Skip to content

mtcollins1 boot branch (operator fast path): #12800 + Started-row cd_error rule + KVM features seeding - #12874

Merged
gunbai-bot[bot] merged 138 commits into
mainfrom
session/eager-owl-205-boot
Oct 1, 2026
Merged

gunbai-bot[bot] merged 138 commits into
mainfrom
session/eager-owl-205-boot

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Operator-directed fast path (2026-10-01): boot mtcollins1 from this unmerged branch until a boot succeeds, while the component PRs (#12800, #12830, the per-code cd_error policy) land on main normally. Draft, for CI only; not for merging as-is.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 30 commits September 27, 2026 15:45
The build job's admission step carried if_condition: none, so every mode's
dispatch paid a full gunbc run to reach ResetDispatchNotThisMode. It now
carries fleet_converge_host_reset_return_step_if, derived from the one mode
roster. The route witness asserts the gate.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t job's gate

Drift between the admission step's mode condition and the consuming
host-reset-return job's condition would skip the observer refusal in the
one mode it applies to. Both derive from the roster; the witness now
asserts they stay equal.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…h-landed, so the diff reduces to the drift witness

Conflicts resolved per region: the workflow yml takes main's side (#12419's gate is already on main); the witness keeps this branch's stronger step-gate == job-gate assertion.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…model

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ote host, wall clock models

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, remote request, coreutils formats, parent rule)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tore), ipmitool observed-output rows, SOL collector/process table, SDR dump, SMpro, uptime, host console

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the real entry (deadline refusal, pinned SOL-teardown defect, held-unit contender)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… each case's own cause; media withdrawal and SOL-drop events

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…UnimportedBareProvider on 'grant')

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; wall clock on std.measure carriers; seed-growth row covers the file arm

- Per eager-owl-205's ruling (msg_83af891b): the eleven matrix cases over the
  new-witness eval-step budget are typed cost-debt admissions
  (floor_cost_debt_admission mtcollins1_boot_matrix_typed_admissions, reason not
  reading) and members of a declared 4b(3) drop
  (gunbc.rung_drop mtcollins1_boot_matrix_new_witness_eval_step_cost, list
  floor_eval_step_cost_drop_boot_matrix_rows) whose restoration trigger is the
  natively emitted evaluation frame on the merge path. The two cases under the
  per-subject line are neither (a row there is stale).
- Review 72230: ModeledWallClock carries EpochSecs and a signed
  std.measure SecondDisplacement (new, beside CelsiusDelta/ArcsecondDisplacement).
- Seed-growth row names file_result_of_observation and the file/argv boundary.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Heal-Candidate-Run: 36427507942
…e host's boot (one attempt), stale cost-debt rows removed, drop population = the 8 over-budget cases, rung-drop projection regenerated

The first floor run showed every typed cost-debt row stale: the matrix cases sit
under the 500ms per-subject line, where such a row blocks. The honest fix is
cost, not a different exemption: operation_realization_index maps bindings by
identity once per frame (each of ~190 dispatches no longer scans the list), and
the SOL-loss case no longer pays a baseline attempt. Measured locally the
dearest case is now 220ms CPU (was 307ms on CI), under the 302ms enrolment
margin. OperationBoundTwice/BindingMatch deleted (unreachable: duplicates refuse
at admission).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e current authority

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the total form)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…othing when nothing is due

Measured on the deadline case (temporary instrumentation, reverted): the modeled
dispatch was ~110ms of ~243ms CPU, and handler selection ~60ms of that -- the
covering_grant fold re-derived per dispatch for ~15 distinct operations. The
selection reads only the operation identity and readonly flag besides frame-fixed
inputs, so the slot keeps each decided selection keyed by that complete identity.
The world advance short-circuits when no BMC event, media transition or console
line is due. Deadline case now 214ms local (was 307/284ms on CI runs).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ause with both identities, not invalid JSON (#12533 finding 5)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ff is the attempt's named cause (#12533 finding 4)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r recovers it only once that process is observed dead (#12533 finding 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ps its SOL drop)

#12423 side-chat review 5342387382: bmc_advance_pending rebuilt pending from its
own accumulator after each applied event, discarding events the transition had
just scheduled -- a power cycle's restore arming the after-boot SOL drop lost
that drop. The advance now fires the earliest due event from the world's own
pending list, applies it, and repeats on the world that transition produced.
New model control a_power_restore_keeps_the_sol_drop_it_schedules (ON host,
cycle at 0, restore at 5, drop at 35; quiet advances to 10 and to 40); it fails
on the previous fold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…entities (finding 5 flips)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…finding 4 flips; identity renamed in its cost-drop row)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… interrupted case flips to recovery, with live and unobservable holder controls (finding 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r the real boot entry

Clock jumps (ModeledClockStep, a pure function of virtual time) inside the media
readiness wait: a backward step reaches the production ReadinessClockIncoherent
refusal; a forward step closes the window; neither makes a handoff.
cd_error_code: 16 with nothing presented (the 2026-09-27 state) refuses before the
handoff; with the host on, nothing is written; an error appearing with readiness
refuses; a stale lane image with 16 is replaced and booted when the stop clears the
code and refused after the replace when it does not (whether it clears is an
unobserved firmware fact, so both arms run); a foreign presented image is not
stopped. Six of the eight join the declared eval-step drop.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 12 commits September 30, 2026 16:22
… drop the uncommitted-intent zz_probe scratch probes from #12533's WIP commit
…ed cases, #12437 claim split, regenerated rung drops

(a) The dry world now answers gunbc.owned_process LaunchOwned for the KVM observer. It starts a
process visible in /proc with its "<pid> <start>" record at the pid path, and writes its journal
only through gunbc.machine_intake_mtcollins1_kvm_still kvm_journal_line: connection-requested,
connection-open, then established with the quoted host:port, session, attempt and gen. While live,
it answers each trigger file with a still, and on the stop file it journals stop-requested, session
release, browser close and stopped, then exits. A line kvm_journal_line refuses is a harness fault.
Still digests are supplied beside the bytes (the gunbc.remote_host_model precedent); sha256sum
answers only for those bytes. All 26 matrix cases PASS under claim_batch locally; at ec1b819,
without this binding, 22 returned false.

(b) a_toolchain_that_is_not_ready_... / an_unresolved_toolchain_...: no Mkdir, no LaunchOwned, no
power action, and the refusal names the toolchain's standing.

(c) The matrix now names the pairing claim that runs runner_browser_toolchain_here_wet for real:
mtcollins1_kvm_observer_protocol_wet_witness a_held_observer_is_admitted_and_its_triggered_still_is_hash_bound.

(e) #12437 (test-only) made the_build_job_carries_the_reset_observer_dispatch_admission build the
whole host-reset-return job to read its if. Both gates read fleet_converge_host_reset_return_step_if,
so the claim is split: the step side compares its gate to that datum, and
the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job side.

(f) docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet on the merged
tree; it wrote no other change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ost rows re-cited from CI, dead-band/cost-debt reclassified, seed-growth cache named

(e) The workflow claim is three claims over three producers:
- the_reset_observer_dispatch_admission_step_carries_its_gate_entry_and_inputs holds the step's
  gate, entry and dispatch inputs over the step's own producer, under budget with no drop
  (claim_batch: 16,102 eval steps including shared fill);
- the_build_job_carries_the_reset_observer_dispatch_admission holds structural membership in the real
  fleet_converge_build_job_own_steps, and is the only claim that runs that producer;
- the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job's side of the gate.
Only the membership claim is under the new declared drop
gunbc.rung_drop fleet_build_job_membership_new_witness_eval_step_cost (eager-owl-205, escalation
msg_00eaf0e6, option 1). Its trigger names the capability: fleet_workflow_steps constructs only the
steps a consumer demands. Its measured_by cites run 36765162766 (155,333 marginal) and run
36743802719 (174,583), and records that the cost predates gunbc#12437.

(d) Every matrix eval-step row now cites PR floor run 36765162766 at 6cac35e, and the two
toolchain arms join that list. The dead-band rows cite that run's CPU, and the stop-clears case
(473 ms) joins them. The interrupted-attempt case (523 ms, over the 500 ms line) leaves the band for a
typed cost-debt admission, as the band's self-staling rule requires.

v2.test.floor_enrolment_margin the_dead_band_authority_names_exactly_the_two_app_attest_claims went
false when gunbc#12533 added the matrix list, and was never re-planned. It now holds the App Attest
list at exactly its two claims, and the honoured identities at exactly the two declared lists.

Review 73376: gunbc.modeled_operation_realization_seed_growth names the per-frame
operation_handler_selection cache: its key, scope and retention. The ProcessArgvExpansion arm was
already covered, and dispatch_file exists on main.

docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s an instant

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Reverts the integration of gunbc#12795 (merge 7393c8e): the megarac.Ui.GetServedBundle
operation, gunbc.machine_intake_mtcollins1_ui_bundle_observe and its witness, the
MtCollins1UiBundleObserve fleet-converge mode row and its ci_spec invoke, the 2026-09-27 bundle digest
row, and the fleet-converge.yml lines. Review 73415 found the mode's step is new string-concat shell
under a Scaffold whose own marker names the modeled route (v2.workflow.bash_emit), which is in use
today. The mode now lands only through eager-cat-463's lane, built on bash_emit nodes. Nothing else in
the tree referenced it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…etween runners

PR floor run 36775473983 at b907f7d (srv3) refused four matrix cases as measured over the
302 ms margin, at 303-318 ms. Run 36765162766 at 6cac35e (srv1) had admitted the same four at
276-290 ms, at identical eval_steps. This is the margin-straddle form of
gunbc.recurring_failure_mode enrolment_dead_band_has_no_representable_standing, which #12533 already
repaired: a dead-band row whose fast-runner reading lies in (envelope floor, margin] is
EnrolmentDeadBandWithinRunnerEnvelope, not stale. Each row cites both runs. docs/design-rung-drops.md
regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PR floor run 36783312538 at 8042d17 (srv3) refused it at 320 ms against the 302 ms margin; run
36765162766 (srv1) admitted it at 283 ms, at identical eval_steps. It is the same straddle form as
the previous four. It was the only blocker on that run: 0 claims failed and 0 over-cost.
docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ite the interrupted-attempt row

Brings in gunbc#12853: a typed cost-debt reading in (line / p90, line] is
EnrolmentRosterGroundWithinRunnerEnvelope rather than stale. The interrupted-attempt case's typed
cost-debt reason now cites all four readings: PR floor runs 36765162766 (srv1, 523 ms), 36775473983
(srv3, 582 ms) and 36783312538 (srv3, 543 ms), and merge-group run 36793281217 (srv4, 466 ms), whose
stale row dequeued this change and which that arm now holds.

docs/design-rung-drops.md: the generated-artifact driver refused it, as it does whenever both sides
change it. Main's projection was taken and regenerated from the merged authorities by
tools.generated_artifact_gate main_wet on a binary rebuilt after the merge. By set difference, no row
of either side went dark.

Local on the merged tree: v2.test.floor_enrolment_margin 44/44, the seed-mirror witness 2/2, the
mtcollins1 boot acceptance matrix 26/26.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(vendor UI reads it only when stopped); the code is recorded, an unread code still withholds

Operator decision 2026-10-01 (boot-from-branch fast path). Grounded in the MegaRAC UI bundle source.min.js
sha256 5029fae2 (rmedia changeInSingleImages): error_code is consulted only at redirection_status 0 and
rendered as the stop reason (16 = Device Ejected). Stopped-row codes keep today's refusal; the per-code
table is the separate policy lane. Matrix and convergence witnesses re-asserted; the three matrix cases
that pinned '16 refuses' now assert the boot proceeds with the code recorded.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-0.32 row (minimum from #12830 for the boot)

Run 36788605665: the served viewer.min.js reads sessionStorage.features.indexOf(...) unguarded in
its KVM view's initialize(), so with features unset it throws and never opens /kvm.

- extdeps.bmc.megarac megarac_ui_features_0_32 (73 names), emitted by
  gunbc.machine_intake_megarac_ui_features megarac_ui_features_row_emit from the retained served
  source.min.js, refused unless it digests to the 2026-09-27 pin (row ported with it);
  megarac_ui_features(firmware) and the vendor storage shape; extdeps.tools.gzip for the decode.
- kvm_still: no row for the firmware -> not started; the launch writes features.json and the init
  script seeds sessionStorage.features; features-unreadable cause.
- loopback viewer reads sessionStorage.features.indexOf unguarded; enrolled wet red
  a_viewer_without_its_feature_list_never_opens_kvm; megarac_ui_features witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review October 1, 2026 05:24
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T05:35:16.453684Z 081fcaf Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 081fcaf641

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


// kvm_observer_launch_in's operands end the node command: base URL, user, credential path, dir,
// attempt, cadence, frame wait, periodic limit, playwright module.
data kvm_observer_operand_count: Int = 9

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Update the KVM operand count for the feature-path argument

When a dry boot reaches the KVM launch, kvm_observer_launch_in now appends ten operands, but this tail parser still counts nine. Consequently kvm_operand(..., 0) reads the username instead of the base URL, index 3 reads the attempt instead of the observer directory, and index 4 reads the cadence instead of the attempt; the modeled handler writes its journal to the wrong path with a mismatched subject, so healthy dry boot scenarios cannot establish the required KVM observer or reach handoff.

Useful? React with 👍 / 👎.

Brian Searls and others added 5 commits October 1, 2026 05:40
…re-list operand (10 operands); establish only over a seeded list

The features port added a tenth operand; the dry worker read operands at a fixed count of 9 from the
end, so every observer launch read the wrong dir/host/attempt and the matrix's observed boots
failed. It now reads 10, and models the vendor viewer: without the feature list the launch wrote, the
observer journals a no-frame refusal and is never established.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflicted files where main equals the pre-squash base 85c4f89 take this
branch's side; design-rung-drops.md is a three-way merge over that base.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ct repair route; heal regenerates it from the merged roster

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nd to typed cost debt

Since the Started-row rule they boot instead of refusing at the handoff gate,
and at identical eval_steps they read 415-423 ms (run 36820943484) and
583-652 ms (run 36825466924): above the envelope floor on a fast runner and
above the per-subject line on a slow one, which only a typed cost-debt row
grounds (enrolment_dead_band_wrong_ground otherwise).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36831359503
gunbc-ci-auto-heal and others added 5 commits October 1, 2026 10:04
…ith no constructor (review 73648)

A Started row with a read cd_error_code is served whatever the code, so the
recheck has no unestablished answer; an unread code is PresentationUnobserved.
The recheck arm, both diagnostic-bundle texts and the witness import go with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
#12830 landed the full form of 7168e53's features seeding, so every path that
commit touched takes main's side; the dry realization's 10-operand fix was
identical on both sides. design-rung-drops.md takes main's projection for heal
to regenerate (no row dark by set difference).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36846857547
#12889's per-code cd_error policy supersedes this branch's interim Started-row
rule, so every conflicted path takes main's side. One hunk is kept from this
branch: the three full-boot cd_error cases stay typed cost debt rather than
dead band (they read 583-652 ms CPU on a slow runner, run 36825466924, where a
dead-band row is the wrong ground). design-rung-drops.md takes main's
projection for heal (no row dark by set difference).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36862331086
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit f32699f Oct 1, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/eager-owl-205-boot branch October 1, 2026 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant