Date: 2026-09-14. Repo: qwen36-multi-variant-proxy (workstation checkout
WORKSTATION/NAMEOFMODEL).
Question answered: is the live/metrics-deploy-20260904 branch — including the
PR #5 hardening layer (review/pr4-hardening-20260911) and the proxy-managed
Unc Q4KM :12702 cutover — fully green and safe to promote to main?
Measured result: 107 passed, 1 skipped in 0.37 s on the validated tip
(27f3620), re-verified green on the main merge result (168d60d, pushed).
The single skip is environmental (thinkingcap-h3 weights absent on this host).
Workflow
flowchart LR
A[Review live worktree:<br/>uncommitted :12702 flip] --> B[Verify intent:<br/>systemd retired, launcher<br/>declares proxy-managed]
B --> C[Fix stale wording<br/>name + description_note]
C --> D[Suite on live tip:<br/>100 passed, 1 skipped]
D --> E[Commit + push<br/>ccf2f53]
E --> F[Review PR #5 diff<br/>13 items, 5 files]
F --> G[Merge review branch<br/>clean, +552/-43]
G --> H[Fix found in review:<br/>LLAMA_API_KEY forwarding]
H --> I[Suite: 107 passed,<br/>1 skipped]
I --> J[Push live tip<br/>27f3620]
J --> K[Merge live into main<br/>168d60d, push]
K --> L[This experiment record]
Step outcomes (observed, in order):
| # | Action | Evidence | Outcome |
|---|---|---|---|
| 1 | Triaged dirty qwen36_model_families.json (managed false->true on :12702) |
Launcher header, systemctl state (disabled/inactive), pre-proxy-managed backup identical to HEAD |
Intentional cutover, kept |
| 2 | Fixed stale systemd wording in family name + note |
git diff on registry |
Committed as ccf2f53 |
| 3 | Full suite on live tip | Run 1 below | 100 passed, 1 skipped, 0.38 s |
| 4 | Reviewed PR #5 vs its base d129eb9 |
5 files, +552/-43, all 13 items checked against code | Sound; 1 edge found (unauthenticated /v1/models probe breaks adoption for keyed workers) |
| 5 | Merged origin/review/pr4-hardening-20260911 |
9b72a5f, auto-merge, zero conflicts |
Clean |
| 6 | Added LLAMA_API_KEY forwarding to _worker_identity_matches |
27f3620, mirrors _backend_request |
Committed |
| 7 | Full suite on live tip | Run 2 below | 107 passed, 1 skipped, 0.37 s |
| 8 | Pushed live branch | 27f3620 on origin |
Done |
| 9 | Merged live into main (isolated worktree; main had advanced via PR #3) | 168d60d, zero conflicts, delta vs live is docs-only |
Pushed to origin main |
| 10 | Full suite on merge result | Run 3 below | 107 passed, 1 skipped, 0.37 s |
What was tested
Unit suite under tests/ (19 files, 107 test functions, one parametrized x2
-> 108 collected). Environment: Python 3.12.13, pytest 9.1.1, fastapi 0.135.3,
AUTO_DISABLE_MISSING_WEIGHTS=0 via tests/conftest.py so results are
independent of weights on disk (see versions,
full inventory).
| Area | File | Tests | Covers |
|---|---|---|---|
| GPU lifecycle / eviction | test_qwen36_variant_proxy_gpu_cleanup.py |
26 | Idle reap, replacement windows, stream-failure accounting |
| Elastic pool | test_qwen36_elastic_pool.py |
17 | Worker acquire/reuse, pools |
| Laguna route | test_laguna_s21_route.py |
8 | Launcher invariants, route contract |
| PR #5 hardening (new) | test_pr4_hardening.py |
7 | Upscale auth, path roots, host allowlist, adoption refusal, router --force, VibeVoice accounting |
| Nemotron route | test_nemotron_embedding_route.py |
7 | Embedding protocol/labels |
| Elastic worker routes | test_elastic_worker_routes.py |
7 | GPU policy, pool placement (1 env skip) |
| Weight auto-disable | test_auto_disable_missing_weights.py |
6 | Missing-weight filtering |
| OrcaRouter route | test_orcarouter_route.py |
5 | Public naming, contract |
| Proxy metrics | test_proxy_metrics.py |
4 | Record/stats, tok/s windows |
| Magiseek routes | test_magiseek_v11_routes.py |
4 | Route contract |
| OCR / Unsloth / Ornith / misc | 9 files | 17 | One route contract each |
The 7 new hardening tests (all passing, 0.19 s standalone):
test_upscale_auth_requires_configured_token— 503 when no token configuredtest_upscale_auth_accepts_only_matching_bearer— 401 on wrong tokentest_upscale_path_roots_block_escape— outside-root input rejectedtest_remote_upscale_inputs_require_explicit_host_allowlist— default deny + subdomain matchtest_elastic_pool_does_not_adopt_unverified_listener— no adoption without identity matchtest_router_model_audit_force_switch_is_opt_in— nox-proxy-forceunless--forcetest_vibevoice_request_accounting_updates_active_count— active-request telemetry
Runs and timing
| Run | Commit / ref | Result | pytest time | Wall |
|---|---|---|---|---|
| 1 — live tip pre-PR#5 | ccf2f53 |
100 passed, 1 skipped | 0.38 s | — |
| 2 — live tip post-merge+fix | 27f3620 |
107 passed, 1 skipped | 0.37 s | 0.58 s |
| 3 — main merge result | 168d60d |
107 passed, 1 skipped | 0.35–0.37 s | — |
| Focused hardening file | 27f3620 |
7 passed | 0.19 s | — |
Slowest tests (from --durations=25): test_record_and_stats and
test_tokens_per_second_uses_ttft_window at 0.03 s each; everything else
<= 0.01 s. Full log: pytest-full-verbose.log;
machine-readable: pytest-junit.xml.
Skip (environmental, pre-existing): tests/test_elastic_worker_routes.py:167
— thinkingcap-h3 weights absent on this host (skip-reason.txt).
Samples produced
Per-test verdict sample (tests/test_pr4_hardening.py -v):
test_upscale_auth_requires_configured_token PASSED [ 14%]
test_upscale_auth_accepts_only_matching_bearer PASSED [ 28%]
test_upscale_path_roots_block_escape PASSED [ 42%]
test_remote_upscale_inputs_require_explicit_host_allowlist PASSED [ 57%]
test_elastic_pool_does_not_adopt_unverified_listener PASSED [ 71%]
test_router_model_audit_force_switch_is_opt_in PASSED [ 85%]
test_vibevoice_request_accounting_updates_active_count PASSED [100%]
7 passed in 0.19s
Suite tail (run 2, live tip 27f3620):
107 passed, 1 skipped in 0.37s
Merge receipts:
9b72a5f Merge PR #5 hardening ... 5 files changed, 552 insertions(+), 43 deletions(-)
168d60d Merge live/metrics-deploy-20260904 into main (pushed: a6b8df5..168d60d)
Follow-ups
- CONCLUSION.md — version comparison (pre-hardening vs hardened vs main) with hypothesis, guardrails, control-arm evidence, and the ship verdict.
- BLOG.md — publication-ready practitioner post built from this experiment’s evidence only.
- SESSION.md — session narrative, decisions, and the Laguna solidity assessment.
Evidence files
- qualification.json — machine-readable summary of runs and outcome
- pytest-full-verbose.log — all 108 verdicts + slowest-25 durations
- pr5-tests-verbose.log — focused run of the 7 new tests
- pytest-junit.xml — JUnit report for tooling
- test-inventory.txt —
--collect-onlylisting (108 items) - git-evidence.txt — log, merge-base, diff stats, per-file counts
- versions.txt — toolchain + commit SHAs
- main-merge-sha.txt — main merge SHA + post-merge suite line
- skip-reason.txt — the single environmental skip
- control-arm.log — new tests run against pre-hardening code (7 failed)
- rerun-suite.sh — regenerates the pytest artifacts
Reproduction
./scripts/rerun-suite.sh [/path/to/qwen36-multi-variant-proxy]
Requires the workstation checkout (or any clone) plus WORKSTATION/miniconda3
Python with pytest/fastapi. The laguna launcher test reads the host-local
run_laguna_s21_iq4xs_3gpu.sh (gitignored); a bare clone without that file
fails that one test with FileNotFoundError — observed once in a fresh
worktree, resolved by staging the host launchers, then green.
Operational notes (from the reviewed changes, not re-tested live)
/v1/upscalenow requiresUPSCALE_API_TOKEN(falls back toTERMINAL_ADMIN_TOKEN); unset means HTTP 503 with a clear message.- Remote upscale URLs require
UPSCALE_ALLOWED_REMOTE_HOSTS(default deny, subdomain-aware); redirects are re-validated against the same allowlist. - Relative upscale outputs now resolve under
COMFY_OUTPUT(previously the process working directory). - VibeVoice gains serialized startup, idle shutdown (default 300 s), and a
configurable container name; router sweeps no longer force-switch unless
passed
--force.
Limits and boundaries
- Unit suite only: no live backend was started; GPU/VRAM behavior, real upscale jobs, and VibeVoice container cycling were reviewed in code, not executed.
- During this session, separate uncommitted ComfyUI work (queue guard,
:8188protection, registry renames) appeared in the proxy worktree. It was deliberately left untouched and is not part ofmainat168d60d. incoming/andresults/batch data in the proxy checkout remain untracked and out of scope.- Interpretation (e.g. “safe to promote”) is mine; the measured facts are the suite verdicts and SHAs above.