Repository navigation
Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease - #11555
Conversation
… follow-up for the codec-move rows The wave-admission wall: touching the roster brings every consumed row due -- the CONVERGENCE-ONE C2 rows (gunbc#11425) were satisfied at the base and are deleted here -- and a used row must name the pull request that deletes it. The two codec-move rows now name #11555 (Cut D 2b), which removes them. The other floor blocker on the previous head, MemoryStallRefusedPageThrash on srv4-01 (138161 major faults/minute, swap off), is the runner's, not the diff's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Round 4 pushed as 280ac1d. Against review 67799:
Also in this push, from the side-chat hold: the claim is now fleet-global on the event log, recovery is one join over claim × authority history covering both crash windows, the subject carries the exact host population with a SHA-256 intent, and the front-door status distinction is executed against a local listener — which caught |
|
Round 6 pushed as 9267157. Against review 67905:
Also in this push (side-chat hold): a foreign lifecycle against a pending state is refused without aborting the claim; the authorized hosts are frozen on Pending/Suspended/Fenced and |
|
Round 8 pushed as 821b137. Against review 67966: the enrolled port is Also in this push (side-chat hold): host-effect placement is a claim on the group's authority partition (a fence at the head, not a pre-check); legacy event chains have |
|
Round 9 pushed as 1a9b860 (main merged; the conflict with #11617's Also in this push (side-chat hold): host-effect liveness is quiescence-required (an overdue claim still fences until released with a receipt); one live effect per host, at the fold, at the claim and in the standings, with hosts of no claimed group claiming on their own partition; a production backfill entry ( |
|
Round 10 pushed (head Side-chat hold (release evidence, claim home, annotation):
Review 68107: both findings fixed — Local: authority-log hermetic (18) and wet (7), host_commitment (24), capacity standing (16), apply (4), v41 build (25), D0 hermetic (20), D0 wet (13), front door (6) all pass. |
|
Round 11 pushed (head
Local: authority-log hermetic 24/24 and wet 7/7; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ the pre-existing main red noted in the body). |
|
Round 12 pushed (head
Local: authority-log hermetic 25/25, wet 7/7; D0 wet 13, front door 6, host_commitment 24. Review 68255 (APPROVE, no findings) — noted, nothing to act on. |
|
Review 68286: fixed at Side chat: SOURCE APPROVE at |
|
CI on |
|
CI on |
|
Review 68373: valid, fixed at |
|
Transition-admission migration for gunbc#11704. No action until the operator sequences #11704's landing. gunbc#11704 moves namespace transition admissions out of the tree. Once it lands, any file under To migrate (paste + delete), after #11704 is on main and merged into this branch: git rm \
dag/gunbc/namespace/transition_admission/gunbc_boot_artifact_delivery_staged_digest_standing_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_bind_observed_access_context_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_control_route_evidence_unnamed_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_probe_evidence_unnamed_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_disposition_derive_fleet_admission_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_disposition_environment_of_qualification_digest_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_adjudicate_single_callback_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_ledger_link_refusal_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_ledger_step_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_intake_producer_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_intake_subject_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_optional_content_hash_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_machine_intake_subject_compare_qualification_subject_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_join_available_bundle_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_join_verified_ticket_after_trust_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_secure_boot_trust_admission_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/product_capacity_pool_events_pool_event_kind_decode_member_nat_event_json.dag \
dag/gunbc/namespace/transition_admission/product_capacity_pool_events_pool_event_kind_decode_member_nonempty_event_json.dag \
dag/gunbc/namespace/transition_admission/test_claim_machine_intake_bmc_secure_witness_test_dev_test_standing_cannot_be_inherited_for_production_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_a_definite_refusal_carries_the_acquiring_record_it_was_read_from_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_a_duplicate_refusal_reads_its_record_from_the_wrapper_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_an_outcome_carries_the_acquiring_record_it_was_read_from_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_the_issued_digest_and_architecture_come_from_one_artifact_content_hash_equal.dag \
dag/gunbc/namespace/transition_admission/test_claim_network_boot_delivery_join_witness_four_receipts_join_to_established_content_hash_equal.dag
git commit -F msg.txt # msg.txt = the text below, verbatim
msg.txt |
|
Round 13 pushed (head
Local: authority-log hermetic 26/26, wet 8/8; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ the pre-existing main red). |
|
Round 14 pushed (head
Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ pre-existing main red). |
|
Round 15 pushed (head Side-chat hold on
Review 68501 (both findings valid, fixed): Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, D0 hermetic 20, host_commitment 24, capacity standing 16, apply 4, v41 build 25, harness_seat 6 (+ pre-existing main red). |
|
Round 16 pushed (head
Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, D0 hermetic 20, host_commitment 24, capacity standing 16, apply 4, v41 build 25, harness_seat 6 (+ pre-existing main red). |
|
Round 17 (side-chat hold at b18fed3), all three seams:
Controls: hermetic intent-mismatch reds (actor / head / next authority); wet inverse control — E1 append-claims P at H, a stranger's claimant-terminal abort refuses and the head is still H, then only the operator's recovery cancels (E1's append is then stale). Also in this push: review 68630 — — sent from proud-deer-538 |
|
Round 18 (side-chat hold at f0b3b7d):
Controls (hermetic, 4 new claims): claim by E2 naming E1 refuses / by E1 lands as CI heal red at f0b3b7d ( (drop the — sent from proud-deer-538 |
|
Re-realized on the fabric DB (main's #11723 replaced git under the fabric event log; #11550 closed per operator decision, its diff carried here; base is now
Review 68755 (fixed): Round 18 (typed — sent from proud-deer-538 |
|
Round 19 (side-chat hold at b376fa1), at
Also: the stale SHA-1 / git-oid wording corrected; — sent from proud-deer-538 |
|
Round 20 (side-chat hold at 408f9ef), at
— sent from proud-deer-538 |
|
Round 20b at — sent from proud-deer-538 |
eeef609 to
dc0e8ac
Compare
|
CI floor red at d1053a6 / #11666's d97e615: main's #11743 left a source annotation inside the — sent from proud-deer-538 |
…e plan/dsv41-cut-d-2b delta re-applied over main@5f4202a5c6 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
b1e20cd to
011c076
Compare
…r_memory_demand, r2_permission_group_observe, namespace_reference_derived_residency_qualification): a source annotation inside a declaration body refuses to parse and reds every floor run Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion wall was deleted by operator ruling 2026-09-19 (gunbc.rung_drop namespace_wave_admission_wall_removed) and a row file in the tree now refuses to resolve Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # ROADMAP.md
…t_capture_historical_binding and runner_microvm_boot_probe to module grain (they refuse to parse and red every floor run) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…test to module grain
…left in chunk_20 (expected expression, found Newline; reds every floor run) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
CI floor at — sent from proud-deer-538 |
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused Heal-Candidate-Run: 35538018867
…ot quiet (OccupancyNotQuiet names every live rank; never dropped into a drifted population); PlacementCleanupUnread replaces the minted "unknown" preparation id and D0 carries preparation: none; the repair binds the consumption it acts on once; one read budget on gunbc.fabric_event_log; the misnamed HostEffectClaimed.generation deleted Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69399 — all five fixed at
Local: D0 hermetic 21/21, wet 13, front door 6; authority-log 32/9; host_commitment 24. — sent from proud-deer-538 |
# Conflicts: # ROADMAP.md
# Conflicts: # ROADMAP.md # dag/gunbc/target_binding.dag
Summary
Carries Cut D PR 2a (#11550, closed per operator decision 2026-09-20 after main's #11723 replaced git under the fabric event log; this PR is re-realized on the fabric DB) and implements D0 of docs/plans/dsv41-cut-d-redesign.md.
Realization (after #11723): every partition this PR adds lives on the fabric DB through
gunbc.fabric_db_client FabricDbBinding(gunbc.fabric_event_log_host event_log_store_for_hostfrom the executor).gunbc.fabric_event_loggains the codec-parameterizedevent_log_read_partition_with/event_log_append_with(the pool-event forms delegate to them), so one store walk and one put-and-advance serve every partition kind. Partition names carry no separator (pair-serving-authority-<group>,host-placement), the one predicate the store's slot addressing asks. The git-era refs backfill entry and its witness are gone with the git realization.gunbc.spark.released_baseline:ReleasedBaselineSpec = QuiescentReservedBaseline | FleetReleasedBaseline, the type ofSuspendedForAuthorizedSuccessor.cleanup.D0Subjectcarries the group and its exact host population, the keyed successor, the cleanup baseline and the lease term.d0_populationjoins the granted hosts tofabric_group_hosts(group)by identity in both directions; a difference refuses before the claim and again before the first authority write. The grant's intent is a SHA-256 over one canonical encoding (d0_intent_text: required scope, group, sorted hosts, successor, cleanup, term, transaction) taken through the sha256sum realization — unavailable is a typed refusal, never a structural fallback.gunbc.durable_cas_fabric_db: a second realization ofstd.durable_compare_and_setbound to a fabric-DB head (slot = headcas-slot-<key>, each generation one link-free object carrying the value, its content digest and the generation it lands (so a cycled value is a different object at each generation and a stale expected-object advance isFabricHeadMoved), the slot's generation the head's own CAS generation and the object's carried generation verified against it on every read,ExpectSlotAbsent/ExpectSlotGenerationan advance against an absent head / against the observed object; a moved head is re-observed so the loser reports what is there; takes the file store'sVerifiedCasAttemptso one digest admission serves both handlers).std.scoped_authorization's claim slot lives there for D0, so two executors racing for one grant produce exactly oneClaimedBy.parse_authorization_claim_stateis the exact inverse of the serializer, for readers that must know who holds a slot.AuthorityTransitionRecord{id, transaction, lifecycle, next};d0_recoveryis one pure join over the claim reading and this lifecycle's history — selected by binding, never by the transaction word, so a fresh escalation reusing a word is not completed from the old one's terminal: claim absent → start;ClaimedBy(T)+ no transition by T + Active → perform the first write; + not Active → abort the claim; pending under T → resume; T's last transition settled → complete the claim with no authority write; T's pending moved by another writer → refused for an operator; held by another / spent / unreadable → refused. A binding-digest failure after the claim landed aborts the claim rather than stranding it. Population drift after the claim is split: before any write it aborts the claim; after the pending state landed the transaction still reaches a terminal under its original authorization (drift is carried into the readings and fences), so a source edit cannot strand the group. The lifecycle is not the executor: the binding carries no executor, so every executor reads the same history and any executor completes a settled lifecycle (Suspended or restored Active) — never aborting or restarting it; a pending lifecycle is owned by the lease's owner fingerprint, and another executor is refused there (no handoff is modeled). The authorized hosts are frozen on every state D0 writes (hostson Pending/Suspended/Fenced);pair_serving_committed_hostsis whathost_commitmentconsumes, and the effectful admission seams (admit_unplaced_host_live, the reachability probe) now read the current authority from the event log before deriving commitment — refusing when any group is unread. Host placement is one partition, and it is the linearization point. Every fact about placement — every effect claim (HostEffectAdmitted{host, purpose, executor, term: Second, residue}), every release, and every authority write's preparation / finalization / abort — is an event on the onehost-placementpartition, and every writer is a CAS against its head. An authority write is a saga across two logs that never frees a host early: prepare → claim → authority → finalize, one saga per group at a time.PlacementPrepared{operation, group, previous_hosts, next_hosts}lands first and fences the union of both populations (refused under a live effect, under another group's fence, whenprevious_hostsis not the group's live commitment, or while the group has another pending preparation; stale when the partition moved); the writer then landsPlacementAppendClaimed{preparation, intent}on the same head — the claim is its intent: the placement fold refuses a claim whose event actor is notintent.actor, and one whose intent is not the write its preparation is for (group, populations the intent's states leave and enter, operation — the samepreparation_ref_refusalthe group fold applies), and recordsAppendClaimed{claimant: intent.actor, expected_head: intent.expected_head, intent}; the intent names the group head the append will CAS against and the exact write it will make: the typedAuthorityWriteIntent{group, expected_head, actor, previous?, next, operation, lifecycle?, grant?, entry_state?}; the consuming group event carries no intent because its intent is the event (event_write_intentderives it from the envelope's parent and actor and the payload's fields), and every joined read compares the claim's carried intent to the consuming event's derived one field for field (write_intent_eq; no digest stands between them) — so another actor, an append retargeted at a later head, or a different next authority/grant/lifecycle over the same host population and operation cannot consume the claim — so an abort and an append contend on one head at every stage: whilePrepared, on the placement head (an abort that read itPreparedis stale once the claim landed); once claimed, on the group head — a recovery abort first landsAuthorityAppendCancelled{preparation, provenance}on the group partition at the head the claim named — after its provenance was admitted against the record (an append-claimed preparation is cancelled only by its claimant,ClaimantTerminalnaming it with the event's actor the claimant, or by aRecoveryAuthorizednaming it; a stranger's abort attempt writes nothing and the group head stays where the claim named it), and the cancellation carries that provenance so replay verifies who wrote it; the group fold refuses a cancellation of a preparation an accepted authority event already consumed (and, as before, a consumer of a cancelled one), so consumed and cancelled exclude each other in both directions, and the joined read requires the cancellation to have been appended at the head the claim named (CancelledPreparation.at_head) (the claimed append's CAS can then never succeed), and only then aborts; a stale cancellation means the head moved, and a fresh join decides: consumed → finalize, never abort; moved otherwise → the abort is safe; the group event (AuthorityEstablished/AuthorityTransitioned) carries a typed copy of the preparation (PlacementPreparationRef{id, group, previous_hosts, next_hosts, operation}) and the group fold refuses a copy whose group is not the partition's, whose populations are not the states' the event leaves and enters, or whose operation is not the event's;PlacementFinalized{preparation: <the same copy>, authority_event}lands last, only for an append-claimed preparation and only when the copy is the record, and retains exactly the next population. The live join (preparation_consumption) reads the record on the placement chain (the group is the record's, never a caller's word) and takes consumption only from the group's accepted fold (AuthorityFold.preparations_consumed: exactConsumedPreparation{preparation, authority_event, intent}) — never from raw chain presence, so an event the fold refuses (a cancelled or already-consumed preparation, a stale previous state, a bad grant) consumes nothing and a refused fold is Unread; the copy must be the record and the intent the claim's — Consumed / NotConsumed{group_head, cancelled} / Absent / Unread, never a fabricated identity. Every authoritative read is joined across both logs:current_pair_serving_authoritylooks up every preparation its chain consumed on the placement chain (present, append-claimed or finalized to that event, copy equal to the record, intent equal to the claim's — else unread; every cancellation it folded must be covered on the placement side by a claimant-terminal or recovery abort of that preparation), andplacement_readlooks up every finalized preparation on its group's accepted fold (consumed by exactly the named event with the record's copy and intent — else unread); the group fold refuses a second consumer of one preparation and a consumer of a cancelled one. A crash before the group append over-fences; after it, over-fences until finalization; a release never exposes its old hosts before the authority moved.PlacementAborted{preparation, reason, provenance}is admitted only when the join says unconsumed, and its provenance must be the claimant's own (an append-claimed preparation is aborted by its claimant, written by its claimant) or a recovery naming it — the same claimant-terminal vs recovery-authorized model as host effects. Each writer prepares its own preparation; a losing writer aborts only what it prepared. Because one preparation per group is pending at a time, finalizations land in authority order. D0 retains the placement standing:AuthorityTransitionRecordcarries the preparation copy; a settling write whose finalization did not land isD0PlacementStillFencing(the consent is not complete, the claim stays held); a rerun repairs the group's pending preparation from the join before its own saga (placement_repair_pending) andD0RecoverCompletefinalizes the settled write's preparation before it completes the claim. Every authority outcome carries its placement standing (PlacementFinalizedAt/PlacementAbortedAt/PlacementCleanupStillFencing{preparation, cause}) — a cleanup that did not land is never dropped from the result; operator routeshost_placement_finalize_wet --arg preparation=(finalizes from the join) /host_placement_abort_wet --arg preparation= --arg reason= --arg claimant=terminated|abandoned --arg receipt=. An effect claim is refused while any pending preparation or live commitment fences its host, or another live claim holds it. Group partitions never carry placement events and the placement partition never carries authority events (both folds refuse).host_effect_admit_at/placement_prepare_atdecide against a supplied read, so interleavings are driven for real. Every group partition has one durable genesis: it startsAuthorityUnestablished, the source row is desired and becomes the group's authority only by anAuthorityEstablishedevent (pair_serving_authority_establish; production routepair_serving_authority_establish_wet --arg group=), preceded by its preparation on the placement partition; re-establishment, a leased state, a transition before establishment, or an authority naming another group than the partition's refuses. The standings read both group partitions plus the placement partition; a group the roster declares but the log has not established is unread. A release is evidence, not a return:HostEffectReleased{admitted_by, evidence: HostQuiescenceEvidence, provenance}— the evidence names the claim it was taken for and when (claim,observed_at), and the fold requiresevidence.claim == admitted_by,observed_at >= the claim's recorded_at, host and residue equal — so a reading taken before the admission, or the reading that released an earlier identical claim, releases nothing; it is sole-constructed in the newgunbc.spark.host_effect_quiescencebyobserve_host_effect_quiescenceover a supplied argv leg (pgrep-fover the claim's declaredprocess_pattern, anddocker ps --filter name=|ancestor=when the effect declares a container; exit 1 is quiet, a listing is residue, any other exit or a leg that did not run is unread), and the release fn and both folds refuse evidence that does not name the claim's host and its own residue spec.release_host_effect_livenow observes before releasing over the fleet-agent ssh leg (settle_host_effect_live): residue or an unread scan leaves the claim live and fails the exit with the cause;host_effect_recover_wetlocates the exact claim on the one placement partition. Provenance: the normal terminal releases asClaimantTerminal{claim, claimant_executor}— admitted only when it names this claim, its claimant is the executor that acquired the claim, and the event's actor is that executor (another executor observing a momentarily quiet host cannot label itself the claimant; its only route is recovery);host_effect_recover_wet --arg host= --arg claim= --arg claimant=terminated|abandoned --arg receipt=is the authorized route for a crashed lane — it takes the exact claim (never "whatever is live on the host") and a typed operator disposition of the claimant bound to that claim (RecoveryAuthorized{claim, claimant, authorized_by, receipt}; the fold refuses one naming another claim), then observes against that claim's residue and releases only when quiet. Each seam declares its residue (vllm_build_host_residue: the source dir on every leg's argv;v41_probe_host_residue: the image reference andancestor=that reference). Liveness is quiescence-required, not timed: the term marks a claim overdue and nothing more. Live effects are commitments in the standings (OccupiedByHostEffect). The retained population is nonempty by wall at decode, at the transition and in the fold. The hosts wire is a JSON array (injective over everyHostIdentity).LeaseGrantrides on the settling event only into the leased terminal; the fold and the transition refuse a grant whose reference/fence/generation are not the lease's; reads derive the observed lease state from the grant and instant; release law is derived (QuiescenceRequired).gunbc.spark.pair_serving_d0—Active → SuspensionPendingReconciliationby one CAS, readings inside it, incumbent first (observe_front_doorover the endpoint: any HTTP status is an answer — 4xx/5xx fences as unidentified; a deadline or an unreadable transport isRouteUnreadand fences; a failed connect (curl 7, which does not prove ECONNREFUSED) isNoStatus, and absence is established on the head host: the head's socket tables (/proc/net/tcp{,6}, now modeled inextdeps.linux.proc_net_tcpand read throughgunbc.host_operation_exec) must show no LISTEN on the enrolled port, the engine-process scan must match nothing, and the declared unit must be readable and not active — otherwise the group fences —HarnessBoundedPresencecarriesConnectFailed{curl_exit} | Deadline | TransportUnreadand never a stronger claim than curl makes), then per-rank reconciliation. A live declared incumbent restores the exact previous Active state unchanged (no key mint while the image axis is uncompared). The entry-state receipt is appended to the authority partition as its own event (addressed by the store's object ref) before settlement and named by the settling event.harness_acquire_onpre-checks the live authority andharness_fence_grantre-reads it after the seat CAS, releasing the seat if the authority moved. This is a post-grant compensation, not one shared linearization point with the authority; held-seat invalidation stays with Cut 3.pair_serving_d0_wetdispatches throughd0_recovery— structurally non-admitting today (resolve_d0_authorizationrefuses with a TRIGGER/SUFFICIENT-FOR naming Cut 0 + the escalation→authorization producer). Not run against the fleet.Test plan
pair_serving_d0_witness(hermetic): reconciliation table incl. drifted-eligible; live declared incumbent restores unchanged; live drifted / unread route / answered-unidentified / unavailable declaration fence; population identity join (reorder agrees; drop / duplicate / swap differ); canonical intent text; the recovery join over every crash point and its refusals; a reused transaction word does not inherit another lifecycle's history (and an undigestable binding identifies none); a failed connect is absence only when the head is quiet (a LISTEN on the port / an engine process / an unread table → fence; active unit → fence; unread unit → fence); another executor is refused against this lifecycle's pending state but completes its settled one; the states D0 writes commit the authorized hosts, not the roster; written suspension admits launch, refuses apply.pair_serving_d0_real_execution_witness(wet lane): the two-write route with the receipt on the log and the seat gate flipping; crash-resume from a keyed Active restoring it exactly; seat granted after the suspension landed is released; fence and restore terminals; same grant claimed from two executors (two bindings to the one placed store) is held once, and spent once; crash after the claim, before the first write → recovered (and a consent with nothing to do → aborted); crash after the settling write, beforeCompletedBy→ completed only, also after a later transaction moved the group on; a grant over another host population is refused before any claim or write; E1/T settles, operator restores, E2/T claims and dies → E2 recovers as FirstWrite and settles from its own history; drift after the claim: before a write the claim is AbortedBy and generation stays 0; after Pending the group reaches FencedRefusal naming both populations, the claim completes, andspark_claimed_members_understill holds the four authorized hosts and not the swapped-in one; a second executor cannot abort a pending lifecycle it did not write — claim and authority untouched, and the first executor still settles; any executor completes a settled lifecycle (Suspended: exit 0; restored Active: not restarted), claimCompletedBy, generation unchanged; the production standings fold over the current authority commits a fenced lifecycle's frozen hosts (srv10 refused as a group member; the roster's fourth host not committed as one).pair_serving_d0_front_door_real_execution_witness(wet lane): a local CPython listener answering 500 / 401 / 200, read through the realhttp.Client.StatusWithin→HarnessResponded{status}→FrontDoorAnsweredUnread/FrontDoorAnswered; a vacated port →HarnessConnectFailed{7}→ silence; a listener that accepts and never answers →HarnessDeadline→RouteUnread→ fenced through the transaction, never read as absent; a 500 front door read inside the transaction's observer reachingFencedRefusalon the log; a vacated port through the transaction: an active head unit fences, a quiet head suspends drifted-eligible; and a listener on 127.0.0.1:P with the door asked at 127.0.0.2:P (curl 7) is read from the host's/proc/net/tcpand fences.transition_admissionrows for thecontent_hash_equalrehoming name Delete the transition-admission rows consumed by Cut D 2a/2b #11666 (the cleanup PR, stacked after this one) as their deletion follow-up.origin/main(not from this stack):harness_seat_witness.the_tolerant_pool_is_a_separate_pool_whose_ceiling_is_not_the_engines_sequence_limit(group B's ceiling after Derive group B's serving route from the fabric assignment, not the retired GLM canary #11617).PlacementPreparationRecord.prepared_by(the preparing event's actor) andabort_provenance_coversdecides thePreparedarm throughrelease_provenance_covers— a Prepared preparation is aborted by its preparer or a recovery, never a stranger (hermetic red); (2) a resume whose grant is not admitted refuses with the admission's own cause before the recovery join; (3)D0GrantRefusedrenders throughstd.scoped_authorization authorization_refusal_reason; (4) one read per partition:spark_host_standings_overreads the placement fold and each group partition once and joins over that snapshot (current_authority_over,placement_read_over,GroupSnapshot); a refused fold flows throughread_group_partitionas the fold it is (no dead arms; onefold_refusal_text); the three consumed-preparation joins are oneconsumed_join;same_groupat the D0 subject; the unusedexecutor/atdropped from the claim fns;d0_settle_admittedexhaustive over the repair outcome (an aborted preparation is the operator's, not a proceed); the authorization argument guarded like the transaction. The one roster dependence left —PairServingActive's population is the lane roster's — is stated on the fold's annotation with its trigger (freezing hosts on Active is the D1 converger's change to the authority model).fabric_db_advancewith W1's stale expected object after the A→B→A cycle (asserting O3 ≠ O1 andFabricHeadMovednaming A@3) — a control the value-only object would fail; the wet D0 doorpair_serving_d0_wetconsumes the standing ofgunbc.rung_drop fabric_db_append_principal_unrefusedand refuses while it stands (hermetic control on the gate), so Cut 0 and the authorization producer cannot make D0 executable before the store's write wall is restored; the drop row states the loss plainly (its trigger restores outsider exclusion only; per-operation D0 authorization at the store is not declared restored) pending the operator's ruling on the trust boundary.durable_cas_fabric_dbbinds every generation object to the generation it lands (value + digest + generation), so a value that cycles A→B→A lands three distinct objects and a writer that observed A@1 cannot advance against A@3 (ExpectHeadAtis object-based); the read verifies the object's generation against the head's and the commit verifies the store's generation is the one derived — wet controla_cycled_value_does_not_let_a_stale_writer_advance. (3)PlacementAppendClaimedcollapsed to{preparation, intent}(claimant and head are the intent's), the fold joining the intent to the preparation — hermetic reds for another group / population / operation. (1) The fabric-DB write-principal wall is main's declared dropgunbc.rung_drop fabric_db_append_principal_unrefused(fabric DB: replace git under the fabric event log #11723); its population is widened here to every D0 writer (authority partitions, host-placement, the consent slot) and D0 stays structurally non-admitting until that trigger lands — escalated to the operator (land with the widened drop vs. hold).fleet_converge_workflownon-exhaustive overApprovalKeyringConverge/MtCollins1Boot, main's approval loop D: converge materialization, loopback bind, mtcollins1_boot mode #11484) is closed here with the two arms the module's own annotation prescribes.TcpSocketRow.local_portisTcpLocalPort = TcpPortBound { port: Port } | TcpPortUnboundoverstd.types Port(a 0000 field is a real kernel value with noPortconstructor), the hex bound is the field's 4 digits, andtcp_rows_listening_ontakes aPort— the consumer no longer strips the refinement.AuthorityWriteIntentcarried on the claim and derived from the consuming event, compared field for field. Hermetic controls: claim by E2 naming E1 refuses / by E1 lands; consumed-then-cancelled refuses at the cancellation and generation stays 1; cancelled-then-consumed refuses (round 16); a cancellation at another head than the claim named is a joined gap, at that head is none; each intent field alone distinguishes two writes; a claim carrying previous state, lifecycle and entry state round-trips, and a mangled previous-state member refuses. Wet: unchanged shape over the typed intent (9 claims).function 'split' not found in scopeingunbc.harness.harness_backend.text_labeled_field, main's GLM Group B serving-load telemetry capture: incarnation-scoped, replayable, qualification deferred #11569 code): root-caused to a v1 resolver defect, not to that code — a braced import fromextdeps.http.client(a module declaring aservice) into a module that also importsv2.std.algebra { filter }makes the builtinssplit/lastunresolvable inside a match-arm block (minimal repro in the PR comment). The trigger was this PR'simport extdeps.http.client { curl_exit_connect_failed, curl_exit_deadline }. Those two rows are curl(1) EXIT CODES — the tool's facts, whose authorityextdeps.http.clientitself names asextdeps.tools.curl— so they now live there andharness_backendimports them from the tool authority; the resolver defect is reported, not worked around in the resolver.AuthorityAppendCancelled; (2)PlacementAppendClaimedand the consuming authority event are bound to oneauthority_write_intent, recomputed by the group fold and compared by every joined read; (3) placement consumption and finalization read only the accepted group fold'spreparations_consumed. Controls — hermetic: an authority event whose intent is not the one recomputed from its own parent, actor and payload refuses in the group fold (another actor; another parent head; another next authority over the same hosts and operation); a consumer of a cancelled or already-consumed preparation refuses (round 16). The rejected-raw-event case is closed by construction rather than by a further claim:preparation_consumptionandfinalization_gapshave no raw-chain producer left — a refused fold isPreparationConsumptionUnread/PlacementUnread, and a preparation absent frompreparations_consumedisNotConsumed. Wet: the inverse control — E1 append-claims P at H, a stranger's claimant-terminal abort refuses with nothing written, the group head is still H, and only the operator's recovery moves it (after which E1's append is stale).std.hex(hex_digit_value,hex_word_value(word, max_digits)) and consumed byextdeps.linux.proc_net_tcp,extdeps.network.macandgunbc.instruments.fabric_ci_evidence;repo_atlas_projection's total decoder over an already-validated digest is left as is (its subject is a validated string, not a bounded word).a_malformed_hosts_member_refuses_rather_than_normalizing(four full envelope decodes, 102940 steps against 72300) is split into two claims of two decodes each over one helper; coverage unchanged.DeclaredOccupantObserved(unreachable on the route) is deleted —reconcile_occupancyreads the head's declared unit first (ACTIVE →OccupancyNotQuiet, fenced as unidentified; unread → fence) and with the head inactive reconciles every rank, so the only reconciled answer isDeclaredOccupantDrifted;head_rank_corroborates_absenceis folded into it and the hermetic fixtures supply route-honest (inactive-head) readings. D0's first write goes throughpair_serving_authority_transition_atwith the exact head its read was taken at, so a state that left and came back at another generation is refused (head) rather than landing a pending state whose lease epoch is not the generation that landed.FabricGroupA—HostEffectClaimRefused/HostEffectReleaseRefusedcarry thepartitionthey were decided on; the host-effect term isSecondon the event, the record and the admit signature (second_countat the codec keeps the wire byte-identical).content_hash_equalis homed instd.content_hash(machine_intake and both spark copies consume it; stage0 mirror regenerated); oneoptional_hash_member; a refused unit declaration is carried as each rank's cause;D0ClaimNotAttemptedis its own printable arm.durable_cas_fabric_db_real_execution_witness(wet lane): create-if-absent, read-back through a second binding to the one store, precondition failures carrying the committed version, stale update refused.container_namevscontainer_imagedistinct on the wire — evidence and provenance;PlacementPreparedincl. an empty next population,PlacementFinalized,PlacementAborted, theplacement_preparationmember on both authority events; a mis-keyed member refuses; the lifecycle member; the hosts array:["a,b","c"]≠["a","b","c"], a malformed member refuses); the placement fold: a preparation under a live claim refuses (still when overdue), lands after the release and, finalized, is the live commitment; a claim under a pending preparation or a live commitment refuses; two claims on one host refuse; a release of a non-live claim refuses; two groups cannot fence one host, an aborted preparation frees it; a preparation whose previous population is not the group's live commitment refuses; a finalization or abort of a non-pending preparation refuses; a release preparation keeps the old hosts fenced until finalized; an authority event on the placement partition and a placement event on a group partition refuse; the observer mints quiet only from a scan that found nothing; evidence for another host/pattern/container/claim, or taken before the admission, refuses and the commitment after it still refuses; the claim's own evidence releases and the commitment lands; C1's evidence cannot release a later identical C2; a recovery naming another claim refuses, one naming its claim releases; a claimant-terminal release by another executor refuses, naming another claim refuses, the claimant's own and an operator's recovery release; the group fold: genesis unestablished, establishment → generation 0, re-establishment / transition-before-establishment / leased state / cross-group authority refuse; grant genealogy, lifecycle records, hosts wire. Wet (9): a released group's member admitted through the production admission lands a claim, the re-claim's commitment refuses athost-effectsuntil the release; an overdue (term-10) claim still refuses at 1005 and at 1012, evidence for another residue refuses atevidence, the claim's own evidence lands and the re-claim proceeds; a second claim refuses atheld; a committed host's claim refuses atcommitted; a fixture host of no fabric group claims on the placement partition (held / released / a second release refused / claimable again); a claim on a group-B host (no establishment) fences an Active(B) establishment athost-effects, a ReleasedToFleet(B) is established at generation 0, the committing transition refuses, the release lands, the transition succeeds at generation 1 and the placement partition carries B's live commitment (a claim on the host then refuses atcommitted); the release needs the host observed quiet by real execution (daemonized sleeper → still held / fenced; killed → released / re-claim proceeds); a stale placement read cannot place or commit: an effect that read quiet before a transition committed its host appends stale (host_effect_admit_at), a fresh read refusescommitted; an authority that read quiet before a claim landed prepares stale (placement_prepare_at) and its fresh transition refuseshost-effects; a stranded preparation fences untilplacement_abort, then the host is claimable; the saga never frees a host early, abort and append contend on one head, and a consumed preparation cannot be aborted: a release that dies after its preparation leaves the old hosts fenced (group B's preparation refused, a second A preparation refused — one saga at a time, an effect refused, the authority still Active), the operator's recovery abort lands and frees nothing wrongly; an abort that read the preparationPreparedappends stale after the writer's append claim landed, an abort by a stranger of a claimed preparation refuses, a recovery abort lands; a release that dies after its group append (driven throughplacement_claim_append+authority_transition_append) leaves them fenced, refuses the abort (the join finds the consuming event) and frees them only by the finalization from that join. Both orderings of abort vs claimed append: a recovery abort of a claimed preparation lands the cancellation at the claimed head and the writer's append at that head is then stale (authority unchanged); a claimed append that landed first makes the abort refuse (consumed). Hermetic reds: an authority event whose preparation copy names another group / another population / another operation refuses in the group fold; a second consumer of one preparation refuses; a finalization whose copy is not the record, or of a never-claimed preparation, refuses; a second pending preparation for a group refuses; a stranger's abort of a claimed preparation refuses; a double claim refuses.🤖 Generated with Claude Code