Files
neuron-tai/.scratch/distributed-gguf-runtime/evidence/DGR-034

DGR-034 evidence — dense-Llama range-aware GGUF ownership

Status: implemented and live-verified on 2026-08-01. prd.json remains the authority for story state.

What changed

  • The pinned llama.cpp patch stack adds meshnet_owned_layer_start/end and filters dense-Llama GGUF registration to blk.N.* for the requested half-open range. token_embd.weight belongs to the head; output_norm and output.weight (or the tied embedding) belong to the tail.
  • The load state exposes a C range report derived from the registered model buffers, and a project-owned meshnet-range-report tool audits the live registered tensor map. It rejects empty, inverted, out-of-model, missing, outside-range, unexpected, and endpoint-inconsistent loads.
  • meshnet_node.range_report accepts only audited tool output. It makes the range and endpoint flags authoritative from loaded state rather than caller assertions, and fails closed on malformed ownership or byte counts.

Real-model memory evidence

Artifact: Magistral-Small-2509-Q4_K_M.gguf, 14,333,911,104 bytes, SHA-256 a17a113480e7f55780ad1d100493c70ac158d1943e578bbdd75acef0872ab7dc. It stayed on the configured mounted drive; no artifact was downloaded or put under /home.

The direct non-mmap lane proves resident storage tracks owned tensors:

Range Registered tensors Resident bytes Process peak RSS
[10, 20) 90 3,304,898,560 3,298,800 KiB
[0, 40) 363 14,326,026,240 14,061,632 KiB

Raw reports and timings are in runs/default-mid-a.* and runs/default-full-nommap.*. The middle range is 23.1% of the full resident allocation and owns 24.8% of the registered tensors.

Commands and results

python3 scripts/llama_cpp_dependency.py reverse --source-dir build/llama.cpp/source
python3 scripts/llama_cpp_dependency.py verify --workspace build/llama.cpp
python3 scripts/llama_cpp_dependency.py apply --source-dir build/llama.cpp/source
# apply/check/reverse succeeded against e920c523e3b8a0163fe498af5bf90df35ff51d25;
# the source was then applied for the focused native checks.

(cd packages/node/native/llama/patches && sha256sum -c SHA256SUMS)
# all six patches: OK

/home/popov/.hermes/hermes-agent/venv/bin/ctest \
  --test-dir build/llama.cpp/dgr034-check \
  -R '^test-meshnet-range-ownership$' --output-on-failure
# 1/1 passed

PYTHONPATH=packages/node MESHNET_RANGE_REPORT_BIN="$PWD/build/llama.cpp/dgr034-check/bin/meshnet-range-report" \
  /home/popov/.hermes/hermes-agent/venv/bin/pytest -q \
  tests/test_range_report.py tests/test_meshnet_range_report_tool.py \
  tests/test_llama_cpp_dependency.py
# 56 passed in 0.87s

PYTHONPATH=packages/node /home/popov/.hermes/hermes-agent/venv/bin/python \
  -m compileall -q packages tests
python3 scripts/ralph_prd_schema.py validate .scratch/distributed-gguf-runtime/prd.json
git diff --check && git diff --cached --check
# all exit 0; PRD validation: 55 stories validated

The model commands used the same meshnet-range-report binary with --no-mmap --no-extra-bufts, first for [10,20) and then [0,40); both returned ok: true and their exact output is retained above.

Changed files

  • packages/node/native/llama/PATCH-STACK.md
  • packages/node/native/llama/UPSTREAM_LOCK.json
  • packages/node/native/llama/patches/{series,SHA256SUMS,UPSTREAM-ASSUMPTIONS.json,0006-meshnet-range-report-tool.patch}
  • packages/node/meshnet_node/range_report.py
  • tests/test_range_report.py
  • tests/test_meshnet_range_report_tool.py
  • .scratch/distributed-gguf-runtime/evidence/DGR-034/*

Limitations and dependency handoff

  • The mmap loader can retain broad contiguous file spans when GGUF tensor order places a tail endpoint near the beginning of the artifact; the direct non-mmap lane is the certified resident-memory result. The raw mmap report is retained in runs/default-head.json and must not be presented as a physical-RSS saving.
  • This story proves loading/ownership only. Partial-range graph execution remains fail-closed until DGR-035 provides typed dense boundary adapters.
  • DGR-037 can bind the worker to llama_model_meshnet_range_report or the strict Python consumer; it must use the reported range, not requested range, for capability publication. DGR-051 must add its V4-specific ownership rules separately.