Skip to content

Promote agents to dev (agents-to-dev-2026-10-03) - #725

Merged
zah merged 5 commits into
devfrom
agents-to-dev-2026-10-03
Oct 3, 2026
Merged

zah merged 5 commits into
devfrom
agents-to-dev-2026-10-03

Conversation

@zah

@zah zah commented Oct 3, 2026

Copy link
Copy Markdown
Member

Stabilisation of agents cut at cb139f8.

Brings to dev:

  • 0735372 garm-provider-agentharbor (Sovereign-CI-Fleet AH3): GARM external provider over agent-harbor's direct sandbox-launch REST API, plus services.garm backend = "agentharbor". Nothing deployed.
  • ce80c53 terraform/github forbidden-branches ruleset helper.
  • 7f169ed git-hooks: upstream installer entry points stay out of other repositories.
  • Stabilisation: 56797a1 drops a trailing blank line in upstream-patches/garm-busy-runner-reap/fix.patch that end-of-file-fixer rewrote (the lint failure on recent PRs).

Verified locally on x86_64-linux: t_garm_provider_agentharbor (behaviour matrix, end-to-end lifecycle, 4/4 negative controls) and t_garm_provider_agentharbor_module; git-hooks-reprobuild-handoff; terraform/github/tests/test-forbidden-branches.sh; prek run --all-files; the garm package builds with the edited patch.
Not verified: aarch64-darwin (the darwin batches and setup-nix darwin verification are red on recent PRs independently of this change). Certificates: none (repo not certificate-enabled).

Zahary Karadjov and others added 5 commits October 1, 2026 00:01
…ndbox jobs

A stateless GARM external provider (v0.1.1 ABI) whose Create/Delete/Get/List
speak to agent-harbor's REST direct-sandbox-launch endpoints
(agent-harbor specs/REST-Service/Direct-Sandbox-Launch.md, PR #590 head
26d8684a). One GARM instance = one ephemeral sandbox job: instance name = job
name, provider_id = job id, garm-controller-id/garm-pool-id labels as owner
tags. GARM's DB is the source of truth; the provider keeps no state.

- Create hands the JIT runner-install script to the launch as stdin (new
  rootless `sandbox` template for local-sandbox; GARM's upstream template for
  vm substrates), always sends ttlSeconds, uses a deterministic
  Idempotency-Key and adopts its own job on 409 name-conflict, and refuses a
  job without a cleanupToken.
- Get/List map ah job states onto GARM statuses (destroyed = not found).
- Delete is idempotent (404 = success) and falls back to the cleanupToken.
- The spec's Problem+JSON error model maps onto GARM error kinds/exit codes.
- With a pinned key, every launch verifies the host's Ed25519 capability
  manifest (key, expiry, substrate, ah-* labels).

Lives in devops-modules as a second command of the garm-provider-vmharness Go
module, reusing its JIT templates, runner-version guard and vendored
garm-provider-common; the vmharness package filters the new files out so its
store path (and every existing check) is byte-identical.

services.garm gains `backend = "agentharbor"` (package default, API key via
LoadCredential, store-safe config). Gates: t_garm_provider_agentharbor
(behaviour matrix, end-to-end runner lifecycle executing the real install
script against a mock ah endpoint, 4 mutation negative controls) and
t_garm_provider_agentharbor_module (eval-only example). Nothing deployed.
Add forbidden-branches.nix, which renders the branch-protection policy's
`forbiddenBranches` field as one `forbidden-branches` repository ruleset
per repository in scope, in the engine's `repositoryRulesets` schema.

Repositories on a policy mainline are derived from the `mainlines` output
of mainline-protection.nix; product-adapted forks are listed explicitly
with their product branch, which must be their default branch. Each
ruleset restricts creation, update and non-fast-forward of the forbidden
refs, never deletion, so a stray branch can still be removed. It is
active with no bypass unless a documented exception is given.

The helper refuses a forbidden entry that would block a policy mainline,
the repository's own mainline or product branch, or a branch class of
the same repository class, as well as malformed fork entries and
undocumented bypass or enforcement exceptions. A policy without the
field renders nothing.

tests/test-forbidden-branches.sh covers the rendered shape, the engine
round trip and one named mutation per refusal, each with a positive
control.
…positories

The flake module's `mcl.gitHooks.installationScript` already refuses to
install into a repository other than the flake's own, but upstream
git-hooks.nix also publishes its installer unwrapped, as
`pre-commit.devShell`, `pre-commit.installationScript` and
`pre-commit.shellHook`. `inputsFrom = [ config.pre-commit.devShell ]` is the
form consumers copy, and entering such a shell from another checkout planted
this flake's `.pre-commit-config.yaml` and hooks there. Those options are
read-only upstream and cannot be redefined.

All of them ask `settings.gitPackage` whether they stand in a repository
(`git rev-parse --git-dir`) before writing anything. The module now sets
`gitPackage` (mkDefault) to a git that answers no outside this flake's
repository, using the same flake.nix identity as the repo guard, and is the
real git for everything else.

checks.git-hooks-same-repo-git runs upstream's real installation script in a
repository with a different flake.nix, one without, and a subdirectory of
the first, and requires them untouched; and from a subdirectory of the
flake's own repository requires the hooks to install. With upstream's
default git it fails on the first case.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brings dev's 11 commit(s) that agents lacked back into agents (dev 6c565de, agents 7f169ed). No conflicts; the one file both sides edited took independent additions from each. Both sides reviewed for intent before merging.
The busy-runner-reap patch ended with an empty line after the format-patch
signature, which the lint job's end-of-file-fixer rewrites, failing lint on
every pull request. The garm package still applies it and builds.
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Thanks for your Pull Request!

Below you will find a summary of the cachix status of each package, for each supported platform.

package x86_64-linux x86_64-darwin aarch64-darwin
attic-migrate-flake ✅ Cached at <0> 🚫 not supported ❌ build failed
attic-migrate-flake-idempotent ✅ Cached at <0> 🚫 not supported ❌ build failed
attic-push-flake-outputs-action ✅ Cached at <0> 🚫 not supported ❌ build failed
aztec ✅ Cached at <0> 🚫 not supported ❌ build failed
cachix ✅ Cached at <0> 🚫 not supported ❌ build failed
cachix-deploy-metrics ✅ Cached at <0> 🚫 not supported ❌ build failed
ci-build-batching ✅ Cached at <0> 🚫 not supported ❌ build failed
ci-image ✅ Cached at <0> 🚫 not supported 🚫 not supported
consumer-flake-cachix-inventory ✅ Cached at <0> 🚫 not supported ❌ build failed
consumer-flake-cachix-inventory-tool ✅ Cached at <0> 🚫 not supported ❌ build failed
consumer-flake-no-cachix-residual ✅ Cached at <0> 🚫 not supported ❌ build failed
consumer-flake-no-cachix-residual-tool ✅ Cached at <0> 🚫 not supported ❌ build failed
dcd ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-attic-nginx-logs-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-attic-push-substitute-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-break-glass-runbook-sections ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-cache-backend-policy ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-cache-corruption-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-cachix-fallback-simulation ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-current-flow-inventory ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-darwin-activation-integration ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-dashboard-query-fixtures ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-direct-ssh-attic-restore-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-direct-ssh-rollback-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-direct-ssh-success-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-e2e-rehearsal-skill-doc ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-event-metrics ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-event-schema-examples ✅ Cached at <0> 🚫 not supported ❌ build failed
deployment-incus-rehearsal-image ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-incus-rehearsal-script-static ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-metrics-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-no-default-cachix-deploy-call ❌ build failed 🚫 not supported 🚫 not supported
deployment-parallel-cache-push-local ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-production-cutover-simulation-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-darwin-integration 🚫 not supported 🚫 not supported ❌ build failed
deployment-pull-agent-latest-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-lock-contention-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-locks-migration-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-rejects-invalid-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-selfheal-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-pull-agent-static ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-reconciler-lock-contention-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-reconciler-skill-doc ❌ build failed 🚫 not supported ❌ build failed
deployment-reconciler-supersession-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-reconciler-timer-retry-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-reconciler-timer-static ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-scheduled-canary-local-vm ✅ Cached at <0> 🚫 not supported 🚫 not supported
deployment-skill-doc-command-references ❌ build failed 🚫 not supported ❌ build failed
deployment-summary-artifact ✅ Cached at <0> 🚫 not supported ❌ build failed
desktop-vms-golden ✅ Cached at <0> 🚫 not supported 🚫 not supported
disko ✅ Cached at <0> 🚫 not supported 🚫 not supported
dmd ✅ Cached at <0> 🚫 not supported 🚫 not supported
dscanner ✅ Cached at <0> 🚫 not supported 🚫 not supported
dub ✅ Cached at <0> 🚫 not supported ❌ build failed
encrypted-s3-artifact ✅ Cached at <0> 🚫 not supported ❌ build failed
erigon ✅ Cached at <0> 🚫 not supported 🚫 not supported
fleet-alertmanager-config ✅ Cached at <0> 🚫 not supported ❌ build failed
fleet-alertmanager-config-deadman ✅ Cached at <0> 🚫 not supported ❌ build failed
folder-size-metrics ✅ Cached at <0> 🚫 not supported 🚫 not supported
foundry ✅ Cached at <0> 🚫 not supported ❌ build failed
garm ✅ Cached at <0> 🚫 not supported ❌ build failed
garm-fleet-alert-rules ✅ Cached at <0> 🚫 not supported ❌ build failed
garm-fleet-external-checks ✅ Cached at <0> 🚫 not supported ❌ build failed
garm-provider-agentharbor ✅ Cached at <0> 🚫 not supported ❌ build failed
garm-provider-aws ✅ Cached at <0> 🚫 not supported ❌ build failed
garm-provider-vmharness ✅ Cached at <0> 🚫 not supported ✅ Cached at <0>
geth ✅ Cached at <0> 🚫 not supported ❌ build failed
git-hooks-reprobuild-handoff ✅ Cached at <0> 🚫 not supported ❌ build failed
git-hooks-same-repo-git ❌ build failed 🚫 not supported ❌ build failed
github-actions-fit-alert-rules ✅ Cached at <0> 🚫 not supported ❌ build failed
github-actions-fit-exporter ✅ Cached at <0> 🚫 not supported ❌ build failed
ldc ✅ Cached at <0> 🚫 not supported 🚫 not supported
lido-withdrawals-automation ✅ Cached at <0> 🚫 not supported ❌ build failed
linux-vm-cloud-init-image ✅ Cached at <0> 🚫 not supported 🚫 not supported
mcl-devops ✅ Cached at <0> 🚫 not supported ✅ Cached at <0>
mcl-devops-no-stale-references ❌ build failed 🚫 not supported ❌ build failed
mcl-devops-single-bin-mcl-provider ❌ build failed 🚫 not supported ❌ build failed
mev-boost ✅ Cached at <0> 🚫 not supported 🚫 not supported
netbird-with-agenix-login-script ✅ Cached at <0> 🚫 not supported 🚫 not supported
nethermind ✅ Cached at <0> 🚫 not supported 🚫 not supported
nimbus ✅ Cached at <0> 🚫 not supported 🚫 not supported
nix ✅ Cached at <0> <1> 🚫 not supported
nix-eval-jobs ✅ Cached at <0> <1> 🚫 not supported
nix-fast-build ✅ Cached at <0> 🚫 not supported ✅ Cached at <0>
nixos-anywhere ✅ Cached at <0> 🚫 not supported 🚫 not supported
nixos-rebuild-ng ✅ Cached at <0> 🚫 not supported ❌ build failed
pyroscope ✅ Cached at <0> 🚫 not supported ❌ build failed
random-alerts ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-flake-checks-artifact-fallback ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-flake-checks-attic-credentials ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-flake-checks-mcl-ref ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-flake-checks-s3-mirror-compat ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-lint-hook-discovery ❌ build failed 🚫 not supported ❌ build failed
reusable-terraform-drift-workflow ✅ Cached at <0> 🚫 not supported ❌ build failed
reusable-terraform-policy-advisories ❌ build failed 🚫 not supported ❌ build failed
reusable-terraform-source-identity ❌ build failed 🚫 not supported ❌ build failed
runner-label-tool ✅ Cached at <0> 🚫 not supported ❌ build failed
rustToolchain ✅ Cached at <0> 🚫 not supported ❌ build failed
seal-alerting-secrets ✅ Cached at <0> 🚫 not supported ❌ build failed
secret-integration ✅ Cached at <0> 🚫 not supported 🚫 not supported
serve-d ✅ Cached at <0> 🚫 not supported 🚫 not supported
setup-nix-hosted-disk-reclamation ❌ build failed 🚫 not supported ❌ build failed
setup-nix-substituter-preflight ✅ Cached at <0> 🚫 not supported ❌ build failed
setup-nix-transfer-resilience ❌ build failed 🚫 not supported ❌ build failed
t_aws_burst_runners ❌ build failed 🚫 not supported 🚫 not supported
t_aws_spot_runners ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_central_garm_recovery ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_ci_runs_on_capability ✅ Cached at <0> 🚫 not supported ❌ build failed
t_cross_host_publish_substitute ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_fit_exporter_repos_env_roundtrip ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_fleet_alert_routing ✅ Cached at <0> 🚫 not supported ❌ build failed
t_fleet_alerting ✅ Cached at <0> 🚫 not supported ❌ build failed
t_garm_api_watchdog ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_busy_runner_not_reaped ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_capability_placement ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_central_multi_host ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_credentials_no_race ❌ build failed 🚫 not supported 🚫 not supported
t_garm_deleting_capacity ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_incus_runner_host ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_incus_storage_pool_source ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_instance_lifecycle ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_job_cache_self_heal ❌ build failed 🚫 not supported 🚫 not supported
t_garm_macos_pools_supported ✅ Cached at <0> 🚫 not supported ❌ build failed
t_garm_macos_runner_install_wrapper ✅ Cached at <0> 🚫 not supported ❌ build failed
t_garm_multi_provider ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_nixos_service_boots ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_pools_labels ❌ build failed 🚫 not supported 🚫 not supported
t_garm_provider_agentharbor ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_provider_agentharbor_module ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_provider_remote ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_provider_remote_old_daemon ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_provider_vmharness_backend ✅ Cached at <0> 🚫 not supported ❌ build failed
t_garm_provider_vmharness_protocol ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_provider_vmharness_windows_toolchain ✅ Cached at <0> 🚫 not supported ❌ build failed
t_garm_reconcile ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_remote_incus_capabilities ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_remote_libvirt_settings ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_stale_scaleset_job_reaped ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_garm_webhook_delivery ❌ build failed 🚫 not supported 🚫 not supported
t_pools_cutover_complete ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_private_repo_hybrid_fallback ✅ Cached at <0> 🚫 not supported ❌ build failed
t_public_repo_free_ci ✅ Cached at <0> 🚫 not supported ❌ build failed
t_repro_binary_cache_systemd_healthz ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_repro_cache_client_render ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_repro_deploy_agent_https_converges ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_repro_lease_reaper_eval ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_runner_fit_monitoring ✅ Cached at <0> 🚫 not supported ❌ build failed
t_runner_label_taxonomy ✅ Cached at <0> 🚫 not supported ❌ build failed
t_runner_mode_manager ✅ Cached at <0> 🚫 not supported ❌ build failed
t_runner_mode_switch ✅ Cached at <0> 🚫 not supported ❌ build failed
t_s3_artifact_store_acl_and_creds ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_vmharness_create_fails_on_dead_guest ✅ Cached at <0> 🚫 not supported ❌ build failed
t_vmharness_image_is_honoured ✅ Cached at <0> 🚫 not supported ❌ build failed
t_vmharness_serve_inventory_textfile ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_vmharness_serve_linux_deploy ✅ Cached at <0> 🚫 not supported 🚫 not supported
t_vmharness_serve_win_libvirt ✅ Cached at <0> 🚫 not supported 🚫 not supported
terraform ✅ Cached at <0> 🚫 not supported 🚫 not supported
terraform-ci-matrix ✅ Cached at <0> 🚫 not supported ❌ build failed
terranix ✅ Cached at <0> 🚫 not supported 🚫 not supported
test-linux-vm-cloud-init ✅ Cached at <0> 🚫 not supported 🚫 not supported
test_darwin_pull_agent_already_current_is_transaction_free 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_already_current_recovers_lifecycle_before_convergence 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_assertion_gate 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_entrypoint_survives_generation_change 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_launchd_contract 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_lock_contention_is_non_destructive 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_recreates_missing_lock_dir ✅ Cached at <0> 🚫 not supported ❌ build failed
test_darwin_pull_agent_rejects_invalid_durable_state 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_rejects_untrusted_and_wrong_target_manifests 🚫 not supported 🚫 not supported ❌ build failed
test_darwin_pull_agent_same_id_sequence_high_water 🚫 not supported 🚫 not supported ❌ build failed
vm-harness ✅ Cached at <0> 🚫 not supported ❌ build failed
vmharness-serve-darwin-posture ✅ Cached at <0> 🚫 not supported ❌ build failed
web3signer ✅ Cached at <0> 🚫 not supported 🚫 not supported
yaml-automation-runner ✅ Cached at <0> 🚫 not supported 🚫 not supported

@zah
zah merged commit c8ef41d into dev Oct 3, 2026
34 of 42 checks passed
@zah
zah deleted the agents-to-dev-2026-10-03 branch October 3, 2026 06:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant