{"aura-ask-grid.af0854de67":"Aura","aura-business-sides.a0853da24b":"Spec sheet","aura-business-visuals.40417391c5":"Aura · resolves","aura-business-visuals.271973aefe":"xMidYMid meet","aura-business-visuals.3e91add48a":"BOARD","aura-showcase.eyebrow":"Dweve platform","aura-showcase.subtitle":"Coding agent and operator assistance. Demo metrics are illustrative.","aura-showcase.pillTools":"25+ tools","aura-showcase.pillRunning":"running","aura-showcase.pillAnalysing":"analysing codebase","aura-showcase.capabilityToolsTitle":"25+ tools","aura-showcase.capabilityToolsBody":"Terminal, search, lint, test, git, and more.","aura-showcase.capabilityMemoryTitle":"Semantic memory","aura-showcase.capabilityMemoryBody":"Remembers your codebase and team context.","aura-showcase.capabilityAgentsTitle":"Multi-agent orchestration","aura-showcase.capabilityAgentsBody":"Specialised agents collaborate across concerns.","aura-showcase.guaranteeAuditTitle":"Audit trail","aura-showcase.guaranteeAuditBody":"Every step is recorded with timestamps.","aura-showcase.guaranteeGuardrailsTitle":"Guardrails","aura-showcase.guaranteeGuardrailsBody":"Policies, checks, and tests always run.","aura-showcase.guaranteeApprovalTitle":"Code changes with approval","aura-showcase.guaranteeApprovalBody":"Review diffs, request changes, final sign-off.","aura-showcase.guaranteeReplayTitle":"Deterministic replay","aura-showcase.guaranteeReplayBody":"Replay any session bit-for-bit when something needs review.","aura-showcase.workflowUnderstand":"Understand","aura-showcase.workflowUnderstandCaption":"Read retry.ts, traced timeout bug","aura-showcase.workflowPlan":"Plan","aura-showcase.workflowPlanCaption":"Extract guard + cap retries","aura-showcase.workflowImplement":"Implement","aura-showcase.workflowImplementCaption":"Patched retry.ts + types.ts","aura-showcase.workflowTest":"Test","aura-showcase.workflowTestCaption":"28 tests, 94% coverage","aura-showcase.workflowVerify":"Verify","aura-showcase.workflowVerifyCaption":"Running lint & typecheck...","aura-showcase.workflowAudit":"Audit","aura-showcase.workflowAuditCaption":"Awaiting summary write-up","aura-showcase.footer":"Autonomous agents that write code and keep receipts","aura-showcase.testsPassing":"passing","aura-showcase.testsFailing":"failing","aura-showcase.modified":"modified","aura-showcase.af0854de67":"Aura","aura-showcase.73989d9c59":"Running","aura-showcase.f9e94338d0":"Analyzing codebase","aura-showcase.d7a484140f":"Workflow","aura-showcase.287fda8114":"Unified","aura-showcase.80e13549b4":"Coverage","aura-showcase.b71cc78b34":"Extracted isRetryableError","aura-showcase.c37a8a9e2b":"to handle\n                    network timeouts, 5xx responses, and idempotent-safe\n                    conditions. Pure helper, fully unit-tested.","aura-tech-middles.7fba7d244f":"Hot path","aura-tech-middles.1be47ef71c":"Cross-cutting","aura-tech-middles.92096d78df":"Ingress","aura-tech-middles.8e05a902ed":"Egress","aura-tech-middles.49a66c994d":"Builtin agents","aura-tech-middles.a60792e996":"Outer loop","aura-tech-middles.0dfd4db698":"Inner loop","aura-tech-middles.bbd88bff92":"Incoming request","aura-tech-middles.a618b4be8d":"Query","aura-tech-middles.a4942c26d0":"SELECT","aura-tech-middles.2cb479aa15":"* FROM","aura-tech-middles.1c255b91e7":"WHERE","aura-tech-middles.2164bde64d":"ORDER BY","aura-tech-middles.82dd2cdf36":"Block","aura-tech-middles.271973aefe":"xMidYMid meet","page-breadcrumb.c766e66518":"Breadcrumb","page-toc.7e439c353e":"On this page","res-forge-action-instrument.089b6f0342":"Triggered by","res-forge-action-instrument.97c89a4d66":"Action","res-forge-ambiguity-board.af13a94202":"is the result, and it is recorded\n          as one.","res-forge-ambiguity-board.e9a46a96e9":"Ambiguous","res-forge-ambiguity-board.1ee9387ca8":"Three ways a person can answer. The search takes none of them on its own.","res-forge-ambiguity-board.f275049b4b":"Which one did you mean?","res-forge-ambiguity-board.e1f6a95de4":"empty sequence","res-forge-ambiguity-board.39f54f4f92":"Input not supplied","res-forge-ambiguity-board.3636a0be7f":"agrees","res-forge-ambiguity-board.140f86aae5":"input","res-forge-ambiguity-board.5a3eea8643":"Every supplied example","res-forge-ambiguity-board.fd50372bde":"The five supplied examples and how both candidates answer them","res-forge-ambiguity-board.86c03753f3":"report the smallest amount in a sequence","res-forge-ambiguity-board.e9c366b4f3":"Requirement","res-forge-ambiguity-board.957a3c6b10":"narrow the domain","res-forge-ambiguity-board.b0567c7519":"add a condition","res-forge-ambiguity-board.7713f29af2":"add an example","res-forge-ambiguity-board.5472c41b95":"reads the empty sequence as outside the permitted input","res-forge-ambiguity-board.2597c3398a":"an error","res-forge-ambiguity-board.9adfc74130":"Candidate 2","res-forge-ambiguity-board.72e8350f75":"reads the empty sequence as having a neutral amount","res-forge-ambiguity-board.170d4a4827":"Candidate 1","res-forge-assurance-ladder.7607387940":"what it does not establish","res-forge-assurance-ladder.204b9b0c88":"what it assumed","res-forge-assurance-ladder.f03d859ccc":"what was checked","res-forge-assurance-ladder.6b3fa46450":"two candidates, two honest stopping points, both reported as they stand","res-forge-assurance-ladder.ed682e5934":"NOT INFERRED FROM Q","res-forge-assurance-ladder.bdad2aeeb8":"Assurance rungs","res-forge-assurance-ladder.9a9f9e5d26":"NO RUNG IS INFERRED","res-forge-assurance-ladder.8259f9a8e2":"formal theory outside the current contract","res-forge-assurance-ladder.4f7ee515f7":"reported as execution linked","res-forge-assurance-ladder.0d9389b742":"Any behaviour on a target the record does not name.","res-forge-assurance-ladder.246b796ef8":"That the recorded identities are the ones the run produced.","res-forge-assurance-ladder.69ded617f9":"graph, plan, artefact and result share one record","res-forge-assurance-ladder.5102f2ad33":"identity bound end to end","res-forge-assurance-ladder.49d89b6ce4":"EXECUTION LINKED","res-forge-assurance-ladder.a1cce5c1a6":"Any property the contract did not encode, and any emitted artefact.","res-forge-assurance-ladder.a7d0feec4e":"The semantics that were encoded and the assumptions the packet pinned.","res-forge-assurance-ladder.fce451ff2c":"the assumptions are pinned and listed","res-forge-assurance-ladder.c830a6c3be":"a proved symbolic property","res-forge-assurance-ladder.da528b9287":"FORMALLY VERIFIED","res-forge-assurance-ladder.d4c1c6915e":"Behaviour beyond the bound, which was never searched.","res-forge-assurance-ladder.99d127dcae":"That the declared domain is the one the result will be used inside.","res-forge-assurance-ladder.d8a8ea038d":"the domain is declared with the claim","res-forge-assurance-ladder.4538c7d77c":"a finite domain, covered","res-forge-assurance-ladder.dfa6e659c8":"BOUNDED CHECKED","res-forge-assurance-ladder.1412ce6f4c":"Behaviour on any input outside the recorded set.","res-forge-assurance-ladder.a1fde5a17c":"That the declared cases represent the behaviour the researcher cares about.","res-forge-assurance-ladder.df4854fc18":"the cases are recorded with the result","res-forge-assurance-ladder.36cba7e6ad":"concrete cases","res-forge-assurance-ladder.b5516f2280":"TESTED","res-forge-assurance-ladder.c0169d217f":"Nothing about behaviour on any input.","res-forge-assurance-ladder.da65feb01c":"Only that the packet named the language the candidate was built from.","res-forge-assurance-ladder.6903a5abc9":"the declared language is closed","res-forge-assurance-ladder.676886a349":"structural validity","res-forge-assurance-ladder.68d222a4f0":"WELL FORMED","res-forge-assurance-ladder.85e08ba525":"That the proof, the graph, the Kera plan and the result identity refer to one another.","res-forge-assurance-ladder.5e68702137":"The supported symbolic property, proved over the encoded semantics.","res-forge-assurance-ladder.9c8a0471a5":"Every value in a finite declared domain, without a failure.","res-forge-assurance-ladder.77345a75bc":"Every concrete case the packet declared, run and compared.","res-forge-assurance-ladder.8c4857d4f9":"Types, shapes, effects, ownership and the declared interface.","res-forge-badge-opened.9a3d81d562":"The badge belongs to one exact program","res-forge-badge-opened.3d1307a7ff":"Back to the plain structural label","res-forge-badge-opened.bac2685fbc":"One step changed","res-forge-badge-opened.aed3b8c6a7":"Verified","res-forge-badge-opened.bf2bc5e115":"The same badge after one step changed","res-forge-badge-opened.d62d8e0dde":"Take any one of these five away and it is a different statement.","res-forge-badge-opened.eb38f1807a":"The badge and the five parts it asserts","res-forge-badge-opened.98987f9e01":"return the result","res-forge-badge-opened.613ac981db":"round it a different way","res-forge-badge-opened.25f1a0d208":"take the reading","res-forge-badge-opened.16b22f5e52":"Says nothing about decimal arithmetic.","res-forge-badge-opened.349be220c7":"A formal result, and a separate check of it.","res-forge-badge-opened.17b29d4546":"Whole numbers only, and nothing outside the program.","res-forge-badge-opened.7d77d99854":"Holds for every whole number in the declared range.","res-forge-badge-opened.7112a3df4e":"This exact program, step for step.","res-forge-boundary-instrument.e29c5de6a0":"One row is shared. Every other responsibility sits on exactly one side of the boundary.","res-forge-boundary-instrument.c6dda4f283":"owned","res-forge-boundary-instrument.d18aac96b9":"shared","res-forge-boundary-instrument.1ac443dbd4":"not owned","res-forge-business-glyph.161d1b9d9a":"One specification","res-forge-business-glyph.ab98f5b857":"Fixed","res-forge-business-glyph.82b6d04b0e":"The requirement that does not move","res-forge-business-glyph.b5bf8067cf":"Candidates","res-forge-business-glyph.7e1d88fa7c":"objective vector","res-forge-business-glyph.45d74a7136":"dominated","res-forge-business-glyph.239aff5852":"on the frontier","res-forge-business-glyph.f476109f39":"ambiguous","res-forge-business-glyph.473161067f":"Selection policy","res-forge-business-glyph.7eff74a5a8":"recorded, not hidden","res-forge-business-glyph.c3b9a01442":"latency","res-forge-business-glyph.b727a735e7":"movement","res-forge-business-glyph.1a7d89d441":"target fit","res-forge-business-glyph.ef64363d23":"proof","res-forge-business-glyph.efe124888c":"assurance named","res-forge-business-glyph.b086634a92":"trade-offs visible","res-forge-business-glyph.ca2bc19088":"Kera executes","res-forge-business-glyph.f735a5ba22":"Research programme, not a software offer","res-forge-candidate-fan.b6871fa0fc":"Silhouettes are structural, not source. Ribbon lengths are relative positions on one\n            frontier.","res-forge-candidate-fan.8641796596":"Candidate E is dominated by candidate D on the active objective set","res-forge-candidate-fan.d769ded7e8":"Candidate","res-forge-candidate-fan.45d74a7136":"dominated","res-forge-candidate-fan.100ec4462d":"evidence","res-forge-candidate-fan.1a7d89d441":"target fit","res-forge-candidate-fan.b727a735e7":"movement","res-forge-candidate-fan.714eea0f4c":"time","res-forge-candidate-fan.73ea3f356f":"Dominated","res-forge-candidate-fan.82f8a46f55":"nested tree","res-forge-candidate-fan.416bfd329b":"On the frontier","res-forge-candidate-fan.00c93cd155":"two lane split","res-forge-candidate-fan.a70e321a36":"compact block","res-forge-candidate-fan.f259a41862":"wide fan","res-forge-candidate-fan.8503665914":"First found","res-forge-candidate-fan.e2a3a58a40":"one long chain","res-forge-choice-board.2f98d2f5be":"Balanced is also a preference, and it is recorded as one.","res-forge-choice-board.ce025222b1":"Every one of these four is correct, so this is a preference and not a ranking.","res-forge-choice-board.48e09e45c5":"Correct","res-forge-choice-board.13f66243ef":"Prefer","res-forge-choice-board.55559438c9":"B gives up the least on any single measure.","res-forge-choice-board.03342dbb85":"Balanced","res-forge-choice-board.3cd298fe82":"D carries the shortest checking path.","res-forge-choice-board.baf123fc17":"Clearest","res-forge-choice-board.58adc98abc":"C runs on the widest set of supported machines.","res-forge-choice-board.b2df292ee2":"Widest","res-forge-choice-board.7987c4ffa8":"B moves the least data, and takes longer to finish.","res-forge-choice-board.4e76f5796f":"Leanest","res-forge-choice-board.cda4a6b217":"A finishes soonest, and holds the most data while it works.","res-forge-choice-board.4cb3bb0fc4":"Fastest","res-forge-choice-board.ed798211fb":"D forgoes one rewrite to stay simple to check.","res-forge-choice-board.2a318223e9":"Program D","res-forge-choice-board.69a71f0df6":"C moves more data to get there.","res-forge-choice-board.d7782ce200":"Program C","res-forge-choice-board.018761680d":"B takes longer to finish.","res-forge-choice-board.d2307ff43a":"Program B","res-forge-choice-board.4c06d2baf8":"A holds the most data while it works.","res-forge-choice-board.2be70eef66":"Program A","res-forge-choice-board.97876b8380":"Checking","res-forge-choice-board.2940ff1e5f":"Machines","res-forge-choice-board.89c8a2851d":"Memory","res-forge-choice-board.6c82e6dd86":"Time","res-forge-choice-instrument.e786244260":"Cost it accepts","res-forge-choice-instrument.fd9a9f965e":"Relative modelled latency","res-forge-choice-instrument.24d3e4fdd9":"Strength","res-forge-choice-instrument.6853c98a6f":"Member","res-forge-conflict-board.0e565b0b3e":"No lane on this board ends with generated fallback code. Each one ends with a named result\n          and the person who owns the next move.","res-forge-conflict-board.bb54db510a":"Accept","res-forge-conflict-board.09c3f0d154":"not represented by the verification contract","res-forge-conflict-board.75e6b42fc5":"Outside scope","res-forge-conflict-board.281dd83602":"Extend","res-forge-conflict-board.8a97b9af81":"theory and budget limit","res-forge-conflict-board.bc7819b34f":"Unknown","res-forge-conflict-board.3e0fb17cab":"Clarify","res-forge-conflict-board.7835f9c578":"rejects the batch","res-forge-conflict-board.9522606498":"returns a neutral total","res-forge-conflict-board.e9a46a96e9":"Ambiguous","res-forge-conflict-board.d36f29cacf":"Reconcile","res-forge-conflict-board.9a064eb243":"no candidate exists in language L","res-forge-conflict-board.5f20d0f3ac":"Unsatisfiable","res-forge-conflict-board.151864867d":"The six clauses of one requirement","res-forge-conflict-board.426475873e":"the result arrives inside a fixed wall clock window","res-forge-conflict-board.6933c35154":"a correcting entry may reduce the total","res-forge-conflict-board.4bf7985a78":"the result is exact to the last unit","res-forge-conflict-board.55dca06fb3":"an empty batch is accepted","res-forge-conflict-board.5b3e0d86e8":"the total never decreases as entries are added","res-forge-conflict-board.33f78f4681":"every amount stays inside the declared range","res-forge-consumer-glyph.9154742cfc":"The job, in one sentence","res-forge-consumer-glyph.b7d5d68aa8":"Keep every reading inside the safe range","res-forge-consumer-glyph.5a29585e3f":"Attempts","res-forge-consumer-glyph.6bd1f59b85":"two fail on a case","res-forge-consumer-glyph.059c3755e1":"two arrive","res-forge-consumer-glyph.d3f5d23e46":"one carries a seal","res-forge-consumer-glyph.6bb9173137":"it searches","res-forge-consumer-glyph.50814a267d":"many possible programs","res-forge-consumer-glyph.64c675f85c":"it rejects","res-forge-consumer-glyph.7403925825":"anything that fails one case","res-forge-consumer-glyph.c1a77ef9ed":"it says how strongly it checked","res-forge-consumer-glyph.691b10181f":"and where the checking stops","res-forge-consumer-glyph.100ec4462d":"evidence","res-forge-consumer-glyph.88acf54a65":"sometimes no program","res-forge-consumer-glyph.72dc433046":"The answer may be no program","res-forge-cost-vector.140b63310c":"Candidate C","res-forge-cost-vector.2437a7ecbd":"Evidence per objective","res-forge-cost-vector.25b7302067":"A comparison that carries across to another experiment packet.","res-forge-cost-vector.26d24d71f0":"Memory traffic","res-forge-cost-vector.3e39972526":"Latency","res-forge-cost-vector.405bdec664":"No measurement exists","res-forge-cost-vector.4b1dda27e1":"What the vector is not","res-forge-cost-vector.555486354d":"Code size","res-forge-cost-vector.5d0b1f6647":"The two lines cross, which is why neither candidate is the answer on its own.","res-forge-cost-vector.66374d941d":"Measured on hardware","res-forge-cost-vector.89a596e251":"The empty cell is the claim: proof complexity was modelled and never measured.","res-forge-cost-vector.8a4da1dcc8":"A place where a model output may stand in for a measurement.","res-forge-cost-vector.ab8dd4df08":"Costlier","res-forge-cost-vector.ac46a8c74c":"Proof complexity","res-forge-cost-vector.ad638eff4a":"Four objectives, two candidates, one experiment","res-forge-cost-vector.b0b01215a0":"Candidate D","res-forge-cost-vector.bf8197e03c":"Relative positions on one experiment, higher is more costly.","res-forge-cost-vector.cd05967fea":"Modelled before any run","res-forge-cost-vector.ec8e6defbf":"A single score the two candidates can be ranked by.","res-forge-cost-vector.f4cfc474fa":"Cheaper","res-forge-counterexample-loop.aca21ce064":"creates a new specification identity","res-forge-counterexample-loop.fb8953469c":"ADD A PRECONDITION","res-forge-counterexample-loop.7e5559029b":"the run continues under the same identity","res-forge-counterexample-loop.89ad46cbd8":"ADD THE CASE","res-forge-counterexample-loop.9001aab10f":"TWO LEGITIMATE ANSWERS TO A FAILURE","res-forge-counterexample-loop.8888c622ac":"what the verifier was asked","res-forge-counterexample-loop.ec6e54733d":"the column never loses a row","res-forge-counterexample-loop.2a117d0937":"EVIDENCE THE NEXT CANDIDATE MUST SATISFY","res-forge-counterexample-loop.da7195483c":"Choose an iteration of the refinement loop","res-forge-counterexample-loop.a0c4d76862":"The third candidate satisfies every recorded obligation. The verifier finds no violating input inside the supported domain and returns a proof with its assumptions listed beside it.","res-forge-counterexample-loop.f4800df8d1":"out","res-forge-counterexample-loop.2c3cbd53a7":"mul","res-forge-counterexample-loop.d052634571":"widen","res-forge-counterexample-loop.c7e42d43b0":"guard","res-forge-counterexample-loop.11f6ad8ec5":"x","res-forge-counterexample-loop.fcdd12a167":"FORMALLY VERIFIED, assumptions listed","res-forge-counterexample-loop.02b8a8db00":"for all x in i32, plus both recorded cases","res-forge-counterexample-loop.30f7f19326":"The second candidate has to satisfy the examples and the overflow case together. It widens the intermediate before multiplying, and the verifier returns a second case the specification had never pinned: an empty input.","res-forge-counterexample-loop.02dc309df7":"CHALLENGED, counterexample found","res-forge-counterexample-loop.9ab3ad07a9":"for all x in i32, plus the recorded case","res-forge-counterexample-loop.47d7508d9a":"The first candidate satisfies the three supplied examples. The verifier searches the whole of i32 and returns one concrete input where the scaled product leaves the declared range.","res-forge-counterexample-loop.ad5fa3b2c6":"for all x in i32","res-forge-counterexample-loop.d1c8b37b24":"x = empty input","res-forge-counterexample-loop.b412089d87":"x = 2147483647, overflow","res-forge-counterexample-loop.1bac5f43a1":"f(120) = 100","res-forge-counterexample-loop.49ed87614a":"f(40) = 40","res-forge-counterexample-loop.14d8b8d361":"f(-9) = 0","res-forge-decision-record.623b533bbb":"nothing on this sheet collapses the four objectives into one number","res-forge-decision-record.d327f7b3ba":"No single rank score","res-forge-decision-record.6a7eee59c0":"Not selected, and why","res-forge-decision-record.3e7c118949":"Selected by","res-forge-decision-record.1918daaba9":"Selected member","res-forge-decision-record.974ff8bb6e":"Objective set","res-forge-decision-record.e38c2194b4":"formally verified","res-forge-decision-record.ea2dfcc9cc":"Assurance threshold","res-forge-decision-record.1ccf5d25df":"Specification","res-forge-decision-record.5a445661ea":"dominated by","res-forge-decision-record.f950982dd0":"Identical under every policy","res-forge-decision-record.e6f8a915dc":"The frontier","res-forge-decision-record.473161067f":"Selection policy","res-forge-decision-record.1a7d89d441":"target fit","res-forge-decision-record.b3c5533e86":"memory movement","res-forge-decision-record.544852fd7a":"simplest proof","res-forge-decision-record.6bf0b2c0d8":"a longer audit path, gaining wider target fit instead","res-forge-decision-record.fdd18306eb":"Member C","res-forge-decision-record.ee96b43256":"a longer audit path, gaining lower movement instead","res-forge-decision-record.1e19ce513c":"Member B","res-forge-decision-record.7ad441b0c0":"a longer audit path than the selected member on the active set","res-forge-decision-record.d04e27e317":"Member A","res-forge-decision-record.fec4a6c489":"A regulated programme reads the same frontier along the evidence axis and takes member D.","res-forge-decision-record.32cba0b9da":"most direct audit path","res-forge-decision-record.f88efb9bc7":"Member D","res-forge-decision-record.47942077ae":"Simplest proof","res-forge-decision-record.e9647ad29d":"runs on fewer supported targets, trading breadth for audit path","res-forge-decision-record.baede38a31":"runs on fewer supported targets, trading breadth for movement","res-forge-decision-record.7b357b2d93":"runs on fewer supported targets than the selected member","res-forge-decision-record.2a6987fbaf":"An estate spread across mixed hardware reads the same frontier along the target axis and takes member C.","res-forge-decision-record.462746df39":"widest target fit","res-forge-decision-record.ad59e3b102":"Broadest","res-forge-decision-record.6235c63244":"moves more data, and keeps a shorter derivation instead","res-forge-decision-record.709e1b623c":"moves more data, spread across more supported targets","res-forge-decision-record.7efb4f14c6":"moves more data than the selected member on the active set","res-forge-decision-record.26929cd71c":"A deployment constrained by memory traffic reads the same frontier along the movement axis and takes member B.","res-forge-decision-record.993033f0b5":"lowest memory movement","res-forge-decision-record.4e76f5796f":"Leanest","res-forge-decision-record.344f41f998":"higher modelled latency, and its shorter audit path is not the axis","res-forge-decision-record.ed3d6e1e77":"higher modelled latency, and its breadth is not being paid for here","res-forge-decision-record.0be3560065":"higher modelled latency than the selected member on the active set","res-forge-decision-record.b8b9888522":"An engineering team with one target machine reads the frontier along the latency axis and takes member A.","res-forge-decision-record.ffefb7fa98":"lowest modelled latency","res-forge-decision-record.4cb3bb0fc4":"Fastest","res-forge-equivalence-space.638d0226a9":"relative positions only, no measured figures","res-forge-equivalence-space.b727a735e7":"movement","res-forge-equivalence-space.e8c39c4d7e":"operations","res-forge-equivalence-space.4619486033":"extracted form","res-forge-equivalence-space.f42512d469":"Extraction target","res-forge-equivalence-space.92149cf8ce":"SEED","res-forge-equivalence-space.217cb1c2eb":"One expression expanded into four classes of equivalent form, with the path to the\n                  selected extraction target lit and one refused edge drawn but never lit","res-forge-equivalence-space.ccce87f620":"An expression expanded into a network of equivalent forms, with conditions on the edges","res-forge-equivalence-space.27fa456ce7":"Extracting for portability takes the strength reduction and the layout change instead. It runs more operations than the algebraic form and reaches the widest set of supported targets.","res-forge-equivalence-space.27d7e452b1":"(a << 1) + a, packed","res-forge-equivalence-space.feba5b9c56":"Extracting for movement carries the same algebraic step on into the fusion class. It runs fewer operations than the layout form and holds the lowest memory movement of the three.","res-forge-equivalence-space.37226e169c":"fuse(a + a + a)","res-forge-equivalence-space.a2f4cd4d38":"Extracting for latency takes the algebraic form and stops there. It runs the fewest operations and moves more data than the fused form, and it is entitled to the width condition that was proved.","res-forge-equivalence-space.4b10d3e274":"3 * a","res-forge-equivalence-space.dfb1d5b6c2":"PORTABILITY","res-forge-equivalence-space.37f756c7d0":"MOVEMENT","res-forge-equivalence-space.49d6c10ece":"LATENCY","res-forge-equivalence-space.8e43c13f74":"f32 reassociation refused","res-forge-equivalence-space.13d2c4a154":"i32 width proved","res-forge-equivalence-space.dcc4e6c574":"LAYOUT CLASS","res-forge-equivalence-space.69688a961b":"FUSION CLASS","res-forge-equivalence-space.16cbdc05fc":"STRENGTH CLASS","res-forge-equivalence-space.dbb0f90765":"ALGEBRAIC CLASS","res-forge-equivalence-space.bc109fb076":"portable","res-forge-equivalence-space.7aca22de0b":"packed","res-forge-equivalence-space.1f08a3216a":"fused","res-forge-equivalence-space.b0c659fe95":"streamed","res-forge-equivalence-space.28e1e451f0":"f32 regroup","res-forge-equivalence-space.231627027e":"(a << 1) + a","res-forge-equivalence-space.62865e04db":"a + a + a","res-forge-equivalence-space.2f65736593":"(a * 2) + a","res-forge-evidence-cards.4a1c00ad00":"Promotion requires evidence, not a control. This affordance is unavailable in every\n              state on this board, which is the rule being drawn.","res-forge-evidence-cards.61c57736e7":"Promote","res-forge-evidence-cards.7d903d3344":"The promotion rule","res-forge-evidence-cards.8fc2a131ae":"one node changed, and the label returns to well formed","res-forge-evidence-cards.4acf3ac41d":"Candidate dossiers","res-forge-evidence-cards.65748fb5d3":"the floating region of the same graph, which this encoding does not represent","res-forge-evidence-cards.d274f5b4e3":"What is not established","res-forge-evidence-cards.8f4f743d7f":"exact integer semantics and a region declared pure by the packet","res-forge-evidence-cards.7d37b7550c":"Under which assumptions","res-forge-evidence-cards.2bae06de12":"every input the formal theory can express","res-forge-evidence-cards.e700afa7f9":"Over which domain","res-forge-evidence-cards.8be740fd8c":"the encoded relation across the whole supported domain","res-forge-evidence-cards.b76e542d96":"What was checked","res-forge-evidence-cards.906c590060":"a supported universal relation was proved under stated assumptions","res-forge-evidence-cards.ea66d3cd71":"Formally verified","res-forge-evidence-cards.b7330133c1":"Candidate R","res-forge-evidence-cards.8e950fc545":"any input outside the supplied set, including the quantified condition","res-forge-evidence-cards.72d0fc35c6":"the reference behaviour supplied with the packet, inside its own domain","res-forge-evidence-cards.2c8e59076b":"the supplied inputs, one at a time","res-forge-evidence-cards.961d36c1e2":"the concrete cases written into the specification","res-forge-evidence-cards.593aeb47dc":"the declared concrete cases passed and nothing beyond them was claimed","res-forge-evidence-cards.919003799d":"Tested","res-forge-evidence-cards.24f43cdd11":"Candidate Q","res-forge-evidence-cards.8af32eb207":"behaviour on a target profile the execution link does not name","res-forge-evidence-cards.d7201bf2e3":"the numerical family and the effects the packet permitted, both pinned","res-forge-evidence-cards.dfaa1686c4":"the declared input range on one supported target profile","res-forge-evidence-cards.707e2a56c9":"the proved relation, then the plan and the artefact that carried it into execution","res-forge-evidence-cards.f092d6fe39":"graph, plan, artefact and result identity stay bound together","res-forge-evidence-cards.32d888fecc":"Execution linked","res-forge-evidence-cards.0483882b1c":"Candidate P","res-forge-experiment-packet.7a6aad1d4c":"new experiment, separate record","res-forge-experiment-packet.aad6b5ae20":"PACKET IDENTITY","res-forge-experiment-packet.bbcc172a1e":"IF ANY FIELD CHANGES","res-forge-experiment-packet.f5ca7850da":"sealed at the start of the run","res-forge-experiment-packet.1f7febf95f":"POLICY DECLARED","res-forge-experiment-packet.39b2c01e18":"LANGUAGE CLOSED","res-forge-experiment-packet.c2bb6fa0c5":"SPECIFICATION IMMUTABLE","res-forge-experiment-packet.4484cb6fa9":"report unknown","res-forge-experiment-packet.feaf4dd4e6":"bound: size <= 6","res-forge-experiment-packet.5aa50aebf7":"formal where supported","res-forge-experiment-packet.31be469709":"POLICY","res-forge-experiment-packet.e1e3e98714":"code size","res-forge-experiment-packet.b3c5533e86":"memory movement","res-forge-experiment-packet.e64e22b150":"OBJECTIVES","res-forge-experiment-packet.48aef70526":"total order fixed","res-forge-experiment-packet.294793bfad":"two's complement, 32 bit","res-forge-experiment-packet.1e9edfb9ee":"SEMANTICS","res-forge-experiment-packet.9c5c96b457":"no external effect","res-forge-experiment-packet.d835dab5b4":"exact integer","res-forge-experiment-packet.2a3ffd9ebb":"LANGUAGE","res-forge-experiment-packet.486c4f6f95":"1 sketch, 2 holes","res-forge-experiment-packet.9254dc6ec8":"1 universal relation","res-forge-experiment-packet.dbeac903da":"4 examples","res-forge-experiment-packet.32082e06e3":"SPECIFICATION","res-forge-forms-instrument.b050566d50":"not at all","res-forge-forms-instrument.d680340c0b":"in part","res-forge-forms-instrument.ad22e7e15b":"settles it","res-forge-forms-instrument.7cb8793606":"does not settle it","res-forge-forms-instrument.ed5a4b874a":"settles it in part","res-forge-four-silences.a2b701e0b3":"No program is produced, and the reason is named.","res-forge-four-silences.5faa59d4bc":"Result","res-forge-four-silences.5647cada0f":"What would change it","res-forge-four-silences.7661e6591f":"What happened","res-forge-four-silences.1189b54fc7":"What was asked","res-forge-four-silences.c648f0b37b":"Four reasons the answer is no program","res-forge-four-silences.2637ce69f5":"THE PROGRAM","res-forge-four-silences.f61fa98a3b":"THE MODEL","res-forge-four-silences.cbbef8ce7e":"OUTSIDE","res-forge-four-silences.ce75fc2aec":"LIMIT GIVEN","res-forge-four-silences.3a339a1749":"RULE 2","res-forge-four-silences.35a7d11e05":"RULE 1","res-forge-four-silences.8cc9c3c016":"Back to what the claim covers","res-forge-four-silences.971c87e299":"Bring the service inside the model, or narrow the claim.","res-forge-four-silences.88868a0c58":"Part of the behaviour rests outside the boundary the checking is able to describe.","res-forge-four-silences.181032c74d":"ask an outside service for the limit","res-forge-four-silences.407dfebcf1":"Back with more room","res-forge-four-silences.97cd9b5795":"A longer run, or a different method.","res-forge-four-silences.33af89d7fc":"The search reached the limit it was given and stopped before settling the question.","res-forge-four-silences.086f7cbb23":"one rule about every supported input","res-forge-four-silences.74864a1ff8":"Back for one decision","res-forge-four-silences.7c78667c01":"Supply one more example.","res-forge-four-silences.fd58916c0c":"Two different behaviours agree on all three examples and disagree on the fourth input.","res-forge-four-silences.96dee44862":"3 gives 9","res-forge-four-silences.9179befc0c":"2 gives 4","res-forge-four-silences.3d47eae588":"1 gives 1","res-forge-four-silences.35f6e4ab6c":"Back to whoever wrote the rules","res-forge-four-silences.5c332290c5":"Relax one of the two rules.","res-forge-four-silences.ece7f203f5":"The two rules meet head on. A negative input cannot satisfy both of them at once.","res-forge-four-silences.b25d65ea16":"return the input unchanged","res-forge-four-silences.a4d3a2c877":"always return a positive number","res-forge-four-silences.20cb7eef2c":"Outside the model","res-forge-four-silences.c439038abe":"Not covered","res-forge-four-silences.04ae6467a0":"No conclusion","res-forge-four-silences.280c5e7fc6":"Two readings","res-forge-four-silences.3fe459f958":"Nothing fits","res-forge-graph-asset.49281c01cf":"assurance returns to well formed","res-forge-graph-asset.670f6bdd9a":"new candidate identity","res-forge-graph-asset.197e419ad3":"NEW GRAPH IDENTITY","res-forge-graph-asset.33dd31d4b3":"CHANGE THE MARKED NODE","res-forge-graph-asset.d7b94d76cf":"ONE NODE, MARKED IN ALL THREE RENDERINGS","res-forge-graph-asset.990742f8b4":"buffers","res-forge-graph-asset.1bdbf6a26d":"clamp, store out","res-forge-graph-asset.e9e90fc64f":"scale, mul, add","res-forge-graph-asset.851967b4a3":"load x, k, lo","res-forge-graph-asset.46599c6b1e":"operator names match the node names","res-forge-graph-asset.59cfc3e2d4":"out = clamp(add(m, lo))","res-forge-graph-asset.c73bb57286":"m = mul(s, k)","res-forge-graph-asset.bdc36b0a67":"s = scale(x)","res-forge-graph-asset.2cef65c1d0":"SAME OBJECT","res-forge-graph-asset.31e8d812fa":"DATAFLOW","res-forge-graph-asset.891bbd450e":"EXPRESSION","res-forge-graph-asset.e7bd56e1ec":"GRAPH","res-forge-graph-asset.30a5d0d91f":"The same semantic graph rendered as a node graph, as an expression and as dataflow,\n              with one node marked in all three renderings and joined by a single rule","res-forge-graph-asset.0be82d1c87":"One semantic graph drawn three ways, as a graph, as an expression and as dataflow, with the clamp node marked in all three","res-forge-graph-asset.da528b9287":"FORMALLY VERIFIED","res-forge-graph-asset.894f6d1562":"GRAPH IDENTITY","res-forge-graph-asset.33daecb09d":"out : i32","res-forge-graph-asset.a4ab4f2116":"clamp","res-forge-graph-asset.58d1bbce29":"add","res-forge-graph-asset.2c3cbd53a7":"mul","res-forge-graph-asset.60020d1b19":"scale","res-forge-graph-asset.cf023c3538":"lo : i32","res-forge-graph-asset.643ea229e1":"k : i32","res-forge-graph-asset.d14f7f166c":"x : i32","res-forge-intent-cards.398168fe2d":"Nothing to check it against","res-forge-intent-cards.f2b3a1f895":"Written straight from the sentence","res-forge-intent-cards.8af3e09e73":"The same sentence answered directly","res-forge-intent-cards.ee3c9325a5":"These can fail, which is the point","res-forge-intent-cards.a014f9c662":"The shape is kept, the gaps are searched.","res-forge-intent-cards.d40fae93b9":"Two gaps","res-forge-intent-cards.32fd056d3d":"Sketch","res-forge-intent-cards.5b6d56b37e":"Checked on every reading the rule can name.","res-forge-intent-cards.43a980aaf8":"reading, the answer stays between 0 and 100, and never moves by more than one\n                  step.","res-forge-intent-cards.d8784ae2ea":"For every","res-forge-intent-cards.57f6dcedb1":"One line","res-forge-intent-cards.78e1790e29":"Rule","res-forge-intent-cards.85ee9e64bf":"Checked on the readings you supplied.","res-forge-intent-cards.ef73fdd1c8":"Four cases","res-forge-intent-cards.eb01bf04c9":"Examples","res-forge-intent-cards.77d979bc52":"Three forms the sentence can take","res-forge-intent-cards.b784f64740":"It separates into three forms, and each one can be checked.","res-forge-intent-cards.6802fdd79e":"What was asked for","res-forge-intent-cards.650c85708e":"missing step","res-forge-intent-cards.d2fb792999":"limit how far it may jump with","res-forge-intent-cards.d2fde1a28f":"hold it inside the range with","res-forge-intent-cards.25f1a0d208":"take the reading","res-forge-intent-cards.94407bb3ee":"“Keep every reading inside the safe range, and never let it jump.”","res-forge-intent-modes-instrument.fd197e80cc":"A form is chosen, not merged. The record keeps which one carried the claim.","res-forge-intent-modes-instrument.a6c44a9033":"Covers","res-forge-intent-modes-instrument.abd6628786":"Three ways to state what a program should do","res-forge-intent-routes.5170330dcc":"Both lanes leave the same requirement. Only one of them is still open at the bottom of the\n          drawing.","res-forge-intent-routes.544852fd7a":"simplest proof","res-forge-intent-routes.3e7c118949":"Selected by","res-forge-intent-routes.9a976fc228":"Selected","res-forge-intent-routes.239aff5852":"on the frontier","res-forge-intent-routes.be601df25e":"Research","res-forge-intent-routes.f577430e54":"new project","res-forge-intent-routes.f6ef754e2d":"Lock-in point","res-forge-intent-routes.7b2d03931b":"Conventional","res-forge-intent-routes.f18b41890d":"behaviour, constraints and risks, written down once","res-forge-intent-routes.e9c366b4f3":"Requirement","res-forge-intent-routes.eb9ceb1149":"counterexample","res-forge-intent-routes.462746df39":"widest target fit","res-forge-intent-routes.120e0af75a":"lowest movement","res-forge-intent-routes.cd3e7bf034":"optimisation project","res-forge-intent-routes.92be6abbc0":"one codebase","res-forge-intent-routes.9732c542fc":"implementation written","res-forge-intent-routes.27df60a6a2":"architecture chosen","res-forge-kera-boundary.1ccf5d25df":"Specification","res-forge-kera-boundary.29a184b65c":"graph","res-forge-kera-boundary.2fa9505626":"artefact","res-forge-kera-boundary.37a5301a88":"result","res-forge-kera-boundary.3bd7b119dd":"every non-dominated member","res-forge-kera-boundary.4aca16af35":"Verification result","res-forge-kera-boundary.61792020d0":"Objective frontier","res-forge-kera-boundary.646e287869":"the proof and its assumptions","res-forge-kera-boundary.6f8f7df48d":"FORGE","res-forge-kera-boundary.700bb94783":"reductions","res-forge-kera-boundary.7bc555991d":"fixed","res-forge-kera-boundary.7c1df38fca":"VERIFIED SEMANTIC GRAPH","res-forge-kera-boundary.807a40a32f":"points back to the graph","res-forge-kera-boundary.8b36233e89":"verified semantic graph plus obligations","res-forge-kera-boundary.8cd3def21e":"no target emitter lives on this side","res-forge-kera-boundary.970c175475":"objective profile","res-forge-kera-boundary.9c31467d05":"Held on this side of the gate","res-forge-kera-boundary.a30f1285d5":"EXECUTION LINK","res-forge-kera-boundary.b727a735e7":"movement","res-forge-kera-boundary.bed97175b0":"plan","res-forge-kera-boundary.c9ff38c8bb":"the pinned research problem","res-forge-kera-boundary.cce55e4309":"order","res-forge-kera-boundary.d4f766efab":"Three holdings, one object crosses","res-forge-kera-boundary.efe0c41bcb":"KERA","res-forge-loop-instrument.1e76c7e5b8":"One counterexample loop, four stages","res-forge-pareto-frontier.e2ee360818":"ADD ENERGY OBJECTIVE","res-forge-pareto-frontier.b0e56d1efe":"the curve is fixed while only the policy changes","res-forge-pareto-frontier.787ca603fd":"the frontier belongs to the objective set","res-forge-pareto-frontier.d0eeccbe8d":"selected by","res-forge-pareto-frontier.173d916846":"energy","res-forge-pareto-frontier.1a7d89d441":"target fit","res-forge-pareto-frontier.b727a735e7":"movement","res-forge-pareto-frontier.c3b9a01442":"latency","res-forge-pareto-frontier.3404b13cac":"objective set","res-forge-pareto-frontier.e38c2194b4":"formally verified","res-forge-pareto-frontier.bf984aca27":"assurance threshold","res-forge-pareto-frontier.03d6a194f4":"specification","res-forge-pareto-frontier.33ca7f61b6":"RETURNS ON ENERGY","res-forge-pareto-frontier.0acbd1c769":"MEMORY MOVEMENT","res-forge-pareto-frontier.4b93d5e7ea":"LATENCY, HIGHER TO THE RIGHT","res-forge-pareto-frontier.43bf415954":"A trade-off plot of latency against memory movement, with target fit drawn as marker\n                size, four non-dominated members joined by the frontier curve, and seven dominated\n                candidates each joined to the member that dominates it","res-forge-pareto-frontier.f2b023979d":"xMinYMid meet","res-forge-pareto-frontier.473161067f":"Selection policy","res-forge-pareto-frontier.7c1e368123":"The balanced knee policy also selects candidate C, by a different argument: it is the point where giving up more latency stops buying much movement. Two policies choosing the same member is a fact about this frontier, and the record still names which policy chose it.","res-forge-pareto-frontier.b7aedb3b70":"The simplest proof policy selects candidate D. It forgoes one aggressive rewrite, so its verification obligation is the smallest of the four.","res-forge-pareto-frontier.5614e2e73d":"The least movement policy selects candidate B. It has the longest critical path of the four, which is the price of moving the least data.","res-forge-pareto-frontier.14826696ec":"The fastest policy selects candidate A. It holds the largest working set on the frontier, and the record keeps that alongside the selection rather than hiding it inside a score.","res-forge-pareto-frontier.c65681bb2d":"target fit: widest","res-forge-pareto-frontier.b097d0ac54":"movement: middling","res-forge-pareto-frontier.05da02c2f2":"latency: middling","res-forge-pareto-frontier.d0b64e1eec":"target fit: middling","res-forge-pareto-frontier.144e5e5e83":"movement: lower","res-forge-pareto-frontier.aa828b0585":"latency: higher","res-forge-pareto-frontier.e3a088e260":"target fit: narrow","res-forge-pareto-frontier.6fc0d51b39":"movement: lowest","res-forge-pareto-frontier.1b565dbd5d":"latency: highest","res-forge-pareto-frontier.79c0f24c30":"movement: highest","res-forge-pareto-frontier.83504b708a":"latency: lowest","res-forge-pareto-frontier.37671e6ba6":"Balanced knee","res-forge-pareto-frontier.47942077ae":"Simplest proof","res-forge-pareto-frontier.8703111807":"Widest target","res-forge-pareto-frontier.0b2147fd0a":"Least movement","res-forge-pareto-frontier.4cb3bb0fc4":"Fastest","res-forge-pareto-frontier.7e6396c2ce":"The widest target policy selects candidate C. It runs on the broadest set of supported targets, and it sits between the two extremes on both plotted axes.","res-forge-programme-boundary.97af50dd3d":"The gate crosses the three published rings and stops at the core boundary. The outer three\n          can be scrutinised without opening the innermost.","res-forge-programme-boundary.9ba1f67469":"A research programme, not a software offer","res-forge-programme-boundary.f72e361ba7":"Publication control","res-forge-programme-boundary.108e9b7f90":"held as research method","res-forge-programme-boundary.88306943fe":"Method","res-forge-programme-boundary.68836c550e":"Core","res-forge-programme-boundary.175267da12":"theory routing","res-forge-programme-boundary.15e58bec8d":"budget allocation","res-forge-programme-boundary.b32f31d61d":"frontier position","res-forge-programme-boundary.6f3c47977c":"scoped measurement","res-forge-programme-boundary.ff7fc62f3f":"assurance state","res-forge-programme-boundary.500aadccf6":"selected candidate","res-forge-programme-boundary.5faa59d4bc":"Result","res-forge-programme-boundary.6840659e94":"treatment of unknown","res-forge-programme-boundary.3404b13cac":"objective set","res-forge-programme-boundary.78a3386c55":"resource limit","res-forge-programme-boundary.90f54b8f1b":"permitted language","res-forge-programme-boundary.c445f7aab5":"specification corpus","res-forge-programme-boundary.1ed77c3f7f":"Protocol","res-forge-programme-boundary.aba4559466":"prior art named","res-forge-programme-boundary.0c447c79ec":"research question","res-forge-programme-boundary.002ff59811":"Question","res-forge-programme-instrument.a725020675":"State","res-forge-programme-instrument.dc4e08a408":"Claim","res-forge-proof-parts-instrument.ba3fef96ae":"A proof in five parts","res-forge-provenance-chain.040c236a24":"four of nine nodes, and no sealed step among them","res-forge-provenance-chain.0ca6a997b6":"WHAT A REPLAY HAS TO REPRODUCE","res-forge-provenance-chain.7c0a292070":"A BRAND DOT MARKS A NODE THE REPLAY LANE HAS TO TOUCH","res-forge-provenance-chain.763ad25abd":"seal r:1c62e08","res-forge-provenance-chain.da528b9287":"FORMALLY VERIFIED","res-forge-provenance-chain.9106ca2738":"SELECTED","res-forge-provenance-chain.416eb4fbb0":"frontier","res-forge-provenance-chain.8e016346a6":"EQUIVALENCE CLASS","res-forge-provenance-chain.97d9eb838e":"cx 2","res-forge-provenance-chain.21fedfd21e":"candidate 2","res-forge-provenance-chain.2ce3ff82d2":"out: candidate 2","res-forge-provenance-chain.656b15a358":"in: candidate 1 plus cx 1","res-forge-provenance-chain.a65edb573d":"RESEARCH STEP","res-forge-provenance-chain.b0b7ba4666":"PRIVATE","res-forge-provenance-chain.6495ecf841":"cx 1","res-forge-provenance-chain.7312546346":"candidate 1","res-forge-provenance-chain.32082e06e3":"SPECIFICATION","res-forge-provenance-chain.4ee56d08c0":"A left to right derivation graph: specification, two candidates, two counterexamples,\n              one sealed internal step, an equivalence class, a frontier and the selected verified\n              result","res-forge-provenance-chain.e259f512bc":"A derivation graph from the specification to the selected verified candidate, with one internal step sealed but connected","res-forge-provenance-chain.191f8b1087":"EXECUTION BINDING","res-forge-provenance-chain.88be68d35d":"VERIFICATION RESULT","res-forge-provenance-chain.bdd7fdaa13":"CANDIDATE 2","res-forge-provenance-chain.608c5b40ac":"SPECIFICATION v1","res-forge-record-timeline.0794c4ea35":"Decision taken","res-forge-record-timeline.0f9c9e32f9":"A version, never a branch name","res-forge-record-timeline.314d8e79c0":"Why was candidate B not chosen?","res-forge-record-timeline.39ab49c337":"The exact failing input, kept for good","res-forge-record-timeline.4868056615":"Nothing on this line was recovered from commit messages.","res-forge-record-timeline.4bd9342a8a":"Three entries answer that, and none of them has to be reconstructed.","res-forge-record-timeline.59d432b5cb":"Alternatives compared","res-forge-record-timeline.6546ec1158":"A reviewer arrives long afterwards","res-forge-record-timeline.6833948a23":"Written at the time","res-forge-record-timeline.7d1e2e97e8":"Requirement stated","res-forge-record-timeline.90726e413a":"Answers the question","res-forge-record-timeline.aaddcdd4a5":"Research method, sealed","res-forge-record-timeline.ccf3d548fe":"Read back","res-forge-record-timeline.de805f67e3":"Five candidates, one dominance relation","res-forge-record-timeline.e4a8371aea":"The record, read left to right","res-forge-record-timeline.e8412cdd3e":"The policy, and the authority behind it","res-forge-record-timeline.eeb026e98f":"Counterexample recorded","res-forge-record-timeline.f4452aa131":"The rung, and the scope that rung covers","res-forge-record-timeline.f65fb0cd45":"Assurance reached","res-forge-search-field.f6d08e6875":"Relative lengths, not counts","res-forge-search-field.e9fd9a1eaa":"What is in the field","res-forge-search-field.fbd8250bed":"UNCHANGED FOR THE WHOLE RUN","res-forge-search-field.6a38722b12":"THE REQUIREMENT","res-forge-search-field.dbd3e24a6c":"A field of candidate program shapes in three states around one fixed requirement frame at the centre","res-forge-search-field.0c596f1034":"xMidYMid slice","res-forge-search-field.7be0fdc4e0":"Built, then caught","res-forge-search-field.9545c5f30a":"Failed a case","res-forge-search-field.e247bbc42c":"Never built at all","res-forge-search-field.3d7da15c51":"Refused by type","res-forge-search-field.70c98ed3c6":"Allowed to be checked","res-forge-search-field.35633f30dd":"Fits the rules","res-forge-search-field.50c026300b":"Admitted","res-forge-silence-instrument.3bc40f4b2a":"Four results that come back without a program","res-forge-size-lattice.a82ce62110":"WIDER LANGUAGE, NEW EXPERIMENT","res-forge-size-lattice.74ed41aa02":"MINIMAL WITHIN LANGUAGE L, AT SIZE 5 OR FEWER","res-forge-size-lattice.4ca63f9c2e":"NOT SEARCHED, NOT CLAIMED","res-forge-size-lattice.b79d0fac18":"DECLARED BOUND","res-forge-size-lattice.5e265fa4aa":"FIRST VERIFIED","res-forge-size-lattice.92664d7dff":"observation, not proof","res-forge-size-lattice.950b23b925":"collapsed as an observed duplicate","res-forge-size-lattice.a615e7ad1a":"refused by type, before evaluation","res-forge-size-lattice.6f389bc568":"admitted","res-forge-specification-desk.65d9989d71":"EVIDENCE FORMS ARE NOT INTERCHANGEABLE","res-forge-specification-desk.166b5a63b2":"passes all four examples","res-forge-specification-desk.26a9ba5602":"x = -9","res-forge-specification-desk.5099050f90":"THE CASE THAT SEPARATES THEM","res-forge-specification-desk.561f36ce2f":"an executable answer, with its own limits","res-forge-specification-desk.ca24d384c1":"domain of the oracle: 0 to 100 only","res-forge-specification-desk.3cee30a3ad":"REFERENCE","res-forge-specification-desk.0d99250013":"structure fixed, two typed holes open","res-forge-specification-desk.c1dc5611bb":"return clamp(t,","res-forge-specification-desk.2e5baed7cb":"let t =","res-forge-specification-desk.b3274ca07a":"let s = scale(x)","res-forge-specification-desk.ebdeb573df":"SKETCH","res-forge-specification-desk.c597bbdbc1":"every input the theory can express","res-forge-specification-desk.15ac2f23db":"for all x in the supported domain:","res-forge-specification-desk.61ed10966f":"CONSTRAINTS","res-forge-specification-desk.0ec3e255af":"four cases, checked exactly","res-forge-specification-desk.9659699670":"EXAMPLES","res-forge-specification-desk.191f4bd034":"clamp a scaled value into a declared range","res-forge-specification-desk.4ad49a4ec4":"ONE TRANSFORMATION","res-forge-specification-desk.d9b48caf78":"violates monotonicity outside the oracle's domain","res-forge-stack-path.4d5fa1b006":"Each system reads the same object rather than a copy of it, which is what keeps the\n          specification, the proof, the plan and the result on one identity.","res-forge-stack-path.86506efb99":"the result identity returns to the graph identity it started from","res-forge-stack-path.c83a5945cb":"where the program keeps verified state","res-forge-stack-path.55561848ab":"Aion","res-forge-stack-path.17ed2b5e88":"where a model of the physical system is part of the specification","res-forge-stack-path.1699ca16fb":"FMI and Twin","res-forge-stack-path.d5f412e831":"Kera","res-forge-stack-path.3ab11b75ca":"Forge","res-forge-stack-path.11e7686a81":"Graph identity","res-forge-stack-path.8e246a1e8d":"No target emitter appears on the Forge plate.","res-forge-technical-glyph.be601df25e":"Research","res-forge-technical-glyph.91a9d5d08f":"Specification immutable","res-forge-technical-glyph.c2237a2d15":"Experiment packet","res-forge-technical-glyph.03d6a194f4":"specification","res-forge-technical-glyph.e11523c5ff":"language","res-forge-technical-glyph.7b7f9366a3":"objectives","res-forge-technical-glyph.f3753f1b6b":"assurance","res-forge-technical-glyph.9d78bc179c":"typed graph region","res-forge-technical-glyph.2b90fe2fea":"time, movement, size","res-forge-technical-glyph.a8a172a738":"challenged","res-forge-technical-glyph.e1d96de67b":"Candidate pool","res-forge-technical-glyph.6f389bc568":"admitted","res-forge-technical-glyph.a503bc1da2":"refused","res-forge-technical-glyph.880949479a":"tested","res-forge-technical-glyph.ec734b6515":"verified","res-forge-technical-glyph.61792020d0":"Objective frontier","res-forge-technical-glyph.096280facb":"one selected","res-forge-technical-glyph.9985d73a38":"Assurance ladder","res-forge-technical-glyph.83ced341c8":"well formed","res-forge-technical-glyph.e38c2194b4":"formally verified","res-forge-technical-glyph.275ed0c2c7":"execution linked","res-forge-technical-glyph.49794a5e29":"Selected candidate","res-forge-technical-glyph.9e955c5620":"counterexamples retained","res-forge-technical-glyph.74ef6c0061":"Handoff to Kera","res-forge-technical-glyph.bed97175b0":"plan","res-forge-technical-glyph.37a5301a88":"result","res-forge-technical-glyph.96a6bf1d97":"verified graph","res-forge-technical-glyph.b8d8aaff0a":"evidence attached","res-forge-technical-glyph.100ec4462d":"evidence","res-forge-technical-glyph.416eb4fbb0":"frontier","res-forge-technical-glyph.dd4fb84f32":"unknown is a result","res-forge-technical-glyph.3137db7c8b":"Unknown, unsatisfiable and ambiguous are results","res-forge-technical-glyph.d5f412e831":"Kera","res-forge-technical-glyph.00f6d27f5f":"DWEVE FORGE","res-forge-three-tries.ca6f569d32":"Nothing is ever removed from the list on the left","res-forge-three-tries.48fce8a80b":"Three attempts at the same problem","res-forge-three-tries.8805376577":"Round 3 carries everything the first two rounds found, and one case more.","res-forge-three-tries.da17ea9bb5":"The case list, round by round","res-forge-three-tries.8cc87a2190":"nothing to add","res-forge-three-tries.36d5623704":"and then proved","res-forge-three-tries.0f0b41cfe8":"Passed every case","res-forge-three-tries.1e35a52de1":"Attempt 3","res-forge-three-tries.3b26ea5e3d":"an empty list","res-forge-three-tries.b8575badd2":"on an empty list","res-forge-three-tries.09fef5d8d9":"Failed","res-forge-three-tries.969a17cecc":"Attempt 2","res-forge-three-tries.15d3c90fb9":"the largest possible number","res-forge-three-tries.f88b9a4765":"on the largest possible number","res-forge-three-tries.ff31d219ef":"Attempt 1","res-forge-three-tries.f65e38d46b":"a list with one item","res-forge-three-tries.e8741ca2e3":"a list already in order","res-forge-three-tries.9450ac4e17":"a short list","res-forge-three-tries.4d944a9d7e":"Round 3","res-forge-three-tries.fa2b87ffe2":"Round 2","res-forge-three-tries.f7648d3834":"Round 1","res-forge-type-sockets.13fff86afe":"Two operations, one join","res-forge-type-sockets.2251b5f821":"Unbounded integers","res-forge-type-sockets.338ce27565":"Three compositions offered to one typed language","res-forge-type-sockets.3d7da15c51":"Refused by type","res-forge-type-sockets.50c026300b":"Admitted","res-forge-type-sockets.5e5da2cd3c":"Network access","res-forge-type-sockets.681bcaf5e4":"A refusal on this board costs nothing, because nothing on it has been evaluated yet.","res-forge-type-sockets.7303a0d112":"Refused by capability","res-forge-type-sockets.73841deb9d":"Closed for this run","res-forge-type-sockets.76123e0c4c":"The second operation needs a capability the packet did not grant, so it is outside the search space.","res-forge-type-sockets.93c6a1f183":"Socket","res-forge-type-sockets.a1369155ac":"File access","res-forge-type-sockets.b4ae90c7f4":"The two sockets do not meet, so no candidate is ever assembled from this pair.","res-forge-type-sockets.b957ab83e5":"The output type meets the input type, so the candidate is assembled and can be evaluated.","res-forge-type-sockets.c7303935a3":"Unchecked aliasing","res-forge-type-sockets.d3f0610632":"Outcome","res-forge-type-sockets.dbe18d2e48":"The language is chosen with the packet and does not widen while the search runs.","res-forge-type-sockets.eb8606da6a":"Offered composition","research-forge.00274e0e63":"refused, error contract","research-forge.002ff59811":"Question","research-forge.005a8c4891":"Bring domain intent, formal methods, hardware measurement or independent review. Forge supplies a shared research object for comparing program discovery, proof and execution.","research-forge.008fef2a92":"Search inside the operations that were permitted.","research-forge.01038388dc":"Non-answers stay visible","research-forge.0109e7127b":"IMPOSSIBLE","research-forge.0143790011":"planning and execution","research-forge.019d4e8e82":"What stays true","research-forge.01f66c63e3":"Two of the pairs cannot be assembled, and the language is what says so.","research-forge.01fc285874":"Responsibilities against Forge and Kera","research-forge.02ff5bf386":"Policy review","research-forge.0303c4bacd":"five fields fixed before the first candidate","research-forge.030afc5361":"Forge can preserve the requirement version, the candidates that mattered, the counterexamples, the assurance transitions, the objective frontier and the policy that selected one member. Two years later the record still answers the question a reviewer actually asks, which is not what was built but why the alternatives were rejected. The trail runs in one direction and every step on it can be walked back up: the requirement that defined success, the verified and rejected candidates that mattered, the counterexamples and assurance transitions, the objective values that placed each candidate on the frontier, and the authority that selected one of them. None of that lives beside the decision. It travels with it.","research-forge.03102018f1":"The candidate is structurally valid.","research-forge.03128bed90":"Verification","research-forge.0393c06f67":"CANDIDATE","research-forge.0397a076c3":"Adding a precondition is a legitimate move, and it creates a new specification identity rather than editing the old one. The earlier experiment stays in the record with its failure attached. The research community calls the general propose, challenge, refine pattern CEGIS.","research-forge.03bec6ab74":"Three forms","research-forge.04126cee0d":"The four meet in the middle, so moving towards one of them usually costs something on another.","research-forge.0428abce3e":"Bounded checked","research-forge.0432a371aa":"Assurance policy","research-forge.04731f0ef3":"One axis only, relative modelled latency. Bar length is not an overall ranking.","research-forge.04ae6467a0":"No conclusion","research-forge.04bf9ee3c6":"not left out of the account","research-forge.04e9b5cd14":"many derivations coexist here","research-forge.04fa443e7b":"Longest critical path","research-forge.05005f366c":"Forge research","research-forge.05625954d2":"however the search goes","research-forge.05d1c23f1f":"failure narrows the search","research-forge.05db5a7f8a":"The specification version every candidate had to meet","research-forge.065d4a5b25":"All of them produce the same kind of typed candidate and enter the same comparison. The organisation therefore compares programs rather than search methods, and the method that found a candidate gives it no advantage in the decision.","research-forge.07a688568e":"Target artefact","research-forge.0820b32b20":"Testing","research-forge.08b22e1ba0":"One contract","research-forge.08cfb3e0f2":"Specification review","research-forge.09496b01f9":"Handoff","research-forge.09a3354e63":"Side conditions","research-forge.09d053226c":"Follow one search","research-forge.0a3eb3abd3":"Internal calibration","research-forge.0a5e7a0583":"Boundary","research-forge.0a799711ad":"Normalising saves search","research-forge.0ab39d71e2":"Equivalence","research-forge.0ade2ace0d":"Each counterexample","research-forge.0ae18773cb":"A research assistant","research-forge.0b101a23a3":"Associative regroup","research-forge.0b81fbebb5":"Optimisation later","research-forge.0ba4e46484":"One graph","research-forge.0bc357c912":"NOT COVERED","research-forge.0c19b6603f":"A future reviewer revisits the decision from the record rather than reconstructing it from commit messages.","research-forge.0c6c9b91c5":"You know that feeling when a task might have a simpler implementation? Forge turns that question into a research workflow: give it a bounded specification, search candidate programs, and record the checks and measurements. The 2025 report documents an experiment, not a production-ready result or published benchmark.","research-forge.0d358c9749":"Two tests, two strengths","research-forge.0db809cc66":"Assurance","research-forge.0e26aaf414":"Model review","research-forge.0e3c434842":"Tested, bounded, proved","research-forge.0ef3858209":"Bounded checks recorded","research-forge.0f1e49f0bf":"Examples constrain behaviour on the inputs you supply. Logical conditions constrain every input the formal theory can express. A sketch preserves an architecture a researcher is not willing to hand to the search and leaves typed holes inside it. Reference behaviour supplies an executable oracle and carries the oracle's own domain with it. Forge records which form supported each conclusion instead of treating every input as a specification of equal strength.","research-forge.109bff6e75":"The specification, not the codebase","research-forge.1178a4ffb4":"Search again","research-forge.1181c3f399":"The packet also states when to stop: the resource bound, the assurance threshold a candidate must reach to enter the frontier, and what the run reports when nothing reaches it. A search that ends without a program still ends with a result.","research-forge.11c14ce16a":"The organisation then owns the intent rather than one expression of it, and can say why a particular implementation was chosen. The requirement becomes the durable asset and the implementation becomes a result it can recompute when the priorities change.","research-forge.11dd823248":"For this input, produce this output.","research-forge.12c8d914cc":"What the result does not establish.","research-forge.13792d7c2a":"PROOF HAS A BOUNDARY","research-forge.140b63310c":"Candidate C","research-forge.1462811ad5":"a candidate that looks convincing","research-forge.151978bff3":"the record names the specification, the threshold and the policy every time","research-forge.15c2d33108":"Research integration under evaluation","research-forge.15f1b08e56":"a proof, a bound or a stated limit","research-forge.16181ed76f":"Permitted operations, types, effects and numerical semantics","research-forge.161fa759f7":"In a finite declared language, search can build candidates by increasing size and refuse invalid compositions before any of them run. Candidates that behave identically on the current evidence can be collapsed to save work, while the equivalence claim itself waits for verification. When the method covers every well formed candidate up to the stated bound, the first verified program establishes size minimality inside that language and that bound. Widening the operation set produces a different experiment with its own answer.","research-forge.169f619e4f":"The honest badge carries its boundary, and the boundary is the most useful part of it.","research-forge.16a3fa00e3":"The supported symbolic property was proved under stated assumptions.","research-forge.16ec74fc0a":"CLEAR","research-forge.171ca0385a":"Behaviour","research-forge.173315f506":"no lane on this board ends with generated fallback code","research-forge.17405ade0e":"Assurance with a scope","research-forge.17a86caa5b":"Obligation","research-forge.17b8b28e9e":"never treated as interchangeable","research-forge.17ecf461a5":"The problem is satisfiable","research-forge.1822a38ec8":"four reasons to keep searching","research-forge.189ee02d36":"Honest non-delivery","research-forge.18d60fce22":"Named assurance rung and its scope","research-forge.18dd2ccb59":"Five parts","research-forge.18e9128279":"Naming the outcome keeps the problem where it belongs. Contradictory requirements go back to whoever wrote them. An unclear case goes back for a decision. An unsettled search goes back with a larger budget or a different method.","research-forge.18f906f6da":"Kept forever","research-forge.192ad837e6":"A recorded policy, not a hidden score","research-forge.19626a1e65":"Anything that fails one case","research-forge.1a23a7cddc":"Forge finds","research-forge.1a66b5eeb6":"Partner access","research-forge.1bb360f468":"Bounded","research-forge.1bb90c04d2":"A failure that produces a concrete input is worth more to the search than a failure that produces a score.","research-forge.1bf39cee63":"Faster, smaller, leaner","research-forge.1bff62bf9b":"The method ran out of room. A different method or a longer run may settle it.","research-forge.1c013851a3":"What the record holds","research-forge.1c56ea452a":"Four specification cards describing the same small transformation, with the single case where two of them disagree","research-forge.1c56fd19d7":"One open case","research-forge.1c82340479":"the claim can be scrutinised","research-forge.1c875de71f":"That is a governance property as much as a technical one. The moment where two readings of a requirement diverge is exactly where a stakeholder decision belongs, and it is far cheaper before an implementation has been built around one of them.","research-forge.1c9bbc4b77":"Keep the alternatives until the policy is written down.","research-forge.1cb61a389f":"a changed field is a new experiment, not a corrected one","research-forge.1ccf5d25df":"Specification","research-forge.1cdd46cd0e":"Read research","research-forge.1d17812687":"Four inputs, four different guarantees","research-forge.1d2c6fe888":"all five, or none","research-forge.1d444e826a":"Kera runs","research-forge.1d9b3bd5d3":"Lowest latency","research-forge.1d9d3e69fa":"Rust, C, Verilog","research-forge.1e269ebac7":"One transformation","research-forge.1e748c3e4b":"change a node and you have a new candidate, with the proof binding following the node","research-forge.1ecdc691a8":"the greyed route produces something readable, and nothing to check it against","research-forge.1ed77c3f7f":"Protocol","research-forge.1fd9da00a7":"The policy and the authority that selected one candidate.","research-forge.2030fae2a7":"Three ways to say it","research-forge.2040757c11":"Cranelift, native perf measurement","research-forge.2041447f84":"search only","research-forge.206009c4a7":"Five policies","research-forge.20cb7eef2c":"Outside the model","research-forge.2154ca1eb7":"Each of those is a result with a different next step. Forge records the strongest state it can justify and names what would have to change to move past it.","research-forge.21a0ffd68c":"the open questions are on the page","research-forge.21efbc283d":"Speed, memory, reach and evidence","research-forge.220b9c622c":"Synthesise","research-forge.2354ab0ba0":"before proposing a program","research-forge.235bfff3a2":"A research programme","research-forge.236656bf91":"Powers","research-forge.23d4ef785c":"size 5","research-forge.243dcbef8c":"planning and emission beneath","research-forge.24a264b83c":"Two candidates, four objectives","research-forge.24c0bda2ba":"Most direct audit path","research-forge.24cb5be0b0":"the decision keeps its reasons","research-forge.24d50592b7":"Objectives","research-forge.2550b1dcad":"Responsibility","research-forge.25754f1c93":"a research programme, not a software offer","research-forge.258195bb3d":"One identity","research-forge.25c843b80e":"That makes the language two things at once. It is an efficiency mechanism, because most of the space never has to be evaluated at all. It is also the boundary around intent, because it states in advance what the machine is permitted to reach for.","research-forge.25fa97aa1a":"It does not tell you whether that route is the fastest, the leanest, the most portable, the easiest to audit or the one the organisation can operate. Those are separate questions with separate evidence.","research-forge.261c22b85c":"An engineering organisation usually commits to one implementation long before it can tell whether that design is the fastest or the easiest to verify. Forge studies a sequence where the specification is the durable asset and the implementation is a search result that a stated policy chooses between.","research-forge.26369471c9":"Exact equivalence, a bounded numerical relation or effect equivalence, each established by verification.","research-forge.267f81bab8":"What the program is allowed to touch","research-forge.277b67c1e8":"and what it would need","research-forge.27f11f9fe1":"a sealed node still publishes its inputs, its outputs and its identity","research-forge.27fab35201":"A named non-answer is more useful than a plausible program.","research-forge.280c5e7fc6":"Two readings","research-forge.281dd83602":"Extend","research-forge.282bd862f4":"Candidate B","research-forge.2877a09f30":"several answers can be reasonable","research-forge.287b80caae":"correctness does not choose","research-forge.294b4c06ac":"The candidate space","research-forge.296e71a0fb":"Candidates by size in a bounded language, showing admitted, refused and collapsed states, the first verified candidate, and the declared bound the claim carries","research-forge.297f419e18":"What it may not do is weaken the behaviour, add an effect the packet did not declare, or turn an unresolved proof state into a success. Optimisation is freedom inside a boundary.","research-forge.29c69b4a35":"or easier to check","research-forge.29fea3a06d":"What it establishes","research-forge.2a03a4b73a":"Undecided","research-forge.2a729227ad":"One expression expanded into a network of equivalent forms with conditions on the edges, and three extraction targets chosen after the space exists","research-forge.2a965a37b7":"That is a policy decision and it has to be stated, not inferred.","research-forge.2a965accf1":"The smallest program the language allows","research-forge.2ad40f7952":"Trade-offs as a governance object","research-forge.2b27b7aec8":"Evidence led","research-forge.2b3a5e307c":"Semantic","research-forge.2b7d95b8c6":"Which trade-off you want","research-forge.2b9c801e9e":"selection stays an explicit policy","research-forge.2bdb5e4d73":"Forge ends with a selected semantic graph and its evidence. Dweve Kera receives that graph, plans supported execution and emits the target artefact, with operation meaning, effects, ownership, numerical contract and proof obligations attached across the handoff. The same discipline connects Forge to the rest of the Dweve stack: Aion where the program keeps verified state, Reed and Selvedge for the surrounding systems work, FMI and Twin where a model of the physical system is part of the specification.","research-forge.2c8c94c95f":"not just what was built","research-forge.2c9ebecf8b":"Search orchestration","research-forge.2cb597863b":"A fast program that is wrong is still wrong.","research-forge.2cd3174fc9":"the result decides the next question","research-forge.2cff331976":"Discovery and proof above","research-forge.2d24e0a549":"And sometimes","research-forge.2d3231ce48":"Ambiguity","research-forge.2da600bf94":"Version","research-forge.2daa013c1b":"A typed semantic graph, not source text","research-forge.2dd3547872":"complete in bound","research-forge.2dfcf898a3":"Comparison","research-forge.2e140f6f42":"Policy selection","research-forge.2ea3bb9377":"Join research partners","research-forge.2f24ebaee0":"Prune","research-forge.2f65736593":"(a * 2) + a","research-forge.2f81a22de0":"Access","research-forge.2f89346f05":"Floating reassociation","research-forge.2f906454d9":"Each form answers a different question, and the research record says which one carried the claim.","research-forge.30833f759b":"Planning and lowering","research-forge.3107902192":"Five candidates","research-forge.310e8151df":"from a description to the evidence","research-forge.31139f400a":"minimal <= 5","research-forge.3146c89579":"which responsibility sits on which side","research-forge.3179a54130":"Examples, rules and a partial program, not the steps","research-forge.31c2157a1c":"A single semantic graph shown as a graph, as an expression and as dataflow, with the identity unchanged across all three, and the effect of changing one node","research-forge.320ce22925":"Strong, for claims","research-forge.3218fcc602":"Proof composition","research-forge.32438a2b70":"Put automated discovery to work","research-forge.32d888fecc":"Execution linked","research-forge.32ec2eb506":"Type directed","research-forge.32fd056d3d":"Sketch","research-forge.32fe9f5bda":"Seed","research-forge.331a390a95":"Record that the guarantee cannot be justified as stated.","research-forge.332fafafd4":"Several programs are optimal","research-forge.337cd4ef85":"and protect afterwards","research-forge.3407af8c74":"The forms reinforce one another. Examples make a logical contract legible to a reader. Constraints stop a candidate overfitting the cases it was shown. A sketch keeps a safety structure fixed while the arithmetic or dataflow inside one region stays open to discovery.","research-forge.3554ae9f37":"A proof of a graph is not automatically a proof of arbitrary compiler output, so execution linkage records the graph, the plan, the artefact and the result together. Forge can then study discovery without claiming to own the emitter.","research-forge.356258d8cf":"Correctness earns entry to the trade-off discussion.","research-forge.357a580465":"expansion with conditions attached","research-forge.3631815377":"that keeps","research-forge.3647998e09":"relative modelled latency on one frontier","research-forge.3662b6cd93":"Optimisation is freedom inside a boundary that was written down first.","research-forge.3678b75177":"Proof anchor","research-forge.3697e2badd":"The same frontier, four defensible answers","research-forge.3750b1e26e":"One requirement","research-forge.378b19c94c":"and universal properties","research-forge.37a1d3ddee":"Search scale","research-forge.37b658da82":"what is established and what remains open","research-forge.37d9b94afa":"A reviewer can follow the chain from end to end without opening a single sealed node.","research-forge.37e5ec20ed":"Silence counts","research-forge.37e8f995e7":"A named non-answer also gives the institution a concrete point to act on. It says which clause conflicts, which behaviour was undetermined, which theory was unavailable or which budget ran out, and therefore what would have to change.","research-forge.3856f4eb7c":"The method reached no conclusion inside its theory and resource limits.","research-forge.387b54720d":"The rung a result has to reach before it counts","research-forge.38b07c05cf":"One assurance ladder with two candidates resting at different rungs and a drawer showing what each rung checked, assumed and does not establish","research-forge.391bc6cb44":"The proof keeps its boundary","research-forge.396c19de10":"Four ways a requirement resists a program","research-forge.39727bd48f":"back to synthesise","research-forge.3977816414":"evidence decides","research-forge.39d6a0ddc5":"Which decisions may the search make on your behalf?","research-forge.39fdec1194":"Tests","research-forge.3a06f841f3":"It is tested beyond the examples it was given.","research-forge.3a4be7155b":"Alternatives","research-forge.3ab11b75ca":"Forge","research-forge.3b08754530":"Forge starts from a description of the behaviour, not from a request for code. You can give it worked examples, rules that must hold in general, or a partly written program with the tricky parts left open. Any of those gives the machine something it can be measured against, and something it can visibly fail.","research-forge.3b0896e4b0":"For supported Kera contracts, pure execution repeats bit identically without a seed, including the covered floating family paths. Where a program deliberately consumes random state, that state is a declared input, and reusing it reproduces the whole run.","research-forge.3b8be5e1a9":"width proved","research-forge.3bb1fa9d93":"is one point in the space","research-forge.3bb59d3903":"Established","research-forge.3bcf82f6df":"Latency is a dimension","research-forge.3bdab018c4":"Verified always has a second half: under these rules, for these inputs.","research-forge.3bf08a84f1":"MOVE","research-forge.3bf4aa62c6":"One graph, two plans, one identity","research-forge.3c37add762":"Well formed","research-forge.3d3349e560":"what the institution decides before a search","research-forge.3d85b7b35e":"Four small cases, each ending without a program for a different reason, showing what was asked, what happened and what would change it","research-forge.3d8dc8dd37":"Carries a simpler checking path","research-forge.3d9d45c6fc":"and prove the wrong model","research-forge.3dbbac272c":"Counterexamples and proof state","research-forge.3e0fb17cab":"Clarify","research-forge.3e39972526":"Latency","research-forge.3e9492ab1e":"Graph, plan, artefact and result stay bound.","research-forge.3f1ea4240e":"The assumptions are part of the result, not small print underneath it. A proof about exact whole numbers says nothing about decimals. A proof about a self contained calculation says nothing about a service it was never told existed.","research-forge.3f2151a870":"Sizes one to six","research-forge.3fd8fb2e1a":"The operations, types, shapes, effects and capabilities a candidate is permitted to use.","research-forge.3fe459f958":"Nothing fits","research-forge.40100e1934":"Non-dominated candidates","research-forge.4025ca409c":"Own your performance","research-forge.408f0af557":"A derivation graph from specification to selected proof, with internal method steps sealed but connected, and the shorter path a replay actually has to reproduce","research-forge.40d33b38ad":"None of that is a caveat added afterwards. It is the content of the result, which is why the record puts the rung and its scope in the same place and why no control can promote one.","research-forge.40f800b699":"The frontier belongs to the objective set that produced it. Adding energy to the packet can return a candidate that was previously dominated, which is a property of the question rather than a change in any program.","research-forge.4141bac3ca":"and let the program change","research-forge.418cdd48b7":"Observed cases","research-forge.41978064b8":"Discuss cooperation","research-forge.41a3ff09e5":"State the behaviour","research-forge.4288fa85e0":"What is settled and what is open","research-forge.42c7f4ea4d":"The frame does not move","research-forge.42e742546a":"and tested is not proved","research-forge.43093ca0db":"Proof scope, structural simplicity, evidence cost","research-forge.435e8ecece":"one program rarely wins all four","research-forge.436fb3032c":"Conclude","research-forge.437b348524":"The order they happen in","research-forge.437bcb1511":"Energy","research-forge.439f7b365e":"Research docs","research-forge.43d54e530d":"Does the encoded requirement match what the organisation actually wants?","research-forge.43d8879a8c":"the execution link is what binds the proof to what actually ran","research-forge.4412dd5d66":"Impossible and undecided are reported, not converted into code.","research-forge.4475dded01":"One implementation","research-forge.44ab85a252":"Origin","research-forge.450d52d3ef":"Searches","research-forge.4585404748":"a candidate that stops at tested is reported as tested","research-forge.45aaefd6f4":"Four reviews","research-forge.4646f9193d":"Well formed is not tested","research-forge.4651a34e4d":"Scope","research-forge.466fc49274":"Keep","research-forge.46ed5f573e":"See the research","research-forge.4719d38f14":"Several behaviours satisfy the supplied evidence and disagree elsewhere.","research-forge.472643c4ca":"One candidate dominates another only when it is no worse in every active objective and better in at least one. Dominated candidates leave the active frontier. The ones that remain are all defensible answers to the same specification, and choosing between them is a policy decision the record keeps, rather than a calculation the search performs quietly.","research-forge.472bff45c9":"One form inside a larger space of equal behaviour.","research-forge.473161067f":"Selection policy","research-forge.47942077ae":"Simplest proof","research-forge.47b74866d6":"Check correctness","research-forge.47bcc2a36a":"Sometimes two things that were asked for cannot both be true. Sometimes the examples allow two different behaviours and there is no way to tell which one was meant. Sometimes the problem is simply harder than the method can settle in the time it was given. Forge reports each of those as what it is, and says what would have to change. An unclear case usually needs one more example rather than a larger budget.","research-forge.47cda15a5a":"Kera: how","research-forge.47da6f0838":"Compose","research-forge.48298eb992":"Search can replace operations, restructure dataflow, fuse regions, remove movement and arrive at an implementation no researcher had in mind. All of that is permitted, and most of it is the point.","research-forge.483bf2075c":"Published","research-forge.4901e146cd":"Compare cost","research-forge.490d255908":"the requirement stays the stable object","research-forge.49df3ec7de":"Runs on more supported machines","research-forge.4a828b8ab7":"Research, Forge","research-forge.4ab1a4f190":"The candidate that arrived first has no standing in the decision beyond its own evidence.","research-forge.4aebc33326":"Four reviews before a claim","research-forge.4b01608cdc":"The search never edits the packet to rescue a candidate.","research-forge.4b1960c2fb":"A system under pressure to produce code will produce code. That converts an unanswered question into a program somebody now has to maintain, and the uncertainty does not go away, it moves somewhere harder to see.","research-forge.4bca6a7cdb":"Where a program starts","research-forge.4c175158a6":"Linked result","research-forge.4c1e9313aa":"One pool","research-forge.4c39a99d3d":"Five rungs","research-forge.4c6bdedadc":"source stays a projection","research-forge.4cb3bb0fc4":"Fastest","research-forge.4d0ff72eb2":"What level of testing or proof does the result have to reach?","research-forge.4d6864f9a3":"Four frontier choices","research-forge.4d7f210eef":"Three candidates checked against a case list that grows by one failing input each round, with nothing ever removed from the list","research-forge.4db6c46b80":"each system reads the same object rather than a copy of it","research-forge.4e4bed5372":"Never on","research-forge.4e76f5796f":"Leanest","research-forge.4e90808185":"Four ways a run can end","research-forge.4e9a44aeb4":"Say what should happen","research-forge.4ec9cc4f2f":"Verified Program Discovery","research-forge.4f9c4e1fdb":"A first correct candidate proves that the problem is satisfiable. It may also be large, slow, memory heavy, awkward to verify or tied to one execution environment. Forge treats it as evidence rather than as the answer, and keeps searching for the families that a different search behaviour would have reached first.","research-forge.4faae9b4e9":"are different statements","research-forge.4fe6240efb":"Does the execution target match the semantics that were proved?","research-forge.500d19ed3e":"The next candidate must satisfy the stronger set.","research-forge.505ddba0dc":"the machine says what it knows","research-forge.506f370762":"the condition badge on an edge decides whether extraction may use it","research-forge.50e944749f":"WIDE","research-forge.50f771745f":"Whether it is a good implementation","research-forge.512f83ac42":"Three candidates checked against a growing obligation set, with the counterexample that ended each one and the two legitimate responses to a failure","research-forge.516f075235":"Four correct programs, four ways to prefer one","research-forge.5183317474":"Freedom","research-forge.52550c8d07":"The record answers why","research-forge.528d188e2a":"The level of proof required","research-forge.52e68a873a":"Constraints","research-forge.531e01782f":"Resolve the conflicting requirements the proof identified.","research-forge.536a08d31b":"FAST","research-forge.541a19b522":"The boundary is what makes the claim exact. A proof of a graph is a proof of that graph, so execution linkage records the graph, the Kera plan, the artefact and the result identity together, rather than assuming the proof travelled with the output.","research-forge.546130711a":"Dweve research programme","research-forge.54a351154f":"Minimality is a scoped statement. It holds for the operations, types and structures the packet permitted, up to the size the run reached. It says nothing about a language the experiment did not declare, and widening the operation set produces a new experiment with its own answer.","research-forge.550d4ccba7":"Numerical family, ordering, state model and the external conditions the run assumes.","research-forge.551fea67e6":"The description comes first, and the implementation stays an open question for as long as possible.","research-forge.5521ea4314":"adding an objective can return a dominated candidate, which is a fact about the question","research-forge.5549dc87d0":"Not every specification","research-forge.5601f89af7":"a candidate that simply looks right","research-forge.563591cebc":"How quickly the program completes","research-forge.56abd17a41":"When nothing comes back","research-forge.577d56824d":"THREE MOVES","research-forge.58357eb5f1":"stronger claims need stronger evidence","research-forge.584e0ea86c":"the vector describes the trade-off","research-forge.58c379fdea":"Size minimal","research-forge.59df8e27c4":"Keep the requirement","research-forge.5a0ba3bb83":"Contract","research-forge.5a2827f530":"Four rings","research-forge.5a314063cc":"how a weak candidate sharpens the question","research-forge.5ab1aaea94":"UNCLEAR","research-forge.5b1142d090":"Budget allocation","research-forge.5b141d8cb7":"Verified under these rules","research-forge.5b2a7fb11c":"Expose","research-forge.5b3facb840":"Four families of equal weight, and the packet decides which are active.","research-forge.5b5d8a5af8":"Record the concrete case and the property it broke.","research-forge.5b6a58fb9f":"Cheap, for search","research-forge.5b78187e47":"not right in every world","research-forge.5b8955c7bc":"Finding the program","research-forge.5b92885b2d":"An engineering team can choose the lowest latency member. A regulated programme can choose the cleanest assurance path. A deployment spread across mixed hardware can choose the broadest target fit. All three are choosing from the same verified set.","research-forge.5c1be9b227":"The claim is replayable","research-forge.5c262f33db":"Ends on","research-forge.5c46a60955":"How the work is split up","research-forge.5c9d4874c3":"Which inputs and which surroundings the claim covers.","research-forge.5ce01f3b67":"The programme publishes what its evidence supports and keeps its research method as research.","research-forge.5dfcf1dcc0":"One identity, three renderings","research-forge.5dfe750940":"Inspectable","research-forge.5e0d7f4f07":"Forge is a Dweve research project. Its internal search portfolio, formal reasoning implementation, transformation knowledge, objective calibration and orchestration are part of that research. What the programme publishes is the question, the protocol, the result and its assurance state, at the disclosure level the evidence supports. Cooperation begins from a bounded synthesis question. Five claims are tracked with their state, three of them settled and two still open, and the open ones are on the page rather than left out of the account.","research-forge.5e22dbb195":"Three pairings","research-forge.5e3db9c4c0":"Counterexample guided refinement","research-forge.5eb51a7a2a":"Follow the evidence, not only the program that came out.","research-forge.5eede4abda":"Widest target fit","research-forge.5f174de1cc":"Proof","research-forge.5f20d0f3ac":"Unsatisfiable","research-forge.5f94916c54":"See the institutional case","research-forge.5faa59d4bc":"Result","research-forge.5ff1729499":"before saying how","research-forge.603a007e8b":"and the alternatives close","research-forge.60508aeb3d":"Where to take the question","research-forge.60539e2c57":"Where the risk sits","research-forge.6066a49124":"That input joins the set every candidate must satisfy.","research-forge.60e5c23b14":"Typed","research-forge.616d1d1b2a":"Five preferences","research-forge.61792020d0":"Objective frontier","research-forge.61988aaea3":"The experiment packet","research-forge.61a0ae3b84":"Limits","research-forge.61ad50a9b9":"Target","research-forge.61c2d00a1e":"Specification forms","research-forge.61d0fdeb05":"The declared interface, its types and its shapes.","research-forge.61e2187199":"After the first valid program","research-forge.625ba6f153":"FIT","research-forge.62c4bc1315":"Two lanes out of the same requirement","research-forge.6320f96544":"let the machine find how","research-forge.636f4e740e":"is rarely the whole answer","research-forge.63ed4981dc":"Pareto","research-forge.63f0dfcfef":"A requirement broken into clauses, with four lanes showing which clauses produced an unsatisfiable, ambiguous, unknown or outside scope result, and the action each one calls for","research-forge.64269f9bd2":"TIME","research-forge.647c656679":"Two candidates can match as text, match once their graphs are normalised, or satisfy the same observable behaviour under the declared contract. Those are three different statements, and only the last one says anything about what the program does.","research-forge.649ed30fda":"The scope travels with the claim. A proof over exact integer semantics does not certify floating behaviour. A pure function proof does not cover an external service that was never declared. A verified graph modified after proof is a new candidate with no proof attached to it yet.","research-forge.64bcb871de":"A counterexample can expose more than an implementation defect. It can reveal an omitted precondition, an edge case nobody had decided, or two readings of the requirement that were both consistent with the examples. The record names which of those the researcher then changed.","research-forge.64c0978f0e":"Open, and the reason the programme exists: how large a verified graph region can usefully become, which specification forms are precise for a machine and workable for a person, how partial proofs compose through optimisation and planning, and which objectives need measured hardware feedback.","research-forge.64d22c2e4e":"Forge fixes the research problem before any candidate exists. One packet names the specification, the permitted operations and types, the effects and numerical semantics, the objective dimensions, the search bounds and the assurance policy a result has to reach. A candidate can only be judged against a problem that was already stated, which makes the packet part of correctness rather than configuration around it. The packet also says when to stop: the resource bound, the assurance threshold a candidate has to reach, and what the run reports when nothing reaches it.","research-forge.64f4056c85":"Policy visible","research-forge.657c02a2ae":"The requirement stays fixed","research-forge.664243d1c2":"Specification forms against what each one settles","research-forge.66b4132999":"Discuss a synthesis question","research-forge.66c7af05f3":"Forge makes the assumptions inspectable, and people still own them.","research-forge.66c95e7fc7":"Sealed","research-forge.66cd84bcef":"the shapes come and go, and the frame in the middle is the same one throughout","research-forge.6703a68b0c":"the policy names the member","research-forge.6767e55d00":"First valid","research-forge.681b5b5ae1":"Availability","research-forge.6848ce552e":"Outcomes","research-forge.68ad9d9693":"What stays fixed","research-forge.693f74e1e9":"The Forge and Kera boundary","research-forge.6978e0d16d":"No program at all can be the honest result","research-forge.6989b87ddb":"That is why the loop only gets stricter. Each round starts with everything the previous rounds established plus the new case, so a candidate can never win by forgetting an earlier failure.","research-forge.699425d26b":"Read the method","research-forge.69da6fa492":"Examples explain","research-forge.6a33efdc4e":"The experiment packet assembled field by field, with the identity that names it and the consequence of changing any field","research-forge.6a455d1ff6":"For every supported input, keep this true.","research-forge.6a54f54941":"The search answers","research-forge.6aa0b7e952":"different institutions choose differently","research-forge.6ab0b8903c":"Numerical meaning","research-forge.6b1716c3e5":"never more forgiving","research-forge.6b2284f302":"Knee point","research-forge.6b6ae4c323":"the obligation set only grows","research-forge.6b6f62925d":"Sometimes the counterexample says something about the request rather than the program. Two rules can turn out to contradict each other, or an edge case can turn out to be one nobody had actually decided. That is worth knowing early.","research-forge.6b7b6dcbaa":"One graph, four roles","research-forge.6bc457b374":"Find a candidate satisfying every known case.","research-forge.6bcf5a7776":"A frontier, not a single score","research-forge.6c4b5393b9":"and constraints decide","research-forge.6c61bbcebe":"Proved","research-forge.6c82e6dd86":"Time","research-forge.6c8dd48ed8":"Measurement plan","research-forge.6c9b8325ab":"no rung is ever inferred","research-forge.6c9c88fe2f":"A description of behaviour changes that relationship. It gives the search a target it has to hit, a way of being caught when it misses, and a record afterwards of exactly which cases the result was ever checked against.","research-forge.6cc1fdfb05":"Tested, bounded and proved are different statements about the same program.","research-forge.6cd40b6ae3":"Requirements begin as desired behaviour, constraints and risks. Development turns them into one architecture and one implementation, and from that moment every alternative is a rewrite, a migration or an optimisation project. The choice was probably reasonable when it was made, and it was made before anyone could compare it with the choices it ruled out.","research-forge.6d058a6f22":"not a general promise","research-forge.6d3a0e2f30":"Types prune first","research-forge.6d525b7156":"Execution","research-forge.6d5ef04ce2":"proof, bound or declared limit","research-forge.6d84ceaf60":"Extract","research-forge.6db87cb08f":"Fastest modelled","research-forge.6dfe9d2cfa":"Forge, the plain view","research-forge.6e3f1d3672":"Four ways to state intent","research-forge.6ef75c79a0":"A replay does not have to reproduce every exploratory branch. It has to reproduce the evidence the claim rests on: the specification, the selected candidate, the verification result and the execution binding. Everything else is search history rather than proof.","research-forge.70bcce6545":"Several routes","research-forge.70cbd1d6b1":"Proposed","research-forge.7173d0cb0f":"unknown, unsat and ambiguous are results","research-forge.718eb2ad28":"Strength reduction to shift","research-forge.71e541f178":"A test runs the program on inputs somebody chose. A proof reasons about every input the written specification covers. Both are useful and they answer different questions. When Forge says a candidate is verified, the sentence has a second half: verified against this property, for these inputs, under these assumptions. Five parts have to travel together for that sentence to mean anything: the exact program that was checked, the property claimed about it, the assumptions, the evidence, and the limits the result does not establish.","research-forge.722e234a05":"Find candidates","research-forge.72637278c6":"what Forge hands over","research-forge.729c82e196":"One object crosses the whole lifecycle, so nothing has to be re-derived from text at each stage.","research-forge.72aeb780b2":"Where the search goes next","research-forge.72e6f70d7c":"the result points back to the graph","research-forge.7305b76252":"stronger evidence earns a stronger label","research-forge.73128a8f5b":"the requirement comes first","research-forge.734e643f73":"Four axes","research-forge.734ee26abf":"Many families","research-forge.736500a024":"discovery and proof","research-forge.73710d0053":"Four things do not change with the outcome, and they are the reason the result can be read by someone who did not run the search.","research-forge.73e5abe068":"and the method stays private","research-forge.740141dd76":"Bounded checks and property tests","research-forge.746a18b508":"Formatting, operand order and the normalised graph. Enough to stop the search doing the same work twice.","research-forge.757b8815d3":"One frame","research-forge.75be5b7552":"What the record publishes","research-forge.75c9be68d0":"Rejects","research-forge.75e6b42fc5":"Outside scope","research-forge.762b81621f":"The rung a candidate must reach to enter the frontier.","research-forge.7701124587":"Proving that no smaller correct program exists inside a declared language is the question the superoptimisation research tradition studies. This bounded search is the instance of that question Forge can carry out and check.","research-forge.7777053d27":"Being wrong on purpose","research-forge.77809a4225":"x86-64, RISC-V, WASM, Vulkan GPU","research-forge.779df62acf":"Four standing commitments","research-forge.77e466696d":"No program in the permitted space can do it. Change the permission or the request.","research-forge.77ed933da8":"Objective vector and frontier position","research-forge.7800ae62d5":"Not just wrong","research-forge.78546ce4c3":"The requested effect is not represented by the verification contract.","research-forge.79919ce9fd":"Effects and capabilities","research-forge.79b38792f6":"Four objective families","research-forge.79b3e4bb6e":"Many candidates","research-forge.7a36809fc6":"Forge studies a different sequence. Keep the requirement explicit for longer. Let several implementations compete inside a declared language. Establish the supported behavioural claims before selecting among performance and deployment trade-offs.","research-forge.7a67d7aba8":"Are the environment, the effects and the numerical rules represented?","research-forge.7b2d03931b":"Conventional","research-forge.7ba8740951":"Which policy selected one member, and who stood behind it","research-forge.7bec3a8510":"Stops on","research-forge.7c04a5cf0e":"A vector of costs produces a frontier, which is a different object from a ranking.","research-forge.7c1e14bb08":"it does not remove human judgement","research-forge.7c3f4fda21":"size 1","research-forge.7d448f8882":"One candidate pool","research-forge.7d58a74832":"A candidate can pass every example it has been shown and still be wrong somewhere nobody looked. Forge searches for a specific input that exposes the difference. That input is a counterexample, and once it exists it joins the permanent set of cases every later candidate has to satisfy. The cycle behind that is short. A candidate is proposed, it is challenged beyond the examples it was given, one input exposes the wrong behaviour, and that input is kept. Then the search starts again against the larger set. It ends on a proof, a bound or a stated limit, and never on a candidate that simply looks right. Nothing is ever removed from that set, which is why the third attempt means more than the first.","research-forge.7d5f9141fc":"Measurement remains to be established","research-forge.7db1bb6632":"Derivation as evidence","research-forge.7df7e32344":"the badge names only the rung","research-forge.7e2e54dae8":"A balanced knee point can be suggested. The suggestion is recorded with the normalisation that produced it, so a reviewer can see that it is a policy rather than an arithmetic inevitability.","research-forge.7e309ec303":"Performance hypothesis, not benchmarked","research-forge.7e5a975b6a":"Identity","research-forge.7e826f7af3":"TRUST","research-forge.7ea014de7b":"Evidence","research-forge.7ea35b3515":"The same object holds four roles without changing category. It is a candidate during search, a member of an equivalence class during exploration, the subject a proof names, and the input Kera plans against. One identity carries all four.","research-forge.7f2b6cf0fd":"A candidate must satisfy the evidence gathered so far. A verifier then searches the supported domain for an input or state where it violates the complete specification. Any counterexample it finds joins the evidence set as a permanent obligation, so the next candidate has to satisfy everything the earlier ones did and the new case as well. The loop only ever gets stricter. It stops on a proof, a bound or a declared limit, and it never stops on a candidate that merely looks convincing. Adding a precondition is allowed, but it opens a new specification identity rather than editing the old one.","research-forge.7f59a1f1d5":"Decision","research-forge.7f5e7b5182":"Four institutional actions","research-forge.7f87260e69":"Written forward, read backward","research-forge.7fc3a8b99e":"The research design combines a DSL over typed expressions with enumerative, CEGIS, genetic-programming, and MCTS search, e-graph equality saturation, Cranelift-based measurement, and Z3/CVC5 checks for bounded obligations. Multi-objective search considers latency, operation count, memory, and register pressure; target code generation includes x86-64, RISC-V, WASM, Vulkan GPU, and Verilog. Task and test counts, cross-host speedups, and production performance remain validation work.","research-forge.7fda8c3a33":"Three candidates, three honest labels","research-forge.7fdf663e3a":"Performance hypothesis, not benchmarked","research-forge.7fef09721e":"Dweve Forge, verified program discovery","research-forge.80302bf5ea":"Bounded checks and search","research-forge.80446347ed":"Form","research-forge.80d70e543d":"Frontier and selection","research-forge.814de3b8b2":"Four frontier members","research-forge.8179013356":"Traffic, working set, transfers and locality","research-forge.81eccd6085":"Four reasons for silence","research-forge.81f08b5724":"long after the people move on","research-forge.8208f3f27b":"The order","research-forge.82319c5d9e":"Applying transformations in a sequence makes an early choice that can rule out a later improvement. Forge studies compact representations that hold many equivalent forms at once, so several transformation paths coexist until extraction. Representing many rewrites together rather than committing to one order is the approach the research literature calls equality saturation.","research-forge.8252f95ddf":"changing one node in a verified graph returns the candidate to well formed","research-forge.825d89212b":"Transformation knowledge","research-forge.8283b9d96c":"No phase order","research-forge.82c24c3687":"The program is free to change shape, and the thing it has to satisfy is not.","research-forge.8301a503f4":"The disagreement between two valid readings is surfaced as a question, not resolved by the search.","research-forge.8368699cf6":"Many possible programs","research-forge.8375a2c337":"Three attempts, one growing case list","research-forge.837b910e11":"until policy selects one","research-forge.83908aa381":"Type, shape, representation and the numerical contract that governs it.","research-forge.83ea53e5ec":"Many equal forms, three worth extracting","research-forge.8597c90c68":"Research tests (scope)","research-forge.864c38bd34":"Where a measurement does not exist, the cell stays empty. An empty cell is a statement about the evidence, and filling it with a model output would quietly convert an estimate into a result.","research-forge.8682d73e62":"Programme","research-forge.869cb36316":"One proposed implementation of the pinned specification.","research-forge.8703ca90ce":"Ownership, memory space and the target restrictions that apply.","research-forge.870d4e66fc":"the record names the scope","research-forge.87805aff07":"No program at all","research-forge.879bb91dae":"neither side absorbs the other's claim","research-forge.87d0c490e0":"The cost dimensions this experiment compares, chosen before any candidate is measured.","research-forge.88306943fe":"Method","research-forge.8831be6339":"When no program appears","research-forge.887b3d18f0":"Forge owns the specification, the candidate search, the equivalence exploration, the objective frontier and the verification. Kera is Dweve's graph-native systems language and Direct Computation foundation, and it owns planning, lowering, target specific emission and execution. What crosses between them is a verified semantic graph with its obligations, its objective profile and its evidence. The graph is named rather than the source, and the result that comes back points at the same identity.","research-forge.887cf267e6":"Unsat","research-forge.888797190c":"one behaviour, several implementations","research-forge.888e561892":"Four ways to ask for better","research-forge.892257a43b":"A proof can be sound","research-forge.89404ea15f":"Formal query","research-forge.894f8a793c":"Use a stronger theory, a wider language or a larger budget.","research-forge.897b3ac98d":"Codegen","research-forge.89b86ab0e6":"Language","research-forge.89c7caf6b5":"Which steps do the work","research-forge.89c8a2851d":"Memory","research-forge.89f5343231":"The durable decision trail","research-forge.8a102fcb06":"Bounded complete search","research-forge.8a9523ae04":"What a candidate node carries","research-forge.8ab2c84ed7":"One architecture","research-forge.8b2d50590f":"Formal evidence covers the specification and the semantics that were encoded. If an environmental condition was left out, or the numerical model does not match the machine, the result is valid and answers a slightly different question.","research-forge.8b593995c8":"Assumptions","research-forge.8b7acd8daf":"Nothing enters the frontier with an assurance label stronger than its evidence supports.","research-forge.8bafd39dbd":"The deliberate product boundary","research-forge.8c0dc9aa18":"Preconditions, postconditions and the assurance the result has to reach.","research-forge.8c1cf9e158":"Examples, logical conditions, sketches and reference behaviour, each recorded with the strength it carries.","research-forge.8cb71202e7":"Several behaviours fit the examples. One more case decides it.","research-forge.8d9c9bb663":"Two records, one graph","research-forge.8daee0af31":"The conventional route narrowing to one codebase and reopening as rewrite projects, beside the research route keeping a fan of verified candidates until a policy selects one","research-forge.8db9aab917":"how strongly it has been checked","research-forge.8dce170de2":"Value","research-forge.8dd2a359fe":"LEAN","research-forge.8df2bb4b75":"The assurance level a candidate must reach, the search bound, and what to report when nothing reaches it.","research-forge.8e2717f3c6":"A candidate that could not be legal is never built, so the frontier only ever holds well formed programs.","research-forge.8e34678d0d":"illegal candidates never enter the pool","research-forge.8e3934fad2":"Four policy tabs selecting different members of one frontier, each producing a complete decision record with dominance reasons for the members it did not select","research-forge.8e50172772":"Independent checking is a separate rung because it asks a different question. Not whether the proof was produced, but whether a checker that did not produce it agrees, using only the evidence supplied with the candidate.","research-forge.8e84017c75":"The link is to a specific program. Change one step inside it and the proof no longer describes what you are holding, so the label goes back to the plain structural one until the checking has been done again.","research-forge.9032517861":"Five claims, five states","research-forge.908b29b50b":"each rung needs a different kind of evidence","research-forge.90e40d5043":"Get started","research-forge.919003799d":"Tested","research-forge.91ad20c2db":"Two plans","research-forge.91c0ae2087":"precise intent lowers implementation risk","research-forge.91cf399266":"can be the real answer","research-forge.9225f51a2a":"Counterexample","research-forge.9233f41df0":"Three targets","research-forge.9297ab4ca3":"Read the story","research-forge.929818c51d":"Largest memory footprint","research-forge.929a9f0f25":"The first one that works","research-forge.92a7058e4e":"Discuss institutional cooperation","research-forge.92f5fe6952":"Four outcomes","research-forge.936c25084e":"Reference behaviour","research-forge.9388f4158d":"the balanced option is a choice like the others, and it says so","research-forge.93c09204c0":"Moderate on both costs","research-forge.93c2975761":"Follow the search","research-forge.93f79d808f":"Does the selected frontier member reflect the stated priority?","research-forge.942587e61e":"Project sheet","research-forge.9477d7acdd":"Apply for partner access","research-forge.94822e9dc6":"Forge, institutional view","research-forge.94827e8438":"Read the papers","research-forge.94859cf20a":"Sealed and open","research-forge.948c81b996":"Several verified ways forward","research-forge.94cc86c489":"one changed step and the badge names a program you are no longer holding","research-forge.94ed3b0134":"from intent to the selected program","research-forge.950dfeeb8b":"Intent becomes code","research-forge.9550373e8b":"Measured","research-forge.95eaeda430":"How large a verified graph region can usefully become.","research-forge.9678c4f1e3":"one identity crosses the boundary","research-forge.96aff7c058":"One counterexample loop","research-forge.96b9633285":"What the search may change","research-forge.973c3f46d7":"In scope","research-forge.978aa6569a":"Finishes sooner","research-forge.97c89a4d66":"Action","research-forge.97ee6e5610":"Propose","research-forge.992bc34385":"A pure specification cannot acquire file or network access along the way. A fixed width integer contract cannot quietly become an unbounded mathematical integer. A scale bearing representation keeps its scale, and a memory safe sketch cannot be completed with an unchecked alias.","research-forge.99508624d6":"No program can be","research-forge.996c4a8976":"has a program in it","research-forge.99dc6bab08":"Two candidates satisfying the same example set and diverging on an input nobody supplied, with the three ways a stakeholder can settle it","research-forge.9a24005705":"One complete search, by size","research-forge.9a469ce88c":"Concrete","research-forge.9a4ce5f246":"the choice has to be stated","research-forge.9ae33a7d0e":"Property","research-forge.9b7bd11153":"A verified graph crossing a hard boundary into Kera, planned two different ways, with both results linked back to the same graph identity","research-forge.9c25db95cc":"Candidate A","research-forge.9c86ef6b28":"Explores candidate implementations under a declared contract","research-forge.9cbe42aaff":"Planned","research-forge.9cfcf5930d":"Latency, movement, deployment fit and evidence burden are untouched by the first result.","research-forge.9d68007b07":"Program","research-forge.9dba232302":"The behaviour that was asked for","research-forge.9dc6ec542b":"is not the same as running it","research-forge.9dd59ab994":"Compares","research-forge.9df0f32743":"Registers, parallelism, device limits, portability","research-forge.9e811eeaf8":"After correctness","research-forge.9ee018232e":"Nothing enters a candidate that the packet did not permit.","research-forge.9f36fa8055":"Keep this shape and find the missing part.","research-forge.9f78c690af":"for different reasons","research-forge.9fea6de725":"Formal","research-forge.9ff7951f81":"A verified badge expanded into its five parts, shown again beside the same program after one step changed and the link between them broke","research-forge.a0a9a568c3":"The candidates that stayed valid, and the ones a counterexample ended","research-forge.a0c9c40551":"the program changes shape","research-forge.a10a7ad63a":"What the packet fixes","research-forge.a266f0a07d":"Explore candidate kernels","research-forge.a2e1cc1b2f":"May change","research-forge.a2f4a96337":"Trade-off","research-forge.a32a41c9d1":"no program, with the reason","research-forge.a336e6650d":"Two candidates, two honest stopping points","research-forge.a3c143732a":"the problem is fixed before the search","research-forge.a3c686e711":"Category","research-forge.a4508fc8ef":"Semantic relation","research-forge.a48f8c0cf7":"Five programs, one specification","research-forge.a4c745386f":"Four policies","research-forge.a57b5d2330":"The search may change","research-forge.a6067adc3c":"latency, ops, memory, registers","research-forge.a618b4be8d":"Query","research-forge.a61c938f35":"Search proposes","research-forge.a723285355":"Modelled","research-forge.a79764b5e5":"Several correct programs, each carrying its own evidence","research-forge.a7987d27ae":"Forgoes one rewrite","research-forge.a898f4eb0d":"It is the same choice anyone makes about a route across a city. The quickest, the cheapest and the one with fewer changes are all reasonable. What is not reasonable is claiming there is only one answer without saying what you optimised for.","research-forge.a8b262d32b":"Asking a model for code and getting something that looks right is a different exercise. There is nothing for the answer to satisfy, so there is nothing for it to fail against, and the person reading it has to supply all of the judgement.","research-forge.a8e5c0ccf3":"The graph the verification result actually names.","research-forge.a91bcce893":"Always","research-forge.a94848cbdb":"Only candidates that passed the gate reach this step.","research-forge.a9d6afeda0":"back to propose","research-forge.a9f1693ebe":"Every member satisfies the declared contract, so the only remaining question is which cost you accept.","research-forge.aa1a2e191d":"STATED FIRST","research-forge.aa2b80d828":"Frontier","research-forge.aa62568659":"Saying what is not known is more useful than filling the gap with something that reads well.","research-forge.aa6708d51a":"A supported universal relation was proved.","research-forge.aa88ef980e":"Which supported environments can run it","research-forge.aa9002c223":"The badge, opened","research-forge.aab9ca1bc6":"In a class","research-forge.ab89d05c4b":"Placement","research-forge.ab98f5b857":"Fixed","research-forge.ab9a4aae0b":"Lowest movement","research-forge.aba86cd010":"Policy selects","research-forge.abc0c09f1f":"The machine may change which steps do the work, the order they happen in, and which intermediate values exist at all. Two programs that share none of those can still be doing the same job, and the search is allowed to prefer either one.","research-forge.ac30f0abf3":"If it changes what the program produces, it is not an improvement to that program. Correctness is what earns a candidate a place in the conversation about cost.","research-forge.acc3156c5b":"Run link","research-forge.ad2cecac38":"Text and structure","research-forge.ad44adccc4":"the proof strengthens a precise claim","research-forge.ad59e3b102":"Broadest","research-forge.adfc01e921":"A candidate can only be judged against a problem that was already stated.","research-forge.adfccdc8de":"Forge: what","research-forge.ae2fee1a70":"Build only type correct larger expressions.","research-forge.aeb1c76446":"Four rings, one publication rule","research-forge.aebc2854f4":"Numerical","research-forge.aeedafb2fe":"failure becomes a durable obligation","research-forge.af3cc2e010":"the program, not the goal","research-forge.af68d81f17":"The behaviour and constraints that defined success.","research-forge.af78a00855":"How directly its behaviour can be checked","research-forge.afbab5dc80":"the first discovered candidate keeps its place in the history and leaves the frontier","research-forge.aff55d9c0e":"Report the smallest verified candidate and its bound.","research-forge.b0339e3e63":"Synthesis, Cranelift, and","research-forge.b048046ec8":"The lowest latency candidate may hold a larger working set. The most portable one may be slower on the machine in front of you. The one with the simplest proof may forgo an aggressive rewrite. A balanced knee point can be suggested, and the suggestion is recorded as a policy with its normalisation attached.","research-forge.b06be2ecea":"That is why Forge publishes the assumptions beside the claim, and why the review has named owners. The specification, the model and the execution target are three separate signatures.","research-forge.b0811e470d":"Trade","research-forge.b0a205ebad":"Start from the permitted inputs and constants.","research-forge.b0b01215a0":"Candidate D","research-forge.b116105199":"Four questions to settle","research-forge.b1d348384e":"More than one kind of better","research-forge.b23977841c":"Counterexamples","research-forge.b26aa65383":"What the word verified covers","research-forge.b2bc0c005f":"Checked","research-forge.b30077250b":"commit early or preserve the alternatives","research-forge.b307b88c84":"Portability","research-forge.b3776d63ad":"Backends","research-forge.b39a168c1e":"The packet is written once, and every result on this page points back to the version that produced it.","research-forge.b3c0c45a3e":"Forge keeps structural validity, concrete testing, bounded exhaustive checking, formal verification, independent checking and execution linkage apart. A candidate moves up only when the evidence for the next rung exists, and the rung it reached is part of the result rather than a decoration on it. A fast search can hold tested candidates while a proof is still being obtained. Independent checking sits on its own rung, because it asks whether a checker that did not produce the proof agrees with it.","research-forge.b45b598d0c":"One graph identity connects the specification, the proof, the plan and the result that came back.","research-forge.b462217ad5":"One input shows the behaviour is wrong.","research-forge.b4dad06170":"Tech specs","research-forge.b51ba796f2":"Starts from","research-forge.b5338782b3":"The dimensions a candidate is ranked on, modelled or measured","research-forge.b568d47f2e":"Input","research-forge.b5b0a8f813":"Concentric layers from the public research question through the reproducible protocol and the released result to the protected internal method","research-forge.b6272cdaf7":"Forge records the specification identity, the candidate ancestry that matters, the counterexamples, the equivalence relations used, the objective values, the assurance transitions and the selection policy. That chain explains why the chosen program exists and which alternatives it displaced, and it is enough for someone else to reconstruct the claim. A replay does not have to repeat every exploratory branch, only the evidence the claim rests on.","research-forge.b638127a16":"Bounded complete","research-forge.b66b54c1d8":"The candidate as an object","research-forge.b6d2f4c9e8":"the search cannot widen the type system","research-forge.b70446abdf":"Requirements can conflict. A set of examples can permit incompatible behaviours. A requested guarantee can lie outside the semantics the verification contract represents. A search can meet its declared limit without a conclusion. Forge reports each of those separately, because they call for four different responses and cost four different amounts to act on. Conflicting clauses are reconciled, competing behaviours are separated by more evidence, an unsettled search is extended, and a guarantee outside the contract is recorded as one that cannot be justified as stated.","research-forge.b71f6e67ce":"Study one implementation decision","research-forge.b74c664479":"Assurance states","research-forge.b78c6b0e99":"passing the examples and satisfying the condition are not the same claim","research-forge.b82b9b1043":"the forms are combined deliberately","research-forge.b895ceb6b1":"a non-answer prevents false confidence","research-forge.b8f5629ab6":"the obligation column never shrinks between iterations","research-forge.b97a1099a3":"Machine checkable","research-forge.b9b15e5f94":"Three dossiers","research-forge.ba25b214d8":"each one asks for something different","research-forge.ba3fef96ae":"A proof in five parts","research-forge.babfc32160":"At least one behaviour satisfies every clause at once.","research-forge.bac127c5b7":"Non dominated","research-forge.bb11a8e3f8":"Rules","research-forge.bb2fe63e5a":"INPUT","research-forge.bb54db510a":"Accept","research-forge.bb9cf14180":"Policy","research-forge.bb9d653f4e":"Challenge","research-forge.bbddd6ecdf":"Which intermediate values exist","research-forge.bc0b16aa7f":"Four verified programs re-ranked by which property you ask for, with the balanced option shown as a preference like the others","research-forge.bc6b9b38a3":"Steps that belong to Dweve's research method appear as sealed nodes with their inputs, outputs and identity published. Institutional transparency and research confidentiality are handled as two properties of one chain rather than as opposites.","research-forge.bc7819b34f":"Unknown","research-forge.bcd3b8580e":"the object never changes category","research-forge.bce0641417":"Search","research-forge.bd163f2c2d":"Every relation carries its side conditions. Algebraic restructuring, strength reduction, vectorisation, fusion, layout change and movement elimination are legal only when the arithmetic, width, rounding, effect and ordering conditions hold in this experiment.","research-forge.bd5d4d39fa":"Says","research-forge.bda89bbff3":"Changing an example, widening a type, permitting an effect or relaxing a numerical tolerance produces a different research problem with a different identity. The earlier run stays in the record under its own packet, so two results are never read as answers to the same question.","research-forge.bdfebc22bf":"Objective vector","research-forge.be601df25e":"Research","research-forge.beb1ed4753":"public evidence beside protected method","research-forge.bef833878c":"the case list never gets shorter between rounds","research-forge.bf55421b4a":"The behaviour asked for is not something the checking covers.","research-forge.bff5c4dd05":"Require","research-forge.business.actionCase":"See the institutional case","research-forge.business.actionCooperate":"Discuss research cooperation","research-forge.business.banner.body1":"It proves that one route exists.","research-forge.business.banner.body2":"It does not prove that the route is the fastest, smallest, most portable, easiest to audit or best suited to the institution that must operate it.","research-forge.business.banner.eyebrow":"The design-space problem","research-forge.business.banner.firstDetail":"The search has established that a permitted candidate exists.","research-forge.business.banner.firstLabel":"One satisfying route","research-forge.business.banner.firstStatus":"Valid in scope","research-forge.business.banner.footer":"Dweve Forge, Verified Program Discovery","research-forge.business.banner.frontierDetail":"Several correct programs remain for different objective profiles.","research-forge.business.banner.frontierLabel":"Non-dominated alternatives","research-forge.business.banner.frontierStatus":"Visible","research-forge.business.banner.headline":"Correct is the start","research-forge.business.banner.headlineAccent":"not the final answer","research-forge.business.banner.instrument":"After correctness","research-forge.business.banner.leftLabel":"First valid candidate","research-forge.business.banner.limitDetail":"The first result says nothing about nearby trade-offs.","research-forge.business.banner.limitLabel":"No universal optimum","research-forge.business.banner.limitStatus":"Keep searching","research-forge.business.banner.policyDetail":"The institution states which trade-off shaped the choice.","research-forge.business.banner.policyLabel":"Recorded selection policy","research-forge.business.banner.policyStatus":"Reviewable","research-forge.business.banner.rightLabel":"Decision frontier","research-forge.business.banner.tag":"Compare","research-forge.business.banner.verdict":"Keep the alternatives until the policy is explicit.","research-forge.business.banner.verdictLabel":"Decision rule","research-forge.business.close.body":"Bring domain intent, formal methods, hardware measurement or independent review. Forge supplies a shared research object for comparing program discovery, proof and execution.","research-forge.business.close.label":"Dweve Forge, research cooperation","research-forge.business.close.primary":"Discuss institutional cooperation","research-forge.business.close.secondary":"Inspect the evidence contract","research-forge.business.close.title":"Challenge one decision.","research-forge.business.eyebrow":"Dweve Forge, Verified Program Discovery","research-forge.business.lede":"Dweve Forge is a research project that turns examples, constraints and partial specifications into a controlled search for valid programs, compares the non-dominated alternatives and preserves the evidence supporting the selected result. The specification remains the durable asset while implementation choices stay open for longer.","research-forge.business.titleAccent":"until proof decides","research-forge.business.titleLead":"Hold intent open","research-forge.businessGlyph.ambiguous":"Behaviour still ambiguous","research-forge.businessGlyph.assurance":"Assurance named","research-forge.businessGlyph.boundary":"Research programme, not a software offer","research-forge.businessGlyph.candidateA":"Candidate A","research-forge.businessGlyph.candidateB":"Candidate B","research-forge.businessGlyph.candidateC":"Candidate C","research-forge.businessGlyph.candidateD":"Candidate D","research-forge.businessGlyph.counterexample":"Counterexample found","research-forge.businessGlyph.execution":"Plan and result linked","research-forge.businessGlyph.fixed":"Fixed","research-forge.businessGlyph.kera":"Kera execution","research-forge.businessGlyph.lowLatency":"Lowest latency","research-forge.businessGlyph.lowMovement":"Lowest movement","research-forge.businessGlyph.policy":"Selection policy","research-forge.businessGlyph.portability":"Widest portability","research-forge.businessGlyph.research":"Research","research-forge.businessGlyph.selected":"Selected graph","research-forge.businessGlyph.simpleProof":"Simplest proof","research-forge.businessGlyph.spec":"Behaviour, boundaries and assurance policy","research-forge.businessGlyph.specFixed":"Specification fixed","research-forge.businessGlyph.specLabel":"Immutable specification","research-forge.businessGlyph.subtitle":"Verified alternatives before execution","research-forge.businessGlyph.title":"Specification decision sheet","research-forge.businessGlyph.tradeoffs":"Trade-offs visible","research-forge.businessGlyph.visible":"Visible","research-forge.businessHero.titleMiddle":"better","research-forge.businessHero.titleSuffix":"software","research-forge.c00cde6a62":"A finite declared domain was covered without failure.","research-forge.c023fe51a2":"Forge is available through Dweve's research partner program. Test bounded program-synthesis questions and agree evaluation terms before access. Results remain research evidence, not a product promise.","research-forge.c040f6e04f":"the bound is stated with the result","research-forge.c0caf528d8":"Multi-objective cost","research-forge.c10a6d0899":"Contradictory requirements found during implementation become delay and rework. An ambiguity found after deployment becomes inconsistent behaviour somebody has to reconcile. Finding either before the implementation exists is the cheapest place to find it.","research-forge.c12f928235":"Graph handoff","research-forge.c144b00ba8":"Latency, throughput and critical path","research-forge.c174fa3158":"The frontier does not move when the policy does","research-forge.c1929c45f3":"A search can prove that nothing in the declared language satisfies the requirement, fail to decide the question within its theory and resource limits, or find that the supplied evidence permits several incompatible behaviours.","research-forge.c1fcd5ecff":"It might be faster. It might be smaller. It might be the neatest thing anyone had thought of for that problem.","research-forge.c20d749a05":"TRADE-OFFS VISIBLE","research-forge.c2184a31d3":"The requirement is the thing worth keeping, and the implementation is a result it produced.","research-forge.c297908b88":"A candidate cannot be promoted by a control, only by evidence that the next rung exists.","research-forge.c29cf0b245":"Trade offs","research-forge.c2bb6fa0c5":"SPECIFICATION IMMUTABLE","research-forge.c2ea17d5fe":"THREE FIELDS","research-forge.c33ef52668":"the requirement does not","research-forge.c3451e6677":"Examples show the expected behaviour on cases people can check. Logical conditions define what has to hold beyond those cases. A partial sketch preserves a safety architecture, an interface or a mandated control flow while one region stays open to discovery. Together they make the requirement precise enough for a machine to fail against, which is what a specification is for. Anything the search is allowed to decide on your behalf belongs in the same document.","research-forge.c36594e8f5":"minimal inside the declared language","research-forge.c3be8bb127":"How fast","research-forge.c3e4b59bd1":"How much data the program moves","research-forge.c439038abe":"Not covered","research-forge.c440d9bf36":"The search cannot rescue a candidate by changing the goal.","research-forge.c4cc9c34bd":"One refinement loop","research-forge.c533db2294":"before seeing the options","research-forge.c554cb5d95":"Dweve Research, the Netherlands","research-forge.c60a3a3cff":"Search the supported domain for a violating input.","research-forge.c648f0b37b":"Four reasons the answer is no program","research-forge.c69925079f":"wrong on this exact case","research-forge.c6c9f7cd5c":"A clever shortcut","research-forge.c6d954c113":"Nothing in the declared language and assumptions satisfies the requirement.","research-forge.c74dddd8a0":"The entries that answer a later question were written when the decision was made.","research-forge.c76a21c28e":"That is why a familiar identity can be admitted in an exact integer region and refused in a floating region within the same graph. The condition stays attached to the relation, so extraction never inherits a rewrite it was not entitled to.","research-forge.c7e00eda62":"the claim is minimal within this language, at this bound","research-forge.c7f2c2e7d4":"Three rounds","research-forge.c8050fa93f":"It proves that one route exists. That is a real result and it is worth having early, because it tells you the requirement can be satisfied at all inside the language you declared.","research-forge.c82f0b5250":"a crossing pair is a trade-off, not a ranking","research-forge.c855f0a33c":"An unsupported theory stops a candidate at tested, or at outside scope, and the record says which. A formal result can name the semantic graph while the emitted artefact still waits for its execution link. None of those states is compressed into a single badge.","research-forge.c932a404bb":"Test, challenge and prove what the evidence supports.","research-forge.c93e1581c7":"Even a small problem can have millions of possible programs in it. Forge looks inside the operations and boundaries the experiment allows, and different search behaviours explore different parts of that space. What none of them may do is make the problem easier: the requirement sits outside the search and does not move.","research-forge.c940737ecf":"Forge, research view","research-forge.c968557f4b":"Verified graph and evidence to Kera","research-forge.c9bf3b001c":"the most valuable result","research-forge.c9d8f0eef6":"prune before evaluating","research-forge.ca032b5844":"What it does","research-forge.ca046ad257":"Read the research","research-forge.ca08ca46bd":"The assurance ladder","research-forge.ca09c54bff":"Capabilities","research-forge.ca6d0e3aaa":"Stage","research-forge.ca7b181648":"The fixed order","research-forge.cb3242398c":"Several programs stay valid","research-forge.cb3888722e":"Neither side absorbs the other's claim, and the graph identity keeps the connection exact.","research-forge.cb48a44ca9":"Three iterations","research-forge.cb4ae000d8":"the program stays open","research-forge.cb5c0156c2":"Carries its own limits","research-forge.cbb9f1b292":"each one says something different","research-forge.cbbe214a22":"Bring a specification","research-forge.cc68ebf0f3":"A frontier holds the candidates that no other candidate beats on every active objective. Removing a member requires a dominance relation that can be shown, not a preference buried in the search. That turns a technical comparison into something a review board can read: each member satisfies the same contract and differs only in what it costs.","research-forge.ccfd13401b":"Pin the problem","research-forge.cd27068c9e":"Durable asset","research-forge.cd3d5a59f1":"Deterministic execution","research-forge.cdaa0de1dc":"Common subexpression share","research-forge.cdbed7e540":"Search language","research-forge.cde215073a":"all four satisfy the same contract","research-forge.cdf33799d9":"Execution link record","research-forge.ce3b4e045e":"before it becomes permanent","research-forge.ce9e850988":"the search reports the divergence rather than choosing one of them","research-forge.cec4b662d3":"Partial program","research-forge.cecae09ffe":"The machine finds a candidate.","research-forge.cf5ed047cf":"Objective values and position on the frontier.","research-forge.cf61965045":"facts available before anything is evaluated","research-forge.cf88038e56":"Not final","research-forge.cf9b77061f":"Open","research-forge.consumer.banner.bodyOne":"A candidate may be faster, smaller or easier to run.","research-forge.consumer.banner.bodyTwo":"If it breaks the specification, it is not an optimisation of that program.","research-forge.consumer.banner.checkDetail":"Require the evidence level named by the experiment.","research-forge.consumer.banner.checkLabel":"Check correctness","research-forge.consumer.banner.checkStatus":"Gate","research-forge.consumer.banner.compareDetail":"Only acceptable candidates enter the trade-off discussion.","research-forge.consumer.banner.compareLabel":"Compare cost","research-forge.consumer.banner.compareStatus":"Then compare","research-forge.consumer.banner.eyebrow":"The non-negotiable boundary","research-forge.consumer.banner.findDetail":"Explore different permitted program structures.","research-forge.consumer.banner.findLabel":"Find candidates","research-forge.consumer.banner.findStatus":"Search","research-forge.consumer.banner.footer":"Dweve Forge, Verified Program Discovery","research-forge.consumer.banner.instrumentTag":"Fixed","research-forge.consumer.banner.instrumentTitle":"The order","research-forge.consumer.banner.stateDetail":"Write the result and its boundaries before search.","research-forge.consumer.banner.stateLabel":"State the behaviour","research-forge.consumer.banner.stateStatus":"Fixed","research-forge.consumer.banner.titleAccent":"if it changes the answer","research-forge.consumer.banner.titleLead":"A clever shortcut is useless","research-forge.consumer.banner.verdictLabel":"The rule","research-forge.consumer.banner.verdictValue":"Correctness earns entry to the trade-off discussion.","research-forge.consumer.close.body":"Public Forge material explains the specification, discovered alternatives, counterexamples and what the research can actually prove. Forge is active internal research, with no software trial, public package or open-source download.","research-forge.consumer.close.eyebrow":"Dweve Forge, Verified Program Discovery","research-forge.consumer.close.primary":"Explore Dweve research","research-forge.consumer.close.secondary":"Return to the experiment","research-forge.consumer.close.title":"Follow the search from intent to evidence.","research-forge.consumer.counterexample.body":"A candidate may work on every supplied example and still fail elsewhere. Forge can challenge it with a concrete input that exposes the difference. That input becomes a counterexample.","research-forge.consumer.counterexample.eyebrow":"Failure as useful evidence","research-forge.consumer.counterexample.footer":"Passing many examples still does not mean that the program has been proved correct.","research-forge.consumer.counterexample.pillFailure":"Concrete failure","research-forge.consumer.counterexample.pillPermanent":"Permanent case","research-forge.consumer.counterexample.pillRetry":"Search again","research-forge.consumer.counterexample.secondaryLeft":"The failing case joins the permanent evidence. The next candidate must satisfy both the earlier examples and the new boundary.","research-forge.consumer.counterexample.secondaryLeftLabel":"The candidate changes","research-forge.consumer.counterexample.secondaryRight":"A failure can also reveal ambiguity or contradiction in the request. Clarifying the intent creates a new specification and keeps the earlier result visible.","research-forge.consumer.counterexample.secondaryRightLabel":"The intent may change","research-forge.consumer.counterexample.sideChallengeDetail":"Look beyond the friendly examples.","research-forge.consumer.counterexample.sideChallengeLabel":"Challenge","research-forge.consumer.counterexample.sideFooter":"Failure narrows the search and clarifies the human requirement.","research-forge.consumer.counterexample.sideMetaLabel":"Direction","research-forge.consumer.counterexample.sideMetaValue":"Stricter each round","research-forge.consumer.counterexample.sideProposeDetail":"Find a candidate that fits the known cases.","research-forge.consumer.counterexample.sideProposeLabel":"Propose","research-forge.consumer.counterexample.sideRememberDetail":"Add the concrete failure to the evidence.","research-forge.consumer.counterexample.sideRememberLabel":"Remember","research-forge.consumer.counterexample.sideRetryDetail":"Search for a candidate that survives the stronger set.","research-forge.consumer.counterexample.sideRetryLabel":"Retry","research-forge.consumer.counterexample.sideStatus":"Loop","research-forge.consumer.counterexample.sideSubtitle":"How a weak candidate sharpens the question","research-forge.consumer.counterexample.sideTitle":"One counterexample loop","research-forge.consumer.counterexample.titleAccent":"wrong on this exact case","research-forge.consumer.counterexample.titleLead":"Not simply wrong","research-forge.consumer.counterexample.visualFooter":"The next candidate must do better without weakening the requirement.","research-forge.consumer.counterexample.visualMeta":"Illustrative case","research-forge.consumer.counterexample.visualStatus":"Counterexample found","research-forge.consumer.counterexample.visualSubtitle":"Three candidates meet an increasingly strict boundary","research-forge.consumer.counterexample.visualTitle":"A failing case becomes a permanent obligation","research-forge.consumer.glyph.evidence.counterexample":"Failure recorded","research-forge.consumer.glyph.evidence.examples":"Examples passed","research-forge.consumer.glyph.evidence.execution":"Execution linked","research-forge.consumer.glyph.evidence.proof":"Relation proved","research-forge.consumer.glyph.footer":"The machine may return no program.","research-forge.consumer.glyph.header.detail":"The request remains fixed while the paths change.","research-forge.consumer.glyph.header.state":"Research active","research-forge.consumer.glyph.header.title":"A program-discovery experiment","research-forge.consumer.glyph.path.a.label":"Fails an edge case","research-forge.consumer.glyph.path.a.state":"Rejected","research-forge.consumer.glyph.path.b.label":"Correct, higher cost","research-forge.consumer.glyph.path.b.state":"Keep","research-forge.consumer.glyph.path.c.label":"Correct, different trade-off","research-forge.consumer.glyph.path.c.state":"Proved","research-forge.consumer.glyph.request.detail":"Examples, rules and a partial program define the search boundary.","research-forge.consumer.glyph.request.label":"Transform every supported input and preserve the stated limit.","research-forge.consumer.hero.eyebrow":"Dweve Forge, Verified Program Discovery","research-forge.consumer.hero.lede":"Dweve Forge is a research project that searches for programs satisfying examples, constraints or partial specifications, improves valid candidates across explicit objectives, and records the evidence supporting each result.","research-forge.consumer.hero.ledgerLabel":"Research note","research-forge.consumer.hero.ledgerPill":"Active","research-forge.consumer.hero.ledgerPurpose":"Purpose","research-forge.consumer.hero.ledgerPurposeValue":"Discover, compare and check programs","research-forge.consumer.hero.ledgerStatus":"Status","research-forge.consumer.hero.ledgerStatusValue":"Active internal research","research-forge.consumer.hero.primary":"Follow one discovered program","research-forge.consumer.hero.secondary":"See what verified means","research-forge.consumer.hero.titleAccent":"Let the machine search for how.","research-forge.consumer.hero.titleLead":"Describe what should happen.","research-forge.consumer.intent.body":"Forge research begins with examples, rules or a partly written program. Examples show specific cases. Rules state what must remain true more generally. A partial program preserves decisions that should not be handed to the search.","research-forge.consumer.intent.eyebrow":"The starting point","research-forge.consumer.intent.footer":"Once the behaviour is clear, the machine can search many possible ways to produce it.","research-forge.consumer.intent.pillExamples":"Examples","research-forge.consumer.intent.pillRules":"Rules","research-forge.consumer.intent.pillSketch":"Partial program","research-forge.consumer.intent.secondaryLeft":"A prompt can ask for code and receive something plausible. It does not, by itself, define a complete standard against which that code can fail.","research-forge.consumer.intent.secondaryLeftLabel":"A prompt","research-forge.consumer.intent.secondaryRight":"A specification fixes the behaviour, boundaries and permitted choices. Changing it creates a different research problem rather than rescuing a weak candidate.","research-forge.consumer.intent.secondaryRightLabel":"A specification","research-forge.consumer.intent.sideExamplesDetail":"For this input, produce this output.","research-forge.consumer.intent.sideExamplesLabel":"Examples","research-forge.consumer.intent.sideFooter":"The requirement comes first; the implementation remains open.","research-forge.consumer.intent.sideMetaLabel":"Fixed during search","research-forge.consumer.intent.sideMetaValue":"Behaviour and scope","research-forge.consumer.intent.sideRulesDetail":"For every supported input, preserve this property.","research-forge.consumer.intent.sideRulesLabel":"Rules","research-forge.consumer.intent.sideSketchDetail":"Keep this structure and discover the missing part.","research-forge.consumer.intent.sideSketchLabel":"Sketch","research-forge.consumer.intent.sideStatus":"Start","research-forge.consumer.intent.sideSubtitle":"Each provides a different kind of boundary","research-forge.consumer.intent.sideTitle":"Three ways to state intent","research-forge.consumer.intent.titleAccent":"before choosing the implementation","research-forge.consumer.intent.titleLead":"Describe the behaviour","research-forge.consumer.intent.visualFooter":"The program changes shape. The requirement does not.","research-forge.consumer.intent.visualMeta":"Illustrative path","research-forge.consumer.intent.visualStatus":"Research active","research-forge.consumer.intent.visualSubtitle":"An illustrative public view of a program-discovery experiment","research-forge.consumer.intent.visualTitle":"One requirement, several candidate paths","research-forge.consumer.proof.body":"A formal result can prove that a program satisfies a stated property for supported inputs and semantics. It does not prove that the requirement was wise, complete or suitable for every real environment.","research-forge.consumer.proof.eyebrow":"What the badge should say","research-forge.consumer.proof.footer":"Sometimes the strongest honest result is that the machine cannot produce a program.","research-forge.consumer.proof.pillAssumptions":"Assumptions visible","research-forge.consumer.proof.pillLimits":"Limits visible","research-forge.consumer.proof.pillScoped":"Scoped","research-forge.consumer.proof.secondaryLeft":"The program, property, assumptions and evidence stay together. If the program changes, the proof binding changes too.","research-forge.consumer.proof.secondaryLeftLabel":"The claim","research-forge.consumer.proof.secondaryRight":"Forge is active, unfinished internal research. It is not a product, public synthesis service or open-source download.","research-forge.consumer.proof.secondaryRightLabel":"The research boundary","research-forge.consumer.proof.sideAssumptionsDetail":"The inputs and environment covered by the claim.","research-forge.consumer.proof.sideAssumptionsLabel":"Assumptions","research-forge.consumer.proof.sideFooter":"The proof strengthens a precise claim, not a vague promise.","research-forge.consumer.proof.sideLimitsDetail":"What the result does not establish.","research-forge.consumer.proof.sideLimitsLabel":"Limits","research-forge.consumer.proof.sideMetaLabel":"Strongest honest state","research-forge.consumer.proof.sideMetaValue":"Named, never implied","research-forge.consumer.proof.sideProgramDetail":"The exact candidate being checked.","research-forge.consumer.proof.sideProgramLabel":"Program","research-forge.consumer.proof.sidePropertyDetail":"The behaviour that is claimed.","research-forge.consumer.proof.sidePropertyLabel":"Property","research-forge.consumer.proof.sideStatus":"Proof","research-forge.consumer.proof.sideSubtitle":"Four parts that must stay together","research-forge.consumer.proof.sideTitle":"A proof statement","research-forge.consumer.proof.titleAccent":"not correct in every possible world","research-forge.consumer.proof.titleLead":"Verified under these rules","research-forge.consumer.proof.visualFooter":"Unknown, impossible, ambiguous and outside scope remain valid research outcomes.","research-forge.consumer.proof.visualMeta":"Illustrative evidence","research-forge.consumer.proof.visualStatus":"Scope visible","research-forge.consumer.proof.visualSubtitle":"Testing, bounded checks, formal proof and execution linkage are different results","research-forge.consumer.proof.visualTitle":"The assurance ladder keeps its rungs separate","research-forge.consumerHero.titleSuffix":"finding better routes","research-forge.d02603176f":"Universal","research-forge.d092bf9ea1":"Explore the research","research-forge.d0f4e7e15e":"the graph keeps them exact","research-forge.d105692d52":"Selected candidate graph","research-forge.d1a475961a":"A bounded complete search can find the smallest expression in a narrow language. Counterexample guided refinement tends to find robust structured programs. Constraint led search resolves difficult bit level regions. Exploratory search reaches unusual implementations.","research-forge.d1b06384eb":"Examples, rules or a partly written program.","research-forge.d1ed30ebcf":"Fixed boundary","research-forge.d1f8a8cdec":"A merge is only ever as strong as the test that justified it.","research-forge.d1f8e5ea93":"Selection","research-forge.d2089fb287":"Theory routing","research-forge.d2316c0df0":"Five entries","research-forge.d23276442b":"The design space problem","research-forge.d23c4c8d4e":"One sentence, three usable forms","research-forge.d255672f1b":"and sharpens the request","research-forge.d286c609a6":"Specification version","research-forge.d2b02aa6ad":"the record binds both sides","research-forge.d2bad80400":"A plain request separating into examples, a rule and a sketch, beside an answer written straight from the sentence that has nothing to check it against","research-forge.d2d0b16b22":"Remove structural duplicates and observed duplicates.","research-forge.d2d43bec88":"Target backends (evaluation scope)","research-forge.d35260a00f":"Targets","research-forge.d362822809":"Where to bring the problem","research-forge.d36f29cacf":"Reconcile","research-forge.d3d6314184":"Each candidate is a line across every axis rather than a point on one.","research-forge.d3dee74f70":"The formal result, and a separate check of it where available.","research-forge.d3ec6e1bad":"The semantic object Kera receives, with its obligations attached.","research-forge.d4621d18f0":"with a stated boundary","research-forge.d4a74b503a":"Read the docs","research-forge.d4ccefcb5e":"none of the four ends by producing something plausible instead","research-forge.d50b109f99":"Several derivations stay alive at once, and the final choice waits for objective evidence.","research-forge.d51fb63a04":"every result points back to it","research-forge.d5383ea7af":"Recorded","research-forge.d5dc89d194":"For supported Kera contracts, pure execution repeats bit identically without a seed, including the covered floating family paths. When a program deliberately consumes random state, that state is a declared input, and reusing it reproduces the entire run.","research-forge.d5ec4f1c39":"Why this program exists","research-forge.d5f412e831":"Kera","research-forge.d659989a95":"Forge searches a language of typed computational operations. Inputs, outputs, shapes, numerical families, effects, capabilities, ownership and target restrictions decide which compositions are legal, so invalid programs are excluded structurally rather than generated and repaired after evaluation. The language is chosen with the packet and closed for the run.","research-forge.d66c44dfdf":"Impossible","research-forge.d6a6f2deb1":"What the loop does","research-forge.d71df112ac":"What the search may do","research-forge.d769ded7e8":"Candidate","research-forge.d79c0b71d1":"whose first correct program is not enough","research-forge.d7e5b39755":"Ambiguity becomes visible before it becomes code. Two candidates can satisfy every supplied example and still disagree on an input nobody wrote down. Forge reports that disagreement and asks for another requirement rather than picking one behaviour quietly.","research-forge.d7e94eb0fb":"Every organisation relies on small, critical pieces of code. Forge asks whether a program-synthesis search can propose candidate implementations under a declared specification and measurement plan. The 2025 report documents an experiment, not production readiness; no published benchmark establishes an optimal or fastest version.","research-forge.d835dab5b4":"exact integer","research-forge.d90c9bd5a7":"size 2 to 4","research-forge.d9f6acb036":"extraction happens last","research-forge.da09c06014":"Forge begins with a behavioural contract that does not move. Search may propose thousands of implementations, and examples, counterexamples and formal queries decide which of them remain. What comes out is a typed program candidate with a derivation, an objective vector and a stated assurance level.","research-forge.da7a712c59":"What the program must do","research-forge.daec3d5393":"Counterexamples, proofs and assurance transitions.","research-forge.db1c784524":"Reference","research-forge.dc131e9db4":"What the packet pins","research-forge.dc16ac61b4":"one axis cannot rank a frontier","research-forge.dc5b5aba63":"tightens the requirement","research-forge.dcd69b02b3":"The specification is consistent","research-forge.dd00b8f82f":"Named assurance","research-forge.dd3c9b9d09":"Do not fix the rewrite order","research-forge.dd3e8f4841":"Tests establish behaviour on the cases that were run. Exhaustive bounded checking covers a declared finite domain. Formal verification proves an encoded relation under stated assumptions. Execution linkage binds the result to the graph and plan that actually ran. Forge reports which of those a candidate reached, because a decision made on the wrong one is a decision made on the wrong evidence. There are five rungs in that ladder, and a candidate holds exactly one of them at a time.","research-forge.de135d6b61":"pure region","research-forge.de56d45fd4":"and what it is not allowed to touch","research-forge.de9e9925af":"the parts that have to stay together","research-forge.dfda3a3599":"Reviewable","research-forge.e0078f1adb":"It may not add file or network access that was never permitted. It may not change the kind of number the answer uses. It may not soften the requirement because a promising candidate very nearly met it.","research-forge.e03608577a":"Boundary review","research-forge.e048b8a355":"How guarantees compose through optimisation and planning.","research-forge.e15760689d":"Refine","research-forge.e192f8980b":"Static models rank candidates before anything runs. Calibrated target profiles sharpen those estimates. Measured runs confirm or correct them. Each stays labelled, so a predicted latency is never displayed in the place a measured one would sit.","research-forge.e24f8562eb":"the implementation becomes a result","research-forge.e29a79fe0c":"Review","research-forge.e2f9cea1dd":"what each form does and does not settle","research-forge.e31ae17fe2":"What it leaves open","research-forge.e340683de2":"The declared concrete cases passed.","research-forge.e341bf4b5e":"Completeness belongs to the declared space, and the report states which space that was.","research-forge.e380a981e1":"Two engineering sequences","research-forge.e3a3474f57":"Equivalent source strings can describe the same computation, and similar looking source can hide different effects. Working on the graph makes structural sharing, candidate comparison, proof binding and provenance exact, instead of something inferred from text after every transformation.","research-forge.e3aa756f4f":"Three views","research-forge.e3f3e0b2d5":"A non-answer with a reason attached is a decision the organisation can act on today.","research-forge.e3f4660921":"When the search keeps several correct programs, somebody has to say which trade-off matters. That is a decision, and Forge records it as one, together with the programs it did not choose and the reason each was passed over.","research-forge.e40786cd04":"the graph is named, not the source","research-forge.e43a425d4c":"One failing case","research-forge.e4709d4a03":"Something in the declared language meets the requirement.","research-forge.e4ec169f06":"Three iterations, one requirement getting sharper","research-forge.e5a5debd01":"and directs the next investment","research-forge.e5e6eefa7c":"each can name a different best candidate","research-forge.e5fa3a8592":"Add the evidence that separates the competing behaviours.","research-forge.e6737991ff":"Candidate search","research-forge.e6c167fd27":"MEMBER","research-forge.e6f72dbc9e":"Well formed through execution linked never blur together.","research-forge.e70fb2879c":"that changes the answer","research-forge.e713d42aa6":"SUBJECT","research-forge.e73791d2ee":"The record is designed to be read by someone who was not there. It names the specification version rather than a branch, the candidate graph rather than a file, and the dominance relation rather than a preference, so a reviewer can ask why not candidate B and get an answer.","research-forge.e78c82b9d8":"Equivalent program space","research-forge.e792eed957":"Enumerate by type and size","research-forge.e79545edad":"Forge can find a program, find several, find a counterexample that ends one, or find that nothing in the permitted space works at all. Any of those can happen in a single run.","research-forge.e7c6bfda5f":"Examples, constraints and sketches","research-forge.e7eaf3097f":"UNDECIDED","research-forge.e83744eb1b":"One graph through the Dweve stack","research-forge.e89c5a1fe5":"Request a demo","research-forge.e8c9206319":"You state the behaviour","research-forge.e93a01e74c":"Inputs and outputs","research-forge.e9a46a96e9":"Ambiguous","research-forge.e9c366b4f3":"Requirement","research-forge.e9e1bb076f":"Proof, graph, plan and result identity are bound together.","research-forge.ea2f183ae8":"A failure that names an exact input teaches the search more than a failure that names a score.","research-forge.ea66222972":"Define the behaviour, the candidate language, the objective vector and the evidence you need. Forge can turn that into a controlled search, comparison and verification experiment.","research-forge.ea66d3cd71":"Formally verified","research-forge.eae192773b":"Made by","research-forge.eb01bf04c9":"Examples","research-forge.eb5d2f4a58":"JIT","research-forge.eb65476556":"a refusal before evaluation costs nothing","research-forge.eb86bd10d0":"Test and formally query the survivors.","research-forge.ebc93602b0":"Research partner program","research-forge.ebd1b8a0ed":"Correctness and cost stay apart","research-forge.ebf002ed26":"What must every permitted input produce or preserve?","research-forge.ec00edb305":"Measurement status","research-forge.ec80d62108":"A three axis trade-off plot with dominated candidates greyed, a policy selector choosing one non-dominated member, and a control that adds an objective and redraws the frontier","research-forge.ec8c6779f3":"Derivation","research-forge.eca98aa4dd":"The standing invariant","research-forge.ecc4622e4a":"Intent as asset","research-forge.eccd8c22c7":"Cases","research-forge.ed03c68d9c":"Partly","research-forge.ed625e27bc":"the answer is read off the record, not rebuilt from it","research-forge.ed834ee730":"Two programs, every example, one disagreement","research-forge.ed868fa2d4":"What one answer settles","research-forge.edd8fb596d":"What the organisation wants","research-forge.ee531c138e":"one identity across the lifecycle","research-forge.ee6e0d9004":"what Kera returns","research-forge.eebc8ec4db":"Largest working set","research-forge.eebfc58277":"There is usually more than one good answer, and saying which one you picked is part of the answer.","research-forge.ef4e3a4971":"What can still differ","research-forge.ef73fdd1c8":"Four cases","research-forge.f04208c0f4":"the outer three rings can be scrutinised without opening the innermost","research-forge.f061352d1c":"Family, width, rounding and the error envelope in force.","research-forge.f0aa98e438":"The problem is written down first","research-forge.f128a0033d":"Forge compares valid candidates across operation count, critical path, memory traffic, working set, register pressure, code size, estimated energy, portability, proof complexity and target fit. Which of those are active belongs to the experiment packet, chosen before any candidate is measured, so the comparison cannot be tuned after the results are in.","research-forge.f1513553a0":"Five candidates implementing the same specification, each with a different structural silhouette and objective ribbon, with the first discovered candidate marked as dominated","research-forge.f19a088441":"A field of candidate program shapes in three states around a fixed requirement frame at the centre that never changes size","research-forge.f1e6269a35":"A Forge candidate is a typed semantic graph. Its nodes retain operations, dependencies, values, effects, ownership and numerical obligations, and search adds, removes and reconnects regions while the interface stays well formed. Source syntax is one view of that object rather than its identity, which is why a proof can bind to it and survive a change of spelling.","research-forge.f21eba9d4c":"The behaviour being claimed about it.","research-forge.f2b83c0462":"Review candidate output","research-forge.f3263fc33a":"Which inputs, effects and environments are inside scope?","research-forge.f33b37791c":"one fixed requirement","research-forge.f34faaf18c":"What stays fixed for the run","research-forge.f3717fe94b":"Three joins, one typed language","research-forge.f3b8596ff9":"Sketches","research-forge.f3e0a2c003":"Operation, state transition and every effect it is permitted to have.","research-forge.f44f712120":"the method stays research","research-forge.f4b90ff6c9":"enumerative, CEGIS, GP, MCTS","research-forge.f4c0773264":"Types, effects, ownership and interfaces are valid.","research-forge.f5330c10d4":"Two systems, one object","research-forge.f539273fc2":"It passed the declared concrete cases.","research-forge.f53a569905":"The institutional problem","research-forge.f591672335":"end to end","research-forge.f5def394f5":"The exact candidate that was checked.","research-forge.f61f151c35":"Describe what happens","research-forge.f6c1c2d45c":"the selected candidate keeps the policy that selected it","research-forge.f6fbfa37a0":"Effect bounded","research-forge.f7313a2c50":"Most systems that write code are asked to continue a text in a plausible way. Forge is asked to satisfy a description of what a program must do. It searches for implementations, rejects the ones that fail on a specific input, compares the ones that survive, and states exactly how strongly the result has been checked.","research-forge.f740162265":"Diffable","research-forge.f793bcd5e3":"Selected by the current policy","research-forge.f7bce3aeb0":"Three kinds of sameness","research-forge.f7fcfa132e":"Verified always means verified against something stated.","research-forge.f85d540ea4":"They also fail differently. A candidate can pass every supplied example and still violate the quantified condition the examples were meant to illustrate. The record names that difference, so passing a test set is never read back later as a proof.","research-forge.f8ad81d4ed":"Two programs can do exactly the same job and still be different to live with. One finishes sooner. One moves less data around. One runs on more kinds of machine. One is simply easier to check. Improving any of those usually costs something on another, so Forge keeps the good ones rather than declaring a single winner.","research-forge.f915e592e0":"Settled enough to state plainly: an immutable specification, one typed candidate pool fed by several search behaviours, counterexamples as permanent obligations, a frontier instead of a hidden score, named assurance rungs, and a graph identity that survives the handoff to Kera.","research-forge.f91cf3695e":"what leaves Forge and what Kera returns","research-forge.f942052ae1":"The first correct program","research-forge.f95d9699ab":"not the definition of best","research-forge.f9743247fa":"Read the documentation","research-forge.f97f6d5c34":"The kind of number in the answer","research-forge.f9917655d9":"The verified and rejected candidates that mattered.","research-forge.f9d589b5e4":"The label names the rung, and the record beside it names the scope that rung covers.","research-forge.fa6b511877":"May not change","research-forge.fa7f633b0c":"Three candidate dossiers stopped at different assurance rungs, each opening the evidence behind its label, with promotion shown as unavailable without evidence","research-forge.fa8d0afff2":"and render source at the edge","research-forge.fb588797f2":"Software that writes","research-forge.fba63933d7":"proving establishes behaviour","research-forge.fbe8d4180f":"One seed, many forms","research-forge.fc5fed48be":"Search the graph","research-forge.fc7583ec76":"Immutable specification","research-forge.fca77b7e3a":"At a glance","research-forge.fca8a06b17":"Forge records which kind of sameness justified each merge, so a cheap deduplication during search is never read back later as a semantic result.","research-forge.fd2145e1f8":"The order that never changes","research-forge.fd9cfb5232":"Several search behaviours produce one kind of typed candidate.","research-forge.fdd0dfedc0":"Four things hold","research-forge.fe03c35158":"Semantics","research-forge.fe0863e1b3":"Five assurance levels","research-forge.fe08eef5c7":"Steps that belong to Dweve's internal method appear in the chain as sealed nodes. Each publishes its inputs, its outputs and its identity, so the chain stays connected while the strategy inside it remains part of the research.","research-forge.fe17f86199":"Design space","research-forge.fe8b95b52a":"The selected graph moving from Forge into Kera along one lane, with the neighbouring Dweve systems that read the same object, and the result identity returning to it","research-forge.fec325ce2f":"Moves less data","research-forge.fef04acdce":"what survives at each candidate size","research-forge.ff52cebd1d":"A finite declared domain was exhausted.","research-forge.ff63942f4e":"A chain a reviewer can walk","research-forge.ff75e0dce3":"Unclear","research-forge.ffa7344f37":"The public Forge material explains the specification, the alternatives that were discovered, the counterexamples that ended some of them, and what the research can actually prove.","research-forge.technicalHero.titleSuffix":"Z3","section_st_a2_split-spec-sheet.7c9a7c0610":"Detail","section_st_a6_split-scenario-triad.f75fd3a884":"No runtime deps","section_st_a6_split-scenario-triad.143ac4ef35":"Single binary","section_st_a6_split-scenario-triad.c61f134d87":"Three surfaces","section_st_a6_split-scenario-triad.215475056e":"WHERE IT RUNS","section_st_a6_split-scenario-triad.a794a586f0":"Sealed-room ready","section_st_a6_split-scenario-triad.42d52c32ea":"Local model","section_st_a6_split-scenario-triad.fe6168e59f":"No network","section_st_a6_split-scenario-triad.7d93f83c3e":"Volume-mounted code","section_st_a6_split-scenario-triad.bee0cb05f8":"Kubernetes","section_st_a6_split-scenario-triad.9f1141549f":"Docker","section_st_a6_split-scenario-triad.5315129cfe":"macOS, Linux, Windows","section_st_a6_split-scenario-triad.a89193f674":"No install","section_st_a6_split-scenario-triad.f600b9e709":"One binary","section_st_a7_split-connector-grid.4e6822a6d4":"Hot-reload","section_st_a7_split-connector-grid.19e35f0609":"Set in TOML","section_st_a7_split-connector-grid.d9de50b343":"Caller-driven inventory","section_st_a7_split-connector-grid.8be1bb51b7":"CONNECTORS","section_st_a8_split-scaling-profile.7e0861e04c":"Tunable in TOML","section_st_a8_split-scaling-profile.56d6732417":"Per-project ceiling","section_st_a8_split-scaling-profile.27a454915b":"Active dots reflect concurrent agents per tier.","section_st_a8_split-scaling-profile.0ea215ea0d":"BACKGROUND","section_st_a8_split-scaling-profile.9fc6fb7e03":"TEAMS","section_st_a8_split-scaling-profile.018d2cd1a5":"PARALLEL","section_st_a8_split-scaling-profile.16623c5d4a":"CHAINS","section_st_a8_split-scaling-profile.0fb79c96ed":"Solo → Team → Network","section_st_a8_split-scaling-profile.068f6b3ecc":"TEAM SCALE","section_st_a8_split-scaling-profile.53ebc572b4":"Network","section_st_a8_split-scaling-profile.218887269a":"Team","section_st_a8_split-scaling-profile.9fc93acaa4":"Solo","section_st_a9_split-time-lost-donut.7c9a7c0610":"Detail","section_st_b5_request-lifecycle.47e364232a":"audit #4521","section_st_b5_request-lifecycle.4d3535f846":"patch · session.rs","section_st_b5_request-lifecycle.6c2519cd62":"Tool execution","section_st_b5_request-lifecycle.f6d1c823ab":"session #128 · 14:02","section_st_b5_request-lifecycle.636de0d0c3":"> \"fix this bug\"","section_st_b5_request-lifecycle.0208131a7d":"User request","section_st_b7_audit-chain.9239506454":"0d4e · 8f2c · 51a9 · 73be","section_st_b7_audit-chain.a383df4adb":"a015 · 7c93 · 3e6f · d28b","section_st_b7_audit-chain.efd3faebc5":"9e1b · 22a7 · 8d50 · 6b3c","section_st_b7_audit-chain.4df252b458":"4f2a · b7d1 · 1c83 · e0a4","section_st_b8_defense-stack.eee0f04cba":"YOUR CODEBASE","section_st_b8_defense-stack.89b6e2a784":"DEFENCE IN DEPTH","section_st_c2_dual-loop-flow.9d29573ea6":"tool / step","section_st_c2_dual-loop-flow.08ab1ac55a":"plan / replan","section_st_c5_integration-spoke.55d0677ac3":"All connectors funnel through the same audit + permission layer.","section_st_c5_integration-spoke.c29eb7e425":"Local agent","section_st_c5_integration-spoke.14afd82a7f":"AURA","section_st_c5_integration-spoke.ed0afbab5a":"GitLab CI","section_st_c5_integration-spoke.39540900bb":"GitHub Actions","section_st_c5_integration-spoke.a2feefe9af":"Jenkins","section_st_c5_integration-spoke.ab4115a7b2":"External tools","section_st_c5_integration-spoke.70c123381f":"JSON-RPC 2.0","section_st_c5_integration-spoke.dc99d54d99":"Local","section_st_c5_integration-spoke.6466df1d3d":"Mistral","section_st_c5_integration-spoke.a19ee5a9fd":"OpenAI","section_st_c5_integration-spoke.b780a23b53":"Anthropic","section_st_f1_cta-dark.90e40d5043":"Get started","toc-rail.f5cbdf6bfb":"Contents"}
