Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
dd22e8f
feat(byof): add LIBERO B200 qualification
timothy-le7 Sep 10, 2026
674d7bd
feat(byof): register LIBERO qualification gate
timothy-le7 Sep 10, 2026
895d7db
Fix LIBERO BYOF live preflight contracts
timothy-le7 Sep 11, 2026
e0a4166
Preserve sanitized private prune receipts
timothy-le7 Sep 11, 2026
2f4b285
Bind LIBERO source metadata schema
timothy-le7 Sep 11, 2026
1e7e626
Isolate LIBERO payload attestation RBAC
timothy-le7 Sep 11, 2026
7af9fb0
Keep private prune paths out of image history
timothy-le7 Sep 11, 2026
a5ac94c
fix(byof): poll submitted scheduler job id
timothy-le7 Sep 11, 2026
340a034
fix(byof): harden SkyPilot image bootstrap
timothy-le7 Sep 11, 2026
663e5b5
Fix BYOF bootstrap security fixture
timothy-le7 Sep 11, 2026
9340b60
Refresh BYOF Linux headers during image build
timothy-le7 Sep 11, 2026
4eb4a47
Harden LIBERO qualification evidence
timothy-le7 Sep 11, 2026
0eaa51f
Harden LIBERO managed cleanup
timothy-le7 Sep 11, 2026
6e75bda
Freeze LIBERO scheduler state identity
timothy-le7 Sep 11, 2026
ab02b30
Fail closed on LIBERO cleanup ambiguity
timothy-le7 Sep 11, 2026
227b015
Validate LIBERO cleanup identities early
timothy-le7 Sep 11, 2026
da67b78
Require verified LIBERO cleanup evidence
timothy-le7 Sep 11, 2026
15ff0f6
Close LIBERO cleanup proof gaps
timothy-le7 Sep 11, 2026
648d91e
Close LIBERO verifier fail-closed gaps
timothy-le7 Sep 11, 2026
73b106f
Keep LIBERO recovery within approved scope
timothy-le7 Sep 11, 2026
cf6ab0e
Bind LIBERO immutable qualification inputs
timothy-le7 Sep 12, 2026
0526498
Keep LIBERO prechecks fail closed
timothy-le7 Sep 12, 2026
68ba0a7
Fail closed when LIBERO execution is skipped
timothy-le7 Sep 12, 2026
8504c3b
feat(byof): add quarantined LIBERO neutral bootstrap
timothy-le7 Sep 12, 2026
dae65cf
fix(byof): close LIBERO runtime dependency metadata
timothy-le7 Sep 12, 2026
09916f5
fix(byof): bind LIBERO publication proof
timothy-le7 Sep 12, 2026
51315fe
fix(byof): harden LIBERO public boundaries
timothy-le7 Sep 12, 2026
44e48f9
fix(byof): bind LIBERO cold fetch receipt
timothy-le7 Sep 12, 2026
b41b87f
fix(byof): close LIBERO public byte proof
timothy-le7 Sep 12, 2026
4b90b87
fix(byof): close LIBERO public proof gaps
timothy-le7 Sep 12, 2026
b7f744b
fix(byof): harden LIBERO bootstrap boundaries
timothy-le7 Sep 12, 2026
4ff7510
fix(byof): clean failed LIBERO cache publication
timothy-le7 Sep 12, 2026
c2ac29d
fix(byof): unify LIBERO cache publication cleanup
timothy-le7 Sep 12, 2026
c1a116f
fix(byof): normalize LIBERO bootstrap build bytes
timothy-le7 Sep 12, 2026
1f939e3
fix(libero): scan modern OCI neutral images
timothy-le7 Sep 12, 2026
e8d5b09
fix(libero): close neutral qualification boundaries
timothy-le7 Sep 12, 2026
1dcf060
test(libero): bind native scanner Python version
timothy-le7 Sep 12, 2026
be0b122
chore(libero): keep scanner test repair scoped
timothy-le7 Sep 12, 2026
db11f56
fix(libero): scan auxiliary OCI image bytes
timothy-le7 Sep 12, 2026
2d4e8e9
test(libero): cover recursive OCI refusals
timothy-le7 Sep 12, 2026
732953f
fix(libero): close publication and runtime lineage
timothy-le7 Sep 12, 2026
b0b9e9d
fix(libero): complete publication and runtime hardening
timothy-le7 Sep 12, 2026
aed92f1
Fix LIBERO review findings with external trust
timothy-le7 Sep 12, 2026
d3c7594
Harden LIBERO authorization and cleanup
timothy-le7 Sep 12, 2026
0cbd069
Bind LIBERO qualification enforcement lineage
timothy-le7 Sep 12, 2026
80aa4a4
Fix LIBERO output signing and payload rechecks
timothy-le7 Sep 12, 2026
091a312
Scope LIBERO pod access to exact workload
timothy-le7 Sep 12, 2026
ba28bb5
Close LIBERO trust and RBAC review gaps
timothy-le7 Sep 12, 2026
f1cdb8d
Close remaining LIBERO review findings
timothy-le7 Sep 13, 2026
9274396
Refresh LIBERO repaired byte contracts
timothy-le7 Sep 13, 2026
0be6eed
Keep publication mutation lock selector-independent
timothy-le7 Sep 13, 2026
df76cd6
Seal LIBERO output evidence owner-only
timothy-le7 Sep 13, 2026
75c413d
Close final LIBERO cleanup review gaps
timothy-le7 Sep 13, 2026
fd4797e
Close exact-range LIBERO review findings
timothy-le7 Sep 13, 2026
87a6572
Require pinned public registry login action
timothy-le7 Sep 13, 2026
c14d147
Harden LIBERO cleanup recovery coverage
timothy-le7 Sep 13, 2026
3686177
Bind LIBERO authorization to exact execution
timothy-le7 Sep 13, 2026
4149b6d
Preserve LIBERO bootstrap receipt across execution
timothy-le7 Sep 13, 2026
c2951f6
Bind LIBERO output and attestation controls
timothy-le7 Sep 13, 2026
99ff83b
Preserve NCore attestation compatibility
timothy-le7 Sep 13, 2026
fa7270d
Close LIBERO execution and evidence gaps
timothy-le7 Sep 13, 2026
426c6fc
Close LIBERO review security findings
timothy-le7 Sep 13, 2026
0026549
Keep BYOF verifier importable by script loaders
timothy-le7 Sep 13, 2026
c436dbe
Close LIBERO publication review findings
timothy-le7 Sep 13, 2026
491427d
Refresh LIBERO readiness runtime hash
timothy-le7 Sep 13, 2026
9497f37
Fix LIBERO pre-submit cleanup transition
timothy-le7 Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
834 changes: 772 additions & 62 deletions .github/workflows/publish-public-images.yml

Large diffs are not rendered by default.

299 changes: 299 additions & 0 deletions docs/workbench/byof-libero.md

Large diffs are not rendered by default.

22 changes: 16 additions & 6 deletions docs/workbench/container-image-catalog.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,12 +46,13 @@ uses `sim2real-eval/Dockerfile`, and `reference-policy` is a derived EnvGen
image. Build sources, eligibility, publication, and functional validation are
separate claims.

The current source inventory, including the pending NCore integration, has
**37 packaging entries** (35 redistribution-eligible and two restricted) and
**38 mapped tools**: 32 public-release members, two restricted tools, and four
quarantined tools (`curobo`, `ncore`, `openpi`, and `robocasa`). These counts come
from `packaging-contract.yaml` and `npa.deploy.images`; they do not constitute
a new registry audit or acceptance of the quarantined images.
The current source inventory, including the pending NCore and LIBERO
integrations, has **38 packaging entries** (36 redistribution-eligible and two
restricted) and **39 mapped tools**: 32 public-release members, two restricted
tools, and five quarantined tools (`curobo`, `libero`, `ncore`, `openpi`, and
`robocasa`). These counts come from `packaging-contract.yaml` and
`npa.deploy.images`; they do not constitute a new registry audit or acceptance
of the quarantined images.

LeRobot 0.6.0 is selectable package support with an accepted optional public
image. The resolver uses the additive `0.6.0-d6-extras-20260912` tag and exact
Expand Down Expand Up @@ -302,6 +303,15 @@ historical evidence.

## Intentionally not published as separate images

- **LIBERO** now has an unbuilt, quarantined public-neutral-bootstrap design,
not a supported or published NPA image. The planned bytes contain only a
digest-pinned Python/Debian base, snapshot-locked bootstrap packages, NPA
code, and immutable manifests—no LIBERO, GPU runtime, model, demonstration,
task/render asset, cache, checkpoint, credential, or output. A future trusted
build needs complete-byte, published-base-provenance, anonymous-pull, and
exact-digest B200 acceptance before any public-table row or release claim.
Historical private r15 bytes do not establish equivalence. See the
[LIBERO qualification contract](byof-libero.md).
- **`npa-cosmos3-nano-video`** extends the digest-pinned upstream
`vllm/vllm-omni:cosmos3` image with Ray Serve, measured chunked video rollouts,
and source-aligned edge-transfer augmentation with verified S3 recovery.
Expand Down
15 changes: 15 additions & 0 deletions docs/workbench/contributing-a-containerized-solution.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ npa/.venv/bin/npa workbench byof run \
--repo-ref "<immutable-ref>" \
--base-profile ubuntu \
--workload solution-smoke \
--source-prune-path '<unused-restricted-source-subtree>' \
--build-command '<pinned-install-command>' \
--smoke-command '<real-capability-command>' \
--solution-name "<solution>" \
Expand All @@ -64,6 +65,20 @@ npa/.venv/bin/npa workbench byof run \
--skip-push --skip-run --dry-run --output json
```

Omit `--source-prune-path` when every source byte is allowed in the private
image. When a headless qualification must exclude one render-only subtree, the
option removes that validated repository-relative path and the Git object
database in the same clone layer, then records the observed commit and prune
receipt in `npa_source_metadata.json`. Deleting files later in `--build-command`
does not remove their bytes from an earlier image layer.

For a private source, that receipt preserves only placeholders, SHA-256 values,
and removal booleans; it never copies the private repository URL, ref, observed
commit, or prune path into reusable metadata. The prune path travels to
BuildKit through an owner-only secret mount, is part of command-output
redaction, and appears in the CLI summary only as a placeholder plus SHA-256;
it is never a plain build argument or image-history value.

For a first-class image, add or update:

- `npa/docker/workbench/<tool>/Dockerfile` and preferably `build.sh`;
Expand Down
1 change: 1 addition & 0 deletions docs/workbench/image-gpu-compatibility-matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,7 @@ likewise predates its current coherent release.
| `npa-ltx2` | unverified runtime | unverified runtime | **verified** [accepted records](#accepted-release-evidence) | unverified runtime | unverified runtime |
| `npa-openpi` | blocked (RTX-only runtime contract) | blocked (RTX-only runtime contract) | pending exact-digest full-DROID qualification | blocked (`sm_120`-only probe/runtime contract) | blocked (`sm_120`-only probe/runtime contract) |
| `npa-curobo` | unbuilt; not validated | unbuilt; not validated | unbuilt; not validated | unbuilt; not validated | unbuilt; not validated |
| `npa-libero` (publication-quarantined neutral bootstrap) | pending build; unverified | pending build; unverified | pending build; unverified | pending build; unverified | pending build; unverified |
| `npa-alpamayo2-super` | supported | supported | **verified** [63] | **verified** [62] | supported (same-major `sm_100` coverage; not measured) |
| `npa-cosmos3-reason` | supported | **verified** [38] | **verified** [43] | **verified** [36] | **verified** [37] |
| `npa-cosmos2-transfer` | supported | supported | supported | **historical evidence** [9] | blocked (cu128 NVRTC cannot JIT `sm_103`) |
Expand Down
2 changes: 1 addition & 1 deletion docs/workbench/npa-workflow-tool-catalog.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ accidental dead entries fail the guardrail. The retired monolithic
| `workbench.sonic.eval` | `npa workbench sonic eval` | `config.onnx_uri` (local path or `s3://`), `config.episodes`, `config.env` | `config.eval_uri` | no |
| `workbench.sim2real_envgen.raw_shard` | `python -m npa.workflows.sim2real_envgen raw-shard` | `config.raw_envs_uri`, `config.env_count` | raw env manifest on S3 | no |
| `workbench.sim2real.write_decision` | demo decision writer | `config.decision_uri`, `config.default_decision` | threshold decision JSON | no |
| `workbench.byof.repo` | `npa workbench byof run` | `config.repo_url`, `config.repo_ref`, `config.base_profile`, optional `config.repo_auth` (defaults to `none`) / `config.repo_token_env` (defaults to empty), `config.build_command` / `config.smoke_command`; private GitHub tokens are forwarded separately with `--secret-env`; registry candidates also set `config.solution_name`, `config.capability_name`, `config.smoke_artifact_name` | BYOF summary, dataset/checkpoint artifacts, solution smoke artifact | no |
| `workbench.byof.repo` | `npa workbench byof run` | `config.repo_url`, `config.repo_ref`, `config.base_profile`, optional `config.repo_auth` (defaults to `none`) / `config.repo_token_env` (defaults to empty), optional same-layer `config.source_prune_path`, `config.build_command` / `config.smoke_command`; private GitHub tokens are forwarded separately with `--secret-env`; registry candidates also set `config.solution_name`, `config.capability_name`, `config.smoke_artifact_name`; the quarantined LIBERO prebuilt path additionally requires an explicit immutable `config.libero_acceptance_candidate_image` and owner-private `config.libero_runtime_use_decision_file`, while its expected decision/build-lineage hashes come only from the checked-in acceptance record | BYOF summary, dataset/checkpoint artifacts, solution smoke artifact | no |
| `workbench.isaac_lab.byof_repo` | alias → `workbench.byof.repo` | same as BYOF | same as BYOF | no |
| `workbench.openpi.negative_terms_gate` | `python -m npa.workflows.byof.openpi_pipeline negative-gate` | digest-pinned OpenPI image; runtime-only scoped terms secret in the parent | attempt-scoped exit-64 child diagnostic with untouched success URI, followed by accepted same-URI retry | no |
| `workbench.openpi.prepare_data` | `python -m npa.workflows.byof.openpi_pipeline prepare-data` | configurable sample counts and seed | deterministic NPZ plus hashed, disjoint train/held-out manifest | no |
Expand Down
46 changes: 46 additions & 0 deletions docs/workbench/oss-solution-catalog.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ unique and must be tested with its own upstream-named capabilities.

| Candidate | Pinned source | Primary (hard-gate) capability | Artifact | NPA workflow |
| --- | --- | --- | --- | --- |
| LIBERO | `Lifelong-Robot-Learning/LIBERO` `8f1084e3…` | `libero_spatial_bc_rnn_train_reload_heldout` | `libero-smoke.json` + reloaded checkpoint | `byof-libero.yaml` |
| ManiSkill | `mani-skill/ManiSkill` `v3.0.1` | `gymnasium_pickcube_registration` | `maniskill_pickcube_step.json` | `byof-maniskill.yaml` |
| MuJoCo Playground | `google-deepmind/mujoco_playground` `v0.2.0` | `mjx_cartpole_step` (+ CheetahRun) | `mujoco_playground_cartpole_step.json` | `byof-mujoco-playground.yaml` |
| RoboCasa | `robocasa/robocasa` `v1.0` | `kitchen_task_registration` | `robocasa_kitchen_env_reset.json` | `byof-robocasa.yaml` |
Expand All @@ -32,6 +33,7 @@ unique and must be tested with its own upstream-named capabilities.

| Solution | Capability | Live status | Run / evidence |
| --- | --- | --- | --- |
| LIBERO | `libero_spatial_bc_rnn_train_reload_heldout` | **qualification pending; public-neutral candidate quarantined/unbuilt** | Requires complete-byte and anonymous-pull proof followed by one STRICT-bound B200 run of the exact candidate digest: eight upstream BC-RNN/AdamW steps on the official LIBERO-Spatial demonstration, checkpoint reload, and full trajectory-disjoint held-out evaluation |
| ManiSkill | `gymnasium_pickcube_registration` | **accepted** | `defcap-maniskill-20260708-230227` (81 `-v1` envs) |
| ManiSkill | `pickcube_cpu_step` / `pickcube_parallel_envs` / `pickcube_gpu_rgb_render` | **accepted** | `defcap11-maniskill-20260709-043408` (sapien 3.0.3 on CUDA Ubuntu22.04/py3.10; Blackwell render OK) |
| MuJoCo Playground | `mjx_cartpole_step` | **accepted** | `defcap8-mujoco-playground-20260709-024455` (+ prior `…-005745`) |
Expand Down Expand Up @@ -65,6 +67,50 @@ unique and must be tested with its own upstream-named capabilities.

## Native Capabilities Per Container

### LIBERO

Pinned runtime source: `Lifelong-Robot-Learning/LIBERO`
`8f1084e3132a39270c3a13ebe37270a43ece2a01` (MIT). The narrow admission
candidate runtime-fetches one official `libero_spatial` demonstration from
`yifengzhu-hf/LIBERO-datasets@f13aa24a3da8c43c7225569f28c562979fa0e35a`
and verifies its 508,779,600 bytes against SHA-256
`ff6f26121653c77280eb40a38773a74141c11a8509f3466058cb56dd2cc60ead`.
The upstream LIBERO publisher declares its datasets CC BY 4.0; the mirror card's
conflicting Apache-2.0 tag is not used to broaden rights.
Task conditioning runtime-fetches the independently pinned Apache-2.0
`google-bert/bert-base-cased@cd5ef92a9fb2f889e972770a36d4ed042daf221e`
files and runs the pinned upstream LIBERO `AutoTokenizer`/`AutoModel`
`pooler_output` path. Neither those model bytes nor the demonstration is baked.
The public-neutral candidate also bakes no LIBERO, robomimic, MuJoCo, PyTorch,
CUDA/NVIDIA runtime, task/render asset, populated cache, checkpoint, credential,
or output byte. It remains unbuilt, absent from the release manifest and public
image table, and quarantined until byte, provenance, anonymous-pull, and live
acceptance. Historical private r15 bytes are old-head evidence only.
The trusted public workflow also refuses before a LIBERO build unless the
manager supplies the separately accepted private-stage complete-image
inventory hash and OCI config digest. Its scanner binds every byte in each
ordered uncompressed layer tar plus every canonical flattened-rootfs record,
and requires the candidate to match both identities; finite payload signatures
are only defense in depth.

| Capability | Status | Upstream basis |
| --- | --- | --- |
| `libero_official_demo_sha256` | qualification pending | Exact official HDF5 mirror revision, byte size, SHA-256, 50 trajectories, 5,068 samples, task language, BDDL, and initial-state hashes |
| `libero_upstream_bert_task_conditioning` | qualification pending | Exact Apache-2.0 BERT revision and file hashes, pinned LIBERO embedding-source hash, and finite 768-dimensional upstream `pooler_output` |
| `libero_trajectory_disjoint_heldout_split` | qualification pending | Deterministic 40-train / 10-held-out trajectory split; no trajectory may appear in both partitions |
| `libero_spatial_bc_rnn_train_reload_heldout` | hard gate, qualification pending | Upstream BERT task conditioning plus `Sequential.observe` + `BCRNNPolicy` + AdamW for eight nonzero optimizer steps, strict upstream checkpoint reload, held-out NLL, and finite reloaded 7-DoF action predictions on exactly one B200 (`sm_100`) |

An authorized runtime sparse-fetch retains the hash-bound BDDL and initial
states but never fetches the unused render-asset tree. The official
demonstration is fetched into a manifest-addressed cache outside the artifact
directory and is never baked or uploaded. A missing or mismatched manager-issued
use decision refuses before cache or network mutation; runtime fetch is delivery,
not permission. Acceptance
requires the Pod-observed immutable image digest in `libero-smoke.json`; imports,
BDDL parsing, dataset inventory, or zero-step training do not pass. Rendered
closed-loop sweeps, all 130 tasks, lifelong-algorithm comparison, and physical
robots remain deferred. See [`byof-libero.md`](byof-libero.md).

### ManiSkill

| Capability | Status | Upstream basis |
Expand Down
10 changes: 10 additions & 0 deletions npa/docker/workbench/blackwell-dc-images.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,16 @@
"validation": "not-required",
"notes": "CPU-only COLMAP ingestion and NCore V4 reader; no Torch, CUDA or GPU architecture assertion. Public release remains quarantined pending exact-image scans and complete capture conversion evidence. NRE reconstruction is a separate RTX-only downstream image."
},
{
"name": "npa-libero",
"dockerfile": "libero/Dockerfile",
"build_script": "libero/build.sh",
"verdict": "unknown",
"validation": "pending-build",
"redistribution": "public",
"smoke": "Run the headless official LIBERO demonstration gate on one B200: real upstream BC-RNN Adam steps, strict checkpoint reload, trajectory-disjoint held-out loss and action predictions, and exact image and GPU evidence.",
"notes": "The current neutral-bootstrap candidate remains unbuilt, quarantined, and unvalidated. It contains no LIBERO source, GPU runtime, model, demonstration, task asset, cache, checkpoint, credential, or output payload. No datacenter Blackwell compatibility or public acceptance is claimed."
},
{
"name": "npa-cosmos3-nano-video",
"dockerfile": "cosmos3-nano-video/Dockerfile",
Expand Down
Loading
Loading