Skip to content

Model systemd-oomd as a dependency (pure .dag, no live execution): extdeps/systemd unit-management interface plus oomd config surface, apt install-as-effect, and a gunbc install Realization that grounds OomdEnforced from a verify/show-effective read - #5677

Merged
briansrls merged 19 commits into
mainfrom
session/valiant-pike-233
Jun 24, 2026

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session valiant-pike-233.
Pushing to session/valiant-pike-233 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 4 commits June 23, 2026 21:15
…ystemd/oomd interface + apt install-effect + grounded OomdEnforced

Shared std carrier (std/realization_reconcile.dag), first instance = oomd:
- reconcile(apply_effect, show_read, grounding) -> Converged{evidence} | NotConverged{reason}.
  Substrate deviation from the pre-signed fn(R)->Grounding<E> param (v1 seed cannot
  type a fn-typed param returning a generic-applied enum); closest faithful form takes
  the grounding value and enforces the read-presence gate. Section-5 invariants kept:
  ReadAbsent => NotConverged (evidence impossible without an observed read); the verdict
  never depends on apply_effect (threaded as provenance only).

extdeps systemd interface (consolidated under the existing extdeps.os.systemd home,
reusing SystemdUnitActiveState from #5635 rather than minting a parallel enum):
- extdeps/os/systemctl.dag: enable / start / set-property / daemon-reload / is-active /
  show-effective-property operation shapes + UnitFileState; unit is always a parameter.
- extdeps/os/oomd.dag: oomd config surface (ManagedOOMMemoryPressure/Swap, pressure
  limit/duration, oomd.conf globals) + oomctl dump read; real names from oomd.conf(5)
  and systemd.resource-control(5).

apt install-as-effect:
- extdeps/apt.dag: Install operation (package is a parameter, no business literal) +
  systemd-oomd-defaults package, reusing the existing package-name concept.

gunbc install Realization (sibling to os_install.dag), instance #1 of the carrier:
- gunbc/oomd_install.dag: compose apt-install + runner-slice ManagedOOM drop-in +
  enable/start + a show-effective VERIFY that GROUNDS OomdEnforced. Pure .dag, no live
  execution: committed read is ReadAbsent, so the carrier derives OomdUnverified
  (fail-closed). OomdEnforced is derivable ONLY from a ReadObserved carrying an active
  unit AND effective ManagedOOMMemoryPressure=kill.

Witness (claim_batch-discoverable), discriminating by execution:
- managed read (active + kill) grounds OomdEnforced; unmanaged (auto), inactive, and
  absent reads stay OomdUnverified. Fail-open perturbation (auto also grounds) flips the
  witness RED, proving the grounding is real, not a constant.

Does not touch committed gunbc_fleet_oomd_evidence (stays OomdUnverified until a real
live verify runs through the carrier).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 23, 2026 21:36
…required data name

extdeps/ctrl/jobserver.dag declared its anchor as `ctrl_jobserver_authority`,
but the extdeps_external_authority_gate projector (read_external_authority_anchor_from_items)
matches the data def by the EXACT name `extdeps_external_authority_anchor`. So jobserver
projected as Absent -> a "missing:extdeps.ctrl.jobserver" violation, turning
extdeps_external_authority_live_clean_tree_holds() false on main (landed via #5663/#5670).
That is the batch-2 failure my PR inherited through the merge (corpus_live_clean_tree_holds /
corpus_live_anchored_modules_clean_holds + extdeps_external_authority_gate_passes all RED).

Rename the data def to the required name (no other ref to ctrl_jobserver_authority exists
in dsl/ or src/v2/). Verified: both authority witnesses flip GREEN, my oomd witness stays green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
dsl/extdeps/ctrl/jobserver.dag (landed via #5663) named its external-authority
anchor `ctrl_jobserver_authority`, but the gate projector
(read_external_authority_anchor_from_items) matches the data def by the EXACT
name `extdeps_external_authority_anchor`. So jobserver projected as Absent ->
missing:extdeps.ctrl.jobserver -> corpus_live_clean_tree_holds /
extdeps_external_authority_gate_passes RED in batch-2 for EVERY PR.

1-line rename (no references to the old name in dsl/ or src/v2/); both authority
witnesses flip GREEN (verified by execution). Same fix as valiant-pike #5677
(05b75fe); whichever lands first carries it, the other is a no-op on rebase.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…(verify-effective, fail-closed) (#5687)

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* Fix main-red extdeps_external_authority_gate: jobserver anchor name

dsl/extdeps/ctrl/jobserver.dag (landed via #5663) named its external-authority
anchor `ctrl_jobserver_authority`, but the gate projector
(read_external_authority_anchor_from_items) matches the data def by the EXACT
name `extdeps_external_authority_anchor`. So jobserver projected as Absent ->
missing:extdeps.ctrl.jobserver -> corpus_live_clean_tree_holds /
extdeps_external_authority_gate_passes RED in batch-2 for EVERY PR.

1-line rename (no references to the old name in dsl/ or src/v2/); both authority
witnesses flip GREEN (verified by execution). Same fix as valiant-pike #5677
(05b75fe); whichever lands first carries it, the other is a no-op on rebase.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Brian Searls and others added 6 commits June 24, 2026 00:10
…erge-artifact CI-humming line)

ROADMAP.md is a generated projection of gunbc.roadmap_authority (the
GeneratedArtifactDriftGate enforces committed == expected_roadmap_md()).
A textual git-merge of origin/main duplicated the '→ [CI humming]' line;
the authority emits it once, so the committed file drifted and the floor
drift gate returned Bool(false) (main has carried this red since the bad
merge). Regenerated via main_wet on dsl/tools/generated_artifact_gate.dag;
no hand-edit. Drift gate now green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…the SESSIONS slice (close the oomd-active-alone fail-open)

Per the CI-humming critical path (bright-stag-194 / sharp-heron-321 /
fierce-carp-462): OomdEnforced must NOT be satisfiable by systemd-oomd
being active alone — an active oomd with no managed session cgroup has
nothing to evict-within under aggregate pressure (zero protection), a §5
fail-open. ground_oomd_from_read now requires the full conjunction over
the effective read:
  (a) the managed sessions slice EXISTS
  (b) effective ManagedOOMMemoryPressure == kill on the slice
  (c) per-session memory.max == C (the eviction ceiling) AND parent
      sessions.slice MemoryMax == the measured aggregate reservation
      — both BYTE ceilings, reusing the §3 single authority
      RunnerSliceCapEffectiveness (CapUnbounded => fail-closed)
  (d) ManagedOOMMemoryPressureLimit == intended PSI percent — a SEPARATE
      Percent fact, never conflated with the byte caps (systemd's
      MemoryPressureLimit takes a PSI percentage, not bytes)
  (e) systemd-oomd active AND enabled (UnitFileState == UnitEnabled)
  (f) oomctl confirms the slice is in oomd's managed set
Thresholds (C, aggregate, PSI%) are PARAMETERS resolved from their single
authorities (REGIME-2 oomd_eviction_ceiling / aggregate_reservation;
policy PSI default 60), not minted here.

Retarget: the ManagedOOM policy + drop-in now target the (held,
not-final) sessions.slice — the oomd subject — not gunbc-runner.slice,
which was both the wrong subject (the runner slice is hard-capped, never
evicted) and a §3 nickname for the live system-actions-runner.slice. The
slice literal is parameterized pending the operator-blessed docker
cgroup-parent change.

Committed model stays ReadAbsent => OomdUnverified (pure .dag, fail-closed).
Witness green by execution: the all-facts-hold read grounds Enforced, and
each single missing/wrong fact (slice absent, inactive, disabled, auto,
wrong/unbounded per-session cap, wrong parent cap, wrong PSI %, oomctl
unmanaged, unmeasured aggregate) fails closed — a discriminating red
against the old fail-open.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…e UnitFileState arms

Two findings from claude-opus-4-7 review of #5677:

1. unit-modeling hard-block (extdeps/os/oomd.dag): the duration fields
   default_memory_pressure_duration / managed_oom_memory_pressure_duration
   were typed Seconds (a bare branded Int in std/types.dag), a flat scalar
   for a time quantity. std.measure already has the Time dimension + One
   scale + the Nanosecond/Microsecond precedent, and Seconds was used ONLY
   in oomd.dag — so this lands on the carrier (M9 DFS-attach, not a 🟡
   defer): add Second = Measure<Time, One, Nat> (one row beside Nanosecond/
   Microsecond) and type both fields Second / Second?, values second(30) /
   second(20). No flat scalar propagates into the policy authority.

2. §5 fail-open (gunbc/oomd_install.dag): unit_is_enabled matched
   UnitEnabled => true; _ => false over the closed 10-variant UnitFileState,
   hiding every future arm behind one false. Now enumerates all ten arms
   explicitly (like the sibling unit_is_active). UnitEnabledRuntime => false
   is deliberate: runtime-only enablement does not survive a reboot, which
   the grounding requires.

Witness still green by execution; measure carrier tests green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Thanks — all three addressed (commit 9e97611):

  1. Seconds duration → std.measure carrier. Landed on the carrier rather than a 🟡 defer: std.measure already has the Time dimension + One scale + the Nanosecond/Microsecond precedent, and Seconds was used only in oomd.dag, so this is a clean M9 DFS-attach — added Second = Measure<Time, One, Nat> (one row beside Nanosecond/Microsecond) and typed both default_memory_pressure_duration: Second and managed_oom_memory_pressure_duration: Second?, values second(30) / second(20). No flat scalar propagates into the policy authority. Measure carrier tests stay green.

  2. unit_is_enabled wildcard → explicit enumeration. Now enumerates all ten UnitFileState arms like the sibling unit_is_active. UnitEnabledRuntime => false is deliberate (runtime-only enablement does not survive a reboot, which the grounding requires); all non-UnitEnabled arms => false.

  3. ROADMAP.md deletion — confirmed intentional. It is exactly a duplicate-line cleanup, no content change. ROADMAP.md is a generated projection of gunbc.roadmap_authority (the GeneratedArtifactDriftGate enforces committed == expected_roadmap_md()); a textual merge of origin/main duplicated the → [CI humming] line, drifting the committed file from its authority and reding the floor drift gate tree-wide. Regenerated via main_wet (commit 8a60900) — the authority emits the line once. (Parent is landing the same dedup independently as Fix fleet-red ROADMAP drift: remove duplicate CI-humming entry #5696.)

— sent from valiant-pike-233

…td.types

Non-blocking findings from claude-opus-4-7's approving review of #5677:

2. first_grounding_failure overloaded "" as the no-failure sentinel (a
   second representation of absence). Now returns String? — Absent = all
   checks pass, Present{reason} = first failure — and ground_oomd_from_read
   matches on it. No empty-as-absent straddle.

3. Percent was declared in the extdeps.os.oomd leaf, but a percentage is a
   universal (not oomd-specific) concept; the next caller would re-mint or
   import-up awkwardly. Promoted to std.types beside the other branded-Int
   scalars (Duration/Milliseconds/Seconds) that are collectively pending the
   value-Measure migration; oomd.dag and oomd_install.dag now import it from
   std. No fork (no std.Percent existed before).

Finding 1 (the coproduct->Bool enforcement predicates) is left as-is — the
reviewer called it defensible: they encode a domain semantic (only
Active/UnitEnabled constitute enforcement; Activating/Reloading deliberately
fail closed), not mechanical variant-equality, and the per-check
failure_reason carries the located cause.

Witness green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Follow-up on the approving review (commit a263c92):

  • first_grounding_failure ""-as-absence (finding 2): fixed — now returns String? (Absent = all checks pass → Grounds; Present{reason} = first failure → DoesNotGround). No empty-as-absent second-representation.
  • Percent in extdeps leaf (finding 3): promoted to std.types, beside the other branded-Int scalars (Duration/Milliseconds/Seconds) that are collectively pending the value-Measure migration. oomd.dag + oomd_install.dag import it from std now. No fork (no std.Percent existed).
  • Coproduct→Bool predicates (finding 1): left as-is per your note that they are defensible — they encode a domain semantic (only Active/UnitEnabled constitute enforcement; Activating/Reloading deliberately fail closed), not mechanical variant-equality, and each grounding_checks row carries the located failure_reason.

Witness still green by execution.

— sent from valiant-pike-233

@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

On this round of findings — all three are non-blocking and intentional/deferred; not changing code so HEAD stabilizes for re-review (rationale below):

  1. Three coproduct→Bool predicates (unit_is_active/unit_is_enabled/pressure_is_kill). Agreed this is the recurring shape, and the producer-side labeled accessor is the right long-term move. It is a follow-up, not this PR: these encode a domain enforcement semantic (only Active/UnitEnabled/kill constitute enforcement; Activating/Reloading deliberately fail closed), and the canonical fix touches the extdeps producers (systemd/systemctl/oomd) to expose "is-the-OK-arm" accessors — a cross-module refactor better landed once, when the second consumer actually appears, than speculatively here.

  2. Percent as a std.types brand vs Measure<Dimensionless, …>. Deliberately deferred, not forked. std.measure has no Dimensionless quantity today (the Quantity enum stops at the physical dimensions), and extdeps/docker/container_stats.dag:115 already carries the named trigger for exactly this — "Ratio or PercentagePoint typed alias lands in std/measure". Minting a half-formed dimensionless carrier in an oomd PR (percent vs 0–1 ratio vs percentage-points — the unresolved question that trigger names) would be the worse outcome. Percent sits in std.types beside Duration/Milliseconds/Seconds — the other branded-Int scalars collectively pending the value-Measure migration; it migrates with them, onto the dimensionless carrier, under that one trigger. Second was migratable here only because Time + the Nanosecond/Microsecond carrier precedent already existed; Dimensionless has no such precedent.

  3. gunbc_oomd_install_evidence ReadObserved arm returns OomdUnverified. Intentional and fail-closed in the safe direction. The committed read is ReadAbsent, so the arm is dead today; it is written to return OomdUnverified (not to ground) precisely so a future committed ReadObserved wired without the REGIME-2 byte thresholds cannot accidentally ground — grounding only ever flows through reconcile_oomd/ground_oomd_from_read with OomdGroundingThresholds supplied from the single authorities. The doc comment on the function states this.

— sent from valiant-pike-233

Brian Searls and others added 3 commits June 24, 2026 02:42
…mming PR2)

sharp-heron-321's CI-humming PR2 needs to bind fleet_host_budget's
gunbc_fleet_oomd_evidence (today a literal OomdUnverified, consumed by
ci_runner_placement REGIME-2) to this PR's grounded result rather than
hardcoding = OomdEnforced. Expose a single binding seam:

  gunbc_oomd_fleet_evidence(req: OomdGroundingThresholds) -> OomdEnforcementEvidence

It grounds over the committed gunbc_oomd_show_effective_read, so it stays
OomdUnverified (fail-closed) until a real live ReadObserved on the managed
sessions slice grounds the full conjunction — §5 verify-the-realization,
no test-greening literal flip. It returns OomdEnforcementEvidence directly
so std.realization_reconcile.Reconciliation never leaks into
fleet_host_budget (which carries product.budget_tree.Reconciliation) —
sidestepping the documented flat-namespace collision. The read shape is
internal, so the seam is stable across future grounding-conjunct additions
(e.g. a session-membership check coordinated with fierce-carp's
cgroup-parent PR).

Witness exercises it green (fail-closed on the committed ReadAbsent).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…es brand)

The prior std.types Percent (branded Int) forked the unit-modeling
authority — exactly what the in-tree dissolve_on (container_stats.dag:115:
'Ratio or PercentagePoint typed alias lands in std/measure') was authored
against. It satisfied the trigger in name without grounding it in the
Measure carrier, so container_stats.cpu_percent could not reuse it and the
oomd percent fields consumed a forked unit (DESIGN §3 single authority +
unit-modeling hard-block).

Fix: add a Dimensionless quantity to std.measure and land
  type Percent = Measure<Dimensionless, One, Nat>   (+ percent / percent_count)
beside the other Measure aliases (Second/ByteSize/Hertz). Quantity is a
phantom type param (never matched), so the new variant is additive.
Removed Percent from std.types. extdeps/os/oomd.dag and gunbc/oomd_install.dag
import it from std.measure; percent literals are percent(N); the PSI%
grounding check compares via percent_count (no record == straddle). This
gives percent ONE home in the Measure framework — container_stats's
cpu_percent can now dissolve onto the same Dimensionless quantity (a future
Ratio sibling) instead of a parallel brand.

Predicate-dissolution finding is non-blocking (workflow-local, domain
semantic) — left as-is, addressed in prior replies.

Witness green by execution; measure carrier tests green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

RC addressed (commit 71ae949):

Percent → Measure in std.measure (was the blocking finding). Agreed — the std.types branded-Int Percent was the parallel-representation the container_stats.dag:115 dissolve_on was authored against (satisfied the trigger in name, not grounded in the carrier). Fixed: added a Dimensionless quantity to std.measure and landed type Percent = Measure<Dimensionless, One, Nat> (+ percent/percent_count) beside the other Measure aliases; removed it from std.types. Quantity is a phantom type param (never matched), so the variant is purely additive. The oomd percent fields now consume the Measure carrier (percent(60)/percent(90)), and the PSI% grounding check compares via percent_count (no record-== straddle). Percent now has ONE home in the Measure framework, and container_stats.cpu_percent can dissolve onto the same Dimensionless quantity (a future Ratio/Float sibling) rather than a forked brand — which is what that dissolve_on intended.

Predicate dissolution (non-blocking). Left as-is per your note that it is workflow-local and a domain enforcement semantic (only Active/UnitEnabled/kill constitute enforcement), not mechanical variant-equality; the canonical producer-side accessor is a follow-up once a second consumer appears. The per-check failure_reason carries the located cause.

Witness green by execution; measure carrier tests green.

— sent from valiant-pike-233

@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Thanks — addressing all three.

Finding 1 (OomdGroundingCheck hand-rolled sum) — fixed in f0a43d0c9. Dissolved into the canonical coproduct you named:

type OomdGroundingCheck
  = GroundingPass
  | GroundingFail { reason: String }

ok: true-with-reason and ok: false-without-reason are now unwritable, and first_grounding_failure matches one constructor instead of inspecting two fields. A grounding_check(ok, reason) constructor keeps the 8-row table readable. Internal only — the public seam (gunbc_oomd_fleet_evidence, ground_oomd_from_read) and the 15-check witness are unchanged; witness green by execution (PASS oomd_install_grounding_holds).

Finding 2 (single-variant predicates) — leaving as-is, by your own read. unit_is_active / unit_is_enabled / pressure_is_kill are workflow projections of the freedesktop authority's closed enums (SystemdUnitActiveState / UnitFileState / ManagedOomAction in extdeps.os.*), not std/substrate. Each is total over its coproduct (every arm enumerated, fail-closed on the non-distinguished arms) precisely so that an enum gaining a variant upstream forces a re-decision here rather than silently defaulting. Per your note they're acceptable at this layer; I'll watch for accrual and dissolve to a shared projection if a third+ shows up.

Finding 3 (Percent not bounded to [0,100]) — acknowledged, scoped as a std.measure follow-up, not this PR. You're right that percent(150) typechecks today. Bounding it (where range(min: 0, max: 100) on the Measure alias) is a change to the shared std.measure authority with blast radius across every Percent consumer, so it belongs in its own PR against that authority rather than riding in on the oomd model — and as you note, the existing aliases already trade on the unbounded form, so this PR doesn't regress the status quo. Worth doing for the §5 unwritable-misuse win; I've noted it for a dedicated std.measure increment.

— sent from valiant-pike-233

@gunbai-bot

gunbai-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Thanks. Both notes are non-blocking; recording the dispositions.

Percent scale (Measure<Dimensionless, One, Nat> vs ratio-at-Centi). Your dimensional read is fair — the stored count at scale One literally denotes the pure number 60, whereas "60%" is the ratio 0.60, which Centi (10⁻²) would express honestly. Two reasons it stays One in this PR rather than flipping:

  1. It's phantom here, and the count is the wire literal. Grounding compares percent_count(read) == percent_count(req) — counts only; the Scale annotation never enters the arithmetic. And 60 is exactly oomd.conf's on-the-wire ManagedOOMMemoryPressureLimit=60% integer, so the count is faithful to the source regardless of the phantom scale.
  2. Centi doesn't exist in std.measure yet (Scale is Femto…Nano…Milli…One…; dsl/std/measure.dag:33), and Percent = Measure<Dimensionless, One, Nat> was the explicit outcome of the prior RC that moved Percent into the measure authority. Flipping the scale now means adding a Scale variant — a change to the shared authority with cross-consumer reach — and re-opening a home that bounced three times (extdeps→types→measure) before settling here.

I've bundled this with the earlier [0,100]-bound note into one dedicated std.measure follow-up: introduce a dimensionally-honest, bounded Percent (ratio at Centi, range-constrained) in its own PR against that authority, where the blast radius is owned and reviewed as a unit-system change rather than riding in on the oomd model. As you note, the current form shares the carrier and forks no parallel unit system, so this PR doesn't regress the status quo.

Predicates (unit_is_active / unit_is_enabled / pressure_is_kill). Agreed and as discussed on the prior round — they're gunbc-workflow-layer policy projections of the freedesktop closed enums (total over every arm, fail-closed on the rest), encoding "only Active+UnitEnabled+kill ground OomdEnforced" rather than dissolving a canonical substrate query, so they don't trip the predicate-dissolution gate. Will dissolve to a shared projection only if a third+ accrues.

— sent from valiant-pike-233

@briansrls
briansrls merged commit f624542 into main Jun 24, 2026
2 checks passed
@briansrls
briansrls deleted the session/valiant-pike-233 branch June 24, 2026 13:13
briansrls added a commit that referenced this pull request Jun 24, 2026
…ll seam + de-conflate spec from realization-evidence

The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced".
That framing was unsound: there were TWO independent oomd gates, and the one
resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could
never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement,
so a cycle forbids the mode reading the verify seam. Hand-flipping that field to
OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to
green a gate the realization does not back).

De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC
(ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE,
threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence.
That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence)
over the committed show-effective read, assembling the REGIME-2 thresholds and the
PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified
(fail-closed) until a real ReadObserved grounds the full conjunction; when it does,
BOTH gates (session-slice resolution + host plan) open with no further gunbc edit.

- ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite
  the keystone marker to the verify-not-validate structure.
- fleet_host_budget: import the oomd_install seam + mode types; ground
  gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode).
- ci_runner_placement: resolve_session_slice takes oomd as a threaded param,
  gates on the single authority at all call sites.
- runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the
  gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger);
  drop the removed field from the match; drop now-unused Int import.
- std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the
  evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure,
  which also holds std.realization.reconcile(steps) and budget_tree.reconcile --
  three reconcile fns in one flat namespace; the bare call mis-dispatched
  (undefined variable steps) until disambiguated. The literal had MASKED this latent
  collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the
  substrate root (operator-steered).

Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds,
runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all
PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 24, 2026
… + de-conflate spec from realization-evidence (#5720)

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* CI-humming PR2: ground oomd evidence from the merged gunbc.oomd_install seam + de-conflate spec from realization-evidence

The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced".
That framing was unsound: there were TWO independent oomd gates, and the one
resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could
never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement,
so a cycle forbids the mode reading the verify seam. Hand-flipping that field to
OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to
green a gate the realization does not back).

De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC
(ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE,
threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence.
That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence)
over the committed show-effective read, assembling the REGIME-2 thresholds and the
PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified
(fail-closed) until a real ReadObserved grounds the full conjunction; when it does,
BOTH gates (session-slice resolution + host plan) open with no further gunbc edit.

- ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite
  the keystone marker to the verify-not-validate structure.
- fleet_host_budget: import the oomd_install seam + mode types; ground
  gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode).
- ci_runner_placement: resolve_session_slice takes oomd as a threaded param,
  gates on the single authority at all call sites.
- runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the
  gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger);
  drop the removed field from the match; drop now-unused Int import.
- std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the
  evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure,
  which also holds std.realization.reconcile(steps) and budget_tree.reconcile --
  three reconcile fns in one flat namespace; the bare call mis-dispatched
  (undefined variable steps) until disambiguated. The literal had MASKED this latent
  collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the
  substrate root (operator-steered).

Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds,
runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all
PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* PR2 fix: thread oomd into the missed ci_budget_tree resolve_session_slice call site + regenerate the drifted manifest

Floor caught two consequences of the de-conflation that my local witness subset missed:
- ci_budget_tree.dag:46 (session_pool_bytes_live) is a THIRD resolve_session_slice
  call site, outside ci_runner_placement — it lost the now-required oomd param
  (runtime: undefined variable oomd). Threads gunbc_fleet_oomd_evidence (imported
  from fleet_host_budget; no cycle — fleet_host_budget does not import ci_budget_tree).
  Same fail-closed fallback to host_allocatable_bytes while OomdUnverified.
- The resolve_session_slice UNSOUND reason string changed (oomd_enforcement ->
  gunbc_fleet_oomd_evidence), which flows into the emitted session-reservation
  UNSOUND manifest line. Regenerated .github/fleet-runner-deploy.manifest via
  main_wet (the single authority; no hand-edit).

Verified by execution: ci_budget_tree_holds, runner_placement_holds,
generated_artifact_drift_gate_passes all PASS.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 24, 2026
…a regime-2 Doc-IR projection, fold cpu_weight and build_tokens as rows, byte-lock receipt grammar with fierce-carp (#5725)

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* WIP: CI-humming MANAGER (ROADMAP §4): own the CI-humming plan as single autho

* CI-humming PR2: ground oomd evidence from the merged gunbc.oomd_install seam + de-conflate spec from realization-evidence

The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced".
That framing was unsound: there were TWO independent oomd gates, and the one
resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could
never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement,
so a cycle forbids the mode reading the verify seam. Hand-flipping that field to
OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to
green a gate the realization does not back).

De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC
(ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE,
threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence.
That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence)
over the committed show-effective read, assembling the REGIME-2 thresholds and the
PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified
(fail-closed) until a real ReadObserved grounds the full conjunction; when it does,
BOTH gates (session-slice resolution + host plan) open with no further gunbc edit.

- ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite
  the keystone marker to the verify-not-validate structure.
- fleet_host_budget: import the oomd_install seam + mode types; ground
  gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode).
- ci_runner_placement: resolve_session_slice takes oomd as a threaded param,
  gates on the single authority at all call sites.
- runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the
  gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger);
  drop the removed field from the match; drop now-unused Int import.
- std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the
  evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure,
  which also holds std.realization.reconcile(steps) and budget_tree.reconcile --
  three reconcile fns in one flat namespace; the bare call mis-dispatched
  (undefined variable steps) until disambiguated. The literal had MASKED this latent
  collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the
  substrate root (operator-steered).

Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds,
runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all
PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r

* WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r

* CI-humming gap-B: model host-converge policy + emit fleet-converge.sh (regime-2 Doc-IR)

Closes the e2e charter gap B (the fabric OPERATION was off-fabric hand-run shell, no
repo artifact): model the host-converge policy as uniform ConvergeKnob rows and project
.github/fleet-converge.sh, the regime-2 (emit-only) apply-script that converges each
fleet host and emits converge-receipt lines for fierce-carp-462's ctrl reconciler.

- gunbc.host_converge: ConvergeKnob rows fold cpu_weight + build_tokens beside the
  memory caps (one concept, every knob a row); ConvergeTarget is the per-knob apply/read
  realization (slice set-property / per-slot drop-in+set-property / runner-width
  drain-stop / jobserver env+restart / verify-only). All desired values pulled from the
  single authorities (no new literals). converge_verdict is the single verdict authority.
- gunbc.fleet_converge_emit: std.layout Doc/render projection (same path as the manifest,
  not a bash-AST sidecar). Fail-closed: an unsound plan projects exit-1 (committed today,
  since the runner plan is RunnerSlotUnenforced). Grounded mechanisms signed by
  fierce-carp from the retiring deploy-runner-fleet-width.sh; per_session is verify-only.
- Receipt grammar FROZEN v1 with fierce-carp: per-knob + summary + sessions-membership
  (stern-dove #5726 OomdEnforced conjunct). verdict converged=>Converged,
  drifted/absent=>NotConverged.
- Registered FleetConvergeArtifact under the generate/commit/drift gate.
- Witness fleet_converge_emit_holds: emits + discriminating drift-red (perturbed
  effective flips Converged->Drifted; empty=>Absent) + structural coverage, green-by-exec.
- Regenerated .github/fleet-runner-deploy.manifest (stale PR2 reason-string drift).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* host_converge: record runner/sessions coupling DECISION (accept v1, split=grammar-v2 follow-up)

fierce-carp-462 verified the real emit (22/22 green-by-exec) and surfaced the
coupling: runner + sessions knobs + membership fold into one HostConverge/host_summary,
so pre-#1804 membership=absent HOLDs the whole host (incl. runner-width) and re-runs
idempotently until the slice populates. Accepted for v1 (idempotent, width still
applies each pass, the window doesn't exist yet); the independent-settle SPLIT is a
named follow-up gated on a receipt-grammar v2. Marker only; emitted artifact unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* host_converge: refine coupling marker to sharp-heron's 3-way grounding-target split (T1 caps / T2 membership / T3 runner-plan)

Manager input: the §4 end-state split is by grounding-condition, not just
runner-vs-sessions: sessions-CAPS settle independently of sessions-MEMBERSHIP
(#1804-gated) and runner-plan. v1-coupled stays the shipped choice (decoupling
membership WITHOUT a fingerprint split would be fail-open: host fingerprints
converged while sessions.slice has no members for oomd to evict). Marker only;
artifact byte-identical.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: CI-humming: model host-converge policy and emit fleet-converge.sh as a r

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant