Systems and Hardware

This appendix collects the embedded timing, memory, power, and actuator models used throughout this book, together with the byte layouts of records that cross the proposal boundary. Each bound depends on a specified device, workload, and operating envelope; the equations identify what must be measured before a physical deadline can be claimed.

How to Use This Appendix

Consult this appendix when diagnosing physical systems bottlenecks, timing jitter, electrical rail instability, or hardware interface boundaries across chapters in this book:

When you encounter this systems symptom Consult For this quantitative tool
A real-time safety task misses periodic execution deadlines section 3 Worst-case execution time (WCET) and Response Time Analysis (RTA)
A software deadlock or kernel panic freezes actuator control loops section 3 Watchdog detection and separately measured stop-path response
Inverter bridge MOSFETs burn out or trip overcurrent protections section 4 Microcontroller PWM complementary timers and dead-time insertion
Heavy neural inference bursts induce compute brownout resets section 5 Inductive voltage droop (\(L dI/dt\)) and alpha-power gate delay
High-rate sensor DMA streams cause safety threads to miss deadlines section 6 DRAM bank-conflict penalties and non-preemptive burst queuing
Sensor fusion streams suffer temporal registration skew under motion section 7 PTP hardware timestamping and bounded clock conversion
Shared memory queues between Linux and the safety microcontroller (MCU) return torn or stale data section 8 SoC hardware mailboxes, RPMSG, and hardware memory barriers
Joint actuators fail to track sudden torque reversals, chatter, or overheat section 9 Stator \(L/R\) constants, thermal ODEs, and reflected rotor jerk limits
Emergency braking spikes DC bus voltage and damages power silicon section 10 Regenerative capacitive energy surges and dynamic brake choppers
Shared serial buses experience queuing and message jitter section 11 CAN FD priority blocking, EtherCAT cycle budgets, and bounded seqlocks
Monocular 3D bounding boxes distort and depth covariance diverges section 12 Pinhole intrinsic projection, Zhang’s calibration, and metric unprojection covariance
A mobile base breaches clearance buffers under surface wetness section 13 Kinematic stopping envelopes, information age lag, and velocity clamps
A record must be laid out for a fixed-size mailbox or log section 14 Proposal and record byte layouts; manifest and register field orders
A handover, fault trial, or release gate must be implemented step by step section 14 Authority-transfer, fault-injection, and release-gate protocols beside their records
You need rapid order-of-magnitude physical anchors across time, kinetics, thermal, and risk section 2 Rate hierarchy, blind travel conversions, thermal constants, and exposure walls

Numbers to Know in Physical AI

Just as Jeff Dean’s “Latency Numbers Every Programmer Should Know”1 shaped distributed systems and classical machine learning systems grounded software performance in memory bandwidth and arithmetic intensity, physical AI systems engineers require a corresponding quantitative intuition spanning computation, kinetics, thermal dissipation, and functional safety. In physical AI, software latency is not merely waiting time; it translates directly into irreversible kinetic momentum, uninspected travel distance, and thermodynamic heat accumulation in motor stators and compute silicon.

This section compiles the foundational order-of-magnitude numbers, scaling laws, and engineering rules of thumb that govern cyber-physical machine design. All numbers are single-sourced from mlsysim. Memorize the relationships; use the specific numbers as sanity checks.

Systems Perspective 0.1: Three physical numbers that matter most
  • Kinetic equivalence: \(1\text{ ms} = 1\text{ mm}\) (at \(1\text{ m/s}\)): At a nominal robotic speed of \(1\text{ m/s}\), every single millisecond of perception, inference, or fieldbus latency translates into exactly \(1\text{ mm}\) of blind travel before retarding torque can be applied. At highway velocity (\(30\text{ m/s}\)), each millisecond is \(3\text{ cm}\). In physical systems, software latency is not waiting time; it is physical displacement.
  • Thermal divergence: \(\tau_{\text{silicon}} \sim 1\text{ ms}\) vs. \(\tau_{\text{stator}} \sim 100\text{ s}\): Semiconductor junctions heat adiabatically within milliseconds during deep neural network bursts, precipitating voltage droop or thermal throttling before heat spreaders react. In contrast, electromagnetic stator windings heat over tens to hundreds of seconds, tolerating transient overcurrent for aggressive maneuvers but accumulating thermal energy that eventually limits sustained torque.
  • The exposure wall: \(N = 3 / \lambda\): Proving an ultra-low catastrophic failure rate of \(10^{-8}/\text{hour}\) (ISO 26262 ASIL D) requires \(3 \times 10^8\) failure-free operational hours under the Poisson Rule of Three (Hanley and Lippman-Hand 1983). Statistical empirical testing of learned end-to-end models cannot cross this exposure wall without deterministic runtime permission envelopes and formal safety filters.

Rate and latency hierarchy across machine levels

Control rates in physical AI rise steeply from the deliberative brain down to the physical body (table 1). Deliberative multimodal models (VLAs) operate at human reaction scales (\(1\text{--}5\text{ Hz}\)). Action chunking models emit future trajectory waypoints at \(10\text{--}50\text{ Hz}\). Beneath the proposal boundary, the permission path enforces safety barriers at \(1\text{ kHz}\). At the lowest levels, power electronic current loops and PWM switching operate at tens to hundreds of kilohertz to maintain electromagnetic flux and drive torque. For real-time timer schedulability and response-time analysis, see section 3; for inverter gate switching and dead-time modeling, see section 4.

Table 1: Rate and Latency Hierarchy Across the Five Machine Levels: Spanning five frequency decades from sub-microsecond MOSFET gate switching up to second-scale foundation model deliberation. Every frequency band imposes a hard cycle period and an uninspected physical travel distance at nominal speed (\(1\text{ m/s}\)).
Machine Level Frequency Band Cycle Period Blind Travel at 1 m/s Architectural Mechanism & Bound
Brain (Deliberation) 1–5 Hz 200–1,000 ms 200–1,000 mm Multimodal VLA reasoning; memory- and compute-bound
Brain (Action Chunking) 10–50 Hz 20–100 ms 20–100 mm Action chunk diffusion/transformer decoding; amortized
Nervous System (Permission) 1 kHz 1 ms 1 mm Control barrier certificates, stopping envelopes, lease watchdog
Body (Current Loop) 10–25 kHz 40–100 µs 40–100 µm Field-oriented current control (FOC), torque tracking, stator flux
Body (Inverter Switching) 50–200 kHz 5–20 µs 5–20 µm Power MOSFET gate drive, dead-time insertion (\(t_{\text{dead}}\)), inductive droop

Kinetic translation and safe stopping envelopes

Total stopping distance \(d_{\text{stop}} = v \cdot \tau_{\text{delay}} + v^2 / (2 a_{\text{brake}})\) combines the linear blind travel accrued during computational delay and the quadratic mechanical braking distance (table 2). As platform speed increases, absolute blind travel expands rapidly, consuming entire clearance margins before deceleration can begin. For multi-axis kinematic chains, jerk-bounded trajectories, and information-age lag derivations, see section 13.

Table 2: Kinetic Translation Across Platform Archetypes: Pre-brake delay converts into unrecoverable physical travel before braking force begins. Stopping distance \(d_{\text{stop}} = v \cdot \tau_{\text{delay}} + v^2 / (2 a_{\text{brake}})\) combines linear blind travel and quadratic braking distance.
Platform Archetype Nominal Velocity \(v\) Braking Decel \(a\) Blind Travel (\(\tau=50\text{ ms}\)) Blind Travel (\(\tau=200\text{ ms}\)) Total Stop (\(\tau=200\text{ ms}\))
Humanoid / Quadruped 1 m/s (3.6 km/h) 4 m/s² (0.41 g) 50 mm 200 mm 325 mm (61.5%)
Warehouse Mobile Manipulator 1.5 m/s (5.4 km/h) 2 m/s² (0.20 g) 75 mm 300 mm 863 mm (34.8%)
Urban Delivery Robot 6 m/s (21.6 km/h) 4.5 m/s² (0.46 g) 300 mm 1.2 m 5.2 m (23.1%)
Autonomous Vehicle (Highway) 30 m/s (108 km/h) 7 m/s² (0.71 g) 1.5 m 6 m 70.3 m (8.5%)

Edge memory bandwidth and action chunk amortization

Large multimodal foundation models on edge system-on-chip (SoC) architectures are memory-bandwidth bound during autoregressive generation (table 3). Streaming a 7-billion-parameter model over a sustained \(140\text{ GB/s}\) LPDDR5 interface limits single-step generation to \(10\text{--}20\text{ Hz}\). Predicting action chunks of length \(H=16\) amortizes the weight streaming transfer over multiple future control steps, lifting effective control bandwidth into the hundreds of hertz. For DRAM bank organization, conflict penalties, and interconnect arbitration under concurrent DMA traffic, see section 6.

Table 3: Edge Memory Bandwidth and Action Chunk Amortization: Autoregressive token decoding on edge accelerators (such as Jetson AGX Orin at \(140\text{ GB/s}\) sustained DRAM bandwidth) is memory-bandwidth bound. Predicting action chunks (\(H\) steps) amortizes the weight transfer over multiple execution cycles, enabling high effective control frequencies.
Model & Precision Parameters Memory Footprint DRAM Read Time (\(140\text{ GB/s}\)) Single-Step Max Rate Chunk Rate (\(H=16\))
VLA-7B (FP16) 7.0B 14 GB 100 ms 10 Hz 160 Hz equivalent
VLA-7B (INT8) 7.0B 7 GB 50 ms 20 Hz 320 Hz equivalent
VLA-7B (INT4) 7.0B 3.5 GB 25 ms 40 Hz 640 Hz equivalent
VLA-14B (INT8) 14.0B 14 GB 100 ms 10 Hz 160 Hz equivalent

Thermal time constants across compute and electromechanics

Thermal dissipation follows an exponential relaxation \(T(t) = T_{\text{amb}} + \Delta T_{\max} (1 - e^{-t/\tau_{\text{th}}})\) with time constants spanning five orders of magnitude (table 4). Silicon junctions overheat within milliseconds during computational bursts, demanding microsecond-scale DVFS and PDN droop management. In contrast, electromagnetic stator windings heat over minutes, allowing transient torque overdrive if bounded by an \(I^2 t\) thermal watchdog. For first-order thermal differential equations and stator winding degradation limits, see section 9; for regenerative energy absorption on DC power buses, see section 10.

Table 4: Thermal Time Constants Across Compute and Electromechanical Subsystems: Thermal inertia spans five orders of magnitude. Adiabatic heating in semiconductor junctions causes rapid thermal throttling within milliseconds, while copper motor windings integrate electrical energy over tens to hundreds of seconds.
Subsystem Component Physical Mechanism Thermal Time Constant \(\tau_{\text{th}}\) Critical Failure Mode Safety Mitigation
Silicon Junction (Die) Transistor channel self-heating 1–10 ms Gate delay stretch, brownout, thermal trip Rapid frequency throttling, PDN decoupling
SoC Heat Sink / Package Convective heat spreader dissipation 10–60 s Package thermal saturation, sustained throttling Active fan modulation, workload migration
Motor Stator Windings Copper resistive Joule heating (\(I^2 R\)) 30–180 s Insulation breakdown (Class H \(180^\circ\text{C}\)), short \(I^2 t\) thermal protection, current derating
Motor Frame / Housing Bulk metallic casing heat conduction 10–30 min Structural deformation, bearing grease loss Natural convection, passive cooling fins
Traction Battery Pack Electrochemical cell internal resistance 5–20 min Thermal runaway (\(> 60^\circ\text{C}\)), fire Liquid cooling loop, charge/discharge cutoff

Statistical safety bounds and exposure walls

Under the Poisson Rule of Three (Hanley and Lippman-Hand 1983), demonstrating that a physical system achieves a catastrophic failure rate target \(\lambda\) with \(95\text{ percent}\) confidence without observing a single failure requires testing for \(N = 3 / \lambda\) operational hours (table 5). Meeting the ultra-dependable thresholds demanded by automotive functional safety (ISO 26262 ASIL D, \(\lambda < 10^{-8}/\text{hour}\) (ISO 26262 2018)) requires 300 million failure-free hours—a scale that renders end-to-end black-box statistical validation mathematically impossible without deterministic runtime permission envelopes. For proposal and manifest wire formats supporting runtime safety contracts, see section 14.

Hanley, James A., and Abby Lippman-Hand. 1983. “If Nothing Goes Wrong, Is Everything All Right? Interpreting Zero Numerators.” JAMA 249 (13): 1743–45. https://doi.org/10.1001/jama.1983.03330370053031.
ISO 26262: Road Vehicles, Functional Safety. 2018. International Organization for Standardization.
Table 5: Functional Safety Standards and Statistical Testing Exposure Walls: Required failure-free operating hours to establish safety targets at \(95\text{ percent}\) confidence via the Rule of Three (\(N = 3 / \lambda\)). Purely statistical end-to-end testing cannot prove catastrophic safety without deterministic runtime guarantees.
Safety Standard / Regime Target Failure Rate \(\lambda\) Equivalent FIT (\(10^{-9}/\text{h}\)) Required 0-Failure Hours (\(N=3/\lambda\)) Engineering Implication
ISO 26262 ASIL D \(< 10^{-8}/\text{hour}\) \(< 10\text{ FIT}\) \(300,000,000\text{ hours}\) (\(3 \times 10^8\text{ h}\)) Empirically untestable by fleet testing alone; requires formal safety barriers
IEC 61508 SIL 3 / PL e \(< 10^{-7}/\text{hour}\) \(< 100\text{ FIT}\) \(30,000,000\text{ hours}\) (\(3 \times 10^7\text{ h}\)) Dual-channel lockstep hardware, diverse software monitoring
Commercial Robotaxi Target \(< 10^{-6}/\text{hour}\) \(< 1,000\text{ FIT}\) \(3,000,000\text{ hours}\) (\(3 \times 10^6\text{ h}\)) Human driver baseline equivalence (\(1\) fatality per \(10^8\text{ miles}\))
Industrial Cobot (PL d) \(< 10^{-6}/\text{hour}\) \(< 1,000\text{ FIT}\) \(3,000,000\text{ hours}\) (\(3 \times 10^6\text{ h}\)) Force and power limiting, speed-and-separation monitoring

Fieldbus latencies, jitter, and determinism

Communication buses exhibit sharp divides in latency and jitter (table 6). Industrial fieldbuses like EtherCAT achieve sub-microsecond jitter via dedicated hardware cut-through processing. In contrast, non-deterministic arbitration and shared wireless channels introduce tail latencies that exceed the reaction deadlines of high-speed electromechanical machines. For IEEE 1588 PTP hardware timestamping bounds, see section 7; for CAN-FD priority arbitration and EtherCAT cycle budgets, see section 11.

Table 6: Communication Bus Latencies, Jitter, and Real-Time Determinism: Comparison of onboard fieldbuses and wireless networks. Hard real-time control requires sub-microsecond jitter, while wireless telemetry exhibits multi-millisecond tail latency that precludes off-board closed-loop safety intervention.
Bus / Network Technology Nominal Transit Latency Worst-Case Jitter Determinism Mechanism Primary Machine Role
EtherCAT (ETG.1000) \(100\,\mu\text{s}\text{--}1\text{ ms}\) \(< 1\,\mu\text{s}\) Hardware cut-through on-the-fly frame processing Synchronous joint servo drive & sensor feedback (Body/Nervous)
CAN-FD (ISO 11898-1) \(100\text{--}500\,\mu\text{s}\) \(50\text{--}200\,\mu\text{s}\) Bitwise non-destructive priority arbitration Distributed sensors, legacy actuator controllers (Nervous/Body)
TSN Ethernet (802.1Qbv) \(10\text{--}100\,\mu\text{s}\) \(< 5\,\mu\text{s}\) Time-aware shaper with scheduled transmission gates High-bandwidth sensor ingress (lidar/cameras) to SoC (Boundary)
Standard IP / UDP Ethernet \(0.5\text{--}5\text{ ms}\) \(1\text{--}20\text{ ms}\) Best-effort CSMA/CD; FIFO queueing Asynchronous logging, inter-node telemetry (Brain)
Wi-Fi 6 / 5G URLLC \(5\text{--}20\text{ ms}\) \(10\text{--}500\text{ ms}\) (RF fade) Wireless packet retransmission, contention window High-level fleet dispatch, cloud mission updates (World/Governance)

Real-Time Timers, Watchdogs, and Schedulability

In embedded real-time systems, temporal predictability is as vital as computational correctness. A late control action is not merely degraded; on physical hardware, it is incorrect and potentially destructive.

Real-time task schedulability and response time analysis

A periodic real-time task \(\tau_i\) is characterized by its worst-case execution time (WCET) \(C_i\), relative deadline \(D_i\), and period \(T_i\). Under a single-core, fixed-priority preemptive model with bounded blocking and no release jitter (such as Rate-Monotonic Scheduling (Liu and Layland 1973)), schedulability is checked using the worst-case response time \(R_i\): \[ R_i = C_i + B_i + I_i \le D_i \] where \(B_i\) is the maximum blocking duration induced by lower-priority tasks accessing shared resources, and \(I_i\) is the interference from higher-priority tasks. The response time is computed via the fixed-point recurrence: \[ R_i^{(k+1)} = C_i + B_i + \sum_{j \in hp(i)} \left\lceil \frac{R_i^{(k)}}{T_j} \right\rceil C_j \] starting with \(R_i^{(0)} = C_i+B_i\) and iterating to a fixed point or until a deadline is exceeded. A finite fixed point with \(R_i \le D_i\) for every task establishes schedulability under these scheduling and interference assumptions. WCET \(C_i\) is one component of response time, not the end-to-end sensor-to-actuator latency.

Hardware watchdogs and fault response

To detect a missed execution checkpoint, an embedded design may use a hardware watchdog timer. Its clock and response path must be independent enough of the monitored task for the claimed fault set; an independent crystal is one implementation.

The timer is initialized to a threshold value \(W_{\text{init}}\). Software execution threads must periodically refresh (or “kick”) the register before the count reaches zero. If \(W(t)\) represents the register count at physical time \(t\), and software executes a refresh at epoch \(t_k\), the register resets:2 \[ W(t_k) = W_{\text{init}} \] If the software misses the configured refresh window, the timer expires and raises its configured interrupt, reset, or external supervisor output. Expiry only detects the missed checkpoint. The safety case must bound expiry-to-drive response, wire any MCU-loss trip independently of the failed MCU, and show that the resulting state-matched brake or hold can stop the plant within its remaining clearance. A reset or safe torque off (STO) command alone may leave a moving load coasting.

Inverter Timers and Power Electronics Gate Drive

Actuator motor drives employ three-phase half-bridge inverters to convert DC bus voltage into alternating stator currents.

Microcontroller timer dead-time insertion

Each inverter phase comprises a high-side power MOSFET (or IGBT) and a low-side power MOSFET connected across the DC supply rail \(V_{\text{bus}}\). Microcontroller timer peripherals generate complementary pulse-width-modulated (PWM) drive signals with hardware-enforced dead-time insertion \(t_{\text{dead}}\): \[ t_{\text{dead}} \ge t_{\text{off, max}} + t_{\text{prop, skew}} - t_{\text{on, min}} \] where \(t_{\text{off, max}}\) is the maximum turn-off time of the power switch, \(t_{\text{on, min}}\) is the minimum turn-on time, and \(t_{\text{prop, skew}}\) is the propagation delay mismatch across gate drivers.3

For the specified device and gate-drive delays, adequate dead time reduces overlap between high-side and low-side conduction. If both switches conduct simultaneously, shoot-through creates a low-impedance path across the DC bus; current and damage depend on bus impedance, protection, and event duration.

Inductive Voltage Droop and Gate Delay Stretch

When deep neural network accelerators (such as systolic array matrix engines) transition from idle to full execution, current draw increases by tens of amperes within nanoseconds.

Power delivery network impedance and rail droop

Every power delivery network (PDN) exhibits finite parasitic loop inductance \(L_{\text{PDN}}\) and equivalent series resistance \(R_{\text{PDN}}\) across PCB traces, package balls, and bond wires. When accelerator execution triggers a transient current step \(\Delta I\) with rise time \(t_r\) (giving current slew rate \(dI/dt \approx \Delta I / t_r\)), Faraday’s law of induction dictates an instantaneous voltage collapse \(\Delta V_{\text{droop}}\): \[ \Delta V_{\text{droop}} = L_{\text{PDN}} \frac{dI}{dt} + \Delta I \cdot R_{\text{PDN}} \] If supply voltage \(V(t) = V_{\text{nom}} - \Delta V_{\text{droop}}\) approaches a device’s characterized minimum operating voltage \(V_{\min}\), timing margin may shrink or brownout protection may act.

Digital logic gate delay and the alpha-power law

In sub-micron CMOS silicon, logic gate propagation delay \(t_{\text{prop}}\) is governed by the Sakurai-Newton alpha-power law:4 \[ t_{\text{prop}}(V) \propto \frac{C_L \cdot V}{(V - V_{\text{th}})^\alpha} \] where \(C_L\) is the gate load capacitance, \(V_{\text{th}}\) is the transistor threshold voltage, and \(\alpha \in [1.2, 1.5]\) is the velocity saturation index (contrasting with \(\alpha = 2.0\) in long-channel theory).

When rail voltage droops from \(V_{\text{nom}}\) to \(V_{\text{droop}}\), propagation delay stretches according to: \[ \frac{t_{\text{prop}}(V_{\text{droop}})}{t_{\text{prop}}(V_{\text{nom}})} = \frac{V_{\text{droop}}}{V_{\text{nom}}} \left( \frac{V_{\text{nom}} - V_{\text{th}}}{V_{\text{droop}} - V_{\text{th}}} \right)^\alpha \] In a synchronous digital pipeline with clock period \(T_{\text{clk}}\), setup time \(t_{\text{setup}}\), and clock skew \(t_{\text{skew}}\), timing closure requires: \[ t_{\text{prop}} + t_{\text{setup}} + t_{\text{skew}} \le T_{\text{clk}} \] Stretching \(t_{\text{prop}}\) reduces setup slack. A timing failure occurs only if the measured path crosses its slack limit; a brownout reset depends on a separately configured supervisor threshold. Local decoupling can reduce the rail excursion, subject to its impedance and placement.

DRAM Contention and Interconnect Arbitration

In shared-memory multi-core SoC platforms, direct memory access (DMA) transfers and vision prefetching compete with the permission path for memory controller command queues and physical DRAM banks.

DRAM bank organization and conflict latency

A DRAM chip is structured into multiple independent banks, each possessing a single row buffer. Accessing storage cells requires three sequential operations:

  1. Row activate (\(t_{\text{RCD}}\)): Loads a row of storage cells into the bank’s row buffer.
  2. Column access (\(t_{\text{CAS}}\)): Reads or writes data from the open row buffer onto the data bus.
  3. Row precharge (\(t_{\text{RP}}\)): Restores charge to storage capacitors and closes the active row.

When consecutive operations target different rows of the same bank (a bank conflict), the controller may need to precharge and activate a row before column access, adding approximately \(t_{\text{RP}}+t_{\text{RCD}}\). Each bank can have its own open row. The penalty and number of switches depend on address mapping and the controller schedule.5

Interconnect crossbars and burst contention

An accelerator tile is split into bounded bus transactions; it is not one atomic AXI burst. For an illustrative FIFO controller that admits all \(K\) transactions ahead of a safety request, with no priority bypass or new arrivals, the ideal bus-transfer component is \[ t_{\text{queue,ideal}}=\frac{\sum_{k=1}^{K}B_k}{\mathrm{BW}_{\text{bus}}}. \] Add the bank-switch penalties for the actual address sequence and then the safety request’s own transfer and compute times. This is a constructed scheduling model, not a portable worst-case bound: refresh, protocol overhead, controller reordering, and competing traffic can increase latency, while qualified QoS can bypass queued work. Contention for Shared Resources gives a recomputable case. A local, coherently published safety snapshot can avoid this DDR path, but TCM capacity alone does not provide the snapshot or bound its transfer time.

Clock Synchronization and Network Timestamps

Distributed perception must convert sensor timestamps into a common clock domain with a measured conversion-error bound.

Precision time protocol message exchange

The IEEE 1588 Precision Time Protocol (PTP) synchronizes a Slave clock (\(S\)) to a Master clock (\(M\)) by exchanging four physical timestamps across the communication link:

  1. \(t_1\): Master transmits a Sync frame, recording its local transmission timestamp.
  2. \(t_2\): Slave receives the Sync frame, recording its local arrival timestamp.
  3. \(t_3\): Slave transmits a Delay_Req frame, recording its local transmission timestamp.
  4. \(t_4\): Master receives the Delay_Req frame, recording its local arrival timestamp.

Assuming stable clocks during the exchange and symmetric forward and reverse propagation delay (\(D_{M \to S}=D_{S \to M}=D\)), the time relationships satisfy: \[ t_2 = t_1 + O + D \] \[ t_4 = t_3 - O + D \] where \(O\) is the slave-minus-master clock offset. Under those assumptions, the estimated offset is: \[ O = \frac{(t_2 - t_1) - (t_4 - t_3)}{2} \] The one-way network propagation delay is: \[ D = \frac{(t_2 - t_1) + (t_4 - t_3)}{2} \] The slave estimates the mapping to the master domain by subtracting \(O\). Asymmetric path delay, oscillator drift between exchanges, and timestamp error leave a residual that must be bounded for evidence-age checks.

Physical layer hardware timestamping

Software timestamping includes operating-system dispatch and queue variation, which must be measured for the selected network stack.

PTP-capable hardware can timestamp near the Ethernet PHY or media access control (MAC) boundary, reducing host-dispatch error.6 It does not by itself establish a submicrosecond end-to-end clock bound; topology, asymmetry, synchronization interval, timestamp location, and MCU clock conversion must be characterized.

Heterogeneous SoC Mailboxes and Memory Barriers

Some robotics SoCs couple an application processor running Linux with a real-time core or microcontroller. Their communication contract must specify memory ownership, cache behavior, message validity, and what the real-time side does when no new message arrives.

Remote processor messaging over shared SRAM

An illustrative shared-memory mailbox works as follows:

  1. Core A writes a message payload to a fixed buffer in shared SRAM.
  2. Core A makes the payload visible to Core B using the platform’s coherent mapping or explicit cache maintenance and ordering.
  3. Core A triggers an inter-processor interrupt (IPI) by writing to Core B’s hardware mailbox register.
  4. Core B checks publication order, integrity, age, and permission before using the payload.

Linux RPMsg is a virtio-based messaging framework that may use shared memory and a platform-specific kick. It does not prescribe this fixed-buffer protocol or a universal latency bound.

CPU pipeline reordering and memory fences

Weak memory ordering and noncoherent caches can let a receiver observe a notification without a current payload unless the producer and consumer follow one published protocol:

// Core A (Application Processor); q_target and q_cmd are joint_target_t structs
shared_buffer->q_target = q_cmd; // Store 1: Payload (struct copy)
mailbox_doorbell = 1;            // Store 2: Interrupt trigger

If the CPU or interconnect reorders Store 2 ahead of Store 1, Core B receives the interrupt before the new joint target is committed to physical memory, reading stale or invalid data.

A data memory barrier can order accesses within its selected shareability domain:7

shared_buffer->q_target = q_cmd; // Struct copy of the joint targets
__asm__ volatile("dmb ish" ::: "memory"); // Only if both peers share this domain
mailbox_doorbell = 1;

The barrier in this example is sufficient only if both cores share the inner-shareable coherent domain and the doorbell has the specified device-memory ordering. It does not flush a noncoherent cache or make data visible to an unrelated DMA master. Otherwise, use the platform’s appropriate barrier and DMA cache-ownership synchronization, or map the buffer coherently, and verify the receiver’s acquire side. The real-time reader still needs a bounded validation attempt and a lease-limited fallback when publication is torn or stale.

Actuator Electrical and Thermal Dynamics

Actuators convert electrical energy into mechanical work through electromagnetic lorentz forces, subject to coupled electrical and thermal constraints.

Stator electrical rise time

A brushless DC (BLDC) motor phase winding exhibits phase resistance \(R_{\text{phase}}\) and phase inductance \(L_{\text{phase}}\). Applying terminal voltage \(V_{\text{terminal}}\) against back-electromotive force \(e_{\text{bemf}} = K_e \omega_m\) yields the first-order stator current ODE: \[ L_{\text{phase}} \frac{dI(t)}{dt} + R_{\text{phase}} I(t) = V_{\text{terminal}} - K_e \omega_m \] For a voltage step applied from rest (\(\omega_m = 0\)), phase current rises exponentially: \[ I(t) = \frac{V_{\text{terminal}}}{R_{\text{phase}}} \left( 1 - e^{-t / \tau_e} \right), \quad \tau_e = \frac{L_{\text{phase}}}{R_{\text{phase}}} \] where \(\tau_e\) is the electrical time constant: in this ideal step model, current reaches about 63 percent of its final value after one \(\tau_e\). Torque \(\tau_m=K_t I\) follows this current only while the magnetic, voltage, and control assumptions hold; a command is not an instantaneous torque change.

Lumped thermal networks and duty cycle

Current flowing through stator windings dissipates resistive Joule heat: \[ P_{\text{loss}}(t) = I_{\text{rms}}^2(t) R_{\text{phase}}(T) \] where copper resistance increases linearly with temperature: \[ R_{\text{phase}}(T) = R_0 \left[ 1 + \alpha_{\text{Cu}} (T - T_0) \right] \] with temperature coefficient \(\alpha_{\text{Cu}} \approx 0.00393\text{ K}^{-1}\) for copper. In a single-node lumped thermal model with thermal resistance to ambient \(\theta_{JA}\) (in \(\text{K/W}\)) and thermal heat capacity \(C_{\text{th}}\) (in \(\text{J/K}\)), temperature rise \(\Delta T(t) = T_{\text{winding}}(t) - T_{\text{ambient}}\) satisfies:8 \[ C_{\text{th}} \frac{d\Delta T(t)}{dt} = P_{\text{loss}}(t) - \frac{\Delta T(t)}{\theta_{JA}} \] Under constant power, temperature rises with thermal time constant \(\tau_{\text{th}} = \theta_{JA} C_{\text{th}}\): \[ \Delta T(t) = P_{\text{loss}} \theta_{JA} \left( 1 - e^{-t / \tau_{\text{th}}} \right) \] Continuous torque capacity \(\tau_{\text{cont}}\) is bounded by maximum allowable winding temperature \(\Delta T_{\max}\): \[ \tau_{\text{cont}} \le K_t \sqrt{\frac{\Delta T_{\max}}{\theta_{JA} R_{\text{phase}}}} \] An above-continuous torque may be permitted transiently if the device’s temperature estimate and specified current-time limits allow it. The integral \(\int_0^t I^2dt\) is one possible protection measure, not a universal motor rating.

Reflected rotor inertia and angular jerk limits

Geared electromagnetic actuators amplify delivered motor torque while multiplying rotor inertia at the joint output. For a transmission with gear reduction ratio \(N = \omega_{\text{motor}} / \omega_{\text{joint}}\), kinetic energy conservation dictates the reflected inertia acting at the output link: \[ E_k = \frac{1}{2} J_{\text{rotor}} \omega_{\text{motor}}^2 + \frac{1}{2} J_{\text{load}} \omega_{\text{joint}}^2 = \frac{1}{2} (J_{\text{load}} + N^2 J_{\text{rotor}}) \dot{q}^2 \] The effective rotational inertia seen at joint coordinate \(q\) is: \[ J_{\text{eff}} = J_{\text{load}} + N^2 J_{\text{rotor}} \] The joint equation of motion under motor electromagnetic torque \(\tau_{\text{motor}}\) is: \[ \ddot{q} = \frac{N \tau_{\text{motor}} - \tau_{\text{ext}}}{J_{\text{load}} + N^2 J_{\text{rotor}}} \] Differentiating \(\ddot{q}\) with respect to gear ratio \(N\) at zero external load yields: \[ \frac{\partial \ddot{q}}{\partial N} = \frac{\tau_{\text{motor}} (J_{\text{load}} - N^2 J_{\text{rotor}})}{(J_{\text{load}} + N^2 J_{\text{rotor}})^2} \] Setting \(\frac{\partial \ddot{q}}{\partial N} = 0\) yields the inertia-matching ratio \(N^* = \sqrt{J_{\text{load}} / J_{\text{rotor}}}\). When \(N > N^*\), counter-intuitively, increasing the gear ratio decreases delivered joint acceleration because the motor spends the majority of its torque accelerating its own rotor rather than the link.

Dynamic angular jerk and torque slew limits

Angular jerk \(j_{\text{joint}}(t) = \dddot{q}(t)\) measures the time rate of change of joint acceleration: \[ j_{\text{joint}}(t) = \frac{N}{J_{\text{load}} + N^2 J_{\text{rotor}}} \frac{d\tau_{\text{motor}}(t)}{dt} \] Electromagnetic torque relates to stator quadrature current via torque constant \(K_t\): \(\tau_{\text{motor}} = K_t I_q\). From the stator electrical dynamics in this section, current slew rate is bounded by winding inductance \(L_{\text{phase}}\): \[ \frac{d\tau_{\text{motor}}}{dt} = K_t \frac{dI_q}{dt} = \frac{K_t}{L_{\text{phase}}} \left( V_{\text{terminal}} - K_e \omega_m - R_{\text{phase}} I_q \right) \] Under maximum DC bus terminal voltage saturation \(V_{\max}\), the physical upper bound on delivered angular jerk is: \[ |j_{\max}| \le \frac{N K_t (V_{\max} - K_e \omega_m)}{L_{\text{phase}} (J_{\text{load}} + N^2 J_{\text{rotor}})} \] When an unprivileged neural policy outputs a step torque discontinuity \(\Delta \boldsymbol{\tau}\) across discrete timesteps, the commanded derivative \(\frac{d\tau}{dt} \to \infty\) cannot be delivered instantaneously by physical silicon. The inverter enters hard voltage saturation, causing steep current slew (\(dI/dt\)), intense thermal stress on power MOSFETs, and shock loads across gear-tooth contact flanks (\(\sigma_b \propto W_t / (b m Y)\)). Synchronous pre-actuation invariant filters evaluate numerical torque derivatives \((\boldsymbol{\tau}[k] - \boldsymbol{\tau}[k-1]) / \Delta t\) to ensure requested actions remain within allowable jerk envelopes before latching power stages.

DC Bus Power Distribution and Energy Absorption

A robotic platform’s electrical power distribution network must supply acceleration surges and absorb regenerative braking energy across finite bus capacitance and harness impedance.

Inductive droop and capacitive decoupling

When multiple actuators accelerate, harness resistance and inductance impede source current while local capacitance supplies the difference. For a specified waveform, the resistive and inductive terms are \(\Delta I_{\text{source}}R_{\text{bus}}\) and \(L_{\text{bus}}\,dI_{\text{source}}/dt\); capacitor discharge obeys \[ \Delta V_C(t)=\frac{1}{C_{\text{bus}}}\int_0^t\bigl(I_{\text{load}}(s)-I_{\text{source}}(s)\bigr)\,ds. \] These terms cannot simply be added as simultaneous peaks without a circuit and waveform model. If the resulting voltage crosses a configured under-voltage lockout (UVLO) threshold for long enough, the supply may disable or reset; the threshold, filtering, and plant consequence require measurement.

Regenerative braking surges and chopper sizing

During controlled regenerative deceleration, some mechanical kinetic energy \(E_k=\frac12mv^2\) (linear) or \(E_k=\frac12J_{\text{load}}\dot q_0^2\) (rotational) may return through the inverter. If the battery cannot accept it and an assumed fraction \(\eta_{\text{regen}}\) reaches the local bus capacitor \(C_{\text{bus}}\) before another sink acts, the ideal capacitor relation is: \[ \Delta E_C = \frac{1}{2} C_{\text{bus}} \left( V_{\text{final}}^2 - V_{\text{initial}}^2 \right) = \eta_{\text{regen}} E_k \] \[ V_{\text{final}} = \sqrt{ V_{\text{initial}}^2 + \frac{2 \eta_{\text{regen}} E_k}{C_{\text{bus}}} } \] For an implementation with an active brake chopper, the resistor and switch must absorb the modeled peak power and pulse energy when \(V_{\text{bus}}\ge V_{\text{clamp}}\):9 \[ R_{\text{brake}} \le \frac{V_{\text{clamp}}^2}{P_{\text{regen, peak}}} \] \[ P_{\text{regen, peak}} \approx \eta_{\text{regen}} \cdot \tau_{\text{brake}} \cdot \omega_{\max} \] The resistor inequality is only a peak-power sizing check; minimum resistance for switch current, pulse energy, and thermal recovery impose additional constraints.

Real-Time Fieldbuses and Lock-Free Synchronization

Coordinating distributed drives requires a measured network schedule and a bounded local publication protocol.

Fieldbus serialization and schedulability

On a shared serial bus, \(N_{\text{axes}}\) drives transmit telemetry and receive setpoints cyclically. Serialization time depends on the complete frame, physical bit rates, and any stuffing or retransmission allowance.

CAN FD uses non-destructive priority arbitration at its nominal bit rate; a winning frame then sends its data phase at the configured data bit rate. An error-free serialization estimate for frame \(i\) is \[ t_{\text{frame},i}\approx\frac{B_{\text{arb},i}}{R_{\text{nom}}}+\frac{B_{\text{data},i}}{R_{\text{data}}}+t_{\text{stuff},i}+t_{\text{interframe},i}. \] This estimate is not a response-time bound. A lower-priority frame already transmitting can block a newly ready high-priority frame until that transmission ends; arbitration losers defer without a collision-error retry. Bound each message’s queuing and release jitter with the actual priority set, frame lengths, error assumptions, and bus load; Bosch’s CAN FD description distinguishes the arbitration and data phases.

EtherCAT processes data as frames pass through slave controllers. For a specified topology, a cycle budget includes serialization of every configured frame, master and slave forwarding, PHY and cable propagation, processing, and a guard for jitter and error recovery: \[ T_{\text{cycle}}\ge\sum_f\frac{B_f}{R_{\text{link}}}+t_{\text{master}}+\sum_s t_{\text{slave},s}+t_{\text{prop}}+t_{\text{guard}}. \] The achievable cycle period is configuration dependent; short advertised periods do not establish a deadline for a particular machine. The EtherCAT Technology Group describes the processing method and configurable process data.

Lock-free seqlocks for multi-rate shared memory

When a producer updates multiword state read by a deadline-bound enforcer, waiting on a producer-held mutex can violate the reader’s deadline. The single-slot mailbox in algorithm 1 uses a sequence counter to detect a torn snapshot.

A sequence counter marks a single writer’s publication in progress with an odd value and a completed publication with an even value:

  1. Writer Protocol:
    • Publish an odd sequence value, write the payload, and make it visible through the platform’s coherent or cache-maintained memory contract.
    • Publish the next even value with release ordering.
  2. Reader Protocol:
    • Read \(S_1\) with acquire ordering. If it is odd, reject this publication without waiting.
    • Make one bounded copy to scratch memory using the platform’s required load ordering, then read \(S_2\).
    • Accept only if \(S_1=S_2\) and both are even, and the copied frame passes integrity, timestamp, and lease checks. Otherwise retain the last validated local command only while its lease and stopping margin permit; then enter the state-matched fallback.

The reader’s one-attempt execution time can be bounded on the target hardware; success probability depends on the writer’s schedule and cannot be inferred from payload size alone. Conventional Linux seqlock readers may retry, as the kernel documentation shows, but a real-time permission gate cannot use an unbounded retry loop.

\begin{algorithm} \caption{Single-Slot Trajectory Seqlock Baseline} \begin{algorithmic} \Require proposal $P$ (proposal header with $\text{sequence\_id}$, $\text{t\_evidence\_ns}$, $\text{sync\_error\_ns}$, $\text{t\_expire\_ns}$; waypoints $\mathbf{w}_{1..K}$; $\text{crc32}$), scratch buffer $B_{\text{scratch}}$ and previously validated active spline $B_{\text{active}}$ in static SRAM, shared SRAM mailbox $(c_{\text{seq}}, \text{Slot}_{\text{shared}})$, current time $t_{\text{now}}$ and evidence-age budget $t_{\text{age,max}}$ (the largest admissible $t_{\text{age}}$), both on the safety microcontroller's clock \Ensure promoted validated chunk in $B_{\text{active}}$ or rejection with $B_{\text{active}}$ unchanged \Statex \Function{PublishActionChunk}{$P$} \State $c_{\text{curr}} \gets \Call{AtomicLoadExplicit}{c_{\text{seq}}, \text{memory\_order\_relaxed}}$ \State $\Call{AtomicStoreExplicit}{c_{\text{seq}}, c_{\text{curr}} + 1, \text{memory\_order\_relaxed}}$ \Comment{mark odd: write in progress} \State $\Call{HardwareMemoryBarrier}{\text{DMB\_OSHST}}$ \Comment{outer-shareable store barrier pushes counter} \State $\Call{CopyMemory}{\text{Slot}_{\text{shared}}.\text{payload}, P, \text{sizeof}(P)}$ \Comment{copy multi-word trajectory} \State $\Call{HardwareMemoryBarrier}{\text{DMB\_OSH}}$ \Comment{outer-shareable full barrier: payload visible} \State $\Call{AtomicStoreExplicit}{c_{\text{seq}}, c_{\text{curr}} + 2, \text{memory\_order\_release}}$ \Comment{mark even: publish committed} \EndFunction \Statex \Function{LatchLatestActionChunk}{$B_{\text{scratch}}, B_{\text{active}}, t_{\text{now}}$} \State $c_{\text{start}} \gets \Call{AtomicLoadExplicit}{c_{\text{seq}}, \text{memory\_order\_acquire}}$ \Comment{load initial counter (ARM LDAR acquire)} \If{$c_{\text{start}}$ is odd} \State \Return $\text{STATUS\_WRITER\_ACTIVE}$ \Comment{writer active; retain prior spline} \EndIf \State $\Call{HardwareMemoryBarrier}{\text{DMB\_OSHLD}}$ \Comment{explicit barrier: prevent payload reads hoisting before counter} \State $\Call{CopyMemory}{B_{\text{scratch}}, \text{Slot}_{\text{shared}}.\text{payload}, \text{sizeof}(\text{Payload})}$ \Comment{tentative copy; active spline unchanged} \State $\Call{HardwareMemoryBarrier}{\text{DMB\_OSHLD}}$ \Comment{LDAR cannot prevent prior reads sinking; DMB forces payload reads before $c_{\text{end}}$} \State $c_{\text{end}} \gets \Call{AtomicLoadExplicit}{c_{\text{seq}}, \text{memory\_order\_acquire}}$ \Comment{re-read sequence counter} \If{$c_{\text{start}} \ne c_{\text{end}}$} \State \Return $\text{STATUS\_TORN\_READ}$ \Comment{concurrent write detected} \EndIf \If{$\Call{ComputeCrc32}{B_{\text{scratch}}} \ne B_{\text{scratch}}.\text{crc32}$} \State \Return $\text{STATUS\_CHECKSUM\_INVALID}$ \EndIf \If{$t_{\text{now}} \ge B_{\text{scratch}}.\text{t\_expire\_ns}$} \State \Return $\text{STATUS\_LEASE\_EXPIRED}$ \Comment{expiry is absolute; the reader may only shorten it} \EndIf \If{$t_{\text{now}} - B_{\text{scratch}}.\text{t\_evidence\_ns} + B_{\text{scratch}}.\text{sync\_error\_ns} > t_{\text{age,max}}$} \State \Return $\text{STATUS\_EVIDENCE\_STALE}$ \Comment{conversion error is added to every age} \EndIf \State $B_{\text{active}} \gets B_{\text{scratch}}$ \Comment{promote only after sequence, CRC, expiry, and evidence-age checks} \State \Return $\text{STATUS\_VALID\_LATCHED}$ \EndFunction \end{algorithmic} \end{algorithm}

Multi-Rate Cadences exchanges the proposal header and its chunk payload through this mailbox; section 14.1 gives their byte layout.

Camera Projective Geometry and Covariance Propagation

Perception pipelines map continuous Euclidean 3D scenes onto discrete 2D camera photosite grids.

Intrinsic projection matrix and radial distortion

Under the standard pinhole camera model, a 3D point \(\mathbf{p}_c = [x_c, y_c, z_c]^\top\) in camera coordinates projects onto pixel coordinates \(\mathbf{u} = [u, v]^\top\) via the intrinsic calibration matrix \(\mathbf{K}\):10 \[ \tilde{\mathbf{u}} = \begin{bmatrix} u \\ v \\ 1 \end{bmatrix} = \frac{1}{z_c} \mathbf{K} \mathbf{p}_c = \frac{1}{z_c} \begin{bmatrix} f_x & 0 & c_x \\ 0 & f_y & c_y \\ 0 & 0 & 1 \end{bmatrix} \begin{bmatrix} x_c \\ y_c \\ z_c \end{bmatrix} \] where \((f_x, f_y)\) are focal lengths in pixel units and \((c_x, c_y)\) is the principal point. Non-linear radial lens distortion is modeled by distortion coefficients \((k_1, k_2)\): \[ r^2 = x_n^2 + y_n^2, \quad x_d = x_n (1 + k_1 r^2 + k_2 r^4), \quad y_d = y_n (1 + k_1 r^2 + k_2 r^4) \] where \((x_n, y_n) = (x_c / z_c, y_c / z_c)\) are normalized image coordinates.

Metric unprojection and spatial covariance propagation

When unprojecting a 2D pixel observation \(\mathbf{u}\) with measured depth \(z\) into 3D camera coordinates, photosite measurement noise \(\mathbf{\Sigma}_{\text{meas}} = \text{diag}(\sigma_u^2, \sigma_v^2, \sigma_z^2)\) propagates through the unprojection Jacobian \(\mathbf{J}_{\text{unproj}}\): \[ \mathbf{p}_c = \begin{bmatrix} (u - c_x) z / f_x \\ (v - c_y) z / f_y \\ z \end{bmatrix}, \quad \mathbf{\Sigma}_c = \mathbf{J}_{\text{unproj}} \mathbf{\Sigma}_{\text{meas}} \mathbf{J}_{\text{unproj}}^\top \] Transforming this 3D point into the robot body frame via rigid extrinsic transform \(\mathbf{T}_{bc} = [\mathbf{R}_{bc}, \mathbf{p}_{bc}; \mathbf{0}^\top, 1]\) yields the spatial body covariance: \[ \mathbf{\Sigma}_b = \mathbf{R}_{bc} \mathbf{\Sigma}_c \mathbf{R}_{bc}^\top + \mathbf{\Sigma}_{\text{ext}} \] where \(\mathbf{\Sigma}_{\text{ext}}\) models independent extrinsic uncertainty under this first-order approximation; correlations require the corresponding cross terms. A probabilistic clearance buffer may scale with \(\sqrt{\lambda_{\max}(\mathbf{\Sigma}_b)}\) at a declared tail risk. A deterministic permission check instead needs a justified bounded-error envelope; covariance alone does not give a worst-case bound.

Zhang’s planar homography and camera calibration

Zhang’s calibration technique computes the camera intrinsic matrix \(\mathbf{K}\) by observing a planar calibration rig (such as a checkerboard pattern) across \(N \ge 3\) distinct orientations (Zhang 2000). Without loss of generality, assume the model plane lies on \(Z = 0\) in world coordinates. A 3D model point \(\mathbf{M} = [X, Y, 0, 1]^\top\) maps to a 2D image point \(\tilde{\mathbf{u}} = [u, v, 1]^\top\) through a \(3 \times 3\) planar homography matrix \(\mathbf{H}\): \[ s \begin{bmatrix} u \\ v \\ 1 \end{bmatrix} = \mathbf{K} \begin{bmatrix} \mathbf{r}_1 & \mathbf{r}_2 & \mathbf{r}_3 & \mathbf{t} \end{bmatrix} \begin{bmatrix} X \\ Y \\ 0 \\ 1 \end{bmatrix} = \mathbf{K} \begin{bmatrix} \mathbf{r}_1 & \mathbf{r}_2 & \mathbf{t} \end{bmatrix} \begin{bmatrix} X \\ Y \\ 1 \end{bmatrix} = \mathbf{H} \begin{bmatrix} X \\ Y \\ 1 \end{bmatrix} \] where \(\mathbf{H} = [\mathbf{h}_1 \; \mathbf{h}_2 \; \mathbf{h}_3] = \lambda \mathbf{K} [\mathbf{r}_1 \; \mathbf{r}_2 \; \mathbf{t}]\) with arbitrary nonzero scalar \(\lambda\).

Zhang, Zhengyou. 2000. “A Flexible New Technique for Camera Calibration.” IEEE Transactions on Pattern Analysis and Machine Intelligence 22 (11): 1330–34. https://doi.org/10.1109/34.888718.

Orthogonality constraints on the absolute conic

Because the rotation vectors \(\mathbf{r}_1\) and \(\mathbf{r}_2\) are orthonormal columns of an \(SO(3)\) matrix (\(\mathbf{r}_1^\top \mathbf{r}_2 = 0\) and \(\|\mathbf{r}_1\| = \|\mathbf{r}_2\| = 1\)), inverting \(\mathbf{K}\) yields: \[ \mathbf{r}_1 = \frac{1}{\lambda} \mathbf{K}^{-1} \mathbf{h}_1, \quad \mathbf{r}_2 = \frac{1}{\lambda} \mathbf{K}^{-1} \mathbf{h}_2 \] Imposing orthonormality on \(\mathbf{r}_1\) and \(\mathbf{r}_2\) defines two fundamental algebraic constraints per homography: \[ \mathbf{h}_1^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_2 = 0 \] \[ \mathbf{h}_1^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_1 - \mathbf{h}_2^\top \mathbf{K}^{-\top} \mathbf{K}^{-1} \mathbf{h}_2 = 0 \] The symmetric matrix \(\mathbf{B} = \mathbf{K}^{-\top} \mathbf{K}^{-1}\) represents the image of the absolute conic (IAC): \[ \mathbf{B} = \begin{bmatrix} B_{11} & B_{12} & B_{13} \\ B_{12} & B_{22} & B_{23} \\ B_{13} & B_{23} & B_{33} \end{bmatrix} \] Defining the 6-vector \(\mathbf{b} = [B_{11}, B_{12}, B_{22}, B_{13}, B_{23}, B_{33}]^\top\), each quadratic term \(\mathbf{h}_i^\top \mathbf{B} \mathbf{h}_j\) can be rewritten as the linear inner product \(\mathbf{v}_{ij}^\top \mathbf{b}\), where: \[ \mathbf{v}_{ij} = \begin{bmatrix} h_{i1}h_{j1} \\ h_{i1}h_{j2} + h_{i2}h_{j1} \\ h_{i2}h_{j2} \\ h_{i3}h_{j1} + h_{i1}h_{j3} \\ h_{i3}h_{j2} + h_{i2}h_{j3} \\ h_{i3}h_{j3} \end{bmatrix} \] The two constraints per observed orientation become the linear system: \[ \begin{bmatrix} \mathbf{v}_{12}^\top \\ (\mathbf{v}_{11} - \mathbf{v}_{22})^\top \end{bmatrix} \mathbf{b} = \mathbf{0} \] Stacking \(N \ge 3\) images forms the homogeneous system \(\mathbf{V} \mathbf{b} = \mathbf{0}\), where \(\mathbf{V} \in \mathbb{R}^{2N \times 6}\). The right singular vector of \(\mathbf{V}\) corresponding to the smallest singular value provides \(\mathbf{b}\) up to a scale factor. The intrinsic parameters \((f_x, f_y, c_x, c_y)\) and skew \(\gamma\) are then uniquely extracted via Cholesky factorization of \(\mathbf{B}\). This closed-form linear solution initializes the non-linear Levenberg–Marquardt optimization minimizing reprojection residuals over all observed fiducial corners.

Kinematic Stopping Envelopes and Information Age Lag

Halting an embodied machine transporting mass \(m\) at speed \(v\) requires balancing sensorimotor information freshness and mechanical braking deceleration.

Sensorimotor information age and lag distance

For a specified hazard detector and stop path, let \(\tau_{\text{delay}}\) bound the time from the physical state represented by the evidence until validated braking deceleration begins: \[ \tau_{\text{delay}} = t_{\text{age}} + t_{\text{detect}} + t_{\text{compute}} + T_{\text{bus}} + T_{\text{act}} \] where:

  • \(t_{\text{age}}\) converts the evidence timestamp to the controller clock and includes exposure/readout and clock error.
  • \(t_{\text{detect}}\) bounds recognition or lease-expiry detection.
  • \(t_{\text{compute}}\) is the admitted stop decision, including any required input transfer.
  • \(T_{\text{bus}}\) bounds command dispatch and network queuing.
  • \(T_{\text{act}}\) ends when the measured actuator begins delivering the specified deceleration, not when a command register is written.

Under the explicit simplifying assumption that speed cannot increase before brake onset, the blind travel is bounded by \(d_{\text{blind}}=v\,\tau_{\text{delay}}\). If propulsion or a slope can increase speed, use its validated acceleration bound in this interval instead.

Braking dynamics and friction limits

Tire-floor friction and actuator torque place upper limits on achievable deceleration; \(a\le\mu g\) does not establish what braking the machine will deliver. Let \(a_{\text{brake}}>0\) be a validated lower bound on achieved deceleration throughout the stop, for the declared load, temperature, slope, brake condition, and surface. A justified friction floor \(\mu_{\text{floor}}\) may support that bound, but does not replace brake tests. With constant or stronger braking after onset, a localization bound \(\delta_{\text{loc}}\), a fixed protective clearance \(\delta_{\text{margin}}\), and a tracking-error bound \(\epsilon_{\text{track}}\), \[ d_{\text{stop}}(v)=v\,\tau_{\text{delay}}+\frac{v^2}{2a_{\text{brake}}}+\delta_{\text{loc}}+\delta_{\text{margin}}+\epsilon_{\text{track}}. \] Motion is admitted only when \(d_{\text{stop}}(v)\le D_{\text{clear}}\), where \(D_{\text{clear}}\) is taken as a validated lower bound on available path clearance. This is the inset stopping distance that Stopping Envelopes defends. The sampled controller must reserve intersample travel and a state-matched stop before the viable region is lost.

Kinetic energy derating and friction collapse

In an ideal friction-limited model, lowering \(\mu\) from \(\mu_{\text{nom}}\) to a positive \(\mu_{\text{fault}}\) changes the braking-distance ratio to \(\mu_{\text{nom}}/\mu_{\text{fault}}\). That ratio is illustrative; actual deceleration can also be limited by brake hardware or control. If surface friction is not sensed in time, derive \(a_{\text{brake}}\) from a controlled surface condition and inspection schedule, exclude degraded surfaces, or withhold motion. For the constant-speed pre-brake model above, solving the clearance inequality gives \[ v_{\text{clamp}}=-a_{\text{brake}}\tau_{\text{delay}}+\sqrt{(a_{\text{brake}}\tau_{\text{delay}})^2+2a_{\text{brake}}\left(D_{\text{clear}}-\delta_{\text{loc}}-\delta_{\text{margin}}-\epsilon_{\text{track}}\right)}. \] This clamp is valid only when \(D_{\text{clear}}\) exceeds the three fixed allowances, the braking and timing lower bounds hold, and the speed bound is enforced before entering the hazard corridor. No positive clamp follows if the available deceleration floor is unknown or zero.

Wire Formats for the Record Chain

The chapters name each record’s fields by meaning and state the invariant the record enforces. This section gives the byte layouts for records that must fit a fixed-size mailbox or log, and the canonical field order for the offline records that are stored and bound by digest. Every absolute time is an unsigned 64-bit count of nanoseconds on the safety microcontroller’s monotonic clock, every duration is an unsigned count of nanoseconds, and sync_error_ns carries the conversion bound for evidence captured on another clock. The clock and integrity policies themselves belong to Multi-Rate Cadences; the layouts here fix the algorithm for each integrity job. Corruption detection uses a CRC-32 (IEEE 802.3) over header and payload, lineage uses a SHA-256 digest of the consumed record, and authority uses HMAC-SHA-256 on operator commands, a keyed hash chain on the forensic log, and Ed25519 signatures on fault records and release artifacts. The authority, fault, and release records are each followed by the protocol that writes or checks them.

Fixed layouts are little-endian and packed in the order listed. Offsets are hexadecimal byte positions from the start of the record, and every multibyte field sits on its natural alignment, so no field needs hidden padding. A field whose length depends on a count comes after every fixed field, and its offset is written in terms of that count. The record itself carries \(K\) waypoints, \(N_j\) commanded joints, \(K_b\) barrier constraints, and \(K_a\) approach channels; the static authority manifest fixes \(N_c\) command components and \(N_s\) state components. Offline records (placement, fault, release) are identified by the SHA-256 digest of their canonical encoding, and the record that consumes one stores that digest under the consumed record’s name.

Proposal header and chunk payload

Every proposal that crosses the proposal boundary opens with the same header, and payload_kind selects the payload that follows at 0x50. Table 7 lays out the header with the minimal chunk payload of Multi-Rate Cadences. The chunk carries kinematic setpoints only. Torque is computed on the permission side, where the tracker derives it from the admitted reference, so a learned proposal never names a motor torque.

Table 7: Proposal header and chunk payload: Field offsets, scalar types, units, and invariants for a chunk proposal exchanged through the seqlock mailbox of algorithm 1. The header occupies 0x00–0x4F in every proposal; the other payload layouts in this section begin at 0x50.
Offset Field Scalar type Unit Invariant and check
0x00 sequence_id uint64_t dimensionless Strictly increasing per producer; a record not newer than the last accepted one is rejected.
0x08 t_evidence_ns uint64_t ns, permission clock Capture epoch of the oldest evidence the proposal rests on, converted to the safety microcontroller’s clock.
0x10 t_issue_ns uint64_t ns, permission clock Time the producer published the record.
0x18 t_expire_ns uint64_t ns, permission clock Requested absolute expiry, no later than the chunk lease allows; the permission path may only shorten it.
0x20 frame_id uint64_t dimensionless Transform-tree key and calibration revision of the setpoints’ frame.
0x28 parent_digest uint8_t[32] SHA-256 Digest of the record this proposal was derived from; establishes lineage, authenticates nothing.
0x48 sync_error_ns uint32_t ns Bound on the evidence time’s conversion error; added to every age the reader checks.
0x4C payload_kind uint16_t enumeration CHUNK for this payload; INTENT, TRAJECTORY, and OPERATOR select the other payloads.
0x4E payload_len uint16_t bytes Payload length; bounds the parser before any payload byte is read.
0x50 num_waypoints uint16_t count Chunk horizon \(K\); a count outside the configured range is rejected.
0x52 num_joints uint8_t count Commanded joints \(N_j\); must equal the configured count, and payload_len must equal \(4+8KN_j\).
0x53 reserved uint8_t — Zero.
0x54 joint_positions float32[K][N_j] rad Commanded joint angles within the reach limits (\(q_{\min} \le q \le q_{\max}\)).
0x54 + \(4KN_j\) joint_velocities float32[K][N_j] rad/s Commanded joint velocities within certified ceilings (\(\lVert \dot{\mathbf{q}} \rVert \le \dot{q}_{\max}\)).
0x50 + payload_len crc32 uint32_t checksum Last field; IEEE 802.3 CRC-32 over all preceding bytes.

Intent payload

The intent lease of The Intent Lease travels under the proposal header with payload_kind set to INTENT (table 8). Three header fields take specific meanings. t_evidence_ns is the parent belief record’s evidence epoch, never its estimate epoch; parent_digest is that belief record’s digest, which the permission path matches against a retained record; and t_expire_ns is the requested expiry, which the permission path shortens to the earliest of the evidence horizon, its configured lease ceiling, and the stop deadline. The six bounds values are three conservative position-error envelopes and three task tolerances in the base frame named by frame_id. They are not an encoding of a covariance, and the producer must justify any conversion from its covariance estimate, including calibration bias and the declared tail risk.

Table 8: Intent payload: The intent lease as a proposal-header payload. Orientation tolerances and contact-mode rules come from an independently approved task profile; the quaternion is the proposed orientation only.
Offset Field Scalar type Unit Invariant and check
0x00–0x4F proposal header as above as above Table 7, with payload_kind = INTENT.
0x50 target_pose float64[7] m; unit quaternion Base-frame position and orientation; finite values, normalized quaternion, workspace prefilter.
0x88 bounds float32[6] m Error envelope \(e_{x,y,z}\), then task tolerance \(r_{x,y,z}\); \(0 \le e_i \le r_i\), each checked against the approved task profile.
0xA0 wrench_request float32[6] N; N·m Three requested forces and three torques; clamped or rejected against independent task and actuator limits.
0xB8 terminal_request uint32_t enumeration Requested terminal mode; the permission path selects a feasible approved response from the current load and contact state.
0xBC crc32 uint32_t checksum IEEE 802.3 CRC-32 over all preceding bytes.

Trajectory payload

The trajectory record of The Trajectory Contract replaces the chunk on the running machine and travels under the same proposal header, with payload_kind set to TRAJECTORY and parent_digest set to the digest of the active intent lease (table 9). The header’s t_expire_ns carries the chunk lease; the intent’s own expiry comes from the lease that parent_digest identifies. The setpoint samples and the assumptions sidecar travel outside this fixed part. The permission path verifies sidecar_digest over both, validates the complete candidate in staging memory, and latches the admitted setpoints and stop suffix in protected memory before tracking begins.

Table 9: Trajectory payload: The trajectory record as a proposal-header payload. The four deadlines are absolute times on the safety microcontroller’s clock; the variable-length setpoint samples and the assumptions sidecar are bound by sidecar_digest and validated before activation.
Offset Field Scalar type Unit Invariant and check
0x00–0x4F proposal header as above as above Table 7, with payload_kind = TRAJECTORY.
0x50 sample_period_ns uint32_t ns Setpoint cadence \(\Delta t_{\text{step}}\); must match the configured decoder.
0x54 num_samples uint16_t count Nominal setpoints in the digested sample payload; bounds its size.
0x56 num_joints uint8_t count Commanded joints \(N_j\); must equal the configured count.
0x57 payload_version uint8_t enumeration Decoder version; an unknown version is rejected.
0x58 t_start_ns uint64_t ns, permission clock First nominal sample.
0x60 t_commit_ns uint64_t ns, permission clock Latest entry into the matched stop suffix; \(t_{\text{commit}}=t_{\text{stop\_end}}-T_{\text{stop}}\).
0x68 t_plan_exp_ns uint64_t ns, permission clock End of the nominal setpoints.
0x70 t_stop_end_ns uint64_t ns, permission clock Protected stop completion; \(t_{\text{start}}\le t_{\text{commit}}<t_{\text{plan\_exp}}<t_{\text{stop\_end}}\).
0x78 sidecar_digest uint8_t[32] SHA-256 Digest over the setpoint samples and the assumptions sidecar; binds content.
0x98 seam_state float32[3][N_j] rad; rad/s; rad/s² Entry state \((q,\dot q,\ddot q)\) of each joint.
0x98 + \(12N_j\) stop_suffix float32[6][N_j] quintic coefficients One quintic stop per joint; must be resident and feasible from every state reachable before \(t_{\text{commit}}\).
0x98 + \(36N_j\) crc32 uint32_t checksum IEEE 802.3 CRC-32 over all preceding bytes.

Enforcement record

The enforcement record of The Enforcement Record is configuration, not a proposal, so it carries no proposal header (table 10). Three digests name what the record rests on: the evaluation record, the limit records behind the stopping envelope, and the validity region. Each threshold names the fallback-ladder rung that a failed check selects. Where the rung depends on whether the body is moving, the row names both, STOP in motion and HOLD at standstill. A proposal refused while the active lease holds selects no rung, because the setpoints already admitted stay in force until that lease lapses.

Table 10: Enforcement record: Thresholds of the permission path with the fallback-ladder rung each failed check selects, and digests of the evaluation record, limit records, and validity region the thresholds rest on. The record is configuration and telemetry; it adds no packet to the proposal stream.
Offset Field Scalar type Unit Check, and the rung a failure selects
0x00 evaluation_record_digest uint8_t[32] SHA-256 Evaluation record whose runtime monitor specifications become this record’s monitor channels.
0x20 limit_record_digest uint8_t[32] SHA-256 Canonical list of the limit records whose braking, onset, and actuator limits parameterize \(d_{\text{stop}}(v)\).
0x40 validity_region_digest uint8_t[32] SHA-256 validity_region, the plant-parameter bounds the thresholds rest on. On the mobile manipulator it covers the arm at the door, where it equals the target ODD, and at the packing station through the mug pick and the handover approach. Each base configuration, normal or restricted, loads as its own enforcement record, so this field holds the region digest of that configuration and its friction premise. A live state outside it that the machine observes selects STOP.
0x60 loop_period_ns uint32_t ns Permission-loop period \(T_{\text{loop}}\); the placement record’s nominal_period_ns must equal it.
0x64 deadline_ns uint32_t ns Permission-path deadline inside the tick; a cycle at risk of overrunning it selects HOLD.
0x68 evidence_age_ceiling_ns uint32_t ns Refusal threshold of the evidence-epoch check, the budgeted observation age plus the clock-conversion bound. A proposal whose upper evidence age exceeds it is refused, and the permission path shortens t_expire_ns to at most t_evidence_ns plus the ceiling minus sync_error_ns. A proposal whose sequence_id is not newer is refused; an expired lease selects STOP in motion and HOLD at standstill.
0x6C watchdog_timeout_ns uint32_t ns The self-watchdog is fed only after a completed tick; expiry requests INHIBIT through the independently wired trip.
0x70 t_stop_ns uint32_t ns Stopping-time bound from the maximum admitted speed; a reference that leaves less clearance than \(\epsilon_{\text{track}} + v_{\max} t_{\text{stop}}\) selects STOP.
0x74 pos_tracking_bound float32 m \(\lvert x_{\text{meas}} - r_{\text{cmd}} \rvert \le \epsilon_{\text{track}}\); STOP above it.
0x78 pos_critical_bound float32 m \(\lvert x_{\text{meas}} - r_{\text{cmd}} \rvert \le \epsilon_{\text{crit}}\), with \(\epsilon_{\text{crit}} > \epsilon_{\text{track}}\); STOP above it.
0x7C vel_ceiling_limit float32 rad/s \(\lvert \dot{q} \rvert \le \dot{q}_{\max}\); PROJECT (QP clamp).
0x80 torque_slew_ceiling float32 N·m/s \(\lvert \dot{\tau} \rvert \le \dot{\tau}_{\max}\); PROJECT (slew limiter).
0x84 actuator_curr_limit float32 A \(\lvert I_{\text{phase}} \rvert \le I_{\text{peak}}\); STOP.
0x88 dc_bus_overvolt_thresh float32 V \(V_{\text{bus}} \le V_{\text{max\_safe}}\); STOP, with the brake chopper absorbing returned energy.
0x8C num_barriers uint16_t count Barrier constraints \(K_b\); must equal the configured count.
0x8E num_approach_channels uint16_t count Approach channels \(K_a\); must equal the configured count.
0x90 cbf_barrier_params float32[K_b][2] normalized distance; \(\text{s}^{-1}\) Margin \(\delta_k\) and class-\(\mathcal{K}\) rate \(\alpha_k\) of each barrier; \(h_k(\mathbf{x}) \ge \delta_k\), else PROJECT, or STOP when no feasible input remains.
0x90 + \(8K_b\) approach_channel_ids uint32_t[K_a] enumeration Zone and activation condition of each channel, drawn from the validity region, such as the tool point inside the door zone or accept_item held.
0x90 + \(8K_b+4K_a\) approach_ceilings float32[K_a] m/s Ceiling on tool-point approach speed while its channel is active; a faster proposal takes PROJECT (QP clamp), and the channel that bound it is logged.
0x90 + \(8K_b+8K_a\) crc32 uint32_t checksum IEEE 802.3 CRC-32 over all preceding bytes; a mismatch rejects the stored record, and no motion is admitted until a valid copy loads.

Placement record

The placement record of Hardware Allocation is offline evidence with a fixed header and a linked test ledger (table 11). It carries no signature of its own; the signed release manifest binds it through placement_record_digest. enforcement_record_digest names the enforcement record whose deadline_ns was tested, and test_ledger_digest identifies the external ledger that states the declared worst-case execution time the loaded test must not exceed, together with distributions, sample counts, test conditions, mitigations, and untested states. A maximum that has not been measured is stored as all ones, never zero, the same unavailable-value convention the fault record uses.

Table 11: Placement record header: Configuration values and observed maxima, with digests linking the tested enforcement record and the external test ledger. The header alone does not establish freedom from interference.
Offset Field Scalar type Unit Invariant and check
0x00 execution_domain_id uint64_t enumeration Must match the declared topology (application processor, NPU, GPU, MCU, lockstep controller).
0x08 privilege_and_ring uint64_t privilege level Proposer at EL0; enforcer at EL1 or above, or in the secure world.
0x10 nominal_period_ns uint32_t ns Enforcer tick; equal to the enforcement record’s loop_period_ns.
0x14 hard_deadline_ns uint32_t ns The permission path’s deadline inside the tick; equal to the enforcement record’s deadline_ns.
0x18 unloaded_observed_max_ns uint64_t ns Largest response observed without competing load; a sample maximum, not a WCET.
0x20 loaded_observed_max_ns uint64_t ns Largest response under the declared load; all ones until a loaded test runs. Independence stands only while it is at most the declared WCET.
0x28 shared_axi_channel_qos uint64_t configured QoS Arbitration priority per claimant; controller semantics verified by register capture and a stress test.
0x30 max_pdn_droop_thermal_trip uint32_t[2] mV; m°C Configured rail-droop and thermal trip thresholds; the ledger records the tests behind them.
0x38 hardware_mitigation_flags uint8_t[32] bitfield Active mitigations, such as a TCM snapshot, memory partitioning, or an isolated rail; register-locked after boot.
0x58 enforcement_record_digest uint8_t[32] SHA-256 Enforcement record whose loop_period_ns and deadline_ns this record tests.
0x78 test_ledger_digest uint8_t[32] SHA-256 External test ledger, including the model and firmware digests under test.

Authority record and operator payload

The authority record of The Authority Log has two runtime layouts. A network operator’s command is a proposal-header payload (table 12), and it is the one proposal whose sender’s identity confers authority, so it carries an HMAC-SHA-256 tag under the operator role’s key. The static authority manifest fixes each role’s channel grant, the command’s component count, order, and units, and the key custody.

Table 12: Operator payload: A network operator’s command under the proposal header. The tag authenticates the role; the permission path still admits the command by its content.
Offset Field Scalar type Unit Invariant and check
0x00–0x4F proposal header as above as above Table 7, with payload_kind = OPERATOR.
0x50 nonce uint64_t — Never repeated within a key’s lifetime; a repeated nonce is rejected as a replay.
0x58 requested_channel_mask uint16_t bitfield Channels requested; must lie within the role’s grant in the static manifest.
0x5A operator_role_id uint8_t enumeration Role whose key produced mac.
0x5B reserved uint8_t — Zero.
0x5C command float32[N_c] per manifest Requested command components in manifest order, admitted like any other proposal.
0x5C + \(4N_c\) mac uint8_t[32] HMAC-SHA-256 Tag over all preceding bytes; an invalid tag locks out the channel.
0x7C + \(4N_c\) crc32 uint32_t checksum IEEE 802.3 CRC-32 over all preceding bytes.

The forensic authority record (table 13) is a log record written once per tick, not a packet. Its time is on the safety microcontroller’s clock; the mapping that relates it to PTP and calendar time, with its error bound, lives in the static manifest together with the vector lengths, units, and component order. Each record’s chain_link is an HMAC-SHA-256, under the log key, over the previous record’s link and this record’s preceding fields, so an altered or deleted record breaks every later link.

Table 13: Forensic authority record: One record per tick of the permission loop. A missing record is a gap in the chain, never an implied pass, and the record is a sampled decision trace, not proof of delivered force or contact.
Offset Field Scalar type Unit Recorded evidence and limit
0x00 t_mcu_ns uint64_t ns, permission clock Event time of this tick’s decision.
0x08 actuator_channel_mask uint16_t bitfield Channels to which this decision applies; bus and DMA permissions enforce write scope.
0x0A preempt_trigger_code uint16_t enumeration Request, timeout, enabling-device loss, or protective input cause.
0x0C authority_state uint8_t enumeration AUTO, PEND, BLEND, MAN, FALLBACK, or PROTECTIVE.
0x0D fallback_rung uint8_t enumeration PROJECT, HOLD, STOP, or INHIBIT when the state is FALLBACK; NONE otherwise.
0x0E operator_role_id uint8_t enumeration Authenticated source role, interpreted against the static manifest.
0x0F reserved uint8_t — Zero.
0x10 blend_factor_alpha float32 dimensionless Progress in \([0,1]\) of the enforcer-owned blending profile.
0x14 policy_proposed_cmd float32[N_c] per manifest Command components before permission; not a motor write.
0x14 + \(4N_c\) enforcer_clamped_cmd float32[N_c] per manifest Components admitted after the current constraint check.
0x14 + \(8N_c\) actuator_delivered_cmd float32[N_c] per manifest Dispatched setpoint components; delivery at the drive needs separate evidence.
0x14 + \(12N_c\) measured_plant_state float32[N_s] per manifest Sampled state components, with sensor timing in the manifest.
0x14 + \(12N_c+4N_s\) chain_link uint8_t[32] HMAC-SHA-256 Keyed link over the previous link and this record’s preceding fields; evidence of tampering only while the key and anchor stay in custody.

Authority-transfer protocol

Used in Authority Transitions and Transfer Without Discontinuity. The protocol runs in the enforcer’s \(1\text{ kHz}\) loop on the safety microcontroller, where the four-phase handshake, integrator pre-biasing, and the \(C^2\) quintic blend become one sequence of per-state steps. Each tick writes the forensic authority record of table 13 under the state names used below.

Cadence and invariants.

  • Execution cadence: Hard real-time periodic timer interrupt (\(f = 1\text{ kHz}\), period \(T_{\text{loop}} = 1.0\text{ ms}\), hardware timing jitter \(< 1.0\,\mu\text{s}\)).
  • Memory invariant: Zero dynamic heap allocation (malloc/free forbidden; all state variables, mailboxes, and circular log buffers statically pre-allocated in DTCM SRAM).
  • Hardware authority: Exclusive write of the admitted setpoints staged for the next EtherCAT frame to the drives, and of the safe torque off (STO) hardware cutoffs.

Execution protocol.

  1. Sample and validate plant state, available stopping reserve, independent protective inputs, and the current authority lease. An independent protective input selects its validated, state-matched stop path of The Fallback Ladder.
  2. In AUTO, a manual request or policy handover request enters PEND; the policy may propose only while its existing permission remains valid. Set \(T_{\text{timeout}}\) to the smaller of the protocol ceiling and clearance-derived deadline. No later than the last permission tick before \(T_{\text{timeout}}\), transfer to the state-matched fallback. An invalid network packet is rejected and logged, not interpreted as a stop request.
  3. In PEND, verify the operator credential, nonce, enabling input, target freshness, actuator limits, and full transfer-plus-stop clearance. On ACK, at the next qualified Commit tick, revoke the policy execution token on the masked channels, latch \(\mathbf u_0\) as its last admitted command, latch a checked human target \(\mathbf u_1\), and set BLEND. The enforcer remains the only actuator writer. If admission fails, retain or enter the independently validated fallback.
  4. In BLEND, evaluate \(s=\min(1,(t-t_0)/T)\) and \(\alpha(s)=6s^5-15s^4+10s^3\). The enforcer proposes \(\mathbf u_{\text{blend}}=(1-\alpha)\mathbf u_0+\alpha\mathbf u_1\), then checks that candidate against current state, torque/rate, and stopping limits before dispatch. These are latched endpoints, not simultaneous live policy and human actuator streams. If the lease, clearance, or tracking assumption fails, use the state-matched fallback. At \(s=1\) with a live manual lease, set MAN and confirm that state to the operator.
  5. In MAN, the enforcer checks each live human proposal. Lease expiry or enabling-device loss revokes manual proposals and transfers to the validated fallback. Log request, ACK, commit, candidate, admitted command, measured response, and clock uncertainty separately; the bounded high-rate record must not block the control tick.

Fault record

The fault record of The Fault Manifest is offline evidence, a fixed header signed with Ed25519 that links to the retained evidence bundle by digest (table 14). The fault-ledger root that the release manifest binds is computed over the canonical encodings of these headers. envelope_point has a per-machine definition in the versioned fault-class manifest; for the mobile manipulator its four values are aisle speed (m/s), payload (kg), floor friction coefficient, and ambient temperature (K).

Table 14: Fault-record header: The fixed part of one fault trial. The linked evidence bundle carries fault duration, hardware and software build identifiers, raw trace references and clock domains, detector identity, every margin value and scale, the measured physical outcome, secondary anomalies, and partial traces for non-pass verdicts.
Offset Field Scalar type Unit Purpose and interpretation
0x00 trial_id uint64_t — Unique trial identifier in the versioned ledger.
0x08 claim_ref_id uint32_t index Precommitted physical claim and its units.
0x0C envelope_point float32[4] per manifest Declared operating point of the trial.
0x1C fault_injection_mode uint16_t enumeration Injected fault class.
0x1E injection_target_node uint16_t enumeration Hardware boundary receiving the injection.
0x20 fault_magnitude float32 per fault class Injection amplitude; its unit is fixed by the fault-class manifest.
0x24 t_det_ns uint32_t ns Fault trigger to detector assertion.
0x28 t_takeover_ns uint32_t ns Fault trigger to measured takeover; subtract t_det_ns for the post-detection interval.
0x2C stl_robustness_rho float32 claim’s unit Raw signed margin for claim_ref_id; other predicate margins remain in the bundle.
0x30 verdict_status uint8_t enumeration PASS, FAIL, INVALID, or UNOBSERVABLE.
0x31 reserved uint8_t[3] — Zero.
0x34 oracle_digest uint8_t[32] SHA-256 Immutable predicate and oracle configuration.
0x54 evidence_digest uint8_t[32] SHA-256 Separately retained trial evidence bundle.
0x74 signature uint8_t[64] Ed25519 Signature over all preceding bytes; the key identifier is in the versioned manifest.

For a trial aborted before injection, detector time, takeover time, and robustness margin are unavailable rather than zero. The layout stores all ones (0xFFFFFFFF) in an unavailable uint32_t time slot and a canonical quiet NaN in an unavailable float32 margin slot, and the signed evidence bundle records a validity flag for each measured field and why it is absent. The oracle checks those flags and the verdict before doing arithmetic, and excludes unavailable slots from pass counts and from latency or margin statistics. The versioned manifest fixes the NaN bit pattern so that hashing remains reproducible.

Fault-injection protocol

Used in Fault Injection on Hardware. The protocol runs one hardware-in-the-loop trial on target silicon, from the precondition audit to the signed header of table 14, and every exit it takes sets one value of that header’s verdict_status.

Substrate and invariants.

  • Execution substrate: Hard real-time field-programmable gate array (FPGA) plant rig and testbed orchestrator (\(f = 1\text{ kHz}\), hardware timestamping jitter \(< 500\text{ ns}\)).
  • Memory invariant: Pre-allocated static DMA buffers in the host test orchestrator; zero runtime dynamic heap allocation on the safety microcontroller.
  • Safety interlock authority: Independent optical or laser truth sensors wired to hardware crowbar relays capable of cutting target actuator power within \(2.0\text{ ms}\) of a physical envelope breach.

Execution protocol.

  1. Precondition audit (stage 1). Sample baseline environmental sensors via \(\mathcal{I}_{\text{truth}}\) (temperature, rail voltage, and wheel speed). Compare each measurement with its declared same-unit tolerance; do not take one norm across kelvin, volts, and meters per second. If any precondition fails, log ERR_PRECONDITION_OUT_OF_SPEC, set the verdict to INVALID, and abort.

  2. Synchronization and steady-state arming (stage 2). Arm the FPGA plant simulator, power up the target two-processor system, and start the periodic control loop (\(1\text{ kHz}\)). Establish a synchronized reference clock across the logic analyzer, FPGA plant, and truth digitizers via a \(10\text{ MHz}\) PXI clock. Allow the physical plant state \(\mathbf{x}(t)\) to stabilize in the nominal operating envelope for \(t_{\text{settle}} = 2.000\text{ s}\). If baseline tracking error \(\|e_{\text{track}}\| > \epsilon_{\text{nom}}\), assert ERR_BENCH_INSTABILITY, set the verdict to INVALID, and abort.

  3. Fault injection trigger (stage 3). At monotonic test epoch \(t_{\text{inject}}\), the hardware test orchestrator asserts the trigger line to the inline injection rig:

    • Proposer stall (F1): The orchestrator kills the chunk-policy task one tick after a lease renewal.
    • Sensor latency or bias (F2): An FPGA interceptor latches a navigation-camera frame or holds a stale encoder payload while preserving its valid hardware timestamp.
    • Frame loss (F3): A fieldbus disturbance node drops or corrupts EtherCAT frames at a drive’s slave port.
    • Control-rail droop (F4a): A programmable electronic load draws the F4a transient of Representative hardware and cyber-physical fault classes from the shared control rail at its battery-low point for \(\Delta t_{\text{duration}} = 5.0\text{ ms}\), while an independent digitizer records the permission rail and the permission path’s heartbeat.
    • Permission-rail feed loss (F4b): A solid-state switch opens the permission rail’s feed as the resident stop from the inspected-floor ceiling begins.
    • Actuator mechanical stall: A four-quadrant dynamometer applies step counter-torque \(\tau_{\text{stall}} = 3.5 \times \tau_{\text{rated}}\).

    Record the injection timestamp \(t_{\text{fault\_start}} \leftarrow t_{\text{now}}\) in nanoseconds on the reference clock.

  4. Enforcer response and takeover audit (stage 4). Monitor the target MCU’s safety enforcer pins, CAN bus telemetry, and gate-driver PWM lines via an isolated logic analyzer:

    • Detect assertion of the non-maskable interrupt (NMI) or diagnostic flag: \(t_{\text{det}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{det}} = t_{\text{det}} - t_{\text{fault\_start}}\).
    • Detect hardware multiplexer preemption of the motor driver: \(t_{\text{takeover}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{takeover}} = t_{\text{takeover}} - t_{\text{fault\_start}}\).
    • Detect the physical plant’s transition to its safe bounded regime: \(t_{\text{bounded}} \leftarrow t_{\text{now}} \implies \Delta t_{\text{bounded}} = t_{\text{bounded}} - t_{\text{fault\_start}}\).

    If the external containment rig trips on a structural envelope breach, the hardware crowbar cuts actuator power; assert ERR_PHYSICAL_BREACH and carry the trial to stage 5, where the violated containment predicate returns FAIL.

  5. Robustness evaluation and ledger serialization (stage 5). Ingest the truth trajectory \(\mathbf{x}_{\text{obs}}(t)\) from independent instrumentation over the declared trial window. If required truth frames are missing, set the verdict to UNOBSERVABLE and retain the partial trace. For an observable trial, compute each precommitted predicate’s signed margin in its own unit, as the STL robustness of Signal Temporal Logic and Continuous Robustness defines it. Return PASS only when every required margin is nonnegative and both measured fault-to-detection and fault-to-drive-takeover times satisfy their declared bounds; otherwise return FAIL. A dimensionless aggregate may be computed only after predeclared per-predicate normalization. Link the fixed fault-record header to the variable-length evidence bundle by digest, sign the header under the specified custody scheme, and retain both.

Release manifest

The release manifest of The Release Manifest is a signed offline artifact, not a mailbox record, so it has a canonical encoding in place of fixed offsets. Fields appear in the order that table 15 lists, each variable-length field carries a length prefix, and the adjudicator’s Ed25519 signature covers the encoding of every preceding field. Every digest is SHA-256. The expiry is the one calendar time in the record chain, and it is checked against a tamper-resistant real-time clock rather than the safety microcontroller’s monotonic clock.

Table 15: Release manifest: Canonical field order of the signed release artifact. A new signed version can supersede a manifest only after the current physical conditions are checked, and the hardware root anchors keys rather than storing mutable digests.
Field Encoding Binds Check before permission
claim_manifest_id uint8_t[16] UUID Top-level safety claim Linked to the root node of the signed argument graph.
argument_digest uint8_t[32] Complete claim–argument–evidence graph Matches the graph the adjudicator reviewed.
policy_weights_digest uint8_t[32] Learned model weights Mismatch refuses release.
enforcer_bitstream_digest uint8_t[32] Enforcer logic image Mismatch refuses release.
rtos_kernel_digest uint8_t[32] Real-time kernel image and drivers Verified by the hardware root of trust at power-on.
calib_trace_pointers length-prefixed list of signed evidence references Calibration certificates Missing or stale evidence refuses unless a separately signed restricted case covers it.
fault_ledger_root uint8_t[32] Signed fault-record headers (section 14.8) Missing, unauthenticated, or mismatched ledger refuses.
authority_record_digest uint8_t[32] Static authority manifest and the forensic log’s initial chain anchor (section 14.6) Mismatch refuses release.
placement_record_digest uint8_t[32] Placement record (section 14.5) Mismatch refuses release.
evaluation_record_digest uint8_t[32] Evaluation record Mismatch refuses release.
verdict_classification uint8_t enumeration UNCOND, COND, or REFUSE Selects the permitted operating envelope.
standing_conditions length-prefixed array of (premise, check rate, trip) Physical premises checked in operation Checked on every permission tick; an unknown premise takes the assessed stop.
telemetry_drift_budget length-prefixed task-specific limits and triggers Tracking and timing drift A bound violation revokes; a trend prompts inspection.
verdict_expiry UTC calendar time (ISO 8601) Validity period of the verdict A real-time clock reading past the expiry voids the permit.
lifecycle_budget uint64_t[2] (hours, cycles) Wear allowance An exceeded budget or an invalid counter refuses motion.
adjudicator_signature key identifier plus uint8_t[64] Ed25519 signature The whole manifest Verifies under an authorized, unrevoked adjudicator key.

Release-gate protocol

Used in The Release Manifest. Before the motor power stages are energized, the release gate attests the silicon state, verifies the manifest of table 15 and its image digests, and audits the standing conditions, in the order below.

Substrate and signature. The hardware root of trust anchors an authorized, revocable adjudicator verification-key chain. Protected storage holds the signed manifest and signed evidence graph. The signature covers every versioned manifest field, including the identity of the signing key, and the verifier checks the key chain and its revocation state before trusting the signature. The individually signed fault records of section 14.8 enter the manifest as one digest over the complete ledger in its declared order. The verifier checks each record signature, the ordering, completeness, and that root against the reviewed evidence index. A digest alone establishes neither record validity nor test adequacy.

Fail-closed authorization. Begin with Permit_gate = 0 and the physical plant in its assessed nonoperating state. All returned decisions use the signed enum UNCOND, COND, or REFUSE; an implementation may log a reason code separately.

  1. Verify the adjudicator key chain and revocation status, the manifest signature, expiry, signed operating-hour and cycle budgets, and every active image digest. Any invalid, missing, or expired item returns REFUSE. A different software bank requires its own signed case and a new check of physical conditions.
  2. Authenticate the complete fault ledger and calibration references against the signed graph. A missing ledger, bad record signature, or root mismatch returns REFUSE, even if the manifest says UNCOND. Stale calibration also returns REFUSE under the full case. It can support COND only when a separately signed restricted case explicitly covers that calibration state and all of its evidence and limits still validate.
  3. Check the state-dependent standing conditions, including brake test, separation, timebase, and monitoring health. KNOWN_FALSE and UNKNOWN both return REFUSE while retaining distinct logged causes. Apply the approved state-matched stop or hold of The Fallback Ladder.
  4. If every check passes and the signed verdict is UNCOND, load the signed full envelope and return UNCOND. If every restricted condition passes under a signed COND case, load its signed reduced envelope and return COND. A signed REFUSE case or any other state returns REFUSE. In both operating modes the learned policy only proposes actions; the independent enforcer checks each candidate and controls actuator permission. Force trip thresholds must include measured detection and response headroom below the contact criterion.

Residual-claims register

The residual-claims register of A Residual-Claims Register tracks every physical premise the release rests on but does not observe, so that an open claim is carried across software deployments and hardware revisions. Like the release manifest, it is an offline artifact whose mandatory fields (table 16) follow a canonical order rather than fixed offsets.

Table 16: Epistemic residual-claims register: Canonical field order of the register. The header binds it to one platform, build, and operating window; each entry must carry its claim, the missing observable, the hazard and its time to harm, the containment that holds meanwhile, and the predeclared test that would close it.
Manifest Category Field Physical Unit Invariant & Operational Contract
Manifest Header system_identifier — Unique embodied platform ID (e.g., WMM-AISLE-01)
Manifest Header hardware_build_rev — Target silicon and chassis revision (HW-REV-3.2)
Manifest Header software_digest — Digest of the released binary
Manifest Header validity_limit_hours hours Configured operating window before review
Residual Claims entry_id — Unique claim tag (e.g., CLAIM-FRIC-001)
Residual Claims target_safety_claim — Explicit safety invariant (\(d_{\text{stop}} \le D_{\text{clear}}\))
Residual Claims missing_observable SI units Unmeasured physical state (e.g., surface friction \(\mu\))
Physical Hazard governing_law — Newton-Euler, Navier-Stokes, Joule heating
Physical Hazard time_to_harm seconds Time from unmodeled transition to irreversible yield
Operational Containment containment_type — FIRMWARE_PARAM_CLAMP, PASSIVE_MECHANICAL, or OPERATING_RESTRICTION; validate the selected limit
Operational Containment authority_limit \(\text{m/s}, \text{N}\) Hard numeric setpoint ceiling (\(v_{\max}, F_{\max}\))
Operational Containment kinetic_energy_ceiling \(\text{J}\) Maximum allowable kinetic energy under fault (\(E_k \le E_{\max}\))
Assurance & Inspection proof_test_interval hours Scheduled test interval; evidence between tests still depends on the operating restriction
Predeclared Closure closure_modality — Transducer technology or formal method required
Predeclared Closure sample_trials count Case-specific independent exposure, sized by the zero-failure rule of Zero-Failure Testing and the Exposure Wall for the declared miss-rate bound
Predeclared Closure confidence_level — Declared one-sided confidence level of that bound

Further Reading

For a deeper foundational understanding of embedded architectures, real-time operating systems, and power electronics, consult the following authoritative references:

  • Computer Organization and Design: The Hardware/Software Interface (Hennessy and Patterson 2019) provides the definitive treatment of processor architectures, cache hierarchies, and memory subsystem trade-offs.
  • Scheduling Algorithms for Multiprogramming in a Hard-Real-Time Environment (Liu and Layland 1973) establishes the mathematical foundations of rate-monotonic scheduling and real-time task schedulability.
  • Modern Operating Systems by Andrew S. Tanenbaum and Herbert Bos provides comprehensive coverage of inter-process communication, lock-free synchronization, and memory management.
  • Real-Time Systems by Jane W. S. Liu delivers the authoritative mathematical formulation of real-time scheduling algorithms, priority inversion, and response time analysis.
Hennessy, John L., and David A. Patterson. 2019. Computer Architecture: A Quantitative Approach. 6th ed. Morgan Kaufmann.
Liu, C. L., and James W. Layland. 1973. “Scheduling Algorithms for Multiprogramming in a Hard-Real-Time Environment.” Journal of the ACM 20 (1): 46–61.
Back to top

Footnotes

  1. Jeff Dean: Google Senior Fellow and systems architect. His latency numbers originally presented with Peter Norvig around 2010 established the canonical latency hierarchy across storage, memory, and network tiers (Scott 2012). Physical AI extends this hierarchy down into electromechanical actuators, stopping kinematics, and thermal time constants.↩︎

  2. Hardware Watchdog Down-Counters: A configured watchdog expires when its expected service does not occur. Its oscillator, timeout, output wiring, and plant response differ by device. Feeding it merely from an unrelated interrupt does not prove that the monitored control computation progressed; a firmware-fed reset also need not signal a drive. See the Linux watchdog API for reset behavior and The Fallback Ladder for stop selection.↩︎

  3. Inverter Dead-Time Insertion: Timer dead time is selected from switch and driver timing over temperature and load, then verified with the actual gate waveforms. An overlap can create a damaging bus short; a numeric current or fuse outcome requires the circuit impedance and protection response.↩︎

  4. Sakurai-Newton Delay Modeling: The alpha-power law models voltage-dependent gate delay; its parameters are technology dependent. The model predicts reduced setup slack during droop, while a missed deadline, register error, or reset must be established against measured path slack and device thresholds.↩︎

  5. DRAM Bank-Conflict Penalties: A row change in one bank can add precharge and activate time. Video DMA can also queue transactions ahead of a safety read. The resulting delay must be bounded for the specific address mapping, arbitration policy, and workload; a fixed penalty per request is generally unjustified.↩︎

  6. Hardware Timestamping: A compatible PHY or MAC timestamps frames closer to the wire than a software interrupt handler. Hardware timestamping removes one source of dispatch variation, while path asymmetry and clock conversion remain. Timestamp uncertainty belongs in the physical belief record and permission budget.↩︎

  7. Hardware Memory Barriers: Barriers order accesses only within their specified shareability and memory-attribute contract. On a noncoherent route, cache clean/invalidate operations or coherent mappings are also required. Arm’s memory-ordering guide distinguishes ordering from coherence.↩︎

  8. Stator Thermal Time Constants: Resistive Joule heating elevates motor phase winding temperatures during continuous high-torque maneuvers. Because copper electrical resistivity increases linearly with temperature, hot windings exhibit higher resistance, reducing torque output under terminal voltage saturation. Exceeding winding insulation temperature limits breaks down dielectric coatings, causing inter-turn short circuits and irreversible actuator destruction.↩︎

  9. Dynamic Braking Choppers: A qualified chopper can dissipate returned energy when the battery is unavailable as a sink. Its threshold, switch and resistor ratings, pulse duration, and thermal recovery must be tested. Regeneration and chopper operation are not inherent to every emergency stop; safe torque off can instead leave a motor coasting.↩︎

  10. Pinhole Intrinsic Projection: The pinhole model projects 3D points onto a 2D sensor through calibrated intrinsics. Under fixed pixel noise, the lateral variance after depth unprojection grows with squared distance; depth-error and calibration terms follow their own models. Uncalibrated intrinsics can bias a clearance estimate and must be included in its error envelope.↩︎

Scott, Colin. 2012. “Numbers Every Programmer Should Know by Year.”