diff --git a/dag/gunbc/roadmap/roadmap_authority.dag b/dag/gunbc/roadmap/roadmap_authority.dag index d6ec3b0fbb1..2343796f7e1 100644 --- a/dag/gunbc/roadmap/roadmap_authority.dag +++ b/dag/gunbc/roadmap/roadmap_authority.dag @@ -2836,7 +2836,7 @@ fn declared_roadmap_nodes() -> List { headline: "Cut D D0: suspend Group A under an exact operator consent, read the fleet inside it, settle to one typed terminal, and never free a host early", boundary: "gunbc.spark.pair_serving_d0 over gunbc.spark.pair_serving_authority_log on the fabric DB: one durable genesis per group partition, the host-placement partition as the linearization point, prepare -> append-claim -> authority -> finalize as one saga bound by a typed AuthorityWriteIntent, consumed/cancelled exclusivity, claim-bound quiescence evidence, total crash recovery by lifecycle identity, the operator consent slot as a fabric-DB head (gunbc.durable_cas_fabric_storage, generation-bearing objects), and a wet door that refuses while the store's write walls are missing. STATE (2026-09-20, wound down under operator direction to re-prioritize v1 performance and v2 migration): the whole stack is one branch, plan/dsv41-cut-d-2b, re-rooted onto the rewritten main and source-approved through twenty-one review rounds; the operator ruled it may land under the widened fabric-DB principal drop. Its stacked follow-up branch, plan/dsv41-cut-d-2b-admission-cleanup, deletes the twenty transition-admission rows the stack consumed and carries the detached-process wet-lane admission row.", displaced_cost: "Without D0 the V4.1 cut over Group A has no transaction: no consent that is spent exactly once across executors, no state in which the group is neither serving nor being mutated by two writers, and no receipt of the fleet as it was read before the authority moved -- the prior state, in which membership and placement were roster words and a crashed lane left no recoverable trace.", - first_slice: "LANDED ON THE BRANCH: the authority log and its folds, the saga and both joined reads, D0 recovery, the fabric-DB CAS, the quiescence observer, the front-door and head-host absence readings, 32 hermetic + 9 wet authority-log claims, 21 hermetic + 13 wet + 6 front-door D0 claims, 2 CAS wet claims, host-commitment and seat gates over the current authority. REMAINING, IN ORDER: (1) land plan/dsv41-cut-d-2b, then its admission-cleanup follow-up (operator merge). (2) The fabric-DB write walls: retire gunbc.rung_drop fabric_storage_append_principal_unrefused by its trigger (observed writer-principal roster in fabric_storage_serve) AND restore gunbc.spark.pair_serving_d0 d0_store_operation_wall (per-operation D0 authorization verified at the store) -- the wet door consumes both and refuses until both stand. (3) Cut 0 keys the V4.1 candidate: the weight manifest is admitted as an exact population reconciled against the index's read shard set, the index file and the tokenizer role manifest are keyed and the escalation -> ScopedAuthorization producer (gunbc.spark.pair_serving_d0_authorization, through gunbc.auth.approval_gate) and the wet door (gunbc.spark.pair_serving_d0_door) are landed by the Cut 0 pull request; the row-store content digest (a fleet read) is the one axis still unestablished, and only once it is keyed is a fleet run of D0 possible. (4) D1 converger: freeze the host population on PairServingActive (retires the one lane-roster dependence stated on authority_fold) and consume released_baseline_retains_reservation. (5) Retire the detached-process wet-lane row (gunbc.ci_layer_roots excl_local_repo_wet_detached_process_reason): a modeled process/listener fixture and mock_response seams for python.Interpreter.RunFile, the pgrep leg, http.Client.StatusWithin and /proc/net/tcp. (6) A v1 resolver defect found and reproduced on the way (a braced import of extdeps.http.client, or v2.std.algebra { filter }, makes the builtins split/last unresolvable inside a match-arm block; minimal fixture recorded on the branch's pull request, round 18) -- owned by the seed lane, avoided here by homing the curl exit codes with extdeps.tools.curl.", + first_slice: "MERGED 2026-09-21: #11555 (the authority log, the saga, D0 recovery, the fabric-DB CAS, the quiescence observer, the front-door and head-host absence readings; 32+9 authority-log claims, 21+13+6 D0 claims, 2 CAS wet claims, host-commitment and seat gates), #11918 (Cut 0's network-derivable axes: the weight manifest admitted as an exact population reconciled against the index's read shard set, the index file and the tokenizer role manifest keyed; one generic gunbc.auth.approval_gate that Mt. Collins and D0 bind; gunbc.spark.pair_serving_d0_authorization -- the exact intent and request frozen before filing, the recorded approval joined to the held claim, live versus recovery approval semantics -- and the wet door gunbc.spark.pair_serving_d0_door), #11936 (the writer-identity reading gunbc.fabric_writer_identity_observe takes through the served door's identity operation; the drop row split into served and local writer populations with a two-wall trigger and the user-not-node grain stated), #11964 (the door as fleet-converge mode pair_serving_d0: Group A by construction, srv1 proved before credentials, consent as the reusable transaction identity, the executing revision joined to the checkout and frozen as the final field of D0FrozenFiling with a mismatched-revision recovery refused, the srv1 host key shared with the pair-serving apply). REMAINING, IN ORDER: (1) srv1's fabric DB endpoint (#11723) and approval broker (#11667) are NOT LIVE: on the operator's go the RLM chain ran (plan 35614110881, apply 35616060173 at eb81d1869c) and dashboard_deploy refused as on 2026-09-17 -- live_deploy cannot observe the host as the runner principal (git dubious ownership at /opt/gunbc/gunbc; /home/briansrls unlistable); the operator ruled that the CONVERGENCE-ONE live_deploy lane repairs its observing principal; and a second blocker found on the operator-local route, the approval-broker unit itself could not render on main (ServiceType carried the retired string mode; PatternMatchFailure at the unit), which #12005 repairs. The terminal is: make the srv1 endpoint and broker live. The writer-identity observations (2) and every D0 fleet execution (4) wait on that; the row-store digest (3) and the source side of the later cuts may proceed, but nothing mutates Group A before those control-plane prerequisites and the two store walls stand. (2) Dispatch fabric_writer_identity_observe once per fleet host (srv1..srv4) and author the writer USER-principal roster and the served-door refusal from the receipts, plus principal admission on the placed host's local write path -- both halves retire gunbc.rung_drop fabric_storage_append_principal_unrefused -- and restore gunbc.spark.pair_serving_d0 d0_store_operation_wall (per-operation D0 authorization at the store); the door consumes both and refuses until both stand. (3) The published-shard row-store content digest (a fleet read on a Spark) keys the last candidate axis. (4) Dispatch pair_serving_d0 on srv1 with a consent id and expected_revision: D0 on Group A. (5) D1 converger: freeze the host population on PairServingActive and consume released_baseline_retains_reservation; then D1a and D2. (6) Retire the detached-process wet-lane row (gunbc.ci_layer_roots excl_local_repo_wet_detached_process_reason) and the v1 resolver defect (a braced import of extdeps.http.client or v2.std.algebra { filter } makes the builtins split/last unresolvable inside a match-arm block; fixture on #11555 round 18) -- seed lane. Hardening noted by review, not required: a source-level apply claim at the pair-serving apply's effect point so a direct invocation also linearizes against D0's transition.", red_control: "A stranger's abort of a prepared or claimed preparation refuses with nothing written; a cancelled preparation cannot be consumed and a consumed one cannot be cancelled; an authority event that is not the exact write its append claim named is unread on every join; a cycled CAS value does not let a stale writer advance at fabric_storage_advance; the wet door refuses while either store wall is missing; a 401/500 front door is an answer and a failed connect is absence only when the head host is quiet.", out_of_scope: "Cut 0 candidate keying and the authorization producer; the fabric-DB principal and per-operation walls (fabric-DB lane); D1 convergence; P1 Cut 3 held-seat invalidation; any fleet mutation before the walls stand.", handback: "Group A suspended under an exact consent with the fleet reading recorded on the log, settled to Suspended / restored Active / FencedRefusal, the consent spent once, every host fence released only by observed quiescence, and the placement finalized -- by execution against the fleet, which no branch has yet done.",