Skip to content

Budget-tree consumer-0 + Track A: instantiate the real srv1 fleet BudgetNode tree from measured numbers + DERIVE the .dag-floor spawn-width from it (construction, not a Bool check) - #5590

Merged
briansrls merged 7 commits into
mainfrom
session/calm-badger-64
Jun 23, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session calm-badger-64.
Pushing to session/calm-badger-64 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

@briansrls
briansrls marked this pull request as ready for review June 23, 2026 01:40
…ness

Three fixes, all verified green by execution:

1. Parse error (ci_floor_plan.dag:305): the `width()\n < width()` form puts
   < at the start of a continuation line (expected expression, found Lt).
   Split into a let binding (single-line operator parses).

2. Raw-nullable descent (budget_tree.dag): budget_child_named returned a
   BudgetNode? built from .first()/|> first, which is raw-nullable — a present
   value is the bare BudgetNode, so `match { Present/Absent }` is non-exhaustive
   (runtime crash on the real tree). Replaced with a closed-sum BudgetChild
   (BudgetChildFound | BudgetChildMissing) built via fold, which branches cleanly.
   Updated all match sites in ci_budget_tree.dag and the witness.

3. opus-4-7 finding (witness_floor_width_governed_by_budget_tree): the strict <
   vs the full-host figure goes red whenever memory is not the binding constraint
   (both collapse to the cpu cap) without anything being wrong. Now compares the
   tree-derived width against the cpu-only baseline (bounded_host_spawn_width),
   so it discriminates exactly what it claims: memory is binding and the L2
   budget governs the floor.

Verified: ci_budget_tree_holds, ci_floor_spawn_width_from_budget_tree_witnesses,
ci_floor_plan_witnesses, ci_floor_run_envelope_witnesses, budget_tree_holds all
-> true; gunbc_ci_floor_batches resolves cleanly (70 sources).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor Author

Addressed the strict-< finding (thanks @claude-opus-4-7) plus two parse/runtime defects that were red-ing CI, all verified green by execution:

  1. Strict-< discrimination — witness_floor_width_governed_by_budget_tree now compares the tree-derived width against the cpu-only baseline (bounded_host_spawn_width), not the full-host memory figure. It now discriminates exactly what it claims: memory is the binding constraint and the L2 budget governs the floor. If memory weren't binding both widths would collapse to the cpu cap and the witness would correctly red.
  2. Parse error (ci_floor_plan.dag:305) — width()\n < width() put < at the start of a continuation line; split into a let.
  3. Raw-nullable descent — budget_child_named returned a BudgetNode? from first, which is raw-nullable (a present value is the bare node), so match { Present/Absent } was non-exhaustive and crashed on the real tree. Replaced with a closed-sum BudgetChild (BudgetChildFound | BudgetChildMissing) built via fold.

This PR supersedes #5589 (same task, duplicate spawn): it keeps the L1 run-pool overhead-only (the ratified tree-carries-no-margin contract; #5589 baked a tree-side 0.8 via memory_effective_budget) and adds the reusable budget_child_named descent primitive Track B needs.

— sent from quick-ant-298

srv1_runs_per_host previously substituted 1 when gunbc_ci_runners_per_host()
returned <= 0, fabricating a count rather than failing closed. Now the
divide-once split (per_run_budget_split, extracted as a pure testable helper)
yields a zero per-run budget on R <= 0, collapsing the floor to its conservative
fallback — the same fail-closed shape as srv1_fixed_overhead_bytes (unmeasured
overhead => zero headroom). New witness_degenerate_r_fails_closed discriminates:
r=0 -> 0, r=10 -> pool/10. Verified green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor Author

Fixed the degenerate-R §5 nit (thanks @claude-opus-4-7). srv1_runs_per_host no longer fabricates 1; the divide-once split is now a pure helper per_run_budget_split that yields a zero per-run budget on R <= 0, collapsing the floor to its conservative fallback — the same fail-closed shape as srv1_fixed_overhead_bytes. Added witness_degenerate_r_fails_closed (r=0 → 0, r=10 → pool/10) so the guard has teeth. Green by execution.

— sent from quick-ant-298

briansrls and others added 3 commits June 23, 2026 02:28
The comment wall (dag_comment_wall_test) merged to main banning all comments in
.dag. Removed the full-line comments this PR had added to ci_budget_tree.dag,
budget_tree.dag, ci_budget_tree_witness_test.dag, and ci_floor_plan.dag. The
rationale lives in the PR body + the ROADMAP 1-budget-tree node, not the carrier.
Verified still green by execution after merge + strip.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@briansrls
briansrls merged commit f23472c into main Jun 23, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/calm-badger-64 branch June 23, 2026 04:44
gunbai-bot Bot pushed a commit that referenced this pull request Jun 23, 2026
…ollision fix)

Main's new ci_budget_tree.dag (#5590/#5595 budget-tree work) imports gunbc.operator_fleet
{ srv1_host }; my rename operator_fleet -> fleet_intent makes that unresolved in the merge
commit. Repointed to gunbc.fleet_intent (srv1_host unchanged). Whole-tree compile: 0
diagnostics. Same class as the earlier rust_gates_ci.dag repoint.
briansrls added a commit that referenced this pull request Jun 23, 2026
…g 970 EVO Plus) + the in-band/out-of-band observability boundary (BMC can't see drives — route queries by channel) + update operator_fleet.dag with per-host drives (srv1/srv2 in-band, srv3 known); multiple-drives-per-host (#5586)

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* Rename operator_fleet{,_network} -> fleet_intent{,_network} (operator-directed)

Module + symbol + file rename (gunbc.operator_fleet -> gunbc.fleet_intent,
gunbc.operator_fleet_network -> gunbc.fleet_intent_network) plus the test
witnesses and the consuming importers (ci_runner_placement, runner_placement
witness, roadmap_authority prose). Pure token substitution; clean compile
0 diagnostics, all witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* Finalize fleet storage: srv3 Samsung 970 EVO Plus 2TB, per-drive serial typed-absent

Operator confirmed (via neat-boar-71): srv1/srv2 = WD_BLACK SN850X 2TB final,
srv3 = Samsung 970 EVO Plus 2TB final (MZ-V7S2T0BW), serials pending in-band
enumeration. StorageDevice gains serial: NonEmptyStr? (typed-absent/pending,
not fabricated) closing the per-drive-identity review finding structurally.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* docs: link intent-linearity draft from self-applying-lenses (heal inherited doc-orphan)

The intent-linearity-design-draft.md (added by #5584 'roadmap discussion') was
unlinked tree-wide — orphan on main HEAD too, reding doc_graph_has_no_orphan_docs
(main CI confirmed red). It is the candidate DESIGN.md articulation of the same
fractal-intent-linearity crux self-applying-lenses.md opens with, so the cross-link
is topically exact (the regime2 <- emission-ingestion-inverse pattern).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Revert orphan cross-link in self-applying-lenses.md (defer to #5604 central fix)

Per parent ruling: #5604 (warm-lark) is the designated CENTRAL orphan fix and
edits this exact file; a per-branch link to the same orphan from the same file
would collide on merge and duplicates the heal (DESIGN §2). Drop my line; #5586
stays orphan-red until #5604 lands, then merges origin/main CLEAN and inherits
the central heal. Keeps the ROADMAP.md regen (my genuine drift fix).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* observability: dissolve channel_observes Bool predicate into route_observation (review §3)

Reviewer (claude-opus-4-7, non-blocking APPROVE) flagged channel_observes(channel,
class) -> Bool as a predicate over coproducts that brushes predicate-dissolution: it
was a second public surface answering the same question route_observation answers with
the typed ObservationRoutingOutcome. Inlined its match into route_observation so the
only public answer is the structured outcome (RoutedTo/ChannelCannotObserve), and the
witness now asserts that typed surface directly (no Bool projection). Compile clean
(0 diagnostics); all 5 observability witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* observability: name the OOB host-inventory blind cell as firmware-grounded (review §3 (b))

Per parent's §6-scaffold conditions: route_observation's OutOfBand StorageInventory/
NetworkInventory arms now go through out_of_band_inventory_blind_pending_firmware_visibility_derivation,
so the carrier itself states this outcome is FIRMWARE-GROUNDED (derives from host
storage/network visibility at the 2nd firmware) rather than reading as a channel-universal
claim. Comments are comment-walled (#5567/#5579 — verified: a // line is a compile error),
so the dissolution trigger lives in the carrier name (DESIGN §6 'the mark on the carrier is
the authority'). No behavior change: the cell still returns ChannelCannotObserve; witnesses
green; flip-openbmc perturb still reds the grounding witness by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fleet_intent: repoint ci_budget_tree.dag import after rename (merge-collision fix)

Main's new ci_budget_tree.dag (#5590/#5595 budget-tree work) imports gunbc.operator_fleet
{ srv1_host }; my rename operator_fleet -> fleet_intent makes that unresolved in the merge
commit. Repointed to gunbc.fleet_intent (srv1_host unchanged). Whole-tree compile: 0
diagnostics. Same class as the earlier rust_gates_ci.dag repoint.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot mentioned this pull request Jun 23, 2026
6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant