Skip to content

feat(workbench): add robomimic BYOF training gate - #452

Draft
timothy-le7 wants to merge 48 commits into
mainfrom
codex/top5-robomimic
Draft

feat(workbench): add robomimic BYOF training gate#452
timothy-le7 wants to merge 48 commits into
mainfrom
codex/top5-robomimic

Conversation

@timothy-le7

@timothy-le7 timothy-le7 commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add a solution-pure, publication-quarantined robomimic BYOF candidate pinned to ARISE-Initiative/robomimic@d309eaecc18acf4152a830a895a6984b8ac71b05 under MIT.
  • Add a valid, planned npa.workflow/v0.0.1 path for real low-dimensional behavior-cloning optimization, a genuine held-out split, checkpoint save/reload, and one held-out action inference on exactly one STRICT-bound B200. No simulator or rendering path is added.
  • Package a deliberately neutral bootstrap on a digest-pinned official Python base. It is designed to contain only pinned MIT source, an exact Debian package closure, and a hash-locked non-CUDA Python closure. It excludes CUDA, cuDNN, NCCL, NVIDIA packages, PyTorch, Triton, pretrained weights, datasets, populated caches, credentials, checkpoints, and outputs.
  • Keep public/ordinary image resolution and non-plan execution fail closed. This PR is not image-byte, runtime, dataset, public-publication, or B200 acceptance evidence.

The exact reviewed range is origin/main@00eba8a4f7a81f152f27317188d5b9cd0b0b0306 through b786a6b5e6de09331469db299da45e2b4df54c34, tree 4180d2151d3a04667f890b999fd7ab0fe5f66391: 48 ordinary commits, zero merges, and 51/53 authorized paths with zero outside scope. The complete 557,314-byte full-index diff has SHA-256 3e78689f8ad0b25ef66090a9d29f855eafb5a6ea43600ef0320da869b8d69119; changed-path SHA-256 is 18331b0f5670a7a5b5a885ef1d5a57c8bacc1ac9cac439f7429015ec0e3a43ce. The three documentation paths landed through #469 are byte-identical to current main.

Immutable neutral inputs and six boundaries

  • Source: the manifest binds upstream commit d309eaecc18acf4152a830a895a6984b8ac71b05, Git tree 4c8ebe35dbef16126dadf59cf8b771b9203753ab, its MIT license, and a canonical 57,907,200-byte, 226-member archive with SHA-256 8dd695200bba3ca6043693a7db4b15713a740d5d6a91787984d4c0053f77fd8b. This is repository metadata, not current fetched-byte evidence.
  • Baked runtime: the proposed parent is exact python:3.11.16-slim-bookworm@sha256:528257d48c1da0dcecc2e725d1ae34498d60c965f1241e39cd6a85a8859bdf84, followed by a locked 78-package Debian closure and the preserved 40-distribution/214-hash non-CUDA Python lock. Build inputs are consumed fail closed without Git or APT network access. PyTorch source licensing is not treated as closure for CUDA-capable wheels or base binaries.
  • Weights: no pretrained weight is required, baked, or fetched. The deferred hard gate trains from initialization and emits a run-scoped checkpoint.
  • Data/assets: the official Lift proficient-human low-dimensional HDF5 is a later immutable runtime fetch at revision 74fa018461f479cd9fd15b924a16103012096203, accepted only at SHA-256 2067777cb8b532e9263dd09fd6448c41cc31224bb27be4a3b734010ae13eb540 and 21,084,088 bytes. No dataset bytes are baked or fetched here.
  • Runtime cache: the neutral bootstrap cannot fetch or populate CUDA/PyTorch. The dependent capability requires a separately authorized operator-built, read-only, exact-inventory runtime. Missing, corrupt, extra, escaping, or mismatched objects refuse before execution.
  • Outputs: checkpoints, logs, configs, metrics, and robomimic-smoke.json remain run-scoped and excluded from image/cache publication. Reserved JSON finalization now uses bounded no-follow reads and verified temporary regular files with atomic replacement; hostile symlink tests prove external targets remain unchanged.

This follows the merged runtime-fetch contract as a neutral bootstrap plus build-your-own dependent runtime. Runtime fetch, credentials, private registries, image selectors, populated caches, and environment flags affect delivery/configuration; none grants permission to use, redistribute, or provide a service with restricted bytes or outputs. There is no invented consent proxy.

Base security repair

The FiftyOne Dockerfile and its base-image vulnerability lane now select the identical immutable official Bookworm digest above. Anonymous official-registry manifest metadata also bound linux/amd64 to sha256:b1add8a6f2aca6bcfcf0b9c9b522352f7ce0d62a3d556a2f2f32511aa0cca250. This replaces the stale Trixie parent that current scanner metadata reported with three fixed critical perl-base findings; no waiver or allowlist was added. The FiftyOne skill now describes the pinned upstream mongod installation without tying optional wheel contents to a stale platform. No layer was pulled and no image was built merely to repair the base pin or its documentation.

Local validation

  • Repository interpreter: CPython 3.12.14.
  • Current repaired content: full robomimic workflow module 91/91; exact final hostile/profile/solution-smoke slice 32/32; failures 0. The preceding same-base code scope passed 600/600 core checks, 186/186 focused solution/image/workflow/guardrail checks, and 733/733 hostile-security checks. Those unaffected broad slices were not rerun after the two-path output-finalizer repair merely to relabel them.
  • Ruff over all npa, Python/YAML parsing, git diff --check, workflow validate, and JSON plan passed. The plan contains one workbench.byof.repo step, exactly B200:1, and two outputs; nothing was submitted.
  • Exact documentation reconciliation: the FiftyOne skill validator passed; 833/833 focused FiftyOne/image-workflow/skill/documentation tests passed; 21,724 non-E2E tests collected; generated docs are current; git diff --check passed.
  • Exact source-security comparison from the unchanged code head: base 677, candidate 677, regressions 0; summary SHA-256 66857a3c7f190742a41730b1a5e636a90df55d679387b2df7beee418f8547d2b. Built-in confidentiality on the final range: raw 0, dispositioned 0, unresolved 0. Gitleaks scanned all 48 commits with zero findings.
  • Scope and seal: clean, merge base equals current main, 48 single-parent commits, zero merges, 51 changed paths inside the 53-path authorization, zero outside.

All earlier-base reviews and CI are historical. Replacement PR CI is the broad current-head gate.

Independent reviews

  • Authenticated Claude Code inspected the complete exact diff using only Read/Grep/Glob: PASS, critical/high/major/medium findings 0, permission denials/writes/tests/scanners/network/subagents 0. It disclosed that Git identities were supplied because Bash was unavailable and retained one info note about the existing GPU field on a refusal-only golden-eval entry. Wrapper SHA-256: 459a5c02abb0ba0f84530946695ee1c16712ad4b2a9b5b441ca46717ad820d7b.
  • A distinct ephemeral read-only Codex verifier inspected all 51 paths and independently recomputed the Git/scope/mainline identities: PASS, findings 0 at every severity, permission denials/writes/tests/scanners/network/subagents 0. Result SHA-256: 77a4a1975d67adef2da97c8869080e50b40dc1d7390d9bdde7a8d893ce9866f7.

Byte and live status

No image was built, tagged, pulled, pushed, or inspected in this transaction. There is no current OCI digest, archive hash, SBOM/provenance, vulnerability/secret/malware result, flattened-rootfs proof, private-pull proof, or anonymous-public-pull proof. The candidate remains unbuilt, quarantined, and unvalidated.

CUDA/cuDNN/NCCL distribution, use, derivative, service, and output rights remain unresolved. No external runtime or dataset was fetched or used; no registry, storage, Kubernetes, SkyPilot, cloud, public workflow, or B200 action was performed. Public catalog acceptance, supported release, ready transition, merge, and auto-merge remain deferred.

After an authoritative human/vendor rights decision and separate live authorization, the hard gate must run the real upstream low-dimensional behavior-cloning stack on the official Lift proficient-human data, perform nonzero optimization with a genuine held-out split, save and reload the checkpoint, and produce exactly one held-out action inference on exactly one STRICT-bound B200. Image-policy sweeps, simulator rollouts, rendering, and the full algorithm matrix remain deferred.

Agent-run data collection is disabled because 0/2 exact required variables are present. No collection destination or environment value is exposed or invented.

@timothy-le7
timothy-le7 force-pushed the codex/top5-robomimic branch 5 times, most recently from d5d3ca6 to 3f58e44 Compare September 12, 2026 19:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant