Repository navigation
howl_guard: a LOST in probation is a strike, default on (cabin's duck cycle); TwoMicSmoke honours MUTAP_SLOW_THREADS - #88
Merged
Conversation
…; ships off A policy option: a LOST in OPEN within probation_s is a strike, as a TRIP there is (the safety design note's alternative for F -> 2F). Measured on the live loop, off -> on (macOS x86_64, AppleClang 17, Release): - Cabin under F -> 2F, 30 s: 7 -> 7 LOST-ducks in the 2 gated runs, 18 -> 17 in the 5 sweep runs (median 4 -> 3 a run). Over 120 s: 72 -> 19 (median 19 -> 4 a run); every cabin run latched at the cap (-11.89 dB) a median 23.27 s after the change and ducked no more. - The other five rooms: one strike from the change's own LOST (inside the cold start's probation), level -3.00 dB, the re-arm at 10.00 s instead of 5.00; no new duck; 0 howl blocks. - Cold start (126 gated, 690 sweep runs), stable material, two mics, soundcheck rows: identical. Walks at exact - 6: same ducks and release timing, each LOST-duck a strike (0 -> 3 gated, 0 -> 6 sweep). The bar for default ON was at most 1 LOST-duck a run in cabin; it is not met, so the default stays off (behaviour unchanged). LouderCouplingRearms runs every row both ways; the LouderCoupling sweep adds the 120 s rows. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDhgJqxUsdmWPKh6pKrV5A
They spawned one thread per row or seed set (4 and 5) regardless. Now a worker pool sized as test_howl_guard_host.cpp sizes it: at most 4 by default, MUTAP_SLOW_THREADS overrides. The printed numbers are identical before and after, by default and on 1 thread. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDhgJqxUsdmWPKh6pKrV5A
…e default Tim's decision (2026-10-09): the cabin is the karaoke scenario itself; 4 ducks then a capped level beats 19 ducks in two minutes, and the 3 dB / 60 s back-off elsewhere is acceptable. The policy default flips to true. docs/howl-guard.md and the gated comments now describe the default: the F -> 2F main tables are the option-on rows (gated, and the sweep at 30 s and 120 s), the PR C re-arm-hold tables stay as the option-off alternative, and the walks at exact - 6 and the song gap carry their strike counts (3 / 6 walk strikes, 3 gap strikes a room, mt5's gap A' maximum -15.10 dB; 0 with the option off). The gap row prints strikes and the restore level. Re-run on the default-on build: every gated HowlGuardHost row reads as the scratch on-build's, 16 of 16 passed, 755.91 s on 4 threads. LouderCouplingRearms runs the default first and still gates both ways. TwoMicSmoke's comment quotes today's unison numbers (-15.34 .. -10.65 dB, medians -11.18 / -13.60), which had moved from the 2026-09-30 ones by a change the log does not single out. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDhgJqxUsdmWPKh6pKrV5A
bench_aec.cpp's -Wsign-conversion under -DMUTAP_WERROR=ON on AppleClang (CI's bench-smoke builds without -Werror), and run_bank's bit-identity not compared under the Cortex-M / Hexagon toolchains. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDhgJqxUsdmWPKh6pKrV5A
tap
force-pushed
the
feat/guard-probation-strike
branch
from
October 9, 2026 15:45
975b62a to
666339b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two leftovers from the safety layer, plus two HANDOFF items from #87.
1.
guard_policy::lost_in_probation_strikes, default onUnder F → 2F, cabin's verdict holds ok while the mic is ducked. It therefore releases on the walk path, and PR C's re-arm hold cannot reach it. The design note's alternative, counting a LOST in OPEN within probation as a strike, is now a policy option (
include/mutap/howl_guard.h: one branch in OPEN, copied throughset_policy(), the field appended aftercap_db). It is on by default. Tim's decision (2026-10-09): the cabin is the karaoke scenario itself; 4 ducks and then a stable capped level beat 19 ducks in two minutes; and the 3 dB / 60 s back-off elsewhere is acceptable. The bar first set for it (≤ 1 LOST-duck a run in cabin) is not met, and no rule that needs three strikes to latch can meet it.All numbers: macOS 15.7 x86_64 (i9-8950HK), AppleClang 17, Release, double, 4 threads.
Headline (default policy; option off in brackets where it differs)
MUTAP_SLOWsweep (six rooms, five seed sets)Cabin, option off → on
What else the default changes (off → on)
docs/howl-guard.md: the main tables are now the default's. The F → 2F section leads with the option-on rows (gated, and the sweep at 30 s and 120 s). PR C's re-arm-hold tables are kept as "measured with the option off". The new section "A LOST in probation as a strike" holds every off → on comparison and the decision. HANDOFF item 12 is updated.Gates:
HowlGuardHost.LouderCouplingRearmsruns the default first and still gates both ways. Every run ducks, 0 howl blocks, at least 4 of 8 re-armed, and at most 4 LOST-ducks after a re-arm. With the option on, cabin must take at least one strike (measured 5), and no other room may end below −6 dB (measured −3.00). Nothing is gated on cabin's duck count. The state-machine suite gainsLostInProbationIsAStrikeWhenEnabled(exact ticks, float and double; the float half runs on both emulated selections). The song-gap row now prints strikes and the restore level.2.
TwoMicSmoke(andTwoMicLoop.DryTwoMicLimitIsTheSummedPaths) honourMUTAP_SLOW_THREADSThese tests spawned 5 and 4 threads regardless of the setting. They now use a worker pool sized the way
test_howl_guard_host.cppsizes it: at most 4 by default, overridden byMUTAP_SLOW_THREADS. The printed numbers are identical before and after, both by default and withMUTAP_SLOW_THREADS=1(diffof the outputs is empty; 17.8 s on 1 thread against 7.1 s by default). The smoke comment now quotes today's unison numbers: uncertainty −15.34 .. −10.65 dB, medians −11.18 / −13.60, misalignment +6.05 .. +14.61. They had moved from the 2026-09-30 numbers, and the log does not single out the change that moved them; the speech rows read as they did then.3. HANDOFF item 8: two open issues found by #87
bench/bench_aec.cppfails-DMUTAP_WERROR=ONon AppleClang (-Wsign-conversion, lines 95 / 115 / 134 / 149). Separately,howl_detail::run_bank's bit-identity has not been compared under the Cortex-M / Hexagon toolchains.Verification (rebased on 00590e5)
cmake -S . -B build -G Ninja -DCMAKE_BUILD_TYPE=Release -DMUTAP_WERROR=ON;ctest --test-dir build: 100% tests passed, 0 tests failed out of 422 (29 skipped: theMUTAP_SLOWsweeps andPortableRandom), 3419.00 s;mutap_fingerprintpassed.HowlGuardHost.*on the default-on build: 16 of 16 passed, 755.91 s on 4 threads. Every table reads as the scratch on-build's, to the last printed digit. After the rebase,LouderCouplingRearmsandSongGapDoesNotRestartwere re-run and are unchanged.howl_guard_test*, validation, RT contract): 42 of 42 passed.HowlGuardSweep.LouderCoupling(30 s and 120 s, on and off): 974.9 s. TheWalks,ColdStartandTwoMicsAndAudibleCostsweeps were run on a scratch build with the option defaulted on (287 s, 2051 s, 619 s) and compared with the option-off build.pre-commit run --fileson the branch's files: passed.scripts/tidy.shon the three changed TUs: clean. A directclang-tidy-18 -p build-tidyon the same TUs (the.clang-tidyheader filter coversinclude/andtests/): 0 warnings. The guard is in no fingerprint or icount workload.🤖 Generated with Claude Code
https://claude.ai/code/session_01DDhgJqxUsdmWPKh6pKrV5A