1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
//! Reproducible operation plans.
//!
//! # Why a plan and not just options
//!
//! [`ExecutionOptions`] says how to run one operation. It does not say what
//! was run, what it produced, or whether re-running it would produce the same
//! thing. A graph evaluated twice under the same options gave no guarantee of
//! the same result, and nothing recorded which inputs and budgets produced a
//! given output.
//!
//! A [`Plan`] is that missing artifact: the options, plus the recorded
//! provenance of every step, plus the outcome. Re-executing a plan against the
//! same inputs must produce the same result, and the plan itself is the
//! evidence of what was run.
//!
//! # Determinism is requested, not assumed
//!
//! [`Determinism`] has always been declarable, but nothing read it: a caller
//! could ask for [`Determinism::Bitwise`] and receive best-effort output with
//! no indication the request was ignored. A plan closes that hole. Executing a
//! plan admits the requested level against what the executing provider
//! actually guarantees, and refuses when the request cannot be met.
//!
//! Refusing is the point. Silently accepting a determinism request a provider
//! cannot honour is exactly the class of quiet wrongness this kernel exists to
//! avoid: the caller believes it can hash the result and compare it across
//! machines, and it cannot.
//!
//! # Scope
//!
//! A plan is an in-process artifact. It is deliberately not serialised: a wire
//! format is a compatibility promise, and freezing one before the public API
//! stabilises would commit to a shape the kernel has not finished learning.
//! Reproducibility is proved by re-executing the same plan, not by persisting
//! it. Serialisation can be added without changing this contract.
use crate;
use crate;
use crate;
/// One recorded step: what ran, where, and under what guarantee.
///
/// Provenance survives across operations by accumulating these in order. A
/// step records the guarantee the provider actually delivered, not the one the
/// caller asked for, so a plan that ran at a weaker level than requested is
/// visible after the fact rather than indistinguishable from one that did not.
/// A reproducible operation plan.
///
/// Carries the options every step runs under and the provenance of the steps
/// taken so far. Re-executing the same plan against the same inputs must
/// produce the same result; the recorded steps are the evidence of what ran.