Skip to content

nas-topology: 8731 follows autoStart (Tom's 09-23 choice: close), plus the green fixes - #466

Merged
mecattaf merged 4 commits into
mainfrom
eval/2026-09-23-dotfiles-green-8731-close
Sep 23, 2026
Merged

mecattaf merged 4 commits into
mainfrom
eval/2026-09-23-dotfiles-green-8731-close

Conversation

@mecattaf

Copy link
Copy Markdown
Owner

Makes main green at checks.nas-topology (#457, #458, #460) and lands the dotfiles-green fixes.

Tom's ruling, 2026-09-23 evening (E13, 00-RULINGS-2026-09-23-evening.md):

E13 8731: "8731-close" (204c96a) lands first so the fleet PR can retarget main.

Commits (on main f8e27b43)

Evidence (REPORTED, evals-2026-09-23/successor/track-dotfiles-green.md section 3)

  • nix flake check --no-build rc 0 on 204c96a0, in a fresh empty scratch store and in the normal store (main f8e27b43 is rc 1 at the 8731 assert).
  • Per-host toplevel drvPaths (coordinator, worker, nas, client) rc 0.
  • nix-diff main vs green toplevels on the three hosts: only the nixos-version revision chain differs.
  • test_allow_kvm.py 10/10.

Post-merge, the lander re-runs nix flake check --no-build on the resulting main in a fresh worktree and records it in the run's RECEIPT.md.

Closes #457
Closes #458

Unknowns and proposed defaults

🤖 Generated with Claude Code

mecattaf and others added 4 commits September 23, 2026 07:39
)

`nix flake check --no-build` passed or failed on store state: two sites
needed a store path during evaluation.

1. pkgs/zenbook-duo-daemon.nix read `${src}/Cargo.lock`, an
   import-from-derivation. Vendor the lock (112 packages, no git sources)
   as pkgs/zenbook-duo-daemon.Cargo.lock and add
   checks.zenbook-duo-daemon-lock, a build-time `cmp` against upstream's
   file at the pinned rev, so a rev bump cannot silently drift.
2. tests/tailscale-personal imported "${pkgs.path}/nixos/...", which forces
   a store copy of nixpkgs that --no-build does not guarantee is valid.
   Use path arithmetic; the check's drvPath is unchanged (jlz5imr3...).

Evidence (evaluation, 2026-09-23): client toplevel with
allow-import-from-derivation=false went from rc 1 (cannot build
61p9hcv4...-source.drv) to rc 0; the package builds with the vendored lock.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
modules/gvisor.nix adds pkgs.gvisor (runsc, containerd-shim-runsc-v1) to
systemPackages behind myGvisor.enable, independent of the k3s gate in
#447, which keeps owning containerd and the RuntimeClass and uses the same
pkgs.gvisor. No state dir (callers pass --root under ~/.local/state), no
network policy. Both twins import it with an explicit `false`.

checks.gvisor-module asserts the gate is off and runsc absent on both
twins, and that an extendModules flip on the worker puts runsc and the
shim on PATH with no failed assertion.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
One flag, parsed before `--`, appends `--dev-bind /dev/kvm /dev/kvm` to the
bwrap line. Default off, so existing callers get the same bwrap argv. With
the flag and no usable /dev/kvm the wrapper exits 1 with a message before
starting anything. No general --dev-bind passthrough; /run/user, the
PID/IPC namespaces and every --unsetenv are unchanged.

tests/runtime-test/test_allow_kvm.py (10 cases, red before, green after)
creates nothing under the host /run/user: default unchanged, the device
opens with the flag, only `kvm` is added to /dev, the private runtime dir
stays empty, the nested no-kvm case fails loudly, usage errors, no
passthrough, --help documents the flag.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
modules/halogen.nix opened `port` on `lanInterface` for every host that set
`services.halogen.enable`. modules/strix.nix declares the server on BOTH twins
and splits only `autoStart`, so the coordinator — which by design serves no
model — was admitting :8731 on wlp192s0, its wifi uplink. The live box had the
rule (`-A nixos-fw -i wlp192s0 -p tcp --dport 8731 -j nixos-fw-accept`) with
nothing listening behind it: an open door to an empty room, which `halogen-switch
flash` would have furnished with an unauthenticated inference endpoint.

The "no authentication is fine, it is admitted on the LAN interface only; every
client on that segment is a pinned house device" argument at the top of this
module is true of the worker's wired enp191s0. It was never a claim about the
coordinator's wifi segment.

New `openLanPort`, defaulting to `autoStart`, now gates the firewall line.
Declaring the server and serving the fleet become separate statements: the
worker keeps its door, the coordinator loses one it was never meant to have,
and a host that genuinely wants to serve sets one visible option instead of
inheriting it from `enable`. Coordinator-local `halogen-switch` use is
unaffected — loopback is never filtered.

flake.nix:1695 already asserted exactly this and had been failing since
2026-09-16, taking `checks.nas-topology` — and everything evaluated after it —
down with it. `nix flake check --offline --no-build` is green again. No
change to the assert; it was right all along.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 334e596)
@mecattaf
mecattaf merged commit 7d4704d into main Sep 23, 2026
mecattaf added a commit that referenced this pull request Sep 23, 2026
mecattaf added a commit that referenced this pull request Sep 23, 2026
Conflicts in flake.nix (checks), hosts/coordinator and hosts/worker: both
sides are additive (ax-fleet checks and myAxFleet vs DF-5/G1 checks and
myGvisor.enable = false); kept both.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant