Skip to content

Commit 615fe93

Browse files
andyclaude
andcommitted
Merge origin/main into wip/clip-audit
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PFPK14wBcLD1s4dYUowpP4
2 parents 9718844 + 0408fd2 commit 615fe93

70 files changed

Lines changed: 2938 additions & 277 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CMakeLists.txt‎

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1994,6 +1994,16 @@ if(PYTHON3_EXECUTABLE)
19941994
set_tests_properties(apps_summary PROPERTIES TIMEOUT 900
19951995
SKIP_RETURN_CODE 77)
19961996

1997+
# The Quantum ESPRESSO tutorial (help/src/qe-first-calculation.md) replayed
1998+
# in the real apps: silicon scf and a water relax, run by pw.x through the
1999+
# Launcher and the job monitor, checked against pw.x on a hand-written deck.
2000+
add_test(NAME apps_qe_walkthrough
2001+
COMMAND ${PYTHON3_EXECUTABLE}
2002+
${CMAKE_CURRENT_SOURCE_DIR}/tests/apps/qe_walkthrough_test.py
2003+
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/tests/apps)
2004+
set_tests_properties(apps_qe_walkthrough PROPERTIES TIMEOUT 3000
2005+
SKIP_RETURN_CODE 77)
2006+
19972007
# The Builder with a calculation's MOs panel open in every panel layout,
19982008
# on a 1366x768 screen: viewer and panel on screen and inside the window.
19992009
add_test(NAME apps_panel_layouts
@@ -2417,6 +2427,13 @@ if(PYTHON3_EXECUTABLE)
24172427
--build ${CMAKE_BINARY_DIR}
24182428
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/tests/queues)
24192429
set_tests_properties(queues_config PROPERTIES TIMEOUT 300 SKIP_RETURN_CODE 77)
2430+
# Which layer a machine comes from (user, server, install) and localhost.
2431+
add_test(NAME queues_layers
2432+
COMMAND ${PYTHON3_EXECUTABLE}
2433+
${CMAKE_CURRENT_SOURCE_DIR}/tests/queues/layers_test.py
2434+
--build ${CMAKE_BINARY_DIR}
2435+
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/tests/queues)
2436+
set_tests_properties(queues_layers PROPERTIES TIMEOUT 300 SKIP_RETURN_CODE 77)
24202437
add_test(NAME queues_configedit
24212438
COMMAND ${PYTHON3_EXECUTABLE}
24222439
${CMAKE_CURRENT_SOURCE_DIR}/tests/queues/configedit_test.py
@@ -2457,8 +2474,9 @@ if(PYTHON3_EXECUTABLE)
24572474
add_test(NAME queues_publish
24582475
COMMAND ${PYTHON3_EXECUTABLE}
24592476
${CMAKE_CURRENT_SOURCE_DIR}/tests/queues/publish_test.py
2477+
--build ${CMAKE_BINARY_DIR}
24602478
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/tests/queues)
2461-
set_tests_properties(queues_publish PROPERTIES TIMEOUT 120 SKIP_RETURN_CODE 77)
2479+
set_tests_properties(queues_publish PROPERTIES TIMEOUT 300 SKIP_RETURN_CODE 77)
24622480
# ecce -admin on a -remote client: ecce-site-admin on a simulated central
24632481
# server, publishing, and the client's ecce-remote-setup --refresh (#234).
24642482
add_test(NAME queues_siteadmin

‎GETTING_STARTED.md‎

Lines changed: 13 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -518,10 +518,13 @@ sudo ecce-remote-setup <server-host>
518518
```
519519

520520
`ecce-remote-setup` also copies the server's registered site machine list
521-
(`sudo ecce -admin` on the server) onto the client, so students don't
522-
register machines by hand; run `sudo ecce-remote-setup --refresh` on the
523-
client after the admin changes that list (#188). It writes only the data server's address; the
524-
client finds the broker on the same host, port 8088 (set `ECCE_BROKER_PORT`
521+
onto the client, so students don't register machines by hand. The published
522+
files are readable without a login; `--login NAME` (password asked for, or in
523+
`ECCE_SETUP_PASSWORD`) is used if given. Run `sudo ecce-remote-setup --refresh`
524+
after the admin changes the list (`sudo ecce -admin` on the server publishes
525+
it, #188, #192). This copy stays until clients fetch the files themselves
526+
(#192 stage 3), which is also when the folder starts to need a login.
527+
The client finds the broker on the same host, port 8088 (set `ECCE_BROKER_PORT`
525528
in the client's environment if the server uses another).
526529

527530
##### TLS for the central server (optional)
@@ -567,8 +570,8 @@ An administrator can edit the server's site machine list from a client
567570
with `ecce -admin -remote`. Register Machines then saves over ssh, as the
568571
administrator's own login on the server (`-l LOGIN` for another one, or a
569572
`User` line in `~/.ssh/config`): `ecce-site-admin` on the server writes
570-
`siteconfig` with the same writers as `ecce -admin` there, publishes the
571-
files to clients, and the client fetches its copy again. The data server
573+
`siteconfig` with the same writers as `ecce -admin` there and publishes the
574+
files to clients. The data server
572575
password plays no part in this; the ssh login and the right to write the
573576
server's `siteconfig` decide.
574577

@@ -600,9 +603,7 @@ echo "$d" > /opt/ecce/siteconfig/PublishDir # as an administrator
600603
Every directory above `$d` must be searchable (`x`) by the administrators,
601604
e.g. `chmod 711 ~ecce` if the home directory is private.
602605

603-
The administrator's own client refreshes its copy when that user can write
604-
its `siteconfig` (the same group setup on the client); otherwise, and on
605-
every other client, `sudo ecce-remote-setup --refresh` fetches the new list.
606+
On the administrator's own client, and on every other, `sudo ecce-remote-setup --refresh` fetches the new list.
606607

607608
Users then run `ecce -remote`. A client quitting never stops the server's
608609
services, and neither does the server account's own plain quit; its
@@ -709,8 +710,9 @@ the data server's contents are untouched.
709710
OpenWire).
710711
- **Clients must be 9.x as well.** An 8.x client cannot talk to a 9.x
711712
broker, nor a 9.x client to an 8.x server. Upgrade the server and every
712-
client together, then re-run `sudo ecce-remote-setup <server-host>` on
713-
each client only if the server's machine list changed.
713+
client together. The data server's `httpd.conf` is regenerated at each
714+
start, so restart it once after upgrading to pick up the read-only rule on
715+
the published site files.
714716

715717
**Shared system broker (mode 3).** Add an account per user with
716718
`sudo ecce-broker-setup --user NAME` (the 8.x broker had no accounts),
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
type: pitfall
3+
title: "A resolver that returns \"\" without setting `$_` leaves its `##tag##` in the deck"
4+
area: codereg
5+
section: "Pitfalls found more than once (check for siblings)"
6+
paths: ["scripts/parsers/ai.qe", "scripts/parsers/qe.tpl", "tests/apps/qe_walkthrough_test.py"]
7+
issues: []
8+
---
9+
**A `##tag##` resolver that wants to emit nothing must set `$_ = ""` itself.**
10+
`modifyInputFile` only overwrites the line when the resolver returns a
11+
non-empty string; on `""` the line still holds `##QEIons##` and is written
12+
to the deck. `ai.qe`'s `QEIons` and `QECell` returned `""` for an scf run
13+
without clearing `$_`, so every Quantum ESPRESSO energy deck had two literal
14+
`##QEIons##`/`##QECell##` lines (pw.x ignores unknown cards with a warning,
15+
which is why nobody noticed). Found by reading the deck the Calculation
16+
Editor stored in `tests/apps/qe_walkthrough_test.py`; set `ECCE_AI_DEBUG=1`
17+
for the "returned EMPTY and nothing replaced the tag" line.
18+
19+
Same walkthrough: pw.x's own default `ecutrho = 4 * ecutwfc` is too low for the
20+
ultrasoft/PAW files of the SSSP set (they want 8x), and the energy depends on
21+
it (0.5 mRy for the 8-atom silicon cell: -91.35634 Ry at 120 Ry, -91.35686 Ry at 240 Ry). `ai.qe` writes `ecutrho = 8 * ecutwfc` when the
22+
"Charge Density Cutoff" box is unticked and one of the chosen files is
23+
ultrasoft or PAW.

‎docs/claude/codereg/config-machine-is-site-then-user-per-key.md‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,10 +32,17 @@ form only when the first word is followed by `:`; otherwise `key value:with:colo
3232
is space form. No trailing `# comment` stripping any more (the C++ reader
3333
used to strip it, gensub never did). Blocks are replaced whole, never appended.
3434

35-
**`-remote`:** the site files are the copies `ecce-remote-setup` fetched into
36-
the client's `siteconfig/`; the user file merges over them exactly as in local
37-
mode. `ecce-dataserver-start` publishes `submit.site` and `QueueManagers` too;
38-
a client of an older server simply keeps its own.
35+
**Layers (#192):** the readers do not build `$ECCE_HOME/siteconfig/<name>`
36+
themselves but ask `Ecce::siteConfigLayers(machine)` (`siteConfigFile`,
37+
`userRegistrationDir`, `siteConfigDirs`): `[user, server site, install]` when
38+
`-remote` has a cache under `~/.ECCE/server/<host>_<port>/` (`site/`,
39+
`user-<login>/`), else `[~/.ECCE, install]`. A machine comes whole from one
40+
site layer (the highest whose `Machines` lists it; its `CONFIG.<m>` is never
41+
merged with a lower layer's), the user's `CONFIG.<m>` merges per key on top.
42+
`localhost` is always the client's: server layers are dropped for it.
43+
gensub gets the same list as `ECCE_SITECONFIG_DIRS` (set by `Launch.C`).
44+
Tests: `queues_config` (three layers, C++ against gensub), `queues_layers`.
45+
Before a cache exists (stage 3 of #192 writes it) nothing differs from local mode.
3946

4047
**The invariant is tested**: `tests/queues/config_test.py` runs
4148
`build/configdump` (C++) and `GENSUB_DUMP_CONFIG=1 gensub` on one site+user

‎docs/claude/codereg/site-admin-from-a-client.md‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,9 @@ text it was edited from) and `SiteAdminClient::send` runs it on the server:
2323
write bit and membership are the authorisation, the data-server password is
2424
not involved - runs processmachine, writes `CONFIG.<m>` through
2525
`ConfigFile`, and runs `$ECCE_HOME/bin/ecce-site-publish`.
26-
4. The client runs `ecce-remote-setup --refresh` when it can write its
27-
`siteconfig`; otherwise it says to run it with sudo. Then `redo()` reloads.
26+
4. The client's `SiteAdminClient::refresh` still runs `ecce-remote-setup
27+
--refresh`, which since #192 only prints a note and exits 0 (the machine
28+
list is no longer copied to the client). Then `redo()` reloads.
2829

2930
Things that are easy to get wrong:
3031

@@ -40,9 +41,12 @@ Things that are easy to get wrong:
4041
- A raw edit is refused when the server's file no longer reads as the
4142
client's copy (someone else changed it); per-key edits merge like
4243
processmachine does.
43-
- `--refresh` removes a `CONFIG.*`/`*.Q` that its previous fetch brought and
44-
the server no longer publishes (it keeps the last MANIFEST in
45-
`siteconfig/RemoteServer/MANIFEST`), so a deleted machine disappears.
44+
- `ecce-site-publish` also writes `INDEX` (sha256sum format, last, and
45+
unchanged when no file changed) and publishes `StartupMessage` and
46+
`NewUserMessage`. `httpd.conf.ecce` serves the folder read-only
47+
without a login (`Require all granted` + `Require method GET HEAD OPTIONS
48+
PROPFIND` under `AuthMerging Off`; a login requirement waits for #192 stage 3; the `<Limit>` sections of
49+
`/Ecce` do not carry over, hence the method list).
4650
- Tests run the "server" on this machine with no ssh: host `127.0.0.1` and no
4751
login make `RCommand` use `DirectTransport`, and an `ecce-site-admin`
4852
wrapper on PATH switches to the server's `ECCE_HOME`/`ECCE_REALUSERHOME`.

‎docs/claude/services/remote-views-use-ecces-own-login.md‎

Lines changed: 18 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ type: pitfall
33
title: "A remote view must ride ECCE's own login, not start an ssh of its own"
44
area: services
55
section: "Pitfalls"
6-
paths: ["src/comm/commtools/TailSource.C", "src/wxgui/comm/WxTailWindow.C", "src/comm/commtools/EcceShell.C", "src/comm/rcommand/SshTransport.C", "src/apps/organizer/CalcMgr.C"]
6+
paths: ["src/comm/commtools/TailSource.C", "src/comm/commxt/JobStore.C", "src/comm/commxt/Launch.C", "src/tdat/resources/AuthCache.C", "src/wxgui/comm/WxTailWindow.C", "src/comm/commtools/EcceShell.C", "src/comm/rcommand/SshTransport.C", "src/apps/organizer/CalcMgr.C"]
77
issues: [204]
88
---
99
**Anything that shows a remote file runs over the RCommand connection that
@@ -16,8 +16,8 @@ and a two-factor one wanted a second code.
1616
Tail now opens `WxTailWindow`, fed by `TailSource`: one `RCommand`, a file
1717
check, then `startStream(script, true)`, which on libssh is
1818
`SshTransport::openStreamOnLogin` -- an exec channel on the session that
19-
just authenticated (the ordinary `openStream`, used by the job monitor,
20-
opens a session of its own and logs in again). Until `closeStream()` that
19+
just authenticated (the ordinary `openStream` opens a session of its own and
20+
logs in again; nothing in ECCE uses it any more). Until `closeStream()` that
2121
session belongs to the stream's pump thread, and `run()`/SFTP on it fail
2222
with "busy". On OpenSSH (a shared connection) and locally (DirectTransport)
2323
the plain stream already shares the login. The script ends `tail` when its
@@ -30,3 +30,18 @@ The terminal route remains behind the `TailInTerminal` preference
3030
ECCE shares is reused, but over libssh it still logs in again.
3131
Tests: `transport_tail`, `transport_tail_window` (ctest),
3232
`tests/transport/sshd/tail_test.sh` (one login per Tail, counted).
33+
34+
The job monitor follows the same rule. eccejobstore (one process per job,
35+
restarted by eccejobmaster) streams eccejobmonitor with
36+
`startStream(cmd, true)` on the login `initConn()` made, and copies the
37+
output files at the end with `RCommand::copyOnLogin` over that login too;
38+
only if that copy fails does it log in again (`RCommand::get`). So one run
39+
of eccejobstore is one login; a dropped connection ends the run, and the
40+
restarted one logs in once. While the stream runs, `remoteconn` can only be
41+
interrupted (`exec("\003")`); `cleanup()` stops the stream before its
42+
`rm`. Launch copies its files with `copyOnLogin` too (`putOnLogin`), so a
43+
job costs two logins: Launch's and eccejobstore's, each its own process.
44+
eccejobstore sets `AuthCache::LAST_URL`; that fallback takes the newest
45+
credential *of the same kind*, because `initConn()` caches the machine's
46+
password (`ssh://`) before `initDAV()` asks for the data server's. Test: `tests/transport/sshd/monitor_login_test.sh` (sshd's
47+
log counts the password logins per job).
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
type: pitfall
3+
title: "The Geometry Trace panel asked for a property named \"\" when nothing can be plotted"
4+
area: wx-viewer
5+
paths: ["src/apps/builder/GeomTracePropertyPanel.C", "scripts/parsers/qe.desc"]
6+
issues: []
7+
---
8+
**`GeomTracePropertyPanel::fillPlot()` fetched the property `""` when the
9+
calculation stores a trace but no per-step series.** Quantum ESPRESSO stores
10+
`GEOMTRACE` and no `TEVEC`/gradient series, so `p_currentProp` stayed empty;
11+
`getProperty("")` fetches the whole `Props/` collection, the data server
12+
answered `301 Moved Permanently` with an HTML page, and `PropertyDoc::parse`
13+
crashed (SIGSEGV when the panel was first shown, found with gdb on a
14+
relax calculation of the QE tutorial). `fillPlot` now returns for an empty
15+
name; the panel then has the frames to play and an empty plot. A per-step
16+
energy series for QE (TEVEC) is not stored: pw.x prints the energy of the
17+
starting geometry first and `qe.geomtrace` starts at the first move, so the
18+
two are offset by one and a stateless `.desc` entry cannot pair them (see
19+
`qe.desc`).

‎help/src/img/qe-h2o-3-cell.png‎

113 KB
Loading

‎help/src/img/qe-h2o-5-theory.png‎

11.4 KB
Loading
88.4 KB
Loading

0 commit comments

Comments
 (0)