Nishi FamilyCompare › Host Load Governance

Nishi Compare · measured, not asserted

Host Load Governance

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

How the estate ADMITS, QUEUES, GOVERNS and OBSERVES heavy work so strenuous load never wedges the hardware -- Nishi vs Kubernetes, Bazel RBE, Slurm and systemd (rival marks are vendor-doc reads)

Layer 1 · Executive

Where we are. The estate admits, queues, governs and observes heavy work with instruments the schedulers do not ship: a memory floor before any compiler fork, I/O-wait discrimination at admission (exceed), a storm ceiling, the D-state witness that is the only axis firing on the wired lanes (exceed), heavy-launch admission with memory estimates, a wait-for-opening queue, per-target build serialization, a bounded build deadline with kill and reap, dynamic batching with backpressure, a unified per-minute governor, the slow-leak trend predicate that caught a 3 GB creeper 5-second samplers missed (exceed), a restart route for every supervised daemon, a D-state roster with zombie census, and the resource axis on the health rollup. Open: the load ceiling is UNCALIBRATED and disabled on both wired lanes, the load-history collector it needs, and a leak verdict that is written every beat and read by nobody.

Where we need to go. Admission that is CALIBRATED from this host's own history rather than disabled, and a leak verdict that is COLLECTED -- a RED that reaches a gate row and a reader -- so the box that idled at load 17-36 and wedged at 132 is governed by measured bars, never by a number somebody picked.

The unit. 1 u = one measured session-leg (estate calibration: graphics R21 in one leg 2026-08-15). Local evidence: the storm ceiling and the D-state witness each landed gated 19/19 with a live RED-then-GREEN bite in one leg on 2026-08-17; estimates are relative to those.
Where we are: 3 open rungs. Admission and observation present and exceeding; calibration and collection open. Counts measured at emit below this line.
Cost to a collected leak verdict: 0.5 u. LV1 a gatereg row and a consumer for the rm_trend RED -- the cheapest rung and the one that turns a written verdict into a collected one.
Cost to a calibrated ceiling: 1.5 u. LV2 the per-beat load field on the collector line (if not already landed -- the cell is measured, not asserted), then LV3 arm SBR_ADMIT_MAXCENTILOAD from that history with the arming protocol published.

Research bar. Kubernetes is measured on requests-based scheduling, PSI eviction post-hoc. Theirs: the scheduler reference. Ours: LV3 is the admission-time counterpart.

Research bar. Linux PSI is measured on pressure stall information. Theirs: the kernel's own pressure signal. Ours: LV2's load field is the cheap proxy; PSI is the named next axis.

12 of 20 capabilities measured|1 of them measured exceeds|8 open|coverage 600/1000|adoption 10 full / 2 partial

Layer 2 · Roadmap

Do this next — computed by the ranker, never chosen by a seat

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787905073 domain=loadgov target_version=0.1 rungs=10 done=6 open=4 finish=0 ranker=nx_dr_ocm

#StageRungPriorityDerivation
#10.1Leak verdict collected (LV1) rm_trend_gatereg1200v=3 m=2 c=5
#2laterPriority classes at the edge window (LV4) tsv_priority_class3600v=9 m=2 c=5
#3laterAdaptive concurrency limit (LV5) tsv_adaptive_limit666v=2 m=2 c=6
#4laterOverload as a distinct error class (LV6) tsv_overload_class666v=2 m=1 c=3

Critical path — contract, done-rule, executor, cost

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Memory floor at admission (LA0)ba_verdict1024 MB floor on both build lanes, fail-closed -- LANDEDOrgan0 u
D-state witness (LA1)
after LA0
BA_BLOCKED_PER_CPUprocs_blocked at or above ncpu QUEUEs independent of the ceiling -- LANDED 19/19Organ0 u
Slow-leak trend (LA2)rm_trendA LEAK NEVER RETURNS MEMORY over append-only beats -- LANDEDOrgan0 u
Restart route for every daemon (LA3)md_direct_restart_ok13 services bounce-able via never-brick restart -- LANDEDOrgan0 u
Leak verdict collected (LV1)
after LA2
rm_trend_gateregA knowledge/gatereg.conf row for the trend log plus a consumer that raises the health rollup to DEGRADED on a trend RED; gate proves a planted RED beat reaches /api/health reasons and a GREEN beat does notOrgan0.5 u
Load-history collector (LV2)rm_load1_centiDONE-LIVE, verified 2026-08-24: every resmon beat line carries load1_centi= (line 1500 reads load1_centi=1745, 1356, 1631) plus procs_scanned/procs_with_vm; the disciplined parser (named ASCII consts, separate exit flag, sentinel -1) reads /proc/loadavg. CORRECTION: a first read of this rung called it a written-compiled-unpromoted landmine because the HEAD of resmon.log (an append-only log) showed pre-deployment rows with no load field -- sampling the head of an append-only file samples its PAST not its present, a law this estate already banked and I broke; contentdiff live-vs-any-rebuild is GREEN both ways so the live binary already carries the string. The load history LV3 needs is present and accumulating. DoneOrgan0.5 u
Load ceiling ARMED on the wired lanes (LV3)
after LV2,LA1
lc_recommendDONE-LIVE 2026-08-24 -- armed max_centiload=1643 from the live resmon.log (verified in the live BUILD-ADMIT report), proven by two independent gates: calibrator nx_loadceil_gate 13/13 (only-green beats, recommend*2==trigger coupling, refuse-below-min) + consumer nx_build_admit_gate 22/22 (T1 GRANTs the healthy band, T3/T11/T14 QUEUE a load above the derived bar). nx_loadceil derives max_centiload from the GREEN-beat load1_centi distribution (p99 of healthy load / BA_HARD_FACTOR, which lands ba_verdict's 2x storm trigger at the top-1permil-of-healthy load), gate GREEN 13/13 -- only GREEN beats enter the distribution, RED-beat load is excluded (a wedge's load must never calibrate the ceiling that catches wedges), the recommend*factor==trigger coupling is a tooth, and too little or no healthy history REFUSES rather than arming a permanently-red ceiling. SAFE BY CONSTRUCTION: ba_verdict's every failure is QUEUE not DENY, so a mis-calibration defers builds and cannot brick the lane; max_centiload is a build_admit.conf value re-armed WITHOUT a rebuild. Done when nx_loadceil's recommendation from the live resmon.log is written to build_admit.conf and a gate proves a load above the derived bar QUEUEs while the healthy band is admitted. The arming write itself is deliberate: it changes admission for every build, so it lands from the measured recommendation, not a guess. DoneOrgan0 u
Priority classes at the edge window (LV4)
after LA1
tsv_priority_classEvery request carries read, write or build; the window sheds the lowest class first with per-class budgets DERIVED from measured service time. Done when a gate proves a build-class storm cannot 503 a read-class census and the budgets print their derivationOrgan1.5 u
Adaptive concurrency limit (LV5)
after LV4,LV2
tsv_adaptive_limitThe in-flight limit follows the latency gradient against a no-load baseline (published with its sample size) instead of the edge_window.conf constant, never below a declared floor. Done when a gate proves the limit falls under a planted latency rise and recoversOrgan2 u
Overload as a distinct error class (LV6)
after LV4
tsv_overload_classOVERLOADED-do-not-retry is answered as its own class the sovereign clients honour; deferred work re-issues from the orchestrator on headroom, never from the caller. Done when a gate proves N synchronised clients do not retry in step and the orchestrator fires the deferred rowOrgan1 u

Milestones

MilestoneRungsCumulative
M1 · CollectedLV10.5 u
M2 · CalibratedLV2,LV32 u
M3 · Pressure-awareLV32 u
Layer 3 · Engineering
How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiKubernetesBazel RBESlurmsystemd
ADMIT
memory floor before any compiler forkMeasured: ba_verdict exists in runtime/_hdl_build/nx_build_admit.nx, verified at emit. Armed at 1024MB on both build lanes; the measured 2026-07-20 wedge cause (334MB avail, userspace could not fork). Fail-closed on unreadable /proc. Adoption: LIVE — fully adopted (top of its ladder).
I/O-wait discrimination at admissionOpen — no implementing organ is measured for this axis yet. loadavg counts R and D so disk-wait reads as CPU saturation; procs_running (R only) confirms before refusing. Measured 2026-07-30: 43 percent idle CPU had been refused by 0.33 of disk-wait load. None of the four admit on live-load discrimination; the K8s scheduler is requests-based by design [k8s-resources] [proc-loadavg].
storm ceiling bounds the run-queue excuseMeasured: BA_HARD_FACTOR exists in runtime/_hdl_build/nx_build_admit.nx, verified at emit. Shipped 2026-08-17, gate 19/19 with live RED-then-GREEN bite: above 2x the ceiling an I/O or swap pileup QUEUEs even with idle CPUs. K8s PSI eviction and systemd MemoryPressure act post-hoc, not at admission [k8s-node-pressure] [kernel-psi]. Adoption: LIVE — fully adopted (top of its ladder).
D-state witness refuses a storm on the wired lanesOpen — no implementing organ is measured for this axis yet. Shipped 2026-08-17: procs_blocked >= ncpu (from the SAME /proc/stat read, zero new syscalls) QUEUEs INDEPENDENT of the load ceiling -- at the time the only axis that could fire on the two lanes that actually run, since both then passed an unreachable max_centiload (runner 1000000, mgmt 100000). This is the fix that made admission real on the lanes builds use while the ceiling was uncalibrated; the load ceiling is since armed at a calibrated 1643 (nx_loadceil, 2026-08-24) so both axes now fire. None of the four gate a compiler on the D-state roster.
load ceiling ARMED on the wired lanesMeasured: lc_recommend exists in runtime/nx_loadceil_lib.nx, verified at emit. DONE-LIVE 2026-08-24: nx_loadceil derives max_centiload from the GREEN-beat load1_centi history (p99 / BA_HARD_FACTOR, landing ba_verdict 2x storm trigger at the top 1permil of healthy load) and it is ARMED at 1643 in build_admit.conf -- BOTH wired lanes read that conf now (the runner live BUILD-ADMIT report prints max_centiload=1643 envelope_src=conf). Two gates prove it: calibrator nx_loadceil_gate 13/13 (only GREEN beats enter, recommend*2==trigger coupling, refuse-below-min-samples) and consumer nx_build_admit_gate 22/22 (a load above the derived bar QUEUEs, the healthy band GRANTs). SAFE: every ba_verdict failure is QUEUE not DENY so a mis-calibration defers builds and cannot brick the lane, and the value re-arms without a rebuild. Adoption: LIB-WIRED importers=3 nonval=2 — fully adopted (top of its ladder).
heavy-launch admission with memory estimateMeasured: sa_verdict exists in runtime/nx_swarm_admit.nx, verified at emit. GRANT QUEUE DENY-LOAD DENY-RAM from live host telemetry with per-launch est_mb plus a 2048MB headroom floor; the cluster schedulers do this best at fleet scale [slurm-overview]. Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
adoption REGISTERED-DARK
QUEUE
wait-for-opening deploy queueMeasured: oc_eval_pre exists in runtime/_hdl_build/nx_orchestrate.nx, verified at emit. Actions queue behind a sibling seat's in-flight work on CHECKABLE compound preconditions and fire when the opening appears; Slurm dependency chains are best-in-class [slurm-sbatch]. Adoption: RUN-BY:cron — fully adopted (top of its ladder).
per-target build serializationOpen — no implementing organ is measured for this axis yet. Concurrent builds of one target serialize on a per-target flock held compile-to-install and released before the run phase; Bazel action-level dedup is Best [bazel-rbe].
bounded build deadline with kill and reapMeasured: SBR_BUILD_DEADLINE_MS exists in runtime/_hdl_build/nx_sov_build_run.nx, verified at emit. 900s default with a --timeout-ms override that announces itself; bite-proven in production 2026-08-16 (a 1ms deadline kills and reaps nx_cc, exit 8). Adoption: LIVE — fully adopted (top of its ladder).
dynamic batching with bounded FIFO backpressureMeasured: mb_admit exists in runtime/nx_mesh_batch.nx, verified at emit. The Triton dynamic-batcher analog [triton-dynamic-batcher]: admit while qlen under cap else REJECT with backpressure, coalescing queued requests into one forward pass. Adoption: REGISTERED-UNAUTHORISED — PARTIAL: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
adoption REGISTERED-UNAUTHORISED
GOVERN
unified per-minute resource governorOpen — no implementing organ is measured for this axis yet. Cron-invoked decide-and-signal from conf with a dry lane; superseded the retired vsz_watchdog so there are no dueling breakers. K8s controllers and systemd resource control are Best [systemd-resource-control].
slow-leak trend on the beat logMeasured exceed: rm_trend in runtime/_hdl_build/nx_resmon.nx, verified at emit. A LEAK NEVER RETURNS MEMORY predicate over append-only beats: caught nx_wiki_gw at 3.05GB creeping 0.7MB per beat while 5-second samplers read HEALTHY. None of the four ship leak-trend detection as a primitive; they remediate by OOM-and-restart. Adoption: LIVE — fully adopted (top of its ladder).
leak verdict COLLECTED not just emittedOpen — watching runtime/_hdl_build/nx_resmon.nx : rm_trend_gatereg, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. OPEN: the trend RED is written every beat and read by nobody (no gatereg row, no consumer of its log) -- measured live 2026-08-17, verdict=RED per beat while /api/health said OK.
watching rm_trend_gatereg
restart route for every supervised daemonMeasured: md_direct_restart_ok exists in runtime/_hdl_build/nx_mgmt_data.nx, verified at emit. Shipped 2026-08-17: the wiki row closed the gap where the worst-committed daemon (nx_wiki_gw, 3.05GB) could not be recycled without a host action. PROVEN LIVE: RESTART-DIRECT killed=1, swap fell 788->684 permil, load 1449->954 in one bounce. 13 services now bounce-able via never-brick /api/restart. Adoption: LIB-WIRED importers=4 nonval=1 — fully adopted (top of its ladder).
OBSERVE
load-history collector for ceiling calibrationMeasured: rm_load1_centi exists in runtime/_hdl_build/nx_resmon.nx, verified at emit. OPEN CONTRACT: no organ logs loadavg per beat (resmon logs swap and mem only, procchurn is event-sparse) -- the arming protocol for the ceiling row cannot run until one load field lands on the beat line. Adoption: LIVE — fully adopted (top of its ladder).
D-state roster with zombie censusMeasured: DS_ADMIT_DEFAULT exists in runtime/_hdl_build/nx_dstate.nx, verified at emit. One-sample WHO-is-blocked partition (R S D Z, sum-checked) with kthread labeling and the 2x-ncpu admit ceiling as a named const; found the uniform one-zombie-per-gateway-daemon pattern on 2026-08-17. Adoption: LIVE — fully adopted (top of its ladder).
health rollup carries the resource axisMeasured: rm_log exists in runtime/_hdl_build/nx_resmon.nx, verified at emit. swap and mem-avail permil on every beat, built because nx_health once said OK at 93.4 percent swap exhaustion; the leak axis abstains (UNOBSERVABLE) rather than acquits. Adoption: LIVE — fully adopted (top of its ladder).
SHED
priority classes at the edge windowOpen — watching runtime/nx_tools_api_serve.nx : tsv_priority_class, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-24 across three lanes: reads, writes and builds are shed at one edge deadline, so a read-only census 503s beside a compiler fork. Contract: every request carries a class (read, write, build) and the window sheds the lowest class first with per-class budgets DERIVED from measured service time, never a picked share. Kubernetes API Priority and Fairness and Slurm QoS shed by class; systemd does not.
watching tsv_priority_class
adaptive concurrency limit from measured latencyOpen — watching runtime/nx_tools_api_serve.nx : tsv_adaptive_limit, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The edge window is one constant. The field derives the in-flight limit from the gradient of observed latency against a no-load baseline so the limit tracks the box instead of a number. Contract: the limit is a derived value published with its baseline sample size, never below a declared floor, and a gate proves it falls under a planted latency rise and recovers.
watching tsv_adaptive_limit
overload is its own error class, not a retry hintOpen — watching runtime/nx_tools_api_serve.nx : tsv_overload_class, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. RFC 9110 Retry-After is a bare scalar with no accuracy obligation, so every herd retries in step -- the estate measured exactly that on its own promote lease. Contract: a saturated window answers OVERLOADED-do-not-retry as a distinct class the sovereign clients honour, separate from the retryable transient, and the deferred work is re-issued by the orchestrator on headroom instead of by the caller. No rival distinguishes the two classes at the edge.
watching tsv_overload_class

Risk register

RiskLikelihood x impactMitigation
A ceiling armed from too few beats refuses healthy builds and becomes the permanently-red detector everyone bypasseslikely x highLV3 publishes the sample size and refuses to arm below a declared minimum of beats; until then the D-state witness stands alone by design.
A collected leak RED that fires on a file-backed daemon trains the fleet to ignore itpossible x mediumLV1 inherits rm_trend's committed-memory predicate (not VmSize), which already excludes file-backed growth.
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/loadgov.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain loadgov, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [k8s-resources] The Kubernetes Authors. Resource Management for Pods and Containers (kubernetes.io/docs/concepts/configuration/manage-resources-containers): requests and limits, how the scheduler places on requests and the kubelet enforces limits. publisher · read in our library knowledge/fetched/cmp_loadgov_k8s-resources.html · pin hd6ce205a93181fd102391cb85665143013449fbdc15e2925b6e258649a138229 · accessed 2026-08-18 · vendor-docGrounds: The Kubernetes column on the ADMIT rows: ADMIT: I/O-wait discrimination at admission notes the K8s scheduler is requests-based by design (it does not admit on live-load discrimination), and ADMIT: heavy-launch admission with memory estimate (Best at fleet scale) -- requests/limits are the documented admission model.
  2. [k8s-node-pressure] The Kubernetes Authors. Node-pressure Eviction (kubernetes.io/docs/concepts/scheduling-eviction/node-pressure-eviction): kubelet eviction signals and thresholds for memory, disk and PID pressure, including PSI-based signals. publisher · read in our library knowledge/fetched/cmp_loadgov_k8s-eviction.html · pin h467e73bdbad3a8cd749447e1609a12b9f538f970af6cb0de1940441d97ee9e19 · accessed 2026-08-18 · vendor-docGrounds: The ADMIT: storm ceiling bounds the run-queue excuse row: K8s PSI eviction acts post-hoc, not at admission -- the documented eviction model is reactive, which is the contrast to queueing a compiler fork BEFORE it forks; also grounds the GOVERN: unified per-minute resource governor row (K8s controllers Best).
  3. [bazel-rbe] Bazel Authors. Remote Execution Overview (bazel.build/remote/rbe): distributing build and test actions to a remote execution service with a content-addressed action cache so identical actions are deduplicated. publisher · read in our library knowledge/fetched/cmp_loadgov_bazel-rbe.html · pin h5c48412f6f8096e29a5919398f2a457c83fc16f40cd9de368214d37afe4a3469 · accessed 2026-08-18 · vendor-docGrounds: The Bazel RBE column: QUEUE: per-target build serialization (Bazel action-level dedup is Best -- the bar for our per-target flock) and QUEUE: bounded build deadline with kill and reap (Best) -- remote execution's action model is what the sovereign build lane is graded against.
  4. [slurm-overview] SchedMD. Slurm Workload Manager -- Overview (slurm.schedmd.com/overview.html): cluster resource allocation, job queue arbitration, plugin architecture and the slurmctld/slurmd daemons. publisher · read in our library knowledge/fetched/cmp_loadgov_slurm-overview.html · pin h95a38035cae196a4ff790022d2125cfabcee618485a415233a345f4144756e93 · accessed 2026-08-18 · vendor-docGrounds: The Slurm column: ADMIT: heavy-launch admission with memory estimate (Best at fleet scale), ADMIT: load ceiling ARMED (Best -- Slurm arbitrates a queue on declared resources) and ADMIT: I/O-wait discrimination (Part) -- the HPC scheduler whose queue-arbitration model the estate's admission organs are compared with.
  5. [slurm-sbatch] SchedMD. sbatch(1) -- submit a batch script to Slurm (slurm.schedmd.com/sbatch.html): --dependency (after, afterok, afternotok, singleton), --mem, --time and the resource request flags. publisher · read in our library knowledge/fetched/cmp_loadgov_slurm-sbatch.html · pin h24fdb032598a7dfa467e4224697cc0cd41a0ae31e7fb030fbcc27a1027eeff65 · accessed 2026-08-18 · vendor-docGrounds: The QUEUE: wait-for-opening deploy queue row: Slurm dependency chains are best-in-class -- the --dependency flags are the documented mechanism our nx_orchestrate CHECKABLE compound preconditions (queue behind a sibling seat's in-flight work, fire when the opening appears) are the analogue of.
  6. [systemd-resource-control] systemd project. systemd.resource-control(5) -- Resource control unit settings: cgroup v2 CPUWeight, MemoryMax, MemoryHigh, IOWeight, TasksMax and ManagedOOMMemoryPressure (man page as mirrored by man7.org). publisher · read in our library knowledge/fetched/cmp_loadgov_systemd-rc.html · pin hbfee44bac49fd1bab582c333671a9e3d6889d415397581b14d31a00d4805946f · accessed 2026-08-18 · vendor-docGrounds: The systemd column: GOVERN: unified per-minute resource governor (systemd resource control is Best), GOVERN: restart route for every supervised daemon (Best) and ADMIT: storm ceiling (systemd MemoryPressure acts post-hoc via ManagedOOMMemoryPressure) -- the cgroup-backed enforcement our decide-and-signal governor is compared with.
  7. [kernel-psi] Linux kernel documentation. PSI -- Pressure Stall Information (docs.kernel.org/accounting/psi.html): /proc/pressure/{cpu,memory,io} some/full stall percentages and the poll trigger interface. publisher · read in our library knowledge/fetched/cmp_loadgov_kernel-psi.html · pin h9b263df79da6a3a4893f6e1dd7de99ee4745ede196046955bf848435fe2cde8b · accessed 2026-08-18 · vendor-docGrounds: The ADMIT: storm ceiling row's K8s PSI eviction and systemd MemoryPressure cells: both consume this kernel interface, and both act after pressure is measured -- the primitive behind every post-hoc rival cell, versus the D-state and storm checks that run BEFORE the fork.
  8. [proc-loadavg] Linux man-pages project. proc_loadavg(5) -- /proc/loadavg (man7.org): the load average figures give the number of jobs in the run queue (state R) or waiting for disk I/O (state D), and the fourth field is currently runnable entities over total entities. publisher · read in our library knowledge/fetched/cmp_loadgov_proc-loadavg.html · pin h77546d7b9bae197106f124cb9673acea83a33486e3e8e8bfa8cee135d12468a8 · accessed 2026-08-18 · vendor-docGrounds: The ADMIT: I/O-wait discrimination at admission row (EXCEED): loadavg counts R and D so disk-wait reads as CPU saturation is a documented property of this file -- the reason ba_ncpu confirms with procs_running (R only) before refusing, and the reason the 2026-07-30 refusal of 43 percent idle CPU by 0.33 of disk-wait load was possible at all.
  9. [triton-dynamic-batcher] NVIDIA. Triton Inference Server -- Model Configuration, dynamic batcher section (user guide): preferred batch sizes, max queue delay, queue policy with max queue size and timeout action. publisher · read in our library knowledge/fetched/cmp_loadgov_triton-modelconfig.html · pin h531bec727c4e04515c0d9657db12bd5cb71532af826e22864f6e15c29ec95b2d · accessed 2026-08-18 · vendor-docGrounds: The QUEUE: dynamic batching with bounded FIFO backpressure row, which names itself the Triton dynamic-batcher analog: admit while qlen under cap else REJECT with backpressure, coalescing queued requests into one forward pass -- the queue policy and delay knobs are Triton's documented shape.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/loadgov.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers