Skip to content

Cut 0 and the D0 authorization producer: the candidate keyed on the published manifests; the consent filed, decided and admitted at the door - #11918

Merged
briansrls merged 25 commits into
mainfrom
plan/dsv41-cut-0
Sep 21, 2026
Merged

briansrls merged 25 commits into
mainfrom
plan/dsv41-cut-0

Conversation

@briansrls

@briansrls briansrls commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Cut 0 keys the V4.1 candidate's model-source axes from the publisher's declared facts at dba1be0a, and lands the escalation → authorization producer and the wet door D0 was blocked on. No host is touched; the row-store content digest (a fleet read) is the one axis still unestablished, so the live candidate stays V41CandidateUnestablished on this head by design.

Model source (extdeps.deepseek.deepseek_v4_1_flash, gunbc.spark.v41_runtime_candidate)

  • DeepseekV41PublishedFile { path, file_bytes, sha256 }: one record for every file the candidate is keyed by. The 46 backbone shard rows are declared from the Hub tree API; the two Engram shard rows derive from deepseek_v4_1_flash_engram_shard_1/_14, which own them.
  • Admission, not counting — deepseek_v4_1_flash_admit_weight_manifest: every generated model-NNNNN-of-00048 path present exactly once (identity join both ways), no foreign path, the declared count, the sizes summed against the tree total, and the index's weight_map shard set equal to the file set. model.safetensors.index.json is a published row (7470294 B, sha256 74b0686a…) and is a row in the admitted canonical text, so an index change is a different model source over the same shards. RED: shard 4 replaced by a duplicate of shard 3 (same size, count and total unchanged) refuses naming both defects.
  • Canonical text is sorted by path: reordering the rows keys identically; a path, size or digest change changes the key.
  • Tokenizer by role (DeepseekV41TokenizerRole × DeepseekV41RoleCarrier): vocabulary = tokenizer.json, configuration = tokenizer_config.json, special tokens embedded in tokenizer.json, prompt encoding = encoding/encoding.py (published file, sha256 502bdaec… — there is no Jinja template), generation defaults = no separate file at the revision. The axis is keyed by the sorted role manifest (role, carrier arm, exact file identity / establishing revision / not-consumed), not by the file set: moving special tokens to not-consumed or re-establishing a no-file fact at another revision changes the key with the files unchanged; an embedded role joins by exact identity; one path with two identities refuses; a role without a carrier refuses.
  • v41_model_source consumes the two admissions and never the raw rows: a defective population is a REFUSED source naming its defects (never an obligation, never a differently keyed one); missing evidence is an obligation. The index's weight_map shard set is a transcribed reading joined against the files, with a supplied-index RED.

Authorization (gunbc.auth.approval_gate, gunbc.spark.pair_serving_d0_authorization, gunbc.spark.pair_serving_d0_door)

  • One generic gunbc.auth.approval_gate (review 69465): ApprovalGate<Subject>, approval_gate_from_poll (live, authorized at the observed instant), the instant probe, the standing read, the bounded poll (each tick admits at the instant of that read), the signed filing. gunbc.machine_intake_mtcollins1_boot_run/_authorization rebind to it; their copies and D0's are deleted. The effectful reads are not generic (no declaration may carry both type parameters and a uses row), so they take the escalation id and return the standing with its instant.
  • The decision as recorded is its own constructor (approval_recorded_from_poll → RecordedApproval<Subject>), never GateAdmitted; D0 turns it into a resumable authorization only against a claim held by this transaction (d0_resumable_authorization), so "historically approved" and "admitted to begin" cannot inhabit one arm.
  • A pending filing expires by the window the broker filed, not a rerun's freshly computed one; the bounded poll makes its declared N waits and reads once more at the boundary, and a decision read on the last tick is that decision.
  • std.scoped_authorization now refuses an instant before granted_at (AuthorizationObservedBeforeGrant) as well as after expires_at: a claim cannot predate the decision it consumes.
  • The filing is frozen before it is asked (pair_serving_d0 d0_freeze_filing, gen 1 / ExpectSlotAbsent, the intent text = the bytes the intent hash is over). A rerun re-derives the identical request from it (d0_filed_request; another transaction under the escalation refuses) with no live subject consulted, reads the durable claim, and: held by this transaction → recorded approval → d0_dispatch resumes under the consent that began the lifecycle, expired or not; absent → the standing is polled and admitted live as a first run's (not filed: the frozen request is filed now); any other holder → refuses. d0_dispatch alone decides start vs resume (Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease #11555's recovery law is preserved).
  • The claim instant is probed after the gate, immediately before dispatch; now is Timestamp through the D0 signatures.
  • d0_live_subject exists iff the candidate is keyed; the request carries the exact intent; the door checks both fabric-storage write walls before filing anything; the stub resolver is deleted.

Witnesses (all pass locally; CI green on the previous head, running on this one)

deepseek authority (manifest admission + REDs; tokenizer role manifest identity + REDs), v41 candidate, D0 authorization (frozen intent round trip; recorded approval resumable only under this transaction's held claim), D0 real execution (+ filing frozen once and read back without a live subject; + a grant whose window has not opened or has closed takes no claim), Mt Collins authorization/run rebound to the shared gate.

Out of scope, in order (roadmap node serving-v41-cut-d-d0-transaction)

Row-store digest (fleet read); the two fabric-storage write walls (#11936 takes the writer-identity reading the roster needs); the D0 door as a fleet-converge mode; D0 on Group A; D1.

🤖 Generated with Claude Code

Brian Searls and others added 15 commits September 20, 2026 17:30
…e plan/dsv41-cut-d-2b delta re-applied over main@5f4202a5c6

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…r_memory_demand, r2_permission_group_observe, namespace_reference_derived_residency_qualification): a source annotation inside a declaration body refuses to parse and reds every floor run

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion wall was deleted by operator ruling 2026-09-19 (gunbc.rung_drop namespace_wave_admission_wall_removed) and a row file in the tree now refuses to resolve

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t_capture_historical_binding and runner_microvm_boot_probe to module grain (they refuse to parse and red every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…left in chunk_20 (expected expression, found Newline; reds every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused
Heal-Candidate-Run: 35538018867
…ot quiet (OccupancyNotQuiet names every live rank; never dropped into a drifted population); PlacementCleanupUnread replaces the minted "unknown" preparation id and D0 carries preparation: none; the repair binds the consumption it acts on once; one read budget on gunbc.fabric_event_log; the misnamed HostEffectClaimed.generation deleted

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	ROADMAP.md
#	dag/gunbc/target_binding.dag
… at dba1be0a, from the Hub tree API) and the tokenizer files are declared in extdeps.deepseek.deepseek_v4_1_flash and key the candidate's weights and tokenizer axes by the digest of their canonical text; the row-store digest remains the one fleet-side obligation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title DS4.1 Cut 0: the V4.1 weight manifest and tokenizer files key the candidate; the row-store digest is the one fleet-side obligation left Sep 21, 2026
@gunbai-bot
gunbai-bot Bot changed the base branch from main to plan/dsv41-cut-d-2b September 21, 2026 01:04
Base automatically changed from plan/dsv41-cut-d-2b to main September 21, 2026 01:39
# Conflicts:
#	ROADMAP.md
#	docs/design-rung-drops.md
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 21, 2026 01:42
…ecord for shards and tokenizer files with one canonical text; the manifest's Engram rows derive from their owners and the total reconciles by fold (review 69452); gunbc.spark.pair_serving_d0_authorization builds the request over the keyed successor and turns the operator's approval poll into ScopedAuthorization<D0Subject>; gunbc.spark.pair_serving_d0_door files the consent, waits, and dispatches under the admitted grant (the stub resolver is gone)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Cut 0: the V4.1 weight manifest and tokenizer files key the candidate; the row-store digest is the one fleet-side obligation left Cut 0 and the D0 authorization producer: the candidate keyed on the published manifests; the consent filed, decided and admitted at the door Sep 21, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69452 — both fixed at 12f0e556fc: one DeepseekV41PublishedFile record and one deepseek_v4_1_flash_published_manifest_text(rows) serve the shard and tokenizer lists; the manifest's rows 47/48 are derived from deepseek_v4_1_flash_engram_shard_1/_14 (the rows that own path, size and digest) rather than declared again, and the tree total is reconciled by a fold (deepseek_v4_1_flash_weight_manifest_agrees_with_tree) with a witness claim, not by prose.

— sent from proud-deer-538

… it is asked and a rerun re-derives the same request from it (no live subject, decision read as recorded), the claim is authorized and stamped at a fresh canonical instant probed after the gate, the weight manifest and tokenizer population are ADMITTED (exact shard cover both ways, index shard set, role cover; canonical text sorted by path) and the candidate consumes the admission never the raw rows, and the approval gate is one generic gunbc.auth.approval_gate that Mt. Collins and D0 both bind (review 69465; side chat source hold at 12f0e55)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69465 (the gate and the door's realization re-minted beside gunbc.machine_intake_mtcollins1_boot_authorization / _run): fixed at ffe688bef6. One generic gunbc.auth.approval_gate now carries ApprovalGate<Subject>, approval_gate_from_poll<Subject> (with a typed GateAdmission: AdmitLiveAt { observed_at } for a start, AdmitAsRecorded for a resume), approval_gate_text, the instant probe, the standing read, the bounded poll and the signed filing. Both MtCollins1BootGate/mtcollins1_boot_gate_from_poll/mtcollins1_boot_poll_ticks/mtcollins1_status_from_get/mtcollins1_boot_instant_from_probe/mtcollins1_approval_expires_at and the D0 copies are deleted; both callers rebind. The effectful reads are not generic (the language realizes no declaration carrying both type parameters and a uses row), so they take the escalation id and return the standing with its instant, and the subject enters only in the pure fold.

The same head carries the side chat's four source findings at 12f0e556fc: the filing is frozen on the fabric log before it is filed and a rerun re-derives the identical request from it (d0_freeze_filing / d0_filed_request; the decision is read as recorded so an expired grant can finish a started lifecycle, and d0_dispatch alone decides start vs resume); the claim is authorized and stamped at a fresh canonical Timestamp probed after the gate (RED: approval admitted, execute_by passed before the claim → no claim, no write); the weight manifest is admitted as an exact population (deepseek_v4_1_flash_admit_weight_manifest: every generated shard path once both ways, no foreign path, count, total, and the index's weight_map shard set — the index file is now a published row, sha256 74b0686a…; RED: a same-size duplicate replacing shard 4 refuses naming both defects); the canonical text is sorted by path (reorder-invariant), and the tokenizer side is admitted by role cover (vocabulary, configuration, special tokens embedded in tokenizer.json, prompt encoding = encoding/encoding.py, generation defaults = no separate file at the revision). v41_model_source consumes the two admissions, never the raw rows.

— sent from proud-deer-538

…ght identity; the tokenizer axis is keyed by the sorted role manifest (role, carrier arm, exact file identity / establishing revision / not-consumed), embedded roles join by exact identity and one path with two identities refuses; std.scoped_authorization refuses an instant before granted_at (AuthorizationObservedBeforeGrant) so a claim cannot predate the decision; the recorded approval is its own constructor (approval_recorded_from_poll) and D0 turns it into a resumable authorization only against a claim held by this transaction (d0_resumable_authorization; the door reads the claim before asking); stale citations in pair_serving_d0's header and the roadmap first-slice text repaired (review 69505)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69505: both citations repaired at 01f93a2f6f — the pair_serving_d0 header now names gunbc.spark.pair_serving_d0_authorization / gunbc.auth.approval_gate / gunbc.spark.pair_serving_d0_door and states the refusal that actually holds (an unkeyed candidate has no subject, so the door refuses before its first write); the roadmap first-slice item (3) no longer names resolve_d0_authorization and records what this PR lands and what remains (the row-store digest). ROADMAP.md does not project that field, so it is unchanged. The same head carries the side chat's round-2 findings (index in the weight identity, tokenizer role manifest as identity, the granted_at lower bound, the recorded approval split from the live gate and joined to D0's held claim); the PR body is rewritten to the current head.

— sent from proud-deer-538

…(ApprovalGateRefusal; ApprovalGate = GateAdmitted | GateRefused{cause}; RecordedApproval's negative arm and D0NotRecorded carry the cause, so a non-admitted outcome cannot hold an authorization by construction), one ApprovalReading feeds both the live and the recorded fold with no dead arm; the bounded poll decides on the standing it read before consulting the budget, so a decision read on the last tick is never reported as expiry (review 69509); a refused manifest population refuses the model source (V41ManifestRefused -> V41IdentityRefused) instead of posing as an obligation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69509 (the last poll tick discarded a standing it had read): fixed at 3401f4b957 — approval_poll_ticks now decides on the standing first and consults the budget only while it is still pending, so a decision read on the final tick is that decision, never ApprovalExpired. Same head: the gate's refusals moved to their own carrier (ApprovalGateRefusal; ApprovalGate = GateAdmitted | GateRefused { cause }), so ApprovalNotRecorded / D0NotRecorded structurally cannot hold an authorization (side chat round-3 hold), and a refused manifest population is V41ManifestRefused → V41IdentityRefused rather than an obligation.

— sent from proud-deer-538

…broker filed, not the caller's (approval_poll_standing), and the bounded poll makes its declared N waits with a terminal read; V41ManifestRefused carries its first defect by construction (first, rest); a refused row store refuses the Engram axis over a membership residual; D0SubjectRefused / D0RequestRefused keep defect and obligation apart through to the door; the index's weight_map shard set is a transcribed reading with a supplied-index RED on the join (review 69513); candidate and D0 propagation controls added

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69513 (the index join was green by construction): fixed at 0c0c7367e6. deepseek_v4_1_flash_index_reading.shard_paths is now deepseek_v4_1_flash_index_weight_map_shards, a transcription of the weight_map's distinct shard values read from the cited index file — not the generator the admission joins against — and the witness supplies a divergent index through deepseek_v4_1_flash_index_reading_of (47 shards; a 49th) with the same 48 files: each refuses on the index arm alone. The roadmap first-slice sentence now says what is established (the manifest reconciled against the index's read shard set; the index file and role manifest keyed) rather than 'the index is admitted'.

— sent from proud-deer-538

Brian Searls and others added 4 commits September 21, 2026 08:41
…ack; the boot authorization witness keeps main's medium claims over the shared approval gate)
…y's (observed_at < expires_at is live; equality is expired, for a pending filing and for filing anew); a spent waiting budget is PollBudgetExhausted, never an expiry -- only the timestamp fold mints PollExpired; the post-read decision is a pure seam (approval_poll_step) the wet recursion consumes, witnessed for a decision on the last tick, a spent budget, and an expiry read as read; the standing read has its own carrier (ApprovalStandingRead) so no arm is unreachable

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rier (an exact-head break no witness reached, since nothing imported the door); fixed, and the door's run-kind decision is now exercised by real execution -- unkeyed candidate refuses before freezing, a frozen filing makes the same call a rerun carrying the frozen request, another transaction's name refuses

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… standing read: not filed -> file the frozen request; pending -> enter the poll; decided -> the live gate at the read's instant; unreadable clock -> refuse) and witnessed at the D0 seam, so a carrier change cannot leave one of the door's two branches unmigrated

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 21, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review 69523: both dangling declarations gone at 0a9cbd9531 — approval_gate_text deleted (approval_refusal_text is the renderer both adopters consume); deepseek_v4_1_flash_shard_paths(count) is now the single production of the generated shard set and deepseek_v4_1_flash_admit_weight_manifest calls it.

— sent from proud-deer-538

@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Correction: #11918 is in the merge queue (position 9) at 62183e99f6, so the branch ref is locked and the deletions above did not land on it. They are held on plan/dsv41-cut-0-dangling (0a9cbd9531) and will follow as a small PR once this lands — both are pure deletions with no behavioral change.

— sent from proud-deer-538

Merged via the queue into main with commit dcd1552 Sep 21, 2026
4 checks passed
@briansrls
briansrls deleted the plan/dsv41-cut-0 branch September 21, 2026 10:54
@briansrls
briansrls restored the plan/dsv41-cut-0 branch September 21, 2026 10:59
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 21, 2026
6 tasks
gunbai-bot Bot pushed a commit that referenced this pull request Sep 21, 2026
…the microVM network mode; the mode roster and the dispatch-input witness keep both sides; fleet-converge.yml regenerated)
gunbai-bot Bot pushed a commit that referenced this pull request Sep 21, 2026
…tness body annotations)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 21, 2026
…ion revision froze in #11964, not #11918), the deploy dependency narrowed to writer-identity observation and D0 execution, and the #12005 unit-render blocker named beside the runner-principal one (side-chat hold)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant