Repository navigation
mtcollins1 boot: integration of #12533, #12556, #12555, #12554, #12553, #12730, #12786, #12437 - #12800
Conversation
The build job's admission step carried if_condition: none, so every mode's dispatch paid a full gunbc run to reach ResetDispatchNotThisMode. It now carries fleet_converge_host_reset_return_step_if, derived from the one mode roster. The route witness asserts the gate. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t job's gate Drift between the admission step's mode condition and the consuming host-reset-return job's condition would skip the observer refusal in the one mode it applies to. Both derive from the roster; the witness now asserts they stay equal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…h-landed, so the diff reduces to the drift witness Conflicts resolved per region: the workflow yml takes main's side (#12419's gate is already on main); the witness keeps this branch's stronger step-gate == job-gate assertion. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…model Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ote host, wall clock models Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, remote request, coreutils formats, parent rule) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tore), ipmitool observed-output rows, SOL collector/process table, SDR dump, SMpro, uptime, host console Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the real entry (deadline refusal, pinned SOL-teardown defect, held-unit contender) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… each case's own cause; media withdrawal and SOL-drop events Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…UnimportedBareProvider on 'grant') Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; wall clock on std.measure carriers; seed-growth row covers the file arm - Per eager-owl-205's ruling (msg_83af891b): the eleven matrix cases over the new-witness eval-step budget are typed cost-debt admissions (floor_cost_debt_admission mtcollins1_boot_matrix_typed_admissions, reason not reading) and members of a declared 4b(3) drop (gunbc.rung_drop mtcollins1_boot_matrix_new_witness_eval_step_cost, list floor_eval_step_cost_drop_boot_matrix_rows) whose restoration trigger is the natively emitted evaluation frame on the merge path. The two cases under the per-subject line are neither (a row there is stale). - Review 72230: ModeledWallClock carries EpochSecs and a signed std.measure SecondDisplacement (new, beside CelsiusDelta/ArcsecondDisplacement). - Seed-growth row names file_result_of_observation and the file/argv boundary. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost Heal-Candidate-Run: 36427507942
…e host's boot (one attempt), stale cost-debt rows removed, drop population = the 8 over-budget cases, rung-drop projection regenerated The first floor run showed every typed cost-debt row stale: the matrix cases sit under the 500ms per-subject line, where such a row blocks. The honest fix is cost, not a different exemption: operation_realization_index maps bindings by identity once per frame (each of ~190 dispatches no longer scans the list), and the SOL-loss case no longer pays a baseline attempt. Measured locally the dearest case is now 220ms CPU (was 307ms on CI), under the 302ms enrolment margin. OperationBoundTwice/BindingMatch deleted (unreachable: duplicates refuse at admission). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e current authority Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the total form) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…othing when nothing is due Measured on the deadline case (temporary instrumentation, reverted): the modeled dispatch was ~110ms of ~243ms CPU, and handler selection ~60ms of that -- the covering_grant fold re-derived per dispatch for ~15 distinct operations. The selection reads only the operation identity and readonly flag besides frame-fixed inputs, so the slot keeps each decided selection keyed by that complete identity. The world advance short-circuits when no BMC event, media transition or console line is due. Deadline case now 214ms local (was 307/284ms on CI runs). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ause with both identities, not invalid JSON (#12533 finding 5) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ff is the attempt's named cause (#12533 finding 4) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r recovers it only once that process is observed dead (#12533 finding 2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ps its SOL drop) #12423 side-chat review 5342387382: bmc_advance_pending rebuilt pending from its own accumulator after each applied event, discarding events the transition had just scheduled -- a power cycle's restore arming the after-boot SOL drop lost that drop. The advance now fires the earliest due event from the world's own pending list, applies it, and repeats on the world that transition produced. New model control a_power_restore_keeps_the_sol_drop_it_schedules (ON host, cycle at 0, restore at 5, drop at 35; quiet advances to 10 and to 40); it fails on the previous fold. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…entities (finding 5 flips) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…finding 4 flips; identity renamed in its cost-drop row) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… interrupted case flips to recovery, with live and unobservable holder controls (finding 2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r the real boot entry Clock jumps (ModeledClockStep, a pure function of virtual time) inside the media readiness wait: a backward step reaches the production ReadinessClockIncoherent refusal; a forward step closes the window; neither makes a handoff. cd_error_code: 16 with nothing presented (the 2026-09-27 state) refuses before the handoff; with the host on, nothing is written; an error appearing with readiness refuses; a stale lane image with 16 is replaced and booted when the stop clears the code and refused after the replace when it does not (whether it clears is an unobserved firmware fact, so both arms run); a foreign presented image is not stopped. Six of the eight join the declared eval-step drop. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed cases, #12437 claim split, regenerated rung drops (a) The dry world now answers gunbc.owned_process LaunchOwned for the KVM observer. It starts a process visible in /proc with its "<pid> <start>" record at the pid path, and writes its journal only through gunbc.machine_intake_mtcollins1_kvm_still kvm_journal_line: connection-requested, connection-open, then established with the quoted host:port, session, attempt and gen. While live, it answers each trigger file with a still, and on the stop file it journals stop-requested, session release, browser close and stopped, then exits. A line kvm_journal_line refuses is a harness fault. Still digests are supplied beside the bytes (the gunbc.remote_host_model precedent); sha256sum answers only for those bytes. All 26 matrix cases PASS under claim_batch locally; at ec1b819, without this binding, 22 returned false. (b) a_toolchain_that_is_not_ready_... / an_unresolved_toolchain_...: no Mkdir, no LaunchOwned, no power action, and the refusal names the toolchain's standing. (c) The matrix now names the pairing claim that runs runner_browser_toolchain_here_wet for real: mtcollins1_kvm_observer_protocol_wet_witness a_held_observer_is_admitted_and_its_triggered_still_is_hash_bound. (e) #12437 (test-only) made the_build_job_carries_the_reset_observer_dispatch_admission build the whole host-reset-return job to read its if. Both gates read fleet_converge_host_reset_return_step_if, so the claim is split: the step side compares its gate to that datum, and the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job side. (f) docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet on the merged tree; it wrote no other change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ost rows re-cited from CI, dead-band/cost-debt reclassified, seed-growth cache named (e) The workflow claim is three claims over three producers: - the_reset_observer_dispatch_admission_step_carries_its_gate_entry_and_inputs holds the step's gate, entry and dispatch inputs over the step's own producer, under budget with no drop (claim_batch: 16,102 eval steps including shared fill); - the_build_job_carries_the_reset_observer_dispatch_admission holds structural membership in the real fleet_converge_build_job_own_steps, and is the only claim that runs that producer; - the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job's side of the gate. Only the membership claim is under the new declared drop gunbc.rung_drop fleet_build_job_membership_new_witness_eval_step_cost (eager-owl-205, escalation msg_00eaf0e6, option 1). Its trigger names the capability: fleet_workflow_steps constructs only the steps a consumer demands. Its measured_by cites run 36765162766 (155,333 marginal) and run 36743802719 (174,583), and records that the cost predates gunbc#12437. (d) Every matrix eval-step row now cites PR floor run 36765162766 at 6cac35e, and the two toolchain arms join that list. The dead-band rows cite that run's CPU, and the stop-clears case (473 ms) joins them. The interrupted-attempt case (523 ms, over the 500 ms line) leaves the band for a typed cost-debt admission, as the band's self-staling rule requires. v2.test.floor_enrolment_margin the_dead_band_authority_names_exactly_the_two_app_attest_claims went false when gunbc#12533 added the matrix list, and was never re-planned. It now holds the App Attest list at exactly its two claims, and the honoured identities at exactly the two declared lists. Review 73376: gunbc.modeled_operation_realization_seed_growth names the per-frame operation_handler_selection cache: its key, scope and retention. The ProcessArgvExpansion arm was already covered, and dispatch_file exists on main. docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s an instant Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Reverts the integration of gunbc#12795 (merge 7393c8e): the megarac.Ui.GetServedBundle operation, gunbc.machine_intake_mtcollins1_ui_bundle_observe and its witness, the MtCollins1UiBundleObserve fleet-converge mode row and its ci_spec invoke, the 2026-09-27 bundle digest row, and the fleet-converge.yml lines. Review 73415 found the mode's step is new string-concat shell under a Scaffold whose own marker names the modeled route (v2.workflow.bash_emit), which is in use today. The mode now lands only through eager-cat-463's lane, built on bash_emit nodes. Nothing else in the tree referenced it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…etween runners PR floor run 36775473983 at b907f7d (srv3) refused four matrix cases as measured over the 302 ms margin, at 303-318 ms. Run 36765162766 at 6cac35e (srv1) had admitted the same four at 276-290 ms, at identical eval_steps. This is the margin-straddle form of gunbc.recurring_failure_mode enrolment_dead_band_has_no_representable_standing, which #12533 already repaired: a dead-band row whose fast-runner reading lies in (envelope floor, margin] is EnrolmentDeadBandWithinRunnerEnvelope, not stale. Each row cites both runs. docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PR floor run 36783312538 at 8042d17 (srv3) refused it at 320 ms against the 302 ms margin; run 36765162766 (srv1) admitted it at 283 ms, at identical eval_steps. It is the same straddle form as the previous four. It was the only blocker on that run: 0 claims failed and 0 over-cost. docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE — 46a252c89e0e1ad17d6d28e5ca2825bd03ac605f
No blocking integration findings.
I reviewed this as one composed boot system, including the listed conflict resolutions and the work that completed #12533 after the initial merge.
Acceptance matrix and KVM boundary
- The matrix drives the real boot entry through
mtcollins1_boot_on_srv1_resolving_toolchain; it supplies only the browser-toolchain resolution boundary. - The Ready route now has a dry KVM observer through launch, establishment, trigger still, hashing and teardown. Its journal lines are produced through
kvm_journal_line. - The NotReady and Unresolved controls distinguish their typed causes and require no KVM directory creation, no
LaunchOwned, and no boot-device or chassis-power action. - Supplying the resolution did not remove the last real path.
a_held_observer_is_admitted_and_its_triggered_still_is_hash_boundcallsrunner_browser_toolchain_here_wet, launches the real held observer against the enforcing loopback transport, admits the handoff, retains a hash-bound triggered still, and observes logout/browser/process teardown. The root-navigation control also retains #12786's request-client boundary: the root is never served.
Conflict composition
- The #12533/#12555 merge preserves
worker_process_started, the matrix filesystem population and the recovery cases. The obsolete permanent-lockout case is gone. - Dead-holder recovery remains fail-closed and generation-bound: a boot hold names boot id, pid, start time and pid namespace; only an observed-dead holder is recovered, while live, unreadable, foreign-namespace and moved-slot arms refuse.
- #12730's SOL gate checks a fresh monotonic reading before admitting a banner, terminates on refused pacing or a stalled clock, and keeps the deadline typed as
Millisecond. - #12554's post-handoff media loss attribution and #12553's duplicate-listing refusal survive in the integrated boot route.
Floor and generated integration
- #12437 is split at the right interfaces: step content, real build-job membership and job gate. Only the real-list membership claim carries the declared cost drop, whose trigger preserves real structural membership and names demand-driven step construction rather than a budget increase or supplied list.
- The matrix eval-step population is the union of the integrated cases. The interrupted recovery case is typed cost debt rather than being hidden in a margin band; the runner-straddling cases have paired measurements and a representable
WithinRunnerEnvelopestanding. - The seed-growth receipt names the operation-selection cache's complete varying key, frame scope and retention, and the file-transport realization is routed through the same transport-path authority as wet dispatch.
- #12795 is fully absent from this branch and remains owned by #12830.
Exact-head run 36787978592 has green floor, generated, emit-build and required witnesses. GitHub currently reports this exact head clean and mergeable.
The intentionally deferred sessionStorage.features, SPA-navigation observation and per-code cd_error_code policy do not create a silent-success path here: KVM establishment still gates handoff and the existing media policy remains fail-closed. They remain follow-up evidence/modeling work rather than integration blockers.
Queue through the normal merge-group gate. This is source/merge approval, not a separate authorization to dispatch hardware.
Non-blocking metadata: the PR title still names reverted #12795 and the body still labels the now-completed #12533 items as outstanding; deleting that stale text would make the landing record accurate, but it does not require another code-head review.
…ite the interrupted-attempt row Brings in gunbc#12853: a typed cost-debt reading in (line / p90, line] is EnrolmentRosterGroundWithinRunnerEnvelope rather than stale. The interrupted-attempt case's typed cost-debt reason now cites all four readings: PR floor runs 36765162766 (srv1, 523 ms), 36775473983 (srv3, 582 ms) and 36783312538 (srv3, 543 ms), and merge-group run 36793281217 (srv4, 466 ms), whose stale row dequeued this change and which that arm now holds. docs/design-rung-drops.md: the generated-artifact driver refused it, as it does whenever both sides change it. Main's projection was taken and regenerated from the merged authorities by tools.generated_artifact_gate main_wet on a binary rebuilt after the merge. By set difference, no row of either side went dark. Local on the merged tree: v2.test.floor_enrolment_margin 44/44, the seed-mirror witness 2/2, the mtcollins1 boot acceptance matrix 26/26. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE — exact head 85c4f893d77705174791e24c2eaece0d54027132
No blocking successor-delta finding.
This is a two-parent merge of the previously approved 46a252c89e0e1ad17d6d28e5ca2825bd03ac605f and main@e44119f99cbaad2d4020d2e338b1e253913300a7, the merge commit that carries #12853. The accepted integration source remains intact.
The one semantic successor edit is correctly bounded: mtcollins1_boot_matrix_typed_admissions still contains exactly the interrupted-attempt identity, and its reason now carries all four readings—523 ms, 582 ms, 543 ms, and the merge-group 466 ms—and names #12853's EnrolmentRosterGroundWithinRunnerEnvelope as the standing for the under-line reading. The typed row remains required; this does not turn 466 ms into an undeclared pass.
The merge preserves #12853's production model and host mirror. The PR's remaining floor_enrolment_margin_test delta only extends the pre-existing exact dead-band-authority assertion to include the declared mtcollins1 list; it does not replace or weaken #12853's 302/303 and 500/501 runner-envelope controls.
docs/design-rung-drops.md is regenerated at the merged composition. Against merged main, its diff is additive: the mtcollins1 eval-step, dead-band, and build-job membership rows are present, and no main row is deleted. The exact-head generated lane remains the final byte-for-byte authority.
Queue only after exact-head floor, generated, and emit-build are green, retaining the merge-group gate.
Conflicted files where main equals the pre-squash base 85c4f89 take this branch's side; design-rung-drops.md is a three-way merge over that base. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e holder is recoverable when observed dead (side-chat blocker 4b)
- mtcollins1_maintenance_hold rebuilt on main's: KvmObserverProbe { run_id, process: ProcessIdentity,
pid_namespace } like BootRun (tag/detail/label/decode); the acquirer captures self_process_identity
and refuses if it cannot; holder_liveness_route (pure) routes a probe holder to its process, so
unit_hold_acquire's observed-dead recovery (#12555) frees a dead probe's hold.
- witness: probe owner renders and routes to its process; a processless one is not observable.
- mtcollins1_boot_dry_realization: 10 observer operands, established only over a seeded feature list.
- observer, loopback transport, rosters: this branch's side (main held their older forms).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Single integration branch for the mtcollins1 boot work, at the operator's request (2026-09-30). It supersedes and closes nine PRs. #12795 was later reverted out of this branch (a980fa6) and moved to #12830, which owns the BMC read-only probes; review 73415 applied. Each was merged in with a merge commit, in this order:
Conflict resolutions (please review these)
worker_filesystemuses mtcollins1 unit hold: recoverable once its holder process is observed dead, never because it is old (#12533 finding 2) #12555'sworker_process_startedwrapper, with mtcollins1 boot acceptance matrix over the real orchestrator (dry BMC/worker world; file arm) #12533's directory list andrefused_reads: []. mtcollins1 unit hold: recoverable once its holder process is observed dead, never because it is old (#12533 finding 2) #12555's recovery cases replace the pinned lockout case, as that PR intended. Its subjects were switched frommtcollins1_boot_wet_on_srv1()toboot_with_toolchain(toolchain: ready_toolchain()), following mtcollins1 boot acceptance matrix over the real orchestrator (dry BMC/worker world; file arm) #12533's toolchain split (ruling A).floor_eval_step_cost_drop/mtcollins1_boot_matrix_new_witness_eval_step_cost. The population is the union of the mtcollins1 boot acceptance matrix over the real orchestrator (dry BMC/worker world; file arm) #12533, mtcollins1 boot matrix: wall-clock and cd_error_code cases (stacked on #12533) #12556 and mtcollins1 unit hold: recoverable once its holder process is observed dead, never because it is old (#12533 finding 2) #12555 rows.pinned_an_interrupted_attempt_locks_out_the_next_oneis dropped because the case no longer exists. The count-free prose is taken from mtcollins1 unit hold: recoverable once its holder process is observed dead, never because it is old (#12533 finding 2) #12555.docs/design-rung-drops.md. Took one side at each merge. It is generated and must be regenerated from the merged tree (tools.generated_artifact_gatemain_wet), as must any other generated artifact thegeneratedlane flags. That includesfleet-converge.yml, which mtcollins1: read-only fleet-converge mode fetches the BMC's UI bundle (source.min.js) #12795 and fleet-converge witness: reset-return admission gate must equal the host-reset-return job gate #12437 both touch.Completed on this branch (fierce-cat-881)
The #12533 WIP was finished here: a dry KVM observer, the NotReady/Unresolved toolchain cases, the real-toolchain pairing claim, the re-measured eval-step/dead-band rows, the #12437 claim split, and regenerated artifacts. Witnesses green at 46a252c (run 36787978592); side-chat approval 5373231170.
Deferred to follow-ups
🤖 Generated with Claude Code