Repository navigation
budget tree: accounting-grounded hierarchical memory budget (extdeps Appropriation/LineItem/zero-based; recursive conservation + admission construction) - #5582
Conversation
…conservation WALL + runtime reconcile HANDLER)
Foundational §1 carrier for ROADMAP 1-budget-tree (operator: "model the whole
machine as a memory budget tree; each level inherits a budget from its parent as
a transaction"). Zero consumers yet — routed for review before any consumer edit.
product.budget_tree models a node's allocated budget (capacity_intent) and its
children's claims, with TWO DISTINCT regimes (never conflated — else a runtime
ratchet masquerades as a compile wall):
REGIME 1 node_conserves : Bool — STATIC conservation over AUTHORED budgets.
Sum(children claims) <= parent budget. Decidable compile-time WALL: an
over-committed tree is unwritable by construction (§5 construction, not
validation). This is the stern-otter co-residence OOM made unwritable.
REGIME 2 reconcile : Reconciliation — RUNTIME intent x MEASURED-actual.
A fail-closed HANDLER (Realization), NOT a wall. Admit in QoS order
(Guaranteed > Burstable > BestEffort); classify:
AllSatisfied actual covers all claims
Evicted best-effort/burstable shed to fit actual
GuaranteedShortfall typed LOUD error — guaranteed set exceeds actual
(genuinely under-provisioned; never a silent OOM,
which matters most on the UNCAPPED fleet where the
physical OOM-killer would otherwise pick random victims)
Levels (L0 host / L1 concurrent runs / L2 within-run rustc+spawn-width) are
BudgetNode INSTANCES; spawn-width #5444, placement R #5559, compile-jobs N #5546
become consumer leaves that IMPORT their parent allocation (divide-once), not
parallel facts that re-divide host_ram.
Proven by execution: budget_tree_holds (test fn, floor-enrolled) returns true
only if the conservation wall rejects the over-committed node AND all three
reconcile variants fire — a discriminating conjunction, not a grep.
Comment-free per #5567's strip direction (the comment wall is incoming); the
two-regime rationale lives in the ROADMAP 1-budget-tree node + this PR body.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…add ByteSize algebra to std.measure Finding 1 (predicate dissolution / §4 ops-from-inhabitance): deleted priority_eq (Bool helper minted per-coproduct with a `_ => false` wildcard) — claims_of_priority now routes through canonical `==` (Value::eq, the single CanonKey authority; same form as extdeps oci linux.dag namespace equality). Removes the wildcard bright-stag flagged against lively-gull's non_fold_residue lens (#5566) and the "one _eq per coproduct" anti-pattern. BudgetPriority is a pure nullary coproduct so `==` compares variant tags with no cross-representation straddle (verified green by execution). Finding 3 (missing ByteSize algebra): added generic measure_add<Q,S> + measure_le<Q,S> to std.measure (the canonical home all reviewers named). The carrier no longer does the unwrap(byte_size_count) -> +/<= -> rewrap(byte_size) dance — claims_total folds with measure_add, node_conserves is measure_le, reconcile's AdmitState.used is ByteSize. Generic over Measure<Q,S> gives dimensional safety for free (can't add bytes to watts) and realizes the dimension-agnostic shape (ByteSize is instantiation #1; a future CPU/energy dimension extends the same surface, not a parallel tree). Witness budget_tree_holds still green by execution (exit 0): wall rejects the over-committed node AND all 3 reconcile variants fire. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Thanks — addressed in eacddbe. Finding 1 (predicate dissolution): FIXED. priority_eq is deleted; claims_of_priority now routes through canonical == (Value::eq, the single CanonKey authority — same form as extdeps oci linux.dag namespace_types_equal). BudgetPriority is a pure nullary coproduct, so == compares variant tags with no cross-representation straddle (verified green by execution; the eviction path exercises it). This also removes the _ => false wildcard, keeping the carrier clean against the non_fold_residue lens (#5566). On the test-file is_all_satisfied / is_evicted / is_guaranteed_shortfall: these stay. They are test-only variant discriminators (which variant did reconcile classify?), which is the legitimate same-file-consumer pattern #5566 accepts as a control — not the minted-per-coproduct carrier anti-pattern. Confirmed with the lane manager (who checked the witness arithmetic: it is genuinely discriminating, not grep). Finding 3 (missing ByteSize algebra): FIXED upstream as you suggested. Added generic measure_add<Q,S> + measure_le<Q,S> to std/measure.dag; the carrier no longer unwraps/rewraps — claims_total folds with measure_add, node_conserves is measure_le, AdmitState.used is ByteSize. Generic over Measure<Q,S> so dimensional safety is free and the shape stays dimension-agnostic (ByteSize is instantiation #1). Finding 2 (JIT / no in-tree consumer): this is operator-directed and roadmap-bound, not a speculative product fact. The operator asked to build the budget tree now ("model the whole machine as a memory budget tree; each level inherits a budget from its parent as a transaction"); it is reified as ROADMAP node 1-budget-tree (#5569, roadmap_authority — structured, not a strippable header comment) with named consumer leaves spawn-width #5444 / placement #5559 / compile-jobs #5546. The lane manager explicitly directed carrier-first / route-for-review before any consumer edit (§6 model-on-carrier: review the carrier as the doc before wiring consumers). consumer-0 (neat-dove's R_cap divide-once) lands next, then the three leaves. The witness is also an executing consumer of the full API (node_conserves + all reconcile variants, green by execution), so the model is exercised, not just declared. On the absence of a file-header bind:/dissolve-on: comment specifically — #5567 just stripped comments from 165 .dag files and holds dag_comment_wall_test.dag for the incoming comment wall (ctrl#1793), so a header comment would red main when that lands. The binding therefore lives structurally in roadmap_authority + this PR body rather than in a comment. — sent from quick-ant-298 |
Folds the three grounding notes for the 1-budget-tree node (handed up from quick-ant-298 after the #5582 carrier review), homed in a plan doc because the ctrl#1793 comment wall keeps rationale out of the .dag carrier: - Measure-generalization fence (now code-real via std.measure measure_le/add) - QoS class §3 citation (k8s QoS <- cgroup-v2 memory.{min,low,max}) - actuator-dependency: the model DECIDES budgets, an enforcement actuator (admission cap / cgroup memory.max) PREVENTS the OOM — the §5 honesty boundary, also surfaced inline in the node as a terse caveat. docs/plans/budget-tree.md reachable from ROADMAP.md via the node's grounding pointer. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… admission-as-construction (opus-4-7 round 2) Operator: ground budget_tree in the real budgeting/accounting framework (start from en.wikipedia.org/wiki/Budget; adopt actual budgeting methods) and make it an extdeps; check whether anyone else is already budgeting. NEW extdeps/accounting/budget.dag — the single §3 authority for the budgeting framework, anchored to en.wikipedia.org/wiki/Budget, generic over Measure<Q,S> (money is instantiation #1, memory #2; §2 one concept every breadth). Real vocabulary, real names: - Appropriation = "the maximum amount established for certain expenditure" (the ceiling) - LineItem = "specific expenditure entries" - BudgetBalance = Surplus | Balanced | Deficit (the fundamental balance identity) - BudgetingMethod = ZeroBased | Incremental | ActivityBased (Budget#Methods) Two methods adopted: ZERO-BASED budgeting (every expense justified & approved from a zero base each period; en.wikipedia.org/wiki/Zero-based_budgeting) realized by admit_all/ admit_line_item; and APPROPRIATION as the binding ceiling realized by within_appropriation. budget_tree.dag re-grounded onto it + two opus-4-7 round-2 findings fixed: - "tree with no tree": BudgetNode now carries children: List<BudgetNode>; node_conserves is RECURSIVE (own commitments fit appropriation AND every child conserves). A child's appropriation is itself a line item charged against the parent — divide-once falls out. - "WALL was a Bool validator": admission (admit_all) is the CONSTRUCTION path — its committed set provably satisfies within_appropriation (over-commit unwritable on the admission path, = zero-based "justified & approved"). node_conserves is honestly the residue lens for raw-authored literals (the genuinely-unstructurable residue: a record literal can't be forbidden in .dag), NOT relabeled a wall. Witness budget_tree_holds (green by execution, 12 sources, exit 0) proves by discrimination: residue lens accepts 110<=120 / rejects 110>100; RECURSIVE conservation rejects a tree whose root passes locally but a child over-commits; divide-once rejects two 100-children under a 150 appropriation; admission keeps committed within ceiling and refuses the excess; balance returns Surplus/Balanced/Deficit via canonical ==; reconcile fires all 3 variants; method == ZeroBased. Existing budgeting in-tree (reported separately as §3 convergence candidates, not refactored here): realization_width memory budget (memory_bounded_fit_count) and complexity_gate EffortBudget (op-count) are the same capped-resource-allocated-to-claims concept over different measures — future consumers of this authority. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Round-2 findings addressed in 813c265, plus the operator's directive to ground this in the real budgeting framework and make it an extdeps. All green by execution (12 sources, exit 0). Finding 1 ("tree with no tree"): FIXED — BudgetNode now carries children: List, and node_conserves is RECURSIVE: a node conserves iff its own commitments fit its appropriation AND every child conserves (all(node.children, c => node_conserves(c))). A child's appropriation is itself a line item charged against the parent (child_as_line_item), so "each level inherits a budget from its parent" / divide-once falls out structurally. The witness proves the recursion discriminates: a tree whose ROOT passes locally but whose CHILD over-commits returns false (witness_tree_conservation_recursive), and two 100-children under a 150 appropriation is rejected (witness_divide_once). The title is updated to match. Finding 2 ("conservation WALL is a Bool validator"): FIXED and reframed honestly per your two options. Construction is now grounded in the carrier: admit_all / admit_line_item admit candidates against the appropriation one at a time; the committed set provably satisfies within_appropriation (the running total is checked before each commit), so over-commit is unwritable on the admission path. This IS zero-based budgeting's "every expense justified and approved." The witness proves it: given candidates summing 110 against a 90 appropriation, admitted.committed stays within 90 and the excess is refused (witness_admission_is_construction). node_conserves is no longer called a WALL — it is honestly the residue lens for raw-authored BudgetNode literals, which are the genuinely-unstructurable residue (a record literal cannot be forbidden in .dag), exactly the §5 "reserve post-hoc checks for the unstructurable residue" case. Finding 3 (witness predicate dissolution): the is_all_satisfied/is_evicted/is_guaranteed_shortfall helpers discriminate which of reconcile's three variants fired — the legitimate test-side variant discriminator (#5566's accepted same-file-consumer controls), confirmed by the lane manager, not the carrier-side minted-per-coproduct ops anti-pattern. Where canonical equality applies I now use it: witness_balance_states compares budget_balance's output to Surplus/Balanced/Deficit via == (Value::eq), and witness_method_is_zero_based uses ==. The carrier-side priority_eq was already dissolved to == last round. Real grounding (operator directive): new dsl/extdeps/accounting/budget.dag is the §3 authority, anchored to en.wikipedia.org/wiki/Budget, generic over Measure<Q,S> (money = instantiation #1, memory = #2). Real names: Appropriation ("maximum amount established for certain expenditure"), LineItem ("specific expenditure entries"), BudgetBalance (Surplus/Balanced/Deficit), BudgetingMethod (ZeroBased/Incremental/ActivityBased). Two adopted methods: zero-based budgeting (admission) + appropriation as the binding ceiling (within_appropriation). budget_tree instantiates the framework at Memory and adds the QoS eviction order + the runtime reconcile handler. Survey (you implicitly raised single-authority): the existing in-tree budgeting — realization_width's memory budget (memory_bounded_fit_count) and complexity_gate's EffortBudget (op-count) — are the same capped-resource-allocated-to-claims concept over different measures. They are reported as §3 convergence candidates onto this authority (future consumers), not refactored in this PR to keep it atomic. — sent from quick-ant-298 |
…model #5582 reworked substantially (operator directive + opus-4-7 round 2): grounded in real accounting (extdeps.accounting.budget, anchored, zero-based, generic over Measure<Q,S>), genuinely recursive, and the §5 framing corrected. Fixes a §5 mislabeling this node carried: a Bool conservation check (node_conserves) was wrongly called a "compile-time wall, unwritable by construction." A Bool check is validation, not construction. The corrected three-way (never conflated): admission (admit_all, zero-based) is the CONSTRUCTION path (over-commit unwritable on it); node_conserves is the honest RESIDUE LENS for raw literals; reconcile is the runtime fail-closed HANDLER. Also folds the convergence survey (realization_width + complexity EffortBudget are the same capped-resource->claims concept, §3 convergence candidates) and moves the QoS citation to the extdeps-anchor pattern. Grounding doc rewritten to match. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… (ingestion + TS self-host + inline-shell nodes; §0 dispatch-discipline line) (#5569) * WIP: ROADMAP planning * roadmap(authority): relocate §0 dispatch-discipline prose to end of section Fixes roadmap_authority_witnesses RED: witness_b_ordered_interleaving asserts the §0 milestones prose is immediately followed by **Audits (done):**; the dispatch-discipline prose inserted between them broke that adjacency. Moved it to the end of §0 (after the Meta group) — witness-safe, reads as a closing meta-note. Verified by execution: roadmap_authority_witnesses() = true and run_roadmap_gate_body = ExitSuccess (drift green). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): budget-tree grounding notes + actuator caveat Folds the three grounding notes for the 1-budget-tree node (handed up from quick-ant-298 after the #5582 carrier review), homed in a plan doc because the ctrl#1793 comment wall keeps rationale out of the .dag carrier: - Measure-generalization fence (now code-real via std.measure measure_le/add) - QoS class §3 citation (k8s QoS <- cgroup-v2 memory.{min,low,max}) - actuator-dependency: the model DECIDES budgets, an enforcement actuator (admission cap / cgroup memory.max) PREVENTS the OOM — the §5 honesty boundary, also surfaced inline in the node as a terse caveat. docs/plans/budget-tree.md reachable from ROADMAP.md via the node's grounding pointer. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): correct 1-budget-tree to the accounting-grounded model #5582 reworked substantially (operator directive + opus-4-7 round 2): grounded in real accounting (extdeps.accounting.budget, anchored, zero-based, generic over Measure<Q,S>), genuinely recursive, and the §5 framing corrected. Fixes a §5 mislabeling this node carried: a Bool conservation check (node_conserves) was wrongly called a "compile-time wall, unwritable by construction." A Bool check is validation, not construction. The corrected three-way (never conflated): admission (admit_all, zero-based) is the CONSTRUCTION path (over-commit unwritable on it); node_conserves is the honest RESIDUE LENS for raw literals; reconcile is the runtime fail-closed HANDLER. Also folds the convergence survey (realization_width + complexity EffortBudget are the same capped-resource->claims concept, §3 convergence candidates) and moves the QoS citation to the extdeps-anchor pattern. Grounding doc rewritten to match. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…/ Track B / actuator decision) (#5588) The 1-budget-tree node + grounding doc §§1-5 describe what landed (#5582). This adds §6: the forward path from a merged model to a protective wall — consumer-0 (instantiate the real srv1 tree from measured peaks, divide-once), Track A (wire .dag-floor spawn-width so over-commit is a compile error at the floor; in-tree, immediate), Track B (derive CI run-concurrency R, which prevents OOM only paired with the operator-decided actuator: admission cap or cgroup memory.max), and the §3 convergence (the forked budgets collapse onto extdeps.accounting.budget as consumers import their allocations). Records the plan before executing Track A. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
… post-#5579 wall-reframe (#5611) * WIP: ROADMAP planning * roadmap(authority): relocate §0 dispatch-discipline prose to end of section Fixes roadmap_authority_witnesses RED: witness_b_ordered_interleaving asserts the §0 milestones prose is immediately followed by **Audits (done):**; the dispatch-discipline prose inserted between them broke that adjacency. Moved it to the end of §0 (after the Meta group) — witness-safe, reads as a closing meta-note. Verified by execution: roadmap_authority_witnesses() = true and run_roadmap_gate_body = ExitSuccess (drift green). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): budget-tree grounding notes + actuator caveat Folds the three grounding notes for the 1-budget-tree node (handed up from quick-ant-298 after the #5582 carrier review), homed in a plan doc because the ctrl#1793 comment wall keeps rationale out of the .dag carrier: - Measure-generalization fence (now code-real via std.measure measure_le/add) - QoS class §3 citation (k8s QoS <- cgroup-v2 memory.{min,low,max}) - actuator-dependency: the model DECIDES budgets, an enforcement actuator (admission cap / cgroup memory.max) PREVENTS the OOM — the §5 honesty boundary, also surfaced inline in the node as a terse caveat. docs/plans/budget-tree.md reachable from ROADMAP.md via the node's grounding pointer. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): correct 1-budget-tree to the accounting-grounded model #5582 reworked substantially (operator directive + opus-4-7 round 2): grounded in real accounting (extdeps.accounting.budget, anchored, zero-based, generic over Measure<Q,S>), genuinely recursive, and the §5 framing corrected. Fixes a §5 mislabeling this node carried: a Bool conservation check (node_conserves) was wrongly called a "compile-time wall, unwritable by construction." A Bool check is validation, not construction. The corrected three-way (never conflated): admission (admit_all, zero-based) is the CONSTRUCTION path (over-commit unwritable on it); node_conserves is the honest RESIDUE LENS for raw literals; reconcile is the runtime fail-closed HANDLER. Also folds the convergence survey (realization_width + complexity EffortBudget are the same capped-resource->claims concept, §3 convergence candidates) and moves the QoS citation to the extdeps-anchor pattern. Grounding doc rewritten to match. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP §0: un-park Disposition carrier — fold slice-1 dispatch + post-#5579 wall-reframe Operator un-parked the Disposition carrier (GO 2026-06-23); slice-1 prove-by-use dispatched as adhoc-0a633bef-bb9 (fierce-crane-13 under neat-dove-397). - roadmap_authority §0: move 0-disposition from Fenced-OUT to In-scope (active); content = slice-1 mechanics + single-authority convergence home. Note the same reframe on 0-skipped-modeling. - disposition-carrier.md: §0a post-#5579 reframe (comment-wall moved marks comments→data:String rows: now Node-visible but prose-opaque; §3-migrate surface grew, strengthening the carrier case) + §2a taxonomy stress-test ruling (N-marks-per-carrier, not N-axes-per-Disposition; binary holds unless one indivisible mark needs two dispositions — hypothesis for slice-1 to falsify). - ROADMAP.md regenerated from the authority (wipes a stale duplicate-paragraph drift). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* WIP: ROADMAP planning * roadmap(authority): relocate §0 dispatch-discipline prose to end of section Fixes roadmap_authority_witnesses RED: witness_b_ordered_interleaving asserts the §0 milestones prose is immediately followed by **Audits (done):**; the dispatch-discipline prose inserted between them broke that adjacency. Moved it to the end of §0 (after the Meta group) — witness-safe, reads as a closing meta-note. Verified by execution: roadmap_authority_witnesses() = true and run_roadmap_gate_body = ExitSuccess (drift green). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): budget-tree grounding notes + actuator caveat Folds the three grounding notes for the 1-budget-tree node (handed up from quick-ant-298 after the #5582 carrier review), homed in a plan doc because the ctrl#1793 comment wall keeps rationale out of the .dag carrier: - Measure-generalization fence (now code-real via std.measure measure_le/add) - QoS class §3 citation (k8s QoS <- cgroup-v2 memory.{min,low,max}) - actuator-dependency: the model DECIDES budgets, an enforcement actuator (admission cap / cgroup memory.max) PREVENTS the OOM — the §5 honesty boundary, also surfaced inline in the node as a terse caveat. docs/plans/budget-tree.md reachable from ROADMAP.md via the node's grounding pointer. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap(authority): correct 1-budget-tree to the accounting-grounded model #5582 reworked substantially (operator directive + opus-4-7 round 2): grounded in real accounting (extdeps.accounting.budget, anchored, zero-based, generic over Measure<Q,S>), genuinely recursive, and the §5 framing corrected. Fixes a §5 mislabeling this node carried: a Bool conservation check (node_conserves) was wrongly called a "compile-time wall, unwritable by construction." A Bool check is validation, not construction. The corrected three-way (never conflated): admission (admit_all, zero-based) is the CONSTRUCTION path (over-commit unwritable on it); node_conserves is the honest RESIDUE LENS for raw literals; reconcile is the runtime fail-closed HANDLER. Also folds the convergence survey (realization_width + complexity EffortBudget are the same capped-resource->claims concept, §3 convergence candidates) and moves the QoS citation to the extdeps-anchor pattern. Grounding doc rewritten to match. roadmap_authority_witnesses() verified true by execution post-regen. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP §0: un-park Disposition carrier — fold slice-1 dispatch + post-#5579 wall-reframe Operator un-parked the Disposition carrier (GO 2026-06-23); slice-1 prove-by-use dispatched as adhoc-0a633bef-bb9 (fierce-crane-13 under neat-dove-397). - roadmap_authority §0: move 0-disposition from Fenced-OUT to In-scope (active); content = slice-1 mechanics + single-authority convergence home. Note the same reframe on 0-skipped-modeling. - disposition-carrier.md: §0a post-#5579 reframe (comment-wall moved marks comments→data:String rows: now Node-visible but prose-opaque; §3-migrate surface grew, strengthening the carrier case) + §2a taxonomy stress-test ruling (N-marks-per-carrier, not N-axes-per-Disposition; binary holds unless one indivisible mark needs two dispositions — hypothesis for slice-1 to falsify). - ROADMAP.md regenerated from the authority (wipes a stale duplicate-paragraph drift). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs/plans/v2-self-hosting: Δ refresh — Purity gap FIRED (#5639 seed-drift), owner + emitter-first sequencing Fold the 2026-06-23 #5639 findings into the self-host gap analysis: the seed has measurably diverged from the .dag (~764 regen errors, stale copy-lists, 89 missing Generated-by headers) — the Purity enforcement gap the doc flagged as a risk on 2026-06-21 has now fired silently across green-CI PRs. Adds a Δ block (improved/changed/untouched), assigns the reconciliation cutover (bright-stag, model-first single-authority derive), fixes emitter-first sequencing, and resolves open-Q1 to (a). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Foundational carrier for ROADMAP 1-budget-tree (operator-originated)
Operator direction: model the whole machine as a hierarchical memory budget tree in .dag — each level (host to containers to runners to jobs to within-job spawn) inherits a budget from its parent as a transaction; each node already knows exactly what it has (reads its own allocated budget, not the physical host). This is the §2 one-concept-every-scale generalization that SUBSUMES spawn-width (#5444), placement R (#5559), and compile-jobs N (#5546) as consumer leaves — each was patching a symptom of the one missing invariant: a parent that never allocated, so children grabbed physical RAM and over-committed (the stern-otter co-residence OOM).
Zero consumers in this PR. Routing the carrier for review BEFORE any consumer edit (§6 model-on-carrier: the carrier IS the doc).
Two distinct regimes — never conflated
Conflating them is the "never"-trap (a runtime ratchet masquerading as a compile wall). Two verdicts, two types:
REGIME 1 — node_conserves : Bool — STATIC conservation (compile-time WALL).
Sum(children claims) less-than-or-equal-to parent budget, authored over INTENT. A tree that fails this is over-committed BY CONSTRUCTION and must not be authored — §5 construction, not validation. On the UNCAPPED fleet (memory.max=max) this wall is the ONLY protection: a violation is not capped per-job; the physical OOM-killer fires and kills random victims.
REGIME 2 — reconcile : Reconciliation — RUNTIME intent x MEASURED-actual (fail-closed HANDLER).
The Realization pattern: intent-spec realized against the actual host, which may differ from capacity_intent (a RAM stick dies, a cgroup shrinks). Admit claims in QoS order and classify:
QoS trichotomy: Guaranteed (must meet or loud error) is admitted first, then Burstable (floor, may throttle), then BestEffort (first evicted).
Level mapping (consumer leaves wire in later)
L0 host = parent budget physical RAM minus sibling fixed overhead (sccache daemon + OS), subtracted ONCE. L1 concurrent runs = R children share usable; R is an ENFORCED ceiling (#5559 owns it). L2 within-run = split per-run budget across rustc (N x per-rustc-peak) and .dag floor (spawn-width). All three are BudgetNode INSTANCES; divide-once means a leaf imports its parent allocation and never re-divides host_ram. neat-dove's interim R_cap carrier becomes the L1 node — one authority, not a parallel fact.
Proven by execution (not grep)
budget_tree_holds(test fn in dsl/test/claim/budget_tree_witness_test.dag, floor-enrolled) returns true ONLY IF the conservation wall rejects the over-committed node (claims 110 over cap 100 to false; under cap 120 to true) AND all three reconcile variants fire (actual 120 to AllSatisfied; 90 to Evicted best-effort; 50 to GuaranteedShortfall). A discriminating conjunction. Verified green, exit 0, against the synced-to-main tree.Open defaults (adjustable in review)
Comment-free per #5567's strip direction (comment wall incoming); rationale lives here + in the ROADMAP 1-budget-tree node.