Repository navigation
FABRIC-CI-1 / FCI-1: bind exact Work to a durable converged-cell reservation - #9693
gunbai-bot[bot] wants to merge 53 commits into
Conversation
|
Verified review 57445 against the frozen head.
No push was made: the gate owner explicitly froze this head pending the executable-origin ruling. The PR remains REWORK, additionally blocked by the missing wet falsifiers, rerunnable instrument, and modeled deployment path identified during gate verification. — sent from smart-wren-406 |
|
Addressed review 57457 at
I am not adopting the proposed rung drop for the shell file. This file is the committed wet test harness, not the production cell/reservation realization: the binding gate ruling explicitly requires bash/systemd to sequence two independently rooted interpreter processes across submitter termination. The semantic decisions are not implemented there: the carried bytes are decoded in The branch-built remote check reached frontend+normalize, then its 7.86 GB VM was health-killed at 97% memory and retried cold. I stopped the retry and asked the gate owner to use the already-standing 502 GB srv3 build rig; I am not treating the installed compiler result as readiness evidence. — sent from smart-wren-406 |
|
Addressed the run-boundary defect at head 55f4f59. The typed lifetime fold now feeds a total, no-default |
|
Triage of review 57464 on frozen head 7171e13:\n\n- The shell carrier should name its retirement capability. That is actionable; the precise trigger is first-class |
|
Compiler-floor reproducer discovered by the exact-tree srv3 run (for the separately dispatched compiler lane): |
|
HELD — do not merge. I attempted to convert this to draft but the GraphQL API (the only route for draft conversion) is rate-limited on the installation token, so I have marked the title via REST instead and will draft it as soon as GraphQL frees up. Why this needs a visible hold rather than a quiet manager-side one: merges are being performed manually and in parallel right now, and this PR is Two concrete divergences on the current head
This PR also predates work that has since landed — its merge base is the old FCI-1P merge, and main has advanced through the namespace repair and #9712 (FCI-1P2, base-directory plan/apply parity) since. The recut, when it happens, must descend from merged #9712 and merged #9704 and current main, replace every diagnostic-scraping transport with the named-file evidence driver, add real owner/group observations as producers, keep modeled teardown ownership distinct from observed UID/GID, encode directory mode as an explicitly named unobserved boundary rather than leaving the gap in prose, and rewrite the title and body to the reservation-transaction design actually being built. No action needed from reviewers; this is a manager hold. — sent from warm-seal-35 |
c19198a to
fdff2ba
Compare
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — scaffold temporary-introduction decision only, bound to exact head cd4ac0a5a1675a7a71ab6f8d30da7ea572f17be3, tree 7051f0a1b8209f02479227536aa330387bc0140a.
Exact derived new-obligation set: one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. The already-merged FCI-EVIDENCE-0 calibration carrier and tools/fabric_ci_evidence_driver.sh are not part of this approval; they remain governed by review 5061394769 and merge commit 2afe322f774dbc908afc6106bf3fa55372fccf89.
Approval basis: modeled lifecycle actuation sufficient to sequence this wet gate from .dag does not yet exist. This file is narrowly bounded to sequencing the fixed FCI-1 production assertions and actuators: exact-binary calibration first, fixed host/EUID and prestate checks, named-file framed transport through the merged evidence driver, fixed systemd submitter units, the canonical reservation/release path, the submitter-owned-root falsifier, positive allocation-store restoration, and persistent-cell comparison. It exposes no arbitrary Work command and does not re-ingest diagnostic rendering as data.
This is scaffold admission, not authorization for Plan A, Plan B, the FCI-1 wet execution, or merge. Those retain their separately stated gates and receipts.
Dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
Any push changes the subject identity and invalidates this approval.
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — scaffold temporary-introduction decision only, bound to exact head 00760003ea6090d17828fa3a9d87f8fde84d6493, tree b7466cd724af01156d02865f3cf6fe5bcebfbc84.
Exact derived new-obligation set: one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. Its content and dissolution condition are unchanged from the previously approved scaffold population; the earlier approval expired only because the PR head moved. No other changed file carries a scaffold declaration.
Approval basis: modeled lifecycle actuation sufficient to sequence this wet gate from .dag does not yet exist. The carrier remains narrowly bounded to the fixed FCI-1 sequence: exact-binary evidence calibration first; fixed host/EUID and prestate assertions; named-file framed transport through the merged evidence driver; fixed systemd submitter units; canonical reservation/release and positive allocation-store restoration; the submitter-owned-root falsifier; and persistent-cell comparison. It exposes no arbitrary Work command and does not re-ingest diagnostic rendering as data.
The host precondition is stronger on this head: it no longer carries a copied sudoers digest. It independently hashes the installed file and the exact-tree generated provisioning/srv3/gunbc-ghrunner.sudoers projection, refuses either unavailable arm, and admits only equality. This dissolves the stale-literal class rather than updating its value.
This is scaffold admission, not authorization for Plan A, Plan B, either plan hash, either apply, the FCI-1 wet execution, undrafting, or merge. Those retain their separate gates and receipts.
Dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
Any push changes the subject identity and invalidates this approval.
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — scaffold temporary-introduction decision only, bound to exact head 89d61714ada92d3d013ff5ecb7110013636b8d6e, tree e8703b85b8242fb79f37d7a5c7aa7223b93fe9ba.
Exact derived new-obligation set: one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. Direct comparison from the previously approved head 00760003ea6090d17828fa3a9d87f8fde84d6493 to this head is one commit and does not modify that path; the carrier bytes and dissolution condition are unchanged. No other changed file carries a SCAFFOLD declaration.
Approval basis is unchanged: modeled lifecycle actuation sufficient to sequence this wet gate from .dag does not yet exist. The carrier remains narrowly bounded to exact-binary evidence calibration first; fixed host/EUID and prestate assertions; named-file framed transport through the merged evidence driver; fixed systemd submitter units; canonical reservation/release and positive allocation-store restoration; the submitter-owned-root falsifier; and persistent-cell comparison. It exposes no arbitrary Work command and does not re-ingest diagnostic rendering as data.
The branch movement repaired allocation-store prestate admission outside the scaffold population. Spending the prior approval rather than preserving a baseline incapable of disagreement was the correct ordering; this review does not independently authorize or grade that plan artifact.
This is scaffold admission, not authorization for Plan A, Plan B, either plan hash, either apply, the FCI-1 wet execution, undrafting, or merge. Those retain their separate gates and receipts.
Dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
Any push changes the subject identity and invalidates this approval.
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — scaffold temporary-introduction decision only, bound to exact head cbd623577557ff8dffe8bf519e6f57290038cfbc, tree c9cef46d9abcc4fa1283f7be866449c4c4439ed8.
Exact derived new-obligation set: one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. Its bytes are identical to the previously approved head 89d61714ada92d3d013ff5ecb7110013636b8d6e; the PR diff contains no other SCAFFOLD declaration. The dissolution condition remains unchanged: modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
Approval basis is unchanged: modeled lifecycle actuation sufficient to sequence this wet gate from .dag does not yet exist. The carrier remains narrowly bounded to exact-binary evidence calibration first; fixed host/EUID and prestate assertions; named-file framed transport through the merged evidence driver; fixed systemd submitter units; canonical reservation/release and positive allocation-store restoration; the submitter-owned-root falsifier; and persistent-cell comparison. It exposes no arbitrary Work command and does not re-ingest diagnostic rendering as data.
The integration after #9780 removed the allocation-store prerequisite implementation from this PR rather than retaining a second authority: the current PR has 10 changed files and the one-file scaffold population remains unchanged. All five exact-head checks are SUCCESS.
This is scaffold admission, not authorization for Plan A hash 9f35b486b4dddb8a, Plan B, either apply, the FCI-1 wet execution, undrafting, or merge. Those retain their separate gates and receipts.
Any push changes the subject identity and invalidates this approval.
briansrls
left a comment
There was a problem hiding this comment.
PARTIAL APPLY AUTHORIZATION — bound to exact PR head cbd623577557ff8dffe8bf519e6f57290038cfbc, tree c9cef46d9abcc4fa1283f7be866449c4c4439ed8, and the exact self-built binary whose provenance the gate manager verified against that subject.
AUTHORIZED ONCE: Plan A only, on srv3:
- plan bundle hash
9f35b486b4dddb8a - scope
fabric-execution-cells-only - member-set / observed-baseline
2c339d71b9c5bd10 prior_generation=3plan_generation=4
Immediately before dispatch, refuse unless the downloaded/local artifact recomputes to that exact bundle hash; every coordinate above matches; the executable is the verified exact-head binary; the generation store still reads 3; and production apply re-observation admits the artifact without host, scope, member-set, baseline, or observation drift. The authorization covers exactly the nine plan-scoped fabric-cell operations fixed by the bundle (three owned-directory ensures, five slice property ensures, and one slice start) plus the production apply envelope’s separately modeled shared ensure of /var/lib/gunbc/fleet-converge before the host-global flock. The installed sudoers projection at this head carries all of those exact argv values. No other plan-scoped operation is authorized.
After Plan A, independently read back the exact three-member cell substrate, UID/GID standing, slice properties, slice active standing, allocation namespace non-mutation, and generation-store value 4; do not rely on apply stdout as the receipt.
NOT AUTHORIZED: Plan B hash fc62dfb9cd4df863 in the requested A→B sequence. Both artifacts were minted against prior_generation=3, but the fence is not scope-specific. All fleet-converge scopes share /var/lib/gunbc/fleet-converge/plan_generation and /var/lib/gunbc/fleet-converge/plan_generation.lock. A successful Plan A runs its apply.sh and then commits generation 4 under that lock. Plan B still expects 3, so its locked guard must report LeaseGenerationStale before running Plan B’s two plan-scoped directory operations. Attempting the stale artifact is therefore not an authorized second apply.
Required continuation: complete and positively verify Plan A, then regenerate Plan B from the same exact approved binary/head. With no allocation-store drift, its scope and member-set/baseline should remain fabric-allocation-store-only / 44913a7a7a0f78d0, its action population should remain exactly the ordered namespace and leaf 0700 root:root ensures, but it must carry prior_generation=4, plan_generation=5, and a new bundle hash. Bring that exact new hash for authorization.
This does not authorize the FCI-1 wet run, #9693 undrafting, or merge. Any PR head movement invalidates this authorization.
briansrls
left a comment
There was a problem hiding this comment.
MODELED-ROUTE APPLY AUTHORIZATION — one-shot, bound to exact PR head cbd623577557ff8dffe8bf519e6f57290038cfbc, tree c9cef46d9abcc4fa1283f7be866449c4c4439ed8.
This supersedes the Plan A authorization in review 5062719965. That earlier authorization named an SSH-produced artifact outside the production artifact-consumption route and may not be used.
AUTHORIZED ONCE: dispatch .github/workflows/fleet-converge.yml on ref session/smart-wren-406 with exactly:
host=srv3mode=applyplan_artifact_hash=9f35b486b4dddb8aplan_workflow_run_id=33353552969
The authorized producer is successful workflow-dispatch run 33353552969 at this exact head. Its unique fleet-converge-plan artifact is artifact ID 9744507892, archive digest sha256:00aeaa41191eb6f52882630e29aae3c992dded6c139441fcd100115485ce9ea3. I independently unpacked it and verified the complete expected artifact population and these coordinates:
- subject host
srv3 - scope
fabric-execution-cells-only - member-set and observed-baseline
2c339d71b9c5bd10 prior_generation=3plan_generation=4- empty Spark typed-actions wire
- bundle token
9f35b486b4dddb8a - exactly nine plan-scoped operations: five
systemctl set-property, one slice start, and the three ordered cell-directory ensures
The modeled route must remain the route. The apply workflow must build and verify binaries from its own exact head_sha, download artifact name fleet-converge-plan from run 33353552969, compare the supplied token with the artifact token, and then let fleet_converge_apply_wet re-observe host/scope/member-set/baseline, recompute the bundle, and enforce generation under the host-global flock. No copying binaries, changing checkout traversal, changing principal, or invoking the entry directly outside that workflow is authorized.
PRE-DISPATCH / EARLY-RUN REFUSALS:
- the branch ref or the newly created apply run's
head_shais not exactlycbd623577557ff8dffe8bf519e6f57290038cfbc; - artifact
9744507892is absent, expired, renamed, duplicated in that run, or its archive digest differs; - the installed srv3 sudoers artifact is not the independently read-back 96-line projection at
430ae6d42ed7d715ef430818e0500fd6efb1da18ce7d8fab799ed2439b5bf5c0; - the generation store does not read exactly
3; /opt/fabric-cellsor/var/lib/gunbc/fabricis no longer absent before production re-observation;- any artifact coordinate or realized argv differs from the population above.
The authorization covers those nine plan-scoped operations plus the production apply envelope's separately modeled shared ensure of /var/lib/gunbc/fleet-converge as ghrunner:ghrunner mode 0755 before the host-global flock. No other plan-scoped effect is authorized.
INDEPENDENT POSTCHECK REQUIRED: generation store exactly 4; exact admitted three-member cell substrate; /opt/fabric-cells and /opt/fabric-cells/srv3-06 root:root; attempts root ghrunner:ghrunner; all five slice properties exactly 17179869184 / 16106127360 / 34359738368 / 16384 / 100; slice active; no Work process started; /var/lib/gunbc/fabric still absent; no Plan B effect. Apply stdout alone is not the receipt.
This does not authorize Plan B, the FCI-1 wet run, #9693 undrafting, or merge. Any PR head movement invalidates this authorization.
briansrls
left a comment
There was a problem hiding this comment.
PLAN B MODELED-ROUTE APPLY AUTHORIZATION — one-shot, bound to exact PR head cbd623577557ff8dffe8bf519e6f57290038cfbc, tree c9cef46d9abcc4fa1283f7be866449c4c4439ed8.
Plan A is accepted as completed on the modeled route: workflow-dispatch run 33358561348, attempt 1, at this exact head concluded SUCCESS; its artifact-download and Fleet converge apply (CAS + generated apply.sh) steps both succeeded. The gate manager's independent postcheck is the standing receipt, not apply stdout.
AUTHORIZED ONCE: dispatch .github/workflows/fleet-converge.yml on ref session/smart-wren-406 with exactly:
host=srv3mode=applyplan_artifact_hash=a0d32cf0e8cba914plan_workflow_run_id=33359140412
The authorized producer is successful workflow-dispatch run 33359140412 at the exact head above. Its unique, unexpired fleet-converge-plan artifact is ID 9746239099, size 2349 bytes, archive digest sha256:7a2557d73abc7e1ec26becb5925707ebb28c765a792ae50d46a6b2d0c1068ff0.
I independently unpacked the archive and verified the complete ten-file artifact population and these coordinates:
- subject host
srv3 - scope
fabric-allocation-store-only - member-set and observed-baseline
44913a7a7a0f78d0 prior_generation=4plan_generation=5- empty Spark typed-actions wire
- bundle token
a0d32cf0e8cba914 - prestate:
/var/lib/gunbc/fabricpositively absent under listed/var/lib/gunbc, with the allocation leaf absent because its namespace is absent - exactly two ordered plan-scoped operations: ensure
/var/lib/gunbc/fabric, then/var/lib/gunbc/fabric/allocation, bothroot:rootmode0700
The modeled route must remain the route. The apply workflow must build and verify binaries from its own exact head_sha, download artifact name fleet-converge-plan from run 33359140412, compare the supplied token with the artifact token, and then let fleet_converge_apply_wet re-observe host/scope/member-set/baseline, recompute the complete bundle, and enforce generation under the host-global flock. No direct entry invocation, copied binary, alternate checkout, changed principal, substituted artifact, or retry is authorized.
PRE-DISPATCH / EARLY-RUN REFUSALS:
- the branch ref or the newly created apply run's
head_shais not exactlycbd623577557ff8dffe8bf519e6f57290038cfbc; - artifact
9746239099is absent, expired, renamed, duplicated in run33359140412, differs in archive digest, or any internal coordinate/action differs from the population above; - installed srv3 sudoers is not the independently read-back 96-line projection at SHA-256
430ae6d42ed7d715ef430818e0500fd6efb1da18ce7d8fab799ed2439b5bf5c0, including the exact ordered namespace and leaf grants; - the generation store does not read exactly
4; /var/lib/gunbc/fabricis no longer positively absent;- production apply re-observation reports any host, scope, member-set, baseline, observation, bundle, or generation disagreement.
The authorization covers exactly the two plan-scoped directory ensures above, plus the production apply envelope's separately modeled idempotent ensure of /var/lib/gunbc/fleet-converge as ghrunner:ghrunner mode 0755, the host-global lock, and the generation-store commit to 5. No cell, runner, Work, reservation, or other plan-scoped effect is authorized.
INDEPENDENT POSTCHECK REQUIRED:
- generation store exactly
5; /var/lib/gunbc/fabricand/var/lib/gunbc/fabric/allocationboth directories atroot:root 0700;- allocation leaf has no unexpected members before the FCI-1 wet run;
- the complete Plan A cell substrate remains unchanged: exact path ownership/modes, slice active standing, and all five resource properties;
- positive no-Work evidence remains: zero cgroup process population and kernel
pids.current=0(or a stronger independent equivalent), with no attempt member or child execution cgroup introduced; - no runner-unit population change and no unrelated host effect.
Apply stdout alone is not the receipt. Any failure spends this one-shot authorization; stop and bring the refusal plus independently observed host state rather than retrying.
This does not authorize the FCI-1 wet run, #9693 undrafting, or merge. Any PR head movement invalidates this authorization.
briansrls
left a comment
There was a problem hiding this comment.
WET RUN NOT AUTHORIZED — exact-head blocker found at cbd623577557ff8dffe8bf519e6f57290038cfbc, tree c9cef46d9abcc4fa1283f7be866449c4c4439ed8.
Plan B itself is accepted as completed on the modeled route: workflow-dispatch run 33362408308, attempt 1, at this exact head concluded SUCCESS; artifact download and fleet-converge apply both succeeded. The gate manager's independent host readback is the standing substrate receipt.
The wet instrument cannot reach its first canonical reservation from that reported state. Plan B correctly left /var/lib/gunbc/fabric/allocation as an empty directory. observe_cas_slot_state therefore reports CasReadableAbsent for slot srv3-06; fci1_allocation_prestate maps that to AllocationStoreAbsent; and fci1_assert_allocation_available explicitly returns ExitFailure("FCI-1 allocation store substrate is absent"). The shell calls that assertion before setting canonical_reservation_may_be_held=1 or starting either submitter. Running the current scaffold would deterministically refuse before the wet transaction and would establish no FCI-1 receipt.
This is a state-space conflation: Plan B established the store directory substrate, while the FCI-1 function interprets an absent slot as an absent store substrate. Do not seed a Free slot out of band to preserve this head or its scaffold approval; that would be an unmodeled durable control-plane mutation.
Accepting AllocationStoreAbsent in only fci1_assert_allocation_available is not sufficient. fci1_allocation_restoration also refuses every absent prestate, so both the success path and cleanup path would still fail after the first legitimate reservation/release. The restoration predicate additionally accepts any post > pre, which does not prove the exact lifecycle and would admit an unexpected extra generation.
A second standing blocker remains on this exact script: the reservation-generation-changed falsifier still calls fci1_assert_replace_held against the canonical allocation root. The prior wet-transaction ruling required this destructive mutation under a run-unique disposable control store, leaving the canonical positive path as reserve → independent observation → release.
Required repair shape:
- Separate directory-substrate standing from slot prestate.
SlotAbsentandSlotFree{generation,...}are both available canonical prestates; held, unreadable and undecodable refuse. - Move the generation-change falsifier to a disposable run-unique store using the same production CAS mechanism.
- Make canonical restoration exact, not merely monotone: with the falsifier removed from the canonical root,
SlotAbsent → Held(1) → Free(2)andSlotFree(N) → Held(N+1) → Free(N+2). Any other generation, path, state, or release outcome refuses. Cleanup must consume the same exact fold. - Correct the postcheck language: a successful append-only CAS lifecycle cannot restore the allocation leaf to byte-empty. It must end semantically Free with durable generation history. Requiring an empty directory after success would contradict the store's no-delete construction.
- Add discriminating controls for absent-slot admission, exact absent→free and free→free transitions, unexpected extra generation, and the disposable generation mutation.
Any repair push invalidates scaffold review 5062636554; request a new exact-head scaffold approval after this closure is frozen.
No root execution of tools/fabric_ci_fci1_live_instrument.sh, no wet reservation effect, no undrafting, and no merge is authorized on this head.
|
Request: new exact-head scaffold approval — repair closure is frozen at head Per the operator's CHANGES_REQUESTED review (2026-08-31 06:42Z, on prior head State on this head: all 5 checks green (required-witnesses-build/floor, rust-unit-tests, fabric-evidence, witnesses), mergeable CLEAN, PR remains draft. No root execution, no wet reservation, no canonical allocation mutation, no manual slot seed, no undraft, no merge has occurred — smart-wren-406 is holding this head pending your exact-head scaffold approval. — gate manager (warm-seal-35) |
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — scaffold temporary-introduction decision only, bound to exact head 647314cf02bff663cc595f386c1fe3b0ecf6b4f9, tree b91fbb7843ce8015dabeb9885f65091036c2e790.
Exact derived new-obligation set: one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. Its bytes changed from the prior approved population as part of repair commit 8a48900a7f6db46ff882576574a25bbb5ead4a23, but the obligation population did not expand and the dissolution condition remains modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
Approval basis: modeled lifecycle actuation sufficient to sequence this wet gate from .dag still does not exist. The repaired carrier remains narrowly bounded to fixed FCI-1 entries: exact-tree binary calibration first; fixed host/EUID and substrate/prestate assertions; framed named-file transport; fixed transient submitter units with systemd-run status consumed; canonical reserve/observe/release sequencing through the production entries; the generation-change mutation on a run-unique disposable store; the exact SlotAbsent/SlotFree restoration fold on both ordinary and cleanup paths; and explicit RuntimeDirectory/unit terminal observations. It exposes no arbitrary Work command and does not construct the semantic reservation or restoration verdict in shell.
This review does not authorize root execution of the instrument, the FCI-1 wet reservation, undrafting, or merge. Wet authorization remains a separate ruling and still requires executed failure-closure evidence that every path leaves the canonical store in the exact expected Free generation with no residue, while every inability to observe refuses rather than passes. In particular, later no-unit-residue evidence must report the observed unit state; mere helper success is not a substitute for showing collection/removal.
Identity note: 647314cf02bff663cc595f386c1fe3b0ecf6b4f9 directly merges fa2d403dc8e08c6841b6521ae5209e1522449b95. During this review, main advanced to 9c34ed7a3b8b19226d35c992a3c37ec621530b34. That does not change this exact scaffold subject, but this approval establishes no current-main parity, integration carry, or merge readiness.
Any push changes the scaffold subject and invalidates this approval.
|
Request: replacement exact-head scaffold approval — strengthening pass frozen at head The single strengthening commit addresses both load-bearing static concerns from ruling 2:
State on this head: all 5 checks green (witnesses, required-witnesses-floor, required-witnesses-build, rust-unit-tests, fabric-evidence), mergeable CLEAN, PR remains draft. Exact-head binary provenance — gate manager (warm-seal-35) |
briansrls
left a comment
There was a problem hiding this comment.
APPROVED — replacement scaffold temporary-introduction decision only, bound to exact head ead1fa42c5e4d3cfe9586fdfb2566467afafcb60, tree d8db46d3c16f8d665167c2b6a6c1d331cfb97516.
Prior scaffold approval 5066157275, bound to 647314cf02bff663cc595f386c1fe3b0ecf6b4f9, was correctly spent by this push and supplies no carry.
The exact derived new-obligation population remains one independently removable scaffold unit, tools/fabric_ci_fci1_live_instrument.sh. The parent delta is the single commit ead1fa42c5e4d3cfe9586fdfb2566467afafcb60; it changes that scaffold plus the production control entry and its enrolled witness, and introduces no second scaffold authority. The dissolution condition remains modeled lifecycle actuation sufficient to sequence a wet gate from .dag.
The strengthening closes the two static scaffold concerns named in the preceding ruling:
AllocationSlotUnreadablenow has an authorable, effect-free discriminator:fci1_assert_unreadable_slot_refused, paired with the enrolledwitness_fci1_unreadable_slot_is_never_available, and invoked before host preconditions or reservation effects. An unreadable slot cannot satisfy availability.unit_terminal_observednow admits only rawLoadState=not-foundwithActiveState=inactive|failed; a loaded terminal unit refuses. Successful observations emit the unit name and both raw states. The dependent RuntimeDirectory check rejects both an existing path and a symlink and emits the raw absent standing after the dependent capture and again from cleanup.
All five checks on this exact head are SUCCESS: required-witnesses-build, required-witnesses-floor, rust-unit-tests, fabric-evidence, and witnesses. The PR is open, mergeable, and still draft.
This approval authorizes only temporary inclusion of the named scaffold at this exact subject. It does not authorize root execution of the instrument, the FCI-1 wet reservation, any failure injection, undrafting, or merge. Wet authorization still requires the subsequent same-head packet to demonstrate every injected failure reaching the exact canonical semantically-Free generation with no residue, raw unit not-found, RuntimeDirectory absence, unchanged cell substrate, no Work start, and every unobservable condition refusing.
Current main is not integrated into this head, so this review makes no current-main-parity or merge-readiness claim. Any push, merge, amend, or other head movement invalidates this approval.
|
Pre-build ruling on the wet-packet strengthening proposal (relayed by gate manager warm-seal-35 from the ruling thread): Pre-build ruling: APPROVED WITH ONE LOAD-BEARING AMENDMENTThe lane’s refusal is correct. At the time of this ruling, #9693 remains frozen at full head The current scaffold cannot honestly produce the wet packet I required:
So: approve one further strengthening commit covering (a), (b), and (c). Do not relabel the current green assertions as raw evidence. One objection to proposal (c)The checkpoints may exit through the The current booleans: are insufficient once failure can occur at more than one lifecycle phase. Two concrete failures show why:
Therefore the strengthening must replace boolean-directed cleanup with an observation-directed, typed cleanup disposition. For the canonical store, cleanup must freshly observe and choose exactly one arm: The shell flags may remain as conservative hints about whether observation is needed, but they cannot decide whether release is executed. The same correction applies to the disposable generation store. It may be deleted only after a fresh observation proves its expected terminal state. Approved checkpoint mechanismA deterministic modeled exit is the right mechanism. I do not prefer signals, transport-file deletion, sleeps, external generation replacement, or manufactured races. Implement the checkpoints as a closed modeled vocabulary, such as a Unknown, empty, duplicate, or phase-inapplicable checkpoint values must refuse before effects. Do not accept line numbers, arbitrary commands, arbitrary paths, or a free-form “fail here” string. Each injected run must be externally classified by: A generic nonzero exit is not a passing mutation. Minimum checkpoint equivalence classesYou do not need a checkpoint after every source line. You do need coverage of every materially different cleanup state:
For the disposable generation falsifier, preserve enough phases to establish: An injected exit while disposable generation The RuntimeDirectory falsifier remains the right opposite control. Its terminal packet must show the held sample existed while the submitter lived, followed by: Raw receipt requirements“Raw” here should mean uncollapsed coordinates from a typed live observation, not unparsed command stdout. AllocationMint each observation once, then use two projections of that same value:
Do not independently reconstruct the printed line in shell. Preserve, at minimum: The final receipt must expose the exact: values—not merely CellPreserve before and after coordinates at member grain, not just the current aggregate hashes: The equality fold and the displayed receipt must derive from the same sealed before/after observations. Receipt lifetimeSplit ephemeral transport from retained evidence: The bundle should identify the full head, tree, exact binary provenance, checkpoint/scenario, original exit status, cleanup verdict, and digests of its receipt files. A failure to create or preserve a required receipt is an explicit refusal, never an omitted line. Zero-Work observationThe proposed population is approved, with these subject rules:
The repository already has declared cgroup-v2 operations that distinguish directory standing, child enumeration, and interface-file reads. Reuse that modeled boundary rather than introducing ad hoc shell The standing non-interference obligation for the 20 actions-runner units also remains. It may be supplied as an independent gate-manager pre/post observation rather than made part of this scaffold, but it cannot disappear from the wet packet. Authorization stateA push implementing this design intentionally spends review Relay note: this governs the next strengthening commit on |
|
Request: final exact-head scaffold approval — the ruled strengthening design is implemented and frozen at head Two commits since the approved
State on this head: all 5 checks green, mergeable CLEAN, still draft; required witnesses lane 3235/3235 FloorClean. No root execution, wet reservation, checkpoint injection, undraft, merge, or main integration has occurred. The 20-actions-runner non-interference observation remains outside the scaffold as the gate manager's independent pre/post evidence, per the ruling. — gate manager (warm-seal-35) |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES — final scaffold approval withheld at exact head 1a8f67130e66df5e0cba364d7481139762deada2, tree 3fb47ff0354eab8d8552c01ae417cf19f84a959c.
The major structural direction is accepted: the checkpoint vocabulary is closed and validated before the cleanup trap/effects; checkpoint exits use reserved status 86; cleanup is observation-directed rather than boolean-directed; a disposable store is removed only after its cleanup observer succeeds; and terminal zero-Work is now a live observation. All five exact-head checks are green. Those facts do not close the following failure/receipt gaps.
-
A real post-commit observation refusal can still leave the canonical slot held.
fci1_live_reserve_and_observe_availablecommits first and only then builds the fullRequiredBuildCellLifetimeSample. If the cell observation refuses after the CAS commit, the submitter returns before publishing the held wire. Cleanup sees the Held slot, butfci1_synthetic_held_sampledepends on the same full cell observation; if it remains unobservable, cleanup returnsCanonicalCleanupRefusedwithout releasing. The same coupling exists for a disposable Held(1)/Held(2). That satisfies “cannot observe refuses” but violates the equally mandatory “every failure path restores and leaves no residue.” Repair this with a reservation-only typed cleanup observation/receipt, independent of the cell-substrate join, that verifies the exact slot, holder reservation/payload/content and generation before releasing once. Alternatively, durably publish that cleanup authority immediately after commit and before the fallible full-cell observation. Add a discriminator for the commit-succeeded/full-observation-refused path. -
Several checkpoint runs still lose the raw evidence they are intended to prove. Cleanup never writes a cell before/after receipt. Therefore
before-canonical-commit,after-canonical-commit-before-transport,after-held-preserved,after-release-before-grading, andruntime-directory-terminalcan finish cleanup whilecell_beforeremains only inFABRIC_CI_VALUE_ROOT, which cleanup deletes. In addition:after-release-before-gradingretains no held sample:CanonicalAlreadyExactFreehas pre/post/restoration but not the held payload/content, whilepositive_beforeis deleted.- the generation falsifier retains no exact
ReservationGenerationChanged(expected=1, observed=2)receipt or Held(1)→Held(2) coordinates;fci1_assert_generation_changedis only a greenProcessExit, and the Free(3) path can end with only the terminal Free observation; - the RuntimeDirectory falsifier retains no typed lifetime-dependent receipt or its held sample;
dependent_beforeis deleted after a green assertion.
Each checkpoint must preserve its own complete retained evidence before scratch deletion. A green assertion is not a raw observation. Cleanup must write the same sealed cell before/after coordinates for every effect-reachable checkpoint, and the canonical/disposable/lifetime receipts must retain the exact held samples and typed expected/observed verdicts.
-
Cell “cannot observe” states are still comparable as if they were observations.
fci1_live_cell_observationserializesFabricCellObservationDeniedandFabricCellObservationNotApplicableinto ordinary strings, andfci1_path_owner_wireserializesPathOwnerUnobservedlikewise.fci1_grade_and_write_cell_receiptthen accepts byte equality. Two equal denials—or two equal owner-read failures—can therefore pass as an unchanged cell. Replace the string-only acquisition with a closed admitted/refused result: denied, not-applicable, or any owner/group read failure must make both the before acquisition and after grade refuse, never enter the comparable admitted carrier. While repairing this receipt, expose the five live boundary-property values as well as the derived boundary digest; the current member state digest/hash is not the requested raw property population. -
The zero-Work service census is active-only.
fci1_zero_work_observationreacheshost_converge_slice1_enumerate_units, which wrapssystemctl_list_units_active_services. An inactive or failedfabric-cell@*.serviceis omitted and can yieldsupervisor_units=[]. This repository already distinguishes that blind reader fromsystemctl_list_units_all_states; use the all-state population for the zero-service claim, with an unreadable enumeration refusing. -
The exact terminal subject and the retained-bundle contract remain under-specified.
fci1_allocation_prestateerasesCellFree.released_by, so canonical/disposable cleanup can admit a Free value at the expected generation without proving it is the Free payload for this reservation. Carry and compare the release identity/content in the terminal observation. Also make the bundle self-identifying and complete: retain an actualCheckpointReachedreceipt, the unit/RuntimeDirectory observations, emit the exact receipt-root plus finalized manifest digest, and enforce a checkpoint-specific required file roster. The current manifest hashes whatever files happen to exist, so a bundle missing the receipts above can still recordcleanup_verdict=0.
The checkpoint injection mechanism itself is acceptable; no signal/race-based replacement is requested. This review is the controlling exact-head scaffold ruling. No root execution, wet reservation, checkpoint run, undraft, or merge is authorized on this head. Any repair push spends this subject and requires a new full-head/tree scaffold ruling.
6fe1f2a to
5105d66
Compare
|
Request: exact-head scaffold ruling — first fully-green frozen head since review 5068553241: head Content since the refused State: all 5 checks green on this exact head, mergeable, still draft; full-corpus parse sweep clean (4453 files). No root execution, wet reservation, checkpoint injection, undraft, merge, or main divergence at any point. smart-wren-406 holds this head frozen pending the ruling; per the standing protocol, wet authorization would be a separate subsequent ruling on this same head and its implemented checkpoint matrix. — gate manager (warm-seal-35) |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES — exact-head scaffold approval withheld
Subject:
head 719b0350bd1525dbf4ebaa9f3016e7cd828040ca
tree 2695d186d79e8fce2c06221ea070fa1f0fff211e
The five checks are green and several parts of review 5068553241 did move in the required direction: cleanup now has a reservation-only carrier, the generation and lifetime falsifiers write typed receipts, cell denial and outer owner-read failure take refusal arms, the service census includes inactive/failed units, and the slot observer retains Free release identity/payload/content. The scaffold is still not safe to execute. Five blocking findings remain.
1. The disposable cleanup authority is stale after Held(1) -> Held(2), so even the ordinary positive run cannot finish
generation_authority_path is written only by the first fci1_live_reserve_and_observe_available, so it names the generation-1 holding. fci1_assert_replace_held then commits generation 2 and accepts no authority path, so the stored authority is never advanced.
Cleanup requires exact authority/holding generation equality, while exact-Free admission requires post_generation == authority_generation + 1. The consequences are deterministic:
generation-held-twoandgeneration-changed-observedenter cleanup with Held(2) against authority(1), so cleanup refuses and leaves the disposable root;- the ordinary path and
generation-free-before-removalrelease Held(2) to Free(3), then grade Free(3) against authority(1), which can admit only Free(2).
Thus the no-checkpoint run itself reaches generation-terminal and refuses, and its trap repeats the same refusal. This is not a missing wet receipt; it is a source-level impossible green.
The replacement transition needs its own exact generation-2 cleanup authority, made available before or atomically with the replacement commit, and the matrix needs a discriminator that executes Held(2) -> Free(3) through that authority.
2. Publishing cleanup authority after commit leaves a modeled residue edge
fci1_live_reserve_and_observe_available first receives CellReserved and only then performs Filesystem.Write(cleanup_path, authority). ReservationCleanupAuthorityWriteRefused therefore occurs after the durable holding exists. On that branch the trap cannot decode an authority; canonical and disposable cleanup refuse without releasing.
This moves the old gap one instruction earlier: full-cell observation refusal is recoverable only if the post-commit authority write succeeded. It does not close write failure, process loss, or any interruption between commit and publication.
Pre-materialize the exact expected authority before the CAS commit, or make authority publication part of the same atomic effect. A failed authority publication must imply no commit occurred. Add the opposite control for commit eligibility with authority publication refused.
3. Manifest finalization manufactures missing evidence instead of refusing it
There is one fixed required_receipts roster for every checkpoint. For every absent member, cleanup writes a shell-authored ReceiptCoordinateNotReached|... file without setting cleanup_status, and then compares the population after those placeholders have filled it.
That is neither checkpoint-exact nor missing-member refusal. A required producer that exits zero but emits no receipt is silently converted into a complete manifest. It also means the ordinary path intentionally carries placeholders for phase-inapplicable files, but no typed relation says which absences are legal for which checkpoint.
Derive an exact required/allowed population from the selected checkpoint. A missing required real receipt must refuse finalization. A not-reached coordinate may exist only as a typed checkpoint-specific disposition, not as a universal shell fallback capable of replacing any evidence file.
4. The cell carrier still does not seal one observation
fci1_cell_receipt_observation acquires an admitted fabric probe, then reads the three owner/group coordinates and the raw boundary values. But its admitted wire is built by fci1_cell_observation_wire(decision), and that renderer performs three additional live owner/group reads through fci1_path_owner_wire.
Therefore an outer owner read can succeed, a second owner read can fail, and the carrier still returns Fci1CellReceiptAdmitted with owner_group_unobserved=... embedded as comparable text. The boundary has the same subject split: the member digest comes from the probe's boundary acquisition, while the five raw properties are read again afterward. fci1_live_cell_observation then transports only wire, discarding the raw baseline fields.
The equality fold and retained before/after coordinates are still not projections of one sealed observation. Acquire probe members, owners, and raw boundary properties once into one admitted/refused value; make every renderer pure; transport the complete baseline value rather than only the string wire.
5. The purported all-state service census still names only three states
systemctl_list_units_all_states binds the exact selector active,inactive,failed, and Systemctl.ListUnits passes that as --state. That closes the earlier inactive/failed blind spot, but it is not a state-complete population: a matching unit in any other runtime state is omitted and may yield supervisor_units=[].
For a zero-population claim, enumerate the complete matching loaded-unit population without a state subset, then judge it. An unreadable enumeration must continue to refuse.
Disposition
exact-head scaffold approval REFUSED
root instrument execution NOT AUTHORIZED
wet reservation NOT AUTHORIZED
checkpoint injection NOT AUTHORIZED
undraft NOT AUTHORIZED
merge NOT AUTHORIZED
Do not execute this head. Any repair push spends this exact review subject and requires another full-head/tree scaffold ruling. Wet authorization remains a later, separate ruling even after scaffold approval.
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES — exact-head scaffold approval withheld
Bound subject:
head 8265651fec850c1e717b42547053148b553d88ae
tree fc28db7814812d6b13ec8c469fc841ddb134cf44
The corrections in the handoff are accepted. The red on 5c0004072... did not establish a carrier defect: one failure was inherited generated drift repaired by composing current main, and the other reproduced on pure main. The measured srv3/session-container/BuildBuddy contrast also supports the intended abstraction: the missing fact is a finite execution entitlement, not machine RAM or architecture. The typed Fci1BoundedExecutionContext, its single property-population projection, live cgroup/manager agreement, one-axis cwd/budget controls, and exact normal-exit-86 live row are all the right direction.
Twenty-one enrolled and executed witnesses are materially stronger than zero. They do not yet supply scaffold approval, because two answerability gaps remain at the exact boundary this pass is intended to close.
1. The executed bootstrap route is still a second systemd-run authority
extdeps.systemd.systemd_run now owns systemd_run_property_argv, systemd_run_transient_wait_unit_argv, and the RunTransientAndWait operation. But fci1_bounded_execution_context_emit.dag independently emits the complete shell grammar four more times:
systemd-run --quiet --wait --collect --unit=...
--property=WorkingDirectory=...
--property=MemoryMax=...
--property=MemoryHigh=...
-- ...
The committed bootstrap fragment is what the live instrument and bounded controls actually call. They do not consume systemd_run_transient_wait_unit_argv or the modeled operation. Thus a mutation to the purported systemd authority — removing --wait, moving --, dropping a property, or changing lifecycle vocabulary — can leave the executed FCI-1 route byte-identical.
The emit witness does not close that gap. It compares the emitter with another complete literal spelling of the same fragment, including the numerical values and every launcher word. That mirror can red on edits to the emitter, but it cannot red when the generic modeled authority and the executed bootstrap route diverge. This is the same class as the earlier local-fold agreement witness.
Repair this to one route. Either:
- derive the bootstrap launcher/template from the modeled wait-operation/property authority and make the generated artifact a projection of that authority; or
- make one modeled shell-template authority the sole producer consumed by both the generic operation and FCI-1.
Do not retain one typed argv authority plus an independently authored emitted command that happens to agree today. The qualifying witness must join the committed executable artifact to the one authority at token identity; it may not compare two local restatements.
2. Status 0 plus unit collection does not establish normal completion
The new model itself records the relevant limitation: systemd-run --wait has been observed to return 0 for a signal-killed default transient service, while normal nonzero exits may be preserved. That distinction is load-bearing here because the new finite memory ceiling makes OOM/signal termination an in-domain outcome.
The positive parent and submitter rows currently do only:
fci1_run_bounded_...(pure entry)
assert unit LoadState=not-found
They require no inner terminal value produced after the gunbc entry completes. Therefore a signal-killed/OOM-killed service that emerges as systemd-run status 0 can satisfy both observations: shell success and collection. The exact exit 86 -> 86 row proves one normal-exit branch; it does not distinguish normal zero from signal death reported as zero.
Add a run-unique, subject-bound normal-completion receipt written only after the pure entry returns its expected typed result. Require that receipt in both positive routes and make absence, malformed content, wrong unit/run identity, or signal termination refuse. For the wet driver, an outer status 0 must likewise be insufficient without the exact inner evidence identity/terminal receipt. Do not call the outcome Completed merely from the systemd-run process code when the boundary admits that it cannot classify signal death.
3. The owed mutation must mutate the subject authority, not its oracle
After the two repairs, perform the declared red/restore demonstration through the actual no-reservation route. At minimum:
single authority omits finite MemoryMax
-> regenerated executable route changes
-> parent and submitter pure controls refuse HostBudgetUnreadable
byte-identical authority restore + regeneration
-> both controls return to green
Also demonstrate the normal-completion carrier by preventing its publication while preserving unit collection; the positive control must red. A mutation of the witness's expected literal, a mock response, or an unused modeled route does not count.
The receipt must bind the mutation and restore trees, generated-artifact digests, binary digests, exact control route, and zero-effect observations. This is evidence of discrimination for named axes, not a claim that arbitrary witness non-vacuity is universally decidable.
Current disposition
typed bounded-execution-context concept ACCEPTED
finite MemoryMax / MemoryHigh derivation ACCEPTED IN DIRECTION
live manager+cgroup agreement ACCEPTED IN DIRECTION
one-axis cwd/budget matrix ACCEPTED IN DIRECTION
executed launcher has one authority NOT ESTABLISHED
normal completion under bounded execution NOT ESTABLISHED
subject-mutation red/restore STILL REQUIRED
exact-head scaffold approval REFUSED
root bounded controls NOT AUTHORIZED
root FCI-1 execution NOT AUTHORIZED
checkpoint injection NOT AUTHORIZED
host mutation / Plan replay NOT AUTHORIZED
undraft / merge NOT AUTHORIZED
source repair AUTHORIZED
The ownerless 500 ms floor-cost instability and the stale pull-request merge-run subject are separate gate/instrument defects. They are not attributed to FCI-1 source here, but a failed required workflow cannot be used as exact-head green evidence. Bring the replacement full head/tree after the source repair and CI adjudication; no operational authorization carries across the push.
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES — the timing refusal is non-adjudicating, and two previously ordered source boundaries remain open on the current head.
Bound subject:
head 3049061c17d567d7638e591515dc0320aeaa4b61
tree df2cc55d94d63c6afd19e7ba2bf61f9f14148ff2
run 33648868054 — terminal failure
Accepted closures
The newest source repair is real. fci1_assert_replace_held now returns the non-Held prestate refusal before constructing or writing the replacement cleanup-authority path; the missing branch close that initially made the else ineffective is present on this head. The sentinel/dispatch cleanup work and the source mutation that made the enrolled target witness plus its same-axis companions red are useful evidence. Twenty-one enrolled witnesses executed and returned true before the required floor refused.
That mutation establishes that the mutated .dag fact is load-bearing to those witness verdicts. It does not, by itself, establish that the same fact owns the shell words actually executed on srv3.
1. The modeled launcher is still not the executed bootstrap launcher
The generic authority remains systemd_run_transient_wait_unit_argv plus systemd.SystemdRun.RunTransientAndWait. It owns the ordered launcher vocabulary and property/command expansion.
The bootstrap emitter still independently writes complete commands for:
fci1_run_bounded_driver
fci1_run_bounded_submitter
fci1_run_bounded_dependent_submitter
fci1_run_unbounded_memory_control
Each function re-authors systemd-run, --quiet, --wait, --collect, the unit spelling, the property words, --, and command expansion. The wet instrument and controls execute those emitted shell functions, not systemd_run_transient_wait_unit_argv.
Therefore the source mutation can make the .dag witnesses red while the executed bootstrap command remains unchanged, or vice versa. The mutation is discriminating over one subject; it has not yet made that subject the execution authority.
The required repair from review 5091370073 still stands: model one launcher template whose tokens include literal words plus unit/property/command expansion sites, and derive both the service transport and bootstrap Bash from that template. An equivalent single-authority construction is admissible; two complete spellings are not.
The authority mutation demonstration must then show:
remove finite MemoryMax at the one template/property authority
→ regenerate
→ parent and submitter actual command bytes both change
→ actual pure routes refuse HostBudgetUnreadable
restore authority byte-identically
→ regenerate
→ both actual routes complete
A floor-only witness red does not replace that executed red.
2. Collection plus status zero still does not prove normal inner completion
The positive controls still call fci1_run_bounded_driver / fci1_run_bounded_submitter and then require only terminal unit collection. The bounded /bin/bash -c wrapper validates cgroup files and execs gunbc; it writes no run-unique terminal receipt after gunbc returns the expected typed result.
This repository's own systemd boundary already records that exact signal-death status is not reliably preserved by this systemd-run --wait realization. Thus these two worlds remain observationally collapsed:
inner gunbc reaches the expected typed success and exits normally
inner process is signal-killed while systemd-run reports status zero, then unit collects
The ordinary exit 86 -> 86 row proves normal nonzero propagation. It does not distinguish the zero/signal pair.
Require a run-unique completion receipt, bound at least to route, nonce, exact binary/entry identity and expected typed outcome, written only after the inner pure entry returns that outcome. The outer control must require the exact receipt in addition to status and collection. Missing, stale, symlinked, duplicate or wrong-run content refuses. Add the opposite mutation: suppress or corrupt completion publication while allowing the unit to collect, and require both positive routes to red.
3. The 500 ms result is a broken answer, not a green to chase
The six-run measurements support the common-mode diagnosis:
cpu_ms(run, witness)
= shared_run_context(run)
+ witness_marginal(witness)
+ residual
The shared run term dominates the identity term. Precision: six samples do not prove mathematical unboundedness of the distribution. They prove that the repository models and enforces no upper bound on that shared term, which is sufficient to invalidate a fixed per-witness source-correctness threshold.
Do not rerun 33648868054 to hunt a sub-500 sample. A green replay would classify a different realization of the same tree, not answer whether the tree is correct. Do not raise the number, and do not add these fourteen identities to an identity-grained cost-debt roster; the observed defect is at run-context grain.
The source authority is not actually ownerless: v2.workflow.required_floor owns required_floor_claim_cpu_safety_limit_ms and changed_witness_cpu_deadline. The operational session may be archived, but the repair belongs to that authority and its executor realization.
Minimum admissible repair:
- separate semantic witness verdict from execution-safety interruption;
- represent interrupted CPU measurement as right-censored/non-adjudicated, never as a claim failure or a measured duration;
- carry execution-context identity on completed observations too;
- move shared preparation/common-mode cost to a run-level observation, leaving only a justified marginal quantity at witness identity grain;
- until that denominator exists, make the 500 ms performance line observational rather than preemptive for this correctness path, while retaining a separately named, substantially coarser runaway-safety boundary that does not attribute its firing to witness semantics.
The current run remains not adjudicated because execution was interrupted and required timing/provenance receipts were not completed. It cannot support scaffold approval. A source repair and new push are required; a rerun of this event is not.
4. #10021 is not presently a merge predecessor
A separate commit-bound review on #10021 has found that it equates guest-visible Firecracker RAM with outer host-cgroup MemoryMax, omitting VMM/realization overhead, and calls six guest vCPUs the cell's CPU envelope while the cell currently realizes only relative CPUWeight, not an absolute CPU entitlement. Its green pair discriminates exact equality, but exact equality is the wrong law. That PR is blocked pending a host/guest envelope split.
Consequently, do not wait for or perform the current #10021 merge, and do not authorize the srv3 controls on this pre-integration FCI head.
Current disposition
replacement prestate before actuation ACCEPTED
missing branch close ACCEPTED
witness enrollment/execution ACCEPTED
reported source mutation discrimination ACCEPTED at witness subject
single executed launcher authority OPEN
normal inner completion discriminator OPEN
500 ms correctness attribution REFUSED
run 33648868054 NON-ADJUDICATING
#10021 current-head merge NOT AUTHORIZED
srv3 bounded-control argv NOT AUTHORIZED on this head
scaffold approval WITHHELD
wet matrix / checkpoint injection NOT AUTHORIZED
undraft / merge #9693 NOT AUTHORIZED
Controlling sequence
The three source repairs may proceed in parallel:
A. #10021: separate host cell envelope, guest machine envelope, and realization budget
B. required-floor: separate run-context cost, witness marginal cost, and runaway safety
C. #9693: one launcher template + run-unique normal-completion receipts
Then:
merge corrected A and B to main
→ merge then-current main into #9693
→ regenerate only through authority
→ exact-head required CI reaches a complete verdict
→ freeze full head/tree and checkout-local binary
→ request one-shot authorization for exactly:
sudo <absolute-exact-checkout>/tools/fabric_ci_fci1_bounded_execution_controls.sh
→ adjudicate actual parent/submitter positive and negative receipts
→ fresh scaffold ruling
→ separate wet authorization
Current main has already advanced beyond both open subjects. No root command or branch merge is authorized merely to preserve today's composition.
briansrls
left a comment
There was a problem hiding this comment.
AMENDMENT TO REVIEW 5092882385 — the immediate timing predecessor now has a concrete owner, and it is narrower than redesigning the whole 500 ms policy.
#10068 at head a556a51ce98a6a3c1e99820706dbbcd6d7989832 adds the common producer gunbc.self_host_compile_phase_frontier.compile_phase_frontier_standing to the cross-claim pure-share authority. Its changed event subject measured one shared fill serving 22 claims across three modules, moved the relevant consumers from approximately 430–503 / 494–502 ms to 75–107 ms, reached interrupted_before_verdict=0, and completed all required jobs successfully. Review 5092929804 accepts that content while withholding merge authorization for its now-stale main composition.
This changes the FCI-1 predecessor as follows:
immediate source of this head's 501/500 censoring
-> #10068 is the owner and candidate repair
whole 500 ms per-claim policy / run-context attribution defect
-> remains open and is NOT retired by #10068
FCI-1 need not wait for the entire performance-policy redesign if, after #10068 lands and current main is integrated, its new exact-head floor receipt establishes a complete semantic partition with every required FCI witness reaching a verdict, failed=0, and interrupted_before_verdict=0. That run is usable for correctness because no timing arm censored the semantic observation; the 500 ms number itself is not cited as evidence.
This is not permission to rerun the current event, raise the threshold, or accept a lucky sub-500 redraw. #10068 changes the charged work and predicts a large directional drop; it is a new subject, not a replay.
The other blockers in 5092882385 are unchanged:
one launcher-template authority OPEN
run-unique normal-completion receipt OPEN
#10021 current equality-based microVM model BLOCKED
srv3 control execution NOT AUTHORIZED
scaffold approval WITHHELD
#10094's broader zero-walk cross-frame serve may repair other producer families, but is not an FCI-1 predecessor once the exact compile-phase producer repair in #10068 lands.
# Conflicts: # .gitattributes # dag/gunbc/generated_artifact.dag
# Conflicts: # dag/gunbc/generated_artifact.dag
…open-PR writing it
This repository's authorities are single by construction (DESIGN §3), which
makes them contention points: one file is where a concept lives, so every lane
touching that concept edits that file. A lane about to restructure a module
cannot see, from its own branch, that three other branches are already
rewriting it -- the conflict is created at authoring time and discovered at
merge time, by whoever lands second. The displaced cost is the rework the later
lane pays, in full, every time.
gunbc run --source-root dag --source-root src/v2 \
--entry dag/gunbc/instruments/path_writer_set_instrument.dag \
--function writers --arg repo=gunb-ai/gunbc --arg path=<path>
A subject ending in `/` asks about a subtree; anything else names one file, and
the report prints which rule it used.
MEASURED LIVE (2026-09-03, gunb-ai/gunbc, 55 open pull requests, 0 unobserved):
`.github/workflows/witnesses.yml` has four writers -- #10261, #9981, #9725,
#9693 -- each printed with its branch, author, head oid and matched paths;
`dag/gunbc/cross_pr_contradiction.dag` has none, and says so in words.
WHY IT IS NOT A WIDENING OF `gunbc.cross_pr_contradiction`. That instrument
reads the same population to ask whether two branches move one roster IDENTITY
in opposite directions, and states in its own header that a same-direction
overlap index is out of scope for it: 45 of the 53 multi-PR keys its hand run
found were same-direction and would have buried the one row that mattered. That
ruling is correct for a SCAN over the whole corpus, and it is exactly why this
is a QUERY -- the subject is supplied by the asker, so there is no population to
bury a finding in.
RENAME DETECTION IS OFF, AND THAT IS THE ONE NEW EXTDEPS OPERATION.
`diff.renames` defaults to true, so a pure rename prints only the DESTINATION
path -- measured: over `git mv a.txt b.txt`, `git diff --name-only HEAD~1 HEAD`
prints `b.txt` alone while `--no-renames` prints both. The branch renaming or
deleting the contended authority is precisely the writer a lane most needs to
know about, so `extdeps.git.git` gains `DiffNameOnlyNoRenames` beside
`DiffNameOnly` and the scope value travels on the report's own row.
EMPTY IS NOT ABSENT (DESIGN §5). This query's most common true answer is
"nobody", so an instrument rendering "I could not read this pull request" as
"this pull request touches nothing" would produce the answer an asker is most
likely to accept without checking, from an observation never made. An unread
branch, a branch empty by derivation, a branch the forge corroborates as empty,
and a diff that refused are four states with four spellings; the completeness
verdict is bound to the exit status, and the "no open pull request touches X"
sentence is reachable only when the population was fully read.
`PrDiffUnobservedCause` gains a `DiffRefused` arm rather than being forked:
`git.Core.Diff` declares no exit status so the contradiction instrument cannot
produce it, and `DiffNameOnlyNoRenames` can. One vocabulary, one set of
consequences.
RUNG: mitigatable, and the ceiling is REACHED rather than stalled below -- what
is being prevented is two people choosing to edit one file, which is not a
state a compiler can refuse. The instrument reports; it closes, comments,
rebases and merges nothing, and the only forge operation it calls is the
readonly `ListOpenJson`.
EVIDENCE. 13 witnesses in dag/test/claim/path_writer_set_witness_test.dag, all
green, with two planted mutations run as discriminating REDs:
`ExactPath => starts_with` reddens exactly `an_exact_subject_does_not_match_a_
longer_path` and nothing else; `report_is_complete => true` reddens exactly the
four completeness witnesses while every positive control stays green. The 27
`cross_pr_contradiction` witnesses stay green over the added arm.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AinEdiYkU1u4HYnS6DUP78
…currently writing it (#10263) * The writer set for a contended authority: given a path, print who is open-PR writing it This repository's authorities are single by construction (DESIGN §3), which makes them contention points: one file is where a concept lives, so every lane touching that concept edits that file. A lane about to restructure a module cannot see, from its own branch, that three other branches are already rewriting it -- the conflict is created at authoring time and discovered at merge time, by whoever lands second. The displaced cost is the rework the later lane pays, in full, every time. gunbc run --source-root dag --source-root src/v2 \ --entry dag/gunbc/instruments/path_writer_set_instrument.dag \ --function writers --arg repo=gunb-ai/gunbc --arg path=<path> A subject ending in `/` asks about a subtree; anything else names one file, and the report prints which rule it used. MEASURED LIVE (2026-09-03, gunb-ai/gunbc, 55 open pull requests, 0 unobserved): `.github/workflows/witnesses.yml` has four writers -- #10261, #9981, #9725, #9693 -- each printed with its branch, author, head oid and matched paths; `dag/gunbc/cross_pr_contradiction.dag` has none, and says so in words. WHY IT IS NOT A WIDENING OF `gunbc.cross_pr_contradiction`. That instrument reads the same population to ask whether two branches move one roster IDENTITY in opposite directions, and states in its own header that a same-direction overlap index is out of scope for it: 45 of the 53 multi-PR keys its hand run found were same-direction and would have buried the one row that mattered. That ruling is correct for a SCAN over the whole corpus, and it is exactly why this is a QUERY -- the subject is supplied by the asker, so there is no population to bury a finding in. RENAME DETECTION IS OFF, AND THAT IS THE ONE NEW EXTDEPS OPERATION. `diff.renames` defaults to true, so a pure rename prints only the DESTINATION path -- measured: over `git mv a.txt b.txt`, `git diff --name-only HEAD~1 HEAD` prints `b.txt` alone while `--no-renames` prints both. The branch renaming or deleting the contended authority is precisely the writer a lane most needs to know about, so `extdeps.git.git` gains `DiffNameOnlyNoRenames` beside `DiffNameOnly` and the scope value travels on the report's own row. EMPTY IS NOT ABSENT (DESIGN §5). This query's most common true answer is "nobody", so an instrument rendering "I could not read this pull request" as "this pull request touches nothing" would produce the answer an asker is most likely to accept without checking, from an observation never made. An unread branch, a branch empty by derivation, a branch the forge corroborates as empty, and a diff that refused are four states with four spellings; the completeness verdict is bound to the exit status, and the "no open pull request touches X" sentence is reachable only when the population was fully read. `PrDiffUnobservedCause` gains a `DiffRefused` arm rather than being forked: `git.Core.Diff` declares no exit status so the contradiction instrument cannot produce it, and `DiffNameOnlyNoRenames` can. One vocabulary, one set of consequences. RUNG: mitigatable, and the ceiling is REACHED rather than stalled below -- what is being prevented is two people choosing to edit one file, which is not a state a compiler can refuse. The instrument reports; it closes, comments, rebases and merges nothing, and the only forge operation it calls is the readonly `ListOpenJson`. EVIDENCE. 13 witnesses in dag/test/claim/path_writer_set_witness_test.dag, all green, with two planted mutations run as discriminating REDs: `ExactPath => starts_with` reddens exactly `an_exact_subject_does_not_match_a_ longer_path` and nothing else; `report_is_complete => true` reddens exactly the four completeness witnesses while every positive control stays green. The 27 `cross_pr_contradiction` witnesses stay green over the added arm. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AinEdiYkU1u4HYnS6DUP78 * Make the summary row unmiscountable: total_writers / total_unobserved, and the witness that keeps it so THE DEFECT WAS IN THE OUTPUT FORMAT, NOT ONLY IN THE READER. The obvious way to count this report's answer is `grep -c '^writer'`. The summary read `writers<TAB>8` above rows spelled `writer<TAB>#10263...`, so both matched `^writer` and that command returned NINE FOR EIGHT WRITERS -- silently, by counting the header as a datum. `unobserved` carried the identical collision against its own per-pull-request rows. It is not hypothetical. It is how this instrument's own author first misreported its output to a manager, while the tool printed the correct number throughout: the source was right and the reader was the defect, and the format invited it. A header note telling readers to mind the summary row would be a rule, and a rule is not a firing mechanism -- the shape is. So the summary keys become `total_pull_requests` / `total_unobserved` / `total_writers`, chosen until THE NAIVE COMMAND IS CORRECT rather than merely warned about: `grep -c '^writer'` and `grep -c '^unobserved'` now yield exactly the row counts they look like they yield. The miscount is not detected, it is unwritable -- 4b's move from validation to construction, applied to an output format. EVIDENCE. `writer_set_row_keys_do_not_collide_with_summary_keys` asserts the property directly over a report carrying BOTH a writer row and an unobserved row, which is the only shape where the collision is visible. Planted RED: restoring the summary key to `writers` reddens exactly that witness and leaves the other 13 green. 14 witnesses green on the repair. Reported by neat-swift-219 on the message where I gave them the wrong count. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AinEdiYkU1u4HYnS6DUP78 --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
|
Superseded by #10270, which is this branch plus the integration with current main. This branch had gone 71 commits stale and CONFLICTING. #10270 carries the identical FCI-1 work — Please close this one rather than merging it; review effort belongs on #10270. |
|
Closing as SUPERSEDED by #10270, not as abandoned. #10270 is the same FCI-1 work re-derived against current main by zesty-eagle-866. This PR is a draft, DIRTY, and 71 commits stale; merging it would land a stale re-derivation of work that already exists in a clean form. Per the replacement-migration rule the intermediate representation is not worth carrying — #10270 is the root. Nothing here is lost: the semantic content is carried forward in #10270. Review effort should go there. — sent from warm-seal-35 |
…sedes #9693, re-derived against current main) (#10270) * FCI-1: bind exact Work through durable cell reservation * FCI-1: restore reservation availability on every exit * FCI-1: wire fabric-only convergence and observed source * Derive FCI-1 sudoers precondition from projection * Repair FCI-1 allocation lifecycle evidence * Strengthen FCI-1 terminal observations * Strengthen FCI-1 wet failure receipts * Close FCI-1 wet failure paths * Fix FCI-1 cleanup disposition closure * Repair rebased FCI-1 sources * Fix binding sample effect declaration * Close FCI-1 binding sample scope * Handle all reservation refusal outcomes * Complete reservation refusal match * Bind cleanup disposition within refusal fold * Keep cleanup disposition in decoded observation scope * Close FCI-1 reservation cleanup edges * Bind instrument processes to derived checkout root * Accept git worktree roots for cwd binding * Carry typed properties through systemd transient runs * Render typed properties before transient transport * Render systemd-run properties into the executed argv The operation declared a typed property population and its transport template ignored it, so a caller asking for a bounded transient unit got a systemd-run command carrying no property at all: the declaration said bounded, the executed command was unbounded. A later spelling passed the full rendered invocation as the operation's command_argv while the transport still prefixed its own launcher words, composing `systemd-run --unit=U --collect systemd-run --unit=U --collect -- <cmd>`. Both are the same defect -- one operational fact with two independently authored representations -- so the fix gives it one home. systemd_run_property_argv is now the single place a SystemdUnitProperty becomes an argv word; systemd_run_transient_unit_argv composes those words rather than re-deriving them; and the transport owns the launcher words exactly once, splicing property_argv and command_argv as separate list bindings. The typed record deliberately stops at that boundary. push_shell_argv_tokens has arms for Str, List and ProcessArgvExpansion and a refusing arm for ambiguous free monoids, but a record reaches none of them: it lands in the catch-all, which Display-formats the value into one argv word rather than refusing. A record spliced into argv would therefore hand systemd-run a fabricated argument at the exact seam that decides whether a unit is bounded. systemd_run_transient_operation_argv_matches_authority previously rebuilt the launcher list locally, so it could only confirm that two local folds agreed and a property that never reached the executed words was invisible to it. It now compares the materialization against the extdeps authority. Evidence. The existing witness passes an empty population and stays green through exactly this defect, so two controls carry a real one: the materialized argv must equal the authority with a MemoryMax population, and the renderer must produce --property=MemoryMax=17179869184. Verified by execution: required-lane build (regen phase) green on a remote runner with these edits confirmed present -- corpus_load, compile.frontend, normalize, reconcile, analyses, emit, then mirror_write, candidate_verify, adjudicate, hand_verify, digest. That is the corpus-wide parse and name resolution which the prior unthreaded head failed. NOT verified here: the two new witnesses. The witnesses lane cannot execute in any venue available to this session -- its floor phase refuses HostBudgetUnreadable because neither the session container nor the BuildBuddy runner binds a cgroup memory limit, and namespace-wave-admission returns NotEvaluated on a depth-1 clone with no merge base. GitHub-hosted CI is the only venue that satisfies the budget arm, so those controls are enrolled here and judged there. * Compare argv by token identity, not by joined text systemd_run_transient_operation_argv_matches_authority compared join(materialized, " ") == join(authority, " "), which is a question about text where the claim is about tokens. One word carrying a space and the words it would split into collapse to the same string, so ["--property=WorkingDirectory=/path with space"] ["--property=WorkingDirectory=/path", "with", "space"] compared equal. That is blind at exactly the seam that carries paths and property values, and it is the seam the bounded-driver work is about to load. There is no zip or index in the list vocabulary to fold two lists in lockstep, so equality is established the way an encoding establishes it: cardinality must agree, and the words are joined on a separator no word contains, which makes the joined form injective. A word containing the separator REFUSES rather than falling back to the ambiguous comparison -- an unusable encoding is an unanswerable question, not a passing one. Three controls, two of which the prior comparison could not express: a WorkingDirectory value containing a space keeps token identity; ["a b"] and ["a", "b"] must compare unequal while ["a b"] equals itself; and a word carrying the separator refuses, asserting the encoding's own precondition rather than assuming it. The same join-comparison stands in systemctl_stop_operation_argv_matches_authority and hostname_short_read_operation_argv_matches_authority. Same class, same blindness; not repaired here because they are not this branch's subject, and noted so the class is recorded rather than rediscovered. Verified by execution on the merged tree: claim_executor --required-ci --required-lane build, REAL_EXIT=0, planned=150, first_generation_equal=true, generated-artifact rostered=35 adjudicated=35 matches=35 drifted=0, phases_run=2 failed=0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PGkDt1W1m3U28vBpV6BY9Z * Model the bounded FCI-1 execution context * Project the FCI-1 context to systemd * Preserve exact exits from waited transient units * Roster the bounded FCI-1 bootstrap projection * Run FCI-1 under bounded collected transient units * Regenerate gitattributes for bounded context artifact * Use generated ordering for gitattributes projection * Enroll FCI-1 witnesses in required floor * Make systemd property witness predicates total * Close FCI-1 declaration and projection witnesses * Require singleton held account before release * Roster FCI1 cleanup wildcard residues * Make cleanup observation dispatch total * Avoid sentinel classification in cleanup authority * Validate replacement prestate before write * Return prestate refusal before actuation * Close checkpoint branch before replacement * Update artifact roster witness count after main merge * Make FCI1 artifact witness presence exact once * Derive emitted systemd property names from carrier * Derive unbounded control property name * Derive MemoryMax names in FCI1 emit witness * Derive all property names in FCI1 witness * Import filter from algebra in artifact witness * Regenerate witnesses workflow projection * Remove inert FCI1 systemd projection witness * Remove inert FCI1 systemd projection witness * FiniteByteSize goes home to std.measure, and both hand-shell carriers name the capability that retires them Three review findings on 293785a. All three are acted on; one of them is right for a reason other than the one given. FINITEBYTESIZE WAS NOT A RE-MINTED ALIAS, BUT IT WAS IN THE WRONG LAYER. The finding read `type FiniteByteSize = Measure<Memory, One, PositiveMeasureCount>` as re-minting a Measure alias outside std.measure and growing net concepts by re-invention. It does not: every symbol in it -- Measure, Memory, One, PositiveMeasureCount -- is std.measure's, so it CONSUMES the canonical carrier rather than coining a second one, and it is the same Compose-shaped row std.measure already writes five times for ByteSize, Kibibyte, Mebibyte, Gibibyte and Gigabyte. Nor is it a nickname for ByteSize: the two differ in the third parameter, Nat against PositiveMeasureCount, which is exactly one real distinction -- zero is unrepresentable rather than merely rejected -- so a consumer projecting it to a live cgroup bound needs no validator deciding whether a purported limit is a limit. What the finding is right about is the LAYER. DESIGN section 3 puts a fact's home at its layer, not its file, and a positive byte quantity is a general measure fact with nothing fabric-specific in it. std.measure already hosts that exact family: PositiveCelsiusDelta, PositiveSlotCount and PositiveShardCount are all "positive X built over PositiveMeasureCount", with the sibling comments saying so. FiniteByteSize is the Memory-axis member of that family and belongs beside them. So the whole cluster moves -- the type, finite_byte_size, finite_byte_size_count, FiniteByteSizeBuild and finite_byte_size_from_byte_size -- and gunbc.fci1_bounded_execution_context imports it instead. ByteSize and FiniteByteSizeBuild drop out of that module's import list because nothing there names them any more. BOTH HAND-SHELL TRIGGERS NOW NAME A CAPABILITY RATHER THAN AN OUTCOME. fabric_ci_fci1_bounded_execution_controls.sh carried no scaffold marker at all. Its sibling carried one that named only "modeled lifecycle actuation sufficient to sequence a wet gate from .dag", which is the grain mismatch DESIGN section 4b(3) warns about: that condition can be satisfied in full while this transport stays hand-authored, so it would retire a marker without retiring the scaffold. What actually replaces a hand-shell carrier is bash emission for a foreign executor, and gunbc.ci_spec already words that trigger three times for the same class -- ci_release_bins_pack, ci_release_bins_unpack_verify and gunbc_ci_fleet_key_agent. Both carriers now use that wording, so the condition is shared with the rows that already depend on it rather than invented here. EVIDENCE, BY EXECUTION. Three witnesses run on this merged base, each returning true with the full closure resolved through the new home: finite_byte_size_refuses_zero fci1_context_derives_the_runner_workload_envelope fci1_bounded_context_fragment_is_registered_once The third matters most for this diff, because finite_byte_size_count moved out from under the emit module and that witness is what proves the fragment still resolves and registers. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * Regenerate the std_measure seed mirror for the FiniteByteSize move Moving the FiniteByteSize cluster into std.measure desynced that module's emitted Rust mirror. The seed emitter caught it as `FAIL generated surface drift: std_measure.rs` with first_generation_equal=false, and this installs the candidate bytes it had already written. The three witnesses that proved the move are blind to this by construction: they run the .dag authority, and the mirror is a separate emission of the same module. Nothing short of the emitter adjudicating its own surface would have found it, which is what the recipe's second and third steps are for -- the first pass runs a binary that predates the change it emits, so it can report a fixed point for the wrong reason. Only std_measure.rs drifted; every other file in the candidate tree is byte-identical to the installed seed. Rebuilt from the installed seed and re-verified, so the verifying binary is the one that contains the emission rather than the one that predates it: required-regen first_generation_equal=true planned=156 executed=156 adjudicated=156 required-regen declared_divergent=1 [main.rs], candidate identical to installed fixed-point fixed_point_equal=true referenced_at=db4207379b Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * Mark the emit carrier with the trigger that retires it, beside the shell it feeds Advisory from review 59764: expected_fci1_bounded_execution_context_env builds its bash by join([...]) -- the medium-as-string tell -- and the reviewer asked that the pair stay on one trigger so they retire together. They were not on one trigger. The two shell files carried the bash-emit condition and this module, which is the carrier that BUILDS them, carried nothing. So the trigger as it stood would have retired the two files it names and left this join standing, with the emitter still concatenating a medium as a string and no mark anywhere in the module saying it should not. The coverage was real and unreachable: a reader of this module cannot see a marker written into the shell it emits. The annotation now names the same capability the shells name -- bash-emit realizing the runner through orchestration emit or typed host_effect_apply -- so the three retire on one condition, which is DESIGN section 6's mark-on-the-carrier rather than a parallel ledger, and section 4b(3)'s requirement that a trigger name a capability rather than an artifact. It is an annotation, so it is inert by construction (DESIGN section 4c: semantic passes receive the annotation-erased projection). Verified rather than assumed: the emit witness fci1_bounded_context_fragment_is_registered_once still returns true, and re-running the wet gate leaves tools/fabric_ci_fci1_bounded_execution_context.env BYTE-IDENTICAL, with this source file the only thing the regeneration leaves dirty. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * Put the calibration runner on the trigger that actually retires it fabric_ci_evidence_calibration.sh carried "dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag" -- the same trigger its two siblings were repaired away from earlier in this branch, and the same §4b(3) defect: it names less than the capability it restores, so it is satisfied while the capability stays dead. Lifecycle actuation lands, the marker retires, and 84 lines of hand-authored shell transport remain with nothing left to retire them. It now carries the bash-emit condition the other carriers carry, so all four retire together: this file, fabric_ci_fci1_live_instrument.sh, fabric_ci_fci1_bounded_execution_controls.sh, and the gunbc.fci1_bounded_execution_context_emit join that builds the shell. Zero instances of the weak wording remain across the four. This file pre-exists on main and is not a scaffold this branch admits. It is repaired here because this diff already modifies it -- adding the two refusal guards above -- and because leaving the weak trigger standing beside three repaired ones would preserve the defect at exactly the carrier a reader would check next. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * RuntimeDirectory is a modeled systemd property, not a string this emitter spells Review 59932's non-blocking nit: RuntimeDirectory was the one property in fci1_run_bounded_dependent_submitter spelled as a literal while every sibling on the same argv -- WorkingDirectory, MemoryMax, MemoryHigh -- routed through systemd_unit_property_wire. It is worth fixing rather than noting, because it is a second authority for one upstream fact. The wire name of a systemd property belongs to extdeps.systemd, and a literal beside four calls to the authority is DESIGN section 3's nickname in the small: one concept spelled twice, where the copy is invisible to anything that reads the SystemdUnitProperty coproduct. Any lens over that carrier sees four properties on this argv and not the fifth. The reason it was a literal is that the property was not modeled at all -- SystemdUnitProperty had no RuntimeDirectory variant -- so this adds the row where it belongs, beside WorkingDirectoryProperty and wired the same way, and the emitter consumes it. Modeling the extdep first and consuming it second is the order DESIGN asks for; spelling it inline is what a missing row makes tempting. VERIFIED AS A PURE REROUTE. The wet gate re-emits tools/fabric_ci_fci1_bounded_execution_context.env BYTE-IDENTICAL, which is the discriminating check for this change: the argv the shell receives must not move, because nothing about the runtime behaviour is being changed -- only which authority spells one word of it. The only files the regeneration leaves dirty are the two sources. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * Carry the measure through the refusal, and fold the slot prestate once instead of to a Bool Two substrate findings from review 59964. Both hold, and the second is the more serious of the two. THE MEASURE SURVIVES THE DIAGNOSTIC NOW. Fci1MemoryHighExceedsMax carried high_bytes and max_bytes as bare Int. This is NOT the same shape as its two sibling variants, and the difference is what makes it a defect: Fci1MemoryMaxNonPositive and Fci1MemoryHighNonPositive carry `observed: Int` because the conversion FAILED and no FiniteByteSize was ever constructed, so an Int is the only thing there is to report. At the ExceedsMax site BOTH values are valid FiniteByteSize values already in scope, and the code called finite_byte_size_count on each purely to store the scalar -- discarding the carrier exactly where it exists. The variant now carries `high: FiniteByteSize, max: FiniteByteSize`, and the count is extracted in the emit module, which is the external boundary where a String is genuinely required. THE BOOL PREDICATE WAS A SECOND REPRESENTATION OF A DECISION THE MODEL ALREADY CARRIED, AND ITS OWN CALLER PROVED IT. fci1_allocation_slot_available folded a five-variant AllocationSlotPrestate to Bool. Its caller fci1_assert_allocation_available then did `if available { ExitSuccess } else { match prestate { ... five arms ... } }` -- re-matching the prestate to recover the cause the Bool had just thrown away. Two of those arms, AllocationSlotAbsent and AllocationSlotFree, COULD NEVER FIRE, because the predicate had already answered true for exactly those two. Dead arms are the proof that the Bool carried nothing the match did not: the match alone answers the whole question. So the Bool is dissolved rather than wrapped. AllocationSlotAdmission is a typed disposition folded once from the prestate, and its refusal arms carry the observed generation where the prestate has one. Every caller now matches a single time. Nothing references fci1_allocation_slot_available anywhere in the corpus. THIS STRENGTHENED TWO CONTROLS AS A SIDE EFFECT, which is the part worth reading. Under the Bool, a held slot and an unreadable slot were the SAME OBSERVATION -- both merely false -- so fci1_assert_unreadable_slot_refused passed if the slot was refused for any reason whatever, and the witness asserted only `!available`. Both now assert the exact cause, and the witness also asserts the generation the held arm reports. EVIDENCE BY EXECUTION, INCLUDING A DISCRIMINATING RED. Both allocation witnesses return true. The strengthened unreadable witness was then mutated at ONE variable -- input AllocationSlotUnreadable replaced by AllocationSlotFree, nothing else touched -- and returned false, so it is discriminating rather than vacuously green. The emit and context witnesses still return true after the variant change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * A converged cell is three named members, not a list that happens to have length three Finding from review 59993. cell_member_shape_complete asserted four cardinalities as a Bool, and its consumer then read `boundary[0]` on the strength of that Bool. That pair is the one DESIGN section 5 names directly: the check re-states a constraint the model should carry, and it can be satisfied while the realization still lies, because nothing structurally connects the predicate to the index. A malformed population stayed representable right up to the point of use, where the guard was a convention rather than a type. FabricCellShape is a sole_constructor carrying root, attempt_root and boundary as FIELDS, so the consumer reads shape.boundary.state_digest and there is no index that could be out of range. The malformed population is not caught at the boundary; it has no constructor there. The fold underneath it answers the real question. fabric_cell_member_at returns Missing, Exactly or Duplicated rather than a Bool, because zero and two are different failures and a count cannot say which. fabric_cell_shape admits only three Exactly results. NO LENGTH TEST SURVIVES, AND THAT IS DERIVED RATHER THAN DROPPED. FabricCellResourceAddress has exactly three variants, so exactly-one-at-each-of-three already entails a population of three: a fourth member would have to duplicate an address, which FabricCellMemberDuplicated refuses. The old `list_length == 3` conjunct was redundant with the three conjuncts that followed it, and removing it loses nothing the type does not now enforce. Both consumers are rewired -- the reservation observer and fci1_cell_pre_reservation_standing in the live probe -- and boundary_digests, which existed only to produce the list that was indexed, is deleted with its last caller. Neither cell_member_shape_complete nor boundary_digests is referenced anywhere in the corpus. Verified by execution: the allocation lifecycle witness returns true, which compiles the closure across both edited modules. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk * ledger_row_coherence: give Fci1BoundedExecutionContextArtifact its match arm The .env artifact carries no ledger rows, so it classifies as NotALedgerArtifact rather than LedgerRowsAllRendered. Without the arm the exhaustive match over GeneratedArtifact refuses, which is what reddened the floor after the variant landed in gunbc.generated_artifact. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nNrB6jSEPS99LPx8zcvqk --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Brian Searls <briansearls1@gmail.com>
Subject
FCI-1 binds the exact FCI-0 Work to the already-converged
srv3-06fabric cell through the production durable-CAS reservation path. It starts no Work process and introduces no supervisor or passive lease unit.Construction
e9eaa579ed0b6585a48965842b43ee09af5671a1and treec8983a3d8412a5e37a309b2d90ceafc698856619. The commit's tree is independently observed throughgit.Core.CommitTreeInRepo; unreadable, malformed, or mismatched observations refuse before the WorkKey assertion.FabricExecutionCellsConvergerequest through production plan/workflow. The fabric-only plan observes only host, generation, and fabric cells; apply decodes scope before choosing its observer population. The merged allocation-store-only scope remains distinct.FleetConvergePlanArtifactis unchanged, and unrelated actions have no constructor in either narrow request./etc/sudoers.d/gunbc-ghrunneragainst the SHA-256 of the exact-tree generatedprovisioning/srv3/gunbc-ghrunner.sudoersartifact. There is no copied digest literal to become stale when the projection changes./opt/fabric-cells,/opt/fabric-cells/srv3-06, and its attempts directory before reservation. Mode remains explicitlyDirectoryModeUnobserved; this PR does not claim full directory-metadata convergence or structural exclusion of world writability.ProcessExit; transport values are framed and written to unique explicit paths. No diagnostic text is parsed as data.Exact-head evidence
Exact-head evidence is pending; it will be taken on the frozen final head and this section will name that head when it exists.
Evidence on 89d6171, superseded:
fci1_invalid_before_wire_refusesreturnedExitSuccessafter the complete probe closure resolved.witness_fabric_only_plan_render_names_scope_and_fabric_without_unrelated_sectionsreturnedtrue.witness_allocation_store_prestate_drift_refuses_with_typed_locationreturnedtruefor both absence→correct-presence and absence→wrong-mode mutations; the full production CLI closure compiled with 0 blocking diagnostics.The frozen producer remains:
Wet status and prerequisites
Not run. No privileged or durable srv3 effect was performed from this head.
The allocation-store desired-state producer is merged, and the operator has installed and independently read back the exact 95-line srv3 sudoers projection at
6d43b95c943ffceb3a1a4ee7d51d5176772bd6b1d0de52acc9db18cf8ddc3f02. Plan A (fabric cell) and Plan B (allocation store) must still be produced from the final approved head; their hashes and complete action populations require independent approval before either apply. FCI-1 never creates either premise.Rung abstention
This receipt will claim only executed exact-subject evidence. It does not claim source-to-application structural type safety; that guarantee is outside this gate while application-binding inhabitance retains an undecided arm.
Scaffold
tools/fabric_ci_fci1_live_instrument.shis a separate scaffold requiring commit-bound external re-approval on this final head. DISSOLVE-ON: modeled lifecycle actuation sufficient to sequence a wet gate from.dag.