Skip to content

Live-read runner unit memory caps into ConvergeTarget semantics - #6113

Merged
briansrls merged 5 commits into
mainfrom
session/cool-lynx-792
Jul 2, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/cool-lynx-792

Conversation

@briansrls

@briansrls briansrls commented Jul 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Slice-1 typed fixture/read carrier for runner-unit memory caps — NOT the live systemctl show transport (that remains ReadAbsent in gunbc.runner_slot_show_effective_read, a separate load-bearing node).

  • extdeps.os.systemd: SystemdCgroupMemoryLimit + parse_systemd_memory_limit_show
  • gunbc.runner_unit_live_read: recorded fixture row for actions-runner@srv1-01.service, parse → ConvergeTarget/PerSlotMemoryCap verdict via target.bytes_value as single authority (no parallel desired param)
  • Witnesses: parse arms, roundtrip, matching/drift, witness_target_bytes_value_is_single_authority (proves verdict follows bytes_value, not an external cap)

Non-goals (deferred): live fleet systemctl show read replacing ReadAbsent, patch/apply engine, runner-count reconciliation, timer.

Test plan

  • gunbc compile --source-root dsl --source-root src/v2 --target dag (clean tree)
  • claim_batch --entry dsl/test/claim/runner_unit_live_read_witness_test.dag --function runner_unit_live_read_grounds_converge_target → PASS
  • CI floor green on latest SHA

Brian Searls and others added 4 commits July 1, 2026 22:42
…n gate.

The multi-line match arm body was rejected by the parser (FatArrow vs EqEq);
collapse to a single-line expression so the floor compiles cleanly.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot gunbai-bot Bot changed the title 2-live-read-runner-memory: live host read, first slice — read MemoryMax/MemorySwapMax/MemoryHigh for ONE live actions-runner unit and ground into ConvergeTarget semantics (typed, no string flattening); non-goals: no patch/apply engine, no runner-count reconciliation, no timer; RED: fixture read diff Live-read runner unit memory caps into ConvergeTarget semantics Jul 1, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 1, 2026 23:13
@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Re: memory_limit_converge_verdict stringifying ByteSize through converge_verdict(effective: String, expected: String) — agreed this is the right interim shape for slice-1.

The live-read path itself stays typed end-to-end (SystemdCgroupMemoryLimit → ByteSize); the stringify hop exists only at the boundary where we project onto the existing PerSlotMemoryCap.bytes_value: String / converge_verdict carrier in gunbc.host_converge. Grounding bytes_value to ByteSize (and comparing structurally) is explicitly out of scope for this slice — it belongs with the broader ConvergeTarget carrier dissolution, not this read-only increment.

— sent from cool-lynx-792

@gunbai-bot

gunbai-bot Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Re: composer-2.5 APPROVE — confirmed accurate on current 61332a4.

  • Typed boundary is extdeps.os.systemd.SystemdCgroupMemoryLimit → ByteSize; projection onto ConvergeTarget/RunnerSliceCapEffectiveness lives in gunbc.runner_unit_live_read.
  • Live transport is intentionally still ReadAbsent in gunbc.runner_slot_show_effective_read; this slice only lands the fixture row + parse/ground/witness path.
  • No new Rust/shell; witnesses are green locally (claim_batch on runner_unit_live_read_witness_test.dag + os_systemd_witness_test.dag).

Awaiting the in-flight ci floor run on this SHA.

— sent from cool-lynx-792

@gunbai-bot

gunbai-bot Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Re: composer-2.5 APPROVE on 1540202d — verified accurate, no further code changes.

  • SystemdCgroupMemoryLimit coproduct + parse_systemd_memory_limit_show live in extdeps/os/systemd.dag; projection onto ConvergeTarget is in gunbc.runner_unit_live_read with target.bytes_value as the sole desired authority (post sunny-newt-884 review).
  • gunbc_runner_unit_live_read_scope_disposition (Terminal) bounds slice-1 to the fixture/read carrier; live systemctl-show replacing ReadAbsent remains explicitly deferred.
  • Floor witnesses: runner_unit_live_read_grounds_converge_target + os_systemd_witness_test.dag memory-limit roundtrips; discriminating drift/single-authority cases included.

— sent from cool-lynx-792

@gunbai-bot

gunbai-bot Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Re: claude-opus-4-7 APPROVE on 1540202d — both observations verified, no code change (non-blocking as noted).

Malformed vs absent (parse_systemd_memory_limit_show): Confirmed "" and parse_int failure both map to MemoryLimitAbsent today. Agree this is mild §5 conflation, but the cited wire surface (systemctl show --value for MemoryMax/MemorySwapMax/MemoryHigh) is closed to "" / "infinity" / decimal integer — witnesses only exercise those arms. Splitting MemoryLimitMalformed is deferred to the live-transport slice when we actually ingest unbounded host output; not introduced debt for this fixture carrier.

String bytes_value equality: Confirmed memory_limit_converge_verdict_for_bytes_value compares via converge_verdict on stringified byte counts, and PerSlotMemoryCap.bytes_value: String is inherited from gunbc.host_converge on main. This PR does not widen that fork; grounding bytes_value to ByteSize and comparing structurally tracks the ConvergeTarget carrier dissolution already called out in prior review.

— sent from cool-lynx-792

@briansrls
briansrls merged commit 6e1bdd2 into main Jul 2, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/cool-lynx-792 branch July 2, 2026 01:14
briansrls added a commit that referenced this pull request Jul 2, 2026
…des done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 2, 2026
* WIP: fable

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap: fold in operator directives + 2026-07-01 live findings

- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour
  bought no wall-clock — serial compile-clean wall dominates); milestones
  updated; fleet-return group becomes fleet-hardening (the return happened
  ungated, the gates are now owed).
- New: 2-compile-clean-serial (the ~47min width-immune dominant cost +
  its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot
  contract), cap-deconflation corrected (width=9 was live by construction;
  the deferred item was only the concept rename), CD-transport reframed
  post-revert, G4 gains the dup-run + lingering in_progress evidence.
- §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the
  .gitignore landed-drift incident as the RED receipt, closes via the
  merge-admission freshness block) and 3-audit-gate-disagreement
  (compile-clean green while discovery red on the same tree — the
  extdeps.shell collision; one tree, one verdict).
- §1 5-defork gains the live evidence line (the shell fork kept main red).

Witnesses re-targeted in lockstep; verified by execution: main_wet regen,
drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: operator review + fabric dispatch design + stateless-frontend MVP

Applies the operator's three directives in one lockstep batch:

1. Roadmap-review blockers:
   - Ubicloud tone: detour was the diagnostic + emergency valve, not a
     failure; stays the break-glass/burst option.
   - CD transport reframed as target-host proof (LocalShell valid only
     when runner identity proves host=srv1), not Ubicloud-specific.
   - v1-collapse dependency edges now REAL: roadmap_spawner readiness is
     all-parents (node_dep_done folds every edge, not the first), with a
     RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
     dissolve-patches, test-migration, seed-honesty, defork.
   - workload-class admission model + cap/admission de-conflation (three
     facts, one knob today) + sound host admission (Guaranteed vs Burst
     with Σ-accounting receipts) + live host read seam as first-class
     nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
     review finding on #6110).
   - Floor group renamed: throughput — reduce work, then schedule it.
   - Shelf: privacy/isolation model + structural correctness walls.

2. Fabric dispatch design (operator-signed): core design rule prose
   (ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
   oversubscription earned by receipts), StrictLease Policy 0, CI shape
   labels (runs-on as a projection; runner availability is backpressure),
   ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
   Policy 1; TERMINAL reworded to "required CI runs on the compute
   fabric"; converge re-land gains the narrow srv2 first-acceptance case;
   ordering prose ①–⑩.

3. Stateless frontend MVP on fabric: first non-CI product-shaped
   consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
   manual DNS, digest-proving receipt, milestones A/B), service
   allocation receipt under control plane, fabric-hostable rule prose,
   shelf HTML line scoped.

Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap dispatch utility + first-receipt splits + converge edge-direction fix

Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).

- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
  for spawn semantics): {ready (full node rows), upcoming (node +
  unmet_parents), done}. node_json also emits parent_node_ids (all
  parents — folds in claude's non-blocking #6110 finding; single
  parent_node_id kept for bridge back-compat). json_escape now escapes
  newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
  --entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
  target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
  the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
  1-resolver-pathology → -a (profile receipt only) / -b (fix one
  confirmed pathology, edge b←a); 2-live-read-runner-memory as the
  first slice of the read seam (seam gated on it); 2-privilege-model
  sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
  now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
  privilege as converge's child); umbrella g2-runner edge removed so it
  cannot gate; periodic-actuation ← converge kept.

Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: dispatch compile-clean shard A (first-receipt split) + mark owned

Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a
(partition boundary + ONE shard + compose proof, no scheduler enrollment)
dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b
(floor-plan enrollment + before/after batch-1 wall receipt) gated on A.
Verified: regen, drift gate, authority + spawner witnesses PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap: mark 3-audit-gate-inventory done (#6116 merged)

#6116 (gate-inventory audit + pilot red-control) merged without flipping
its node, unlike #6120 which self-marked. Set done: true to parity with
the resolver node — both now render "⏳ awaiting sign-off" (the [x]
checkbox is gated on operator sign-off by design, not merge alone).

Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS;
dispatch file moves 3-audit-gate-inventory to the done partition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap #6122: drop #6120 duplicate resolver node + heal doc-graph orphan

Addresses cursor REQUEST_CHANGES on #6122:
- Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced
  near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation).
- Findings 1/2 (drift-heal, not regression): done:true renders
  "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge);
  #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off —
  that was drift, and the regen heals it to the honest awaiting-sign-off state.
- Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md
  (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node
  via a new with_plan helper (keeps the node sized).

Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph
orphans + dangling links all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap #6122: keep PR scoped — move hostname-converge demo off this branch

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap #6122: sync main (#6113/#6115/#6118) + mark those 3 merged nodes done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 2, 2026
* WIP: fable

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap: fold in operator directives + 2026-07-01 live findings

- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour
  bought no wall-clock — serial compile-clean wall dominates); milestones
  updated; fleet-return group becomes fleet-hardening (the return happened
  ungated, the gates are now owed).
- New: 2-compile-clean-serial (the ~47min width-immune dominant cost +
  its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot
  contract), cap-deconflation corrected (width=9 was live by construction;
  the deferred item was only the concept rename), CD-transport reframed
  post-revert, G4 gains the dup-run + lingering in_progress evidence.
- §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the
  .gitignore landed-drift incident as the RED receipt, closes via the
  merge-admission freshness block) and 3-audit-gate-disagreement
  (compile-clean green while discovery red on the same tree — the
  extdeps.shell collision; one tree, one verdict).
- §1 5-defork gains the live evidence line (the shell fork kept main red).

Witnesses re-targeted in lockstep; verified by execution: main_wet regen,
drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: operator review + fabric dispatch design + stateless-frontend MVP

Applies the operator's three directives in one lockstep batch:

1. Roadmap-review blockers:
   - Ubicloud tone: detour was the diagnostic + emergency valve, not a
     failure; stays the break-glass/burst option.
   - CD transport reframed as target-host proof (LocalShell valid only
     when runner identity proves host=srv1), not Ubicloud-specific.
   - v1-collapse dependency edges now REAL: roadmap_spawner readiness is
     all-parents (node_dep_done folds every edge, not the first), with a
     RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
     dissolve-patches, test-migration, seed-honesty, defork.
   - workload-class admission model + cap/admission de-conflation (three
     facts, one knob today) + sound host admission (Guaranteed vs Burst
     with Σ-accounting receipts) + live host read seam as first-class
     nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
     review finding on #6110).
   - Floor group renamed: throughput — reduce work, then schedule it.
   - Shelf: privacy/isolation model + structural correctness walls.

2. Fabric dispatch design (operator-signed): core design rule prose
   (ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
   oversubscription earned by receipts), StrictLease Policy 0, CI shape
   labels (runs-on as a projection; runner availability is backpressure),
   ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
   Policy 1; TERMINAL reworded to "required CI runs on the compute
   fabric"; converge re-land gains the narrow srv2 first-acceptance case;
   ordering prose ①–⑩.

3. Stateless frontend MVP on fabric: first non-CI product-shaped
   consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
   manual DNS, digest-proving receipt, milestones A/B), service
   allocation receipt under control plane, fabric-hostable rule prose,
   shelf HTML line scoped.

Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap dispatch utility + first-receipt splits + converge edge-direction fix

Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).

- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
  for spawn semantics): {ready (full node rows), upcoming (node +
  unmet_parents), done}. node_json also emits parent_node_ids (all
  parents — folds in claude's non-blocking #6110 finding; single
  parent_node_id kept for bridge back-compat). json_escape now escapes
  newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
  --entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
  target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
  the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
  1-resolver-pathology → -a (profile receipt only) / -b (fix one
  confirmed pathology, edge b←a); 2-live-read-runner-memory as the
  first slice of the read seam (seam gated on it); 2-privilege-model
  sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
  now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
  privilege as converge's child); umbrella g2-runner edge removed so it
  cannot gate; periodic-actuation ← converge kept.

Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: dispatch compile-clean shard A (first-receipt split) + mark owned

Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a
(partition boundary + ONE shard + compose proof, no scheduler enrollment)
dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b
(floor-plan enrollment + before/after batch-1 wall receipt) gated on A.
Verified: regen, drift gate, authority + spawner witnesses PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap: mark 3-audit-gate-inventory done (#6116 merged)

#6116 (gate-inventory audit + pilot red-control) merged without flipping
its node, unlike #6120 which self-marked. Set done: true to parity with
the resolver node — both now render "⏳ awaiting sign-off" (the [x]
checkbox is gated on operator sign-off by design, not merge alone).

Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS;
dispatch file moves 3-audit-gate-inventory to the done partition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap #6122: drop #6120 duplicate resolver node + heal doc-graph orphan

Addresses cursor REQUEST_CHANGES on #6122:
- Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced
  near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation).
- Findings 1/2 (drift-heal, not regression): done:true renders
  "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge);
  #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off —
  that was drift, and the regen heals it to the honest awaiting-sign-off state.
- Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md
  (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node
  via a new with_plan helper (keeps the node sized).

Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph
orphans + dangling links all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap #6122: keep PR scoped — move hostname-converge demo off this branch

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap #6122: sync main (#6113/#6115/#6118) + mark those 3 merged nodes done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 2, 2026
…emit-partition (#6135)

* WIP: fable

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap: fold in operator directives + 2026-07-01 live findings

- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour
  bought no wall-clock — serial compile-clean wall dominates); milestones
  updated; fleet-return group becomes fleet-hardening (the return happened
  ungated, the gates are now owed).
- New: 2-compile-clean-serial (the ~47min width-immune dominant cost +
  its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot
  contract), cap-deconflation corrected (width=9 was live by construction;
  the deferred item was only the concept rename), CD-transport reframed
  post-revert, G4 gains the dup-run + lingering in_progress evidence.
- §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the
  .gitignore landed-drift incident as the RED receipt, closes via the
  merge-admission freshness block) and 3-audit-gate-disagreement
  (compile-clean green while discovery red on the same tree — the
  extdeps.shell collision; one tree, one verdict).
- §1 5-defork gains the live evidence line (the shell fork kept main red).

Witnesses re-targeted in lockstep; verified by execution: main_wet regen,
drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: operator review + fabric dispatch design + stateless-frontend MVP

Applies the operator's three directives in one lockstep batch:

1. Roadmap-review blockers:
   - Ubicloud tone: detour was the diagnostic + emergency valve, not a
     failure; stays the break-glass/burst option.
   - CD transport reframed as target-host proof (LocalShell valid only
     when runner identity proves host=srv1), not Ubicloud-specific.
   - v1-collapse dependency edges now REAL: roadmap_spawner readiness is
     all-parents (node_dep_done folds every edge, not the first), with a
     RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
     dissolve-patches, test-migration, seed-honesty, defork.
   - workload-class admission model + cap/admission de-conflation (three
     facts, one knob today) + sound host admission (Guaranteed vs Burst
     with Σ-accounting receipts) + live host read seam as first-class
     nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
     review finding on #6110).
   - Floor group renamed: throughput — reduce work, then schedule it.
   - Shelf: privacy/isolation model + structural correctness walls.

2. Fabric dispatch design (operator-signed): core design rule prose
   (ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
   oversubscription earned by receipts), StrictLease Policy 0, CI shape
   labels (runs-on as a projection; runner availability is backpressure),
   ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
   Policy 1; TERMINAL reworded to "required CI runs on the compute
   fabric"; converge re-land gains the narrow srv2 first-acceptance case;
   ordering prose ①–⑩.

3. Stateless frontend MVP on fabric: first non-CI product-shaped
   consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
   manual DNS, digest-proving receipt, milestones A/B), service
   allocation receipt under control plane, fabric-hostable rule prose,
   shelf HTML line scoped.

Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap dispatch utility + first-receipt splits + converge edge-direction fix

Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).

- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
  for spawn semantics): {ready (full node rows), upcoming (node +
  unmet_parents), done}. node_json also emits parent_node_ids (all
  parents — folds in claude's non-blocking #6110 finding; single
  parent_node_id kept for bridge back-compat). json_escape now escapes
  newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
  --entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
  target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
  the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
  1-resolver-pathology → -a (profile receipt only) / -b (fix one
  confirmed pathology, edge b←a); 2-live-read-runner-memory as the
  first slice of the read seam (seam gated on it); 2-privilege-model
  sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
  now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
  privilege as converge's child); umbrella g2-runner edge removed so it
  cannot gate; periodic-actuation ← converge kept.

Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: dispatch compile-clean shard A (first-receipt split) + mark owned

Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a
(partition boundary + ONE shard + compose proof, no scheduler enrollment)
dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b
(floor-plan enrollment + before/after batch-1 wall receipt) gated on A.
Verified: regen, drift gate, authority + spawner witnesses PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap: mark 3-audit-gate-inventory done (#6116 merged)

#6116 (gate-inventory audit + pilot red-control) merged without flipping
its node, unlike #6120 which self-marked. Set done: true to parity with
the resolver node — both now render "⏳ awaiting sign-off" (the [x]
checkbox is gated on operator sign-off by design, not merge alone).

Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS;
dispatch file moves 3-audit-gate-inventory to the done partition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap #6122: drop #6120 duplicate resolver node + heal doc-graph orphan

Addresses cursor REQUEST_CHANGES on #6122:
- Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced
  near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation).
- Findings 1/2 (drift-heal, not regression): done:true renders
  "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge);
  #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off —
  that was drift, and the regen heals it to the honest awaiting-sign-off state.
- Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md
  (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node
  via a new with_plan helper (keeps the node sized).

Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph
orphans + dangling links all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap #6122: keep PR scoped — move hostname-converge demo off this branch

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap #6122: sync main (#6113/#6115/#6118) + mark those 3 merged nodes done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap: derive 2-debash-orchestration (#6106) + 5-dual-rep-lens (#6104) done; flip 2-privilege-model (#6114); mark 2-emit-partition dispatched

- authored_merged_prs += 6104, 6106 (operator merged both)
- 2-privilege-model done: #6114 merged, live receipts on #6123/#6130 wet runs
- 2-emit-partition now un-gated and dispatched (adhoc-2040cdfe-46b)
- regen ROADMAP.md via generated_artifact_gate main_wet; drift gate + roadmap witnesses PASS

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 2, 2026
…led GitHub default) (#6154)

* WIP: fable

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap: fold in operator directives + 2026-07-01 live findings

- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour
  bought no wall-clock — serial compile-clean wall dominates); milestones
  updated; fleet-return group becomes fleet-hardening (the return happened
  ungated, the gates are now owed).
- New: 2-compile-clean-serial (the ~47min width-immune dominant cost +
  its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot
  contract), cap-deconflation corrected (width=9 was live by construction;
  the deferred item was only the concept rename), CD-transport reframed
  post-revert, G4 gains the dup-run + lingering in_progress evidence.
- §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the
  .gitignore landed-drift incident as the RED receipt, closes via the
  merge-admission freshness block) and 3-audit-gate-disagreement
  (compile-clean green while discovery red on the same tree — the
  extdeps.shell collision; one tree, one verdict).
- §1 5-defork gains the live evidence line (the shell fork kept main red).

Witnesses re-targeted in lockstep; verified by execution: main_wet regen,
drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: operator review + fabric dispatch design + stateless-frontend MVP

Applies the operator's three directives in one lockstep batch:

1. Roadmap-review blockers:
   - Ubicloud tone: detour was the diagnostic + emergency valve, not a
     failure; stays the break-glass/burst option.
   - CD transport reframed as target-host proof (LocalShell valid only
     when runner identity proves host=srv1), not Ubicloud-specific.
   - v1-collapse dependency edges now REAL: roadmap_spawner readiness is
     all-parents (node_dep_done folds every edge, not the first), with a
     RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
     dissolve-patches, test-migration, seed-honesty, defork.
   - workload-class admission model + cap/admission de-conflation (three
     facts, one knob today) + sound host admission (Guaranteed vs Burst
     with Σ-accounting receipts) + live host read seam as first-class
     nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
     review finding on #6110).
   - Floor group renamed: throughput — reduce work, then schedule it.
   - Shelf: privacy/isolation model + structural correctness walls.

2. Fabric dispatch design (operator-signed): core design rule prose
   (ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
   oversubscription earned by receipts), StrictLease Policy 0, CI shape
   labels (runs-on as a projection; runner availability is backpressure),
   ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
   Policy 1; TERMINAL reworded to "required CI runs on the compute
   fabric"; converge re-land gains the narrow srv2 first-acceptance case;
   ordering prose ①–⑩.

3. Stateless frontend MVP on fabric: first non-CI product-shaped
   consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
   manual DNS, digest-proving receipt, milestones A/B), service
   allocation receipt under control plane, fabric-hostable rule prose,
   shelf HTML line scoped.

Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap dispatch utility + first-receipt splits + converge edge-direction fix

Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).

- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
  for spawn semantics): {ready (full node rows), upcoming (node +
  unmet_parents), done}. node_json also emits parent_node_ids (all
  parents — folds in claude's non-blocking #6110 finding; single
  parent_node_id kept for bridge back-compat). json_escape now escapes
  newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
  --entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
  target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
  the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
  1-resolver-pathology → -a (profile receipt only) / -b (fix one
  confirmed pathology, edge b←a); 2-live-read-runner-memory as the
  first slice of the read seam (seam gated on it); 2-privilege-model
  sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
  now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
  privilege as converge's child); umbrella g2-runner edge removed so it
  cannot gate; periodic-actuation ← converge kept.

Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: dispatch compile-clean shard A (first-receipt split) + mark owned

Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a
(partition boundary + ONE shard + compose proof, no scheduler enrollment)
dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b
(floor-plan enrollment + before/after batch-1 wall receipt) gated on A.
Verified: regen, drift gate, authority + spawner witnesses PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap: mark 3-audit-gate-inventory done (#6116 merged)

#6116 (gate-inventory audit + pilot red-control) merged without flipping
its node, unlike #6120 which self-marked. Set done: true to parity with
the resolver node — both now render "⏳ awaiting sign-off" (the [x]
checkbox is gated on operator sign-off by design, not merge alone).

Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS;
dispatch file moves 3-audit-gate-inventory to the done partition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap #6122: drop #6120 duplicate resolver node + heal doc-graph orphan

Addresses cursor REQUEST_CHANGES on #6122:
- Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced
  near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation).
- Findings 1/2 (drift-heal, not regression): done:true renders
  "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge);
  #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off —
  that was drift, and the regen heals it to the honest awaiting-sign-off state.
- Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md
  (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node
  via a new with_plan helper (keeps the node sized).

Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph
orphans + dangling links all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap #6122: keep PR scoped — move hostname-converge demo off this branch

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap #6122: sync main (#6113/#6115/#6118) + mark those 3 merged nodes done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap: derive 2-debash-orchestration (#6106) + 5-dual-rep-lens (#6104) done; flip 2-privilege-model (#6114); mark 2-emit-partition dispatched

- authored_merged_prs += 6104, 6106 (operator merged both)
- 2-privilege-model done: #6114 merged, live receipts on #6123/#6130 wet runs
- 2-emit-partition now un-gated and dispatched (adhoc-2040cdfe-46b)
- regen ROADMAP.md via generated_artifact_gate main_wet; drift gate + roadmap witnesses PASS

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Revert throwaway deploy-principal edits (restore live_deploy/apply + ci_deploy_access to main)

The manual-deploy investigation surfaced two real bugs (dash/pipefail + principal
fiction) but the fix belongs in the modeled grounded-principal lane, not anemic
stopgap strings. Restoring these two files to origin/main clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* CI policy: 30-minute job timeout (workflow layer; GitHub 360min default stays modeled)

Operator directive 2026-07-02: a healthy floor is ~9min solo — a job past 30min is
pathological and must fail fast + release its runner slot instead of squatting toward
the platform ceiling (observed: 6h-timeout jobs holding all 25 fleet slots in a
self-sustaining queue deadlock, ~9h single-core claim_executor runs).

- gunbc_ci_job_timeout_policy_minutes: Int = 30 (+ Terminal disposition carrying the rationale)
- extdeps default_job_timeout_minutes = 360 deliberately unchanged (§3: it faithfully
  models GitHub's real platform default; policy lives in the workflow layer)
- ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* CI emergency: roll back #6127 width-1 compile-clean sharding (30.9x regression)

#6127 (merged 15:08 today) sharded compile-clean into ~1,605 per-module gunbc-compile
subprocesses, each re-resolving its full import closure (sum-of-closures ~30.9x the
monolith CPU), scheduled at WIDTH 1 because the width fold priced each single-module
shard against a stale whole-corpus 4.24GiB RSS sample vs the 8GiB cap. Live regression:
8h57m wall / 8h07m CPU per job on an 87%-idle 128-core box. Pre-regression monolith
green runs were 28-96min.

Sets the modeled rollback valve GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1 on the ci job (env),
restoring the whole-tree monolith compile-clean. Authority = the matching v2.workflow
valve; rationale on ci_compile_clean_rollback_dissolution_trigger; Scaffold disposition
bound, dissolves with the v2 authority once the in-process shard resolve pool lands.

ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Back out #6127 rollback valve-flip; keep only the 30min timeout policy

The GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE valve does NOT cleanly restore a green
monolith floor: under the valve, gunbc_ci_floor_schedule_lens_holds() FAILs and
batch-0 carries neither shards nor the monolith gate label (verified by execution
with claim_batch --wet under GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1). The valve looks
like a half-exercised scaffold from #6127. Flipping it and patching witnesses to
match an unverified plan path would violate DESIGN §5 (ship only what runs green),
so this PR keeps only the sound, approved part:

- gunbc_ci_job_timeout_policy_minutes = 30 (workflow-layer; GitHub 360 default stays modeled)
- disposition text reconciled: 30min is deliberately BELOW today's 28-96min floor — a
  fail-fast smoke alarm until the resolver single-thread fix lands (verification local meanwhile)

The #6127 regression is better addressed by a clean revert of #6127 or a proper fix
to the plan's rollback branch (load-bearing floor-plan work) — surfaced to the operator.

ci.yml regenerated (timeout-only, no rollback env); drift gate PASS; both shard-b
floor witnesses PASS at origin/main state.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 2, 2026
…#6164)

* WIP: fable

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap: fold in operator directives + 2026-07-01 live findings

- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour
  bought no wall-clock — serial compile-clean wall dominates); milestones
  updated; fleet-return group becomes fleet-hardening (the return happened
  ungated, the gates are now owed).
- New: 2-compile-clean-serial (the ~47min width-immune dominant cost +
  its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot
  contract), cap-deconflation corrected (width=9 was live by construction;
  the deferred item was only the concept rename), CD-transport reframed
  post-revert, G4 gains the dup-run + lingering in_progress evidence.
- §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the
  .gitignore landed-drift incident as the RED receipt, closes via the
  merge-admission freshness block) and 3-audit-gate-disagreement
  (compile-clean green while discovery red on the same tree — the
  extdeps.shell collision; one tree, one verdict).
- §1 5-defork gains the live evidence line (the shell fork kept main red).

Witnesses re-targeted in lockstep; verified by execution: main_wet regen,
drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: operator review + fabric dispatch design + stateless-frontend MVP

Applies the operator's three directives in one lockstep batch:

1. Roadmap-review blockers:
   - Ubicloud tone: detour was the diagnostic + emergency valve, not a
     failure; stays the break-glass/burst option.
   - CD transport reframed as target-host proof (LocalShell valid only
     when runner identity proves host=srv1), not Ubicloud-specific.
   - v1-collapse dependency edges now REAL: roadmap_spawner readiness is
     all-parents (node_dep_done folds every edge, not the first), with a
     RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
     dissolve-patches, test-migration, seed-honesty, defork.
   - workload-class admission model + cap/admission de-conflation (three
     facts, one knob today) + sound host admission (Guaranteed vs Burst
     with Σ-accounting receipts) + live host read seam as first-class
     nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
     review finding on #6110).
   - Floor group renamed: throughput — reduce work, then schedule it.
   - Shelf: privacy/isolation model + structural correctness walls.

2. Fabric dispatch design (operator-signed): core design rule prose
   (ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
   oversubscription earned by receipts), StrictLease Policy 0, CI shape
   labels (runs-on as a projection; runner availability is backpressure),
   ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
   Policy 1; TERMINAL reworded to "required CI runs on the compute
   fabric"; converge re-land gains the narrow srv2 first-acceptance case;
   ordering prose ①–⑩.

3. Stateless frontend MVP on fabric: first non-CI product-shaped
   consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
   manual DNS, digest-proving receipt, milestones A/B), service
   allocation receipt under control plane, fabric-hostable rule prose,
   shelf HTML line scoped.

Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* WIP: fable

* Roadmap dispatch utility + first-receipt splits + converge edge-direction fix

Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).

- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
  for spawn semantics): {ready (full node rows), upcoming (node +
  unmet_parents), done}. node_json also emits parent_node_ids (all
  parents — folds in claude's non-blocking #6110 finding; single
  parent_node_id kept for bridge back-compat). json_escape now escapes
  newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
  --entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
  target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
  the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
  1-resolver-pathology → -a (profile receipt only) / -b (fix one
  confirmed pathology, edge b←a); 2-live-read-runner-memory as the
  first slice of the read seam (seam gated on it); 2-privilege-model
  sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
  now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
  privilege as converge's child); umbrella g2-runner edge removed so it
  cannot gate; periodic-actuation ← converge kept.

Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap: dispatch compile-clean shard A (first-receipt split) + mark owned

Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a
(partition boundary + ONE shard + compose proof, no scheduler enrollment)
dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b
(floor-plan enrollment + before/after batch-1 wall receipt) gated on A.
Verified: regen, drift gate, authority + spawner witnesses PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap: mark 3-audit-gate-inventory done (#6116 merged)

#6116 (gate-inventory audit + pilot red-control) merged without flipping
its node, unlike #6120 which self-marked. Set done: true to parity with
the resolver node — both now render "⏳ awaiting sign-off" (the [x]
checkbox is gated on operator sign-off by design, not merge alone).

Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS;
dispatch file moves 3-audit-gate-inventory to the done partition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap #6122: drop #6120 duplicate resolver node + heal doc-graph orphan

Addresses cursor REQUEST_CHANGES on #6122:
- Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced
  near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation).
- Findings 1/2 (drift-heal, not regression): done:true renders
  "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge);
  #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off —
  that was drift, and the regen heals it to the honest awaiting-sign-off state.
- Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md
  (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node
  via a new with_plan helper (keeps the node sized).

Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph
orphans + dangling links all PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* WIP: fable

* Roadmap #6122: keep PR scoped — move hostname-converge demo off this branch

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roadmap #6122: sync main (#6113/#6115/#6118) + mark those 3 merged nodes done

The three verification-target PRs merged without self-marking their nodes;
central-marker flips 2-cd-transport, 2-live-read-runner-memory, and
2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator
sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Roadmap: derive 2-debash-orchestration (#6106) + 5-dual-rep-lens (#6104) done; flip 2-privilege-model (#6114); mark 2-emit-partition dispatched

- authored_merged_prs += 6104, 6106 (operator merged both)
- 2-privilege-model done: #6114 merged, live receipts on #6123/#6130 wet runs
- 2-emit-partition now un-gated and dispatched (adhoc-2040cdfe-46b)
- regen ROADMAP.md via generated_artifact_gate main_wet; drift gate + roadmap witnesses PASS

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Revert throwaway deploy-principal edits (restore live_deploy/apply + ci_deploy_access to main)

The manual-deploy investigation surfaced two real bugs (dash/pipefail + principal
fiction) but the fix belongs in the modeled grounded-principal lane, not anemic
stopgap strings. Restoring these two files to origin/main clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* CI policy: 30-minute job timeout (workflow layer; GitHub 360min default stays modeled)

Operator directive 2026-07-02: a healthy floor is ~9min solo — a job past 30min is
pathological and must fail fast + release its runner slot instead of squatting toward
the platform ceiling (observed: 6h-timeout jobs holding all 25 fleet slots in a
self-sustaining queue deadlock, ~9h single-core claim_executor runs).

- gunbc_ci_job_timeout_policy_minutes: Int = 30 (+ Terminal disposition carrying the rationale)
- extdeps default_job_timeout_minutes = 360 deliberately unchanged (§3: it faithfully
  models GitHub's real platform default; policy lives in the workflow layer)
- ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* CI emergency: roll back #6127 width-1 compile-clean sharding (30.9x regression)

#6127 (merged 15:08 today) sharded compile-clean into ~1,605 per-module gunbc-compile
subprocesses, each re-resolving its full import closure (sum-of-closures ~30.9x the
monolith CPU), scheduled at WIDTH 1 because the width fold priced each single-module
shard against a stale whole-corpus 4.24GiB RSS sample vs the 8GiB cap. Live regression:
8h57m wall / 8h07m CPU per job on an 87%-idle 128-core box. Pre-regression monolith
green runs were 28-96min.

Sets the modeled rollback valve GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1 on the ci job (env),
restoring the whole-tree monolith compile-clean. Authority = the matching v2.workflow
valve; rationale on ci_compile_clean_rollback_dissolution_trigger; Scaffold disposition
bound, dissolves with the v2 authority once the in-process shard resolve pool lands.

ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* Back out #6127 rollback valve-flip; keep only the 30min timeout policy

The GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE valve does NOT cleanly restore a green
monolith floor: under the valve, gunbc_ci_floor_schedule_lens_holds() FAILs and
batch-0 carries neither shards nor the monolith gate label (verified by execution
with claim_batch --wet under GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1). The valve looks
like a half-exercised scaffold from #6127. Flipping it and patching witnesses to
match an unverified plan path would violate DESIGN §5 (ship only what runs green),
so this PR keeps only the sound, approved part:

- gunbc_ci_job_timeout_policy_minutes = 30 (workflow-layer; GitHub 360 default stays modeled)
- disposition text reconciled: 30min is deliberately BELOW today's 28-96min floor — a
  fail-fast smoke alarm until the resolver single-thread fix lands (verification local meanwhile)

The #6127 regression is better addressed by a clean revert of #6127 or a proper fix
to the plan's rollback branch (load-bearing floor-plan work) — surfaced to the operator.

ci.yml regenerated (timeout-only, no rollback env); drift gate PASS; both shard-b
floor witnesses PASS at origin/main state.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* docs: land enforcement-intent governance model (DESIGN thread + ROADMAP §3 node + sketch)

Model the operator's recurring standing directives (complexity repo-wide,
lenses-must-be-live, self-application, no dual-representation/anemia) as durable
StandingIntent rows, gated fail-closed against LensContract + coverage receipts
-- "ask once, compile forever". One new authority (StandingIntent); everything
else extends existing machinery (LensRegistryEntryV0 -> LensContract; reuse
ConstructionJustification / subject_roster; consume intent_linearity /
self_applying_lenses for the fractal/self-application layer). Un-shelves the
lens-meta-wall lane into ROADMAP §3 with displaced-cost justification (the
operator's repeated manual what-is-enforced-by-what-lens-over-what-corpus join).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* docs: enforcement-intent review refinements (consumer/mode/receipt/exemption types + roadmap A-E split)

Operator design-review deltas before the model becomes load-bearing:
- ConsumerKind / ConsumerRequirement replace the hardwired FloorGate — merge-admission,
  pre-push, periodic-actuator, deploy-readback are valid consumers (gate leg 4 = consumer_satisfies).
- EnforcementMode order (Advisory < AuditOnly < Blocking) modeled with enforcement_mode_satisfies;
  no overloaded >=.
- CoverageReceipt shape added; the gate reads receipts, never self-declared contract claims
  (a red_control:Present whose receipt is RedControlFailedToFlip still reds).
- ScopeSatisfaction / NarrowingReason type the whole-corpus-narrowing path (BootstrapBlocked /
  TypeReflectionUnavailable / ExternalRuntimeOnly / ExplicitOperatorExemption) — not a stringly hatch.
- StandingIntent admission rule (recurring + displaced cost + scoped + mechanism class + receiptable)
  keeps the carrier from becoming a preference dump.
- ROADMAP node split into parent + children A-E with explicit A->B->C-before-object-rules dependency.

DESIGN.md entry unchanged (its "mechanism claiming enforcement" wording was already the refinement).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: fable

* docs: fix #6164 review — edit .dag AUTHORITIES not generated artifacts; de-nickname PropertyClass

Addresses cursor REQUEST_CHANGES (all three findings valid):
- DESIGN.md / ROADMAP.md are EMITTED from gunbc.design_document / gunbc.roadmap_authority.
  My hand-edits to the generated artifacts were drift (a §3 parallel-representation of the
  authority, and would fail the generated-artifact drift gate). Moved the enforcement-intent
  content INTO the authorities (open_threads_blocks li + section_3 node + un-shelve prose) and
  regenerated (claim_batch main_wet). Drift gate now PASSES: committed == emitted.
- Removed the PropertyClass nickname (git-grep empty; a fork of the existing LensIdV0
  lens-property coproduct at src/v2/lens/registry.dag:10) — the exact §3 sin this PR argues
  against. StandingIntent.property now reuses LensIdV0.

Fitting that a single-authority PR forked its own authority; caught by review, fixed at the source.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant