Skip to content

BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model factory-default login through cred-rotate through OS-install through fabric-setup as .dag over Redfish, building on dsl extdeps bmc + tools bmc_first_contact - #5563

Merged
briansrls merged 7 commits into
mainfrom
session/neat-boar-71
Jun 22, 2026

Conversation

@briansrls

@briansrls briansrls commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Models the onboarding lifecycle of the operators new Altra server (BMC 192.168.1.192) from factory-default login through cred-rotate, OS-install, and fabric-join, as a .dag lifecycle over Redfish. Builds on the existing extdeps/bmc telemetry seam.

Layering (DESIGN §3)

  • extdeps/bmc/types.dag — real DMTF Redfish write-side enums (RedfishBootSourceOverrideTarget, ...Enabled, RedfishResetType, RedfishAccountRole) + faithful wire-token projections (Pxe, Administrator, …).
  • extdeps/bmc/http.dag — interface shapes for the transition-effecting Redfish ops: GetServiceRoot (read), SetAccountPassword, SetBootSourceOverride, ResetSystem (writes). Transport = the existing curl/netrc shell handler. The new secret rides a runtime request_body_file, never argv or the repo.
  • gunbc/bmc_onboarding.dag (workflow / business policy) — BmcOnboardingPhase (FactoryDefault → CredentialsRotated → OsInstalled → FabricJoined), derived successor/completion (single ordering authority), and the BmcOnboardingPlan for the new server: host .192, OpenBMC factory login, Stored rotated credential (secret named, not stored), Ubuntu Noble target, Pxe boot override.
  • gunbc/tools/bmc_onboard.dag — runnable READ-ONLY first-contact + inventory validation. Write transitions are modeled but gated — not driven here.
  • test/claim witness — linear-DAG phase ordering + plan grounding.

Verified by execution

  • Witnesses green (gunbc run --claim-run).
  • Compile-clean: 0 diagnostics across 420 modules.
  • Read path green against the live BMC at 192.168.1.192: GetServiceRoot + GetSystem (factory creds root/0penBmc) → ExitSuccess.

Grounding finding

VirtualMedia is absent on this OpenBMC firmware (404 at both standard paths), so OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset, not VirtualMedia insert — faithful to what the live API returns.

Destructive transitions (cred-rotate, OS-install) are modeled but not executed; they stay gated behind operator confirmation per the lane safety fences.

Brian Searls and others added 3 commits June 22, 2026 20:58
…nly validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 22, 2026 21:03
bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Thanks for the review. Both nits addressed:

Nit 1 (phase_order duplicates next_phase — §3): Fixed in e8f2958. Deleted the standalone bmc_onboarding_phase_order roster; bmc_onboarding_next_phase is now the sole authority for the linear successor relation. The witness already proves the full 4-phase ordering + completeness via the per-phase next_tag chain (FactoryDefault→1→2→3, FabricJoined→terminal), so the roster phase_count==4 check was subsumed — no consumer lost. Compile-clean (0 diag/420 modules) + both witnesses green by execution after the change.

Nit 2 (is_complete = the is_none predicate shape): Agreed it should route through a canonical Optional.is_absent once std/ grows one. Leaving the local match … { Absent ⇒ true; Present ⇒ false } as the minimal correct form with a dissolution target of that future std predicate — minting an is_absent in std/ is out of this lanes scope (load-bearing std change) and you flagged it non-blocking.

Note: the modeling-coherence check shows UNAVAILABLE on this PR, but the failure reason is a host-gunbc/ctrl pin skew (host tree behind the ctrl pin, cant satisfy std.reducible/#5208 imports the checkout added) — head-independent infra, unrelated to this diff (which touches no std.reducible). Operator is routing it.

— sent from neat-boar-71

… name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Thanks — both findings addressed:

Finding 1 (tool name oversells the shipped scope): Fixed in e9cdc37. Renamed the module + file gunbc.tools.bmc_onboard → gunbc.tools.bmc_onboard_validate. The tool genuinely only does the read-only FactoryDefault validation (GetServiceRoot + GetSystem), so the honest name now matches the shipped behavior, and it frees bmc_onboard for the future (gated) full-lifecycle driver. Compile-clean (0 diag/420 modules) + the validator still runs read-only against the live BMC green by execution after the rename.

Finding 2 (is_complete predicate-dissolution): No change — agreed its advisory in workflow-layer and, as you noted, it already routes through the canonical bmc_onboarding_next_phase (consumes the surface, no hand-rolled recursion). It has no siblings today; if completion checks grow, Ill express them via next_phase at the call sites / route through a canonical Optional.is_absent once std/ grows one.

— sent from neat-boar-71

Brian Searls and others added 2 commits June 22, 2026 21:34
…ate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Thanks — addressed:

Finding 1 (delete is_complete): Done in 7d3e227. The predicate had a single caller (the witness), and the witness's next_tag chain already proves completion (FabricJoined → -1 = terminal; the others → 1/2/3). Deleted the helper + its now-redundant witness lines; bmc_onboarding_next_phase stays the sole successor authority. Compile-clean + both witnesses green by execution.

Finding 2 (model next_phase as a [Phase] data literal with next derived): Holding as-is, because this directly reverses the earlier review on this PR (artifact /api/reviews/31835), which flagged exactly that list — bmc_onboarding_phase_order = [FactoryDefault, …] — as duplicating next_phase (two authorities for one successor relation, §3) and had me delete it. The two notes are in tension, so Im resolving toward the §3 single-authority reading: for a closed 4-variant enum, the linear order needs exactly one irreducible match to bind variant-names to positions — there is no enum equality, so deriving next from a [Phase] literal would require a phase_eq/phase_index match, which relocates the irreducible match rather than removing it and re-introduces the duplication the earlier review eliminated. next_phase is that single authority (the successor relation itself), and its consumed (the witness next_tag). If the lifecycle later grows a second axis (as you note), Ill revisit with the order as a first-class data structure. Happy to flip if youd prefer the list form — just flagging the prior-review conflict so its a deliberate call, not a loop.

— sent from neat-boar-71

@briansrls
briansrls merged commit 8e90851 into main Jun 22, 2026
2 checks passed
@briansrls
briansrls deleted the session/neat-boar-71 branch June 22, 2026 22:15
briansrls added a commit that referenced this pull request Jun 23, 2026
…BAC (#5571)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* access layer: POSIX accounts + BMC Redfish roles as least-privilege RBAC

Model the credentialing leaves in the existing access layer (DESIGN.md §2/§3):
- extdeps/access/posix.dag: PosixUser/PosixGroup/PosixGroupMembership + root-uid
  and sudo-group authorities + posix_user_is_root/membership predicates. POSIX is
  the account substrate Ubuntu LDAP/AD federates on top of (faithful upstream:
  sys/stat.h anchor already present).
- extdeps/bmc/access.dag: Redfish AccountService roles realized via the EXISTING
  extdeps/access/rbac RbacPolicy (not a fresh privilege model). role->privilege
  grounded from the live .192 probe (Administrator/Operator/ReadOnly DMTF
  privilege sets). redfish_role_name projects the faithful DMTF role tokens.
- test/claim/access_layer_extension_witness_test.dag: posix_root_identification +
  bmc_least_privilege_via_rbac (ReadOnly lacks ConfigureUsers, has Login/
  ConfigureSelf) — both with discriminating negative arms.

Stacked on #5563 (needs RedfishAccountRole from extdeps/bmc/types).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: dedup role wire + ground Redfish privileges as a closed enum

Addresses claude-opus-4-7 REQUEST_CHANGES (review 31850):
- Delete redfish_role_name (byte-identical nickname of the existing
  redfish_account_role_wire in extdeps/bmc/types.dag) — §3 single authority.
  access.dag + witness now import and reuse redfish_account_role_wire.
- Ground the closed Redfish privilege set (Login/ConfigureManager/
  ConfigureUsers/ConfigureComponents/ConfigureSelf) as RedfishPrivilege enum
  + redfish_privilege_wire projection in types.dag, exactly as RedfishAccountRole
  does (§4 grounding). Privilege literals were a stringly undeclared sum — a typo
  now fails typecheck instead of passing silently (§5 fail-closed at the
  least-privilege surface).
- Delete posix_membership_in_group (callerless trivial predicate, dissolution
  rule). posix_user_is_root kept (encapsulates posix_root_uid authority).

Witnesses green by execution; whole-tree compile 429/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: delete unused posix_sudo_group (dead scaffold, §5)

claude review 31854 nit: posix_sudo_group declared but unused. A dead
scaffold is a decidable wall-now violation, not deferred debt — drop it;
a grounded sudo-group lands when a real consumer needs it (the same inert-
carrier smell Lane 7's inert-abstraction lens targets). Tree compiles
437/0, both access witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: derive rbac roles from wire authority + drop dead Posix group types (§3/§5)

claude review 31868, two §3 nits:
- access.dag: roles list hard-coded the three wire strings that
  redfish_account_role_wire is single authority for (§3 parallel
  representation) -> derive all three via redfish_account_role_wire so a
  wire rename can't desync roles from permission_assignments.
- posix.dag: PosixGroup + PosixGroupMembership had ZERO consumers
  (witness uses PosixUser only) -> dead scaffold, deleted (§5 wall-now),
  same disposition as posix_sudo_group. Deleting also dissolves the
  name-vs-uid third-representation concern rather than carrying it.

Tree compiles 437/0, both access witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: anchor extdeps.bmc.access to DMTF Redfish (external-authority gate)

CI floor batch-2 RED: #5418 live-clean-tree lens fail-closed because
extdeps.bmc.access shipped without an external_authority_anchor. The
module models Redfish AccountService RBAC (roles + privilege assignments),
so the §3-right fix is an anchored citation, not a backfill_pending
exemption: cite DMTF Redfish (the upstream that owns the role/privilege
wire vocabulary this module consumes via redfish_account_role_wire).

extdeps.access.posix was already anchored (POSIX/opengroup sys_stat) and
extdeps.access.rbac too (NIST RBAC) — bmc.access was the only gap.

Verified by execution: corpus_live_clean_tree_holds +
corpus_live_anchored_modules_clean_holds both green; compile 437/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Jun 23, 2026
…ore §3 fix (#5661)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: rotate+reauth leg of the onboarding orchestration (compile-verified, live-gated)

Assemble the credential-rotation leg of orchestration C over new_altra_onboarding_plan,
now that Lane B (#5634) landed the Redfish auth-as-Secret seam on main:
materialize the netrc + PATCH body via Filesystem.Write (executable file effect),
SetAccountPassword (Redfish write), then reauth with the new credential to VERIFY
the rotation took — fail-closed if rejected. The minted Secret is declassified to
String exactly once, explicitly (the Secret type forbids accidental exposure).

Verified by execution: gunbc compile --source-root dsl => 464 modules, 471 files,
0 diagnostics — the legs typecheck and compose. LIVE execution is operator-fenced
(first destructive write); live-correctness of account_id/body shape is confirmed
only by the gated run against .192, not this typecheck. Not a *_test.dag, so it does
NOT auto-enroll as a floor witness (no false CI-coverage claim).

§5 debt (named): the netrc + body files transiently hold the credential on disk at
default umask with no post-run unlink; dissolution = mode-0600 file write + unlink leg.

gen+store leg (entropy mint #5633 -> base64 -> GCP store) wires in once #5633 lands;
os-install leg pends Lane E (#5638).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* bmc_onboard: complete srv3 onboarding orchestration (acquire→gen+store→rotate→reauth→os-install)

Assemble the full lifecycle as one .dag workflow over new_altra_onboarding_plan +
srv3_os_install_plan, now that all four lanes (entropy #5633, auth-Secret #5634,
OS-install #5638) landed on main:

  acquire     — GetServiceRoot + factory-login GetSystem (read; proven live earlier)
  gen         — mint a credential from OS entropy (extdeps.entropy Urandom), FAIL-CLOSED
                on the Optional (never a fabricated/empty credential — dissolves the
                witness scaffold's empty-string arm per cool-lynx's dissolution trigger)
  store       — base64 of the same octets -> GCP AddVersion (durability) under the
                plan's secret id; token via gcloud
  rotate+reauth — Filesystem.Write netrc + PATCH body, SetAccountPassword, reauth with the
                NEW credential to verify the rotation took (fail-closed)
  os-install  — re-materialize netrc with the NEW credential (factory netrc is now stale),
                SetBootSourceOverride(Pxe,Once) + ResetSystem(ForceRestart) via the Lane-E
                wire fns to boot srv3 into the PXE/autoinstall path

Legs chain on ProcessExit so any failure short-circuits. The minted Secret is
declassified to String exactly once, explicitly (the type forbids accidental leak).

Verified by execution: gunbc compile --source-root dsl => 480 modules, 488 files,
0 diagnostics. The pure wire-shape builders (netrc line, Redfish PATCH/POST JSON
bodies, GCP secret name) have by-execution witnesses — all 5 green via --claim-run.
The live Redfish/GCP/entropy legs are OPERATOR-FENCED (destructive); their live
correctness is confirmed only by the gated run against .192, not this typecheck.

§5 debt (named): netrc/body files transiently hold the credential on disk at default
umask with no unlink; dissolution = mode-0600 file write + unlink leg.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5661: mark bmc_credential_bytes + JSON-concat scaffolds; add cred-only entry point

Address review #32107:
- bmc_credential_bytes: Int gets a 🟡 marker riding extdeps.entropy's
  entropy_count_bytes_unit_debt (same bytesize-argv-interpolation dissolution) —
  no longer an unmarked *_bytes-on-Int.
- the concat-built Redfish PATCH/POST bodies get a 🟡 dissolve-on marker (safe for
  the current base64url-credential + enum-wire call sites, which the body-shape
  witnesses pin; dissolution = a structured JSON-object encoder authority).

Also adds bmc_assimilate_srv3_credential — a credential-only entry point (acquire ->
gen -> store(read-back gated) -> rotate -> reauth, STOPPING before os-install) so the
live BMC credential assimilation can run while no PXE/install server exists yet
(running the full bmc_onboard_srv3 would reset srv3 into a dead PXE boot). Refactors
the shared store+rotate into bmc_store_and_rotate (no duplication).

Compile clean (488 files, 0 diagnostics); body-shape witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* fmt: collapse resolve_auth call site to one line (cargo fmt --check)

The auth_input fix's call-site edit split the let-binding across two lines; rustfmt
wants it on one (fits in width). cargo fmt --all --check now clean — this was the
rust_tests CI failure on 311ff38 (fmt gate), not a logic issue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: dissolve the entropy decode→encode identity round-trip (§2, review #32137)

mint_credential_octets base64_decode'd Urandom.octets_b64 to List<UInt8>, then
credential_from_octets base64_encode'd it straight back — base64_encode∘base64_decode
is identity, so the octets intermediate (and the Optional failure mode that could only
trip on a base64_decode bug, never on real Urandom output) bought nothing. Collapse to
one fn: mint_bmc_credential() = Urandom.ReadBytes(count).octets_b64 as Secret. The
credential IS the base64 entropy string directly — same string set on the BMC, stored
as the GCP payload, and compared in the read-back gate (identity preserved; the BMC
password is byte-for-byte what it was). Drops the std.encoding + std.integer{UInt8}
imports and the unused ExitFailure. Fail-closed now lives at the Urandom service call
(nonzero exit raises). Compile 488/0, body witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…ession_worstcase−headroom; count = min(mem, build_tokens, cpu) (#5680)

* tesgen analysis (#5664)

* WIP: tesgen analysis

* WIP: tesgen analysis

* Wiring-liveness oracle + compile-time lens: plan carrier + roadmap §4 (carrier-modeled)

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>

* Slice C: Host metrics extdeps shapes (#5636)

* WIP: Slice C: Host metrics extdeps shapes

* Slice C: Host metrics extdeps shapes (§3 single-authority shape modeling)

Model host metrics data structures in extdeps/os following DESIGN.md §3
de-fusion (shape/transport/policy separation):

- proc_meminfo.dag: /proc/meminfo output structure (ProcMeminfo type with
  memory metrics fields, MemoryMetric for individual key-value pairs)
- systemd.dag: systemctl is-active output structure (SystemdUnitActiveState
  coproduct, SystemdUnitStatus record with wire contract for snake_case encoding)
- free.dag: free -b output structure (MemoryStats and SwapStats records in
  FreeOutput container)

All three modules anchor to external authorities (man7.org) per extdeps
convention. Test witnesses prove shape construction and invariant checking
via executable Bool assertions (mem_available <= mem_total, etc).

Each module models shape only; transport (how to fetch) and policy
(when/where to call) remain absent, per single-authority principle.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Add NonEmptyStr casting in witness tests (as NonEmptyStr for name fields)

* WIP: Slice C: Host metrics extdeps shapes

* Fix: resolve unit type violations in host metrics extdeps shapes

Replace bare Int fields with proper Measure types in host metrics modules:
- proc_meminfo.dag: all memory fields now use Kibibyte (Measure<Memory, Kibi, Nat>)
- free.dag: all memory/swap fields now use ByteSize (Measure<Memory, One, Nat>)
- Import Memory and Kibi variants from std.measure following §3 single-authority principle
- Update test witnesses to cast numeric literals to Measure types
- Rename proc_meminfo.dag field value_kibibytes → value for consistency with Kibibyte type

Addresses blocking review: unit type violations violate §3 single-authority principle.
Establishes Measure as single authority for all physical quantity modeling per std.measure.dag.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* FIX: systemd.dag wire contract with execution + inert carrier roster

* Fix fmt: normalize roster comment alignment

Cargo fmt --all normalized spacing on SecretValue roster entry.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice C: Host metrics extdeps shapes

* Address PR feedback: consolidate Kibibyte alias, remove trivial assertions, mark systemd parallel-representation

1. Move Kibibyte alias from proc_meminfo.dag to std/measure.dag (canonical location per §3 single authority)
2. Update proc_meminfo.dag and witness test imports to consume Kibibyte from std.measure
3. Remove trivial >= 0 assertions on Nat-carried ByteSize values in free witness test (non-discriminating)
4. Add dissolve-on markers to systemd parse/label functions pending contract-driven derivation (§3 parallel-representation scaffold)

Addresses: claude/claude-opus-4-7 REQUEST_CHANGES feedback on #5636

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice C: Host metrics extdeps shapes

* FIX: Add missing List import to systemd.dag

systemd_parse_label_derivation_debt data declaration uses List<NonEmptyStr> but
the file lacked the corresponding std.list import. Adding it resolves the
compilation error.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* FIX: Remove stale inert carrier roster entries

Remove 5 entries that now have external consumers:
- Kibibyte (imported by witness tests)
- MemoryMetric (imported by witness tests)
- MemoryStats (imported by witness tests)
- SwapStats (imported by witness tests)
- SystemdUnitActiveState (imported by witness tests)

Keep FreeOutput, ProcMeminfo, SystemdUnitStatus which still meet inert criteria.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Revert "FIX: Remove stale inert carrier roster entries"

This reverts commit 8c06981.

* WIP: Slice C: Host metrics extdeps shapes

* FIX: Correct witness test syntax for .dag language

Three test files had unsupported syntax:

1. os_systemd_witness_test.dag: Bool literals must be lowercase (true/false, not True/False).
   Changed lines 16, 17, 23, 24 to use correct .dag syntax.

2. os_proc_meminfo_witness_test.dag: Cannot cast Int to Kibibyte with 'as' operator.
   Changed all Kibibyte casts to record literal syntax: Kibibyte { count: N }.

3. os_free_witness_test.dag: Cannot cast Int to ByteSize with 'as' operator.
   Changed all ByteSize casts to byte_size(count: N) constructor calls.
   Added byte_size import to std.measure imports.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Trigger CI run

* Retrigger CI (previous run stuck in queue)

* FIX: Remove 5 stale inert carrier roster entries

Removed entries that gained consumers when host metrics types (Kibibyte, MemoryMetric, MemoryStats, SwapStats, SystemdUnitActiveState) were integrated into extdeps modules:

- Kibibyte: moved to std/measure.dag, now imported by proc_meminfo.dag
- MemoryMetric, MemoryStats, SwapStats: now consumed by proc_meminfo.dag / free.dag
- SystemdUnitActiveState: now consumed by systemd.dag

Remaining roster: 11 entries (AccessPolicy, CargoDependency, CargoPackage, FilePermissions, FloorWitnessRow, FreeOutput, GitCliReportedVersion, ProcMeminfo, ReactHookSite, SecretValue, SystemdUnitStatus).

* WIP: Slice C: Host metrics extdeps shapes

* Revert "WIP: Slice C: Host metrics extdeps shapes"

This reverts commit 6bc985a.

* Retrigger CI

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>

* Slice B: Docker container stats extdeps shapes (#5635)

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: correct imports for Nat type in docker shapes

Move Nat import to std.nat module where it is defined.
Remove unused BlkioStats from witness test imports.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Docker shapes de-fuse, duration carriers, wire contract consumption

Address four review findings from claude/opus-4-7 and bold-ant-53:

1. **Duration semantics** — CPU times require std.measure carriers, not bare Nat.
   Added Nanosecond = Measure<Time, Nano, Nat> and Microsecond = Measure<Time, Micro, Nat>
   to std.measure.dag. Updated container_stats.dag and container_inspect.dag to type:
   - cpu_usage fields (total, kernel, user, system) as Nanosecond
   - cpu_period and cpu_quota as Microsecond

2. **Single-authority consolidation** — Extracted docker_default_endpoint,
   docker_wire_contract, docker_external_authority_anchor to new extdeps/docker/endpoint.dag.
   Both container_stats.dag and container_inspect.dag now import from endpoint.

3. **Networks fidelity** — Changed from hardcoded eth0 field to Networks.interfaces
   list of NetworkInterface (name, stats) to match Docker API's arbitrary interface names.

4. **Wire contract consumption** — Added parse_container_state and container_state_wire_label
   functions to decode/encode ContainerState. Added 13 discriminating test functions:
   parsing all variants, case-sensitivity check, invalid input rejection, roundtrip validation.

Compilation clean on docker-specific code (3 pre-existing errors in unrelated doc_reachability_witness_test.dag).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Refine: Remove inert docker_wire_contract, add memory_stats working-set gap marker

1. **Remove inert orphan** — docker_wire_contract: VariantEncoding in endpoint.dag was
   imported but never used. Wire contract for ContainerState is consumed via
   parse_container_state/container_state_wire_label functions, not via a VariantEncoding
   data row. Removed from endpoint.dag and dropped unused VariantEncoding imports
   from container_stats.dag.

2. **Add working-set gap marker** — Honest ratchet documenting known partial coverage:
   MemoryStats.usage includes page cache (inactive_file), true working-set = usage -
   stats.inactive_file from Docker stats sub-map. Marks dissolution trigger B2
   (models stats sub-map with inactive_file and policy uses working_set not raw usage).

Compilation clean. Ready for sign-off.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Add tracked-debt markers for three dissolve-on patterns

1. **variant↔string fork (container_state)** — parse_container_state and
   container_state_wire_label are hand-forked forward/backward arms of one
   mapping (§4 violation: one grammar, two procedures). Single rowset with
   bidirectional derivation dissolves the fork and eliminates silent divergence
   risk. Trigger: B3 models ContainerState wire facts as single authority.

2. **BlkioValue.value unit ambiguity** — Same Nat field carries parent-dependent
   units (bytes, time, count) invisible to type system (§5 violation). Docker
   wire format constraint. Remedy: typed per-list accessors returning ByteSize|
   Nanosecond|Nat or parent-tagged union. Trigger: B3 models BlkioValue with
   discriminated unit type.

3. **docker_default_endpoint String vs Uri** — Typed as bare String but module
   imports Uri; anemic-leaf (§2/§5). Same file uses Uri for authority anchor.
   Ground endpoint as Uri variant carrying socket/http/https/fd schemes.
   Trigger: B3 grounds docker endpoint with Uri type.

All three tracked per §6 framework: honest ratchet markers with named
dissolution triggers and layer they belong to (B3 modeling layer).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Add dissolve-on markers for anemic-leaf and error-response scaffolds

Address REQUEST_CHANGES review findings by adding honest ratchet markers
for remaining scaffolds per §6 pattern:

1. **HostConfig/ContainerConfig anemic leaves** (container_inspect.dag:76-78)
   - cap_add/cap_drop, exposed_ports, port_bindings, volumes, volumes_from,
     device_requests (HostConfig); env, cmd, entrypoint, labels, volumes,
     exposed_ports (ContainerConfig) are structured concepts flattened to
     bare List<String>? (§2 violation: anemic leaves)
   - Trigger B3: ground each as typed coproduct (PortBinding record,
     EnvVar record) or decomposed with named axes

2. **NetworkSettings bare-string fields** (container_inspect.dag:104-108)
   - gateway, ip_address, mac_address should be typed network carriers
     (IpAddress, MacAddress) not bare String?
   - Lower stakes since std/network primitives don't exist yet, but marks
     structured-validation gap (§5 fail-closed)
   - Trigger B3: introduces network address carriers in std/ or extdeps

3. **Error responses as opaque strings** (both files)
   - 404/500 => String collapses two distinct error shapes, violates §5
   - Docker returns structured JSON error objects with reason/message
   - Trigger B3: model as ErrorDetail coproduct (NotFound | ServerError
     variants with typed failure details)

All markers follow §6 self-flagged scaffold pattern with closure/, root
cause, and B3 dissolution trigger.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Ground ContainerStateDetail.error with ErrorMessage type

ContainerStateDetail.error was typed as bare String?, violating
bare-primitive-nicknames-concept modeling coherence. Error messages
are a semantic concept that must be grounded in a type.

Added type ErrorMessage = String to carry the semantic meaning,
replacing bare String usage. This grounds the concept per §3
(single authority) and §2 (minimize anemic leaves).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Remove unused import of VariantEncoding/StringVariant/VariantNaming/AsAuthored

Dead remnants from the old wire-contract approach. These imports are not
used anywhere in the file and violate §3 (minimize redundancy). Removing
them eliminates potential compile errors and cleans up the module's
actual dependencies.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Address review findings: add cpu_percent ratio tracking + fix Optional matcher consistency

- Add dissolve_on_cpu_percent_ratio_carrier to container_stats.dag documenting bare Float? unit modeling gap (§5); triggers B3 grounding with Ratio/PercentagePoint type alias
- Fix container_inspect.dag optional accessors to use consistent Present/Absent pattern instead of null matching (all three: memory_limit, cpu_quota, cpu_period)

Both findings valid from claude/claude-opus-4-7 review #5635. Dissolve-on marker ensures tracking discipline; pattern consistency prevents silent wildcard-fallthrough risk.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Add dissolve markers for ContainerStateDetail redundancy + container_state_is_running symmetry

- Add dissolve_on_container_state_detail_redundant_bools documenting parallel status coproduct + redundant bool fields allowing illegal states; marks for B3 resolution via bool predicates derived from status only
- Add dissolve_on_container_state_predicate_family for symmetry with parse/wire-label pair (both marker-tracked); documents handrolled predicate helper discipline gap and marks for B3 consolidation

Both findings from claude/claude-opus-4-7 review #5635 (non-blocking nits, but valuable tracking discipline).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Add dissolve marker for HostConfig.memory_swap -1 unlimited convention loss

HostConfig.memory_swap: ByteSize? loses Docker wire convention where -1 encodes 'unlimited'; Nat-backed ByteSize cannot represent -1, causing fidelity gap at extdeps boundary. Added dissolve_on_memory_swap_unlimited_convention marker documenting the gap and B3 trigger (coproduct variant or tagged union to preserve wire semantics).

Finding from claude/claude-opus-4-7 review #5635 (APPROVE, non-blocking).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Remove unescaped braces in dissolve_on_hostconfig_containerconfig_anemic_leaves string

Unescaped { and } in the example text caused .dag parser to treat them as template interpolation markers, failing on colon in field names. Rephrase example without braces.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Test all container state roundtrips instead of unused list binding

Remove unused `states` binding and expand roundtrip test to verify all
5 ContainerState variants (Running, Paused, Exited, Dead, Restarting)
roundtrip correctly through parse/wire-label functions per review feedback.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix REQUEST_CHANGES architectural violations per parent guidance

Three fixes applied per Section-8 guidance:

Fix 1 — Remove container_state_is_running predicate (§2/§3)
- Delete function and dissolve_on marker (lines 163-168)
- Callers now inline: match state { Running => ... _ => ... }
- Update test file imports and remove predicate-only tests
- Keep predicate-using test (sample_inspect_has_running_state) via direct equality

Fix 2 — Ground parse/wire-label fork via CoproductWireContract (§4)
- Add container_state_wire_contract data item
- Import CoproductWireContract, StringVariant, SnakeCase from std.serialization
- Rename dissolve_on_variant_wire_fork_container_state to structural_coverage_gap_container_state_codec_hand_rolled
- Update marker text to reference contract and remove B3 reference

Fix 3 — Rewrite all B3 references with concrete triggers
- container_inspect.dag (5 markers): wire-deserialization, Unlimited variant, typed carriers, network addresses, typed errors
- container_stats.dag (3 markers): Ratio/PercentagePoint, typed errors, typed/tagged union

Verification: gunbc compile --source-root dsl → 0 docker diagnostics

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>

* BMC onboarding: complete srv3 lifecycle orchestration (.dag) + GCP store §3 fix (#5661)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: rotate+reauth leg of the onboarding orchestration (compile-verified, live-gated)

Assemble the credential-rotation leg of orchestration C over new_altra_onboarding_plan,
now that Lane B (#5634) landed the Redfish auth-as-Secret seam on main:
materialize the netrc + PATCH body via Filesystem.Write (executable file effect),
SetAccountPassword (Redfish write), then reauth with the new credential to VERIFY
the rotation took — fail-closed if rejected. The minted Secret is declassified to
String exactly once, explicitly (the Secret type forbids accidental exposure).

Verified by execution: gunbc compile --source-root dsl => 464 modules, 471 files,
0 diagnostics — the legs typecheck and compose. LIVE execution is operator-fenced
(first destructive write); live-correctness of account_id/body shape is confirmed
only by the gated run against .192, not this typecheck. Not a *_test.dag, so it does
NOT auto-enroll as a floor witness (no false CI-coverage claim).

§5 debt (named): the netrc + body files transiently hold the credential on disk at
default umask with no post-run unlink; dissolution = mode-0600 file write + unlink leg.

gen+store leg (entropy mint #5633 -> base64 -> GCP store) wires in once #5633 lands;
os-install leg pends Lane E (#5638).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* bmc_onboard: complete srv3 onboarding orchestration (acquire→gen+store→rotate→reauth→os-install)

Assemble the full lifecycle as one .dag workflow over new_altra_onboarding_plan +
srv3_os_install_plan, now that all four lanes (entropy #5633, auth-Secret #5634,
OS-install #5638) landed on main:

  acquire     — GetServiceRoot + factory-login GetSystem (read; proven live earlier)
  gen         — mint a credential from OS entropy (extdeps.entropy Urandom), FAIL-CLOSED
                on the Optional (never a fabricated/empty credential — dissolves the
                witness scaffold's empty-string arm per cool-lynx's dissolution trigger)
  store       — base64 of the same octets -> GCP AddVersion (durability) under the
                plan's secret id; token via gcloud
  rotate+reauth — Filesystem.Write netrc + PATCH body, SetAccountPassword, reauth with the
                NEW credential to verify the rotation took (fail-closed)
  os-install  — re-materialize netrc with the NEW credential (factory netrc is now stale),
                SetBootSourceOverride(Pxe,Once) + ResetSystem(ForceRestart) via the Lane-E
                wire fns to boot srv3 into the PXE/autoinstall path

Legs chain on ProcessExit so any failure short-circuits. The minted Secret is
declassified to String exactly once, explicitly (the type forbids accidental leak).

Verified by execution: gunbc compile --source-root dsl => 480 modules, 488 files,
0 diagnostics. The pure wire-shape builders (netrc line, Redfish PATCH/POST JSON
bodies, GCP secret name) have by-execution witnesses — all 5 green via --claim-run.
The live Redfish/GCP/entropy legs are OPERATOR-FENCED (destructive); their live
correctness is confirmed only by the gated run against .192, not this typecheck.

§5 debt (named): netrc/body files transiently hold the credential on disk at default
umask with no unlink; dissolution = mode-0600 file write + unlink leg.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5661: mark bmc_credential_bytes + JSON-concat scaffolds; add cred-only entry point

Address review #32107:
- bmc_credential_bytes: Int gets a 🟡 marker riding extdeps.entropy's
  entropy_count_bytes_unit_debt (same bytesize-argv-interpolation dissolution) —
  no longer an unmarked *_bytes-on-Int.
- the concat-built Redfish PATCH/POST bodies get a 🟡 dissolve-on marker (safe for
  the current base64url-credential + enum-wire call sites, which the body-shape
  witnesses pin; dissolution = a structured JSON-object encoder authority).

Also adds bmc_assimilate_srv3_credential — a credential-only entry point (acquire ->
gen -> store(read-back gated) -> rotate -> reauth, STOPPING before os-install) so the
live BMC credential assimilation can run while no PXE/install server exists yet
(running the full bmc_onboard_srv3 would reset srv3 into a dead PXE boot). Refactors
the shared store+rotate into bmc_store_and_rotate (no duplication).

Compile clean (488 files, 0 diagnostics); body-shape witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* fmt: collapse resolve_auth call site to one line (cargo fmt --check)

The auth_input fix's call-site edit split the let-binding across two lines; rustfmt
wants it on one (fits in width). cargo fmt --all --check now clean — this was the
rust_tests CI failure on 311ff38 (fmt gate), not a logic issue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: dissolve the entropy decode→encode identity round-trip (§2, review #32137)

mint_credential_octets base64_decode'd Urandom.octets_b64 to List<UInt8>, then
credential_from_octets base64_encode'd it straight back — base64_encode∘base64_decode
is identity, so the octets intermediate (and the Optional failure mode that could only
trip on a base64_decode bug, never on real Urandom output) bought nothing. Collapse to
one fn: mint_bmc_credential() = Urandom.ReadBytes(count).octets_b64 as Secret. The
credential IS the base64 entropy string directly — same string set on the BMC, stored
as the GCP payload, and compared in the read-back gate (identity preserved; the BMC
password is byte-for-byte what it was). Drops the std.encoding + std.integer{UInt8}
imports and the unused ExitFailure. Fail-closed now lives at the Urandom service call
(nonzero exit raises). Compile 488/0, body witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* Fix main-red regression: lens-test v2_source_roots missing dsl root after 5647 disposition import, plus regen 2 github pipeline snapshots after 5644 restructure (#5672)

* WIP: Fix main-red regression: lens-test v2_source_roots missing dsl root afte

* Resolve merge conflicts: take main's v2_layer_roots() and typed-field assertions

#5668 landed equivalent fixes using the single-authority helper; resolve
all four conflicted files to main's version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* ROADMAP §1: CI-humming operations plan (un-throttle runner slots from the modeled budget) (#5682)

Single CI-operations authority for the ▸ NOW host-operation-on-.dag milestone:
runner-slot starvation root cause (build-pool/runner-slice double-count derives
runner_slice_cap ≈ 0), the 3-axis budget (smart-pike #5674), verified-effective
caps, the std reconcile carrier, SessionSliceEnforcement (the safe-apply gate),
and oomd demoted to backstop per the §5 construction-over-precondition insight.
Linked from ROADMAP §1 (orphan-doc lens).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…osed fallback, CPU-core term unified with spawn_width, sccache named reservation, emit consumable per-host count (#5674)

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* STAGE-2 PR-2: wire runner-slot count to the derived fleet-resource budget model

Consume #5663's conserving fleet_host_budget.runner_slice_cap as the single
authority for the GHA runner-slot count, dissolving the §3 fork where the runner
slice had two homes (ci_runner_placement.host_runner_slice = host-overhead-
session_slice vs fleet_host_budget.runner_slice_cap = host-overhead-baselines-
sccache_build_pool-headroom).

- CPU-core term unified with spawn_width: new std.realization_width.cpu_cores_available
  (nproc - margin) is the ONE CPU-core authority. ctrl jobserver cpu_bound now reads it
  (token count byte-identical), fleet_host_budget exposes effective_runner_cpu_cap from it,
  and the runner count = int_min(memory_fit, cpu_cores_available) -- the spawn_width
  min-over-cores shape, minus the >=1 floor (a runner count of 0 is valid -> fail closed).
- enforce flag (§5 live-enforcement gate): RunnerSlotEnforcement committed Unenforced
  because the runner-slice MemoryMax drop-in is inert (effective MemoryMax=INFINITY); a
  derived count would assume a cap the host does not enforce. Model-sound but
  live-unenforced still fails closed.
- fail-closed fallback: budget-model Unsound OR enforcement Unenforced -> PlanUnsound; no
  silent legacy-slice fallback (kills the old conservative-fallback fail-open).
- sccache named reservation: budget child build_pool -> sccache_build_pool.
- consumable per-host emit: runner-deploy lines carry runner_count + per_slot_memory_max_bytes
  + build_tokens, one line per host, or the typed Unsound reason gracefully (no partial line).
  Committed manifest correctly emits UNSOUND (preconditions left as-is per §5 guardrail).
- operating curve reframed to SESSION-side coverage only (runner count is now independent
  of the session operating point).

Witnessed by execution (claim_batch) -- dual direction: (a) live/committed -> Unsound
manifest with typed reason, no host lines; (b) OomdEnforced+HeadroomSet+Enforced spliced
test-locally -> real per-host count+cap+tokens. fleet_model_holds, runner_placement_holds,
realization_width_witnesses, ci_budget_tree_holds all green. ci_budget_tree.runner_pool_bytes_at
left as a named follow-up (separate consumer).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* T0: fix runner-slice double-subtract — runner_slice = host−overhead−session_worstcase−headroom; count = min(mem, build_tokens, cpu) (#5680)

* tesgen analysis (#5664)

* WIP: tesgen analysis

* WIP: tesgen analysis

* Wiring-liveness oracle + compile-time lens: plan carrier + roadmap §4 (carrier-modeled)

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>

* Slice C: Host metrics extdeps shapes (#5636)

* WIP: Slice C: Host metrics extdeps shapes

* Slice C: Host metrics extdeps shapes (§3 single-authority shape modeling)

Model host metrics data structures in extdeps/os following DESIGN.md §3
de-fusion (shape/transport/policy separation):

- proc_meminfo.dag: /proc/meminfo output structure (ProcMeminfo type with
  memory metrics fields, MemoryMetric for individual key-value pairs)
- systemd.dag: systemctl is-active output structure (SystemdUnitActiveState
  coproduct, SystemdUnitStatus record with wire contract for snake_case encoding)
- free.dag: free -b output structure (MemoryStats and SwapStats records in
  FreeOutput container)

All three modules anchor to external authorities (man7.org) per extdeps
convention. Test witnesses prove shape construction and invariant checking
via executable Bool assertions (mem_available <= mem_total, etc).

Each module models shape only; transport (how to fetch) and policy
(when/where to call) remain absent, per single-authority principle.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Add NonEmptyStr casting in witness tests (as NonEmptyStr for name fields)

* WIP: Slice C: Host metrics extdeps shapes

* Fix: resolve unit type violations in host metrics extdeps shapes

Replace bare Int fields with proper Measure types in host metrics modules:
- proc_meminfo.dag: all memory fields now use Kibibyte (Measure<Memory, Kibi, Nat>)
- free.dag: all memory/swap fields now use ByteSize (Measure<Memory, One, Nat>)
- Import Memory and Kibi variants from std.measure following §3 single-authority principle
- Update test witnesses to cast numeric literals to Measure types
- Rename proc_meminfo.dag field value_kibibytes → value for consistency with Kibibyte type

Addresses blocking review: unit type violations violate §3 single-authority principle.
Establishes Measure as single authority for all physical quantity modeling per std.measure.dag.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* FIX: systemd.dag wire contract with execution + inert carrier roster

* Fix fmt: normalize roster comment alignment

Cargo fmt --all normalized spacing on SecretValue roster entry.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice C: Host metrics extdeps shapes

* Address PR feedback: consolidate Kibibyte alias, remove trivial assertions, mark systemd parallel-representation

1. Move Kibibyte alias from proc_meminfo.dag to std/measure.dag (canonical location per §3 single authority)
2. Update proc_meminfo.dag and witness test imports to consume Kibibyte from std.measure
3. Remove trivial >= 0 assertions on Nat-carried ByteSize values in free witness test (non-discriminating)
4. Add dissolve-on markers to systemd parse/label functions pending contract-driven derivation (§3 parallel-representation scaffold)

Addresses: claude/claude-opus-4-7 REQUEST_CHANGES feedback on #5636

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice C: Host metrics extdeps shapes

* FIX: Add missing List import to systemd.dag

systemd_parse_label_derivation_debt data declaration uses List<NonEmptyStr> but
the file lacked the corresponding std.list import. Adding it resolves the
compilation error.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* FIX: Remove stale inert carrier roster entries

Remove 5 entries that now have external consumers:
- Kibibyte (imported by witness tests)
- MemoryMetric (imported by witness tests)
- MemoryStats (imported by witness tests)
- SwapStats (imported by witness tests)
- SystemdUnitActiveState (imported by witness tests)

Keep FreeOutput, ProcMeminfo, SystemdUnitStatus which still meet inert criteria.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Revert "FIX: Remove stale inert carrier roster entries"

This reverts commit 8c06981.

* WIP: Slice C: Host metrics extdeps shapes

* FIX: Correct witness test syntax for .dag language

Three test files had unsupported syntax:

1. os_systemd_witness_test.dag: Bool literals must be lowercase (true/false, not True/False).
   Changed lines 16, 17, 23, 24 to use correct .dag syntax.

2. os_proc_meminfo_witness_test.dag: Cannot cast Int to Kibibyte with 'as' operator.
   Changed all Kibibyte casts to record literal syntax: Kibibyte { count: N }.

3. os_free_witness_test.dag: Cannot cast Int to ByteSize with 'as' operator.
   Changed all ByteSize casts to byte_size(count: N) constructor calls.
   Added byte_size import to std.measure imports.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Trigger CI run

* Retrigger CI (previous run stuck in queue)

* FIX: Remove 5 stale inert carrier roster entries

Removed entries that gained consumers when host metrics types (Kibibyte, MemoryMetric, MemoryStats, SwapStats, SystemdUnitActiveState) were integrated into extdeps modules:

- Kibibyte: moved to std/measure.dag, now imported by proc_meminfo.dag
- MemoryMetric, MemoryStats, SwapStats: now consumed by proc_meminfo.dag / free.dag
- SystemdUnitActiveState: now consumed by systemd.dag

Remaining roster: 11 entries (AccessPolicy, CargoDependency, CargoPackage, FilePermissions, FloorWitnessRow, FreeOutput, GitCliReportedVersion, ProcMeminfo, ReactHookSite, SecretValue, SystemdUnitStatus).

* WIP: Slice C: Host metrics extdeps shapes

* Revert "WIP: Slice C: Host metrics extdeps shapes"

This reverts commit 6bc985a.

* Retrigger CI

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>

* Slice B: Docker container stats extdeps shapes (#5635)

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: correct imports for Nat type in docker shapes

Move Nat import to std.nat module where it is defined.
Remove unused BlkioStats from witness test imports.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Docker shapes de-fuse, duration carriers, wire contract consumption

Address four review findings from claude/opus-4-7 and bold-ant-53:

1. **Duration semantics** — CPU times require std.measure carriers, not bare Nat.
   Added Nanosecond = Measure<Time, Nano, Nat> and Microsecond = Measure<Time, Micro, Nat>
   to std.measure.dag. Updated container_stats.dag and container_inspect.dag to type:
   - cpu_usage fields (total, kernel, user, system) as Nanosecond
   - cpu_period and cpu_quota as Microsecond

2. **Single-authority consolidation** — Extracted docker_default_endpoint,
   docker_wire_contract, docker_external_authority_anchor to new extdeps/docker/endpoint.dag.
   Both container_stats.dag and container_inspect.dag now import from endpoint.

3. **Networks fidelity** — Changed from hardcoded eth0 field to Networks.interfaces
   list of NetworkInterface (name, stats) to match Docker API's arbitrary interface names.

4. **Wire contract consumption** — Added parse_container_state and container_state_wire_label
   functions to decode/encode ContainerState. Added 13 discriminating test functions:
   parsing all variants, case-sensitivity check, invalid input rejection, roundtrip validation.

Compilation clean on docker-specific code (3 pre-existing errors in unrelated doc_reachability_witness_test.dag).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Refine: Remove inert docker_wire_contract, add memory_stats working-set gap marker

1. **Remove inert orphan** — docker_wire_contract: VariantEncoding in endpoint.dag was
   imported but never used. Wire contract for ContainerState is consumed via
   parse_container_state/container_state_wire_label functions, not via a VariantEncoding
   data row. Removed from endpoint.dag and dropped unused VariantEncoding imports
   from container_stats.dag.

2. **Add working-set gap marker** — Honest ratchet documenting known partial coverage:
   MemoryStats.usage includes page cache (inactive_file), true working-set = usage -
   stats.inactive_file from Docker stats sub-map. Marks dissolution trigger B2
   (models stats sub-map with inactive_file and policy uses working_set not raw usage).

Compilation clean. Ready for sign-off.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Add tracked-debt markers for three dissolve-on patterns

1. **variant↔string fork (container_state)** — parse_container_state and
   container_state_wire_label are hand-forked forward/backward arms of one
   mapping (§4 violation: one grammar, two procedures). Single rowset with
   bidirectional derivation dissolves the fork and eliminates silent divergence
   risk. Trigger: B3 models ContainerState wire facts as single authority.

2. **BlkioValue.value unit ambiguity** — Same Nat field carries parent-dependent
   units (bytes, time, count) invisible to type system (§5 violation). Docker
   wire format constraint. Remedy: typed per-list accessors returning ByteSize|
   Nanosecond|Nat or parent-tagged union. Trigger: B3 models BlkioValue with
   discriminated unit type.

3. **docker_default_endpoint String vs Uri** — Typed as bare String but module
   imports Uri; anemic-leaf (§2/§5). Same file uses Uri for authority anchor.
   Ground endpoint as Uri variant carrying socket/http/https/fd schemes.
   Trigger: B3 grounds docker endpoint with Uri type.

All three tracked per §6 framework: honest ratchet markers with named
dissolution triggers and layer they belong to (B3 modeling layer).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Add dissolve-on markers for anemic-leaf and error-response scaffolds

Address REQUEST_CHANGES review findings by adding honest ratchet markers
for remaining scaffolds per §6 pattern:

1. **HostConfig/ContainerConfig anemic leaves** (container_inspect.dag:76-78)
   - cap_add/cap_drop, exposed_ports, port_bindings, volumes, volumes_from,
     device_requests (HostConfig); env, cmd, entrypoint, labels, volumes,
     exposed_ports (ContainerConfig) are structured concepts flattened to
     bare List<String>? (§2 violation: anemic leaves)
   - Trigger B3: ground each as typed coproduct (PortBinding record,
     EnvVar record) or decomposed with named axes

2. **NetworkSettings bare-string fields** (container_inspect.dag:104-108)
   - gateway, ip_address, mac_address should be typed network carriers
     (IpAddress, MacAddress) not bare String?
   - Lower stakes since std/network primitives don't exist yet, but marks
     structured-validation gap (§5 fail-closed)
   - Trigger B3: introduces network address carriers in std/ or extdeps

3. **Error responses as opaque strings** (both files)
   - 404/500 => String collapses two distinct error shapes, violates §5
   - Docker returns structured JSON error objects with reason/message
   - Trigger B3: model as ErrorDetail coproduct (NotFound | ServerError
     variants with typed failure details)

All markers follow §6 self-flagged scaffold pattern with closure/, root
cause, and B3 dissolution trigger.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Ground ContainerStateDetail.error with ErrorMessage type

ContainerStateDetail.error was typed as bare String?, violating
bare-primitive-nicknames-concept modeling coherence. Error messages
are a semantic concept that must be grounded in a type.

Added type ErrorMessage = String to carry the semantic meaning,
replacing bare String usage. This grounds the concept per §3
(single authority) and §2 (minimize anemic leaves).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Remove unused import of VariantEncoding/StringVariant/VariantNaming/AsAuthored

Dead remnants from the old wire-contract approach. These imports are not
used anywhere in the file and violate §3 (minimize redundancy). Removing
them eliminates potential compile errors and cleans up the module's
actual dependencies.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Address review findings: add cpu_percent ratio tracking + fix Optional matcher consistency

- Add dissolve_on_cpu_percent_ratio_carrier to container_stats.dag documenting bare Float? unit modeling gap (§5); triggers B3 grounding with Ratio/PercentagePoint type alias
- Fix container_inspect.dag optional accessors to use consistent Present/Absent pattern instead of null matching (all three: memory_limit, cpu_quota, cpu_period)

Both findings valid from claude/claude-opus-4-7 review #5635. Dissolve-on marker ensures tracking discipline; pattern consistency prevents silent wildcard-fallthrough risk.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Add dissolve markers for ContainerStateDetail redundancy + container_state_is_running symmetry

- Add dissolve_on_container_state_detail_redundant_bools documenting parallel status coproduct + redundant bool fields allowing illegal states; marks for B3 resolution via bool predicates derived from status only
- Add dissolve_on_container_state_predicate_family for symmetry with parse/wire-label pair (both marker-tracked); documents handrolled predicate helper discipline gap and marks for B3 consolidation

Both findings from claude/claude-opus-4-7 review #5635 (non-blocking nits, but valuable tracking discipline).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Add dissolve marker for HostConfig.memory_swap -1 unlimited convention loss

HostConfig.memory_swap: ByteSize? loses Docker wire convention where -1 encodes 'unlimited'; Nat-backed ByteSize cannot represent -1, causing fidelity gap at extdeps boundary. Added dissolve_on_memory_swap_unlimited_convention marker documenting the gap and B3 trigger (coproduct variant or tagged union to preserve wire semantics).

Finding from claude/claude-opus-4-7 review #5635 (APPROVE, non-blocking).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Remove unescaped braces in dissolve_on_hostconfig_containerconfig_anemic_leaves string

Unescaped { and } in the example text caused .dag parser to treat them as template interpolation markers, failing on colon in field names. Rephrase example without braces.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix: Test all container state roundtrips instead of unused list binding

Remove unused `states` binding and expand roundtrip test to verify all
5 ContainerState variants (Running, Paused, Exited, Dead, Restarting)
roundtrip correctly through parse/wire-label functions per review feedback.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Slice B: Docker container stats extdeps shapes

* Fix REQUEST_CHANGES architectural violations per parent guidance

Three fixes applied per Section-8 guidance:

Fix 1 — Remove container_state_is_running predicate (§2/§3)
- Delete function and dissolve_on marker (lines 163-168)
- Callers now inline: match state { Running => ... _ => ... }
- Update test file imports and remove predicate-only tests
- Keep predicate-using test (sample_inspect_has_running_state) via direct equality

Fix 2 — Ground parse/wire-label fork via CoproductWireContract (§4)
- Add container_state_wire_contract data item
- Import CoproductWireContract, StringVariant, SnakeCase from std.serialization
- Rename dissolve_on_variant_wire_fork_container_state to structural_coverage_gap_container_state_codec_hand_rolled
- Update marker text to reference contract and remove B3 reference

Fix 3 — Rewrite all B3 references with concrete triggers
- container_inspect.dag (5 markers): wire-deserialization, Unlimited variant, typed carriers, network addresses, typed errors
- container_stats.dag (3 markers): Ratio/PercentagePoint, typed errors, typed/tagged union

Verification: gunbc compile --source-root dsl → 0 docker diagnostics

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>

* BMC onboarding: complete srv3 lifecycle orchestration (.dag) + GCP store §3 fix (#5661)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: rotate+reauth leg of the onboarding orchestration (compile-verified, live-gated)

Assemble the credential-rotation leg of orchestration C over new_altra_onboarding_plan,
now that Lane B (#5634) landed the Redfish auth-as-Secret seam on main:
materialize the netrc + PATCH body via Filesystem.Write (executable file effect),
SetAccountPassword (Redfish write), then reauth with the new credential to VERIFY
the rotation took — fail-closed if rejected. The minted Secret is declassified to
String exactly once, explicitly (the Secret type forbids accidental exposure).

Verified by execution: gunbc compile --source-root dsl => 464 modules, 471 files,
0 diagnostics — the legs typecheck and compose. LIVE execution is operator-fenced
(first destructive write); live-correctness of account_id/body shape is confirmed
only by the gated run against .192, not this typecheck. Not a *_test.dag, so it does
NOT auto-enroll as a floor witness (no false CI-coverage claim).

§5 debt (named): the netrc + body files transiently hold the credential on disk at
default umask with no post-run unlink; dissolution = mode-0600 file write + unlink leg.

gen+store leg (entropy mint #5633 -> base64 -> GCP store) wires in once #5633 lands;
os-install leg pends Lane E (#5638).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* bmc_onboard: complete srv3 onboarding orchestration (acquire→gen+store→rotate→reauth→os-install)

Assemble the full lifecycle as one .dag workflow over new_altra_onboarding_plan +
srv3_os_install_plan, now that all four lanes (entropy #5633, auth-Secret #5634,
OS-install #5638) landed on main:

  acquire     — GetServiceRoot + factory-login GetSystem (read; proven live earlier)
  gen         — mint a credential from OS entropy (extdeps.entropy Urandom), FAIL-CLOSED
                on the Optional (never a fabricated/empty credential — dissolves the
                witness scaffold's empty-string arm per cool-lynx's dissolution trigger)
  store       — base64 of the same octets -> GCP AddVersion (durability) under the
                plan's secret id; token via gcloud
  rotate+reauth — Filesystem.Write netrc + PATCH body, SetAccountPassword, reauth with the
                NEW credential to verify the rotation took (fail-closed)
  os-install  — re-materialize netrc with the NEW credential (factory netrc is now stale),
                SetBootSourceOverride(Pxe,Once) + ResetSystem(ForceRestart) via the Lane-E
                wire fns to boot srv3 into the PXE/autoinstall path

Legs chain on ProcessExit so any failure short-circuits. The minted Secret is
declassified to String exactly once, explicitly (the type forbids accidental leak).

Verified by execution: gunbc compile --source-root dsl => 480 modules, 488 files,
0 diagnostics. The pure wire-shape builders (netrc line, Redfish PATCH/POST JSON
bodies, GCP secret name) have by-execution witnesses — all 5 green via --claim-run.
The live Redfish/GCP/entropy legs are OPERATOR-FENCED (destructive); their live
correctness is confirmed only by the gated run against .192, not this typecheck.

§5 debt (named): netrc/body files transiently hold the credential on disk at default
umask with no unlink; dissolution = mode-0600 file write + unlink leg.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5661: mark bmc_credential_bytes + JSON-concat scaffolds; add cred-only entry point

Address review #32107:
- bmc_credential_bytes: Int gets a 🟡 marker riding extdeps.entropy's
  entropy_count_bytes_unit_debt (same bytesize-argv-interpolation dissolution) —
  no longer an unmarked *_bytes-on-Int.
- the concat-built Redfish PATCH/POST bodies get a 🟡 dissolve-on marker (safe for
  the current base64url-credential + enum-wire call sites, which the body-shape
  witnesses pin; dissolution = a structured JSON-object encoder authority).

Also adds bmc_assimilate_srv3_credential — a credential-only entry point (acquire ->
gen -> store(read-back gated) -> rotate -> reauth, STOPPING before os-install) so the
live BMC credential assimilation can run while no PXE/install server exists yet
(running the full bmc_onboard_srv3 would reset srv3 into a dead PXE boot). Refactors
the shared store+rotate into bmc_store_and_rotate (no duplication).

Compile clean (488 files, 0 diagnostics); body-shape witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* fmt: collapse resolve_auth call site to one line (cargo fmt --check)

The auth_input fix's call-site edit split the let-binding across two lines; rustfmt
wants it on one (fits in width). cargo fmt --all --check now clean — this was the
rust_tests CI failure on 311ff38 (fmt gate), not a logic issue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: dissolve the entropy decode→encode identity round-trip (§2, review #32137)

mint_credential_octets base64_decode'd Urandom.octets_b64 to List<UInt8>, then
credential_from_octets base64_encode'd it straight back — base64_encode∘base64_decode
is identity, so the octets intermediate (and the Optional failure mode that could only
trip on a base64_decode bug, never on real Urandom output) bought nothing. Collapse to
one fn: mint_bmc_credential() = Urandom.ReadBytes(count).octets_b64 as Secret. The
credential IS the base64 entropy string directly — same string set on the BMC, stored
as the GCP payload, and compared in the read-back gate (identity preserved; the BMC
password is byte-for-byte what it was). Drops the std.encoding + std.integer{UInt8}
imports and the unused ExitFailure. Fail-closed now lives at the Urandom service call
(nonzero exit raises). Compile 488/0, body witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* WIP: Wire runner-slot count to derived budget model: enforce flag, fail-close

* Fix main-red regression: lens-test v2_source_roots missing dsl root after 5647 disposition import, plus regen 2 github pipeline snapshots after 5644 restructure (#5672)

* WIP: Fix main-red regression: lens-test v2_source_roots missing dsl root afte

* Resolve merge conflicts: take main's v2_layer_roots() and typed-field assertions

#5668 landed equivalent fixes using the single-authority helper; resolve
all four conflicted files to main's version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* ROADMAP §1: CI-humming operations plan (un-throttle runner slots from the modeled budget) (#5682)

Single CI-operations authority for the ▸ NOW host-operation-on-.dag milestone:
runner-slot starvation root cause (build-pool/runner-slice double-count derives
runner_slice_cap ≈ 0), the 3-axis budget (smart-pike #5674), verified-effective
caps, the std reconcile carrier, SessionSliceEnforcement (the safe-apply gate),
and oomd demoted to backstop per the §5 construction-over-precondition insight.
Linked from ROADMAP §1 (orphan-doc lens).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>

* Resolve merge: keep counted-once runner_slice_cap (4-arg, no build_pool subtract) + import RunnerSliceCapEffectiveness from ci_floor_measurement single-authority home (drop #5687 5-arg double-subtract form per bright-stag §2/§3 2026-06-23 ruling)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Jun 24, 2026
…t + SA + IAM + WIF as .dag, proven live) (#5712)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: rotate+reauth leg of the onboarding orchestration (compile-verified, live-gated)

Assemble the credential-rotation leg of orchestration C over new_altra_onboarding_plan,
now that Lane B (#5634) landed the Redfish auth-as-Secret seam on main:
materialize the netrc + PATCH body via Filesystem.Write (executable file effect),
SetAccountPassword (Redfish write), then reauth with the new credential to VERIFY
the rotation took — fail-closed if rejected. The minted Secret is declassified to
String exactly once, explicitly (the Secret type forbids accidental exposure).

Verified by execution: gunbc compile --source-root dsl => 464 modules, 471 files,
0 diagnostics — the legs typecheck and compose. LIVE execution is operator-fenced
(first destructive write); live-correctness of account_id/body shape is confirmed
only by the gated run against .192, not this typecheck. Not a *_test.dag, so it does
NOT auto-enroll as a floor witness (no false CI-coverage claim).

§5 debt (named): the netrc + body files transiently hold the credential on disk at
default umask with no post-run unlink; dissolution = mode-0600 file write + unlink leg.

gen+store leg (entropy mint #5633 -> base64 -> GCP store) wires in once #5633 lands;
os-install leg pends Lane E (#5638).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* bmc_onboard: complete srv3 onboarding orchestration (acquire→gen+store→rotate→reauth→os-install)

Assemble the full lifecycle as one .dag workflow over new_altra_onboarding_plan +
srv3_os_install_plan, now that all four lanes (entropy #5633, auth-Secret #5634,
OS-install #5638) landed on main:

  acquire     — GetServiceRoot + factory-login GetSystem (read; proven live earlier)
  gen         — mint a credential from OS entropy (extdeps.entropy Urandom), FAIL-CLOSED
                on the Optional (never a fabricated/empty credential — dissolves the
                witness scaffold's empty-string arm per cool-lynx's dissolution trigger)
  store       — base64 of the same octets -> GCP AddVersion (durability) under the
                plan's secret id; token via gcloud
  rotate+reauth — Filesystem.Write netrc + PATCH body, SetAccountPassword, reauth with the
                NEW credential to verify the rotation took (fail-closed)
  os-install  — re-materialize netrc with the NEW credential (factory netrc is now stale),
                SetBootSourceOverride(Pxe,Once) + ResetSystem(ForceRestart) via the Lane-E
                wire fns to boot srv3 into the PXE/autoinstall path

Legs chain on ProcessExit so any failure short-circuits. The minted Secret is
declassified to String exactly once, explicitly (the type forbids accidental leak).

Verified by execution: gunbc compile --source-root dsl => 480 modules, 488 files,
0 diagnostics. The pure wire-shape builders (netrc line, Redfish PATCH/POST JSON
bodies, GCP secret name) have by-execution witnesses — all 5 green via --claim-run.
The live Redfish/GCP/entropy legs are OPERATOR-FENCED (destructive); their live
correctness is confirmed only by the gated run against .192, not this typecheck.

§5 debt (named): netrc/body files transiently hold the credential on disk at default
umask with no unlink; dissolution = mode-0600 file write + unlink leg.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5661: mark bmc_credential_bytes + JSON-concat scaffolds; add cred-only entry point

Address review #32107:
- bmc_credential_bytes: Int gets a 🟡 marker riding extdeps.entropy's
  entropy_count_bytes_unit_debt (same bytesize-argv-interpolation dissolution) —
  no longer an unmarked *_bytes-on-Int.
- the concat-built Redfish PATCH/POST bodies get a 🟡 dissolve-on marker (safe for
  the current base64url-credential + enum-wire call sites, which the body-shape
  witnesses pin; dissolution = a structured JSON-object encoder authority).

Also adds bmc_assimilate_srv3_credential — a credential-only entry point (acquire ->
gen -> store(read-back gated) -> rotate -> reauth, STOPPING before os-install) so the
live BMC credential assimilation can run while no PXE/install server exists yet
(running the full bmc_onboard_srv3 would reset srv3 into a dead PXE boot). Refactors
the shared store+rotate into bmc_store_and_rotate (no duplication).

Compile clean (488 files, 0 diagnostics); body-shape witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* fmt: collapse resolve_auth call site to one line (cargo fmt --check)

The auth_input fix's call-site edit split the let-binding across two lines; rustfmt
wants it on one (fits in width). cargo fmt --all --check now clean — this was the
rust_tests CI failure on 311ff38 (fmt gate), not a logic issue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* bmc_onboard: dissolve the entropy decode→encode identity round-trip (§2, review #32137)

mint_credential_octets base64_decode'd Urandom.octets_b64 to List<UInt8>, then
credential_from_octets base64_encode'd it straight back — base64_encode∘base64_decode
is identity, so the octets intermediate (and the Optional failure mode that could only
trip on a base64_decode bug, never on real Urandom output) bought nothing. Collapse to
one fn: mint_bmc_credential() = Urandom.ReadBytes(count).octets_b64 as Secret. The
credential IS the base64 entropy string directly — same string set on the BMC, stored
as the GCP payload, and compared in the read-back gate (identity preserved; the BMC
password is byte-for-byte what it was). Drops the std.encoding + std.integer{UInt8}
imports and the unused ExitFailure. Fail-closed now lives at the Urandom service call
(nonzero exit raises). Compile 488/0, body witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* GCP one-token bootstrap of the keyless BMC assimilator: API-enablement + SA + IAM + WIF modeled as .dag, proven live

Collapses the entire operator-fenced WIF runbook (every manual `gcloud` block) into a
single admin-token .dag orchestration over the proven v1 REST executor. The only manual
input is the initial admin access token, acquired via the operator's existing gcloud login
(shell.GCloud.AuthPrintAccessToken). No host/.rs changes — the REST executor already
serializes list/map/record JSON bodies.

New surfaces (all extdeps interface shapes + one workflow orchestration):
- extdeps/cloud/gcp/serviceusage.dag — ServiceUsage.BatchEnableServices
- extdeps/cloud/gcp/iam_admin.dag — IamAdmin.{CreateServiceAccount,CreateWorkloadIdentityPool,CreateWorkloadIdentityPoolProvider}
- extdeps/cloud/gcp/secret_manager.dag — SecretManager.SetSecretIamPolicy (resource-level least-priv)
- gcp.dag — shared GcpOperation + GcpService.{GcpIamCredentials,GcpServiceUsage} + gcp_service_api_id
- gunbc/assimilate/bmc_bootstrap_provision.dag — enable -> SA -> bind -> pool -> provider

API enablement is a DEPENDENCY OF USAGE, not a hand-typed list: bmc_required_gcp_apis is
derived from bmc_assimilate_service_deps (the GcpService set the path uses) via
gcp_service_api_id, single-authority on the GcpService enum.

PROVEN LIVE 2026-06-24 against gunbai-secrets: all 5 ops dispatched; SA minted, both
least-priv roles bound on bmc-srv3-admin only, WIF provider ACTIVE. Witness
bmc_bootstrap_provision_witness_test.dag green by execution (least-priv + closed-API-set +
derivation, with discriminating negatives). §3 single authority preserved (federation facts).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant