Kshana run report

Jamming, spoofing, holdover and integrity: a chained mission

Kind campaign · engine 0.34.0 · scenario campaign-jam-spoof-holdover-integrity.toml (file digest cec1e10f8eb478ba…)

1. Executive summary

Campaign: existing scenario kinds composed into one run, with every number read from a real run of the named kind.

campaign f87a4a0e0bab | Jamming, spoofing, holdover and integrity: a chained mission | chain: 6 phases over 4570 s, 2 events, alarm raised on 2770 s of the grid | 18 member runs (MODELLED)

reproducibility.runs_total
18 count
seed
20260928
timeline.duration_s
4570 s
timeline.step_s
10 s
reproducibility.runs_total
18 count

Honesty label (result `label`): MODELLED composition of existing scenario kinds. Every number is read from a real run of the named kind; the chaining (additive carry of a channel across a phase boundary, zero-order hold onto the timeline grid, a phase ended at a computed time) is a modelling choice, and each phase carries the label of the kind that produced it.

Capabilities used: 5 VALIDATED, 7 MODELLED, 1 PARTNER (relied on, not provided); see section 5.

Member runs: 18, aggregated in section 3a.

2. Inputs

Every field the scenario file sets, flattened to its path. Units come from the result's units block (the field-units schema, docs/field-units-schema.json) where it describes the field, otherwise from the field-name suffix; a unit neither states is shown as not stated.

ParameterValueUnitUnit source
kindcampaigntexta text input carries no unit
phases[0].duration_s600sfield-name suffix
phases[0].namenominaltexta text input carries no unit
phases[0].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[0].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[0].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[0].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[0].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[0].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[0].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[0].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[0].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[0].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[0].runs[0].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[0].runs[0].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[0].runs[0].scenario.gnss.windows[0].t1600not statedno units entry and no unit suffix
phases[0].runs[0].scenario.seed421field-units schema: input entry `seed`, matched by field name
phases[0].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[0].runs[0].scenario.time.duration_s600sfield-name suffix
phases[0].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[0].runs[1].scenario.constellation.altitude_km20200kmfield-name suffix
phases[0].runs[1].scenario.constellation.inclination_deg55degfield-name suffix
phases[0].runs[1].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[0].runs[1].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[0].runs[1].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[0].runs[1].scenario.kindjammingtexta text input carries no unit
phases[0].runs[1].scenario.mask_deg5degfield-name suffix
phases[0].runs[1].scenario.receiver.alt_m0mfield-name suffix
phases[0].runs[1].scenario.receiver.lat_deg52degfield-name suffix
phases[0].runs[1].scenario.receiver.lon_deg4degfield-name suffix
phases[0].runs[1].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[0].runs[1].scenario.time.duration_s600sfield-name suffix
phases[0].runs[1].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[0].runs[1].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[0].runs[2].scenario.al_h_m40mfield-name suffix
phases[0].runs[2].scenario.al_v_m50mfield-name suffix
phases[0].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[0].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[0].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[0].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[0].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[0].runs[2].scenario.kindintegritytexta text input carries no unit
phases[0].runs[2].scenario.mask_deg5degfield-name suffix
phases[0].runs[2].scenario.p_fa1.0000e-5not statedno units entry and no unit suffix
phases[0].runs[2].scenario.p_md0.001not statedno units entry and no unit suffix
phases[0].runs[2].scenario.seed71field-units schema: input entry `seed`, matched by field name
phases[0].runs[2].scenario.sigma_uere_m1mfield-name suffix
phases[0].runs[2].scenario.time.duration_s600sfield-name suffix
phases[0].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[0].runs[2].scenario.user.altitude_km0.4kmfield-name suffix
phases[0].runs[2].scenario.user.inclination_deg45degfield-name suffix
phases[0].runs[2].scenario.user.raan_deg10degfield-name suffix
phases[0].runs[2].scenario.user.u0_deg0degfield-name suffix
phases[1].duration_s600sfield-name suffix
phases[1].namejammingtexta text input carries no unit
phases[1].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[1].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[1].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[1].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[1].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[1].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[1].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[1].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[1].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[1].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[1].runs[0].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[1].runs[0].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[1].runs[0].scenario.gnss.windows[0].t1600not statedno units entry and no unit suffix
phases[1].runs[0].scenario.seed431field-units schema: input entry `seed`, matched by field name
phases[1].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[1].runs[0].scenario.time.duration_s600sfield-name suffix
phases[1].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[1].runs[1].scenario.constellation.altitude_km20200kmfield-name suffix
phases[1].runs[1].scenario.constellation.inclination_deg55degfield-name suffix
phases[1].runs[1].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[1].runs[1].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[1].runs[1].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[1].runs[1].scenario.jammer.bandwidth_mhz20MHzfield-name suffix
phases[1].runs[1].scenario.jammer.gain_dbi0dBifield-name suffix
phases[1].runs[1].scenario.jammer.jammer_typebroadbandtexta text input carries no unit
phases[1].runs[1].scenario.jammer.position_ecef_m[3.9264e6, 2.7449e5, 5.0028e6]mfield-name suffix
phases[1].runs[1].scenario.jammer.power_dbw-30dBWfield-name suffix
phases[1].runs[1].scenario.kindjammingtexta text input carries no unit
phases[1].runs[1].scenario.mask_deg5degfield-name suffix
phases[1].runs[1].scenario.receiver.alt_m0mfield-name suffix
phases[1].runs[1].scenario.receiver.lat_deg52degfield-name suffix
phases[1].runs[1].scenario.receiver.lon_deg4degfield-name suffix
phases[1].runs[1].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[1].runs[1].scenario.time.duration_s600sfield-name suffix
phases[1].runs[1].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[1].runs[1].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[1].runs[2].scenario.al_h_m40mfield-name suffix
phases[1].runs[2].scenario.al_v_m50mfield-name suffix
phases[1].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[1].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[1].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[1].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[1].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[1].runs[2].scenario.kindintegritytexta text input carries no unit
phases[1].runs[2].scenario.mask_deg5degfield-name suffix
phases[1].runs[2].scenario.p_fa1.0000e-5not statedno units entry and no unit suffix
phases[1].runs[2].scenario.p_md0.001not statedno units entry and no unit suffix
phases[1].runs[2].scenario.seed71field-units schema: input entry `seed`, matched by field name
phases[1].runs[2].scenario.sigma_uere_m1mfield-name suffix
phases[1].runs[2].scenario.time.duration_s600sfield-name suffix
phases[1].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[1].runs[2].scenario.user.altitude_km0.4kmfield-name suffix
phases[1].runs[2].scenario.user.inclination_deg45degfield-name suffix
phases[1].runs[2].scenario.user.raan_deg10degfield-name suffix
phases[1].runs[2].scenario.user.u0_deg0degfield-name suffix
phases[2].duration_s900sfield-name suffix
phases[2].end_atclassical.detect_time_stexta text input carries no unit
phases[2].namespoofingtexta text input carries no unit
phases[2].runs[0].scenario.attack.rate_ns_per_s0.1sfield-name suffix
phases[2].runs[0].scenario.attack.start_s0sfield-name suffix
phases[2].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[2].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[2].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[2].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[2].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[2].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[2].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[2].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[2].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[2].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[2].runs[0].scenario.kindspooftexta text input carries no unit
phases[2].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[2].runs[0].scenario.time.duration_s900sfield-name suffix
phases[2].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[2].runs[1].scenario.attack.carrier_alignedfalseflaga true/false input carries no unit
phases[2].runs[1].scenario.attack.el_imbalance0.12not statedno units entry and no unit suffix
phases[2].runs[1].scenario.attack.num_biased3not statedno units entry and no unit suffix
phases[2].runs[1].scenario.attack.power_advantage_db1.5dBfield-name suffix
phases[2].runs[1].scenario.attack.pushpositiontexta text input carries no unit
phases[2].runs[1].scenario.attack.push_magnitude_m75mfield-name suffix
phases[2].runs[1].scenario.detector.agc_margin_db3dBfield-name suffix
phases[2].runs[1].scenario.detector.fusion_threshold0.5not statedno units entry and no unit suffix
phases[2].runs[1].scenario.detector.raim_p_fa0.001not statedno units entry and no unit suffix
phases[2].runs[1].scenario.detector.sat_power_dbm-130dBmfield-name suffix
phases[2].runs[1].scenario.detector.sigma_m5mfield-name suffix
phases[2].runs[1].scenario.detector.sqm_tolerance0.1not statedno units entry and no unit suffix
phases[2].runs[1].scenario.kindspoof-detecttexta text input carries no unit
phases[2].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[2].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[2].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[2].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[2].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[2].runs[2].scenario.jammer.bandwidth_mhz20MHzfield-name suffix
phases[2].runs[2].scenario.jammer.gain_dbi0dBifield-name suffix
phases[2].runs[2].scenario.jammer.jammer_typebroadbandtexta text input carries no unit
phases[2].runs[2].scenario.jammer.position_ecef_m[3.9264e6, 2.7449e5, 5.0028e6]mfield-name suffix
phases[2].runs[2].scenario.jammer.power_dbw-30dBWfield-name suffix
phases[2].runs[2].scenario.kindjammingtexta text input carries no unit
phases[2].runs[2].scenario.mask_deg5degfield-name suffix
phases[2].runs[2].scenario.receiver.alt_m0mfield-name suffix
phases[2].runs[2].scenario.receiver.lat_deg52degfield-name suffix
phases[2].runs[2].scenario.receiver.lon_deg4degfield-name suffix
phases[2].runs[2].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[2].runs[2].scenario.time.duration_s900sfield-name suffix
phases[2].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[2].runs[2].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[3].carry[time_error_ns]not statedno units entry and no unit suffix
phases[3].duration_s1800sfield-name suffix
phases[3].nameholdovertexta text input carries no unit
phases[3].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[3].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[3].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[3].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[3].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[3].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[3].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[3].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[3].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[3].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[3].runs[0].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[3].runs[0].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[3].runs[0].scenario.gnss.windows[0].t11not statedno units entry and no unit suffix
phases[3].runs[0].scenario.gnss.windows[1].statedeniedtexta text input carries no unit
phases[3].runs[0].scenario.gnss.windows[1].t01not statedno units entry and no unit suffix
phases[3].runs[0].scenario.gnss.windows[1].t11800not statedno units entry and no unit suffix
phases[3].runs[0].scenario.seed441field-units schema: input entry `seed`, matched by field name
phases[3].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[3].runs[0].scenario.time.duration_s1800sfield-name suffix
phases[3].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[3].runs[1].scenario.alt_m0mfield-name suffix
phases[3].runs[1].scenario.fix_interval_s1sfield-name suffix
phases[3].runs[1].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[3].runs[1].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[3].runs[1].scenario.gnss.windows[0].t1100not statedno units entry and no unit suffix
phases[3].runs[1].scenario.gnss.windows[1].statedeniedtexta text input carries no unit
phases[3].runs[1].scenario.gnss.windows[1].t0100not statedno units entry and no unit suffix
phases[3].runs[1].scenario.gnss.windows[1].t11900not statedno units entry and no unit suffix
phases[3].runs[1].scenario.imu_classical.accel_bias[0.03, -0.02, 0]not statedno units entry and no unit suffix
phases[3].runs[1].scenario.imu_classical.gyro_bias[0, 0, 1.0000e-4]not statedno units entry and no unit suffix
phases[3].runs[1].scenario.imu_classical.idtactical-imutexta text input carries no unit
phases[3].runs[1].scenario.imu_classical.provenanceTactical-grade MEMS/quartz inertial unit: larger residual biastexta text input carries no unit
phases[3].runs[1].scenario.imu_quantum.accel_bias[0.015, 0, 0]not statedno units entry and no unit suffix
phases[3].runs[1].scenario.imu_quantum.gyro_bias[0, 0, 5.0000e-5]not statedno units entry and no unit suffix
phases[3].runs[1].scenario.imu_quantum.idcold-atom-imutexta text input carries no unit
phases[3].runs[1].scenario.imu_quantum.provenanceQuantum-grade inertial unit: low residual accelerometer/gyro bias (cold-atom-class)texta text input carries no unit
phases[3].runs[1].scenario.kindgnss-instexta text input carries no unit
phases[3].runs[1].scenario.lat_deg52degfield-name suffix
phases[3].runs[1].scenario.lon_deg4degfield-name suffix
phases[3].runs[1].scenario.seed71field-units schema: input entry `seed`, matched by field name
phases[3].runs[1].scenario.sigma_pos_m1mfield-name suffix
phases[3].runs[1].scenario.sigma_vel_mps0.05m/sfield-name suffix
phases[3].runs[1].scenario.threshold_m50mfield-name suffix
phases[3].runs[1].scenario.time.duration_s1900sfield-name suffix
phases[3].runs[1].scenario.time.step_s0.5sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[3].runs[1].skip_s100sfield-units schema: input entry `timeline.phases[].runs[].skip_s`, matched by field name
phases[3].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[3].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[3].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[3].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[3].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[3].runs[2].scenario.jammer.bandwidth_mhz20MHzfield-name suffix
phases[3].runs[2].scenario.jammer.gain_dbi0dBifield-name suffix
phases[3].runs[2].scenario.jammer.jammer_typebroadbandtexta text input carries no unit
phases[3].runs[2].scenario.jammer.position_ecef_m[3.9264e6, 2.7449e5, 5.0028e6]mfield-name suffix
phases[3].runs[2].scenario.jammer.power_dbw10dBWfield-name suffix
phases[3].runs[2].scenario.kindjammingtexta text input carries no unit
phases[3].runs[2].scenario.mask_deg5degfield-name suffix
phases[3].runs[2].scenario.receiver.alt_m0mfield-name suffix
phases[3].runs[2].scenario.receiver.lat_deg52degfield-name suffix
phases[3].runs[2].scenario.receiver.lon_deg4degfield-name suffix
phases[3].runs[2].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[3].runs[2].scenario.time.duration_s1800sfield-name suffix
phases[3].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[3].runs[2].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[4].carry[time_error_ns]not statedno units entry and no unit suffix
phases[4].duration_s600sfield-name suffix
phases[4].nameintegrity-alarmtexta text input carries no unit
phases[4].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[4].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[4].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[4].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[4].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[4].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[4].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[4].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[4].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[4].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[4].runs[0].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[4].runs[0].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[4].runs[0].scenario.gnss.windows[0].t11not statedno units entry and no unit suffix
phases[4].runs[0].scenario.gnss.windows[1].statedeniedtexta text input carries no unit
phases[4].runs[0].scenario.gnss.windows[1].t01not statedno units entry and no unit suffix
phases[4].runs[0].scenario.gnss.windows[1].t1600not statedno units entry and no unit suffix
phases[4].runs[0].scenario.seed451field-units schema: input entry `seed`, matched by field name
phases[4].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[4].runs[0].scenario.time.duration_s600sfield-name suffix
phases[4].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[4].runs[1].scenario.constellation.altitude_km20200kmfield-name suffix
phases[4].runs[1].scenario.constellation.inclination_deg55degfield-name suffix
phases[4].runs[1].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[4].runs[1].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[4].runs[1].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[4].runs[1].scenario.jammer.bandwidth_mhz20MHzfield-name suffix
phases[4].runs[1].scenario.jammer.gain_dbi0dBifield-name suffix
phases[4].runs[1].scenario.jammer.jammer_typebroadbandtexta text input carries no unit
phases[4].runs[1].scenario.jammer.position_ecef_m[3.9264e6, 2.7449e5, 5.0028e6]mfield-name suffix
phases[4].runs[1].scenario.jammer.power_dbw-30dBWfield-name suffix
phases[4].runs[1].scenario.kindjammingtexta text input carries no unit
phases[4].runs[1].scenario.mask_deg25degfield-name suffix
phases[4].runs[1].scenario.receiver.alt_m0mfield-name suffix
phases[4].runs[1].scenario.receiver.lat_deg52degfield-name suffix
phases[4].runs[1].scenario.receiver.lon_deg4degfield-name suffix
phases[4].runs[1].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[4].runs[1].scenario.time.duration_s600sfield-name suffix
phases[4].runs[1].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[4].runs[1].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[4].runs[2].scenario.al_h_m40mfield-name suffix
phases[4].runs[2].scenario.al_v_m50mfield-name suffix
phases[4].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[4].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[4].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[4].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[4].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[4].runs[2].scenario.kindintegritytexta text input carries no unit
phases[4].runs[2].scenario.mask_deg25degfield-name suffix
phases[4].runs[2].scenario.p_fa1.0000e-5not statedno units entry and no unit suffix
phases[4].runs[2].scenario.p_md0.001not statedno units entry and no unit suffix
phases[4].runs[2].scenario.seed71field-units schema: input entry `seed`, matched by field name
phases[4].runs[2].scenario.sigma_uere_m1mfield-name suffix
phases[4].runs[2].scenario.time.duration_s600sfield-name suffix
phases[4].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[4].runs[2].scenario.user.altitude_km0.4kmfield-name suffix
phases[4].runs[2].scenario.user.inclination_deg45degfield-name suffix
phases[4].runs[2].scenario.user.raan_deg10degfield-name suffix
phases[4].runs[2].scenario.user.u0_deg0degfield-name suffix
phases[5].duration_s600sfield-name suffix
phases[5].namerecoverytexta text input carries no unit
phases[5].runs[0].scenario.clock_classical.idcsac-sa45stexta text input carries no unit
phases[5].runs[0].scenario.clock_classical.provenanceMicrochip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10; q_wf=sigma_y(1s)^2.texta text input carries no unit
phases[5].runs[0].scenario.clock_classical.q_rw0not statedno units entry and no unit suffix
phases[5].runs[0].scenario.clock_classical.q_wf9.0000e-20not statedno units entry and no unit suffix
phases[5].runs[0].scenario.clock_classical.y05.0000e-10not statedno units entry and no unit suffix
phases[5].runs[0].scenario.clock_quantum.idoptical-sr-latticetexta text input carries no unit
phases[5].runs[0].scenario.clock_quantum.provenanceStrontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457); not flown.texta text input carries no unit
phases[5].runs[0].scenario.clock_quantum.q_rw0not statedno units entry and no unit suffix
phases[5].runs[0].scenario.clock_quantum.q_wf1.0000e-30not statedno units entry and no unit suffix
phases[5].runs[0].scenario.clock_quantum.y05.0000e-17not statedno units entry and no unit suffix
phases[5].runs[0].scenario.gnss.windows[0].statenominaltexta text input carries no unit
phases[5].runs[0].scenario.gnss.windows[0].t00not statedno units entry and no unit suffix
phases[5].runs[0].scenario.gnss.windows[0].t1600not statedno units entry and no unit suffix
phases[5].runs[0].scenario.seed461field-units schema: input entry `seed`, matched by field name
phases[5].runs[0].scenario.threshold_ns50nsfield-name suffix
phases[5].runs[0].scenario.time.duration_s600sfield-name suffix
phases[5].runs[0].scenario.time.step_s10sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[5].runs[1].scenario.constellation.altitude_km20200kmfield-name suffix
phases[5].runs[1].scenario.constellation.inclination_deg55degfield-name suffix
phases[5].runs[1].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[5].runs[1].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[5].runs[1].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[5].runs[1].scenario.kindjammingtexta text input carries no unit
phases[5].runs[1].scenario.mask_deg5degfield-name suffix
phases[5].runs[1].scenario.receiver.alt_m0mfield-name suffix
phases[5].runs[1].scenario.receiver.lat_deg52degfield-name suffix
phases[5].runs[1].scenario.receiver.lon_deg4degfield-name suffix
phases[5].runs[1].scenario.seed11field-units schema: input entry `seed`, matched by field name
phases[5].runs[1].scenario.time.duration_s600sfield-name suffix
phases[5].runs[1].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[5].runs[1].scenario.tracking_threshold_dbhz25dB-Hzfield-name suffix
phases[5].runs[2].scenario.al_h_m40mfield-name suffix
phases[5].runs[2].scenario.al_v_m50mfield-name suffix
phases[5].runs[2].scenario.constellation.altitude_km20200kmfield-name suffix
phases[5].runs[2].scenario.constellation.inclination_deg55degfield-name suffix
phases[5].runs[2].scenario.constellation.phasing_f1not statedno units entry and no unit suffix
phases[5].runs[2].scenario.constellation.planes6not statedno units entry and no unit suffix
phases[5].runs[2].scenario.constellation.sats_per_plane4not statedno units entry and no unit suffix
phases[5].runs[2].scenario.kindintegritytexta text input carries no unit
phases[5].runs[2].scenario.mask_deg5degfield-name suffix
phases[5].runs[2].scenario.p_fa1.0000e-5not statedno units entry and no unit suffix
phases[5].runs[2].scenario.p_md0.001not statedno units entry and no unit suffix
phases[5].runs[2].scenario.seed71field-units schema: input entry `seed`, matched by field name
phases[5].runs[2].scenario.sigma_uere_m1mfield-name suffix
phases[5].runs[2].scenario.time.duration_s600sfield-name suffix
phases[5].runs[2].scenario.time.step_s30sfield-units schema: input entry `timeline.step_s`, matched by field name
phases[5].runs[2].scenario.user.altitude_km0.4kmfield-name suffix
phases[5].runs[2].scenario.user.inclination_deg45degfield-name suffix
phases[5].runs[2].scenario.user.raan_deg10degfield-name suffix
phases[5].runs[2].scenario.user.u0_deg0degfield-name suffix
seed202609281field-units schema: units entry `seed`
timeline.step_s10sfield-units schema: units entry `timeline.step_s`
titleJamming, spoofing, holdover and integrity: a chained missiontexta text input carries no unit

3. Results

Result chart
Result chart (also written to campaign-jam-spoof-holdover-integrity.chart.svg)

Scalar results

ResultValueUnit
reproducibility.campaign_hashf87a4a0e0babe2ea4b7e8adc7739cf564e270dc1c261d2ff48386766bf9d1ba1text
reproducibility.run_digestac0944979edf3371b78ca93d2b64f905fc4c96191f780ca868d009c3b6efd58etext
reproducibility.runs_total18count
seed202609281
timeline.channels.alarm.labelalarm flag: 1 while any monitor of the phase alarmstext
timeline.channels.alarm.unit1text
timeline.channels.alert_limit_m.labelvertical alert limittext
timeline.channels.alert_limit_m.unitmtext
timeline.channels.cn0_dbhz.labelmean effective carrier-to-noise density ratio over the visible satellitestext
timeline.channels.cn0_dbhz.unitdB-Hztext
timeline.channels.cn0_floor_dbhz.labeltracking-loss floor of the receivertext
timeline.channels.cn0_floor_dbhz.unitdB-Hztext
timeline.channels.guard_ns.labeltime-error guard (the run's own threshold)text
timeline.channels.guard_ns.unitnstext
timeline.channels.position_error_m.labelposition errortext
timeline.channels.position_error_m.unitmtext
timeline.channels.position_threshold_m.labelposition-error threshold (the run's own)text
timeline.channels.position_threshold_m.unitmtext
timeline.channels.protection_level_m.labelvertical protection leveltext
timeline.channels.protection_level_m.unitmtext
timeline.channels.time_error_ns.labelclock time errortext
timeline.channels.time_error_ns.unitnstext
timeline.channels.tracking.labelsatellites still trackingtext
timeline.channels.tracking.unitcounttext
timeline.duration_s4570s
timeline.step_s10s

Numeric columns

ColumnCountMinMaxFirstLastUnit
timeline.channels.alarm.values[]45801001
timeline.channels.alert_limit_m.values[]24150505050m
timeline.channels.cn0_dbhz.values[]458-12.15767543.03730443.03730443.019529dB-Hz
timeline.channels.cn0_floor_dbhz.values[]45825252525dB-Hz
timeline.channels.guard_ns.values[]45850505050ns
timeline.channels.position_error_m.values[]1800.61660224343.2178380.61660224343.217838m
timeline.channels.position_threshold_m.values[]18050505050m
timeline.channels.protection_level_m.values[]2238.943063135.44494221.6358928.943063m
timeline.channels.time_error_ns.values[]458-0.43277662.7377490-0.432776ns
timeline.channels.tracking.values[]4580888count
timeline.events[].t_s21200157012001570s
timeline.phases[].carried.time_error_ns23759.5803213759.580321ns
timeline.phases[].runs[].skip_s18010000s
timeline.phases[].t0_s60397003970s
timeline.phases[].t1_s660045706004570s
timeline.t_s[]4580457004570s

3a. Aggregation of member runs

Mode chain, 18 member runs.

Run digest (SHA-256 over the member result digests, in dispatch order): ac0944979edf3371b78ca93d2b64f905fc4c96191f780ca868d009c3b6efd58e

Chain phases

phasestart (s)end (s)duration (s)ended bymember kindscarried in
nominal0600600duration_sclock, jamming, integritynothing carried
jamming6001200600duration_sclock, jamming, integritynothing carried
spoofing12001570370end_at classical.detect_time_s = 370 sspoof, spoof-detect, jammingnothing carried
holdover157033701800duration_sclock, gnss-ins, jammingtime_error_ns = 37
integrity-alarm33703970600duration_sclock, jamming, integritytime_error_ns = 59.580321
recovery39704570600duration_sclock, jamming, integritynothing carried

3b. Animation and exports

Animation of the run's time series
The run's own samples drawing in behind a moving time cursor (the animated drawing of --animate svg; it shows the finished picture under reduced motion and in print).

The interactive player is written by kshana scenarios/campaign-jam-spoof-holdover-integrity.toml --animate html.

ExportAppliesFiles or reason
czml
https://github.com/AnalyticalGraphicsInc/czml-writer/wiki/CZML-Structure
yeswritten by kshana scenarios/campaign-jam-spoof-holdover-integrity.toml --export all
kml
https://www.ogc.org/standard/kml/
yeswritten by kshana scenarios/campaign-jam-spoof-holdover-integrity.toml --export all
geojson
https://www.rfc-editor.org/rfc/rfc7946
yeswritten by kshana scenarios/campaign-jam-spoof-holdover-integrity.toml --export all
stk
https://help.agi.com/stk/#stk/importfiles-02.htm
yeswritten by kshana scenarios/campaign-jam-spoof-holdover-integrity.toml --export all
sigmf
https://github.com/sigmf/SigMF/blob/main/sigmf-spec.md
nono member scenario of the campaign has anything this format describes; export a member on its own to see its reason

4. Events timeline

phase nominal (ended by duration_s)phase jamming (ended by duration_s)phase spoofing (ended by end_at classiphase holdover (ended by duration_s)phase integrity-alarm (ended by duratiphase recovery (ended by duration_s)point events (2)0 s1142.5 s2285 s3427.5 s4570 s
Windows as bars, point events as dots, on the run's own time axis.
Start (s)End (s)EventSource
0600phase nominal (ended by duration_s)result `timeline.phases[0]`
6001200phase jamming (ended by duration_s)result `timeline.phases[1]`
12001570phase spoofing (ended by end_at classical.detect_time_s = 370 s)result `timeline.phases[2]`
1200point eventRF spoofing detector alarms (fused consistency, power and signal-quality monitors) (phase spoofing) [alarm]result `timeline.events[]`
15703370phase holdover (ended by duration_s)result `timeline.phases[3]`
1570point eventclock-aided spoofing monitor alarms (phase spoofing) [alarm]result `timeline.events[]`
33703970phase integrity-alarm (ended by duration_s)result `timeline.phases[4]`
39704570phase recovery (ended by duration_s)result `timeline.phases[5]`

5. Verification labels

Each row is a verification-matrix row this run's kinds exercise, with the label and the oracle the matrix gives it (src/verification.rs, docs/VERIFICATION-MATRIX.md). A label grades the capability as the matrix records it; it does not grade this scenario's configuration, and a VALIDATED row does not make the run's inputs measured. A PARTNER row is a discipline the run relies on that Kshana does not provide.

