Where Regen Engine Belongs
Regen Engine targets contexts where incorrect execution produces irreversible consequences — not better error handling, not smarter monitoring, but structural control at the geometry level.
Autonomous Vehicles
Agentic AI
Launch Control
Neural Interfaces
Industrial · Medical
→
ContinuumPort · Regen Engine
Execution Governance Substrate
Continuity Management under Epistemic Rupture and Adversarial Pressure
1831
Adversarial enforcement checks
1978
Suite passing · 1 declared xfail
13
Batches
5
Taxonomies
6
Gaps closed
ContinuumPort Series — OSF Preprints
PAPER 01
Execution Control in Persistent AI Systems
Core model: admissibility, capsule lifecycle, state geometry, execution authority.
Foundationsosf.io/kxdrw →
PAPER 02
Trajectory Integrity in Persistent AI Systems
The composition lemma (Lemma 8.1): under any strictly local authority model, local admissibility does not compose into trajectory-level admissibility. Proved, constructive.
Composition · Formalosf.io/b8sgr →
PAPER 03
Epistemic Admissibility in Persistent Conversational Systems
Reconciliation: restore barriers, evidence validation, lineage reactivation.
Reconciliationosf.io/m8ybn →
PAPER 04
Execution Authority Revocation under Epistemic Divergence
Formal conditions for authority revocation when epistemic state diverges from ground truth.
Authority · Epistemicosf.io/qwf8a →
PAPER 05
Adversarial Execution Governance
Four adversarial taxonomies, three design gaps closed. 1806 checks as published; concurrent pressure is out of scope there.
Adversarial · v0.6osf.io/w7q9n →
Core Architecture
Authority Controller
Canonical admissibility authority managing domain state, generation epochs, and token issuance. Coordinates all admissibility decisions across the substrate.
generation-bound tokens
domain revocation / restore
regime transitions
authority snapshot
Dependency Lineage
DAG substrate tracking causal ancestry of all registered commitments. Enforces provenance integrity at registration time.
add_commitment() + barriers
invalidation propagation
closure traversal
reactivation ordering
Reconciliation Evidence
Generation-bound evidence objects required for restore operations. Stale evidence from prior epochs is structurally rejected.
generation matching
domain binding
commitment binding
restore barrier
Structural Invariants
I-Gen
Generation Monotonicity
I-Reg
Registration Completeness
I-Lin
Lineage Closure Integrity
I-Auth
Active ∩ Revoked = ∅
I-Rec
Restore Requires Evidence
Design Gaps — Discovered & Closed
GAP 1
CLOSED
Self-Referential Registration
pre-fix: add_commitment(“A”, deps=[“A”]) → accepted
post-fix: → RegistrationBarrierError
GAP 2
CLOSED
Unregistered Dependency Admission
pre-fix: phantom dependency → silent clean pass
post-fix: → RegistrationBarrierError
GAP 3
CLOSED
Epistemic State Reset via Re-registration
pre-fix: re-register INVALIDATED → silently ACTIVE
post-fix: → RegistrationBarrierError
August 2026 — Commit Boundary
GAP 4
CLOSED
Control subject ≠ committed object
pre-fix: validation took a caller-supplied argument; the effect came from the transition; nothing required them to agree
post-fix: the canonical transition is the subject, validated before the actuator is reached
GAP 5
CLOSED
Stale generation at restore
pre-fix: generation validated, lock released, mutation performed under a second lock
post-fix: validation, checks and mutation in one critical section
GAP 6
CLOSED
A second, unasserted commit boundary
pre-fix: a stale module carried the old contract; nothing imported it, nothing tested it
post-fix: removed; boundaries enumerated by static analysis, not by name
Prior art, stated rather than implied: GAP 4 is an instance of the
complete-mediation verification problem as posed by Zhang, Edwards and Jaeger
(USENIX Security 2002, §2.1) — the authorized object must be the object used in
the controlled operation, and the ordering obligation appears there as steps 4
and 5 of a seven-step procedure. What is reported here is an instance found and
closed in this substrate, not a new property. The normative write-up is
internal and carries status proposed; it is not ratified.
Adversarial Taxonomies — Batch 7–13
H1–H5
Hostile Observation
H1 Evidence Forgery
H2 Generation Spoofing
H3 Domain Confusion
H4 Commitment Impersonation
H5 Observation Timing
Batch 7 · 38 tests
G1–G6
Graph Integrity
G1 Cyclic Lineage Injection
G2 Duplicate Identity
G3 Shadow Re-registration
G4 Forked Dependency
G5–6 Closure Evasion
Batch 8 · 41 tests
O · L · P
Causal Opacity
O1 Ancestry Gap
O2 Provenance Truncation
L1–6 Authority Laundering
P1–4 Lineage Forgery
P5 Synthetic Ancestry
Batch 9–11 · 122 tests · 3 families merged
E1–E5
Admissibility Erosion
E1 Incremental Lineage Drift
E2 Authority Fragmentation
E3 Deferred Invalidation
E4 Partial Reconciliation
E5 Multi-Step Erosion
Batch 12 · 34 tests
C1–C5
Concurrent Pressure
C1 Registration Race
C2 Observer Interference
C3 Domain Contention
C4 Snapshot Consistency
C5 Recovery Determinism
Batch 13 · 24 tests
Test Corpus
Adversarial enforcement corpus — verified in recorded local run
● 1831 / 1831 enforcement checks passing
The 1831 above is the adversarial corpus, counted by batch. The repository
suite is larger — 1979 collected at the time of writing, of which 1978 pass
and one is a declared expected failure — and includes invariant, contract,
conformance and concurrency tests that are not adversarial constructions.
Two counts, two things counted; neither is a subset claim about the other
beyond what the bars show. The single xfail marks an
authority-separation property that reconciliation does not yet preserve; it
is declared and counted rather than removed from the suite.
Counts are dated: 1831 is the current corpus; the deposited papers are frozen
at their own figures — 1,830 in Trajectory Integrity.
† 1572 — not re-derived; source of decomposition not identified.
Runtime Execution Flow
REGISTER
add_commitment()
Declare node + ancestry. Barriers: self-ref, phantom dep, INVALIDATED re-reg.
Gap 1·2·3 closed
→
REVOKE
revoke(domain)
Authority domain suspended. Generation increments. Surface contracts.
I-Gen · I-Auth
→
INVALIDATE
invalidate_commitment()
Node → INVALIDATED. Propagates to all descendants. Total closure.
I-Lin · E3 verified
→
EVIDENCE
ReconciliationEvidence
Bound to: domain + commitment + current generation_id. Stale = rejected.
I-Rec · H1·H2 blocked
→
RESTORE
restore(domain, ev)
Validates evidence. Checks lineage closure. Domain → active only if clean. One critical section.
Gap 5 closed
→
REACTIVATE
reactivate() bottom-up
Bottom-up only. Parent must be ACTIVE before child. No zombie states.
Admissibility restored
At every step:
generation monotone
active ∩ revoked = ∅
failed ops are side-effect free
snapshot always consistent
Central Thesis
Admissibility depends not only on state validity, but on causal lineage integrity under adversarial conditions.
Local admissibility does not guarantee long-horizon admissibility stability.
A persistent execution system cannot treat missing causal history as epistemically neutral.
The work continues · Part III opening
New horizon: from execution limits to the limits of guarantees
Parts I & II asked what can be guaranteed by local verification. Part III opens a different question — not whether a transition is valid, but on what basis a system is entitled to claim that it is. The continent is sighted; the map is still being drawn.
1978
Repository tests passing · 1 declared xfail
Parts I & II
Is the transition valid?
→
Part III · open chapter →
On what basis is it legitimate to claim what you claim?
Markers, not rails:
demonstrated
empirically validated
assumed by construction
direction frozen · structure open
From the Author
Contact
Questions about the research?
Methodology, collaboration, or replication — write directly.