Fix stadium_grant_quota() donor floor; rerun std79 DoE clean, 81/81 (FABRIC-3.md §XVII)
capsule_birth.c hardcoded every new VM's initial Stadium quota grant to split from Hera specifically. Since a grant always halves whatever the donor currently has, Hera's own free list converges toward empty after a bounded number of grants — independent of whether the Stadium as a whole still had spare capacity, since VMs she'd granted to earlier typically still held nearly all of their own share untouched. Past that point every subsequent VM birth's Stadium grant would be silently refused (soft-failed, non-fatal by existing design), even with plenty of capacity sitting idle elsewhere. Fixed by adding an O(1)-maintained free_count to StadiumVMQuota (incremented in stadium_evict(), decremented at both of stadium_admit()'s free-list-pop sites, set/adjusted in stadium_grant_quota()'s own split — this also let grant_quota drop its old O(free-list length) counting walk in favor of an O(1) read) and stadium_best_donor(), an O(live VM count) scan over quota slots returning whichever in-use VM currently has the most free cells. capsule_birth.c's birth path now splits from that VM instead of unconditionally vm_uuid_hera(). Verified with another full rerun of the 3x9x3 std79 DoE campaign from scratch — same discipline as the prior Stadium fix (any defect repair reruns the whole DoE from the top) — one continuous boot per architecture, all 9 identities simultaneously live throughout. 81/81 trials correct, 0 mismatches, DOE-RUN header sequence md5-identical to every prior run. aarch64 ~280s total (vs ~290s for the O(ncells)-scan fix alone — confirms no regression). Both known Stadium defects are now closed together on one clean campaign rerun. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXieurDfDSsDFdnSyusuWo
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
9eff122090
commit
e51a8d229e
@@ -4,10 +4,12 @@ The formal successor to `experiments/std79-exerciser/`'s ad hoc campaign (see FA
|
||||
requested as a genuine randomized full-factorial design matching this project's own DoE
|
||||
methodology (`capsules/doe.4th`'s Fisher-Yates run-matrix shuffle) rather than convenience
|
||||
batching — and written entirely in FORTH, not host-orchestrated shell scripting. See
|
||||
FABRIC-3.md §XV for the design writeup and §XVI for the real aarch64 Stadium/COOL scaling bug
|
||||
that was found, root-caused, and fixed (`src/starkernel/vm/stadium.c`, commit pending) — the
|
||||
3-boot batching workaround below is now historical only; a single boot with all 9 identities
|
||||
simultaneously live works cleanly on all three architectures as of the fix.
|
||||
FABRIC-3.md §XV for the design writeup, §XVI for the real aarch64 Stadium/COOL scaling bug that
|
||||
was found, root-caused, and fixed (`src/starkernel/vm/stadium.c`), and §XVII for a second,
|
||||
related Stadium bug (`stadium_grant_quota()`'s donor-floor) found while writing up §XVI and
|
||||
fixed in a follow-up pass — the 3-boot batching workaround below is now historical only; a
|
||||
single boot with all 9 identities simultaneously live works cleanly on all three architectures
|
||||
as of both fixes.
|
||||
|
||||
`std79-doe.fth` is not a capsule loaded via `EXEC` — feed it as raw text to a running REPL
|
||||
(e.g. `socat - UNIX-CONNECT:<serial_sock> < std79-doe.fth`), same as the original exerciser, then
|
||||
@@ -25,11 +27,16 @@ boots if ever needed for an unrelated reason. Every boot must use the *same* see
|
||||
`{aarch64,riscv64}-doe-batch{1,2,3}-raw.log` (27 trials each, split across 3 boots of 3
|
||||
identities, the then-necessary workaround). **Result: 81/81 trials correct, 0 mismatches.**
|
||||
|
||||
`results-20260911-stadium-fix/` holds the *post-fix* rerun — one boot per architecture, all 9
|
||||
identities simultaneously live in every boot, same seed throughout. **Result: 81/81 trials
|
||||
correct, 0 mismatches, byte-identical output to the original campaign** — and the DOE-RUN
|
||||
header sequence (run_id/id_idx/id_label/rep assignment) is md5-identical across all three raw
|
||||
logs, confirming the master shuffle is genuinely architecture-independent. Total per-architecture
|
||||
wall-clock (boot + all 9 identity attaches + full 27-trial run, one continuous QEMU session):
|
||||
amd64 ~165s, aarch64 ~290s, riscv64 ~161s — aarch64's identity 04 attach alone, which stalled
|
||||
90+ minutes before the fix, now completes in ~34s.
|
||||
`results-20260911-stadium-fix/` holds the rerun after §XVI's O(ncells)-scan fix — one boot per
|
||||
architecture, all 9 identities simultaneously live in every boot, same seed throughout.
|
||||
**Result: 81/81 trials correct, 0 mismatches, byte-identical output to the original campaign** —
|
||||
and the DOE-RUN header sequence (run_id/id_idx/id_label/rep assignment) is md5-identical across
|
||||
all three raw logs, confirming the master shuffle is genuinely architecture-independent. Total
|
||||
per-architecture wall-clock (boot + all 9 identity attaches + full 27-trial run, one continuous
|
||||
QEMU session): amd64 ~165s, aarch64 ~290s, riscv64 ~161s — aarch64's identity 04 attach alone,
|
||||
which stalled 90+ minutes before the fix, now completes in ~34s.
|
||||
|
||||
`results-20260911-donor-floor-fix/` holds a further rerun after §XVII's donor-floor fix (same
|
||||
discipline: any Stadium defect repair reruns the whole DoE from the top). **Result: 81/81
|
||||
trials correct, 0 mismatches**, DOE-RUN header sequence md5-identical to every prior run. Total
|
||||
wall-clock: amd64 ~161s, aarch64 ~280s (confirms no regression from §XVI's fix), riscv64 ~162s.
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user