Skip to content

V4.1: Engram arms by image config digest (A upstream pinned, B production file-backed); production image receipt row; differential bound to it; DeepSelect as image capability - #12331

Merged
briansrls merged 5 commits into
mainfrom
session/clever-gull-48-arms
Sep 27, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #12303, based on proud-deer-538's report that the arm A image is built.

  • Arm A is bound. The binding points at the pre-V4.1 Engram file-backed: release verify page cache (fail-closed on residue); batched fetch_rows gather #12304 srv8 image, fleet-converge run 36207135528, config sha256:ea39410ed01d396caad86339d877c1adb181a983baadffd22c722069109ea664. Arms are now keyed on the image config digest, which is the same digest every rank's startup receipt carries (V41OciImageDigest), so a receipt's arm can be read off its own image. Previously they were keyed on a patch digest. An image with zero or more than one binding has no arm. v41_engram_arm_binding_frontier now names only arm B, the image built from main after V4.1 Engram file-backed: release verify page cache (fail-closed on residue); batched fetch_rows gather #12304.
  • DeepSelect as an image capability fact. The image logged Failed to import the DeepSelect extension (vllm._deepselect_C), which is the indexer top-k kernel, so vLLM may take a slower fallback that could dominate TTFT at 262k. Each rank's startup reading now carries V41ImageExtensionStanding: ExtensionLoaded, ExtensionImportFailed { logged } (recorded and admitted), or ExtensionUnobserved, which refuses by name like every other missing reading.

Evidence: claim_batch … --entry dag/test/claim/spark/v41_capacity_measurement_witness_test.dag gives 25/25 PASS in-session. Two new claims cover the arm resolution (bound versus unbound image) and the DeepSelect refusal.

🤖 Generated with Claude Code

Brian Searls and others added 2 commits September 26, 2026 02:20
…mport as an image capability fact

Arm A is the pre-#12304 image from run 36207135528 (config
sha256:ea39410e...). Arms are keyed on the image config digest every rank's
startup receipt carries, instead of a patch digest. Each rank's startup
reading records whether vllm._deepselect_C loaded, failed to import (a
recorded fact), or was not observed (refuses). 25/25 witness claims.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Review 71462: the recorded DeepSelect import had no reader. The capacity
report now names the kernel its figures ran on; a failed import on any rank
reaches it with the logged line. 26/26 witness claims.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Review 71462 (/api/reviews/71462/artifacts/stdout.log). Taking the two observations in order:

  • DeepSelect result has no reader: fixed in b33399f. V41CapacityReport now carries indexer_kernel (via v41_report_indexer_kernel). If any rank's import failed, the report states it with that rank's logged line. A refused startup receipt leaves it ExtensionUnobserved. A new claim covers both arms; 26/26 pass in-session.
  • Arm A digest typed in by hand: keeping it as is. It is the full config digest from the build run's report, with the build run (36207135528) recorded beside it as provenance. Reading it from the image directly belongs to the wet fleet mode, which reads each rank's image digest into its startup receipt. v41_engram_arm_of then joins that observed digest against this binding, so a mistyped digest makes every arm-A cell unresolvable. It cannot resolve silently to the wrong arm.
    — sent from clever-gull-48

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 26, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Sep 26, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Hold: do not merge. The arm A binding here is a false fact. The image from run 36207135528 does not serve file-backed Engram: on main, ParallelEngramEmbedding._allocate_weights still constructs upstream DPSharedEngramStorage (engram_storage_backed.patch only imports the file-backed names). So binding it as EngramCacheRetained misnames what that image runs. I've proposed a fix to proud-deer-538: rename the arm to upstream-pinned, and make the _allocate_weights cutover its own PR. I'll rework this PR once that's decided.
— sent from clever-gull-48

@gunbai-bot
gunbai-bot Bot marked this pull request as draft September 26, 2026 04:50
…ckedReleased

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he images serve

Arm A is EngramUpstreamPinned (images built before the design-B cutover serve
upstream DPShared/pinned storage); arm B is EngramFileBackedReleased (the first
image after the cutover). 28/28 witness claims.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 27, 2026 07:32
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Reworked and un-held at 47c53a3. main is merged in, and the arms are renamed to what the images actually serve, as agreed with proud-deer-538:

@briansrls
briansrls added this pull request to the merge queue Sep 27, 2026
@gunbai-bot gunbai-bot Bot changed the title V4.1 capacity: bind Engram arm A by image config digest; DeepSelect as an image capability fact V4.1: Engram arms by image config digest (A upstream pinned, B production file-backed); production image receipt row; differential bound to it; DeepSelect as image capability Sep 27, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Extended at 1545847 with the production V4.1 image (fleet-converge run 36327364664 on srv8: tag gunbc-vllm-dsv41-gb10:3cedb66f0ec0869e, config sha256:5de3c355…, source_head d2d649e6, worktree_diff_sha256 e967c379…, all read from that run's receipt):

  1. v41_runtime_image_converge v41_production_produced_image: the held receipt row. spark_v41_runtime_image_distribute now moves this image, and a witness checks that the row re-derives the printed tag through the build's key fold.
  2. v41_engram_differential_run v41_differential_image is bound to the production image, so the differential runs the overlay module from it.
  3. Arm B (EngramFileBackedReleased) is bound to the production image in v41_capacity_measurement, and the binding frontier is dissolved.
    Witnesses in-session: distribution 9/9, differential 6/6, capacity measurement 29/29.
    — sent from clever-gull-48

@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Correction to my previous comment: that push was rejected, because this PR is in the merge queue at 47c53a3 and queued branches can't be updated. This PR lands as queued: the arms renamed to what the images serve, plus DeepSelect. The production-image receipt row, the differential binding and arm B are in #12416, which builds on this PR.
— sent from clever-gull-48

Merged via the queue into main with commit 7352575 Sep 27, 2026
5 of 14 checks passed
@briansrls
briansrls deleted the session/clever-gull-48-arms branch September 27, 2026 18:00
gunbai-bot Bot pushed a commit that referenced this pull request Sep 27, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant