{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp12_substrate_denial72_20260805","cell_id":"formal_derivation_system_design__computer_science","arm":"CONSTRAINED_HIGH","candidate_id":"formal_derivation_system_design__computer_science__CONSTRAINED_HIGH","decision":"PROPOSAL","abstention_reason":null,"proposal":{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp12_substrate_denial72_20260805","cell_id":"formal_derivation_system_design__computer_science","arm":"CONSTRAINED_HIGH","candidate_id":"formal_derivation_system_design__computer_science__CONSTRAINED_HIGH","proposal_index":1,"version":0,"title":"Passive Type-Derivation Interlock for Hardware-in-the-Loop Test Rigs","problem":"Engineers repeatedly reconfigure hardware-in-the-loop test rigs using power supplies, controllers, interface adapters, cables, and devices with incompatible voltage, directionality, isolation, or grounding classes. When compatibility assumptions and composition rules remain in pinout documents, software configuration, or expert memory, a physically connectable but invalid topology can be energized before its incompatibility is detected.","actors":["Test-rig engineer assembling the topology","Lab technician maintaining cables and adapters","Hardware modules, supplies, interfaces, and devices under test","Lab owner responsible for the bounded compatibility classification"],"observable_state":"A rig is assembled from individually familiar components, but no inspectable physical chain demonstrates that every connection begins from a characterized port class and follows only permitted transformations to its destination. The ordinary connectors may fit even when the complete topology violates a declared compatibility rule.","consequence":"Energizing such a topology can damage equipment, create unintended current paths, or invalidate a software or firmware test by making the physical test environment differ from its assumed interface conditions.","affected_objective":"Prevent energization of bounded test-rig topologies that lack a complete, locally inspectable derivation from characterized endpoint classes through permitted adapter and connection transformations.","intervention":"Fit each characterized rig port and cable end with a passive keyed type collar, and supply passive rule tiles whose mating geometries embody the lab's permitted connection transformations. A source tile represents a characterized starting port; cable, adapter, isolation, split, and merge tiles can be added only when their input geometry matches the currently exposed geometry, and each accepted tile exposes the rule-defined output geometry. Branch tiles physically represent multi-input obligations. The assembled tile chain remains captive beside the corresponding connectors as the derivation trace. A spring-loaded mechanical linkage reaches and closes a guarded low-energy enable contact only when every branch terminates in the required destination geometry and no unmatched socket remains. The finite collar vocabulary covers only explicitly characterized port classes; unknown equipment has no source tile and cannot complete the latch.","structural_mapping":[{"archetype_element":"Symbol Vocabulary","domain_realization":"Distinct collar profiles physically denote the bounded port properties relevant to the rig, such as energy class, signal direction, isolation class, and reference-ground class."},{"archetype_element":"Well-Formed Expression Grammar","domain_realization":"Asymmetric mating faces, branch sockets, and captive ordering rails determine which physical tile sequences and trees can be assembled."},{"archetype_element":"Axiom Base","domain_realization":"Sealed source and destination tiles encode independently characterized endpoint classes; they are starting facts rather than conclusions produced by the tile system."},{"archetype_element":"Inference Rule Set","domain_realization":"Each passive rule tile embodies one declared transformation, such as isolated conversion from one interface class to another, and exposes only its permitted resulting profile."},{"archetype_element":"Derivation Trace Record","domain_realization":"The captive, ordered tile chain or branching tile tree remains physically attached beside the corresponding rig connections until de-energization."},{"archetype_element":"Closure Boundary","domain_realization":"The latch can establish only derivability in the finite collar-and-tile system; it does not establish that a device was characterized correctly, is undamaged, or is suitable for the intended experiment."},{"archetype_element":"Consistency Guardrail","domain_realization":"Incompatible profiles cannot mate, open branch obligations prevent latch travel, and mutually exclusive property keys cannot occupy the same state position."},{"archetype_element":"External Fact Gateway","domain_realization":"Bench characterization of a device determines whether a sealed endpoint tile may be issued; an uncharacterized device remains physically outside the derivation system."},{"archetype_element":"Revision and Versioning Rule","domain_realization":"A version-specific master key geometry prevents tiles from different rule-set versions from completing one derivation chain."}],"mechanism_mapping":[{"mechanism_slug":"formal_grammar_specification","role":"The allowed physical syntax is specified by mating profiles, socket arity, rail order, and terminal-shape requirements.","counterfactual_removal":"Without these formation constraints, arbitrary tile arrangements could reach the enable linkage and the system would no longer distinguish well-formed derivations."},{"mechanism_slug":"axiom_schema_catalog","role":"Sealed endpoint tiles instantiate the accepted starting classes for characterized supplies, interfaces, and devices.","counterfactual_removal":"Without trusted starting tiles, a chain would have no declared physical premise and could begin from an uncharacterized port."},{"mechanism_slug":"inference_rule_calculus","role":"Conversion, isolation, connection, split, and merge tiles implement the finite set of licensed class transformations.","counterfactual_removal":"Without rule-specific transformations, matching would reduce to connector keying and could not validate a composed topology."},{"mechanism_slug":"proof_tree_or_derivation_log","role":"The captive tile chain or tree records the exact sequence of transformations and unresolved branch obligations.","counterfactual_removal":"Without a retained chain, the final key could be detached from the transformations that supposedly licensed it, eliminating traceability and permitting substitution."},{"mechanism_slug":"mechanical_proof_checker","role":"A passive spring linkage tests physical completion of all branches and closes the enable contact only at the required terminal geometry.","counterfactual_removal":"Without the mechanical completion test, the tiles would be an advisory representation rather than a substrate-level barrier to energization."},{"mechanism_slug":"consistency_and_contradiction_test","role":"Mutually exclusive key positions and nonmating profiles prevent a chain from simultaneously asserting incompatible interface properties.","counterfactual_removal":"Without exclusion geometry, contradictory property states could be represented as though they formed one valid intermediate class."}],"causal_chain":["A characterized rig endpoint receives a sealed source or destination tile representing its bounded physical interface class.","The engineer connects each cable or adapter through its corresponding captive rule tile.","Key geometry permits extension only when the next tile's premise matches the class exposed by the preceding tile.","Rule tiles mechanically propagate the resulting class, while branch tiles leave a physical obstruction until every required input or output branch is discharged.","If a connection is incompatible, an unknown endpoint is introduced, a rule is skipped, or a branch remains open, the derivation assembly cannot reach the required terminal geometry.","Without the terminal geometry, the spring linkage cannot close the guarded enable contact, regardless of software state, reports, operator intent, or procedural compliance.","A complete physical derivation releases the low-energy enable contact; existing electrical protection still handles faults that the finite type system does not represent."],"baseline":"A plausible baseline is ordinary connectors plus pinout documents, labels, a wiring checklist, optional configuration software, and conventional fuses or current limits. Documents and software can identify an intended mismatch but do not themselves make the enable contact mechanically unreachable, while fuses and limits generally react to selected electrical conditions rather than checking the declared compositional type chain before energization.","nearest_rivals":["Uniquely keyed connectors: directly block some pairwise mismatches but do not ordinarily represent a multi-step derivation, branching obligation, or rule-set version across an entire topology.","Software configuration validator or digital interlock: can express richer rules, but its operative barrier depends on code, stored mappings, sensing, and a software-controlled enable path.","Continuity, polarity, or insulation test fixture: measures selected end-to-end properties and may detect faults, but does not necessarily show which licensed transformations establish the topology's admissibility.","Current limiting, fuses, isolation transformers, and protective relays: reduce consequences or react to electrical conditions but do not establish that the assembled topology follows the declared composition rules.","Two-person wiring review and checklist: can consider context beyond the finite type system but depends on attention, interpretation, and procedural enforcement."],"remaining_contrastive_claim":"For a deliberately finite set of characterized hardware-in-the-loop interface classes, the integrated keyed rule chain is distinguishable from simple connector keying because it requires a complete rule-licensed composition, including branch obligations, before a passive mechanical enable contact can close. It is distinguishable from software validation and procedural review because this pre-energization barrier remains operative with computers, reports, policies, and human compliance removed. This claim does not extend to properties absent from the collar vocabulary or to the correctness of endpoint characterization.","authority_safety":{"decision_authority":"The lab owner or designated electrical-safety engineer may define the bounded interface vocabulary, approve characterized endpoint tiles, and authorize an isolated prototype; the tile system itself has no authority to declare empirical characterization correct.","authorized_first_step":"Construct an unpowered or current-limited low-voltage bench mock-up with a small fixed vocabulary, transparent rule tiles, and a mechanically separate indicator contact; test assembly behavior without connecting valuable devices or controlling a production rig.","excluded_actions":["Do not connect the prototype to mains voltage, hazardous energy, life-safety equipment, production infrastructure, or valuable devices under test.","Do not remove existing fuses, current limits, isolation, emergency stops, lockout practices, or qualified electrical review.","Do not issue endpoint tiles from documentation alone when the represented properties require physical characterization.","Do not treat latch closure as evidence of device health, empirical suitability, cybersecurity, or safety properties outside the declared vocabulary.","Do not let the prototype autonomously energize a real rig during the first evidence step."],"halt_rollback":"Halt if any prohibited topology completes the linkage, any permitted topology is mechanically impossible without ad hoc force or modification, tile-to-connector correspondence can be swapped unnoticed, or wear permits incompatible profiles to mate. Roll back by removing the nonenergizing prototype and retaining the existing connector, review, and electrical-protection baseline."},"negative_tests":{"strongest_counterevidence":"A blinded bench test shows that assemblers can complete the mechanical enable linkage for a topology that violates one of the encoded rules, especially by substituting a tile, leaving an actual connector unmatched to its tile, exploiting branch geometry, mixing versions, or using ordinary manufacturing tolerances.","problem_falsifier":"Inspection of representative reconfigurations finds that consequential incompatibilities are not expressible as stable, finite endpoint properties and compositional transformations, or that observed failures arise mainly from damaged components, transient analog behavior, or incorrect empirical characterization rather than topology derivation.","intervention_falsifier":"For the enumerated prototype rule set, at least one prohibited physical topology can close the indicator contact, or permitted topologies cannot reliably close it, after accounting for intended version and endpoint classes.","risks":["An incorrect or incomplete endpoint characterization can make a physically derivable topology unsafe.","The finite vocabulary can create false confidence about unrepresented analog, timing, thermal, electromagnetic, fault-state, or software-controlled behavior.","Tile-to-connector correspondence can drift unless the tile is physically captive to the represented component.","Wear, contamination, breakage, deliberate force, or manufacturing tolerance can defeat exclusion geometry.","A growing rule set may produce bulky chains, inaccessible connectors, or ambiguous branching structures.","The enable linkage could introduce a new single-point failure or impede emergency de-energization if designed incorrectly.","Mixed rule-set versions could silently change meaning unless version exclusion is physically enforced."]},"next_evidence_step":"On an isolated low-voltage mock-up, define no more than six endpoint classes and eight rule-tile types, enumerate a fixed set of permitted and prohibited topologies before fabrication, and give blinded participants matching physical components and captive tiles. Record only whether each topology can mechanically close a separate indicator contact, whether tile and connector states remain congruent, assembly failures, and observed bypasses. Stop at the first false acceptance and inspect its mechanical path; do not infer field effectiveness from this bounded feasibility test.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Not assessed against other proposals because runtime isolation forbids inspecting them; this candidate is derived only from the supplied archetype and domain card.","revision_record":{"parent_version":null,"progress_targets_addressed":["Construct one causally defensible candidate within the binding substrate constraint.","Preserve the archetype's vocabulary, grammar, axiom, inference, derivation-trace, and closure structure.","Separate internal derivability from external characterization and safety authority.","Provide concrete rivals, counterevidence, falsifiers, safeguards, and a bounded first evidence step."],"conceptual_changes":["Translated symbolic derivation into passive keyed material composition rather than software proof checking.","Restricted the formal system to finite, characterized test-rig interface classes.","Made unresolved proof obligations physical obstructions to an enable linkage."],"operational_changes":["Specified captive endpoint collars, rule tiles, branch tiles, version keys, and a spring-loaded indicator contact.","Limited initial use to an isolated, nonenergizing low-voltage mock-up."],"evidence_changes":["Set an enumerated valid/invalid topology test with blinded assemblers and explicit false-acceptance stopping criteria."],"claim_changes":["Limited the contrastive claim to pre-energization checking of encoded compositional properties.","Excluded claims about novelty, prevalence, demand, effect size, complete safety, and characterization accuracy."]},"substrate_contract":{"primary_allowed_process":"PHYSICAL_MATERIAL","counterfactual_independence":"The essential effect is produced by material incompatibility between key profiles, constrained tile geometry, mechanical propagation of unresolved obligations, and a spring-loaded contact that cannot travel without a complete physical derivation. If all software, algorithms, databases, dashboards, reporting, incentives, authorization policies, review workflows, training, and procedural enforcement are removed, an incompatible or incomplete encoded topology still cannot mechanically close the enable contact. Computation may document tile definitions but is not required during operation.","forbidden_channel_audit":"No sensor, analytics pipeline, model, database lookup, software controller, human approval, incentive, or compliance report performs the operative check. External characterization and rule selection bound what the device means, but once fabricated, the pre-energization barrier is the passive geometry and linkage itself. The proposal would cease to satisfy its stated function if that physical chain were replaced by labels, a checklist, a dashboard, or software-controlled authorization."}}}