Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
c482c63
feat: add trusted measurement receipt controls before native qualific…
functionstackx Sep 19, 2026
52deac0
feat: enable the prepared native H100 Phase 1 pilot
functionstackx Sep 19, 2026
8cc15c4
chore: link Phase 1 qualification to PR 3299
functionstackx Sep 19, 2026
a12eb85
fix: bind tokenizer snapshots and verify the native runtime in CI
functionstackx Sep 19, 2026
4f4d50c
Merge current main for Phase 1 sweep qualification
functionstackx Sep 19, 2026
4e44348
fix(ci): launch native pilot with managed Python
functionstackx Sep 19, 2026
c4af40d
fix(results): stream receipt archive verification
functionstackx Sep 19, 2026
d5726ab
fix(results): integrate streaming receipt verification
functionstackx Sep 19, 2026
9d365ac
docs: record Phase 1 GitHub qualification evidence
functionstackx Sep 19, 2026
12ef722
refactor(recipes): follow existing H100 recipe layout
functionstackx Sep 19, 2026
14d56f1
fix: bind pilot topology and inspect H100 assets through CI
functionstackx Sep 20, 2026
3ebcabe
feat: provision and qualify the native H100 pilot without publication
functionstackx Sep 20, 2026
065cb56
fix: prepare real offline H100 client caches and probes
functionstackx Sep 20, 2026
bc07109
fix: use native-safe cancellation qualification intents
functionstackx Sep 20, 2026
366842b
fix: match cancellation probes to the real c28 eval server
functionstackx Sep 20, 2026
1742322
fix: pin Step Manager aware native H100 execution
functionstackx Sep 20, 2026
6fc5932
docs: show shared Phase 1 serving argument calls
functionstackx Sep 20, 2026
c3db6c7
docs: record corrected Phase 1 CI and sweep replacement
functionstackx Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
172 changes: 118 additions & 54 deletions .github/workflows/benchmark-tmpl.yml

Large diffs are not rendered by default.

142 changes: 142 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,11 @@ on:
- 'infx/ruff.toml'
- '**/pytest.ini'
- 'utils/srt-slurm'
- 'benchmarks/multi_node/srt-slurm-recipes/dsv41flash/vllm/h100-fp4/**'
- 'benchmarks/multi_node/srt-slurm-recipes/configs/prepared-runtime-lock.json'
- 'benchmarks/multi_node/srt-slurm-recipes/configs/dsv41flash-agentx-client-policy.json'
- 'runners/srt-slurm/h100-phase1.yaml'
- 'utils/fixtures/native_pilot/**'
push:
branches: [main]
paths: *python-paths
Expand Down Expand Up @@ -82,3 +87,140 @@ jobs:
python -c "import torch; assert torch.version.cuda is None and torch.version.hip is None"
# SRT is initialized for our connector tests; its upstream suite runs in its own CI.
python -m pytest utils/ runners/ experimental/CollectiveX/tests/ experimental/operatorx/tests/ --ignore=utils/srt-slurm -n 4

native-pilot:
name: Native pilot contract
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false

- name: Validate native runtime lock
id: native-lock
shell: python
run: |
import json
import os
import re
from pathlib import Path

lock = json.loads(Path("benchmarks/multi_node/srt-slurm-recipes/configs/prepared-runtime-lock.json").read_text())
if type(lock.get("schema_version")) is not int or lock["schema_version"] != 1:
raise ValueError("Unsupported native runtime lock schema")
if lock.get("repository") != "https://github.com/SemiAnalysisAI/srt-slurm.git":
raise ValueError("Native runtime repository is not allowlisted")
for field, length in (("revision", 40), ("uv_lock_sha256", 64)):
value = lock.get(field)
if not isinstance(value, str) or re.fullmatch(r"[0-9a-f]{%d}" % length, value) is None:
raise ValueError(f"Invalid native runtime {field}")
with Path(os.environ["GITHUB_OUTPUT"]).open("a") as output:
output.write("repository=SemiAnalysisAI/srt-slurm\n")
output.write(f"revision={lock['revision']}\n")

- name: Checkout pinned native runtime
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ${{ steps.native-lock.outputs.repository }}
ref: ${{ steps.native-lock.outputs.revision }}
path: .native-phase1
fetch-depth: 0
persist-credentials: false

- name: Verify native source and version lineage
shell: python
run: |
import hashlib
import json
import subprocess
from pathlib import Path

source = Path(".native-phase1").resolve()
lock = json.loads(Path("benchmarks/multi_node/srt-slurm-recipes/configs/prepared-runtime-lock.json").read_text())
def git(*args):
return subprocess.run(
["git", "-C", str(source), *args], check=True,
capture_output=True, text=True, timeout=120,
).stdout.strip()
if git("rev-parse", "HEAD") != lock["revision"]:
raise ValueError("Native checkout differs from its pinned revision")
if hashlib.sha256((source / "uv.lock").read_bytes()).hexdigest() != lock["uv_lock_sha256"]:
raise ValueError("Native dependency lock differs from its pinned digest")
# hatch-vcs needs the original NVIDIA release tag, which the fork may not carry.
git("fetch", "--no-tags", "--force", "https://github.com/NVIDIA/srt-slurm.git",
"refs/tags/v2.2.1:refs/tags/v2.2.1")
upstream = "984180e5b8755aef85e9995048b5a16cb5336bce"
if git("rev-parse", "refs/tags/v2.2.1^{commit}") != upstream:
raise ValueError("NVIDIA v2.2.1 tag no longer matches the reviewed lineage")
git("merge-base", "--is-ancestor", upstream, "HEAD")
if git("describe", "--tags", "--match", "v[0-9]*", "--abbrev=0") != "v2.2.1":
raise ValueError("Unexpected native hatch-vcs release lineage")
if git("status", "--porcelain", "--untracked-files=all"):
raise ValueError("Native source checkout must remain clean")

- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
cache-suffix: Native-pilot-contract
cache-dependency-glob: |
uv.lock
.native-phase1/uv.lock

- name: Prepare independent locked test environments
shell: python
run: |
import os
import subprocess
from pathlib import Path

workspace = Path(os.environ["GITHUB_WORKSPACE"])
native_env = Path(os.environ["RUNNER_TEMP"]) / "native-phase1-venv"
subprocess.run(
["uv", "sync", "--locked", "--all-extras", "--group", "test",
"--no-editable", "--python", "3.12"],
cwd=workspace, check=True, timeout=600,
env={**os.environ, "UV_PROJECT_ENVIRONMENT": str(workspace / ".venv")},
)
subprocess.run(
["uv", "sync", "--frozen", "--dev", "--no-editable", "--python", "3.12"],
cwd=workspace / ".native-phase1", check=True, timeout=600,
env={**os.environ, "UV_PROJECT_ENVIRONMENT": str(native_env)},
)

- name: Run pinned native Linux tests
shell: python
run: |
import os
import subprocess
from pathlib import Path

python = Path(os.environ["RUNNER_TEMP"]) / "native-phase1-venv/bin/python"
source = Path(os.environ["GITHUB_WORKSPACE"]) / ".native-phase1"
subprocess.run(
[str(python), "-m", "pytest", "tests/", "-m", "not integration", "-q"],
cwd=source, check=True, timeout=600,
env={**os.environ, "PYTHONPATH": str(source / "src"),
"PATH": str(python.parent) + os.pathsep + os.environ["PATH"]},
)

- name: Run nine-point installed native boundary test
shell: python
run: |
import os
import subprocess
from pathlib import Path

workspace = Path(os.environ["GITHUB_WORKSPACE"])
native_env = Path(os.environ["RUNNER_TEMP"]) / "native-phase1-venv"
subprocess.run(
[str(workspace / ".venv/bin/python"), "-I", "-m", "pytest", "-q",
"utils/test_native_pilot.py::test_installed_native_runtime_prepares_and_renders_the_entire_pilot"],
cwd=workspace, check=True, timeout=180,
env={**os.environ,
"PATH": str(workspace / ".venv/bin") + os.pathsep + os.environ["PATH"],
"INFX_NATIVE_PHASE1_PYTHON": str(native_env / "bin/python"),
"INFX_NATIVE_PHASE1_SOURCE": str(workspace / ".native-phase1")},
)
89 changes: 89 additions & 0 deletions .github/workflows/e2e-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,17 @@ permissions:
on: # zizmor: ignore[concurrency-limits]
workflow_dispatch:
inputs:
phase1-site-operation:
description: "H100 site preparation or disposable native cancellation qualification"
required: false
type: choice
options: [none, inspect, provision, cancel-startup, cancel-client]
default: none
phase1-site-draft:
description: "Explicit shared site-draft.json path for cancellation qualification"
required: false
type: string
default: ""
generate-cli-command:
description: "Command passed to generate matrix script"
required: false
Expand Down Expand Up @@ -110,6 +121,16 @@ on: # zizmor: ignore[concurrency-limits]
MODAL_TOKEN_SECRET:
required: false
inputs:
phase1-site-operation:
description: "H100 site preparation or disposable native cancellation qualification"
required: false
type: string
default: none
phase1-site-draft:
description: "Explicit shared site-draft.json path for cancellation qualification"
required: false
type: string
default: ""
generate-cli-command:
description: "Command passed to generate matrix script"
required: false
Expand Down Expand Up @@ -205,7 +226,75 @@ on: # zizmor: ignore[concurrency-limits]
default: "[]"

jobs:
phase1-site-route:
name: Queue Phase 1 site preparation
if: ${{ inputs.phase1-site-operation && inputs.phase1-site-operation != 'none' }}
runs-on: ubuntu-latest
outputs:
queue-token: ${{ steps.token.outputs.result }}
steps:
- id: token
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
SITE_OPERATION: ${{ inputs.phase1-site-operation }}
with:
result-encoding: string
script: |
if (!['inspect', 'provision', 'cancel-startup', 'cancel-client'].includes(process.env.SITE_OPERATION)) {
throw new Error('Unknown Phase 1 site operation');
}
return require('crypto').createHash('sha256')
.update(`${context.runId}:${process.env.GITHUB_RUN_ATTEMPT}:phase1-site`)
.digest('hex').slice(0, 32);
phase1-site:
if: ${{ inputs.phase1-site-operation && inputs.phase1-site-operation != 'none' }}
needs: phase1-site-route
name: Phase 1 H100 site and lifecycle qualification
# The shared Linux paths can only be inspected from this cluster's login runners.
runs-on: ${{ fromJSON(format('["self-hosted","cluster:h100-dgxc","nodes:1","ci-job-1.000-{0}","ci-attempt-{1}"]', needs.phase1-site-route.outputs.queue-token, github.run_attempt)) }}
timeout-minutes: 120
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Provision the same immutable tree the sweep will measure (PR merge SHA).
ref: ${{ inputs.ref || github.workflow_sha }}
path: phase1-site-${{ github.run_id }}-${{ github.run_attempt }}
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- name: Prepare explicit shared paths
working-directory: phase1-site-${{ github.run_id }}-${{ github.run_attempt }}
env:
SITE_OPERATION: ${{ inputs.phase1-site-operation }}
SITE_DRAFT: ${{ inputs.phase1-site-draft }}
# H100 login runners do not provide an ambient python executable.
shell: uv run --locked --no-dev --python 3.12 python {0} # zizmor: ignore[misfeature]
run: |
import os, sys
from pathlib import Path
operation = os.environ["SITE_OPERATION"]
if operation in {"cancel-startup", "cancel-client"}:
from infx.srt_slurm.qualify_cancellation import qualify
if not os.environ["SITE_DRAFT"]:
raise ValueError("Cancellation qualification requires phase1-site-draft")
mode = operation.removeprefix("cancel-")
walltime, observation = (300, 240) if mode == "startup" else (3600, 3300)
qualify(Path.cwd(), Path(os.environ["SITE_DRAFT"]), Path("phase1-provision-report"),
f"{os.environ['GITHUB_RUN_ID']}-{os.environ['GITHUB_RUN_ATTEMPT']}-{mode}",
mode=mode, walltime_seconds=walltime,
observation_timeout_seconds=observation, cleanup_timeout_seconds=180)
else:
from infx.srt_slurm.provision import main
sys.argv = ["provision", "--config", "runners/srt-slurm/h100-phase1-provision.json", "--output", "phase1-provision-report", "--operation", operation]
raise SystemExit(main())
- name: Preserve provisioning evidence
if: ${{ always() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: phase1-site-${{ inputs.phase1-site-operation }}-${{ github.run_id }}-${{ github.run_attempt }}
path: phase1-site-${{ github.run_id }}-${{ github.run_attempt }}/phase1-provision-report/
if-no-files-found: error
get-jobs:
if: ${{ !inputs.phase1-site-operation || inputs.phase1-site-operation == 'none' }}
name: get-jobs
runs-on: ubuntu-latest
outputs:
Expand Down
79 changes: 79 additions & 0 deletions .github/workflows/phase1-receipt.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
name: Seal Phase 1 measurement receipt

# Each reviewed approval produces an independent immutable record; later requests must not cancel pending issuances.
on: # zizmor: ignore[concurrency-limits]
workflow_dispatch:
inputs:
kind:
description: Seal source measurement or its later publication reference
required: true
default: measurement
type: choice
options: [measurement, publication]
approval-path:
description: Reviewed default-branch qualification/phase1/*.json expectation
required: true
type: string

permissions:
contents: read
actions: read # Read source workflow attempts and download the exact artifacts being sealed.

jobs:
seal:
name: Seal reviewed measurement or publication
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.workflow_sha }}
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- name: Resolve reviewed expectation
env:
APPROVAL_PATH: ${{ inputs.approval-path }}
shell: python
run: |
import os
from pathlib import Path
path = Path(os.environ['APPROVAL_PATH']).resolve(strict=True)
root = Path('qualification/phase1').resolve()
if not path.is_relative_to(root) or path.suffix != '.json' or any(c in str(path) for c in '\r\n'):
raise ValueError('approval must be a reviewed qualification/phase1 JSON file')
with Path(os.environ['GITHUB_ENV']).open('a') as stream:
stream.write(f'REVIEWED_APPROVAL={path}\n')
- name: Seal independently approved complete source sweep
if: inputs.kind == 'measurement'
env:
GH_TOKEN: ${{ github.token }}
TRUSTED_WORKFLOW_SHA: ${{ github.workflow_sha }}
shell: python
run: |
import os, subprocess
subprocess.run(['uv', 'run', '--locked', 'python', '-m', 'infx.workflows.phase1_publication',
'--approval', os.environ['REVIEWED_APPROVAL'], '--archives', 'verified-archives',
'--output', 'receipt.json'], check=True)
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: inputs.kind == 'measurement'
with:
name: measurement-receipt
path: receipt.json
if-no-files-found: error
- name: Bind accepted source to reviewed publication
if: inputs.kind == 'publication'
env:
GH_TOKEN: ${{ github.token }}
TRUSTED_ISSUER_SHAS: ${{ vars.INFX_RECEIPT_ISSUER_SHAS }}
DEPLOYED_READER_SHA: ${{ vars.INFX_PHASE1_READER_REVISION }}
shell: python
run: |
import os, subprocess
subprocess.run(['uv', 'run', '--locked', 'python', '-m', 'infx.workflows.phase1_record',
'--approval', os.environ['REVIEWED_APPROVAL'], '--output', 'publication.json'], check=True)
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: inputs.kind == 'publication'
with:
name: publication-record
path: publication.json
if-no-files-found: error
22 changes: 22 additions & 0 deletions .github/workflows/recover-reused-ingest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,34 @@ concurrency:
jobs:
trigger-agentic-ingest:
name: trigger-agentic-ingest
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: read
actions: read # Verify issuer workflow attempts and download accepted receipt artifacts.
steps:
- name: Checkout trusted receipt resolver
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.workflow_sha }}
persist-credentials: false
- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- name: Resolve accepted immutable publication
id: receipt
env:
GH_TOKEN: ${{ github.token }}
SOURCE_RUN_ID: ${{ inputs.source-run-id }}
MERGE_RUN_ID: ${{ inputs.merge-run-id }}
INFX_RECEIPT_ISSUER_SHAS: ${{ vars.INFX_RECEIPT_ISSUER_SHAS }}
INFX_RECEIPT_ISSUER_WORKFLOW: ${{ vars.INFX_RECEIPT_ISSUER_WORKFLOW }}
run: uv run --locked python -m infx.workflows.receipt_transport --publication-required
- name: Trigger agentic database ingest
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
SOURCE_RUN_ID: ${{ inputs.source-run-id }}
MERGE_RUN_ID: ${{ inputs.merge-run-id }}
RECEIPT_TRANSPORT: ${{ steps.receipt.outputs.payload }}
with:
# Cross-repository dispatch credential for maintainer-triggered ingest recovery.
github-token: ${{ secrets.FRONTEND_PAT }} # zizmor: ignore[secrets-outside-env]
Expand All @@ -37,6 +58,7 @@ jobs:
repo: "InferenceX-app",
event_type: "ingest-agentic-results",
client_payload: {
...JSON.parse(process.env.RECEIPT_TRANSPORT),
"source-run-id": process.env.SOURCE_RUN_ID,
"merge-run-id": process.env.MERGE_RUN_ID,
"database-target": "production"
Expand Down
Loading
Loading