Skip to content

DS4.1 - #11957

Closed
briansrls wants to merge 25 commits into
mainfrom
plan/dsv41-cut-0
Closed

DS4.1#11957
briansrls wants to merge 25 commits into
mainfrom
plan/dsv41-cut-0

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session proud-deer-538.
Pushing to plan/dsv41-cut-0 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 25 commits September 20, 2026 17:30
…e plan/dsv41-cut-d-2b delta re-applied over main@5f4202a5c6

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…r_memory_demand, r2_permission_group_observe, namespace_reference_derived_residency_qualification): a source annotation inside a declaration body refuses to parse and reds every floor run

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion wall was deleted by operator ruling 2026-09-19 (gunbc.rung_drop namespace_wave_admission_wall_removed) and a row file in the tree now refuses to resolve

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t_capture_historical_binding and runner_microvm_boot_probe to module grain (they refuse to parse and red every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…left in chunk_20 (expected expression, found Newline; reds every floor run)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md fabric_storage_append_principal_unrefused
Heal-Candidate-Run: 35538018867
…ot quiet (OccupancyNotQuiet names every live rank; never dropped into a drifted population); PlacementCleanupUnread replaces the minted "unknown" preparation id and D0 carries preparation: none; the repair binds the consumption it acts on once; one read budget on gunbc.fabric_event_log; the misnamed HostEffectClaimed.generation deleted

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	ROADMAP.md
#	dag/gunbc/target_binding.dag
… at dba1be0a, from the Hub tree API) and the tokenizer files are declared in extdeps.deepseek.deepseek_v4_1_flash and key the candidate's weights and tokenizer axes by the digest of their canonical text; the row-store digest remains the one fleet-side obligation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	ROADMAP.md
#	docs/design-rung-drops.md
…ecord for shards and tokenizer files with one canonical text; the manifest's Engram rows derive from their owners and the total reconciles by fold (review 69452); gunbc.spark.pair_serving_d0_authorization builds the request over the keyed successor and turns the operator's approval poll into ScopedAuthorization<D0Subject>; gunbc.spark.pair_serving_d0_door files the consent, waits, and dispatches under the admitted grant (the stub resolver is gone)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… it is asked and a rerun re-derives the same request from it (no live subject, decision read as recorded), the claim is authorized and stamped at a fresh canonical instant probed after the gate, the weight manifest and tokenizer population are ADMITTED (exact shard cover both ways, index shard set, role cover; canonical text sorted by path) and the candidate consumes the admission never the raw rows, and the approval gate is one generic gunbc.auth.approval_gate that Mt. Collins and D0 both bind (review 69465; side chat source hold at 12f0e55)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ght identity; the tokenizer axis is keyed by the sorted role manifest (role, carrier arm, exact file identity / establishing revision / not-consumed), embedded roles join by exact identity and one path with two identities refuses; std.scoped_authorization refuses an instant before granted_at (AuthorizationObservedBeforeGrant) so a claim cannot predate the decision; the recorded approval is its own constructor (approval_recorded_from_poll) and D0 turns it into a resumable authorization only against a claim held by this transaction (d0_resumable_authorization; the door reads the claim before asking); stale citations in pair_serving_d0's header and the roadmap first-slice text repaired (review 69505)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…(ApprovalGateRefusal; ApprovalGate = GateAdmitted | GateRefused{cause}; RecordedApproval's negative arm and D0NotRecorded carry the cause, so a non-admitted outcome cannot hold an authorization by construction), one ApprovalReading feeds both the live and the recorded fold with no dead arm; the bounded poll decides on the standing it read before consulting the budget, so a decision read on the last tick is never reported as expiry (review 69509); a refused manifest population refuses the model source (V41ManifestRefused -> V41IdentityRefused) instead of posing as an obligation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…broker filed, not the caller's (approval_poll_standing), and the bounded poll makes its declared N waits with a terminal read; V41ManifestRefused carries its first defect by construction (first, rest); a refused row store refuses the Engram axis over a membership residual; D0SubjectRefused / D0RequestRefused keep defect and obligation apart through to the door; the index's weight_map shard set is a transcribed reading with a supplied-index RED on the join (review 69513); candidate and D0 propagation controls added

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ack; the boot authorization witness keeps main's medium claims over the shared approval gate)
…y's (observed_at < expires_at is live; equality is expired, for a pending filing and for filing anew); a spent waiting budget is PollBudgetExhausted, never an expiry -- only the timestamp fold mints PollExpired; the post-read decision is a pure seam (approval_poll_step) the wet recursion consumes, witnessed for a decision on the last tick, a spent budget, and an expiry read as read; the standing read has its own carrier (ApprovalStandingRead) so no arm is unreachable

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rier (an exact-head break no witness reached, since nothing imported the door); fixed, and the door's run-kind decision is now exercised by real execution -- unkeyed candidate refuses before freezing, a frozen filing makes the same call a rerun carrying the frozen request, another transaction's name refuses

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… standing read: not filed -> file the frozen request; pending -> enter the poll; decided -> the live gate at the read's instant; unreadable clock -> refuse) and witnessed at the D0 seam, so a carrier change cannot leave one of the door's two branches unmigrated

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Auto-opened for plan/dsv41-cut-0 after that branch landed as #11918 (squash); nothing here is unmerged. — sent from proud-deer-538

@gunbai-bot gunbai-bot Bot closed this Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant