← Complete research archive
Architecture researchPreregistered84 lines

PCF3: Ministral Publication Confirmation Successor

PCF1 and PCF2 remain immutable with formal result null. PCF1 failed before source access because Newton does not supply SLURM TMPDIR. PCF2 repaired and qualified allocation-local scratch, then CPU preparation stopped before atomic source publication because the generated-candidat…

docs/research/SHOHIN_PCF3_MINISTRAL_PUBLICATION_CONFIRMATION.mdOpen original Markdown ↗

PCF3: Ministral Publication Confirmation Successor

Status: prospectively frozen on 2026-08-11 before PCF3 remote mutation, reference admission, model load, source publication, or scientific compute.

Authorization and closed predecessors

PCF1 and PCF2 remain immutable with formal result null. PCF1 failed before source access because Newton does not supply SLURM_TMPDIR. PCF2 repaired and qualified allocation-local scratch, then CPU preparation stopped before atomic source publication because the generated-candidate capability grammar was incorrectly applied to a trusted, hash-pinned supervisor reference. PCF2 used no H100, did not load a model, did not train or generate, and did not publish or open the confirmation assessor. Jobs 751657--751684 never ran.

The user's standing explicit authorization to do everything necessary to achieve Shohin authorizes this separately named pre-science successor. PCF3 does not rewrite, retry, or relabel either predecessor.

Immutable scientific contract

PCF3 inherits every scientific term, byte, hash, host, source split, arm, prompt, seed, optimizer setting, update count, generation setting, threshold, sealed-data rule, and stop condition from SHOHIN_PCF1_MINISTRAL_PUBLICATION_CONFIRMATION.md and SHOHIN_PCF2_MINISTRAL_PUBLICATION_CONFIRMATION.md. The sole gate remains:

  • unchanged >=387/1289 with every domain nonzero;
  • revision >= unchanged+65 and >= self-refinement+39, with no per-domain loss against either;
  • commit >= revision+13, at least 95% retention of both revision-correct and unchanged-correct identities, and no per-domain loss against revision; and
  • exact 1289/1289 custody/order, zero assessment truncation, zero malformed selections, complete hashes/accounting, zero retries, and zero holdout/public/product access.

The generated-candidate policy remains exact SHA-256 f27124db3d134a1e3dbde06958ab03220cd5e9585abcc356baa6a49d9edd1f1e. No generated candidate gains an import, builtin, filesystem, process, introspection, environment, network, randomness, or resource capability.

Sole PCF3 repair: trusted-reference separation

The exact frozen MBPP reference code is supervisor evidence, not model output. PCF3 transports it through the already sealed assessor memfd as assessment mode trusted_reference, after the full allocation sandbox probe and standalone setup qualification. It remains:

  • mounted as the only raw read-only candidate source;
  • executed as PID 1 inside the same networkless Bubblewrap namespace;
  • restricted to the same minimal read-only Python/ELF projection, private /proc and /dev, bounded /tmp, clean environment, deterministic runtime, and CPU/memory/file/process/wall limits;
  • followed by the exact official setup and tests with trusted completion attestation; and
  • represented in custody only by identity, program, setup, runtime, sandbox, and execution hashes—never reference or test content.

The untrusted generated-candidate grammar is explicitly not applied to this trusted reference. The reference cannot become a confirmation candidate, training target, prompt field, proposal, verifier input, or score. Holdout reference content remains unaccessed.

Before any PCF3 graph, an infrastructure-only CPU canary must run the full sandbox qualification and execute every train/development MBPP reference behind this exact trusted mode. It emits no capability statistic, model artifact, assessor, prompt, candidate content, or scientific score. Every nonsealed reference and official test must pass; any miss closes PCF3 before science. A fresh 40-probe sandbox receipt is also mandatory because the trusted transport enum changes the bootstrap/config hashes. The already qualified scratch implementation is reused only because train/jobs/pcf1_common.sh remains byte-identical at SHA-256 b709fb2069d715837abe20458cd5792c54439e91d4c4277d9486355298b7f3c0.

Execution and stop rule

After the reference canary, fresh sandbox receipt, full local suite, immutable runtime package, storage check, clean private checkout, and live preflight all pass, submit exactly one PCF3 graph. Disable requeue, retries, and automatic successors. Infrastructure failure, formal PASS, or formal FAIL ends PCF3. If scoring is reached, the authorized CPU scorer is still the sole assessor reader and opens the board exactly once. Do not open holdout, product, public, an alternate host, or a successor after PCF3.