Ana içeriğe geç
NM-RFC-0034

Statik XOR'dan faz oracle'ına adaptörler

Tasarım belgesi · Özgün kaynak

RFC'ler tasarım ve değişiklik kayıtlarıdır. Bir önerinin burada bulunması, özelliğin kullanıma hazır olduğu anlamına gelmez. Güncel dil desteğini incele

Özgün belgedeki durum: Öneri

Bağlı özgün kaynak · SHA-256
96d366aa1a48c01e60d61831fe01c873df348f456b565d3bb4bcc67ffcafa2d1

Status: proposed Revision: 2 (2026-08-12) Feature flag: experimental.oracleAdapters=true Depends on: NM-RFC-0002 exact-version imports, NM-RFC-0010 typed generic oracles, and NM-RFC-0015 generalized circuit signatures Implementation gate: the section 13 review record is mandatory before implementation Does not change: the five-qubit verification/runtime ceilings, PhaseOracle<N> meaning, generic Grover ready range, runtime-sized register policy, or hardware claims

1. Purpose

NM-RFC-0010 deliberately removed the expression-shaped phase_kickback(f, aux) coercion. That form created a dynamic oracle value, captured a runtime qubit, and skipped the mandatory Tier B verification applied to every PhaseOracle<N>.

This RFC proposes the strict one-way adapter program deferred by NM-RFC-0010 §23.5:

text
XorOracle<N,1> + caller-owned |-> resource -> logical PhaseOracle<N> effect

Revision 2 is a design contract only. It creates no parser rule, runtime path, capability entry, package export, Playground toggle, or executable ready range.

2. Frozen decisions

The first adapter contract has these non-negotiable properties:

  1. Conversion is one-way. No PhaseOracle<N> to XorOracle<N,1> adapter is defined or inferred.
  2. An adapter is a statically named declaration or an exact-version package export. It is never a value-producing expression, closure, callback, or runtime-loaded circuit.
  3. The source oracle is exactly XorOracle<N,1>. M != 1, untyped circuits, approximate unitaries, and runtime-selected exports are rejected.
  4. The caller supplies every qubit: data, the minus carrier, and the source oracle's statically declared CleanAncilla<K>. The adapter allocates no data, output, or scratch qubit.
  5. The |-> resource is represented by the linear MinusAncilla<1> carrier. An untyped QReg<1> or a caller assertion is insufficient.
  6. The source oracle, adapter declaration, concrete sizes, complete resource signature, and package versions are resolved before runtime. K = 0 omits the clean-source resource; K > 0 requires one explicit disjoint binding.
  7. The full composite is verified numerically under Tier B. There is no structural or large-N exemption.
  8. Global phase is not discarded. Under future control it would become relative phase, so equality includes the exact complex sign convention.

3. Static source model

The proposed declaration form binds an exact oracle symbol but does not bind a runtime qubit:

nm
derive phase_oracle marked_by_f<const N: Int>
  from xor_oracle package.example@1.2.3::f
  using MinusAncilla<1>;

The declaration has logical type PhaseOracle<N> plus an explicit MinusAncilla<1> requirement and the source oracle's exact CleanAncilla<K> requirement. The following ancilla-free source has K = 0, so only the minus resource is threaded at its monomorphized call site:

K and the clean resource positions are inherited from the verified exact source symbol. An adapter declaration cannot restate, narrow, widen, or reorder that signature.

nm
let data: QReg<4> = qreg[4];
let scratch: CleanAncilla<1> = qreg[1];
let minus: MinusAncilla<1> = prepare_minus(scratch);

grover<4, 3>(data, oracle: marked_by_f, using: minus);

let scratch = release_minus(minus);

marked_by_f is a symbol, not a variable. using: minus is an explicit linear resource argument, not closure capture. If the exact source oracle declares CleanAncilla<K> with K > 0, the closed call form additionally requires one clean: source_work binding:

nm
let data: QReg<3> = qreg[3];
let minus_storage: CleanAncilla<1> = qreg[1];
let source_work: CleanAncilla<1> = qreg[1];
let minus: MinusAncilla<1> = prepare_minus(minus_storage);

grover<3, 1>(data, oracle: marked_by_f, using: minus, clean: source_work);

let minus_storage = release_minus(minus);

clean: is absent when K = 0 and mandatory exactly once when K > 0; its static width must equal K. The compiler threads both resources only through calls that require the adapter, then expands the complete concrete circuit before runtime. Data, minus, and source-work positions must be pairwise disjoint. Omitting, duplicating, aliasing, dynamically selecting, or supplying an extra resource is an error.

The existing grover<N,R>(..., oracle: PhaseOracle<N>) source remains valid for direct phase-oracle declarations. Adapter resource threading is an additional closed call form and must not silently change direct-oracle ABI or semantics.

4. MinusAncilla<1> typestate

MinusAncilla<1> is a linear state carrier, not a general register type.

  • prepare_minus consumes one caller-owned CleanAncilla<1> known to be |0>, applies canonical X then H, and returns the unique minus carrier.
  • While borrowed by an adapter, the carrier cannot be indexed, aliased, measured, reset, exposed to noise, passed to an arbitrary gate, or used by a second call.
  • A conforming adapter returns the same carrier in |->; ownership returns to the caller after every application.
  • release_minus consumes the carrier, applies canonical H then X, verifies the clean postcondition, and returns CleanAncilla<1>.
  • The carrier cannot cross an unbounded loop, escape through a dynamic value, enter a runtime-sized collection, or remain live at function return.
  • A bound CleanAncilla<K> source-work register is borrowed for the same call, cannot alias data or the minus carrier, and must return in its clean typestate before either resource is made available to the caller again.

Preparation and release occur outside the oracle body. This does not weaken NM-RFC-0010's ban on allocation, measurement, reset, or runtime control inside an oracle.

5. Normative phase semantics

For a verified source oracle U_f implementing

text
U_f |x>|y> = |x>|y xor f(x)>

the adapter must implement, on the complete promised input subspace,

text
U_f |x>|-> = (-1)^f(x) |x>|->

for every computational basis input x. The logical action on the data register is therefore diagonal with entries exactly in {+1,-1}, and the minus carrier is restored. The contract does not infer a general diagonal unitary, arbitrary phase function, approximate kickback, or hardware-level phase calibration.

The compiler may inline the source oracle or call a concrete exact-version export. It may not replace the operation with a truth-table guess, a sampled approximation, or a different synthesized phase circuit unless a future RFC defines and independently verifies that synthesis transformation.

6. Verification

Verification is normative and numerical. For each concrete specialization the verifier constructs the full 2^(N + 1 + K) matrix, where K is the total caller-supplied clean scratch width required by the source XorOracle.

It must prove within the frozen NM-RFC-0010 tolerance:

  1. the source oracle remains a valid XorOracle<N,1> with exact complex +1 permutation entries;
  2. the composite is unitary;
  3. the |-> subspace is invariant;
  4. data-basis action is diagonal and each diagonal value is +1 or -1;
  5. that sign equals (-1)^f(x) for every x;
  6. MinusAncilla<1> and every CleanAncilla<K> are restored; and
  7. recomputing from canonical source and package inputs reproduces the adapter identity and verification digest.

Syntactic phase-kickback recognition is permitted only as an early diagnostic. It is not proof and never replaces the matrix check. A matrix that is correct only up to global phase is rejected.

7. Exact-version package and artifact

The first standard export is reserved as algorithms.oracle_adapters@0.1. Publication requires a signed, explicitly licensed exact-version package and a strict nm-oracle-adapter@0.1 artifact.

The artifact contains only closed fields:

  • adapter format/version and declaration name;
  • exact source package specifier/export and integrity digest;
  • concrete N, source scratch width K, and resource signature;
  • canonical source/specialization/expanded-circuit digests;
  • source-oracle verification identity;
  • complete composite matrix-verification result and digest;
  • gate, depth, two-qubit, controlled-gate, and maximum-live-qubit counts;
  • requested/effective backend compatibility;
  • compiler, verifier, tolerance, and feature-negotiation versions; and
  • artifact integrity.

The artifact stores no private signing key, package credential, session token, raw browser identity, or unverifiable caller assertion. Readers reject unknown fields, unsupported versions, duplicate keys, non-finite numbers, and size or count overflow before allocation.

8. Bounds and ready range

Tier B counts the data register, minus carrier, and all source scratch:

text
N + 1 + K <= NM_ORACLE_VERIFICATION_MAX_WIDTH = 5

Consequently, an ancilla-free source has a maximum planning width N <= 4. This is a verification ceiling, not an executable-ready claim. Revision 2 publishes no runnable adapter range.

Every specialization must also pass the existing expanded gate, depth, two-qubit, modifier, and execution budgets. The adapter does not raise the statevector ceiling and is not a scalability feature. A future implementation may publish a narrower range, including only N = 2 or N <= 3, if retained performance and browser evidence justify no more.

9. Modifiers and composition

Revision 2 proposes no ctrl, pow, or nested adapter composition. adjoint adds no useful behavior because the verified logical marking effect is self-inverse; source-level modifier syntax on an adapter is rejected rather than silently erased.

An adapter cannot consume another adapter, bind a runtime oracle, or appear inside an oracle body as a dynamic callable. Direct PhaseOracle<N> and XorOracle<N,M> declarations retain all NM-RFC-0010 rules.

10. Diagnostics

Tablo 1
CodeMeaning
NM-ADAPTER-001adapter feature was not explicitly negotiated
NM-ADAPTER-002declaration is anonymous, expression-shaped, or not exact-version bound
NM-ADAPTER-003source is not XorOracle<N,1> or its specialization differs
NM-ADAPTER-004MinusAncilla<1> preparation, ownership, or release is invalid
NM-ADAPTER-005resource is missing, extra, width-mismatched, aliased, captured, or used while borrowed
NM-ADAPTER-006total verification width or another resource budget is exceeded
NM-ADAPTER-007source XOR verification or exact complex permutation check fails
NM-ADAPTER-008composite unitarity, diagonality, sign, or phase equality fails
NM-ADAPTER-009minus or clean ancillary state is not restored
NM-ADAPTER-010artifact, package, source, or recomputation digest differs
NM-ADAPTER-011unsupported modifier or nested adapter composition was requested
NM-ADAPTER-012runtime, provider, or executable surface advertised an unapproved adapter

Diagnostics name the declaration and static resource position, never a secret, credential, raw package body, or user identity.

11. Security and failure policy

  • Resolution is exact-version and integrity checked before parsing or matrix allocation.
  • Source bytes, AST nodes, expanded gates, width, matrix elements, artifact bytes, and verification time are bounded before allocation.
  • Cancellation or timeout produces no valid adapter artifact.
  • Verification failure never falls back to a direct hand-written phase oracle.
  • An unavailable package or verifier is a hard error, not a request to fetch arbitrary network code.
  • UI and CLI must label all proposal previews non-runnable until capability promotion is independently approved.

12. Acceptance criteria

  • Positive fixtures cover constant-zero, constant-one, affine parity, and one non-linear but bounded XorOracle<N,1>.
  • Negative fixtures cover wrong M, -1 permutation entries, non-unitarity, global-phase drift, missing/wrong/aliased minus resources, missing/extra/ width-mismatched/aliased source work, dirty scratch, package drift, modifier use, width overflow, timeout, and tampered artifacts.
  • Numeric fixtures prove both data phase and exact carrier restoration for every basis input at the maximum published range.
  • Core, CLI, Worker, LSP, VS Code, Playground, Oracle Builder, and package tools agree on diagnostics and never advertise a wider range.
  • Existing generic-oracle programs remain byte-equivalent when the new feature is disabled.
  • While this RFC is proposed, runtime protocol, capability registry, package exports, and Playground controls contain no executable adapter surface.

13. Required reviews

Tablo 2
OwnerDecisionStatus
Language ownerstatic declaration and using resource grammarpending
Type-system ownerlinear minus/source-work ownership, aliasing, and escape rulespending
Compiler ownermonomorphization, dual resource threading, and identitypending
Verification ownerfull matrix, sign, phase, and restoration checkspending
Security ownerpackage/artifact readers, allocation bounds, and timeoutpending
Product ownernon-runnable proposal wording and ready-range disclosurepending

Approval must record reviewer identity, date, rationale, and a retained review artifact for every row. A merge, prototype, passing test, or local UI is not approval. Until every row is approved, no feature flag, parser/compiler/runtime surface, package export, capability, Playground control, or Oracle Builder preview may be added.

14. Implementation sequence

  1. Approve the static declaration and linear-resource model; otherwise revise this RFC without adding parser syntax.
  2. Freeze strict adapter artifact/schema/readers and hostile fixtures.
  3. Add MinusAncilla<1> typestate and compiler-only resource threading.
  4. Implement full Tier B verification and deterministic identity generation.
  5. Add the exact-version standard package export and CLI/tooling diagnostics.
  6. Add Playground and Oracle Builder previews only after Core conformance.
  7. Publish the measured ready range through the normal capability promotion process; no step auto-promotes NM-RFC-0010 or this RFC.