Repository navigation
Runner obligation and census read committed identities; Spark training readiness takes its roster - #13602
Runner obligation and census read committed identities; Spark training readiness takes its roster#13602briansrls wants to merge 1 commit into
Conversation
…g readiness takes its roster Runner (earliest unjustified boundary: #12339). #12339 moved srv1's committed population to identity grain -- srv1-01..(width-1) plus the shakedown slot srv1-13 (runner_slot_allocation host_committed_identities_at) -- but two readers kept enumerating 1..width: the census desired set and the width-transition obligation (target+1..prior). So the census classified srv1-13 as retiring and the obligation required it, while the fleet slot the width stopped charging for was neither live nor required. Both now go through one derivation, runner_slot_population_census committed_unit_names_at, and the obligation is prior minus committed as a set difference. The converge witness fixtures had the same index cut and are derived from that authority too. New claim the_obligation_excludes_a_committed_member_above_the_fleet_range discriminates by membership (old and new rules give the same count, 39, at width 11). srv1s_obligation_is_fully_covered_by_its_declared_scope stays red, honestly: srv1's width is now 10, so srv1-10..12 are required retirees and the 2026-09-17 operator authorization names only 13..50. Extending it is an operator decision, not something this change may mint. Spark (stale since #10009). The 2026-09-02 operator decision made srv6 a serving cell, so spark_training_readiness over the production roster left the positive control with no subject and every refusal claim over srv6 passing on role alone. spark_training_readiness_in takes the roster (the spark_cell_role_in precedent); the witness supplies srv5 serving / srv6 training, and a new claim pins the production wrapper refusing srv6. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f867e9d670
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| limit: t.prior_width, | ||
| units: prior_minus_committed( | ||
| prior: desired_unit_names_range(host: t.host, slot: 1, limit: t.prior_width), | ||
| committed: committed_unit_names_at(host: t.host, committed: target), |
There was a problem hiding this comment.
Preserve srv1-13's purpose-retirement obligation
When srv1's committed width is below the authored index 13, subtracting the committed identity set correctly removes srv1-13 from the width-retiree list, but transition_required_retiring has no other way to recover it: fabric_purpose_retirees_for_host still intersects fabric members using id.slot_index <= w, so it also excludes this committed high-index fabric member. The previous range-based width obligation happened to include srv1-13; after this change a live Actions runner on the shakedown cell has no retirement obligation before that cell is used for fabric execution. Update the purpose-retiree intersection to use committed identity membership as part of this change.
Useful? React with 👍 / 👎.
|
Operator decision 2026-10-09: retire srv1-10..12 now; srv1-13 removed from the authorization (it is the committed microVM shakedown slot). |
Two real defects found while triaging six files that fail under plain
claim_batchon main.Runner: the earliest unjustified boundary is #12339
#12339 moved srv1's committed population to identity grain: srv1-01..(width-1) plus the shakedown slot srv1-13 (
gunbc.runner_slot_allocationhost_committed_identities_at). Two readers kept counting slots as1..width:runner_slot_population_censusslot_population_census)runner_width_transitiontransition_required_retirees_at,target+1..prior)As a result the census classified srv1-13, a committed fabric member, as retiring, and the obligation required it. The fleet slot that the width no longer charges for was neither live nor required. Both readers now go through one derivation,
committed_unit_names_at, and the obligation is computed as prior minus committed, a set difference. The fixtures inrunner_host_file_converge_witness_testused the same index cut, which is why they agreed with the old rule. They now derive from the same authority.New claim
the_obligation_excludes_a_committed_member_above_the_fleet_range. It checks membership rather than count, because at width 11 the old and new rules both produce 39 units.Still red, on purpose:
srv1s_obligation_is_fully_covered_by_its_declared_scope. srv1's derived width is now 10, so srv1-10, srv1-11 and srv1-12 are required retirees. The 2026-09-17 operator authorization (srv1_transition_interruption_authorization) only names 13..50, and it also names srv1-13, which is committed. The refusal is correct. Widening the authorization is an operator decision, and this PR does not make it.Spark: stale since #10009
The 2026-09-02 operator decision made srv6 a serving cell. Reading the production roster left the positive control
w_a_fully_retired_training_cell_is_readywith no subject. It also meant every refusal claim over srv6 passed on role alone instead of on the axis it is meant to test. Following thespark_cell_role_inprecedent,spark_training_readiness_innow takes the roster. The witness supplies a roster with srv5 serving and srv6 training. A new claim checks that the production wrapper refuses srv6.Evidence (claim_batch at ded96bd, plain/hermetic)
🤖 Generated with Claude Code