Multi-HAL provider federation product (BL-75)

July 29, 2026 · View on GitHub

Capability-true federation matrix over ambient hardware/hal_* adapters and backend descriptors. Default no-submit dry-run (BL-47). Never invent-green live submit without an owner ticket; never invent online queue depth.

Module: scpn_quantum_control.multi_hal_federation_product

Rules

RuleBehaviour
Product schemamulti_hal_federation_product.v1
Inventory sourceAmbient list_hal_backend_descriptors + built_in_backend_profiles
Unknown backendFail closed
Dry-runAllowed, no network
Ticketed prepAllowed only with owner ticket
Would-live auto-submitRefused on product surface
Invent-green live submitRefused

Capability fields (per HAL row)

backend_id, provider, broker, adapter_module, modality, supports_shots, supports_mid_circuit_measurement, supports_pulse, supports_statevector, submit_requires_approval, can_submit, is_cloud, ir_formats, max_qubits (None = unknown, not invent-green), no_submit_default=True.

list_hal_backend_ids() and list_hal_providers() return deterministic catalogue-order identifiers. get_hal_capability(backend_id) performs exact lookup after trimming outer whitespace and raises ValueError for blank or unknown ids. iter_hal_capabilities(...) filters independently by provider, support posture, and pulse capability; no matches return an empty tuple.

HalCapabilityRecord is immutable and validates provider, broker, adapter, modality, IR formats, optional qubit bounds, and the no-submit policy. build_federation_matrix() serialises every record without probing a network.

Route decisions

decide_federation_route() returns a PathEligibilityDecision:

ModeResult
dry_runallowed only with network access disabled
ticketed_prepallowed only when an owner ticket is present
would_livealways refused on this product surface

Unknown modes, invent-green live-submit requests, networked dry-runs, missing tickets, and non-submitting backends produce typed blockers. An allowed ticketed preparation is not submission authority and does not contact a HAL.

Offline capability probes

materialise_federation_dry_run_probe() converts catalogue metadata into an offline ProviderCapabilitySnapshot, then applies the ambient capability assessor. Optional IR and minimum-qubit requirements can block the result. Unknown qubit capacity uses a schema-only floor of one and is never presented as measured hardware capacity. Queue depth, calibration time, shots, circuits, and online status remain unknown/offline.

materialise_demo_federation_dry_run_probe() selects the first canonical row. Both probes return immutable records with backend/provider, status, blockers, warnings, no_submit=True, and invent_green_live_submit=False.

Registry and integrity

map_multi_hal_federation_public_surfaces() identifies the product, descriptor inventory, backend profiles, and offline assessor with their roles and policy scope. build_multi_hal_federation_product_registry() combines those surfaces with schemas, counts, providers, matrix rows, and no-submit policy.

assert_multi_hal_federation_product_integrity(payload=None) rejects missing or malformed matrices, blank/duplicate ids, missing provider/adapter/IR data, row-level submission permission, canonical-set drift, inconsistent counts, or unsafe global policies. It returns a shallow validated mapping.

Exported contracts and boundaries

The module exports schema/claim constants, FederationRouteMode, SupportPosture, PathDecisionOutcome, and the three immutable record types. Importing, listing, routing, probing, or building the registry does not open a network connection, query a live queue, submit a workload, consume provider credentials, execute feedback control, mutate HAL profiles, or promote hardware readiness. Those actions remain separately ticketed and evidenced.

Quick start

from scpn_quantum_control.multi_hal_federation_product import (
    assert_multi_hal_federation_product_integrity,
    build_multi_hal_federation_product_registry,
    decide_federation_route,
    list_hal_backend_ids,
    materialise_demo_federation_dry_run_probe,
)

reg = assert_multi_hal_federation_product_integrity(
    build_multi_hal_federation_product_registry()
)
assert reg["no_submit_default_policy"] is True
assert reg["backend_count"] == len(list_hal_backend_ids())

backend = list_hal_backend_ids()[0]
assert decide_federation_route(backend, mode="dry_run").allowed is True
assert decide_federation_route(
    backend, mode="would_live", owner_ticket_present=True
).allowed is False

probe = materialise_demo_federation_dry_run_probe()
assert probe.invent_green_live_submit is False
assert probe.no_submit is True

Residuals (honest)

  • S75.4 — full feedback_* wire under BL-67/47
  • S75.5 — BL-61 competitor-watch version automation
  • Live ticketed submit remains residual (product refuses auto would_live)
  • Pack: docs/internal/differentiable_programming/p3_strategic/bl75_multi_hal_provider_federation.md
  • Ambient: hardware.backends, hardware.hal, provider_capability_core
  • BL-47 hardware-safe execution; BL-52 route matrix; BL-67 control compose

Authored by Anulum Fortis & Arcane Sapience (protoscience@anulum.li)