Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
0d2cc47
RLM-2a: typed fleet plan/apply + dashboard deploy receipts, RoadmapLa…
Aug 30, 2026
e50d1d0
RLM-2a: rename the two SystemdUnitProperty variants that collided wit…
Aug 30, 2026
ab0037a
RLM-2a: ListHeadResult arms in exec_start parse; tamper controls matc…
Aug 30, 2026
6f12fde
RLM-2a: split is a std.algebra builtin hidden by the selective import…
Aug 30, 2026
5c35de9
RLM-2a: split is the String method spelling
Aug 30, 2026
74c0dcb
RLM-2a: exec_start argv parse via the typed fold idiom (list_head ove…
Aug 30, 2026
52d3cb8
Merge origin/main into session/crisp-newt-85 (RLM-2a): keep #9752's a…
Aug 30, 2026
7609d22
RLM-2a: the receipt witness names the workflow file through rlm_workf…
Aug 30, 2026
b1839cf
RLM-2a: the two document witnesses grep the emitted ": " separator
Aug 30, 2026
06c2e31
RLM-2a: regenerate fleet-converge.yml from gunbc.fleet_converge_workf…
Aug 30, 2026
7382d27
RLM-2a review 57664: dissolve the two Bool coproduct predicates (per-…
Aug 30, 2026
c6906cd
Merge origin/main (fabric allocation store) into session/crisp-newt-8…
Aug 30, 2026
a2a43a1
Rework for review 5061891290: expected-revision admission before appl…
Aug 31, 2026
e7d171b
Merge main (through 0a6d177619) into session/crisp-newt-85
Aug 31, 2026
4683c48
Review 57708: Microsecond/Second measure carriers for timer cadence a…
Aug 31, 2026
0f764a4
Merge main into session/crisp-newt-85
Aug 31, 2026
9b89da8
Dissolve the stale cadence-comparison residue note: values are compar…
Aug 31, 2026
7722485
Merge main (through b41d56484f) into session/crisp-newt-85
Aug 31, 2026
e49dd85
Review 5062738052: routed health is the release/tree binding and the …
Aug 31, 2026
faaf41e
Review 5063097188 B2 refinement: state the provenance split at the mo…
Aug 31, 2026
05e93e1
Split the freshness machine-readability witness into fresh/stale sing…
Aug 31, 2026
6b90284
Merge main (through a6d6c68d4d) into session/crisp-newt-85
Aug 31, 2026
785cc03
Regenerated .gitattributes on the merged tree (generated_artifact_gat…
Aug 31, 2026
f14021d
Review 57760: Minute carrier for the rlm receipt-job backstop, typed …
Aug 31, 2026
e5e9967
Executing evidence for the target_decision decode refusal: unknown wi…
Aug 31, 2026
f474d96
Review 57773: class-preserving four-arm member reads replace the coll…
Aug 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ DESIGN.md merge=generated-artifact
ROADMAP.md merge=generated-artifact
dag/gunbc/stage0/stage0_crate_layout_generated.dag merge=generated-artifact
dag/gunbc/stage0/stage0_crate_partition_generated.dag merge=generated-artifact
dag/gunbc/stage0/stage0_executable_assembly_generated.dag merge=generated-artifact
docs/design-ledgers.md merge=generated-artifact
docs/plans/budget-tree.md merge=generated-artifact
docs/plans/ci-humming.md merge=generated-artifact
Expand Down
207 changes: 201 additions & 6 deletions .github/workflows/fleet-converge.yml

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions dag/extdeps/github/actions.dag
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,7 @@ data workflow_run_activity_completed: String = "completed"

type Workflow {
name: String
run_name: String?
on: List<WorkflowTrigger>
concurrency: ConcurrencySpec?
jobs: List<Job>
Expand Down
9 changes: 9 additions & 0 deletions dag/extdeps/github/actions_environment.dag
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,15 @@ data github_run_id_variable_name: String = "GITHUB_RUN_ID"
data github_run_attempt_variable_name: String = "GITHUB_RUN_ATTEMPT"
data github_runner_name_variable_name: String = "RUNNER_NAME"

// THE RUN'S REPOSITORY AND WORKFLOW REFERENCE, carried for the same reason the coordinates above
// are. GITHUB_REPOSITORY is `owner/repo`; GITHUB_WORKFLOW_REF is
// `owner/repo/.github/workflows/<file>@<ref>`, the one runner-supplied variable that names the
// workflow FILE a run executes -- the same path the reviewed fleet-desired admission binds through
// the workflow_run event's `path` member. A consumer proving "this run executed THIS workflow"
// reads it here rather than re-deriving the file from a workflow display name.
data github_repository_variable_name: String = "GITHUB_REPOSITORY"
data github_workflow_ref_variable_name: String = "GITHUB_WORKFLOW_REF"

// Missing and present-but-empty stay separate arms, exactly as they do for the sha above. Outside
// Actions every one of these is legitimately absent, which is a different fact from a runner that
// set the variable to nothing, and only the second is a defect in the environment.
Expand Down
25 changes: 25 additions & 0 deletions dag/extdeps/github/workflow_runs.dag
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ data conclusion_authority_consolidation_frontier_rows: List<FrontierRow> = [
type WorkflowRun {
id: Int
name: String?
path: String?
head_sha: CommitSha
status: WorkflowRunStatus
conclusion: WorkflowRunConclusion?
Expand Down Expand Up @@ -128,6 +129,30 @@ service github.WorkflowRuns {
rate_limit: { requests: 5000, per: hour, scope: core }
}

operation GetRun {
input {
auth_token: Secret
owner: String
repo: String
run_id: String
}
output {
run: WorkflowRun
}
readonly
transport rest {
method: GET,
path: "/repos/\{owner\}/\{repo\}/actions/runs/\{run_id\}"
}
response {
200 => WorkflowRun
401 => GitHubErrorShape
403 => GitHubErrorShape
404 => GitHubErrorShape
500 => GitHubErrorShape
}
}

operation ListForRef {
input {
auth_token: Secret
Expand Down
24 changes: 24 additions & 0 deletions dag/extdeps/http/client.dag
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,30 @@ service http.Client {
}
}

operation GetBounded {
input { url: NonEmptyStr }
output { body: String from "stdout", success: Bool from "exit_success" }
readonly
transport shell {
argv: [
"curl",
"-fsS",
"--connect-timeout",
http_client_localhost_connect_timeout_flag(),
"--max-time",
http_client_localhost_max_time_flag(),
"{url}",
]
}
exit {
0 => Unit
nonzero => String "http client bounded GET failed"
}
mock_response {
0 => { body: "", success: false } "hermetic: no live HTTP endpoint; routed observation refuses rather than fabricate a body"
}
}

operation PostJsonFromFile {
input { url: NonEmptyStr, request_body_file: NonEmptyStr }
output { body: String from "stdout", success: Bool from "exit_success" }
Expand Down
8 changes: 7 additions & 1 deletion dag/extdeps/languages/yaml/gha_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -498,7 +498,13 @@ fn optional_env_top(entries: List<YamlKeyValue>?) -> List<YamlKeyValue> {

fn project_workflow_to_yaml(workflow: Workflow) -> YamlValue {
yaml_mapping(entries: concat(
[kv(key: "name", value: yaml_string(s: workflow.name))],
concat(
[kv(key: "name", value: yaml_string(s: workflow.name))],
match workflow.run_name {
Absent => []
Present { value: rn } => [kv(key: "run-name", value: yaml_string(s: rn))]
}
),
concat(
[kv(key: "on", value: workflow_triggers_yaml(triggers: workflow.on))],
concat(
Expand Down
91 changes: 90 additions & 1 deletion dag/extdeps/systemd/systemd.dag
Original file line number Diff line number Diff line change
@@ -1,8 +1,11 @@
module extdeps.systemd

import std.types { NonEmptyStr, String, Int }
import std.types { list_length }
import std.algebra { trim }
import std.types { List }
import std.measure { ByteSize, byte_size, byte_size_count }
import std.measure { ByteSize, byte_size, byte_size_count, Microsecond, microsecond }
import std.checked_arithmetic { checked_int_magnitude, CheckedNat, CheckedNatReady, CheckedNatOverflow }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }
import extdeps.systemd.systemd_contracts { systemd_unit_active_state_wire_contract }
Expand Down Expand Up @@ -52,6 +55,18 @@ type SystemdUnitProperty
| ActiveEnterTimestampMonotonic
| ActiveState
| MainPID
| LoadState
| UnitFileState
| SubState
| Result
| ExecMainStatus
| ExecStartProperty
| User
| WorkingDirectoryProperty
| Unit
| NextElapseUSecMonotonic
| AccuracyUSec
| TimersMonotonic

fn systemd_unit_property_wire(property: SystemdUnitProperty) -> NonEmptyStr {
match property {
Expand All @@ -66,6 +81,18 @@ fn systemd_unit_property_wire(property: SystemdUnitProperty) -> NonEmptyStr {
ActiveEnterTimestampMonotonic => "ActiveEnterTimestampMonotonic" as NonEmptyStr
ActiveState => "ActiveState" as NonEmptyStr
MainPID => "MainPID" as NonEmptyStr
LoadState => "LoadState" as NonEmptyStr
UnitFileState => "UnitFileState" as NonEmptyStr
SubState => "SubState" as NonEmptyStr
Result => "Result" as NonEmptyStr
ExecMainStatus => "ExecMainStatus" as NonEmptyStr
ExecStartProperty => "ExecStart" as NonEmptyStr
User => "User" as NonEmptyStr
WorkingDirectoryProperty => "WorkingDirectory" as NonEmptyStr
Unit => "Unit" as NonEmptyStr
NextElapseUSecMonotonic => "NextElapseUSecMonotonic" as NonEmptyStr
AccuracyUSec => "AccuracyUSec" as NonEmptyStr
TimersMonotonic => "TimersMonotonic" as NonEmptyStr
}
}

Expand All @@ -85,6 +112,68 @@ data systemd_tasks_max_property: NonEmptyStr = systemd_unit_property_wire(proper

data systemd_tasks_current_property: NonEmptyStr = systemd_unit_property_wire(property: TasksCurrent)

// systemd.time(7) TIME SPAN NORMALIZATION, the smallest slice launch standing needs: a span is one
// or more whitespace-separated <value><unit> parts (a bare value reads as seconds), and the units
// below are the documented spellings for the magnitudes systemd renders timer facts in (usec
// through hours). The result is microseconds, systemd's own internal resolution, so "60s" ==
// "1min" becomes decidable equality instead of a string comparison. Unknown units, empty input, or
// a malformed part refuse with Absent -- never a partial sum.
type SystemdTimeSpanPart {
value: Int
unit: String
}

fn systemd_time_span_unit_usec(unit: String) -> Int? {
if unit == "usec" || unit == "us" { Present { value: 1 } }
else if unit == "msec" || unit == "ms" { Present { value: 1000 } }
else if unit == "seconds" || unit == "second" || unit == "sec" || unit == "s" || unit == "" { Present { value: 1000000 } }
else if unit == "minutes" || unit == "minute" || unit == "min" || unit == "m" { Present { value: 60000000 } }
else if unit == "hours" || unit == "hour" || unit == "hr" || unit == "h" { Present { value: 3600000000 } }
else { none }
}

fn systemd_time_span_split(part: String) -> SystemdTimeSpanPart? {
let scan = fold(chars(s: part), init: 0, f: (n, c) =>
if n < 0 { n } else if c >= 48 && c <= 57 { n + 1 } else { 0 - n - 1 })
let digits = if scan < 0 { 0 - scan - 1 } else { scan }
if digits == 0 {
none
} else {
match parse_int(s: substring(s: part, start: 0, end: digits)) {
Absent => none
Present { value: v } =>
Present { value: SystemdTimeSpanPart { value: v, unit: substring(s: part, start: digits, end: string_length(s: part)) } }
}
}
}

fn systemd_duration_usec(text: String) -> Microsecond? {
let parts = filter(split(s: trim(s: text), delimiter: " "), p => p != "")
if list_length(items: parts) == 0 {
none
} else {
let total = fold(parts, init: 0, f: (acc, part) =>
if acc < 0 { acc } else {
match systemd_time_span_split(part: part) {
Absent => 0 - 1
Present { value: vu } =>
match systemd_time_span_unit_usec(unit: vu.unit) {
Absent => 0 - 1
Present { value: mult } => acc + vu.value * mult
}
}
})
if total < 0 {
none
} else {
match checked_int_magnitude(a: total) {
CheckedNatOverflow { cause: _ } => none
CheckedNatReady { value: n } => Present { value: microsecond(count: n) }
}
}
}
}

type SystemdCgroupMemoryLimit
= MemoryLimitUnbounded
| MemoryLimitBytes { bytes: ByteSize }
Expand Down
Loading
Loading