CAIN-42 Evolution 18 — 4D Spatial Autonomy Fabric

TESTED no third-party review ephemeral key no vehicle / drone / robot

E18 governs proposals from autonomous systems across a predictive 4D world: reachability, intent, predicted trajectories, interaction and conflict fields, counterfactual futures, consequence, actionability, uncertainty, micro-authorization and a continuous re-authorization loop, all through the E8 governance kernel. ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY. AUTHORIZATION IS A FUNCTION OF WORLD STATE. If any material input changes, REVALIDATE; if the required state cannot be established, DO NOT EXECUTE.

Q1–Q89 invariants 89/89 hold; the CAIN-42-E18-Spatial-Autonomy-Bench is 123/123 contained; end-to-end OK (12/12 mutations governed); the clean-room verifier INTACT (111/111 checks).

NOT IMPLEMENTED / UNKNOWN, stated: an autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack; a real vehicle / drone / robot / sensor / actuator / airspace integration; a physical safety guarantee; hardware attestation or certified autonomy; real sensor validation and real-world adversarial validation; third-party review; multi-host behaviour. HASH_INTEGRITY != SEMANTIC_TRUTH | PREDICTION != REALITY | REACHABILITY != PERMISSION | ACTIONABILITY != AUTHORIZATION.

Q1–Q89 invariant matrix

IDInvariantResult
Q01spatial state is not realityHOLDS
Q02prediction is not realityHOLDS
Q03prediction is not authorityHOLDS
Q04reachability is not permissionHOLDS
Q05permission is not authorizationHOLDS
Q06authorization is not executionHOLDS
Q07execution is not successful outcomeHOLDS
Q08uncertainty cannot silently become certaintyHOLDS
Q09stale state cannot authorize current actionHOLDS
Q10stale trajectory cannot authorize current actionHOLDS
Q11stale geofence cannot authorize current actionHOLDS
Q12stale policy cannot authorize current actionHOLDS
Q13stale model cannot authorize current actionHOLDS
Q14identity substitution invalidates affected authorizationHOLDS
Q15material sensor conflict invalidates affected authorizationHOLDS
Q16material world-state drift invalidates affected authorizationHOLDS
Q17material trajectory drift invalidates affected authorizationHOLDS
Q18material actuator drift invalidates affected authorizationHOLDS
Q19spatial authority cannot exceed delegated authorityHOLDS
Q20geographic authority cannot expand itselfHOLDS
Q21temporal authority cannot expand itselfHOLDS
Q22model confidence cannot create authorityHOLDS
Q23ensemble agreement cannot create authorityHOLDS
Q24prediction consensus cannot create authorityHOLDS
Q25simulation cannot become realityHOLDS
Q26counterfactual cannot become observed stateHOLDS
Q27reachable set cannot become authorized setHOLDS
Q28actionability cannot become authorizationHOLDS
Q29collective intent cannot become authorityHOLDS
Q30external agent messages cannot create authorityHOLDS
Q31dynamic geofences require provenanceHOLDS
Q32spatial identities require provenanceHOLDS
Q33world-state versions must be replayableHOLDS
Q34world-state branches cannot silently mergeHOLDS
Q35trajectories must bind to world stateHOLDS
Q36actions must bind to trajectoriesHOLDS
Q37actions must bind to authorityHOLDS
Q38actions must bind to capabilityHOLDS
Q39actions must bind to consequenceHOLDS
Q40actions must bind to policyHOLDS
Q41actions must bind to riskHOLDS
Q42actions must bind to authorizationHOLDS
Q43every consequential action reaches E8HOLDS
Q44no direct actuator path may bypass governanceHOLDS
Q45unknown cannot become allowHOLDS
Q46denied cannot become allow through retryHOLDS
Q47revoked authorization cannot resurrectHOLDS
Q48consumed authorization cannot replayHOLDS
Q49legitimate sequential execution must remain possibleHOLDS
Q50uncertainty must propagateHOLDS
Q51governance latency cannot justify governance bypassHOLDS
Q52degraded mode cannot silently increase authorityHOLDS
Q53safe state cannot silently become active stateHOLDS
Q54model substitution invalidates model-bound authorizationHOLDS
Q55map substitution invalidates map-bound authorizationHOLDS
Q56sensor provenance cannot be rewritten silentlyHOLDS
Q57historical evidence is immutableHOLDS
Q58prediction error becomes evidenceHOLDS
Q59reality gap cannot be ignoredHOLDS
Q60simulation cannot establish real-world safetyHOLDS
Q61physical integration must remain explicitly boundedHOLDS
Q62unsupported hardware cannot be represented as verifiedHOLDS
Q63third-party validation cannot be impliedHOLDS
Q64multi-host behavior cannot be inferred from single-host testsHOLDS
Q65physical safety cannot be claimed from software-only testsHOLDS
Q66human authority must retain explicit provenanceHOLDS
Q67emergency authority must be boundedHOLDS
Q68recovery cannot mint authorityHOLDS
Q69self-improvement cannot mint authorityHOLDS
Q70collective agreement cannot mint authorityHOLDS
Q71spatial coordination cannot bypass policyHOLDS
Q72trajectory optimization cannot bypass consequence governanceHOLDS
Q73prediction horizon cannot exceed evidence validity without revalidationHOLDS
Q74action authorization must be state-specificHOLDS
Q75every authorization must have a deterministic verification pathHOLDS
Q76conflict detection is not distance-onlyHOLDS
Q77digital-twin layers are never conflatedHOLDS
Q78spatial incident replay uses immutable evidenceHOLDS
Q79geofence versions are monotonicHOLDS
Q80the E8 action binds every spatial digestHOLDS
Q81a refusing policy cannot be re-issued into an authorizationHOLDS
Q82the commit boundary requires an ACTIONABLE, fully evaluated actionabilityHOLDS
Q83a revoked or out-of-domain spatial authority refuses at the boundaryHOLDS
Q84risk above threshold or unknown refusesHOLDS
Q85uncertainty above threshold or unknown refuses and never drops between layersHOLDS
Q86an omitted constraint never matches a constrained authority domainHOLDS
Q87micro-authorization cannot skip revalidation or continue across a world changeHOLDS
Q88the world digest binds the map (roadspace and airspace)HOLDS
Q89a declared altitude must match the positionHOLDS

Spatial autonomy adversarial bench (123/123)

ScenarioResult
actionability_denied_on_authorityCONTAINED
actionability_revalidationCONTAINED
actionability_safe_stateCONTAINED
actuator_substitutionCONTAINED
airspace_altitude_bandCONTAINED
airspace_altitude_spoofCONTAINED
airspace_exclusion_zoneCONTAINED
altitude_spoofingCONTAINED
authority_capability_omissionCONTAINED
authority_lane_omissionCONTAINED
authorization_resurrectionCONTAINED
authorization_reuseCONTAINED
binding_mismatch_capabilityCONTAINED
binding_mismatch_commandCONTAINED
branch_merge_without_reconciliationCONTAINED
classification_unknownCONTAINED
communication_lossCONTAINED
compromised_actuator_adapterCONTAINED
compromised_coordinatorCONTAINED
compromised_perception_agentCONTAINED
compromised_plannerCONTAINED
compromised_world_modelCONTAINED
confidence_inflationCONTAINED
conflict_authority_noneCONTAINED
conflicting_autonomous_agentsCONTAINED
correlated_model_failureCONTAINED
degraded_navigationCONTAINED
delayed_telemetryCONTAINED
drone_action_not_in_domainCONTAINED
drone_vehicle_interactionCONTAINED
dynamic_geofence_attackCONTAINED
emergency_state_bypassCONTAINED
empty_uncertainty_budgetCONTAINED
ensemble_outlierCONTAINED
entity_covariance_invalidCONTAINED
false_object_identityCONTAINED
fleet_wide_policy_mutationCONTAINED
future_branch_invalidCONTAINED
geofence_expiredCONTAINED
geofence_mutationCONTAINED
geofence_no_signatureCONTAINED
geographic_boundary_bypassCONTAINED
governance_clock_staleCONTAINED
governance_window_expiredCONTAINED
governance_window_outside_regionCONTAINED
gps_spoofing_position_jumpCONTAINED
human_override_spoofingCONTAINED
identity_continuity_jumpCONTAINED
incident_replay_missingCONTAINED
intent_unknownCONTAINED
interaction_self_loopCONTAINED
interaction_unknown_relationCONTAINED
invariant_scenario_actionability_not_authorizationCONTAINED
invariant_scenario_conflict_not_distanceCONTAINED
invariant_scenario_deterministic_pathCONTAINED
invariant_scenario_e8_binds_allCONTAINED
invariant_scenario_geofence_monotonicCONTAINED
invariant_scenario_no_actuator_bypassCONTAINED
invariant_scenario_prediction_not_authorityCONTAINED
invariant_scenario_reachability_not_permissionCONTAINED
invariant_scenario_replay_immutableCONTAINED
invariant_scenario_spatial_state_not_realityCONTAINED
invariant_scenario_state_specificCONTAINED
invariant_scenario_twin_layersCONTAINED
invariant_scenario_uncertainty_propagatesCONTAINED
invariant_scenario_unknown_not_allowCONTAINED
latency_budgetCONTAINED
map_corruptionCONTAINED
map_substitution_under_live_authorizationCONTAINED
micro_authorization_consumedCONTAINED
micro_authorization_world_changeCONTAINED
micro_skip_revalidationCONTAINED
missing_obstacleCONTAINED
model_substitutionCONTAINED
multi_agent_coordination_attackCONTAINED
multimodal_independenceCONTAINED
nan_uncertainty_componentCONTAINED
partial_executionCONTAINED
phantom_obstacleCONTAINED
policy_eligibility_not_authorizationCONTAINED
prediction_poisoningCONTAINED
proposal_without_authority_deniedCONTAINED
race_conditionsCONTAINED
reachable_horizon_invalidCONTAINED
reality_gap_materialCONTAINED
recovery_abuseCONTAINED
reissued_actionability_deniedCONTAINED
reissued_actionability_unevaluatedCONTAINED
reissued_authority_out_of_domainCONTAINED
reissued_capability_escalationCONTAINED
reissued_ineligible_policyCONTAINED
reissued_revoked_authorityCONTAINED
reissued_risk_criticalCONTAINED
reissued_risk_missingCONTAINED
reissued_risk_nanCONTAINED
reissued_safe_state_onlyCONTAINED
reissued_trajectory_of_other_entityCONTAINED
reissued_uncertainty_missingCONTAINED
reissued_uncertainty_saturatedCONTAINED
replay_authorizationCONTAINED
roadspace_pedestrian_zoneCONTAINED
roadspace_speed_limitCONTAINED
rollbackCONTAINED
safe_state_bypassCONTAINED
sensor_disagreementCONTAINED
simulation_reality_confusionCONTAINED
simulation_world_cannot_authorizeCONTAINED
spatial_authority_escalationCONTAINED
stale_localizationCONTAINED
temporal_boundary_bypassCONTAINED
timestamp_manipulationCONTAINED
toctouCONTAINED
trajectory_forkCONTAINED
trajectory_substitutionCONTAINED
ttc_uncertainty_presentCONTAINED
twin_gapCONTAINED
uncertainty_budget_exceededCONTAINED
uncertainty_layer_launderingCONTAINED
uncertainty_suppressionCONTAINED
vehicle_action_not_in_domainCONTAINED
world_frozen_cannot_mutateCONTAINED
world_model_divergenceCONTAINED
world_state_forkCONTAINED

End-to-end

StepResult
PERCEPTIONOK
EVIDENCEOK
IDENTITYOK
WORLD_STATE_CREATIONOK
PREDICTIONOK
REACHABLE_SETSOK
TRAJECTORY_HYPOTHESESOK
INTERACTION_GRAPHOK
CONSEQUENCE_PREDICTIONOK
ACTIONABILITYOK
AUTHORITYOK
POLICYOK
AUTHORIZATIONOK
E8_COMMITOK
SIMULATED_EXECUTIONOK
NEW_OBSERVATIONOK
WORLD_STATE_MUTATIONOK
AUTHORIZATION_INVALIDATIONOK
RE_EVALUATIONOK
SAFE_STATE_TRANSITIONOK

Status: TESTED, PRE-PRODUCTION, no third-party review, ephemeral signing key. Evidence class: in-process reference run, not a real-world deployment.