Repository navigation
Wet-witness host-premise census; host_capacity ledger cells take a supplied memory reading - #12652
Conversation
…pplied memory reading The three ledger cells reached compute_reserve_on, which reads the runner's /proc/meminfo, so a busy fleet runner answered ComputeHostBelowFloor and the cell was red by assignment (RFM wet_witness_keyed_to_the_runner_not_its_subject, residual named in its census receipt). They now reserve against a supplied reading; the real route is kept by one relation claim that asserts the verdict follows the host's own reading. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Int (review 72722) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressed review 72722 in 9977a14: the supplied reading is now |
|
Local wet receipt (claim_batch built from source into a private target dir, aarch64 session container, uid 1000)
This host had well over 1 MiB free, so the real-route claim took its admitted arm. The below-floor arm of the relation did not execute here. On BuildBuddy, the same run was OOM-killed (exit 137, about 7–8 GB runners) before any claim ran. — sent from neat-moth-20 |
|
CI wet receipt for floor job 109589210076 (run 36620781638) at head 9e7f365, runner srv3-16: all 9 |
…e flipping runner condition Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… in #12434 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Work item: wet-witness audit (assumed host state across all wet claims).
Census.
docs/plans/wet-witness-host-premise-census.mdclassifies all 51 modules onv2.workflow.local_repo_wet_terminallocal_repo_wet_schedule, one row per witness and claim: the premise it assumes and its disposition, under RFMwet_witness_keyed_to_the_runner_not_its_subject..cargoin fleet_release_bins, fixed absent paths, umask, and a fixed sleep. Tool-presence premises are recorded but not scheduled.The census was produced by reading the sources, not by executing the claims.
Fix, batch 1:
test.claim.compute.host_capacity_wet_witness. Three ledger cells went throughcompute_reserve_on, which reads the runner's/proc/meminfo. On a busy runner they answeredComputeHostBelowFloor. This is the residual the RFM's census receipt names. They now reserve against a supplied reading (reserve_with_room), as the headroom cells already did (DESIGN §3, a witness discriminates at one interface).The pairing obligation is kept by the new
the_real_reservation_route_admits_exactly_what_the_reading_backs. It runs the realcompute_reserve_onroute and asserts its verdict as a relation to the host's own reading: admitted if at least 1 MiB is free, below-floor otherwise, and a typed refusal if the reading is unobserved. It never asserts a fixed arm. The claim is enrolled in the wet schedule and infloor_route_gap_expectation_chunk_21; it reachesfresh_rootlike its siblings.Evidence: none local yet. A remote
gunbc runof the claims hit its 45-minute limit without a verdict, so the wet lane on this PR is the execution receipt.Later batches follow the census: git config isolation, fleet_release_bins env/ancestor, fixed absent paths / umask / chmod-as-root / sleep. No CI jobs are added.
🤖 Generated with Claude Code