Repository navigation
Model systemd-oomd as a dependency (pure .dag, no live execution): extdeps/systemd unit-management interface plus oomd config surface, apt install-as-effect, and a gunbc install Realization that grounds OomdEnforced from a verify/show-effective read - #5677
Conversation
…ystemd/oomd interface + apt install-effect + grounded OomdEnforced
Shared std carrier (std/realization_reconcile.dag), first instance = oomd:
- reconcile(apply_effect, show_read, grounding) -> Converged{evidence} | NotConverged{reason}.
Substrate deviation from the pre-signed fn(R)->Grounding<E> param (v1 seed cannot
type a fn-typed param returning a generic-applied enum); closest faithful form takes
the grounding value and enforces the read-presence gate. Section-5 invariants kept:
ReadAbsent => NotConverged (evidence impossible without an observed read); the verdict
never depends on apply_effect (threaded as provenance only).
extdeps systemd interface (consolidated under the existing extdeps.os.systemd home,
reusing SystemdUnitActiveState from #5635 rather than minting a parallel enum):
- extdeps/os/systemctl.dag: enable / start / set-property / daemon-reload / is-active /
show-effective-property operation shapes + UnitFileState; unit is always a parameter.
- extdeps/os/oomd.dag: oomd config surface (ManagedOOMMemoryPressure/Swap, pressure
limit/duration, oomd.conf globals) + oomctl dump read; real names from oomd.conf(5)
and systemd.resource-control(5).
apt install-as-effect:
- extdeps/apt.dag: Install operation (package is a parameter, no business literal) +
systemd-oomd-defaults package, reusing the existing package-name concept.
gunbc install Realization (sibling to os_install.dag), instance #1 of the carrier:
- gunbc/oomd_install.dag: compose apt-install + runner-slice ManagedOOM drop-in +
enable/start + a show-effective VERIFY that GROUNDS OomdEnforced. Pure .dag, no live
execution: committed read is ReadAbsent, so the carrier derives OomdUnverified
(fail-closed). OomdEnforced is derivable ONLY from a ReadObserved carrying an active
unit AND effective ManagedOOMMemoryPressure=kill.
Witness (claim_batch-discoverable), discriminating by execution:
- managed read (active + kill) grounds OomdEnforced; unmanaged (auto), inactive, and
absent reads stay OomdUnverified. Fail-open perturbation (auto also grounds) flips the
witness RED, proving the grounding is real, not a constant.
Does not touch committed gunbc_fleet_oomd_evidence (stays OomdUnverified until a real
live verify runs through the carrier).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…required data name extdeps/ctrl/jobserver.dag declared its anchor as `ctrl_jobserver_authority`, but the extdeps_external_authority_gate projector (read_external_authority_anchor_from_items) matches the data def by the EXACT name `extdeps_external_authority_anchor`. So jobserver projected as Absent -> a "missing:extdeps.ctrl.jobserver" violation, turning extdeps_external_authority_live_clean_tree_holds() false on main (landed via #5663/#5670). That is the batch-2 failure my PR inherited through the merge (corpus_live_clean_tree_holds / corpus_live_anchored_modules_clean_holds + extdeps_external_authority_gate_passes all RED). Rename the data def to the required name (no other ref to ctrl_jobserver_authority exists in dsl/ or src/v2/). Verified: both authority witnesses flip GREEN, my oomd witness stays green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
dsl/extdeps/ctrl/jobserver.dag (landed via #5663) named its external-authority anchor `ctrl_jobserver_authority`, but the gate projector (read_external_authority_anchor_from_items) matches the data def by the EXACT name `extdeps_external_authority_anchor`. So jobserver projected as Absent -> missing:extdeps.ctrl.jobserver -> corpus_live_clean_tree_holds / extdeps_external_authority_gate_passes RED in batch-2 for EVERY PR. 1-line rename (no references to the old name in dsl/ or src/v2/); both authority witnesses flip GREEN (verified by execution). Same fix as valiant-pike #5677 (05b75fe); whichever lands first carries it, the other is a no-op on rebase. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…(verify-effective, fail-closed) (#5687) * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * Fix main-red extdeps_external_authority_gate: jobserver anchor name dsl/extdeps/ctrl/jobserver.dag (landed via #5663) named its external-authority anchor `ctrl_jobserver_authority`, but the gate projector (read_external_authority_anchor_from_items) matches the data def by the EXACT name `extdeps_external_authority_anchor`. So jobserver projected as Absent -> missing:extdeps.ctrl.jobserver -> corpus_live_clean_tree_holds / extdeps_external_authority_gate_passes RED in batch-2 for EVERY PR. 1-line rename (no references to the old name in dsl/ or src/v2/); both authority witnesses flip GREEN (verified by execution). Same fix as valiant-pike #5677 (05b75fe); whichever lands first carries it, the other is a no-op on rebase. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…erge-artifact CI-humming line) ROADMAP.md is a generated projection of gunbc.roadmap_authority (the GeneratedArtifactDriftGate enforces committed == expected_roadmap_md()). A textual git-merge of origin/main duplicated the '→ [CI humming]' line; the authority emits it once, so the committed file drifted and the floor drift gate returned Bool(false) (main has carried this red since the bad merge). Regenerated via main_wet on dsl/tools/generated_artifact_gate.dag; no hand-edit. Drift gate now green by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…the SESSIONS slice (close the oomd-active-alone fail-open)
Per the CI-humming critical path (bright-stag-194 / sharp-heron-321 /
fierce-carp-462): OomdEnforced must NOT be satisfiable by systemd-oomd
being active alone — an active oomd with no managed session cgroup has
nothing to evict-within under aggregate pressure (zero protection), a §5
fail-open. ground_oomd_from_read now requires the full conjunction over
the effective read:
(a) the managed sessions slice EXISTS
(b) effective ManagedOOMMemoryPressure == kill on the slice
(c) per-session memory.max == C (the eviction ceiling) AND parent
sessions.slice MemoryMax == the measured aggregate reservation
— both BYTE ceilings, reusing the §3 single authority
RunnerSliceCapEffectiveness (CapUnbounded => fail-closed)
(d) ManagedOOMMemoryPressureLimit == intended PSI percent — a SEPARATE
Percent fact, never conflated with the byte caps (systemd's
MemoryPressureLimit takes a PSI percentage, not bytes)
(e) systemd-oomd active AND enabled (UnitFileState == UnitEnabled)
(f) oomctl confirms the slice is in oomd's managed set
Thresholds (C, aggregate, PSI%) are PARAMETERS resolved from their single
authorities (REGIME-2 oomd_eviction_ceiling / aggregate_reservation;
policy PSI default 60), not minted here.
Retarget: the ManagedOOM policy + drop-in now target the (held,
not-final) sessions.slice — the oomd subject — not gunbc-runner.slice,
which was both the wrong subject (the runner slice is hard-capped, never
evicted) and a §3 nickname for the live system-actions-runner.slice. The
slice literal is parameterized pending the operator-blessed docker
cgroup-parent change.
Committed model stays ReadAbsent => OomdUnverified (pure .dag, fail-closed).
Witness green by execution: the all-facts-hold read grounds Enforced, and
each single missing/wrong fact (slice absent, inactive, disabled, auto,
wrong/unbounded per-session cap, wrong parent cap, wrong PSI %, oomctl
unmanaged, unmeasured aggregate) fails closed — a discriminating red
against the old fail-open.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…e UnitFileState arms Two findings from claude-opus-4-7 review of #5677: 1. unit-modeling hard-block (extdeps/os/oomd.dag): the duration fields default_memory_pressure_duration / managed_oom_memory_pressure_duration were typed Seconds (a bare branded Int in std/types.dag), a flat scalar for a time quantity. std.measure already has the Time dimension + One scale + the Nanosecond/Microsecond precedent, and Seconds was used ONLY in oomd.dag — so this lands on the carrier (M9 DFS-attach, not a 🟡 defer): add Second = Measure<Time, One, Nat> (one row beside Nanosecond/ Microsecond) and type both fields Second / Second?, values second(30) / second(20). No flat scalar propagates into the policy authority. 2. §5 fail-open (gunbc/oomd_install.dag): unit_is_enabled matched UnitEnabled => true; _ => false over the closed 10-variant UnitFileState, hiding every future arm behind one false. Now enumerates all ten arms explicitly (like the sibling unit_is_active). UnitEnabledRuntime => false is deliberate: runtime-only enablement does not survive a reboot, which the grounding requires. Witness still green by execution; measure carrier tests green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Thanks — all three addressed (commit 9e97611):
— sent from valiant-pike-233 |
…td.types Non-blocking findings from claude-opus-4-7's approving review of #5677: 2. first_grounding_failure overloaded "" as the no-failure sentinel (a second representation of absence). Now returns String? — Absent = all checks pass, Present{reason} = first failure — and ground_oomd_from_read matches on it. No empty-as-absent straddle. 3. Percent was declared in the extdeps.os.oomd leaf, but a percentage is a universal (not oomd-specific) concept; the next caller would re-mint or import-up awkwardly. Promoted to std.types beside the other branded-Int scalars (Duration/Milliseconds/Seconds) that are collectively pending the value-Measure migration; oomd.dag and oomd_install.dag now import it from std. No fork (no std.Percent existed before). Finding 1 (the coproduct->Bool enforcement predicates) is left as-is — the reviewer called it defensible: they encode a domain semantic (only Active/UnitEnabled constitute enforcement; Activating/Reloading deliberately fail closed), not mechanical variant-equality, and the per-check failure_reason carries the located cause. Witness green by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Follow-up on the approving review (commit a263c92):
Witness still green by execution. — sent from valiant-pike-233 |
|
On this round of findings — all three are non-blocking and intentional/deferred; not changing code so HEAD stabilizes for re-review (rationale below):
— sent from valiant-pike-233 |
…mming PR2) sharp-heron-321's CI-humming PR2 needs to bind fleet_host_budget's gunbc_fleet_oomd_evidence (today a literal OomdUnverified, consumed by ci_runner_placement REGIME-2) to this PR's grounded result rather than hardcoding = OomdEnforced. Expose a single binding seam: gunbc_oomd_fleet_evidence(req: OomdGroundingThresholds) -> OomdEnforcementEvidence It grounds over the committed gunbc_oomd_show_effective_read, so it stays OomdUnverified (fail-closed) until a real live ReadObserved on the managed sessions slice grounds the full conjunction — §5 verify-the-realization, no test-greening literal flip. It returns OomdEnforcementEvidence directly so std.realization_reconcile.Reconciliation never leaks into fleet_host_budget (which carries product.budget_tree.Reconciliation) — sidestepping the documented flat-namespace collision. The read shape is internal, so the seam is stable across future grounding-conjunct additions (e.g. a session-membership check coordinated with fierce-carp's cgroup-parent PR). Witness exercises it green (fail-closed on the committed ReadAbsent). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…es brand) The prior std.types Percent (branded Int) forked the unit-modeling authority — exactly what the in-tree dissolve_on (container_stats.dag:115: 'Ratio or PercentagePoint typed alias lands in std/measure') was authored against. It satisfied the trigger in name without grounding it in the Measure carrier, so container_stats.cpu_percent could not reuse it and the oomd percent fields consumed a forked unit (DESIGN §3 single authority + unit-modeling hard-block). Fix: add a Dimensionless quantity to std.measure and land type Percent = Measure<Dimensionless, One, Nat> (+ percent / percent_count) beside the other Measure aliases (Second/ByteSize/Hertz). Quantity is a phantom type param (never matched), so the new variant is additive. Removed Percent from std.types. extdeps/os/oomd.dag and gunbc/oomd_install.dag import it from std.measure; percent literals are percent(N); the PSI% grounding check compares via percent_count (no record == straddle). This gives percent ONE home in the Measure framework — container_stats's cpu_percent can now dissolve onto the same Dimensionless quantity (a future Ratio sibling) instead of a parallel brand. Predicate-dissolution finding is non-blocking (workflow-local, domain semantic) — left as-is, addressed in prior replies. Witness green by execution; measure carrier tests green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
RC addressed (commit 71ae949): Percent → Measure in std.measure (was the blocking finding). Agreed — the std.types branded-Int Predicate dissolution (non-blocking). Left as-is per your note that it is workflow-local and a domain enforcement semantic (only Witness green by execution; measure carrier tests green. — sent from valiant-pike-233 |
|
Thanks — addressing all three. Finding 1 (
Finding 2 (single-variant predicates) — leaving as-is, by your own read. Finding 3 ( — sent from valiant-pike-233 |
|
Thanks. Both notes are non-blocking; recording the dispositions. Percent scale (
I've bundled this with the earlier Predicates ( — sent from valiant-pike-233 |
…ll seam + de-conflate spec from realization-evidence The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced". That framing was unsound: there were TWO independent oomd gates, and the one resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement, so a cycle forbids the mode reading the verify seam. Hand-flipping that field to OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to green a gate the realization does not back). De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC (ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE, threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence. That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence) over the committed show-effective read, assembling the REGIME-2 thresholds and the PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified (fail-closed) until a real ReadObserved grounds the full conjunction; when it does, BOTH gates (session-slice resolution + host plan) open with no further gunbc edit. - ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite the keystone marker to the verify-not-validate structure. - fleet_host_budget: import the oomd_install seam + mode types; ground gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode). - ci_runner_placement: resolve_session_slice takes oomd as a threaded param, gates on the single authority at all call sites. - runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger); drop the removed field from the match; drop now-unused Int import. - std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure, which also holds std.realization.reconcile(steps) and budget_tree.reconcile -- three reconcile fns in one flat namespace; the bare call mis-dispatched (undefined variable steps) until disambiguated. The literal had MASKED this latent collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the substrate root (operator-steered). Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds, runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… + de-conflate spec from realization-evidence (#5720) * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * CI-humming PR2: ground oomd evidence from the merged gunbc.oomd_install seam + de-conflate spec from realization-evidence The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced". That framing was unsound: there were TWO independent oomd gates, and the one resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement, so a cycle forbids the mode reading the verify seam. Hand-flipping that field to OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to green a gate the realization does not back). De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC (ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE, threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence. That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence) over the committed show-effective read, assembling the REGIME-2 thresholds and the PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified (fail-closed) until a real ReadObserved grounds the full conjunction; when it does, BOTH gates (session-slice resolution + host plan) open with no further gunbc edit. - ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite the keystone marker to the verify-not-validate structure. - fleet_host_budget: import the oomd_install seam + mode types; ground gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode). - ci_runner_placement: resolve_session_slice takes oomd as a threaded param, gates on the single authority at all call sites. - runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger); drop the removed field from the match; drop now-unused Int import. - std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure, which also holds std.realization.reconcile(steps) and budget_tree.reconcile -- three reconcile fns in one flat namespace; the bare call mis-dispatched (undefined variable steps) until disambiguated. The literal had MASKED this latent collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the substrate root (operator-steered). Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds, runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * PR2 fix: thread oomd into the missed ci_budget_tree resolve_session_slice call site + regenerate the drifted manifest Floor caught two consequences of the de-conflation that my local witness subset missed: - ci_budget_tree.dag:46 (session_pool_bytes_live) is a THIRD resolve_session_slice call site, outside ci_runner_placement — it lost the now-required oomd param (runtime: undefined variable oomd). Threads gunbc_fleet_oomd_evidence (imported from fleet_host_budget; no cycle — fleet_host_budget does not import ci_budget_tree). Same fail-closed fallback to host_allocatable_bytes while OomdUnverified. - The resolve_session_slice UNSOUND reason string changed (oomd_enforcement -> gunbc_fleet_oomd_evidence), which flows into the emitted session-reservation UNSOUND manifest line. Regenerated .github/fleet-runner-deploy.manifest via main_wet (the single authority; no hand-edit). Verified by execution: ci_budget_tree_holds, runner_placement_holds, generated_artifact_drift_gate_passes all PASS. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…a regime-2 Doc-IR projection, fold cpu_weight and build_tokens as rows, byte-lock receipt grammar with fierce-carp (#5725) * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho * CI-humming PR2: ground oomd evidence from the merged gunbc.oomd_install seam + de-conflate spec from realization-evidence The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced". That framing was unsound: there were TWO independent oomd gates, and the one resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement, so a cycle forbids the mode reading the verify seam. Hand-flipping that field to OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to green a gate the realization does not back). De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC (ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE, threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence. That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence) over the committed show-effective read, assembling the REGIME-2 thresholds and the PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified (fail-closed) until a real ReadObserved grounds the full conjunction; when it does, BOTH gates (session-slice resolution + host plan) open with no further gunbc edit. - ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite the keystone marker to the verify-not-validate structure. - fleet_host_budget: import the oomd_install seam + mode types; ground gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode). - ci_runner_placement: resolve_session_slice takes oomd as a threaded param, gates on the single authority at all call sites. - runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger); drop the removed field from the match; drop now-unused Int import. - std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure, which also holds std.realization.reconcile(steps) and budget_tree.reconcile -- three reconcile fns in one flat namespace; the bare call mis-dispatched (undefined variable steps) until disambiguated. The literal had MASKED this latent collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the substrate root (operator-steered). Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds, runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r * WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r * CI-humming gap-B: model host-converge policy + emit fleet-converge.sh (regime-2 Doc-IR) Closes the e2e charter gap B (the fabric OPERATION was off-fabric hand-run shell, no repo artifact): model the host-converge policy as uniform ConvergeKnob rows and project .github/fleet-converge.sh, the regime-2 (emit-only) apply-script that converges each fleet host and emits converge-receipt lines for fierce-carp-462's ctrl reconciler. - gunbc.host_converge: ConvergeKnob rows fold cpu_weight + build_tokens beside the memory caps (one concept, every knob a row); ConvergeTarget is the per-knob apply/read realization (slice set-property / per-slot drop-in+set-property / runner-width drain-stop / jobserver env+restart / verify-only). All desired values pulled from the single authorities (no new literals). converge_verdict is the single verdict authority. - gunbc.fleet_converge_emit: std.layout Doc/render projection (same path as the manifest, not a bash-AST sidecar). Fail-closed: an unsound plan projects exit-1 (committed today, since the runner plan is RunnerSlotUnenforced). Grounded mechanisms signed by fierce-carp from the retiring deploy-runner-fleet-width.sh; per_session is verify-only. - Receipt grammar FROZEN v1 with fierce-carp: per-knob + summary + sessions-membership (stern-dove #5726 OomdEnforced conjunct). verdict converged=>Converged, drifted/absent=>NotConverged. - Registered FleetConvergeArtifact under the generate/commit/drift gate. - Witness fleet_converge_emit_holds: emits + discriminating drift-red (perturbed effective flips Converged->Drifted; empty=>Absent) + structural coverage, green-by-exec. - Regenerated .github/fleet-runner-deploy.manifest (stale PR2 reason-string drift). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * host_converge: record runner/sessions coupling DECISION (accept v1, split=grammar-v2 follow-up) fierce-carp-462 verified the real emit (22/22 green-by-exec) and surfaced the coupling: runner + sessions knobs + membership fold into one HostConverge/host_summary, so pre-#1804 membership=absent HOLDs the whole host (incl. runner-width) and re-runs idempotently until the slice populates. Accepted for v1 (idempotent, width still applies each pass, the window doesn't exist yet); the independent-settle SPLIT is a named follow-up gated on a receipt-grammar v2. Marker only; emitted artifact unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * host_converge: refine coupling marker to sharp-heron's 3-way grounding-target split (T1 caps / T2 membership / T3 runner-plan) Manager input: the §4 end-state split is by grounding-condition, not just runner-vs-sessions: sessions-CAPS settle independently of sessions-MEMBERSHIP (#1804-gated) and runner-plan. v1-coupled stays the shipped choice (decoupling membership WITHOUT a fingerprint split would be fail-open: host fingerprints converged while sessions.slice has no members for oomd to evict). Marker only; artifact byte-identical. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Auto-opened by session-dashboard for session
valiant-pike-233.Pushing to
session/valiant-pike-233advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan