Skip to content

Preserve the transport-seam split: an assumption that compiles clean, passes witnesses, and refuses on every host - #9143

Closed
gunbai-bot[bot] wants to merge 3 commits into
mainfrom
session/smart-ram-730-transport-seam
Closed

gunbai-bot[bot] wants to merge 3 commits into
mainfrom
session/smart-ram-730-transport-seam

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

stern-boar-129 measured this while converting a string-bodied shell install to typed steps. Their session was archived when its PR merged, and the seam annotation they designed was never pushed — so the finding survived only in inter-session messages. This is the durable copy.

Every claim was re-verified against origin/main by a different session before publication, because a finding relayed through messages and re-published is precisely where a detail gets softened.

The finding

One host effect decomposes into two halves with different transport readiness:

  • argv half (publish, rename, daemon-reload, start) — types cleanly on SshShell today.
  • bytes half (write the unit contents) — FleetSsh-only. gunbc.typed_remote_file_write converge_typed_remote_file takes context: FleetSshExecutionContext and shapes through shape_fleet_ssh_exec. No SshShell arm.

And every production route arrives on SshShell: gunbc.host_identity_access host_identity_ssh_access constructs transport: SshShell { ssh_host }, and host_identity_srv1_access…srv4_access are all built by it.

So a conversion assuming this effect is typeable on the transport we use compiles clean, passes its witnesses (which supply a FleetSshExecutionContext), and refuses on all four hosts — reintroducing the exact unreachability the work item exists to close, one layer down, wearing the repair's clothes.

The transferable part

Not care, and not a gate — one question in a specific form:

Answer a population question from what a caller passes, never from what the enum can express.

The enum reading is cheaper, always available, locally valid, and wrong. An arm's existence and its reachability for this operation are different facts with different owners. Same shape as reachability read as occupancy, from the opposite direction.

What this also records

The designed repair has no owner. A landed, uncounted deficit has a frequency of zero by construction, and the lane holding the correct end state (extdeps.ssh.session's dissolve-on names host_effect_realize first) keeps its obligation with no evidence anyone needs it discharged.

One adjacent receipt

install leaves the destination inode unchanged (8280789 before and after), so it writes through rather than renaming — meaning a read-back on the staged file verifies the wrong artifact. Measures a mechanism, not an incident.

— sent from smart-ram-730

gunbc-ci-auto-heal added 2 commits August 24, 2026 21:48
stern-boar-129 measured this while converting a string-bodied shell
install to typed steps. Their session was archived when its PR merged,
and the seam annotation they designed was never pushed — so the finding
survived only in inter-session messages. This brief is the durable copy.

Every claim was re-verified against origin/main by a different session
before publication, because a finding relayed through messages and then
re-published is exactly where a detail gets softened:

  host_identity_ssh_access constructs transport: SshShell, and
  host_identity_srv1..srv4_access are all built by it — so every
  production route arrives on SshShell, zero on FleetSsh.

  converge_typed_remote_file and its neighbours take
  context: FleetSshExecutionContext and shape through
  shape_fleet_ssh_exec. There is no SshShell arm for the bytes half.

  compile_pool_slice_install_body is on main, building a program as a
  String and running it through shell_exec_via_bash.

THE FINDING: one host effect decomposes into an argv half that types
cleanly on SshShell and a bytes half that is FleetSsh-only. A conversion
assuming "this effect is typeable on the transport we use" compiles
clean, passes witnesses that supply a FleetSshExecutionContext, and
refuses on all four hosts — reintroducing the exact unreachability the
work item exists to close, one layer down, wearing the repair's clothes.

THE TRANSFERABLE PART is the question form, not the care: answer a
population question from WHAT A CALLER PASSES, never from WHAT THE ENUM
CAN EXPRESS. The enum reading is cheaper, always available, locally
valid, and wrong — the arm's existence and the arm's reachability for
this operation are different facts with different owners. Same shape as
reachability-read-as-occupancy, from the opposite direction.

Also records that the designed repair HAS NO OWNER, since a landed,
uncounted deficit has a frequency of zero by construction and the lane
holding the correct end state keeps its obligation with no evidence
anyone needs it discharged.

Includes one adjacent receipt: install(1) leaves the destination inode
unchanged (8280789 before and after), so a read-back on the staged file
verifies the wrong artifact.
…ssing context

Requested by deep-ant-102 on review, and it is the requirement most
likely to be lost between publication and dispatch. A refusal saying
only 'no FleetSshExecutionContext' cannot be joined to
extdeps.ssh.session's dissolve-on row without re-deriving the
measurement this brief exists to preserve — so naming the transport that
IS present is load-bearing, not presentation.
@briansrls briansrls closed this Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant