Repository navigation
refactor(dedup): one authority per concept for #17856 rows 2, 3, 5, 9-12, 13b, 14, 19 — copies retired, each pinned by a guard (#17856) - #18271
Merged
Conversation
…e-event writer and RS256 prefix (#17856)
…eprecated utils/cache_manager.py is retired (#17856)
…Memory; orchestration/workflow_memory.py is the one (#17856)
…y; services/device_jwt.py is the one device-JWT minter (#17856)
…, one implementation (#17856)
… the role default and the slm group override apply (#17856)
…-slm-env-ports; 11434 is Ollama (#17856)
…ck fix renders the canonical unit with backend_workers=1 (#17856)
…g plays take it from roles/backend (#17856)
…py; fix-backend-worker-deadlock.yml is the one (#17856)
….yml; every other ansible home references it (#17856)
…did not supply the AI-stack port (#17856)
…d its sudoers grant (#17856)
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 16 minutes. View limit details
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
✅ SSOT Configuration Compliance: Passing🎉 No new hardcoded values of either class — Known backlog in |
This was referenced Oct 11, 2026
mrveiss
added a commit
that referenced
this pull request
Oct 11, 2026
- THREAT_MODEL: is_rs256_jti_revoked anchor :91 -> :89 (#18271 edited rs256_denylist.py). - symbol_fork_baseline: the 7 entries #18271/#18310 resolved are dropped (list only shrinks). - ansible_concept_forks_17856_test: the two hand-rolled `#` comment checks use the canonical tools.lint._comment_syntax.code_lines (#17941). - MIN_GUARDS_EXAMINED 170 -> 209, as guard_reach_floor_window prescribes. - stylelint-tokens: contract.css (the token definition site) is excluded from the changed-libs list by pathspec. The lint step passes --config-basedir, and stylelint resolves relative ignoreFiles against that base, so the kit config ignore never matched. 84 passed locally across the affected tests.
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thinking Path
#17856 inventoried 19 concepts that each have more than one definition. The owner decided on 2026-10-10 that every row gets one authority, and the copies are retired. This PR delivers the rows that are not blocked or owned elsewhere: the FIX-NOW batch (rows 12, 19, 11b, 13b) and the decided rows 2, 3, 5, 9, 10, 11 (the fleet half) and 14. Every retired copy was checked for callers first (static imports,
importlib/string loads, yml/j2/json), and each retirement is pinned by a guard with contrast fixtures.What Changed, per row
40a698896atasks/retention_audit.py). One unverified-claims JWT decoder (autobot_shared/auth/jwt_core.py), with every caller repointed. One SLM node-event writer (services/node_events.py). One RS256 denylist prefix.39eae368c5api/system.pyuses the advanced cache manager. The deprecatedutils/cache_manager.pyis retired; its only importers were two local imports._ensure_redis_clientnow really initialises, so cold-start stats and the Redis health check no longer reportunavailable.8b0e0ea5f6orchestration/workflow_memory.py. The test-onlyautobot_shared/workflow_memory.pyand its mypy override are retired.73ce2485eeservices/device_jwt.py(aud claim, revocation, audit). The weaker, unimportedservices/device_token_service.pyis retired.ee095b3bd8GET /fleet/servicesandPATCH .../categorydelegate to the orchestration handlers. The duplicateFleetService*models are removed.78e872a4d3,b135de763bbackend_workershas one literal (theroles/backenddefault), plus the SLM group override and the deadlock playbook's purposeful1. Thebackend-env.ymloverride that reset dedicated VMs to 1 on every update is gone. Five plays and tasks no longer hardcode4. The two that rendered the unit directly now go throughroles/backendunit_only, androles/backend_services(a second rendering path) folds into it.ea91829f35,b6fd9f322a,5a3b86cd41ansible/inventory/group_vars/all.yml: 8080; 11434 is Ollama). Every other ansible home references it, and thedefault(8080)fallbacks are dropped. The shell scripts use${AUTOBOT_AI_STACK_PORT:?...}, so a failedssot-config.shsource fails with its reason. A test pins the ansible value equal tossot_config'saistackdefault.278282931d,cb8047125f,52a27376dfbackend_workers=1byfix-backend-worker-deadlock.yml, so itsExecStartPreis kept. The single-worker template andfix-backend-deadlock.sh(an inline unit copy with a stale path) are retired. Thediagnose-portwrapper subcommand and its NOPASSWD sudoers grant lost their only caller and are retired with it. The least-privilege test now asserts the grant is gone.Note on the row-5 path:
fix-backend-worker-deadlock.ymlnow goes throughroles/backendunit_only, so it also re-renders the celery and celery-beat units and runsmemory_limits.yml. It does not restart celery.Behaviour changes
/fleet/servicesstill returnsip_addressandportper node. The orchestration handler had left them null, so it now fills them, and the orchestration path returns them too.unavailable.distributed_setupandfix-slm-env-ports.ymlrendered 11434, the Ollama port, as the AI-stack port. They now render 8080.Review risks, stated
ai_stack_portno longer has adefault()fallback, so a play that runs withoutgroup_vars/fails on an undefined variable instead of silently using 8080. The two documented group_vars-less callers (api/tls.py,services/replication.py) don't use the port. That was established by reading them, not by running them.yaml.safe_load(one indent error from an edit was caught and fixed), and every changed shell script passesbash -n. No playbook was executed.Verification
reach_scope_claim_17844_test, run alone: 10 passed.concept_forks_17856guard, the sudo least-privilege test, the size ratchet, ceiling parity, the symbol-fork ratchet and guard-reach meta: 126 passed.api/system.py1112→1108, SLMapi/services.py1208→1121, SLMmodels/schemas.py2180→2155.Not done, stated rather than implied
_sha256_filework on another branch.api/secrets.py.hardware_metrics): blocked onissue-17906-monitoring-launchers, which still imports it./fleet/servicespath with a 410 waits on the SLM frontend moving off it.So this PR is Refs #17856.
Refs #17856
Model Used
Claude Opus 5.5 (master session: decisions, review of reports, PR). The implementation was done by a Claude subagent.
🤖 Generated with Claude Code