Repository navigation
Lane D: dotted-name emit-shape rendering fix (pattern/construction/type-position) + orch_while falsifier fast-lane relocation - #7098
Conversation
…, not claim_batch --functions) Corrects the local-recipe command in the note added per cursor review 41792's suggestion (PR #7098) to match the actual CLI surface, verified by execution. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Re review 41804's non-blocking note on — sent from keen-ibex-888 |
…ior auto-commit race The auto-committer captured a WIP snapshot mid-merge (commit 7c25ef6) before this session's conflict resolution had been staged, landing raw <<<<<<</=======/>>>>>>> markers in docs/probes/curated_cargo_frontier_probe_sweep.tsv and src/v2/compiler/self_host/frontier_probe_types.dag (flagged by review 41850). Resolution: adopt main's v3 TSV schema/rows (docs/probes/curated_cargo_frontier_probe_sweep.tsv) as the base — a full re-sweep against the merged code (both Lane D's dotted-name emit fixes and Lane A's std_dup fix, #7097) is in progress to refresh it with true post-merge state. For frontier_probe_types.dag, kept BOTH honest_frontier_refresh_2026_07_23_note (Lane D) and honest_frontier_refresh_2026_07_23_lane_a_note (Lane A, renamed from the conflicting duplicate name) since they document distinct, complementary work rather than competing claims. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Re review 41892's minor observation (rust_name vs name in variant_pattern_shape_key for optional variants): this is the same finding as review 41804 earlier on this PR, which I investigated and replied to directly (comment above). Confirmed by tracing — sent from keen-ibex-888 |
…sing leg rows (#7127) Root cause: the batch-3 floor panicked in `witness_execution_leg_label` (cli_run.rs:8508) — "no census TSV row for entry dag/test/claim/ci_heal_job_witness_test.dag (refuse — regenerate ...)". This is the correct fail-closed refusal (§5): the leg loader has no row for a witness entry the floor is about to run. The census TSV (docs/probes/witness_entry_eligibility_census.tsv) is a generated artifact regenerated only by hand via scripts/witness_entry_eligibility_census.sh (the witness_entry_eligibility_census_emit transport, which delegates every classification column to the v2.compiler.self_host.witness_entry_eligibility_census authority). Its committed bytes carried an 08:16-EDT snapshot (stamp 12:16Z) that predated a burst of PRs which added/relocated witness *_test.dag files under witness_layer_roots (ci_heal #7112, Belt B #7113, Lane D relocation #7098, host-convergence #7121, ...). Because the Rust sync test that checks census/roster freshness was removed from CI on 2026-07-11, the drift merged to main undetected and only surfaced as the floor panic on the first uncovered entry. The roster drifted by +10/-3 vs the census (857 -> 864): 10 entries added (ci_heal_job, component_dispatch_button, css_grain, dispatch_presentation, floor_discovery_hand_rust_equivalence, floor_discovery_roster_fixture, host_axis_caps, media_type, roadmap_sandbox, long/orchestration_while_emit) and 3 removed (fleet_converge_emit, roadmap_dashboard_emit_witness, the old workflow/orchestration_while_emit location). Fix (regenerate the artifact from its authority — no hand-forked classification): - regenerate census.tsv + histogram.txt via witness_entry_eligibility_census_emit (864 entries; every current roster entry now has a non-empty execution_leg) - bump witness_entry_eligibility_census_entry_count 857 -> 864 and the census_test `== 857` assertion to `== 864` - refresh the decorative stamp constant and the two prose "857" references Proof by execution: witness_entry_eligibility_census_tsv_sync_tests:: tsv_data_row_count_matches_declared_authority passes from the repo root (declared authority count 864 == committed TSV data rows 864). Claude-Session: https://claude.ai/code/session_014qyDtPF6EM5hvRiUDUG5fe Co-authored-by: Claude <noreply@anthropic.com>
…railing line) Branch was behind main's v1_compiler_emit_rust.rs (Lane D #7098); merged main and rebuilt the seed. Emitted-Rust artifacts now match; ROADMAP.md re-regenerated without main's stale trailing blank line. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…eanup (#7027) * fix(srv3): DirectLayout on-ISO autoinstall + os-install reconcile spine (T3/T4) Rebased onto main: StoragePolicyDirectLayout on seeded ISO autoinstall, split reconcile modules (core/types/receipt/apply/dry_run/record_approval), honest freeze scope and printf receipt echo, fail-closed observed_at parse, ServeReady virtual-media session match, and review-driven witness coverage. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(srv3): observe script bash syntax — drop stray HTTP_CODE= before if Serve receipt echo was concatenated into curl_tail as HTTP_CODE=if test…, breaking live reconcile observe on srv1. Witness guards the regression. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(srv3): observe script curl HTTP_CODE — remove extra closing paren $(curl … || echo 000) had a stray ) breaking bash on live srv1 observe. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(srv4): BMC onboarding gap analysis — srv3-hardcoded plan + gcloud not provisioned srv4 racked, BMC at FactoryDefault (403 PasswordChangeRequired). The rotation workflow (bmc_converge_credential_idempotent, wired into host_standup_spine) is fully modeled and fail-closed, but bottoms out on the srv3-hardcoded new_altra_onboarding_plan and assumes gcloud is present. Documents 4 gaps (G1 per-host parameterization [dispositive], G2 gcloud self-provision, G3 operator-token handler, G4 srv4 identity rows) for review before modeling. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(srv4): close BMC onboarding gaps — per-host plan, gcloud self-provision, operator-token handler, srv4 identity Full close of the four gaps from the analysis doc (PR #7027), so BMC onboarding is hands-off per-host instead of srv3-hardcoded: G1 — per-host parameterization: altra_onboarding_plan(bmc_host, secret_name) constructor + srv3_onboarding_plan / srv4_onboarding_plan rows replace the srv3-literal new_altra_onboarding_plan. Threaded `plan` through every bmc_onboard func; de-nicknamed srv3_gcp_project -> bmc_secrets_gcp_project (fleet-wide). Zero-arg per-host entries srv3_converge_credential / srv4_converge_credential are what the standup decl_ref + executor invoke. G2 — gcloud self-provision: modeled gcloud_cli_tool (extdeps/tools/gcloud.dag) + package_google_cloud_cli, and bmc_credential_actuator_toolchain_requirement (curl + gcloud) mirroring the OS-install toolchain-ensure. G3 — token de-fork: gunbc.auth.access_token_source with AccessTokenSource = GcloudPrintToken | OperatorSuppliedToken{token} and resolve_access_token, so an operator-supplied token is a first-class handler (drives rotation with no gcloud on the actuator). G4 — srv4 identity: operator_host_srv4 + srv4_bmc_endpoint (.195) in fleet_intent_network. Verified: full-corpus typecheck clean (850 modules, 0 errors) + 11 witnesses green by execution across every touched module, incl. a new discriminating srv4_plan_targets_195_with_srv4_secret and the updated endpoint-count witness. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc): mint OpenBMC-policy-compliant credential (found by live srv3/srv4 rotation) First live execution of the rotation flow (srv3's was never run green) surfaced that mint_bmc_credential's base64 octets are rejected by OpenBMC password validation (PropertyValueFormatError). A firmware-policy divergence also showed: srv4 (newer OpenBMC) accepts alphanumeric, but srv3 (OpenBMC 2.07.00, pwquality, MinPasswordLength 9 / MaxPasswordLength 20) requires a 4th character class. Fix: Urandom.ReadPassword — composition-guaranteed generator (>=1 upper/lower/ digit/special from the shell/JSON/basic-auth-safe set _.@#%-); mint_bmc_credential mints a 16-char such password (within 9-20, accepted by both firmwares). The fail-closed read-back gate correctly aborted every base64/alnum attempt before rotating, so no lockout. Both srv3 (secret bmc-srv3-admin v6) and srv4 (v2) are now live-rotated off factory 0penBmc; orphaned pre-rotation versions destroyed. Full-corpus typecheck clean (850 modules, 0 errors) + witnesses green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): model fleet SSH access — operator + automation public keys (durable in repo) SSH-who, the third principal facet alongside POSIX-who (fleet_posix_accounts) and GCP-who (fleet_operator_gcp_iam_member): - extdeps/access/ssh.dag: SshPublicKey type + authorized_keys line renderer. - gunbc/fleet_ssh_access.dag: operator MacBook key (global break-glass, logs in as briansrls) + fleet-automation key (machine access). Both PUBLIC keys grounded in the repo (public keys aren't secret). fleet_authorized_keys = both, applied to every host by breadth. - fleet_automation_ssh_privkey_secret → SecretRef to Secret Manager 'fleet-automation-ssh-key' (project gunbai-secrets, v1). The private key's only copy lives there; generated 2026-07-21, local copy shredded. - keys/fleet-ssh-public-keys.txt: plain-text backup of both public keys. FOLLOW-UP: fleet-automation-ssh-key has no secret-level IAM binding yet (project- scoped access). Lock to a dedicated automation SA with secretAccessor, mirroring bmc-assimilator on bmc-srv*-admin. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc): remove fabricated-fallback in onboarding_secret_id (§5 fail-closed) onboarding_secret_id matched plan.rotated_credential and, on the Chained arm, fabricated a secret id (plan.bmc.host; pre-existing code fabricated a literal) — a §5 "fabricated plausible output" fallback. Construction-first fix: narrow the plan field from rotated_credential: CredentialFlow to secret_name: NonEmptyStr, so the Chained state is unwritable and the function is total (plan.secret_name, no match, no fallback). Dropped now-unused std.credentials imports. Verified by execution: srv3/srv4 plan witnesses (now assert secret_name directly) + bmc_onboard load, all green. rotated_credential/Chained gone from the corpus. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): dedicated fleet-automation SA scoped to the SSH private key Created service account fleet-automation@gunbai-secrets (least-privilege: secretAccessor on fleet-automation-ssh-key only, mirroring bmc-assimilator's scoping). Grounded in the model: fleet_automation_sa_email + SecretOwner record tying the SA to the private-key secret, so "who owns the private key" is answered in the repo, not just in GCP. Binding applied out-of-band (provenance recorded); full WIF SecretAccessGrant modeling is follow-up. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): bake fleet SSH keys into autoinstall, disable password SSH Wire the access model into the OS install: UbuntuAutoinstallPayload gains ssh_authorized_keys (List<SshPublicKey>) + ssh_password_auth; os_install_emit renders the subiquity ssh section with authorized-keys (operator + automation public keys) and allow-pw. srv3 payloads set fleet_authorized_keys + allow-pw false — installed hosts trust the fleet keys and refuse password SSH. Verified by execution: srv3_os_install_emit witnesses green, incl. a new discriminating one asserting both key lines present + "allow-pw: false". Note: identity.password still carries the bootstrap hash; per-host strong console break-glass credential is part of Step B (per-host install identity). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(srv4): autoinstall payload + seeded-ISO rows (Step B) srv4 host identity baked at install time: srv4_autoinstall_identity (hostname srv4, console break-glass hash; plaintext in Secret Manager host-srv4-console) + srv4_ubuntu_autoinstall_on_iso (NoCloudLocal, DirectLayout, fleet SSH keys, allow-pw false). srv4 seeded-media artifact rows + srv4_seeded_install_media_remaster mirror srv3, driven by the same install_media_remaster_script builder. Dry-run verified (typechecks, script generates, ExitSuccess). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): model UEFI Shell + boot-config solver (dissolve manual UEFI GUI step) The manual "enter UEFI setup, enable PXE / set boot" GUI step becomes a grounded, solvable model: - extdeps/firmware/uefi_shell.dag: UEFI Shell command surface (bcfg boot dump/add/mv/rm, map, reset) cited to the UEFI Shell 2.2 spec, with a renderer to the real command text + a script folder. - gunbc/uefi_boot_config.dag: DesiredBootSource (install media | PXE entry) -> bcfg command sequence — the UEFI-shell realization of the same "what to boot" intent the Redfish BootSourceOverride path already models (§2, one intent / two realizations). srv4_uefi_install_boot targets fs0:\EFI\BOOT\BOOTAA64.EFI. Verified by execution: witnesses assert the exact bcfg sequence for install-media boot and for PXE-entry reorder. Next: SOL send transport (extend serial_console, currently capture-only) to drive these over obmc-console into srv4's UEFI shell. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi/sol): SOL send transport + drive UEFI-shell boot-config over IPMI SOL Confirmed live first (operator's caution): the ASRock ALTRAD8UD OpenBMC 2.07.00 supports IPMI SOL (ipmitool -I lanplus sol info → Enabled, ADMINISTRATOR, port 623). That capability was unmodeled — grounded it now: BmcCapability gains CapabilitySerialConsole, added to the 2.07.00 list with a live-probe provenance row. Transport: extdeps.bmc.serial_console gains SolConsoleTransport::IpmiSol + SolConsoleSendIntent + sol_console_send_script (ipmitool sol activate with piped input via IPMI_PASSWORD -E; obmc-console send arm too; RedfishSerialInterface send fail-closed as read-only). Runner: gunbc.uefi_shell_over_sol turns the solved bcfg sequence into serial input (\r-submitted) and a SOL send script; srv4_uefi_boot_config_sol_send_intent targets .195. So the manual UEFI GUI step is now: solve DesiredBootSource → bcfg → drive over SOL, fully executable. Verified by execution: witnesses assert the srv4 send carries the bcfg sequence, the script uses ipmitool sol activate, and the ASRock 2.07.00 row declares the serial-console capability. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(sol): IpmiSol exhaustiveness in srv3_sol_console_capture witness Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): model the UEFI Shell command surface + observable environment Back up and ground the real shell interaction (not ad-hoc poking): - Command surface expanded: connect -r (ConnectRecursive), devices (ListDevices), ifconfig (list / set dhcp / set static) alongside bcfg/map/reset — the commands actually used driving srv4 over SOL, cited to the UEFI Shell 2.2 spec. - Observable environment types: UefiNetworkInterface (+ UefiMediaState), UefiBootOption, UefiDeviceMapping, UefiShellEnvironment — so the interaction is observe->decide->act. - gunbc.srv4_uefi_observed: srv4's ACTUAL environment captured live over SOL 2026-07-21 (map -r, bcfg boot dump -v, ifconfig -l): NVMe with Windows Boot Manager + EFI Shell, eth0/eth2 media present (eth0 link-local 169.254.0.18), eth1/eth3 disconnected. Finding that motivated this: UEFI network stack is ALREADY up in srv4's shell (eth0 has media) — PXE-enable via GUI is unnecessary; ifconfig -s eth0 dhcp reaches the network directly. Windows-on-disk confirmed (operator OK'd wipe). Verified by execution: new commands render, srv4 observed env asserts eth0-has-link + Windows-present. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): boot-install decision/diagnostic model (observe→diagnose→decide→act) Generalize the "we're at a UEFI shell, now what?" case into a goal-directed decision procedure over the observed environment: - DesiredOutcome = InstalledFleetNode (the goal: wipe + unattended Ubuntu). - diagnose_boot_install(env) -> BootInstallSituation: pure read of the observed UefiShellEnvironment → InstallMediaReady | NetworkReady | NetworkUpNeedsDhcp | NoBootSourceAvailable. Fail-closed: no media + no link says so, never pretends. - decide_boot_install(situation, goal) -> BootInstallAction: goal-directed; refusal is a first-class outcome (RefuseNoSource), not a silent no-op. - boot_install_commands(action) -> List<UefiShellCommand>?: Absent for a refusal — a caller cannot extract a "do nothing" sequence and mistake it for progress. Grounded on srv4's real observed env: diagnoses NetworkUpNeedsDhcp{eth0} (media up, link-local) → DhcpThenNetworkBoot → ifconfig -s eth0 dhcp. Discriminating fail-closed control witness: no-media/no-link env → RefuseNoSource → Absent commands. Verified by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc): model self-contained BMC netboot serve (no runtime central server) Answering "why srv1?" — it isn't needed at runtime. Model the BMC as the netboot host: gunbc.bmc_netboot_serve.BmcNetbootServePlan + srv4 instance. - bmc_netboot_serve_command: busybox httpd -f -p 8080 -h /tmp/netboot (the BMC hosts the ~88MB bootstrap: kernel/initrd/grub + a staged static busybox). - bmc_netboot_grub_cfg: boots /vmlinuz + /initrd with url= at the Ubuntu MIRROR (host streams the ~1.5GB bulk directly, never on the BMC) and ds=nocloud-net;s= at the BMC's own seed dir. - bmc_netboot_nocloud_user_data: the served seed = autoinstall_user_data(srv4 payload) — carries fleet SSH keys + allow-pw:false, same emit as the on-ISO path. So provisioning is BMC + internet: no central serve host at runtime; srv1's only role is one-time (cacheable) extraction of the 88MB bootstrap from the ISO. Scaffold-marked (medium-as-string ssh/httpd glue) like nbd_proxy_serve. Verified by execution: grub.cfg targets mirror-bulk + BMC-seed, serve cmd is busybox httpd, served seed carries the fleet keys. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(bmc/netboot): model components structurally in extdeps (no concat blobs) Per operator direction — model each piece appropriately in extdeps first, legibly, instead of hand-built concat strings: - extdeps/firmware/kernel_cmdline.dag: KernelCmdlineArg = KernelFlag | KernelKeyValue; kernel_cmdline_render via join/map (cited to kernel-parameters.rst). - extdeps/bootloader/grub.dag: GrubConfig / GrubMenuEntry (structured), grub_config_render via join — replaces the string-blob grub cmdline pattern (cited to the GRUB manual). - extdeps/tools/busybox.dag: busybox CliTool + service busybox.Httpd.Serve with structured argv transport (the idiomatic form, like curl.Http). - extdeps/firmware/uefi_http_boot.dag: UefiHttpBootEntry + provisioning variants (cited to UEFI 2.10 HTTP Boot). gunbc.bmc_netboot_serve recomposed to build a GrubConfig + UefiHttpBootEntry from the plan (no bespoke concat); grub.cfg, http-boot target, and BMC-served nocloud seed all derive from structured values. Bulk from the Ubuntu mirror, seed from the BMC. Verified by execution: grub.cfg renders the full structured cmdline, http-boot entry targets the BMC url, served seed carries the fleet keys. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): model BMC ssh transport + structured staging manifest - extdeps/bmc/ssh.dag: service bmc.Ssh (ExecScript + PutFile) over sshpass -e (password via SSHPASS env, never argv) — structured argv, mirrors curl.Http. - gunbc.bmc_netboot_serve: staging modeled as a structured manifest (BmcStagedFile / StagedContentSource = InlineText | LocalArtifact | FetchFromUri): busybox+kernel+initrd+grub as LocalArtifact, the rendered grub.cfg + nocloud user-data/meta-data as InlineText. Separates WHAT must be on the BMC from HOW it gets there. Verified: manifest stages the rendered grub.cfg (ds=nocloud-net) and the seed (fleet keys) inline, 7 files. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(exec): transport seam — one command, N transports (§3, no forked blobs) extdeps/exec/command.dag: ShellCommand { argv } + CommandTransport = LocalShell | SshExec { ssh_target }; command_over_transport wraps a command's argv with the transport prefix; shell_command_render joins to a string. One operation, chosen transport — not a per-site command blob. - busybox: service busybox.Httpd removed in favor of busybox_httpd_command -> ShellCommand (single authority for the command shape; runs local OR over BMC-ssh via the seam, no dual representation). - bmc.Ssh: ExecScript removed (superseded by SshExec transport); PutFile kept for file transfer. - bmc_netboot_serve: the serve command is busybox_httpd_command over bmc_transport (SshExec root@bmc); local and BMC renderings both derive from it. Discriminating witness serve_command_one_shape_two_transports: the same command renders "busybox httpd -p 8080 -h /tmp/netboot" locally and the sshpass-wrapped form over the BMC transport. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): orchestration provision func (realize via the seam) bmc_netboot_provision: sequences the staged manifest + serve — mkdir + serve go through the extdeps.exec.command seam (bmc_netboot_run_bmc), artifacts via bmc.Ssh.PutFile, rendered grub.cfg/seed via Filesystem.Write then PutFile. process_exit_first_failure collects the first failure (no fabricated success). srv4_bmc_netboot_provision is the zero-arg entry. bmc.Ssh.PutFile gains a mock_response for hermetic dry-run. Marked realization scaffold. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc/netboot): httpd command uses the staged busybox binary (found by live run) Live provision revealed the serve invoked the BMC's system busybox (no httpd applet) instead of our staged static busybox. busybox_httpd_command now takes busybox_bin; bmc_netboot_serve_command_local passes the staged path (/tmp/netboot/busybox). Witness updated to the staged-path rendering. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): model the busybox cross-build (reproducible, not manual) - extdeps/exec/command: shell_command_render now shell-quotes each arg (handles args with spaces like EXTRA_CFLAGS="-march=... -mfloat-abi=..."), robustness fix. - gunbc/command_runner: run_shell_command / run_shell_commands — generic sequential runner over the seam with short-circuit (fold-with-effects, verified). - extdeps/tools/busybox: busybox_source_1_36_1_url; apt package_gcc_arm_linux_gnueabi. - gunbc/busybox_bmc_build: BusyboxCrossBuildPlan + busybox_build_commands (fetch → extract → defconfig → enable static → disable TC → cross-compile armv5te soft-float → install artifact) + busybox_bmc_build_run. Solves the BMC-httpd wall found live: the AST2500 (armv6, no VFP) SIGILLs on prebuilt busybox httpd; our conservative-flags build runs clean (verified: httpd serves HTTP 200 on the BMC). busybox_bmc_build_run regenerated the artifact from source end-to-end. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc/netboot): srv4 boot NIC is eth2 (leases DHCP), not eth0 (found live) eth0 has media but its UEFI DHCP falls back to link-local; eth2 leases 192.168.1.196 on the LAN segment with the BMC. Plan boot_interface + witness updated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * srv4 fleet subsumption + BMC virtual-media install path + modeling cleanup Subsume srv4 into the fleet and get it onto GitHub Actions runners, plus the supporting install-path modeling and several dissolved shell/§3 forks found along the way. Fleet membership (srv4): - srv4_host + samsung_970_evo_500gb_catalog (its actual drive, cited), LAN endpoint 192.168.1.196, srv4_offer, deployed_intent_v1_srv4. Placement solver now allocates srv4 runner slots (fleet_concurrent_runs 30->40). Runner deploy (the width-INCREASE gap, now modeled): - runner_host_deploy.dag: RunnerHostDeploy intent citing the ctrl installer (install-actions-runner.sh) as the bound realization handler (§3 cite-upstream, not re-coined). Renders the CTRL_RUNNER_* invocation, the App-key SecretRef, and the actions-runner@srv4-NN enables. srv4: user briansrls, 5 slots (disk-cap note for the 500GB NVMe vs 2TB fleet). Execution-surface honesty + toolchain provisioning (§5 model-reality gap): - fleet_intent_execution_surface no longer lies: container_runtime Present{Docker} + toolchains [sccache] instead of none/[]. - extdeps/cache/sccache.dag: SccacheBinaryRelease (pinned v0.15.0 + per-arch sha256, cited to mozilla/sccache/releases) + install script. - extdeps/container/docker_ce.dag: DockerCeAptRepo + packages + rootless-docker apt prereq install, cited to docs.docker.com. BMC virtual-media install path (used to install srv4 end-to-end): - extdeps/storage/nbd.dag, extdeps/linux/usb_gadget.dag (typed ConfigfsOp list, not scattered concats), gunbc/bmc_virtual_media.dag: nbd-server -> nbd-client -> configfs mass_storage USB gadget. Unified under extdeps/bmc/virtual_media.dag VirtualMediaIntent with the existing nbd-proxy-websocat path (§3 fork dissolved). - extdeps/firmware/uefi_shell.dag + gunbc/bmc_netboot_shell_boot.dag: shell-native tftp/execute boot modeling. Install bugfixes (root-caused live, captured in the model + witnesses): - grub.dag: quote kernel cmdline args containing ';' (grub command separator) — ds=nocloud;s=... was truncated at ';', dropping the seedfrom, so autoinstall fell to interactive. grub_cmdline_arg_render + the seeded-media builders quote it. - ubuntu_seeded_install_media_remaster.dag: xorriso -boot_image any replay (was mkisofs, which destroyed the arm64 El Torito/ESP boot structure); instance-id derived from hostname (was hardcoded srv3). All new modeling lands with witnesses (green) and dissolution markers on the shell-as-string leaves. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plans: fleet subsumption manual-gaps receipt (srv4 hand-steps -> modeling backlog) Modeled plan doc capturing every step of srv4 install+subsumption that was done by hand — each a modeling gap. Two families: (A) credential handling (every temp credential file = a missing MaterializedSecret lifecycle; reach-secrets ADC; SecretRef liveness after the stale App-key 401) and (B) provisioning (runner SLOT provisioning = the width-INCREASE gap fleet-converge.sh already names, documented in full: pinned ActionsRunnerRelease + per-slot dir seed + count reconcile, all hand-unrolled this time; fleet runner-user; fresh-host prereqs; configfs virtual-media install actuator + media-detach lifecycle). Each item carries acceptance tier + RED control; the plan's dissolution trigger retires item-by-item, fully gone when srv5 subsumes with zero hand-run shell. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * review 41721: shell_quote escapes embedded apostrophes (witnessed); IPv4 link-local/removable-media classifiers grounded on extdeps.firmware.uefi_shell rows (prefix test, cited tokens, dissolve-on to parsed device-path); bmc_netboot_provision folds the staging manifest (single authority; hand-unrolled sequence deleted; FetchFromUri refuses typed) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * plans: fold srv4 host-convergence OOM receipt into the manual-gaps doc Section C added: the 2026-07-23 follow-on where srv4 OOM-killed live PR CI. Sharper framing than the install-time hand-steps — this is an ENROLLMENT failure: srv4 is not a member of the modeled fleet (fleet_intent declares srv1/2/3 only), so the converge derivation cannot name it; the runner installer hand-pointed at srv4 made it a member in GitHub's eyes and a ghost in the model. Records: (1) model-without-actuator + emit-unprovable (KnobUnimplemented refusal AND fleet_converge_emit at 104 compile errors, so converge can neither apply nor emit today) — the displaced-cost pricing for 2-converge-reland; (2) the interim actuation receipt (swap 8->127G, per-slot MemoryMax/SwapMax inf->16G/32G derived-equal on identical 125GiB RAM, oomd installed+active, reclaim timer active — each interim, dissolution = enrollment + converge lane); (3) the three fixes it prices — actuation lane, SwapDevice modeled axis, and the enrollment wall as construction (installer refuses on a host absent from fleet_intent). Canonical host-state rows stay on the operator sheet (1a lane); this doc is the incident receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * crypto.hash: single-variant coproduct via leading-pipe form; verify-line rendering re-homed beside the Digest authority type HashAlgorithm = Sha256 parsed as a type ALIAS to a nonexistent type (the grammar's single-name RHS form), so no Sha256 variant constructor existed and the sccache digest witness failed at runtime with 'undefined variable: Sha256'. The leading-pipe form selects the coproduct parse path explicitly. digest_shell_verify_line moves into extdeps.crypto.hash so the match over HashAlgorithm lives beside its authority; sccache.dag consumes it with the file path as a parameter. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * Regenerate DESIGN.md + fleet-converge.sh from .dag authorities (drift gate fix) CI generated_artifact_drift_gate_passes was red on 05c6a3b from two latent drifts, both now regenerated from their authorities via main_wet: - DESIGN.md: the srv4 open-threads bullet was hand-added to the projection but not to design_document.dag (its authority). Added as an li() row there; DESIGN.md regenerated to match. docs/plans/srv4-bmc-onboarding-gap.md is a genuinely new file needing a reference, so the bullet stays — just homed in the .dag single authority, not the generated .md. - .github/fleet-converge.sh: srv4 fleet enrollment updated the FleetConvergeArtifact authority; the committed script lacked the 'gunbc converge --host srv4' line. Regenerated. Verified: generated_artifact_drift_gate_passes returns true (exit 0). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * De-fork BMC scp transport onto the single ssh/scp posture authority (review 41797) bmc/ssh.dag (new in this PR) re-minted the sshpass -e + StrictHostKeyChecking=no + UserKnownHostsFile=/dev/null posture that extdeps.exec.command establishes as the single authority — a §3 parallel representation in the same PR that adds the unified transport seam. Fixed by construction, not a second copy: - command.dag: extract sshpass_prefix() and ssh_host_key_override_opts() shared helpers; ssh_exec_prefix now composes them; add scp_command(local, remote) that reuses the SAME two helpers (scp is a distinct binary with the host in remote_target, so it cannot compose through command_over_transport's ssh prefix — but it shares the posture authority). - bmc_netboot_serve.dag: bmc_netboot_put_path renders scp_command via the same shell.Exec.Run + shell_command_render path as bmc_netboot_run_bmc; the extdeps.bmc.ssh import and the whole bmc.Ssh service are deleted. - Two discriminating witnesses: scp render carries the exact shared posture argv; red control asserts no second/forked posture. All bmc_netboot_serve witnesses PASS; gate-equivalent compile has zero hard diagnostics. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * De-fork BMC scp: trigger-text + discriminating witnesses (review 41797) Completes the scp de-fork commit: dissolution trigger now names scp_command (the single ssh/scp posture authority) instead of the deleted bmc.Ssh.PutFile, and adds two witnesses proving the scp path carries the shared posture argv and never a second/forked one. All bmc_netboot_serve witnesses PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * Accept #7121 deletion of .github/fleet-converge.sh (paper transport retired; FleetConvergeArtifact deregistered) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Regen ci.yml: drop fleet-converge.sh from auto-heal add-list (deregistered in #7121) The generated ci.yml auto-heal git-add list is derived from the artifact registry; #7121 removed FleetConvergeArtifact, so the regenerated list no longer names .github/fleet-converge.sh. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Regen ROADMAP.md: restore main's ts-ui-model row + drop trailing blank line (serializer drift) A bad merge had reverted main's belt-B roadmap row from roadmap_authority.dag; restored from main. Regenerating with a fresh seed also drops a trailing blank line the current markdown serializer no longer emits (main's committed copy is stale, kept green there by the auto-heal job). Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Merge main + regen artifacts with new-emitter seed (drop ROADMAP.md trailing line) Branch was behind main's v1_compiler_emit_rust.rs (Lane D #7098); merged main and rebuilt the seed. Emitted-Rust artifacts now match; ROADMAP.md re-regenerated without main's stale trailing blank line. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Enroll srv4 witnesses in the eligibility census (864 -> 876) My PR added ~12 witness test entries; main's witness_entry_eligibility_census (#7111) fail-closes the floor when a witness entry has no census TSV row (panic at cli_run.rs:8508). Bumped the declared count 864->876, regenerated the census TSV + histogram, updated the count assertion. Sync + count witnesses green by execution; the previously-panicking argv_command_render entry is now present. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Merge main (#7110) + regen census TSV to match merged roster Kept branch current with main's witness/census churn; regenerated the eligibility census TSV+histogram so committed == emit(merged roster) (876 entries, emit's internal roster==count check green). Generated-artifact drift clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Worker attestation
npm test,cargo test) and the result.Closes #Ndirective.Summary
Extinguishes the dotted-name emit-shape classes tracked in
docs/probes/curated_cargo_frontier_probe_sweep.tsvacross every discovered rendering position — pattern (00_compile/03_ingest, "brace root"), construction (01_tokenize, "struct literal body without path"), type (02_parse/source_authority, "dotted-in-struct"), fn-sig-type (5 sibling render fns), VALUE-expression, and CALL-callee — all instances of the same systemic §5 fail-open: a namespace-qualified dotted name (postsource_authority, e.g.v2.std.node.Edge) reaching Rust-emit as literal text instead of being reduced to its bare terminal segment via the single authorityqualified_last_segment(v1.std.core).Fixed at the render seams in
src/v1/05_emit_rust.dag(variant-pattern rendering,emit_typed_record_lit) and one insrc/v1/coercion.dag(coerce_primitive_type'sAbsentfallback) — no per-call-site patch, one shared local/helper per seam. Fixing these unmasked a fourth, structurally identical defect in fn-signature/closure-parameter TYPE position (render_rust_fn_sig_typeand 4 sibling functions), fixed via one shared helper,rust_fn_sig_leaf_name, reused at all 5 call sites.Newly folded in this session (reported cross-session by sharp-bee-290 as a fresh
E0425 cannot find value v2class on a kept04_inferprobe crate): a fifth and sixth sibling defect in the same family, both inemit_value_ref_ident/emit_typed_call(src/v1/05_emit_rust.dag):emit_value_ref_ident'sAbsentregistry-miss arm fell through toemit_ident(name: name, ...)with the full dotted string still attached (emit_identhas no dot-awareness); fixed to pass the already-computedleaf(the samequalified_last_segmentreduction thePresentarm already keys its lookup on).emit_typed_call's callee identifier rendering (func_ident) and its registry lookup (callee) both keyed on the raw dottedfuncstring instead of its leaf; fixed by re-keying the lookup onqualified_last_segment(func)and reusingemit_value_ref_identdirectly for the identifier itself (DESIGN §2/§3 — one shared helper, not a third forked derivation).Root-causing this pair by execution turned out to unmask far more than the single reported
materialization_carriersoccurrence: re-sweeping the entire curated cargo probe corpus (10 modules) shows the CALL-callee fix alone resolved thenamespace_resolutionclass (E0433 UriScheme/E0433 NamedEdgeTargetLookup) on five more modules —04_infer.dag,05_eval.dag,06_translate.dag,05_emit.dag,program_partition.dag— plus03_normalize.dag's distinctE0423class, all of which now converge on the same pre-existingHARNESS_ARTIFACT_std_dupfloor the other modules already sit on.materialization_carriers.dagitself lands on a different, unrelated, out-of-scope class (E0107 missing generics for struct Measure) — confirmed by execution (direct inspection of the freshly generated Rust) that the reportedE0425signature is gone.src/v1/stage0/src/*.rsregenerated viaregen_stage0after each.dagedit to stay in sync (confirmed idempotent — a second consecutive regen produces zero diff).Also relocated the three
orch_while_*golden-witness tests (v2.test.long.orchestration_while_emit) that were tripping the falsifier — diagnosis: their ownevalexceeds the operator's 5-second fast-lane budget (2026-07-12 rule), not a behavior regression. No test content was changed; all three still assert byte-identical goldens. Re-run locally by execution post-relocation, all green:orch_while_locate_pipeline_matches_golden_holds→trueorch_while_step_matches_golden_holds→trueorch_while_emit_has_teeth_holds→trueVerification (by execution, not just source edits)
Re-probed all ten modules tracked in
docs/probes/curated_cargo_frontier_probe_sweep.tsvwithCSSL_STD_SEED_LINK=1 scripts/curated_cargo_probe_one.sh(gunbc rebuilt at each probe head, correctly ordered:regen_stage0first, then rebuildgunbc/cssl_assemblefrom the regenerated stage0):00_compile.dagHARNESS_ARTIFACT_std_dup(226 diag)01_tokenize.dagHARNESS_ARTIFACT_std_dup02_parse.dagHARNESS_ARTIFACT_std_dup(59 diag)03_ingest.dagHARNESS_ARTIFACT_std_dup(226 diag)source_authority.dagHARNESS_ARTIFACT_std_dup(94 diag)03_normalize.dagE0423expected value, found cratestd(27 diag)HARNESS_ARTIFACT_std_dup(9 diag)06_translate.dagE0433cannot find typeUriScheme(8 diag)HARNESS_ARTIFACT_std_dup(8 diag)04_infer.dagE0433cannot find typeNamedEdgeTargetLookup(0 diag)HARNESS_ARTIFACT_std_dup(0 diag)05_eval.dagE0433cannot find typeNamedEdgeTargetLookup(0 diag)HARNESS_ARTIFACT_std_dup(0 diag)program_partition.dagE0433cannot find typeUriScheme(8 diag)HARNESS_ARTIFACT_std_dup(8 diag)05_emit.dagE0433cannot find typeUriScheme(8 diag)HARNESS_ARTIFACT_std_dup(8 diag)materialization_carriers.dagE0425cannot find valuev2(46 diag)E0107missing generics for structMeasure(50 diag, unrelated, out of scope)Every named dotted-name-rendering class is now zero-row in
docs/probes/curated_cargo_frontier_probe_sweep.tsv. What remains on nine of the ten modules is the pre-existingE0255: the name 'List' is defined multiple times— the curated-seed-link cssl-assembly std-collision, already tracked as a probe-harness artifact (gate_a_flip_probe_witness_std_dup_reason, seev1_deletion_plan.dagstd_dup_assembly_fix) and shared by the other cargo-stage modules in this sweep (03_resolve,fold_lowering). This is not a flip toSelfEmitted—measured_blockerstaysEmitSurfaceGap/SeedRetainedon all affected rows insrc/v2/compiler/self_host/frontier.dag; onlylocated_reasonmoves off the now-retired reasons onto the shared std_dup one (or, formaterialization_carriers, ontogate_a_flip_probe_unresolved_compiler_error_reasonfor its distinct residual class), so the roster names what was actually last measured (mirrors the 2026-07-21 receipt-correction precedent).Full diagnosis recorded in
honest_frontier_refresh_2026_07_23_note(src/v2/compiler/self_host/frontier_probe_types.dag).Known, separately-owned red — not this lane's responsibility: per a cross-session heads-up from Lane A's cadence check (sharp-bee-290), behind the now-green
orch_while_*falsifier class there is a known second wet-batch red waiting: the03_normalizebehavioral receipt fails on main (stale hand shims vs. the post-#7057 grown closure, proven by execution on a control worktree). This is a distinct signal from the same-named module's probe-sweep row above (which only measures cargo-compile of the curated seed-link crate, not the behavioral receipt) — the row change here does not fix, and is not claiming to fix, that separately-dispatched red. If the falsifier's wet batch advances and reds on the03_normalizeshim class after this PR merges, that is the other lane's counted red, not a regression from this change.Test plan
curated_cargo_probe_one.shre-run by execution on all 10 tracked modules (table above) — every named dotted-name class gone,docs/probes/curated_cargo_frontier_probe_sweep.tsvupdated with fresh rows.src/v2/compiler/self_host/frontier.daglocated_reasonupdated on the 5 rows whose measured class actually changed (04_infer,05_eval,06_translate,05_emit,program_partition→ std_dup;materialization_carriers→ unresolved-compiler-error), confirmed by compilingfrontier.dagthrough its import closure and grepping the error output for zerofrontier.dag-attributed errors (the closure's 94 remaining errors are pre-existing, unrelatedunlisted import useissues elsewhere in the tree).regen_stage0run and confirmed idempotent (zero diff on re-run) after each.dagedit.gunbc run --claim-runon all threeorch_while_*test fns at their new location — alltrue.05_emitfamily) — this PR only touches rendering (pattern/construction/type/fn-sig-type/value-expression/call-callee leaf-name extraction), never import-list synthesis.