virtuoso_models — Independent Verification + Integration Report

Date: 2026-07-08 · Branch: claude/virtuoso-models-integration-fvhjow · Base: origin/main @ 515f609 Re-run everything: python3 -m pytest tests/shared/ -c tests/shared/pytest.ini (37 tests)

Every claim below is backed by a command, diff, or output in this branch's commits. Bold items contradict the package's own documentation or the repo's CLAUDE.md claims.


Step 0 — Package ingest

No virtuoso_models.zip exists anywhere in the environment (the prompt's <FILL IN> path was never provided). The package was already present at both canonical homes, byte-identical to each other (diff -r --exclude=__pycache__ clean):

Branch note: the prompt asked for feat/virtuoso-models-integration; this session's binding instructions mandate claude/virtuoso-models-integration-fvhjow. All work is on the latter.

Locked rules, in one paragraph (re-derived from model_registry.py, not the docs): every LLM call resolves through one frozen registry that pins four roles to in-family flagships — DATA_CAUSAL→Google (gemini-3.1-pro-preview base, auto-flipped to gemini-3.5-flash because GEMINI_35_FLASH_IS_GA=True, a deliberate Boss cost/latency override of "capability over cost"), CODING_ARCH→claude-opus-4-8, CREATIVE_MM→gpt-5.5, DEVOPS_OPS→grok-4.3. The in-family lock binds the primary path only; every role cross-vendor fails over to the single global backup claude-opus-4-8, which fires only after a primary failure, is tagged served_by="global_fallback" + primary_error, can be disabled per call (fallback=False re-raises), and may never silently become a primary (assert_fallback_not_primary; CODING_ARCH legitimately shares the string, so its failover is a re-raise). Retired strings are rejected at startup (assert_no_legacy_strings, config-scan and registry-self-audit modes); model strings live only in the registry (get_model(Role.X).model); JourneyEvents get deterministic event_id = sha256(source||type||stable_keys) and an idempotent gate that compare-and-sets on source_payload_hash (insert/update/duplicate); provenance (response_schema_hash, connector_version) is stamped from the live schema, never by hand; the Phase enum is seven-phase SRPVDAL by schema fiat.

Step 1 — Independent code audit

Prior-fix verification (all three real)

Past bug Evidence it is fixed
Missing assert_fallback_not_primary import vendor_adapters.py:24-26 imports it; called at virtuoso_call entry
Missing fallback exports __init__.py exports GLOBAL_FALLBACK, get_fallback, assert_fallback_not_primary, virtuoso_call, VirtuosoResponse
Sticky-mutation in get_model() Returns dataclasses.replace(spec, model=resolved) copy; ModelSpec is frozen=True; proven by test_flip_on_off_reverts_and_registry_never_mutates

NEW bugs found (all proven at runtime before fixing — commit fbb5f52)

# Bug Runtime proof Blast radius
A call_gpt referenced undefined kwargs (no **kwargs in signature) NameError: name 'kwargs' is not defined on every call Every CREATIVE_MM call died pre-API; with default fallback=True it was silently served by claude-opus-4-8 forever (tagged, but 100% degraded)
B call_grok: same undefined kwargs same NameError Every DEVOPS_OPS call permanently degraded to fallback
C virtuoso_call dispatch passed system=/tools= twice (explicit + **kwargs) TypeError: ...got multiple values for keyword argument 'system' Any call with a system prompt never reached its primary vendor; for CODING_ARCH it raised outright
D virtuoso-models-service startup guard caught assert_no_legacy_strings failures and only logged code read, main.py:55-60 Guard contract is refuse-to-boot; a poisoned registry would have served traffic
E journey_event.validate raised jsonschema.ValidationError (foreign type) on the strict path but package ValidationError on the fallback path test test_malformed_event_fails_validation_with_package_error fails pre-fix The deployed service (jsonschema==4.26.0 in its requirements.txt) returned HTTP 500 instead of 422 for schema-invalid normalized events

Why A/B/C survived earlier audits: py_compile passes (NameError is a runtime error), and a naive AST scan is fooled because call_claude has a local kwargs = dict(...). The package's "verified in isolation" claim cannot have included a single real (or even stubbed) call_gpt/call_grok invocation, nor any virtuoso_call(..., system=...).

Fixes: uniform (messages, system=None, tools=None, **kwargs) adapter signatures; dispatch passes kwargs exactly once; GPT structured output moved to the Responses-API text.format param (old code passed response_format, which is a Chat-Completions param — flagged live-verify); optional params only sent when set; guard re-raises; validate() normalizes to the package exception. Both homes kept byte-identical (enforced by test_vendored_home_matches_lib_home).

Test suite

tests/shared/test_virtuoso_models.py — 33 tests, all passing: 4-role resolution, flip on→off reversibility + REGISTRY integrity, env-override precedence, forbidden-override refusal, legacy guard (raise/pass/self-audit), fallback-not-primary guard, failover tagging, fallback=False re-raise, CODING_ARCH self-loop, regression tests for bugs A–C, deterministic event_id, gate insert→duplicate→updated, all 4 mappers strict-validated (real jsonschema + independent recursive additionalProperties walker), malformed-event negative paths on both validation branches, ingest_gate missing-id refusal, boss_plane surface, vendored parity, and schema_hash pinned to the live deploy (823d6116b33c… — post-fix hash is unchanged, so net schema change vs production is zero).

Step 2 — Repo reality check

Retired/superseded model strings

The full grep found 140 hits across ~34 files (excluding the package itself). This contradicts the repo CLAUDE.md v6.45.10 claim of a completed "MIZ OKI 3.5 Model String Purge." Status table (grouped; full per-line evidence is in the commit diffs):

Location Strings Status Action taken
boss_agent_core.py ×5 live AnthropicVertex streaming calls claude-opus-4-6 RETIRED/forbidden → CLAUDE_PRIMARY_MODEL via registry (2810003)
boss_agent_core.py Gemini sites + /models listing gemini-3.1-pro-preview literals, gemini-2.0-flash-001 SUPERSEDED-hardcode / RETIRED → GEMINI_PRIMARY_MODEL via registry
boss modules: event_ingestion_integration, data_transformation_engine, gemini_data_pipeline_v2 gemini-2.0-flash (SHUT DOWN 2026-06-01) RETIRED → registry-resolved defaults
dynamic_orchestrator.py MOA templates gemini-2.0-flash-exp, -thinking-exp, chatgpt-5.4, grok-2-1212 RETIRED/SUPERSEDED → registry lookups
session_manager, ai_creative_marketing_automation, agent_runtime_ledger claude-opus-4-6*, chatgpt-5.4, grok-4.1, imagen-3 RETIRED/SUPERSEDED → current registry strings
boss config YAMLs (boss_agent_knowledge_graph, creative_automation, gemini_data_pipeline, config.yaml ×2) claude-opus-4-6-20260201 ×11, chatgpt-5.4 ×12, gemini-2.0-flash RETIRED 27 replacements (2810003) — these would have hard-failed the startup guard the repo claimed was already wired
src/shared/model_registry.py (the OLD registry) pinned chatgpt-5.4, claude-opus-4.6, grok-4.1; listed gemini-3.1-pro-preview (the package's DATA_CAUSAL base) as LEGACY CONFLICTING SOURCE OF TRUTH now resolves through virtuoso registry, env overrides preserved (4b64ca7)
claude-gemini-orchestrator (app + cloudbuild), UI configs gemini-2.0-flash-exp, chatgpt-5.3-codex, chatgpt-5.4 RETIRED/SUPERSEDED replaced (23d7fd0, 439bdb1)
tests/test_integration_srdal_pipeline.py expected ["…","claude-opus-4.6","chatgpt-5.4","grok-4.1"] STALE TEST updated to current strings
.evaluation/incoming/model_registry.py + vendor_adapters.py tracked stale May-31 drop (pre-fallback semantics) STALE STAGING COPY flagged, not deleted (punch list #6) — contradicts the package CLAUDE.md claim that staging copies were removed
archive/, local_dev/ mocks, docs various ARCHIVE/MOCK untouched by design
remaining live-code hits after purge 0 (residuals are deny-list definitions + my own comments) — verified by re-grep

LLM call-site inventory (full table in the audit transcript; highlights)

Call-shape conformance (primary direct-SDK sites vs adapter encoding)

Site Shape issue vs adapter
boss messages.stream(...) AnthropicVertex No effort, no adaptive-thinking param; model naming dialect differs (Vertex Anthropic IDs vs claude-opus-4-8 API string) — live-verify on Vertex (punch #2)
moa/models.py, multi_model_client.py Route "grok"/"chatgpt" labels through Vertex Gemini/Anthropic classes — model strings resolve via old registry (now virtuoso-backed) but no true xAI/OpenAI path exists outside virtuoso_call
GenerativeModel(...) Vertex sites No thinking_level; passing gemini-3.5-flash string is registry-consistent; converting to virtuoso_call is punch #4 (streaming/multimodal shapes prevented mechanical conversion now)

SRDAL vs SRPVDAL verdict

The repo is a three-way mix; the package's 7-phase enum matches the newest canonical code but not the Boss execution path.

  1. 7-phase, VALIDATE spelling (= package enum, no conflict): contracts/canonical-event-envelope (PHASES, line 48), src/core/srpvdal.py, src/core/srdal.py (misnamed file, 7-phase body), src/cells/google_ads_gaql, plugins/ads-decision/intelligence/srpvdal.py, boss kg_instrumentation_layer_integration.py.
  2. 7-phase, VERIFY spelling (CONFLICTS): the whole boss ADC family — srdal_adc.py, srpvdal_plan_verify.py, srpvdal_autonomous_integration.py ("strictly called VERIFY", line 794), semantic_tool_router.py (aliases VALIDATE = "verify"), graph_native_decision_intelligence.py, others. Events these stamp would fail the JourneyEvent srpvdal_phase enum.
  3. 5-phase SRDAL (CONFLICTS): src/core/pipeline_state.py, boss_agent_core.py (line ~25730), connector_gateway/srdal.py, customer-journey-system (named SRPVDAL, only 5 stages), command-center backend. Even the repo's own PR template says "Sense -> Reason -> Decide -> Act -> Learn".

No phase handling was changed (per ground rules). Reconciliation needed: either add VERIFY to the schema enum or rename the boss ADC phase to VALIDATE — one edit, both sides together (punch #7).

Step 3 — Integration edits (commits, one per cell/service)

Commit Scope
fbb5f52 Package bug fixes (A–E) + 33-test verification suite, both homes
4b64ca7 src/shared/model_registry.py → resolves through virtuoso registry (verified output: opus-4-8 / gpt-5.5 / gemini-3.5-flash / grok-4.3; env overrides still win)
2810003 Boss cell: 5 live call sites + Gemini sites → registry constants; Dockerfile.v5 ships shared/; startup legacy-string guard wired (dry-run proven clean against every boss YAML first); config YAML purge (27 strings)
23d7fd0 UI configs, claude-gemini-orchestrator, provenance template, stale test, moe/moa docstrings
91cf762 gemini-kg-pipeline: real upsert_fn — Firestore transactional CAS on source_payload_hash (journey_events/virtuoso_ingest.py), SENSE ingress POST /api/v1/journey-events/virtuoso/{source} for all 4 connectors, startup guard hardened from log-only to refuse-to-boot, ANTHROPIC_API_KEY documented in deploy.sh; bridge tests
439bdb1 Final stragglers (orchestrator cloudbuild env, test fixture)

Event-store conflict (flagged, not silently resolved): gemini-kg-pipeline already has its own JourneyEvent system (pydantic contract, dedup_key, Firestore journey_events collection with merge=True — no CAS, no inserted/updated/duplicate distinction) whose schema differs from the package's canonical journey-event.json. The new gate therefore writes to a separate virtuoso_journey_events collection keyed by event_id. Merging the two shapes needs a migration decision (punch #8).

ANTHROPIC_API_KEY coverage (required everywhere virtuoso_call runs — the global fallback needs it)

Service Key present?
boss-agent-adk (cloudbuild.v5.yaml) ✅ (anthropic-api-key:latest)
coding-moa ✅ (coding-moa-anthropic-key)
gemini-kg-pipeline (uses virtuoso_call) ❌ missing — documented in deploy.sh this branch; operator must run the --update-secrets command (punch #1)
creative-suite-service (uses virtuoso_call) ❌ missing from its cloudbuild (punch #1)
miz-oki-adk-agents/specialists/* (whichever service ships them) verify at deploy (punch #1)
virtuoso-models-service n/a by design (registry viewer, no LLM proxy)
google-ads-gaql-cell, cell06 no LLM calls found — not required today

Step 4 — Live connection proofs

Environment reality: GEMINI_API_KEY / ANTHROPIC_API_KEY / OPENAI_API_KEY / XAI_API_KEY all unset; no GCP ADC (gcloud unconfigured); no vendor SDKs installed; Docker daemon unavailable. Nothing below is simulated-and-called-live.

Proof Status Evidence
1. One live LLM call per role (served_by="primary", latency, tokens; Vertex flash / opus effort=xhigh no-temperature / GPT Responses API / grok reasoning_effort) BLOCKED — no vendor keys, no SDKs, no ADC Adapter request shapes verified against stubbed SDK spies (models, reasoning={'effort':'high','summary':'auto'}, reasoning_effort='high', text.format json mode, no temperature anywhere) in the test suite
2. Failover proof (break Gemini → served by opus-4-8) + fallback=False re-raise BLOCKED live (needs a valid Anthropic key for the backup to answer) Mechanics fully proven mocked: served_by="global_fallback", primary_error="ConnectionError: gemini down", re-raise on fallback=False, CODING_ARCH self-loop re-raise — TestVirtuosoCallFailover (5 tests)
3. JourneyEvent E2E into the real store (insert → duplicate → updated, query back) BLOCKED for Firestore (no ADC) Full cycle proven through the actual production service: live POST /normalize/meta on virtuoso-models-service returned event_id 754e8fcc… / payload_hash af88f374… — byte-identical to the local mapper on the same vector (determinism across build+network boundary). CAS insert→duplicate→updated proven against the bridge's in-memory CAS; the Firestore transaction implements the same compare-and-set
4. Gemini structured output vs schema BLOCKED live gemini_response_format() verified to carry the canonical schema verbatim (strict:true, schema_hash 823d6116… matching the live /health)
Bonus live proofs (real production traffic, no keys needed) ✅ Live /health: {data_causal: gemini-3.5-flash, coding_arch: claude-opus-4-8, creative_mm: gpt-5.5, devops_ops: grok-4.3}, global_fallback: claude-opus-4-8; live /guard?text=grok-4-1-fast-reasoning → HTTP 422 with the exact violation

Step 5 — Deploy readiness


Punch list before production traffic (priority order)

  1. Mount ANTHROPIC_API_KEY on gemini-kg-pipeline and creative-suite-service (--update-secrets=ANTHROPIC_API_KEY=anthropic-api-key:latest). Until then their virtuoso_call failover path throws instead of failing over.
  2. Run the four live per-role calls + the real failover drill (Step 4 items 1-2) with real keys; specifically live-verify (a) gemini-3.5-flash on Vertex location=global incl. causal quality vs 3.1 Pro (registry REVIEW_TRIGGERS item), (b) opus-4-8 effort=xhigh accepted, (c) GPT Responses-API text.format json mode on the installed openai SDK, (d) whether AnthropicVertex in boss accepts the claude-opus-4-8 string or needs a Vertex-dialect model ID.
  3. Migrate the 4 legacy google.generativeai files to google-genai (kg-pipeline extraction_engine + files_handler, cell03 gemini_structurer — still pinned gemini-1.5-pro — and boss data_transformation_engine).
  4. Convert the remaining direct Vertex GenerativeModel call sites (boss, moa/models, budget_allocator, gemini_stitcher, templates parser) to virtuoso_call where the shape allows; they now source strings from the registry, but bypass failover/tagging/MII capture.
  5. Delete or repoint the dead PaLM text-bison* sites (graphrag-integrated, cell03 GraphRAG ×2, scripts) — those models are long retired.
  6. Remove the stale tracked drop at .evaluation/incoming/ (pre-fallback semantics; future greps/agents will keep tripping over it).
  7. Decide the phase-name reconciliation (schema VALIDATE vs boss ADC VERIFY vs 5-phase SRDAL cluster) and change schema + stampers together.
  8. Decide the JourneyEvent store unification: pydantic journey_events (dedup_key) vs canonical virtuoso_journey_events (event_id CAS) — one schema, one collection, one migration.
  9. Wire startup guards into the remaining FastAPI cells (google_ads_gaql, cell06, creative-suite) — pattern is now proven in boss + kg-pipeline + the service.
  10. Run the E2E Firestore CAS proof from an authorized environment (insert → duplicate → updated → query back) and add pricing verification for opus-4-8/gpt-5.5/grok-4.3 in agent_runtime_ledger.MODEL_COSTS.
  11. Feed plane.call() / MII reasoning-trace rows into the mii.reasoning_traces BigQuery sink (WIRING §6) — currently JSONL-local only.

Post-merge reconciliation (2026-07-08, same day)

On push, the repo's auto-merge bot immediately merged this branch into main (a690f26, "theirs strategy") — and a second, concurrent Claude session had been pushing overlapping virtuoso work to main in parallel (35551a8 BigQuery stores.py + boss SENSE gate, b25b9a2 purge incl. the live xai-bridge XAI_MODEL=grok-4.1 deploy config, 25c340b its own REPORT.md — overwritten by this file in the merge). The blind merge produced three regressions, all caught by this branch's test suite / runtime probes and fixed in the follow-up commit:

  1. virtuoso_call silently dropped every system prompt and tool — the other session popped system/tools from kwargs; my dispatch forwarded only the remaining kwargs; combined, both were popped then discarded. Caught by test_regression_system_and_tools_kwargs_reach_primary (assert None == 'be terse'). Fixed: explicit single forwarding on both the primary and fallback paths.
  2. Boss ingest_single broke on every call — the merge kept the other session's gate call sites (_JOURNEY_MAPPERS / _journey_ingest_gate / self._journey_upsert) but dropped their definitions; proven at runtime (AttributeError: ... has no attribute '_journey_upsert'). Fixed by grafting the reconciled import block + dataclass field + initialize wiring from 35551a8; runtime probe now: ingest_single success: True.
  3. Vendored-home drift — stores.py landed only in the lib home; the deployed service image would not have shipped it. Caught by test_vendored_home_matches_lib_home; homes re-synced.

Post-reconciliation: 37/37 tests green on the merged tree.

New punch item (12): stores.py's MERGE writes context_json / provenance_json columns, but the package DDL (schemas/journey_events.bigquery.sql) declares context / provenance STRUCTs — the SQL and the DDL disagree; reconcile before the first live BigQuery ingest. Also note there are now TWO real upsert paths (BigQuery MERGE via boss stores.py, Firestore CAS via gemini-kg-pipeline virtuoso_ingest.py) — complementary, but punch #8 (store unification) now covers three shapes, not two.

Process note: the auto-merge bot merges claude/* on push with no CI gate in between — two concurrent sessions plus "theirs strategy" produced a broken main for ~30 minutes. Recommend requiring the test suite (tests/shared/) as a merge gate for the bot.


Session addendum — 2026-07-08 (branch feat/virtuoso-models-integration)

Independent re-verification pass, run from scratch on main @ adf09545 (post-regression-repair), per the "do not trust prior claims" ground rule. Every result below was re-derived; commands are re-runnable as shown.

Step 0/1 re-verification (independent)

Step 2 stragglers found by widening the grep (NEW this session)

The WIRING §2 grep misses non-retired-but-wrong strings. Widening to all "(gemini|claude|gpt|grok|chatgpt)-…" literals in active LLM call-site files found four bugs prior passes missed — all four contradict the repo's own "purge complete" commit messages:

File Was Status Fix (this branch)
src/shared/marketing/toolkit.py:26 grok-3 default RETIRED (in DEVOPS_OPS forbidden_legacy) registry-resolve → grok-4.3 (00a0fcde)
services/gemini-kg-pipeline/src/gemini/extraction_engine.py GeminiModel.FLASH_2_5="gemini-2.5-flash" (the service DEFAULT, main.py:149), FLASH_1_5="gemini-1.5-flash", PRO_1_5/2_5="gemini-3.1" FORBIDDEN / retired / never-callable enum values registry-resolved; member names kept as aliases (718fce70)
services/cell03-intelligence/.../gemini_structurer.py:21 gemini-1.5-pro RETIRED (404s live) env > registry > base resolution (8f1addab)
miz-oki-command-center-ui/claude-gemini-orchestrator/app/main.py claude-3-opus@20240229, claude-3-haiku@20240307, claude-sonnet-4-6@20260201, plus MOA defaults claude-4.1-sonnet/gemini-3.1-pro/grok-4.0-heavy RETIRED / SUPERSEDED / invalid registry-resolved with env overrides; LIVE-VERIFY AnthropicVertex @-format (ab824d0f)
miz-oki-adk-agents/boss/gemini_firestore_kg_pipeline.py:109 hardcoded gemini-3.1-pro-preview default CURRENT but bypassed registry registry-resolve, GFK_GEMINI_MODEL override kept (fe575fe2)

Not changed, flagged only: local_dev/ mock strings (never call APIs); .evaluation/incoming/ (stale quarantine copy of the package — recommend deleting); grok-2-image (xAI image gen is outside registry scope); data_transformation_engine.py:54 is only the ImportError fallback constant of an already-registry-routed default (correct as-is).

Step 3 secrets audit (ANTHROPIC_API_KEY = global-fallback requirement)

Of the LLM-calling services: boss (cloudbuild.v5.yaml), coding-moa, and claude-gemini-orchestrator have ANTHROPIC_API_KEY. Missing it: services/virtuoso-models-service (registry/ingest only today — needed the moment it proxies calls), services/cell03-intelligence, services/gemini-kg-pipeline (both call Gemini; their global fallback cannot fire without the key). 25 further cell manifests set secrets but not this one — most don't call LLMs; wire it only where virtuoso_call lands.

Step 4 live proofs — what was possible from this VM

No vendor API keys and no GCP ADC exist in this environment (checked env + ~/.config/gcloud: absent). Therefore:

Step 5

Updated punch list (priority order)

  1. Provision the four vendor keys (or Vertex ADC) in a controlled env and run the Step-4 live matrix: one virtuoso_call per role, echo served_by, latency, token counts; Claude effort=xhigh accepted; GPT-5.5 via Responses API; Grok explicit reasoning_effort=high.
  2. Failover live proof: poisoned GEMINI_API_KEY in an isolated env → DATA_CAUSAL served by claude-opus-4-8 with primary_error set; then fallback=False re-raise.
  3. Reconcile stores.py MERGE columns (context_json/provenance_json) vs DDL (context/provenance STRUCTs) before first live BigQuery ingest.
  4. Wire ANTHROPIC_API_KEY into gemini-kg-pipeline, cell03-intelligence, virtuoso-models-service deploy configs (global-fallback prerequisite).
  5. Redeploy stale services so the July 6-8 fixes reach Cloud Run (bot-merged commits do not trigger push-filtered deploy workflows; see fleet audit).
  6. LIVE-VERIFY the AnthropicVertex model-ID format in claude-gemini-orchestrator (@-suffix vs bare); override via CLAUDE_CODE_MODEL if needed.
  7. Vendor the shared lib (or add env pins) into images that can't import it: cell03-intelligence, claude-gemini-orchestrator.
  8. Delete .evaluation/incoming/ (stale package copy) once confirmed unused.
  9. Migrate google.generativeai (legacy SDK) call sites to google-genai: gemini-kg-pipeline/extraction_engine.py, cell03 gemini_structurer.py, boss gemini_firestore_kg_pipeline.py.
  10. Add the tests/shared/ suite as a CI gate on the auto-merge bot.
← All docsView source on GitHub →