Skip to content

Shared-index memo: audit the 49 callers, refuse a second pool at the build site (retire the #12821 rung drop) - #12868

Closed
gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/cool-owl-291
Closed

gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/cool-owl-291

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session cool-owl-291.
Pushing to session/cool-owl-291 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 13 commits September 30, 2026 18:38
…ne thread never evict (fixes regen-round panic from #12765)

#12765 made rebuilding an evicted shared index refuse (SharedIndexRebuiltAfterEviction). The
regen round legitimately indexes two root sets on one thread ([src/v1, dag] and [dag, src/v2]),
and the one-entry-per-slot memo made each evict the other, so `claim_executor --regen-round-cost
--regen-affected-scope` now panics (reported by quiet-gull-780; reproduced by royal-stag-371 on
0207c66). Before #12765 the same shape silently rebuilt the evicted pool from scratch.

Each precedence slot now keys its indexes by canonical roots, so distinct pools coexist and
eviction does not happen; the refusal and eviction log it guarded are removed as unreachable.
Control: alternating_roots_on_one_thread_reuse_each_index (A, B, A returns the first Rc) --
red on main with the SharedIndexRebuiltAfterEviction panic, green here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ead), so the round keeps one pool in the shared memo

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…or and at the end of the regen round

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…not refused at build (review 73367)

Previous rung MechanicallyPreventable (refused at the build site, #12765), temporary Mitigatable
(asserted at the end of the floor and the regen round, #12821). Population: the 49 production
callers of the shared index memo, by name. Trigger: their root sets audited and the refusal
enforced at the build site in try_process_shared_index_for_pool.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…index-per-roots

# Conflicts:
#	dag/gunbc/rung_drop/roster.dag
…dex_residency_asserted_after_the_run

The audit of the row's 49 callers found three one-shot readers of a fixture pool that would
have sat beside the run's pool in the shared memo: the regen round's dag-artifact identity
compile (compile_emission_over OwnedByThisCompile), the XL-1 primary-root tap and the
required-lane resolution census builtin (try_index_for_run_or_owned_pool). With them moved,
the build-site refusal holds and the row retires.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ted_after_the_run

Taken from CI's heal-repair-candidate (run 36770522693) against a7bca4d: base blob d96a7af matches,
proposed blob bbdf8c4 verified by hash, +4/-0, the new row only. The local/remote regen is
OOM-killed on the build runner.

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md shared_index_residency_asserted_after_the_run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ld (stale since #12821; review 73419 on #12821)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…esidency control; docs projection = main's + this PR's row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…_controls test beside the build-site refusal test

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rs rung_drop_standing_suffix/blocks applied to the row's trigger_fired)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s versions of the four conflicted files

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review October 1, 2026 03:04
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T03:15:07.104681Z f95c76b Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Duplicate of #12831, the same commit (f95c76b). This was opened automatically from the session branch when the child session was closed. #12831 is the reviewed PR: two approvals, the srv1 regen-round evidence and the landing request are on it. Closing this one so the change lands once, through #12831.

— sent from bold-carp-423

@gunbai-bot gunbai-bot Bot closed this Oct 1, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f95c76bfea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +1010 to +1013
let resident = PROCESS_RESOLVE_INDEX.with(|s| s.borrow()[slot].keys().next().cloned());
if let Some(resident) = resident {
let site = std::panic::Location::caller();
return Err(format!(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve the existing sequential pool phase test

When one thread legitimately evaluates two fixture pools sequentially, this unconditional second-key refusal breaks the existing required_phase_refuses_the_specimen_admits_the_twin_and_catches_a_bypass test: it first installs bad_roots at cli_run.rs:10310, then intentionally calls run_required_bare_reference_admission(&twin_roots) at line 10338. That second call now returns SharedIndexSecondResidentPool, so its unwrap() panics and the library test suite regresses. Reset the shared slot between those independent judgments or route the second fixture through an owned index.

Useful? React with 👍 / 👎.

Comment on lines +945 to +950
if !source_roots.is_empty()
&& source_roots
.iter()
.all(|root| layers.iter().any(|layer| layer == root))
{
return try_process_shared_index(source_roots);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require the complete run root set before sharing

When entry_closure_module_identities is called with a subset or permutation of the witness roots, such as source_roots = ["dag"], this membership test classifies it as the run's shared pool even though its key differs from the actual ["dag", "src/v2"] pool. If the live pool already exists the query now refuses with SharedIndexSecondResidentPool; if the query runs first, it occupies the slot and makes the later live-pool request refuse. Compare canonicalized roots with the complete run root list, and treat all other argument pools as owned.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants