Skip to content

Finish the self-host memory audit PRs (#13673, #13674): fail-closed receipt writer, discriminating reader checks, lever stacked on the audit - #13676

Closed
gunbai-bot[bot] wants to merge 10 commits into
mainfrom
stack-lever
Closed

gunbai-bot[bot] wants to merge 10 commits into
mainfrom
stack-lever

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session eager-ibex-819.
Pushing to stack-lever advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 10 commits October 10, 2026 05:30
…del row, pool-drop counterfactual

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…p claims of a parser and a consumer that do not exist

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e figures in module or doc; drop the production-path pool-drop lever; declare the consumer frontier

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…pt; correct module citation

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ler/regression declared as frontier

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ed Optional<ByteSize> readings; trend rows consumed by the readout

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…adout, seed-growth receipt

- writer refuses (exit 2, located) on unreadable rss/peak, trim reading, open or write failure; no fabricated zero
- readout: tolerance is structure_count*1024 (KB rounding); the tree<=moment check is deleted, closure-scale measurement declared as the frontier
- structure_has_trend_row enumerates the closed coproduct (floor NonFoldResidueRosterDiverged)
- gunbc.memory_composition_seed_growth row; receipt regenerated from one run

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…the seed moment or during cargo

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ol released before resolution)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review October 10, 2026 08:30
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T08:33:42.522344Z c0da105 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c0da105beb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +84 to +88
release();
let after_release = rss_kb();
let trimmed = super::trim_retained_heap();
let after_trim = rss_kb();
record_bucket(name, trimmed);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Include pages released directly by drop

When a released structure contains mmap-sized allocations or the allocator otherwise returns pages during release(), RSS falls between before and after_release; recording only the subsequent malloc_trim delta omits those bytes and can report a zero-sized bucket for a large structure. The bucket must account for the complete before-to-after_trim decrease rather than only trim_retained_heap().

Useful? React with 👍 / 👎.

rss_kb_after={rss_after_kb:?}); cargo build",
crate_dir.display()
);
super::memory_composition::release_stages();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bypass product-cache hits during memory collection

When GUNBC_NATIVE_CACHE_ROOT produces a verified hit, prepare_emitted_compiler_for_entry returns at line 461 before emission, so neither the three readbacks nor this release hook runs, while the self-host instrument can still report success from the cached binary. A memory-composition run therefore silently writes no measurement; cache reuse must be disabled or refused while composition is enabled.

Useful? React with 👍 / 👎.

Comment on lines +68 to +69
StepMemoryStructure { receipt_kind: "bucket", receipt_name: "pool_content_tokens_newline", structure: "whole-tree token pool: V1LexArtifact + content + newline index of every pooled module (pool_acquire POOL)", owner: SeedProcess, scale: WholeTree, live_at_seed_peak: false, live_during_cargo: false, ender: ClosureScopedIngestion },
StepMemoryStructure { receipt_kind: "bucket", receipt_name: "pool_heads", structure: "whole-tree parsed heads (pool_acquire Acquired.heads)", owner: SeedProcess, scale: WholeTree, live_at_seed_peak: false, live_during_cargo: false, ender: ClosureScopedIngestion },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Do not classify the post-clear pool as whole-tree

The production path clears the whole-tree pool before resolution at cli_run.rs:7957, but release_stages measures its pool buckets only after emission. Consequently these rows can contain only an empty or subsequently reacquired subset, not the advertised token and heads data for every pooled module; treating them as WholeTree corrupts the audit's scale classification and trend conclusions.

Useful? React with 👍 / 👎.

Comment on lines +57 to +59
let Some(path) = std::env::var_os("GUNBC_MEMORY_COMPOSITION_RECEIPT") else {
return;
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refuse an enabled audit without a receipt path

When GUNBC_MEMORY_COMPOSITION is set but GUNBC_MEMORY_COMPOSITION_RECEIPT is absent, every readback and bucket reaches this branch and is silently discarded, yet the instrument continues successfully. This contradicts the fail-closed writer contract and allows a requested audit to produce no receipt; the missing path should invoke refuse when collection is enabled.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

This PR was auto-opened by the dashboard from the closing lane's working branch (stack-lever, head c0da105). Its head is byte-identical to #13674's head (c0da105), and its diff is the union of #13673 (the audit model, writer and receipt) and #13674 (the lever, stacked on #13673). Closing as a duplicate so one set of reviews lands where the changes live. Review 78421's two findings are carried onto #13674 by comment and will be fixed there before either PR leaves draft: the lever's trend row must be PoolReleasedBeforeResolution with the stale PoolReleasedAfterCensus arm deleted or made true, and the committed receipt must name the configuration it measured.

— sent from smart-gull-336

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants