Skip to content

Wet-witness host-premise census; host_capacity ledger cells take a supplied memory reading - #12652

Merged
gunbai-bot[bot] merged 5 commits into
mainfrom
session/neat-moth-20-host-capacity
Sep 30, 2026
Merged

gunbai-bot[bot] merged 5 commits into
mainfrom
session/neat-moth-20-host-capacity

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Work item: wet-witness audit (assumed host state across all wet claims).

Census. docs/plans/wet-witness-host-premise-census.md classifies all 51 modules on v2.workflow.local_repo_wet_terminal local_repo_wet_schedule, one row per witness and claim: the premise it assumes and its disposition, under RFM wet_witness_keyed_to_the_runner_not_its_subject.

The census was produced by reading the sources, not by executing the claims.

Fix, batch 1: test.claim.compute.host_capacity_wet_witness. Three ledger cells went through compute_reserve_on, which reads the runner's /proc/meminfo. On a busy runner they answered ComputeHostBelowFloor. This is the residual the RFM's census receipt names. They now reserve against a supplied reading (reserve_with_room), as the headroom cells already did (DESIGN §3, a witness discriminates at one interface).

The pairing obligation is kept by the new the_real_reservation_route_admits_exactly_what_the_reading_backs. It runs the real compute_reserve_on route and asserts its verdict as a relation to the host's own reading: admitted if at least 1 MiB is free, below-floor otherwise, and a typed refusal if the reading is unobserved. It never asserts a fixed arm. The claim is enrolled in the wet schedule and in floor_route_gap_expectation_chunk_21; it reaches fresh_root like its siblings.

Evidence: none local yet. A remote gunbc run of the claims hit its 45-minute limit without a verdict, so the wet lane on this PR is the execution receipt.

Later batches follow the census: git config isolation, fleet_release_bins env/ancestor, fixed absent paths / umask / chmod-as-root / sleep. No CI jobs are added.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 29, 2026 18:16
…pplied memory reading

The three ledger cells reached compute_reserve_on, which reads the runner's
/proc/meminfo, so a busy fleet runner answered ComputeHostBelowFloor and the
cell was red by assignment (RFM wet_witness_keyed_to_the_runner_not_its_subject,
residual named in its census receipt). They now reserve against a supplied
reading; the real route is kept by one relation claim that asserts the verdict
follows the host's own reading.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Int (review 72722)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 72722 in 9977a14: the supplied reading is now data supplied_host: Kibibyte = kibibyte(count: 67108864) and is passed straight through as total:/available:. The older one_gibibyte_in_kibibytes bare Int is untouched, as the review noted. — sent from neat-moth-20

@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Local wet receipt (claim_batch built from source into a private target dir, aarch64 session container, uid 1000)

PASS competing_reservations_cannot_over_reserve_and_a_release_returns_the_capacity
PASS a_request_the_machine_cannot_back_refuses_below_the_live_floor
PASS an_appropriation_larger_than_the_machine_refuses_rather_than_admitting
PASS two_instances_on_one_host_resolve_to_one_pool_at_one_root
PASS a_reused_reference_is_a_ledger_refusal_and_never_reported_as_a_full_pool
PASS two_requests_summing_past_the_observed_headroom_cannot_both_admit
PASS the_real_observation_reads_this_machine
PASS releasing_one_seat_twice_is_not_a_ledger_failure_and_charges_nothing
PASS the_real_reservation_route_admits_exactly_what_the_reading_backs

This host had well over 1 MiB free, so the real-route claim took its admitted arm. The below-floor arm of the relation did not execute here.

On BuildBuddy, the same run was OOM-killed (exit 137, about 7–8 GB runners) before any claim ran.

— sent from neat-moth-20

@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

CI wet receipt for floor job 109589210076 (run 36620781638) at head 9e7f365, runner srv3-16: all 9 test.claim.compute.host_capacity_wet_witness identities show [local-repo-wet] … expected=passed observed=passed, including the_real_reservation_route_admits_exactly_what_the_reading_backs. The 4 changed identities read [changed-witness] standing=hermetic-route-gap-held-and-wet-passed. — sent from neat-moth-20

…e flipping runner condition

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… in #12434

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 091ea05 Sep 30, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/neat-moth-20-host-capacity branch September 30, 2026 03:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants