Skip to content

Project CMUX product transport receipts into adaptive verification observations - #1102

Merged
teamleaderleo merged 15 commits into
mainfrom
issue-547-cmux-product-transport-observations
Sep 22, 2026
Merged

teamleaderleo merged 15 commits into
mainfrom
issue-547-cmux-product-transport-observations

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #547 and merged #1100. Depends on manaflow-ai/cmux#13540 landing its current CMUX_TEST_PRODUCT_RESTORE receipt fields.

What this adds

  • a pure cmux_product_transport_adapter;
  • input: an already-validated CmuxWorkloadVerificationObservationBatch plus CMUX's closed product-restore JSON receipt;
  • physical receipt identity is the full immutable tuple: repository, artifact/provider identity, archive SHA-256, product-contract digest, source revision, producer run, and producer attempt;
  • source revision and shard must match the semantic workload before transport evidence is accepted;
  • peer transfer -> artifact_transfer observation with measured lookup + transfer time, bytes transferred, exact physical archive identity, semantic consumer identity, backend, and inherited validity inputs;
  • canonical restore -> separate restore observation with measured restore time and archive bytes;
  • local hits -> restore evidence only, with zero invented transfer bytes;
  • R2/GitHub fallback receipts -> restore evidence only until CMUX exports their transfer time/bytes.

Unit discipline

The semantic shard receipt reports unpacked runtime-input tree bytes. The transport receipt reports compressed archive/transport bytes. They are different units.

This adapter therefore:

  • retains both values;
  • sets split_comparable_bytes_available=false;
  • deliberately leaves required_consumer_bytes unset on transport observations.

Repeated full-product peer transfers can rediscover retain_local_immutable_artifact with an exact validity contract. They cannot manufacture split_consumer_artifact. #13365 still needs selected/required bytes measured in the same transport unit.

Proof

Tests use the real #13540 transport-control byte count and peer timings (606,055,356-byte product, 0.262123s lookup, 0.781782s peer transfer). The restore duration in the unit fixture is synthetic; this PR does not claim a controlled canonical-restore benchmark. The tests prove:

  • transfer and restore are emitted separately;
  • three repeated peer transfers generate exact local-retention advice;
  • no split-artifact candidate is generated;
  • local hits do not invent transfer work;
  • inconsistent source/peer flags fail closed;
  • JSON and human output explain the incomparable-byte boundary.

Merge after manaflow-ai/cmux#13540 so the producer receipt contract is landed.

Stage-specific reuse accounting

The shard semantic result may be exact-product-reuse, while transport locality is a separate fact. Peer artifact_transfer rows are emitted as cold. Every accepted physical receipt also emits a restore row classified by its source: local restores are reuse; peer/R2/GitHub restores are cold. The test-execution row continues to carry the CMUX compiled-product reuse class.

For retain_local_immutable_artifact, utility prefers those restore rows when computing hit frequency and falls back to transfer rows for older observation producers. This prevents repeated peer misses from being reported as local hits while allowing real local receipts to contribute measured hit frequency.

Regression coverage asserts three peer transfers produce exact local-retention advice at 0 bp, and adding one matching local-hit receipt produces 2,500 bp. The same evidence still produces no split_consumer_artifact candidate.

@teamleaderleo
teamleaderleo merged commit 3127bfc into main Sep 22, 2026
5 checks passed
@teamleaderleo
teamleaderleo deleted the issue-547-cmux-product-transport-observations branch September 22, 2026 23:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant