Skip to content

Add: [H3] seal and validate HBG execution slots - #2175

Draft
TaoZQY wants to merge 1 commit into
hw-native-sys:mainfrom
TaoZQY:codex/hbg-pr-h3
Draft

Add: [H3] seal and validate HBG execution slots#2175
TaoZQY wants to merge 1 commit into
hw-native-sys:mainfrom
TaoZQY:codex/hbg-pr-h3

Conversation

@TaoZQY

@TaoZQY TaoZQY commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

A graph packet must not authorize writes using its own claimed addresses. Seal actual frozen context resources during prepare and publish them into an independent context-owned AICPU registry. Before exposing a restore view, compare the packet's complete bindings, device, generation and runtime binary identity against this record.

Reserve a separate 192-byte registry slice outside all mutable graph images, retaining two physical allocations. Ready registrations are immutable; duplicates must match exactly. The resident DSO stores only a registry pointer. Rejected packets leave working memory, registry and output unchanged. HBG packet version 2 carries device and binary identity while preserving the 64-byte K1 envelope and invocation-owned callable identity.

Validation

  • All 147 non-hardware C++ test executables passed, including 59 HBG cases per architecture.
  • Full rebased stack at H3 Add: [H3] seal and validate HBG execution slots #2175: 147 C++ test executables and 159 Python tests passed (4 hardware-marked skips), covering ABI, task interfaces and simulator DMA workspace.
  • Full-stack simulation with the pinned PTO ISA required: A2/A3 74 passed, 8 skipped; A5 71 passed.
  • Runtime libraries rebuilt; repository pre-commit checks passed. Each earlier milestone was independently compiled and tested.
  • mkdocs build --strict passed separately at all five PR heads. The HBG contract page is included in navigation from H1; the execution-slot page is included from H3.

The Host prepare callback and device control/admission interfaces are implemented. H4 must supply semantic validation and pristine restore; H5/common owner must connect CANN registration, PrepareTail ordering and device detachment before context close. Unit cache operations are stubbed; no onboard coherence or capture/replay claim is made.

Dependency and review scope

Draft 5/5: H3. Depends on #2174.

This draft is rebased onto main at a1aa7fddf42b2d28849bc3fb6fe1eb50ab891324 and squashed to one commit. The rebase retains the upstream documentation-theme update. Source and test files match the previous PR head exactly; the squash preserves the complete rebased tree. Applicable pre-commit checks passed again.

All five HBG drafts target main. Each PR has exactly one commit, containing K1 plus all HBG milestones through the stage in its title. Squashing changes commit history, not the cumulative code scope. The original isolated diff above remains available to review this stage alone. Rebase in dependency order after prerequisites land.

The K1 snapshot originally carried from 21fb15c0 is included in this squashed commit, with its human author retained as co-author. Upstream #2064 remains open and has advanced; alignment with its final version remains public execution integration work.

No idle onboard devices were available. Simulation golden checks cover existing program-mode regression; mixed ACLGraph capture/replay, DSV4 CSA device accuracy and comparative performance remain unvalidated.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

- Reserve context-owned registry storage outside mutable graph images
  and seal frozen addresses, capacities and runtime identity at prepare.
- Publish immutable device registrations and compare complete packet
  bindings before exposing a restore view, with no writes on rejection.
- Carry device and binary identity in the versioned HBG packet while
  preserving the 64-byte K1 envelope and invocation-owned callable data.
- Cover registration, forged bindings, stale generations, publication
  and context ownership on both architectures; document owner hooks.

Include the kernel-mode C ABI, state and invocation headers required
by this implementation. Retain the preceding HBG resource and packet
changes present in this draft where applicable. Public kernel launch
integration remains pending.

Co-authored-by: sunkaixuan2018 <baiyi@mail.ustc.edu.cn>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant