Keeper desk · decision page · for your red pen

The Disk Policy

One signature turns five report-only cleanup instruments into working ones — and ends the per-incident disk asks for good.

Draft for ratification · 2026-08-26 · basis: disk-rootcause-20260826.md · nothing deletes until you sign
One signature = a standing scope, not another per-incident ask
Every pool gets an expiry AND a size cap — age alone provably fails
The never-touch list is enforced by machine, not memory
An overrun becomes one failed job — never your frozen machine

Why now

The disk died three times today. The fleet writes roughly 400 MB a minute; the only cleaner allowed to act runs once a day and only touches things older than 24 hours. Six purpose-built cleanup instruments watched it happen — five are forbidden to delete by their own headers, every one citing your rule that no agent deletes. The rule is right. What was never built is its other half: a scope you sign once, so the machinery can act inside it without asking. A complete, self-checked cleanup engine has sat finished and uninstalled since June 17. This is an authorization gap, not an engineering gap.

↘ go deeper — the day, as the hourly watcher recorded it

Free space on the machine, from ~/next-arc/disk-watch.log: overnight it drifted 12 → 10 GB with four warnings nobody could act on. At 08:11 it hit 4.3 GB — freeze one. Your manual reap brought it to 55 GB by 10:11. By 13:11 it had burned back down to 12 GB — that hour is the measured 367 MB/min — and at 14:11 it froze again at 5.4 GB. The watcher wrote every line and reclaimed nothing; its own header says "WATCH-ONLY, deletes nothing… Keeper executes all deletions." Full receipts: disk-rootcause-20260826.md.

What you're signing

The pools the machinery may clean, each with an expiry and a hard size cap. (Why both: the compile cache already self-expires at 7 days and still hit 9 GB — a burst writer fills the window faster than the window closes. Age controls the tail; only a cap controls the burst.)

PoolExpiresCap
Finished sealed-run folders2h after the run's evidence is banked15 GB
Compile cache24h3 GB
Test-fixture books (temp)12h10 GB
Session scratchpads2h after the session is provably dead20 GB
Arc worktreeson declared lease expiry — never inferred from git state25 GB

Watermarks: below 60 GB free — quiet cleanup of expired items. Below 25 GB — aggressive cleanup plus one notification. The existing 5 GB freeze stays as the floor and should never fire again.

Never touched, ever: the canon repo · the bay's clean mirror · anything a live process holds · live benches and leases · the bay's ledger · and anything registered anywhere — before any delete, the machinery greps every registration surface (hooks, statusline, crontab, launchd, schedule registry, open file handles); any hit means keep and report. That turns this morning's near-miss — a sweep took a live rollback lever — from a lesson someone must remember into a rule the machine enforces.

Anything outside this table still stops and asks you. A new pool, a shorter expiry, a bigger cap — each is a new signature. Inside the table, the machinery works without asking, forever.

What executes under the signature

  1. Finished runs reap themselves. The sweeper that knows the exact right moment — when a run's evidence is safely banked elsewhere — was built on August 2 and has never had a caller. It gets wired to fire at harvest. (This alone caps today's biggest recurring writer.)
  2. The 30-minute cleanup engine wakes up. The June 17 draft — already adversarially self-checked — gets its scope widened to these pools and its clocks tightened to today's fill rate. It rides a heartbeat that already exists; no new machinery.
  3. Every allocation declares an owner and an expiry at birth. Cleanup-on-exit is structurally wrong on this box — sessions die by kill, and a killed process runs no cleanup. A birth registration is readable after its owner is dead. The registry instrument for this exists; it gets call sites.
  4. Fleet scratch moves to a size-capped volume on the Extreme SSD. Your own August 23 spill ruling — "fan-outs never on internal disk" — made enforceable by the filesystem instead of by discipline. This is the one move that makes everything else a nicety: with it, an overrun fails one job loudly and your machine physically cannot freeze.
  5. The 5 GB guard learns to fire the cleanup before it blocks. Today it blocks its own cure — verified: the janitor, the reaper, and the restart command are all refused under it; only a hand-typed delete gets through. The daily janitor and hourly watchers retire into the watermark layer; manual reaps survive only as the escape hatch.

The quota volume can't live on internal disk today

Internal is 89% full — the capped volume must land on the Extreme SSD (where your August 23 ruling already points) or wait for a reclaim. Signing doesn't block on this; the software layers land first and the volume follows.

One doctrine line changes in the fleet's bay

The bay's job table says, in its own comment, "nothing deletes." That line is load-bearing doctrine and amending it is exactly what this signature authorizes — the edit routes through warp with its own review, not as a desk drive-by.

The word

Sign it?

"sign" ratifies the policy as written · "sign with changes: …" red-pens any row first · every piece then lands with its own court, and this page records the ratification. Until you sign, nothing deletes anything — today's report-only world continues.