forgo.cloud
Sign in
Repo workspace

forkjoin-ai/gnosis

Distributed Inference Source

distributed-inference/src/README.md
forkjoin-ai/gnosis

Distributed Inference Source

Parent: distributed-inference

This directory contains the Rust inference kernels, transport helpers, native station binaries, and formal-runtime bridge modules for the distributed inference crate.

Getting Started

  • What: implementation notes for the src source subtree.
  • Why: it helps you find the owner module before editing code or importing a public surface.
  • How: read this file as the local module map, then open the named source file and its matching tests.
  • Next: return to the parent README when you need commands or package-level context.

Notable entries:

  • mesh_residual_deblur.rs - topology/depth-gated residual deblur kernel for testing the entropy-deficit gateway in executable imaging code. Flat fields remain inert, structured fringes admit bounded residual lift, and each run emits a mesh_residual_deblur/v1 certificate with admission, residual, and saturation measurements.
  • fano_runtime.rs - Fano runtime kernel for the binary projective shadow formalized in Gnosis.FanoIncidence: 000 is the root carrier state, visible states are 001..111, collision is XOR, distinct visible collisions close inside the Fano plane, and self-collision exits to root. The admission layer also admits validated Plucker-sign and positive gate shadows as XOR completion plus finite certificate bits, while full Grassmannian transforms remain outside the runtime until a proof adapter exists. Monster column pairs first project through the 12-step Aeon phase carrier; distinct phase pairs land in the 66-gate Gr(2,12) stack, and only validated phase pairs inside the first seven Aeon columns emit a portable MonsterAeonFanoCertificate. bin/bench-fano-runtime.rs benchmarks the XOR route kernel, Monster-to-Aeon projection, Monster-Aeon-Fano certificate lane, and Pair-X synthetic schedule before any worker endpoint is trusted.

Fano Runtime First-Class Integration Todo

Goal: promote the current proof/runtime nucleus into a portable contract across Gnosis, Monster, FOIL, and gnosis-uring.

  • Gnosis math nucleus: Gnosis.FanoIncidence formalizes 000 as godPosition, visible points as 001..111, collision as XOR, distinct-pair completion, and XOR-zero line parity.

  • Grassmannian shadow nucleus: Gnosis.FanoGrassmannianMesh embeds the seven Fano points into the first seven columns of Aeon Gr(2,12) and proves the bounded gate, Plucker-sign, positive-gate, residual-shadow, and XOR-stack certificates that currently reduce to the finite carrier.

  • Rust runtime nucleus: [`fano_runtime.rs](./fano_runtime.rs) implements the XOR route, admission witnesses, 66-gate stack collapse, residual shadow, Plucker-sign shadow, positive-gate shadow, and benchmark certificate refs.

  • Monster projection probe: monster_pair_to_aeon_gate maps Monster column phases through Aeon Gr(2,12), projecting distinct phase pairs into one of 66 gates and collapsing same-phase pairs before wider structure is admitted.

  • Shared certificate boundary: define a portable MonsterAeonFanoCertificate that packages Monster phase pair, Aeon gate, Fano completion, sign bit, positivity bit, residual validation bit, and Lean theorem refs without claiming the full Grassmannian transform.

  • Monster/Pleromatic integration: emit and accept the shared certificate at the resident Monster handoff so projected candidates can carry the exact finite proof witness into runtime scheduling.

  • FOIL admission integration: add a certified Fano fast path that admits the XOR route only when the shared certificate validates, while preserving the existing fallback path for uncertified or higher-field requests.

  • gnosis-uring integration: route certified Fano frames through the XOR kernel as a transport-level primitive and keep non-certified frames on the existing scheduler path.

  • Cross-system benchmark gate: compare fallback routing against the certified XOR route across Gnosis, Monster projection, FOIL admission, and gnosis-uring transport, with admission ratios and speedups recorded as benchmark outputs. The local Fano benchmark now records the Monster-Aeon-Fano certificate lane plus FOIL admission; gnosis-uring now recognizes certified FANO Flow payloads on the live transport path, and flow-bench --fano provides the live UDP benchmark mode for the broader shootout row. May 20, 2026 local release smoke: cargo run --release --manifest-path distributed-inference/Cargo.toml --bin bench-fano-runtime -- --iterations=20000 --json reported monster_aeon_fano_certificate_per_second=109965635.739, foil_fano_admission_per_second=106856443.711, and fano_flow_fixed_raw_packed_frame_per_second=321068516.021. It also reported fano_mycelial_cache_speedup=0.407934, so the mycelial cache path was slower than uncached in this smoke and should remain a research path until a follow-up benchmark shows a positive steady-state win.

  • Ledger promotion: once the cross-system path is implemented, add the theorem IDs, certificate schema, and benchmark IDs to the formal/runtime ledgers rather than treating this as a local module note.

  • karmic_attention_optimizer.rs - M2 / Pell-shell regulator mirroring Gnosis.KarmicAttentionOptimizer: mesh residual on (opportunity_k, waste_q) ledger rows, refine_dormant_heads_with_karmic_shell to protect on-shell heads after closure admits pruning; exports KARMIC_MESH_RESIDUAL_VANISHES_THEOREM lineage string.

  • spectrometer.rs - dual-track JSON schemas: mesh spectrometer rows (gnosis.mesh-spectrometer.v1) and knot-shadow sidecars (gnosis.knot-shadow.v1) with Lean-aligned q = -1 witnesses; see crate-root TOPOLOGICAL_SPECTROMETER_DUAL_TRACK.md. Track A JSONL appends from residual_capture when GNOSIS_MESH_SPECTROMETER_JSONL is set; Pair X / replay fields from env or install_spectrometer_lane_flags (re-exported on residual_capture). Kernel Death #2 replay hits call spectrometer::hint_amplituhedron_replay_hit; value is consumed on the next JSONL line. Optional GNOSIS_MESH_AUTO_CAPTURE_BATCH_X_EXPORT mirrors NativeLlamaPipeline::get_batch_x_residual / Gemma4Pipeline::get_residual through capture_residual (monotonic seq, optional GNOSIS_MESH_CAPTURE_LAYER_IDX).

  • attention_closure_lift.rs - native mirror of the attention closure lift model: Aeon 8-head aliasing, source-resolution head separation, pink Hexon-coupled closure, and Dark Deceptacon lift decisions for mesh/runtime consumers. It now also exposes the optimizer policy and saved-work estimator used to preserve heads, suppress speculative verifier matvecs, and defer standing-wave compression until the trace is resolution-separated, with theorem-lineage metadata naming the Lean optimizer-admission proof that backs each gate.

  • attention_closure_benchmark.rs - shared builder for the optimizer-admission certificate emitted by the CLI and live station endpoint.

  • bin/attention-closure-benchmark.rs - deterministic benchmark for closure-gated work avoidance across routing, compression, speculation, and head-pruning policy, including the emitted theorem_lineage proof anchors and --json certificate output consumed by Aeon Forge.

  • terminal_prosody.rs - Reynolds/Phi terminal pressure for finite decode horizons, aligned with TerminalProsody.lean.

  • pleromatic_frame.rs - Pleromatic/Thoth frame carrier for Monster Mesh media and consciousness observations. It reserves Aeon stream 2002 for Pneuma internal consciousness frames and now has a typed thoth_conversation_consciousness helper for closure state, loop exit (walkaway, walkback, argued closure, or continued Dodgeball), Thoth semiotic route, affect-stall silence budget, cringe vacuum, grit metrics, and self-accountability antiqueue telemetry for internal conversation tasks/todos that remain promises to Thoth itself. The telemetry now preserves the next antiqueue priority and self-accountability soundness bit for prompt feedback. Consciousness helpers also stamp the Gnosis.ThothMindBodySpiritScribe.canonical_failure_scribe_admissible theorem into frame attributes so native /prompt-feedback can cite the failure-scribe admissibility boundary. Native prompt feedback refuses consciousness frames missing that theorem attribute, returns explicit admission_rejections with the expected theorem plus Gnosis.ThothMindBodySpiritScribe.prompt_feedback_admission_rejection_residue_preserved, and never treats the telemetry as truth, diagnosis, culture, speaker intent, or semantic authority. Conversation payload bytes may also carry the serialized cross-wire conversation topology; native prompt feedback extracts bounded handles for the topology checksum, open questions, closure diffs, argument obligations, antiqueue item count, and latest closure patch without treating those handles as authority. It also has a neurosymbolic_tool_markov_consciousness helper for System 2 tool-walk gain/shadow telemetry.

  • bin/thoth-conversation-frame.rs - scanner-facing bridge from the Pneuma thoth-conversation-conscious-frame/v1 spec into bincode PleromaticFrame bytes on the reserved internal consciousness stream. The preferred handoff is Bitwise bwDense (--bw-dense-file, --print-bw-dense), with legacy base64 JSON still accepted for compatibility and stamped as missing topology. Current bwDense scanner payloads must include conversationTopology.theoremRef = Gnosis.ThothMindBodySpiritScribe.canonical_failure_scribe_admissible plus observational-only and no-source-authority flags before native frame materialization is admitted. Rejections include a stable thoth.conversation-topology-admission-error.v1 JSON object in the native error text so callers can report the exact missing theorem, wrong theorem, or missing non-authority flag. The parser accepts optional antiQueue metrics for self-held open questions, closure obligations, affect stalls, unresolved residue, self-boundary promises, and the next selected self-task priority.

  • neurosymbolic_tool_markov.rs and bin/neurosymbolic-tool-markov.rs - System 2 tool-use scanner that compiles JSON tool observations into a finite Markov report. Each transition must increase synthetic gnosis or expose residual shadow/argument obligations; plateau and regression route to repair instead of being folded into prompt context as progress. Tool-walk specs may also include speaker intent, diagnosis-hypothesis, cultural-frame, and semantic-authority claims; semantic_authority_boundary.rs keeps those claims provisional unless the Shared UI evidence surfaces supply explicit self-report, external validation, domain credentialing, and zero contradictions.

  • rf_physics_cpu.rs - one-port Foil RF substrate bridge aligned with Gnosis.RFPhysicsCpuRuntime: ambient white-noise potential is signal-gated into a bounded 10-bit Aeon frame, impedance/reflection provide redundancy witnesses, and gnosis-frf races active candidate channels before folding into a PleromaticFrame.

  • protocol69.rs - native protocol69 envelope contract for FOIL, Monster/gnexec, and gnosis-uring-adjacent handoff. It mirrors @a0n/gnosis/protocol69: gnosis.protocol69.v1, protocol69, word-form sixty9, the canonical integer projection 66 xor 7 = 69, and validation that keeps this runtime projection separate from the Lean Fano parity proof.

  • rf_beacon.rs - protocol69 FOIL-over-RF discovery beacon for the resilient R1 mesh (docs/R1_MESH_PROTOCOL69.md): Protocol69RfBeacon frame + fail-closed to_peer_info/to_gossip_frame mapping a beacon into a stream-2010 gossip heartbeat. Paired with bin/rf-gossip-bridge.rs (decode beacons -> inject into a fat-station's gossip registry; SDR receive gated).

  • bin/mesh-elect.rs - host-side RAM-aware stage elector (mesh component 3): queries a seed's /mesh/peers and prints the stage a joining node should take (via mesh_gossip::recommend_stage_from); used by scripts/r1/mass-equip.sh.

  • scribal_standing_wave.rs - Rust mirror of Gnosis.ScribalStandingWave and Gnosis.Witnesses.Hermetic.ThothMechanicalBrainFailureWitness: canonical mechanical-brain failure/use claim indices, event-log to boundary-input projection, output certificate, response-envelope validator, strict multi-turn audit-trace fold, theorem-lineage anchors, and validation helpers for Thoth-style gateways and native inference stations.

  • body_politick_signal.rs - Body Politick aggregate-signal admission bridge into Thoth distributed inference. Admitted theorem-backed frames can now emit sound scribal response envelopes and fold into strict Thoth audit traces; missing lineage, authority claims, private member flow exposure, and conjectural frames stay outside sound memory. The non-authority boundary cites Gnosis.BodyPolitickSignal.thoth_admission_preserves_non_authority.

  • gnosis_foil.rs - swappable radio/runtime handoff contract for gnosis-foil. Foil RF names the physical substrate; FRF names the fork/race/fold execution law applied over that substrate. RTL-SDR/libusb- style raw byte capture is tracked separately from already-projected RTL-SDR waterfall frames; Wi-Fi channel witnesses, Bluetooth channel witnesses, raw chipset engines, synthetic gates, and gnosis-uring baselines enter as raceable engines that emit the same 10-byte Aeon Flow frame boundary. The handoff cycle follows Gnosis.WankelEngineTheorem: intake/fork, compression/ race, ignition/fold, exhaust/vent, with interference as the fifth contact that closes the cycle. GnosisFoilJsonlRawIngressEngine provides the bounded report/FIFO seam for one raw capture JSON object at a time and rejects descriptor drift or captures larger than the declared block size. GnosisFoilDirectDeviceReadEngine is the next lower seam: it reads fixed-size RTL-SDR/libusb-style blocks into a reusable buffer and exposes a borrowed GnosisFoilRawBlock so projection can bypass both waterfall frames and owned capture allocation on the hot path. GnosisFoilRtl2832BulkEngine specializes that seam to the Osmocom RTL2832 shape: Realtek VID/PID, IN bulk endpoint 0x81, and fixed-size raw-IQ blocks behind a Rtl2832BulkTransfer trait. gnosis-foil-control --raw-engine librtlsdr loads the local librtlsdr dynamic library at runtime and feeds rtlsdr_read_sync blocks through that same transfer trait. --raw-engine libusb-rtl2832 keeps the API shape and swaps in a direct runtime-loaded libusb_bulk_transfer reader against endpoint 0x81; it is the clean-room replacement seam for deleting the librtlsdr implementation once RTL2832 control/tuner initialization is owned here. --libusb-cold-probe exercises a standard USB GET_STATUS control transfer before bulk reads, validating the owned control-transfer machinery. The probe is implemented as a data-driven Rtl2832InitPlan, so clean-room RTL2832/R820T register steps can be added as explicit checked ControlRead/ControlWrite entries without changing the Flow/BWF2/FRF API.

  • mesh_probability_admission.rs - finite route-mass admission table for mesh hot paths. It emits explore/cover/speculate/reuse witnesses from observed request-shape mass and cached payload availability. gnosis-foil-control enables it by default on Flow/UDP, so repeated covered paths can reuse resident payloads before entering heavier route computation. Opt out with --no-probability-admission, GNOSIS_FOIL_PROBABILITY_ADMISSION=0, or GNOSIS_FOIL_NO_PROBABILITY_ADMISSION=1. Inspect GET /.aeon/flow for the live admission policy, tracked-key count, total observations, per-decision reuse/speculate/cover/explore counters, cached-response admissions, and lock misses. Entropy-sensitive attestation routes include the resident entropy certificate fingerprint in the Flow probability cache key, so changing entropy evidence forces a fresh payload instead of reusing stale /.aeon/runtime-attestation bytes.

  • bin/mesh-probability-admission-bench.rs - deterministic proof benchmark for the default admission hot path. It compares repeated route payload construction against the finite-mass reuse path and reports mean/p50/p95/max plus speedup. Latest local run, May 20, 2026, 50,000 iterations with a 9/10 hot-route mix:

    cargo run --manifest-path open-source/gnosis/distributed-inference/Cargo.toml \
      --bin mesh-probability-admission-bench -- --iterations=50000 --hot-ratio=9
    
    mesh probability admission bench
    iterations=50000 hot_ratio=9/10 reuse_count=44998
    baseline mean=18565ns p50=6334ns p95=9542ns max=31778167ns
    probability mean=6125ns p50=208ns p95=5375ns max=57730917ns speedup=3.03x

    This is a hotpath admission benchmark, not an end-to-end model-quality claim: the measured gain is from avoiding repeated route payload construction after the finite-mass cover has admitted cached reuse. This run also had a larger probability-path max outlier than baseline, so use mean/p50/p95 plus live counters together rather than treating max as a stable steady-state value.

  • bin/fib20-rf-hardware.rs - native gnosis-foil fib(20) shootout leg for the Gnosis RF path. It optionally consumes a live waterfall frame or a fixed raw device block (--raw-device-input, --raw-block-size, --raw-sample-rate, --raw-center-hz, --raw-engine, --raw-sample-format), requires the RF hardware gate to expose the 10-bit interference frame, iterates Fibonacci through RF-gated additions, verifies fib(20)=6765, and emits a JSON or BWF2 binary timing report. Use --raw-engine rtl2832-bulk for the RTL2832-shaped bulk-transfer path.

  • bin/gnosis-foil-control.rs - native gnosis-foil control surface. It serves /.aeon/health, /.aeon/session, /.aeon/capabilities, /.aeon/flow, /.aeon/udp, and /.aeon/runtime-attestation from the foil runtime certificate. It also serves GET /.aeon/protocol69 with the canonical protocol69 projection envelope and accepts POST /.aeon/protocol69 to validate a submitted gnosis.protocol69.v1 envelope for Monster/gnexec and gnosis-uring transport parity. It also serves /.aeon/entropy-attestation when --entropy-harvest-jsonl <path|-> is supplied, which lets one process feed a bitwise/Monster entropy-export JSONL file into another process and surface the harvest telemetry as a utilization gauge. It also starts a uring-compatible UDP listener for 10-byte Aeon Flow frames. Use --raw-capture-jsonl <path|-> to attach one bounded raw capture JSONL object at startup and expose it through /.aeon/raw-capture. The /.aeon/braid-collapse-bench surface now emits the native gnosis-braid-fast-path-benchmark-v1 report with selected/fallback timings, per-operation timing, checksum equality, semantic mismatch counts, runtime decision counts, and the foil runtime certificate. Its default mode=core measures the collapsed braid arithmetic core; mode=route routes through the foil execute/execute_uncertified shape that mirrors the gnosis-uring compiled-route boundary. The same resident process now exposes GET /.aeon/rf-fibonacci?n=20&repetitions=100000 with /.aeon/fib20-rf retained as a compatibility alias for older benchmark scripts: it keeps the raw --raw-device-input handle, reusable RTL2832/direct buffer, and RfFibonacciSmartSkipCache warm across requests so repeated same-shape RF-gated Fibonacci work pays the observation/read boundary without relaunching the worker. Add format=bwf2 for the fixed 128-byte binary hot-path report; omit it for compact diagnostic JSON. The Flow/UDP listener serves the same resident computation as a BWF2 payload inside the 10-byte Aeon Flow frame, so hot callers can skip HTTP response formatting entirely. Regular-file raw fixtures replay on EOF for benchmark stability; device streams stay sequential. Use --raw-engine librtlsdr --rtlsdr-library /opt/homebrew/lib/librtlsdr.dylib for the known-good local RTL-SDR path, or --raw-engine libusb-rtl2832 --libusb-library /opt/homebrew/lib/libusb-1.0.dylib for the direct libusb bulk-read path. The direct path preserves the same Flow/BWF2/FRF API but still needs owned RTL2832 control initialization before it fully replaces librtlsdr from a cold device. Add --libusb-cold-probe to validate the direct libusb_control_transfer path with standard USB GET_STATUS. Use --raw-engine ambient-host for the no-radio resident witness engine: it harvests safe host jitter/timing chaos into the same raw-block observation contract without reading unallocated memory. wifi-noise, bt-noise, and bluetooth-noise are current aliases for that safe ambient witness shape until platform-specific Wi-Fi/BT observation engines are wired in. Start the control surface with --proxy-all --proxy-upstream-port N to front a loopback app shell while preserving native /.aeon/* control routes on the foil listener; when proxying is enabled, / belongs to the app shell and /.aeon/health remains the native health route. The resident RF Fibonacci hotpath now defaults --smart-skip-retention-floor to 12, matching the FOIL core boost witness and retaining more reusable witness state on warm repeats; override it only when you want a different cache tradeoff for research. FOIL kernel races default FOIL_RACE_LOSER_POLICY to integration, which admits cacheable loser work onto a bounded resident queue while returning the current winner without synchronously firing loser kernels. Explicit cancel remains the one-shot latency opt-out. Explicit adaptive keeps cold calls cancel-fast and self-activates integration only after a same-shape cache has already produced a hit. Explicit drain-and-cache remains a synchronous comparison mode, and drain is a measurement mode for completion without residue retention. On the release fib(20) microbench (bench-foil-loser-policy --iterations 20000 --n 20 --repetitions 2 --workload long-tail), explicit integration measured 837.99585ns mean with 2209ns p99, while cancel measured 1351.6479ns mean with 2459ns p99 in the same post-rename run. Adaptive measured 878.25205ns mean with 917ns p99, because it preserves the cancel-fast cold boundary before resident reuse activates integration. The older async-drain-and-cache spelling remains accepted as a compatibility alias. Integration maps to the "vacuum of the future" runtime metaphor in bounded form: admitted off-path work preserves the present winner while future same-shape requests can inherit lower-entropy resident cache structure. The failure policy is non-escalating. If the bounded resident queue is full, FOIL drops the off-path loser work and reports loser_kernels_dropped; it does not promote the work back into the synchronous race. If a resident cache is absent, stale, or shape-mismatched, the smart path rebuilds the current winner cache and integration can admit fresh loser work for later reuse. The Lean boundary for this is stale_recovery_uses_current_winner and stale_integration_recovery_preserves_cancel_winner. Runtime reports expose the same distinction as cache_status: fresh, absent-built, or stale-rebuilt; the loser-policy benchmark aggregates those as cache_fresh, cache_absent_built, and cache_stale_rebuilt. Use bench-foil-loser-policy --workload saturation --repetitions N to keep the winner cache hot while making off-path loser tasks heavy enough to pressure the resident queue. In that mode, loser_kernels_dropped is the admission-failure counter: nonzero values mean integration protected the present winner by dropping future-facing work instead of blocking or synchronously draining. The runtime also exposes foil_async_loser_queue_telemetry() with resident queue lifetime counters: admitted_tasks, dropped_tasks, and completed_tasks, plus the resident worker_count. Benchmark rows report per-policy deltas as queue_admitted_tasks, queue_dropped_tasks, and queue_completed_tasks, so queue pressure can be observed directly instead of inferred from a single race report. Because the worker is resident, queue_completed_tasks is a windowed observation and can include backlog admitted by an earlier row; use queue_pending_before and queue_pending_after to see that carryover. foil_async_loser_queue_telemetry_theorem_ids() and the HTTP/Flow /.aeon/runtime-attestation.async_loser_queue_telemetry_theorem_ids field point this telemetry surface at integration_telemetry_admitted_bounded, integration_telemetry_accounts_for_residue, and integration_telemetry_preserves_cancel_winner, which formalize the counters as bounded admission metadata rather than winner-selection inputs. The same field also cites runtime_attestation_transport_preserves_theorem_ids and runtime_attestation_transport_preserves_summary, plus runtime_attestation_transport_preserves_entropy_certificate for optional resident entropy evidence. These Lean boundaries say HTTP and Flow/UDP may change the transport wrapper but must preserve theorem-id, summary, and entropy certificate projections. Add --drain-queue-between-policies when you want isolated policy rows rather than resident carryover; the benchmark waits up to --drain-timeout-ms (default 1000) before each row and reports whether that wait reached zero as queue_drained_before. Add --policy integration, --policy adaptive, or a comma-separated list such as --policy adaptive,integration when you only need targeted queue-pressure rows. Unknown policy/workload values and --iterations 0 exit with status 2 instead of producing an empty or undefined benchmark row. Set FOIL_ASYNC_LOSER_WORKERS=N before process start to test more resident off-path workers; the runtime clamps this to 1..=8 and keeps the default at 1. In the targeted saturation probe, FOIL_ASYNC_LOSER_WORKERS=4 previously measured slower than the default single worker, so more workers remain opt-in rather than default. The race hot path now uses resident-cache APIs for benchmark/control surfaces: fresh cache hits update the caller's cache slot in place and the benchmark uses rf_fibonacci_race_resident_cache_sample(...) to return only the fields it reports. That avoids a retained-witness clone and full report construction on every benchmark hit. Async integration loser tasks also compact their RF observation and use a no-allocation RF value loop off-thread, preserving bounded queue admission without copying the full observation. Latest targeted release saturation probe, May 20, 2026: cargo run --release --manifest-path distributed-inference/Cargo.toml --bin bench-foil-loser-policy -- --policy cancel,adaptive,integration --iterations 1200 --n 35 --repetitions 200 --workload saturation --drain-queue-between-policies --drain-timeout-ms 1000. All three rows verified smart-skip with p99 42ns. cancel was the fastest mean at 57.9167ns with no queue work. adaptive measured 67.7083ns, admitted 1024 queue tasks, dropped 174, and left 1024 pending. Explicit integration measured 94.445ns, admitted 1025, dropped 175, and left 1025 pending. This keeps integration viable as the default semantic policy, but the measurement honestly shows cancel is the lower-overhead path when no future cache benefit is needed; use p99 plus queue counters rather than the nanosecond-scale mean alone. The runtime certificate also lowers the gnosis-math DiscreteMachineNumberFastPath shape into Rust as finite u128 cross-multiplied brackets for binary32 and binary64 constants; machine-target pi/e/sqrt2/phi rows now report forced=true when their discrete brackets fit entirely inside the target machine cell. Monster closure validation uses the same finite style: candidates are checked as 10 * 3^n by discrete division before any cache growth, so FOIL can reject arbitrary non-tower Monster positions without building the closure tower. BracketedSpace Phi refinements are also lowered as finite containment certificates, letting FOIL carry a narrower non-discrete bracket witness without reopening the enclosing bracket computation. GodBracket budget rows extend that reuse into rejection weights, so a checked narrower bracket can skip straight to its higher runtime weight. CausalDiamond race rows now expose the same finite decision boundary for runtime scheduling: refine into the narrower diamond while it is above the sliver limit, then terminate.

  • ../fixtures/gnosis-foil-raw-capture.jsonl

    • minimal ChipsetRaw JSONL fixture for exercising the raw-capture control path without hardware.
  • model.rs - native Llama-family pipeline and station kernels. FFN pressure telemetry defaults to observe, which does not change logits. Set GNOSIS_FFN_LEAKAGE_MODE=off to disable it, or explicitly choose mask-low-N, mask-input-low-N, mask-hidden-low-N, or mask-tail-low-N to try block-level low-pressure FFN skips in supported quantized kernels. mask-low-43 is the aggressive moonshine experiment and may change token output. guard-tail-low-43 is the first zero-divergence candidate: it runs a tail mask speculatively and falls back to observe whenever the candidate actually skips FFN work. spherical-43, spherical-guard-43, and harmonic-43 are aliases for that guarded 43 profile; the formal 2586 pressure-weighted interference total is exposed as metadata, not as a raw tensor-unit activation threshold. experimental-mirror-tail-low-43 is the first explicit harmonic tensor approximation: on the final FFN layer only it mirrors low-pressure intermediate blocks with a raw 1:1 antipodal copy before down_proj, and reports mirrored blocks separately from skipped blocks. Scaled forms such as experimental-mirror-tail-low-43-scale-750 attenuate the copied block by that milli-scale factor for calibration sweeps. Predictive forms such as experimental-predictive-mirror-tail-low-43-scale-750 and guarded alias predictive-tail-latency-43 use the prior tail hidden block mask to skip Q5 gate/up output rows before mirroring. This is the first work-saving mirror kernel and remains experimental: it is calibrated by same-run token divergence and FFN mean, not promoted by the finite Lean certificate. GNOSIS_FFN_PREDICTIVE_MIN_GATE_UP_SKIP_BLOCKS defaults to 1 and raises the minimum prior inactive 256-row blocks required before the predictive output-mask kernel is used; below that floor, the candidate keeps the same mirror semantics but runs the regular Q5 gate/up pair to avoid low-density masking overhead. /decode-next also accepts X-FFN-Predictive-Min-Gate-Up-Skip-Blocks, and bench-decode-next exposes the same request-scoped control as --predictive-min-gate-up-skip-blocks. tail-latency-43, p90-guard-43, and p90-guard-mirror-43 are named aliases for the guarded final-layer mirror at threshold 43 and scale 750; they are tail-latency experiments, not replacements for the semantics-preserving spherical-43 guarded mask alias. guard-mirror-tail-low-N-scale-S records a pre-execution weather check before attempting the mirror candidate: position zero, prior low logit margin, prior high mirrored-block pressure, and prior 3-step RMS drift above the default 1.12 threshold route directly to observe mode unless the prior logit margin is above 4.5; all pre-rejections expose ffn_guard_weather_* telemetry plus ffn_guard_sieve_pre_rejects. Each guarded decode also records a finite weather cell over position, prior margin, prior 3-step RMS drift, and prior mirrored-block pressure bands. For example, cell 1111 means position-zero/margin-unknown/drift-unknown/no-prior-blocks, while 3332 means steady/watch-margin/high-drift/bounded-blocks. The drift threshold can be swept with GNOSIS_FFN_GUARD_RMS_DELTA3_THRESHOLD; the margin floor and high-confidence override can be swept with GNOSIS_FFN_GUARD_MIN_LOGIT_MARGIN and GNOSIS_FFN_GUARD_HIGH_CONFIDENCE_LOGIT_MARGIN. /decode-next also accepts request-scoped guard threshold overrides: X-FFN-Guard-RMS-Delta3-Threshold, X-FFN-Guard-Min-Logit-Margin, and X-FFN-Guard-High-Confidence-Logit-Margin; the station restores its prior defaults after each request. bench-decode-next forwards the same controls with --guard-rms-delta3-threshold, --guard-min-logit-margin, and --guard-high-confidence-logit-margin, so threshold sweeps can run against one hot station instead of restarting between candidates. GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS is an empty-by-default calibration table for cells that have earned explicit benchmark admission. Listing a cell only suppresses soft low-margin/high-drift weather rejects, and only for non-position-zero, non-high-block cells; hard guards remain hard. Admitted samples expose ffn_guard_weather_cell_admitted=1 so sweeps can audit the change. X-FFN-Guard-Speculate-Weather-Cells and benchmark flag --speculate-weather-cells are weaker: they only bypass the pre-execution weather reject and still keep the post-candidate logit margin fallback. /decode-next also accepts X-FFN-Guard-Admit-Weather-Cells as a request-scoped replay override, restored after the request like X-FFN-Leakage-Mode, so benchmark policy manifests can be tested without restarting the station. Candidate-run reject reasons remain exposed separately as ffn_guard_mirror_reject_*, so benchmarks can separate avoided double-path fallbacks from post-candidate fallbacks. The station also reports pre-FFN residual L2/RMS tail norms plus final-step and 3-step RMS drift, so the weather predictor can be calibrated against residual pressure and turbulence before either becomes an admission rule.

  • bin/fat-station.rs - native HTTP station for local mesh validation and generation. It also serves GET /.aeon/attention-closure-benchmark, a live JSON optimizer-admission certificate using station-local hidden-dimension and layer-count defaults.

  • bin/bench-decode-next.rs - decode-step comparison harness. With --baseline-mode, --candidate-mode, and optional --probe-mode, it can compare observe output, guarded weather output, and a raw mirror probe in one interleaved run. The weather_probe summary records raw mirror divergences, guarded divergences, weather-caught divergences, weather misses, conservative weather rejects, and per-cell outcomes for calibration. The comparison gate is explicit: --gate speedup requires zero divergence plus faster p50/p90/FFN timing, --gate tail-latency requires zero divergence plus faster p90 and FFN mean but does not claim p50 improvement, --gate semantic requires zero divergence only, and --gate none records without failing. Probe runs default to the semantic gate. Add --json-summary to emit a final machine-readable summary line for threshold sweeps. Add --weather-grid with either explicit --grid-starts token@position,... or the cross product of --grid-tokens and --grid-positions to aggregate many starts into one per-cell weather report. Grid runs require --baseline-mode, --candidate-mode, and --probe-mode; their JSON output uses kind=decode-next-weather-grid and records aggregate caught, missed, conservative, p50/p90 speedup, and FFN speedup counts per weather cell. Grid runs also emit policy candidates when a cell has enough clean samples: --policy-min-samples controls the sample floor, and --policy-min-replicates controls how many independent grid starts must reproduce the cell-local gate before a manifest can promote that cell. --policy-min-replicate-samples controls the per-start sample floor for those replicated checks. --policy-max-conservative-rate controls the maximum conservative-reject rate. --policy-min-p50-speedup, --policy-min-p90-speedup, and --policy-min-ffn-speedup default to 1.0, so suggested cells must be at least non-slower on each measured axis. Position-zero and high-block cells are hard guards and are never suggested for explicit admission. Candidate output includes weather_grid_policy_env=GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=...; copying that env value is an explicit calibration act, not a default semantic claim. Add --policy-manifest to emit a compact signed JSON admission table, or --policy-manifest-out path/to/manifest.json to write a pretty JSON manifest. The manifest is gated again before emission: global guarded divergence and missed raw divergences must be zero, each admitted cell must still clear the sample, replicate, conservative-rate, hard-guard, and p50/p90/FFN speed floors, and the payload is tagged with a deterministic fnv1a64-json-v1 checksum signature. Schema version 2 manifests include the replicate gates; older policy files are intentionally rejected by replay. Replay a manifest with --policy-manifest-in path/to/manifest.json, or replay a raw cell list with --admit-weather-cells 3232,3332; the harness forwards the cells as X-FFN-Guard-Admit-Weather-Cells on each /decode-next request. Unsafe cells can be forced into pre-execution observe with --deny-weather-cells 3321,3322, forwarded as X-FFN-Guard-Deny-Weather-Cells. Denial is a hard guard and wins over any admission list entry for the same cell; use it only for cells with observed raw divergence misses or other replicated safety failures. Connection or JSON failures include request id, token, position, and FFN mode so aborting raw experimental probes can be traced to the exact lane that failed. A May 2, 2026 current-build debug smoke against the local Qwen2.5 0.5B knot recorded observe/guarded tokens [284,220,15], raw mirror probe tokens [284,220,16], raw_probe_divergent_tokens=1, guarded_divergent_tokens=0, caught_raw_divergences=1, missed_raw_divergences=0, and conservative_rejects=2. With lattice telemetry enabled, the guarded stream grouped into cells 1231 and 2231; 2231 held the raw mirror divergence with caught=1, missed=0, and conservative=1. Treat that as calibration evidence for the pre-execution sieve, not as a release-mode speed claim. A two-start --weather-grid smoke over 8@0 and 284@1 also verified aggregate JSON output with kind=decode-next-weather-grid, cells 1231 and 2231, zero guarded divergence, zero raw-probe divergence, zero misses, and two conservative rejects. A station-level admission smoke with GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=1231,2231 recorded 1231:samples=1,rejects=1,admissions=0 and 2231:samples=1,rejects=0,admissions=1, preserving the hard position-zero guard while admitting the soft warmup/high-drift cell. After policy speed gates landed, a hard-filter smoke with relaxed speed floors emitted only GNOSIS_FFN_GUARD_ADMIT_WEATHER_CELLS=2231; cell 1231 recorded admission_allowed=false despite faster local timing. The same grid under default 1.0x speed floors emitted no policy env because soft cell 2231 measured below the p50, p90, and FFN floors on that sample. A later May 2, 2026 guarded-43 mirror run added the explicit --gate tail-latency boundary. On a seven-start weather grid with tail-latency-43 against observe and raw experimental-mirror-tail-low-43-scale-750 as the probe, the guarded candidate recorded divergent_tokens=0, p50_speedup=1.1654x, p90_speedup=1.1436x, and ffn_speedup=1.0421x, while the raw probe diverged on 45/56 samples. The same profile over a single 128-iteration endurance from token 9707@0 remained semantically clean but failed the tail-latency gate (p90_speedup=0.9124x, ffn_speedup=1.0322x). Treat guarded 43 mirror as a distribution-sensitive p90 profile until a broader prompt mix reproduces the tail win. The first explicit replay winner was cell 3332 only: --admit-weather-cells 3332 over the 128-sample 9707@0 endurance passed --gate tail-latency with divergent_tokens=0, p50_speedup=1.0170x, p90_speedup=1.2344x, and ffn_speedup=1.2285x. Expanding the replay to 3331,3332 stayed semantically clean but failed the tail-latency gate, so replicated manifest promotion should require repeated 3332 evidence rather than broadening to adjacent cells from a single run. A replicated two-start replay then falsified broad default admission for 9707@0: raw probe divergence in cells 3321 and 3322 produced missed_raw_divergences=4, blocking schema-v2 manifest emission. Those cells now form the first explicit deny replay boundary for the next 43-tail run. The first predictive gate/up row-skip experiment preserved a separate predictive hidden block mask and added ffn_predictive_gate_up_skipped_blocks telemetry. On the same 9707@0 endurance with --admit-weather-cells 3332 --deny-weather-cells 3321,3322, the optimized block-mask kernel fired (predictive_gate_up_skipped_blocks=988) and kept divergent_tokens=0, but still failed --gate tail-latency (p50_speedup=0.9374x, p90_speedup=0.9770x, ffn_speedup=0.9401x). A 64-sample raw probe caught all raw predictive divergences (raw_probe_divergent_tokens=17, missed_raw_divergences=0) but did not expose a safe high-volume cell to admit. Treat predictive 43 row-skipping as instrumented but not promotable until a pre-execution policy can reduce fallbacks without admitting divergent low-margin cells.