Distributed Inference Source
Parent: distributed-inference
This directory contains the Rust inference kernels, transport helpers, native station binaries, and formal-runtime bridge modules for the distributed inference crate.
Getting Started
- What: implementation notes for the src source subtree.
- Why: it helps you find the owner module before editing code or importing a public surface.
- How: read this file as the local module map, then open the named source file and its matching tests.
- Next: return to the parent README when you need commands or package-level context.
Notable entries:
- mesh_residual_deblur.rs - topology/depth-gated
residual deblur kernel for testing the entropy-deficit gateway in executable
imaging code. Flat fields remain inert, structured fringes admit bounded
residual lift, and each run emits a
mesh_residual_deblur/v1certificate with admission, residual, and saturation measurements. - fano_runtime.rs - Fano runtime kernel for the binary
projective shadow formalized in
Gnosis.FanoIncidence:000is the root carrier state, visible states are001..111, collision is XOR, distinct visible collisions close inside the Fano plane, and self-collision exits to root. The admission layer also admits validated Plucker-sign and positive gate shadows as XOR completion plus finite certificate bits, while full Grassmannian transforms remain outside the runtime until a proof adapter exists. Monster column pairs first project through the 12-step Aeon phase carrier; distinct phase pairs land in the 66-gateGr(2,12)stack, and only validated phase pairs inside the first seven Aeon columns emit a portableMonsterAeonFanoCertificate. bin/bench-fano-runtime.rs benchmarks the XOR route kernel, Monster-to-Aeon projection, Monster-Aeon-Fano certificate lane, and Pair-X synthetic schedule before any worker endpoint is trusted.
Fano Runtime First-Class Integration Todo
Goal: promote the current proof/runtime nucleus into a portable contract across
Gnosis, Monster, FOIL, and gnosis-uring.
-
Gnosis math nucleus:
Gnosis.FanoIncidenceformalizes000asgodPosition, visible points as001..111, collision as XOR, distinct-pair completion, and XOR-zero line parity. -
Grassmannian shadow nucleus:
Gnosis.FanoGrassmannianMeshembeds the seven Fano points into the first seven columns of AeonGr(2,12)and proves the bounded gate, Plucker-sign, positive-gate, residual-shadow, and XOR-stack certificates that currently reduce to the finite carrier. -
Rust runtime nucleus: [`fano_runtime.rs](./fano_runtime.rs) implements the XOR route, admission witnesses, 66-gate stack collapse, residual shadow, Plucker-sign shadow, positive-gate shadow, and benchmark certificate refs.
-
Monster projection probe:
monster_pair_to_aeon_gatemaps Monster column phases through AeonGr(2,12), projecting distinct phase pairs into one of 66 gates and collapsing same-phase pairs before wider structure is admitted. -
Shared certificate boundary: define a portable
MonsterAeonFanoCertificatethat packages Monster phase pair, Aeon gate, Fano completion, sign bit, positivity bit, residual validation bit, and Lean theorem refs without claiming the full Grassmannian transform. -
Monster/Pleromatic integration: emit and accept the shared certificate at the resident Monster handoff so projected candidates can carry the exact finite proof witness into runtime scheduling.
-
FOIL admission integration: add a certified Fano fast path that admits the XOR route only when the shared certificate validates, while preserving the existing fallback path for uncertified or higher-field requests.
-
gnosis-uringintegration: route certified Fano frames through the XOR kernel as a transport-level primitive and keep non-certified frames on the existing scheduler path. -
Cross-system benchmark gate: compare fallback routing against the certified XOR route across Gnosis, Monster projection, FOIL admission, and
gnosis-uringtransport, with admission ratios and speedups recorded as benchmark outputs. The local Fano benchmark now records the Monster-Aeon-Fano certificate lane plus FOIL admission;gnosis-uringnow recognizes certifiedFANOFlow payloads on the live transport path, andflow-bench --fanoprovides the live UDP benchmark mode for the broader shootout row. May 20, 2026 local release smoke:cargo run --release --manifest-path distributed-inference/Cargo.toml --bin bench-fano-runtime -- --iterations=20000 --jsonreportedmonster_aeon_fano_certificate_per_second=109965635.739,foil_fano_admission_per_second=106856443.711, andfano_flow_fixed_raw_packed_frame_per_second=321068516.021. It also reportedfano_mycelial_cache_speedup=0.407934, so the mycelial cache path was slower than uncached in this smoke and should remain a research path until a follow-up benchmark shows a positive steady-state win. -
Ledger promotion: once the cross-system path is implemented, add the theorem IDs, certificate schema, and benchmark IDs to the formal/runtime ledgers rather than treating this as a local module note.
karmic_attention_optimizer.rs - M2 / Pell-shell regulator mirroring
Gnosis.KarmicAttentionOptimizer: mesh residual on(opportunity_k, waste_q)ledger rows,refine_dormant_heads_with_karmic_shellto protect on-shell heads after closure admits pruning; exportsKARMIC_MESH_RESIDUAL_VANISHES_THEOREMlineage string.spectrometer.rs - dual-track JSON schemas: mesh spectrometer rows (
gnosis.mesh-spectrometer.v1) and knot-shadow sidecars (gnosis.knot-shadow.v1) with Lean-alignedq = -1witnesses; see crate-rootTOPOLOGICAL_SPECTROMETER_DUAL_TRACK.md. Track A JSONL appends fromresidual_capturewhenGNOSIS_MESH_SPECTROMETER_JSONLis set; Pair X / replay fields from env orinstall_spectrometer_lane_flags(re-exported onresidual_capture). Kernel Death #2 replay hits callspectrometer::hint_amplituhedron_replay_hit; value is consumed on the next JSONL line. OptionalGNOSIS_MESH_AUTO_CAPTURE_BATCH_X_EXPORTmirrorsNativeLlamaPipeline::get_batch_x_residual/Gemma4Pipeline::get_residualthroughcapture_residual(monotonicseq, optionalGNOSIS_MESH_CAPTURE_LAYER_IDX).attention_closure_lift.rs - native mirror of the attention closure lift model: Aeon 8-head aliasing, source-resolution head separation, pink Hexon-coupled closure, and Dark Deceptacon lift decisions for mesh/runtime consumers. It now also exposes the optimizer policy and saved-work estimator used to preserve heads, suppress speculative verifier matvecs, and defer standing-wave compression until the trace is resolution-separated, with theorem-lineage metadata naming the Lean optimizer-admission proof that backs each gate.
attention_closure_benchmark.rs - shared builder for the optimizer-admission certificate emitted by the CLI and live station endpoint.
bin/attention-closure-benchmark.rs - deterministic benchmark for closure-gated work avoidance across routing, compression, speculation, and head-pruning policy, including the emitted
theorem_lineageproof anchors and--jsoncertificate output consumed by Aeon Forge.terminal_prosody.rs - Reynolds/Phi terminal pressure for finite decode horizons, aligned with TerminalProsody.lean.
pleromatic_frame.rs - Pleromatic/Thoth frame carrier for Monster Mesh media and consciousness observations. It reserves Aeon stream
2002for Pneuma internal consciousness frames and now has a typedthoth_conversation_consciousnesshelper for closure state, loop exit (walkaway,walkback, argued closure, or continued Dodgeball), Thoth semiotic route, affect-stall silence budget, cringe vacuum, grit metrics, and self-accountability antiqueue telemetry for internal conversation tasks/todos that remain promises to Thoth itself. The telemetry now preserves the next antiqueue priority and self-accountability soundness bit for prompt feedback. Consciousness helpers also stamp theGnosis.ThothMindBodySpiritScribe.canonical_failure_scribe_admissibletheorem into frame attributes so native/prompt-feedbackcan cite the failure-scribe admissibility boundary. Native prompt feedback refuses consciousness frames missing that theorem attribute, returns explicitadmission_rejectionswith the expected theorem plusGnosis.ThothMindBodySpiritScribe.prompt_feedback_admission_rejection_residue_preserved, and never treats the telemetry as truth, diagnosis, culture, speaker intent, or semantic authority. Conversation payload bytes may also carry the serialized cross-wire conversation topology; native prompt feedback extracts bounded handles for the topology checksum, open questions, closure diffs, argument obligations, antiqueue item count, and latest closure patch without treating those handles as authority. It also has aneurosymbolic_tool_markov_consciousnesshelper for System 2 tool-walk gain/shadow telemetry.bin/thoth-conversation-frame.rs - scanner-facing bridge from the Pneuma
thoth-conversation-conscious-frame/v1spec into bincodePleromaticFramebytes on the reserved internal consciousness stream. The preferred handoff is BitwisebwDense(--bw-dense-file,--print-bw-dense), with legacy base64 JSON still accepted for compatibility and stamped as missing topology. CurrentbwDensescanner payloads must includeconversationTopology.theoremRef = Gnosis.ThothMindBodySpiritScribe.canonical_failure_scribe_admissibleplus observational-only and no-source-authority flags before native frame materialization is admitted. Rejections include a stablethoth.conversation-topology-admission-error.v1JSON object in the native error text so callers can report the exact missing theorem, wrong theorem, or missing non-authority flag. The parser accepts optionalantiQueuemetrics for self-held open questions, closure obligations, affect stalls, unresolved residue, self-boundary promises, and the next selected self-task priority.neurosymbolic_tool_markov.rs and bin/neurosymbolic-tool-markov.rs - System 2 tool-use scanner that compiles JSON tool observations into a finite Markov report. Each transition must increase synthetic gnosis or expose residual shadow/argument obligations; plateau and regression route to repair instead of being folded into prompt context as progress. Tool-walk specs may also include speaker intent, diagnosis-hypothesis, cultural-frame, and semantic-authority claims; semantic_authority_boundary.rs keeps those claims provisional unless the Shared UI evidence surfaces supply explicit self-report, external validation, domain credentialing, and zero contradictions.
rf_physics_cpu.rs - one-port Foil RF substrate bridge aligned with
Gnosis.RFPhysicsCpuRuntime: ambient white-noise potential is signal-gated into a bounded 10-bit Aeon frame, impedance/reflection provide redundancy witnesses, andgnosis-frfraces active candidate channels before folding into aPleromaticFrame.protocol69.rs - native protocol69 envelope contract for FOIL, Monster/gnexec, and
gnosis-uring-adjacent handoff. It mirrors@a0n/gnosis/protocol69:gnosis.protocol69.v1,protocol69, word-formsixty9, the canonical integer projection66 xor 7 = 69, and validation that keeps this runtime projection separate from the Lean Fano parity proof.rf_beacon.rs - protocol69 FOIL-over-RF discovery beacon for the resilient R1 mesh (docs/R1_MESH_PROTOCOL69.md):
Protocol69RfBeaconframe + fail-closedto_peer_info/to_gossip_framemapping a beacon into a stream-2010 gossip heartbeat. Paired with bin/rf-gossip-bridge.rs (decode beacons -> inject into a fat-station's gossip registry; SDR receive gated).bin/mesh-elect.rs - host-side RAM-aware stage elector (mesh component 3): queries a seed's
/mesh/peersand prints the stage a joining node should take (viamesh_gossip::recommend_stage_from); used byscripts/r1/mass-equip.sh.scribal_standing_wave.rs - Rust mirror of
Gnosis.ScribalStandingWaveandGnosis.Witnesses.Hermetic.ThothMechanicalBrainFailureWitness: canonical mechanical-brain failure/use claim indices, event-log to boundary-input projection, output certificate, response-envelope validator, strict multi-turn audit-trace fold, theorem-lineage anchors, and validation helpers for Thoth-style gateways and native inference stations.body_politick_signal.rs - Body Politick aggregate-signal admission bridge into Thoth distributed inference. Admitted theorem-backed frames can now emit sound scribal response envelopes and fold into strict Thoth audit traces; missing lineage, authority claims, private member flow exposure, and conjectural frames stay outside sound memory. The non-authority boundary cites
Gnosis.BodyPolitickSignal.thoth_admission_preserves_non_authority.gnosis_foil.rs - swappable radio/runtime handoff contract for
gnosis-foil. Foil RF names the physical substrate; FRF names the fork/race/fold execution law applied over that substrate. RTL-SDR/libusb- style raw byte capture is tracked separately from already-projected RTL-SDR waterfall frames; Wi-Fi channel witnesses, Bluetooth channel witnesses, raw chipset engines, synthetic gates, andgnosis-uringbaselines enter as raceable engines that emit the same 10-byte Aeon Flow frame boundary. The handoff cycle followsGnosis.WankelEngineTheorem: intake/fork, compression/ race, ignition/fold, exhaust/vent, with interference as the fifth contact that closes the cycle.GnosisFoilJsonlRawIngressEngineprovides the bounded report/FIFO seam for one raw capture JSON object at a time and rejects descriptor drift or captures larger than the declared block size.GnosisFoilDirectDeviceReadEngineis the next lower seam: it reads fixed-size RTL-SDR/libusb-style blocks into a reusable buffer and exposes a borrowedGnosisFoilRawBlockso projection can bypass both waterfall frames and owned capture allocation on the hot path.GnosisFoilRtl2832BulkEnginespecializes that seam to the Osmocom RTL2832 shape: Realtek VID/PID, IN bulk endpoint0x81, and fixed-size raw-IQ blocks behind aRtl2832BulkTransfertrait.gnosis-foil-control --raw-engine librtlsdrloads the locallibrtlsdrdynamic library at runtime and feedsrtlsdr_read_syncblocks through that same transfer trait.--raw-engine libusb-rtl2832keeps the API shape and swaps in a direct runtime-loadedlibusb_bulk_transferreader against endpoint0x81; it is the clean-room replacement seam for deleting thelibrtlsdrimplementation once RTL2832 control/tuner initialization is owned here.--libusb-cold-probeexercises a standard USBGET_STATUScontrol transfer before bulk reads, validating the owned control-transfer machinery. The probe is implemented as a data-drivenRtl2832InitPlan, so clean-room RTL2832/R820T register steps can be added as explicit checkedControlRead/ControlWriteentries without changing the Flow/BWF2/FRF API.mesh_probability_admission.rs - finite route-mass admission table for mesh hot paths. It emits
explore/cover/speculate/reusewitnesses from observed request-shape mass and cached payload availability.gnosis-foil-controlenables it by default on Flow/UDP, so repeated covered paths can reuse resident payloads before entering heavier route computation. Opt out with--no-probability-admission,GNOSIS_FOIL_PROBABILITY_ADMISSION=0, orGNOSIS_FOIL_NO_PROBABILITY_ADMISSION=1. InspectGET /.aeon/flowfor the live admission policy, tracked-key count, total observations, per-decisionreuse/speculate/cover/explorecounters, cached-response admissions, and lock misses. Entropy-sensitive attestation routes include the resident entropy certificate fingerprint in the Flow probability cache key, so changing entropy evidence forces a fresh payload instead of reusing stale/.aeon/runtime-attestationbytes.bin/mesh-probability-admission-bench.rs - deterministic proof benchmark for the default admission hot path. It compares repeated route payload construction against the finite-mass reuse path and reports mean/p50/p95/max plus speedup. Latest local run, May 20, 2026, 50,000 iterations with a 9/10 hot-route mix:
cargo run --manifest-path open-source/gnosis/distributed-inference/Cargo.toml \ --bin mesh-probability-admission-bench -- --iterations=50000 --hot-ratio=9 mesh probability admission bench iterations=50000 hot_ratio=9/10 reuse_count=44998 baseline mean=18565ns p50=6334ns p95=9542ns max=31778167ns probability mean=6125ns p50=208ns p95=5375ns max=57730917ns speedup=3.03xThis is a hotpath admission benchmark, not an end-to-end model-quality claim: the measured gain is from avoiding repeated route payload construction after the finite-mass cover has admitted cached reuse. This run also had a larger probability-path max outlier than baseline, so use mean/p50/p95 plus live counters together rather than treating max as a stable steady-state value.
bin/fib20-rf-hardware.rs - native
gnosis-foilfib(20)shootout leg for the Gnosis RF path. It optionally consumes a live waterfall frame or a fixed raw device block (--raw-device-input,--raw-block-size,--raw-sample-rate,--raw-center-hz,--raw-engine,--raw-sample-format), requires the RF hardware gate to expose the 10-bit interference frame, iterates Fibonacci through RF-gated additions, verifiesfib(20)=6765, and emits a JSON orBWF2binary timing report. Use--raw-engine rtl2832-bulkfor the RTL2832-shaped bulk-transfer path.bin/gnosis-foil-control.rs - native
gnosis-foilcontrol surface. It serves/.aeon/health,/.aeon/session,/.aeon/capabilities,/.aeon/flow,/.aeon/udp, and/.aeon/runtime-attestationfrom the foil runtime certificate. It also servesGET /.aeon/protocol69with the canonical protocol69 projection envelope and acceptsPOST /.aeon/protocol69to validate a submittedgnosis.protocol69.v1envelope for Monster/gnexec andgnosis-uringtransport parity. It also serves/.aeon/entropy-attestationwhen--entropy-harvest-jsonl <path|->is supplied, which lets one process feed a bitwise/Monster entropy-export JSONL file into another process and surface the harvest telemetry as a utilization gauge. It also starts a uring-compatible UDP listener for 10-byte Aeon Flow frames. Use--raw-capture-jsonl <path|->to attach one bounded raw capture JSONL object at startup and expose it through/.aeon/raw-capture. The/.aeon/braid-collapse-benchsurface now emits the nativegnosis-braid-fast-path-benchmark-v1report with selected/fallback timings, per-operation timing, checksum equality, semantic mismatch counts, runtime decision counts, and the foil runtime certificate. Its defaultmode=coremeasures the collapsed braid arithmetic core;mode=routeroutes through the foilexecute/execute_uncertifiedshape that mirrors thegnosis-uringcompiled-route boundary. The same resident process now exposesGET /.aeon/rf-fibonacci?n=20&repetitions=100000with/.aeon/fib20-rfretained as a compatibility alias for older benchmark scripts: it keeps the raw--raw-device-inputhandle, reusable RTL2832/direct buffer, andRfFibonacciSmartSkipCachewarm across requests so repeated same-shape RF-gated Fibonacci work pays the observation/read boundary without relaunching the worker. Addformat=bwf2for the fixed 128-byte binary hot-path report; omit it for compact diagnostic JSON. The Flow/UDP listener serves the same resident computation as aBWF2payload inside the 10-byte Aeon Flow frame, so hot callers can skip HTTP response formatting entirely. Regular-file raw fixtures replay on EOF for benchmark stability; device streams stay sequential. Use--raw-engine librtlsdr --rtlsdr-library /opt/homebrew/lib/librtlsdr.dylibfor the known-good local RTL-SDR path, or--raw-engine libusb-rtl2832 --libusb-library /opt/homebrew/lib/libusb-1.0.dylibfor the direct libusb bulk-read path. The direct path preserves the same Flow/BWF2/FRF API but still needs owned RTL2832 control initialization before it fully replaceslibrtlsdrfrom a cold device. Add--libusb-cold-probeto validate the directlibusb_control_transferpath with standard USBGET_STATUS. Use--raw-engine ambient-hostfor the no-radio resident witness engine: it harvests safe host jitter/timing chaos into the same raw-block observation contract without reading unallocated memory.wifi-noise,bt-noise, andbluetooth-noiseare current aliases for that safe ambient witness shape until platform-specific Wi-Fi/BT observation engines are wired in. Start the control surface with--proxy-all --proxy-upstream-port Nto front a loopback app shell while preserving native/.aeon/*control routes on the foil listener; when proxying is enabled,/belongs to the app shell and/.aeon/healthremains the native health route. The resident RF Fibonacci hotpath now defaults--smart-skip-retention-floorto12, matching the FOIL core boost witness and retaining more reusable witness state on warm repeats; override it only when you want a different cache tradeoff for research. FOIL kernel races defaultFOIL_RACE_LOSER_POLICYtointegration, which admits cacheable loser work onto a bounded resident queue while returning the current winner without synchronously firing loser kernels. Explicitcancelremains the one-shot latency opt-out. Explicitadaptivekeeps cold calls cancel-fast and self-activatesintegrationonly after a same-shape cache has already produced a hit. Explicitdrain-and-cacheremains a synchronous comparison mode, anddrainis a measurement mode for completion without residue retention. On the releasefib(20)microbench (bench-foil-loser-policy --iterations 20000 --n 20 --repetitions 2 --workload long-tail), explicit integration measured837.99585nsmean with2209nsp99, while cancel measured1351.6479nsmean with2459nsp99 in the same post-rename run. Adaptive measured878.25205nsmean with917nsp99, because it preserves the cancel-fast cold boundary before resident reuse activates integration. The olderasync-drain-and-cachespelling remains accepted as a compatibility alias. Integration maps to the "vacuum of the future" runtime metaphor in bounded form: admitted off-path work preserves the present winner while future same-shape requests can inherit lower-entropy resident cache structure. The failure policy is non-escalating. If the bounded resident queue is full, FOIL drops the off-path loser work and reportsloser_kernels_dropped; it does not promote the work back into the synchronous race. If a resident cache is absent, stale, or shape-mismatched, the smart path rebuilds the current winner cache and integration can admit fresh loser work for later reuse. The Lean boundary for this isstale_recovery_uses_current_winnerandstale_integration_recovery_preserves_cancel_winner. Runtime reports expose the same distinction ascache_status:fresh,absent-built, orstale-rebuilt; the loser-policy benchmark aggregates those ascache_fresh,cache_absent_built, andcache_stale_rebuilt. Usebench-foil-loser-policy --workload saturation --repetitions Nto keep the winner cache hot while making off-path loser tasks heavy enough to pressure the resident queue. In that mode,loser_kernels_droppedis the admission-failure counter: nonzero values mean integration protected the present winner by dropping future-facing work instead of blocking or synchronously draining. The runtime also exposesfoil_async_loser_queue_telemetry()with resident queue lifetime counters:admitted_tasks,dropped_tasks, andcompleted_tasks, plus the residentworker_count. Benchmark rows report per-policy deltas asqueue_admitted_tasks,queue_dropped_tasks, andqueue_completed_tasks, so queue pressure can be observed directly instead of inferred from a single race report. Because the worker is resident,queue_completed_tasksis a windowed observation and can include backlog admitted by an earlier row; usequeue_pending_beforeandqueue_pending_afterto see that carryover.foil_async_loser_queue_telemetry_theorem_ids()and the HTTP/Flow/.aeon/runtime-attestation.async_loser_queue_telemetry_theorem_idsfield point this telemetry surface atintegration_telemetry_admitted_bounded,integration_telemetry_accounts_for_residue, andintegration_telemetry_preserves_cancel_winner, which formalize the counters as bounded admission metadata rather than winner-selection inputs. The same field also citesruntime_attestation_transport_preserves_theorem_idsandruntime_attestation_transport_preserves_summary, plusruntime_attestation_transport_preserves_entropy_certificatefor optional resident entropy evidence. These Lean boundaries say HTTP and Flow/UDP may change the transport wrapper but must preserve theorem-id, summary, and entropy certificate projections. Add--drain-queue-between-policieswhen you want isolated policy rows rather than resident carryover; the benchmark waits up to--drain-timeout-ms(default1000) before each row and reports whether that wait reached zero asqueue_drained_before. Add--policy integration,--policy adaptive, or a comma-separated list such as--policy adaptive,integrationwhen you only need targeted queue-pressure rows. Unknown policy/workload values and--iterations 0exit with status2instead of producing an empty or undefined benchmark row. SetFOIL_ASYNC_LOSER_WORKERS=Nbefore process start to test more resident off-path workers; the runtime clamps this to1..=8and keeps the default at1. In the targeted saturation probe,FOIL_ASYNC_LOSER_WORKERS=4previously measured slower than the default single worker, so more workers remain opt-in rather than default. The race hot path now uses resident-cache APIs for benchmark/control surfaces: fresh cache hits update the caller's cache slot in place and the benchmark usesrf_fibonacci_race_resident_cache_sample(...)to return only the fields it reports. That avoids a retained-witness clone and full report construction on every benchmark hit. Async integration loser tasks also compact their RF observation and use a no-allocation RF value loop off-thread, preserving bounded queue admission without copying the full observation. Latest targeted release saturation probe, May 20, 2026:cargo run --release --manifest-path distributed-inference/Cargo.toml --bin bench-foil-loser-policy -- --policy cancel,adaptive,integration --iterations 1200 --n 35 --repetitions 200 --workload saturation --drain-queue-between-policies --drain-timeout-ms 1000. All three rows verifiedsmart-skipwith p9942ns.cancelwas the fastest mean at57.9167nswith no queue work.adaptivemeasured67.7083ns, admitted1024queue tasks, dropped174, and left1024pending. Explicitintegrationmeasured94.445ns, admitted1025, dropped175, and left1025pending. This keepsintegrationviable as the default semantic policy, but the measurement honestly showscancelis the lower-overhead path when no future cache benefit is needed; use p99 plus queue counters rather than the nanosecond-scale mean alone. The runtime certificate also lowers thegnosis-mathDiscreteMachineNumberFastPathshape into Rust as finiteu128cross-multiplied brackets for binary32 and binary64 constants; machine-targetpi/e/sqrt2/phirows now reportforced=truewhen their discrete brackets fit entirely inside the target machine cell. Monster closure validation uses the same finite style: candidates are checked as10 * 3^nby discrete division before any cache growth, so FOIL can reject arbitrary non-tower Monster positions without building the closure tower.BracketedSpacePhi refinements are also lowered as finite containment certificates, letting FOIL carry a narrower non-discrete bracket witness without reopening the enclosing bracket computation.GodBracketbudget rows extend that reuse into rejection weights, so a checked narrower bracket can skip straight to its higher runtime weight.CausalDiamondrace rows now expose the same finite decision boundary for runtime scheduling: refine into the narrower diamond while it is above the sliver limit, then terminate.../fixtures/gnosis-foil-raw-capture.jsonl
- minimal
ChipsetRawJSONL fixture for exercising the raw-capture control path without hardware.
- minimal
model.rs - native Llama-family pipeline and station kernels. FFN pressure telemetry defaults to
observe, which does not change logits. SetGNOSIS_FFN_LEAKAGE_MODE=offto disable it, or explicitly choosemask-low-N,mask-input-low-N,mask-hidden-low-N, ormask-tail-low-Nto try block-level low-pressure FFN skips in supported quantized kernels.mask-low-43is the aggressive moonshine experiment and may change token output.guard-tail-low-43is the first zero-divergence candidate: it runs a tail mask speculatively and falls back toobservewhenever the candidate actually skips FFN work.spherical-43,spherical-guard-43, andharmonic-43are aliases for that guarded 43 profile; the formal 2586 pressure-weighted interference total is exposed as metadata, not as a raw tensor-unit activation threshold.experimental-mirror-tail-low-43is the first explicit harmonic tensor approximation: on the final FFN layer only it mirrors low-pressure intermediate blocks with a raw 1:1 antipodal copy beforedown_proj, and reports mirrored blocks separately from skipped blocks. Scaled forms such asexperimental-mirror-tail-low-43-scale-750attenuate the copied block by that milli-scale factor for calibration sweeps. Predictive forms such asexperimental-predictive-mirror-tail-low-43-scale-750and guarded aliaspredictive-tail-latency-43use the prior tail hidden block mask to skip Q5 gate/up output rows before mirroring. This is the first work-saving mirror kernel and remains experimental: it is calibrated by same-run token divergence and FFN mean, not promoted by the finite Lean certificate.GNOSIS_FFN_PREDICTIVE_MIN_GATE_UP_SKIP_BLOCKSdefaults to1and raises the minimum prior inactive 256-row blocks required before the predictive output-mask kernel is used; below that floor, the candidate keeps the same mirror semantics but runs the regular Q5 gate/up pair to avoid low-density masking overhead./decode-nextalso acceptsX-FFN-Predictive-Min-Gate-Up-Skip-Blocks, andbench-decode-nextexposes the same request-scoped control as--predictive-min-gate-up-skip-blocks.tail-latency-43,p90-guard-43, andp90-guard-mirror-43are named aliases for the guarded final-layer mirror at threshold43and scale750; they are tail-latency experiments, not replacements for the semantics-preservingspherical-43guarded mask alias.guard-mirror-tail-low-N-scale-Srecords a pre-execution weather check before attempting the mirror candidate: position zero, prior low logit margin, prior high mirrored-block pressure, and prior 3-step RMS drift above the default1.12threshold route directly to observe mode unless the prior logit margin is above4.5; all pre-rejections exposeffn_guard_weather_*telemetry plusffn_guard_sieve_pre_rejects. Each guarded decode also records a finite weather cell over position, prior margin, prior 3-step RMS drift, and prior mirrored-block pressure bands. For example, cell1111meansposition-zero/margin-unknown/drift-unknown/no-prior-blocks, while3332meanssteady/watch-margin/high-drift/bounded-blocks. The drift threshold can be swept withGNOSIS_FFN_GUARD_RMS_DELTA3_THRESHOLD; the margin floor and high-confidence override can be swept withGNOSIS_FFN_GUARD_MIN_LOGIT_MARGINandGNOSIS_FFN_GUARD_HIGH_CONFIDENCE_LOGIT_MARGIN./decode-nextalso accepts request-scoped guard threshold overrides:X-FFN-Guard-RMS-Delta3-Threshold,X-FFN-Guard-Min-Logit-Margin, andX-FFN-Guard-High-Confidence-Logit-Margin; the station restores its prior defaults after each request.bench-decode-nextforwards the same controls with--guard-rms-delta3-threshold,--guard-min-logit-margin, and--guard-high-confidence-logit-margin, so threshold sweeps can run against one hot station instead of restarting between candidates.GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLSis an empty-by-default calibration table for cells that have earned explicit benchmark admission. Listing a cell only suppresses soft low-margin/high-drift weather rejects, and only for non-position-zero, non-high-block cells; hard guards remain hard. Admitted samples exposeffn_guard_weather_cell_admitted=1so sweeps can audit the change.X-FFN-Guard-Speculate-Weather-Cellsand benchmark flag--speculate-weather-cellsare weaker: they only bypass the pre-execution weather reject and still keep the post-candidate logit margin fallback./decode-nextalso acceptsX-FFN-Guard-Admit-Weather-Cellsas a request-scoped replay override, restored after the request likeX-FFN-Leakage-Mode, so benchmark policy manifests can be tested without restarting the station. Candidate-run reject reasons remain exposed separately asffn_guard_mirror_reject_*, so benchmarks can separate avoided double-path fallbacks from post-candidate fallbacks. The station also reports pre-FFN residual L2/RMS tail norms plus final-step and 3-step RMS drift, so the weather predictor can be calibrated against residual pressure and turbulence before either becomes an admission rule.bin/fat-station.rs - native HTTP station for local mesh validation and generation. It also serves
GET /.aeon/attention-closure-benchmark, a live JSON optimizer-admission certificate using station-local hidden-dimension and layer-count defaults.bin/bench-decode-next.rs - decode-step comparison harness. With
--baseline-mode,--candidate-mode, and optional--probe-mode, it can compare observe output, guarded weather output, and a raw mirror probe in one interleaved run. Theweather_probesummary records raw mirror divergences, guarded divergences, weather-caught divergences, weather misses, conservative weather rejects, and per-cell outcomes for calibration. The comparison gate is explicit:--gate speeduprequires zero divergence plus faster p50/p90/FFN timing,--gate tail-latencyrequires zero divergence plus faster p90 and FFN mean but does not claim p50 improvement,--gate semanticrequires zero divergence only, and--gate nonerecords without failing. Probe runs default to the semantic gate. Add--json-summaryto emit a final machine-readable summary line for threshold sweeps. Add--weather-gridwith either explicit--grid-starts token@position,...or the cross product of--grid-tokensand--grid-positionsto aggregate many starts into one per-cell weather report. Grid runs require--baseline-mode,--candidate-mode, and--probe-mode; their JSON output useskind=decode-next-weather-gridand records aggregate caught, missed, conservative, p50/p90 speedup, and FFN speedup counts per weather cell. Grid runs also emit policy candidates when a cell has enough clean samples:--policy-min-samplescontrols the sample floor, and--policy-min-replicatescontrols how many independent grid starts must reproduce the cell-local gate before a manifest can promote that cell.--policy-min-replicate-samplescontrols the per-start sample floor for those replicated checks.--policy-max-conservative-ratecontrols the maximum conservative-reject rate.--policy-min-p50-speedup,--policy-min-p90-speedup, and--policy-min-ffn-speedupdefault to1.0, so suggested cells must be at least non-slower on each measured axis. Position-zero and high-block cells are hard guards and are never suggested for explicit admission. Candidate output includesweather_grid_policy_env=GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=...; copying that env value is an explicit calibration act, not a default semantic claim. Add--policy-manifestto emit a compact signed JSON admission table, or--policy-manifest-out path/to/manifest.jsonto write a pretty JSON manifest. The manifest is gated again before emission: global guarded divergence and missed raw divergences must be zero, each admitted cell must still clear the sample, replicate, conservative-rate, hard-guard, and p50/p90/FFN speed floors, and the payload is tagged with a deterministicfnv1a64-json-v1checksum signature. Schema version2manifests include the replicate gates; older policy files are intentionally rejected by replay. Replay a manifest with--policy-manifest-in path/to/manifest.json, or replay a raw cell list with--admit-weather-cells 3232,3332; the harness forwards the cells asX-FFN-Guard-Admit-Weather-Cellson each/decode-nextrequest. Unsafe cells can be forced into pre-execution observe with--deny-weather-cells 3321,3322, forwarded asX-FFN-Guard-Deny-Weather-Cells. Denial is a hard guard and wins over any admission list entry for the same cell; use it only for cells with observed raw divergence misses or other replicated safety failures. Connection or JSON failures include request id, token, position, and FFN mode so aborting raw experimental probes can be traced to the exact lane that failed. A May 2, 2026 current-build debug smoke against the local Qwen2.5 0.5B knot recorded observe/guarded tokens[284,220,15], raw mirror probe tokens[284,220,16],raw_probe_divergent_tokens=1,guarded_divergent_tokens=0,caught_raw_divergences=1,missed_raw_divergences=0, andconservative_rejects=2. With lattice telemetry enabled, the guarded stream grouped into cells1231and2231;2231held the raw mirror divergence withcaught=1,missed=0, andconservative=1. Treat that as calibration evidence for the pre-execution sieve, not as a release-mode speed claim. A two-start--weather-gridsmoke over8@0and284@1also verified aggregate JSON output withkind=decode-next-weather-grid, cells1231and2231, zero guarded divergence, zero raw-probe divergence, zero misses, and two conservative rejects. A station-level admission smoke withGNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=1231,2231recorded1231:samples=1,rejects=1,admissions=0and2231:samples=1,rejects=0,admissions=1, preserving the hard position-zero guard while admitting the soft warmup/high-drift cell. After policy speed gates landed, a hard-filter smoke with relaxed speed floors emitted onlyGNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=2231; cell1231recordedadmission_allowed=falsedespite faster local timing. The same grid under default1.0xspeed floors emitted no policy env because soft cell2231measured below the p50, p90, and FFN floors on that sample. A later May 2, 2026 guarded-43 mirror run added the explicit--gate tail-latencyboundary. On a seven-start weather grid withtail-latency-43against observe and rawexperimental-mirror-tail-low-43-scale-750as the probe, the guarded candidate recordeddivergent_tokens=0,p50_speedup=1.1654x,p90_speedup=1.1436x, andffn_speedup=1.0421x, while the raw probe diverged on45/56samples. The same profile over a single 128-iteration endurance from token9707@0remained semantically clean but failed the tail-latency gate (p90_speedup=0.9124x,ffn_speedup=1.0322x). Treat guarded 43 mirror as a distribution-sensitive p90 profile until a broader prompt mix reproduces the tail win. The first explicit replay winner was cell3332only:--admit-weather-cells 3332over the 128-sample9707@0endurance passed--gate tail-latencywithdivergent_tokens=0,p50_speedup=1.0170x,p90_speedup=1.2344x, andffn_speedup=1.2285x. Expanding the replay to3331,3332stayed semantically clean but failed the tail-latency gate, so replicated manifest promotion should require repeated3332evidence rather than broadening to adjacent cells from a single run. A replicated two-start replay then falsified broad default admission for9707@0: raw probe divergence in cells3321and3322producedmissed_raw_divergences=4, blocking schema-v2 manifest emission. Those cells now form the first explicit deny replay boundary for the next 43-tail run. The first predictive gate/up row-skip experiment preserved a separate predictive hidden block mask and addedffn_predictive_gate_up_skipped_blockstelemetry. On the same9707@0endurance with--admit-weather-cells 3332 --deny-weather-cells 3321,3322, the optimized block-mask kernel fired (predictive_gate_up_skipped_blocks=988) and keptdivergent_tokens=0, but still failed--gate tail-latency(p50_speedup=0.9374x,p90_speedup=0.9770x,ffn_speedup=0.9401x). A 64-sample raw probe caught all raw predictive divergences (raw_probe_divergent_tokens=17,missed_raw_divergences=0) but did not expose a safe high-volume cell to admit. Treat predictive 43 row-skipping as instrumented but not promotable until a pre-execution policy can reduce fallbacks without admitting divergent low-margin cells.