Skip to content

shell→dag Phase-2: typed HostEffect variants for live_deploy/apply.dag - #7004

Merged
briansrls merged 9 commits into
mainfrom
session/nimble-carp-340
Jul 22, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/nimble-carp-340

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Migrates all six ShellCommand{script:...} construction sites in gunbc.live_deploy.apply to typed HostEffect variants realized through host_effect_apply (Wave B preflight pattern):

# Site Typed shape
1 live_deploy_fold apply path LiveDeployApply/Retract/EnsureDependency/DigestReadback
2 live_deploy_mutation_denied same typed effect in denied intent
3–5 preflight intent placeholders DeployAccessPreflight {} (intent-only, realization fail-closes)
6 preflight target-host shell removed — deploy_mutation_gate(access, Absent, Absent)

Test plan

  • claim_batch deploy_mutation_gate_witnesses — PASS
  • claim_batch live_deploy_apply_witnesses — PASS
  • CI floor (auto on ready)

@gunbai-bot gunbai-bot Bot changed the title shell->dag Phase-2: live_deploy/apply.dag — migrate its 6 ShellCommand{script:...} construction sites to typed HostEffect variants realized on host_effect_apply, following the Wave B reference (PR #6926 ci_deploy_access) and building on C5's typed-argv machinery (#6946, merging now). DFS FIRST — con shell→dag Phase-2: typed HostEffect variants for live_deploy/apply.dag Jul 21, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 21, 2026 16:24
@gunbai-bot
gunbai-bot Bot marked this pull request as draft July 21, 2026 16:36
@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Verified both review artifacts against current 9df4282:

review 40839 (claude-opus-4-7, APPROVE) — Confirmed: five typed HostEffect variants land in host_effect.dag; script dispatch is centralized in gunbc.live_deploy.host_effect_script (mirrors srv3_host_effect_script_for); scaffold disposition binds live_deploy_remote_mutation_service_op_realization_dissolution_trigger; total-fold consumers (ci_deploy_access_observe, fleet_converge_cli, srv3_host_effect_script, host_effect_realize HostOs+BmcController) are exhaustively extended; preflight collapses to deploy_mutation_gate(access, Absent, Absent) (no parallel shell path). No code changes required.

review 40840 (composer-2.5, APPROVE) — Confirmed: all six ShellCommand construction sites are gone from apply.dag; live_deploy_fold takes effect: HostEffect; DeployAccessPreflight fail-closes at realization; witness tests updated for the new signature. No code changes required.

Retriggered CI (workflow_dispatch run 29849299926) after the prior run sat queued ~11m with stale fail markers from cancelled superseded runs.

— sent from nimble-carp-340

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 21, 2026 16:58
@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Verified review 41031 (claude-opus-4-7, APPROVE) against current 76b5b30:

  • apply.dag has zero ShellCommand construction sites; mutations route through LiveDeployApply/Retract/EnsureDependency/DigestReadback, preflight through intent-only DeployAccessPreflight {} + deploy_mutation_gate
  • live_deploy/host_effect_script.dag carries Scaffold { dissolves_to: RealizationDispatch, bind: live_deploy_remote_mutation_service_op_realization_dissolution_trigger } at lines 44–50
  • Total-fold arms present in ci_deploy_access_observe.dag, fleet_converge_cli.dag, srv3_host_effect_script.dag, and host_effect_realize.dag
  • Witness test updated for effect: HostEffect fold signature
  • Dead fallthrough arms in host_effect_realize.dag acknowledged — mirror srv3 sibling pattern, no action

No code changes required for this review.

— sent from nimble-carp-340

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Verified review 41037 (composer-2.5, APPROVE) against current 76b5b30 — findings confirmed, no code changes required:

  • DeployAccessPreflight intent-only: host_effect_realize.dag:253-256 refuses apply with typed IncompatibleCell; live_deploy_preflight_intent (apply.dag:51-58) constructs the gate record without shell.
  • Mutation realization path: live_deploy_host_effect_script_for → ShellOnHost at host_effect_realize.dag:206-207, consistent with srv3 sibling dispatch.
  • Preflight gate authority: live_deploy_access_preflight_for (apply.dag:264-268) uses deploy_mutation_gate — same authority as live_deploy_fold mutations, not a fail-open shell shortcut.
  • Zero ShellCommand in apply.dag: all six Phase-2 sites migrated.

— sent from nimble-carp-340

@gunbai-bot

gunbai-bot Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Verified review 41137 (claude-opus-4-7, APPROVE) against current b404ad4b:

  • Zero ShellCommand in live_deploy/apply.dag; six sites migrated to typed LiveDeploy* / DeployAccessPreflight variants
  • Script authority centralized in live_deploy_host_effect_script_for, chained after srv3_host_effect_script_for in resolve_host_effect_cell (host_effect_realize.dag:203-207)
  • host_effect_script.dag carries Scaffold { dissolves_to: RealizationDispatch, bind: live_deploy_remote_mutation_service_op_realization_dissolution_trigger }
  • DeployAccessPreflight intent-only: live_deploy_access_preflight_for synthesizes reconciliation from deploy_mutation_gate (apply.dag:264-268); resolver IncompatibleCell (host_effect_realize.dag:253-256) is correct unreachable backstop
  • Total folds extended in ci_deploy_access_observe.dag, fleet_converge_cli.dag, host_effect_realize.dag, srv3_host_effect_script.dag
  • Witness test mechanical script: → effect: rename confirmed

No code changes required.

— sent from nimble-carp-340

@briansrls
briansrls merged commit c23c5ad into main Jul 22, 2026
3 checks passed
@briansrls
briansrls deleted the session/nimble-carp-340 branch July 22, 2026 00:53
gunbai-bot Bot pushed a commit that referenced this pull request Jul 22, 2026
The prior WIP autosave (c908aae, merging origin/main's PR #7004
into this branch) captured host_effect_realize.dag mid-resolution
with unresolved <<<<<<< markers still in the HostOs and BmcController
match-effect arms. Union both sides' typed arms and restore correct
brace balancing for the exhaustive fold.
briansrls added a commit that referenced this pull request Jul 22, 2026
…bservation/fleet_converge_cli ShellCommand sites to typed HostEffect variants (#7006)

* WIP: shell->dag Phase-2: three small runtime-present migrations — fleet_show_

* WIP: shell->dag Phase-2: three small runtime-present migrations — fleet_show_

* Fix remaining merge-conflict markers in host_effect_realize.dag

The prior WIP autosave (c908aae, merging origin/main's PR #7004
into this branch) captured host_effect_realize.dag mid-resolution
with unresolved <<<<<<< markers still in the HostOs and BmcController
match-effect arms. Union both sides' typed arms and restore correct
brace balancing for the exhaustive fold.

* live_deploy/host_effect_script: add missing arms for the 3 host_effect variants

resolve_host_effect_cell's live_deploy_host_effect_script_for was
non-exhaustive after the host_effect.dag merge — HostIdentityShortHostnameRead,
SystemdUnitMemoryMaxRead, SystemdUnitMemoryPropertiesRead had no arm.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
briansrls added a commit that referenced this pull request Jul 22, 2026
…st (#7065)

* shell→dag: exhaustive per-instance census (§4) — the tracked punch-list

§1–§3 recorded direction at #6507; this adds §4, the complete current
per-instance list grounded at origin/main so every shell-string-construction
site is tracked to closure — motivated by the relocation regression (#7004,
#7006, closed srv* cluster) that counted concat-relocations as migrations.

Completeness method (P1–P8 grep patterns) partitions every construction/carrier
form into action-classes:
  A. relocation regression (fake-migrated *_script.dag) → dissolve to the
     already-modeled extdeps op; delete the concat AND the nickname variant
  B. direct ShellCommand{script} still in intent
  C. runtime-present shell.Exec.Run with a string/_script body
  D. ssh command-string vs typed ExecArgv
  E. foreign-executor/bootstrap (legit emit, bounded roster)
  F. bottom transport + the porous TransportScript brand (Phase-3 wall)
  G. bash-AST emit vocab (emit-internal, confined)
  H. oracle/test retainers

Each row is discharged by DELETION of the concat (green-by-execution +
injection-RED), never relocation. §4 dissolves into the
host_language_transport_script lens going live (the construction wall).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

* shell→dag census §4: re-ground on main + re-anchor on symbols (review 41399)

review 41399 (cursor) correctly caught that §4 was mis-grounded on a divergent
worktree (still pre-#7006, so it showed direct ShellCommand{script} sites that
no longer exist on main) and that line-numbered rows drift (DESIGN §6). Fixes:

- Re-anchor every row on file + symbol NAME, not line numbers (drift-proof).
- §4.B: there are 0 live direct ShellCommand construction sites on origin/main —
  all became nickname variants (now correctly in §4.A). §4.B is residue only
  (host_effect_plan placeholder + host_effect.dag type def). Removed the wrong
  fleet_show/host_identity ShellCommand rows.
- §4.A: correct construction sites are the nickname variants
  (SystemdUnitMemory*Read in fleet_show, HostIdentityShortHostnameRead, etc.)
  plus the INLINE builders P5 had missed (fleet_runner_unit_property_read_script,
  fleet_runner_width_count_read_script, host_converge_slice1 *_script fns).
- §4.0 P5: broadened to inline `fn … -> String` builders outside *_script.dag.
- §4.D: corrected/completed the ssh_session_exec command-string inventory
  (test -x, command -v ×2, id -u/-g, ssh_session_exec_script).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* shell→dag census §5: Method of Action — per-instance path with op receipts

Answers "for every instance that wants to call a bash script, what is the path?"
with filenames + receipts, grounded @ 78f43c3.

Headline: the whole arc needs only ~4 NEW typed ops —
  - extdeps.os.hostname (Read/Set)           [new file]
  - systemd.Systemctl.ListUnits              [add to existing systemctl.dag]
  - extdeps.os.id (uid/gid/user)             [new file]
  - ssh.Session.ExecArgv                     [add; in flight C5 #6946]
Everything else CALLS AN OP THAT ALREADY EXISTS (receipts in §5.B): Clock.Now
for `date`, shell.Which.Check for `command -v`, shell.Find.IsExecutable for
`test -x`, git.Core.Show for `git show`, systemd.Systemctl.ShowProperty/
SetProperty for systemctl, Filesystem.Write for file writes, WitnessBin.Run/
cargo.Build for the witness transports.

Four paths per instance: 5.B call-existing-op · 5.A add-one-op-then-call ·
5.C emit-for-foreign-executor (bounded roster) · 5.D deferred (srv*/C5/nbd).
5.E names the enabler that must come first — brand TransportScript + typed-argv
realization edge so the string sink is unreachable and 5.B can't be faked by
argv_join (the sleek-crab #7064 failure mode).

Receipts: op inventory (present) + new-ops (absent) both verified @ 78f43c3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* shell→dag census: fix multiline-P1 completeness hole (review 41467)

review 41467 (cursor) correctly caught that §4.B's "0 direct ShellCommand sites"
was false: live_deploy/readiness.dag constructs ShellCommand{script:...} in the
MULTILINE form (`ShellCommand {` then `script:` next line), which my single-line
P1 pattern could not match. Fixes:

- §4.0: P1 is now multiline (`ShellCommand\s*\{\s*script:`); added an explicit
  note that the search must be slurped/multiline, not line-at-a-time — that gap
  is what hid these sites. Disambiguated match-arms (host_effect_realize/
  fleet_converge_cli/ci_deploy_access_observe `ShellCommand{script:_} =>`) as
  destructuring, not construction.
- §4.B: NOT zero — 2 live direct sites in readiness.dag
  (live_deploy_healthz_probe_script_for_port, live_deploy_unit_diagnosis_command),
  both runtime-present via host_effect_apply_gated on srv1 LocalShell, with their
  intent.dag builders and dissolve-to paths. Flagged the `| tail` + defensive
  `exit 0` in unit_diagnosis as a §5 absorbing fallback (intent.dag's own comment
  admits it masks systemctl's nonzero).
- §5.A: add systemd.Systemctl.Status (models exit-3-for-dead-unit, retires the
  tail/exit-0 fallback). §5.B: healthz curl → http.Client.Get (already exists,
  no new op).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 25, 2026
…_slice1, host_identity_adopt/assimilation, live_deploy/apply off the retained_runtime/retained_srvn bridges to typed host_effect_apply ops — INCLUDING the #7004/#7006 relocation debt (concats were moved-not-deleted; delete them, do (#7192)

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* fix: extract first field from systemctl list-units rows

The typed ListUnits consumer must mirror the old awk '{print $1}'
behavior — systemctl --plain still emits multi-column rows on live
hosts. Update the hermetic mock to multi-column output and strengthen
the witness so a regression to full-line trim goes red.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat: route SetHostnameCas through os.Hostname.Set (D1 consumer)

Wire host_identity adopt/assimilation hostname writes via gunbc.hostname_set:
CAS-guarded read (ReadShort) then typed Set, replacing the
host_effect_hostname_script concat bridge. Delete the relocation module;
add discriminating witnesses for argv authority and CAS base mismatch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* WIP: shell→dag D2 (census §5.B, host-state cluster): migrate host_converge_sl

* fix(live_deploy): dissolve tree_sync unit-diagnosis §5 absorbing fallback

Declare the exit-0/tail concat as scaffold with a dissolution trigger, route
poll-bound readiness capture through typed Systemctl.Status observation (exit
code as data, never masked), and witness that dead-unit failure text survives.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
…caffolds it found

Re-censused sections 4.A, 4.B and 4.D of the shell->dag arc census against
origin/main by execution over the tree rather than trusting the 07-22 rows.

Four corrections:

1. 4.D is NOT a dispatchable typed-argv bucket. Every ssh_session_exec(command:)
   site is inside an srv3_* fn (the operator-wound-down srv* cluster), except
   :1169 which is the realization core's own RetainedShellScript transport. The
   old table listed verbs without enclosing fns, which read as an independent
   A1 bucket. Reclassified as A5-deferred, with the exhaustive site list.

2. 4.A4 and 4.B are DONE. live_deploy/host_effect_script.dag is deleted and
   dag/gunbc/live_deploy/ has zero ShellCommand. Closes do-not-miss item 1
   (the #7004/#7006 relocation debt) -- the loudest open warning in the doc.

3. 4.A1 is DONE but had left two dead concat builders behind, deleted here:
     - fleet_runner_unit_memory_props_read_script -- zero refs tree-wide
     - fleet_runner_width_count_read_script -- zero production callers
   The live path is typed (systemctl_show_read -> ShowProperty,
   systemctl_list_units -> ListUnits), so both were superseded scaffolds.
   Deletion is the receipt: a row claiming done beside a live concat is the
   relocation pattern this census exists to catch.

   Two things made this worth recording, not just quietly fixing:
   - fleet_show_effective_read.dag:62 claimed "no concat shell strings" while
     two sat 110 lines below it -- true of the live path, false of the file.
   - witness_transport_reads_use_show_property_authority carried a third
     conjunct asserting the dead builder's string contains "list-units". It is
     tautological (a concat of a literal containing list-units always does),
     asserts nearly the OPPOSITE of the witness's stated purpose (that a
     shell-concat bypass still exists with the right shape), and kept a dead
     symbol referenced so it never read as dead code. Removing it leaves the
     witness asserting exactly what its name claims -- stronger, not weaker.

4. Added one uncensused consumer: fleet_converge_cli.dag:57's ShellCommand
   match arm, so the terminal type delete has a complete consumer list (a
   missed match arm is what turns that delete into a non-exhaustive break).

Net: with bucket D (4.E/4.I) in flight, the non-deferred remainder of this arc
is 4.F wall-green only, which is coupled to the visibility-grants lane.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
…caffolds it found (#7271)

* WIP: shell -> dag migration

* Census true-up (4.A/4.B/4.D) + delete the two dead systemctl concat scaffolds it found

Re-censused sections 4.A, 4.B and 4.D of the shell->dag arc census against
origin/main by execution over the tree rather than trusting the 07-22 rows.

Four corrections:

1. 4.D is NOT a dispatchable typed-argv bucket. Every ssh_session_exec(command:)
   site is inside an srv3_* fn (the operator-wound-down srv* cluster), except
   :1169 which is the realization core's own RetainedShellScript transport. The
   old table listed verbs without enclosing fns, which read as an independent
   A1 bucket. Reclassified as A5-deferred, with the exhaustive site list.

2. 4.A4 and 4.B are DONE. live_deploy/host_effect_script.dag is deleted and
   dag/gunbc/live_deploy/ has zero ShellCommand. Closes do-not-miss item 1
   (the #7004/#7006 relocation debt) -- the loudest open warning in the doc.

3. 4.A1 is DONE but had left two dead concat builders behind, deleted here:
     - fleet_runner_unit_memory_props_read_script -- zero refs tree-wide
     - fleet_runner_width_count_read_script -- zero production callers
   The live path is typed (systemctl_show_read -> ShowProperty,
   systemctl_list_units -> ListUnits), so both were superseded scaffolds.
   Deletion is the receipt: a row claiming done beside a live concat is the
   relocation pattern this census exists to catch.

   Two things made this worth recording, not just quietly fixing:
   - fleet_show_effective_read.dag:62 claimed "no concat shell strings" while
     two sat 110 lines below it -- true of the live path, false of the file.
   - witness_transport_reads_use_show_property_authority carried a third
     conjunct asserting the dead builder's string contains "list-units". It is
     tautological (a concat of a literal containing list-units always does),
     asserts nearly the OPPOSITE of the witness's stated purpose (that a
     shell-concat bypass still exists with the right shape), and kept a dead
     symbol referenced so it never read as dead code. Removing it leaves the
     witness asserting exactly what its name claims -- stronger, not weaker.

4. Added one uncensused consumer: fleet_converge_cli.dag:57's ShellCommand
   match arm, so the terminal type delete has a complete consumer list (a
   missed match arm is what turns that delete into a non-exhaustive break).

Net: with bucket D (4.E/4.I) in flight, the non-deferred remainder of this arc
is 4.F wall-green only, which is coupled to the visibility-grants lane.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fix a stale consumer reference in section 5.A left by the true-up

Section 5.A's ListUnits row still named fleet_runner_width_count_read_script as
a consumer. It never became one: it was superseded by the typed op and left
dead, and this branch deletes it. host_converge_slice1 is the real consumer,
via systemctl_list_units_active_services.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 20, 2026
§1–§3 recorded direction at #6507; this adds §4, the complete current
per-instance list grounded at origin/main so every shell-string-construction
site is tracked to closure — motivated by the relocation regression (#7004,
#7006, closed srv* cluster) that counted concat-relocations as migrations.

Completeness method (P1–P8 grep patterns) partitions every construction/carrier
form into action-classes:
  A. relocation regression (fake-migrated *_script.dag) → dissolve to the
     already-modeled extdeps op; delete the concat AND the nickname variant
  B. direct ShellCommand{script} still in intent
  C. runtime-present shell.Exec.Run with a string/_script body
  D. ssh command-string vs typed ExecArgv
  E. foreign-executor/bootstrap (legit emit, bounded roster)
  F. bottom transport + the porous TransportScript brand (Phase-3 wall)
  G. bash-AST emit vocab (emit-internal, confined)
  H. oracle/test retainers

Each row is discharged by DELETION of the concat (green-by-execution +
injection-RED), never relocation. §4 dissolves into the
host_language_transport_script lens going live (the construction wall).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant