Conversation
Preserve the a835951 planning commit on the current accepted Q1 base so its contract and gate records can govern the implementation without reverting newer runtime and Torch work.
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Resolve an exact release tag through the existing GitHub metadata owner and map publisher asset identity and SHA-256 evidence into the source-neutral manifest. Keep the established release DTO and cache schema unchanged, and keep the signed retrieval URL out of the manifest. Record Q1 scope and evidence without advancing AQ-HTTP.
Move task, nested effect, predecessor drain, and projection custody into one acquisition supervisor. Isolate consumer scopes and register each terminal projection before admission so scoped and global shutdown retain repeatable outcomes. Keep model root grants, destination queues, and admission matching in the HF policy facade. Retain opaque effect leases through observation and leave persistent download formats unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owning plan and milestone
docs/plans/artifact-acquisition/plan.mdExact candidate
maine37bbf4b964a0e2aadf25f80ab71edd8fa6b3eb35ef3e0530a3b2c050d35cc302a22b9f783ccc777(contract, plan, evidence, and work-set decision update). Exact production-code test candidate remainsc3052583860baa76dc114edf6420805e9b06f327; no production source has yet implemented the newly admitted schema-6 migration boundary, so those tests do not verify that behavior.2193236087f549df9b98eefa39ada440d9012c96; the current head integrates the scoped-custody worker commit584b5f45a17a80cd584b16ce77f7be5d9688a9b8without rewriting history.a8359512a580aa25fb2f9c9e4cd7e0dd64fd970dremains preserved in branch history.Intended outcome
Q1 will provide one durable, source-neutral acquisition owner used by ordinary Hugging Face model acquisition and the existing llama.cpp installer. Consumers keep model import or runtime installation publication, and hold verified acquisition inputs through their completion and cleanup.
This candidate advances the custody boundary: one crate-private supervisor now owns task populations, effect custody, generations, predecessor drainage, projection receipts, and consumer scopes. HF keeps model admission, root grants, destination queues, and its current persistence/projection decisions. Existing manifest and HTTP body handling are consumed in the normal HF path; exact-tag GitHub asset resolution preserves publisher identity; physical-root grant bookkeeping coalesces independent opens without replacing capability validation. The native installer still uses its independent downloader. A durable source-neutral acquisition store, shared consumer handoff, and native cutover do not yet exist.
Included scope and exclusions
Included across this milestone branch so far: source-neutral manifest values; shared HTTP response/body handling in the existing HF workflow; exact GitHub release-asset resolution; physical-root grant bookkeeping; native install/removal shutdown custody; consumer-scoped task custody extraction; and plan/evidence updates.
Not yet implemented or claimed: a shared durable acquisition task/store/workspace owner; source-neutral native acquisition and verified-input installation; supported retained-store migration/reopen; exact package-file acquisition; S3; runtime installation identities or model-adapter registration; R1–R5; real model generation.
Prerequisites and gates
mainafter repository, plan, recovery-owner, and supported-store inspection. The exact baselinea8359512a580aa25fb2f9c9e4cd7e0dd64fd970dwas resolved and preserved. Deployed retained-state population and old-writer retirement/isolation remain unknown; no live root was read or changed.Ownership, persistence, generated interfaces, and lifecycle
DownloadPersistenceremains the single current persistence owner while the neutral owner cutover is pending.Evidence on the exact current candidate
On
c3052583860baa76dc114edf6420805e9b06f327:cargo test --manifest-path rust/Cargo.toml --locked -p pumas-library --lib acquisition::task_custody::tests:: -- --test-threads=4: 34 passed.cargo test --manifest-path rust/Cargo.toml --locked -p pumas-library --lib model_library::hf:: -- --test-threads=4: 219 passed using controlled local HTTP fixtures and authorized loopback access.git diff --checkpassed for the integration.On earlier exact source candidate
48ad1ba374593f4619fb22f0044377914b268381, app-manager 257, RPC unit 265, integration 17, and intent-integration 2 passed; 13 tests were ignored. App-manager/RPC all-targets/all-features Clippy with-D warnings, RPC no-default-features check, and Rust formatting passed. Those results are historical to that candidate and are not CI evidence for the current head. Earlier exact resolver/manifest, library Clippy, headless, and format checks also passed on their recorded source candidates.The custody and HF suites use local fixtures/disposable state. They are real tests of those components, but not live HF/native service acceptance. No current-head test proves a live source, native shared acquisition, a retained live-root migration/reopen, desktop operation, configured S3, model generation, or network-denied Torch installation.
GitHub Actions run
36661110500is attached to exact PR head5ef3e0530a3b2c050d35cc302a22b9f783ccc777. It was queued with no jobs started when this description was updated; no current-head hosted check is claimed passed. Run36660428556for previous docs head7129d51631d7257742573d4e4873009f20158becremained in progress at the same observation. Earlier run36658935346for source candidatec3052583860baa76dc114edf6420805e9b06f327was canceled and is not promoted to later heads; skipped or absent jobs are not passes.Independent review and remaining acceptance
Independent read-only review of the five-file custody extraction found no substantiated P0/P1/P2/P3 finding in its scope. It verified scope isolation, retained task/effect ownership, shutdown receipts, failure visibility, opaque-payload destruction outside the mutex, HF policy preservation, and crate-private visibility. The reviewer ran no tests. A separate native-custody review found no P0/P1 in its reviewed scope; active shutdown and panic paths were partly source-supported rather than independently executed. Earlier root-grant review found no blocking defect and noted inactive weak identity slots should be pruned or bounded when dynamic multi-root use begins.
Remaining acceptance includes a single durable neutral acquisition/store owner; exact-generation consumer commit/reconciliation across supported retained-state readers/writers; actual HF and llama.cpp consumer cutovers with lease, integrity, cancellation, shutdown, and reopen evidence; desktop and required platform/source evidence; complete current-head CI; and final independent review plus final Coding-Standards routing. None is represented as complete. This draft does not authorize merging to
main.