Skip to content

Floor execution requirement moves to gunbc.floor_demand (floor_demand witness closure 1,761 -> 52) - #12788

Merged
gunbai-bot[bot] merged 5 commits into
mainfrom
session/bold-bat-516-floor-execution
Sep 30, 2026
Merged

gunbai-bot[bot] merged 5 commits into
mainfrom
session/bold-bat-516-floor-execution

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Cut (B) of the floor_demand closure item (jolly-boar-500, from sleek-ibex-207). It is independent of cut (A), #12783. Both are module-boundary moves: no resolver change, no new concept, no re-export shim.

Derivation

  • gunbc.floor_demand closes over about 47 modules.
  • Its own witness, and several production consumers, read the floor's execution requirement (floor_execution_requirements). That requirement lived in gunbc.fabric_witness_run, whose subject is building the witness run's Work and CI job, and which closes over about 1,255 modules on main.
  • The requirement's memory is floor_demand's own floor_memory_requirement(). The rest (thread count, capability, trust domain, isolation profile) completes what the floor asks of a host.
  • So it is a fact about floor demand, placed in the module that consumes it most heavily.

Change

  • Moved to gunbc.floor_demand, with names unchanged:
    • floor_execution_requirements
    • floor_isolation_requirement
    • gunbc_internal_fleet_trust_domain
  • The trust domain moves with them. It has no shared home: trust domains are declared beside their consumers (spark_serving_trust_domain lives in gunbc.serving.turn_admission). Its role here is the domain floor Work is declared under, which runner_attempt_launch admits. Leaving it in fabric_witness_run would create a cycle, and a new module for one constant would be a new authority.
  • floor_demand gains imports of product.fabric.{work, isolation} and ResourceEnvelope. Nothing under dag/product imports gunbc.*, so there is no cycle.

Every importer of the moved symbols (enumerated, since not all are under the required gate)

Now imported from gunbc.floor_demand:

  • gunbc.fabric_witness_run: keeps only floor_execution_requirements, which it uses itself.
  • gunbc.fabric_floor_dispatch
  • gunbc.fabric_control_plane: previously imported it through fabric_floor_dispatch, a re-export; now imports it directly from its home.
  • gunbc.runner_attempt_launch: import, plus the comment citing the trust domain's module.
  • gunbc.runner_microvm
  • gunbc.runner_microvm_shakedown
  • test.claim.floor_demand_witness
  • test.claim.fabric_isolation_witness
  • test.claim.runner_microvm_slot_controller_witness
  • test.claim.runner_throughput_qualification_witness: import, plus its decl_ref(module_path: "gunbc.fabric_witness_run", decl_name: "floor_execution_requirements"), which now names gunbc.floor_demand.

No Rust references the moved symbols.

Why the floor_demand witness keeps reading floor_execution_requirements

The suggestion was that it read floor_memory_requirement() directly. Its claim the_work_memory_requirement_is_the_held_set_peak_or_absent checks that the held-set standing reaches the Work's execution requirement (floor_execution_requirements().shape.envelope.memory). That is an inhabitance claim on the route into Work (DESIGN §3), and reading the upstream value would weaken it. After the move it imports the requirement from gunbc.floor_demand, the module under test, so the closure concern is gone without losing the route.

Evidence

Each affected witness was run with gunbc run --claim-run, one cold process per file, 16 GiB memory.max leaf, on current main plus this change:

witness result closure files time peak RSS
floor/floor_demand_witness_test 29 PASS 52 (main: 1,761) 54s (main: 251s) 7.5 GB (main: 15.2 GB)
fabric/fabric_isolation_witness_test 6 PASS 51 49s 7.5 GB
runner/runner_microvm_slot_controller_witness_test 13 PASS 1,805 253s 15.9 GB
runner/runner_throughput_qualification_witness_test 28 PASS 1,782 238s 15.6 GB
fabric/fabric_floor_dispatch_witness_test 4 PASS 1,763 228s 15.3 GB
fabric/fabric_witness_run_test refused at resolve — — —
  • fabric_witness_run_test refuses on main too, as a standalone run, with the same class: effect summary incomplete … names no registry row. On main the named callees include product.fabric.isolation.current_runner_slot_profile and product.fabric.supply.offer_affordability_for. The class predates this PR and it does not introduce it. I'm noting it rather than fixing it here.
  • The runner and dispatch witnesses keep large closures through their other imports. Cut (A), Fleet build tuning to gunbc.fleet_workflow_steps; emitter drops unused heavy import (floor_demand closure 1,761 -> 218) #12783, shrinks the part of that which comes from fabric_witness_run.

Do not merge; landing goes through the operator.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 4 commits September 30, 2026 14:03
…ernal-fleet trust domain move to gunbc.floor_demand

The floor's execution demand is a fact about floor demand; it lived in gunbc.fabric_witness_run,
so every consumer (floor dispatch, control plane, runners, and floor_demand's own witness) paid
for that module's closure to read it. Names unchanged, every importer updated, no re-export.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t.claim.fabric_witness_run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…bric_witness_run's closure

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The // blocks explaining floor_isolation_requirement (with its next-rung trigger),
gunbc_internal_fleet_trust_domain and floor_execution_requirements (architecture, control-plane
class, envelope reasoning with the storage-frontier trigger) now sit directly above their own
declarations in gunbc.floor_demand, instead of on an unrelated symbol in fabric_witness_run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 73251: fixed in d71833a. My move cut each declaration's body and left its leading // rationale behind in fabric_witness_run.dag, where it read as one long comment on the SOURCE ROOTS declaration. All four blocks now sit directly above their own declarations in gunbc.floor_demand:

  • "WHAT A FLOOR RUN REQUIRES OF ITS EXECUTOR…" (with its CONSUMPTION STATUS / NEXT-RUNG TRIGGER) → floor_isolation_requirement
  • "THE FLEET'S OWN TRUST DOMAIN, AS A ROW…" → gunbc_internal_fleet_trust_domain
  • "OUR FLOOR IS arm64. THE CLASS IS NOT." (its "this function previously spelled the architecture inside a capability tag" refers to the capabilities field) plus "THE FLOOR IS CONTROL-PLANE WORK…" (the envelope reasoning with the storage-frontier TRIGGER) → floor_execution_requirements

fabric_witness_run.dag no longer carries any of them. The relocation note is now part of the leading block rather than a standalone block (§4c admits only attached leading blocks). floor_demand_witness_test passes 29/29 and fabric_isolation_witness_test 6/6 on this head.

— sent from bold-bat-516

…not 'above' (review 73274)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 68ad067 Sep 30, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/bold-bat-516-floor-execution branch September 30, 2026 18:08
gunbai-bot Bot pushed a commit that referenced this pull request Sep 30, 2026
…ibution; floor execution demand moved in by #12788)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants