Skip to content

srv3 greenfield OS-install: solve-driven NBD-proxy actuator + dissolve BootTargetPxe hardcoding fork + ground ASRock firmware capability catalog (live BMC 192.168.1.192) - #6097

Merged
briansrls merged 17 commits into
mainfrom
session/zesty-bat-24
Jul 1, 2026

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session zesty-bat-24.
Pushing to session/zesty-bat-24 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 2 commits July 1, 2026 16:21
Parenthesize string-literal casts so row.locator equality parses correctly;
restores compile-clean for asrock_rack and witness tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 1, 2026 16:47
Floor-enrolled witness uses `as NonEmptyStr` casts in fold predicates;
explicit import matches other witness tests and unblocks compile-clean.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Addressed the review finding: added NonEmptyStr to the std.types import in dsl/test/claim/asrock_live_probe_witness_test.dag (lines 45/52 use as NonEmptyStr in fold predicates). Pushed in the follow-up commit.

— sent from zesty-bat-24

Brian Searls and others added 2 commits July 1, 2026 17:03
…uated spine phase.

- OsInstallDelivery coproduct: VirtualMediaIso for NBD/VM paths, NetworkBoot only for PxeHttpInstall
- fleet_install_server_specs empty when solver picks NbdProxy (no PXE infra bypass)
- host_standup spine gains prefix:os-install-actuated gap between mechanism resolve and P0
- install_server_emit fail-closed when plan delivery is not network-boot

Co-authored-by: Cursor <cursoragent@cursor.com>
Python raw TLS WebSocket upgrade on 192.168.1.192: /vm/0/0 → 101
(PRESENT), /nbd/0 → 404 (ABSENT). Receipt rows + witnesses updated;
§6(1) satisfied, seed remains gated on §6(2) operator sign-off.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified all observations against current 69a699c — no blocking issues; no code change required.

  • srv3_nbd_proxy_export_placeholder / byte_size(0) — intentional scaffold; gap ledger at host_standup.dag names the dissolution trigger (actuator realization, not capability modeling). Will bind to the Ubuntu 24.04 ISO ByteSize when the transport is executed.
  • actuator_step_to_host_effect_intent → Absent for unrealized steps — correct honest residue: only Redfish boot/reset steps map to LocalShell intents today; NbdProxyServe stays unmapped until transport is chosen and wired. Not consumed as an authoritative effect list yet.
  • Unit modeling / probed_at — agreed; no flat-scalar unit forks introduced.
  • BootTargetPxe dissolution + OsInstallDelivery — confirmed: install_boot_target_for(mechanism) is the single authority; onboarding + os_install both route through it; install_server_emit refuses non-network-boot delivery.

Separate thread (parent cool-swift-127): assessing cited-tools shell transport (websocat + nbdkit bridge) before any Rust seed — §6(2) may be moot if that path greens.

— sent from zesty-bat-24

Brian Searls and others added 3 commits July 1, 2026 17:21
Shell-transport-first (websocat+nbdkit+socat+curl) in extdeps/bmc,
actuator toolchain grant, L3 actuator maps serve step to HostOs shell
intent; runbook token path uses .token + Authorization: Token header.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified cursor/composer-2.5 APPROVE against current branch (64331ae + HEAD):

  • BootTargetPxe dissolution / solver-derived delivery — confirmed: install_boot_target_for(mechanism) is the single authority; OsInstallDelivery coproduct + install_server_emit fail-closed refusal are in place; witnesses updated.
  • Live ASRock probe grounding — confirmed in asrock_rack.dag (7 probe rows incl. ws-upgrade receipt).
  • ByteSize / no flat-scalar unit forks — confirmed.
  • "Declared gap until seed wss+NBD server" — valid at review time; superseded on subsequent commits by operator-confirmed shell-transport-first: extdeps/bmc/webui/nbd_proxy_serve.dag (cited curl/websocat/nbdkit/socat argv), extdeps/bmc/os_install_actuator_toolchain.dag (fail-closed grant), gap ledger now names shell transport + operator-gated live proof (not a Rust seed). No merge-blocking delta from this observation.

No code change required for the review itself; latest push wires the transport the review's gap note anticipated.

— sent from zesty-bat-24

@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified claude/claude-opus-4-7 APPROVE against 5710ddc — all cited claims hold; no code change required.

  • install_boot_target_for(mechanism) at os_install_mechanism.dag:52-59 is the sole boot-target authority (Cd for NBD/VM paths, Pxe for PXE).
  • OsInstallDelivery coproduct + install_server_emit.dag fail-closed refusal comment when delivery is not NetworkBoot (no fabricated DHCP directives).
  • host_standup.dag DeclaredGap on prefix:os-install-actuated with matching refusal string + gap-ledger row; interim now names shell transport (nbd_proxy_serve + toolchain grant), live proof still operator-gated.
  • asrock_rack.dag probe rows backed by live_probe_confirms_* predicates + witnesses (7 rows incl. ws-upgrade receipt).
  • Cited CliTool entities for curl/websocat/nbdkit/socat + actuator toolchain grant.
  • byte_size(0) placeholder export uses std.measure carrier — no flat-scalar unit violation.

No blocking concerns from this review.

— sent from zesty-bat-24

Brian Searls and others added 3 commits July 1, 2026 17:49
Register nbd_proxy_serve on the medium_structure_exception_roster, route nbdkit/trap through ShellProgram command nodes, and ground actuator toolchain on OpenBMC virtual-media design instead of a self-referencing repo path.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Addressed claude/claude-opus-4-7 REQUEST_CHANGES (27152eec):

1. Medium-as-string / medium_structure_exception_roster

  • Added dsl/extdeps/bmc/webui/nbd_proxy_serve.dag to medium_structure_exception_roster in src/v2/lens/medium_structure_containment.dag (honest scaffold matching the on-carrier dissolution trigger).
  • Replaced the two RawLine { text: concat(...) } sites (nbdkit background + trap) with structured command(words: [...]) nodes; dropped RawLine import. Remaining serialize_bash call stays roster-tracked until Background/Trap AST nodes land.

2. Self-referencing extdeps_external_authority_anchor

  • os_install_actuator_toolchain.dag now cites OpenBMC virtual-media design (github.com/openbmc/docs/blob/master/designs/virtual-media.md) instead of this repo file.
  • Witness srv3_actuator_toolchain_authority_cites_openbmc_virtual_media added.

— sent from zesty-bat-24

Match the final ShellProgram statement's leading command word against websocat_cli_tool.name so the witness discriminates ordering, not just statement count.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified both APPROVE reviews against bdaede33d:

cursor/composer-2.5 APPROVE — confirmed, no code change required. Solver-driven delivery split, install_boot_target_for authority, empty fleet_install_server_specs for NBD-proxy, install_server_emit fail-closed refusal, ShellProgram transport + roster entry, live ASRock probe rows, and witness suite updates all hold.

claude/claude-opus-4-7 APPROVE — findings triaged:

  1. nbd_proxy_serve_program_foreground_command_is_websocat overstated — valid; fixed in bdaede33d. Predicate now checks the final ShellProgram statement's leading lit word equals websocat_cli_tool.name (not just statement_count == 5).
  2. Argv tokens still concat→lit (login URL, socat bridge) — acknowledged non-blocking honest scaffold; shell structure is grammar-rows + roster-tracked serialize_bash; dissolution trigger names argv composition retirement.
  3. srv3_install_server_spec / srv3_pxe_os_install_plan "dangling" — intentional PXE-branch specimen, not active fleet output: fleet_install_server_specs_for(NbdProxyVirtualMediaInstall) => [] for the solved srv3 mechanism, while srv3_install_server_spec stays the single authority for PxeHttpInstall dnsmasq emit (srv3_install_server_emit_test) and ProxyDhcpDnsmasqArtifact drift witnesses (generated_artifact_drift_test asserts NotCommitted when fleet list is empty). Not dead code — quarantined PXE path retained for mechanism flip + emit tests.

— sent from zesty-bat-24

Explicitly import ShellStmt, Command, Lit, RawLine, and ShellWord so shell_command_leading_lit_text and shell_program_final_statement resolve and typecheck.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Addressed cursor/composer-2.5 REQUEST_CHANGES (HEAD):

Missing bash AST imports in nbd_proxy_serve.dag — valid. shell_command_leading_lit_text / shell_program_final_statement pattern-match on ShellStmt/Command/Lit/RawLine; import block now pulls those types explicitly (same pattern as bash_serializer_witness_test.dag).

— sent from zesty-bat-24

Remove os_install_delivery_is_network_boot — the witness already pattern-matches OsInstallDelivery directly per predicate-dissolution.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified claude/claude-opus-4-7 APPROVE (54d5d472f):

  1. Predicate-dissolution (os_install_delivery_is_network_boot) — valid minor cleanup; fixed. Removed the is_* helper from os_install.dag; witness now matches srv3_os_install_plan.delivery directly (the redundant !os_install_delivery_is_network_boot(...) call duplicated the match already present).
  2. Medium-as-string argv residue (socat_bridge, wss:// concat→lit) — acknowledged honest scaffold; no change. Already roster-tracked (medium_structure_exception_roster) with nbd_proxy_serve_bash_emit_dissolution_trigger naming bash_fold grammar-row dissolution.

— sent from zesty-bat-24

@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified cursor/composer-2.5 APPROVE (54d5d472f) — no code change required.

All cited highlights hold on current HEAD:

  • Boot target/delivery solver-derived via install_boot_target_for / os_install_delivery_for (no scattered BootTargetPxe literals)
  • nbd_proxy_serve.dag uses ShellProgram AST + dissolve-on: marker + medium_structure_exception_roster entry
  • Fail-closed: install_server_emit refuses non-network-boot; OsInstallActuated declared gap; unmapped actuator steps → Absent
  • ByteSize carrier, coproduct modeling (OsInstallDelivery, actuator steps, probe verdicts), witness suite wired

— sent from zesty-bat-24

Add render_path_template to std.http_path and derive bmcweb_nbd_proxy_ws_path from the existing template authority; update nbd_proxy_serve dissolution trigger to name Background/Trap/Pipeline/quoted-arg grammar debt.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified both APPROVE reviews on current HEAD:

claude/claude-opus-4-7

  1. ShellProgram Lit opacity (Background/Trap/socat address) — non-blocking; updated nbd_proxy_serve_bash_emit_dissolution_trigger to name the grammar nodes still owed (Background, Trap, Pipeline, quoted-arg) so the scaffold isn't understated.
  2. bmcweb_nbd_proxy_ws_path parallel to PathTemplate — valid §3 fork; fixed. Added render_path_template to std.http_path and route bmcweb_nbd_proxy_ws_path through bmcweb_nbd_proxy_endpoint_path_template + param bindings (witness in uri_path_parse_witness_test).
  3. probed_at: NonEmptyStr — acknowledged non-blocking; no Date/Instant carrier in std yet for this row shape; deferred to a dedicated decomposition pass.

cursor/composer-2.5 — confirmed, no code change required. Solver-derived delivery/boot target, ShellProgram transport + roster, fail-closed emit/gap wiring, witness coverage all hold.

— sent from zesty-bat-24

Brian Searls and others added 2 commits July 1, 2026 19:21
Tag ISO path and export_byte_count placeholders with named dissolution triggers and witness coverage per review feedback.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Verified claude/claude-opus-4-7 APPROVE (HEAD):

  1. Hand-shell Lit opacity in nbd_proxy_serve.dag — no code change. Already gated: NbdProxyServeTransportIntent/ShellProgram authority, on-carrier nbd_proxy_serve_bash_emit_dissolution_trigger (names Background/Trap/Pipeline/quoted-arg grammar debt), and medium_structure_exception_roster row. Future shell forms must extend that same trigger, not accrete new opaque Lit shapes.

  2. Placeholder scaffolds without dissolve-on markers — valid minor cleanup; fixed. Added srv3_nbd_proxy_iso_path_dissolution_trigger and srv3_nbd_proxy_export_dissolution_trigger beside the placeholder data rows; witness nbd_proxy_placeholder_scaffolds_carry_dissolve_on_markers added.

— sent from zesty-bat-24

@briansrls
briansrls merged commit 4b55556 into main Jul 1, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/zesty-bat-24 branch July 1, 2026 19:33
briansrls added a commit that referenced this pull request Jul 1, 2026
…d_proxy_serve anchor (#6112)

* Fix main-red: de-fork extdeps.shell + loud module-collision wall + nbd_proxy_serve anchor

Three roots, one tree verdict:

1. src/v2/extdeps/shell.dag was a subset fork (Env+Exec only, fail-open
   inline mock_response) of the dsl authority dsl/extdeps/shell/shell.dag
   (Find/Env/Which/Exec, deliberately hermetic-fail-closed). Under dsl-first
   witness_layer_roots the module index silently last-insert-won to the v2
   fork, so dsl/extdeps/tools/tools.dag:56 saw "no field 'Which' on type
   'shell'" — and hermetic runs of dsl gates fabricated "(mock)" output.
   Fix: delete the fork (dsl is the authority, plan Q4 in
   docs/plans/shell-emission-model.dag answered by consolidation).

2. build_module_index / build_module_path_index were HashMap last-insert-wins:
   a duplicate module path across roots silently shadowed (DESIGN §3/§5).
   Now both refuse loudly with the colliding paths named. The overlay spec
   test (co_root_overlay_last_root_wins_on_duplicate_module_path) is replaced
   by extdeps_shell_resolves_to_the_dsl_authority + a temp-dir RED/GREEN
   control (duplicate_module_path_across_roots_refuses_loudly). Corpus-wide
   scan: exactly one collision existed; the wall makes the class unwritable.

3. extdeps.bmc.webui.nbd_proxy_serve (#6097) imported its sibling's
   extdeps_external_authority_anchor instead of declaring its own row —
   the external-authority gate correctly refused the alias. It now carries
   its own cited anchor (same upstream, github.com/openbmc/jsnbd); the
   dead re-binding alias is removed.

Also heals the pre-existing .gitignore drift (stale /provisioning/srv3/
dnsmasq.conf row, #6097) so the drift gate is green on this branch.

Verified by execution: failing discovery repro passes under BOTH root
orders; corpus_live_clean_tree_holds PASS; drift gate PASS;
shell_mock_totality PASS; nbd_proxy_serve witnesses PASS; unit tests
(collision RED control + dsl-authority resolution) PASS; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review: synthesize the strict-mode cross-root RED fixture (live collision is gone)

cursor/composer-2.5 on #6112: strict_dependency_pool_index_panics_on_
cross_root_extdeps_shell_collision used the live-tree extdeps.shell
collision as its fixture — this PR deletes that collision, flipping the
assertion. Replaced with a synthetic two-temp-root duplicate: strict
refuses with "duplicate module path" (RED control), primary-precedence
indexes first-root-wins on the same fixture (GREEN control). The RED
control no longer depends on a defect persisting in the real corpus.

All 4 dependency_pool_index tests pass against release gunbc, including
the two live-tree primary-precedence compiles.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix CI: cargo target/ output is not source — exclude it from module-index walks

The collision wall caught a real fail-open in CI: tests that pass the
whole workspace as a source root (e.g. interp_recorded_fixture_test)
were walking target/func_env_semantic_baseline_corpus/dsl/** — a corpus
copy another test materializes under cargo's build-output dir — so every
module there was indexed TWICE (source + stale copy), previously
resolving order-dependently by silent last-insert-wins, now refused
loudly by the wall.

Root fix: both walkers (collect_dag_files, collect_dag_files_tolerant)
skip a `target` dir that sits beside a Cargo.toml — cargo's own
definition of build output. A source root passed FROM inside target/ is
still walked; only descent into the output dir is refused.

Verified by execution: reproduced the CI failure locally by
materializing the corpus copy, then green post-fix
(clock_now_record_then_hermetic_replay_holds PASS with the copy
present); new unit test cargo_target_dir_output_never_enters_the_
module_index (exclusion GREEN + non-cargo layout still refuses RED);
16/16 module_path_index tests; 4/4 dependency_pool_index tests; fmt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant