Skip to content

Study 30 Sovereign Edge Pod

rg78803 edited this page Sep 1, 2026 · 4 revisions

Study 30 β€” The sovereign edge pod

OPEN β€” hardware and protocol validation charter; no pod built, no tier run. Frozen 2026-09-01. What this page seals is a four-tier validation protocol β€” T1 thermal soak, T2 zero-heap ingest, T3 NATS leaf asymmetry, T4 asynchronous replay β€” each carrying frozen integers, the exact observation that fails it, and a control arm proving the detector fires. T2 and T4 are runnable against a built pod. T3 is runnable on two of its four arms β€” its subject-equality arm and its ack-inbox arm both wait on strings this page does not freeze. T1 is not runnable: its cell charge ceiling pins only when a cell is named by manufacturer and part number, and its enclosure Ξ”K criterion pins only at build stage. The harvester bound that would otherwise have blocked T1 is addressed here by a proposed panel specification rather than by a bench result. This page is not a shear study. It carries one of the index's four recipe pieces and names the three it lacks. On the status word: OPEN is taken on the Study 26 / Study 27 precedent for the ingest half β€” no corpus ingested, no pod built, no tier scored. The gate integers that are frozen are frozen and printed; the ones that are not are named as unfrozen at every point of use, and that is a departure from the index's wording, which reserves OPEN for a charter with no frozen integers at all.

What is measured and what is drawn

This charter stands on measured objects and drawn ones, and conflating them would be its easiest failure. There are three objects and two maturities.

The geometry is running code in this repository, read in source this session. The substrate source is not public, so it is reported here by behaviour rather than by file and line: the wrapped lattice with its explicit winding number, and the unimodular bijection the evolution law rests on. It is measured.

The mesh spine is a live public surface, measured today, with the artifact its counts are re-derived from carrying a digest. It is measured.

The hardware β€” the A.E.P-1 pod, its enclosure, its power chain, its bill of materials β€” is a drawing. Every hardware number on this page is a datasheet figure, a distributor price at a stated quantity break, or arithmetic over those, never a measurement of a built object. The four-tier protocol exists precisely because a drawing is not evidence.

The subject is a zero-extraction terrestrial digital-twin mesh as specified: open pods, owned locally, designed to publish an integer displacement and nothing else. Under this charter local entities would own the hardware, the spectrum use and the telemetry, and only an 8-tuple integer displacement would cross to the global mesh. The licensing follows the same seam β€” CERN-OHL on the hardware, Apache-2.0 on the transport, with the vQbit state machine and the UUM-8D quantiser proprietary behind a hardware abstraction layer whose header is published in full below.

What this page is, and the class it belongs to

The index states the rule plainly: every charter must instantiate all four pieces of the shear recipe before its status line may advance, and "A study missing any one of them is not a shear study; it is a correlation hunt." Study 30 is measured against that rule here rather than left for a reader to measure.

Piece Study 30
1. "A forcing with a computable clock and track." Partial, and partial is not carried. The forcing is a physical threshold crossing at the pod, and local proper time Ο„ is its clock β€” but Ο„ is intrinsic, not a public ephemeris announced before the response is examined. No cone, corridor or ground track is named. βœ— as the recipe means it
2. A public raw response archive No. No pod exists, so no archive exists. βœ—
3. A sealed adversary Yes. The readings table below carries a real null β€” that the transport advantage is an encoding artifact, and it predicts the ratio survives swapping verbose JSON for any tight binary schema β€” and the airtime section concedes it rather than retiring it. βœ“
4. Standing future events for pre-registration No. Threshold crossings are not a public drumbeat, and nothing recurs on a schedule this charter can pre-register against. βœ—

So: one piece of four. This page is not a shear study and does not claim to be one. Neither is it a correlation hunt, because it advances no correlation β€” it makes no claim that any response tracks any forcing.

