Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/live-deploy-srv1-apply.sh

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion DESIGN.md

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,7 @@ Receipts + adjacent levers: [fractal Gantt](docs/plans/ci-floor-fractal-gantt.md
- [x] **slice 0 — CI EAGAIN-retry** ✓ (#6467) — `ci_cargo_eagain_retry_core` → `emit(Retry, Bash)`; byte-oracle = committed `ci.yml` [plan](docs/plans/shell-emission-model.md) — ✓ signed off: operator
- [x] **slice 1 — control-flow emit (census-scoped)** ✓ (#6475; tier-2 Procedure/Let band #6566) — the `If` band only (`orch_emit_step::If` + else + condition forms + pipes/cmdsubst/`$?`/AndOr/redirect/env words, byte goldens); `For`/`While` NOT in scope — the pre-runtime census (2026-07-03) found zero pre-runtime sites needing them [plan](docs/plans/shell-emission-model.md) — ✓ signed off: operator
- [ ] **slice 2 — converge thin-run** *(IN FLIGHT 2026-07-14 — FLAGs 2a(i)/2b/2c operator-signed, keystone worker dispatched; [census](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) §2)* — fleet_converge steady-state moves into the binary as a typed plan via `apply()` (models `EmitArtifactThenThinRun`); emitted bash shrinks to the fresh-standup/self-repair bootstrap fragment + a thin invocation line (supersedes 'emit the whole `.github/fleet-converge.sh`') [plan](docs/plans/shell-emission-model.md)
- [ ] **shell→intent Phase 1 — agnostic orchestration emit** — MERGED (#6832), operator sign-off PENDING — `While`/`BoundedPoll`/general `Retry` (N-level escalation) emit via `05_emit_orchestration` + bash grammar rows; byte goldens `orchestration_*_emit_test`; production consumer `ci_floor_peak_emit.dag`. Flip to `done: true` + `sign(operator)` on sign-off (mirrors `6-shell-slice2`). [plan](docs/plans/shell-intent-emit-realization-design.md)
- [ ] **`apply()` Phases B–F** — B `host_exec`→`apply()` (gated on srv3 OsInstalled) · C Redfish live (partially via #6097) · D converge lane = EmitArtifactThenThinRun handler (first ctrl LOC deleted) · E pull-mode self-converge (autoinstall plants the on-host agent; the push star retires) · F decom. Phase A landed (#5756). [plan](docs/plans/host-effect-orchestration.md)
- [ ] **temporal-effect-spine-a — temporal realization spine (T1 vocabulary)** *(operator 2026-07-02; not a workflow engine)* — `std.temporal_effect`: durable facts + `plan_next_step_from_prior_receipt_and_lease` (single prior+lease; list fold is consumer-side); 🟡 markers on stringly receipt labels + derived step id. RED: approval/lease/read-back gates. **Non-goals:** live mutation, DB, scheduler. **Accept (T1):** witness suite green.
- [ ] **srv3-install-reconcile-a — dry-run reconcile entrypoint** *(queued; gated on temporal-effect-spine-a + os-install-deduction-a)* — `InstallAttemptIntent` + workflow steps as data; `srv3_os_install_reconcile` folds preflight + diagnostic + temporal spine; dry-run first. **Accept (T3):** dry-run receipt on srv1 actuator host.
Expand Down
2 changes: 1 addition & 1 deletion dag/gunbc/design_document.dag

Large diffs are not rendered by default.

8 changes: 4 additions & 4 deletions dag/gunbc/plans/shell_emission_model.dag
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ fn shell_emission_model_body() -> List<MarkdownBlock> {
li(text: "**Intent coproduct exists** — `src/v2/std/orchestration.dag`: `Run` / `Step\{Do,If,For,While,Retry\}` / `Pipeline` / `Predicate`."),
li(text: "**Bidirectional bash language exists** — `src/v2/extdeps/languages/bash.dag` (~2201 lines, POSIX-cited)."),
li(text: "**Intent→bash lowering exists but is bespoke** — `src/v2/compiler/05_emit_orchestration.dag` is a per-construct dispatcher, **not** the same `target_model_edge_translation_rules` table that emits Rust/TS (`06_translate.dag` has zero orchestration refs)."),
li(text: "**Control-flow emission — the `If` band has since LANDED (verified 2026-07-16).** The 'all return `outcome_rejected`' text was written 2026-07-03 and is superseded: `05_emit_orchestration.dag:497` lowers `If` via `orch_emit_if_step` **with `else_`**, and every `Predicate` arm lowers (`ExitZero`, `StrEq`, `StrEmpty`, `StrNonempty`, `LogMatches`, `Not`, `And`, `Or`). `Retry` lowers with `on_exhausted` threaded. `For`/`While` still return `outcome_rejected` **by design** — the 2026-07-03 census found every live `For`/`While`/trap/background site is RUNTIME-PRESENT (dissolves to typed folds + argv/Pipeline interpreted by the binary), so only the `If` band is pre-runtime-justified; this is a decision, not a gap. `Run.command:String` remains the **same anemic leaf** as `host_effect.ShellCommand.script` — dissolution target `Do\{effect\}` with typed effect leaves ([host-effect-orchestration](host-effect-orchestration.md) effect-plan band)."),
li(text: "**Control-flow emission — the `If` band has since LANDED (verified 2026-07-16).** The 'all return `outcome_rejected`' text was written 2026-07-03 and is superseded: `05_emit_orchestration.dag:497` lowers `If` via `orch_emit_if_step` **with `else_`**, and every `Predicate` arm lowers (`ExitZero`, `StrEq`, `StrEmpty`, `StrNonempty`, `LogMatches`, `Not`, `And`, `Or`). `Retry` lowers with `on_exhausted` threaded. `For` still returns `outcome_rejected` (census-scoped — RUNTIME-PRESENT `For`/trap/background sites dissolve to typed folds + argv/Pipeline interpreted by the binary). **`While`/`BoundedPoll` lowering has since LANDED (#6832):** the 2026-07-03 'zero pre-runtime `While` sites' finding was superseded when a pre-runtime readiness-poll (`ci_floor_peak_emit`) required it, so `While` is emitter-supported and no longer refuses; this is a decision that was revisited, not a gap. `Run.command:String` remains the **same anemic leaf** as `host_effect.ShellCommand.script` — dissolution target `Do\{effect\}` with typed effect leaves ([host-effect-orchestration](host-effect-orchestration.md) effect-plan band)."),
]),
h2(text: "2. The model (locked)"),
p(text: "**ADOPT:** `intent(std)` → `bash(extdeps)` via `emit(intent, Bash)`, extending the existing dispatcher."),
Expand All @@ -26,7 +26,7 @@ fn shell_emission_model_body() -> List<MarkdownBlock> {
p(text: "Bash is a **normal medium, not a privileged exception** — grammar rows, emit, and (eventually) ingest with explicit `DecodeFidelity`; its lossless fragment is intentionally small, and ambiguous bash **fails closed** with a typed refusal rather than becoming authority. Bash is emitted only where its low-dependency property is essential: **(a) foreign executors** that require shell payloads (GHA `run:` blocks, cron entry lines, autoinstall late-commands, git hook files) and **(b) bootstrap windows** before the gunbc runtime or a typed transport exists on the host. Where the runtime IS present, effects are typed argv invocations (extdeps service ops), typed transports (REST/Redfish), or binary-interpreted effect-plan values (`EmitArtifactThenThinRun`) — never generated scripts."),
p(text: "**Process invocation is not bash-the-language:** a typed argv (program + args → exit/stdout) needs no bash semantics; most `shell.Exec.Run` sites are invocations wearing bash syntax. **Slice scope derives from the pre-runtime census, not from the existing bash inventory.** New non-thin bash surface outside the two sanctioned windows requires a live leak fact, roster entry, dissolve trigger, and sign-off. Thin-run guardrail: the binary must interpret a **typed plan** and emit typed receipts — replacing an opaque bash script with an opaque imperative driver is no progress; the typed plan stays the authority. *(Supersedes the ci-humming T5 framing of the emitted converge shell as the steady-state handler: srv1/srv2 converge arms reclassify to binary-interpreted; only the fresh-standup/self-repair bootstrap arm stays emitted bash.)*"),
p(text: "→ **Typed authority (sign-ready draft):** [provisioning-window-executor-capability-design.md](provisioning-window-executor-capability-design.md) — formalizes the two sanctioned windows as `ExecutorCapability` + `ProvisioningWindow` with an `authorize_shell_emission` predicate, census row table, and lens sequencing (M0–M3)."),
p(text: "**Pre-runtime census receipt (2026-07-03):** PRE-RUNTIME = GHA `run:` bodies (slice-0 retry, the 8 `ci_workflow` RunSteps, bmc smoke), cron entry lines, the fleet-converge fresh-standup arm, a pre-push thin shim, future autoinstall late-commands (today: zero shell — pure cloud-config YAML). RUNTIME-PRESENT = the entire srv3 install tail (executes on srv1 via `shell.Exec.Run` from inside `gunbc run`), live_deploy (srv1 LocalShell), the `dag/tools` witness transports (invoked from `claim_executor`), fleet-converge srv1/srv2 arms. Derived pre-runtime construct scope: Run sequencing · If-with-else (exit-status / negated-pipeline / `[ ]` tests) · pipes · cmdsubst assignment · `$?`/exit propagation · AndOr · redirects incl. `>>` · env-scoped invocation · `set` framing · Retry (landed) · one `TargetArchitecture` dispatch replacing `case uname`. NOT justified at any pre-runtime site: `For`, `While`, trap, background `&`, functions, arrays, arithmetic, process substitution."),
p(text: "**Pre-runtime census receipt (2026-07-03):** PRE-RUNTIME = GHA `run:` bodies (slice-0 retry, the 8 `ci_workflow` RunSteps, bmc smoke), cron entry lines, the fleet-converge fresh-standup arm, a pre-push thin shim, future autoinstall late-commands (today: zero shell — pure cloud-config YAML). RUNTIME-PRESENT = the entire srv3 install tail (executes on srv1 via `shell.Exec.Run` from inside `gunbc run`), live_deploy (srv1 LocalShell), the `dag/tools` witness transports (invoked from `claim_executor`), fleet-converge srv1/srv2 arms. Derived pre-runtime construct scope: Run sequencing · If-with-else (exit-status / negated-pipeline / `[ ]` tests) · pipes · cmdsubst assignment · `$?`/exit propagation · AndOr · redirects incl. `>>` · env-scoped invocation · `set` framing · Retry (landed) · one `TargetArchitecture` dispatch replacing `case uname`. NOT justified at any pre-runtime site (2026-07-03 census — superseded for `While` by #6832, which landed `While`/`BoundedPoll` emit for the `ci_floor_peak_emit` readiness-poll): `For`, trap, background `&`, functions, arrays, arithmetic, process substitution."),
CodeBlock { code: "std/orchestration (intent) → 05_emit_orchestration (dispatcher)\n → v2.extdeps.languages.bash (rows)\n → shell text\n" },
h2(text: "3. Effects are first-class (load-bearing)"),
p(text: "**host_effect Phase B:** the `ShellCommand\{script:String\}` payload dissolves onto **modeled orchestration intent** (a `Pipeline`), **NOT** onto the doomed `program.dag`+`serialize_bash` sidecar. The existing [host-effect-orchestration.md](host-effect-orchestration.md) Phase-B text pointing at `program.dag` **predates** `emit(intent,Bash)` and is **superseded** by this plan."),
Expand All @@ -39,13 +39,13 @@ fn shell_emission_model_body() -> List<MarkdownBlock> {
h2(text: "5. Slice sequence (each gated by a frozen committed byte oracle)"),
ol(items: [
li(text: "**Slice 0 — CI EAGAIN-retry cutover — LANDED (#6467, verified 2026-07-16).** `dag/gunbc/ci_spec.dag` `ci_cargo_eagain_retry_intent` (:222) is a real `Retry \{ body: Pipeline\{steps:[Do\{run\}], on_failure: FailFast\}, escalations, on_exhausted \}` and `ci_cargo_eagain_retry_core` (:235) routes it through `orch_emit_step(medium: bash_orchestration_emit_medium())`, matching Accepted/Rejected. Refusal carries `ci_retry_emit_refused_poison` — a deliberately-invalid marker so a rejected emission reds BOTH the committed `ci.yml` drift gate and the yaml parse gate rather than letting a hand-spelled fallback mask it (§5 refuse-never-widen). Env lowering is structured since #5868+#6137 (`EnvUnset` + multi-binding `EnvPrefixed`; the `orch_emit_run_env_welded` weld is dissolved). **Precondition RESOLVED:** `Retry.on_exhausted` is no longer emitter-ignored — `05_emit_orchestration.dag:503` threads it to `orch_emit_retry`, bound at :627 via `orch_emit_pipeline(p: on_exhausted)`. The residual `concat` at :250 is a two-part `\"set -o pipefail\\n\"` prefix, not a nested-concat blob."),
li(text: "**Slice 1 — control-flow emission (census-scoped) — LANDED (#6475; tier-2 Procedure/Let band #6566; operator-signed in `roadmap_authority.dag` `6-shell-slice1`).** The `If` band only — `orch_emit_step::If` arm with else (`05_emit_orchestration.dag:497` → `orch_emit_if_step`), the condition forms, plus pipes / cmdsubst assignment / `$?` propagation / AndOr / redirects incl. `>>` / env framing word support, each with byte goldens. Every `Predicate` arm lowers (`ExitZero`, `StrEq`, `StrEmpty`, `StrNonempty`, `LogMatches`, `Not`, `And`, `Or`). `For`/`While` emission is **NOT in scope**: the pre-runtime census found zero pre-runtime sites needing them (the mirror-retry `for` loop maps to the typed Retry/escalation model interpreted by the binary) — they refuse **by design**, which is a decision, not a gap. While `While` stays emitter-unsupported the model must say so — no inert `While.bound` carried as if meaningful (the inert field is dissolved by #6718)."),
li(text: "**Slice 1 — control-flow emission (census-scoped) — LANDED (#6475; tier-2 Procedure/Let band #6566; operator-signed in `roadmap_authority.dag` `6-shell-slice1`).** The `If` band only — `orch_emit_step::If` arm with else (`05_emit_orchestration.dag:497` → `orch_emit_if_step`), the condition forms, plus pipes / cmdsubst assignment / `$?` propagation / AndOr / redirects incl. `>>` / env framing word support, each with byte goldens. Every `Predicate` arm lowers (`ExitZero`, `StrEq`, `StrEmpty`, `StrNonempty`, `LogMatches`, `Not`, `And`, `Or`). `For` emission is **NOT in scope** (census-scoped): the mirror-retry `for` loop maps to the typed Retry/escalation model interpreted by the binary — it refuses **by design**, a decision, not a gap. **`While` emission has since LANDED (#6832):** the 2026-07-03 'zero pre-runtime `While` sites' finding was superseded by the `ci_floor_peak_emit` readiness-poll, so `While`/`BoundedPoll` now lower via `05_emit_orchestration` with byte goldens (`orchestration_while_emit_test`) and `While` is no longer emitter-unsupported (the earlier inert `While.bound` field was dissolved by #6718; #6832 gave `While` a real bound-carrying emit)."),
li(text: "**Slice 2 — converge thin-run — WORK OBSERVABLY COMPLETE; operator sign-off PENDING (receipts read 2026-07-16).** Tree receipts: `.github/fleet-converge.sh` is now **21 lines** — `gunbc converge --host srv1|srv2|srv3` (ConvergePlan interpreted in-process) plus the fresh-standup bootstrap fragment, the one arm the bash-minimization rule sanctions as pre-runtime; `fleet_converge_emit.dag` has **zero** bash fn defs and emits one artifact (`expected_fleet_converge_sh`); `EmitArtifactThenThinRun` is a live `transport:` arm on `gunbc.host_effect` (`dag/test/claim/fleet_converge_apply_witness_test.dag`), no longer prose-only. The 4 for-loops / while-read drain / verdict arithmetic / 12 functions are gone. **This doc does NOT declare the slice done.** `roadmap_authority.dag` `6-shell-slice2` is the status authority and still reads `done: false` (*IN FLIGHT 2026-07-14 — FLAGs 2a(i)/2b/2c*); flipping it requires an `operator` `signed(...)` attestation, which only the operator can give — every `done: true` row in that carrier is operator-signed. The FLAGs are not resolvable from tree receipts alone. **Operator: if the FLAGs are discharged, sign `6-shell-slice2` and this row becomes LANDED.** The `~275 lines / 12+ fn defs` row in [the residual census](shell-to-dag-residual-census-and-arc-completion.md) is likewise stale against the current emitter."),
li(text: "**Slice 3 — live_deploy:** RUNTIME-PRESENT (runs on srv1 over LocalShell with gunbc as the invoker) → thin-run/typed-effect candidate, **not** a golden to freeze-and-emit: heredoc file bodies become typed `Filesystem.Write` effects with foreign-media payloads as data; apt/systemctl/tailscale become typed argv invocations. Its self-referential drift gate (compares the emit fn to itself) stays named as the #6023-class trap until the reshape."),
li(text: "**Slice 4 — tail consumers (pre-runtime residue):** `bmc_token_federation` (two `Do\{Run\}` rows — slice-0 machinery suffices) → `ci_workflow` inline `RunStep`s (case/`uname` → model as `TargetArchitecture`; cross-link ROADMAP §1 `1-inline-shell-defork`) → githooks as a **thin shim** (ensure-built + exec `claim_batch --pre-push` with stdin passed through; the case-rosters/arrays/while-read stdin parse move into the binary)."),
]),
h2(text: "6. Sidecar dissolution (parallel)"),
p(text: "**LANDED (#6831, Phase 0):** `dag/extdeps/languages/bash/program.dag` (`ShellProgram`/`serialize_bash`) deleted; the vacuous bash-program importer-count ratchet is pruned with it (resolve fails before the ratchet could fire). Remaining arc work is intent-layer shell→`emit(intent, Bash)` migration (Categories A–C in [shell-intent-emit-realization-design.md](shell-intent-emit-realization-design.md)), not sidecar restoration."),
p(text: "**LANDED (#6831, Phase 0):** `dag/extdeps/languages/bash/program.dag` (`ShellProgram`/`serialize_bash`) deleted; the vacuous bash-program importer-count ratchet is pruned with it (resolve fails before the ratchet could fire). Remaining arc work is intent-layer shell→`emit(intent, Bash)` migration (Categories A–C in [shell-intent-emit-realization-design.md](shell-intent-emit-realization-design.md)), not sidecar restoration. **Phase 1 LANDED (#6832):** `While`/`BoundedPoll`/general `Retry` emit — see `roadmap_authority.dag` `6-shell-intent-phase1`."),
p(text: "Tracked in [emission-ingestion-inverse.md](emission-ingestion-inverse.md) / `emission_ingestion_inverse.dag` — **cross-link only, do not duplicate** the roster here."),
h2(text: "7. Named residue / dissolution triggers"),
ul(items: [
Expand Down
Loading
Loading