Skip to content

Commit 0f3ea5e

Browse files
author
HiddenTrojan
committed
Repair Experiment 013 runtime context contract
1 parent 84edf42 commit 0f3ea5e

6 files changed

Lines changed: 384 additions & 28 deletions

research/EXPERIMENT_013_STATIC_RHT_Q468_PROTOCOL.md

Lines changed: 66 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,25 @@
11
# Experiment 013: static RHT-Q468 packed-native adoption protocol
22

3-
> **Status: replacement-H0 candidate after a preserved pre-model authorization
4-
> failure; not yet re-preregistered.**
3+
> **Status: second replacement-H0 candidate after a preserved pre-model
4+
> sealed-smoke contract failure; not yet re-preregistered.**
55
>
66
> This replacement working copy becomes the next frozen Experiment 013
77
> preregistration only when its exact bytes and dependencies are committed in a
88
> clean source commit H0 and that H0 is bound before any further identity
9-
> resolution, policy fitting, protected materialization, model-weight loading,
10-
> or quality measurement. A dirty or unbound working copy is not a frozen
11-
> protocol.
9+
> resolution, model staging or loading, policy fitting, protected
10+
> materialization, or quality measurement. A dirty or unbound working copy is
11+
> not a frozen protocol.
1212
>
1313
> The amendment history is retained below, but its rules remain candidate rules
1414
> until that H0 binding. Prior identities, token spans, tokenizer-file hashes,
1515
> and content hashes remain preserved as superseded evidence under the disclosed
16-
> reuse rule; the replacement identity has not yet been resolved or promoted.
17-
> An identity candidate is not authorization to load model weights.
16+
> reuse rule; the next replacement identity has not yet been resolved or
17+
> promoted. An identity candidate is not authorization to stage or load model
18+
> weights.
1819
1920
Protocol draft initiated: 2026-08-02
2021

21-
Current replacement-H0 candidate amended: 2026-08-15
22+
Current second replacement-H0 candidate amended: 2026-08-15
2223

2324
Pre-resolution audit amendment: 2026-08-02. The amendment corrects a
2425
cache-exposed-span off-by-one, binds the Stage-A calibration chain by exact
@@ -322,6 +323,62 @@ promotion-hash cascade may differ. Any inventory, byte, hash, version, or
322323
semantic-identity mismatch stops reuse and requires a separately preregistered
323324
fresh complete batch after the replacement H0.
324325

326+
Fourteenth pre-resolution adapter-context amendment: 2026-08-15. Under source
327+
commit `85625a5c4e4d7c6d1b015c0f3cccffea5c3d71c3`, tag
328+
`experiment013-h0-85625a5`, and identity-only descendant
329+
`84edf4299e8a5b3af970f74f03abc099d3696904`, the identity-bound `stage-model`
330+
step published a local copy of the exact three-file pinned model. Its frozen
331+
identity file SHA-256 is
332+
`e401a3c18a002626da096ba6ba86aa5d297d16b5c8ab76711658ce730e5a5f77`.
333+
The first sealed `--fisher-h1-smoke` attempt then authenticated the sealed
334+
runtime, H0 source, the frozen identity bytes committed at H1, and all four
335+
bound manifest byte strings. It parsed and matched the public model-file
336+
metadata but failed deterministically
337+
while initializing `AdapterConstructionContext`: calibration-runner v3 supplied
338+
the inert absolute `git_executable` path that capture procedure v6 requires,
339+
while the authenticated calibration API's exact runtime-context key set omitted
340+
that key.
341+
342+
The failed smoke did not reach reviewed-adapter loading or construction,
343+
calibration materialization, tokenizer, dataset, or RULER access, staged-model-
344+
root traversal or file hashing, model configuration or weight deserialization,
345+
CUDA or Fisher execution, or output-directory checking or publication. It
346+
created no smoke output or staging sibling and produced no smoke report,
347+
completion marker, score, policy, calibration binding, stability value, or
348+
quality result. The separately completed `stage-model` action did access and
349+
publish the model payload under H1; the failed smoke itself did not read that
350+
published model root. This is a downstream execution-contract defect, not an
351+
experimental result or infrastructure interruption. The H0, tag, H1, identity,
352+
and staged model root remain unchanged as superseded incident evidence and
353+
authorize no further official execution.
354+
355+
Calibration-runner v4 aligns the authenticated API with capture v6's existing
356+
five-key runtime context. The API now accepts, validates, copies, and retains
357+
the absolute inert Git path while preserving exact-key rejection and recursive
358+
mapping immutability. Production `_official_main` and the regression share one
359+
context-construction helper; the regression loads the exact authenticated API
360+
and reviewed adapter and checks that construction creates none of its model,
361+
cache, RULER, or bytecode sentinel paths. A separate no-data boundary
362+
regression carries the same context through the real adapter into the
363+
manifest-bound capture module and stops before artifact decoding, Hub,
364+
tokenizer, or dataset access. No record selection, dataset revision, token
365+
span, Fisher boundary, quantization policy, metric, gate, model contract, or
366+
protected-stage rule changes.
367+
368+
Runner revision advances from v3 to v4. Identity schema v5; capture and
369+
resolver procedure v6; adapter revision v2; RULER launcher v7, generation-
370+
manifest v2, and runtime-manifest v3; calibration runtime-manifest v4; source-
371+
manifest schema/profile v2; model-manifest v1; frozen-contract and model-
372+
staging-authorization stdout schemas v1; run-report v2; and Fisher-boundary and
373+
smoke-marker contracts v1 remain unchanged. A new clean H0, repository-source
374+
manifest, promoted calibration identity, H1, and identity-bound model
375+
publication are required. The exact authenticated RULER v7 batch, sealed
376+
runtime, public model metadata manifest, Parquet manifest, and shared Hub cache
377+
may be reused only after their existing byte, inventory, and semantic checks
378+
pass unchanged. The old H1 model root may be treated only as preserved incident
379+
evidence, not as the official model root for the next H1; a fresh no-overwrite
380+
root must be published by a newly authorized `stage-model` execution.
381+
325382
## Question
326383

327384
Can a calibration-frozen, static Q4/Q6/Q8 recurrent-state layout satisfy the
@@ -717,7 +774,7 @@ Before committing H1, the exact promoted identity bytes in their ignored,
717774
no-overwrite precommit location must pass `verify-frozen-identity-contract`.
718775
That read-only command authenticates H0 and its source manifest, loads the exact
719776
H0 resolver, and consumes the complete record inventory through calibration-
720-
runner v3's identity view. It accepts no H1, model manifest, Hub, cache, or
777+
runner v4's identity view. It accepts no H1, model manifest, Hub, cache, or
721778
output argument. Its non-persisted canonical JSON stdout document uses artifact
722779
kind `recurquant_experiment013_frozen_identity_contract_verification`, schema
723780
version one, and binds the H0/source contract, portable Git identity, all four

scripts/run_static_q468_calibration.py

Lines changed: 50 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@
5656
CANONICAL_ADAPTER_MODULE: Final = "recurquant.experiment013_qwen35_adapter"
5757
CANONICAL_ADAPTER_PATH: Final = "src/recurquant/experiment013_qwen35_adapter.py"
5858

59-
RUNNER_REVISION: Final = "experiment-013-static-q468-calibration-runner-v3"
59+
RUNNER_REVISION: Final = "experiment-013-static-q468-calibration-runner-v4"
6060
FROZEN_IDENTITY_SCHEMA_VERSION: Final = 5
6161
FISHER_BOUNDARY_SCHEMA: Final = "recurquant.experiment013.fisher-boundary.v1"
6262
FISHER_BOUNDARY_NAMESPACE: Final = b"recurquant.experiment013.fisher-boundary.v1\0"
@@ -5486,6 +5486,43 @@ def _install_authenticated_recurquant_namespace(repository_root: Path) -> Module
54865486
return package
54875487

54885488

5489+
def _adapter_construction_context(
5490+
*,
5491+
calibration_api: ModuleType,
5492+
repository_root: Path,
5493+
model_root: Path,
5494+
cache_root: Path,
5495+
ruler_root: Path,
5496+
repository_source_manifest_bytes: bytes,
5497+
calibration_runtime_manifest_bytes: bytes,
5498+
model_file_manifest_bytes: bytes,
5499+
parquet_materialization_manifest_bytes: bytes,
5500+
runtime_context: SealedRuntimeContext,
5501+
interpreter_path: Path,
5502+
) -> Any:
5503+
"""Build the exact authenticated context consumed by the reviewed adapter."""
5504+
5505+
return calibration_api.AdapterConstructionContext(
5506+
repository_root=Path(repository_root),
5507+
model_root=Path(model_root),
5508+
cache_root=Path(cache_root),
5509+
ruler_root=Path(ruler_root),
5510+
execution_binding_artifacts={
5511+
"repository_source_manifest_bytes": bytes(repository_source_manifest_bytes),
5512+
"calibration_runtime_manifest_bytes": bytes(calibration_runtime_manifest_bytes),
5513+
"model_file_manifest_bytes": bytes(model_file_manifest_bytes),
5514+
"parquet_materialization_manifest_bytes": bytes(parquet_materialization_manifest_bytes),
5515+
},
5516+
runtime_authentication_context={
5517+
"base_runtime_root": runtime_context.base_runtime_root,
5518+
"git_executable": runtime_context.git_executable_path,
5519+
"staged_interpreter": Path(interpreter_path),
5520+
"package_runtime_roots": dict(runtime_context.package_roots),
5521+
"package_import_paths": dict(runtime_context.package_import_paths),
5522+
},
5523+
)
5524+
5525+
54895526
def _load_adapter(
54905527
specification: str,
54915528
*,
@@ -5923,24 +5960,18 @@ def _official_main(
59235960
raise CalibrationRunError("runtime authenticator returned a different manifest identity")
59245961
model_manifest = parse_model_file_manifest(model_manifest_bytes)
59255962
_model_contract_matches(identity, model_manifest)
5926-
context = _AUTHENTICATED_CALIBRATION_API.AdapterConstructionContext(
5927-
repository_root=Path(args.repository_root),
5928-
model_root=Path(args.model_root),
5929-
cache_root=Path(args.cache_root),
5930-
ruler_root=Path(args.ruler_root),
5931-
execution_binding_artifacts={
5932-
"repository_source_manifest_bytes": bytes(source_manifest_bytes),
5933-
"calibration_runtime_manifest_bytes": bytes(runtime_manifest_bytes),
5934-
"model_file_manifest_bytes": bytes(model_manifest_bytes),
5935-
"parquet_materialization_manifest_bytes": bytes(parquet_manifest_bytes),
5936-
},
5937-
runtime_authentication_context={
5938-
"base_runtime_root": runtime_context.base_runtime_root,
5939-
"git_executable": runtime_context.git_executable_path,
5940-
"staged_interpreter": Path(interpreter_path),
5941-
"package_runtime_roots": dict(runtime_context.package_roots),
5942-
"package_import_paths": dict(runtime_context.package_import_paths),
5943-
},
5963+
context = _adapter_construction_context(
5964+
calibration_api=_AUTHENTICATED_CALIBRATION_API,
5965+
repository_root=args.repository_root,
5966+
model_root=args.model_root,
5967+
cache_root=args.cache_root,
5968+
ruler_root=args.ruler_root,
5969+
repository_source_manifest_bytes=source_manifest_bytes,
5970+
calibration_runtime_manifest_bytes=runtime_manifest_bytes,
5971+
model_file_manifest_bytes=model_manifest_bytes,
5972+
parquet_materialization_manifest_bytes=parquet_manifest_bytes,
5973+
runtime_context=runtime_context,
5974+
interpreter_path=interpreter_path,
59445975
)
59455976
adapter = _load_adapter(
59465977
args.adapter,

src/recurquant/experiment013_calibration_api.py

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@
2626
RUNTIME_AUTHENTICATION_CONTEXT_KEYS = frozenset(
2727
{
2828
"base_runtime_root",
29+
"git_executable",
2930
"package_import_paths",
3031
"package_runtime_roots",
3132
"staged_interpreter",
@@ -70,6 +71,7 @@ def _normalize_runtime_authentication_context(
7071
if not isinstance(value, Mapping) or set(value) != RUNTIME_AUTHENTICATION_CONTEXT_KEYS:
7172
raise ValueError("runtime_authentication_context keys differ from the frozen API")
7273
base_root = _absolute_inert_path(value["base_runtime_root"], name="base_runtime_root")
74+
git_executable = _absolute_inert_path(value["git_executable"], name="git_executable")
7375
interpreter = _absolute_inert_path(
7476
value["staged_interpreter"],
7577
name="staged_interpreter",
@@ -96,6 +98,7 @@ def _normalize_runtime_authentication_context(
9698
return MappingProxyType(
9799
{
98100
"base_runtime_root": base_root,
101+
"git_executable": git_executable,
99102
"package_import_paths": MappingProxyType(import_paths),
100103
"package_runtime_roots": MappingProxyType(package_roots),
101104
"staged_interpreter": interpreter,

tests/test_experiment013_calibration_api.py

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
import pytest
88

99
from recurquant.experiment013_calibration_api import (
10+
RUNTIME_AUTHENTICATION_CONTEXT_KEYS,
1011
AdapterConstructionContext,
1112
AuthenticatedModelFiles,
1213
AuthenticatedSequence,
@@ -32,6 +33,7 @@ def binding_artifacts() -> dict[str, bytes]:
3233
def runtime_context() -> dict[str, object]:
3334
return {
3435
"base_runtime_root": ROOT / "runtime" / "base",
36+
"git_executable": ROOT / "tools" / "git.exe",
3537
"staged_interpreter": ROOT / "runtime" / "base" / "python.exe",
3638
"package_runtime_roots": {"calibration": ROOT / "runtime" / "packages"},
3739
"package_import_paths": {"calibration": "Lib/site-packages"},
@@ -62,6 +64,10 @@ def test_context_copy_normalizes_exact_binding_bytes() -> None:
6264

6365
def test_context_normalizes_and_freezes_runtime_authentication_paths() -> None:
6466
source = runtime_context()
67+
package_roots = source["package_runtime_roots"]
68+
package_import_paths = source["package_import_paths"]
69+
assert isinstance(package_roots, dict)
70+
assert isinstance(package_import_paths, dict)
6571
context = AdapterConstructionContext(
6672
ROOT,
6773
ROOT,
@@ -70,18 +76,43 @@ def test_context_normalizes_and_freezes_runtime_authentication_paths() -> None:
7076
source,
7177
binding_artifacts(),
7278
)
79+
source["git_executable"] = ROOT / "changed-git.exe"
7380
source["package_runtime_roots"] = {}
81+
package_roots["calibration"] = ROOT / "changed-packages"
82+
package_import_paths["calibration"] = "changed/site-packages"
83+
assert set(context.runtime_authentication_context) == RUNTIME_AUTHENTICATION_CONTEXT_KEYS
7484
assert context.runtime_authentication_context["base_runtime_root"] == (
7585
ROOT / "runtime" / "base"
7686
)
87+
assert context.runtime_authentication_context["git_executable"] == (ROOT / "tools" / "git.exe")
88+
assert context.runtime_authentication_context["package_runtime_roots"] == {
89+
"calibration": ROOT / "runtime" / "packages"
90+
}
91+
assert context.runtime_authentication_context["package_import_paths"] == {
92+
"calibration": "Lib/site-packages"
93+
}
7794
with pytest.raises(TypeError):
7895
context.runtime_authentication_context["new"] = ROOT # type: ignore[index]
96+
with pytest.raises(TypeError):
97+
context.runtime_authentication_context["package_runtime_roots"]["new"] = ROOT # type: ignore[index]
98+
with pytest.raises(TypeError):
99+
context.runtime_authentication_context["package_import_paths"]["new"] = "Lib" # type: ignore[index]
79100

80101
malformed = runtime_context()
81102
malformed["package_import_paths"] = {"calibration": "../site-packages"}
82103
with pytest.raises(ValueError, match="not canonical"):
83104
AdapterConstructionContext(ROOT, ROOT, ROOT, ROOT, malformed, binding_artifacts())
84105

106+
relative_git = runtime_context()
107+
relative_git["git_executable"] = Path("git.exe")
108+
with pytest.raises(ValueError, match="git_executable must be an absolute normalized Path"):
109+
AdapterConstructionContext(ROOT, ROOT, ROOT, ROOT, relative_git, binding_artifacts())
110+
111+
missing_git = runtime_context()
112+
missing_git.pop("git_executable")
113+
with pytest.raises(ValueError, match="keys differ"):
114+
AdapterConstructionContext(ROOT, ROOT, ROOT, ROOT, missing_git, binding_artifacts())
115+
85116

86117
def test_adapter_facing_values_have_one_stable_importable_identity() -> None:
87118
sequence = AuthenticatedSequence((1, 2), "a" * 64, "b" * 64, None, "c" * 64)

tests/test_experiment013_qwen35_adapter.py

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ def _context(tmp_path: Path) -> AdapterConstructionContext:
3737
ruler_root=tmp_path / "ruler-does-not-need-to-exist-at-construction",
3838
runtime_authentication_context={
3939
"base_runtime_root": tmp_path / "runtime" / "base",
40+
"git_executable": tmp_path / "tools" / "git.exe",
4041
"staged_interpreter": tmp_path / "runtime" / "base" / "python.exe",
4142
"package_runtime_roots": {"calibration": tmp_path / "runtime" / "packages"},
4243
"package_import_paths": {"calibration": "Lib/site-packages"},
@@ -244,6 +245,7 @@ def materialize(
244245
assert materialization_references[0]() is None
245246
assert adapter._execution_binding_artifacts is None
246247
assert adapter._runtime_authentication_context is None
248+
assert runtime_calls[0]["git_executable"] == (tmp_path / "tools" / "git.exe")
247249
assert runtime_calls[0]["staged_interpreter"] == (tmp_path / "runtime" / "base" / "python.exe")
248250
assert set(adapter._materialized_sequences or {}) == {_sha(index + 1) for index in range(160)}
249251
assert all(

0 commit comments

Comments
 (0)