Skip to content

fix(scale): resolve S20–S22 process RSS growth blocking S24 admission #1278

Description

@DecisionNerd

Problem

The validated S18/S19/S20/S22 prefix at merged report commit 989579078cc7e71ca4deaa1464afbbed7d222222 (measured executable source 710c6c64f4718c0664d08bdd3aafe21de4a29eba) cannot advance to S24 under the existing full admission policy.

S20 process VmHWM is 199,135,232 B; S22 is 262,049,792 B, a 31.5939% increase. The independent rss_bounded_or_plateaued gate allows at most 10% growth. Low absolute RSS does not satisfy that gate.

A read-only replay validated the complete prefix and called progressive_host_run._admit_projection for S24 with reported free capacity 733,767,651,328 B and unchanged reserve 141,258,578,535 B. It returned projection_refused, with only rss_bounded_or_plateaued false. The storage-only admit therefore does not establish full S24 admission.

Evidence: measured lifecycle report, S20 receipt, S22 receipt, admission policy.

Objective

Resolve the verified memory-growth cause so comparable lower-rung evidence satisfies unchanged full S24 admission.

Acceptance criteria

  • Reproduce the refusal from the accepted prefix and attribute additional process RSS to specific lifecycle phases and Rust allocations, distinguishing bounded overhead from graph-size-dependent state and measurement effects.
  • Repair the independently verified cause; add regression coverage that exercises it through the relevant real Rust/facade path rather than merely mirroring implementation.
  • Collect comparable S20/S22 evidence on OVHC-AGENCY under the existing authorized lower-rung process, preserving executable/generator identity consistency and required prefix validation.
  • Demonstrate that the unchanged full S24 admission policy passes, including the 10% RSS growth gate, using fresh measured host capacity and all required evidence dimensions.
  • Preserve lifecycle correctness and publish the evidence and limitations with green checks for the changed surface.

Completion scenarios

Given the preserved pre-repair receipts, when full S24 admission is replayed, then it refuses on RSS growth despite storage headroom passing.

Given a verified repair and comparable accepted lower-rung evidence, when the unchanged full admission policy runs, then S24 is admitted without relaxing memory, correctness, or other gates.

Non-goals

Runtime/seal optimization is owned by the sibling runtime issue. No gate waiver, increased memory budget, unrelated refactor, higher-scale run, or new release-only certification requirement.

Related prior work

#1094 addressed S18/S19 recount/query RSS and is closed; #904/#902 also contain earlier bounded-memory repairs. This issue concerns the newly reproduced S20/S22 refusal, not reopening completed acceptance criteria.

Scope and relationships

Native sub-issue of and blocker for #900, limited to its existing scale admission and lifecycle acceptance criteria. #900 remains the canonical close gate; #1194/#745 retain final capacity and billion-edge outcomes. Prioritize the RSS blocker, diagnose independent runtime evidence while waiting, and integrate repairs before collecting a shared comparable prefix. Neither child depends on completion of the other solely for diagnosis.

Rust owns product behavior; Python/Node remain thin bindings. Preserve generator semantics, exact source/imported counts, canonical queries, portable verification, durability, recovery, the unchanged reserve, resource limits, and first-failure stopping. This issue does not authorize S24/S25/S26 execution or a new certification workflow. Use the existing designated-host ladder within separately authorized scale limits.

Validation and documentation

Use targeted deterministic Rust/facade regressions for the verified cause and existing admission tests. Run checks appropriate to the changed surface and required exact-head CI Gate before merge. Record exact commands, source/executable identities, raw and sanitized evidence, and limitations in the existing scale evidence ledger. Keep process RSS separate from cgroup/page-cache measurements; do not claim that logical budgets prove native memory bounds. Preserve unrelated work and the team WIP limit.

No new public API or security/privacy surface is intended. Retain the existing sanitized evidence contract: no graph content, credentials, UUID inventories, or private host paths in checked-in evidence.

Activity

  1. DecisionNerd commented on Sep 29, 2026

    @DecisionNerd
    ContributorAuthor

    Evidence relocated from the docs tree (#1625). The 28 file(s) below were committed under docs/development/ as measurement evidence for this issue. They are removed from the tree by #1628 (the #1625 pull request); the repository keeps method and content digests, results live here. Every file remains available at its permalink on commit 29a7b34ebe44, and its SHA-256 is recorded next to it.

    Directory permalinks:

    Files (28 total, 35,331 lines)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions