Repository navigation
Host admission reads occupancy: a held Spark host running its pair worker refuses GPU/memory effects - #12351
Merged
Conversation
…rker refuses GPU/memory effects Adds gunbc.compute.host_occupancy (serving-unit state, nvidia-smi compute processes, MemAvailable, read on the host) and gunbc.spark.host_occupancy_admission (admit_spark_host_unoccupied, the with_spark_pair_vacated stop/re-read/restore bracket). The V4.1 image build and row-store encode now require held-by-subject AND unoccupied. Files recurring_failure_mode host_ownership_admitted_as_vacancy. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed ends_with, and name the service nvidia_smi.Smi so it does not collide with the nvidia vendor datum (floor UnimportedBareProvider) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
….spark.serving_incarnation_observe's installed-unit reading of the same name) and the witness helper admission, which forked bare names (floor AmbiguousBareNameRead) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sBareNameRead: String read bare, declared by std.string_type and v2.std.text) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
….algebra filter, which errored non-exhaustively on the unparsed arm (same capture gunbc.commit_workflow records) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Sep 26, 2026
# Conflicts: # dag/gunbc/spark/vllm_runtime_image_build.dag
…tate (review 71643): parse_systemd_unit_active_state, match on the enum, ServingUnitActive carries the enum; an unmodeled state word is unread (new red) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Addressed review 71643 in 318639d. — sent from still-seal-656 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Admission gap found 2026-09-26 on srv8:
gunbc.spark.host_commitmentadmit_host_held_by_subjectadmitted srv8 for V4.1 work because the Group A pair subject holds it. That subject's own V4 pair worker (gunbc-spark-pair-worker.service) was holding ~99.7 GB of the unified pool, leaving 15 GiB; adding a probe on top made the host thrash, and it needed a power cycle. Ownership was read as vacancy. The design was approved by proud-deer-538 before building, with two additions:HostMemoryShort, and occupancy that is not limited to known units.What changes
gunbc.compute.host_occupancy(fabric/compute domain): an occupancy reading taken on the host, made of three modeled reads (systemctl is-activeper serving unit, nvidia-smi compute processes,/proc/meminfo). A pure admission foldadmit_host_occupancyreturns one of:HostOccupiedBy{occupant, others, gpu_used}HostMemoryShort{available, need}HostOccupancyNotRead{cause}HostUnoccupiedEvery GPU compute process is an occupant, whether or not a known unit owns it, so a stray container also refuses. A failed read (Unread) refuses and never counts as vacant. The leg that runs the commands is supplied, the same pattern as
host_effect_quiescence.extdeps.nvidia.system_management_interface: thenvidia.Smi.QueryComputeAppsoperation (cited upstream), plus a parse in which a withheld per-process figure ([N/A]) is its own arm, not zero. A row that does not parse is Unread, not skipped.gunbc.host_operation_exec: newProcfsReadMeminfo,NvidiaSmiQueryComputeAppsandSystemctlStartvariants. Every argv is derived from its extdeps declaration and none is re-spelled.gunbc.spark.host_occupancy_admission:admit_spark_host_unoccupiedreads the realization's pair head and worker units and the two retired units.spark_ctx_argv_runadapts the privileged leg the V4.1 effects already hold.with_spark_pair_vacatedis the modeled vacate: a bracket that stops exactly the serving units the reading found active (stop, not disable), re-reads, and runs the body only when the host reads vacant. It then starts exactly those units and reads each back. Restoration is structural, and nobody has to remember it.Callers: the V4.1 image build (
v41_runtime_image_converge) and the row-store encode (v41_row_store_encode_run) now require both held-by-subject and unoccupied. Each declares its memory need (vllm_build_host_memory_need48 GiB,v41_row_store_encode_memory_need16 GiB). Both figures are declared bets with a read obligation, not measurements.recurring_failure_modehost_ownership_admitted_as_vacancy: new row. Found at rung 1, now at rung 2. The ceiling is stated, and the next trigger is that every memory/GPU door arrives through this seam.Checkpoint materialize and row-store readback keep ownership-only admission. They stage or read bytes at rest and declare no memory need.
Declared frontiers (DESIGN §3c)
with_spark_pair_vacatedhas no real-host consumer in this PR, by ruling: no real-host vacate or restore here, and srv8 stays as it was hand-left. Its first consumer is the V4.1 cutover of the V4 pair on srv5–srv8 and the V4.1 capacity-measurement serve. That door must also bind the vacate to the pair-serving authority, because stopping a worker degrades the peer head.admit_spark_host_unoccupied.Evidence
claim_batchontest.claim.spark.host_occupancy_admission_witness: 11/11 PASS. The REDs:The GREEN control is that a vacated host admits. The mutation control (dropping GPU processes from the reading) turns the pair-worker RED and the unattributed-process RED to FAIL while the vacated control stays PASS. The existing
v41_row_store_encode_run(5/5) andv41_runtime_image_produce(7/7) witnesses pass over the rewired callers. Each fixture answers only the argv thathost_operation_execderives, so drift in an argv turns the admitting claims red.🤖 Generated with Claude Code