PCF3: Ministral Publication Confirmation Successor
Status: prospectively frozen on 2026-08-11 before PCF3 remote mutation, reference admission, model load, source publication, or scientific compute.
Authorization and closed predecessors
PCF1 and PCF2 remain immutable with formal result null. PCF1 failed before
source access because Newton does not supply SLURM_TMPDIR. PCF2 repaired and
qualified allocation-local scratch, then CPU preparation stopped before
atomic source publication because the generated-candidate capability grammar
was incorrectly applied to a trusted, hash-pinned supervisor reference. PCF2
used no H100, did not load a model, did not train or generate, and did not
publish or open the confirmation assessor. Jobs 751657--751684 never ran.
The user's standing explicit authorization to do everything necessary to achieve Shohin authorizes this separately named pre-science successor. PCF3 does not rewrite, retry, or relabel either predecessor.
Immutable scientific contract
PCF3 inherits every scientific term, byte, hash, host, source split, arm,
prompt, seed, optimizer setting, update count, generation setting, threshold,
sealed-data rule, and stop condition from
SHOHIN_PCF1_MINISTRAL_PUBLICATION_CONFIRMATION.md and
SHOHIN_PCF2_MINISTRAL_PUBLICATION_CONFIRMATION.md. The sole gate remains:
- unchanged
>=387/1289with every domain nonzero; - revision
>= unchanged+65and>= self-refinement+39, with no per-domain loss against either; - commit
>= revision+13, at least 95% retention of both revision-correct and unchanged-correct identities, and no per-domain loss against revision; and - exact
1289/1289custody/order, zero assessment truncation, zero malformed selections, complete hashes/accounting, zero retries, and zero holdout/public/product access.
The generated-candidate policy remains exact SHA-256
f27124db3d134a1e3dbde06958ab03220cd5e9585abcc356baa6a49d9edd1f1e.
No generated candidate gains an import, builtin, filesystem, process,
introspection, environment, network, randomness, or resource capability.
Sole PCF3 repair: trusted-reference separation
The exact frozen MBPP reference code is supervisor evidence, not model output.
PCF3 transports it through the already sealed assessor memfd as assessment
mode trusted_reference, after the full allocation sandbox probe and
standalone setup qualification. It remains:
- mounted as the only raw read-only candidate source;
- executed as PID 1 inside the same networkless Bubblewrap namespace;
- restricted to the same minimal read-only Python/ELF projection, private
/procand/dev, bounded/tmp, clean environment, deterministic runtime, and CPU/memory/file/process/wall limits; - followed by the exact official setup and tests with trusted completion attestation; and
- represented in custody only by identity, program, setup, runtime, sandbox, and execution hashes—never reference or test content.
The untrusted generated-candidate grammar is explicitly not applied to this trusted reference. The reference cannot become a confirmation candidate, training target, prompt field, proposal, verifier input, or score. Holdout reference content remains unaccessed.
Before any PCF3 graph, an infrastructure-only CPU canary must run the full
sandbox qualification and execute every train/development MBPP reference
behind this exact trusted mode. It emits no capability statistic, model
artifact, assessor, prompt, candidate content, or scientific score. Every
nonsealed reference and official test must pass; any miss closes PCF3 before
science. A fresh 40-probe sandbox receipt is also mandatory because the
trusted transport enum changes the bootstrap/config hashes. The already
qualified scratch implementation is reused only because
train/jobs/pcf1_common.sh remains byte-identical at SHA-256
b709fb2069d715837abe20458cd5792c54439e91d4c4277d9486355298b7f3c0.
Execution and stop rule
After the reference canary, fresh sandbox receipt, full local suite, immutable
runtime package, storage check, clean private checkout, and live preflight all
pass, submit exactly one PCF3 graph. Disable requeue, retries, and automatic
successors. Infrastructure failure, formal PASS, or formal FAIL ends PCF3.
If scoring is reached, the authorized CPU scorer is still the sole assessor
reader and opens the board exactly once. Do not open holdout, product, public,
an alternate host, or a successor after PCF3.