Skip to content

refactor(validator): make relay the only recurring SN39 posture - #157

Merged
wallscaler merged 2 commits into
mainfrom
codex/validator-docs-simplify-20260828
Aug 28, 2026
Merged

wallscaler merged 2 commits into
mainfrom
codex/validator-docs-simplify-20260828

Conversation

@wallscaler

@wallscaler wallscaler commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Outcome targets

  1. The signed HTTPS feed plus shadow provenance audit is the only recurring SN39 writer posture.
  2. A missing or invalid feed fails closed. It never escalates into a different writer.
  3. The bounded one-shot UID30 launch and finalized-attempt recovery remain available without becoming recurring authority modes.
  4. Operators have one supported SN39 profile, one origin publisher service, and one origin worker.
  5. Install verification is read-only with respect to wallets, vectors, validator execution, network calls, and chain state.
  6. Existing submission journals remain canonical. No reset, archive, re-anchor, or initialization helper is shipped.
  7. Documentation records the dated UID124 zero-burn proof and subnet emission zero without claiming TAO earnings.

What changed

  • Removed the authority and self-compose SN39 profiles.
  • Removed CLI, module, config, and environment selectors for recurring authority/full operation.
  • Removed feed-down fallback and the recurring authority tick implementation.
  • Made new recurring authorizations thin-only while retaining historical document verification.
  • Preserved bounded UID30 launch and finalized authority-labelled journal recovery.
  • Added a dedicated immutable-install verify mode that exits before validator execution.
  • Deleted the false active miner/validator launch-design page and unsafe provenance catch-up procedure.
  • Deleted alternate publisher service and environment assets.
  • Fixed the canonical origin service, Docker entrypoint, and console wrapper to one worker.
  • Added an idempotent legacy-unit retirement procedure with inactive and masked gates.
  • Updated README, validator, provenance, boundary, thin-runbook, and historical migration notes.
  • Added regression tests for the single recurring posture, launch recovery, operator docs, and one origin service.

Compatibility boundaries

  • Serialized authority lane values remain readable for bounded launch and historical recovery.
  • The one-shot UID30 launch writer remains intentionally available and hard-fenced.
  • No CyberGym mechanism, adapter, routing, scoring, or allocation behavior changed.
  • No live validator or publisher service was started.
  • No wallet was loaded and no chain transaction was submitted.

Verification

  • Merged head: c2e7e9a
  • Logical cleanup commit: d9a29ce
  • Reviewed base: b3277cf
  • Final exact diff SHA-256: 7c6ec8a9c806708fe4c996307d783bed80f81cc42c0e3274e792c5f9993821bc
  • Claude Fable reviewed logical diff SHA-256 1a6359556c99eea09dd5947675f7f0d2f4f5182822960f02494cf664db11715f with no P0, P1, or P2 findings.
  • The final two-test formatting delta was independently verified as AST-identical. All 18 affected tests passed. No P0, P1, or P2 findings remained.
  • Focused validator, recovery, authorization, operator-safety, and publisher tests: 346 passed.
  • Additional scoped review suites: 452 passed.
  • Ruff checks and git diff check: passed.
  • Broad local Mac run: 2,896 passed, 9 skipped. The remaining failures are existing host or suite-environment constraints, including BSD date behavior, the pinned Linux /usr/bin/python3.12 path, absent installed cathedral distribution metadata, sandbox cleanup, and cross-test publisher environment setup.
  • Full local collection also lacks the separate cathedral_distill package used only by the excluded CyberGym prelaunch test. This PR does not alter CyberGym.

Merge gate

Merge only when:

  • required GitHub Linux CI is green,
  • the reviewed commit SHA is unchanged,
  • no new P0, P1, or P2 review finding appears,
  • the diff still contains no CyberGym mechanism change.

Post-merge outcome

A validator operator sees one recurring SN39 path. A dead feed stops writes instead of switching modes. Historical launch recovery remains possible. Publisher deployment exposes one canonical service and one worker. Existing journals stay intact.


Note

High Risk
This changes mainnet weight-submission posture (removes recurring authority/self-compose and feed-down escalation) and publisher systemd layout, so mis-upgraded hosts could stop writing or run duplicate origins until legacy units are retired.

Overview
Makes the signed HTTPS shadow relay the only supported recurring SN39 writer. cathedral-validator serve now rejects non-shadow provenance and drops --mode / --provenance plus feed_down_fallback; a bad or missing feed fails closed with no escalation to independent recomputation. Authority-labelled paths stay internal for bounded UID30 launch and read-only journal recovery.

Operator and deploy surface is narrowed to one profile and one origin publisher. Removes authority/self-compose TOML profiles, MINER_VALIDATOR.md, provenance catch-up docs, and init-clean-journal.sh; documents the finalized UID124 launch vector and warns against blind --broadcast. Publisher packaging collapses to cathedral-scorer-sn39 with a fixed single worker; legacy publisher units/envs and journal-init helpers are deleted. Immutable install gains a read-only verify mode; liveness checks drop WAITING_FOR_JOB; new recurring authorizations are thin-lane only.

Reviewed by Cursor Bugbot for commit c2e7e9a. Bugbot is set up for automated code reviews on this repo. Configure here.

Make the signed-feed shadow relay the only recurring SN39 writer posture while preserving the bounded UID30 launch and finalized recovery contracts. Remove obsolete authority and self-compose profiles, feed-down escalation, unsafe journal reset guidance, and alternate publisher services. Add a no-write install verifier, enforce one origin worker, and document the dated UID124 zero-burn proof without claiming token earnings.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 28, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-28T22:48:03.490869Z d9a29ce PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cursor

cursor Bot commented Aug 28, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_017ab735-4757-4456-a4fd-4ab02128ad1e)

@cursor
cursor Bot requested a review from ai-hpc August 28, 2026 22:44
Python 3.11/3.12 failed on `ruff format --check` for the two new
thin-suite files. Wrap long lines only; no behavior change.

Co-authored-by: Ancient Runner  <wallscaler@users.noreply.github.com>
@cursor

cursor Bot commented Aug 28, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_511a92fa-05ed-4e4d-a8c0-f34a05ed9289)

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d9a29ce29d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scaffold/cli.py
Comment on lines +249 to +252
if isinstance(provenance, dict) and "feed_down_fallback" in provenance:
raise ValueError(
"[provenance].feed_down_fallback was removed; a missing feed now "
"always fails closed without changing submission authority"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Scope the retired-option rejection to validator startup

On an upgraded host whose existing TOML still contains [provenance].feed_down_fallback, this unconditional loader check also breaks cathedral-validator status: _cmd_status calls _resolve_serve_config, so it raises an uncaught ValueError before reading the journal, even though status is documented as journal-only and does not use this runtime option. Reject the retired key on serve/launch paths while allowing status to extract its journal and interval settings.

Useful? React with 👍 / 👎.

@wallscaler
wallscaler merged commit af234b3 into main Aug 28, 2026
7 checks passed
@wallscaler

Copy link
Copy Markdown
Contributor Author

Squash-merged #157 to main as af234b3e08cc34d92ed3f3312ca3099ea3176c39.

Exact-head CI on c2e7e9a:

  • Python 3.11: success
  • Python 3.12: success
  • Publisher suite: success
  • Integration lane: success

Honesty: relay/shadow is the only recurring SN39 posture; UID124 remains a dated zero-burn proof; no SN70 ownership; no Fast-as-TDX claim. CyberGym #146/#147, UID30 launch, wallets, and PolarIS prod were not touched.

@wallscaler

Copy link
Copy Markdown
Contributor Author

Post-merge live gate (source is on main as af234b3; this merge did not start a validator or publisher).

Do not cut over a live recurring writer until the signed HTTPS feed is actually answering. config/validator-thin-sn39-relay.toml pins https://api.cathedral.computer. That origin is still Cloudflare 522 (health, enroll, evidence, weights/next). Relay/shadow is now the only recurring posture: a dead feed fails closed. There is no authority/self-compose fallback anymore. Upgrading a live host onto af234b3 while the feed is down would stop writes.

When the feed is healthy:

  1. Retire and mask cathedral-publisher.service and cathedral-weight-feed-publish.service per deploy/publisher/README.md (inactive + masked, recovery copy under /etc/cathedral-publisher/retired-units). Install only cathedral-scorer-sn39.service at --workers 1. Do not start it until signing identity, DB, public-feed export, and allocation contract pass cutover checks. Leave CATHEDRAL_ALLOCATION_CONTRACT unset (v2).
  2. Recurring validator unit is cathedral-validator-sn39-relay + the thin relay profile only. Do not load the removed authority/self-compose profiles.
  3. Preserve journals. No --broadcast, --confirm-uid30-launch, --confirm-canary, serve_axon, or wallet load.

cathedral.computer catalog is unchanged (Fast Persistent Hetzner $0.15 available, no receipt; one-shot Fast off; Sealed live_testing; GPU unavailable). PolarIS prod stays source_sha=8e1dc3d / migration 080; PolarIS #1163 stays draft; do not roll alembic 081. CyberGym #146/#147 stay held. No SN70 claim.

Gathering facts here; not treating this as the final live state.

wallscaler added a commit that referenced this pull request Aug 28, 2026
Status ignores leftover [provenance].feed_down_fallback so it can read the journal. Serve, preflight-launch, and reconcile-launch still reject the retired key. A missing feed still fail-closes. Tiny follow-up to #157; not a reopen. No CyberGym, UID30, wallet, or live-writer changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants