NAUX Architecture Decision Records

Accepted ADRs are normative below the Architecture Charter and North Star. Proposed entries are non-normative design boundaries until their acceptance gates pass.

ADRDecision
ADR-0001Canonical Typed Core
ADR-0002Binding-time judgment
ADR-0003Allocation and identity observability
ADR-0004Region evidence vs physical placement
ADR-0005P1 lighthouse scope
ADR-0006Numeric semantics
ADR-0007FFI trust boundary
ADR-0008Production sovereignty and external tools
ADR-0009RC fallback and cycle policy
ADR-0010Nauxogenesis and the generative fixed point
ADR-0011Surface-to-Core T2 admission boundary
ADR-0012Surface direct-function T2B boundary
ADR-0013Bounded logical store for Core P1V1
ADR-0014Bounded existential closures for Core P1V2
ADR-0015Linear lexical algebraic handlers for Core P1V3
ADR-0016Bounded affine Unique ownership for Core P1V4
ADR-0017Bounded ownership return for Core P1V5
ADR-0018Profiled Core semantics identity and bounded Stage 1 freeze
ADR-0019B0 request trust boundary and policy identity
ADR-0020B0 structural node identity and intraprocedural judgment
ADR-0021B0 deterministic interprocedural fixed point
ADR-0022B0 sealed evidence and independent replay
ADR-0023R0 specialization value and request boundary
ADR-0024R0-B evidence-gated static evaluation
ADR-0025R0-B2 interprocedural continuation machine and mixed static-fact frontiers
ADR-0026R0-C1 scalar-slot Residual Core generation
ADR-0027R0-C2 folding and opaque evaluation records
ADR-0028R0-D sealed residual evidence and regenerative validation
ADR-0029CoreVM0 bounded typed program representation
ADR-0030CoreVM0 full ProgramImage and definitional Core boundary
ADR-0031Evidence-gated polyvariant R1 boundary
ADR-0032Structural partial values and bounded helper unfolding
ADR-0033Bounds-preserving arrays and CoreVM0 admission
ADR-0034Canonical summaries and CoreVM0 structural erasure
ADR-0035Gate A translation validation and canonical Residual Core to typed SSA handoff
ADR-0036Canonical target-independent Machine IR trust boundary
ADR-0037Canonical x86-64 target plan and checked encoding (R1-S7a validated; successor R1-S7b validated by ADR-0038)
ADR-0038Verifier-gated W^X native runner (S7b-a/b/c locally validated)
ADR-0039Direct ELF64 standalone image and libc-free startup (finite R1-S8 correctness accepted; Gate B performance open)
ADR-0040Sealed 51-case Core↔SSA and SSA↔Machine IR correspondence roots carried by R1-S8 authority
ADR-0041Fixed end-to-end Gate B measurement, matched standalone baseline, and claim admission
ADR-0042Fail-closed tail/copy/control-flow encoder policy 1.3 and measured migration
ADR-0043Rejected greedy tail-home offset swaps after exact weighted Gate B audit
ADR-0044Accepted reachable unique-predecessor one-operation superblock encoder policy 1.4 with fail-closed ordinary fallback
ADR-0045Accepted historical schema-1.1 post-policy-1.4 weighted profile and evidence-selected shared-join optimization class
ADR-0046Accepted historical schema-1.2 bounded topological ownership and transitive shared-join composition; encoder policy remains 1.4
ADR-0047Accepted branch-arm cross-tab data retained; ingress-route admission and schema-1.3 route authority superseded by ADR-0048; encoder policy remains 1.4
ADR-0048Accepted exact per-ingress ordered shared-join lineage and schema-1.4 seal; encoder policy remains 1.4
ADR-0049Accepted proof-only shadow prospective shared-join realization and schema-1.5 seal; encoder policy remains 1.4 and candidate selection remains closed
ADR-0050Accepted bounded independent machine-semantic decoder and schema-1.6 proof seal for register shared-join shadow slices; encoder policy remains 1.4 and candidate selection remains closed
ADR-0051Accepted sealed, independently regenerable policy-1.5 candidate capsule; no native, process, standalone, or timing authority
ADR-0052Accepted finite 51-case policy-1.5 candidate native correctness admission with exact policy-1.4 Bounds fallback; no process, standalone, or timing authority
ADR-0053Accepted process-isolated correspondence for the exact ADR-0052 candidate/fallback identity; no standalone, timing, claim, or global policy-1.5 authority
ADR-0054Accepted candidate-specific standalone ELF and untimed 51-case direct-process correspondence; no measurement, claim, or global policy-1.5 authority
ADR-0055Accepted candidate-matched Gate B measurement boundary; exact policy-1.5 candidate claim rejected at 3.824029928x pinned median ratio, global encoder policy remains 1.4
ADR-0056Accepted sovereign structural and pinned body/process attribution; proof-only TailStateTransferElimination selected, global encoder policy remains 1.4
ADR-0057Accepted bounded persistent typed tail-state plan with independently replayed parallel-copy/alias/cycle semantics; no candidate bytes and global encoder policy remains 1.4
ADR-0058Accepted sovereign finite GPR/XMM tail-bank allocation with independent liveness, interference, spill, scratch, and transition replay; no candidate bytes and global encoder policy remains 1.4
ADR-0059Accepted bounded physical-template preservation census and exact non-executable transition realization with cross-bank scratch replay; global encoder policy remains 1.4
ADR-0060Accepted owned canonical x86-64 transition-byte capsule with concrete trap-anchor rel32 layout, exhaustive byte binding, and independent decoder; no executable authority and global encoder policy remains 1.4
ADR-0061Accepted historical schema-1.0 whole-body binding and CFG-liveness proof; region-wide frontier adapter construction superseded by ADR-0063, no byte or executable authority
ADR-0062Accepted bounded symbolic x86-64 body/frontier realization with independent typed-token replay over corrected ADR-0063 evidence; no new byte or executable authority
ADR-0063Accepted schema-1.1 exact frontier live-set narrowing and per-frontier register injectivity, superseding ADR-0061 region-wide adapters; global encoder policy remains 1.4
ADR-0064Accepted owned non-executable body/frontier byte capsule with typed trap anchors, external ADR-0060 references, and a separately implemented decoder; global encoder policy remains 1.4
ADR-0065Accepted closed non-executable semantic image composition with unique predecessor-byte ownership, real internal relocation, typed ABI terminal anchors, and independent full-CFG recovery; global encoder policy remains 1.4
ADR-0066Accepted sovereign entry/return/Bounds ABI-envelope byte capsule with exhaustive byte binding, symbolic state replay, and a separately implemented decoder; no execution authority and global encoder policy remains 1.4
ADR-0067Accepted exact ADR-0065 + ADR-0066 fully enveloped image composition with complete rel32 repatching, exhaustive byte binding, and independent predecessor projection; no execution authority and global encoder policy remains 1.4
ADR-0068Accepted sovereign W^X execution and sealed 51-case finite correspondence for only verified ADR-0067 images; canonical MXCSR scope, mandatory teardown, no fallback, and no process, standalone, timing, claim, or global policy authority
ADR-0069Accepted sovereign one-child containment under process root e3f97622…d7ae, with bounded aggregate IPC, exact 51-record parent oracle-only replay, process-group termination and mandatory reap; no executable attestation, historical process stack, standalone, timing, claim, or global policy authority
ADR-0070Accepted reviewed worker identity and immutable exact-FD launch under policy root 96728249…5317d; caller-supplied digest/length, NAUX-owned four-seal memfd, execveat(AT_EMPTY_PATH), and exact ADR-0069 replay; no ELF dependency closure, sandbox, standalone, timing, claim, or global policy authority
ADR-0071Accepted proof-only independent ELF64 worker inventory under policy root 1a6c96c8…3bbf, binding program headers, dynamic entries, interpreter, dependencies, hardening and refusal facts; no dependency admission, execution, sandbox, standalone, timing, claim, or global policy authority
ADR-0072Accepted exact caller-reviewed interpreter/dependency/flags manifest admission under policy root 5a694705…ec22; no resolution, file identity, loading, execution, sandbox, timing, claim, or global policy authority
ADR-0073Accepted exact path/length/digest object admission under policy root c9780ea7…7bc9, retaining private read-only four-seal descriptors with independent bounded ELF replay; no loader-resolution, transitive-closure, mapping, execution, timing, claim, or global policy authority
ADR-0074Accepted independent DT_SONAME plus ordered transitive DT_NEEDED inventory under policy root 7083c3d4…371f over opaque ADR-0073 sealed objects; no closure admission, resolution, mapping, execution, timing, claim, or global policy authority
ADR-0075Accepted externally reviewed canonical SONAME/digest/edge closure under policy root 6835b65f…bd56; duplicate appearances collapse only under exact digest and dynamic-fact agreement, with no host resolution, mapping, execution, timing, claim, or global policy authority
ADR-0076Accepted proof-only independent GNU Verneed/Vernaux inventory under policy root 7c278cc0…5b32: three exact requirement records and twelve exact auxiliary names bind only to reviewed DT_NEEDED providers; no version-definition, symbol-binding, relocation, execution, timing, claim, or global policy authority
ADR-0077Accepted proof-only independent GNU Verdef/Verdaux inventory under policy root f4475333…72ce: 70 exact definitions and 131 exact auxiliaries preserve base identities, primary hashes, indices, and ordered parents; no requirement matching, symbol binding, relocation, execution, timing, claim, or global policy authority
ADR-0078Accepted proof-only exact strong GNU requirement-to-definition compatibility under policy root 017832c1…c84e: twelve ordered bindings select only their reviewed direct providers; no weak fallback, dynamic-symbol inventory, binding, relocation, execution, timing, claim, or global policy authority
ADR-0079Accepted proof-only independent dynsym extent, System V/GNU hash reconstruction, and parallel versym inventory under policy root d39244c8…7758: 3,455 exact provider symbols; no root-worker inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority
ADR-0080Accepted proof-only independent root Verneed/Vernaux inventory under policy root 1e728341…ecdf: three direct-provider records and twenty exact requirements replay from the immutable descriptor after source replacement; no definition matching, root-symbol inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority
ADR-0081Accepted proof-only exact root requirement-to-definition compatibility under policy root db6e8c46…df0e: twenty ordered strong bindings select only each root requirement’s sealed direct provider, including two provider-distinct GLIBC_2.3 bindings; no root-symbol inventory, lookup, binding, relocation, execution, timing, claim, or global policy authority
ADR-0082Accepted proof-only independent root dynsym/parallel versym inventory under policy root 6d68c8c4…6ea4: 108 exact ordered symbols with a valid GNU all-import/no-export topology bind every nonlocal index to exact ADR-0080/0081 requester/provider evidence; no lookup scope, selection, binding, relocation, execution, timing, claim, or global policy authority
ADR-0083Accepted proof-only reviewed root lookup scope under policy root 4b913fa2…65a: exact precedence libgcc_s.so.1, libc.so.6, then ld-linux-x86-64.so.2 binds all accepted providers once to ADR-0075/0079 identities and the ADR-0082 requester; no name/hash lookup, selection, binding, relocation, execution, timing, claim, or global policy authority
ADR-0084Accepted proof-only exact strong versioned candidate selection under policy root 261495db…7c21 and semantic topology root 1e9d41d8…631e: 96 requests replay 181 bounded provider hash probes, select 90 exact definitions, and explicitly refuse six IFUNC definitions; no weak-requester fallback, runtime address, relocation, execution, timing, claim, or global policy authority
ADR-0085Accepted proof-only root DT_RELA/DT_JMPREL inventory under policy root 825edbe0…3779: artifact-local relative prefixes join an invariant 105 GLOB_DAT / 3 JUMP_SLOT topology to 89 selected, 8 IFUNC-refused, and 11 unsupported ADR-0082/0084 records; no runtime address, relocation write, mapping, initialization, execution, timing, claim, or global policy authority

New decisions use the next sequence number. A changed decision is recorded by a new ADR that explicitly supersedes the old one; accepted history is not edited silently.