Skip to content

fix(models): keep the vendored model contract in sync - #208

Merged
andersalm merged 2 commits into
developfrom
fix/model-contract-vendor
Oct 8, 2026
Merged

andersalm merged 2 commits into
developfrom
fix/model-contract-vendor

Conversation

@andersalm

@andersalm andersalm commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Marketplace now carries Assistant’s canonical model contract, including route kind, context facts and output-token controls. The existing required Assistant shell smoke checks byte identity and refuses a stale or missing vendored contract. The canonical vendor source remains Assistant.

Validation: canonical vendor, product-data, Assistant shell/behavior and format gates pass. Independent development and local Claude Opus adversarial reviews pass at the refreshed candidate. The full local pre-push gate passes, including 2,803 Runtime unit tests (27 ignored). Installed Get-to-reply acceptance is owned by #150 and PR #153.

Refs #84, #150.

@andersalm

Copy link
Copy Markdown
Contributor Author

Development review PASS (gpt-6.1-sol high, one independent round), head 3ac4c85fb3f08fa6b177d3d6c02c97a390be2007 / tree fe47e431fa51a3bbfc20cb59fa978147958df020, exact diff SHA-256 d269a1a2118711d905657b391520d5fa83a4e8e5f4fe33773d4a0cd1101a985c.

Marketplace matches the unchanged canonical Assistant file through the existing vendor rule. Current Marketplace imports use unchanged helpers. The CI-run entropy guard accepts matching bytes and refuses both the actual old develop copy and a missing copy. Diff, vendor, entropy, Assistant shell smoke and syntax checks pass. The different-family adversarial verdict is separate.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus via elastos-pr-review, 2026-10-02), head 3ac4c85.
VERDICT: PASS

Blocking findings: none.

Marketplace behaviour is unchanged. capsules/marketplace/browser/model-services.js:1 imports only eligibleTextOffers and offerSelectionFacts. Neither function is in the diff. The changed functions, textOfferRows and textRunCreateBody, have no Marketplace caller. Assistant callers are untouched. The new max_output_tokens field appears only in Assistant's copy, which is already canonical. offerRouteKind, MODEL_TEXT_INPUT_V2_SCHEMA and readBytes (scripts/home-entropy-check.mjs:31) exist at the PR head. The PR touches no authority boundary, token, sandbox or update path.

The gate fails closed. scripts/home-entropy-check.mjs:892-897 compares the two files byte for byte, and readFileSync throws if either file is missing. CI runs this gate (.github/workflows/ci.yml:61). The old develop copy lacked routeKind and context, so the gate would have failed on it. The new gate therefore catches the drift that the old CI gate missed.

Non-blocking notes:

  1. The check now exists twice: once in scripts/vendor-ui-tokens.sh:127-133 and again in the entropy gate. CI does not run vendor-ui-tokens.sh --check, so the other vendored copies are still not enforced in CI: model-management.js and model-management.css (in Marketplace and System), model-selection.js and the UI token, picker and font copies. Adding ./scripts/vendor-ui-tokens.sh --check to ci.yml would protect all of them with one check, and the duplicate assertion could then go.
  2. The assertion message tells the operator to run just vendor-ui but does not name the drifting file. The vendor script does name it.
  3. Marketplace now ships two contract fields it does not use (routeKind, context). This is harmless, and it is the price of keeping one byte-identical source.

Not checked: I ran no gates; the PR's claims that its checks pass and that the gate refuses the old copy are unverified here. Installed Home and Marketplace on the seed, Mac and Jetson are also unchecked; the PR defers them to existing journey gates.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review: Claude Opus via elastos-pr-review, PASS at head 8fc0f72, tree 8cbb7837895f32a1bf945c1bc7e8fb730d547efe.
Scope: canonical contract copy and required Assistant shell parity smoke; blockers: none. Byte identity and stale/missing refusal pass locally.
The existing shell smoke owns this narrow CI assertion; the vendor helper owns generation. Marketplace’s consumer functions retain their behavior. Installed acceptance stays with #150/#153.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent development review: PASS at head 8fc0f72, tree 8cbb7837895f32a1bf945c1bc7e8fb730d547efe.
Diff reviewed against develop 1828919; SHA-256 38bae43ee71b62011c0db9d52da12f81b2c7c70f471f2c2cb3709bdab46017c1; findings: none.
The full push gate passed, including 2,803 Runtime tests (27 ignored); current CI run 37716598127 supplies the remaining required checks.

@andersalm
andersalm marked this pull request as ready for review October 8, 2026 02:14
@andersalm
andersalm merged commit b226129 into develop Oct 8, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant