Skip to content

floor-sized microVM execution shape - #11783

Closed
briansrls wants to merge 29 commits into
mainfrom
session/wise-tern-670
Closed

briansrls wants to merge 29 commits into
mainfrom
session/wise-tern-670

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session wise-tern-670.
Pushing to session/wise-tern-670 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 29 commits September 19, 2026 03:15
…an the cold-build receipt

gunbc.floor_demand is the floor's demand authority: the per-run cgroup peak carrier
moves here from ci_floor_measurement, the 2026-09-12 uncensored scope measurement and
the 2026-09-19 throttle pin are typed receipts, and the slot wall's measured-peak
rows derive from them instead of carrying a stale 2026-08-17 figure. The floor Work
now states its memory demand (a lower bound, 26849763328 bytes) and the fleet cell's
offer states memory_max, so offers that state no memory stop covering the floor.

gunbc.runner_microvm derives the guest shape: the Work's threads admitted against the
cell's absolute entitlement, MemoryMax less the reserve floor-divided to MiB and
admitted only above the Work's minimum, the per-attempt workspace grant admitted only
above the Work's storage minimum, and the cell's TasksMax carried into the guest as
sysctl.kernel.pid_max on the kernel command line. Seven typed refusals; the declared
4 GiB row is a boot-smoke fixture, not a production arm; plan_attempt_launch takes the
shape. The guest-size derivation stall retires.

At today's rows production refuses: the floor's demonstrated demand exceeds the
26 GiB cell's remainder beside the 1 GiB reserve by 5.9 MiB. The refusal carries both
figures and is the expecting-red probe that flips when the cell row or the demand moves.

gunbc.floor_cold_build_receipt plans the arm64, CARGO_HOME-wiped, sccache-unreachable
receipt: host-side instruments, warm baseline, verdict fold against the lane timeout,
the cell and the workspace grant, and a stated wall prediction. Standing is Pending.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
memory.peak charges page cache, so a peak read at the throttle line is a ceiling
that includes cache rather than the floor's demand (operator ruling 2026-09-19).
The non-reclaimable partition -- anon, unevictable, shmem, unreclaimable slab,
kernel stacks, page tables, percpu, sock -- is what a machine must hold, and it is
now read from memory.stat on every heartbeat beside the reclaimable file figures,
so a floor run on the host slot produces the receipt the guest is to be sized from.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…waits on the non-reclaimable receipt

Per operator ruling 2026-09-19: memory.peak charges reclaimable cache, so the
receipts' maximum is renamed the charge ceiling and stops being the Work's
minimum. The Work's memory requirement is the non-reclaimable partition peak
plus a declared page-cache allowance, and is absent while that partition is
unmeasured -- so the guest shape refuses on the absence, not on the ceiling.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ce to the guest; adjudicate the six moved bindings

The floor heartbeat's first memory.stat receipt (run 35419304682, srv4-04):
26725773568 bytes non-reclaimable at the 25 GiB line with 13 MiB of cache left --
the cache had been reclaimed to nothing and anonymous memory was being swapped.
The floor Work states that measured minimum and nothing more; the 2 GiB cache
allowance is guest policy in gunbc.runner_microvm, evidenced by the receipt's two
beats, and the shape refuses at today's cell row with all three figures.

Six transition admissions cover the bindings the floor-demand move retargeted.
fabric_floor_dispatch_witness_test's NoFeasibleAlternativeUse literal gains its
required receipt field: a latent resolve defect the floor never reached on main.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68237 (advisory): the new seed reader carried no checkable receipt in
the repository's form. This is the SeedGrowthJustification row -- purpose
admission under v1_seed_standing, hand-item delta +1, dissolution lane and the
trigger that migrates the line into the observation model's per-beat sample.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cache allowance from it

Review 68259: the allowance's evidence lived only in an annotation. The receipt
now carries both beats as FloorNonReclaimableBeat values, and the allowance is the
last unstalled beat's file cache at gibibyte grain rather than a declared 2 GiB.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…producer returns

Review 68284: a bare Int beside gunbc.memory_stall_refusal's EventsPerMinute was a
second representation of one quantity (DESIGN 3). One carrier now, both sides.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ing-red probe

Review 68307: deleting the guest-size derivation stall left the state 'the
floor's measured demand does not fit the cell, so no production guest can be
shaped' untracked, and the either-state witness could not record which state
production is in. runner_microvm_floor_fit_stall names the trigger; the new
probe pins today's refusal with its three figures and flips on the fit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…made due

The wave-admission wall refuses consumed rows on the roster's next touch
(gunbc.namespace_wave_admission namespace_wave_admission_note); this PR's six
rows are that touch. The 40 ACTION-USE rows were already satisfied at the base.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lope, cite the plan's instruments

(i) gunbc.rung_drop.slot_row_pinned_below_demonstrated_demand_unrefused: the
wall's floor-demand conjunct cannot see a throttle pin at the declared line by
its own guard's design, so a row below demonstrated demand is observed, not
refused; previous MechanicallyPreventable, temporary Mitigatable, two-clause
restoration trigger. Ledger projection regenerated.
(ii) fleet_container's idle_memory_envelope was byte-identical to the new
product.fabric.envelope memory_envelope; deleted, consumers repointed.
(iii) ColdBuildReceiptPlan.instruments are DeclarationRefs to the producers
(WorkflowJobRun, CgroupMemoryInterfaceFile, the new stat_allocated_blocks_command,
admitted as an argv_command caller); the witness is an identity join, not a count.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… due

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e, so demand is read from memory.stat

The attributions to a session ruling are dropped from the heartbeat reader's
doc comment and the .dag rows; the reader carries the fact the receipt
established, which is what survives.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…, a non-overlapping held-set rule

(1) The demand receipt carries the raw memory.stat beats 12-15 as typed values,
each transcribed from its own heartbeat line (beat 14 stall 6/min, beat 15
66940/min); the peak and last-unstalled beats are derived folds, and a witness
joins the typed beats to the cited producer readings.
(2) The task ceiling is applied as the guest agent unit's own TasksMax= (a new
ServiceTasksMax directive; pids.max on its cgroup) from the one cell row; the
kernel.pid_max boot arg and its helper are deleted -- pid_max is the PID wrap
ceiling, a different fact. In-guest readback is a named frontier.
(3) memory.stat is not a partition: file includes shmem and unevictable is a
list-state counter. beat_held_set folds disjoint terms only (anon + shmem +
unreclaimable kernel memory), stated as a resident held-set lower bound; the
fixture reds a rule that summed unevictable or reclaimable slab.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…subtraction

(1) The producer prints memory.stat as one flat memory_stat=[...] list of raw
counters with no grouping; the derivation has one home, gunbc.floor_demand
beat_held_set. The FloorNonReclaimable* vocabulary is renamed FloorHeldSet* /
FloorMemoryStatBeat, the seed-growth row follows the reader's new name, and the
prose says raw beat -> held-set derivation -> resident held-set lower bound.
(2) beat_reclaimable_cache returns std.measure MeasureSubtraction; the guest
cache allowance is a coproduct (AllowanceDerived | AllowanceUnderivable) and the
shape refuses on ShapeRefusedCacheAllowanceUnderivable. RED enrolled at both the
subtraction (shmem = file + 1) and the shape.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tence, finite-arithmetic audit

(A) FloorMemoryStatBeat carries file_dirty; the four transcribed beats carry
it; nothing the producer emits is dropped.
(B) No sentence presents unevictable as additive; no witness keeps the old name.
(C) The fit is decided by subtraction (need > remainder, then allowance >
remainder - need), never by need + allowance; RED at the representable bound
enrolled. beat_held_set is a checked seven-term chain over
std.checked_arithmetic and a torn beat makes the receipt stand as
HeldSetReceiptUnrepresentable; round_up_to_gibibyte_grain is checked
(GrainRounding) and the storage total is a checked fold, surfacing as
FloorStorageDemand and refused by the shape as ShapeRefusedWorkStorageUnstated.
REDs enrolled for the sum, the grain and the shape.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…bound from its row

gunbc_floor_measured_peak_armed_high had no consumer after the move (the pin
classification carries the armed line inside ThrottlePin); deleted. The
cold-build witness compared against a transcribed 10800 while importing
witness_floor_lane_timeout unused; it now derives the bound from that row.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…y storage components

267 s was transcribed into the cold-build prediction note with no producer.
gunbc.floor_demand gunbc_cold_build_step_wall_x86_64_2026_09_19 carries it
(invocation, architecture, vCPUs, Second); the plan cites the row and the
witness reads it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…-item grain is modeled

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The 2026-09-19 no-ceiling ruling (#11716) makes the production entitlement
RelativeOnly; the shape now admits the Work's threads unbounded on that arm
instead of refusing, since a relative share can refuse no count. The
guest-size derivation stall stays retired; main's edit to it is superseded by
runner_microvm_floor_fit_stall. Fleet-cost sentences re-pointed at the memory
axis, which binds now.
…d lives in std.measure

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
main's workspace readback compared against runner_attempt_workspace_size,
which this branch moved to runner_microvm_workspace_grant; the readback now
reads that one grant.
…he guest on both entry points

extdeps.virtualization.firecracker carries firecracker_vcpu_range_v1_16_1
(1..32) beside the pinned release and firecracker_vcpu_count_admission over it.
runner_microvm_shape refuses ShapeRefusedVcpuCountUnsupported{requested,
minimum, maximum} before either entitlement arm -- a relative-only cell lifts
no VMM bound -- and guest_resources_of_machine_config applies the same range to
a hand-authored FirecrackerMachineConfig, so admission cannot be bypassed with
a count the VMM refuses. Nothing clamps. Witnesses: 8 and 32 resolve; 33 is the
boundary refusal and 64 refuses, on both entry points.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ction, never hand-resolved)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…unt, as does the count they bound

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…md regenerated by the projection instrument)
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Duplicate of #11672, which merged as b90b6cf; this branch is fully contained in main. Closing. — sent from wise-tern-670

@gunbai-bot gunbai-bot Bot closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant