Skip to content

Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease - #11555

Merged
briansrls merged 14 commits into
mainfrom
plan/dsv41-cut-d-2b
Sep 21, 2026
Merged

briansrls merged 14 commits into
mainfrom
plan/dsv41-cut-d-2b

Conversation

@briansrls

@briansrls briansrls commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Carries Cut D PR 2a (#11550, closed per operator decision 2026-09-20 after main's #11723 replaced git under the fabric event log; this PR is re-realized on the fabric DB) and implements D0 of docs/plans/dsv41-cut-d-redesign.md.

Realization (after #11723): every partition this PR adds lives on the fabric DB through gunbc.fabric_db_client FabricDbBinding (gunbc.fabric_event_log_host event_log_store_for_host from the executor). gunbc.fabric_event_log gains the codec-parameterized event_log_read_partition_with / event_log_append_with (the pool-event forms delegate to them), so one store walk and one put-and-advance serve every partition kind. Partition names carry no separator (pair-serving-authority-<group>, host-placement), the one predicate the store's slot addressing asks. The git-era refs backfill entry and its witness are gone with the git realization.

  • Baseline contract — gunbc.spark.released_baseline: ReleasedBaselineSpec = QuiescentReservedBaseline | FleetReleasedBaseline, the type of SuspendedForAuthorizedSuccessor.cleanup.
  • Authorization subject — D0Subject carries the group and its exact host population, the keyed successor, the cleanup baseline and the lease term. d0_population joins the granted hosts to fabric_group_hosts(group) by identity in both directions; a difference refuses before the claim and again before the first authority write. The grant's intent is a SHA-256 over one canonical encoding (d0_intent_text: required scope, group, sorted hosts, successor, cleanup, term, transaction) taken through the sha256sum realization — unavailable is a typed refusal, never a structural fallback.
  • Fleet-global claim — new gunbc.durable_cas_fabric_db: a second realization of std.durable_compare_and_set bound to a fabric-DB head (slot = head cas-slot-<key>, each generation one link-free object carrying the value, its content digest and the generation it lands (so a cycled value is a different object at each generation and a stale expected-object advance is FabricHeadMoved), the slot's generation the head's own CAS generation and the object's carried generation verified against it on every read, ExpectSlotAbsent/ExpectSlotGeneration an advance against an absent head / against the observed object; a moved head is re-observed so the loser reports what is there; takes the file store's VerifiedCasAttempt so one digest admission serves both handlers). std.scoped_authorization's claim slot lives there for D0, so two executors racing for one grant produce exactly one ClaimedBy. parse_authorization_claim_state is the exact inverse of the serializer, for readers that must know who holds a slot.
  • Total recovery — every D0 transition carries a lifecycle identity (the authorization binding) and the fold retains AuthorityTransitionRecord{id, transaction, lifecycle, next}; d0_recovery is one pure join over the claim reading and this lifecycle's history — selected by binding, never by the transaction word, so a fresh escalation reusing a word is not completed from the old one's terminal: claim absent → start; ClaimedBy(T) + no transition by T + Active → perform the first write; + not Active → abort the claim; pending under T → resume; T's last transition settled → complete the claim with no authority write; T's pending moved by another writer → refused for an operator; held by another / spent / unreadable → refused. A binding-digest failure after the claim landed aborts the claim rather than stranding it. Population drift after the claim is split: before any write it aborts the claim; after the pending state landed the transaction still reaches a terminal under its original authorization (drift is carried into the readings and fences), so a source edit cannot strand the group. The lifecycle is not the executor: the binding carries no executor, so every executor reads the same history and any executor completes a settled lifecycle (Suspended or restored Active) — never aborting or restarting it; a pending lifecycle is owned by the lease's owner fingerprint, and another executor is refused there (no handoff is modeled). The authorized hosts are frozen on every state D0 writes (hosts on Pending/Suspended/Fenced); pair_serving_committed_hosts is what host_commitment consumes, and the effectful admission seams (admit_unplaced_host_live, the reachability probe) now read the current authority from the event log before deriving commitment — refusing when any group is unread. Host placement is one partition, and it is the linearization point. Every fact about placement — every effect claim (HostEffectAdmitted{host, purpose, executor, term: Second, residue}), every release, and every authority write's preparation / finalization / abort — is an event on the one host-placement partition, and every writer is a CAS against its head. An authority write is a saga across two logs that never frees a host early: prepare → claim → authority → finalize, one saga per group at a time. PlacementPrepared{operation, group, previous_hosts, next_hosts} lands first and fences the union of both populations (refused under a live effect, under another group's fence, when previous_hosts is not the group's live commitment, or while the group has another pending preparation; stale when the partition moved); the writer then lands PlacementAppendClaimed{preparation, intent} on the same head — the claim is its intent: the placement fold refuses a claim whose event actor is not intent.actor, and one whose intent is not the write its preparation is for (group, populations the intent's states leave and enter, operation — the same preparation_ref_refusal the group fold applies), and records AppendClaimed{claimant: intent.actor, expected_head: intent.expected_head, intent}; the intent names the group head the append will CAS against and the exact write it will make: the typed AuthorityWriteIntent{group, expected_head, actor, previous?, next, operation, lifecycle?, grant?, entry_state?}; the consuming group event carries no intent because its intent is the event (event_write_intent derives it from the envelope's parent and actor and the payload's fields), and every joined read compares the claim's carried intent to the consuming event's derived one field for field (write_intent_eq; no digest stands between them) — so another actor, an append retargeted at a later head, or a different next authority/grant/lifecycle over the same host population and operation cannot consume the claim — so an abort and an append contend on one head at every stage: while Prepared, on the placement head (an abort that read it Prepared is stale once the claim landed); once claimed, on the group head — a recovery abort first lands AuthorityAppendCancelled{preparation, provenance} on the group partition at the head the claim named — after its provenance was admitted against the record (an append-claimed preparation is cancelled only by its claimant, ClaimantTerminal naming it with the event's actor the claimant, or by a RecoveryAuthorized naming it; a stranger's abort attempt writes nothing and the group head stays where the claim named it), and the cancellation carries that provenance so replay verifies who wrote it; the group fold refuses a cancellation of a preparation an accepted authority event already consumed (and, as before, a consumer of a cancelled one), so consumed and cancelled exclude each other in both directions, and the joined read requires the cancellation to have been appended at the head the claim named (CancelledPreparation.at_head) (the claimed append's CAS can then never succeed), and only then aborts; a stale cancellation means the head moved, and a fresh join decides: consumed → finalize, never abort; moved otherwise → the abort is safe; the group event (AuthorityEstablished / AuthorityTransitioned) carries a typed copy of the preparation (PlacementPreparationRef{id, group, previous_hosts, next_hosts, operation}) and the group fold refuses a copy whose group is not the partition's, whose populations are not the states' the event leaves and enters, or whose operation is not the event's; PlacementFinalized{preparation: <the same copy>, authority_event} lands last, only for an append-claimed preparation and only when the copy is the record, and retains exactly the next population. The live join (preparation_consumption) reads the record on the placement chain (the group is the record's, never a caller's word) and takes consumption only from the group's accepted fold (AuthorityFold.preparations_consumed: exact ConsumedPreparation{preparation, authority_event, intent}) — never from raw chain presence, so an event the fold refuses (a cancelled or already-consumed preparation, a stale previous state, a bad grant) consumes nothing and a refused fold is Unread; the copy must be the record and the intent the claim's — Consumed / NotConsumed{group_head, cancelled} / Absent / Unread, never a fabricated identity. Every authoritative read is joined across both logs: current_pair_serving_authority looks up every preparation its chain consumed on the placement chain (present, append-claimed or finalized to that event, copy equal to the record, intent equal to the claim's — else unread; every cancellation it folded must be covered on the placement side by a claimant-terminal or recovery abort of that preparation), and placement_read looks up every finalized preparation on its group's accepted fold (consumed by exactly the named event with the record's copy and intent — else unread); the group fold refuses a second consumer of one preparation and a consumer of a cancelled one. A crash before the group append over-fences; after it, over-fences until finalization; a release never exposes its old hosts before the authority moved. PlacementAborted{preparation, reason, provenance} is admitted only when the join says unconsumed, and its provenance must be the claimant's own (an append-claimed preparation is aborted by its claimant, written by its claimant) or a recovery naming it — the same claimant-terminal vs recovery-authorized model as host effects. Each writer prepares its own preparation; a losing writer aborts only what it prepared. Because one preparation per group is pending at a time, finalizations land in authority order. D0 retains the placement standing: AuthorityTransitionRecord carries the preparation copy; a settling write whose finalization did not land is D0PlacementStillFencing (the consent is not complete, the claim stays held); a rerun repairs the group's pending preparation from the join before its own saga (placement_repair_pending) and D0RecoverComplete finalizes the settled write's preparation before it completes the claim. Every authority outcome carries its placement standing (PlacementFinalizedAt / PlacementAbortedAt / PlacementCleanupStillFencing{preparation, cause}) — a cleanup that did not land is never dropped from the result; operator routes host_placement_finalize_wet --arg preparation= (finalizes from the join) / host_placement_abort_wet --arg preparation= --arg reason= --arg claimant=terminated|abandoned --arg receipt=. An effect claim is refused while any pending preparation or live commitment fences its host, or another live claim holds it. Group partitions never carry placement events and the placement partition never carries authority events (both folds refuse). host_effect_admit_at / placement_prepare_at decide against a supplied read, so interleavings are driven for real. Every group partition has one durable genesis: it starts AuthorityUnestablished, the source row is desired and becomes the group's authority only by an AuthorityEstablished event (pair_serving_authority_establish; production route pair_serving_authority_establish_wet --arg group=), preceded by its preparation on the placement partition; re-establishment, a leased state, a transition before establishment, or an authority naming another group than the partition's refuses. The standings read both group partitions plus the placement partition; a group the roster declares but the log has not established is unread. A release is evidence, not a return: HostEffectReleased{admitted_by, evidence: HostQuiescenceEvidence, provenance} — the evidence names the claim it was taken for and when (claim, observed_at), and the fold requires evidence.claim == admitted_by, observed_at >= the claim's recorded_at, host and residue equal — so a reading taken before the admission, or the reading that released an earlier identical claim, releases nothing; it is sole-constructed in the new gunbc.spark.host_effect_quiescence by observe_host_effect_quiescence over a supplied argv leg (pgrep -f over the claim's declared process_pattern, and docker ps --filter name=|ancestor= when the effect declares a container; exit 1 is quiet, a listing is residue, any other exit or a leg that did not run is unread), and the release fn and both folds refuse evidence that does not name the claim's host and its own residue spec. release_host_effect_live now observes before releasing over the fleet-agent ssh leg (settle_host_effect_live): residue or an unread scan leaves the claim live and fails the exit with the cause; host_effect_recover_wet locates the exact claim on the one placement partition. Provenance: the normal terminal releases as ClaimantTerminal{claim, claimant_executor} — admitted only when it names this claim, its claimant is the executor that acquired the claim, and the event's actor is that executor (another executor observing a momentarily quiet host cannot label itself the claimant; its only route is recovery); host_effect_recover_wet --arg host= --arg claim= --arg claimant=terminated|abandoned --arg receipt= is the authorized route for a crashed lane — it takes the exact claim (never "whatever is live on the host") and a typed operator disposition of the claimant bound to that claim (RecoveryAuthorized{claim, claimant, authorized_by, receipt}; the fold refuses one naming another claim), then observes against that claim's residue and releases only when quiet. Each seam declares its residue (vllm_build_host_residue: the source dir on every leg's argv; v41_probe_host_residue: the image reference and ancestor= that reference). Liveness is quiescence-required, not timed: the term marks a claim overdue and nothing more. Live effects are commitments in the standings (OccupiedByHostEffect). The retained population is nonempty by wall at decode, at the transition and in the fold. The hosts wire is a JSON array (injective over every HostIdentity).
  • Lease join — the LeaseGrant rides on the settling event only into the leased terminal; the fold and the transition refuse a grant whose reference/fence/generation are not the lease's; reads derive the observed lease state from the grant and instant; release law is derived (QuiescenceRequired).
  • gunbc.spark.pair_serving_d0 — Active → SuspensionPendingReconciliation by one CAS, readings inside it, incumbent first (observe_front_door over the endpoint: any HTTP status is an answer — 4xx/5xx fences as unidentified; a deadline or an unreadable transport is RouteUnread and fences; a failed connect (curl 7, which does not prove ECONNREFUSED) is NoStatus, and absence is established on the head host: the head's socket tables (/proc/net/tcp{,6}, now modeled in extdeps.linux.proc_net_tcp and read through gunbc.host_operation_exec) must show no LISTEN on the enrolled port, the engine-process scan must match nothing, and the declared unit must be readable and not active — otherwise the group fences — HarnessBoundedPresence carries ConnectFailed{curl_exit} | Deadline | TransportUnread and never a stronger claim than curl makes), then per-rank reconciliation. A live declared incumbent restores the exact previous Active state unchanged (no key mint while the image axis is uncompared). The entry-state receipt is appended to the authority partition as its own event (addressed by the store's object ref) before settlement and named by the settling event.
  • Seat fence (compensating) — harness_acquire_on pre-checks the live authority and harness_fence_grant re-reads it after the seat CAS, releasing the seat if the authority moved. This is a post-grant compensation, not one shared linearization point with the authority; held-seat invalidation stays with Cut 3.
  • Entry: pair_serving_d0_wet dispatches through d0_recovery — structurally non-admitting today (resolve_d0_authorization refuses with a TRIGGER/SUFFICIENT-FOR naming Cut 0 + the escalation→authorization producer). Not run against the fleet.

Test plan

  • pair_serving_d0_witness (hermetic): reconciliation table incl. drifted-eligible; live declared incumbent restores unchanged; live drifted / unread route / answered-unidentified / unavailable declaration fence; population identity join (reorder agrees; drop / duplicate / swap differ); canonical intent text; the recovery join over every crash point and its refusals; a reused transaction word does not inherit another lifecycle's history (and an undigestable binding identifies none); a failed connect is absence only when the head is quiet (a LISTEN on the port / an engine process / an unread table → fence; active unit → fence; unread unit → fence); another executor is refused against this lifecycle's pending state but completes its settled one; the states D0 writes commit the authorized hosts, not the roster; written suspension admits launch, refuses apply.
  • pair_serving_d0_real_execution_witness (wet lane): the two-write route with the receipt on the log and the seat gate flipping; crash-resume from a keyed Active restoring it exactly; seat granted after the suspension landed is released; fence and restore terminals; same grant claimed from two executors (two bindings to the one placed store) is held once, and spent once; crash after the claim, before the first write → recovered (and a consent with nothing to do → aborted); crash after the settling write, before CompletedBy → completed only, also after a later transaction moved the group on; a grant over another host population is refused before any claim or write; E1/T settles, operator restores, E2/T claims and dies → E2 recovers as FirstWrite and settles from its own history; drift after the claim: before a write the claim is AbortedBy and generation stays 0; after Pending the group reaches FencedRefusal naming both populations, the claim completes, and spark_claimed_members_under still holds the four authorized hosts and not the swapped-in one; a second executor cannot abort a pending lifecycle it did not write — claim and authority untouched, and the first executor still settles; any executor completes a settled lifecycle (Suspended: exit 0; restored Active: not restarted), claim CompletedBy, generation unchanged; the production standings fold over the current authority commits a fenced lifecycle's frozen hosts (srv10 refused as a group member; the roster's fourth host not committed as one).
  • pair_serving_d0_front_door_real_execution_witness (wet lane): a local CPython listener answering 500 / 401 / 200, read through the real http.Client.StatusWithin → HarnessResponded{status} → FrontDoorAnsweredUnread / FrontDoorAnswered; a vacated port → HarnessConnectFailed{7} → silence; a listener that accepts and never answers → HarnessDeadline → RouteUnread → fenced through the transaction, never read as absent; a 500 front door read inside the transaction's observer reaching FencedRefusal on the log; a vacated port through the transaction: an active head unit fences, a quiet head suspends drifted-eligible; and a listener on 127.0.0.1:P with the door asked at 127.0.0.2:P (curl 7) is read from the host's /proc/net/tcp and fences.
  • The 18 transition_admission rows for the content_hash_equal rehoming name Delete the transition-admission rows consumed by Cut D 2a/2b #11666 (the cleanup PR, stacked after this one) as their deletion follow-up.
  • Pre-existing red on clean origin/main (not from this stack): harness_seat_witness.the_tolerant_pool_is_a_separate_pool_whose_ceiling_is_not_the_engines_sequence_limit (group B's ceiling after Derive group B's serving route from the fabric assignment, not the retired GLM canary #11617).
  • Every wet fixture establishes group A's source row on its temp partition at 990 (the same route production takes) before any scenario event.
  • Review 68915: (1) PlacementPreparationRecord.prepared_by (the preparing event's actor) and abort_provenance_covers decides the Prepared arm through release_provenance_covers — a Prepared preparation is aborted by its preparer or a recovery, never a stranger (hermetic red); (2) a resume whose grant is not admitted refuses with the admission's own cause before the recovery join; (3) D0GrantRefused renders through std.scoped_authorization authorization_refusal_reason; (4) one read per partition: spark_host_standings_over reads the placement fold and each group partition once and joins over that snapshot (current_authority_over, placement_read_over, GroupSnapshot); a refused fold flows through read_group_partition as the fold it is (no dead arms; one fold_refusal_text); the three consumed-preparation joins are one consumed_join; same_group at the D0 subject; the unused executor/at dropped from the claim fns; d0_settle_admitted exhaustive over the repair outcome (an aborted preparation is the operator's, not a proceed); the authorization argument guarded like the transaction. The one roster dependence left — PairServingActive's population is the lane roster's — is stated on the fold's annotation with its trigger (freezing hosts on Active is the D1 converger's change to the authority model).
  • Round 20 (side-chat hold at 408f9ef): the ABA control now drives fabric_db_advance with W1's stale expected object after the A→B→A cycle (asserting O3 ≠ O1 and FabricHeadMoved naming A@3) — a control the value-only object would fail; the wet D0 door pair_serving_d0_wet consumes the standing of gunbc.rung_drop fabric_db_append_principal_unrefused and refuses while it stands (hermetic control on the gate), so Cut 0 and the authorization producer cannot make D0 executable before the store's write wall is restored; the drop row states the loss plainly (its trigger restores outsider exclusion only; per-operation D0 authorization at the store is not declared restored) pending the operator's ruling on the trust boundary.
  • Round 19 (side-chat hold at b376fa1): (2) durable_cas_fabric_db binds every generation object to the generation it lands (value + digest + generation), so a value that cycles A→B→A lands three distinct objects and a writer that observed A@1 cannot advance against A@3 (ExpectHeadAt is object-based); the read verifies the object's generation against the head's and the commit verifies the store's generation is the one derived — wet control a_cycled_value_does_not_let_a_stale_writer_advance. (3) PlacementAppendClaimed collapsed to {preparation, intent} (claimant and head are the intent's), the fold joining the intent to the preparation — hermetic reds for another group / population / operation. (1) The fabric-DB write-principal wall is main's declared drop gunbc.rung_drop fabric_db_append_principal_unrefused (fabric DB: replace git under the fabric event log #11723); its population is widened here to every D0 writer (authority partitions, host-placement, the consent slot) and D0 stays structurally non-admitting until that trigger lands — escalated to the operator (land with the widened drop vs. hold).
  • The heal red at b376fa1 (fleet_converge_workflow non-exhaustive over ApprovalKeyringConverge/MtCollins1Boot, main's approval loop D: converge materialization, loopback bind, mtcollins1_boot mode #11484) is closed here with the two arms the module's own annotation prescribes.
  • Review 68755: TcpSocketRow.local_port is TcpLocalPort = TcpPortBound { port: Port } | TcpPortUnbound over std.types Port (a 0000 field is a real kernel value with no Port constructor), the hex bound is the field's 4 digits, and tcp_rows_listening_on takes a Port — the consumer no longer strips the refinement.
  • Round 18 (side-chat hold at f0b3b7d): (1) an append claim is written by its claimant (placement fold red); (2) cancellation and consumption are mutually exclusive in the group fold (a cancellation of a consumed preparation refuses at the cancellation; the authority stays readable); (3) the cancellation is bound to the claim's expected head on the joined read; (4) the FNV structural digest is replaced by the typed AuthorityWriteIntent carried on the claim and derived from the consuming event, compared field for field. Hermetic controls: claim by E2 naming E1 refuses / by E1 lands; consumed-then-cancelled refuses at the cancellation and generation stays 1; cancelled-then-consumed refuses (round 16); a cancellation at another head than the claim named is a joined gap, at that head is none; each intent field alone distinguishes two writes; a claim carrying previous state, lifecycle and entry state round-trips, and a mangled previous-state member refuses. Wet: unchanged shape over the typed intent (9 claims).
  • CI heal red at f0b3b7d (function 'split' not found in scope in gunbc.harness.harness_backend.text_labeled_field, main's GLM Group B serving-load telemetry capture: incarnation-scoped, replayable, qualification deferred #11569 code): root-caused to a v1 resolver defect, not to that code — a braced import from extdeps.http.client (a module declaring a service) into a module that also imports v2.std.algebra { filter } makes the builtins split/last unresolvable inside a match-arm block (minimal repro in the PR comment). The trigger was this PR's import extdeps.http.client { curl_exit_connect_failed, curl_exit_deadline }. Those two rows are curl(1) EXIT CODES — the tool's facts, whose authority extdeps.http.client itself names as extdeps.tools.curl — so they now live there and harness_backend imports them from the tool authority; the resolver defect is reported, not worked around in the resolver.
  • Round 17 (side-chat hold at b18fed3): (1) abort provenance is admitted before any cancellation write and rides on AuthorityAppendCancelled; (2) PlacementAppendClaimed and the consuming authority event are bound to one authority_write_intent, recomputed by the group fold and compared by every joined read; (3) placement consumption and finalization read only the accepted group fold's preparations_consumed. Controls — hermetic: an authority event whose intent is not the one recomputed from its own parent, actor and payload refuses in the group fold (another actor; another parent head; another next authority over the same hosts and operation); a consumer of a cancelled or already-consumed preparation refuses (round 16). The rejected-raw-event case is closed by construction rather than by a further claim: preparation_consumption and finalization_gaps have no raw-chain producer left — a refused fold is PreparationConsumptionUnread / PlacementUnread, and a preparation absent from preparations_consumed is NotConsumed. Wet: the inverse control — E1 append-claims P at H, a stranger's claimant-terminal abort refuses with nothing written, the group head is still H, and only the operator's recovery moves it (after which E1's append is stale).
  • Review 68630: the hex digit/word decoder is hoisted to std.hex (hex_digit_value, hex_word_value(word, max_digits)) and consumed by extdeps.linux.proc_net_tcp, extdeps.network.mac and gunbc.instruments.fabric_ci_evidence; repo_atlas_projection's total decoder over an already-validated digest is left as is (its subject is a validated string, not a bounded word).
  • Floor budget: a_malformed_hosts_member_refuses_rather_than_normalizing (four full envelope decodes, 102940 steps against 72300) is split into two claims of two decodes each over one helper; coverage unchanged.
  • Review 68501: DeclaredOccupantObserved (unreachable on the route) is deleted — reconcile_occupancy reads the head's declared unit first (ACTIVE → OccupancyNotQuiet, fenced as unidentified; unread → fence) and with the head inactive reconciles every rank, so the only reconciled answer is DeclaredOccupantDrifted; head_rank_corroborates_absence is folded into it and the hermetic fixtures supply route-honest (inactive-head) readings. D0's first write goes through pair_serving_authority_transition_at with the exact head its read was taken at, so a state that left and came back at another generation is refused (head) rather than landing a pending state whose lease epoch is not the generation that landed.
  • Review 68107: the ungrouped-host refusals no longer mint FabricGroupA — HostEffectClaimRefused/HostEffectReleaseRefused carry the partition they were decided on; the host-effect term is Second on the event, the record and the admit signature (second_count at the codec keeps the wire byte-identical).
  • Review 67905: content_hash_equal is homed in std.content_hash (machine_intake and both spark copies consume it; stage0 mirror regenerated); one optional_hash_member; a refused unit declaration is carried as each rank's cause; D0ClaimNotAttempted is its own printable arm.
  • durable_cas_fabric_db_real_execution_witness (wet lane): create-if-absent, read-back through a second binding to the one store, precondition failures carrying the committed version, stale update refused.
  • Authority-log witnesses: codec per arm (incl. host-effect events with term, residue — container_name vs container_image distinct on the wire — evidence and provenance; PlacementPrepared incl. an empty next population, PlacementFinalized, PlacementAborted, the placement_preparation member on both authority events; a mis-keyed member refuses; the lifecycle member; the hosts array: ["a,b","c"] ≠ ["a","b","c"], a malformed member refuses); the placement fold: a preparation under a live claim refuses (still when overdue), lands after the release and, finalized, is the live commitment; a claim under a pending preparation or a live commitment refuses; two claims on one host refuse; a release of a non-live claim refuses; two groups cannot fence one host, an aborted preparation frees it; a preparation whose previous population is not the group's live commitment refuses; a finalization or abort of a non-pending preparation refuses; a release preparation keeps the old hosts fenced until finalized; an authority event on the placement partition and a placement event on a group partition refuse; the observer mints quiet only from a scan that found nothing; evidence for another host/pattern/container/claim, or taken before the admission, refuses and the commitment after it still refuses; the claim's own evidence releases and the commitment lands; C1's evidence cannot release a later identical C2; a recovery naming another claim refuses, one naming its claim releases; a claimant-terminal release by another executor refuses, naming another claim refuses, the claimant's own and an operator's recovery release; the group fold: genesis unestablished, establishment → generation 0, re-establishment / transition-before-establishment / leased state / cross-group authority refuse; grant genealogy, lifecycle records, hosts wire. Wet (9): a released group's member admitted through the production admission lands a claim, the re-claim's commitment refuses at host-effects until the release; an overdue (term-10) claim still refuses at 1005 and at 1012, evidence for another residue refuses at evidence, the claim's own evidence lands and the re-claim proceeds; a second claim refuses at held; a committed host's claim refuses at committed; a fixture host of no fabric group claims on the placement partition (held / released / a second release refused / claimable again); a claim on a group-B host (no establishment) fences an Active(B) establishment at host-effects, a ReleasedToFleet(B) is established at generation 0, the committing transition refuses, the release lands, the transition succeeds at generation 1 and the placement partition carries B's live commitment (a claim on the host then refuses at committed); the release needs the host observed quiet by real execution (daemonized sleeper → still held / fenced; killed → released / re-claim proceeds); a stale placement read cannot place or commit: an effect that read quiet before a transition committed its host appends stale (host_effect_admit_at), a fresh read refuses committed; an authority that read quiet before a claim landed prepares stale (placement_prepare_at) and its fresh transition refuses host-effects; a stranded preparation fences until placement_abort, then the host is claimable; the saga never frees a host early, abort and append contend on one head, and a consumed preparation cannot be aborted: a release that dies after its preparation leaves the old hosts fenced (group B's preparation refused, a second A preparation refused — one saga at a time, an effect refused, the authority still Active), the operator's recovery abort lands and frees nothing wrongly; an abort that read the preparation Prepared appends stale after the writer's append claim landed, an abort by a stranger of a claimed preparation refuses, a recovery abort lands; a release that dies after its group append (driven through placement_claim_append + authority_transition_append) leaves them fenced, refuses the abort (the join finds the consuming event) and frees them only by the finalization from that join. Both orderings of abort vs claimed append: a recovery abort of a claimed preparation lands the cancellation at the claimed head and the writer's append at that head is then stale (authority unchanged); a claimed append that landed first makes the abort refuse (consumed). Hermetic reds: an authority event whose preparation copy names another group / another population / another operation refuses in the group fold; a second consumer of one preparation refuses; a finalization whose copy is not the record, or of a never-claimed preparation, refuses; a second pending preparation for a group refuses; a stranger's abort of a claimed preparation refuses; a double claim refuses.

🤖 Generated with Claude Code

@gunbai-bot gunbai-bot Bot changed the title DS4.1 Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease Sep 18, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 18, 2026 02:28
gunbai-bot Bot pushed a commit that referenced this pull request Sep 18, 2026
… follow-up for the codec-move rows

The wave-admission wall: touching the roster brings every consumed row due --
the CONVERGENCE-ONE C2 rows (gunbc#11425) were satisfied at the base and are
deleted here -- and a used row must name the pull request that deletes it.
The two codec-move rows now name #11555 (Cut D 2b), which removes them.

The other floor blocker on the previous head, MemoryStallRefusedPageThrash on
srv4-01 (138161 major faults/minute, swap off), is the runner's, not the diff's.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 18, 2026
@briansrls
briansrls removed this pull request from the merge queue due to a manual request Sep 18, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Round 4 pushed as 280ac1d. Against review 67799:

  1. Claim-state parsing — parse_authorization_claim_state now lives in std.scoped_authorization as the serializer's exact inverse (round-trip + non-inhabiting-bytes witness), and D0 consumes it; the re-spelled tab match is gone.
  2. term_seconds: Nat — D0Subject.term is now std.measure Second; d0_lease_policy converts with second_count at the LeasePolicy boundary.
  3. The two transition_admission rows naming PullRequest 11555 — those rows are Cut D PR 2a: pair-serving authority on its own event-log partition, read by every effectful consumer #11550's (stacked base, currently queued): they admit the codec-move rebind Cut D PR 2a: pair-serving authority on its own event-log partition, read by every effectful consumer #11550 lands on main, and Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease #11555 is the PR that deletes them once that has merged, which is what the row says. Deleting them in this branch before Cut D PR 2a: pair-serving authority on its own event-log partition, read by every effectful consumer #11550 lands would turn this PR's own namespace-wave-admission red for the rebind it still carries in its diff against main. They are removed here the moment Cut D PR 2a: pair-serving authority on its own event-log partition, read by every effectful consumer #11550 is on main (merge main → delete both files), as with the 71 consumed rows already deleted on this stack.

Also in this push, from the side-chat hold: the claim is now fleet-global on the event log, recovery is one join over claim × authority history covering both crash windows, the subject carries the exact host population with a SHA-256 intent, and the front-door status distinction is executed against a local listener — which caught %{http_code} in StatusWithin's argv being read as a template variable (the transport had never run). PR body updated.

@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Round 6 pushed as 9267157. Against review 67905:

  1. content_hash_equal — one home now: std.content_hash.content_hash_equal (the refusing-direction Bool beside the comparison it folds). gunbc.machine_intake.subject's copy is deleted and its five consumers import from std; the two spark re-mints (content_hash_eq, hashes_agree) and three witness helpers are gone. Stage0 mirror regenerated.
  2. lifecycle_decode / entry_state_decode — one optional_hash_member(doc, key) returning OptionalHashMember.
  3. SparkPairServingUnitRefused — observe_ranks now takes the declared realization and reads every declared rank as UnitOccupancyUnread { IncarnationUnitPropertyUnread { property: "desired-unit", cause: <the refusal's cause> } }, so the receipt records what happened.
  4. D0ClaimTerminated for "not attempted" — new D0ClaimNotAttempted { still_held_by }, rendered as "the claim stays held by ; a rerun under it recovers…"; the eligible-settled arm renders whichever terminal it got.

Also in this push (side-chat hold): a foreign lifecycle against a pending state is refused without aborting the claim; the authorized hosts are frozen on Pending/Suspended/Fenced and host_commitment consumes them; curl exit 7 is no longer read as absence — absence is corroborated on the head rank's unit. PR body updated.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 8 pushed as 821b137. Against review 67966: the enrolled port is Port through the whole listener reading — EndpointListenerReading's three arms, read_endpoint_listener(port: Port), and HeadEndpointListening.port — with Int only at the /proc/net/tcp boundary (TcpSocketRow.local_port, converted once at the read).

Also in this push (side-chat hold): host-effect placement is a claim on the group's authority partition (a fence at the head, not a pre-check); legacy event chains have event_log_backfill_event_refs and the reader names it; the hosts wire is a JSON array. The previous head's CI blockers: the codec claim is split three ways under budget, the consumed mtcollins1 row is deleted, and the 18 content_hash_equal admission rows name #11666 (draft cleanup PR stacked after this one) as their deletion follow-up.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 9 pushed as 1a9b860 (main merged; the conflict with #11617's admit_unplaced_host_among is resolved by defining admit_unplaced_host_in over it). Against review 68062: the annotation in pair_serving_apply.dag now names spark_pair_apply_plans_current (the symbol that exists).

Also in this push (side-chat hold): host-effect liveness is quiescence-required (an overdue claim still fences until released with a receipt); one live effect per host, at the fold, at the claim and in the standings, with hosts of no claimed group claiming on their own partition; a production backfill entry (fabric_event_log_event_refs_backfill_wet) with a receipt ref per partition that the reader's refusal consults; and an empty retained population is refused at decode, at the transition and in the fold. The seat-ceiling red (the_tolerant_pool_is_a_separate_pool…) is pre-existing on clean origin/main after #11617, not from this stack.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 10 pushed (head c7f94c211b, main merged; stage0 std_content_hash.rs regenerated over the merged dag).

Side-chat hold (release evidence, claim home, annotation):

  • A host-effect release is now typed quiescence evidence, never a receipt: HostEffectReleased{admitted_by, evidence: HostQuiescenceEvidence}, sole-constructed in the new gunbc.spark.host_effect_quiescence by observe_host_effect_quiescence over a supplied argv leg (pgrep -f on the claim's declared process_pattern; docker ps --filter name=|ancestor= --quiet when the effect declares a container; a listing is residue, exit 1 is quiet, any other exit or a leg that did not run is unread). The release fn and both folds refuse evidence that does not name the claim's host and its own residue spec. release_host_effect_live observes (fleet-agent ssh) before releasing and never reads the exit as evidence; host_effect_recover_wet --arg host= is the authorized crash-recovery route (reads the home, takes the live claim, observes against that claim's residue). Each seam declares its residue (vllm_build_host_residue, v41_probe_host_residue).
  • One stable home: host_effect_home is the host's fabric group (claimed or not) or its own partition when in no group; an unclaimed group's partition is read as host-effect events only and the authority fold reads the same chain once the group is claimed; the transition also reads each committed host's own partition; standings read every home.
  • The stale host_commitment annotation and the HarnessConnectFailed arm name are fixed.
  • Controls: hermetic — observer mints quiet only from a scan that found nothing (listing → residue; exit 2 / no leg / docker non-zero → unread), evidence for another host/pattern/container refuses at that event and the claim keeps fencing, the claim's own evidence releases; wet — evidence refused at evidence, group-B host claims on group B's partition and folds to OccupiedByHostEffect, and a real daemonized process carrying the pattern keeps the claim live (settle_host_effect_over over the real local leg → still held, re-claim fenced) until it is killed, then the release lands and the re-claim proceeds.

Review 68107: both findings fixed — HostEffectClaimRefused/HostEffectReleaseRefused carry the partition they were decided on (no FabricGroupA minted for a host-partition claim), and the host-effect term is Second on the event, the record and the admit signature (second_count at the codec keeps the wire byte-identical).

Local: authority-log hermetic (18) and wet (7), host_commitment (24), capacity standing (16), apply (4), v41 build (25), D0 hermetic (20), D0 wet (13), front door (6) all pass.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 11 pushed (head 57e244fcbe, main merged) — the side-chat's three remaining holds:

  1. Evidence bound to its claim and instant. HostQuiescenceEvidence now carries claim and observed_at; release_admission (release fn + both folds) requires evidence.claim == admitted_by, observed_at >= the claim's recorded_at, host and residue equal. Controls: evidence for another claim id, or taken before the admission, refuses at that event; the reading that released C1 cannot release a later identical C2 on the same host/residue.
  2. Recovery names the exact claim and the claimant's standing. HostEffectReleased carries a provenance: ClaimantTerminal (the claimant observes after its own body returned) or RecoveryAuthorized{claim, claimant: terminated|abandoned, authorized_by, receipt}; the fold refuses a recovery provenance naming another claim. host_effect_recover_wet takes host, claim, claimant, receipt — it never picks a live claim by host, and a quiet host without the typed disposition cannot release (the disposition is the operator's fact at the declared boundary, §4b).
  3. One durable genesis per group partition. Every group partition starts AuthorityUnestablished (commits nothing); the source row becomes the authority only by an AuthorityEstablished event (pair_serving_authority_establish, one CAS; production route pair_serving_authority_establish_wet --arg group=), fenced by the host-effect records already on the chain; a second establishment, a leased state, or a transition before establishment refuses. One fold reads every group partition; the source roster is consulted by nothing that reads the log. Standings: a group the roster declares but the log has not established is unread (hosts not free until the operator establishes); undeclared-and-unestablished contributes its claims. Control (wet): claim on a group-B host while unestablished → establishing Active(B) over the same chain refuses at host-effects → ReleasedToFleet(B) lands and reads at generation 0 with the claim → re-establish refuses → the committing transition refuses → the claim's own release lands → the transition succeeds at generation 1. Every wet fixture establishes group A's row at 990 first.

Local: authority-log hermetic 24/24 and wet 7/7; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ the pre-existing main red noted in the body).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 12 pushed (head c8b3063b59) — the side-chat's two remaining construction defects:

  1. A claimant-terminal release is the claimant's. ClaimantTerminal{claim, claimant_executor}; release_admission (fold and live seam) requires the provenance to name this claim, its claimant to be the executor that acquired the claim, and the event's actor to be that executor. Red: E2 writes a terminal release against E1's claim with correctly bound evidence → refused, claim stays live; naming another claim → refused; E1's own → releases; an operator's RecoveryAuthorized naming the claim → releases.
  2. An establishment names its partition's group. The fold refuses an AuthorityEstablished whose authority names another group than the partition it was read from. Red: Group B authority inside Group A's establishment event → refused at that event.
  3. The authority-log opening prose now describes desired-vs-established (the removed "empty partition means the resting row governs" paragraph is gone).

Local: authority-log hermetic 25/25, wet 7/7; D0 wet 13, front door 6, host_commitment 24.

Review 68255 (APPROVE, no findings) — noted, nothing to act on.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68286: fixed at 98392d47b7 — product.capacity.event_json now has one chain_envelope_read (schema, partition, parent-empty-is-none, recorded_at, actor, kind) that both chain_event_decode (adds the schema check and the payload decode) and chain_envelope_decode consume; the second spelling is deleted. capacity_pool (5), capacity_lease_chain (13), authority-log hermetic (25) and fabric_event_log_append wet (5) pass locally.

Side chat: SOURCE APPROVE at c8b3063b59 (this push is the codec dedup only).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

CI on 98392d47b7: floor clean (planned=executed=4211, 0 failures, verdict=FloorClean); the only red was namespace-wave-admission: 40 consumed admission rows owned by #11587 (already landed on main) with no deletion follow-up, due on the roster's next touch. Pushed b3558e68a2 deleting those 40 rows — no other change. Side chat: approval carried to 98392d47b7; this delta is roster-only.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

CI on b3558e6 (floor clean again): main moved under the PR — #11602 added gunbc.network_boot_delivery (+ its witness) consuming content_hash_equal from the deleted machine_intake_subject home, and #11660 left one consumed admission row. Pushed 9be3464f06: main merged, the two consumers repointed to std.content_hash, four admission rows (deletion follow-up #11666), the #11660 row deleted. network_boot_delivery_join_witness 46/46 locally.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Review 68373: valid, fixed at 3023e57712. pair_serving_authority_establish, host_effect_admit and pair_serving_authority_transition now read every partition a host's claim could live on other than the one being written (other_home_claims: the host's own partition and both group partitions; group partitions through the authority fold, host partitions through the host-effect fold) and refuse under a live claim (held / host-effects) or an unread partition. Wet control: a claim written on a group-B host's own partition (its former home) refuses a group-partition admission and an Active(B) establishment; both land after its release. Authority-log wet 8/8, D0 wet 13, front door 6 locally.

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Transition-admission migration for gunbc#11704. No action until the operator sequences #11704's landing.

gunbc#11704 moves namespace transition admissions out of the tree. Once it lands, any file under dag/gunbc/namespace/transition_admission/ refuses at this PR's own gate, and the admission has to be carried in a commit message on this branch instead. The block below was derived mechanically from this PR's 24 row file(s) at its current head. The only edits: deletion_follow_up, owner_pull_request and their now-unused imports are dropped, because those fields no longer exist. All 24 blocks load through the production fold (carried_admissions_from_messages) with no refusal.

To migrate (paste + delete), after #11704 is on main and merged into this branch:

git rm \
  dag/gunbc/namespace/transition_admission/gunbc_boot_artifact_delivery_staged_digest_standing_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_bind_observed_access_context_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_control_route_evidence_unnamed_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_access_probe_evidence_unnamed_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_disposition_derive_fleet_admission_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_disposition_environment_of_qualification_digest_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_adjudicate_single_callback_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_ledger_link_refusal_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_ledger_step_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_intake_producer_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_intake_subject_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_receipt_same_optional_content_hash_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_machine_intake_subject_compare_qualification_subject_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_join_available_bundle_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_join_verified_ticket_after_trust_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/gunbc_network_boot_delivery_secure_boot_trust_admission_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/product_capacity_pool_events_pool_event_kind_decode_member_nat_event_json.dag \
  dag/gunbc/namespace/transition_admission/product_capacity_pool_events_pool_event_kind_decode_member_nonempty_event_json.dag \
  dag/gunbc/namespace/transition_admission/test_claim_machine_intake_bmc_secure_witness_test_dev_test_standing_cannot_be_inherited_for_production_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_a_definite_refusal_carries_the_acquiring_record_it_was_read_from_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_a_duplicate_refusal_reads_its_record_from_the_wrapper_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_an_outcome_carries_the_acquiring_record_it_was_read_from_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/test_claim_machine_intake_disposition_witness_test_the_issued_digest_and_architecture_come_from_one_artifact_content_hash_equal.dag \
  dag/gunbc/namespace/transition_admission/test_claim_network_boot_delivery_join_witness_four_receipts_join_to_established_content_hash_equal.dag
git commit -F msg.txt   # msg.txt = the text below, verbatim

-F keeps the lines exactly as they are. The squash merge carries the message into the queue run, and nothing lands in the tree. If a row is wrong later, a later block with the same stem supersedes it.

msg.txt
Move transition admissions into the commit message (gunbc#11704)

```transition-admission
module gunbc.namespace.transition_admission.gunbc_boot_artifact_delivery_staged_digest_standing_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_boot_artifact_delivery_staged_digest_standing_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.boot_artifact_delivery", "staged_digest_standing"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_access_bind_observed_access_context_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_access_bind_observed_access_context_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_access", "bind_observed_access_context"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_access_control_route_evidence_unnamed_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_access_control_route_evidence_unnamed_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_access", "control_route_evidence_unnamed"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_access_probe_evidence_unnamed_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_access_probe_evidence_unnamed_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_access", "probe_evidence_unnamed"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_disposition_derive_fleet_admission_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_disposition_derive_fleet_admission_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_disposition", "derive_fleet_admission"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_disposition_environment_of_qualification_digest_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_disposition_environment_of_qualification_digest_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_disposition", "environment_of_qualification_digest"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_adjudicate_single_callback_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_adjudicate_single_callback_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "adjudicate_single_callback"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_ledger_link_refusal_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_ledger_link_refusal_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "ledger_link_refusal"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_ledger_step_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_ledger_step_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "ledger_step"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_same_intake_producer_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_same_intake_producer_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "same_intake_producer"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_same_intake_subject_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_same_intake_subject_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "same_intake_subject"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_receipt_same_optional_content_hash_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_receipt_same_optional_content_hash_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_receipt", "same_optional_content_hash"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_machine_intake_subject_compare_qualification_subject_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_machine_intake_subject_compare_qualification_subject_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.machine_intake_subject", "compare_qualification_subject"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_network_boot_delivery_join_available_bundle_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_network_boot_delivery_join_available_bundle_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.network_boot_delivery", "join_available_bundle"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_network_boot_delivery_join_verified_ticket_after_trust_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_network_boot_delivery_join_verified_ticket_after_trust_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.network_boot_delivery", "join_verified_ticket_after_trust"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_network_boot_delivery_secure_boot_trust_admission_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_network_boot_delivery_secure_boot_trust_admission_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.network_boot_delivery", "secure_boot_trust_admission"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.product_capacity_pool_events_pool_event_kind_decode_member_nat_event_json

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data product_capacity_pool_events_pool_event_kind_decode_member_nat_event_json: TransitionAdmission = TransitionAdmission {
  label: "Cut D 2a: the chain-envelope JSON codec moves to product.capacity.event_json; pool_events consumes member_nat from there" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("product.capacity.pool_events", "pool_event_kind_decode"),
    spelling: "member_nat" as NonEmptyStr,
    expected_candidates: [decl_ref("product.capacity.event_json", "member_nat")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.product_capacity_pool_events_pool_event_kind_decode_member_nonempty_event_json

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data product_capacity_pool_events_pool_event_kind_decode_member_nonempty_event_json: TransitionAdmission = TransitionAdmission {
  label: "Cut D 2a: the chain-envelope JSON codec moves to product.capacity.event_json; pool_events consumes member_nonempty from there" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("product.capacity.pool_events", "pool_event_kind_decode"),
    spelling: "member_nonempty" as NonEmptyStr,
    expected_candidates: [decl_ref("product.capacity.event_json", "member_nonempty")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_machine_intake_bmc_secure_witness_test_dev_test_standing_cannot_be_inherited_for_production_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_machine_intake_bmc_secure_witness_test_dev_test_standing_cannot_be_inherited_for_production_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.machine_intake_bmc_secure_witness_test", "dev_test_standing_cannot_be_inherited_for_production"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_machine_intake_disposition_witness_test_a_definite_refusal_carries_the_acquiring_record_it_was_read_from_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_machine_intake_disposition_witness_test_a_definite_refusal_carries_the_acquiring_record_it_was_read_from_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.machine_intake_disposition_witness_test", "a_definite_refusal_carries_the_acquiring_record_it_was_read_from"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_machine_intake_disposition_witness_test_a_duplicate_refusal_reads_its_record_from_the_wrapper_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_machine_intake_disposition_witness_test_a_duplicate_refusal_reads_its_record_from_the_wrapper_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.machine_intake_disposition_witness_test", "a_duplicate_refusal_reads_its_record_from_the_wrapper"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_machine_intake_disposition_witness_test_an_outcome_carries_the_acquiring_record_it_was_read_from_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_machine_intake_disposition_witness_test_an_outcome_carries_the_acquiring_record_it_was_read_from_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.machine_intake_disposition_witness_test", "an_outcome_carries_the_acquiring_record_it_was_read_from"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_machine_intake_disposition_witness_test_the_issued_digest_and_architecture_come_from_one_artifact_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_machine_intake_disposition_witness_test_the_issued_digest_and_architecture_come_from_one_artifact_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.machine_intake_disposition_witness_test", "the_issued_digest_and_architecture_come_from_one_artifact"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_network_boot_delivery_join_witness_four_receipts_join_to_established_content_hash_equal

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_network_boot_delivery_join_witness_four_receipts_join_to_established_content_hash_equal: TransitionAdmission = TransitionAdmission {
  label: "content_hash_equal is homed in std.content_hash beside the comparison it folds (review 67905); gunbc.machine_intake_subject's mint is deleted and its consumers rebind" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.network_boot_delivery_join_witness", "four_receipts_join_to_established"),
    spelling: "content_hash_equal" as NonEmptyStr,
    expected_candidates: [decl_ref("std.content_hash", "content_hash_equal")],
  },
  disposition: TargetChanged,
}
```

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 13 pushed (head 843fa587e3, main merged) — the side-chat hold on 3023e57712:

  1. One stable linearization fact. Host placement is now one partition, host-placement, carrying every effect claim/release and every authority's HostsCommitted{group, hosts, intent} (with HostsCommitmentVoided as the compensating event). A transition or establishment that commits hosts first lands its commitment there by CAS (refused under a live claim or another group's commitment; stale when the partition moved), then appends on the group partition; a group append that does not land voids the commitment (a failed void is reported and the hosts stay fenced until host_placement_void_wet). A claim is refused under a live commitment or claim. The placement fold refuses authority events; the group fold refuses placement events and no longer carries host effects. The home machinery (per-host partitions, host_effect_home, other_home_claims) is deleted — a source edit moving a host between groups moves nothing.
  2. Recovery locates the exact claim on that one partition (live_claim_on); there is no home to derive.
  3. Controls (wet, real execution): an effect that read the partition quiet, then a transition committed its host, appends stale via host_effect_admit_at; an authority that read quiet, then a claim landed, commits stale via hosts_commit_at and its fresh transition refuses at host-effects; a stranded commitment fences the host until voided; plus the group-B sequence (claim → Active(B) establishment refused → ReleasedToFleet(B) established → committing transition fenced → release → transition lands with B's live commitment → a claim then refuses committed). Hermetic: the placement fold's refusals (commitment under live/overdue claim; claim under commitment; two groups on one host; void semantics; cross-partition events).

Local: authority-log hermetic 26/26, wet 8/8; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ the pre-existing main red).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 14 pushed (head 66d2e4c7d4) — the side-chat hold on 843fa587e3 (the two-log saga):

  1. Prepare → authority → finalize, never freeing early. PlacementPrepared{operation, group, previous_hosts, next_hosts} lands first and fences the union of both populations (refused under a live effect, another group's fence, or when previous_hosts is not the group's live commitment); the group event carries placement_preparation; PlacementFinalized{preparation, authority_event} retains exactly the next population. A release/replacement crash before the group append over-fences; after it, over-fences until finalization.
  2. No adoption, exact join. Each writer prepares its own preparation; both authority events name theirs; the group fold records the consumed preparations. AlreadyCommitted is gone.
  3. Abort only when unconsumed; cleanup carried. placement_abort reads the group's chain (preparation_consumption) and refuses when an authority event names the preparation; the fold refuses a finalization/abort of a non-pending preparation. Every AuthorityTransition / AuthorityEstablishment outcome carries a PlacementCleanup (FinalizedAt / AbortedAt / StillFencing{preparation, cause}) — the stale-and-readable arm no longer discards a failed cleanup. host_placement_finalize_wet / host_placement_abort_wet replace the raw void.
  4. Controls (wet): a release that dies after its preparation → group B's preparation over the host refused, an effect refused, the authority still Active, the abort lands and the host stays committed; a release that dies after its group append (driven via authority_transition_append) → authority reads Released, host still fenced, abort refused (consumed), finalization frees it; a stale placement read cannot place (host_effect_admit_at) or prepare (placement_prepare_at); a stranded preparation fences until aborted. Hermetic: union fencing, previous-population check, non-pending finalize/abort refusals, a release preparation keeps old hosts fenced until finalized.

Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, host_commitment 24, capacity standing 16, apply 4, v41 build 25, D0 hermetic 20, harness_seat 6 (+ pre-existing main red).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 15 pushed (head 631f3baaca, main merged).

Side-chat hold on 66d2e4c7d4:

  1. Abort ↔ append serialization. The saga is now prepare → claim → authority → finalize: PlacementAppendClaimed{preparation, claimant} lands on the placement head before the group append, so an abort that read the preparation Prepared appends stale once the claim landed; a claimed preparation is aborted only by its claimant (claimant-terminal, written by the claimant) or by a recovery naming it. The abort derives the group from the preparation record — there is no group argument to supply wrongly.
  2. Exact preparation ↔ authority join. Both authority events carry a typed copy PlacementPreparationRef{id, group, previous_hosts, next_hosts, operation}; the group fold refuses a copy whose group is not the partition's, whose populations are not the states' the event leaves/enters, or whose operation is not the event's. PlacementFinalized carries the same copy and the placement fold finalizes only an append-claimed preparation whose copy is the record. preparation_consumption walks the record's group chain for the carrying event and verifies the copies; consuming_event_of and its fallback are gone (Consumed / NotConsumed / Absent / Unread).
  3. Authority order = finalization order: one pending preparation per group (a second refuses "one saga at a time").
  4. Controls (wet): one-saga-at-a-time; abort-vs-claim interleaving → stale; stranger's abort of a claimed preparation refused; recovery abort lands; crash-after-append → abort refused (consumed), finalize from the join frees. Hermetic reds: foreign-group / mismatched-population / other-operation copy in the group fold; forged finalization; unclaimed finalization; second pending preparation; stranger abort; double claim.

Review 68501 (both findings valid, fixed): DeclaredOccupantObserved was unreachable on the route — deleted; reconcile_occupancy reads the head's declared unit first (ACTIVE → OccupancyNotQuiet, fenced as unidentified), then every rank, so the reconciled answer is always DeclaredOccupantDrifted; head_rank_corroborates_absence is folded in and the fixtures supply route-honest inactive-head readings. D0's first write now goes through pair_serving_authority_transition_at with the exact head its read was taken at, refusing (head) a state that left and came back at another generation, so the pending lease epoch is always the generation that lands.

Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, D0 hermetic 20, host_commitment 24, capacity standing 16, apply 4, v41 build 25, harness_seat 6 (+ pre-existing main red).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 16 pushed (head b18fed3405) — the side-chat hold on 631f3baaca:

  1. AppendClaimed ↔ authority append/abort serialization. PlacementAppendClaimed now names the group head the append will CAS against. A recovery abort of a claimed preparation first lands AuthorityAppendCancelled{preparation} on the group partition at that head (so the claimed append's CAS can never land), then aborts; a stale cancellation means the head moved, and a fresh join decides (consumed → finalize, never abort; moved otherwise → the abort is safe). The group fold refuses a consumer of a cancelled preparation. Wet: both orderings — cancellation lands, writer's append at the claimed head is stale, authority unchanged; append landed first, abort refuses (consumed).
  2. Cross-log authoritative join. current_pair_serving_authority looks up every preparation its chain consumed on the placement chain (present, append-claimed or finalized to that event, copy equal to the record — else unread); placement_read looks up every finalized preparation's authority event on its group chain (present, carrying the record's copy — else unread); the group fold refuses a second consumer of one preparation. Hermetic red for duplicate consumption; the joined reads run in every wet claim.
  3. D0 retains placement cleanup. AuthorityTransitionRecord carries the preparation copy; a settling write whose finalization did not land is D0PlacementStillFencing (consent not complete, claim stays held); a rerun repairs the group's pending preparation from the join before its own saga (placement_repair_pending), and D0RecoverComplete finalizes the settled write's preparation before completing the claim.

Local: authority-log hermetic 26/26, wet 9/9; D0 wet 13, front door 6, D0 hermetic 20, host_commitment 24, capacity standing 16, apply 4, v41 build 25, harness_seat 6 (+ pre-existing main red).

@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Round 17 (side-chat hold at b18fed3), all three seams:

  1. Abort provenance before any write. placement_abort_attempt admits the provenance against the record's state (abort_provenance_covers) before cancel_claimed_append may touch the group partition; a stranger's attempt refuses with "nothing was written" and the group head stays where the claim named it. AuthorityAppendCancelled now carries the provenance ({preparation, provenance}), and current_pair_serving_authority requires each folded cancellation to be covered on the placement side by a claimant-terminal or recovery abort of that preparation.
  2. One exact write intent. authority_write_intent(group, head, actor, previous?, next, operation, lifecycle, grant, entry_state) — a content hash over one canonical encoding. PlacementAppendClaimed{…, intent} and the consuming AuthorityEstablished/AuthorityTransitioned{…, intent} carry it; the group fold recomputes it from the event's own parent/actor/payload and refuses a mismatch (another actor, a retargeted head, a different next authority/grant over the same hosts + operation); both joined reads compare the claim's intent to the consuming event's; ConsumedPreparation retains it.
  3. Consumption from the accepted fold only. preparation_consumption and finalization_gaps read AuthorityFold.preparations_consumed — a refused fold is unread, a preparation absent there is not consumed; no raw-chain producer remains.

Controls: hermetic intent-mismatch reds (actor / head / next authority); wet inverse control — E1 append-claims P at H, a stranger's claimant-terminal abort refuses and the head is still H, then only the operator's recovery cancels (E1's append is then stale).

Also in this push: review 68630 — std.hex (hex_digit_value, hex_word_value) hoisted and consumed by extdeps.linux.proc_net_tcp, extdeps.network.mac, gunbc.instruments.fabric_ci_evidence; repo_atlas_projection's decoder is left as is (a total decoder over an already-validated digest, not a bounded-word parser). And the CI red at b18fed3 (a_malformed_hosts_member_refuses_rather_than_normalizing at 102940 eval steps vs the 72300 new-witness budget — four full envelope decodes, longer since the intent member) is split into two claims of two decodes over one helper; coverage unchanged.

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Round 18 (side-chat hold at f0b3b7d):

  1. The claim is its claimant's. The placement fold refuses PlacementAppendClaimed whose event actor is not its claimant ("a claim is written by its claimant").
  2. Consumed and cancelled exclude each other both ways. The group fold refuses AuthorityAppendCancelled naming a preparation an accepted authority event already consumed (cancellation_refusal), at the cancellation — the authority stays readable and the preparation finalizes normally; a consumer of a cancelled preparation refused already. CancelledPreparation retains at_head (the cancellation's parent) and cancellation_gap requires it to equal the claim's expected_head.
  3. No digest. AuthorityWriteIntent{group, expected_head, actor, previous?, next, operation, lifecycle?, grant?, entry_state?} is the typed carrier on PlacementAppendClaimed (wire: intent_* members, previous under intent_prev_, next under intent_next_); authority events carry no intent — theirs is the event, event_write_intent(env, …) derives it from the envelope's parent/actor and the payload — and write_intent_eq compares field for field in consumed_preparation_gap, finalization_gaps and preparation_consumption. intent_refusal and the FNV content_hash_of_value use are gone.

Controls (hermetic, 4 new claims): claim by E2 naming E1 refuses / by E1 lands as AppendClaimed by E1; consumed P → later cancellation refuses at the cancellation, generation stays 1; cancelled P → later consumer refuses; a cancellation at e9 against a claim naming e0 is a joined gap, at e0 none, a stranger's provenance a gap; each intent field alone distinguishes writes; a claim carrying previous/lifecycle/entry-state round-trips and a mangled intent_prev_state member refuses. Wet unchanged in shape (9).

CI heal red at f0b3b7d (function 'split' not found in scope at gunbc.harness.harness_backend.text_labeled_field, code from main's #11569): a v1 resolver defect, reproduced locally with the same binary — harness_backend resolves on clean origin/main, and stops resolving the moment it carries import extdeps.http.client { curl_exit_connect_failed, curl_exit_deadline } (this PR's line); the same file importing a braced row from extdeps.tools.curl instead resolves. Minimal fixture that reproduces independently:

module probe.a
import std.types { String, List, Bool }
import v2.std.optional { Present, Absent }
import v2.std.algebra { filter }

fn f(body: String) -> String? {
  let lines = split(s: body, delimiter: "\n")
  match first(filter(lines, l => l != "")) {
    Absent => none
    Present { value: line } => {
      let parts = split(s: line, delimiter: ":")   // function 'split' not found in scope
      last(parts)                                  // function 'last' not found in scope
    }
  }
}

(drop the v2.std.algebra import and use first(lines) → resolves). The builtins go out of scope inside a match-arm block under particular import combinations; the diagnostic is in v1_compiler_infer at the global_bare_callable_node miss. Not fixed here (seed resolver, outside this lane). In this PR the two rows moved to their real authority — curl(1) EXIT CODES are the tool's facts, and extdeps.http.client already names extdeps.tools.curl as the tool authority — which also removes the trigger; the gate's heal_repair_declaration runs clean locally.

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Re-realized on the fabric DB (main's #11723 replaced git under the fabric event log; #11550 closed per operator decision, its diff carried here; base is now main):

  • gunbc.fabric_event_log: event_log_read_partition_with / event_log_append_with take the partition owner's codec (the pool-event forms delegate), so one store walk and one put-and-advance serve every partition kind — no second log per kind.
  • gunbc.spark.pair_serving_authority_log, pair_serving_d0, host_commitment, harness_seat (the after-grant authority gate re-applied on main's version): every read and append goes through FabricDbBinding from event_log_store_for_host; a store fault is carried as event_log_refusal_wire. Partition names carry no separator (pair-serving-authority-<group>, host-placement), the store's slot-addressing predicate.
  • gunbc.durable_cas_fabric_db replaces durable_cas_event_log: D0's claim slot is a fabric-DB head cas-slot-<key> — each generation a link-free object carrying value + content digest, the slot's generation the head's own CAS generation, ExpectSlotAbsent/ExpectSlotGeneration an advance against an absent head / the observed object, a moved head re-observed so the loser reports what is there; takes the file store's VerifiedCasAttempt (one digest admission for both handlers).
  • The entry-state receipt's id is the store's object ref (a content-hash wire), parsed with parse_content_hash; the git-era refs/fabric-events backfill entry and its witness are deleted with the realization they served.
  • Wet witnesses (authority log 9, D0 13, front door 6, CAS 1) run against a temp file-store root through FabricDbLocalFiles; "two executors" are two bindings to the one placed store, which is the shape the fabric DB has.

Review 68755 (fixed): TcpSocketRow.local_port is TcpLocalPort = TcpPortBound { port: Port } | TcpPortUnbound over std.types Port — 0000 is a real kernel value for an unbound socket and Port (1..65535) has no constructor for it, so the row says which it read rather than carrying 0 as a port; the hex bound is the field's four digits; tcp_rows_listening_on takes a Port, and serving_incarnation_observe passes the refinement through instead of casting it away.

Round 18 (typed AuthorityWriteIntent, claimant-written claims, consumed/cancelled exclusivity, cancellation bound to the claimed head) is in the same head; see the round-18 comment above for its controls.

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Round 19 (side-chat hold at b376fa1), at 408f9ef5f9:

  1. CAS ABA under a cycled value — fixed. gunbc.durable_cas_fabric_db binds every generation object to the generation it lands ({value, content, generation}), so A→B→A lands three distinct objects and a writer that observed A@1 cannot advance against A@3 — ExpectHeadAt is object-based and now the object is history-unique; the read refuses an object whose carried generation is not the head's, and the commit refuses a store generation other than the derived one. Wet control a_cycled_value_does_not_let_a_stale_writer_advance_by_real_execution (W1 observes A@1 → B@2 → A@3 → W1 expecting 1 gets CasPreconditionFailed naming 3).
  2. The claim is its intent — fixed. PlacementAppendClaimed{preparation, intent}; the placement fold requires the event actor to be intent.actor and the intent to be the write its preparation is for (preparation_ref_refusal over the intent's group, the populations its states leave and enter, and its operation), and records AppendClaimed{claimant: intent.actor, expected_head: intent.expected_head, intent}. Hermetic reds: claim by E2 for E1's write; intent for group B / another population / another operation over the [] → [srv5] tx-op preparation.
  3. Fabric-DB write principal. This is main's declared drop gunbc.rung_drop fabric_db_append_principal_unrefused (fabric DB: replace git under the fabric event log #11723, review 68598) whose restoration trigger — an observed roster of the principals fleet writers present through tailscale serve, sufficient for fabric_db_serve_handle — is the fabric-DB lane's, not modeled here. What this PR does: widens the drop's population to every D0 writer (the authority partitions, host-placement, the consent slot) with the note that D0's first fleet run inherits that trigger, and D0 stays structurally non-admitting (resolve_d0_authorization refuses; never run against the fleet). Whether Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease #11555 lands under the widened drop or holds for the wall is escalated to the operator.

Also: the stale SHA-1 / git-oid wording corrected; parse_authorization_claim_state restored onto main's std.scoped_authorization (lost in the merge); the heal red at b376fa1 (main's fleet_converge_workflow non-exhaustive over ApprovalKeyringConverge/MtCollins1Boot) closed with the two arms its annotation prescribes. Local: authority-log hermetic 31, wet 9; CAS wet 2; D0 hermetic 20, wet 13, front door 6; host_commitment 24; claim-state 2.

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Round 20 (side-chat hold at 408f9ef), at 1682ee695d:

  1. ABA control now discriminates the repair. a_cycled_value_does_not_let_a_stale_writer_advance_by_real_execution commits A@1, keeps the head's exact object O1, moves the slot B@2 → A@3 (O3), asserts O3 ≠ O1, and drives fabric_db_advance(expected: ExpectHeadAt{O1}) directly — FabricHeadMoved naming the A@3 head at generation 3. With value-only objects O3 == O1 and that advance would pass; the test no longer re-runs the whole compare-and-set after the cycle.
  2. The wet D0 door consumes the drop's standing. pair_serving_d0_wet reads gunbc.rung_drop fabric_db_append_principal_unrefused.standing first (d0_store_write_wall_standing) and refuses while it stands, naming the row and its trigger — so Cut 0 and the escalation → authorization producer cannot make D0 executable before the store's write wall is restored, by construction; retiring the row is the only thing that opens the gate (hermetic control covers both standings).
  3. The drop states the loss plainly: its trigger restores outsider exclusion only; the served door carries no partition/action/subject/grant to the store, so once the roster lands every rostered writer is trusted for every head, and per-operation D0 authorization at the store is a wall the row does not declare restored. The trust-boundary decision (hold for the wall / land under the widened drop with the door gated) is with the operator; the branch records the escalation, not a ruling.
  4. PR summary's CAS description corrected (object = value + digest + generation).

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Round 20b at 4566e066b3: the wet D0 door also refuses while the per-operation store wall is missing — gunbc.spark.pair_serving_d0 d0_store_operation_wall (StoreOperationWallMissing{trigger}; a missing construction, not a drop: it never existed under git either) — so retiring fabric_db_append_principal_unrefused alone does not open D0; the drop row cross-references it and the hermetic gate control covers both walls. Side chat: SOURCE APPROVE at 1682ee6, merge conditional on the operator's trust-boundary ruling, which is escalated at the reviewer's exact strength.

— sent from proud-deer-538

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 20, 2026
@gunbai-bot
gunbai-bot Bot force-pushed the plan/dsv41-cut-d-2b branch from eeef609 to dc0e8ac Compare September 20, 2026 14:23
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 20, 2026
6 tasks
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

CI floor red at d1053a6 / #11666's d97e615: main's #11743 left a source annotation inside the TargetProducer declaration body in gunbc.target_binding, which refuses to parse (required-ci: parse FAIL … source annotation sits inside a declaration body) and fails every floor run on every PR. Hoisted to module grain here (b1e20cd), the same repair #11831 made for the previous instance; main will want the same one-liner.

— sent from proud-deer-538

…e plan/dsv41-cut-d-2b delta re-applied over main@5f4202a5c6

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot force-pushed the plan/dsv41-cut-d-2b branch from b1e20cd to 011c076 Compare September 20, 2026 18:07
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 20, 2026
6 tasks
Brian Searls and others added 8 commits September 20, 2026 18:08
…r_memory_demand, r2_permission_group_observe, namespace_reference_derived_residency_qualification): a source annotation inside a declaration body refuses to parse and reds every floor run

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion wall was deleted by operator ruling 2026-09-19 (gunbc.rung_drop namespace_wave_admission_wall_removed) and a row file in the tree now refuses to resolve

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t_capture_historical_binding and runner_microvm_boot_probe to module grain (they refuse to parse and red every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…left in chunk_20 (expected expression, found Newline; reds every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

CI floor at 956baf4: the branch now parses (the split tail: lines in floor_route_gap chunk_20 and the body-scope annotations from #11731/#11743/#11765 are all repaired here), but the floor refuses at ChangedWitnessObservationFailed: the base revision — main — does not parse (src/v2/workflow/floor_route_gap.dag at main has 317 diagnostics from #11731's split tail: lines), so the arm-set-changed sublane cannot reconstruct the base side of the diff. That is not fixable from this PR; main needs the same one-line repair (join tail: with the following Cons { / Empty {}, 7 sites in chunk_20) before any PR's floor can be adjudicated. Everything else on this head is green (compiler, clippy; local: authority-log 32/9, D0 21/13, front door 6, CAS 2, host_commitment 24).

— sent from proud-deer-538

gunbai-bot Bot and others added 2 commits September 20, 2026 21:59
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused
Heal-Candidate-Run: 35538018867
…ot quiet (OccupancyNotQuiet names every live rank; never dropped into a drifted population); PlacementCleanupUnread replaces the minted "unknown" preparation id and D0 carries preparation: none; the repair binds the consumption it acts on once; one read budget on gunbc.fabric_event_log; the misnamed HostEffectClaimed.generation deleted

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Review 69399 — all five fixed at 62c9274289:

  1. Live worker absorbed as drifted — real. RankVerdict now has RankLive { host }, reconcile_occupancy answers OccupancyNotQuiet { live } naming every rank whose declared unit is installed, byte-identical and active (head or worker), and only with every rank read and none live is drift decided; d0_decide fences on it as an unidentified occupant naming the hosts. The hermetic witness that encoded the widen (head inactive + three workers active → "drifted, 1") is inverted to require OccupancyNotQuiet with the three workers; the one-rank-other-bytes claim states its population honestly (four drifted).
  2. "unknown" as EventId — PlacementCleanup gains PlacementCleanupUnread { cause } (no preparation could be named); D0PlacementStillFencing.preparation is EventId? and the door/recovery arms carry none with the cause rather than a minted id.
  3. Double read in placement_repair_pending — the consumption is bound once and the bound value is what placement_finalize acts on.
  4. Read budget re-mint — one gunbc.fabric_event_log event_log_read_budget, consumed by the authority/placement folds and by tools.fabric_partition_read (its local partition_read_budget deleted).
  5. HostEffectClaimed.generation — deleted (no consumer; its value was the local list length, not a generation).

Local: D0 hermetic 21/21, wet 13, front door 6; authority-log 32/9; host_commitment 24.

— sent from proud-deer-538

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant