ADR 0023: Uniform instruction-attempt status and fault isolation
Context
PTO exposes three decoded execution boundaries: scalar, bundle/command, and
direct tile. Each returned an executed or rejected status, but each also read
the shared _LastFault latch without first beginning a new attempt. A fault
from an earlier instruction could therefore make a later valid instruction
report rejection unless its caller invoked ClearFault() manually.
ClearFault() is not the right execution-boundary operation. It clears the
current ACR's visible trap status, cause, arguments, and validity in addition to
the transient model latch. Starting a handler instruction after trap entry must
not erase the architectural record that the manager will inspect.
Decision
- Every public decoded execution boundary begins exactly one architectural
instruction attempt. The boundary clears only
_LastFaultand_FaultAddress, then advances architectural time once. - Beginning an attempt does not modify ACR trap status, cause, arguments, asynchronous state, saved trap context, pending interrupts, or any scalar, bundle, tile, memory, or ordering state.
- Scalar, command, tile, and unified status types are typed projections of the
same two-outcome contract:
Executedmeans the decoded attempt completed without a synchronous architectural fault;Rejectedmeans the attempt raised a synchronous fault, including an unknown encoding, illegal operand or selector, instruction-legality fault, breakpoint/assertion, service request, or runtime access fault.
- A rejected attempt must leave
_LastFaultset to its architectural fault. A successful attempt leaves_LastFault = Fault_Noneand_FaultAddress = 0. - Unknown encodings and pre-effect legality failures may change only the architectural time and synchronous trap envelope. Instruction-specific runtime faults obey their family's defined preflight and rollback contract.
ExecutePTOInstructiondelegates 16-, 32-, and 48-bit attempts to exactly one scalar or command boundary. Its unknown 64-bit path begins the attempt itself. No path may tick twice.ExecuteTileInstructionWithoutTimeis an internal composition boundary. A bundle commit may call it only inside an already-started command attempt; it neither resets the attempt latch nor advances time.ClearFault()remains an explicit manager/test transition for clearing the visible current-ACR trap bank. It is never an implicit instruction prelude.
Consequences
A valid handler instruction is no longer poisoned by the fault that transferred control to it, and inspecting the prior trap remains possible after that instruction executes. Scalar, command, direct tile, and unified execution now have the same success/rejection meaning, one-tick rule, and legality-failure preservation boundary.
The uniform contract does not claim that every instruction-family runtime corner is already closed. Per-form result, alias, access, and rollback evidence remains owned by Stage 4; this decision closes only the shared execution-attempt boundary.