S-C - Continuity and the embodiment substrate (UNI.OS)
How to read this page
Three ways to read this page. Precise is the document itself, exactly as it is written in the repository. Plain and Clear were written for this website to help you meet that document — they are about it. They are not it, and they are not evidence.
The Encyclopedia is the UNI method written out as a reference work: 39 pages, arranged in wings, setting out what the programme is attempting and why it is built the way it is. This is where the ideas are explained in order and in prose, rather than as code, as runbooks, or as dated receipts.
Every chapter is authored against two ledgers and never ahead of them. One records what UNI has built, and the evidence class of each claim. The other records nature's own regularities, kept separate on purpose. That way a fact about biology is never quietly reused as a fact about the software. Where a chapter and a ledger disagree, the chapter is the thing that is wrong. Every chapter closes with an invitation to falsify it, and a recorded negative is published beside the result it qualifies rather than after it.
Read "How to read this work" first. It is the evidence constitution: the classes, the four ledger states, and the rule that a finished chapter is not the same as a working system. Then the calibration ledger, which carries the figures every other chapter is required to use.
What it is not: a description of a person or of a mind. The programme calls itself a developmental active-inference simulation, a bounded peek into a toy world, and its own index prints how much of the developmental ladder has actually been earned — roughly two rungs out of eleven or more. It is also not a report of what is running today. For what ran, and when, go to the evidence record.
Your browser cannot switch reading levels, so the document itself is shown.
Precise — the source document
This is the document. Rendered from the repository at the commit above, with nothing rewritten for the web. A gate re-renders it on every deploy and fails the build if a single byte differs.
The honest position, stated first. This chapter cards the substrate that carries the UNI program: the physical machines, the deterministic serialization that lets a saved mind-state come back unchanged, the fail-closed transport between nodes, the categorical sensorium through which a box reads its own body, and the gated action surface through which it touches its own services. Every claim here is ENGINEERING evidence, not science evidence. It is the evidence class of "we built a substrate that persists and operates correctly on real metal," and it is never the evidence class of "a science gate on the L0-L12 developmental ladder was met." The two ladders are orthogonal by construction. A substrate that survives a restart, senses itself, and acts under approval tells you the body works; it tells you nothing about awareness, comprehension, or active inference as a demonstrated capability. The program remains a developmental active-inference SIMULATION: a bounded peek, a toy world, never a person. The honest program position is unchanged across every chapter: ~2 of 11+ developmental rungs earned.
The single most important fence in this chapter, repeated because careless readers reach for it: the sensorium is never awareness, and "the mind survives a kernel swap" is NOT shown. What is shown is narrower and is stated exactly below. This sub-ladder is read as a single discipline so that the strong parts (deterministic replay, byte-exact serialization, fail-closed transport, on-metal operation) never bleed into the parts that are merely owed, parked, or negative. Every PASS below is authored next to the negative that travels with it.
The substrate on real metal (C0, C6)
The substrate is a two-node fleet running on real hardware, not a cloud abstraction (C0, Class A, proven). Production runs on a Dell PowerEdge with a no-AVX Intel Xeon X5650 (Westmere) booting from a PERC HDD array of roughly 5.5 TB of spinning disks, explicitly NOT SSD (the owner's initial expectation of SSDs was contradicted on inspection and the ledger carries the corrected fact). The second node is a Dell OptiPlex on NVMe. They are tied by a WireGuard mesh; each box that boots the image auto-takes a unique per-device identity uni-lab-<mac> and mints its own TLS leaf on firstboot, so two boxes never both answer to the same name. The no-AVX CPU is load-bearing: AVX-compiled binaries fault, and the stack runs only because its components do runtime CPU dispatch. Falsifier (C0): a node fails to boot or appear, the status page is not served, or the hardware spec (no-AVX Xeon, HDD-not-SSD) is contradicted on inspection.
On top of that hardware sits the on-core inference anchor (C6, Class A, proven): a sealed f64 belief-update trace that comes out byte-identical across 4 distinct software/emulated stacks over 5 runs. This is a determinism anchor, not a capability: it proves the same arithmetic produces the same bits across different software stacks, which is exactly what a continuity substrate needs. The travelling calibration is mandatory: this figure is "4 distinct stacks / 5 runs," never "5 stacks." A peer-reviewed honesty audit (os-cycles 39-53) caught the "5 stacks" headline as an over-statement and calibrated it down to the measured value; the inflated figure is forbidden. Falsifier (C6): a fifth distinct stack produces a non-identical trace, or the cross-architecture leg is shown not to be genuinely distinct (the cross-arch leg is the recorded weak point).
The continuity ladder: Stage-1 GREEN, Stage-2 OWED (C1, C2)
Continuity is treated as a ladder of separate falsifiable rungs, not a slogan. Each rung answers a sharper question about what it means to say a process or a mind "persisted."
Stage-1 (C1, REQ-002 GREEN, proven): the real UNI active-inference agent state survived a process restart BIT-FOR-BIT. The state was durable, sha256-verified, fail-closed, and produced a bit-identical tick across a real child-process boundary with at least two distinct actions (the Path-B receiver passed 3/3). The transport recipe is engineering, not science: serialize -> bytes (sorted-key JSON over base64 raw float32/int32), blob_sha256 as the anchor, deserialize -> bit-exact, verifying both that serialize(deserialize(blob)) == blob and that tick-continuity holds across the boundary, failing closed on a single-bit corruption. The ledger cards Stage-1 at Class C (B-substrate): deterministic replay plus serialization plus fail-closed transport, explicitly not general-AIF evidence. The mind-side gate was peer-reviewed and down-calibrated, and its joint verdict signature is still null (not sealed). Falsifier (C1): a process-restart replay diverges bit-for-bit, fail-closed does not trigger on a one-bit corruption, or serialize(deserialize(blob)) != blob.
Stage-2 (C2, NEGATIVE / OWED) travels inseparably with Stage-1 and must never be stripped from it. The real kernel swap was proven infrastructure-only. A real production kexec cutover from kernel 6.12.86 to 6.12.73 completed in roughly 59 seconds with zero data loss (Odoo tables identical, sentinel rows preserved), and CRIU/livepatch were proven on the box. But mind-tick continuity across the swap was NOT shown. The node2 evidence-collected swap was infra-only (roughly a 90-second freeze; api and tts CRIU-preserved; two publishers fresh-restarted), and the first attempt FAILED outright (an unclean kexec left a dirty ext4/ESP, dropping the box into emergency mode) before it was root-caused, fixed, and recovered on the retry. The honest claim is therefore "mechanism green across a real process boundary," never "the mind survives a kernel swap." This is the standing pairing the front matter enforces: Continuity Stage-1 (bit-for-bit process restart) is cited ALWAYS with Stage-2 OWED (mind-tick continuity across a kernel swap not shown). Falsifier / discharge (C2): a kernel swap shown preserving mind-tick continuity bit-for-bit end-to-end (not merely infrastructure) discharges the owed Stage-2.
A second recorded negative fences the headline further. C7 (NEGATIVE bound, Class A): a single-box swap is a seconds-long FREEZE, not zero-downtime; true zero-freeze needs the second node carrying the platform, and external media legs (RTP/SIP/kernel-mode rtpengine) are NOT preserved across kexec. Falsifier (C7): a single-box kexec demonstrated with zero freeze and preserved media legs, without a second node carrying the platform.
The body-to-mind sensorium (C3) - and why it is never awareness
The embodiment core is a live categorical sensorium (C3, Class A live / Class C engineering reuse, proven). The box reads its own telemetry (os_sysinfo, systemctl, podman ps, journalctl) into a 7-modality categorical contract {load, mem, swap, disk, services, containers, journal} encoded as [M=7, O_max=4] - explicitly not a float vector and not a softmax, but a discrete categorical alphabet. A 28-cell string_vector flows live on both boxes. Raw integer rows are recorded, band edges live in exactly one place (the mind), and a consumer-side validator runs before banding. Falsifier (C3): the string_vector stops flowing on either box, or the contract is found to be float/softmax rather than the [M=7, O_max=4] categorical alphabet.
This is the load-bearing fence of the whole chapter: a body that senses itself is not a body that is aware of itself. A categorical sensorium is an input channel, an honest worked example of "a body that senses itself and acts on belief." It is never evidence of awareness, sentience, or consciousness. The recorded engineering negative reinforces the design: C8 (NEGATIVE, Class C) - an over-compressed 2-modality sensory bottleneck went NEGATIVE on held data, so the contract keeps all 7 modalities. This negative is the reason the 7-modality contract is the contract. Falsifier (C8): a 2-modality bottleneck beats the 7-modality contract on held data.
ASK mode, learning, and the gated action surface (C4, C5, C13, C14)
The substrate acts on its own services through a fixed, gated surface. ASK mode (C4, ITIL-as-active-inference, Class A learning-shift / Class C, proven, live both boxes): the mind escalates a reasoned change request; the operator approves-and-executes (with auto-rollback) or declines-with-category; and every verdict updates a persistent Dirichlet policy-prior keyed by (host-state, action). The learning shift is measured, not asserted: decline x3 leads it to stop proposing; not_a_problem x2 leads to a noop; approve-and-fixed makes it more confident. The safe-action set is FIXED (observe / scale / restart); the mind never self-executes and never widens the safe set. This is real continual parameter-learning over a policy prior - and it is explicitly NOT consciousness. Falsifier (C4): the Dirichlet prior does not update across operator verdicts, the mind self-executes or widens the safe set, or the measured proposal-shifts do not reproduce.
Cross-box single-human-approval-per-mutation (C5, Class A, proven live 2026-06-26): a token-gated, self-documenting control surface routes cross-box "limb" mutating calls through exactly ONE human approval on the entry box (a tool-and-args-bound one-time HMAC). Proven live on both boxes: a prod-to-node2 write was gated once and landed, while the node2 queue stayed at count 0. Falsifier (C5): a routed cross-box mutation executes without the single approval, requires a double-gate, or the node2 queue increments unexpectedly.
The substrate ships continuity-isolation primitives (C13, Class B, proven by grounded inspection): Markov-blanket isolation assertion, least-privilege vault, a brand-voice drift sentinel (cosine plus Youden-J), byte-exact state checkpoint, sha256 output integrity, a zero-hidden-LLM reply path, and live Postgres row-level security passing 5/5. These are mechanisms shown working under grounded inspection (Class B), not held-out gates - never present a B as a held PASS. Travelling with them is C14 (NEGATIVE gap, Class B): the bare substrate is MISSING tenant/client/namespace isolation (flat global permissions) and temporal decay on learned counts (so contamination would be permanent). The product build is the tenant wrapper plus decay; it is not the core. Falsifiers: C13 - any listed primitive absent or non-functional under inspection; C14 - resolved only by building the namespacing plus count-decay layer.
The honest trades and the central open gap (C9, C10, C11, C12)
C9 (NEGATIVE trade, Class C): the exact-discrete active-inference transformer (EDAIT) trades fluency for calibration - held-out perplexity ~33 versus a backprop GPT's ~25. Less fluent, but natively online-learning and calibrated. This is an honest trade, not a win, and it is never phrased as "beats LLMs." Falsifier (C9): the EDAIT matches or beats backprop-GPT held-out perplexity (~25) while keeping online-learning plus calibration.
C10 (PARKED, Class U) is the program's central open gap, and it is named as such. The "embody only what's proven" coupling is signed-in-principle but NOT literally true. UNI.OS does not yet run the no-backprop Dirichlet learning, the exact info-gain EFE, or structural (whitelist) isolation that earned the science gates; its isolation is heuristic (denylist), and it runs a different developmental model (Gray-Scott, not the forager/ontogeny that earned the bars). The lab evidence store /var/lib/uni/evidence is empty, with 0 worlds registered. Everything beyond the passed gates stays Class-U-not-claimed. Falsifier / per-primitive discharge (C10): UNI.OS runs the no-backprop Dirichlet learning, exact info-gain EFE, structural isolation assertion, and forager-ontogeny developmental model frozen at the actual passed-gate SHA, with recorded evidence.
A SIGNED consult (UNI-GPT, 2026-06-27, recorded as governance record G-2026-06-27.2) sets the discharge ORDER without discharging anything: port the no-backprop Dirichlet learning primitive FIRST (the highest first-port value of the four), frozen at the actual passed-gate science-repo SHA, with byte/behavior equivalence proven in CI and the ledger (the conjugate count update and the expected-log tensor E_Q[ln A] = psi(a_ij) - psi(sum_k a_kj), plus the no-backprop guard). The recommended partial-discharge wording is to be used only once actually verified, and even then it discharges only the learning-primitive gap: exact info-gain EFE, structural-whitelist blanket enforcement, and forager/ontogeny developmental-model equivalence remain unported and unclaimed. This is a recommended order and wording, not a discharge: C10 stays PARKED, central gap, Class U.
Two further parks are recorded honestly. C11 (PARKED, Class U directive / Class C host-native hosting proven): a host-native (off-podman) brain runtime is an owner directive whose outcome is not yet in the archive, though a colony already runs host-native on the box. C12 (PARKED, provisional, Class U): a node2 local auto-kiosk reported "SOLVED 2026-06-26" is provisional and contradicted same-day - a later same-day transcript shows the limb-2 UI frozen, an agent action that ended ALL video output, and the session cut at a usage limit. Treat it as fragile pending hands-on monitor re-verification. Falsifier (C12): hands-on re-verification on the physical monitor shows the kiosk stable across live churn (promotes) or still fragile (confirms the regression).
What is NOT claimed in S-C (Continuity and the embodiment substrate)
- Ceiling. "UNI.OS proves the mind is alive / aware / survives a kernel swap, and therefore a science gate is met" is NOT shown. The most we claim is exactly this: engineering continuity - a real two-node fleet on real metal (C0), an on-core inference trace byte-identical across 4 distinct stacks over 5 runs (C6), a mind-state that survived a process restart BIT-FOR-BIT at Class C (B-substrate) (C1), a 7-modality categorical sensorium live on both boxes (C3), a measured Dirichlet policy-prior learning shift under ASK mode (C4), and a proven single-human-approval-per-mutation gate (C5). Substrate work, never a capability rung.
- Fences engaged (named). Red line 8 (substrate/continuity engineering must never imply a science gate is met - the spine of this chapter); red line 2 (never consciousness/sentience/aware - the sensorium is never awareness; ASK-mode learning is never consciousness); red line 3 (never "active inference demonstrated" - the live UNI.OS loop is a separate reimplementation, not gate-matched); red line 5 (never "beats LLMs" - the EDAIT ~33-vs-~25 result is an honest trade); red line 7 (never raise a claim above its source class - C13 stays Class B, not a held PASS); red line 10 (no PII, no featured channel handles, no patent-level math); the calibration-down rule (carry "4 stacks/5 runs" and "ONE box / infra-only continuity," never the inflated headlines).
- Negatives that travel with this claim (cite alongside, never strip). C2 Stage-2 OWED (kernel-swap mind-tick continuity NOT shown; first attempt FAILED then recovered; infra-only) - this is the mandatory partner of the C1 Stage-1 PASS. C7 single-box swap is a seconds-long freeze, media legs not preserved. C8 the 2-modality bottleneck went NEGATIVE, so keep all 7. C9 the EDAIT ~33-vs-~25 honest trade. C14 the multi-tenancy gap on the bare substrate. The audit-layer calibration-down travels too: ONE box (not two), infrastructure continuity only (not "the mind survives a patch"), 4 distinct stacks / 5 runs (not "5 stacks").
- Parked / owed. C2 Stage-2 is OWED (the kernel-swap mind-tick continuity observation itself is owed - a Class-A end-to-end demonstration, not merely a sign-to-park). C10 is PARKED, Class U, and is the program's central open gap: the four primitives are unported (Dirichlet learning first per the signed discharge order, then info-gain EFE, structural isolation, forager-ontogeny dev model), the evidence store is empty with 0 worlds registered, and nothing is claimed beyond the passed gates. C11 and C12 are PARKED (host-native runtime outcome not in archive; node2 kiosk provisional and contradicted same-day). The joint REQ-002 verdict signature is still null.
- One-line honest summary a skeptic could not dispute. UNI.OS is a real two-node appliance that persists a mind-state bit-for-bit across a process restart, senses its own body through a 7-modality categorical channel, and acts only under one human approval - and it has not shown mind-continuity across a kernel swap, has not literally embodied the primitives that earned the science gates, and proves no science gate at all: it is engineering evidence for a developmental simulation, ~2 of 11+ rungs earned.
Falsify this
The lead falsifier is the owed Stage-2 (C2), stated operably: demonstrate a real kernel swap that preserves mind-tick continuity bit-for-bit end-to-end - not infrastructure-only, but the active-inference mind's own tick sequence carried unbroken across the swap, sha256-verified and fail-closed. Such a demonstration would discharge the owed Stage-2 and lift the continuity ladder one rung. Until then the honest claim stays "mechanism green across a real process boundary," never "the mind survives a kernel swap." A second operable falsifier discharges the central gap C10 per-primitive: show UNI.OS running the no-backprop Dirichlet learning primitive frozen at the actual passed-gate science-repo SHA, with byte/behavior equivalence proven in CI and the ledger (the conjugate count update and the E_Q[ln A] = psi(a_ij) - psi(sum_k a_kj) expected-log tensor, plus a tripping no-backprop guard) - and even that would discharge only the learning-primitive gap, leaving info-gain EFE, structural-whitelist isolation, and forager-ontogeny equivalence unported and unclaimed.
Sources
CLAIM-LEDGER.md, Section 2 (Continuity / Embodiment-Substrate Sub-Ladder), rows C0-C14, the audit-layer calibration-down note, and the SIGNED C10 Dirichlet-first port insert (governance record G-2026-06-27.2, UNI-GPT consult 2026-06-27).encyclopedia/MASTER-PLAN.md, FM-1 through FM-4 (the Evidence Constitution, the A-U rubric, the red-line list, the "What is NOT claimed" template) and the S-C authoring spec.curated/uni-os-digest.md(the substrate, sensorium, live OS update, ASK mode, single-approval gate, the honesty audit calibration-down) andcurated/uni-mind-digest.md(REQ-002 Stage-1 mind-side continuity, the continuity transport recipe, the EDAIT trade, the owed Stage-2).- Archive pointers (no PII):
...-UNI-OS,...-uni-mind,...-MarketingWright.
sha256 b884ed404697a421 — of the original file, so what was ingested stays checkable.
Plain — written for this website, not the source document
The machines the program runs on are the subject here, and the question the chapter asks is how much they actually show. Everything in it is engineering evidence. There are two machines on real metal, a deterministic way of saving and restoring a mind-state, and a fail-closed link between them. There is a categorical channel through which a machine reads its own body, and an action surface gated by one human approval. None of it is science evidence. What runs on that substrate is still a developmental active-inference simulation, a bounded peek at a toy world and never a person. The line repeated hardest is that a body that senses itself is not a body aware of itself, and that a claim of the mind surviving a kernel swap has not been shown. What has been shown is narrower: state survived a process restart bit for bit, and the swap itself was infrastructure only, with the first attempt failing before it was fixed.
Plain · written 2026-08-01 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is b884ed404697a421
Clear — written for this website, not the source document
The chapter records a substrate and keeps it strictly separate from the developmental ladder. What runs on top of that substrate is a simulation — a toy world, not a person. A substrate that survives a restart, senses itself and acts under approval tells you the body works; it tells you nothing about awareness, comprehension, or inference as a shown capability.
The hardware is described plainly: two machines on real metal rather than a cloud abstraction, one of them on an older processor without a vector instruction set, booting from spinning disks rather than solid state. That last detail is a corrected fact, since the original expectation was wrong and the ledger, a record added to and never edited, carries the correction. On top of that sits a determinism anchor, a sealed belief-update trace that comes out byte-identical across several distinct software stacks over several runs. The calibration on that figure is mandatory, because an audit caught an inflated version of it and pulled it down.
Continuity is treated as a ladder of separate falsifiable rungs. The first rung is green: agent state survived a process restart bit for bit, durable, hash-checked and failing closed on a single-bit corruption. The second rung travels with it inseparably and is owed. A real kernel cutover completed with no data loss, while continuity of the mind's own tick across that swap has not been shown. The first attempt failed outright before being root-caused and recovered, and the honest phrasing is mechanism green across a process boundary. A further negative records that a single-machine swap is a seconds-long freeze rather than zero downtime, and that some media paths are not preserved.
The sensorium section carries the chapter's loudest warning. The machine reads its own telemetry into a small categorical alphabet flowing live on both boxes. It is an input channel and an honest worked example, and it is never evidence of awareness. A recorded negative explains the design, since an over-compressed version of the channel went negative on held data, which is why the fuller contract is the contract.
The remaining sections describe a gated action surface, in which the operator approves or declines and every verdict updates a persistent prior. They also cover a single-approval route for cross-machine changes, and isolation primitives shown under inspection rather than as held gates. Last comes a set of honest trades and open gaps, the central one being that the live system does not yet run the primitives that earned the science gates.
Clear · written 2026-08-01 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is b884ed404697a421