|
VIP arity gap CLOSED + R11's three ruled gate changes executed
provider-bundle-check.py could not express what R2 and R11 already ruled: :137 required exactly 3 addresses per vip (a dual-family VIP is 6, so it would have failed EVERY application) and :149's octet extraction returned the whole string on a v6 literal, leaving every v6 leg trivially unique and unchecked. The apex now holds the dual-family set a renderer will emit, so the only gate that validates overlays could not validate what is about to be produced. Arity: a vip is now a v4 triple OR a dual-family sextet. The v6 legs are validated against the per-DC v6 /64s READ FROM THE APEX RECORD (D-136 option (D)), reusing dc-plane-ipam.sh's (role, kind) keying -- the provider leg takes the dedicated GUA VIP /64, admin/internal their plane /64s. The v6 host part must MIRROR the v4 octet textually. prefer-ipv6 and the v6 legs are COUPLED in both directions: the measured L3-9 finding is that the merge order which keeps prefer-ipv6 while dropping the v6 legs is the one that exits 0. An unreadable apex REFUSES at exit 2; a v4-only bundle needs no apex. R11 (D-020 amendment, ruled 2026-07-27), same pass: band 50-60 -> 50-99 in both separately-named sites; VIP_COUNT_EXPECT 11 -> 13; EXPECT_PUBLIC_VIP deliberately stays 11 (measured -- neither vault nor designate has a public binding); and an hacluster principal with no vip now FAILS, since cluster_count is asserted nowhere and a 3->1 rewrite of all 20 values produces a byte-identical PASS. Measured consequence, not glossed: two sub-checks flip PASS -> FAIL (designate's missing VIP; CHECK 1 at OK=11 want 13). preflight was ALREADY exit 1 before this change and is still exit 1 after -- no deploy path that was open is closed. Both reds are the ruled gate reporting real work owed; per R6 the .61/.62 VIPs land before the HA overlay. Harness 15 -> 28. Three cases RE-POINTED rather than deleted: the fixture base splits into a pristine repo bundle and one carrying designate's ruled .62, with new case T16 asserting the pristine bundle DOES trip the new invariant. When .62 lands, T16 gets re-pointed, not deleted. Proven able to both fail and pass on the same check (T16 red / T18 green). Gauntlet ALL GREEN (84) on vcloud; repo-lint 0 fail / 604 files scanned. Scope was operator-gated: "Fix the arity gap first, then start the renderer", with the arity-alone vs arity-plus-R11 fork put separately and answered "Arity gap + R11's three ruled changes (Recommended)". OPS under GA-R3, no D-number. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260728-vip-arity-gate.md 0 → 100644 |
|---|
| scripts/lib-net.sh |
|---|
| scripts/provider-bundle-check.py |
|---|
| tests/provider-bundle-check/run-tests.sh |
|---|