Skip to main content
NM-RFC-0029

Bounded leakage runtime

Design document · Original source

RFCs record designs and changes. A proposal appearing here does not mean its feature is ready to use. Explore current language support

Status recorded in the original: Proposed

Bound original source · SHA-256
4f3e825b7021fc80a48f1ad3ef8e491c0018f6297d47adf891089bc6a31b09ed

  • Status: proposed
  • Revision: 1 (2026-08-11)
  • Target contract: 0.1.0-experimental
  • Feature flag: experimental.leakageNoise=true
  • Owners: language, compiler, runtime, verification, tooling, product, security
  • Depends on: approved NM-RFC-0018 typed channels; NM-RFC-0019 only when timed rates are requested
  • Does not change: QReg<N>, qubit statevector/density results, stabilizer semantics, or hardware providers
  • Implementation gate: section 17 approval is required before implementation

1. Summary

Leakage leaves the computational qubit subspace. It cannot be represented honestly by adding another qubit Kraus channel to a 2-by-2 state. This RFC therefore proposes a distinct three-level local model and a distinct bounded backend. It never labels the third level as an ordinary qubit value.

nm
@target("browser-leakage-density");
@leakage_profile("package.lab.leakage@1.0.0", "reference_profile");

qreg q[2];
sample 1024 {
  X(q[0]);
  CNOT(q[0], q[1]);
  measure_leakage_aware(q[0]);
  measure_leakage_aware(q[1]);
}

The model is a local, supplied-channel experiment. It is not a transmon, device, pulse, or calibration-fidelity claim.

2. Decision set

  1. Leakage uses target browser-leakage-density; no other backend selects it automatically.
  2. Every allocated site has local dimension three with ordered basis |0>, |1>, |2>. |2> is the leakage level.
  3. Revision 1 accepts one to three sites. The density dimension is 3^n.
  4. Ordinary gates are embedded into the computational subspace and act as the identity on leakage levels according to frozen matrices.
  5. Leakage channels are exact-version typed package data. Inline matrices, callbacks, URLs, and runtime discovery are forbidden.
  6. Terminal measurement has outcomes 0, 1, and L; leakage is never folded into 0/1 unless a later explicit readout model defines that operation.
  7. Qubit assertions/exports fail closed when they cannot preserve L.

3. Source restrictions

Revision 1 accepts a single compile-time qreg of width 1..3, a unitary prefix, optional leakage channels resolved by the active profile, and exactly one terminal measure_leakage_aware per site. Ordinary measure, reset, mid-circuit measurement, feed-forward, dynamic indexing, allocation, QEC, generic oracle expansion, and mixed backend execution are rejected.

The profile reference is an exact canonical package specifier plus export name. Ranges, tags, workspace references, paths, and network addresses fail closed.

4. Gate embedding

Revision 1 gate set is I, X, Y, Z, H, S, Sdg, T, Tdg, Rx, Ry, Rz, Phase, CNOT, CZ, and SWAP. One-site qubit matrix U embeds as:

text
[[U00, U01, 0],
 [U10, U11, 0],
 [0,   0,   1]]

Two-site gates embed on the four computational basis states and are identity on all five basis states containing at least one |2>. The carrier records the complete row-major matrix and basis ordering. Controlled behavior does not activate on |2>.

This is a frozen abstract model, not a physical pulse-level gate extension.

5. Typed leakage channel

An exact package export resolves to nm-leakage-channel@0.1 or a bounded nm-leakage-profile@0.1. Each channel has arity one or two, local dimension three, 1..8 Kraus operators, immutable package/export/digest identity, ordered match rules, limitations, and SHA-256 integrity.

Matrix dimension is 3^arity. The strict reader applies NM-RFC-0018's finite, shape, complete-positivity, and trace-preservation checks using tolerance 1e-10, recomputed for the declared dimension. Qubit KrausChannel<N> and leakage channels are not interchangeable.

The closed built-in reference profile may contain:

  • leak_1_to_2(p): population transfer from |1> to |2>;
  • seep_2_to_1(p): population transfer from |2> to |1>; and
  • leakage_dephase(p): dephasing between the computational and leakage subspaces.

Exact matrices are frozen in a later approved implementation revision; these names are not implementable until then.

6. Measurement and probabilities

Terminal measurement uses projectors onto local |0>, |1>, and |2>. Canonical histogram keys are ternary strings over 0, 1, and L, ordered by the written measurement map. Counts sum exactly to shots.

The result separately reports:

  • full ternary exact probabilities;
  • sampled ternary histogram;
  • per-site leakage probability P(L);
  • any-site leakage probability;
  • computational-subspace mass; and
  • conditioned 0/1 probabilities only when explicitly labeled postselectedOnNoLeakage.

Postselected values are descriptive and never replace unconditional evidence. Zero computational mass yields no conditioned distribution.

7. Bounds

  • sites: 1..3;
  • density dimension: 3..27;
  • density entries: at most 729 complex values;
  • executable gates: at most 128;
  • matched channel applications: at most 64;
  • channel operators: 1..8 each;
  • shots: 1..4096;
  • channel/profile artifact: at most 65,536 UTF-8 bytes; and
  • result: at most 524,288 UTF-8 bytes.

Every dimension/count is validated with checked arithmetic before allocation.

8. Carrier and runtime validation

The compiler emits a closed leakage carrier with source/gate/profile/package identity, embedded qutrit gate matrices, channel artifacts and placements, terminal measurement map, seed/shots, numeric policy, bounds, and complete integrity. Runtime re-derives every matrix and placement and validates all CPTP and density invariants before and during execution.

Carrier/result identities are distinct from NM-RFC-0018 qubit artifacts. Changing local dimension, basis order, gate embedding, channel, package, placement, seed, shots, or measurement invalidates the carrier.

9. Result artifact

nm-leakage-density-run@0.1 contains the bounded final density matrix, ternary probabilities/histogram, leakage metrics, ordered channel provenance, numeric drift, random-source version, and limitations. It never serializes the state as a qubit density matrix and never emits a two-level purity/fidelity claim without stating the subspace and conditioning policy.

10. Diagnostics

Table 1
CodeMeaning
NM-LEAK-001explicit negotiation or distinct target is absent
NM-LEAK-002source structure or terminal leakage-aware measurement is invalid
NM-LEAK-003package/profile reference is not exact or immutable
NM-LEAK-004channel shape, dimension, CPTP, version, or integrity failure
NM-LEAK-005unsupported gate, assertion, exporter, or mixed backend
NM-LEAK-006site, gate, placement, operator, shot, byte, or allocation bound exceeded
NM-LEAK-007embedded gate or compiler/runtime carrier mismatch
NM-LEAK-008density invariant, ternary probability, histogram, or result failure

11. Tool and product behavior

After approval, every surface must display the distinct backend and three-level basis. Charts include an explicit L category and accessible text/table data. Experiment Studio may compare qubit-only and leakage models only as different model contracts; it cannot imply one is a more accurate device prediction.

The product must always show: supplied local model, at most three sites, no calibration unless an approved exact binding is present, no pulse dynamics, no mitigation/QEC, and no hardware-fidelity claim.

12. Export and compatibility

OpenQASM 2/3, Quantikz, ordinary qubit JSON IR, framework circuit exports, stabilizer, and hardware jobs fail closed because they do not preserve the three-level state and L measurement. A future qutrit-aware sidecar/exporter requires a separate contract. Flag-off qubit programs remain unchanged.

13. Security

  • Package channels are inert strict data; no package code is evaluated.
  • Reject all sizes before 3^n, matrix, or result allocation.
  • Copy validated arrays and reject prototypes/getters/sparse/future fields.
  • SHA-256 is integrity, not authorization or physical validation.
  • Logs omit raw matrices, source, and owner-private package content.

14. Non-goals

  • More than one leakage level, more than three sites, transmon Hamiltonians, pulse envelopes, coherent drive simulation, non-Markovian memory, or fitting.
  • Converting leakage to erasure, applying a decoder, logical error rates, mitigation, fault tolerance, or hardware-provider execution.
  • Implicitly treating L as 0, 1, loss, or a missing shot.

15. Rollout

  1. Approve dependencies and all named reviews.
  2. Freeze qutrit basis, gate matrices, channel schemas, and numeric fixtures.
  3. Implement strict compiler/runtime carriers and allocation guards.
  4. Add bounded density kernel and leakage-aware measurement.
  5. Add artifacts, CLI/tool parity, and localized lab surfaces.
  6. Close CPTP/invariant fuzz, maximum-workload performance, cross-platform determinism, browser, accessibility, and claims evidence.

16. Acceptance criteria

  • Qubit artifacts cannot be passed to the leakage runtime or vice versa.
  • Identity/no-channel fixtures preserve computational-subspace qubit results.
  • Hand-computed leak/seep fixtures preserve trace and expected ternary mass.
  • L is visible in every histogram/table/export boundary.
  • Oversized, malformed, non-CPTP, mutated, and wrong-dimension inputs fail before allocation.
  • Same carrier/seed produces byte-identical evidence on pinned Windows/Linux Node 22.

17. Required review record

Table 2
ReviewRequired decisionStatus
Language ownertarget, source restrictions, measurement spellingpending
Runtime ownerqutrit kernel, embedding, boundspending
Verification ownerCPTP/invariants, basis, ternary measurementpending
Security ownerartifact reader and 3^n allocation guardspending
Product ownerleakage labels and comparison boundariespending

This proposal creates no target, flag, runtime, capability, or UI. Passing CI or merging it is not approval to implement.