Repository navigation
G1: belt verify through the materialization provider; compute outcomes and binaries in the bounded store - #13097
gunbai-bot[bot] wants to merge 80 commits into
Conversation
…k_identity is its derived request_key Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ReleasePolicy gains ReleasedAfterInterval { after_write } -- an object lifecycle
rule or artifact retention period reclaims the entry, after which a lookup is an
established Miss. It is distinct from InvalidationTrigger TtlExpiry (freshness).
realize_route no longer recomputes over every rejected hit: only FreshnessExpired
(a declared invalidation) recomputes; integrity and availability rejections
refuse, so a corrupt or unreachable store is never absorbed by a rebuild.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the built bytes Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dowed occupancy index, self-clean on open Each request family's store is constructed by std.artifact_store store_over_provider from its own CapacityBounded/ExactLimit/LeastRecentlyUsed provider row (typed-module 4 GiB as named policy); the host ceiling is their declared sum. Occupancy lives in a per-family CAS slot retained as a generation window (new opt-in gunbc.durable_cas_file_store CasSlotRetention; every existing slot declares KeepAllGenerations). Commits reserve before publishing, evict LRU within the family, and refuse typed on did-not-fit / undeclared budget / unreadable index. Open sweeps unindexed objects; recency is advisory, one CAS per process. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion/bold-dove-431-cutover
…ects, sealed FabricBlobReading, put plan with size bound) Split out of session/royal-moth-86 (#13080) so the bounded local store (C1b) can realize byte parts on it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…are module-item grain); retire stale std.materialization_object#get roster row Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e; belt claim verify through compute_provide; receipt cites the shared computation Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…im run spells --wet Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s address fails closed instead of substituting a digest Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… no mock) and scheduled on the local-repo wet lane, as their file's existing wet witnesses are Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s only at the occupancy codec Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e refusal, one realization for seed and emitted programs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, not-found; classifier: cross-device, unrecognized), enrolled as held route gaps and on the wet lane Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… third enrolment beside the route-gap and wet-schedule rows) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… session/quick-gull-60-c1b # Conflicts: # src/v2/workflow/floor_route_gap.dag # src/v2/workflow/local_repo_wet_terminal.dag
… session/quick-gull-60-c1b
…rd v3), staged files linked create-only and verified on every read, charged to the family budget and evicted with their record Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d; dependents execute verified readings; store_dir deleted Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… build commit, attach and dependent resolution on a scratch root Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… identity (triple, rustc -vV, cargo, sccache, provider revision); wet claim runs refused on the legacy provider; honest native provenance rung Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…m, link into /tmp, asserting the st_dev precondition (coreutils.Stat.PathDevice) so an unobservable runner reds rather than greens Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ared frontier at #13095, not a present fact Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… session/quick-gull-60-c1b
…ts trigger (local_store_link_part consumes LinkCreateNew); the seed-growth receipt names the present consumer Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ve a body-position annotation to its declaration Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Merged the reworked C1 base (
Remote runs on this head:
— sent from bold-dove-431 |
- LocalStoreDeleteAttempt carries the FilesystemDelete outcome itself; confirmed and refused deletes are split by matching it once, and receipts (eviction_delete_refused, the sweep's delete_refused) carry the refused attempts with their typed outcomes. - LocalStoreIndexRefusal carries the CAS layer's causes as they are (CasAttemptAdmission, CasStoreFailure, CasUnreadableSlot, window, decode, contention) on the index read, the index write, the reservation, the post-publish re-read, the sweep and recency. The one rendering to text is local_store_index_refusal_text, used only where std.materialization_object's realization-agnostic refusal takes a String; the commit receipt also carries the typed refusal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
LocalStoreRecordDelete says which file the host refused (the record, with its typed attempt; or its parts, with theirs) or that the root could not be listed, so no record is assumed partless. Receipts carry the record-level attempts. 24/24 store wet controls pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t named for its unit Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…75099) - The policy figure, the durable rows and the host ceiling move to gunbc.materialization_store_budgets (with a C2 consumer frontier); the transport keeps the budget shape, its sum and its enforcement, and every admitting/sweeping operation takes the rows as a parameter. Witness fixture rows live in the witness file. The catalog row is materialization_store_local_facts_at(ceiling) applied by the deploying layer. - local_store_doomed_bytes returns ByteSize and is the one doomed-bytes sum (reserve and publish); the reservation carries its budget, replacing a zero fallback; an unprepared commit has its own reservation arm. - design_argument leasing row: sentence boundary and doubled period fixed; DESIGN.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… through it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…moves to gunbc.materialization_store_budgets; the provider opens its store with root + budgets Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tier naming gunbc#13077 (review 75127) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Two changes in b37307b. 1. Merged the reworked C1 base (
2. Review 75127 is right, and fixed.
Remote runs:
— sent from bold-dove-431 |
…sion trigger, not a transcribed measurement (review 75170) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 75170: fixed in c6c7c40.
The transcribed per-binary sizes and the — sent from bold-dove-431 |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Retargeted to main after the store stack landed: merge commit 3a08c88, with parents the previous cutover tip and main a453be9. Merge. The stack was squash-merged, so a textual three-way merge carried stale stack content and differed from main in about 1,000 files. I rebuilt the merge as main's tree plus only this PR's own diff ( Adapted to main's final store API:
Also moved the live_deploy deploy-row annotation to module-item grain. Main is currently broken for every closure reaching the roadmap modules: #13388 removed
I'll merge main again once #13480 lands. — sent from bold-dove-431 |
…ncy binaries join by typed part id and digest, not path shape (review 77120) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 77120: both findings fixed in 74a8846.
Remote runs, with the
— sent from bold-dove-431 |
|
The — sent from bold-dove-431 |
… binaries are one verified reading per GunbcBinary; an uncitable compute claim run refuses Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 77173: all three findings fixed in 87ec0f8.
Remote runs on main with #13487 (no runner-side patches now):
— sent from bold-dove-431 |
…ts display word (review 77184 note) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
The
This PR does not touch that witness or — sent from bold-dove-431 |
|
Correction to my previous comment. The — sent from bold-dove-431 |
Dogfood G1, part 2 (node adhoc-cfe036d0-023): the shared-computation cutover. This PR is stacked on #13095 (C1b byte parts), which sits on #13081, #13082 and #13091, and it lands after that stack. It includes #13072, the compute request family with the ruling's fixes, which lands first.
What moves onto the real route
extdeps.realization.materialization_store_local, in the bounded per-host durable root.outcome.jsonis deleted.store_diris deleted.gunbc.materialization_store_budgetsmaterialization_store_compute_work_budget_policyis 1 GiB per host. The store transport receives budgets as a parameter, so the policy lives in that module beside the typed-module row. The budget must hold one build record percompute_pool_slots, with headroom. It is chosen rather than derived, because no instrument re-derives a build's size. The revision trigger (a build record refused for not fitting, or evicted while a dependent is in flight) is stated beside the row.compute_work_ladder_verdictjudges against the store's own family provider row. A build, a compile or a hermetic claim run is Discharged, so it is memoized. A wet claim run is ExemptFreshEffect, so it is recomputed.StoreLookupis routed directly.realize_route's only recompute-on-rejection arm isFreshnessExpired, and this store has no freshness window to expire. That is a stated divergence; the rule itself is kept whole.compute_dependency_readresolves the build's binaries throughlocal_store_lookup_parts. A build record that is evicted or tampered refuses; it never triggers a rebuild.GunbcClaimValidationnow runs asRunClaimsthroughcompute_provide, on the verified head's tree, in a capped unit.--claim-runit replaces. The argv now spells--wet. Before this,claim_batch's hermetic default ran "wet" requests hermetic.ValidationExecution.computationcites the request key, the outcome identity, the verified head's ExactTree, and whether the run attached or computed. A present-but-broken citation makes the receipt unreadable.gunbc.roadmap_belt_actuateshared_computation_observe_for_attempt(instance, attempt, head_sha)returnsSharedComputationObserved{head_sha, window_identity, citations},Absent{reason}orRefused{cause}.gunbc.live_deploy.specgets aMaterializationStoreDirectoryrow, which discharges thestd.materialization_store_granttrigger. Its path comes from the grant's datum.Evidence (claim_batch, remote; wet files run with
--wet)compute/work_request_witness_testmaterialization_provider_witness_testgetroster row retired on the runner only; #13064 retires it)materialization_store_witness_testmaterialization_store_local_wet_witness_testcompute/attempt_lifecycle_wet_witness_testroadmap/roadmap_verification_receipt_witness_testroadmap/roadmap_validation_oracle_witness_testroadmap/roadmap_belt_actuate_witness_testdevboot_subject_identity_witness_testcompute/work_class_grant_witness_testThe one store failure (
a_tampered_part_size_is_an_integrity_refusal) and the 7 belt failures (witness_exec_*, hermetic route gaps) fail identically on main 6d87482.attempt_lifecycle_wet'sa_build_record_round_trips_and_a_dependent_resolves_verified_binariesis the real-route claim the pure controls are paired with. It runs commit with staged parts, then attach, then dependent resolution, on a scratch root.Not in this PR
roadmap_verifyandsource_snapshot_handoffstill run claims through the host command; the brief covered belt verify.🤖 Generated with Claude Code