Skip to content

v1 closeout mega branch - #13641

Merged
briansrls merged 2047 commits into
mainfrom
integration/v1-closeout
Oct 10, 2026
Merged

briansrls merged 2047 commits into
mainfrom
integration/v1-closeout

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Composition

The head is 2bf8735ecb5 (composition A, under review 5474794145):

Stage0 regeneration (one regen, at the fixed point)

  • Regenerated on top of 5c0d9d5d667.
  • Generation 2 reached the fixed point: first_generation_equal=true, planned/executed/adjudicated 169, declared_divergent=1 (main.rs), verify exit 0.
  • Root cause of the earlier regen loop: the coverage check reads the host-shell roster from the tree's lib.rs. A regen from a seed older than the crate planner had stripped three pub mod lines from it. The restore is canonical.

Instruments (srv1, fixed-point seed)

Instrument Exit Wall time Evidence
gunbc test //gunbc/instruments:v2-native-cli 0 616 s Discriminating red on v2_cli_compile_cli; controls held
gunbc test //gunbc/instruments:self-host 0 706 s Red on v2_compiler_compile; poison specimen refused

The full table is in the #13675 body.

fleet-converge

  • The empty Spark choice is omitted now, and an empty choice is refused at emission (port of ffe8a90a591; none of Make fleet-converge branch-agnostic and parseable #13660's other changes).
  • Two facts for the operator's read, not changed here:
    • gcp-iam-converge also fires for branch_run_grant.
    • hetzner-cloud-control is minted through the branch-dispatch pool.
    • Both sit behind an operator-approved request step.

Not yet discharged

Item 4 is deferred to after landing: enforcing 22/21 GiB with zero swap on the runners. The convergence dispatch needs the repaired fleet-converge.yml on main first. Until then, receipts read the old 26/25 GiB + swap slot.

Terminal ledger

Every PR open when the closeout started on 2026-10-09, plus every PR opened during it, now has one of these outcomes. Generated from GitHub state and from ancestry checks against this branch.

Folded into this branch (122): head is an ancestor of the branch, PR closed as superseded

#12942, #13072, #13108, #13126, #13202, #13210, #13224, #13225, #13243, #13247, #13255, #13260, #13307, #13308, #13320, #13325, #13328, #13333, #13346, #13351, #13357, #13359, #13379, #13380, #13406, #13412, #13425, #13428, #13429, #13436, #13438, #13442, #13453, #13454, #13460, #13469, #13472, #13496, #13497, #13501, #13502, #13503, #13507, #13511, #13513, #13516, #13517, #13519, #13520, #13544, #13545, #13548, #13549, #13550, #13554, #13560, #13563, #13565, #13566, #13567, #13568, #13569, #13570, #13571, #13574, #13575, #13577, #13579, #13580, #13582, #13583, #13584, #13585, #13586, #13587, #13588, #13590, #13591, #13593, #13595, #13596, #13597, #13598, #13599, #13600, #13601, #13602, #13603, #13604, #13607, #13609, #13610, #13611, #13613, #13615, #13616, #13618, #13621, #13622, #13625, #13626, #13633, #13635, #13636, #13643, #13644, #13646, #13649, #13650, #13651, #13653, #13655, #13657, #13658, #13659, #13660, #13661, #13665, #13666, #13667, #13668, #13669

Folded, then taken back out

PR Outcome
#13123 folded, then reverted in favour of the AdmitCallersEdge route (#13643)
#13341 folded, then dropped during the eager-gull fold
#13662 folded, then reverted by operator ruling; re-landing on main as #13670
#13663 folded, then reverted by operator ruling; re-landing on main as #13671
#13664 folded at 7fe66fb, then reverted per review 5474794145 (close without folding); the branch is kept for archaeology, and #13672 is held as a draft

Closed without folding (74)

PR Title Why
#12691 Journal initial commissioning and gate workspace supply on committed r A stale draft on codex/allocation-vertical (2026-09-29), not targeting main. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, surv…
#12707 luna pro low qual Model-eval scratch ('luna pro low qual'), stale since 2026-09-29. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The b…
#12737 kimi k3 low Model-eval scratch ('kimi k3 low'), stale since 2026-09-30. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch …
#12749 Observe mode for the approval broker: unit, journal, slice cgroup, /li A stale, conflicting approval-broker observe-mode change (2026-09-30), superseded by later broker work. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations,…
#12917 DS4.1 Model-eval scratch ('DS4.1'), stale since 2026-10-01. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kep…
#13097 G1: belt verify through the materialization provider; compute outcomes G1 store/belt cutover: red, an incomplete cutover. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept f…
#13125 belt: demote the monolithic tick into event-driven attempt obligations Superseded by #13641 at 634453d, which folds this PR at 75af82e (via integration/bold-bee-114). The WIP head 9f20643 (always-true scratch_tc test, unfinished drain lifecycle fixes) was deliberately NOT folded and…
#13149 Unify printer starts behind ntfy approval, idle checks and durable cla A conflicting printer draft, superseded by the printer work landed in #13334. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, sur…
#13211 mtcollins1 runner: dispatch the floor to the attempt's slot and read t The floor-runner dispatch is red at its 90-minute floor cap, and it serves the retiring floor. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that…
#13212 Starter eval set: .dag modeling and DESIGN.md adherence, graded mechan Not fixing these under the v1 closeout. #13212 (starter eval set) is up for closure in #13641's terminal ledger: an eval harness doesn't serve the frozen seed emission, v2-native development, or live operations, which is…
#13217 Deployment risk D2: role-following singletons resolve the prod-role ho D2: red floor and conflicting with main; the deployment-risk D2 stack is not complete. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is comp…
#13218 Route approval clients to the active store writer A conflicting draft, superseded by the approval-broker store work. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The …
#13223 Separate pinned Orca fit-prototype preparation from printer execution A conflicting printer draft, superseded by #13334. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept f…
#13252 mtcollins1 runner offer at measured one-socket shape + census meminfo Waits on a census boot measurement that doesn't exist. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is ke…
#13265 Type parameters bind only inside their own declaration (rule 2 / A'; s REQUEST_CHANGES (review 78367): it would bind Result's ok to an unrelated fn ok (fabricated type). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and …
#13284 v2: kernel-String concat through a free-monoid structure bound on the Red and conflicting; its XL-2 lane is cancelled. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for…
#13288 mtcollins1 runner: the dedicated runner-qualification group, ensured o Stacked on #13211, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13295 Consolidate cassette joinery, power and shared platform profiles A conflicting printer consolidation (2026-10-04) with no owner. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The bra…
#13330 Derived-node identity step 2, shape 2: unify_generics reads a containe REQUEST_CHANGES (review 76999): a new std Bool predicate over DeclField. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives…
#13339 D2 follow-up: role-singleton observation by host self-report (ssh prob Stacked on #13217, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13377 node_query: qualify the Cardinality/Optional references (import-level Red; its partial import makes the DependencyView ambiguity worse. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The b…
#13378 std.unicode.scalar: partial from_code_point (typed refusal) + char_tex Red and stale against #13453. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology; no fo…
#13382 Accepting wildcards cut 1: name the verdict classifier and the two rou Accepting-wildcards cut 1 is blocked only on the retiring floor's browser-toolchain premise; the surviving native job doesn't require it. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-nati…
#13383 Accepting wildcards cut 2: name the vocabulary walls, the grounding ga Stacked on #13382, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13390 Split RFC 3986 §2.1 percent-coding into extdeps.uri.percent_encoding; Stacked on #13378, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13391 Refuse a product value at a kernel-scalar (or refined) declared type REQUEST_CHANGES (review 78347): the climb claim omits its required whole-corpus census. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is com…
#13392 Manual git R0 fixture: request the default -z records its decoders mod Stacked on #13378, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13399 Move the bottom seam to the leaf std.error_primitives; trim diverges t Red and conflicting with main. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology; no f…
#13411 Accepting wildcards cut 3: name the two wet-step exit gates Stacked on #13383, which is closed. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology;…
#13420 Managed-host cut 5: fan, served-UI and KVM observations over ManagedHo Red; waits on floor machinery that is being retired. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept…
#13426 Foreign lexer reds: rust ingest bare +, TS single-quoted string body; Never ran CI; based on gate/parse-test-foreign-grammars. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is …
#13430 XL-2 PR2b: string templates — disjoint lexer, one ^dag_string_template XL-2 PR2b; red WIP head with scratch; its lane is cancelled. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch…
#13432 [DO NOT MERGE] baseline control: fixture-closure union with only a KVM A scratch baseline control marked DO NOT MERGE. The branch is kept for archaeology; no follow-up obligation is created.
#13475 fold_list empty: [] no longer locks the accumulator as List Red (4 failing checks). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology; no follow-u…
#13482 C2: typecheck materialization through the local store The C2 cross-run typecheck store is unfinished (no real-route control or timings). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete…
#13488 Design: nested optionality census + layer-count carrier (no code) REQUEST_CHANGES (review 78334): the 'no code' plan rewrites the compiler; layers: Int admits 0/-1 and saturates at 8. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or li…
#13541 Retire v2.std.algebra filter/any onto the collection roster's callback 15 scratch shell scripts at the repo root (review 78343); conflicting. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. …
#13552 BMC-hosted shell boot as a boot-delivery candidate; name srv13-srv16 Closing in the v1 closeout: it builds the BMC-hosted boot route, which was dropped, and its srv13-16 naming is already in #13570 (folded into #13641). Branch kept.
#13555 BMC-hosted netboot: plans derive from a per-host roster; srv4 unchange Closing in the v1 closeout: it builds the BMC-hosted boot route, which was dropped, and its srv13-16 naming is already in #13570 (folded into #13641). Branch kept.
#13557 plans: tie native memory rulings to resumable roadmap milestones A plans-only draft; the plans bankruptcy (#13550) applies. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch i…
#13558 N7: derive payload-binder facts for construct-field consumption Based on the non-main n7/payload-binder-combined-base; never ran CI; its stack includes the #13630 fail-open. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live opera…
#13564 argv dissolution: replace hand-typed id/hostname argv with typed build Closed as superseded by #13626 (folded into #13641): both replace the hand-typed id/hostname argv in host_reach_identity_probe with the extdeps.tools builders. Branch kept.
#13572 argv dissolution: Lane A complete (HTTP -> transport rest), Lane B pa… argv dissolution Lane A/B: closed by its owner, superseded by the folded argv work (#13626).
#13573 os_install_actuator_selection witness: pin the declared rosters by who Closing as superseded: main fixed the same witness independently in 13b9152 (match on the optional .first() instead of T? == T), which uses the runtime-sound match-on-Present form (#13581). This PR now conflicts and …
#13576 DRAFT: floor-control for #13575 (plan forged-probe census) A throwaway red draft control for #13575. The branch is kept for archaeology; no follow-up obligation is created.
#13578 Generalize hosted OpenAI-compat failures (one classifier, no retry) REQUEST_CHANGES (review 78337): a PlacedOnFleetSeat meaning-fork and a fabricated clock. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is co…
#13589 shell_exec_run: judge the witness argv as a whole value (optional-equa Closing as superseded: main fixed the same witness independently in d0f2067 (match the Optional from first(), the runtime-sound form per #13581). This PR now conflicts and adds nothing. — sent from lively-ram-153
#13592 argv dissolution: live-deploy restart+tailscale as typed privileged ar argv dissolution (live-deploy restart, tailscale): closed by its owner, superseded by the folded argv work.
#13605 DRAFT control: #13211 floor on #13575 (DO NOT MERGE) DO-NOT-MERGE floor control for #13211. The floor is retired.
#13606 Tail-position rewrite: walk_cgroup + entry_presence (unblocks D2 floor Closing: this PR was auto-opened from an unverified draft (not compiled, not emitted, no claim run, per its author's handoff). The same fix is being finished, with receipts, by sharp-heron-165, who will open the PR that …
#13608 RFM: fixture-closure-union-emit suspected superlinear cost Superseded by #13641: only the two emitter commits (23f2d08, 8ff94ca) were taken, re-derived as #13665 and folded. The floor-only instrumentation commits were dropped because the floor lane is deleted, per review…
#13612 DRAFT control: #13211 floor with #13608 union-emit fix (DO NOT MERGE) DO-NOT-MERGE floor control for #13211. The floor is retired.
#13614 seed interpreter: withdraw the spelling-admitted, label-blind PureCall A seed-interpreter fix; the interpreter isn't part of the one retained seed emission. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is compl…
#13617 Key native producer_compiler on the running seed executable A paused legacy seed-provenance programme; not required for the one retained seed emission. The branch is kept for archaeology; no follow-up obligation is created.
#13620 CONTROL (do not merge): #13211 head + union-emit begin line DO-NOT-MERGE control for #13211. The floor is retired.
#13623 Type undeclared lambda actuals from preceding application formals (N7 Stacked on #13558's non-main base; red on its target. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kep…
#13624 CONTROL (do not merge): #13211 head + union-emit begin and stage lines DO-NOT-MERGE control for #13211. The floor is retired.
#13628 Native product cache: use this runner's rustc on a hit (fix cross-runn Closing as a duplicate of #13627, which carries the same fix (re-resolve this runner's rustc on a hit, admit only on identical identity) with typed refusal causes, and is already green. — sent from swift-bat-828
#13629 Floor: reach differential reuses the prepared required_floor authority It repairs the retiring v1 floor's reach differential; the floor is removed by the CI bankruptcy. The branch is kept for archaeology; no follow-up obligation is created.
#13630 Recover callee Arrow through Instantiation-grounding refusal REQUEST_CHANGES (reviews 78331/78359): a section 5 fail-open where a refused callee reaches eval. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and t…
#13631 dusk qwen 1 Closing in the v1 closeout. It doesn't compile (~640 errors), and the credential model is unresolved (the rest ops take username/password while the call sites pass netrc_file). The lane's handoff says to restart from scr…
#13632 dusk qwen 3 jq length(null)->0 is a fabricated default (DESIGN section 5). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The bran…
#13634 C2 #13482: the seven review fixes (own-interface entries, lookup-first Follow-up fixes to the unfinished C2 store (#13482, also closed); it also re-adds the scratch t_tmp.sh (review 78363). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or l…
#13637 XL-2 3c: enumerate ServiceSetAside consumers before delete-first A docs-only plan; the plans bankruptcy (#13550) applies. The branch is kept for archaeology; no follow-up obligation is created.
#13638 XL-2 PR2b: finish #13430 string templates Duplicate of #13430 (same 1107-line change from the archived predecessor). Superseded; branch kept.
#13639 Deployment risk conformance: one environment model for the repo The D2 respawn; REQUEST_CHANGES (review 78345): unstated Absent->srv1 fallbacks. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, …
#13640 mtcollins1 runner: dispatch floor to ephemeral slot + collect instrume A superseded WIP flush (quiet-cat-583). The branch is kept for archaeology; no follow-up obligation is created.
#13642 Census: quoted-key brace is not a record field at resolve, not lowerin Red (2 failing checks). Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology; no follow-u…
#13645 Compile door: do not refuse module shells as member_not_a_binder Parent asked not to open a PR; this item is folded into integration/bold-bee-114 (#13560). Branch kept for the closeout report.
#13647 qwen babysitter Closing in the v1 closeout. This branch adds only #13632 on top of #13626, and #13626 is already in the mega branch #13641. #13632 is left out: its lane checked against a real run that jq length/count on a null or wron…
#13648 v2 Foundation Mgr Closing in the v1 closeout. This PR was auto-opened when neat-boar-16 was archived. pkg11b-fix is a stale late-September worktree with no merge base with main, and the flushed WIP commit c055320 adds only .probe_tmp/…
#13652 qwen babysitter Closing as a duplicate. The dashboard re-opened this integration branch's PR when its manager was archived. Its content is in the v1 closeout mega branch #13641 (for qwen-argv, #13626 is in and #13632 is deliberately lef…
#13654 Compile door refuses minimal modules with member_not_a_binder (blocks Closing: auto-opened when lively-wren-411 was archived. This is the superseded duplicate of #13560, which is in #13641. Review 78370's over-broad identity exemption does not reach #13641: #13560's module-surface predicat…
#13656 dusk qwen 2 Closing in the v1 closeout. This is a wind-down WIP push (8255a8f) of the #13626 follow-up on FQDN vs short-hostname identity. That decision is still open, and review 78372 shows the WIP contradicts itself: the probe …

Landed on main directly during the closeout window, before main was frozen (6)

#13334, #13509, #13559, #13581, #13619, #13627

Still open

PR Why
#13641 This PR.
#13203 Blackjack, kept open at the operator's request.
#13670 #13662 re-landing on main after this PR, by operator ruling.
#13671 #13663 re-landing on main after this PR, by operator ruling.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits October 9, 2026 17:10
# Conflicts:
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
# Conflicts:
#	dag/gunbc/auth/privileged_effect_census.dag
# Conflicts:
#	src/v2/std/symbol_index.dag
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
# Conflicts:
#	dag/gunbc/instruments/native_emission_controls.dag
…aven-357

# Conflicts:
#	src/v2/workflow/floor_pure_producer_share.dag
Brian Searls and others added 2 commits October 10, 2026 04:23
… main.

GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ay outside the closeout)

deep-cat-540 recuts it onto main after #13641.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 3 commits October 10, 2026 05:12
Review 78408: regeneration had folded a sold-out Spark roster into target options: [] while spark_* modes stayed selectable. Restoring srv5-srv12 would invent enrolled hosts. Emission now drops the target input and spark_* mode options, and refuses any remaining empty InputChoice.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ndary.

A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha.

Co-authored-by: Cursor <cursoragent@cursor.com>
… on 5c0d9d5

The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around.

First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs.

Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here.

Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 2 commits October 10, 2026 07:23
…he administrator roster is empty; refuse an empty choice at emission (port of ffe8a90)

The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes.

What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name.

The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
's body (review 5474794145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot requested a review from briansrls October 10, 2026 07:46
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Composed head 353b24efc70 = #13675 (2c6b90864d9, stage0 + projections regenerated once, fixed point verified) + deletion of docs/plans/v1-closeout-pr-accounting.md. The terminal ledger and receipts are in the PR body. witnesses is green on this exact sha: run 38034358978. Re-review requested for review 5474794145.

gunbc-ci-auto-heal added 2 commits October 10, 2026 07:52
…5477471759: close #13664 without folding, branch preserved; projections regenerated next
# Conflicts:
#	.github/workflows/fleet-converge.yml
#	dag/gunbc/fleet/fleet_converge_workflow.dag
#	docs/design-rung-drops.md
gunbc-ci-auto-heal and others added 2 commits October 10, 2026 08:38
… (name + branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET (review 78420)

Review 78420 on gunbc#13660 (folded here at 60c9457) found that extdeps.github.deployment_environments modeled the deployment-branch policy as SelectedRefs { refs: ["refs/heads/main"] }, while the API carries no refs: the environment object's deployment_branch_policy is null or { protected_branches, custom_branch_policies }, and the custom rules live at GET /repos/{owner}/{repo}/environments/{name}/deployment-branch-policies as branch_policies rows { name, type } with type "branch" or "tag". A reading of the real API can therefore never match the modeled refs, so gunbc.auth.github_deployment_environment's standing could never move from Unobserved to Holds (DESIGN section 3: model what the API actually returns; section 5: a check that cannot be discharged is not a boundary).

The model now carries DeploymentBranchPolicyRule { name, ref_type: PolicyRefBranch | PolicyRefTag } under SelectedBranchesAndTags { rules }, the srv1-production requirement is the single branch rule named main with required reviewers, the restriction predicate requires exactly one rule that is a branch named main, and the read obligation names both GETs and the shapes they return. The witness gains a supplied-value control: a tag rule named main and a two-rule policy are not the main-branch boundary, the single branch rule is. Standing stays Unobserved until the operator applies the setting and its readback lands; that flip is the first follow-up on main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…13664, fold of #13660)

Same recipe as f8c3fa4, on a shallow clone of dbdc9d2 with the previous fixed-point seed as the boot seed (srv1, logs8): main_wet exit 0; required-regen generation 0 drifted gunbc_cli_dispatch_surface.rs (gunbc.cli_dispatch_surface is touched by #13660), generation 1 drifted gunbc_cli_dispatch_generated.rs, generation 2 first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; verify (dry main) exit 0; rebuild; gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0 warning_count=0 wall_s=611, discriminating red on v2_cli_compile_cli) and //gunbc/instruments:self-host exit 0 (wall_s=716, red on v2_compiler_compile). The projections resolved toward #13660's side in the merge (ROADMAP.md, fleet-converge.yml, docs/design-rung-drops.md) were byte-identical to main_wet's output, so only .gitattributes and the two cli_dispatch mirrors change here.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Composition receipts for the head neat-wolf-604 is fast-forwarding to, repair/closeout-composition-a at 2bf8735 (four commits over 353b24e), prepared per review 5477471759:

  • Item 1 (the exact head builds and both native instruments pass). Stage0 set regenerated from one known-good seed to a fixed point, twice: first on 5c0d9d5 (first_generation_equal=true at generation 2, PR closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5d667 #13675, folded at 2c6b908), then on this composition (generation 2 again: first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; only .gitattributes and the two cli_dispatch mirrors changed). Drift verifier (generated_artifact_gate main) exit 0. On srv1 with the fixed-point seed: gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0, warning_count=0, wall 611 s, discriminating red established) and //gunbc/instruments:self-host exit 0 (wall 716 s, red established). No generated Rust was patched by hand: the one provisional (three pub mod roster lines the earlier integration regen had dropped) was restored before the first regen and is now the regen's own output, and v1_rt.rs is unchanged. The fleet's own run on the previous composed head 353b24e was green (run 38034358978); the run on this head follows the fast-forward.
  • Item 2 (Make fleet-converge branch-agnostic and parseable #13660). Folded at 60c9457 (dbdc9d2), closed as superseded by snappy-stag-26 with the parser receipt: the composed fleet-converge.yml has 20 dispatch inputs and 12 jobs, and a plan/srv1 dispatch from this branch created run 38038258991 with real jobs. One shape defect review 78420 found on that fold is fixed here (fecc974): the deployment-branch policy is modeled as GitHub returns it (name plus branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET once the operator applies the environment setting (that application and readback remain the first follow-up on main; the session's app token cannot write environments).
  • Item 3 (Land the v2 cutover program as designed roadmap entries #13664). Its fold (5c0d9d5) is reverted (b5bd6a5); the content stays reachable at 7fe66fb for archaeology and in bold-crane's draft Population: inhabitance claim over the real row + declared runtime task #13672, which is held, not landed.
  • Item 4 (memory policy enforced before the receipt). Deferred to post-landing, stated here rather than silently: the slot convergence is dispatched through the repaired fleet-converge.yml, which reaches main only when this PR lands, so the receipt on this head will still read the old 26/25 GiB + swap slot on the fleet. The model row (22/21/0) and the gate's refusal on any OOM or swap are in; the converge-then-cold-run order is the first fleet action after landing.
  • Item 5. The accounting doc is deleted (353b24e); the terminal-ledger body is neat-wolf-604's.

— sent from smart-gull-336

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Required run on the final composed head 2bf8735: witnesses success (run 38043137616, 09:56 to 10:18): seed build, self-host emit and build exit_status=0 warning_count=0 wall_s=585, v2-native-cli exit_status=0 wall_s=512, fresh product receipts, slot-grain MEMORY RECEIPTs on srv3-07 (still the pre-convergence 26/25 GiB + swap slot, as stated above under item 4). GitHub admits the merge (mergeStateStatus CLEAN before the review decision). Ready for the operator's landing decision; neat-wolf-604 files the ask.

— sent from smart-gull-336

@briansrls
briansrls merged commit fa44b98 into main Oct 10, 2026
1 check passed
@briansrls
briansrls deleted the integration/v1-closeout branch October 10, 2026 15:27
gunbai-bot Bot pushed a commit that referenced this pull request Oct 10, 2026
…perties.

Rebase onto #13641 left stream_properties using exit_hook without declaring it, so the headless spawn claims could not resolve.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Oct 10, 2026
…it executor (#13670)

* Headless Claude dispatch: print argv, systemd unit, stream-json projection.

When the harness has no spark, ExecutorDefault can admit Claude if custody is present; events stay in the belt's Codex envelope. Credential converge on srv1 remains an operator decision.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 78387: one Claude event mapping, explicit executor, transmit effort.

parse_codex_jsonl now classifies bounded Claude stream-json via claude_code_line_codex_kind; jq only bounds those lines. ExecutorDefault stays a harness refusal. Print argv carries --effort.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 78389: emit tmux event pipe only for tmux containers.

Claude and harness systemd spawn no longer derive readiness from tee/pipe emission or refuse as tmux-event-pipe-emit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Replace CodexProviderEventKind with a provider-neutral classifier.

Delete the Codex-named event vocabulary at the root. One typed classifier
decides observe, skip, or refuse; jq only bounds and preserves fields.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refuse fabricated Claude projector fields and malformed tool-use content.

jq no longer fills is_error or subtype; the typed reader refuses a missing
or non-boolean is_error. Assistant and user content that is not a well-formed
block list is unreadable rather than treated as no tool use.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Thread closeout ExecStopPost through the split stdout/stderr unit properties.

Rebase onto #13641 left stream_properties using exit_hook without declaring it, so the headless spawn claims could not resolve.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls restored the integration/v1-closeout branch October 10, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants