Skip to main content

SemanticTransitionSession

Struct SemanticTransitionSession 

Source
pub struct SemanticTransitionSession { /* private fields */ }
Expand description

Single owner of one serial transition stream, graph, scratch, and receipt bank. Retains the provider independently of the caller’s handle.

Implementations§

Source§

impl SemanticTransitionSession

Source

pub const CHECKPOINT_REFERENT_BYTES: usize

Fixed compact checkpoint v2 extent, also reserved by the cold exporter.

Source

pub fn checkpoint_allocation_domain( &self, ) -> Result<(Arc<CudaKernelProvider>, ResidentExecutionDomain), SemanticTransitionError>

Retain the actual allocation owner and serial stream for a private successor. Source and successor allocations remain charged to this same provider’s resource stack; constructing a successor does not grant a fresh budget or consume another permanent stream-pool slot.

Source

pub fn state_material_admission( bytes: &[u8], ) -> Result<SemanticAdmissionRecords, SemanticTransitionError>

Decode and validate one complete native material before allocating a new CUDA owner, returning only the original immutable admission needed to construct that fresh owner. This is the same state codec consumed by restore_state_material, not an independently serialized graph.

Source

pub fn state_material_projection( bytes: &[u8], ) -> Result<SemanticCheckpointNativeProjection, SemanticTransitionError>

Decode the original sealed material once and project its selected publication. This performs no CUDA allocation and does not create a runnable owner.

Source

pub fn state_material_input_projection( bytes: &[u8], ) -> Result<SemanticPublicationInputProjection, SemanticTransitionError>

Inspect original source and cache operands through the sole full-state decoder, without a CUDA owner or a new historical execution claim.

Source

pub fn prepare_segment_steps( &mut self, transitions: impl ExactSizeIterator<Item = SemanticTransitionKind> + Clone, cold_capacity: SemanticSegmentColdCapacity, ) -> Result<Vec<SemanticPreparedStep>, SemanticTransitionError>

Allocate every native step owner before the first capture begins. Freeze requested modes and reserve the complete segment before creating per-step storage. Device admission alone selects terminal drain.

Source

pub fn prepared_transition_kind( &self, step: &SemanticPreparedStep, ) -> Result<SemanticTransitionKind, SemanticTransitionError>

Original nominal schedule mode, available only before construction ends. It does not predict the effective mode selected by device admission.

Source

pub fn prepared_stream( &self, step: &SemanticPreparedStep, ) -> Result<Arc<CudaStream>, SemanticTransitionError>

Source

pub fn reserve_tensor_content( &mut self, step: &SemanticPreparedStep, tensor_capacity: usize, ) -> Result<(), SemanticTransitionError>

Reserve private digest storage for original tensors born while recording. The producer derives this bound from its retained allocation capacity.

Source

pub fn reserve_model_work( &mut self, step: &SemanticPreparedStep, event_capacity: usize, ) -> Result<(), SemanticTransitionError>

Reserve and allocate the original producer’s event roster before capture. This does not execute the model or upload any recording-time event data.

Source

pub fn model_work_buffer( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export the original work scratch as U64[capacity,3] before capture. Each row is [actual_units, sticky_overflow, producer_writes]. It is not a canonical receipt or a writable alias of the immutable work descriptors.

Source

pub fn record_model_device_work( &mut self, step: &SemanticPreparedStep, kind: ModelWorkKind, upper_dimensions: &[u64], ) -> Result<usize, SemanticTransitionError>

Reserve an occurrence in the current original recording and enqueue its reset immediately before the producer. A composite operator records one occurrence per actual unit category, rather than charging a dense mask.

Source

pub fn record_model_work( &mut self, step: &SemanticPreparedStep, kind: ModelWorkKind, dimensions: &[u64], ) -> Result<(), SemanticTransitionError>

Append an actual operator occurrence during the original first recording. Geometry is expressed in the agreed unit (coordinates, summands or bytes), not FLOPs, elapsed time, or a caller-computed aggregate cost.

Source

pub fn record_model_invocation( &mut self, step: &SemanticPreparedStep, ) -> Result<(), SemanticTransitionError>

Record at the original model-call site, within its active bank capture. A marker executes only in the selected graph, not once per cold capture.

Source

pub fn record_saved_tensor_work( &mut self, step: &SemanticPreparedStep, witness: &SemanticTensorContentWitness, ) -> Result<(), SemanticTransitionError>

Charge each original saved clone from its retained native tensor layout. A repeated storage still costs another copy when a new witness records another save occurrence. Reusing the same occurrence is rejected.

Source

pub fn prepared_source( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_prefix( &mut self, step: &SemanticPreparedStep, bank: usize, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_record( &mut self, step: &SemanticPreparedStep, role: SemanticStateRole, index: u64, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_range_keys( &self, step: &SemanticPreparedStep, ) -> Result<Vec<(SemanticStateRole, u64)>, SemanticTransitionError>

Source

pub fn prepared_tensor( &mut self, step: &SemanticPreparedStep, role: SemanticStateRole, index: u64, bank: usize, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export the fixed original capacity; live extents remain device inputs.

Source

pub fn prepared_training_view_port( &mut self, step: &SemanticPreparedStep, port: SemanticTrainingViewPort, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export one fixed device port produced by this Update step’s native selection. Its status word remains device-resident and gates consumers.

Source

pub fn prepared_tensor_allocation( &mut self, step: &SemanticPreparedStep, role: SemanticStateRole, index: u64, bank: usize, consumer_stream: u64, ) -> Result<(DeviceAllocationProvenance, DlpackManagedTensor), SemanticTransitionError>

Actual allocation origin and complete backing bytes of the fixed view exported by prepared_tensor. The byte export retains the original step grant and stream ordering. Live extents and version counters are separate.

Source

pub fn prepared_terminal( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_prefix_extent( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_ring_head( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Source

pub fn prepared_model_geometry( &self, step: &SemanticPreparedStep, ) -> Result<(Identity256, Identity256, u64, u64, u64, u64), SemanticTransitionError>

Immutable admitted model geometry; no future publication values occur.

Source

pub fn prepared_model_binding( &mut self, step: &SemanticPreparedStep, consumer_streams: &[u64], ) -> Result<(SemanticPublishedIdentity, Option<SemanticPublishedIdentity>, u64, Identity256, Identity256), SemanticTransitionError>

Authenticate the retained model inputs of an actually completed step. This cold observation joins every original consumer before checking the private input seals and reading that step’s actual acquisition/result. It never acquires a current bank or constructs a historical live reader.

Returns (predecessor, successor-or-None, model generation, model geometry digest, model numerical digest). A numerical refusal has no successor; skipped steps and unknown completion have no observable input binding. Model record 44 and complete model backing allocations are the existing prepared record/tensor exports, retained until original step retirement. Recheck this binding after serializing those read-only exports. This is not complete semantic replay material or authority for another forward.

Source

pub fn prepared_feedback( &mut self, step: &SemanticPreparedStep, consumer_stream: u64, ) -> Result<(SemanticFeedbackSchema, [DlpackManagedTensor; 6]), SemanticTransitionError>

Source

pub fn prepared_feedback_records( &mut self, step: &SemanticPreparedStep, consumer_streams: &[u64], ) -> Result<(SemanticPublishedIdentity, Option<SemanticPublishedIdentity>, Vec<SemanticFeedbackRecordMaterial>), SemanticTransitionError>

Cold readback of each original raw feedback, statement and provenance record, after known completion and before this prepared step retires. The original input guard brackets readback; neither a current-bank reader nor a fresh encoder/semantic query is constructed. These bytes are inputs to the canonical carrier, not an execution or replay grant.

Source

pub fn begin_prepared_segment( &mut self, resources: Vec<Arc<dyn Send + Sync>>, ) -> Result<(SemanticPreparedSegmentCapture, Arc<CudaStream>), SemanticTransitionError>

The caller keeps the builder outside its Session lock while recording original producers. Retained resources own their preallocated pools.

Source

pub fn bind_prepared_model_content( &mut self, step: &SemanticPreparedStep, bank: usize, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticTensorContentWitness, SemanticTransitionError>

Bind the original live model roster cold. Each execution later copies its expected seals from the actual device-acquired publication.

Source

pub fn bind_prepared_gradient_delivery( &mut self, step: &SemanticPreparedStep, bank: usize, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticGradientDeliveryBinding, SemanticTransitionError>

Authenticate and retain the original physical tensor rows used by one prepared bank’s AccumulateGrad delivery owner. Every row must be the exact typed alias of that bank’s roles 18 through 25.

Source

pub fn capture_prepared_tensor_content( &mut self, step: &SemanticPreparedStep, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticTensorContentWitness, SemanticTransitionError>

Attach actual original output owners as they are born during recording. Every private digest cell already exists; this operation cannot allocate device storage or establish a second baseline for native producer aliases.

Source

pub fn record_prepared_tensor_content( &mut self, step: &SemanticPreparedStep, witness: &SemanticTensorContentWitness, verify: bool, ) -> Result<(), SemanticTransitionError>

Source

pub fn bind_prepared_continuation( &mut self, step: &SemanticPreparedStep, bank: usize, continuation: SemanticContinuationInput, witness: &SemanticTensorContentWitness, model_content_witness: Option<&SemanticTensorContentWitness>, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Bind original forward outputs after their private witness was recorded. Numerical copies and native continuation preparation are recorded later by the complete step body; fresh authority bytes are uploaded at submit. Proposal blocks retain this bank’s original model-content witness; their schema and identity come from its acquired device snapshot on each replay.

Source

pub fn record_prepared_model_forward( &mut self, step: &SemanticPreparedStep, bank: usize, role: usize, logits: SemanticTensorInput, consumer_stream: u64, ) -> Result<SemanticModelForwardWitness, SemanticTransitionError>

Bind the complete producer-owned model backing after the original selected-view backward and optimizer update were recorded. The output is copied into the inactive neural bank by a prepared CUDA node before the sole publication transition commits its pointer and generation state. Record one baseline or candidate forward at the actual producer site. The receipt node is inserted into the active prepared bank capture and cannot be reconstructed later from handoff argument position.

Source

pub fn bind_prepared_update_output( &mut self, step: &SemanticPreparedStep, bank: usize, model_memory: SemanticModelMemory, tensors: Vec<SemanticTensorInput>, admissibility: SemanticTensorInput, slab_backing: SemanticTensorInput, baseline_forward: &SemanticModelForwardWitness, candidate_forward: &SemanticModelForwardWitness, witness: &SemanticTensorContentWitness, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn verify_prepared_tensor_content( &mut self, step: &SemanticPreparedStep, witness: &SemanticTensorContentWitness, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_admission( &mut self, step: &SemanticPreparedStep, conditional_handle: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_inputs( &mut self, step: &SemanticPreparedStep, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_requested_bank_gate( &mut self, step: &SemanticPreparedStep, bank: usize, conditional_handle: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_drain_gate( &mut self, step: &SemanticPreparedStep, conditional_handle: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_active_gate( &mut self, step: &SemanticPreparedStep, conditional_handle: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn guard_prepared_content( &mut self, step: &SemanticPreparedStep, keys: &[(SemanticStateRole, u64)], consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Source

pub fn record_prepared_step_release( &mut self, step: &SemanticPreparedStep, ) -> Result<(), SemanticTransitionError>

Source

pub fn finish_prepared_segment( &mut self, executable: &mut Option<SemanticPreparedExecutable>, ) -> Result<(), SemanticTransitionError>

Source

pub fn take_prepared_executable_for_retirement( &mut self, ) -> Result<Option<CapturedCudaGraph>, SemanticTransitionError>

Detach the completed executable so the caller can destroy it outside its Session mutex. The actual allocation resources remain Session-owned until every original prepared step and its final consumers have retired.

Source

pub fn take_prepared_resources_for_retirement( &mut self, ) -> Result<Vec<Arc<dyn Send + Sync>>, SemanticTransitionError>

Return the original pool/model owners only after all joined step owners and their imported aliases are gone. Drop the returned owners unlocked.

Source

pub fn begin_initial_prefill( &mut self, layout: SemanticInitialSourceLayout, model_generation: u64, ) -> Result<SemanticInitialPrefillLease, SemanticTransitionError>

Reserve exactly one native prefill stage for the imported task. The expected tokens come from its admitted source mapping, not a model-side copy. This stage owns the device comparison input before any model call.

Source

pub fn record_initial_prefill_input( &mut self, lease: &SemanticInitialPrefillLease, input: SemanticTensorInput, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Compare the actual I64 tensor at the model’s pre-hook against the admitted prefix on device. The stream edge completes before the model continues, and the original DLPack owner remains in this stage.

Source

pub fn bind_initial_prefill_model_content( &mut self, lease: &SemanticInitialPrefillLease, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticInitialPrefillContentWitness, SemanticTransitionError>

Seal the original model roster before its prefill forward. The caller supplies model tensors followed by their complete original backing allocations, exactly as it will supply them to parent binding.

Source

pub fn capture_initial_prefill_tensor_content( &mut self, lease: &SemanticInitialPrefillLease, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticInitialPrefillContentWitness, SemanticTransitionError>

Capture original pre-call, transient or saved tensors after the model roster is sealed, before any dependent read may change their bytes. Pre-call capture does not replace the actual input pre-hook.

Source

pub fn record_initial_prefill_outputs( &mut self, lease: &SemanticInitialPrefillLease, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Seal the original model outputs at the post-detach wrapper boundary. Every prefill cache/state tensor later supplied to parent binding must be this exact allocation, layout and logical interval.

Source

pub fn verify_initial_prefill_tensor_content( &mut self, lease: &SemanticInitialPrefillLease, witness: &SemanticInitialPrefillContentWitness, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Check the same original prefill seal before a dependent model or saved tensor read, including after the parent has consumed the one-use stage.

Source

pub fn bind_parent( &mut self, parent: SemanticParentBinding, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Snapshot every supplied cold owner into fixed publication storage, then initialize and seal bank zero through the actual native command.

Source

pub fn restore_state_material( &mut self, bytes: &[u8], ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Reconstruct native material into this fresh admitted owner. This performs actual graph insert/seal and native state hashing; it does not establish an episode’s provenance, current use rights, or model replay equivalence. The trusted execution importer must verify those before issuing TaskUse.

Source

pub fn restore_learning_phase_material( &mut self, bytes: &[u8], transition: &SemanticLearningPhaseTransition, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Cold-create a private successor from an authentic complete checkpoint. Only the explicit phase and producer-authorized optimizer reset change; all effective parameters, caches, native records and progress are copied. The public Controller retains the old runnable owner until durable handoff.

Source

pub fn learning_phase_history(&self) -> &[SemanticLearningPhaseRecord]

Actual phase lineage owned by this Session. This is a cold metadata read, not a scientific acceptance result or permission to execute training.

Source

pub fn rebind_restored_training_arena( &mut self, source: &[u8], witness: SemanticTaskGoalWitness, rows: Vec<SemanticTrainingViewRow>, objective: SemanticTrainingObjective, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Admit a new immutable training arena after an exact cold restore, while its Session is still private. The saved publication is the only source of model, replay, receipt and optimizer bytes; only the live task authority binding and its runtime contract are regenerated.

Source

pub fn verify_restored_state_material( &mut self, lease: &SemanticPublishedLease, bytes: &[u8], ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Re-read the selected publication after its external model owner has been reconstructed and prove that it is still the fresh instance recovered from these exact original logical and state roots.

Source

pub fn checkpoint_initial_prefill_material( &mut self, lease: &SemanticPublishedLease, ) -> Result<(Vec<u8>, bool), SemanticTransitionError>

Snapshot the original prefill while its model and output producers are still owned. Later checkpoints reuse these exact seals, never a new baseline from a post-action model or restored publication.

Source

pub fn verify_checkpoint_initial_prefill_source( section: &[u8], native: &[u8], task_identity: Identity256, task_epoch: u64, task_content: SemanticTaskContentIdentity, require_original_publication: bool, ) -> Result<bool, SemanticTransitionError>

Source

pub fn bind_restored_checkpoint_initial_prefill( &mut self, lease: &SemanticPublishedLease, native: &[u8], section: &[u8], referent: &[u8], ) -> Result<(), SemanticTransitionError>

Bind a restored pre-action publication to the exact original prefill section and compact reference of the full checkpoint that carried it.

Source

pub fn acquire( &mut self, ) -> Result<SemanticPublishedLease, SemanticTransitionError>

Source

pub fn retained_step_identity( &self, lease: &SemanticPublishedLease, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Authenticate the original step even after its publication bank retires. This grants no publication access and refuses poisoned or released owners.

Source

pub fn require_retired_publication( &self, lease: &SemanticPublishedLease, ) -> Result<(), SemanticTransitionError>

Prove full consumer retirement of this original publication owner. A retired bank alone, an abort, or a failed identity lookup is not proof that its retained steps, evaluations and captured executables are gone.

Source

pub fn published_identity( &self, lease: &SemanticPublishedLease, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Source

pub fn current_recompute_state_material( &mut self, lease: &SemanticPublishedLease, ) -> Result<Vec<u8>, SemanticTransitionError>

The selected parent must still be the current native publication, and its own sealed attempt must be a successful recompute. A later publish invalidates this admission source; a nonpublishing refusal does not.

Source

pub fn published_range_keys( &self, lease: &SemanticPublishedLease, ) -> Result<Vec<(SemanticStateRole, u64)>, SemanticTransitionError>

Complete ordered role/index roster from this acquired directory, not a prediction from role counts or a read of a newer publication. This is cached structural metadata; it does not certify current tensor bytes.

Source

pub fn guard_published_content( &mut self, lease: &SemanticPublishedLease, keys: &[(SemanticStateRole, u64)], consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Enqueue a live-content check against this reader’s original range seals. Call after hooks/writers and before reads on the declared consumer stream. Integrity corruption invokes an unconditional device trap: the isolated task process must terminate, not reset or reuse its Session/tensors. A successful return means enqueued, not GPU-complete or accepted output. Concurrent external alias writes through the end of consumption are forbidden.

Source

pub fn capture_tensor_content( &mut self, lease: &SemanticPublishedLease, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticTensorContentWitness, SemanticTransitionError>

Capture private device digests after the trusted original computation, before public hooks. This establishes stability, never derivation or rights. The model owner must attach the issued witness to its original execution. Native feedback and fixed input aliases verify their original producer seals; their exact type, shape, interval and coordinate are preserved. Requires stream-ordered allocation support; a synchronizing allocator is never substituted for this enqueue-only path.

Source

pub fn bind_model_content( &mut self, lease: &SemanticPublishedLease, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<SemanticTensorContentWitness, SemanticTransitionError>

Bind the complete live model roster to this parent’s originally sealed model content and generation. A new reader receives a new witness, not a new baseline. Initial physical layout/address may differ; later verify retains this invocation’s exact producer storage and layout. Enqueue-only.

Source

pub fn verify_tensor_content( &mut self, lease: &SemanticPublishedLease, witness: &SemanticTensorContentWitness, tensors: Vec<SemanticTensorInput>, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Verify the actual consumer tensors against the original private witness. Metadata/pointer substitution is a typed input refusal; later byte mutation is a terminal device integrity error. Return is enqueue-only. Ordinary completion/observation must succeed before activating outputs or replay.

Source

pub fn published_source( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export private step-owned physical source slots without host copying or rotation.

Source

pub fn published_terminal( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export the original acquired terminal flag as a read-only U64[1] view into the same private step inputs used by source and model context. The ordinary cold input preparation and retained consumer lifetime apply; no terminal value is inferred from source tokens or model metadata.

Source

pub fn published_model_context( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<SemanticModelContext, SemanticTransitionError>

Join retained acquisition metadata with fixed private prefix identity, extent, ring head and source views. Device acquisition supplies every value once; the step retains these inputs through the final consumer.

Source

pub fn published_resident_model_memory( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<SemanticResidentModelMemory, SemanticTransitionError>

Export the selected resident neural bank without the private step copy used by per-tensor late-backward exports. Full backing allocations occur once and retain the acquired reader, while the returned geometry names every typed view in roles 18..=25. Callers must keep these aliases read-only and release the parent only after every consumer stream joins.

Source

pub fn published_prefix( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<(SemanticPublishedIdentity, DlpackManagedTensor), SemanticTransitionError>

Export this acquired parent’s prefix storage as U64[capacity, 8]. Columns follow SemanticTextSlot exactly, including source/generated provenance and its native ledger index. Only [0, prefix_extent) is committed, including the legal empty prefix; unused capacity must not be consumed as content. The export neither acquires again nor copies rows to host. The managed owner retains the same reader and append-only prefix storage. Consumers must not modify this sealed view and must join their final use through release, just as for published_tensor.

Source

pub fn continuation_rng( &self, lease: &SemanticPublishedLease, ) -> Result<SemanticRngBinding, SemanticTransitionError>

Read RNG coordinates from the actual parent of the pending continuation. The application cannot supply a replacement stream or proposal identity.

Source

pub fn acknowledge_delivery( &mut self, lease: &SemanticPublishedLease, receipt: &[u8], recipient_id: Identity256, verification_key: &[u8; 32], expected_effect: &[u8], ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Verify a durable receiver receipt against the actual current FINAL intent, then append it through the publication word’s sole CAS. This is cold external-effect control, not a model or semantic transition.

Source

pub fn admit_external_activation( &mut self, lease: &SemanticPublishedLease, ) -> Result<(), SemanticTransitionError>

A FINAL acquired bank must contain its actual native terminal intent. This readiness check does not deliver an effect or issue use authority.

Source

pub fn published_tensor( &mut self, lease: &SemanticPublishedLease, role: SemanticStateRole, index: u64, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export the cold physical-capacity tensor shape, retaining its original sealed logical range. Unused rows are not content. Shared prefix caches retain the reader; private input caches retain their original step.

Source

pub fn select_training_view( &mut self, lease: &SemanticPublishedLease, ) -> Result<SemanticSelectedTrainingView, SemanticTransitionError>

Select the exact published training view from the cold resident arena. The host supplies neither an ordinal nor an identity: both the cursor and RNG coordinates come from this acquired publication, while CUDA verifies the complete role-29 bytes before exposing fixed output ports.

Source

pub fn published_tensor_allocation( &mut self, lease: &SemanticPublishedLease, role: SemanticStateRole, index: u64, consumer_stream: u64, ) -> Result<(DeviceAllocationProvenance, DlpackManagedTensor), SemanticTransitionError>

Allocation origin and complete backing bytes of the exact view exported by published_tensor, retaining that view’s reader/step access grant. Exported capacity is not evidence that unused contents are model inputs.

Source

pub fn published_active_rows( &mut self, lease: &SemanticPublishedLease, ) -> Result<SemanticActiveRows, SemanticTransitionError>

Read the map from this acquired bank’s sealed record, not a later pending invocation. Reading these small identity records never reads tensor values.

Source

pub fn published_model_numerical_mode( &mut self, lease: &SemanticPublishedLease, ) -> Result<Vec<u8>, SemanticTransitionError>

Cold read of the original model contribution from this acquired parent. The application freezes external writers; registered consumer prefixes are joined before reading and verifying the original sealed bytes. This is never a host query inside a resident reasoning loop.

Source

pub fn published_state_material( &mut self, lease: &SemanticPublishedLease, ) -> Result<Vec<u8>, SemanticTransitionError>

Cold export of the complete native material reachable from this acquired parent. The bytes carry content, not a use grant or publication authority. The canonical execution carrier must bind them to its original invocation.

Source

pub fn published_replay_evidence( &mut self, predecessor: &SemanticPublishedLease, successor: &SemanticPublishedLease, ) -> Result<Vec<u8>, SemanticTransitionError>

Cold export of native evidence from two genuinely held adjacent publications. Only the successor identity and its six publication-only records enter the evidence; the successor’s full state is not exported. The application must freeze further writers and register all consumer streams before this call. Both later release rosters must include one.

Source

pub fn published_replay_provenance( &mut self, predecessor: &SemanticPublishedLease, successor: &SemanticPublishedLease, ) -> Result<Vec<u8>, SemanticTransitionError>

Cold export of the original authority envelope and actual successor continuation decision from held adjacent publications. The execution carrier stores this as its reconstruction provenance root, not evidence of current rights and not a second copy of the complete predecessor. Further writers must be frozen and every consumer stream registered; both later release rosters must include the guard’s stream one.

Source

pub fn restore_replay_material( &mut self, material: &SemanticReplayMaterial, ) -> Result<SemanticPublishedIdentity, SemanticTransitionError>

Restore already-decoded complete predecessor material through the sole native cold restoration path. Current use authority remains external.

Source

pub fn verify_replay_publication( &mut self, material: &SemanticReplayMaterial, predecessor: &SemanticPublishedLease, successor: &SemanticPublishedLease, ) -> Result<(), SemanticTransitionError>

Compare a genuine rerun with the expected complete logical/state hashes and normalized publication records. Runtime instance/word coordinates differ after restoration and are checked as new lineage, not byte-equal. This cold check neither issues a use grant nor proves historical origin. It guards every actual range of both held readers before cold readback; cached seals alone cannot detect writes through shared tensor aliases. The method owns consumer stream one for both readers. Their later release rosters must include one as well as every application consumer stream.

Source

pub fn published_record( &mut self, lease: &SemanticPublishedLease, role: SemanticStateRole, index: u64, consumer_stream: u64, ) -> Result<DlpackManagedTensor, SemanticTransitionError>

Export the actual bytes of one acquired non-tensor owner, including native raw feedback. This performs no host tensor-value read or numeric cast.

Source

pub fn published_feedback( &mut self, lease: &SemanticPublishedLease, consumer_stream: u64, ) -> Result<SemanticFeedback, SemanticTransitionError>

Encode the exact acquired raw slots and current lineage on the device, without packing or status/validity readback. The projection kernel traps on invalid provenance before the consumer event can become ready. All six outputs receive their original private content seals before export. Later tensor-content capture verifies those seals, not a new baseline made from potentially modified consumer aliases.

Source

pub fn quiesce_published_reader( &mut self, lease: &SemanticPublishedLease, consumer_streams: &[u64], ) -> Result<(), SemanticTransitionError>

Retire all aliases and their final consumer use while keeping the actual native reader acquired. This cold boundary performs the same completion checks as release, but no native decrement. It permits final guarded comparison after callbacks have relinquished their writable aliases.

Source

pub fn release_published_reader( &mut self, lease: &mut SemanticPublishedLease, consumer_streams: &[u64], ) -> Result<(), SemanticTransitionError>

Retire only the actual publication reader after final bank use. Original numerical content, producer seals and policy outputs retain this step. A live bank alias still prevents reuse; no retained content is discarded.

Source

pub fn release( &mut self, lease: &mut SemanticPublishedLease, consumer_streams: &[u64], ) -> Result<(), SemanticTransitionError>

All aliases must have returned their managed owners. Completion events are recorded after final consumer use, joined, and completed before the sole native reader decrement, unless that reader has already retired. Failure retains the original step and every unfinished owner.

Source

pub fn release_prepared_step( &mut self, step: &SemanticPreparedStep, consumer_streams: &[u64], ) -> Result<(), SemanticTransitionError>

Join final consumers and retire one actually completed prepared owner. The device reader was released by its recorded body; this cold operation never issues a second decrement or replaces its original private seals.

Source

pub fn quiesce_prepared_step( &mut self, step: &SemanticPreparedStep, consumer_streams: &[u64], ) -> Result<(), SemanticTransitionError>

Establish final device use without discarding the producer owners. This permits the caller to retire callback-owned aliases outside its mutex.

Source

pub fn admit_transition( &mut self, lease: &SemanticPublishedLease, kind: SemanticTransitionKind, ) -> Result<(), SemanticTransitionError>

Source

pub fn bind_continuation( &mut self, lease: &SemanticPublishedLease, continuation: SemanticContinuationInput, witness: &SemanticTensorContentWitness, consumer_stream: u64, ) -> Result<(), SemanticTransitionError>

Snapshot original forward outputs against this exact admitted reader. Completion records and outputs must come from the forward that consumed the acquired parent; metadata alone never grants use authority.

Source

pub fn policy_layout( &self, ) -> Result<SemanticPolicyLayout, SemanticTransitionError>

Source

pub fn policy_support_layout( &self, ) -> Result<(Vec<Range<usize>>, usize), SemanticTransitionError>

All original category spans in native catalogue order. Inactive TEXT retains its reserved span, but the device emits singleton NULL without reading that span. Selection never changes subsequent category offsets.

Source

pub fn new( provider: &Arc<CudaKernelProvider>, domain: &ResidentExecutionDomain, ) -> Result<Self, SemanticTransitionError>

Source

pub fn from_hypergraph( graph: SemanticHypergraph, ) -> Result<Self, SemanticTransitionError>

Consumes the sole admitted semantic owner. The acquired base, accepted symbol bytes, descriptors and arena remain inseparable for capture/replay.

Source

pub fn from_hypergraph_with_program( graph: SemanticHypergraph, program: Option<&SemanticProgramAdmission>, ) -> Result<Self, SemanticTransitionError>

Bind the source-derived edit grammar before allocating the resident codebooks and policy buffers. The task observer is bound separately.

Source

pub fn is_poisoned(&self) -> bool

Source

pub fn abort(&mut self)

Irreversibly close this owner after trusted application validation fails, including a failure discovered after cold parent binding has completed. All existing readers/controllers consult this same poison state before further execution. Repeated aborts are harmless; no resource is freed, no device work is enqueued, and no poisoned CUDA context is reset. Existing recorded retirement/quarantine retains outstanding owners. A fatal CUDA error still requires termination of the isolated process.

Source

pub fn join_observed_cold_release( &mut self, ) -> Result<(), SemanticTransitionError>

Join the actual cold observer before its fresh, unpublished Session is removed from the Python owner. A failed wait keeps every allocation in that owner and prohibits a restored Session from overlapping it.

Source

pub fn finish_observed_cold_release(self) -> Result<(), SemanticTransitionError>

Destroy the joined cold owner outside the Python Session mutex, then complete the allocator’s real pending deallocations before returning.

Source

pub fn task_observation_roots( &mut self, spec: &SemanticTaskEvaluationSpec, replay: Option<&SemanticReplayMaterial>, ) -> Result<SemanticTaskObservationRoots, SemanticTransitionError>

Inspect the actual cold root, or a decoded replay predecessor, through the retained native admission before importing its task authority. The selected replay is not restored here, and these records establish neither historical execution nor any current use permission.

Source

pub fn bind_task_evaluation( &mut self, spec: SemanticTaskEvaluationSpec, ) -> Result<Identity256, SemanticTransitionError>

Execute the supplied native observer and bind its outputs to this admission. This data binding does not issue publication, inference, or training rights. The trusted controller must independently import those rights before use.

Source

pub fn observe_cold_task_content( &mut self, statement_records: [u32; 3], allowed_support_records: &[u32], program: &dyn SemanticTaskProgram, ) -> Result<(SemanticTaskContentIdentity, [SemanticTruth; 3]), SemanticTransitionError>

Execute the same native observer before the final task import so a context admission can bind its original task content. This read grants no use authority; final import must reproduce the same content exactly.

Source

pub fn bind_task_goal_witness( &mut self, witness: SemanticTaskGoalWitness, ) -> Result<Identity256, SemanticTransitionError>

Bind the controller’s independently validated goal closure to the native task bank before any publication, capture, or model work may begin.

Source

pub fn task_evaluation_identity(&self) -> Option<Identity256>

Identity of the immutable task data bank, not a use-authority token.

Source

pub fn task_content( &self, ) -> Option<(SemanticTaskContentIdentity, [SemanticTruth; 3])>

Exact content identities and observed truths of the currently bound task, excluding its controller authority and scoring policy.

Source

pub fn task_scoring_law_identity( &self, ) -> Result<Option<Identity256>, SemanticTransitionError>

Identity of the exact scoring law bound to the current native task.

Source

pub fn task_objective_law(&self) -> Option<SemanticTaskObjectiveLaw>

The same cold law used by arena admission and checkpoint identity, with no selected denominators or actor-eligibility grant. No device read occurs.

Source

pub fn task_training_domain(&self) -> Option<&SemanticTrainingDomain>

Immutable pre-action input domain. No device read or use grant occurs.

Source

pub fn task_semantic_goal_root(&self) -> Option<Identity256>

Semantic root of the validated goal witness bound to the current task. This is the same root retained in its completed task ground.

Source

pub fn task_priority_levels(&self) -> Option<&[SemanticTaskPriorityLevel]>

Ordered priority levels from the same immutable native task binding consumed by the device selector and later completed task ground.

Source

pub fn bind_training_view_arena( &mut self, rows: Vec<SemanticTrainingViewRow>, objective: SemanticTrainingObjective, ) -> Result<(), SemanticTransitionError>

Bind every admitted training view once while the task is still cold. No row is selected here and the arena cannot be replaced after binding.

Source

pub fn task_evaluation_spec( &self, ) -> Result<&SemanticTaskEvaluationSpec, SemanticTransitionError>

Exact original admission selections in task query order, not inferred from canonical statement values. Support order and duplicates are kept as supplied to the validated binding. These indices grant no use rights.

Source

pub fn feedback_statement_bytes( &self, ) -> Result<[&[u8]; 3], SemanticTransitionError>

Native learned-value projection for the three fixed queries, in query order. Each payload is a length-delimited canonical predicate/arity/argument byte sequence followed by the ordered, length-delimited qualifier values. Encoding-domain and schema-digest service headers are excluded. The original qualified key identity remains separately bound to the task. These schema bytes contain no observer answers or use authority.

Source

pub fn feedback_adapter_identity() -> Identity256

Identity of this build’s actual native feedback projection source, not any statement value, task identity, observer answer or authority decision.

Source

pub fn task_evaluation_epoch(&self) -> u64

Changes on every successful task import, even when data bytes are identical.

Source

pub fn binding(&self) -> SemanticCatalogueBinding

Source

pub fn components(&self) -> &[SemanticComponent]

Source

pub fn descriptor_meaning( &self, field: u32, category: u32, ) -> Option<&SemanticActionDescriptor>

Source

pub fn host_io_stats(&self) -> SemanticTransitionHostIoStats

Source

pub fn root_snapshot( &mut self, ) -> Result<SemanticRootSnapshot, SemanticTransitionError>

Source

pub fn bind_inputs( &mut self, binding: SemanticCatalogueBinding, rng: SemanticRngBinding, inputs: &[SemanticComponentInput], ) -> Result<(), SemanticTransitionError>

Validates the entire binding before touching resident state. The cold owner supplies a globally unique stream namespace and the acquired proposal. This is reconstruction of pending state, not publication or advancement of the canonical RNG. Rebinding after observation keeps the captured addresses.

Source

pub fn capture(&mut self) -> Result<(), SemanticTransitionError>

Source

pub fn launch(&mut self) -> Result<(), SemanticTransitionError>

Nonblocking replay. All 136 distributions and RNG blocks execute on device.

Source

pub fn observe( &mut self, expected_proposal: u32, ) -> Result<SemanticTransitionOutcome, SemanticTransitionError>

Waits for completion, copies the typed bank into pinned memory, then observes the actual immutable hypergraph root. Unreconciled failures poison reuse; verified ordinary refusals retain the original invocation for finalization.

Trait Implementations§

Source§

impl Drop for SemanticTransitionSession

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.