Skip to content

fix(ladder): de-claim by exact artifact (sha256 + file) — D2 for #3715 - #4615

Closed
noahgift wants to merge 6 commits into
split/ont10-rest-0.70from
89/3715-d2-file-key
Closed

noahgift wants to merge 6 commits into
split/ont10-rest-0.70from
89/3715-d2-file-key

Conversation

@noahgift

Copy link
Copy Markdown
Contributor

Operator ruling D2 (cop-inbox/handoff/ruling-3715-2010.md): "claims keyed by exact artifact (file sha / quant), per BIN-001 identity. It lands in the rc.2 PR set with red/green proof, then IQ2_XXS is withdrawn by data."

Stacked on #4603, which adds cells.declaimed. Its base is 0d/3715-b1-main because main does not have the de-claim feature yet.

Change

  • Before this PR, cells.declaimed was keyed (host, arch). gx10 UD-IQ2_XXS is qwen35, so an arch entry would have withdrawn the whole flagship family on that host.
  • An entry now names either an arch or one artifact (sha256 + file). Naming both, or giving a sha that is not 64 lowercase hex, is a FAIL.
  • The judge (model_ladder_cells.py), the producer and the receipt writer (model_ladder.sh) match a file entry by sha256 only. If the host holds a same-named file with different bytes, that file still owes every cell, and the judge FAILs with a message naming the stale entry.
  • The contract withdraws gx10 Qwen3.5-0.8B-UD-IQ2_XXS.gguf, sha256 a369165c…e54, until 0.70.1. I checked the sha with sha256sum on gx10. All four verbs hit the 600 s timeout on GB10 in the H4 run (apr 0.70.0 8d021f6). The file is withdrawn by that data, not waived.

Red / green

check before after
green-cells-declaimed-file under the pre-change judge (MODEL_LADDER_CELLS_LIB) rc 1 (RED): an arch key cannot withdraw one file rc 0
check_model_ladder.sh --self-test n/a 156 cases, 0 bad
new judge mutants: declaim-file, declaim-by-name, declaim-widen, declaim-stale, declaim-sha-hex n/a all 5 killed
producer self-test, new mutant declaim-name n/a killed
real H4 inventories, gx10 + lambda n/a only gx10 IQ2_XXS is DECLAIMED (40 cells); gx10 still owes 200, lambda 240
receipt writer fixture: same file name, other bytes n/a stays in inventory[] (owed)
pv validate contracts/model-capability-ladder-v1.yaml n/a valid

Refs #3715 · Agent: aprender-89

🤖 Generated with Claude Code

noahgift and others added 3 commits September 28, 2026 22:26
…ne — D2 for #3715

cells.declaimed was keyed (host, arch). gx10's failing Qwen3.5-0.8B-UD-IQ2_XXS is
qwen35, so an arch entry would withdraw the whole flagship family on that host.
Operator ruling D2: claims keyed by exact artifact per BIN-001 identity.

A de-claim now names either an arch or one artifact (sha256 + file), never both.
The judge, the producer and the receipt writer all match a file entry by sha256
only. If the host holds a same-named file with different bytes, that file still
owes every cell, and the judge FAILs with a message naming the stale entry.

The contract withdraws gx10 IQ2_XXS a369165c… (0.70.1). All four verbs hit the
600 s timeout on GB10 in the H4 run. Every other gx10 Qwen3.5 file, and lambda,
still owe their cells.

Red/green:
- The pre-change judge FAILs green-cells-declaimed-file.
- check_model_ladder.sh --self-test: 156 cases, 0 bad.
- 5 new judge mutants and 1 new producer mutant are killed.
- On the real H4 inventory, only the 40 IQ2_XXS cells on gx10 are withdrawn.

Refs #3715

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two conflicts, and both sides are kept.
- contracts/model-capability-ladder-v1.yaml: base's qwen3moe arch entry (D1) plus the D2 IQ2_XXS sha256+file entry.
- scripts/check_model_ladder.sh: base's declaim-claimed cmutant plus the 5 D2 cmutants. declaim-host stays on the
  dkey() form.
declaim_still_claimed (from base) looks up (host, arch) and never matches a sha256: key, so a file de-claim does
not contradict its rung.
After the merge: check_model_ladder.sh --self-test 157 cases, 0 bad; producer self-test all as expected; pv validate
valid.

Refs #3715

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rum finding on #4615

Finding from the sonnet-5 lane at 11395f7. declaim_still_claimed (from base) looked up only (host, arch). A rung
carries its artifact's sha256, so a rung naming exactly the de-claimed file would keep claiming it on that host in
released pv, and no check would catch it.

The lookup now goes through declaim_of (sha first, then arch). The arch message is unchanged.
- New case red-cells-declaimed-file-still-claimed.
- New cmutant declaim-claimed-file puts back the arch-only lookup; the new case kills it.
- green-cells-declaimed-file narrows ctrl-q4km to hosts: [lambda], the same fix base applied to green-cells-declaimed.
The real contract has no rung for the IQ2_XXS file, so it is unaffected.

check_model_ladder.sh --self-test: 158 cases, 0 bad. Producer self-test ok. pv validate: valid.

Refs #3715

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

Head is now b957e7fd79. It merges base 2205cfd761 (merge commit, no rebase). Both conflicts are resolved by keeping both sides: the qwen3moe arch de-claim and the IQ2_XXS sha de-claim, plus both sets of mutants.

Quorum round 2, at 11395f7810: the sonnet-5 lane returned FAIL. The base's declaim_still_claimed ignored file de-claims, so a rung naming the de-claimed file would still claim it. Fixed in b957e7fd79 with a new red case red-cells-declaimed-file-still-claimed and a new cmutant declaim-claimed-file, which that case kills.

Quorum round 3, at b957e7fd79: PASS 3/3, degraded: same-family. The lanes were sonnet-5, a second sonnet-5 lane in the agy seat, and haiku-4-5. agy is not_measured: its headless plan mode auto-denied a command twice, so it produced no output.

check_model_ladder.sh --self-test: 158 cases, 0 bad. Producer self-test ok. pv validate: valid.

Agent: aprender-89

noahgift and others added 2 commits September 29, 2026 00:16
…w receipt so its patch-id binds the final diff

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

# Conflicts:
#	.github/workflows/nightly.yml
#	docs/roadmaps/roadmap.yaml
…se-folded

Independent pr-review (Sonnet 5) at 0ba69a1 found, measured:
- an unquoted all-digit sha256 is a YAML int: it passed the 64-hex check via
  str() and then crashed SHA_KEY + int with TypeError. Now a FAIL row.
  New case red-cells-declaimed-file-sha-int + mutant declaim-sha-int (killed).
- declaim_of / model_ladder.sh gone() compared inventory sha case-sensitively
  against the lowercase-only declaration; both now lower() the inventory side.
Self-test: 159 cases, 0 bad (declaim-by-name/widen/sha-hex re-anchored).

Refs #3715

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…und to patch-id 9e2c2357

Reviewer claude-sonnet-5 (author claude-opus-5-5). Verdict FINDINGS: 5 advisory, 0 blocking
(measured 4, asserted 1). Consultations pmat/cuda/crux/mutation (148/148 killed)/agy
(gemini-3.1-pro-high) all consulted. It supersedes the 0ba69a1 receipt (committed here as
evidence). The receipt is unsigned; the ci pr-review-sign job signs it.

Agent: aprender-89
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Base automatically changed from 0d/3715-b1-main to split/ont10-rest-0.70 September 29, 2026 20:03
noahgift added a commit that referenced this pull request Oct 3, 2026
…rename release:ModelCell

Re-ran the hotspot check that §4 requires before B2 and OBS-05, git only,
against origin/main 316dee2. Trial merges used the old git merge-tree,
with one positive and two negative controls. Every conflict in B2 (6 code
files) and OBS-05 (ontology/shapes.rs) comes from one commit, 989cb01
(fold(0.70) #4655). Of the added lines in the ONT-10 PR heads,
#4587/#4588/#4589/#4611 have 99-100% on main and #4615 has 93%; the
not-on-main controls score 2.6% and 11.2%. So the "after ONT-10" condition
is met in content.

B2 duplicates nothing on main, but the class release:ModelCell now means
two things. On main, v1 (since 989cb01) uses it for a non-generating
model-command cell whose shape requires release:row. Seg 7's v2 uses it for
a cell derived from kernel cells whose shape requires release:usesKernel.
B2 renames its class before the PR. This is a static reading; no cargo
was run (C277).

Agent: la-0.71
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

noahgift commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Closed: grows build-path Python, against the operator ruling of 2026-10-04. The work returns as a Rust port (the build-path Python port ticket). Branch kept.

@noahgift noahgift closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant