Skip to content

§3b observability conformance row; the floor heartbeat renders through the observation model again - #11017

Merged
briansrls merged 6 commits into
mainfrom
session/stern-heron-185-observability
Sep 11, 2026
Merged

briansrls merged 6 commits into
mainfrom
session/stern-heron-185-observability

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Lane B of the process-observability / decision-conformance brief (reviewed against main at b0a6d53). Stacked on #11010 (Lane A); the diff to read is this branch against session/stern-heron-185.

Row

conformance-observability ("process observability / reporting") on gunbc.design_argument conformance_domains. Homes (typed decl_ref literals, resolved by the ingestion declaration index on this PR's required run): std.observation::ObservationEvent, ::RecordedObservation, ::ObservationPresentation; gunbc.observation_ci_render::ci_event_line, ::ci_render_line. Scoped to process reporting — a repository population measured at a revision stays with gunbc.repository_census_observation, durable delivery with the effect authorities; the narrative keeps the four responsibilities (owning domain / observation model / renderer or codec / bound effect) explicit and says producing bytes is not delivery.

First concrete repair: the heartbeat

gunbc.observation_emit_census floor_heartbeat_site recorded that #9228 deleted the [floor-memory] projection and a raw [floor-heartbeat] key=value eprintln took its job. Restored:

  • Model — gunbc.observation_ci_render HeartbeatSample is replaced (§3 replacement migration, not extended) with the one-attempt floor's real sample: wall since floor start, the seam as a RunSegment+PhaseSegment subject, and every reading the raw line had grown under a measured justification as a Measured arm — cpu delta, major faults, rss, cgroup charge, high/max/local-high events, host swap-in and major faults — plus the stall window carried as gunbc.memory_stall_refusal's own MemoryStallObservation, so the printed rate and share come from the two functions the refusal itself consumes. Unreadability is kept at the grain the seed reads (one /proc/self/stat read feeds cpu and faults together; three cgroup files; one vmstat; both stall counters or none) and every arm names its cause; nothing prints 0.
  • Seed boundary — gunbc.observation_seed_render seed_heartbeat_line is the oracle over the seed's primitive input space. The liveness thread calls the Rust mirror cli_run::render_heartbeat_line_mirror (no interpreter on that thread, per the brief); floor_resource_sample becomes a typed FloorResourceSample with None for unread sources and floor_stall_window_observation returns the governor's MemoryStallObservation or None (half-read or zero-wall window). The raw wall_s= phase= cpu_ms= shape is gone from the seed; FLOOR_HEARTBEAT_CENSUS_MARKER keeps the roster's presence check honest.
  • Evidence, by route —
    • executes on the required floor: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat, the treadmill specimen's 178795 faults/min at 0.8% user cpu, no fabricated zero on any arm, and a zero-wall stall window refusing. Ran green under claim_batch on this tree (5/5), and it is discovered by the floor on this PR.
    • off the merge path (declared drop rust_unit_tests_off_the_merge_path): cli_run::heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle runs the .dag through the interpreter on the same two specimens and asserts byte-equality with the mirror and with the same literal strings, so oracle, mirror and floor witness agree over one input. Executed remotely (receipt in the PR comments).
    • test.claim.observation_ci_render_witness_test and observation_crawl_replay_test (executing) updated to the replaced sample; the captured crawl replays with its uncaptured vitals honestly unreadable (not captured by run 30044816605).

[floor-claim-memory] stays a CountedFrontierSite: a growth line is a delta between two readings on a named claim and the renderer has no measurement-delta projection; its dissolution now names that projection.

Census extension (bounded)

CensusedEmitSite gains producer: EmitProducer (a DeclarationRef into hand Rust — the ingestion wall counts these outside-index rather than resolving them; the declined hygiene suite holds each symbol present in the seed) and consumption: EmitConsumption = MachineConsumed { reader, fields_read } | HumanPresentationOnly { evidence } | ConsumerUnresolved { searched }. Every row is ConsumerUnresolved with its in-repo search stated — none is booked human-only on a prefix grep, per the brief. Producer is one declaration per family at function grain; the multi-site enumeration remains the unbuilt occurrence-grain discovery the module already names. Folds: observation_emit_unresolved_consumer_count, observation_emit_located_producer_count; new executing witness observation_emit_census_producer_witness_test (pure folds + planted controls).

Finding recorded in the census: seed_emit_sources had fallen behind the cli_run/ split — [floor-claim-memory] lives only in cli_run/required_floor_runner.rs, so census_marker_present answered false for its own row and the declined suite reported nothing; four files added. The lockstep witness's no-fabrication row had likewise gone false a second time on the same split (needles into cli_run.rs for code now in required_floor_runner.rs). Both suites are repaired to the restored subject; their declined standing is restated, not changed — they executed under claim_batch on this tree (7/7, 20/20) and nowhere on the merge path. This PR does not lift the live-tree decline.

Not claimed

No corpus-wide migration (frontier count moves 8→7: this family only); no effectful convergence; no external-reader survey — if a reader outside the tree parsed the old key=value line, it now reads prose, which is exactly what the ConsumerUnresolved row says. DESIGN.md regenerated via generated_artifact_gate main_wet.

🤖 Generated with Claude Code

https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

gunbc-ci-auto-heal and others added 2 commits September 11, 2026 02:32
…hard laws

Adds the conformance-decision domain to gunbc.design_argument conformance_domains,
homed on std.decision (DecisionSubject, RealizationSelectionResult, SelectionReceipt,
select_realization) and std.pareto (SelectionAxis, ParetoEntry, DominanceVerdict).
The row is narrow: inhabitance of the decision/Pareto models, or a stated departure.
Consumer route for the home: gunbc.spark.serving_deployment_selection
select_serving_deployment and product.fleet_operating_point fleet_operating_point_selection
call select_realization; exercised by test.claim.spark.serving_deployment_selection_witness_test
and test.claim.realization_selection_witness_test.

The s3d.selection-precedes-convergence reviewer keeps only the hard laws (no answer
outrunning field/constraints/evidence/policy; a front is not a winner; missing funded
evidence is never a fabricated zero or settled fact; goal assessment/ensure never choose)
and says a stated home departure excuses none of them. Home-inhabitance tells moved to
the conformance row.

Witness: a_stated_departure_from_the_decision_home_is_admitted_while_the_selection_law_still_fails
folds one plan through the existing review machinery -- conformance-decision answers
DivergesStated (approved with reason), selection-precedes-convergence requests changes on the
same file, the report fails; the converse plan with the laws honoured approves.

gunbc.design_document: "missing authority" -> "selection authority" in §3d; §3b no longer
claims the overlap counter proves the partition (review_criterion_identities_are_unique proves
unique keys only and disclaims semantic exclusivity); scope/ownership mismatch distinguished
from a non-resolving citation; §3d records the admitted row and that the effectful
convergence cycle (plan, admission, actuation, readback) still has no consumed home.
DESIGN.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
…h the observation model again

Lane B of the process-observability brief.

Row: conformance-observability on gunbc.design_argument conformance_domains, homed on
std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and
gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting;
repository populations stay with gunbc.repository_census_observation, delivery with effects.

Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation
row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in
gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall,
seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults,
rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the
stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its
own rate/share functions. seed_heartbeat_line is the oracle over that input space;
cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no
interpreter on that thread); floor_resource_sample and the stall window become typed
producers (FloorResourceSample, floor_stall_window_observation) with None for unread
sources -- nothing formats a number outside the mirror.

Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes
on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat,
the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing;
cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror
byte-equal to the interpreter on the same two specimens (off the merge path: rung drop
rust_unit_tests_off_the_merge_path).

Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and
consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is
ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep.
seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory]
lived only in required_floor_runner.rs, so the census could not find its own row and the
declined hygiene suite reported nothing. New executing witness
observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep)
are repaired to the restored subject and their standing restated -- the lockstep
no-fabrication row had gone false a second time on the same cli_run split.

DESIGN.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
@gunbai-bot gunbai-bot Bot changed the title conformance §3b observability conformance row; the floor heartbeat renders through the observation model again Sep 11, 2026
@gunbai-bot
gunbai-bot Bot changed the base branch from main to session/stern-heron-185 September 11, 2026 03:21
gunbc-ci-auto-heal and others added 2 commits September 11, 2026 03:22
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor Author

Execution receipts for the Rust half (head c2e37afb25d):

  • clippy, all targets (the CI-equivalent step) — BuildBuddy remote, amd64: cargo clippy -p v1-compiler --all-targets -- -D warnings → CLIPPY_RC=0.
  • oracle equality — cli_run::heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle plus the two floor_stall_metric_tests: test result: ok. 3 passed; 0 failed (release, --lib). Run locally in the session container, not on BuildBuddy: the interpreter's host-budget arm refuses a runner with no cgroup memory limit (HostBudgetUnreadable, the documented BuildBuddy receipt in gunbc.host_budget_source), so an interpreter-backed test cannot execute there by design — the remote attempt panicked at exactly that arm. The session container carries a cgroup bound, so the oracle resolved gunbc.observation_seed_render through the interpreter and the mirror matched it byte-for-byte on both specimens.
  • floor-side (claim_batch on this tree, borrowed interpreter): observation_seed_heartbeat_witness_test 5/5, observation_emit_census_producer_witness_test 4/4, observation_ci_render_witness_test all green, observation_crawl_replay_test 3/3, observation_seed_scoped_run_witness_test 10/10; the declined suites observation_emit_census_witness_test 20/20 and observation_lockstep_witness_test 7/7 — executed here only; their floor standing is still declined and the PR body says so.

— sent from stern-heron-185

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 11, 2026 03:38
Review 63436: cpu_ms/cgroup_charge_bytes/stall_window_ms/stall_user_cpu_ms (and
elapsed_ms, rss_bytes) were bare Nat with a unit suffix. They are now Millisecond /
ByteSize, on the precedent of ci_batch_summary_text's `work: Nanosecond`; the seed test
builds each carrier through the interpreter's millisecond / byte_size constructor, so a
caller handing the wrong unit cannot typecheck. Dimensionless counts stay Nat.
Oracle test green locally (3/3); floor witness 5/5.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63436 (blocking, flat-scalar unit params on seed_heartbeat_line) — fixed in 9c36ff9. elapsed, cpu, stall_window, stall_user_cpu are now Millisecond and rss, cgroup_charge are ByteSize; the oracle runner in cli_run::heartbeat_tests builds each carrier through the interpreter's millisecond / byte_size constructors (the ci_batch_summary_text work: Nanosecond precedent), so a wrong unit at the seam no longer typechecks. Dimensionless counts (faults, events, swap-ins) stay Nat. Re-run receipts: oracle-equality test 3/3 locally (interpreter-backed, same cgroup-bound caveat as the comment above); observation_seed_heartbeat_witness_test 5/5 under claim_batch.

Noting for the record rather than as a counter: every pre-existing fn in gunbc.observation_seed_render (phase_concluded_line elapsed_ms: Nat, seed_peak_rss_line rss_bytes: Nat, seed_psi_hold_line avg10_bp: Nat, …) still uses the bare-integer seam shape this PR inherited; converting them is the same mechanical change and is out of this PR's scope.

— sent from stern-heron-185

Base automatically changed from session/stern-heron-185 to main September 11, 2026 05:12
…md regenerated via generated_artifact_gate main_wet)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
@briansrls
briansrls merged commit 624197e into main Sep 11, 2026
8 of 16 checks passed
@briansrls
briansrls deleted the session/stern-heron-185-observability branch September 11, 2026 16:50
@briansrls
briansrls restored the session/stern-heron-185-observability branch September 11, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant