Skip to content

Turn the supply fold into a cross-mode selector: the six inputs supply.dag named as missing, and a duration that can be unknown - #9397

Merged
briansrls merged 11 commits into
mainfrom
session/zesty-hawk-615
Aug 27, 2026
Merged

briansrls merged 11 commits into
mainfrom
session/zesty-hawk-615

Conversation

@briansrls

@briansrls briansrls commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Read this first: one witness here would have passed against the defect it was written to catch

Review 56498 found a fail-open path — the availability wall compared an offer's window against the commitment horizon's wall (remainder + one billing quantum), a number that is the interval the decision commits and was never an upper bound on how long the work runs. So an offer available for a finite interval was admitted to a job of unknown length on the strength of a fabricated bound.

I fixed it and wrote a witness. The first version of that witness used a 480-second window — which the old fold also refused, on a different arm (OfferUnavailableForGrant, since 480 < 4020). It went green against the fixed code and it would have gone green against the broken code too. Coverage that exists, runs, passes, and asserts nothing about the defect.

The witness now uses a 5000-second window — larger than the old wall of 4020 — so the previous fold admitted and priced this offer. Reverting only that arm to the old comparison (mutation E) leaves 17 of 18 witnesses green and reds exactly a_finite_window_refuses_an_unbounded_job_rather_than_comparing. A paired control, a_finite_window_still_admits_a_bounded_job_that_fits_it, keeps this from being a wall in the wrong place.

The question that caught it: would the OLD code also have refused this input? A passing red-check is indistinguishable in review from one that discriminates.


What this changes

product.fabric.supply ended its billing-quantum discussion with "WHAT SELECTION WOULD NEED, none of which exists here", listed six facts, and closed: "Until those land, this fold is honest as a screen and would be a lie as a selector." That sentence was the acceptance test. It is gone, and a selector exists.

product.fabric.selection is new: it composes the two existing screens with six named per-offer observations and ranks offers across billing modes.

One of the six had already landed while the list still claimed it had not. The entry said offer_quoted_total_for_grant's billed_unit_count was a synthetic one-hour quantum, not a per-supplier tariff row. billing_quantum became a field on SupplierOffer in #8960, the fold reads it, and the declaration a few lines above says so — so the list contradicted its own file. Corrected in place.

The other five are modeled, plus a sixth the list did not name and should have: the marginal operating cost. An owned host's explicit zero quote is an asking price; power and cooling are incurred by running and are real cash. Without that axis an owned offer wins every comparison it enters.

The six are a closed SelectionInputAxis coproduct rather than six prose sentences, so exhaustiveness protects the enumeration. Every axis has an arm for not read, which refuses — an unknown cost entering a sum as zero does not lose information, it flatters the supplier nobody measured.

No mode tag anywhere

Continuous owned, hourly rented, per-container cloud are not three kinds of offer. They are settings of facts one carrier already holds: a quantum of 0 against 3600, an explicit zero quote against a published rate, a paid-through interval against pay-as-you-go, an operating cost we bear against one the vendor bears. Nothing in the fold knows which offers are ours.

Two sentences already standing in supply.dag were falsified by the operator on 2026-08-27 and are corrected here: "rented supply being selected only after owned supply is exhausted" and "owned capacity at an explicit zero quote is simply the cheapest admissible ask while any remains." An already-bought Hetzner hour has had its cash spent unrecoverably, so over the remainder its marginal cost is zero, while owned metal is never zero over the same interval. The rented hour wins and our machine stays idle. The old sentences took a prediction about how the numbers usually come out and wrote it down as a property of the fold.

Duration is a state, not a number

Second operator ruling: "we have 7 minutes left on a VM, but aren't sure how long a customer job will take — we have to assume it will spill over to the next hour."

GrantDuration gains UnobservedGrantDuration, on the existing type rather than beside it, at keen-bat-142's request so their fold stops compiling instead of silently treating unknown as known. grant_duration_seconds is renamed grant_duration_bound_seconds and returns Second? — a total accessor over a partial fact would have needed something to return, and every candidate is the fabrication the arm exists to prevent. offer_quoted_total_for_grant returns a QuotedTotal coproduct: a rate quote times an unobserved duration is not a number. A flat per-grant quote still prices, because duration never entered its arithmetic.

CommitmentHorizon has three arms with three different remedies — covered by an interval already paid for, billed beyond one (choose another offer), spill-priced because the duration could not rule the crossing out (go and measure). It travels out on the selected arm, so the receipt says which. Collapsing the last two would send a broker shopping when it should have sent it measuring.

Spill is one billing quantum, so on continuous capacity it is zero by the same arithmetic that gives an hourly supplier 3600 seconds. There is no continuity test and none is needed; if there were, it would be bolted on.

This is not "assume the worst wherever a duration is missing". Spill is a price computed for one question; the unobserved state travels onward intact, and the basis it produces (CommitmentFloorCost — a lower bound, never a projection) says which question was answered.

Evidence

18 witnesses, SubstrateInputsOnly, all green by execution; supply.dag, selection.dag and the witness module all compile with 0 blocking diagnostics.

Five mutations, five distinct red signatures, restored control green:

mutation reds
an unread alternative use prices as zero an_unread_alternative_use_refuses_rather_than_pricing_at_zero
a paid-through commitment never reduces the billed interval a_paid_through_rented_hour_beats_our_own_metal, a_bounded_job_that_fits_the_remainder_is_covered_and_free
an unobserved duration does not price the spill unit seven_minutes_left_and_an_untimed_job_prices_the_spill_hour
operating cost priced at zero 4 witnesses including an_explicit_zero_quote_is_not_a_zero_running_cost
the availability wall compares against the horizon again (the fail-open arm review 56498 found) a_finite_window_refuses_an_unbounded_job_rather_than_comparing

The witness pairs are self-discriminating: the same two offers swap places when one field moves. A paid-through hour with 40 minutes left beats our metal; with 40 seconds left it loses, because a 90-second job crosses the boundary and buys a whole second hour.

The family, and what it answers without modification

Generated rather than solved case-by-case, per the operator's request:

case answered unmodified witness
paid-through rented hour vs owned metal yes a_paid_through_rented_hour_beats_our_own_metal
owned metal already powered and idle yes — measured operating rate, NoFeasibleAlternativeUse an_explicit_zero_quote_is_not_a_zero_running_cost
GCP container-second nobody has bought yes — per-second quote, small quantum, supplier-borne power (shape; no binding written)
a rented hour that expires in 40 seconds yes an_expiring_commitment_buys_the_next_unit_and_stops_winning
an owned host serving someone who would pay more yes — AlternativeUseDisplaced an_alternative_use_displaced_prices_a_paid_through_hour_above_zero
untimed job vs a 7-minute remainder yes seven_minutes_left_and_an_untimed_job_prices_the_spill_hour
the same job vs a 55-minute remainder yes — prices identically an_untimed_job_prices_the_same_against_seven_minutes_and_fifty_five
a hard bound that fits yes a_bounded_job_that_fits_the_remainder_is_covered_and_free
a hard bound that does not fit yes a_bounded_job_that_exceeds_the_remainder_is_billed_beyond_it
the same against a continuous offer (control) yes — no special case spill_costs_nothing_on_continuous_capacity_without_a_special_case
two demands and one offer no not built — demand-side (keen-bat-142, #9395)

The 7-vs-55-minute result is a finding, not a shortfall. With nothing known about duration both remainders commit exactly one further hour, because neither can rule out the crossing. Pricing them apart would invent information. What separates them is a bound, and the two witnesses either side show it separating them the moment one exists — which is what the unobserved arm's obligation asks for.

Declared honestly

  • Tie-break is roster-order-stable, not roster-order-independent. That needs a total order over OfferKey, which is branded over NonEmptyStr, and std carries no string ordering. Next-rung trigger named in the file.
  • CandidateOffer is sole_constructor. That confines who may construct and establishes nothing about whether the observations were honestly taken — a boundary obligation on whoever produced them, per §4b's ceiling rule.
  • Under a wholly unobserved duration a continuous offer prices at a commitment floor of zero. That is correct — continuous capacity commits nothing beyond the seconds it uses — but it makes ignorance-mode ranking degenerate among continuous offers. The remedy is a duration bound.
  • The spill quantum is a floor, and ranking on a floor is biased. One billing quantum is the minimum additional commitment starting incurs — a real quantity, not a prediction. But an unbounded job can cross two boundaries or ten, so an hourly supplier's floor understates by up to 3599 seconds per further crossing while a continuous offer's floor is exact. That bias favours the coarse-quantum mode. It is declared beside the comparator with the bounded-duration carrier as its retirement trigger. A second quantum "to be safer" was rejected: it would invent the very prior this fold refuses to invent elsewhere, and it would always answer.
  • AvailableIndefinitely is not a large interval. An offer with no stated end can hold work of any length; a time-boxed one cannot, and an unbounded job is refused against a finite window by name rather than compared.
  • No supplier bindings written. Scope was the shape they bind to. product/supplier/ubicloud.dag is untouched.

Breaking, deliberately

grant_duration_seconds → grant_duration_bound_seconds returning Second?; offer_quoted_total_for_grant returns QuotedTotal; DemandOfferAffordability gains QuoteNotPriceableWithoutDuration; GrantDuration gains a third arm. Every one of these is a loud break by design, requested by the consuming lane.

@gunbai-bot gunbai-bot Bot changed the title Turn the supply fold from an honest screen into a real cross-mode selector: the six inputs supply.dag names as missing Turn the supply fold into a cross-mode selector: the six inputs supply.dag named as missing, and a duration that can be unknown Aug 27, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 27, 2026 04:35
@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

1 similar comment
@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant