record blocked legacy model provenance migration
This commit is contained in:
+102
@@ -0,0 +1,102 @@
|
|||||||
|
{
|
||||||
|
"schema_version": 1,
|
||||||
|
"generated_at": "2026-08-09T13:20:00Z",
|
||||||
|
"audit_id": "reviewedexp6-provenance-migration-audit-r1",
|
||||||
|
"status": "blocked_lineage_incomplete",
|
||||||
|
"model": {
|
||||||
|
"path": "/app/models/geointel-building-yolov8s-reviewedexp6-minpx3-img640-ft20.pt",
|
||||||
|
"sha256": "038f1f97a6afd534f29e1f392a730a58207b928ca01e31ab8d8fed6106705820",
|
||||||
|
"size_bytes": 22514794,
|
||||||
|
"observed_mtime": "2026-07-15T05:11:29.338792783+02:00",
|
||||||
|
"lifecycle": "legacy_unpromoted_challenger"
|
||||||
|
},
|
||||||
|
"observed_training_artifacts": [
|
||||||
|
{
|
||||||
|
"role": "training_summary",
|
||||||
|
"path": "/app/storage/training/operator-yolo/geointel-building-yolov8s-reviewedexp6-minpx3-img640-ft20/training_summary.json",
|
||||||
|
"sha256": "961b9d119b24967977c22ba89a54f9caea51e440769bebde5641b7ee8bfae1eb"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"role": "ultralytics_arguments",
|
||||||
|
"path": "/app/storage/training/operator-yolo/geointel-building-yolov8s-reviewedexp6-minpx3-img640-ft20/args.yaml",
|
||||||
|
"sha256": "87e07dbed3ad12cc474e6b895147839431805b7044496277242e1538fcd91a0b"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"role": "training_metrics",
|
||||||
|
"path": "/app/storage/training/operator-yolo/geointel-building-yolov8s-reviewedexp6-minpx3-img640-ft20/results.csv",
|
||||||
|
"sha256": "57e72102b855c138b212efc293249952ec821e0f07201666ea4b17fb23d727a9"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"role": "dataset_summary",
|
||||||
|
"path": "/app/storage/operator-data/yolo-building-aoi1024-reviewedexp6-minpx3vis035/yolo_tile_dataset_summary.json",
|
||||||
|
"sha256": "7c917e31216d1df2174c0f9c736f88a81f3835aa991971f8fb8665e17ddf5c9c"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"role": "dataset_yaml",
|
||||||
|
"path": "/app/storage/operator-data/yolo-building-aoi1024-reviewedexp6-minpx3vis035/dataset.yaml",
|
||||||
|
"sha256": "62e12f4433508cb0640f1d90ec0ffd389cd21ebe655fac4e7d9402f04da1168e"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"role": "legacy_dataset_quality_audit",
|
||||||
|
"path": "/app/storage/operator-data/model-review/reviewedexp6-corpus/audit/operator_yolo_dataset_quality_audit.json",
|
||||||
|
"sha256": "42c34cddfcf7b8656d4513efa4e7249d73678164c2a1121f245be42ac56daf12"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"reproduced_training_configuration": {
|
||||||
|
"task": "detect",
|
||||||
|
"epochs": 20,
|
||||||
|
"image_size": 640,
|
||||||
|
"batch_size": 4,
|
||||||
|
"device": "cpu",
|
||||||
|
"seed": 0,
|
||||||
|
"deterministic_requested": true,
|
||||||
|
"base_model_sha256": "a9088b8491dfae36694b53e9e9406cb4e3511d334a5712fa34f75078a47759c1",
|
||||||
|
"dataset_tile_count": 252,
|
||||||
|
"dataset_label_count": 79192,
|
||||||
|
"train_tile_count": 234,
|
||||||
|
"validation_tile_count": 18
|
||||||
|
},
|
||||||
|
"human_review_gate": {
|
||||||
|
"evaluated_with": "scripts.training_release_manifest.human_review_audit_failures",
|
||||||
|
"passed": false,
|
||||||
|
"failures": [
|
||||||
|
"accepted_human_review_evidence_missing",
|
||||||
|
"review_audit_manifest_not_immutable",
|
||||||
|
"review_audit_spatial_leakage_not_ok",
|
||||||
|
"review_complete_not_true"
|
||||||
|
],
|
||||||
|
"interpretation": "The retained quality audit is not a checksum-bound accepted human-review ledger and cannot be upgraded into one retroactively."
|
||||||
|
},
|
||||||
|
"missing_required_original_evidence": [
|
||||||
|
"exact training repository commit recorded at training start",
|
||||||
|
"training container image digest",
|
||||||
|
"pinned Python, PyTorch, CUDA and Ultralytics runtime receipt for the original CPU run",
|
||||||
|
"dependency lock or SBOM checksum",
|
||||||
|
"immutable source corpus manifest and freeze-sidecar checksum",
|
||||||
|
"label release checksum",
|
||||||
|
"independent split manifest checksum and zero-under-2-km audit",
|
||||||
|
"accepted human review ledger with reviewer identity, per-sample decision, timestamp and reviewed artifact hash",
|
||||||
|
"complete training RunManifest binding all upstream artifacts before execution"
|
||||||
|
],
|
||||||
|
"forbidden_inferences": [
|
||||||
|
"A nearby Git commit may not be assigned as the training commit from file times.",
|
||||||
|
"The current container runtime may not be copied backwards as the historical training runtime.",
|
||||||
|
"The dataset quality contact sheet may not be represented as accepted human review.",
|
||||||
|
"A structurally valid runtime sidecar may not be generated with invented UUIDs or placeholder upstream checksums."
|
||||||
|
],
|
||||||
|
"actions": {
|
||||||
|
"runtime_sidecar_created": false,
|
||||||
|
"source_registry_rows_created": false,
|
||||||
|
"production_inference_executed": false,
|
||||||
|
"production_model_changed": false,
|
||||||
|
"candidate_quarantine_state": "not_active_and_not_exposed_by_production_catalog",
|
||||||
|
"active_model_sha256": "a9088b8491dfae36694b53e9e9406cb4e3511d334a5712fa34f75078a47759c1"
|
||||||
|
},
|
||||||
|
"decision": {
|
||||||
|
"migration_allowed": false,
|
||||||
|
"promotion_allowed": false,
|
||||||
|
"new_training_allowed": false,
|
||||||
|
"reason": "GeoIntel's execution contract explicitly forbids retroactively completing legacy RunManifest evidence. The current accuracy-program ledger also keeps training and promotion locked until P2-00 through P2-07 and the governed Phase-4 product gates pass.",
|
||||||
|
"safe_next_gate": "Complete P2-00 through P2-07, obtain representative human review, freeze a new independently split corpus, then train a new pre-registered GPU candidate with complete provenance from process start."
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -12498,3 +12498,33 @@ Open:
|
|||||||
- The active model remains review-required and Kempen-scoped. The export gate
|
- The active model remains review-required and Kempen-scoped. The export gate
|
||||||
prevents overstated results; it does not replace the missing independent,
|
prevents overstated results; it does not replace the missing independent,
|
||||||
human-reviewed national accuracy corpus or improve model weights by itself.
|
human-reviewed national accuracy corpus or improve model weights by itself.
|
||||||
|
|
||||||
|
## 2026-08-09 - Reviewedexp6 provenance migration audit
|
||||||
|
|
||||||
|
### Inspected
|
||||||
|
|
||||||
|
- Recovered and checksummed the original challenger weights, training summary,
|
||||||
|
Ultralytics arguments, results, dataset YAML, 252-tile/79,192-label summary
|
||||||
|
and legacy dataset-quality audit.
|
||||||
|
- Reproduced the recorded seed `0`, deterministic request, CPU device, twenty
|
||||||
|
epochs, active base-model hash and train/validation counts.
|
||||||
|
- Ran the current human-review eligibility validator against the retained
|
||||||
|
audit; it failed on missing accepted review evidence, manifest immutability,
|
||||||
|
spatial-leakage status and incomplete review state.
|
||||||
|
|
||||||
|
### Decision
|
||||||
|
|
||||||
|
- Refused to invent the absent historical training commit, container digest,
|
||||||
|
runtime receipt, corpus/label/split manifests, reviewer decisions or source
|
||||||
|
registry UUIDs.
|
||||||
|
- Created no runtime sidecar, database provenance row or production model
|
||||||
|
activation. The active scoped model and healthy GPU runtime remain unchanged.
|
||||||
|
- Retained the complete fail-closed audit under
|
||||||
|
`artifacts/evidence/accuracy/model-training/20260809-reviewedexp6-provenance-migration-audit.json`.
|
||||||
|
|
||||||
|
### Required next gate
|
||||||
|
|
||||||
|
- Complete P2-00 through P2-07 and the governed Phase-4 blockers, obtain real
|
||||||
|
representative human review, freeze a new independent corpus and only then
|
||||||
|
train a pre-registered GPU candidate with provenance captured from process
|
||||||
|
start. The legacy checkpoint cannot be made compliant retroactively.
|
||||||
|
|||||||
@@ -1141,3 +1141,9 @@ This file now starts with the current implementation status. Older preparation/b
|
|||||||
image/model/config hashes, shadow evidence and tested rollback.
|
image/model/config hashes, shadow evidence and tested rollback.
|
||||||
- [ ] P2-12: monitor drift into a human reviewqueue without automatic
|
- [ ] P2-12: monitor drift into a human reviewqueue without automatic
|
||||||
self-training or silent promotion.
|
self-training or silent promotion.
|
||||||
|
- [x] Audit whether the July `reviewedexp6` checkpoint can be migrated into the
|
||||||
|
current runtime provenance contract without invented evidence; retain the
|
||||||
|
checksum-bound blocked report.
|
||||||
|
- [ ] Do not generate a production sidecar for `reviewedexp6`: its exact
|
||||||
|
training commit/runtime, immutable corpus-label-split manifests and accepted
|
||||||
|
human-review ledger were not retained and cannot be reconstructed safely.
|
||||||
|
|||||||
@@ -62,3 +62,28 @@ the only safe production choice.
|
|||||||
|
|
||||||
Machine-readable hashes, metrics, paths and the exact decision are in
|
Machine-readable hashes, metrics, paths and the exact decision are in
|
||||||
`artifacts/evidence/accuracy/model-training/20260809-v68-checkpoint-and-threshold-review.json`.
|
`artifacts/evidence/accuracy/model-training/20260809-v68-checkpoint-and-threshold-review.json`.
|
||||||
|
|
||||||
|
## Provenance migration follow-up
|
||||||
|
|
||||||
|
The original July training directory was audited after the threshold review.
|
||||||
|
It retains exact weights, Ultralytics arguments, result curves, dataset YAML,
|
||||||
|
dataset summary and a structural quality audit. This recovers useful facts,
|
||||||
|
including seed `0`, deterministic mode, the base-model hash and all dataset
|
||||||
|
counts.
|
||||||
|
|
||||||
|
It does not retain the complete evidence required to construct a current
|
||||||
|
production sidecar truthfully. In particular, the exact training commit,
|
||||||
|
container digest, dependency/runtime receipt, immutable corpus and label
|
||||||
|
release manifests, independent split audit and accepted human-review ledger
|
||||||
|
are absent. The current review validator reproduces four failures:
|
||||||
|
|
||||||
|
- `accepted_human_review_evidence_missing`;
|
||||||
|
- `review_audit_manifest_not_immutable`;
|
||||||
|
- `review_audit_spatial_leakage_not_ok`; and
|
||||||
|
- `review_complete_not_true`.
|
||||||
|
|
||||||
|
No UUID, upstream checksum, historical runtime or reviewer decision was
|
||||||
|
invented. Consequently no runtime sidecar or database source snapshot was
|
||||||
|
created, and the challenger remains unavailable to production inference. The
|
||||||
|
full machine-readable audit is retained in
|
||||||
|
`artifacts/evidence/accuracy/model-training/20260809-reviewedexp6-provenance-migration-audit.json`.
|
||||||
|
|||||||
Reference in New Issue
Block a user