TESTED no third-party review ephemeral key no vehicle / drone / robot
E18 governs proposals from autonomous systems across a predictive 4D world: reachability, intent, predicted trajectories, interaction and conflict fields, counterfactual futures, consequence, actionability, uncertainty, micro-authorization and a continuous re-authorization loop, all through the E8 governance kernel. ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY. AUTHORIZATION IS A FUNCTION OF WORLD STATE. If any material input changes, REVALIDATE; if the required state cannot be established, DO NOT EXECUTE.
Q1–Q89 invariants 89/89 hold; the CAIN-42-E18-Spatial-Autonomy-Bench is 123/123 contained; end-to-end OK (12/12 mutations governed); the clean-room verifier INTACT (111/111 checks).
NOT IMPLEMENTED / UNKNOWN, stated: an autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack; a real vehicle / drone / robot / sensor / actuator / airspace integration; a physical safety guarantee; hardware attestation or certified autonomy; real sensor validation and real-world adversarial validation; third-party review; multi-host behaviour. HASH_INTEGRITY != SEMANTIC_TRUTH | PREDICTION != REALITY | REACHABILITY != PERMISSION | ACTIONABILITY != AUTHORIZATION.
| ID | Invariant | Result |
|---|---|---|
| Q01 | spatial state is not reality | HOLDS |
| Q02 | prediction is not reality | HOLDS |
| Q03 | prediction is not authority | HOLDS |
| Q04 | reachability is not permission | HOLDS |
| Q05 | permission is not authorization | HOLDS |
| Q06 | authorization is not execution | HOLDS |
| Q07 | execution is not successful outcome | HOLDS |
| Q08 | uncertainty cannot silently become certainty | HOLDS |
| Q09 | stale state cannot authorize current action | HOLDS |
| Q10 | stale trajectory cannot authorize current action | HOLDS |
| Q11 | stale geofence cannot authorize current action | HOLDS |
| Q12 | stale policy cannot authorize current action | HOLDS |
| Q13 | stale model cannot authorize current action | HOLDS |
| Q14 | identity substitution invalidates affected authorization | HOLDS |
| Q15 | material sensor conflict invalidates affected authorization | HOLDS |
| Q16 | material world-state drift invalidates affected authorization | HOLDS |
| Q17 | material trajectory drift invalidates affected authorization | HOLDS |
| Q18 | material actuator drift invalidates affected authorization | HOLDS |
| Q19 | spatial authority cannot exceed delegated authority | HOLDS |
| Q20 | geographic authority cannot expand itself | HOLDS |
| Q21 | temporal authority cannot expand itself | HOLDS |
| Q22 | model confidence cannot create authority | HOLDS |
| Q23 | ensemble agreement cannot create authority | HOLDS |
| Q24 | prediction consensus cannot create authority | HOLDS |
| Q25 | simulation cannot become reality | HOLDS |
| Q26 | counterfactual cannot become observed state | HOLDS |
| Q27 | reachable set cannot become authorized set | HOLDS |
| Q28 | actionability cannot become authorization | HOLDS |
| Q29 | collective intent cannot become authority | HOLDS |
| Q30 | external agent messages cannot create authority | HOLDS |
| Q31 | dynamic geofences require provenance | HOLDS |
| Q32 | spatial identities require provenance | HOLDS |
| Q33 | world-state versions must be replayable | HOLDS |
| Q34 | world-state branches cannot silently merge | HOLDS |
| Q35 | trajectories must bind to world state | HOLDS |
| Q36 | actions must bind to trajectories | HOLDS |
| Q37 | actions must bind to authority | HOLDS |
| Q38 | actions must bind to capability | HOLDS |
| Q39 | actions must bind to consequence | HOLDS |
| Q40 | actions must bind to policy | HOLDS |
| Q41 | actions must bind to risk | HOLDS |
| Q42 | actions must bind to authorization | HOLDS |
| Q43 | every consequential action reaches E8 | HOLDS |
| Q44 | no direct actuator path may bypass governance | HOLDS |
| Q45 | unknown cannot become allow | HOLDS |
| Q46 | denied cannot become allow through retry | HOLDS |
| Q47 | revoked authorization cannot resurrect | HOLDS |
| Q48 | consumed authorization cannot replay | HOLDS |
| Q49 | legitimate sequential execution must remain possible | HOLDS |
| Q50 | uncertainty must propagate | HOLDS |
| Q51 | governance latency cannot justify governance bypass | HOLDS |
| Q52 | degraded mode cannot silently increase authority | HOLDS |
| Q53 | safe state cannot silently become active state | HOLDS |
| Q54 | model substitution invalidates model-bound authorization | HOLDS |
| Q55 | map substitution invalidates map-bound authorization | HOLDS |
| Q56 | sensor provenance cannot be rewritten silently | HOLDS |
| Q57 | historical evidence is immutable | HOLDS |
| Q58 | prediction error becomes evidence | HOLDS |
| Q59 | reality gap cannot be ignored | HOLDS |
| Q60 | simulation cannot establish real-world safety | HOLDS |
| Q61 | physical integration must remain explicitly bounded | HOLDS |
| Q62 | unsupported hardware cannot be represented as verified | HOLDS |
| Q63 | third-party validation cannot be implied | HOLDS |
| Q64 | multi-host behavior cannot be inferred from single-host tests | HOLDS |
| Q65 | physical safety cannot be claimed from software-only tests | HOLDS |
| Q66 | human authority must retain explicit provenance | HOLDS |
| Q67 | emergency authority must be bounded | HOLDS |
| Q68 | recovery cannot mint authority | HOLDS |
| Q69 | self-improvement cannot mint authority | HOLDS |
| Q70 | collective agreement cannot mint authority | HOLDS |
| Q71 | spatial coordination cannot bypass policy | HOLDS |
| Q72 | trajectory optimization cannot bypass consequence governance | HOLDS |
| Q73 | prediction horizon cannot exceed evidence validity without revalidation | HOLDS |
| Q74 | action authorization must be state-specific | HOLDS |
| Q75 | every authorization must have a deterministic verification path | HOLDS |
| Q76 | conflict detection is not distance-only | HOLDS |
| Q77 | digital-twin layers are never conflated | HOLDS |
| Q78 | spatial incident replay uses immutable evidence | HOLDS |
| Q79 | geofence versions are monotonic | HOLDS |
| Q80 | the E8 action binds every spatial digest | HOLDS |
| Q81 | a refusing policy cannot be re-issued into an authorization | HOLDS |
| Q82 | the commit boundary requires an ACTIONABLE, fully evaluated actionability | HOLDS |
| Q83 | a revoked or out-of-domain spatial authority refuses at the boundary | HOLDS |
| Q84 | risk above threshold or unknown refuses | HOLDS |
| Q85 | uncertainty above threshold or unknown refuses and never drops between layers | HOLDS |
| Q86 | an omitted constraint never matches a constrained authority domain | HOLDS |
| Q87 | micro-authorization cannot skip revalidation or continue across a world change | HOLDS |
| Q88 | the world digest binds the map (roadspace and airspace) | HOLDS |
| Q89 | a declared altitude must match the position | HOLDS |
| Scenario | Result |
|---|---|
| actionability_denied_on_authority | CONTAINED |
| actionability_revalidation | CONTAINED |
| actionability_safe_state | CONTAINED |
| actuator_substitution | CONTAINED |
| airspace_altitude_band | CONTAINED |
| airspace_altitude_spoof | CONTAINED |
| airspace_exclusion_zone | CONTAINED |
| altitude_spoofing | CONTAINED |
| authority_capability_omission | CONTAINED |
| authority_lane_omission | CONTAINED |
| authorization_resurrection | CONTAINED |
| authorization_reuse | CONTAINED |
| binding_mismatch_capability | CONTAINED |
| binding_mismatch_command | CONTAINED |
| branch_merge_without_reconciliation | CONTAINED |
| classification_unknown | CONTAINED |
| communication_loss | CONTAINED |
| compromised_actuator_adapter | CONTAINED |
| compromised_coordinator | CONTAINED |
| compromised_perception_agent | CONTAINED |
| compromised_planner | CONTAINED |
| compromised_world_model | CONTAINED |
| confidence_inflation | CONTAINED |
| conflict_authority_none | CONTAINED |
| conflicting_autonomous_agents | CONTAINED |
| correlated_model_failure | CONTAINED |
| degraded_navigation | CONTAINED |
| delayed_telemetry | CONTAINED |
| drone_action_not_in_domain | CONTAINED |
| drone_vehicle_interaction | CONTAINED |
| dynamic_geofence_attack | CONTAINED |
| emergency_state_bypass | CONTAINED |
| empty_uncertainty_budget | CONTAINED |
| ensemble_outlier | CONTAINED |
| entity_covariance_invalid | CONTAINED |
| false_object_identity | CONTAINED |
| fleet_wide_policy_mutation | CONTAINED |
| future_branch_invalid | CONTAINED |
| geofence_expired | CONTAINED |
| geofence_mutation | CONTAINED |
| geofence_no_signature | CONTAINED |
| geographic_boundary_bypass | CONTAINED |
| governance_clock_stale | CONTAINED |
| governance_window_expired | CONTAINED |
| governance_window_outside_region | CONTAINED |
| gps_spoofing_position_jump | CONTAINED |
| human_override_spoofing | CONTAINED |
| identity_continuity_jump | CONTAINED |
| incident_replay_missing | CONTAINED |
| intent_unknown | CONTAINED |
| interaction_self_loop | CONTAINED |
| interaction_unknown_relation | CONTAINED |
| invariant_scenario_actionability_not_authorization | CONTAINED |
| invariant_scenario_conflict_not_distance | CONTAINED |
| invariant_scenario_deterministic_path | CONTAINED |
| invariant_scenario_e8_binds_all | CONTAINED |
| invariant_scenario_geofence_monotonic | CONTAINED |
| invariant_scenario_no_actuator_bypass | CONTAINED |
| invariant_scenario_prediction_not_authority | CONTAINED |
| invariant_scenario_reachability_not_permission | CONTAINED |
| invariant_scenario_replay_immutable | CONTAINED |
| invariant_scenario_spatial_state_not_reality | CONTAINED |
| invariant_scenario_state_specific | CONTAINED |
| invariant_scenario_twin_layers | CONTAINED |
| invariant_scenario_uncertainty_propagates | CONTAINED |
| invariant_scenario_unknown_not_allow | CONTAINED |
| latency_budget | CONTAINED |
| map_corruption | CONTAINED |
| map_substitution_under_live_authorization | CONTAINED |
| micro_authorization_consumed | CONTAINED |
| micro_authorization_world_change | CONTAINED |
| micro_skip_revalidation | CONTAINED |
| missing_obstacle | CONTAINED |
| model_substitution | CONTAINED |
| multi_agent_coordination_attack | CONTAINED |
| multimodal_independence | CONTAINED |
| nan_uncertainty_component | CONTAINED |
| partial_execution | CONTAINED |
| phantom_obstacle | CONTAINED |
| policy_eligibility_not_authorization | CONTAINED |
| prediction_poisoning | CONTAINED |
| proposal_without_authority_denied | CONTAINED |
| race_conditions | CONTAINED |
| reachable_horizon_invalid | CONTAINED |
| reality_gap_material | CONTAINED |
| recovery_abuse | CONTAINED |
| reissued_actionability_denied | CONTAINED |
| reissued_actionability_unevaluated | CONTAINED |
| reissued_authority_out_of_domain | CONTAINED |
| reissued_capability_escalation | CONTAINED |
| reissued_ineligible_policy | CONTAINED |
| reissued_revoked_authority | CONTAINED |
| reissued_risk_critical | CONTAINED |
| reissued_risk_missing | CONTAINED |
| reissued_risk_nan | CONTAINED |
| reissued_safe_state_only | CONTAINED |
| reissued_trajectory_of_other_entity | CONTAINED |
| reissued_uncertainty_missing | CONTAINED |
| reissued_uncertainty_saturated | CONTAINED |
| replay_authorization | CONTAINED |
| roadspace_pedestrian_zone | CONTAINED |
| roadspace_speed_limit | CONTAINED |
| rollback | CONTAINED |
| safe_state_bypass | CONTAINED |
| sensor_disagreement | CONTAINED |
| simulation_reality_confusion | CONTAINED |
| simulation_world_cannot_authorize | CONTAINED |
| spatial_authority_escalation | CONTAINED |
| stale_localization | CONTAINED |
| temporal_boundary_bypass | CONTAINED |
| timestamp_manipulation | CONTAINED |
| toctou | CONTAINED |
| trajectory_fork | CONTAINED |
| trajectory_substitution | CONTAINED |
| ttc_uncertainty_present | CONTAINED |
| twin_gap | CONTAINED |
| uncertainty_budget_exceeded | CONTAINED |
| uncertainty_layer_laundering | CONTAINED |
| uncertainty_suppression | CONTAINED |
| vehicle_action_not_in_domain | CONTAINED |
| world_frozen_cannot_mutate | CONTAINED |
| world_model_divergence | CONTAINED |
| world_state_fork | CONTAINED |
| Step | Result |
|---|---|
| PERCEPTION | OK |
| EVIDENCE | OK |
| IDENTITY | OK |
| WORLD_STATE_CREATION | OK |
| PREDICTION | OK |
| REACHABLE_SETS | OK |
| TRAJECTORY_HYPOTHESES | OK |
| INTERACTION_GRAPH | OK |
| CONSEQUENCE_PREDICTION | OK |
| ACTIONABILITY | OK |
| AUTHORITY | OK |
| POLICY | OK |
| AUTHORIZATION | OK |
| E8_COMMIT | OK |
| SIMULATED_EXECUTION | OK |
| NEW_OBSERVATION | OK |
| WORLD_STATE_MUTATION | OK |
| AUTHORIZATION_INVALIDATION | OK |
| RE_EVALUATION | OK |
| SAFE_STATE_TRANSITION | OK |
Status: TESTED, PRE-PRODUCTION, no third-party review, ephemeral signing key. Evidence class: in-process reference run, not a real-world deployment.