You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
consumed h86-* evidence remains diagnostic-only and permanently ineligible for this campaign.
This issue authorizes physical reference/candidate calibration execution and, only after a later explicit maintainer authorization in this issue, the single-use h95 holdout unseal and holdout execution.
verify every committed v4 methodology/schema/manifest hash from main;
verify the h95 ciphertext, certificate, custody-record bytes, and external custody remain exactly the frozen identities;
perform an applicability census of the physical reference/candidate environments against the frozen subject. Any material correctness-relevant dependency drift stops the campaign for maintainer adjudication rather than silently changing the subject.
No physical result may be used to modify the methodology, sample size, tier classification, threshold rule, decision-domain construction, semantic theorem, or holdout.
Frozen physical subject
Retain the issue #95 subject unless pre-execution applicability validation stops the campaign:
Capture exact node/device/software/backend/topology identity before execution and bind it into evidence.
Frozen v4 statistical / comparator contract
Statistical calibration
c95: exactly 1,896 cases;
exactly 24 frozen population cells;
exactly 79 independent cases/cell;
independent unit = case;
selected stress contributes zero predictive sample size.
Stress
p95: exactly 48 reference-only cases, 2/cell;
compute the frozen reference margin only;
reject negative/nonfinite margins according to the frozen selector contract;
select exactly four smallest finite nonnegative margins + four largest;
deterministic case-ID tie break;
freeze/commit/push/refetch the selected-eight identity before candidate stress execution.
Acceptance-bearing core
Exactly four scalar families:
fp32-consumer-logits:max-absolute-difference;
fp32-consumer-logits:rms-difference;
fp32-consumer-logits:p99-absolute-error;
decision_local_E_D / per-case max over all 8 canonical-prefix decisions.
Mandatory telemetry
Exactly the twelve internal family/metric identities classified by accepted #93. They remain mandatory retained evidence, but a finite reference-band exceedance alone is not a qualification failure.
NaN/Inf at any finite_required identity remains fail-closed.
Phase A — physical calibration
A1. Reference execution
Run the frozen reference path for:
all 1,896 c95 statistical cases;
all 48 p95 stress-pool cases.
For each applicable decision/case retain the evidence required by #95, including:
all twelve mandatory telemetry identities retained.
Telemetry reference-band exceedances are recorded as TELEMETRY_ALERT but do not independently fail qualification.
Any valid acceptance-bearing holdout failure is terminal. No post-result tuning, resealing, replacement holdout, or valid-failure rerun is permitted.
Invalid-run policy
A rerun is allowed only for evidence-supported invalid execution (for example interrupted transport, node failure, corrupt/incomplete artifact production, or demonstrable applicability violation before a valid result exists).
If an execution produced a valid correctness-bearing observation, an unfavorable result is not an invalid run and cannot be rerun away.
Preserve invalid-run evidence and reason codes rather than deleting inconvenient attempts.
Final evidence / verdict
Retain a machine-readable and human terminal report with exact producer/provenance hashes and complete core/telemetry/semantic accounting.
Use a narrow terminal result, for example:
V4_QUALIFICATION_PASS;
V4_CALIBRATION_INTEGRITY_FAIL;
V4_CALIBRATION_SEMANTIC_FAIL;
V4_CALIBRATION_APPLICABILITY_BLOCKED;
V4_HOLDOUT_CORE_FAIL;
V4_HOLDOUT_SEMANTIC_FAIL;
V4_HOLDOUT_INTEGRITY_FAIL;
V4_HOLDOUT_APPLICABILITY_FAIL.
Do not reuse #88's verdict identity and do not reinterpret #88.
Objective
Execute the first physical Gemma v4 qualification campaign under the methodology frozen by issue #95 / PR #96.
Accepted starting point:
NUMERICAL_CORE_TWO_TIER_DOCTRINE_ACCEPTED;GEMMA_V4_PREDICTION_ALIGNED_METHODOLOGY_FROZEN;e056b2ae46f4c36da8ae93a3beb0b38c820a283e;e12a6e3d5589044bace0c9555c0d364fb57a6229;V3_HOLDOUT_FAIL;h86-*evidence remains diagnostic-only and permanently ineligible for this campaign.This issue authorizes physical reference/candidate calibration execution and, only after a later explicit maintainer authorization in this issue, the single-use h95 holdout unseal and holdout execution.
Do not change the frozen methodology.
Pre-execution synchronization
Before any CUDA/model execution:
ROADMAP.mdfrom the stalepending maintainer acceptancewording to accepted Gemma v4 methodology: freeze prediction-aligned two-tier qualification before physical execution #95 state;e12a6e3d5589044bace0c9555c0d364fb57a6229and terminal methodology disposition;No physical result may be used to modify the methodology, sample size, tier classification, threshold rule, decision-domain construction, semantic theorem, or holdout.
Frozen physical subject
Retain the issue #95 subject unless pre-execution applicability validation stops the campaign:
google/gemma-4-12B-it;707f0a3b8a3c7ad586ed01e27eafbad8a27dd0f7;5a84cb313260ac447237b890387116dfa8682e49a6b44bc585ae8353abbff18d;<=64row regime;Capture exact node/device/software/backend/topology identity before execution and bind it into evidence.
Frozen v4 statistical / comparator contract
Statistical calibration
Stress
Acceptance-bearing core
Exactly four scalar families:
fp32-consumer-logits:max-absolute-difference;fp32-consumer-logits:rms-difference;fp32-consumer-logits:p99-absolute-error;decision_local_E_D/ per-case max over all 8 canonical-prefix decisions.Mandatory telemetry
Exactly the twelve internal family/metric identities classified by accepted #93. They remain mandatory retained evidence, but a finite reference-band exceedance alone is not a qualification failure.
NaN/Inf at any
finite_requiredidentity remains fail-closed.Phase A — physical calibration
A1. Reference execution
Run the frozen reference path for:
For each applicable decision/case retain the evidence required by #95, including:
No candidate observation may influence stress selection or decision-domain membership.
A2. Freeze selected stress
Mechanically apply the frozen selector to p95 reference evidence.
Commit, push, and byte-refetch:
Only the selected eight receive candidate stress execution.
A3. Candidate calibration execution
Run the frozen heterogeneous candidate for:
Candidate execution must be teacher-forced on the exact reference canonical prefix at all 8 decisions.
Retain:
Calibration adjudication
After complete valid calibration evidence, use only the frozen issue #95 evidence-consuming deriver.
It must independently:
case_E_D;Core and telemetry reducers remain prospectively frozen as
max(statistical_max, selected_stress_max).Calibration must stop before holdout unless all of the following pass
DECISION_DOMAIN_ESCAPE;E_Dderived without manual edit/rounding;SEALED_NOT_CONSUMED.A valid calibration failure is terminal for this campaign. Do not tune and retry.
Mandatory holdout stop / maintainer gate
After threshold/band freeze and successful non-decrypting h95 preflight, STOP.
Do not decrypt h95 yet.
Post a maintainer-review checkpoint containing at minimum:
PRECONDITIONS_PASS_STOP_BEFORE_DECRYPTor precise failure;Use a narrow ready state such as:
V4_HOLDOUT_UNSEAL_READYOnly an explicit maintainer authorization after reviewing this checkpoint may continue to Phase B.
Phase B — single-use h95 holdout (not authorized until maintainer says so)
After explicit maintainer authorization only:
Holdout acceptance
A successful campaign requires every one of the 24 holdout cases to satisfy:
observed <= limit;DECISION_LOCAL_BOUND_EXCEEDED;DECISION_DOMAIN_ESCAPE;Telemetry reference-band exceedances are recorded as
TELEMETRY_ALERTbut do not independently fail qualification.Any valid acceptance-bearing holdout failure is terminal. No post-result tuning, resealing, replacement holdout, or valid-failure rerun is permitted.
Invalid-run policy
A rerun is allowed only for evidence-supported invalid execution (for example interrupted transport, node failure, corrupt/incomplete artifact production, or demonstrable applicability violation before a valid result exists).
If an execution produced a valid correctness-bearing observation, an unfavorable result is not an invalid run and cannot be rerun away.
Preserve invalid-run evidence and reason codes rather than deleting inconvenient attempts.
Final evidence / verdict
Retain a machine-readable and human terminal report with exact producer/provenance hashes and complete core/telemetry/semantic accounting.
Use a narrow terminal result, for example:
V4_QUALIFICATION_PASS;V4_CALIBRATION_INTEGRITY_FAIL;V4_CALIBRATION_SEMANTIC_FAIL;V4_CALIBRATION_APPLICABILITY_BLOCKED;V4_HOLDOUT_CORE_FAIL;V4_HOLDOUT_SEMANTIC_FAIL;V4_HOLDOUT_INTEGRITY_FAIL;V4_HOLDOUT_APPLICABILITY_FAIL.Do not reuse #88's verdict identity and do not reinterpret #88.
Deliverables
Before the holdout-ready checkpoint:
After authorized holdout execution:
Non-negotiable constraints
Exit criteria
This issue is complete only after either:
Do not merge an evidence PR before maintainer adjudication of the applicable terminal state.