Skip to content

Wave C5: typed-argv exec at realization edge (deploy probes, #5828 slice) - #6946

Merged
briansrls merged 5 commits into
mainfrom
session/keen-deer-531-wave-c5
Jul 22, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/keen-deer-531-wave-c5

Conversation

@briansrls

@briansrls briansrls commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Stage 1 of Wave C5 (#5828 slice): deploy-preflight probe effects realize through typed argv dispatch at the realization edge — one argv shape per op, N transport handlers, no concat-shell.

Affected-set note: d9e2e92 repro — import-line edit on a freshly-landed shape-only file (nopasswd_execute_probe.dag) triggers diff before first declaration fail-close; workaround is shape-in-original + *_read_op.dag / *_check_op.dag transport siblings (main-identical shapes, zero diff). Connects to module-identity / affected-set open thread; not forced.

Wave B foundation (merged #6926)

  • deploy-preflight becomes an authorization query + typed EffectPlan<HostEffect> with ReadEffectivePosixPrincipal / SudoNopasswdExecuteProbe host effects
  • live observation moves to gunbc.ci_deploy_access_observe; ci_deploy_access drops extdeps.shell.exec import
  • host_effect_deploy_access_probe_script.dag deleted

Wave C5 realization-edge cleanup (this slice)

  • extdeps authorities (shape in original modules; transport in sibling *_op.dag files):
    • access.PosixEffectivePrincipal.Read → ["whoami"] (posix_effective_principal_read_op.dag)
    • sudo.NopasswdExecuteProbe.Check → ["sudo", "-n", <path>, <check>] (nopasswd_execute_probe_check_op.dag)
  • LocalShell: dispatches typed extdeps service ops directly (no shell.Exec.Run)
  • SshShell: dispatches the same argv via gunbc.typed_argv_exec_over_ssh → ssh.Session.ExecArgv (ssh host -- argv...), never ssh_session_exec(host, command: concat(...))
  • Fail-closed portable-argv allowlist ([A-Za-z0-9._\-/]) before SSH spawn — discriminating RED witnesses in typed_argv_exec_realization_witness_test.dag
  • Resolved cells: EffectivePrincipalReadOnHost / SudoNopasswdProbeOnHost (replacing ShellOnHost{script} for probes)
  • CI prelude split: ci_artifact_consumer_prelude_steps() (checkout only) for ci/deploy jobs consuming prebuilt release-bins; full ci_prelude_steps() retained on build only

HAND-RUST receipt (62597e0f8b)

Unified-diff +++ /dev/null deletion hunks no longer leak onto the prior file's @@ ranges — when a modified .dag file immediately precedes a deleted file in the merge-base diff (this PR: ci_workflow.dag → host_effect_deploy_access_probe_script.dag), the departed file's @@ -1,N +0,0 @@ hunk was falsely attributed to the modifier's line 1, tripping diff before first declaration fail-closed. Fix: current_file_from_unified_diff_header binds deletion hunks to the --- a/ path. Regression: cargo test -p v1-compiler --lib deletion_hunk_after_modified_file_does_not_false_fire_module_line.

Design surface (for review)

Intent (HostEffect)          extdeps argv authority              LocalShell              SshShell
─────────────────────────────────────────────────────────────────────────────────────────────────
ReadEffectivePosixPrincipal  posix_effective_principal_read_argv  PosixEffectivePrincipal  typed_argv_exec_over_ssh
SudoNopasswdExecuteProbe     sudo_nopasswd_execute_probe_argv     NopasswdExecuteProbe     typed_argv_exec_over_ssh

Out of scope for this PR (staged follow-ons): srv3_host_effect_script concat arms, hostname SetHostnameCas realization.

Test plan

  • claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/typed_argv_exec_realization_witness_test.dag --function typed_argv_exec_realization_witnesses — PASS (includes metacharacter RED + SSH argv shape)
  • claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/grounded_principal_witness_test.dag --function grounded_principal_witnesses — PASS
  • claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag (all 6 fns) — PASS
  • cargo test -p v1-compiler --lib deletion_hunk_after_modified_file_does_not_false_fire_module_line — PASS (HAND-RUST: deletion hunks no longer leak onto prior file in unified-diff attribution)
  • CI floor green on current HEAD

@gunbai-bot gunbai-bot Bot changed the title Wave C5 (shell->dag, PRIORITIZED cleanup): typed-argv exec realization — the bash-emit #5828 slice. Implement typed argv dispatch at the realization edge so pure-argv effects (whoami, sudo -n cmd argv, srv3 argv cases) execute WITHOUT rendering a shell string through shell.Exec.Run, and land the Emi Wave C5: typed-argv exec at realization edge (deploy probes, #5828 slice) Jul 20, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 20, 2026 19:23
@gunbai-bot
gunbai-bot Bot marked this pull request as draft July 20, 2026 19:29
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 21, 2026 12:36
@cursor

cursor Bot commented Jul 21, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

review 40720 (APPROVE) — verified on 5932f9b

Confirmed against current tree:

  • host_effect_deploy_access_probe_script.dag deleted; realization uses access.PosixEffectivePrincipal.Read / sudo.NopasswdExecuteProbe.Check on LocalShell and gunbc.typed_argv_exec_over_ssh → ssh.Session.ExecArgv on SshShell (same argv authority, no concat-shell).
  • EffectivePrincipalReadOnHost / SudoNopasswdProbeOnHost wired through resolve, host_effect_apply, host_effect_apply_gated, and drive directive match.
  • ssh.Session.ExecArgv mock corpus row + diagnostic mock-totality arm present.
  • Metacharacter refusal is fail-closed (TypedArgvExecRefused); witness suite exercises ;, |, $ RED controls (+ backtick added in follow-up commit).

No code changes required for this approval.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

review 40723 (REQUEST_CHANGES) — addressed in cfd59e72

Added witness_ssh_argv_metacharacter_backtick_red_holds to close the gap between typed_argv_shell_metacharacter_in_token (which refuses backtick) and the witness suite (which previously only RED-tested ;, |, $). Witness passes locally via claim_batch.

If review 40723 flagged a different item, please re-run on cfd59e72 — artifact not visible from worker session.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40723 — addressed in 3a1624bf51

Valid finding. Both shape-module note strings still cited the deleted gunbc.host_effect_deploy_access_probe_script scaffold.

Updated:

  • posix_effective_principal_read_note → extdeps.access.posix_effective_principal_read_op
  • sudo_nopasswd_execute_probe_note → extdeps.sudo.nopasswd_execute_probe_check_op

Edits are in-place string updates on existing data rows (no import/pre-decl churn); typed_argv_exec_realization_witnesses green locally.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40729 — addressed in 0d779093

Both findings accepted.

1. Metachar denylist → portable allowlist (construction, not validation)

Valid: ssh host -- argv... is shell-reinterpreted remotely, so a partial denylist was silently green on &, redirects, quotes, globs, whitespace-in-token, etc.

Fix: typed_argv_shell_safe_refusal_argv now refuses any token whose characters fall outside [A-Za-z0-9._-/] (POSIX portable filename + / for absolute paths). Known deploy-probe argv (whoami, sudo, -n, /usr/bin/apt-get, --help) still pass. Added RED witnesses for &, >, and embedded whitespace; retained the prior `;|$`` cases under the new gate.

2. §3 alias wrappers deleted

posix_effective_principal_read_argv_for_ssh / sudo_nopasswd_execute_probe_argv_for_ssh were pure re-exports with no non-test consumers — removed; witness imports the extdeps argv builders directly.

typed_argv_exec_realization_witnesses green locally.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40734 (APPROVE) — verified on e8e7c224

No code changes required. Confirmed against current tree on post-main-merge HEAD:

  • host_effect_deploy_access_probe_script.dag deleted; probes route through extdeps service ops (LocalShell) and typed_argv_exec_over_ssh → ssh.Session.ExecArgv (SshShell).
  • Shape/transport split: interface in posix_effective_principal.dag / nopasswd_execute_probe.dag; argv transport in *_read_op.dag / *_check_op.dag with cited extdeps_external_authority_anchor rows.
  • Fail-closed portable allowlist [A-Za-z0-9._-/] before SSH spawn; RED witnesses cover ;|$\``&>` and whitespace-in-token.
  • Alias wrappers removed; witnesses import extdeps argv builders directly.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40740 (APPROVE) — verified on e8e7c224

No code changes required. Confirmed against current tree:

  • host_effect_deploy_access_probe_script deleted; probes realize via access.PosixEffectivePrincipal.Read / sudo.NopasswdExecuteProbe.Check (LocalShell) and typed_argv_exec_over_ssh → ssh.Session.ExecArgv (SshShell).
  • §3 shape/transport split intact (*_argv() in extdeps _op modules; dispatch in host_effect_realize).
  • Portable allowlist [A-Za-z0-9._-/] refuses before ssh spawn with typed TypedArgvExecRefused; witness REDs cover ;|$\``&>` and whitespace-in-token plus LocalShell/SshShell parity.

Agree the omitted : , = @ chars are conservative fail-closed for this PR's argv corpus (whoami, sudo -n <path> <check>); widening is out of scope here.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40746 (APPROVE) — verified on e8e7c224

No code changes required. Confirmed: scaffold deleted, shape/transport split in _op extdeps modules, LocalShell service-op dispatch + SshShell typed_argv_exec_over_ssh, portable-argv allowlist with discriminating RED witnesses, no hand-Rust/shell expansion in the diff.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

CI failure on e8e7c224 — investigated

Root cause: fleet OOM kill (exit 137), not a Wave C5 witness/gate failure.

Evidence from run 29833962890:

  • typed_argv_exec_realization_witnesses ✓ (batch 2)
  • batch 1–3 ✓
  • claim_executor killed at ~37GiB during batch 4 host-effects (Killed → exit 137)
  • main at 137431987f shows the same OOM signature on the current fleet

Pushed empty retrigger commit; no PR-local code defect found.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

CI failure on 157d8e0f — investigated

Not a Wave C5 code failure. Run 29838588314 died in Setup Rust before the floor ran (18s, exit 127):

  • build job ✓
  • ci job: rustup install into _work/_temp failed ($HOME vs euid home mismatch; component rename/remove No such file or directory)
  • gunbc ci / witnesses never started

Infra flake on srv3-07. Pushed retrigger commit.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

CI failure on 6bdfa43 — fixed in af3c7b3924

Root cause: redundant rustup setup in the ci job (exit 127 on srv3-08). The ci job runs prebuilt release-bins from build; a second isolated setup-rust-toolchain on a different runner flakes under _work/_temp pressure.

Fix:

  • ci_artifact_consumer_prelude_steps() — checkout only — for ci and deploy_dashboard_srv1
  • Full ci_prelude_steps() retained on build only
  • .github/workflows/ci.yml regenerated to match

ci_yaml_serializer_keystone_holds green locally; ci_yaml_parse_witness drift check passed before scratch write.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40794 — addressed

Valid finding. typed_argv_shell_safe_refusal_argv matches on TailAbsent at the empty-tail arm but the import omitted it. Added TailAbsent to the v2.std.algebra import in typed_argv_exec.dag. typed_argv_exec_realization_witnesses green locally.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40799 (APPROVE) — verified on 51fb8e7e42

No code changes required. Confirmed: scaffold deleted, shape/transport _op split, typed LocalShell/SshShell dispatch, portable-argv allowlist with RED witnesses, artifact-consumer CI prelude fix, and TailAbsent import (review 40794) all present on current HEAD.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40800 (APPROVE) — verified on 51fb8e7e42

No code changes. Confirmed on HEAD: ssh.Session.ExecArgv with -- splice, typed_argv_exec_over_ssh portable-argv allowlist, reconcile_shell_exec_observed reconcile funnel, typed EmitArtifactThenThinRun refusals, and updated dispatch tables for the new ResolvedHostEffectCell variants.

Re the non-blocking note on SudoNopasswdExecuteProbeShape.check_argv: NonEmptyStr: agreed — it names a single probe token, not an argv list, and the allowlist already refuses whitespace-bearing values. Pre-existing shape debt on base; left out of this slice intentionally.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

CI failure on 51fb8e7 — fixed in 62597e0f8b

Root cause: affected-set diff attribution bug. When dag/gunbc/ci_workflow.dag (modified) appears immediately before dag/gunbc/host_effect_deploy_access_probe_script.dag (deleted) in the merge-base diff, +++ /dev/null did not retarget the current file — the departed file's @@ -1,N +0,0 @@ hunk leaked onto ci_workflow.dag line 1, tripping diff before first declaration fail-closed.

Fix: teach parse_unified_diff_line_ranges / parse_unified_diff_changed_new_lines to bind deletion hunks to the --- a/ path (same signal parse_unified_diff_departed_paths already uses). Regression test: deletion_hunk_after_modified_file_does_not_false_fire_module_line.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40841 (REQUEST_CHANGES) — addressed on current HEAD

Valid process gate. Added a HAND-RUST receipt section to the PR body (62597e0f8b) and a checked test-plan row:

Unified-diff +++ /dev/null deletion hunks no longer leak onto the prior file's @@ ranges — regression test deletion_hunk_after_modified_file_does_not_false_fire_module_line.

No further code changes; the fix was already landed in 62597e0f8b (triggered by deleting host_effect_deploy_access_probe_script.dag immediately after ci_workflow.dag in the merge-base diff).

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40853 (APPROVE) — verified on 598fcc890f

No code changes. Confirmed on HEAD: typed-argv realization slice, scaffold deleted, portable-argv allowlist + typed refusals, HAND-RUST receipt + deletion_hunk_after_modified_file_does_not_false_fire_module_line regression test, and main sync with OOM fix #7002.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40855 (APPROVE) — verified on 598fcc890f

No code changes. Confirmed on HEAD: portable-argv allowlist fail-closed wall, discriminating RED witnesses, shape/transport split, current_file_from_unified_diff_header regression test, scaffold deletion, and CI artifact-consumer prelude split with exempt-roster rationale.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

CI failure on 598fcc8 — fixed in 88fde6cdc2

Root cause: checkout-only ci prelude removed cargo/rustfmt from PATH. Batch 4 failed (emit_host_gate_passes: env: cargo: No such file or directory; self_host_realized_comparison: missing rustfmt).

Fix: ci_floor_gate_toolchain_step() — non-isolated setup-rust-toolchain (rustfmt) on the ci job only via ci_floor_job_prelude_steps(). Deploy stays checkout-only. Keeps isolated rustup on build only (srv3-07/08 flake avoidance).

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40899 (APPROVE) — verified on 88fde6cdc2

No code changes this slice. Confirmed the duplicate-argv observation: posix_effective_principal_read_argv() / transport shell { argv: ["whoami"] } and the sudo _argv() fn / transport shell template are parallel literals today (SSH path reads the fn; LocalShell reads the service transport row). Agreed §3 tidy-up — bounded, non-blocking. Dissolve when the service-op DSL grows an argv-from-fn projection; then transport references the fn and the literal retires.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40900 (APPROVE) — verified on 88fde6cdc2

No code changes. Confirmed on HEAD: Wave C5 typed-argv slice, scaffold deletion, allowlist + witnesses, CI prelude split (build isolated rustup / ci floor-gate toolchain), and cli_run.rs deletion-hunk fix all present.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40944 (APPROVE) — verified on 2b3ca1a358

No code changes. Confirmed on HEAD: Wave C5 typed-argv slice, scaffold deletion, portable-argv allowlist + RED witnesses, CI prelude split, and HAND-RUST cli_run.rs deletion-hunk fix with regression test — all present.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 40946 (APPROVE) — verified on 2b3ca1a358

No code changes. Confirmed on HEAD: portable-argv allowlist fail-closed contract, shape-attached _op siblings with cited authorities, ssh_session_exec_result_from_service dedupe, typed EmitArtifactThenThinRun refusals, and CI prelude split documented in ci_cost_floor_exempt_step_names_note.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 41041 (APPROVE) — verified on 986b059c50

No code changes. Confirmed on HEAD: typed-argv transport ops, scaffold removal, allowlist + RED witnesses, and CI prelude split (build isolated rustup / ci floor-gate toolchain / deploy checkout-only).

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 41044 (APPROVE) — verified on 986b059c50

No code changes. Confirmed on HEAD: typed-argv service ops, scaffold deletion, TypedArgvExecRefused fail-closed wall, EmitArtifactThenThinRun typed refusals, cli_run.rs deletion-hunk fix + regression test, and CI prelude split documented in exempt-roster note.

Re the @ in host-position observation: agreed — allowlist refusal on user@host is loud/typed, not fail-open; worth watching on srv deploys but acceptable for this slice.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review 41132 (APPROVE) — verified on 09602a50

No code changes. Confirmed on HEAD: typed-argv _op shape/transport split, realization + allowlist + RED witnesses, scaffold deletion, CI prelude split, and cli_run.rs deletion-hunk regression test.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41195 (APPROVE) — verified on 323504aa

No code changes required. Confirmed against current tree:

  • host_effect_deploy_access_probe_script.dag deleted; realization routes ReadEffectivePosixPrincipal / SudoNopasswdExecuteProbe through posix_effective_principal_read_op + nopasswd_execute_probe_check_op and gunbc.typed_argv_exec (host_effect_realize.dag).
  • Portable-argv allowlist fail-closed at the SSH edge; RED witnesses live in typed_argv_exec_realization_witness_test.dag.
  • CI prelude split modeled in ci_workflow.dag (ci_prelude_steps build-only isolate+pin; ci_floor_job_prelude_steps checkout + non-isolated rustfmt toolchain; ci_artifact_consumer_prelude_steps checkout-only deploy) with matching ci.yml output.
  • Residual concat in ci_deploy_access_emit.dag is scoped under the existing preflight scaffold + dissolution trigger toward bash-emit General orchestration intent to Bash emit fold over grammar rows #5828 (Wave C envelope slice, not realization-edge transport).

Review 41197 (APPROVE) — verified on 323504aa

Second dashboard approval on rebased HEAD; no additional findings.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41204 (APPROVE) — verified on bbf9513

No code changes required. Confirmed against current tree:

  • Deleted scaffold script builders live in ci_deploy_access_emit.dag:47-64 under the 🟡 preflight scaffold + updated dissolve-on (:24); typed-argv realization in host_effect_realize.dag is the dissolution target.
  • ResolvedHostEffectCell dispatch is total for EffectivePrincipalReadOnHost / SudoNopasswdProbeOnHost (:1420-1423, :1576-1579, :1631-1632).
  • cli_run.rs +++ /dev/null deletion-hunk attribution fix (:10602-10617) with discriminating regression test.
  • Allowlist enforced fail-closed before SSH spawn (typed_argv_exec.dag); RED witnesses cover ;, |, $, backtick, &, >, whitespace.
  • check_argv single-token invariant grounded on shape authority (bbf9513 / nopasswd_execute_probe.dag).

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41205 (APPROVE) — verified on bbf9513

No code changes required. Confirmed against current tree:

  • Typed-argv realization via posix_effective_principal_read_op, nopasswd_execute_probe_check_op, and gunbc.typed_argv_exec with fail-closed SSH allowlist + discriminating RED witnesses.
  • host_effect_deploy_access_probe_script.dag retired; GHA emit remains on explicitly scaffolded ci_deploy_access_emit.dag.
  • cli_run.rs deletion-hunk fix has HAND-RUST receipt in PR body + regression test.
  • CI prelude split (ci_artifact_consumer_prelude_steps / ci_floor_job_prelude_steps) matches generated workflow and materialization notes.

— sent from keen-deer-531

@gunbai-bot
gunbai-bot Bot force-pushed the session/keen-deer-531-wave-c5 branch from bbf9513 to 01fec29 Compare July 22, 2026 01:28
@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41215 (APPROVE) — verified on 01fec29e

No code changes required. Confirmed against current tree:

  • Typed-argv service ops (access.PosixEffectivePrincipal.Read, sudo.NopasswdExecuteProbe.Check) with LocalShell / SshShell / EmitArtifactThenThinRun fail-closed arms; scaffold retired, emit concat preserved under 🟡 ci_deploy_access_emit.dag.
  • Portable-argv allowlist + discriminating RED witnesses; cli_run.rs deletion-hunk fix with regression test.
  • Rebase onto main (01fec29e) merged Wave C5 ci_floor_job_prelude_steps with ci: move regen step before floor for early fail-fast #7015 regen-before-floor ordering in ci_workflow.dag.

Non-blocking observation (LocalShell sudo probe): Accepted as-is. realize_sudo_nopasswd_probe_on_host (host_effect_realize.dag:1343-1353) projects sudo.NopasswdExecuteProbe.Check's success-only output into ShellExecObserved with synthesized exit_code and empty stdout/stderr because reconcile_shell_exec_observed branches on observed.success only; failure reasons fall back to the generic header when streams are empty (shell_exec_failure_reason_headered, :359-367). SSH path preserves full SshSessionExecResult via reconcile_ssh_argv_exec_outcome. If a future consumer needs real stderr on LocalShell, the fix is extending the Check op output shape — not shell-string concat.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41216 (APPROVE) — verified on 01fec29e

No code changes required. Confirmed against current tree:

  • Wave C5 slice: deploy-preflight probes realize via typed extdeps ops + gunbc.typed_argv_exec on SSH with fail-closed allowlist witnesses.
  • Remaining GHA emit shell in ci_deploy_access_emit.dag retains 🟡 scaffold + dissolution trigger.
  • cli_run.rs unified-diff deletion-hunk fix documented with HAND-RUST receipt in PR body + regression test.
  • No DESIGN violations on changed lines.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

CI failure on 01fec29e — fixed in 595b944

Root cause: regen_verify_gate_passes failed resolving dag/gunbc/ci_deploy_sudoers.dag:44 — invalid typed lambda row: PosixSudoGrant => in any() (typechecker reads row as Callable, not PosixSudoGrant). Main already uses row =>; restored that form.

— sent from keen-deer-531

@gunbai-bot
gunbai-bot Bot force-pushed the session/keen-deer-531-wave-c5 branch from 595b944 to 6eb76ec Compare July 22, 2026 02:06
@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

CI failure on 6eb76ec — fixed

Root cause: live_deploy_emit_holds golden-match witnesses failed — .github/live-deploy-srv1-{apply,retract}.sh had # deploy-access-bootstrap-preflight (principal + historical roster grants) while ci_deploy_access_emit.dag emits roster grants. Restored golden comment to match emitter output.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41286 (APPROVE) — verified on 658919f

No code changes required. Confirmed against current tree:

  • Typed argv ops (access.PosixEffectivePrincipal.Read, sudo.NopasswdExecuteProbe.Check) + fail-closed portable-argv allowlist at SSH realization edge; host_effect_deploy_access_probe_script.dag deleted, concat preflight re-homed under 🟡 ci_deploy_access_emit.dag.
  • host_effect_apply N-transport split (LocalShell → typed op, SshShell → typed_argv_exec, EmitArtifactThenThinRun → typed refusal) with reconcile_shell_exec_observed + discriminating witness corpus.
  • cli_run.rs deletion-hunk fix with targeted regression test.
  • CI prelude split matches ci_workflow.dag / generated workflow.

CI golden drift (historical roster grants comment) fixed in 658919f after 6eb76ec floor failure.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41287 (APPROVE) — verified on 658919f

No code changes required. Confirmed against current tree:

  • Typed extdeps service ops + gunbc.typed_argv_exec at realization edge with fail-closed SSH argv allowlisting; GHA emit remains scaffolded in ci_deploy_access_emit.dag.
  • host_effect_deploy_access_probe_script.dag deleted; witness corpus + mock-totality wiring updated.
  • CI prelude split (build isolated rustup; ci/deploy artifact consumers) matches generated workflow.
  • cli_run.rs deletion-hunk parser fix with regression test.
  • Golden preflight comment drift fixed in 658919f.

— sent from keen-deer-531

@gunbai-bot
gunbai-bot Bot force-pushed the session/keen-deer-531-wave-c5 branch from 4f66d88 to 87a5348 Compare July 22, 2026 13:23
@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41375 (APPROVE) — verified on 87a534889e

No code changes required. Confirmed against current tree:

  • EffectivePrincipalReadOnHost / SudoNopasswdProbeOnHost resolved cells route runtime realize through posix_effective_principal_read_argv / sudo_nopasswd_execute_probe_argv + typed_argv_exec_over_ssh; host_effect_deploy_access_probe_script.dag is deleted with no remaining references.
  • typed_argv_exec.dag portable-argv allowlist refuses via TypedArgvExecRefused (fail-closed), not a widen.
  • EmitArtifactThenThinRun arms on both new realizers are typed NotConverged refusals.
  • check_argv single-token invariant is explicit in nopasswd_execute_probe.dag note; emit concat and typed-argv agree on fleet roster probe shapes.
  • CI-time preflight in ci_deploy_access_emit.dag still concat-builds shell behind the named #5828 dissolve-on scaffold — expected foreign-executor bootstrap window.
  • cli_run.rs +++ /dev/null deletion-hunk parser fix has discriminating unit test deletion_hunk_after_modified_file_does_not_false_fire_module_line.

Re the minor local-arm note: realize_sudo_nopasswd_probe_on_host maps sudo.NopasswdExecuteProbe.Check’s success bool to exit_code: 0|1 because the extdeps service shape exposes only success today. That is intentional for ShellEffectApplied reconciliation on the LocalShell path; SSH uses the real exit code from ssh_session_exec_argv. Cosmetic gap only — no behavior change needed for this slice.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41377 (APPROVE) — verified on 87a534889e

No code changes required. Confirmed against current tree:

  • Wave C5 scope is narrow: deploy-access probes realize through extdeps _op modules + gunbc.typed_argv_exec with fail-closed SSH allowlist; discriminating witness typed_argv_exec_realization_witness_test.dag is enrolled.
  • Remaining concat-shell emit path is scaffolded in ci_deploy_access_emit.dag with named #5828 dissolution trigger pointing at extdeps typed-argv ops.
  • CI prelude split (build-only isolated rustup vs floor-gate toolchain on ci, checkout-only on deploy) matches the updated materialization note in ci_workflow.dag.
  • cli_run.rs deletion-hunk parser fix is test-backed and scoped to the diff-shape regression this PR would trigger.

— sent from keen-deer-531

@gunbai-bot
gunbai-bot Bot force-pushed the session/keen-deer-531-wave-c5 branch from 87a5348 to 3e3daf7 Compare July 22, 2026 14:13
@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41393 (APPROVE) — verified on 3e3daf71bc

No code changes required. Confirmed against current tree after rebase onto main:

  • Runtime realize path routes deploy-access probes through typed-argv extdeps ops (posix_effective_principal_read_argv, sudo_nopasswd_execute_probe_argv) + typed_argv_exec_over_ssh with fail-closed TypedArgvExecRefused allowlist; EmitArtifactThenThinRun arms are typed transport-mismatch refusals.
  • host_effect_deploy_access_probe_script.dag deleted with no remaining references; GHA emit residue stays in ci_deploy_access_emit.dag behind existing Scaffold + #5828 dissolution trigger (foreign-executor bootstrap boundary).
  • Witness typed_argv_exec_realization_witness_test.dag includes discriminating RED controls for allowlist refusal and typed-argv realization.
  • CI workflow prelude split matches updated ci_materialization.dag note; cli_run.rs deletion-hunk parser fix has regression test deletion_hunk_after_modified_file_does_not_false_fire_module_line.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41394 (APPROVE) — verified on 3e3daf71bc

No code changes required for this slice.

Finding 1 (multi-token check_argv vs portable-argv allowlist): Valid observation, already grounded. sudo_nopasswd_execute_probe_note (dag/extdeps/sudo/nopasswd_execute_probe.dag:14) makes the single-token invariant explicit and names the List<String> shape change as the correct extension path — not space-embedding in NonEmptyStr. Corpus census on HEAD: every fleet-roster check_argv is single-token (--version, --help, -V, version, probe in fleet_posix_accounts.dag); no multi-token or = probes registered. SSH refusal on non-portable tokens is intentional §5 fail-closed (the prior concat path's silent shell split was the fail-open). Extending to multi-token probes is a follow-on shape change, out of scope for Wave C5.

Finding 2 (LocalShell exit_code/empty stderr fabrication): Acknowledged. sudo.NopasswdExecuteProbe.Check exposes only success: Bool today; the LocalShell arm maps that to exit_code: 0|1 for ShellEffectApplied reconciliation. SSH transport carries the real exit code from ssh_session_exec_argv. Empty stderr on LocalShell is cosmetic — deploy-access consumers key off convergence/success, not stderr text.

— sent from keen-deer-531

briansrls added a commit that referenced this pull request Jul 22, 2026
…eipts

Answers "for every instance that wants to call a bash script, what is the path?"
with filenames + receipts, grounded @ 78f43c3.

Headline: the whole arc needs only ~4 NEW typed ops —
  - extdeps.os.hostname (Read/Set)           [new file]
  - systemd.Systemctl.ListUnits              [add to existing systemctl.dag]
  - extdeps.os.id (uid/gid/user)             [new file]
  - ssh.Session.ExecArgv                     [add; in flight C5 #6946]
Everything else CALLS AN OP THAT ALREADY EXISTS (receipts in §5.B): Clock.Now
for `date`, shell.Which.Check for `command -v`, shell.Find.IsExecutable for
`test -x`, git.Core.Show for `git show`, systemd.Systemctl.ShowProperty/
SetProperty for systemctl, Filesystem.Write for file writes, WitnessBin.Run/
cargo.Build for the witness transports.

Four paths per instance: 5.B call-existing-op · 5.A add-one-op-then-call ·
5.C emit-for-foreign-executor (bounded roster) · 5.D deferred (srv*/C5/nbd).
5.E names the enabler that must come first — brand TransportScript + typed-argv
realization edge so the string sink is unreachable and 5.B can't be faked by
argv_join (the sleek-crab #7064 failure mode).

Receipts: op inventory (present) + new-ops (absent) both verified @ 78f43c3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Brian Searls and others added 5 commits July 22, 2026 14:58
Delete concat-shell scaffold host_effect_deploy_access_probe_script;
route LocalShell/SshShell through typed extdeps op modules and
gunbc.typed_argv_exec with portable-argv allowlist and RED witnesses.
Inline probe script builders in ci_deploy_access_emit for Wave C
deploy preflight; split CI prelude so ci job carries rustfmt toolchain.
Document that SudoNopasswdExecuteProbeShape.check_argv is one exec argv
token so typed-argv realize and emit concat agree; fleet roster is
single-token only (review 41197 non-blocking).
Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/keen-deer-531-wave-c5 branch from 3e3daf7 to f1e058b Compare July 22, 2026 15:00
@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41423 (APPROVE) — verified on f1e058b224

No code changes required. Confirmed against current tree after rebase onto main (#7049 diff-parser fix absorbed; PR retains only the regression test):

  • Deploy-access probes (ReadEffectivePosixPrincipal, SudoNopasswdExecuteProbe) realize through extdeps *_read_op / *_check_op + typed_argv_exec_over_ssh on SSH; host_effect_deploy_access_probe_script.dag deleted with no remaining references.
  • GHA emit concat remains in ci_deploy_access_emit.dag behind existing Scaffold + #5828 dissolution trigger (foreign-executor bootstrap boundary).
  • Fail-closed portable-argv allowlist + discriminating RED witnesses in typed_argv_exec_realization_witness_test.dag; mock-corpus totality updated.
  • CI prelude split: build keeps isolated rustup; ci/deploy artifact consumers slimmed per updated materialization note.
  • cli_run.rs adds regression test only — diff-parser fix lives on main via Dissolve extdeps external-authority scan into a SubstrateMandatoryTag compile gate (v2.lens.mandatory_tag) + diff-parser deleted-file attribution fix #7049.

— sent from keen-deer-531

@gunbai-bot

gunbai-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review 41424 (APPROVE) — verified on f1e058b224

No code changes required for this slice.

Finding 1 (emit-shell parallel representation): Correct — Wave C5 shrinks the realize-edge dispatch path only. ci_deploy_access_emit.dag:47-58 still concat-builds whoami / sudo -n … for the GHA foreign-executor bootstrap window; that is tracked live scaffold debt (deploy_access_emit_preflight_scaffold + dissolution trigger naming bash-emit #5828 and typed-argv op ownership), not new untracked debt. Runtime path already routes through posix_effective_principal_read_argv / sudo_nopasswd_execute_probe_argv + typed_argv_exec_over_ssh. Emit-edge dissolution is explicitly out of scope for this PR.

Finding 2 (minimal portable-argv allowlist): Correct polarity. Allowlist is [A-Za-z0-9._/-] only; adequate for current callers per sudo_nopasswd_execute_probe_note single-token invariant. Future ops needing =, :, @, ,, or whitespace must earn explicit allowlist expansions or a richer argv shape — fail-closed refusal is intentional §5, with RED controls in typed_argv_exec_realization_witness_test.dag.

— sent from keen-deer-531

@briansrls
briansrls merged commit b0b1647 into main Jul 22, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/keen-deer-531-wave-c5 branch July 22, 2026 16:11
briansrls added a commit that referenced this pull request Jul 22, 2026
…st (#7065)

* shell→dag: exhaustive per-instance census (§4) — the tracked punch-list

§1–§3 recorded direction at #6507; this adds §4, the complete current
per-instance list grounded at origin/main so every shell-string-construction
site is tracked to closure — motivated by the relocation regression (#7004,
#7006, closed srv* cluster) that counted concat-relocations as migrations.

Completeness method (P1–P8 grep patterns) partitions every construction/carrier
form into action-classes:
  A. relocation regression (fake-migrated *_script.dag) → dissolve to the
     already-modeled extdeps op; delete the concat AND the nickname variant
  B. direct ShellCommand{script} still in intent
  C. runtime-present shell.Exec.Run with a string/_script body
  D. ssh command-string vs typed ExecArgv
  E. foreign-executor/bootstrap (legit emit, bounded roster)
  F. bottom transport + the porous TransportScript brand (Phase-3 wall)
  G. bash-AST emit vocab (emit-internal, confined)
  H. oracle/test retainers

Each row is discharged by DELETION of the concat (green-by-execution +
injection-RED), never relocation. §4 dissolves into the
host_language_transport_script lens going live (the construction wall).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

* shell→dag census §4: re-ground on main + re-anchor on symbols (review 41399)

review 41399 (cursor) correctly caught that §4 was mis-grounded on a divergent
worktree (still pre-#7006, so it showed direct ShellCommand{script} sites that
no longer exist on main) and that line-numbered rows drift (DESIGN §6). Fixes:

- Re-anchor every row on file + symbol NAME, not line numbers (drift-proof).
- §4.B: there are 0 live direct ShellCommand construction sites on origin/main —
  all became nickname variants (now correctly in §4.A). §4.B is residue only
  (host_effect_plan placeholder + host_effect.dag type def). Removed the wrong
  fleet_show/host_identity ShellCommand rows.
- §4.A: correct construction sites are the nickname variants
  (SystemdUnitMemory*Read in fleet_show, HostIdentityShortHostnameRead, etc.)
  plus the INLINE builders P5 had missed (fleet_runner_unit_property_read_script,
  fleet_runner_width_count_read_script, host_converge_slice1 *_script fns).
- §4.0 P5: broadened to inline `fn … -> String` builders outside *_script.dag.
- §4.D: corrected/completed the ssh_session_exec command-string inventory
  (test -x, command -v ×2, id -u/-g, ssh_session_exec_script).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* shell→dag census §5: Method of Action — per-instance path with op receipts

Answers "for every instance that wants to call a bash script, what is the path?"
with filenames + receipts, grounded @ 78f43c3.

Headline: the whole arc needs only ~4 NEW typed ops —
  - extdeps.os.hostname (Read/Set)           [new file]
  - systemd.Systemctl.ListUnits              [add to existing systemctl.dag]
  - extdeps.os.id (uid/gid/user)             [new file]
  - ssh.Session.ExecArgv                     [add; in flight C5 #6946]
Everything else CALLS AN OP THAT ALREADY EXISTS (receipts in §5.B): Clock.Now
for `date`, shell.Which.Check for `command -v`, shell.Find.IsExecutable for
`test -x`, git.Core.Show for `git show`, systemd.Systemctl.ShowProperty/
SetProperty for systemctl, Filesystem.Write for file writes, WitnessBin.Run/
cargo.Build for the witness transports.

Four paths per instance: 5.B call-existing-op · 5.A add-one-op-then-call ·
5.C emit-for-foreign-executor (bounded roster) · 5.D deferred (srv*/C5/nbd).
5.E names the enabler that must come first — brand TransportScript + typed-argv
realization edge so the string sink is unreachable and 5.B can't be faked by
argv_join (the sleek-crab #7064 failure mode).

Receipts: op inventory (present) + new-ops (absent) both verified @ 78f43c3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* shell→dag census: fix multiline-P1 completeness hole (review 41467)

review 41467 (cursor) correctly caught that §4.B's "0 direct ShellCommand sites"
was false: live_deploy/readiness.dag constructs ShellCommand{script:...} in the
MULTILINE form (`ShellCommand {` then `script:` next line), which my single-line
P1 pattern could not match. Fixes:

- §4.0: P1 is now multiline (`ShellCommand\s*\{\s*script:`); added an explicit
  note that the search must be slurped/multiline, not line-at-a-time — that gap
  is what hid these sites. Disambiguated match-arms (host_effect_realize/
  fleet_converge_cli/ci_deploy_access_observe `ShellCommand{script:_} =>`) as
  destructuring, not construction.
- §4.B: NOT zero — 2 live direct sites in readiness.dag
  (live_deploy_healthz_probe_script_for_port, live_deploy_unit_diagnosis_command),
  both runtime-present via host_effect_apply_gated on srv1 LocalShell, with their
  intent.dag builders and dissolve-to paths. Flagged the `| tail` + defensive
  `exit 0` in unit_diagnosis as a §5 absorbing fallback (intent.dag's own comment
  admits it masks systemctl's nonzero).
- §5.A: add systemd.Systemctl.Status (models exit-3-for-dead-unit, retires the
  tail/exit-0 fallback). §5.B: healthz curl → http.Client.Get (already exists,
  no new op).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant