docs(perception): record joint startup proof and remaining clock wait

This commit is contained in:
DCCONSTRUCTIONS
2026-09-02 21:16:03 +03:00
parent 48835a0499
commit 35d28418f3
3 changed files with 152 additions and 3 deletions
+11 -3
View File
@@ -1,6 +1,10 @@
# Observatory: четыре этапа создания полного real-time Perception-профиля
Дата: 2026-09-01; обновлено 2026-09-02 20:37 МСК. **Этап 1 закрыт; этап 2 в работе. Инкремент 15: полный Mac↔Worker graph подключён к continuous clock/freshness; canary FAIL.** Добавлены ответное подтверждение часов Worker, immutable source anchor, uncertainty для всех слоёв/ячеек и WAIT без потери локального владельца. Исправлены EOF ordering, повторное чтение часов внутри одного результата и ранний disconnect до application OPEN.297 local/173 Worker tests PASS; ранний reconnect дополнительно12/12 PASS.
Дата: 2026-09-01; обновлено 2026-09-02 21:12 МСК. **Этап1 закрыт; этап2 продолжается. Инкремент16: двусторонний старт принят, непрерывный real-time canary FAIL.** Код `48835a0`: обе стороны прогревают часы до source anchor; явное подтверждение Worker и data grant обязательны до старта1×. Потерянный ACK не меняет уже предложенный/принятый anchor.241 local/198 Worker tests PASS,2 Worker-only skip локально;129 измеренных source hashes совпадают.
Один32-кадровый canary теперь принял начало0–5 и после WAIT/resync3031:8 результатов,1 compute discard,9 source WAIT и14 sync skips, без неучтённых кадров. p95/p99 до consumer-ready215.767ms,5 полных свежих scene,6 результатов до EOF. Все55 raw t1–t6 обменов независимо пересчитаны;41 ready. На работающем источнике uncertainty5.0315.667ms превысила неизменные5ms; RPC errors0, Worker telemetry33/33 PASS, lease1/PIDs сохранены. PeakVRAM2363MiB, не предел24GiB. [Отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md),53 artifacts, manifest `9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`.
Предыдущий инкремент15: полный Mac↔Worker graph подключён к continuous clock/freshness; прежний canary FAIL. Добавлены ответное подтверждение часов Worker, immutable source anchor, uncertainty для всех слоёв/ячеек и WAIT без потери локального владельца. Исправлены EOF ordering, повторное чтение часов внутри одного результата и ранний disconnect до application OPEN.297 local/173 Worker tests PASS; ранний reconnect дополнительно12/12 PASS.
Финальный32-кадровый1× canary:13 кадров пропущены при ожидании допуска,17 при keyframe/sensor resync, приняты только30–31; оба результата после конца короткого source window,143.881/155.743ms. Все пропуски учтены, но availability/latency/result-before-EOF gates не пройдены.78 clock samples,28 ready; условная uncertainty median5.312ms при неизменном пределе5ms. Peak VRAM2365MiB — не свидетельство предела24GiB. Более ранняя попытка вернула30 exact результатов, но имела2 compute discards и EOF error; её нельзя выдавать за финальный PASS. [Отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_CROSSHOST_GRAPH_2026-09-02.md), код `35b6cd9`, evidence198 artifacts/manifest `7b435cac111b3e0e789aa137ba064651e6d344a5f8fb8fa35b0abbd0e7cb1d74`.
@@ -14,7 +18,7 @@ CPU-only Mac↔Worker006 proof:72/72 timestamp-наблюдения незави
Граница доказательства: два контейнера одного Worker с проверенным общим Linux monotonic clock, временные штатные частоты2610/10251MHz; **не Mac↔Worker full-graph, не radio/live и не standalone**. История зависимых слоёв после gap закономерно отличается от uninterrupted reference. Все230 опубликованных scene/масок проверены на стороне приёмника и повторно сверены. [Подробный отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_NETWORK_2026-09-02.md). Evidence236 artifacts: `.runtime/perception-stage2-network-graph-20260902T1541Z/manifest.json`, SHA-256 `d1bc7e26850a2d9050ee1d8f8a5ece2e6b8c53e2e7dba381cbd4445d68a5ec17`.
Следующий проверяемый результат этапа2: отделить двусторонний clock warmup от фиксации source anchor, подтвердить готовность и Mac, и Worker до старта1×; текущий фиксированный2s lead этого не доказывает. После старта clock не переносить, backlog не догонять. Снять raw probe/ack timings, получить стабильный короткий canary; затем controlled cross-host gap/slow-consumer и standalone image без developer/model mounts. Начальный retry bounded pilots не является production recovery service. Продуктовый LAB path не переключён; этапы3–4 не начаты. GPU/clocks после последовательных замеров восстановлены, Ollama/Frigate exited/restart=no, временные контейнеры/volumes/listener/key/bootstrap удалены. Mac8000 и Worker telemetry работают.
Следующий проверяемый результат этапа2: CPU-only attribution/A/B задержек clock/control loop при передаче/приёме scene; отделить application scheduling от транспортного участка, затем оптимизировать подтверждённую причину. Стартовый барьер реализован; сам по себе он не сделал clock readiness стабильным. Увеличение числа samples в прежних2s не устраняет наблюдённый WAIT даже offline. Пороги5ms/125ms и source1× не ослаблять, source clock после старта не переносить, backlog не догонять. После стабильного короткого full-graph canary — controlled cross-host gap/slow-consumer, длинный поток и standalone без developer/model mounts. Новая длительная GPU-нагрузка на проваленном baseline не запускалась. Этапы34/registry/UI cutover не открыты. Временные контейнеры/lease/collector/tunnel18561/key/bootstrap удалены, сервисы и GPU auto mode восстановлены; Ollama/Frigate exited/restart=no. Mac8000/Worker telemetry работают.
Предыдущий инкремент12 (`0310592`, `1916122`): CPU-only gRPC/TLS proof Mac↔Worker,16/16 payload/reply; синтетический source clock и CPU sentinel, моделей0. Same-Mac RTT14.360/23.919/120.815ms min/median/max — не one-way age/FPS.105 local и20 Worker tests PASS, проверены bounded slow-reader/quarantine. Evidence `.runtime/perception-stage2-grpc-20260902T1500Z/manifest.json`, SHA-256 `adf5eaf092feaed6721f66e2adaceded0cdbf55754e1f9953f54623bfb52d331`.
@@ -245,6 +249,8 @@ EoMT — семейство ViT-моделей сегментации изобр
## Progress
- 2026-09-02 21:12 МСК: `48835a0`, инкремент16. Joint startup PASS; 1× source начинается с0, anchor принят обеими сторонами. Full canary8/32 FAIL: compute discard6, source WAIT715, sync1629, результаты05/3031. Raw receipt exact8/8; до EOF6, полностью fresh5. Clock exchanges55/55 пересчитаны, readiness41/55; running uncertainty5.0315.667ms, host telemetry33/33 без ошибок. Lease1/4PID пережили WAIT, после End всё освобождено.241 local/198 Worker PASS;129 source hashes.53 artifacts/manifest `9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`. Следующий gate — CPU-only control/data scheduling attribution, не ещё один слепой GPU retry.
- 2026-09-02 20:37 МСК: `35b6cd9`, инкремент15. Full Mac↔Worker graph использует acknowledged clock bounds, uncertainty для слоёв/ячеек, WAIT и immutable source anchor. Исправлены EOF ordering, repeated clock read и ранний disconnect до OPEN;297 local/173 Worker/12 repeated reconnect PASS. Финальный canary2/32,13 source WAIT+17 sync skips, оба результата после EOF,143.881/155.743ms; real-time FAIL, пороги не ослаблены. Следующий пункт — совместный pre-start clock readiness обеих сторон, затем короткий повтор. Все попытки сохранены;198 artifacts, manifest `7b435cac111b3e0e789aa137ba064651e6d344a5f8fb8fa35b0abbd0e7cb1d74`. Temporary resources удалены, leases released, stock-clock lock снят, четыре сервиса восстановлены,8000/telemetry работают. Этап2 остаётся открытым, stages3–4 не начаты.
- 2026-09-02 19:42 МСК: `d7b8989`, инкремент14. TLS Poll выдаёт pending grant с activation binding без GPU/model authority; four-timestamp mapping с conditional500ppm/50us envelope,16 samples/expiry2s. CPU-only Mac↔Worker:72 probes,60 внутри5ms,8/8 exact echoes, gap2.202s сохраняет PID9/lease1 и22 локальных renewal. Mapping истёк и восстановился; readiness менялась также после warmup.252 local PASS/2 Worker-only skips,65 Worker PASS; Ruff/mypy PASS.81 source hashes сверены; manifest18 artifacts SHA-256 `cd479c577fa3da78b1b01a6a90e03e8c742ecb53561e606d939408120a53a622`. Full-graph mapping/freshness integration остаётся впереди; модели не запускались. Временные ресурсы/секреты удалены, owner released,8000 и телеметрия работают. Старый perception-worker self-restart26→27 зафиксирован, не объявлен исправленным.
@@ -296,6 +302,8 @@ EoMT — семейство ViT-моделей сегментации изобр
## Surprises / открытые вопросы
- Инкремент16: согласованный старт и отсутствие RPC errors не означают непрерывную готовность часов. Running bounds вышли за5ms без GPU/owner failure; это условная uncertainty при500ppm budget, не измеренный физический drift. Offline добавление всех probes в прежних2s всё ещё даёт FAIL на тех же девяти samples. Для следующего изменения нужен timing trace scheduling/control/data, а не автоматическое расширение history или бюджета.
- 2026-09-02 13:55 → 14:22 МСК: два старых range_m расхождения 1.3877787807814457e-17 m воспроизведены и исправлены. Quaternion начинался на byte 24 общего pose buffer; адрес 8 mod 16 менял norm на один ULP в текущем NumPy runtime. Offsets 0/16/32/48 возвращают reference, 8/24/40/56 точно воспроизводят оба отклонения. Теперь quaternion — отдельная immutable 32-byte копия с проверенным 16-byte alignment; формулы и comparator прежние. Полный граф подтвердил 128/128 exact дважды. Это квалификация numeric layout текущего pinned runtime, не универсальное обещание bitwise равенства на любом CPU/NumPy.
- Четыре удалённые full-frame copies дают небольшой измеримый эффект в IPC, не объясняют разницу 192→91 ms. При одинаковых фиксированных частотах контроль тоже проходил 125-ms gate до оптимизации. Новый p95 колеблется внутри межпрогонного разброса; p99 немного ниже в обоих повторах. CPU-only кандидат имел native-decode outlier и худший total p99, хотя IPC-minus-decode снизился; отрицательный результат сохранён. Автоматический runtime не должен обещать fixed-clock qualification без фактического envelope и не должен сам менять host clocks без отдельной authority.
- В том же запуске auto memory clocks переходят 10,251 → 405–810 MHz. По последнему 0.5-s sample перед receipt high/low cohorts имеют p95 88.269/172.079 ms (39/89 кадров). Это корреляция внутри одного прогона, не controlled A/B и не отдельная qualification. Общий p95/p99 161.974/191.806 ms остаётся FAIL. Decoder p95/p99 10.871/11.606 ms, RPC+bundle 18.053/38.991 ms, очередь 44.284/84.492 ms, DDRNet RPC 73.068/77.479 ms; CPU throttled delta=0. Нельзя приписать всю разницу с предыдущими 124.98/136.12 ms новому транспорту или сделать вывод об исчерпании 24 GiB VRAM.
@@ -352,6 +360,6 @@ EoMT — семейство ViT-моделей сегментации изобр
## Outcomes / retrospective
Этап1 завершён; этап2 продолжается. Инкремент15 подключил continuous WAIT/resync/uncertainty к полному Mac↔Worker graph и дал отрицательный canary:2/32 после ожидания допуска и синхронизации, без неучтённых потерь.297 local/173 Worker tests и12 повторных early-reconnect cases PASS; исправлены конкретные ошибки clock assessment, EOF и early disconnect. Нужен двусторонний pre-start readiness barrier, затем повторный короткий full-graph canary и только после него gap/slow-consumer/standalone. Прежние same-Worker128/128 и gap результаты сохраняют свои границы, не заменяют межмашинную квалификацию. Native-host GPU inventory и физический radio/live не квалифицированы; batch/registry/UI и этапы34 не начаты, actuation=false. Mac8000/telemetry работают,8765/temporary18561 закрыты, Ollama/Frigate exited/restart=no. Временные контейнеры/секреты удалены, owned leases released, четыре сервиса восстановлены; прежние service defects не объявлены исправленными.
Этап1 завершён; этап2 продолжается. Инкремент16 закрыл двусторонний pre-start handshake и сохранил начало записи в настоящем full-graph запуске. Непрерывный real-time пока не принят:8/32, один input-gap discard,9 WAIT+14 sync skips, p95/p99 215.767ms.55 полных clock exchanges пересчитаны независимо: WAIT вызван превышением условной5ms uncertainty, не GPU telemetry/owner loss. Нужна CPU-only диагностика scheduling/transport и оптимизация подтверждённой причины, затем короткая полная перепроверка.241 local/198 Worker tests PASS;129 source hashes,53 artifacts. Одна GPU-проба без повторов. Исторические same-Worker128/128 не заменяют cross-host qualification; standalone/native-host inventory/radio/live не квалифицированы. Batch/registry/UI и этапы34 не начаты, actuation=false. Mac8000/telemetry работают,8765/temporary18561 закрыты, Ollama/Frigate exited/restart=no. Временные ресурсы удалены, lease released, четыре точных service IDs и GPU auto mode восстановлены; прежние service defects не объявлены исправленными.
После этапа 4 здесь будут перечислены digest самостоятельного полного образа, измеренные статусы и ошибки по recordings, реально проверенные source/hardware/config комбинации, состояние сохранённого EoMT-варианта и оставшиеся physical-live/quality/vehicle-integration ограничения. Готовый Docker и готовая автономия не отождествляются.
@@ -869,3 +869,21 @@ and a fixed2s lead do not establish Worker readiness. Next gate separates two-si
clock warmup from source-anchor activation before1x starts; after start the source
timeline remains immutable through outages. No gate widening, backlog replay,
standalone or Stage3 promotion. [Evidence and rejected attempts](../../experiments/perception/PERCEPTION_STREAM_STAGE2_CROSSHOST_GRAPH_2026-09-02.md).
## Stage 2 increment 16: joint startup before immutable 1x activation (2026-09-02)
Pre-start clock reports carry a null anchor and warm both observation windows.
Version2 replies bind responder bounds and accepted anchor to the issued challenge.
Source checks both current intervals, ages peer evidence through ACK transit, obtains
explicit anchor acceptance and a data grant before startup. A lost ACK cannot create
a different anchor; missing the agreed start fails rather than silently retiming input.
The existing5ms/2s/500ppm/50us budgets and lease/data authority separation remain intact.
The single32-frame GPU canary now admits frame0, but is not realtime-qualified:
8 results,1 input-gap discard,9 WAIT and14 synchronization skips. All55 six-timestamp
exchanges independently reconstruct; running uncertainty5.0315.667ms causes a real
clock WAIT without an RPC error, GPU telemetry loss or model restart. More samples
inside the same2s horizon would not remove the measured WAIT.241 local/198 Worker
tests PASS,129 measured source hashes match code48835a0. Next investigate control-loop
scheduling/transport before another full-graph qualification, without budget widening.
[Detailed evidence](../../experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md).
@@ -0,0 +1,123 @@
# Stage 2 increment 16 — joint source activation and measured clock WAIT
2026-09-02, 21:12 MSK. Code `48835a0`. **Joint startup PASS; full real-time canary FAIL.**
Stage 2 remains open; no Stage 3/4 cutover, standalone release or actuation.
## Change and invariants
Clock warmup no longer starts the recording. The Mac acknowledges every issued probe,
including pre-start probes with a null source anchor. Worker accumulates responder
evidence and returns typed bounds plus its accepted anchor. Both sides must satisfy
the current clock gate before proposing a start; Worker must explicitly accept it.
Mac additionally waits for the pending data grant before returning from startup.
ReportClock uses closed `missioncore.stream-clock-report/v2` and
`missioncore.stream-clock-receipt/v2` documents; legacy/malformed responses fail closed.
Nanoseconds, including signed clock offsets, remain exact canonical decimal strings.
Client checks activation, nonce, clock identities, envelope and accepted anchor.
Peer bounds are aged to the latest possible Worker time at source use, including ACK
transit; a cached readiness boolean cannot authorize a later observation.
The one-second lead is only for bounded grant delivery/setup AFTER joint readiness.
Lost ACK retains the exact same proposal because Worker may already have accepted it.
Explicit nonacceptance permits another pre-start proposal; an accepted anchor never
changes. Missing the accepted start fails startup rather than retiming the recording.
Source input paths are checked before clock activation. Receipt diagnostics retain
bounded raw t1t6, with one evaluation timestamp per reported readiness snapshot.
Unchanged: 1x original source clock, every-frame candidate, <=16MiB tracked inputs,
two pending cameras, serialized GPU, 125ms p95/p99 whole-path gate, <=5ms conditional
clock uncertainty, 500ppm relative-rate budget, 50us timestamp-error budget, 2s expiry
and 16 recent samples. These are conditional assumptions, not a measurement that the
physical clocks actually drift by 500ppm. WAIT preserves models/local ownership;
resync discards backlog and requires a new epoch/keyframe/current sensors.
## One full-graph canary
Session `.runtime/perception-stage2-joint-start-20260902T1805Z`, run `joint32-worker`.
Actual source start 18:04:32.831227Z; session ID is an identifier, not the run timestamp.
Mac incrementally reads the existing raw recording and receives real scene/mask payloads;
Worker006 runs DDRNet-39 GOOSE, RF-DETR, LiDAR/distance, motion, TRAVEL TGS/costmap/policy.
Model container has no recording mount. One GPU profile, 8 CPUs/8GiB, temporary
2610/10251MHz stock-clock reference, unchanged 450W. No alternate model run or retry.
Pinned dependency image plus developer/model mounts remains **not standalone**.
Transport is gRPC/TLS through SSH/Tailscale, not a measured rover radio/onboard link.
| Original camera sequences | Observed outcome |
| --- | --- |
| 05 | Six results; initial camera/keyframe and sensor prefix admitted |
| 6 | Accepted, then explicitly discarded as `input-gap` |
| 715 | Nine source WAIT skips |
| 1629 | Fourteen synchronization skips while waiting for a fresh keyframe/sensor pair |
| 3031 | Two results after recovery; both arrive after the short source window ends |
Ledger: 32 released =8 results +1 compute discard +9 WAIT skips +14 sync skips.
No unaccounted frame, reply drop, source error or control/data RPC error. Source remains
1x; release-lag p95/p99 3.062/17.286ms, max36.725ms. Joint startup admitted frame0,
unlike increment15's final attempt; this does not establish continuous availability.
Eight Worker/Mac scene payloads are byte-exact; all masks, detections, material,
lineage and sensor bindings match the uninterrupted reference. Geometry/tracks/threats
and raw TGS state match on the six pre-gap results, not on the two post-resync results:
their temporal history was intentionally reset. Do not claim eight uninterrupted
full-graph reference matches. Five received scenes are fully fresh; six arrive before EOF.
Same-Mac source-due → consumer-ready: min101.345ms, median144.951ms,
p95/p99/max215.767ms, n=8. This tiny failing sample is not a stable throughput estimate.
DDRNet GPU-model mean12.895ms, detector mean12.862ms; these are component intervals,
not end-to-end latency or evidence of spare realtime capacity. Peak sampled VRAM2363MiB,
cgroup3341.08MiB, Mac source RSS61,767,680B, tracked inputs12,055,035B, reply419,194B.
The result does not indicate exhaustion of24GiB GPU memory.
## Independently reconstructed clock evidence
All55 exchanges retained t1(source send), t2/t3(Worker receive/send), t4(source receipt),
t5(Worker receipt of report), t6(source ACK return). Independent integer calculations
reproduce BOTH published interval windows and all55 readiness decisions;41 are ready.
The sole accepted source anchor and a ready observation precede initial data connect.
After startup, source samples2735 are unavailable: uncertainty5.0315.667ms at the
unchanged5ms limit. Sample36 returns to4.867ms. Worker continuous WAIT lasts864.139ms;
keyframe recovery magnifies the resulting output gap. Source uncertainty min/median/max
4.217/4.620/32.053ms includes initial warmup; the maximum is not running-source drift.
Probe-cycle min/median/max8.420/13.991/101.253ms; report/ACK-cycle7.392/13.269/104.500ms.
These intervals include application scheduling and cannot alone attribute delay to
radio, TCP, SSH, gRPC or event-loop contention.
An offline diagnostic retaining EVERY sample within the same2s horizon also exceeds
5ms throughout these nine unavailable samples. Increasing the16-sample count alone
would not remove this WAIT in the trace. No runtime window/threshold was changed.
Worker host-control observations33/33 accepted, no expiry or envelope violations;
the observed WAIT was clock admission, not missing GPU telemetry or owner loss.
Two input epochs retain lease generation1 and resident PIDs11/40/48/49. Recovery clears
temporal stores with all children alive; final orderly completion releases all resources.
## Validation, evidence and next gate
241 focused local tests PASS,2 Worker-only cases skipped locally;198 Worker CPU tests
PASS, including real TLS joint startup, malformed/legacy receipts, lost accepted-anchor
ACK, one-sided/stale bounds, missing grant, unchanged anchor after recovery and existing
ingress/lifecycle/backpressure cases. Ruff/check-format and typed clock modules mypy PASS.
129 measured Python source files match the local committed code and code-v2 archive.
Code-v1 CPU evidence remains retained; v2 only makes diagnostic readiness use its
recorded timestamp. Only v2 ran the GPU canary.
Archive SHA256 `52e9778cdd54aab33b9e347081ae67ebcc53968773717b9c708174381f2d6eed`.
53 retained artifacts; manifest SHA256
`9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`.
`verify.py`, `verify_clocks.py`, `clock-reconstruction.json`, `review.json` and
`acceptance.json` reproduce receipt accounting, freshness, timing and closed resources.
Next: CPU-only attribution/A/B of clock/control scheduling versus concurrent scene
transfer/receipt work, preserving the existing route and admission budgets. Determine
what is application scheduling and what is transport; then optimize the proven cause.
Do not add artificial outages or start a long GPU qualification on this failing baseline.
After a stable short full-graph canary: controlled gap/slow-consumer, longer runs and
standalone packaging within Stage2. Product integration stays in later stages.
Temporary model/test containers, collector, lease volume, tunnel18561, key/bootstrap
are gone; owner released, four exact prior service IDs restored, Triton200, Telegraf
Running. Clock-lock reset commands succeeded; subsequent automatic210/405MHz observed,
450W unchanged. Ollama/Frigate remain exited/restart=no. Canonical Mac8000 PID33360 and
identity-matched Worker telemetry work;8765 absent. Existing legacy-service defects
are not declared fixed. No K1, motor, autonomous-driving or external/Synology deployment.