Repository navigation
Turn the supply fold into a cross-mode selector: the six inputs supply.dag named as missing, and a duration that can be unknown - #9397
Merged
Conversation
added 6 commits
August 27, 2026 03:01
added 3 commits
August 27, 2026 04:48
Contributor
|
|
Contributor
|
|
1 similar comment
Contributor
|
|
This was referenced Aug 27, 2026
Closed
Merged
Closed
This was referenced Aug 27, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Read this first: one witness here would have passed against the defect it was written to catch
Review 56498 found a fail-open path — the availability wall compared an offer's window against the commitment horizon's wall (
remainder + one billing quantum), a number that is the interval the decision commits and was never an upper bound on how long the work runs. So an offer available for a finite interval was admitted to a job of unknown length on the strength of a fabricated bound.I fixed it and wrote a witness. The first version of that witness used a 480-second window — which the old fold also refused, on a different arm (
OfferUnavailableForGrant, since 480 < 4020). It went green against the fixed code and it would have gone green against the broken code too. Coverage that exists, runs, passes, and asserts nothing about the defect.The witness now uses a 5000-second window — larger than the old wall of 4020 — so the previous fold admitted and priced this offer. Reverting only that arm to the old comparison (mutation E) leaves 17 of 18 witnesses green and reds exactly
a_finite_window_refuses_an_unbounded_job_rather_than_comparing. A paired control,a_finite_window_still_admits_a_bounded_job_that_fits_it, keeps this from being a wall in the wrong place.The question that caught it: would the OLD code also have refused this input? A passing red-check is indistinguishable in review from one that discriminates.
What this changes
product.fabric.supplyended its billing-quantum discussion with "WHAT SELECTION WOULD NEED, none of which exists here", listed six facts, and closed: "Until those land, this fold is honest as a screen and would be a lie as a selector." That sentence was the acceptance test. It is gone, and a selector exists.product.fabric.selectionis new: it composes the two existing screens with six named per-offer observations and ranks offers across billing modes.One of the six had already landed while the list still claimed it had not. The entry said
offer_quoted_total_for_grant'sbilled_unit_countwas a synthetic one-hour quantum, not a per-supplier tariff row.billing_quantumbecame a field onSupplierOfferin #8960, the fold reads it, and the declaration a few lines above says so — so the list contradicted its own file. Corrected in place.The other five are modeled, plus a sixth the list did not name and should have: the marginal operating cost. An owned host's explicit zero quote is an asking price; power and cooling are incurred by running and are real cash. Without that axis an owned offer wins every comparison it enters.
The six are a closed
SelectionInputAxiscoproduct rather than six prose sentences, so exhaustiveness protects the enumeration. Every axis has an arm for not read, which refuses — an unknown cost entering a sum as zero does not lose information, it flatters the supplier nobody measured.No mode tag anywhere
Continuous owned, hourly rented, per-container cloud are not three kinds of offer. They are settings of facts one carrier already holds: a quantum of 0 against 3600, an explicit zero quote against a published rate, a paid-through interval against pay-as-you-go, an operating cost we bear against one the vendor bears. Nothing in the fold knows which offers are ours.
Two sentences already standing in
supply.dagwere falsified by the operator on 2026-08-27 and are corrected here: "rented supply being selected only after owned supply is exhausted" and "owned capacity at an explicit zero quote is simply the cheapest admissible ask while any remains." An already-bought Hetzner hour has had its cash spent unrecoverably, so over the remainder its marginal cost is zero, while owned metal is never zero over the same interval. The rented hour wins and our machine stays idle. The old sentences took a prediction about how the numbers usually come out and wrote it down as a property of the fold.Duration is a state, not a number
Second operator ruling: "we have 7 minutes left on a VM, but aren't sure how long a customer job will take — we have to assume it will spill over to the next hour."
GrantDurationgainsUnobservedGrantDuration, on the existing type rather than beside it, atkeen-bat-142's request so their fold stops compiling instead of silently treating unknown as known.grant_duration_secondsis renamedgrant_duration_bound_secondsand returnsSecond?— a total accessor over a partial fact would have needed something to return, and every candidate is the fabrication the arm exists to prevent.offer_quoted_total_for_grantreturns aQuotedTotalcoproduct: a rate quote times an unobserved duration is not a number. A flat per-grant quote still prices, because duration never entered its arithmetic.CommitmentHorizonhas three arms with three different remedies — covered by an interval already paid for, billed beyond one (choose another offer), spill-priced because the duration could not rule the crossing out (go and measure). It travels out on the selected arm, so the receipt says which. Collapsing the last two would send a broker shopping when it should have sent it measuring.Spill is one billing quantum, so on continuous capacity it is zero by the same arithmetic that gives an hourly supplier 3600 seconds. There is no continuity test and none is needed; if there were, it would be bolted on.
This is not "assume the worst wherever a duration is missing". Spill is a price computed for one question; the unobserved state travels onward intact, and the basis it produces (
CommitmentFloorCost— a lower bound, never a projection) says which question was answered.Evidence
18 witnesses,
SubstrateInputsOnly, all green by execution;supply.dag,selection.dagand the witness module all compile with 0 blocking diagnostics.Five mutations, five distinct red signatures, restored control green:
an_unread_alternative_use_refuses_rather_than_pricing_at_zeroa_paid_through_rented_hour_beats_our_own_metal,a_bounded_job_that_fits_the_remainder_is_covered_and_freeseven_minutes_left_and_an_untimed_job_prices_the_spill_houran_explicit_zero_quote_is_not_a_zero_running_costa_finite_window_refuses_an_unbounded_job_rather_than_comparingThe witness pairs are self-discriminating: the same two offers swap places when one field moves. A paid-through hour with 40 minutes left beats our metal; with 40 seconds left it loses, because a 90-second job crosses the boundary and buys a whole second hour.
The family, and what it answers without modification
Generated rather than solved case-by-case, per the operator's request:
a_paid_through_rented_hour_beats_our_own_metalNoFeasibleAlternativeUsean_explicit_zero_quote_is_not_a_zero_running_costan_expiring_commitment_buys_the_next_unit_and_stops_winningAlternativeUseDisplacedan_alternative_use_displaced_prices_a_paid_through_hour_above_zeroseven_minutes_left_and_an_untimed_job_prices_the_spill_houran_untimed_job_prices_the_same_against_seven_minutes_and_fifty_fivea_bounded_job_that_fits_the_remainder_is_covered_and_freea_bounded_job_that_exceeds_the_remainder_is_billed_beyond_itspill_costs_nothing_on_continuous_capacity_without_a_special_casekeen-bat-142, #9395)The 7-vs-55-minute result is a finding, not a shortfall. With nothing known about duration both remainders commit exactly one further hour, because neither can rule out the crossing. Pricing them apart would invent information. What separates them is a bound, and the two witnesses either side show it separating them the moment one exists — which is what the unobserved arm's obligation asks for.
Declared honestly
OfferKey, which is branded overNonEmptyStr, and std carries no string ordering. Next-rung trigger named in the file.CandidateOfferissole_constructor. That confines who may construct and establishes nothing about whether the observations were honestly taken — a boundary obligation on whoever produced them, per §4b's ceiling rule.AvailableIndefinitelyis not a large interval. An offer with no stated end can hold work of any length; a time-boxed one cannot, and an unbounded job is refused against a finite window by name rather than compared.product/supplier/ubicloud.dagis untouched.Breaking, deliberately
grant_duration_seconds→grant_duration_bound_secondsreturningSecond?;offer_quoted_total_for_grantreturnsQuotedTotal;DemandOfferAffordabilitygainsQuoteNotPriceableWithoutDuration;GrantDurationgains a third arm. Every one of these is a loud break by design, requested by the consuming lane.