Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,8 @@ jobs:
Path("scripts/cmux_fleet_bootstrap.py"),
Path("scripts/test-cmux-fleet.py"),
Path("scripts/test-cmux-fleet-bootstrap.py"),
Path("scripts/cmux_workload_request.py"),
Path("scripts/test-cmux-workload-request.py"),
Path("scripts/test-verify-focused.py"),
Path("scripts/verify-changed-rustfmt"),
Path("scripts/test-hot-run.py"),
Expand Down Expand Up @@ -121,6 +123,7 @@ jobs:
python3 scripts/test-owned-linux-admission.py
python3 scripts/test-cmux-fleet.py
python3 scripts/test-cmux-fleet-bootstrap.py
python3 scripts/test-cmux-workload-request.py
python3 scripts/test-verify.py
python3 scripts/test-verify-changed-rustfmt.py
python3 scripts/test-front-door.py
Expand Down
114 changes: 114 additions & 0 deletions docs/CMUX_WORKLOAD_PROFILES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# CMUX repository-owned workload profiles

CMUX owns the meaning of CMUX workload profiles. Glaeda may admit, place, execute, cache, time, and recover those workloads without copying their command lines or redefining pass/fail semantics.

The paired CMUX implementation is tracked by `manaflow-ai/cmux#13411`.

## Request boundary

`scripts/cmux_workload_request.py` accepts a bounded semantic request containing:

- exact `manaflow-ai/cmux` commit and tree;
- CMUX profile ID and explicit semantic generation;
- benchmark state class;
- bounded integer semantic parameters, such as an app-host shard number;
- caller correlation and an advisory reuse hint.

It rejects caller-controlled argv, shell text, cwd, host paths, backend/machine choice, resource values, cache roots, attempt identity, or cleanup authority.

A planned request resolves only this fixed adapter:

```json
{
"kind": "cmux-repository-profile/v1",
"repository_runner": "scripts/ci/cmux_workload_profile.py",
"semantic_result_contract": "cmux-workload-result/v1"
}
```

Glaeda does not keep a copy of the CMUX registry. Profile validity is checked after exact source materialization by the runner inside that CMUX tree.

## Physical execution

A physical adapter follows this sequence:

1. materialize the exact requested CMUX commit/tree;
2. choose an eligible backend and admitted cache/state class from Glaeda-owned observations;
3. run the checked-in CMUX profile runner's `plan` command and require the same source, profile ID/generation, state class, and semantic parameters;
4. allocate a task-private state root and any reviewed runtime inputs;
5. run the same CMUX profile runner and retain the exact canonical `cmux-workload-result/v1`;
6. wrap its digest and terminal state in Glaeda's physical receipt.

The generic repository adapter may translate the semantic request into the fixed CMUX runner interface. It does not reconstruct Xcode, test-selector, package, release, or developer-build commands.

Runtime-input paths stay physical. Their content identities are published by the CMUX semantic result when the profile contract requires them.

## Identity

Three identities remain separate:

- caller correlation: external request/work references;
- semantic execution binding: exact source + CMUX profile/generation + state class + semantic parameters + fixed adapter generation;
- physical attempt: Glaeda backend, node, leases, cache placement, resources, timing, cleanup, and recovery state.

Caller correlation and reuse hints do not mint another execution binding. A profile generation change does.

## Result correlation

`observe` accepts only canonical `cmux-workload-result/v1` bytes and verifies:

- exact repository/commit/tree;
- exact profile ID/generation;
- exact semantic parameters;
- requested benchmark state class;
- presence of the CMUX semantic validator, artifact collection, and cleanup evidence.

It validates the shared `cmux-workload-result/v1` integrity envelope before projection: the result schema is closed, nested identity/evidence shapes are typed and bounded by the document ceiling, the toolchain identity must match its observations, timestamps and cleanup are self-consistent, and a `passed` result must have exit zero, complete required-artifact validation, and clean process settlement. These are interface-integrity checks; Glaeda does not re-run or reinterpret CMUX's profile-specific validators.

It then projects the CMUX terminal vocabulary without redefining profile semantics:

- `passed` -> `succeeded`;
- `failed` -> `failed`;
- `timed_out` -> `timed_out`;
- `ambiguous` -> `ambiguous`.

The outer observation stores the exact CMUX result digest. Glaeda-specific machine and execution evidence belongs beside that digest in the physical receipt.

## Fleet roles and routing

The first CMUX mapping is:

```yaml
cmux_linux_ci:
acceptance:
profile: cmux.ci.guard
generation: 1

cmux_macos_native_build:
acceptance:
profile: cmux.macos.dev-check
generation: 1
```

Role acceptance consumes the current profile identity from CMUX rather than a Glaeda-owned recipe. Routing experiments can compare backends only when the CMUX semantic comparison identity and benchmark context agree.

This gives #148 a repository-owned named-profile source, #546 comparable routing evidence, #547 a stable semantic operation for optimization, and #1056 an exact acceptance workload. #1057's caller/orchestrator identity remains independent from this workload identity.

## Synthetic proof

`docs/experiments/cmux-workload-profile/` contains a request and its deterministic planned result. It proves the GitHub/repository-only request boundary without claiming physical execution.

Run:

```sh
python3 scripts/cmux_workload_request.py plan \
< docs/experiments/cmux-workload-profile/request.json \
> /tmp/cmux-workload-plan.json

cmp /tmp/cmux-workload-plan.json \
docs/experiments/cmux-workload-profile/plan.json

python3 scripts/test-cmux-workload-request.py
```

Physical Mac acceptance remains a separate approved fleet experiment.
17 changes: 17 additions & 0 deletions docs/experiments/cmux-workload-profile/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# CMUX workload profile synthetic plan

This fixture proves Glaeda can accept a caller-neutral CMUX semantic workload request while leaving CMUX semantics in the CMUX repository.

`request.json` freezes synthetic exact source identity plus `cmux.ci.guard@1` and the `cold` state class. `plan.json` resolves only the fixed `cmux-repository-profile/v1` adapter and grants no execution, placement, resource-override, or redispatch authority.

The OIDs are deliberately synthetic; this fixture exercises the request contract without claiming that a CMUX checkout or physical worker ran.

Regenerate and compare:

```sh
python3 scripts/cmux_workload_request.py plan \
< docs/experiments/cmux-workload-profile/request.json \
> /tmp/cmux-workload-plan.json
cmp /tmp/cmux-workload-plan.json \
docs/experiments/cmux-workload-profile/plan.json
```
1 change: 1 addition & 0 deletions docs/experiments/cmux-workload-profile/plan.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"authority":{"authorizes_execution":false,"authorizes_host_selection":false,"authorizes_redispatch":false,"authorizes_resource_override":false},"benchmark_state_class":"cold","correlation":{"work_ref":"cmux:work:fixture-1"},"document_type":"glaeda-cmux-workload-plan","execution_binding_sha256":"sha256:45ac07054ec2ba65cb46d039c879b6b973c33e2fe3f2290033f09981bfe1b8ff","external_request_ref":"cmux:workload:fixture-1","parameters":{},"physical_preflight":["materialize_exact_source","cmux_runner_plan_matches_frozen_source_and_profile","cmux_runner_owns_semantic_validation"],"profile":{"generation":1,"id":"cmux.ci.guard"},"request_sha256":"sha256:2ff1cc2403bfd2226d0e610fca06d74c0de221f18a252452b6cf58cc742a5d81","resolved_adapter":{"kind":"cmux-repository-profile/v1","repository_runner":"scripts/ci/cmux_workload_profile.py","semantic_result_contract":"cmux-workload-result/v1"},"schema_version":1,"source":{"commit":"1111111111111111111111111111111111111111","repository":"manaflow-ai/cmux","tree":"2222222222222222222222222222222222222222"},"state":"planned"}
1 change: 1 addition & 0 deletions docs/experiments/cmux-workload-profile/request.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"benchmark_state_class":"cold","correlation":{"work_ref":"cmux:work:fixture-1"},"document_type":"glaeda-cmux-workload-request","external_request_ref":"cmux:workload:fixture-1","profile":{"generation":1,"id":"cmux.ci.guard"},"reuse_hint":"no_preference","schema_version":1,"source":{"commit":"1111111111111111111111111111111111111111","repository":"manaflow-ai/cmux","tree":"2222222222222222222222222222222222222222"}}
Loading