From dd37094a5b3ee684678bd2c013620485528e7fa7 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Mon, 5 Oct 2026 21:31:06 +0000 Subject: [PATCH] ember-tune.md: a signed prior is a starting point inside the card's own reported limits, never a memory clock; the tests that prove the clamp (consequences row C25) Co-Authored-By: Claude Fable 5.1 --- docs/plans/ember-tune.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/plans/ember-tune.md b/docs/plans/ember-tune.md index 22869c77..f0d93f1d 100644 --- a/docs/plans/ember-tune.md +++ b/docs/plans/ember-tune.md @@ -96,6 +96,7 @@ race has run). | Faults: a rejected or mismatched hash marks the step; the card leaving `mining`, a worker error, a job, a pause or 90 C aborts the run and restores the point from before | `Run::sample_fault`, `sweep_drive`, `sweep_abort` | | Memory clock held: never set; a step that drags it under 95% of the baseline's cannot win | `Row::from_samples` | | Vendor limits: every point clamped to the reported range; the clock floor 60% when none is reported | `Limits` | +| A signed prior is only ever a starting point inside the card's OWN reported limits (`power.min_limit` to `power.max_limit`, the clock floor to `clocks.max.gr` or the ADLX `gmax_range`), never a memory clock, never a value the card did not report; the confirm step measures it and the full plan replaces it when a neighbour beats it, so a bad prior costs the fleet one confirm step per card, not a setting. The signing key (K1, docs/security/keys.md) therefore cannot push a card past its vendor ceiling or under its floor | `Plan::confirm` clamps through `Limits::clamp_clock` and `power_pct.clamp(50, 100)`; proven by `ember::tests::the_confirm_plan_checks_the_prior_and_its_neighbour` (a prior of 9,000 MHz at 30% becomes 3,090 MHz at 50%) and `limits_never_exceed_the_vendor_or_undercut_the_floor` | | No prompt the user did not ask for: the NVIDIA helper starts only with Power control on; the `--sweep` job never counts as permission | `sweep_probe_known`, `sweep_helper_start` | | The elevated helper restores the limit and resets the clocks by itself after 20 idle minutes | `sweep::helper_script_*` |