Expand description
Isolated vNext contracts for the runtime redesign.
These types are intentionally not wired into legacy product or execution paths. They define GPU-free, fail-closed boundaries for later migration.
Structs§
- Active
Sequence Abort Receipt - Core-signed evidence that the exact active slot epoch was atomically poisoned. This type is trusted output and has no deserialization or public construction path.
- Active
Sequence Completion Receipt - Core-signed evidence that synchronization succeeded and the exact active slot epoch was atomically cleared. It is trusted output and deliberately cannot be deserialized or constructed by a caller.
- Active
Sequence Permit - Non-cloneable guard for an admitted active-sequence slot. Dispatch borrows this permit; the sequence owner retains it until all asynchronous work is synchronized or cancelled.
- Admission
Deferred - Admission
Demand - Opaque demand derived by the execution plan. Product/backend callers can inspect it but cannot construct or deserialize a lower demand.
- Admission
Policy - Admission
Rejected - Admitted
Request Resources - Request root authority. Request-lifetime state is physically and logically
claimed once, then shared by exact child sequence authorities through an
owning
Arcparent hold. - Admitted
Sequence Resources - Sequence authority. There is exactly one state cell for the exact
SequenceAuthorityIdissued by B1; no ceiling-sized slot vector and no caller-selected slot allocator exist here. - Attribute
Id - Stable semantic attribute identity. Attribute names are data, not ad-hoc strings interpreted by an individual provider.
- Attribute
Schema - Closed attribute vocabulary for one operation contract.
- Attribute
Spec - Axis
Weight Component - Backing
Chunk Identity - Backing
Segment - Batch
Invocation Id - Batch
Operation Identity - Batch
Operation Identity Materialization Snapshot - Batch
Operation Node Identity - One immutable-plan node inside a physical command batch. Participant identities stay node-local even when several nodes share one submission.
- Batch
Operation Participant Identity - Batch
Participant Authority - Batch
Participant Token Range - Exact packed-token projection for one participant in a scheduler step. The range addresses the shared batch transient arena; it is derived from the canonical participant work and cannot be supplied independently.
- Batch
Participant Token Span - Opaque association between one exact admitted participant and token work derived from that participant’s actual token ids.
- Batch
Step Id - Batch
Work Shape - Immutable work authority for one exact non-empty participant set. The dimensions remain private so downstream claims and dispatch can only use the shape that core bound to this participant topology and fingerprint.
- Batched
Operation Invocation - Borrowed provider view for exactly one physical command. Participant-local resources remain separate projections while invocation/step/plan resources may be shared by every projection.
- Block
Quantization Spec - Self-contained fixed-size quantization blocks such as GGML/GGUF Q4_K and
Q6_K. Per-block scales, minima, and packed values are part of the opaque
block ABI identified by
format_id; providers must not reinterpret these bytes as the separate-scaleQuantizationSpecrepresentation. - Bound
Device Submission Attribution - Bound
Execution Resource Maintenance - Allocator-issued proof for one successful post-admission backing mutation.
- Bound
Execution Stream - Bound
Operation Oracle - Non-cloneable authority borrowed from one registry-owned oracle object.
- Bound
Operation Provider - Unforgeable per-node provider authority. Its provider object and plan/node binding are private. Normal bindings borrow the composition registry; immutable plan bindings own the same selected provider object.
- Bound
Operation Provider Set - Immutable provider selection for every node in one executable plan.
- Buffer
Descriptor - Buffer
Request - Canonical
Rational - Capability
Catalog - Deterministically ordered provider capabilities consumed once by planning.
- Capability
Id - Capacity
Availability Epoch - Capacity
Domain Id - Capacity
Domain Spec - Capacity
Entry - Capacity
Epochs - Capacity
Shortfall - Capacity
Snapshot - Capacity
Units - Capacity
Vector - Capacity
Wait Condition - Exact, non-authoritative retry predicate captured with one deferral. Copying this value cannot allocate capacity; it can only suppress or permit a later authoritative admission probe.
- Capacity
Wait Recheck - Capacity
Wait Registration - Capacity
Wait Snapshot - One coherent observation used to publish a deferred capacity decision.
- Claimed
Backing Transaction - One atomic physical/logical backing claim bound to an immutable batch work authority. Even an empty resource demand retains the work shape and claim fingerprint through dispatch and fence ownership.
- Claimed
Submission Wave Backing - One physical/logical Invocation backing transaction shared by every node in an immutable-plan submission wave. Physical demand is charged once for the liveness-derived peak and retained until the wave’s terminal fence.
- Compiled
Submission Wave Identity - Cold-path identity topology for one immutable plan on one execution lane.
- Completion
Drain Receipt - Completion
Fence Timing - Fence timing for one exact operation completion. Device execution and host wait use different clocks and may overlap; consumers must not add them.
- Completion
Handle - Weakly bound observation authority. Dropping a handle cannot drop or reap the scheduler-owned completion registry.
- Completion
Quarantine Receipt - Completion
Readback Batch Receipt - Completion
Readback Batch Request - Completion
Readback Collection Request - Canonical terminal readbacks for multiple node/resource groups. Every
group remains a complete participant batch; this type does not weaken the
single-node invariant of
CompletionReadbackBatchRequest. - Completion
Readback Output - Completion
Readback Receipt - Completion
Readback Request - Completion
Readback Timing - Completion
Reaper - Scheduler-owned completion registry. The global map lock only resolves a slot; each fence is queried or waited under its own record lock.
- Completion
Retention Spec - Explicit semantic activations that must remain readable at the terminal completion fence. The empty default preserves the normal execution plan.
- Completion
Slot Id - Completion
Sweep Entry - Completion
Sweep Receipt - Composite
Weight Part - Contract
Version - A versioned contract uses major for breaking and minor for additive changes.
- Copy
Region - Deferred
Device Cleanup Maintenance Receipt - Deferred
Device Cleanup Status - Definitely
NotSubmitted - A submit failure that guarantees no device-visible work was enqueued.
- Definitely
NotSubmitted Retry Authority - The sole retry edge after a device runtime proves that submit did not happen. It owns the exact invocation, topology and work evidence; dropping it retires the ledger tombstone and cannot be relabeled as retryable later.
- Definitely
NotSubmitted Wave Retry Authority - Device
Allocation Permit - Device
Allocation Receipt - Device
Buffer Retention - Opaque core ownership retained by backend commands that outlive the borrowed buffer view used to encode them. Backends may clone and store this value, but cannot inspect or manufacture resource ownership.
- Device
Capacity Pressure - Exact device-wide pressure observed while trying to grow dynamic backing.
- Device
Command Batch - Core-owned physical submission unit.
- Device
Command Entry - One command plus the core-issued semantic phase that constrains backend execution optimizations.
- Device
Command Execution Timing - Backend-counter timing for one command entry in a core-owned submission. A command may own multiple physical encoder intervals, for example a gather-compute-scatter implementation.
- Device
Command Logical Work - Core-owned logical work bound to a node-scoped device command.
- Device
Descriptor - Device
Error Report - Backend-provided description of one device error. The backend cannot pick a failure domain or execution identity; core attaches both after checking the concrete runtime device.
- Device
Execution Interval - Device
Execution Timing - Device
Id - Device
Native Operation Id - Stable machine identity for backend-native work attribution.
- Device
Native Work Attribution - Backend-observed physical work for one core-owned command entry.
- Device
Replayed Logical Command Attribution - One logical plan-node command sealed inside a physical reusable executable.
- Device
Replayed Segment Attribution - Logical-node attribution for one physical reusable executable launch.
- Device
Reusable Execution Capture - Core metadata attached to a full eager encoding while a backend prepares reusable programs. The backend may publish a catalog entry only when every referenced segment is resident and the observed node topology is stable.
- Device
Reusable Execution Invocation - One exact invocation of a segment from the sealed reusable program catalog.
- Device
Reusable Execution Observation - Aggregate reusable-execution work observed inside one backend submission.
- Device
Reusable Execution Plan - Cold-path capacity selected by the model execution plan before reusable device executables are prepared.
- Device
Reusable Execution Preparation - Backend receipt for the explicit configure -> prepare -> seal lifecycle.
- Device
Reusable Execution Program - Catalog row assembled during backend preparation and published only after
that preparation window is sealed. A partial row may contain only typed
gaps; product requests can reference resident segments, while determinism
requires
Self::is_determinism_ready. - Device
Reusable Execution Program Gap - One classified replay-eligible gap in a partial reusable program.
- Device
Reusable Execution Program Id - Runtime-local identity for one immutable reusable program.
- Device
Reusable Execution Segment - One contiguous node range owned by a resident backend executable.
- Device
Reusable Execution Topology Fingerprint - Opaque provider-owned topology identity for one reusable compute program.
- Device
Reusable Execution Trim - Cold-path receipt for releasing backend reusable executables after an execution lane has reached proven quiescence.
- Device
Submission Attribution - Device
Submission Execution Span - One physical device interval owner inside an exact submission.
- Device
Submission Execution Timing - Terminal backend-counter evidence for one exact submission. Physical spans cover every core command exactly once, remain ordered, and may explicitly mark a range unavailable without discarding measured sibling spans.
- Device
Terminal Receipt - A terminal and its optional backend clock evidence are inseparable. This prevents timing from being queried before the exact fence proves quiescence.
- Disabled
Device Submission Timing Sink - Disabled
Execution Event Sink - Domain
Capacity Snapshot - Dynamic
Backing Blocker - Dynamic
Backing Deferred - Dynamic
Backing Packing Envelope - Dynamic
Backing Pool Id - Dynamic
Backing Pool Spec - One self-contained physical-compatibility class for demand-driven backing. Membership, runnable minima, completion-order reuse evidence, and elastic bounds are canonical plan data, so a runtime does not have to rediscover pool structure by scanning unrelated descriptors.
- Dynamic
Pool Contract Status - Dynamic
Pool Growth Batch Receipt - Dynamic
Pool Growth Receipt - Dynamic
Pool Growth Request - Dynamic
Pool Idle Reclaim - Dynamic
Pool Live Occupancy Status - Dynamic
Pool Maintenance Boundary Chunk - One resident chunk as observed while every pool maintenance/state lock is held and before a pressure-driven rebalance mutates residency.
- Dynamic
Pool Maintenance Boundary Pool - Event-bound physical and logical state for one pool at a failed device reservation. Consumers can recompute the complete reclaim frontier instead of inferring it from a later health snapshot.
- Dynamic
Pool Maintenance Boundary Receipt - Atomic cold-path receipt for the exact capacity boundary that caused a
rebalance attempt. Selected chunks describe the planner decision before
mutation;
reclaim_sufficient=falseis the typed reason maintenance must wait for a release epoch instead of retrying allocation. - Dynamic
Pool Maintenance Controller - Plan-owner capability for changing physical dynamic-pool residency. It is
created once during provisioning, is intentionally not
Clone, and cannot be derived from any request, sequence, step, invocation, or static lease. - Dynamic
Pool Maintenance Status - Dynamic
Pool Occupancy Counter - Dynamic
Pool Provisioning Policy - Typed bounds for elastic residency.
minimum_resident_bytesis the amount required to make one request runnable, not an initial reservation. Pools may grow on demand up tomaximum_resident_bytes; the process-wide device account remains the authority when several pools compete for that memory. - Dynamic
Pool Quarantine Release - Dynamic
Pool Quarantine Release Receipt - Dynamic
Pool Rebalance Receipt - Dynamic
Pool Residency Occupancy Status - Dynamic
Pool Resident Pressure - Exact pool-local resident ceiling observed while maintaining otherwise valid deferred backing.
- Dynamic
Pool Resource Contract - Dynamic
Pool Status - Dynamic
Resource Descriptor - Dynamic
Resource Shape Bucket - Dynamic
Storage Contract - Dynamic
Storage Profile - Backend-neutral physical addressability offered by a runtime and accepted by an operation provider. This is independent from capacity formulas.
- Dynamic
Storage Requirement - Canonical non-empty set of profiles accepted by a provider binding or one provider-owned workspace. The planner intersects this with runtime offers and the ordered runtime-policy allowlist.
- Encoded
Device Operation - Provider-encoded work for one logical operation.
- Encoded
Reusable Execution Bindings - Per-wave commands that remain outside one resident reusable compute segment. Program bindings may be coalesced into the wave prelude; dynamic and result bindings preserve their position around the segment launch.
- Engine
Provider Descriptor - Engine
Selection - Event
Batch Emission Permit - Owned capability created only after the emitter has validated an ordered event batch against one transactional cursor.
- Event
Emission Permit - Owned capability created only after the emitter has validated the event against its transactional cursor. Ownership lets asynchronous sinks defer materialization without cloning the event or extending producer lifetimes.
- Executable
Plan - Owned executable produced directly by the planner for a concrete runtime
composition root. It is intentionally smaller than a product-level
ResolvedModelPlan. - Execution
Batch Participants - Canonical non-empty set selected by the scheduler for one continuous batch. Membership is exact; capacity shapes may not claim a different sequence count and no global concurrency ceiling is embedded here.
- Execution
Determinism Catalog Provider Requirement - Execution
Determinism Coverage Registry - Runtime-derived proof denominator for one CUDA catalog and every resolved model plan admitted to the release matrix.
- Execution
Determinism Evidence Denominator - Current-binary source of truth consumed by the CUDA determinism collector.
- Execution
Determinism Initialization Spec - One complete logical input/state range that must be restored before a deterministic eager or replay submission.
- Execution
Determinism Model Plan Identity - Execution
Determinism Model Provider Selection - Execution
Determinism Provider Evidence Denominator - Exact immutable witness denominator for one provider selection in one resolved model plan.
- Execution
Determinism Value Location - Trusted semantic-to-physical projection shared by determinism initialization and terminal witnesses.
- Execution
Determinism Witness Plan - Execution
Determinism Witness Spec - Execution
Event - Execution
Event Cursor - Execution
Event Emitter - Execution
Event Sink Error - Execution
Frame Id - Execution
Identity Envelope - Execution
Identity Parts - Execution
Lane - Scheduler-owned stream lane. It is intentionally not bound to any request or sequence and may enqueue multiple mixed-batch commands in stream order.
- Execution
Lane Id - Execution
Lane Reusable Execution Catalog - Execution
Plan - Execution
Plan Payload - Execution
Resource Maintenance Participant - Execution
Weight Plan - Trusted physical weight contract selected for one immutable execution plan.
- External
Model Metadata Id - Failure
Envelope - Portable failure payload. Execution identity is carried by the surrounding event or resource receipt rather than flattened into this message.
- Fence
Indeterminate - Blocking wait could not prove fence quiescence. The fence and all in-flight ownership must remain retained for lane recovery or quarantine.
- File
Fingerprint - Gated
Delta Chunk Plan - Gated
Delta Chunked Scan Capability - Gated
Delta Execution Capabilities - Physical gated-delta implementation available to one provider for an already-compatible operation shape. This capability is deliberately not a model attribute: the same immutable model plan can select a different form as the request work shape changes.
- Host
Transfer Layout - Identified
Failure - Indeterminate
Submission Handle - Weak recovery authority for a submit unwind where no fence was returned. Only a successful lane-wide drain can release the retained invocation.
- Initial
Sequence Backing Deferral - Non-cloneable authority for physical maintenance of an uncommitted initial request/sequence bundle. It owns no request or sequence lease.
- Initialized
Resource Transaction - Typestate owner proving every plan-static allocation was initialized and every selected weight component reached either a quiescent successful upload fence or one sealed all-or-nothing import transaction.
- Invocation
Admission Backing Deferral - Non-cloneable backing authority for one exact node invocation under one live step.
- Invocation
Resource Admission Request - Invocation
Resource Lease - Exact prepared batch node/provider invocation authority. No device command has been submitted at this layer; dropping it performs the typed definitely-not-submitted participant-flight rollback.
- Invocation
Resource Liveness - Json
Resolution Source Parser - Lane
Stable Arena Slot Identity - Leased
Buffer View - Borrowed access to a live, active, generation-bound committed buffer.
- Logical
Admission Coordinator - Logical
Admission Coordinator Id - Logical
Admission Lease - Logical
Backing Buffer View - Logical
Backing Slice Authority - Logical
Backing Slice Evidence - Logical
Batch Capacity Lease - Logical
Capacity Lease - Logical
Request Lease - Memory
Plan - Model
Config Fingerprint - Model
Family Id - Model
Program - Backend-free semantic program for a model family.
- Model
Semantic Metadata - Monotonic
Timestamp - NoStatic
- Explicit no-op result for plans that have no plan-lifetime buffers. It binds the validated plan to one exact runtime without manufacturing an empty reservation ledger or a zero-byte device-capacity claim.
- NodeId
- Node
Invocation Id - Node
Token Binding Projection - Exact resolved binding projection whose one logical axis advances with the core-issued packed token work shape.
- Operation
Buffer Region Iter - Operation
Buffer Regions - A checked logical range translated to physical device-buffer regions. Dynamic buffers never expose an arena buffer without its physical offsets.
- Operation
Buffer View - Operation
Completion Receipt - Operation
Descriptor - Operation
Dispatch - Operation
Failure - Operation
Id - Operation
Invocation - One participant projection inside a plan-selected physical batch. It has no public constructor and does not own submission authority.
- Operation
Oracle Descriptor - Trusted, Serialize-only identity of an executable operation oracle.
- Operation
Oracle Id - Stable identity of one checked-in oracle implementation contract.
- Operation
Oracle Registration - Composition-root registration that independently anchors the expected descriptor before an implementation can enter the trusted registry.
- Operation
Oracle Registry - Trusted concrete registry that owns contracts and exact oracle objects for the lifetime of every bound invocation handle.
- Operation
Oracle Request - Canonical, bounded request delivered to an
OperationOracle. - Operation
Oracle Result - Canonical, bounded outputs produced by an oracle implementation.
- Operation
Participant Completion Receipt - Operation
Physical Region - One indivisible physical region. The buffer reference is intentionally returned only together with the physical byte range.
- Operation
Planning Handle - Planning view issued only by a concrete runtime registry. Holding this view proves that node resolution used the same composition root that can later bind the selected runtime provider.
- Operation
Provider Descriptor - Operation
Resource Estimate - Untrusted raw output from one registered provider implementation. Identity and input claims remain explicit so the core can reject a buggy or malicious implementation before creating a trusted plan resource record.
- Operation
Resource Estimate Request - Exact semantic input presented to a selected provider’s resource estimator. The core creates this request only after provider selection and verifies the raw estimate against the same independently computed fingerprint. Global admission ceilings are deliberately absent: the provider describes one actual invocation and the scheduler decides how many invocations to admit.
- Operation
Runtime Registry - Composition-root registry that owns the exact provider objects used for both planning and runtime dispatch. A dispatch call receives only a bound handle issued by this registry, never an arbitrary provider implementation.
- Oracle
Tensor - Canonical row-major, little-endian host tensor used by all oracles. Float encodings must be finite; exact comparison is bit-exact, including distinct positive and negative zero encodings.
- Original
Model Source - Original
Model Sources - Participant
Node Key - One participant-local node topology key in the physical batch ledger. Attempt ids are deliberately absent so a fresh id cannot bypass overlap detection for the same sequence/frame/node work.
- Physical
Backing Claim Identity - Physical
Weight Component Binding - Physical
Weight Component Ref - Plan
Build Request - Plan
Capacity Wait Registration - A capacity wait registration that keeps its exact plan runtime alive until the waiter either observes a retry epoch or is cancelled by being dropped.
- Plan
Exact Alias - Core-proven exact storage equality between one output and its declared input. A MayAlias contract with distinct storage deliberately emits no edge.
- Plan
Hash - PlanId
- Plan
Node - Plan
Node Resolution - Per-node trusted physical resolution. It supplies physical bindings and a provider estimator result, but cannot provide memory totals, compatibility reports, plan identities, or hashes.
- Plan
Runtime Close Failure - Plan
Runtime Close Receipt - Plan
Runtime Handoff Error - Plan
Runtime Quarantine Receipt - Plan
Runtime Resources - Unique plan-lifetime owner of the runtime, dynamic pools, maintenance authority, static buffers, capacity claims, and cleanup authority.
- Plan
Schema Version - Plan
State Effect - Typed state effect derived from the operation access contract for a declared ModelProgram state binding.
- Pool
Compatibility Key - Prepared
Model Family - Prepared
Step Submission Node - One immutable-plan node projection inside a prepared physical submission wave. The parent wave owns device-flight and retry authority for every node as one atomic unit.
- Prepared
Step Submission Wave - Exact canonical command wave for one Step. Product waves cover the complete plan; determinism probes carry a sealed purpose for a plan-ordered subset. Node projections and shared Step backing remain owned until the one device fence reaches a terminal state; dropping a prepared wave rolls back.
- Product
Model Artifact Binding - One selected artifact inside a role-specific model source.
- Product
Model Source Identity - Immutable product-facing identity for the exact model sources selected by resolution and family preparation.
- Profiled
Submission Handle - Program
Binding Execution Binding - One exact plan/lane binding of a cold-compiled layout to a live reusable
arena slot. The wave owns this authority through its terminal fence; node
commands retain only an
Arcplus their immutable plan index. - Program
Binding Layout - Cold-compiled binding arena layout for one immutable reusable-execution bucket. Every slot is a fixed, non-overlapping projection into one contiguous lane-stable physical claim.
- Program
Binding Node Binding - Backend-visible authority for exactly one provider-owned binding slot. Cloning this handle is allocation-free and cannot change the selected slot.
- Program
Binding Slot - Program
Block - Program
Node - Program
Plan Compilation - Immutable executable plus the trusted node resolutions used to build it. Keeping the resolutions allows a product-level plan wrapper to validate the exact same physical decisions without reconstructing provider evidence.
- Program
Plan Compile Options - Explicit semantic inputs, per-node selection preferences, and optional completion diagnostics for compiling a model program. Product input capacities are required because they bound request-lifetime backing; the compiler never guesses a one-token capacity.
- Program
Plan Compiler - Backend-neutral compiler from semantic model programs to immutable physical execution plans. A metadata-only provider pass discovers the initial value alignment, then aligned dtype arenas are rebuilt until the estimator result reaches a bounded monotonic fixed point. This avoids both an unproved alignment guess and one device allocation per weight component.
- Program
Tensor Spec - Program
Value Id - Provider
Compatibility Rejection - Provider
Compatibility Report - Provider
Compatibility Request - Provider
Determinism Coverage Requirement - Provider
Execution Contract Fingerprint - Provider
Execution Semantics - Provider
Id - Provider
Requirement - Provider
Resource Plan - Trusted output from the selected provider’s shape/attribute-specific resource estimator. The core binds it to the exact estimator input and selected provider before the values can enter an executable plan.
- Provider
Selection - Provider
Storage Binding Requirement - Provider-accepted physical profiles for one exact operation binding slot. Role and ordinal are contract identities, not model-specific names.
- Provider
Workspace Requirement - Provisioned
Plan Parts - Named result of consuming
ProvisionedPlanResources. Keeping both fields in product ownership prevents maintenance authority from being silently discarded while request admission remains live. - Provisioned
Plan Resources - The indivisible result of plan provisioning. Product code must consume
this owner through
Self::into_parts, which hands out the plan runtime outcome and its unique maintenance controller together. There is no controller-less extraction path. - Quantization
Format Id - Quantization
Spec - Quiescent
Completion Contract Failure - Rational
Value - Rejected
Provider - Replay
Evidence - Independent evidence needed to rebuild a replay identity. None of these values are accepted from the serialized replay envelope itself.
- Replay
Identity - A replay identity is trusted output. Deserialization always goes through
UnvalidatedReplayIdentityand reconstruction from independent evidence. - Request
Authority Id - Request
Backing Deferral - Non-cloneable authority for one exact request-admission backing attempt. The embedded evidence can be projected to schedulers and traces, but only this handle can invoke live revalidation.
- Request
Identity - Request
Resource Admission Request - Request
State Hazard Blocker - Request
State Hazard Deferral - Request
State Hazard Permit - Request
State Hazard Poison - Request
State Hazard Split Required - Request
State Hazard Wait Registration - Resolution
Artifact Id - Resolution
Decision - Resolution
Decision Binding - Construction-time link from a resolved field to externally supplied source evidence. It intentionally carries no chosen-value fingerprint; core derives that fingerprint independently from both sides after parsing raw evidence.
- Resolution
Decision Evidence - Resolution
Fingerprint - Resolution
Parser Descriptor - Resolution
Reason Id - Resolution
Source Artifact - Resolution
Source Evidence - External source bytes plus the exact trusted parser used to derive typed decision fields. This evidence is never serialized into a resolved plan.
- Resolved
Model Plan - The single validated, data-only result consumed by a product entrypoint.
- Resolved
Model Plan Inputs - Resolved
Model Plan Parts - Resolved
Model Source - Resolved
Model Sources - Resolved
Plan Validation Context - Trusted inputs that are intentionally outside a serialized resolved plan. A wire payload cannot choose its model registry, source evidence, physical node bindings, provider preference, or resource estimate and then validate itself against those same values.
- Resolved
Reusable Execution Bucket - Resolved
Runtime Policy - Resolved
Storage Component - Resolved
Tensor Spec - Concrete tensor shape selected by planning and consumed unchanged by an operation provider.
- Resolved
Value Binding - Value/resource binding shared by the execution plan and provider invocation. Keeping one representation prevents a lossy translation at the runtime boundary.
- Resolved
Value Storage - Physical resources backing one semantic value. A logical quantized weight can bind packed values, scales, zero-points, and indices without pretending they are one dense allocation.
- Resolved
Weight Binding - Immutable physical weight contract carried by an execution-plan binding.
This prevents the provider boundary from collapsing a quantized/composite
layout into only resource ranges and a synthetic
u8dtype. - Resolved
Weight Component Layout - Provider-visible physical identity for one component of a resolved weight. Source file names are intentionally excluded: source provenance belongs to the prepared family fingerprint, while providers need shape, role, and ABI.
- Resource
Abandon Signal - Resource
Allocation - Resource
Commit View - Borrowed view used to reconcile an invalid allocation. Core retains the actual buffer regardless of the driver’s return value.
- Resource
Compensation Record - Resource
Driver Failure - Resource
Failure Id - Resource
Failure Point - Resource
Failure Receipt - Resource
Id - Resource
Lease Entry - Resource
Lease Transition Receipt - Resource
Lease Validation Context - Resource
Ledger Entry Snapshot - Resource
Ledger Snapshot - Resource
Owned Buffer - Resource
Ownership Transfer Failure - Resource
Poisoned Transaction - Resource
Pool Event - Resource
Pool Event Cursor - Resource
Pool Event Identity - Resource
Pool Evidence - Resource
Pool Id - Process-local identity of one provisioned resource pool. It is independent from both the request that provisioned the pool and requests that later use one of its active-sequence slots.
- Resource
Pool Identity - Resource
Pool Ownership - Ownership transferred out of core when normal cleanup cannot prove that buffers and their device-capacity claim are gone. Dropping this object is the durable owner’s explicit cleanup point.
- Resource
Prepare Transition Error - Resource
Recovery Failure - Resource
Release Transition Error - Resource
Requirements - Shape-independent resource contract. Concrete byte counts, scopes, and alignment are produced by the selected provider’s versioned estimator and bound into the immutable execution plan.
- Resource
Reservation - Resource
Reservation Batch - Resource
Rollback Transition Error - Resource
Transaction - Resource
Transaction Context - Resource
Transaction Identity - Resource
Transition Receipt - Resource
Transition Record - Resource
Transition Validation Context - Trusted before/after journal supplied independently of an untrusted receipt. There is no public constructor and it is Serialize-only.
- Resource
Work Shape - Typed shape evidence shared by scoped admission and provider formula evaluation. The aggregate dimensions and fingerprint are core-derived.
- Retained
Completion Value - Immutable plan evidence for one semantic activation retained until the terminal completion fence. Callers never reconstruct this binding from raw node and resource strings.
- Retained
Host Memory Region - An owned, bounds-checked subregion of stable host memory.
- Reusable
Execution Bucket Id - Reusable
Execution Bucket Spec - Reusable
Execution Capacity - Reusable
Execution Class Id - Reusable
Execution Memory Plan - Reusable
Execution Policy - Reusable
Execution Program Policy - Fully resolved, fingerprinted logical startup-capture contract.
- Reusable
Execution Program Spec - One logical startup capture case bound to its covering workspace class.
- Reusable
Execution Topology Request - Lightweight provider view used to bind dynamic compute topology into a reusable program identity before catalog lookup.
- Reusable
Pool Workspace Budget - RunId
- Runtime
Memory Policy - Runtime
Resource Driver - Production transaction adapter for a concrete
DeviceRuntime. - Sampling
Policy - Sequence
Admission Backing Deferral - Non-cloneable authority for one sequence-admission backing attempt. Holding it keeps the exact parent request alive; a sibling request cannot maintain or substitute for that parent.
- Sequence
Authority Id - Sequence
Backing Generation - Sequence
Backing Snapshot - Immutable sequence-lifetime backing captured by one scheduler step. Later generations may append capacity, while an in-flight step retains the exact generation it submitted until its completion ownership is released.
- Sequence
Capacity Parent - One exact sequence parent of a batch-scoped child capacity claim. The coordinator derives this evidence from live leases and returns it in canonical sequence-authority order; callers cannot construct authority by copying these identifiers.
- Sequence
Extension Backing Deferral - Non-cloneable authority for backing growth of one exact open sequence generation and target work shape.
- Sequence
Resource Admission Request - Sequence
Resource Extension Request - Sequence
Session - Core-owned logical sequence lifecycle. It owns sequence resources but no device stream; scheduler-owned execution lanes may serve many sessions.
- Sequence
Session Cancel Snapshot - Sequence
Session Epoch - Sequence
Session Fingerprint - Sequence
Session Terminal Receipt - Sequence
Synchronization Failure - Retry owner for a failed stream drain. It intentionally does not expose the active dispatch permit, so no operation can be submitted between a failed synchronization attempt and its retry.
- SpanId
- Special
Token Collision - Special
Token Collision Policy - Special
Token Metadata - Standard
Operation Contract - One checked-in standard operation contract. Construction stays private so production registries cannot mutate a descriptor after a provider binds its fingerprint.
- StateId
- State
Spec - Static
Initialization Failure - Failure owner for initialization. A quiescent failure can return the committed transaction immediately. An indeterminate failure first requires explicit stream recovery; dropping it intentionally retains all device and capacity ownership rather than risking premature reuse.
- Static
Initialization Policy - Explicit host-staging budget for cold plan initialization. The composition root supplies this policy through typed configuration; it is not inferred from a model name, GPU name, or environment variable.
- Static
Initialization Receipt - Static
Provisioning Binding - Immutable identity and capacity envelope signed into an admission permit. This is trusted output and intentionally cannot be deserialized directly.
- Static
Provisioning Lease - Static
Provisioning Permit - One-shot plan/admission authority. It cannot be constructed, cloned, or
deserialized by product or backend code.
ResourceTransaction::beginconsumes it, closing the old caller-built reservation bypass. - Step
Admission Backing Deferral - Non-cloneable physical-backing authority for one exact batch participant set and immutable step work shape.
- Step
Finalization Failure - Step
Participant Frame Assignment - Step
Participant Retirement - Step
Resource Admission Request - Step
Resource Lease - Resources whose lifetime is one exact continuous-batch execution frame.
Child invocation leases retain this scope through
Arc, so shared frame capacity and every participant authority outlive asynchronous device work. - Step
Resource Slot - A set of Step-scoped logical resources that may project onto one physical extent. Multi-resource slots are emitted only when plan dependencies prove that every member’s final user completes before the next member starts.
- Step
Retirement Receipt - Step
Submission Wave Backing Deferral - Non-cloneable backing authority for one immutable-plan submission wave.
- Stop
Policy - Stop
Token Collision Policy - Submission
Execution Policy - Core-owned execution controls independent from timing instrumentation.
- Submission
Wave Determinism Artifact Attribution - Submission
Wave Determinism Artifact Execution - Submission
Wave Determinism Artifact Initialization Identity - Submission
Wave Determinism Artifact Logical Command - Submission
Wave Determinism Artifact Physical Command - Submission
Wave Determinism Artifact Replayed Segment - Submission
Wave Determinism Artifact Witness - Submission
Wave Determinism Evidence - Fail-closed terminal evidence for one forced eager or replay execution.
- Submission
Wave Determinism Handle - Submitted deterministic work whose terminal observation remains bound to the exact immutable-plan witness denominator.
- Submission
Wave Determinism Initialization Identity - Domain-separated semantic initialization identities for one deterministic execution. These values are derived from the exact typed restore payloads; artifact producers cannot substitute independently computed digests.
- Submission
Wave Determinism Logical Range - One exact logical range as seen by a provider for one prepared participant.
- Submission
Wave Determinism Participant Order - Stable semantic participant authority for one physically canonical batch.
- Submission
Wave Determinism Physical Readback - One physical readback buffer retained once even when multiple semantic witnesses intentionally project onto the same bytes.
- Submission
Wave Determinism Readback Plan - Canonical terminal readback denominator for one prepared deterministic submission wave.
- Submission
Wave Determinism Readback Target - One physical readback group and every semantic witness that projects onto that exact range.
- Submission
Wave Determinism Restore - Complete participant-major input/state restoration bound to one immutable plan and one exact prepared-wave work topology.
- Submission
Wave Determinism Restore Layout - Provider-visible deterministic I/O layout for one exact prepared wave.
- Submission
Wave Determinism Witness Readback - Semantic witness mapped to exactly one physical participant readback.
- Submission
Wave Input Upload - One typed host input written into an exact participant’s resolved plan input before any provider command executes. The request names semantic plan coordinates rather than exposing backend buffers or allocation ids.
- Submitted
Operation Participant Receipt - Submitted
Operation Receipt - Synchronized
Sequence Permit - Stream-drained typestate. It has no dispatch API and must choose exactly one terminal slot disposition.
- Template
Metadata - Tensor
Contract - Tensor
Id - Token
Span Work - Evidence for one non-empty immediate token span inside an exact full input. Counts are derived from the supplied token slice and private range rather than accepted as caller-provided aggregate dimensions.
- Tokenizer
Descriptor - Tokenizer
Id - Transaction
Committed - Transaction
Id - Transaction
New - Transaction
Quarantined - Transaction
Released - Transaction
Reserved - Transaction
Rolled Back - Trusted
Aborted Sequence Binding - Trusted
Active Sequence Binding - Trusted
Completed Sequence Binding - Trusted
Execution Event Context - Trusted
Execution Topology - Trusted
Execution Weight Plan - Non-serializable proof that a process-local registry implementation produced and validated this physical execution schema.
- Trusted
Node Topology - Trusted
Plan Runtime Binding - Sealed owning proof that one exact plan, runtime instance, provisioning
outcome, and admission coordinator belong together. Every durable child
authority holds the same root
Arc. - Trusted
Plan Runtime Evidence - Typed
Family Registration - Unvalidated
Execution Event - Unvalidated
Execution Identity Parts - Unvalidated
Execution Plan - Unvalidated
Failure Envelope - Unvalidated
Identified Failure - Unvalidated
Operation Failure - Unvalidated
Operation Oracle Descriptor - Untrusted wire shape for an oracle descriptor. It is never executable until reconstructed and matched to a registry-owned trait object.
- Unvalidated
Operation Oracle Request - Unvalidated
Operation Oracle Result - Unvalidated
Oracle Tensor - Untrusted wire tensor.
revalidatechecks all rank, extent, byte and scalar encoding bounds before producing a trusted host tensor. - Unvalidated
Plan Node - Unvalidated
Prepared Model Family - Serialized prepared packages are evidence, not trusted runtime objects. Rehydration must resolve the typed provider again and reproduce every field.
- Unvalidated
Provider Resource Plan - A wire payload is deliberately not an executable plan. It must be rebuilt against a typed model family, catalog, and runtime policy before use.
- Unvalidated
Replay Identity - Unvalidated
Resolution Source Artifact - Unvalidated
Resolved Model Plan - Unvalidated
Resolved Model Plan Parts - Unvalidated
Resource Compensation Record - Unvalidated
Resource Lease Entry - Unvalidated
Resource Lease Transition Receipt - Unvalidated
Resource Pool Event - Unvalidated
Resource Pool Event Identity - Unvalidated
Resource Pool Identity - Unvalidated
Resource Transaction Identity - Unvalidated
Resource Transition Receipt - Unvalidated
Resource Transition Record - Unvalidated
Static Provisioning Binding - Weight
Component Payload - Validated physical bytes for one model weight component.
- Weight
Component Spec - Weight
Format Id - Weight
Id - Weight
Layout Id - Weight
Materializer Descriptor - Serializable capability identity for one trusted weight transformation.
- Weight
Materializer Id - Weight
Materializer Registry - Process-local registry retaining the exact implementations authorized to transform checkpoint schemas. It is deliberately neither serializable nor reconstructible from a capability catalog.
- Weight
Reference - Weight
Schema - Weight
Tensor Spec
Enums§
- Abandoned
Sequence Recovery Error - Active
Sequence Abort Disposition - Terminal resource disposition produced by an explicit sequence abort.
- Admission
Decision - Admission
FitPolicy - Admission
Pressure Action - Alias
Policy - Allocation
Kind - Allocation
Lifetime - Attribute
Constraint - Attribute
Value Kind - Backing
Initialization Status - Batch
Capacity Claim Decision - Blocked
Tensor Padding - Buffer
Usage - Capacity
Availability Source - One independently changing source that can make a deferred capacity decision worth recomputing. Global release/capacity epochs remain audit versions; scheduler retry eligibility is derived from these exact sources.
- Capacity
Claim Decision - Capacity
Shortfall Kind - Completion
Observation - Completion
Readback Batch Observation - Completion
Readback Disposition - Completion
Readback Observation - Completion
Recovery Cause - Completion
Recovery Outcome - Completion
Sweep Observation - Deferred
Action - Device
Allocation Error - Device
Batching Form - Device
Capacity Pressure Scope - Capacity boundary that rejected one otherwise valid dynamic growth.
- Device
Class - Backend-neutral device classes. Concrete backend names do not belong here.
- Device
Command Phase - Semantic phase of one command inside a core-owned submission batch.
- Device
Compute Path Requirement - Required compute implementation for one physical submission.
- Device
Execution Interval Kind - One backend-counter interval relative to the first sampled command in an exact submission. Intervals remain in a device elapsed-time domain; they must not be subtracted from host timestamps.
- Device
Execution Path - Device
Execution Span Kind - Device
Execution Span Measurement - Device
Reusable Address Scope - Device
Reusable Execution Preparation State - Device
Reusable Execution Program GapReason - Exact reason why one replay-eligible plan node is absent from a resident reusable executable. These rows preserve the cold-path failure class after the backend publishes a partial product catalog.
- Device
Reusable Execution Program State - Device
Submission Attribution Requirement - Backend evidence required for one physical submission.
- Device
Submission Stage - Typed host boundaries inside one backend submission. These intervals use the host monotonic clock and must not be combined with device-event time.
- Device
Terminal - A quiescent device terminal. Both variants prove that command-owned buffers are no longer accessed by the device.
- Device
Timing Clock - Device
Timing Measurement - Device
Timing Mode - Backend timing is enabled monotonically before product requests start.
Offmust not allocate backend events or add host clock reads to the hot path;Completionmeasures only the existing submission terminal and readback boundaries;Replaymeasures physical executable/eager spans;Kerneladditionally attributes backend-observed physical work to immutable-plan node indices.Verificationretains full logical/kernel attribution. Execution-path selection and scratch initialization are independent typed submission policy; timing cannot silently change either one. - Device
Timing Unavailable Reason - Dimension
Constraint - Dynamic
Admission Fault Kind - Dynamic
Backing Claim Scope - Semantic ownership boundary for one atomic physical backing attempt.
InitialSequenceBundleis the only scope allowed to combine Request and Sequence descriptors; it publishes neither lifetime unless both can commit. - Dynamic
Backing Deferral Reason - Dynamic
Backing Pressure - Recoverable physical pressure returned by deferred backing maintenance.
- Dynamic
Chunk Quarantine Reason - Dynamic
Deferred Maintenance Outcome - Dynamic
Pool Provisioning Mode - Dynamic
Resource Demand - Core-bounded resource demand stored in an immutable memory plan. Provider
estimators use
ProviderWorkspaceSizeFormula; core adds runtime-policy bounds only after provider selection. - Dynamic
Storage Allocator - Dynamic
Storage View - Element
Type - Execution
Determinism Comparison Kind - Execution
Determinism Initialization Kind - Execution
Determinism Provider Coverage - Execution
Determinism Requirement - Execution
Determinism Value Extent - Runtime work projection for one immutable value binding.
- Execution
Determinism Witness Kind - Execution
Event Capture Policy - Execution
Event Detail - Execution
Event Kind - Execution
Event Sink Enablement - Execution
Lane Creation Error - Execution
Phase - Execution
Resource Maintenance Stage - Execution
Stream Creation Error - Failure
Domain - Fence
Query - Non-blocking fence observation. An indeterminate query retains the fence and routes ownership to blocking recovery; it is not a terminal failure.
- Gated
Delta Decay Parameterization - Gated
Delta Execution Form - Gated
Delta Execution Preference - Cost-model preference kept separate from physical support. A provider may derive it from calibrated crossover data and live batch topology without changing the immutable model plan.
- Gated
Delta Value Head Mapping - Initial
Sequence Resource Admission Decision - Invocation
Liveness Mode - Invocation
Resource Admission Decision - Layout
Constraint - Model
Artifact Source Role - Model
Source Kind - Node
Work Contract - Core-derived work mapping stored in the immutable execution plan. Token projections are resolved from one model-declared source dimension through the operation’s symbolic signature, so providers never infer work from a tensor element count or model family.
- Operation
Buffer Storage Kind - Operation
Completion Disposition - Operation
Dispatch Error - Operation
Participant Completion Disposition - Oracle
Spec - Physical
Storage Layout - Storage geometry for one physical component binding. Strides are measured in the component’s schema storage unit: elements for dense encodings, bytes for separate-component packing, and blocks for block quantization. The component’s declared dimensions describe its raw stored span, while this geometry maps the semantic component shape onto that span without inference or hidden padding.
- Physical
Weight Layout - Typed physical storage tree for one logical weight. Every leaf binds one physical component exactly once. Recursive composition allows indexing or expert stacking around dense, tiled, strided, or quantized values without architecture-specific cases.
- Physical
Weight Padding - Padding is always explicit and carries the exact semantic padded shape.
Exacthas no hidden storage extension.ZeroFillmust increase at least one dimension and, for tiled or grouped storage, must be the unique minimal shape implied by that contract. - Plan
Exact Alias Kind - Plan
Provider Reject Reason - Plan
Runtime Close Outcome - Profile
Phase - Program
Node Work Spec - Provider
Compatibility Reject Reason - Provider
Execution Repeatability - Repeatability promised for one immutable plan/provider/runtime binding.
- Provider
Replay Equivalence - Whether a provider authorizes reusable device execution for the same immutable eager operation.
- Provider
Selection Reason - Provider
Workspace Reuse Policy - Content contract applied whenever an existing physical workspace is reused.
- Provider
Workspace Scope - Provider
Workspace Size Formula - Provider-owned unit sizing formula. Scheduler and admission ceilings are intentionally absent so one implementation estimate remains reusable across runtime policies. Core binds those ceilings when it builds the executable memory plan.
- Quantization
Grouping - How values are partitioned along a quantized layout’s
group_axis. - Quantization
Packing - Replay
Cleanup Requirement - Replay
Cleanup Status - Replay
Plan Cleanup Evidence - Independent root-cleanup evidence supplied while rebuilding replay. Pending is explicit and is accepted only when the caller allows pending cleanup. The receipt variants are core-signed outputs and cannot be deserialized or constructed by the replay caller.
- Request
Admission Decision - Request
Resource Admission Decision - Request
State Hazard Access - Request
State Hazard Poison Cause - Resolution
Decision Source - Resolution
Field - Resolution
Source Provenance - Externally anchored origin of resolution source bytes. A source is either one exact file from the locked model snapshot or an explicitly identified upstream producer. There is no unstructured locator variant.
- Resolved
Tensor Layout - Resolved
Value Role - Resource
Commit Transition Error - Resource
Compensation Action - Resource
Lease Action - Resource
Lease State - Resource
Ownership Reason - Resource
Pool Event Detail - Resource
Pool Event Kind - Resource
Presence Requirement - Resource
Recovery Strategy - Resource
Retention Decision - Resource
Retention Policy - Core-owned retention policy derived from
AllocationLifetime. A backend or scheduler may decide when to act on it, but may not rewrite it after admission. - Resource
Transaction Action - Resource
Transaction State - Reusable
Execution Catalog Lifetime - Reusable
Execution Catalog Miss Policy - Reusable
Execution Program Shape - Exact logical startup capture case for a reusable device-program catalog.
- Reusable
Execution Program Shape Semantics - Reusable
Execution Topology - A provider declaration for the compute topology captured by a resident reusable program.
- Reusable
Execution Value Address - How one resolved value address enters a resident reusable executable. Direct captures require lane-stable address authority. Program-bound values are instead materialized into the provider’s typed binding slot before every replay and therefore may remain request- or sequence-owned.
- Reusable
Execution Workspace Address - Provider workspace addresses captured by a resident executable.
- Scheduling
Discipline - Semantic
Value - Sequence
Resource Admission Decision - Sequence
Resource Extension Decision - Sequence
Session Terminal Disposition - Sequence
Synchronization Error - Special
Token Role - State
Capacity Demand - Backend-neutral capacity formula for semantic state. This deliberately says nothing about pages, blocks, allocator kind, or provider-visible regions. Concrete physical storage is selected only while building an execution plan from provider requirements, runtime offers, and typed policy.
- State
Initialization - State
Lifetime - Static
Provisioning - Static provisioning has two physically distinct outcomes. Only
Requiredcarries transaction authority;NoStaticcannot be passed toResourceTransaction::begin. - Step
Participant Retirement Disposition - Step
Resource Admission Decision - Step
Resource Admission Profile Phase - Step
Resource Slot Kind - Step
Submission Wave Admission Decision - Stream
State - Stride
Constraint - Structured
Output Policy - Submission
Scratch Initialization - Scratch bytes presented to every provider invocation in one submission.
ProviderContractpreserves the selected provider’s declared reuse policy; explicit fill patterns are diagnostic proof inputs and are encoded before compute outside reusable executable capture. - Submission
Wave Dispatch Stage - Typed host boundaries inside one prepared wave dispatch. These intervals are host wall time and must not be combined with backend device timing.
- Tensor
Access - TriState
Policy - Trusted
Resource Pool Event Context - Unvalidated
Execution Event Detail - Unvalidated
Resource Pool Event Detail - VNext
Error - Structured, fail-closed errors produced by the vNext contracts.
- Weight
Component Role - Structural role of a physical component in a weight format. The role is intentionally independent of any named quantization or model family.
- Weight
Encoding - Weight
Materialization Fidelity - Whether a physical weight transformation preserves source values.
Constants§
- CAUSAL_
PAGED_ ATTENTION_ F16_ CAPABILITY_ ID - CAUSAL_
PAGED_ ATTENTION_ F32_ MASTER_ CAPABILITY_ ID - CAUSAL_
PAGED_ ATTENTION_ F32_ MASTER_ OPERATION_ ID - CAUSAL_
PAGED_ ATTENTION_ OPERATION_ ID - DENSE_
LINEAR_ F16_ CAPABILITY_ ID - DENSE_
LINEAR_ OPERATION_ ID - DENSE_
SWIGLU_ F16_ CAPABILITY_ ID - DENSE_
SWIGLU_ OPERATION_ ID - DEVICE_
COPY_ NATIVE_ OPERATION_ ID - DEVICE_
NATIVE_ ADAPTIVE_ ATTENTION_ CAPABILITY_ ID - Backend-neutral declaration that a composition can compile a native invocation-adaptive attention provider.
- DEVICE_
REUSABLE_ EXECUTION_ CAPABILITY_ ID - Backend-neutral device capability for an explicit cold-path reusable executable preparation lifecycle.
- DEVICE_
ZERO_ NATIVE_ OPERATION_ ID - DYNAMIC_
POOL_ MAINTENANCE_ BOUNDARY_ SCHEMA_ VERSION - EXECUTION_
DETERMINISM_ COVERAGE_ VERSION - EXECUTION_
DETERMINISM_ EVIDENCE_ DENOMINATOR_ VERSION - EXECUTION_
DETERMINISM_ WITNESS_ VERSION - EXECUTION_
IDENTITY_ VERSION - EXECUTION_
PLAN_ SCHEMA - EXECUTION_
RESOURCE_ MAINTENANCE_ EVENT_ SCHEMA_ VERSION - GATED_
DELTA_ EXECUTION_ FORM_ SELECTOR_ VERSION - GATED_
DELTA_ RECURRENT_ ATTENTION_ F16_ CAPABILITY_ ID - GATED_
DELTA_ RECURRENT_ ATTENTION_ F32_ MASTER_ CAPABILITY_ ID - GATED_
DELTA_ RECURRENT_ ATTENTION_ F32_ MASTER_ OPERATION_ ID - GATED_
DELTA_ RECURRENT_ ATTENTION_ OPERATION_ ID - HOST_
UPLOAD_ NATIVE_ OPERATION_ ID - IDENTITY_
WEIGHT_ MATERIALIZER_ ID - LAST_
TOKEN_ DENSE_ LINEAR_ F16_ CAPABILITY_ ID - LAST_
TOKEN_ DENSE_ LINEAR_ F32_ CAPABILITY_ ID - LAST_
TOKEN_ DENSE_ LINEAR_ F32_ OPERATION_ ID - LAST_
TOKEN_ DENSE_ LINEAR_ OPERATION_ ID - LAST_
TOKEN_ MASKED_ ARGMAX_ F16_ CAPABILITY_ ID - LAST_
TOKEN_ MASKED_ ARGMAX_ F32_ CAPABILITY_ ID - LAST_
TOKEN_ MASKED_ ARGMAX_ F32_ OPERATION_ ID - LAST_
TOKEN_ MASKED_ ARGMAX_ OPERATION_ ID - MAX_
COMPLETION_ SWEEP_ SLOTS - MAX_
DEFERRED_ DEVICE_ CLEANUP_ MAINTENANCE_ TASKS - MAX_
DEFERRED_ DEVICE_ CLEANUP_ TASKS - Cleanup pressure is independent from model size and normal request concurrency. Once one plan accumulates this many non-quiescent owners, new execution authority is rejected until an explicit recovery worker drains the backlog.
- MAX_
ENGINE_ PROVIDER_ ROWS - MAX_
EXECUTION_ EVENT_ WIRE_ BYTES - MAX_
EXECUTION_ PLAN_ RESOURCE_ ROWS - Maximum number of O(graph) static allocations plus dynamic descriptors. This limit is independent of the concurrency ceiling.
- MAX_
EXECUTION_ PLAN_ WIRE_ BYTES - MAX_
FAILURE_ ENVELOPE_ WIRE_ BYTES - Maximum encoded size accepted by the untrusted failure-envelope decoder.
- MAX_
OPERATION_ CATALOG_ ROWS - MAX_
OPERATION_ FAILURE_ WIRE_ BYTES - MAX_
OPERATION_ PROVIDER_ ROWS - MAX_
ORACLE_ ATTRIBUTES - Maximum number of typed attributes in an oracle request.
- MAX_
ORACLE_ ATTRIBUTE_ BYTES - Maximum canonical JSON bytes occupied by oracle request attributes.
- MAX_
ORACLE_ CALL_ BYTES - Maximum cumulative tensor bytes in an oracle request or result.
- MAX_
ORACLE_ TENSORS - Maximum number of input or output tensors in one oracle call.
- MAX_
ORACLE_ TENSOR_ BYTES - Maximum encoded bytes in one canonical host tensor.
- MAX_
ORACLE_ TENSOR_ ELEMENTS - Maximum logical elements in one canonical host tensor.
- MAX_
ORACLE_ TENSOR_ RANK - Maximum rank of one canonical host tensor passed through an oracle.
- MAX_
ORACLE_ WIRE_ BYTES - Maximum JSON wire bytes accepted before decoding any unvalidated oracle type.
- MAX_
PHYSICAL_ WEIGHT_ LAYOUT_ DEPTH - Hard bounds keep directly constructed and deserialized recursive schemas cheap to validate. Ownership makes cycles unrepresentable; these limits additionally bound adversarial depth and fan-out.
- MAX_
PHYSICAL_ WEIGHT_ LAYOUT_ NODES - MAX_
PREPARED_ MODEL_ FAMILY_ WIRE_ BYTES - Maximum raw JSON bytes accepted before decoding a prepared family package.
- MAX_
PROVIDER_ WORKSPACE_ SHAPE_ BUCKETS - MAX_
REFERENCE_ ORACLE_ DEPTH - MAX_
REPLAY_ IDENTITY_ WIRE_ BYTES - MAX_
RESOLUTION_ FIELD_ PATHS - Maximum number of source JSON pointers recorded by one artifact.
- MAX_
RESOLUTION_ FIELD_ PATH_ BYTES - Maximum byte length of one source JSON pointer.
- MAX_
RESOLUTION_ FIELD_ PATH_ TOTAL_ BYTES - Maximum cumulative bytes across all source JSON pointers in one artifact.
- MAX_
RESOLUTION_ JSON_ DEPTH - Maximum container nesting depth in a parsed resolution source document.
- MAX_
RESOLUTION_ JSON_ KEY_ AND_ STRING_ BYTES - Maximum cumulative bytes across object keys and string values.
- MAX_
RESOLUTION_ JSON_ NODES - Maximum total JSON values in a parsed resolution source document.
- MAX_
RESOLUTION_ PROVENANCE_ BYTES - Maximum cumulative string bytes in one resolution source provenance record.
- MAX_
RESOLUTION_ SOURCE_ BYTES - Maximum raw byte length accepted for one resolution source artifact.
- MAX_
RESOLVED_ MODEL_ PLAN_ WIRE_ BYTES - Maximum serialized byte length accepted by resolved-plan wire decoding.
- MAX_
RESOURCE_ LEASE_ RECEIPT_ WIRE_ BYTES - MAX_
RESOURCE_ POOL_ EVENT_ WIRE_ BYTES - MAX_
RESOURCE_ TRANSITION_ RECEIPT_ WIRE_ BYTES - MAX_
REUSABLE_ EXECUTION_ BUCKETS - MAX_
REUSABLE_ EXECUTION_ PROGRAM_ SHAPES - MAX_
WEIGHT_ MATERIALIZERS - PRODUCT_
MODEL_ SOURCE_ IDENTITY_ SCHEMA_ VERSION - PROVIDER_
EXECUTION_ SEMANTICS_ VERSION - RESIDUAL_
ADD_ F16_ CAPABILITY_ ID - RESIDUAL_
ADD_ F32_ F16_ CAPABILITY_ ID - RESIDUAL_
ADD_ F32_ F16_ OPERATION_ ID - RESIDUAL_
ADD_ OPERATION_ ID - RMS_
NORM_ F16_ CAPABILITY_ ID - RMS_
NORM_ F32_ CAPABILITY_ ID - RMS_
NORM_ F32_ OPERATION_ ID - RMS_
NORM_ F32_ TO_ F16_ CAPABILITY_ ID - RMS_
NORM_ F32_ TO_ F16_ OPERATION_ ID - RMS_
NORM_ OPERATION_ ID - ROUTED_
SHARED_ SWIGLU_ MOE_ F16_ CAPABILITY_ ID - ROUTED_
SHARED_ SWIGLU_ MOE_ OPERATION_ ID - ROUTED_
SWIGLU_ MOE_ F16_ CAPABILITY_ ID - ROUTED_
SWIGLU_ MOE_ OPERATION_ ID - TOKEN_
EMBEDDING_ F16_ CAPABILITY_ ID - TOKEN_
EMBEDDING_ F32_ MASTER_ CAPABILITY_ ID - TOKEN_
EMBEDDING_ F32_ MASTER_ OPERATION_ ID - TOKEN_
EMBEDDING_ OPERATION_ ID
Statics§
Traits§
- Device
Runtime - Stable primitive boundary implemented by a concrete device runtime.
- Device
Submission Timing Sink - Diagnostic-only sink for backend submission attribution.
- Dispatch
Retry Authority - Executable
Plan View - Minimal trusted view consumed by resource admission and operation dispatch. Product resolution may wrap this with tokenizer, sampling, source, and API policy, but those concerns do not enter the device execution boundary.
- Execution
Event Sink - Execution
Planner - Pure planner boundary. Execution consumes the immutable plan and performs no capability/backend selection in the token loop.
- Model
Family Provider - Compile-time model family provider with a typed, validated configuration.
- Model
Family Registration - Object-safe loading-time trampoline for a heterogeneous family catalog. The raw JSON exists only at the configuration boundary; a typed provider validates it before producing the backend-free package.
- Model
Family Registry - Operation
Contract - Object-safe semantic operation contract used while building a plan.
- Operation
Oracle - Object-safe executable correctness oracle. Runtime callers receive a registry-bound handle and never supply an oracle implementation per call.
- Operation
Planning Registry - Typed implementation registry used at the planning trust boundary. The core requires exactly one matching contract and estimator; missing or duplicate registrations fail closed before an executable plan is built.
- Operation
Provider - A compile-time provider contract for one concrete runtime buffer type. The kernel method consumes only a dispatch-created invocation.
- Operation
Resource Estimator - Runtime-independent planning half of an operation provider. This remains object-safe so planning can invoke the real implementation without inventing a device runtime type.
- Resolution
Source Parser - Trusted parser implementation supplied by the composition root. Core records its exact identity and reruns it for every wire revalidation.
- Resource
Transaction Driver - Backend adapter for one resource at a time. Core owns action ordering, actual state, all buffers, receipts, and recovery progress. Methods must be idempotent for the full identity/action/resource/generation key.
- Runtime
Policy - Typed policy selected before planning. Memory capacity is part of the public policy contract so a plan cannot depend on an undocumented env var.
- Stable
Host Memory - Owner for host bytes whose address, length, and contents remain stable for the lifetime of the owner.
- Static
Weight Import Session - Cold-path transaction for backends that can bind immutable weight components directly instead of allocating and uploading one contiguous physical arena.
- Submission
Wave Dispatch Timing Sink - Diagnostic-only timing sink for the prepared-wave dispatch hot path.
- Transaction
Stage - Weight
Component Source - Backend-neutral source of schema-addressed physical weight components.
Implementations own checkpoint file-format discovery and source-payload
validation. The execution plan’s trusted
super::WeightMaterializerowns any repacking or quantization before resource initialization performs placement and device submission. - Weight
Materializer - Trusted authority for one physical weight transformation.
Functions§
- canonical_
runtime_ policy_ fingerprint - causal_
paged_ attention_ contract - Dense causal attention including input normalization, Q/K normalization, RoPE, KV update, attention, optional output gate, output projection, and the attention residual. KV physical paging remains a provider concern.
- causal_
paged_ attention_ f32_ master_ contract - classify_
device_ error - Closes a backend error over the exact runtime instance and a core-owned device failure domain.
- compare_
oracle_ results - Applies a terminal operation’s exact, absolute or relative
OracleSpecto two already canonical result sets. Relative tolerance isabs(actual-reference) <= tolerance * abs(reference), so a zero reference accepts only an exact zero difference. - dense_
linear_ contract - dense_
swiglu_ contract - gated_
delta_ recurrent_ attention_ contract - Gated DeltaNet mixer including input normalization, projections, recurrent convolution/Delta state update, gated normalization, output projection, and the attention residual. Weight ordinals are part of the stable contract.
- gated_
delta_ recurrent_ attention_ f32_ master_ contract - last_
token_ dense_ linear_ contract - Projects only the final row of a non-empty token-major tensor. Keeping this semantic fusion explicit prevents materializing prompt-length vocabulary logits while leaving providers free to use a pointer offset, row gather, or a fused kernel.
- last_
token_ dense_ linear_ f32_ contract - last_
token_ masked_ argmax_ contract - Selects one token from a final-position F16 logits row after applying an exact per-vocabulary validity mask and an optional sparse repetition penalty. Selection policy is carried by typed inputs so it remains visible to planning and cannot be hidden in backend flags. Semantic logits remain immutable; providers use invocation-scoped scratch for any penalized view.
- last_
token_ masked_ argmax_ f32_ contract - maintain_
static_ initialization_ cleanups - Runs bounded recovery for abandoned static-initialization owners. This may block in backend synchronization and belongs on a recovery thread.
- residual_
add_ contract - residual_
add_ f32_ f16_ contract - rms_
norm_ contract - rms_
norm_ f32_ contract - rms_
norm_ f32_ to_ f16_ contract - routed_
shared_ swiglu_ moe_ contract - A routed SwiGLU expert set plus one sigmoid-gated shared SwiGLU expert.
- routed_
swiglu_ moe_ contract - A top-K routed SwiGLU expert set without a shared expert branch.
- static_
initialization_ cleanup_ status - Process-reachable status for initialization owners whose submission state was indeterminate and whose explicit failure owner was dropped.
- token_
embedding_ contract - token_
embedding_ f32_ master_ contract - validate_
oracle_ wire_ byte_ length - Validates the raw availability boundary shared by all oracle wire decoders.
Type Aliases§
- Completion
Readback Collection Observation - Completion
Readback Collection Receipt - Collection receipts use the same ordered, fingerprinted disposition evidence as a single readback batch.
- Submission
Wave Dispatch Error