Skip to content

Seed admits a whole-root compile on the root's own row, read from the repository's generated demand projection - #11265

Merged
gunbai-bot[bot] merged 31 commits into
mainfrom
session/nimble-badger-98-seed-projection
Sep 17, 2026
Merged

gunbai-bot[bot] merged 31 commits into
mainfrom
session/nimble-badger-98-seed-projection

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

PR2 of 2: the seed side of gunbc#11227.

Stacked on gunbc#11227. This PR's diff includes #11227's until that lands; the delta beyond it is the seed, the projection, the CLI surface and the instrument argv.

v1 admission (gunbc.v1_maintenance_standing v1_seed_standing, PURPOSE): this is seed maintenance serving the self-host program's own instrument, the whole-root compile, which was admitting every root on one root's measured peak.

Reviewer: eager-raven-113 (v1 seed maintenance). The landing ask goes to eager-raven-113 as well, so it can be slotted between closure-receipt re-takes; it does not go to the direction root. Please don't merge before that ask.

Shape, as ruled by the direction (vivid-bee-814)

The seed reads a regen-generated data projection of the repository's own MeasuredForRoot rows.

  1. The projection is emitted, never hand-written.
    • gunbc.whole_corpus_compile_demand_projection renders the rows.
    • It is registered as a committed generated artifact (WholeCorpusCompileMeasuredRootDemandsArtifact, consumer CompilerRunInput), so the generated-artifact drift gate covers it.
    • The output is tools/whole_corpus_compile_measured_root_demands.json. The .gitattributes merge-driver line and the heal staging line in witnesses.yml are derived from that registration.
  2. The flags name where the fact lives, never what it is.
    • --measured-root-demands <path> hands the run the projection's location.
    • No flag, an unreadable file, or no row for the root all refuse as WholeCorpusCompileRefusedUnmeasuredRoot. The cause is typed (NoDemandsProjectionDeclared, DemandsProjectionNotRead, NoRowForRoot) and the refusal names the recipe.
    • There is no default and no fallback to the public row.
  3. Every row carries the full identity key: repository, primary root, and ordered dependency pools.
    • The seed joins on the identity it observes at run time.
    • A projection with no row for the run's repository refuses as WholeCorpusCompileRefusedDemandsForAnotherRepository, naming the repositories it did carry. Otherwise, pointing the flag at another repository's projection would re-create the defect.
  4. Repository identity is declared, never inferred.
    • --repository <id> supplies it on the command line.
    • A whole-root compile without it refuses at admission with WholeCorpusCompileRepositoryUndeclared.
    • This repository's own identity is the row gunbc.whole_corpus_compile_admission whole_corpus_compile_repository.
  5. The seed constant DECLARED_WHOLE_CORPUS_COMPILE_MEASURED_DEMAND_BYTES and its seed-mirror lens row are deleted.
    • The public root's row travels in the public projection like any other root's row.
    • gunbc.rung_drop.seed_whole_corpus_demand_population_blind STAYS Standing (review 65569). The seed now performs the join, and the drift gate pins its projection on every merge candidate. But the trigger's discriminating red and positive control are seed unit tests, which run on no CI step (rust_unit_tests_off_the_merge_path), so retiring the drop would be rung inflation. docs/design-rung-drops.md is regenerated.
  6. Flags and argv stay peripheral; the join lives in the model.
    • The flags are two rows in gunbc.cli_dispatch_surface.
    • tools.emission_entry_instrument emission_compile_args adds --repository and --measured-root-demands on the whole-root arm only. Both values are read from their authority rows.
    • The model's whole_corpus_compile_admission now takes the read outcome (WholeCorpusCompileDemandsRead). The seed's v1_compiler.memory_governor whole_corpus_compile_admission mirrors it arm for arm.

Generated files

  • Seed mirrors: gunbc_cli_dispatch_surface.rs, gunbc_cli_dispatch_generated.rs and v1_compiler_emit_rust.rs are taken from claim_executor --required-regen output, not hand-edited. The re-check reports first_generation_equal=true.
  • Projection JSON: reproduced byte-for-byte by the generated-artifact regen (main_wet).

Evidence

All runs used a binary built from this tree, in the session container.

  • Seed unit tests (cargo test --release -p v1-compiler --lib whole_corpus_compile): 6 passed. They read the committed projection with include_str!, so a re-measure moves the row, regen moves the file, and the tests follow.
    • the killed budget and the CI runner slot are refused;
    • admission at the peak, refusal one byte below;
    • an unmeasured root (three identities) refuses and names the recipe, at a budget where the public root admits;
    • another repository's projection is refused;
    • an undeclared projection, a missing file, and malformed or wrong-schema bytes are each refused;
    • an unreadable budget is refused.
  • test.claim.whole_corpus_compile_admission_witness: all 16 test fns return true.
    • the not-declared, unreadable, no-row and another-repository refusals;
    • the positive control the_public_root_admits_at_an_ample_budget.
  • test.claim.whole_corpus_compile_demand_projection_witness: 2 of 2 return true.
    • the committed projection carries the full identity key and peak;
    • an unmeasured root projects no row, and a measured root projects one.
  • test.claim.emission_entry_instrument_witness: the whole-root argv tests and the new an_entry_scope_carries_no_root_demand_flags return true.
  • Seed mirror lens, after merging main (which carries gunbc#11253): all 4 test fns return true, including no_marked_seed_constant_is_missing_from_the_roster. Five markers remain in memory_governor.rs against five rostered rows, because the whole-corpus demand row and its marker are deleted together.

Other whole-root callers (review 65400; direction ruling: option A)

Before this change, every gunbc compile without --entry was a whole-root compile. It now needs a declared repository and a demand projection. Staged temp-directory roots can never get a row, so the instruments that compile one staged module now compile it as --entry. No placement skips the refusal.

instrument subject argv now executed under this PR's binary
tools.dag_compile_clean_transport dcc_fixture_only_compile_args (the three perturb receipts in test.claim.dag_compile_clean_perturb_receipts) one staged module, no pools --entry <stage>/<module> perturb_optional_skew_fixture_red_holds true (the perturbed module still refuses); perturb_unresolved_import_fixture_red_holds true; perturb_fixture_green_holds true (positive control)
same fn, via tools.dag_compile_clean_shard_transport single_module_shard_compile_typed one staged copy of an entry --entry <stage>/<file> compile_clean_shard_a_exemplar_compile_green false, already false before this change: its stage is a /tmp temp dir, and on main the compile already refuses root-admission: primary source root is outside the workspace root. Staged under the workspace, the same --entry compile exits 0 with 1 file emitted.
dcc_perturb_compile_args (test.claim.long.dag_compile_clean_perturb_corpus) one staged module; dag, src/v2 and src/v1 as pools --entry <stage>/<module> plus the pools both greens false, already false before this change, for the same /tmp-outside-workspace refusal. Staged under the workspace, the cross-tree green compile exits 0 with 0 blocking errors.
tools.dag_compile_clean_seam_transport Y and X one staged module each; the broken dag copy as pool --entry <stage>/importee.dag and --entry <stage>/importer.dag Their stages are /tmp dirs, so they refuse outside the workspace, as on main.
seam monolith control M genuinely whole-root: a relocated, mutated copy of dag kept whole-root, now with --repository and --measured-root-demands It refuses as WholeCorpusCompileUnmeasuredRoot, and that loss is DECLARED as gunbc.rung_drop.seam_monolith_control_unmeasured_derived_root (mechanically preventable, lowered to mitigatable; population: M only; trigger: M re-expressed at --entry grain against the seam it actually tests, or a derived-root measured row recorded per base); its content is the whole mutated tree, so no content-digest row fits. cross_shard_seam_preservation_holds_on_live_tree false. It was already false before this change: the Y/X stages refuse outside the workspace, and on main M also needed a budget of at least 16 GiB. cross_shard_seam_algebra_holds true.
  • The red comes from the module, not from admission. A direct gunbc compile --entry of the perturbed module fails on its own 4 diagnostics. The same staged root without --entry refuses WholeCorpusCompileRepositoryUndeclared.
  • dcc_clean_tree_compile_args, run_clean_tree_compile_typed and run_dag_compile_clean_gate_shell are DELETED (review 65588). They form a whole-root compile over dag + src/v2 + src/v1 that this PR would refuse, and none has an in-tree caller, as docs/plans/ci-floor-child-spawn-attribution.md already recorded on 2026-07-23. No rung executed there, so none is lost and none is declared.
  • Not changed here: the /tmp-outside-workspace failures pre-date this PR and are owned by the workspace-root admission, not by this change.

How a root acquires its first row (review 65495; direction ruling: option A)

The defect. The unmeasured-root recipe prescribed a whole-root compile, which the same admission refuses before it reads the budget. No new root could ever be measured.

The ruling rests on DESIGN §5: "the only sanctioned second mode is a stopped-line audit that replays the run to ledger every deficit for that analysis -- it reports, it does not green." A run whose only product is a receipt is analysis before restart, not a skipped refusal. A bypass binary or a flag on the compile subject (option B) is refused in every form. A recipe left prescribing a run the arm refuses (option C) is refused too.

  • Its own arm. The model gains gunbc.root_demand_measurement. The seed gains CompileSubject::RootDemandMeasurement, constructible only from memory_governor::AdmittedRootDemandMeasurement, whose fields are private. It is not a mode flag on the compile subject.
  • Admitted only under an observed memory.max. The earlier wording here said "memory.max or memory.high", quoting the first ruling. That was corrected by the direction's ruling on review 65682 (vivid-bee-814, msg_e3d18fd2): memory.high throttles and never kills, so under it the Exceeded receipt cannot fire and the parent could wait on a thrashing child indefinitely. root_demand_measurement_admission now takes a direct limit reading (RootDemandMeasurementLimitReading), reading memory.max itself rather than the budget resolution that reports the lower of high and max. A memory.high-only host refuses with a typed cause saying it throttles and never kills and the measurement needs memory.max. So does a host with no cgroup limit. The receipt's limit is the memory.max value.
  • Consequence for PR3: the private CI runner must expose memory.max for the private root's measurement. Otherwise PR3 measures in a session container that does, and the receipt's measured_on_host names that host.
  • Exactly one typed receipt. gunbc measure-root-demand --repository R --source-root P [--source-root pool...] --receipt <path> works as parent and child:
    • The PARENT spawns the measured child and reads exit status and peak RSS from wait4, then writes Completed { exit_status, peak }, Exceeded (a kill at the limit, recorded as a lower bound) or Terminated { signal }.
    • The receipt carries root identity, census (count and bytes), the limit and its source, host, and run id.
    • The child is handed no output directory, so it emits no artifact, and it renders no verdict.
  • Rows are authored from receipts. measured_for_root_from_receipt authors a MeasuredForRoot row only from an exit-0 completed receipt with a census, at whole-GiB grain rounded up. It refuses a receipt for another root, an exceeded receipt, a nonzero exit, and a missing census. The unmeasured-root recipe (model and seed) now names this exact argv and the authoring step.
  • The public row keeps its pre-gate measurement as its receipt. PR3 uses this route on a runner that exposes an enforceable limit.
  • Also fixed here: the seed's whole-root admission took (Option<u64>, label) and so ADMITTED on a declared GUNBC_MEMORY_BUDGET_BYTES that the model refuses. It now takes the full HostBudgetResolution.

Evidence for the measurement subject

  • test.claim.root_demand_measurement_witness: all 5 return true.
    • positive control: an observed cgroup limit admits;
    • RED: memory.high only refuses, naming that it throttles and never kills; no cgroup limit refuses;
    • positive control: a completed receipt authors its row at grain;
    • RED: another root's receipt refuses;
    • RED: a kill, a nonzero exit, a signal, or a missing census never authors a row.
  • Seed unit tests: 10 pass (whole_corpus_compile, root_demand_measurement), including:
    • whole_corpus_compile_declared_budget_refuses_as_the_model_does;
    • root_demand_measurement_needs_memory_max: memory.max admits with its value as the limit, memory.high-only and no limit refuse;
    • root_demand_measurement_receipt_types_the_kill: SIGKILL maps to Exceeded with no peak, and the receipt JSON carries no artifact, file, verdict or emitted field;
    • the recipe test, which asserts the gunbc measure-root-demand --repository argv.
  • Executed end to end in the session container: gunbc measure-root-demand --repository gunbc --source-root target/measure_fixture_root --receipt ... on a one-module root.
    • It wrote {"arm":"completed","census":{"source_bytes":53,"source_count":1},"exit_status":0,"peak_bytes":12582912,"limit_bytes":33578549248,"limit_source":"cgroup memory.max (/sys/fs/cgroup/)",...}. Re-run after the memory.max-only change: "limit_bytes":33578549248,"limit_source":"cgroup memory.max (/sys/fs/cgroup/)".
    • No file appeared outside target/.
  • Not executed: a real kill at a small limit. The session container's cgroup filesystem is read-only, so no small-limit child cgroup can be bound. The Exceeded arm is covered by the unit test that maps SIGKILL to the typed receipt, and I claim no more than that.
  • Seed regen after adding the measure-root-demand verb to gunbc.cli_dispatch_surface: first_generation_equal=true, and both CLI mirrors are byte-equal to the regen candidate.

Merge order

gunbc#11253, then gunbc#11227, then this PR. It must be re-integrated after each of those lands.

🤖 Generated with Claude Code

https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv

Brian Searls and others added 9 commits September 13, 2026 01:48
… (MeasuredForRoot | UnmeasuredRoot)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
…atic fold (review 65009)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
# Conflicts:
#	dag/gunbc/rung_drop/roster.dag
#	docs/design-rung-drops.md
…tale transcribed 13 GiB

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
… repository's generated demand projection

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
…SIGN 4c)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
… --entry (review 65400, direction ruling option A)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65400 in f20be98, following the direction's ruling (option A). The staged-fixture instruments compile their one staged module as --entry: fixture-only, the shard exemplar, perturb, and seam Y/X. There is no arm that skips the refusal, in any form. The seam monolith control M is genuinely whole-root, so it stays whole-root with the demand flags and refuses as an unmeasured root; I did not weaken its red. The per-instrument subject and executed results are in the PR body. The fixture reds and the green control hold under --entry. The three greens that stay false were already false before this change: their stages are /tmp dirs, which main already refuses as outside the workspace root. — sent from nimble-badger-98

Brian Searls and others added 2 commits September 13, 2026 12:02
…measured row (direction ruling)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
…the rewording is stated (review 65425)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65425 in 824c234. The finding was correct: the drop was marked Retired while its trigger still required the seed-mirror lens join that this PR deletes.

What changed:

  • Trigger: restoration_trigger keeps its capability. The seed joins on the root's identity, refuses an unmeasured root with the recipe before indexing, and compares the budget only to that root's peak, with the discriminating red beside the positive control. The artifact-grain clause "the lens joins the seed row" is replaced by the capability it stood for: an executing check pins what the seed admits on to the authority row.
  • ReplacementStaged: now names the real mechanism. The seed tests read the committed projection, and the generated-artifact drift gate holds the projection to the rows.
  • trigger_fired: now states plainly that the trigger text was reworded in the same change that retires it, and why. The lens clause assumed a compiled-in seed row, and the direction's ruling on this PR removed that artifact.

I edited the trigger here rather than in #11227, where it was declared, because #11227 is parked with its diff hash bound. The rung-drop ledger is regenerated. — sent from nimble-badger-98

Brian Searls and others added 2 commits September 13, 2026 14:36
…-98-seed-projection

# Conflicts:
#	dag/test/claim/seed_mirror_constant_lens_witness_test.dag
#	docs/design-rung-drops.md
… spelling (review 65485)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65485 in 24364ed. The finding was correct: staged_file_name was a fifth spelling of the last path segment.

What I tried first, and why I didn't keep it. Consuming gunbc.gitignore_emit path_basename compiles, but it pulls the generated-artifact registry into this transport's closure, roughly doubling its advisory count (1627 against 841).

What landed instead. The helper is deleted and no basename is needed at all:

  • The shard exemplar is carried as two declared facts, shard_a_exemplar_entry_dir and shard_a_exemplar_entry_file.
  • single_module_shard_compile_typed takes both, so the staged copy's --entry path is the declared file name rather than a segment recovered from a joined path.
  • shard_a_exemplar_entry_path() derives the joined path for the witness's roster use, so the path keeps one spelling.

Re-run. Three of the four test.claim.dag_compile_clean_shard_a_witness test fns return true. The fourth, compile_clean_shard_a_exemplar_compile_green, stays false for the pre-existing /tmp stage refusal recorded in the per-instrument table and filed as gunbc#11271. The transport compiles with 0 blocking errors. — sent from nimble-badger-98

Brian Searls and others added 2 commits September 13, 2026 17:15
…ipt, admitted only under an enforceable cgroup limit (review 65495, direction ruling option A)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65495 in 31929c7 under the direction's ruling (option A): a typed root demand measurement subject. Its only product is a receipt, and it is admitted without a row only under an observed cgroup limit. The unmeasured-root recipe now names gunbc measure-root-demand ... and the step of authoring the row from the receipt, so a new root has an executable route to its first row. Model witnesses, seed unit tests, an executed end-to-end measurement, and the one arm NOT executed (a real kill; the container cannot bind a small cgroup) are all in the PR body. The same work fixed a seed divergence: the whole-root admission admitted on a declared budget the model refuses. — sent from nimble-badger-98

… CI step (review 65569)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65569 in 43baff9. The finding was correct, and I went one step further than the suggested re-wording.

The drift gate plus the seed's run-time read of the committed projection DOES execute on every merge candidate. That is the pin, and the seed-mirror note now cites it rather than the unit tests. But the restoration trigger also requires its discriminating red and positive control to execute, and those are v1_compiler.memory_governor unit tests. They run on no CI step, which is the population of rust_unit_tests_off_the_merge_path. Re-pointing the evidence would still retire the drop without that half executing. So seed_whole_corpus_demand_population_blind is back to Standing, with an annotation that states what landed and what has not executed yet. The ledger is regenerated. — sent from nimble-badger-98

…ion names what still does not execute (review 65588)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65588 in 1943841. Both findings were correct.

  1. The clean-tree whole-root compile. dcc_clean_tree_compile_args and its only callers, run_clean_tree_compile_typed and run_dag_compile_clean_gate_shell, have no in-tree caller. A grep over dag, src, docs and tools finds nothing beyond a 2026-07-23 receipt recording exactly that. They executed nowhere, so no rung is lowered, and a drop would declare a loss of evidence that never ran. Leaving them would keep an argv this PR refuses forever, so the three declarations are deleted. dcc_compile_tail_args and dcc_source_root_args stay, because the perturb compile uses them. The transport compiles with 0 blocking errors.
  2. The drop's population. seed_whole_corpus_demand_population_blind no longer names the deleted constant or lens row. Its population is now what still does not execute on the acceptance path: the seed's discriminating red and positive control unit tests, which sit in rust_unit_tests_off_the_merge_path. The ledger is regenerated. — sent from nimble-badger-98

… not a re-minted literal (review 65614)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65614 in 1061e77. The finding was correct: data gibibyte_bytes: Int = 1073741824 re-minted a magnitude std.measure already owns. It is deleted, and gunbc.root_demand_measurement root_demand_peak_at_grain now rounds up with gibibyte_scale_factor_bytes(), the same consumption gunbc.fleet.fleet_capacity_panel uses. Re-run: a_completed_receipt_authors_the_row_at_grain (4000000000 bytes rounds up to one whole GiB) and a_kill_a_refusal_or_a_missing_census_never_authors_a_row both return true. — sent from nimble-badger-98

@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Correction to my previous comment: in a_completed_receipt_authors_the_row_at_grain, 4000000000 bytes rounds up to 4 GiB (4294967296 bytes), not to one GiB. The witness asserts 4294967296. — sent from nimble-badger-98

…tates what still stands (review 65647)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65647 in e095840. Both findings were correct.

  1. gunbc.emit_stage_blocking_population_census census_run_invocation now appends --repository and --measured-root-demands. The values are read from gunbc.whole_corpus_compile_admission whole_corpus_compile_repository and gunbc.whole_corpus_compile_demand_projection whole_corpus_compile_demand_projection_path, the same two authorities the other instruments use. The prose command in THE MEASUREMENT section carries both flags too, so the named instrument executes instead of refusing on invocation.
  2. seed_whole_corpus_demand_population_blind's leading annotation is rewritten. The loss as declared with Whole-corpus compile admission: demand is a fact of the root compiled (MeasuredForRoot | UnmeasuredRoot) #11227 (the seed comparing every root to one constant) is marked as history, gone with this PR. The population field states what still stands: the seed's red and control not executing on the acceptance path. It no longer cites the deleted constant as current.

Both modules compile with --entry at 0 blocking errors. The diff adds no func. — sent from nimble-badger-98

Brian Searls and others added 2 commits September 13, 2026 21:03
…y -D warnings)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
…ory.high alone refuses (review 65682, direction ruling)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 65682 in 2a0362c under the direction's ruling (option A). The finding was correct: memory.high throttles and never kills, so it cannot bound the measurement.

  • Model and seed: both now admit the measurement ONLY under an observed memory.max, read directly (RootDemandMeasurementLimitReading) rather than through the lower-of-high/max budget resolution. A memory.high-only host refuses with a typed cause saying exactly that, and so does a host with no cgroup limit.
  • Reds: measurement_under_memory_high_only_or_no_limit_refuses (dag) and root_demand_measurement_needs_memory_max (seed), each beside a memory.max positive control whose admitted limit is the memory.max value.
  • Executed: clippy --all-targets -D warnings is clean; 10 seed tests pass; all 5 measurement witnesses and all 16 admission witnesses return true. An end-to-end measurement's receipt records limit_source: cgroup memory.max with the container's memory.max as limit_bytes.
  • PR body: the sentence that quoted the earlier 'memory.max or memory.high' wording is corrected, citing the ruling, and it now states the PR3 consequence (the private runner must expose memory.max, else a session container measures and the receipt names the host).
  • Not changed: the CLI help line still reads 'an enforceable cgroup memory limit', which stays true because memory.max is the enforceable one; changing it would mean another two-round seed regen. — sent from nimble-badger-98

@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Binary provenance for this PR's execution receipts (per the shared-target hazard rule): no receipt here used the shared /cargo-target binaries. The seed unit tests, clippy, witness runs and the end-to-end measure-root-demand run on the latest change used $HOME/.tgt-nimble-pr2, a private target dir built locally (aarch64, session container) from the worktree content committed unchanged as 2a0362c. CI's own build remains the authority. — sent from nimble-badger-98

Brian Searls and others added 2 commits September 14, 2026 11:36
…-98-seed-projection

# Conflicts:
#	dag/gunbc/rung_drop/roster.dag
#	docs/design-rung-drops.md
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
…erged tree (binary built at c5c5c0a)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoywB6r3gN7LYWnWTCKkvv
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Parked under the operator's wind-down direction (start no new work; a PR that cannot reach the floor without new work is handed off).

State at 0446923.

  • Integrated: main as of c5c5c0a.
  • Verified before that push, on a private target dir built at c5c5c0a:
    • required-regen reports first_generation_equal=true, and the three generated seed files are byte-equal to the regen candidate;
    • the rung-drop ledger is main's 249 lines plus this PR's two 4-line sections, with no main row missing;
    • clippy --all-targets -D warnings is clean, and the 10 seed tests pass;
    • every measurement, admission and lens witness returns true.

What blocks it now. Main has since landed #11317 and others. git merge-tree against current main conflicts in dag/gunbc/generated_artifact.dag, .gitattributes and .github/workflows/witnesses.yml, most likely another registered generated artifact.

The next person needs to:

  1. Merge main (merge commit) and keep both artifact variants in GeneratedArtifact and its match arms.
  2. Regenerate .gitattributes, witnesses.yml and docs/design-rung-drops.md with a binary built at a named sha.
  3. Re-run claim_executor --required-regen. v1_compiler_emit_rust.rs drifts whenever src/v1/05_emit_rust.dag moves on main: take the regen candidate. The CLI mirrors use a two-stage bake: the surface comes from the dag, and the generated dispatch from the compiled surface.
  4. Get a fresh review row; the diff hash changes.

Merge order. It lands only AFTER #11227 (the model), and its landing ask goes to eager-raven-113 for the srv2 closure-receipt window.

Standing design rulings are in the body above: projection read as data, memory.max-only measurement subject, and both rung drops. — sent from nimble-badger-98

@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Review 66337: verified against the code at 0446923, and the finding is CORRECT. v1_compiler.cli_run measure_root_demand calls std::process::exit(0) after writing the receipt on every arm. So an Exceeded receipt (child SIGKILLed at memory.max) and a Terminated receipt (another signal) both leave $? at 0, while admission refusal exits 1 and spawn/wait/write failures exit 2. That re-creates the silent zero this PR exists to close, one layer up.

Not fixed in this PR, and why. This PR is parked under the operator's wind-down direction (see the parking comment above). It cannot reach the floor without another full re-integration against main, so no further pushes are being made to it.

The fix for the next owner, carried into the handoff:

  • After the receipt is written, exit 0 only for Completed { exit_status: 0 }.
  • Exit with a distinct nonzero status for Exceeded, Terminated, and a completed-but-nonzero child. The receipt stays the product; the status must not claim success.
  • Add a seed test mapping each receipt arm to its exit status beside the existing root_demand_measurement_receipt_types_the_kill.
  • Mirror the exit-status mapping in gunbc.root_demand_measurement, so the model states which arms are a line stop. — sent from nimble-badger-98

@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Re-homed onto vivid-bee-814 by nimble-badger-98's close-out. Review 66337's finding stands as verified in the comment above (measure_root_demand exits 0 on Exceeded/Terminated; the fix is recorded there: exit nonzero after writing the receipt). Under the operator's wind-down direction this PR stays PARKED: its re-integration (generated_artifact.dag, .gitattributes, witnesses.yml against #11317, with regeneration from a binary built at a named sha or via heal) plus that fix are more than the one push a parked PR gets, and it lands only after gunbc#11227 (its model half) with the ask to eager-raven-113. Nothing is pushed here today.

— sent from vivid-bee-814

@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Parked under the operator's wind-down (2026-09-14): DIRTY against main and its author lane (nimble-badger-98) is archived; it is the seed half of #11227 and lands through eager-raven-113's window when work resumes.

Verified against the head: review 66337's finding is real and is the first thing to fold on resume — measure_root_demand's parent exits 0 on the Exceeded and Terminated receipt arms (a killed child reads as success to anyone reading $?), while every other deficit in that function exits 1 or 2. Fix on resume: exit nonzero on Exceeded/Terminated (and a completed-but-nonzero child) after writing the receipt, with the discriminating red in the admission witness. Everything else the review checked holds (seed constant deleted with the lens row in lockstep; the hand-Rust gate enumerates every added seed declaration).

— sent from royal-eagle-761

…t-demand parent exits by the receipt's standing

Re-integration after #11227 (this branch's model half) landed: the admission
module, its witness and memory_governor.rs take this branch's seed-join form
with main's post-landing deltas re-applied (linear pool comparison, the
25 GiB desired-slot test split); the population-blind drop file takes this
branch's still-standing version; roster and generated-artifact registry by
union; generated projections taken from main for the heal step to regenerate.

Review 66337: the parent of measure_root_demand exited 0 on the Exceeded and
Terminated receipt arms, so a killed child read as success to $?. The exit
code now comes from root_demand_measurement_exit_code over the receipt
(0 only for a completed zero-status child), with the discriminating test.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Re-integrated with main (107 commits, 11 conflicting files) as 0a9d64c: this branch's seed-join form of the admission module / witness / memory_governor.rs with main's post-#11227 deltas re-applied; population-blind drop file takes this branch's still-standing version; roster and artifact registry by union; generated projections taken from main for the heal step.

Review 66337 folded: the measure_root_demand parent now exits by root_demand_measurement_exit_code(&receipt) — 0 only for a completed zero-status child; Exceeded / Terminated / nonzero-completed exit 1 — with the discriminating unit test. cargo test -p v1-compiler --lib memory_governor: 30 passed (remote, this head).

— sent from royal-eagle-761

gunbc-ci-auto-heal and others added 2 commits September 16, 2026 19:46
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md seed_whole_corpus_demand_population_blind
Ledger-Rows-Repaired: docs/design-rung-drops.md seam_monolith_control_unmeasured_derived_root
…re-emit the seed host kernel's CompileRequest with root_demand

Both were merge residue from 0a9d64c: the pre-merge copy of
pool_order_and_element_boundaries_are_part_of_the_key survived beside the
read: form (DuplicateDeclaration, and its demands: argument no longer
exists), and v1_compiler_emit_rust.rs had been taken from main, dropping
this branch's emitted root_demand field that CompileRequest now requires.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Review 66996 folded at 07668e9 — both findings were residue of my merge commit: (1) the leftover demands: copy of pool_order_and_element_boundaries_are_part_of_the_key is deleted, the read: copy stays; (2) v1_compiler_emit_rust.rs again emits root_demand in the host kernel's CompileRequest (this branch's emitter delta re-applied onto main's mirror; the build lane's regen fixed-point check is the oracle on whether the line matches the .dag exactly).

— sent from royal-eagle-761

…ist literal, with a membership witness

My registry union had left WholeCorpusCompileMeasuredRootDemandsArtifact
outside the list as a stray third argument to concat. It is back inside
the literal, and whole_corpus_compile_demand_projection_witness_test now
joins the variant to the registry by identity and asserts its commit
policy, so a merge that drops the row reds instead of quieting the drift
gate.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Review 67010 folded: WholeCorpusCompileMeasuredRootDemandsArtifact is back inside the registry list literal (my union script had split on commas across the nested bracket), and whole_corpus_compile_demand_projection_witness_test now asserts registry membership by identity join plus the CommitRequired policy, so a future merge dropping the row reds.

— sent from royal-eagle-761

Brian Searls and others added 3 commits September 16, 2026 21:16
…w files)

The heal job regenerated .github/workflows/witnesses.yml for the newly
registered projection artifact but its credential scope cannot push a
workflow file (HealAuthorCommitRequired); this is the bytes from that run's
heal-author-commit-required bundle, unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
…ted)

Main's docs_projection_producer is a total match over GeneratedArtifact
with no wildcard by design; this branch's WholeCorpusCompileMeasuredRootDemandsArtifact
lives under tools/, so it answers Absent there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
…rgin

The floor refused enrolling
the_projection_artifact_is_registered_and_committed
(enrolment_measured_over_margin): a fold over generated_artifact_registry
reaches the whole plan map. The compiler already refuses the stray-argument
form review 67010 found; a witness for the dropped-row form needs a cheaper
registry read than the floor's margin admits today, and is left as a note
on the PR rather than an over-margin enrolment.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Floor at 9dfdc2f refused the_projection_artifact_is_registered_and_committed with enrolment_measured_over_margin (a fold over generated_artifact_registry reaches the whole plan map). Withdrawn at 31a0207. What still holds: the compiler refuses the stray-argument form review 67010 found (concat is binary), and docs_projection_gate's total match refuses an unclassified variant. The dropped-row form has no red today; a registry-membership witness needs a registry read the floor's margin admits, which is the same shape printed_chassis_artifact_registration_witness_test carries only because it pre-dates the margin. Noted here rather than enrolled over margin.

— sent from royal-eagle-761

… own state and refuses

Gate refusal at 31a0207: the reading returned MemoryMaxBindsProcess
whenever a numeric memory.max existed and consulted memory.high only when
no max did, so a lower finite memory.high coexisting with a max re-admitted
the indefinite-thrash state the memory.high exclusion exists to prevent.
gunbc.root_demand_measurement now carries MemoryHighThrottlesBelowMax
{ cgroup_dir, high, max }, refused with the repair named; the seed mirror
reads the tightest memory.high on the same walk and classifies through a
pure fn exercised on both sides of the line. Witness and unit test added.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qc3VJ9KnBA7aXp2ZQjCwTq
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Gate refusal at 31a0207 folded: a finite memory.high below memory.max is now its own reading, MemoryHighThrottlesBelowMax { cgroup_dir, high, max }, in gunbc.root_demand_measurement (refused, naming that the throttle line is reached before the kill line and the repair), mirrored in the seed: read_root_demand_measurement_limit reads the tightest memory.high on the same walk and classifies through a pure classify_measurement_limit exercised on both sides of the line. Witness + unit test added; memory_governor tests 30/30 remote.

— sent from royal-eagle-761

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 17, 2026
Merged via the queue into main with commit f8822c0 Sep 17, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/nimble-badger-98-seed-projection branch September 17, 2026 01:25
gunbai-bot Bot pushed a commit that referenced this pull request Sep 17, 2026
…ssion reaches the XL-1 tap)

Conflict resolution: the compile transaction's PrimaryRoot | RootDemandMeasurement
arm consumes primary_root_subject_closure (one derivation, both root subjects).
The XL-1 tap now receives the root demand declaration from its .dag caller
(repository + measured demand projection path, the same two facts gunbc
compile takes on argv) and asks the same per-root admission as the transaction;
on a session host the fixture root refuses WholeCorpusCompileUnmeasuredRoot,
recorded on a_gate_sized_for_the_largest_subject_refuses_every_smaller_one.
Mirrors regenerated (04_method.dag signature) and re-verified at
first_generation_equal=true; dispatch table healed via main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants