AQ-SCN-003 — Scenario 3 specification: Compound system stress
This document specifies the compound scenario in the AQ-SCN series for AQ-NODE-01 (AKQ-NODE-1 in Parts up to 12). It is a specification of an intended procedure. No run of AQ-SCN-003 has been performed at any evidence level, and AQ-SCN-003 may not be run before AQ-SCN-002 has been run to Stage C — several of its parameters are derived from AQ-SCN-002 measurements and cannot be set otherwise.
AQ-SCN-002 applies its injections one at a time so that each effect is attributable. AQ-SCN-003 exists because attributable single effects are not the interesting case: the question is what the three stress axes do to each other.
F1 — IDENTIFIER AND STATUS
- Identifier
AQ-SCN-003. Subject articleAQ-NODE-01. Tier CA for the compound behaviour model, Y1 for the bench implementation. - Current evidence level Concept; target progression Theory → Simulation → Lab validation on rung 1 (optical bench). No stage of AQ-SCN-003 addresses any higher rung of the reach ladder.
- Layers exercised: L1, L2, L4 (AQ-TSE-01), L5 (command authority), L6 (Evidence & Provenance Fabric, primary under this scenario), L7, L8 (advisory only), L9.
- Trust boundaries: TB-2 must be shown unaffected by the stress applied to TB-3 and TB-5; that separation is itself a measured outcome, not an assumption.
F2 — QUESTION THE SCENARIO ANSWERS
When information degrades, the decision window shortens and compute is contended at the same time, does the node degrade in a bounded, observable and recorded way — or does it produce a confident output it has no basis for? “Degrade gracefully” is used in this document with one operational meaning and no other:
Degradation is graceful when, and only when, it is: bounded (the outcome set narrows toward abstain / safe-hold and never widens); monotonic (trust falls on one observation and rises only through the full recovery sequence, DC-4); observable (each narrowing is announced with a reason before it takes effect); recorded (each consequential transition is durably written before its effect, DC-5); and non-oscillatory (state changes stay within the declared flap bound over the window Wo). A node that keeps executing under pressure has not degraded gracefully; it has failed silently.
F3 — EVIDENCE LEVEL AND CLAIM CEILING BY STAGE
| Stage | Executed on | Level reached | Ceiling on what may be claimed |
|---|---|---|---|
| A | Model of the coupled loop (evaluation time, outcome mix, evidence write load) | Theory | That the coupling exists in the model. Nothing about magnitudes. |
| B | Implementation under injected traces plus synthetic host load | Simulation | Behaviour of the implementation under the injected load profile only. |
| C | Optical bench, real feeds, real contention, TB-4 into a dummy load | Lab validation | Behaviour on that bench at those run-card magnitudes. No extrapolation to any other rung, platform or duty cycle. |
F4 — DERIVED PARAMETERS
No numeric target is asserted here. Each parameter below is set on the run card from prior measurement, and the derivation rule is recorded with the run:
Te— measured trust-evaluation completion time distribution from AQ-SCN-002 Stage C (the input, not a target).Wq— the bounded decision window for a command, stepped downward across the observedTedistribution so that the run brackets the point at which the window binds.Wd— the damping window (F7a).Wo— the rolling window over which the flap count is computed; declared flap boundNfis the maximum admissible state changes withinWo.Qe— the durable-write queue depth of the Evidence Fabric, andLethe measured durable-write latency at that depth.
F5 — PRECONDITIONS AND ENTRY STATE
- AQ-SCN-002 Stage C complete, its findings closed, and
Te,Bf,Na,Wa,Bc,Wt,Qfrecorded. - Node in NORMAL with a recorded baseline; DC-1 tagging pre-check clean; Evidence Fabric durable and its queue depth instrumented before the first stressor is applied.
- A quiescent control run at each stress level with no command traffic, so that command-driven and load-driven effects can be separated afterwards.
F6 — STRESSOR SET
| Ref | Stressor | Magnitude (run-card parameter) | Timing | Telemetry label |
|---|---|---|---|---|
| S3-A | Information degradation | A named subset of the AQ-SCN-002 injections applied concurrently: input delay on one feed, absence on a second, divergence between a redundant pair, quality below Qf on a fourth. Magnitudes held at the values that were individually detected in AQ-SCN-002. | Applied first and held for the whole compound phase, so that A alone is never the new variable. | aq.l1.* as in AQ-SCN-002, plus aq.l4.basis.count_undetermined |
| S3-B | Decision-time constraint | Command arrivals with decision window Wq stepped downward across the Te distribution; then a burst profile stepping arrival rate upward at a fixed Wq. | Applied in steps on top of held S3-A; each step long enough to observe steady state and the transient into it. | aq.l5.cmd.window, aq.l4.eval.elapsed, aq.l5.outcome |
| S3-C | Computational pressure | Contention injected on the TB-3 and TB-5 hosts across processor, memory and evidence-store write throughput, stepped until measured evaluation time exceeds Wq for a material fraction of commands. | Applied last, on top of held S3-A and the current S3-B step, so that the coupled loop can be reached deliberately rather than by accident. | aq.l6.queue.depth, aq.l6.write.latency, aq.tb2.acq.jitter |
F7 — EXPECTED BEHAVIOUR
- Decision-window expiry is an outcome, not an error. If trust evaluation does not complete within
Wq, the issued outcome isabstainwith an explicit timeout reason — never a fall-through toexecute, never a cached prior verdict re-issued as current (DC-3). - Hard constraints do not time out into leniency. If Q1–Q3 cannot be established within
Wq, the outcome is deny: the command has not been shown valid and authorised now. Only Q4 yieldsabstain, and Q4 can only ever reduce what Q1–Q3 allowed. - TB-2 separation. Acquisition timestamping at the FPGA must not move with host load. Observed drift in
aq.tb2.acq.jittercorrelated with S3-C is a trust-boundary violation and is reported as such even if every decision outcome was otherwise correct. - Outcome mix narrows monotonically. As stress rises the mix must shift
execute→execute-restricted→safe-hold/abstain. Any re-appearance ofexecuteat a higher stress step than one at which it had already disappeared is a finding.
Abstention is not free. Computational pressure lengthens evaluation, which makes Wq bind, which raises the abstention rate — and every abstention is itself a consequential record that must be durably written, which raises the evidence queue depth, which lengthens write latency, which lengthens evaluation again. The node can be driven into safe-hold by the cost of recording its own caution. This loop is the specific object of measurement in AQ-SCN-003.
Figure 1 - the abstention-record feedback loop under compound stress
+----------------------+ +---------------------------+
| S3-A information | | S3-C computational |
| degradation (held) | | pressure on TB-3 / TB-5 |
+----------+-----------+ +-------------+-------------+
| |
v v
inputs undetermined evaluation time rises
(DC-2: explicit) toward the window Wq
| |
+---------------+------------------+
v
+---------------------+
| outcome narrows to |
| abstain / safe-hold | <-- DC-3, permitted
+----------+----------+
|
each outcome is a Class C
evidence record (DC-5)
|
v
+---------------------+
| L6 durable queue |
| depth -> Qe |
+----------+----------+
|
if a Class C record cannot be durably written
within Wq -> safe-hold, state at most RESTRICTED
|
+-----> feeds back into evaluation time
F7a — DAMPING WINDOW Wd
Wd exists to stop the node chattering between states while stress hovers at a bound. It is defined asymmetrically, and the asymmetry is the whole point:
Wdnever applies to a downward transition. The first qualifying observation lowers the trust state within the evaluation cycle in which it is admitted (DC-4). Any implementation that delays a fall to “confirm” it has inverted the design commitment and fails the run.Wdapplies to: any upward transition (which must additionally pass the full recovery sequence via RECOVERING); re-announcement of an unchanged state to L5 and L7 consumers; and the L8 advisory re-scoring cadence.- Any breach during the dwell restarts the dwell; a partially served
Wdcarries no credit. - Derivation rule, with the number set from measurement rather than chosen:
Wdis at least the nominal reporting interval of the slowest bound-relevant input multiplied by the number of consecutive clean samples the recovery sequence requires, and at least the measured evaluation-cycle period multiplied by the declared cycles-to-confirm. The larger governs. - Oscillation is measured, not assumed away: report the flap count over
Woand the full dwell-time distribution per state. A flap count aboveNfis a defect against the F-series register, not a tuning nuisance to be filed as configuration.
Figure 2 - asymmetric damping
down (no damping, one observation is enough):
NORMAL --(breach)--> RESTRICTED --(breach)--> CRITICAL --(breach)--> DENY
up (never direct; recovery sequence plus continuous clean dwell >= Wd):
CRITICAL --> RECOVERING --[all bounds satisfied for Wd]--> RESTRICTED
^ |
+------ any breach restarts the dwell --------+
F7b — EVIDENCE-STORE BACKLOG BEHAVIOUR
Records are separated into two classes at the point of generation, and the classification is fixed in code, not chosen at runtime under load:
| Class | Contents | Behaviour when the queue approaches Qe |
|---|---|---|
| C | Consequential: trust-state transitions, every decision outcome and its reason, conflict entries, recovery-sequence steps, boundary violations, gap markers. | Never dropped, never reordered, never summarised. If a Class C record cannot be durably written within Wq, the outcome is safe-hold (or abstain where no hold state exists) and the trust state falls to at most RESTRICTED. |
| T | Periodic observation telemetry between transitions. | May be decimated. The decimation is itself written as a Class C record naming the interval, the ratio and the cause — a thinner record is a recorded fact, not a quieter one (DC-2). |
- Repeated identical outcomes. Successive abstentions on the same command identity for the same reason are written once with a repeat count and first/last acquisition timestamps. This is a defined aggregation with a stated rule, and it is the only aggregation permitted on Class C.
- Gap markers. Any interval in which the fabric could not accept writes is bounded by a gap marker at each end. After recovery, values reconstructed across a gap are tagged DERIVED and reference the marker; a reconstructed value presented as MEASURED is a DC-1 violation and a run failure.
- Backlog is a first-class input. Queue depth and write latency are inputs to the trust evaluation, not merely operational metrics: a node that cannot record cannot authorise.
F8 — INSTRUMENTATION
As AQ-SCN-002 F8, with three additions: per-command elapsed evaluation time against Wq; queue depth and durable-write latency sampled at the evaluation-cycle rate; and TB-2 acquisition jitter recorded continuously against the injected host-load profile so that separation can be tested rather than asserted. L8 output is captured and takes no part in any decision.
F9 — RUN-LEVEL FAILURE CRITERIA
- Any
executeissued after aWqexpiry, or from a cached prior verdict. - Any consequential effect taken while its Class C record was unwritten.
- Any Class C record dropped, reordered, or aggregated outside the stated rule.
- Flap count above
NfoverWo; or any upward transition insideWd; or any downward transition delayed by damping. - TB-2 acquisition timing correlated with S3-C load.
- Any Q1–Q3 timeout resolved as
abstainrather thandeny. - Any state recovery to NORMAL that did not pass the full sequence.
F10 — ABORT AND CONTAINMENT
Bench only; TB-4 gated into an instrumented dummy load throughout. Abort and record if: the fabric becomes non-durable while a command is in flight and the node continues to issue outcomes; injected contention escapes the intended hosts; DC-1 tagging fails mid-run; or the run cannot be stopped from the operator console within one evaluation cycle. Aborted runs are retained with their cause and are never overwritten by a later clean run.
F11 — EVIDENCE RECORD, RECONSTRUCTION, AND THE NEGATIVE RESULT
The DC-5 reconstruction test of AQ-SCN-002 F11 applies unchanged, with one addition: the reconstruction must also recover the backlog history — when the queue was near Qe, which intervals were decimated, where the gap markers sit, and which outcomes were forced by an unwritable record rather than by the trust state. If backlog history is not reconstructable, the run has not demonstrated DC-5 no matter how favourable the outcome mix looks.
A run in which AQ-NODE-01 fails to degrade gracefully under compound stress is a significant and publishable negative result, and it is recorded and reported as one at the evidence level reached. Knowing the load at which a trust-state machine begins to chatter, or the queue depth at which recording cost forces safe-hold, is a real finding about a real design and is more useful to the programme and to anyone reading it than a clean run at magnitudes chosen to be survivable. What is not permitted under L9 governance: discarding an unfavourable run; re-running at reduced magnitudes and reporting only the later run; reclassifying a Class C failure as a configuration issue; or narrowing the run card after the fact so that the failed region falls outside the declared scope. Every executed run, including every abort, stays in the record with its run card attached.
A complete Stage C pass supports one statement: that on this bench, at these run-card magnitudes, under this contention profile, the implementation narrowed its outcomes monotonically, stayed within the declared flap bound, and recorded every consequential transition durably before its effect. It supports no claim of readiness for any platform, no claim about behaviour beyond rung 1 of the reach ladder, no claim about adversarial conditions, and no security property. Results are reported at Lab validation; anything above that on the ladder is not established.