## Body whitelist `fabric.module` body may contain only: * `fabric.pe` (both `[spatial]` and `[temporal]`) * `fabric.switch` (both `[spatial]` and `[temporal]`; see `docs/spec-fabric-switch.md`) * `fabric.mem` (an optional `[spatial]` or `[temporal]` Operation Engine, an optional Local Memory Service, or both; see `docs/spec-fabric-mem.md`) * `fabric.fifo` (see `docs/spec-fabric-fifo.md`) * nested named `fabric.module` template declarations; sibling top-level declarations remain in their enclosing symbol table rather than the body * `fabric.instantiate` (binds a previously-defined fabric symbol into this scope; see `docs/spec-fabric-instantiate.md`) * `fabric.boundary` (single op covering all three boundary directions -- `[s2t]`, `[t2t]`, `[t2s]` -- between the spatial `bits` domain and the temporal `bits_tag` domain; see `docs/spec-fabric-boundary.md`) * `fabric.yield` (terminator) `builtin.unrealized_conversion_cast` is **not** in the whitelist. All fabric module values must come from a real fabric producer (a sub- module result) or from the module's entry-block arguments.