Repository navigation
fabric DB: replace git under the fabric event log - #11723
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… deploy and witness rosters (WIP) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…route), ensured store root, served-handler claim, plan doc Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… a verb that never landed (review 68555) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
Addressed review 68555 in e3d9233:
|
… over it (floor NewUnresolvedness) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ung drop (review 68598) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
Addressed review 68598 in 0a43a9a. The finding holds: under git an append needed an ssh credential on srv1, and the served endpoint refuses no principal.
|
…ded rows kept, projection regenerated) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s status line through extdeps.tools.curl classify_curl_http_code_after_newline (one authority) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Sep 20, 2026
briansrls
pushed a commit
that referenced
this pull request
Sep 20, 2026
Resolves: fabric_event_log_append_real_execution_witness_test deleted on main (#11723) while migrated here -- deletion taken. Main added a new shell.Symlink consumer (devboot_text_blob_real_execution_witness_test); migrated onto ln_symbolic_force_command like the others, so the service deletion stands. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 20, 2026
…ng meets the participation roster main's #11723 (fabric DB under the event log) replaced layout: EventLogLayout with store: FabricDbBinding through the harness candidate/placement path, where this branch threads participation_roster; every such function now carries both. fabric_event_log takes main's side wholesale (the branch's cat_file_chasing_remote had no referent once the git mirror was replaced). serving_incarnation_observe takes main's Optional refusal arm with this branch's names: threading re-applied. ci_spec and fleet_converge_workflow union both sides' modes and steps. floor_route_gap keeps both expectation populations, this branch's chunk renumbered to 18. Review 68783: the apply script's dead changed=0/1 computation is deleted. The emitted fleet-converge.yml is main's copy pending regeneration: three local regeneration attempts were refused (MemoryStallRefusedPageThrash) or killed by session restarts on a saturated host, so the generated-artifact job is the adjudicator. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces git as the storage of the fabric event log with our own fabric DB (operator decision 2026-09-19). This is a replacement migration (DESIGN §3): the git plumbing is deleted in one motion, with no dual path and no fallback to git. Scope is steps 1–3 of
docs/plans/fabric-db.md.What changed
1. Interface:
std.fabric_db. Immutable content-addressed objects plus compare-and-set named heads, built fromstd.content_hashkeys andstd.durable_compare_and_setrather than new vocabulary.FabricStoreUnreachableFabricStoreRefused(carriesCasStoreFailure)FabricObjectMissingFabricObjectCorruptFabricReplyUndecodableFabricHeadNameRefusedFabricHeadMoved, carrying both heads. Under git, a lost race and an unreachable store both exited 128.NonEmptyStr, so git's "empty blob published as head" defect has no constructor.std.artifact_store. That store evicts entries least-recently-used; log history must never be evicted.2. Realization. Interface, realization and policy are three separate facts.
gunbc.fabric_db_file_store. Heads aredurable_cas_file_storeO_EXCL slots, objects are write-once files beside them, and the closure walk is bounded.gunbc.fabric_db_serve. It isgunbc serveon srv1, bound to 127.0.0.1, reachable only throughtailscale serveon :10000 at the root mount. srv1's :443 is the dashboard and :8443 is ntfy.gunbc.fabric_db_client. The placed host runs the store in process; every other host makes one bounded curl POST. The newextdeps.http.client PostStdinWithinkeeps curl's exit code, whichextdeps.tools.curl CurlExitOutcomeclassifies. Connect failure or timeout becomesFabricStoreUnreachablebefore any reply is read, and a non-200 reply becomesFabricReplyUndecodable.gunbc.fabric_db_wireis the one text form all arms cross the hop in.gunbc.fabric_db_placementis the policy row: srv1 and the store root, with the URL derived from the fleet tailnet domain.FabricDbStoreDirectory), so no retract can remove the log. The old mirror root was owned and torn down withrm -rf.fabric_db_placed_on).3. Cutover.
gunbc.fabric_event_logruns on the fabric DB; the mirror, ls-remote, fetch, cat-file, push-with-lease and placement ensure are deleted.EventLogRefusal, and seat outcomes gainedSeatStoreRefused/SeatStandingStoreRefused.harness_seat,harness_clifabric_quota,fabric_event_log_hostroadmap_publish_observe, a consumer the survey missedfabric_event_log_probegained a_servedentry; the collision probes take an endpoint)Single writer by construction. The head CAS stays O_EXCL on srv1's local disk, so concurrent requests cannot both win; nothing relies on the serve loop being serial. Restart loses nothing: state is the files, and the handler holds nothing in memory.
Drain (operator condition)
Partitions start empty; nothing is imported from git.
gunbc.harness.harness_cli harness_seat_policy.maximum_duration_seconds(request deadline + release allowance).roadmap_publish_observe) takes 120 s./opt/gunbc/fabric-event-log.giton srv1 stays read-only as history, and nothing consults it.Access (operator condition)
tailscale serve, perextdeps.tailscale.identity.Evidence
All runs are
gunbc run --claim-runat this head, built locally.New witnesses (all pass):
test.claim.fabric.fabric_db_witness: 9 pure claims (decode, truncation, stream, verification, head admission).test.claim.fabric.fabric_db_wire_witness: 10. Each arm survives the hop, and the transport arms are checked: exit 7/28 → unreachable, a non-200 → undecodable.test.claim.fabric.fabric_db_file_store_wet_witness: 9. These are the discriminating REDs for lost race, missing object, hole, corrupt object, bound and navigating name, plus the served handler's store side.test.claim.fabric.fabric_event_log_wet_witness: 3, including the inhabitance claim: three chained appends read back whole through the real store.Evidence moved, not dropped (§4b(4)). The git red control for
identity_hashed_from_a_shared_mutable_pathmoved totest.claim.devboot_text_blob_real_execution, since devboot is git's remaining stdin caller. The failure-mode row's evidence was updated to match.Live checks:
fabric_event_log_probeagainst a fresh store: all 9 steps pass (appends, stale race, chain read, seat grant → full → release → grant).store unreachable: could not connect (curl exit 7).Re-run touched suites (pass): harness guidance, turn admission, turn completion; roadmap_publish_observe; devboot_subject_identity; desired_roster; live_deploy apply and emit (67); local_repo_wet_terminal; witness_exclusion_reconciliation; serving_availability_bind_wet; http_client_get.
Pre-existing reds, reproduced at base
43643bad4f, not caused here:deployed_tree_remote_witness the_remote_converges_after_its_inputs_and_before_the_beltharness_seat_witness the_tolerant_pool_is_a_separate_pool_whose_ceiling_is_not_the_engines_sequence_limitlive_deploy_unit_emission_oraclethe_serve_unit_matches_the_deployed_bytesandserve_unit_execstart_carries_admitted_entrypointPending: the live read of the group A partition on srv1, which needs deploy plus srv1 access. The partition starts empty after cutover, so the first live receipt is
fabric_event_log_probe_servedagainst the srv1 endpoint, followed by a real seat bind.Known limits (declared in the plan doc)
🤖 Generated with Claude Code