Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
142 commits
Select commit Hold shift + click to select a range
b69c7cc
feat(components): generate the native Reflux v1 contract
wolf75222 Jul 29, 2026
bbe3072
feat(runtime): validate and invoke local Reflux kernels
wolf75222 Jul 29, 2026
c418145
docs(components): bound external Reflux authority
wolf75222 Jul 29, 2026
821b7c6
test(components): pin native interface id parity
wolf75222 Jul 29, 2026
63130f2
test(mpi): exercise interface scheduler on execution lane
wolf75222 Jul 29, 2026
2e11639
feat(mpi): execute interface collectives on resolved communicator
wolf75222 Jul 29, 2026
518ecaa
refactor(runtime): scope layout transfers to execution communicator
wolf75222 Jul 29, 2026
3c428f0
test(runtime): fence layout transfer communicator scope
wolf75222 Jul 29, 2026
8a24d12
merge: refresh ADC-683 on green master
wolf75222 Jul 29, 2026
733f3ea
merge: combine ADC-683 communicator-owned runtime paths
wolf75222 Jul 29, 2026
9a25359
feat(diagnostics): author typed balance ledgers
wolf75222 Jul 29, 2026
6b4612f
feat(runtime): publish accepted five-term balances
wolf75222 Jul 29, 2026
142a6f4
test(diagnostics): prove accepted balance evidence
wolf75222 Jul 29, 2026
c9bab2a
docs(output): document explicit balance ledgers
wolf75222 Jul 29, 2026
d20cce8
feat(output): delete ParaView series compatibility route
wolf75222 Jul 29, 2026
4e5a08e
test(output): enforce canonical ParaView collection authoring
wolf75222 Jul 29, 2026
20e2a7c
docs(output): record ParaView authoring cutover
wolf75222 Jul 29, 2026
0f5c076
fix(diagnostics): reserve balance codegen route
wolf75222 Jul 29, 2026
f66ea9c
fix(runtime): isolate the balance attempt mailbox
wolf75222 Jul 29, 2026
126399f
test(diagnostics): reject balance namespace spoofing
wolf75222 Jul 29, 2026
c9429df
docs(output): reserve the balance term namespace
wolf75222 Jul 29, 2026
6874ccb
test(diagnostics): keep the balance sink private
wolf75222 Jul 29, 2026
fbdf121
Merge origin/master into ADC-686 balance ledger
wolf75222 Jul 29, 2026
6410c18
docs(output): state balance cadence cost
wolf75222 Jul 29, 2026
36bbbf3
test(mpi): run layout transfers on execution communicator
wolf75222 Jul 29, 2026
fae33d5
fix(output): refuse start-time balance schedules
wolf75222 Jul 29, 2026
51fa332
test(output): prove balance starts after an attempt
wolf75222 Jul 29, 2026
ec0859f
merge: refresh ADC-681 on current master
wolf75222 Jul 29, 2026
5e19b9a
feat(output): fuse accepted balance cadence
wolf75222 Jul 29, 2026
cb65ace
test(output): prove sparse balance reductions
wolf75222 Jul 29, 2026
b5a9ae7
docs(output): document balance due fusion
wolf75222 Jul 29, 2026
1e14b4b
fix(ci): isolate the balance contract import leaf
wolf75222 Jul 29, 2026
5501456
fix(runtime): close sparse balance edge cases
wolf75222 Jul 29, 2026
105e3f5
fix(runtime): keep zero-step output exact
wolf75222 Jul 29, 2026
b05e24f
feat(time): author public program cadence
wolf75222 Jul 29, 2026
5a73053
test(runtime): prove sparse balance edge cases
wolf75222 Jul 29, 2026
2f92824
fix(output): bound native balance cadence periods
wolf75222 Jul 29, 2026
57b3648
test(restart): replay balance programs selectively
wolf75222 Jul 29, 2026
022da59
fix(time): keep cadence in the core layer
wolf75222 Jul 29, 2026
c6e6f67
feat(output): detach async scientific diagnostics
wolf75222 Jul 29, 2026
e5312de
fix(ci): isolate balance due contracts from output
wolf75222 Jul 29, 2026
5135fd2
docs(output): specify cadence and async balance semantics
wolf75222 Jul 29, 2026
4636a02
Merge ADC-702 integration into ADC-686 output ledger
wolf75222 Jul 29, 2026
e656950
fix(ci): reconcile merged Python duration catalog
wolf75222 Jul 30, 2026
63959ca
fix(output): keep root async writers nonblocking
wolf75222 Jul 30, 2026
8bb4d2a
fix(runtime): type authenticated cadence callables
wolf75222 Jul 30, 2026
c3b4f68
merge: refresh ADC-683 on current master
wolf75222 Jul 30, 2026
3badb13
merge: refresh ADC-693 on current master
wolf75222 Jul 30, 2026
f135206
Merge remote-tracking branch 'origin/master' into codex/adc681-reflux…
wolf75222 Jul 30, 2026
819ce7f
Merge current master into ADC-686 exact output balance ledger
wolf75222 Jul 30, 2026
fb02634
test(mpi): prove exact nonzero balance terms
wolf75222 Jul 30, 2026
dd2b947
Merge ADC-683 communicator-scoped native collectives
wolf75222 Jul 30, 2026
3acc617
Merge ADC-680 authenticated fixed component packages
wolf75222 Jul 30, 2026
a4ec359
Merge ADC-681 generated native Reflux interface
wolf75222 Jul 30, 2026
a461c5e
Merge ADC-684 authenticated runtime-plan consumption
wolf75222 Jul 30, 2026
d068309
Merge ADC-686 exact accepted-step balance ledgers
wolf75222 Jul 30, 2026
21cd6bd
Merge ADC-686 nonzero MPI balance proof
wolf75222 Jul 30, 2026
204c679
Merge ADC-693 ParaView legacy authoring cutover
wolf75222 Jul 30, 2026
0676a12
feat(runtime): enforce planned determinism at install
wolf75222 Jul 30, 2026
411bb5a
Merge Kokkos 5 concurrency compatibility into P3
wolf75222 Jul 30, 2026
3d65b15
feat(runtime): enforce single-layout plan projection
wolf75222 Jul 30, 2026
81973ae
feat(runtime): enforce multi-layout plan projection
wolf75222 Jul 30, 2026
3d3b250
refactor(mpi): name interface field rank authority
wolf75222 Jul 30, 2026
ab675cb
docs(runtime): qualify communicator rank-space limit
wolf75222 Jul 30, 2026
84a2f2b
docs(runtime): map System communicator injection boundary
wolf75222 Jul 30, 2026
60ddc22
release: prove the exact installed wheel
wolf75222 Jul 30, 2026
83158f6
release: bind codesign evidence to runtime bytes
wolf75222 Jul 30, 2026
0d8c015
feat(runtime): retain automatic balance evidence per attempt
wolf75222 Jul 30, 2026
f2135ac
feat(amr): extract signed reflux balance corrections
wolf75222 Jul 30, 2026
31d2143
test(architecture): fence automatic reflux balance evidence
wolf75222 Jul 30, 2026
d30fd43
release: bind final examples to signed runtime
wolf75222 Jul 30, 2026
cb0e235
Merge remote-tracking branch 'origin/master' into codex/adc688-releas…
wolf75222 Jul 30, 2026
f9348aa
release: authenticate wheel before native import
wolf75222 Jul 30, 2026
6300ebd
api: prove source and wheel public parity
wolf75222 Jul 30, 2026
23d9aca
release: gate publication on public API parity
wolf75222 Jul 30, 2026
8b6133c
feat(amr): execute prepared local Reflux kernels
wolf75222 Jul 30, 2026
cddd9da
feat(components): install Reflux into AMR transitions
wolf75222 Jul 30, 2026
1f2add4
test(architecture): fence prepared Reflux authority
wolf75222 Jul 30, 2026
db88e5b
merge: refresh ADC-683 on current master
wolf75222 Jul 30, 2026
df04495
fix(amr): include logical clock in reflux contract
wolf75222 Jul 30, 2026
61bd2f3
fix(codegen): bind qualified flux provider packs (ADC-682)
wolf75222 Jul 30, 2026
d7b3401
test(codegen): prove exact flux provider identity (ADC-682)
wolf75222 Jul 30, 2026
1b34f39
merge: refresh ADC-681 Reflux ABI on current master
wolf75222 Jul 30, 2026
e5ef103
test(amr): execute prepared Reflux kernel
wolf75222 Jul 30, 2026
fd77a35
merge: refresh prepared Reflux runtime on ABI head
wolf75222 Jul 30, 2026
027c8bb
fix(runtime): make field view launch contracts exact (ADC-683)
wolf75222 Jul 30, 2026
0ac4942
test(runtime): fence complete field view descriptors (ADC-683)
wolf75222 Jul 30, 2026
40a0b07
refactor(output): require observer-owned HDF5 communication (ADC-683)
wolf75222 Jul 30, 2026
c32d76e
test(output): fence observer-owned HDF5 lanes (ADC-683)
wolf75222 Jul 30, 2026
836f2f2
docs(output): describe duplicated HDF5 observer lanes (ADC-683)
wolf75222 Jul 30, 2026
5ee5cf7
refactor(output): isolate ROOT gathers on consumer lanes (ADC-683)
wolf75222 Jul 30, 2026
26b9b96
test(output): fence run-scoped ROOT MPI lanes (ADC-683)
wolf75222 Jul 30, 2026
fe1af95
docs(output): document ROOT consumer lane ownership (ADC-683)
wolf75222 Jul 30, 2026
a34649c
feat(numerics): bind generated flux provider slots
wolf75222 Jul 30, 2026
2cc1f15
tests: prove qualified native flux binding
wolf75222 Jul 30, 2026
3c33ea6
docs: record generated flux provider ABI
wolf75222 Jul 30, 2026
df46de3
release: prove installed-wheel component packages
wolf75222 Jul 30, 2026
90354cf
release: isolate component package evidence audit
wolf75222 Jul 30, 2026
9642bac
test(release): lock wheel-owned AOT evidence
wolf75222 Jul 30, 2026
9266ecf
docs: record installed-wheel AOT proof
wolf75222 Jul 30, 2026
9a853c5
release: normalize retained JUnit paths
wolf75222 Jul 30, 2026
9ad7aba
feat(runtime): capture due projection balance evidence (ADC-686)
wolf75222 Jul 30, 2026
ab41987
test(balance): fence projection evidence cadence (ADC-686)
wolf75222 Jul 30, 2026
b2c7a90
docs(balance): describe qualified projection evidence (ADC-686)
wolf75222 Jul 30, 2026
3247df3
test(balance): distinguish projection fast path ordering (ADC-686)
wolf75222 Jul 30, 2026
2824e00
release: compare the installed public API
wolf75222 Jul 30, 2026
f6d91d2
release: gate on installed API parity
wolf75222 Jul 30, 2026
7e43a77
feat(amr): resolve Reflux through provider protocol
wolf75222 Jul 30, 2026
4e7cc59
tests(amr): prove public Reflux provider installation
wolf75222 Jul 30, 2026
bd8ee62
docs(amr): publish Reflux provider selection
wolf75222 Jul 30, 2026
220cefe
test(release): reject installed API drift
wolf75222 Jul 30, 2026
9795d67
test(release): exercise installed API resolution
wolf75222 Aug 1, 2026
1c16d32
docs(release): describe installed API parity gate
wolf75222 Aug 1, 2026
f0900f9
release: bind retained wheel to promised lane
wolf75222 Aug 1, 2026
02585bf
test(release): refuse wheel lane identity drift
wolf75222 Aug 1, 2026
61a7935
docs(release): document exact wheel lane proof
wolf75222 Aug 1, 2026
c76e7c6
feat(balance): select native ledger terms explicitly (ADC-686)
wolf75222 Aug 1, 2026
5412a95
feat(runtime): resolve qualified automatic balance evidence (ADC-686)
wolf75222 Aug 1, 2026
7a57c4d
test(balance): prove qualified native term selection (ADC-686)
wolf75222 Aug 1, 2026
e7e70f6
docs(balance): define automatic ledger authority (ADC-686)
wolf75222 Aug 1, 2026
036e6ec
Merge remote-tracking branch 'origin/master' into codex/p3-consolidat…
wolf75222 Aug 1, 2026
c3ed39a
Merge current master into ADC-689 source-wheel parity
wolf75222 Aug 1, 2026
c2e0b05
Merge refreshed source-wheel parity into installed parity
wolf75222 Aug 1, 2026
8f23769
release: bind installed public API distribution identity
wolf75222 Aug 1, 2026
a43338f
release: authenticate installed API parity evidence
wolf75222 Aug 1, 2026
38904ca
Merge ADC-689 installed API parity into P3
wolf75222 Aug 1, 2026
6409bf8
Merge remote-tracking branch 'origin/master' into codex/adc688-releas…
wolf75222 Aug 1, 2026
a9f7e23
release: bind codesign to published wheel bytes
wolf75222 Aug 1, 2026
b5a384f
test(release): refuse post-install signature drift
wolf75222 Aug 1, 2026
687aa34
docs(release): require signed wheel byte parity
wolf75222 Aug 1, 2026
c8f665d
Merge ADC-688 signed wheel proof into P3
wolf75222 Aug 1, 2026
d0e8849
Merge ADC-680 installed-wheel AOT proof into P3
wolf75222 Aug 1, 2026
250c28d
Merge ADC-681 prepared public Reflux provider into P3
wolf75222 Aug 1, 2026
c571882
Merge ADC-683 authenticated output lanes into P3
wolf75222 Aug 1, 2026
ba0cd7f
Merge ADC-686 qualified automatic balance evidence into P3
wolf75222 Aug 1, 2026
e174968
Merge ADC-682 qualified native flux packs into P3
wolf75222 Aug 2, 2026
cb46686
refactor(numerics): consume exact flux provider packs (ADC-682)
wolf75222 Aug 2, 2026
f47431c
test(numerics): migrate flux fixtures to provider protocol
wolf75222 Aug 2, 2026
c731100
fix(release): reconcile merged service contracts
wolf75222 Aug 2, 2026
05a3b1f
test(history): reduce the explicit current state
wolf75222 Aug 2, 2026
7a51a20
test(runtime): pass exact balance owner coordinates
wolf75222 Aug 2, 2026
3d1cd8a
Merge ADC-682 exact provider-pack cutover into P3
wolf75222 Aug 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,15 +61,21 @@ jobs:
wheels=("$RUNNER_TEMP"/wheelhouse/pops-*.whl)
test "${#wheels[@]}" -eq 1
evidence="$RUNNER_TEMP/pops-final-evidence.json"
public_api_evidence="$RUNNER_TEMP/pops-final-evidence-public-api.json"
python scripts/run_final_gate.py --wheel "${wheels[0]}" --evidence "$evidence"
python scripts/prove_public_api_parity.py \
--wheel "${wheels[0]}" \
--installed \
--evidence "$public_api_evidence"
python - <<'PY'
from pops.runtime_environment import runtime_environment_report
report = runtime_environment_report()
assert report["kokkos_backend"] == "Serial", report
assert report["mpi_compiled"] is False, report
PY
python scripts/release_preflight.py \
--release --tag "$GITHUB_REF_NAME" --installed --evidence "$evidence"
--release --tag "$GITHUB_REF_NAME" --installed --evidence "$evidence" \
--public-api-evidence "$public_api_evidence"

- name: Retain authenticated release evidence
uses: actions/upload-artifact@v7
Expand Down
27 changes: 27 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,36 @@ Format: [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versioning

### Changed

- `Program.cadence(substeps=..., stride=...)` now authors the native global cadence as immutable,
identity-bearing Program data and installs it before the Uniform or AMR runtime freezes.
- `AsyncScientificOutput` now accepts fields, diagnostics, or both on one exact schedule. Diagnostic
reductions, including the five-term `Balance` ledger, are captured transactionally before the
accepted snapshot is detached; the asynchronous worker receives only immutable arrays and
scalars. Sparse Balance cadences elide off-cadence reductions, publish an exact zero ledger for
held Program strides, and replay accepted state without reopening the native mailbox.
- ParaView output now has one collection-authoring keyword: `collection`. The deprecated
`ParaView(series=...)` compatibility route is deleted instead of being retained beside the
canonical PVD collection contract.
- Release codesign now preserves an existing valid ad-hoc signature and refuses publication when
post-install signing changes the retained wheel's native bytes, so the published wheel and the
runtime exercised by conformance and final examples are byte-identical.
- Strict AMR checkpoint payload v7 now persists the accepted shared-interface flux audit together
with Program clocks, histories, tagging state, conservative ledger and synchronization report.
Restart validates every fragment's topology epoch, level pair, exact clock window, resolved
rational stage weight, geometry and duration before publishing the image; rejected restart or
Program attempts leave the previous accepted report byte-exact.
- The final release gate now proves an external source component against the exact installed wheel:
its isolated AOT lane clears the checkout-owned `POPS_INCLUDE`, requires the wheel-owned signed
header tree and native Kokkos extension, compiles/installs/loads the component, and retains one
exact no-skip/no-xfail JUnit result whose node ID and command are reauthenticated by preflight.
- External AMR `Reflux` components now use the normalized public provider route from
`AMR(..., reflux=...)` through resolve, compiled provenance and transactional native
installation; the builtin flux-register kernel follows the same reported contract.
- Generated physical-flux bricks now make their qualified provider requirements executable native
ABI evidence: the binder validates every row at compile time and reads only its declared storage
slots instead of scanning the model's complete auxiliary width. Physical laws consume that exact
pack directly through compile-time provider reads; `PhysicalFluxView` no longer reconstructs a
process-wide `Aux` value.
- AMR checkpoint capability reports now distinguish same-rank bit-identical replay from
non-bit-identical rank-count rematerialization with Dense persisted histories. The explicit
`RegridOnRestart()` policy now restores and authenticates the recorded accepted state before one
Expand Down Expand Up @@ -116,6 +141,8 @@ Format: [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versioning
native ABI, and checkpoint envelopes independently in one generated Python/C++ release contract;
declares the exact source/wheel matrix; and adds a fail-closed release preflight requiring exact
tag, installed native identity, clean tree, generated products, and authenticated final-gate evidence.
The retained wheel filename and its internal `WHEEL` record must also identify exactly the promised
native macOS/arm64/cp312 lane; Python/ABI, platform, purelib, build-tag, or metadata drift is refused.
- ADC-633 Compiled condensed-implicit time Program (std.condensed_schur, theta=1) on the AMR hierarchy: the condensed operators run per level through AmrProgramContext::grid_context / assembly_target / assembly_source (matrix-free coefficiented apply, reconstruct, energy), so a flat hierarchy is bit-identical to the uniform Program (the emitted matrix-free BiCGStab runs on level 0 through ctx.solve_linear_matfree) and a refined hierarchy solves the tensor elliptic by the composite FAC (CompositeFacPoisson in amr_condensed_elliptic.hpp), matching the native source-stage route; the vestigial AMR deferral stubs are removed and the Spec 6 sec.20 clean_schur_program.amr.mono cell flips to green.
- ADC-640 One spatial-reconstruction dispatch generator (include/pops/runtime/builders/scheme_dispatch.hpp): dispatch_limiter binds a typed LimiterRouteId to its compile-time reconstruction policy behind an X-macro plus a count-lock static_assert, so the 17 hand-written limiter ladders across the System, polar, AMR multi-block, AMR compiled and external-brick builders collapse to one dispatch_limiter call each. A forgotten limiter is now a build error (the -Werror-free tree could only warn on a missing switch arm). Same template instantiations, bit-identical.
- ADC-637 condensed_schur gained a generic lowering route: the electrostatic-Lorentz linearization J = [[0, B_z], [-B_z, 0]] is authored in the DSL (pops.lib.physics.author_electrostatic_lorentz, an m.local_linear_map on the momentum subset) and the macro (route="generic") lowers the condensed tensor coefficient A = I + c*rho*(I - theta*dt*J)^-1, the fused RHS and the velocity reconstruction through the closed-form block_inverse codegen, with no coupling/schur vocabulary. Bit-identical to the retiring hand-written Schur brick over a multi-step trajectory at theta == 1 and theta == 0.5 (golden, np.array_equal): the coefficient tensor reuses block_inverse<2> (== LorentzEliminator's binv entries) and the flux/reconstruct vector applies reuse a new factored block_apply_inverse intrinsic reproducing apply_Binv's operation order. The brick route stays the default until it is retired.
Expand Down
7 changes: 7 additions & 0 deletions docs/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -799,6 +799,13 @@ model-qualified `FaceTrace` values plus `FaceContext` and returns a typed densit
`SpatialOperator` alone applies face and cell measures. Provider packs are selected from exact
`(owner, space kind, space name, component)` identities. Missing, unavailable or contract-mismatched
providers fail during selection; homonymous components from different owners never alias.
Generated physical models carry those qualified rows as `flux_provider_requirements`. The native
binder validates their count, qualification, availability, unique in-range storage slots and then
loads only those declared slots into the model-qualified device pack. The physical law reads that
pack directly through the bounded `flux_provider<Component>()` protocol: `PhysicalFluxView` never
reconstructs the global `Aux` source/implicit carrier. Hand-written C++ fixtures that do not declare
the generated ABI may populate a full-width test pack, but they execute through the same direct
physical-flux protocol.

## Limitations

Expand Down
4 changes: 4 additions & 0 deletions docs/VERSIONING.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,5 +86,9 @@ before the official build begins.
`## [x.y.z] - YYYY-MM-DD` section.
3. Run `python scripts/generate_release_contract.py --check` and the release preflight; a missing
build/codesign/example/conformance evidence record blocks tagging.
The Darwin gate first preserves an already-valid ad-hoc signature and requires the post-codesign
native digest to remain byte-identical to the retained wheel member. A repair confined to the
installed copy therefore blocks publication: the wheel users receive must itself contain the
exact signed runtime exercised by conformance and the final examples.
4. Merge, then `git tag vx.y.z` on master and `git push --tags`. The `release.yml` workflow
turns the tag into a GitHub Release built from that CHANGELOG section.
71 changes: 57 additions & 14 deletions docs/design/SPECIFICATION_TECHNIQUE_FINALE_POPS_ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -606,22 +606,24 @@ Les builtins de `pops.lib.amr` et les composants externes implémentent le même
provider. Un composant externe est sélectionné sans callback Python :

```python
from pops.amr import ClusteringProvider, TaggerProvider
from pops.amr import ClusteringProvider, RefluxProvider, TaggerProvider

layout = AMR(
...,
tagger=TaggerProvider(component=my_tagger),
clustering=ClusteringProvider(component=my_clustering),
reflux=RefluxProvider(component=my_reflux),
)
resolved = pops.resolve(
pops.validate(case),
layout=layout,
components=(my_tagger, my_clustering),
components=(my_tagger, my_clustering, my_reflux),
)
```

Les deux valeurs doivent référencer un exact `pops.external.ExternalComponent` portant
respectivement l'interface générée `Tagger` ou `Clustering`. Le même objet exact doit être fourni à
Les trois valeurs doivent référencer un exact `pops.external.ExternalComponent` portant
respectivement l'interface générée `Tagger`, `Clustering` ou `Reflux`. Le même objet exact doit
être fourni à
`resolve(components=...)`; son identité de manifest, son interface et sa version traversent
`resolve -> compile -> bind`. Le manifest doit déclarer une classification déterministe `bitwise` ou
`reproducible`, car chaque rang doit produire la même hiérarchie. Un `Tagger` déclare en plus une
Expand Down Expand Up @@ -705,9 +707,13 @@ doivent couvrir exactement la hiérarchie.

Le provider natif livré matérialise le coeur maillage/stockage en 2D et ses kernels de transfert,
correction conservative et sous-cyclage AMR exigent un ratio de transition égal à 2. La correction
coarse/fine reste l'unique ledger de flux détenu par PoPS : aucune interface externe `Reflux`
n'existe, car déléguer ce dépôt créerait une seconde autorité conservative. Une autre dimension ou un autre
ratio est refusé pendant la résolution ou le bind avec les capacités observées. Le coeur de
coarse/fine reste l'unique ledger de flux détenu par PoPS. L'interface native `Reflux` ne peut
déléguer qu'un kernel local et non collectif : PoPS lui fournit les flux coarse/fine déjà intégrés
dans le temps et ramenés sur la même face coarse ; le kernel écrit la correction locale
`side * (fine - coarse) / dx`. PoPS conserve exclusivement la topologie d'interface, le ledger, la
réduction MPI, la transaction et l'application à l'état. Un provider `Reflux` ne devient donc jamais
une seconde autorité conservative. Une autre dimension ou un autre ratio est refusé pendant la
résolution ou le bind avec les capacités observées. Le coeur de
planification ne normalise jamais la demande vers ce sous-ensemble. Défensivement,
`AmrProgramContext` revalide aussi chaque transition à sa construction et refuse un ratio différent
de 2 avant le premier pas : cette limite appartient au provider natif reflux/average-down installé,
Expand Down Expand Up @@ -1405,14 +1411,30 @@ paramètres, interfaces, requirements, capabilities, effets, layouts, clocks, d
restart et points d'entrée.

Le même catalogue génère les IDs et tables C/POD versionnées des interfaces natives (flux numérique,
ghost boundary, closure de champ, tagging, clustering, transfert, solveur de champ, writer et
topologie de champ). Le reflux conservatif reste une autorité interne pilotée par le flux ledger ;
aucune table externe `Reflux` n'est annoncée. Chaque famille possède sa propre version d'interface, indépendante de la version
ghost boundary, closure de champ, tagging, clustering, transfert, kernel local de reflux, solveur de
champ, writer et topologie de champ). Le reflux conservatif complet reste une autorité interne
pilotée par le flux ledger ; la table externe `Reflux` ne couvre que la transformation locale,
non collective, de flux intégrés en correction non appliquée. Chaque famille possède sa propre version d'interface, indépendante de la version
du protocole enveloppe. Le loader authentifie identité sémantique, manifest, digest du catalogue,
taille/header de table et opérations requises avant de conserver le handle de bibliothèque. Les tables
sont résolues une fois à l'installation ; aucun `dlsym`, nom de classe ou dispatch Python n'entre dans
une boucle de cellules.

Le contrat `Reflux` v1 possède maintenant un adaptateur préparé interne vers
`PreparedAmrProgramRefluxTransition`. Pour chaque patch enfant local, l'adaptateur reçoit quatre
paires de flux déjà intégrés et écrit quatre corrections dans des buffers persistants empoisonnés
avant l'appel. PoPS vérifie que chaque valeur a été écrite et reste finie, atteint un consensus
d'échec entre rangs, puis applique seul périodicité, masque de couverture, réduction MPI et
publication transactionnelle. La présence et le contrat exact du provider sont également comparés
entre rangs avant toute exécution.

La sélection `AMR(..., reflux=RefluxProvider(component))` traverse désormais la même résolution
normalisée, identité de provider, artifact et transaction d'installation que `Tagger` et
`Clustering`. Sans sélection explicite, `FluxRegisterReflux` décrit le kernel builtin par le même
protocole et apparaît dans le même rapport de providers. La qualification initiale de l'adaptateur
reste limitée à la cible 2D, `float64`, CPU avec stockage hôte. Le chemin n'est pas encore prouvé par
exécution MPI avec un composant externe, mesure de conservation ni backend GPU.

Les champs sémantiques inconnus, capacités sans preuve, collisions d'identité et entry points manquants
sont refusés. Un vieux manifest n'est pas « réparé » silencieusement.

Expand Down Expand Up @@ -1491,10 +1513,13 @@ scientifiques choisissent obligatoirement un `ParallelMode` typé :
d'un unique writer rang 0, `COLLECTIVE` pour les hyperslabs HDF5 MPIO exacts, ou `PER_RANK` pour des
artefacts locaux qualifiés par rang et un reçu agrégé. Le mode, le format, la sélection, la cible et
l'identité de chaque pièce native (`global_box_index`, `owner_rank`, `replicated`) sont authentifiés
entre rangs avant toute écriture. La route `COLLECTIVE` appelle le backend C++ HDF5 parallèle sur
`MPI_COMM_WORLD`; `h5py` reste uniquement un lecteur/écrivain série optionnel et n'est jamais un
transport MPI. Une dépendance HDF5 parallèle native absente, un mode incompatible ou un backend
Kokkos GPU/device handle non supporté est refusé avant le
entre rangs avant toute écriture. La capture native `ROOT` reçoit uniquement une lane consommateur
dupliquée pour le run et la libère collectivement à sa fermeture ; les façades
`System`/`AmrSystem` n'acceptent plus le singleton monde pour cette route. La route `COLLECTIVE`
appelle le backend C++ HDF5 parallèle avec la lane MPI dupliquée possédée par la session observateur ;
le writer ne redécouvre ni n'emprunte `MPI_COMM_WORLD`. `h5py` reste uniquement un
lecteur/écrivain série optionnel et n'est jamais un transport MPI. Une dépendance HDF5 parallèle
native absente, un mode incompatible ou un backend Kokkos GPU/device handle non supporté est refusé avant le
constructeur de `System`/`AmrSystem`; aucune route série implicite ne remplace une demande MPI.

Les maillages non structurés, mobiles/déformables ou changeant de topologie, de nouvelles familles de
Expand Down Expand Up @@ -1536,6 +1561,24 @@ dans `examples/final/`. Chaque script doit :

## 14. Gate de conformance finale

Le job de release exécute d'abord
`scripts/run_final_gate.py --wheel <wheel> --evidence <chemin-hors-checkout>`. Ce gate installe
l'artefact exact avant que
`scripts/prove_public_api_parity.py --wheel <wheel> --installed --evidence <autre-chemin-hors-checkout>`
ne résolve la distribution installée avec `importlib.metadata`, sans importer `pops` dans le
processus du gate. Le chemin résolu doit être extérieur au checkout. La preuve compare octet par
octet tous les fichiers Python et de typage (`*.py`, `*.pyi`, `py.typed`) du checkout, du wheel
retenu et du package installé, puis importe séparément les trois arbres dans des interpréteurs
isolés. Les trois snapshots doivent exposer la même racine publique, les mêmes signatures et
annotations, un `Case` explicite, des handles qualifiés distincts et
authoring/validation/inspection sans chargement de `_pops`. Un ancien nom public, un fichier de
typage absent, un chemin provenant du checkout ou une divergence source/wheel/installé bloque la
publication. La preuve authentifie aussi le `Name`, la `Version` et le digest du `METADATA` de la
distribution installée contre ceux du wheel. Enfin `release_preflight.py` reçoit cette evidence via
`--public-api-evidence` et vérifie son producteur, le SHA-256 du wheel et le chemin du package contre
le même runtime installé que l'evidence finale ; une evidence de parité issue d'un autre wheel ou
d'une autre installation ne peut donc pas être réutilisée.

Une release ne peut être déclarée conforme que par
`scripts/run_final_gate.py --evidence <chemin-hors-checkout>`. La commande exige un checkout propre,
refuse d'écraser une evidence existante et produit une evidence JSON liée au commit, à la version du
Expand Down
Loading
Loading