Skip to content

Loop: one machine, one process, done - #8

Closed
1zeroone0 wants to merge 1 commit into
mainfrom
loop
Closed

1zeroone0 wants to merge 1 commit into
mainfrom
loop

Conversation

@1zeroone0

@1zeroone0 1zeroone0 commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

What this PR does

The first end-to-end run: Firecracker boots one machine, one process drives a shell, done returns the answer, the log records every step. One SWE-bench-class task, graded by the official harness on the host.

Scope: image-to-rootfs converter (the task image boots as the single root disk); Firecracker boot plus vsock; the harness cycle over brush with bounded output and spill; the log as a flat file; done emitting git diff; a predictions writer for the official SWE-bench harness. Correct but incomplete: the flat file becomes a Merkle log later without changing meaning; one process becomes a tree without changing the cycle.

Host: Linux x86_64 with KVM (the Surface, NixOS), driven over ssh from the Mac. SWE-bench images are x86_64, so they run natively.

Crosswalk of one SWE-bench Verified instance:

Benchmark piece cead piece
per-instance Docker image (300–500 MB, deps preinstalled) task image; no network needed
repo at base commit (/testbed) checkout, already in the image
issue text (long) context on stdin; the argv query stays commit-sized
model patch done emits git diff; cead run stdout is the prediction
hidden tests plus official harness grader on the host; the test patch never enters the guest

Shape: cead run "Fix the issue on stdin; repo is in /testbed" < issue.md > patch.diff

  • Baseline: a bash-only scaffold (mini-SWE-agent, SWE-bench's bash-only leaderboard; verify current numbers). Pick 10–20 instances it already solves with the same model, so a failure points at cead. Landing near the published number validates the pipeline; a delta is the finding. The benchmark is noisy (one 2026 audit: 28.5% of a 49-task sample accepted an incorrect patch).
  • Under most stress: truncation. pytest output is long; this tests whether spill plus head/grep is enough.
  • Limits, not budget: the loop has one process, so it needs per-process limits only: steps, window size, output bound, wall time. Mirror the baseline's step and context caps for comparability; that is an eval setting, not a mechanism.
  • CLI contract: argv is a commit-style query; stdin is optional context; stdout is the answer only; stderr is diagnostics; exit code is the outcome, with distinct codes for done, limit reached, timeout, policy denied (sysexits). No chat: each run starts a fresh window over whatever the state now is.
  • Operator shell: cead with no verb opens a shell over a declaration and its state; run inside it is the same verb. Each step renders as its receipt on the TTY: prompt line and command, then permit · exit 0 · 212 bytes or forbid · no network in this process · exit 77 (see assets/terminal-mockup.png). Plain lines, no ratatui. One-shot cead run prints the same on stderr when stderr is a TTY. Operator verbs are git-shaped (boot mount run log diff fork export evict); only run for v0. Wrap only where cead adds state-awareness.
  • Output behaves like read(): bounded, short reads, remainder spilled to a file the model can seek into. Open: byte- vs line-oriented defaults.
  • System prompt: capped around 300–600 bytes, fails at boot if over. Names sets, not commands; rendered from what was mounted. Per-step values go in the shell prompt string ([step 12/100] $). Open: exact cap.
  • Habits that keep later work open: deterministic, prefix-stable window assembly; exact tokens (and logprobs where available) logged, not just text; model and weights version recorded. Grader, log and observer live outside the guest from the first run.
  • Typed sketch, directional: Ctx<S> (memfd, Unsealed → Sealed); Bounded(Vec<u8>), constructible only by truncation; Window::push(&mut self, b: Bounded); #[must_use] Evicted, which must be written to the log.
  • Facts (checked 2026-09-20; re-verify): aarch64 and riscv64 Linux have no pipe syscall; rustix's linux_raw backend uses pipe2 (v1.1.5). pipe2 entered POSIX.1-2024. rustix does not cover seccomp, landlock or bpf: use seccompiler, landlock, aya. In a microVM we are init and choose the kernel, so no systemd cgroup delegation.

What this PR does not do

  • rlm, budget, or more than one process (Horizon: rlm and budget).
  • The observer, policy beyond permit-all, the core/task disk split (Horizon).
  • A tamper-evident log, containers in the guest, a TLA+ or Lean model, Kubernetes.
  • A leaderboard claim.

Merge requirements

  • cead run resolves at least one instance end to end, graded by the official harness on the host.
  • Every step has a receipt in the flat-file log.
  • Zero placeholders (CODE.md); cargo clippy and cargo test green.
  • Five measurements: cold boot to first command; rootfs and snapshot size; memory per idle process; harness time per step; cost per resolved task, inference vs everything else.
  • One honest limitation, stated here.

🤖 Generated with Claude Code

1zeroone0 added a commit that referenced this pull request Sep 26, 2026
## What this PR does

Retires `prs.md`. Its §1 is now the loop draft PR (#8); every other
section is a comment on the Horizon PR (#7), which is never merged and
holds future PRs until they are ready. AGENTS.md gains the rule that
makes #7 the home of any leaning without a PR.

Dropped rather than moved: §10 (the name is held and published; the
trademark check moved to the first-release comment) and the next-session
housekeeping (tracked by the operator).

## What this PR does not do

- Sequence the Horizon items. They are pulled when ready, not ordered in
advance.

## Merge requirements

- [ ] Every prs.md section is accounted for in #7, #8 or the list above.
- [ ] Operator approves the AGENTS.md line.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1zeroone0 added a commit that referenced this pull request Sep 26, 2026
…ps (#3)

## What this PR does

A fresh asset set that matches cead's Irish name and Ogham mark.

- **Accents:** a deep forest green and a burnt orange, the tricolour's
hues kept muted and matte.

  | Role | Before | After | OKLCH (L, C, h) |
  |---|---|---|---|
  | lichen (permit) | `#5f7a45` | `#2f5f43` | 0.45, 0.07, 155 |
  | iron (forbid) | `#b3402f` | `#a95a27` | 0.55, 0.12, 50 |

- **The mark:** Ogham c, e, a, d on its original grid (20 px strokes, 44
px pitch), the stem trimmed to the lettering and closed with feather
marks (᚛ ᚜) as in manuscript Ogham; the green *a* stroke runs unbroken
across the stem. Groups keep Ogham's even rhythm rather than sitting
over their Latin letters.
- **Lockups are SVG** and are their own source: the mark is rects and
lines, the letters are traced from the previous raster.
- `lockup.svg`, `lockup-light.svg`: the README's stacked lockup for dark
and light themes, switched with `<picture>`. Before, the stone letters
vanished on GitHub's light theme.
- `lockup-source.svg`: stacked, stone on slate, no accents, for places
that cannot render color (a terminal).
  - `lockup-source-color.svg`: the same with accents.
- **`palette.png`, `terminal-mockup.png`** regenerated in Fira Code with
current vocabulary: verdicts `permit`/`forbid` (CODE.md), the shell
prompt `[step 12/100]` (#8), "process" for "node"; the header mark is
stone-only.
- **Caption:** the name's gloss becomes a centered caption under the
lockup instead of a dangler after the opening paragraph.

## What this PR does not do

- Commit a generator. The SVGs are hand-editable sources; the two PNGs
are mockups, regenerated by a one-off script.
- Match the old monospace face exactly (it was JetBrains Mono or
similar, not installed); Fira Code is used throughout.
- Rename the swatches (`lichen`, `iron`).

## Merge requirements

- [ ] Operator approves the README top on GitHub in light and dark mode.
Known tradeoff: forest green on dark grounds is 2.5:1 contrast (the
`permit` word in the mockup).
- [x] Every asset uses the new accents; no PNG lockup remains.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@1zeroone0

Copy link
Copy Markdown
Owner Author

Parked on #7 as the "loop" comment; initial-spec comes first (#10).

@1zeroone0 1zeroone0 closed this Sep 28, 2026
@1zeroone0
1zeroone0 deleted the loop branch September 28, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant