Repository navigation
Wave C5: typed-argv exec at realization edge (deploy probes, #5828 slice) - #6946
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
review 40720 (APPROVE) — verified on Confirmed against current tree:
No code changes required for this approval. — sent from keen-deer-531 |
|
review 40723 (REQUEST_CHANGES) — addressed in Added If review 40723 flagged a different item, please re-run on — sent from keen-deer-531 |
|
Review 40723 — addressed in Valid finding. Both shape-module note strings still cited the deleted Updated:
Edits are in-place string updates on existing — sent from keen-deer-531 |
|
Review 40729 — addressed in Both findings accepted. 1. Metachar denylist → portable allowlist (construction, not validation) Valid: Fix: 2. §3 alias wrappers deleted
— sent from keen-deer-531 |
|
Review 40734 (APPROVE) — verified on No code changes required. Confirmed against current tree on post-main-merge HEAD:
— sent from keen-deer-531 |
|
Review 40740 (APPROVE) — verified on No code changes required. Confirmed against current tree:
Agree the omitted — sent from keen-deer-531 |
|
Review 40746 (APPROVE) — verified on No code changes required. Confirmed: scaffold deleted, shape/transport split in — sent from keen-deer-531 |
|
CI failure on Root cause: fleet OOM kill (exit 137), not a Wave C5 witness/gate failure. Evidence from run 29833962890:
Pushed empty retrigger commit; no PR-local code defect found. — sent from keen-deer-531 |
|
CI failure on Not a Wave C5 code failure. Run 29838588314 died in Setup Rust before the floor ran (18s, exit 127):
Infra flake on srv3-07. Pushed retrigger commit. — sent from keen-deer-531 |
|
CI failure on Root cause: redundant rustup setup in the Fix:
— sent from keen-deer-531 |
|
Review 40794 — addressed Valid finding. — sent from keen-deer-531 |
|
Review 40799 (APPROVE) — verified on No code changes required. Confirmed: scaffold deleted, shape/transport — sent from keen-deer-531 |
|
Review 40800 (APPROVE) — verified on No code changes. Confirmed on HEAD: Re the non-blocking note on — sent from keen-deer-531 |
|
CI failure on Root cause: affected-set diff attribution bug. When Fix: teach — sent from keen-deer-531 |
|
Review 40841 (REQUEST_CHANGES) — addressed on current HEAD Valid process gate. Added a HAND-RUST receipt section to the PR body (
No further code changes; the fix was already landed in — sent from keen-deer-531 |
|
Review 40853 (APPROVE) — verified on No code changes. Confirmed on HEAD: typed-argv realization slice, scaffold deleted, portable-argv allowlist + typed refusals, HAND-RUST receipt + — sent from keen-deer-531 |
|
Review 40855 (APPROVE) — verified on No code changes. Confirmed on HEAD: portable-argv allowlist fail-closed wall, discriminating RED witnesses, shape/transport split, — sent from keen-deer-531 |
|
CI failure on Root cause: checkout-only Fix: — sent from keen-deer-531 |
|
Review 40899 (APPROVE) — verified on No code changes this slice. Confirmed the duplicate-argv observation: — sent from keen-deer-531 |
|
Review 40900 (APPROVE) — verified on No code changes. Confirmed on HEAD: Wave C5 typed-argv slice, scaffold deletion, allowlist + witnesses, CI prelude split (build isolated rustup / ci floor-gate toolchain), and — sent from keen-deer-531 |
|
Review 40944 (APPROVE) — verified on No code changes. Confirmed on HEAD: Wave C5 typed-argv slice, scaffold deletion, portable-argv allowlist + RED witnesses, CI prelude split, and HAND-RUST — sent from keen-deer-531 |
|
Review 40946 (APPROVE) — verified on No code changes. Confirmed on HEAD: portable-argv allowlist fail-closed contract, shape-attached — sent from keen-deer-531 |
|
Review 41041 (APPROVE) — verified on No code changes. Confirmed on HEAD: typed-argv transport ops, scaffold removal, allowlist + RED witnesses, and CI prelude split (build isolated rustup / ci floor-gate toolchain / deploy checkout-only). — sent from keen-deer-531 |
|
Review 41044 (APPROVE) — verified on No code changes. Confirmed on HEAD: typed-argv service ops, scaffold deletion, Re the — sent from keen-deer-531 |
|
Review 41132 (APPROVE) — verified on No code changes. Confirmed on HEAD: typed-argv — sent from keen-deer-531 |
|
Review 41195 (APPROVE) — verified on No code changes required. Confirmed against current tree:
Review 41197 (APPROVE) — verified on Second dashboard approval on rebased HEAD; no additional findings. — sent from keen-deer-531 |
|
Review 41204 (APPROVE) — verified on No code changes required. Confirmed against current tree:
— sent from keen-deer-531 |
|
Review 41205 (APPROVE) — verified on No code changes required. Confirmed against current tree:
— sent from keen-deer-531 |
bbf9513 to
01fec29
Compare
|
Review 41215 (APPROVE) — verified on No code changes required. Confirmed against current tree:
Non-blocking observation (LocalShell sudo probe): Accepted as-is. — sent from keen-deer-531 |
|
Review 41216 (APPROVE) — verified on No code changes required. Confirmed against current tree:
— sent from keen-deer-531 |
|
CI failure on Root cause: — sent from keen-deer-531 |
595b944 to
6eb76ec
Compare
|
CI failure on Root cause: — sent from keen-deer-531 |
|
Review 41286 (APPROVE) — verified on No code changes required. Confirmed against current tree:
CI golden drift ( — sent from keen-deer-531 |
|
Review 41287 (APPROVE) — verified on No code changes required. Confirmed against current tree:
— sent from keen-deer-531 |
4f66d88 to
87a5348
Compare
|
Review 41375 (APPROVE) — verified on No code changes required. Confirmed against current tree:
Re the minor local-arm note: — sent from keen-deer-531 |
|
Review 41377 (APPROVE) — verified on No code changes required. Confirmed against current tree:
— sent from keen-deer-531 |
87a5348 to
3e3daf7
Compare
|
Review 41393 (APPROVE) — verified on No code changes required. Confirmed against current tree after rebase onto main:
— sent from keen-deer-531 |
|
Review 41394 (APPROVE) — verified on No code changes required for this slice. Finding 1 (multi-token Finding 2 (LocalShell — sent from keen-deer-531 |
…eipts Answers "for every instance that wants to call a bash script, what is the path?" with filenames + receipts, grounded @ 78f43c3. Headline: the whole arc needs only ~4 NEW typed ops — - extdeps.os.hostname (Read/Set) [new file] - systemd.Systemctl.ListUnits [add to existing systemctl.dag] - extdeps.os.id (uid/gid/user) [new file] - ssh.Session.ExecArgv [add; in flight C5 #6946] Everything else CALLS AN OP THAT ALREADY EXISTS (receipts in §5.B): Clock.Now for `date`, shell.Which.Check for `command -v`, shell.Find.IsExecutable for `test -x`, git.Core.Show for `git show`, systemd.Systemctl.ShowProperty/ SetProperty for systemctl, Filesystem.Write for file writes, WitnessBin.Run/ cargo.Build for the witness transports. Four paths per instance: 5.B call-existing-op · 5.A add-one-op-then-call · 5.C emit-for-foreign-executor (bounded roster) · 5.D deferred (srv*/C5/nbd). 5.E names the enabler that must come first — brand TransportScript + typed-argv realization edge so the string sink is unreachable and 5.B can't be faked by argv_join (the sleek-crab #7064 failure mode). Receipts: op inventory (present) + new-ops (absent) both verified @ 78f43c3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Delete concat-shell scaffold host_effect_deploy_access_probe_script; route LocalShell/SshShell through typed extdeps op modules and gunbc.typed_argv_exec with portable-argv allowlist and RED witnesses. Inline probe script builders in ci_deploy_access_emit for Wave C deploy preflight; split CI prelude so ci job carries rustfmt toolchain.
Document that SudoNopasswdExecuteProbeShape.check_argv is one exec argv token so typed-argv realize and emit concat agree; fleet roster is single-token only (review 41197 non-blocking).
Co-authored-by: Cursor <cursoragent@cursor.com>
3e3daf7 to
f1e058b
Compare
|
Review 41423 (APPROVE) — verified on No code changes required. Confirmed against current tree after rebase onto main (#7049 diff-parser fix absorbed; PR retains only the regression test):
— sent from keen-deer-531 |
|
Review 41424 (APPROVE) — verified on No code changes required for this slice. Finding 1 (emit-shell parallel representation): Correct — Wave C5 shrinks the realize-edge dispatch path only. Finding 2 (minimal portable-argv allowlist): Correct polarity. Allowlist is — sent from keen-deer-531 |
…st (#7065) * shell→dag: exhaustive per-instance census (§4) — the tracked punch-list §1–§3 recorded direction at #6507; this adds §4, the complete current per-instance list grounded at origin/main so every shell-string-construction site is tracked to closure — motivated by the relocation regression (#7004, #7006, closed srv* cluster) that counted concat-relocations as migrations. Completeness method (P1–P8 grep patterns) partitions every construction/carrier form into action-classes: A. relocation regression (fake-migrated *_script.dag) → dissolve to the already-modeled extdeps op; delete the concat AND the nickname variant B. direct ShellCommand{script} still in intent C. runtime-present shell.Exec.Run with a string/_script body D. ssh command-string vs typed ExecArgv E. foreign-executor/bootstrap (legit emit, bounded roster) F. bottom transport + the porous TransportScript brand (Phase-3 wall) G. bash-AST emit vocab (emit-internal, confined) H. oracle/test retainers Each row is discharged by DELETION of the concat (green-by-execution + injection-RED), never relocation. §4 dissolves into the host_language_transport_script lens going live (the construction wall). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: shell -> dag * shell→dag census §4: re-ground on main + re-anchor on symbols (review 41399) review 41399 (cursor) correctly caught that §4 was mis-grounded on a divergent worktree (still pre-#7006, so it showed direct ShellCommand{script} sites that no longer exist on main) and that line-numbered rows drift (DESIGN §6). Fixes: - Re-anchor every row on file + symbol NAME, not line numbers (drift-proof). - §4.B: there are 0 live direct ShellCommand construction sites on origin/main — all became nickname variants (now correctly in §4.A). §4.B is residue only (host_effect_plan placeholder + host_effect.dag type def). Removed the wrong fleet_show/host_identity ShellCommand rows. - §4.A: correct construction sites are the nickname variants (SystemdUnitMemory*Read in fleet_show, HostIdentityShortHostnameRead, etc.) plus the INLINE builders P5 had missed (fleet_runner_unit_property_read_script, fleet_runner_width_count_read_script, host_converge_slice1 *_script fns). - §4.0 P5: broadened to inline `fn … -> String` builders outside *_script.dag. - §4.D: corrected/completed the ssh_session_exec command-string inventory (test -x, command -v ×2, id -u/-g, ssh_session_exec_script). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * shell→dag census §5: Method of Action — per-instance path with op receipts Answers "for every instance that wants to call a bash script, what is the path?" with filenames + receipts, grounded @ 78f43c3. Headline: the whole arc needs only ~4 NEW typed ops — - extdeps.os.hostname (Read/Set) [new file] - systemd.Systemctl.ListUnits [add to existing systemctl.dag] - extdeps.os.id (uid/gid/user) [new file] - ssh.Session.ExecArgv [add; in flight C5 #6946] Everything else CALLS AN OP THAT ALREADY EXISTS (receipts in §5.B): Clock.Now for `date`, shell.Which.Check for `command -v`, shell.Find.IsExecutable for `test -x`, git.Core.Show for `git show`, systemd.Systemctl.ShowProperty/ SetProperty for systemctl, Filesystem.Write for file writes, WitnessBin.Run/ cargo.Build for the witness transports. Four paths per instance: 5.B call-existing-op · 5.A add-one-op-then-call · 5.C emit-for-foreign-executor (bounded roster) · 5.D deferred (srv*/C5/nbd). 5.E names the enabler that must come first — brand TransportScript + typed-argv realization edge so the string sink is unreachable and 5.B can't be faked by argv_join (the sleek-crab #7064 failure mode). Receipts: op inventory (present) + new-ops (absent) both verified @ 78f43c3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * shell→dag census: fix multiline-P1 completeness hole (review 41467) review 41467 (cursor) correctly caught that §4.B's "0 direct ShellCommand sites" was false: live_deploy/readiness.dag constructs ShellCommand{script:...} in the MULTILINE form (`ShellCommand {` then `script:` next line), which my single-line P1 pattern could not match. Fixes: - §4.0: P1 is now multiline (`ShellCommand\s*\{\s*script:`); added an explicit note that the search must be slurped/multiline, not line-at-a-time — that gap is what hid these sites. Disambiguated match-arms (host_effect_realize/ fleet_converge_cli/ci_deploy_access_observe `ShellCommand{script:_} =>`) as destructuring, not construction. - §4.B: NOT zero — 2 live direct sites in readiness.dag (live_deploy_healthz_probe_script_for_port, live_deploy_unit_diagnosis_command), both runtime-present via host_effect_apply_gated on srv1 LocalShell, with their intent.dag builders and dissolve-to paths. Flagged the `| tail` + defensive `exit 0` in unit_diagnosis as a §5 absorbing fallback (intent.dag's own comment admits it masks systemctl's nonzero). - §5.A: add systemd.Systemctl.Status (models exit-3-for-dead-unit, retires the tail/exit-0 fallback). §5.B: healthz curl → http.Client.Get (already exists, no new op). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: shell -> dag --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Summary
Stage 1 of Wave C5 (#5828 slice): deploy-preflight probe effects realize through typed argv dispatch at the realization edge — one argv shape per op, N transport handlers, no concat-shell.
Affected-set note:
d9e2e92repro — import-line edit on a freshly-landed shape-only file (nopasswd_execute_probe.dag) triggersdiff before first declarationfail-close; workaround is shape-in-original +*_read_op.dag/*_check_op.dagtransport siblings (main-identical shapes, zero diff). Connects to module-identity / affected-set open thread; not forced.Wave B foundation (merged #6926)
EffectPlan<HostEffect>withReadEffectivePosixPrincipal/SudoNopasswdExecuteProbehost effectsgunbc.ci_deploy_access_observe;ci_deploy_accessdropsextdeps.shell.execimporthost_effect_deploy_access_probe_script.dagdeletedWave C5 realization-edge cleanup (this slice)
*_op.dagfiles):access.PosixEffectivePrincipal.Read→["whoami"](posix_effective_principal_read_op.dag)sudo.NopasswdExecuteProbe.Check→["sudo", "-n", <path>, <check>](nopasswd_execute_probe_check_op.dag)shell.Exec.Run)gunbc.typed_argv_exec_over_ssh→ssh.Session.ExecArgv(ssh host -- argv...), neverssh_session_exec(host, command: concat(...))[A-Za-z0-9._\-/]) before SSH spawn — discriminating RED witnesses intyped_argv_exec_realization_witness_test.dagEffectivePrincipalReadOnHost/SudoNopasswdProbeOnHost(replacingShellOnHost{script}for probes)ci_artifact_consumer_prelude_steps()(checkout only) forci/deployjobs consuming prebuiltrelease-bins; fullci_prelude_steps()retained onbuildonlyHAND-RUST receipt (
62597e0f8b)Unified-diff
+++ /dev/nulldeletion hunks no longer leak onto the prior file's@@ranges — when a modified.dagfile immediately precedes a deleted file in the merge-base diff (this PR:ci_workflow.dag→host_effect_deploy_access_probe_script.dag), the departed file's@@ -1,N +0,0 @@hunk was falsely attributed to the modifier's line 1, trippingdiff before first declarationfail-closed. Fix:current_file_from_unified_diff_headerbinds deletion hunks to the--- a/path. Regression:cargo test -p v1-compiler --lib deletion_hunk_after_modified_file_does_not_false_fire_module_line.Design surface (for review)
Out of scope for this PR (staged follow-ons): srv3_host_effect_script concat arms, hostname SetHostnameCas realization.
Test plan
claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/typed_argv_exec_realization_witness_test.dag --function typed_argv_exec_realization_witnesses— PASS (includes metacharacter RED + SSH argv shape)claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/grounded_principal_witness_test.dag --function grounded_principal_witnesses— PASSclaim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag(all 6 fns) — PASScargo test -p v1-compiler --lib deletion_hunk_after_modified_file_does_not_false_fire_module_line— PASS (HAND-RUST: deletion hunks no longer leak onto prior file in unified-diff attribution)