Skip to content

refactor(dedup): one authority per concept for #17856 rows 2, 3, 5, 9-12, 13b, 14, 19 — copies retired, each pinned by a guard (#17856) - #18271

Merged
mrveiss merged 15 commits into
mainfrom
issue-17856-concept-forks
Oct 11, 2026
Merged

mrveiss merged 15 commits into
mainfrom
issue-17856-concept-forks

Conversation

@mrveiss

@mrveiss mrveiss commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

Thinking Path

#17856 inventoried 19 concepts that each have more than one definition. The owner decided on 2026-10-10 that every row gets one authority, and the copies are retired. This PR delivers the rows that are not blocked or owned elsewhere: the FIX-NOW batch (rows 12, 19, 11b, 13b) and the decided rows 2, 3, 5, 9, 10, 11 (the fleet half) and 14. Every retired copy was checked for callers first (static imports, importlib/string loads, yml/j2/json), and each retirement is pinned by a guard with contrast fixtures.

What Changed, per row

Row Commit One authority now
12, 19, 11b, 13b 40a698896a One retention deletion-audit emitter (tasks/retention_audit.py). One unverified-claims JWT decoder (autobot_shared/auth/jwt_core.py), with every caller repointed. One SLM node-event writer (services/node_events.py). One RS256 denylist prefix.
9 39eae368c5 api/system.py uses the advanced cache manager. The deprecated utils/cache_manager.py is retired; its only importers were two local imports. _ensure_redis_client now really initialises, so cold-start stats and the Redis health check no longer report unavailable.
10 8b0e0ea5f6 orchestration/workflow_memory.py. The test-only autobot_shared/workflow_memory.py and its mypy override are retired.
14 73ce2485ee services/device_jwt.py (aud claim, revocation, audit). The weaker, unimported services/device_token_service.py is retired.
11 (fleet) ee095b3bd8 SLM GET /fleet/services and PATCH .../category delegate to the orchestration handlers. The duplicate FleetService* models are removed.
2 78e872a4d3, b135de763b backend_workers has one literal (the roles/backend default), plus the SLM group override and the deadlock playbook's purposeful 1. The backend-env.yml override that reset dedicated VMs to 1 on every update is gone. Five plays and tasks no longer hardcode 4. The two that rendered the unit directly now go through roles/backend unit_only, and roles/backend_services (a second rendering path) folds into it.
3 ea91829f35, b6fd9f322a, 5a3b86cd41 The AI-stack port is one literal (ansible/inventory/group_vars/all.yml: 8080; 11434 is Ollama). Every other ansible home references it, and the default(8080) fallbacks are dropped. The shell scripts use ${AUTOBOT_AI_STACK_PORT:?...}, so a failed ssot-config.sh source fails with its reason. A test pins the ansible value equal to ssot_config's aistack default.
5 278282931d, cb8047125f, 52a27376df The canonical backend unit, rendered with backend_workers=1 by fix-backend-worker-deadlock.yml, so its ExecStartPre is kept. The single-worker template and fix-backend-deadlock.sh (an inline unit copy with a stale path) are retired. The diagnose-port wrapper subcommand and its NOPASSWD sudoers grant lost their only caller and are retired with it. The least-privilege test now asserts the grant is gone.

Note on the row-5 path: fix-backend-worker-deadlock.yml now goes through roles/backend unit_only, so it also re-renders the celery and celery-beat units and runs memory_limits.yml. It does not restart celery.

Behaviour changes

  • Row 11: /fleet/services still returns ip_address and port per node. The orchestration handler had left them null, so it now fills them, and the orchestration path returns them too.
  • Row 9: the Redis health check initialises the client on a cold start instead of reporting unavailable.
  • Row 2: a dedicated backend VM keeps its 4 workers across updates. Before, every update silently dropped it to 1.
  • Row 3: distributed_setup and fix-slm-env-ports.yml rendered 11434, the Ollama port, as the AI-stack port. They now render 8080.
  • Row 5: one passwordless sudo grant fewer.

Review risks, stated

  • ai_stack_port no longer has a default() fallback, so a play that runs without group_vars/ fails on an undefined variable instead of silently using 8080. The two documented group_vars-less callers (api/tls.py, services/replication.py) don't use the port. That was established by reading them, not by running them.
  • yamllint and ansible-lint are not in the test venv. Every changed yaml was parsed with yaml.safe_load (one indent error from an edit was caught and fixed), and every changed shell script passes bash -n. No playbook was executed.

Verification

  • reach_scope_claim_17844_test, run alone: 10 passed.
  • Combined run of the ansible guard, the concept_forks_17856 guard, the sudo least-privilege test, the size ratchet, ceiling parity, the symbol-fork ratchet and guard-reach meta: 126 passed.
  • Earlier runs on this branch:
    • 29 ansible / hardcoded-value / shell-port / sudo repo tests plus the three SLM ansible tests: 397 passed;
    • the cache, workflow-memory, device-JWT and 17049 tests: 51;
    • the SLM fleet and services tests and the system-migration batch: 41.
  • Ceilings lowered: api/system.py 1112→1108, SLM api/services.py 1208→1121, SLM models/schemas.py 2180→2155.

Not done, stated rather than implied

So this PR is Refs #17856.

Refs #17856

Model Used

Claude Opus 5.5 (master session: decisions, review of reports, PR). The implementation was done by a Claude subagent.

🤖 Generated with Claude Code

…Memory; orchestration/workflow_memory.py is the one (#17856)
…y; services/device_jwt.py is the one device-JWT minter (#17856)
… the role default and the slm group override apply (#17856)
…ck fix renders the canonical unit with backend_workers=1 (#17856)
…py; fix-backend-worker-deadlock.yml is the one (#17856)
@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 4e6e5d76-a02b-4441-b413-b2e9a0db5f1b

📥 Commits

Reviewing files that changed from the base of the PR and between 1349f43 and 75f5888.


⛔ Files ignored due to path filters (4)
  • autobot-slm-frontend/src/types/generated/api.ts is excluded by !**/generated/**
  • pipeline-scripts/hardcoded_values_baseline.txt is excluded by !**/*_baseline.txt, !pipeline-scripts/hardcoded_values_baseline.txt
  • repo_tests/python_file_size_ratchet_baseline.py is excluded by !repo_tests/python_file_size_ratchet_baseline.py
  • scripts/python_file_size_known_large.py is excluded by !scripts/python_file_size_known_large.py

📒 Files selected for processing (68)
  • autobot-backend/a2a/peer_identity.py
  • autobot-backend/api/system.py
  • autobot-backend/cache/simple_cache_cold_start_17856_test.py
  • autobot-backend/llm_shared/provider_auth.py
  • autobot-backend/services/device_token_service.py
  • autobot-backend/services/rs256_revocation.py
  • autobot-backend/services/secrets_service.py
  • autobot-backend/tasks/chat_retention.py
  • autobot-backend/tasks/file_retention.py
  • autobot-backend/tasks/knowledge_retention.py
  • autobot-backend/tasks/retention_audit.py
  • autobot-backend/tests/integration/test_purpose_bound_tokens_are_not_logins_17049.py
  • autobot-backend/tests/unit/test_data_retention.py
  • autobot-backend/tests/unit/test_unverified_claims_callers_17856.py
  • autobot-backend/utils/advanced_cache_manager.py
  • autobot-backend/utils/cache_manager.py
  • autobot-infrastructure/shared/scripts/phase_validation_system.py
  • autobot-infrastructure/shared/scripts/setup/system/autobot-cleanup-port
  • autobot-infrastructure/shared/scripts/setup/system/setup_passwordless_sudo.sh
  • autobot-slm-backend/ansible/deploy-autobot-native.sh
  • autobot-slm-backend/ansible/deploy-hybrid.sh
  • autobot-slm-backend/ansible/deploy-native.sh
  • autobot-slm-backend/ansible/deploy.sh
  • autobot-slm-backend/ansible/fix-backend-deadlock.sh
  • autobot-slm-backend/ansible/fix-backend-worker-deadlock.yml
  • autobot-slm-backend/ansible/fix-slm-env-ports.yml
  • autobot-slm-backend/ansible/inventory/group_vars/all.yml
  • autobot-slm-backend/ansible/inventory/group_vars/infrastructure.yml
  • autobot-slm-backend/ansible/inventory/production.yml
  • autobot-slm-backend/ansible/playbooks/deploy-backend-local.yml
  • autobot-slm-backend/ansible/playbooks/deploy-backend-remote.yml
  • autobot-slm-backend/ansible/playbooks/deploy-nginx-proxy.yml
  • autobot-slm-backend/ansible/playbooks/fix-backend-environment.yml
  • autobot-slm-backend/ansible/playbooks/health-check.yml
  • autobot-slm-backend/ansible/playbooks/vars/backend-env.yml
  • autobot-slm-backend/ansible/roles/backend/defaults/main.yml
  • autobot-slm-backend/ansible/roles/backend_services/tasks/main.yml
  • autobot-slm-backend/ansible/roles/common/defaults/main.yml
  • autobot-slm-backend/ansible/roles/distributed_setup/defaults/main.yml
  • autobot-slm-backend/ansible/setup-ai-stack.yml
  • autobot-slm-backend/ansible/setup-user-backend.yml
  • autobot-slm-backend/ansible/templates/autobot-backend-single-worker.service.j2
  • autobot-slm-backend/ansible/utils/health-check.sh
  • autobot-slm-backend/api/nodes.py
  • autobot-slm-backend/api/orchestration.py
  • autobot-slm-backend/api/services.py
  • autobot-slm-backend/api/updates.py
  • autobot-slm-backend/models/schemas.py
  • autobot-slm-backend/services/node_events.py
  • autobot-slm-backend/services/rs256_denylist.py
  • autobot-slm-backend/tests/api/test_fleet_services_delegates_17856.py
  • autobot-slm-backend/tests/api/test_node_code_status_read_derivation_12428.py
  • autobot-slm-backend/tests/api/test_nodes_list_timeout_10913.py
  • autobot-slm-backend/tests/api/test_slm_endpoints_12515.py
  • autobot-slm-backend/tests/services/code_version_test.py
  • autobot-slm-backend/tests/test_service_registry_covers_shipped_units_13915.py
  • autobot-slm-frontend/openapi.json
  • autobot_shared/auth/interactive_principal.py
  • autobot_shared/auth/jwt_claims_unverified_17856_test.py
  • autobot_shared/auth/jwt_core.py
  • autobot_shared/workflow_memory.py
  • autobot_shared/workflow_memory_test.py
  • pyproject.toml
  • repo_tests/_reach_policy.py
  • repo_tests/ansible_concept_forks_17856_test.py
  • repo_tests/concept_forks_17856_test.py
  • repo_tests/reach_scope_claim_17844_test.py
  • repo_tests/setup_passwordless_sudo_least_privilege_14317_test.py

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

✅ SSOT Configuration Compliance: Passing

🎉 No new hardcoded values of either class — ssot and other both block.

Known backlog in pipeline-scripts/hardcoded_values_baseline.txt is suppressed and tracked in #14371.

mrveiss added a commit that referenced this pull request Oct 11, 2026
- THREAT_MODEL: is_rs256_jti_revoked anchor :91 -> :89 (#18271 edited rs256_denylist.py).
- symbol_fork_baseline: the 7 entries #18271/#18310 resolved are dropped (list only shrinks).
- ansible_concept_forks_17856_test: the two hand-rolled `#` comment checks use the canonical
  tools.lint._comment_syntax.code_lines (#17941).
- MIN_GUARDS_EXAMINED 170 -> 209, as guard_reach_floor_window prescribes.
- stylelint-tokens: contract.css (the token definition site) is excluded from the
  changed-libs list by pathspec. The lint step passes --config-basedir, and stylelint
  resolves relative ignoreFiles against that base, so the kit config ignore never matched.

84 passed locally across the affected tests.
@mrveiss
mrveiss merged commit e2bf921 into main Oct 11, 2026
64 of 85 checks passed
@mrveiss
mrveiss deleted the issue-17856-concept-forks branch October 11, 2026 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant