diff --git a/docs/OBSERVATORY_REALTIME_PROFILES_EXECPLAN.md b/docs/OBSERVATORY_REALTIME_PROFILES_EXECPLAN.md index 127f669..cbfdec9 100644 --- a/docs/OBSERVATORY_REALTIME_PROFILES_EXECPLAN.md +++ b/docs/OBSERVATORY_REALTIME_PROFILES_EXECPLAN.md @@ -1,6 +1,10 @@ # Observatory: четыре этапа создания полного real-time Perception-профиля -Дата: 2026-09-01; обновлено 2026-09-02 20:37 МСК. **Этап 1 закрыт; этап 2 в работе. Инкремент 15: полный Mac↔Worker graph подключён к continuous clock/freshness; canary FAIL.** Добавлены ответное подтверждение часов Worker, immutable source anchor, uncertainty для всех слоёв/ячеек и WAIT без потери локального владельца. Исправлены EOF ordering, повторное чтение часов внутри одного результата и ранний disconnect до application OPEN.297 local/173 Worker tests PASS; ранний reconnect дополнительно12/12 PASS. +Дата: 2026-09-01; обновлено 2026-09-02 21:12 МСК. **Этап1 закрыт; этап2 продолжается. Инкремент16: двусторонний старт принят, непрерывный real-time canary FAIL.** Код `48835a0`: обе стороны прогревают часы до source anchor; явное подтверждение Worker и data grant обязательны до старта1×. Потерянный ACK не меняет уже предложенный/принятый anchor.241 local/198 Worker tests PASS,2 Worker-only skip локально;129 измеренных source hashes совпадают. + +Один32-кадровый canary теперь принял начало0–5 и после WAIT/resync30–31:8 результатов,1 compute discard,9 source WAIT и14 sync skips, без неучтённых кадров. p95/p99 до consumer-ready215.767ms,5 полных свежих scene,6 результатов до EOF. Все55 raw t1–t6 обменов независимо пересчитаны;41 ready. На работающем источнике uncertainty5.031–5.667ms превысила неизменные5ms; RPC errors0, Worker telemetry33/33 PASS, lease1/PIDs сохранены. PeakVRAM2363MiB, не предел24GiB. [Отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md),53 artifacts, manifest `9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`. + +Предыдущий инкремент15: полный Mac↔Worker graph подключён к continuous clock/freshness; прежний canary FAIL. Добавлены ответное подтверждение часов Worker, immutable source anchor, uncertainty для всех слоёв/ячеек и WAIT без потери локального владельца. Исправлены EOF ordering, повторное чтение часов внутри одного результата и ранний disconnect до application OPEN.297 local/173 Worker tests PASS; ранний reconnect дополнительно12/12 PASS. Финальный32-кадровый1× canary:13 кадров пропущены при ожидании допуска,17 при keyframe/sensor resync, приняты только30–31; оба результата после конца короткого source window,143.881/155.743ms. Все пропуски учтены, но availability/latency/result-before-EOF gates не пройдены.78 clock samples,28 ready; условная uncertainty median5.312ms при неизменном пределе5ms. Peak VRAM2365MiB — не свидетельство предела24GiB. Более ранняя попытка вернула30 exact результатов, но имела2 compute discards и EOF error; её нельзя выдавать за финальный PASS. [Отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_CROSSHOST_GRAPH_2026-09-02.md), код `35b6cd9`, evidence198 artifacts/manifest `7b435cac111b3e0e789aa137ba064651e6d344a5f8fb8fa35b0abbd0e7cb1d74`. @@ -14,7 +18,7 @@ CPU-only Mac↔Worker006 proof:72/72 timestamp-наблюдения незави Граница доказательства: два контейнера одного Worker с проверенным общим Linux monotonic clock, временные штатные частоты2610/10251MHz; **не Mac↔Worker full-graph, не radio/live и не standalone**. История зависимых слоёв после gap закономерно отличается от uninterrupted reference. Все230 опубликованных scene/масок проверены на стороне приёмника и повторно сверены. [Подробный отчёт](../experiments/perception/PERCEPTION_STREAM_STAGE2_NETWORK_2026-09-02.md). Evidence236 artifacts: `.runtime/perception-stage2-network-graph-20260902T1541Z/manifest.json`, SHA-256 `d1bc7e26850a2d9050ee1d8f8a5ece2e6b8c53e2e7dba381cbd4445d68a5ec17`. -Следующий проверяемый результат этапа2: отделить двусторонний clock warmup от фиксации source anchor, подтвердить готовность и Mac, и Worker до старта1×; текущий фиксированный2s lead этого не доказывает. После старта clock не переносить, backlog не догонять. Снять raw probe/ack timings, получить стабильный короткий canary; затем controlled cross-host gap/slow-consumer и standalone image без developer/model mounts. Начальный retry bounded pilots не является production recovery service. Продуктовый LAB path не переключён; этапы3–4 не начаты. GPU/clocks после последовательных замеров восстановлены, Ollama/Frigate exited/restart=no, временные контейнеры/volumes/listener/key/bootstrap удалены. Mac8000 и Worker telemetry работают. +Следующий проверяемый результат этапа2: CPU-only attribution/A/B задержек clock/control loop при передаче/приёме scene; отделить application scheduling от транспортного участка, затем оптимизировать подтверждённую причину. Стартовый барьер реализован; сам по себе он не сделал clock readiness стабильным. Увеличение числа samples в прежних2s не устраняет наблюдённый WAIT даже offline. Пороги5ms/125ms и source1× не ослаблять, source clock после старта не переносить, backlog не догонять. После стабильного короткого full-graph canary — controlled cross-host gap/slow-consumer, длинный поток и standalone без developer/model mounts. Новая длительная GPU-нагрузка на проваленном baseline не запускалась. Этапы3–4/registry/UI cutover не открыты. Временные контейнеры/lease/collector/tunnel18561/key/bootstrap удалены, сервисы и GPU auto mode восстановлены; Ollama/Frigate exited/restart=no. Mac8000/Worker telemetry работают. Предыдущий инкремент12 (`0310592`, `1916122`): CPU-only gRPC/TLS proof Mac↔Worker,16/16 payload/reply; синтетический source clock и CPU sentinel, моделей0. Same-Mac RTT14.360/23.919/120.815ms min/median/max — не one-way age/FPS.105 local и20 Worker tests PASS, проверены bounded slow-reader/quarantine. Evidence `.runtime/perception-stage2-grpc-20260902T1500Z/manifest.json`, SHA-256 `adf5eaf092feaed6721f66e2adaceded0cdbf55754e1f9953f54623bfb52d331`. @@ -245,6 +249,8 @@ EoMT — семейство ViT-моделей сегментации изобр ## Progress +- 2026-09-02 21:12 МСК: `48835a0`, инкремент16. Joint startup PASS; 1× source начинается с0, anchor принят обеими сторонами. Full canary8/32 FAIL: compute discard6, source WAIT7–15, sync16–29, результаты0–5/30–31. Raw receipt exact8/8; до EOF6, полностью fresh5. Clock exchanges55/55 пересчитаны, readiness41/55; running uncertainty5.031–5.667ms, host telemetry33/33 без ошибок. Lease1/4PID пережили WAIT, после End всё освобождено.241 local/198 Worker PASS;129 source hashes.53 artifacts/manifest `9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`. Следующий gate — CPU-only control/data scheduling attribution, не ещё один слепой GPU retry. + - 2026-09-02 20:37 МСК: `35b6cd9`, инкремент15. Full Mac↔Worker graph использует acknowledged clock bounds, uncertainty для слоёв/ячеек, WAIT и immutable source anchor. Исправлены EOF ordering, repeated clock read и ранний disconnect до OPEN;297 local/173 Worker/12 repeated reconnect PASS. Финальный canary2/32,13 source WAIT+17 sync skips, оба результата после EOF,143.881/155.743ms; real-time FAIL, пороги не ослаблены. Следующий пункт — совместный pre-start clock readiness обеих сторон, затем короткий повтор. Все попытки сохранены;198 artifacts, manifest `7b435cac111b3e0e789aa137ba064651e6d344a5f8fb8fa35b0abbd0e7cb1d74`. Temporary resources удалены, leases released, stock-clock lock снят, четыре сервиса восстановлены,8000/telemetry работают. Этап2 остаётся открытым, stages3–4 не начаты. - 2026-09-02 19:42 МСК: `d7b8989`, инкремент14. TLS Poll выдаёт pending grant с activation binding без GPU/model authority; four-timestamp mapping с conditional500ppm/50us envelope,16 samples/expiry2s. CPU-only Mac↔Worker:72 probes,60 внутри5ms,8/8 exact echoes, gap2.202s сохраняет PID9/lease1 и22 локальных renewal. Mapping истёк и восстановился; readiness менялась также после warmup.252 local PASS/2 Worker-only skips,65 Worker PASS; Ruff/mypy PASS.81 source hashes сверены; manifest18 artifacts SHA-256 `cd479c577fa3da78b1b01a6a90e03e8c742ecb53561e606d939408120a53a622`. Full-graph mapping/freshness integration остаётся впереди; модели не запускались. Временные ресурсы/секреты удалены, owner released,8000 и телеметрия работают. Старый perception-worker self-restart26→27 зафиксирован, не объявлен исправленным. @@ -296,6 +302,8 @@ EoMT — семейство ViT-моделей сегментации изобр ## Surprises / открытые вопросы +- Инкремент16: согласованный старт и отсутствие RPC errors не означают непрерывную готовность часов. Running bounds вышли за5ms без GPU/owner failure; это условная uncertainty при500ppm budget, не измеренный физический drift. Offline добавление всех probes в прежних2s всё ещё даёт FAIL на тех же девяти samples. Для следующего изменения нужен timing trace scheduling/control/data, а не автоматическое расширение history или бюджета. + - 2026-09-02 13:55 → 14:22 МСК: два старых range_m расхождения 1.3877787807814457e-17 m воспроизведены и исправлены. Quaternion начинался на byte 24 общего pose buffer; адрес 8 mod 16 менял norm на один ULP в текущем NumPy runtime. Offsets 0/16/32/48 возвращают reference, 8/24/40/56 точно воспроизводят оба отклонения. Теперь quaternion — отдельная immutable 32-byte копия с проверенным 16-byte alignment; формулы и comparator прежние. Полный граф подтвердил 128/128 exact дважды. Это квалификация numeric layout текущего pinned runtime, не универсальное обещание bitwise равенства на любом CPU/NumPy. - Четыре удалённые full-frame copies дают небольшой измеримый эффект в IPC, не объясняют разницу 192→91 ms. При одинаковых фиксированных частотах контроль тоже проходил 125-ms gate до оптимизации. Новый p95 колеблется внутри межпрогонного разброса; p99 немного ниже в обоих повторах. CPU-only кандидат имел native-decode outlier и худший total p99, хотя IPC-minus-decode снизился; отрицательный результат сохранён. Автоматический runtime не должен обещать fixed-clock qualification без фактического envelope и не должен сам менять host clocks без отдельной authority. - В том же запуске auto memory clocks переходят 10,251 → 405–810 MHz. По последнему 0.5-s sample перед receipt high/low cohorts имеют p95 88.269/172.079 ms (39/89 кадров). Это корреляция внутри одного прогона, не controlled A/B и не отдельная qualification. Общий p95/p99 161.974/191.806 ms остаётся FAIL. Decoder p95/p99 10.871/11.606 ms, RPC+bundle 18.053/38.991 ms, очередь 44.284/84.492 ms, DDRNet RPC 73.068/77.479 ms; CPU throttled delta=0. Нельзя приписать всю разницу с предыдущими 124.98/136.12 ms новому транспорту или сделать вывод об исчерпании 24 GiB VRAM. @@ -352,6 +360,6 @@ EoMT — семейство ViT-моделей сегментации изобр ## Outcomes / retrospective -Этап1 завершён; этап2 продолжается. Инкремент15 подключил continuous WAIT/resync/uncertainty к полному Mac↔Worker graph и дал отрицательный canary:2/32 после ожидания допуска и синхронизации, без неучтённых потерь.297 local/173 Worker tests и12 повторных early-reconnect cases PASS; исправлены конкретные ошибки clock assessment, EOF и early disconnect. Нужен двусторонний pre-start readiness barrier, затем повторный короткий full-graph canary и только после него gap/slow-consumer/standalone. Прежние same-Worker128/128 и gap результаты сохраняют свои границы, не заменяют межмашинную квалификацию. Native-host GPU inventory и физический radio/live не квалифицированы; batch/registry/UI и этапы3–4 не начаты, actuation=false. Mac8000/telemetry работают,8765/temporary18561 закрыты, Ollama/Frigate exited/restart=no. Временные контейнеры/секреты удалены, owned leases released, четыре сервиса восстановлены; прежние service defects не объявлены исправленными. +Этап1 завершён; этап2 продолжается. Инкремент16 закрыл двусторонний pre-start handshake и сохранил начало записи в настоящем full-graph запуске. Непрерывный real-time пока не принят:8/32, один input-gap discard,9 WAIT+14 sync skips, p95/p99 215.767ms.55 полных clock exchanges пересчитаны независимо: WAIT вызван превышением условной5ms uncertainty, не GPU telemetry/owner loss. Нужна CPU-only диагностика scheduling/transport и оптимизация подтверждённой причины, затем короткая полная перепроверка.241 local/198 Worker tests PASS;129 source hashes,53 artifacts. Одна GPU-проба без повторов. Исторические same-Worker128/128 не заменяют cross-host qualification; standalone/native-host inventory/radio/live не квалифицированы. Batch/registry/UI и этапы3–4 не начаты, actuation=false. Mac8000/telemetry работают,8765/temporary18561 закрыты, Ollama/Frigate exited/restart=no. Временные ресурсы удалены, lease released, четыре точных service IDs и GPU auto mode восстановлены; прежние service defects не объявлены исправленными. После этапа 4 здесь будут перечислены digest самостоятельного полного образа, измеренные статусы и ошибки по recordings, реально проверенные source/hardware/config комбинации, состояние сохранённого EoMT-варианта и оставшиеся physical-live/quality/vehicle-integration ограничения. Готовый Docker и готовая автономия не отождествляются. diff --git a/docs/adr/0049-stream-first-perception-profiles.md b/docs/adr/0049-stream-first-perception-profiles.md index efcf7f5..f9e1246 100644 --- a/docs/adr/0049-stream-first-perception-profiles.md +++ b/docs/adr/0049-stream-first-perception-profiles.md @@ -869,3 +869,21 @@ and a fixed2s lead do not establish Worker readiness. Next gate separates two-si clock warmup from source-anchor activation before1x starts; after start the source timeline remains immutable through outages. No gate widening, backlog replay, standalone or Stage3 promotion. [Evidence and rejected attempts](../../experiments/perception/PERCEPTION_STREAM_STAGE2_CROSSHOST_GRAPH_2026-09-02.md). + +## Stage 2 increment 16: joint startup before immutable 1x activation (2026-09-02) + +Pre-start clock reports carry a null anchor and warm both observation windows. +Version2 replies bind responder bounds and accepted anchor to the issued challenge. +Source checks both current intervals, ages peer evidence through ACK transit, obtains +explicit anchor acceptance and a data grant before startup. A lost ACK cannot create +a different anchor; missing the agreed start fails rather than silently retiming input. +The existing5ms/2s/500ppm/50us budgets and lease/data authority separation remain intact. + +The single32-frame GPU canary now admits frame0, but is not realtime-qualified: +8 results,1 input-gap discard,9 WAIT and14 synchronization skips. All55 six-timestamp +exchanges independently reconstruct; running uncertainty5.031–5.667ms causes a real +clock WAIT without an RPC error, GPU telemetry loss or model restart. More samples +inside the same2s horizon would not remove the measured WAIT.241 local/198 Worker +tests PASS,129 measured source hashes match code48835a0. Next investigate control-loop +scheduling/transport before another full-graph qualification, without budget widening. +[Detailed evidence](../../experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md). diff --git a/experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md b/experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md new file mode 100644 index 0000000..aca37ef --- /dev/null +++ b/experiments/perception/PERCEPTION_STREAM_STAGE2_JOINT_START_2026-09-02.md @@ -0,0 +1,123 @@ +# Stage 2 increment 16 — joint source activation and measured clock WAIT + +2026-09-02, 21:12 MSK. Code `48835a0`. **Joint startup PASS; full real-time canary FAIL.** +Stage 2 remains open; no Stage 3/4 cutover, standalone release or actuation. + +## Change and invariants + +Clock warmup no longer starts the recording. The Mac acknowledges every issued probe, +including pre-start probes with a null source anchor. Worker accumulates responder +evidence and returns typed bounds plus its accepted anchor. Both sides must satisfy +the current clock gate before proposing a start; Worker must explicitly accept it. +Mac additionally waits for the pending data grant before returning from startup. + +ReportClock uses closed `missioncore.stream-clock-report/v2` and +`missioncore.stream-clock-receipt/v2` documents; legacy/malformed responses fail closed. +Nanoseconds, including signed clock offsets, remain exact canonical decimal strings. +Client checks activation, nonce, clock identities, envelope and accepted anchor. +Peer bounds are aged to the latest possible Worker time at source use, including ACK +transit; a cached readiness boolean cannot authorize a later observation. + +The one-second lead is only for bounded grant delivery/setup AFTER joint readiness. +Lost ACK retains the exact same proposal because Worker may already have accepted it. +Explicit nonacceptance permits another pre-start proposal; an accepted anchor never +changes. Missing the accepted start fails startup rather than retiming the recording. +Source input paths are checked before clock activation. Receipt diagnostics retain +bounded raw t1–t6, with one evaluation timestamp per reported readiness snapshot. + +Unchanged: 1x original source clock, every-frame candidate, <=16MiB tracked inputs, +two pending cameras, serialized GPU, 125ms p95/p99 whole-path gate, <=5ms conditional +clock uncertainty, 500ppm relative-rate budget, 50us timestamp-error budget, 2s expiry +and 16 recent samples. These are conditional assumptions, not a measurement that the +physical clocks actually drift by 500ppm. WAIT preserves models/local ownership; +resync discards backlog and requires a new epoch/keyframe/current sensors. + +## One full-graph canary + +Session `.runtime/perception-stage2-joint-start-20260902T1805Z`, run `joint32-worker`. +Actual source start 18:04:32.831227Z; session ID is an identifier, not the run timestamp. +Mac incrementally reads the existing raw recording and receives real scene/mask payloads; +Worker006 runs DDRNet-39 GOOSE, RF-DETR, LiDAR/distance, motion, TRAVEL TGS/costmap/policy. +Model container has no recording mount. One GPU profile, 8 CPUs/8GiB, temporary +2610/10251MHz stock-clock reference, unchanged 450W. No alternate model run or retry. +Pinned dependency image plus developer/model mounts remains **not standalone**. +Transport is gRPC/TLS through SSH/Tailscale, not a measured rover radio/onboard link. + +| Original camera sequences | Observed outcome | +| --- | --- | +| 0–5 | Six results; initial camera/keyframe and sensor prefix admitted | +| 6 | Accepted, then explicitly discarded as `input-gap` | +| 7–15 | Nine source WAIT skips | +| 16–29 | Fourteen synchronization skips while waiting for a fresh keyframe/sensor pair | +| 30–31 | Two results after recovery; both arrive after the short source window ends | + +Ledger: 32 released =8 results +1 compute discard +9 WAIT skips +14 sync skips. +No unaccounted frame, reply drop, source error or control/data RPC error. Source remains +1x; release-lag p95/p99 3.062/17.286ms, max36.725ms. Joint startup admitted frame0, +unlike increment15's final attempt; this does not establish continuous availability. + +Eight Worker/Mac scene payloads are byte-exact; all masks, detections, material, +lineage and sensor bindings match the uninterrupted reference. Geometry/tracks/threats +and raw TGS state match on the six pre-gap results, not on the two post-resync results: +their temporal history was intentionally reset. Do not claim eight uninterrupted +full-graph reference matches. Five received scenes are fully fresh; six arrive before EOF. + +Same-Mac source-due → consumer-ready: min101.345ms, median144.951ms, +p95/p99/max215.767ms, n=8. This tiny failing sample is not a stable throughput estimate. +DDRNet GPU-model mean12.895ms, detector mean12.862ms; these are component intervals, +not end-to-end latency or evidence of spare realtime capacity. Peak sampled VRAM2363MiB, +cgroup3341.08MiB, Mac source RSS61,767,680B, tracked inputs12,055,035B, reply419,194B. +The result does not indicate exhaustion of24GiB GPU memory. + +## Independently reconstructed clock evidence + +All55 exchanges retained t1(source send), t2/t3(Worker receive/send), t4(source receipt), +t5(Worker receipt of report), t6(source ACK return). Independent integer calculations +reproduce BOTH published interval windows and all55 readiness decisions;41 are ready. +The sole accepted source anchor and a ready observation precede initial data connect. + +After startup, source samples27–35 are unavailable: uncertainty5.031–5.667ms at the +unchanged5ms limit. Sample36 returns to4.867ms. Worker continuous WAIT lasts864.139ms; +keyframe recovery magnifies the resulting output gap. Source uncertainty min/median/max +4.217/4.620/32.053ms includes initial warmup; the maximum is not running-source drift. +Probe-cycle min/median/max8.420/13.991/101.253ms; report/ACK-cycle7.392/13.269/104.500ms. +These intervals include application scheduling and cannot alone attribute delay to +radio, TCP, SSH, gRPC or event-loop contention. + +An offline diagnostic retaining EVERY sample within the same2s horizon also exceeds +5ms throughout these nine unavailable samples. Increasing the16-sample count alone +would not remove this WAIT in the trace. No runtime window/threshold was changed. +Worker host-control observations33/33 accepted, no expiry or envelope violations; +the observed WAIT was clock admission, not missing GPU telemetry or owner loss. +Two input epochs retain lease generation1 and resident PIDs11/40/48/49. Recovery clears +temporal stores with all children alive; final orderly completion releases all resources. + +## Validation, evidence and next gate + +241 focused local tests PASS,2 Worker-only cases skipped locally;198 Worker CPU tests +PASS, including real TLS joint startup, malformed/legacy receipts, lost accepted-anchor +ACK, one-sided/stale bounds, missing grant, unchanged anchor after recovery and existing +ingress/lifecycle/backpressure cases. Ruff/check-format and typed clock modules mypy PASS. +129 measured Python source files match the local committed code and code-v2 archive. +Code-v1 CPU evidence remains retained; v2 only makes diagnostic readiness use its +recorded timestamp. Only v2 ran the GPU canary. + +Archive SHA256 `52e9778cdd54aab33b9e347081ae67ebcc53968773717b9c708174381f2d6eed`. +53 retained artifacts; manifest SHA256 +`9cb369fe7ae185d1a92f6050bc1018a878483f5eec169267f100843245428691`. +`verify.py`, `verify_clocks.py`, `clock-reconstruction.json`, `review.json` and +`acceptance.json` reproduce receipt accounting, freshness, timing and closed resources. + +Next: CPU-only attribution/A/B of clock/control scheduling versus concurrent scene +transfer/receipt work, preserving the existing route and admission budgets. Determine +what is application scheduling and what is transport; then optimize the proven cause. +Do not add artificial outages or start a long GPU qualification on this failing baseline. +After a stable short full-graph canary: controlled gap/slow-consumer, longer runs and +standalone packaging within Stage2. Product integration stays in later stages. + +Temporary model/test containers, collector, lease volume, tunnel18561, key/bootstrap +are gone; owner released, four exact prior service IDs restored, Triton200, Telegraf +Running. Clock-lock reset commands succeeded; subsequent automatic210/405MHz observed, +450W unchanged. Ollama/Frigate remain exited/restart=no. Canonical Mac8000 PID33360 and +identity-matched Worker telemetry work;8765 absent. Existing legacy-service defects +are not declared fixed. No K1, motor, autonomous-driving or external/Synology deployment.