Repository navigation
fix: four of the #280 follow-ups: mint credentials, listing dedupe, ensure identity, launch_image_arn - #540
Merged
Merged
Conversation
…IALS (#280) `ProxyAuth::token_for` reclassified every minter failure as `WireKind::AuthTokenMint`, which is `ERR_RETRYABLE`, so a mint the control plane refused for the caller's identity told the caller to retry, with a message that said both "waiting will not fix this" (the credential's own text) and "the identical request may succeed". A credential failure keeps `ErrorKind::Credentials` now, with the minter's reason as its source; every other mint failure, a throttle among them, stays retryable. `a_credential_failure_during_a_mint_is_err_credentials_not_retryable` fails on the base with `left: Retryable, right: Credentials` and passes with the fix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ges carry it (#280) The service can return one VM on two pages of a `ListMicrovms` walk while VMs change state (measured 2026-10-01, recorded in docs/PLATFORM.md by #500), and `list_microvms_matching` extended its result with every page, so `ls --remote` and both bindings' `ControlPlane.list` could list it twice. A repeat now replaces the earlier entry in place: the VM keeps the position it was first listed at and the entry read last, the newer reading of its state. `a_vm_the_fleet_listing_meets_on_two_pages_is_listed_once` fails on the base with `left: ["mvm-a", "mvm-moved", "mvm-moved", "mvm-b"]` and passes with the fix. Verified offline only: no live run has listed a VM twice through the client. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
) `ensure_image` hashed the artifact, the base, a pinned base version and the size class into the image's name, and left out what `CreateMicrovmImage` fixes for the image's life: identity repair, `inherit_workdir`, the run and build hook timeouts, and the log group and stream. A ready image under the name was reused whatever those were, so a caller asking for identity repair could get an image built without it (from #454). `prepare` builds the unnamed create request first and names the image for `create_identity_hash` of exactly that request, so every field it carries is read once. The stream's domain tag moves to `microvms-ensure-image/2` and tags each create-only field, length-prefixed, with an absent optional distinct from an empty one. Every ensured image is renamed once, which is the fix: an image named by the old stream may lack a field its next caller asks for. `pinned_identity_hash` and `image_identity_hash` keep their signatures and answer the identity of an image with the create request's defaults; the agent recipe's `image_name_for` names its request's own fields, so its two-step path and its ensure still name one image. Tags stay out of the name. `each_create_only_field_names_a_different_image` fails on the base with `repair_guest_identity is create-only, so it is identity` (left and right both `task-48daea63e51c`) and passes with the fix. Two tests change with the behavior: `a_created_image_carries_every_field_of_the_request` asserts the configured name differs where it asserted it was equal, and `an_ensure_from_a_create_request_keeps_its_fields` gives the direct ensure the same log group and identity repair as the create it compares to. The three image-name parity cases take the new names, which core and the CLI runner answer. Verified offline only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e's (#280) #401 added `Sandbox::launch_image_arn` to core for the image a launch resolved, and the CLI's `run --image` reports it, but neither binding exposed it, so a Python or Node caller launching by name could not read the ARN the name became. Python gets a `launch_image_arn` property and Node an async `launchImageArn()`, the form napi gives every Sandbox accessor, both reading core's value. The capability table gets its `launch-image-arn` row naming all four surfaces, and the stub and declarations are regenerated. `test_launch_image_arn_names_the_image_the_launch_sent` fails on the base with `AttributeError: 'microvms.Sandbox' object has no attribute 'launch_image_arn'`, and the node test `launchImageArn names the image the launch sent` with `TypeError: sandbox.launchImageArn is not a function`; both pass with the change, as do both suites (pytest 461 passed, 1 skipped; node 349 passed) and `tools/check-parity.py`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`mise run fail-to-pass -- --jobs 4 --emit parity-followups` against 334a668, the merge base with origin/main, proved six of the branch's new or changed tests: each passes on the head and fails with the branch's product hunks reversed, and each becomes an entry in verify/guards/faults/parity-followups.toml with its patch, so CI's `guards` job fires it again. fired: f2p-a-created-image-carries-every-field-of-the-request fired: f2p-each-create-only-field-names-a-different-image fired: f2p-a-vm-the-fleet-listing-meets-on-two-pages-is-listed-once fired: f2p-a-credential-failure-during-a-mint-is-err-credentials fired: f2p-test-launch-image-arn-names-the-image-the-launch-sent fired: f2p-launchimagearn-names-the-image-the-launch-sent `an_ensure_from_a_create_request_keeps_its_fields` changed with the rename and passes with the fix taken out, so it gets no entry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
20 of 28 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Four of #280's "Follow-ups found during the burn-down", each in its own commit with its failing-first test. Based on main at
cae2ec7, which carries #536 (the per-crate semver gates, merged asdef2815), so those gates judge this change too.ERR_CREDENTIALS(c3046d4).ProxyAuth::token_forreclassified every minter failure asWireKind::AuthTokenMint, so a mint the control plane refused for the caller's identity wasERR_RETRYABLE(exit 3) with a message promising "the identical request may succeed". A minter failure of kindCredentialskeeps it, with the minter's reason as its source; a throttle and every other mint failure stay retryable.ControlPlane::list_microvmslists each VM once (7148700). The service can return one VM on two pages while VMs change state (docs/PLATFORM.md, measured 2026-10-01 by fix(conformance): CLI-8 names the run's VM from its history, and counts a listing's VMs once #500), and the listing concatenated pages, sols --remoteand both bindings'ControlPlane.listcould list a VM twice. A repeat keeps the VM's first position and the entry read last, the newer reading of its state.499ae33). The identity hash left out identity repair,inherit_workdir, the hook timeouts and the log group and stream, so a reuse could return an image built without a field the caller asked for (from feat(cli): build --reuse, run's build and agent-up go through core's ensure_image, and the aws s3 cp upload is gone (#258) #454).preparenames the image forcreate_identity_hashof the exact create request it sends; the stream's tag moves tomicrovms-ensure-image/2, so every ensured image, the agent recipes' included, is renamed once. The publicpinned_identity_hashandimage_identity_hashkeep their signatures and answer the identity with the create request's defaults. Tags stay out of the name.launch_image_arn(707f785). Python'sSandbox.launch_image_arnproperty and Node'sSandbox.launchImageArn()read core'sSandbox::launch_image_arn(fix: Sandbox::run resolves a bare image name to its ARN, for every surface (#253) #401), with alaunch-image-arnrow inverify/parity/capabilities.tomlnaming all four surfaces (the CLI's isrun --image).Changelog:
changelog.d/280.fixed.md(three entries) andchangelog.d/280.added.md.Size: 424 changed lines of product code against origin/main, past the soft cap, because the owner asked for these four #280 boxes as one branch. The change can be split: each box is its own commit, so review can take it commit by commit, and the ensure rename (
499ae33) is most of the lines.Verified offline only. Nothing here was exercised against AWS; the dedupe follows the 2026-10-01 measurement, and the mint path's credential class is asserted against a fake minter.
Evidence
Main moved to
8d87a3b(nightly chore(deps): nightly rollup 2026-10-09 #538, docs docs: correct cli.md's microvm.toml section and envelope key lists against the code #539) after the rebase.b69c0eemerges into it without conflicts, andTMPDIR=<scratch>/t mise run -c checkon that merged tree exits 0 in 310 s (cold build).cargo fmt --all -- --checkcargo clippy --all-targets -- -D warnings(throughmise run check)cargo test --all(throughmise run check; the workspace's Rust tests also pass withcargo test --workspace --exclude microvms-py --exclude microvms-js --no-fail-fast)TMPDIR=<scratch>/t mise run -c checkat the final commit (b69c0ee, rebased ontocae2ec7): exit 0 in 110 s (warm; the cold run before the guards re-proof, at10c21e7, exited 0 in 301 s).mise run semver:checkexits 0 too: all five comparisons against 0.11.0 pass (196 checks: 196 pass, 58 skip each). Before the rebase, a run failedlinton aclippy::type_complexityin the new ensure test, fixed by a type alias in499ae33.Both binding suites, built the way
bindings:pyandbindings:jsbuild them: pytest 461 passed, 1 skipped;node --test349 passed, 0 failed../tools/generate-py-stubs.pyandmise run dtsregeneratedmicrovms.pyiandindex.d.ts;stubs:checkanddts:checkpass incheck.Failing first, each watched red before its fix:
session::proxy::tests::a_credential_failure_during_a_mint_is_err_credentials_not_retryable:left: Retryable, right: Credentials.control::microvm::tests::a_vm_the_fleet_listing_meets_on_two_pages_is_listed_once:left: ["mvm-a", "mvm-moved", "mvm-moved", "mvm-b"].control::ensure::tests::each_create_only_field_names_a_different_image:repair_guest_identity is create-only, so it is identity, both namestask-48daea63e51c.test_launch_image_arn_names_the_image_the_launch_sent:AttributeError: 'microvms.Sandbox' object has no attribute 'launch_image_arn'; node'slaunchImageArn names the image the launch sent:TypeError: sandbox.launchImageArn is not a function.Parity
microvms.pyi,index.d.ts). Python gainsSandbox.launch_image_arnand NodeSandbox.launchImageArn(); core's public paths are unchanged (core-api:checkpasses).verify/parity/capabilities.tomlupdated: thelaunch-image-arnrow names core,run --image,Sandbox.launch_image_arnandSandbox.launchImageArn.mise run parity:checkpasses.The three
image-namecases inverify/parity/cases/take the renamed images (parity-task-178447f17502,agent-vm-claude-code-cb158b8e2c7d,agent-vm-claude-code-codex-937344ac9c1b); core, the CLI and both bindings' runners answer them.Guards
mise run fail-to-pass -- --jobs 4 --emit parity-followupsagainstcae2ec73845c, the merge base with origin/main, wrote six entries intoverify/guards/faults/parity-followups.tomlwith their patches:control::ensure::tests::an_ensure_from_a_create_request_keeps_its_fieldschanged too (its direct ensure takes the same log group and identity repair as the create it compares to) and passes with the fix taken out, so it proves nothing about the fix and has no entry; the two ensure entries above guard the rename.Follow-ups
cost --cyclesdefaults to 1 and the bindings'suspend_resume_cyclesto 0. Left open: it is a product decision for the owner (from test: every surface default is held to core's through the parity table (#300) #457), and stays on tracking: core parity across the CLI, Python and TypeScript #280's checklist.identity=on launch #263 and core: move the CLI's probe-then-register attach and the budget gate into core #270 stay open: their boxes wait for live runs that drive the bindings' tunnel handles and the import probe.import_record/importRecordagainst a real VM (from feat: registering a record another machine wrote is core's (#270) #470); stays on tracking: core parity across the CLI, Python and TypeScript #280's checklist./1-named images in an account; nothing deletes them. A caller who wants them gone deletes them by name.Platform claims
Scope
(see
docs/STRATEGY.md).