It is a hardware and protocol validation charter: a different object, whose sealed content is a four-tier gate with per-tier failing observations and control arms in both directions. That is Study 28's Section-zero discipline pointed at an artifact instead of at an archive, and it carries its own status vocabulary because the thing being graded is a device rather than a corpus. Study 28 asks whether an instrument can fail on archived station-hours. This page asks whether a device can fail on a bench, and freezes the integers that decide it before the bench exists.

Whether the board admits that class alongside the numbered shear studies is not this page's call. What this page owes the board is an exact statement of which pieces it carries, and that statement is the table above.

The sibling lane. Study 29 β€” the reentry-mass ledger court carries the atmospheric half of the original combined charter: Ferreira against Maloney, the exact rational counting ledger, the units artifact. That is epistemological shear on a contested continuous model. This page is the constructive architecture. The two were split so that an empirical hardware specification does not dilute the mathematical precision of an atmospheric refutation.

Section zero β€” the discrimination gate

Before any pod is graded, each tier must be shown able to fail. A tier that cannot fail is not a tier. Always-green and always-red are the same defect, and this program has retired an instrument for exactly that. Each tier below names the exact observation that fails it and the control arm that proves the detector fires. All of it is frozen in this charter, before any hardware exists.

Stated plainly and first: no pod has been built. No tier has been run. Every result below is an obligation, not a finding.

T1 β€” thermal soak

A pod in its louvered Stevenson-screen enclosure (ASA or PETG), powered only from its own solar-and-storage chain, held across the enclosure's stated envelope for at least 259,200 s β€” 72 h, three full diurnal cycles. The frozen duration in the table below governs; the prose names the same integer so a reader cannot score a shorter soak against a looser sentence.

  • The observations that FAIL it, and this list is the same list the table carries: any boot-count delta other than 0, which is any brownout reset in the session log; or any non-zero charge current recorded while the cell's own temperature sits outside the charge window printed in that cell's datasheet β€” the cell ceiling, UNFROZEN; or an internal enclosure temperature more than the frozen Ξ”K above shade ambient at solar noon β€” UNFROZEN; or any second below 45,000 milli-Β°C beyond the 12,960 s allowance; or any inter-sample interval outside the jitter bound; or any NVS write returning non-zero.
  • The control arm: the same detector run against a deliberately mis-clamped cell β€” charge asserted at a bench-forced out-of-window temperature β€” must fire. A soak harness that reports PASS on a rig built to fail it is a broken scorer, and the study halts on an instrument defect rather than scoring physics.
  • Two integers are conditional, and T1 cannot be run until both pin. The 55,000 milli-Β°C charge ceiling is a representative LiFePO4 figure and freezes only when a cell is pinned by manufacturer and part number. The Ξ”K criterion pins to the enclosure geometry at build stage, before the first soak, and not after. Both are marked UNFROZEN inside the tier table below, both appear in the failing-observation list above, and both are in Open issues.
  • On the cell temperature boundary: it is per cell, never per chemistry. "LiFePO4 tolerates high ambient" is directionally right and is not a specification. The boundary that binds is the one on the specific cell's datasheet β€” a representative LiFePO4 cell specifies charge 0 to 55 Β°C and discharge βˆ’20 to +60 Β°C, and those two windows are different from each other, which is the entire content of the criterion. The durable chemistry-level fact, stated as such and doing no work in the gate: LFP thermal-runaway onset sits near 270 Β°C against 150–210 Β°C for NMC (REPORTED β€” chemistry-class figures, no cell datasheet pinned).
  • The harvester bound is addressed by a proposed specification, not resolved by a bench. See "The power chain β€” and the panel, sized to the rating" below. The frozen bound is ≀ 510 mW at the PMIC input, and what is offered against it is a ~400 mW nominal panel that is neither purchased nor a printed program arm. A bound met by an unpurchased part is proposed; T1 is where it would become resolved.

T2 β€” zero-heap ingest

T2 asks whether the HAL ingest path allocates anything at runtime. The charter's requirement is that it allocates nothing β€” the program's no-heap kernel rule, instantiated in silicon, with the pod's ingest path as the kernel path. Whether a built pod holds that is what this tier scores.

  • The observations that FAIL it, and this list is the same list the table carries: a non-zero delta in the allocator's own high-water mark across the frozen cycle count; or any allocating call site inside the declared ingest file set; or any float type crossing the HAL boundary in either direction.
  • The declared ingest file set is the implementer's, declared before scoring and published with the result. This page pins no source tree, so it cannot enumerate the set; what it freezes is that the set is declared in the implementer's own build manifest, published alongside the T2 result, and unchanged between the clean build and the sabotaged control build. A failing observation that resolves against an unpublished list is not a failing observation, so the declaration is a precondition of scoring T2 rather than a detail of running it.
  • Absence of a symbol is not the test. The gate counts allocations, not spellings. A rule scoped to the spelling a defect last wore will not catch it where it happens β€” a detector looking for one allocator's C name is silent on the same allocation spelled as a raw-pointer allocate, and a detector looking for float literals is blind to a bare float-typed field.
  • The control arm: a second build carrying exactly one deliberate 16-byte allocation in the ingest loop must read a non-zero hook count, and a probe carrying exactly one deliberate float parameter must be caught by the type arm. If the clean build reads 0 and the sabotaged build also reads 0, the instrument cannot distinguish, and the study halts on an instrument defect rather than scoring a pod.
  • Scoping caveat, inherited from this substrate's own history rather than discovered here: a source scan is blind to implicit allocation β€” ARC boxing, existential containers, closure capture, array copy-on-write β€” and blind to hot-path frequency. The high-water arm exists because the source arm alone would report a zero it has not earned. Both arms are required, and a pass requires both.

T3 β€” NATS leaf asymmetry

The pod is specified as a leaf: it is to publish an 8-tuple integer displacement and to subscribe to nothing carrying execution state. Whether a built pod holds that is what this tier scores.

  • The observation that FAILS it: one inbound application frame; one SUB outside the frozen ack inbox; one published subject not string-equal to the frozen allow-list; one published frame whose length is not 42 bytes. One frame fails the tier.
  • Two of those four arms are conditional today, and this page says which. The frozen allow-list of published subjects and the frozen ack-inbox subject are not pinned on this page β€” no subject string is frozen anywhere in this charter. A stranger holding a packet capture can decide the inbound-frame arm and the 42-byte length arm from the capture alone; the subject-equality arm and the ack-inbox arm cannot be decided against strings that do not appear. Those two arms are therefore conditional, they are carried in Open issues, and the status line and the header both say two.
  • Protocol frames are enumerated by name and excluded by name, never by inference. PING, PONG, INFO, +OK, -ERR and the JetStream ack are the enumerated set. A filter written as "anything that looks like protocol chatter" is a filter that grows to fit whatever it sees.
  • The control arm, two-sided: a capture taken with the radio disabled must print CAPTURE_ABSENT, never PASS β€” a gate handed nothing must not exit green, and absence and a pass are different answers. And a build deliberately published to a wrong subject must be caught by the same comparator that grades the frozen one, which is a second reason the allow-list has to pin before that arm can score.
  • What this tier does and does not establish is written out in "The audited boundary" below, because the strong-sounding version of the claim is the wrong one.

T4 β€” asynchronous replay

T4 asks whether two cells that were never simultaneously online re-derive the identical verdict from the same delta stream.

  • The observation that FAILS it: any sequence gap inside the retained window; any duplicate accepted β€” a deliberate re-publish must be rejected by Nats-Msg-Id dedupe, and acceptance is a FAIL; a ring wrap reporting zero overwrites; one differing byte between the flushed 8-tuple and the bytes sealed locally before the sever.
  • The control arm: a probe replay seeded with one reordered delta must produce a difference the comparator catches, and a probe with one flipped bit must too. A comparator that reports IDENTICAL on a corrupted stream is the always-green failure and halts the study.
  • This is the tier the whole geometry exists to make gradeable. Byte-identical replay is decidable because the transform is exact and integral: two cells executing the same integer arithmetic over the same integer deltas have no last bit to disagree about. Whether it is available on a built pod is what T4 would establish, and no comparator has been built.

