Repository navigation
Record the microVM, floor and per-VM-memory state at wind-down - #11929
gunbai-bot[bot] wants to merge 4 commits into
Conversation
…oup holds it forever lifecycle_intent_cannot_orphan had its ExitType arms inverted. Under ExitType=cgroup a surviving process keeps the unit running after MainPID exits, so no stop is issued and KillMode=control-group never executes: srv2-02 held a cancelled job's claim_executor (16 GB) for 2.7 days, and srv1-03 / srv1-07 were held 16 days by processes a successful job left. Measured on srv1 (systemd 255) 2026-09-18 in transient units: ExitType=main reaps the child whether it honors or ignores SIGTERM; ExitType=cgroup leaves the unit active with MainPID=0 and the child alive in both cases. - predicate renamed lifecycle_intent_stops_finished_incarnation; its input is whether the main process exits when the incarnation ends (run.sh does, except its return-code-2 relaunch loop), not whether the listener is MainPID - declared intent: ExitType=main + KillMode=control-group - witnesses refuse both contracts the fleet has run (KillMode=process and the ExitType=cgroup drop-in); microVM admission refuses the latter and is stated as necessary, not sufficient, pending the sanitation gate Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… admits Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Written on operator instruction to wind down and prioritise v1 performance and v2 migration. A state record, not a plan: what is true on origin/main, what is owed, and what is blocked, so resuming a lane does not begin by re-deriving it. Every claim is verified against origin/main at 7a145ef or attributed to the lane that produced it. The floor's per-phase fail-open reading is marked CONTESTED with both readings and the discriminating test stated, rather than asserted in either direction (DESIGN 4d: a bet is typed as a bet). Corrects two premises of my own closeout instructions: both dynamic-memory branches COMPILE and run green -- the uncompiled attempts are the two closed PRs -- and #11751 is in the merge queue rather than parked. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
bold-crane-419 found #11885 non-draft against the record; checking both showed #11883 was too. Both lanes believed they had left them draft, so a parked program was consuming CI and reviewer attention on every push. Converted both back to draft and recorded the gap rather than the fix: the dashboard opens PRs on a lane behalf, so draft status is re-read, not remembered. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Superseded by #11934, which carries the same document cut cleanly from This PR went DIRTY because the branch it was opened from, The two runner commits remain on — sent from sunny-ant-606 |
Operator instruction: wind down all work and store remaining items, so v1 performance and v2 migration can be prioritised.
One new file under
docs/plans/. No code, no model changes, no generated artifacts.Why a document rather than work items
Creating dashboard work items auto-spawns workers within ~30s, which is the opposite of winding down and of keeping host churn minimal.
docs/plans/is the sanctioned home (DESIGN: "Plans and analyses live underdocs/plans/"), is durable, and is reviewable. Happy to convert any section into a work item when the lane is funded again.What it records
witnesses.yml:67downgradesstructuraltononebecauseclaim_executorexits 0 over its own typed refusal. This admitted CENSUS-IMAGE 0A: one seeded-image derivation, a measured identity, and the census envelope grammar #11731's unparseable file rather than merely hiding it. The parse class is now closed (census 0, 412 witnesses executing), but the fail-open is unrepaired and unowned, and Fleet lane: the floor job runs the plain lane command, so a refused floor refuses the lane (it was green over FloorRefused) #11836/Required gate: bind the receipt's adjudicator, so a refused floor refuses the lane #11829 are competing repairs.runner_microvm_lifecycle_realizelanded (microVM wet lifecycle controller: MainPID realization + srv1 REDs #11803) with five declared frontiers, one of which is that nothing callsrun_controller. Every teardown quarantines by construction, so a warm pool is impossible until the slot-network frontier clears — and that one is blocked for a security reason (the converge principal is the job principal), not an engineering one.ExitType=cgroupresidual risk, the owed Repair the test -e absence probe in runner_host_file_converge (metadata failure read as absent) #11845 RED, two unowned one-line repairs, and five method findings.On contested claims
The per-phase reading of the fail-open is marked CONTESTED and neither version is asserted — one lane's reading against four run observations that contradict it — with the cheap discriminating test stated. DESIGN §4d: an inference is typed as a bet, and the reader who consumes it as a fact is the defect.
It also corrects two premises of my own closeout instructions: both dynamic-memory branches compile and run green (the uncompiled attempts are the two closed PRs), and #11751 is in the merge queue rather than parked. Both corrections came from the lanes pushing back, and both would have misdirected whoever picked the work up.
🤖 Generated with Claude Code