Repository navigation
mtcollins1 runner: extract qualification instruments from the run (leg 3b) - #13225
gunbai-bot[bot] wants to merge 71 commits into
Conversation
…inding (leg 2) One JIT mint over a slot sum (microVM cell | transient systemd unit on a gunbc.managed_host host); ensure-style deregistration with org-listing readback and typed refusal on every exit; teardown inventory generalized to a host-unit arm; census row for deregistration (pre-approved, ruling 2026-10-03); route legs registration/deregistration bound. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttempt label as input; collect the run back (leg 3) Generalizes extdeps.github.workflows CreateDispatch from the heal-only expected_healed_sha key to the upstream's own inputs object, and dissolves create_dispatch_unconsumed_frontier_rows with a production caller. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ack's subject is the dispatched run Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e the carrier-returning helper (constructor proxy) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ob log; claim-cost read refuses typed (leg 3b) Model the Actions artifacts (List workflow run artifacts, Download an artifact) and job-logs (Download job logs for a workflow run) REST operations in extdeps.github with upstream names; the 302 is followed by the bound REST handler. Parse [floor-phase] rows in gunbc.required_ci_phase_roster and [floor-cgroup] level rows in gunbc.host_budget_source, decoding values through extdeps.linux.cgroup_v2_memory. The collect stage reads each served job's log into typed readings or a typed refusal and attempts the claim-cost artifact read, carrying its typed refusal. The single extraction frontier row becomes three rows, one per missing capability. Supplied-input witnesses are paired with an inhabitance claim over a recorded required-floor log's verbatim rows. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/gentle-bear-467 # Conflicts: # dag/gunbc/runner/runner_qualification_dispatch.dag # dag/test/claim/runner/runner_qualification_dispatch_witness_test.dag
…pt, token check, workflow compare; split RouteLegStanding
(1) post-delete listing consumes the delete receipts (readback_after_deletes)
(2) JitRegistration sole_constructor, minted only by jit_registration_of
(3) refuse a token or authority for another App/installation
(4) JitDeregistrationReceipt sealed, built only from a GitHub listing
(OrganizationRunnerListRead sealed); pure classifier kept
(5) slots carry their workflow; mint refuses a group restricted to another
RouteLegStanding = LegWired | LegAuthorityImplemented | LegAwaitingAuthority;
route_is_executable requires LegWired; registration/deregistration are
LegAuthorityImplemented with the wiring they owe.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mplemented with the fleet-converge wiring owed Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… derived runner image until the untangle 4a runner medium Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion/jolly-bat-898
…ation line's absence from the log, with the recorded run as receipt Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Reviewed exact head 3be84a5ee342c43fafae5b87fb3cbcaadfdfea4f.
The provider-facing half is directionally right. The job-log endpoint is modeled as the upstream job-id read through its redirect, the artifact listing/download vocabulary is separated, a short page refuses, garbled tagged rows refuse rather than disappearing, and the missing claim-cost upload remains an explicit typed standing/frontier rather than being fabricated from the log preview. The recorded excerpt also discriminates the slot-level filter from the parent levels.
I cannot approve this head yet. Five structural blockers remain in leg 3b itself, beside the inherited #13211/#13206 findings.
1. The extraction authority is implemented but not wired, while the frontier says the two log instruments are done
collect_qualification_instruments has no production caller in this stack. CollectInstruments in the route carries only the instrument list; it has no authority standing, and route_is_executable checks only effectful legs. Therefore a future route can become executable without any edge to this collector.
The old broad extraction frontier has meanwhile been replaced by rows only for claim cost, boot readback and cohort observation. That reports FloorPhaseRows and FloorCgroupRows as consumed when only witness calls reach the fold.
Represent the same split #13206 is moving toward: extraction authority implemented vs extraction wired into the route. Keep a frontier/awaiting standing until the production route invokes this exact collector, or land the orchestrator edge in this PR. A witness calling the pure fold is not that consumer.
2. Target, run and slot identity are independently cross-wirable
The production entry is:
collect_qualification_instruments(
target: QualificationWorkflowTarget,
collected: CollectedQualificationRun,
slot_unit: NonEmptyStr,
)
None of those three values is joined. A real collected run can be combined with another repository/workflow target for the log/artifact reads and another unit name for the cgroup suffix filter. CollectedQualificationRun does not retain the sealed dispatch or the authorized JIT slot, so this function cannot reject the cross-wire.
The effect must consume one sealed extraction subject derived from the dispatched run plus the authorized JIT registration/host-unit slot. That subject should own the repository/workflow/ref, run and run-attempt identity, designated floor job, runner id and exact systemd unit. No caller-supplied target or unit string should remain at the effect boundary.
Required REDs: a target from run B beside collected run A refuses before a network read; slot B beside run A cannot select any cgroup row.
3. A successful extraction is forgeable and loses the read evidence
QualificationInstrumentsRead is an open variant, extract_qualification_instruments is unrestricted, and AttemptJobLogRead plus ClaimCostArtifactRead are caller-authorable. Any caller can directly author a successful extraction, or obtain one by feeding invented log text to a real CollectedQualificationRun. The construction wall added in #13211 stops fabrication of the collected run, but not fabrication of what that run supposedly measured.
Keep the pure decoder witnessable, but make the production success receipt construction-confined and mint it only downstream of the actual GitHub reads. Retain the source evidence in that receipt: sealed dispatch/collection identity, each job id, a digest and byte count of each complete log body, the read outcome, and the artifact-list/download receipt. A later assessment must not have to trust rows detached from the bytes and job that produced them.
Controls should pin direct-literal refusal, an outside call to the production constructor, and a supplied log whose job id is not the designated collected job.
4. Rows from different jobs can be combined into one apparent floor measurement
conclude_qualification_run still identifies jobs only by attempt label + started_at. Leg 3b downloads every such job and flattens all phase and cgroup rows. Phase rows from job A and a slot cgroup row from job B therefore satisfy one QualificationInstrumentsRead; the success payload drops the source job identities entirely.
This PR cannot retire the job-log instruments before #13211's exact-floor-job/runner-identity blocker is closed. Carry the minted runner id into collection, identify the actual floor/instrument-producing job, and read that job only—or retain readings per job and require both instrument classes from the same designated job. Add the split-across-two-jobs RED.
5. The result and local field types overclaim what is established
QualificationInstrumentsRead is constructed while claim_cost may be ClaimCostArtifactAbsent/unreadable and while GuestIdleMeminfoAndNproc and ConcurrentCohortSeatWindows are not represented in the payload at all. That arm therefore does not mean “qualification instruments read”; it means only that the two job-log instruments were decoded. Model a standing per instrument, or narrow the arm to QualificationJobLogInstrumentsRead, so a downstream route cannot interpret partial extraction as the completed collect stage.
Also:
FloorPhaseTimed.wall_msshould use the existingstd.measuremillisecond carrier rather than a bareIntwhose unit exists only in the field name.- The three new REST operations declare exact
500only. Use the repository's5xxresponse arm so 502/503/504 remain typed unreadable outcomes instead of falling outside the claimed refusal surface.
I accept keeping claim-cost parsing open: the workflow currently does not publish the named artifact, and the present text-only REST realization cannot open the zip. Mapping a download-time 410 to ClaimCostArtifactExpired rather than generic archive-unreadable would be a useful local correction, but it is not an additional blocker.
Exact-head required CI is currently queued. The supplied 13/13 result and the live redirect read support the parser mechanics, but they do not close the construction, subject-binding and route-wiring gaps above.
…verged on the floor) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tter's reading; the interpreter's after #13228) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/gentle-bear-467
…ambiguous standing, App-token credential, runner-id floor join, attempt-1 binding, ruling+interpretation+interlock - QualificationDispatchSubject (sole_constructor) minted only from the route's JIT registration and its delivered credential, the slot's workflow == the generated fleet-converge workflow, and a floor job whose runs-on is exactly the declared attempt input; REDs for other workflows and labels - dispatch classified through RestMutationExchange: 4xx refused, transport/5xx/undecodable ambiguous - CreateDispatch takes its bearer as an input; dispatch runs under the gunbai-ci installation token, credential checked against DispatchWorkflow; takes the host-generic UnitHoldProof (interlock) - collection: attempt-scoped jobs, run_attempt == 1, revision pinned, workflow path, and the floor job's runner_id == the minted runner id; collected payload keeps the sealed dispatch + WorkflowRun - WorkflowJobRun gains runner_id/runner_name (upstream job resource fields) - census: IrreversibleEffect, discharged by the 2026-10-03 ruling (verbatim) through a separate scope interpretation (eager-gull-22, 2026-10-04); interlock rostered; narrowed-interpretation RED Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…esignated job, sealed receipt with evidence, per-source standing, collect leg not wired 1. The collect stage carries a RouteLegStanding (mtcollins1_collect_leg, LegAuthorityImplemented) that counts toward route_is_executable; the log instruments keep a frontier row until the route invokes collect_qualification_instruments. 2. collect_qualification_instruments takes the sealed DispatchedQualificationRun, the collection and the authorized JitRegistration -- no target or unit argument. QualificationExtractionSubject (sole_constructor) is minted only when the run, attempt and host-unit slot agree. 3. QualificationJobLogReceipt (sole_constructor) is minted only by job_log_standing (admit_callers: collect_qualification_instruments) after the network read, and carries the subject, the log's code-point length and content digest, and the rows. The decoder stays open and identity-free. 4. The floor job is the one served job whose runner_name is the registration's name; zero or two refuse, and only that job's log is read. WorkflowJobRun regains runner_name with this consumer. 5. Per-source standing (QualificationJobLogInstrumentsRead / claim_cost) replaces the instruments-read arm; wall is std.measure Millisecond; new operations use 5xx; a download 410 is ClaimCostArtifactExpired. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n_ref_in_list arity, no panic) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressed at 1. Collect stage implemented but not wired.
2. Cross-wirable target, run and slot.
3. Forgeable success that loses its evidence.
4. Rows from different jobs combined.
5. Overclaiming result and field types.
Evidence:
|
…rolled -- with the capability that would enrol it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the minted JitRegistration name); drop runner_id; fix witness braces Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Re-reviewed exact head 3199c077fdd92fffd39e5f46ad6a9953b79ce3ca.
The five leg-3b findings on 3be84a5 are substantially improved:
- the collect stage now has an explicit
LegAuthorityImplementedstanding and participates inroute_is_executable; - target/run/slot inputs have been replaced with a sealed
QualificationExtractionSubjectand pre-read run/attempt checks; - the job-log success is a sealed receipt minted only downstream of the network read and retains the source subject, complete-body digest and length;
- readings are no longer pooled across every attempt-labelled job;
- the result is split by instrument source,
wall_msis typed asMillisecond, the REST interfaces use5xx, and 410 is an expiry.
Three subject-identity gaps remain in this head, plus two required stack reconciliations.
1. The registration is not joined to the dispatched workflow/repository
QualificationExtractionSubject retains both values, but qualification_extraction_subject compares only:
- dispatch run id to collection run id;
- dispatch attempt to collection/slot attempt;
- runner name to job runner name.
It never compares registration.organization with dispatched.target.owner, and never compares the host-unit slot's workflow with the target's owner/repo/workflow/ref identity. Therefore a valid registration for workflow B can be paired with a dispatch to workflow A when the host and attempt spelling are the same.
The subject mint needs a structural workflow target carried by both registration and dispatch, or a total canonical comparison over owner, repo, workflow id and ref. Required REDs: another organization and another workflow/ref refuse before the log or artifact read.
2. “Floor job” is still inferred only from runner name
designated_floor_job chooses the sole served job whose runner_name equals the registration name. It does not inspect WorkflowJobRun.name or any job identity declared by the target workflow. The witness's helper constructs every candidate with name: "floor", so it does not discriminate this gap.
A helper job can be the sole job on the minted runner while the actual required-floor job runs elsewhere; this code will call the helper the floor job and read its log. The parser will often refuse, but that is not proof that the measured job was the pinned workload — another helper could emit the same tags.
Bind the extraction subject to the declared instrument-producing job identity of the target workflow and require both runner identity and job identity. Required control: helper on the registered runner + floor elsewhere refuses; the declared floor job on the registered runner admits.
3. Reruns and the executed revision are still erased
collect_qualification_run still calls ListJobs, whose default is the latest attempt. It neither uses the available ListAttemptJobs operation nor checks WorkflowRun.run_attempt against every WorkflowJobRun.run_attempt. CollectedQualificationRun then drops run attempt, head_sha, workflow id and event identity beyond the one-time check.
A rerun therefore keeps the dispatch run id but silently replaces the jobs and conclusion used by this extraction. The sealed receipt also cannot later establish that the bytes came from the exact FloorWorkloadPin.revision being assessed.
Use the attempt-specific jobs read or refuse when the run has advanced beyond the admitted attempt; carry the observed run attempt and head_sha (plus target/workflow identity) in the sealed collection/extraction subject. Required RED: attempt 2 under the same run id cannot stand in for the run created by the admitted dispatch.
Stack walls still present at this exact head
This branch still contains the #13206 ccad694 construction hole: jit_registration_of accepts the open JitMintDispatchAuthorized arm, so an outside caller can proxy-mint the sealed JitRegistration on which this extraction subject relies. It also contains the older #13211 dispatch/collection implementation, including mutation outcomes collapsed to QualificationDispatchRefused. Those base change requests must be resolved and this branch rebased before the seal here has the standing claimed for it.
Required prerequisite reconciliation
- #13228 must land first. This exact head correctly uses bare
response_format: Text; under the old interpreter the live read is still decoded as JSON. - After #13227 lands, the claim-cost frontier and PR body become stale: the required workflow does upload
required-floor-claim-cost. Rebase and narrow that row to the remaining binary-body/inflate/member-read capability; do not continue to cite absence of the upload as half of the open trigger.
The one-time seal probes are reported at the right rung — checked once, not enrolled — and I accept that statement. Exact-head CI is still running. The blockers above are subject and stack semantics, not witness-count issues.
…mplate expression (floor NonFoldResidueRosterDiverged) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… joined floor job; one join, not two collect_qualification_run now joins the floor job to the minted runner (job_ran_on), so leg 3b's designated_floor_job and QualificationExtractionSubject are deleted; the receipt carries the sealed CollectedQualificationRun and the registration's host-unit slot. Log and artifact reads are token-bound beside read_run_with in gunbc.github_effect_perform. ActionsArtifact keeps only the fields a consumer reads (review 75456: the unread size_in_bytes Int is removed, not wrapped). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 75456 ( Nothing in the change reads The same head merges #13211 Local evidence on this head: 14/14 dispatch witnesses and 29/29 route witnesses pass. Seal probes on the new signatures: forged receipt 1, outside call 1, control 0. That remains "checked once, not enrolled". |
…uery subject (side-chat RC on #13206) (1) JitMintDispatchAuthorized { dispatch: AuthorizedJitMintDispatch } sole_constructor, minted only by dispatch_jit_mint; dispatch_jit_mint, attempt_dispatch and the witness helper `dispatched` are admit_callers-sealed so no admitted caller returns it onward. (2) OrganizationRunnerListRead carries organization, name, App and installation; readback_subject_refusal runs before the answer is read; conclude_from_readback, its inner step and readback_after_deletes admit only ensure_jit_runner_deregistered. REDs: compile probe test.probe.jit_deregistration_forged_probe (victim-runner forgeries of all four sealed records + unadmitted conclusion) enrolled by test.claim.jit_deregistration_forged_probe_witness; pure readback-subject RED. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head af96af4bdf5ead38423fbcced2fdb51ea9b9fbb1, against DESIGN.md §§3/3c, 4b and 5. The inherited-base-only blocker from the review at 3641482933 is closed, and the accepted leg-3b confinement repair remains intact.
GitHub's comparison establishes that the now-approved #13211 head 7ebc19e01aa6076c4d5acc87089a2c00570589a6 is an ancestor. The merged source keeps its planned collection: collect_qualification_run derives run identity from the sealed dispatch, calls plan_qualification_collection with the actual token identity, and performs reads and constructs the collection only inside the admitted arm. The deleted unchecked collection helper is not restored. The receiver and generate-fold seals are incorporated as well.
The leg-3b entry independently checks its actual token through collect_read_plan using the same token_names_registration. collect_qualification_instruments_under still admits only that checked entry and takes only (collected, token); its job and run ids come from the sealed collection, not independent arguments. read_claim_cost_artifact remains confined to that helper. There is no newly opened route around either token check or the collection's designated job/run.
The combined real-mint claim retains BOTH planner discriminators: foreign App and foreign installation plan no collection reads and no instrument reads; matching identities retain the exact run, attempt and floor-job read plans. The previously accepted outside-helper and free-token artifact-read probes remain outside the changed-file delta. The merge does not replace either check with a constructed success plan in the production entry.
The extraction frontier remains honest: the log path can produce its own instrument receipt, while binary archive/member parsing, boot readback and cohort observation remain separately owed, and production wiring is still required. Approval does not claim a completed throughput qualification or authorize a live dispatch.
Reviewed the correction from 3641482933, base ancestry and merge differences, the exact merged collection/extraction paths and combined witness, and prior discussions. Dispatch 21/21, route 29/29, forged 5/5 and mutation results are author-reported; I did not run local tests, mutants or network/hardware actions. Exact-head witnesses run 37253102577 was still in progress. The head was unchanged immediately before submission. Land after #13211, preserve the accepted #13288 changes when integrating the sibling, and retain required exact-head checks; approval of this tree does not automatically cover a later merge/rebase head.
… conflict resolved keeping both sides' imports and claims Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s; covers is the single source of which rows take its discharge (branch-pin sites dropped: federated on their own parameters); claim pins the iff Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion msg_5756a200) recorded as its own row beside the verbatim 10-03 ruling, replacing the agent interpretation; dispatch and branch pins back in covers and every covered row derives its discharge from it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/test/claim/authorization_pattern_selection_witness_test.dag
…ion/gentle-bear-467 # Conflicts: # dag/test/claim/authorization_pattern_selection_witness_test.dag
… row takes it only if covers names it); covered sites the selection federates on their own parameters -- registration, deregistration, the reversible branch pins -- do not consume it and owe no interlock Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/gentle-bear-467
…ts own federated standing, not by the 10-03/10-05 rulings; covers lists ensure_qualification_ref_pin for its branch create only Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion/gentle-bear-467
…me field, no RestExchangePerformance) Conflicts: github_effect_perform.dag (imports; the generate fold takes main's RestResult and keeps this branch's admit_callers seal) and github_effect_perform_witness_test.dag (main's RestAnswered call, this branch's sealed BoundJitCredential pattern). Beyond the conflicts, the port touches logic: this branch's REST ops drop their outcome fields (CreateDispatch's body is now result: WorkflowDispatchReceipt), the qualification performers carry RestResult<T>, and the dispatch, run collection, ref pin and branch removal decisions match RestAnswered/RestRefused and classify only the refusal (classify_rest_refusal, read or mutation). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The three new operations drop their outcome field; read_job_log_with / list_run_artifacts_with / download_artifact_with carry RestResult beside the sealed read; job-log and claim-cost refusals carry RestExchangeRefusal from classify_rest_refusal (a download 410 stays ClaimCostArtifactExpired). Witnesses build supplied RestResult values through small helpers. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… UnimportedBareProvider) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact requested head ee6a021a5ce43cbb2512ae270a43988ab49da36d, against DESIGN.md §§3, 4b and 5. The RestResult port preserves the accepted leg-3b decisions and confinement. GitHub's comparison confirms that the separately approved #13211 head 15eb7f6b1a16bf967cca27513522d3ae344cc536 is an ancestor.
The job-log, artifact-list and artifact-download performers now carry RestResult over their actual payloads. They project answer.log, answer.result and answer.archive only inside RestAnswered and preserve RestRefused; no failed exchange is paired with an invented successful body. actions_artifacts continues to bind auth_input to the supplied token, and the explicit Text import resolves the existing serialization name rather than introducing another response-format authority.
The consumer uses main's classify_rest_refusal with RestReadExchange for unreadable logs, lists, run readbacks and archives. A download's explicit 410 still has its existing expiry meaning. An answered archive still yields ClaimCostArchiveNotInflatable, not a parsed TSV or completed instrument reading. The binary-body/member-inflation frontier is not discharged by adopting RestResult.
collect_qualification_instruments still plans against the actual token's App and installation before any read. The only admitted caller of collect_qualification_instruments_under is that checked entry; _under takes only the sealed collection and token, deriving the designated job, run and host-unit slot itself. read_claim_cost_artifact remains confined to _under, and job_log_standing remains confined there too. The compiler probe retains the literal, receipt-mint, unchecked-helper and free-token/run-id controls beside the names-only control. The base's sealed JIT delivery and planned run collection are not replaced by a competing path.
The artifact decision still refuses incomplete lists, zero/multiple matching names, expired artifacts and unreadable reads. The run is read after the listing and must still be at the dispatched attempt before download. The port does not reintroduce first-match duplicate selection or infer attempt identity from the run id alone.
The successful job-log receipt still retains the sealed collection, its slot, complete-log digest and code-point count, and decoded readings. Phase and cgroup rows come from that one designated job, and the slot-level filter is unchanged. A job-log receipt is not a claim that the artifact, boot or cohort instruments were obtained; the per-source standing and implemented-but-unwired collect frontier remain explicit.
Verified the exact-head witnesses workflow 37318668116 completed successfully. The remote Hermetic dispatch 21/21, route 29/29 and forged 5/5 results are author-run receipts; I did not execute claims, mutations, live API reads or hardware operations. The requested head remained unchanged and mergeable before submission.
No source blocker remains in this port. Land after its base and through the normal required landing-head checks. This approval does not cover a later merge/rebase head, archive-reader completion or the eventual live qualification/boot wiring.
|
Heads-up before queueing: this PR adds |
|
Superseded by #13641 (v1 closeout): this head is an ancestor of integration/v1-closeout. |
* dispatch-actuator witness: import the lineage, alignment and ticket names #13622's specimen uses Review 78285 on #13622: the supplied-specimen claims call lineage_walk, lineage_is_rooted and alignment_chain and build TicketLine/TicketFields/NodeParent/AdmittedRoot/RoadmapNodeIdentity without importing them. They resolved only through the flat bare-name tier DESIGN schedules for removal, so they would go red when it is cut. Import each from its declaring module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert "Merge #13548 (session/sharp-deer-755-unimported-type-import-migrate) into integration/sharp-raven-357" This reverts commit 1a22abd, reversing changes made to a04255a. * native_emission_controls: repair integration union (close variant_literal_application_cases, one roster, one composition over all 17 case groups) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Exclude #13604 from integration/eager-gull-22: WIP, open REQUEST_CHANGES (review 78326) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs/design-rung-drops.md: regenerate through tools.docs_projection_gate regen after the #13569 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * grammar: import int_to_decimal_string from std.integer (#13436 moved it; #13379's binding-power row still named v2.std.integer integer_int_to_decimal_string) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: mtcollins1 runner: boot leg, runner image medium + runner-host-up termin * Realize reviewed kernel dependencies through guarded host maintenance * Rewrite the cross-module record-field pin to the refusal it named as its trigger. Infer now refuses `n: true` against `RcfFar` declared in another module; keeping the counted-Undecidable pin would be a meaning fork of the same claim name. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the post-main census: drop the Map interpolation hole, concat the spatial cast. Merging main reintroduced one implicit stringify (Map Display in the canonical-order witness) and left the spatial_dimension `{o as String}` template as a v1 span mismatch. Named Int/Nat/Symbol routes stay; the Map hole is deleted rather than given a fourth renderer. Co-authored-by: Cursor <cursoragent@cursor.com> * Regenerate fleet-converge.yml via generated_artifact_gate main_wet Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Remove scratch witness scripts committed by the close-out flush (review 78354) The wind-down flush committed untracked local files (.runwit*.sh, .probe2.sh, .wit/) as 32dcf74. They are local receipt scaffolding, not part of the boot leg. This restores the tree to 80c24b3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * cax onboard: enumerate the closed-coproduct arms the floor's non-fold residue check refused approved_grant_policy, plan_against_policy and provider_controlled_host matched closed coproducts with a wildcard arm; each arm is now explicit, so a new variant refuses at compile rather than being absorbed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * v1 closeout: open PR accounting Every open PR, with its owning lane and its disposition in the mega branch. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: add the side-chat dispositions and wave 2 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 emit_rust mirror for the integrated authorities (first_generation_equal=true, 0 installs on pass 2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: bold-bee and qwen dispositions Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: outstanding work, closed PRs, and a re-sweep of all 162 open PRs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: #13607, swift-bat-828 branches Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration/silent-lark-156: regenerate generated artifacts after merging #13472 and #13610 Produced by main_wet + claim_executor --required-regen on BuildBuddy at fd4421d; second regen round installed nothing (fixed point). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: silent-lark, gentle-dove, royal-moth, neat-boar, nimble-heron, valiant-crab handoffs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Second-type OpenRouter Retry-After and quota term (review 78356) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: lively-ram and silent-lark handoffs, #13460 folded, #13108 and #13330 dispositions Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md and the v1_compiler_emit_rust stage0 mirror for the integrated tree Generated through docs_projection_gate regen and claim_executor --required-regen on srv1; round 2 reports first_generation_equal=true (a fixed point). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: #13488, #13574, #13475, #13634 reviews; #13648 closed; archive-flush residue Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * provisional: gentle-dove-36 mirrors for conflicted generated files (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Revert "Merge #13574 into integration/gentle-dove-36" This reverts commit 32720e2, reversing changes made to eee50a4. * provisional: v1_rt.rs from silent-lark-156 (carries host_budget_darwin_physical; seed bootstrap, regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * provisional: v1_rt.rs = v1-closeout + silent-lark-156 delta (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: sharp-raven report, #13265, #13574 revert decision Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * provisional: append rt_host_budget (HostBudgetJoin*) to v1_rt.rs (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Fix stderr-capture tests so they hit real routes, not decoys. Delete the rustc program that returned Err before spawn without compiling emit_shell_stderr_policy_binding; absent policy is already refused at the emit diagnostic wall. Drive Complete limits from the live host-budget join and keep drain specimens on the emit_rust authority strings. Co-authored-by: Cursor <cursoragent@cursor.com> * fabric_quota: re-attach the window-start comment to quota_window_start (review 78371) checked_second had been inserted between the comment and the function it documents. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Required CI: withdraw the four v1-judged lanes; the gate is emit-build alone (operator ruling 2026-10-09) The operator's v1 withdrawal: v1 is no longer a validation authority, and the one use left to the seed is emitting v2. gunbc.compiler_gate_workflow drops `floor`, `generated`, `rust-unit-tests` and `seed`; the `witnesses` aggregate reads the one remaining lane, `emit-build`, through the same folded roster (one row). The GateArmSkippedOnPullRequest arm leaves with its only inhabitant. The loss is one declared drop, gunbc.rung_drop v1_required_lanes_withdrawn, stated member by member (witnesses, stage0 mirrors and every generated artifact, lint, v1 unit tests, module resolution outside the two emitted closures, the downstream consumers), with a trigger that names the capability: a binary built from an emission of v2 judging that population on the required path. rust_unit_tests_off_pull_requests is Superseded (its lane runs nowhere; trigger did not fire; the new row holds the loss). gunbc.required_ci_contract_epoch moves to 2026-10-09.1: the name `witnesses` now carries a materially different contract. Consumers repaired rather than left dangling: the lane-resolution census roster (the census now does not hold by design and is the instrument that re-derives the drop's module population), DESIGN section 3's typed required-gate reference (gunbc.documentary_refs, now emitted_subject_build_rows), the Building & checks rows, the onboarding path's run-witnesses step, five recurring_failure_mode evidence rows that cited deleted declarations, and the two gate witness files (the blocking set is asserted as exactly emit-build; a new RED asserts the four withdrawn variables reach neither gate surface). Projections regenerated by tools.generated_artifact_gate main_wet (the run peaked at 15.8 GB RSS, against the 7.55 GiB that module's own note cites for 2026-08-31): witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/onboarding.md; every other rostered artifact came out byte-identical. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Drop process-global budget env from stderr-capture tests. review 78373: planting Complete limits through GUNBC_MEMORY_BUDGET_BYTES leaked into parallel tests and did not inhabit the emit bind. Claim the drain strings only; leave the host-budget join uncovered. Co-authored-by: Cursor <cursoragent@cursor.com> * regen round 0: stage0 mirrors from claim_executor --required-regen (supersedes provisional splices) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * provisional: re-append rt_host_budget to v1_rt.rs (round-0 regen emitted v1_rt.rs without it; seed bootstrap) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * regen round 2: stage0 mirrors (v1_rt.rs now emitted with rt_host_budget; hand-appended lines gone) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate generated artifacts for integration/eager-gull-22 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * required_ci_phase_roster: import std.optional (v2.std.optional moved by #13388; stale import from #13225) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: all lanes reported; remaining merge plan; closed auto-opened PRs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert #13123 (admit_callers enforcement: mega's AdmitCallersEdge is the one enforcer) * v1 closeout accounting: #13516 folded, #13212 dispositioned; every lane reported Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop #13545 transcribed-count red chunk (counts derive from ci_runner_sudo_binaries); retarget caller-admission real-route evidence to exact counts Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: eager-gull review outcomes, #13608 newer head, updated plan Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop the seed-growth citation of the deleted absent-policy decoy. review 78381: hand_authored_declarations still named emitted_absent_policy_refuses_before_spawn after that test was removed. Absent policy stays cited as capture_channels_without_stderr_capture_input_refuse_the_union. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert #13586 (receipt-only, excluded by operator review) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Revert #13453 (base-compiler/floor protocol; excluded by operator review): seed Rust, workflow steps and the script-row refusal API go with it Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * WIP: one required job, fresh products, memory envelope, heal-publish deletion (pre-merge, projections not yet regenerated) * stage0 mirrors: restore generated mirrors to the mega branch's coherent set pending one regen round Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * floor_route_gap: give the belt exit-drain expectations their own chunk_43 Two folded PRs (#13442's seeded_filler rows and #13125's belt exit-drain rows) each added floor_route_gap_expectation_chunk_42. The second silently replaced the first and the native emitter refused (duplicate declaration). The exit-drain chunk becomes chunk_43 and joins the roster, so both expectation sets are read. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * live_deploy: reconcile #13599 with #13583's directory authority #13583 made owned directories the single directory authority (directory demands; host_directories) and removed the directory kinds from the ensured steps and the instance parameter from deployment_ensured_steps. #13599, folded alongside it, still called deployment_ensured_steps(instance:, target:) and its witness matched on the deleted step kinds. The call passes target only, and the lab-vs-production fabric-store claim now counts fabric_storage_store_directories demands in deployment_directory_demands. Same claim, read through the surviving authority. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * roadmap_task_record: JSON codec for a runtime RoadmapNode (piece 1, uncompiled draft) * roadmap_task_record witness * roadmap_task_store: chain-partition roster over the fabric state binding, with wet witness (draft) * roadmap_task_record: parent and centering required on the wire; drop nested optionals Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * managed_host: a superseded rung drop is not a standing citation drop_is_standing_citation matched RungDropStanding with Retired and Standing only. Superseded has existed since the 2026-10-06 supersession, and the closeout's seed refuses the non-exhaustive match, which reaches every closure through managed_host (generated_artifact_gate included). A superseded drop no longer stands, so it is not a citation, the same as Retired. (Found by smart-gull-336.) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: federation retired-path row below imports; floor_demand pinned envelope rows; managed_host Superseded arm (pre-regen) * Headless Claude dispatch: print argv, systemd unit, stream-json projection. When the harness has no spark, ExecutorDefault can admit Claude if custody is present; events stay in the belt's Codex envelope. Credential converge on srv1 remains an operator decision. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API 6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API 6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit 94464b1) * roadmap_task_record: balance ticket decode braces Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address review 78387: one Claude event mapping, explicit executor, transmit effort. parse_codex_jsonl now classifies bounded Claude stream-json via claude_code_line_codex_kind; jq only bounds those lines. ExecutorDefault stays a harness refusal. Print argv carries --effort. Co-authored-by: Cursor <cursoragent@cursor.com> * v2 compiler: reconcile #13438's precedence climbing with #13582 and #12942 Two merge-born references to deleted code, found by emit-build on #13641: - 02_parse: #13438's infix stamp still wrote ParseProvenanceState.frame / FrameMinted, which #13582 deleted with the packrat memo. The write goes; the sibling stamps already carry none. - body_lowering_fold: #12942's sealed body_lower_fold_raw kept the pre-#13438 pipe-tower test (body_lower_is_pipe_tower_root / body_lower_tower_pipes_into_fold), which #13438 deleted. It now uses #13438's replacement predicate, body_lower_application_pipes_into_fold, and keeps #12942's sealed outcome. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fleet_converge_workflow: drop MtCollins1UiBundleObserve from the mode list #13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list now resolves to a declared variant. (Found by smart-gull-336.) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: trip is a ByteSize derived from the slot envelope (review 78388 item 3); witness claim the_trip_sits_inside_the_slot_envelope * Address review 78389: emit tmux event pipe only for tmux containers. Claude and harness systemd spawn no longer derive readiness from tee/pipe emission or refuse as tmux-event-pipe-emit. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: two stale references from folded deletions - first_element_of_a_list_has_three_spellings cited v2.std.optional Optional; the module is std.optional (#13388's move). - authorization_pattern_selection_witness imported PastedOperatorToken, which #13568 removed with the pasted-token refusal; the import was unused. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerated projections for the one-job gate, on the merged closeout tree One main_wet of tools.generated_artifact_gate over this branch merged with integration/v1-closeout a925452 (regen 632 s, verify 693 s, both exit 0, on srv1 under capped MemorySwapMax=0 scopes), nine artifacts: - witnesses.yml: both subject steps carry GUNBC_BIND_MEMORY_CGROUP_BYTES (the derived trip, 20 GiB) and the failure notice carries the envelope lines (what 137 means, no larger runner and no retry, the MEMORY RECEIPT). - DESIGN.md, docs/design-rung-drops.md: the CI row and the drop roster. - .gitattributes: the deleted heal-publish.yml leaves the generated-artifact merge list. - fleet-converge.yml: the closeout's authority fix projected. - tools/fabric_ci_fci1_bounded_execution_context.env: the fci1 context follows the slot (22/21 GiB). - provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: a 22 GiB slot fits more slots per host than a 26 GiB one, so the derived rosters grow (srv1 gains srv1-10 and srv1-11). Desired state; applying it is the converge effect. The witness batch on the same tree: 16 files, green except the two latent reds already recorded in the PR (fci1_bounded_execution_context: a stale envelope-basis expectation; heal_publication_boundary: 23/34). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Enrol roadmap_task_store wet witness on the local-repo wet lane, as the allocation seam witness is Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Land the v2 cutover program as designed roadmap entries: 11 nodes, native_obligation_population plan, edges, RED acceptance witnesses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md belt_liveness_publication_answers_unconsumed Ledger-Rows-Repaired: docs/design-rung-drops.md bmc_secure_apply_converge_new_witness_eval_step_cost Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci Ledger-Rows-Repaired: docs/design-rung-drops.md fixture_closure_union_unmodeled_stderr_capture Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer Ledger-Rows-Repaired: docs/design-rung-drops.md kvm_observer_protocol_wet_witnesses_deleted_with_the_observer Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost Heal-Candidate-Run: 38000315997 * closeout: regenerate stage0 mirrors and workflows from the folded tree One emission round (operator ruling 2026-10-04) on srv1 at a925452: claim_executor --required-regen, then generated_artifact_gate main_wet. Then on the regenerated tree: seed build OK, gunbc test //gunbc/instruments:v2-native-cli exit 0, //gunbc/instruments:self-host exit 0. Settles the files the folds left provisional (fleet-converge.yml, the std_* and v1_compiler_* mirrors). docs/design-rung-drops.md was already regenerated by CI auto-heal (17a309c). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: option B -- subject steps require the slot envelope; per-step trip withheld by the declared drop native_step_trip_awaits_fleet_job_cgroup; slot-grain receipt in gunbc test; seed-growth receipt (pre-regen) * Enrol roadmap_task_store wet witness in floor_route_gap and the local-repo wet terminal, as the allocation seam witness is Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate ROADMAP.md, docs/plans and .gitattributes for the cutover rows; repair updated(...) wrapping Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Describe the envelope as slot-grain (option B) in witnesses-one-required-job; regenerate projections on the merged head Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Type the cutover receipt readings (closed kinds, ByteSize) and make the peak-above-trip control compare against the slot trip Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Subject steps require the slot envelope; the per-step trip waits on a fleet fact; the envelope decision is a .dag fold the seed mirrors The first required run that passed GUNBC_BIND_MEMORY_CGROUP_BYTES (38002497388 on a4b8f78) refused in four seconds: MemoryCgroupBindRefused, the cgroup2 tree is not writable. memory_governor apply_memory_cgroup_bind creates its leaf at the cgroup ROOT (a container-root design; the bind had never been requested on the fleet) and a fleet job runs as the setpriv'd job user under a root unit, so no job process can create the bound. The operator approved the slot-grain arm (escalation 2026-10-09). gunbc.memory_envelope (new) owns the decision and the verdict as folds over supplied inputs -- the sibling of gunbc.memory_cgroup_binding -- and test.claim.memory_envelope_witness_test reaches every arm by supplied value, including the RED an inline decision could not: a slot requirement over a process no numeric memory.max binds REFUSES (MemoryEnvelopeAbsent) rather than running as bounded. The seed mirrors it arm for arm with unit tests; the shells resolve the bounding cgroup through binding_cap_cgroup_dir (never the peak locator), read memory.swap.max/.current/.peak (modeled in extdeps.linux.cgroup_v2_memory) before and after the producer, print a slot-grain MEMORY RECEIPT with event deltas and the peak labelled by whether it rose, and refuse the run on any OOM kill or swap. gunbc.emitted_subject_build_gate carries two envelope inputs and ONE decision over them, native_step_memory_inputs(ownership): every subject step REQUIRES the slot envelope (GUNBC_MEMORY_ENVELOPE_REQUIRED=slot, the projection of EnvelopeSlotRequired) and the bind input at the derived trip is withheld while gunbc.runner_slot_desired gunbc_runner_slot_job_cgroup_ownership is JobOwnsNoBoundedCgroup. That is a fleet fact, not a rung drop -- nothing on the required path ever held the trip -- so the climb is rostered as gunbc.guarantee_stall native_step_trip_awaits_fleet_job_cgroup_stall (grounding: unit delegation with DelegateSubgroup=, a per-job cgroup staged by the root JIT wrapper, the governor's already-bound arm). The workflow and the failure notice consume the fact; the witness exercises both arms by supplied value, reads the live row, and asserts the bind KEY is absent. The slot wall follows the ruling too: gunbc.runner_slot_allocation gunbc_runner_slot_allocation_wall_holds drops its three floor conjuncts (a slot sized to a tenant that no longer runs in it) and requires MemorySwapMax == 0 instead of a swap above the maximum; the floor-fit drop slot_row_pinned_below_demonstrated_demand_unrefused is Superseded with v1_required_lanes_withdrawn as its loss holder; the slot witness re-pins the row to 22/21/0 and its width alarms to the smaller slot's derivation (srv1 12, srv3/srv4 21). The slot's demand oracle from here is the first cold required run's MEMORY RECEIPT, a declared frontier. The trip stays a ByteSize derived from the slot (review 78388 item 3). The seed growth is receipted as gunbc.memory_envelope_receipt_seed_growth (review 78391). The design document's CI row and the slot row's note say the same. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * emit_rust: locate module via ModuleIndex.by_name; is_known_variant reads carried variant_to_enum (port of #13608 23f2d08, 8ff94ca; mirrors pending regen) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * decimal_digit_of_units: construct the units digit via the successor table; no D9 default for out-of-range Int * closeout: bind variant_to_enum correctly at three #13665 call sites import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate ROADMAP.md on the merged head; re-cite the envelope fact and stall Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Take sold Group B (srv9-srv12) out of everything that reaches hardware; declare fixture residue as a rung drop Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Supply sold Group B (srv9-srv12) as in-witness fixture population; production rosters stay empty Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that discriminated on the Group B population (commitment standings, admissibility, rail rows, topology membership, reach labels) read nothing. spark_host_commitment_witness now folds the production placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate std_integer stage0 mirror (remote required-regen candidate) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * closeout: revert #13662's fold (operator decision 2026-10-10) #13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Recut to five durable outcomes: cold-run envelope receipt rename, acceptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * roadmap: split the event carrier's directory demand into a leaf module gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status -> host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories -> roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory; the carrier, the directory list and the owned-directory witness import it from there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Address review 78405: delete the never-red frontier-count decoration; eligibility and disjointness controls run over supplied members Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * closeout: five merge-born refusals that main_wet found - managed_host: HostnameAllocation no longer carries canonical_hostname; read it through allocated_canonical_hostname (hostname_allocation's name scheme, #13625). - host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own account lookup does: the standing still decides the BMC route. - mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation. - fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of #13607 and #13625). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Make fleet-converge branch-agnostic and parseable. GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha. Co-authored-by: Cursor <cursoragent@cursor.com> * Name the branch-dispatch ruling; type malformed expected_revision. Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose. Co-authored-by: Cursor <cursoragent@cursor.com> * Declare the named-revision and deploy-branch drop. Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger. Co-authored-by: Cursor <cursoragent@cursor.com> * Recut #13660: restore privileged WIF to reviewed-main equality. A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop leftover census conflict markers and project the named-revision drop. The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix OidcClaimPin inhabitance and the privileged-pin wording fork. branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation. Co-authored-by: Cursor <cursoragent@cursor.com> * Split presented OIDC claims from pins; printer session-branch is a red. Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin. Co-authored-by: Cursor <cursoragent@cursor.com> * Regenerate fleet-converge.yml (21 inputs) and pin dashboard-deploy to main. GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: revert #13663's fold (operator ruling: #13662 and #13663 stay outside the closeout) deep-cat-540 recuts it onto main after #13641. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Omit Spark dispatch when the administrator roster is empty. Review 78408: regeneration had folded a sold-out Spark roster into target options: [] while spark_* modes stayed selectable. Restoring srv5-srv12 would invent enrolled hosts. Emission now drops the target input and spark_* mode options, and refuses any remaining empty InputChoice. Co-authored-by: Cursor <cursoragent@cursor.com> * Treat srv1-production environment protection as the root-mutation boundary. A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5 The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around. First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs. Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here. Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fleet-converge: omit the Spark target input and spark_* modes while the administrator roster is empty; refuse an empty choice at emission (port of ffe8a90) The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes. What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name. The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: delete the accounting doc; the terminal ledger lives in #13641's body (review 5474794145) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * closeout: revert the #13664 fold (5c0d9d5) per the operator's review 5477471759: close #13664 without folding, branch preserved; projections regenerated next * deployment environments: model the branch policy as GitHub returns it (name + branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET (review 78420) Review 78420 on gunbc#13660 (folded here at 60c9457) found that extdeps.github.deployment_environments modeled the deployment-branch policy as SelectedRefs { refs: ["refs/heads/main"] }, while the API carries no refs: the environment object's deployment_branch_policy is null or { protected_branches, custom_branch_policies }, and the custom rules live at GET /repos/{owner}/{repo}/environments/{name}/deployment-branch-policies as branch_policies rows { name, type } with type "branch" or "tag". A reading of the real API can therefore never match the modeled refs, so gunbc.auth.github_deployment_environment's standing could never move from Unobserved to Holds (DESIGN section 3: model what the API actually returns; section 5: a check that cannot be discharged is not a boundary). The model now carries DeploymentBranchPolicyRule { name, ref_type: PolicyRefBranch | PolicyRefTag } under SelectedBranchesAndTags { rules }, the srv1-production requirement is the single branch rule named main with required reviewers, the restriction predicate requires exactly one rule that is a branch named main, and the read obligation names both GETs and the shapes they return. The witness gains a supplied-value control: a tag rule named main and a two-rule policy are not the main-branch boundary, the single branch rule is. Standing stays Unobserved until the operator applies the setting and its readback lands; that flip is the first follow-up on main. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: regenerate at the fixed point on composition A (revert of #13664, fold of #13660) Same recipe as f8c3fa4, on a shallow clone of dbdc9d2 with the previous fixed-point seed as the boot seed (srv1, logs8): main_wet exit 0; required-regen generation 0 drifted gunbc_cli_dispatch_surface.rs (gunbc.cli_dispatch_surface is touched by #13660), generation 1 drifted gunbc_cli_dispatch_generated.rs, generation 2 first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; verify (dry main) exit 0; rebuild; gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0 warning_count=0 wall_s=611, discriminating red on v2_cli_compile_cli) and //gunbc/instruments:self-host exit 0 (wall_s=716, red on v2_compiler_compile). The projections resolved toward #13660's side in the merge (ROADMAP.md, fleet-converge.yml, docs/design-rung-drops.md) were byte-identical to main_wet's output, so only .gitattributes and the two cli_dispatch mirrors change here. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: gunbc-ci-auto-heal <briansrls@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: x <x@x> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Leg 3b of the mtcollins1 qualification route. Stacked on #13211: this branch contains its commits until it lands, and I will merge main in afterwards.
Dissolves
gunbc.runner.runner_qualification_dispatchqualification_instrument_extraction_frontier_rowsas it was (one row, every instrument unextracted). It is now three rows, one per missing capability. Each row is retired by its own trigger.What reads now
extdeps.github, cited by upstream name:extdeps.github.actions_artifacts, servicegithub.Artifacts, withListWorkflowRunArtifacts(actions/list-workflow-run-artifacts) andDownloadArtifact(actions/download-artifact;archive_formatis upstream's single memberzip, written into the path).github.WorkflowRunsDownloadJobLogsForWorkflowRun(actions/download-job-logs-for-workflow-run).302+Location. The interface names the answer at the end of the redirect; the seed REST handler (ureq) follows it. Transport stays a bound handler (DESIGN §3).qualification_instrument_producer, not with a new authority:gunbc.required_ci_phase_rostergetsread_floor_phase_row(timed and untimed rows are separate arms; a missing phase or a non-countwall_msis garbled). It also holds the one reader for the floor's[tag] k=vline encoding.gunbc.host_budget_sourcegetsread_floor_cgroup_level_row. It decodeshighandpeakthroughextdeps.linux.cgroup_v2_memory(maxis Unlimited, never a number).extract_qualification_instrumentstakes the sealedCollectedQualificationRunand returns phase rows plus the slot's own cgroup level rows. Levels above the slot are refused as the slot's reading.InstrumentReadRefusal:JobLogUnreadable,FloorPhaseRowGarbledInLog,FloorCgroupRowGarbledInLog,FloorPhaseRowsAbsent, orSlotCgroupLevelAbsent(which lists the levels seen).collect_qualification_instrumentsis the network caller. It reads each served job's log and attempts the claim-cost artifact read.ClaimCostArtifactReadarms are: list unreadable, list truncated, absent (with the names that were present), expired, archive unreadable, and archive not inflatable. There is deliberately no parsed arm yet.qualification_instrument_sourceis a total match, so a new instrument cannot compile without saying where its reading comes from.The three remaining rows (parent ruling A: no seed growth here)
[over-cost]preview and on[floor-shared-fill]rows, and the calibration[witness]line is absent.required-floor-claim-costagain. When this PR was first written it did not: the upload had been lost in CI: required witnesses check builds only the compiler, on a hosted runner #11742, and recent runs then published onlyrequired-ci-measurement-receiptandcompiler-pair-candidate. The read now runs under the registration's token, refuses zero or several same-name artifacts, and binds the listing to the collected attempt by re-reading the run afterwards.Stringonly, so a zip answersRestBodyUndecodable.required_floor_claim_cost.tsvmember of the upload-artifact zip, parsed byparse_claim_cost_tsvand bound to this collected run.mtcollins1_boot_leg, still LegAwaitingAuthority).seal_cohortneeds a barrier-released roster of seats, and a one-slot route has none.10 MB cap: a recorded full floor log measured 1.5 MB, so it is not refused for size. Above the cap, the read surfaces as
RestBodyUndecodable→JobLogUnreadable, typed and never truncated.Evidence
conclude_qualification_runby name, so the sealing from mtcollins1 runner: dispatch the floor to the attempt's slot and read the run back (leg 3) #13211 holds.the_extraction_reads_a_recorded_required_floor_log:test.fixture.recorded_required_floor_log_excerpt, the verbatim[floor-phase]/[floor-cgroup]lines of run 35048059968 / job 104642384772.level_is_slotaccept every level turns the positive control, the slot-level-absent refusal and the inhabitance claim red. Restored.read_attempt_job_logon job 104642384772 followed the redirect and read 5,744 lines.read_claim_cost_artifacton run 37174570297 answeredClaimCostArtifactAbsent { names_seen: [required-ci-measurement-receipt] }.runner_qualification_dispatch_witness_testpassed under the interpreter. A full floor and clippy run was not done locally; CI judges.Found along the way, not fixed here
The seed ignores a bare
response_format: Text. It reads only the quoted string"Text", so the bare spelling silently decodes as JSON. The first live run of the log read failed exactly this way with status 200. The new operations use"Text".extdeps.github.pullsgithub.Pulls.Diffstill uses the bare spelling and is presumably broken the same way.Since review on 3be84a5 (sealed receipt, one floor-job join)
The per-blocker replies are on the PR.
job_ran_on. This PR adds no second join.QualificationJobLogReceiptissole_constructor, andjob_log_standingisadmit_callers: [collect_qualification_instruments].test.claim.qualification_job_log_receipt_forged_probe_witnesscompilestest.probe.qualification_job_log_receipt_forged_probeand requiresSoleConstructorViolationatQualificationJobLogReceiptandConstructorCallAdmissionRefusedatjob_log_standing, beside a names-only control that refuses at neither.ReadsLiveTree;v2.workflow.required_floordeletedDeclinedLiveTree.🤖 Generated with Claude Code