Repository navigation
nas-topology: 8731 follows autoStart (Tom's 09-23 choice: close), plus the green fixes - #466
Merged
Merged
Conversation
) `nix flake check --no-build` passed or failed on store state: two sites needed a store path during evaluation. 1. pkgs/zenbook-duo-daemon.nix read `${src}/Cargo.lock`, an import-from-derivation. Vendor the lock (112 packages, no git sources) as pkgs/zenbook-duo-daemon.Cargo.lock and add checks.zenbook-duo-daemon-lock, a build-time `cmp` against upstream's file at the pinned rev, so a rev bump cannot silently drift. 2. tests/tailscale-personal imported "${pkgs.path}/nixos/...", which forces a store copy of nixpkgs that --no-build does not guarantee is valid. Use path arithmetic; the check's drvPath is unchanged (jlz5imr3...). Evidence (evaluation, 2026-09-23): client toplevel with allow-import-from-derivation=false went from rc 1 (cannot build 61p9hcv4...-source.drv) to rc 0; the package builds with the vendored lock. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
modules/gvisor.nix adds pkgs.gvisor (runsc, containerd-shim-runsc-v1) to systemPackages behind myGvisor.enable, independent of the k3s gate in #447, which keeps owning containerd and the RuntimeClass and uses the same pkgs.gvisor. No state dir (callers pass --root under ~/.local/state), no network policy. Both twins import it with an explicit `false`. checks.gvisor-module asserts the gate is off and runsc absent on both twins, and that an extendModules flip on the worker puts runsc and the shim on PATH with no failed assertion. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
One flag, parsed before `--`, appends `--dev-bind /dev/kvm /dev/kvm` to the bwrap line. Default off, so existing callers get the same bwrap argv. With the flag and no usable /dev/kvm the wrapper exits 1 with a message before starting anything. No general --dev-bind passthrough; /run/user, the PID/IPC namespaces and every --unsetenv are unchanged. tests/runtime-test/test_allow_kvm.py (10 cases, red before, green after) creates nothing under the host /run/user: default unchanged, the device opens with the flag, only `kvm` is added to /dev, the private runtime dir stays empty, the nested no-kvm case fails loudly, usage errors, no passthrough, --help documents the flag. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
modules/halogen.nix opened `port` on `lanInterface` for every host that set `services.halogen.enable`. modules/strix.nix declares the server on BOTH twins and splits only `autoStart`, so the coordinator — which by design serves no model — was admitting :8731 on wlp192s0, its wifi uplink. The live box had the rule (`-A nixos-fw -i wlp192s0 -p tcp --dport 8731 -j nixos-fw-accept`) with nothing listening behind it: an open door to an empty room, which `halogen-switch flash` would have furnished with an unauthenticated inference endpoint. The "no authentication is fine, it is admitted on the LAN interface only; every client on that segment is a pinned house device" argument at the top of this module is true of the worker's wired enp191s0. It was never a claim about the coordinator's wifi segment. New `openLanPort`, defaulting to `autoStart`, now gates the firewall line. Declaring the server and serving the fleet become separate statements: the worker keeps its door, the coordinator loses one it was never meant to have, and a host that genuinely wants to serve sets one visible option instead of inheriting it from `enable`. Coordinator-local `halogen-switch` use is unaffected — loopback is never filtered. flake.nix:1695 already asserted exactly this and had been failing since 2026-09-16, taking `checks.nas-topology` — and everything evaluated after it — down with it. `nix flake check --offline --no-build` is green again. No change to the assert; it was right all along. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> (cherry picked from commit 334e596)
mecattaf
added a commit
that referenced
this pull request
Sep 23, 2026
mecattaf
added a commit
that referenced
this pull request
Sep 23, 2026
Conflicts in flake.nix (checks), hosts/coordinator and hosts/worker: both sides are additive (ax-fleet checks and myAxFleet vs DF-5/G1 checks and myGvisor.enable = false); kept both. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 23, 2026
Closed
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes
maingreen atchecks.nas-topology(#457, #458, #460) and lands the dotfiles-green fixes.Tom's ruling, 2026-09-23 evening (E13,
00-RULINGS-2026-09-23-evening.md):Commits (on main
f8e27b43)7d72c5d4flake check: remove the two store-dependent evaluation sites (DF-5, nix flake check aborts at nixosConfigurations.client, so the checks output is never reached #455). The zenbook-duo-daemon Cargo.lock is vendored with acmpcheck against upstream (checks.zenbook-duo-daemon-lock);tests/tailscale-personalusespkgs.path + ...instead of a string-interpolated import.1d5fd526gvisor: a runsc-only module (myGvisor.enable, default false), imported on the twins, gate OFF, withchecks.gvisor-module(G1).0ed74d7eruntime-test: opt-in--allow-kvmbinds/dev/kvmand nothing else (runtime-test: let a caller opt into --dev-bind /dev/kvm, declared and reviewed, instead of agents copying the wrapper #453), withtests/runtime-test/test_allow_kvm.py.204c96a0halogen: the LAN door followsautoStart, notenable(halogen: the coordinator opens the unauthenticated :8731 inference port on its wifi uplink (flake check nas-topology is red) #460). Cherry-pick of llm-agents 2026-09-23 (claude-code 2.1.280), drop the SessionEnd harvest hook, shut the coordinator's :8731 wifi door (#460) #461's334e5964: coordinatorwlp192s0becomes[80,443]; workerenp191s0keeps[3003,8731]. The coordinator already runs this behaviour (live revision3a658991).Evidence (REPORTED,
evals-2026-09-23/successor/track-dotfiles-green.mdsection 3)nix flake check --no-buildrc 0 on204c96a0, in a fresh empty scratch store and in the normal store (mainf8e27b43is rc 1 at the 8731 assert).nix-diffmain vs green toplevels on the three hosts: only thenixos-versionrevision chain differs.test_allow_kvm.py10/10.Post-merge, the lander re-runs
nix flake check --no-buildon the resultingmainin a fresh worktree and records it in the run's RECEIPT.md.Closes #457
Closes #458
Unknowns and proposed defaults
tests/runtime-test/test_isolation.pywas not run (it writes under the live/run/user). Default: left as is, noted in the track doc.🤖 Generated with Claude Code