MS2V2 mlir-stage-25-v1 passing 5000/5000
Estimated confidence: 90.8%. Conservative lower bound: 33.3% (95% level).
uniform over observed structural partitions. observed partitions; unseen partitions have no supplied target weight. Partitions use recursive production counts and derivation depth. Behavioral classes combine each input’s compiler coverage and assertion decision paths. Catalog partitions with no observations retain maximal missing mass.
Baseline tests: Every tracked test file with a RUN line invoking loom-raise-opt (77 files); other executables and native unit tests excluded
| Source file | Baseline coverage | Baseline + input | Contributing input |
|---|---|---|---|
…/lib/Frontend/Raising/MaterializeFMulAddPass.cppMS2V | 70/106lines66.0% 11/26branches42.3% | 71/106lines67.0%+1 12/26branches46.2%+1 | +1 line · +1 branchOpen PBT |
1 newly covered line · 1 newly covered branch175 | |||
…/lib/Dataflow/Transforms/DataflowRewritePass.cppMS2V | 338/559lines60.5% 172/340branches50.6% | 338/559lines60.5%+0 172/340branches50.6%+0 | Open PBT |
…/lib/Frontend/Lowering/ExpandGraphMemrefCopyPass.cppMS2V | 79/90lines87.8% 20/22branches90.9% | 79/90lines87.8%+0 20/22branches90.9%+0 | Open PBT |
…/lib/Frontend/Lowering/LowerForToGraphPass.cppMS2V | 1033/1240lines83.3% 374/540branches69.3% | 1033/1240lines83.3%+0 374/540branches69.3%+0 | Open PBT |
…/lib/Frontend/Lowering/LowerForallToThreadPass.cppMS2V | 30/34lines88.2% 2/4branches50.0% | 30/34lines88.2%+0 2/4branches50.0%+0 | Open PBT |
…/lib/Frontend/Lowering/LowerGraphConstantsPass.cppMS2V | 80/83lines96.4% 18/24branches75.0% | 80/83lines96.4%+0 18/24branches75.0%+0 | Open PBT |
…/lib/Frontend/Lowering/LowerGraphMemoryPass.cppMS2V | 525/841lines62.4% 208/400branches52.0% | 525/841lines62.4%+0 208/400branches52.0%+0 | Open PBT |
…/lib/Frontend/Lowering/Pipeline.cppMS2V | 18/21lines85.7% branchesnot measured | 18/21lines85.7%+0 branchesnot measured | Open PBT |
…/lib/Frontend/Raising/CallableRegions.hMS2V | 32/34lines94.1% 12/16branches75.0% | 32/34lines94.1%+0 12/16branches75.0%+0 | Open PBT |
…/lib/Frontend/Raising/DeduplicateSCFWhileStatePass.cppMS2V | 13/135lines9.6% 0/60branches0.0% | 13/135lines9.6%+0 0/60branches0.0%+0 | Open PBT |
…/lib/Frontend/Raising/LLVMArithToArithPass.cppMS2V | 300/319lines94.0% 94/116branches81.0% | 300/319lines94.0%+0 94/116branches81.0%+0 | Open PBT |
…/lib/Frontend/Raising/LLVMCfToCfPass.cppMS2V | 77/80lines96.2% 8/8branches100.0% | 77/80lines96.2%+0 8/8branches100.0%+0 | Open PBT |
…/lib/Frontend/Raising/LiftCFToSCFPass.cppMS2V | 616/694lines88.8% 293/386branches75.9% | 616/694lines88.8%+0 293/386branches75.9%+0 | Open PBT |
…/lib/Frontend/Raising/NormalizeLiftedSCFExitPass.cppMS2V | 232/250lines92.8% 120/182branches65.9% | 232/250lines92.8%+0 120/182branches65.9%+0 | Open PBT |
…/lib/Frontend/Raising/Pipeline.cppMS2V | 10/19lines52.6% branchesnot measured | 10/19lines52.6%+0 branchesnot measured | Open PBT |
…/lib/Frontend/Raising/SCFForToForallPass.cppMS2V | 494/738lines66.9% 241/458branches52.6% | 494/738lines66.9%+0 241/458branches52.6%+0 | Open PBT |
…/lib/Frontend/Raising/SCFWhileToForPass.cppMS2V | 164/176lines93.2% 70/94branches74.5% | 164/176lines93.2%+0 70/94branches74.5%+0 | Open PBT |
…/loom/tools/loom-raise-opt/loom-raise-opt.cppMS2V | 12/12lines100.0% branchesnot measured | 12/12lines100.0%+0 branchesnot measured | Open PBT |
Review PR: Regression test from seed 4
candidate to D0 and checks exact concrete Fabric admission. No unresolved parent, mixed Fused/Split child, hidden backend default, or target-code-generation choice may cross the ExecutionShape boundary.
llvm.func @f0(%arg0: f64, %arg1: f64, %arg2: f64) -> f64 { %residual = llvm.fmul %arg0, %arg1 : f64 %v0 = llvm.intr.fmuladd(%arg0, %arg1, %arg2) {fastmathFlags = #llvm.fastmath<nnan>} : (f64, f64, f64) -> f64 llvm.return %v0 : f64 } llvm.func @f1(%arg0: f64, %arg1: f64, %arg2: f64) -> f64 { llvm.return %arg2 : f64 }
The current Structured ExecutionShape generator consumes a finite set of exact Structured Program references. An empty input set produces an empty output set.
llvm.intr.fmuladd remains unchanged in S0 until one typed
ExecutionShape decision materializes either Fused or
Split(arith.mulf, arith.addf) under the exact floating environment and
fast-math contract.
A parent containing an unresolved, exactly representable
llvm.intr.fmuladd emits the canonical pair of complete Structured children:
One decision applies uniformly to every unresolved fmuladd in the selected
Spatial ownership of that complete parent. It never rewrites residual
InstructionCore operations or operations owned by nested callables.
That decision is candidate lineage and may be evaluated as a performance choice; target code generation cannot choose it implicitly. The Ownership generator selects the Spatial region but does not own this decision.
candidate.pg// Structured ExecutionShape generator inputs: a finite set of exact Structured // Program references (imported llvm.func callables), each either free of any // unresolved execution-shape choice or carrying unresolved, exactly // representable llvm.intr.fmuladd operations in its own callable ownership. start: {new NFUN = random.randint(1, 3); new F = 0} funcs; funcs: (F < NFUN) function {F += 1} funcs | (F == NFUN) ''; function: {new TY = random.choice(['f32', 'f64', 'vector<4xf32>']); new NOPS = random.randint(0, 2); new I = 0; new LAST = '%arg2'; new RESIDUAL = random.choice([0, 1])} 'llvm.func @' fname '(%arg0: ' tyx ', %arg1: ' tyx ', %arg2: ' tyx ') -> ' tyx ' {\n' residual body ' llvm.return ' lastx ' : ' tyx '\n' '}\n'; fname: ['f' + str(F)]; tyx: [TY]; lastx: [LAST]; idx: [str(I)]; // A residual InstructionCore operation the ExecutionShape generator must not // rewrite: it states no unresolved execution-shape choice. residual: (RESIDUAL == 1) ' %residual = llvm.fmul %arg0, %arg1 : ' tyx '\n' | (RESIDUAL == 0) ''; body: (I < NOPS) fmuladd_op {I += 1} body | (I == NOPS) ''; fmuladd_op: {new FM = random.choice(['', ' {fastmathFlags = #llvm.fastmath<nnan>}', ' {fastmathFlags = #llvm.fastmath<contract>}', ' {fastmathFlags = #llvm.fastmath<nnan, contract>}'])} ' %v' idx ' = llvm.intr.fmuladd(%arg0, %arg1, ' lastx ')' fmx ' : (' tyx ', ' tyx ', ' tyx ') -> ' tyx '\n' {LAST = '%v' + str(I)}; fmx: [FM];
No unresolved parent, mixed Fused/Split child, hidden backend default, or target-code-generation choice may cross the ExecutionShape boundary.
candidate.spctpostcondition execution_shape_boundary_is_closed { language v0; vocabulary mlir = mlir.generic@1; metadata { project = "PolyArch/loom"; revision = "48615bc5925ef4b9db8b4550b5d4322933cf4b7b"; source = "docs/spec-compiler-part-2-scf.md:L1042-L1044"; } constraints { let unresolved = seq { op | op in output.operations where op.name == "llvm.intr.fmuladd" }; let fused_children = seq { op | op in output.operations where op.name == "math.fma" }; let split_children = seq { op | op in output.operations where op.name == "arith.mulf" or op.name == "arith.addf" }; // No unresolved parent crosses the ExecutionShape boundary. assert no_unresolved_parent: cardinality(unresolved) == 0; // No mixed Fused/Split child crosses the ExecutionShape boundary: the one // decision applies uniformly to the whole published output set. assert no_mixed_fused_split_child: cardinality(fused_children) == 0 or cardinality(split_children) == 0; // No hidden backend default or target-code-generation choice crosses the // boundary: a published Split child never restates the `contract` // permission that would let a later pass or the backend re-fuse the pair // into one rounding, so the materialized shape is the whole decision. forall child in split_children { assert split_child_leaves_no_refusion_choice: "fastmath" in child.attributes implies (child.attributes["fastmath"].canonical_text == "#arith.fastmath<none>" or child.attributes["fastmath"].canonical_text == "#arith.fastmath<nnan>"); } } }
20260911-183119started2026-09-11T18:31:19Zsubjectloom-raise-optsubject revision48615bc5925erun results
output condition verdicts
raw trace evidence
llvm.func @f0(%arg0: f64, %arg1: f64, %arg2: f64) -> f64 { %residual = llvm.fmul %arg0, %arg1 : f64 %v0 = llvm.intr.fmuladd(%arg0, %arg1, %arg2) {fastmathFlags = #llvm.fastmath<nnan>} : (f64, f64, f64) -> f64 llvm.return %v0 : f64 } llvm.func @f1(%arg0: f64, %arg1: f64, %arg2: f64) -> f64 { llvm.return %arg2 : f64 }
"builtin.module"() ({ "llvm.func"() <{CConv = #llvm.cconv<ccc>, function_type = !llvm.func<f64 (f64, f64, f64)>, linkage = #llvm.linkage<external>, sym_name = "f0", unnamed_addr = 0 : i64, visibility_ = 0 : i64}> ({ ^bb0(%arg3: f64, %arg4: f64, %arg5: f64): %0 = "llvm.fmul"(%arg3, %arg4) <{fastmathFlags = #llvm.fastmath<none>}> : (f64, f64) -> f64 %1 = "arith.mulf"(%arg3, %arg4) <{fastmath = #arith.fastmath<nnan>}> : (f64, f64) -> f64 %2 = "arith.addf"(%1, %arg5) <{fastmath = #arith.fastmath<nnan>}> : (f64, f64) -> f64 "llvm.return"(%2) : (f64) -> () }) : () -> () "llvm.func"() <{CConv = #llvm.cconv<ccc>, function_type = !llvm.func<f64 (f64, f64, f64)>, linkage = #llvm.linkage<external>, sym_name = "f1", unnamed_addr = 0 : i64, visibility_ = 0 : i64}> ({ ^bb0(%arg0: f64, %arg1: f64, %arg2: f64): "llvm.return"(%arg2) : (f64) -> () }) : () -> () }) : () -> ()
partial source coverage: Approved for execution and public reporting; translation accuracy and completeness remain separately unvalidated.
authoring-context.json{"entries":[{"file_sha256":"bfc1e646e91fe0ba6d7d16e43994100b05c3b8ff79c2e07288e8955c43d9d79d","kind":"documentation_input","lines":"1016-1044","path":"docs/spec-compiler-part-2-scf.md","roles":["context","applicability","input_construction"],"text":"### Structured ExecutionShape Generator\n\nThe current Structured ExecutionShape generator consumes a finite set of exact\nStructured Program references. An empty input set produces an empty output\nset. A parent with no unresolved selected-Spatial execution-shape choice passes\nthrough unchanged. A parent containing an unresolved, exactly representable\n`llvm.intr.fmuladd` emits the canonical pair of complete Structured children:\n\n```text\nFused -> math.fma\nSplit -> arith.mulf followed by arith.addf\n```\n\nOne decision applies uniformly to every unresolved `fmuladd` in the selected\nSpatial ownership of that complete parent. It never rewrites residual\nInstructionCore operations or operations owned by nested callables. This is a\ntwo-element semantic policy domain, not one independent Boolean dimension per\noperation. Distinct per-operation combinations are not part of the current\ncontract.\n\nEach child preserves the exact floating type, fast-math contract, source\nlocation, Ownership lineage, and source-provenance projection. It is verified\nand finalized through the sole Structured Program finalizer before publication\nto the output set. Schedule and MemoryCommunication may then form further\ncomplete Structured children. The terminal SpecialMathAccuracy generator is\nthe selected-Spatial semantic-closure gate that first lowers the final complete\ncandidate to D0 and checks exact concrete Fabric admission. No unresolved\nparent, mixed Fused/Split child, hidden backend default, or\ntarget-code-generation choice may cross the ExecutionShape boundary.","why":"Governing context of the selected obligation: the ExecutionShape generator consumes exact Structured Program references, a parent with no unresolved choice passes through unchanged, and a parent holding an unresolved exactly representable llvm.intr.fmuladd emits the canonical Fused/Split child pair. Fixes what the sampled inputs must be and which outputs the obligation governs."},{"file_sha256":"bfc1e646e91fe0ba6d7d16e43994100b05c3b8ff79c2e07288e8955c43d9d79d","kind":"documentation_input","lines":"177-185","path":"docs/spec-compiler-part-2-scf.md","roles":["input_construction","input_well_formedness"],"text":"FMA normalization is semantic rather than name based. An exact fused LLVM FMA\nbecomes `math.fma`. `llvm.intr.fmuladd` remains unchanged in S0 until one typed\n`ExecutionShape` decision materializes either `Fused` or\n`Split(arith.mulf, arith.addf)` under the exact floating environment and\nfast-math contract. That decision is candidate lineage and may be evaluated as\na performance choice; target code generation cannot choose it implicitly. The\nOwnership generator selects the Spatial region but does not own this decision.\nThe ExecutionShape generator resolves it before Schedule or Dataflow lowering\nmay consume the candidate. After materialization, no `fmuladd` operation may","why":"States that llvm.intr.fmuladd stays unresolved in S0 until one typed ExecutionShape decision materializes Fused or Split(arith.mulf, arith.addf) under the exact floating environment and fast-math contract, and that target code generation may not choose it implicitly. Drives generating unresolved intrinsics with explicit fast-math contracts as the input domain."},{"file_sha256":"2b0705aba1c16c80e5338d443989a9cdcbac47a60c140bff5b886c617a9f9a8f","kind":"implementation","lines":"1-33","path":"lib/Frontend/Raising/MaterializeFMulAddPass.cpp","roles":["applicability","context"],"text":"// Materialize the execution shape of `llvm.intr.fmuladd`.\n//\n// `llvm.intr.fmuladd` is not a computation, it is an unmade choice: the target\n// may contract it into one fused multiply-add with a single rounding, or\n// evaluate an ordinary multiply followed by an ordinary add with two. The two\n// results differ, so nothing downstream may pick one implicitly and no shape\n// can be inferred from the intrinsic spelling. Mechanical raising therefore\n// leaves the intrinsic alone, and this pass materializes exactly the one shape\n// its caller selected:\n//\n// Fused -> math.fma\n// Split -> arith.mulf then arith.addf\n//\n// The two shapes differ in what they permit, not only in what they spell.\n// Fused carries the complete source fast-math contract onto the one fused\n// operation. Split consumes the source's `contract` permission: the multiply\n// and the add each round on their own, and neither may be contracted back\n// into a single rounding by a later pass or by target code generation.\n//\n// The selected shape is the entire decision this pass makes, so it is a\n// required typed option rather than a defaulted one, in the same shape as the\n// typed Dataflow rewrite catalog.\n//\n// A materialization is legal only when the target operations restate the whole\n// source computation: exact numeric types, the operation's fast-math contract,\n// the default floating-point environment the intrinsic is evaluated in, and\n// the enclosing callable's floating-point environment. `math.fma` and the\n// `arith` floating operations state no environment of their own, so a callable\n// stating one that they cannot restate cannot receive either shape.\n//\n// Representability is intrinsic-local. An intrinsic whose complete semantics\n// the selected standard form cannot restate remains explicit; it does not\n// prevent representable siblings from receiving the selected shape.","why":"Pass header states the stage identity (Fused -> math.fma, Split -> arith.mulf then arith.addf), that the shape is a required typed option with no default, and that representability is intrinsic-local. Confirms the stage attribution of the sampled obligation and the op names the output condition observes."},{"file_sha256":"2b0705aba1c16c80e5338d443989a9cdcbac47a60c140bff5b886c617a9f9a8f","kind":"verifier","lines":"59-98","path":"lib/Frontend/Raising/MaterializeFMulAddPass.cpp","roles":["applicability","context"],"text":"void materializeOne(::mlir::LLVM::FMulAddOp op, FMulAddExecutionShape shape,\n ::mlir::IRRewriter &rewriter) {\n rewriter.setInsertionPoint(op);\n ::mlir::Location loc = op.getLoc();\n ::mlir::Type type = op.getRes().getType();\n ::mlir::arith::FastMathFlags fastmath =\n loom::raising::exactFastMathFlags(op.getFastmathFlags());\n // No materialized operation states a rounding mode. An arith or math\n // operation that states one is a constrained operation: standard lowering\n // turns it into `llvm.intr.experimental.constrained.*` under an explicit\n // rounding and exception mode, and drops the fast-math flags on the way.\n // llvm.intr.fmuladd is an ordinary non-constrained intrinsic in the default\n // environment, so both shapes leave the mode absent and lower back to\n // ordinary LLVM floating operations.\n if (shape == FMulAddExecutionShape::Fused) {\n // Fusing is what the shape decided, so the complete source contract,\n // `contract` included, carries onto the one fused operation.\n rewriter.replaceOpWithNewOp<::mlir::math::FmaOp>(\n op, type, op.getA(), op.getB(), op.getC(), fastmath);\n return;\n }\n\n // `contract` is the source's permission to fuse this multiply and add into\n // one rounding. Selecting Split is the decision that declines it, so the\n // permission is consumed here rather than restated on the result: a\n // multiply and an add that still carried it would let any later contraction\n // -- upstream's own arith-to-math.fma uplift, or a backend -- re-fuse them\n // and silently undo the shape. Every other source flag is a property of the\n // computation, not of fusion, and carries onto both operations unchanged.\n ::mlir::arith::FastMathFlags split = ::mlir::arith::bitEnumClear(\n fastmath, ::mlir::arith::FastMathFlags::contract);\n\n auto product =\n ::mlir::arith::MulFOp::create(rewriter, loc, type, op.getA(), op.getB());\n product.setFastmath(split);\n auto sum = ::mlir::arith::AddFOp::create(rewriter, loc, type,\n product.getResult(), op.getC());\n sum.setFastmath(split);\n rewriter.replaceOp(op, sum);\n}","why":"materializeOne is the acceptance implementation of the boundary: it replaces the intrinsic with math.fma carrying the full contract, or with an arith.mulf/arith.addf pair whose `contract` permission is cleared so no later pass or backend may re-fuse them. Basis for reading 'hidden backend default / target-code-generation choice' as the contract-free Split children asserted in the postcondition."},{"file_sha256":"2b0705aba1c16c80e5338d443989a9cdcbac47a60c140bff5b886c617a9f9a8f","kind":"verifier","lines":"100-115,148-181","path":"lib/Frontend/Raising/MaterializeFMulAddPass.cpp","roles":["applicability","input_well_formedness"],"text":"void appendRepresentable(\n ::mlir::Operation *operation,\n ::llvm::SmallVectorImpl<::mlir::LLVM::FMulAddOp> &selected) {\n auto fmuladd = ::mlir::dyn_cast<::mlir::LLVM::FMulAddOp>(operation);\n if (fmuladd && loom::raising::restatesExactly(fmuladd.getOperation(),\n /*floating=*/true))\n selected.push_back(fmuladd);\n}\n\nvoid materializeSelected(::mlir::MLIRContext &context,\n ::llvm::ArrayRef<::mlir::LLVM::FMulAddOp> selected,\n FMulAddExecutionShape shape) {\n ::mlir::IRRewriter rewriter(&context);\n for (::mlir::LLVM::FMulAddOp op : selected)\n materializeOne(op, shape, rewriter);\n}\n // The shape is the decision, so there is no default: silently choosing one\n // would materialize a form the caller never selected.\n ::mlir::Pass::Option<FMulAddExecutionShape> shape{\n *this, \"shape\",\n ::llvm::cl::desc(\"execution shape to materialize for llvm.intr.fmuladd\"),\n ::llvm::cl::values(\n clEnumValN(FMulAddExecutionShape::Fused, \"fused\",\n \"one math.fma with a single rounding\"),\n clEnumValN(FMulAddExecutionShape::Split, \"split\",\n \"an arith.mulf followed by an arith.addf\"))};\n\n void runOnOperation() final {\n if (!shape.hasValue()) {\n getOperation()->emitError(\n \"loom-materialize-fmuladd requires an explicit 'shape' option\");\n return signalPassFailure();\n }\n\n ::llvm::SmallVector<::mlir::LLVM::FMulAddOp> selected;\n (void)loom::raising::forEachCallableRegion(\n getOperation(), [&](::mlir::Region ®ion) {\n (void)loom::raising::forEachOwnedOperation(\n region, [&](::mlir::Operation *op) {\n appendRepresentable(op, selected);\n return ::mlir::WalkResult::advance();\n });\n return ::mlir::success();\n });\n\n if (selected.empty())\n return markAllAnalysesPreserved();\n\n materializeSelected(getContext(), selected, shape.getValue());\n }","why":"Collection over callable regions of exactly representable intrinsics, and the required `shape` option whose absence makes the pass emit an error and fail. Establishes that the subject invocation must carry shape=fused|split and that only representable intrinsics inside callable regions are resolved, which the grammar guarantees."},{"file_sha256":"fc8794a0235430f2ab7b87b0fb63e4991acfa052ab630501b484fce956154a56","kind":"verifier","lines":"21-52,123-161","path":"lib/Frontend/Raising/ExactStandardSpelling.h","roles":["input_well_formedness","input_construction"],"text":"// The conditions under which a standard `arith` or `math` operation restates\n// an LLVM computation exactly. Mechanical alias normalization and typed\n// fmuladd materialization both have to prove the same facts, so they are\n// stated once here rather than restated per pass.\n\n// True when `type` has an exact standard counterpart: a signless integer of\n// non-zero width, `index`, a float, or a fixed-shape vector of those.\n//\n// arith rejects zero-width and signed integers. A scalable vector's element\n// count is a runtime `vscale` multiple rather than a shape, so it fails closed\n// here and keeps its operations in llvm form: only once a typed structured\n// transform has materialized the computation as fixed-width chunks, loops, and\n// masks or tails do the resulting operations hold a fixed shape that these\n// aliases accept.\ninline bool isExactNumericType(::mlir::Type type) {\n if (auto vectorType = ::mlir::dyn_cast<::mlir::VectorType>(type)) {\n if (vectorType.isScalable())\n return false;\n type = vectorType.getElementType();\n }\n if (auto integerType = ::mlir::dyn_cast<::mlir::IntegerType>(type))\n return integerType.isSignless() && integerType.getWidth() > 0;\n return ::mlir::isa<::mlir::IndexType, ::mlir::FloatType>(type);\n}\n\ninline bool allExactNumericTypes(::mlir::ValueRange values) {\n for (::mlir::Value value : values) {\n if (!isExactNumericType(value.getType()))\n return false;\n }\n return true;\n}\ninline bool statesFloatingPolicy(::mlir::LLVM::LLVMFuncOp funcOp) {\n if (auto env = funcOp.getDenormalFpenvAttr())\n if (!statesDefaultDenormalEnvironment(env))\n return true;\n if (auto noSignedZeros = funcOp.getNoSignedZerosFpMathAttr())\n if (noSignedZeros.getValue())\n return true;\n if (auto contraction = funcOp.getFpContractAttr())\n if (contraction.getValue() != \"off\")\n return true;\n if (funcOp.getReciprocalEstimatesAttr())\n return true;\n if (auto passthrough = funcOp.getPassthroughAttr())\n for (::mlir::Attribute entry : passthrough)\n if (passthroughEntryStatesFloatingPolicy(entry))\n return true;\n return false;\n}\n\n// True when the enclosing callable states a floating-point environment the\n// standard operation cannot restate.\ninline bool enclosingFloatingPolicyBlocksRewrite(::mlir::Operation *op) {\n auto funcOp = ::mlir::dyn_cast_or_null<::mlir::LLVM::LLVMFuncOp>(\n getNearestCallableOp(op));\n return funcOp && statesFloatingPolicy(funcOp);\n}\n\n// True when every operand and the single result of `op` have an exact standard\n// counterpart and, for a computation that reads or produces a floating value,\n// the enclosing callable states no environment the standard operation cannot\n// restate. An integer computation is independent of that environment and is\n// never blocked by it.\ninline bool restatesExactly(::mlir::Operation *op, bool floating) {\n if (!allExactNumericTypes(op->getOperands()))\n return false;\n if (!isExactNumericType(op->getResult(0).getType()))\n return false;\n return !floating || !enclosingFloatingPolicyBlocksRewrite(op);\n}","why":"Defines exact representability: exact numeric types (float or fixed-shape vector of floats accepted; scalable vectors rejected) and an enclosing llvm.func stating no floating-point policy (denormal env, nsz, fp_contract, reciprocal_estimates, passthrough). The grammar samples only f32/f64/vector<4xf32> operands in attribute-free llvm.func callables so every generated fmuladd is exactly representable and no unresolved parent may legitimately survive."},{"file_sha256":"fc8794a0235430f2ab7b87b0fb63e4991acfa052ab630501b484fce956154a56","kind":"verifier","lines":"163-189","path":"lib/Frontend/Raising/ExactStandardSpelling.h","roles":["input_construction"],"text":"// arith counterpart of LLVM's fast-math flags. Both enums name the same\n// seven facts but assign them different bit positions, so each flag is\n// mapped by name instead of being reinterpreted.\ninline ::mlir::arith::FastMathFlags\nexactFastMathFlags(::mlir::LLVM::FastmathFlags flags) {\n const std::pair<::mlir::LLVM::FastmathFlags, ::mlir::arith::FastMathFlags>\n equivalents[] = {\n {::mlir::LLVM::FastmathFlags::nnan,\n ::mlir::arith::FastMathFlags::nnan},\n {::mlir::LLVM::FastmathFlags::ninf,\n ::mlir::arith::FastMathFlags::ninf},\n {::mlir::LLVM::FastmathFlags::nsz, ::mlir::arith::FastMathFlags::nsz},\n {::mlir::LLVM::FastmathFlags::arcp,\n ::mlir::arith::FastMathFlags::arcp},\n {::mlir::LLVM::FastmathFlags::contract,\n ::mlir::arith::FastMathFlags::contract},\n {::mlir::LLVM::FastmathFlags::afn, ::mlir::arith::FastMathFlags::afn},\n {::mlir::LLVM::FastmathFlags::reassoc,\n ::mlir::arith::FastMathFlags::reassoc}};\n\n ::mlir::arith::FastMathFlags result{};\n for (auto [llvmFlag, arithFlag] : equivalents) {\n if (::mlir::LLVM::bitEnumContainsAll(flags, llvmFlag))\n result = result | arithFlag;\n }\n return result;\n}","why":"exactFastMathFlags maps the LLVM fast-math flag names onto the arith flags one-for-one, which fixes the finite fast-math spellings the generator samples (none, nnan, contract, nnan+contract) and the resulting arith attribute spellings the postcondition compares against."},{"file_sha256":"d1315fabeb736f07fdd93eca093e20d05a201967b181a40cb02f37048ba2c79a","kind":"implementation","lines":"15-95","path":"lib/Frontend/Raising/CallableRegions.h","roles":["input_construction","applicability"],"text":"// True when `op` is a callable whose own region is the subject of a separate\n// region-level raising decision. An S0 program contains exactly two callable\n// kinds: an imported llvm.func and a genuinely standard-MLIR-native func.func.\n// It is deliberately not every FunctionOpInterface operation, because a later\n// ownership carrier such as a Dataflow definition is not an input to\n// mechanical raising and its region is not something these passes can claim to\n// structure exactly.\n//\n// Both kinds are callables, but only one is an imported LLVM ABI authority. A\n// native func.func is a callable region raised like any other and is never an\n// ABI envelope: a floating-point environment is read only when the nearest\n// callable is an llvm.func, and an llvm.func is never copied into another\n// dialect to obtain a pass wrapper. That leaves llvm.func the sole imported\n// LLVM callable and ABI owner of its body.\ninline bool isCallableOp(::mlir::Operation *op) {\n return ::mlir::isa<::mlir::LLVM::LLVMFuncOp, ::mlir::func::FuncOp>(op);\n}\n\n// Return the nearest callable that owns `op`, or null when `op` is outside\n// every callable region. A nested callable cuts off ownership inherited from\n// any callable above it.\ninline ::mlir::Operation *getNearestCallableOp(::mlir::Operation *op) {\n for (::mlir::Operation *parent = op->getParentOp(); parent;\n parent = parent->getParentOp()) {\n if (isCallableOp(parent))\n return parent;\n }\n return nullptr;\n}\n\n// Run `transform` on every non-empty region of every callable reachable from\n// `root`, visiting nested callables before their ancestors and stopping at the\n// first failure.\n//\n// Callable regions are the sole subject of mechanical raising. An imported\n// llvm.func owns its body and its complete ABI envelope, so raising rewrites\n// that body where it stands instead of copying the function into another\n// dialect to obtain a pass wrapper. A region outside a callable, such as an\n// llvm.mlir.global initializer, carries no recoverable control flow and must\n// stay expressible as an LLVM constant, so it is never rewritten.\ninline ::mlir::LogicalResult forEachCallableRegion(\n ::mlir::Operation *root,\n ::llvm::function_ref<::mlir::LogicalResult(::mlir::Region &)> transform) {\n ::mlir::WalkResult walked =\n root->walk<::mlir::WalkOrder::PostOrder>([&](::mlir::Operation *op) {\n if (!isCallableOp(op))\n return ::mlir::WalkResult::advance();\n for (::mlir::Region ®ion : op->getRegions()) {\n if (region.empty())\n continue;\n if (failed(transform(region)))\n return ::mlir::WalkResult::interrupt();\n }\n return ::mlir::WalkResult::advance();\n });\n return walked.wasInterrupted() ? ::mlir::failure() : ::mlir::success();\n}\n\n// Offer `visit` to every operation `region` owns, recursing into nested\n// regions that belong to the same callable -- scf.for, scf.if, a graph\n// region -- but stopping at any nested callable, whose own body this region\n// must not claim to own.\n//\n// This is the operation-level half of callable ownership: a callable processes\n// exactly the operations its nearest enclosing callable owns, and a nested\n// callable's body is left to that callable's own region-level walk. Crossing\n// into a nested callable here would visit its operations twice -- once\n// descended into from the enclosing region and once from the callable's own\n// walk -- so the nested callable is pruned instead. Pruning happens in\n// pre-order: in a post-order walk a callable's body is visited before the\n// callable itself, so the skip would arrive one descent too late.\ninline ::mlir::WalkResult forEachOwnedOperation(\n ::mlir::Region ®ion,\n ::llvm::function_ref<::mlir::WalkResult(::mlir::Operation *)> visit) {\n return region.walk<::mlir::WalkOrder::PreOrder>(\n [&](::mlir::Operation *op) -> ::mlir::WalkResult {\n if (isCallableOp(op))\n return ::mlir::WalkResult::skip();\n return visit(op);\n });\n}","why":"Callable ownership: only llvm.func and func.func are callable regions, a nested callable cuts off ownership, and a region outside every callable is never rewritten. Justifies generating top-level llvm.func parents that own their fmuladd operations so the obligation applies to every generated parent."},{"file_sha256":"6f55dfe3ca2a9edcd0d955b965b5011a8010478cf28db89485df1fdfb2750c9c","kind":"test","lines":"1-10","path":"test/raise/fmuladd-materialization.mlir","roles":["applicability","context"],"text":"// RUN: split-file %s %t\n// RUN: not loom-raise-opt --loom-materialize-fmuladd %t/choice.mlir 2>&1 | FileCheck %s --check-prefix=UNSELECTED\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=fused %t/choice.mlir | FileCheck %s --check-prefix=FUSED\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=split %t/choice.mlir | FileCheck %s --check-prefix=SPLIT\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=fused %t/choice.mlir | mlir-opt --convert-math-to-llvm --convert-arith-to-llvm | FileCheck %s --check-prefix=FUSED-LLVM --implicit-check-not=constrained\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=split %t/choice.mlir | mlir-opt --convert-math-to-llvm --convert-arith-to-llvm | FileCheck %s --check-prefix=SPLIT-LLVM --implicit-check-not=constrained\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=split %t/choice.mlir | mlir-opt --math-uplift-to-fma | FileCheck %s --check-prefix=SPLIT-KEPT --implicit-check-not=math.fma\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=fused %t/unrepresentable.mlir | FileCheck %s --check-prefix=SCOPED\n// RUN: loom-raise-opt --loom-materialize-fmuladd=shape=fused %t/nested.mlir | FileCheck %s --check-prefix=NESTED --implicit-check-not=llvm.intr.fmuladd\n// RUN: loom-raise-opt --loom-lower-for-to-graph --mlir-disable-threading %t/selected-fused.mlir | FileCheck %s --check-prefix=SELECTED-FUSED --implicit-check-not=loom.spatial_region","why":"RUN lines fix the concrete option spellings --loom-materialize-fmuladd=shape=fused and =shape=split and show that the bare flag is an error; evidence for the subject-command.json revision."},{"file_sha256":"6f55dfe3ca2a9edcd0d955b965b5011a8010478cf28db89485df1fdfb2750c9c","kind":"example","lines":"28-48,91-115","path":"test/raise/fmuladd-materialization.mlir","roles":["input_construction","input_well_formedness"],"text":"// The split shape is an ordinary multiply then an ordinary add, each rounding\n// on its own. `contract` is the source's permission to fuse them back into one\n// rounding, so selecting Split consumes it: neither operation restates it.\n// Every other imported flag describes the computation rather than the fusion\n// and carries onto both operations unchanged.\n// SPLIT-LABEL: llvm.func @chosen\n// SPLIT: %[[PROD:.*]] = arith.mulf %arg0, %arg1 fastmath<nnan> : f32\n// SPLIT: arith.addf %[[PROD]], %arg2 fastmath<nnan> : f32\n// SPLIT-NOT: llvm.intr.fmuladd\n// SPLIT-LABEL: llvm.func @vector_chosen\n// SPLIT: %[[VPROD:.*]] = arith.mulf %arg0, %arg1 : vector<4xf32>\n// SPLIT: arith.addf %[[VPROD]], %arg2 : vector<4xf32>\n// SPLIT-NOT: llvm.intr.fmuladd\n\n// Consuming the permission is what enforces the decision. Upstream's own\n// arith-to-`math.fma` uplift contracts a multiply and add only when both still\n// permit it, so the selected split survives it unchanged instead of being\n// silently re-fused.\n// SPLIT-KEPT-LABEL: llvm.func @chosen\n// SPLIT-KEPT: %[[KPROD:.*]] = arith.mulf %arg0, %arg1 fastmath<nnan> : f32\n// SPLIT-KEPT: arith.addf %[[KPROD]], %arg2 fastmath<nnan> : f32\n//--- choice.mlir\nllvm.func @chosen(%x: f32, %y: f32, %z: f32) -> f32 {\n %r = llvm.intr.fmuladd(%x, %y, %z)\n {fastmathFlags = #llvm.fastmath<nnan, contract>} : (f32, f32, f32) -> f32\n llvm.return %r : f32\n}\n\nllvm.func @vector_chosen(%x: vector<4xf32>, %y: vector<4xf32>,\n %z: vector<4xf32>) -> vector<4xf32> {\n %r = llvm.intr.fmuladd(%x, %y, %z)\n : (vector<4xf32>, vector<4xf32>, vector<4xf32>) -> vector<4xf32>\n llvm.return %r : vector<4xf32>\n}\n\n//--- unrepresentable.mlir\nllvm.func @representable(%x: f32, %y: f32, %z: f32) -> f32 {\n %r = llvm.intr.fmuladd(%x, %y, %z) : (f32, f32, f32) -> f32\n llvm.return %r : f32\n}\n\nllvm.func @estimated(%x: f32, %y: f32, %z: f32) -> f32\n attributes {reciprocal_estimates = \"all\"} {\n %r = llvm.intr.fmuladd(%x, %y, %z) : (f32, f32, f32) -> f32\n llvm.return %r : f32\n}","why":"Accepted input spelling of llvm.intr.fmuladd with fastmathFlags on scalar and vector floating types inside llvm.func, and the Split expectation in which `contract` is consumed and survives upstream math-uplift-to-fma. Used only for input syntax and for the concrete arith fast-math spellings, not as an extra obligation."}],"primary_bundle_sha256":"88a68ea7de41d20d7373fea9118db9dd7807515e02ae1870158de3e2e1d65cf6","project":"PolyArch/loom","revision":"48615bc5925ef4b9db8b4550b5d4322933cf4b7b","schema":"spectriad.authoring-context/v1","selection_sha256":"5786326099a757c190508d32f5efea9f010328130bfb9e287cfbcf1512e6162b"}
sessions/reverse-generator/session-evidence/result-events.json[
{
"api_error_status": null,
"duration_api_ms": 40495,
"duration_ms": 40527,
"fast_mode_disabled_reason": "sdk_opt_in_required",
"fast_mode_state": "off",
"first_content_frame_ms": 1680,
"is_error": false,
"modelUsage": {
"claude-opus-5": {
"cacheCreationInputTokens": 3763,
"cacheReadInputTokens": 0,
"canonicalModel": "claude-opus-5",
"contextWindow": 1000000,
"costBasis": "list",
"costUSD": 0.11463999999999999,
"inputTokens": 2,
"maxOutputTokens": 64000,
"outputTokens": 3080,
"provider": "firstParty",
"thinkingTokens": 854,
"webSearchRequests": 0
}
},
"num_turns": 1,
"permission_denials": [],
"queued_turn_count": 0,
"result": "## Preconditions\n\n1. Every emitted program is a sequence of one or more top-level MLIR `llvm.func` definitions, each with a body region, concatenated with no enclosing `module` wrapper, no imports, and no other top-level entities.\n2. Each function takes exactly three formal parameters, named `%arg0`, `%arg1`, and `%arg2`, all of the same single type, and its declared result type is that same type.\n3. The parameter/result type of a function is a floating-point-valued LLVM dialect type \u2014 either a scalar float type or a fixed-length vector of floats \u2014 and it is uniform within a function, so no type conversion, broadcast, or mixed-width operation is ever needed.\n4. Each function body is a single basic block with no block labels, no branches, no loops, no regions nested in operations, and no early exits.\n5. Each function body ends with exactly one terminator, `llvm.return`, which returns a single value whose type is spelled identically to the function result type.\n6. The value returned is the most recently defined value of the accumulation chain: the last `llvm.intr.fmuladd` result if the body contains at least one such operation, and otherwise the third parameter `%arg2` itself, so a function with no fmuladd operations is a pure pass-through of `%arg2`.\n7. Every operand referenced by any operation is either a block argument or an SSA value defined by an earlier operation in the same block, so definitions strictly dominate uses and the program is in textual def-before-use order.\n8. All SSA value names are distinct within a function, and each SSA name is defined exactly once.\n9. Every `llvm.intr.fmuladd` operation takes exactly three operands and produces one result; all three operand types and the result type equal the function's type, and the call-style type signature `(T, T, T) -> T` is written explicitly on the operation.\n10. The `llvm.intr.fmuladd` operations of a function form a single linear accumulation chain: the first two operands are always the function parameters `%arg0` and `%arg1`, and the third operand is the result of the immediately preceding fmuladd in the same function, or `%arg2` for the first one; there is never any fan-out, reuse of an intermediate value by more than one consumer, or cross-function data flow.\n11. Each `llvm.intr.fmuladd` carries either no fast-math attribute at all or exactly one `fastmathFlags` attribute holding an `#llvm.fastmath<...>` flag set; the attribute, when present, is attached directly to that operation and to no other operation.\n12. A function may additionally contain at most one `llvm.fmul` operation, whose operands are `%arg0` and `%arg1` and whose result type is the function type; when present it appears before all fmuladd operations in the block.\n13. That `llvm.fmul` result is never used: it is not an operand of any later operation and is not returned, so it is a dead but well-formed operation that must remain syntactically valid on its own.\n14. No operation kind other than `llvm.fmul`, `llvm.intr.fmuladd`, and `llvm.return` ever appears, and in particular there are no constants, loads/stores, allocations, calls, comparisons, selects, casts, or other intrinsics.\n15. Functions are mutually independent: none calls, declares, or otherwise references another, and each is self-contained with respect to types and values.\n16. All functions are definitions with bodies; no function is a bodiless external declaration, and no function carries visibility, linkage, calling-convention, or other attributes.\n\n## Sampling conventions\n\n1. The number of functions per program is drawn from 1, 2, or 3 inclusive; programs with zero functions or more than three are never emitted.\n2. Function names are assigned by a fixed positional scheme `@f0`, `@f1`, `@f2` matching the zero-based index of the function in the file; no other naming style and no name-collision avoidance mechanism is used.\n3. The per-function type is chosen from exactly three admissible forms \u2014 `f32`, `f64`, and `vector<4xf32>` \u2014 and never from `f16`, `bf16`, `f80`, `f128`, other vector widths, vectors of `f64`, scalable vectors, or arrays.\n4. The type is chosen independently per function, so different functions in one program may use different types, but the choice is made once per function and reused verbatim in the parameter list, the result type, every operation type signature, and the return type.\n5. The number of `llvm.intr.fmuladd` operations per function is drawn from 0, 1, or 2 inclusive, so chains never exceed length two, and the empty-body case (a bare return of `%arg2`) is deliberately included.\n6. The presence of the unused `llvm.fmul` operation is an independent per-function binary choice; when included it is always exactly one such operation, always named `%residual`, always `llvm.fmul %arg0, %arg1`, and always placed as the first operation of the block.\n7. The dead operation is always `llvm.fmul` specifically; other plain arithmetic such as `llvm.fadd`, `llvm.fsub`, or `llvm.fdiv` is never used for this role.\n8. fmuladd results are named `%v0` and `%v1` following the zero-based index of the operation within its own function, restarting at `%v0` in every function.\n9. The fast-math annotation is chosen from exactly four admissible spellings \u2014 absent, `{fastmathFlags = #llvm.fastmath<nnan>}`, `{fastmathFlags = #llvm.fastmath<contract>}`, and `{fastmathFlags = #llvm.fastmath<nnan, contract>}` \u2014 and the flags `ninf`, `nsz`, `arcp`, `afn`, `reassoc`, `fast`, and `none` are never emitted.\n10. The fast-math choice is made independently for each fmuladd operation, so two operations in the same function may carry different flag sets.\n11. The accumulation shape is fixed: the multiplicands are always the two parameters rather than previous results, so the emitted chains are strictly accumulator-threaded and never tree-shaped or argument-permuted.\n12. Operand order within each fmuladd is fixed as `(%arg0, %arg1, <accumulator>)`; the grammar never swaps the multiplicands or places the accumulator first.\n13. The textual layout is fixed: each function header is on one line, body operations are indented by two spaces, one operation per line, the closing `}` is on its own line, and functions are emitted back to back with no blank lines or comments.\n14. Result types are always written in the explicit call-style form `: (T, T, T) -> T` for fmuladd and in the short form `: T` for `llvm.fmul` and `llvm.return`, with no location information, no `loc(...)` suffixes, and no generic operation syntax.",
"result_index": 0,
"session_id": "59e750b6-0995-41a2-b8f8-205244de5d84",
"stop_reason": "end_turn",
"subagent_stats": {
"by_type": {},
"completed": 0,
"failed": 0,
"killed": {
"parent": 0,
"system": 0,
"user": 0
},
"max_depth": 0,
"refused": {
"budget": 0,
"concurrency_limit": 0,
"depth_limit": 0
},
"requested": {
"background": 0,
"foreground": 0,
"unset": 0
},
"spawned": 0,
"spawned_by_subagents": 0,
"started_in_background": 0
},
"subtype": "success",
"terminal_reason": "completed",
"time_to_request_ms": 32,
"total_cost_usd": 0.11463999999999999,
"ttft_ms": 13503,
"ttft_stream_ms": 1295,
"type": "result",
"usage": {
"cache_creation": {
"ephemeral_1h_input_tokens": 3763,
"ephemeral_5m_input_tokens": 0
},
"cache_creation_input_tokens": 3763,
"cache_read_input_tokens": 0,
"inference_geo": "not_available",
"input_tokens": 2,
"iterations": [],
"output_tokens": 3080,
"output_tokens_details": {
"thinking_tokens": 854
},
"server_tool_use": {
"web_fetch_requests": 0,
"web_search_requests": 0
},
"service_tier": "standard",
"speed": "standard"
},
"uuid": "bb032749-f6c2-4afc-97fd-242d8c4ddb9d"
}
]
sessions/reverse-postcondition/session-evidence/result-events.json[
{
"api_error_status": null,
"duration_api_ms": 14581,
"duration_ms": 14603,
"fast_mode_disabled_reason": "sdk_opt_in_required",
"fast_mode_state": "off",
"first_content_frame_ms": 2070,
"is_error": false,
"modelUsage": {
"claude-opus-5": {
"cacheCreationInputTokens": 5654,
"cacheReadInputTokens": 0,
"canonicalModel": "claude-opus-5",
"contextWindow": 1000000,
"costBasis": "list",
"costUSD": 0.0812,
"inputTokens": 2,
"maxOutputTokens": 64000,
"outputTokens": 986,
"provider": "firstParty",
"thinkingTokens": 279,
"webSearchRequests": 0
}
},
"num_turns": 1,
"permission_denials": [],
"queued_turn_count": 0,
"result": "This postcondition examines only the subject's output program \u2014 the `input` root is never mentioned \u2014 and it scans `output.operations`, which enumerates every operation at every nesting depth, including the root `builtin.module`. It builds three name-selected sequences: `unresolved` (operations named exactly `llvm.intr.fmuladd`), `fused_children` (operations named exactly `math.fma`), and `split_children` (operations named either `arith.mulf` or `arith.addf`); no other operation names, dialects, operands, results, types, or regions are inspected. The first assertion is an unquantified count check that rejects any output containing one or more `llvm.intr.fmuladd` operations anywhere. The second assertion is also an unquantified count check: it accepts an output only if at least one of the two child sequences is empty, so an output with both a `math.fma` and an `arith.mulf` (or `arith.addf`) is rejected, while an output with only `math.fma` ops, only `arith.mulf`/`arith.addf` ops, or neither is accepted. The third assertion is universally quantified over every member of `split_children`, and for each such operation it is guarded by `\"fastmath\" in child.attributes`: when that key is absent the implication holds trivially and the operation passes, and when present the attribute's `canonical_text` must equal one of exactly two literal strings, `\"#arith.fastmath<none>\"` or `\"#arith.fastmath<nnan>\"`, so any other fastmath spelling (including one naming `contract`) is rejected. The only allowed value sources are these hard-coded string literals compared against `op.name` and against `canonical_text`; nothing is drawn from the input program, from other operations, or from computed values. Vacuously, an output with no `arith.mulf` or `arith.addf` operations satisfies the third assertion with no witnesses examined, and an output containing none of the three selected op kinds \u2014 for instance an empty module \u2014 satisfies all three assertions. The postcondition is non-vacuous only when the output actually contains `llvm.intr.fmuladd` operations, contains both child kinds simultaneously, or contains a split child that carries a `fastmath` attribute.",
"result_index": 0,
"session_id": "d05fa3d8-4a40-47c3-a328-3015483f42f3",
"stop_reason": "end_turn",
"subagent_stats": {
"by_type": {},
"completed": 0,
"failed": 0,
"killed": {
"parent": 0,
"system": 0,
"user": 0
},
"max_depth": 0,
"refused": {
"budget": 0,
"concurrency_limit": 0,
"depth_limit": 0
},
"requested": {
"background": 0,
"foreground": 0,
"unset": 0
},
"spawned": 0,
"spawned_by_subagents": 0,
"started_in_background": 0
},
"subtype": "success",
"terminal_reason": "completed",
"time_to_request_ms": 23,
"total_cost_usd": 0.0812,
"ttft_ms": 5929,
"ttft_stream_ms": 1406,
"type": "result",
"usage": {
"cache_creation": {
"ephemeral_1h_input_tokens": 5654,
"ephemeral_5m_input_tokens": 0
},
"cache_creation_input_tokens": 5654,
"cache_read_input_tokens": 0,
"inference_geo": "not_available",
"input_tokens": 2,
"iterations": [],
"output_tokens": 986,
"output_tokens_details": {
"thinking_tokens": 279
},
"server_tool_use": {
"web_fetch_requests": 0,
"web_search_requests": 0
},
"service_tier": "standard",
"speed": "standard"
},
"uuid": "f9cbcc90-b174-4873-b502-31403def1c56"
}
]
This paired revision was activated by an explicit partial-scope team review bound to both executable artifact hashes.
Approved for execution and public reporting; translation accuracy and completeness remain separately unvalidated.