Skip to content

Ship stateless C3R Core API with guarded CLM System-One inference - #6

Draft
wilkont wants to merge 55 commits into
mainfrom
feat/stateless-production-api
Draft

wilkont wants to merge 55 commits into
mainfrom
feat/stateless-production-api

Conversation

@wilkont

@wilkont wilkont commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Stateless Core v1 scope

  • Dedicated C3R endpoint first; MC-1 is excluded.
  • Typed System-One questions: implemented and live privately.
  • Direct candidate ranking: implemented and live privately.
  • Text-only, non-storing Responses subset: implemented and live privately through independently verified controller fallback; CLM remains non-generative.
  • Production qualification target: System One is self-hosted CLM + Qwen3-8B; System Two is self-hosted DeepSeek V4.1 Flash on the existing 8×H100 node. No OpenRouter, no hosted production inference and no additional GPU infrastructure. This target is not yet production-qualified.
  • Trace collection and online learning: disabled. External effects / execute: disabled (501).
  • No C3R-trained weights, empirical DecisionMix or calibrated task-success claims.

Verified increment

  • 135 local tests pass; selected controller/provider modules pass strict typing.
  • The preceding 134-test snapshot passed independent Cloud Build on Python 3.11/3.12/3.13 and runtime/retention image scans. Exact final-head verification is still required.
  • The reviewed API and hardened CPU CLM head have fresh scans with zero HIGH/CRITICAL findings.
  • All 13 private live functional/security probes and scoped CLM-outage/operator-recovery drills pass.
  • Pinned encoder artifacts were checked against the running process's read-only mount. This is deployment-host evidence, not remote cryptographic attestation.
  • A short load pilot measured bounded 429/503 admission; it is not sustained capacity or a public canary.

Remaining production gates

  1. Dedicated, source-verifiable hardened Qwen encoder: scan, side-by-side parity and cutover.
  2. Same-node DeepSeek qualification after security review: preserve the raw scan, review every applicable HIGH/CRITICAL finding and independently qualify the running host kernel; then three canonical cold starts, 13 acceptance checks each, sustained mixed load, outage and bidirectional rollback evidence. No model restart while the security review is unresolved; no automatic host reboot.
  3. Actual infrastructure/provider cost attribution and conservative CVoC priors, without invented quality.
  4. Dedicated managed TLS endpoint, least-privilege secrets/gateway access, and payload-retention verification across public layers.
  5. External Requests/OpenAI SDK acceptance; sustained load/SLO measurements; full provider/gateway/encoder fault tests; alert delivery.
  6. Immutable artifact rollback, staged canary, evidence-matched release-owner authorization, and exact-final-head Cloud Build including encoder/head builds and scans.
  7. Only after the evidence passes: mark ready, merge, tag the exact merged commit and deploy its immutable artifacts.

PR remains draft. Research PR #2 is separate: its review does not silently become collection approval, and C3R-specific training is not a prerequisite for this stateless inference release. No public production declaration is warranted yet.

Kernel-header security qualification — 2026-10-01

The release criterion is zero unreviewed applicable HIGH/CRITICAL findings, not an artificially empty raw scan. The unchanged scan has 168 unique CVEs (5 CRITICAL, 163 HIGH), all attributed to linux-libc-dev. A pinned Canonical exact-product review supports not-affected status for 165; two lack an exact match and one is marked affected. Those three, exact-image inventory/JIT proof, independent review and the separate running-host assessment remain unresolved. No finding has been suppressed, no header/package metadata removed, and no production approval inferred. The private CVE matrix retains per-CVE raw findings, vendor evidence and OVAL/USN references. Prior build tests and image builds passed, but its CLM scan timed out and the DeepSeek scan did not run; that build is not a passed security gate.

@wilkont

wilkont commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Independent verification for this draft: Cloud Build 411ac97a-c9cb-4111-8f99-6b4cf2a5a6fe completed SUCCESS in the dedicated C3R staging project. It ran 125 tests on each of Python 3.11, 3.12, and 3.13; built and smoke-tested runtime and retention images; and passed the configured Trivy HIGH/CRITICAL image gates. The GitHub Actions checks did not start because the ColomboAI account remains billing-locked, as run 36765766237 reports.

This is build/security-scan evidence only. There is still no live CLM-backed production host, qualified /v1/responses or typed System-One contract, public C3R hostname, canary, or release-owner approval. Keep this PR draft and do not enable collection or promote public traffic.

@wilkont

wilkont commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Implemented and published the typed CLM/Responses increment and independent review fixes. Current source: 0a81568.

  • 135 local tests pass; selected controller/provider modules pass strict typing. Independent Cloud Build verified the preceding 134-test snapshot on Python 3.11/3.12/3.13 and scanned the runtime/retention images.
  • Typed inference now honors disable switches before provider calls. Readiness is coalesced for 15 seconds, exercises generation, and reports System-One availability independently of DeepSeek.
  • Pinned upstream encoder identities were verified against the running encoder's actual read-only mount. This is deployment-host evidence, not remote cryptographic attestation.
  • The reviewed API and hardened CPU head have fresh scans with zero HIGH/CRITICAL findings. The private updated API passed all 13 functional/security probes and scoped CLM outage/operator kill-recovery drills.
  • The short load pilot explicitly reports 429/503 admission rejections; it does not establish sustained SLOs or a public canary.

Private evidence for the authorized reviewer: https://github.com/ColomboAI-com/c3r-security-evidence/blob/main/evidence/c3r-core-v1-evidence-2026-09-30.md

PR remains draft: the separate encoder/shared DeepSeek image is not security-qualified, and measured infrastructure-cost integration, dedicated TLS/external SDK acceptance, complete outage/rollback/canary evidence, and exact release-owner authorization remain open. No shared DeepSeek/VM stop, public promotion, research trace collection, empirical calibration claim or MC-1 integration occurred. This stateless v1 does not require C3R-specific training, but it still requires its own production gates.

Reviewed local source: f1c4cbb. Qualification remains pending.
Reviewed local source: 9adf275. Qualification remains pending.
Reviewed local source: a7acb8c. Qualification remains pending.
Reviewed local source: 5a06bc7. Qualification remains pending.
Reviewed local source: 45f2a86. Qualification remains pending.
@wilkont

wilkont commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Incremental qualification update (not release approval): canonical checkpoint verification passed, but the newer candidate failed Triton compilation after development headers were removed. Recovery restored the incumbent and all 13 private synthetic API checks passed; Qwen stayed healthy. PR head 0333653 fixes the headers, adds a compiler preflight and blocks the known-failed image. The rebuilt candidate passes that probe but its unsuppressed scan reports 168 HIGH/CRITICAL findings on kernel-header metadata. Please review the exact-image applicability evidence and separate running-host kernel assessment before any exception or further candidate restart. Raw scan and chronological recovery packet: https://github.com/ColomboAI-com/c3r-security-evidence/blob/main/evidence/c3r-canonical-qualification-2026-10-01.md . Ubuntu kernel-team guidance supports investigation, not blanket dismissal. Independent Python 3.11/3.12/3.13 suites pass for the repair build; remaining image gates are running. PR remains draft; no production promotion or HF relabeling.

wilkont commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded for integration review by draft PR #7: #7 . The release/c3r-core-v0.1.0 branch deliberately reconciles all five production commits with the reviewed readiness lineage; the production tree at 0333653 exactly matches local 45f2a86. Both existing branches are preserved and no force-update occurred. Please review the integrated candidate rather than merge this stale branch. Neither PR is production-approved: host enforcement, live qualification and release evidence remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant