The kernel proves the pipeline finishes in 972 µs. The HAL proves no sample was invented or silently lost. Neither answers the question that actually harms a user:
The electrode has been off the scalp for four seconds. Why is this system still classifying intent and actuating on it?
Timing correctness is a property of the machine. Signal trustworthiness is a
property of the world — and nothing in AxonOS was reading it. The HAL already
reports everything needed: is_recoverable(), breaks_continuity(), per-frame
lead-off and saturation, cumulative diagnostics. Until now nothing consumed
any of it. This crate is that consumer.
| Posture | Meaning | Classify | Actuate | Record |
|---|---|---|---|---|
Nominal |
the signal is what it claims to be | ✓ | ✓ | ✓ |
Degraded |
usable, but no longer trustworthy | ✓ | ✓ (marked untrusted) | ✓ |
Restricted |
not fit to drive anything | ✓ | ✗ | ✓ |
Safe |
the device or the contact has failed | ✗ | ✗ | ✓ |
Acquisition is never gated. Recording continues in every posture, including
Safe — the moments a system stops trusting itself are precisely the ones a
clinician needs to see afterwards. What degrades is the right to act, because
acting on a bad signal is the only failure here that reaches the physical world.
Degraded deliberately still actuates. A posture that made the device useless
at the first imperfect window would be switched off by its users, and a safety
mechanism people disable protects nobody. What changes is that
signal_trustworthy goes false and downstream must carry that mark.
Degradation is immediate; recovery is earned. A device fault drops the posture on the frame it arrives. Climbing back requires two sustained clean windows and a current window that justifies nothing worse — so a system on the edge does not oscillate between actuating and refusing several times a second, which would be worse than either state. A test drives one bad frame in thirty across six hundred frames and asserts at most two transitions.
Safe is terminal until a human resets it. The same rule as consent
withdrawal, for the same reason: an authority that can restore itself is not an
authority. A device that has decided it is unfit does not get to change its own
mind. reset() also clears the window — a posture restored on evidence gathered
before the fault would be restored on evidence about a different device.
Every transition records its cause. "The system stopped actuating" is not an
incident report. Cause::LeadOff { frames: 32 } at a stated microsecond is.
A converter that simply stops delivering produces no errors at all — it looks
exactly like nothing happening. tick(now_us) exists for that: silence past the
staleness limit is Safe, with the silent duration named. A supervisor that is
purely event-driven cannot see the absence of events.
The window is 64 observations — 256 ms at 250 SPS. Long enough that a single bad frame does not move the posture; short enough that a lifted electrode is caught within a quarter of a second. That bound is what a safety argument needs, and it is asserted in the integration test against the simulated converter.
#![no_std] · #![forbid(unsafe_code)] · #![deny(missing_docs)] · no
allocation · one byte per observation · thresholds public and tunable, with
defaults that are defensible because a threshold nobody sets is the one that
ships.
electrodes → axonos-hal → axonos-vault → axonos-signal-pipeline → axonos-consent
│ ▲
└────────── diagnostics ──→ [ axonos-supervisor ] ─────┘
gates the right to act
Apache-2.0 OR MIT, matching the AxonOS core.
© The AxonOS Project / Denis Yermakou
axonos.org · medium.com/@AxonOS · connect@axonos.org · security@axonos.org