Skip to content

SHELL-DAG: NBD proxy — observe-side port/unit read-back on cited extdeps.systemd, retire the systemd-run WitnessBin scaffold - #8582

Merged
briansrls merged 3 commits into
mainfrom
session/calm-carp-788
Aug 19, 2026
Merged

briansrls merged 3 commits into
mainfrom
session/calm-carp-788

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session calm-carp-788.
Pushing to session/calm-carp-788 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

…ystemd, retire systemd-run WitnessBin

host_effect_nbd_proxy_serve_dissolution_trigger read "DISSOLVES WHEN observe-side
port/unit query is grounded on cited extdeps.systemd/systemctl read-back and typed
argv dispatch retires WitnessBin systemd-run scaffolding." Both conditions are now
met, so the module's disposition is a std.disposition.Terminal, not a Scaffold.

Retired: host_effect_nbd_proxy_serve_witness_bin_run_argv's direct
gunbc.WitnessBin.Run(...) calls for systemd-run transient unit start and systemctl
stop.

Replaced with: the typed-argv-exec dispatch pattern already used by
systemctl_status_read.dag / systemctl_show_read.dag, routed through
gunbc.typed_argv_exec and v2.std.operation_argv:
  - extdeps/systemd/systemd_run.dag: new extdeps module citing systemd-run's own
    man page (systemd-run is a distinct upstream binary from systemctl), with a
    RunTransient operation and the variadic command_argv authority.
  - extdeps/systemd/systemctl.dag: added a Stop operation mirroring Restart.
  - gunbc/systemd_run_transient.dag, gunbc/systemctl_stop_run.dag,
    gunbc/systemctl_is_active_read.dag: typed dispatch modules over
    LocalShell/SshShell/FleetSsh, refusing EmitArtifactThenThinRun, following the
    exact structure of systemctl_status_read.dag / systemctl_show_read.dag.

Grounded: host_effect_nbd_proxy_serve_observe_port now reads
gunbc.systemctl_is_active_read (systemd.Systemctl.IsActive) against the transient
websocat unit name -- the unit name is this scope's identity anchor, so no
MainPID/port-scan primitive is needed. active -> PortObserved (with a documented
pid:0/cmdline sentinel that classify_process_port never inspects), inactive ->
PortAbsent, typed capture refusal -> PortInaccessible. Previously this was an
unconditional PortInaccessible stub.

Tests: nbd_proxy_serve_transport_witness_test.dag gained direct-arm coverage for
all three observe_port outcomes plus a LocalShell wiring witness, and argv-authority
round-trip witnesses for the three new typed operations.
srv3_host_effect_apply_witness_test.dag's "observe unimplemented" witness now
targets the one transport that genuinely cannot observe (EmitArtifactThenThinRun),
and its dissolution-carrier witness asserts the Terminal disposition instead of a
retired Scaffold. witness_deferral_freeze.dag's frozen row for that file is
shrunk (not grown) to drop the two identities that no longer exist under their old
names, with a shrink-log entry recording why.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 19, 2026 21:57
gunbc-ci-auto-heal and others added 2 commits August 19, 2026 22:14
The three new argv-authority test wrappers shared the exact name of
the function they called (systemd_run_transient_operation_argv_matches_authority
etc.), so the test fn's own zero-arg declaration shadowed the real
one and the call resolved to itself instead of the intended function.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…er as PortInaccessible

ProcessPortObservation gains a third state, PortObservationRefused, carrying the
real refusal reason instead of collapsing "I could not observe" into "the port is
genuinely inaccessible" (DESIGN.md recurring failure mode). classify_process_port
maps it to the existing (previously unreachable) ObservationVerdict.UnknownRefused;
classify_process_port_upsert threads the real reason through rather than the fixed
"port observation refused" fallback string.

host_effect_nbd_proxy_serve_observation_from_is_active_capture routes
UnitIsActiveCaptureRefused into the new state, preserving `reason` instead of
discarding it. The two consumers are dispositioned: the observe-unimplemented
predicate now checks for the EmitArtifactThenThinRun refusal signature rather than
the no-longer-produced "port inaccessible" string, and the srv3 apply witness
comment is corrected to describe the new routing. A discriminating witness
(nbd_proxy_observe_port_capture_refusal_yields_port_observation_refused_not_answer)
exhaustively matches all ProcessPortObservation arms so it goes RED if a refusal is
ever rendered as PortInaccessible or any other answer state again.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@briansrls
briansrls merged commit 74b9a6e into main Aug 19, 2026
1 check passed
@briansrls
briansrls deleted the session/calm-carp-788 branch August 19, 2026 23:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant