diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 43d363d..8e2ca98 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -456,15 +456,26 @@ is the precedent). **R2 RULED 2026-07-27 -- exact utterance "Carve v6 and deploy dual-stack as ruled (Recommended)"**, recorded as a D-101 RULING NOTE (re-confirmation, no amendment; - design-decisions.md is the authority). **This CHANGES THE PLAN: D-101's "Remaining open - item" -- the org ULA /48 and per-DC GUA carve -- was carried as non-blocking "pending - NetBox assignment" and is now a STAGE-5 PRECONDITION**, because dual-stack cannot deploy - against literals that do not exist. R9 and R11 inherit dual-family from it; the L3-9 - overlay collision must be reconciled BEFORE either authority location is populated (the - dangerous merge order is the one that PASSES -- it silently drops every v6 leg). R8 - (octavia family) is NOT resolved by it. A new sub-question **R2a (which literals)** is - QUEUED, not ruled -- the shape is the operator's, and hard rule 2 forbids inventing a - prefix. Remaining: R2a, R3-R11 blocking, R12-R15 standing, in + design-decisions.md is the authority). + **CORRECTION, same session, before dependent work: the v6 literals are ASSIGNED, not + pending.** This entry first claimed D-101's "Remaining open item" (org ULA /48 + per-DC + GUA carve) had become a Stage-5 precondition. It had not: **D-111 ADOPTED them + 2026-07-11** and the apex carries them -- ULA `fd50:840e:74e2::/48` with DC0 planes at + `:220/:221/:230/:240/:250::/64` and DC1 at `:320/:321/:330/:340/:350::/64`, GUA + provider-public DC0 `2602:f3e2:f02:10::/64` + VIP `f02:11::/64` and DC1 + `2602:f3e2:f03:10::/64` + VIP `f03:11::/64` (measured from + `netbox/draft/vr1-office1-current-20260725.json`; line 264 of THIS document already + recorded the apex as holding the v6 GUA/ULA). Sub-question R2a is **WITHDRAWN as never + open**. **The real precondition is PROPAGATION and needs NO ruling**: the ratified values + are absent from `scripts/lib-net.sh` (no v6 arm at all) and from MAAS (no v6 on any of + the 12 DC plane fabrics), and both are mechanical copies from an authoritative source -- + moved to the Phase-3 mechanical batch. R9 and R11 still inherit dual-family; the L3-9 + overlay collision must still be reconciled BEFORE either authority location is populated + (the dangerous merge order is the one that PASSES -- it silently drops every v6 leg); R8 + is still NOT resolved. **NEW DOCFIX-class finding: D-101's own "Remaining open item" + paragraph is STALE** (still says "pending NetBox assignment" for literals D-111 adopted + on 07-11) -- that stale prose is what caused this error, and it is queued in Phase 3. + Remaining: R3-R11 blocking, R12-R15 standing, in `docs/audit/queued-rulings-20260727.md`. - Position inside Stage 3: deploy step A EXECUTED 2026-07-19 (6/0/6 exact; convergence zero -- diff --git a/docs/audit/queued-rulings-20260727.md b/docs/audit/queued-rulings-20260727.md index cc57b82..f195f6f 100644 --- a/docs/audit/queued-rulings-20260727.md +++ b/docs/audit/queued-rulings-20260727.md @@ -105,12 +105,43 @@ exist. R9 and R11 both inherit "dual-family" from this. The L3-9 overlay collision must be reconciled BEFORE either authority location is populated; note the dangerous direction is the one that PASSES (vips overlay last silently drops every v6 leg and -reports green). R8 is NOT resolved by this ruling. **Immediate next sub-question, -queued not ruled: WHICH literals** -- see R2a below. +reports green). R8 is NOT resolved by this ruling. **R2a WITHDRAWN -- see below.** --- -## R2a. WHICH IPv6 literals? (opened by the R2 ruling) +## R2a. WHICH IPv6 literals? -- WITHDRAWN 2026-07-27, NEVER OPEN + +**This question was asked in error and is withdrawn before any ruling.** The operator +asked whether the NetBox apex had been polled. It had not. It has now been read, and +the literals are ASSIGNED, RATIFIED AND RECORDED -- and have been since 2026-07-11 +under **D-111 (ADOPTED)**. + +MEASURED from `netbox/draft/vr1-office1-current-20260725.json` (139 prefixes, 103 +IPv6), every row tagged `D-101/D-111`: ULA `fd50:840e:74e2::/48` with DC0 planes at +`:220`/`:221`/`:230`/`:240`/`:250::/64` and DC1 at `:320`/`:321`/`:330`/`:340`/`:350::/64`; +GUA provider-public DC0 `2602:f3e2:f02:10::/64` + VIP `f02:11::/64`, DC1 +`2602:f3e2:f03:10::/64` + VIP `f03:11::/64`. + +**What is actually owed is PROPAGATION, and it needs no ruling.** The ratified values +are absent from the two places Stage 5 reads: `scripts/lib-net.sh` carries no v6 arm at +all, and MAAS carries no v6 on any of the 12 DC plane fabrics. Both are mechanical +copies from an authoritative source. This moves from Part A (needs a decision) to the +Phase-3 mechanical batch in the readiness doc. + +**Why the error happened, recorded because it is the audit's own failure mode:** the +audit's lens 2 explicitly listed the apex as UNMEASURED and warned "D-101's literals +may exist in NetBox and simply not be carved into MAAS -- L2-3's claim is scoped to +MAAS + node reality and does not assert the apex is empty." That warning was correct +and available, and a question was put to the operator anyway, on the strength of +D-101's own stale "Remaining open item" prose. Trusting stale decision prose over an +available measurement is precisely what this audit was convened to catch. + +**Consequential side-finding, logged not fixed (hard rule 1):** D-101's "Remaining open +item" paragraph still reads "pending NetBox assignment (gap #3)" for literals D-111 +adopted on 2026-07-11. That is a DOCFIX-class contradiction of a later ruling -- +DOCFIX-200/204 class -- and it is what misled this session. Added to the Phase-3 batch. + +OPERATOR UTTERANCE: *(none required -- withdrawn, not ruled)* R2 directs that the org ULA /48 and per-DC GUA carve be assigned; it does not assign them. This is an apex assignment and under D-136's unruled coupling the working apex diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 8a7bb54..24ead90 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -2077,11 +2077,49 @@ D-101's family matrix requires ULA on data-tenant, storage and replication plus a ULA leg on metal-admin and metal-internal -- none of which has any MAAS v6 presence to bind against. -**Effect -- the consequential part.** D-101's "Remaining open item" above (the exact NetBox -literals: org ULA /48, per-DC GUA carve) has until now been carried as "pending NetBox -assignment ... not a ratification question", i.e. non-blocking. **It is now a STAGE-5 -PRECONDITION.** Dual-stack cannot be deployed against literals that do not exist, so the -assignment moves onto the critical path ahead of `juju deploy`. +**Effect -- CORRECTED 2026-07-27, same session, before any dependent work.** This note +first stated that D-101's "Remaining open item" (the org ULA /48 and per-DC GUA carve) +moved onto the critical path because dual-stack cannot deploy against literals that do not +exist. **That was WRONG, and the error was mine.** The operator asked whether the NetBox +apex had actually been polled; it had not. It has now been read, and the literals are +**ASSIGNED, RATIFIED AND RECORDED** -- they have been since 2026-07-11. + +MEASURED from the apex record `netbox/draft/vr1-office1-current-20260725.json` (139 +prefixes, 103 IPv6), every entry tagged `D-101/D-111`: +- **ULA `fd50:840e:74e2::/48`.** VR1 DC0: metal-admin `:220::/64`, metal-internal + `:221::/64` (inside the metal `/60`), data-tenant `:230::/64`, storage `:240::/64`, + replication `:250::/64`. VR1 DC1: `:320::/64`, `:321::/64`, `:330::/64`, `:340::/64`, + `:350::/64`. Each with its parent `/60`. +- **GUA provider-public.** DC0 `2602:f3e2:f02:10::/64` plus VIP `/64` at `f02:11::/64`; + DC1 `2602:f3e2:f03:10::/64` plus VIP `/64` at `f03:11::/64`. + +**D-111 is ADOPTED 2026-07-11** (`docs/design-decisions.md:2351`) and is the ratifying +decision. `docs/CURRENT-STATE.md:264` already recorded that the apex "holds the entire IP +PREFIX layer (all 12 planes + transit + uplink + v6 GUA/ULA), DRIFT-FREE". + +**So the real effect is narrower and better: the Stage-5 precondition is PROPAGATION, not +ASSIGNMENT, and it requires no further ruling.** The ratified values exist in the apex and +in `netbox/`; they are absent from the two places Stage 5 actually reads: +1. **`scripts/lib-net.sh` carries NO v6 at all** (measured: essentially zero v6 tokens in + the file). Its `PLANE_CIDRS` arms are v4-only for both DCs. +2. **MAAS carries no v6 on any of the 12 DC plane fabrics** (measured: one v6 subnet + cloud-wide, on the Office1 base fabric). +Note that CURRENT-STATE's "DRIFT-FREE across netbox/lib-net/artifacts" is not contradicted +by this: drift-free means the values that appear in more than one place AGREE, not that +coverage is complete. `lib-net.sh` simply never gained a v6 arm. + +**D-101's own "Remaining open item" paragraph above is therefore STALE** -- it still reads +"pending NetBox assignment (gap #3 ...)" for literals that D-111 adopted on 2026-07-11. +That is a DOCFIX-class contradiction of a later ruling, the same class as DOCFIX-200 and +DOCFIX-204, and it is what misled this session. Logged, not fixed here (hard rule 1); +queued in the Stage-5 audit's Phase-3 batch. + +**PROCESS FAILURE, OWNED.** The audit's own lens 2 recorded the apex as UNMEASURED and +warned in terms: "D-101's literals may exist in NetBox and simply not be carved into MAAS +-- L2-3's claim is scoped to MAAS + node reality and does not assert the apex is empty." +That warning was correct, was available, and was not acted on before a question was put to +the operator. This is the exact failure the audit exists to catch -- trusting stale +decision prose over an available measurement -- committed by the audit itself. **Sequenced consequences, all of which now inherit "dual-family" from this ruling:** 1. The `vr1-dc1-vips` / `dc-dc-ipv6-family-matrix` per-key REPLACE collision must be @@ -2097,11 +2135,17 @@ 4. Octavia's family remains the standing sub-ruling recorded in the 07-25 note and is presented separately as R8; this ruling does NOT resolve it. -**NOT ruled here, and queued as the immediate next sub-question:** WHICH literals. The org -ULA /48 (RFC 4193 pseudo-random) and the per-DC GUA carve out of the existing -`2602:f3e2:f01::/48` allocation are an apex assignment, and under D-136's unruled coupling -the apex is `office1-netbox`. This ruling directs that they be assigned; it does not assign -them. +**WITHDRAWN:** this note first queued a sub-question "R2a -- WHICH literals". It is +withdrawn as never having been open. D-111 assigned them on 2026-07-11 and the apex carries +them; see the corrected Effect above. Nothing further is owed from the operator on the +address values. + +**What IS owed, all mechanical, no ruling required:** propagate the ratified v6 carve into +`scripts/lib-net.sh` (a v6 arm per DC, keyed the same way the v4 `PLANE_CIDRS` arms are), +and carve the twelve plane prefixes into MAAS as subnets on their existing fabrics. Both +have an authoritative source to copy from, so neither is a judgement call. Sequence them +BEFORE the L3-9 overlay-collision reconciliation, since that reconciliation needs the +per-app dual-family values these produce. ---