Conversation
Move route_a.sh, its supervisor, sampler and a static release-flag checker into tools/route_a/, with every machine path in a git-ignored route_a.env (example committed). The release stage now stages telemetry by default: a wrapper fetches the HF token with agent-secret at exec time, so it never reaches the stage config, argv or logs. ROUTE_A_STAGING=0 restores --no-staging. Every gate, refusal and the published: false hand-off are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…n engine-free CI The engine-free job syncs without extras, so psutil (already locked, via the US extra) was missing and the wrapper-isolation test, which runs the real supervisor, failed at import. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adding psutil to the dev group moved uv.lock, which the Primary-QRF worker identity pins (APPROVED_UV_LOCK_SHA256), so every stacked-spine test refused the lock. Revert that. The engine-free test now runs the wrapper directly under bash -x and reads the child's argv with ps, so it needs no psutil and still checks exec (same pid). The real-supervisor version moves to engine_workflow/us, whose job installs psutil through the US extra. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Until now the Route A driver lived only on the build machine, and its release passed
--no-staging. Pavel asked for both to change (2026-10-05). This PR:tools/route_a/;What moved (
tools/route_a/):route_a.sh: the driver. Every machine path now comes from a settings file. The settings file isroute_a.env, which is git-ignored, or the fileROUTE_A_ENVnames;route_a.env.exampleis committed.supervise.py: copied unchanged. It does admission, the RSS, wall and CPU limits, and the DISK_FLOOR kill, and writesRESULT.json. The driver writesACCEPTEDonce it accepts a result.sample_series.py: the resource sampler. It's unchanged apart fromdatetime.UTC, for lint.check_flags.py: replaces the driver's grep-for-a-quoted-flag check. It checks the release flags against the release parser's literaladd_argumentdeclarations without importing the tool, and those flags now include any inRELEASE_EXTRA_ARGS.with_hf_token.sh: fetches the HF token at exec time (below).README.md: configuration, the stages and their gates, the published run's exact release argv, the Modal-base hand-off, and what the Build progress tab shows.What changed: staging.
With
ROUTE_A_STAGING=1(the default), the release runs underwith_hf_token.sh <agent-secret> <release argv>. The wrapper:agent-secret get HUGGING_FACE_TOKEN_MAX, refusing if the lookup fails or returns an empty value;HF_TOKEN, thenexecs the release.The driver writes
release-config.jsonbefore the supervisor launches anything, so the config records only the wrapper and helper paths.ROUTE_A_STAGING=0restores--no-staging, strips the HF variables and never calls the helper.Any other value of
ROUTE_A_STAGINGis refused, and so is--no-staginginsideRELEASE_EXTRA_ARGS.The base, prefetch, both gate preflights and the publisher preflight behave as before; the preflights still strip secrets and run with the Hub offline.
Unchanged:
--preflight-only, and thepublished: falsehand-off;6840b990…, 18,991,218 bytes);4b57d15a2release and its run directory are untouched.Invariants (tested)
tools/build_us_fiscal_refresh_release.py's parser, with staging on and off and with the example's extra arguments.--no-stagingis in the release argv if and only ifROUTE_A_STAGING=0. The wrapper is the launcher if and only ifROUTE_A_STAGING=1.set -xand through the helper's stderr.RELEASE_EXTRA_ARGSrefusals still fire, including the--flag=valueforms the old matcher missed.tools/route_a/contains a/Users/path or a token-shaped string.bash -nand shellcheck.Tests
pytest packages/microcosm-build/tests/engine_free/us/test_route_a_driver.py packages/microcosm-build/tests/engine_workflow/us/test_route_a_supervisor_secrets.py: 25 passed, run locally against this branch's sources. Droppingexecfrom the wrapper, or echoing the token, fails both secret tests.ruff checkandruff format --checkpass on the new files, and shellcheck passes.tools/ci_test_plan.py verifypasses; the module is in the engine-free US group.exec, leaking the token through argv orset -x, accepting an empty lookup, adding an undeclared flag, and flipping each staging mode.Judgment calls
RUN_ROOTis a fresh directory, because an existingbase-sup/ACCEPTEDskips the base stage. PointingLADDERat the CT ladder alone would not rebuild an accepted base.--resolve. It keeps its old exit behavior: commit blockers are logged but don't on their own make it exit non-zero.stat -f).psutil, which the engine-free job doesn't install. Adding it to the dev group would moveuv.lock, which the Primary-QRF worker identity pins (APPROVED_UV_LOCK_SHA256), so the test is split instead anduv.lockis untouched. The engine-free test runs the wrapper directly underbash -xand reads the child's argv withps.engine_workflow/us/test_route_a_supervisor_secrets.pyruns the same check through the real supervisor in the US engine job, which haspsutilthrough the US extra.Requested by Pavel Makarchuk. Related: microcosm#1082, which keeps staging on for every build; reviewed separately.
🤖 Generated with Claude Code