Not normative · Verdict
GI1 verdict — interoperability
This page records why SOVM-IROH §10 marks GI1 closed. It is a record of evidence, not part of the specification: it adds no requirement, and the gate’s text on the binding page is what it answers to.
1. The gate
Section titled “1. The gate”GI1 interoperability: two independent nodes complete a sync exchange over a direct path and over a relay, with byte-identical outcomes.
2. Where the evidence was read
Section titled “2. Where the evidence was read”- Commit.
d6f6a00e0e5ba94a78318401a87d0bd76ded7d6e, onmainsince the promotion of 2026-09-11. Every test named below exists at that commit. - Run. CI run 19083, job
Rust Test (sovm workspace), 2026-09-08T22:47Z, which checked out exactly that commit. Stepcargo test (sovm workspace on loopback)carries the two-process column below; stepcargo test (GI1 container topology)carries the container column; the job’s closing step recorded its own machine-readable verdict asran_all_passed. - Host. The run’s preflight read the runner host as stalled on IO
(
psi_io_full11.89 over ten seconds, the build disk 92% busy). Every earlier failure of the container roster had been attributed to that condition, so a clean pass under it removes that confound rather than benefiting from its absence.
3. The clauses, and the tests that carry each
Section titled “3. The clauses, and the tests that carry each”Two columns, because the gate is carried twice. The two-process column runs on every merge; the container column is the one that makes the relay a fact of routing rather than of configuration.
| Clause | Two processes, every merge (sovm-run’s two_machines tests) |
Two containers (sovm-run’s two_containers tests) |
|---|---|---|
| two independent nodes complete a sync exchange | two_machines_name_each_other_resume_and_exit_on_a_signal: two processes, two state directories, two keypairs, durable resume |
the whole roster: two containers, two filesystems, three bridge networks |
| over a direct path | two_machines_converge_over_a_direct_path; falsifier a_direct_exchange_fails_a_relay_requirement |
two_containers_on_one_bridge_converge_over_a_direct_path |
| over a relay | two_machines_converge_over_a_relay; falsifier a_relayed_exchange_fails_a_direct_requirement |
a_relay_carries_an_exchange_between_unroutable_networks; the isolation it rests on is falsified by a_disjoint_topology_denies_a_direct_path, and that falsifier’s own falsifier is a_witness_on_both_bridges_reads_the_route_as_surviving |
| byte-identical outcomes | the_direct_and_relayed_legs_converge_to_identical_bytes; negative controls independently_authored_legs_do_not_compare_equal, a_leg_that_dropped_the_object_does_not_compare_equal and a_fetch_of_an_object_no_one_holds_fails |
the_container_legs_converge_to_identical_bytes; negative controls independently_authored_container_legs_do_not_compare_equal and a_container_leg_that_dropped_the_object_does_not_compare_equal |
In run 19083 all fourteen two_machines tests passed, and all seven
container tests executed and passed; the one case the container step filtered
out is the file’s own helper unit test, not a topology test. The path each leg
claims is read from the carrying connection’s own account of its carriage, not
from an address map, and a node required to observe a path fails on an
unreadable carriage rather than passing on it.
4. The rulings that interpreted the gate
Section titled “4. The rulings that interpreted the gate”Two rulings, both delivered on 2026-09-08 by the technical lead before the gate was marked closed.
Independence is the clause’s falsification target, not a count of kernels. The word is in the gate to exclude what a single-process exchange fakes: one address space, one store serving both roles, one keypair standing in for two identities, and a loopback path no relay ever sees. The container topology removes all four and forces the relay by routing. An earlier reading, written when the only alternative on offer was two processes over loopback, asked for more than one machine; the container topology answers that reading’s objection by construction, and the ruling superseded it. Ruling it sufficient is a two-way door: a later two-host run only strengthens this record.
The residual is stated exactly as SOVM-IROH §10 states it:
The residual is one shared kernel, and therefore one clock and one network stack: real clock skew on the hybrid-logical-clock path and real path characteristics — MTU, address translation, loss, reordering — are not demonstrated by this evidence. Neither is a clause of GI1, whose byte-identity comparison is between the direct leg and the relayed leg rather than between two hosts. A two-host run would strengthen the record and is not required to close the gate; reading independent as reaching the clock would instead narrow a transport gate onto a property it does not name.
A gate closes on a named executed run, never on a pipeline’s colour. The container step may decline to run when the host’s container daemon does not answer, which is a fact about the host rather than the change; a declined run is recorded as a distinct outcome and is never counted as a pass. That is why section 2 names a run rather than a green build.
5. What the evidence does not show
Section titled “5. What the evidence does not show”The container roster is nondeterministic on a loaded host, and the closure does
not claim otherwise. A later run on 2026-09-09 passed six of the seven tests
and failed the byte-identity test, with a node on a relay-required leg
reporting a direct carriage while bytes flowed: the pair was routable at that
instant, which is a lapse of the host’s topology rather than of the binding.
Since 2026-09-09 the step records such a run as ran_topology_lapsed, carrying
no evidence in either direction. Run 19083 is a positive observation of every
clause under the gate’s own falsifiers; that later run is an absent
observation, not a contradicting one.
The closure does not promote the binding page out of Draft, does not assert
that any implementation claims SOVM-IROH, and does not demonstrate clock skew
or real path characteristics between two hosts.
6. Reproducibility
Section titled “6. Reproducibility”The workspace these tests live in is not released, so an outsider cannot
re-run them today. Reproducibility is a target, owed under decision D-0002
by project P-0058, which releases the node code the tests exercise; until
then this page is a record an outsider can read and not yet one they can check.