Skip to content

Derive the floor's microVM shape from typed floor-demand receipts; plan the cold-build receipt - #11672

Merged
gunbai-bot[bot] merged 29 commits into
mainfrom
session/wise-tern-670
Sep 20, 2026
Merged

gunbai-bot[bot] merged 29 commits into
mainfrom
session/wise-tern-670

Conversation

@briansrls

@briansrls briansrls commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Lane of the srvN microVM program (parent sunny-ant-606). Derives the floor's guest shape from the floor's Work and the cell, grounded in typed floor-demand receipts, and plans the cold-build receipt. Nothing here makes the floor job select the microVM path.

What changed

gunbc.floor_demand (new, leaf) — the floor's demand as typed receipts, one home:

  • FloorRunCgroupPeakReceipt and the four 2026-07-11 receipts MOVED here from gunbc.ci_floor_measurement (which re-imports them), so the slot allocation, the CI measurement and the floor's Work can all read one carrier without a cycle.
  • gunbc_floor_uncensored_demand_receipt: the 2026-09-12 srv1 scope measurement that sized the 26/25 GiB cell, typed for the first time (scope memory.peak 24412725248 under a 64 GiB armed line). gunbc_floor_measured_peak_observation / _armed_high / _is_uncensored are now DERIVED from it; gunbc.runner_slot_allocation's wall conjunct imports them. Until now the wall gated on the 2026-08-17 15.5 GB figure — stale by two rulings.
  • gunbc_floor_throttle_pin_receipt_2026_09_19: merge-group run 35408627003 on srv1-03 pinned at the CURRENT row — peak 26849763328 against high 26843545600, 1928 memory.high events, FloorClean, 46m28s. The floor is welded to the 25 GiB line again, one week after the row was sized to end that.
  • floor_peak_reading_kind (uncensored vs pin, decided by peak against the armed line), gunbc_floor_memory_demand_lower_bound (max peak over receipts, pins included), floor_memory_requirement, floor_storage_requirement (sum of five measured components rounded up to GiB grain = 2 GiB; two components are x86_64 proxies, labelled as such), and the warm whole-job wall receipt.

The floor Work states its memory — gunbc.fabric_witness_run floor_execution_requirements now carries memory: floor_memory_requirement() (26849763328 bytes, a lower bound, which is what MemoryRequirement.min_bytes honestly is). Consequence on the offer side, taken deliberately: an offer that states no memory no longer covers the floor (MemoryNotOffered), so the fleet cell's offer envelope is a production row — gunbc_runner_slot_offer_envelope() = memory_envelope(memory_max) — and the live probe and the two fixture offers read it. Storage is stated in floor_demand and consumed by the shape, but NOT placed on the Work's envelope: product.fabric.supply compares no storage axis (a stated-but-unchecked axis is the fail-open the envelope exists to prevent), and adding one would refuse every host-slot offer because the fleet has no per-slot disk number. Declared frontier with its trigger in the comment.

gunbc.runner_microvm derives the shape — runner_microvm_shape(work, storage, cpu, envelope, reserve, task_ceiling, workspace):

  • vCPUs = the Work's hard threads (8), admitted first against the pinned Firecracker release's own range (extdeps.virtualization.firecracker firecracker_vcpu_range_v1_16_1, 1..32 — never clamped to), then against the cell's absolute entitlement when the slot declares one; under the 2026-09-19 no-ceiling ruling (cores_per_slot = 1 per operator ruling; the CPU axis stops binding, CPUQuota stays unset #11716) the slot carries only a relative share, which bounds no count, so the Work's threads stand. The same range is applied to a hand-authored FirecrackerMachineConfig at admission.
  • memory = MemoryMax − reserve, floor-divided to MiB (so guest_memory_fits admits it by construction), admitted only if the Work's minimum plus the guest's cache allowance fits — decided by subtraction, never by a sum, with the checked-arithmetic REDs enrolled; the guest is granted the remainder rather than the minimum because the minimum is a censored bound and guest RAM is lazily faulted.
  • workspace = the per-attempt grant (runner_microvm_workspace_grant, X's WORKGB=4, moved here from the planner), admitted only if it holds the Work's storage minimum.
  • task ceiling = the cell's TasksMax applied INSIDE the guest as the runner agent unit's own TasksMax= (ServiceTasksMax, pids.max on its cgroup; gunbc.runner_guest_image), because in this topology the cell's TasksMax bounds only the VMM's threads. It is not kernel.pid_max, which is the PID-number wrap ceiling. In-guest readback is the first attempt's frontier.
  • Typed refusals (vCPU range, entitlement, unstated memory, unmodeled/oversized reserve, memory remainder with all three figures, storage vs grant, underivable allowance, unstated storage), each carrying the numbers that disagreed. The declared 4 GiB srv4 row is no longer a production arm; it stays as the boot-smoke fixture. gunbc_runner_microvm_vm_config reads the shape. plan_attempt_launch takes the shape (the workspace grant flows from it; main's microVM guest network: tap-grain default-deny egress, slot network readback, workspace staging gate #11675 readback compares against the same grant).
  • The stall runner_microvm_guest_size_derivation_stall is retired: both trigger clauses executed.

gunbc.floor_cold_build_receipt (new) — the plan: subject (aarch64, CARGO_HOME wiped, sccache unreachable), three HOST-side instruments, the warm baseline, the rows a receipt revises, a verdict fold against the lane timeout / cell MemoryMax / workspace grant, and a stated prediction (cold wall under 2× warm). Standing is ColdBuildReceiptPending; the first guest floor attempt (the cutover lane's) takes it.

The finding

The first draft of this PR treated the cgroup peak as the floor's demand; the parent ruled that a bet (memory.peak charges reclaimable cache). So the floor heartbeat now prints the leaf's raw memory.stat counters every beat (floor_cgroup_stat_beat, Rust, with a seed-growth receipt), and the first receipt — this PR's own CI run 35419304682 on srv4-04, beats 12–15 transcribed raw as FloorMemoryStatBeat — is typed in gunbc.floor_demand. beat_held_set folds the disjoint terms (anon + shmem + unreclaimable slab, kernel stacks, page tables, percpu, sock; file/unevictable/reclaimable slab excluded, with why) into a resident held-set lower bound: 26725773568 B at the 25 GiB line (anon 26664632320), with 13 MiB of file cache left; beat 15's stall clause reads 66940 major faults/min with host swap-in rising. The cache hypothesis is falsified: the cache was already gone and anonymous memory was being swapped, so the reading is censored on the held-set axis itself (and from a partial run — it refused at 15 min on the latent defect below). All sums are checked construction (std.checked_arithmetic), the cache subtraction is std.measure measure_sub, and a torn receipt stands as HeldSetReceiptUnrepresentable.

  • The floor Work states min_bytes = 26725773568 (measured, no allowance). A 26 GiB cell covers it, so the host-slot fabric path stays fungible.
  • The guest gets a cache allowance as guest policy (gunbc_runner_microvm_guest_cache_allowance, a coproduct that refuses rather than reading zero), DERIVED from the receipt's last unstalled beat (file − shmem = 1.8 GB at zero stall, one beat before the thrash) rounded up to GiB grain = 2 GiB. Operator may revise the rule; the number follows the receipt.
  • Production shape: remainder 25 GiB < 24.89 + 2 GiB → refuses with all three figures. Guest needs ≥ 26.9 GiB, i.e. a 28/27 GiB cell row (cores 10→11, width 12→11 per host) or lower demand. That call is the operator's; reported to the parent.

CI repairs

  • Six transition_admission rows for the bindings the floor-demand move retargeted (namespace-wave-admission).
  • fabric_floor_dispatch_witness_test:105 lacked NoFeasibleAlternativeUse.receipt — a latent resolve defect the floor never reached on main because the module was never in a change's subject; this PR's edit put it there. Repaired.

Evidence

Witnesses run locally with an arm64 binary from this head (gunbc run --claim-run): runner_microvm, floor_demand, floor_cold_build_receipt, runner_attempt_launch, runner_slot_allocation, fabric_floor_dispatch, ci_floor_measurement — all PASS. fabric_witness_run_test does not resolve under gunbc run on main either; the floor covers it. Storage/wall figures: cold x86_64 build on BuildBuddy invocation abbc8fb7-69eb-4ef0-b8a4-5504084196c9 (target 558310704 B, registry 58151348 B, 267 s cold on 6 vCPU); arm64 toolchain and checkout measured in-session; job 105803508248 timings from the Actions API.

🤖 Generated with Claude Code

…an the cold-build receipt

gunbc.floor_demand is the floor's demand authority: the per-run cgroup peak carrier
moves here from ci_floor_measurement, the 2026-09-12 uncensored scope measurement and
the 2026-09-19 throttle pin are typed receipts, and the slot wall's measured-peak
rows derive from them instead of carrying a stale 2026-08-17 figure. The floor Work
now states its memory demand (a lower bound, 26849763328 bytes) and the fleet cell's
offer states memory_max, so offers that state no memory stop covering the floor.

gunbc.runner_microvm derives the guest shape: the Work's threads admitted against the
cell's absolute entitlement, MemoryMax less the reserve floor-divided to MiB and
admitted only above the Work's minimum, the per-attempt workspace grant admitted only
above the Work's storage minimum, and the cell's TasksMax carried into the guest as
sysctl.kernel.pid_max on the kernel command line. Seven typed refusals; the declared
4 GiB row is a boot-smoke fixture, not a production arm; plan_attempt_launch takes the
shape. The guest-size derivation stall retires.

At today's rows production refuses: the floor's demonstrated demand exceeds the
26 GiB cell's remainder beside the 1 GiB reserve by 5.9 MiB. The refusal carries both
figures and is the expecting-red probe that flips when the cell row or the demand moves.

gunbc.floor_cold_build_receipt plans the arm64, CARGO_HOME-wiped, sccache-unreachable
receipt: host-side instruments, warm baseline, verdict fold against the lane timeout,
the cell and the workspace grant, and a stated wall prediction. Standing is Pending.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/wise-tern-670 branch from fa2c5cb to 0bb83f9 Compare September 19, 2026 03:15
@gunbai-bot gunbai-bot Bot changed the title floor-sized microVM execution shape Derive the floor's microVM shape from typed floor-demand receipts; plan the cold-build receipt Sep 19, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 19, 2026 03:15
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Local witness runs (arm64 binary built from this head, gunbc run --claim-run): runner_microvm, floor_demand, floor_cold_build_receipt, runner_attempt_launch, runner_slot_allocation, ci_floor_measurement all PASS, exit 0. fabric_witness_run_test and fabric_floor_dispatch_witness_test do not resolve under gunbc run on main either (effect-summary / NoFeasibleAlternativeUse.receipt refusals, reproduced against 7261964 with the same binary), so their fungibility claims over the memory-stating floor Work are verified by the CI floor rather than locally.

Brian Searls and others added 6 commits September 19, 2026 03:20
memory.peak charges page cache, so a peak read at the throttle line is a ceiling
that includes cache rather than the floor's demand (operator ruling 2026-09-19).
The non-reclaimable partition -- anon, unevictable, shmem, unreclaimable slab,
kernel stacks, page tables, percpu, sock -- is what a machine must hold, and it is
now read from memory.stat on every heartbeat beside the reclaimable file figures,
so a floor run on the host slot produces the receipt the guest is to be sized from.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…waits on the non-reclaimable receipt

Per operator ruling 2026-09-19: memory.peak charges reclaimable cache, so the
receipts' maximum is renamed the charge ceiling and stops being the Work's
minimum. The Work's memory requirement is the non-reclaimable partition peak
plus a declared page-cache allowance, and is absent while that partition is
unmeasured -- so the guest shape refuses on the absence, not on the ceiling.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ce to the guest; adjudicate the six moved bindings

The floor heartbeat's first memory.stat receipt (run 35419304682, srv4-04):
26725773568 bytes non-reclaimable at the 25 GiB line with 13 MiB of cache left --
the cache had been reclaimed to nothing and anonymous memory was being swapped.
The floor Work states that measured minimum and nothing more; the 2 GiB cache
allowance is guest policy in gunbc.runner_microvm, evidenced by the receipt's two
beats, and the shape refuses at today's cell row with all three figures.

Six transition admissions cover the bindings the floor-demand move retargeted.
fabric_floor_dispatch_witness_test's NoFeasibleAlternativeUse literal gains its
required receipt field: a latent resolve defect the floor never reached on main.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68237 (advisory): the new seed reader carried no checkable receipt in
the repository's form. This is the SeedGrowthJustification row -- purpose
admission under v1_seed_standing, hand-item delta +1, dissolution lane and the
trigger that migrates the line into the observation model's per-beat sample.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cache allowance from it

Review 68259: the allowance's evidence lived only in an annotation. The receipt
now carries both beats as FloorNonReclaimableBeat values, and the allowance is the
last unstalled beat's file cache at gibibyte grain rather than a declared 2 GiB.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…producer returns

Review 68284: a bare Int beside gunbc.memory_stall_refusal's EventsPerMinute was a
second representation of one quantity (DESIGN 3). One carrier now, both sides.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68284: fixed in the pushed head — FloorNonReclaimableBeat.stall is now std.measure EventsPerMinute (the carrier memory_stall_major_fault_rate returns), and both witnesses read it through events_per_minute_count. Both modules re-run green locally.

— sent from wise-tern-670

Brian Searls and others added 2 commits September 19, 2026 08:19
…ing-red probe

Review 68307: deleting the guest-size derivation stall left the state 'the
floor's measured demand does not fit the cell, so no production guest can be
shaped' untracked, and the either-state witness could not record which state
production is in. runner_microvm_floor_fit_stall names the trigger; the new
probe pins today's refusal with its three figures and flips on the fit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68307: fixed in the pushed head. The untracked state is now gunbc.guarantee_stall.runner_microvm_floor_fit_stall (rostered; blocker AwaitsOneGrounding on the operator's cell-row/demand decision, with the in-guest cold receipt as the other mover; trigger = production shape resolves and the probe flips). The pinned control the_production_shape_refuses_today_on_the_memory_remainder_with_all_three_figures asserts today's refusal with need/allowance/remainder and reds when the fit changes; the either-state witness stays as the invariant. Both stall and microvm witness modules green locally.

— sent from wise-tern-670

…made due

The wave-admission wall refuses consumed rows on the roster's next touch
(gunbc.namespace_wave_admission namespace_wave_admission_note); this PR's six
rows are that touch. The 40 ACTION-USE rows were already satisfied at the base.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Transition-admission migration for gunbc#11704. No action until the operator sequences #11704's landing.

gunbc#11704 moves namespace transition admissions out of the tree. Once it lands, any file under dag/gunbc/namespace/transition_admission/ refuses at this PR's own gate, and the admission has to be carried in a commit message on this branch instead. The block below was derived mechanically from this PR's 6 row file(s) at its current head. The only edits: deletion_follow_up, owner_pull_request and their now-unused imports are dropped, because those fields no longer exist. All 6 blocks load through the production fold (carried_admissions_from_messages) with no refusal.

To migrate (paste + delete), after #11704 is on main and merged into this branch:

git rm \
  dag/gunbc/namespace/transition_admission/gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_floor_run_peak_receipt_at_throttle_line.dag \
  dag/gunbc/namespace/transition_admission/gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_gunbc_ci_floor_run_peak_receipts.dag \
  dag/gunbc/namespace/transition_admission/gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_is_uncensored.dag \
  dag/gunbc/namespace/transition_admission/gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_observation.dag \
  dag/gunbc/namespace/transition_admission/test_claim_runner_slot_allocation_witness_witness_declared_high_clears_measured_floor_peak_gunbc_floor_measured_peak_observation.dag \
  dag/gunbc/namespace/transition_admission/test_claim_runner_slot_allocation_witness_witness_floor_peak_input_is_uncensored_not_a_throttle_pin_gunbc_floor_measured_peak_is_uncensored.dag
git commit -F msg.txt   # msg.txt = the text below, verbatim

-F keeps the lines exactly as they are. The squash merge carries the message into the queue run, and nothing lands in the tree. If a row is wrong later, a later block with the same stem supersedes it.

msg.txt
Move transition admissions into the commit message (gunbc#11704)

```transition-admission
module gunbc.namespace.transition_admission.gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_floor_run_peak_receipt_at_throttle_line

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_floor_run_peak_receipt_at_throttle_line: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME floor_run_peak_receipt_at_throttle_line moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.ci_floor_measurement", "witness_floor_run_peak_receipts_at_throttle_line"),
    spelling: "floor_run_peak_receipt_at_throttle_line" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "floor_run_peak_receipt_at_throttle_line")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_gunbc_ci_floor_run_peak_receipts

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_ci_floor_measurement_witness_floor_run_peak_receipts_at_throttle_line_gunbc_ci_floor_run_peak_receipts: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME gunbc_ci_floor_run_peak_receipts moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.ci_floor_measurement", "witness_floor_run_peak_receipts_at_throttle_line"),
    spelling: "gunbc_ci_floor_run_peak_receipts" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "gunbc_ci_floor_run_peak_receipts")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_is_uncensored

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_is_uncensored: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME gunbc_floor_measured_peak_is_uncensored moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.runner_slot_allocation", "gunbc_runner_slot_allocation_wall_holds"),
    spelling: "gunbc_floor_measured_peak_is_uncensored" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "gunbc_floor_measured_peak_is_uncensored")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_observation

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data gunbc_runner_slot_allocation_gunbc_runner_slot_allocation_wall_holds_gunbc_floor_measured_peak_observation: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME gunbc_floor_measured_peak_observation moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("gunbc.runner_slot_allocation", "gunbc_runner_slot_allocation_wall_holds"),
    spelling: "gunbc_floor_measured_peak_observation" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "gunbc_floor_measured_peak_observation")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_runner_slot_allocation_witness_witness_declared_high_clears_measured_floor_peak_gunbc_floor_measured_peak_observation

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_runner_slot_allocation_witness_witness_declared_high_clears_measured_floor_peak_gunbc_floor_measured_peak_observation: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME gunbc_floor_measured_peak_observation moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.runner_slot_allocation_witness", "witness_declared_high_clears_measured_floor_peak"),
    spelling: "gunbc_floor_measured_peak_observation" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "gunbc_floor_measured_peak_observation")],
  },
  disposition: TargetChanged,
}
```

```transition-admission
module gunbc.namespace.transition_admission.test_claim_runner_slot_allocation_witness_witness_floor_peak_input_is_uncensored_not_a_throttle_pin_gunbc_floor_measured_peak_is_uncensored

import std.types { NonEmptyStr, List }
import std.decl_ref { decl_ref }
import gunbc.compiler_frontend_program_interlock { TargetChanged }
import gunbc.namespace.transition_admission { TransitionAdmission, Binding }

data test_claim_runner_slot_allocation_witness_witness_floor_peak_input_is_uncensored_not_a_throttle_pin_gunbc_floor_measured_peak_is_uncensored: TransitionAdmission = TransitionAdmission {
  label: "FLOOR-DEMAND HOME gunbc_floor_measured_peak_is_uncensored moves to gunbc.floor_demand (gunbc#11672)" as NonEmptyStr,
  subject: Binding {
    enclosing: decl_ref("test.claim.runner_slot_allocation_witness", "witness_floor_peak_input_is_uncensored_not_a_throttle_pin"),
    spelling: "gunbc_floor_measured_peak_is_uncensored" as NonEmptyStr,
    expected_candidates: [decl_ref("gunbc.floor_demand", "gunbc_floor_measured_peak_is_uncensored")],
  },
  disposition: TargetChanged,
}
```

…lope, cite the plan's instruments

(i) gunbc.rung_drop.slot_row_pinned_below_demonstrated_demand_unrefused: the
wall's floor-demand conjunct cannot see a throttle pin at the declared line by
its own guard's design, so a row below demonstrated demand is observed, not
refused; previous MechanicallyPreventable, temporary Mitigatable, two-clause
restoration trigger. Ledger projection regenerated.
(ii) fleet_container's idle_memory_envelope was byte-identical to the new
product.fabric.envelope memory_envelope; deleted, consumers repointed.
(iii) ColdBuildReceiptPlan.instruments are DeclarationRefs to the producers
(WorkflowJobRun, CgroupMemoryInterfaceFile, the new stat_allocated_blocks_command,
admitted as an argv_command caller); the witness is an identity join, not a count.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68382: all three findings fixed in the pushed head. (1) gunbc.rung_drop.slot_row_pinned_below_demonstrated_demand_unrefused declares the drop on the wall's floor-demand conjunct (previous MechanicallyPreventable → temporary Mitigatable; trigger requires BOTH the row/demand moving under an operator ruling AND a wall conjunct that makes a pin at the declared line loud), rostered and projected into docs/design-rung-drops.md. Extending the wall instead would refuse the current row on every required run until an operator moves it, which is the fleet-cost decision the parent is holding. (2) fleet_container.idle_memory_envelope deleted; its two consumers read product.fabric.envelope memory_envelope. (3) ColdBuildReceiptPlan.instruments is now List<DeclarationRef> naming WorkflowJobRun, CgroupMemoryInterfaceFile and the new extdeps.tools.stat stat_allocated_blocks_command (%b %B, admitted as an argv_command caller); the witness joins on module path + declaration name instead of counting. Affected modules green locally.

— sent from wise-tern-670

Brian Searls and others added 3 commits September 19, 2026 12:29
… due

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e, so demand is read from memory.stat

The attributions to a session ruling are dropped from the heartbeat reader's
doc comment and the .dag rows; the reader carries the fact the receipt
established, which is what survives.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

SOURCE HOLD — exact head 53970759d02960ea9bc3002dc1f997f539c8e9b5

The core direction is right: the floor Work now carries demand, production shape resolution refuses honestly on need + allowance > cell remainder, the refusal carries all three figures, and the unresolved production state is tracked instead of widened. The earlier false attribution is also gone. The later stage-1 memory design is not itself a reason to hold this truthful refusal.

Three source findings remain:

  1. The typed receipt disagrees with its own provenance. gunbc_floor_non_reclaimable_receipt_2026_09_19.peak.stall is events_per_minute(count: 6), while the adjacent source account and PR body say the same beat read 66,940 major faults/min. EventsPerMinute stores that count literally; the witness checks only zero/nonzero, so all four green checks can pass across this four-order-of-magnitude disagreement. Carry the producer's actual value—or correct the provenance if 6 is right—and add a control that joins the typed value to the cited reading rather than only testing its sign.

  2. TasksMax is not kernel.pid_max. The model says it carries the cell's systemd/cgroup TasksMax into the guest, but emits sysctl.kernel.pid_max=. Linux defines pid_max as the PID-allocation wrap ceiling; cgroup pids.max is the hard concurrent-process limit whose fork/clone refusal is the EAGAIN mechanism this row was introduced to govern. Either realize and read back a guest systemd TasksMax=/cgroup pids.max, or introduce an honestly distinct guest PID-allocation policy. Do not project one authority as the other.

  3. The memory.stat value called a non-reclaimable partition is not structurally derivable from the carrier as written. The emitted list includes anon, shmem, and unevictable; kernel memory-stat vocabulary says file includes tmpfs/shared memory, while unevictable is list state that can overlap the type counters. The typed receipt then carries only one aggregate, not the raw components or a disjoint formula, even though that aggregate becomes the Work's memory minimum. Carry the raw beat fields and derive the demand through a checkable non-overlapping fold, or narrow the name and claim to the quantity actually computed.

Operationally, this head is also no longer merge-ready: current main has advanced, GitHub reports the PR non-mergeable, and the branch is 17 commits behind/diverged. After the source repairs, compose current main and rerun the exact resulting head.

@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Sep 19, 2026
Brian Searls and others added 3 commits September 19, 2026 18:24
…, a non-overlapping held-set rule

(1) The demand receipt carries the raw memory.stat beats 12-15 as typed values,
each transcribed from its own heartbeat line (beat 14 stall 6/min, beat 15
66940/min); the peak and last-unstalled beats are derived folds, and a witness
joins the typed beats to the cited producer readings.
(2) The task ceiling is applied as the guest agent unit's own TasksMax= (a new
ServiceTasksMax directive; pids.max on its cgroup) from the one cell row; the
kernel.pid_max boot arg and its helper are deleted -- pid_max is the PID wrap
ceiling, a different fact. In-guest readback is a named frontier.
(3) memory.stat is not a partition: file includes shmem and unevictable is a
list-state counter. beat_held_set folds disjoint terms only (anon + shmem +
unreclaimable kernel memory), stated as a resident held-set lower bound; the
fixture reds a rule that summed unevictable or reclaimable slab.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…subtraction

(1) The producer prints memory.stat as one flat memory_stat=[...] list of raw
counters with no grouping; the derivation has one home, gunbc.floor_demand
beat_held_set. The FloorNonReclaimable* vocabulary is renamed FloorHeldSet* /
FloorMemoryStatBeat, the seed-growth row follows the reader's new name, and the
prose says raw beat -> held-set derivation -> resident held-set lower bound.
(2) beat_reclaimable_cache returns std.measure MeasureSubtraction; the guest
cache allowance is a coproduct (AllowanceDerived | AllowanceUnderivable) and the
shape refuses on ShapeRefusedCacheAllowanceUnderivable. RED enrolled at both the
subtraction (shmem = file + 1) and the shape.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tence, finite-arithmetic audit

(A) FloorMemoryStatBeat carries file_dirty; the four transcribed beats carry
it; nothing the producer emits is dropped.
(B) No sentence presents unevictable as additive; no witness keeps the old name.
(C) The fit is decided by subtraction (need > remainder, then allowance >
remainder - need), never by need + allowance; RED at the representable bound
enrolled. beat_held_set is a checked seven-term chain over
std.checked_arithmetic and a torn beat makes the receipt stand as
HeldSetReceiptUnrepresentable; round_up_to_gibibyte_grain is checked
(GrainRounding) and the storage total is a checked fold, surfacing as
FloorStorageDemand and refused by the shape as ShapeRefusedWorkStorageUnstated.
REDs enrolled for the sum, the grain and the shape.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…bound from its row

gunbc_floor_measured_peak_armed_high had no consumer after the move (the pin
classification carries the armed line inside ThrottlePin); deleted. The
cold-build witness compared against a transcribed 10800 while importing
witness_floor_lane_timeout unused; it now derives the bound from that row.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68616: both findings fixed in the pushed head. gunbc_floor_measured_peak_armed_high (and its derivation fn) deleted — git grep now returns nothing; the armed line lives inside ThrottlePin. The cold-build witness now bounds the prediction ceiling by minute_count(witness_floor_lane_timeout) * seconds_per_minute() instead of a bare 10800. Both modules plus runner_slot_allocation green locally.

— sent from wise-tern-670

Brian Searls and others added 2 commits September 19, 2026 20:46
…y storage components

267 s was transcribed into the cold-build prediction note with no producer.
gunbc.floor_demand gunbc_cold_build_step_wall_x86_64_2026_09_19 carries it
(invocation, architecture, vCPUs, Second); the plan cites the row and the
witness reads it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

review 68648: fixed in the pushed head — the cold x86_64 build wall is now gunbc.floor_demand gunbc_cold_build_step_wall_x86_64_2026_09_19 (typed ColdBuildStepWallReceipt, Second, with its BuildBuddy invocation and architecture), carried on ColdBuildReceiptPlan.cold_proxy_build_step and read by the plan witness; the note names the row instead of the number.

— sent from wise-tern-670

Brian Searls and others added 3 commits September 19, 2026 22:15
…-item grain is modeled

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The 2026-09-19 no-ceiling ruling (#11716) makes the production entitlement
RelativeOnly; the shape now admits the Work's threads unbounded on that arm
instead of refusing, since a relative share can refuse no count. The
guest-size derivation stall stays retired; main's edit to it is superseded by
runner_microvm_floor_fit_stall. Fleet-cost sentences re-pointed at the memory
axis, which binds now.
…d lives in std.measure

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

reviews 68686 and 68703: both fixed in the pushed head. ColdBuildStepWallReceipt.vcpus is HardwareThreadCount (hardware_thread_count(count: 6)), and minute_to_second now lives in std.measure beside minute_to_millisecond, consumed by the cold-build verdict and its witness. floor_demand, floor_cold_build_receipt and measure_lifted_algebra modules green locally.

— sent from wise-tern-670

Brian Searls and others added 5 commits September 20, 2026 00:05
main's workspace readback compared against runner_attempt_workspace_size,
which this branch moved to runner_microvm_workspace_grant; the readback now
reads that one grant.
…he guest on both entry points

extdeps.virtualization.firecracker carries firecracker_vcpu_range_v1_16_1
(1..32) beside the pinned release and firecracker_vcpu_count_admission over it.
runner_microvm_shape refuses ShapeRefusedVcpuCountUnsupported{requested,
minimum, maximum} before either entitlement arm -- a relative-only cell lifts
no VMM bound -- and guest_resources_of_machine_config applies the same range to
a hand-authored FirecrackerMachineConfig, so admission cannot be bypassed with
a count the VMM refuses. Nothing clamps. Witnesses: 8 and 32 resolve; 33 is the
boundary refusal and 64 refuses, on both entry points.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ction, never hand-resolved)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unt, as does the count they bound

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…md regenerated by the projection instrument)
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 20, 2026
Merged via the queue into main with commit b90b6cf Sep 20, 2026
1 of 2 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/wise-tern-670 branch September 20, 2026 03:08
@briansrls
briansrls restored the session/wise-tern-670 branch September 20, 2026 03:09
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 20, 2026
6 tasks
gunbai-bot Bot pushed a commit that referenced this pull request Sep 20, 2026
… enrolment) into #11677

Resolution: the plan keeps my JIT fields, device staging and both-stagings gate,
and takes #11672's RunnerMicroVmShape parameter, runner_microvm_workspace_grant
and with_boot_arg rename. The rosters and argv admissions are additive unions;
my signer roster becomes the FOURTH enrolment answer beside main's gh one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant