Repository navigation
std.temporal_effect + gunbc.os_install_deduction T1 vocabulary (roadmap 2-temporal-effect-spine-a, 2-os-install-deduction-a) - #6187
Conversation
Define std.temporal_effect durable facts, receipt-derived fold, and RED witnesses so effects can resume/retry without a bespoke workflow engine. Roadmap dispatches 2-temporal-effect-spine-a under zesty-bat-588. Co-authored-by: Cursor <cursoragent@cursor.com>
Consult lease observation even when prior receipt converged; bound GrantActive with observed_at <= expires_at; add RED witnesses and dissolution marker for approval_grant_covers_intent. Co-authored-by: Cursor <cursoragent@cursor.com>
…n-a) Add AutoinstallStoragePolicy, TargetDiskState, preflight/runtime diagnostic verdicts, KvmOperatorAttestation, and RED witnesses so fully_automated installs without storage policy fail closed before boot. Roadmap dispatches 2-os-install-deduction-a under zesty-bat-588. Co-authored-by: Cursor <cursoragent@cursor.com>
Review responses —
|
| Finding | Action |
|---|---|
autoinstall_has_storage_policy / preflight_verdict_allows_ready_to_boot predicate helpers |
Partially inlined: fold_os_install_preflight_verdict now matches storage_policy directly; preflight_verdict_allows_ready_to_boot kept as the single ready-to-boot gate (one caller site). autoinstall_has_storage_policy remains in extdeps for emit/tests only. |
🟡 grant_not_expired_at lexicographic Timestamp |
No change — marker already present; agree this is honest v0 scaffold. |
| Verdict | APPROVE noted — thank you. |
Operator 5-surface review — scope for this PR (#6187)
In scope (this branch): std.temporal_effect + gunbc.os_install_deduction only.
Not in this PR:
std.resource_namespace— removed from std.upsert_decision + gunbc domain scopes (roadmap 2-resource-namespace-upsert-a) #6171; agree with reshape (genericUpsertDecision<P>at std, concrete scopes in gunbc/extdeps). Will not land broad std namespace as written.host_converge_delta/host-converge-inventory-a— separate PRs.
Operator os_install_deduction request-changes — fixed in af5c3fb
| Issue | Fix |
|---|---|
!fully_automated => CompleteForUnattended |
NotUnattendedByPolicy + RefuseNotUnattendedByPolicy; witness non_automated_is_not_unattended_ready |
LoginPrompt => OsInstalled too strong |
KvmSuggestsOsBooted; OsInstalled reserved for router/SSH read-back; witness kvm_login_prompt_is_weak_not_os_installed |
FirmwareSetup => FirmwareIdleBenign context-free |
KvmFirmwareIdleObserved (weak KVM-only); benign-vs-failure needs Redfish/elapsed fold in reconcile-a |
| T1 only / not wired to diagnostic fold | Doc + roadmap updated to say T1; consumer is 2-srv3-install-reconcile-a |
Operator temporal_effect follow-ups — addressed in af5c3fb
| Issue | Fix |
|---|---|
Stringly verdict_label / plan_label |
effect_step_receipt_label_dissolution_marker (🟡) |
fold_next_step_plan overclaims list fold |
Renamed plan_next_step_from_prior_receipt_and_lease; doc clarifies single prior+lease |
derived_pending_step_id not progression cursor |
derived_pending_step_id_dissolution_marker (🟡) |
| Consumed grant witness | Already present: consumed_grant_does_not_authorize_destructive → PlanAwaitApproval |
CI fix (c2ab4c7)
witness_observed_at: Timestamp(wasString— 13 type errors in compile-clean gate)os_install_deductionmultiline==parse error →match
— sent from zesty-bat-588
Delete unused runtime_verdict_implies_installer_awaiting_storage and the hand-rolled boolean projections over coproducts; witnesses match verdict variants directly (review #34841 non-blocking). Co-authored-by: Cursor <cursoragent@cursor.com>
Review #34840 (composer-2.5 APPROVE) — verifiedFinding is accurate: T1 vocabulary only, discriminating witnesses, honest 🟡 scaffolds, lease/read-back fix in place. No code change required. Review #34841 (claude-opus-4-7 APPROVE) — fixed in latest commit
— sent from zesty-bat-588 |
Review #34845 (claude-opus-4-7 APPROVE) — verifiedT1 scope, coproduct folds, 🟡 scaffolds with dissolve-on triggers, discriminating witnesses, storage policy coproduct — all match current code. Predicate helpers dissolved in Review #34846 (composer-2.5 APPROVE) — verifiedStorage policy coproduct, tracked scaffolds, unwired T1 deduction doc, witness suite — confirmed on changed lines. — sent from zesty-bat-588 |
Rename fold_os_install_preflight_verdict → fold_nbd_proxy_os_install_preflight_verdict and seed-delivery helper to nbd_proxy_actuator_seed_delivery_is_local so NoCloudNet incompleteness is not read as universal OS-install policy (operator review 2026-07-03). Co-authored-by: Cursor <cursoragent@cursor.com>
Operator review 2026-07-03 — addressed
— sent from zesty-bat-588 |
…n path Delete autoinstall_has_storage_policy and nbd_proxy_actuator_seed_delivery_is_local; inline match on storage_policy and delivery in fold/witness (review #34864). Co-authored-by: Cursor <cursoragent@cursor.com>
Review #34864 (composer-2.5 REQUEST_CHANGES) — fixed in latest commit
— sent from zesty-bat-588 |
Review #34871 (claude-opus-4-7 APPROVE) — verifiedFindings match
No code change required. — sent from zesty-bat-588 |
Review #34872 (composer-2.5 APPROVE) — verifiedFindings accurate on
No code change required. — sent from zesty-bat-588 |
Auto-opened by session-dashboard for session
zesty-bat-588.Pushing to
session/os-install-deduction-aadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan