Skip to content

closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5d667 - #13675

Merged
gunbai-bot[bot] merged 2 commits into
integration/v1-closeoutfrom
repair/closeout-stage0-regen
Oct 10, 2026
Merged

gunbai-bot[bot] merged 2 commits into
integration/v1-closeoutfrom
repair/closeout-stage0-regen

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Regenerated stage0 set and projections for the composed closeout tip, at a fixed point (for neat-wolf-604 to fold into integration/v1-closeout).

Base: integration/v1-closeout at 5c0d9d5 (the revert of #13663 and the fold of #13664's fixed head included). The first commit adds exactly the files that main_wet and claim_executor --required-regen changed on that tree, iterated with the tree's own rebuilt seed until the regen reported the first generation equal (two generation-1 provisionals explained below; everything in it is generated). The second commit is one authored hunk the reviewers of the first forced, explained in its own section.

What was wrong, and the repair

claim_executor --required-regen refused on the tip with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate), the same refusal neat-wolf-604 hit with the d9368e8 seed. The coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed (an emitter that predates the crate planner, #13597) rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and their .dag sources stayed in the tree. So every edge touching those modules reported no crate, and no seed could fix it because the check is over the tree.

Repair: restore the three declarations in lib.rs where 3674580 had them (before the v1_tests_claim_interpolation_hole_census block), then regenerate with a seed whose emitter knows the planner (built from 3674580). The regenerated lib.rs lists them canonically, and the loop reaches the fixed point.

A second generation-1 provisional, also recorded in the closeout's own history (42954d2): --required-regen renders src/v1/stage0/src/v1_rt.rs from the SEED's compiled-in runtime rows, not from the tree, so the boot seed's candidate carried a v1_rt.rs without the host-budget join (HostBudgetCgroupV1, HostBudgetJoin) that the tip's memory_governor mirror consumes, and generation 1 failed to build. The committed v1_rt.rs is kept for generation 1 (it is consistent with the tip: no runtime_rust.dag or v1_rt.rs commit since d9368e8, where the seed built and both instruments were green); generation 2, whose seed carries the tip's rows, emits it canonically and the fixed point includes it.

Recipe (srv1, shallow clone of 5c0d9d5; each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0, GUNBC_MEMORY_BUDGET_BYTES=60000000000)

boot seed: cargo build --release -p v1-compiler --bin gunbc --bin claim_executor   (on 3674580f62f)
W:  gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet
R:  rm -rf target/stage0-regen-candidate; claim_executor --required-regen --source-root dag --source-root src/v2
    (exit 1 with first_generation_equal=false writes the candidate; install it: cp -r target/stage0-regen-candidate/src/. src/v1/stage0/src/)
B:  cargo build --release -p v1-compiler --bin gunbc --bin claim_executor   (the tip's own seed)
V:  gunbc run ... --function main   (dry verify)

Order: W, lib.rs repair, R with the boot seed (first_generation_equal=false, planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs], candidate 244 files) -> install -> B, W, R with the tip's seed until first_generation_equal=true -> V -> gunbc test //gunbc/instruments:v2-native-cli -> gunbc test //gunbc/instruments:self-host.

Receipts

All on srv1, shallow clone of 5c0d9d5 (~/sg336-boot/tip3, logs under ~/sg336-boot/logs4..7), every step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0:

step result
boot seed (3674580) cargo build --release -p v1-compiler --bin gunbc --bin claim_executor exit 0, 5m20s
main_wet with the boot seed on the tip exit 0 (11 min; 59 projection writes)
required-regen with the boot seed, after the lib.rs roster repair first_generation_equal=false planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs], candidate 244 files
generation 1 (tip seed from the candidate + committed v1_rt.rs): build / main_wet / required-regen exit 0 (442 s) / exit 0 (591 s) / first_generation_equal=false (503 s; expected: the boot seed's emitter differs from the tip's)
generation 2: build / main_wet / required-regen exit 0 (461 s) / exit 0 (584 s) / first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs] (482 s)
verify (generated_artifact_gate main, dry) with the generation-2 seed exit 0
rebuild after the last main_wet (gunbc test refuses StaleBinary otherwise) exit 0 (335 s)
gunbc test //gunbc/instruments:v2-native-cli exit 0; emit and build completed exit_status=0 warning_count=0 wall_s=616; discriminating red established on v2_cli_compile_cli (red=610); filesystem and native-ingest layout controls held; door refused as cli_no_entry; closure fb87bd0506212b90…, binary d816d15e6f33d1a9…, seed 551d9f5f697bc28f…
gunbc test //gunbc/instruments:self-host exit 0; v1->v2 emit and build completed exit_status=0 warning_count=0 wall_s=706; discriminating red established on v2_compiler_compile (red=4256); poison specimen refused (tokenize_lex_e1_unrecognized_char); closure 3395c09396cc3c30…, binary 08d0e50fcaee8efc…, same seed
tree after the instruments the same 15 changed files as after the fixed point (no instrument wrote into the tree)

No MEMORY RECEIPT lines: the envelope is not requested outside the fleet job (GUNBC_MEMORY_ENVELOPE_REQUIRED unset), so these runs establish the products, not the slot reading.

Second commit: one authored hunk, because the faithful regen was GitHub-invalid

The reviewers of the first commit found that the regenerated fleet-converge.yml carried target: type: choice, options: []: the Spark administrator roster (gunbc.spark.credential_workflow) has been empty since 2026-10-10 and the authority had no wall for an empty closed choice, so the regen was faithful and the artifact undispatchable (GitHub rejects a choice without options; the old committed file was drift the other way, hand-kept srv5..srv12 for hosts no longer enrolled). Review 78408 on #13660 found the same, and snappy-stag-26 fixed the authority at ffe8a90; #13660 is ruled outside the closeout at its WIF scope, so the second commit here ports exactly that empty-roster hunk and nothing else: fleet_converge_spark_target_modes, fleet_converge_dispatchable_modes(), the target omission filter over fleet_converge_dispatch_input_rows, fleet_converge_empty_choice_input_names(), and the refusal arm in expected_fleet_converge_yml() (DESIGN §5: refuse, never emit options: []), plus the two witness changes. The regenerated workflow is main_wet's output over that authority with the fixed-point seed: the target input is gone, the mode choice carries no spark_* entry, 20 dispatch inputs remain under GitHub's 25, and the six inputs.target references sit only in steps whose mode can no longer be selected (main_wet exit 0 on srv1, logs7). The stage0 mirrors are untouched by it (the module is not in the emitted population), so the fixed point of the first commit stands.

Witness: claim_batch --entry dag/test/claim/workflow_dispatch_input_witness_test.dag over its 38 functions on the ported tree: 38 PASS, 0 FAIL, exit 0, including every_dispatch_option_is_a_wire_value_of_the_vocabulary over the dispatchable modes and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes.

Reviewer notes carried for the operator (not changed here): the regenerated workflow, by the authority #13436's fold already carries, lets the gcp-iam-converge job also fire for mode == branch_run_grant and adds a WIF mint of hetzner-cloud-control through the branch-dispatch pool github-fleet-converge-dispatch; both are gated on an operator-approved request step under the same environment, and no YAML guard was dropped relative to the old file. The host-shell roster in lib.rs is self-referential (read by the regen as input and written as output), so a module whose only consumer is hand-authored host Rust has no .dag-visible demand and can be dropped by a regen from an older seed; that is the structural cause of the Stage0EmittedEdgesNotCovered loop and is recorded as a runtime task, not fixed here.

What the fold needs after this

  • Nothing authored changes here. If the closeout tip moves before the fold, re-run W and R once with the seed built from this branch; the mirrors stay at this fixed point unless the move touches the emitted population.
  • One green witnesses run on the exact composed sha before the operator lands v1 closeout mega branch #13641.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits October 10, 2026 06:38
… on 5c0d9d5

The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around.

First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs.

Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here.

Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…he administrator roster is empty; refuse an empty choice at emission (port of ffe8a90)

The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes.

What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name.

The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review October 10, 2026 07:23
@gunbai-bot
gunbai-bot Bot merged commit 2c6b908 into integration/v1-closeout Oct 10, 2026
@gunbai-bot
gunbai-bot Bot deleted the repair/closeout-stage0-regen branch October 10, 2026 07:25
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Folded: integration/v1-closeout was fast-forwarded onto this branch's head 2c6b908 by neat-wolf-604 (closeout tip 353b24e adds only the accounting-doc deletion), and the required witnesses run on that head is green (run 38034358978). The composition then moved to repair/closeout-composition-a per the operator's review 5477471759 (revert of the #13664 fold, fold of #13660); the stage0 set of this PR is its base. Closing as folded, branch kept.

— sent from smart-gull-336

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants