# Loading the PROCEDURE model assets Repository: `HeyDonto/SURGFIELD-ORena-2026-PROCEDURE-FINAL`. ## Download a pinned snapshot The immutable source release below contains the 85 repaired serving files and unchanged model assets. The original asset release remains `6a7fc05f196b98d751e3a14775d60f1161166d2a`. Its full-download and CPU validation results apply to that earlier snapshot. The current verifier expects the repaired 85-file source tree, so it is incompatible with the earlier 84-file snapshot. ```text ORIGINAL_ASSET_PROVENANCE_REVISION=6a7fc05f196b98d751e3a14775d60f1161166d2a SOURCE_REVISION=0de0658c69a972ce8b92b9742f40beb62c9134f1 ``` ```python import re from huggingface_hub import snapshot_download SOURCE_REVISION = "0de0658c69a972ce8b92b9742f40beb62c9134f1" if not re.fullmatch(r"[0-9a-f]{40}", SOURCE_REVISION): raise SystemExit("Bind the immutable repaired-source commit before downloading") snapshot = snapshot_download( repo_id="HeyDonto/SURGFIELD-ORena-2026-PROCEDURE-FINAL", repo_type="model", revision=SOURCE_REVISION, local_dir="procedure-final-repaired", ) ``` Private-repository access requires locally configured Hugging Face authentication. ## File layout and verification Most files retain their original image paths under `image_root/`: `/app/artifacts/...` maps to `image_root/app/artifacts/...`, and `/app/runtime_zoom_entry.py` maps to `image_root/app/runtime_zoom_entry.py`. [ASSET_MANIFEST.json](ASSET_MANIFEST.json) lists 46 physical asset files totaling 33,967,875,210 bytes and 11 relative OWLv2 snapshot aliases. [SOURCE_MANIFEST.json](SOURCE_MANIFEST.json) lists the 85 repaired serving files. [IMAGE_IDENTITY.json](IMAGE_IDENTITY.json) records the repaired image, archive and original 8d3 ancestry. The asset inventory includes both OWLv2 weight formats to preserve the complete selected cache; it is not a minimum download set. Hugging Face disallows a `.cache` repository path segment. The OWLv2 cache is therefore stored at `image_root/app/hf_cache/`, corresponding to `/app/.cache/` in the original image. Manifests record both `image_path` and `repo_path`; aliases also have an explicit `resolved_repo_path`. Each selected file has a recorded size and SHA-256. These hashes identify the payload independently of its directory name or adapter configuration. Download each physical file once and recreate the eleven relative aliases from the manifest mappings. When assembling a filesystem with the original image layout, map the contents of `image_root/app/hf_cache/` back to `/app/.cache/` and preserve the relative links. The native configuration remains `HF_HOME=/app/.cache/huggingface`. The snapshot and examples below do not modify a running container or fetch replacement models for cache aliases. Run the bundled verifier from the trusted documentation checkout against the downloaded snapshot: ```bash python3 -B verify_files.py procedure-final-repaired --restore-aliases ``` The verifier authenticates both manifests, streams SHA-256 checks over all 131 selected physical asset/source files, and verifies or creates the eleven specified aliases. An existing alias with a different target causes verification to fail. Without `--restore-aliases`, verification is read-only. A successful result establishes file integrity; model loading and GPU execution require separate validation. Dense48 and Point320 are distinct 247,513,400-byte adapters, although their 1,135-byte configuration files match. Both use checkpoint 12,910. Reproducing the released model requires these separate adapters, the recorded base revision and the existing prequantized int8 weights, without merging or exchanging adapters or regenerating the quantized base. ## Load components for inspection or research The image reports Python **3.11.11** and these installed versions: Transformers **5.14.0**, PEFT **0.20.0**, Torch **2.13.0**, bitsandbytes **0.50.1**, Accelerate **1.14.0**, safetensors **0.8.0**, tokenizers **0.22.2**, huggingface-hub **1.29.0**, Pillow **12.3.0**, and PyAV **16.1.0**. These values come from the installed packages; the older `PYTORCH_VERSION` environment label is not authoritative. Matching package versions alone does not reproduce the CUDA libraries or complete image environment. [load_components.py](load_components.py) provides a CUDA loading example based on the shipped `vlm_cholec.py` and `object_specialist.py` calls. It verifies the files, loads the processor from `image_root/app/artifacts/q38_base` and the prequantized base from `q38_base_int8_prequant`, then attaches Dense48 as `default` and Point320 as `point_object`. RNG state is preserved during the second adapter attachment. The loader uses the saved quantization configuration and keeps the adapters separate. ```python from load_components import load processor, model = load("procedure-final-repaired") # Dense48 is active initially. For a custom component-level experiment: try: model.set_adapter("point_object", inference_mode=True) model.eval() # Prepare authorized inputs with processor, then call model.generate(...). finally: model.set_adapter("default", inference_mode=True) model.eval() ``` The auxiliary OWLv2 detector can also be loaded from its exact local snapshot: ```python from pathlib import Path from transformers import Owlv2Processor, Owlv2ForObjectDetection owl_path = ( Path("procedure-final-repaired").resolve() / "image_root/app/hf_cache/huggingface/hub" / "models--google--owlv2-large-patch14-ensemble/snapshots" / "95e26936e865f87db1742128404b3c035d47d89d" ) owl_processor = Owlv2Processor.from_pretrained(str(owl_path), local_files_only=True) owl_model = Owlv2ForObjectDetection.from_pretrained( str(owl_path), local_files_only=True ).to("cuda") owl_model.eval() ``` This optional example uses the original detector's processor/model API and requires the verifier to have restored the cache aliases. The component loader checks package versions and CUDA availability. Its API sequence was checked against the serving source using CPU test doubles. Separate tests on the downloaded assets passed configuration, processor and tensor-header checks. The CUDA component-loading function itself has not been executed as a new GPU load. These component examples do not reproduce the native question router, warmups, per-request control checks, input shell or temporal budget policy. Validation of the repaired image's full runtime is recorded separately in [RELEASE_VERIFICATION.json](RELEASE_VERIFICATION.json). ## Run the validated image The extracted files do not include a standalone operating system or Python environment. The repaired OCI image provides the environment used for native execution validation: ```text us-central1-docker.pkg.dev/heydonto-425716/surgfield/surgfield-proc-q38-validation@sha256:f0590e6d79097a37f502260cf665624bd4ca87e9cbda66d240d6d4db7d0bb63d ``` Its image configuration is `sha256:94d0791cb96f3ac9248e9ec7c918e3bbdc5960646b48d201cb478d488fcda576`. The archive has SHA-256 `b63dcf1bbee6554942a78edc823dfc4b38a89dba54f029acdd28a8c91bfa4a2d` and size 52,775,393,310 bytes, at generation `1789119563478283` of `gs://heydonto-surgfield-research/finals/procedure/candidates/20260911/procedure-diagnostic-repair-20260911-0846-b/procedure-diagnostic-repair-20260911-0846-b.tar.gz`. Original 8d3 remains available as immutable ancestry at revision `b2176cf6d0f77e58e34a90583041b1a929417fb3`. Registry/GCS access is separate from Hugging Face access; the archive is not duplicated in this repository. The default command is `/opt/conda/bin/python -B /app/runtime_zoom_entry.py --submission`, with working directory `/app` and UID/GID 1000. The shell reads `/input/request.json`, organizer `/input/FO_definitions.json` and the supplied video layout. It writes `/output/answer.json` with `{qID, content, latency}` records. Inputs must follow this contract and be authorized for use. Private evaluation fixtures and reference answers are not included. Historical 8d3 native score checks used H100 with 16 CPUs and 196,608 MiB of host memory. Current repaired-image execution checks are documented separately in [RELEASE_VERIFICATION.json](RELEASE_VERIFICATION.json). These are test allocations; minimum resource requirements and guaranteed process runtimes have not been established. Reproduction uses the image's default entrypoint, flags and environment.