Skip to content

Commit 19aab3d

Browse files
committed
fix: stamp the commit that ran, and group the board by instrument everywhere
THE STAMP NAMED THE WRONG COMMIT. run-on-ec2.sh derived BENCH_ENGINE_COMMIT from the operator's local HEAD while the boxes fetch $BENCH_COMMIT. Those are equal only when BENCH_COMMIT is left to default - and pinning it is exactly what you do when re-measuring gateways onto the harness the rest of the board already used. So the thirteen gateways re-measured pinned to 80030c2, specifically so the board would be ONE instrument, came back stamped 7fd350e. They ran the pinned tree; only the label was wrong. The board then concluded it was mixed and blanked busbar-150 - the one row genuinely on the pinned engine. Measurements right, label wrong, conclusion inverted, and nothing looked broken. THE INSTRUMENT, NOT THE COMMIT, IN EVERY READER. C8 already grouped commits whose built binaries are byte-identical, but gen-data compared raw shas and bench-audit filtered on a sha prefix. Three parts of one pipeline disagreed about what "the same engine" means, so C8 could pass a board that gen-data then marked mixed and bench-audit refused to audit. They now all resolve through instrument-equivalence.json. The per-row stamp still reports the exact commit: the instrument decides comparability, the sha still identifies the tree. 80030c2 and 7fd350e are attested as one instrument on BUILT-ARTIFACT evidence - both build otb to e97eb008... - which is the only evidence that file admits. AND ONE AUDIT INVARIANT WAS ACCUSING THE SEARCH OF ITS OWN DESIGN. check_no_rung_fails_below_one_already_carried tested `<= clean` while its docstring said BELOW. The ascending sweep probes a rung once; if that probe passes, confirmation at the SAME concurrency fails, and the engine steps down and publishes the lower rung - the normal way a ceiling is found. apisix anthropic>anthropic did exactly that (c=16384 passed the sweep, lost both confirmation windows, 8192 published after holding 4 of 4) and was reported as "impossible for the gateway alone". A failure AT the proven top is the search working; only one strictly BELOW it has no gateway-only explanation. The 14 red-before guards in bench-audit_test still each reject their own violation.
1 parent 392582d commit 19aab3d

4 files changed

Lines changed: 126 additions & 9 deletions

File tree

‎bench-audit.py‎

Lines changed: 66 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -127,8 +127,53 @@ def snapshot_paths():
127127
MAX_RPS_PER_CONNECTION = 20_000
128128

129129

130+
def _instrument_map():
131+
"""commit sha -> instrument id, from site/instrument-equivalence.json.
132+
133+
THE INSTRUMENT, NOT THE COMMIT - the same grouping C8 and gen-data use. Two commits whose built
134+
binaries are byte-identical are one instrument, so pinning the audit to a raw sha would drop rows
135+
that were measured by the very same binary. That is how busbar-150 fell out of this audit while
136+
being on the board: it was stamped 80030c2f and the rest 7fd350ed, commits that build identical
137+
bytes. An entry is only honoured here if it carries the artifact evidence its own file demands.
138+
"""
139+
p = os.path.join(HERE, "site", "instrument-equivalence.json")
140+
out = {}
141+
try:
142+
doc = json.load(open(p))
143+
except Exception:
144+
return out
145+
for inst in doc.get("instruments") or []:
146+
commits = inst.get("commits") or []
147+
ev = ((inst.get("evidence") or {}).get("otb_release_sha256")) or {}
148+
hashes = list(ev.values())
149+
if not inst.get("id") or not commits:
150+
continue
151+
# No artifact evidence, or hashes that disagree, means the entry proves nothing.
152+
if len(hashes) < len(commits) or len(set(hashes)) != 1:
153+
continue
154+
for c in commits:
155+
out[c] = inst["id"]
156+
return out
157+
158+
159+
def _same_instrument(sha, engine, imap):
160+
"""Does `sha` belong to the instrument identified by `engine` (a sha prefix or an instrument id)?"""
161+
if not engine:
162+
return True
163+
if sha.startswith(engine):
164+
return True
165+
mine = imap.get(sha)
166+
if mine is None:
167+
return False
168+
# `engine` may be an instrument id, or any sha belonging to that instrument.
169+
if mine == engine:
170+
return True
171+
return any(mine == inst for c, inst in imap.items() if c.startswith(engine))
172+
173+
130174
def load(engine=None, gateway=None):
131-
"""The newest snapshot per gateway, pinned to one engine so a board is audited as a board."""
175+
"""The newest snapshot per gateway, pinned to one INSTRUMENT so a board is audited as a board."""
176+
imap = _instrument_map()
132177
by_gw = {}
133178
for f in snapshot_paths():
134179
try:
@@ -140,7 +185,7 @@ def load(engine=None, gateway=None):
140185
sha = ((d.get("rig") or {}).get("engine") or {}).get("commit") or ""
141186
if not gw or (gateway and gw != gateway):
142187
continue
143-
if engine and not sha.startswith(engine):
188+
if not _same_instrument(sha, engine, imap):
144189
continue
145190
by_gw[gw] = (f, d, sha)
146191
return by_gw
@@ -484,7 +529,13 @@ def stream_trace(c):
484529

485530
def proven_clean_top(rungs):
486531
"""The highest concurrency the UNCONTAMINATED ascending prefix carried - every rung from the
487-
first up to and including it passed, before anything in this cell had failed."""
532+
first up to and including it passed, before anything in this cell had failed.
533+
534+
This is the ASCENDING PREFIX and nothing else: it deliberately stops at the first failed window,
535+
so the concurrency it returns is one the cell reached before anything in it had gone wrong. What
536+
counts as a violation relative to that top is decided by the caller - see the note there on why a
537+
failure AT the top is the search working and only a failure BELOW it is a finding.
538+
"""
488539
top = 0
489540
for r in rungs:
490541
if r.get("passed") is not True:
@@ -563,7 +614,17 @@ def check_no_rung_fails_below_one_already_carried(name, c):
563614
clean = proven_clean_top(rungs)
564615
if clean <= 0:
565616
return
566-
below = [r.get("conc") for r in rungs if r.get("passed") is not True and (r.get("conc") or 0) <= clean]
617+
# BELOW, NOT AT. This read `<= clean`, which flags the search's own terminating condition: the
618+
# ascending sweep probes a rung once, that probe passes, confirmation at the SAME concurrency then
619+
# fails, and the engine steps down and publishes the lower rung. apisix anthropic>anthropic did
620+
# exactly that - c=16384 passed the sweep, lost both confirmation windows, and 8192 was published
621+
# after holding 4 of 4 - and it was reported as "impossible for the gateway alone".
622+
#
623+
# A failure AT the top is how a ceiling is found. A failure strictly BELOW a concurrency the cell
624+
# already carried is the thing that has no gateway-only explanation, which is what the docstring
625+
# above has always said ("cannot fail BELOW one the same cell has already carried") and what the
626+
# 2026-07-31 six-cell case actually looked like. The comparison now matches the claim.
627+
below = [r.get("conc") for r in rungs if r.get("passed") is not True and (r.get("conc") or 0) < clean]
567628
if not below:
568629
return
569630
absences = c.get("absences") or {}
@@ -1430,7 +1491,7 @@ def main():
14301491
sha = ((d.get("rig") or {}).get("engine") or {}).get("commit") or ""
14311492
if not gw or (args.gateway and gw != args.gateway) or gw in snaps:
14321493
continue
1433-
if not sha.startswith(engine):
1494+
if not _same_instrument(sha, engine, _instrument_map()):
14341495
skipped[gw] = sha[:7] or "no engine stamp"
14351496

14361497
violations = collections.defaultdict(list)

‎run-on-ec2.sh‎

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -325,7 +325,21 @@ ARCH="${ARCH:-arm64}"
325325
#
326326
# Everything else still counts, including UNTRACKED files: a new gateways/<name>/ directory is
327327
# untracked and absolutely does change what runs.
328-
BENCH_ENGINE_COMMIT="$(git -C "$HERE" rev-parse HEAD 2>/dev/null || echo '')"
328+
# THE STAMP MUST NAME THE COMMIT THE BOXES ACTUALLY RAN, which is $BENCH_COMMIT - the tree they fetch
329+
# by `git ls-tree` - and NOT this machine's HEAD.
330+
#
331+
# These are the same value only when BENCH_COMMIT is left to default. Override it to pin a run to an
332+
# older engine (the whole point of pinning: re-measure lagging gateways on the harness the rest of the
333+
# board already used) and the two diverge silently: the boxes build the pinned tree and the artifact is
334+
# stamped with whatever the operator's checkout happened to be sitting on.
335+
#
336+
# That is not cosmetic. The engine stamp is C8's entire input. On 2026-08-03 thirteen gateways were
337+
# re-measured pinned to 80030c2f specifically so the board would be ONE instrument; they were stamped
338+
# 7fd350ed - a local commit that touched no engine file - and the board concluded it was mixed and
339+
# blanked the one row that was genuinely on the pinned engine. The measurements were right and the
340+
# label was wrong, which is the worst shape of this bug: nothing looks broken, and the conclusion is
341+
# inverted. A stamp that can name a commit the run never used is not provenance.
342+
BENCH_ENGINE_COMMIT="${BENCH_COMMIT:-$(git -C "$HERE" rev-parse HEAD 2>/dev/null || echo '')}"
329343
if [ -n "$(git -C "$HERE" status --porcelain -- . ':(exclude)results' 2>/dev/null)" ]; then BENCH_ENGINE_DIRTY=1; else BENCH_ENGINE_DIRTY=0; fi
330344
export BENCH_ENGINE_COMMIT BENCH_ENGINE_DIRTY
331345

‎site/gen-data.mjs‎

Lines changed: 29 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ import { join, dirname } from "node:path";
2626
import { fileURLToPath } from "node:url";
2727
import { createHash } from "node:crypto";
2828
import { snapshotCellCoords, isStrictSubset, layerScopedMatrix } from "./snapshots.mjs";
29+
import { instrumentOf } from "./check-consistency.mjs";
2930
import { sealMetric, sealFrontier, makeSource, SWEEP, UNGATED_LAT_FIELDS, UNGATED_COST_FIELDS, DEFAULT_BOUND_MS, frontierAt, UNGATED_STREAM_FIELDS, isMetricField, zeroNoteFor } from "./seal.mjs";
3031

3132
const HERE = dirname(fileURLToPath(import.meta.url));
@@ -1129,15 +1130,40 @@ if (existsSync(redirects) && OUT !== HERE) copyFileSync(redirects, join(OUT, "_r
11291130
//
11301131
// The board's version is the engine of the most recently measured row, which is the one a re-run
11311132
// moves forward. A row whose engine differs from it is marked, and the site renders that in red.
1132-
const engineOf = (g) => (g && g.rig && g.rig.engine && g.rig.engine.commit) || null;
1133+
// THE INSTRUMENT, NOT THE COMMIT - the same resolution C8 uses, from the same file.
1134+
//
1135+
// C8 groups the board by instrument: commits whose BUILT BINARIES are byte-identical are one
1136+
// instrument, attested in site/instrument-equivalence.json. This function compared raw shas, so
1137+
// gen-data and check-consistency disagreed about what "the same engine" means - C8 would pass a board
1138+
// that gen-data then marked as mixed and (under OTB_SINGLE_ENGINE) blanked. Two commits that provably
1139+
// build the same binary cannot be a real difference in one place and not the other.
1140+
//
1141+
// Falls back to the raw sha for any commit the file does not attest, which is the safe default: an
1142+
// unlisted commit is its own instrument, so silence never merges anything.
1143+
const equivalence = (() => {
1144+
const f = join(HERE, "instrument-equivalence.json");
1145+
if (!existsSync(f)) return new Map();
1146+
return instrumentOf(readFileSync(f, "utf8"));
1147+
})();
1148+
const engineOf = (g) => {
1149+
const sha = (g && g.rig && g.rig.engine && g.rig.engine.commit) || null;
1150+
return sha == null ? null : (equivalence.get(sha) || sha);
1151+
};
1152+
// The raw commit, for the per-row stamp a reader sees. The instrument decides COMPARABILITY; the sha
1153+
// is still what identifies the exact tree, and collapsing it here would hide which commit ran.
1154+
const engineShaOf = (g) => (g && g.rig && g.rig.engine && g.rig.engine.commit) || null;
11331155
const newestRow = gateways
11341156
.filter((g) => displayedMeasuredMs(g) > 0)
11351157
.sort((a, b) => displayedMeasuredMs(b) - displayedMeasuredMs(a))[0];
11361158
const boardEngine = engineOf(newestRow);
11371159
for (const g of gateways) {
1138-
const sha = engineOf(g);
1160+
// `sha` is what ran; `inst` is what it is comparable TO. A row is current when its INSTRUMENT
1161+
// matches the board's, so two commits proven to build the same binary both read as current while
1162+
// the row still reports the exact commit that produced it.
1163+
const sha = engineShaOf(g);
1164+
const inst = engineOf(g);
11391165
g.engine = sha
1140-
? { sha, short: sha.slice(0, 7), current: boardEngine == null || sha === boardEngine }
1166+
? { sha, short: sha.slice(0, 7), current: boardEngine == null || inst === boardEngine }
11411167
// A row with no engine stamp predates the stamp entirely; saying so is better than implying it
11421168
// matches, and better than omitting the field so the render site has to guess.
11431169
: { sha: null, short: null, current: false };

‎site/instrument-equivalence.json‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,22 @@
4040
},
4141
"verified_at": "2026-08-02T19:00:00Z"
4242
}
43+
},
44+
{
45+
"id": "otb-e97eb008",
46+
"commits": [
47+
"80030c2fe13e9312f7cddd5db4c5908a1e54d94e",
48+
"7fd350ed5ecc7cd60953a33d78afc15fd8ec74d7"
49+
],
50+
"reason": "busbar 1.5.0 measured at 80030c2f. The other thirteen were then re-measured PINNED to that same commit (BENCH_COMMIT=80030c2f) precisely so the board would be one instrument - and they came back stamped 7fd350ed, because run-on-ec2.sh derived the stamp from the operator's local HEAD instead of the commit the boxes fetch. They ran the pinned tree; only the label was wrong. 7fd350ed is 80030c2f plus one board commit (drop the 1.4.1 declaration, move a star record, add a snapshot) and touches no engine file. The stamping bug itself is fixed in the same change that adds this entry, so the two can no longer diverge; this entry exists because the artifacts on disk were already stamped by the broken path and re-running fourteen gateways to correct a label would change no measurement.",
51+
"evidence": {
52+
"method": "cargo build --release --bin otb at each commit in a separate detached git worktree, same host and toolchain, hashed with shasum -a 256. `git diff 80030c2f 7fd350ed -- engine/` is also empty, but the binaries are the admissible evidence and the diff is only what made the entry worth checking.",
53+
"otb_release_sha256": {
54+
"80030c2fe13e9312f7cddd5db4c5908a1e54d94e": "e97eb00893a1c6c4c4960c27920313b92ad1b00e6ca0e2a0b056760808ea0a60",
55+
"7fd350ed5ecc7cd60953a33d78afc15fd8ec74d7": "e97eb00893a1c6c4c4960c27920313b92ad1b00e6ca0e2a0b056760808ea0a60"
56+
},
57+
"verified_at": "2026-08-03T18:10:00Z"
58+
}
4359
}
4460
]
4561
}

0 commit comments

Comments
 (0)