# Modelled capabilities — rationale
<!-- Generated by `cargo run --bin gen_validation_artifacts` from src/verification.rs; pinned by tests/verification_artifacts_doc_sync.rs. Do not edit by hand. -->
These capabilities are implemented from published or first-principles physics with tests, but are **honestly labelled MODELLED** — not checked against an independent external oracle to a stated tolerance. The matrix invariant tests enforce that only `ExternalDataset`-backed rows may be VALIDATED, so nothing here can be silently promoted. Each row states why it stays Modelled.
| Requirement | Capability | Oracle kind | Why it stays Modelled | Module | Tests |
|---|---|---|---|---|---|
| GNSS-denied clock holdover | Closed-form coast-error growth + holdover-to-threshold; quantum-clock classes | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Multi-step clock_state covariance recursion (same-codebase cross-check); the underlying coast-variance & holdover-inversion kernel is externally validated vs scipy (see 'Clock-holdover coast-variance & threshold inversion'). The per-class red-noise-floor holdover figures stay MODELLED | holdover | holdover::tests (vs multi-step Kalman covariance recursion; white-FM exact; round-trip); coast-variance kernel externally validated in tests/gnss_denied_clock_holdover_reference.rs (vs scipy Van-Loan/brentq) |
| Onboard clock state estimation | 3-state (phase/freq/drift) van-Loan Kalman clock, Joseph-stabilised | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — filterpy 1.4.5 KalmanFilter (R. Labbe, MIT), with F via scipy.linalg.expm and Q via the Van-Loan 1978 block-matrix — an independent reference implementation reproducing kshana's full filter trajectory. Cross-implementation consistency: the clock physics / Allan calibration are not externally validated, so this stays MODELLED | clock_state | clock_state::tests (analytic van-Loan Q; NEES; PSD positivity); tests/clock_state_reference.rs (full predict+update trajectory — state x and 3×3 covariance P over 1925 steps / 4 parameter sets vs filterpy 1.4.5; worst |relΔ| 2.8e-14) |
| Time-transfer error budgeting | Two-way/TWSTFT (Sagnac), GNSS common-view, PPP; link-jitter→range | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — Sagnac magnitude checked against an authoritative PUBLISHED VALUE — N. Ashby, 'Relativity in the GPS', Living Reviews in Relativity 6:1 (2003), Eq. 1.29: an eastward equatorial circumnavigation accrues 207.4 ns (2ωA_E/c²); kshana reproduces 207.386 ns. Independently corroborated by RTKLIB 2.4.3 geodist() (Takasu, BSD-2-Clause), which carries the same 2Aω/c² geometry. The composite BIPM TWSTFT transponder/common-view/PPP budget has no external oracle, so the capability stays Modelled | timetransfer, timetransfer_adv | timetransfer::tests (reciprocal cancellation; two-form Sagnac identity); tests/time_transfer_error_budgeting_reference.rs (equatorial-circumnavigation Sagnac = 207.386 ns vs the published Ashby 207.4 ns to <0.05 ns; plus Sagnac/geodist geometry cross-checked against RTKLIB 2.4.3 geodist() compiled from C source) |
| Nav-signal modulation & code-tracking analysis | BPSK-R/BOC PSD, spectral-separation κ, Gabor bandwidth, DLL jitter, multipath | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — GPS C/A Gold cross/auto-correlation matched EXACTLY (integer ±65/−1/63) against independent IS-GPS-200 code generation; BPSK-R(1)/BOC(1,1) PSD shape vs an independent scipy periodogram. The modulation/SSC/DLL closed forms (Betz 2001 / Kaplan & Hegarty) remain analytic, so the row stays MODELLED — but the code-correlation sub-claim is externally matched | navsignal | navsignal::tests (BPSK self-SSC = 2/3R_c; unit-area PSD; DLL); tests/nav_signal_modulation_code_tracking_reference.rs (GPS C/A Gold cross/auto-correlation exact-integer match vs independent IS-GPS-200 code generation; BPSK-R(1)/sine-BOC(1,1) PSD vs an independent scipy periodogram) |
| Quantum inertial sensor performance | Cold-atom interferometer accelerometer from first principles (k_eff·T², QPN) | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — Published CAI primary-paper numeric vectors (Cheinet 2008 transfer function; Peters/Freier sensitivity): k_eff·T² matched exactly, shot-noise ASD a one-sided floor within ~2× of each published instrument (real devices carry technical noise above the quantum floor). A bracket, not parity | inertial::quantum_imu | quantum_imu::tests (k_eff; Mach-Zehnder T²; Freier-2016 floor bracket); tests/quantum_inertial_sensor_reference.rs (transfer function |H(ω)|, k_eff·T² and shot-noise ASD vs published Cheinet 2008 / Peters / Freier numeric vectors) |
| Quantum inertial sensor fringe-ambiguity / dynamic range | Mach–Zehnder fringe-ambiguity dynamic range: the 2π-periodic fringe readout sets a maximum unambiguous specific force a_max=π/(k_eff·T²), and the unambiguous range in resolution cells a_max/σ_a=π/σ_Φ is independent of the optical scale factor — the T² sensitivity gain costs unambiguous range in exact lockstep (interrogation time trades resolution for range, leaving the cell count fixed by the readout phase noise) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Self-consistency of the interferometer fringe model: the half-fringe edge, the 2π-periodic aliasing structure, and the scale-factor cancellation in the range/resolution ratio are closed-form algebraic identities checked against the engine's own Mach–Zehnder phase and sensitivity functions — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED ideal three-pulse fringe-ambiguity; no wavefront-aberration or contrast-loss bounds on the unambiguous range | inertial::quantum_imu | quantum_imu::tests (a_max sits at the ±π half-fringe edge with the 1/T² range scaling; wrapped-phase recovery is exact inside [−a_max,a_max] and aliases by exactly 2·a_max outside it; the unambiguous dynamic range a_max/σ_a=π/σ_Φ is identical across two very different wavelength/T scale factors; the CaiAccelerometer methods match the free functions) |
| Quantum inertial dead-reckoning resilience | Composed bias + scale-factor + VRW + stability-decay position budget over holdover | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Independent numpy Monte-Carlo SDE integration of double-integrated white-acceleration noise (validates the analytic VRW variance by a genuinely independent algorithm) + a Groves 2013 published-value anchor for the bias/scale-factor terms; the CAI device numbers quantify partner hardware and stay MODELLED | inertial::quantum_imu (QuantumNavBudget) | budget_tests (bias vs AccelModel integrator; VRW vs analytic integral); tests/quantum_inertial_dead_reckoning_reference.rs (VRW vs an independent numpy Monte-Carlo double-integration of white-acceleration noise, worst dev 0.42% within ±3% over 6 coast times; bias/scale-factor vs a Groves 2013 closed-form value; holdover round-trips) |
| GNSS/INS sensor fusion | 15-state error-state EKF (loosely & tightly coupled), tightly-coupled pseudorange/Doppler UKF, and a coupled clock+position filter | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — filterpy 1.4.5 (R. Labbe, MIT) on numpy/scipy. The three LINEAR filters reach the uniquely-defined Bayesian posterior independently (Joseph vs standard form, machine precision) — a genuine library-vs-library check; the tightly-coupled UKF shares the same sigma-point recursion, so it is consistency-only. Stays MODELLED (the trajectory truth / sensor calibration are not externally validated) | fusion (gnss_ins_ekf, tightly_coupled, ukf, coupled) | fusion::tests (UKF==linear-KF identity; outage coast; NEES); tests/gnss_ins_sensor_fusion_reference.rs (50 cases vs filterpy 1.4.5: linear EKF loose/tight + coupled-PNT posteriors to ≤2.4e-12; UKF 40-epoch run worst |Δx| 1.9e-7 / |ΔP| 9.5e-6) |
| GNSS-denied jamming resilience | Geometry J/S link budget, anti-jam C/N₀, per-satellite loss-of-lock | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Anti-jam C/N₀ link-budget equation cross-checked against an independent numpy re-derivation (shares the same closed form → InternalConsistency) plus a real-JammerTest-2024 C/N₀ degradation characterisation | jamming | jamming::tests (PSD-derived Q cross-check; despreading); tests/gnss_denied_jamming_resilience_reference.rs (FSPL/J-S/effective-C-N₀ vs an independent numpy re-derivation of the Kaplan & Hegarty §9.4 link budget; real JammerTest C/N₀ falls monotonically through the 25 dB-Hz threshold) |
| Spoofing detection | Clock-aided χ², RAIM, AGC, SQM fused per-epoch security FoM | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — TEXBAT scenario parameters (Humphreys 2012) — characterisation, not pinned vectors | spoof, spoof_detect, spoof_monitors | tests/spoof_texbat_validation.rs (TEXBAT parameter characterisation) |
| Timing Protection Level under spoofing | Closed-form bound on worst-case undetected time error = monitor floor + oscillator coast-σ over CUSUM detection latency, reported as a red-noise-floor band | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Composes Validated primitives (allan/holdover van-Loan, security floor); calibrated on JammerTest 2024 scenario 2.1.1 (~1.01 ms real served-time pull vs ≤51 ns claimed). Bridge over Validated parts — not itself an external validation. | tpl | tpl::tests (closed-form oracles + CUSUM); examples/tpl_jammertest.rs (JammerTest 2024 real-spoof calibration) |
| Alternative / complementary PNT | Gravity-map matching, terrain-referenced (TERCOM/SITAN), magnetic anomaly | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — IGRF-14 coefficients; first-principles matched-filter CRLB | altpnt, mapmatch, gravimeter, igrf | tests/* (map-matching CRLB; IGRF-14 field) |
| Reproducibility & software assurance | Deterministic, scenario-hashed, SBOM + cross-platform golden gates | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — SBOM conformance to the official CycloneDX 1.5 JSON Schema (+ valid SPDX identifiers) — an external published standard, zero validation errors over the full dependency graph; the FoM-determinism / byte-reproducibility part remains a pinned self-consistency check, so the row stays MODELLED | report, scenario; CI (golden/determinism/SBOM) | tests/golden.rs, tests/determinism.rs, tests/cross_platform_golden.rs; tests/reproducibility_software_assurance_reference.rs (the generated SBOM validates with zero errors against the official CycloneDX 1.5 JSON Schema over the full ~59-component locked graph) |
| AI/ML RF-impairment detection evaluation (13494) | Labelled synthetic impairment corpus + detector-agnostic ROC/AUC/confusion/Pfa-Pmd harness; leakage guard, stratified split, distribution-shift (in- vs out-of-regime) optimism report. Runnable from the CLI/bindings as the `impairment-eval` scenario kind (scenarios/impairment-eval.toml) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form AUC bounds (Mann–Whitney) + a perfect-oracle detector; corpus is SYNTHETIC (parameter-grounded, not field/IQ) | impairment_eval | impairment_eval::tests (AUC perfect=1/identical=0.5/tie=0.125, ROC monotone, fused>0.8, per-class layer separation, leakage guard, reproducible corpus, distribution-shift flags optimism); dominance_demonstrators (reachable + reproducible + MODELLED-not-VALIDATED + optimism-gap self-consistent) |
| AI/ML RF-impairment optimism-gap study & ID-only gap predictor | Controlled synthetic study of the in-distribution→out-of-distribution AUC optimism gap across published-method and learned (logistic-regression / one-hidden-layer MLP) detectors: per-class scaling-law trends (Spearman ρ + slope on 1−severity) and an ID-only ridge predictor that estimates the gap from in-distribution diagnostics alone, scored leave-one-detector-out and leave-one-class-out. Reproducible via `cargo run --release --example optimism_study` | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Hand-derived statistics vs closed forms (binormal AUC Φ(d'/√2), DeLong variance, tied-rank Spearman, exact OLS recovery) + leave-one-out CV against the predict-the-mean baseline. Corpus is SYNTHETIC (parameter-grounded, never field/IQ) and the optimism gap is a synthetic→synthetic severity shift, NOT a sim-to-field result | impairment_study, impairment_ml, eval_stats | impairment_study::tests (per-class oracle AUC≈1, learned optimism gap>0, grid shape + bootstrap CI brackets the mean + positive scaling trend, ID features finite, gap predictor beats predict-the-mean under BOTH leave-one-detector-out and leave-one-class-out CV + deterministic); impairment_ml::tests (logreg separates + deterministic + loss↓, MLP solves XOR a linear model cannot + seeded); eval_stats::tests (bootstrap/DeLong/Spearman/ridge vs closed forms) |
| Quantum-vs-classical PNT trade & GNSS-denied resilience (13503) | Measured-ADEV ingestion (NNLS), trade table (timing/inertial holdover + benefit), resilience-vs-time envelope; floor caveat carried on the artifact. Runnable from the CLI/bindings as the `quantum-trade` scenario kind (scenarios/quantum-trade.toml) | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — The measured-ADEV→PSD fit (NNLS) kernel is matched to scipy.optimize.nnls (tests/scipy_reference.rs / tests/quantum_vs_classical_pnt_trade_reference.rs) — an independent external kernel; but the trade NUMBERS quantify (never validate) a partner clock/CAI, so the trade itself stays MODELLED, no validation halo | quantum_trade | quantum_trade::tests (ADEV round-trip recovery, NNLS non-negativity, floor-caveat present/absent, benefit>1, monotone envelope + alt-PNT bound); dominance_demonstrators (measured-ADEV is data-driven not floor-assumed, assumed-class flags floor + caveat, malformed curve rejected, MODELLED-not-VALIDATED) |
| Space-weather environment & activity-driven thermospheric density | Solar/geomagnetic indices (definitional Kp↔ap table), Jacchia-1971 exospheric temperature, and a calibrated first-order activity density correction over the static USSA76 atmosphere (the solar-cycle density swing the static model omits). Runnable from the CLI/bindings as the `space-weather` scenario kind (scenarios/space-weather.toml) | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — Definitional Kp↔ap table + Jacchia-1971 exospheric-temperature closed form (matched to <1 K vs the published anchors, tests/space_weather_reference.rs); the density correction is characterised against pymsis NRLMSISE-00 (an independent NRL model) — directionally correct and within a factor of 3 of the 400 km solar-cycle swing, but diverging up to ~8× aloft, so the density layer is a CALIBRATED first-order model and stays MODELLED | space_weather | space_weather::tests (Kp↔ap exact at grid points + round-trip + monotone, daily-Ap mean, exospheric-T vs published solar-min/mean/max + storm increment anchors, density unity-at-reference, solar-cycle swing in the observed 5–10× band, scenario reproducible + MODELLED-not-VALIDATED + out-of-range rejection); dominance_demonstrators (reachable + reproducible + physical T + MODELLED-not-VALIDATED) |
| Launch-window & ascent geometry (mission analysis) | Two-body launch azimuth(s) (sin Az = cos i / cos lat), minimum reachable inclination, circular velocity, Earth-rotation eastward bonus, dogleg plane-change Δv and daily opportunities. Runnable from the CLI/bindings as the `launch-window` scenario kind (scenarios/launch-window.toml) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form spherical-trig launch geometry vs published worked-example anchors (Vallado, Fundamentals of Astrodynamics 4th ed., Algorithm 37 launch-azimuth + Ch.6 plane-change; tests/launch_window_ascent_geometry_reference.rs). These re-use the same closed form kshana implements (a published-value parity / transcription check, InternalConsistency); MODELLED two-body, no rotating-Earth velocity-triangle / ascent / drag-loss model | launch | launch::tests (due-east launch reaches i=latitude, KSC→ISS = textbook 45°, polar = N/S, i<lat unreachable, 465 m/s equatorial bonus, plane-change 10° ≈ 1.34 km/s + 180° = 2v, daily-opportunity counts, scenario reproducible/MODELLED + dogleg path); dominance_demonstrators (reachable + reproducible + KSC→ISS 45° + MODELLED-not-VALIDATED) |
| Ballistic re-entry corridor (Allen–Eggers) | Peak deceleration (ballistic-coefficient-independent), velocity + altitude at peak-g, and peak-heating velocity for an exponential-atmosphere ballistic entry. Runnable from the CLI/bindings as the `reentry` scenario kind (scenarios/reentry.toml) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form Allen–Eggers analytic entry, additionally cross-checked vs a scipy 1.18 solve_ivp (DOP853) numerical integration of the SAME drag-only entry ODE (tests/ballistic_re_entry_corridor_reference.rs, 36 cases, worst a_max rel 2.9e-9) — a numeric-integral-vs-own-analytic-form check, so still InternalConsistency, NOT an external validation. MODELLED ballistic (no lift), no aerothermal/TPS — heating output is a velocity, not a heat-flux | reentry | reentry::tests (peak-g independent of ballistic coefficient + physical g-band, grows with steeper γ / faster entry, peak-g velocity = V_e·e^(−1/2) and peak-heating = V_e·e^(−1/6) faster, peak-g altitude physical + deeper for higher B, scenario reproducible/MODELLED + degenerate-geometry rejected); dominance_demonstrators (reachable + reproducible + V_e·e^(−1/2) fraction + MODELLED-not-VALIDATED) |
| EO payload footprint & coverage geometry | SMAD space-triangle geometry: Earth angular radius, swath width, nadir GSD, maximum off-nadir access, circular period + equatorial ground-track spacing with a contiguous-coverage flag. Runnable from the CLI/bindings as the `eo-coverage` scenario kind (scenarios/eo-coverage.toml) | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — Closed-form SMAD/Wertz space-triangle relations cross-checked against Skyfield/SGP4 + a WGS-84 ray-ellipsoid geodesic (tests/eo_payload_coverage_reference.rs): equatorial node spacing within 1% of an SGP4 propagation and the limb angle within 0.3° of the ellipsoid. MODELLED spherical-Earth geometry (the ellipsoid/SGP4 envelope difference is the modelling gap), no radiometry/MTF/atmosphere/jitter/glint | eo_payload | eo_payload::tests (angular radius 64° at 700 km + shrinks with altitude, nadir→zenith/zero-range, horizon→ε=0/max central angle, past-horizon errors, swath grows with FOV / GSD with altitude, ~2750 km node spacing, scenario reproducible/MODELLED + bad-input rejection); dominance_demonstrators (reachable + reproducible + 64° angular radius + MODELLED-not-VALIDATED) |
| 3-DOF attitude & pointing error budget (AOCS) | Gravity-gradient worst-case disturbance torque ((3/2)(μ/R³)ΔI) + RSS pointing-error budget over named 1σ contributors with the dominant term. Runnable from the CLI/bindings as the `attitude-budget` scenario kind (scenarios/attitude-budget.toml) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form gravity-gradient torque and quadrature RSS, cross-checked against a hand-coded full-tensor torque numerically maximised over attitude (Hipparchus 3.1 linalg) which blindly rediscovers the 45° peak — a strong self-consistency check, but the GG physics is shared/hand-coded so it stays InternalConsistency, not external. MODELLED scalar AOCS budget — no control-loop/6-DoF/flexible-mode simulation | attitude_budget | attitude_budget::tests (GG torque vanishes for a symmetric body, grows lower-down, linear in ΔI, RSS quadrature sum, variance-fractions-sum-to-1); tests/attitude_gg_torque_reference.rs (20 cases vs an independent full-tensor GG torque T=(3μ/R³)(n̂×(I·n̂)) numerically maximised over attitude with Hipparchus 3.1 linalg; worst rel 6e-15, + Wertz/Sidi published O(1e-6) s⁻² band) |
| Frugal cost-per-coverage / ROI framing | Cost-per-percent-coverage + coverage-per-euro ROI over the constellation sizing engine; per-satellite cost is a caller-sourced low/nominal/high bracket (no fabricated prices) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form cost arithmetic vs hand-derived values; an economic FRAMING of a modelled coverage figure, not a quote or validated cost model | frugal (over walker) | frugal::tests (hand-derived cost-per-coverage 48/96=0.5, ROI ratio 2.667, bracket-ordering + zero-coverage guards) |
| Detection-miss integrity impact (context-aware HPL/VPL vs alert limit) | Maps an undetected spoof/jam bias to effective error → Stanford region (available/unavailable/MI/HMI) against context-specific HAL/VAL (open-sky vs urban) | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Composes the externally-validated RAIM Stanford classification (raim::classify_stanford); the detection-miss→AL mapping itself is modelled, not a certified integrity allocation | integrity_impact (over raim) | integrity_impact::tests (same miss flips Available→MI→HMI as the context tightens; conservative-PL→Unavailable; per-axis HMI; input guards) |
| CAI cited error-model parameter sheet (13503) | Bracketed (best/nominal/conservative) cold-atom-interferometer performance — bias instability, velocity/angle random walk, scale-factor stability, interrogation-limited sample rate, fringe-ambiguity dynamic range — each citation-traceable; feeds QuantumNavBudget without modelling hardware | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Internal consistency: the cited VRW bracket cross-checked against CaiAccelerometer::accel_asd physics + raw dynamic range computed from the fringe-ambiguity limit; numbers are MODELLED literature-survey brackets (needs_source_confirmation), no device validated, no validation halo | inertial::cai_params (over inertial::quantum_imu) | inertial::cai_params::tests (physics VRW lands inside the cited VRW bracket at all 3 levels; raw fringe-ambiguity range computed from k_eff·T²; conservative budget drifts more than best; every bracket sourced + confirmation-flagged; bracket-ordering guards) |
| Timing-integrity conformance benchmark — Stanford integrity-diagram epoch classifier | TIB Stanford integrity-diagram epoch classification (nominal / unavailable / MI / HMI) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy re-implementation of the four-region rule (scripts/gen_tib_scorer_reference.py) on the identical sample set; method Cited from the Stanford–ESA integrity diagram (Tossaint et al., ION GNSS 2007) and RTCA DO-229 WAAS MOPS. NOT an ExternalDataset accuracy oracle — the benchmark is honesty-immune. | src/benchmark/stanford.rs | src/benchmark/stanford.rs::tests (four regions + inclusive boundaries + |error| + PL>AL unavailability); tests/tib_scorer_reference.rs (classification counts vs independent numpy on a fixed synthetic set) |
| Timing-integrity conformance benchmark — integrity-coverage scorer | TIB integrity-coverage scoring (HMI/MI/availability rates + overbound-coverage verdict) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy region re-count in tests/fixtures/tib/reference.json; scorer machinery cross-check only, no accuracy claim. | src/benchmark/coverage.rs | src/benchmark/coverage.rs::tests (clean/under-bounded/all-unavailable/empty); tests/tib_scorer_reference.rs (counts + rates + coverage_ok vs numpy to 1e-12) |
| Timing-integrity conformance benchmark — fault catalog (parametric generators) | TIB fault menu (domain-divergence, clock-slam, holdover-coast, static/incremental/symmetric/asymmetric delay, replay-within-freshness, path-selective, k-of-N quorum) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Representative parametric fault generators (Modelled); the undetectable set (symmetric delay, replay-within-freshness) is Cited from Mizrahi RFC 7384 and Narula & Humphreys (IEEE JSTSP 2018). No external oracle — a fault catalog makes no measured claim. | src/benchmark/faults.rs | src/benchmark/faults.rs::tests (offset profiles, monotone coast, undetectable-set flagging, max_offset consistency, exactly two undetectable classes) |
| Timing-integrity conformance benchmark — undetectable-absorption verdict | TIB undetectable-absorption verdict (symmetric/replay must be absorbed by the PL, never reported detected) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Property check that the Verdict enum structurally cannot report an undetectable fault as detected (Mizrahi RFC 7384); absorbed ⟺ PL ≥ offset. No accuracy oracle. | src/benchmark/scorecard.rs | src/benchmark/scorecard.rs::tests (reference PL absorbs; broken PL unabsorbed-never-detected; detectable coverage verdict; the honesty property that no coverage/detection verdict is reachable for an undetectable scenario) |
| Hybrid optical/RF report self-description | The hybrid-optical-rf report states the link configuration it actually ran at (carrier wavelength, transmit and receive aperture, range, pulse width, integration time, efficiencies and losses, defaults resolved) and carries a units block giving the unit and provenance class of every quantity a paper is likely to quote, including the handoff covariance traces in square metres | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — No external oracle, and none is possible: this is self-description, not a measurement. It is recorded because the absence of it was a defect -- P5 had to quote the carrier wavelength and transmit aperture from source defaults, and to infer that a bare `variance` was in square metres from an internal consistency check. The inference was correct, which is precisely why it mattered: nothing would have caught it being wrong | hybrid_integrity | hybrid_integrity::tests (the resolved configuration is echoed for defaults and for overrides, without round-tripping the wavelength through metres; every units entry carries both a unit and a provenance class; every field the units block names is actually emitted, so it cannot document a ghost) |
| Hybrid optical/RF link availability on the RF side | The hybrid-optical-rf report states an RF link availability, composed from quantities the engine already computes rather than from an imported climatology, and states the composition as a named rule: A_rf = I_closure * I_track, where I_closure is the closure verdict of the one-way CCSDS-401 / DSN-810-005 link budget (linkbudget::link_budget, Eb/N0 margin >= 0) at the scenario's own range and I_track is the tracking-loop verdict (jamming::lock_status) on the C/N0 that SAME budget returned. Each factor carries its input's provenance class through to the output, and the factors deliberately NOT in the product -- geometric visibility, interference denial, and an RF outage climatology -- are named with the reason rather than silently set to 1. The resolved RF leg is echoed as its own rf_link_configuration block, and the continuous figures beside the indicator (link margin, C/N0 margin, the closed-form closure and tracking ranges, and the range utilisation) are the range inversions of the same budget. The report states in full, on the block and in the units entry a reader lands on, that this figure is MARGIN/GEOMETRY-LIMITED and DETERMINISTIC while optical availability is WEATHER/CLIMATOLOGY-LIMITED and probabilistic, so the two can never be quoted as a comparable pair of percentages | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — No external oracle, and ExternalDataset is declined. The two inputs are an Eb/N0 margin and a C/N0 threshold crossing, both functions of a MODELLED EIRP, figure of merit and lumped loss allocation; there is no measured availability record for an Earth-Moon optical/RF hybrid service to check the composed figure against. The checks that exist are internal and are stated as such: the composition is recomputed from the report's own published margins rather than from the emitter's internals, and the closure range is verified by re-running the link equation AT it and requiring the margin to vanish -- an inversion round trip, not an independent implementation. The honest limit of the figure is recorded on the report itself: it is a deterministic 0/1 indicator, not a probability, because nothing in this engine measures an RF link-outage distribution at this band and geometry. That missing input is named in rf_availability.factors_not_included rather than invented, and supplying it is what a probabilistic RF availability would need | hybrid_integrity, linkbudget, jamming | hybrid_integrity::tests (the availability equals the product of the two indicators recomputed from the report's own margins, and those margins are themselves reassembled from the report's own EIRP, free-space loss, lumped loss, figure of merit, Boltzmann term, data rate and requirement to 1e-9 dB; the value is measured to be 0 or 1 while the optical availability at the same run is measured to be strictly between them; each factor row carries a provenance class from the closed field_schema vocabulary; the reported closure range re-run through the link budget returns a margin of 0 to 1e-9 dB and is measured to be independent of the range the run sat at across four decades, while the range utilisation moves by exactly the range ratio; a -40 dBW link reports availability 0, LOST, and a utilisation above 1 rather than a fraction; the superseded 'no RF-availability counterpart is computed by this engine' note is asserted gone and the replacement is asserted to name the new field; a malformed RF input is refused rather than clamped) |
| Like-for-like optical-versus-RF ranging comparison | The hybrid-optical-rf report emits the optical-versus-RF ranging ratio with the ONE configuration both legs were evaluated at carried in the same object: the same one-way path, the same range, and the same accumulation time. The optical leg is the engine's photon-limited ToA CRLB on the one-way photon count; the RF leg is the engine's DLL early-late thermal code-tracking jitter at the C/N0 the engine's own link budget returns for that same one-way range. The loop noise bandwidth is derived, not chosen: B_L = 1/(2*integration_s) puts the RF leg at exactly the optical accumulation time, and if a caller overrides it so the two averaging times disagree the ratio is REFUSED -- null, with the mismatch and both times named -- rather than quoted at two operating points. No ratio is formed against the scenario's CHOSEN parametric rf_position_sigma_m, and the refusal says why: that input carries no configuration at all. The released two-way optical headline and the exact factor bridging it to the one-way comparison leg are emitted beside the ratio, so the report cannot be read as carrying two disagreeing optical sigmas | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — No external oracle for the RATIO, and ExternalDataset is declined deliberately. The underlying RF chain does have one -- tests/validate_p5_rf_ranging_precision.rs checks linkbudget::link_budget and navsignal::dll_code_jitter_chips against an independent Python/NumPy fixture and against the hardcoded Kaplan & Hegarty worked value (2.814e-3 chip / 0.825 m at 45 dB-Hz) -- and the optical CRLB has its own closed-form row. Claiming either anchor for this row would be borrowed validation, which the matrix invariants exist to prevent: the quantity here is a RATIO at a configuration with a MODELLED EIRP, figure of merit, transmit power and aperture, and no measured optical-versus-RF ranging comparison at a common operating point exists to check it against. What is checked internally is the thing the ratio can actually get wrong: that the two legs sit at one operating point. That is measured by scaling the common accumulation time and requiring both legs to move by the same square-root law and the ratio to stay put, and it is enforced by refusing the ratio outright when the averaging times disagree. Both legs are thermal/shot-noise bounds and both exclude media delay, clock error and ambiguity, so the exclusion is identical on each side; the report says so rather than leaving it inferred | hybrid_integrity, optical_linkbudget, linkbudget, navsignal | hybrid_integrity::tests (the ratio equals the two emitted legs divided, to 1e-15 relative, and its reciprocal and decibel forms agree; each leg's range and time sigma are related by exactly c; the emitted common configuration is asserted equal to the scenario's own range and integration time and the RF leg's range is asserted equal to the optical leg's; the RF leg's C/N0 is bit-for-bit the availability block's, from one link budget, not a re-derivation; the LIKE-FOR-LIKE property is MEASURED rather than asserted -- quadrupling the common accumulation time halves the optical leg to 1e-12 and the RF leg to 1e-7 and leaves the ratio unmoved to 3.19e-9 relative, which a leg secretly averaging over something else could not do; an rf_dll_bandwidth_hz override that breaks the common averaging time makes the ratio null with a reason naming both times, while both legs are still emitted; a one-way run makes the comparison leg bit-for-bit the released headline with a penalty factor of exactly 1, and a two-way run reproduces the penalty 0.5/sqrt(return-path geometric loss) recomputed from the report's own geometric_loss_db to 1e-12) |
| Link-budget report self-description | The link-budget report states every absolute constant its own margin was computed from -- the carrier frequency the free-space loss used, the EIRP, the figure of merit, the lumped loss and the Boltzmann term -- plus the required G/T at which the margin is zero, the link constant (EIRP - losses - required Eb/N0) that is the only combination a published rate/gain table can ever fix, and, when a caller states a system noise temperature, the receive antenna gain that figure of merit implies | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — No external oracle: this is self-description over an equation already validated against a published design-control table (see the one-way link budget row). It is recorded because the absence of it was a measured defect -- reproducing the released d1_rate_gain_beamwidth.csv required back-solving one effective constant to 0.0034 dB from all thirty rows, and the engine now both names that combination and proves, by test, that no released table could ever have separated its three components | linkbudget | linkbudget::tests (across three bands, four decades of range and both closure verdicts, the margin and the free-space loss under it are recomputed from the report alone to better than 1e-9 dB; the required G/T assembled from the equation terms agrees with the same quantity reached as G/T minus margin, and re-running at it zeroes the margin; three budgets with wildly different EIRP, loss and threshold but an equal link constant give an identical requirement, while 1 dB on the constant moves it exactly 1 dB; the gain split is absent unless a noise temperature is stated and a non-positive one is refused; every field the units block names is actually emitted) |
| Per-clock-class lunar time crossover table | One lunar-time-budget run emits a clock-vs-frame crossover row per clock class against a single shared frame term, so the clock is the only variable in the comparison; each row carries the crossover reached two ways -- bisected from the general power-law time-error curve and inverted algebraically from the row's dominant noise type -- with the relative difference between them | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Two different in-codebase computations of the same quantity, not one restated: bisection on the IEEE-1139 power-law curve knows nothing about noise type, while the closed form inverts the dominant type algebraically, so a misclassified noise type or a bad bracket shows as a non-tiny relative difference. The four values also reproduce the paper's published table to half its last printed digit -- but that table was itself reconstructed from the same closed form, so it is a reproducibility check and not an external oracle, and the frame term it is measured against is a Modelled allocation | lunar_time_budget | lunar_time_budget::tests and lunar_time_budget_scenario::tests (all four classes present in one run and in a requested subset order; every row agrees with its own closed form to better than 1e-12 relative; scaling the frame error by k scales the crossover by k for a flicker-FM clock and by k^2 for a white-FM one, checked at k=2 and k=3, which separates the two noise classes; each row reproduces the single-clock crossover the budget already reported; every row recovers the one shared frame term; an unknown clock name is rejected) |
| Joint UT1 and polar-motion error over a common row set | One table reports the UT1 prediction error, the polar-motion pole error and their quadrature combination at the Moon over an IDENTICAL epoch set per horizon, emitting the epochs each component was measured at. Separately, the scenario names whichever EOP input is in force and decomposes its row census, and always emits the predicted-versus-final horizon table with an explicit statement of why it is empty when it is | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — An algebraic identity evaluated by a different expression than the one under test: the emitted combination is the root-mean-square of the per-epoch hypotenuse, and the check is the hypotenuse of the two components' own root-mean-squares. The residual path is cross-checked against a separate call into frame_eop, and the row census against the identity rows = finals + predictions. The residual MAGNITUDE is checked only against a plausibility band, never against an IERS-published prediction-accuracy figure -- reading a real product is provenance, not an oracle, which is why this stays Modelled | frame_eop | frame_eop::tests and realtime_frame_eop::tests (all three components carry equal, elementwise-identical, strictly ascending epoch sets over both real IERS extracts; the joint set collapses to the intersection when the two Bulletin B blocks genuinely disagree, and a horizon with no shared rows is omitted rather than zero-filled; the emptiness of the predicted-versus-final table is stated in the document rather than implied by a missing field; a real second vintage populates it, cross-checked row for row; a missing later vintage is an error, not a silent empty table) |
| Offline default Earth-orientation input is a real IERS product | The `realtime-frame-eop` runtime default is the library's own embedded copy of a verbatim IERS finals2000A extract (MJD 61173-61204) carrying BOTH row vintages the format defines -- 20 Bulletin B finals and 12 Bulletin A prediction-only rows -- so a bare run with no file argument and no network emits a populated per-horizon table and `predicted_rows.n = 12`, together with the operational-predictor comparison and the agreement against the product's own published prediction rows. The prior five-row final-only excerpt remains shipped, byte-pinned and exercised: on it `predicted_rows.n` is 0, which is the input file's property and not a parser outcome, and the emitted census names whichever input is in force and decomposes it as rows = final_rows + prediction_rows | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — The published IERS finals2000A series itself, used verbatim and byte-pinned: this row's claim is a claim about that external product -- how many rows of each Bulletin vintage the shipped extract carries, over which MJD span -- and the reference is the file's own fixed-column content, whose SHA-256 is recorded in tests/fixtures/agency/NOTICE.md and which is byte-identical to the copy the arXiv P4 artifact bundle publishes. ExternalDataset is nonetheless DECLINED and the status is Modelled, deliberately: the count is taken by this crate's own parser and checked by this crate's own parser over the same bytes, so the check shares its expression with the thing under test; the IERS publishes no companion table of per-vintage row counts for an arbitrary excerpt that could serve as an independent oracle; and the excerpt is a slice this repository cut, not a product IERS issued in that form. What the external data does buy is PROVENANCE -- the rows are real and unaltered -- which is not the same as an oracle, the same line already drawn on the joint-EOP and operational-predictor rows. REVISION (programme rule R4): moving the default off the five-row final-only excerpt moved ten cells of the released p4_frame_eop.csv -- eop_source, predicted_rows.n 0 -> 12, first_mjd and last_mjd from blank to 61193 / 61204, the measured pole floor 0.07693113803915594 -> 0.06776429738439221 mas with its two per-axis terms 0.05439852939188552 -> 0.04791659420284556 mas, the Earth-orientation term 14.016178596543083 -> 14.016014260081214 m, the total 20.097702765309116 -> 20.09758815707301 m and 67.03872038471734 -> 67.03833809279155 ns -- and the twenty-four populated Table 2 cells of tests/golden/realtime-frame-eop.csv. The other twelve cells of p4_frame_eop.csv, and both Table 1 rows of the golden CSV, are unchanged. Every moved cell is enumerated old-to-new in docs/revisions/G12-default-eop-cell-changes.md. The revised pole floor is the SAME quantity P4 already publishes in its polar-motion table (n = 20, 0.0678 mas): before this change the paper's budget took that floor from the five-row excerpt while its pole table took it from the 2026 extract, and the budget's value was 13.5 % the larger of the two. Every other figure P4 prints from this table -- 14.016 m, 14.403 m, 0.177 m, 20.098 m, 67.04 ns, 0.7170 ms, the 48.6 / 51.4 / 0.008 percent variance shares and the 20.3 / 21.6 / 50.0 percent halving sensitivities -- is unchanged at the precision printed; the two pole figures are the only printed numbers that move | realtime_frame_eop, eop | realtime_frame_eop::tests and tests/operational_eop_predictor_reference.rs (a bare default run asserted to report 32 rows / 20 finals / 12 predictions spanning MJD 61193-61204 against an INDEPENDENT count taken by eop::parse_all and eop::parse_all_predicted over the same bytes, with every horizon row required to be measured from real rows; the same scenario run on the final-only excerpt asserted to report zero prediction rows and rows == final_rows, with eop::parse_all_predicted independently confirming the file publishes none; both `tools/` runtime assets pinned byte-for-byte against their `tests/fixtures/` mirrors and asserted to be different products; the census prose asserted to name the input in force and asserted NOT to contain the superseded explanation; and the frozen pre-change capture of the old default still asserted field for field, with no tolerance, against a run on the input it was captured on -- the three source-identity strings that legitimately moved pinned individually old-to-new so the allowance cannot absorb a numeric change) |
| Capture footprint against altitude and beamwidth | Two-axis sweep of the pattern-weighted, altitude-limited surface capture footprint over transmitter altitude and dish diameter, emitted one row per operating point with the half-power beamwidth each diameter implies, and limb capture reported as a THRESHOLD -- per row the limb J/S, its margin and the transmit power that would close it; per grid the located crossings, or an explicit statement that the limb is not reached anywhere on the grid, with the shortfall | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Set inclusion: the jammer-to-signal ratio enters as a uniform decibel offset, so the captured set at a higher transmit power contains the set at a lower one and the fraction can only rise -- a property the Airy pattern does NOT give in beamwidth or altitude, where the captured region breaks into rings and the fraction is genuinely non-monotone. No published table gives the captured disk fraction of a lunar orbital transmitter against altitude and beamwidth, so there is nothing external to check these cells against; the pattern underneath is separately Validated against published Bessel values and keeps its own row | antenna | antenna::tests and attack_surface::tests (the grid is complete and every captured fraction lies in [0,1]; captured fraction is non-decreasing in transmit power at every node; it is NOT monotone in beamwidth or altitude, which is pinned by its own test so the sweep cannot later be smoothed; the baseline node reproduces the existing captured fraction bit-for-bit; the limb-only evaluation is bit-identical to the full sweep's last point; a located crossing sits on the threshold to 1e-9 dB and is straddled) |
| Lunar time-error budget reproducibility | The lunar-time-budget scenario publishes its array-valued outputs as a long-form (grid index, averaging time, term) table alongside the report, so the seven per-term x(tau) curves and the root-sum-square total are engine output rather than something a reader rebuilds from the method section | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Self-consistency only: the published total is checked against the root-sum-square of the terms in the same file, and the emitted curve reproduces the released p3_time_budget_curve.csv over all 57 points. Both checks share this engine's own term definitions, so neither is independent. The clock term rests on published clock specifications, but the link, frame, relativistic and ephemeris floor MAGNITUDES are documented budget allocations with no external oracle | lunar_time_budget_scenario | lunar_time_budget_scenario::tests (all 57 averaging times x 8 terms present, the grid index runs 0..=56 and carries 8 rows each; the `total` row equals the root-sum-square of the seven terms beside it at every tau; the table follows a requested grid rather than a hard-coded one; emitting it leaves the report JSON byte-identical) |
| Lunar geodetic VLBI | Near-field VLBI delay for an Earth baseline observing a lunar beacon + partials | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Plane-wave delta_dor (same-codebase) in the far-field limit; finite-difference partials | lunar_vlbi | lunar_vlbi::tests (far-field limit matches delta_dor; near-field correction; FD partials) |
| Earth-GNSS at lunar distance | Earth-GNSS reception at lunar distance: the weak-signal layer P7 Table 1 names and the engine had no model for. Per satellite and per epoch it computes the off-boresight angle against the transmitter nadir, whether the Earth occults the straight path, the slant range and its free-space loss, the transmit gain at that angle, the received power and the carrier-to-noise density; it then aggregates only the links clearing a tracking threshold, and sweeps a full constellation revolution so the answer is a DISTRIBUTION rather than one snapshot. Three facts drive the result and the report states each: the Earth subtends 13.90 deg from the constellation radius so the beam PEAK is geometrically unavailable to any lunar-bound ray; what remains is the main-lobe edge and the sidelobes, the regime LuGRE operated in at the Moon in 2025; and the L1 path loss is about 208 dB, some 25 dB more than a terrestrial user pays. MEASURED on the bundled 24-satellite GPS-class geometry over 64 epochs of one orbital period: SIGNAL availability 0.375 with a best link of 30.93 dB-Hz, and FIX availability 0.000 - at most two simultaneous trackable links, never the four a position needs. The separation of those two availabilities is the point, and the report refuses to let them be confused: Earth-GNSS at lunar distance is a TIMING-grade layer, not a position-grade one, and a layered-resilience prior must take the fix availability. The conditioning is emitted for the same reason - every visible satellite lies inside a cone a couple of degrees wide as seen from the Moon, so the lines of sight are near-parallel by construction. Runnable as the `earth-gnss-lunar` kind | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form identities and internal consistency; NO external oracle is claimed. The limb half angle is checked against asin(R_earth/r_orbit) and the geometry against it; the free-space loss, the DOP kernel and the SGP4 propagation this composes are each externally validated in their own rows and this row does not borrow their status. WHY MODELLED, and it is the transmit pattern: the gain at angle is a uniformly illuminated circular aperture, the Airy pattern, while a real GPS L1 antenna is a twelve-element helical array with a shaped main lobe peaked off-boresight to even out power across the Earth disc and sidelobes that are not Airy. Published measured patterns exist and are not vendored here, so orderings and orders of magnitude carry, while the dB of any single satellite does not. A FIRST IMPLEMENTATION OF THIS ROW WAS WRONG IN A WAY WORTH RECORDING: the Airy expression is valid only in the forward hemisphere, its argument goes as sin(theta), and at theta near 180 deg it wraps around and returns FULL BORESIGHT GAIN behind the aperture - so the two strongest links in the first report were satellites pointing their antennas away from the Moon, and they were the only two that cleared the threshold. Behind the aperture the model now applies a flat back-lobe floor, stated as a bound rather than a fabricated pattern shape. Deliberately absent, each making the budget OPTIMISTIC: no ionospheric or tropospheric loss on the limb-grazing rays, no polarisation, pointing or implementation loss, and a spherical Earth with no refractive extension. The Moon position is an INPUT, not an ephemeris lookup, because the quantity under test is the link and the beam geometry. Upgrading this row to Validated needs a measured transmit pattern and LuGRE normal points to check against; neither is in the repository and neither is invented here | earth_gnss_lunar | earth_gnss_lunar::tests (11 lib tests: the Earth-limb half angle against its closed form asin(R/r) with a further assertion that EVERY un-occulted link lies outside that cone, so the occultation test and the limb angle cannot disagree; the occultation predicate checked on the near side, the far side and the case where the body lies BEHIND the transmitter; path loss bounded to the plausible lunar-range band on every link; the trackable set shown to be a subset of the geometrically visible set and disjoint from the occulted one; monotonicity in both directions - more receiving gain never reduces the count, a stricter threshold never raises it; no link credited with more than boresight gain; a receiver inside the Earth refused; the sweep asserted to actually VARY with epoch; and signal-vs-fix availability asserted distinct, correctly ordered, and consistent with the per-epoch rows) |
| Lunar surface-beacon DOP augmentation | Beacon-augmented dilution of precision for a lunar surface user: the visible-satellite line-of-sight rows and the visible-surface-beacon ranging rows are concatenated into one design matrix and evaluated through the shared DOP kernel, and the resulting DOP is mapped to a realised 1-sigma accuracy IN METRES through a per-beacon user-equivalent ranging error assembled as the root-sum-square of clock-synchronisation, multipath and survey terms. Beacon visibility is the airless-Moon two-height geometric horizon, which has no refractive extension and is therefore exact rather than approximate. Runnable as the `lunar-beacon` scenario kind, which reports satellites alone, satellites plus beacons, and a larger constellation as the competing route to the same geometry. MEASURED on the bundled golden geometry (user at -80 deg, three surveyed beacons, six-satellite illustrative LCNS at t=0, 5 deg mask): 5 visible satellites give PDOP 9.6941 and a 3-D 1-sigma of 11.222 m; adding the beacons that actually clear the horizon gives PDOP 4.1160 and 4.765 m, a factor of 2.355; the 24-satellite service instead gives PDOP 2.4226 and 2.804 m, a factor of 4.002. The report prints the VISIBLE beacon count rather than the configured one, and on this geometry only ONE of the three beacons clears the horizon: the two flanking sites lie about 333 km from the user against an 86 km horizon for a 2 m antenna, so a reader is never left to assume all three contributed | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — The DOP arithmetic is the crate::orbit::dop kernel, separately externally validated against gnss_lib_py in tests/dop_reference.rs; this row does not re-borrow that row's status. The beacon-visibility horizon is the L01 closed form, and sigma = DOP x sigma_URE is the standard GNSS relation (Kaplan and Hegarty, Understanding GPS/GNSS, section 7). Within this row the augmentation itself is checked against an independent in-repo DOP path and pinned to a committed golden. WHY MODELLED: the constellation design, the beacon placement, the antenna heights and all three error-budget magnitudes are illustrative inputs rather than a fielded survey or a measured link, so the reported metres are a property of a chosen scenario and not of any deployed service. NOTE ON PROVENANCE: this capability was advertised in the README and exercised by two validation tests, yet carried NO matrix row and no scenario kind, so it could not be reached from a run at all. It was claimed in prose, absent from the ledger, and unreachable in the engine at the same time. The row and the kind were added together | lunar_beacon | lunar_beacon::tests (horizon visibility against the L01 closed form; the beacon-augmented DOP against the bare one; the error-budget root-sum-square; the DOP-to-metres relation); tests/validate_p2_beacon_before_after_table.rs (the whole before/after table pinned to a committed golden at 1e-9 relative); tests/validate_p2_beacon_before_after_independent_dop.rs (the same geometry through an INDEPENDENT DOP path, so the augmentation is not checked against the kernel that produced it) |
| Common-mode integrity blindness | Exact parity-subspace split of a measurement error into the part RAIM cannot see and the part it can. For the linearised snapshot model y = G·x + e, any error dy decomposes uniquely into a BLIND component in range(G) — absorbed as a state error S·dy and annihilated by the residual projector Pperp = I − G·S, so invisible to ANY residual test, not merely to a particular threshold — and a DETECTABLE component in parity space. The module returns the projector, the split, and the blind fraction, so a caller can quantify how much of a specific error a snapshot monitor is structurally unable to report. Applied to the real inter-ephemeris floor: the metre-level DE440-vs-INPOP21a and DE440-vs-EPM2021 disagreement in the geocentric Moon position is absorbed almost entirely as user position error (median blind fraction 1.000000; median blind position error 2.3955 m and 2.0050 m) against a parity residual at the 1e-15 m level | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — An independent numpy implementation of the same 4x4 least-squares split, fed byte-identical inputs (user, satellites and every per-satellite dy are rounded to 1 micrometre before being written to reference.json and before reaching the oracle), so the only difference between the two sides is the linear solver. WHY THIS IS NOT VALIDATED, despite using real data: the DE440 / INPOP21a / EPM2021 inter-ephemeris disagreement is an INPUT both sides receive, not an independent check of the answer — numpy evaluates the same formula, so it corroborates the implementation and not the model. The lunar constellation geometry (8 LCNS-like nodes at 5000 km slant range) is an original deterministic construction, not a surveyed or published one. The blindness is in any case a known, correct property of all snapshot RAIM; the contribution is quantifying it on a real inter-ephemeris floor, not discovering it. Ephemeris provenance for the reused Moon states is in tests/fixtures/inter_ephemeris/NOTICE.md (JPL, IMCCE, IAA RAS) | lunar_common_mode | lunar_common_mode::tests (8 lib tests: the split is additive and reconstructs dy; a common-mode covariance yields a positive common-mode protection level while a parity-only covariance yields a near-zero one; the projector annihilates range(G)); tests/lunar_common_mode_integrity_reference.rs (the engine split against an independent numpy computation on byte-identical inputs over the committed 366-epoch sample, relative AND absolute error < 1e-3) |
| Common-mode protection level and total integrity envelope | cmpl_horizontal bounds the k-sigma horizontal position error contributed by the blind common-mode class, by forming blind_position_covariance = S*Cov*S^T and projecting it into ENU; integrity_envelope reports hpl_total = hpl_araim + cmpl. The distinction the pair exists to make: the RAIM/ARAIM RESIDUAL test is provably blind to range(G) errors, but the ARAIM PROTECTION LEVEL is not - its fault-free term already bounds them up to a provider URA plus nominal bias. The CMPL is therefore only the cross-provider EXCESS that a single provider per-provider URA/ISM does not overbound, and the sum is a conservative triangle-inequality bound rather than an RSS, valid only where that excess is not already inside URA. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Analytic projector algebra checked against itself: a covariance confined to range(G) must give a positive CMPL, a covariance confined to parity space must give approximately zero, and the envelope must sum two measurement-space-orthogonal contributions. The common-mode covariance, the constellation geometry and k are representative Modelled inputs, NOT a certified budget, and no claim is made that the triangle bound is tight. NOTE ON PROVENANCE: cmpl_horizontal, blind_position_covariance and integrity_envelope are public and shipped, and their unit tests were already cited by the common-mode blindness row, but the ENVELOPE CLAIM itself carried no row - so the one caveat that keeps it honest, that the sum is a triangle bound and not an RSS, was stated nowhere in the ledger. The row registers the claim and the caveat together. | lunar_common_mode | lunar_common_mode::tests (common_mode_covariance_gives_positive_cmpl, parity_only_covariance_gives_near_zero_cmpl, envelope_sums_the_two_classes, state_map_matches_split) |
| Lunar joint multi-technique OD + clock | Batch fusion of VLBI + lunar-local range + inter-sat range to recover station+constellation positions and clocks | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Recovery of an injected simulated truth + NEES covariance consistency (internal); the underlying batch-LS estimator primitive is additionally cross-checked against Orekit 12.2 / Hipparchus Levenberg-Marquardt on identical observations (ReferenceImpl). The joint multi-technique solve as a whole stays MODELLED — the frame/VLBI sub-models are validated separately | lunar_combination | lunar_combination::tests (recovers simulated truth; VLBI restores station 3-D observability; deterministic); tests/lunar_joint_multi_technique_od_reference.rs (6 geometries × 16 params, 31 obs each, vs Orekit 12.2 / Hipparchus Levenberg-Marquardt on identical observations; recovered state worst |Δ| 1.4e-8 m) |
| Lunar absolute-station observability (datum defect) | Fisher-information observability of the joint lunar solve: without Earth baselines the absolute-frame datum lies in the null space of HᵀWH (station position unobservable); ≥3 baselines restore full rank and bound the station Cramér–Rao error, which the estimator attains | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Analytic datum-defect structure — the unobservable absolute-frame mode lies in the null space of the Fisher information (closed-form), the rank threshold matches the published 3-station design rationale, and the estimator attains the resulting CRLB in Monte-Carlo. The lunar geometry itself is a representative network (not a flown ephemeris), so the row stays MODELLED; the underlying FIM/CRLB engine is checked against the Kay (1993) closed forms separately | lunar_combination (lunar_observability) + fim | lunar_combination::tests (rank-deficient without Earth baselines; three baselines restore full rank — the 3-station threshold from the information rank, not solve error; station CRLB attained by the estimator at efficiency 0.98; CRLB tightens monotonically with baselines) |
| Lunar joint communications-and-navigation geometry | Per-satellite topocentric look angles and slant range at a named selenographic site, and the signal-in-space ranging accuracy exposed as a scenario parameter so the service-volume sweep yields a ranging REQUIREMENT rather than a pass/fail at one fixed sigma | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form geometry whose answer is known without running the code (elevation 90 deg overhead, azimuth 0/90/270 deg due north/east/west, Euclidean slant range) plus cross-agreement with lunar_service::visible_sat_positions, which computes the same elevation through a separate expression. MODELLED: the oracle is internal. The MCI propagation and the visible-satellite SET the export is derived from are separately Validated against ANISE 0.10.2 (see the service-volume row); an external azimuth/range oracle is the outstanding upgrade for this row | lunar_service | lunar_service::tests (topocentric against hand-computed geometry: overhead, due north/east/west, antipodal, and the degenerate polar east direction; the exported visible flag agrees with the independent visibility filter over a full 6 h sweep; the export is off by default and provably changes nothing else; protection levels are exactly linear in the exposed sigma while the geometry underneath is untouched) |
| Lunar differential PNT | NovaMoon-class differential reference station: common-mode cancellation + baseline-growing residual + DGNSS protection levels | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Differential error-cancellation identity + reuse of the DO-229E SBAS PL machinery; the single-difference + WLS solve is additionally cross-checked against RTKLIB's lsq()/matinv() (Takasu, BSD-2-Clause, compiled C) — independent solver code, but the same first-order LOS-difference algebra, so still InternalConsistency | lunar_dpnt | lunar_dpnt::tests (clock common-mode cancels exactly; residual grows with baseline; reuses SBAS PL; the satellite count is honoured to the builder's limit of 24, so a larger constellation cannot silently return a smaller one); tests/lunar_differential_pnt_reference.rs (single-difference residual + WLS position solve vs RTKLIB's lsq() compiled from C source) |
| Lunar interoperability export | LunaNet/IOAG-aligned lunar frame + time + ephemeris export (CCSDS OEM + KIF) with round-trip conformance | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — kshana's lunar OEM export re-parsed by the independent third-party `oem` library (R. J. Anderson): frame/time tokens and per-epoch state agree to write precision (1 mm / 1e-9 km/s) and a dropped-TIME_SYSTEM export is rejected — a structural interchange round-trip; the lunar frame/time physical semantics are validated by their own rows, so this stays MODELLED | lunar_interop | lunar_interop::tests (OEM carries lunar REF_FRAME/TIME_SYSTEM; time metadata round-trips; KIF envelope); tests/lunar_interoperability_export_reference.rs (kshana's emitted lunar OEM re-parsed by the independent `oem` Python library: REF_FRAME/TIME_SYSTEM/CENTER tokens + per-epoch state to format precision; a corrupted export is rejected) |
| PNT-resilience framework-aligned scoring | Per-dimension sub-scores over DHS RPCF categories, RethinkPNT RDRR functions and Yang criteria, each tagged Modelled with its driver; tentative RPCF Level with a bounded-degradation gate. Simulation-derived self-assessment, never certification. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Hand-derived per-metric formulas: inverse-Simpson diversity, weighted-mean composite, bounded/unbounded timeline durations, weakest-link Level ladder | resilience::arch, resilience::score, resilience::diversity, resilience::timeline | resilience::score::tests (monotonicity, composite bounds, level cap, modelled-provenance); resilience::diversity::tests (inverse-Simpson, common-mode, SPOF) |
| Resilience-score decision-instability study | Quantifies how a single composite score / RPCF Level reorders architectures under a defensible weighting simplex and a threat ensemble (top-1 flip rate, Kendall-tau dispersion, Level-flip rate, rank ranges); declared-vs-measured and diversity-collapse analyses. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form rank-statistics identities (tau in [-1,1] with hand-computed values; deterministic seeded Dirichlet) and constructed stable/unstable witnesses | resilience::stats, resilience::study, resilience::panel | resilience::stats::tests (Kendall-tau hand example, Dirichlet simplex, flip-rate); resilience::study::tests (stability control, instability witness, declared-vs-measured, diversity collapse) |
| Demonstration representativeness & gaps-to-flight | Per-result honesty ledger qualifying a demonstration output: its external anchors, modelled assumptions, gaps-to-flight and representative TRL band, with invariants enforced (Validated requires an external anchor; Modelled requires a gap and cannot claim above TRL 4). | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form invariants mapping to the 'representativeness justified + gaps-to-flight identified' compliance discipline; tied to the verification status/oracle-kind boundary | representativeness | representativeness::tests (validated-needs-external-anchor, modelled-needs-gap, modelled-TRL-ceiling, malformed-band, JSON fields) |
| Quantum-vs-classical trade evidence (common shape) | One reproducible TradeEvidence object (fixed frame: scenario+seed+engine; common per-FoM quantum-vs-classical values with polarity-correct benefit, optional 95% CI, validated/modelled label) carrying a representativeness record, so every quantum-PNT vertical reports the trade the same honest way. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form benefit/winner identities + faithful wrap of the existing quantum_trade::TradeResult; honesty tied to the representativeness ledger and verification labels | qtrade | qtrade::tests (benefit polarity higher/lower-is-better, wraps a real TradeResult faithfully, dishonest evidence rejected, validated-FoM needs external anchor, deterministic JSON) |
| Quantum device error-model library | Device cards (optical/trapped-ion/mercury-ion + classical clocks reused from holdover/clock_state; cold-atom interferometer; classical + entanglement/single-photon time-transfer links) each carrying a representativeness record; the entanglement link adds a shot-limited timing-precision model (~jitter/sqrt(R*tau), dark-count penalty, systematic floor). | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Reused clock/CAI coefficients (holdover/clock_state, published values) + closed-form shot-noise/loss identities for the entanglement link | quantum_devices | quantum_devices::tests (clock cards honest+ordered; entanglement precision ~1/sqrt(tau); detected rate -10x/10dB; dark counts degrade; systematic floor bounds; card modelled+valid) |
| Trusted quantum timing (time transfer + secure dissemination + anomaly) | End-to-end quantum vs classical time-transfer chain (clock coast + link precision in quadrature), a reused timing protection level, a delay/replay-attack security FoM (1-P_md) and a clock-anomaly detection probability + CUSUM latency, emitted as honest TradeEvidence with a representativeness record. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form quadrature budget over reused validated kernels (ADEV vs Stable32/NIST; TPL bound; detection analytic_pd/pmd); honesty tied to the representativeness ledger | timetransfer_chain | timetransfer_chain::tests (precision improves with integration; quantum can win AND lose; PL finite-positive; security FoM in [0,1] and grows with attack delay; anomaly Pd monotone; trade is_honest) |
| GNSS-free quantum navigation | Quantum (cold-atom interferometer) vs classical navigation-grade INS dead-reckoning over a GNSS outage: position-error growth, holdover to a position threshold, and the quantum-vs-classical trade as honest TradeEvidence; honest observability note (bias unobservable without a fix, so error grows). | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Reused inertial budgets cross-checked against an independent Octave double-integration of the same dead-reckoning ODE (different runtime, shared model → ReferenceImpl) plus the Freier-2016 published short-term noise as a one-sided anchor; the quantum-vs-classical composite stays MODELLED | quantum_nav_od | quantum_nav_od::tests (quantum beats classical over a long outage; advantage is outage-dependent; trade is_honest); tests/gnss_free_quantum_navigation_reference.rs (dead-reckoning position growth vs an independent Octave double-integration + the Freier-2016 published noise anchor) |
| Fault/anomaly detection for quantum PNT systems | Labelled quantum-fault catalog (clock frequency-jump/drift/lock-loss; sensor bias-step/dropout), a detection-statistic ROC AUC with a bootstrap CI, and a minimum-detectable fault at a fixed false-alarm rate; a quantum-clock-aided monitor detects smaller faults than a classical one, emitted as honest TradeEvidence. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form Gaussian AUC = Phi(mu/(sigma*sqrt2)) cross-checked against the externally-validated eval_stats::bootstrap_auc_ci (vs scikit-learn) + detection analytic thresholds | quantum_faults | quantum_faults::tests (analytic AUC known values; empirical bootstrap AUC brackets the closed form; quantum detects smaller faults / higher AUC; advantage vanishes for huge faults; 5-class catalog; trade is_honest) |
| Torque-free rigid-body attitude dynamics | Euler's rotational equations of motion (I ω̇ = τ − ω × Iω, principal-axis and general inertia tensor) coupled to quaternion attitude kinematics (q̇ = ½ q ⊗ ω) and propagated with a fixed-step RK4 integrator that re-normalises the quaternion each step | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Physical conservation laws of the free rigid body (quaternion-norm, rotational kinetic energy, body-frame and inertial angular-momentum) plus the closed-form symmetric-top body-cone precession rate (Goldstein §5.6–5.7; Wertz §16) — these are self-consistency invariants the integrator must preserve, NOT an external dataset, so the row stays InternalConsistency. MODELLED first-principles dynamics — no flexible-body / control-loop / external-torque environment | attitude_dynamics | attitude_dynamics::tests (apply/solve inverse, spherical-top zero torque, principal-axis fixed point, short-run energy+momentum conservation, q̇=½q⊗ω, symmetric-top rate sign + body-cone precession); tests/attitude_dynamics_reference.rs (200 000-step torque-free runs: |q|=1 to 1e-10, kinetic energy T=½ωᵀIω conserved to 1e-9 rel, |Iω| and the inertial momentum vector conserved to 1e-9/1e-8 rel, both on a tri-axial and a general non-diagonal inertia; symmetric-top oblate + prolate body-cone precession reproduced to 1e-6 vs the analytic λ=ω₃(I_a−I_t)/I_t) |
| Clohessy–Wiltshire / Hill relative-motion dynamics | Linearised relative motion of a chaser about a target on a circular reference orbit in the LVLH frame (ẍ−2nẏ−3n²x=0, ÿ+2nẋ=0, z̈+n²z=0), solved by the closed-form 6×6 state-transition matrix Φ(n,t) (Clohessy–Wiltshire 1960; Vallado Alg. 48), with the bounded relative-orbit condition ẏ₀=−2n·x₀ | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — The closed-form CW state-transition matrix cross-checked against an independent numeric integration of the same linearised equations of motion, plus the analytic relative-orbit invariants (time-reversibility Φ(t)Φ(−t)=I, the −2n·x₀ bounded-orbit condition, the −12π·x₀ per-orbit secular drift, decoupled cross-track SHM) — self-consistency checks of the linear dynamics, NOT an external dataset, so the row stays InternalConsistency. MODELLED linear relative motion on a circular reference orbit — no eccentricity (Tschauner–Hempel), J2, or differential-drag terms | cw_dynamics | cw_dynamics::tests (Φ(0)=I, cross-track decoupled SHM); tests/cw_dynamics_reference.rs (closed-form Φ vs an independent fixed-step RK4 integration of the same Hill ODEs to <1e-6 over a third of an orbit; Φ(t)Φ(−t)=I to 1e-9; the bounded condition ẏ₀=−2n·x₀ closes the full state after one period to 1e-9 with no secular along-track drift over 10 orbits; a pure radial offset drifts the analytic −12π·x₀ per orbit) |
| TDOA/FDOA passive emitter geolocation | Locate an emitter (jammer/spoofer, or an opportunistic source for reverse-PNT) from time-difference-of-arrival across a receiver network — the τᵢ=(Rᵢ−R₀)/c hyperboloid intersection solved by Gauss–Newton least squares — and, adding frequency-difference-of-arrival (range-rate differences) with moving receivers, jointly recover position and velocity; with the Cramér–Rao lower bound on the position covariance from the measurement geometry | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Self-consistency of the estimator and geometry: forward→inverse round trips, the Fisher/CRLB identity J·CRLB=I, GDOP monotonicity, and the estimator attaining its own Cramér–Rao bound under Monte-Carlo noise — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED passive geolocation — point-source line-of-sight model; no multipath / NLOS, receiver-clock-bias, or atmospheric-refraction terms | geolocation | geolocation::tests (noiseless TDOA forward→inverse to 1e-6 m; J·CRLB=I with a symmetric PD covariance; the CRLB position-variance trace is non-increasing when a receiver is added; joint TDOA+FDOA recovers a moving emitter's position+velocity; <4 receivers rejected); tests/geolocation_reference.rs (round trips over four geometries with a 3-D-diverse network; the Gauss–Newton estimator attains its Cramér–Rao bound — empirical error covariance tracks the analytic bound over 4000 Monte-Carlo trials) |
| GNSS carrier-phase integer ambiguity resolution (LAMBDA) | Integer least-squares ambiguity fixing the LAMBDA way: a volume-preserving integer (Z) decorrelating transform (integer-Gauss size reduction of the L D Lᵀ factor) + an exact Schnorr–Euchner depth-first branch-and-bound integer least-squares search + the closed-form bootstrapped success rate P_s=∏(2Φ(1/(2σ_{i|I}))−1), with the ratio test on the two best candidates | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Self-consistency of the integer estimator: the Z-transform invariants (unimodularity, congruence, determinant), the EXACT ILS verified against independent brute-force enumeration, and the bootstrapped success rate verified against a Monte-Carlo of the rounding process it models — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED integer-Gauss decorrelation (the conditional-variance reordering permutations of the full LAMBDA reduction are out of scope; they speed the search but change neither the exact ILS answer nor the bootstrapped rate) | lambda | lambda::tests (L D Lᵀ reconstructs Q); tests/lambda_reference.rs (the Z-transform is unimodular |det Z|=1 with Q_z=ZᵀQZ SPD, det-preserving, and lower total off-diagonal correlation; the Schnorr–Euchner ILS matches brute-force enumeration over 300 random covariances; the full decorrelate→search→back-transform pipeline equals the direct ILS and Z⁻ᵀZᵀ round-trips integers; the closed-form bootstrapped success rate matches a 200k-trial Monte-Carlo of sequential conditional rounding to <0.01) |
| B-plane targeting & patched-conic gravity assist | Hyperbolic-flyby geometry (a=−μ/v∞², e=1+r_p·v∞²/μ, turn angle δ=2·asin(1/e), impact parameter |B|=|a|·√(e²−1)), the B-plane Ŝ/T̂/R̂ aim-point frame and B·T̂/B·R̂ decomposition, and a patched-conic gravity assist (v∞-magnitude conserved, direction deflected by δ, heliocentric Δv=2·v∞·sin(δ/2) at no propellant cost) with the Tisserand parameter T_P=a_P/a+2√((a/a_P)(1−e²))cos i | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Self-consistency of the flyby geometry and the patched-conic invariants: the hyperbolic closed forms, the B-plane orthonormal decomposition, v∞ conservation, and Tisserand invariance (cross-checked two ways — invariance across the deflection and the v∞ link) are analytic identities checked against the engine's own state→element conversion — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED patched-conic two-body flyby on a circular planetary orbit — no finite-sphere-of-influence transition, encounter third-body perturbations, or ephemeris | bplane | bplane::tests (the flyby scalars satisfy the closed forms with two agreeing |B| identities and |B|>r_p; the turn angle decreases with periapsis radius and hits the δ→0 / δ→π limits; deflection preserves v∞ speed and rotates exactly by δ; the assist Δv magnitude equals 2·v∞·sin(δ/2) and is bounded by 2·v∞; the B-plane axes are orthonormal and ⊥ Ŝ with |B|²=(B·T̂)²+(B·R̂)²; the Tisserand parameter is invariant across a v∞-preserving deflection that does change a,e,i, and equals 3−(v∞/v_circ)²) |
| INS/TRN coasting error growth & threshold crossings | Position-error-vs-coast-duration budget built from IMU coefficients — accelerometer bias (t²), gyro-bias tilt through gravity (t³), velocity random walk (t^1.5), angle random walk (t^2.5) and scale factor times the travelled distance (t¹ cruising, t² under sustained specific force) — combined under a stated rule (rss / linear-sum / deterministic-sum-with-stochastic-rss), with the coast durations reaching caller-supplied position thresholds (10 m and 50 m by default) located by bisection, a per-contribution breakdown naming the dominant source at each crossing, and a TRN-bounded mode giving the largest terrain-fix interval that holds each threshold. Runnable as the `ins-trn-coast` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Two in-codebase routes that never see this module's algebra. (1) `inertial::AccelModel`, the engine's step-by-step stochastic dead-reckoner, integrated forward at dt = 0.01-0.05 s: deterministic for the bias and gyro-bias channels (agreeing to the Euler truncation, rel < 2e-4 and < 1e-3), and Monte-Carlo over 300 fixed seeds for the velocity- and angle-random-walk channels, whose sample RMS reproduces σ_vrw·t^1.5/√3 and g·σ_arw·t^2.5/√20 to rel < 0.10 (the sampling error of an RMS over 300 seeds is ~4%). The simulator only ever adds a white increment per step; it has no knowledge of the t^1.5 or t^2.5 laws, so this is a different route to the same number, not the same expression restated. (2) `inertial::imu_errors::ImuErrorModel::distort` double-integrated over an accelerate-then-cruise profile, reproducing s×(travelled distance) to rel < 2e-3 without ever multiplying a distance by a scale factor. Separately, and labelled a COMPATIBILITY check rather than an oracle, the model reduces bit-close (rel < 1e-12) to `quantum_trade::ClassicalInsBudget` when the gyro channels are off and the platform is under sustained specific force — that shares the expression and so cannot fail with it; it is there to prove no second, divergent error model was forked. Threshold crossings are located by the engine's existing bisection (`quantum_trade::PositionDrift::inertial_holdover_s`) and each single contribution's crossing is additionally inverted algebraically, the two agreeing to rel < 1e-15. The IMU class coefficients (navigation/tactical/industrial/consumer) are representative Groves 2013 Table 4.1 BAND figures and stay MODELLED, as does the TRN fix residual, which is a documented input. No external reference dataset of coasted position error exists in the tree and none was fetched: promoting this row to Validated needs a logged inertial dataset with position truth propagated through an independent strapdown navigator | inertial::coast (CoastModel, Contribution, Combination, TrnFixMode, InsTrnCoastScenario); scenario kind `ins-trn-coast` | inertial::coast::tests (36 library tests). Growth powers: doubling_the_coast_scales_each_contribution_by_two_to_its_own_power; a_pure_bias_error_quadruples_and_a_pure_random_walk_error_grows_by_two_to_the_three_halves; the_exponents_the_document_publishes_are_the_ones_the_curves_actually_follow. Cross-model oracles: the_bias_law_matches_the_engines_stochastic_dead_reckoner_stepped_forward; the_gyro_tilt_law_matches_the_engines_stochastic_dead_reckoner_stepped_forward; the_velocity_random_walk_law_matches_a_monte_carlo_of_the_engines_dead_reckoner (300 seeds, rel < 0.10); the_angle_random_walk_law_matches_a_monte_carlo_of_the_engines_dead_reckoner (300 seeds, rel < 0.10); the_scale_factor_law_matches_a_double_integration_of_the_engines_imu_error_model (rel < 2e-3); the_model_reduces_to_the_engines_existing_classical_ins_budget (rel < 1e-12). Crossings: every_contributions_closed_form_crossing_agrees_with_the_engines_bisection (20 pairs, rel < 1e-9); the_located_crossing_puts_the_model_on_the_threshold_it_searched_for; an_error_free_imu_never_reaches_a_threshold_and_says_so_instead_of_reporting_zero. TRN: a_full_reset_fix_makes_every_inter_fix_excursion_identical; a_position_only_fix_lets_each_excursion_exceed_the_last_and_the_peak_is_the_final_one; the_largest_fix_interval_holding_a_threshold_puts_the_peak_on_that_threshold; a_position_only_fix_cannot_bound_a_tactical_hour_at_any_fix_rate; a_fix_residual_above_the_threshold_is_reported_as_never_holding_not_as_a_zero. Surface: every_published_field_carries_a_unit_and_a_provenance_class; the_scenario_runs_through_the_engines_public_dispatch_and_is_reproducible |
| Aperture navigation-versus-communications duty cycle | One run takes a contact plan (a list of aos_s/los_s windows, each asking the aperture for navigation or communications — the same window vocabulary `passes::predict_passes` emits, converted by `aperture_duty::windows_from_passes`), an aperture count and an explicit arbitration policy, and returns the navigation duty, the communications duty, the idle duty and the per-session outage. The policy is an input with a documented default (`navigation-priority`; also `communications-priority` and non-preemptive `first-come-first-served`), and the report carries the resolved policy, its full definition and the duty and outage definitions, because a duty figure quoted without its arbitration rule is not reproducible. The schedule is an exact interval sweep over the window boundaries, so a window that ends exactly where the next begins never contends, and navigation, communications and idle aperture-seconds are accumulated independently in that one sweep. Runnable as the `aperture-duty-cycle` scenario kind | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Internal consistency, from three quantities computed by different expressions in the same sweep and then required to close. Navigation aperture-seconds, communications aperture-seconds and idle aperture-seconds are accumulated separately — idle from (apertures − |served|) per elementary interval, never as a remainder — and their sum is asserted against apertures × horizon_s, which a mis-bracketed boundary, a double-counted interval or a dropped one breaks immediately; the per-session served times are separately required to add back to the two service totals. The scheduler's structural properties are measured rather than assumed: served time is asserted non-decreasing in the aperture count over 200 pseudo-random plans for all three policies (not obvious for the non-preemptive policy, where an extra aperture changes who holds what at every later boundary), and the boundary arithmetic is pinned at the touching/one-second-overlap pair where an off-by-one would otherwise hide. The pass-predictor bridge is checked against `passes::predict_passes` output: with one aperture and no competing service the navigation aperture-seconds equal the predictor's own summed pass durations. No external oracle is claimed and none exists: the capability supersedes hand arithmetic rather than being checked against it, the bundled contact plan is illustrative rather than flown, and no operational scheduler publishes a plan-plus-answer pair with its arbitration rule stated — a duty computed under an unstated policy is not comparable to one computed under a stated one, and the policy dependence is measured (navigation duties of 100/150 vs 50/150 on the identical plan). Slew and changeover time, data volume, buffer state, energy and link closure are excluded in the report label rather than silently modelled | aperture_duty | aperture_duty::tests (a window that ends exactly when the next begins does not contend, and moving it one second earlier costs exactly one second — the off-by-one guard; overlapping windows beyond the aperture count put the lower-ranked session in outage, with the contention interval pinned; the arbitration policy decides which service holds the aperture, with all three policies' numbers pinned on one plan; first-come-first-served does not preempt a session already holding an aperture; a session that loses arbitration at its start acquires an aperture when one frees; the three duties account for every available aperture-second across 3 policies × 4 aperture counts; adding an aperture never increases any session outage, measured over 200 pseudo-random plans × 3 policies × every aperture count; enough apertures for every session leave no outage at all; the reporting horizon clips the plan and sets the duty denominator; a predicted pass list becomes a contact plan without a second window type; the bundled plan duty numbers are engine outputs for one and two apertures; the report states the policy that produced the numbers; every reported figure carries a unit and a provenance class; the scenario is reproducible and declares itself MODELLED; the scenario rejects a plan it cannot schedule); api::tests::aperture_duty_cycle_kind_round_trips_through_the_dispatch |
| Lunar surface-navigation RF jamming (per-satellite J/S) | Lunar-native jammer-to-signal ratio, effective C/N₀ and loss of lock for a selenographic surface user under a lunar surface (or raised) jammer, over the illustrative public-source Moonlight/LCNS-class constellation. Composes the open jamming chain (j_over_s_db, effective_cn0_dbhz, rx_antenna_gain_db, lock_status, q_factor, nominal_cn0_dbhz, free_space_path_loss_db) with the open lunar sky geometry (lunar_service::LunarConstellation + topocentric, lunar::selenographic_to_mcmf); no geometry or radiometry is re-derived. Unlike the Earth `jamming` kind the signal leg is not a fixed received power: each satellite's isotropic received power is its own link-budget EIRP − FSPL(slant range), so J/S varies satellite by satellite with lunar range and elevation. Emits ONE ROW PER VISIBLE (epoch, satellite) LINK as JSON and as a *.table.csv artifact, with both received powers the J/S is the difference of printed alongside it; aggregate figures of merit sit beside that table, never in place of it. Runnable as the `lunar-jamming` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Composition cross-check against an independent in-repo code path: every per-link J/S is re-derived as the difference of two link budgets computed with linkbudget::received_signal_power_dbw, whose free-space loss is the single expression 20·log10(4πRf/c) rather than the three-term sum jamming::free_space_path_loss_db uses — the two agree to < 1e-9 dB on every row (measured worst case 7.11e-14 dB, i.e. float round-off). The underlying interference chain it composes is separately externally anchored in tests/gnss_denied_jamming_resilience_reference.rs (independent numpy/scipy re-derivation of J/S and effective C/N₀ pinned to Kaplan & Hegarty §9.4, plus JammerTest 2024 measured C/N₀, Zenodo 10.5281/zenodo.15910563); the lunar geometry it composes is the lunar_service/lunar geometry with its own oracles. Closed-form identities checked here: a halved jammer standoff adds exactly 20·log10(2) dB to every row; J/S is exactly invariant to the user-antenna boresight gain while C/N₀ moves by exactly that gain; an elevation mask changes no surviving row bit-for-bit. The row itself stays ReferenceImpl/Modelled: no measured lunar jamming campaign exists to validate against, and the constellation is an illustrative public-source Moonlight/LCNS-class geometry, not a flown ephemeris | lunar_jamming (composing jamming, lunar_service, lunar) | lunar_jamming::tests (17 lib tests: j_over_s_equals_the_difference_of_two_independent_link_budget_runs; the_report_prints_both_link_budget_legs_so_the_difference_is_checkable_from_it; the_scenario_reports_one_j_over_s_row_per_visible_satellite_and_never_a_median; a_single_median_j_over_s_would_misreport_the_outcome_that_the_table_reports; a_closer_jammer_raises_j_over_s_by_exactly_the_free_space_loss_difference; a_more_distant_satellite_is_the_weaker_signal_so_it_carries_the_higher_j_over_s; j_over_s_is_invariant_to_the_user_antenna_boresight_gain; a_narrowband_jammer_leaves_a_higher_effective_cn0_than_broadband_at_equal_js; a_selenographic_jammer_gets_its_range_from_the_shared_lunar_geometry; a_strong_enough_jammer_takes_every_lunar_link_below_the_tracking_threshold; no_jammer_is_a_clean_sky_lunar_baseline_with_an_undefined_j_over_s; raising_the_elevation_mask_can_only_remove_rows_never_change_the_ones_that_remain; every_emitted_numeric_field_has_a_unit_and_a_provenance_class; the_csv_table_carries_every_row_of_the_json_table; the_run_is_deterministic_and_the_dispatch_surface_is_populated; bad_inputs_are_rejected_rather_than_producing_a_number); api::tests::lunar_jamming_kind_round_trips_through_the_dispatch_with_a_per_satellite_table |
| Lunar denial contour with an uncertainty band from the measured C/N₀ spread | The `lunar-jamming` report no longer rests its denial contour on one scalar. It emits the full measured wanted-signal C/N₀ distribution over the per-satellite table — n, min, p05, p25, median, p75, p95, max, mean, sample stdev, and the sample's own asymmetry (p95 − median) − (median − p05) — beside the per-link rows, which are unchanged. The contour is then reported at each of those order statistics under BOTH denial criteria the engine recognises, never one in place of the other: the incumbent power-ratio criterion (J/S = 30 dB, the same threshold attack_surface and tracking_loop use, and the criterion behind the released lunar link-jamming table's `denial` column), and the loss-of-lock criterion (the effective C/N₀ falling to tracking_threshold_dbhz), which is the criterion this report's own links[].status column is scored with. Each contour point is given on both axes of the denial plane — the jammer EIRP required at the scenario's standoff, and the denial standoff at the scenario's EIRP — so the band is an interval on the same axes a contour plot is drawn on. The band edges ARE contour(p05) and contour(p95): the same closed-form map applied to the sample's own quantiles, not a sigma fitted to the sample and not median ± k·stdev, and the report says so in a band_definition string beside the numbers. stdev is emitted for continuity and is used by nothing. A quantile whose C/N₀ is already at or below the tracking threshold has no finite denying J/S; those columns are emitted as null with a counted reason rather than as an infinity or a clamped radius | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Internal consistency against the engine's own forward functions, which is all this capability can honestly claim. Every contour point is a closed-form inversion, and each inversion is checked by pushing its answer back through the FORWARD function the report's own rows were scored with: the J/S column through jamming::effective_cn0_dbhz (which must return tracking_threshold_dbhz to < 1e-9 dB-Hz), the standoff column through jamming::free_space_path_loss_db and jamming::j_over_s_db (the same J/S to < 1e-9 dB), the EIRP column through jamming::j_over_s_db at the scenario's own standoff. The contour is further checked to be the BOUNDARY of the denial set rather than a point inside it — lock_status loses lock on a strict inequality, so the verdict is measured to flip from DEGRADED to LOST across 1e-4 dB of J/S either side of the contour, which an off-by-an-epsilon contour would fail. The strongest check is per-link rather than per-quantile: applying the same map to every row's own C/N₀ reproduces the report's status column exactly — 0 disagreements on 38 of 38 rows at the documented operating point (kind = lunar-jamming, every input default except jammer.range_m = 25 000 m), where 26 rows are LOST and 12 are not. Monotonicity is measured, not assumed: 20 001 samples across [tracking_threshold + 1e-3, 80] dB-Hz, 0 violations of a strictly decreasing standoff and a strictly increasing required power, so the quantile ordering of the band is demonstrated rather than asserted. ExternalDataset is declined and Validated with it: no measured lunar jamming campaign exists to compare a denial radius against, the constellation is an illustrative public-source Moonlight/LCNS-class geometry rather than a flown ephemeris, and the contour's inputs (EIRP, jammer power, antenna gains, noise temperature) are representative magnitudes. ReferenceImpl was considered and declined too — the inverse and the forward expression are the SAME algebra read in two directions, so the round trip catches transcription and sign errors but is not an independent implementation; calling it a cross-check would be the borrowed-independence move the matrix invariants exist to prevent. What the band buys is measured and quoted rather than asserted: at that operating point the single-scalar contour is 27.402916 km and puts 25 km on the denied side for all 38 rows, while the band 21.256108 .. 29.921360 km contains the operating point and therefore reports the split the table actually shows. The two criteria are also measured to disagree — the power-ratio band (38.186527 .. 53.691675 km) does not contain 25 km at all — which is why both are printed | lunar_jamming (denial_js_db, range_for_free_space_path_loss_m, Cn0Distribution, DenialContourPoint, ContourBand, DenialContour; inverting jamming::effective_cn0_dbhz, jamming::j_over_s_db and jamming::free_space_path_loss_db) | lunar_jamming::tests (10 lib tests: the_contour_is_the_exact_inverse_of_the_functions_the_rows_were_scored_with; the_band_is_the_measured_quantiles_pushed_through_the_contour_not_a_sigma; the_asymmetry_the_band_carries_is_the_samples_own_shape_bent_by_the_criterion; the_contour_is_monotone_in_cn0_measured_over_a_dense_sweep_not_assumed; the_band_recovers_the_split_verdict_the_single_scalar_contour_lost; the_distribution_is_the_tables_own_order_statistics_and_keeps_the_rows; a_link_already_below_the_threshold_gets_a_null_contour_point_not_a_number; a_clean_sky_run_has_no_contour_at_all_rather_than_an_empty_one; the_denial_threshold_is_the_same_thirty_decibels_the_rest_of_the_engine_uses; the_units_block_describes_the_contour_and_names_nothing_the_report_omits) |
| Cross-modality integrity monitor detection power | The hybrid-optical-rf report states what the cross-modality chi-square monitor can actually DETECT, not only that it passes a fault-free case: the minimum detectable bias per monitored axis (east, north, up, clock) at the scenario's stated false-alarm and missed-detection probabilities, the detection-power curve either side of it, the noise-free bias multiple at which the realised statistic first crosses the threshold, and the time-to-detect for a bias ramp at a stated rate. Faults are also injected through the real monitor and the statistic it returns is reported alongside the analytic prediction | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Two internal oracles, no external dataset. (1) Closed-form round trip: the minimum detectable bias is produced by inverting the non-central chi-square tail on the non-centrality (raim::pbias) and is verified by feeding the resulting non-centrality back through raim::noncentral_chi2_cdf at the monitor's own threshold, which must return P_md. (2) Injection vs analysis: a bias is written into the RF estimate of one axis and cross_raim::run_cross_raim is re-run, so the statistic compared against the analytic non-centrality is the one the monitor computed, not a re-derivation. A seeded Monte-Carlo of the statistic itself is carried in the tests as a third check; it is deliberately NOT in the report, because a sampled estimate would be slower and not reproducible bit-for-bit. ExternalDataset is declined: the quantity is the detection power of THIS monitor at THIS scenario's sigma allocation, and the sigma magnitudes the MDB is scaled by are Modelled representative inputs, not measurements. ReferenceImpl was also considered and declined — the Monte-Carlo samples the same statistic the analysis describes, so it catches transcription and coefficient errors but is not an independent implementation of the monitor | hybrid_integrity | hybrid_integrity::tests (the detection-power curve runs from the false-alarm rate at zero fault to 1 − P_md at the minimum detectable bias; the minimum detectable bias fed back through noncentral_chi2_cdf at the threshold the monitor itself applied returns P_md to 1e-9, on every axis and through the public helper; a bias actually injected into the RF estimate shifts the monitor's own statistic by exactly the hand-computed b²/(σ_rf² + σ_opt²); a noise-free bias is caught above √(T/λ*)×MDB and missed below it, with the injected ladder straddling that crossing; detection power is monotone in fault magnitude and identical on all four axes in MDB multiples; a seeded 200,000-sample Monte-Carlo of the monitor statistic reproduces the analytic power within 4σ at four points on the curve; the timing MDB is pinned above the timing alert limit, which is a measured weakness and not a feature; the Wilson-Hilferty quantile is measured to disagree with the monitor's exact threshold by ~4%, recording why it was not used; the ramp figure is exactly MDB/rate and scales inversely with the rate, and a non-positive rate reports null rather than zero) |
| Post-handover covariance re-growth against the alert limit | The hybrid-optical-rf report exposes the filter's process-noise model and states how long the post-handover solution stays inside the alert limit: for both handoff directions it carries the per-axis covariance the handover left behind, propagates it forward under a stated random-walk process noise, and reports the time at which the coverage-scaled 1σ reaches the horizontal, vertical and timing alert limits, which limit binds first, the variance doubling time constant, and a sampled coast profile that brackets the crossing. Process-noise PSDs, the coverage factor and the alert limits are all inputs with documented defaults | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — No external oracle. The crossing is a closed-form solution of the random-walk variance growth, and the tests recompute it independently from the values the report itself publishes rather than from the emitter's internals. The starting covariance is pinned bit-for-bit to the trace the existing handoff block already reported, so the coast cannot propagate a covariance nobody else saw. The process-noise PSDs are MODELLED representative inputs and the crossing times scale directly with them, which the scaling test states as a measured property rather than a claim. ExternalDataset is declined deliberately: the coast time is a direct function of two Modelled PSDs and of alert limits that are themselves representative, and there is no measured lunar optical/RF handover coast to compare against. An external oracle here would need a published post-handover covariance-growth or holdover-accuracy curve for a comparable receiver with its process-noise model stated, checked to a tolerance | hybrid_integrity | hybrid_integrity::tests (the coast starts from exactly the covariance trace the handoff block reports, for both directions, so the replayed diagonal cannot drift from the reported handover; the reported crossing time is recomputed from the report's own handover sigma, process-noise PSD and coverage factor, and the bound is inside the alert limit just before it and outside just after; the coast time scales exactly inversely with the process-noise PSD and shortens when the alert limit tightens; a zero-PSD coast reports null rather than a zero time, because never is not immediately; the emitted profile crosses exactly once and brackets the reported crossing; the variance doubling time and the alert-limit crossing time are pinned apart, being eight orders of magnitude different after the tight optical stage and within one order of magnitude after the loose RF stage; leaving the optical modality buys more coast time than leaving RF, by exactly the covariance difference divided by the horizontal growth rate; and random_walk_time_to_limit separates already-outside, crosses-at-t and never-crosses) |
| Off-boresight antenna pattern in the lunar geometry export | The per-satellite geometry export carries, per (epoch, satellite), the off-boresight angle AT THE SATELLITE and the transmit gain toward the site from the real uniformly-illuminated circular-aperture (Airy) pattern, and reports the in-beam count under that pattern BESIDE the in-beam count under the symmetric gain-to-beamwidth approximation (θ_3dB[deg] = √(31000/G_lin)), with the difference emitted as an explicit correction in links, in satellites per epoch, and as the worst single epoch. Both implied aperture efficiencies of the approximation are emitted (0.641 against the 70·λ/D degrees rule it is quoted with, 0.920 against a uniform circular aperture) so the efficiency it silently assumes is stated rather than inferred. Off by default: the block appears only when an export site and an aperture are both given | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Mixed, and separated rather than pooled. The PATTERN underneath is externally validated and keeps its own row (a scipy.special.j1 fixture to < 0.05 dB in tests/validate_p1_orbital_footprint.rs, plus here the published Airy half-power abscissa x = 1.61634 located by bisection rather than assumed). The GEOMETRY is checked against closed-form triangle trigonometry written as a different expression from the dot product under test. The CONTAINMENT of the real beam by the approximate cone is derived algebra (28.019/√η vs 29.479 degrees per λ/D), so the correction can only be non-positive for η ≤ 0.9035. But the in-beam COUNTS themselves have no external oracle: no published table gives how many satellites of a Moonlight/LCNS-class shell hold a south-polar site inside a given dish's half-power beam, and the constellation is an illustrative public-source approximation, not a flown ephemeris. The measured disagreement at the documented working point — 0 links in beam under the real pattern against 28 under the approximation, −2.33 satellites per epoch, worst epoch 3, on 76 evaluated links — is therefore a MODELLED finding about the approximation, pinned as a regression literal (the nearest row sits 0.069° from either beam edge, four orders of magnitude above any last-digit disagreement), not an externally validated coverage number. Labelling the row ExternalDataset on the strength of the pattern's own external anchor would be borrowed validation, which is the move the matrix invariants exist to prevent | lunar_service, antenna | antenna::tests and lunar_service::tests (the half-power crossing located by bisection on the pattern matches the published Airy x = 1.61634 and yields the exact 1.02899·λ/D width, recording that the conventional 1.02 coefficient sits at −2.955 dB not −3.010 dB; the pattern is strictly decreasing over 400 points from boresight to the first null; the implied-efficiency algebra round-trips to 1e-12 and reproduces 0.641 / 0.920; the off-boresight angle matches tan θ = R·sin γ/(r − R·cos γ) at 20 points and both limits to 1e-12; the approximate cone contains the real beam row by row; the headline counts equal the per-row flags they summarise and the correction equals their difference; every row verdict is recomputable from the emitted report alone; every emitted numeric and boolean field has a unit and a provenance class; an impossible aperture emits no block; with no antenna configured the export keeps exactly its six pre-existing keys, 0 leaves changed and 0 removed) |
| Tracking-loop loss of lock and spoof pull-in under interference | Loss of lock computed from loop dynamics instead of a power ratio: carrier (Costas) and code (non-coherent early/late) 1σ thermal jitter against C/N₀ with the squaring loss, against the stated rules 3σ_PLL + θ_e ≤ 45° and 3σ_DLL + ramp lag ≤ d/2 chips; drop and re-lock C/N₀ thresholds with the binding loop named and the hysteresis DERIVED from the wider pull-in bandwidth rather than asserted; the declared time to lose lock from a two-threshold lock detector with confirmation dwells, reported separately from the physical phase-escape time (Viterbi mean time between cycle slips, in log₁₀ s because it spans hundreds of decades); the largest code slew and carrier Doppler rate the victim's loops can follow; and the DENIAL RADIUS the loop dynamics imply reported alongside the existing power-ratio radius with their signed difference as its own named field. Runnable as the `tracking-loop` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — The engine's own sdr correlator (sdr::correlate / synth_if / CaCode) stepped forward on seeded synthetic IF at a calibrated C/N₀ — a separate code path reaching the same numbers by numerical correlation of sampled IQ rather than by an algebraic jitter expression, so it is a different route and not a restatement — plus standard tabulated modified-Bessel I₀ values for the cycle-slip term. Loop theory per Kaplan & Hegarty ch. 8 and Viterbi/Gardner for the slip time. The row stays ReferenceImpl/MODELLED: the cross-check lives in this same codebase, and the bessel_i0 check validates one special function rather than the tracking model, so promoting the row on that basis would be self-serving labelling. ExternalDataset would need a recorded raw-IF dataset with ground-truth C/N₀ and an annotated loss-of-lock instant (TEXBAT/OAKBAT class); none ships in this tree, and even with the IQ those datasets publish no per-epoch loop-state truth, so a declared loss-of-lock time could only be validated against some other receiver's lock detector, which is a modelled choice and not an oracle. The loop bandwidths, integration time, correlator spacing, pull-in ratio, dwells, jammer power and antenna gains are representative band figures, not a datasheet | tracking_loop (composing sdr, jamming) | tracking_loop::tests (open-loop Costas discriminator jitter against sdr::correlate stepped forward on seeded synthetic IF, 3 pooled noise realisations × 900 epochs, agreeing to 0.63% over 35-45 dB-Hz, with the squaring-loss term required to fit at least 3× better than the no-squaring-loss form wherever it is resolvable; the ~32 dB-Hz atan-discriminator saturation asserted rather than merely stated, so the validity limit is pinned; closed-loop σ against a stepped sdr Costas loop over 4000 epochs to 3.7%; first-order DLL ramp lag against a stepped sdr DLL to 0.17%; bessel_i0 against tabulated I₀ to 7.4e-8; the hysteresis width required to fall in [5·log₁₀ r, 10·log₁₀ r] across 4 ratios × 2 integration times × 3 bandwidths); api::tests::tracking_loop_kind_round_trips_through_the_dispatch |
| Lunar-VLBI station-coordinate covariance from a tracking schedule | Delay partials accumulated over a schedule of baselines × epochs into a Fisher information matrix, inverted to the station coordinate covariance and the per-coordinate station sigma, replacing an assumed isotropic equipartition link from a scalar delay precision. The state carries Earth-fixed (ITRS) station coordinates, so the Jacobian is the inertial partial rotated by each epoch's GCRS→ITRS matrix and Earth rotation is what makes those coordinates observable — the report MEASURES the Earth-fixed line-of-sight sweep and the beacon declination rather than assuming them. Rank, datum defect, condition number, the information spectrum and the free-network null space are emitted on every run, and under a rank deficiency the headline sigma is published as NULL with a status rather than read out of a near-singular inverse. The equipartition value c·σ_τ·√(g/N) for the SAME schedule is printed beside the computed one with their ratio, together with the isotropic trace bound √(p/trace(M)) that AM-HM makes a hard floor. Runnable as the `lunar-vlbi-fim` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — An independent in-repo route. Every Jacobian row is re-derived by central finite difference of lunar_vlbi::vlbi_delay_s evaluated from the state's own Earth-fixed and Moon-body-fixed coordinates rotated forward through the frame chain — a path that computes no derivative and shares no expression with the analytic partials — and the information matrices the two routes build agree to < 1e-6 of the largest diagonal. The linear-algebra kernel this composes (information_matrix, crlb, sym_eig) is separately externally anchored against numpy.linalg.eigh / numpy.linalg.inv in tests/fim_observability_reference.rs, and the delay observable carries lunar_vlbi's own delta-DOR far-field oracle; the row does not borrow either status. Closed-form identities checked here and labelled as such: σ² and 1/N scaling, and √(p/trace(M)) as an AM-HM lower bound the computed sigma cannot beat, which coincides with the equipartition value only on an isotropic geometry — which is why the measured ratio is exactly the anisotropy the assumption discarded. The row stays ReferenceImpl/MODELLED: no published lunar-VLBI schedule-plus-covariance pair exists to validate against, the station coordinates and beacon site are illustrative rather than surveyed, and the Moon-centre ephemeris, station clocks, troposphere and Earth-orientation parameters are held FIXED while a real session co-estimates them with correlated scan noise, so the covariance is a Cramér-Rao bound for a reduced parameter set and is optimistic in its own right. An IVS SINEX covariance would not be comparable without that co-estimation | lunar_vlbi_fim (composing lunar_vlbi, fim, cio, lunar_frame, frames) | lunar_vlbi_fim::tests (24 lib tests: the analytic Jacobian against a central finite difference of lunar_vlbi::vlbi_delay_s taken through a route that rotates the state's own coordinates forward and never touches a partial derivative, agreeing to < 1e-6 of 1/c per column, with the two information matrices agreeing to < 1e-6 of the largest diagonal and the covariances to < 1e-5 relative; an orthogonal unit geometry whose covariance is c·σ_τ per axis in closed form to 1e-12, which is also the one case where the equipartition link is exact; the covariance spectrum and every station's 3-D sigma invariant under a rigid rotation of the whole network to 1e-9 with C_rot = R·C·Rᵀ pinned blockwise AND an explicit assertion that the per-axis sigmas did move, so the test cannot pass vacuously; covariance scaling exactly as σ² and as 1/N; the AM-HM trace bound never beaten; the delay closure τ_ik = τ_ij + τ_jk pinned to one ULP on the delays and on the Jacobian rows, with a redundant baseline shown to add information but never rank; a single epoch reported rank-deficient with a null headline; a longer arc measured to condition better at matched observation count; the beacon block shown unobservable on this schedule; the neglected differenced-Shapiro partial measured by finite difference at run time and emitted rather than waved away) |
| Lunar-surface-point coordinate covariance from a VLBI delay schedule, kept distinct from the Earth-station one | A third datum choice, `all-stations-fixed`, that holds every Earth station and estimates the BEACON's Moon-body-fixed coordinates alone — the configuration a lunar surface-point uncertainty is actually quoted for, since Earth station coordinates are an input to the delay model rather than an unknown of it. It exists because the station-level covariance and the surface-point covariance are DIFFERENT QUANTITIES separated by the lever arm ρ/B, and nothing previously stopped one being quoted against the other. The emitted `beacon_link` block carries ρ, the longest baseline, the lever arm, the surface-point form of the equipartition link c·σ_τ·(ρ/B)·√(g/N), the computed per-coordinate beacon sigma and their ratio — the ratio null rather than misleading whenever the beacon is unestimated or the matrix rank-deficient. B is taken as the LONGEST baseline present, the most favourable one, so the ratio can only understate. Runnable as `datum = "all-stations-fixed"` with `estimate_beacon = true`, which is refused with a message naming the missing input when the beacon is not estimated | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Closed-form identities, with no external oracle claimed or available. The lever arm is checked against ρ/B and the two equipartition forms against each other to 1e-15 — algebraic identities, so they catch a wiring error and nothing else, and are labelled as such. The substantive result is MEASURED rather than asserted: a delay from a fixed baseline constrains the beacon's DIRECTION, so the line-of-sight component reaches the information matrix only through the near-field range term, and the test reads the resulting anisotropy off the emitted spectrum instead of deriving it. AM-HM makes √(p/trace(M)) a hard floor, so an isotropic-equipartition link can only ever UNDERSTATE, and the computed-over-equipartition ratio is exactly the anisotropy it discarded. MEASURED on the Goldstone-like/Canberra-like pair whose chord is 10726.748 km: over 112 sampled days, 36 admit no mutually visible epoch at all at a 10° mask, the most ever mutually visible is 17 of a 49-sample schedule, and on the 73 viable days the three-component ratio runs from 113.9× to four orders of magnitude more, median 1513×, while restricting to the two transverse directions the line of sight does not starve gives 3.94× to 25.8×, median 7.8×. WHAT THIS ROW DOES NOT CLAIM: any of those figures as a property of a real campaign. It establishes that the surface-point quantity is now COMPUTED rather than assumed, and that it cannot be silently interchanged with the station-level one. Stays ReferenceImpl/MODELLED: no published lunar-VLBI surface-point covariance exists to validate against, the stations and beacon site are illustrative rather than surveyed, and the ephemeris, clocks, troposphere and Earth-orientation parameters are held FIXED, so this is a Cramér-Rao bound for a reduced parameter set and optimistic in its own right | lunar_vlbi_fim (composing lunar_vlbi, fim, cio, lunar_frame, frames) | lunar_vlbi_fim::tests (7 lib tests: every datum spelling round-trips through parse/as_str and an unknown one is refused; holding every station without the beacon is refused with an error naming `estimate_beacon`; the lever arm is asserted EQUAL to ρ/B and the beacon equipartition EQUAL to the station equipartition times it, both to 1e-15, with a further assertion that the lever arm exceeds 10 so the two budgets are not confusable on this geometry; the fixture's published baseline is pinned to 10726.748 km and its 49-sample schedule asserted to yield strictly fewer than 49 mutually visible observations; the beacon spectrum on a single baseline is measured to span at least five decades and the resulting ratio asserted above 1 by AM-HM and above 100 in fact; the station-plus-beacon layout is asserted rank-deficient with BOTH computed fields null while the modelled comparand still reports. Plus a guard on the fixture itself: a top-level key spliced after an array-of-tables becomes station data instead, so the splice point is asserted and the parsed scenario checked to carry the key — the failure mode is a run that silently uses a different configuration from the one the test names) |
| Lunar differential PNT — correction-link residual budget | The three terms a differential correction picks up between the epoch it is computed at and the epoch it is used at, each previously left as unmodelled headroom: reference-station survey error (correlated across satellites, baseline-independent, ~1:1 position transfer and provably not DOP-amplified), correction ageing (the frozen orbit-error vector re-projected onto the line of sight the engine's own propagator puts the satellite on one latency later, plus c·σ_y(τ)·τ clock drift from the calibrated power law), and uniform link quantization over an exact ±(orbit_err + clock_err) full scale with step²/12 variance. Reported in both the range and position domains, beside — never in place of — the existing residual and protection level, with a latency curve beside the single figure | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form identities and self-consistency: the uniform-quantizer step²/12 variance, the exact (GᵀG)⁻¹GᵀRG(GᵀG)⁻¹ covariance propagation collapsing to σ·PDOP for equal σ, the survey term's 1:1 transfer as a consequence of û_user ≈ û_ref, and switching-off quadrature closure. The PDOP cross-check against orbit::dop shares the [−û, 1] normal matrix, so it is a consistency check and is labelled as one rather than an independent oracle. No ExternalDataset is available or claimed: no lunar surface station has a published surveyed accuracy, no lunar differential-correction link has a published latency or message format, and the quantization result is a closed form rather than a measurement. RTKLIB — already the external-code oracle for the single-difference and weighted-least-squares kernel — could be driven with a deliberately mis-surveyed base to confirm the 1:1 survey transfer, but that is independent code over the same first-order line-of-sight algebra. MAGNITUDES ARE MODELLED: the survey default is this crate's own lunar frame-realisation allocation rather than a measured station, the latency and bit count are ILLUSTRATIVE inputs, and growth of the broadcast ephemeris error VECTOR itself is not modelled at all — stated in the emitted ageing-law string, because it is the term most likely to dominate a real link | lunar_dpnt | lunar_dpnt::tests (a purely-additive guard whose key-set delta is exactly {correction_link, units} with every pre-existing value bit-identical against literals captured before the change; survey error does NOT decorrelate with baseline while the orbit term does, and survives a zero baseline where the orbit term is exactly zero — the structural check that catches wiring the term into the wrong place; a 1 m station error transfers 1:1 and is proved not DOP-amplified; zero latency reproduces the un-aged residual bit-for-bit and the residual is monotone in latency, with the emitted curve equal to direct runs; the quantization step halves exactly per bit and σ² = step²/12, and the full scale tracks the injected magnitudes; each term switched off in turn recovers the other two in quadrature; equal per-satellite σ propagates to exactly σ·PDOP and that PDOP agrees with orbit::dop; every emitted field carries a unit and a provenance class, checked in both directions) |
| Spatial, noisy, multi-family cislunar arc-length observability | The cislunar arc-length observability threshold in the SPATIAL six-state CR3BP rather than the planar four-state, across DRO, L2 halo and L2 near-rectilinear halo families, with measurement noise entering the Gramian and TWO criteria reported because there is no single honest one: the published rank criterion, which is provably invariant to a homoscedastic measurement sigma (whitening multiplies the observability matrix by a scalar, leaving the relative singular-value spectrum and hence rank, defect and condition unchanged), and an estimability criterion — the first arc at which the formal 1σ position uncertainty of the chief's initial state falls below a stated bound — which is the one that does move with noise. Each threshold carries the epoch-grid bracket it sits in; an unreached criterion is null with a reason. Planar mode remains the default and out-of-plane families are refused there rather than flattened into a state that cannot represent them | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — An independent row-echelon rank by Gaussian elimination with partial pivoting confirms every six-state rank verdict — a different algorithm sharing no code with the eigen/SVD route under test. The 6×6 CR3BP state-transition matrix this composes carries its own ReferenceImpl oracle against SciPy variational integration, and the halo/NRHO initial conditions come from a corrector that reproduces the published L2 southern 9:2 Gateway orbit. The existing square-root-information-filter leg is explicitly NOT counted as corroboration: it consumes the same Jacobians and reduces to the same normal matrix, so it is a consistency check between two numerical machines, and the emitted extension label says so. NOT externally anchored, and ExternalDataset is therefore declined rather than borrowed from the STM's row: the threshold arc lengths themselves depend on the MODELLED constellation design, the epoch grid, and — measurably, by up to 40× — on the singular-value tolerance. The published planar 2.09 h is reproduced exactly at rel_tol = 1e-6 and is itself tolerance-dependent (10.25 h at 1e-4, 0.42 h at 1e-8), which is a property of the criterion rather than of the orbit. No public dataset publishes an arc-length observability threshold for a chosen cislunar constellation. MEASURED RESULT: the spatial six-state threshold is 22.17 h for the L2 NRHO and 40.42 h for the L2 halo, and DOES NOT EXIST for the planar-DRO family the published claim was derived on — rank 4 of 6 with datum defect 2 and two exactly-zero eigenvalues, a structural defect no arc length recovers | cislunar_observability, observability_gramian, intersat_range, cislunar_srif | cislunar_observability::tests and observability_gramian::tests (the default document pinned bit-for-bit by FNV-1a of its JSON, summary and SVG, with explicit-default values asserted to be a no-op and the eight extension keys asserted ABSENT so the capture cannot be regenerated into a self-comparison; rank invariance under a homoscedastic sigma asserted at σ = 0, 0.1, 1, 10, 100 m; σ_pos asserted to scale exactly linearly with σ to 1e-6 relative; the DRO null space asserted to be exactly the z and ż coordinate axes with the two causes separated — a range row between coplanar spacecraft has û_z = 0, and the CR3BP out-of-plane block decouples exactly at z = 0; spatial Jacobians against central finite differences and against the crate's independent 3-D range-rate observable; out-of-plane families refused in planar mode) |
| Operational-style Earth-orientation prediction error, measured predicted-versus-final | A least-squares bias-plus-rate fit over a trailing window plus the principal periodic terms — annual, semi-annual and the two principal zonal tides for UT1; Chandler, annual and semi-annual for the pole — extrapolated with the last in-window residual carried forward: the class IERS Bulletin A uses, in place of the persistence predictor the published horizon rested on. Scored the only honest way: a forecast for T+h built from rapid Bulletin A rows at or before T, measured against the LATER-PUBLISHED Bulletin B final at T+h, with persistence scored over the identical epoch set against the identical finals beside it. A target epoch with no published final is dropped rather than re-scored against the rapid column; a periodic term the window cannot constrain is reported as rejected with the cycles it actually spans; an incomplete window is refused rather than quietly shortened | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Three independent routes, none of them a published prediction-accuracy figure. (1) An analytic signal with known coefficients — the only way to exercise the periodic machinery, since no committed series is long enough to admit an annual term. (2) The textbook closed-form least-squares solution, different algebra from the matrix solve under test, on real rows. (3) The genuine archived Bulletin A prediction rows the real 2026 product publishes, compared per lead as an AGREEMENT statistic and explicitly not as an error: 0.256 ms at 1 day, 0.695 ms at 2 days, 1.252 ms at 3 days, drifting to 3.885 ms at 9 days. So this is Bulletin A's CLASS, close at short lead, not Bulletin A. The predicted-versus-final residuals are real measured quantities over real IERS rows, but their magnitude is checked only against the DIRECTION of the comparison, never against an IERS-published accuracy number — reading a real product is provenance, not an oracle. MEASURED: at day 1 the operational predictor gives 3.78 m of Moon-frame error against persistence's 11.39 m (3.01×), at day 2 10.23 m against 21.72 m (2.12×), at day 3 20.33 m against 30.57 m (1.50×) — and it is WORSE beyond three days (0.87× at 5 days, 0.43× at 10), which the report emits rather than showing only the horizons that flatter it. NOT reproduced: the autoregressive residual filter and the tabulated zonal-tide reduction, the 365-day operational window is unreachable with the committed data, and NO archived earlier vintage of the series exists in this repository — so the archived-vintage table reports no rows rather than scoring a synthesised one | frame_eop, realtime_frame_eop | frame_eop::tests, realtime_frame_eop::tests and tests/operational_eop_predictor_reference.rs (analytic-signal coefficient recovery to 1e-9 at a 365-day window; a bias-plus-rate fit equal to the closed-form ordinary-least-squares slope and intercept to 1e-12 on real rows; TWO look-ahead detectors that wreck the rapid UT1 and pole columns of every row after the issue epoch — leaving the Bulletin B finals intact — and demand bit-identical output, mutation-verified to turn 10 tests red when the fit barrier is loosened by exactly one day; an independently rebuilt epoch list; a target's Bulletin B block blanked and the epoch shown to leave the table; term admission checked at 6, 15, 150 and 365-day windows; monotone row counts; and a frozen pre-change capture of the default report asserted field for field with no tolerance, which additionally asserts the capture does not contain the new keys so it cannot be silently regenerated into a self-comparison) |
| Lunar frame datum from an observing campaign | The seven-parameter Helmert datum propagated from a SIMULATED OBSERVING CAMPAIGN instead of recovered from an injected transform. Earth stations observe a sourced catalogue of lunar-surface beacons over an explicit schedule; the lunar-VLBI delay partials are accumulated into a beacon-coordinate Fisher information matrix and pushed through the Helmert design A = [I₃ | [p]ₓ | p] into H = AᵀM_bA, so the reported datum accuracy is a function of the observing programme — exactly linear in the delay sigma and monotone in the arc through the libration the report MEASURES. The datum defect is the subject rather than a footnote: rank, defect, condition number, spectrum, unobservable directions in the seven-parameter basis, the weakest direction even at full rank and each parameter's share of it are emitted on every run, and any parameter the campaign does not constrain is published as NULL with a status. Beacon-error correlation is MEASURED, not assumed — exactly zero with the stations held fixed, and printed with its cost when they are estimated. Runnable as the `lunar-frame-campaign` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Closed-form identities and an independent in-repo route, with no external oracle claimed. The Helmert design — the only new derivative in the module — is re-derived by central finite difference of lunar_frame_realise::apply_helmert, a path sharing no expression with the analytic form. The accumulation it composes is lunar-vlbi-fim's, whose Jacobian is finite-differenced against lunar_vlbi::vlbi_delay_s there, and whose linear-algebra kernel is separately externally anchored against numpy in tests/fim_observability_reference.rs — this row borrows neither status. The physics oracle is structural rather than numerical: a beacon delay partial is the near-field DIFFERENCE of two near-parallel unit vectors, so the worst-determined translation direction MUST be the body-fixed direction to Earth, and the test asserts the computed answer against the separately measured direction. MEASURED: campaign-derived translation sigma 6.3975 m against the injected-transform scenario's 0.3125 m recovery error (20.5× tighter), while rotation and scale run the OTHER way at 2.32× and 13.5× looser — the injected path assumes one isotropic sigma and so spreads its error uniformly across seven parameters, which the delay observable does not. Rank 7/7 but condition 3.8e5, with one direction 99.57 % pure translation-toward-Earth and forty times worse than any other. WHAT THIS ROW DOES NOT CLAIM: that the campaign figure is right in absolute terms. It establishes that the figure now DERIVES from a schedule, a geometry and an error model rather than from a planted answer. Stays ReferenceImpl/MODELLED: no published lunar-VLBI campaign-plus-datum-covariance pair exists, the station network and delay sigma are ILLUSTRATIVE inputs (the beacon catalogue is sourced, the campaign is not), observations are treated as independent while a real session's troposphere and clock are correlated between nearby scans, and the ephemeris, clocks, troposphere and Earth-orientation parameters are held FIXED | lunar_frame_campaign (composing lunar_vlbi, lunar_vlbi_fim, fim, lunar, lunar_frame_realise, frames, cio, lunar_frame) | lunar_frame_campaign::tests (21 lib tests: the Helmert design against a central finite difference of lunar_frame_realise::apply_helmert — the module the datum is FOR, which computes no derivative and so pins the [p]ₓ sign convention — all 84 design entries agreeing to < 1e-6; a pure network translation read back as a pure translation with < 1e-6 leakage into the other six parameters; the datum sigma exactly linear in the delay sigma to 1e-8 over a 3× change on all seven parameters; a 16 h arc measured worse and a 48 h arc measured better than 24 h, with the emitted libration sweep ordered the same way; the worst translation axis asserted to BE the dominant axis of the separately measured body-fixed direction to Earth and worse than the others by > 5×, a physics oracle nothing in the solver was told about; three collinear beacons producing a defect with every datum sigma NULL and the null directions emitted in the seven-parameter basis; offblock_fraction and inter-beacon correlation exactly 0.0 with the stations fixed and both > 0 with them estimated; the comparison block's injected-transform figures shown equal to an independent run of that scenario to 1e-14 relative rather than transcribed; a guard that no injected/recovered datum appears anywhere in the document; the lunar-frame-realisation emission pinned byte-for-byte by FNV-1a-64 over json‖summary‖svg for three input shapes, fingerprinted before the work began) |
| Independent-estimator corroboration of the cislunar arc-length threshold | A batch least-squares estimator that RECOVERS the chief's initial state from simulated inter-satellite measurements over growing prefixes of the same epoch grid the rank-vs-arc table uses, with the measurement partials taken as central finite differences of the composed forward model. It consumes none of the machinery the threshold was measured with — no analytic Jacobian row, no variational state-transition matrix, no singular-value or eigen decomposition, no rank tolerance, no square-root information filter — and shares only the dynamics, the initial conditions, the scalar observable and the epoch grid, each named in the emitted document. Two criteria, both swept: noise-free recovery (the rank analogue) and Monte-Carlo estimability (the estimability analogue, measured against a known truth rather than predicted from a covariance). Runnable as the `cislunar-arc-recovery` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — A separate estimator in this codebase on a different algorithm and a disjoint code path: nonlinear weighted Gauss-Newton with finite-difference partials, its verdict read as a measured state-recovery error in km and mm/s. It has no expression in common with the Gramian's rank-and-covariance route, and the separation is ENFORCED by a source-text guard rather than asserted. MEASURED on the published planar DRO grid: the ESTIMABILITY criterion is CORROBORATED — the measured Monte-Carlo boundary is 5.739130 h against the formal 5.739130 h (ratio 1.0000), and the measured RMS reproduces the formal 1σ over 21 arc lengths to a geometric-mean ratio of 0.9804. The RANK criterion is NOT corroborated as a recoverability boundary: the estimator recovers from 0.782609 h against the Gramian's 2.086957 h, ratio 0.375, and at 1.826087 h — the last prefix the rank read scores 3 of 4 — recovers to 1.96e-5 of the a-priori displacement. The recovery boundary is unmoved over three decades of its own bound while the rank threshold spans 'never' to 0.782609 h over four decades of rel_tol, and the two coincide exactly at rel_tol = 1e-8. That span was first recorded as reaching 0.260870 h; that figure was an ARTEFACT, produced by a rank read that counted 4 directions from 2 measurement rows below the f64 noise floor, and it is corrected here rather than left standing. The rank read is now bounded by Sylvester's inequality with the reason emitted, and the corrected span saturates at exactly the arc where the independent estimator recovers, which strengthens this row's cross-validation rather than weakening it: the published 1e-6 is a conservative singular-value CONVENTION, not a statement about recoverability. Same pattern spatially: NRHO 9.290323 h against 21.677419 h, halo 22.978723 h against 39.829787 h, with estimability agreeing exactly in both. The planar-DRO six-state recovers at no arc, independently reproducing that family's structural datum defect from an estimator told nothing about it. NOT externally anchored — the dynamics and initial conditions are shared with the analysis under test and no public dataset publishes such a threshold — so ExternalDataset is declined | cislunar_arc_recovery, batch_ls | cislunar_arc_recovery::tests and tests/cislunar_arc_recovery_reference.rs (both boundaries and their ratios pinned on the published grid; the measured error curve compared to the formal covariance row by row with a per-row factor-of-two bound and a geometric-mean bound; a NEGATIVE CONTROL — the planar-DRO six-state — asserting the criterion CAN fail and that the unregularised estimator diverges past 1e6 km rather than returning a plausible small error; parameterisation invariance asserted on every prefix to 1e-3 relative; a source-text guard that strips comments, string literals and the test module and then fails on any mention of the Jacobian, STM, SVD-rank or SRIF machinery, mutation-verified by injecting a forbidden call; a test-only check that the finite differences equal the analytic rows, so the linearisation is known good while the analytic route stays absent from the estimator; determinism asserted byte-for-byte; the released cislunar-observability document pinned by key set, canonical fingerprint and summary line) |
| Lunar service volume from real, retrieved constellation geometry | Accepts a tabulated Moon-centred state ephemeris (the evaluation of an SPK/BSP kernel) or a published constellation definition behind `ephemeris_path`, runs the identical coverage / DOP / protection-level sweep against it, and emits the σ_URE ranging requirement it implies BESIDE the unchanged illustrative Keplerian and perturbed results with the difference as its own named quantity. Every figure carries a provenance class that distinguishes kernel-derived from published-element-derived from modelled, so the two can never be confused in a downstream quotation | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — The GEOMETRY is external and hashed: three fixtures whose numbers come only from documents retrieved with URL, retrieval date and SHA-256, regenerable by committed generators that verify the upstream hash and ABORT rather than emit a number — the LANS interoperability-demonstration reference constellation (NASA NTRS 20250009447, SHA-256 d1b916be…), the LNCSS case studies (NAVIGATION 70(4) navi.613, CC BY, SHA-256 4e294687…), and a genuine flown-spacecraft ephemeris for LRO, Danuri, Chandrayaan-2 and CAPSTONE evaluated from JPL's own reconstructed kernels via Horizons. NO lunar-navigation constellation kernel exists publicly — Moonlight/LCNS, LCRNS and LNSS are not flying and NAIF publishes nothing for them — and none was invented. The DERIVED σ_URE requirement has NO external oracle (nobody publishes the ranging accuracy a 50 m lunar HPL demands over this service volume), so it is checked against its own algebraic identity and, independently, by re-running the whole sweep at the computed requirement and confirming availability flips there. MEASURED: the published 8-satellite design needs σ_URE 2.9044 m at 100 % coverage against the illustrative constellation's 0.3591 m at 37.85 % — an 8.09× revision of a published number under programme rule R4. The qualitative conclusion survives (LNIS-class 30 m still does not close a 50 m south-polar HPL) but the shortfall was overstated eightfold. The 5-satellite LANS demo yields ZERO protection-level samples — five satellites cannot give the six-in-view a single-fault hypothesis set needs — and the requirement field is ABSENT rather than fabricated; likewise for the four real spacecraft at 0 % coverage. InternalConsistency is the honest kind: the INPUT data is external and hashed, but the quantity this row is about is validated only against itself | lunar_ephemeris, lunar_service | lunar_ephemeris::tests (format and frame parsing; Lagrange interpolation exact at nodes and on a linear track off-node; ICRF elements take the IAU 2015 reduction and are byte-equal to an explicit icrf_to_iau_moon application; true↔mean anomaly round-trips against a forward Kepler solve; malformed files refused with the reason named). lunar_service::tests (with `ephemeris_path` unset the report's key set and SHA-256 are pinned; the Keplerian row equals the standalone Keplerian run field for field; the identity σ_required · HPL_max / σ_URE = AL, then an END-TO-END re-run at the computed requirement reaching 100 % protection-level availability and a re-run 1 % above it not reaching it; every emitted numeric field of both new blocks walked from the produced JSON for a unit and a provenance class; the committed fixtures matched to their source tables satellite for satellite; a horizon past the end of a table refused) |
| Unit and provenance declared for every reported quantity | A machine-readable schema giving unit, provenance class and definition for every numeric field of every scenario report, plus a single global gate that runs every registered scenario kind and fails if an emitted numeric field lacks either. The provenance vocabulary is closed and each class carries an evidence tier, with two classes deliberately mapped to `inherits-scenario-label` and `depends-on-input` rather than being assigned a tier the class does not determine | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — The emitted document itself: every numeric leaf must resolve to an entry in that document's own units block. There is no external unit registry to check a DECLARED unit against, so a declared unit is a reviewed assertion and not a verified one — the gate verifies COMPLETENESS and WELL-FORMEDNESS, not truth, and Validated would be wrong because nothing external confirms that `m` is the right unit for a field named `_m`. An independent name-suffix cross-check was run over the 1,434 described fields: of the 691 carrying a unit-bearing suffix, 40 disagree with the declared unit and all 40 are explained (per-second suffixes, minima, aperture-seconds, newton-metres against a nanometre-looking suffix), so no wrong unit surfaced. COVERAGE MOVED 7 of 56 kinds to 56 of 58, and 389 of 1354 fields to 1434 of 1477. Two kinds remain uncovered and are named with reasons rather than hidden behind a wildcard: `sweep-nd`, two of whose columns are caller-keyed so their units are data, and `cislunar-observability`, whose released document is byte-frozen by an explicit additivity pin asserting it has no units key — adding one is a decision about that pin, not about units. The work also surfaced twelve unit or documentation defects in existing code, reported rather than fixed under R1 | field_schema | tests/field_units_global.rs (all 58 registered kinds run, one document shape each, ~31 s: every numeric leaf must resolve to an entry in that document's own units block; a malformed entry counts as missing for EVERY kind, exempt or not, so a placeholder buys no coverage; the exemption list may not exceed its pinned ceiling, a listed kind that turns out to be fully covered FAILS the gate so the list cannot be padded, and a registered kind absent from the runner table fails so a new pack cannot slip in unexamined — which it did, catching both kinds added after this work began; a one-way ratchet on the described-but-undefined backlog; and a staleness check on the committed schema document); field_schema::tests |
| Lunar frame datum from a REAL observing campaign | The seven-parameter Helmert datum covariance, with its two simulated inputs replaced by measured ones: the schedule is the ground-transmit epochs of 337 archived ILRS lunar laser-ranging normal points (2015-04-08 to 2015-06-27, Grasse MeO 7845 and Matera MLRO 7941, all five retroreflector arrays) and every observation weight is that point's own archived precision bin_rms/√n_raw — median 5.13 mm of one-way range, read out of the file. Station coordinates IERS ITRF2020, reflector coordinates JPL DE430 Table 7. Runnable as the `lunar-llr-datum` scenario kind | ReferenceImpl | checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative — Closed-form identities and an independent in-repo route; NO external oracle is claimed for the covariance, because no published lunar-LLR datum-covariance pair exists to check it against. The only new derivative — the range partial with respect to the reflector's body-fixed position — is re-derived by central finite difference of the two-way light time it differentiates, a path sharing no expression with the analytic form. The physics oracle is structural: the partial of a range IS twice the line of sight, so the body-fixed coordinate along the mean direction to Earth must be determined far better than the two plane-of-sky coordinates, which only the libration reaches — measured at 50.7× to 71.7× across the five arrays against a libration sweep the report measures independently, with the isotropic small-angle prediction and the transverse anisotropy that explains the gap both printed. WHAT CHANGED: the schedule, the observation count and every observation weight are now measured; 337 of 349 archived points are used and the 12 that are not are skipped and counted, because ITRF2020 carries no position for Apache Point. MEASURED: datum translation sigma 1.851746e-2 m against the SIMULATED campaign's 6.3975 m (345×), rotation 36×, scale 24× — a ratio between a laser-range network and a VLBI-delay network, so a finding rather than a validation. Reflector information rank 15/15 with inter-array coupling exactly 0; Helmert rank 7/7, condition 2.4e4. WHAT THIS ROW DOES NOT CLAIM: that the figure is right in absolute terms. A real LLR solution co-estimates the lunar orbit, physical librations, Earth orientation, station coordinates and tidal and relativistic parameters, and reports decimetres (DE430 Table 7's own 0.12-0.27 m) where this bound is far smaller; this is a Cramér-Rao bound for a stated reduced parameter set, not an accuracy. Stays MODELLED: the Moon-centre ephemeris and the IAU 2015 body orientation are modelled, and troposphere, tides, station eccentricity, polar motion, UT1-UTC, relativistic delay and station clocks are absent. Their combined size is PUBLISHED rather than argued — observed-minus-computed one-way range 156,494 m RMS over the 337 points — and their effect on the covariance is BOUNDED rather than argued: re-solving the entire datum with every partial tilted by 0.1° (twice the measured worst-epoch ephemeris tilt, sign alternating) moves the deliverable by 0.288 % | lunar_llr, realdata::llr_crd (composing fim, cio, frames, ephem, lunar_frame, lunar_frame_campaign) | tests/lunar_llr_real_data.rs (11 tests: all 15 committed CRD files byte-identical to their recorded digests; all 349 records accounted for, 337 used and 12 skipped for a named reason; every archived range inside the real perigee/apogee envelope; the weights shown to BE bin_rms/√n_raw; the line-of-sight coordinate best determined for every array with the libration sweep that buys it measured separately; the residual and its independent confirmation against JPL Horizons; the 0.1-degree geometry-tilt sensitivity; the simulated-campaign comparison shown equal to an independent run of that scenario; an R1 bit-for-bit pin on the three pre-existing lunar frame packs); lunar_llr::tests (12: the range partial against a central finite difference of the modelled time of flight to < 1e-6 relative; the light time a converged lunar round trip; the datum sigma exactly linear in the weight scale to 1e-9; block-diagonality exact; a missing data directory refused rather than substituted; an edited catalogue row caught by its own radius column); realdata::llr_crd::tests (7: field semantics, midnight rollover, refusal of a non-UTC time scale and of an unsupported format version, and no substituted sigma for an empty bin) |
| Gate integrity — a green that means what it says | Three structural guards over the verification process itself, each closing a class of defect that reached the canonical gate as an intermittent or spurious red. (1) Every constructed temp path in the Rust sources must carry a per-call unique component; a process id is rejected, because cargo runs the library tests as parallel threads of ONE process and the pid is shared by all of them. (2) Every byte-for-byte or hash pin must declare, next to itself or in its module header, what it covers and what it deliberately excludes — so a cross-cutting change can tell at a glance which pins are in scope and which have silently become repository-wide change detectors. (3) A green is claimable only from the FULL suite: scripts/gate.sh runs `cargo test --all`, captures the true exit code with no pipe in the way, and writes a receipt naming the commit, the integration-binary count, the test count and the duration; the pre-push check refuses a push whose commit no valid receipt names, on a clean tree. Repeatability is sampled separately by scripts/check-repeatability.sh, which runs the library suite N times and fails if the set of passing tests differs. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form: each guard is run over a fixed known-bad snippet that must fire and a fixed known-good snippet that must stay silent, both literal constants the detector cannot influence. The two known-bad snippets are the F22 and F25 defects in their original shape. This is an INTERNAL oracle and the row is MODELLED accordingly: it proves the guards discriminate the defect from its fix, not that the classes they describe are exhaustive. Their stated blind spots — shared state that is not a path, a pin held in a short named constant, a rare race that three runs do not sample, and a receipt that anyone who can write the file can forge — are written out in the module documentation of tests/source_guards.rs and in each script's header rather than left to be discovered. | scripts/gate.sh, scripts/check-gate-receipt.sh, scripts/check-repeatability.sh, scripts/install-gate-hook.sh | tests/source_guards.rs (9 tests: both guards over the whole source tree, plus mutation fixtures that grade each guard in both directions — the F22 pattern reported on both colliding paths, the shipped atomic-sequence fix accepted, a half-fix reported on exactly the path that lost its unique component, a tempfile handle and an inherited unique directory accepted, a wall clock rejected; an undeclared pin reported, a declared one accepted, a scope without an exclusion rejected, a declaration in the enclosing test's doc comment accepted and shown not to leak to the next test; and each pin spelling — hex, decimal, digest string, byte length, named byte count, golden file — seen while algorithm constants, RNG seeds and small cardinality checks are not) |
| Composed timing PL — scalar MHSS specialization (H=1_N) | Scalar-time solution-separation TPL over heterogeneous sources; PL driven by worst-exclusion subset noise + UTC(k) bias | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Direct MHSS integrity-risk sum Σ p·Q((PL−b−T)/σ) cross-check; ARAIM lineage Blanch 2015 / Joerger 2014 | src/integrity/tpl_scalar.rs | integrity::tpl_scalar::tests (rank-1, fuse/exclude, bias-dominance, IR cross-check) |
| Composed timing PL — P0-seeded holdover ride-through | PL(τ)=max(TPL_handover,HPL(τ)); lower-semicontinuous PL(0+)≥PL(0−); K(IR/2) running-max; τ/τ³/τ⁵ phase exponents | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Property tests (monotonicity, no-drop-at-handover) + exponent lint against holdover::coast_phase_variance | src/integrity/composed_pl.rs | integrity::composed_pl::tests (monotone, P0-floor, K(IR/2), exponents, lower-semicontinuity) |
| Composed timing PL — LIL a.s. envelope (impossibility + consistency) | No finite worst-case holdover (Brownian sup diverges); IR-allocated HPL consistent with Hartman-Wintner envelope as IR→0 | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form a.s. envelope √(2Dt·lnln t) identity + HPL-dominance check; Baweja arXiv:2606.24210 impossibility seam | src/integrity/lil_envelope.rs | integrity::lil_envelope::tests (divergence, threshold, IR-tightening dominance) |
| Heterogeneous UTC(k) traceability-bias integrity overbound | Per-source bias overbound b = (U/k_cov)·Phi^-1(1-tail/2) + ageing, inflating a published Type-B expanded uncertainty to an allocated integrity tail; bridges to tpl_scalar as bias_s | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy + stdlib-statistics reproduction of the overbound closed form (InternalConsistency). The BIPM Circular-T [UTC-UTC(USNO)] series is a CITED input only — it is the SAME series already Validated for the R4 holdover-coverage row and is NOT re-validated here; reproducing its values proves nothing about R2. Deep integrity tail is Modelled. | src/integrity/hetero_budget.rs | integrity::hetero_budget::tests + tests/hetero_budget_reference.rs |
| Correlated traceability-bias cross-covariance (common-mode-unsafe allocation) | N×N bias cross-covariance with rho·b_i·b_j off-diagonals for sources sharing a UTC(k) realizer; PROVEN correlated_fused_bias >= independent_fused_bias (naive independent allocation under-bounds the fused bias -> optimistic -> unsafe) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy reproduction of the cross-covariance and the correlated-vs-independent fused bias inequality (InternalConsistency). Representative source set; Modelled scenario. | src/integrity/hetero_budget.rs | integrity::hetero_budget::tests (correlated_fused_bias_dominates_independent_when_correlated, rho_one_single_realizer_recovers_linear_sum) + tests/hetero_budget_reference.rs |
| GLS common-mode whitening (Aitken) + Mahalanobis identity | Hand-rolled Cholesky Omega=LL^T and forward-substitution whitening z=L^-1 r (Cov(z)=I when Cov(r)=Omega); Mahalanobis square z^T z = r^T Omega^-1 r | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy Cholesky/solve reproduction of the whitened Mahalanobis square (InternalConsistency). GLS/Aitken 1935 whitening is Cited. | src/integrity/gls_commonmode.rs | integrity::gls_commonmode::tests + tests/gls_reference.rs |
| Common-mode consistency statistic (separation-blind shared-reference fault) | Score statistic (1^T Omega^-1 r)^2/(1^T Omega^-1 1) ~ chi^2_1 for a common-mode shift that solution separation (contrasts orthogonal to 1) cannot see; a common-mode shift inflates it while pairwise separations stay flat | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Independent numpy reproduction of the statistic + property test that a common-mode injection inflates it (InternalConsistency). Modelled scenario. | src/integrity/gls_commonmode.rs | integrity::gls_commonmode::tests (common_mode_shift_inflates_statistic_but_not_contrasts, post_fit_common_mode_statistic_is_zero) + tests/gls_reference.rs |
| Residual-outside-Omega undetectable common-mode bound | Irreducible undetectable common-mode error: min(alpha_ss, alpha_cm) fault magnitude escaping BOTH separation (whitened contrast norm) and the common-mode statistic (1^T Omega^-1 d); INFINITY when the fault direction lies outside the modelled Omega common axis (published honest blind spot) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Property tests over the finite/infinite detectability boundary (InternalConsistency). PROVEN blind-spot bound; no accuracy claim. Modelled. | src/integrity/gls_commonmode.rs | integrity::gls_commonmode::tests (separation_alone_is_blind_to_common_mode, degenerate_direction_or_non_pd_gives_no_finite_ceiling) |
| Lunar datum null-space classification (LLR rank-additivity + libration defect-lift) | Classification of the internal-ranging datum problem: a single range observation contributes rank 1 (6-dimensional null space); the origin-X and scale pair is near-null and physical DE440 libration lifts the defect to zero while the pair stays near-degenerate | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Engine-reproduced geometric structure plus the closed-form 2x2 Schur identity; consistent in STRUCTURE with Sosnica et al. 2025 (arXiv:2510.15484), whose reported magnitudes are NOT reproduced here. The classification is structural; the correlation/CRLB magnitudes under real geometry are MODELLED (reflector coordinates and orientation held fixed). | lunar_identifiability, lunar_datum | tests/lunar_datum_identifiability_reference.rs (single_internal_range_row_has_six_dim_datum_null_space; extending_the_librating_arc_lifts_the_origin_scale_degeneracy) |
| Multi-technique lunar datum information (LLR + lunar VLBI + orbiter range) | Datum-Jacobian rows for Earth-reflector LLR range, two-station lunar-VLBI differential delay, and orbiter-to-beacon range over the 7-parameter datum, combined into one consistently-preconditioned Fisher; demonstrates that off-radial (orbiter / depth-diverse) tracking breaks the origin-X to scale degeneracy where transverse VLBI helps only indirectly | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Analytic-vs-finite-difference cross-checks of each technique's partials (internal); the improvement DIRECTION is a geometric fact. Beacon locations, schedules and noise are MODELLED/representative (see tests/fixtures/llr_geometry/NOTICE.md). | lunar_datum, lunar_identifiability | lunar_datum::tests (LLR/VLBI/orbiter analytic partials vs finite difference); lunar_identifiability::tests (adding_an_offradial_technique_collapses_the_origin_scale_degeneracy; transverse-vs-radial via crlb_diag) |
| DE440 lunar principal-axis orientation provider | MOON_PA_DE440 to J2000 rotation at arbitrary epochs, by element-wise linear interpolation of a committed 731-row daily series with column Gram-Schmidt re-orthonormalisation; embedded at compile time so there is no runtime filesystem I/O and the WASM build carries it | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — The series itself is external: JPL DE440 binary PCK moon_pa_de440_200625.bpc, NAIF frame 31008, extracted by the committed scripts/gen_de440_moon_pa.py via spiceypy 8.1.2, fixture SHA-256 3076f81ef95d83f5efa240ed4c7ccb422f109407dde841fcf28d42dc63586eb7. What is NOT independent: the node-level test round-trips through the same embedded copy the engine reads, so it checks the parser and interpolator, not JPL. The independent content is physical - the recovered sub-Earth libration spans 15.6 deg in longitude and 13.6 deg in latitude, which is the known lunar optical libration, and a constant or mis-scaled series cannot produce it. Interpolation between the one-day nodes is MEASURED, not asserted, at about 14 m at the lunar surface after re-orthonormalisation; the module is therefore a geometry substrate for identifiability analysis and is NOT sub-metre in absolute orientation. | lunar_orientation | lunar_orientation::tests (de440_moon_pa_reproduces_fixture_rows, de440_moon_pa_shows_real_libration); tests/lunar_pa_frame_realisation_guard.rs::the_orientation_series_interpolation_error_is_tens_of_metres_not_sub_metre |
| Lunar LLR datum geometry substrate (principal-axis reflectors, ground stations, analytic range partials) | The five near-side retroreflector arrays in PA body-frame metres and the LLR ground stations in geodetic coordinates; reflector body-to-inertial placement through the DE440 PA orientation; analytic partials of Earth-to-reflector range with respect to the 4-parameter datum; and the LLR-only Fisher matrix exhibiting the lunocentre-X to scale degeneracy that motivates the 7-parameter analysis | ExternalDataset | a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled — The computation is checked internally: every analytic partial against a finite difference, and the zero-datum case against the nominal range. The CATALOGUE is checked externally and independently - the DE440 principal-axis coordinates (Park et al. 2021, tests/fixtures/llr_geometry/de440_retroreflectors_pa.csv) are cross-checked against Table 6 of the DE430 surface-coordinates memorandum (tests/fixtures/lunar_llr/de430_retroreflectors_pa.csv, machine-extracted from a SHA-256-verified PDF by tests/fixtures/lunar_llr/generate_de430_retroreflectors_pa.py) and agree to 1.12 m, while the mean-Earth realisation of the same five arrays differs by 672 to 871 m. The DEGENERACY STRUCTURE is checked against a published result: Sosnica et al. 2025, 'Definition and Realization of the International Lunar Reference Frame', arXiv:2510.15484, which reports for the lunar principal-axis frame a lunocentre-X to scale correlation coefficient of r = -0.97, and that LLR fails to reach the actual centre of mass of the Moon with an accuracy better than 12 cm because of that correlation. This module recovers the same structure (|corr(t_x, scale)| between 0.9 and 0.9999, datum defect <= 1) from an LLR-only Fisher design. The corroboration is across ephemerides, not a round trip: the paper combines INPOP21a, DE430 and EPM2021, whereas this module is driven by DE440 libration. What is NOT reproduced is magnitude - the correlation here is about -0.988 against their -0.97, and the 4-parameter CRLB is sub-millimetre against their 12 cm achieved floor, because orientation and reflector coordinates are held fixed here and solved there. Geometry and degeneracy structure only; no accuracy claim about a solved datum. | lunar_llr_geometry | lunar_llr_geometry::tests (reflector_and_station_catalogs_are_well_formed, analytic_partials_match_finite_difference, llr_one_way_range_is_earth_moon_scale, zero_datum_reproduces_nominal_range, llr_only_fisher_shows_strong_com_x_scale_degeneracy); tests/lunar_pa_frame_realisation_guard.rs; tests/llr_datum_degeneracy_reference.rs |
| Range to clock-offset degeneracy in one-way lunar ranging, and the geometric-diversity design law | The per-node radial-range to receiver-clock-offset degeneracy is exact at 1 m to 3.336 ns (one over c). The {scale, offset} Schur-complement marginal (coupled_marginal_fisher) shows that in a geometrically diverse network two-way ranging lifts the marginal by about the same factor as an equal count of additional one-way data, while in the idealised single-node regime the two-way lift is orders of magnitude larger. The design law that follows: geometric diversity, not two-way ranging as such, is what separates lunar frame scale from timescale offset in one-way ranging; a two-way or external time tie is required only in the low-diversity or single-user regime. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Schur-complement marginal Fisher of the coupled information matrix, in closed-form linear algebra, checked against the two limiting regimes it predicts. The 1 m to 3.336 ns equivalence is the definition of the metre via c and is not an empirical result. The observation networks are representative Modelled geometry, so the design law is a statement about the geometry presented to it and carries no claim about any fielded lunar network. | lunar_gauge | lunar_gauge::tests (coupled_marginal_well_posed_network_is_psd, coupled_marginal_twoway_equals_more_oneway_in_diverse_network, coupled_marginal_twoway_lift_three_orders, oneway_range_row_has_correct_temporal_entries, twoway_range_row_has_zero_at_offset_and_rate, time_tie_row_equals_pure_offset_vector, rate_tie_row_has_correct_structure) |
| Relativistic clock-rate to frame coupling for the lunar timescale | rate_frame_jacobian gives the sensitivity of the lunar timescale rate to the frame realisation: d_alpha/d_scale = +U_moon/c^2, about +3.140e-11; d_alpha/d_velocity about -1.11e-14; d_alpha/d_r_radial = +g_moon/c^2, about +1.807e-17 per metre, with the radial entry equal to the scale entry divided by the lunar radius. Propagated through a frame-estimation datum these bound the rate perturbation at about 2e-17, far below the roughly 1.7e-11 rate offset of a lunar timescale against TT, so a frame re-realisation at this level does not move the timescale rate measurably. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — First-order relativistic rate model - self-potential, kinetic term and redshift gradient - differentiated with respect to the frame parameters in closed form, with the internal identity d_alpha/dr = d_alpha/ds divided by RE_MOON_M checked to 1e-12 so the two derivatives cannot drift apart. The comparison band and the tidal and J2 contributions are Modelled reference-surface figures, not a metrological budget, and no claim is made that a real lunar clock realises this rate. | lunar_gauge, lunar_time | lunar_gauge::tests (d_alpha_d_scale_approx_3_140e_minus_11, d_alpha_d_velocity_approx_neg_1_11e_minus_14, d_alpha_d_radial_approx_1_807e_minus_17, d_alpha_d_radial_equals_scale_over_r_moon) |
| Basis-invariant classification of the coupled frame and timescale null space | classify_null_space decomposes the datum null space into spatial-only (dimension d minus rank U_T), temporal-only (d minus rank U_S) and genuinely coupled (rank U_S plus rank U_T minus d) parts, plus the spatial-to-temporal projector coupling norm p_st_norm, the Frobenius norm of the off-diagonal block of the null-space projector. Every one of these is a function of the PROJECTOR rather than of a chosen basis, so they are invariant under any orthonormal choice of null vectors - which is what makes the classification reportable at all. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Projector-based invariants of the coupled Fisher null space, in closed-form linear algebra, proven by construction and then checked by rotating the null basis and requiring every reported quantity to be unchanged. The invariance test is the load-bearing one: a classification computed from a particular basis would agree with this one on the constructed cases and disagree the moment a real problem produced a different basis for the same subspace. | lunar_gauge | lunar_gauge::tests (classify_is_invariant_under_null_basis_rotation - an axis-aligned null basis and its 0.6 rad rotation yield identical defect, dim_spatial, dim_temporal, coupled_dim and p_st_norm; classify_direct_sum_null and classify_coupled_null - constructed direct-sum and genuinely coupled cases confirm the dimension decomposition; classify_basis_invariant; index_consts_are_correct) |
| Representative multi-technique measurement menu and the additive Fisher combination rule | MeasurementBlock holds one candidate measurement campaign as a 7x7 Fisher information contribution plus a scalar relative cost; block_from_rows builds one from raw datum-Jacobian rows so every block is preconditioned identically through lunar_identifiability::assemble_multi_info; combine sums the information of a chosen subset, which is the correct rule because Fisher information is additive across independent measurements; representative_lunar_menu supplies a deterministic four-block menu (LLR, a transverse VLBI limb beacon, a near-side orbiter and a far-side orbiter). The budget-constrained design optimiser that consumes this menu is not part of this crate. | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Additivity of Fisher information across independent measurements is a closed-form property, checked here against an independently written element-wise sum and against the order-invariance and monotonicity that follow from it. NOTE ON EVIDENCE: the combiner previously had no test at all, and the one test in the module summed the two information matrices inline instead of calling it, so a broken combiner would have left the module green; the test now goes through combine and fails when it is mutated. All beacon locations, orbiter geometry, per-technique precisions and relative costs are representative choices rather than mission values (see tests/fixtures/llr_geometry/NOTICE.md), so every degeneracy metric and CRLB figure reached through this menu inherits the Modelled status of lunar_identifiability::decompose. | lunar_techniques | lunar_techniques::tests (combine_is_additive_order_independent_and_empty_is_zero - empty selection gives the zero matrix, a single selection is the identity, a pair equals an independently written element-wise sum, and the result is invariant under selection order; adding_a_block_never_reduces_the_degeneracy_metric - monotonicity under added information; radial_diversity_beats_transverse_for_breaking_the_degeneracy - the far-side orbiter block raises the degeneracy metric more than the transverse VLBI block) |
| Cross-provider consistency tolerance for a mixed-provider user | consistency_tolerance: inverts a user position budget to a per-parameter inter-provider Helmert agreement requirement (origin/scale/rotation) at a reference lever arm, optionally inflated by the P1 single-provider realization CRLB | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Worst-case triangle bound on the Helmert point-Jacobian action (closed form) | lunar_interop_budget | lunar_interop_budget::tests (monotonicity in budget; RSS budget reduction under a per-provider CRLB; worked rotation tolerance at the lunar lever arm; binding-term = rotation) |
| Multi-provider lunar interoperability error budget and frame-vs-ephemeris design law | interop_budget: reducible (common frame-tie) vs irreducible (dynamics) split under PerProvider / CommonFrameTie / CommonEphemeris conventions, with the irreducible-fraction design-law metric (~0.69 on real DE440/INPOP/EPM: a common frame tag alone leaves the dominant floor) | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — RMS aggregation of the Validated per-pair splits under each convention (closed form) | lunar_interop_budget | lunar_interop_budget::tests (CommonEphemeris zeroes the budget; CommonFrameTie < PerProvider; irreducible_fraction > 0.5 on the real splits; convention ordering) |
| Byzantine block-spark detect/identify bound on the autonomous per-node lunar network (T3) | byzantine_bound instantiates the secure-state-estimation coding / sparse-observability bound on the per-node network geometry: a Byzantine peer injects an arbitrary linear combination of the measurements it participates in, and the network DETECTS any coalition of ≤ f = block_spark − 1 peers and uniquely IDENTIFIES any coalition of ≤ ⌊(block_spark − 1)/2⌋, where block_spark is the smallest peer-coalition whose stacked effective signatures P⊥·B_T are column-rank-deficient. Peer detectability is FULL COLUMN RANK of P⊥·B_j (a nonzero-but-rank-deficient block is a nonzero attack that lands in range(G) and leaves no residual), not merely P⊥·B_j ≠ 0 | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Geometric instantiation of the block-wise spark / secure-state-estimation bound (Fawzi–Tabuada–Diggavi 2014; Shoukry–Tabuada 2016; block-wise spark of Donoho–Elad 2003; Candès–Tao 2005) — NOT the Lamport–Shostak–Pease 3f+1 consensus threshold ('Byzantine' names the arbitrary/colluding fault MODEL only). The specific tolerated-fault count is a Modelled property of the representative network geometry, checked for self-consistency by hand-constructed analytic cases and the count formulas | lunar_faultobs | lunar_faultobs::tests — byzantine_c3_rank_deficient_but_nonzero_is_undetectable (nonzero yet rank-deficient block ⇒ block_spark 1, f_detect 0; independent columns ⇒ block_spark 2, f_detect 1), byzantine_real_network_uniform_bias_is_clock_offset (a peer owning all of a node's measurements = a clock-offset error ∈ range(G), undetectable, with a clear Gram spectral gap), byzantine_redundant_net_identifies_at_least_one (six independent single-measurement peers ⇒ block_spark 7, f_identify 3), byzantine_analytic_spark_identity_projector + byzantine_detect_identify_relations (P⊥ = I hand cases pin f_detect = block_spark − 1, f_identify = ⌊(block_spark − 1)/2⌋) |
| Autonomous-holdover temporal-gauge floor for the self-referential lunar constellation (T4) | holdover_floor establishes that in an ensemble of autonomous nodes connected only by inter-node measurements the common clock rate (δα_j += 1 ∀j) is an ensemble-time free parameter lying in N(GᵀWG): no amount of additional inter-node ranging can observe it (rate_in_gauge = true, temporal_gauge_dim = 2 with the common offset). This is the genuine holdover floor — the temporal analog of the rigid-frame position gauge. Adding one external absolute-rate tie (a direct link to an off-network reference) expels the common rate from the null space (rate_in_gauge = false, temporal_gauge_dim = 1), proving the floor is a real gauge, not an oscillator-model artefact | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Ensemble-time free-parameter argument (Percival 1978; Lewandowski & Thomas 1991) instantiated on the representative real-DE440 per-node network: a relative-residual null test of the analytic common-rate generator against GᵀWG, with the tie-broken contrast distinguishing the genuine gauge from an oscillator-model artefact. Representative Modelled geometry, not a certified timing budget | lunar_faultobs | lunar_faultobs::tests — holdover_floor_self_ref_and_anchored (self-referential net: the common rate lies in N(GᵀWG), temporal_gauge_dim 2; after one external rate-tie row: rate expelled from the gauge, temporal_gauge_dim 1 with the common offset surviving) |
| Provider common/differential split, one-rank-deficiency unification, and protection-gap slope (T5 / §0 / g7) | Three facets of the single decomposition ℝ^{state_dim} = N(GᵀWG) ⊕ range(GᵀWG) with the 8-dim datum⊕timescale gauge as N(G) and the state_dim − 8 = 32 observable directions as range(G): (T5) provider_mismatch_split classifies a common multi-provider bias (∈ range(G)) as UNDETECTABLE — needing an external tie — and a differential bias (∉ range(G)) as self-monitored / DETECTABLE; (§0) the unification is that the SAME range(G) blind subspace governs the undetectable fault class, so the datum gauge N(G) and the fault-blind subspace range(G) are one geometry, not two; (g7) slope returns the Brown protection-gap slope ‖Π_obs Δx̂‖ / ‖P⊥b‖_W → ∞ for a fault b ∈ range(G) (estimator corrupted with zero parity) and finite for a detectable fault | InternalConsistency | checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle — Closed-form parity-projector / pseudo-inverse algebra on the representative real-DE440 per-node network: the common/differential split, the N(G) ⊕ range(G) unification and the Brown (1992) protection-gap slope all follow from range annihilation P⊥·G = 0. Representative Modelled geometry, not a certified protection level | lunar_faultobs | lunar_faultobs::tests — provider_mismatch_split_common_undetectable_differential_detectable (common bias undetectable, differential detectable), slope_infinity_in_range_finite_detectable (g7: slope ∞ for b ∈ range(G), finite for b ∉ range(G)), pernode_rank_is_state_dim_minus_eight (§0: rank(GᵀWG) = state_dim − 8, the 8-dim gauge is the entire null space with a >1e6 spectral gap) |
100 capabilities labelled MODELLED.