Skip to content

integration/royal-moth-86: wind-down fold of #13569 (store held-session + reclaim/observe fixes) - #13636

Closed
gunbai-bot[bot] wants to merge 31 commits into
mainfrom
integration/royal-moth-86
Closed

gunbai-bot[bot] wants to merge 31 commits into
mainfrom
integration/royal-moth-86

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Wind-down integration for root lane royal-moth-86 (per swift-bat-828's wind-down policy, 2026-10-09). Branched from origin/main; operator merges directly — not via the merge queue.

Folded in

  • store: held-session op + O(1) named hold-slot reads #13569 (session/bright-dove-288 @ 121565a) — held-session store op + named k=2 hold-slot reads, ascending stop-at-first-failure reclaim, bounded cas_observe_window (8 passes; ObservationBoundExceeded reports a pass count), realization-private NamedWindowHeadMoved. Side-chat APPROVE at exact head 121565a; witnesses passed at that head (before the queue was flushed). Merged with a plain merge commit.
    • Conflict: docs/design-rung-drops.md (generated). Regenerated through tools.docs_projection_gate regen on the merged tree — no hand edit (cf2f527).

Left out (pushed as-is, draft)

Gate (no v1 CI), one remote dispatch at 936ab10 (the #13569 merge)

BuildBuddy invocation 2bd30c22-badd-4ba3-9190-49c0654f600d, GUNBC_MEMORY_BUDGET_BYTES forwarded:

  • cargo build --release -p v1-compiler --bin gunbc → BUILD_EXIT=0
  • gunbc run ... docs_projection_gate.dag --function regen → REGEN_EXIT=0; the only changed path was docs/design-rung-drops.md (committed as cf2f527)
  • gunbc test //gunbc/instruments:v2-native-cli → NATIVE_CLI_EXIT=0 (exit_status=0, warning_count=0, door_exit_status=0, refusal control exit 2 as cli_no_entry)

cf2f527 differs from the gated 936ab10 only in that one generated doc file.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits October 8, 2026 02:16
Per-commit family-hold brackets listed the whole store root on every write. A session acquires once for many lookups and commits; check and release verify the known generation by path so they stay O(1) in store size. Unknown-head acquire still lists, because a windowed slot is not a presence prefix.

Co-authored-by: Cursor <cursoragent@cursor.com>
Initialize/open already acquires and releases the family hold for the sweep, so an absolute head of 2 was never the session's signature. The control is the delta: +2 for one session, +2N for N per-commit brackets.

Co-authored-by: Cursor <cursoragent@cursor.com>
Probing generations with per-file Reads was a second observation route and showed up as host_effect_refused / route-gap on the changed-witness wet lane. The store's own listing fold already runs in this file.

Co-authored-by: Cursor <cursoragent@cursor.com>
Changed-witness admission treated the unenrolled Mktemp as route-gap-before-verdict and never joined the local-repo wet terminal. The rest of this file's wet identities are already that triple: gap row, wet schedule, LocalRepoWetLane exclusion.

Co-authored-by: Cursor <cursoragent@cursor.com>
Check and release already go through the named-generation ops; leaving the listing twins in tree left two answers for one question. Named observe also dropped the unused window parameter — the two-file verify does not read it. Acquire still lists, because a reclaimed prefix is not a presence sequence from gen 1.

Co-authored-by: Cursor <cursoragent@cursor.com>
…un forever.

cas_observe_window recursed on listed-max G when G+1 still read present; under a TCO lowering that does not increment attempt that is the hang after hold-typed_module.1507/.1508. Fold at most eight list-and-verify passes instead.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ch a hole.

Independent deletes could remove G+1 while G survived, which made named window verify report G as head. Reclaim now walks eligible generations in ascending order and leaves later ones in place after a host refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>
The no-holes reclaim already stops at the first failed generation. This pins that generation against unlink, runs another acquire/release, and requires reuse of the leaked hold to refuse stale with no object or index write.

Co-authored-by: Cursor <cursoragent@cursor.com>
The two-read check is sound only while reclaim cannot drop G+1 and leave G; the previous comment treated that as already true.

Co-authored-by: Cursor <cursoragent@cursor.com>
Per-step min-and-filter of remaining was O(n²); DESIGN §6 requires that cost shape fixed regardless of n.

Co-authored-by: Cursor <cursoragent@cursor.com>
…irst.

commit_under re-observes the hold before any index write; the pin control must match that Unsettled cause, and a failed IMMUTABLE ioctl cannot green the claim.

Co-authored-by: Cursor <cursoragent@cursor.com>
They were second names for unsealed local_store_lookup and local_store_commit_under; the seal is only local_store_held_session.

Co-authored-by: Cursor <cursoragent@cursor.com>
The two-file plant is GREEN on main's recursive observe; it only asserts the fold returns.

Co-authored-by: Cursor <cursoragent@cursor.com>
The Int 8 row was a second source for the same bound; the diagnostic now reports the list length.

Co-authored-by: Cursor <cursoragent@cursor.com>
Eight-pass cas_observe_window was a refused read by sentence; named verify with G+1 present was the same Unsettled arm. The leaked-hold control now matches HoldNamedWindowHeadMoved, and the attempt bound remains count of cas_window_observation_attempts.

Co-authored-by: Cursor <cursoragent@cursor.com>
…erve.

ProbedNamedWindowHeadMoved had been projected as CasUnreadableObservationBoundExceeded { bound: 1 }, which is the eight-pass budget arm. Named verify now returns CasNamedWindowVerify; observe_cas_slot_state_windowed_at is deleted rather than left sealed with no caller.

Co-authored-by: Cursor <cursoragent@cursor.com>
HoldReleaseAgainstAnotherGeneration and HoldRecoverySlotMoved name an observed current generation. Named verify only established that a successor of G exists, so those constructors were lying when acquired/reported equalled G. The leaked-hold helper is named for Moved, not Unsettled.

Co-authored-by: Cursor <cursoragent@cursor.com>
…servation.

local_store_hold_check and windowed release/recovery consume NamedWindowHeadCurrent | NamedWindowHeadMoved directly. Dedicated release/recovery refusals stay; DurableHoldObservation and CasSlotProbe no longer carry a moved-head arm.

Co-authored-by: Cursor <cursoragent@cursor.com>
It was a second name for local_store_held_session with no production caller. The wet N-vs-2N inhabitance claim now calls the session operation; v2.compiler.compile is the named later consumer that will admit itself when typecheck writes leave per-commit local_store_commit.

Co-authored-by: Cursor <cursoragent@cursor.com>
Stop-at-first-failure means a non-empty failed list is the same fact as the boolean, so the walk now keys off that list.

Co-authored-by: Cursor <cursoragent@cursor.com>
Windowed named verify is a file-store realization outcome consumed by
materialization_store_local; keep-all fabric and host matches no longer
carry dead NamedWindow arms. BoundExceeded now renders as an attempt
budget rather than a generation.

Co-authored-by: Cursor <cursoragent@cursor.com>
The shared detail string is now "observation bound exceeded: N" so a
pass count or a fabric closure bound is not reported as a generation.

Co-authored-by: Cursor <cursoragent@cursor.com>
After release, G+1 is present, so named verify refuses the leaked G as
head-moved rather than decoding the new free head as LocalStoreHoldStale.

Co-authored-by: Cursor <cursoragent@cursor.com>
The floor cannot set FS_IMMUTABLE (CAP_LINUX_IMMUTABLE); that member was
false by construction there. The hole stays on reclaim_stops (mkdir
unlink-refusal). Leaked-hold after a clean release stays on the
NamedWindowHeadMoved control.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep it off local_repo_wet ExpectedToHold: the CI wet runner lacks
CAP_LINUX_IMMUTABLE. Restore the identity and enroll the hermetic gap
like its siblings. Restoration is a wet lane that grants the capability,
or an unlink-refusal that needs none; the floor wall stays reclaim_stops.

Co-authored-by: Cursor <cursoragent@cursor.com>
Body // inside floor_route_gap_expectation_chunk_09 is DESIGN 4c-unmodeled and native emit-build refuses it.

Co-authored-by: Cursor <cursoragent@cursor.com>
A route-gap row still planned the changed identity with no terminal. Own file classified BinWitnessWet and named in the no-CI-wet-lane population, so the floor declines instead of requiring a verdict.

Co-authored-by: Cursor <cursoragent@cursor.com>
Removing the leaked-hold row left an extra closer that ended the
function early, so the next item was unparseable and CI refused the
module index.

Co-authored-by: Cursor <cursoragent@cursor.com>
A blank-separated block after the type was nearest-following the
renderer, so the field's meaning sat on the wrong subject.

Co-authored-by: Cursor <cursoragent@cursor.com>
…l-moth-86

# Conflicts:
#	docs/design-rung-drops.md
…ate regen after the #13569 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 9, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Closing as a duplicate. This branch is folded into the v1 closeout mega branch #13641 (integration/v1-closeout), which is the single landing path. Branch kept. Review findings on this PR are handled there. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants