223 capabilities, each graded. 83 validated against independent external oracles. 136 honestly labelled Modelled. 4 partner-owned. Nothing is rounded up.
Verification matrix v0.29.0From the repository
83Validated
136Modelled
4Partner-owned
223capabilities
Hover or focus a cell to read its capability and the oracle that grades it.
Validated: an independent external oracle agreesModelledPartner-owned
Engine v0.29.0 · web/data/verification-matrix.json, generated from src/verification.rs · 223 rows · no scenario or seed: the engine's own ledgerRead the ledger
Free coreThe ledger, the results, the reproducibility stamp and the tests behind them are all in the open engine.
ProPackages the evidence into an audit-grade, reproducible evidence pack for a review board. See below
Custom studyAnswers your own question with the same labels, not a certification. See below
01Validated results · every compared value
Checked against someone else's answer.
Each tile draws every value the engine compared with an independent reference: published vectors, a separate flight-dynamics library, precise ephemerides, a statistics library, a standards publication, and a measured clock record held out from fitting. Hover or focus a mark for its value.
Orbits · analyticValidated
666/666
SGP4 (Simplified General Perturbations 4) orbit propagation
Every AIAA (American Institute of Aeronautics and Astronautics) reference vector reproduced, deep-space SDP4 (Simplified Deep-space Perturbations 4) cases included. Worst case 4.12 mm.
One square per compared vector, coloured by its position error.
Engine v0.29.0, build e6bde8f · tests/numerical_cowell_propagator_reference.rs · deterministic, no seedNo Kshana Studio view: this comparison runs as an engine test.
Orbits · millimetres to metresValidated
0.61m Galileo/0.10m Swarm-A
Every orbit residual on one scale
From the propagator checks to fits against ESA (European Space Agency) precise ephemerides. The lunar orbiter, above the bar, is shown too.
Each residual on a logarithmic scale from a millimetre to twenty metres.
oracle · ESA precise ephemerides, the lunar orbiter's reconstructed trajectory, Orekit 12.2, AIAA vectorsHow it was checked
Engine v0.29.0 · docs/AGENCY-ORBIT-VALIDATION.md residual tables, with the two propagator checks recomputed at build e6bde8f · deterministic, no seedNo Kshana Studio view: precise orbit determination runs as engine tests.
Clocks · stabilityValidated
12of 12 published values
Allan deviation
Reproduces the reference values of NIST (National Institute of Standards and Technology) Special Publication (SP) 1065, Table 31, on its own 1000-point data set.
Four deviations against averaging time, with the published values as rings.
Validated means an independent external source agrees: published reference vectors, a separate tool, or measured data. Anything else says Modelled. Pick a label to light its cells.
Capabilities graded
83of 223 validated
Hover a cell
Counts are exact, from the engine's verification matrix. Cells follow the ledger's row order.
Three words, used strictly
Kshana outputengine run
Independent oraclepublished reference
Validated
Only with an independent external oracle: published reference vectors, a separate implementation, or measured data held out from fitting. The ledger names the oracle and the test, and the matrix invariant tests enforce the rule.
Modelled
A published model or a documented modelling choice, internally tested, with no independent external oracle yet. Said out loud, not rounded up.
Partner-owned
Spacecraft bus engineering, navigation payload and antenna hardware, quantum payload hardware, and flight-hardware product assurance. Kshana claims none of them; a partner owns them.
With Pro: a mission dossier checks every requirement against real runs and keeps these labels in its verification matrix: a requirement met on a MODELLED or PARTNER basis is flagged. See a real dossier
03Validation ledger
All 223 rows, one line each.
Every row names its requirement, its status and the module that implements it. Open a row for its oracle and tests, or pick a domain to narrow it.
By domain: bar length is rows, colour is status. Pick one to filter.
Allan/modified/Hadamard deviation + power-law noise ID with χ² CIs
Oracle
NIST SP 1065 (Riley) / Stable32 reference deviations on NBS14
Tests
tests/allan_reference.rs (NBS14 vs Stable32 to 1e-4); allan::tests
ValidatedFrequency stability on a real measured clockallan
Capability
Overlapping Allan + overlapping Hadamard deviation on a real caesium standard
Oracle
Stable32 overlapping ADEV/HDEV on the measured 5071A caesium phase series (allantools)
Tests
tests/cs5071a_reference.rs (real 5071A Cs vs H-maser, 556 990 pts, 16 averaging factors vs Stable32 to 1e-3; data-gated via scripts/fetch_cs5071a.sh)
ValidatedAllan estimator parity on the canonical Stable32 reference seriesallan
Capability
Overlapping Allan + modified Allan + time deviation across the full AF ladder
Oracle
Stable32 reference deviations for PHASE.DAT (Riley; the standard regression series)
Tests
tests/phasedat_reference.rs (Stable32 PHASE.DAT, 139 averaging factors, OADEV/MDEV/TDEV to 1e-3; data-gated via scripts/fetch_phasedat.sh)
ValidatedExtended-range frequency stability (Theo1 / TOTDEV)allan
Capability
Theo1 and total deviation (TOTVAR) — extended-range long-tau stability estimators reaching ~75% of the record where the Allan deviation gives out near ~50%; the bias-removed ThêoH hybrid (allan::theoh_curve) built on them stays MODELLED
Oracle
allantools 2024.06 — an independent third-party frequency-stability library — theo1 (NIST SP 1065 eq 30) and totdev (NIST SP 1065 eq 25) on the hermetic NIST SP 1065 §12.4 LCG data set; regenerable offline via tests/fixtures/theo1_totvar/generate_theo1_totvar_reference.py
Tests
tests/theo1_totvar_reference.rs (Theo1 + TOTDEV on the NIST SP 1065 §12.4 1000-point LCG data set, 6 + 6 averaging factors vs allantools 2024.06 to <1e-9); allan::tests (white-FM closed-form tracking; TOTVAR=ADEV…
ValidatedMaximum Time Interval Error (MTIE) — telecom wander metricallan (mtie,mtie_curve)
Capability
MTIE(τ): the maximum peak-to-peak time-error swing over any sliding window of τ = m·tau0, the ITU-T G.810/G.823/G.8261 wander statistic synchronisation-network limits (MTIE masks) are written against — an extremal (max/min) figure distinct from the RMS Allan family
Oracle
allantools 2024.06 — an independent third-party frequency-stability library — mtie() on the hermetic NIST SP 1065 §12.4 LCG phase series; MTIE is a pure max/min statistic, so the estimator output is bit-exact against allantools on the identically-built phase array (the committed 15-significant-figure reference constants sit within 1 ULP). Regenerable offline via tests/fixtures/mtie/generate_mtie_reference.py
Tests
tests/mtie_reference.rs (MTIE on the hermetic NIST SP 1065 §12.4 1000-point LCG phase series, 9 averaging factors m=1..256 vs allantools 2024.06 mtie to <1e-9, observed ≤4e-15); allan::tests (hand-derived peak-to-peak…
ValidatedModified Allan / Time deviation (MDEV / TDEV)allan (modified_adev,time_deviation)
Capability
MDEV(τ): the overlapping modified Allan deviation (second-difference sliding-window estimator that separates white- from flicker-phase noise), and TDEV(τ) = τ/√3·MDEV(τ), the ITU-T G.811/G.812/G.823 time-domain wander statistic the sync masks are written against
Oracle
allantools 2024.06 — an independent third-party frequency-stability library — mdev() and tdev() on the hermetic NIST SP 1065 §12.4 LCG phase series (same series as the Theo1/TOTDEV/MTIE rows), computing the same uniquely-defined estimators; matched to <1e-9 relative. Regenerable offline via tests/fixtures/mdev_tdev/generate_mdev_tdev_reference.py. (The data-gated phasedat_reference.rs also checks these against Stable32 to 1e-3; this is the tight, always-on hermetic cross-check)
Tests
tests/mdev_tdev_reference.rs (MDEV + TDEV on the hermetic NIST SP 1065 §12.4 1000-point LCG phase series, 8 averaging factors m=1..200 vs allantools 2024.06 mdev/tdev to <1e-9 relative, plus the τ/√3 identity on the…
ValidatedOptical-clock frequency stability on a real measured curvequantum_trade (qparams_from_adev_curve),powerlaw
Capability
Power-law (white-FM + red-noise-floor) NNLS recovery from a published measured ⁸⁸Sr optical-clock-transition Allan deviation — reproducing σ_y(τ) and the headline 4.7e-16/√τ short-τ scaling with a genuine measured long-τ floor, rather than the synthesised optical-class floor holdover.rs otherwise assumes
Oracle
Norcia, Young, Eckner, Oelker, Ye, Kaufman, Science 366:93 (2019), Fig. 4 measured ADEV; curve vendored verbatim from Zenodo 10.5281/zenodo.3382347 (CC-BY-4.0). Scoped to reproducing the published measured stability curve — the clock-class holdover-to-threshold device figures stay MODELLED
Tests
tests/optical_clock_adev_reference.rs (Norcia et al. ⁸⁸Sr tweezer-clock σ_y(τ), 8 averaging times 0.92–117.76 s vendored verbatim under CC-BY-4.0: NNLS reconstructs the curve to ~10% RMS / ≤21% worst point; recovered…
ValidatedNumerical Cowell propagator & force modelpropagator,forces
Capability
Cowell numerical propagator with a hierarchical force model (two-body, J2–J6 zonal, Sun/Moon third-body, cannonball SRP, exponential drag); RK4 step-doubling / DP5(4)
Oracle
Orekit 12.2 (CS GROUP, Apache-2.0) NumericalPropagator/DormandPrince853 — an independent library, a different integrator and spherical-harmonic recursion. The conservative tiers (two-body → J2–J6 zonal → Sun/Moon third-body → cannonball SRP) agree to sub-metre over a 24 h arc, validating the integrator + force algebra; the drag tier and the absolute Sun/Moon-ephemeris / density input fidelity stay MODELLED (characterisation only)
Tests
tests/numerical_cowell_propagator_reference.rs (275 epochs = 11 cases × 25 hourly states, LEO+GTO, vs Orekit 12.2 DormandPrince853; conservative tiers T1–T5 worst |Δr| 0.08 m over 24 h; drag tier characterised at 333 m)
Recover an epoch state [r,v] from ground-station ranges via a Gauss–Newton batch differential corrector and a sequential filter, over a two-body+J2 force model
Oracle
Orekit 12.2 (CS GROUP, Apache-2.0) BatchLSEstimator (Levenberg–Marquardt) + KalmanEstimator (EKF) — an independent third-party estimation library on a matched force model; recovered epoch state + post-fit residual RMS agree to <1e-3 m noiseless and <3 m at a 5 m noise floor
Tests
tests/batch_sequential_orbit_determination_reference.rs (8 scenarios: 6 noiseless LEO/MEO/eccentric/3–4-station + 2 σ=5 m, vs Orekit 12.2; worst batch |Δr| 1e-3 m / |Δv| 1e-6 m/s, sequential |Δr| 0.9 m)
ANISE 0.10 (Nyx Space, MPL-2.0) converged-Newtonian aberration light time (Aberration::CN; SPICE spkapo-equivalent) over JPL DE440 — an independent Rust SPICE implementation; kshana's fixed-point retarded solver matched to sub-nanosecond. The broader Doppler / Shapiro / reduced-dynamic OD figures stay MODELLED
Tests
tests/deep_space_mars_radiometric_reference.rs (24 legs over 8 epochs 2020–2027 vs ANISE DE440; worst |Δτ| 1.03e-9 s, |Δrange| 0.31 m at up to 2.5 AU)
ValidatedBroadcast-ephemeris satellite position (multi-GNSS RINEX)rinex (parse_nav,RinexEphemeris::sv_position_ecef)
Capability
IS-GPS-200 / Galileo-OS / BeiDou-OS broadcast-ephemeris Keplerian → ECEF satellite position from a parsed RINEX-3 navigation record
Oracle
RTKLIB v2.4.2-p13 eph2pos() compiled from C source (T. Takasu, BSD-2-Clause) — an independent IS-GPS-200/SIS-ICD implementation, fed the identical RINEX-3 nav records; satellite ECEF position matched to ~62 nm. (SP3 precise-ephemeris interpolation is validated separately — see 'SP3 precise-ephemeris interpolation')
IGS-standard Lagrange interpolation of SP3 precise-ephemeris satellite positions with the per-node Earth-rotation correction (rotate each node by ω⊕·(t_node−t) into the query instant's Earth-fixed frame before the polynomial fit)
Oracle
RTKLIB peph2pos() compiled from C source (preceph.c; T. Takasu, BSD-2-Clause) — the de-facto IGS reference, an independent implementation; kshana's interpolator (now carrying the same Earth-rotation node correction) matched to ~15 nm on a real SP3 product, down from ~5.5 cm before the correction
Tests
tests/sp3_interp_reference.rs (72 off-node SV-epoch cases / 6 satellites vs RTKLIB peph2pos; worst per-axis |Δ| 1.5e-8 m)
ValidatedStrapdown INS mechanizationinertial::mechanization,inertial::attitude,inertial::imu_errors
Capability
Quaternion-attitude, WGS-84 NED strapdown inertial mechanization (coning/sculling-compensated) propagating a navigation state from (Δθ, Δv) increments
Oracle
NaveGo v1.4 (R. Gonzalez et al., LGPL-3) run under Octave — an independent published INS toolbox driven by the identical (Δθ,Δv) increment stream. Attitude matches bit-for-bit (same NED / scalar-first-quaternion / Earth-rate / transport-rate conventions); velocity/position agree to two documented differences — the deflection-of-vertical north-gravity term NaveGo includes and kshana omits by design (plumb-bob gravity; matched to the Groves closed form to every digit, with a sanity-floor assert) and O(dt²) integrator differences — not mechanization errors
Tests
tests/classical_strapdown_ins_reference.rs (static/turn/coning profiles, 30 epochs each, vs NaveGo: attitude bit-identical 0 rad; velocity/position within named analytic bounds)
ValidatedGravity-field functional synthesis (gravity-aided / GNSS-free nav map)gravity_sh
Capability
Spherical-harmonic gravity magnitude + disturbance (mGal) from any ICGEM .gfc model; GRS80 normal gravity
Oracle
GRS80 (Moritz 1980, IAG) Somigliana normal gravity + published γ_e/γ_p; real ICGEM EGM2008 field
Tests
tests/icgem_gravity_reference.rs (GRS80 synthesis reproduces Somigliana to 3.5e-12; real ICGEM EGM2008 disturbance map physical)
ValidatedLambert two-body transfer solvermaneuver (lambert)
Capability
Izzo-2015 single-revolution Lambert solver (r1, r2, time-of-flight → boundary velocities) across LEO→GEO→heliocentric transfers, prograde and retrograde
Oracle
lamberthub 1.0.0 izzo2015 (J. Martínez Garrido, MIT) — an independent third-party Lambert solver. The single-revolution (M=0) Lambert problem has a unique solution, so library-vs-library agreement is a genuine external check; matched to <1e-4 m/s (observed ~1e-11), the same kind of validation DOP gets vs gnss_lib_py
Tests
tests/lambert_reference.rs (13 transfers vs lamberthub izzo2015; worst |Δv| 7e-12 m/s)
The distributional core every protection level rests on: the snapshot fault-detection threshold χ²₁₋ₚfₐ(dof), the missed-detection non-centrality pbias=√λ, and the K_fa/K_md/K_V solution-separation multipliers
Oracle
SciPy 1.17.0 (scipy.stats.chi2/.norm/.ncx2 + optimize.brentq) — independent library (Cephes/Boost), a different algorithm from Kshana's incomplete-gamma series; matched to ≤1e-6 rel. Kernel only. The ARAIM MHSS P_HMI budget *allocation* is no longer without a published numeric oracle — the WG-C ARAIM Technical Subgroup's own worked example now backs the separate 'ARAIM MHSS protection levels against published reference vectors' row, matched at the reference's own TOL_PL = 5e-2 m — so this row's scope is the statistical kernel and that row carries the allocation (see docs/ARAIM_REFERENCE.md)
Tests
tests/raim_reference.rs (171 cases: χ² CDF/quantile, normal CDF/quantile, non-central χ² CDF, pbias across the P_fa/P_md/redundancy ranges)
DO-229E Appendix J weighted-least-squares protection levels: D=(GᵀWG)⁻¹ from per-satellite elevation/azimuth and error budget, horizontal error-ellipse major axis and vertical σ, scaled by the published K-factors
Oracle
RTKLIB SBAS-PL fork — zsiki/rtklib_ws waasprotlevels() (Siki & Takács 2017, "DO-229D Appendix J"), run by rnx2rtkp -ws on real EGNOS GEO-PRN120 messages + real BUTE/Budapest RINEX; independent third-party implementation, HPL matched to < 2e-3 m. gLAB v6.0.0 (core/filter.c) confirmed identical convention. Both oracles round K_V→5.33 vs Kshana's exact Φ⁻¹(1−5e-8)=5.3267 (~0.06%), so the vertical is checked as the K-factor-free d_U
ValidatedAnomaly-detection scoring on real spacecraft telemetryimpairment_eval,eval_stats
Capability
ROC AUC + bootstrap CI separating real labelled anomalies; transparent detector (reproduces-labels)
Oracle
scikit-learn roc_auc_score on the OPSSAT-AD test split (Ruszczak et al. 2025, CC BY 4.0) — real OPS-SAT telemetry
Tests
tests/opssat_ad_reference.rs (real ESA OPS-SAT, AUC reproduces scikit-learn to 1e-9); tests/ai_ml_rf_impairment_detection_evaluation_reference.rs (122 cases on the real OPSSAT-AD test split: full operating-point…
tests/scipy_reference.rs (NNLS; χ² at operating dof ≥ 48; van-Loan Q)
ValidatedGeomagnetic reference field (IGRF-14 synthesis)igrf,igrf_data
Capability
Spherical-harmonic synthesis of the IGRF-14 main field — X/Y/Z/F components, declination and inclination — feeding the magnetic-anomaly alt-PNT layer
Oracle
ppigrf 2.1.0 (K. M. Laundal, MIT) — the IAGA-VMOD pure-Python IGRF reference implementation shipping the official IGRF14.shc coefficients (IAGA 14th generation, Zenodo 10.5281/zenodo.14012302); an independent third-party codebase computing the uniquely-defined IGRF-14 field, matched over a global grid
Tests
tests/alternative_complementary_pnt_reference.rs (2520 global points × altitudes vs ppigrf @ epoch 2025.0; worst |ΔXYZF| 3.9e-4 nT, |ΔD| 2.8e-6°, |ΔI| 3.6e-7°)
Analytic binormal ROC AUC = Φ(μ/(σ√2)) and the minimum detectable fault σ·(Φ⁻¹(1−P_fa)+Φ⁻¹(P_d)) underpinning the quantum-fault and anomaly detectors
Oracle
scipy 1.17 (Cephes ndtr/ndtri) + scikit-learn roc_auc_score (Pedregosa et al., JMLR 2011), both BSD-3-Clause — independent libraries computing the same uniquely-defined Gaussian-tail / AUC quantities, matched to the A&S-erf floor (~7e-8). The quantum-vs-classical advantage built on top stays MODELLED
Rank-correlation and resampling kernels under the resilience decision-instability study: Kendall τ-b, Dirichlet mean, competition ranking and percentile confidence intervals
Oracle
scipy 1.18 (stats.kendalltau variant='b', rankdata) + numpy.percentile (BSD-3-Clause) — independent implementations (merge-sort τ) of the uniquely-defined rank statistics, matched to 1e-12. The decision-instability study built on these kernels stays MODELLED
Tests
tests/resilience_score_decision_instability_reference.rs (124 cases vs scipy 1.18 / numpy 2.4: 61 Kendall τ-b to 2e-16, ranking exact, Dirichlet mean + percentile-CI to 1e-12)
Analytic Hierarchy Process priority weights = normalised principal (Perron) eigenvector of a reciprocal pairwise-comparison matrix by power iteration, with the Saaty Consistency Index / Consistency Ratio and the CR<0.10 acceptance gate
Oracle
Saaty (1980) canonical Random Index table (RI(5)=1.12) reproduced exactly + SciPy/LAPACK scipy.linalg.eig (BSD-3-Clause) as an independent eigensolver computing the same uniquely-defined Perron eigenvector/eigenvalue, matched to <1e-9. The Pareto / sensitivity / MAUT decision layer built on this kernel stays MODELLED (the WSM/WPM/TOPSIS/VIKOR/PROMETHEE/ELECTRE aggregators are separately externally validated — see the rows below)
Tests
tests/mcda_ahp_reference.rs (Saaty 1980 Random Index table n=1..10 EXACT; priority vector + λ_max + CR vs SciPy/LAPACK eig on a consistent 3×3 and inconsistent 3×3 / 4×4, matched to <1e-9)
Weighted Sum Model (min–max-normalised additive aggregate + ranking) and Weighted Product Model (sum-normalised, reciprocal-for-cost multiplicative aggregate) — the two value-aggregation trade-study scorers
Oracle
pymcdm (methods.WSM + normalizations.minmax_normalization; methods.WPM + normalizations.sum_normalization) — an independent, widely-used third-party Python MCDA library computing the same uniquely-defined weighted aggregates; matched to <1e-9. Regenerable offline via tests/fixtures/mcda_wsm/ and tests/fixtures/mcda_wpm/. Garbage-in-garbage-out on the inputs; the sensitivity/robustness layer stays MODELLED
Tests
tests/mcda_wsm_reference.rs (WSM scores + ranking) and tests/mcda_wpm_reference.rs (WPM scores + ranking), each vs pymcdm to <1e-9 on a fixed 4×3 benefit/cost decision matrix
Technique for Order of Preference by Similarity to Ideal Solution — min–max normalisation, weighted positive/negative ideal solutions, relative closeness Cᵢ = d⁻/(d⁺+d⁻) and ranking
Oracle
pymcdm methods.TOPSIS + normalizations.minmax_normalization — an independent third-party MCDA library computing the same uniquely-defined closeness coefficients; matched to <1e-9. Regenerable offline via tests/fixtures/mcda_topsis/generate_topsis_reference.py
Tests
tests/mcda_topsis_reference.rs (closeness coefficients + ranking vs pymcdm to <1e-9 on a fixed 4×3 benefit/cost matrix)
VlseKriterijumska Optimizacija — group-utility Sᵢ, individual-regret Rᵢ and the compromise index Qᵢ at strategy weight v=0.5, with the lower-is-better ranking
Oracle
pymcdm methods.VIKOR(v=0.5) — an independent third-party MCDA library computing the same uniquely-defined range-normalised S/R/Q aggregation; matched to <1e-9. Regenerable offline via tests/fixtures/mcda_vikor/generate_vikor_reference.py
Tests
tests/mcda_vikor_reference.rs (Q index + ranking vs pymcdm to <1e-9 on a fixed 4×3 benefit/cost matrix)
Preference Ranking Organization METHod — pairwise preference index with the six standard generalised-criterion shapes, positive/negative outranking flows and the complete net-flow ranking (usual criterion validated)
Oracle
pymcdm methods.PROMETHEE_II('usual') — an independent third-party MCDA library computing the same uniquely-defined net outranking flow; matched to <1e-9. Regenerable offline via tests/fixtures/mcda_promethee/generate_promethee_reference.py. The thresholded (q/p/σ) preference shapes reduce to the same generalised-criterion algebra and stay property-checked
Tests
tests/mcda_promethee_reference.rs (net outranking flow + ranking, usual criterion, vs pymcdm to <1e-9 on a fixed 4×3 benefit/cost matrix)
ELimination Et Choix Traduisant la REalité — concordance / discordance matrices, the concordance-and-non-veto dominance relation and the outranking choice kernel (all-benefit, sum-normalised-weight, single-global-scale convention)
Oracle
pyDecision algorithm.electre_i (Valdecy Pereira) — an independent third-party multi-criteria decision library computing the same uniquely-defined concordance/discordance/dominance/kernel; matched element-for-element to <1e-9. Regenerable offline via tests/fixtures/mcda_electre/generate_electre_reference.py. The ĉ/d̂ threshold choices are analyst inputs (sensitivity stays MODELLED)
Tests
tests/mcda_electre_reference.rs (concordance, discordance, dominance matrices element-for-element + kernel/dominated set vs pyDecision to <1e-9 on a fixed 4×3 all-benefit dataset)
Weighted Aggregated Sum Product ASSessment (linear-normalised convex blend λ·WSM+(1−λ)·WPM at λ=0.5) and the MOORA ratio system (vector-normalised weighted benefit total minus weighted cost total) — the stability-hardened value blend and the signed ratio-system scorer
Oracle
pymcdm (methods.WASPAS + normalizations.linear_normalization, l=0.5; methods.MOORA ratio system, vector normalisation) — an independent, widely-used third-party Python MCDA library computing the same uniquely-defined aggregates; matched to <1e-9. Regenerable offline via tests/fixtures/mcda_waspas/ and tests/fixtures/mcda_moora/. Garbage-in-garbage-out on the inputs; the sensitivity/robustness layer stays MODELLED
Tests
tests/mcda_waspas_reference.rs (WASPAS preferences + ranking) and tests/mcda_moora_reference.rs (MOORA scores + ranking), each vs pymcdm to <1e-9 on a fixed 4×3 benefit/cost decision matrix
COmplex PRoportional ASsessment — column-sum-normalised benefit significance S⁺ plus the inverse-cost significance term, the relative significance Q and utility degree U = Q/max Q (best alternative = 1)
Oracle
pyDecision algorithm.copras_method (Valdecy Pereira) — an independent third-party MCDA library computing the same uniquely-defined COPRAS relative-significance/utility. pyDecision is used deliberately: pymcdm 1.4.0's COPRAS collapses algebraically to the trivial S⁺+S⁻ and is not a faithful reference, whereas pyDecision implements the canonical Q = S⁺+(min(S⁻)·ΣS⁻)/(S⁻·Σ(min(S⁻)/S⁻)). Matched to <1e-9; regenerable offline via tests/fixtures/mcda_copras/generate_copras_reference.py
Tests
tests/mcda_copras_reference.rs (utility degrees + ranking vs pyDecision to <1e-9 on a fixed 4×3 benefit/cost matrix)
Tabular-CUSUM detector worst-case detection latency (⌊h/(z−k)⌋+1) and out-of-control average run length, used by the timing-protection-level and spoof monitors
Oracle
Published tabular-CUSUM ARL: Siegmund (1985) Brownian-motion approximation (Hawkins & Olwell 1998, eq. 3.7) cross-anchored to Montgomery, Introduction to Statistical Quality Control (Wiley) ARL tables for k=½, h∈{4,5}; deterministic latency matched exactly to a first-passage oracle. The composed TPL bound stays MODELLED
Tests
tests/timing_protection_level_under_spoofing_reference.rs (16 deterministic-latency cases EXACT vs a first-passage oracle; 8 ARL₁ cases, Monte-Carlo @60k trials vs the Siegmund approximation + published Montgomery…
Coast phase-error variance growth q_wf·t + q_rw·t³/3 + q_drift·t⁵/20 and its monotone inversion to a timing-error holdover threshold
Oracle
scipy 1.18 (BSD-3-Clause): linalg.expm computing the Van-Loan 1978 discrete process-noise Q₀₀ = ∫₀ᵗ ΦQcΦᵀds via Padé scaling-and-squaring on the 6×6 augmented matrix — an independent route that never sees kshana's polynomial coefficients; plus optimize.brentq inverting the same monotone curve vs kshana's bisection. The per-class red-noise floor figures (ClockClass) stay MODELLED
Tests
tests/gnss_denied_clock_holdover_reference.rs (27 cases vs scipy 1.18: 12 coast-variance vs linalg.expm Van-Loan Q₀₀ worst rel 1.1e-15; 7 holdover inversions vs optimize.brentq worst rel 1.5e-16)
Effective architectural diversity = inverse-Simpson / Hill-order-2 number 1/Σpᵢ² over per-independence-group source qualities (the diversity term in the resilience score)
Oracle
scikit-bio 0.7.3 skbio.diversity.alpha.inv_simpson (McDonald et al., BSD-3-Clause) — an independent third-party library computing the uniquely-defined inverse-Simpson index; reproduced byte-for-byte. The DHS-RPCF scoring framework (weights/levels) built on top stays MODELLED
filterpy 1.4.5 KalmanFilter (R. Labbe, MIT), with F via scipy.linalg.expm and Q via the Van-Loan 1978 block-matrix — an independent reference implementation reproducing kshana's full filter trajectory. Cross-implementation consistency: the clock physics / Allan calibration are not externally validated, so this stays MODELLED
Tests
clock_state::tests (analytic van-Loan Q; NEES; PSD positivity); tests/clock_state_reference.rs (full predict+update trajectory — state x and 3×3 covariance P over 1925 steps / 4 parameter sets vs filterpy 1.4.5; worst…
Sagnac magnitude checked against an authoritative PUBLISHED VALUE — N. Ashby, 'Relativity in the GPS', Living Reviews in Relativity 6:1 (2003), Eq. 1.29: an eastward equatorial circumnavigation accrues 207.4 ns (2ωA_E/c²); kshana reproduces 207.386 ns. Independently corroborated by RTKLIB 2.4.3 geodist() (Takasu, BSD-2-Clause), which carries the same 2Aω/c² geometry. The composite BIPM TWSTFT transponder/common-view/PPP budget has no external oracle, so the capability stays Modelled
Tests
timetransfer::tests (reciprocal cancellation; two-form Sagnac identity); tests/time_transfer_error_budgeting_reference.rs (equatorial-circumnavigation Sagnac = 207.386 ns vs the published Ashby 207.4 ns to <0.05 ns…
GPS C/A Gold cross/auto-correlation matched EXACTLY (integer ±65/−1/63) against independent IS-GPS-200 code generation; BPSK-R(1)/BOC(1,1) PSD shape vs an independent scipy periodogram. The modulation/SSC/DLL closed forms (Betz 2001 / Kaplan & Hegarty) remain analytic, so the row stays MODELLED — but the code-correlation sub-claim is externally matched
Tests
navsignal::tests (BPSK self-SSC = 2/3R_c; unit-area PSD; DLL); tests/nav_signal_modulation_code_tracking_reference.rs (GPS C/A Gold cross/auto-correlation exact-integer match vs independent IS-GPS-200 code generation…
ValidatedGPS L1 C/A spreading-code generationsdr
Capability
G1/G2 LFSR C/A-code generator reproducing the IS-GPS-200 published first-10-chip octal verification vectors for PRN 1–9 (plus 1023-chip length, 512-ones balance, three-valued periodic autocorrelation)
Oracle
IS-GPS-200 Table 3-Ia 'Code Phase Assignments' — the authoritative US-Government public-domain published first-10-chip OCTAL verification vectors (GPS Directorate, navcen.uscg.gov); kshana's own G1/G2 LFSR regenerates every PRN 1–9 vector exactly. The downstream modulation/SSC/DLL closed forms stay Modelled (separate row)
Cold-atom interferometer accelerometer from first principles (k_eff·T², QPN)
Oracle
Published CAI primary-paper numeric vectors (Cheinet 2008 transfer function; Peters/Freier sensitivity): k_eff·T² matched exactly, shot-noise ASD a one-sided floor within ~2× of each published instrument (real devices carry technical noise above the quantum floor). A bracket, not parity
Tests
quantum_imu::tests (k_eff; Mach-Zehnder T²; Freier-2016 floor bracket); tests/quantum_inertial_sensor_reference.rs (transfer function |H(ω)|, k_eff·T² and shot-noise ASD vs published Cheinet 2008 / Peters / Freier…
Mach–Zehnder fringe-ambiguity dynamic range: the 2π-periodic fringe readout sets a maximum unambiguous specific force a_max=π/(k_eff·T²), and the unambiguous range in resolution cells a_max/σ_a=π/σ_Φ is independent of the optical scale factor — the T² sensitivity gain costs unambiguous range in exact lockstep (interrogation time trades resolution for range, leaving the cell count fixed by the readout phase noise)
Oracle
Self-consistency of the interferometer fringe model: the half-fringe edge, the 2π-periodic aliasing structure, and the scale-factor cancellation in the range/resolution ratio are closed-form algebraic identities checked against the engine's own Mach–Zehnder phase and sensitivity functions — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED ideal three-pulse fringe-ambiguity; no wavefront-aberration or contrast-loss bounds on the unambiguous range
Tests
quantum_imu::tests (a_max sits at the ±π half-fringe edge with the 1/T² range scaling; wrapped-phase recovery is exact inside [−a_max,a_max] and aliases by exactly 2·a_max outside it; the unambiguous dynamic range…
Composed bias + scale-factor + VRW + stability-decay position budget over holdover
Oracle
Independent numpy Monte-Carlo SDE integration of double-integrated white-acceleration noise (validates the analytic VRW variance by a genuinely independent algorithm) + a Groves 2013 published-value anchor for the bias/scale-factor terms; the CAI device numbers quantify partner hardware and stay MODELLED
Tests
budget_tests (bias vs AccelModel integrator; VRW vs analytic integral); tests/quantum_inertial_dead_reckoning_reference.rs (VRW vs an independent numpy Monte-Carlo double-integration of white-acceleration noise, worst…
15-state error-state EKF (loosely & tightly coupled), tightly-coupled pseudorange/Doppler UKF, and a coupled clock+position filter
Oracle
filterpy 1.4.5 (R. Labbe, MIT) on numpy/scipy. The three LINEAR filters reach the uniquely-defined Bayesian posterior independently (Joseph vs standard form, machine precision) — a genuine library-vs-library check; the tightly-coupled UKF shares the same sigma-point recursion, so it is consistency-only. Stays MODELLED (the trajectory truth / sensor calibration are not externally validated)
Tests
fusion::tests (UKF==linear-KF identity; outage coast; NEES); tests/gnss_ins_sensor_fusion_reference.rs (50 cases vs filterpy 1.4.5: linear EKF loose/tight + coupled-PNT posteriors to ≤2.4e-12; UKF 40-epoch run worst…
ModelledGNSS-denied jamming resiliencejamming
Capability
Geometry J/S link budget, anti-jam C/N₀, per-satellite loss-of-lock
Oracle
Anti-jam C/N₀ link-budget equation cross-checked against an independent numpy re-derivation (shares the same closed form → InternalConsistency) plus a real-JammerTest-2024 C/N₀ degradation characterisation
Tests
jamming::tests (PSD-derived Q cross-check; despreading); tests/gnss_denied_jamming_resilience_reference.rs (FSPL/J-S/effective-C-N₀ vs an independent numpy re-derivation of the Kaplan & Hegarty §9.4 link budget; real…
Closed-form bound on worst-case undetected time error = monitor floor + oscillator coast-σ over CUSUM detection latency, reported as a red-noise-floor band
Oracle
Composes Validated primitives (allan/holdover van-Loan, security floor); calibrated on JammerTest 2024 scenario 2.1.1 (~1.01 ms real served-time pull vs ≤51 ns claimed). Bridge over Validated parts — not itself an external validation.
NASA/JPL Three-Body Periodic Orbit Database (SSD, periodic_orbits.api; Earth–Moon L2 Southern halo family, Howell/Davis methodology) — externally-published period T, Jacobi C and perpendicular-crossing initial conditions; kshana's single-shooting STM corrector, seeded with the catalog IC and perturbed, converges back onto the catalog members
Tests
cr3bp::tests (STM vs finite-diff); tests/cislunar_mission_analysis_reference.rs (5 JPL L2-S NRHO members: the 9:2 + 4 neighbours; worst |ΔC| 1.5e-5, |ΔT|/T 9.6e-5, perilune 0.7 km in JPL length units)
ValidatedSRTM digital-elevation reader on real terrainaltpnt::terrain
Capability
Hand-rolled SRTM .hgt parser (16-bit big-endian, north-row-first, void-aware) + bilinear sampler reading a real public-domain DEM tile and resolving a documented survey benchmark
Oracle
NASA/USGS SRTM v3 (1-arc-second) N36W117 tile — US-Government PUBLIC-DOMAIN elevation data from the AWS elevation-tiles-prod open mirror, decimated to 6-arc-second and committed under tests/fixtures/terrain/ (see NOTICE.md). The documented Badwater Basin benchmark (−86 m, lowest in North America) anchors the geo-referenced read. The terrain-matching/TERCOM nav-fix that consumes the DEM stays Modelled (separate Alternative/complementary PNT row)
Tests
tests/terrain_nav_validation.rs (real_srtm_committed_badwater_tile_reads_real_relief — the committed 6-arc-second decimation of the public-domain SRTM v3 N36W117 tile places Badwater Basin, the lowest point in North…
ModelledReproducibility & software assurancereport,scenario; CI (golden/determinism/SBOM)
Capability
Deterministic, scenario-hashed, SBOM + cross-platform golden gates
Oracle
SBOM conformance to the official CycloneDX 1.5 JSON Schema (+ valid SPDX identifiers) — an external published standard, zero validation errors over the full dependency graph; the FoM-determinism / byte-reproducibility part remains a pinned self-consistency check, so the row stays MODELLED
Tests
tests/golden.rs, tests/determinism.rs, tests/cross_platform_golden.rs; tests/reproducibility_software_assurance_reference.rs (the generated SBOM validates with zero errors against the official CycloneDX 1.5 JSON Schema…
Labelled synthetic impairment corpus + detector-agnostic ROC/AUC/confusion/Pfa-Pmd harness; leakage guard, stratified split, distribution-shift (in- vs out-of-regime) optimism report. Runnable from the CLI/bindings as the impairment-eval scenario kind (scenarios/impairment-eval.toml)
Oracle
Closed-form AUC bounds (Mann–Whitney) + a perfect-oracle detector; corpus is SYNTHETIC (parameter-grounded, not field/IQ)
ModelledAI/ML RF-impairment optimism-gap study & ID-only gap predictorimpairment_study,impairment_ml,eval_stats
Capability
Controlled synthetic study of the in-distribution→out-of-distribution AUC optimism gap across published-method and learned (logistic-regression / one-hidden-layer MLP) detectors: per-class scaling-law trends (Spearman ρ + slope on 1−severity) and an ID-only ridge predictor that estimates the gap from in-distribution diagnostics alone, scored leave-one-detector-out and leave-one-class-out. Reproducible via cargo run --release --example optimism_study
Oracle
Hand-derived statistics vs closed forms (binormal AUC Φ(d'/√2), DeLong variance, tied-rank Spearman, exact OLS recovery) + leave-one-out CV against the predict-the-mean baseline. Corpus is SYNTHETIC (parameter-grounded, never field/IQ) and the optimism gap is a synthetic→synthetic severity shift, NOT a sim-to-field result
Tests
impairment_study::tests (per-class oracle AUC≈1, learned optimism gap>0, grid shape + bootstrap CI brackets the mean + positive scaling trend, ID features finite, gap predictor beats predict-the-mean under BOTH…
Measured-ADEV ingestion (NNLS), trade table (timing/inertial holdover + benefit), resilience-vs-time envelope; floor caveat carried on the artifact. Runnable from the CLI/bindings as the quantum-trade scenario kind (scenarios/quantum-trade.toml)
Oracle
The measured-ADEV→PSD fit (NNLS) kernel is matched to scipy.optimize.nnls (tests/scipy_reference.rs / tests/quantum_vs_classical_pnt_trade_reference.rs) — an independent external kernel; but the trade NUMBERS quantify (never validate) a partner clock/CAI, so the trade itself stays MODELLED, no validation halo
Tests
quantum_trade::tests (ADEV round-trip recovery, NNLS non-negativity, floor-caveat present/absent, benefit>1, monotone envelope + alt-PNT bound); dominance_demonstrators (measured-ADEV is data-driven not floor-assumed…
Solar/geomagnetic indices (definitional Kp↔ap table), Jacchia-1971 exospheric temperature, and a calibrated first-order activity density correction over the static USSA76 atmosphere (the solar-cycle density swing the static model omits). Runnable from the CLI/bindings as the space-weather scenario kind (scenarios/space-weather.toml)
Oracle
Definitional Kp↔ap table + Jacchia-1971 exospheric-temperature closed form (matched to <1 K vs the published anchors, tests/space_weather_reference.rs); the density correction is characterised against pymsis NRLMSISE-00 (an independent NRL model) — directionally correct and within a factor of 3 of the 400 km solar-cycle swing, but diverging up to ~8× aloft, so the density layer is a CALIBRATED first-order model and stays MODELLED
Tests
space_weather::tests (Kp↔ap exact at grid points + round-trip + monotone, daily-Ap mean, exospheric-T vs published solar-min/mean/max + storm increment anchors, density unity-at-reference, solar-cycle swing in the…
CCSDS 502.0 OEM importer (parse_oem), tolerant of COMMENT lines / extra metadata keywords / covariance blocks and the exact inverse of the writer; round-trip + external-file ingest with a velocity-consistency check. Runnable from the CLI/bindings as the oem-interop scenario kind (scenarios/oem-interop.toml)
Oracle
Independent third-party CCSDS-502 parser oem 0.4.5 (B. Sease, MIT) — a separate codebase that decodes kshana's emitted EME2000/UTC OEM byte-identically (24 states across 2 fixtures, pos/vel Δ = 0) and whose strict reader confirms the metadata tokens; kshana's parser likewise agrees with it on a vendored external OEM. Two honest interop findings (the oem library rejects kshana's per-satellite multi-segment convention and its multi-entry covariance lines) are documented in the test — so this validates the conformant single-object interchange, not full CCSDS-502 conformance of every kshana variant
Tests
tests/ccsds_oem_interop_reference.rs (24 states / 2 fixtures decoded byte-identically by the independent oem parser, pos/vel Δ = 0); oem::tests (parse an external-tool OEM with extra keywords/comments/covariance…
Two-body launch azimuth(s) (sin Az = cos i / cos lat), minimum reachable inclination, circular velocity, Earth-rotation eastward bonus, dogleg plane-change Δv and daily opportunities. Runnable from the CLI/bindings as the launch-window scenario kind (scenarios/launch-window.toml)
Oracle
Closed-form spherical-trig launch geometry vs published worked-example anchors (Vallado, Fundamentals of Astrodynamics 4th ed., Algorithm 37 launch-azimuth + Ch.6 plane-change; tests/launch_window_ascent_geometry_reference.rs). These re-use the same closed form kshana implements (a published-value parity / transcription check, InternalConsistency); MODELLED two-body, no rotating-Earth velocity-triangle / ascent / drag-loss model
Peak deceleration (ballistic-coefficient-independent), velocity + altitude at peak-g, and peak-heating velocity for an exponential-atmosphere ballistic entry. Runnable from the CLI/bindings as the reentry scenario kind (scenarios/reentry.toml)
Oracle
Closed-form Allen–Eggers analytic entry, additionally cross-checked vs a scipy 1.18 solve_ivp (DOP853) numerical integration of the SAME drag-only entry ODE (tests/ballistic_re_entry_corridor_reference.rs, 36 cases, worst a_max rel 2.9e-9) — a numeric-integral-vs-own-analytic-form check, so still InternalConsistency, NOT an external validation. MODELLED ballistic (no lift), no aerothermal/TPS — heating output is a velocity, not a heat-flux
Tests
reentry::tests (peak-g independent of ballistic coefficient + physical g-band, grows with steeper γ / faster entry, peak-g velocity = V_e·e^(−1/2) and peak-heating = V_e·e^(−1/6) faster, peak-g altitude physical +…
SMAD space-triangle geometry: Earth angular radius, swath width, nadir GSD, maximum off-nadir access, circular period + equatorial ground-track spacing with a contiguous-coverage flag. Runnable from the CLI/bindings as the eo-coverage scenario kind (scenarios/eo-coverage.toml)
Oracle
Closed-form SMAD/Wertz space-triangle relations cross-checked against Skyfield/SGP4 + a WGS-84 ray-ellipsoid geodesic (tests/eo_payload_coverage_reference.rs): equatorial node spacing within 1% of an SGP4 propagation and the limb angle within 0.3° of the ellipsoid. MODELLED spherical-Earth geometry (the ellipsoid/SGP4 envelope difference is the modelling gap), no radiometry/MTF/atmosphere/jitter/glint
Tests
eo_payload::tests (angular radius 64° at 700 km + shrinks with altitude, nadir→zenith/zero-range, horizon→ε=0/max central angle, past-horizon errors, swath grows with FOV / GSD with altitude, ~2750 km node spacing…
ValidatedCCSDS Space Packet (133.0) TM/TC framingspace_packet
Capability
CCSDS 133.0-B Space Packet primary-header encode/decode (version/type/sec-hdr/APID/seq-flags/count/data-length) + a framing scenario. Runnable from the CLI/bindings as the space-packet scenario kind (scenarios/space-packet.toml)
Oracle
spacepackets 0.32.0 (us-irs/spacepackets-py, R. Mueller, Apache-2.0) — an independent third-party implementation of CCSDS 133.0-B-2; kshana's encode_packet/decode_packet matched byte-exact (the 6-octet primary header for 33 cases + the full encoded packet for 12)
Tests
space_packet::tests (header bits match the CCSDS-133 layout, encode→decode round-trips all fields, out-of-range/truncated rejected); tests/ccsds_space_packet_reference.rs (33 cases vs spacepackets 0.32.0, incl. 12…
Gravity-gradient worst-case disturbance torque ((3/2)(μ/R³)ΔI) + RSS pointing-error budget over named 1σ contributors with the dominant term. Runnable from the CLI/bindings as the attitude-budget scenario kind (scenarios/attitude-budget.toml)
Oracle
Closed-form gravity-gradient torque and quadrature RSS, cross-checked against a hand-coded full-tensor torque numerically maximised over attitude (Hipparchus 3.1 linalg) which blindly rediscovers the 45° peak — a strong self-consistency check, but the GG physics is shared/hand-coded so it stays InternalConsistency, not external. MODELLED scalar AOCS budget — no control-loop/6-DoF/flexible-mode simulation
Tests
attitude_budget::tests (GG torque vanishes for a symmetric body, grows lower-down, linear in ΔI, RSS quadrature sum, variance-fractions-sum-to-1); tests/attitude_gg_torque_reference.rs (20 cases vs an independent…
Time-domain visibility passes (AOS/TCA/LOS, max elevation, duration) of an orbit over a station above an elevation mask, with interpolated rise/set crossings and total access. Runnable from the CLI/bindings as the passes scenario kind (scenarios/passes.toml)
Oracle
Orekit 12.2 (CS GROUP, Apache-2.0) + Hipparchus 3.1 — an independent flight-dynamics library: ElevationDetector (Brent root-finder) + EventsLogger over an ITRF ephemeris, station as a WGS-84 TopocentricFrame. AOS/LOS/max-elevation/pass-count/total-access matched on identical orbit+station+mask+window (committed fixture; driver xval/orekit-passes)
ValidatedOne-way link budget (comms / link design)linkbudget
Capability
Free-space path loss, C/N₀, Eb/N₀, margin and closure over the CCSDS 401 / DSN 810-005 link equation for EIRP/G·T/range/rate/band against a required Eb/N₀. Runnable from the CLI/bindings as the link-budget scenario kind (scenarios/link-budget.toml)
Oracle
Published deep-space telecom design-control table as pinned numeric vectors: DESCANSO / J. H. Yuen (ed.), Deep Space Telecommunications Systems Engineering, JPL Pub 82-76, Table 1-1 (Galileo X-band) — kshana reassembles the table line-items and reproduces its published end-to-end L_fs 290.54 dB and Pr/N0 54.6 dB-Hz; free-space loss also checked vs ITU-R P.525
ModelledFrugal cost-per-coverage / ROI framingfrugal (over walker)
Capability
Cost-per-percent-coverage + coverage-per-euro ROI over the constellation sizing engine; per-satellite cost is a caller-sourced low/nominal/high bracket (no fabricated prices)
Oracle
Closed-form cost arithmetic vs hand-derived values; an economic FRAMING of a modelled coverage figure, not a quote or validated cost model
Tests
frugal::tests (hand-derived cost-per-coverage 48/96=0.5, ROI ratio 2.667, bracket-ordering + zero-coverage guards)
ModelledDetection-miss integrity impact (context-aware HPL/VPL vs alert limit)integrity_impact (over raim)
Capability
Maps an undetected spoof/jam bias to effective error → Stanford region (available/unavailable/MI/HMI) against context-specific HAL/VAL (open-sky vs urban)
Oracle
Composes the externally-validated RAIM Stanford classification (raim::classify_stanford); the detection-miss→AL mapping itself is modelled, not a certified integrity allocation
Tests
integrity_impact::tests (same miss flips Available→MI→HMI as the context tightens; conservative-PL→Unavailable; per-axis HMI; input guards)
Bracketed (best/nominal/conservative) cold-atom-interferometer performance — bias instability, velocity/angle random walk, scale-factor stability, interrogation-limited sample rate, fringe-ambiguity dynamic range — each citation-traceable; feeds QuantumNavBudget without modelling hardware
Oracle
Internal consistency: the cited VRW bracket cross-checked against CaiAccelerometer::accel_asd physics + raw dynamic range computed from the fringe-ambiguity limit; numbers are MODELLED literature-survey brackets (needs_source_confirmation), no device validated, no validation halo
Tests
inertial::cai_params::tests (physics VRW lands inside the cited VRW bracket at all 3 levels; raw fringe-ambiguity range computed from k_eff·T²; conservative budget drifts more than best; every bracket sourced +…
Independent numpy re-implementation of the four-region rule (scripts/gen_tib_scorer_reference.py) on the identical sample set; method Cited from the Stanford–ESA integrity diagram (Tossaint et al., ION GNSS 2007) and RTCA DO-229 WAAS MOPS. NOT an ExternalDataset accuracy oracle — the benchmark is honesty-immune.
Tests
src/benchmark/stanford.rs::tests (four regions + inclusive boundaries + |error| + PL>AL unavailability); tests/tib_scorer_reference.rs (classification counts vs independent numpy on a fixed synthetic set)
Representative parametric fault generators (Modelled); the undetectable set (symmetric delay, replay-within-freshness) is Cited from Mizrahi RFC 7384 and Narula & Humphreys (IEEE JSTSP 2018). No external oracle — a fault catalog makes no measured claim.
TIB undetectable-absorption verdict (symmetric/replay must be absorbed by the PL, never reported detected)
Oracle
Property check that the Verdict enum structurally cannot report an undetectable fault as detected (Mizrahi RFC 7384); absorbed ⟺ PL ≥ offset. No accuracy oracle.
Tests
src/benchmark/scorecard.rs::tests (reference PL absorbs; broken PL unabsorbed-never-detected; detectable coverage verdict; the honesty property that no coverage/detection verdict is reachable for an undetectable…
Partner-ownedSpacecraft bus engineering (AOCS/thermal/structures/propulsion/power)
Capability
Not provided — Kshana is a navigation-performance simulator, not a bus house
Ashby & Patla 2024, 'A Relativistic Framework to Estimate Clock Rates on the Moon', Astronomical Journal 167:149 (NIST; basis for the IAU/IAG LunaNet LTC): Moon-surface self-potential L_m = 3.13881e-11 and secular total 56.02 µs/day matched as published numeric values; geocentric Moon speed cross-checked vs JPL DE440 (de440s.bsp via SPICE)
Tests
lunar_time::tests (closed-form rate; round-trip); tests/lunar_coordinate_time_reference.rs (LTC self-potential & secular-rate terms vs published Ashby & Patla 2024 values + geocentric Moon speed vs JPL DE440)
The hybrid-optical-rf report states the link configuration it actually ran at (carrier wavelength, transmit and receive aperture, range, pulse width, integration time, efficiencies and losses, defaults resolved) and carries a units block giving the unit and provenance class of every quantity a paper is likely to quote, including the handoff covariance traces in square metres
Oracle
No external oracle, and none is possible: this is self-description, not a measurement. It is recorded because the absence of it was a defect -- P5 had to quote the carrier wavelength and transmit aperture from source defaults, and to infer that a bare variance was in square metres from an internal consistency check. The inference was correct, which is precisely why it mattered: nothing would have caught it being wrong
Tests
hybrid_integrity::tests (the resolved configuration is echoed for defaults and for overrides, without round-tripping the wavelength through metres; every units entry carries both a unit and a provenance class; every…
ModelledHybrid optical/RF link availability on the RF sidehybrid_integrity,linkbudget,jamming
Capability
The hybrid-optical-rf report states an RF link availability, composed from quantities the engine already computes rather than from an imported climatology, and states the composition as a named rule: A_rf = I_closure * I_track, where I_closure is the closure verdict of the one-way CCSDS-401 / DSN-810-005 link budget (linkbudget::link_budget, Eb/N0 margin >= 0) at the scenario's own range and I_track is the tracking-loop verdict (jamming::lock_status) on the C/N0 that SAME budget returned. Each factor carries its input's provenance class through to the output, and the factors deliberately NOT in the product -- geometric visibility, interference denial, and an RF outage climatology -- are named with the reason rather than silently set to 1. The resolved RF leg is echoed as its own rf_link_configuration block, and the continuous figures beside the indicator (link margin, C/N0 margin, the closed-form closure and tracking ranges, and the range utilisation) are the range inversions of the same budget. The report states in full, on the block and in the units entry a reader lands on, that this figure is MARGIN/GEOMETRY-LIMITED and DETERMINISTIC while optical availability is WEATHER/CLIMATOLOGY-LIMITED and probabilistic, so the two can never be quoted as a comparable pair of percentages
Oracle
No external oracle, and ExternalDataset is declined. The two inputs are an Eb/N0 margin and a C/N0 threshold crossing, both functions of a MODELLED EIRP, figure of merit and lumped loss allocation; there is no measured availability record for an Earth-Moon optical/RF hybrid service to check the composed figure against. The checks that exist are internal and are stated as such: the composition is recomputed from the report's own published margins rather than from the emitter's internals, and the closure range is verified by re-running the link equation AT it and requiring the margin to vanish -- an inversion round trip, not an independent implementation. The honest limit of the figure is recorded on the report itself: it is a deterministic 0/1 indicator, not a probability, because nothing in this engine measures an RF link-outage distribution at this band and geometry. That missing input is named in rf_availability.factors_not_included rather than invented, and supplying it is what a probabilistic RF availability would need
Tests
hybrid_integrity::tests (the availability equals the product of the two indicators recomputed from the report's own margins, and those margins are themselves reassembled from the report's own EIRP, free-space loss…
The hybrid-optical-rf report emits the optical-versus-RF ranging ratio with the ONE configuration both legs were evaluated at carried in the same object: the same one-way path, the same range, and the same accumulation time. The optical leg is the engine's photon-limited ToA CRLB on the one-way photon count; the RF leg is the engine's DLL early-late thermal code-tracking jitter at the C/N0 the engine's own link budget returns for that same one-way range. The loop noise bandwidth is derived, not chosen: B_L = 1/(2*integration_s) puts the RF leg at exactly the optical accumulation time, and if a caller overrides it so the two averaging times disagree the ratio is REFUSED -- null, with the mismatch and both times named -- rather than quoted at two operating points. No ratio is formed against the scenario's CHOSEN parametric rf_position_sigma_m, and the refusal says why: that input carries no configuration at all. The released two-way optical headline and the exact factor bridging it to the one-way comparison leg are emitted beside the ratio, so the report cannot be read as carrying two disagreeing optical sigmas
Oracle
No external oracle for the RATIO, and ExternalDataset is declined deliberately. The underlying RF chain does have one -- tests/validate_p5_rf_ranging_precision.rs checks linkbudget::link_budget and navsignal::dll_code_jitter_chips against an independent Python/NumPy fixture and against the hardcoded Kaplan & Hegarty worked value (2.814e-3 chip / 0.825 m at 45 dB-Hz) -- and the optical CRLB has its own closed-form row. Claiming either anchor for this row would be borrowed validation, which the matrix invariants exist to prevent: the quantity here is a RATIO at a configuration with a MODELLED EIRP, figure of merit, transmit power and aperture, and no measured optical-versus-RF ranging comparison at a common operating point exists to check it against. What is checked internally is the thing the ratio can actually get wrong: that the two legs sit at one operating point. That is measured by scaling the common accumulation time and requiring both legs to move by the same square-root law and the ratio to stay put, and it is enforced by refusing the ratio outright when the averaging times disagree. Both legs are thermal/shot-noise bounds and both exclude media delay, clock error and ambiguity, so the exclusion is identical on each side; the report says so rather than leaving it inferred
Tests
hybrid_integrity::tests (the ratio equals the two emitted legs divided, to 1e-15 relative, and its reciprocal and decibel forms agree; each leg's range and time sigma are related by exactly c; the emitted common…
The link-budget report states every absolute constant its own margin was computed from -- the carrier frequency the free-space loss used, the EIRP, the figure of merit, the lumped loss and the Boltzmann term -- plus the required G/T at which the margin is zero, the link constant (EIRP - losses - required Eb/N0) that is the only combination a published rate/gain table can ever fix, and, when a caller states a system noise temperature, the receive antenna gain that figure of merit implies
Oracle
No external oracle: this is self-description over an equation already validated against a published design-control table (see the one-way link budget row). It is recorded because the absence of it was a measured defect -- reproducing the released d1_rate_gain_beamwidth.csv required back-solving one effective constant to 0.0034 dB from all thirty rows, and the engine now both names that combination and proves, by test, that no released table could ever have separated its three components
Tests
linkbudget::tests (across three bands, four decades of range and both closure verdicts, the margin and the free-space loss under it are recomputed from the report alone to better than 1e-9 dB; the required G/T…
ModelledPer-clock-class lunar time crossover tablelunar_time_budget
Capability
One lunar-time-budget run emits a clock-vs-frame crossover row per clock class against a single shared frame term, so the clock is the only variable in the comparison; each row carries the crossover reached two ways -- bisected from the general power-law time-error curve and inverted algebraically from the row's dominant noise type -- with the relative difference between them
Oracle
Two different in-codebase computations of the same quantity, not one restated: bisection on the IEEE-1139 power-law curve knows nothing about noise type, while the closed form inverts the dominant type algebraically, so a misclassified noise type or a bad bracket shows as a non-tiny relative difference. The four values also reproduce the paper's published table to half its last printed digit -- but that table was itself reconstructed from the same closed form, so it is a reproducibility check and not an external oracle, and the frame term it is measured against is a Modelled allocation
Tests
lunar_time_budget::tests and lunar_time_budget_scenario::tests (all four classes present in one run and in a requested subset order; every row agrees with its own closed form to better than 1e-12 relative; scaling the…
ModelledJoint UT1 and polar-motion error over a common row setframe_eop
Capability
One table reports the UT1 prediction error, the polar-motion pole error and their quadrature combination at the Moon over an IDENTICAL epoch set per horizon, emitting the epochs each component was measured at. Separately, the scenario names whichever EOP input is in force and decomposes its row census, and always emits the predicted-versus-final horizon table with an explicit statement of why it is empty when it is
Oracle
An algebraic identity evaluated by a different expression than the one under test: the emitted combination is the root-mean-square of the per-epoch hypotenuse, and the check is the hypotenuse of the two components' own root-mean-squares. The residual path is cross-checked against a separate call into frame_eop, and the row census against the identity rows = finals + predictions. The residual MAGNITUDE is checked only against a plausibility band, never against an IERS-published prediction-accuracy figure -- reading a real product is provenance, not an oracle, which is why this stays Modelled
Tests
frame_eop::tests and realtime_frame_eop::tests (all three components carry equal, elementwise-identical, strictly ascending epoch sets over both real IERS extracts; the joint set collapses to the intersection when the…
ModelledOffline default Earth-orientation input is a real IERS productrealtime_frame_eop,eop
Capability
The realtime-frame-eop runtime default is the library's own embedded copy of a verbatim IERS finals2000A extract (MJD 61173-61204) carrying BOTH row vintages the format defines -- 20 Bulletin B finals and 12 Bulletin A prediction-only rows -- so a bare run with no file argument and no network emits a populated per-horizon table and predicted_rows.n = 12, together with the operational-predictor comparison and the agreement against the product's own published prediction rows. The prior five-row final-only excerpt remains shipped, byte-pinned and exercised: on it predicted_rows.n is 0, which is the input file's property and not a parser outcome, and the emitted census names whichever input is in force and decomposes it as rows = final_rows + prediction_rows
Oracle
The published IERS finals2000A series itself, used verbatim and byte-pinned: this row's claim is a claim about that external product -- how many rows of each Bulletin vintage the shipped extract carries, over which MJD span -- and the reference is the file's own fixed-column content, whose SHA-256 is recorded in tests/fixtures/agency/NOTICE.md and which is byte-identical to the copy the arXiv P4 artifact bundle publishes. ExternalDataset is nonetheless DECLINED and the status is Modelled, deliberately: the count is taken by this crate's own parser and checked by this crate's own parser over the same bytes, so the check shares its expression with the thing under test; the IERS publishes no companion table of per-vintage row counts for an arbitrary excerpt that could serve as an independent oracle; and the excerpt is a slice this repository cut, not a product IERS issued in that form. What the external data does buy is PROVENANCE -- the rows are real and unaltered -- which is not the same as an oracle, the same line already drawn on the joint-EOP and operational-predictor rows. REVISION (programme rule R4): moving the default off the five-row final-only excerpt moved ten cells of the released p4_frame_eop.csv -- eop_source, predicted_rows.n 0 -> 12, first_mjd and last_mjd from blank to 61193 / 61204, the measured pole floor 0.07693113803915594 -> 0.06776429738439221 mas with its two per-axis terms 0.05439852939188552 -> 0.04791659420284556 mas, the Earth-orientation term 14.016178596543083 -> 14.016014260081214 m, the total 20.097702765309116 -> 20.09758815707301 m and 67.03872038471734 -> 67.03833809279155 ns -- and the twenty-four populated Table 2 cells of tests/golden/realtime-frame-eop.csv. The other twelve cells of p4_frame_eop.csv, and both Table 1 rows of the golden CSV, are unchanged. Every moved cell is enumerated old-to-new in docs/revisions/G12-default-eop-cell-changes.md. The revised pole floor is the SAME quantity P4 already publishes in its polar-motion table (n = 20, 0.0678 mas): before this change the paper's budget took that floor from the five-row excerpt while its pole table took it from the 2026 extract, and the budget's value was 13.5 % the larger of the two. Every other figure P4 prints from this table -- 14.016 m, 14.403 m, 0.177 m, 20.098 m, 67.04 ns, 0.7170 ms, the 48.6 / 51.4 / 0.008 percent variance shares and the 20.3 / 21.6 / 50.0 percent halving sensitivities -- is unchanged at the precision printed; the two pole figures are the only printed numbers that move
Tests
realtime_frame_eop::tests and tests/operational_eop_predictor_reference.rs (a bare default run asserted to report 32 rows / 20 finals / 12 predictions spanning MJD 61193-61204 against an INDEPENDENT count taken by…
ModelledCapture footprint against altitude and beamwidthantenna
Capability
Two-axis sweep of the pattern-weighted, altitude-limited surface capture footprint over transmitter altitude and dish diameter, emitted one row per operating point with the half-power beamwidth each diameter implies, and limb capture reported as a THRESHOLD -- per row the limb J/S, its margin and the transmit power that would close it; per grid the located crossings, or an explicit statement that the limb is not reached anywhere on the grid, with the shortfall
Oracle
Set inclusion: the jammer-to-signal ratio enters as a uniform decibel offset, so the captured set at a higher transmit power contains the set at a lower one and the fraction can only rise -- a property the Airy pattern does NOT give in beamwidth or altitude, where the captured region breaks into rings and the fraction is genuinely non-monotone. No published table gives the captured disk fraction of a lunar orbital transmitter against altitude and beamwidth, so there is nothing external to check these cells against; the pattern underneath is separately Validated against published Bessel values and keeps its own row
Tests
antenna::tests and attack_surface::tests (the grid is complete and every captured fraction lies in [0,1]; captured fraction is non-decreasing in transmit power at every node; it is NOT monotone in beamwidth or…
The lunar-time-budget scenario publishes its array-valued outputs as a long-form (grid index, averaging time, term) table alongside the report, so the seven per-term x(tau) curves and the root-sum-square total are engine output rather than something a reader rebuilds from the method section
Oracle
Self-consistency only: the published total is checked against the root-sum-square of the terms in the same file, and the emitted curve reproduces the released p3_time_budget_curve.csv over all 57 points. Both checks share this engine's own term definitions, so neither is independent. The clock term rests on published clock specifications, but the link, frame, relativistic and ephemeris floor MAGNITUDES are documented budget allocations with no external oracle
Tests
lunar_time_budget_scenario::tests (all 57 averaging times x 8 terms present, the grid index runs 0..=56 and carries 8 rows each; the total row equals the root-sum-square of the seven terms beside it at every tau; the…
ModelledLunar geodetic VLBIlunar_vlbi
Capability
Near-field VLBI delay for an Earth baseline observing a lunar beacon + partials
Oracle
Plane-wave delta_dor (same-codebase) in the far-field limit; finite-difference partials
ModelledEarth-GNSS at lunar distanceearth_gnss_lunar
Capability
Earth-GNSS reception at lunar distance: the weak-signal layer P7 Table 1 names and the engine had no model for. Per satellite and per epoch it computes the off-boresight angle against the transmitter nadir, whether the Earth occults the straight path, the slant range and its free-space loss, the transmit gain at that angle, the received power and the carrier-to-noise density; it then aggregates only the links clearing a tracking threshold, and sweeps a full constellation revolution so the answer is a DISTRIBUTION rather than one snapshot. Three facts drive the result and the report states each: the Earth subtends 13.90 deg from the constellation radius so the beam PEAK is geometrically unavailable to any lunar-bound ray; what remains is the main-lobe edge and the sidelobes, the regime LuGRE operated in at the Moon in 2025; and the L1 path loss is about 208 dB, some 25 dB more than a terrestrial user pays. MEASURED on the bundled 24-satellite GPS-class geometry over 64 epochs of one orbital period: SIGNAL availability 0.375 with a best link of 30.93 dB-Hz, and FIX availability 0.000 - at most two simultaneous trackable links, never the four a position needs. The separation of those two availabilities is the point, and the report refuses to let them be confused: Earth-GNSS at lunar distance is a TIMING-grade layer, not a position-grade one, and a layered-resilience prior must take the fix availability. The conditioning is emitted for the same reason - every visible satellite lies inside a cone a couple of degrees wide as seen from the Moon, so the lines of sight are near-parallel by construction. Runnable as the earth-gnss-lunar kind
Oracle
Closed-form identities and internal consistency; NO external oracle is claimed. The limb half angle is checked against asin(R_earth/r_orbit) and the geometry against it; the free-space loss, the DOP kernel and the SGP4 propagation this composes are each externally validated in their own rows and this row does not borrow their status. WHY MODELLED, and it is the transmit pattern: the gain at angle is a uniformly illuminated circular aperture, the Airy pattern, while a real GPS L1 antenna is a twelve-element helical array with a shaped main lobe peaked off-boresight to even out power across the Earth disc and sidelobes that are not Airy. Published measured patterns exist and are not vendored here, so orderings and orders of magnitude carry, while the dB of any single satellite does not. A FIRST IMPLEMENTATION OF THIS ROW WAS WRONG IN A WAY WORTH RECORDING: the Airy expression is valid only in the forward hemisphere, its argument goes as sin(theta), and at theta near 180 deg it wraps around and returns FULL BORESIGHT GAIN behind the aperture - so the two strongest links in the first report were satellites pointing their antennas away from the Moon, and they were the only two that cleared the threshold. Behind the aperture the model now applies a flat back-lobe floor, stated as a bound rather than a fabricated pattern shape. Deliberately absent, each making the budget OPTIMISTIC: no ionospheric or tropospheric loss on the limb-grazing rays, no polarisation, pointing or implementation loss, and a spherical Earth with no refractive extension. The Moon position is an INPUT, not an ephemeris lookup, because the quantity under test is the link and the beam geometry. Upgrading this row to Validated needs a measured transmit pattern and LuGRE normal points to check against; neither is in the repository and neither is invented here
Tests
earth_gnss_lunar::tests (11 lib tests: the Earth-limb half angle against its closed form asin(R/r) with a further assertion that EVERY un-occulted link lies outside that cone, so the occultation test and the limb angle…
Beacon-augmented dilution of precision for a lunar surface user: the visible-satellite line-of-sight rows and the visible-surface-beacon ranging rows are concatenated into one design matrix and evaluated through the shared DOP kernel, and the resulting DOP is mapped to a realised 1-sigma accuracy IN METRES through a per-beacon user-equivalent ranging error assembled as the root-sum-square of clock-synchronisation, multipath and survey terms. Beacon visibility is the airless-Moon two-height geometric horizon, which has no refractive extension and is therefore exact rather than approximate. Runnable as the lunar-beacon scenario kind, which reports satellites alone, satellites plus beacons, and a larger constellation as the competing route to the same geometry. MEASURED on the bundled golden geometry (user at -80 deg, three surveyed beacons, six-satellite illustrative LCNS at t=0, 5 deg mask): 5 visible satellites give PDOP 9.6941 and a 3-D 1-sigma of 11.222 m; adding the beacons that actually clear the horizon gives PDOP 4.1160 and 4.765 m, a factor of 2.355; the 24-satellite service instead gives PDOP 2.4226 and 2.804 m, a factor of 4.002. The report prints the VISIBLE beacon count rather than the configured one, and on this geometry only ONE of the three beacons clears the horizon: the two flanking sites lie about 333 km from the user against an 86 km horizon for a 2 m antenna, so a reader is never left to assume all three contributed
Oracle
The DOP arithmetic is the crate::orbit::dop kernel, separately externally validated against gnss_lib_py in tests/dop_reference.rs; this row does not re-borrow that row's status. The beacon-visibility horizon is the L01 closed form, and sigma = DOP x sigma_URE is the standard GNSS relation (Kaplan and Hegarty, Understanding GPS/GNSS, section 7). Within this row the augmentation itself is checked against an independent in-repo DOP path and pinned to a committed golden. WHY MODELLED: the constellation design, the beacon placement, the antenna heights and all three error-budget magnitudes are illustrative inputs rather than a fielded survey or a measured link, so the reported metres are a property of a chosen scenario and not of any deployed service. NOTE ON PROVENANCE: this capability was advertised in the README and exercised by two validation tests, yet carried NO matrix row and no scenario kind, so it could not be reached from a run at all. It was claimed in prose, absent from the ledger, and unreachable in the engine at the same time. The row and the kind were added together
Tests
lunar_beacon::tests (horizon visibility against the L01 closed form; the beacon-augmented DOP against the bare one; the error-budget root-sum-square; the DOP-to-metres relation)…
Exact parity-subspace split of a measurement error into the part RAIM cannot see and the part it can. For the linearised snapshot model y = G·x + e, any error dy decomposes uniquely into a BLIND component in range(G) — absorbed as a state error S·dy and annihilated by the residual projector Pperp = I − G·S, so invisible to ANY residual test, not merely to a particular threshold — and a DETECTABLE component in parity space. The module returns the projector, the split, and the blind fraction, so a caller can quantify how much of a specific error a snapshot monitor is structurally unable to report. Applied to the real inter-ephemeris floor: the metre-level DE440-vs-INPOP21a and DE440-vs-EPM2021 disagreement in the geocentric Moon position is absorbed almost entirely as user position error (median blind fraction 1.000000; median blind position error 2.3955 m and 2.0050 m) against a parity residual at the 1e-15 m level
Oracle
An independent numpy implementation of the same 4x4 least-squares split, fed byte-identical inputs (user, satellites and every per-satellite dy are rounded to 1 micrometre before being written to reference.json and before reaching the oracle), so the only difference between the two sides is the linear solver. WHY THIS IS NOT VALIDATED, despite using real data: the DE440 / INPOP21a / EPM2021 inter-ephemeris disagreement is an INPUT both sides receive, not an independent check of the answer — numpy evaluates the same formula, so it corroborates the implementation and not the model. The lunar constellation geometry (8 LCNS-like nodes at 5000 km slant range) is an original deterministic construction, not a surveyed or published one. The blindness is in any case a known, correct property of all snapshot RAIM; the contribution is quantifying it on a real inter-ephemeris floor, not discovering it. Ephemeris provenance for the reused Moon states is in tests/fixtures/inter_ephemeris/NOTICE.md (JPL, IMCCE, IAA RAS)
Tests
lunar_common_mode::tests (8 lib tests: the split is additive and reconstructs dy; a common-mode covariance yields a positive common-mode protection level while a parity-only covariance yields a near-zero one; the…
ModelledCommon-mode protection level and total integrity envelopelunar_common_mode
Capability
cmpl_horizontal bounds the k-sigma horizontal position error contributed by the blind common-mode class, by forming blind_position_covariance = S*Cov*S^T and projecting it into ENU; integrity_envelope reports hpl_total = hpl_araim + cmpl. The distinction the pair exists to make: the RAIM/ARAIM RESIDUAL test is provably blind to range(G) errors, but the ARAIM PROTECTION LEVEL is not - its fault-free term already bounds them up to a provider URA plus nominal bias. The CMPL is therefore only the cross-provider EXCESS that a single provider per-provider URA/ISM does not overbound, and the sum is a conservative triangle-inequality bound rather than an RSS, valid only where that excess is not already inside URA.
Oracle
Analytic projector algebra checked against itself: a covariance confined to range(G) must give a positive CMPL, a covariance confined to parity space must give approximately zero, and the envelope must sum two measurement-space-orthogonal contributions. The common-mode covariance, the constellation geometry and k are representative Modelled inputs, NOT a certified budget, and no claim is made that the triangle bound is tight. NOTE ON PROVENANCE: cmpl_horizontal, blind_position_covariance and integrity_envelope are public and shipped, and their unit tests were already cited by the common-mode blindness row, but the ENVELOPE CLAIM itself carried no row - so the one caveat that keeps it honest, that the sum is a triangle bound and not an RSS, was stated nowhere in the ledger. The row registers the claim and the caveat together.
ModelledLunar joint multi-technique OD + clocklunar_combination
Capability
Batch fusion of VLBI + lunar-local range + inter-sat range to recover station+constellation positions and clocks
Oracle
Recovery of an injected simulated truth + NEES covariance consistency (internal); the underlying batch-LS estimator primitive is additionally cross-checked against Orekit 12.2 / Hipparchus Levenberg-Marquardt on identical observations (ReferenceImpl). The joint multi-technique solve as a whole stays MODELLED — the frame/VLBI sub-models are validated separately
ValidatedFisher information & Cramér–Rao observabilityfim
Capability
Fisher information M=HᵀWH, Cramér–Rao lower bound, observability rank / datum-defect null space (Moore–Penrose pseudo-inverse), and D/A/E/T-optimal experiment-design scalars from a symmetric Jacobi eigensolver
Oracle
NumPy 2.4.1 (numpy.linalg.eigh / .inv; BSD-3-Clause, LAPACK-backed) — an independent third-party authority computing the same uniquely-defined eigenvalues, σ²(XᵀX)⁻¹ Cramér–Rao covariance and GNSS dilution-of-precision factors by a different algorithm (LAPACK divide-and-conquer + LU) than Kshana's cyclic-Jacobi sweep and spectral pseudo-inverse; matched to 1e-9. The same external-library class already validates the DOP engine (vs gnss_lib_py) and the χ²/erf kernels (vs SciPy). Additionally cross-checked against the Kay (1993) closed-form CRLBs and Monte-Carlo CRLB attainment (internal)
Tests
tests/fim_observability_reference.rs (eigenvalues vs numpy.linalg.eigh; CRLB covariance vs σ²(XᵀX)⁻¹ via numpy.linalg.inv; GNSS GDOP/PDOP/HDOP/VDOP/TDOP from the information matrix vs numpy — all matched to 1e-9)…
ModelledLunar absolute-station observability (datum defect)lunar_combination (lunar_observability) + fim
Capability
Fisher-information observability of the joint lunar solve: without Earth baselines the absolute-frame datum lies in the null space of HᵀWH (station position unobservable); ≥3 baselines restore full rank and bound the station Cramér–Rao error, which the estimator attains
Oracle
Analytic datum-defect structure — the unobservable absolute-frame mode lies in the null space of the Fisher information (closed-form), the rank threshold matches the published 3-station design rationale, and the estimator attains the resulting CRLB in Monte-Carlo. The lunar geometry itself is a representative network (not a flown ephemeris), so the row stays MODELLED; the underlying FIM/CRLB engine is checked against the Kay (1993) closed forms separately
Tests
lunar_combination::tests (rank-deficient without Earth baselines; three baselines restore full rank — the 3-station threshold from the information rank, not solve error; station CRLB attained by the estimator at…
7-parameter Helmert datum fit + ICRF orientation tie from a network of points
Oracle
Independent closed-form weighted Umeyama (Horn) similarity-transform solver (numpy/scipy SVD-based; Umeyama 1991 IEEE TPAMI, Horn 1987 JOSA A) — a different algorithm from kshana's iterative Gauss–Newton fit, reaching the same uniquely-defined weighted-LS optimum on byte-identical point networks
Tests
lunar_frame_realise::tests (recovers injected Helmert transform); tests/lunar_reference_frame_realisation_reference.rs (14 cases vs an independent closed-form Umeyama-SVD solver; worst |Δ| translation 2.0e-5 m…
ValidatedLunar navigation service volumelunar_service
Capability
Moonlight-class lunar DOP / coverage / availability + generalised lunar ARAIM protection levels over a service volume
Oracle
Independent third-party authority ANISE 0.10.2 astro::Orbit Keplerian propagator (Nyx Space, MPL-2.0) — an equinoctial two-body code path distinct from kshana's Newton-Raphson Kepler; per-satellite MCI position agrees to <1e-3 m and the derived visible-satellite count/set matches exactly at every grid point. The DOP kernel is gnss_lib_py-validated; integrity uses published LunaNet/LCNS parameters
Tests
lunar_service::tests (DOP reuses the validated kernel; PL reduces to the south-pole case); tests/lunar_navigation_service_volume_reference.rs (per-satellite MCI position to <1e-3 m + EXACT visible-satellite set over…
Per-satellite topocentric look angles and slant range at a named selenographic site, and the signal-in-space ranging accuracy exposed as a scenario parameter so the service-volume sweep yields a ranging REQUIREMENT rather than a pass/fail at one fixed sigma
Oracle
Closed-form geometry whose answer is known without running the code (elevation 90 deg overhead, azimuth 0/90/270 deg due north/east/west, Euclidean slant range) plus cross-agreement with lunar_service::visible_sat_positions, which computes the same elevation through a separate expression. MODELLED: the oracle is internal. The MCI propagation and the visible-satellite SET the export is derived from are separately Validated against ANISE 0.10.2 (see the service-volume row); an external azimuth/range oracle is the outstanding upgrade for this row
Tests
lunar_service::tests (topocentric against hand-computed geometry: overhead, due north/east/west, antipodal, and the degenerate polar east direction; the exported visible flag agrees with the independent visibility…
Differential error-cancellation identity + reuse of the DO-229E SBAS PL machinery; the single-difference + WLS solve is additionally cross-checked against RTKLIB's lsq()/matinv() (Takasu, BSD-2-Clause, compiled C) — independent solver code, but the same first-order LOS-difference algebra, so still InternalConsistency
Tests
lunar_dpnt::tests (clock common-mode cancels exactly; residual grows with baseline; reuses SBAS PL; the satellite count is honoured to the builder's limit of 24, so a larger constellation cannot silently return a…
LunaNet/IOAG-aligned lunar frame + time + ephemeris export (CCSDS OEM + KIF) with round-trip conformance
Oracle
kshana's lunar OEM export re-parsed by the independent third-party oem library (R. J. Anderson): frame/time tokens and per-epoch state agree to write precision (1 mm / 1e-9 km/s) and a dropped-TIME_SYSTEM export is rejected — a structural interchange round-trip; the lunar frame/time physical semantics are validated by their own rows, so this stays MODELLED
Tests
lunar_interop::tests (OEM carries lunar REF_FRAME/TIME_SYSTEM; time metadata round-trips; KIF envelope); tests/lunar_interoperability_export_reference.rs (kshana's emitted lunar OEM re-parsed by the independent oem…
Per-dimension sub-scores over DHS RPCF categories, RethinkPNT RDRR functions and Yang criteria, each tagged Modelled with its driver; tentative RPCF Level with a bounded-degradation gate. Simulation-derived self-assessment, never certification.
Quantifies how a single composite score / RPCF Level reorders architectures under a defensible weighting simplex and a threat ensemble (top-1 flip rate, Kendall-tau dispersion, Level-flip rate, rank ranges); declared-vs-measured and diversity-collapse analyses.
Oracle
Closed-form rank-statistics identities (tau in [-1,1] with hand-computed values; deterministic seeded Dirichlet) and constructed stable/unstable witnesses
Tests
resilience::stats::tests (Kendall-tau hand example, Dirichlet simplex, flip-rate); resilience::study::tests (stability control, instability witness, declared-vs-measured, diversity collapse)
Per-result honesty ledger qualifying a demonstration output: its external anchors, modelled assumptions, gaps-to-flight and representative TRL band, with invariants enforced (Validated requires an external anchor; Modelled requires a gap and cannot claim above TRL 4).
Oracle
Closed-form invariants mapping to the 'representativeness justified + gaps-to-flight identified' compliance discipline; tied to the verification status/oracle-kind boundary
One reproducible TradeEvidence object (fixed frame: scenario+seed+engine; common per-FoM quantum-vs-classical values with polarity-correct benefit, optional 95% CI, validated/modelled label) carrying a representativeness record, so every quantum-PNT vertical reports the trade the same honest way.
Oracle
Closed-form benefit/winner identities + faithful wrap of the existing quantum_trade::TradeResult; honesty tied to the representativeness ledger and verification labels
Tests
qtrade::tests (benefit polarity higher/lower-is-better, wraps a real TradeResult faithfully, dishonest evidence rejected, validated-FoM needs external anchor, deterministic JSON)
Device cards (optical/trapped-ion/mercury-ion + classical clocks reused from holdover/clock_state; cold-atom interferometer; classical + entanglement/single-photon time-transfer links) each carrying a representativeness record; the entanglement link adds a shot-limited timing-precision model (~jitter/sqrt(R*tau), dark-count penalty, systematic floor).
Oracle
Reused clock/CAI coefficients (holdover/clock_state, published values) + closed-form shot-noise/loss identities for the entanglement link
ModelledTrusted quantum timing (time transfer + secure dissemination + anomaly)timetransfer_chain
Capability
End-to-end quantum vs classical time-transfer chain (clock coast + link precision in quadrature), a reused timing protection level, a delay/replay-attack security FoM (1-P_md) and a clock-anomaly detection probability + CUSUM latency, emitted as honest TradeEvidence with a representativeness record.
Oracle
Closed-form quadrature budget over reused validated kernels (ADEV vs Stable32/NIST; TPL bound; detection analytic_pd/pmd); honesty tied to the representativeness ledger
Tests
timetransfer_chain::tests (precision improves with integration; quantum can win AND lose; PL finite-positive; security FoM in [0,1] and grows with attack delay; anomaly Pd monotone; trade is_honest)
Quantum (cold-atom interferometer) vs classical navigation-grade INS dead-reckoning over a GNSS outage: position-error growth, holdover to a position threshold, and the quantum-vs-classical trade as honest TradeEvidence; honest observability note (bias unobservable without a fix, so error grows).
Oracle
Reused inertial budgets cross-checked against an independent Octave double-integration of the same dead-reckoning ODE (different runtime, shared model → ReferenceImpl) plus the Freier-2016 published short-term noise as a one-sided anchor; the quantum-vs-classical composite stays MODELLED
Tests
quantum_nav_od::tests (quantum beats classical over a long outage; advantage is outage-dependent; trade is_honest); tests/gnss_free_quantum_navigation_reference.rs (dead-reckoning position growth vs an independent…
ModelledFault/anomaly detection for quantum PNT systemsquantum_faults
Capability
Labelled quantum-fault catalog (clock frequency-jump/drift/lock-loss; sensor bias-step/dropout), a detection-statistic ROC AUC with a bootstrap CI, and a minimum-detectable fault at a fixed false-alarm rate; a quantum-clock-aided monitor detects smaller faults than a classical one, emitted as honest TradeEvidence.
Oracle
Closed-form Gaussian AUC = Phi(mu/(sigma*sqrt2)) cross-checked against the externally-validated eval_stats::bootstrap_auc_ci (vs scikit-learn) + detection analytic thresholds
Tests
quantum_faults::tests (analytic AUC known values; empirical bootstrap AUC brackets the closed form; quantum detects smaller faults / higher AUC; advantage vanishes for huge faults; 5-class catalog; trade is_honest)
Euler's rotational equations of motion (I ω̇ = τ − ω × Iω, principal-axis and general inertia tensor) coupled to quaternion attitude kinematics (q̇ = ½ q ⊗ ω) and propagated with a fixed-step RK4 integrator that re-normalises the quaternion each step
Oracle
Physical conservation laws of the free rigid body (quaternion-norm, rotational kinetic energy, body-frame and inertial angular-momentum) plus the closed-form symmetric-top body-cone precession rate (Goldstein §5.6–5.7; Wertz §16) — these are self-consistency invariants the integrator must preserve, NOT an external dataset, so the row stays InternalConsistency. MODELLED first-principles dynamics — no flexible-body / control-loop / external-torque environment
Tests
attitude_dynamics::tests (apply/solve inverse, spherical-top zero torque, principal-axis fixed point, short-run energy+momentum conservation, q̇=½q⊗ω, symmetric-top rate sign + body-cone precession)…
ModelledClohessy–Wiltshire / Hill relative-motion dynamicscw_dynamics
Capability
Linearised relative motion of a chaser about a target on a circular reference orbit in the LVLH frame (ẍ−2nẏ−3n²x=0, ÿ+2nẋ=0, z̈+n²z=0), solved by the closed-form 6×6 state-transition matrix Φ(n,t) (Clohessy–Wiltshire 1960; Vallado Alg. 48), with the bounded relative-orbit condition ẏ₀=−2n·x₀
Oracle
The closed-form CW state-transition matrix cross-checked against an independent numeric integration of the same linearised equations of motion, plus the analytic relative-orbit invariants (time-reversibility Φ(t)Φ(−t)=I, the −2n·x₀ bounded-orbit condition, the −12π·x₀ per-orbit secular drift, decoupled cross-track SHM) — self-consistency checks of the linear dynamics, NOT an external dataset, so the row stays InternalConsistency. MODELLED linear relative motion on a circular reference orbit — no eccentricity (Tschauner–Hempel), J2, or differential-drag terms
Tests
cw_dynamics::tests (Φ(0)=I, cross-track decoupled SHM); tests/cw_dynamics_reference.rs (closed-form Φ vs an independent fixed-step RK4 integration of the same Hill ODEs to <1e-6 over a third of an orbit; Φ(t)Φ(−t)=I to…
Locate an emitter (jammer/spoofer, or an opportunistic source for reverse-PNT) from time-difference-of-arrival across a receiver network — the τᵢ=(Rᵢ−R₀)/c hyperboloid intersection solved by Gauss–Newton least squares — and, adding frequency-difference-of-arrival (range-rate differences) with moving receivers, jointly recover position and velocity; with the Cramér–Rao lower bound on the position covariance from the measurement geometry
Oracle
Self-consistency of the estimator and geometry: forward→inverse round trips, the Fisher/CRLB identity J·CRLB=I, GDOP monotonicity, and the estimator attaining its own Cramér–Rao bound under Monte-Carlo noise — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED passive geolocation — point-source line-of-sight model; no multipath / NLOS, receiver-clock-bias, or atmospheric-refraction terms
Tests
geolocation::tests (noiseless TDOA forward→inverse to 1e-6 m; J·CRLB=I with a symmetric PD covariance; the CRLB position-variance trace is non-increasing when a receiver is added; joint TDOA+FDOA recovers a moving…
Optimal three-axis attitude from weighted vector observations (star/sun/magnetometer directions): the deterministic two-vector TRIAD, Davenport's q-method (the exact Wahba-loss minimiser — the optimal quaternion is the largest-eigenvalue eigenvector of the 4×4 Davenport matrix K, solved by a symmetric Jacobi eigensolve), and QUEST (Newton/secant root of K's characteristic equation seeded at Σ weights, then Gibbs-vector quaternion recovery)
Oracle
scipy.spatial.transform.Rotation.align_vectors (SciPy 1.13; Virtanen et al., Nature Methods 2020) — the Kabsch/Markley SVD solution of Wahba's problem, a genuinely independent algorithm (SVD of the attitude profile matrix) and codebase from kshana's Davenport-K eigensolve / QUEST characteristic-root method, computing the SAME uniquely-defined Wahba-optimal attitude. On noiseless weighted vector-observation sets TRIAD, the q-method and QUEST reproduce scipy's optimal rotation to <1e-9 rad (compared via the sign-invariant attitude-error angle). The noisy Monte-Carlo 'optimal beats TRIAD' statistical claim stays MODELLED (no external oracle); point-direction unit-vector observations only — no sensor field-of-view/bias/temporal-correlation modelling, and QUEST is singular at 180° (the q-method covers that case)
Tests
wahba::tests (A(identity quaternion)=I; the Jacobi eigensolver satisfies Kv=λv and preserves the trace on a known symmetric matrix; K is symmetric); tests/wahba_reference.rs (TRIAD, Davenport's q-method and QUEST…
Square-law (non-coherent) acquisition detector over a code-phase × Doppler search: false-alarm probability (central χ² with 2M dof), the threshold achieving a target P_fa (χ² CDF inverted by bisection), and detection probability (non-central χ² with non-centrality 2M·ρ for per-cell post-correlation SNR ρ), with the generalized Marcum Q-function Q_M(a,b)=1−F_{χ'²(2M,a²)}(b²)
Oracle
scipy.stats.ncx2 / scipy.stats.chi2 (SciPy 1.13; Cephes/Boost) — an independent algorithm (continued-fraction non-central/central χ²) from kshana's incomplete-gamma series (raim::chi2_cdf / noncentral_chi2_cdf), computing the same uniquely-defined detection-statistics KERNEL: the generalized Marcum Q_M(a,b)=ncx2.sf(b²,2M,a²), the detection probability P_d, the false-alarm probability P_fa and the P_fa→threshold inversion, matched to ~1e-6 — the same independence basis as the Validated 'RAIM/ARAIM integrity statistical kernel' row. KERNEL only: the per-cell CFAR cell-averaging and code/Doppler-bin straddling loss stay MODELLED
Tests
acquisition::tests (Marcum-Q central case Q_1(0,b)=exp(−b²/2); the P_d=Q_M(√(2Mρ),√γ) identity; P_fa↔threshold round-trip across M and P_fa; ROC monotonicity — P_d rises with SNR, falls with threshold, P_d→P_fa as…
Integer least-squares ambiguity fixing the LAMBDA way: a volume-preserving integer (Z) decorrelating transform (integer-Gauss size reduction of the L D Lᵀ factor) + an exact Schnorr–Euchner depth-first branch-and-bound integer least-squares search + the closed-form bootstrapped success rate P_s=∏(2Φ(1/(2σ_{i|I}))−1), with the ratio test on the two best candidates
Oracle
Self-consistency of the integer estimator: the Z-transform invariants (unimodularity, congruence, determinant), the EXACT ILS verified against independent brute-force enumeration, and the bootstrapped success rate verified against a Monte-Carlo of the rounding process it models — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED integer-Gauss decorrelation (the conditional-variance reordering permutations of the full LAMBDA reduction are out of scope; they speed the search but change neither the exact ILS answer nor the bootstrapped rate)
Tests
lambda::tests (L D Lᵀ reconstructs Q); tests/lambda_reference.rs (the Z-transform is unimodular |det Z|=1 with Q_z=ZᵀQZ SPD, det-preserving, and lower total off-diagonal correlation; the Schnorr–Euchner ILS matches…
Hyperbolic-flyby geometry (a=−μ/v∞², e=1+r_p·v∞²/μ, turn angle δ=2·asin(1/e), impact parameter |B|=|a|·√(e²−1)), the B-plane Ŝ/T̂/R̂ aim-point frame and B·T̂/B·R̂ decomposition, and a patched-conic gravity assist (v∞-magnitude conserved, direction deflected by δ, heliocentric Δv=2·v∞·sin(δ/2) at no propellant cost) with the Tisserand parameter T_P=a_P/a+2√((a/a_P)(1−e²))cos i
Oracle
Self-consistency of the flyby geometry and the patched-conic invariants: the hyperbolic closed forms, the B-plane orthonormal decomposition, v∞ conservation, and Tisserand invariance (cross-checked two ways — invariance across the deflection and the v∞ link) are analytic identities checked against the engine's own state→element conversion — internal-consistency checks, NOT an external dataset, so the row stays InternalConsistency. MODELLED patched-conic two-body flyby on a circular planetary orbit — no finite-sphere-of-influence transition, encounter third-body perturbations, or ephemeris
Tests
bplane::tests (the flyby scalars satisfy the closed forms with two agreeing |B| identities and |B|>r_p; the turn angle decreases with periapsis radius and hits the δ→0 / δ→π limits; deflection preserves v∞ speed and…
ValidatedCRPA anti-jam array beamformingcrpa
Capability
Controlled-reception-pattern antenna nulling: complex array steering vectors a(û)=exp(j·k·pₙ·û), deterministic null-steering (unit gain toward the SV, exact nulls toward up to N−1 jammers via the minimum-norm w=Aᴴ(AAᴴ)⁻¹b), and MVDR adaptive weights w=R⁻¹a_sv/(a_svᴴR⁻¹a_sv) that self-steer deep nulls onto strong interferers (with a from-scratch complex linear-algebra kernel)
Oracle
numpy.linalg / scipy.linalg (LAPACK zgesv complex solve) — an independent linear-algebra codebase from kshana's from-scratch complex kernel, computing the SAME uniquely-defined weights: MVDR w=R⁻¹a_sv/(a_svᴴR⁻¹a_sv) and minimum-norm null-steering w=Aᴴ(AAᴴ)⁻¹b, plus the resulting array-response gains, matched to ~1e-9 — the same class of oracle as the Validated DOP (gnss_lib_py) and Fisher-information (numpy) rows. MODELLED narrowband far-field identical-isotropic-element array — no mutual coupling, per-element mismatch, finite-bandwidth (STAP), or steering-vector estimation error
Tests
crpa::tests (complex arithmetic identities incl. z/z=1, |exp(jθ)|=1, zᴴz=|z|²; deterministic null-steering gives exact unit SV gain and <1e-9 jammer nulls on a 4-element ULA with 3 jammers; an N-element array rejects…
The five-coefficient IEEE-1139 PSD↔Allan-variance conversion S_y(f)=Σh_α f^α → σ_y²(τ) (white/flicker PM, white/flicker/random-walk FM), the flicker-FM floor σ_y=√(2 ln2·h_{-1}) as a first-class fittable term, and a non-negative FM-family fit in the {(2π²/3)τ, 2 ln2, 1/(2τ)} basis that recovers the floor the drift basis {1/τ,τ,τ³} cannot represent
Oracle
allantools 2024.06 (A. Wallin; Kasdin & Walter 1992 / Vernotte 2015 coefficients) — an independent third-party codebase and citation lineage computing the SAME uniquely-defined IEEE-1139 PSD→Allan conversion σ_y(τ) for each of the five power-law noise types. kshana's powerlaw::allan_deviation matches the allantools closed forms (white/flicker-FM, RW-FM and white-PM to <5e-9 relative; flicker-PM to ~1e-5 — the genuine independence signal, kshana using the NIST-SP-1065 tabulated 1.038 constant vs allantools' full 3γ−ln2), and the flicker-FM floor √(2 ln2·h_{-1}) matches allantools across the ladder — the same bar the Validated MDEV/TDEV/Theo1/MTIE rows clear. MODELLED stationary power-law model — no deterministic-drift (τ²) term; per-device coefficients / measured floors stay Modelled
Tests
powerlaw::tests (each pure noise type shows its signature ADEV log-log slope — white FM −½, flicker FM 0, random-walk FM +½, white PM −1; the flicker-FM term is a flat floor equal to √(2 ln2·h_{-1}) across five decades…
Serialise and parse the CCSDS 502.0 OEM COVARIANCE_START…COVARIANCE_STOP block — the 6×6 position/velocity covariance written as its 21-element lower triangle (canonical CX_X … CZ_DOT_Z_DOT order) with the optional COV_REF_FRAME, complementing the existing OEM state-vector writer/parser so orbit-determination and filter covariances round-trip in the standard format
Oracle
oem 0.4.5 (Brad Sease, MIT) — the SAME independent CCSDS-502 parser trusted by the Validated 'CCSDS OEM interoperability' row, a completely separate codebase (its own KVN tokenizer, covariance-section state machine and numpy matrix assembly). kshana emits a full OEM segment carrying its unlabelled bare-number lower-triangular COVARIANCE block; oem parses it and reconstructs the symmetric 6×6, matching kshana's input covariance element-for-element to f64 round-off — a genuine library-vs-library interchange round-trip (compared against oem's reconstruction, not a kshana re-parse), closing the row's previous 'no third-party fixture' gap
Tests
oem::tests (a symmetric PD covariance round-trips KVN→parse to f64 round-off and stays symmetric; the block emits exactly the 21 lower-triangular entries — i+1 per matrix row — with/without COV_REF_FRAME; a block with…
Position-error-vs-coast-duration budget built from IMU coefficients — accelerometer bias (t²), gyro-bias tilt through gravity (t³), velocity random walk (t^1.5), angle random walk (t^2.5) and scale factor times the travelled distance (t¹ cruising, t² under sustained specific force) — combined under a stated rule (rss / linear-sum / deterministic-sum-with-stochastic-rss), with the coast durations reaching caller-supplied position thresholds (10 m and 50 m by default) located by bisection, a per-contribution breakdown naming the dominant source at each crossing, and a TRN-bounded mode giving the largest terrain-fix interval that holds each threshold. Runnable as the ins-trn-coast scenario kind
Oracle
Two in-codebase routes that never see this module's algebra. (1) inertial::AccelModel, the engine's step-by-step stochastic dead-reckoner, integrated forward at dt = 0.01-0.05 s: deterministic for the bias and gyro-bias channels (agreeing to the Euler truncation, rel < 2e-4 and < 1e-3), and Monte-Carlo over 300 fixed seeds for the velocity- and angle-random-walk channels, whose sample RMS reproduces σ_vrw·t^1.5/√3 and g·σ_arw·t^2.5/√20 to rel < 0.10 (the sampling error of an RMS over 300 seeds is ~4%). The simulator only ever adds a white increment per step; it has no knowledge of the t^1.5 or t^2.5 laws, so this is a different route to the same number, not the same expression restated. (2) inertial::imu_errors::ImuErrorModel::distort double-integrated over an accelerate-then-cruise profile, reproducing s×(travelled distance) to rel < 2e-3 without ever multiplying a distance by a scale factor. Separately, and labelled a COMPATIBILITY check rather than an oracle, the model reduces bit-close (rel < 1e-12) to quantum_trade::ClassicalInsBudget when the gyro channels are off and the platform is under sustained specific force — that shares the expression and so cannot fail with it; it is there to prove no second, divergent error model was forked. Threshold crossings are located by the engine's existing bisection (quantum_trade::PositionDrift::inertial_holdover_s) and each single contribution's crossing is additionally inverted algebraically, the two agreeing to rel < 1e-15. The IMU class coefficients (navigation/tactical/industrial/consumer) are representative Groves 2013 Table 4.1 BAND figures and stay MODELLED, as does the TRN fix residual, which is a documented input. No external reference dataset of coasted position error exists in the tree and none was fetched: promoting this row to Validated needs a logged inertial dataset with position truth propagated through an independent strapdown navigator
One run takes a contact plan (a list of aos_s/los_s windows, each asking the aperture for navigation or communications — the same window vocabulary passes::predict_passes emits, converted by aperture_duty::windows_from_passes), an aperture count and an explicit arbitration policy, and returns the navigation duty, the communications duty, the idle duty and the per-session outage. The policy is an input with a documented default (navigation-priority; also communications-priority and non-preemptive first-come-first-served), and the report carries the resolved policy, its full definition and the duty and outage definitions, because a duty figure quoted without its arbitration rule is not reproducible. The schedule is an exact interval sweep over the window boundaries, so a window that ends exactly where the next begins never contends, and navigation, communications and idle aperture-seconds are accumulated independently in that one sweep. Runnable as the aperture-duty-cycle scenario kind
Oracle
Internal consistency, from three quantities computed by different expressions in the same sweep and then required to close. Navigation aperture-seconds, communications aperture-seconds and idle aperture-seconds are accumulated separately — idle from (apertures − |served|) per elementary interval, never as a remainder — and their sum is asserted against apertures × horizon_s, which a mis-bracketed boundary, a double-counted interval or a dropped one breaks immediately; the per-session served times are separately required to add back to the two service totals. The scheduler's structural properties are measured rather than assumed: served time is asserted non-decreasing in the aperture count over 200 pseudo-random plans for all three policies (not obvious for the non-preemptive policy, where an extra aperture changes who holds what at every later boundary), and the boundary arithmetic is pinned at the touching/one-second-overlap pair where an off-by-one would otherwise hide. The pass-predictor bridge is checked against passes::predict_passes output: with one aperture and no competing service the navigation aperture-seconds equal the predictor's own summed pass durations. No external oracle is claimed and none exists: the capability supersedes hand arithmetic rather than being checked against it, the bundled contact plan is illustrative rather than flown, and no operational scheduler publishes a plan-plus-answer pair with its arbitration rule stated — a duty computed under an unstated policy is not comparable to one computed under a stated one, and the policy dependence is measured (navigation duties of 100/150 vs 50/150 on the identical plan). Slew and changeover time, data volume, buffer state, energy and link closure are excluded in the report label rather than silently modelled
Tests
aperture_duty::tests (a window that ends exactly when the next begins does not contend, and moving it one second earlier costs exactly one second — the off-by-one guard; overlapping windows beyond the aperture count…
Lunar-native jammer-to-signal ratio, effective C/N₀ and loss of lock for a selenographic surface user under a lunar surface (or raised) jammer, over the illustrative public-source Moonlight/LCNS-class constellation. Composes the open jamming chain (j_over_s_db, effective_cn0_dbhz, rx_antenna_gain_db, lock_status, q_factor, nominal_cn0_dbhz, free_space_path_loss_db) with the open lunar sky geometry (lunar_service::LunarConstellation + topocentric, lunar::selenographic_to_mcmf); no geometry or radiometry is re-derived. Unlike the Earth jamming kind the signal leg is not a fixed received power: each satellite's isotropic received power is its own link-budget EIRP − FSPL(slant range), so J/S varies satellite by satellite with lunar range and elevation. Emits ONE ROW PER VISIBLE (epoch, satellite) LINK as JSON and as a *.table.csv artifact, with both received powers the J/S is the difference of printed alongside it; aggregate figures of merit sit beside that table, never in place of it. Runnable as the lunar-jamming scenario kind
Oracle
Composition cross-check against an independent in-repo code path: every per-link J/S is re-derived as the difference of two link budgets computed with linkbudget::received_signal_power_dbw, whose free-space loss is the single expression 20·log10(4πRf/c) rather than the three-term sum jamming::free_space_path_loss_db uses — the two agree to < 1e-9 dB on every row (measured worst case 7.11e-14 dB, i.e. float round-off). The underlying interference chain it composes is separately externally anchored in tests/gnss_denied_jamming_resilience_reference.rs (independent numpy/scipy re-derivation of J/S and effective C/N₀ pinned to Kaplan & Hegarty §9.4, plus JammerTest 2024 measured C/N₀, Zenodo 10.5281/zenodo.15910563); the lunar geometry it composes is the lunar_service/lunar geometry with its own oracles. Closed-form identities checked here: a halved jammer standoff adds exactly 20·log10(2) dB to every row; J/S is exactly invariant to the user-antenna boresight gain while C/N₀ moves by exactly that gain; an elevation mask changes no surviving row bit-for-bit. The row itself stays ReferenceImpl/Modelled: no measured lunar jamming campaign exists to validate against, and the constellation is an illustrative public-source Moonlight/LCNS-class geometry, not a flown ephemeris
ModelledLunar denial contour with an uncertainty band from the measured C/N₀ spreadlunar_jamming (denial_js_db,range_for_free_space_path_loss_m,Cn0Distribution,DenialContourPoint,ContourBand,DenialContour; inverting jamming::effective_cn0_dbhz,jamming::j_over_s_db and jamming::free_space_path_loss_db)
Capability
The lunar-jamming report no longer rests its denial contour on one scalar. It emits the full measured wanted-signal C/N₀ distribution over the per-satellite table — n, min, p05, p25, median, p75, p95, max, mean, sample stdev, and the sample's own asymmetry (p95 − median) − (median − p05) — beside the per-link rows, which are unchanged. The contour is then reported at each of those order statistics under BOTH denial criteria the engine recognises, never one in place of the other: the incumbent power-ratio criterion (J/S = 30 dB, the same threshold attack_surface and tracking_loop use, and the criterion behind the released lunar link-jamming table's denial column), and the loss-of-lock criterion (the effective C/N₀ falling to tracking_threshold_dbhz), which is the criterion this report's own links[].status column is scored with. Each contour point is given on both axes of the denial plane — the jammer EIRP required at the scenario's standoff, and the denial standoff at the scenario's EIRP — so the band is an interval on the same axes a contour plot is drawn on. The band edges ARE contour(p05) and contour(p95): the same closed-form map applied to the sample's own quantiles, not a sigma fitted to the sample and not median ± k·stdev, and the report says so in a band_definition string beside the numbers. stdev is emitted for continuity and is used by nothing. A quantile whose C/N₀ is already at or below the tracking threshold has no finite denying J/S; those columns are emitted as null with a counted reason rather than as an infinity or a clamped radius
Oracle
Internal consistency against the engine's own forward functions, which is all this capability can honestly claim. Every contour point is a closed-form inversion, and each inversion is checked by pushing its answer back through the FORWARD function the report's own rows were scored with: the J/S column through jamming::effective_cn0_dbhz (which must return tracking_threshold_dbhz to < 1e-9 dB-Hz), the standoff column through jamming::free_space_path_loss_db and jamming::j_over_s_db (the same J/S to < 1e-9 dB), the EIRP column through jamming::j_over_s_db at the scenario's own standoff. The contour is further checked to be the BOUNDARY of the denial set rather than a point inside it — lock_status loses lock on a strict inequality, so the verdict is measured to flip from DEGRADED to LOST across 1e-4 dB of J/S either side of the contour, which an off-by-an-epsilon contour would fail. The strongest check is per-link rather than per-quantile: applying the same map to every row's own C/N₀ reproduces the report's status column exactly — 0 disagreements on 38 of 38 rows at the documented operating point (kind = lunar-jamming, every input default except jammer.range_m = 25 000 m), where 26 rows are LOST and 12 are not. Monotonicity is measured, not assumed: 20 001 samples across [tracking_threshold + 1e-3, 80] dB-Hz, 0 violations of a strictly decreasing standoff and a strictly increasing required power, so the quantile ordering of the band is demonstrated rather than asserted. ExternalDataset is declined and Validated with it: no measured lunar jamming campaign exists to compare a denial radius against, the constellation is an illustrative public-source Moonlight/LCNS-class geometry rather than a flown ephemeris, and the contour's inputs (EIRP, jammer power, antenna gains, noise temperature) are representative magnitudes. ReferenceImpl was considered and declined too — the inverse and the forward expression are the SAME algebra read in two directions, so the round trip catches transcription and sign errors but is not an independent implementation; calling it a cross-check would be the borrowed-independence move the matrix invariants exist to prevent. What the band buys is measured and quoted rather than asserted: at that operating point the single-scalar contour is 27.402916 km and puts 25 km on the denied side for all 38 rows, while the band 21.256108 .. 29.921360 km contains the operating point and therefore reports the split the table actually shows. The two criteria are also measured to disagree — the power-ratio band (38.186527 .. 53.691675 km) does not contain 25 km at all — which is why both are printed
The hybrid-optical-rf report states what the cross-modality chi-square monitor can actually DETECT, not only that it passes a fault-free case: the minimum detectable bias per monitored axis (east, north, up, clock) at the scenario's stated false-alarm and missed-detection probabilities, the detection-power curve either side of it, the noise-free bias multiple at which the realised statistic first crosses the threshold, and the time-to-detect for a bias ramp at a stated rate. Faults are also injected through the real monitor and the statistic it returns is reported alongside the analytic prediction
Oracle
Two internal oracles, no external dataset. (1) Closed-form round trip: the minimum detectable bias is produced by inverting the non-central chi-square tail on the non-centrality (raim::pbias) and is verified by feeding the resulting non-centrality back through raim::noncentral_chi2_cdf at the monitor's own threshold, which must return P_md. (2) Injection vs analysis: a bias is written into the RF estimate of one axis and cross_raim::run_cross_raim is re-run, so the statistic compared against the analytic non-centrality is the one the monitor computed, not a re-derivation. A seeded Monte-Carlo of the statistic itself is carried in the tests as a third check; it is deliberately NOT in the report, because a sampled estimate would be slower and not reproducible bit-for-bit. ExternalDataset is declined: the quantity is the detection power of THIS monitor at THIS scenario's sigma allocation, and the sigma magnitudes the MDB is scaled by are Modelled representative inputs, not measurements. ReferenceImpl was also considered and declined — the Monte-Carlo samples the same statistic the analysis describes, so it catches transcription and coefficient errors but is not an independent implementation of the monitor
Tests
hybrid_integrity::tests (the detection-power curve runs from the false-alarm rate at zero fault to 1 − P_md at the minimum detectable bias; the minimum detectable bias fed back through noncentral_chi2_cdf at the…
ModelledPost-handover covariance re-growth against the alert limithybrid_integrity
Capability
The hybrid-optical-rf report exposes the filter's process-noise model and states how long the post-handover solution stays inside the alert limit: for both handoff directions it carries the per-axis covariance the handover left behind, propagates it forward under a stated random-walk process noise, and reports the time at which the coverage-scaled 1σ reaches the horizontal, vertical and timing alert limits, which limit binds first, the variance doubling time constant, and a sampled coast profile that brackets the crossing. Process-noise PSDs, the coverage factor and the alert limits are all inputs with documented defaults
Oracle
No external oracle. The crossing is a closed-form solution of the random-walk variance growth, and the tests recompute it independently from the values the report itself publishes rather than from the emitter's internals. The starting covariance is pinned bit-for-bit to the trace the existing handoff block already reported, so the coast cannot propagate a covariance nobody else saw. The process-noise PSDs are MODELLED representative inputs and the crossing times scale directly with them, which the scaling test states as a measured property rather than a claim. ExternalDataset is declined deliberately: the coast time is a direct function of two Modelled PSDs and of alert limits that are themselves representative, and there is no measured lunar optical/RF handover coast to compare against. An external oracle here would need a published post-handover covariance-growth or holdover-accuracy curve for a comparable receiver with its process-noise model stated, checked to a tolerance
Tests
hybrid_integrity::tests (the coast starts from exactly the covariance trace the handoff block reports, for both directions, so the replayed diagonal cannot drift from the reported handover; the reported crossing time…
ModelledOff-boresight antenna pattern in the lunar geometry exportlunar_service,antenna
Capability
The per-satellite geometry export carries, per (epoch, satellite), the off-boresight angle AT THE SATELLITE and the transmit gain toward the site from the real uniformly-illuminated circular-aperture (Airy) pattern, and reports the in-beam count under that pattern BESIDE the in-beam count under the symmetric gain-to-beamwidth approximation (θ_3dB[deg] = √(31000/G_lin)), with the difference emitted as an explicit correction in links, in satellites per epoch, and as the worst single epoch. Both implied aperture efficiencies of the approximation are emitted (0.641 against the 70·λ/D degrees rule it is quoted with, 0.920 against a uniform circular aperture) so the efficiency it silently assumes is stated rather than inferred. Off by default: the block appears only when an export site and an aperture are both given
Oracle
Mixed, and separated rather than pooled. The PATTERN underneath is externally validated and keeps its own row (a scipy.special.j1 fixture to < 0.05 dB in tests/validate_p1_orbital_footprint.rs, plus here the published Airy half-power abscissa x = 1.61634 located by bisection rather than assumed). The GEOMETRY is checked against closed-form triangle trigonometry written as a different expression from the dot product under test. The CONTAINMENT of the real beam by the approximate cone is derived algebra (28.019/√η vs 29.479 degrees per λ/D), so the correction can only be non-positive for η ≤ 0.9035. But the in-beam COUNTS themselves have no external oracle: no published table gives how many satellites of a Moonlight/LCNS-class shell hold a south-polar site inside a given dish's half-power beam, and the constellation is an illustrative public-source approximation, not a flown ephemeris. The measured disagreement at the documented working point — 0 links in beam under the real pattern against 28 under the approximation, −2.33 satellites per epoch, worst epoch 3, on 76 evaluated links — is therefore a MODELLED finding about the approximation, pinned as a regression literal (the nearest row sits 0.069° from either beam edge, four orders of magnitude above any last-digit disagreement), not an externally validated coverage number. Labelling the row ExternalDataset on the strength of the pattern's own external anchor would be borrowed validation, which is the move the matrix invariants exist to prevent
Tests
antenna::tests and lunar_service::tests (the half-power crossing located by bisection on the pattern matches the published Airy x = 1.61634 and yields the exact 1.02899·λ/D width, recording that the conventional 1.02…
ModelledTracking-loop loss of lock and spoof pull-in under interferencetracking_loop (composing sdr,jamming)
Capability
Loss of lock computed from loop dynamics instead of a power ratio: carrier (Costas) and code (non-coherent early/late) 1σ thermal jitter against C/N₀ with the squaring loss, against the stated rules 3σ_PLL + θ_e ≤ 45° and 3σ_DLL + ramp lag ≤ d/2 chips; drop and re-lock C/N₀ thresholds with the binding loop named and the hysteresis DERIVED from the wider pull-in bandwidth rather than asserted; the declared time to lose lock from a two-threshold lock detector with confirmation dwells, reported separately from the physical phase-escape time (Viterbi mean time between cycle slips, in log₁₀ s because it spans hundreds of decades); the largest code slew and carrier Doppler rate the victim's loops can follow; and the DENIAL RADIUS the loop dynamics imply reported alongside the existing power-ratio radius with their signed difference as its own named field. Runnable as the tracking-loop scenario kind
Oracle
The engine's own sdr correlator (sdr::correlate / synth_if / CaCode) stepped forward on seeded synthetic IF at a calibrated C/N₀ — a separate code path reaching the same numbers by numerical correlation of sampled IQ rather than by an algebraic jitter expression, so it is a different route and not a restatement — plus standard tabulated modified-Bessel I₀ values for the cycle-slip term. Loop theory per Kaplan & Hegarty ch. 8 and Viterbi/Gardner for the slip time. The row stays ReferenceImpl/MODELLED: the cross-check lives in this same codebase, and the bessel_i0 check validates one special function rather than the tracking model, so promoting the row on that basis would be self-serving labelling. ExternalDataset would need a recorded raw-IF dataset with ground-truth C/N₀ and an annotated loss-of-lock instant (TEXBAT/OAKBAT class); none ships in this tree, and even with the IQ those datasets publish no per-epoch loop-state truth, so a declared loss-of-lock time could only be validated against some other receiver's lock detector, which is a modelled choice and not an oracle. The loop bandwidths, integration time, correlator spacing, pull-in ratio, dwells, jammer power and antenna gains are representative band figures, not a datasheet
Tests
tracking_loop::tests (open-loop Costas discriminator jitter against sdr::correlate stepped forward on seeded synthetic IF, 3 pooled noise realisations × 900 epochs, agreeing to 0.63% over 35-45 dB-Hz, with the…
ModelledLunar-VLBI station-coordinate covariance from a tracking schedulelunar_vlbi_fim (composing lunar_vlbi,fim,cio,lunar_frame,frames)
Capability
Delay partials accumulated over a schedule of baselines × epochs into a Fisher information matrix, inverted to the station coordinate covariance and the per-coordinate station sigma, replacing an assumed isotropic equipartition link from a scalar delay precision. The state carries Earth-fixed (ITRS) station coordinates, so the Jacobian is the inertial partial rotated by each epoch's GCRS→ITRS matrix and Earth rotation is what makes those coordinates observable — the report MEASURES the Earth-fixed line-of-sight sweep and the beacon declination rather than assuming them. Rank, datum defect, condition number, the information spectrum and the free-network null space are emitted on every run, and under a rank deficiency the headline sigma is published as NULL with a status rather than read out of a near-singular inverse. The equipartition value c·σ_τ·√(g/N) for the SAME schedule is printed beside the computed one with their ratio, together with the isotropic trace bound √(p/trace(M)) that AM-HM makes a hard floor. Runnable as the lunar-vlbi-fim scenario kind
Oracle
An independent in-repo route. Every Jacobian row is re-derived by central finite difference of lunar_vlbi::vlbi_delay_s evaluated from the state's own Earth-fixed and Moon-body-fixed coordinates rotated forward through the frame chain — a path that computes no derivative and shares no expression with the analytic partials — and the information matrices the two routes build agree to < 1e-6 of the largest diagonal. The linear-algebra kernel this composes (information_matrix, crlb, sym_eig) is separately externally anchored against numpy.linalg.eigh / numpy.linalg.inv in tests/fim_observability_reference.rs, and the delay observable carries lunar_vlbi's own delta-DOR far-field oracle; the row does not borrow either status. Closed-form identities checked here and labelled as such: σ² and 1/N scaling, and √(p/trace(M)) as an AM-HM lower bound the computed sigma cannot beat, which coincides with the equipartition value only on an isotropic geometry — which is why the measured ratio is exactly the anisotropy the assumption discarded. The row stays ReferenceImpl/MODELLED: no published lunar-VLBI schedule-plus-covariance pair exists to validate against, the station coordinates and beacon site are illustrative rather than surveyed, and the Moon-centre ephemeris, station clocks, troposphere and Earth-orientation parameters are held FIXED while a real session co-estimates them with correlated scan noise, so the covariance is a Cramér-Rao bound for a reduced parameter set and is optimistic in its own right. An IVS SINEX covariance would not be comparable without that co-estimation
Tests
lunar_vlbi_fim::tests (24 lib tests: the analytic Jacobian against a central finite difference of lunar_vlbi::vlbi_delay_s taken through a route that rotates the state's own coordinates forward and never touches a…
ModelledLunar-surface-point coordinate covariance from a VLBI delay schedule, kept distinct from the Earth-station onelunar_vlbi_fim (composing lunar_vlbi,fim,cio,lunar_frame,frames)
Capability
A third datum choice, all-stations-fixed, that holds every Earth station and estimates the BEACON's Moon-body-fixed coordinates alone — the configuration a lunar surface-point uncertainty is actually quoted for, since Earth station coordinates are an input to the delay model rather than an unknown of it. It exists because the station-level covariance and the surface-point covariance are DIFFERENT QUANTITIES separated by the lever arm ρ/B, and nothing previously stopped one being quoted against the other. The emitted beacon_link block carries ρ, the longest baseline, the lever arm, the surface-point form of the equipartition link c·σ_τ·(ρ/B)·√(g/N), the computed per-coordinate beacon sigma and their ratio — the ratio null rather than misleading whenever the beacon is unestimated or the matrix rank-deficient. B is taken as the LONGEST baseline present, the most favourable one, so the ratio can only understate. Runnable as datum = "all-stations-fixed" with estimate_beacon = true, which is refused with a message naming the missing input when the beacon is not estimated
Oracle
Closed-form identities, with no external oracle claimed or available. The lever arm is checked against ρ/B and the two equipartition forms against each other to 1e-15 — algebraic identities, so they catch a wiring error and nothing else, and are labelled as such. The substantive result is MEASURED rather than asserted: a delay from a fixed baseline constrains the beacon's DIRECTION, so the line-of-sight component reaches the information matrix only through the near-field range term, and the test reads the resulting anisotropy off the emitted spectrum instead of deriving it. AM-HM makes √(p/trace(M)) a hard floor, so an isotropic-equipartition link can only ever UNDERSTATE, and the computed-over-equipartition ratio is exactly the anisotropy it discarded. MEASURED on the Goldstone-like/Canberra-like pair whose chord is 10726.748 km: over 112 sampled days, 36 admit no mutually visible epoch at all at a 10° mask, the most ever mutually visible is 17 of a 49-sample schedule, and on the 73 viable days the three-component ratio runs from 113.9× to four orders of magnitude more, median 1513×, while restricting to the two transverse directions the line of sight does not starve gives 3.94× to 25.8×, median 7.8×. WHAT THIS ROW DOES NOT CLAIM: any of those figures as a property of a real campaign. It establishes that the surface-point quantity is now COMPUTED rather than assumed, and that it cannot be silently interchanged with the station-level one. Stays ReferenceImpl/MODELLED: no published lunar-VLBI surface-point covariance exists to validate against, the stations and beacon site are illustrative rather than surveyed, and the ephemeris, clocks, troposphere and Earth-orientation parameters are held FIXED, so this is a Cramér-Rao bound for a reduced parameter set and optimistic in its own right
Tests
lunar_vlbi_fim::tests (7 lib tests: every datum spelling round-trips through parse/as_str and an unknown one is refused; holding every station without the beacon is refused with an error naming estimate_beacon; the…
The three terms a differential correction picks up between the epoch it is computed at and the epoch it is used at, each previously left as unmodelled headroom: reference-station survey error (correlated across satellites, baseline-independent, ~1:1 position transfer and provably not DOP-amplified), correction ageing (the frozen orbit-error vector re-projected onto the line of sight the engine's own propagator puts the satellite on one latency later, plus c·σ_y(τ)·τ clock drift from the calibrated power law), and uniform link quantization over an exact ±(orbit_err + clock_err) full scale with step²/12 variance. Reported in both the range and position domains, beside — never in place of — the existing residual and protection level, with a latency curve beside the single figure
Oracle
Closed-form identities and self-consistency: the uniform-quantizer step²/12 variance, the exact (GᵀG)⁻¹GᵀRG(GᵀG)⁻¹ covariance propagation collapsing to σ·PDOP for equal σ, the survey term's 1:1 transfer as a consequence of û_user ≈ û_ref, and switching-off quadrature closure. The PDOP cross-check against orbit::dop shares the [−û, 1] normal matrix, so it is a consistency check and is labelled as one rather than an independent oracle. No ExternalDataset is available or claimed: no lunar surface station has a published surveyed accuracy, no lunar differential-correction link has a published latency or message format, and the quantization result is a closed form rather than a measurement. RTKLIB — already the external-code oracle for the single-difference and weighted-least-squares kernel — could be driven with a deliberately mis-surveyed base to confirm the 1:1 survey transfer, but that is independent code over the same first-order line-of-sight algebra. MAGNITUDES ARE MODELLED: the survey default is this crate's own lunar frame-realisation allocation rather than a measured station, the latency and bit count are ILLUSTRATIVE inputs, and growth of the broadcast ephemeris error VECTOR itself is not modelled at all — stated in the emitted ageing-law string, because it is the term most likely to dominate a real link
Tests
lunar_dpnt::tests (a purely-additive guard whose key-set delta is exactly {correction_link, units} with every pre-existing value bit-identical against literals captured before the change; survey error does NOT…
The lunar protection level's geometry-to-covariance step — (GᵀG)⁻¹ over the all-in-view and every single-fault sub-geometry, projected onto the local vertical and the horizontal block trace — and its statistical kernel: the Bonferroni detector multiplier, the Gaussian upper tail of every fault hypothesis, and the root solve mapping an integrity-risk budget onto a protection level, over a 7-point lunar service volume
Oracle
Two established third-party implementations composed, both run offline, with the fixture regenerated end-to-end and verified byte-identical. RTKLIB 2.4.2-p13 (T. Takasu, BSD-2-Clause), commit 71db0ff, src/rtkcmn.c compiled from C source with -ULAPACK: lsq() → matinv() → ludcmp()/lubksb() inverts the normal matrix by Crout LU with partial pivoting, an algorithm unrelated to kshana's hand-written Gauss-Jordan invert4(); numpy.linalg.inv (LAPACK getrf/getri) re-inverts every one as a third independent inverse, agreeing with RTKLIB to 1.112e-12 relative. SciPy 1.17.0 / NumPy 2.4.1 (BSD-3-Clause) supply norm.isf, norm.sf (Cephes ndtri/ndtr) and optimize.brentq against kshana's Numerical-Recipes incomplete-gamma series, bisected inverse and 200-step bisection — and SciPy's direct sf is a different numerical route into the far tail than kshana's 1 − Φ, so the deep-tail cancellation is measured rather than mirrored. The vertical axis is the radial unit vector (the definition of local vertical on a spherical Moon) and the horizontal variance is the trace of the horizontal block, so no East/North azimuth convention is shared. EXPLICITLY NOT VALIDATED BY THIS ROW: σ_URE, the per-satellite fault prior and the illustrative Moonlight/LCNS-class constellation are MODELLED inputs handed to the oracle as given; and the FORM of the single-fault MHSS integrity equation is transcribed from the same published bound kshana implements — a shared closed form is a shared assumption, so this row covers a wrong evaluation of that equation, not a wrong choice of it. No third-party MHSS ARAIM implementation is reachable (RTKLIB exposes no protection-level entry point, no such PyPI distribution exists, Stanford MAAST is MATLAB), which is the outstanding upgrade
Tests
tests/lunar_protection_level_reference.rs (7 service-volume cases — south-polar, mid-latitude, equatorial, raised highland — 6 to 19 satellites, σ_URE 10/30/60 m, P_HMI 1e-3 down to 1e-7, protection levels spanning…
ValidatedARAIM MHSS protection levels against published reference vectorsaraim_reference (araim_reference_protection_levels,published_vectors),raim (araim_protection_level,araim_integrity_risk,normal_quantile)
Capability
The multiple-hypothesis solution-separation protection-level equation itself: all-in-view and per-fault-mode weighted least squares on an East/North/Up geometry with one clock state per constellation, the sub-solution sigmas, solution-separation sigmas and one-sided nominal-bias projections, the Bonferroni K_fa thresholds, the unmonitored-fault risk allocation, and the VPL/HPL that solve the integrity-risk equation. Runnable as the araim-reference-check scenario kind
Oracle
EU-U.S. Working Group C ARAIM Technical Subgroup, Reference Airborne Algorithm Description Document v3.1 (20 June 2019), Appendix D worked numerical example — published INPUTS (10-satellite 2-constellation geometry matrix, C_int/C_acc diagonals, b_nom, P_sat, P_const, LPV-200 constants) and published OUTPUTS (VPL 18.3 m, HPL 13.45 m, EMT 7.2998 m, σ_v_acc 1.3694 m, K_fa_3 5.1083, and six constellation-fault intermediates), retrieved 2026-09-20, source SHA-256 7f42934488c5c2261363439fabd48385e39526df34d514f395e22b6990b6bdb7. Matched at the reference's OWN stated tolerance TOL_PL = 5e-2 m: VPL 0.0074 m, HPL 0.0437 m; EMT and σ_v_acc to their printed precision. The same subgroup's Milestone 3 Report (2016) Annex A §A.IX states the same example but is internally inconsistent — a sign typo in row 3 of G (+0.7477 where the 2019 document prints −0.7477; with the plus, the document's own σ_v_acc comes out 0.8690 m against its published 1.47 m), and a K_fa_3 evaluated at 57 fault modes while the document states N_fault_max = 1, i.e. 12, so its EMT follows the 57-mode threshold and its VPL/HPL do not. No conforming implementation can reproduce all of its outputs at once. Its geometry intermediates reproduce exactly and its protection levels are recorded as measured discrepancies (VPL 0.0171 m, HPL 0.0842 m, EMT 0.4806 m), excluded from the acceptance figure; the tolerance was not widened to absorb them. SCOPE: N_fault_max = 1 only — multi-event fault subsets are refused rather than truncated, and exclusion, the chi-square consistency check and the double-counting re-allocation step stay MODELLED
Tests
tests/araim_reference_vectors.rs (2 published vectors + 6 negative controls, fixture tests/fixtures/araim_reference/wgc_araim_reference_vectors.txt: dropping the nominal bias misses the published VPL by 2.6457 m, a 10…
The cislunar arc-length observability threshold in the SPATIAL six-state CR3BP rather than the planar four-state, across DRO, L2 halo and L2 near-rectilinear halo families, with measurement noise entering the Gramian and TWO criteria reported because there is no single honest one: the published rank criterion, which is provably invariant to a homoscedastic measurement sigma (whitening multiplies the observability matrix by a scalar, leaving the relative singular-value spectrum and hence rank, defect and condition unchanged), and an estimability criterion — the first arc at which the formal 1σ position uncertainty of the chief's initial state falls below a stated bound — which is the one that does move with noise. Each threshold carries the epoch-grid bracket it sits in; an unreached criterion is null with a reason. Planar mode remains the default and out-of-plane families are refused there rather than flattened into a state that cannot represent them
Oracle
An independent row-echelon rank by Gaussian elimination with partial pivoting confirms every six-state rank verdict — a different algorithm sharing no code with the eigen/SVD route under test. The 6×6 CR3BP state-transition matrix this composes carries its own ReferenceImpl oracle against SciPy variational integration, and the halo/NRHO initial conditions come from a corrector that reproduces the published L2 southern 9:2 Gateway orbit. The existing square-root-information-filter leg is explicitly NOT counted as corroboration: it consumes the same Jacobians and reduces to the same normal matrix, so it is a consistency check between two numerical machines, and the emitted extension label says so. NOT externally anchored, and ExternalDataset is therefore declined rather than borrowed from the STM's row: the threshold arc lengths themselves depend on the MODELLED constellation design, the epoch grid, and — measurably, by up to 40× — on the singular-value tolerance. The published planar 2.09 h is reproduced exactly at rel_tol = 1e-6 and is itself tolerance-dependent (10.25 h at 1e-4, 0.42 h at 1e-8), which is a property of the criterion rather than of the orbit. No public dataset publishes an arc-length observability threshold for a chosen cislunar constellation. MEASURED RESULT: the spatial six-state threshold is 22.17 h for the L2 NRHO and 40.42 h for the L2 halo, and DOES NOT EXIST for the planar-DRO family the published claim was derived on — rank 4 of 6 with datum defect 2 and two exactly-zero eigenvalues, a structural defect no arc length recovers
Tests
cislunar_observability::tests and observability_gramian::tests (the default document pinned bit-for-bit by FNV-1a of its JSON, summary and SVG, with explicit-default values asserted to be a no-op and the eight…
A least-squares bias-plus-rate fit over a trailing window plus the principal periodic terms — annual, semi-annual and the two principal zonal tides for UT1; Chandler, annual and semi-annual for the pole — extrapolated with the last in-window residual carried forward: the class IERS Bulletin A uses, in place of the persistence predictor the published horizon rested on. Scored the only honest way: a forecast for T+h built from rapid Bulletin A rows at or before T, measured against the LATER-PUBLISHED Bulletin B final at T+h, with persistence scored over the identical epoch set against the identical finals beside it. A target epoch with no published final is dropped rather than re-scored against the rapid column; a periodic term the window cannot constrain is reported as rejected with the cycles it actually spans; an incomplete window is refused rather than quietly shortened
Oracle
Three independent routes, none of them a published prediction-accuracy figure. (1) An analytic signal with known coefficients — the only way to exercise the periodic machinery, since no committed series is long enough to admit an annual term. (2) The textbook closed-form least-squares solution, different algebra from the matrix solve under test, on real rows. (3) The genuine archived Bulletin A prediction rows the real 2026 product publishes, compared per lead as an AGREEMENT statistic and explicitly not as an error: 0.256 ms at 1 day, 0.695 ms at 2 days, 1.252 ms at 3 days, drifting to 3.885 ms at 9 days. So this is Bulletin A's CLASS, close at short lead, not Bulletin A. The predicted-versus-final residuals are real measured quantities over real IERS rows, but their magnitude is checked only against the DIRECTION of the comparison, never against an IERS-published accuracy number — reading a real product is provenance, not an oracle. MEASURED: at day 1 the operational predictor gives 3.78 m of Moon-frame error against persistence's 11.39 m (3.01×), at day 2 10.23 m against 21.72 m (2.12×), at day 3 20.33 m against 30.57 m (1.50×) — and it is WORSE beyond three days (0.87× at 5 days, 0.43× at 10), which the report emits rather than showing only the horizons that flatter it. NOT reproduced: the autoregressive residual filter and the tabulated zonal-tide reduction, the 365-day operational window is unreachable with the committed data, and NO archived earlier vintage of the series exists in this repository — so the archived-vintage table reports no rows rather than scoring a synthesised one
Tests
frame_eop::tests, realtime_frame_eop::tests and tests/operational_eop_predictor_reference.rs (analytic-signal coefficient recovery to 1e-9 at a 365-day window; a bias-plus-rate fit equal to the closed-form…
ModelledLunar frame datum from an observing campaignlunar_frame_campaign (composing lunar_vlbi,lunar_vlbi_fim,fim,lunar,lunar_frame_realise,frames,cio,lunar_frame)
Capability
The seven-parameter Helmert datum propagated from a SIMULATED OBSERVING CAMPAIGN instead of recovered from an injected transform. Earth stations observe a sourced catalogue of lunar-surface beacons over an explicit schedule; the lunar-VLBI delay partials are accumulated into a beacon-coordinate Fisher information matrix and pushed through the Helmert design A = [I₃ | [p]ₓ | p] into H = AᵀM_bA, so the reported datum accuracy is a function of the observing programme — exactly linear in the delay sigma and monotone in the arc through the libration the report MEASURES. The datum defect is the subject rather than a footnote: rank, defect, condition number, spectrum, unobservable directions in the seven-parameter basis, the weakest direction even at full rank and each parameter's share of it are emitted on every run, and any parameter the campaign does not constrain is published as NULL with a status. Beacon-error correlation is MEASURED, not assumed — exactly zero with the stations held fixed, and printed with its cost when they are estimated. Runnable as the lunar-frame-campaign scenario kind
Oracle
Closed-form identities and an independent in-repo route, with no external oracle claimed. The Helmert design — the only new derivative in the module — is re-derived by central finite difference of lunar_frame_realise::apply_helmert, a path sharing no expression with the analytic form. The accumulation it composes is lunar-vlbi-fim's, whose Jacobian is finite-differenced against lunar_vlbi::vlbi_delay_s there, and whose linear-algebra kernel is separately externally anchored against numpy in tests/fim_observability_reference.rs — this row borrows neither status. The physics oracle is structural rather than numerical: a beacon delay partial is the near-field DIFFERENCE of two near-parallel unit vectors, so the worst-determined translation direction MUST be the body-fixed direction to Earth, and the test asserts the computed answer against the separately measured direction. MEASURED: campaign-derived translation sigma 6.3975 m against the injected-transform scenario's 0.3125 m recovery error (20.5× tighter), while rotation and scale run the OTHER way at 2.32× and 13.5× looser — the injected path assumes one isotropic sigma and so spreads its error uniformly across seven parameters, which the delay observable does not. Rank 7/7 but condition 3.8e5, with one direction 99.57 % pure translation-toward-Earth and forty times worse than any other. WHAT THIS ROW DOES NOT CLAIM: that the campaign figure is right in absolute terms. It establishes that the figure now DERIVES from a schedule, a geometry and an error model rather than from a planted answer. Stays ReferenceImpl/MODELLED: no published lunar-VLBI campaign-plus-datum-covariance pair exists, the station network and delay sigma are ILLUSTRATIVE inputs (the beacon catalogue is sourced, the campaign is not), observations are treated as independent while a real session's troposphere and clock are correlated between nearby scans, and the ephemeris, clocks, troposphere and Earth-orientation parameters are held FIXED
Tests
lunar_frame_campaign::tests (21 lib tests: the Helmert design against a central finite difference of lunar_frame_realise::apply_helmert — the module the datum is FOR, which computes no derivative and so pins the [p]ₓ…
ModelledIndependent-estimator corroboration of the cislunar arc-length thresholdcislunar_arc_recovery,batch_ls
Capability
A batch least-squares estimator that RECOVERS the chief's initial state from simulated inter-satellite measurements over growing prefixes of the same epoch grid the rank-vs-arc table uses, with the measurement partials taken as central finite differences of the composed forward model. It consumes none of the machinery the threshold was measured with — no analytic Jacobian row, no variational state-transition matrix, no singular-value or eigen decomposition, no rank tolerance, no square-root information filter — and shares only the dynamics, the initial conditions, the scalar observable and the epoch grid, each named in the emitted document. Two criteria, both swept: noise-free recovery (the rank analogue) and Monte-Carlo estimability (the estimability analogue, measured against a known truth rather than predicted from a covariance). Runnable as the cislunar-arc-recovery scenario kind
Oracle
A separate estimator in this codebase on a different algorithm and a disjoint code path: nonlinear weighted Gauss-Newton with finite-difference partials, its verdict read as a measured state-recovery error in km and mm/s. It has no expression in common with the Gramian's rank-and-covariance route, and the separation is ENFORCED by a source-text guard rather than asserted. MEASURED on the published planar DRO grid: the ESTIMABILITY criterion is CORROBORATED — the measured Monte-Carlo boundary is 5.739130 h against the formal 5.739130 h (ratio 1.0000), and the measured RMS reproduces the formal 1σ over 21 arc lengths to a geometric-mean ratio of 0.9804. The RANK criterion is NOT corroborated as a recoverability boundary: the estimator recovers from 0.782609 h against the Gramian's 2.086957 h, ratio 0.375, and at 1.826087 h — the last prefix the rank read scores 3 of 4 — recovers to 1.96e-5 of the a-priori displacement. The recovery boundary is unmoved over three decades of its own bound while the rank threshold spans 'never' to 0.782609 h over four decades of rel_tol, and the two coincide exactly at rel_tol = 1e-8. That span was first recorded as reaching 0.260870 h; that figure was an ARTEFACT, produced by a rank read that counted 4 directions from 2 measurement rows below the f64 noise floor, and it is corrected here rather than left standing. The rank read is now bounded by Sylvester's inequality with the reason emitted, and the corrected span saturates at exactly the arc where the independent estimator recovers, which strengthens this row's cross-validation rather than weakening it: the published 1e-6 is a conservative singular-value CONVENTION, not a statement about recoverability. Same pattern spatially: NRHO 9.290323 h against 21.677419 h, halo 22.978723 h against 39.829787 h, with estimability agreeing exactly in both. The planar-DRO six-state recovers at no arc, independently reproducing that family's structural datum defect from an estimator told nothing about it. NOT externally anchored — the dynamics and initial conditions are shared with the analysis under test and no public dataset publishes such a threshold — so ExternalDataset is declined
Tests
cislunar_arc_recovery::tests and tests/cislunar_arc_recovery_reference.rs (both boundaries and their ratios pinned on the published grid; the measured error curve compared to the formal covariance row by row with a…
ModelledLunar service volume from real, retrieved constellation geometrylunar_ephemeris,lunar_service
Capability
Accepts a tabulated Moon-centred state ephemeris (the evaluation of an SPK/BSP kernel) or a published constellation definition behind ephemeris_path, runs the identical coverage / DOP / protection-level sweep against it, and emits the σ_URE ranging requirement it implies BESIDE the unchanged illustrative Keplerian and perturbed results with the difference as its own named quantity. Every figure carries a provenance class that distinguishes kernel-derived from published-element-derived from modelled, so the two can never be confused in a downstream quotation
Oracle
The GEOMETRY is external and hashed: three fixtures whose numbers come only from documents retrieved with URL, retrieval date and SHA-256, regenerable by committed generators that verify the upstream hash and ABORT rather than emit a number — the LANS interoperability-demonstration reference constellation (NASA NTRS 20250009447, SHA-256 d1b916be…), the LNCSS case studies (NAVIGATION 70(4) navi.613, CC BY, SHA-256 4e294687…), and a genuine flown-spacecraft ephemeris for LRO, Danuri, Chandrayaan-2 and CAPSTONE evaluated from JPL's own reconstructed kernels via Horizons. NO lunar-navigation constellation kernel exists publicly — Moonlight/LCNS, LCRNS and LNSS are not flying and NAIF publishes nothing for them — and none was invented. The DERIVED σ_URE requirement has NO external oracle (nobody publishes the ranging accuracy a 50 m lunar HPL demands over this service volume), so it is checked against its own algebraic identity and, independently, by re-running the whole sweep at the computed requirement and confirming availability flips there. MEASURED: the published 8-satellite design needs σ_URE 2.9044 m at 100 % coverage against the illustrative constellation's 0.3591 m at 37.85 % — an 8.09× revision of a published number under programme rule R4. The qualitative conclusion survives (LNIS-class 30 m still does not close a 50 m south-polar HPL) but the shortfall was overstated eightfold. The 5-satellite LANS demo yields ZERO protection-level samples — five satellites cannot give the six-in-view a single-fault hypothesis set needs — and the requirement field is ABSENT rather than fabricated; likewise for the four real spacecraft at 0 % coverage. InternalConsistency is the honest kind: the INPUT data is external and hashed, but the quantity this row is about is validated only against itself
Tests
lunar_ephemeris::tests (format and frame parsing; Lagrange interpolation exact at nodes and on a linear track off-node; ICRF elements take the IAU 2015 reduction and are byte-equal to an explicit icrf_to_iau_moon…
ModelledUnit and provenance declared for every reported quantityfield_schema
Capability
A machine-readable schema giving unit, provenance class and definition for every numeric field of every scenario report, plus a single global gate that runs every registered scenario kind and fails if an emitted numeric field lacks either. The provenance vocabulary is closed and each class carries an evidence tier, with two classes deliberately mapped to inherits-scenario-label and depends-on-input rather than being assigned a tier the class does not determine
Oracle
The emitted document itself: every numeric leaf must resolve to an entry in that document's own units block. There is no external unit registry to check a DECLARED unit against, so a declared unit is a reviewed assertion and not a verified one — the gate verifies COMPLETENESS and WELL-FORMEDNESS, not truth, and Validated would be wrong because nothing external confirms that m is the right unit for a field named _m. An independent name-suffix cross-check was run over the 1,434 fields described AT THAT TIME: of the 691 carrying a unit-bearing suffix, 40 disagree with the declared unit and all 40 are explained (per-second suffixes, minima, aperture-seconds, newton-metres against a nanometre-looking suffix), so no wrong unit surfaced. That cross-check has not been re-run since, and coverage has grown past it — the figure is left at what was actually measured rather than restated at the current total. COVERAGE MOVED 7 of 56 kinds to 60 of 61, and 389 of 1354 fields to 1,742 of 1,744 (docs/field-units-schema.json, which a staleness check keeps current). ONE kind remains uncovered and is named with its reason rather than hidden behind a wildcard: sweep-nd, two of whose columns are caller-keyed so their units are data. cislunar-observability was the second, and came off the list when its released document gained a units block: the additivity pin that had named units as a forbidden key now PROVES the addition is additive instead — strip the block back off and the document still hashes to the two constants frozen before it existed, so a released value that moved underneath the addition still fails. The work also surfaced twelve unit or documentation defects in existing code, reported rather than fixed under R1
Tests
tests/field_units_global.rs (all 61 registered kinds run, one document shape each: every numeric leaf must resolve to an entry in that document's own units block; a malformed entry counts as missing for EVERY kind…
ModelledLunar frame datum from a REAL observing campaignlunar_llr,realdata::llr_crd (composing fim,cio,frames,ephem,lunar_frame,lunar_frame_campaign)
Capability
The seven-parameter Helmert datum covariance, with its two simulated inputs replaced by measured ones: the schedule is the ground-transmit epochs of 337 archived ILRS lunar laser-ranging normal points (2015-04-08 to 2015-06-27, Grasse MeO 7845 and Matera MLRO 7941, all five retroreflector arrays) and every observation weight is that point's own archived precision bin_rms/√n_raw — median 5.13 mm of one-way range, read out of the file. Station coordinates IERS ITRF2020, reflector coordinates JPL DE430 Table 7. Runnable as the lunar-llr-datum scenario kind
Oracle
Closed-form identities and an independent in-repo route; NO external oracle is claimed for the covariance, because no published lunar-LLR datum-covariance pair exists to check it against. The only new derivative — the range partial with respect to the reflector's body-fixed position — is re-derived by central finite difference of the two-way light time it differentiates, a path sharing no expression with the analytic form. The physics oracle is structural: the partial of a range IS twice the line of sight, so the body-fixed coordinate along the mean direction to Earth must be determined far better than the two plane-of-sky coordinates, which only the libration reaches — measured at 50.7× to 71.7× across the five arrays against a libration sweep the report measures independently, with the isotropic small-angle prediction and the transverse anisotropy that explains the gap both printed. WHAT CHANGED: the schedule, the observation count and every observation weight are now measured; 337 of 349 archived points are used and the 12 that are not are skipped and counted, because ITRF2020 carries no position for Apache Point. MEASURED: datum translation sigma 1.851746e-2 m against the SIMULATED campaign's 6.3975 m (345×), rotation 36×, scale 24× — a ratio between a laser-range network and a VLBI-delay network, so a finding rather than a validation. Reflector information rank 15/15 with inter-array coupling exactly 0; Helmert rank 7/7, condition 2.4e4. WHAT THIS ROW DOES NOT CLAIM: that the figure is right in absolute terms. A real LLR solution co-estimates the lunar orbit, physical librations, Earth orientation, station coordinates and tidal and relativistic parameters, and reports decimetres (DE430 Table 7's own 0.12-0.27 m) where this bound is far smaller; this is a Cramér-Rao bound for a stated reduced parameter set, not an accuracy. Stays MODELLED: the Moon-centre ephemeris and the IAU 2015 body orientation are modelled, and troposphere, tides, station eccentricity, polar motion, UT1-UTC, relativistic delay and station clocks are absent. Their combined size is PUBLISHED rather than argued — observed-minus-computed one-way range 156,494 m RMS over the 337 points — and their effect on the covariance is BOUNDED rather than argued: re-solving the entire datum with every partial tilted by 0.1° (twice the measured worst-epoch ephemeris tilt, sign alternating) moves the deliverable by 0.288 %
Tests
tests/lunar_llr_real_data.rs (11 tests: all 15 committed CRD files byte-identical to their recorded digests; all 349 records accounted for, 337 used and 12 skipped for a named reason; every archived range inside the…
ValidatedBuilt-in analytic lunar ephemeris — its STATED ACCURACY BOUND checked against real dataephem (moon_position),lunar_llr,realdata::llr_crd
Capability
ephem::moon_position, the low-precision geocentric lunar series the crate falls back on when no DE/SPK kernel is present, measured against real lunar laser ranging and against a published planetary ephemeris over the same span. This row validates the bound the module states about itself, NOT an accuracy: the series is confirmed to be no worse than it says, not confirmed to be good
Oracle
TWO independent external datasets that share nothing. (1) 337 archived ILRS lunar laser-ranging normal points (EUROLAS Data Center, DGFI-TUM, 2015-04-08 to 2015-06-27, five retroreflector arrays, committed with per-file SHA-256 and a re-download-and-verify script): observed-minus-computed one-way range 156,494 m RMS, with station coordinates from IERS ITRF2020 and reflector coordinates from JPL DE430 Table 7, so the residual is dominated by the Moon-centre series. (2) JPL Horizons geometric geocentric Moon states over the same span: 112,567 m RMS radial, 195,655 m RMS vector, worst epoch 360,324 m = 0.0536°. A range residual responds to the RADIAL part of an ephemeris error, so (1) and (2) are the same quantity reached two ways and agree to 1.39× — which is what licenses the lunar-llr-datum scenario to attribute its residual to the ephemeris. The engine's own module documentation claims ~0.3° / ~few·10² km; both measurements are inside it, the angular claim with a 5.6× margin. SCOPE, stated so no reader can mistake it: this validates the stated BOUND, not an accuracy figure. The series remains unsuitable for any application needing better than ~1e5 m, and that limitation is the row's content as much as the agreement is. Regenerable offline by the committed fetch-and-verify scripts
Tests
tests/lunar_llr_real_data.rs::the_analytic_moon_series_disagrees_with_jpl_by_the_same_amount (12 weekly geocentric states, worst-epoch angle asserted < 0.3° and RMS < 5e5 m against the module's own documented claim…
ModelledGate integrity — a green that means what it saysscripts/gate.sh,scripts/check-gate-receipt.sh,scripts/check-repeatability.sh,scripts/install-gate-hook.sh
Capability
Three structural guards over the verification process itself, each closing a class of defect that reached the canonical gate as an intermittent or spurious red. (1) Every constructed temp path in the Rust sources must carry a per-call unique component; a process id is rejected, because cargo runs the library tests as parallel threads of ONE process and the pid is shared by all of them. (2) Every byte-for-byte or hash pin must declare, next to itself or in its module header, what it covers and what it deliberately excludes — so a cross-cutting change can tell at a glance which pins are in scope and which have silently become repository-wide change detectors. (3) A green is claimable only from the FULL suite: scripts/gate.sh runs cargo test --all, captures the true exit code with no pipe in the way, and writes a receipt naming the commit, the integration-binary count, the test count and the duration; the pre-push check refuses a push whose commit no valid receipt names, on a clean tree. Repeatability is sampled separately by scripts/check-repeatability.sh, which runs the library suite N times and fails if the set of passing tests differs.
Oracle
Closed-form: each guard is run over a fixed known-bad snippet that must fire and a fixed known-good snippet that must stay silent, both literal constants the detector cannot influence. The two known-bad snippets are the F22 and F25 defects in their original shape. This is an INTERNAL oracle and the row is MODELLED accordingly: it proves the guards discriminate the defect from its fix, not that the classes they describe are exhaustive. Their stated blind spots — shared state that is not a path, a pin held in a short named constant, a rare race that three runs do not sample, and a receipt that anyone who can write the file can forge — are written out in the module documentation of tests/source_guards.rs and in each script's header rather than left to be discovered.
Tests
tests/source_guards.rs (9 tests: both guards over the whole source tree, plus mutation fixtures that grade each guard in both directions — the F22 pattern reported on both colliding paths, the shipped atomic-sequence…
Running-max envelope overbound-covers (zero-piercing) a real metrological series at every tested lag tau>=90d on a disjoint segment; short-tau (<=30d) is a disclosed Modelled boundary
Per-source bias overbound b = (U/k_cov)·Phi^-1(1-tail/2) + ageing, inflating a published Type-B expanded uncertainty to an allocated integrity tail; bridges to tpl_scalar as bias_s
Oracle
Independent numpy + stdlib-statistics reproduction of the overbound closed form (InternalConsistency). The BIPM Circular-T [UTC-UTC(USNO)] series is a CITED input only — it is the SAME series already Validated for the R4 holdover-coverage row and is NOT re-validated here; reproducing its values proves nothing about R2. Deep integrity tail is Modelled.
N×N bias cross-covariance with rho·b_i·b_j off-diagonals for sources sharing a UTC(k) realizer; PROVEN correlated_fused_bias >= independent_fused_bias (naive independent allocation under-bounds the fused bias -> optimistic -> unsafe)
Oracle
Independent numpy reproduction of the cross-covariance and the correlated-vs-independent fused bias inequality (InternalConsistency). Representative source set; Modelled scenario.
Score statistic (1^T Omega^-1 r)^2/(1^T Omega^-1 1) ~ chi^2_1 for a common-mode shift that solution separation (contrasts orthogonal to 1) cannot see; a common-mode shift inflates it while pairwise separations stay flat
Oracle
Independent numpy reproduction of the statistic + property test that a common-mode injection inflates it (InternalConsistency). Modelled scenario.
Irreducible undetectable common-mode error: min(alpha_ss, alpha_cm) fault magnitude escaping BOTH separation (whitened contrast norm) and the common-mode statistic (1^T Omega^-1 d); INFINITY when the fault direction lies outside the modelled Omega common axis (published honest blind spot)
Oracle
Property tests over the finite/infinite detectability boundary (InternalConsistency). PROVEN blind-spot bound; no accuracy claim. Modelled.
ValidatedLunar datum identifiability - decomposition linear algebralunar_identifiability
Capability
Schur-complement marginal of the {lunocenter-X, scale} block of the 7-parameter Helmert datum Fisher: the scalar degeneracy metric lambda_min(S), the origin-X CRLB, and the origin-scale correlation
Oracle
Independent SciPy/NumPy reference (scripts/gen_datum_identifiability_ref.py -> tests/fixtures/datum_identifiability/scipy_ref.csv): the Schur complement, its eigenvalues, and the 2x2 inverse computed by an independent library. Scoped to the decomposition LINEAR ALGEBRA; the lunar correlation/CRLB MAGNITUDES from real geometry remain MODELLED.
Tests
tests/lunar_datum_identifiability_reference.rs::decompose_matches_scipy_reference (16 synthetic 7x7 SPD matrices spanning well-conditioned to {0,3}-near-degenerate; Schur lambda_min / origin CRLB / |corr| vs…
ModelledLunar datum null-space classification (LLR rank-additivity + libration defect-lift)lunar_identifiability,lunar_datum
Capability
Classification of the internal-ranging datum problem: a single range observation contributes rank 1 (6-dimensional null space); the origin-X and scale pair is near-null and physical DE440 libration lifts the defect to zero while the pair stays near-degenerate
Oracle
Engine-reproduced geometric structure plus the closed-form 2x2 Schur identity; consistent in STRUCTURE with Sosnica et al. 2025 (arXiv:2510.15484), whose reported magnitudes are NOT reproduced here. The classification is structural; the correlation/CRLB magnitudes under real geometry are MODELLED (reflector coordinates and orientation held fixed).
ModelledMulti-technique lunar datum information (LLR + lunar VLBI + orbiter range)lunar_datum,lunar_identifiability
Capability
Datum-Jacobian rows for Earth-reflector LLR range, two-station lunar-VLBI differential delay, and orbiter-to-beacon range over the 7-parameter datum, combined into one consistently-preconditioned Fisher; demonstrates that off-radial (orbiter / depth-diverse) tracking breaks the origin-X to scale degeneracy where transverse VLBI helps only indirectly
Oracle
Analytic-vs-finite-difference cross-checks of each technique's partials (internal); the improvement DIRECTION is a geometric fact. Beacon locations, schedules and noise are MODELLED/representative (see tests/fixtures/llr_geometry/NOTICE.md).
Tests
lunar_datum::tests (LLR/VLBI/orbiter analytic partials vs finite difference); lunar_identifiability::tests (adding_an_offradial_technique_collapses_the_origin_scale_degeneracy; transverse-vs-radial via crlb_diag)
MOON_PA_DE440 to J2000 rotation at arbitrary epochs, by element-wise linear interpolation of a committed 731-row daily series with column Gram-Schmidt re-orthonormalisation; embedded at compile time so there is no runtime filesystem I/O and the WASM build carries it
Oracle
The series itself is external: JPL DE440 binary PCK moon_pa_de440_200625.bpc, NAIF frame 31008, extracted by the committed scripts/gen_de440_moon_pa.py via spiceypy 8.1.2, fixture SHA-256 3076f81ef95d83f5efa240ed4c7ccb422f109407dde841fcf28d42dc63586eb7. What is NOT independent: the node-level test round-trips through the same embedded copy the engine reads, so it checks the parser and interpolator, not JPL. The independent content is physical - the recovered sub-Earth libration spans 15.6 deg in longitude and 13.6 deg in latitude, which is the known lunar optical libration, and a constant or mis-scaled series cannot produce it. Interpolation between the one-day nodes is MEASURED, not asserted, at about 14 m at the lunar surface after re-orthonormalisation; the module is therefore a geometry substrate for identifiability analysis and is NOT sub-metre in absolute orientation.
ModelledLunar LLR datum geometry substrate (principal-axis reflectors, ground stations, analytic range partials)lunar_llr_geometry
Capability
The five near-side retroreflector arrays in PA body-frame metres and the LLR ground stations in geodetic coordinates; reflector body-to-inertial placement through the DE440 PA orientation; analytic partials of Earth-to-reflector range with respect to the 4-parameter datum; and the LLR-only Fisher matrix exhibiting the lunocentre-X to scale degeneracy that motivates the 7-parameter analysis
Oracle
The computation is checked internally: every analytic partial against a finite difference, and the zero-datum case against the nominal range. The CATALOGUE is checked externally and independently - the DE440 principal-axis coordinates (Park et al. 2021, tests/fixtures/llr_geometry/de440_retroreflectors_pa.csv) are cross-checked against Table 6 of the DE430 surface-coordinates memorandum (tests/fixtures/lunar_llr/de430_retroreflectors_pa.csv, machine-extracted from a SHA-256-verified PDF by tests/fixtures/lunar_llr/generate_de430_retroreflectors_pa.py) and agree to 1.12 m, while the mean-Earth realisation of the same five arrays differs by 672 to 871 m. The DEGENERACY STRUCTURE is checked against a published result: Sosnica et al. 2025, 'Definition and Realization of the International Lunar Reference Frame', arXiv:2510.15484, which reports for the lunar principal-axis frame a lunocentre-X to scale correlation coefficient of r = -0.97, and that LLR fails to reach the actual centre of mass of the Moon with an accuracy better than 12 cm because of that correlation. This module recovers the same structure (|corr(t_x, scale)| between 0.9 and 0.9999, datum defect <= 1) from an LLR-only Fisher design. The corroboration is across ephemerides, not a round trip: the paper combines INPOP21a, DE430 and EPM2021, whereas this module is driven by DE440 libration. What is NOT reproduced is magnitude - the correlation here is about -0.988 against their -0.97, and the 4-parameter CRLB is sub-millimetre against their 12 cm achieved floor, because orientation and reflector coordinates are held fixed here and solved there. Geometry and degeneracy structure only; no accuracy claim about a solved datum.
ValidatedCoupled lunar frame and timescale gauge: the joint spatial-datum, clock-offset and clock-rate null spacelunar_gauge
Capability
assemble_coupled_info builds the 9-parameter coupled Fisher over [t_x, t_y, t_z, s, theta_x, theta_y, theta_z, d_tau, d_alpha]; classify_null_space returns a basis-invariant decomposition of its null space into spatial-only, temporal-only and genuinely coupled dimensions plus the spatial-to-temporal projector coupling norm; coupled_marginal_eigs gives the {scale, offset} Schur-complement marginal. On the committed networks the engine reports a full-rank datum (defect 0) for the well-posed case and an exact single rate-direction defect for the single-epoch case (elapsed time zero, so the rate is unobservable by construction), and computes the {s, d_tau} marginal in both.
Oracle
WHAT IS EXTERNALLY CHECKED, stated narrowly: kshana computes the eigendecomposition with its own hand-written Jacobi solver (fim::sym_eig) and the marginal with its own pseudo-inverse; the oracle recomputes both with numpy/LAPACK (np.linalg.eigvalsh/eigh/pinv) via scripts/gen_coupled_gauge_ref.py. Agreement to rel<1e-3 is therefore an independent-library check of THIS CRATE ARITHMETIC against a standard implementation, which is the Validated claim and the whole of it. WHAT IS NOT: the assembly and the null-space classification are this module's own rules, and the oracle reproduces them from the same specification rather than from an independent source - that corroborates the implementation, not the rule. The beacon and orbiter geometry is Modelled and representative. The observation rows do carry the real DE440 Moon PA orientation (lunar_datum::orbiter_range_row_datum7 -> lunar_orientation::de440_moon_pa_body_to_inertial), but that is an INPUT both sides receive, not evidence about the answer, and it is recorded here as provenance rather than as the warrant for the status - the same distinction main already draws in the common-mode integrity row. Every row float is rounded to 6 dp before network.json is written, so both sides read identical IEEE-754 doubles and the only difference left is the solver.
Tests
tests/lunar_coupled_gauge_reference.rs::coupled_gauge_matches_numpy_on_real_de440_rows (9 eigenvalues, defect/dim_spatial/dim_temporal/coupled_dim/p_st_norm and the {scale,offset} Schur marginal for the well_posed…
ModelledRange to clock-offset degeneracy in one-way lunar ranging, and the geometric-diversity design lawlunar_gauge
Capability
The per-node radial-range to receiver-clock-offset degeneracy is exact at 1 m to 3.336 ns (one over c). The {scale, offset} Schur-complement marginal (coupled_marginal_fisher) shows that in a geometrically diverse network two-way ranging lifts the marginal by about the same factor as an equal count of additional one-way data, while in the idealised single-node regime the two-way lift is orders of magnitude larger. The design law that follows: geometric diversity, not two-way ranging as such, is what separates lunar frame scale from timescale offset in one-way ranging; a two-way or external time tie is required only in the low-diversity or single-user regime.
Oracle
Schur-complement marginal Fisher of the coupled information matrix, in closed-form linear algebra, checked against the two limiting regimes it predicts. The 1 m to 3.336 ns equivalence is the definition of the metre via c and is not an empirical result. The observation networks are representative Modelled geometry, so the design law is a statement about the geometry presented to it and carries no claim about any fielded lunar network.
ModelledRelativistic clock-rate to frame coupling for the lunar timescalelunar_gauge,lunar_time
Capability
rate_frame_jacobian gives the sensitivity of the lunar timescale rate to the frame realisation: d_alpha/d_scale = +U_moon/c^2, about +3.140e-11; d_alpha/d_velocity about -1.11e-14; d_alpha/d_r_radial = +g_moon/c^2, about +1.807e-17 per metre, with the radial entry equal to the scale entry divided by the lunar radius. Propagated through a frame-estimation datum these bound the rate perturbation at about 2e-17, far below the roughly 1.7e-11 rate offset of a lunar timescale against TT, so a frame re-realisation at this level does not move the timescale rate measurably.
Oracle
First-order relativistic rate model - self-potential, kinetic term and redshift gradient - differentiated with respect to the frame parameters in closed form, with the internal identity d_alpha/dr = d_alpha/ds divided by RE_MOON_M checked to 1e-12 so the two derivatives cannot drift apart. The comparison band and the tidal and J2 contributions are Modelled reference-surface figures, not a metrological budget, and no claim is made that a real lunar clock realises this rate.
ModelledBasis-invariant classification of the coupled frame and timescale null spacelunar_gauge
Capability
classify_null_space decomposes the datum null space into spatial-only (dimension d minus rank U_T), temporal-only (d minus rank U_S) and genuinely coupled (rank U_S plus rank U_T minus d) parts, plus the spatial-to-temporal projector coupling norm p_st_norm, the Frobenius norm of the off-diagonal block of the null-space projector. Every one of these is a function of the PROJECTOR rather than of a chosen basis, so they are invariant under any orthonormal choice of null vectors - which is what makes the classification reportable at all.
Oracle
Projector-based invariants of the coupled Fisher null space, in closed-form linear algebra, proven by construction and then checked by rotating the null basis and requiring every reported quantity to be unchanged. The invariance test is the load-bearing one: a classification computed from a particular basis would agree with this one on the constructed cases and disagree the moment a real problem produced a different basis for the same subspace.
Tests
lunar_gauge::tests (classify_is_invariant_under_null_basis_rotation - an axis-aligned null basis and its 0.6 rad rotation yield identical defect, dim_spatial, dim_temporal, coupled_dim and p_st_norm…
ModelledRepresentative multi-technique measurement menu and the additive Fisher combination rulelunar_techniques
Capability
MeasurementBlock holds one candidate measurement campaign as a 7x7 Fisher information contribution plus a scalar relative cost; block_from_rows builds one from raw datum-Jacobian rows so every block is preconditioned identically through lunar_identifiability::assemble_multi_info; combine sums the information of a chosen subset, which is the correct rule because Fisher information is additive across independent measurements; representative_lunar_menu supplies a deterministic four-block menu (LLR, a transverse VLBI limb beacon, a near-side orbiter and a far-side orbiter). The budget-constrained design optimiser that consumes this menu is not part of this crate.
Oracle
Additivity of Fisher information across independent measurements is a closed-form property, checked here against an independently written element-wise sum and against the order-invariance and monotonicity that follow from it. NOTE ON EVIDENCE: the combiner previously had no test at all, and the one test in the module summed the two information matrices inline instead of calling it, so a broken combiner would have left the module green; the test now goes through combine and fails when it is mutated. All beacon locations, orbiter geometry, per-technique precisions and relative costs are representative choices rather than mission values (see tests/fixtures/llr_geometry/NOTICE.md), so every degeneracy metric and CRLB figure reached through this menu inherits the Modelled status of lunar_identifiability::decompose.
Tests
lunar_techniques::tests (combine_is_additive_order_independent_and_empty_is_zero - empty selection gives the zero matrix, a single selection is the identity, a pair equals an independently written element-wise sum, and…
rotation-only (6-parameter translation+rotation) decomposition of the DE440/INPOP21a/EPM2021 geocentric-Moon disagreement into a reducible common ICRF frame-tie and an irreducible lunar-orbit-orientation excess (the full 7-parameter Helmert fit is a separate public function NOT covered by this external check: its evidence is an internal analytic-recovery unit test plus tests/lunar_helmert_fit_cross_check.rs, which agrees it against the Validated exact Gauss-Newton fit in lunar_frame_realise and pins the opposite-rotation-sign convention between the two)
Oracle
Three independent authoritative ephemerides — DE440 (JPL), INPOP21a (IMCCE), EPM2021 (IAA RAS) — sampled via IMCCE calceph, cross-checked by an independent numpy SVD least-squares fit. WHY THIS IS Validated WHERE lunar_common_mode IS NOT, on the same three ephemerides: here the reported quantity IS a property of the published data — their mutual disagreement — so the ephemerides are the oracle, not an input. In lunar_common_mode the same disagreement feeds a MODELLED constellation geometry and the answer is a property of that model, which is why that row is correctly Modelled/ReferenceImpl.
Tests
tests/lunar_interop_budget_reference.rs (raw / rotation-residual / theta_moon / theta_frametie / theta_excess / reducible / irreducible for 3 provider pairs vs the independent SciPy SVD lstsq fit in…
ModelledCross-provider consistency tolerance for a mixed-provider userlunar_interop_budget
Capability
consistency_tolerance: inverts a user position budget to a per-parameter inter-provider Helmert agreement requirement (origin/scale/rotation) at a reference lever arm, optionally inflated by the P1 single-provider realization CRLB
Oracle
Worst-case triangle bound on the Helmert point-Jacobian action (closed form)
Tests
lunar_interop_budget::tests (monotonicity in budget; RSS budget reduction under a per-provider CRLB; worked rotation tolerance at the lunar lever arm; binding-term = rotation)
ModelledMulti-provider lunar interoperability error budget and frame-vs-ephemeris design lawlunar_interop_budget
Capability
interop_budget: reducible (common frame-tie) vs irreducible (dynamics) split under PerProvider / CommonFrameTie / CommonEphemeris conventions, with the irreducible-fraction design-law metric (~0.69 on real DE440/INPOP/EPM: a common frame tag alone leaves the dominant floor)
Oracle
RMS aggregation of the Validated per-pair splits under each convention (closed form)
Tests
lunar_interop_budget::tests (CommonEphemeris zeroes the budget; CommonFrameTie < PerProvider; irreducible_fraction > 0.5 on the real splits; convention ordering)
On the real-DE440 per-node lunar network (each row a differential inter-node one-way range built via pernode_range_row with a real DE440 Moon PA-frame line of sight), the engine computes the weighted parity projector P⊥ = I − G(GᵀWG)⁺GᵀW (the rank-deficient pseudo-inverse form that survives the 8-dim datum⊕timescale gauge), the T1 detectability residual ‖P⊥·b‖ (in-range faults annihilated, generic faults detectable), the Baarda MDB non-centrality quadratic form cᵀWP⊥c (the correct single-P⊥ weighted form, NOT the double-P⊥ form cᵀP⊥WP⊥c) with MDB = √(λ₀/cᵀWP⊥c), and the Byzantine block-spark detect/identify counts of the stacked effective peer signatures P⊥·B_T (column-rank, not merely nonzero)
Oracle
Independent numpy/scipy linear-algebra reproduction on real DE440 Moon PA-frame line-of-sight rows (P⊥ from the SVD of the whitened design W^{1/2}G; the MDB non-centrality from the classical Baarda (1968) parity-subspace squared norm; the block rank from a numpy SVD singular-value count) — a genuinely different numerical route than the crate's cyclic-Jacobi eigendecomposition of GᵀWG. Scope (per tests/fixtures/faultobs/NOTICE.md): this validates the LINEAR-ALGEBRA PIPELINE on these rows only. The node geometry is Modelled. It is NOT an operational integrity guarantee, a protection-level certification, or any RAIM/ARAIM availability claim, and NOT a Byzantine-fault-tolerance mission guarantee — the tolerated-fault COUNT for this network is Modelled, while the detect>f / identify>2f block-spark BOUND is Cited (Fawzi–Tabuada–Diggavi 2014; Shoukry–Tabuada 2016; block-wise spark of Donoho–Elad 2003) and proven-instantiation in code
Tests
tests/lunar_faultobs_reference.rs (faultobs_matches_numpy_scipy_on_real_de440_rows: the 84×84 P⊥ element-wise, trace(P⊥) = parity_dim = 52 and rank(G) = 32, detectability norms + flags, the MDB quadratic form cᵀWP⊥c +…
ModelledByzantine block-spark detect/identify bound on the autonomous per-node lunar network (T3)lunar_faultobs
Capability
byzantine_bound instantiates the secure-state-estimation coding / sparse-observability bound on the per-node network geometry: a Byzantine peer injects an arbitrary linear combination of the measurements it participates in, and the network DETECTS any coalition of ≤ f = block_spark − 1 peers and uniquely IDENTIFIES any coalition of ≤ ⌊(block_spark − 1)/2⌋, where block_spark is the smallest peer-coalition whose stacked effective signatures P⊥·B_T are column-rank-deficient. Peer detectability is FULL COLUMN RANK of P⊥·B_j (a nonzero-but-rank-deficient block is a nonzero attack that lands in range(G) and leaves no residual), not merely P⊥·B_j ≠ 0
Oracle
Geometric instantiation of the block-wise spark / secure-state-estimation bound (Fawzi–Tabuada–Diggavi 2014; Shoukry–Tabuada 2016; block-wise spark of Donoho–Elad 2003; Candès–Tao 2005) — NOT the Lamport–Shostak–Pease 3f+1 consensus threshold ('Byzantine' names the arbitrary/colluding fault MODEL only). The specific tolerated-fault count is a Modelled property of the representative network geometry, checked for self-consistency by hand-constructed analytic cases and the count formulas
ModelledAutonomous-holdover temporal-gauge floor for the self-referential lunar constellation (T4)lunar_faultobs
Capability
holdover_floor establishes that in an ensemble of autonomous nodes connected only by inter-node measurements the common clock rate (δα_j += 1 ∀j) is an ensemble-time free parameter lying in N(GᵀWG): no amount of additional inter-node ranging can observe it (rate_in_gauge = true, temporal_gauge_dim = 2 with the common offset). This is the genuine holdover floor — the temporal analog of the rigid-frame position gauge. Adding one external absolute-rate tie (a direct link to an off-network reference) expels the common rate from the null space (rate_in_gauge = false, temporal_gauge_dim = 1), proving the floor is a real gauge, not an oscillator-model artefact
Oracle
Ensemble-time free-parameter argument (Percival 1978; Lewandowski & Thomas 1991) instantiated on the representative real-DE440 per-node network: a relative-residual null test of the analytic common-rate generator against GᵀWG, with the tie-broken contrast distinguishing the genuine gauge from an oscillator-model artefact. Representative Modelled geometry, not a certified timing budget
Tests
lunar_faultobs::tests — holdover_floor_self_ref_and_anchored (self-referential net: the common rate lies in N(GᵀWG), temporal_gauge_dim 2; after one external rate-tie row: rate expelled from the gauge…
Three facets of the single decomposition ℝ^{state_dim} = N(GᵀWG) ⊕ range(GᵀWG) with the 8-dim datum⊕timescale gauge as N(G) and the state_dim − 8 = 32 observable directions as range(G): (T5) provider_mismatch_split classifies a common multi-provider bias (∈ range(G)) as UNDETECTABLE — needing an external tie — and a differential bias (∉ range(G)) as self-monitored / DETECTABLE; (§0) the unification is that the SAME range(G) blind subspace governs the undetectable fault class, so the datum gauge N(G) and the fault-blind subspace range(G) are one geometry, not two; (g7) slope returns the Brown protection-gap slope ‖Π_obs Δx̂‖ / ‖P⊥b‖_W → ∞ for a fault b ∈ range(G) (estimator corrupted with zero parity) and finite for a detectable fault
Oracle
Closed-form parity-projector / pseudo-inverse algebra on the representative real-DE440 per-node network: the common/differential split, the N(G) ⊕ range(G) unification and the Brown (1992) protection-gap slope all follow from range annihilation P⊥·G = 0. Representative Modelled geometry, not a certified protection level
Tests
lunar_faultobs::tests — provider_mismatch_split_common_undetectable_differential_detectable (common bias undetectable, differential detectable), slope_infinity_in_range_finite_detectable (g7: slope ∞ for b ∈ range(G)…
ValidatedTelecom-timing MTIE and TDEV on a holdover time-error seriestelecom_timing (mtie_sliding,mtie_curve_ns,tdev_curve_ns); allan (mtie,time_deviation)
Capability
The maximum time interval error and time deviation the telecom-timing scenario kind reports, on a telecom-scale holdover record: an O(n) monotonic-queue sliding-window MTIE (telecom_timing::mtie_sliding, needed so a day of one-second samples stays fast) and the engine's TDEV (allan::time_deviation), evaluated on the grid the kind reports and read back out of a full run that ingests the series
Oracle
allantools 2024.06 — an independent third-party frequency-stability library — mtie() and tdev() on tests/fixtures/telecom_timing/holdover_te_series.csv, the series parsed from the same 17-significant-figure text on both sides; the reference records the series' SHA-256 and is regenerable offline via tests/fixtures/telecom_timing/generate_telecom_timing_reference.py. Validates the ESTIMATORS on this record, not the synthetic holdover that produced it
Tests
tests/telecom_timing_reference.rs (17 MTIE and 12 TDEV averaging factors on a committed 2 048-sample chip-scale-atomic-clock holdover series with aging, flicker and temperature, vs allantools 2024.06 to <1e-12 / <1e-9…
ModelledITU-T telecom synchronisation masks with PASS/FAIL and margintelecom_timing (MASKS,eprtc_a_holdover_limit_ns,check_curve,check_mask)
Capability
Transcribed limits of ITU-T G.8272 (07/2025) PRTC-A/B, G.8272.1 (2024) Amd. 1 (07/2025) ePRTC locked and ePRTC-A holdover (including the Table 3 time-error envelope), G.8273.2 (2023) Amd. 2 (11/2025) T-BC/T-TSC classes A-D and G.8271.1 (2022) Amd. 3 (05/2025) reference point C, each open or closed interval as the table states it, with every 'for further study' entry left out; a verdict and a margin at the binding point per check, and the time to exceed each budget. Runnable as the telecom-timing scenario kind
Oracle
Transcription of the named Recommendations (freely downloadable from itu.int), each limit carrying its table or clause, listed with every unconfirmed or unimplemented item in docs/TELECOM-TIMING.md; the breakpoint-continuity identities the tables imply are checked in the tests. A standards transcription with internal consistency checks, not a conformance test and not an external validation
Tests
telecom_timing::tests (mask_boundaries_follow_the_tables_exactly — open and closed ends, the τ = 400 s gap of G.8271.1 Table 7-3, continuity at every breakpoint the tables imply…
ModelledOscillator holdover presets from public datasheetstelecom_timing (PRESETS,fit_noise,with_flicker_floor,synthesize_holdover); models (ClockModel)
Capability
Four presets — OCXO (Microchip OX-208), rubidium (Microchip 8040C), caesium (Microchip 5071A high-performance tube) and CSAC (Microchip SA.45s) — each carrying its datasheet's Allan-deviation maxima, aging and temperature bound; a non-negative least-squares white + flicker + random-walk frequency-noise fit scaled to envelope every datasheet point, a flicker floor never below the longest-τ figure, linear aging and a sinusoidal temperature term, synthesised as a seeded holdover after a GNSS loss
Oracle
The four named Microchip datasheets (document numbers and URLs in each preset and in docs/TELECOM-TIMING.md) for the input figures; the closed-form aging ramp and the fit's envelope property as internal checks. How the figures become a noise model — the fit, the floor rule, the 30-day month, the linear temperature reading — is a modelling choice; no preset is a measurement of a unit
Tests
telecom_timing::tests (every_preset_carries_a_named_datasheet_and_figures; the_noise_fit_envelopes_every_datasheet_point; pure_aging_matches_its_closed_form — the discrete aging ramp within 0.1 % of (1/2)·D·t² over a…
ValidatedHoldover prediction from a measured clock record, checked on held-out dataslot_timing (ClockNoise::from_phase_record,fit_weighted,slot_budget,breach_after_sync_s)
Capability
The slot-timing kind's measured-record path: the overlapping Allan deviation of a phase record fitted by edf-weighted non-negative least squares in the white-phase and IEEE Std 1139 frequency-modulation basis (slot_timing::fit_weighted), then inverted for the coast time at which the time error reaches a threshold (slot_timing::slot_budget). The red-noise floor is measured from the record instead of assumed
Oracle
A real free-running atomic clock: 556 990 one-second phase samples of a 5071A caesium standard measured against a hydrogen maser (A. Wallin, distributed with allantools; pinned commit and SHA-256 in scripts/fetch_cs5071a.sh), the same record tests/cs5071a_reference.rs uses for the estimators. The held-out two thirds are an external measurement the prediction never saw. Data-gated: the realdata-clock workflow fetches the record and runs the test with KSHANA_REQUIRE_REALDATA=1. Validates the fit-then-invert path on a white-FM-dominated atomic standard over coasts up to about 50 000 s; not the datasheet or class sources, not the deterministic terms. NOT a crystal oscillator: on a measured OCXO record (tests/slot_timing_ocxo_holdout.rs, allantools, 5.5 h against a hydrogen maser) the held-out prediction is conservative, at 0.59 to 0.70 of the measured breach, and mostly outside the bar, because that oscillator's noise floor halved during the record; in sample it is within 0.98 to 1.17. The crystal case stays MODELLED. NOT atomic clocks in orbit either: on 10 GPS Block IIF satellite clocks (tests/slot_timing_igs_holdout.rs, IGS final 30 s clocks, 14 days, protocol written before download) 8 land within the bar and 2 (G25, G30) are optimistic by up to about 2x, so under the protocol the orbital case stays MODELLED
Tests
tests/slot_timing_cs5071a_holdout.rs (holdover_inversion_predicts_the_held_out_caesium_record: fit on the first third of the record, predict the one-sigma breach at 0.5, 0.75, 1, 1.5, 2 and 2.5 ns, measure it on the…
ModelledSeconds until a free-running clock leaves a time-indexed slot's guard, and the fix cadence that keeps it insideslot_timing (predicted_error_s,breach_after_sync_s,terms_at,slot_budget,ClockNoise::from_datasheet,SlotTimingScenario); clock_state (ClockClass::Tcxo,Ocxo,Rafs,source)
Capability
The slot-timing kind: the predicted error E(t) = k·√(σ₀² + σ_x²(t)) + (|y₀| + |c_T·ΔT|)·t + ½|D|t² inverted for the breach, the time left, the resynchronisation interval net of the fix latency and fixes per day, each term itemised with the dominant one named; clocks from the six ClockClass defaults (TCXO, OCXO and RAFS added, each citing one datasheet), the telecom-timing presets, an inline datasheet or a measured record; a breach beyond the source's longest averaging time flagged as extrapolated
Oracle
Closed forms for each term alone and the independent holdover::holdover_seconds root-find; the datasheet figures are the named documents (docs/SLOT-TIMING.md). A class default rests on an assumed red-noise floor and a datasheet source is an envelope of maxima, so neither is a measurement of any unit
Tests
tests/slot_timing_igs_holdout.rs (10 GPS Block IIF satellite clocks, 14 days of IGS final clocks: 8 within the 1.5 bar, G25 and G30 optimistic by up to about 2x, pinned); tests/slot_timing_ocxo_holdout.rs (a measured…
ModelledTiming protection level for a receiver in orbit under GNSS spoofingorbital_timing (orbital_timing,visibility_half_angle_rad,max_pass_s,crosslink_neighbour_is_outside_footprint)
Capability
orbital_timing::orbital_timing, reachable as the slot-timing kind's spoofing section: circular-orbit speed and period, the longest time a ground spoofer can reach the satellite per pass, the clock-aided monitor floor and CUSUM detection latency, the conditional protection level (floor plus coast over the latency), the pull a spoofer at a stated maximum ramp rate accumulates before the satellite leaves its footprint or an independent check runs, and whether each ground-contact or crosslink check is independent of one ground spoofer
Oracle
Reduction to the existing timing protection level and the circular-orbit and spherical-Earth visibility closed forms. Conditional on detection, one terrestrial spoofer at a stated ramp rate, an overhead pass on a non-rotating Earth; not validated on a spoofed receiver in orbit
Tests
orbital_timing::tests (reduces_to_the_terrestrial_tpl — exactly tpl::timing_protection_level_ns when the clock has no flicker, white-phase or random-run term; leo_geometry_matches_its_closed_forms…
ValidatedClosed-form L-band signal power spectral densities and spectral separation coefficientsnavsignal (Modulation::psd,spectral_separation_coeff_offset,q_from_ssc); spectrum (psd_nulls_hz,psd_peak_hz,main_lobe_null_to_null_hz,Jammer::ssc)
Capability
Unit-area power spectral densities of GPS L1 C/A and L2C (BPSK(1)), GPS L5 and Galileo E5a (BPSK(10)), sine-BOC(1,1) and Galileo E1 MBOC(6,1,1/11) (navsignal::Modulation::psd, with an MBOC variant added), their numerically located nulls and maxima (spectrum::psd_nulls_hz, psd_peak_hz, main_lobe_null_to_null_hz), and the spectral separation coefficient of a signal against any spectrum at any offset (navsignal::spectral_separation_coeff_offset) or against a tone, flat noise, a chirp or matched noise (spectrum::Jammer::ssc), with the anti-jam coefficient Q = 1/(R_c kappa)
Oracle
Published textbook values: the BPSK(n) main lobe of 2n x 1.023 MHz null to null and the anti-jam coefficients Q = 1 for a narrowband (CW) jammer and Q = 1.5 for a spread-spectrum jammer matched to C/A (Kaplan & Hegarty, Understanding GPS/GNSS, 3rd ed., section 9.4); the BOC(m,n) main lobes centred at plus or minus m x 1.023 MHz (Betz, Binary Offset Carrier Modulations for Radionavigation, NAVIGATION 48(4), 2001); the spectral separation coefficients -61.8, -64.8 and -67.8 dB/Hz for C/A with C/A, BOC(1,1) with BOC(1,1) and C/A with BOC(1,1) (Betz 2001; Hein et al., MBOC: The New Optimized Spreading Modulation Recommended for Galileo L1 OS and GPS L1C, Inside GNSS, May/June 2006), reproduced here from their Parseval autocorrelation closed forms. The BOC(1,1) maximum is not at 1.023 MHz: the lobe spans the carrier null to 2.046 MHz and peaks at 0.759 MHz, and the test pins both. The MBOC mix is the ICD definition, checked for unit area and linearity only
Tests
spectrum::tests (bpsk_main_lobe_null_to_null_is_two_n_times_1_023_mhz — BPSK(1) 2.046 MHz and BPSK(10) 20.46 MHz located numerically on the closed form; boc11_lobes_are_centred_at_plus_minus_1_023_mhz — carrier null…
ModelledL-band spectrum waterfall with per-band J/S and effective C/N0 under a scripted jammer timelinespectrum (SpectrumScenario,SpectrumModel::bin_psd_w_per_hz,SpectrumModel::band_state,effective_cn0_multi_dbhz,system_temp_k,Jammer::power_fraction_in,Jammer::duty)
Capability
The spectrum kind: a frequency-by-time grid of the L-band power spectral density (thermal floor k T_sys with T_sys = T_ant + 290 K (F - 1), the signals at their interface-specification minimum received powers, and continuous-wave, narrowband, chirp and matched-noise jammers with on/off times), each cell averaged over its bin and row (chirps exactly over whole and partial sweeps, jammers by duty), per-band effective C/N0 = [1/(C/N0) + sum (J/S) kappa]^-1 per row, J/S per band, in-band J/S, and an SVG waterfall with C/N0 bars. The report carries a cross-check against the jamming kind's chain on the same link inputs
Oracle
Reduction to the existing jamming kind's anti-jam equation and link budget (the same code, called on the same inputs), and the k T0 F noise-floor closed form. The signal spectra underneath are the validated row above; the jammer powers, timeline and front-end bandwidths are scenario inputs, the spectra are continuous (no spreading-code lines), and no automatic gain control, blanking or antenna pattern acts on the jammer. No measured jammed spectrum is in the repository to check the composite against. The jamming kind's representative Q table (broadband 1.0, CW 1.5) differs from the Q this model derives from the spectra (CW at the carrier 1.0, matched 1.5, flat null-to-null 2.2); the report prints both
Tests
spectrum::tests (agrees_with_the_jamming_kind_chain — J/S equal to jamming::j_over_s_db and effective C/N0 equal to jamming::effective_cn0_dbhz with Q = 1/(R_c kappa) to 1e-9 dB, and the 32.105 dB anchor of the jamming…
ModelledSigMF recording input and output, and Welch spectral estimates of complex IQsigmf (read,write,encode,decode,parse_meta,meta_to_json); spectrum (welch_psd,fft_in_place,synthesise_iq)
Capability
sigmf: read and write Signal Metadata Format recordings (JSON .sigmf-meta with the core global, captures and annotations fields; raw .sigmf-data as cf32_le, ci16_le or ci8, the integer decoders shared with realdata::iqif::load_iq), all on strings and byte buffers. spectrum::welch_psd: Hann-windowed, overlapped, averaged periodograms, density-scaled, on an in-crate radix-2 transform (spectrum::fft_in_place). spectrum::synthesise_iq draws the model as IQ, and the spectrum kind's [iq] section runs model to IQ to SigMF to Welch and compares with the model; its [recording] section estimates a real recording (native builds)
Oracle
Round-trip identities, a direct discrete Fourier transform, and the white-noise, Parseval and Hann equivalent-noise-bandwidth closed forms. The SigMF field names follow the published specification (github.com/sigmf/SigMF), but no externally produced recording is in the repository, so reading a third-party file is untested here and the row stays Modelled. A synthesised periodic chirp shows lines, Fresnel ripple and edge tails the smooth model omits: total power agrees within 2 %, per-bin densities near a chirp do not
ValidatedPlanet positions across the solar system from the JPL Standish Keplerian elementsephem (standish_state,standish_elements,standish_nominal_error,ecliptic_to_icrf); ephem_provider (AnalyticSolarSystem); solar_system (SolarSystemScenario)
Capability
Heliocentric positions of Mercury, Venus, the Earth-Moon barycentre, the Earth, Mars, Jupiter and Saturn from Standish Table 1 (1800 AD to 2050 AD), and of all eight planets from Tables 2a/2b (3000 BC to 3000 AD, with the b, c, s, f mean-anomaly terms), following the JPL page's algorithm step for step and rotated to the ICRF (International Celestial Reference Frame) by the page's obliquity; the Earth is split from the barycentre by the Montenbruck & Gill lunar series and the mass ratio. Composed as ephem_provider::AnalyticSolarSystem so any body is available relative to any other, and runnable as the solar-system kind
Oracle
JPL Horizons geometric heliocentric state vectors in the J2000 ecliptic from DE441, committed in tests/fixtures/solar_system/horizons_heliocentric_ecliptic.csv with the exact query and the retrieval date (2026-09-28). The bar is twice the nominal error the JPL page states for each planet in heliocentric longitude, latitude and distance, set after the first comparison because the page's figures are nominal, not maxima; the observed worst ratio is 1.87. Uranus and Neptune from Table 1 do not meet it and are a separate MODELLED row
Tests
tests/solar_system_horizons_reference.rs (standish_table1_mercury_to_saturn_within_twice_the_nominal_error: 12 epochs 1800 to 2049, worst 1.87 times nominal, Saturn's distance in 2020…
ValidatedLight time between solar-system bodiesradiometric (light_time_solution,two_way_range,shapiro_delay); ephem_provider (AnalyticSolarSystem); solar_system (link)
Capability
The Newtonian one-way light time from any body to any other, received at an epoch, solved by the existing radiometric fixed-point light-time solver (radiometric::light_time_solution, transmitter at its retarded position) on the analytic solar-system ephemeris; the two-way range from radiometric::two_way_range and the Sun's Shapiro delay from radiometric::shapiro_delay, reported separately. Emitted for every body against an observer and for any extra link by the solar-system kind, and for the body-to-Earth downlink by the body-pnt kind
Oracle
JPL Horizons light-time-corrected geocentric vectors with the one-way light time LT (DE441), committed in tests/fixtures/solar_system/horizons_light_time.csv with the query and retrieval date. The bar is twice the sum of the Standish distance errors of the target and the Earth-Moon barycentre, divided by the speed of light: the light time can be no better than the positions. Validates the Newtonian geometric light time at the Standish accuracy, not a relativistic or plasma-corrected observable
Tests
tests/solar_system_horizons_reference.rs (light_time_matches_horizons_within_the_position_bound: Mars and Jupiter to the Earth's centre at four epochs 2000 to 2040 through solar_system::link, solved in the heliocentric…
ModelledUranus and Neptune from Standish Table 1, Pluto, and planetary velocitiesephem (standish_state,StandishElements::state_at_mean_anomaly,Planet::Pluto); solar_system (position_label)
Capability
Positions of Uranus and Neptune from Standish Table 1 (the default inside 1800 AD to 2050 AD), Pluto from the 1992 Table 1 row the current JPL page no longer lists, and the heliocentric velocity of every planet: the two-body derivative with the mean motion the elements imply plus the turning of the ellipse by the perihelion, inclination and node rates
Oracle
Measured against JPL Horizons DE441 (the same committed fixtures), but not validated: Table 1's stated figures for Uranus and Neptune are exceeded by up to 2.0 and 5.2 times against DE441 heliocentric positions (Neptune meets them against barycentric positions, which suggests the fit was not heliocentric), the page states no error for Pluto, and no published bound exists for the velocities. Tables 2a/2b meet their own figures for Uranus and Neptune and are covered by the validated row
Tests
tests/solar_system_horizons_reference.rs (standish_table1_uranus_and_neptune_exceed_the_nominal_error: pinned at 2.04 and 5.16 times the nominal longitude error, under six times…
ModelledPositions of the Moon and seven major moons (Phobos, Deimos, the Galilean moons, Titan)ephem (satellite_state,Satellite,SatelliteMethod,moon_icrf,moon_icrf_velocity); ephem_provider (AnalyticSolarSystem)
Capability
The geocentric Moon from the Montenbruck & Gill series (whose -1.3972 deg per century term already refers it to the J2000 equinox), and planetocentric positions and velocities of Phobos, Deimos, Io, Europa, Ganymede and Callisto from the JPL Solar System Dynamics mean elements in each moon's Laplace plane with the mean-longitude rate taken from the IAU synchronous rotation rate (the table prints the period to too few digits to hold the phase), and of Titan from the IAU rotation model (the moon on minus the body-fixed x axis at the mean distance), because Titan's printed Laplace-plane row does not reproduce Horizons even at its own epoch
Oracle
Measured against JPL Horizons satellite ephemerides (DE441, MAR099, JUP365, SAT441) committed in tests/fixtures/solar_system/horizons_satellites_icrf.csv with the query and retrieval date; no published accuracy exists for mean elements or for the rotation-model placement, so the pinned bars catch regressions and do not validate. Mean elements omit the resonant and solar perturbations, and Phobos' secular acceleration is not modelled
Tests
tests/solar_system_horizons_reference.rs (moons_track_horizons_to_the_measured_angles: worst angular error seen from the planet over 2000 to 2040, Phobos 5.65 deg, Deimos 0.38, Io 0.40, Europa 1.63, Ganymede 0.22…
ModelledPhysical constants of every solar-system body and the whole-system reportbody (Body::by_name,Body::facts,Body::prime_meridian,SOLAR_SYSTEM,BodyFacts); solar_system (SolarSystemScenario,position_label)
Capability
Body gains Mercury, Venus, Jupiter, Saturn, Uranus, Neptune, Pluto, Phobos, Deimos, Io, Europa, Ganymede, Callisto and Titan (gravitational parameter, reference radius, J2 where published with the radius it is referenced to, IAU pole and prime meridian), a name lookup and a BodyFacts record (NAIF code, class, parent, equatorial and mean radius); the solar-system kind reports them for all eighteen bodies with the positions, light times and an orbit track over one revolution, each body labelled VALIDATED or MODELLED
Oracle
Transcription of published constants, each cited where it is defined: gravitational parameters from the JPL Horizons body records and the JPL satellite physical-parameter table, radii from the JPL physical-parameter tables (IAU WGCCRE 2015), poles and prime meridians from the IAU Working Group on Cartographic Coordinates and Rotational Elements (mean values, without the T-rate and periodic terms), J2 from Smith et al. 2012, Iess et al. 2018 and 2019, and Jacobson 2009 and 2014. Checked for internal consistency (the Jupiter rotation period against the System III rate, each J2 against its reference radius), not against an external oracle
ModelledPositioning around any solar-system body with a local constellation and a deep-space link from Earthbody_pnt (BodyPntScenario,formal_sigma,fix_error); orbit (dop); batch_ls (gauss_newton); mars_pnt (chord_clears_sphere); mars_frame (bodyfixed_to_inertial)
Capability
The body-pnt kind: an orbiter or a surface lander around a body chosen by name navigates with one-way pseudoranges from a Walker navigation constellation around the body (two-body orbits with the body's J2 secular drift, an unknown user clock) and an optional clock-free two-way range from the Earth, the Earth's direction and distance from the analytic ephemeris at every epoch; lines of sight blocked by the body's sphere and a surface elevation mask; per epoch the constellation-only GDOP and PDOP (orbit::dop), the formal position uncertainty with and without the Earth row, and seeded Gauss-Newton fixes (batch_ls::gauss_newton) each way, with the body-to-Earth light time and round trip
Oracle
Closed forms and self-consistency: Kepler's third law for the relay period, the orbit radius and the surface radius held over the run, adding a measurement never increasing the formal uncertainty, and the seeded errors agreeing with the covariance. The relay orbits ignore third bodies (Jupiter's pull on relays around Europa is not modelled), the noise is Gaussian at stated levels and the measurement model is instantaneous, so this is not validated against any mission's navigation data
ValidatedWalker constellation geometry and the published nominal slots of GPS, Galileo and GLONASSconstellation (WalkerSpec::elements,gps_slots,galileo_walker,glonass_slots,GPS_BASELINE_SLOTS,GPS_EXPANDABLE_SLOTS)
Capability
The constellation-design kind's generators: Walker delta and star patterns in the T/P/F convention (node spacing 360/P or 180/P, in-plane spacing 360·P/T, inter-plane phase offset 360·F/T), and the GPS baseline and expandable 24-slot, Galileo and GLONASS presets built from their published nominal elements, placed in an Earth-fixed frame by the Greenwich hour angle their documents state
Oracle
Published agency documents: Galileo Open Service Service Definition Document issue 1.1 (European GNSS Service Centre) Tables 1 and 23, the reference constellation at 2016-11-21 00:00 UTC; GLONASS Interface Control Document edition 5.1 (2008) section 5.2, the slot formula for node longitude and argument of latitude; GPS Standard Positioning Service Performance Standard 5th edition (April 2020) Tables 3.2-1, 3.2-2 and 3.2-3, including the groundtrack equatorial crossing column, which is an independent statement of the Earth-fixed geometry the preset must reproduce. Validates the generators and the transcription; the BeiDou medium-orbit phase and inclined-geosynchronous nodes are not published and are not covered
Tests
constellation::tests::walker_24_3_1_reproduces_galileo_os_sdd_table_23 (all 24 RAAN and mean-anomaly rows to 1e-9 deg); constellation::tests::glonass_icd_slot_formula_is_a_walker_24_3_1 (the ICD slot formula and a…
ValidatedGlobal dilution of precision of the GPS baseline constellationconstellation (coverage,dop_at,NormalAccum)
Capability
The constellation-design coverage engine on the GPS baseline 24-slot preset under the GPS Standard Positioning Service Performance Standard (SPS PS) Appendix B conditions (one sidereal day, 287 five-minute steps, a 4 x 4 deg global grid weighted by the cosine of latitude, all in view, 5 deg mask, one receiver clock): the global HDOP distribution, the PDOP median and the PDOP-at-most-6 availability, globally and at the worst site
Oracle
GPS SPS PS 5th edition (April 2020) Appendix B sections B.3.2.2 and B.3.2.3, the published global-average HDOP distribution of the fully occupied baseline 24-slot constellation (median 0.94, 90 % 1.16, 95 % 1.25, 98 % 1.37, mean 0.96), Table 3.8-1 (PDOP availability) and Table B.3-1 (ensemble PDOP of a degraded constellation, used only as an upper bound), plus a hand-derived closed form for one epoch. The VDOP and PDOP distributions of the full constellation are published only as a figure, so PDOP is pinned one-sided; the worst time-space point (HDOP 2.40 and VDOP 5.22 here, 2.49 and 5.43 published) depends on the grid and is reported, not pinned
Tests
constellation::tests::gps_baseline_global_dop_matches_the_sps_performance_standard (HDOP median 0.940, 90 % 1.165, 95 % 1.255, 98 % 1.370, mean 0.965 against 0.94, 1.16, 1.25, 1.37 and 0.96, bar 0.03 on each fixed…
ModelledCoverage and dilution-of-precision maps for arbitrary multi-constellation designs at scale, around any central bodyconstellation (coverage,ConstellationDesignScenario,beidou_slots,body_by_name)
Capability
The constellation-design kind beyond the two pinned cases: explicit and multi-shell designs, several constellations per run with one receiver clock per constellation, the Earth, the Moon and Mars from the body constants, the BeiDou preset (medium-orbit phase and 118 deg E inclined-geosynchronous crossing modelled), per-cell satellites in view, GDOP, PDOP, HDOP, VDOP and availability, downsampled ground tracks, and a sub-satellite-latitude visibility prefilter that runs a 5 000-satellite design on a 10 deg grid in a fraction of a second
Oracle
Internal consistency: the brute-force elevation scan, the hand-computed and orbit::dop reductions, and the closed-form Walker and geosynchronous geometry. Two-body orbits with an optional secular J2, a spherical body with the local vertical along the radius, geometric visibility only (no signal power, satellite health, terrain or third-body perturbation), and the relative phase between systems taken from different reference epochs, so it is not a snapshot of any date
Tests
constellation::tests (prefilter_matches_brute_force_exactly — every map and counter equals a scan with the direct elevation test; five_thousand_satellites_on_a_coarse_grid — 5 000 satellites, prints the run time and…
ModelledA chained mission across scenario kinds on one shared timelinecampaign (run_campaign_detailed,run_chain,presets,extract,to_svg)
Capability
The campaign kind's phases: each phase runs one or more scenarios of existing kinds through run_toml, reads their outputs into named channels (clock time error and guard, mean effective carrier-to-noise density ratio and tracking floor, vertical protection level and alert limit, position error, satellites tracking, alarm flags) by per-kind presets or explicit result paths, places them at the phase start and holds them onto a common grid, with phase boundaries and events; state is handed on by carry (a channel continues from the previous phase's end value), handoff (a previous phase's number written into the next scenario) and end_at (a phase ends at a time a run computed, such as a spoofing monitor's detection time); a campaign hash and a digest over every member result
Oracle
Composition identities against the stand-alone runs of the same kinds: a one-phase campaign reproduces the stand-alone output bit for bit, the carried offset equals the previous run's own last sample, and the phase ended by end_at has exactly the run's detection time as its length. The additive carry across a phase boundary and the zero-order hold are modelling choices, and each phase is as good as the kind that ran it; no chained mission has been checked against a measured one
ModelledParameter sweeps and seeded Monte Carlo ensembles over any scenario kindcampaign (run_sweep,run_monte_carlo,ensemble); sweep (GenericAxis,coords_of,set_dotted_value); inertial (metric_stat)
Capability
The campaign kind's sweep (one to three dotted keys of any kind, on the generic sweep's axis values, optionally an ensemble at every node) and monte_carlo sections: realisation k runs at base_seed + k; each metric reports mean, standard deviation, nearest-rank 5th/50th/95th percentiles and a fixed-seed percentile-bootstrap 95% confidence interval on the mean (inertial::metric_stat); metric units read from the swept kind's own units block
Oracle
The closed form of the phase random walk under white frequency noise, variance q_wf tau (NIST Technical Note 1337), for the statistics machinery, and byte equality with the stand-alone runs for the seeding. It checks the ensemble arithmetic on the engine's own clock model, not an external dataset
Tests
tests/campaign_composition_reference.rs (a_fixed_seed_ensemble_is_byte_stable_and_each_realisation_is_the_standalone_run; the_ensemble_mean_and_spread_match_the_white_fm_closed_form — 200 seeds of a…
ModelledSeveral scenarios under shared conditions, with a combined summarycampaign (run_compose)
Capability
The campaign kind's compose section: named shared values (for example one jammer's power and position) written into each member at the keys it binds them to, every member run, and per metric the smallest, largest and mean value across the members with the member named; metric units must agree across members
Oracle
Composition identity against the stand-alone run. The shared-condition arithmetic is bookkeeping; the physics is that of the member kinds, each with its own row
Tests
tests/campaign_composition_reference.rs (a_one_node_sweep_and_a_one_member_composition_read_the_standalone_number — a one-member composition reads the stand-alone number and result digest)
ValidatedBand-limited closed forms for any ranging signal: power in band and early-late code-tracking jitter against published values, with the Gabor bandwidth and offset spectral separation cross-checkednavsignal (sine_integral,bpsk_power_in_band_closed_form,bpsk_gabor_bandwidth_closed_form_hz,dll_jitter_bandlimited_s,dll_jitter_small_spacing_limit_s,bpsk_offset_ssc_closed_form,altboc_15_10_psd,parse_modulation)
Capability
navsignal: the sine integral (sine_integral), the BPSK-R fraction of power inside a double-sided band in closed form (bpsk_power_in_band_closed_form), the band-limited BPSK Gabor bandwidth in closed form (bpsk_gabor_bandwidth_closed_form_hz), the band-limited coherent and non-coherent early-late delay-lock-loop jitter for any unit-area spectrum after Betz & Kolodziejski 2009 (dll_jitter_bandlimited_s) and its vanishing-spacing Gabor bound (dll_jitter_small_spacing_limit_s), the offset BPSK spectral separation coefficient in closed form (bpsk_offset_ssc_closed_form), the Galileo E5 AltBOC(15,10) spectrum (altboc_15_10_psd) and a modulation-label parser (parse_modulation); used by the leo-signal kind for every signal design
Oracle
Externally pinned: 90.3 per cent main-lobe power, the coherent early-late jitter at the stated operating point, the sine-integral table values, and the BPSK self spectral separation coefficient 2/(3 R_c) at zero offset. Internal cross-checks only, not external validation: the band-limited BPSK Gabor-bandwidth closed form and its asymptote, and the offset BPSK spectral separation coefficient at non-zero offsets, both derived here and checked against quadrature. Published closed forms: the BPSK-R sinc-squared spectrum and its 90 per cent main-lobe power (Kaplan & Hegarty, Understanding GPS/GNSS, 3rd ed.); the coherent early-late code-tracking jitter sigma^2 = B_L d / (2 C/N0) chips^2 (Kaplan & Hegarty, section 8) and the band-limited generalisation with its Gabor-bandwidth limit (Betz & Kolodziejski, Generalized Theory of Code Tracking with an Early-Late Discriminator, Part I, IEEE Transactions on Aerospace and Electronic Systems 45(4), 2009); the sine-integral tables of Abramowitz & Stegun (Table 5.1); the spectral separation coefficient as the Fourier transform of the squared autocorrelation (Betz 2001). The AltBOC spectrum is checked for unit area and lobe position only (the Galileo Open Service Signal-in-Space Interface Control Document expression integrates to 8 and is divided by it).
Tests
navsignal::band_limited_tests (sine_integral_matches_tables_and_its_limit — Si(1), Si(pi), Si(2 pi) to 1e-12; bpsk_power_in_band_closed_form_matches_textbook_and_numeric — 0.9028 of the power in the main lobe for…
ValidatedMaximum Doppler of a low Earth orbit navigation satellite, which sizes the acquisition searchleo_signal (max_doppler_hz)
Capability
leo_signal::max_doppler_hz: the largest satellite Doppler on an overhead pass at the elevation mask for a circular orbit, v R_E cos(el) / (R_E + h) times f / c, from each preset's own carrier and orbit altitude; the leo-signal kind adds oscillator and user terms and turns it into Doppler bins
Oracle
Published figures: Xona Pulsar X1 maximum Doppler 32 to 34 kHz (Leclère, Marathe & Reid, ION GNSS+ 2025, https://arxiv.org/abs/2509.19551); Iridium Doppler up to +/-36 kHz (Resilient Navigation and Timing Foundation, Recent PNT Improvements and Test Results Based on Low Earth Orbit Satellites). Earth rotation is left out, which moves the figure by up to about 2.3 kHz; both published figures are met without it.
Tests
leo_signal::tests::max_doppler_matches_published_xona_and_iridium_figures — Xona Pulsar X1 (1593.3225 MHz, 1080 km) 33.2 kHz inside the published 32 to 34 kHz; Iridium (1621 MHz, 780 km) within 0.5 kHz of the published…
ModelledLow Earth orbit positioning, navigation and timing signal designs: code tracking, acquisition, GNSS compatibility and a band trade for any systemleo_signal (LeoSignalScenario,SignalDesign,Component,Shape,code_jitter_m,gabor_bandwidth_hz,detection_probability,threshold_for_pfa,mean_acquisition_time_s,ssc_leo_into_gnss,ssc_gnss_into_leo,jammer_tolerance,gnss_victim,preset,public_signal)
Capability
The leo-signal kind: parameterised signal designs (band, transmit bandwidth, ITU allocation; acquisition, data and pilot components with BPSK(n), BOC(m,n), MBOC or flat spectra, power shares, FDMA sub-carriers, code lengths and data rates) from compiled-in public preset files (Xona Pulsar, Iridium STL, Starlink signal of opportunity, CentiSpace, a generic C-band design and generic UHF/L/S/C/wide-C designs, each with its source URL and unpublished values labelled REPRESENTATIVE) or written inline; per signal the band-limited power spectral density, in-band power fractions, Gabor bandwidth, code jitter against C/N0 and spacing and the ranging accuracy, the acquisition search space, square-law detection probability and mean serial and code-parallel acquisition time, the spectral separation coefficient into and from GPS L1 C/A, Galileo E1, GPS L5, Galileo E5a, E5b and AltBOC with the C/N0 degradation, and the CW, wideband and matched J/S tolerance from the spectrum kind's SSC chain; a band trade of ionospheric delay, free-space loss, ranging accuracy at equal C/N0 and equal EIRP and jammer tolerance; and qualitative shape checks of a design against a described measurement
Oracle
The validated closed forms of the two rows above, the square-law false-alarm identity P_d(snr = 0) = P_fa and Holmes's mean acquisition time, and reduction to the spectrum kind's own SSC chain (the same Jammer::ssc code). The designs themselves are inputs: presets marked REPRESENTATIVE or WORKSHOP are not published specifications, enhanced Feher QPSK, code shift keying and OFDM spectra are approximated, and the shape checks compare shapes, not calibrated levels.
ModelledMulti-band spectrum waterfall (UHF, L, S, C) with designed signals and per-band jammersspectrum (Band::unit_psd,Band::tracked_power_dbw,BandDesign,BandCfg,PanelCfg,SpectrumScenario,Waveform,multi_band_svg); leo_signal (SignalDesign::to_spectrum_band)
Capability
The spectrum kind extended beyond the L band: bands given as a preset signal design (drawn with every component, band-limited to the transmit bandwidth, C/N0 and J/S referred to the tracked component) or as a custom carrier and modulation; extra waterfall panels over any frequency range on the same timeline and colour scale; a wideband (barrage) jammer beside CW, narrowband, chirp and matched noise; per-band J/S and effective C/N0 from the unchanged spectral separation coefficient chain
Oracle
Reduction to the existing spectrum chain and the jamming kind's anti-jam equation (a single-component band gives the same numbers as before the extension) and the signal spectra of the validated rows. The jammer powers, timeline, front-end bandwidths and the designed signals are inputs, and a designed signal is truncated at its transmit band (no out-of-band emission).
Tests
tests/leo_signal_reference.rs (the multi-band waterfall runs with four panels, the UHF, L5-band, S and C jammers each deny only their own band, and a plain-band run is unchanged by the extension)…
ValidatedRain specific-attenuation coefficients for any band a LEO-PNT link usesleo_link::itu (p838_coefficients,p838_k_alpha,rain_specific_attenuation_db_km)
Capability
ITU-R (International Telecommunication Union, Radiocommunication Sector) P.838-3 equations (1) to (5): k_H, alpha_H, k_V, alpha_V from the Tables 1 to 4 curve fits, the path- and polarisation-dependent (k, alpha) and the specific attenuation k R^alpha; used by the leo-pass kind's rain term
Oracle
ITU-R P.838-3 (03/2005) Table 5, the Recommendation's own tabulated k_H, alpha_H, k_V, alpha_V, committed in tests/fixtures/leo_link/p838_3_table5.csv with the PDF URL and retrieval date. The table is rounded to its printed digits, so the bar is that rounding
Tests
tests/leo_link_reference.rs (p838_coefficients_reproduce_table5_to_its_printed_digits: all 115 rows of Table 5, 1 GHz to 1000 GHz, every coefficient within 0.6 of its last printed digit; worst observed 0.51)
ValidatedLong-term slant-path rain attenuation on an Earth-space linkleo_link::itu (p618_rain_attenuation_db,RainPath)
Capability
ITU-R P.618-14 section 2.2.1.1 steps 2 to 10 (slant and horizontal path below the rain height, horizontal reduction and vertical adjustment factors, A0.01 and its scaling to 0.001 % to 5 % of an average year), with the rain height (P.839) and R0.01 (P.837) as inputs because the engine carries neither digital map; applied per band and epoch by the leo-pass kind
Oracle
ITU-R Study Group 3 validation examples file CG-3M3J-13-ValEx-Rev8.3.0 for P.618-14, as tabulated by the ITU-Rpy validation pages, with each site's P.839-4 rain height from the same examples; committed in tests/fixtures/leo_link/p618_14_rain_attenuation.csv with the URLs and retrieval date. Validates the procedure given h_R and R0.01, not the maps
Tests
tests/leo_link_reference.rs (p618_rain_attenuation_matches_the_itu_validation_examples: 56 cases at five sites, 14.25 and 29 GHz, 0.001 % to 1 %, within 1e-4 dB; observed 5e-6 dB)
ValidatedTropospheric amplitude scintillation on an Earth-space linkleo_link::itu (p618_scintillation_db,wet_refractivity,ScintillationPath)
Capability
ITU-R P.618-14 section 2.4.1 steps 3 to 9 (reference sigma from N_wet, effective path length, antenna averaging factor, fade depth for 0.01 % to 50 % of the time), with N_wet an input or computed from temperature, humidity and pressure by the ITU-R P.453-14 expressions; below 4 GHz the leo-pass kind flags the value as an extrapolation
Oracle
ITU-R Study Group 3 validation examples (CG-3M3J-13-ValEx-Rev8.3.0) for P.618-14 scintillation, with each site's P.453-14 N_wet from the same examples; committed in tests/fixtures/leo_link/p618_14_scintillation.csv with the URLs and retrieval date. The wet-refractivity expression from temperature and humidity is not covered by this row
Tests
tests/leo_link_reference.rs (p618_scintillation_matches_the_itu_validation_examples: 42 cases at seven sites, 14.25 and 20 GHz, within 1e-5 dB; observed 5e-7 dB)
ValidatedBuilding entry loss for an indoor LEO-PNT userleo_link::itu (p2109_building_entry_loss_db,BuildingClass); detection (normal_inv_cdf)
Capability
ITU-R P.2109-2 Annex 1 equations (1) to (10) with Table 1: the loss not exceeded with probability P for traditional and thermally-efficient buildings at the elevation of the path at the facade, 80 MHz to 100 GHz; applied per band and epoch to an indoor user by the leo-pass kind (the UHF indoor case)
Oracle
The ITU-R Study Group 3 Clutter and BEL validation workbook values, as transcribed in the reference MATLAB implementation's validation script (github.com/eeveetza/p2109), committed in tests/fixtures/leo_link/p2109_bel.csv with the URL and retrieval date. The workbook prints three decimals
Tests
tests/leo_link_reference.rs (p2109_building_entry_loss_matches_the_itu_workbook: 568 values, 28 GHz at 0 deg and 2 GHz at 45 deg, both classes, P from 1e-7 to 0.998, within 0.001 dB)
ValidatedFirst-order ionospheric delay per band, the ionosphere-free combination and free-space lossleo_link::iono (group_delay_m,iono_free_coefficients,iono_free_noise_amplification); leo_link (fspl_db); linkbudget (free_space_loss_db)
Capability
Group delay 40.3 STEC/f^2 per band; the ionosphere-free coefficients f1^2/(f1^2 - f2^2) and -f2^2/(f1^2 - f2^2) and the noise amplification sqrt(a1^2 s1^2 + a2^2 s2^2) for any band pair; the free-space loss 20 log10(4 pi R f/c) of linkbudget::free_space_loss_db in its kilometre-megahertz form
Oracle
IS-GPS-200 section 20.3.3.3.3.2, which states the L1/L2 group-delay ratio gamma = (77/60)^2 that follows from first-order 1/f^2 scaling, and the Friis transmission formula (Proc. IRE, 1946). Validates the scaling laws, not a slant TEC
Tests
tests/leo_link_reference.rs (first_order_iono_reproduces_the_is_gps_200_group_delay_ratio: gamma = (77/60)^2 to 1e-12, L1/L2 and L1/L5 amplification 2.978 and 2.588…
ValidatedMaximum Doppler a static user sees from a LEO or MEO orbitleo_link::geometry (max_static_user_range_rate,DopplerEnvelope,doppler_hz)
Capability
leo_link::geometry::max_static_user_range_rate: a search over every orbit position and every user on the satellite's horizon of a circular orbit, with the Earth turning, for the largest range rate, plus the orbital and largest Earth-fixed satellite speeds; reported per band as the Doppler envelope by the leo-pass kind and used as the cold-start search window of its low-energy model
Oracle
Leclere, Marathe and Reid, Insights into Xona Pulsar LEO PNT: Constellation, Signals, and Receiver Design, ION GNSS+ 2025, arXiv 2509.19551, Table 1 (static receiver on a 6371 km sphere, Earth rotation the only other effect): 37751.7 / 33628.5 / 31813.4 / 4018.4 Hz on L1. Covers circular two-body orbits
Tests
tests/leo_link_reference.rs (doppler_envelope_reproduces_the_pulsar_paper_table_1: Pulsar IOV 520 km 97 deg, Pulsar FOC polar 1080 km 97 deg, Pulsar FOC inclined 1080 km 53 deg and GPS 20180 km 55 deg; orbital speed…
ModelledA LEO-PNT pass and its per-band link budget against the MEO GNSS satellites in viewleo_pass (LeoPassScenario); leo_link::geometry (design_pass,link_geometry,numerical_check,SatMotion,UserMotion); leo_link::antenna; leo_link::itu (p676_gaseous_attenuation_db); leo_link (system_noise_temperature_k,cn0_dbhz)
Capability
The leo-pass kind: satellites from a designed pass, elements, a TLE through SGP4 or a Walker constellation from constellation-design; per band and epoch the look angles, range, closed-form range rate and range acceleration (checked each run against central differences and reported), free-space loss, EIRP with an isoflux, Gaussian or flat pattern, a patch, hemispherical or isotropic user antenna, ITU-R P.676-10 Annex 2 gaseous attenuation, P.618 rain and scintillation, P.2109 building entry loss, polarisation mismatch, system noise temperature, C/N0, Doppler and Doppler rate, and the first-order delay from a Klobuchar or vertical-TEC slant TEC scaled by the Chapman fraction below the satellite; ionosphere-free pairs with code noise at the pass peak; Galileo or GPS carriers from their interface-document received powers through the same receiver
Oracle
Closed forms and self-consistency: the range-rate and range-acceleration identities against numerical derivatives, the isoflux gain cancelling the range growth, the textbook polarisation-loss limits, the qualitative LEO-versus-GNSS observation (a bell-shaped pass of minutes peaking several dB above flat 44-51 dB-Hz GNSS carriers). The EIRPs and patterns are published received powers turned into an EIRP or representative choices, the gaseous term is the superseded P.676-10 simplified method, and nothing is compared with a measured LEO C/N0
Tests
leo_pass::tests (the_leo_pass_is_a_bell_above_flat_gnss; closed_form_doppler_agrees_with_the_numerical_derivative: under 0.01 Hz and 0.01 Hz/s; indoor_uhf_suffers_less_building_loss_than_c_band…
ModelledNamed LEO-PNT system presets with stated sources, and a system-agnostic engineleo_link::presets (SystemPreset,BandPreset,all,by_id,gnss_meo); leo_pass (resolve_bands)
Capability
leo_link::presets: generic multi-band (UHF, L, S, C), generic C band, Xona Pulsar X1/X5, Iridium STL, Starlink as a Doppler-only signal of opportunity, CentiSpace and an optional Celeste IOD preset, each with its source marked PUBLIC (with URL), REPRESENTATIVE or WORKSHOP, the workshop one in the optional Celeste IOD preset file, compiled in only when that file exists; every band and orbit overridable in a scenario, and a scenario may name no preset at all
Oracle
Transcription of the cited public figures and a consistency check: an EIRP set from a published minimum received power predicts the published maximum within 0.5 dB with a flat pattern. That is a check of the range spread, not a validation of any satellite's antenna; representative presets make no claim about a real system
ModelledLow-energy positioning: time to first fix and energy per fix against duty cycleleo_link::energy (fix_budget,duty_curve,IotReceiver,IotSignal); leo_pass (iot_section)
Capability
leo_link::energy and the leo-pass kind's [iot] section: coherent integration capped by the Doppler rate, square-law non-coherent sums to a detection threshold, a Doppler-bin search over the orbit's static-user envelope (cold) or an aided window (hot), parallel or serial code search, navigation-message time on a cold start, energy per fix and battery life across fix intervals, for each LEO band and the GNSS signal
Oracle
Internal consistency of a stated design model: every power, threshold and search choice is an input, and the model ignores bit-edge ambiguity, missed detection and re-acquisition. Not compared with a measured receiver
ValidatedGlobal-average signal-in-space range error weights for any orbit altitudeleo_navmsg::sisre (sisre_weights,StatsAcc)
Capability
leo_navmsg::sisre::sisre_weights: the radial weight w_R and the squared transverse weight w_AC^2 as averages of cos^2 and half sin^2 of the line-of-sight nadir angle over users uniformly distributed on the visible Earth cap above an elevation mask, for any orbit radius, by Simpson integration; used by every leo-navmsg SISRE figure (at 510 km, w_R 0.46 and w_AC^2 1/2.5)
Oracle
The published SISRE weighting-factor table of Montenbruck, Steigenberger and Hauschild (2018), Multi-GNSS signal-in-space range error assessment - Methodology and results, Advances in Space Research 61(12):3020-3038, doi 10.1016/j.asr.2018.03.041: GPS 0.98 and 1/49, GLONASS 0.98 and 1/45, Galileo 0.98 and 1/61, BeiDou MEO 0.98 and 1/54, BeiDou IGSO/GEO 0.99 and 1/126. The same average evaluated at LEO radii gives the LEO weights; no published LEO table is pinned, so the LEO values are the validated method applied, not separately validated
Tests
leo_navmsg::sisre::tests (weights_reproduce_the_published_meo_and_geo_table — GPS 0.979 and 1/48.9, GLONASS 1/45.0, Galileo 0.984 and 1/61.1, BeiDou MEO 1/54.2, geostationary 0.992 and 1/126.2 at a 0 deg mask, each…
ValidatedGalileo ICD broadcast-ephemeris user algorithm as the base of a LEO navigation messageleo_navmsg::elements (kepler_point,kepler_frame,ephemeris_at,sat_state)
Capability
leo_navmsg::elements::kepler_point: the Galileo OS SIS ICD Keplerian evaluation (Kepler's equation, second-harmonic corrections, Earth-fixed node) written separately from the engine's RINEX evaluator, returning the position with the argument of latitude, inclination and node the along/cross/radial correction frame is built from, and the Liu et al. 2025 extension terms
Oracle
RTKLIB 2.4.2-p13 eph2pos ECEF positions (an independent implementation of the same ICD algorithm) for real BKG/IGS broadcast records of 2024-09-10, both committed with provenance in tests/fixtures/rinex_sp3_interop (NOTICE, rinex_ecef_reference.txt, brdc_multignss_slice.rnx). This validates the Keplerian user algorithm; the along/cross/radial corrections and the Liu terms added on top are Kshana's and are covered by the modelled rows below
Tests
tests/leo_navmsg_reference.rs (the_galileo_user_algorithm_reproduces_rtklib_to_a_millimetre — four real Galileo broadcast ephemerides E10, E19, E24, E25 at tk = 0, +/-600, +/-1800, +/-3600 s, every axis within 1 mm of…
ValidatedCRC-24Q frame check for the LEO navigation messageleo_navmsg::codec (crc24q,encode,decode)
Capability
leo_navmsg::codec::crc24q: generator polynomial 0x1864CFB, initial value 0, no reflection, no final XOR, the check the Kshana LEO frame carries over every preceding byte
Oracle
The CRC catalogue check value for these parameters (reveng.sourceforge.io CRC catalogue, CRC-24/LTE-A: width 24, poly 0x864CFB, init 0, check 0xCDE703), which are the CRC-24Q parameters of RTCM 10403 and the Galileo OS SIS ICD, and the message-type 1005 example frame printed in RTCM 10403
Tests
leo_navmsg::codec::tests (crc24q_matches_the_catalogue_check_value — 0xCDE703 for the ASCII string 123456789; crc24q_matches_the_rtcm_1005_example_frame — the three check bytes 0x360B98 of the RTCM 10403 message-type…
ModelledLEO broadcast-ephemeris fitter and signal-in-space range error versus fit interval and update periodleo_navmsg::fit (fit_message,lstsq,polyfit); leo_navmsg::truth (TruthOrbit,TruthClock); leo_navmsg (sequence_stats,LeoNavmsgScenario)
Capability
The leo-navmsg kind's fitter and trade: a truth orbit integrated with zonal J2-J6 or EGM2008 gravity to the chosen degree and drag, and a seeded free or steered clock; a Levenberg-Marquardt fit of the Galileo Keplerian set on non-singular elements with weak priors, then along-track, cross-track and radial correction polynomials by linear least squares; the clock polynomial fitted net of the user's relativistic term; SISRE (orbit-only and with clock) over usage periods centred in their fit windows, versus fit interval and update period
Oracle
Internal consistency: a two-body truth is recovered by the 16-parameter set to below 1 mm (the model is exact there), and a J2-J6 truth over one minute by the corrected set to below 1 mm. The SISRE figures are the representation error against Kshana's own integrated truth; no orbit determination or prediction error is modelled and no real LEO broadcast message is in the repository to compare with
ModelledMid-pass LEO navigation message update with a continuity check at the switchleo_navmsg (LeoNavmsgScenario::midpass,worst_case_jump,elevation,geodetic_to_ecef)
Capability
The leo-navmsg midpass-update analysis: the highest pass over a user within a search span, messages on a global schedule with usage periods centred in their fit windows, and at each switch the 3D position jump, the clock jump, the user pseudorange jump, the largest jump over any visible line of sight (closed form over the nadir cone), the range error before and after, and PASS/FAIL against a threshold
Oracle
Internal consistency (the jump identity and the cone bound against brute-force sampling). The threshold is an input; no published LEO continuity requirement is pinned
Tests
leo_navmsg::tests::a_mid_pass_update_is_continuous (every switch's range jump equals the change in range error, and a corrected 300 s fit updated every 150 s passes a 5 cm threshold)…
ModelledDocumented binary encoding of the LEO navigation message with a quantisation-error budgetleo_navmsg::codec (encode,decode,write_payload,read_payload,field_table,quantisation_budget)
Capability
leo_navmsg::codec: Kshana's own frame (preamble, version, model, length, payload, CRC-24Q) for the four ephemeris models, the clock polynomial, SVID, issue of data, band, health, a Klobuchar set, NeQuick-G coefficients and UTC parameters, every field with a stated width and step (field_table), quantisation with range refusal, and a budget of the largest position and clock change a half-step change of each field makes over the validity window
Oracle
Round-trip identities and the budget itself. The format is Kshana's own, modelled on the published message components and the Galileo ICD field set; it is not the bit layout of Celeste or any other system (none is public), so there is no external layout to validate against
Tests
leo_navmsg::codec::tests (signed_fields_round_trip_through_the_bit_packer; week8_resolves_near_the_reference); leo_navmsg::tests::every_model_round_trips_through_the_binary_frame (every model within 2 mm of the exact…
ModelledRINEX-4-style and CSV exports of LEO navigation messagesleo_navmsg::text (rinex_export,rinex_import,csv_export,csv_import,calendar,from_calendar)
Capability
leo_navmsg::text: a RINEX-4-style block (> EPH record header, satellite and epoch line with three clock terms, D19.12 broadcast-orbit lines) with system letter L and record types KP16, KRAC, LU22 and APOL, labelled in every header as a Kshana extension not part of RINEX 4.02, and a CSV table with a default column schema and preset schemas, each with an importer
Oracle
Round trips and the calendar arithmetic. RINEX 4.02 defines no LEO navigation records (IGS RINEX 4.02), so the layout is a documented extension with arXiv 2401.17767 cited as prior art; no external reader of it exists to check against
Tests
leo_navmsg::text::tests (calendar_round_trips_and_knows_the_gps_origin; d19_is_rinex_shaped); leo_navmsg::tests::rinex_and_csv_round_trips (every model within 0.1 mm after the text block, the CSV exact)
ModelledSelectable LEO ephemeris models: the Liu et al. 2025 22-parameter model and the ATOMIC zero-clock polynomialleo_navmsg::elements (kepler_point,ephemeris_at); leo_navmsg::fit (fit_message); leo_navmsg (liu_comparison,LIU2025_TABLE)
Capability
leo_navmsg::elements::EphemerisModel, variant Liu22 (the 16-parameter set plus a semi-major-axis rate, a mean-motion rate and once- and three-per-revolution radius harmonics, as Kshana reads the paper's parameter list) and EcefPoly (a per-axis ECEF polynomial with no clock terms, the relativistic term from -2 r.v/c^2, scored against a steered clock); the model-comparison analysis and Kshana's 22-parameter fit at the paper's five altitudes over 20-minute arcs beside the published SISRE
Oracle
Liu, Su, Xie, Zhou and Qu (2025), Remote Sensing 17(16):2894, doi 10.3390/rs17162894, SISRE 8.88, 6.21, 2.87, 2.11 and 0.75 cm at 320, 475, 786, 966 and 1336 km over a 20-minute arc, is printed beside Kshana's figures, not pinned: the paper fitted real precise science orbits and its full text (the exact parameter equations) was not accessible, so the setups differ. ATOMIC model facts from InsideGNSS (6th-order polynomial, about one minute validity, 30 s refresh, clock steered, 24 cm clock error)
ModelledSingle-frequency ionospheric and UTC services of a LEO navigation messageleo_navmsg::services (klobuchar_delay_m,effective_ionisation_level,system_to_utc)
Capability
leo_navmsg::services: the Klobuchar broadcast delay at any carrier (the engine's L1 model scaled by (f_L1/f)^2), the NeQuick-G effective ionisation level Az = ai0 + ai1 mu + ai2 mu^2 with the all-zero and [0, 400] sfu rules, and system time to UTC with the ICD's three leap-second cases
Oracle
The ICD formulas (IS-GPS-200 section 20.3.3.5.2.5 for Klobuchar, Galileo OS SIS ICD sections 5.1.6 and 5.1.7 and the Galileo single-frequency ionospheric algorithm for NeQuick-G Az and UTC) as closed forms, and the RTKLIB-checked L1 Klobuchar model the delay reuses. The NeQuick electron-density integration is not implemented, and no correction is made for a LEO satellite flying inside the ionosphere
Tests
leo_navmsg::services::tests (klobuchar_scales_with_inverse_frequency_squared — the L1 value is RTKLIB's 6.1278 m; nequick_az_rules; utc_without_an_event_is_tow_minus_leap_seconds_folded_to_a_day…
ValidatedDoppler a ground receiver must handle from a LEO navigation satelliteleo_fusion::geom (EarthOrbit); leo_fusion::doppler (range_rate,doppler_envelope)
Capability
Exact range rate of a satellite whose Earth-fixed position and velocity come from a two-body orbit with the secular J2 drift and the Earth's rotation (leo_fusion::geom::EarthOrbit::state, velocity the exact time derivative of the position), turned into Doppler at a carrier; the largest absolute Doppler, Doppler rate and jerk above an elevation mask over a window (leo_fusion::doppler::doppler_envelope), reported per LEO system by the leo-pvt kind in doppler mode
Oracle
Published figures reproduced from the stated orbit and carrier: Iridium Doppler up to plus or minus 36 kHz (Resilient Navigation and Timing Foundation, Recent PNT improvements and test results based on LEO satellites) and Xona Pulsar X1 maximum Doppler 32 to 34 kHz (Leclère, Marathe and Reid, ION GNSS+ 2025, arXiv:2509.19551). The Iridium figure is a rounded upper bound, hence the 5% bar. The Doppler rate and jerk are reported but not validated: the modelled overhead-pass jerk of Pulsar X1 is about 1.0 Hz/s^2 against the published 1.26
Tests
tests/leo_doppler_reference.rs (iridium_doppler_reaches_the_published_36_khz: one satellite at 780 km and 86.4 deg flown for a day at 1621 MHz over four latitudes, maximum within 5% of 36 kHz…
ModelledPositioning from LEO Doppler, single- and multi-satellite, with clock-drift and velocity statesleo_fusion::doppler (solve,formal_covariance,single_pass_geometry,offset_site,closest_approach); leo_fusion::pvt_kind (run_doppler)
Capability
Batch Gauss-Newton positioning from range rate with analytic partials (d rho_dot / d r = -(I - u u^T)(v_s - v_u)/rho, d/dv = -u, d/d drift = 1), a constant user velocity as an option, a height pseudo-measurement for a surface user, damped steps; the formal covariance at the truth; along-track, cross-track and vertical projections; the single-pass accuracy against the user's cross-track offset; the time of closest approach. The leo-pvt kind's doppler mode adds the error against window length and a Doppler-only signals-of-opportunity mode (the starlink-sop preset)
Oracle
Internal consistency: noise-free recovery, the kinematic identity rho_ddot = (|v|^2 - rho_dot^2 + d.a)/rho differentiated numerically, zero Doppler at closest approach, the mirror solution of a single pass, and seeded errors against the formal covariance. The Starlink figure of Kozhaya, Saroufim and Kassas (NAVIGATION 72(1), 2025: about 2 m in 20 s with three satellites) is a comparison only: the modelled receiver, with a perfect ephemeris and every error in a 30 Hz Doppler sigma, is several times less accurate over the same window, and the paper's receiver and measurement rate are not reproduced
Tests
leo_fusion::doppler::tests (range_acceleration_obeys_the_kinematic_identity_and_vanishes_doppler_at_closest_approach; noise_free_multi_satellite_doppler_recovers_the_user: to 1 mm and the drift to 1e-6 m/s…
ModelledJoint GNSS and LEO pseudorange positioning with inter-system biases and per-signal error modelsleo_fusion::joint_pvt (solve,dop,code_sigma_dll_m,SystemClock); leo_fusion::system (SystemCfg,System); leo_fusion::pvt_kind (run_joint)
Capability
Weighted least-squares Gauss-Newton fixes over any mix of systems, one receiver clock per system (the inter-system bias estimated with the position) or a known broadcast offset on the reference time scale; per-measurement sigmas supplied by the caller, by default the engine's delay-lock-loop thermal noise (navsignal::dll_code_jitter_chips) at the C/N0 of the elevation combined with the signal-in-space range error; unweighted DOP (GDOP, PDOP, HDOP, VDOP, TDOP) in the local geodetic frame, formal east-north-up sigmas and the bias sigmas; the leo-pvt joint mode compares GNSS-only, LEO-only and fused fixes and sweeps the DOP against the number of LEO satellites added
Oracle
A hand-derived four-satellite DOP (one satellite at the zenith and three on the horizon 120 deg apart, whose normal matrix inverts by hand), the structural identity that a system with its own clock and one satellite adds no geometry, noise-free recovery of position, clock and bias, and seeded errors against the covariance. Internal checks only; not compared with a receiver's output
ModelledPrecise point positioning convergence with GNSS only and with LEO augmentationleo_fusion::ppp (run,PppScenario,LI_2019)
Capability
A float PPP extended Kalman filter on ionosphere-free code and phase: static coordinates, a white receiver clock, one inter-system bias per extra system, a random-walk zenith wet delay mapped by 1/sin(elevation), a float ambiguity per satellite arc added at rise and dropped at set, and the precise orbit-and-clock error common to a satellite's code and phase, processed as one correlated two-row update in a Joseph-stabilised form; measurements simulated from the same model; convergence time (errors below the thresholds until the end of the run), error curves and the run-averaged position NEES for GNSS only and each LEO case, run as the leo-ppp kind
Oracle
The NEES chi-square test is an internal consistency check (truth and filter share the model). The trend is compared with Li et al., LEO constellation-augmented multi-GNSS for rapid PPP convergence, J. Geod. 93:749-764 (2019), doi 10.1007/s00190-018-1195-2: multi-GNSS 9.6 min shortened to 7.0, 3.2, 2.1 and 1.3 min with 60, 96, 192 and 288 LEO satellites. The bundled scenario gives 7.4, 4.8, 3.2, 2.7 and 2.3 min with its own representative 1000 km, 60 deg shells, noise and stations; the paper's constellations, noise and convergence definition are not reproduced, so this is a MODELLED consistency of the trend (monotone shortening, the largest constellation under a third of the GNSS-only time), not a validation
Tests
leo_fusion::ppp::tests (the_filter_is_consistent_over_monte_carlo_seeds: 24 seeds, run-averaged NEES mean in [2.4, 3.6] and at least 75% of epochs inside the two-sided 95% chi-square band; measured with 150 seeds, mean…
Modelled5G non-terrestrial-network positioning accuracy from signal bandwidthleo_fusion::ntn (gabor_bandwidth_flat_hz,gabor_bandwidth_bpsk_hz,gabor_bandwidth_numeric_hz,toa_crb_sigma_m,doppler_crb_sigma_hz,NtnScenario)
Capability
The Cramér-Rao bound on time of arrival from the root-mean-square (Gabor) bandwidth, c/(2 pi beta sqrt(2 (C/N0) T)), for a flat OFDM spectrum (beta = B/sqrt(12)), a band-limited BPSK spectrum (closed-form numerator) or any spectrum by quadrature, and on the frequency of a complex tone, sqrt(3/(2 pi^2 (C/N0) T^3)); downlink time-of-arrival fixes with an unknown receiver clock and a single-satellite Doppler fix over a pass in the 3GPP n256 MSS S band, run as the ntn-positioning kind
Oracle
Internal consistency with the textbook closed forms (Kay, Fundamentals of Statistical Signal Processing: Estimation Theory, 1993, chapter 3; Rife and Boorstyn 1974 for the tone), by quadrature and hand evaluation; no published worked figure is pinned, so the bound is not labelled validated. The positioning accuracy is a bound on a multipath-free channel with a stated synchronisation error, not an achieved result
Tests
leo_fusion::ntn::tests (the_numerical_rms_bandwidth_matches_the_closed_forms; the_range_bound_scales_as_one_over_bandwidth_and_root_cn0: 0.4157 m by hand at 5 MHz, 45 dB-Hz, 0.1 s…
ModelledLEO-assisted time transfer to UTC against C/N0 and the receiver oscillatorleo_fusion::timing (simulate,utc_offset_s,system_to_utc_s); leo_fusion::pvt_kind (run_timing)
Capability
Clock measurements from every LEO satellite in view at a known position, combined by inverse variance from the pseudorange noise model, filtered by a two-state (phase, frequency) Kalman filter whose process noise is the oscillator class's white and random-walk frequency noise (slot_timing::ClockNoise, clock_state::ClockClass; the coast variance of holdover::coast_phase_variance), a seeded truth clock from the same levels, and the IS-GPS-200 section 20.3.3.5.2.4 system-time-to-UTC expression with a broadcast-offset uncertainty added as a per-run bias; the leo-pvt timing mode sweeps oscillators and C/N0 offsets
Oracle
Internal consistency: the published offset expression evaluated by hand, the normalised error over 40 seeds, and the floor set by the offset uncertainty. The NIST figure for Iridium timing receivers with a miniature atomic clock (under 40 ns from UTC(NIST) over 40 days) is a comparison only; the bundled Iridium scenario gives 10 to 11 ns RMS at nominal power with its representative 5 m range error. Flicker frequency noise and ionospheric delay are not simulated
ModelledLEO coverage and dilution of precision for polar and Arctic users against MEO GNSSleo_fusion::polar (latitude_sweep); leo_fusion::joint_pvt (dop)
Capability
Satellites in view and median PDOP, HDOP and VDOP with availability against latitude, over sampled longitudes and epochs, for the MEO GNSS systems alone, the LEO systems alone and all of them, each system with its own mask and clock model, run as the leo-pvt polar mode
Oracle
Internal consistency with the known geometry: MEO orbits at 55 to 56 deg leave the polar sky equatorward and low, so GNSS VDOP rises toward the pole (1.20 at the equator to 1.51 at 89.9 deg for GPS and Galileo in the bundled scenario), while a near-polar LEO shell converges there. Geometry only; no scintillation, terrain or signal power
ModelledNamed LEO PNT systems as optional data presets, each with its sourceleo_fusion::presets (all,by_id,cn0_range_dbhz,noise_density_dbw_hz); leo_fusion::system (SystemCfg::build)
Capability
System-agnostic inputs: every system is Walker shells, explicit elements or a GNSS preset, a signal (carrier, chip rate, bandwidth, received power or C/N0 range), a SISRE, a Doppler sigma and a clock model; presets fill only what a scenario leaves out, one file each with sources marked PUBLIC (with a URL), WORKSHOP or DERIVED and the unpublished values listed as representative: Xona Pulsar X1/X5, Iridium STL, Starlink signals of opportunity, CentiSpace, a representative C-band system, the ATOMIC zero-clock ephemeris model, and one workshop-derived preset in the optional Celeste IOD preset file, withheld by deleting that file and its scenarios
Oracle
Transcription of the cited public values, checked for structure (every public source has a URL, Walker patterns divide evenly, the C/N0 from received power over kT at 290 K), not against an external oracle. Representative values are named in each preset and are illustrative
ModelledOne LEO-PNT system end to end: signal design, pass link budget, navigation message and fused positioning, each stage's output handed to the nextleo_pnt_chain (LeoPntChainScenario); leo_pass (BandCfg::signal,design_tracking); leo_navmsg (LeoNavmsgScenario::broadcast_sisre); leo_fusion::pvt_kind; leo_fusion::ppp
Capability
The leo-pnt-chain kind: a leo-signal design (public preset or inline) sets a leo-pass band's centre, bandwidth, chip rate and EIRP split; the pass gives the tracked-component C/N0 and band-limited code jitter per epoch; a least-squares C/N0 line in sin(elevation), the leo-navmsg message's SISRE (fitted at the pass satellite's orbit, plus a stated orbit-determination term in root-sum-square) and the design's carrier and chip rate go to every LEO system of a leo-pvt joint fix and, optionally, to the LEO cases of leo-ppp; every hand-off is reported with its value and unit
Oracle
Self-consistency of the hand-offs: each handed-on value equals the upstream stage's own output, and mutating an upstream input moves every downstream figure that depends on it. The stages keep their own labels; the chain adds no physics and no external oracle
Tests
leo_pnt_chain::tests (a_sine_line_fit_recovers_its_line); tests/leo_pnt_chain.rs (every_upstream_change_moves_the_downstream_figures: a stronger EIRP, a longer fit interval and a larger orbit-determination term each…
ModelledSpoofing detection by LEO Doppler and pass-geometry consistencyleo_link::spoof (range_rate_position_gradient,line_of_sight,fll_frequency_jitter_hz,doppler_consistency_window,doppler_consistency); leo_pass (SpooferCfg,spoof_section)
Capability
The leo-pass kind's [spoofer] section: a spoofer counterfeits, self-consistently in range and range rate, the signals seen at a claimed position that jumps and/or is pushed from the true one after an onset (per LEO band and for the MEO GNSS signal); the receiver predicts every range rate from the broadcast orbit and an independent prior position and velocity, and tests the measured range rates with a generalised least-squares chi-square statistic over a window of epochs (clock drift a nuisance or with a prior), on the GNSS channels, the LEO channels and all channels, with frequency-lock-loop thermal noise from C/N0 (Kaplan & Hegarty 2006, section 5.6.2); detection probability from the non-central chi-square law at a stated false-alarm probability, detection declared at a stated missed-detection probability
Oracle
Closed forms and identities, not an external measurement: the range-rate gradient against a central difference, the information-form statistic against the dense covariance form, a pure clock drift giving zero, a prior-explained push giving at most |dx|^2/sigma_p^2, the statistic quadratic in a jump. No detection figure is compared with a measured attack; the spoofer is idealised (no power, angle-of-arrival or correlation-peak signature)
ModelledSpoofing detection by cross-band consistency of a multi-band LEO signalleo_link::spoof (cross_band_step); leo_pass (spoof_section: pairs,cross_band)
Capability
For every LEO satellite and pair of ranging bands the [spoofer] section forms the geometry-free pseudorange combination, removes the receiver's ionospheric model and tests its epoch-to-epoch step against the two bands' code noise and a stated tolerated unmodelled ionospheric rate (two-sided Gaussian, exact detection probability); a spoofer that counterfeits some bands and not others, or every band without the ionosphere, is seen at its onset; one that counterfeits every band and simulates the ionosphere is not, which the result states
Oracle
Identities: the onset step of an ionosphere-free spoofer equals the pair's modelled ionospheric delay difference, the threshold is the two-sided normal quantile times the step's standard deviation plus the rate bound. The receiver's ionospheric model is the engine's, so the authentic residual is zero in the mean by construction; no external oracle
ModelledIonosphere sounding: slant TEC from the dual-band delay of a LEO passleo_pass (IonoFreePair::geometry_free_stec_tecu,geometry_free_stec_sigma_tecu)
Capability
For every band pair of a leo-pass satellite the report gives the slant total electron content the geometry-free code combination recovers at the pass peak, (P2 - P1) f1^2 f2^2 / (40.3 (f1^2 - f2^2)), and its 1-sigma from the two bands' thermal code noise, so any multi-band LEO-PNT design can be traded as an ionosphere sounder
Oracle
The first-order dispersion identity, exact by construction against the engine's own first-order delay (whose 1/f^2 scaling is VALIDATED against IS-GPS-200 in its own row); the precision is thermal code noise only, without multipath or inter-frequency biases
Tests
tests/leo_resilience_verticals.rs (the_geometry_free_tec_is_the_pass_slant_tec: equals the pass's slant TEC at the peak to 1e-9 and its sigma equals the RSS code noise over 40.3 (1/f1^2 - 1/f2^2))
Nothing matches that filter.
Generated from the engine's verification matrix and pinned by a test. Scroll the list, or open a row for its capability, oracle and tests. The full table, every column at once, is in the docs: Capability reference.
ProNeed this ledger as an audit-grade, reproducible evidence pack for a review board? Kshana Pro packages it.
04Reproducible by default
Rerun it. Get the same numbers.
Free core A result is reproducible bit for bit from scenario, seed and engine version. Nothing here needs a licence, an account or us.
The stamp every result.json carriesRecorded run
This one is from the recorded clock-holdover run. Open it in Kshana Studio, or rerun it yourself:
Run the same scenario.It writes result.json, chart.svg, report.html and table.csv next to the scenario.
Compare the stamp.The scenario hash is a SHA-256 (256-bit Secure Hash Algorithm) digest over the canonical scenario: seed, thresholds, model parameters. Change any input and the hash changes. Every chart footer carries its first 12 hex characters.
Let the engine check itself.On every build, tests confirm that the published figures still reproduce (tests/published_figures_still_reproduce.rs) and that every ledger row names a test and cites evidence that exists (tests/verification_rows_name_a_test_that_exists.rs, tests/verification_rows_cite_evidence_that_exists.rs).
05Standards grid
Speaks the formats you already file.
13 standards and formats the engine implements. A green mark means it is checked against real data, a published example or an independent reference implementation.
TLE / SGP4AIAA 2006-6753CheckedTLE two-line element set · SGP4 Simplified General Perturbations 4, an orbit model · AIAA American Institute of Aeronautics and Astronautics
RINEX 3real IGS data → surveyed coordinateCheckedRINEX Receiver Independent Exchange Format · IGS International GNSS Service
SP3-c / dfit to real ESA/ESOC precise orbitsCheckedSP3 Standard Product 3, a precise-orbit format · ESA European Space Agency · ESOC European Space Operations Centre
CCSDS OEM / OMMparses the CCSDS 502.0-B-3 Blue Book OEM exampleCheckedCCSDS Consultative Committee for Space Data Systems · OEM orbit ephemeris message · OMM orbit mean-elements message
IS-GPS-200broadcast ephemeris → real-data PVTCheckedIS-GPS-200 GPS interface specification for the L1 and L2 signals · GPS Global Positioning System · PVT position, velocity and time
IEEE 1139ADEV/MDEV/TDEV/HDEV vs NIST SP 1065 reference deviationsCheckedIEEE Institute of Electrical and Electronics Engineers · ADEV Allan deviation · MDEV modified Allan deviation · TDEV time deviation · HDEV Hadamard deviation · NIST National Institute of Standards and Technology
SBAS / DO-229EDO-229E HPL/VPL vs RTKLIB SBAS-PL fork on real EGNOS data · L1/L5 iono-freeCheckedSBAS satellite-based augmentation system · DO-229E RTCA minimum operational performance standards for satellite-based augmentation system receivers, revision E · HPL horizontal protection level · VPL vertical protection level · RTKLIB an open-source GNSS positioning library · EGNOS European Geostationary Navigation Overlay Service
IONEX / KlobucharKlobuchar L1 delay vs RTKLIB ionmodel · IONEX TEC-map reader lenient, no external oracle yetCheckedIONEX Ionosphere Map Exchange format · RTKLIB an open-source GNSS positioning library · TEC total electron content
IGRF-14vs official BGS IGRF-14 valuesCheckedIGRF-14 International Geomagnetic Reference Field, 14th generation · BGS British Geological Survey
CCSDS 133.0primary header vs CCSDS 133.0-B-2 + spacepackets-py vectorsCheckedCCSDS Consultative Committee for Space Data Systems
CCSDS TDMparses the CCSDS 503.0-B-2 Blue Book TDM exampleCheckedCCSDS Consultative Committee for Space Data Systems · TDM tracking data message
CCSDS 401 / DSNlink equation vs published DESCANSO/JPL Galileo DCTCheckedCCSDS Consultative Committee for Space Data Systems · DSN Deep Space Network · DESCANSO Deep Space Communications and Navigation Systems Center of Excellence · JPL Jet Propulsion Laboratory · DCT design control table, the link-budget worksheet
Nothing matches that filter.
When a review needs more
Same evidence, packaged or done for you.
The engine and everything above stay free. Two paid routes build on them, under contract.
Pro
Kshana Pro: a mission dossier and an evidence pack
Kshana Pro packages the evidence a review or procurement board asks for, reproducibly. What it builds on: this ledger, where every capability names its oracle and its test, and the stamp every result carries. In one command, a mission dossier checks every requirement against real runs and writes a verification matrix with its open items and a PDF (Portable Document Format).
A custom study answers your own question with the same labels: every figure Validated or Modelled, not a certification. Export-controlled work is handled under clearance and NDA (non-disclosure agreement).
5 papers on arXiv, the open preprint archive, built on the open engine. Each opens to a figure rerun on the engine, its findings, the command and its DOI (Digital Object Identifier).
Lunar navigation · arXiv:2607.06212
The Cost of Lunar South-Polar Geometry, and Surface Beacons as the Efficient Fix: A Dilution-of-Precision Analysis
Planned orbits bunch overhead for a lunar south-pole user; a few ranging beacons on nearby high ground fix the geometry more cheaply than more satellites.
ModelledEngine v0.29.0 · lunar-beacon.toml · deterministic, no seedOpen in Kshana Studio
Key findings
In the bundled run, the one beacon that clears the horizon cuts the geometric dilution of precision from 11.66 to 4.998; a 24-satellite constellation instead reaches 2.893.
The satellites a south-polar user sees bunch into a small patch overhead, so the geometry is limited by their spread, not their number.
A few beacons on elevated terrain reach geometry that an orbit-only design reaches only with a much larger fleet.
How Kshana reproduces it
The lunar-beacon kind builds the ranging geometry of an orbital constellation plus the surveyed surface beacons that clear the airless horizon, on the dilution-of-precision kernel checked against an independent library, and reports each configuration's dilution of precision and its accuracy in metres.
The figure. One epoch of the bundled scenario, its default geometry: the satellites alone, the satellites plus the beacons that clear the horizon, and a 24-satellite constellation instead.
Reproduce it
Runs the scenario kind lunar-beacon (scenarios/lunar-beacon.toml) with the installed engine.
@misc{baweja2026cost,
title = "{The Cost of Lunar South-Polar Geometry, and Surface Beacons as the Efficient Fix: A Dilution-of-Precision Analysis}",
author = {Baweja, Chakshu},
year = {2026},
eprint = {2607.06212},
archivePrefix = {arXiv},
primaryClass = {astro-ph.EP},
doi = {10.48550/arXiv.2607.06212},
url = {https://arxiv.org/abs/2607.06212}
}
Lunar navigation · arXiv:2607.02566
Earth-baseline VLBI restores the observability of a lunar surface station in joint orbit-and-clock determination
Lunar-network ranging fixes only relative geometry; an Earth-baseline very-long-baseline interferometry delay ties a surface station to the Earth frame, even with few satellites. VLBI very long baseline interferometry
Ranging inside the lunar network leaves the cluster free to shift and rotate unseen; the clocks stay observable, so the defect is purely positional.
In the engine run (3 satellites), the Fisher information without the interferometry legs has rank 15 of 16; with them it has full rank and a Cramér–Rao bound of 20.1 m.
With a rich constellation the interferometry tie only sharpens the bound; with a sparse one it restores the station's absolute position.
How Kshana reproduces it
The lunar-joint-od-clock kind fuses Earth-baseline interferometry delays, lunar-local ranges and inter-satellite ranges in one batch least-squares fit, runs it with and without the interferometry legs on the same seed, and reports the rank of the Fisher information, the datum defect and the Cramér–Rao bound.
The figure. The bundled simulated network: 3 lunar satellites, 6 Earth stations, one surface station, the same seed and truth for both fits.
Reproduce it
Runs the scenario kind lunar-joint-od-clock (scenarios/lunar-joint-od-clock.toml) with the installed engine.
@misc{baweja2026earth,
title = "{Earth-baseline VLBI restores the observability of a lunar surface station in joint orbit-and-clock determination}",
author = {Baweja, Chakshu},
year = {2026},
eprint = {2607.02566},
archivePrefix = {arXiv},
primaryClass = {eess.SP},
doi = {10.48550/arXiv.2607.02566},
url = {https://arxiv.org/abs/2607.02566}
}
Timing integrity · arXiv:2606.24210
A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing
A recorded spoof shows a timing receiver serving time far more wrong than it reports; no unconditional bound exists, so the paper bounds the undetected error conditionally. GNSS Global Navigation Satellite System
FigureModelledEngine v0.29.0 · examples/tpl_jammertest.rs · deterministic, no seedKey findings
A public recorded spoof pulled the receiver's served time by about 1.01 ms while it reported at most 51 ns.
Against a slow enough ramp no finite unconditional bound exists, so the bound is conditional on an independent cross-satellite check detecting the attack.
The engine's Timing Protection Level is 114 ns at 1 s detection latency and 458 ns at 60 s.
How Kshana reproduces it
The Timing Protection Level module adds a monitor's detection floor to the oscillator's coast over the detection latency. The example calibrates it with the scalars recovered from the public JammerTest 2024 recording; the raw recording is not shipped.
The figure. The example's printout: the conditional Timing Protection Level at five detection latencies, and the two scalars it recovered from the public JammerTest 2024 recording.
Reproduce it
Regenerates the study artifact from examples/tpl_jammertest.rs, in a clone of the repository.
Cite it
BibTeX · baweja2026conditional
@misc{baweja2026conditional,
title = "{A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing}",
author = {Baweja, Chakshu},
year = {2026},
eprint = {2606.24210},
archivePrefix = {arXiv},
primaryClass = {eess.SP},
doi = {10.48550/arXiv.2606.24210},
url = {https://arxiv.org/abs/2606.24210}
}
Resilience scoring · arXiv:2607.05415
How Stable Is a PNT Resilience Score? Decision-Instability of Single-Number Resilience Ratings under Framework-Aligned Weighting
Single-number resilience ratings for positioning, navigation and timing are stable only where one design dominates; weighting, threat and declared techniques can flip them. PNT positioning, navigation and timing
Re-weighting alone changes the top-ranked architecture in 22% of draws under nominal conditions, and in at most 1.25% under each active threat.
A weakest-link maturity level depends on the threat assumed, not only on the architecture.
Because the composite rewards declared techniques, a design that declares more can outscore a more resilient one.
How Kshana reproduces it
The resilience module scores seven reference architectures across the seven framework categories and five threats, draws the category weights at random from a Dirichlet distribution and counts how often the top rank changes. The example writes the whole study as one deterministic file.
The figure. 7 reference architectures, 2,000 random category weightings per threat.
Reproduce it
Regenerates the study artifact from examples/resilience_report.rs, in a clone of the repository.
Cite it
BibTeX · baweja2026stable
@misc{baweja2026stable,
title = "{How Stable Is a PNT Resilience Score? Decision-Instability of Single-Number Resilience Ratings under Framework-Aligned Weighting}",
author = {Baweja, Chakshu},
year = {2026},
eprint = {2607.05415},
archivePrefix = {arXiv},
primaryClass = {cs.CR},
doi = {10.48550/arXiv.2607.05415},
url = {https://arxiv.org/abs/2607.05415}
}
Radio-frequency interference · arXiv:2606.22054 · version 2
Anticipating the Optimism Gap: Predicting Distribution-Shift Degradation of RF-Impairment Detectors from In-Distribution Statistics
How much an interference detector loses under shifted conditions can be predicted from its own in-distribution scores; synthetic results, checked on open field recordings. RF radio frequency
The gap between in-distribution and shifted area under the curve grows as the shift deepens, and depends on how many observables a detector uses rather than on whether it is learned.
In the engine run, a ridge model on in-distribution score statistics predicts the gap for a detector it has not seen (R² 0.47) and for an interference class it has not seen (R² 0.46).
The headline findings are synthetic; the paper then checks them on open field recordings.
How Kshana reproduces it
The impairment study generates a synthetic, parameter-grounded corpus for four interference classes, scores thirteen detectors at four shift severities over five seeds, and fits the gap predictor with leave-one-out cross-validation and a permutation test.
The figure. 260 detector, class and severity cells; each prediction is made for a detector left out of the fit.
Reproduce it
Regenerates the study artifact from examples/optimism_study.rs, in a clone of the repository.
Cite it
BibTeX · baweja2026anticipating
@misc{baweja2026anticipating,
title = "{Anticipating the Optimism Gap: Predicting Distribution-Shift Degradation of RF-Impairment Detectors from In-Distribution Statistics}",
author = {Baweja, Chakshu},
year = {2026},
eprint = {2606.22054},
archivePrefix = {arXiv},
primaryClass = {eess.SP},
doi = {10.48550/arXiv.2606.22054},
url = {https://arxiv.org/abs/2606.22054}
}
Cite the engine
Every release is archived on Zenodo with a citable DOI, and a CITATION.cff ships in the repository. Please cite the engine version, the scenario and the seed.
Baweja, C. (2026). Kshana — a PNT-resilience simulator with quantum-sensor performance models (Version 0.29.0). Ashforde OÜ. https://doi.org/10.5281/zenodo.20528627
BibTeX for the engine
BibTeX
@software{kshana,
title = {Kshana — a PNT-resilience simulator with quantum-sensor performance models},
author = {Baweja, Chakshu},
version = {0.29.0},
year = {2026},
doi = {10.5281/zenodo.20528627},
url = {https://github.com/ashfordeOU/kshana},
license = {AGPL-3.0-only}
}