NAUX Architecture Decision Records
Accepted ADRs are normative below the Architecture Charter and North Star. Proposed entries are non-normative design boundaries until their acceptance gates pass.
| ADR | Decision |
|---|---|
| ADR-0001 | Canonical Typed Core |
| ADR-0002 | Binding-time judgment |
| ADR-0003 | Allocation and identity observability |
| ADR-0004 | Region evidence vs physical placement |
| ADR-0005 | P1 lighthouse scope |
| ADR-0006 | Numeric semantics |
| ADR-0007 | FFI trust boundary |
| ADR-0008 | Production sovereignty and external tools |
| ADR-0009 | RC fallback and cycle policy |
| ADR-0010 | Nauxogenesis and the generative fixed point |
| ADR-0011 | Surface-to-Core T2 admission boundary |
| ADR-0012 | Surface direct-function T2B boundary |
| ADR-0013 | Bounded logical store for Core P1V1 |
| ADR-0014 | Bounded existential closures for Core P1V2 |
| ADR-0015 | Linear lexical algebraic handlers for Core P1V3 |
| ADR-0016 | Bounded affine Unique ownership for Core P1V4 |
| ADR-0017 | Bounded ownership return for Core P1V5 |
| ADR-0018 | Profiled Core semantics identity and bounded Stage 1 freeze |
| ADR-0019 | B0 request trust boundary and policy identity |
| ADR-0020 | B0 structural node identity and intraprocedural judgment |
| ADR-0021 | B0 deterministic interprocedural fixed point |
| ADR-0022 | B0 sealed evidence and independent replay |
| ADR-0023 | R0 specialization value and request boundary |
| ADR-0024 | R0-B evidence-gated static evaluation |
| ADR-0025 | R0-B2 interprocedural continuation machine and mixed static-fact frontiers |
| ADR-0026 | R0-C1 scalar-slot Residual Core generation |
| ADR-0027 | R0-C2 folding and opaque evaluation records |
| ADR-0028 | R0-D sealed residual evidence and regenerative validation |
| ADR-0029 | CoreVM0 bounded typed program representation |
| ADR-0030 | CoreVM0 full ProgramImage and definitional Core boundary |
| ADR-0031 | Evidence-gated polyvariant R1 boundary |
| ADR-0032 | Structural partial values and bounded helper unfolding |
| ADR-0033 | Bounds-preserving arrays and CoreVM0 admission |
| ADR-0034 | Canonical summaries and CoreVM0 structural erasure |
| ADR-0035 | Gate A translation validation and canonical Residual Core to typed SSA handoff |
| ADR-0036 | Canonical target-independent Machine IR trust boundary |
| ADR-0037 | Canonical x86-64 target plan and checked encoding (R1-S7a validated; successor R1-S7b validated by ADR-0038) |
| ADR-0038 | Verifier-gated W^X native runner (S7b-a/b/c locally validated) |
| ADR-0039 | Direct ELF64 standalone image and libc-free startup (finite R1-S8 correctness accepted; Gate B performance open) |
| ADR-0040 | Sealed 51-case Core↔SSA and SSA↔Machine IR correspondence roots carried by R1-S8 authority |
| ADR-0041 | Fixed end-to-end Gate B measurement, matched standalone baseline, and claim admission |
| ADR-0042 | Fail-closed tail/copy/control-flow encoder policy 1.3 and measured migration |
| ADR-0043 | Rejected greedy tail-home offset swaps after exact weighted Gate B audit |
| ADR-0044 | Accepted reachable unique-predecessor one-operation superblock encoder policy 1.4 with fail-closed ordinary fallback |
| ADR-0045 | Accepted historical schema-1.1 post-policy-1.4 weighted profile and evidence-selected shared-join optimization class |
| ADR-0046 | Accepted historical schema-1.2 bounded topological ownership and transitive shared-join composition; encoder policy remains 1.4 |
| ADR-0047 | Accepted branch-arm cross-tab data retained; ingress-route admission and schema-1.3 route authority superseded by ADR-0048; encoder policy remains 1.4 |
| ADR-0048 | Accepted exact per-ingress ordered shared-join lineage and schema-1.4 seal; encoder policy remains 1.4 |
| ADR-0049 | Accepted proof-only shadow prospective shared-join realization and schema-1.5 seal; encoder policy remains 1.4 and candidate selection remains closed |
| ADR-0050 | Accepted bounded independent machine-semantic decoder and schema-1.6 proof seal for register shared-join shadow slices; encoder policy remains 1.4 and candidate selection remains closed |
| ADR-0051 | Accepted sealed, independently regenerable policy-1.5 candidate capsule; no native, process, standalone, or timing authority |
| ADR-0052 | Accepted finite 51-case policy-1.5 candidate native correctness admission with exact policy-1.4 Bounds fallback; no process, standalone, or timing authority |
| ADR-0053 | Accepted process-isolated correspondence for the exact ADR-0052 candidate/fallback identity; no standalone, timing, claim, or global policy-1.5 authority |
| ADR-0054 | Accepted candidate-specific standalone ELF and untimed 51-case direct-process correspondence; no measurement, claim, or global policy-1.5 authority |
| ADR-0055 | Accepted candidate-matched Gate B measurement boundary; exact policy-1.5 candidate claim rejected at 3.824029928x pinned median ratio, global encoder policy remains 1.4 |
| ADR-0056 | Accepted sovereign structural and pinned body/process attribution; proof-only TailStateTransferElimination selected, global encoder policy remains 1.4 |
| ADR-0057 | Accepted bounded persistent typed tail-state plan with independently replayed parallel-copy/alias/cycle semantics; no candidate bytes and global encoder policy remains 1.4 |
| ADR-0058 | Accepted sovereign finite GPR/XMM tail-bank allocation with independent liveness, interference, spill, scratch, and transition replay; no candidate bytes and global encoder policy remains 1.4 |
| ADR-0059 | Accepted bounded physical-template preservation census and exact non-executable transition realization with cross-bank scratch replay; global encoder policy remains 1.4 |
| ADR-0060 | Accepted owned canonical x86-64 transition-byte capsule with concrete trap-anchor rel32 layout, exhaustive byte binding, and independent decoder; no executable authority and global encoder policy remains 1.4 |
| ADR-0061 | Accepted historical schema-1.0 whole-body binding and CFG-liveness proof; region-wide frontier adapter construction superseded by ADR-0063, no byte or executable authority |
| ADR-0062 | Accepted bounded symbolic x86-64 body/frontier realization with independent typed-token replay over corrected ADR-0063 evidence; no new byte or executable authority |
| ADR-0063 | Accepted schema-1.1 exact frontier live-set narrowing and per-frontier register injectivity, superseding ADR-0061 region-wide adapters; global encoder policy remains 1.4 |
| ADR-0064 | Accepted owned non-executable body/frontier byte capsule with typed trap anchors, external ADR-0060 references, and a separately implemented decoder; global encoder policy remains 1.4 |
| ADR-0065 | Accepted closed non-executable semantic image composition with unique predecessor-byte ownership, real internal relocation, typed ABI terminal anchors, and independent full-CFG recovery; global encoder policy remains 1.4 |
| ADR-0066 | Accepted sovereign entry/return/Bounds ABI-envelope byte capsule with exhaustive byte binding, symbolic state replay, and a separately implemented decoder; no execution authority and global encoder policy remains 1.4 |
| ADR-0067 | Accepted exact ADR-0065 + ADR-0066 fully enveloped image composition with complete rel32 repatching, exhaustive byte binding, and independent predecessor projection; no execution authority and global encoder policy remains 1.4 |
| ADR-0068 | Accepted sovereign W^X execution and sealed 51-case finite correspondence for only verified ADR-0067 images; canonical MXCSR scope, mandatory teardown, no fallback, and no process, standalone, timing, claim, or global policy authority |
| ADR-0069 | Accepted sovereign one-child containment under process root e3f97622…d7ae, with bounded aggregate IPC, exact 51-record parent oracle-only replay, process-group termination and mandatory reap; no executable attestation, historical process stack, standalone, timing, claim, or global policy authority |
| ADR-0070 | Accepted reviewed worker identity and immutable exact-FD launch under policy root 96728249…5317d; caller-supplied digest/length, NAUX-owned four-seal memfd, execveat(AT_EMPTY_PATH), and exact ADR-0069 replay; no ELF dependency closure, sandbox, standalone, timing, claim, or global policy authority |
| ADR-0071 | Accepted proof-only independent ELF64 worker inventory under policy root 1a6c96c8…3bbf, binding program headers, dynamic entries, interpreter, dependencies, hardening and refusal facts; no dependency admission, execution, sandbox, standalone, timing, claim, or global policy authority |
| ADR-0072 | Accepted exact caller-reviewed interpreter/dependency/flags manifest admission under policy root 5a694705…ec22; no resolution, file identity, loading, execution, sandbox, timing, claim, or global policy authority |
| ADR-0073 | Accepted exact path/length/digest object admission under policy root c9780ea7…7bc9, retaining private read-only four-seal descriptors with independent bounded ELF replay; no loader-resolution, transitive-closure, mapping, execution, timing, claim, or global policy authority |
| ADR-0074 | Accepted independent DT_SONAME plus ordered transitive DT_NEEDED inventory under policy root 7083c3d4…371f over opaque ADR-0073 sealed objects; no closure admission, resolution, mapping, execution, timing, claim, or global policy authority |
| ADR-0075 | Accepted externally reviewed canonical SONAME/digest/edge closure under policy root 6835b65f…bd56; duplicate appearances collapse only under exact digest and dynamic-fact agreement, with no host resolution, mapping, execution, timing, claim, or global policy authority |
| ADR-0076 | Accepted proof-only independent GNU Verneed/Vernaux inventory under policy root 7c278cc0…5b32: three exact requirement records and twelve exact auxiliary names bind only to reviewed DT_NEEDED providers; no version-definition, symbol-binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0077 | Accepted proof-only independent GNU Verdef/Verdaux inventory under policy root f4475333…72ce: 70 exact definitions and 131 exact auxiliaries preserve base identities, primary hashes, indices, and ordered parents; no requirement matching, symbol binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0078 | Accepted proof-only exact strong GNU requirement-to-definition compatibility under policy root 017832c1…c84e: twelve ordered bindings select only their reviewed direct providers; no weak fallback, dynamic-symbol inventory, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0079 | Accepted proof-only independent dynsym extent, System V/GNU hash reconstruction, and parallel versym inventory under policy root d39244c8…7758: 3,455 exact provider symbols; no root-worker inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0080 | Accepted proof-only independent root Verneed/Vernaux inventory under policy root 1e728341…ecdf: three direct-provider records and twenty exact requirements replay from the immutable descriptor after source replacement; no definition matching, root-symbol inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0081 | Accepted proof-only exact root requirement-to-definition compatibility under policy root db6e8c46…df0e: twenty ordered strong bindings select only each root requirement’s sealed direct provider, including two provider-distinct GLIBC_2.3 bindings; no root-symbol inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0082 | Accepted proof-only independent root dynsym/parallel versym inventory under policy root 6d68c8c4…6ea4: 108 exact ordered symbols with a valid GNU all-import/no-export topology bind every nonlocal index to exact ADR-0080/0081 requester/provider evidence; no lookup scope, selection, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0083 | Accepted proof-only reviewed root lookup scope under policy root 4b913fa2…65a: exact precedence libgcc_s.so.1, libc.so.6, then ld-linux-x86-64.so.2 binds all accepted providers once to ADR-0075/0079 identities and the ADR-0082 requester; no name/hash lookup, selection, binding, relocation, execution, timing, claim, or global policy authority |
| ADR-0084 | Accepted proof-only exact strong versioned candidate selection under policy root 261495db…7c21 and semantic topology root 1e9d41d8…631e: 96 requests replay 181 bounded provider hash probes, select 90 exact definitions, and explicitly refuse six IFUNC definitions; no weak-requester fallback, runtime address, relocation, execution, timing, claim, or global policy authority |
| ADR-0085 | Accepted proof-only root DT_RELA/DT_JMPREL inventory under policy root 825edbe0…3779: artifact-local relative prefixes join an invariant 105 GLOB_DAT / 3 JUMP_SLOT topology to 89 selected, 8 IFUNC-refused, and 11 unsupported ADR-0082/0084 records; no runtime address, relocation write, mapping, initialization, execution, timing, claim, or global policy authority |
New decisions use the next sequence number. A changed decision is recorded by a new ADR that explicitly supersedes the old one; accepted history is not edited silently.