Skip to content

fix(mamba): skip prefill donation when an in-flight verify aliases the keep slot - #64

Open
rchalamala wants to merge 1 commit into
integration/kimi-k3-v0.5.20from
fix/mamba-checkpoint-donation
Open

rchalamala wants to merge 1 commit into
integration/kimi-k3-v0.5.20from
fix/mamba-checkpoint-donation

Conversation

@rchalamala

@rchalamala rchalamala commented Sep 26, 2026 •

Copy link
Copy Markdown

Motivation

With lazy extra-buffer mamba checkpoints and speculative decoding, a lazy
final prefill holds its checkpoint in one physical ping-pong slot (keep == next,
second position −1). When the first verify's pending-slot allocation fails —
naturally, when the checkpoint pool is momentarily full of unlocked cached
checkpoints, because that allocation deliberately does not evict — the verify
scatters in place into the keep slot. Prefill result processing then donates
that physical slot to the radix tree under the prefill's tracked depth C,
while the already-launched verify commits newer checkpoint state at a tracking
boundary T > C into the same slot. The tree deterministically labels newer
state as the old depth, and a later prefix match is served a checkpoint for
the wrong position.

Runtime-confirmed on Qwen3-Next-80B-A3B + its NEXTN MTP head (2xB300,
extra_buffer_lazy, track interval 256, overlap scheduler, 255-token prompts):
forced pending-slot failure publishes the keep slot under C=192 while the
verify commits T=256 into it, in both the finishing and unfinished cases, and
a repeat request matches the corrupted node (cached_tokens=192) and produces
greedy output divergent from the flushed-cache control. Natural reproduction
without any test flag (12-slot pool, 40 distinct prompts): 140 natural
pending-slot allocation failures across 35 requests, 70 aliased donations,
every one with the matching crossing commit into the same slot.

New patch, not an upstream duplicate: sgl-project#37837 resets the
ReplaySSM ring cursor on the donate path and never touches the donation
decision or the in-flight verify's captured destination — disjoint files and
failure mode.

Modifications

  • batch_result_processor.py: prefill result processing now applies the decode
    guard's keep_may_be_written_in_flight recompute (new helper
    _mamba_lazy_keep_may_be_written_in_flight) before the finishing tree insert
    (is_insert=False) and before the unfinished donation, when lazy extra-buffer
    spec is active, the pending ping-pong position is empty, and a tracking-boundary
    crossing is reachable. The first verify result repairs the request-side
    label, so the checkpoint publishes later under the correct depth T.
    Conservative superset semantics match the decode guard (size-1 buffer and
    non-overlap cases return False by construction), and the lazy-spec-inactive
    path is byte-equivalent (early False, pure reads).
  • test/registered/unit/managers/test_batch_result_processor_mamba_lazy_donation.py:
    12 tests — predicate matrix (lazy/spec/window/buffer arms), finishing
    suppression, unfinished-donation suppression, no-alias arms unchanged, and
    two flow tests pinning the defect end to end.

Accuracy Tests

  • 12/12 new registered CPU tests pass on the fix tree; on the unfixed tree the
    two flow tests fail with exactly the defect behavior (is_insert=True,
    donation made) and the 7 predicate tests fail structurally (attributable
    control; the 3 no-alias arms pass on both trees).
  • Runtime verification of the fix on the same model/box: forced arms
    suppressed (prefill_alias_suppressed; correct publication under T=256 at
    finish); natural arm: 140 failures, 70 suppressions, 0 aliased donations.
    The already-released request's verify result is skipped by design in
    process_batch_result_decode (confirmed by decode_skip_finished receipts).
  • Neighbor registered suites pass (boundary, hidden_states, spec_grammar,
    bookkeeping); one pre-existing failure (test_spec_invalid_result_lifecycle)
    reproduces identically on the unfixed tree — unrelated.
  • Gates: check_registered_tests, ruff F401/F821/UP037, ruff format, isort,
    codespell — all clean; git merge-tree --write-tree vs the integration base
    exits 0 with 0 conflicts; pairwise merge-tree vs the heads of
    fix/spec-invalid-prefix-lifecycle, metrics/decode-step-gap,
    metrics/fp8-range-observations, metrics/generated-token-timing,
    fix/mla-hicache-host-dedup-txn, and fix/renorm-deterministic — all clean.

Speed Tests and Profiling

No hot-path cost: the predicate is one short-circuiting evaluation per
prefill result-processing call under lazy extra-buffer spec (pure reads, no
allocation, no synchronization), and early-False otherwise. No serving
performance impact is expected or measured; full combined-tree serving
acceptance remains the campaign follow-up.

Checklist


CI States

Latest PR Test (Base): ❌ Run #36218669347
Latest PR Test (Extra): ❌ Run #36218669275
Latest PR Test (AMD ROCm 10): ❌ Run #36218669322

…e keep slot

Under extra_buffer_lazy + speculative decoding with the overlap
scheduler, the first verify after a lazy final prefill is launched
before the prefill result is processed. If the pending ping-pong slot
allocation fails at verify prepare, the verify plan falls back to the
keep slot as its scatter destination. Prefill result processing then
donated/inserted that physical slot into the radix tree under the
prefill tracked depth C while the already-launched verify commits the
crossing state T > C into the same slot, so the tree records newer
state under the stale depth.

Apply the decode guard keep_may_be_written_in_flight recompute at the
prefill caching decision: skip the finishing insert and the unfinished
donation while the pending position is empty and a crossing is
reachable. The first verify result repairs the request-side label, so
the checkpoint is published later under the correct depth.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T04:47:13.407710Z 32ffd43 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 32ffd43643

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant