Skip to content

Upgrade the Linx ISA projection to PTO 0.57.1 - #161

Merged
zhoubot merged 22 commits into
mainfrom
codex/linx-isa-0.57.1
Aug 2, 2026
Merged

zhoubot merged 22 commits into
mainfrom
codex/linx-isa-0.57.1

Conversation

@zhoubot

@zhoubot zhoubot commented Jul 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Upgrade the LinxISA superproject and all maintained projections to the normative PTO ISA 0.57.1 contract from PTO-ISA/pto-spec#19.

  • lock pto-spec commit 2f3f605e289b09d56ef5a9ba39fc80b52948a5f5, release manifest, ABI identity, hardware profile, and canonical numeric vectors
  • project exactly 98 TEPL + 9 TMA + 13 CUBE direct operations (120 total, zero optional) and 761 command forms
  • adopt raw Mode/Function TEPL plus the frozen B.IOT, B.DATR, and B.CATR layouts
  • delete TFMA, TFMOD, TFMODS, TADDC, TSUBC, TADDSC, TSUBSC, TLRELU, and TRANDOM
  • lock 128-byte CELLs, 256-KiB per PE, implicit ACC, commit-only reuse, exact DataType/MX/numeric behavior, and pto-v0 identity
  • regenerate golden, C/QEMU codecs, and Sail decode/coverage artifacts
  • repin the reviewed LLVM, PTOAS, QEMU, Linux, libc, RTL/model, pyCircuit, skills, PTO-Kernel, and SuperNPUBench branches
  • keep DavinciOO ISA definitions byte-for-byte aligned without introducing Linx branding

Normative hashes:

  • content: 748c1c6ac1bd5482d219cd08b8f0a871c7eda2b8f8afb1e81d498ec742e8abe8
  • hardware profile: becfbefcc7a31408e5e5293802493f833f68a2fccebb3f9e8008d8b9f4e7658c
  • numeric vectors: b9f908deb9cfec412388e95f4532563cf4e462032b43d15996f0f7b4b93b4ec9

Depends on PTO-ISA/pto-spec#19.

Companion PRs

Validation

  • repository layout, Linux source completeness, canonical ISA/golden, and agent-map gates
  • exact PTO inventory and source-identity/hash checks
  • Linx64 + Linx32 compiler coverage: 100%; 728/728 mnemonics and 763 compiler instructions
  • clean QEMU build and all suites: 1366/1366
  • QEMU executable coverage: L1 728/728, L2 60/60, L3 60/60, rejected 0
  • command-form coverage: 761/761
  • Tile transaction tests: 11/11; production numeric tests: 9/9; Python tests: 22/22
  • Sail decode/coverage gate: 761 forms (760 executable-subset, DMA decode-only)
  • PTOAS CTest: 16/16; targeted lit: 9/9; MX/TSORT: 3/3
  • fresh full vmlinux plus external-O call/return audit
  • musl static/shared matrix, C++ runtime, glibc G1b build, and glibc QEMU runtime
  • SPEC2017 static build, source immutability, Stage-A attestation, and QEMU test/train sentinels
  • TSVC hard-break profile
  • git diff --check

Known scope

  • Full SPEC2017 refrate is not run; the release hard-break uses bounded test/train sentinels.
  • Full LLVM lit remains 75/218 because of documented upstream LLVM 21 baseline gaps; all Linx 0.57.1 targeted suites pass.
  • Sail is the exact decode/coverage model; payload/numeric execution remains covered by the production QEMU oracle.

Final merged-source refresh (2026-08-02)

  • Normative source is the merged Publish the normative PTO ISA 0.57.1 contract PTO-ISA/pto-spec#19 squash commit 2f3f605e289b09d56ef5a9ba39fc80b52948a5f5.
  • Final release identity: content 748c1c6ac1bd5482d219cd08b8f0a871c7eda2b8f8afb1e81d498ec742e8abe8; encoding projection 9705a984e2e48e0d4e856d3fbcfa07041c8578dd326d81f1c90279e826354c32.
  • The final merge keeps the 120-operation names/selectors, command masks/matches, hardware profile, and numeric vectors unchanged; it refreshes source identity plus Bundle/restart/system-register semantic metadata. Embedded locks/ELF identity constants were refreshed where applicable, and focused gates were rerun before promotion.\n\n## Final superproject gate (2026-08-02)\n\n- Rebuilt LLVM from merged SHA 3feb50e4e1896105746a1831d3545d690518d3b3; focused identity lit 4/4 and Linx64/Linx32 AVS coverage passed.\n- Rebuilt QEMU from merged SHA cfc253e844f4b0d017b2190a025c4375771f899a (1366/1366); refreshed non-overwriting r2 evidence: L2 60/60, L3 60/60, rejected 0, all PCs unchanged.\n- Rebuilt merged Linux vmlinux with verified provenance; initramfs smoke and full boot passed.\n- PTO host-vs-QEMU parity matched for all kernels.\n- LINX_GATE_TIER=pr RUN_EXTENDED_CROSS_GATES=1 tools/regression/strict_cross_repo.sh completed all selected gates.\n

@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

LinxISA Automation added 19 commits July 31, 2026 05:13
Project the locked PTO 0.57.1 manifest into the Linx golden catalog and regenerate every checked-in decoder surface so Sail, QEMU, and C consume the same raw ABI.

Constraint: PTO-ISA/pto-spec commit 852b537 is the sole source for 120 tile operations and 99 command forms.

Rejected: Retain legacy TileOpcode decode or deleted D-class operations | the accepted design requires an explicit ABI break with reserved holes.

Confidence: high

Scope-risk: broad

Reversibility: clean

Directive: Use tools/isa/import_pto_v0571.py for future updates and repin leaf submodules only after their semantic gates pass.

Tested: full ISA guard suite, Sail freshness and coverage, repository layout, git diff --check, independent code review

Not-tested: Full executable Sail semantics and downstream LLVM/QEMU/RTL/kernel/libc migrations remain separate leaf PRs.
Regenerate every English documentation projection and encoding diagram after the golden 0.57.1 change, removing the retired generic CUBE page and refreshing translation provenance.

Constraint: Documentation CI treats generated pages, SVGs, and translation hashes as checked release artifacts.

Confidence: high

Scope-risk: moderate

Directive: Regenerate documentation whenever the canonical v0.57 catalog changes.

Tested: docs/check_documentation.py --root .; git diff --check

Not-tested: Full MkDocs and AsciiDoctor rendering is delegated to PR CI.
Align the hand-authored ISA chapters with Mode/Function TEPL selection, typed CUBE and TMA forms, exact B.IOT capacity, implicit ACC, commit-time reuse, and B.DATR ownership.

Constraint: The AsciiDoc manual must not contradict the locked PTO release or include retired generated forms.

Confidence: high

Scope-risk: moderate

Directive: Treat pto-spec and the Linx lock as authoritative when editing manual examples.

Tested: docs/check_documentation.py --root .; git diff --check

Not-tested: Local AsciiDoctor render unavailable because Bundler 2.4.19 is not installed; PR CI performs the render.
Replace stale TileOpcode, 512 KiB, explicit ACC, legacy B.ARG, and generic CUBE claims with the accepted PTO release contract, and repair the section nesting exposed by strict AsciiDoctor rendering.

Constraint: Documentation CI treats every warning as a failure.

Confidence: high

Scope-risk: moderate

Directive: Keep hand-authored chapters synchronized with the machine-readable PTO lock and generated reference.

Tested: docs/check_documentation.py --root .; git diff --check

Not-tested: Local AsciiDoctor unavailable; GitHub CI is the authoritative strict render.
Derive the semantic-status schema identity from the canonical spec version so the AVS gate accepts the locked 0.57.1 projection while still failing closed on mismatches.

Constraint: The old checker hard-coded the retired 0.57.0 schema.

Confidence: high

Scope-risk: narrow

Directive: Never duplicate the current ISA patch version in Sail validation code.

Tested: check_sail_model.py; py_compile; git diff --check

Not-tested: Local Sail parser unavailable; GitHub AVS installs and runs the pinned toolchain.
The normative PTO release now assigns the ELF note type and descriptor framing required for independent producer and loader implementations. Refresh the projection lock and release manifest without changing the 0.57.1 encoding map.

Constraint: PTO-ISA/pto-spec remains the sole normative source
Confidence: high
Scope-risk: narrow
Directive: Leaf ELF implementations must consume note type 1 and the no-NUL canonical JSON descriptor from this manifest
Tested: import check; golden check; PTO manifest check; standalone spec validation; git diff --check
Not-tested: leaf LLVM and loader gates pending
Downstream producer and loader work needs the exact note owner, numeric type, alignment, and descriptor termination rules now fixed by pto-spec. Record them in the accepted integration plan so leaf PR reviews use one testable representation.

Constraint: The values are projected from pto-spec b30ed3d rather than defined by LinxISA
Confidence: high
Scope-risk: narrow
Directive: Keep LLVM, kernel, glibc, and musl tests on this exact note framing
Tested: documentation integrity check; generated documentation drift checks; git diff --check
Not-tested: leaf note implementation gates pending
Remove retired B.ARG, BSTART.FIXP, generic CUBE, and deleted direct operations from the live golden, generated codecs, Sail projection, AVS carriers, and current manuals. Descriptor examples now use B.DATR and CUBE selects ACC implicitly through its opcode.

Constraint: PTO-ISA/pto-spec b30ed3df is the sole normative truth for the 0.57.1 executable set.

Rejected: Preserve generic or legacy decodes as compatibility aliases | the selected policy reserves them and requires illegal-instruction behavior.

Confidence: high

Scope-risk: broad

Directive: Regenerate all golden, codec, Sail, and manual projections whenever the command catalog changes.

Tested: golden check; spec validator; PTO manifest and canonical guards; Sail structural/model tests; generated manual and documentation integrity checks; git diff --check.

Not-tested: Full compiler-QEMU-Linux execution awaits downstream leaf updates and repins.
Clarify that the 13 CUBE operations are named forms with implicit ACC, publish the complete 120-operation split, and regenerate all dependent manual and instruction pages.

Constraint: PTO-ISA/pto-spec is the sole normative source and DavinciOO must remain implementation-neutral.

Rejected: Preserve generic BSTART.CUBE aliases | they expose an executable form that 0.57.1 reserves.

Confidence: high

Scope-risk: narrow

Directive: Do not reintroduce generic CUBE/FIXP or explicit ACC descriptor operands.

Tested: build_golden --check; gen_manual_adoc --check; gen_instruction_fragments --check; gen_isa_pages --check; validate_spec; documentation integrity checks

Not-tested: downstream emulator numeric semantics, pending the N01-N08 normative profile update
A shared opcode projection is insufficient to establish the frozen hardware numeric contract. Extend the Linx import lock and validation gate to bind the normative hardware profile and executable vectors, and record the accepted numeric and matrix decisions in the upgrade plan.

Constraint: PTO-ISA/pto-spec commit 0141ec89 is the sole normative 0.57.1 source
Rejected: Treat unchanged encoding hash as full conformance | numeric semantics can diverge independently of opcode bits
Confidence: high
Scope-risk: narrow
Directive: Do not claim 0.57.1 hardware conformance without matching both locked numeric hashes and executing the vectors
Tested: importer check; manifest validator; Python bytecode compilation; git diff check
Not-tested: downstream emulator and RTL execution of numeric vectors
The checked-in examples still reflected retired command spellings and stale generation provenance. Regenerate the supported reference kernels with the reviewed LLVM and PTO-Kernel branches, record both exact commits, and remove stale scratch/legacy navigation.

Constraint: Examples must use canonical named TMA/CUBE forms and contain no executable legacy surface
Rejected: Keep historical examples beside current output | repository history already preserves them and active navigation would imply support
Confidence: high
Scope-risk: narrow
Directive: Regenerate these files only from the commits recorded in index.yaml
Tested: translation manifest freshness; repository layout; forbidden executable spelling scan; git diff check
Not-tested: numeric result parity of every example, covered later by the top-level E2E gate
The manual chapter still included pages for retired BSTART.FIXP and B.ARG forms after the generated instruction set correctly deleted them. Remove those includes and describe only canonical scalar, parallel, typed Tile, and TEPL starts.

Constraint: D-class and retired generic command forms must be absent from the active manual
Rejected: Restore placeholder pages for deleted instructions | that would imply executable support
Confidence: high
Scope-risk: narrow
Directive: When generated instruction pages disappear, update chapter includes in the same ISA projection change
Tested: documentation projection check; 728 instruction pages and 67 groups current; all AsciiDoc includes resolve; translation freshness; git diff check
Not-tested: local Asciidoctor render because Bundler 2.4.19 is unavailable; CI Ruby 3.2 render is the authoritative rerun
Record the reviewed 0.57.1 producer, consumer, loader, model, workload, and
skills commits in one superproject baseline. Align the integrated compiler AVS
with raw TEPL Mode/Function syntax, friendly disassembly, and legal frame
vectors so both Linx widths retain truthful 100% mnemonic evidence.

Constraint: PTO ISA 0.57.1 exposes TEPL as Mode[1:0] plus Function[4:0]
Constraint: Final promotion must bind every reviewed leaf SHA in the superproject
Rejected: Lower the coverage threshold | the PR gate requires all 728 architectural mnemonics
Rejected: Count friendly TEPL operations as generic BSTART | that misattributes raw carrier evidence
Confidence: high
Scope-risk: moderate
Directive: Repin any leaf whose PR head advances before final promotion
Directive: Friendly BSTART.T* aliases absent from the spec cover BSTART.TEPL, not BSTART
Tested: python3 -m unittest avs/compiler/linx-llvm/tests/test_analyze_coverage.py (14/14)
Tested: generated-vector FRET.RA/FRET.STK disassembly probe
Tested: compiler-contract linx64 and linx32 (100%/100%)
Tested: leaf-owned gates recorded in the upgrade matrix
Not-tested: final QEMU all-suites and Linux flow remain downstream gates
The generated decoder now preserves retired-encoding traps without creating pathological flow-typing facts, while the executable subset models descriptor preflight, atomic publication, implicit ACC, MX scaling, and the full TMA/CUBE selector surface.

Constraint: PTO-ISA/pto-spec 0.57.1 is the sole normative source.

Rejected: Mark all forms architecturally complete | Sail does not yet carry bit-level Tile payloads or the OCP/HiF numeric oracle.

Confidence: high

Scope-risk: broad

Directive: Keep decode condition aggregation flow-neutral and regenerate decode.sail after encoding changes.

Tested: Sail parser, generated-source freshness, directed suite, coverage/status checks, and C backend through tools/bringup/check_sail_model.py.

Not-tested: Bit-exact OCP and HiF arithmetic remains covered by the QEMU numeric oracle.
The runtime catalog and parity suites no longer advertise or invoke the retired mamulb convenience kernel; coverage remains on the normative TMATMUL operation and guards prevent the alias from returning.

Constraint: The frozen 120-operation PTO 0.57.1 surface contains TMATMUL and no mamulb alias.

Rejected: Preserve mamulb as a compatibility test | Legacy is maintained in repository history and must not remain in the current ISA flow.

Confidence: high

Scope-risk: narrow

Directive: Add runtime kernels only when their direct ISA operation exists in the normative catalog.

Tested: python3 -m unittest avs.qemu.test_run_tests (18 tests).
The superproject now identifies the QEMU TSTORE descriptor fix and the PTO-Kernel THISTOGRAM semantic correction that passed their leaf gates and the fresh QEMU build.

Constraint: Submodule pins must name the exact reviewed PR heads before end-to-end evidence is recorded.

Rejected: Keep the earlier pins until PR merge | The validation branch must exercise the actual final candidates.

Confidence: high

Scope-risk: moderate

Directive: Do not advance either pin independently without rerunning the QEMU and PTO-Kernel parity gates.

Tested: QEMU recursive clean build at 091df5e; PTO-Kernel host build and 11/11 CTests at 06804db; focused AVS Test 0x1701 passes at the unchanged 15-second bound.

Not-tested: Full superproject QEMU and Linux profiles run after this pin commit.
The superproject now exercises QEMU scalar-IOR and width-changing conversion fixes together with PTO-Kernel removal of one-output TSORT and stale scale-handle assumptions found by the fixed-timeout DeepSeek gate.

Constraint: The release branch must pin the exact candidates that pass the runtime hard break.

Rejected: Retain the prior reviewed pins | They trap or miscompute under the final workload flow.

Confidence: high

Scope-risk: broad

Directive: Treat fixed-timeout AVS failures as contract evidence before considering timeout changes.

Tested: PTO-Kernel host 11/11; QEMU transaction 11/11; focused DeepSeek AVS PASS at 10 seconds using the pinned source heads.

Not-tested: Clean recursive QEMU build and full qemu-contract are running after this commit.
Refresh the checked-in opcode, ISA, and executable coverage reports against QEMU 583cad3f6ce68d05a559a354a3e7059844f47a5d and retain the referenced run artifacts so clean-tree CI can independently validate every accepted form.

Constraint: The coverage manifest is only reproducible when its referenced ELF, object, assembly, UART, and PC-watch artifacts are present.

Rejected: Publish reports after pruning generated artifacts | the require-clean reporter then rejects every missing evidence path.

Confidence: high

Scope-risk: narrow

Directive: Regenerate these reports and evidence bundles together whenever the pinned QEMU semantics change.

Tested: report_qemu_executable_coverage.py --require-nonzero --require-clean (L2=60 L3=60 rejected=0); git diff --cached --check

Not-tested: Hosted libc and SPEC2017 runtime gates are executed separately.
Pin the Linux signal-frame UAPI correction and teach the call/return and SPEC runners to consume the explicitly selected external kernel build. This keeps the release flow on one clean vmlinux provenance and avoids accidentally compiling host tools with the Linx target compiler.

Constraint: release verification builds Linux with O= outside the source tree and must not fall back to stale in-tree artifacts.

Rejected: Copy generated host tools into the Linux source tree | that would hide provenance and dirty a submodule.

Confidence: high

Scope-risk: moderate

Directive: Keep SPEC, libc, and call/return audits aligned on LINUX_VMLINUX_OUT_DIR when validating release candidates.

Tested: 76 SPEC runner unit tests; Python compile; bash syntax and shellcheck; external-O call/ret audit; fresh full vmlinux; libc hosted runtime; SPEC2017 static build, attestation, test and train sentinels; full PR source/compiler/QEMU/TSVC report.

Not-tested: Full SPEC2017 refrate workload.
LinxISA Automation added 2 commits July 31, 2026 06:47
Refresh the Chinese translation source hashes after the final QEMU coverage and opcode synchronization evidence changed. The translated files are unchanged; this records the reviewed source revision consumed by the documentation integrity gate.

Constraint: docs/check_documentation.py requires exact source and translation hashes for every tracked Chinese projection.

Confidence: high

Scope-risk: narrow

Directive: Regenerate the translation manifest whenever tracked source documentation changes.

Tested: update_translation_manifest --check; full docs/check_documentation.py; 762 generated SVG freshness checks; 728 instruction pages and 67 group pages.

Not-tested: Browser rendering of the generated site.
@zhoubot
zhoubot marked this pull request as ready for review August 2, 2026 12:55
@zhoubot
zhoubot requested review from a team as code owners August 2, 2026 12:55
@zhoubot
zhoubot requested review from a team as code owners August 2, 2026 12:55
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@zhoubot
zhoubot merged commit 609fd87 into main Aug 2, 2026
5 checks passed
@zhoubot
zhoubot deleted the codex/linx-isa-0.57.1 branch August 2, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant