Skip to content

G1 re-derived: belt verify through the materialization provider; compute outcomes in the bounded store (re-derives #13097) - #13690

Merged
gunbai-bot[bot] merged 2 commits into
mainfrom
session/gentle-heron-422
Oct 11, 2026
Merged

gunbai-bot[bot] merged 2 commits into
mainfrom
session/gentle-heron-422

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Re-derives gunbc#13097 (G1, closed 2026-10-09; branch session/bold-dove-431-cutover kept as history) on current main. #13097's reviews 74699 and 74747 were already fixed inside that branch (consumer paragraph; GunbcBinary closed coproduct instead of a name-recovered id) and are carried in that fixed form.

What changed (3b homes: std.realization / std.materialization_provider / std.artifact_store / std.cache_interface; fleet/compute: gunbc.compute.*; leasing: attempt slot-first order)

  • Compute outcomes realize only through extdeps.realization.materialization_store_local (bounded per-host root); the provider's private outcome.json and per-identity store_dir are gone. Binaries are byte parts of the record.
  • The ladder (std.materialization_ladder) decides store vs recompute: build/compile/hermetic claims memoize; a wet claim run is recomputed per occurrence, never read from or committed to the store. The §2 law holds: the cache discharges only unavoidable recurrence.
  • A refused lookup refuses; only established absence produces (stated divergence: realize_route FreshnessExpired arm has no inhabitant in this store).
  • Belt verify runs RunClaims through compute_provide (belt_run_claim_through_compute), wet, with the diff window as a keyed declared input; receipt cites request key/outcome/tree (G2); reader shared_computation_observe_for_attempt.
  • Rebuilt against main rather than carried: live_deploy.spec now adds the materialization store root as an OwnedDirectoryDeclared host directory in deployment_srv1_host_directories (main's current shape; the old EnsuredDependencyKind arm no longer exists). Deleted compute_operation_admission and the FreshEffectNotServed outcome: the refusal of wet runs is superseded by occurrence identity, and leaving them would be dangling declarations (3c).

Was #13125 superseded?

Yes, by a landed commit: folded into #13641 (merge commit fa44b98102, folded at 75af82e via integration/bold-bee-114). The WIP head 9f20643 was deliberately not folded. Nothing from #13125 is carried here.

Receipts (claim_batch on a seed built from this branch, CTRL_BUILD_MODE=local)

  • compute/work_request_witness_test: exit 0, 23/23
  • compute/work_class_grant_witness_test: exit 0, 21/21
  • roadmap/roadmap_verification_receipt_witness_test: exit 0, 8/8
  • roadmap/roadmap_validation_oracle_witness_test: exit 0, 38/38
  • materialization_provider_witness_test: exit 0, 48/48
  • roadmap/roadmap_belt_actuate_witness_test: exit 1; the 9 failures are all "hermetic route has no arm" route gaps (witness_exec_*, verify_without_observable_subject_defers_instead_of_rerunning, observe_only_instance_refuses_dispatch_and_stop); three of them (one per kind) were re-run on origin/main and fail identically.

Not run / operator-only

  • Wet witnesses: RUN on head 32da939 (seed built from this tree, non-hermetic, real filesystem; both touch only /tmp, so srv1 was not needed): materialization_store_local_wet_witness_test 40/40, compute/attempt_lifecycle_wet_witness_test 14/14.
  • Still unexecuted: a live srv1 belt attempt end to end. The new materialization-store host directory is created only by a deploy (fleet-converge), so store behavior on the real deployed path is activation evidence for that deploy, not a landing condition (side-chat ruling).
  • Deploying the new host directory is a fleet-converge step: operator-only.
  • Not carried: roadmap_verify/source_snapshot_handoff still use the host command (outside G1: belt verify through the materialization provider; compute outcomes and binaries in the bounded store #13097's brief); native toolchain provenance (blocked on a native-construction ruling).

🤖 Generated with Claude Code

Brian Searls and others added 2 commits October 10, 2026 18:30
…ation provider; compute outcomes and binaries in the bounded store (re-derives #13097)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot merged commit dd786ba into main Oct 11, 2026
1 check passed
@gunbai-bot
gunbai-bot Bot deleted the session/gentle-heron-422 branch October 11, 2026 00:53
gunbai-bot Bot pushed a commit that referenced this pull request Oct 11, 2026
Refresh for G1 belt claim verification (#13690) and the error-primitives seam (#13686).
gunbai-bot Bot pushed a commit that referenced this pull request Oct 11, 2026
… (absorbs main's drift from #13690/#13705/#13710)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbai-bot Bot added a commit that referenced this pull request Oct 11, 2026
…role holder (#13688)

* Deployment risk D2 layer 1: role-following singletons resolve the prod-role holder (re-derives #13217)

ProdRoleHolder token and resolver in roadmap_dashboard_instance, actuated join in live_deploy.desired,
fabric placement, approval broker placement and emit repointed off the srv1 pin. Claims in
test.claim.prod_role_realization_witness_test.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Deployment risk D2 layer 1: witness fixtures follow the role-following signatures

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Deployment risk D2 layer 1: enrolment-code issuer follows the placed broker host; apply witness stays at main's fixture

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Deployment risk D2 layer 1: emit_test and release fixture follow RoleSingletonHolding and instance-keyed fabric paths

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Deployment risk D2 layer 1: drop unconsumed shell.Stat GroupOf; pin ProdRoleHolderUnactuatable in the actuated-join claim (review 78458)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Deployment risk D2 layer 1: unit-emission oracle follows role_singletons and the broker base-url environment

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate fleet-converge.yml and gunbc-ghrunner.sudoers via main_wet (absorbs main's drift from #13690/#13705/#13710)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Cite approval_broker_host_under at its home module (review 78559)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Drop the L2-only role_singleton_disposition fixture edit from the launch receipt witness (not a field on main's LiveDeployApplyReceipt)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbai-bot Bot added a commit that referenced this pull request Oct 11, 2026
…gression) (#13732)

* lab-dev: the deploy creates the materialization store's staging sibling

Every compute build on srv1 refused 'store unavailable: could not create the
compute directories' since dd786ba moved compute to the durable store under
/var/lib/gunbc: the deploy declared materialization-store but not the
'-staging' sibling compute stages into, and the service user cannot create
it under the root-owned /var/lib/gunbc. The sibling's path now derives once
in std.materialization_store_grant, consumed by compute_staging_dir and by a
new srv1 host-directory member.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate the srv1 sudoers projection: stat readback for the store's staging sibling

Generated by generated_artifact_gate main_wet_one on this tree (keeps #13723's
fabric-storage-control grant).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants