Skip to content

[Q1] Build shared artifact acquisition for Hugging Face and runtime installs - #7

Draft
MrScripty wants to merge 15 commits into
mainfrom
work/acquisition-q1-http
Draft

MrScripty wants to merge 15 commits into
mainfrom
work/acquisition-q1-http

Conversation

@MrScripty

@MrScripty MrScripty commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Owning plan and milestone

  • Plan: docs/plans/artifact-acquisition/plan.md
  • Milestone: Acquisition Q1 — one shared HTTP acquisition lifecycle consumed by the normal Hugging Face model workflow and native runtime installer.
  • This remains a draft implementation PR. Q1 is in progress; AQ-HTTP is not ready.

Exact candidate

  • Target: main
  • Accepted base: e37bbf4b964a0e2aadf25f80ab71edd8fa6b3eb3
  • Current PR head: 5ef3e0530a3b2c050d35cc302a22b9f783ccc777 (contract, plan, evidence, and work-set decision update). Exact production-code test candidate remains c3052583860baa76dc114edf6420805e9b06f327; no production source has yet implemented the newly admitted schema-6 migration boundary, so those tests do not verify that behavior.
  • Previous primary head: 2193236087f549df9b98eefa39ada440d9012c96; the current head integrates the scoped-custody worker commit 584b5f45a17a80cd584b16ce77f7be5d9688a9b8 without rewriting history.
  • Baseline plan commit a8359512a580aa25fb2f9c9e4cd7e0dd64fd970d remains preserved in branch history.

Intended outcome

Q1 will provide one durable, source-neutral acquisition owner used by ordinary Hugging Face model acquisition and the existing llama.cpp installer. Consumers keep model import or runtime installation publication, and hold verified acquisition inputs through their completion and cleanup.

This candidate advances the custody boundary: one crate-private supervisor now owns task populations, effect custody, generations, predecessor drainage, projection receipts, and consumer scopes. HF keeps model admission, root grants, destination queues, and its current persistence/projection decisions. Existing manifest and HTTP body handling are consumed in the normal HF path; exact-tag GitHub asset resolution preserves publisher identity; physical-root grant bookkeeping coalesces independent opens without replacing capability validation. The native installer still uses its independent downloader. A durable source-neutral acquisition store, shared consumer handoff, and native cutover do not yet exist.

Included scope and exclusions

Included across this milestone branch so far: source-neutral manifest values; shared HTTP response/body handling in the existing HF workflow; exact GitHub release-asset resolution; physical-root grant bookkeeping; native install/removal shutdown custody; consumer-scoped task custody extraction; and plan/evidence updates.

Not yet implemented or claimed: a shared durable acquisition task/store/workspace owner; source-neutral native acquisition and verified-input installation; supported retained-store migration/reopen; exact package-file acquisition; S3; runtime installation identities or model-adapter registration; R1–R5; real model generation.

Prerequisites and gates

  • Q1 began from accepted main after repository, plan, recovery-owner, and supported-store inspection. The exact baseline a8359512a580aa25fb2f9c9e4cd7e0dd64fd970d was resolved and preserved. Deployed retained-state population and old-writer retirement/isolation remain unknown; no live root was read or changed.
  • AQ-HTTP requires the plan's AC01–AC10, AC15, AC16, and AC18 evidence at the claimed scope, including the same real acquisition owner through HF import and native archive installation, restart/reopen, cancellation, desktop behavior, and source/platform evidence. It is not ready.
  • AQ-PACKAGES and AQ-S3 are not ready. Runtime R1 and later milestones have not started and remain gated on accepted prerequisites.

Ownership, persistence, generated interfaces, and lifecycle

  • The acquisition module owns source-neutral manifest values and shared custody mechanics. Existing HF and native installation owners still own their consumer policy/publication; the final single acquisition/store owner and composition are unfinished.
  • Model-root marker/deletion policy remains model-owned. Physical-root identity bookkeeping never substitutes for current held-capability validation.
  • The five-file scoped-custody commit changed no durable schema, migration, download marker/deletion policy, native installer, generated RPC/interface, frontend projection, dependency lockfile, or retained data. The shared contract now admits schema 6 in the existing store, with explicit offline migration from schema 4/5 and no migration during normal open; that source behavior remains unimplemented. DownloadPersistence remains the single current persistence owner while the neutral owner cutover is pending.
  • The native custody work retains install/removal and state-mutation effects through shutdown. It does not replace native transfer; network waits can still delay shutdown.
  • Manifest identity excludes credentials and signed retrieval URLs. Source resolution does not authorize execution of acquired code.

Evidence on the exact current candidate

On c3052583860baa76dc114edf6420805e9b06f327:

  • cargo test --manifest-path rust/Cargo.toml --locked -p pumas-library --lib acquisition::task_custody::tests:: -- --test-threads=4: 34 passed.
  • cargo test --manifest-path rust/Cargo.toml --locked -p pumas-library --lib model_library::hf:: -- --test-threads=4: 219 passed using controlled local HTTP fixtures and authorized loopback access.
  • git diff --check passed for the integration.

On earlier exact source candidate 48ad1ba374593f4619fb22f0044377914b268381, app-manager 257, RPC unit 265, integration 17, and intent-integration 2 passed; 13 tests were ignored. App-manager/RPC all-targets/all-features Clippy with -D warnings, RPC no-default-features check, and Rust formatting passed. Those results are historical to that candidate and are not CI evidence for the current head. Earlier exact resolver/manifest, library Clippy, headless, and format checks also passed on their recorded source candidates.

The custody and HF suites use local fixtures/disposable state. They are real tests of those components, but not live HF/native service acceptance. No current-head test proves a live source, native shared acquisition, a retained live-root migration/reopen, desktop operation, configured S3, model generation, or network-denied Torch installation.

GitHub Actions run 36661110500 is attached to exact PR head 5ef3e0530a3b2c050d35cc302a22b9f783ccc777. It was queued with no jobs started when this description was updated; no current-head hosted check is claimed passed. Run 36660428556 for previous docs head 7129d51631d7257742573d4e4873009f20158bec remained in progress at the same observation. Earlier run 36658935346 for source candidate c3052583860baa76dc114edf6420805e9b06f327 was canceled and is not promoted to later heads; skipped or absent jobs are not passes.

Independent review and remaining acceptance

Independent read-only review of the five-file custody extraction found no substantiated P0/P1/P2/P3 finding in its scope. It verified scope isolation, retained task/effect ownership, shutdown receipts, failure visibility, opaque-payload destruction outside the mutex, HF policy preservation, and crate-private visibility. The reviewer ran no tests. A separate native-custody review found no P0/P1 in its reviewed scope; active shutdown and panic paths were partly source-supported rather than independently executed. Earlier root-grant review found no blocking defect and noted inactive weak identity slots should be pruned or bounded when dynamic multi-root use begins.

Remaining acceptance includes a single durable neutral acquisition/store owner; exact-generation consumer commit/reconciliation across supported retained-state readers/writers; actual HF and llama.cpp consumer cutovers with lease, integrity, cancellation, shutdown, and reopen evidence; desktop and required platform/source evidence; complete current-head CI; and final independent review plus final Coding-Standards routing. None is represented as complete. This draft does not authorize merging to main.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Resolve an exact release tag through the existing GitHub metadata owner and map publisher asset identity and SHA-256 evidence into the source-neutral manifest. Keep the established release DTO and cache schema unchanged, and keep the signed retrieval URL out of the manifest. Record Q1 scope and evidence without advancing AQ-HTTP.
@MrScripty MrScripty changed the title [Q1] Share HTTP artifact protocol with Hugging Face [Q1] Build shared artifact acquisition for Hugging Face and runtime installs Sep 30, 2026
Move task, nested effect, predecessor drain, and projection custody into one acquisition supervisor. Isolate consumer scopes and register each terminal projection before admission so scoped and global shutdown retain repeatable outcomes.

Keep model root grants, destination queues, and admission matching in the HF policy facade. Retain opaque effect leases through observation and leave persistent download formats unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant