Evidence center / current mainSource 84926841a401760b869af158ee80b0e709d0d6af

Proof before promise.

FerrumOS publishes what was measured, how it was measured, and what the result does not prove. Learned forecasts can add caution. They cannot remove deterministic warnings or grant execution authority.

The authority boundary is countable.

Executable operations

41

The catalog, declared count, and dispatch implementation independently agree. Thirty-seven are exposed directly to the model.

Kernel syscalls

61

The source enum spans syscall numbers 0–60. Agent effects still cross this deterministic ABI.

Permission tiers

5

Observe, safe, network, modify, and destructive classes remain distinct from model prediction.

Unknown actions

Closed

Unrecognized catalog entries are rejected rather than silently mapped to a permissive fallback.

QEMU command audit

101 / 101

A dated emulator audit passed all focused cases and 81/81 catalog entries for OS source c92056d; its evidence record is included in the current snapshot above.

Cyber-physical contracts

152 / 152

Deterministic physical-runtime, neural-protocol, neurod, and simulator-bridge tests passed on the named source snapshot.

Model & decoder gates

32 / 32

Physical-model, robustness, and neural-simulator gates passed without promoting learned output into actuator authority.

A measured gain, not a mythology.

GateBalanced accuracyFalse negative rateBoundary
Rules + JEPA81.4%20.8%Authored 500-episode counterfactual fixture
Rules + action mean81.2%No material JEPA advantage established over this simple baseline
Five complete pipelines79.76% meanIndependent training runs on the same authored fixture

Claim boundary — do not overread this resultThe fixture is balanced and authored. It is not natural-use prevalence, independent human annotation, 500 live destructive executions, formal verification, or a certified safety result.

Preview latency stays bounded in the measured profile.

H=1 preview

1.29–1.40 ms

Ring-3 benchmark run means under the documented QEMU/WHPX profile.

H=5 preview

1.43–1.57 ms

Bounded lookahead in the same environment.

Model loading

26–30 ms

With zero measured heap-growth bytes in all three benchmark runs.

Queue response

96 / 96

Every serialized preview response returned in each run; this is not parallel inference throughput.

The reference vertical is wired—inside a strict evidence boundary.

Current main joins versioned provenance, deterministic replay and faults, virtual devices, Gazebo/ROS 2 and Webots bridge boundaries, watchdog and recovery logic, ROS 2/MQTT/CAN conformance, actuator-disabled delivery, bounded neural proposals, host-managed cells, privacy, and reliability primitives.

Claim boundaryThis local deterministic regression does not prove installed third-party infrastructure, physical clocks, live EEG, robot execution, hard-real-time behavior, native hypervisor containment, certification, or independent replication.

Strong simulator results retain narrow claims.

InterfaceMeasured resultWhat it provesWhat it does not
Physical JEPA99.44% balanced accuracy; 1 FN, 16 FPDeterministic simulator screening; permanently shadow-onlyNo robot, camera, hardware-in-the-loop, or actuator-permit claim
Neural decoder600/600 signals; 400/400 artifact abstentions; 0/10,000 idle candidatesDeterministic synthetic-evidence contractNo human participant, live-EEG accuracy, medical, or mind-reading claim

Reproduce the evidence yourself.

Inspect the system, not the slogan.

View the source ↗