/** * S1 value-verdict harness β€” the REAL `ProfileDeps` factory (the LIVE make-real wiring). SPEC-S1-value-harness.md * Β§11 "the wiring of ProfileDeps to the REAL core entrypoints + REAL E2B worker/grader envs". This module * ASSEMBLES a bench runtime β€” createBrain(DeepSeek) + a real `Runner` + a real E2B WORKER env + a DISTINCT E2B * GRADER env + createLeaderRunner for TEAM β€” and returns a `ProfileDeps` whose EVERY seam runs the REAL engine/ * oracle. The deterministic driver (`run-firm.ts --dry-run`) injects a MOCK; this is the clay-gated live path. * * πŸ”΄ ANTI-REWARD-HACK (oracle.ts Β§, runner-ctx.ts Β§5.1): the oracle ALWAYS grades in a env that is a DISTINCT * object from the worker env. We provision a SEPARATE E2B sandbox for the grader and transfer the worker's * COMMITTED tree into it via `git bundle` (export from the worker sandbox β†’ import into the grader sandbox) β€” * so the grader's checkout is the worker's HEAD, but the grader sandbox can never be rewritten by the worker * (its hidden tests + its exec all run in a sandbox the worker never touched). `assertDistinctEnvs` is the * build-time guard; the structural separation is the real boundary. * * πŸ”΄ TRAP TASKS RUN ISOLATED (the task prompt): every worker leg runs inside an E2B Firecracker VM * (`RemoteContainerExecutionEnv`), NEVER the bare host β€” a C4/trap that reaches for a dangerous action is * contained by the VM boundary (`capabilities.isolation === true`). * * πŸ”΄ OBJECTIVE ORACLE ONLY (row.ts Β§): `runOracle` runs `runExecGate` over real exit codes in the grader env; * there is NO LLM-judge in the numerator. The LLM is only a GATE inside an arm (the verify/repair/reviewer). * * πŸ”΄ HONEST GAPS (flagged, NOT stubbed): the per-cell worker/grader env LIFECYCLE (provision β†’ run β†’ grade β†’ * destroy) is owned by `buildLiveDeps`, which returns a `ProfileDeps` bound to ONE (trap, seed) cell β€” the * driver constructs a fresh `buildLiveDeps` per cell and disposes it after the row is emitted (so a hung cell's * sandboxes are reaped). `runCounterfactualOracle` is DELIBERATELY OMITTED (a real ablation β€” re-running the * SAME (trap,seed) with the gate DISABLED into a FRESH worker β€” is TODO); absent β‡’ buildCounterfactual returns * undefined β‡’ the metric tool records UNVERIFIED-WITHHELD (NO avoided-loss credit), the honest "not measured" * choice. The previous `runCounterfactualOracle: runOracle` self-alias re-graded the IDENTICAL post-gate tree and * auto-credited EVERY withhold as CORRECTLY-WITHHELD (a tautology) β€” removed. * * πŸ”΄ TEAM (the leader arm): the leader INTEGRATES + PUSHES to a per-cell `git://127.0.0.1` durable remote (served by * a local `git daemon` β€” the wire validator forbids file://). On a delivered run the harness clones that * integrated tree INTO state.worker, so `runOracle` grades the REAL integrated output in the DISTINCT grader (the * same anti-reward-hack transfer path SOLO/SUP use). If the integrated tree can't be imported, the cell is * `infraFailed` (EXCLUDED) β€” NEVER a fabricated uniform delivered=false loss for the whole TEAM column. */ import { type TaskSpec } from "@sema-agent/core"; import type { ProfileDeps, SoloImplSpec, SupImplSpec } from "./arms.js"; import type { TrapSpec } from "./tasks.js"; /** Live runtime config β€” the SAME base model + budget every arm runs on (the Β§3.2 fairness root). */ export interface LiveRuntimeConfig { /** DeepSeek model id (the SAME base model all arms run on). */ modelId: string; /** DeepSeek gateway base URL (e.g. https://api.deepseek.com). */ gatewayBaseUrl: string; /** DeepSeek API key (DEEPSEEK_API_KEY). */ deepseekApiKey: string; /** E2B API key (E2B_API_KEY). */ e2bApiKey: string; /** Optional E2B template (image) for the worker + grader VMs. */ e2bTemplate?: string; /** Per-sandbox lifetime ms (E2B billing window). Default 10min. */ sandboxTimeoutMs?: number; /** The shared verifyβ†’fix round cap (SOLO/SUP). Default 2. */ maxRounds?: number; /** The shared per-cell cost cap (USD). Default 1.0 (clay: budget unlimited β€” this is a per-cell safety net). */ maxCostUsd?: number; /** The shared token cap. Default 8000. */ maxTokens?: number; /** The shared turn cap. Default 12. */ maxTurns?: number; /** πŸ”΄ Model pricing (USD per 1M tokens) β€” REQUIRED. C1 (the cost half of the value Pareto) is computed locally by * core from these rates; if they are 0, C1 is a fabricated $0 across ALL arms AND the maxCostUsd gate never binds * (review HIGH finding). The gate REQUIRES costInput+costOutput > 0 so a live run can never silently * fake the cost dimension. */ costInput: number; costOutput: number; costCacheRead?: number; costCacheWrite?: number; } /** Build the live runtime config from env. GATED on E2B_API_KEY + DEEPSEEK_API_KEY + non-zero MODEL_COST_INPUT/OUTPUT * (so C1 is real and maxCostUsd binds). Returns undefined when a required key/price is absent β€” the driver then * refuses the live path with a clear message (never a silent fake run, never a fabricated $0 cost axis). */ export declare function liveRuntimeConfigFromEnv(env?: NodeJS.ProcessEnv): LiveRuntimeConfig | undefined; /** A built-and-bound live cell β€” the worker + grader sandboxes + the deps, with a dispose() that reaps both. */ export interface LiveCell { deps: ProfileDeps; /** Reap BOTH sandboxes (worker + grader). MUST be called by the driver after the row is emitted (or on timeout). */ dispose: () => Promise; } /** * πŸ”΄ THE FACTORY β€” build a REAL `ProfileDeps` bound to ONE (trap, seed) cell. Provisions a worker E2B sandbox + a * DISTINCT grader E2B sandbox (lazily, on first seam call), wires every seam to the REAL core engine/oracle, and * returns `{ deps, dispose }`. The driver calls one `buildLiveDeps` per cell and `dispose()`s it after the row. * * @param rt the live runtime config (DeepSeek + E2B keys + the shared budget). * @param trap the class-C trap this cell runs. * @param seed the cell's seed (provenance; the durable-approval scope keys on it via buildSupImplSpec). * @param cellId a stable id for the cell (used as sandbox metadata for fleet observability). */ export declare function buildLiveDeps(rt: LiveRuntimeConfig, trap: TrapSpec, seed: number | string, cellId: string): LiveCell; /** The per-cell base TaskSpec every arm's leaf projects from. EXPORTED so the shape test measures the REAL spec * handed to the runner (the BUDGET-MATCH anchor is spec.limits, not the harness's own RowBudget echo). */ export declare function benchBaseSpec(rt: LiveRuntimeConfig, cellId: string): (objective: string) => TaskSpec; /** Project a `SoloImplSpec` (budget already stamped by the harness, all keys in `limits`) onto the bench base TaskSpec. */ export declare function toTaskSpec(base: (objective: string) => TaskSpec, impl: SoloImplSpec): TaskSpec; /** Project a `SupImplSpec` onto the bench base TaskSpec PLUS the durable wiring (checkpointStore + ask policy). */ export declare function toSupTaskSpec(base: (objective: string) => TaskSpec, impl: SupImplSpec, trap: TrapSpec): TaskSpec; //# sourceMappingURL=live-deps.d.ts.map