Repository navigation
Record the microVM, floor and per-VM-memory state at wind-down - #11934
Merged
Merged
Conversation
Written on operator instruction to wind down and record remaining items, so that v1 performance and v2 migration can be prioritised. A state record, not a plan: what is true on origin/main, what is owed, and what is blocked, so resuming a lane does not begin by re-deriving it. One new file under docs/plans/. No code, no model changes, no generated artifacts. Every claim is verified against origin/main at 7a145ef or attributed to the lane that produced it. The floor's per-phase fail-open reading is marked CONTESTED, carrying both readings and the discriminating test that would settle it, rather than asserted in either direction (DESIGN 4d: an inference is typed as a bet, and the reader who consumes it as a fact is the defect). Corrects three premises of my own closeout instructions, each caught by the lane it misdescribed: both dynamic-memory branches COMPILE and run green (the uncompiled attempts are the two closed PRs), #11751 is in the merge queue rather than parked, and both parked PRs were non-draft. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both findings verified and both hold. TRANSCRIBED MEASUREMENTS (DESIGN 6). Every copied tally is replaced by the producer that re-derives it: the floor census now names the required floor invocation that prints its own summary line rather than quoting counts that move with every landed witness; the floor-fit figures name gunbc.runner_slot_allocation and gunbc.floor_memory_demand and send the reader to the stall row where the numbers sit beside the reading that produced them. Where a figure is a lane's reported reading rather than a re-derivable instrument -- the srv1 wet run, the two branch claim_batch results -- it is now ATTRIBUTED as a lane receipt of a past run, with the re-derivation named, instead of being stated as a standing fact. That distinction is the point: those are receipts, not facts a reader may refresh, and they are written so staleness is visible rather than plausible. UNLINKED PLAN (DESIGN 3c). The finding is correct and the page is an orphan. Rather than hand-add a gunbc.design_document row -- DESIGN.md is a projection, and editing that authority is not a wind-down act -- the page now names its consumer (the two re-entry briefs that cite it by path) and DECLARES the frontier with its trigger, which 3c admits. It also admits by name that it joins the population already rostered as doc_graph_orphan_population_stall rather than adding to it silently. Trigger: whichever funded lane resumes a program named here links this page from the section governing its work, or supersedes and deletes it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Operator instruction: wind down all work and store remaining items, so v1 performance and v2 migration can be prioritised.
One new file under
docs/plans/. No code, no model changes, no generated artifacts.Supersedes #11929, which accidentally carried two unrelated commits from the same session branch and went DIRTY as a result. This branch is cut from
origin/mainand contains the document only.Why a document rather than work items
Creating dashboard work items auto-spawns workers within ~30s, which is the opposite of winding down and of keeping host churn minimal — four spawns landed on parked nodes while I was closing them out, each re-running the same staleness grep.
docs/plans/is the sanctioned home, is durable, and is reviewable. Any section converts to a work item when the lane is funded again.What it records
witnesses.yml:67downgradesstructuraltononebecauseclaim_executorexits 0 over its own typed refusal. This admitted CENSUS-IMAGE 0A: one seeded-image derivation, a measured identity, and the census envelope grammar #11731's unparseable file rather than merely hiding it — the hollow gate is upstream of the breakage. The parse class is now closed (census 0, 412 witnesses executing), but the fail-open is unrepaired and unowned, and Fleet lane: the floor job runs the plain lane command, so a refused floor refuses the lane (it was green over FloorRefused) #11836/Required gate: bind the receipt's adjudicator, so a refused floor refuses the lane #11829 are competing repairs.runner_microvm_lifecycle_realizelanded (microVM wet lifecycle controller: MainPID realization + srv1 REDs #11803) carrying five declared frontiers, one of which is that nothing callsrun_controller. Every teardown quarantines by construction, so a warm pool is impossible until the slot-network frontier clears — and that one is blocked for a security reason (the converge principal is the job principal), not an engineering one.ExitType=cgroupresidual risk, the owed Repair the test -e absence probe in runner_host_file_converge (metadata failure read as absent) #11845 RED, two unowned one-line repairs, and five method findings.On contested and corrected claims
The per-phase reading of the fail-open is marked CONTESTED — one lane's reading against four run observations that contradict it — with the cheap discriminating test stated and neither version asserted.
It also corrects three premises of my own closeout instructions, each caught by the lane it misdescribed: both dynamic-memory branches compile and run green (the uncompiled attempts are the two closed PRs), #11751 is queued rather than parked, and both parked PRs were non-draft and consuming CI. Each would have misdirected whoever picked the work up.
🤖 Generated with Claude Code