Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions dag/gunbc/ci/ci_diff_policy.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
module gunbc.ci_diff_policy

import std.types { String }
import gunbc.repo_identity { gunbc_merge_target_ref }

// THE CI DIFF POLICY IS ITS OWN MODULE BECAUSE ITS CONSUMERS NEED IT AND NOTHING ELSE. Closure is
// module-grain: a module that reaches one field of gunbc.ci_spec gunbc_ci_spec reaches all of
// gunbc.ci_spec, and through it the gate roster, the deploy stages and everything they import.
// The floor's diff observer (v2.workflow.floor_diff_observe) asks only which base, which head and
// which range form -- and, reaching it through the CI spec, resolved and typechecked most of the
// corpus, which the process resolve store then held for the whole floor beside the floor's own
// prepared subject. The size of that closure is read from the required floor's [floor-heap] seam
// census (shared_index parse/typed counts at diff-base-decl-census), not from this comment. The policy is one fact with
// one home here; gunbc.ci_spec carries it by reference in CiSpec.diff_policy, never a second copy.

type DiffMode = DiffMergeBase | DiffTwoDot

type DiffPolicy {
base: String
head: String
mode: DiffMode
}

data gunbc_ci_diff_policy: DiffPolicy = {
base: gunbc_merge_target_ref as String,
head: "HEAD",
mode: DiffMergeBase
}
16 changes: 2 additions & 14 deletions dag/gunbc/ci/ci_spec.dag
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ import gunbc.commit_workflow {
project_ci_floor_witness_entries
}
import std.realization_schedule { ScheduleWitnessEntry }
import gunbc.repo_identity { gunbc_merge_target_ref }
import gunbc.ci_diff_policy { DiffMergeBase, DiffTwoDot, DiffPolicy, gunbc_ci_diff_policy }
import gunbc.auth.heal_publisher_federation {
heal_publisher_installation_token_request_body,
heal_publisher_key_unreadable_message,
Expand Down Expand Up @@ -140,8 +140,6 @@ import v2.std.diagnostic { EmitDirective, SeverityWarning }
import std.disposition { Disposition, Scaffold, SingleAuthority }
import std.decl_ref { DeclarationRef, WholeDeclaration }

type DiffMode = DiffMergeBase | DiffTwoDot

type FloorBatchStopPolicy = StopBeforeDependents | FullLedger

type RuntimeUnitCount = RuntimeUnitCountObserved { units: Nat } | RuntimeUnitCountUnavailable { cause: String }
Expand Down Expand Up @@ -247,12 +245,6 @@ data gunbc_ci_floor_batch_stop_policy_claim_executor_seed_disposition: Dispositi
}
}

type DiffPolicy {
base: String
head: String
mode: DiffMode
}

type DeployStage {
id: String
step_name: String
Expand Down Expand Up @@ -321,11 +313,7 @@ data gunbc_ci_spec: CiSpec = {
gates: gunbc_ci_floor_gates,
witness_entries: gunbc_ci_floor_witness_entries,
discovery_scan_dirs: witness_discovery_scan_dirs,
diff_policy: {
base: gunbc_merge_target_ref as String,
head: "HEAD",
mode: DiffMergeBase
},
diff_policy: gunbc_ci_diff_policy,
notice_title: "v2 claim corpus",
deploy_stages: gunbc_ci_deploy_stages,
}
Expand Down
8 changes: 5 additions & 3 deletions dag/gunbc/floor/floor_cgroup_stat_beat_seed_growth.dag
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,12 @@ import std.decl_ref { DeclarationRef, WholeDeclaration }
data floor_cgroup_stat_beat_seed_growth_justification: SeedGrowthJustification = SeedGrowthJustification {
hand_authored_declarations: [
DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "floor_cgroup_stat_beat", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "floor_seam_current", field: WholeDeclaration }
DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "floor_seam_current", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "floor_heap_beat", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "process_resolve_census", field: WholeDeclaration }
],
reason: "WHY RUST IS STILL NEEDED: the required floor executes in the seed, and the leaf cgroup's memory.stat is readable only by the process running inside it -- the host slot's slice -- at the moment the floor is at its peak. gunbc.floor_demand owns the receipt vocabulary (FloorHeldSetReceipt: raw FloorMemoryStatBeat rows, from which beat_held_set derives a resident held-set lower bound by a stated non-overlapping rule); this function is the reader that produces the lines those raw beats are transcribed from, one file read per heartbeat, every counter printed as read or as na, in one flat list with no grouping -- memory.stat is not a partition and grouping would already be a derivation, which has one home.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program. The required floor is the instrument guarding that program and the srvN microVM cutover sizes the guest that will run it; memory.peak charges reclaimable cache and is therefore a ceiling rather than a demand, so memory.stat's counters are the measurement to take. This adds the reading and nothing else: no language behavior, compatibility route, escape hatch, seed feature, or emitted public surface. It is not a HeartbeatSample field because HeartbeatSample is the modeled per-beat record with a rendered mirror, and growing it here would have put a new modeled row on the critical path of a sizing question; the emit lands under the already-censused [floor-cgroup] tag beside floor_cgroup_envelope, whose row in gunbc.observation_emit_census names the migration trigger for both.\n\nTHE SEAM READER, ADDED 2026-09-21, IS THE SECOND HAND ITEM AND IT EXISTS FOR ONE REASON: the beat and the seam it was sampled in were two separate stderr streams joined only by the order the lines happened to appear in. That is a positional citation (DESIGN 3) -- any line emitted between them by another thread invalidates it silently, and the reader transcribing a receipt is the one who guesses. floor_seam writes the process-global seam slot and the heartbeat has always read it for its human line; floor_seam_current is the same read for the stat line, so gunbc.floor_demand FloorMemoryStatBeat can carry a typed FloorSeam and receipt_peak_seam can DERIVE which phase established the peak instead of a transcriber reading it off a log. It adds no new observation and no new file read -- it reads a slot the process already maintains.\n\nTHE STALL CLAUSE MOVED ONTO THE SAME LINE IN THE SAME CHANGE, because it had the identical defect: the stall is the heartbeat's quantity and was readable only from the heartbeat line printed BESIDE the beat, so FloorMemoryStatBeat.stall was transcribed by adjacency like the seam. That field is not decorative -- receipt_last_unstalled_beat derives gunbc.runner_microvm gunbc_runner_microvm_guest_cache_allowance from it, so a mis-joined stall mis-sizes a guest. Fixing the seam and leaving the stall would have been a half-repair of one class, so the beat line now carries seam, stall and counters together and is self-contained: no reader of it joins anything by position.\n\nHAND-ITEM DELTA: +2, exactly the two readers enumerated above; the call sites in floor-entry and the heartbeat loop are edits inside existing declarations and are ExistingSeedItemModified.\n\nHAND-LOC DELTA AT THIS RECEIPT, which is a figure about a LANDED change and therefore cannot rot the way an in-flight one does: src/v1/stage0/src/cli_run/required_floor_runner.rs +56 and src/v1/stage0/src/cli_run.rs +3 against the origin/main of that receipt. The item observation producer is currently absent, so these diff-derived figures remain review evidence rather than a mechanically joined admission.\n\nTHE 2026-09-21 SEAM READER'S LOC DELTA IS NOT TRANSCRIBED HERE, AND THE REASON IS A RECEIPT. An earlier revision of this row carried it as +25 -1 on required_floor_runner.rs with cli_run.rs stated as unchanged. Both figures then ROTTED INSIDE THE SAME BRANCH: bracketing the seam read around the procfs sample, and routing the heartbeat through the shared reader, moved them without anyone touching this row. A hand-written count of a diff that is still being written is a transcription with no producer to re-derive it (DESIGN 6), and this row already says the item observation producer is absent -- so the count is the first thing that goes stale and the last thing anyone rechecks. The delta is read from the diff by whoever adjudicates the hand-item admission, at the head they are adjudicating; when the item observation producer lands, it states the figure and this paragraph goes with it.",
reason: "WHY RUST IS STILL NEEDED: the required floor executes in the seed, and the leaf cgroup's memory.stat is readable only by the process running inside it -- the host slot's slice -- at the moment the floor is at its peak. gunbc.floor_demand owns the receipt vocabulary (FloorHeldSetReceipt: raw FloorMemoryStatBeat rows, from which beat_held_set derives a resident held-set lower bound by a stated non-overlapping rule); this function is the reader that produces the lines those raw beats are transcribed from, one file read per heartbeat, every counter printed as read or as na, in one flat list with no grouping -- memory.stat is not a partition and grouping would already be a derivation, which has one home.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program. The required floor is the instrument guarding that program and the srvN microVM cutover sizes the guest that will run it; memory.peak charges reclaimable cache and is therefore a ceiling rather than a demand, so memory.stat's counters are the measurement to take. This adds the reading and nothing else: no language behavior, compatibility route, escape hatch, seed feature, or emitted public surface. It is not a HeartbeatSample field because HeartbeatSample is the modeled per-beat record with a rendered mirror, and growing it here would have put a new modeled row on the critical path of a sizing question; the emit lands under the already-censused [floor-cgroup] tag beside floor_cgroup_envelope, whose row in gunbc.observation_emit_census names the migration trigger for both.\n\nTHE SEAM READER, ADDED 2026-09-21, IS THE SECOND HAND ITEM AND IT EXISTS FOR ONE REASON: the beat and the seam it was sampled in were two separate stderr streams joined only by the order the lines happened to appear in. That is a positional citation (DESIGN 3) -- any line emitted between them by another thread invalidates it silently, and the reader transcribing a receipt is the one who guesses. floor_seam writes the process-global seam slot and the heartbeat has always read it for its human line; floor_seam_current is the same read for the stat line, so gunbc.floor_demand FloorMemoryStatBeat can carry a typed FloorSeam and receipt_peak_seam can DERIVE which phase established the peak instead of a transcriber reading it off a log. It adds no new observation and no new file read -- it reads a slot the process already maintains.\n\nTHE STALL CLAUSE MOVED ONTO THE SAME LINE IN THE SAME CHANGE, because it had the identical defect: the stall is the heartbeat's quantity and was readable only from the heartbeat line printed BESIDE the beat, so FloorMemoryStatBeat.stall was transcribed by adjacency like the seam. That field is not decorative -- receipt_last_unstalled_beat derives gunbc.runner_microvm gunbc_runner_microvm_guest_cache_allowance from it, so a mis-joined stall mis-sizes a guest. Fixing the seam and leaving the stall would have been a half-repair of one class, so the beat line now carries seam, stall and counters together and is self-contained: no reader of it joins anything by position.\n\nHAND-ITEM DELTA: +2, exactly the two readers enumerated above; the call sites in floor-entry and the heartbeat loop are edits inside existing declarations and are ExistingSeedItemModified.\n\nHAND-LOC DELTA AT THIS RECEIPT, which is a figure about a LANDED change and therefore cannot rot the way an in-flight one does: src/v1/stage0/src/cli_run/required_floor_runner.rs +56 and src/v1/stage0/src/cli_run.rs +3 against the origin/main of that receipt. The item observation producer is currently absent, so these diff-derived figures remain review evidence rather than a mechanically joined admission.\n\nTHE 2026-09-21 SEAM READER'S LOC DELTA IS NOT TRANSCRIBED HERE, AND THE REASON IS A RECEIPT. An earlier revision of this row carried it as +25 -1 on required_floor_runner.rs with cli_run.rs stated as unchanged. Both figures then ROTTED INSIDE THE SAME BRANCH: bracketing the seam read around the procfs sample, and routing the heartbeat through the shared reader, moved them without anyone touching this row. A hand-written count of a diff that is still being written is a transcription with no producer to re-derive it (DESIGN 6), and this row already says the item observation producer is absent -- so the count is the first thing that goes stale and the last thing anyone rechecks. The delta is read from the diff by whoever adjudicates the hand-item admission, at the head they are adjudicating; when the item observation producer lands, it states the figure and this paragraph goes with it.\n\nEXTENSION FOR PHASE ATTRIBUTION (2026-09-22, work item floor memory attribution baseline): the seam on the beat line says which phase a watchdog minute was in, never where a phase began or ended, and the 2026-09-19 receipt is censored on swap because the swap figure beside the leaf was the HOST's. So v1_compiler.cli_run floor_seam now emits one beat at every phase boundary, with seams added inside strict-preparation (changed-witness-planning, prepare-closure-resolve, prepared-subject-warm), at publication, and in claim_executor at parse, declarations and floor-entry; and the reader prints a second line per beat carrying a wall clock, the leaf's own memory.swap.current, memory.events.local (oom, oom_kill), memory.pressure (PSI), and the leaf's cgroup.procs as pid:comm:VmRSS -- all raw, nothing summed. That is the same reading at a finer grain plus a second subject (the processes charged to the leaf, which separates overlap from retained state); it adds no language behavior, route, or emitted surface. The first run carrying it (floor job 106950715986) showed the floor process entering with its resident set already high and growing most across the planning window before resolve, with no other process of size in the leaf; RSS cannot say whether that is state still owned or memory glibc freed and kept, so floor_heap_beat prints glibc mallinfo2's in-use and free bytes at every seam -- a read, unlike malloc_trim, which would return the free half and change the heap being measured -- and seams split the planning window (nominal-subject-seeds, arm-set-planning) and mark lane-roster before parse. The second run (floor job 106963145694) put the growth in LIVE heap, not allocator-held free, in two early steps whose results are small -- the lane-roster evaluation, which resolves through the process-lifetime shared index and resolve store, and the diff projections -- so the heap line also carries process_resolve_census (the store's entry count and each shared-index slot's parse, typed-module and resolved-graph memo counts, read-only), and seams split the diff projections (diff-base-decl-census, diff-edits, diff-changed-witness-identities, diff-touched-module-seeds). HAND-ITEM DELTA: +2, floor_heap_beat and process_resolve_census; the rest are edits inside floor_cgroup_stat_beat, floor_seam, run_required_floor and changed_and_enrolled_witness_identities_with_index, and floor_seam gains a pub re-export. Its trigger is this row's: the allocator split becomes a Measured arm of the same per-beat observation. HAND-LOC DELTA: read it from this change's own diff against its base rather than from a figure transcribed here.",
owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId,
trigger: "Delete the seed reader when the raw memory.stat counters become Measured arms of gunbc.observation_ci_render's per-beat sample and is rendered by that record's seed mirror, so the [floor-cgroup] stat line is a projection of the observation model rather than a hand-formatted eprintln -- the same migration gunbc.observation_emit_census floor_heartbeat_site records for the heartbeat itself.",
trigger: "Delete the seed reader when the raw memory.stat counters, and the leaf readings printed on the second beat line (memory.swap.current, memory.events.local, memory.pressure, and cgroup.procs as pid:comm:VmRSS) and the [floor-heap] allocator split, all become Measured arms of gunbc.observation_ci_render's per-beat sample and are rendered by that record's seed mirror, so both [floor-cgroup] beat lines are a projection of the observation model rather than a hand-formatted eprintln -- the same migration gunbc.observation_emit_census floor_heartbeat_site records for the heartbeat itself.",
current_boundary: "leaf cgroup memory.stat -> v1_compiler.cli_run floor_cgroup_stat_beat -> [floor-cgroup] stat_level= seam= stall_per_min= memory_stat= line in the required-witnesses-floor job log -> gunbc.floor_demand FloorHeldSetReceipt raw beats (transcribed by a reader of that log) -> beat_held_set"
}
Loading