Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
77fd998
Bound materialization_store_local: per-family ExactLimit budgets, win…
Oct 3, 2026
d9896b3
Move capacity-refusal and sweep notes above their types (annotations …
Oct 3, 2026
16be520
Enrol the ten new wet witnesses: held route gaps (DirWithTemplate has…
Oct 3, 2026
7743f04
Review 74578: index row size is a ByteSize; the Int projection happen…
Oct 3, 2026
15b2996
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 3, 2026
51e0276
chore: regenerate drifted generated artifacts (ci auto-heal)
gunbai-bot[bot] Oct 3, 2026
eed2b31
Review 74673: a reclaim failure carries the host's own error text, an…
Oct 3, 2026
be98dbd
Review 74701: index name recovery, eviction diff, sweep membership an…
Oct 3, 2026
746dea5
Merge origin/main into session/quick-gull-60-c1
Oct 3, 2026
2585470
Merge origin/main into session/quick-gull-60-c1
Oct 3, 2026
9cb7286
Materialization store: establish the disk ceiling under races and ref…
Oct 3, 2026
bb3b97c
Store refusals stay typed (review 75054)
Oct 3, 2026
af65ffa
Store budgets are the consumer's policy, not the transport's (review …
Oct 3, 2026
89aea9d
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 3, 2026
a550137
materialization_store_local imports its map operations from v2.std.co…
Oct 3, 2026
9fe2537
A live row is not yet a present object: a retry of an unpublished req…
Oct 4, 2026
653a7d5
An unfinished reservation binds nothing, including its size
Oct 4, 2026
5963fd4
Merge origin/main (#13091 landed): filesystem_delete gains the Filesy…
Oct 4, 2026
caed43c
Merge branch 'main' of https://github.com/gunb-ai/gunbc into session/…
Oct 4, 2026
281714d
Migrate main's new gunbc.roadmap_dogfood_route (#13077) to the CAS re…
Oct 4, 2026
63b4f3c
One writer per family: the materialization store's writes run inside …
Oct 4, 2026
ce8dafe
Merge origin/main (#13131 managed-host unit hold): redo the mechanica…
Oct 4, 2026
b976881
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
57d609c
process_hold_identity start_time_text matches every StartTime arm; de…
Oct 4, 2026
f35e12d
Store: the family hold is required by every mutation; one canonical f…
Oct 4, 2026
268dd0d
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
2a26767
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
eaab4f0
Merge origin/main into session/quick-gull-60-c1 (non-fold-residue: bo…
Oct 4, 2026
71b0c14
Migrate main's workspace allocation hold callers (#13092) to the hold…
Oct 4, 2026
d43d4b5
Store authority boundary: one bracket, the hold carries the root, sea…
Oct 4, 2026
dc28a95
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
04bf405
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
6d80e60
Seal every remaining effectful store helper: local_store_create_new, …
Oct 4, 2026
aac23d0
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
6b0a345
The opened store is one sealed capability: root, store instance and t…
Oct 4, 2026
257a648
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
d556921
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
21d1774
Merge origin/main; migrate main's gunbc.host_boot_attempt_admission a…
Oct 4, 2026
2a4cb50
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
a2064e5
Merge origin/main; migrate main's workspace commissioning, allocation…
Oct 4, 2026
9005a79
Round 10: exact marker catalog codec; a writable capability only afte…
Oct 4, 2026
77d6548
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 4, 2026
6942881
Merge origin/main; main's dogfood start receipt (#13208) uses the CAS…
Oct 5, 2026
e283ae4
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 5, 2026
c0f04a3
Re-cut the CAS/hold retention API additively: main's operations uncha…
Oct 5, 2026
a0d9060
Merge origin/main (DESIGN.md regenerated from the merged authorities)
Oct 5, 2026
5f19cbd
Merge remote-tracking branch 'origin/main' into session/quick-gull-60-c1
Oct 5, 2026
2a6dc32
The windowed CAS/hold contract is store-private; the raw helpers bene…
Oct 5, 2026
9419c77
Marker scan state is a declared sum; span byte counts are ByteSize (r…
Oct 5, 2026
3a8672d
store_marker_decode names every scan arm (no wildcard over a closed c…
Oct 5, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ The domain roster is a modeled fact, not this prose: `gunbc.design_argument` `co

- **external facts** — each independently versioned upstream has its own module; this is the strongest instance and was, until this section, the only one with a reviewer. Home authorities: `extdeps.external_authority::ExternalModelScope`.
- **materialization / realization** — materialization and realization are separate interfaces with admissible handlers: materialization presents and stores an admitted identity and result contract; realization orders, places and transports work. This row owns whether a handler, provider or placement faithfully realizes that admitted identity and result contract (completeness, readback, retention, transport, refusal, binding obligations) without substituting, truncating or bypassing the admitted key. Cache purity is one discriminator across that boundary, not the whole domain. Key RELATION -- what relation, what scope, what complete canonical preimage, equality and collision disposition, and whether declared inputs are complete -- is owned by conformance-identity. Home authorities: `std.realization::Materialization`, `std.materialization_provider::ArtifactRequest`, `std.artifact_store::ArtifactStore`, `std.cache_interface::StorageSurface`.
- **leasing / locking / grants / privileged access** — exclusive or bounded use and privileged access are one domain: leases with a declared deadline, compare-and-set expectations, scoped authorizations, grants naming who may perform an effect and how it is released, resource handles -- and, since 2026-09-19, which AUTHORIZATION PATTERN performs a privileged effect. That pattern is a §3d selection (gunbc.auth.authorization_pattern_selection consumes std.decision over the effect's frequency, reversibility, surface, workload-identity binding, minted reach and billing consequence): workload identity federation with a per-secret cell for recurring automated effects, one operator approval through the ntfy loop for one-off or witnessed effects, a named human-only step where no API exists, and a refusal for an operator token relayed by chat or between sessions. The census (gunbc.auth.privileged_effect_census) classifies every current site by executing that selection, so the reviewer's three-valued answer is derived for the sites that exist and asked of the site a change adds. Home authorities: `std.temporal_effect::HeldLease`, `std.durable_compare_and_set::CasExpectation`, `std.durable_exclusive_hold::DurableHoldState`, `std.scoped_authorization::ScopedAuthorization`, `std.effect_grant::Grant`, `std.resources::ResourceHandle`, `gunbc.auth.authorization_pattern_selection::select_authorization_pattern`, `gunbc.auth.github_gcp_federation::github_wif_provider`, `gunbc.auth.gcp_secret_access::SecretAccessGrant`, `gunbc.auth.access_request::AccessRequest`, `gunbc.auth.approval_capability::ApprovalCapability`, `gunbc.auth.approval_broker::redeem_capability`, `gunbc.auth.access_token_source::select_access_token_source`, `gunbc.auth.privileged_effect_census::privileged_effect_census`.
- **leasing / locking / grants / privileged access** — exclusive or bounded use and privileged access are one domain: leases with a declared deadline, compare-and-set expectations, scoped authorizations, grants naming who may perform an effect and how it is released, resource handles -- and, since 2026-09-19, which AUTHORIZATION PATTERN performs a privileged effect. That pattern is a §3d selection (gunbc.auth.authorization_pattern_selection consumes std.decision over the effect's frequency, reversibility, surface, workload-identity binding, minted reach and billing consequence): workload identity federation with a per-secret cell for recurring automated effects, one operator approval through the ntfy loop for one-off or witnessed effects, a named human-only step where no API exists, and a refusal for an operator token relayed by chat or between sessions. The census (gunbc.auth.privileged_effect_census) classifies every current site by executing that selection, so the reviewer's three-valued answer is derived for the sites that exist and asked of the site a change adds. A compare-and-set slot's generation line is kept whole by file_compare_and_set and observe_cas_slot_state (gunbc.durable_cas_file_store), because several slots read it as an audit trail; a slot whose only fact is its head -- the materialization store's occupancy index and family holds are the first -- uses the distinct windowed operations (file_compare_and_set_windowed, observe_cas_slot_state_windowed, and the file_hold_*_windowed family) with a CasGenerationWindow of k >= 2, so a bounded store's own bookkeeping does not grow with its commits. They are two contracts, not one operation with a mode: keep-all callers are untouched, and only a caller that names the windowed operation can delete generations. A window read takes the head from a listing of the slot root and verifies head+1 is absent, re-reading on a race and never guessing; a write reclaims below head-k only after its own commit, and a refused delete is reported, never fatal. Exclusion is unchanged -- losers re-read and retry -- so nothing waits on a hold. docs/plans/fabric-storage.md names the head-probe bound this also lifts and assigns its remedy to compaction -- a head that starts from a snapshot; a window is that head-starting-above-1 shape for a slot whose history needs no snapshot, and the fabric heads are not opted in. Home authorities: `std.temporal_effect::HeldLease`, `std.durable_compare_and_set::CasExpectation`, `gunbc.durable_cas_file_store::file_compare_and_set_windowed`, `std.durable_exclusive_hold::DurableHoldState`, `std.scoped_authorization::ScopedAuthorization`, `std.effect_grant::Grant`, `std.resources::ResourceHandle`, `gunbc.auth.authorization_pattern_selection::select_authorization_pattern`, `gunbc.auth.github_gcp_federation::github_wif_provider`, `gunbc.auth.gcp_secret_access::SecretAccessGrant`, `gunbc.auth.access_request::AccessRequest`, `gunbc.auth.approval_capability::ApprovalCapability`, `gunbc.auth.approval_broker::redeem_capability`, `gunbc.auth.access_token_source::select_access_token_source`, `gunbc.auth.privileged_effect_census::privileged_effect_census`.
- **fabric / compute** — allocation, placement and negotiation of resources. The shared authority is product.capacity (lease, pool, seat events) and product.fabric (priced selection over a provider parameter); the subjects that consume it are compute cells (work contracts, compute layouts, cell reservations, capacity class admission) and inference serving (seat binding, co-tenancy admission). Serving is INSIDE this domain, not beside it -- but the sharing is partial and the boundary is the point: both subjects reach the same priced selection fold, and each carries its OWN occupancy producer and linearization (serving: a termed LeaseGrant settled by fabric_seat_acquire over an event chain; compute: a timeless LeaseIdentity settled by file_compare_and_set). They differ further in what the lease is over -- a compute cell is stateless between grants and settles money, a serving seat is over a replica with loaded state and is quality-conditioned instead. The argument is [the serving capacity home ruling](docs/plans/serving-capacity-home-ruling.md). Home authorities: `product.fabric.selection::select_supply`, `product.capacity.lease::LeaseGrant`, `product.capacity.pool_events::SeatRequest`, `product.fabric.work::ExecutionRequirements`, `gunbc.fabric_event_log::fabric_seat_acquire`, `gunbc.compute.work_request::WorkOperation`, `gunbc.compute.work_provider_local::ComputeLayout`, `gunbc.fabric_control_plane::CellReservation`, `gunbc.fabric_executor_class::CapacityClassAdmission`, `gunbc.harness.harness_seat::harness_bind_seat`, `gunbc.serving.turn_admission::serving_group_admission`.
- **decision / selection** — a choice must remain attributable to its subject, candidate field, constraints, evidence and policy, and conformance exposes accidental forks of that authority; the hard selection laws -- no answer outrunning its evidence, no front standing as a winner -- stay with the §3d reviewer, and goal assessment (std.goal_assessment) is a boundary of this row, not a member of it. Home authorities: `std.decision::DecisionSubject`, `std.decision::RealizationSelectionResult`, `std.decision::SelectionReceipt`, `std.decision::select_realization`, `std.pareto::SelectionAxis`, `std.pareto::ParetoEntry`, `std.pareto::DominanceVerdict`.
- **keys / hashing** — the row's scope today is the three keying relations that have a consumed home: structural node identity (v2.std.node content_hash over std.content_hash HashFamily), the request and artifact keys of std.materialization_provider (request_key, artifact_request_key), and occurrence identity within one source graph (std.occurrence_identity) -- plus the declared-equality admissibility of a key TYPE (std.algebra algebra_profile_equality_extensional), which governs whether distinct keys of a finite map are decidably distinct (consumed by the map-literal duplicate-key check, docs/plans/map-literal-introduction-design.md). That admissibility is instantiation-blind at this rung: an opaque brand or a type parameter admits unjudged, and its next-rung trigger is instantiation-grain admission (v1 infer equality_admission_wall_note). This row owns the key RELATION -- what relation, what scope, what complete canonical preimage derives it, what equality and collision disposition govern it -- and whether the declared inputs are complete. Faithful realization of an admitted identity and result contract (completeness, readback, retention, transport, refusal, binding; cache purity as one discriminator) is owned by conformance-realization. Two further relations -- demand identity (the question asked) and the dependency read set an answer consumed -- are a declared frontier, not members: they have no home authority yet, are modeled by docs/plans/demand-engine-program.md, and enter this row when M1 of that program lands their carriers; until then a reviewer asks nothing about them under this row (DESIGN §3b: a home that owns only part of a claimed scope is a scope mismatch, so the scope is stated at what the homes own). Each member is a named keying relation within a named scope, derived rather than authored; the relation model is docs/plans/keying-relation-design.md. Home authorities: `std.content_hash::HashFamily`, `std.materialization_provider::request_key`, `v2.std.node::content_hash`, `std.occurrence_identity::OccurrenceIdAllocator`, `extdeps.realization.cache_purity::CachePurityVerdict`, `std.computation_identity::ComputationIdentity`, `std.algebra::algebra_profile_equality_extensional`.
Expand Down
2 changes: 1 addition & 1 deletion dag/extdeps/cache.dag
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ import extdeps.realization.reconcile_in_process {
parse_cache_id,
typed_module_cache_id,
}
import extdeps.realization.materialization_store_local { materialization_store_local_facts }
import gunbc.materialization_store_budgets { materialization_store_local_facts }
import std.cache_identity { CacheInterfaceId }
import std.cache_interface {
ArtifactIdentity,
Expand Down
36 changes: 36 additions & 0 deletions dag/extdeps/filesystem/filesystem_io.dag
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,41 @@ type FilesystemCreateNew
| FilesystemCreateRefused { path: String, kind: FilesystemFailureKind, error: String }
| FilesystemCreateKindUnrecognized { path: String, observed: String, error: String }

// A DELETE IS OBSERVED THE SAME WAY A CREATE IS: the host's error KIND, admitted through the one
// classifier, never its message. An absent target is its own arm because a caller confirming that a
// name is gone (a store retiring an evicted object) must tell "already gone" from "the host refused";
// the second leaves bytes on disk and the first does not.
type FilesystemDelete
= FilesystemDeleted { path: String }
| FilesystemDeleteTargetAbsent { path: String }
| FilesystemDeleteRefused { path: String, kind: FilesystemFailureKind, error: String }
| FilesystemDeleteKindUnrecognized { path: String, observed: String, error: String }

fn filesystem_delete(
path: String,
success: Bool,
error: String,
error_kind: String,
) -> FilesystemDelete {
if success {
FilesystemDeleted { path: path }
} else {
match admit_filesystem_failure_kind(observed: error_kind) {
FilesystemFailureKindUnrecognized { observed: o } =>
FilesystemDeleteKindUnrecognized { path: path, observed: o, error: error }
FilesystemFailureKindAdmitted { kind: k } =>
match k {
FilesystemNotFound => FilesystemDeleteTargetAbsent { path: path }
FilesystemAlreadyExists => FilesystemDeleteRefused { path: path, kind: k, error: error }
FilesystemPermissionDenied => FilesystemDeleteRefused { path: path, kind: k, error: error }
FilesystemNotDirectory => FilesystemDeleteRefused { path: path, kind: k, error: error }
FilesystemOtherFailure => FilesystemDeleteRefused { path: path, kind: k, error: error }
FilesystemCrossDevice => FilesystemDeleteRefused { path: path, kind: k, error: error }
}
}
}
}

fn filesystem_create_new(
path: String,
success: Bool,
Expand Down Expand Up @@ -818,6 +853,7 @@ service Filesystem {
output {
success: Bool from "delete_success"
error: String from "error"
error_kind: String from "error_kind"
}
transport file { path: "{path}", verb: "delete" }
}
Expand Down
Loading