docs(simulation): accept Polygon SIM S0

This commit is contained in:
DCCONSTRUCTIONS 2026-07-24 17:24:26 +03:00
parent 2548bb5740
commit a19053dfd4
5 changed files with 163 additions and 24 deletions

View File

@ -129,16 +129,22 @@ lifecycle, authority, canonical contracts, provenance and reports; Gazebo, PX4
SITL, ROS 2, Nav2 and viewers remain replaceable providers. Simulation, replay,
digital twin, HIL and physical shadow keep distinct causal run kinds.
The current implementation is SIM S0 preflight only. Its strict candidate
profile fixes D-only worker placement, loopback ports, process ownership,
Gazebo simulation time and disabled real/direct actuator authority. The doctor
does not install or launch anything and cannot report `GO` without
digest-bound target-worker evidence:
SIM S0 is accepted on the reviewed D-only worker. Its strict profile fixes
loopback-only process isolation, exact provider pins, a 2 ms physics step,
1×/2× RTF/resource budgets and disabled real/direct actuator authority. Two
accepted-profile stock-rover runs and nine digest-bound evidence claims passed;
the target doctor returned `GO`. The doctor remains read-only and a development
host without the private evidence pack still returns `INCOMPLETE`:
```bash
uv run missioncore-sim s0 doctor --json
uv run missioncore-sim s0 doctor \
--evidence /path/to/private/evidence.yaml \
--json
```
This accepts simulation infrastructure, not navigation behavior, safety
behavior, S1 command authority or real actuator control.
See the [Polygon product/SRS](docs/12_SIMULATION_POLYGON_PRODUCT_AND_SRS.md),
[ADR 0015](docs/adr/0015-simulation-polygon-qualification-boundary.md) and the
[SIM S0 worker runbook](docs/runbooks/SIM_S0_AI_WORKER.md).

View File

@ -3,7 +3,7 @@
This plan supersedes the app-dependent experiment order in the reference Bible.
Each gate produces evidence and an explicit GO, PAUSE or BLOCKED result.
## Current checkpoint — 2026-07-20
## Current checkpoint — 2026-07-24
| Stage | Result |
| --- | --- |
@ -24,7 +24,7 @@ Each gate produces evidence and an explicit GO, PAUSE or BLOCKED result.
| Plugin isolation | GO (laboratory control plane) — vendor backend/frontend and optional scene controls are plugin-owned; manifest/runtime descriptor parity, versioned handshake, lifecycle health and transport correlation fail closed while execution remains in-process |
| K1 application control | GO (physical staged cycle) — after fixing the PCAP-proven `sint64` time field, one explicit UI launch completed all 14 canonical operations on one control session, reached live `SCANNING + project + init_ready`, displayed real points, then one explicit STOP returned K1 to unbound `READY`. No retry or fallback command was sent. Native-project reuse through LixelGO/USB remains an independent verification |
| Stage 8 product storage | PAUSE — retention, replication, encryption, capacity monitoring and long-run browser/WASM stress remain deployment gates |
| Simulation Polygon | STARTED, NOT ACCEPTED — product/SRS and ADR 0015 define a separate qualification boundary; SIM S0 has a strict candidate D-only/version/clock/port/process profile and read-only doctor. No target-worker evidence, rover run, navigation/safety acceptance or real actuator authority exists |
| Simulation Polygon | SIM S0 GO — dedicated Docker-free D-only worker, exact accepted pins, stock Ackermann PX4/ROS 2/Gazebo telemetry, authoritative clock, pause/2 ms step, 1×/2× RTF/resource baselines, repeated clean lifecycle and all nine digest-bound evidence claims passed target doctor. S1 orchestrator/control, navigation/safety acceptance and real actuator authority remain absent |
USB project copying remains optional ground truth rather than a blocker for the
now-verified network path. Owner-operated LixelGO traffic verifies the MQTT
@ -129,16 +129,18 @@ The Polygon branch follows
and
[`ADR 0015`](adr/0015-simulation-polygon-qualification-boundary.md).
It does not reorder or weaken the K1 physical-evidence gates in this document.
Its first gate is SIM S0:
Its first gate, SIM S0, is accepted:
- candidate Windows 11/WSL2 Ubuntu 24.04 worker profile;
- exact Windows 11 / dedicated `MissionCore-Sim` WSL2 Ubuntu 24.04 worker
profile;
- all mutable runtime bytes physically on D;
- ROS 2 Jazzy, Gazebo Harmonic, PX4 v1.17.0, matching `px4_msgs`,
Micro XRCE-DDS and Nav2 compatibility;
- authoritative Gazebo `/clock`;
- loopback port and deterministic process ownership;
- target-worker rover/telemetry/pause/step/stop/resource evidence;
- explicit `GO`, `INCOMPLETE` or `BLOCKED` result.
- target-worker rover/telemetry/pause/2 ms step/1×/2× resource evidence;
- target doctor `GO` for profile SHA-256
`aeecf5005301db230e1340b85215cbbd862b72974a22b8c43767c28be8453e2f`.
The repository doctor is side-effect free:
@ -146,7 +148,10 @@ The repository doctor is side-effect free:
uv run missioncore-sim s0 doctor --json
```
Without admitted target-worker evidence its correct result is `INCOMPLETE`.
Without the exact admitted target-worker evidence its correct result remains
`INCOMPLETE`. S1 starts from the accepted S0 version/storage/time/process
boundary and must add server-owned lifecycle, canonical rover commands,
TTL/watchdog/failsafe evidence and immutable qualification runs.
## Stage 0 — repository and host baseline

View File

@ -52,20 +52,21 @@ accepted navigation behavior, safety behavior or real actuator control.
Polygon is now a parallel product branch. As of this document:
- P0 architecture and SRS are committed on the Polygon branch;
- SIM S0 has a strict candidate qualification profile and read-only doctor;
- the dedicated D-only worker distribution has been created and the candidate
- SIM S0 has a strict accepted qualification profile and read-only doctor;
- the dedicated D-only worker distribution has been created and the accepted
PX4/Gazebo/ROS 2/Nav2 stack has been installed without using Docker;
- PX4 v1.17.0 and the stock Ackermann rover have completed repeated factual
smoke runs with ROS 2 vehicle status, Gazebo clock and clean shutdown;
- the exact accepted-profile generation has passed pause freeze, one 2 ms
single-step, 1×/2× speed and structured resource cases;
- the complete digest-bound S0 evidence manifest and final target doctor
verdict are the remaining S0 admission steps;
- all nine digest-bound S0 evidence claims validate and the target doctor
returns `GO` for profile SHA-256
`aeecf5005301db230e1340b85215cbbd862b72974a22b8c43767c28be8453e2f`;
- `actuator_authority=false`;
- `navigation_or_safety_accepted=false`.
The doctor must report `INCOMPLETE` until exact worker evidence is supplied. A
repository manifest is never enough for a `GO`.
The doctor reports `GO` only on the matching target with the exact confined
worker evidence. A repository manifest alone remains insufficient.
## 3. Goals
@ -380,7 +381,7 @@ The S0 accepted line is:
- Gazebo Harmonic;
- PX4 Autopilot v1.17.0;
- matching `px4_msgs` v1.17.0 generation;
- Micro XRCE-DDS Agent v2.4.3 candidate;
- Micro XRCE-DDS Agent v2.4.3;
- Nav2 Jazzy;
- PX4 Gazebo stock rover models.

View File

@ -2,7 +2,7 @@
## Status
Accepted for architecture and SIM S0 implementation on 2026-07-24.
Accepted for architecture; SIM S0 qualification returned `GO` on 2026-07-24.
Navigation behavior, safety behavior and real actuator authority are not
accepted.
@ -76,7 +76,7 @@ reports easy to misuse.
The qualification doctor is deliberately read-only:
- `simulation/s0/qualification-profile.yaml` is the candidate stack,
- `simulation/s0/qualification-profile.yaml` is the accepted S0 stack,
storage, clock, authority, port and process contract.
- `k1link.simulation.s0` strictly validates that contract and optional
digest-bound worker evidence.
@ -97,5 +97,6 @@ evidence generation. These scripts are qualification tooling; the S1
Simulation Orchestrator remains the future product lifecycle owner.
The doctor reports `INCOMPLETE` until it is running on the reviewed target with
resolved/accepted pins and all required evidence. It cannot infer `GO` from the
repository state.
resolved/accepted pins and all required evidence. On the accepted profile
generation and nine-claim confined evidence set it returned `GO`; it cannot
infer that result from repository state alone.

View File

@ -0,0 +1,126 @@
# Lab 007: SIM S0 acceptance
Date: 2026-07-24 (Europe/Moscow).
## Scope
This lab closes the infrastructure qualification gate for Mission Core
Polygon. It validates the exact D-only worker profile, stock PX4 Ackermann
runtime, ROS 2 telemetry, Gazebo time control, 1×/2× resource behavior,
deterministic shutdown and digest-bound evidence admission.
It does not accept S1 orchestration, rover command behavior, Nav2 navigation,
safety behavior, HIL, physical shadow or real actuator control.
`actuator_authority=false` throughout.
## Accepted profile
- profile ID: `ai-worker-px4-gazebo-v1`;
- profile SHA-256:
`aeecf5005301db230e1340b85215cbbd862b72974a22b8c43767c28be8453e2f`;
- evidence tooling commit:
`2548bb57403411ce9c8374151e3bfa34ac0866ee`;
- target: dedicated Docker-free `MissionCore-Sim` WSL2 Ubuntu 24.04 on D;
- all seven component pins: resolved and `accepted`;
- all seven mutable roots: present under `/mnt/d/NDC_MISSIONCORE`;
- disk at final doctor: 365.55 GiB free, above the 300 GiB start and
200 GiB stop thresholds.
Exact ROS 2, Gazebo, PX4, `px4_msgs`, PX4 Gazebo model, Micro XRCE-DDS Agent and
Nav2 versions remain recorded in the qualification profile and Lab 006.
## Accepted runs
The exact accepted-profile generation produced two immutable runs:
- `20260724T155000Z-accepted-1x`;
- `20260724T160000Z-accepted-2x`.
Both runs passed:
- stock world `rover`, model `rover_ackermann_0`;
- PX4 v1.17.0 and Micro XRCE-DDS session;
- ROS 2 `/fmu/out/vehicle_status_v1`;
- authoritative Gazebo `/clock`;
- loopback-only network namespace;
- pause, single-step and declared speed behavior;
- structured resource baseline;
- clean shutdown with no owned process residue.
The vehicle stayed disarmed. No actuator command was issued.
## Time acceptance
| Case | Pause advance | Single step | Measured RTF | Accepted range |
| --- | ---: | ---: | ---: | ---: |
| 1× | 0 ns | +2,000,000 ns / +1 iteration | 0.981913 | 0.81.2 |
| 2× | 0 ns | +2,000,000 ns / +1 iteration | 1.967258 | 1.62.4 |
Gazebo `/clock` is the closed-loop simulation authority. The zero pause
advance and exact 2 ms single-step are observed deltas, not inferred settings.
## Resource acceptance
| Metric | 1× | 2× | Contract |
| --- | ---: | ---: | ---: |
| Samples at 500 ms | 15 | 15 | at least 6 |
| Peak owned RSS | 407,629,824 B | 408,756,224 B | at most 2 GiB |
| Peak owned CPU | 101.8% | 169.2% | at most 800% |
| Minimum available WSL RAM | 28,437,897,216 B | 28,662,071,296 B | at least 8 GiB |
| Minimum D free | 392,613,560,320 B | 392,568,233,984 B | at least 200 GiB |
| Maximum swap used | 0 B | 0 B | observed |
Global GPU context peaked at 13,579 MiB used and 52% utilization in both cases.
Those values include unrelated co-tenants and are intentionally not attributed
to headless S0.
## Evidence admission
The private D-only evidence generation contains nine redacted JSON artifacts
and one manifest, approximately 100 KiB total:
1. worker inventory;
2. D-only physical placement;
3. PX4 stock-rover launch;
4. ROS 2 telemetry;
5. authoritative simulation clock;
6. pause/step/speed;
7. clean stop with no orphans;
8. 1× resource baseline;
9. 2× resource baseline.
Every manifest entry is `pass`, names a confined regular file and binds its
SHA-256. The manifest binds the accepted profile SHA-256. Failed diagnostic
generations were not reused.
## Target doctor
The read-only doctor returned:
```text
verdict=go
target_host_match=true
profile-contract=pass
authority-contract=pass
clock-contract=pass
port-registry=pass
process-registry=pass
target-host=pass
d-only-storage=pass
disk-budget=pass
version-lock=pass
required-tools=pass
factual-evidence=pass
```
The persisted redacted `doctor.json` SHA-256 is
`6a2571bd7af0e85b1345201068ccd4bffa215f84a8a9f62a4357d5dbfa236c6c`.
## Verdict
`GO` for SIM S0 infrastructure qualification.
The next permitted product phase is SIM S1: server-owned start/pause/resume/
step/reset/stop, immutable `QualificationRun`, canonical Ackermann and
Differential rover commands, TTL/heartbeat/watchdog, stop-on-loss and captured
PX4 failsafe behavior. No real-control permission is created by this verdict.