Repository navigation
Cut 0 and the D0 authorization producer: the candidate keyed on the published manifests; the consent filed, decided and admitted at the door - #11918
Conversation
…e plan/dsv41-cut-d-2b delta re-applied over main@5f4202a5c6 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…r_memory_demand, r2_permission_group_observe, namespace_reference_derived_residency_qualification): a source annotation inside a declaration body refuses to parse and reds every floor run Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion wall was deleted by operator ruling 2026-09-19 (gunbc.rung_drop namespace_wave_admission_wall_removed) and a row file in the tree now refuses to resolve Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # ROADMAP.md
…t_capture_historical_binding and runner_microvm_boot_probe to module grain (they refuse to parse and red every floor run) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…test to module grain
…left in chunk_20 (expected expression, found Newline; reds every floor run) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused Heal-Candidate-Run: 35538018867
…ot quiet (OccupancyNotQuiet names every live rank; never dropped into a drifted population); PlacementCleanupUnread replaces the minted "unknown" preparation id and D0 carries preparation: none; the repair binds the consumption it acts on once; one read budget on gunbc.fabric_event_log; the misnamed HostEffectClaimed.generation deleted Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # ROADMAP.md
# Conflicts: # ROADMAP.md # dag/gunbc/target_binding.dag
… at dba1be0a, from the Hub tree API) and the tokenizer files are declared in extdeps.deepseek.deepseek_v4_1_flash and key the candidate's weights and tokenizer axes by the digest of their canonical text; the row-store digest remains the one fleet-side obligation Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # ROADMAP.md # docs/design-rung-drops.md
…ecord for shards and tokenizer files with one canonical text; the manifest's Engram rows derive from their owners and the total reconciles by fold (review 69452); gunbc.spark.pair_serving_d0_authorization builds the request over the keyed successor and turns the operator's approval poll into ScopedAuthorization<D0Subject>; gunbc.spark.pair_serving_d0_door files the consent, waits, and dispatches under the admitted grant (the stub resolver is gone) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69452 — both fixed at — sent from proud-deer-538 |
… it is asked and a rerun re-derives the same request from it (no live subject, decision read as recorded), the claim is authorized and stamped at a fresh canonical instant probed after the gate, the weight manifest and tokenizer population are ADMITTED (exact shard cover both ways, index shard set, role cover; canonical text sorted by path) and the candidate consumes the admission never the raw rows, and the approval gate is one generic gunbc.auth.approval_gate that Mt. Collins and D0 both bind (review 69465; side chat source hold at 12f0e55) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69465 (the gate and the door's realization re-minted beside The same head carries the side chat's four source findings at — sent from proud-deer-538 |
…ght identity; the tokenizer axis is keyed by the sorted role manifest (role, carrier arm, exact file identity / establishing revision / not-consumed), embedded roles join by exact identity and one path with two identities refuses; std.scoped_authorization refuses an instant before granted_at (AuthorizationObservedBeforeGrant) so a claim cannot predate the decision; the recorded approval is its own constructor (approval_recorded_from_poll) and D0 turns it into a resumable authorization only against a claim held by this transaction (d0_resumable_authorization; the door reads the claim before asking); stale citations in pair_serving_d0's header and the roadmap first-slice text repaired (review 69505) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69505: both citations repaired at — sent from proud-deer-538 |
…(ApprovalGateRefusal; ApprovalGate = GateAdmitted | GateRefused{cause}; RecordedApproval's negative arm and D0NotRecorded carry the cause, so a non-admitted outcome cannot hold an authorization by construction), one ApprovalReading feeds both the live and the recorded fold with no dead arm; the bounded poll decides on the standing it read before consulting the budget, so a decision read on the last tick is never reported as expiry (review 69509); a refused manifest population refuses the model source (V41ManifestRefused -> V41IdentityRefused) instead of posing as an obligation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69509 (the last poll tick discarded a standing it had read): fixed at — sent from proud-deer-538 |
…broker filed, not the caller's (approval_poll_standing), and the bounded poll makes its declared N waits with a terminal read; V41ManifestRefused carries its first defect by construction (first, rest); a refused row store refuses the Engram axis over a membership residual; D0SubjectRefused / D0RequestRefused keep defect and obligation apart through to the door; the index's weight_map shard set is a transcribed reading with a supplied-index RED on the join (review 69513); candidate and D0 propagation controls added Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69513 (the index join was green by construction): fixed at — sent from proud-deer-538 |
…ack; the boot authorization witness keeps main's medium claims over the shared approval gate)
…y's (observed_at < expires_at is live; equality is expired, for a pending filing and for filing anew); a spent waiting budget is PollBudgetExhausted, never an expiry -- only the timestamp fold mints PollExpired; the post-read decision is a pure seam (approval_poll_step) the wet recursion consumes, witnessed for a decision on the last tick, a spent budget, and an expiry read as read; the standing read has its own carrier (ApprovalStandingRead) so no arm is unreachable Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rier (an exact-head break no witness reached, since nothing imported the door); fixed, and the door's run-kind decision is now exercised by real execution -- unkeyed candidate refuses before freezing, a frozen filing makes the same call a rerun carrying the frozen request, another transaction's name refuses Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… standing read: not filed -> file the frozen request; pending -> enter the poll; decided -> the live gate at the read's instant; unreadable clock -> refuse) and witnessed at the D0 seam, so a carrier change cannot leave one of the door's two branches unmigrated Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69523: both dangling declarations gone at — sent from proud-deer-538 |
|
Correction: #11918 is in the merge queue (position 9) at — sent from proud-deer-538 |
…the microVM network mode; the mode roster and the dispatch-input witness keep both sides; fleet-converge.yml regenerated)
…tness body annotations) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Cut 0 keys the V4.1 candidate's model-source axes from the publisher's declared facts at
dba1be0a, and lands the escalation → authorization producer and the wet door D0 was blocked on. No host is touched; the row-store content digest (a fleet read) is the one axis still unestablished, so the live candidate staysV41CandidateUnestablishedon this head by design.Model source (
extdeps.deepseek.deepseek_v4_1_flash,gunbc.spark.v41_runtime_candidate)DeepseekV41PublishedFile { path, file_bytes, sha256 }: one record for every file the candidate is keyed by. The 46 backbone shard rows are declared from the Hub tree API; the two Engram shard rows derive fromdeepseek_v4_1_flash_engram_shard_1/_14, which own them.deepseek_v4_1_flash_admit_weight_manifest: every generatedmodel-NNNNN-of-00048path present exactly once (identity join both ways), no foreign path, the declared count, the sizes summed against the tree total, and the index's weight_map shard set equal to the file set.model.safetensors.index.jsonis a published row (7470294 B, sha25674b0686a…) and is a row in the admitted canonical text, so an index change is a different model source over the same shards. RED: shard 4 replaced by a duplicate of shard 3 (same size, count and total unchanged) refuses naming both defects.DeepseekV41TokenizerRole×DeepseekV41RoleCarrier): vocabulary = tokenizer.json, configuration = tokenizer_config.json, special tokens embedded in tokenizer.json, prompt encoding =encoding/encoding.py(published file, sha256502bdaec…— there is no Jinja template), generation defaults = no separate file at the revision. The axis is keyed by the sorted role manifest (role, carrier arm, exact file identity / establishing revision / not-consumed), not by the file set: moving special tokens to not-consumed or re-establishing a no-file fact at another revision changes the key with the files unchanged; an embedded role joins by exact identity; one path with two identities refuses; a role without a carrier refuses.v41_model_sourceconsumes the two admissions and never the raw rows: a defective population is a REFUSED source naming its defects (never an obligation, never a differently keyed one); missing evidence is an obligation. The index's weight_map shard set is a transcribed reading joined against the files, with a supplied-index RED.Authorization (
gunbc.auth.approval_gate,gunbc.spark.pair_serving_d0_authorization,gunbc.spark.pair_serving_d0_door)gunbc.auth.approval_gate(review 69465):ApprovalGate<Subject>,approval_gate_from_poll(live, authorized at the observed instant), the instant probe, the standing read, the bounded poll (each tick admits at the instant of that read), the signed filing.gunbc.machine_intake_mtcollins1_boot_run/_authorizationrebind to it; their copies and D0's are deleted. The effectful reads are not generic (no declaration may carry both type parameters and ausesrow), so they take the escalation id and return the standing with its instant.approval_recorded_from_poll→RecordedApproval<Subject>), neverGateAdmitted; D0 turns it into a resumable authorization only against a claim held by this transaction (d0_resumable_authorization), so "historically approved" and "admitted to begin" cannot inhabit one arm.std.scoped_authorizationnow refuses an instant beforegranted_at(AuthorizationObservedBeforeGrant) as well as afterexpires_at: a claim cannot predate the decision it consumes.pair_serving_d0 d0_freeze_filing, gen 1 /ExpectSlotAbsent, the intent text = the bytes the intent hash is over). A rerun re-derives the identical request from it (d0_filed_request; another transaction under the escalation refuses) with no live subject consulted, reads the durable claim, and: held by this transaction → recorded approval →d0_dispatchresumes under the consent that began the lifecycle, expired or not; absent → the standing is polled and admitted live as a first run's (not filed: the frozen request is filed now); any other holder → refuses.d0_dispatchalone decides start vs resume (Cut D PR 2b: D0 — atomic transfer into suspension, ordered readings inside it, settled authority under a lease #11555's recovery law is preserved).nowisTimestampthrough the D0 signatures.d0_live_subjectexists iff the candidate is keyed; the request carries the exact intent; the door checks both fabric-storage write walls before filing anything; the stub resolver is deleted.Witnesses (all pass locally; CI green on the previous head, running on this one)
deepseek authority (manifest admission + REDs; tokenizer role manifest identity + REDs), v41 candidate, D0 authorization (frozen intent round trip; recorded approval resumable only under this transaction's held claim), D0 real execution (+ filing frozen once and read back without a live subject; + a grant whose window has not opened or has closed takes no claim), Mt Collins authorization/run rebound to the shared gate.
Out of scope, in order (roadmap node
serving-v41-cut-d-d0-transaction)Row-store digest (fleet read); the two fabric-storage write walls (#11936 takes the writer-identity reading the roster needs); the D0 door as a fleet-converge mode; D0 on Group A; D1.
🤖 Generated with Claude Code