Skip to content

feat: connect browser public tasks to cooperative peer execution - #178

Merged
erikleblansch merged 33 commits into
mainfrom
feature/browser-cooperative-compute
Oct 4, 2026
Merged

erikleblansch merged 33 commits into
mainfrom
feature/browser-cooperative-compute

Conversation

@erikleblansch

@erikleblansch erikleblansch commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Task-process lifetime correction — 434431d8

Current candidate 434431d897c50ca85706a56fc84b8f76df698c75, tree c46f0504e82a9df91d1eb04901a86dc1f874a0f1, separates task cleanup from the persistent provider broker. The existing descendant walker deliberately includes its root; the browser and Code pre-stop checks therefore included the still-running broker, whose shutdown occurs only later in fixture cleanup. The correction retains the original ownership list and excludes only that exact validated broker PID/start-time from the task-only check. Every other recorded process, including sandbox parents and tokenizer/worker descendants, must have ended. Existing after-broker-stop cleanup, source/model/EOS/cancellation criteria and resource bounds are unchanged.

Verification: three real Linux process controls, 32 browser fixture checks and nine Code checks pass. The real process regression spawns descendants from a non-leader thread, retains a live broker, rejects a surviving sandbox parent after its model child ends, and succeeds only once all transient descendants are reaped. Missing/duplicate identities and changed start-times refuse. Independent review found no blocker. No new live trial is claimed by this commit.

Exact synthesis-profile trial — result join passed, task-process observation failed

Run 37207405766, exact source 7621087a9f287fdb68bb7b7127f72e029c45f865, tree a755c880e32ae37c27f883dd4abaae0d9f830752, is terminal FAILED. The inventory gate passes and the source route connects on its first attempt. Seven real peer jobs preserve the two-part original source, two refinement splits to depth two, a four-answer EOS frontier and one EOS synthesis. The corrected exact retained-result join now passes and exports its original structural result. The browser reaches closed complete status; its second task reaches scoped cancellation with coordinator cleanup confirmed.

The observer then fails specifically in worker_cleanup_check; final process-lifetime/panel proof is not complete. The persistent-broker scope bug above is established in source and reproduced with actual processes, but individual live-process identities were not retained in the original artifact, so additional surviving transient processes cannot be excluded retrospectively. Semantic answer quality is not proved. Final private cleanup leaves zero owned objects and matching guest-root network snapshots, not an independent outer-host claim. Original ZIP SHA-256 63d50a3602f4bea04827d4ec0dc2d026f2fe6f3cdda68651c1b05813d62fb4d7; original job 111451377964 log SHA-256 ad19dcb449e5005bebd76e674cd70cb3c3ba0b4b3afe8f0724577e228faa0019.

The preceding synthesis-profile fix requires the selected non-default 360M profile in the exact signed-v3 dataset equality, preserving real serialization and all output/source criteria. Thirty-two Python checks and the focused Rust serialization/signature/row-derivation check passed before this live trial. No original failed run is retrospectively relabelled.

Original startup-gated trial — reached real synthesis, failed at result join

Run 37205581731, exact source 05e75021fe195e94b4dd32658ac9636ebde3422b, is FAILED. The inventory gate passed and the source route connected on its first attempt. Seven native worker executions have confirmed terminal receipts: one original EOS answer and one token-limit answer, two refinement levels producing four effective EOS answers, then one EOS synthesis. Coordinator execution, answer completion and cleanup are confirmed; the separate observer fails in result_join with an unknown specific predicate. Exact retained provenance, browser completion and subsequent cancellation proof are therefore not complete. EOS does not prove semantic answer quality.

The source/schema mismatch above is independently reproduced, but the original private retained tree was cleaned: it is not proof of that run's first failed predicate. Private cleanup leaves zero owned objects and matching guest-root network snapshots, not separate outer-host evidence. Original ZIP SHA-256 84da36736e2fcc0663ffbde865688eb2d49f221f63c6c63d49c7d2067cb0358b; original job 111445972182 log SHA-256 a8a4faa41383ce028619bf1aee2f9da1c696a6a1b6f39aff16ca7e13316ec377.

The bounded startup gate waits up to 60 seconds for six expected relay/two exit advertisements before first Connect, with two-second read-only RPCs. Inventory is not route readiness; legacy135, production selection, retry classifications and all compute criteria remain unchanged.


Original diagnostic trial — failed before compute

Run 37204198825, exact source 774597444616af465e684dde3ed874b80542971f, failed at JOBS_ROUTE_UNAVAILABLE: 14 attempts/13 retries, final NO_ELIGIBLE_PATHS. The retained 48/400-event ring contains 13 INVALID_SNAPSHOT and one NO_EXIT, no other recognized sampler reasons. This is unknown/ambiguous, not last-attempt attribution: incomplete discovery also counts as INVALID_SNAPSHOT, so corruption or a specific missing advert is not established. No peer inference, refinement or browser task ran. Cleanup had zero owned objects and matching guest-root network snapshots, not independent outer-host evidence. Original ZIP SHA-256 0c6d00f7769579fc093564f165781f3b1dd5b0762ef79f7b0a88d269251bdf9a; job-log SHA-256 5e66d9e34c645a5b5f90cea357ed189896ea34da798c05115a7ae204c19b149a.


