Systems and Hardware
This appendix collects the embedded timing, memory, power, and actuator models used throughout this book, together with the byte layouts of records that cross the proposal boundary. Each bound depends on a specified device, workload, and operating envelope; the equations identify what must be measured before a physical deadline can be claimed.
How to Use This Appendix
Consult this appendix when diagnosing physical systems bottlenecks, timing jitter, electrical rail instability, or hardware interface boundaries across chapters in this book:
| When you encounter this systems symptom | Consult | For this quantitative tool |
|---|---|---|
| A real-time safety task misses periodic execution deadlines | section 3 | Worst-case execution time (WCET) and Response Time Analysis (RTA) |
| A software deadlock or kernel panic freezes actuator control loops | section 3 | Watchdog detection and separately measured stop-path response |
| Inverter bridge MOSFETs burn out or trip overcurrent protections | section 4 | Microcontroller PWM complementary timers and dead-time insertion |
| Heavy neural inference bursts induce compute brownout resets | section 5 | Inductive voltage droop (\(L dI/dt\)) and alpha-power gate delay |
| High-rate sensor DMA streams cause safety threads to miss deadlines | section 6 | DRAM bank-conflict penalties and non-preemptive burst queuing |
| Sensor fusion streams suffer temporal registration skew under motion | section 7 | PTP hardware timestamping and bounded clock conversion |
| Shared memory queues between Linux and the safety microcontroller (MCU) return torn or stale data | section 8 | SoC hardware mailboxes, RPMSG, and hardware memory barriers |
| Joint actuators fail to track sudden torque reversals, chatter, or overheat | section 9 | Stator \(L/R\) constants, thermal ODEs, and reflected rotor jerk limits |
| Emergency braking spikes DC bus voltage and damages power silicon | section 10 | Regenerative capacitive energy surges and dynamic brake choppers |
| Shared serial buses experience queuing and message jitter | section 11 | CAN FD priority blocking, EtherCAT cycle budgets, and bounded seqlocks |
| Monocular 3D bounding boxes distort and depth covariance diverges | section 12 | Pinhole intrinsic projection, Zhang’s calibration, and metric unprojection covariance |
| A mobile base breaches clearance buffers under surface wetness | section 13 | Kinematic stopping envelopes, information age lag, and velocity clamps |
| A record must be laid out for a fixed-size mailbox or log | section 14 | Proposal and record byte layouts; manifest and register field orders |
| A handover, fault trial, or release gate must be implemented step by step | section 14 | Authority-transfer, fault-injection, and release-gate protocols beside their records |
| You need rapid order-of-magnitude physical anchors across time, kinetics, thermal, and risk | section 2 | Rate hierarchy, blind travel conversions, thermal constants, and exposure walls |
Numbers to Know in Physical AI
Just as Jeff Dean’s “Latency Numbers Every Programmer Should Know”1 shaped distributed systems and classical machine learning systems grounded software performance in memory bandwidth and arithmetic intensity, physical AI systems engineers require a corresponding quantitative intuition spanning computation, kinetics, thermal dissipation, and functional safety. In physical AI, software latency is not merely waiting time; it translates directly into irreversible kinetic momentum, uninspected travel distance, and thermodynamic heat accumulation in motor stators and compute silicon.
This section compiles the foundational order-of-magnitude numbers, scaling laws, and engineering rules of thumb that govern cyber-physical machine design. All numbers are single-sourced from mlsysim. Memorize the relationships; use the specific numbers as sanity checks.
Systems Perspective 0.1: Three physical numbers that matter most
- Kinetic equivalence: \(1\text{ ms} = 1\text{ mm}\) (at \(1\text{ m/s}\)): At a nominal robotic speed of \(1\text{ m/s}\), every single millisecond of perception, inference, or fieldbus latency translates into exactly \(1\text{ mm}\) of blind travel before retarding torque can be applied. At highway velocity (\(30\text{ m/s}\)), each millisecond is \(3\text{ cm}\). In physical systems, software latency is not waiting time; it is physical displacement.
- Thermal divergence: \(\tau_{\text{silicon}} \sim 1\text{ ms}\) vs. \(\tau_{\text{stator}} \sim 100\text{ s}\): Semiconductor junctions heat adiabatically within milliseconds during deep neural network bursts, precipitating voltage droop or thermal throttling before heat spreaders react. In contrast, electromagnetic stator windings heat over tens to hundreds of seconds, tolerating transient overcurrent for aggressive maneuvers but accumulating thermal energy that eventually limits sustained torque.
- The exposure wall: \(N = 3 / \lambda\): Proving an ultra-low catastrophic failure rate of \(10^{-8}/\text{hour}\) (ISO 26262 ASIL D) requires \(3 \times 10^8\) failure-free operational hours under the Poisson Rule of Three (Hanley and Lippman-Hand 1983). Statistical empirical testing of learned end-to-end models cannot cross this exposure wall without deterministic runtime permission envelopes and formal safety filters.
Rate and latency hierarchy across machine levels
Control rates in physical AI rise steeply from the deliberative brain down to the physical body (table 1). Deliberative multimodal models (VLAs) operate at human reaction scales (\(1\text{--}5\text{ Hz}\)). Action chunking models emit future trajectory waypoints at \(10\text{--}50\text{ Hz}\). Beneath the proposal boundary, the permission path enforces safety barriers at \(1\text{ kHz}\). At the lowest levels, power electronic current loops and PWM switching operate at tens to hundreds of kilohertz to maintain electromagnetic flux and drive torque. For real-time timer schedulability and response-time analysis, see section 3; for inverter gate switching and dead-time modeling, see section 4.
| Machine Level | Frequency Band | Cycle Period | Blind Travel at 1 m/s | Architectural Mechanism & Bound |
|---|---|---|---|---|
| Brain (Deliberation) | 1–5 Hz | 200–1,000 ms | 200–1,000 mm | Multimodal VLA reasoning; memory- and compute-bound |
| Brain (Action Chunking) | 10–50 Hz | 20–100 ms | 20–100 mm | Action chunk diffusion/transformer decoding; amortized |
| Nervous System (Permission) | 1 kHz | 1 ms | 1 mm | Control barrier certificates, stopping envelopes, lease watchdog |
| Body (Current Loop) | 10–25 kHz | 40–100 µs | 40–100 µm | Field-oriented current control (FOC), torque tracking, stator flux |
| Body (Inverter Switching) | 50–200 kHz | 5–20 µs | 5–20 µm | Power MOSFET gate drive, dead-time insertion (\(t_{\text{dead}}\)), inductive droop |
Kinetic translation and safe stopping envelopes
Total stopping distance \(d_{\text{stop}} = v \cdot \tau_{\text{delay}} + v^2 / (2 a_{\text{brake}})\) combines the linear blind travel accrued during computational delay and the quadratic mechanical braking distance (table 2). As platform speed increases, absolute blind travel expands rapidly, consuming entire clearance margins before deceleration can begin. For multi-axis kinematic chains, jerk-bounded trajectories, and information-age lag derivations, see section 13.
| Platform Archetype | Nominal Velocity \(v\) | Braking Decel \(a\) | Blind Travel (\(\tau=50\text{ ms}\)) | Blind Travel (\(\tau=200\text{ ms}\)) | Total Stop (\(\tau=200\text{ ms}\)) |
|---|---|---|---|---|---|
| Humanoid / Quadruped | 1 m/s (3.6 km/h) | 4 m/s² (0.41 g) | 50 mm | 200 mm | 325 mm (61.5%) |
| Warehouse Mobile Manipulator | 1.5 m/s (5.4 km/h) | 2 m/s² (0.20 g) | 75 mm | 300 mm | 863 mm (34.8%) |
| Urban Delivery Robot | 6 m/s (21.6 km/h) | 4.5 m/s² (0.46 g) | 300 mm | 1.2 m | 5.2 m (23.1%) |
| Autonomous Vehicle (Highway) | 30 m/s (108 km/h) | 7 m/s² (0.71 g) | 1.5 m | 6 m | 70.3 m (8.5%) |
Edge memory bandwidth and action chunk amortization
Large multimodal foundation models on edge system-on-chip (SoC) architectures are memory-bandwidth bound during autoregressive generation (table 3). Streaming a 7-billion-parameter model over a sustained \(140\text{ GB/s}\) LPDDR5 interface limits single-step generation to \(10\text{--}20\text{ Hz}\). Predicting action chunks of length \(H=16\) amortizes the weight streaming transfer over multiple future control steps, lifting effective control bandwidth into the hundreds of hertz. For DRAM bank organization, conflict penalties, and interconnect arbitration under concurrent DMA traffic, see section 6.
| Model & Precision | Parameters | Memory Footprint | DRAM Read Time (\(140\text{ GB/s}\)) | Single-Step Max Rate | Chunk Rate (\(H=16\)) |
|---|---|---|---|---|---|
| VLA-7B (FP16) | 7.0B | 14 GB | 100 ms | 10 Hz | 160 Hz equivalent |
| VLA-7B (INT8) | 7.0B | 7 GB | 50 ms | 20 Hz | 320 Hz equivalent |
| VLA-7B (INT4) | 7.0B | 3.5 GB | 25 ms | 40 Hz | 640 Hz equivalent |
| VLA-14B (INT8) | 14.0B | 14 GB | 100 ms | 10 Hz | 160 Hz equivalent |
Thermal time constants across compute and electromechanics
Thermal dissipation follows an exponential relaxation \(T(t) = T_{\text{amb}} + \Delta T_{\max} (1 - e^{-t/\tau_{\text{th}}})\) with time constants spanning five orders of magnitude (table 4). Silicon junctions overheat within milliseconds during computational bursts, demanding microsecond-scale DVFS and PDN droop management. In contrast, electromagnetic stator windings heat over minutes, allowing transient torque overdrive if bounded by an \(I^2 t\) thermal watchdog. For first-order thermal differential equations and stator winding degradation limits, see section 9; for regenerative energy absorption on DC power buses, see section 10.
| Subsystem Component | Physical Mechanism | Thermal Time Constant \(\tau_{\text{th}}\) | Critical Failure Mode | Safety Mitigation |
|---|---|---|---|---|
| Silicon Junction (Die) | Transistor channel self-heating | 1–10 ms | Gate delay stretch, brownout, thermal trip | Rapid frequency throttling, PDN decoupling |
| SoC Heat Sink / Package | Convective heat spreader dissipation | 10–60 s | Package thermal saturation, sustained throttling | Active fan modulation, workload migration |
| Motor Stator Windings | Copper resistive Joule heating (\(I^2 R\)) | 30–180 s | Insulation breakdown (Class H \(180^\circ\text{C}\)), short | \(I^2 t\) thermal protection, current derating |
| Motor Frame / Housing | Bulk metallic casing heat conduction | 10–30 min | Structural deformation, bearing grease loss | Natural convection, passive cooling fins |
| Traction Battery Pack | Electrochemical cell internal resistance | 5–20 min | Thermal runaway (\(> 60^\circ\text{C}\)), fire | Liquid cooling loop, charge/discharge cutoff |
Statistical safety bounds and exposure walls
Under the Poisson Rule of Three (Hanley and Lippman-Hand 1983), demonstrating that a physical system achieves a catastrophic failure rate target \(\lambda\) with \(95\text{ percent}\) confidence without observing a single failure requires testing for \(N = 3 / \lambda\) operational hours (table 5). Meeting the ultra-dependable thresholds demanded by automotive functional safety (ISO 26262 ASIL D, \(\lambda < 10^{-8}/\text{hour}\) (ISO 26262 2018)) requires 300 million failure-free hours—a scale that renders end-to-end black-box statistical validation mathematically impossible without deterministic runtime permission envelopes. For proposal and manifest wire formats supporting runtime safety contracts, see section 14.
| Safety Standard / Regime | Target Failure Rate \(\lambda\) | Equivalent FIT (\(10^{-9}/\text{h}\)) | Required 0-Failure Hours (\(N=3/\lambda\)) | Engineering Implication |
|---|---|---|---|---|
| ISO 26262 ASIL D | \(< 10^{-8}/\text{hour}\) | \(< 10\text{ FIT}\) | \(300,000,000\text{ hours}\) (\(3 \times 10^8\text{ h}\)) | Empirically untestable by fleet testing alone; requires formal safety barriers |
| IEC 61508 SIL 3 / PL e | \(< 10^{-7}/\text{hour}\) | \(< 100\text{ FIT}\) | \(30,000,000\text{ hours}\) (\(3 \times 10^7\text{ h}\)) | Dual-channel lockstep hardware, diverse software monitoring |
| Commercial Robotaxi Target | \(< 10^{-6}/\text{hour}\) | \(< 1,000\text{ FIT}\) | \(3,000,000\text{ hours}\) (\(3 \times 10^6\text{ h}\)) | Human driver baseline equivalence (\(1\) fatality per \(10^8\text{ miles}\)) |
| Industrial Cobot (PL d) | \(< 10^{-6}/\text{hour}\) | \(< 1,000\text{ FIT}\) | \(3,000,000\text{ hours}\) (\(3 \times 10^6\text{ h}\)) | Force and power limiting, speed-and-separation monitoring |
Fieldbus latencies, jitter, and determinism
Communication buses exhibit sharp divides in latency and jitter (table 6). Industrial fieldbuses like EtherCAT achieve sub-microsecond jitter via dedicated hardware cut-through processing. In contrast, non-deterministic arbitration and shared wireless channels introduce tail latencies that exceed the reaction deadlines of high-speed electromechanical machines. For IEEE 1588 PTP hardware timestamping bounds, see section 7; for CAN-FD priority arbitration and EtherCAT cycle budgets, see section 11.
| Bus / Network Technology | Nominal Transit Latency | Worst-Case Jitter | Determinism Mechanism | Primary Machine Role |
|---|---|---|---|---|
| EtherCAT (ETG.1000) | \(100\,\mu\text{s}\text{--}1\text{ ms}\) | \(< 1\,\mu\text{s}\) | Hardware cut-through on-the-fly frame processing | Synchronous joint servo drive & sensor feedback (Body/Nervous) |
| CAN-FD (ISO 11898-1) | \(100\text{--}500\,\mu\text{s}\) | \(50\text{--}200\,\mu\text{s}\) | Bitwise non-destructive priority arbitration | Distributed sensors, legacy actuator controllers (Nervous/Body) |
| TSN Ethernet (802.1Qbv) | \(10\text{--}100\,\mu\text{s}\) | \(< 5\,\mu\text{s}\) | Time-aware shaper with scheduled transmission gates | High-bandwidth sensor ingress (lidar/cameras) to SoC (Boundary) |
| Standard IP / UDP Ethernet | \(0.5\text{--}5\text{ ms}\) | \(1\text{--}20\text{ ms}\) | Best-effort CSMA/CD; FIFO queueing | Asynchronous logging, inter-node telemetry (Brain) |
| Wi-Fi 6 / 5G URLLC | \(5\text{--}20\text{ ms}\) | \(10\text{--}500\text{ ms}\) (RF fade) | Wireless packet retransmission, contention window | High-level fleet dispatch, cloud mission updates (World/Governance) |
Real-Time Timers, Watchdogs, and Schedulability
In embedded real-time systems, temporal predictability is as vital as computational correctness. A late control action is not merely degraded; on physical hardware, it is incorrect and potentially destructive.
Real-time task schedulability and response time analysis
A periodic real-time task \(\tau_i\) is characterized by its worst-case execution time (WCET) \(C_i\), relative deadline \(D_i\), and period \(T_i\). Under a single-core, fixed-priority preemptive model with bounded blocking and no release jitter (such as Rate-Monotonic Scheduling (Liu and Layland 1973)), schedulability is checked using the worst-case response time \(R_i\): \[ R_i = C_i + B_i + I_i \le D_i \] where \(B_i\) is the maximum blocking duration induced by lower-priority tasks accessing shared resources, and \(I_i\) is the interference from higher-priority tasks. The response time is computed via the fixed-point recurrence: \[ R_i^{(k+1)} = C_i + B_i + \sum_{j \in hp(i)} \left\lceil \frac{R_i^{(k)}}{T_j} \right\rceil C_j \] starting with \(R_i^{(0)} = C_i+B_i\) and iterating to a fixed point or until a deadline is exceeded. A finite fixed point with \(R_i \le D_i\) for every task establishes schedulability under these scheduling and interference assumptions. WCET \(C_i\) is one component of response time, not the end-to-end sensor-to-actuator latency.
Hardware watchdogs and fault response
To detect a missed execution checkpoint, an embedded design may use a hardware watchdog timer. Its clock and response path must be independent enough of the monitored task for the claimed fault set; an independent crystal is one implementation.
The timer is initialized to a threshold value \(W_{\text{init}}\). Software execution threads must periodically refresh (or “kick”) the register before the count reaches zero. If \(W(t)\) represents the register count at physical time \(t\), and software executes a refresh at epoch \(t_k\), the register resets:2 \[ W(t_k) = W_{\text{init}} \] If the software misses the configured refresh window, the timer expires and raises its configured interrupt, reset, or external supervisor output. Expiry only detects the missed checkpoint. The safety case must bound expiry-to-drive response, wire any MCU-loss trip independently of the failed MCU, and show that the resulting state-matched brake or hold can stop the plant within its remaining clearance. A reset or safe torque off (STO) command alone may leave a moving load coasting.
Inverter Timers and Power Electronics Gate Drive
Actuator motor drives employ three-phase half-bridge inverters to convert DC bus voltage into alternating stator currents.
Microcontroller timer dead-time insertion
Each inverter phase comprises a high-side power MOSFET (or IGBT) and a low-side power MOSFET connected across the DC supply rail \(V_{\text{bus}}\). Microcontroller timer peripherals generate complementary pulse-width-modulated (PWM) drive signals with hardware-enforced dead-time insertion \(t_{\text{dead}}\): \[ t_{\text{dead}} \ge t_{\text{off, max}} + t_{\text{prop, skew}} - t_{\text{on, min}} \] where \(t_{\text{off, max}}\) is the maximum turn-off time of the power switch, \(t_{\text{on, min}}\) is the minimum turn-on time, and \(t_{\text{prop, skew}}\) is the propagation delay mismatch across gate drivers.3
For the specified device and gate-drive delays, adequate dead time reduces overlap between high-side and low-side conduction. If both switches conduct simultaneously, shoot-through creates a low-impedance path across the DC bus; current and damage depend on bus impedance, protection, and event duration.
Inductive Voltage Droop and Gate Delay Stretch
When deep neural network accelerators (such as systolic array matrix engines) transition from idle to full execution, current draw increases by tens of amperes within nanoseconds.
Power delivery network impedance and rail droop
Every power delivery network (PDN) exhibits finite parasitic loop inductance \(L_{\text{PDN}}\) and equivalent series resistance \(R_{\text{PDN}}\) across PCB traces, package balls, and bond wires. When accelerator execution triggers a transient current step \(\Delta I\) with rise time \(t_r\) (giving current slew rate \(dI/dt \approx \Delta I / t_r\)), Faraday’s law of induction dictates an instantaneous voltage collapse \(\Delta V_{\text{droop}}\): \[ \Delta V_{\text{droop}} = L_{\text{PDN}} \frac{dI}{dt} + \Delta I \cdot R_{\text{PDN}} \] If supply voltage \(V(t) = V_{\text{nom}} - \Delta V_{\text{droop}}\) approaches a device’s characterized minimum operating voltage \(V_{\min}\), timing margin may shrink or brownout protection may act.
Digital logic gate delay and the alpha-power law
In sub-micron CMOS silicon, logic gate propagation delay \(t_{\text{prop}}\) is governed by the Sakurai-Newton alpha-power law:4 \[ t_{\text{prop}}(V) \propto \frac{C_L \cdot V}{(V - V_{\text{th}})^\alpha} \] where \(C_L\) is the gate load capacitance, \(V_{\text{th}}\) is the transistor threshold voltage, and \(\alpha \in [1.2, 1.5]\) is the velocity saturation index (contrasting with \(\alpha = 2.0\) in long-channel theory).
