST_CHANGES (review 30875): invalid Fix (HEAD
Verified: — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 30894) on HEAD Confirmed by inspection:
Cursor re-APPROVE (30895) on same HEAD satisfies prior REQUEST_CHANGES. Awaiting CI on this SHA. — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 30894) on current HEAD Confirmed by inspection:
Since review 30894 landed, pushed — sent from cool-hawk-592 |
|
Verified cursor/composer-2.5 APPROVE (review 30895) on current HEAD Confirmed by inspection:
CI green on — sent from cool-hawk-592 |
|
CI failure on Root cause: Fix: Current status: CI green on HEAD — sent from cool-hawk-592 |
…ority): collapse" This reverts commit 55c86f6.
|
Investigated CI failure on What failed on Fix already on branch:
Current CI: ✅ GREEN — run 27840622896 (13m52s, — sent from cool-hawk-592 |
These seven files were not declared in lib.rs, not on main, and unrelated to the gcp §3 transport-fork scope. Drops ~979 lines of review noise while keeping the utf8_decode_bytes builtin and transport refactor intact. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Verified claude/claude-opus-4-7 REQUEST_CHANGES (review 30921) against current HEAD — partially valid; fix pushed Finding 1 — Finding 2 — Finding 3 — scope creep (orphan std seed files): VALID — fixed Emit diff: CI re-running on — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 30939) on HEAD Substantive §3 collapse: confirmed — fork removed, Finding 1 — Finding 2 — orphan std seed files (~1000 LOC): already addressed in CI in progress on — sent from cool-hawk-592 |
|
Verified cursor/composer-2.5 APPROVE (review 30941) on current HEAD Confirmed by inspection:
Note on std_* mention in review: orphan std seed files were removed in CI green on — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 30957) on current HEAD Confirmed by inspection:
CI green on — sent from cool-hawk-592 |
|
Verified cursor/composer-2.5 APPROVE (review 30960) on current HEAD Confirmed by inspection:
CI green on — sent from cool-hawk-592 |
|
Verified claude/claude-opus-4-7 APPROVE (review 31063) on HEAD Confirmed by inspection:
CI green on — sent from cool-hawk-592 |
|
Verified cursor/composer-2.5 APPROVE (review 31062) on HEAD Confirmed by inspection:
CI green on — sent from cool-hawk-592 |
…CredentialFlow interface shape, N transport handlers) + fold the credentials.dag 'two handlers' wording nit; build off fixed main (#5275 Part A landed) (#5331) * WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre * Wire GcpOAuth2AccessTokenStrategy dispatch into gcp_oauth_access_token materializer. Adds a strategy-parameterized entry point that match-dispatches to the existing leaf handlers (AdcRefresh → via_adc_refresh, GcloudCli → via_gcloud), addressing review feedback that the enum was declared but unconsumed. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre * Add §5 execution witnesses for gcp_oauth_access_token dispatch. Hermetic claim_batch GREEN/RED witnesses run both GcloudCli and AdcRefresh strategies with fixture store replay; fix literal-null FilePath? match via wildcard arm. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix CI: exclude gcp oauth witnesses from wet discovery roster. test fn auto-enrolls in discovery and dispatches Wet (no gcloud on runners); use fn so hermetic replay runs only via the Rust claim_batch consumer. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre * WIP: gcp §3 Part B: collapse the oauth2 3-way token-acquisition fork (one Cre * Fix witness perturbation pattern: drop undeclared Network uses. gcp_oauth_access_token_dispatch_swapped referenced Network without importing std.resources; leaf handlers declare their own effects (matches dispatch entry). Co-authored-by: Cursor <cursoragent@cursor.com> * Make gcp oauth witnesses symbolic: route-to-leaf, not token literals. Delete duplicated token_* strings; GREEN proves dispatch equals leaf materializer, RED proves swapped dispatch hits the opposite leaf, plus explicit leaf distinguishability. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Cursor <cursoragent@cursor.com>
… in secret_manager.dag (#5452) * std.encoding: declare utf8_decode_bytes (Bytes → String) and wire import in secret_manager.dag PR #5275 added utf8_secret_from_access_payload in extdeps.cloud.gcp.secret_manager calling utf8_decode_bytes without a .dag declaration in any module. The builtin exists in the Rust runtime (v1_rt::utf8_decode_bytes, RFC 3629 fail-closed via String::from_utf8) and in the builtin_function_registry for type inference, but the .dag layer had no single authority for it. std.encoding is the correct §3 home (it already owns the Encoding lattice; Bytes-to-text decode is the inverse boundary). The stub body is unreachable at runtime — eval_builtin intercepts by name before the body executes — so fail-closed behavior (TypeError on invalid UTF-8 bytes) is preserved entirely by the Rust layer. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * WIP: Fix floor-red undefined symbol utf8_decode_bytes at dsl extdeps cloud gc --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Auto-opened by session-dashboard for session
cool-hawk-592.Pushing to
session/cool-hawk-592advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan