PitForge, Exact Ultimate Pit Limit & Nested Whittle Pit-Shell Workbench
An open-pit mine-design workbench that solves the ultimate pit limit exactly, as a maximum-weight closure of the block-precedence graph reduced to a minimum cut on a Dinic max-flow engine, running live in the browser, and derives the nested Whittle pit shells by revenue factor. It reproduces the published optima of three real MineLib instances to at most 2e-9 relative error, and self-checks every solve with the max-flow duality identity. This is the only one of the Faena four whose headline is validated against third-party published optima rather than its own generator.
Business Context
The ultimate pit and its nested shells set the envelope for reserves, phasing and cash flow, so a wrong or unauditable pit propagates into every downstream number. PitForge's value is that its exact answer is checkable two ways: against published third-party optima it did not create, and against the max-flow duality identity. A 14,153-block instance with 219,778 precedences solves exactly in well under a second on a laptop, in a Node bake of the same TypeScript engine the browser runs (the milliseconds are machine-dependent; repeat runs on one machine varied by a factor of several, so the artifact records its environment and the claim here is about scale), which puts a design-grade optimiser on a static page with no server and no licence. The learned surrogates are positioned as fast approximations for what-if exploration, never as replacements for the exact result.
Strategic Value
PitForge is the most strongly validated of the Faena four, and the validation is third-party: its exact ultimate pit reproduces three published MineLib optima (newman1, zuck_small, kd) to at most 2e-9 relative error, with the largest solved in a fraction of a second in a Node median-of-3 bake of the same engine (a machine-dependent figure, recorded with its environment). Two further properties reinforce it. Scenario knobs are locked in real mode because the MineLib instances publish their own net values and precedences, so re-deriving them would break comparability with the published optimum, a deliberate decision to protect the benchmark. And the learned grade-nn is reported as a loss, not a win: on a held-out geology it reaches R2 0.8757, narrowly beating IDW at 0.8591 and trailing ordinary kriging at 0.9333, and the artifact calls it a fast approximation that never beats the exact result. That number moved when a leaky random-row split was replaced with a grouped leave-one-geology-out split, so the smaller figure is the trustworthy one. The CPIT lane parses the published newman1.cpit scenario (6 periods, 8% discount, two resource constraints), reproduces its published LP bound to 3.7e-9, and publishes a 3.81% bound-to-feasible gap; a separate synthetic twin, labelled non-comparable, sits at 11.29%. It is a reusable pattern for an auditable, self-checking optimiser that proves itself against numbers it did not author.
The Challenge
The ultimate pit limit, the set of blocks worth mining once slope precedences are honoured, is the foundation of every open-pit design, and it has an exact solution: the maximum-weight closure of the precedence graph, equivalent to a minimum cut. In practice it is often approximated, or locked inside commercial software whose results cannot be reproduced or audited. Proving an implementation is correct requires more than "it returns a pit": it requires matching a published optimum on an instance you did not generate yourself, and checking the solver against its own duality identity on every run.
Our Approach
PitForge solves the ultimate pit limit as a maximum-weight closure, reduced to a minimum cut via Picard's 1976 construction and solved by a Dinic max-flow engine written in TypeScript, running live in the browser. The exact result is what it is described as: this is the max-closure / min-cut equivalent of Lerchs-Grossmann, not a re-implementation of Lerchs-Grossmann. Dinic is the live engine, and an independent Hochbaum normalised-tree pseudoflow rung runs beside it, reproducing the same optimal value and the same block set on every validated instance; identical cuts are not claimed for tied optima in general, since a minimum cut need not be unique. From the exact pit it derives the nested Whittle pit shells over an ascending revenue-factor schedule, yielding value, tonnage and strip-ratio curves. Grade estimation runs two ways live (IDW and a grade-nn ONNX surrogate over a 27-vector neighbour stencil), with ordinary kriging as the offline benchmark baseline the network is measured against, plus a pit-inclusion surrogate. A CPIT LP relaxation (scipy HiGHS) with greedy integer rounding is computed offline and rendered from JSON, never live. The duality identity pitValue = sum(positiveValue) minus maxflow is asserted in the explicit-precedence MineLib lane and surfaced as a displayed check on the interactive lane. Static on GitHub Pages, with an in-app drag-and-drop CSV path for bring-your-own block models.
Key Performance Indicators
| KPI | Baseline | Result | Impact |
|---|---|---|---|
| Correctness, third-party validated | Returns "a pit" with no external check | Reproduces 3 published MineLib optima (newman1, zuck_small, kd) to <= 2e-9 relative error | Validated against optima it did not generate, not against its own output |
| Exact solve, in the browser | Approximate pit, or a licensed desktop solver | 14,153 blocks / 219,778 precedences solved exactly in a fraction of a second (Node median-of-3 of the same TypeScript engine the browser runs, machine-dependent; Dinic min-cut over Picard reduction) | Design-grade optimiser on a static page, zero backend |
| Self-check on every solve | Trust the returned number | pitValue = sum(positive) - maxflow asserted on every solve (max-flow duality identity) | The optimiser checks itself, not just the caller |
| Learned surrogate vs kriging | Claim the neural net beats kriging | grade-nn R2 0.8757 vs ordinary kriging 0.9333 and IDW 0.8591 on a leave-one-geology-out split (a loss to kriging, published as such); reported as a fast approximation, never beating the exact result | A 0.0033 margin is a tie, and the card says so |
Architecture
pitforge pipeline
The exact pit, in the browser, checked against published optima
PitForge is an open-pit mine-design workbench. It solves the ultimate pit limit exactly, as a maximum-weight closure of the block-precedence graph reduced to a minimum cut on a Dinic max-flow engine, running live in the browser, and derives the nested Whittle pit shells by revenue factor. Live at pitforge.fasl-work.com, part of the Faena mining-analytics hub.
Say what the engine is
The exact result is the max-closure / min-cut equivalent of Lerchs-Grossmann, via Picard’s 1976 reduction on a Dinic engine. It is not a re-implementation of Lerchs-Grossmann. Dinic is the live engine, and an independent Hochbaum normalised-tree pseudoflow rung runs beside it, reproducing the same optimal value and the same block set on every validated instance; identical cuts are not claimed for tied optima in general. From the exact pit, nested Whittle shells over an ascending revenue-factor schedule give value, tonnage and strip-ratio curves.
Validated against MineLib, not against itself
The exact pit reproduces the published optima of three real MineLib instances:
- newman1: 1,060 blocks, relative error 9.96e-10
- zuck_small: 9,400 blocks, 1.86e-10
- kd: 14,153 blocks / 219,778 precedences, 1.30e-10
The relative errors are properties of the algorithm and reproduce anywhere. Solve times are not: measured under Node on the same TypeScript engine the browser runs, the three take milliseconds to a fraction of a second, but repeat runs on one laptop varied by a factor of several, so the artifact records its environment and no decimal figure is published here. What is stable is the comparison in the same run: the independent pseudoflow rung is one to two orders of magnitude slower on the two larger instances.
All three match: true. Two further instances (marvin, mclaughlin_limit) are excluded with committed reasons (marvin ships with commercial Whittle software; neither has a verified public mirror) rather than silently dropped. In real mode the scenario knobs are locked, because the instances publish their own net values and precedences and re-deriving them would break comparability with the published optimum.
The learned and offline rungs
The duality identity pitValue = sum(positive) - maxflow is asserted in the explicit-precedence MineLib lane and displayed as a live check on the interactive lane, so the optimiser checks itself against its own dual. Grade estimation runs two ways live (IDW and a grade-nn ONNX surrogate), with ordinary kriging as the offline benchmark baseline; the learned grade-nn trails kriging (R2 0.8757 against ordinary kriging 0.9333 and IDW 0.8591, on a split that leaves one whole geology out), and the artifact calls it a fast approximation that never beats the exact result. Both learned models are trained and evaluated on synthetic seeded deposits, with no real drillholes. Scheduling is a CPIT LP relaxation computed offline with scipy HiGHS, rendered from JSON, never live; on the published newman1.cpit scenario (6 periods, 8% discount, two resource constraints) it reproduces MineLib’s published LP bound of 24,486,184 to 3.7e-9 and publishes a 3.81% bound-to-feasible gap, with a separate synthetic twin at 11.29% explicitly labelled non-comparable, and it states plainly that the rounded schedule is a heuristic and is never optimal. It is a design optimiser, not a JORC or NI 43-101 resource estimate.
Technology Stack
In action
A short tour of the live app: the real interface, recorded from the deployed site.

Application Screenshots

