Repository navigation
Decommission Group A (srv5-srv8, sold): remove it from fleet config and convergence - #13544
Merged
gunbai-bot[bot] merged 54 commits intoOct 10, 2026
Merged
gunbai-bot[bot] merged 54 commits into
gunbai-bot[bot] merged 54 commits into
Conversation
…d the FabricGroupA variant, router bindings and reservations, LAN endpoints, chassis placeholders, cell roles, bootstrap SSIDs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… roadmap components, administrator credentials, wireless link, first-party serving), physical inventory rows, the Group A development grant, and the A arms of serving enrollment, offer, group launch, accelerator and the harness rosters Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tor via valiant-crab-775: no consumer, restorable from history; serving_load_runner kept) and the Group-A-only modules and their witnesses; the snapshot replica witness supplies its checkpoint snapshot Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r ci_spec targets and invokes and their dispatch inputs; the llama.cpp RPC reservation input (its only producer was srv7/srv8); the V4.1 Group A capacity measurement; v41_row_store_encode derives its directory itself Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d the produced-image witnesses Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… grant were Group A's; the fabric store now admits no scope for the operations D0 performed, refusing them as NoApprovalFlowForOperation); the D0 mode, targets and dispatch input; d0_store_walls_single_lifecycle Superseded; the pair-serving authority claims no group; Group A arms of the pair head and head-unit render Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ng and dump entry; the DeepSeek (Group A pair) arm of deployment selection; Group A's observed rank free memory, KV pool, units and head Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… only grant and both consumers were Group A's) and D0's census sites; declarations orphaned by the removal (D0's authority-log writers and their record type, the V4.1 launch policy, the staircase log path, the registry-dump helpers, the unit observation type) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… reach/multi-principal probe rosters and the srv5/srv6 branches of the converge CLI and the reach principal; the first pair's bootstrap credential population Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… srv6 as read Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…leted witnesses' rows leave the route-gap, wet-terminal, exclusion, cost-drop and reference-census rosters; the byte-span producer (only consumer was the Group A V4.1 checkpoint) and its drop Superseded; procurement holds four units Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d D0 recovery claim leaves the route-gap and wet-terminal rosters Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ation deletion left behind Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…le-variant coproduct (an empty record FabricGroupB {} and the alias FabricGroup), so values and match arms read FabricGroupB {}
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t, the Group A modes and invokes stay removed; the store-admission witness supplies D0's scope byte-for-byte and exercises approved_operation at its interface, plus a claim that the door now refuses the consent write Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nsumes (#13321 imports none of them); keep v41_published_image_observation (engram materialization, deployment selection, capability probe) and v41_runtime_image_probe (the runtime-image probe mode) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… path never executes -- pair_incumbent_identity with its instrument, pair_serving_capacity_floor -- and their witnesses; arm_memory_fit's intent witness keeps the projections it still exercises Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ss as a rung drop instead of inventing a training-cell row; cascade the declarations the pair-serving deletion orphaned Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ted (the floor refuses any other standing for an absent file) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…FabricGroup also import its single variant (the alias needs its target in scope); the two V4.1 produced-image claims go with their images; four pre-existing optional-versus-required comparisons now compare against Present Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…le stays; only the Group A grant goes), D0, the group arm launch and the standing recovery stay deleted, the mtjade1 witness's group-scope claim runs over a supplied Group B fixture grant Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…group_checkpoint_materialize is moot (both deleted with the arm path); its new hub_dereferenced_bytes_argv stays consumed by snapshot_rail_replica Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Group A modes stay removed Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nnotation stop documenting the deleted Group A modes Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… only, the Group A modes and inputs gone) and the design rung-drops projection Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…o its claims discriminate over a supplied roster (training cell admitted, serving cell refused on role alone, the refusal claims reaching their own property); the coverage-loss rung drop is withdrawn because nothing is lost Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es on the store-operation door at its surviving home (gunbc.fabric_store_operation_admission admit_store_operation on every write path), not on the deleted D0 module Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rawing the training-readiness drop Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pointed srv11 fixture; every module that writes FabricGroupB {} imports both the variant and its alias (an alias resolves only with its target in scope), the seal probe's compiled source included
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ecordedFabricGroup -- a live FabricGroup or the RETIRED Group A -- so D0's Group A history decodes and folds as history; writers take only a live FabricGroup (no Group A constructor), a retired record never matches a live group's query or fence, and consumption/cancellation of one refuses naming it; controls over the real codec and fold Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Disposition stays the convergence type's), the arrival standing's accounted arm separates on-LAN from disposed units, and the ordered note states the retained four and the sold four Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…aining test record constructions wrap theirs; the procurement witness imports the renamed arrival arm Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tion is empty since Group A went; the V4.1 serving row's confirmation and placement say their Group A producers were deleted rather than citing them as live Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…roup promoted, Group B not laundered into it) and names its constructor claims as over a supplied group; the D0 census claims go with the D0 sites; the mtjade1 fixture's hold names a surviving declaration Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e RecordedAuthority (live, or the retired Group A state as history), so D0's Group A append claims decode and fold; live writers mint only the live arm, a live intent naming a retired state refuses, and a full retired saga (prepared, claimed, finalized) then a Group B event folds through the real codec with Group B's fence exactly its own Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rts Group B's own declared model path (from its launch authority), which the production route compares against Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…leased_by_real_execution -- its subject was a claimed pair-serving group whose release frees its hosts in the production standings (Group A); with no group claimed, releasing Group B's authority frees nothing the GLM arm holds. The fence-on-reclaim property stays covered by an_overdue_host_effect_claim_fences_until_released_by_real_execution Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tained units, not the sold srv5/srv6 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…over a real temp store, retained Group B host srv9 is refused for its real serving-arm commitment and the placement partition reads back with no host effect appended; scheduled on the wet lane and the route-gap roster Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…a path that differs from Group B's declared one (it reported the GLM path, which is now the declared path) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ndezvous ss argv, pgrep pid listing, roadmap fleet components); the Present-wrapped rewrite reds on the floor's equality Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the checker refuses a bare optional-vs-required ==, and the floor's evaluator fails a Present-wrapped ==) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…gate main_wet; required-regen installed no mirror); design-rung-drops.md stays on main's side for heal Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md sha256_span_program_serialize_new_witness_eval_step_cost Heal-Candidate-Run: 37806121520
…name-join and claimed-host arms from sold srv5-srv8 to retained srv9 (spark-0c75, .236), and asserts sold srv5's reading is now unjoinable Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Review 78113 addressed in 568c345; both findings were valid. In — sent from cool-carp-342 |
Generated files (fleet-converge.yml, design-rung-drops.md, stage0 cli dispatch) take the integration side for the single srv1 regen. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Contributor
Author
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 10, 2026
Keeps #13544 deletions (srv5-srv6 rows/witnesses, Group A modes) and #13607 WorkspaceAllocationPlan/WorkspaceImageBuild/ci_fleet_wif_auth_step_when; PR's HetznerCloudServerRead/BranchRunGrant modes retained; ci_wif_auth_step_with_id_when folded onto integration's ci_wif_auth_step_with_condition. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Operator-approved (msg_5d88338f, msg_9e5a2fee via valiant-crab-775): Group A (srv5–srv8, fabric cage 1) was sold and wiped, so it is removed from fleet config and convergence. Group B (srv9–srv12, cage 2) is untouched. Nothing was dispatched to the hosts.
Removed
operator_host_srv5..8identities, the four cage-1 lanes and theFabricGroupAvariant, the router bindings and reservations, the LAN endpoints. The procurement keeps its meaning: 8 ordered and all 8 accounted for. 4 are retained (srv9–srv12, the only source of fleet rosters). The 4 cage-1 units are typedDgxSparkAssetSolddispositions under the operator's 2026-10-07 decision. No inventoryQuantitySoldis booked: no serial is joined to a router label, so that join is an open obligation.group_arm_launch,arm_group_launch_dispatch,group_checkpoint_materialize,group_image_produce,group_arm_serving_load,runtime_image_produce_dispatchandglm53_kvplan_image.serving_load_runneris kept.standing_operator_grant. The fabric store now admits no scope for the operations D0 performed, so they refuse asNoApprovalFlowForOperation, which fails closed.d0_store_walls_single_lifecycleandsha256_span_program_serialize_new_witness_eval_step_costare Superseded, because their population went with Group A.FabricGroupB.Kept, as records
History strings, dated receipts, GB10 measurements, the cable EEPROM readings, recurring-failure-mode rows, and the retired debt-ledger dispositions.
srv7 blob daemon
Nothing outside Group A pulls blobs from srv7. Blob sources are per group by construction: the checkpoint seed is per group, and image distribution requires a source in the image's own group. So no replacement source is needed.
Rulings applied (valiant-crab-775, 2026-10-07)
gunbc.rung_drop.training_readiness_has_no_training_cell_after_group_a. Its population is four claims inspark_training_ready_witness. It restores when a fleet host is assigned a training cell role.pair_incumbent_identitywith its instrument, andpair_serving_capacity_floor. A cascade also removed eight declarations that became unreferenced. Kept, because Group B's path executes them:pair_serving_apply: the host-apply plan types, used bynative_serving_applyandnative_experiment_apply.pair_serving_launch_receipt:serving_standing, used bynative_serving_apply.pair_serving_realization: unit, container and port names, used byserving_offer,serving_group_launch,host_occupancy_admissionandserving_enrollment.pair_serving_authorityandpair_serving_authority_log: the authority read and the host-effect claims, used byharness_seat,host_commitment, and image build and distribution.pair_serving_desired: the group head, used byserving_enrollment.pair_serving_observed: the rank free-memory type, used by deployment selection. Its rows are now empty.v41_published_image_observation(engram materialization, deployment selection, capability probe) andv41_runtime_image_probe(the runtime-image probe mode).Notes
RecordedFabricGroup(a live group, orRecordedRetiredGroupA), and its intents carryRecordedAuthority(a live state, or the retired Group A state word). So Group A history decodes and folds as history. Writers take only a liveFabricGroup, which has no Group A constructor. A retired record never matches a live query or fence, and consuming or cancelling one refuses naming it. The controls run through the real codec andplacement_fold: a full retired saga (prepared, claimed, finalized) followed by a Group B event folds, and Group B's fence is exactly its own.FabricGroupnow has one variant. It is written the way the corpus writes single-variant coproducts:type FabricGroupB {}plus the aliastype FabricGroup = FabricGroupB, with valuesFabricGroupB {}.gunbc.auth.standing_operator_grantstays and only the Group A grant is removed. Its three effect arms have no consuming gate now. They stay only because the type cannot be empty until Emit arrival_converge; IAM pair and pinned accessor (msg_f03558d1) #13497 lands mtjade1's arms.NoApprovalFlowForOperation. The receipt checkapproved_operationis exercised at its own interface with a supplied scope.🤖 Generated with Claude Code