Skip to content

build(whisper): verify portable dynamic runtime - #68

Merged
vriesd merged 9 commits into
mainfrom
codex/portable-whisper-acceleration-plan
Aug 27, 2026
Merged

build(whisper): verify portable dynamic runtime#68
vriesd merged 9 commits into
mainfrom
codex/portable-whisper-acceleration-plan

Conversation

@vriesd

@vriesd vriesd commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Why

Echo's qualified Vulkan runtime used whisper.cpp's host-native CPU default. That tied its instruction set to the build laptop and provided no machine-readable build contract.

This phase creates a portable Linux x86_64 runtime package before Echo changes production GPU selection.

Scope

  • Build whisper.cpp with dynamic CPU dispatch, all fourteen x86_64 variants, Vulkan, stable source paths, and a pinned source timestamp.
  • Record source, patches, compiler observations, CMake options, package files, private ELF dependencies, platform ABI, and same-toolchain reproducibility in receipt schema 2.
  • Verify exact required regular files, ELF64 x86_64 identity, package-owned private libraries, the host-owned Vulkan loader, CPU dispatch, and a Vulkan device receipt.
  • Keep the managed CPU archive and production GPU admission behavior unchanged.
  • Add the approved six-phase acceleration plan and its decision trail.

Tradeoffs

The portable bundle grows by 14.2 MB before compression because it includes fourteen CPU implementations. The growth is smaller than the variant files themselves because the old native CPU module is removed.

The receipt is an unsigned build observation. PR 16.2 will bind its digest into trusted release metadata.

The runtime requires GLIBC 2.38, GLIBCXX 3.4.32, and CXXABI 1.3.9. Debian Bookworm has GLIBC 2.36, so the evidence records it as an unsupported ABI instead of claiming universal Linux support.

Blast radius

This changes the qualification runtime builder, verifier, and evidence replay. It does not change production runtime selection, installed models, microphone handling, or decoding.

Malformed receipts, missing or symlinked required modules, duplicate inventory rows, changed runtime bytes, unsupported ELF identities, loader escapes, and tagless pinned source clones now have deterministic tests.

Verification

  • Two clean builds produced artifact ID 317aa0de89d05f1abd6a4fd7bd8d993cdaa2b4946f131212ba04de321b5e1e32 and receipt SHA-256 f3e0e18872f9587bf5e3113ad7d6b715bbbca621a26aa1bafdfa17575a1566cc.
  • Two deterministic archives produced SHA-256 f76c7b7ffe1d76ef6470300bb6d66b33433f3600ad1e964e181af699865af28f.
  • Twenty-nine mutation and contract tests pass.
  • All ten live lanes pass against receipt schema 2. They cover CPU without a Vulkan loader, Alder Lake dispatch, Nehalem SSE4.2, Conroe x64, package drift, ELF bindings, repeat receipts, Ubuntu Debian installation, and Fedora RPM installation.
  • Eighty committed performance samples bind the model and audio digests, runtime identities, transcript digests, stderr digests, and Vulkan receipt. The replay verifier recomputes the summary on every CI run.
  • CPU median deltas are +2.43% for Small and +1.04% for Large Turbo. CPU p95 deltas are +0.23% and +0.61%.
  • Vulkan median deltas are -0.27% for Small and +0.13% for Large Turbo. Vulkan p95 deltas are +0.25% and -0.05%.
  • Transcript parity is exact. All twenty candidate Vulkan samples contain the same valid device receipt.
  • Frontend build, lint, 94 tests, two responsive browser tests, clippy, the full Rust workspace, release build, icon drift, desktop metadata, changelog parsing, benchmark, corpus, acceleration, runtime archive, and evidence replay checks pass.

The durable evidence lives in .audit/pr16-1-summary.json and .audit/pr16-1-evidence/.

Split the rollout into six ordered PRs with unit, live, performance, review, and merge evidence. Record the architecture decisions and the plan-check result.
Build the pinned receipt runtime with portable CPU dispatch, a dynamic Vulkan module, deterministic timestamps, and stable compiler paths. Add a strict package receipt and runtime verifier for the CMake contract, staged files, backend loading, and ELF resolution.
Preserve the red baseline, build attempts, reproducibility runs, focused checks, full repository gates, and the append-only PR 16.1 decision trail.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 96bfec4b22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/verify-whisper-vulkan-runtime.py Outdated
Comment thread scripts/verify-whisper-vulkan-runtime.py Outdated
@vriesd

vriesd commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Root shipping verdict

PASS at bc3ff7d5e651e0c3740cd0d1888255f43263c801.

This verdict applies only to this exact head. A new commit voids it.

Independent lanes

  • Gates. PASS. Local, remote, and PR SHAs match. The worktree is clean. All required checks pass. Both review threads are resolved. GitHub reports MERGEABLE and CLEAN.
  • Security. PASS. The reviewer reproduced the previous bypasses. False transcript parity, mixed candidate Vulkan receipts, booleans, negative or oversized device integers, pre-existing receipt symlinks, and dynamic-loader injection now fail closed. All 29 mutation tests pass.
  • Live runtime. PASS. CPU and Vulkan verification pass. Fresh Small-model CPU and GPU transcriptions produced byte-identical JSON. The Vulkan inference receipt matches the probe receipt.
  • Packages and evidence. PASS. The Debian and RPM payloads preserve the schema-2 runtime. QEMU selects SSE4.2 on Nehalem and x64 on Conroe. The 80-run replay, package mutations, ABI boundary, ten screenshots, and archive hashes match the committed evidence.
  • Audit and plan. PASS after root judgment. PR 16.1 has 24 of 25 boxes checked; only this verdict and merge remained. The current production verifier module is 920 lines. Git binds the committed screenshots, exact-head CI replays the manifests, and the exact-head CI workspace run supersedes the older local log.

Exact identities

  • Runtime artifact: 317aa0de89d05f1abd6a4fd7bd8d993cdaa2b4946f131212ba04de321b5e1e32
  • Build receipt: f3e0e18872f9587bf5e3113ad7d6b715bbbca621a26aa1bafdfa17575a1566cc
  • Deterministic archive: f76c7b7ffe1d76ef6470300bb6d66b33433f3600ad1e964e181af699865af28f
  • Performance run manifest: 09978a93b118aeee2d273939e84edf5b183a722f689aab30590d41041560dcd0
  • Interleaved timings: 9afedbb719b72c887ee7b88fdaab36ea4a6185460a05feeaefb77a58494cc928
  • Workspace log: 14edf5f45075e27c9a291bab42376110cb0fae8ee87e8587bb704451833baa38

Exact-head GitHub evidence

Deliberate phase boundaries

  • Compiler metadata remains an unsigned buildObservation. PR 16.2 adds the trusted Echo release binding.
  • CPU operation succeeds without a Vulkan loader. PR 16.4 owns the stronger rule that CPU mode performs no GPU enumeration.
  • Hardware-wide production GPU selection remains disabled until the later hardware matrix and operator review.

Reviewed independently by four gpt-5.6-luna lanes, then countersigned by the root verifier.

@vriesd
vriesd merged commit f78db18 into main Aug 27, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants