Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
53 commits
Select commit Hold shift + click to select a range
9d77c97
fix(azure): return cloud task outcomes
ruby-dlee Aug 25, 2026
3b2869b
fix(azure): return cloud task outcomes
ruby-dlee Aug 25, 2026
f79e95c
fix(azure): preserve retained cloud returns
ruby-dlee Aug 25, 2026
ab6e61a
fix(azure): route detached gate tests privately
ruby-dlee Aug 24, 2026
49af0fe
no-mistakes(review): Replace Azure source assertions with behavioral …
ruby-dlee Aug 24, 2026
3342d2d
no-mistakes(test): Align teardown fixture with authoritative HEAD
ruby-dlee Aug 24, 2026
35d72f6
fix(validation): bound local behavior proof
ruby-dlee Aug 25, 2026
a54fa28
no-mistakes(test): Reap watcher subprocesses and parallelize local va…
ruby-dlee Aug 25, 2026
0daace4
no-mistakes(document): Correct Azure capability documentation counts
ruby-dlee Aug 25, 2026
2cc890e
no-mistakes: apply CI fixes
ruby-dlee Aug 25, 2026
4af9b03
no-mistakes(document): Document concurrent local validation lanes
ruby-dlee Aug 25, 2026
6d17d29
no-mistakes(review): Add pytest adapters for Azure and liveness contr…
ruby-dlee Aug 25, 2026
ed41992
no-mistakes(document): Document exact Azure pytest coverage proof
ruby-dlee Aug 25, 2026
8ec236b
no-mistakes(review): Prove no-mistakes YAML test routing behavior
ruby-dlee Aug 25, 2026
feb1b2f
no-mistakes(document): Document no-mistakes test routing proof
ruby-dlee Aug 25, 2026
19f4a24
Merge commit 'feb1b2f76d17d3cb0fc4061a25477aa68ba3453b' into fm/azure…
ruby-dlee Aug 26, 2026
8aa0667
Merge commit '9d77c97d9c39a4415aa3770438cf6c45c52ba42b' into fm/azure…
ruby-dlee Aug 26, 2026
1decd77
fix(azure): reuse isolated worker profiles
ruby-dlee Aug 26, 2026
dfe2f9f
integrate reusable Azure worker profiles
ruby-dlee Aug 26, 2026
f7d0f1f
fix(checkout): audit same-home scheduler script drift
ruby-dlee Aug 26, 2026
cbf60bb
integrate retained Azure cloud return recovery
ruby-dlee Aug 26, 2026
1036fad
fix(azure): accept localized tracking endpoint state
ruby-dlee Aug 26, 2026
8356940
fix(azure): return cloud task outcomes
ruby-dlee Aug 25, 2026
24f5bdd
fix(azure): preserve retained cloud returns
ruby-dlee Aug 25, 2026
8f8452a
no-mistakes(review): Reject empty required report sections
ruby-dlee Aug 25, 2026
28f28eb
no-mistakes(review): Block release without valid returned reports
ruby-dlee Aug 25, 2026
140a68f
no-mistakes(review): Block artifact writes through directory symlinks
ruby-dlee Aug 25, 2026
593173b
no-mistakes(review): Reject redirected state directory paths
ruby-dlee Aug 25, 2026
2d51a78
no-mistakes(review): Require cloud evidence for Azure release
ruby-dlee Aug 25, 2026
4ebd30d
no-mistakes(review): Bind Azure release authority to controller place…
ruby-dlee Aug 25, 2026
5fa2904
no-mistakes(test): Join watcher report-prune processes during shutdown
ruby-dlee Aug 26, 2026
f4f80d9
no-mistakes(document): Correct stale Azure return status
ruby-dlee Aug 26, 2026
2df4f22
no-mistakes: apply CI fixes
ruby-dlee Aug 26, 2026
25f9c12
no-mistakes: apply CI fixes
ruby-dlee Aug 26, 2026
09abeb6
fix(azure): accept present return endpoint
ruby-dlee Aug 26, 2026
55e9d53
fix(runner): seal private gate head before public ref proof
ruby-dlee Aug 26, 2026
5844461
fix(azure): admit retained-disk resume after compute removal
ruby-dlee Aug 26, 2026
213a0a8
fix(azure): resume after compute removal
ruby-dlee Aug 26, 2026
4852bc9
fix(azure): adopt exact initial execute stub
ruby-dlee Aug 26, 2026
376424d
fix(azure): isolate nested worker deployments
ruby-dlee Aug 26, 2026
217d3c4
fix(azure): bind worker containers by stable resource identity
ruby-dlee Aug 26, 2026
e7917e1
fix(runner): verify direct private bundle ancestry
ruby-dlee Aug 26, 2026
7f4828f
no-mistakes(review): Require substantive reports for all successful c…
ruby-dlee Aug 26, 2026
6293c5a
test: mark repaired private Azure composite acceptance
ruby-dlee Aug 26, 2026
16e70eb
no-mistakes(review): Atomically fence staging uploads with assignment…
ruby-dlee Aug 26, 2026
89e802f
fix(azure): fence result return and use portable guest command
ruby-dlee Aug 26, 2026
7b7e59b
fix(azure): integrate no-mistakes offload
ruby-dlee Aug 26, 2026
6337bca
fix(azure): materialize returned task branch
ruby-dlee Aug 26, 2026
bda4ba3
feat(azure): add no-mistakes worker wrapper
ruby-dlee Aug 26, 2026
b7582f9
feat(azure): bundle Pi runtime for no-mistakes
ruby-dlee Aug 26, 2026
6b2cf5b
fix(azure): bind worker runtime identity
ruby-dlee Aug 26, 2026
0a53609
fix(azure): pin worker execution closure
ruby-dlee Aug 26, 2026
d5c6ccb
chore: merge current main into Azure worker branch
ruby-dlee Aug 26, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .no-mistakes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,8 @@ disable_project_settings: true
# The ordinary local test command derives every herdr-lab and herdr-mixed file
# from tests/test-capabilities.tsv, admits those files through tests/run.sh's
# sealed safety and lab-ownership boundary, and runs them serially on the
# real-Herdr path before Agent Fleet's locked pytest and compileall checks.
# real-Herdr path concurrently with Agent Fleet's locked pytest and compileall
# checks.
# It deliberately does not duplicate hermetic-only behavior files on the Mac.
# The required Behavior tests CI job owns the complete behavior inventory:
# eight isolated runners admit every selected path through tests/run.sh, run
Expand All @@ -36,6 +37,8 @@ disable_project_settings: true
# bypasses worktree scripts and delegates lint plus every behavior shard to the
# root-owned bridge, so command children receive neither provider nor GitHub
# credentials and never execute on the credentialed coordinator VM.
# tests/fm-azure-runner.test.sh executes this test command in an isolated fixture
# and proves that its two branches exclusively reach those respective owners.
commands:
lint: 'if [ "${FM_AZURE_VALIDATION_CELL:-0}" = 1 ]; then exec "$FM_AZURE_VALIDATION_SHARD_BRIDGE" lint -- bin/fm-azure-runner-command.sh bash -c ''bin/fm-lint.sh && uv run --directory tools/agent-fleet --locked ruff check .''; else exec bin/fm-azure-runner-dispatch.sh lint -- bin/fm-azure-runner-command.sh bash -c ''bin/fm-lint.sh && uv run --directory tools/agent-fleet --locked ruff check .''; fi'
test: 'if [ "${FM_AZURE_VALIDATION_CELL:-0}" = 1 ]; then exec "$FM_AZURE_VALIDATION_SHARD_BRIDGE" behavior --count "${FM_AZURE_VALIDATION_SHARD_COUNT:-8}"; else exec bin/fm-no-mistakes-test-command.sh; fi'
Expand Down
212 changes: 212 additions & 0 deletions bin/fm-azure-runner-agent-fleet-install.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,212 @@
#!/usr/bin/env python3
"""Install the exact locked Agent Fleet source into a prepared offline venv.

The Azure runner has no package network while repository code executes and its
wheelhouse intentionally contains only locked registry dependencies. Agent
Fleet has no runtime dependencies, so this trusted installer copies the exact
snapshot package into the fresh venv, writes ordinary distribution metadata,
and creates the release-local console entrypoint without invoking an unsealed
PEP 517 build backend.
"""

import base64
import csv
import hashlib
import io
import os
from pathlib import Path
import re
import stat
import sys
import sysconfig


class InstallError(RuntimeError):
pass


def real_subdirectory(root, parts, label):
current = root
for part in parts:
current = current / part
try:
metadata = current.lstat()
except OSError as exc:
raise InstallError("{} is unavailable: {}".format(label, exc))
if not stat.S_ISDIR(metadata.st_mode):
raise InstallError("{} must have real directory ancestry".format(label))
return current


def regular_file(path, label):
try:
metadata = path.lstat()
except OSError as exc:
raise InstallError("{} is unavailable: {}".format(label, exc))
if not stat.S_ISREG(metadata.st_mode):
raise InstallError("{} must be a regular non-link file".format(label))
return path


def write_new(path, content, mode=0o644):
path.parent.mkdir(parents=True, exist_ok=True)
flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL
descriptor = os.open(str(path), flags, mode)
with os.fdopen(descriptor, "wb") as handle:
handle.write(content)
os.chmod(path, mode)


def record_digest(path):
digest = base64.urlsafe_b64encode(hashlib.sha256(path.read_bytes()).digest()).rstrip(b"=")
return "sha256=" + digest.decode("ascii")


def copy_package(source, destination):
if destination.exists() or destination.is_symlink():
raise InstallError("Agent Fleet package destination already exists")
destination.mkdir(parents=True, mode=0o755)
copied = []
for child in sorted(source.rglob("*")):
relative = child.relative_to(source)
metadata = child.lstat()
target = destination / relative
if stat.S_ISLNK(metadata.st_mode):
raise InstallError("Agent Fleet source contains a link: {}".format(relative))
if stat.S_ISDIR(metadata.st_mode):
target.mkdir(mode=0o755)
continue
if not stat.S_ISREG(metadata.st_mode):
raise InstallError("Agent Fleet source contains a non-regular entry: {}".format(relative))
target.parent.mkdir(parents=True, exist_ok=True)
write_new(target, child.read_bytes())
copied.append(target)
if not copied:
raise InstallError("Agent Fleet source package is empty")
return copied


def install(project, venv):
if sys.version_info < (3, 11):
raise InstallError("Agent Fleet requires Python 3.11 or newer")
project = project.resolve()
venv = venv.resolve()
if Path(sys.prefix).resolve() != venv:
raise InstallError("installer must run with the exact target venv interpreter")

pyproject_path = regular_file(project / "pyproject.toml", "Agent Fleet pyproject")
lock_path = regular_file(project / "uv.lock", "Agent Fleet lock")
source = real_subdirectory(project, ("src", "agent_fleet"), "Agent Fleet package source")

try:
pyproject_text = pyproject_path.read_text(encoding="utf-8")
lock_text = lock_path.read_text(encoding="utf-8")
except OSError as exc:
raise InstallError("Agent Fleet project metadata is unreadable: {}".format(exc))

project_match = re.search(r"(?ms)^\[project\]\n(.*?)(?=^\[|\Z)", pyproject_text)
scripts_match = re.search(r"(?ms)^\[project\.scripts\]\n(.*?)(?=^\[|\Z)", pyproject_text)
if project_match is None or scripts_match is None:
raise InstallError("Agent Fleet project tables are absent")
project_table = project_match.group(1)
scripts_table = scripts_match.group(1)
name_match = re.search(r'^name = "([^"]+)"$', project_table, re.MULTILINE)
version_match = re.search(r'^version = "([^"]+)"$', project_table, re.MULTILINE)
dependencies_match = re.search(r"^dependencies = (.+)$", project_table, re.MULTILINE)
name = name_match.group(1) if name_match else None
version = version_match.group(1) if version_match else None
if name != "agent-fleet" or version is None or not re.fullmatch(r"[0-9]+(?:\.[0-9]+){2}", version):
raise InstallError("Agent Fleet project identity is not exact")
script_lines = [line.strip() for line in scripts_table.splitlines() if line.strip()]
if script_lines != ['agent-fleet = "agent_fleet.cli:main"']:
raise InstallError("Agent Fleet console entrypoint declaration is not exact")
if dependencies_match is None or dependencies_match.group(1).strip() != "[]":
raise InstallError("Agent Fleet gained runtime dependencies outside the sealed offline closure")

locked = []
for block in lock_text.split("[[package]]")[1:]:
locked_name = re.search(r'^name = "([^"]+)"$', block, re.MULTILINE)
if locked_name and locked_name.group(1) == name:
locked.append(block)
if len(locked) != 1:
raise InstallError("Agent Fleet lock does not contain one exact project record")
locked_block = locked[0]
if (
not re.search(r'^version = "{}"$'.format(re.escape(version)), locked_block, re.MULTILINE)
or not re.search(r'^source = \{ editable = "\." \}$', locked_block, re.MULTILINE)
or re.search(r"^dependencies = \[", locked_block, re.MULTILINE)
):
raise InstallError("Agent Fleet lock does not bind the exact editable project without runtime dependencies")

purelib = Path(sysconfig.get_path("purelib")).resolve()
scripts_dir = Path(sysconfig.get_path("scripts")).resolve()
if venv not in purelib.parents or venv not in scripts_dir.parents:
raise InstallError("target interpreter paths escape the exact venv")

package_destination = purelib / "agent_fleet"
dist_info = purelib / "agent_fleet-{}.dist-info".format(version)
entrypoint = scripts_dir / "agent-fleet"
if dist_info.exists() or dist_info.is_symlink() or entrypoint.exists() or entrypoint.is_symlink():
raise InstallError("Agent Fleet project or console entrypoint is already installed")

installed = copy_package(source, package_destination)
dist_info.mkdir(mode=0o755)
metadata = (
"Metadata-Version: 2.3\n"
"Name: agent-fleet\n"
"Version: {}\n"
"Summary: Machine-global account profile routing for local agent CLIs\n"
"Requires-Python: >=3.11\n"
"\n"
).format(version).encode("utf-8")
write_new(dist_info / "METADATA", metadata)
write_new(dist_info / "WHEEL", b"Wheel-Version: 1.0\nGenerator: fm-azure-runner\nRoot-Is-Purelib: true\nTag: py3-none-any\n")
write_new(dist_info / "entry_points.txt", b"[console_scripts]\nagent-fleet = agent_fleet.cli:main\n")
write_new(dist_info / "INSTALLER", b"fm-azure-runner\n")

python_path = venv / "bin" / "python"
if not python_path.exists():
raise InstallError("target venv has no Python entrypoint")
entrypoint_bytes = (
"#!{}\n"
"import sys\n"
"from agent_fleet.cli import main\n"
"if __name__ == '__main__':\n"
" sys.exit(main())\n"
).format(python_path).encode("utf-8")
write_new(entrypoint, entrypoint_bytes, mode=0o755)

record_rows = []
for path in sorted(installed + [
dist_info / "METADATA",
dist_info / "WHEEL",
dist_info / "entry_points.txt",
dist_info / "INSTALLER",
entrypoint,
]):
relative = path.relative_to(venv).as_posix()
record_rows.append((relative, record_digest(path), str(path.stat().st_size)))
record_path = dist_info / "RECORD"
record_rows.append((record_path.relative_to(venv).as_posix(), "", ""))
output = io.StringIO(newline="")
writer = csv.writer(output, lineterminator="\n")
writer.writerows(record_rows)
write_new(record_path, output.getvalue().encode("utf-8"))
return entrypoint


def main():
if len(sys.argv) != 3:
print("usage: fm-azure-runner-agent-fleet-install.py <project> <venv>", file=sys.stderr)
return 2
try:
entrypoint = install(Path(sys.argv[1]), Path(sys.argv[2]))
except InstallError as exc:
print("agent-fleet offline install failed: {}".format(exc), file=sys.stderr)
return 125
print("agent-fleet offline install: {}".format(entrypoint))
return 0


if __name__ == "__main__":
sys.exit(main())
35 changes: 28 additions & 7 deletions bin/fm-azure-runner-dispatch.sh
Original file line number Diff line number Diff line change
Expand Up @@ -443,13 +443,34 @@ if [ -z "$CONFIRM" ]; then
CONFIRM=$FM_AZURE_SUBSCRIPTION_ID
fi

SOURCE_ARGUMENTS=()
if [ "$ROUTING_STATE" = selected ]; then
# A per-run no-mistakes step executes from the gate's detached, pipeline-owned
# snapshot. Give that exact HEAD a deterministic private bundle ref derived
# from the already-proved run id instead of guessing or pushing a task branch.
# The direct bundle takes the ordinary standalone shared-capacity path; it is
# not a validation-cell child and carries no parent reservation.
[ -n "$ROUTING_RUN_ID" ] \
|| refuse "selected per-run routing has no exact no-mistakes run identity"
SOURCE_ARGUMENTS=(
--source-ref "refs/heads/fm-no-mistakes/$ROUTING_RUN_ID"
--private-snapshot-from-head
)
fi

printf 'azure-runner: class=%s selected REMOTE resource-class=%s source=%s (dispatching)\n' \
"$COMMAND_CLASS" "$RESOURCE_CLASS" "$SELECTION_SOURCE" >&2

exec "$SCRIPT_DIR/fm-azure-runner.sh" run \
--confirm-run \
--confirm-subscription "$CONFIRM" \
--task "$TASK" \
--generation "$GENERATION" \
--resource-class "$RESOURCE_CLASS" \
-- "$@"
RUNNER_ARGUMENTS=(
run
--confirm-run
--confirm-subscription "$CONFIRM"
--task "$TASK"
--generation "$GENERATION"
--resource-class "$RESOURCE_CLASS"
)
if [ "$ROUTING_STATE" = selected ]; then
RUNNER_ARGUMENTS+=("${SOURCE_ARGUMENTS[@]}")
fi
RUNNER_ARGUMENTS+=(-- "$@")
exec "$SCRIPT_DIR/fm-azure-runner.sh" "${RUNNER_ARGUMENTS[@]}"
2 changes: 1 addition & 1 deletion bin/fm-azure-runner-exec.py
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@


RESULT_SCHEMA = "fm.azure-command-result/v1"
PRIVATE_SOURCE_MODES = ("private-parent-bundle", "private-exact-bundle")
PRIVATE_SOURCE_MODES = ("private-parent-bundle", "private-exact-bundle", "private-direct-bundle")


def fail(message):
Expand Down
Loading
Loading