Skip to content

reflex v0.2.4

Latest

Choose a tag to compare

@katopz katopz released this 03 Oct 09:39
edc3c99

reflex v0.2.4

The decision engine's fourth release. The headline: the shipped binary now serves YOUR corpus — point RIIR_REFLEX_CORPUS at a directory of markdown files and /decide answers in-corpus questions out of the box. Internal record ids are gone from the public wire, the game heads moved to a mint-your-own-vessels posture, and every archive carries the MIT licence text.

Serve your own corpus (RIIR_REFLEX_CORPUS) — new

RIIR_REFLEX_CORPUS=<dir> boots the engine on your corpus instead of the demo one:

  • One <domain>.md file (one document) or one <domain>/ directory of .md files (one document per file) per domain; domain names sort.
  • 1..=8 domains; over 8 refuses with the count (use the in-repo harness lane for larger corpora).
  • A malformed directory refuses the boot (exit 2, named reason) — a named corpus is never silently swapped for the demo engine.
  • /healthz discloses the posture: "corpus":"demo" or "corpus":{"domains":["billing","deploy","onboarding"]}.
  • The first-corpus posture is distance-gated: in-corpus questions answer with the engine's best pick; off-corpus questions abstain. (A first corpus is too thin to calibrate the confidence readout — measured — so the score axis stays open and the labeled-by-construction corpus-distance gate decides.) A sample corpus ships in the repo at examples/first_corpus/.

Breaking / behavior changes

  • Game heads are mint-only. v0.2.3 fitted the tetris/lanes/flappy heads from fixtures at boot; that boot fit is retired. Heads now load from SIGNED vessels only: reflex mint-heads --fixtures assets/game_heads --out <dir> --key-id <u32> --key <64-hex-seed>, then boot with RIIR_REFLEX_HEADS_DIR=<dir> and trust it via RIIR_REFLEX_HEADS_PUBKEY=<verifying key hex> (the mint command prints it). Out of the box the game boards abstain loudly and say so — nothing is fitted at serve time (bytes are runtime, capability is compile-time; no runtime minting).
  • Internal record ids are off the wire. The game-head routing.reason no longer carries Bench NNN-style ids (internal planning records, not wire vocabulary). A public-reason gate keeps the whole served-reason surface id-free.
  • Question-level wire violations are 422 (too few options, noul with options) — the agent skill's older 400 wording was wrong; fixed at the source.
  • /decide accepts an optional sidecar field (parsed and ignored on this lane — the widened-wire escape hatch for hybrid senders).
  • The unknown-lane error lists modelless, raw, laya, laya-ane.
  • noul probability tails shifted slightly (the route-term polarity fix and the option-name routing resolution) — same abstain posture, picks stable.

Licence

The binary is MIT (matching its public MIT source). Every archive carries LICENSE beside THIRD_PARTY_LICENSES.md.

Accuracy work (the harness board, not the served demo posture)

The published benchmark board's modelless lane closed most of its gap to the laya reference through four default-on levers: option-conditioned count tables (typed +13.5 pt), the NBSVM closed-form ridge readout (emotion +11 pt), count-table scopes (ag_news −44 → −7.5), and gate-fit-on-the-calibrated-scale. These are harness-posture selections; the served demo/corpus engine keeps its documented default knobs. The six synthetic harness decision-point families were retired entirely (owner call) — the wide template-disjoint eval measured them at chance, and semantic_defects replaces them as the standing code-defect family.

New comparison lanes (measurement, never the product lane)

The arena grew honest third-party lanes over their own wire: PAW (ProgramAsWeights), GLiNER2.5-Decide, AgentJev, OpenThai-SystemOne, bekko, the clef local-MLX rig, and a distill-teacher seam (--distill-teacher openthai|bekko) for training-side consumption. Every lane is opt-in and off by default; the product binary serves the modelless engine.

Under the hood

  • Laya Metal lane: batched heads, a simdgroup GEMM trio, packed-QKV fused flash attention (kill-switch LAYA_METAL_FLASH=0), split-K epilogue folds, MPS dispatch for dense batch-1 GEMMs, head-drain deferral — 9/9 suite p50 AND p99 wins vs the torch reference on the M3, G5 parity green at every step (drift ≤ 1e-3 gate, measured ≤ 6e-6).
  • The CubeCL portable backend and the CUDA backend ride behind their own opt-in features.
  • Determinism: same-corpus repeat answers byte-identical (the wire capture asserts it against the release binary).

Gates this release ran: full CI guard (9 layers, PASSED) on the tagged tree; G2 latency p99 44 µs (ceiling 1000 µs) + G4 alloc-free core, both PASS with the box state quoted — PROVENANCE: power=AC load=5.27 powermode=2(high) canary=113.9us/best5, preflight PASSED; G5 laya parity green (CPU + Metal); wire capture + copy gate on reflex.gist.rs.

Disclosed: the darwin binaries embed two id-shaped strings (Issue 020, Plan 616) inside the Metal kernel source's COMMENTS (the laya lane ships MSL source strings; Metal ignores comments). They are never served on any route — wire-inert, page-inert — and the same class shipped in v0.2.3. They live in the laya substrate crate and are stripped there, not patched here.

SHA256SUMS covers every archive; the leak scan (no symbol tables, no machine paths, no secret-shaped strings) passed on all five binaries.