Skip to content

Seal of Placement

Choose a tag to compare

@aie0 aie0 released this 10 Sep 08:29
· 1948 commits to main since this release

What Progressed In The Story

Tickoni can now describe the runtime placement contract that turns tile
boundaries from logical lanes into real isolated process boundaries. v2.14
places every tile, link, workspace, and CPU assignment under an explicit rule:
shared paths are allowed only when declared, correctness links do not silently
drop, and one failed tile must not drag the rest of the runtime down with it.

The user can now:

  • inspect one supervisor-managed process per configured tile,
  • see which shared-memory workspace backs each inter-tile link,
  • distinguish exclusive-core, shared-core, and floating CPU placement,
  • verify that shared-core placement still keeps separate tile address spaces,
  • identify reliable links, MTU, depth, and flow-control expectations,
  • see failed placement, malformed workspace, and invalid link shape fail
    closed,
  • observe crash identity and crash-only supervisor behavior,
  • and keep source ownership, contracts, codecs, scenarios, fixtures, and test
    support in clearer Tickoni-owned paths.

Want the changelog first? Skip the Tickoni story and jump to the release notes ↓

Chapter 6: Seal of Placement

assets/banners/banner.png

By morning, Maro had chosen.

The boatwright would be paid first. The investment basket could wait.

With the payment proposal beneath his belt, Maro sat beside the mast as Tickoni guided their black boat north.

At noon, eight red pillars appeared through the mist.

Between them lay the Eight-Core Strait.

Eight channels cut through black cliffs toward a harbor built on cedar stilts. Foxfire lanterns marked safe routes between reefs.

But no ship was moving.

Rice carriers, barges, skiffs, and treasury vessels crowded the entrance, their sails like a forest trapped at sea.

Every captain demanded private passage.

At the harbor’s center, Sora, a kitsune harbor-master, stood atop a signal tower.

The fox spirit wore a white captain’s mask, three red tails moving behind her as she directed traffic with burning fans.

Green meant advance. Blue meant turn. Red meant hold.

Then the seabed groaned.

Coins rattled inside Maro’s purse. Far below, an enormous yellow eye opened. Long whiskers dragged through the mud. A black tail struck the earth.

Above its head, a great old stone leaned from the seabed.
A crack split its center.

The sea rose.

All eight channels twisted toward the harbor’s center, forming a whirlpool.

— Namazu, — Tickoni said.

The giant catfish spirit caused earthquakes when it thrashed beneath the earth. Here, its anger bent currents.

The kitsune raised every fan.

Red fire filled the harbor.

Hold.

Turn back.

The captains ignored her.

A treasury ship forced toward the first channel. A grain carrier crossed its bow, and skiffs rushed between them.

A copper barge struck the carrier. One skiff caught the treasury ship’s anchor chain. The anchor tore free and smashed through a fishing vessel.

Wood exploded across the water.

One ship struck another.

Then another.

Masts broke. Cargo spilled. Boats drifted without signals.

A vessel struck the signal tower. It tilted above the whirlpool.

Tickoni pulled the sail hard. Their boat shot between two barges as the tower collapsed.

The kitsune leapt.

For one moment, she became a red fox running through open air.

She landed in Tickoni’s boat and returned to human form. Her mask was cracked.

— You crossed a closed harbor.

— It is no longer closed. It is unguided.

— And where is an oni without an Order going?

— To forge a contract no oni can break.

The kitsune studied Tickoni for a moment.

— I see.

Another tower fell.

— Eight channels. Forty-three ships, — the kitsune said. — Every captain demands water no one else may enter. Without the towers, I cannot place them. Once one captain thinks a channel is safer, the others follow. Then it stops being safer.

She watched another ship turn toward the crowded passage.

— Fear travels faster than ships.

Tickoni studied the spaces between the ships.

Their direction. Their speed. Their damage.

The flame-script beneath its ribs glowed, and lines appeared across the water.

— Those four are moving north. Place them together.

— Each demanded an exclusive channel.

— They demanded safety. They mistook exclusivity for its only form.

The treasury captain raised his horn.

— My vessel will not share water with common cargo!

The kitsune watched the ships behind him begin turning toward other channels.

— One captain believes the channel is unsafe, — she said. — Soon it will be.

The whirlpool caught his stern. A crack opened below deck, and rei poured into the sea.

Maro shouted:

— Your private channel is sinking!

Tickoni drew a black line through the nearest passage.

— One shared channel. Same direction. Same pace. Separate ships.

— If one loses control, all four collide.

— Then govern entry. Each captain keeps command. No one advances until the space ahead is clear.

The kitsune smiled.

— A convoy.

She climbed Tickoni’s mast. Maro tied a fallen signal bell beneath the torn sail.

Their little boat became the new signal tower.

One bell meant hold. Two meant enter. Three meant clear the channel.

Foxfire settled upon the water as markers.

The grain carrier entered first, followed by the treasury ship and two barges.

— Match the vessel ahead! — the kitsune called.

— I refuse to be paced by rice! — shouted the treasury captain.

Tickoni crossed his bow.

— Then be paced by the seabed.

Namazu’s mouth opened beneath the harbor.

The captain slowed.

Four vessels entered one channel.

Separate decks.

Separate rudders.

One declared passage.

Then Namazu struck again.

The last barge lurched sideways. Its mast snapped toward the treasury ship.

Maro rang the danger bell.

The channel burned red.

Tickoni leapt onto the barge and caught the mast before impact. Black water poured through the hull.

— Tie us to the treasury ship! — the captain shouted.

Tickoni cut the rope.

— One broken ship must not drag the others down.

Tugboats pulled the damaged barge into a protected lane while the others continued north.

— They shared the channel, but the damage stayed with one ship, — Maro said.

— Because they shared a path, not a hull.

Namazu rose from the harbor, its black head large as an island. Broken anchors hung from its whiskers.

The captains panicked again.

Maro struck his payment tag against the signal bell.

The clear note cut through the shouting.

— I thought moving first would make my problems smaller. It only made them heavier. You are doing the same with your ships!

The harbor fell silent.

— There is no empty sea. Stop fighting for one.

Only four channels still burned.

— Give each one a purpose, — Tickoni said.

One for ships moving north.

One for ships moving south.

One protected lane for damaged vessels and rescue boats.

One waiting basin where unplaced ships held position instead of drifting free.

The kitsune sent the pattern across the harbor.

This time, the captains obeyed.

— Interesting, — she said. — The water has not changed. Only what they expect from one another.

When one ship slowed, those behind waited. When one failed, its channel closed. Tickoni carried each changed signal from vessel to vessel.

Nothing moved without a place.

Nothing shared without a rule.

At sunset, the final ship cleared the northern gate.

The whirlpool weakened.

Namazu’s yellow eye watched Tickoni.

— You did not defeat me, little guardian.

— No.

— Then what did you protect?

Tickoni looked across the harbor.

Separate vessels floated beneath separate flags—some damaged, some delayed, all still themselves.

Between them burned shared lines of foxfire.

— Their boundaries.

Namazu closed its eye and sank.

The cracked stone settled deeper into the mud.

The water became still.

Then one of the foxfire lines remained burning.

It ran from the northern channel to the southern channel, across the rescue lane, and around the waiting basin.

Four paths.

Four purposes.

One harbor.

The lines folded inward.

At their crossing, something black rose from the water.

A fragment shaped like an eight-pointed compass.

Tickoni recognized the black fire before the fragment reached it.

Another lost law.

It struck the flame-script beneath Tickoni’s ribs and locked beside Ticket and Weight.

All eight harbor bells rang.

A name returned to the sea.

The Seal of Placement.

Every act must find its place.

Maro watched the ships divide among the channels.

The damaged barge floated alone in the rescue lane. Beyond it, the grain carrier and treasury ship continued north.

Maro watched them for a while.

— They can travel together without belonging to each other.

— They have to, — Tickoni said.

The torn sail rose.

Behind them, the captains entered the shared waters in order.

Ahead, the Ledger Sea opened.

Beneath Tickoni’s ribs, three seals burned.


Long after the harbor had gone quiet, the kitsune climbed the ruined signal tower.

Inside, a single lantern burned above an empty desk.

On the wall hung a sheet bearing the crest of the Order of the Oni.

Below the crest was a charcoal likeness.

TICKONI

Her eyes passed once over the notice.

— Forge a contract no oni can break...

One tail moved through the lantern light.

— We’ll see.

Release Notes

Release: v2.14 — The Seal of Placement

v2.14 turns Tickoni placement into an explicit runtime contract. Tiles are
placed as supervisor-managed processes, correctness-bearing links are placed in
Firedancer Tango shared memory, CPU assignments are validated as exclusive,
shared, or floating, and source-tree ownership is tightened so runtime,
contracts, codecs, scenarios, fixtures, and test support have clear homes.

tile topology -> process placement + shared-memory links -> isolated, observable runtime boundaries

What is now true: Tickoni can distinguish a shared CPU from a shared process,
prove that a tile has its own declared place, and fail closed when placement,
workspace, or link shape is invalid. What is still not true: this release does
not add new financial policy rules, execution authority, live adapters, model
shortcuts, audit schema changes, or replay semantic changes.

Headline Features

1. Supervisor-Managed Tile Processes

Tickoni’s tile topology moves from logical in-process lanes toward real
process boundaries managed by the supervisor.

The operator can inspect:

  • one process identity per configured tile,
  • supervisor launch records tying each child process to the runtime,
  • boot, heartbeat, halt, and fail lifecycle state,
  • and crash reports that identify the failed tile instead of treating the
    runtime as one opaque process.

2. Firedancer Tango Shared-Memory Links

Correctness-bearing tile links are specified around Firedancer
mcache/dcache shared-memory fragments instead of heap-backed production
queues.

The release defines:

  • workspace identifiers per link,
  • producer and consumer ownership,
  • link depth and MTU,
  • reliable flow control through fseq or fctl,
  • backpressure for correctness links,
  • and counted drops only for explicitly lossy telemetry links.

3. Explicit CPU Placement

Tickoni no longer inherits a validator-style assumption that every useful tile
must own an exclusive core.

Placement modes are now part of the contract:

  • exclusive means one tile process is pinned to one CPU,
  • shared means multiple declared tile processes may intentionally reuse one
    CPU,
  • floating means no fixed CPU pinning,
  • malformed or unavailable CPU ids fail closed,
  • and undeclared oversubscription is rejected instead of becoming accidental
    runtime behavior.

4. Source Ownership Cleanup

v2.14 also makes the Tickoni source tree easier to review before the runtime
gets more platform-specific.

The release clarifies:

  • canonical schemas live under src/tickoni/schema,
  • protobuf contracts share one proto root,
  • codecs live under src/tickoni/codec,
  • narrow Firedancer wrappers stay under src/tickoni/c_abi,
  • deterministic demo orchestration is separated from runtime tiles,
  • fixtures, mocks, and test roots use predictable naming,
  • and tile-local message/type files do not masquerade as canonical schemas.

Governance and Safety

1. Crash Containment Boundary

A failed tile is now treated as an identified runtime boundary event.

The supervisor contract records which tile failed, keeps sibling state from
being treated as implicitly corrupted by that process, and follows the
declared crash-only shutdown or restart behavior.

2. Fail-Closed Placement And Workspace Validation

Invalid placement is not repaired silently.

v2.14 makes these failures explicit:

  • malformed CPU ids,
  • unavailable CPU ids,
  • undeclared CPU oversubscription,
  • malformed or stale workspace identifiers,
  • missing queue or control objects,
  • link MTU or fragment-size mismatches,
  • invalid dcache chunk references,
  • and accidental heap-queue selection in process mode.

3. No Financial Semantics Drift

This is a runtime-placement release, not a policy or execution release.

v2.14 does not change capability envelopes, policy outcomes, approval
requirements, audit record shape, replay capsule shape, investment demo
semantics, adapter authority, or the approved execution ledger/live execution access.

4. Firedancer Reuse Without Solana Semantics

The release keeps the reuse boundary narrow.

Tickoni reuses generic Firedancer substrate such as Tango queues, workspaces,
control state, sandbox patterns, topology discipline, metrics patterns, and
crash-only process behavior. It does not import Solana validator tiles, RPC
schemas, validator auto-layout assumptions, or product fields into upstream
Firedancer topology structs.

Platform Work

1. Process-Mode Evidence

The process-mode tests and evidence model record enough operating-system
identity to prove isolation.

Evidence includes:

  • supervisor PID,
  • child PID or equivalent process id per tile,
  • tile id and placement mode,
  • assigned CPU when pinned,
  • and parent/child launch records.

2. Shared-Core Runtime Path

The release preserves consumer and developer hardware viability by allowing
explicit shared-core placement without weakening process isolation.

Multiple tile processes may share a CPU only when the config says so. They
still remain separate processes with separate address spaces.

3. Link And Lifecycle Documentation

Each link and tile lifecycle now needs explicit answers for ownership,
workspace, mapping mode, producer, consumer, depth, MTU, reliability,
backpressure or overrun behavior, restart behavior, shutdown behavior, and
health signals.

This keeps future topology work reviewable instead of relying on implicit
thread or queue behavior.

4. Test And Fixture Tree Predictability

The runtime hardening work is paired with source-tree hygiene so future
contributors can tell whether a file is production runtime, canonical schema,
codec implementation, deterministic demo orchestration, fixture data, mock
support, or a test root by looking at its path and filename.

Demo

Run the v2.14 evidence gate through the Tickoni integration lane:

just test-integration-tk

The review path should prove:

  1. process-mode topology uses one supervisor-managed process per configured
    tile,
  2. correctness-bearing links cross tile boundaries through shared-memory
    backing rather than heap queues,
  3. explicit shared-core placement is accepted while undeclared
    oversubscription fails closed,
  4. malformed workspace, CPU, and link-shape cases fail closed,
  5. and demo/replay behavior remains equivalent across exclusive-core and
    shared-core placement configs.

What Comes Next: V2.21 — macOS Retail Runtime Support

v2.14 gives Tickoni a Linux full-runtime placement contract. V2.21 turns that
contract into a platform-support decision for consumer and developer Mac users:
what can run natively, what remains Linux full-runtime only, which guarantees
are degraded, and how version, platform tier, isolation tier, audit output,
and replay proof stay visible.

Next:

  • define supported macOS retail runtime tiers without weakening the Linux
    Firedancer path,
  • make tickoni doctor and demo preflight report version, host, architecture,
    platform tier, isolation tier, and live-execution status,
  • prove deterministic paper/sandbox fixture flows produce equivalent policy,
    audit, proposal, and replay results across Linux full-runtime and macOS
    retail mode.