Core-2 previewnormative preview; implementation unavailable

The hardware and physics specification decision ledger.

Core-2 Design Decisions

Status: design ledger; normative rules are in the edition authorities

Decision Rationale and consequence
Sixth callable domain, physical model kind outside the matrix Hardware owns spatial progress and physical authority; equations describe models rather than callable execution.
New Core-2 and ZLM3 Existing Core-1 tags, effects and artifact meanings remain stable.
Hardware before cumulative physics Digital structure and boundaries can be implemented before numerical solvers.
Four region disciplines Clockless designs need explicit evolution laws; target-dependent behavior needs measured validity.
Clock ownership applies to clocked state Asynchronous state must remain expressible without inventing a clock.
Bit and Logic families Hardware interfaces require known values as well as unknown/high-impedance semantics.
Any-domain realization proposals State, Flow and Optimize remain eligible, subject to preservation of their full contracts.
Explicit original-contract latitude Lowering cannot silently trade durability, exactness, timing or error behavior for speed.
Mesh-based generic equations One mathematical core supports EM and other physics without discipline-specific grammar.
Strong and weak forms Models can express both differential laws and variational formulations with explicit relation evidence.
Foundational bridges, composable wrappers Sampling/loading/uncertainty remain inspectable beneath ADC/DAC abstractions.
Generated and authored realizations share a gate Code generation changes provenance, not required semantics or trust.
ZER5-74 binding preparation before refinement admission Resolve actual checked contracts and native model profiles through one source/generated gate; retain baseline body policies separately from the unchanged public contract and explicitly leave observation/equivalence admission pending.
ZER5-74 typed scalar maps before equivalence Explicit original parameter/result encodings and complete root coverage make the proposed trace relation inspectable; recheck original dependency pins and retain every proof obligation, rather than treating type agreement as semantic equivalence.
ZER5-74 source constraints share the mapper Source-owned proposal tables retain names and provenance outside circuit execution records; selecting a named root relation rechecks its original contract and uses the same canonical typed map gate as generated rows.
ZER5-74 canonical proposal assembly revalidates maps Joining checked objects is not a trust shortcut: compare the original map pins and rows against a fresh check, retain all proof obligations and leave portable IDs/promotion to their independent gates.
Typed SolverPlans Backend choices remain flexible but visible, bounded and checked.
Profile-specific evidence Universal proofs, bounded analyses, numerical error and empirical device claims have different scopes.
ZER5-75 bounded scalar evaluation before promotion Recheck actual proposal dependencies and enumerate the complete supported finite domain using original software semantics and fresh Simulator authority. Missing coverage, budgets, unsupported assumptions and unavailable simulation never become pass. Keep native reference results separate from toolchain attestation, independent target evidence and atomic promotion.
Vendor-neutral adapters Bitstreams bind target implementations; vendors do not define language semantics.
ZER5-76 bounded two-state netlist before target synthesis Reuse actual component/model admission, preserve nominal widths at each primitive, retain instance ownership while flattening wiring, and separate source locations from implementation identity. A sized RTL projection and independent simulator comparisons do not imply target evidence or promotion.
ZER5-77 bounded scalar proposals through authored gates Translate only a checked non-trapping fixed-width leaf subset, retain sequential value versions and original types, then parse/elaborate/bind/map the emitted source through existing gates. Unknown faults and control flow reject generation; missing local metadata requires C2-REAL-010 checked typing. Generated provenance is unattested; evaluation and promotion remain distinct.
Checked relocated scalar locals Preserve checked bytes and original pins; inspect retained scalar tables or reconstruct bounded initialized straight-line types. Never infer ownership, execute/fold instructions or turn a typing report into proof.
Logical ZLM3 now, binary minors later Specify semantic structure without claiming interoperability for unallocated byte layouts.
ZER5-65 closed record registry and bounded native normalizer Structural validity and canonical JSON are inspectable before binary emission; exact common framing is specified without allocating a minor or claiming domain admission.
ZER5-66 hardware minor 0 Allocate C2-ART-007 framing only for logical/hardware records; independent bounded decoding verifies an external SHA-256 byte pin and canonical re-encoding, without inventing semantic hashes or execution authority.
Separate structural artifact discovery ZLM3 3.0 transport is inspectable; old executable version/API surfaces and Core-2 stable gates remain unchanged.
ZER5-235 source-resolved executable minor 5 Rebuild actual portable component preimages and the exact native model from checked source closure; require independently selected bytes/model/limits and fresh Simulator authority. Do not reinterpret structural minors, admit standalone invented graphs or infer physical evidence.
ZER5-68 identity framing before semantic encoders Fix tagged preimages and full typed equality with independent cross-language vectors; keep framing integrity separate from subject admission and preserve legacy/native identity formats.
ZER5-68 bounded component semantic identities Public specialization and ordered ports define the combinational contract; the full circuit body has its own identity. Exclude source locations, execution limits and separate realization proposals; reject profiles whose semantic inputs are not represented.
ZER5-68 portable scalar refinement edges Preserve the original software contract and bind portable component bodies plus typed maps. Keep baseline-body/native-model evidence context distinct; equal logical IDs never authorize stale proof reuse.
ZER5-68 scoped interface/5 before whole-module reflection Export one checked component contract with explicit scope/feature closure, strict canonical transport and an external full-identity expectation. Revalidate type/name/hash integrity without exporting private circuit state or inferring authority; keep default /4 surfaces unchanged.
ZER5-68 checked-context semantic/5 Inspect an admitted component body and its separate public contract through typed projection references. Exact comparison against actual checked dependencies rejects rehashed substitutions; a hash-only body importer is not silently treated as semantic admission. Keep the private body separate from public-interface export.
ZER5-68 public claims separate from semantic evidence context Export scoped scalar realizations through actual checked identities. Baseline/native-model rebinding can leave the public claim unchanged, so public verification never authorizes stale evidence reuse; semantic verification must also bind the exact context.
ZER5-68 inherit software projections without reinterpreting IDs Preserve the exact checked /4 declaration and semantic producers in explicit /5 scopes; keep original software contracts, capability requirements and preview identity. Public output omits body inspection. Verification requires an actual checked expected module and never admits external hashes as software.
ZER5-69 pure reference values before simulation Immutable bounded Bit/Logic values and exact finite resolution folds can be tested independently; they do not create hardware sessions or admit circuit execution.
ZER5-72 separate guarded CDC profile Keep strict clocked admission unchanged; source-defined transfer laws execute through fresh model-scoped Simulator authority with atomic candidate state and owned traces.
ZER5-73 pure async event-law foundation Separate immutable collecting/sealed queues from source evaluation and live authority; explicit intervals, simultaneous commits and inertial cancellation retain outstanding obligations without claiming their proof.
ZER5-73 checked async source laws Bind explicit initialized targets, guarded drivers and optional protocol/fork assumptions; normalize branch sets and check guard/endpoint provenance without inferring physical evidence or live execution.
ZER5-73 guarded async horizons Evaluate every due logical point under fresh authority, retain explicit interval schedules and protocol observations, and publish whole horizons atomically without refunding failed admitted work; physical obligations remain separate.
CDC pre-state and post-register source sampling Word transfers and registers sample pre-state, while scalar synchronization also observes coincident register changes. Reset release holds ordinary state through its finishing edge.
Point-aware CDC wrapper before mixed-region composition Preserve legacy v1 value bytes/costs and strictly increasing timestamps; give bounded timestamp/microstep transitions their own identity, without fictitious clock ticks or implicit execution admission.
ZER5-135 checked async-to-clock composition Use distinct record/model/trace identities and the point wrapper; preserve simultaneous pre-state word/register decisions, post-register scalar sampling, whole-horizon ownership and failed charges. Reverse bridges and physical evidence remain separate work.
ZER5-137 retained-word endpoint reset values Give independent synchronous/asynchronous endpoint holds a distinct pure law with retained words/acknowledgements and explicit target-retention obligations; do not reinterpret coordinated v1 resets or imply cancellation/source execution.
ZER5-140 retained-word source bindings Bind distinct checked constructors to actual clock/reset ownership, retain old allocation layouts via an explicit bridge-record law discriminator, and reject execution until its own guarded profile exists.
ZER5-141 retained clocked executor Introduce an explicit model factory and identity domains; mix retained and legacy values without growing old layouts, normalize raw reset pins independently, retain full failed-step charges and publish complete steps atomically. Composed retained horizons and physical proof remain separate.
ZER5-142 retained composed horizons Keep retained source contracts fixed at256 points, wrap legacy bridge values at the queue bound, and add exact-profile run/view gates and whole-horizon publication. Preserve all old costs and identity domains; microsteps do not supply edges or reset recovery.
Explicit bounded CDC reset/event subsets Raw coordinated word resets retain their own recovery law; unsupported synchronous word resets and direct bridge-fed scalar event networks fail instead of acquiring invented scheduling semantics.
Explicit uncertainty at value boundaries Four-state branches are required for an uncertain mux selector; checked conversion reports the first LSB indeterminate bit. Known zero divisors remain explicit errors even with uncertain numerators.
Exact quantities and stable mesh keys Reduced rational dimensions and retained IEEE bit patterns avoid tolerance-dependent identities; coordinate ordering cannot reorder element connectivity.
ZL512 successor Freeze the imported software baseline and add equal hardware/physics allocations without breaking ZL256.
Specification Review before implementation acceptance Delivered documents and future executable support have separate evidence and completion states.

The initial spelling public physical model and realization profiles are chosen for this preview. Future incompatible changes require explicit edition revision, retired clause identities where meanings change, and migration examples. No optional syntax compatibility with other HDLs is implied.

Projected fromspec/editions/core-2/decisions.md