Skip to content

HRX: fix the MoE router expert-id fault (engine#123) - #170

Merged
bong-water-water-bong merged 3 commits into
mainfrom
hrx-123-moe-router-expert-id
Sep 27, 2026
Merged

bong-water-water-bong merged 3 commits into
mainfrom
hrx-123-moe-router-expert-id

Conversation

@bong-water-water-bong

Copy link
Copy Markdown
Collaborator

What

Bumps third_party/llama.cpp to the fix for #123 and documents it in docs/hrx.md.

Upstream: 1bit-MONSTER/llama.cpp#25

Root cause

llama_decode intermittently died with HSA_STATUS_ERROR_MEMORY_FAULT (ret = -3) on MoE models. It was reported against the decode-split multipass path, but it is not in flash attention — disabling that dispatch only changed the layout enough to mask it. A serial-execution trace put the fault in qwen3_moe_routed_gate_up_swiglu_q4k_q8:

router_top8_f32.loom seeded each lane's argmax with best_id = 0x7FFFFFFF and only replaced it on an ordered ogt or the equal-value tie-break. A lane whose candidate logits are unordered (NaN) or below -FLT_MAX published the sentinel verbatim into route_ids; consumers treat the id as bounded via index.assume (a hint, not a check) and compute expert * expert_stride in 32 bits, so 0x7FFFFFFF * 884736 mod 2^32 = 0xFFF28000 (~4.29 GB) walked off the end of the weights buffer. The logged fault page matched up_binding + 0xFFF28000 + 25*1152 exactly.

Verified

gfx1151 (Strix Halo), Qwen3-Coder-30B-A3B-Instruct-Q4_K_M, -dev HRX0, llama-bench -p 0 -n 8, quiet box, on the superset tree with GGML_HRX=ON:

  • pre-fix -d 2100: 5/5 faults → post-fix 0/5
  • -d 3000 / -d 4800: 0/3 / 0/3
  • <=2048 path (-d 1500): 0/3
  • greedy llama-server output on HRX0 == CPU backend of the same build

Re-point the pin at the PR merge commit once #25 lands.

Pins third_party/llama.cpp at the fix for engine#123: router_top8_f32 could
publish its 0x7FFFFFFF no-winner seed as an expert id, which
qwen3_moe_routed_gate_up_swiglu_q4k_q8 then turned into a wild weight address
(HSA_STATUS_ERROR_MEMORY_FAULT / llama_decode ret=-3). Upstream PR:
1bit-MONSTER/llama.cpp#25

Re-point at the merge commit once #25 lands.
@context7

context7 Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Docs7 for 1bit-monster/engine

Result Status Action
Deployment ➖ Not used —
Content review ➖ Did not run. This site has no agent runs available this month. Wait for the monthly reset or check your Docs7 plan. —

Commit df519c8

bong-water-water-bong and others added 2 commits September 27, 2026 04:16
… leaves open

Re-points third_party/llama.cpp from the PR head (53c0715) to the merge
commit of 1bit-MONSTER/llama.cpp#25 and regenerates registry/architectures.json
(the registry_pins check failed on the moved pin). docs/hrx.md: the merge
commit, and that the fix turns NaN router logits into a valid-but-wrong expert
instead of a fault; the NaN source stays open (#140), with the page-migration
measurement that points at it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bong-water-water-bong

Copy link
Copy Markdown
Collaborator Author

Reviewed. The root cause and fix hold up: seeding with lane_expert_base is bit-identical whenever a lane has a winner, and the fault page matching up_binding + 0xFFF28000 is convincing. It only touches qwen_moe/router_top8_f32.loom, so ZAYA and the other non-Qwen-MoE paths are untouched.

registry_pins failed because the registry recorded 53c0715 (the PR head) while the pin is 895d63f (the merge commit). I pushed df519c8, which regenerates it; counts are unchanged.

Worth a follow-up: now that the fault is traced to the router rather than flash attention, #148's decode-split default can be revisited. #140's nondeterminism (up to 3.66 nats between identical requests) is a separate issue and still has to be ruled out with repeated runs before the kernel goes back on.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant