Trajectory Planning

Trajectory Planning

Isometric blueprint showing 3D flight trajectory planning for an autonomous aerial quadrotor drone: BLDC outrunner cutaway, aerodynamic thrust cones, executed cyan 3D polynomial spline threading an obstacle ring, prospective amber waypoint chunk, and crimson hover-recovery stopping suffix landing on a terminal perch.

Purpose

What does a physical machine do during the unbudgeted milliseconds when the next neural trajectory chunk is late?

A moving physical machine carries continuous momentum while high-capacity neural policies compute upcoming trajectory chunks. If an executing action sequence terminates before its successor arrives, coasting blindly consumes the clearance required for a safe stop. Conversely, abruptly splicing an unconstrained proposal into an ongoing trajectory demands instantaneous joint accelerations that violate actuator torque limits or trigger destructive structural resonance across the mechanical transmission.

Trajectory planning resolves this computational-physical mismatch by transforming discrete model inferences into continuous, kinematically feasible motion profiles. Every dispatched trajectory chunk must guarantee \(C^2\) continuity across chunk seams and carry an invariant, pre-verified stopping suffix. This stopping continuation ensures the real-time execution layer can arrest motion safely within current clearance bounds if downstream computation encounters tail latency or hardware faults. In the physical AI stack, planning reconciles the Brain’s asynchronous, variable-latency inference with the Nervous System’s hard real-time execution cadence.

Learning Objectives
  • Select trajectory horizons from replacement latency, target-evidence age, and the time the stop needs
  • Evaluate trajectory feasibility and seam continuity against the body’s actuator and transmission limits
  • Distinguish trajectory failures detectable before execution from those requiring monitoring during physical motion
  • Calculate the distance a matched stop suffix adds to the machine’s stopping budget and compare it with the clear distance
  • Specify the commitment deadline and matched stop that govern a replacement trajectory arriving late or never
  • Construct a trajectory record that the permission path can admit by content, from its parent lease, deadlines, and stop

Continuous Trajectories

The arm of the warehouse mobile manipulator, reaching for a mug on a moving conveyor, possesses physical mass, structural inertia \(\mathbf{M}(\mathbf{q})\), and continuous kinetic energy \(E_k = \frac{1}{2} \dot{\mathbf{q}}^T \mathbf{M}(\mathbf{q}) \dot{\mathbf{q}}\). It cannot change velocity or direction instantly. Even when upstream autonomy grants a time-bounded intent lease, authorizing motion toward a grounded semantic goal, that semantic permission alone cannot turn motor shafts. The machine must synthesize continuous nominal motion while target evidence remains valid, plus a separately authorized stopping continuation if tracking authority ends. On this machine the arm’s joint tracking loop evaluates feedback and setpoints at 1 kHz (datasheet; see the Reader Guide); that period does not specify the physical stopping response. Above this loop sits the Brain, where modern robot learning policies, such as Action Chunking with Transformers (ACT) (Zhao et al. 2023) or score-based Diffusion Policies (Chi et al. 2024), process multimodal observations to synthesize future reference paths on the application processor.1 Inference latency varies with workload and contention. The machine’s chunk policy is budgeted at an illustrative 40 ms per pass at P99, vision included, yet memory or scheduling interference can stretch a single pass beyond 150 ms, so the horizon is sized from the deployed tail rather than from the budget.

↰ Prerequisite: Kinetic energy (\(E_k\)) and joint torque limits are established in Kinetic Momentum.

If an architecture predicts actions one step ahead (\(N = 1\)), the motor tracking loop starves. If it generates a multi-step action chunk of \(N > 1\) setpoints across a finite future horizon, the machine must cross an execution seam, the junction where one chunk’s setpoints give way to the next. When an active trajectory chunk finishes executing before its replacement clears the tail of the inference distribution, the controller faces an execution discontinuity. If the controller clamps to the final position, the reference velocity steps to zero and asks the drive to remove the arm’s momentum within one servo tick. If a newly arrived chunk begins with a velocity or acceleration that diverges from the physical state of the moving mechanism, the commanded torque steps and excites the structure.

Definition 1.1: Kinodynamic feasibility envelope

Kinodynamic feasibility envelope is the subset of state space from which a physical machine can track a candidate trajectory while strictly satisfying simultaneous actuator torque limits, velocity ceilings, and jerk bounds, with position, velocity, and acceleration continuous across segment seams, without exceeding mechanical stopping margins.

  1. Significance: Geometric collision freedom is necessary but insufficient for physical execution; an arm may follow a collision-free path that nonetheless demands motor torques exceeding continuous thermal ratings or produces accelerations that tip an underactuated base. The envelope states the conditions under which the model predicts trackable motion; runtime sensing and actuator checks must still validate them.
  2. Distinction: Unlike pure kinematic reachability (which evaluates whether the robot’s linkages can attain a spatial configuration), kinodynamic feasibility incorporates time parameterization, actuator force and torque limits, reflected inertia, and mechanical braking runways.
  3. Common pitfall: Checking feasibility only at discrete waypoints. Interpolation splines between sample points can produce intra-sample velocity overshoots and torque spikes that breach motor limits even when every individual waypoint passes validation.

Intent defines the admissible goal; planning supplies the continuous motion, temporal parameterization, and dynamic limits needed to pursue that goal. Across the proposal boundary (The Machine in Five Levels), a plan is not a command written to actuator registers. It is an unprivileged proposal, sent from the application processor to the safety microcontroller (MCU), where the tracking controller follows it and the permission path (Safety Enforcement) checks it.2 Because inference latency has a long tail, the downstream controller in this design consumes admitted references on its own clock and cannot suspend physical motion while the model finishes. A plan must therefore be self-contained. It carries its own seam state, continuous through acceleration (\(C^2\)),3 its own deadlines, and its own stop, a stopping suffix admitted with the nominal motion so that the stopping continuation exists before it is needed.

↰ Prerequisite: Expiring intent leases provide the bounded time windows discharged by trajectories in The Intent Lease.

Momentum, a long inference tail, and a seam that must stay continuous together decide what a plan has to contain. The first decision is therefore what the planner hands to the tracking controller and the permission path while the arm is still moving.

What Planning Hands Over

For a two-joint arm, one pair of joint angles \((q_1,q_2)\) is one point in configuration space \(\mathcal{C}\). An obstacle excludes some angle pairs, leaving \(\mathcal{C}_{\mathrm{free}}=\mathcal{C}\setminus\mathcal{C}_{\mathrm{obs}}\). A curve through that free set says where the arm may move, but not how quickly it may move or whether its motors can supply the required torque (Lozano-Pérez 1983). A trajectory assigns time to the curve and exposes \(\mathbf{x}(t)=[\mathbf{q}(t)^T,\dot{\mathbf{q}}(t)^T,\ddot{\mathbf{q}}(t)^T]^T\). The planner proposes that time-indexed reference, and the permission path checks it before any setpoint reaches the drive. A geometric path alone supplies neither timing nor fallback clearance.

Lozano-Pérez, Tomás. 1983. “Spatial Planning: A Configuration Space Approach.” IEEE Transactions on Computers C-32 (2): 108–20. https://doi.org/10.1109/TC.1983.1676196.

What the planner hands over is a trajectory record, the immutable proposal that the tracking controller follows and the permission path admits. It names its coordinate frame \(\mathcal{F}\), evidence time \(t_0\), initial reference state, and four deadlines in the MCU monotonic clock domain: nominal tracking begins at \(t_{\mathrm{start}}\), the nominal setpoints end at \(t_{\mathrm{plan\_exp}}\), replacement closes at \(t_{\mathrm{commit}}\), and the admitted stop finishes at \(t_{\mathrm{stop\_end}}\). It also links to the active intent expiry \(t_{\mathrm{intent\_exp}}\). Conversion from the sensor and host clocks carries a bounded error. The planner schedules each replacement against an earlier target, the blend deadline \(t_{\mathrm{blend}}\), by which the successor should be admitted and at which the arm’s obstacle clearance is last checked; it is the schedule’s target, not a field of the record.

The permission path permits nominal TRACK only while the intent and plan are valid, so the intent’s expiry ends TRACK at once, whatever the record’s own deadlines allow. A second clock also bounds TRACK. The chunk policy proposes base velocity and arm joint targets together, so one chunk lease (Multi-Rate Cadences) governs both bodies, and only an admitted chunk renews it, every 50 ms on this machine. When the lease lapses 60 ms after the last admission, each body enters its own stop, the base its resident stop and the arm its state-matched fallback, a separately validated stop that solves its matched suffix’s \(C^2\) profile again from the measured state. The arm needs the separate fallback because its matched stop suffix is anchored at the position the arm will occupy at \(t_{\mathrm{commit}}\). An intent expiry or a fault that invalidates the path before \(t_{\mathrm{commit}}\) sends the arm to that same fallback.

After a lapse, the arm’s stop begins one permission tick, one bus cycle, and one brake onset later; together with the lease itself, these delays make up the renewal-to-onset delay of Multi-Rate Cadences. Commitment caps the lease, because stop onset must come by \(t_{\mathrm{commit}}\), so no lease may run longer than \(t_{\mathrm{commit}}\) less those three delays. Only a lease run near that ceiling lets a record reach \(t_{\mathrm{commit}}\) without a successor; such a record transfers to STOP on its matched stop suffix, which may finish after the intent’s tracking permission expires. On this machine the 60 ms lease lapses long before commitment, so a stalled proposer meets the renewal-to-onset delay rather than the ceiling, and section 1.5 charges that delay against the arm’s clearance.

The two consumers read different parts of the record. The tracker interpolates the admitted reference, timestamps, and feedforward terms to drive the actuators along a smooth path. The independent permission path reads the lineage, timing, dynamic assumptions, validity bounds, and stop suffix, and it monitors current limits and authority without inheriting the planner’s feasibility claim as proof; a fresh obstacle, changed payload, or contact event can revoke TRACK and invoke the state-matched fallback. Because each field in the handoff corresponds to a runtime check, the Nervous System can admit fast motion without assuming that the next inference cycle will succeed. Producing such a record begins from a goal that carries no timing at all.

From Goal to Trajectory

The intent lease for the mug, which the arm takes from the conveyor for the coworker at the packing station, grants a goal region and effort ceilings (The Intent Lease), but no actuator can execute a region. The tracking controller needs a trajectory, which assigns state targets, feedforward terms, and timestamps across a bounded interval. If a learned policy could output valid motor currents at the 1 kHz joint loop rate, planning would not exist as an architectural stage, and the machine would operate as a high-rate feedback controller. Learned policies instead need tens or hundreds of milliseconds to compute a motion sequence, while the tracking controller and the permission path run deterministically on fixed millisecond-scale periods.

Classical sampling-based planners answer the geometric half of this problem. A probabilistic roadmap (Kavraki et al. 1996) or a rapidly-exploring random tree (LaValle 1998) searches \(\mathcal{C}_{\text{free}}\) for a collision-free path without building an explicit model of the obstacles. A path from such a search, like a chunk from a learned policy, still carries no timing, no derivatives at its ends, and no stop, and those are what this chapter supplies.

Kavraki, Lydia E., Petr Švestka, Jean-Claude Latombe, and Mark H. Overmars. 1996. “Probabilistic Roadmaps for Path Planning in High-Dimensional Configuration Spaces.” IEEE Transactions on Robotics and Automation 12 (4): 566–80. https://doi.org/10.1109/70.508439.
LaValle, Steven M. 1998. Rapidly-Exploring Random Trees: A New Tool for Path Planning. TR 98-11. Computer Science Department, Iowa State University.
Zhao, Tony Z., Vikash Kumar, Sergey Levine, and Chelsea Finn. 2023. “Learning Fine-Grained Bimanual Manipulation with Low-Cost Hardware.” Robotics: Science and Systems (RSS). https://doi.org/10.15607/RSS.2023.XIX.016.

Learned proposers bridge slow inference and fast actuator control by receding-horizon action chunking (Supply, Freshness, and the Memory Wall), predicting a multi-step sequence, executing a prefix, and replanning on fresh observations. Three kinds of proposer fill this role, and each matters here through the latency and continuity of what it emits. ACT (Zhao et al. 2023) predicts \(N\) future joint setpoints at once and blends overlapping chunks by the temporal ensembling of Supply, Freshness, and the Memory Wall, which averages setpoints but leaves derivative continuity at the chunk seam to this chapter. Diffusion Policy (Chi et al. 2024) denoises a chunk of horizon \(T_p\) (16 steps in the real Push-T setup), executes a subset \(T_a\) (six there), and replans on the next observation; its iterative denoising adds workload-dependent latency and variance. A learned warm-start for a constrained trajectory optimizer can cut solver iterations when it lands near a feasible basin, but it can also choose the wrong side of an obstacle or miss the deadline. None of these outputs is a feasibility certificate, and only a candidate whose full path, seam, torque, and stop checks pass is admitted.

This receding-horizon structure mirrors classical Model Predictive Control (MPC) and trajectory optimization, where an optimizer plans a trajectory over a finite horizon \(T\), executes an initial prefix, and resolves the problem from the updated state on the next cycle. Classical MPC formulates trajectory synthesis as an explicit constrained numerical optimization problem, minimizing a cost function subject to analytical system dynamics (\(\dot{\mathbf{x}} = f(\mathbf{x}, \mathbf{u})\)) and hard inequality constraints on physical boundaries (\(\mathbf{x} \in \mathcal{X}_{\text{safe}}\)) and actuator torques (\(\mathbf{u} \in \mathcal{U}_{\text{adm}}\)). Where analytical models accurately capture the physical plant and state dimensions remain compact, MPC provides rigorous guarantees of constraint satisfaction and closed-loop stability. Yet classical trajectory optimization hits the “Classical Wall” of The Classical Wall when applied to unstructured open-world manipulation: numerical solvers cannot ingest high-dimensional semantic tokens (such as raw camera pixels or natural-language instructions) directly, and non-smooth contact mechanics or deformable objects introduce combinatorial local minima that render online numerical optimization intractable within real-time control periods. Generative action chunking resolves the semantic ingestion problem by learning continuous multimodal trajectory distributions directly from visual demonstrations, but sacrifices analytical guarantees. The physical AI architecture therefore treats learned chunking policies as unprivileged semantic proposers across multi-second task horizons, relying on the kinodynamic feasibility checks and seam contracts developed in this chapter to guarantee physical admissibility before actuation. Executing these feasibility checks and seamlessly replacing the active trajectory introduces computational and transport delays that must be strictly bounded across replacement cycles.

The scheduling quantity is replacement latency \(L\): elapsed time from the observation needed for a new proposal through transfer, inference, full-trajectory validation, and admission. An illustrative stage ledger for the machine’s chunk policy has 15 ms of sensing, 5 ms of DMA, the policy’s 40 ms of inference, 2 ms of deserialization, 18 ms of validation, and 1 ms of activation, totaling 81 ms. When stages overlap or share contention, a sum of stage percentiles is not a percentile of the sum (Measurement Freshness), so the horizon is sized from the end-to-end distribution of \(L\).

\[L = t_{\mathrm{sense\_ingress}} + t_{\mathrm{ipc\_dma}} + t_{\mathrm{infer}} + t_{\mathrm{deser}} + t_{\mathrm{validate}} + t_{\mathrm{admit}} \tag{1}\]

The choice of action chunk prediction horizon \(H\) introduces a fundamental systems dilemma between computational amortization and reactive responsiveness (figure 1). High-capacity vision-language-action (VLA) models and diffusion policies require non-trivial inference latency (\(t_{\mathrm{infer}} \approx 180\ \text{ms}\) on embedded accelerators). If the planner evaluates actions single-step (\(H = 1\)), the compute duty cycle exceeds 100 percent (\(t_{\mathrm{infer}} / \Delta t = 900\%\)), starving the 50 Hz control loop (\(\Delta t = 20\ \text{ms}\)) and causing the robot to pause and shudder between consecutive steps. Expanding the prediction horizon \(H\) amortizes inference across multi-step execution windows, reducing accelerator duty cycle below 50 percent once \(H \ge 18\). However, executing a long chunk open-loop inflates the mean reaction delay to dynamic obstacles, \(\tau_{\mathrm{react}} \approx \frac{1}{2} H \Delta t + t_{\mathrm{infer}}\). When \(H > 36\) (\(>720\ \text{ms}\) physical window), reaction delay exceeds the dynamic obstacle avoidance threshold (\(\sim 350\ \text{ms}\)), causing closed-loop task success in dynamic environments to plunge from 90 percent down to single digits. Sizing the action chunk horizon to the Pareto-optimal window \(H^* \in [16, 24]\) achieves the necessary balance: compute duty cycle remains comfortably amortized at 38 to 45 percent while reaction latency stays below 400 ms, preserving high closed-loop success rates across both static and dynamic operating conditions.

Figure 1: The action chunk horizon dilemma: compute amortization versus dynamic reaction delay: Two-panel systems evaluation across action chunk horizon \(H\) under a 50 Hz control loop (\(\Delta t = 20\ \text{ms}\)) and 180 ms model inference latency. Top: GPU compute duty cycle (red) drops below the 100 percent real-time feasibility ceiling only when \(H \ge 9\), while mean reaction delay to unexpected obstacles (blue) scales linearly with horizon length. Bottom: Closed-loop manipulation success rate across stationary objects (green) and moving obstacles (orange). While static tasks tolerate long horizons (\(H > 30\)), dynamic workspace interactions collapse due to open-loop latency, establishing an empirical Pareto-optimal operating window at \(H^* \in [16, 24]\) (\(320\text{--}480\ \text{ms}\) execution window).

The component sum in equation 1 is an elapsed replacement path, not an absolute timestamp. Consider a generic replanner, slower than this machine’s chunk renewal, that makes \(K=3000\) handoffs in a ten-minute mission at 5 Hz. If each handoff independently has a \(0.01\) chance of exceeding a \(P_{99}\) budget, the expected number of late handoffs is 30 and the probability that all arrive on time is \((0.99)^{3000}\approx8 \times 10^{-14}\). Correlated contention clusters misses, which breaks the independence this arithmetic assumes. Allocating a mission exceedance target \(\epsilon_{\mathrm{mission}}=10^{-3}\) equally gives a per-handoff target \(\epsilon\le\epsilon_{\mathrm{mission}}/K\approx3.3 \times 10^{-7}\) by the union bound. The corresponding \(P_{99.99997}\) is a design quantile target, a risk allocation rather than an observed latency. A deployment either supports it with representative load testing and a conservative bound, or accepts a higher fallback rate.

Conceptual strip comparing a P99 latency allowance with a much rarer design-tail target. The rarer percentile is a risk allocation.

The tail target allocates replacement risk; observed latency and confidence determine whether the chosen deadline is credible.

The next request leaves no later than \(T_{\mathrm{request}}\) after the active chunk starts. Admission must finish before \(t_{\mathrm{commit}}\), not merely before the last nominal setpoint. With a replacement-latency target \(Q_{1-\epsilon}(L)\) and reserve \(T_{\mathrm{reserve}}\), require \(t_{\mathrm{commit}}-t_{\mathrm{start}}\ge T_{\mathrm{request}}+Q_{1-\epsilon}(L)+T_{\mathrm{reserve}}\). The admitted stop then needs another \(T_{\mathrm{stop}}\) under MCU authority. The complete time horizon \(T_{\mathrm{record}}\) that the record must cover, regardless of encoding, has the lower bound:

\[T_{\mathrm{record}}\ge T_{\mathrm{request}}+Q_{1-\epsilon}(L)+T_{\mathrm{reserve}}+T_{\mathrm{stop}} \tag{2}\]

The complete duration in equation 2 includes the stop suffix. The machine’s chunk policy emits a setpoint every 20 ms (the setpoint period \(\Delta t_{\text{step}}\)), 16 to a chunk, so one chunk carries 320 ms of nominal motion. For the conveyor-tracking arm, a chosen request delay of 60 ms, replacement target of 160 ms, and reserve of 20 ms, with a separately checked 300 ms stop, require at least 540 ms of complete motion authority, or 27 setpoint-period duration equivalents. This does not mean 27 stored setpoints: \(N\) in the record counts only nominal samples; the stop is represented by its separately validated polynomial coefficients. An authority horizon that covered only the request delay, replacement target, and reserve would omit the stop runway.

The chunk policy sends its next request in the renewal slot 50 ms after each chunk starts (Supply, Freshness, and the Memory Wall), so in steady operation several requests are in flight at once, an admitted chunk arrives every 50 ms, and their latencies overlap. The bound sets \(T_{\mathrm{request}}\) 10 ms above that slot, so it still holds for a request that leaves up to that much late.

The replacement target is a design-tail quantile of the whole replacement path, so it sits well beyond both the policy’s 40 ms P99 pass and the 81 ms stage ledger. The blend deadline must fall at least 240 ms after start, the sum of request delay, replacement target, and reserve, and the worked 300 ms commitment of section 1.5 leaves 60 ms beyond that target. In the worked arm, the chunk’s nominal setpoints end at 320 ms and the admitted stop completes at 600 ms, so the complete authority window spans 30 setpoint-period duration equivalents.

The 240 ms replacement window is the arm’s limit rather than its operating case. The shared lease of section 1.2 lapses once an admission falls more than 10 ms behind its slot, so a replacement that takes the full design tail ends in the arm’s state-matched fallback long before the blend deadline, and the window instead sets how long any lease may run on this arm.

This timing lower bound competes with target-evidence age. Even under a qualified local tracker, where only the conveyor’s residual slip carries the mug away from the tracker’s prediction, Goals That Expire finds that one observation stays inside the grasp tolerance for less time than the 300 ms commitment. A single observation therefore cannot justify nominal tracking to commitment. The tracker must deliver fresh evidence before its horizon ends; otherwise TRACK ends at evidence expiry and the MCU uses its state-matched fallback. Extending a target timestamp because the compute tail is long would invert the permission rule.

Whatever the proposer, the systems interface treats the learned model as a stochastic producer of motion chunks, characterized by an empirical latency profile and an output horizon \(N\); diffusion schedules, attention caching, and token generation shape that profile but sit below the first budgetable quantity. The execution buffer absorbs inference latency while the controller still reacts to disturbances, as the Push-T recoveries of figure 2 show. Sizing \(N\) against a validated latency distribution lowers the risk of a late replacement; the protected stop handles a miss.

Three Push-T examples show recovery from camera occlusion, in-flight target movement, and target movement near completion. The real Push-T configuration predicts 16 steps and executes 6 before replanning; the experiment includes no stopping suffix.
Figure 2: Push-T disturbance recovery: Chi et al. report a real Push-T configuration with 16 predicted and 6 executed action steps; 10 Hz commands were interpolated to 125 Hz. The recoveries show closed-loop replanning; the experiment includes no stopping suffix and no inference-starvation case (Chi et al. 2024).
Chi, Cheng, Zhenjia Xu, Siyuan Feng, Eric Cousineau, Yilun Du, Benjamin Burchfiel, Russ Tedrake, and Shuran Song. 2024. “Diffusion Policy: Visuomotor Policy Learning via Action Diffusion.” The International Journal of Robotics Research 44 (10-11): 1684–704. https://doi.org/10.1177/02783649241273668.

A replacement planner must account for motion during its computation. In an illustrative 80 ms delay at a constant joint speed of 0.50 rad/s, a stale request-epoch pose lags the moving reference by 0.040 rad (2.29°). A proposed replacement can instead start from the active plan’s projected reference at the intended seam:

\[\Delta q_{\mathrm{reference}}=\int_{t_0}^{t_{\mathrm{seam}}}\dot q_A(t)\,dt,\qquad \hat{\mathbf{x}}_{\mathrm{seam}}=\mathbf{x}_A(t_{\mathrm{seam}}) \tag{3}\]

The projected seam in equation 3 is useful for constructing a candidate; contact, tracking error, or scheduling changes can make the plant differ. The MCU therefore measures current encoder state, validates the actual seam \((q,\dot q,\ddot q)\) and any bridge, and refuses a candidate outside the admitted region. Matching two reference trajectories makes the references \(C^2\), not the plant.

Definition 1.2: Future-state conditioning

Future-state conditioning is the practice of generating candidate motion plans anchored to the anticipated state at execution time rather than the stale state measured at plan initiation.

  1. Significance: Offsets computational latency \(\Delta t_{\text{plan}}\), removing the reference jump at trajectory handoff that planning from the stale state would create, without zero-velocity stops between chunks.
  2. Distinction: Distinct from state estimation or filtering; it is a reference-planning strategy that projects the admitted trajectory forward rather than filtering sensor noise.
  3. Common pitfall: Treating the predicted execution state as the measured one; if a disturbance displaces the plant during planning, the candidate stays inadmissible until the MCU checks the seam against encoder state.

The horizon now answers to two clocks. It must be long enough for a design-tail replacement to land before commitment with the stop still behind it, and that same window caps the lease. The evidence behind the target, meanwhile, must stay fresh for as long as TRACK runs. A replacement that arrives in time, however, secures only the plan’s continuity in time. The setpoints it carries must also lie within what the joints can deliver and join the mechanism’s actual velocity and acceleration at the seam.

Checkpoint 1.1: Action chunk horizon and tail latency budgeting

Before turning from replacement timing to the feasibility of the motion itself, verify your ability to size an action chunk horizon against the latency tail:

Kinodynamic Feasibility

A candidate trajectory is a geometric and timed proposal, not permission to move. Before submitting it, the planner screens it by testing whether the verified initial state lies inside the candidate’s kinodynamic feasibility envelope, evaluating joint position and velocity, predicted actuator torque and current, contact limits, obstacle clearance, and the matched stop suffix over the proposed horizon. For an arm, the rigid-body model maps \(\mathbf{q}(t)\), \(\dot{\mathbf{q}}(t)\), and \(\ddot{\mathbf{q}}(t)\) to \(\boldsymbol{\tau}(t)=\mathbf{M}(\mathbf{q})\ddot{\mathbf{q}}+\mathbf{C}(\mathbf{q},\dot{\mathbf{q}})\dot{\mathbf{q}}+\mathbf{g}(\mathbf{q})\) and \(I_i(t)=\tau_i(t)/k_{\tau,i}\) (Craig 2005; Lynch and Park 2017). The planner’s screen is not admission; the MCU repeats the decisive check and admits the bounded trajectory only if its configured limits and complete stop clearance hold for the verified initial state; it then checks tracking, freshness, and the remaining stopping budget during execution. An optimizer may smooth a path or reduce obstacle proximity, but the admitted trajectory and resident stop, not the optimizer’s objective value, define the motion permission (figure 3).

Craig, John J. 2005. Introduction to Robotics: Mechanics and Control. 3rd ed. Pearson Prentice Hall.
Lynch, Kevin M, and Frank C Park. 2017. Modern Robotics: Mechanics, Planning, and Control. Cambridge University Press.

↰ Prerequisite: Actuator torque saturation limits and rotor inertia scaling (\(N^2 J\)) are derived in Actuator Transmission Limits.

Real-Time Trajectory Optimization and Dynamic Obstacle Avoidance on Industrial Manipulators. Experimental deployment of GPU-accelerated motion generation (cuRobo) executing time-parameterized, minimum-jerk trajectory splines on physical hardware. (Top row) A canonical 6-DOF industrial manipulator executes an online obstacle avoidance trajectory around a dynamic workspace obstacle, continuously evaluating continuous-time collision distances against a 3D Euclidean Signed Distance Field (ESDF) voxel map generated via real-time depth perception. (Middle row) A canonical 6-DOF collaborative arm executes a collision-free pick-and-lift trajectory spline constrained by joint velocity, acceleration, and torque limits. (Bottom row) Coordinated multi-arm trajectory synthesis in simulation showing two canonical industrial manipulators executing synchronized, collision-free obstacle avoidance around shared workspace boundaries. Adapted from [@sundaralingam2023curobo].
Figure 3: Real-time trajectory optimization: GPU-accelerated motion generation executing minimum-jerk splines on hardware, avoiding a dynamic obstacle against a signed distance field, executing a constrained pick-and-lift, and coordinating two arms in a shared workspace. Collision distance is evaluated in continuous time rather than at waypoints, which is what allows the trajectory to be re-optimized while it is being executed. Adapted from (Sundaralingam et al. 2023).
Sundaralingam, Balakumar, Siva Kumar Sastry Hari, Adam Fishman, Caelan Garrett, Karl Van Wyk, Valts Blukis, Alexander Millane, et al. 2023. “CuRobo: Parallelized Collision-Free Robot Motion Generation.” IEEE International Conference on Robotics and Automation (ICRA), 11124–31.

Feasibility checked only at waypoints is not feasibility of the motion. The mechanism follows an interpolated path between samples spaced \(T_s\) apart, so a check at \(t_k = k T_s\) alone lets derivatives exceed their bounds inside \([t_k, t_{k+1}]\). If the interpolator may apply up to \(a_{\max}\) within a sample, a worst-case triangular acceleration reversal across the sampling midpoint lets velocity overshoot the sampled values by as much as \(\Delta v \le \frac{1}{4} a_{\max} T_s\), so two samples just under \(v_{\max}\) can bracket a peak above it and trip an over-speed clamp between two valid waypoints. To bound velocity in continuous time without evaluating every point, the admission filter tests a contracted limit, \(|\dot{q}_k| \le v_{\max} - \frac{1}{4} a_{\max} T_s\), which absorbs the largest intra-sample overshoot.

Concatenating individually feasible chunks can create an infeasible seam. Position-only matching (\(C^0\)) can leave a velocity step; matching velocity (\(C^1\)) can leave a finite acceleration and torque step. In a rigid-inertia approximation, a commanded velocity change \(\Delta\dot q\) spread over servo period \(T_c\) asks for the torque in equation 4, where \(J_{\mathrm{eff}}=J_L+N_g^2J_{\text{rotor}}\) is the output-side inertia, the load’s plus the rotor’s reflected through gear ratio \(N_g\). A physical drive saturates or filters that request according to its current limits and compliance. Figure 4 places that request beside its remedy, a finite \(C^2\) bridge that removes the reference velocity step.

\[\tau_{\mathrm{request}}=J_{\mathrm{eff}}\frac{\Delta\dot q}{T_c} \tag{4}\]

Panel (a) shows a velocity step at a trajectory seam and a high one-tick torque request. Panel (b) shows a smoother C-squared reference bridge. The diagram compares proposed reference demands, not measured torque.
Figure 4: Seam demand and checked bridge: A position-matched velocity step creates a large one-tick inertial torque request. A finite \(C^2\) bridge removes the reference velocity step, but its interior jerk, torque, and joint response still require validation.
Definition 1.3: C² spline seam

A \(C^2\) spline seam is a trajectory junction that enforces continuity through the second time derivative (position, velocity, and acceleration) between adjoining motion segments.

  1. Significance: Prevents instantaneous acceleration steps across trajectory chunks, bounding the inertial torque spike \(\tau_{\text{step}} = J_{\text{eff}} \Delta\ddot{q}\) demanded from actuators.
  2. Distinction: Distinct from \(C^1\) continuity (which matches only velocity and allows finite acceleration jumps) and \(C^0\) continuity (which matches only position and allows infinite acceleration impulses).
  3. Common pitfall: Assuming \(C^2\) continuity guarantees torque feasibility; while acceleration is continuous, interior velocities, accelerations, or jerks within the blending bridge may still violate physical actuator or clearance limits.

The transmission shapes the response to what the drive delivers. For a two-inertia model with load inertia \(J_L\), reflected motor inertia \(J_{\text{ref}}=N_g^2J_{\text{rotor}}\), and coupling stiffness \(k_\theta\), the antiresonance and resonance frequencies for this model are \(\frac{1}{2\pi}\sqrt{k_\theta/J_L}\) and \(\frac{1}{2\pi}\sqrt{k_\theta(1/J_L+1/J_{\text{ref}})}\). In the arm’s strain-wave joints, reflected rotor inertia and a compliant transmission can amplify a sharp reference change, so admission needs the joint’s identified, load-dependent modes and checks bridge extrema, torque, and drive limits against them. No frequency, stiffness, or jerk range transfers between products without measured parameters.4

Smoothing the seam’s velocity step requires online \(C^2\) trajectory spline blending, which must be treated as the synthesis of an entirely new motion plan rather than as cosmetic filtering. When the planner inserts a polynomial bridge \(\theta_{\mathrm{blend}}(t)\) over a transition interval \(T_{\mathrm{blend}}\), a duration distinct from the blend deadline \(t_{\mathrm{blend}}\), to connect chunk \(A\) and incoming chunk \(B\), the resulting bridge segment must undergo the exact same dynamic feasibility checks as the primary chunks.5

The bridge is a fifth-order (quintic) polynomial because torque follows acceleration (\(\tau = J_{\mathrm{eff}}\ddot\theta\) in the rigid-inertia model), so a bridge that matches only velocity still leaves an acceleration step, and with it a torque step of \(J_{\mathrm{eff}}\Delta\ddot\theta\). For \(C^2\) continuity across the seam, the bridge must match position, velocity, and acceleration at both endpoints, a total of six boundary conditions: \[\theta(0) = \theta_0, \quad \dot{\theta}(0) = \dot{\theta}_0, \quad \ddot{\theta}(0) = \ddot{\theta}_0\] \[\theta(T_{\mathrm{blend}}) = \theta_1, \quad \dot{\theta}(T_{\mathrm{blend}}) = \dot{\theta}_1, \quad \ddot{\theta}(T_{\mathrm{blend}}) = \ddot{\theta}_1\] where \((\theta_0, \dot{\theta}_0, \ddot{\theta}_0)\) is the terminal physical state of chunk \(A\) at the seam instant, and \((\theta_1, \dot{\theta}_1, \ddot{\theta}_1)\) is the target state on incoming chunk \(B\) at \(t = T_{\mathrm{blend}}\). Matching six boundary conditions requires six independent coefficients (\(a_0 \dots a_5\)), uniquely dictating a fifth-degree polynomial: \[\theta(t) = a_0 + a_1 t + a_2 t^2 + a_3 t^3 + a_4 t^4 + a_5 t^5\] The six coefficients follow in closed form from these boundary conditions (Smooth Trajectories and Bumpless Transfer), and the bridge’s jerk varies quadratically in time, finite over a finite blend. Admission must check its extrema and the measured joint response; \(C^2\) endpoints alone do not suppress all resonant energy.

A fixed-degree polynomial can be evaluated with bounded work per axis on a chosen controller. Coefficient synthesis and whole-trajectory extrema checks occur at admission; the measured worst-case execution time, including memory access and monitoring, must fit the configured servo period.

Representation affects what can be proved at admission. Table 1 separates continuity supplied by the representation from the dynamic checks still required. A B-spline of degree \(p\) has \(C^{p-r}\) continuity at an interior knot of multiplicity \(r\); its control-point convex hull bounds position, not automatically velocity, torque, or clearance. Minimizing an integrated jerk objective requires solving that optimization; choosing a B-spline does not itself solve it.

Table 1: Trajectory representations and required checks: Smooth parameterization helps form a candidate but does not by itself prove dynamic feasibility.
Representation Native seam property Checks before execution
Quintic bridge Can match \(q,\dot q,\ddot q\) at both ends; jerk is generally quadratic. Check interior extrema, torque, clearance, and timed admission.
B-spline Continuity depends on degree and knot multiplicity. Check derivatives, dynamics, clearance, and optimizer result.
ACT action chunk Discrete setpoints; zero-order hold jumps at ticks, linear interpolation is \(C^0\). Construct and admit a feasible bridge and stop.
Diffusion action chunk Discrete sampled actions; no intrinsic actuator authority. Validate timing, state, bridge, limits, and stop.

Napkin Math 1.1: Seam acceleration and torque requests
For the registered CSG-25-50-2UH teaching example, reflected rotor inertia is 0.25 kg·m². Correcting a 0.2 rad/s reference velocity gap in one 1 ms tick asks for 50 N·m of inertial torque. The manufacturer’s specification gives 51 N·m rated L10 and 127 N·m repeated peak; this one-tick request is below the rated value. A symmetric \(C^2\) velocity blend over 50 ms has 1 N·m mean and 1.5 N·m peak inertial torque, a 33.3× peak-request reduction. Total torque still includes load, gravity, friction, and control response; it needs a full peak and thermal check.

Illustrative one-tick velocity-step request of 50 newton-meters versus a 50-millisecond C-squared blend with 1.5 newton-meter peak inertial torque.

In this inertia model, the \(C^2\) blend cuts the peak inertial torque request by 33.3×.

Output chatter in learned proposals is a related failure. Stochastic sampling can produce successive chunks whose every sample satisfies position and velocity limits while the commanded acceleration reverses sign rapidly, and each reversal asks the drive for a torque reversal, with the current transitions and \(I^2R\) heating that follow if the drive tracks it (Actuator Transmission Limits).6 The systems engineer budgets that variation as actuator thermal rise and transmission fatigue, not as perceptual roughness; a trajectory that excites structural resonances or exceeds the drive’s thermal limits is infeasible however closely its waypoints follow the task. Even a candidate that passes every internal and seam check must still provide for a replacement that never arrives.

Behavior at the Seam

Suppose the chunk policy stalls while the arm is reaching toward the mug. On this machine the shared lease ends the wait 60 ms after the last admission, and the arm enters its state-matched fallback along the renewal-to-onset path of section 1.2. The record’s own deadlines decide how long any lease could be allowed to run, because until the stop begins the arm keeps moving, and every millisecond the MCU waits is travel its stop can no longer use. Let the lease run to its ceiling, then, so that the blend deadline \(t_{\mathrm{blend}}\) passes with no replacement admitted. The four deadlines of section 1.2, compared in the MCU monotonic clock with \(t_{\mathrm{intent\_exp}}\), now decide what happens. A replacement may still be admitted until \(t_{\mathrm{commit}}\), the entry of the matched stop suffix, whose duration is \(T_{\mathrm{stop}}=t_{\mathrm{stop\_end}}-t_{\mathrm{commit}}\). It must pass the full admission check before that cutoff; a late host progress report has no authority.

For a cruise entry with \(q(t_{\mathrm{commit}})=q_c\), speed \(v_c>0\), and zero entry acceleration, a \(C^2\) position-and-velocity-matched stop over duration \(T\) uses \(u=(t-t_{\mathrm{commit}})/T\):

\[q(u)=q_c+v_cT\left(u-u^3+\tfrac12u^4\right),\qquad 0\le u\le1 \tag{5}\]

Differentiating equation 5 gives speed \(v_c(1-3u^2+2u^3)\) and acceleration \(-6v_c u(1-u)/T\), peak deceleration is \(1.5v_c/T\), and stopping distance is \(v_cT/2\). Unlike a constant-deceleration switch, its acceleration begins and ends at zero. Holding the peak at the credible deceleration \(a_{\text{brake}}\) fixes \(T=1.5v_c/a_{\text{brake}}\) and a distance of \(0.75v_c^2/a_{\text{brake}}\), half again the constant-deceleration distance \(v_c^2/2a_{\text{brake}}\), so in a stopping budget the suffix behaves like constant braking at \(a_{\text{eff}}=a_{\text{brake}}/1.5\). A nonzero measured entry acceleration requires a general quintic matching the actual \((q,\dot q,\ddot q)\) at entry and zero terminal velocity and acceleration; the permission path checks its interior speed, acceleration, jerk, torque, and clearance.

In the worked arm case, the blend deadline is 240 ms, matched commitment 300 ms, nominal setpoint end 320 ms, and stop end 600 ms, so \(T\) is 300 ms. At the arm’s 1 m/s TCP speed limit, the suffix’s peak deceleration is 5 m/s² and it travels 150 mm. Clearance is last checked at the blend deadline, so the cruise from 240 ms to physical brake onset at 300 ms is charged against that clearance and uses 60 mm; the full 210 mm leaves 90 mm of the 300 mm obstacle clearance. Sensing and model error must still come out of that geometric margin. The stated 300 ms is physical suffix onset, so the MCU must close replacement admission and pretrigger any communication or actuator delay \(\delta\) by that instant minus \(\delta\). If it does not, add \(v_c\delta\) of travel and shift the stop end; the 90 mm margin is then smaller. Nominal setpoints end at 320 ms while MCU STOP continues to 600 ms, and the case assumes that fresh target evidence keeps TRACK valid that long (section 1.3). Figure 5 places those instants on a single axis and separates the two ownership regimes, so the point where nominal reference tracking ends can be read against the separately authorized stop that carries the arm to rest.

A stall on this machine never reaches commitment. One permission tick, one bus cycle, and brake onset, 22 ms together, put the arm’s stop onset 82 ms after the last admission, or 82 mm of travel at the TCP limit. From zero-acceleration cruise the \(C^2\) profile matches the arm at whatever instant it starts, so the state-matched fallback travels the same 150 mm as the matched stop suffix. The renewal-to-onset path therefore uses 232 mm of the 300 mm clearance and leaves 68 mm, against 90 mm when the stop begins at commitment. Because stop onset must come by the 300 ms commitment, the lease may run at most 278 ms.

On the arm, commitment decides whether the 90 mm margin survives. A lease 200 ms longer than the arm’s 278 ms ceiling would let tracking run that far past commitment, and cruise at the TCP limit would add 200 mm before the same stop and breach the 300 mm clearance by 110 mm. A later stop must still match its actual entry state; this counterfactual holds cruise speed constant only to show the lost clearance. An arm that waits that long may already occupy a state from which no admissible control avoids the obstacle.

Definition 1.4: Inevitable collision state

Inevitable collision state (ICS) is any dynamic plant state \(\mathbf{x}(t) \in \mathcal{X}\) from which every physically admissible future control trajectory \(\mathbf{u}_{[t, \infty)} \in \mathcal{U}\) inevitably produces collision with an obstacle or constraint boundary: \[\mathbf{x} \in \text{ICS}(\mathcal{X}_{\text{obs}}) \iff \forall \mathbf{u}(\cdot) \in \mathcal{U}, \; \exists \tau \ge t \text{ such that } \mathbf{x}(\tau) \in \mathcal{X}_{\text{obs}}\] where \(\mathcal{U}\) denotes the admissible control input set bounded by actuator torque, traction, and deceleration limits.

  1. Significance: Sets the commitment deadline \(t_{\text{commit}}\) in receding-horizon planning; continuing nominal motion past it without an admitted successor can carry the plant into an ICS, and no later replanning can bring it back out.
  2. Distinction: Unlike static geometric collision checks that evaluate only instantaneous spatial overlap (\(\mathbf{x} \in \mathcal{X}_{\text{obs}}\)), an ICS identifies dynamically trapped states where current momentum and finite braking torque make future boundary breach physically unavoidable.
  3. Common pitfall: Delaying emergency braking in the expectation that an overdue neural planner will complete an evasive path, ignoring that moving mass enters an ICS long before geometric contact occurs.
Timeline distinguishes preferred blend at 240 milliseconds, physical stop commitment at 300, nominal setpoint end at 320, and stop end at 600. A second panel shows tracking transferring to a protected stopping state when no replacement is admitted. The stop can continue after nominal or intent tracking permission ends.
Figure 5: Nominal tracking and the matched stop suffix: The worked arm permits a checked replacement before the 300 ms physical stop onset. Nominal references would end at 320 ms, while the separately authorized, \(C^2\) stop reaches rest at 600 ms. The suffix is matched to the commitment state; earlier invalidation needs the state-matched fallback. All deadlines use the MCU monotonic clock, and physical clearance includes the full response and stop.

These deadlines and the stop they protect are fixed at admission, before motion begins. The candidate declares payload, contact, effort, and obstacle assumptions. The MCU first validates its fixed header and lineage, then checks the complete bounded trajectory and suffix, including the seam \((q,\dot q,\ddot q)\) against its current encoder state, interior extrema, clearance, stopping distance, and a feasible response from every state reachable before commitment. A scan over \(N\) setpoints is \(O(N)\), even with a fixed maximum \(N\) and measured worst-case execution time; after admission, a distinct \(O(1)\) per-tick check reads the current state and local reference. A replacement received after the blend deadline passes the same check with a compressed bridge, whose higher acceleration and torque its extrema must still clear, and if the check cannot finish before commitment the MCU keeps the current record. A candidate received after commitment cannot restore the spent runway.

The planner proposes the suffix, but the MCU latches the validated payload and stop coefficients into protected memory before enabling TRACK and selects that resident path at commitment without reading host DRAM, so a host crash, bus stall, or corrupted shared packet cannot erase the stop.7 If the measured state falls outside the latched suffix’s entry region, the MCU uses the state-matched fallback; torque disable or a spring brake is not a universal substitute for a controlled stop, especially with a suspended load (The Fallback Ladder).

The base of the mobile manipulator stops the same way, and for a reason of its own. The loaded tote rack tolerates the machine’s credible deceleration only if that deceleration is reached gradually; a stop that begins and ends at zero acceleration costs half again the distance of an abrupt one at the same peak. That cost now enters the stopping budget. At the drive limit of 1.5 m/s, a suffix that peaks at the credible 2 m/s² lasts 1,125 ms and travels 843.75 mm, against the 562.5 mm of constant-deceleration braking in equation. The suffix therefore adds 281.25 mm to the budget that Sensor Transduction and Calibration left at 912.9 mm, for a running total of 1,194.15 mm. That total passes the 1.10 m rack-end clear distance by 94.15 mm. This is the stopping condition of principle \(\ref{pri-vol4-irreversibility}\) with one more term, because a stop the load can tolerate is a longer stop and the distance it adds comes out of the same clear distance. With such a stop the machine can no longer run at its drive limit and still stop short of a person who has stepped out at the rack end. Of the budget’s terms, only speed is left to give that distance back, and Stopping Envelopes sets it once the last term is in.

For either body, the admission and fallback decisions in table 2 are distinct from an emergency power cut.

Table 2: Tracking and fallback decisions: A host crash does not remove a latched stop. TRACK is the nominal mode; STOP is the stop rung of the fallback ladder in The Fallback Ladder.
State Trigger MCU action and required evidence
TRACK, ordinary handoff Replacement passes the complete admission check before commitment. Latch the new nominal path and its own stop, then transfer at a checked \(C^2\) seam.
TRACK, late candidate Candidate arrives after the blend deadline but before commitment. Admit only if the compressed bridge, full path, stop, and timing still fit; otherwise keep the current record.
STOP, matched suffix No successor admitted by commitment. MCU follows its protected suffix from the validated entry state; nominal tracking may end while STOP continues.
STOP, earlier invalidation Lease lapse, intent expiry, contact, state mismatch, or fault before commitment. MCU selects the state-matched fallback with reserved clearance.
Fault response Controlled stop cannot be assured from measured state. Use the machine-specific risk response (which may include drive inhibit, brake, or compliance) only under its validated load and timing assumptions.
Checkpoint 1.2: Commitment and full stopping clearance

Before committing an autonomous machine to an action chunk, verify your understanding of commitment deadlines, stopping budgets, and trajectory continuity:

Each row of table 2 presumes that its trigger reaches the MCU in time. A failure can first show itself in the candidate, at the seam, or in the world, and each reaches the MCU on a different schedule.

How Plans Go Wrong

A plan can become infeasible by execution time. Between synthesis in the learned policy and actuation at the causal boundary (The Causal Boundary), the machine’s state drifts, the environment shifts, or the seam between consecutive chunks violates dynamic constraints. Where a failure first becomes visible decides which subsystem holds the signal and how much time it has to detect and reject the plan.

The earliest failure is a chunk that is invalid before it reaches the drives. A pre-execution bound checker evaluates each candidate at admission against fixed kinematic and dynamic limits, computing the margin \(M(t) = L_{\mathrm{limit}} - |x(t)|\) at every trajectory point for position \(q\), velocity \(\dot{q}\), and acceleration \(\ddot{q}\). Any sample beyond its limit makes \(M(t)\) negative at that instant, and the checker rejects the chunk with a fault record naming the joint channel, the limit, the violation time, and the negative margin. Rejection at admission causes no dynamic disturbance, because the machine stays on its previously validated trajectory.

A boundary checker is the admission-time guard for the seam of section 1.4. It compares the candidate with the active plan and measured joint state at \(t_{\mathrm{seam}}\), including \(\Delta q\), \(\Delta\dot q\), and \(\Delta\ddot q\), and bounds the torque the seam requests by equation 4.

For the CSG-25-50 joint of the seam notebook, counting only its 0.25 kg·m² reflected rotor inertia over one 1 ms tick and allocating the whole 127 N·m repeated-peak rating to this acceleration gives an idealized ceiling of 0.51 rad/s on \(\Delta\dot q\). Available margin is smaller after link and payload inertia, gravity, friction, other commanded torque, current rise time, and thermal or bus limits are accounted for. The permission path must use that state-dependent margin and the measured drive response when evaluating a finite bridge. It rejects a direct velocity discontinuity even if its one-tick arithmetic falls below that ceiling; a bounded \(C^2\) bridge and its interior checks are still required.8

Even with all pre-execution and boundary checks passed, changes in the physical world can render the plan infeasible. A grasped workpiece can slip from its intended \(\mathrm{SE}(3)\) pose, an unmodeled obstacle can enter the workspace, or structural tracking error can accumulate beyond allowable tolerances. Runtime monitors detect changed-world infeasibility by observing four dedicated signals, comprising joint state divergence, tracking error velocity, unexpected contact wrenches, and the invalidation of the geometric assumptions the record declares (section 1.7). The tracking error allowance \(\epsilon_{\mathrm{pos}}\) is the swept-volume clearance, the distance between the planned trajectory’s swept volume and the nearest obstacle boundary, less the structural deflection and gearbox compliance allowance \(\delta_{\mathrm{deflect}}\). For the mobile manipulator’s arm reaching past the conveyor guard, a budgeted swept-volume clearance of 0.020 m and an unmodeled payload deflection and gearbox compliance allowance \(\delta_{\mathrm{deflect}}\) of 0.005 m leave an allowance \(\epsilon_{\mathrm{pos}}\) of 0.015 m. The allowance caps the tracking bound rather than replacing it. The arm tracker’s own validated bound, the arm’s instance of the \(\epsilon_{\text{track}}\) that What the Tracker Hands Over validates for the base, must sit inside those 0.015 m, and the per-tick check trips on \(\epsilon_{\text{track}}\). If measured Cartesian tool-position error \(\|\mathbf{x}_{\mathrm{tool,actual}}(t)-\mathbf{x}_{\mathrm{tool,planned}}(t)\|\) exceeds \(\epsilon_{\text{track}}\), or a six-axis force-torque sensor reports an unmodeled 10 N contact in this free-space example, the monitor revokes nominal tracking and requests the validated state-matched fallback. Actual deceleration begins after the measured detection, dispatch, and actuator response delays.

A plan can also exhaust its nominal references before the next candidate passes admission. The MCU must not wait for the execution pointer to run off the array or treat a final-position hold as a stop. On this machine the chunk lease ends the wait first, and a lease run toward its ceiling reaches the commitment rule of section 1.5, which the MCU applies in its own monotonic clock. Complete stopping clearance includes detection, dispatch, actuator response, and motion under the selected profile; an assumed constant deceleration is insufficient for the \(C^2\) worked suffix.

Every detector in this section relies on an explicit contract between the trajectory generator and the execution runtime. A plan delivered as a raw list of coordinates, without its valid lifespan, clearance bounds, boundary derivatives, and fallback, leaves the permission path unable to tell whether an ongoing motion remains safe or has drifted into infeasibility.

The Trajectory Contract

Each time the chunk policy proposes 16 new setpoints for the reach toward the mug, the permission path must decide whether to admit them without asking the planner anything. The trajectory record, immutable and handed over at every replanning cycle, makes that decision possible. None of its nominal setpoints is admitted unless the record’s matched stop suffix is resident and feasible from every state reachable before \(t_{\text{commit}}\). It answers to the intent lease of The Intent Lease, whose digest it carries as its parent, and every setpoint it proposes pursues the lease’s target without exceeding its effort ceilings. The record stores the motion as setpoint arrays or spline coefficients, together with the sample cadence (on this machine a 20 ms period \(\Delta t_{\text{step}}\), a 50 Hz setpoint stream), the nominal end \(t_{\mathrm{plan\_exp}}\) (320 ms for one chunk), and SI units. With the frame and evidence time of section 1.2, the units, and the cadence in the handoff, the joint controller interpolates setpoints and evaluates derivatives without frame mismatches or reliance on ambient system clocks.

↳ Downstream: Trajectory feasibility proposals are separately checked against conditional control barrier functions in Safe Sets as Conditional Permission.

Physical feasibility depends on the scene and load used to validate the plan. The immutable sidecar therefore identifies obstacle-map epochs, payload and friction assumptions, limits, validator version, measured margin, and the source observation, and a digest in the fixed header binds it to the setpoints. The validator proves the stop feasible only under these assumptions, and they may claim no more than evaluation sampled, so the payload and friction the sidecar declares must lie inside the target ODD of Evaluation Logs. The permission path revokes TRACK when live state leaves them, since a recorded margin holds only for the scene it was computed against. Solver seed and model hash belong in the audit sidecar for reproducibility where the toolchain supports it, not in the servo’s per-tick path.

On this machine the chunk policy’s output supplies only the nominal part of each trajectory record. Planning adds the seam state, the four deadlines, and the matched stop suffix, so the permission path admits one stream of records. The fixed header groups each record’s fields by purpose. Lineage fields give a sequence number, the evidence time \(t_0\), and the digest of the parent intent lease. Timing fields give the four deadlines of section 1.2, and the record’s tracking authority ends at the earliest of its commitment deadline, the lapse of the chunk lease (Multi-Rate Cadences) 60 ms after the last admitted chunk, the parent intent’s expiry, and target-evidence expiry. Seam fields give the frame, each joint’s entry state \((q,\dot q,\ddot q)\), and the stop-suffix coefficients. Content fields give the payload kind and size and one digest over the setpoint payload and the sidecar. A variable-length setpoint payload and immutable provenance/assumption sidecar are outside the fixed header, and the MCU verifies their digest before the admission check of section 1.5. The payload digest binds content, and the parent digest binds lineage. The record carries no keyed tag, because the permission path admits a proposal by its content rather than its origin (Multi-Rate Cadences).

↳ Byte layout: The trajectory record’s field offsets and sizes are given in Trajectory payload.

Filled in for one reach toward the mug, the record is the timeline of figure 5 with its fields named. Its parent is the mug’s intent lease, bound by digest; its frame is the machine’s base frame, and every time field is in the MCU monotonic clock. Measured from \(t_{\mathrm{start}}\), the timing fields hold the 300 ms commitment, the 320 ms nominal end that 16 setpoints at 20 ms give, and the 600 ms stop end; the 240 ms blend deadline is the schedule’s target, not a field. The seam fields hold a 300 ms \(C^2\) suffix that peaks at 5 m/s² and brings the arm to rest from its 1 m/s TCP limit in 150 mm. While the record is in force, the 60 ms chunk lease bounds its tracking, a lapse leads to the state-matched fallback along a path that uses 232 mm of the 300 mm clearance, and commitment caps that lease at 278 ms. The sidecar declares a payload of at most 3 kg, free space until the grasp, and a scene inside the target ODD. Each field is one the permission path checks at admission or monitors on every tick, without asking the planner what it meant.

In the worked case the deadlines satisfy \(t_{\mathrm{start}}\le t_{\mathrm{commit}}<t_{\mathrm{plan\_exp}}<t_{\mathrm{stop\_end}}\). The MCU applies these deadlines under the TRACK and STOP rules of section 1.2, and a header timestamp cannot make a mismatched suffix safe. A log records evidence, request, validation, admission, activation, transfer, and stop-completion times in a common converted domain so actual response delay can be measured.

Every record in the runtime chain, from the observation contract through the belief record and the intent lease to the trajectory record itself, now names what it rests on and when it expires. The trajectory record proves only what the planner could foresee, a stop feasible from the states reachable before commitment under the scene and load in its sidecar. Several of the fallacies that follow mistake that bounded proof for a broader one.

Fallacies and Pitfalls

A trajectory remains feasible only while its physical assumptions hold at chunk boundaries and during fallback. Admission and execution checks must address those transitions as well as the nominal path.

Fallacy: Static admission checks protect a machine against obstacle displacements during active execution.

The arm begins an admitted reach toward the mug with the conveyor guard clear of its swept volume. During execution, a coworker slides a tote into the tool’s path. The admission check was correct for the earlier geometry but no longer supports continued motion. Execution monitoring must detect the changed clearance and begin deceleration while sufficient stopping room remains. The design must bound how quickly workspace changes become visible via sensor bus latency and reserve the stopping margin needed to respond before the updated geometry becomes impossible to avoid.

Pitfall: Checking each action chunk alone without examining the motion the chunks compose.

The arm receives successive chunks that each reverse a joint’s direction. Each chunk passes its own acceleration and jerk checks, yet the sequence produces oscillatory motion that can excite the drivetrain’s resonant frequencies through gearbox compliance. Admission must compare derivatives across each seam and retain enough recent motion history to detect recurring reversals that would drive Joule heating (\(I^2R\)) in the stator. The motor and transmission execute the composed trajectory, and treating chunks as independent requests hides behavior that appears only when the requests are joined.

Pitfall: Delaying fallback transition past the hard stopping horizon in the hope that delayed compute finishes.

With the lease run to its 278 ms ceiling, the worked arm’s record ends its nominal setpoints at 320 ms and carries a 300 ms matched stop suffix that must finish by 600 ms, so the MCU must commit to fallback at 300 ms unless it has admitted a valid replacement. At that point the application processor reports inference nearly complete, but it has not delivered an executable plan. Waiting spends the runway reserved for deceleration. The MCU must follow the matched stop suffix at the commitment point. Progress reports cannot extend a mechanical stopping budget; only a newly validated trajectory can justify continued execution.

Pitfall: Relying solely on feedforward dynamic models when physical contact or payload mass can change abruptly.

The arm lifts an item near its 3 kg payload bound using feedforward torque computed for the loaded arm. The item slips from the gripper, but the drives keep applying the same lifting torque to the now unloaded arm, so it accelerates upward. The admitted trajectory has not changed; the dynamics that made its commands appropriate have. Feedback monitoring must detect the resulting tracking error and constrain the commands within the available margin before a mechanical limit strike or thermal derating. A feedforward model improves nominal tracking, but it cannot replace runtime checks for abrupt changes in payload or contact.

Fallacy: A trajectory can omit an achievable terminal stopping suffix if replacement plans are expected to arrive in time.

At its 1.5 m/s drive limit, the mobile manipulator’s base needs a \(C^2\) suffix of \(T=1.5v_c/a_{\text{brake}}\), 1,125 ms at the credible 2 m/s², to stop without exceeding that deceleration. A proposed suffix sized by the constant-deceleration time \(v_c/a_{\text{brake}}\) is a third shorter, so its profile peaks at \(1.5a_{\text{brake}}\), past what the loaded rack tolerates. Expecting the next plan to arrive does not make this fallback executable. The admission gate must check \(T_{\mathrm{stop}} \ge 1.5\,v_c/a_{\text{brake}}\) for the \(C^2\) profile it latches and reject a record that fails. Every accepted trajectory needs a physically achievable termination path for the case in which no replacement becomes available.

Summary

A trajectory is a timed proposal, and what shapes it is the case in which the next one is late. An inference-latency quantile is a scheduling risk target, not a safety certificate. It sets how often the machine should expect a late replacement, and the resident stop is what the machine does when one comes due. Two clocks bound the horizon from opposite sides. The compute tail pushes the commitment point later, while target evidence expires on its own schedule; on the conveyor, even a tracked observation of the mug expires before the worked 300 ms commitment (Goals That Expire), so tracking that long needs fresh evidence rather than a later timestamp.

Commitment is where these results meet. A replacement must pass full admission before \(t_{\mathrm{commit}}\), not merely before the last nominal setpoint. On this machine the shared 60 ms lease ends a stall long before then and sends the arm to its state-matched fallback with 68 mm of clearance left; commitment caps that lease at 278 ms, and a record that reaches commitment without a successor plays the \(C^2\) suffix the MCU latched before motion began. The worked arm’s 60 mm of cruise and 150 mm suffix leave 90 mm of geometric margin before uncertainty and unreserved delay. On the mobile manipulator’s base, the suffix the tote rack tolerates raises the stopping budget at the drive limit to 1,194.15 mm, past the 1.10 m rack-end clear distance.

Key Takeaways: Timed motion and independent stopping
  • A latency quantile is a risk target: The design-tail replacement target allocates the risk of a late plan and never certifies arrival, so every admitted trajectory carries a resident stop for the miss.
  • Commit before the runway is spent: Admission closes at \(t_{\mathrm{commit}}\), the deadline chosen so the matched stop still fits, and commitment caps the chunk lease that ends a stall first. On the arm, a lease run 200 ms past commitment breaches the 300 mm clearance by 110 mm.
  • Evidence age and the compute tail pull apart: A long tail pushes commitment later while target evidence expires on its own clock. Tracking past the evidence horizon needs a fresh observation, never a stretched timestamp.
  • A gentle stop is a longer stop: A \(C^2\) stop at the same peak deceleration travels half again the constant-deceleration distance, and on the mobile manipulator adding that term carries the budget past the rack-end clear distance at the drive limit.
  • The stage that first sees a failure owns it: An invalid chunk, an infeasible seam, and a changed world first become visible at admission, at the seam, and during motion, so each stage holds its own signal and its own time budget for rejecting the plan.
  • Continuity is not feasibility: A \(C^2\) seam removes reference jumps, but the bridge’s interior jerk, torque, resonance, and clearance must still be checked against the actual drive.
  • The planner proposes, the MCU admits: The trajectory record binds setpoints, deadlines, and stop coefficients under its parent lease’s digest, so the permission path judges the proposal by its content and holds a stop no host failure can erase.

What’s Next: From admitted plans to per-tick permission
This chapter admits whole proposals. The MCU checks a complete trajectory and its matched stop before commitment and latches the stop in protected memory. Admission judges the plan against the state the machine was in when the plan arrived, yet while the plan runs the plant can lag its reference, an obstacle can appear, and an actuator can saturate. Safety Enforcement checks each tick against live state, insets the stopping distance by the tracking error the controller can bound, and owns the fallback ladder whose stop rung plays this chapter’s resident stop. That inset is the last term of the machine’s stopping budget, and adding it sets the speed at which the mobile manipulator may run the aisle.

Back to top

Footnotes

  1. Action chunking representations: ACT and Diffusion Policy chunks carry no boundary-derivative constraints, so the planner must propose a transition bridge across each replanning seam, and the permission path checks it before admission.↩︎

  2. Deterministic proposal verification: The permission path isolates unprivileged trajectory proposals within hardware-managed staging buffers and admits one only after checking it there (section 1.5), so no unchecked setpoint reaches the motor control registers. For runtime safety filter architectures, see The Deterministic Gatekeeper.↩︎

  3. \(C^2\) derivative continuity: \(C^2\) continuity means that position, velocity, and acceleration remain unbroken functions of time across trajectory boundaries. In permanent-magnet synchronous motors (PMSM), electromagnetic torque couples directly to quadrature stator current (\(\tau = K_t I_q\)). An acceleration step asks for a finite torque and current step under this model, while a velocity step implies an ideal acceleration impulse.↩︎

  4. Sampling and mechanical modes: A control period faster than a mechanical mode can help resolve that mode but is not a stability proof. Controller phase margin, sensor delay, damping, filtering, and actuator bandwidth must be validated for the identified joint.↩︎

  5. Trajectory jerk: A jerk objective can make a particular bridge smoother. A finite jerk bound alone does not exclude energy near a measured resonance; the complete command spectrum and closed-loop response must be checked for the joint and load.↩︎

  6. Actuator Thermal Derating: Joule heating (\(I^2R\)) in the windings raises stator temperature, and past its limit degrades magnet flux and insulation, so motor controllers enforce derating curves that throttle continuous torque. A velocity profile that ignores this governor meets a mid-trajectory current limit and loses tracking.↩︎

  7. Inter-core shared-memory contracts: A shared-memory implementation needs an ownership protocol, cache maintenance where required, and release/acquire ordering. The MCU validates a completed candidate and copies the admitted plan and stop into protected memory before activation.↩︎

  8. Drive and resonance response: A sharp command can excite a joint’s identified flexible modes, but their frequencies and damping depend on the transmission and load. Current limiting, desaturation detection, DC-bus response, and shutdown depend on the selected driver and its configuration; see the TI gate-driver protection description.↩︎