Skip to content

CI-humming: model host-converge policy and emit fleet-converge.sh as a regime-2 Doc-IR projection, fold cpu_weight and build_tokens as rows, byte-lock receipt grammar with fierce-carp - #5725

Merged
briansrls merged 10 commits into
mainfrom
session/wise-eagle-664
Jun 24, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 24, 2026 •

Copy link
Copy Markdown
Contributor

CI-humming gap-B: model host-converge policy + emit fleet-converge.sh

Closes gap B of the CI e2e charter (ci_process_end_to_end): the fabric operation (placement caps + runner width) was off-fabric, hand-run shell with no repo artifact. This puts it on .dag.

Stacked on #5720 (PR2 oomd-ground / Regime2 de-conflation). My code requires PR2's de-conflated Regime2AggregateOomd shape, so this branch merges PR2 in; the diff cleans up once #5720 lands on main. (Also regenerated the stale .github/fleet-runner-deploy.manifest — PR2's committed manifest drifted from its own .dag; flagged to the manager.)

What lands

  • gunbc.host_converge — the host-converge policy as uniform ConvergeKnob rows. cpu_weight and build_tokens fold in as rows beside the memory caps (one concept, every knob a row — no bespoke inline field per knob). ConvergeTarget is the per-knob apply/read realization (slice set-property / per-slot drop-in+set-property / runner-width drain-stop / jobserver env+restart / verify-only). Every desired value pulled from the single authorities (no new literals). converge_verdict is the single verdict authority.
  • gunbc.fleet_converge_emit — fleet-converge.sh as a regime-2 Doc-IR projection via std.layout render (same path as the manifest; not a bash-AST sidecar). Fail-closed: an unsound plan projects an exit 1 script — which is what's committed today, since the live runner plan is RunnerSlotUnenforced.
  • Receipt grammar BYTE-LOCKED v1 with fierce-carp-462 (gunbc_host_converge_receipt_grammar_marker): three line-kinds — per-knob, summary, and a sessions-membership line (sessions_in_slice/sessions_legacy_flat) for stern-dove-499's OomdEnforced conjunct (CI-humming: model the oomd membership conjunct - sessions parented into slice AND non-empty AND not-100-percent-legacy - and DEFINE the membership-signal contract the guard consumes, fail-closed; extends gunbc.oomd_install grounding, model-first off critical path #5726). Mapped to std.realization_reconcile.Reconciliation: converged⇒Converged, drifted/absent⇒NotConverged (absent = the ReadAbsent read-presence gate).
  • Grounded mechanisms signed by fierce-carp from the retiring deploy-runner-fleet-width.sh / deploy-session-slice.sh: runner template actions-runner@.service, per-slot drop-in + per-instance set-property, drain-before-stop (SIGTERM, never SIGKILL) highest-NN-first, build_tokens via /etc/default/ctrl-jobserver + restart. Safety: per_session_max_bytes is carry+verify only (never set-property, never retro-caps existing scopes — the spawn path owns the write).
  • Registered FleetConvergeArtifact under the generate/commit/drift gate.

Green-by-execution

dsl/test/claim/fleet_converge_emit_test.dag::fleet_converge_emit_holds emits the script and proves a discriminating drift-red (perturbed effective flips Converged→Drifted; empty⇒Absent) plus structural coverage of every knob, the fold, caps-before-widen ordering, verify-only per_session, and the membership line. Ran green; drift / layering / extdeps-authority gates green. fierce-carp's thin-run on a real host is the end-to-end consumer.

🤖 Generated with Claude Code

briansrls and others added 6 commits June 24, 2026 13:30
…ll seam + de-conflate spec from realization-evidence

The capacity unlock was scoped as a "1-line flip OomdUnverified -> OomdEnforced".
That framing was unsound: there were TWO independent oomd gates, and the one
resolve_session_slice read (the Regime2 mode's oomd_enforcement FIELD) could
never be grounded in place -- gunbc.oomd_install imports ci_floor_measurement,
so a cycle forbids the mode reading the verify seam. Hand-flipping that field to
OomdEnforced would be the DESIGN section 5 anti-pattern (editing a declaration to
green a gate the realization does not back).

De-conflation (DESIGN section 4): the Regime2 mode is pure operating-point SPEC
(ceiling + concurrency + aggregate); oomd enforcement is realization EVIDENCE,
threaded from the SINGLE grounded authority fleet_host_budget.gunbc_fleet_oomd_evidence.
That authority now binds the gunbc.oomd_install seam (gunbc_oomd_fleet_evidence)
over the committed show-effective read, assembling the REGIME-2 thresholds and the
PSI single authority (gunbc_oomd_sessions_policy). It stays OomdUnverified
(fail-closed) until a real ReadObserved grounds the full conjunction; when it does,
BOTH gates (session-slice resolution + host plan) open with no further gunbc edit.

- ci_floor_measurement: drop oomd_enforcement from Regime2AggregateOomd; rewrite
  the keystone marker to the verify-not-validate structure.
- fleet_host_budget: import the oomd_install seam + mode types; ground
  gunbc_fleet_oomd_evidence via gunbc_fleet_oomd_evidence_for(mode).
- ci_runner_placement: resolve_session_slice takes oomd as a threaded param,
  gates on the single authority at all call sites.
- runner_deploy_emit: PSI dissolve-repoint (interim Int 60 -> percent_count of the
  gunbc_oomd_sessions_policy single authority; #5677 was the dissolve trigger);
  drop the removed field from the match; drop now-unused Int import.
- std.realization_reconcile: rename reconcile -> reconcile_grounded. Grounding the
  evidence newly EXECUTES the reconcile path inside fleet_host_budget's closure,
  which also holds std.realization.reconcile(steps) and budget_tree.reconcile --
  three reconcile fns in one flat namespace; the bare call mis-dispatched
  (undefined variable steps) until disambiguated. The literal had MASKED this latent
  collision; grounding surfaced it (DESIGN section 5). Flat fn namespace is the
  substrate root (operator-steered).

Verified by EXECUTION: runner_placement_holds, oomd_install_grounding_holds,
runner_slot_enforcement_grounding_holds, reconcile_share_collapse_witnesses all
PASS via claim_batch. Posture stays fail-closed (committed read is ReadAbsent).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… (regime-2 Doc-IR)

Closes the e2e charter gap B (the fabric OPERATION was off-fabric hand-run shell, no
repo artifact): model the host-converge policy as uniform ConvergeKnob rows and project
.github/fleet-converge.sh, the regime-2 (emit-only) apply-script that converges each
fleet host and emits converge-receipt lines for fierce-carp-462's ctrl reconciler.

- gunbc.host_converge: ConvergeKnob rows fold cpu_weight + build_tokens beside the
  memory caps (one concept, every knob a row); ConvergeTarget is the per-knob apply/read
  realization (slice set-property / per-slot drop-in+set-property / runner-width
  drain-stop / jobserver env+restart / verify-only). All desired values pulled from the
  single authorities (no new literals). converge_verdict is the single verdict authority.
- gunbc.fleet_converge_emit: std.layout Doc/render projection (same path as the manifest,
  not a bash-AST sidecar). Fail-closed: an unsound plan projects exit-1 (committed today,
  since the runner plan is RunnerSlotUnenforced). Grounded mechanisms signed by
  fierce-carp from the retiring deploy-runner-fleet-width.sh; per_session is verify-only.
- Receipt grammar FROZEN v1 with fierce-carp: per-knob + summary + sessions-membership
  (stern-dove #5726 OomdEnforced conjunct). verdict converged=>Converged,
  drifted/absent=>NotConverged.
- Registered FleetConvergeArtifact under the generate/commit/drift gate.
- Witness fleet_converge_emit_holds: emits + discriminating drift-red (perturbed
  effective flips Converged->Drifted; empty=>Absent) + structural coverage, green-by-exec.
- Regenerated .github/fleet-runner-deploy.manifest (stale PR2 reason-string drift).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 24, 2026 14:30
briansrls and others added 4 commits June 24, 2026 14:39
…plit=grammar-v2 follow-up)

fierce-carp-462 verified the real emit (22/22 green-by-exec) and surfaced the
coupling: runner + sessions knobs + membership fold into one HostConverge/host_summary,
so pre-#1804 membership=absent HOLDs the whole host (incl. runner-width) and re-runs
idempotently until the slice populates. Accepted for v1 (idempotent, width still
applies each pass, the window doesn't exist yet); the independent-settle SPLIT is a
named follow-up gated on a receipt-grammar v2. Marker only; emitted artifact unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…g-target split (T1 caps / T2 membership / T3 runner-plan)

Manager input: the §4 end-state split is by grounding-condition, not just
runner-vs-sessions: sessions-CAPS settle independently of sessions-MEMBERSHIP
(#1804-gated) and runner-plan. v1-coupled stays the shipped choice (decoupling
membership WITHOUT a fingerprint split would be fail-open: host fingerprints
converged while sessions.slice has no members for oomd to evict). Marker only;
artifact byte-identical.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 24, 2026
… shell (§2 handler by emission)

Re-apply the post-operator apply-transport redirect into the migrated .dag
authority (dsl/gunbc/plans/ci_humming.dag, post #5727) + regenerate the
docs/plans/ci-humming.md projection:
- T5 reframed: host apply via gunbc-emitted .github/fleet-converge.sh (the §2
  regime-2 Doc-IR projection handler that inhabits the §6 carrier by emission),
  thin ctrl consume/run; supersedes the closed JS reconciler #1803.
- C1: reconcile -> reconcile_grounded (the flat-namespace collision PR2 #5720
  surfaced when grounding newly executed the fn in a closure holding two other
  reconcile fns).
- New "Re-sequence 2026-06-24" section: A (converge emit #5725) / B (thin
  consume/run #1805) / G (membership conjunct #5726) + the fail-closed
  grounding order.

Supersedes the closed #5723 (which edited the .md directly, pre-migration).
Verified green-by-execution: plan-lens (dissolution-trigger + titled) PASS,
read-side generated-artifact drift gate ExitSuccess (disk == projection),
regen idempotent.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit edf0b71 into main Jun 24, 2026
2 checks passed
@briansrls
briansrls deleted the session/wise-eagle-664 branch June 24, 2026 15:57
briansrls added a commit that referenced this pull request Jun 24, 2026
… shell (§2 handler by emission) (#5728)

Re-apply the post-operator apply-transport redirect into the migrated .dag
authority (dsl/gunbc/plans/ci_humming.dag, post #5727) + regenerate the
docs/plans/ci-humming.md projection:
- T5 reframed: host apply via gunbc-emitted .github/fleet-converge.sh (the §2
  regime-2 Doc-IR projection handler that inhabits the §6 carrier by emission),
  thin ctrl consume/run; supersedes the closed JS reconciler #1803.
- C1: reconcile -> reconcile_grounded (the flat-namespace collision PR2 #5720
  surfaced when grounding newly executed the fn in a closure holding two other
  reconcile fns).
- New "Re-sequence 2026-06-24" section: A (converge emit #5725) / B (thin
  consume/run #1805) / G (membership conjunct #5726) + the fail-closed
  grounding order.

Supersedes the closed #5723 (which edited the .md directly, pre-migration).
Verified green-by-execution: plan-lens (dissolution-trigger + titled) PASS,
read-side generated-artifact drift gate ExitSuccess (disk == projection),
regen idempotent.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant