Repository navigation
SHELL-DAG: NBD proxy — observe-side port/unit read-back on cited extdeps.systemd, retire the systemd-run WitnessBin scaffold - #8582
Merged
Conversation
…ystemd, retire systemd-run WitnessBin
host_effect_nbd_proxy_serve_dissolution_trigger read "DISSOLVES WHEN observe-side
port/unit query is grounded on cited extdeps.systemd/systemctl read-back and typed
argv dispatch retires WitnessBin systemd-run scaffolding." Both conditions are now
met, so the module's disposition is a std.disposition.Terminal, not a Scaffold.
Retired: host_effect_nbd_proxy_serve_witness_bin_run_argv's direct
gunbc.WitnessBin.Run(...) calls for systemd-run transient unit start and systemctl
stop.
Replaced with: the typed-argv-exec dispatch pattern already used by
systemctl_status_read.dag / systemctl_show_read.dag, routed through
gunbc.typed_argv_exec and v2.std.operation_argv:
- extdeps/systemd/systemd_run.dag: new extdeps module citing systemd-run's own
man page (systemd-run is a distinct upstream binary from systemctl), with a
RunTransient operation and the variadic command_argv authority.
- extdeps/systemd/systemctl.dag: added a Stop operation mirroring Restart.
- gunbc/systemd_run_transient.dag, gunbc/systemctl_stop_run.dag,
gunbc/systemctl_is_active_read.dag: typed dispatch modules over
LocalShell/SshShell/FleetSsh, refusing EmitArtifactThenThinRun, following the
exact structure of systemctl_status_read.dag / systemctl_show_read.dag.
Grounded: host_effect_nbd_proxy_serve_observe_port now reads
gunbc.systemctl_is_active_read (systemd.Systemctl.IsActive) against the transient
websocat unit name -- the unit name is this scope's identity anchor, so no
MainPID/port-scan primitive is needed. active -> PortObserved (with a documented
pid:0/cmdline sentinel that classify_process_port never inspects), inactive ->
PortAbsent, typed capture refusal -> PortInaccessible. Previously this was an
unconditional PortInaccessible stub.
Tests: nbd_proxy_serve_transport_witness_test.dag gained direct-arm coverage for
all three observe_port outcomes plus a LocalShell wiring witness, and argv-authority
round-trip witnesses for the three new typed operations.
srv3_host_effect_apply_witness_test.dag's "observe unimplemented" witness now
targets the one transport that genuinely cannot observe (EmitArtifactThenThinRun),
and its dissolution-carrier witness asserts the Terminal disposition instead of a
retired Scaffold. witness_deferral_freeze.dag's frozen row for that file is
shrunk (not grown) to drop the two identities that no longer exist under their old
names, with a shrink-log entry recording why.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The three new argv-authority test wrappers shared the exact name of the function they called (systemd_run_transient_operation_argv_matches_authority etc.), so the test fn's own zero-arg declaration shadowed the real one and the call resolved to itself instead of the intended function. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…er as PortInaccessible ProcessPortObservation gains a third state, PortObservationRefused, carrying the real refusal reason instead of collapsing "I could not observe" into "the port is genuinely inaccessible" (DESIGN.md recurring failure mode). classify_process_port maps it to the existing (previously unreachable) ObservationVerdict.UnknownRefused; classify_process_port_upsert threads the real reason through rather than the fixed "port observation refused" fallback string. host_effect_nbd_proxy_serve_observation_from_is_active_capture routes UnitIsActiveCaptureRefused into the new state, preserving `reason` instead of discarding it. The two consumers are dispositioned: the observe-unimplemented predicate now checks for the EmitArtifactThenThinRun refusal signature rather than the no-longer-produced "port inaccessible" string, and the srv3 apply witness comment is corrected to describe the new routing. A discriminating witness (nbd_proxy_observe_port_capture_refusal_yields_port_observation_refused_not_answer) exhaustively matches all ProcessPortObservation arms so it goes RED if a refusal is ever rendered as PortInaccessible or any other answer state again. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
calm-carp-788.Pushing to
session/calm-carp-788advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan