Repository navigation
Derive the floor's microVM shape from typed floor-demand receipts; plan the cold-build receipt - #11672
Conversation
…an the cold-build receipt gunbc.floor_demand is the floor's demand authority: the per-run cgroup peak carrier moves here from ci_floor_measurement, the 2026-09-12 uncensored scope measurement and the 2026-09-19 throttle pin are typed receipts, and the slot wall's measured-peak rows derive from them instead of carrying a stale 2026-08-17 figure. The floor Work now states its memory demand (a lower bound, 26849763328 bytes) and the fleet cell's offer states memory_max, so offers that state no memory stop covering the floor. gunbc.runner_microvm derives the guest shape: the Work's threads admitted against the cell's absolute entitlement, MemoryMax less the reserve floor-divided to MiB and admitted only above the Work's minimum, the per-attempt workspace grant admitted only above the Work's storage minimum, and the cell's TasksMax carried into the guest as sysctl.kernel.pid_max on the kernel command line. Seven typed refusals; the declared 4 GiB row is a boot-smoke fixture, not a production arm; plan_attempt_launch takes the shape. The guest-size derivation stall retires. At today's rows production refuses: the floor's demonstrated demand exceeds the 26 GiB cell's remainder beside the 1 GiB reserve by 5.9 MiB. The refusal carries both figures and is the expecting-red probe that flips when the cell row or the demand moves. gunbc.floor_cold_build_receipt plans the arm64, CARGO_HOME-wiped, sccache-unreachable receipt: host-side instruments, warm baseline, verdict fold against the lane timeout, the cell and the workspace grant, and a stated wall prediction. Standing is Pending. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fa2c5cb to
0bb83f9
Compare
|
Local witness runs (arm64 binary built from this head, |
memory.peak charges page cache, so a peak read at the throttle line is a ceiling that includes cache rather than the floor's demand (operator ruling 2026-09-19). The non-reclaimable partition -- anon, unevictable, shmem, unreclaimable slab, kernel stacks, page tables, percpu, sock -- is what a machine must hold, and it is now read from memory.stat on every heartbeat beside the reclaimable file figures, so a floor run on the host slot produces the receipt the guest is to be sized from. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…waits on the non-reclaimable receipt Per operator ruling 2026-09-19: memory.peak charges reclaimable cache, so the receipts' maximum is renamed the charge ceiling and stops being the Work's minimum. The Work's memory requirement is the non-reclaimable partition peak plus a declared page-cache allowance, and is absent while that partition is unmeasured -- so the guest shape refuses on the absence, not on the ceiling. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ce to the guest; adjudicate the six moved bindings The floor heartbeat's first memory.stat receipt (run 35419304682, srv4-04): 26725773568 bytes non-reclaimable at the 25 GiB line with 13 MiB of cache left -- the cache had been reclaimed to nothing and anonymous memory was being swapped. The floor Work states that measured minimum and nothing more; the 2 GiB cache allowance is guest policy in gunbc.runner_microvm, evidenced by the receipt's two beats, and the shape refuses at today's cell row with all three figures. Six transition admissions cover the bindings the floor-demand move retargeted. fabric_floor_dispatch_witness_test's NoFeasibleAlternativeUse literal gains its required receipt field: a latent resolve defect the floor never reached on main. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68237 (advisory): the new seed reader carried no checkable receipt in the repository's form. This is the SeedGrowthJustification row -- purpose admission under v1_seed_standing, hand-item delta +1, dissolution lane and the trigger that migrates the line into the observation model's per-beat sample. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cache allowance from it Review 68259: the allowance's evidence lived only in an annotation. The receipt now carries both beats as FloorNonReclaimableBeat values, and the allowance is the last unstalled beat's file cache at gibibyte grain rather than a declared 2 GiB. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…producer returns Review 68284: a bare Int beside gunbc.memory_stall_refusal's EventsPerMinute was a second representation of one quantity (DESIGN 3). One carrier now, both sides. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68284: fixed in the pushed head — — sent from wise-tern-670 |
…ing-red probe Review 68307: deleting the guest-size derivation stall left the state 'the floor's measured demand does not fit the cell, so no production guest can be shaped' untracked, and the either-state witness could not record which state production is in. runner_microvm_floor_fit_stall names the trigger; the new probe pins today's refusal with its three figures and flips on the fit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68307: fixed in the pushed head. The untracked state is now — sent from wise-tern-670 |
…made due The wave-admission wall refuses consumed rows on the roster's next touch (gunbc.namespace_wave_admission namespace_wave_admission_note); this PR's six rows are that touch. The 40 ACTION-USE rows were already satisfied at the base. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Transition-admission migration for gunbc#11704. No action until the operator sequences #11704's landing. gunbc#11704 moves namespace transition admissions out of the tree. Once it lands, any file under To migrate (paste + delete), after #11704 is on main and merged into this branch: git rm \
dag/gunbc/namespace/transition_admission/gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_floor_run_peak_receipt_at_throttle_line.dag \
dag/gunbc/namespace/transition_admission/gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_gunbc_ci_floor_run_peak_receipts.dag \
dag/gunbc/namespace/transition_admission/gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_is_uncensored.dag \
dag/gunbc/namespace/transition_admission/gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_observation.dag \
dag/gunbc/namespace/transition_admission/test_claim_runner_slot_allocation_witness_witness_declared_high_clears_measured_floor_peak_gunbc_floor_measured_peak_observation.dag \
dag/gunbc/namespace/transition_admission/test_claim_runner_slot_allocation_witness_witness_floor_peak_input_is_uncensored_not_a_throttle_pin_gunbc_floor_measured_peak_is_uncensored.dag
git commit -F msg.txt # msg.txt = the text below, verbatim
msg.txt |
…lope, cite the plan's instruments (i) gunbc.rung_drop.slot_row_pinned_below_demonstrated_demand_unrefused: the wall's floor-demand conjunct cannot see a throttle pin at the declared line by its own guard's design, so a row below demonstrated demand is observed, not refused; previous MechanicallyPreventable, temporary Mitigatable, two-clause restoration trigger. Ledger projection regenerated. (ii) fleet_container's idle_memory_envelope was byte-identical to the new product.fabric.envelope memory_envelope; deleted, consumers repointed. (iii) ColdBuildReceiptPlan.instruments are DeclarationRefs to the producers (WorkflowJobRun, CgroupMemoryInterfaceFile, the new stat_allocated_blocks_command, admitted as an argv_command caller); the witness is an identity join, not a count. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68382: all three findings fixed in the pushed head. (1) — sent from wise-tern-670 |
… due Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e, so demand is read from memory.stat The attributions to a session ruling are dropped from the heartbeat reader's doc comment and the .dag rows; the reader carries the fact the receipt established, which is what survives. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
SOURCE HOLD — exact head
|
…, a non-overlapping held-set rule (1) The demand receipt carries the raw memory.stat beats 12-15 as typed values, each transcribed from its own heartbeat line (beat 14 stall 6/min, beat 15 66940/min); the peak and last-unstalled beats are derived folds, and a witness joins the typed beats to the cited producer readings. (2) The task ceiling is applied as the guest agent unit's own TasksMax= (a new ServiceTasksMax directive; pids.max on its cgroup) from the one cell row; the kernel.pid_max boot arg and its helper are deleted -- pid_max is the PID wrap ceiling, a different fact. In-guest readback is a named frontier. (3) memory.stat is not a partition: file includes shmem and unevictable is a list-state counter. beat_held_set folds disjoint terms only (anon + shmem + unreclaimable kernel memory), stated as a resident held-set lower bound; the fixture reds a rule that summed unevictable or reclaimable slab. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…subtraction (1) The producer prints memory.stat as one flat memory_stat=[...] list of raw counters with no grouping; the derivation has one home, gunbc.floor_demand beat_held_set. The FloorNonReclaimable* vocabulary is renamed FloorHeldSet* / FloorMemoryStatBeat, the seed-growth row follows the reader's new name, and the prose says raw beat -> held-set derivation -> resident held-set lower bound. (2) beat_reclaimable_cache returns std.measure MeasureSubtraction; the guest cache allowance is a coproduct (AllowanceDerived | AllowanceUnderivable) and the shape refuses on ShapeRefusedCacheAllowanceUnderivable. RED enrolled at both the subtraction (shmem = file + 1) and the shape. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tence, finite-arithmetic audit (A) FloorMemoryStatBeat carries file_dirty; the four transcribed beats carry it; nothing the producer emits is dropped. (B) No sentence presents unevictable as additive; no witness keeps the old name. (C) The fit is decided by subtraction (need > remainder, then allowance > remainder - need), never by need + allowance; RED at the representable bound enrolled. beat_held_set is a checked seven-term chain over std.checked_arithmetic and a torn beat makes the receipt stand as HeldSetReceiptUnrepresentable; round_up_to_gibibyte_grain is checked (GrainRounding) and the storage total is a checked fold, surfacing as FloorStorageDemand and refused by the shape as ShapeRefusedWorkStorageUnstated. REDs enrolled for the sum, the grain and the shape. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…bound from its row gunbc_floor_measured_peak_armed_high had no consumer after the move (the pin classification carries the armed line inside ThrottlePin); deleted. The cold-build witness compared against a transcribed 10800 while importing witness_floor_lane_timeout unused; it now derives the bound from that row. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68616: both findings fixed in the pushed head. — sent from wise-tern-670 |
…y storage components 267 s was transcribed into the cold-build prediction note with no producer. gunbc.floor_demand gunbc_cold_build_step_wall_x86_64_2026_09_19 carries it (invocation, architecture, vCPUs, Second); the plan cites the row and the witness reads it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 68648: fixed in the pushed head — the cold x86_64 build wall is now — sent from wise-tern-670 |
…-item grain is modeled Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The 2026-09-19 no-ceiling ruling (#11716) makes the production entitlement RelativeOnly; the shape now admits the Work's threads unbounded on that arm instead of refusing, since a relative share can refuse no count. The guest-size derivation stall stays retired; main's edit to it is superseded by runner_microvm_floor_fit_stall. Fleet-cost sentences re-pointed at the memory axis, which binds now.
…d lives in std.measure Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
reviews 68686 and 68703: both fixed in the pushed head. — sent from wise-tern-670 |
main's workspace readback compared against runner_attempt_workspace_size, which this branch moved to runner_microvm_workspace_grant; the readback now reads that one grant.
…he guest on both entry points
extdeps.virtualization.firecracker carries firecracker_vcpu_range_v1_16_1
(1..32) beside the pinned release and firecracker_vcpu_count_admission over it.
runner_microvm_shape refuses ShapeRefusedVcpuCountUnsupported{requested,
minimum, maximum} before either entitlement arm -- a relative-only cell lifts
no VMM bound -- and guest_resources_of_machine_config applies the same range to
a hand-authored FirecrackerMachineConfig, so admission cannot be bypassed with
a count the VMM refuses. Nothing clamps. Witnesses: 8 and 32 resolve; 33 is the
boundary refusal and 64 refuses, on both entry points.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ction, never hand-resolved) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unt, as does the count they bound Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…md regenerated by the projection instrument)
… enrolment) into #11677 Resolution: the plan keeps my JIT fields, device staging and both-stagings gate, and takes #11672's RunnerMicroVmShape parameter, runner_microvm_workspace_grant and with_boot_arg rename. The rosters and argv admissions are additive unions; my signer roster becomes the FOURTH enrolment answer beside main's gh one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Lane of the srvN microVM program (parent sunny-ant-606). Derives the floor's guest shape from the floor's Work and the cell, grounded in typed floor-demand receipts, and plans the cold-build receipt. Nothing here makes the floor job select the microVM path.
What changed
gunbc.floor_demand(new, leaf) — the floor's demand as typed receipts, one home:FloorRunCgroupPeakReceiptand the four 2026-07-11 receipts MOVED here fromgunbc.ci_floor_measurement(which re-imports them), so the slot allocation, the CI measurement and the floor's Work can all read one carrier without a cycle.gunbc_floor_uncensored_demand_receipt: the 2026-09-12 srv1 scope measurement that sized the 26/25 GiB cell, typed for the first time (scopememory.peak24412725248 under a 64 GiB armed line).gunbc_floor_measured_peak_observation/_armed_high/_is_uncensoredare now DERIVED from it;gunbc.runner_slot_allocation's wall conjunct imports them. Until now the wall gated on the 2026-08-17 15.5 GB figure — stale by two rulings.gunbc_floor_throttle_pin_receipt_2026_09_19: merge-group run 35408627003 on srv1-03 pinned at the CURRENT row — peak 26849763328 against high 26843545600, 1928memory.highevents, FloorClean, 46m28s. The floor is welded to the 25 GiB line again, one week after the row was sized to end that.floor_peak_reading_kind(uncensored vs pin, decided by peak against the armed line),gunbc_floor_memory_demand_lower_bound(max peak over receipts, pins included),floor_memory_requirement,floor_storage_requirement(sum of five measured components rounded up to GiB grain = 2 GiB; two components are x86_64 proxies, labelled as such), and the warm whole-job wall receipt.The floor Work states its memory —
gunbc.fabric_witness_run floor_execution_requirementsnow carriesmemory: floor_memory_requirement()(26849763328 bytes, a lower bound, which is whatMemoryRequirement.min_byteshonestly is). Consequence on the offer side, taken deliberately: an offer that states no memory no longer covers the floor (MemoryNotOffered), so the fleet cell's offer envelope is a production row —gunbc_runner_slot_offer_envelope()=memory_envelope(memory_max)— and the live probe and the two fixture offers read it. Storage is stated infloor_demandand consumed by the shape, but NOT placed on the Work's envelope:product.fabric.supplycompares no storage axis (a stated-but-unchecked axis is the fail-open the envelope exists to prevent), and adding one would refuse every host-slot offer because the fleet has no per-slot disk number. Declared frontier with its trigger in the comment.gunbc.runner_microvmderives the shape —runner_microvm_shape(work, storage, cpu, envelope, reserve, task_ceiling, workspace):extdeps.virtualization.firecracker firecracker_vcpu_range_v1_16_1, 1..32 — never clamped to), then against the cell's absolute entitlement when the slot declares one; under the 2026-09-19 no-ceiling ruling (cores_per_slot = 1 per operator ruling; the CPU axis stops binding, CPUQuota stays unset #11716) the slot carries only a relative share, which bounds no count, so the Work's threads stand. The same range is applied to a hand-authoredFirecrackerMachineConfigat admission.guest_memory_fitsadmits it by construction), admitted only if the Work's minimum plus the guest's cache allowance fits — decided by subtraction, never by a sum, with the checked-arithmetic REDs enrolled; the guest is granted the remainder rather than the minimum because the minimum is a censored bound and guest RAM is lazily faulted.runner_microvm_workspace_grant, X's WORKGB=4, moved here from the planner), admitted only if it holds the Work's storage minimum.TasksMax=(ServiceTasksMax, pids.max on its cgroup;gunbc.runner_guest_image), because in this topology the cell's TasksMax bounds only the VMM's threads. It is not kernel.pid_max, which is the PID-number wrap ceiling. In-guest readback is the first attempt's frontier.gunbc_runner_microvm_vm_configreads the shape.plan_attempt_launchtakes the shape (the workspace grant flows from it; main's microVM guest network: tap-grain default-deny egress, slot network readback, workspace staging gate #11675 readback compares against the same grant).runner_microvm_guest_size_derivation_stallis retired: both trigger clauses executed.gunbc.floor_cold_build_receipt(new) — the plan: subject (aarch64, CARGO_HOME wiped, sccache unreachable), three HOST-side instruments, the warm baseline, the rows a receipt revises, a verdict fold against the lane timeout / cell MemoryMax / workspace grant, and a stated prediction (cold wall under 2× warm). Standing isColdBuildReceiptPending; the first guest floor attempt (the cutover lane's) takes it.The finding
The first draft of this PR treated the cgroup peak as the floor's demand; the parent ruled that a bet (memory.peak charges reclaimable cache). So the floor heartbeat now prints the leaf's raw
memory.statcounters every beat (floor_cgroup_stat_beat, Rust, with a seed-growth receipt), and the first receipt — this PR's own CI run 35419304682 on srv4-04, beats 12–15 transcribed raw asFloorMemoryStatBeat— is typed ingunbc.floor_demand.beat_held_setfolds the disjoint terms (anon + shmem + unreclaimable slab, kernel stacks, page tables, percpu, sock;file/unevictable/reclaimable slab excluded, with why) into a resident held-set lower bound: 26725773568 B at the 25 GiB line (anon 26664632320), with 13 MiB of file cache left; beat 15's stall clause reads 66940 major faults/min with host swap-in rising. The cache hypothesis is falsified: the cache was already gone and anonymous memory was being swapped, so the reading is censored on the held-set axis itself (and from a partial run — it refused at 15 min on the latent defect below). All sums are checked construction (std.checked_arithmetic), the cache subtraction isstd.measure measure_sub, and a torn receipt stands asHeldSetReceiptUnrepresentable.min_bytes = 26725773568(measured, no allowance). A 26 GiB cell covers it, so the host-slot fabric path stays fungible.gunbc_runner_microvm_guest_cache_allowance, a coproduct that refuses rather than reading zero), DERIVED from the receipt's last unstalled beat (file − shmem = 1.8 GB at zero stall, one beat before the thrash) rounded up to GiB grain = 2 GiB. Operator may revise the rule; the number follows the receipt.CI repairs
transition_admissionrows for the bindings the floor-demand move retargeted (namespace-wave-admission).fabric_floor_dispatch_witness_test:105lackedNoFeasibleAlternativeUse.receipt— a latent resolve defect the floor never reached on main because the module was never in a change's subject; this PR's edit put it there. Repaired.Evidence
Witnesses run locally with an arm64 binary from this head (
gunbc run --claim-run): runner_microvm, floor_demand, floor_cold_build_receipt, runner_attempt_launch, runner_slot_allocation, fabric_floor_dispatch, ci_floor_measurement — all PASS. fabric_witness_run_test does not resolve undergunbc runon main either; the floor covers it. Storage/wall figures: cold x86_64 build on BuildBuddy invocation abbc8fb7-69eb-4ef0-b8a4-5504084196c9 (target 558310704 B, registry 58151348 B, 267 s cold on 6 vCPU); arm64 toolchain and checkout measured in-session; job 105803508248 timings from the Actions API.🤖 Generated with Claude Code