When rail voltage droops from \(V_{\text{nom}}\) to \(V_{\text{droop}}\), propagation delay stretches according to: \[ \frac{t_{\text{prop}}(V_{\text{droop}})}{t_{\text{prop}}(V_{\text{nom}})} = \frac{V_{\text{droop}}}{V_{\text{nom}}} \left( \frac{V_{\text{nom}} - V_{\text{th}}}{V_{\text{droop}} - V_{\text{th}}} \right)^\alpha \] In a synchronous digital pipeline with clock period \(T_{\text{clk}}\), setup time \(t_{\text{setup}}\), and clock skew \(t_{\text{skew}}\), timing closure requires: \[ t_{\text{prop}} + t_{\text{setup}} + t_{\text{skew}} \le T_{\text{clk}} \] Stretching \(t_{\text{prop}}\) reduces setup slack. A timing failure occurs only if the measured path crosses its slack limit; a brownout reset depends on a separately configured supervisor threshold. Local decoupling can reduce the rail excursion, subject to its impedance and placement.
DRAM Contention and Interconnect Arbitration
In shared-memory multi-core SoC platforms, direct memory access (DMA) transfers and vision prefetching compete with the permission path for memory controller command queues and physical DRAM banks.
DRAM bank organization and conflict latency
A DRAM chip is structured into multiple independent banks, each possessing a single row buffer. Accessing storage cells requires three sequential operations:
- Row activate (\(t_{\text{RCD}}\)): Loads a row of storage cells into the bank’s row buffer.
- Column access (\(t_{\text{CAS}}\)): Reads or writes data from the open row buffer onto the data bus.
- Row precharge (\(t_{\text{RP}}\)): Restores charge to storage capacitors and closes the active row.
When consecutive operations target different rows of the same bank (a bank conflict), the controller may need to precharge and activate a row before column access, adding approximately \(t_{\text{RP}}+t_{\text{RCD}}\). Each bank can have its own open row. The penalty and number of switches depend on address mapping and the controller schedule.5
Interconnect crossbars and burst contention
An accelerator tile is split into bounded bus transactions; it is not one atomic AXI burst. For an illustrative FIFO controller that admits all \(K\) transactions ahead of a safety request, with no priority bypass or new arrivals, the ideal bus-transfer component is \[ t_{\text{queue,ideal}}=\frac{\sum_{k=1}^{K}B_k}{\mathrm{BW}_{\text{bus}}}. \] Add the bank-switch penalties for the actual address sequence and then the safety request’s own transfer and compute times. This is a constructed scheduling model, not a portable worst-case bound: refresh, protocol overhead, controller reordering, and competing traffic can increase latency, while qualified QoS can bypass queued work. Contention for Shared Resources gives a recomputable case. A local, coherently published safety snapshot can avoid this DDR path, but TCM capacity alone does not provide the snapshot or bound its transfer time.
Clock Synchronization and Network Timestamps
Distributed perception must convert sensor timestamps into a common clock domain with a measured conversion-error bound.
Precision time protocol message exchange
The IEEE 1588 Precision Time Protocol (PTP) synchronizes a Slave clock (\(S\)) to a Master clock (\(M\)) by exchanging four physical timestamps across the communication link:
- \(t_1\): Master transmits a Sync frame, recording its local transmission timestamp.
- \(t_2\): Slave receives the Sync frame, recording its local arrival timestamp.
- \(t_3\): Slave transmits a Delay_Req frame, recording its local transmission timestamp.
- \(t_4\): Master receives the Delay_Req frame, recording its local arrival timestamp.
Assuming stable clocks during the exchange and symmetric forward and reverse propagation delay (\(D_{M \to S}=D_{S \to M}=D\)), the time relationships satisfy: \[ t_2 = t_1 + O + D \] \[ t_4 = t_3 - O + D \] where \(O\) is the slave-minus-master clock offset. Under those assumptions, the estimated offset is: \[ O = \frac{(t_2 - t_1) - (t_4 - t_3)}{2} \] The one-way network propagation delay is: \[ D = \frac{(t_2 - t_1) + (t_4 - t_3)}{2} \] The slave estimates the mapping to the master domain by subtracting \(O\). Asymmetric path delay, oscillator drift between exchanges, and timestamp error leave a residual that must be bounded for evidence-age checks.
Physical layer hardware timestamping
Software timestamping includes operating-system dispatch and queue variation, which must be measured for the selected network stack.
PTP-capable hardware can timestamp near the Ethernet PHY or media access control (MAC) boundary, reducing host-dispatch error.6 It does not by itself establish a submicrosecond end-to-end clock bound; topology, asymmetry, synchronization interval, timestamp location, and MCU clock conversion must be characterized.
Heterogeneous SoC Mailboxes and Memory Barriers
Some robotics SoCs couple an application processor running Linux with a real-time core or microcontroller. Their communication contract must specify memory ownership, cache behavior, message validity, and what the real-time side does when no new message arrives.
CPU pipeline reordering and memory fences
Weak memory ordering and noncoherent caches can let a receiver observe a notification without a current payload unless the producer and consumer follow one published protocol:
// Core A (Application Processor); q_target and q_cmd are joint_target_t structs
shared_buffer->q_target = q_cmd; // Store 1: Payload (struct copy)
mailbox_doorbell = 1; // Store 2: Interrupt triggerIf the CPU or interconnect reorders Store 2 ahead of Store 1, Core B receives the interrupt before the new joint target is committed to physical memory, reading stale or invalid data.
A data memory barrier can order accesses within its selected shareability domain:7
shared_buffer->q_target = q_cmd; // Struct copy of the joint targets
__asm__ volatile("dmb ish" ::: "memory"); // Only if both peers share this domain
mailbox_doorbell = 1;The barrier in this example is sufficient only if both cores share the inner-shareable coherent domain and the doorbell has the specified device-memory ordering. It does not flush a noncoherent cache or make data visible to an unrelated DMA master. Otherwise, use the platform’s appropriate barrier and DMA cache-ownership synchronization, or map the buffer coherently, and verify the receiver’s acquire side. The real-time reader still needs a bounded validation attempt and a lease-limited fallback when publication is torn or stale.
Actuator Electrical and Thermal Dynamics
Actuators convert electrical energy into mechanical work through electromagnetic lorentz forces, subject to coupled electrical and thermal constraints.
Stator electrical rise time
A brushless DC (BLDC) motor phase winding exhibits phase resistance \(R_{\text{phase}}\) and phase inductance \(L_{\text{phase}}\). Applying terminal voltage \(V_{\text{terminal}}\) against back-electromotive force \(e_{\text{bemf}} = K_e \omega_m\) yields the first-order stator current ODE: \[ L_{\text{phase}} \frac{dI(t)}{dt} + R_{\text{phase}} I(t) = V_{\text{terminal}} - K_e \omega_m \] For a voltage step applied from rest (\(\omega_m = 0\)), phase current rises exponentially: \[ I(t) = \frac{V_{\text{terminal}}}{R_{\text{phase}}} \left( 1 - e^{-t / \tau_e} \right), \quad \tau_e = \frac{L_{\text{phase}}}{R_{\text{phase}}} \] where \(\tau_e\) is the electrical time constant: in this ideal step model, current reaches about 63 percent of its final value after one \(\tau_e\). Torque \(\tau_m=K_t I\) follows this current only while the magnetic, voltage, and control assumptions hold; a command is not an instantaneous torque change.
Lumped thermal networks and duty cycle
Current flowing through stator windings dissipates resistive Joule heat: \[ P_{\text{loss}}(t) = I_{\text{rms}}^2(t) R_{\text{phase}}(T) \] where copper resistance increases linearly with temperature: \[ R_{\text{phase}}(T) = R_0 \left[ 1 + \alpha_{\text{Cu}} (T - T_0) \right] \] with temperature coefficient \(\alpha_{\text{Cu}} \approx 0.00393\text{ K}^{-1}\) for copper. In a single-node lumped thermal model with thermal resistance to ambient \(\theta_{JA}\) (in \(\text{K/W}\)) and thermal heat capacity \(C_{\text{th}}\) (in \(\text{J/K}\)), temperature rise \(\Delta T(t) = T_{\text{winding}}(t) - T_{\text{ambient}}\) satisfies:8 \[ C_{\text{th}} \frac{d\Delta T(t)}{dt} = P_{\text{loss}}(t) - \frac{\Delta T(t)}{\theta_{JA}} \] Under constant power, temperature rises with thermal time constant \(\tau_{\text{th}} = \theta_{JA} C_{\text{th}}\): \[ \Delta T(t) = P_{\text{loss}} \theta_{JA} \left( 1 - e^{-t / \tau_{\text{th}}} \right) \] Continuous torque capacity \(\tau_{\text{cont}}\) is bounded by maximum allowable winding temperature \(\Delta T_{\max}\): \[ \tau_{\text{cont}} \le K_t \sqrt{\frac{\Delta T_{\max}}{\theta_{JA} R_{\text{phase}}}} \] An above-continuous torque may be permitted transiently if the device’s temperature estimate and specified current-time limits allow it. The integral \(\int_0^t I^2dt\) is one possible protection measure, not a universal motor rating.
Reflected rotor inertia and angular jerk limits
Geared electromagnetic actuators amplify delivered motor torque while multiplying rotor inertia at the joint output. For a transmission with gear reduction ratio \(N = \omega_{\text{motor}} / \omega_{\text{joint}}\), kinetic energy conservation dictates the reflected inertia acting at the output link: \[ E_k = \frac{1}{2} J_{\text{rotor}} \omega_{\text{motor}}^2 + \frac{1}{2} J_{\text{load}} \omega_{\text{joint}}^2 = \frac{1}{2} (J_{\text{load}} + N^2 J_{\text{rotor}}) \dot{q}^2 \] The effective rotational inertia seen at joint coordinate \(q\) is: \[ J_{\text{eff}} = J_{\text{load}} + N^2 J_{\text{rotor}} \] The joint equation of motion under motor electromagnetic torque \(\tau_{\text{motor}}\) is: \[ \ddot{q} = \frac{N \tau_{\text{motor}} - \tau_{\text{ext}}}{J_{\text{load}} + N^2 J_{\text{rotor}}} \] Differentiating \(\ddot{q}\) with respect to gear ratio \(N\) at zero external load yields: \[ \frac{\partial \ddot{q}}{\partial N} = \frac{\tau_{\text{motor}} (J_{\text{load}} - N^2 J_{\text{rotor}})}{(J_{\text{load}} + N^2 J_{\text{rotor}})^2} \] Setting \(\frac{\partial \ddot{q}}{\partial N} = 0\) yields the inertia-matching ratio \(N^* = \sqrt{J_{\text{load}} / J_{\text{rotor}}}\). When \(N > N^*\), counter-intuitively, increasing the gear ratio decreases delivered joint acceleration because the motor spends the majority of its torque accelerating its own rotor rather than the link.
Dynamic angular jerk and torque slew limits
Angular jerk \(j_{\text{joint}}(t) = \dddot{q}(t)\) measures the time rate of change of joint acceleration: \[ j_{\text{joint}}(t) = \frac{N}{J_{\text{load}} + N^2 J_{\text{rotor}}} \frac{d\tau_{\text{motor}}(t)}{dt} \] Electromagnetic torque relates to stator quadrature current via torque constant \(K_t\): \(\tau_{\text{motor}} = K_t I_q\). From the stator electrical dynamics in this section, current slew rate is bounded by winding inductance \(L_{\text{phase}}\): \[ \frac{d\tau_{\text{motor}}}{dt} = K_t \frac{dI_q}{dt} = \frac{K_t}{L_{\text{phase}}} \left( V_{\text{terminal}} - K_e \omega_m - R_{\text{phase}} I_q \right) \] Under maximum DC bus terminal voltage saturation \(V_{\max}\), the physical upper bound on delivered angular jerk is: \[ |j_{\max}| \le \frac{N K_t (V_{\max} - K_e \omega_m)}{L_{\text{phase}} (J_{\text{load}} + N^2 J_{\text{rotor}})} \] When an unprivileged neural policy outputs a step torque discontinuity \(\Delta \boldsymbol{\tau}\) across discrete timesteps, the commanded derivative \(\frac{d\tau}{dt} \to \infty\) cannot be delivered instantaneously by physical silicon. The inverter enters hard voltage saturation, causing steep current slew (\(dI/dt\)), intense thermal stress on power MOSFETs, and shock loads across gear-tooth contact flanks (\(\sigma_b \propto W_t / (b m Y)\)). Synchronous pre-actuation invariant filters evaluate numerical torque derivatives \((\boldsymbol{\tau}[k] - \boldsymbol{\tau}[k-1]) / \Delta t\) to ensure requested actions remain within allowable jerk envelopes before latching power stages.
DC Bus Power Distribution and Energy Absorption
A robotic platform’s electrical power distribution network must supply acceleration surges and absorb regenerative braking energy across finite bus capacitance and harness impedance.
Inductive droop and capacitive decoupling
When multiple actuators accelerate, harness resistance and inductance impede source current while local capacitance supplies the difference. For a specified waveform, the resistive and inductive terms are \(\Delta I_{\text{source}}R_{\text{bus}}\) and \(L_{\text{bus}}\,dI_{\text{source}}/dt\); capacitor discharge obeys \[ \Delta V_C(t)=\frac{1}{C_{\text{bus}}}\int_0^t\bigl(I_{\text{load}}(s)-I_{\text{source}}(s)\bigr)\,ds. \] These terms cannot simply be added as simultaneous peaks without a circuit and waveform model. If the resulting voltage crosses a configured under-voltage lockout (UVLO) threshold for long enough, the supply may disable or reset; the threshold, filtering, and plant consequence require measurement.
Regenerative braking surges and chopper sizing
During controlled regenerative deceleration, some mechanical kinetic energy \(E_k=\frac12mv^2\) (linear) or \(E_k=\frac12J_{\text{load}}\dot q_0^2\) (rotational) may return through the inverter. If the battery cannot accept it and an assumed fraction \(\eta_{\text{regen}}\) reaches the local bus capacitor \(C_{\text{bus}}\) before another sink acts, the ideal capacitor relation is: \[ \Delta E_C = \frac{1}{2} C_{\text{bus}} \left( V_{\text{final}}^2 - V_{\text{initial}}^2 \right) = \eta_{\text{regen}} E_k \] \[ V_{\text{final}} = \sqrt{ V_{\text{initial}}^2 + \frac{2 \eta_{\text{regen}} E_k}{C_{\text{bus}}} } \] For an implementation with an active brake chopper, the resistor and switch must absorb the modeled peak power and pulse energy when \(V_{\text{bus}}\ge V_{\text{clamp}}\):9 \[ R_{\text{brake}} \le \frac{V_{\text{clamp}}^2}{P_{\text{regen, peak}}} \] \[ P_{\text{regen, peak}} \approx \eta_{\text{regen}} \cdot \tau_{\text{brake}} \cdot \omega_{\max} \] The resistor inequality is only a peak-power sizing check; minimum resistance for switch current, pulse energy, and thermal recovery impose additional constraints.
Real-Time Fieldbuses and Lock-Free Synchronization
Coordinating distributed drives requires a measured network schedule and a bounded local publication protocol.
Fieldbus serialization and schedulability
On a shared serial bus, \(N_{\text{axes}}\) drives transmit telemetry and receive setpoints cyclically. Serialization time depends on the complete frame, physical bit rates, and any stuffing or retransmission allowance.
CAN FD uses non-destructive priority arbitration at its nominal bit rate; a winning frame then sends its data phase at the configured data bit rate. An error-free serialization estimate for frame \(i\) is \[ t_{\text{frame},i}\approx\frac{B_{\text{arb},i}}{R_{\text{nom}}}+\frac{B_{\text{data},i}}{R_{\text{data}}}+t_{\text{stuff},i}+t_{\text{interframe},i}. \] This estimate is not a response-time bound. A lower-priority frame already transmitting can block a newly ready high-priority frame until that transmission ends; arbitration losers defer without a collision-error retry. Bound each message’s queuing and release jitter with the actual priority set, frame lengths, error assumptions, and bus load; Bosch’s CAN FD description distinguishes the arbitration and data phases.
EtherCAT processes data as frames pass through slave controllers. For a specified topology, a cycle budget includes serialization of every configured frame, master and slave forwarding, PHY and cable propagation, processing, and a guard for jitter and error recovery: \[ T_{\text{cycle}}\ge\sum_f\frac{B_f}{R_{\text{link}}}+t_{\text{master}}+\sum_s t_{\text{slave},s}+t_{\text{prop}}+t_{\text{guard}}. \] The achievable cycle period is configuration dependent; short advertised periods do not establish a deadline for a particular machine. The EtherCAT Technology Group describes the processing method and configurable process data.
Camera Projective Geometry and Covariance Propagation
Perception pipelines map continuous Euclidean 3D scenes onto discrete 2D camera photosite grids.
Intrinsic projection matrix and radial distortion
Under the standard pinhole camera model, a 3D point \(\mathbf{p}_c = [x_c, y_c, z_c]^\top\) in camera coordinates projects onto pixel coordinates \(\mathbf{u} = [u, v]^\top\) via the intrinsic calibration matrix \(\mathbf{K}\):10 \[ \tilde{\mathbf{u}} = \begin{bmatrix} u \\ v \\ 1 \end{bmatrix} = \frac{1}{z_c} \mathbf{K} \mathbf{p}_c = \frac{1}{z_c} \begin{bmatrix} f_x & 0 & c_x \\ 0 & f_y & c_y \\ 0 & 0 & 1 \end{bmatrix} \begin{bmatrix} x_c \\ y_c \\ z_c \end{bmatrix} \] where \((f_x, f_y)\) are focal lengths in pixel units and \((c_x, c_y)\) is the principal point. Non-linear radial lens distortion is modeled by distortion coefficients \((k_1, k_2)\): \[ r^2 = x_n^2 + y_n^2, \quad x_d = x_n (1 + k_1 r^2 + k_2 r^4), \quad y_d = y_n (1 + k_1 r^2 + k_2 r^4) \] where \((x_n, y_n) = (x_c / z_c, y_c / z_c)\) are normalized image coordinates.
Metric unprojection and spatial covariance propagation
When unprojecting a 2D pixel observation \(\mathbf{u}\) with measured depth \(z\) into 3D camera coordinates, photosite measurement noise \(\mathbf{\Sigma}_{\text{meas}} = \text{diag}(\sigma_u^2, \sigma_v^2, \sigma_z^2)\) propagates through the unprojection Jacobian \(\mathbf{J}_{\text{unproj}}\): \[ \mathbf{p}_c = \begin{bmatrix} (u - c_x) z / f_x \\ (v - c_y) z / f_y \\ z \end{bmatrix}, \quad \mathbf{\Sigma}_c = \mathbf{J}_{\text{unproj}} \mathbf{\Sigma}_{\text{meas}} \mathbf{J}_{\text{unproj}}^\top \] Transforming this 3D point into the robot body frame via rigid extrinsic transform \(\mathbf{T}_{bc} = [\mathbf{R}_{bc}, \mathbf{p}_{bc}; \mathbf{0}^\top, 1]\) yields the spatial body covariance: \[ \mathbf{\Sigma}_b = \mathbf{R}_{bc} \mathbf{\Sigma}_c \mathbf{R}_{bc}^\top + \mathbf{\Sigma}_{\text{ext}} \] where \(\mathbf{\Sigma}_{\text{ext}}\) models independent extrinsic uncertainty under this first-order approximation; correlations require the corresponding cross terms. A probabilistic clearance buffer may scale with \(\sqrt{\lambda_{\max}(\mathbf{\Sigma}_b)}\) at a declared tail risk. A deterministic permission check instead needs a justified bounded-error envelope; covariance alone does not give a worst-case bound.
Zhang’s planar homography and camera calibration
Zhang’s calibration technique computes the camera intrinsic matrix \(\mathbf{K}\) by observing a planar calibration rig (such as a checkerboard pattern) across \(N \ge 3\) distinct orientations (Zhang 2000). Without loss of generality, assume the model plane lies on \(Z = 0\) in world coordinates. A 3D model point \(\mathbf{M} = [X, Y, 0, 1]^\top\) maps to a 2D image point \(\tilde{\mathbf{u}} = [u, v, 1]^\top\) through a \(3 \times 3\) planar homography matrix \(\mathbf{H}\): \[ s \begin{bmatrix} u \\ v \\ 1 \end{bmatrix} = \mathbf{K} \begin{bmatrix} \mathbf{r}_1 & \mathbf{r}_2 & \mathbf{r}_3 & \mathbf{t} \end{bmatrix} \begin{bmatrix} X \\ Y \\ 0 \\ 1 \end{bmatrix} = \mathbf{K} \begin{bmatrix} \mathbf{r}_1 & \mathbf{r}_2 & \mathbf{t} \end{bmatrix} \begin{bmatrix} X \\ Y \\ 1 \end{bmatrix} = \mathbf{H} \begin{bmatrix} X \\ Y \\ 1 \end{bmatrix} \] where \(\mathbf{H} = [\mathbf{h}_1 \; \mathbf{h}_2 \; \mathbf{h}_3] = \lambda \mathbf{K} [\mathbf{r}_1 \; \mathbf{r}_2 \; \mathbf{t}]\) with arbitrary nonzero scalar \(\lambda\).
Orthogonality constraints on the absolute conic
Because the rotation vectors \(\mathbf{r}_1\) and \(\mathbf{r}_2\) are orthonormal columns of an \(SO(3)\) matrix (\(\mathbf{r}_1^\top \mathbf{r}_2 = 0\) and \(\|\mathbf{r}_1\| = \|\mathbf{r}_2\| = 1\)), inverting \(\mathbf{K}\) yields: \[ \mathbf{r}_1 = \frac{1}{\lambda} \mathbf{K}^{-1} \mathbf{h}_1, \quad \mathbf{r}_2 = \frac{1}{\lambda} \mathbf{K}^{-1} \mathbf{h}_2 \] Imposing orthonormality on \(\mathbf{r}_1\) and \(\mathbf{r}_2\) defines two fundamental algebraic constraints per homography: \[ \mathbf{h}_1^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_2 = 0 \] \[ \mathbf{h}_1^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_1 - \mathbf{h}_2^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_2 = 0 \] The symmetric matrix \(\mathbf{B} = \mathbf{K}^{-\top} \mathbf{K}^{-1}\) represents the image of the absolute conic (IAC): \[ \mathbf{B} = \begin{bmatrix} B_{11} & B_{12} & B_{13} \\ B_{12} & B_{22} & B_{23} \\ B_{13} & B_{23} & B_{33} \end{bmatrix} \] Defining the 6-vector \(\mathbf{b} = [B_{11}, B_{12}, B_{22}, B_{13}, B_{23}, B_{33}]^\top\), each quadratic term \(\mathbf{h}_i^\top \mathbf{B} \mathbf{h}_j\) can be rewritten as the linear inner product \(\mathbf{v}_{ij}^\top \mathbf{b}\), where: \[ \mathbf{v}_{ij} = \begin{bmatrix} h_{i1}h_{j1} \\ h_{i1}h_{j2} + h_{i2}h_{j1} \\ h_{i2}h_{j2} \\ h_{i3}h_{j1} + h_{i1}h_{j3} \\ h_{i3}h_{j2} + h_{i2}h_{j3} \\ h_{i3}h_{j3} \end{bmatrix} \] The two constraints per observed orientation become the linear system: \[ \begin{bmatrix} \mathbf{v}_{12}^\top \\ (\mathbf{v}_{11} - \mathbf{v}_{22})^\top \end{bmatrix} \mathbf{b} = \mathbf{0} \] Stacking \(N \ge 3\) images forms the homogeneous system \(\mathbf{V} \mathbf{b} = \mathbf{0}\), where \(\mathbf{V} \in \mathbb{R}^{2N \times 6}\). The right singular vector of \(\mathbf{V}\) corresponding to the smallest singular value provides \(\mathbf{b}\) up to a scale factor. The intrinsic parameters \((f_x, f_y, c_x, c_y)\) and skew \(\gamma\) are then uniquely extracted via Cholesky factorization of \(\mathbf{B}\). This closed-form linear solution initializes the non-linear Levenberg–Marquardt optimization minimizing reprojection residuals over all observed fiducial corners.
Kinematic Stopping Envelopes and Information Age Lag
Halting an embodied machine transporting mass \(m\) at speed \(v\) requires balancing sensorimotor information freshness and mechanical braking deceleration.
Sensorimotor information age and lag distance
For a specified hazard detector and stop path, let \(\tau_{\text{delay}}\) bound the time from the physical state represented by the evidence until validated braking deceleration begins: \[ \tau_{\text{delay}} = t_{\text{age}} + t_{\text{detect}} + t_{\text{compute}} + T_{\text{bus}} + T_{\text{act}} \] where:
- \(t_{\text{age}}\) converts the evidence timestamp to the controller clock and includes exposure/readout and clock error.
- \(t_{\text{detect}}\) bounds recognition or lease-expiry detection.
- \(t_{\text{compute}}\) is the admitted stop decision, including any required input transfer.
- \(T_{\text{bus}}\) bounds command dispatch and network queuing.
- \(T_{\text{act}}\) ends when the measured actuator begins delivering the specified deceleration, not when a command register is written.
Under the explicit simplifying assumption that speed cannot increase before brake onset, the blind travel is bounded by \(d_{\text{blind}}=v\,\tau_{\text{delay}}\). If propulsion or a slope can increase speed, use its validated acceleration bound in this interval instead.
Braking dynamics and friction limits
Tire-floor friction and actuator torque place upper limits on achievable deceleration; \(a\le\mu g\) does not establish what braking the machine will deliver. Let \(a_{\text{brake}}>0\) be a validated lower bound on achieved deceleration throughout the stop, for the declared load, temperature, slope, brake condition, and surface. A justified friction floor \(\mu_{\text{floor}}\) may support that bound, but does not replace brake tests. With constant or stronger braking after onset, a localization bound \(\delta_{\text{loc}}\), a fixed protective clearance \(\delta_{\text{margin}}\), and a tracking-error bound \(\epsilon_{\text{track}}\), \[ d_{\text{stop}}(v)=v\,\tau_{\text{delay}}+\frac{v^2}{2a_{\text{brake}}}+\delta_{\text{loc}}+\delta_{\text{margin}}+\epsilon_{\text{track}}. \] Motion is admitted only when \(d_{\text{stop}}(v)\le D_{\text{clear}}\), where \(D_{\text{clear}}\) is taken as a validated lower bound on available path clearance. This is the inset stopping distance that Stopping Envelopes defends. The sampled controller must reserve intersample travel and a state-matched stop before the viable region is lost.
Kinetic energy derating and friction collapse
In an ideal friction-limited model, lowering \(\mu\) from \(\mu_{\text{nom}}\) to a positive \(\mu_{\text{fault}}\) changes the braking-distance ratio to \(\mu_{\text{nom}}/\mu_{\text{fault}}\). That ratio is illustrative; actual deceleration can also be limited by brake hardware or control. If surface friction is not sensed in time, derive \(a_{\text{brake}}\) from a controlled surface condition and inspection schedule, exclude degraded surfaces, or withhold motion. For the constant-speed pre-brake model above, solving the clearance inequality gives \[ v_{\text{clamp}}=-a_{\text{brake}}\tau_{\text{delay}}+\sqrt{(a_{\text{brake}}\tau_{\text{delay}})^2+2a_{\text{brake}}\left(D_{\text{clear}}-\delta_{\text{loc}}-\delta_{\text{margin}}-\epsilon_{\text{track}}\right)}. \] This clamp is valid only when \(D_{\text{clear}}\) exceeds the three fixed allowances, the braking and timing lower bounds hold, and the speed bound is enforced before entering the hazard corridor. No positive clamp follows if the available deceleration floor is unknown or zero.
Wire Formats for the Record Chain
The chapters name each record’s fields by meaning and state the invariant the record enforces. This section gives the byte layouts for records that must fit a fixed-size mailbox or log, and the canonical field order for the offline records that are stored and bound by digest. Every absolute time is an unsigned 64-bit count of nanoseconds on the safety microcontroller’s monotonic clock, every duration is an unsigned count of nanoseconds, and sync_error_ns carries the conversion bound for evidence captured on another clock. The clock and integrity policies themselves belong to Multi-Rate Cadences; the layouts here fix the algorithm for each integrity job. Corruption detection uses a CRC-32 (IEEE 802.3) over header and payload, lineage uses a SHA-256 digest of the consumed record, and authority uses HMAC-SHA-256 on operator commands, a keyed hash chain on the forensic log, and Ed25519 signatures on fault records and release artifacts. The authority, fault, and release records are each followed by the protocol that writes or checks them.
Fixed layouts are little-endian and packed in the order listed. Offsets are hexadecimal byte positions from the start of the record, and every multibyte field sits on its natural alignment, so no field needs hidden padding. A field whose length depends on a count comes after every fixed field, and its offset is written in terms of that count. The record itself carries \(K\) waypoints, \(N_j\) commanded joints, \(K_b\) barrier constraints, and \(K_a\) approach channels; the static authority manifest fixes \(N_c\) command components and \(N_s\) state components. Offline records (placement, fault, release) are identified by the SHA-256 digest of their canonical encoding, and the record that consumes one stores that digest under the consumed record’s name.
Proposal header and chunk payload
Every proposal that crosses the proposal boundary opens with the same header, and payload_kind selects the payload that follows at 0x50. Table 7 lays out the header with the minimal chunk payload of Multi-Rate Cadences. The chunk carries kinematic setpoints only. Torque is computed on the permission side, where the tracker derives it from the admitted reference, so a learned proposal never names a motor torque.
0x00–0x4F in every proposal; the other payload layouts in this section begin at 0x50.
| Offset | Field | Scalar type | Unit | Invariant and check |
|---|---|---|---|---|
0x00 |
sequence_id |
uint64_t |
dimensionless | Strictly increasing per producer; a record not newer than the last accepted one is rejected. |
0x08 |
t_evidence_ns |
uint64_t |
ns, permission clock | Capture epoch of the oldest evidence the proposal rests on, converted to the safety microcontroller’s clock. |
0x10 |
t_issue_ns |
uint64_t |
ns, permission clock | Time the producer published the record. |
0x18 |
t_expire_ns |
uint64_t |
ns, permission clock | Requested absolute expiry, no later than the chunk lease allows; the permission path may only shorten it. |
0x20 |
frame_id |
uint64_t |
dimensionless | Transform-tree key and calibration revision of the setpoints’ frame. |
0x28 |
parent_digest |
uint8_t[32] |
SHA-256 | Digest of the record this proposal was derived from; establishes lineage, authenticates nothing. |
0x48 |
sync_error_ns |
uint32_t |
ns | Bound on the evidence time’s conversion error; added to every age the reader checks. |
0x4C |
payload_kind |
uint16_t |
enumeration | CHUNK for this payload; INTENT, TRAJECTORY, and OPERATOR select the other payloads. |
0x4E |
payload_len |
uint16_t |
bytes | Payload length; bounds the parser before any payload byte is read. |
0x50 |
num_waypoints |
uint16_t |
count | Chunk horizon \(K\); a count outside the configured range is rejected. |
0x52 |
num_joints |
uint8_t |
count | Commanded joints \(N_j\); must equal the configured count, and payload_len must equal \(4+8KN_j\). |
0x53 |
reserved | uint8_t |
— | Zero. |
0x54 |
joint_positions |
float32[K][N_j] |
rad | Commanded joint angles within the reach limits (\(q_{\min} \le q \le q_{\max}\)). |
0x54 + \(4KN_j\) |
joint_velocities |
float32[K][N_j] |
rad/s | Commanded joint velocities within certified ceilings (\(\lVert \dot{\mathbf{q}} \rVert \le \dot{q}_{\max}\)). |
0x50 + payload_len |
crc32 |
uint32_t |
checksum | Last field; IEEE 802.3 CRC-32 over all preceding bytes. |
Intent payload
The intent lease of The Intent Lease travels under the proposal header with payload_kind set to INTENT (table 8). Three header fields take specific meanings. t_evidence_ns is the parent belief record’s evidence epoch, never its estimate epoch; parent_digest is that belief record’s digest, which the permission path matches against a retained record; and t_expire_ns is the requested expiry, which the permission path shortens to the earliest of the evidence horizon, its configured lease ceiling, and the stop deadline. The six bounds values are three conservative position-error envelopes and three task tolerances in the base frame named by frame_id. They are not an encoding of a covariance, and the producer must justify any conversion from its covariance estimate, including calibration bias and the declared tail risk.
| Offset | Field | Scalar type | Unit | Invariant and check |
|---|---|---|---|---|
0x00–0x4F |
proposal header | as above | as above | Table 7, with payload_kind = INTENT. |
0x50 |
target_pose |
float64[7] |
m; unit quaternion | Base-frame position and orientation; finite values, normalized quaternion, workspace prefilter. |
0x88 |
bounds |
float32[6] |
m | Error envelope \(e_{x,y,z}\), then task tolerance \(r_{x,y,z}\); \(0 \le e_i \le r_i\), each checked against the approved task profile. |
0xA0 |
wrench_request |
float32[6] |
N; N·m | Three requested forces and three torques; clamped or rejected against independent task and actuator limits. |
0xB8 |
terminal_request |
uint32_t |
enumeration | Requested terminal mode; the permission path selects a feasible approved response from the current load and contact state. |
0xBC |
crc32 |
uint32_t |
checksum | IEEE 802.3 CRC-32 over all preceding bytes. |
Trajectory payload
The trajectory record of The Trajectory Contract replaces the chunk on the running machine and travels under the same proposal header, with payload_kind set to TRAJECTORY and parent_digest set to the digest of the active intent lease (table 9). The header’s t_expire_ns carries the chunk lease; the intent’s own expiry comes from the lease that parent_digest identifies. The setpoint samples and the assumptions sidecar travel outside this fixed part. The permission path verifies sidecar_digest over both, validates the complete candidate in staging memory, and latches the admitted setpoints and stop suffix in protected memory before tracking begins.
sidecar_digest and validated before activation.
| Offset | Field | Scalar type | Unit | Invariant and check |
|---|---|---|---|---|
0x00–0x4F |
proposal header | as above | as above | Table 7, with payload_kind = TRAJECTORY. |
0x50 |
sample_period_ns |
uint32_t |
ns | Setpoint cadence \(\Delta t_{\text{step}}\); must match the configured decoder. |
0x54 |
num_samples |
uint16_t |
count | Nominal setpoints in the digested sample payload; bounds its size. |
0x56 |
num_joints |
uint8_t |
count | Commanded joints \(N_j\); must equal the configured count. |
0x57 |
payload_version |
uint8_t |
enumeration | Decoder version; an unknown version is rejected. |
0x58 |
t_start_ns |
uint64_t |
ns, permission clock | First nominal sample. |
0x60 |
t_commit_ns |
uint64_t |
ns, permission clock | Latest entry into the matched stop suffix; \(t_{\text{commit}}=t_{\text{stop\_end}}-T_{\text{stop}}\). |
0x68 |
t_plan_exp_ns |
uint64_t |
ns, permission clock | End of the nominal setpoints. |
0x70 |
t_stop_end_ns |
uint64_t |
ns, permission clock | Protected stop completion; \(t_{\text{start}}\le t_{\text{commit}}<t_{\text{plan\_exp}}<t_{\text{stop\_end}}\). |
0x78 |
sidecar_digest |
uint8_t[32] |
SHA-256 | Digest over the setpoint samples and the assumptions sidecar; binds content. |
0x98 |
seam_state |
float32[3][N_j] |
rad; rad/s; rad/s² | Entry state \((q,\dot q,\ddot q)\) of each joint. |
0x98 + \(12N_j\) |
stop_suffix |
float32[6][N_j] |
quintic coefficients | One quintic stop per joint; must be resident and feasible from every state reachable before \(t_{\text{commit}}\). |
0x98 + \(36N_j\) |
crc32 |
uint32_t |
checksum | IEEE 802.3 CRC-32 over all preceding bytes. |
Enforcement record
The enforcement record of The Enforcement Record is configuration, not a proposal, so it carries no proposal header (table 10). Three digests name what the record rests on: the evaluation record, the limit records behind the stopping envelope, and the validity region. Each threshold names the fallback-ladder rung that a failed check selects. Where the rung depends on whether the body is moving, the row names both, STOP in motion and HOLD at standstill. A proposal refused while the active lease holds selects no rung, because the setpoints already admitted stay in force until that lease lapses.
| Offset | Field | Scalar type | Unit | Check, and the rung a failure selects |
|---|---|---|---|---|
0x00 |
evaluation_record_digest |
uint8_t[32] |
SHA-256 | Evaluation record whose runtime monitor specifications become this record’s monitor channels. |
0x20 |
limit_record_digest |
uint8_t[32] |
SHA-256 | Canonical list of the limit records whose braking, onset, and actuator limits parameterize \(d_{\text{stop}}(v)\). |
0x40 |
validity_region_digest |
uint8_t[32] |
SHA-256 | validity_region, the plant-parameter bounds the thresholds rest on. On the mobile manipulator it covers the arm at the door, where it equals the target ODD, and at the packing station through the mug pick and the handover approach. Each base configuration, normal or restricted, loads as its own enforcement record, so this field holds the region digest of that configuration and its friction premise. A live state outside it that the machine observes selects STOP. |
0x60 |
loop_period_ns |
uint32_t |
ns | Permission-loop period \(T_{\text{loop}}\); the placement record’s nominal_period_ns must equal it. |
0x64 |
deadline_ns |
uint32_t |
ns | Permission-path deadline inside the tick; a cycle at risk of overrunning it selects HOLD. |
0x68 |
evidence_age_ceiling_ns |
uint32_t |
ns | Refusal threshold of the evidence-epoch check, the budgeted observation age plus the clock-conversion bound. A proposal whose upper evidence age exceeds it is refused, and the permission path shortens t_expire_ns to at most t_evidence_ns plus the ceiling minus sync_error_ns. A proposal whose sequence_id is not newer is refused; an expired lease selects STOP in motion and HOLD at standstill. |
0x6C |
watchdog_timeout_ns |
uint32_t |
ns | The self-watchdog is fed only after a completed tick; expiry requests INHIBIT through the independently wired trip. |
0x70 |
t_stop_ns |
uint32_t |
ns | Stopping-time bound from the maximum admitted speed; a reference that leaves less clearance than \(\epsilon_{\text{track}} + v_{\max} t_{\text{stop}}\) selects STOP. |
0x74 |
pos_tracking_bound |
float32 |
m | \(\lvert x_{\text{meas}} - r_{\text{cmd}} \rvert \le \epsilon_{\text{track}}\); STOP above it. |
0x78 |
pos_critical_bound |
float32 |
m | \(\lvert x_{\text{meas}} - r_{\text{cmd}} \rvert \le \epsilon_{\text{crit}}\), with \(\epsilon_{\text{crit}} > \epsilon_{\text{track}}\); STOP above it. |
0x7C |
vel_ceiling_limit |
float32 |
rad/s | \(\lvert \dot{q} \rvert \le \dot{q}_{\max}\); PROJECT (QP clamp). |
0x80 |
torque_slew_ceiling |
float32 |
N·m/s | \(\lvert \dot{\tau} \rvert \le \dot{\tau}_{\max}\); PROJECT (slew limiter). |
0x84 |
actuator_curr_limit |
float32 |
A | \(\lvert I_{\text{phase}} \rvert \le I_{\text{peak}}\); STOP. |
0x88 |
dc_bus_overvolt_thresh |
float32 |
V | \(V_{\text{bus}} \le V_{\text{max\_safe}}\); STOP, with the brake chopper absorbing returned energy. |
0x8C |
num_barriers |
uint16_t |
count | Barrier constraints \(K_b\); must equal the configured count. |
0x8E |
num_approach_channels |
uint16_t |
count | Approach channels \(K_a\); must equal the configured count. |
0x90 |
cbf_barrier_params |
float32[K_b][2] |
normalized distance; \(\text{s}^{-1}\) | Margin \(\delta_k\) and class-\(\mathcal{K}\) rate \(\alpha_k\) of each barrier; \(h_k(\mathbf{x}) \ge \delta_k\), else PROJECT, or STOP when no feasible input remains. |
0x90 + \(8K_b\) |
approach_channel_ids |
uint32_t[K_a] |
enumeration | Zone and activation condition of each channel, drawn from the validity region, such as the tool point inside the door zone or accept_item held. |
0x90 + \(8K_b+4K_a\) |
approach_ceilings |
float32[K_a] |
m/s | Ceiling on tool-point approach speed while its channel is active; a faster proposal takes PROJECT (QP clamp), and the channel that bound it is logged. |
0x90 + \(8K_b+8K_a\) |
crc32 |
uint32_t |
checksum | IEEE 802.3 CRC-32 over all preceding bytes; a mismatch rejects the stored record, and no motion is admitted until a valid copy loads. |
Placement record
The placement record of Hardware Allocation is offline evidence with a fixed header and a linked test ledger (table 11). It carries no signature of its own; the signed release manifest binds it through placement_record_digest. enforcement_record_digest names the enforcement record whose deadline_ns was tested, and test_ledger_digest identifies the external ledger that states the declared worst-case execution time the loaded test must not exceed, together with distributions, sample counts, test conditions, mitigations, and untested states. A maximum that has not been measured is stored as all ones, never zero, the same unavailable-value convention the fault record uses.
| Offset | Field | Scalar type | Unit | Invariant and check |
|---|---|---|---|---|
0x00 |
execution_domain_id |
uint64_t |
enumeration | Must match the declared topology (application processor, NPU, GPU, MCU, lockstep controller). |
0x08 |
privilege_and_ring |
uint64_t |
privilege level | Proposer at EL0; enforcer at EL1 or above, or in the secure world. |
0x10 |
nominal_period_ns |
uint32_t |
ns | Enforcer tick; equal to the enforcement record’s loop_period_ns. |
0x14 |
hard_deadline_ns |
uint32_t |
ns | The permission path’s deadline inside the tick; equal to the enforcement record’s deadline_ns. |
0x18 |
unloaded_observed_max_ns |
uint64_t |
ns | Largest response observed without competing load; a sample maximum, not a WCET. |
0x20 |
loaded_observed_max_ns |
uint64_t |
ns | Largest response under the declared load; all ones until a loaded test runs. Independence stands only while it is at most the declared WCET. |
0x28 |
shared_axi_channel_qos |
uint64_t |
configured QoS | Arbitration priority per claimant; controller semantics verified by register capture and a stress test. |
0x30 |
max_pdn_droop_thermal_trip |
uint32_t[2] |
mV; m°C | Configured rail-droop and thermal trip thresholds; the ledger records the tests behind them. |
0x38 |
hardware_mitigation_flags |
uint8_t[32] |
bitfield | Active mitigations, such as a TCM snapshot, memory partitioning, or an isolated rail; register-locked after boot. |
0x58 |
enforcement_record_digest |
uint8_t[32] |
SHA-256 | Enforcement record whose loop_period_ns and deadline_ns this record tests. |
0x78 |
test_ledger_digest |
uint8_t[32] |
SHA-256 | External test ledger, including the model and firmware digests under test. |
Fault record
The fault record of The Fault Manifest is offline evidence, a fixed header signed with Ed25519 that links to the retained evidence bundle by digest (table 14). The fault-ledger root that the release manifest binds is computed over the canonical encodings of these headers. envelope_point has a per-machine definition in the versioned fault-class manifest; for the mobile manipulator its four values are aisle speed (m/s), payload (kg), floor friction coefficient, and ambient temperature (K).
| Offset | Field | Scalar type | Unit | Purpose and interpretation |
|---|---|---|---|---|
0x00 |
trial_id |
uint64_t |
— | Unique trial identifier in the versioned ledger. |
0x08 |
claim_ref_id |
uint32_t |
index | Precommitted physical claim and its units. |
0x0C |
envelope_point |
float32[4] |
per manifest | Declared operating point of the trial. |
0x1C |
fault_injection_mode |
uint16_t |
enumeration | Injected fault class. |
0x1E |
injection_target_node |
uint16_t |
enumeration | Hardware boundary receiving the injection. |
0x20 |
fault_magnitude |
float32 |
per fault class | Injection amplitude; its unit is fixed by the fault-class manifest. |
0x24 |
t_det_ns |
uint32_t |
ns | Fault trigger to detector assertion. |
0x28 |
t_takeover_ns |
uint32_t |
ns | Fault trigger to measured takeover; subtract t_det_ns for the post-detection interval. |
0x2C |
stl_robustness_rho |
float32 |
claim’s unit | Raw signed margin for claim_ref_id; other predicate margins remain in the bundle. |
0x30 |
verdict_status |
uint8_t |
enumeration | PASS, FAIL, INVALID, or UNOBSERVABLE. |
0x31 |
reserved | uint8_t[3] |
— | Zero. |
0x34 |
oracle_digest |
uint8_t[32] |
SHA-256 | Immutable predicate and oracle configuration. |
0x54 |
evidence_digest |
uint8_t[32] |
SHA-256 | Separately retained trial evidence bundle. |
0x74 |
signature |
uint8_t[64] |
Ed25519 | Signature over all preceding bytes; the key identifier is in the versioned manifest. |
For a trial aborted before injection, detector time, takeover time, and robustness margin are unavailable rather than zero. The layout stores all ones (0xFFFFFFFF) in an unavailable uint32_t time slot and a canonical quiet NaN in an unavailable float32 margin slot, and the signed evidence bundle records a validity flag for each measured field and why it is absent. The oracle checks those flags and the verdict before doing arithmetic, and excludes unavailable slots from pass counts and from latency or margin statistics. The versioned manifest fixes the NaN bit pattern so that hashing remains reproducible.
Fault-injection protocol
Used in Fault Injection on Hardware. The protocol runs one hardware-in-the-loop trial on target silicon, from the precondition audit to the signed header of table 14, and every exit it takes sets one value of that header’s verdict_status.
Substrate and invariants.
- Execution substrate: Hard real-time field-programmable gate array (FPGA) plant rig and testbed orchestrator (\(f = 1\text{ kHz}\), hardware timestamping jitter \(< 500\text{ ns}\)).
- Memory invariant: Pre-allocated static DMA buffers in the host test orchestrator; zero runtime dynamic heap allocation on the safety microcontroller.
- Safety interlock authority: Independent optical or laser truth sensors wired to hardware crowbar relays capable of cutting target actuator power within \(2.0\text{ ms}\) of a physical envelope breach.
Execution protocol.
Precondition audit (stage 1). Sample baseline environmental sensors via \(\mathcal{I}_{\text{truth}}\) (temperature, rail voltage, and wheel speed). Compare each measurement with its declared same-unit tolerance; do not take one norm across kelvin, volts, and meters per second. If any precondition fails, log
ERR_PRECONDITION_OUT_OF_SPEC, set the verdict toINVALID, and abort.Synchronization and steady-state arming (stage 2). Arm the FPGA plant simulator, power up the target two-processor system, and start the periodic control loop (\(1\text{ kHz}\)). Establish a synchronized reference clock across the logic analyzer, FPGA plant, and truth digitizers via a \(10\text{ MHz}\) PXI clock. Allow the physical plant state \(\mathbf{x}(t)\) to stabilize in the nominal operating envelope for \(t_{\text{settle}} = 2.000\text{ s}\). If baseline tracking error \(\|e_{\text{track}}\| > \epsilon_{\text{nom}}\), assert
ERR_BENCH_INSTABILITY, set the verdict toINVALID, and abort.Fault injection trigger (stage 3). At monotonic test epoch \(t_{\text{inject}}\), the hardware test orchestrator asserts the trigger line to the inline injection rig:
- Proposer stall (F1): The orchestrator kills the chunk-policy task one tick after a lease renewal.
- Sensor latency or bias (F2): An FPGA interceptor latches a navigation-camera frame or holds a stale encoder payload while preserving its valid hardware timestamp.
- Frame loss (F3): A fieldbus disturbance node drops or corrupts EtherCAT frames at a drive’s slave port.
- Control-rail droop (F4a): A programmable electronic load draws the F4a transient of Representative hardware and cyber-physical fault classes from the shared control rail at its battery-low point for \(\Delta t_{\text{duration}} = 5.0\text{ ms}\), while an independent digitizer records the permission rail and the permission path’s heartbeat.
- Permission-rail feed loss (F4b): A solid-state switch opens the permission rail’s feed as the resident stop from the inspected-floor ceiling begins.
- Actuator mechanical stall: A four-quadrant dynamometer applies step counter-torque \(\tau_{\text{stall}} = 3.5 \times \tau_{\text{rated}}\).
Record the injection timestamp \(t_{\text{fault\_start}} \leftarrow t_{\text{now}}\) in nanoseconds on the reference clock.
Enforcer response and takeover audit (stage 4). Monitor the target MCU’s safety enforcer pins, CAN bus telemetry, and gate-driver PWM lines via an isolated logic analyzer:
- Detect assertion of the non-maskable interrupt (NMI) or diagnostic flag: \(t_{\text{det}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{det}} = t_{\text{det}} - t_{\text{fault\_start}}\).
- Detect hardware multiplexer preemption of the motor driver: \(t_{\text{takeover}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{takeover}} = t_{\text{takeover}} - t_{\text{fault\_start}}\).
- Detect the physical plant’s transition to its safe bounded regime: \(t_{\text{bounded}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{bounded}} = t_{\text{bounded}} - t_{\text{fault\_start}}\).
If the external containment rig trips on a structural envelope breach, the hardware crowbar cuts actuator power; assert
ERR_PHYSICAL_BREACHand carry the trial to stage 5, where the violated containment predicate returnsFAIL.Robustness evaluation and ledger serialization (stage 5). Ingest the truth trajectory \(\mathbf{x}_{\text{obs}}(t)\) from independent instrumentation over the declared trial window. If required truth frames are missing, set the verdict to
UNOBSERVABLEand retain the partial trace. For an observable trial, compute each precommitted predicate’s signed margin in its own unit, as the STL robustness of Signal Temporal Logic and Continuous Robustness defines it. ReturnPASSonly when every required margin is nonnegative and both measured fault-to-detection and fault-to-drive-takeover times satisfy their declared bounds; otherwise returnFAIL. A dimensionless aggregate may be computed only after predeclared per-predicate normalization. Link the fixed fault-record header to the variable-length evidence bundle by digest, sign the header under the specified custody scheme, and retain both.
Release manifest
The release manifest of The Release Manifest is a signed offline artifact, not a mailbox record, so it has a canonical encoding in place of fixed offsets. Fields appear in the order that table 15 lists, each variable-length field carries a length prefix, and the adjudicator’s Ed25519 signature covers the encoding of every preceding field. Every digest is SHA-256. The expiry is the one calendar time in the record chain, and it is checked against a tamper-resistant real-time clock rather than the safety microcontroller’s monotonic clock.
| Field | Encoding | Binds | Check before permission |
|---|---|---|---|
claim_manifest_id |
uint8_t[16] UUID |
Top-level safety claim | Linked to the root node of the signed argument graph. |
argument_digest |
uint8_t[32] |
Complete claim–argument–evidence graph | Matches the graph the adjudicator reviewed. |
policy_weights_digest |
uint8_t[32] |
Learned model weights | Mismatch refuses release. |
enforcer_bitstream_digest |
uint8_t[32] |
Enforcer logic image | Mismatch refuses release. |
rtos_kernel_digest |
uint8_t[32] |
Real-time kernel image and drivers | Verified by the hardware root of trust at power-on. |
calib_trace_pointers |
length-prefixed list of signed evidence references | Calibration certificates | Missing or stale evidence refuses unless a separately signed restricted case covers it. |
fault_ledger_root |
uint8_t[32] |
Signed fault-record headers (section 14.8) | Missing, unauthenticated, or mismatched ledger refuses. |
authority_record_digest |
uint8_t[32] |
Static authority manifest and the forensic log’s initial chain anchor (section 14.6) | Mismatch refuses release. |
placement_record_digest |
uint8_t[32] |
Placement record (section 14.5) | Mismatch refuses release. |
evaluation_record_digest |
uint8_t[32] |
Evaluation record | Mismatch refuses release. |
verdict_classification |
uint8_t enumeration |
UNCOND, COND, or REFUSE |
Selects the permitted operating envelope. |
standing_conditions |
length-prefixed array of (premise, check rate, trip) | Physical premises checked in operation | Checked on every permission tick; an unknown premise takes the assessed stop. |
telemetry_drift_budget |
length-prefixed task-specific limits and triggers | Tracking and timing drift | A bound violation revokes; a trend prompts inspection. |
verdict_expiry |
UTC calendar time (ISO 8601) | Validity period of the verdict | A real-time clock reading past the expiry voids the permit. |
lifecycle_budget |
uint64_t[2] (hours, cycles) |
Wear allowance | An exceeded budget or an invalid counter refuses motion. |
adjudicator_signature |
key identifier plus uint8_t[64] Ed25519 signature |
The whole manifest | Verifies under an authorized, unrevoked adjudicator key. |
Release-gate protocol
Used in The Release Manifest. Before the motor power stages are energized, the release gate attests the silicon state, verifies the manifest of table 15 and its image digests, and audits the standing conditions, in the order below.
Substrate and signature. The hardware root of trust anchors an authorized, revocable adjudicator verification-key chain. Protected storage holds the signed manifest and signed evidence graph. The signature covers every versioned manifest field, including the identity of the signing key, and the verifier checks the key chain and its revocation state before trusting the signature. The individually signed fault records of section 14.8 enter the manifest as one digest over the complete ledger in its declared order. The verifier checks each record signature, the ordering, completeness, and that root against the reviewed evidence index. A digest alone establishes neither record validity nor test adequacy.
Fail-closed authorization. Begin with Permit_gate = 0 and the physical plant in its assessed nonoperating state. All returned decisions use the signed enum UNCOND, COND, or REFUSE; an implementation may log a reason code separately.
- Verify the adjudicator key chain and revocation status, the manifest signature, expiry, signed operating-hour and cycle budgets, and every active image digest. Any invalid, missing, or expired item returns
REFUSE. A different software bank requires its own signed case and a new check of physical conditions. - Authenticate the complete fault ledger and calibration references against the signed graph. A missing ledger, bad record signature, or root mismatch returns
REFUSE, even if the manifest saysUNCOND. Stale calibration also returnsREFUSEunder the full case. It can supportCONDonly when a separately signed restricted case explicitly covers that calibration state and all of its evidence and limits still validate. - Check the state-dependent standing conditions, including brake test, separation, timebase, and monitoring health.
KNOWN_FALSEandUNKNOWNboth returnREFUSEwhile retaining distinct logged causes. Apply the approved state-matched stop or hold of The Fallback Ladder. - If every check passes and the signed verdict is
UNCOND, load the signed full envelope and returnUNCOND. If every restricted condition passes under a signedCONDcase, load its signed reduced envelope and returnCOND. A signedREFUSEcase or any other state returnsREFUSE. In both operating modes the learned policy only proposes actions; the independent enforcer checks each candidate and controls actuator permission. Force trip thresholds must include measured detection and response headroom below the contact criterion.
Residual-claims register
The residual-claims register of A Residual-Claims Register tracks every physical premise the release rests on but does not observe, so that an open claim is carried across software deployments and hardware revisions. Like the release manifest, it is an offline artifact whose mandatory fields (table 16) follow a canonical order rather than fixed offsets.
| Manifest Category | Field | Physical Unit | Invariant & Operational Contract |
|---|---|---|---|
| Manifest Header | system_identifier |
— | Unique embodied platform ID (e.g., WMM-AISLE-01) |
| Manifest Header | hardware_build_rev |
— | Target silicon and chassis revision (HW-REV-3.2) |
| Manifest Header | software_digest |
— | Digest of the released binary |
| Manifest Header | validity_limit_hours |
hours | Configured operating window before review |
| Residual Claims | entry_id |
— | Unique claim tag (e.g., CLAIM-FRIC-001) |
| Residual Claims | target_safety_claim |
— | Explicit safety invariant (\(d_{\text{stop}} \le D_{\text{clear}}\)) |
| Residual Claims | missing_observable |
SI units | Unmeasured physical state (e.g., surface friction \(\mu\)) |
| Physical Hazard | governing_law |
— | Newton-Euler, Navier-Stokes, Joule heating |
| Physical Hazard | time_to_harm |
seconds | Time from unmodeled transition to irreversible yield |
| Operational Containment | containment_type |
— | FIRMWARE_PARAM_CLAMP, PASSIVE_MECHANICAL, or OPERATING_RESTRICTION; validate the selected limit |
| Operational Containment | authority_limit |
\(\text{m/s}, \text{N}\) | Hard numeric setpoint ceiling (\(v_{\max}, F_{\max}\)) |
| Operational Containment | kinetic_energy_ceiling |
\(\text{J}\) | Maximum allowable kinetic energy under fault (\(E_k \le E_{\max}\)) |
| Assurance & Inspection | proof_test_interval |
hours | Scheduled test interval; evidence between tests still depends on the operating restriction |
| Predeclared Closure | closure_modality |
— | Transducer technology or formal method required |
| Predeclared Closure | sample_trials |
count | Case-specific independent exposure, sized by the zero-failure rule of Zero-Failure Testing and the Exposure Wall for the declared miss-rate bound |
| Predeclared Closure | confidence_level |
— | Declared one-sided confidence level of that bound |
Further Reading
For a deeper foundational understanding of embedded architectures, real-time operating systems, and power electronics, consult the following authoritative references:
- Computer Organization and Design: The Hardware/Software Interface (Hennessy and Patterson 2019) provides the definitive treatment of processor architectures, cache hierarchies, and memory subsystem trade-offs.
- Scheduling Algorithms for Multiprogramming in a Hard-Real-Time Environment (Liu and Layland 1973) establishes the mathematical foundations of rate-monotonic scheduling and real-time task schedulability.
- Modern Operating Systems by Andrew S. Tanenbaum and Herbert Bos provides comprehensive coverage of inter-process communication, lock-free synchronization, and memory management.
- Real-Time Systems by Jane W. S. Liu delivers the authoritative mathematical formulation of real-time scheduling algorithms, priority inversion, and response time analysis.
Footnotes
Jeff Dean: Google Senior Fellow and systems architect. His latency numbers originally presented with Peter Norvig around 2010 established the canonical latency hierarchy across storage, memory, and network tiers (Scott 2012). Physical AI extends this hierarchy down into electromechanical actuators, stopping kinematics, and thermal time constants.↩︎
Hardware Watchdog Down-Counters: A configured watchdog expires when its expected service does not occur. Its oscillator, timeout, output wiring, and plant response differ by device. Feeding it merely from an unrelated interrupt does not prove that the monitored control computation progressed; a firmware-fed reset also need not signal a drive. See the Linux watchdog API for reset behavior and The Fallback Ladder for stop selection.↩︎
Inverter Dead-Time Insertion: Timer dead time is selected from switch and driver timing over temperature and load, then verified with the actual gate waveforms. An overlap can create a damaging bus short; a numeric current or fuse outcome requires the circuit impedance and protection response.↩︎
Sakurai-Newton Delay Modeling: The alpha-power law models voltage-dependent gate delay; its parameters are technology dependent. The model predicts reduced setup slack during droop, while a missed deadline, register error, or reset must be established against measured path slack and device thresholds.↩︎
DRAM Bank-Conflict Penalties: A row change in one bank can add precharge and activate time. Video DMA can also queue transactions ahead of a safety read. The resulting delay must be bounded for the specific address mapping, arbitration policy, and workload; a fixed penalty per request is generally unjustified.↩︎
Hardware Timestamping: A compatible PHY or MAC timestamps frames closer to the wire than a software interrupt handler. Hardware timestamping removes one source of dispatch variation, while path asymmetry and clock conversion remain. Timestamp uncertainty belongs in the physical belief record and permission budget.↩︎
Hardware Memory Barriers: Barriers order accesses only within their specified shareability and memory-attribute contract. On a noncoherent route, cache clean/invalidate operations or coherent mappings are also required. Arm’s memory-ordering guide distinguishes ordering from coherence.↩︎
Stator Thermal Time Constants: Resistive Joule heating elevates motor phase winding temperatures during continuous high-torque maneuvers. Because copper electrical resistivity increases linearly with temperature, hot windings exhibit higher resistance, reducing torque output under terminal voltage saturation. Exceeding winding insulation temperature limits breaks down dielectric coatings, causing inter-turn short circuits and irreversible actuator destruction.↩︎
Dynamic Braking Choppers: A qualified chopper can dissipate returned energy when the battery is unavailable as a sink. Its threshold, switch and resistor ratings, pulse duration, and thermal recovery must be tested. Regeneration and chopper operation are not inherent to every emergency stop; safe torque off can instead leave a motor coasting.↩︎
Pinhole Intrinsic Projection: The pinhole model projects 3D points onto a 2D sensor through calibrated intrinsics. Under fixed pixel noise, the lateral variance after depth unprojection grows with squared distance; depth-error and calibration terms follow their own models. Uncalibrated intrinsics can bias a clearance estimate and must be included in its error envelope.↩︎