Skip to content

Runner obligation and census read committed identities; Spark training readiness takes its roster - #13602

Closed
briansrls wants to merge 1 commit into
mainfrom
fix/runner-committed-identities-spark-roster
Closed

briansrls wants to merge 1 commit into
mainfrom
fix/runner-committed-identities-spark-roster

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Two real defects found while triaging six files that fail under plain claim_batch on main.

Runner: the earliest unjustified boundary is #12339

#12339 moved srv1's committed population to identity grain: srv1-01..(width-1) plus the shakedown slot srv1-13 (gunbc.runner_slot_allocation host_committed_identities_at). Two readers kept counting slots as 1..width:

  • the census desired set (runner_slot_population_census slot_population_census)
  • the transition obligation (runner_width_transition transition_required_retirees_at, target+1..prior)

As a result the census classified srv1-13, a committed fabric member, as retiring, and the obligation required it. The fleet slot that the width no longer charges for was neither live nor required. Both readers now go through one derivation, committed_unit_names_at, and the obligation is computed as prior minus committed, a set difference. The fixtures in runner_host_file_converge_witness_test used the same index cut, which is why they agreed with the old rule. They now derive from the same authority.

New claim the_obligation_excludes_a_committed_member_above_the_fleet_range. It checks membership rather than count, because at width 11 the old and new rules both produce 39 units.

Still red, on purpose: srv1s_obligation_is_fully_covered_by_its_declared_scope. srv1's derived width is now 10, so srv1-10, srv1-11 and srv1-12 are required retirees. The 2026-09-17 operator authorization (srv1_transition_interruption_authorization) only names 13..50, and it also names srv1-13, which is committed. The refusal is correct. Widening the authorization is an operator decision, and this PR does not make it.

Spark: stale since #10009

The 2026-09-02 operator decision made srv6 a serving cell. Reading the production roster left the positive control w_a_fully_retired_training_cell_is_ready with no subject. It also meant every refusal claim over srv6 passed on role alone instead of on the axis it is meant to test. Following the spark_cell_role_in precedent, spark_training_readiness_in now takes the roster. The witness supplies a roster with srv5 serving and srv6 training. A new claim checks that the production wrapper refuses srv6.

Evidence (claim_batch at ded96bd, plain/hermetic)

  • spark_training_ready_witness_test: 12/13 → 14/14
  • runner_slot_retirement_witness_test: 62/63 → 63/64 (the remaining red is the operator-scope gap above)
  • runner_host_file_converge_witness_test: 49/49 → 49/49
  • runner_slot_population_census 9/9, runner_slot_census_typed_argv 8/8, shell_dag_slot_population_census_read 4/4

🤖 Generated with Claude Code

…g readiness takes its roster

Runner (earliest unjustified boundary: #12339). #12339 moved srv1's committed
population to identity grain -- srv1-01..(width-1) plus the shakedown slot
srv1-13 (runner_slot_allocation host_committed_identities_at) -- but two readers
kept enumerating 1..width: the census desired set and the width-transition
obligation (target+1..prior). So the census classified srv1-13 as retiring and
the obligation required it, while the fleet slot the width stopped charging for
was neither live nor required. Both now go through one derivation,
runner_slot_population_census committed_unit_names_at, and the obligation is
prior minus committed as a set difference. The converge witness fixtures had
the same index cut and are derived from that authority too. New claim
the_obligation_excludes_a_committed_member_above_the_fleet_range discriminates
by membership (old and new rules give the same count, 39, at width 11).

srv1s_obligation_is_fully_covered_by_its_declared_scope stays red, honestly:
srv1's width is now 10, so srv1-10..12 are required retirees and the
2026-09-17 operator authorization names only 13..50. Extending it is an
operator decision, not something this change may mint.

Spark (stale since #10009). The 2026-09-02 operator decision made srv6 a
serving cell, so spark_training_readiness over the production roster left the
positive control with no subject and every refusal claim over srv6 passing on
role alone. spark_training_readiness_in takes the roster (the
spark_cell_role_in precedent); the witness supplies srv5 serving / srv6
training, and a new claim pins the production wrapper refusing srv6.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T23:49:32.277078Z f867e9d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f867e9d670

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

limit: t.prior_width,
units: prior_minus_committed(
prior: desired_unit_names_range(host: t.host, slot: 1, limit: t.prior_width),
committed: committed_unit_names_at(host: t.host, committed: target),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve srv1-13's purpose-retirement obligation

When srv1's committed width is below the authored index 13, subtracting the committed identity set correctly removes srv1-13 from the width-retiree list, but transition_required_retiring has no other way to recover it: fabric_purpose_retirees_for_host still intersects fabric members using id.slot_index <= w, so it also excludes this committed high-index fabric member. The previous range-based width obligation happened to include srv1-13; after this change a live Actions runner on the shakedown cell has no retirement obligation before that cell is used for fabric execution. Update the purpose-retiree intersection to use committed identity membership as part of this change.

Useful? React with 👍 / 👎.

@briansrls

Copy link
Copy Markdown
Contributor Author

Operator decision 2026-10-09: retire srv1-10..12 now; srv1-13 removed from the authorization (it is the committed microVM shakedown slot). srv1s_obligation_is_fully_covered_by_its_declared_scope is now green; all 7 witness files importing gunbc.runner_slot_retirement pass (276/276).

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Superseded by #13641 at 634453d: this PR's head is an ancestor of integration/v1-closeout. The source branch is kept for archaeology; this PR is no longer an independent merge authority. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant