Repository navigation
Required CI: withdraw the four v1-judged lanes; the gate is emit-build alone (operator ruling 2026-10-09) - #13658
Conversation
…d alone (operator ruling 2026-10-09) The operator's v1 withdrawal: v1 is no longer a validation authority, and the one use left to the seed is emitting v2. gunbc.compiler_gate_workflow drops `floor`, `generated`, `rust-unit-tests` and `seed`; the `witnesses` aggregate reads the one remaining lane, `emit-build`, through the same folded roster (one row). The GateArmSkippedOnPullRequest arm leaves with its only inhabitant. The loss is one declared drop, gunbc.rung_drop v1_required_lanes_withdrawn, stated member by member (witnesses, stage0 mirrors and every generated artifact, lint, v1 unit tests, module resolution outside the two emitted closures, the downstream consumers), with a trigger that names the capability: a binary built from an emission of v2 judging that population on the required path. rust_unit_tests_off_pull_requests is Superseded (its lane runs nowhere; trigger did not fire; the new row holds the loss). gunbc.required_ci_contract_epoch moves to 2026-10-09.1: the name `witnesses` now carries a materially different contract. Consumers repaired rather than left dangling: the lane-resolution census roster (the census now does not hold by design and is the instrument that re-derives the drop's module population), DESIGN section 3's typed required-gate reference (gunbc.documentary_refs, now emitted_subject_build_rows), the Building & checks rows, the onboarding path's run-witnesses step, five recurring_failure_mode evidence rows that cited deleted declarations, and the two gate witness files (the blocking set is asserted as exactly emit-build; a new RED asserts the four withdrawn variables reach neither gate surface). Projections regenerated by tools.generated_artifact_gate main_wet (the run peaked at 15.8 GB RSS, against the 7.55 GiB that module's own note cites for 2026-08-31): witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/onboarding.md; every other rostered artifact came out byte-identical. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…deletion (pre-merge, projections not yet regenerated)
…e authority and its projections: this branch's side; projections regenerated in the next commit)
…ssion/smart-gull-336
…nvelope rows; managed_host Superseded arm (pre-regen)
…l-336: managed_host takes the closeout's arm; projections this side, regenerated next
…_workflow no longer imports the deleted script-row refusal API 6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…item 3); witness claim the_trip_sits_inside_the_slot_envelope
…ssion/smart-gull-336
…tree One main_wet of tools.generated_artifact_gate over this branch merged with integration/v1-closeout a925452 (regen 632 s, verify 693 s, both exit 0, on srv1 under capped MemorySwapMax=0 scopes), nine artifacts: - witnesses.yml: both subject steps carry GUNBC_BIND_MEMORY_CGROUP_BYTES (the derived trip, 20 GiB) and the failure notice carries the envelope lines (what 137 means, no larger runner and no retry, the MEMORY RECEIPT). - DESIGN.md, docs/design-rung-drops.md: the CI row and the drop roster. - .gitattributes: the deleted heal-publish.yml leaves the generated-artifact merge list. - fleet-converge.yml: the closeout's authority fix projected. - tools/fabric_ci_fci1_bounded_execution_context.env: the fci1 context follows the slot (22/21 GiB). - provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: a 22 GiB slot fits more slots per host than a 26 GiB one, so the derived rosters grow (srv1 gains srv1-10 and srv1-11). Desired state; applying it is the converge effect. The witness batch on the same tree: 16 files, green except the two latent reds already recorded in the PR (fci1_bounded_execution_context: a stale envelope-basis expectation; heal_publication_boundary: 23/34). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Re review 78388 (cursor, on
— sent from smart-gull-336 |
…ip withheld by the declared drop native_step_trip_awaits_fleet_job_cgroup; slot-grain receipt in gunbc test; seed-growth receipt (pre-regen)
…ssion/smart-gull-336 # Conflicts: # .github/workflows/fleet-converge.yml # .github/workflows/witnesses.yml # docs/design-rung-drops.md
… fleet fact; the envelope decision is a .dag fold the seed mirrors The first required run that passed GUNBC_BIND_MEMORY_CGROUP_BYTES (38002497388 on a4b8f78) refused in four seconds: MemoryCgroupBindRefused, the cgroup2 tree is not writable. memory_governor apply_memory_cgroup_bind creates its leaf at the cgroup ROOT (a container-root design; the bind had never been requested on the fleet) and a fleet job runs as the setpriv'd job user under a root unit, so no job process can create the bound. The operator approved the slot-grain arm (escalation 2026-10-09). gunbc.memory_envelope (new) owns the decision and the verdict as folds over supplied inputs -- the sibling of gunbc.memory_cgroup_binding -- and test.claim.memory_envelope_witness_test reaches every arm by supplied value, including the RED an inline decision could not: a slot requirement over a process no numeric memory.max binds REFUSES (MemoryEnvelopeAbsent) rather than running as bounded. The seed mirrors it arm for arm with unit tests; the shells resolve the bounding cgroup through binding_cap_cgroup_dir (never the peak locator), read memory.swap.max/.current/.peak (modeled in extdeps.linux.cgroup_v2_memory) before and after the producer, print a slot-grain MEMORY RECEIPT with event deltas and the peak labelled by whether it rose, and refuse the run on any OOM kill or swap. gunbc.emitted_subject_build_gate carries two envelope inputs and ONE decision over them, native_step_memory_inputs(ownership): every subject step REQUIRES the slot envelope (GUNBC_MEMORY_ENVELOPE_REQUIRED=slot, the projection of EnvelopeSlotRequired) and the bind input at the derived trip is withheld while gunbc.runner_slot_desired gunbc_runner_slot_job_cgroup_ownership is JobOwnsNoBoundedCgroup. That is a fleet fact, not a rung drop -- nothing on the required path ever held the trip -- so the climb is rostered as gunbc.guarantee_stall native_step_trip_awaits_fleet_job_cgroup_stall (grounding: unit delegation with DelegateSubgroup=, a per-job cgroup staged by the root JIT wrapper, the governor's already-bound arm). The workflow and the failure notice consume the fact; the witness exercises both arms by supplied value, reads the live row, and asserts the bind KEY is absent. The slot wall follows the ruling too: gunbc.runner_slot_allocation gunbc_runner_slot_allocation_wall_holds drops its three floor conjuncts (a slot sized to a tenant that no longer runs in it) and requires MemorySwapMax == 0 instead of a swap above the maximum; the floor-fit drop slot_row_pinned_below_demonstrated_demand_unrefused is Superseded with v1_required_lanes_withdrawn as its loss holder; the slot witness re-pins the row to 22/21/0 and its width alarms to the smaller slot's derivation (srv1 12, srv3/srv4 21). The slot's demand oracle from here is the first cold required run's MEMORY RECEIPT, a declared frontier. The trip stays a ByteSize derived from the slot (review 78388 item 3). The seed growth is receipted as gunbc.memory_envelope_receipt_seed_growth (review 78391). The design document's CI row and the slot row's note say the same. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Head
— sent from smart-gull-336 |
|
Re review 78398 (cursor, on
— sent from smart-gull-336 |
The ruling this carries
Operator, 2026-10-09 (the brief to this session, the v2 half of the v1 withdrawal; neat-wolf-604 holds the v1 half): "v1 is effectively bankrupt due to memory instability - i want to go back to pure v2 native compiler development - that means deleting most of our current CI jobs", and "i suggest we bankrupt the current CI first".
This is the bankruptcy. It is a replacement migration cut at the root (DESIGN §3): the lanes are deleted, not retuned, because a v1 lane made survivable is investment in the implementation the ruling retires.
What changes
gunbc.compiler_gate_workflow(→.github/workflows/witnesses.yml) goes from five lanes to one.floorclaim_executor --required-ci --required-lane witnesses)generated--required-lane build), registry drift + repair chain, clippyrust-unit-testscargo test -p v1-compiler --libseedKept: the emit-and-build steps, as ONE required job named
witnesses(second-round ruling: "collapse emit-build plus the aggregate into one required job named witnesses"). The seed emitsv2.compiler.compileandv2.cli.compile_cli, cargo builds the emitted crates, the built binaries are started against their controls (gunbc.emitted_subject_build_gate). The job carries the id the ruleset requires, so its own check is the required context: the aggregate job and the whole derived lane roster (CompilerGateLaneRow, standings, the env block and shell conditionals folded from them) are deleted — with one job there is nothing to join. A second required job is a roster growth the operator signs off, and brings the fold back with it. Fork pull requests now carry nowitnessescheck (the job is fleet-guarded) rather than the excused green the aggregate printed.Fresh emission and build, every run (same ruling: "requires fresh emission/build of both retained products and refuses a restored final-product hit. Ordinary Cargo reuse may remain"). The native product store's steps — job-private root, the two WIF federations, the save — left the job, and every subject step passes
GUNBC_NATIVE_PRODUCT_REUSE=fresh(gunbc.emitted_subject_build_gatenative_product_reuse_env_name/_fresh_value, pinned to the runner's constants by the witness). Underfreshthe runner (native_lane_runnerprepare_emitted_compiler_for_entry) consults no store, commits nothing, refuses a run that also bindsGUNBC_NATIVE_CACHE_ROOT(NativeProductReuseRefused— a contradiction, not a miss), and prints oneFRESH PRODUCT RECEIPTline per product:realization=fresh, the product key's six axes (source closure, producer compiler, target, toolchain, build configuration, lens contract), the emitted closure identity, the seed executable's sha256 and the built executable's sha256. Cargo's own dependency reuse inside the job's checkout is untouched. The job's permissions carry noid_token.Ordinary Cargo reuse, bound (the "may remain" half of the ruling). The isolation step wipes
$RUNNER_TEMP/cargoon every run, so the seed build was fully cold: 3m38s on run 37976254311 for registry download plus 113 crates. The already-modelledgunbc.fleet_workflow_steps ci_cache_cargo_step(actions/cache v5.1.0, admitted; paths = the isolated home's registry index/cache/git db plustarget/, key =cargo-ci-<os>-<arch>-hashFiles(**/Cargo.lock, rust-toolchain.toml)) sat on the deletedseedjob behind a keyed-miss condition; it is nowci_cache_cargo_step_under(condition)and thewitnessesjob binds it unconditionally after the isolation step. It caches the SEED's build and dependencies only — the two products are built in a private probe root the cache never sees, and the gate witness asserts no store marker reaches the job. What it recovers is measured by the first two runs (each runner slot has its own$RUNNER_TEMPpath, so Cargo fingerprints keyed on absolute paths may rebuild across slots); nothing here asserts a number. Levels the ruling closes: no cache of the emission (the interpreter's 21 min, 57% of a PR run — that is the later materialization ruling) and no sccache on the product-crate builds (a served rustc output is a restored product compile under another name). The 6 min the old key derivation + store transfer cost per run is deleted outright underfresh, not cached.One declared drop,
gunbc.rung_drop v1_required_lanes_withdrawn(§4b(3)), with its population stated member by member — the witnesses, the stage0 mirrors and every registry-rostered generated artifact (witnesses.ymlandDESIGN.mdincluded), the lint, the v1 unit tests, module resolution outside the two emitted closures, and the downstream consumers (no merge-queue compiler-pair candidate; fleet admission under a new epoch). Its trigger names the capability: a binary built from an emission of v2 judging that population on the required path, member by member. What does not retire it is stated: returning any v1 lane, a partial native row, a run off the required path, a count where an identity join belongs.gunbc.rung_drop rust_unit_tests_off_pull_requests→Superseded(its text said the unit lane still blocks at the queue; it runs nowhere now; trigger did not fire; loss holder is the new row). No other drop is amended:required_gate_bankruptcy,witness_floor_off_the_required_gate,required_lanes_do_not_resolve_product_layer_modules,v1_integration_tests_deleted_from_the_unit_lanename capabilities a native lane can still fire.gunbc.required_ci_contract_epoch→2026-10-09.1. The namewitnessesnow carries a materially different contract (what a success entitles a consumer to conclude), which is exactly the case that module says to bump for;gunbc.fleet_revision_acceptancetherefore cannot admit a revision judged under the old contract as the new one or vice versa.Consumers repaired rather than left dangling:
gunbc.required_lane_resolution_census_live: thefloor/generatedrows left with their jobs; the census now does not hold by design and is the instrument that re-derives the drop's module population (gunbc test //gunbc/instruments:required-lane-resolution-census).gunbc.documentary_refs: DESIGN §3's typed "inside the required gate" reference repointed fromv2.workflow.required_floor required_gate_prefixes(the deleted floor's roster) togunbc.emitted_subject_build_gate emitted_subject_build_rows.gunbc.design_documentBuilding & checks: the local-checks row (clippy and the v1 unit tests are now local-only), the hook row, and the CI row (what a green required context does and does not say).gunbc.contributor_onboarding_pathrun-witnesses: the floor is no longer "the corpus lane the merge gate runs".gunbc.recurring_failure_moderows cited deleted declarations as typed evidence; each now cites the surviving authority (required_floor_runs_at_its_memory_ceilingalso records that its lane was deleted rather than given headroom, and that the class outlives the lane:emit-buildruns in the same slot class and nothing adjudicates its peak either).gunbc.runner_slot_allocationgunbc_runner_slot_allocation_wall_holds: the wall's three floor conjuncts (MemoryHigh ≥ the floor's minimum viable budget and ≥ its measured uncensored peak, guarded by the uncensored check) are withdrawn with the floor — they related the slot to a tenant that no longer runs in it — and its swap conjunct is inverted by the ruling (it required MemorySwapMax above MemoryMax; it now requires exactly zero). The slot's demand oracle from here is the first cold required run's MEMORY RECEIPT, a declared frontier in the wall's note.gunbc.rung_dropslot_row_pinned_below_demonstrated_demand_unrefused(the drop about that conjunct's blind spot) isSupersededunder the same ruling withv1_required_lanes_withdrawnas its loss holder.test.claim.runner.runner_slot_allocation_witness_testre-pins the row to 22/21/0 by the 2026-10-09 ruling, deletes the dead-tenant claim (the floor's own relation lives infloor_demand_witness_test), and re-pins its two width alarms to the derivation's answers under the smaller slot (srv1 11 → 12, srv3/srv4 17 → 21 — the same growth the regenerated sudoers show).test.claim.compiler_gate_emit_build_lane_witness_test/compiler_gate_workflow_witness_test: claims over the deleted jobs removed; the blocking set is asserted as exactlyemit-buildat identity grain; a new RED asserts the four withdrawn variables (RUST_UNIT_TESTS,SEED,FLOOR,GENERATED) reach neither gate surface, so a partial revert of this cut reds.main_wetover the merged tree, fixed point verified bymain):witnesses.yml(the envelope requirement on both subject steps — the bind input withheld by the declared drop — and the envelope lines in the notice),DESIGN.md,docs/design-rung-drops.md,docs/onboarding.md,.gitattributes(the deleted heal-publish path leaves the generated-artifact merge list),.github/workflows/fleet-converge.yml(the closeout's authority fix projected),tools/fabric_ci_fci1_bounded_execution_context.env(the fci1 context follows the slot: 22/21 GiB), andprovisioning/srv{1,3,4}/gunbc-ghrunner.sudoers— a consequence worth reading: a 22 GiB slot fits more slots per host than a 26 GiB one, so the derived slot rosters grow (srv1 gainssrv1-10/srv1-11); these are desired-state projections, and applying them to hosts is the converge effect the post-landing conditions already name.The memory envelope is part of the verdict (the relayed REQUEST_CHANGES on #13641: "MemorySwapMax=0 and a fixed hard memory maximum; a lower compiler abort/trip threshold; a peak and swap receipt; no larger-runner retry"). Three layers, each modelled, and one of them a declared drop after the first required run that asked for it:
gunbc.runner_slot_desiredgoes 26/25 GiB + 32 GiB swap → MemoryMax 22 GiB, MemoryHigh 21 GiB, MemorySwapMax 0 (the desired state; applying it to hosts is a converge/manual effect, not this PR's).GUNBC_MEMORY_ENVELOPE_REQUIRED=slot(gunbc.emitted_subject_build_gatenative_step_memory_envelope_env_name/_slot_value):gunbc testrefuses a run that no cgroupmemory.maxbinds (MemoryEnvelopeAbsent), reads the bounding cgroup before the producer, and at exit printsMEMORY RECEIPT grain=slot cgroup=… limit_max=… peak_bytes=… high_events_delta=… max_events_delta=… oom_kills_delta=… swap_current_bytes=…— the event counters as the difference over the step, because the slot's cgroup outlives it — and refuses the run on any OOM kill the step added, any swap charged, or an unreadable swap counter, even over a producer that held. "No thrashing, ever" is therefore enforced on every required run at the slot's grain, today, before the host converge.native_step_memory_tripis aByteSizeDERIVED from the slot's MemoryHigh less a declared one-GiB headroom (the_trip_sits_inside_the_slot_envelopeexecutes the derivation; its mutation control is receipted below), andgunbc testbinds it as the step's own cgroup throughGUNBC_BIND_MEMORY_CGROUP_BYTES(the governor's existing bind). The first required run that passed it (38002497388, heada4b8f788) refused in four seconds:MemoryCgroupBindRefused — the cgroup2 tree is not writable. Two host facts:memory_governor apply_memory_cgroup_bindcreates its leaf at the cgroup root (a container-root design; the bind had never been requested on the fleet — main'switnesses.ymlnever carried it), and a fleet job runs as the setpriv'd job user under a root unit. Nothing fell, so this is not a rung drop (an earlier revision of this head declared one; review of that revision called it a §4b(2) stall wearing the §4b(3) carrier, correctly). It is a fleet fact,gunbc.runner_slot_desiredgunbc_runner_slot_job_cgroup_ownership=JobOwnsNoBoundedCgroup, whichnative_step_memory_inputs(ownership)consumes: a job that owns no bounded cgroup is handed the slot requirement alone; a job that does is handed the requirement and the bind at the trip. The climb is rostered asgunbc.guarantee_stallnative_step_trip_awaits_fleet_job_cgroup_stall(current Mitigatable, ceiling MechanicallyPreventable, grounding: unit delegation withDelegateSubgroup=, a per-job cgroup staged at the trip by the root JIT wrapper, the governor's already-bound arm; trigger: a required step observed inside a bounded cgroup at the trip on each host class). Flipping the fact when the fleet earns it returns the bind to every subject step with no other edit; a claim exercises both arms by supplied value, the live claim reads the live row and asserts the bind KEY is absent, and the failure notice is a function of the same fact. Escalated to the operator as the fork it is (host-first vs. slot-grain now); this is the approved arm.The decision is a
.dagfold, the Rust its mirror.gunbc.memory_envelopeowns the requirement (EnvelopeNotRequested | EnvelopeSlotRequired | EnvelopeRequirementUnreadable), the grain,memory_envelope_decision(bind, requirement, numeric_max_binds)andmemory_envelope_verdict(oom_kills_delta, swap_current, swap_peak_rose)over supplied inputs — the sibling ofgunbc.memory_cgroup_binding— andtest.claim.memory_envelope_witness_testreaches every arm by supplied value, including the RED the first revision of this head could not reach: a slot requirement over a process no numericmemory.maxbinds REFUSES (MemoryEnvelopeAbsent) instead of running as bounded. The seed'smemory_envelope_decision/memory_envelope_violatedmirror it arm for arm with unit tests; the shells resolve the bounding cgroup through the governor'sbinding_cap_cgroup_dirwalk (which readsmaxas unset — never the peak locator), readmemory.swap.max/.current/.peak(modeled asextdeps.linux.cgroup_v2_memoryMemorySwapMax/MemorySwapPeak) before and after the producer, and label the peak by whether it rose during the step. The slot'smemory.swap.maxis reported, not required: the ruling's MemorySwapMax=0 is the converge that follows this landing, and until then a step that swaps is refused by observation (resident at exit, or a swap peak that rose) — and a swap peak the kernel cannot show under a cgroup whosememory.swap.maxis not zero is a violation too, never read as "did not rise" (RED_an_unobservable_swap_peak_refuses_unless_the_swap_limit_is_zero, in both the.dagwitness and the Rust tests).The seed growth (the mirror rows and the host-reading shells in
target_invocation_host.rsandfloor_memory_supervisor.rs) is admitted under the v1 PURPOSE test and receipted asgunbc.memory_envelope_receipt_seed_growth(lanev1-hand-queue-drain; trigger: the retained CLI evaluating the.dagfold directly, and the native door receiving the cgroup readings as values) — the row review 78391 asked for.heal-publish deleted (same ruling: "no no-op job left running on every PR"):
.github/workflows/heal-publish.yml,gunbc.heal_publisher_workflow, its registry variant (every exhaustive match fixed forward) and its witness file are gone;gunbc.auth.heal_publisher_federationkeeps the pool's model with the workflow path as a retired literal — the pool is dead, not deleted, recorded as an external-estate obligation.heal.yml(manual) stays. Review 78398's finding — the manual route still seals and uploads the candidate the deleted publisher consumed, so "nothing sealed one" is false for it — is right, and is answered off this head (the operator approved exactly75bd66f0for the fold): the freeze-and-declare commit (the route a named frozen member ofv1_required_lanes_withdrawn's population; header, drop wording and DESIGN CI row aligned; regen/verify re-run green) is onfollowups/smart-gull-336, with the latent-red repairs the same ruling routes to runtime tasks, for a post-fold PR.Base is
integration/v1-closeout(neat-wolf-604 folds this head; #13641 is the only closeout PR into main), and this branch carries a merge of that branch so the diff is clean against it; the gate authority took this side (the #13346 slice-cost step stays a local-only command, per ruling). This PR's own green run is therefore aworkflow_dispatchofwitnesses.ymlon this branch, not a pull_request run.What the required context establishes from here
Green means: the seed emitted both retained v2 closures, both emitted crates built, and the built binaries passed their controls. Nothing else. No witness is evaluated, no module outside those two closures is resolved, no generated artifact is compared with its authority — this PR's own regen included, which is why its drift verify was run locally and is receipted below.
A verdict joins this gate as a row of
emitted_subject_build_rowsjudged by a binary built from the seed's emission (the green set + one frontier target from the operator's plan), never as a lane that hands the corpus to the v1 interpreter.Sizing, by instrument
The producer is the
witnessesjob of any run of this workflow (namedemit-buildbefore this change). Receipt from the last green merge-queue run before this change, 37939840454 (gh run view 37939840454 --json jobs):emit-build57 min wall (seed build 4 min,self-host27 min,v2-native-cli23 min, product save 2.5 min). The deleted lanes on that run:seed5 min →floor50 min (the critical path),generated15 min,rust-unit-tests7 min. So the wall per landing is unchanged (emit-buildwas already the longest lane); what is removed is three fleet slots per run (~77 slot-minutes) and the one process that ran at its slot'smemory.high(gunbc.recurring_failure_mode required_floor_runs_at_its_memory_ceiling).Deliberately not in this PR
emitted_subject_build_rowsonce the operator's plan is agreed.repo_self_slice_cost_control_commandstep (acargo test -p v1-stage0-runtimecontrol on thegeneratedlane, on neat-wolf-604's closeout branch) is not carried over: it is a v1 unit test and joins the withdrawn population's unit-test member. When the closeout branch takes this cut's side on the two files, that declaration is dangling and should be deleted there.Evidence, third round (final head
75bd66f0: this branch +integration/v1-closeoutd9368e89; seed built from this tree)All on srv1 under
systemd-run --user --scope -p MemorySwapMax=0with a hardMemoryMaxper run (28 GiB regen/verify, 18 GiB per witness).61523aa0+): regenerationtools.generated_artifact_gate main_wet678 s exit 0, fixed-point verifymain690 s exit 0; 26 witness files — green:compiler_gate_emit_build_lane_witness_test28/28,compiler_gate_workflow_witness_test4/4,memory_envelope_witness_test10/10,memory_cgroup_binding_witness_test11/11,guarantee_stall_witness_test11/11,action_use_admission35/35,documentary_refs4/4,rung_drop_{amendment,declaration,shared_capability,standing_partition,superseded_standing}4/6/7/4/8,heal_candidate12/12,floor_demand29/29,floor_cold_build_receipt8/8,ci_budget_tree13/13,github_app_registry54/54,gcp_estate_convergence_binding4/4,gcp_iam_bootstrap23/23,runner_group_restriction_ensure10/10,runner_slot_enforcement_grounding11/11,seed_growth_admission9/9,seed_growth_change_population7/7. Red: the two latent main reds (fci1_bounded_execution_context1/2,heal_publication_boundary11/34) andrunner_slot_allocation_witness_test28/34 — this PR's: the slot wall and its witness still asserted the 26/25 GiB row and the floor's demand against it; repaired as described under What changes (floor conjuncts withdrawn with the floor, swap required zero, the floor-fit drop superseded, the witness re-pinned).75bd66f0's content): regeneration 677 s exit 0, verify 682 s exit 0; the eleven touched witnesses green —compiler_gate_emit_build_lane28/28,runner_slot_allocation33/33,memory_envelope12/12,guarantee_stall11/11,floor_demand29/29,seed_growth_admission9/9,runner_slot_enforcement_grounding11/11,rung_drop_{declaration,standing_partition,superseded_standing}6/4/8,documentary_refs4/4.cargo test -p v1-compiler --lib memory_envelope_tests, local): 9/9, includingRED_a_slot_requirement_with_no_numeric_max_refuses_as_absent,RED_an_unobservable_swap_peak_refuses_unless_the_swap_limit_is_zeroandRED_an_applied_or_existing_bind_over_no_numeric_max_refuses_at_its_grain;cargo clippy -p v1-compiler --bin gunbc -- -D warningsclean.witnesses.ymldispatched on75bd66f0— run id and the MEMORY RECEIPT lines are appended below when it completes (the previous head's run, 38002497388, is the four-secondMemoryCgroupBindRefusedthis construction answers).Required run on
75bd66f0: 38016653087 — green (witnessesjob 02:21–02:57, 36 min; seed built with the Cargo cache warm; both subject steps fresh, both discriminating reds established since a dispatch runs the fault experiment). The slot-grain receipts, verbatim — note the slot is still the unconverged 26/25 GiB + 32 GiB-swap row, which the receipt says (limit_max,swap_max), and the step was refused on none of OOM, resident swap or a swap-peak rise:The self-host step's peak rose from 6.4 GB to 17.2 GB inside the step and the CLI step added almost nothing above it — the first phase-peak numbers the ruling asked a cold run to record, at the slot grain; the per-step grain follows the fleet fact.
Evidence, second round (merged tree
cf657e6e= this branch +integration/v1-closeouta9254527; seed65bef5c9)65bef5c9), merged treecf657e6e:test.claim.compiler_gate_emit_build_lane_witness_test26/26 PASS (gunbc run --claim-run, 17.4 GB peak RSS). Mutation control over a scratch copy withnative_step_memory_headroom = byte_size(0): 25 PASS / 1 FAIL, the one red being exactlythe_trip_sits_inside_the_slot_envelope— the claim discriminates on the derivation it names and on nothing else.Two files in that batch are red on pristine
origin/maintoo, under the merged seed AND under an older seed (8653f654, main's tree) — latent reds no required lane ever executed, not this PR's:test.claim.fabric.fci1_bounded_execution_context_witness_testfci1_context_derives_the_runner_workload_envelopeexpects an envelope basis ingunbc.runner_slot_allocationwhilegunbc.fabric.fci1_bounded_execution_contextdeclares it ingunbc.runner_slot_desired(a stale expectation); andtest.claim.heal_publication_boundary_witness_test23/34 red. Left for their owners; recorded here because this is the only place anything records them now.The third latent red,
test.claim.required_lane_claim_agreement_witness_testw_no_projected_ledger_denies_a_lane_the_roster_requires, is the lane-roster fork the one-job cut leaves standing:gunbc.witness_floor_lanesrequired_lanes_rosterstill rostersbuild/floor/… as required whilegunbc.compiler_gate_workflowcompiler_gate_merge_path_job_idsanswers[witnesses], and twelve modules consume the old roster (the gate, the ruleset, the floor workflow, two drops, a failure-mode row, both v2 workflow modules). Cutting it is therequired-lane-roster-after-the-one-job-cutruntime task the ruling names, not a fixture repair; it is recorded here so the fork is named rather than discovered. The other two latent reds (fci1, publication boundary) are repaired onfollowups/smart-gull-336.Two reds in
test.claim.floor.floor_demand_witness_testWERE this PR's (green on main): both joined the withdrawn floor's 2026-09-19 receipts to the live slot row (held ≤ memory_max,armed == memory_high), which the ruling moved. Repaired by carrying the envelope the receipts were taken under as the floor's own rows (gunbc.floor_demand gunbc_floor_pinned_memory_max/_high) and joining to those — the floor is frozen and runs in no slot, so a join to the live row would assert a relation between a dead instrument and a slot it never inhabited.Evidence, first round (local, with the seed built from this tree)
Seed
gunbcbuilt from this tree (cargo build --release -p v1-compiler --bin gunbc, 113 crates compiled,gunbc --version= this base sha); every run below used that binary. Because nothing on the required path judges any of this any more, these are the receipts:tools.generated_artifact_gate main_wetover the whole registry, exit 0; it rewrotewitnesses.yml,DESIGN.md,docs/design-rung-drops.mdand (after a secondmain_wet_one)docs/onboarding.md; every other rostered artifact came out byte-identical. The run's VmHWM was 15.8 GB against the 7.55 GiB that module's own note cites for 2026-08-31 — recorded here as a growth receipt, not acted on.tools.generated_artifact_gate main(the deleted lane's verify argv), exit 0.gunbc run --claim-run --entry <file>on srv1 insidesystemd-run --user --scope -p MemoryMax=20G -p MemorySwapMax=0(the operator's envelope discipline — no swap, a kill is a receipt; none was killed):test.claim.compiler_gate_workflow_witness_test7/7test.claim.compiler_gate_emit_build_lane_witness_test38/38 (the control on pristineorigin/main, same binary: 36/39 — see the next bullet)test.claim.documentary_refs_witness_test4/4 ·rung_drop_superseded_standing_witness_test8/8 ·rung_drop_standing_partition_witness_test4/4 ·contributor_onboarding_path_witness_test18/18 ·fleet.fleet_revision_acceptance_witness_test9/9 ·contract_identity.required_ci_epoch_real_execution_witness_test4/4 ·required_lane_resolution_census_witness_test8/8test.claim.required_lane_claim_agreement_witness_test4/5:w_no_projected_ledger_denies_a_lane_the_roster_requiresis RED, and the control — the same file, same binary, on pristineorigin/main(d0f2067) — is red on the same claim. Pre-existing, and its roster authority is itself stale:gunbc.witness_floor_lanes required_lanes_rosterstill namesrequired-witnesses-build/-floor, lanes deleted long before this PR, while the failure-modes ledger quotes the negation phrase as an example (recurring_failure_mode stale_claim_survives_its_own_correct_edit) and names those lanes in nine rows, and the check conjoins the two at document grain. Not touched here; handed to the roadmap program asrequired-lane-roster-after-the-one-job-cut.origin/main(control run, same file, same binary, pristine main at d0f2067):the_lane_binds_one_step_per_subject_above_the_preludeassertedlength(steps) == 6 + rows + 1, a count the lane outgrew when the native-product steps landed (main'semit-buildjob has 13 steps) — it is now an identity join on step names;the_established_lanes_still_blocklisted four lanes whileseedhad joined the blocking set on 2026-10-06; andw_RED_the_deleted_unit_test_lane_reaches_neither_surfaceasserted the absence of a lane that had returned. All three are green here because the roster they describe is now one row. That this file could sit red on main with the required context green is the drop's population made concrete: it is outside the floor's gate prefixes, so no required run ever executed it.Review pointers
witnesses.ymldiff is large and mechanical; readcompiler_gate_lane_rows,compiler_gate_workflow.jobs, andexpected_compiler_gate_yml's conjunct list in the authority instead.🤖 Generated with Claude Code