_runtime_amp_failsafe's SUSPECT label is uninformative under vmap — i.e. on every production path
Summary
anglemarg._runtime_amp_failsafe records a "this call's amplitude exceeded the
size the dense grids were built for" label via jax.debug.callback, guarded by
jax.lax.cond. Under vmap a batched predicate lowers to a select, so both
branches execute, and the callback branch passes a literal True rather
than the predicate — so _record_amp_failsafe cannot distinguish tripped from
not-tripped.
Every --mode flowmc-* run with --angle-marg-scheme exact or laplace is
therefore labelled SUSPECT regardless of whether it is, and a genuinely
undersized run is indistinguishable from a sound one. The label is
uninformative in both directions on exactly the path it exists to guard.
Measured
Sound run, predicate false by four orders of magnitude (amp_sizing forced to
1e12 against a worst reported amplitude of 10.49):
| transformation |
tripped |
n_calls |
| plain call |
False |
0 |
under jit |
False |
0 |
under vmap |
True |
2 |
Reproduction: build any likelihood data, call _runtime_amp_failsafe three ways
(plain / jit / vmap) with a deliberately huge amp_sizing, and read
anglemarg._AMP_FAILSAFE after jax.effects_barrier().
Why it matters beyond the label
Two independent sessions were on the point of using the label's cleanliness as
evidence of a method's soundness for paper 1. It cannot serve that purpose. A
label named SUSPECT that is True on a sound run is worse than no label,
because it invites exactly that use.
Suggested fix
Evaluate the intended predicate on the HOST — compare the max reported amplitude
against AMP_FAILSAFE_TRIP_FACTOR * amp_sizing there — or pass the traced
predicate into the callback instead of a literal, so the record reflects it.
Also, adjacent and probably the same fix
The comment block at anglemarg.py ~:570-577 promises "a POISON term the caller
ADDS to its result ... FAIL CLOSED". The function returns None, both call
sites discard it, and the block immediately below retracts the design and
explains why. Two adjacent contradictory blocks, the first of which reads as a
contract.
Provenance
Pre-existing; NOT introduced by #221. Found independently by the chip-05
session and confirmed by the measurement above during #221's review.
Deliberately not folded into #221 (pre-existing, needs its own validation).
DESIGN_jax_distance_quadrature.md section 5(a) records it and instructs
readers to treat the fail-safe as ABSENT on any vmapped path — but a design-note
caveat does not stop the next person building a soundness check on the label,
which is why this is filed.
_runtime_amp_failsafe's SUSPECT label is uninformative undervmap— i.e. on every production pathSummary
anglemarg._runtime_amp_failsaferecords a "this call's amplitude exceeded thesize the dense grids were built for" label via
jax.debug.callback, guarded byjax.lax.cond. Undervmapa batched predicate lowers to aselect, so bothbranches execute, and the callback branch passes a literal
Trueratherthan the predicate — so
_record_amp_failsafecannot distinguish tripped fromnot-tripped.
Every
--mode flowmc-*run with--angle-marg-scheme exactorlaplaceistherefore labelled SUSPECT regardless of whether it is, and a genuinely
undersized run is indistinguishable from a sound one. The label is
uninformative in both directions on exactly the path it exists to guard.
Measured
Sound run, predicate false by four orders of magnitude (
amp_sizingforced to1e12 against a worst reported amplitude of 10.49):
trippedn_callsjitvmapReproduction: build any likelihood data, call
_runtime_amp_failsafethree ways(plain /
jit/vmap) with a deliberately hugeamp_sizing, and readanglemarg._AMP_FAILSAFEafterjax.effects_barrier().Why it matters beyond the label
Two independent sessions were on the point of using the label's cleanliness as
evidence of a method's soundness for paper 1. It cannot serve that purpose. A
label named SUSPECT that is
Trueon a sound run is worse than no label,because it invites exactly that use.
Suggested fix
Evaluate the intended predicate on the HOST — compare the max reported amplitude
against
AMP_FAILSAFE_TRIP_FACTOR * amp_sizingthere — or pass the tracedpredicate into the callback instead of a literal, so the record reflects it.
Also, adjacent and probably the same fix
The comment block at
anglemarg.py~:570-577 promises "a POISON term the callerADDS to its result ... FAIL CLOSED". The function returns
None, both callsites discard it, and the block immediately below retracts the design and
explains why. Two adjacent contradictory blocks, the first of which reads as a
contract.
Provenance
Pre-existing; NOT introduced by #221. Found independently by the chip-05
session and confirmed by the measurement above during #221's review.
Deliberately not folded into #221 (pre-existing, needs its own validation).
DESIGN_jax_distance_quadrature.mdsection 5(a) records it and instructsreaders to treat the fail-safe as ABSENT on any vmapped path — but a design-note
caveat does not stop the next person building a soundness check on the label,
which is why this is filed.