Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
07f5917
WIP: onboard OpenRouter Nemotron 3 Ultra free as a quota-leased harne…
Oct 5, 2026
c1a915f
Fix type errors found by the witness run; thread the hosted unit thro…
Oct 5, 2026
54da7c1
Model the OpenRouter key read as a workload accessor grant; classify …
Oct 5, 2026
f7dd0b5
Name the fabric state key row in the roster identity join (red since …
Oct 5, 2026
1731de7
Merge remote-tracking branch 'origin/main' into session/neat-lark-813
Oct 5, 2026
232c3bc
Type the listing's per-token price as std.measure MoneyAmountMicro (r…
Oct 5, 2026
ea01cbb
Codex + Cursor harness credentials from gunbai-secrets (slice 1)
Oct 5, 2026
26f2c3f
Carry the key-read deadline as Second and the hosted max_tokens as To…
Oct 5, 2026
87d7aa3
Codex via single-host custody with write-back; Cursor custody; grants…
Oct 5, 2026
3ae082e
Drive Claude (subscription setup-token) from belt dispatch via an exp…
Oct 5, 2026
36da686
Merge branch 'pr13367' into session/swift-stag-32
Oct 5, 2026
ca25bc2
Refuse malformed optional stream-json members; one argv encoding; dec…
Oct 5, 2026
c4791c8
Wire Codex and Cursor worker turns into the dispatch spawn; fix parse…
Oct 5, 2026
84937e7
Admit flock_program to the program roster; retarget codex-on-srv1 wit…
Oct 5, 2026
6efe115
Admit the env-var name as a POSIX shell name before it reaches the sh…
Oct 5, 2026
f85b975
Merge branch 'pr13367' into session/swift-stag-32
Oct 5, 2026
b3321e2
Merge #13367 fix (PosixShellName); Cursor spawn admits its env-var name
Oct 5, 2026
aa24780
Emit the export-and-exec sh program from the bash grammar; retire the…
Oct 5, 2026
6c1a8c2
Merge branch 'pr13367' into session/swift-stag-32
Oct 5, 2026
cf0e9c8
Merge #13367 aa24780 (emitted sh program); Cursor spawn matches its r…
Oct 5, 2026
b693062
Charge hosted requests to both quota pools before sending, with windo…
Oct 5, 2026
76d7e4e
Bind one credential snapshot from admission to child load; select on …
Oct 5, 2026
e36db9a
WIP: custody-bound observed standing for Codex and Cursor (pre-merge)
Oct 5, 2026
0d28238
Merge branch 'pr13367' into session/swift-stag-32
Oct 5, 2026
426912d
Codex standing trip runs through the admitted press invocation with a…
Oct 5, 2026
c3d6a2c
Lab witness: the Claude spawn reads the attempt's credential snapshot
Oct 5, 2026
747619a
Check quota settle/observe against the folded pool before appending; …
Oct 5, 2026
51bfcbc
Snapshot removal is a precondition of exec; one owner discards it on …
Oct 5, 2026
8292555
Merge branch 'pr13367' into session/swift-stag-32
Oct 5, 2026
d70d436
Merge #13367 51bfcbc (belt-owned snapshot discard); Cursor abandonmen…
Oct 5, 2026
6582f88
Count hosted sends still in flight across a window rollover against t…
Oct 6, 2026
f6fadf6
Merge remote-tracking branch 'origin/main' into session/swift-stag-32
Oct 6, 2026
d2881e3
Port merged-main changes: REST result shape in codex write-back; expl…
Oct 6, 2026
ca4932a
Regenerate fleet-converge.yml on the merged tree (custody credential …
Oct 6, 2026
35fa5bd
Merge remote-tracking branch 'origin/main' into session/swift-stag-32
Oct 6, 2026
bbc0585
Make the upstream 429 the typed backstop; drop the send-admission che…
Oct 6, 2026
5e10b39
Merge remote-tracking branch 'origin/main' into session/neat-lark-813
Oct 6, 2026
c22f4bb
Address review 76922: honest quota-full wording, typed secret-fetch c…
Oct 6, 2026
7dec906
Retry-After is delay-seconds only when it is 1*DIGIT; signed, fractio…
Oct 6, 2026
531697e
An unread curl header dump is carried as unknown, not reported as no …
Oct 6, 2026
51b26ab
Merge main (incl. #13367) into session/neat-lark-813
Oct 6, 2026
6ad0c59
Merge origin/main (#13367) into session/swift-stag-32
Oct 6, 2026
035cd96
Update Claude dispatch witness matches for the Codex/Cursor inner-arg…
Oct 6, 2026
ca6ad6a
Custody: host-authoritative files repair metadata in place and publis…
Oct 6, 2026
ff14668
Custody converge: import RemoteFileModeOwnerReadWrite for the owner-r…
Oct 6, 2026
462ed65
Merge origin/main into session/swift-stag-32; repoint v2.std.optional…
Oct 7, 2026
59e4de9
Merge origin/main into session/swift-stag-32
Oct 7, 2026
613b4a9
Merge branch 'main' into session/neat-lark-813
briansrls Oct 7, 2026
5e02f01
Merge origin/main; tmux-ls witness compares through any() instead of …
Oct 7, 2026
0f3d7ea
Import Present/Absent from std.optional in the hosted witness file (v…
Oct 7, 2026
e5a6115
Merge main into session/neat-lark-813
Oct 8, 2026
2c2e3e1
Merge origin/main into session/swift-stag-32; union custody roster, r…
Oct 8, 2026
957afe1
Merge #13357 (neat-lark-813) into session/swift-stag-32; union access…
Oct 8, 2026
21298e3
Merge origin/main into session/swift-stag-32; take main's tmux-ls wit…
Oct 8, 2026
4a056e8
Restore branch changes to roadmap_dispatch_actuator_witness_test lost…
Oct 9, 2026
4b1564a
Merge #13357 (OpenRouter Nemotron 3 Ultra free hosted route) into int…
Oct 9, 2026
ab84964
Merge #13359 (Codex + Cursor CLI worker turns) into integration/swift…
Oct 9, 2026
9af02c8
Regenerate fleet-converge.yml via generated_artifact_gate main_wet
Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/fleet-converge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ on:
credential:
description: "host_credential_custody_converge only: which rostered custody row to deliver (gunbc.host_credential_custody_converge). A closed choice, never a free-text secret name: each option carries its own SecretRef, path, owner, group, mode and directory, and a row scoped to one host refuses any other"
required: false
options: [controller_app_key, approval_ntfy_publisher_token, fabric_state_writer_key, oracle_oci_api_signing_key, claude_code_oauth_harness_token]
options: [controller_app_key, approval_ntfy_publisher_token, fabric_state_writer_key, cursor_worker_turn_api_key, codex_worker_turn_auth, oracle_oci_api_signing_key, claude_code_oauth_harness_token]
type: choice
d0_consent:
description: "pair_serving_d0 only (Cut D, Group A on srv1; expected_revision is required and frozen with the filing): the escalation id the consent is filed under. It names the transaction, and a rerun after a crash MUST name the same id to find its frozen filing and held claim -- a fresh id is a new consent"
Expand Down
1 change: 1 addition & 0 deletions dag/extdeps/exec/program.dag
Original file line number Diff line number Diff line change
Expand Up @@ -185,6 +185,7 @@ fn uncataloged_program(invocation: NonEmptyStr) -> ProgramIdentity
decl_ref(module_path: "extdeps.tools.uname", decl_name: "uname_program"),
decl_ref(module_path: "extdeps.tools.squashfs_tools", decl_name: "unsquashfs_program"),
decl_ref(module_path: "extdeps.tools.util_linux_umount", decl_name: "umount_program"),
decl_ref(module_path: "extdeps.tools.util_linux_flock", decl_name: "flock_program"),
decl_ref(module_path: "extdeps.systemd.systemctl", decl_name: "systemctl_path_resolved_program"),
decl_ref(module_path: "extdeps.systemd.systemd_run", decl_name: "systemd_run_program"),
decl_ref(module_path: "extdeps.ntfy.serve", decl_name: "ntfy_version_command"),
Expand Down
34 changes: 34 additions & 0 deletions dag/extdeps/http/client.dag
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,13 @@ fn http_client_get_unix_socket_argv(socket: NonEmptyStr, url: NonEmptyStr, max_t
// for endpoints that read application/x-www-form-urlencoded (the OAuth token endpoint among
// them), one content-type line differs, and the body still rides --data @{file} so a client
// secret in the form body is never an argv word (gunbc.credential_argv_exposure).
// PostJsonFromFileWithHeaderFile IS PostJsonFromFile FOR AN ENDPOINT THAT AUTHENTICATES, with the
// credential carried exactly as GetFollowRedirectsBoundedWithHeaderFile carries it: one header line in
// a caller-owned file read by curl -H @file, so the bearer is never an argv word
// (gunbc.credential_argv_exposure) and the body still rides --data @{file}. --fail-with-body keeps an
// error status's body, which is where a hosted API's typed refusal lives. The response headers are dumped
// to a caller-owned file (curl -D) because a refusal's retry hints (Retry-After, X-RateLimit-*) are headers
// and --fail-with-body returns only the body.
// PostStdinWithinUnixSocket, THE SAME BOUNDED POST OVER A UNIX SOCKET (curl --unix-socket, curl(1)):
// the URL still names the scheme, authority and path the server routes on, but the connection is
// made to the socket file and the kernel attests the caller to the server. The exit codes are
Expand Down Expand Up @@ -309,6 +316,33 @@ service http.Client {
}
}

operation PostJsonFromFileWithHeaderFile {
requires Network
input { url: NonEmptyStr, request_body_file: NonEmptyStr, header_file: NonEmptyStr, response_headers_file: NonEmptyStr, max_seconds: NonEmptyStr }
output { body: String from "stdout", success: Bool from "exit_success" }
transport shell {
argv: [
"curl",
"--fail-with-body",
"-sS",
"--max-time", "{max_seconds}",
"-D", "{response_headers_file}",
"-X", "POST",
"{url}",
"-H", "Content-Type: application/json",
"-H", "@{header_file}",
"--data", "@{request_body_file}",
]
}
exit {
0 => Unit
nonzero => String "curl POST JSON from file with header file failed"
}
mock_response {
0 => { body: "", success: false } "hermetic: no live endpoint; a transport that never connects, so the caller answers unreachable rather than fabricating a completion"
}
}

operation PostFormFromFile {
input { url: NonEmptyStr, request_body_file: NonEmptyStr, max_seconds: NonEmptyStr }
output { body: String from "stdout", success: Bool from "exit_success" }
Expand Down
30 changes: 30 additions & 0 deletions dag/extdeps/llm/codex_auth.dag
Original file line number Diff line number Diff line change
Expand Up @@ -251,3 +251,33 @@ fn codex_default_organization(token: CodexIdToken) -> CodexOrganizationMembershi
fn codex_organization_ids(token: CodexIdToken) -> List<NonEmptyStr> {
token.openai_auth.organizations |> map(o => o.id)
}

// WHAT THE SOURCE SAYS, BESIDE WHAT ONE HOST SHOWED. codex_observed_refresh_persistence records an
// observation on codex-cli 0.145.0 and stays as observed; this row records a separate fact, read from
// the CLI's source at a pinned revision, so neither one gets rewritten into the other. At
// github.com/openai/codex 7f892275e31002f0422477c6219189284560e689 (2026-10-04), crate codex-rs/login,
// module auth/manager.rs: AuthManager::auth refreshes when should_refresh_proactively holds, meaning
// the access_token JWT exp falls within CHATGPT_ACCESS_TOKEN_REFRESH_WINDOW_MINUTES (5) of now, or
// last_refresh is older than TOKEN_REFRESH_INTERVAL (8 days). refresh_and_persist_chatgpt_token then
// calls persist_tokens, which writes id_token, access_token, the refresh_token the response returned
// and last_refresh back to the auth storage (CODEX_HOME/auth.json under the default
// AuthCredentialsStoreMode::File). So at this revision the file is rewritten about once an hour
// during use, not only at login.\n\nRotation stays a separate fact. The response's refresh_token is
// an Option, and the client maps the issuer's error code refresh_token_reused to
// RefreshTokenFailedReason::Exhausted, so the issuer detects reuse. The source shows the CLIENT is
// ready for rotation; whether the issuer actually rotates on every exchange is server behaviour, and
// codex_observed_refresh_rotation stays CodexRotationUnobserved until it is observed.\n\nThe source
// also has no cross-process lock on the file: the refresh lock is per process, and the guarded
// reload compares account ids, not a lock token. So two processes refreshing one copy can both
// present the same refresh token.
data codex_source_revision: NonEmptyStr = "github.com/openai/codex@7f892275e31002f0422477c6219189284560e689" as NonEmptyStr
data codex_source_refresh_persistence: CodexRefreshPersistence = CodexPersistsOnRefresh
data codex_source_access_token_refresh_window: Second = second(count: 300)

// THE auth.json KEYS THE HARNESS READS to decide a write-back, as named by codex-rs/login
// token_data.rs TokenData and auth/storage.rs AuthDotJson. They are wire names of the observed file layout above, not new
// vocabulary.
data codex_auth_file_auth_mode_key: NonEmptyStr = "auth_mode" as NonEmptyStr
data codex_auth_file_tokens_key: NonEmptyStr = "tokens" as NonEmptyStr
data codex_auth_file_refresh_token_key: NonEmptyStr = "refresh_token" as NonEmptyStr
data codex_auth_file_account_id_key: NonEmptyStr = "account_id" as NonEmptyStr
62 changes: 39 additions & 23 deletions dag/extdeps/llm/cursor_cli.dag
Original file line number Diff line number Diff line change
Expand Up @@ -108,8 +108,11 @@ data cursor_model_grok_high_fast: CursorModelId = "cursor-grok-4.5-high-fast" as
data cursor_observed_model_roster_size: Int = 193

// DELIBERATELY NOT USED: -w/--worktree starts the agent in an isolated git worktree the CLI creates under ~/.cursor/worktrees/<repo>/<name>. This repository's belt already creates and owns attempt worktrees under the dashboard instance's own attempts root, with the branch name and attempt identity bound to the roadmap node.\n\nAccepting the CLI's worktree would hand that ownership to the provider: the location would move outside the instance root the model treats as owned, the naming would stop deriving from the attempt, and teardown would belong to a directory nobody declared. The flag is recorded so the choice is visible rather than looking like an oversight — a later reader finding two worktree mechanisms should know only one is ours.
type CursorInvocation {
auth: CursorAuth
// THE RUN AND THE CREDENTIAL ARE TWO FACTS. Everything but the key decides the argv; the key decides
// only where the credential travels. Keeping them apart lets a caller whose key is not in hand (a
// spawn that exports it from a custody file in the child, gunbc.roadmap_dispatch_actuator) build the
// same argv this module builds, rather than spelling cursor-agent's flags a second time.
type CursorRunShape {
model: CursorModelId
mode: CursorExecutionMode
sandbox: CursorSandboxChoice
Expand All @@ -120,6 +123,11 @@ type CursorInvocation {
prompt: NonEmptyStr
}

type CursorInvocation {
auth: CursorAuth
run: CursorRunShape
}

// THE AUTH FIELD WAS NEVER READ, SO BOTH ARMS PRODUCED THE SAME PROCESS. shape_cursor_agent_argv
// built an argv and returned a List of String, and its accompanying note explained at length why
// the key is deliberately absent from that argv — which was true, and which meant a
Expand Down Expand Up @@ -147,20 +155,20 @@ type CursorProcessInvocation {
environment: List<CursorEnvBinding>
}

fn cursor_common_argv(inv: CursorInvocation) -> List<String> {
fn cursor_common_argv(run: CursorRunShape) -> List<String> {
concat(
[cursor_cli_program, "--print"],
concat(
["--output-format", cursor_output_format_wire(f: inv.output_format)],
["--output-format", cursor_output_format_wire(f: run.output_format)],
concat(
["--model", inv.model as String],
["--model", run.model as String],
concat(
cursor_mode_args(mode: inv.mode),
cursor_mode_args(mode: run.mode),
concat(
cursor_sandbox_args(choice: inv.sandbox),
cursor_sandbox_args(choice: run.sandbox),
concat(
if inv.force { ["--force"] } else { [] },
if inv.trust_workspace { ["--trust"] } else { [] },
if run.force { ["--force"] } else { [] },
if run.trust_workspace { ["--trust"] } else { [] },
),
),
),
Expand All @@ -169,28 +177,34 @@ fn cursor_common_argv(inv: CursorInvocation) -> List<String> {
)
}

fn cursor_tail_argv(inv: CursorInvocation) -> List<String> {
fn cursor_tail_argv(run: CursorRunShape) -> List<String> {
concat(
["--workspace", inv.workspace as String],
[inv.prompt as String],
["--workspace", run.workspace as String],
[run.prompt as String],
)
}

// The argv of a run whose key reaches the process through CURSOR_API_KEY set by someone else: the
// environment arm's argv, with nothing about the key in it.
fn cursor_environment_authenticated_argv(run: CursorRunShape) -> List<String> {
concat(cursor_common_argv(run: run), cursor_tail_argv(run: run))
}

fn shape_cursor_invocation(inv: CursorInvocation) -> CursorProcessInvocation {
match inv.auth {
CursorApiKeyArgument { key } =>
CursorProcessInvocation {
program: cursor_cli_program,
argv: concat(
cursor_common_argv(inv: inv),
concat(["--api-key", key as String], cursor_tail_argv(inv: inv)),
cursor_common_argv(run: inv.run),
concat(["--api-key", key as String], cursor_tail_argv(run: inv.run)),
),
environment: [],
}
CursorApiKeyEnvironment { key } =>
CursorProcessInvocation {
program: cursor_cli_program,
argv: concat(cursor_common_argv(inv: inv), cursor_tail_argv(inv: inv)),
argv: cursor_environment_authenticated_argv(run: inv.run),
environment: [
CursorEnvBinding { name: cursor_api_key_env_var, value: key },
],
Expand All @@ -212,14 +226,16 @@ fn cursor_automation_invocation(
) -> CursorInvocation {
CursorInvocation {
auth: CursorApiKeyEnvironment { key: key },
model: model,
mode: mode,
sandbox: sandbox,
output_format: output_format,
force: force,
trust_workspace: trust_workspace,
workspace: workspace,
prompt: prompt,
run: CursorRunShape {
model: model,
mode: mode,
sandbox: sandbox,
output_format: output_format,
force: force,
trust_workspace: trust_workspace,
workspace: workspace,
prompt: prompt,
},
}
}

Expand Down
99 changes: 99 additions & 0 deletions dag/extdeps/nvidia/api_trial_terms.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
module extdeps.nvidia.api_trial_terms

import std.types { NonEmptyStr, List }
import std.decl_ref { DeclarationRef, WholeDeclaration }
import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef }
import extdeps.uri { Uri, Https }

// THE TERMS THAT GOVERN AN NVIDIA-HOSTED API SERVICE, as their own upstream because they are an
// independently versioned document (DESIGN section 3, external upstream decomposition). They are not
// a property of a model -- the Nemotron 3 Ultra weights are licensed under OpenMDW-1.1, a different
// document with different obligations -- and not of a router that forwards to the service: OpenRouter
// links this PDF as the terms of service of its Nvidia endpoint for the free slug, and the obligations
// below are NVIDIA's whoever relays the request.
//
// READ 2026-10-05 from the PDF itself; the document's own last line is "v. September 19, 2025". Every
// obligation row below cites the section that states it, and the section text was read from that
// version, not transcribed from a summary.
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https,
locator: "assets.ngc.nvidia.com/products/api-catalog/legal/NVIDIA%20API%20Trial%20Terms%20of%20Service.pdf",
}
}

data extdeps_model_scope: ExternalModelScope = ExternalModelScope {
subject: ExternalSubjectRef {
declaration: DeclarationRef {
module_path: "extdeps.nvidia.api_trial_terms",
decl_name: "nvidia_api_trial_terms_v20250919",
field: WholeDeclaration
}
},
first_citation: extdeps_external_authority_anchor,
further_citations: [],
}

type NvidiaApiTrialTermsVersion20250919 {}

type NvidiaApiTrialTermsVersion = NvidiaApiTrialTermsVersion20250919

// WHAT THE TERMS OBLIGE OF A USER, one arm per obligation a caller's conduct can breach, each named for
// the section that states it. A closed set rather than prose because a consumer deciding whether a use
// is admissible must be able to ask about each obligation separately; a paragraph cannot be asked.
//
// - 1.2 Trial Access Rights: access "for limited trial purposes only and without use of the API
// Service or Generated Content in production"; 1.4 repeats the trial limit for credits.
// - 2.6(a): User Content may not include "any confidential information, controlled or sensitive
// data, including protected health information, personal data"; 4.3 forbids uploading personal,
// financial, health or governmental information.
// - 3.3(iv): NVIDIA collects "User Content and Generated Content to improve NVIDIA products and
// services, including AI models". This is a disclosure rather than a user duty, carried because a
// caller choosing what to send needs it as much as the prohibitions.
// - 4.2: no copying, selling, sublicensing, transferring or distributing the service or Generated
// Content to others.
// - 4.12: no use of the service or Generated Content "to develop or improve products or services
// that compete with the API Service".
type NvidiaApiTrialObligation
= TrialPurposeNoProduction
| NoConfidentialOrPersonalData
| ContentUsedToImproveNvidiaProducts
| NoRedistributionOfServiceOrOutput
| NoCompetingProductDevelopment

fn nvidia_api_trial_obligation_section(o: NvidiaApiTrialObligation) -> NonEmptyStr {
match o {
TrialPurposeNoProduction => "1.2, 1.4" as NonEmptyStr
NoConfidentialOrPersonalData => "2.6(a), 4.3" as NonEmptyStr
ContentUsedToImproveNvidiaProducts => "3.3(iv)" as NonEmptyStr
NoRedistributionOfServiceOrOutput => "4.2" as NonEmptyStr
NoCompetingProductDevelopment => "4.12" as NonEmptyStr
}
}

type NvidiaApiTrialTerms {
version: NvidiaApiTrialTermsVersion
version_label: NonEmptyStr
obligations: List<NvidiaApiTrialObligation>
terms: ExternalAuthority
}

data nvidia_api_trial_terms_v20250919: NvidiaApiTrialTerms = NvidiaApiTrialTerms {
version: NvidiaApiTrialTermsVersion20250919 {},
version_label: "2025-09-19" as NonEmptyStr,
obligations: [
TrialPurposeNoProduction,
NoConfidentialOrPersonalData,
ContentUsedToImproveNvidiaProducts,
NoRedistributionOfServiceOrOutput,
NoCompetingProductDevelopment,
],
terms: extdeps_external_authority_anchor,
}

fn nvidia_api_trial_terms_wire(t: NvidiaApiTrialTerms) -> NonEmptyStr {
join([
"NVIDIA API Trial Terms of Service v. ", t.version_label as String, " (",
join(map(t.obligations, o => nvidia_api_trial_obligation_section(o: o) as String), "; "), ")",
], "") as NonEmptyStr
}
46 changes: 46 additions & 0 deletions dag/extdeps/nvidia/nemotron_3_ultra.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
module extdeps.nvidia.nemotron_3_ultra

import std.types { NonEmptyStr }
import std.decl_ref { DeclarationRef, WholeDeclaration }
import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef }
import extdeps.uri { Uri, Https }

// NVIDIA NEMOTRON 3 ULTRA, as its own extdeps authority for the reason extdeps.deepseek.deepseek_v4 and
// extdeps.zhipu.glm_5_3_flash are: an independently versioned upstream model is not a property of
// whatever serves it. What a HOSTED endpoint of this model admits -- its window, its output ceiling, the
// reasoning efforts its router accepts -- is the endpoint's fact and lives with the router
// (extdeps.openrouter.openrouter); what the endpoint's operator requires of its users lives with those
// terms (extdeps.nvidia.api_trial_terms). This module carries only what the model card says about the
// model.
//
// READ 2026-10-05 from the model card at the anchor: 550B total / 55B active parameters, a hybrid
// Transformer-Mamba mixture-of-experts, text in and text out, weights under OpenMDW-1.1.
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https,
locator: "huggingface.co/nvidia/NVIDIA-Nemotron-3-Ultra-550B-A55B-BF16",
}
}

data extdeps_model_scope: ExternalModelScope = ExternalModelScope {
subject: ExternalSubjectRef {
declaration: DeclarationRef {
module_path: "extdeps.nvidia.nemotron_3_ultra",
decl_name: "nemotron_ultra_thinking_end_token",
field: WholeDeclaration
}
},
first_citation: extdeps_external_authority_anchor,
further_citations: [],
}

// THE CARD'S REASONING MODES ARE NOT MODELLED HERE, AND THE ABSENCE IS DELIBERATE. The card names three --
// off and full via chat_template_kwargs enable_thinking, and "Medium-effort reasoning" via medium_effort,
// which "uses significantly fewer reasoning tokens than full thinking mode" -- but those keys address a
// chat template, and the only route this repository has to the model is a router that takes its own
// reasoning parameter and translates it unseen. Nothing here can send them, so a type for them would be
// a declaration with no consumer. A self-hosted Nemotron unit is the consumer that would add it.

// THE END-OF-THINKING CLOSER. The card's budget client splits a completion on "</think>" and appends it
// when a capped trace never produced one, so it is the model's own delimiter.
data nemotron_ultra_thinking_end_token: NonEmptyStr = "</think>" as NonEmptyStr
Loading
Loading