Skip to content

Install pinned Jetson llama engine through Runtime - #133

Merged
andersalm merged 23 commits into
developfrom
feat/0.7.1-jetson-runtime-install
Oct 2, 2026
Merged

andersalm merged 23 commits into
developfrom
feat/0.7.1-jetson-runtime-install

Conversation

@andersalm

@andersalm andersalm commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Runtime installs the pinned Jetson ARM64 llama.cpp engine and libraries, verifies their hashes and glibc compatibility, and selects the bounded CPU profile. Carrier setup uses the configured UDP address. Explicit loopback binds use one IP transport with auxiliary port mapping disabled.

The current candidate 5963d0c normally includes develop de1db92. The pinned UDP transport schedules physical socket close after logical endpoint shutdown. Short-lived configured setup now waits up to one second on AddrInUse for the same requested address, with other errors returned immediately and ephemeral fallback disabled. The regression checks transient port release, occupied-address refusal, two sequential downloads and bounded final physical release. Existing success, error, timeout and borrowed-endpoint cleanup checks remain in CI.

All four local basic gates pass. The new Rust regression and cleanup checks require the current CI result. Earlier b3e9851 run 36800185608 recorded the immediate-rebind failure; that failed result is separate from accepted behavior.

The qualified prior 26de9c5 run 36783916734 passed all eight checks and supplied the verified ARM64 package. One approved isolated Jetson run installed all 16 components through Carrier, then stopped at an unattributed fixture boundary refusal before visible Assistant proof. Cleanup passed and that hardware scope is closed. #150 owns ordinary three-platform installed journeys; #154 owns admitted-offer readiness.

This PR changes CI and Carrier isolation. It stays draft until current checks are green, then requests irzhywau. Merge requires his approval under #151. #153 stays draft until this PR merges. Refs #97; required human review and visible SmolLM2 hardware acceptance remain open.

Stage the accepted b10516 Jetson archive as a release input and select its CPU profile. Check host CPU features, installed ELF architecture and library loading before writing the engine receipt. Extend ARM64 admission and native proof coverage.

Verified: release-platform-input-test.py; prepare-release-platform-test.py; focused elastos-server setup/profile/startup tests; repository format and entropy gates.
@andersalm andersalm mentioned this pull request Sep 30, 2026
9 tasks
Keep explicitly loopback-bound Carrier endpoints inside their local socket boundary by disabling Iroh port mapping. The default portmapper can start UPnP discovery through an auxiliary wildcard UDP socket.

Verified: required diff, Home entropy and formatting gates; cargo test -p elastos-server test_explicit_ (3 pass). Focused security review passes diff 0064a077522efea9f37e277a17d18fe0555476e4db9160df3dc60f64df710f91. Installed ARM64 proof remains open.
@andersalm andersalm added this to the 0.7.2 milestone Sep 30, 2026
Share the strict Carrier address reader between Runtime startup and ordinary standalone component setup. Every trusted-source route uses the chosen address without an ephemeral fallback; fetch cleanup releases the owned endpoint before the next component.

Verified: required source gates; configured setup port ownership fixture (occupied refusal, two sequential fetches, immediate rebind); existing strict configuration test; focused security review of diff 0c645b36edfbe54a63bcb16b948f2cd3fb351dc76005d57a03d022cfd6f79bd0. Installed Assistant proof remains open.
@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus, run by the operator for Anders, 2 October; different model family from the author).
VERDICT: FAIL. Blocking: fetch_first_party_component_via_carrier (setup.rs:2709-2710) now binds every first-party Carrier fetch to the configured carrier_bind_addr (carrier.rs). A running Runtime already holds that address, so in-process callers (Home launch component download, supervisor download_external) would get AddrInUse and fail whenever carrier_bind_addr is set. Inferred from code, not executed; a test that fetches while the Runtime's own endpoint is bound would settle it.
Non-blocking: on ARM64 hosts without dotprod/FP16 the setup run aborts instead of skipping llama-server (setup.rs:596-598); CI depends on artifact run 36501810782, which expires 6 October.

@andersalm

Copy link
Copy Markdown
Contributor Author

The configured listener stays with Runtime. Candidate fbd30c0df839f6860ff1be51a4acd9559317fea9 (tree f9882cd98900ab9aec4132a1e54c2130649043f9) passes an explicit Runtime context through Home/Supervisor downloads, Browser-image streaming and approved operator-update asset/metadata refresh. These short-lived clients choose a temporary port on the same configured IP. Standalone setup/update retains the configured fixed bind and its occupied-port refusal. Peer identity, size and checksum admission stay in the existing paths; owned clients close after transfer.

Executed on this Mac with cargo test --release --locked -p elastos-server --lib: Runtime download/refresh and Browser streamed install/hash-refusal tests passed, along with two configured-bind tests, six client cleanup tests and 22 signed update tests (32 total). The Runtime test holds its configured listener throughout, observes client source IP/ports, verifies both refreshed artifacts and hash refusal, checks temporary-port release, and finishes a real request through the owner’s endpoint. All four basic gates and one development review round passed. The shared current-run ARM input from #200 is also integrated.

This answers the blocking bind finding with executed evidence. Current CI and a new operator-posted different-family adversarial review remain required before merge. The prepared Jetson slot uses its separately recorded candidate and fixed guard.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus, run by the operator for Anders, 2 October), head fbd30c0 (re-review).
VERDICT: PASS. The Carrier bind finding is fixed: every in-process caller (Home launch download, supervisor download_external, Browser image streaming, operator update refresh) keeps the configured IP with port 0; a new test holds the Runtime's endpoint on the configured address while downloads, a hash refusal and a refresh run, and the listener keeps serving. Checksum before extraction, the HWCAP gate, the binary probe and receipt checks are unchanged; the CI artifact dependency is gone. Merge when all checks are green.
Non-blocking (record in #97 or #109): standalone elastos setup and elastos update still bind the fixed port and fail with AddrInUse while a Runtime holds it; setup aborts rather than skips llama-server on ARM64 hosts without dotprod/FP16 (setup.rs:348).

@andersalm andersalm mentioned this pull request Oct 2, 2026
7 tasks
@andersalm

Copy link
Copy Markdown
Contributor Author

CI36965769572 proved the engine pin and every source/platform job except ARM compatibility: the verifier ran on a PR while its package producer was skipped, so elastos-runtime-linux-arm64.tar.gz was absent.
The narrow correction 7317b37d restores packaging for ARM PRs before that verifier; upload guards, engine recipe/hash, cache rules and deadlines stay fixed. Candidate d50d58f4d1e3cad08ebe80110022ee2b569a98de / tree 2eb537c008a787a190d5fd5a8fcb83ddad8d6b1a includes the normal reviewed develop 17132f05 merge; task push is fast-forward and divergence is 0/0.
Independent development review (gpt-6.1-sol high): VERDICT PASS for that candidate/tree and concern diff SHA-256 e1d8ef8d91f1fdc1761944ea4127a01b46201cd7cd4a00a12b92fbc4a300f8bf. The existing CI policy suite passes 12 tests, including refusal of the old guard and an omitted producer; ARM archive verification passes 11 tests, YAML syntax and all four basic gates pass, and current-base merge/remerge is clean.
Current CI36972102961 is in progress. The operator's Carrier PASS at fbd30c0d remains qualified history; this workflow candidate waits for a current different-family operator adversarial PASS and the remaining #97 acceptance gates. The existing Irzhy request stays in place.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus, run by the operator for Anders, 2 October), head d50d58f (delta from fbd30c0).
VERDICT: PASS. The new commits leave the engine logic untouched (setup.rs, carrier.rs, the bundle build and the package verifier): checksum before extraction, the pinned SHA-256, the HWCAP gate and the probe are unchanged; the verifier writes its receipt only on success; the new test catches the old guard and a removed package step. Merge when all checks are green.
Non-blocking: ARM PR runs now also build the release package, which adds time to that job.

@andersalm
andersalm merged commit 829a24a into develop Oct 2, 2026
10 checks passed
@andersalm andersalm mentioned this pull request Oct 8, 2026
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant