Expand description
Safe, bounded TOSA graph ingestion for virtio-accel providers.
This crate validates a TOSA FlatBuffer before exposing zero-copy borrowed views. The public API contains no generated FlatBuffers types and no unchecked accessors. Validation is deliberately split into two layers:
parseenforces the serialization envelope, resource limits, stable TOSA 1.0 schema boundary, names, references, and operator/attribute correspondence;Model::validate_forexhaustively enforces the stable operator arities, operand kinds, ranks, profiles, extensions, level limits, attributes, compile-time constants, static shapes, control-flow signatures, and numerical parameter rules for a declaredTarget; and- provider-specific capability and
Op::CUSTOMpolicy can be layered throughModelValidator.
Semantic validation proves model legality; it does not execute tensor data or replace a
backend’s runtime checks for data-dependent TOSA REQUIRE conditions.
The checked-in schema is from TOSA Tools v2026.05.0. The tools release implements TOSA
specification 1.0.1 and appends draft TOSA 1.1 entries; parse accepts stable graph version
1.0.0 and rejects those appended entries.
Structs§
- Analysis
Options - Limits for optional analysis work. They do not relax semantic or parser limits.
- Analysis
Span - Compact half-open span into one of
TosaAnalysis’s indexed slices. - Analyzed
Block - One basic block and its precomputed execution order.
- Analyzed
Operator - One operator indexed independently of serialized names.
- Analyzed
Region - One region and its contiguous block span.
- Analyzed
Value - One globally indexed value in a model. Names and serialized payloads remain borrowed.
- Arity
- Accepted serialized operand counts for an operator.
- Attribute
Kind - Discriminant of an operator’s serialized attribute table.
- Basic
Block - Borrowed basic-block view.
- Basic
Blocks - BlockId
- Cache
Insert Error - An insertion that could not reserve its one bounded cache entry.
- Capability
Descriptor - Conservative semantic admission descriptor for one exact TOSA target.
- DType
- A TOSA tensor data-type discriminant.
- DType
Capability - One dtype admitted in explicitly listed graph roles.
- DType
Constraints - Extension
Set - TOSA 1.0 profile-extension bits.
- Graph
Capabilities - Whole-graph structural boundary that is not reducible to an operator bit.
- I32List
- Borrowed FlatBuffers vector of little-endian
i32attribute values. - I32Values
- Exact-size iterator returned by
I32List::iter. - Level
Limits - Argument ceilings assigned by a TOSA 1.0 implementation level.
- Limits
- Resource ceilings applied before and during graph traversal.
- Model
- A verified, zero-copy TOSA graph.
- NanPropagation
Mode - Op
- A TOSA operator discriminant.
- Operator
- Borrowed operator view.
- Operator
Capability - One implemented operator and the conservative restrictions a scheduler must preserve.
- Operator
Constraints - Operator
Id - Operators
- Optimization
Hints - Numerically safe and provider-conditional lowering opportunities.
- Profile
Set - Set of TOSA base profiles implemented by a target.
- Region
- Borrowed region view.
- Region
Id - Regions
- Resize
Mode - Rounding
Mode - Runtime
Error - Located runtime-specialization failure.
- Runtime
Validation - Result of checking every dynamic CTC value needed by one specialization.
- Runtime
Value - One host-readable dynamic CTC value supplied for specialization.
- Semantic
Validator - Complete stable-TOSA semantic pass for a declared device-neutral target.
- Shape
- Borrowed shape-value view.
- Shape
Values - Exact-size iterator over little-endian
i64shape values. - Shapes
- Specialization
Cache - Small exact-key LRU for compiled shape specializations.
- Specialization
Key - Exact, collision-safe key for one set of dynamic shapes and CTC bytes.
- Specialization
KeyBuilder - Bounded builder for provider cache keys.
- Stats
- Counts collected during the bounded validation pass.
- String
List - Iterator over borrowed TOSA symbol names.
- Target
- Device-neutral target requirements carried in
virtio-accel’s opaque target words. - Tensor
- Borrowed tensor view.
- Tensors
- Tosa
Analysis - Compact provider-neutral overlay used by lowering and specialization code.
- ValueId
- Value
Roles - Version
- Stable TOSA graph version.
Enums§
- Analysis
Error - Failure while producing a compact lowering plan.
- Analyzed
Value Kind - Zero-copy source value retained by an analyzed plan.
- Artifact
Error - Constant
State - How an analyzed value becomes constant for lowering.
- Error
- Failure returned for malformed, unsupported, or over-budget input.
- Integer
Error - A TOSA integer arithmetic precondition was not satisfied.
- Level
- TOSA implementation level.
- Name
Kind - OpAttributes
- Safe, exhaustive view of the attribute payload used by a stable TOSA 1.0 operator.
- Operand
Role - Operand side used in semantic diagnostics.
- Resource
- Runtime
Condition - Conditions that a provider may need to lower or inspect at execution time.
- Runtime
Condition Support - Provider treatment of semantic runtime conditions derived during TOSA analysis.
- Runtime
Error Kind - Failure while resolving or checking dynamic CTC data.
- Semantic
Error - Located semantic validation failure.
- Semantic
Error Kind - Operator-level failure after the serialization envelope has already been validated.
- Specialization
Error - Failure while constructing a canonical specialization key.
- Target
Error
Constants§
- ARTIFACT_
FORMAT - Raw TOSA FlatBuffer payload (
"TOSA"as a big-endian four-character code). - SCHEMA
- TOSA schema source pinned into this crate.
- SCHEMA_
RELEASE - Upstream TOSA Tools release from which
SCHEMAwas copied. - SCHEMA_
SHA256 - SHA-256 of
SCHEMAas shipped by TOSA Toolsv2026.05.0.
Traits§
- Model
Validator - Extension point for semantic, profile, extension, or backend-capability validators.
- Tosa
Capability Provider - Optional host-side interface implemented by concrete TOSA providers.
Functions§
- apply_
scale_ 16 - Apply TOSA’s 16-bit fixed-point scaling helper exactly.
- apply_
scale_ 32 - Apply TOSA’s 32-bit fixed-point scaling helper exactly.
- dot_
i8_ i32 - Compute an exact signed INT8 dot product with INT32 accumulation.
- fp8e4m3_
to_ bf16_ bits - Convert one TOSA/OCP FP8 E4M3 bit pattern to BF16 storage bits.
- fp8e4m3_
to_ f32 - Convert one TOSA/OCP FP8 E4M3 bit pattern to an exactly representable
f32value. - fp8e5m2_
to_ bf16_ bits - Convert one TOSA/OCP FP8 E5M2 bit pattern to BF16 storage bits.
- fp8e5m2_
to_ f32 - Convert one TOSA/OCP FP8 E5M2 bit pattern to an exactly representable
f32value. - low_
precision_ storage_ bytes - Return the packed byte count for an INT4, INT8, FP8E4M3, or FP8E5M2 tensor.
- pack_
int4 - Pack two TOSA INT4 values, with
lowin the low nibble andhighin the high nibble. - parse
- Parse with finite production defaults.
- parse_
with_ limits - Verify and parse a stable TOSA 1.0 graph under caller-selected resource ceilings.
- rescale_
i32_ to_ i8 - Rescale one INT32 accumulator into a signed INT8 tensor value.
- unpack_
int4 - Decode one signed two’s-complement INT4 value packed low nibble first.
- validate_
runtime_ values - Validate dynamic CTC encodings and every associated mandatory
ERROR_IFcondition. - validate_
semantics - Validate stable TOSA operator, profile, extension, level, shape, and numerical constraints.