Repository navigation
Runner-slot caps: operator per-axis targets (16GiB x 5 guaranteed, swap 32GiB applied); de-fork swap knob onto the authority - #6463
Merged
Conversation
…ed, swap 32GiB applied) and de-fork the swap knob onto the authority row Operator ruling 2026-07-10 (via merry-owl-649), resolving the declared-vs-live fork on runner_slot_allocation: MemorySwapMax target 32GiB APPLIED (the emitted converge hardcoded MemorySwapMax=0 against the row's 32GiB — the knob now derives from the row through RunnerHostDeployment.per_runner_memory_swap_cap); MemoryMax target 16GiB/slot; slots_per_host 5. Sigma = 5x16 = 80GiB = runner_slice_cap exactly — guaranteed mode, no oversubscription; width-1 floor (~14.7GiB) fits the slot anon. declared_runner_count derives 80/16 = 5, so the count stays coherent with the row by construction. The prior 8GiB x 10 shape is the after-S2b target, not current. row == converge emit == expected readback, and the emitted converge_per_slot_cap already readback-verifies each apply (drifted on inert apply, the verify-effective leg). The live-read witness now carries the discriminating pair: the recorded pre-converge live read (swap=0) DRIFTS against the desired target; a target-matching read converges. Count pins consciously moved: is_ten -> is_five. 14/14 touched witnesses green by execution (wall, boundary-exact, RED oversubscription control, emit pins, delta keystone, live-read pair, conservation, placement). memory_high preserves the authored max-1GiB relation (15GiB; converge does not yet emit a MemoryHigh knob — row coherence only). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… authority -> deployment -> knob -> verify trio as swap per_runner_memory_high_cap on RunnerHostDeployment fed from gunbc_runner_slot_desired().memory_high (15GiB, the authored max-1GiB relation); MemoryHigh legacy_converge_knob (40-fleet-high.conf) emitted per slot on all three hosts; wall pins the value; the row-coherence-only caveat is dropped from the authority disposition. Verify-effective pair added: the recorded live read (high=infinity) DRIFTS against the 15GiB target, a matching read converges. Sigma-swap (160GiB/host) resolved by operator provisioning guarantee host-side; the Sigma-swap wall stays roadmap host-admission. 10/10 touched witnesses green by execution; fleet-converge.sh regenerated, drift gate green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2 of 3 tasks
This was referenced Jul 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Runner-slot caps: operator per-axis targets applied, swap knob de-forked onto the authority row
Resolves the declared-vs-live cap fork found off the #6453 calibration point (merry-owl-649's read, escalated to the operator; ruling 2026-07-10):
runner_slot_allocation.dagdeclared 32GiB MemorySwapMax + 8GiB MemoryMax, but the generatedfleet-converge.shappliedMemorySwapMax=0on every host, and the killing cgroup ran live at 24GiB — the authority row lying in two directions at once.Per-axis targets (operator-set — explicitly NOT reconciled toward live)
"0"(the §3 fork:host_converge.dag's knob carried its own value beside the authority). Reconciling toward live-0 would have cemented the OOM.runner_slice_capexactly — guaranteed mode, no oversubscription (the ≤ check holds with equality; the RED control at 6 slots still discriminates: 96 > 80).Mechanism (one authority, three representations equal by construction)
RunnerHostDeploymentgainsper_runner_memory_swap_cap, fed fromgunbc_runner_slot_desired().memory_swap_max— the swap knob now flows authority → deployment → emit, parallel to how MemoryMax already flowed.declared_runner_count()derives 80/16 = 5, so the count agrees withslots_per_hostby construction at these values.converge_per_slot_capalready does apply →systemctl showreadback → verdict per unit; an authored-but-inert cap readsdrifted, never green. This PR points that existing gate at the right expected values.per_runner_memory_high_capflows authority → deployment → knob (40-fleet-high.conf) with its own verify-effective pair (recorded live read high=infinity drifts against the 15GiB target; matching read converges). The authored max−1GiB relation, now a real cap: a hit at 15 throttles and spills to swap before the 16 kill line. Σ-swap (160GiB/host) is resolved by the operator's host-side provisioning guarantee; the Σ-swap ≤ host_swap_budget wall stays roadmap host-admission.Receipts
declared_runner_count_is_five, placement aggregate.fleet-converge.shregenerated viamain_wet; the drift witness (committed == expected) is green, so the generated artifact matches the new authority.declared_runner_count_is_ten→is_five(2 sites);derives_tenrenamed to the value-agnosticderives_declared_count(it compared symbolically already).Post-merge sequence
fleet-converge.sh(ctrl applies host-side — never from this repo).gunbc_ci_runner_slot_memory_max_live(24GiB, 2026-07-05 receipt) updates on that real converge receipt, firing its own dissolve-on (live == declared → collapse to the single authority).Related: the rust-tests-from-CI drop (reclaiming the 10→5 worker cut) is merry-owl-649's lane, deliberately not folded in here.