Versioned models and experiment history
Export, verify, migrate, import, evict, and clear bounded local QML artifacts with strict schemas, canonical integrity, and explicit privacy policy.
Model, experiment record, and history 0.1 contracts
The three local artifact surfaces publish strict readers, permanent fixtures, canonical digests, bounded schemas, explicit legacy migrations, and compatible Core/browser/package behavior.
Integrity-protected model packages
A model binds parser-clean source, exact trained parameter keys and values, finite training evidence, simulator environment, source digest, and canonical package digest. Nested unknown fields and direct tampering fail closed.
const imported = importNMModelPackageJson(json);
const compatibility = validateNMModelPackageCompatibility(imported.package);
const applied = applyNMModelPackageChecked(imported.package, {
target: nmModelPackageRuntimeTargets.browserStatevector,
});
const migrated = migrateNMModelPackage(legacyPackage);Open model package JSON SchemaFail-closed runtime compatibility
Apply validates the package reader, closed runtime target, language major/minor, exact engine, qubit capacity, and explicit noise support before source parameters can change. Any mismatch returns NM-MODEL-011 without applying the model.
Every apply publishes six ordered checks: package, target, language, engine, qubits, and noise.
packagetargetlanguageenginequbitsnoisePrivacy-minimized experiment records
Source text is omitted by default while its hash remains part of stable experiment identity. Run identity covers time and outcome; whole-record integrity additionally covers runtime metadata.
256 KB JSON and 10000000 circuit evaluations maximum.
Identity v0.1: experiment-id-created-at-and-canonical-outcome
Open experiment record JSON SchemaMigrating local experiment history
History exports are newest-first, integrity protected, duplicate free, and preserve each record's explicit source choice. The default store evicts the oldest record atomically at capacity.
200 records, 32 MB JSON, IndexedDB schema v3.
Open experiment history JSON SchemaCanonical whole-artifact integrity
FNV-1a-64 is an accidental/tamper integrity checksum, not a signature. Source, model, record, and history digests are recomputed before use.
Canonical config and run identity
Experiment id uses source hash plus ordered workload fields. Run id uses experiment id, exact timestamp, and recursively key-sorted outcome JSON, so object key order cannot fork one semantic run. Runtime metadata is excluded from comparison identity but covered by whole-record integrity; legacy order-dependent ids require explicit migration.
Explicit source privacy
Experiment creation excludes source by default. Export never silently adds or removes source and publishes the exact count of source-carrying records.
Deterministic quota behavior
At 200 records the default policy evicts the oldest createdAt/runId entry; callers may explicitly select fail-closed rejection instead.
No implicit legacy trust
Pre-integrity model/record files, order-dependent legacy run ids, and raw history arrays are rejected by strict readers. Explicit migration validates every field, derives canonical identity and integrity, and refuses lossy conversion. IndexedDB v1/v2 rows upgrade to v3; invalid rows move to quarantine.
Stable artifact diagnostics
NM-MODEL-001NM-MODEL-002NM-MODEL-003NM-MODEL-004NM-MODEL-005NM-MODEL-006NM-MODEL-007NM-MODEL-008NM-MODEL-009NM-MODEL-010NM-MODEL-011NM-EXPERIMENT-001NM-EXPERIMENT-002NM-EXPERIMENT-003NM-EXPERIMENT-004NM-EXPERIMENT-005NM-EXPERIMENT-006NM-EXPERIMENT-007NM-EXPERIMENT-008NM-EXPERIMENT-009NM-EXPERIMENT-010NM-HISTORY-001NM-HISTORY-002NM-HISTORY-003NM-HISTORY-004NM-HISTORY-005NM-HISTORY-006NM-HISTORY-007NM-HISTORY-008NM-HISTORY-009NM-HISTORY-010FNV integrity does not authenticate an author or protect against a malicious party that can recompute hashes. Signed release artifacts and remote synchronization remain separate future capabilities.
Permanent current, tampered, legacy, and future-language fixtures; the six-check runtime matrix; source/runtime/outcome tampering; byte limits; 200-record eviction/rejection; export/import; clean tarballs; mobile docs; and maximum-carrier performance are automated.