Capability (matrix requirement)LabelUsed bySource: oracleTest evidence
Frequency stability characterisation
Allan/modified/Hadamard deviation + power-law noise ID with χ² CIs
VALIDATED
exercised
clockNIST SP 1065 (Riley) / Stable32 reference deviations on NBS14 (ExternalDataset)tests/allan_reference.rs (NBS14 vs Stable32 to 1e-4); allan::tests
Integrity (RAIM/ARAIM/SBAS)
ARAIM multiple-hypothesis solution separation per the ARAIM Airborne Design Document (ADD) v4.2 (araim_reference::add_v42_protection_levels and add_v42_protection_levels_ecef: subset determination by the P_THRES and FC_THRES rules, VPL, HPL, the effective monitor threshold EMT and sigma_acc); chi-squared snapshot RAIM fault detection with single-satellite exclusion (raim::snapshot_raim, raim::snapshot_raim_fde) and slope-based HPL/VPL on the geodetic local level; and the SBAS DO-229E protection-level combination (sbas::sbas_protection_level) on the L1 service. NOT covered, stated plainly: the uniform-sigma convenience functions raim::araim_raim and raim::araim_dual_raim are NOT ADD-conformant (on matched inputs they miss Stanford MAAST by 0.75 m VPL / 4.04 m HPL and 0.39 m VPL / 1.93 m HPL, a finding); the dual-frequency multi-constellation (DFMC) L5 SBAS comparison is a finding (308 user-epoch pairs with no GEO in view are protected by Kshana and not by MAAST, whose GEO-reception gate Kshana does not model); raim::solution_separation_raim has no external comparison
VALIDATED
exercised
integrityThree independent tools, pre-registered (0123cee1) before any fixture or oracle output existed, tolerances fixed then. (1) ARAIM: Stanford MAAST for ARAIM 2 (commit ab70e2a3, BSD-3) mhss_raim_baseline_v5.m, run as a separate program under GNU Octave 8.4 with a driver-side unique() compatibility shim (disclosed, no algorithm change), at the ADD TOL_PL of 0.05 m: the Rust reproduces the ADD reference implementation on 270 real cases. Disclosed: the Kshana ADD path was written after the pre-registration, following the ADD as MAAST implements it; an independent hold-out by the reviewer (270 new user geometries and a second integrity support message, MAAST re-run against the frozen code) passed at the same bar. (2) Snapshot RAIM: RTKLIB v2.4.2-p13 (BSD-2) estpos/valsol/raim_fde in a separate C harness for detection and exclusion; the slope PL from RTKLIB matinv/xyz2enu plus SciPy 1.18.1 chi2/ncx2, where both sides evaluate the same closed form (Brown; Parkinson and Axelrad), so the PL check covers the implementation, not the formula. (3) SBAS: Stanford MAAST (commit 7d32b049) usr_vhpl, unmodified, on MAAST own recorded WAAS broadcasts: L1 levels within 1e-4 m after the K rescaling and an equal protected set. The same comparisons produced the findings stated in the capability: the uniform-sigma ARAIM functions are not ADD-conformant, and the L5 set equality fails on 308 pairs with no GEO in view (the levels on the 3267 pairs both tools protect agree to 1e-13 m). The DO-229E/DO-316 K-factors are transcribed constants and the real geometry is an input; neither is counted as an oracle. 0.30 revision: snapshot_raim protection levels moved from the radial to the geodetic local level (up to 0.31 m HPL and 0.14 m VPL at 16 deg N) (ExternalDataset)tests/integrity_araim_stanford_oracle.rs::araim_mhss_matches_stanford_maast_add_v4_2 (270 real-geometry cases, Celestrak GPS+Galileo and IGS SP3: worst |dVPL| 2.2e-3 m, |dHPL| 1.1e-3 m, |dEMT| 2.1e-10 m against the ADD TOL_PL 0.05 m); tests/integrity_araim_stanford_oracle.rs::uniform_sigma_matched_gap_finding (the uniform-sigma gaps, pinned); tests/integrity_snapshot_raim_rtklib_oracle.rs::snapshot_raim_decisions_and_slope_levels_match_rtklib (real IGS ABMF 2018-05-13, 288 epochs, 2016 cases with injected 10 to 100 m biases: 2016/2016 detection and 801/801 exclusion decisions identical, slope HPL/VPL within 2.7e-12 m against 1e-6 m); tests/integrity_sbas_stanford_oracle.rs::sbas_l1_protection_levels_match_stanford_maast_on_real_waas_messages (2868 user-epoch pairs on real WAAS broadcasts, the same protected set, worst |dVPL| 7.1e-6 m and |dHPL| 1.6e-5 m against 1e-4 m); tests/integrity_sbas_stanford_oracle.rs::sbas_l5_finding_geo_reception_gate (the L5 finding, pinned); tests/igs_real_data.rs and tests/araim_dual_real_data.rs (plausibility on real IGS SP3 and Celestrak geometry, kept as regression checks, not oracles)
GNSS geometry / dilution of precision (DOP)
GDOP/PDOP/HDOP/VDOP/TDOP from line-of-sight geometry via Q=(HᵀH)⁻¹ with a local ENU split
VALIDATED
exercised
integritygnss_lib_py 1.0.4 (Stanford NAV Lab) DOP — independent library, matched to 1e-6 relative (ExternalDataset)tests/dop_reference.rs (8 geometries, well-conditioned → near-singular)
RAIM/ARAIM integrity statistical kernel (χ² / non-central χ² / normal laws)
The distributional core every protection level rests on: the snapshot fault-detection threshold χ²₁₋ₚfₐ(dof), the missed-detection non-centrality pbias=√λ, and the K_fa/K_md/K_V solution-separation multipliers
VALIDATED
exercised
integritySciPy 1.17.0 (scipy.stats.chi2/.norm/.ncx2 + optimize.brentq) — independent library (Cephes/Boost), a different algorithm from Kshana's incomplete-gamma series; matched to ≤1e-6 rel. Kernel only. The ARAIM MHSS P_HMI budget *allocation* is no longer without a published numeric oracle — the WG-C ARAIM Technical Subgroup's own worked example now backs the separate 'ARAIM MHSS protection levels against published reference vectors' row, matched at the reference's own TOL_PL = 5e-2 m — so this row's scope is the statistical kernel and that row carries the allocation (see docs/ARAIM_REFERENCE.md) (ExternalDataset)tests/raim_reference.rs (171 cases: χ² CDF/quantile, normal CDF/quantile, non-central χ² CDF, pbias across the P_fa/P_md/redundancy ranges)
GNSS-denied clock holdover
Closed-form coast-error growth + holdover-to-threshold; quantum-clock classes
MODELLED
exercised
clockMulti-step clock_state covariance recursion (same-codebase cross-check); the underlying coast-variance & holdover-inversion kernel is externally validated vs scipy (see 'Clock-holdover coast-variance & threshold inversion'). The per-class red-noise-floor holdover figures stay MODELLED (ReferenceImpl)holdover::tests (vs multi-step Kalman covariance recursion; white-FM exact; round-trip); coast-variance kernel externally validated in tests/gnss_denied_clock_holdover_reference.rs (vs scipy Van-Loan/brentq)
Onboard clock state estimation
3-state (phase/freq/drift) van-Loan Kalman clock, Joseph-stabilised
MODELLED
exercised
clockfilterpy 1.4.5 KalmanFilter (R. Labbe, MIT), with F via scipy.linalg.expm and Q via the Van-Loan 1978 block-matrix — an independent reference implementation reproducing kshana's full filter trajectory. Cross-implementation consistency: the clock physics / Allan calibration are not externally validated, so this stays MODELLED. 0.30 external comparison, a finding (stays MODELLED): on IGS final 30 s clocks of 11 GPS Block IIF satellites (2025-08-17 to 30), with Q fitted to the first-half ADEV and the filter scored on the held-out second half, the filter is consistent one step ahead (0.906 to 0.971 of epochs inside its 95 % band, bar 90 %) but over-confident at one hour on 9 of 11 clocks (0.486 to 0.829) and its innovation sums fall outside [2.4, 3.6] on 5. The fitted white-phase noise is zero on every satellite, and the hour-scale error (periodic terms, flicker FM) is not in the 3-state model. 0.30 round 2, an extended filter (flicker FM and once- and twice-per-revolution states) on fresh held-out IGS clocks of 2025-09-01 to 14 (pre-registered 4b1a841e), a finding (stays MODELLED): the one-step and one-hour consistency criteria hold on all 11 satellites (0.948 to 0.988 and 0.907 to 0.996), but the innovation-sum criterion fails on G24 (0.964) and G30 (1.929) against [2.4, 3.6]. D9 round 3, the round-2 extended filter, tuning and criteria unchanged after the frozen clock_library conditioning detector, on fresh IGS clocks of 2026-04-01 to 14 (pre-registered fb475550), a finding (stays MODELLED): (a) one-step 0.941 to 0.968 and (c) triple-NIS mean 2.641 to 3.549 hold on all 11 satellites; (b) one hour fails on G09 (0.894) and G26 (0.876) against 0.90 (ReferenceImpl)clock_state::tests (analytic van-Loan Q; NEES; PSD positivity); tests/clock_state_reference.rs (full predict+update trajectory — state x and 3×3 covariance P over 1925 steps / 4 parameter sets vs filterpy 1.4.5; worst |relΔ| 2.8e-14); tests/clock_state_igs_holdout_oracle.rs::three_state_filter_on_held_out_igs_clocks_finding (pins the finding); tests/clock_state_ext_igs_fresh_oracle.rs::extended_filter_on_fresh_igs_clocks_finding; tests/clock_state_ext_igs_conditioned_oracle.rs::conditioned_extended_filter_finding (D9 round 3)
Quantum inertial sensor performance
Cold-atom interferometer accelerometer from first principles (k_eff·T², QPN)
MODELLED
exercised
gnss-insPublished CAI primary-paper numeric vectors (Cheinet 2008 transfer function; Peters/Freier sensitivity): k_eff·T² matched exactly, shot-noise ASD a one-sided floor within ~2× of each published instrument (real devices carry technical noise above the quantum floor). A bracket, not parity. 0.30 round 2 (pre-registered fcb9ac64), a finding (stays MODELLED): the QPN-only rotation noise against the measured Gauguet et al. 2009 Fig. 14 points gives ratios 0.695 to 0.788 at the three admitted points (0.751 at the operating point), missing the pre-registered 30 % bar by 0.5 points; the QPN floor sits 21 to 31 % below the measured noise, as expected of a model without laser and detection noise. The gradiometer composition matches the Janvier et al. 2022 QPN model line (ratio 1.013 to 1.017, Reference). The measured test cannot discriminate a sqrt(2) composition error; only the unequal-contrast Janvier line can (ExternalDataset)quantum_imu::tests (k_eff; Mach-Zehnder T²; Freier-2016 floor bracket); tests/quantum_inertial_sensor_reference.rs (transfer function |H(ω)|, k_eff·T² and shot-noise ASD vs published Cheinet 2008 / Peters / Freier numeric vectors); tests/quantum_inertial_measured_qpn.rs (gauguet_finding_qpn_floor_sits_below_the_measured_noise, pinned; gradiometer_qpn_line_matches_janvier_model)
GNSS/INS sensor fusion
15-state error-state EKF, loosely coupled (validated on a real IMU/GNSS drive against NaveGo); a tightly coupled pseudorange/Doppler UKF and a coupled clock+position filter (consistency-only, outside the validated claim)
VALIDATED
exercised
gnss-insNaveGo v1.4 (R. Gonzalez, LGPL-3.0, run as a tool under GNU Octave, never linked): its loosely coupled ins_gnss on its own real Ekinox IMU/GNSS land-vehicle drive, both solutions scored against the Ekinox reference trajectory. Both filters read the same 20 Hz float32 input, and Kshana's configuration is mapped mechanically from the dataset's published parameters. Kshana's horizontal and vertical position RMS and its position-innovation RMS are within 1.2x of NaveGo's (measured 0.912, 0.940 and 0.861) and its mean normalised innovation is at most 1.5 (measured 0.395: about 2.5x under-confident, given the dataset's stated GNSS sigmas); tolerances fixed before the comparison. Scope: GNSS is present at 5 Hz for the whole drive, so no outage or coast is tested and the check catches gross filter defects rather than fine tuning (lever-arm-corrected raw fixes would land near the vertical bar); the lever-arm transform is computed in the test harness. The tightly coupled UKF and the coupled clock+position filter keep their filterpy 1.4.5 consistency checks (linear posteriors to 2.4e-12) and stay outside the validated claim (ExternalDataset)fusion::tests (UKF==linear-KF identity; outage coast; NEES); tests/gnss_ins_sensor_fusion_reference.rs (50 cases vs filterpy 1.4.5: linear EKF loose/tight + coupled-PNT posteriors to ≤2.4e-12; UKF 40-epoch run worst |Δx| 1.9e-7 / |ΔP| 9.5e-6); tests/gnss_ins_navego_dataset_oracle.rs::loosely_coupled_rms_within_1p2x_of_navego (NaveGo v1.4 loosely coupled solution on NaveGo's real Ekinox IMU/GNSS drive: horizontal RMS 0.912x, vertical 0.940x, position-innovation RMS 0.861x of NaveGo's, mean normalised innovation 0.395; bars 1.2x, 1.2x, 1.2x and 1.5 fixed before the run)
GNSS-denied jamming resilience
Geometry J/S link budget, anti-jam C/N₀, per-satellite loss-of-lock
MODELLED
exercised
jammingAnti-jam C/N₀ link-budget equation cross-checked against an independent numpy re-derivation (shares the same closed form → InternalConsistency) plus a real-JammerTest-2024 C/N₀ degradation characterisation. 0.30 round 2, blocked (stays MODELLED): the measured JammerTest 2024 C/N0 drop against a link-budget prediction (pre-registered 6a66994b, within 3 dB) was not run because the F8.1 antenna position and pointing at Bleik and the L1 share of the multi-band 1.6.4 ramp power are not documented in the test catalogue or the official log (InternalConsistency)jamming::tests (PSD-derived Q cross-check; despreading); tests/gnss_denied_jamming_resilience_reference.rs (FSPL/J-S/effective-C-N₀ vs an independent numpy re-derivation of the Kaplan & Hegarty §9.4 link budget; real JammerTest C/N₀ falls monotonically through the 25 dB-Hz threshold); tests/jamming_jammertest_cn0_oracle.rs (pre-registered, blocked, not run)
Spoofing detection
Clock-aided χ², RAIM, AGC, SQM fused per-epoch security FoM
MODELLED
exercised
clock, spoof, spoof-detectTEXBAT scenario parameters (Humphreys 2012) — characterisation, not pinned vectors. 0.30 external comparison, a finding (stays MODELLED): on JammerTest 2024 (Bleik; GPL-3.0 data) the observable-level monitors (clock-aided chi-square, RAIM, solve failure) raised no alarm within 10 s of any of the 8 evaluable published spoofing onsets (where the pre-onset window was clean, the first alarm came 10.2 to 39 s after the published slot start), and three pre-onset windows carried false alarms from the clock monitor (81, 64 and 173 epochs). The first observable effect was a loss of dual-frequency GPS tracking, not a RAIM inconsistency. The published onsets are minute-resolution schedule slot starts; that they precede the RF capture is an interpretation, not a measurement. 0.30 round 2, against the organisers official JammerTest 2024 log (second resolution; pre-registered 6a66994b with a Hadamard-calibrated three-state clock monitor without latching), a finding (stays MODELLED): the monitor alarms within 10 s at 4 of 10 logged onsets; at the other six it is 18 to 211 s late or raises pre-onset clock false alarms (1 at 2.1.4, 85 at 2.3.15). D9 round 3 (a receiver card from the JammerTest unit's other sessions, pre-registered 2ec76864) blocked: 167 training epochs against 3600. D9 rounds 4 and 4b (noise levels from a u-blox ZED-F9P model-class card, Wroclaw 2021, pre-registered fb475550; 4b a disclosed re-run with a corrected extraction, c9cc0d49), a finding (stays MODELLED): zero pre-onset false alarms at all 10 logged onsets and 6 of 10 within 10 s; 2.1.1, 2.3.5, 2.3.10 and 2.6.1 stay late (+211, +23, +18, +51 s), unchanged by the clock noise level (ExternalDataset)tests/spoof_texbat_validation.rs (TEXBAT parameter characterisation); tests/spoof_detection_jammertest_oracle.rs::monitors_against_the_published_onsets_reproduce_the_recorded_disagreement (pins the finding); tests/spoof_detection_jammertest_log_oracle.rs::engine_monitors_against_the_logged_onsets_reproduce_the_recorded_disagreement; tests/clock_library_tcxo_card_jammertest_oracle.rs (round_3_is_blocked_by_the_training_minimum; round_4_reproduces_the_recorded_finding; round_4b_reproduces_the_recorded_finding; D9)
Reproducibility & software assurance
Deterministic, scenario-hashed, SBOM + cross-platform golden gates
MODELLED
exercised
every runSBOM conformance to the official CycloneDX 1.5 JSON Schema (+ valid SPDX identifiers) — an external published standard, zero validation errors over the full dependency graph; the FoM-determinism / byte-reproducibility part remains a pinned self-consistency check, so the row stays MODELLED (ExternalDataset)tests/golden.rs, tests/determinism.rs, tests/cross_platform_golden.rs; tests/reproducibility_software_assurance_reference.rs (the generated SBOM validates with zero errors against the official CycloneDX 1.5 JSON Schema over the full 66-component shipped graph: default + python + wasm features, dev-dependencies excluded)
Navigation RF payload & antenna hardware design
Not provided — Kshana models signal performance, not payload/antenna hardware
PARTNER
relied on, not provided
jamming, spoof-detectnone: a partner-owned discipline, with no module and no test by design (NoneKind)none: a partner-owned discipline
A chained mission across scenario kinds on one shared timeline
The `campaign` kind's phases: each phase runs one or more scenarios of existing kinds through run_toml, reads their outputs into named channels (clock time error and guard, mean effective carrier-to-noise density ratio and tracking floor, vertical protection level and alert limit, position error, satellites tracking, alarm flags) by per-kind presets or explicit result paths, places them at the phase start and holds them onto a common grid, with phase boundaries and events; state is handed on by carry (a channel continues from the previous phase's end value), handoff (a previous phase's number written into the next scenario) and end_at (a phase ends at a time a run computed, such as a spoofing monitor's detection time); a campaign hash and a digest over every member result
MODELLED
exercised
campaignComposition identities against the stand-alone runs of the same kinds: a one-phase campaign reproduces the stand-alone output bit for bit, the carried offset equals the previous run's own last sample, and the phase ended by end_at has exactly the run's detection time as its length. The additive carry across a phase boundary and the zero-order hold are modelling choices, and each phase is as good as the kind that ran it; no chained mission has been checked against a measured one (InternalConsistency)tests/campaign_composition_reference.rs (a_one_phase_clock_campaign_reproduces_the_standalone_run_bit_for_bit, a_one_phase_integrity_campaign_reproduces_the_standalone_run_bit_for_bit, a_one_phase_jamming_campaign_reproduces_the_standalone_run_bit_for_bit — the member result byte-identical to the stand-alone run and every aligned value equal to the stand-alone series; the_chained_mission_hands_state_on_and_ends_the_spoofing_phase_on_detection; a_handoff_writes_the_previous_phase_number_into_the_next_scenario; malformed_campaigns_fail_loudly)

6. Not modelled, and assumptions

Each item is quoted from where it is stated: the result document, the kind catalogue, the scenario file, or the verification matrix's reason a MODELLED row stays modelled.

StatementSource
MODELLED composition of existing scenario kinds. Every number is read from a real run of the named kind; the chaining (additive carry of a channel across a phase boundary, zero-order hold onto the timeline grid, a phase ended at a computed time) is a modelling choice, and each phase carries the label of the kind that produced it.result `label`
MODELLED: the additive carry and the zero-order hold are modelling choices, and each phase carries the label of the kind that ran it.kind catalogue (`kshana kinds --json`)
MODELLED: the chaining is a modelling choice (additive carry, zero-order hold), and each phase is as good as the kind that ran it.scenario file comment, lines 30 to 31
GNSS-denied clock holdover is MODELLED, not validated: checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative.verification matrix (docs/MODELLED-RATIONALE.md)
Onboard clock state estimation is MODELLED, not validated: checked against a separate implementation in this same codebase — independent of the unit under test, but not externally authoritative.verification matrix (docs/MODELLED-RATIONALE.md)
Quantum inertial sensor performance is MODELLED, not validated: a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled.verification matrix (docs/MODELLED-RATIONALE.md)
GNSS-denied jamming resilience is MODELLED, not validated: checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle.verification matrix (docs/MODELLED-RATIONALE.md)
Spoofing detection is MODELLED, not validated: a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled.verification matrix (docs/MODELLED-RATIONALE.md)
Reproducibility & software assurance is MODELLED, not validated: a sub-claim is externally checked, but the whole capability composes modelled pieces, so the capability stays Modelled.verification matrix (docs/MODELLED-RATIONALE.md)
A chained mission across scenario kinds on one shared timeline is MODELLED, not validated: checked against its own closed-form / analytic identity — catches transcription and coefficient errors, but is not an external oracle.verification matrix (docs/MODELLED-RATIONALE.md)

7. Reproducibility record

Command to reproducekshana scenarios/campaign-jam-spoof-holdover-integrity.toml
Working directoryRun the command from the directory the original run was started in: the scenario path, and any relative data path inside the scenario, resolve against it. Check the scenario file against scenario_sha256 first.
Engine version0.34.0
Source commitnot recorded: this engine was built without the KSHANA_GIT_COMMIT environment variable; the engine version identifies the release
Scenario filecampaign-jam-spoof-holdover-integrity.toml
Scenario file SHA-256 (Secure Hash Algorithm 256-bit)cec1e10f8eb478bae58acebe9c2f06cfccf6572f6f6895dc633fb409b8d8ee5f
Result scenario_hashf87a4a0e0babe2ea4b7e8adc7739cf564e270dc1c261d2ff48386766bf9d1ba1 (the kind's own fingerprint of the scenario; not the file digest)
Result document SHA-25602ac48d48602d64e41fbabc76c43c94de37c96a0009e984fdc3b027a7a509819 (campaign-jam-spoof-holdover-integrity.result.json)
Seed20260928 (scenario `seed`)
Platformlinux / x86_64 (unix)
DeterminismSame scenario bytes, seed and engine build give a byte-identical result document and report; this report carries no timestamp. Floating-point results are pinned per platform; another operating system or architecture may differ in the last digits.

To print this page to a Portable Document Format (PDF) file, use the browser's print dialog and choose “Save as PDF”; the print stylesheet fits A4 and US Letter paper, repeats table headers across pages and starts the inputs, results, labels and reproducibility sections on a new page. The engine writes no PDF itself. report.json carries the same content as this page.