Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
4043ce5
Add standalone decision boundary and evidence-gated launch matrix
wilkont Sep 22, 2026
ad395f2
Bridge compiled state to provider adapters with data-boundary checks
wilkont Sep 22, 2026
076cf54
Persist redacted trace chain transactionally across restarts
wilkont Sep 22, 2026
76ae74d
Constrain hosted requests and record measured provider usage
wilkont Sep 22, 2026
bfa8eef
Exercise unsafe model requests and provider outage fallback
wilkont Sep 22, 2026
1f49f68
Record narrow Qwen and frontier provider smoke evidence
wilkont Sep 22, 2026
5f280f9
Audit Laya data provenance and seal benchmark test split
wilkont Sep 22, 2026
9b9ffad
Record pinned synthetic source audit evidence
wilkont Sep 22, 2026
5b1a18a
Publish controlled paired runtime replay evidence
wilkont Sep 22, 2026
cf18ba5
Pin controlled replay generator and source scope
wilkont Sep 22, 2026
2e23dcf
Document Cloud Run staging and internal-task telemetry scope
wilkont Sep 22, 2026
889f29d
Add governed standalone ingress and internal-task trace controls
wilkont Sep 23, 2026
41fb6cf
Bind governed traces to trusted source and task
wilkont Sep 23, 2026
dd62929
Make malformed ingress test portable across platforms
wilkont Sep 23, 2026
350d8e1
Add fail-closed staging container composition
wilkont Sep 23, 2026
c853ed5
Build staging image in CI
wilkont Sep 23, 2026
afcae2e
Record CI image-build evidence without deployment claim
wilkont Sep 23, 2026
559e212
Gate staging image on high-severity vulnerability scan
wilkont Sep 23, 2026
0ec8911
Reduce staging image attack surface and retain scan gate
wilkont Sep 23, 2026
598c033
Remove vulnerable runtime tools and record on-call owner
wilkont Sep 23, 2026
5486c19
Remove vendored vulnerable build tools from runtime
wilkont Sep 23, 2026
cd5e97d
Pin clean runtime image and current scanner
wilkont Sep 23, 2026
e991472
Record verified pinned image scan and reviewer gate
wilkont Sep 23, 2026
7c0b01a
Record named independent C3R reviewer pending acceptance
wilkont Sep 23, 2026
e89786c
Add independent release review handoff
wilkont Sep 23, 2026
2f002cb
Fail closed when governed trace purge is overdue
wilkont Sep 23, 2026
89ebe13
Record reviewer acceptance and add fixture-only trace dry run
wilkont Sep 23, 2026
403c244
Restrict C3R Cloud Build source upload
wilkont Sep 23, 2026
654f9e4
Add fixed-disabled Cloud Run staging host
wilkont Sep 23, 2026
4c8a88b
Record private disabled staging deployment and rollback
wilkont Sep 23, 2026
0df0882
Record unverified notification drill
wilkont Sep 23, 2026
5a2c281
Clarify private staging status in README
wilkont Sep 23, 2026
2cb34a0
Record acknowledged staging alert drill
wilkont Sep 23, 2026
a45899a
Add private C3R retention backstop and staged evidence
wilkont Sep 23, 2026
075d59a
Verify scheduler-triggered empty retention run
wilkont Sep 23, 2026
862daab
Verify scoped staging deletion and clarify review gate
wilkont Sep 23, 2026
c0cf499
Add C3R retention failure alert policy and evidence
wilkont Sep 23, 2026
ebd6288
Add independent C3R reviewer sign-off template
wilkont Sep 23, 2026
daf7e91
Record independent fixture review and staging evidence gaps
wilkont Sep 23, 2026
75bd27f
docs: update README.md with verified review status
wilkont Sep 24, 2026
656b659
Add fail-closed standalone staging and governed trace controls
wilkont Sep 24, 2026
37f2b74
Bind retention purge target to dedicated Cloud Run project
wilkont Sep 24, 2026
a7fb298
Test Cloud Run metadata-bound retention target and version deletion
wilkont Sep 24, 2026
7b62ff2
Add dedicated retention image build recipe
wilkont Sep 24, 2026
2f4a73b
Build and scan retention image in CI
wilkont Sep 24, 2026
3befd38
Fail closed on standalone effect execution
wilkont Sep 29, 2026
3e859bb
Add scoped stateless C3R API with guarded CLM System-One
wilkont Sep 30, 2026
247d58e
Implement typed CLM API and close independent review findings
wilkont Sep 30, 2026
061ca58
Harden CPU CLM serving and add private load qualification runner
wilkont Sep 30, 2026
0a81568
Record private qualification scope and add recoverable outage drills
wilkont Sep 30, 2026
ab9344f
Pin self-hosted H100 qualification config and correct startup flag
wilkont Oct 1, 2026
a9e91f9
Pin self-hosted H100 qualification config and correct startup flag
wilkont Oct 1, 2026
e8b82c3
Pin self-hosted H100 qualification config and correct startup flag
wilkont Oct 1, 2026
197b026
Pin self-hosted H100 qualification config and correct startup flag
wilkont Oct 1, 2026
0333653
Pin self-hosted H100 qualification config and correct startup flag
wilkont Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
.git
.github
__pycache__
*.pyc
.pytest_cache
.ruff_cache
.venv
tests
data
evidence
docs
assets

12 changes: 12 additions & 0 deletions .gcloudignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# C3R staging build uploads runtime source only. Do not send papers, traces,
# local evidence, secrets, or repository metadata to Cloud Build.
**
!Dockerfile
!Dockerfile.retention
!cloudbuild.retention.yaml
!.dockerignore
!c3r/
!c3r/**
**/__pycache__/
**/*.pyc

16 changes: 16 additions & 0 deletions .gcloudignore.verify
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Separate verification upload: source and synthetic tests only.
# Never upload local evidence, credentials, trace rows, papers, or Git metadata.
**
!Dockerfile
!Dockerfile.retention
!cloudbuild.verify.yaml
!.dockerignore
!c3r/
!c3r/**
!tests/
!tests/**
!scripts/
!scripts/run_controlled_pairs.py
!scripts/run_trace_control_dry_run.py
**/__pycache__/
**/*.pyc
50 changes: 50 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,53 @@ jobs:
python-version: ${{ matrix.python-version }}
- run: python -m unittest discover -s tests -v

image-build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: docker build --pull --tag c3r:ci .
- run: docker run --rm c3r:ci python -c 'import c3r.serve'
- name: Scan image for high and critical vulnerabilities
uses: aquasecurity/trivy-action@v0.36.0
with:
version: v0.74.0
image-ref: c3r:ci
format: json
output: trivy-image.json
severity: HIGH,CRITICAL
exit-code: '1'
- name: Preserve scan findings
if: always()
uses: actions/upload-artifact@v4
with:
name: trivy-image-${{ github.run_id }}
path: trivy-image.json
if-no-files-found: ignore
retention-days: 30

retention-image-build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: docker build --pull --file Dockerfile.retention --tag c3r-retention:ci .
- name: Verify retention entrypoint
run: |
test "$(docker image inspect c3r-retention:ci --format '{{json .Config.Cmd}}')" = '["python","-m","c3r.retention_job"]'
- run: docker run --rm c3r-retention:ci python -c 'import c3r.retention_job'
- name: Scan retention image for high and critical vulnerabilities
uses: aquasecurity/trivy-action@v0.36.0
with:
version: v0.74.0
image-ref: c3r-retention:ci
format: json
output: trivy-retention-image.json
severity: HIGH,CRITICAL
exit-code: '1'
- name: Preserve retention scan findings
if: always()
uses: actions/upload-artifact@v4
with:
name: trivy-retention-image-${{ github.run_id }}
path: trivy-retention-image.json
if-no-files-found: ignore
retention-days: 30
10 changes: 10 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
FROM python:3.11-alpine3.24@sha256:cd04730b8511def3fbf14204d66a0c1536f290b8e896ed5a94cd64cb15ac1356

ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1
WORKDIR /app
RUN python -m pip uninstall -y setuptools wheel jaraco.context
COPY --chown=10001:10001 c3r ./c3r
USER 10001:10001
EXPOSE 8080
CMD ["python", "-m", "c3r.serve"]

9 changes: 9 additions & 0 deletions Dockerfile.retention
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
FROM python:3.11-alpine3.24@sha256:cd04730b8511def3fbf14204d66a0c1536f290b8e896ed5a94cd64cb15ac1356

ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1
WORKDIR /app
RUN python -m pip uninstall -y setuptools wheel jaraco.context
COPY --chown=10001:10001 c3r ./c3r
USER 10001:10001
CMD ["python", "-m", "c3r.retention_job"]

5 changes: 5 additions & 0 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,8 @@ Upstream model: https://huggingface.co/convaiinnovations/laya
Upstream source: https://github.com/NandhaKishorM/laya

No derived Laya weights are included in this repository at this time.

The optional CLM service adapter targets Contrastive-LM/CLM at upstream source
commit bb42c6c5bf914fd449bed2f6ca65be80602cb1f7. Upstream CLM source is
Apache-2.0: https://github.com/Contrastive-LM/CLM. No CLM source, encoder
weights, or projection-head weights are redistributed in this repository.
104 changes: 89 additions & 15 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,24 +15,60 @@ C3R is an open-core control plane that decides **which computation is worth perf
It evaluates tools, retrieval, local and frontier models, verification, placement, and stopping as
typed candidates under one conservative value-of-computation policy.

The v0.1 vertical slice now includes bounded hierarchical candidate compilation, a revision-verified Laya
fast path with calibration-gated abstention, and a reproducible DecisionMix v1 schema preview.
It is a research alpha: the controller is runnable and tested; fine-tuned weights and empirical
production calibration remain release gates, not implied claims.
The v0.1 vertical slice includes bounded hierarchical candidate compilation, a
calibration-gated System-One seam, and a reproducible DecisionMix v1 schema preview.
CLM is the new default System-One provider in code; Laya remains optional.
It is a research alpha: the controller is runnable and tested. Fine-tuned weights
and empirical calibration remain gates for the **empirical model/data release**,
not for the separate stateless recommendation API described below.

> **Launch status:** Neither the standalone decision service nor governed trace collection
> is enabled for public use. The independent [PR #2 review](https://github.com/ColomboAI-com/c3r/pull/2#pullrequestreview-5293835066)
> requests changes. A real cloud storage audit probe and the first natural
> empty-bucket purge run are recorded for reviewer inspection, but they do not
> establish deletion of aged traces or backups, trained weights, or calibration
> for the research release. The separate stateless API still needs its own
> security, live provider, and canary evidence. See the [reviewer packet](docs/reviewer-staging-packet-2026-09-23.md).

### Separate stateless API path

The [C3R Core API v1 contract](docs/stateless-core-api.md) separates a
recommendation-only, non-persistent inference service from the governed trace
collection and empirical-release program above. The current branch implements
the typed CLM API, direct ranking, a text-only Responses subset, a production
host, and a fail-closed `production_inference` mode. A private, loopback-only
candidate has returned actual CLM rankings and local DeepSeek text; it is
**not** a publicly launched or production-qualified API. Upstream CLM provides
advisory System-One ranking, not generative text or calibrated task-success
probabilities. `/v1/c3r/execute` remains disabled. `/v1/responses` invokes
DeepSeek through an admitted, independently checked text-only controller
fallback; it does not claim positive learned CVoC or expose private reasoning.
The first public hostname is a dedicated C3R endpoint, not an MC-1 integration.
See the [scope-specific release policy](docs/release-policy.md).

### Default language model

C3R's default **deliberative** language model is
[`deepseek-ai/DeepSeek-V4.1-Flash`](https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash)
(MIT). The hosted default uses `deepseek/deepseek-v4.1-flash` through OpenRouter; the
official DeepSeek API alias is `deepseek-flash`. Laya remains the separate System-One
decision fast path, and DeepSeek recommendations remain subject to the same verifier and
(MIT), self-hosted on the existing eight-H100 node alongside Qwen3-8B/CLM.
The default provider uses the private loopback `/model` alias; no OpenRouter or
hosted inference provider is part of the production target. CLM is the default separate
System-One decision engine; Laya remains optional. DeepSeek recommendations
remain subject to the same verifier and
trusted commit boundary as every other candidate.

The 763B-parameter checkpoint is not assumed to fit a single GPU merely because only
8B/16B parameters are active per token. A GCP deployment must pass storage, aggregate
accelerator memory, runtime-version, and smoke-test gates before C3R labels it self-hosted;
otherwise the GPU service uses the hosted provider profile and stores no model weights.
The official checkpoint has passed a private 8×H100 GCP serving smoke test and is backed
up in a private GCS bucket. Its vLLM endpoint is bound to localhost; this is **not** a
public C3R service or end-to-end production qualification. The checkpoint's active
parameter count does not imply it fits on one GPU.

The recovered **older** serving image passed all 13 private C3R checks at 85%
GPU reservation with Qwen still running. The clean, pinned newer image is a
separate qualification target: its first startup rejected an obsolete flag.
The corrected launch configuration is tracked in
[`deploy/deepseek-v41`](deploy/deepseek-v41/README.md). Repeated cold starts,
sustained mixed load, outage/rollback, final-head builds, TLS and canary remain
required; recovery alone is not production qualification.

## Why C3R

Expand All @@ -42,7 +78,7 @@ keeps that recommendation separate from authority to act.
```mermaid
flowchart LR
S[Versioned state] --> C[Hierarchical candidate compiler]
C --> L[Laya fast path]
C --> L[CLM default / Laya optional]
C --> D[Deliberative envelope]
L --> V[Robust CVoC]
D --> V
Expand All @@ -60,11 +96,12 @@ failed verification into success, or directly commit an external effect.
| Surface | Included now |
| --- | --- |
| Candidate Compiler | family → subgroup → operation → arguments → placement → verifier; hard masks, budget pruning, caps, progressive widening |
| Laya fast path | exact upstream revision and license verification, typed probabilities, slice calibration, confidence/margin abstention |
| System-One fast path | CLM loopback rank adapter with strict response checks and calibration-gated abstention; optional revision-verified Laya |
| DecisionMix v1 | validated records, immutable deterministic splits, source/license provenance, SHA-256 manifest, 144-record synthetic preview |
| Authority boundary | action-bound verifier attestations, expiring single-use approvals, atomic nonce claims |
| Runtime control | conservative CVoC selection, deterministic `STOP`, cost twin, deliberative contracts, evidence-grade traces |
| Runtime control | conservative CVoC selection, deterministic `STOP`, cost twin, deliberative contracts, trace schema and optional transactional SQLite hash chain |
| Operational controls | fail-closed feature flags, tested frontier/open-weight HTTP contracts, Colibri shadow recommendations, canonical trace hash chain |
| Standalone controller boundary | tested state → candidates → optional System-One → CVoC → independent verifier → read-only recommendation or deterministic fallback → redacted trace composition; the standalone controller rejects external executors until effects and durable trace commits can be made atomic. A separate private Cloud Run staging host is fixed-disabled; it is not the decision service or a public launch. |

This compiler is the reviewed vertical slice, not the directive's full Candidate Compiler
Definition of Done. Rich typed value constraints, per-argument provenance, dominated-branch
Expand Down Expand Up @@ -127,13 +164,42 @@ is `STOP`.
every Definition of Done item in Execution Directive v2.
- [`docs/empirical-release-plan.md`](docs/empirical-release-plan.md) — gated path from synthetic
preview to trained, calibrated, independently reproducible release.
- [`docs/standalone-launch.md`](docs/standalone-launch.md) — current production exit gates,
evidence status, and operator inputs, with MC-1 excluded from standalone scope only.
- [`docs/launch-announcement.md`](docs/launch-announcement.md) — canonical launch copy plus
LinkedIn, X, and Hacker News variants with a publication checklist.
- [`docs/prior-art.md`](docs/prior-art.md) — explicit attribution links and the canonical novelty
boundary required by the execution directive.

## CLM System-One integration

`C3R_SYSTEM_ONE_PROVIDER=clm` is the configuration default, while
`C3R_ENABLED` and `C3R_SYSTEM_ONE` still default to off. The adapter targets
the upstream [Contrastive-LM/CLM](https://github.com/Contrastive-LM/CLM)
`/v1/rank` API on a loopback-only origin. Its source is pinned at
`bb42c6c5bf914fd449bed2f6ca65be80602cb1f7` (Apache-2.0). The running
encoder and CLM head need their own immutable artifact revision, passed as
`C3R_CLM_ARTIFACT_REVISION`; the current adapter validates the declaration's
format but does not yet attest the live server's artifact hash. This repository
does not bundle or claim trained C3R-specific CLM weights. The host supplies `C3R_CLM_URL` (default
`http://127.0.0.1:8700`), an optional `C3R_CLM_API_KEY`, and a fitted
`TemperatureCalibrator` to `build_default_clm_fast_path`. The initial
`C3R_CLM_TIMEOUT_MS=500` bounds the complete System-One decision; production
latency thresholds still require live measurement.

CLM ranks bounded, policy-surviving candidate labels and fixed typed questions.
Its raw ranking is advisory, not an action selection. Missing calibration,
malformed responses, outages, or timeouts lead to abstention or deterministic
fallback. CVoC, independent verification, and the commit boundary retain
authority. Private live CLM ranking and co-resident DeepSeek recovery have been
observed; neither sustained GPU coexistence qualification nor held-out C3R
calibration is claimed by this code change.

## Laya integration

Laya remains an explicitly selected comparison/compatibility provider; it is not
the default System-One engine.

The adapter pins `convaiinnovations/laya` at
`1c5edc17a7acd8701df6fc341c0d179f1c62c982`. Before loading, the backend resolves the Hub
metadata, verifies that exact SHA and the Apache-2.0 license, downloads that revision, and passes
Expand All @@ -152,6 +218,12 @@ without presenting generated fixtures as real training evidence. The empirical c
only when provenance, licensing, held-out integrity, and calibration support are independently
auditable.

For the first empirical source, ColomboAI approved only C3R-authored internal
tasks under the [interim trace policy](docs/internal-task-trace-policy.md). It
sets a 30-day private retention limit and requires independent review before
any de-identified row is published. Collection remains off until the technical
controls are verified; this approval does not make the preview empirical.

Required empirical metrics include accuracy, Brier score, ECE, maximum calibration error, NLL,
selective risk versus coverage, abstention, escalation, p50/p95 latency, throughput, calls avoided,
and cost per completed task.
Expand All @@ -163,6 +235,7 @@ Production hosts must preserve independent control of:
```text
C3R_ENABLED
C3R_SYSTEM_ONE
C3R_SYSTEM_ONE_PROVIDER=clm
C3R_DELIBERATIVE
C3R_ROUTING
C3R_SPECULATION
Expand All @@ -177,7 +250,7 @@ learning. The reference provider and Colibri shadow contracts are documented in

## Release truth

Not yet claimed: trained `C3R-Decision-Laya-421M-v0.1` weights, empirical DecisionMix training
Not yet claimed: C3R-trained CLM heads or Laya weights, empirical DecisionMix training
data, live provider qualification, MC-1 product integration, a Colibri shadow deployment, or
measured production calibration/latency/cost results. Tested adapter and shadow-control contracts
are included, but they are not represented as production runs. These remain documented gates.
Expand All @@ -192,3 +265,4 @@ Do not report vulnerabilities in a public issue; follow [`SECURITY.md`](SECURITY
effects must be completely mediated by an independently configured commit gateway.

Apache License 2.0. See [`LICENSE`](LICENSE). If you use C3R, cite [`CITATION.cff`](CITATION.cff).

Loading
Loading