Discovered-cooperation trial — failed

Original run 37202586461, exact source 95e45ac122347622253e1506f4f02b618de9ec7d, selected the actual agent-cooperative-browser-discovered/360M contract but stopped before compute at JOBS_ROUTE_UNAVAILABLE: 26 connect attempts, 25 retries, final NO_ELIGIBLE_PATHS. The retained 107-record ring reports one NO_EXIT and 25 unrecognized reasons; it does not establish the last attempt's cause. No inference, refinement, synthesis or cancellation proof ran. Private/guest cleanup passed with zero owned objects and identical guest-root network snapshots; no separate outer-host claim. ZIP SHA-256 62b9e1980ee22c7fc9a839eedaa32676929f8dc83a7035643a5fb2289af1c1d3; original job-log SHA-256 64a0a2c9054974bc47f1e365fcce4a216aa6523d4078079c79dab24e16e278cf.

Candidate 774597444616af465e684dde3ed874b80542971f completes the closed diagnostic allowlist with the three other existing sampler reasons: INVALID_POLICY, INVALID_SNAPSHOT and ENTROPY. All 24 targeted checks pass, including an exact comparison with the five source emitter codes. No raw identifiers/text are exported, and no retry, timing, selection or success condition changes. This is improved failure evidence, not a route fix or successful compute result.

Previous fixed-135M trial — failed

Original run 37075778441, head 913fd0c4749efddb278fdc55de59473da3b3a657, reached a real route after 11 attempts/10 retries and executed 11 workers with confirmed terminal receipts. One answer ended at EOS, ten at the token limit. No complete answer, refinement or synthesis was retained. The legacy scenario does not enable refinement; that dispatch did not exercise the multi-level candidate. Guest cleanup passed with zero owned objects and matching guest-root network snapshots, not separate outer-host proof. ZIP SHA-256 23e764c7d91b7cec73c7f66a5ffde7397b5e9b9b008deea1c142abbb8ca39dd8; original job-log SHA-256 525507c48267165996a56c9ead5a959e7e9f505cf6bec6caeb83499583326fda. Retained-ring preselection diagnostics remain unknown because the bounded ring was full; no final-attempt reason is inferred.


Previous route-selection correction

Candidate e61a6f6a7b5a905258b3a44388b4f5942887cd9b preserves eligible alternatives before choosing one original signed control for an Exit. Existing transport/family/capacity/diversity checks, ambiguity checks, exact lineage, pinned controls and terminal rejection remain in force. Signed regression fails before the correction; 7 route and 18 sampler tests plus strict targeted Clippy pass. Fixed public-training sources are also included without changing this branch's README/document input. Run 37072548276 is terminal FAILED before compute: legacy 135M source-route setup, 15 attempts/14 retries and final NO_ELIGIBLE_PATHS; earlier attempt codes and preselection subtype were not retained. No browser task, inference, child answer or synthesis ran. Private/guest cleanup passed with zero objects and matching guest snapshots, not an outer-host claim. ZIP SHA-256 6a9cbb6951a8e26f412dfead984cf1a5c35f0878fc4c02b7d861f454317eabfa; original job-log SHA-256 821d494fdd82e3b4de8dbafab53d3e0bf42faf115b04b1d99bed158eb797730a.

Original run 37065757332 remains failed before compute (JOBS_ROUTE_UNAVAILABLE, 29 attempts, final NO_ELIGIBLE_PATHS), with confirmed guest cleanup. Its retained diagnostics do not prove this independently reproduced defect caused that failure. No completed model answer or live route is inferred from the source fix.


Public cooperative browser execution — candidate

Adds a separate owner-controlled compute public-serve interface for real protected peer execution and synthesis. Browser inputs require explicit public-content consent and appropriate rights; private inputs never fall through to this public endpoint. The core retains authority over discovery, providers, resource budgets, cancellation and signed receipts. Companion: Browser PR #5.

Latest implementation: c2c7cb268db0a07c3638367324d838ef26f4a101

Owner-enrolled --refinement-levels 2..4 allows an incomplete public source fragment to be split again. Completed original and child answers are reused; every original receipt remains unchanged. All levels share at most sixteen split intents/thirty-two child jobs, existing scheduling/resource budgets, source expiry, model/cohort and cancellation. The default stays at one level with backward-compatible enrollment encoding.

Only a verified, gap-free EOS frontier covering the entire original input can enter synthesis. Intermediate token-limit receipts are not relabelled as complete. The discovered-360M fixture enables four levels; its original input, question, model limits and acceptance gates remain intact. Closed child-ending diagnostics contain no text, source ranges or identities.

Verification: 75 focused Rust document tests, strict CLI/test Clippy and formatting pass. The joined synthetic RPC lifecycle covers repeated refinement, cancellation, exact receipt preservation and offline resume. Twenty-two Browser and nine Code fixture checks pass. Independent Rust review found no blocker. These checks are not actual model or browser proof. Earlier wrapper dispatches selected the legacy fixed-135M scenario, not the intended discovered contract. The distinct current trial above now explicitly selects the discovered scenario; no live success is claimed.

Earlier completed live trial remains failed

Run 37058432693, exact source b76b8a2497a428b96b7379af9939de2c87dcf698, retained four real worker receipts and confirmed normal task cleanup. The original leaves were one EOS and one token-limited result; no complete joined answer or synthesis was produced. Child ending subtypes were not exported and remain unknown. Final private cleanup passed, zero owned objects remained and guest network snapshots were identical. This is not complete browser/compute acceptance.

Earlier failures remain failures, including run 37052601519 with two missing terminal receipts and 48 observed discovery failures. Full historical scope, original artifact hashes and listener-recovery evidence are retained in docs/COOPERATIVE_BROWSER.md.

This PR remains draft. Protected private remote inference, automatic model selection, answer-quality improvements, complete coding-agent behavior and the full alpha remain separate unfinished requirements.

@erikleblansch
erikleblansch merged commit 4299094 into main Oct 4, 2026
5 checks passed
@erikleblansch
erikleblansch deleted the feature/browser-cooperative-compute branch October 4, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant