← Part 26

AQ-SDD-001-S1

A fully worked pre-registration of sections 1-9 for the control run of AQ-NODE-01 on the optical bench — objective, question, falsifiable hypothesis, version fields, layers exercised, protocol, no injected faults, and criteria that declare no numeric targets — with sections 10-17 left unfilled and the reason stated.

Charter artifact · gated by Part 26 · revision 0, draft for internal review

AQ-SDD-001-S1 — Worked Dossier: Scenario 1, Normal Conditions

Status: DRAFT, not sealed. This document shows sections 1 to 9 as they would be registered before the first run of AQ-NODE-01, and shows sections 10 to 17 unfilled with the reason. It asserts no result.

DRAFTED BEFORE THE ARTICLE EXISTS

AQ-NODE-01 has not been built. The version fields in section 5 therefore carry field definitions and no values. Sealing is prohibited until every field in section 5 is populated from built hardware and both reviewers have signed. Nothing here is evidence of anything: current level Concept for the integrated path, no run attempted.

SECTION 1 — DOSSIER IDENTITY AND REGISTRATION

FieldRegistered value
DossierAQ-SDD-001-S1
Run idassigned at seal, format RUN-S1-nnn
ScenarioS1, Normal conditions. This is the control scenario against which S2 and later fault-injection scenarios are read.
ArticleAQ-NODE-01 (the same article appears as AKQ-NODE-1 in Parts up to 12)
Reach ladderRung 1 of 6: optical bench. No metro fibre, free-space, HAPS, CubeSat, LEO or constellation element is present.
TierY1 (Year-1 prototype)
Level heldTheory for the trust-state reasoning; Concept for the integrated acquisition-to-decision path
Level soughtLab validation, bench scope only, for the path L1/L2 → TB-2 → L4 → L5 → TB-4 → L6
ReviewersR1 scientific; R2 safety and governance (L9). Neither is an author.
Supersedesnone

SECTION 2 — OBJECTIVE

To establish, under bench conditions with no injected fault, the baseline behaviour of the acquisition-to-decision path of AQ-NODE-01 across trust boundaries TB-1 to TB-5, and to produce the first measured distributions from which later thresholds will be defined. The run informs two programme decisions: whether the fault-injection scenarios S2 onward may proceed against this article, and whether any metric in section 9 produces a distribution stable enough to carry a threshold at all. If the control run cannot be interpreted, no fault-injection result against this article can be interpreted either.

SECTION 3 — RESEARCH QUESTION

Under bench conditions with no injected fault, does AQ-NODE-01 hold trust state NORMAL for the full run while every value presented to L4 carries a DC-1 tag, and is every L5 decision taken during the run reconstructable from the Evidence Fabric alone?

SECTION 4 — HYPOTHESIS AND FALSIFICATION CONDITION

H-S1. With all commands valid, authorised and issued at the cadence fixed in section 7, and with no fault injected, the trust state remains NORMAL for the whole run, every L5 evaluation returns execute, every value entering L4 is tagged, and an independent reviewer can rebuild each decision from L6 records without recourse to console logs or operator recollection.

Falsification. H-S1 is falsified by any one of: (a) a transition out of NORMAL that cannot be attributed to a recorded environmental observation; (b) any untagged value reaching L4; (c) any consequential transition that a reviewer cannot rebuild from L6 alone; (d) any Q4 outcome that permits more than Q1 to Q3 allowed.

Secondary hypothesis H-S1b. The characterisation statistics M-06 and M-07 are stationary within the run. The assessment method — the statistic, the window and the comparison — is fixed here before the run; no threshold value is declared, because none can be justified before the first distribution exists.

SECTION 5 — SYSTEM VERSION AND CONFIGURATION RECORD

FieldRequired formValue at draft
V-01AQ-NODE-01 article revision and build sheet idunpopulated, hardware not built
V-02Optical bench configuration id and layout drawing revision (L0)unpopulated
V-03Entropy source part number, serial, and last characterisation date (L1)unpopulated
V-04Timing reference: discipline source, holdover configuration, last comparison record (L2)unpopulated
V-05FPGA bitstream SHA-256 and toolchain version (TB-2 deterministic acquisition)unpopulated
V-06AQ-TSE-01 build id plus rule-set version (L4, TB-3)unpopulated
V-07L5 command authority policy id governing Q1 to Q4unpopulated
V-08Hardware gate configuration at TB-4, including its interlock state at power-onunpopulated
V-09Evidence Fabric schema version and writer build (L6, TB-5)unpopulated
V-10Calibration certificate ids and dates for every instrument named in section 7unpopulated
V-11Environmental logger ids and sampling configurationunpopulated
V-12Operator console software commit id and configuration file hashesunpopulated

SECTION 6 — ARCHITECTURE EXERCISED

LayerStatusNote
L0exercisedBench optical path only. No propagation path of any kind is represented.
L1exercisedEntropy source under characterisation; M-06 is the recorded statistic.
L2exercisedTiming reference and its integrity checks; M-07.
L3stubbedKeys issued by a bench-local test authority. This does not represent key custody, enrolment or revocation, and no S1 result may be read as evidence about L3.
L4exercisedAQ-TSE-01 is the primary subject of the run.
L5exercisedQ1 to Q4 evaluated for every synthetic command. Q1 to Q3 pass by construction in S1; the run therefore observes Q4 in isolation.
L6exercisedRecording is itself under test through M-05 and M-09.
L7stubbedSingle node. No orchestration, no peer, no network path.
L8not presentAdvisory only and excluded from the decision path by construction. No L8 output is admitted to L4 or L5 in S1.
L9exercisedAbort authority, review roles and the safety brief for bench operation.

Trust boundaries. TB-1 exercised (physical bench to system). TB-2 exercised (deterministic acquisition on FPGA). TB-3 exercised (trust reasoning). TB-4 exercised, with the physical effect limited to the bench gate and its indicator. TB-5 exercised (runtime to evidence).

Conflicts and decision boundaries. No conflict case among CF-1 to CF-7 is deliberately induced in S1; a conflict that arises is a section 13 observation and falsifies H-S1 if it moves the trust state. Only the decision boundaries traversed by a NORMAL-state execute path are exercised; every boundary among B-1 to B-5 not traversed is listed in section 16 as untested by this run.

Figure 1 - S1 path under test, acquisition to physical effect to evidence

  [L0 optical bench]
        |  TB-1 physical/system
        v
  [L1 entropy]  [L2 timing]
        |            |
        +-----+------+
              |  TB-2 deterministic acquisition (FPGA)
              |  every sample timestamped and tagged MEASURED (DC-1)
              v
     [L4 AQ-TSE-01 trust state]        TB-3 trust reasoning
     state in {NORMAL, RESTRICTED, CRITICAL, DENY, RECOVERING}
     S1 expectation: NORMAL for the whole run
              |
              v
     [L5 command authority]
     Q1 who sent it -> Q2 valid -> Q3 authorised now   (HARD)
                                   -> Q4 execute under this trust state
                                      (may only REDUCE what Q1-Q3 allowed)
              |
              |  TB-4 decision / physical effect, hardware-gated
              v
     outcome in {execute, execute-restricted, safe-hold, abstain, deny}
              |
              |  TB-5 runtime/evidence
              v
     [L6 Evidence Fabric]  -> DC-5 reconstruction source for M-05

  [L8 AI-assisted analysis] NOT PRESENT in S1: advisory only, and
                            no path into L4 or L5 exists in this run.

SECTION 7 — PROTOCOL

  • P-01 Record every section 5 field from the article as built; refuse the run if any field is unpopulated.
  • P-02 Verify calibration validity dates for every instrument; record certificate ids.
  • P-03 Power on with acquisition disabled and the TB-4 gate interlocked; record the cold-state register dump.
  • P-04 Start Evidence Fabric recording; write the run start marker and the seal hash reference; confirm the marker is readable back.
  • P-05 Warm-up period at the duration fixed in the bench procedure; environmental sample at start and end of warm-up.
  • P-06 Baseline acquisition with no commands issued; this window is the source for M-06, M-07 and M-08.
  • P-07 Release the TB-4 interlock; issue the synthetic command sequence C-01 onward at the fixed cadence. All commands are valid and authorised by construction.
  • P-08 For each command, record the Q1 to Q4 evaluation, the trust state at evaluation time, the outcome, and the gate response at TB-4.
  • P-09 Mid-run environmental sample and operator observation note, whether or not anything is observed.
  • P-10 Continue to the planned command count.
  • P-11 Stop commands, re-interlock the gate, continue acquisition for the tail period.
  • P-12 Stop recording; compute and record dataset hashes before leaving the bench.
  • P-13 Power down; record the shutdown register dump.
  • P-14 Operator writes section 10 deviations at the bench, before leaving it.

Abort criteria. Any condition on the L9 bench abort list; any operator uncertainty about safety; any loss of Evidence Fabric recording. A run that loses recording does not resume — it stops, and a new run identifier is issued, because a gap in L6 makes DC-5 unassessable for the whole run.

SECTION 8 — INPUT AND FAULT CONDITIONS

Controlled: command cadence; command set composition (all valid, all authorised); bench alignment configuration; planned command count; warm-up and tail durations.

Recorded, not controlled: ambient temperature, vibration, supply condition, operator identity, time of day. Each is sampled at the points fixed in section 7; a missing sample is recorded as undetermined under DC-2, never interpolated.

INJECTED FAULTS: NONE — THIS IS THE CONTROL

No fault among F-1 to F-14 is injected in S1. Each is deliberately excluded and scheduled to a later scenario. Their absence here is not evidence that the article handles them; S1 can produce no statement whatsoever about detection of any F-* condition. No attempt is made to induce RESTRICTED, CRITICAL, DENY or RECOVERING. Should any of those states appear, it is recorded in section 13 and falsifies H-S1.

SECTION 9 — METRICS, SUCCESS AND FAILURE CRITERIA

IDMetricTagSuccess criterionFailure criterion
M-01Trust state trajectory over the runMEASUREDNORMAL for the whole runAny transition out of NORMAL not attributable to a recorded environmental observation
M-02DC-1 tag coverage of values entering L4DERIVEDEvery value carries MEASURED, DERIVED or MODELLED. This is structural, not a tuned target.One or more untagged values
M-03Decision outcome distribution across C-01 onwardMEASUREDEvery command yields execute. An abstain or safe-hold is not itself a failure under DC-3 but is a section 13 observation and must carry its cause.Any deny or execute-restricted with no recorded cause; any outcome outside the permitted set
M-04Q4 reduction eventsMEASUREDZero, or each event traceable to a recorded trust-state inputAny Q4 outcome that permits more than Q1 to Q3 allowed. This is a specification violation: stop the run.
M-05Reconstruction completeness (DC-5), scored by reviewer replay from L6 aloneDERIVEDEvery consequential transition rebuilt without console logs or operator recollectionAny consequential transition not reconstructable
M-06Entropy source characterisation statistic (L1)MEASUREDDistribution recorded and stationary by the method fixed in section 4. Target undefined: the S1 distribution is the input from which a threshold for later scenarios is defined, as a stated quantile of that distribution, after the run.Statistic not computable from the recorded data; or non-stationarity with no recorded environmental correlate
M-07Timing integrity statistic (L2)MEASUREDAs M-06. Target undefined; the threshold rule is the same and is applied only after the distribution exists.As M-06
M-08Acquisition determinism at TB-2MEASUREDSample-to-record ordering monotone and gap-free across the runAny dropped or reordered sample not accounted for in the record
M-09Evidence Fabric write completenessDERIVEDFabric record count reconciles with the acquisition counter and the command countAny unreconciled difference
M-10Environmental record completenessMEASUREDEvery planned sample present, or explicitly written undetermined per DC-2A silently missing sample
WHY NO NUMBERS APPEAR HERE

S1 declares no numeric performance target, by design. Before the first run there is no measured distribution from which a threshold could be justified, and a number invented now would become the number the article is later tuned to satisfy. Section 9 therefore fixes what is measured, how it is tagged, and the rule by which each threshold will be derived from S1 data. Thresholds enter the programme through a section 17 disposition and a new dossier, never through an edit to this one.

SECTIONS 10 TO 17 — UNFILLED

SecStatusReason
10UNFILLEDExecution Record: no execution has occurred. Written at the bench by the operator at step P-14.
11UNFILLEDRaw Data and Custody: no dataset exists. Hashes are computed at P-12 before anyone leaves the bench.
12UNFILLEDMeasured Results: no measurement exists. Any value written here before the run would be MODELLED and would not belong in this section at all.
13UNFILLEDFailure Observations: mandatory after the run. If nothing is observed, the entry requires the signed detection-coverage justification defined in AQ-SDD-001 §5 — which F-* conditions this instrumentation could have detected, and at what sensitivity.
14UNFILLEDAnalysis: the verdict on H-S1 must be one of supported, not supported, or undetermined, and cannot be anticipated.
15UNFILLEDEvidence Level: the article stands at Concept and Theory. A bench run can at most support Lab validation in bench scope; it can support nothing about field, dynamic-platform or flight conditions.
16UNFILLEDThreats to Validity: the known-in-advance limitations (L3 stubbed, L7 stubbed, L8 absent, single article, bench-only L0, untraversed B-* boundaries) are carried forward from sections 6 and 8 and completed with what the run actually reveals.
17UNFILLEDDisposition: whether S2 fault injection may proceed against this article, and which thresholds S1 data can justify, are outputs of the run and not inputs to it.
WRITING BELOW THE BOUNDARY VOIDS THE DOSSIER

Completing any of sections 10 to 17 before the seal and the run voids pre-registration under AQ-SDD-001 §2. The dossier would be marked VOID, retained in the record, and replaced by a new identifier carrying a supersedes link. Until sections 5 and 10 to 17 are populated from a real run, this document is a registered intention and nothing more.