Declaration
Lat, LIR, L-UI, and source metadata provide reportable facts before runtime decisions.
Disabled-by-Default Runtime Surface
The Runtime Boundary is the line between validated metadata and future operational behavior. Nucleus task records and runtime reports remain no-effect, report-only, and denied-by-default.
Current Rule
Current runtime work adds request labels, effect labels, policy decisions, denial reasons, authority prerequisites, Nucleus task metadata, Lat/LIR evidence propagation, and deterministic reports. It does not execute commands, run Lat or LIR, mutate files, contact networks, control hardware, recover systems, or provide a sandbox.
Lat, LIR, L-UI, and source metadata provide reportable facts before runtime decisions.
Constrained authority metadata must be present, no-effect, and successful before any no-effect allow result.
Task classification records request kind, effect kind, prerequisites, policy, denial reason, and no-execution flags.
Runtime records copy evidence, classify modes, report gates, and keep operational requests future-gated.
Reports expose policy, reason, mode, allowed effect, authority labels, task flags, and source spans.
Runtime Snapshot
These fields summarize the posture readers should keep in mind when interpreting runtime or Nucleus records.
Policy Matrix
The policy matrix reports why a request is report-only, validation-only, classification-only, future-gated, blocked, prerequisite-denied, invalid, or unsupported.
Render, task, and evidence reports may be classified only when mode and prerequisites match.
Lat, LIR, Lat pipeline, and authority checks can be validation-only with no-effect metadata.
Classification surfaces can report decisions while preserving execution and mutation flags at zero.
Runtime execute, command execute, file write, network, recovery, hardware, and boot requests stay gated.
Mutation, network, hardware, boot, recovery, external, and unknown effects remain denied.
Failed authority, failed render metadata, failed Lat metadata, failed LIR metadata, or missing task data denies the request.
Nucleus Boundary
Nucleus task records make future task execution auditable by naming request, effect, policy, denial, authority status, gate state, operator metadata, and no-execution flags.
State reports, transition previews, render reports, Lat validation, LIR validation, authority checks, and runtime reports when no-effect prerequisites are satisfied.
Runtime execution, command execution, server interaction, self-update, recovery, rollback, hardware, boot, Lat execution, and LIR execution.
Unknown requests, unknown effects, failed prerequisites, non-no-effect authority flags, and operator-confirmation attempts to override policy.
Local Commands
These guards compile and inspect deterministic C report surfaces. They do not activate runtime behavior.
sh scripts/test-runtime-boundary.sh
sh scripts/test-runtime-boundary-refinement-implementation.sh
sh scripts/test-runtime-boundary-policy-matrix-refinement.sh
sh scripts/test-runtime-boundary-domain-matrix-refinement.sh
sh scripts/test-nucleus-preview.sh
sh scripts/test-nucleus-task-execution.sh
Source Records