← Part 26

AQ-SCN-003

Eleven-field specification for combined information degradation, bounded decision time and computational pressure, defining the oscillation damping window, evidence-store backlog rules, and the programme position that ungraceful degradation is a publishable negative result.

Charter artifact · gated by Part 26 · revision 0, draft for internal review

AQ-SCN-003 — Scenario 3 specification: Compound system stress

This document specifies the compound scenario in the AQ-SCN series for AQ-NODE-01 (AKQ-NODE-1 in Parts up to 12). It is a specification of an intended procedure. No run of AQ-SCN-003 has been performed at any evidence level, and AQ-SCN-003 may not be run before AQ-SCN-002 has been run to Stage C — several of its parameters are derived from AQ-SCN-002 measurements and cannot be set otherwise.

AQ-SCN-002 applies its injections one at a time so that each effect is attributable. AQ-SCN-003 exists because attributable single effects are not the interesting case: the question is what the three stress axes do to each other.

F1 — IDENTIFIER AND STATUS

  • Identifier AQ-SCN-003. Subject article AQ-NODE-01. Tier CA for the compound behaviour model, Y1 for the bench implementation.
  • Current evidence level Concept; target progression Theory → Simulation → Lab validation on rung 1 (optical bench). No stage of AQ-SCN-003 addresses any higher rung of the reach ladder.
  • Layers exercised: L1, L2, L4 (AQ-TSE-01), L5 (command authority), L6 (Evidence & Provenance Fabric, primary under this scenario), L7, L8 (advisory only), L9.
  • Trust boundaries: TB-2 must be shown unaffected by the stress applied to TB-3 and TB-5; that separation is itself a measured outcome, not an assumption.

F2 — QUESTION THE SCENARIO ANSWERS

When information degrades, the decision window shortens and compute is contended at the same time, does the node degrade in a bounded, observable and recorded way — or does it produce a confident output it has no basis for? “Degrade gracefully” is used in this document with one operational meaning and no other:

DEFINITION — GRACEFUL DEGRADATION

Degradation is graceful when, and only when, it is: bounded (the outcome set narrows toward abstain / safe-hold and never widens); monotonic (trust falls on one observation and rises only through the full recovery sequence, DC-4); observable (each narrowing is announced with a reason before it takes effect); recorded (each consequential transition is durably written before its effect, DC-5); and non-oscillatory (state changes stay within the declared flap bound over the window Wo). A node that keeps executing under pressure has not degraded gracefully; it has failed silently.

F3 — EVIDENCE LEVEL AND CLAIM CEILING BY STAGE

StageExecuted onLevel reachedCeiling on what may be claimed
AModel of the coupled loop (evaluation time, outcome mix, evidence write load)TheoryThat the coupling exists in the model. Nothing about magnitudes.
BImplementation under injected traces plus synthetic host loadSimulationBehaviour of the implementation under the injected load profile only.
COptical bench, real feeds, real contention, TB-4 into a dummy loadLab validationBehaviour on that bench at those run-card magnitudes. No extrapolation to any other rung, platform or duty cycle.

F4 — DERIVED PARAMETERS

No numeric target is asserted here. Each parameter below is set on the run card from prior measurement, and the derivation rule is recorded with the run:

  • Te — measured trust-evaluation completion time distribution from AQ-SCN-002 Stage C (the input, not a target).
  • Wq — the bounded decision window for a command, stepped downward across the observed Te distribution so that the run brackets the point at which the window binds.
  • Wd — the damping window (F7a).
  • Wo — the rolling window over which the flap count is computed; declared flap bound Nf is the maximum admissible state changes within Wo.
  • Qe — the durable-write queue depth of the Evidence Fabric, and Le the measured durable-write latency at that depth.

F5 — PRECONDITIONS AND ENTRY STATE

  • AQ-SCN-002 Stage C complete, its findings closed, and Te, Bf, Na, Wa, Bc, Wt, Qf recorded.
  • Node in NORMAL with a recorded baseline; DC-1 tagging pre-check clean; Evidence Fabric durable and its queue depth instrumented before the first stressor is applied.
  • A quiescent control run at each stress level with no command traffic, so that command-driven and load-driven effects can be separated afterwards.

F6 — STRESSOR SET

RefStressorMagnitude (run-card parameter)TimingTelemetry label
S3-AInformation degradationA named subset of the AQ-SCN-002 injections applied concurrently: input delay on one feed, absence on a second, divergence between a redundant pair, quality below Qf on a fourth. Magnitudes held at the values that were individually detected in AQ-SCN-002.Applied first and held for the whole compound phase, so that A alone is never the new variable.aq.l1.* as in AQ-SCN-002, plus aq.l4.basis.count_undetermined
S3-BDecision-time constraintCommand arrivals with decision window Wq stepped downward across the Te distribution; then a burst profile stepping arrival rate upward at a fixed Wq.Applied in steps on top of held S3-A; each step long enough to observe steady state and the transient into it.aq.l5.cmd.window, aq.l4.eval.elapsed, aq.l5.outcome
S3-CComputational pressureContention injected on the TB-3 and TB-5 hosts across processor, memory and evidence-store write throughput, stepped until measured evaluation time exceeds Wq for a material fraction of commands.Applied last, on top of held S3-A and the current S3-B step, so that the coupled loop can be reached deliberately rather than by accident.aq.l6.queue.depth, aq.l6.write.latency, aq.tb2.acq.jitter

F7 — EXPECTED BEHAVIOUR

  • Decision-window expiry is an outcome, not an error. If trust evaluation does not complete within Wq, the issued outcome is abstain with an explicit timeout reason — never a fall-through to execute, never a cached prior verdict re-issued as current (DC-3).
  • Hard constraints do not time out into leniency. If Q1–Q3 cannot be established within Wq, the outcome is deny: the command has not been shown valid and authorised now. Only Q4 yields abstain, and Q4 can only ever reduce what Q1–Q3 allowed.
  • TB-2 separation. Acquisition timestamping at the FPGA must not move with host load. Observed drift in aq.tb2.acq.jitter correlated with S3-C is a trust-boundary violation and is reported as such even if every decision outcome was otherwise correct.
  • Outcome mix narrows monotonically. As stress rises the mix must shift executeexecute-restrictedsafe-hold/abstain. Any re-appearance of execute at a higher stress step than one at which it had already disappeared is a finding.
THE COUPLED LOOP THIS SCENARIO EXISTS TO EXPOSE

Abstention is not free. Computational pressure lengthens evaluation, which makes Wq bind, which raises the abstention rate — and every abstention is itself a consequential record that must be durably written, which raises the evidence queue depth, which lengthens write latency, which lengthens evaluation again. The node can be driven into safe-hold by the cost of recording its own caution. This loop is the specific object of measurement in AQ-SCN-003.

Figure 1 - the abstention-record feedback loop under compound stress

  +----------------------+        +---------------------------+
  | S3-A information     |        | S3-C computational        |
  | degradation (held)   |        | pressure on TB-3 / TB-5   |
  +----------+-----------+        +-------------+-------------+
             |                                  |
             v                                  v
     inputs undetermined              evaluation time rises
     (DC-2: explicit)                 toward the window Wq
             |                                  |
             +---------------+------------------+
                             v
                   +---------------------+
                   | outcome narrows to  |
                   | abstain / safe-hold |   <-- DC-3, permitted
                   +----------+----------+
                              |
                   each outcome is a Class C
                   evidence record (DC-5)
                              |
                              v
                   +---------------------+
                   | L6 durable queue    |
                   | depth -> Qe         |
                   +----------+----------+
                              |
         if a Class C record cannot be durably written
         within Wq  ->  safe-hold, state at most RESTRICTED
                              |
                              +-----> feeds back into evaluation time

F7a — DAMPING WINDOW Wd

Wd exists to stop the node chattering between states while stress hovers at a bound. It is defined asymmetrically, and the asymmetry is the whole point:

  • Wd never applies to a downward transition. The first qualifying observation lowers the trust state within the evaluation cycle in which it is admitted (DC-4). Any implementation that delays a fall to “confirm” it has inverted the design commitment and fails the run.
  • Wd applies to: any upward transition (which must additionally pass the full recovery sequence via RECOVERING); re-announcement of an unchanged state to L5 and L7 consumers; and the L8 advisory re-scoring cadence.
  • Any breach during the dwell restarts the dwell; a partially served Wd carries no credit.
  • Derivation rule, with the number set from measurement rather than chosen: Wd is at least the nominal reporting interval of the slowest bound-relevant input multiplied by the number of consecutive clean samples the recovery sequence requires, and at least the measured evaluation-cycle period multiplied by the declared cycles-to-confirm. The larger governs.
  • Oscillation is measured, not assumed away: report the flap count over Wo and the full dwell-time distribution per state. A flap count above Nf is a defect against the F-series register, not a tuning nuisance to be filed as configuration.

Figure 2 - asymmetric damping

down (no damping, one observation is enough):
  NORMAL --(breach)--> RESTRICTED --(breach)--> CRITICAL --(breach)--> DENY

up (never direct; recovery sequence plus continuous clean dwell >= Wd):
  CRITICAL --> RECOVERING --[all bounds satisfied for Wd]--> RESTRICTED
                    ^                                             |
                    +------ any breach restarts the dwell --------+

F7b — EVIDENCE-STORE BACKLOG BEHAVIOUR

Records are separated into two classes at the point of generation, and the classification is fixed in code, not chosen at runtime under load:

ClassContentsBehaviour when the queue approaches Qe
CConsequential: trust-state transitions, every decision outcome and its reason, conflict entries, recovery-sequence steps, boundary violations, gap markers.Never dropped, never reordered, never summarised. If a Class C record cannot be durably written within Wq, the outcome is safe-hold (or abstain where no hold state exists) and the trust state falls to at most RESTRICTED.
TPeriodic observation telemetry between transitions.May be decimated. The decimation is itself written as a Class C record naming the interval, the ratio and the cause — a thinner record is a recorded fact, not a quieter one (DC-2).
  • Repeated identical outcomes. Successive abstentions on the same command identity for the same reason are written once with a repeat count and first/last acquisition timestamps. This is a defined aggregation with a stated rule, and it is the only aggregation permitted on Class C.
  • Gap markers. Any interval in which the fabric could not accept writes is bounded by a gap marker at each end. After recovery, values reconstructed across a gap are tagged DERIVED and reference the marker; a reconstructed value presented as MEASURED is a DC-1 violation and a run failure.
  • Backlog is a first-class input. Queue depth and write latency are inputs to the trust evaluation, not merely operational metrics: a node that cannot record cannot authorise.

F8 — INSTRUMENTATION

As AQ-SCN-002 F8, with three additions: per-command elapsed evaluation time against Wq; queue depth and durable-write latency sampled at the evaluation-cycle rate; and TB-2 acquisition jitter recorded continuously against the injected host-load profile so that separation can be tested rather than asserted. L8 output is captured and takes no part in any decision.

F9 — RUN-LEVEL FAILURE CRITERIA

  • Any execute issued after a Wq expiry, or from a cached prior verdict.
  • Any consequential effect taken while its Class C record was unwritten.
  • Any Class C record dropped, reordered, or aggregated outside the stated rule.
  • Flap count above Nf over Wo; or any upward transition inside Wd; or any downward transition delayed by damping.
  • TB-2 acquisition timing correlated with S3-C load.
  • Any Q1–Q3 timeout resolved as abstain rather than deny.
  • Any state recovery to NORMAL that did not pass the full sequence.

F10 — ABORT AND CONTAINMENT

Bench only; TB-4 gated into an instrumented dummy load throughout. Abort and record if: the fabric becomes non-durable while a command is in flight and the node continues to issue outcomes; injected contention escapes the intended hosts; DC-1 tagging fails mid-run; or the run cannot be stopped from the operator console within one evaluation cycle. Aborted runs are retained with their cause and are never overwritten by a later clean run.

F11 — EVIDENCE RECORD, RECONSTRUCTION, AND THE NEGATIVE RESULT

The DC-5 reconstruction test of AQ-SCN-002 F11 applies unchanged, with one addition: the reconstruction must also recover the backlog history — when the queue was near Qe, which intervals were decimated, where the gap markers sit, and which outcomes were forced by an unwritable record rather than by the trust state. If backlog history is not reconstructable, the run has not demonstrated DC-5 no matter how favourable the outcome mix looks.

PROGRAMME POSITION ON AN UNFAVOURABLE RESULT

A run in which AQ-NODE-01 fails to degrade gracefully under compound stress is a significant and publishable negative result, and it is recorded and reported as one at the evidence level reached. Knowing the load at which a trust-state machine begins to chatter, or the queue depth at which recording cost forces safe-hold, is a real finding about a real design and is more useful to the programme and to anyone reading it than a clean run at magnitudes chosen to be survivable. What is not permitted under L9 governance: discarding an unfavourable run; re-running at reduced magnitudes and reporting only the later run; reclassifying a Class C failure as a configuration issue; or narrowing the run card after the fact so that the failed region falls outside the declared scope. Every executed run, including every abort, stays in the record with its run card attached.

WHAT A PASSING RUN DOES NOT LICENSE

A complete Stage C pass supports one statement: that on this bench, at these run-card magnitudes, under this contention profile, the implementation narrowed its outcomes monotonically, stayed within the declared flap bound, and recorded every consequential transition durably before its effect. It supports no claim of readiness for any platform, no claim about behaviour beyond rung 1 of the reach ladder, no claim about adversarial conditions, and no security property. Results are reported at Lab validation; anything above that on the ladder is not established.