Skip to content

Decommission Group A (srv5-srv8, sold): remove it from fleet config and convergence - #13544

Merged
gunbai-bot[bot] merged 54 commits into
integration/v1-closeoutfrom
session/cool-carp-342-group-a-decom
Oct 10, 2026
Merged

gunbai-bot[bot] merged 54 commits into
integration/v1-closeoutfrom
session/cool-carp-342-group-a-decom

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Operator-approved (msg_5d88338f, msg_9e5a2fee via valiant-crab-775): Group A (srv5–srv8, fabric cage 1) was sold and wiped, so it is removed from fleet config and convergence. Group B (srv9–srv12, cage 2) is untouched. Nothing was dispatched to the hosts.

Removed

  • Roots: the operator_host_srv5..8 identities, the four cage-1 lanes and the FabricGroupA variant, the router bindings and reservations, the LAN endpoints. The procurement keeps its meaning: 8 ordered and all 8 accounted for. 4 are retained (srv9–srv12, the only source of fleet rosters). The 4 cage-1 units are typed DgxSparkAssetSold dispositions under the operator's 2026-10-07 decision. No inventory QuantitySold is booked: no serial is joined to a router label, so that join is an open obligation.
  • Fleet rows: site/locale, phase status, cell roles, chassis, roadmap components, administrator credentials, wireless link, host keys, reach-identity receipts, the reach and multi-principal probe rosters, the first pair's bootstrap population, and first-party serving.
  • Serving: the A arms of enrollment, offer, group launch and the harness rosters. The pair-serving authority now claims no group. The Group A runtime row and its registry reading are removed, as is the DeepSeek (Group A) arm of deployment selection.
  • (f) The arm path, which had no consumer once Group A was gone: group_arm_launch, arm_group_launch_dispatch, group_checkpoint_materialize, group_image_produce, group_arm_serving_load, runtime_image_produce_dispatch and glm53_kvplan_image. serving_load_runner is kept.
  • Group-A-only modules: the V4.1 Group A launch, load, checkpoint and runs; the GLM staircase; llama.cpp RPC; the V4.1 capacity measurement; and the byte-span producer, whose only consumer was the V4.1 checkpoint.
  • The twelve Group A workflow modes, the D0 mode, their ci_spec targets and their dispatch inputs.
  • (a) D0 whole, plus standing_operator_grant. The fabric store now admits no scope for the operations D0 performed, so they refuse as NoApprovalFlowForOperation, which fails closed.
  • The rung drops d0_store_walls_single_lifecycle and sha256_span_program_serialize_new_witness_eval_step_cost are Superseded, because their population went with Group A.
  • Rosters: the entries for deleted witnesses are removed from route-gap, wet-terminal, exclusion, cost-drop and reference-census.
  • Tests: tests of Group A behaviour are deleted; tests that only used Group A as a fixture are re-pointed to srv9–srv12 / FabricGroupB.

Kept, as records

History strings, dated receipts, GB10 measurements, the cable EEPROM readings, recurring-failure-mode rows, and the retired debt-ledger dispositions.

srv7 blob daemon

Nothing outside Group A pulls blobs from srv7. Blob sources are per group by construction: the checkpoint seed is per group, and image distribution requires a source in the image's own group. So no replacement source is needed.

Rulings applied (valiant-crab-775, 2026-10-07)

  1. Training readiness: no training-cell row is invented. The coverage loss is declared as gunbc.rung_drop.training_readiness_has_no_training_cell_after_group_a. Its population is four claims in spark_training_ready_witness. It restores when a fleet host is assigned a training cell role.
  2. Pair serving: pieces that Group B's path never executes are deleted: pair_incumbent_identity with its instrument, and pair_serving_capacity_floor. A cascade also removed eight declarations that became unreferenced. Kept, because Group B's path executes them:
    • pair_serving_apply: the host-apply plan types, used by native_serving_apply and native_experiment_apply.
    • pair_serving_launch_receipt: serving_standing, used by native_serving_apply.
    • pair_serving_realization: unit, container and port names, used by serving_offer, serving_group_launch, host_occupancy_admission and serving_enrollment.
    • pair_serving_authority and pair_serving_authority_log: the authority read and the host-effect claims, used by harness_seat, host_commitment, and image build and distribution.
    • pair_serving_desired: the group head, used by serving_enrollment.
    • pair_serving_observed: the rank free-memory type, used by deployment selection. Its rows are now empty.
  3. V4.1 modules: arm_memory_fit memory tiers (part 2 of 2): Spark as the one-tier inhabitant, GH200 two-tier frontier #13321 imports none of them. Eleven unconsumed modules are deleted with their witnesses. Kept: v41_published_image_observation (engram materialization, deployment selection, capability probe) and v41_runtime_image_probe (the runtime-image probe mode).

Notes

  • Durable placement history. The shared host-placement partition still holds D0's Group A records. Its records carry RecordedFabricGroup (a live group, or RecordedRetiredGroupA), and its intents carry RecordedAuthority (a live state, or the retired Group A state word). So Group A history decodes and folds as history. Writers take only a live FabricGroup, which has no Group A constructor. A retired record never matches a live query or fence, and consuming or cancelling one refuses naming it. The controls run through the real codec and placement_fold: a full retired saga (prepared, claimed, finalized) followed by a Group B event folds, and Group B's fence is exactly its own.
  • FabricGroup now has one variant. It is written the way the corpus writes single-variant coproducts: type FabricGroupB {} plus the alias type FabricGroup = FabricGroupB, with values FabricGroupB {}.
  • Main's Standing mtjade1 live-ops grant; grant scope is fabric-group or host #13493 added an mtjade1 standing grant, so gunbc.auth.standing_operator_grant stays and only the Group A grant is removed. Its three effect arms have no consuming gate now. They stay only because the type cannot be empty until Emit arrival_converge; IAM pair and pinned accessor (msg_f03558d1) #13497 lands mtjade1's arms.
  • With D0 gone, the fabric store admits no scope for the operations D0 performed, so they refuse as NoApprovalFlowForOperation. The receipt check approved_operation is exercised at its own interface with a supplied scope.
  • Four optional-versus-required comparisons that were already broken on main are fixed. They were on this change's closure, so the floor reported them.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 23 commits October 7, 2026 15:46
…d the FabricGroupA variant, router bindings and reservations, LAN endpoints, chassis placeholders, cell roles, bootstrap SSIDs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… roadmap components, administrator credentials, wireless link, first-party serving), physical inventory rows, the Group A development grant, and the A arms of serving enrollment, offer, group launch, accelerator and the harness rosters

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tor via valiant-crab-775: no consumer, restorable from history; serving_load_runner kept) and the Group-A-only modules and their witnesses; the snapshot replica witness supplies its checkpoint snapshot

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r ci_spec targets and invokes and their dispatch inputs; the llama.cpp RPC reservation input (its only producer was srv7/srv8); the V4.1 Group A capacity measurement; v41_row_store_encode derives its directory itself

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d the produced-image witnesses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… grant were Group A's; the fabric store now admits no scope for the operations D0 performed, refusing them as NoApprovalFlowForOperation); the D0 mode, targets and dispatch input; d0_store_walls_single_lifecycle Superseded; the pair-serving authority claims no group; Group A arms of the pair head and head-unit render

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ng and dump entry; the DeepSeek (Group A pair) arm of deployment selection; Group A's observed rank free memory, KV pool, units and head

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… only grant and both consumers were Group A's) and D0's census sites; declarations orphaned by the removal (D0's authority-log writers and their record type, the V4.1 launch policy, the staircase log path, the registry-dump helpers, the unit observation type)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… reach/multi-principal probe rosters and the srv5/srv6 branches of the converge CLI and the reach principal; the first pair's bootstrap credential population

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… srv6 as read

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…leted witnesses' rows leave the route-gap, wet-terminal, exclusion, cost-drop and reference-census rosters; the byte-span producer (only consumer was the Group A V4.1 checkpoint) and its drop Superseded; procurement holds four units

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d D0 recovery claim leaves the route-gap and wet-terminal rosters

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ation deletion left behind

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…le-variant coproduct (an empty record FabricGroupB {} and the alias FabricGroup), so values and match arms read FabricGroupB {}

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t, the Group A modes and invokes stay removed; the store-admission witness supplies D0's scope byte-for-byte and exercises approved_operation at its interface, plus a claim that the door now refuses the consent write

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nsumes (#13321 imports none of them); keep v41_published_image_observation (engram materialization, deployment selection, capability probe) and v41_runtime_image_probe (the runtime-image probe mode)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… path never executes -- pair_incumbent_identity with its instrument, pair_serving_capacity_floor -- and their witnesses; arm_memory_fit's intent witness keeps the projections it still exercises

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ss as a rung drop instead of inventing a training-cell row; cascade the declarations the pair-serving deletion orphaned

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ted (the floor refuses any other standing for an absent file)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…FabricGroup also import its single variant (the alias needs its target in scope); the two V4.1 produced-image claims go with their images; four pre-existing optional-versus-required comparisons now compare against Present

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…le stays; only the Group A grant goes), D0, the group arm launch and the standing recovery stay deleted, the mtjade1 witness's group-scope claim runs over a supplied Group B fixture grant

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…group_checkpoint_materialize is moot (both deleted with the arm path); its new hub_dereferenced_bytes_argv stays consumed by snapshot_rail_replica

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Group A modes stay removed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review October 7, 2026 20:13
gunbc-ci-auto-heal and others added 6 commits October 7, 2026 20:21
…nnotation stop documenting the deleted Group A modes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… only, the Group A modes and inputs gone) and the design rung-drops projection

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…o its claims discriminate over a supplied roster (training cell admitted, serving cell refused on role alone, the refusal claims reaching their own property); the coverage-loss rung drop is withdrawn because nothing is lost

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es on the store-operation door at its surviving home (gunbc.fabric_store_operation_admission admit_store_operation on every write path), not on the deleted D0 module

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rawing the training-readiness drop

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pointed srv11 fixture; every module that writes FabricGroupB {} imports both the variant and its alias (an alias resolves only with its target in scope), the seal probe's compiled source included

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 13 commits October 8, 2026 00:08
…ecordedFabricGroup -- a live FabricGroup or the RETIRED Group A -- so D0's Group A history decodes and folds as history; writers take only a live FabricGroup (no Group A constructor), a retired record never matches a live group's query or fence, and consumption/cancellation of one refuses naming it; controls over the real codec and fold

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Disposition stays the convergence type's), the arrival standing's accounted arm separates on-LAN from disposed units, and the ordered note states the retained four and the sold four

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…aining test record constructions wrap theirs; the procurement witness imports the renamed arrival arm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tion is empty since Group A went; the V4.1 serving row's confirmation and placement say their Group A producers were deleted rather than citing them as live

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…roup promoted, Group B not laundered into it) and names its constructor claims as over a supplied group; the D0 census claims go with the D0 sites; the mtjade1 fixture's hold names a surviving declaration

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e RecordedAuthority (live, or the retired Group A state as history), so D0's Group A append claims decode and fold; live writers mint only the live arm, a live intent naming a retired state refuses, and a full retired saga (prepared, claimed, finalized) then a Group B event folds through the real codec with Group B's fence exactly its own

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rts Group B's own declared model path (from its launch authority), which the production route compares against

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…leased_by_real_execution -- its subject was a claimed pair-serving group whose release frees its hosts in the production standings (Group A); with no group claimed, releasing Group B's authority frees nothing the GLM arm holds. The fence-on-reclaim property stays covered by an_overdue_host_effect_claim_fences_until_released_by_real_execution

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tained units, not the sold srv5/srv6

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…over a real temp store, retained Group B host srv9 is refused for its real serving-arm commitment and the placement partition reads back with no host effect appended; scheduled on the wet lane and the route-gap roster

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…a path that differs from Group B's declared one (it reported the GLM path, which is now the declared path)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ndezvous ss argv, pgrep pid listing, roadmap fleet components); the Present-wrapped rewrite reds on the floor's equality

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the checker refuses a bare optional-vs-required ==, and the floor's evaluator fails a Present-wrapped ==)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 8, 2026
gunbc-ci-auto-heal and others added 2 commits October 8, 2026 15:43
…gate main_wet; required-regen installed no mirror); design-rung-drops.md stays on main's side for heal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 8, 2026
gunbai-bot Bot and others added 2 commits October 8, 2026 18:18
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md sha256_span_program_serialize_new_witness_eval_step_cost
Heal-Candidate-Run: 37806121520
…name-join and claimed-host arms from sold srv5-srv8 to retained srv9 (spark-0c75, .236), and asserts sold srv5's reading is now unjoinable

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Review 78113 addressed in 568c345; both findings were valid. In v41_runtime_image_build_witness_test, the hostname-join claim now uses retained srv9 (spark-0c75, 192.168.1.236) for the answered and mismatch arms. A new arm asserts that a reading from sold srv5 classifies as SparkHostIdentityUnjoinable. The claimed-host claim drops the srv5-srv8 not-unplaced arms, which were vacuous once those hosts were gone, and its build-refusal arm now asks for claimed srv9. All 25 claims in the file pass in a remote claim_batch run.

— sent from cool-carp-342

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 8, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 9, 2026
Generated files (fleet-converge.yml, design-rung-drops.md, stage0 cli dispatch) take the integration side for the single srv1 regen.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot changed the base branch from main to integration/v1-closeout October 10, 2026 03:12
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Folded into #13641 (merge second parent = 9fb3744).

@gunbai-bot
gunbai-bot Bot merged commit 3652559 into integration/v1-closeout Oct 10, 2026
3 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/cool-carp-342-group-a-decom branch October 10, 2026 03:13
gunbai-bot Bot pushed a commit that referenced this pull request Oct 10, 2026
Keeps #13544 deletions (srv5-srv6 rows/witnesses, Group A modes) and #13607 WorkspaceAllocationPlan/WorkspaceImageBuild/ci_fleet_wif_auth_step_when; PR's HetznerCloudServerRead/BranchRunGrant modes retained; ci_wif_auth_step_with_id_when folded onto integration's ci_wif_auth_step_with_condition.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants