Ana içeriğe geç
NM-RFC-0019

Kalibrasyona duyarlı zamanlama ve boşta gürültü

Tasarım belgesi · Özgün kaynak

RFC'ler tasarım ve değişiklik kayıtlarıdır. Bir önerinin burada bulunması, özelliğin kullanıma hazır olduğu anlamına gelmez. Güncel dil desteğini incele

Özgün belgedeki durum: Öneri

Bağlı özgün kaynak · SHA-256
5b52b2c83f9aaeda4b445a8c57a151d0df3fca412c686e03855c2668d2c913dd

  • Status: proposed
  • Revision: 1 (2026-08-11)
  • Target contract: 0.2.0-experimental
  • Feature flag: experimental.calibrationAwareTiming=true
  • Owners: language, compiler, runtime, verification, tooling, product, security
  • Depends on: NM-RFC-0002 exact-version resolution, NM-RFC-0006 target constraints, NM-RFC-0018 bounded density execution
  • Uses: nm-target-calibration@0.1 snapshots and deterministic target scheduling
  • Does not change: existing calibration comparison, stable target selection, trajectory noise, or provider APIs
  • Implementation gate: this proposal does not authorize implementation; section 18 approval is mandatory

1. Summary

N/M can import and compare bounded target-calibration snapshots and can produce a deterministic target schedule. Those two surfaces are deliberately not bound today. A displayed T1/T2 value must not silently influence simulation.

This RFC proposes an explicit, immutable binding from one calibration snapshot and one target profile to a timed execution plan. The density-matrix runtime may then apply a closed idle channel to each scheduled idle window.

nm
@target("local-density-reference");
@calibration_binding(
  "calibration.lab.reference@2026.08.11",
  digest: "sha256:...",
  max_age_hours: 168
);
@timing_noise("idle-t1-t2-v1");

qreg q[2];
sample 1024 {
  H(q[0]);
  CNOT(q[0], q[1]);
  measure(q[0]);
  measure(q[1]);
}

The proposal is a replayable local model derived from a frozen snapshot. It is not a live device model, provider promise, or hardware-fidelity claim.

2. Decision set

  1. Calibration never binds automatically; source and API callers opt in.
  2. Runtime never fetches live provider data. The complete accepted snapshot is resolved before compilation and bound by identity plus SHA-256 digest.
  3. The compiler first freezes target-native lowering and scheduling, then derives idle windows, then resolves idle channels. This order is observable.
  4. Revision 1 executes only on the approved NM-RFC-0018 density backend with at most five qubits. Statevector trajectories and stabilizer execution fail closed.
  5. Snapshot age is evaluated against an explicit caller-supplied observation time carried in evidence, never the runtime wall clock.
  6. Missing required metrics never fall back to defaults or neighboring qubits.
  7. Imported snapshots remain display-only unless a valid binding carrier is present.
  8. The feature, artifacts, and product controls remain absent until section 18 review approval.

3. Source and API boundary

The source directive contains an exact immutable calibration identifier, a lowercase sha256: digest, and max_age_hours in 1..8760. Tags such as latest, version ranges, URLs, filesystem paths, environment interpolation, and bare provider identifiers are rejected.

@timing_noise("idle-t1-t2-v1") is the only revision-1 model. It requires a calibration binding and cannot coexist with stable @noise, NM-RFC-0017 trajectory profiles, or a second timing-noise activation.

API callers provide an explicit RFC-3339 UTC observedAt value. Source-only CLI execution uses a required --calibration-observed-at argument. This makes freshness replayable. No code path calls Date.now() to decide acceptance.

4. Calibration snapshot requirements

The resolved nm-target-calibration@0.1 snapshot must pass its strict reader and provide:

  • immutable snapshot ID, exact target-profile ID/version, captured-at time, schema version, and SHA-256 content digest;
  • positive finite gate durations for every scheduled native gate;
  • positive finite measurement durations;
  • per-qubit positive finite t1Ns and t2Ns; and
  • explicit units and provenance for every consumed metric.

For every qubit, t2Ns <= 2 * t1Ns + 1e-9. A violation is rejected rather than clamped. Missing values, stale digests, unit conversion ambiguity, duplicate qubits, unknown gates, partial topology, NaN, Infinity, signed zero, and values above 1e15 nanoseconds fail closed.

Snapshot trust/attestation is recorded but does not make the data true. A cryptographically intact snapshot may still be an inaccurate model.

5. Deterministic timed plan

The compiler emits nm-timed-execution-plan@0.1 after target-native lowering. It contains:

  • source, compiler, target profile, calibration snapshot, and binding IDs;
  • exact target/calibration digests and observation/capture times;
  • canonical ordered native operations with start/end nanoseconds;
  • dependency edges and per-qubit occupied intervals;
  • all derived idle windows, including leading and inter-operation windows;
  • closed numeric policy, bounds, and integrity; and
  • the hash of the lower-level gate carrier used by NM-RFC-0018.

Scheduling is ASAP with stable source-order tie breaking. Durations are integer nanoseconds. Simultaneous operations are permitted only when target resource constraints allow them. Measurement is terminal. A qubit's trailing idle time after its terminal measurement is not simulated.

Changing one duration, dependency, topology edge, operation, qubit mapping, or tie-break order changes the plan identity.

6. Idle-window derivation

For each allocated qubit, sort occupied intervals by (start, end, operationId). Intervals may touch but may not overlap. An idle window is each positive gap between preparation time zero and the first operation, and between consecutive operations before terminal measurement.

Zero-length gaps are omitted. Each window records qubit, start, end, duration, preceding/following operation IDs, T1/T2 source metric IDs, and the derived channel parameters. At most 512 idle windows are accepted.

7. Frozen idle channel

For an idle duration dt, calibration values T1 and T2 yield:

text
gamma = 1 - exp(-dt / T1)
1 / Tphi = 1 / T2 - 1 / (2 * T1)
lambda = 1 - exp(-dt / Tphi)

If 1/Tphi is within 1e-15 of zero, lambda = 0. A negative value beyond that tolerance is rejected. gamma and lambda must remain finite in 0..1.

The runtime applies amplitude damping followed by phase damping at the end of each idle window, ordered by (end, qubit, start), before an operation starting at that same timestamp. The matrices are exactly the NM-RFC-0018 built-ins. No random draw is consumed by channel application.

This ordering is a model definition, not a statement about microscopic device physics.

8. Freshness and comparison policy

text
age_hours = (observedAt - capturedAt) / 3600 seconds
accept iff 0 <= age_hours <= max_age_hours

Times use exact parsed UTC instants. A future snapshot, absent timezone, leap second spelling, or negative/overflowing age fails. Freshness expresses only the user's replay policy. It does not certify that calibration remained valid throughout the interval.

The existing calibration comparison UI may prepare a binding candidate, but it must show the exact selected snapshot/digest and require a separate explicit action. Viewing, importing, or comparing a snapshot never activates noise.

9. Bounds

  • source: existing NM-RFC-0018 bound;
  • qubits: 1..5;
  • native operations: 1..256;
  • dependency edges: at most 1024;
  • idle windows: at most 512;
  • shots: 1..4096;
  • duration and T1/T2: positive integer nanoseconds, at most 1e15;
  • timed plan: at most 262,144 UTF-8 bytes; and
  • runtime result: existing NM-RFC-0018 result bound.

All counts are checked before multiplication, sorting, matrix allocation, or channel construction.

10. Runtime carrier and result

The NM-RFC-0018 carrier embeds the complete validated timed plan and calibration binding, not a mutable lookup key. Public runtime revalidates both artifacts, recomputes idle windows and channel parameters, and requires exact agreement before density allocation.

The density result adds a versioned timingNoise record containing plan and snapshot identities, freshness inputs, total/maximum idle time, ordered idle applications, per-qubit T1/T2 provenance, and numeric drift. It retains the limitations:

  • frozen-snapshot local model;
  • not live calibration;
  • not hardware fidelity;
  • no crosstalk, leakage, pulses, non-Markovian memory, mitigation, or fault-tolerance claim.

11. Diagnostics

Tablo 1
CodeMeaning
NM-TIMING-NOISE-001explicit negotiation is absent
NM-TIMING-NOISE-002malformed, duplicate, or conflicting directive
NM-TIMING-NOISE-003calibration identifier/version/digest is not exact
NM-TIMING-NOISE-004snapshot schema, integrity, target binding, metric, or unit failure
NM-TIMING-NOISE-005snapshot is future-dated or outside explicit freshness policy
NM-TIMING-NOISE-006schedule has missing duration, overlap, dependency, or topology failure
NM-TIMING-NOISE-007qubit, operation, edge, window, duration, byte, or shot bound exceeded
NM-TIMING-NOISE-008T1/T2 relation or derived gamma/lambda is invalid
NM-TIMING-NOISE-009incompatible backend, noise profile, exporter, or dynamic operation
NM-TIMING-NOISE-010carrier, gate-plan, schedule, calibration, or result binding failed

12. Tool and product behavior

After approval, Core, CLI, Worker, LSP, VS Code, Playground saved/share contexts, Backend & Calibration Lab, and Experiment Studio must expose one consistent explicit opt-in. The product surface must show:

  • snapshot ID/digest and captured/observed times;
  • freshness policy and pass/fail;
  • schedule plus every derived idle interval;
  • exact consumed T1/T2 metrics and derived channel parameters; and
  • a persistent frozen-snapshot/no-hardware-fidelity boundary.

The UI cannot offer a latest calibration shortcut. Secrets, provider tokens, raw provider payloads, and owner-private metadata do not enter client artifacts.

13. Export and compatibility

Strict JSON IR may preserve the timed plan after schema/reader implementation. Circuit-only QASM, Quantikz, and framework exports cannot preserve calibration or idle-channel semantics and fail closed in strict mode. A separate sidecar may carry the complete plan and digests. Flag-off programs and existing calibration comparison remain unchanged.

14. Security and privacy

  • Resolve snapshots through existing owner-scoped storage or immutable package artifacts; never from a source-provided URL/path.
  • Validate byte length before parsing and copy accepted values to owned data.
  • Reject unknown/inherited/accessor fields and future versions.
  • Treat digest as integrity, not authorization or scientific validation.
  • Telemetry contains bounded IDs, ages, counts, and diagnostics, not raw calibration payloads, tokens, or source.

15. Non-goals

  • Live provider polling, automatic refresh, cron binding, secret management, QPU submission, device selection, or calibration truth claims.
  • Crosstalk, leakage, pulse envelopes, readout confusion, drift interpolation, non-Markovian memory, Lindblad integration, or correlated channels.
  • Raising density/statevector ceilings or supporting stabilizer/statevector timing noise in revision 1.
  • Optimization against noisy fidelity; scheduling is deterministic and target-constrained, not an accuracy optimizer.

16. Rollout sequence

  1. Approve NM-RFC-0018 and this RFC's review record.
  2. Freeze snapshot/binding/timed-plan schemas and hostile readers.
  3. Bind deterministic lowering and scheduling without executing noise.
  4. Add idle-window derivation and reference numeric fixtures.
  5. Integrate with the bounded density carrier/result.
  6. Add tool and localized product surfaces.
  7. Close cross-platform determinism, fuzz, maximum-allocation, browser, accessibility, and privacy evidence.

17. Acceptance criteria

  • Importing/comparing a calibration does not alter execution.
  • Same source, snapshot, target, observation time, and compiler produce the same plan and idle evidence on pinned Windows/Linux Node 22 runners.
  • Any gate, schedule, duration, metric, digest, or freshness mutation fails carrier validation.
  • Missing per-qubit metrics never use defaults.
  • A two-qubit fixture proves deterministic simultaneous scheduling and idle order against a hand-computed density reference.
  • Invalid T1/T2, overlapping intervals, oversized plans, and forged result evidence fail closed before density allocation.
  • Every UI calls the result a frozen-snapshot local model.

18. Required review record

Tablo 2
ReviewRequired decisionStatus
Language ownerdirectives, conflicts, exact identitypending
Compiler ownerlowering/scheduling order and plan bindingpending
Runtime ownerdensity integration, limits, cancellationpending
Verification ownerT1/T2 formulas, ordering, numeric tolerancespending
Security ownersnapshot resolution, strict readers, privacypending
Product ownerexplicit binding and evidence wordingpending

This revision creates no runtime, flag, capability, backend, or automatic calibration binding. Passing CI or merging the proposal is not approval.