Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Nazm v1 — the domain matrix

Every v1 domain claim points here (systems-domains.md, Part T). A row is VERIFIED only when its reference workload has executable evidence of the kind its Evidence column names; otherwise it is PARTIAL (some evidence, gaps named), PLANNED (Gate 3 work not yet done) or BLOCKED (cannot be run here, and why). Evidence labels are systems-domains.md’s: run-verified (native), under Rosetta, emulated host, under Wine (not evidence from a Windows host), emulator-verified. capability-matrix.md remains the implementation truth; where they disagree, it is right.

Opened 2026-10-10 at 5caa642, the start of Gate 3: each status below is the state before Gate 3’s work, and is updated by the step that changes it.

Hosts

HostTargetsEvidenceStatusRemaining gapNon-claim
macOS ARM64aarch64-apple-darwinrun-verified (native), both backends (cross.rs); prebuilt archive, clean install passed (3B)VERIFIED——
macOS x86_64x86_64-apple-darwinrun-verified under Rosetta, both backends; prebuilt archive, clean install passed under Rosetta (3B)PARTIAL — Rosetta, not an Intel hostnative Intel execution, if final Tier-1 policy requires itnot “verified on Intel hardware”
Linux ARM64aarch64-unknown-linux-gnurun-verified in a container, both backends; prebuilt archive, clean install in a clean container passed (3B)VERIFIED——
Linux x86_64x86_64-unknown-linux-gnucompile-onlyPLANNED (3B)execution—
Windows x86_64x86_64-pc-windows-gnu (MinGW-w64)run-verified under Wine, both backends (windows.rs, 3C): conformance, files, sockets and the reactor, processes and pipes, clocks, UTF-8 arguments, traps and N0408PARTIAL — Wine, not a Windows hostreal Windows host execution — a final-v1 item; a DLL; a prebuilt toolchain for a Windows host; the MSVC environmentWine evidence is not Windows-host evidence
Windows ARM64—noneTier 2 / preview at most——

Domains

DomainProfileTargetsRequired mechanismsReference workloadEvidenceStatusRemaining ecosystem gapNon-claim
Systems / OS foundationkernel (no-spawn, no-foreign, no-blocking, no-heap)aarch64-unknown-none, riscv64gc-unknown-none-elfatomics, statics, sections, board manifests, interrupts, arena, failure hook (3D)timer-interrupt kernel image (kernel.rs)emulator-verifiedVERIFIED on AArch64, emulator-verified (3D): the workload boots under QEMU at -O0 and -O2 — timer ticks into a static atomic, a polled UART, a fault the @on_failure hook sees by number; each mechanism’s own QEMU test (sections.rs, manifests.rs, interrupts.rs, heap.rs). PARTIAL on RISC-V: no interrupts (refused by name, N0626); its other mechanisms are not run in 3Ddrivers, filesystems, paging, RISC-V interruptsnot “OS-ready”; no hardware run
Embeddedembeddedthe two boards + Cortex-M thumbv7m-none-eabi (3E)@std/hal, timers, interrupts, linker layout, manifeststimer + GPIO state machine (embedded.rs)emulator-verifiedVERIFIED, emulator-verified (3E): one traffic light, generic over @std/hal’s traits, runs unchanged on QEMU’s AArch64 virt (PL011, PL061, the GIC’s timer) and the MPS2 Cortex-M3 (CMSDK UART, FPGA LEDs, SysTick) at -O0 and -O2; the Cortex-M3 has no floating point, no 64-bit device access and no heap in 1.0vendor HALs, real boards, more MCU familiesno hardware run
Realtimerealtimeboards; hostbounded loops/stack/blocking, static topology, deadlines, fixed-priority mode (3F)periodic tasks with deadlines (realtime_tasks.rs)emulator-verified, profile reportsVERIFIED, emulator-verified (3F): @tasks at two priorities run by the fixed-priority scheduler on both boards (1004), a missed deadline reported (N0414); realtime with bounded-stack and no-heap. Narrowed: no-heap for no-heap-after-init, bounded-loops its one counted formWCET analysis; preemption; an initialisation phase that allocatesnot “hard real-time”; no execution time bounded
Roboticsrobotics = realtime + device authorityhost, boardsfloat, @std/linalg, timers, bounded channels, HALsense → control → actuate at a fixed raterun- and emulator-verifiedPLANNED (3G)ROS/DDS—
Industrialindustrial = realtime + critical + watchdogboardswatchdog, state machine, device I/Ocontroller with fail-safe stateemulator-verifiedPLANNED (3G)Modbus, EtherCAT, PROFINET, OPC UA—
High assurancecritical, strengthenedhost, boardsbounded memory/stack/loops, no unknown effects, strict FFI, reproducible artefact, obligations, tracecontroller with every obligation proved or checkedrun-verified, obligation and trace reportsPARTIAL — contracts and obligations (N87)proof, qualified toolchainnot certified
Aerospaceaerospace = embedded + realtime + critical + domain rulesboardsas above + deterministic floatssample → estimate → actuate, fault transition, telemetryemulator-verifiedPLANNED (3G)ARINC, MIL-STD, SpaceWireno DO-178C claim
Automotiveautomotive = realtime + criticalboards, hostCAN-like frame boundaryperiodic ECU task, state machine, failure stateemulator- and run-verifiedPLANNED (3G)AUTOSARno ISO 26262 claim
Medical-device stylemedical = critical + realtime + auditboards, hostaudit records, fault state, restricted authoritydevice controller with audit logrun-verifiedPLANNED (3G)—no regulatory approval
Cybersecuritycyberhostslocked build, provenance, attestation, explicit authorityattested secure servicerun-verifiedPARTIAL — profile, provenance, attestation (N73, N87, N94)TLS, cryptographyno sandboxing or non-interference claim
AI / HPC— (accelerator)macOS (OpenCL), CPUCPU provider, float kernels, SIMD (3H)map/zip/reduce held to an oraclerun-verifiedPARTIAL — one provider, Int only, no CPU fallback (N67, N88)Metal, CUDA, ROCm, SPIR-Vno performance claim without a filed measurement
Storage engine—hostsbinary layout, WAL, recovery, locking (3I)page store with crash recoveryrun-verifiedPARTIAL — kvstore (Gate 2)mmap, direct I/O if unsoundno database-maturity claim
Distributed—hostsnode identity, framed transport, retry, idempotency (3I)two processes, one restartedrun-verifiedPLANNED — TCP/UDP, select, deadlines existconsensus, TLS—
WASM / Web—wasm32-unknown-unknown, wasm32-wasip1 (3J)heap, streams, files under capability rulesWASI program on a reference runtimerun-verifiedPARTIAL — freestanding wasm32 on Node (N64)browser DOM—
Mobile—aarch64-linux-android, aarch64-apple-ios (3K)C-ABI library, host shellNazm library called from a minimal hostAndroid: as run; iOS: after XcodePLANNEDUI frameworksnot run-verified where not run
Desktop integration—macOSC ABI, callback, event loopa Cocoa window driven by Nazm logicrun-verifiedPLANNED (3K)a Nazm GUI framework—
Web3web3, accountsEVM, wasm32contract model, metering, upgrade checkssimulator/EVM/WASM agreementrun-verified (py-evm, Node)PARTIAL — qualified in 3L (N69–N72, N96)sBPF (blocked), chain host interfacesnot audited, not deployed
Requirements traceability—allrequirement ids, DefKey-keyed obligations, nazm trace (3L)high-assurance controller’s tracerun-verifiedPLANNED—no certification claim