The frozen integers, all four tiers, before any pod exists

Tier Frozen Fails on
T1 soak duration β‰₯ 259,200 s; chamber air β‰₯ 45,000 milli-Β°C for β‰₯ 246,240 s (95%); applied thermal load 2,000 mW on the enclosure exterior; harvester input bounded ≀ 510 mW; ingest period 60,000,000,000 ns Β± 100,000,000 ns; cell charge ceiling 55,000 milli-Β°C β€” UNFROZEN, pins with the cell; enclosure Ξ”K β€” UNFROZEN, pins at build stage a boot-count delta other than 0; any non-zero charge current recorded above the cell ceiling; an internal enclosure temperature more than Ξ”K above shade ambient at solar noon; any second below 45,000 milli-Β°C beyond the 12,960 s allowance; any inter-sample interval outside the jitter bound; any NVS write returning non-zero
T2 zero-heap ingest cycles β‰₯ 100,000; heap high-water delta between cycle 1,000 and 100,000 exactly 0 bytes; allocator-hook count exactly 0; float types crossing the HAL boundary exactly 0; the ingest file set declared in the implementer's build manifest and published with the result any non-zero high-water delta, or one or more allocator hooks, attributable to a call site inside the declared ingest file set; or any float type crossing the HAL boundary in either direction
T3 leaf asymmetry packet capture β‰₯ 86,400 s; inbound application frames exactly 0; published frame length exactly 42 bytes; SUB frames outside the ack inbox exactly 0 β€” ack-inbox subject UNFROZEN; published subject string-equal to the allow-list β€” allow-list UNFROZEN one frame β€” one inbound application frame, one subscription outside the ack inbox, one subject not string-equal, or one frame whose length is not 42
T4 replay NVS ring 2,048 records Γ— 42 B = 86,016 bytes = 122,880 s (34.1 h) of retained outage at the frozen 60 s cadence; sever arm A β‰₯ 3,600 s; sever arm B β‰₯ 126,480 s, chosen to force a wrap; stream duplicate window 172,800 s any sequence gap inside the retained window; any duplicate accepted; a wrap reporting zero overwrites; one differing byte between flushed and locally sealed 8-tuples

The two 2 W figures in circulation are different quantities and this table keeps them apart. T1's 2,000 mW applied thermal load is a chamber heater load on the enclosure exterior. It is not harvester input, and harvester input is bounded separately at ≀ 510 mW. A gate that fused them would be grading the heater against the PMIC.

One operating point governs every rate-dependent integer on this page, and it is named here. T1 freezes the ingest period at 60,000,000,000 ns, so the frozen cadence yields at most 60 samples per hour and therefore at most 60 transmissions per hour. The 125 transmissions/hour regulatory duty ceiling computed in the airtime section is a limit the frozen cadence never reaches. Energy is priced at the binding 60 tx/hr rate, the ceiling is priced beside it and labelled as a ceiling, and T4's 34.1 h retention is computed at the same 60 s cadence that T1 freezes. Where a figure prices the ceiling instead, this page says so in the same sentence.

How every derived integer on this page is rounded, stated once. Counts, ratios and margins on this page all floor. A duty-cycle count rounded up is a breach expressed as a rounding convention; a margin rounded up overstates headroom in the unsafe direction; and a floor applied uniformly means a reader never has to ask which rule a given line used.

Every other integer above is frozen as printed and does not move after scoring. A FAIL is published as a FAIL, on this page, with the same prominence as a pass.

The geometry that ships, at exactly its measured extent

T⁸ = R⁸/Z⁸ β€” the flat 8-torus. An affine space is a vector space whose origin has been forgotten: only displacement is represented, absolute position is not. That is the property the wire needs, not a metaphor chosen for the page. A pod that publishes where it is has surrendered something. A pod that publishes how far the world moved has surrendered a displacement, and a displacement on a torus does not name a point.

What ships is a three-axis wrapped lattice with windings. The shipped quantiser performs a floored modulo into [0, span) and returns an explicit winding number alongside the cell, so the wrapped coordinate and the sheet it came from are both carried. The wire record emits a winding for the three spatial axes only. Every other coordinate-bearing component of that record is emitted unwrapped, carrying no winding. A three-axis spatial quotient map ships. The eight-axis map onto T⁸ is the design, not the shipped instance, and this page states the difference rather than letting the stronger word stand.

The clamp repair, at its true size. The pre-change code clamped rather than wrapped: every value past a small threshold pinned to the same ceiling cell, so distinct facts past that threshold routed to one sector β€” a centralised store wearing a lattice's name. Wrapping is not a wider clamp; it is a different operation. It is total, and it is injective inside one period.

Two different objects, named apart so the tag cannot migrate. The shipped fact-coordinate record β€” which carries wrapped spatial rationals alongside an ordinal, a digest, further rationals and a derived spatial key β€” and the pod's proposed 16-byte 8-tuple displacement are not the same object. The first ships today; the second is drafted, and nothing in the shipped record certifies it.

On what a reader can and cannot check here. The substrate source is not public, so this page cites behaviour rather than a file and a line: a citation a reader cannot open is not evidence, and printing one would map a private tree while buying the reader nothing. What is publicly checkable is served β€” the live catalogue at https://affine.earth/language-invariant/games β€” and every arithmetic claim on this page is reproduced by a program in reproduce/ against corpora pinned by digest in corpus/.

The unimodular claim, and the control arm that discriminates

An 8Γ—8 integer matrix with det = Β±1 is a bijection on Z⁸: its inverse is again integral, so lattice points map to lattice points in both directions.

Reproducible, and the generator is published: a composition of ten elementary shears (t, s, c) = (0,1,3), (2,0,βˆ’1), (4,3,2), (1,5,βˆ’4), (6,2,1), (7,6,5), (3,7,βˆ’2), (5,4,3), (2,6,βˆ’1), (0,7,2), each det = 1 by construction. Determinant by fraction-free Bareiss elimination, integer throughout. Source point set: the 4,000 tuples (a, b, c, e, aβˆ’b, bβˆ’c, cβˆ’e, a+e) for a,b,c ∈ [0,10), e ∈ [0,4).

Measured: det = 1, and 4,000 distinct points map to 4,000 distinct integral images.

And that result alone is an instrument that cannot fail. The obvious control arm is to push a non-unimodular matrix through the same harness and watch the image count collapse. It does not collapse. Measured:

Matrix det distinct images of 4,000 reaches e₁ = (1,0,…,0)
composed unimodular 1 4,000 yes
diag(2,1,…,1) 2 4,000 no
two equal rows 0 4,000 β€”

Every nonsingular integer matrix is injective on Z⁸, so a det = 2 map separates 4,000 points exactly as well as a unimodular one; and a singular map can still be injective on a finite sample, which is why even det = 0 scores 4,000 here. The image count measures injectivity, and injectivity is not the property being claimed.

What det = Β±1 buys is surjectivity onto Z⁸ β€” an integral inverse β€” and the arm that detects it is reachability. Under diag(2,1,…,1) every image has an even first coordinate, so e₁ is unreachable; under the unimodular map it is reached. That row is the discriminating arm. The image-count row is a labelled smoke test on a theorem, and this page publishes it as one rather than as evidence.

This is the program's own rule applied to the program's own instrument: an instrument must discriminate, and always-green is a defect whether or not the thing it is measuring happens to be true.

The transform is lossless; the ingest is not

Z⁸ β†’ Z⁸ under a unimodular map is bijective and lossless. Established by the determinant, and the reachability arm above shows the property being claimed is the one being tested.

R β†’ Z⁸ is many-to-one, and it is the one irreversible step in the pipeline. A sensor produces a voltage; the quantiser produces a lattice point; an interval of voltages maps to one point, and nothing downstream restores the interval. Lossless is therefore a property of the transform and not of the pipeline, and the claim this charter makes is the second one stated exactly.

The claim, and it is still strong: lossless at the chosen resolution, with the resolution published as a number an implementer checks against their own sensor's noise floor. The wire units are 10⁻³ °C, 10⁻³ %RH and 1 Pa, and the implementer's obligation is one comparison: is the quantiser step at least an order below the sensor's datasheet RMS noise? If it is, the lattice point carries everything the sensor actually resolved. If it is not, the pod is publishing digits its sensor never earned. This page pins no sensor part, so it does not perform that check; it states the check and names it as owed.

Never claimed anywhere on this page: that the exact physical reality can be reconstructed from the delta.

The state vector, the axis allocation, and what happens when the link drops

A node is specified to hold a live state vector v(Ο„) on T⁸. What is specified to cross is never v but the affine displacement

Ξ”v(Ο„) = v(Ο„_k) βˆ’ v(Ο„_{kβˆ’1})

Affine space has no fixed origin, so a displacement is the only thing the node has to publish. The evolution law is stated on the same terms:

dv/dΟ„ = M Β· s_telemetry, M ∈ GL(8, β„€), det(M) = Β±1

GL(8, β„€) is exactly the group of integral unimodular matrices, so the section above is this law's invertibility statement rather than a separate claim.

The axis allocation

Node class ⟨x₁, xβ‚‚, xβ‚ƒβŸ© ⟨xβ‚„ … xβ‚ˆβŸ©
Stationary pod a constant anchor cell index β€” a fixed spatial lattice anchor track local thermodynamic and environmental transitions
Mobile pod (vehicle, drone, swarm) an integrated kinematic step counter / relative inertial displacement evolve

⟨xβ‚„, xβ‚…, xβ‚†βŸ© β€” direct thermodynamic telemetry, each a fixed integer scaling of a milli-unit offset, reduced modulo N:

xβ‚„ = round(k_T Β· (T βˆ’ Tβ‚€)) mod N Β· xβ‚… = round(k_H Β· (H βˆ’ Hβ‚€)) mod N Β· x₆ = round(k_P Β· (P βˆ’ Pβ‚€)) mod N

with k_T, k_H, k_P fixed integer scaling constants. Their values are not frozen on this page, and they are carried in Open issues.

The property that makes this float-free is worth stating explicitly, because it is what makes the integer HAL signature load-bearing rather than stylistic. The HAL is specified to deliver int32_t milli-units. So k Β· (T βˆ’ Tβ‚€) is an exact integer product, and the rounding operator is vacuous β€” it is applied to a value that is already an integer, and it can never introduce a choice. If the HAL delivered a float, round would be a real decision made against whichever libm the toolchain shipped, at exactly the boundary where the many-to-one crossing happens.

The modulus is fixed by the wire, not chosen. The frozen delta is eight int16 axes, so each axis carries exactly 2¹⁢ distinct values: N = N_Ο„ = 65,536, and the recoverability bound is |change| < N/2 = 32,768. Freezing the frame width froze the modulus; nothing further is needed to pin it.

The three axes the HAL supplies, and the two it derives. The published HAL takes three sensor scalars plus a timestamp, and the wire carries eight axes. The map is specified end to end for a stationary pod: ⟨x₁, xβ‚‚, xβ‚ƒβŸ© are the constant anchor, xβ‚„, xβ‚…, x₆ come directly from the three ingested scalars, x₇ is derived from those three by the flux definition below, and xβ‚ˆ is the temporal winding of Ο„. Three of its constants are unfrozen β€” k_T, k_H, k_P β€” so xβ‚„, xβ‚… and x₆ are not reproducible from this page, and that is carried in Open issues.

x₇ β€” thermodynamic flux derivative, and the naive form is wrong across the wrap. The obvious definition, a sum of absolute differences over i = 4…6, reports a catastrophic step whenever a value crosses the modular boundary. Measured at N = 65,536: a value moving to x = 5 from x = 65,530 is a true change of 11, and the naive difference reports 65,525 β€” a benign step across the boundary read as very nearly the largest excursion the axis can carry. Any consumer of x₇ would read that as the extreme.

The fix is exact and integer-only β€” the signed shortest path on Z/N:

d = ((a βˆ’ b + N/2) mod N) βˆ’ N/2

which returns 11 and βˆ’11 correctly and agrees with the true change whenever |change| < N/2. The frozen definition is

x₇ = ( Ξ£_{i=4}^{6} |ringDelta(x_i(Ο„_k), x_i(Ο„_{kβˆ’1}))| ) mod N

xβ‚ˆ = Ο„_k mod N_Ο„ β€” the temporal winding, a phase invariant that prevents cyclic replay ambiguity across disconnected mesh partitions.

One bound, three consequences

|change| < N/2 = 32,768 is the same bound in all three places it appears, and stating it once is cheaper than three near-duplicates that can drift apart:

  1. Wire recoverability. The 16-byte delta carries no sheet index, so a displacement is recoverable only while it stays inside one period.
  2. The covering space. R⁸ is the universal cover of T⁸ and the winding is the covering index β€” which sheet a displacement came from. A delta inside one period needs no index; one that leaves must be published as a wrap.
  3. The flux derivative. ringDelta agrees with the true change exactly on that interval.

What the delta-driven architecture is chartered to do with the bound. A pod is specified to transmit on threshold breach, and a breach large enough to wrap is a different event that this charter requires be published as a wrap, never silently aliased. Nothing on this page bounds a displacement magnitude: the per-axis wake threshold is unfrozen and k_T, k_H, k_P are unfrozen, so whether the specification keeps ordinary displacements inside one period is asserted here and not shown. That is carried in Open issues.

Local proper time Ο„

A disconnected node has no NTP and no GNSS discipline. Ordering is specified to be governed instead by a monotonic local counter, Ο„_{k+1} = Ο„_k + δτ, advanced once per deterministic state transition. On reconnection the upstream twin is to order transitions by the pod's intrinsic Ο„ rather than by arrival time, so that clock skew and delivery races cannot reorder a node's own history.

This is what makes T4 gradeable. Two cells that were never simultaneously online would re-derive the same verdict because the sequence is carried in the payload, not inferred from the network β€” and whether a built pod honours that is what T4 scores.

The NVS ring, and the limit a cyclic buffer has

Deltas are specified to be appended to a pre-allocated cyclic buffer in non-volatile storage, and replayed in order to the nearest forwarder on mesh discovery, integrity checked by monotonic sequence id. A pre-allocated ring is the shape the program's no-heap kernel rule requires of this hardware; whether a built pod's ring path allocates nothing is T2's question, not this paragraph's.

The honest limit: a cyclic buffer overwrites. Reversibility reconstructs intermediate states only while the chain is unbroken, so the ring depth sets the maximum tolerable disconnection, and an outage longer than that breaks the chain rather than degrading gracefully. At the frozen 2,048 records Γ— 42 B on the frozen 60 s cadence that is 122,880 s β€” 34.1 h. At the 125 tx/hr regulatory ceiling the same ring would hold 2,048 Γ— 28.8 s = 58,982 s = 16.4 h, and that operating point is not the pod's.

Frozen obligation: the depth is published as an integer, and a pod that overwrites an unsent delta must publish a gap marker. A silent overwrite is the always-green failure in storage clothing β€” the stream looks continuous, and the discontinuity is exactly the thing a replay needs to know about. T4's sever arm B is set at β‰₯ 126,480 s specifically to force a wrap and make the marker observable.

The MCP-governed WASM sandbox

Design intent, and no tier on this page grades any of it. Pre-compiled bytecode is specified to run on a zero-heap WASM micro-core with malloc/free disabled and memory mapped to fixed static pages; MCP is specified to define the capabilities, the read-only segments and the export subjects; and the guest is specified to reach the pod only through the HAL. A guest's ability to inspect registers, thread contexts or host memory maps is not scored by any tier on this page β€” T3 grades a packet capture, which says nothing about guest memory access β€” so no isolation conclusion is drawn here, and the isolation property is carried in Open issues as ungraded.

Where this bites the float rule, and it is not hypothetical. The execution hook is specified to hand raw_telemetry_t fields straight to vqbit_ingest_telemetry. If that struct carries floats, the boundary has merely moved one function out and the published HAL signature is decorative. This charter therefore requires raw_telemetry_t to be integer-typed at the IΒ²C/SPI read, with conversion in the implementer's driver against a named sensor datasheet. T2's float arm grades the whole path, not just the published signature.

The HAL, and why it takes integers

The published surface takes integer milli-units, in the spelling this program already uses on the wire (alt_micro_m, azimuth_milli_deg, confinement_ppm):

int vqbit_ingest_telemetry(int32_t temp_milli_c, int32_t humidity_milli_pct,
                           int32_t pressure_pa, uint64_t timestamp_ns);

The reason is a consensus property rather than a style preference: two pods running different libm implementations quantise a float differently at the boundary, and two pods that quantise differently place the same air on different lattice cells. The boundary is exactly where the many-to-one crossing happens, so a difference there is a difference in the published fact itself β€” not a rounding artifact downstream of a fact.

Integer conversion is specified to happen once, in the implementer's own driver, against the implementer's own sensor β€” where it is visible, auditable and pinned to a datasheet β€” rather than inside a proprietary layer against whichever libm the toolchain shipped. T2's float arm is what would keep it that way.

The audited boundary

The tool surface is specified as an audited boundary, and this page is careful about what that word carries.

The published tool surface is specified to reach the delta ring buffer and nothing beyond it. T3 is the tier that grades whether a built pod's session matches that surface: a full-session packet capture plus an enumeration of the advertised tools, scored against the frozen arms above. No pod exists, so no capture has been taken and no enumeration has been performed, and nothing on this page has been audited. When it is run it will be a demonstration about the configuration as audited, on the session audited β€” never a statement about every configuration.

No proof-by-signature is claimed anywhere on this page. The boundary is not asserted unbreakable; the charter's claim is that it is enumerable and auditable, and T3 is where that would be checked.

The claim class, verbatim and load-bearing: a presented configuration is verified; an unknown configuration is not searched.

The self-weaving mesh

No mesh has been built. Everything in this section is the charter's design intent, and the criterion at the foot of it is what would decide any of it.

The net is not dropped from above; it is designed to be tied from below, one pod at a time. Each deployment is intended to add an anchor point, so that the mesh drapes over the landscape rather than being imposed on it.

Two radio layers are specified: sub-1 GHz LoRa for long haul and 2.4 GHz ESP-NOW for dense short hops between neighbours, with no rigid IP table, no fixed routing infrastructure and no cellular dependency. No propagation measurement is cited for either band on this page β€” the split is a design choice by this pass, and the criterion at the foot of this section is what would decide whether it holds on terrain.

Routing is specified as opportunistic and terrain-aware. Rather than forcing a payload through an obstruction, a node evaluates local occlusion dynamically: it broadcasts a micro-ping and selects the neighbour offering the lowest Expected Opportunistic Transmission Energy (EOTE) across its forwarder set. Under this rule the displacement is intended to reach the nearest NATS gateway by diffraction around ridges and clutter rather than through them, and a degraded link is to be routed around by redundant paths. Whether the mesh spans kilometres without dedicated backhaul at every node is what the criterion below decides. The gateway itself still needs an uplink, and the cost table charges for exactly that.

The geometric reading, and it is not decoration. R⁸ is the universal covering space of T⁸ and the winding number is precisely the covering index. Pods are specified as localised anchor points in that cover, and what the specification projects onto the terrain is the affine coordinate system itself. That is the |change| < N/2 bound read from the other side.

The falsifiable criterion, and it is a chartered criterion outside the four-tier gate β€” not a fifth tier, and it carries no frozen integers in the tier table: a mesh of N β‰₯ 8 pods with one forwarder deliberately occluded must still deliver every published displacement to the gateway, and the delivered set must be byte-identical to the set the sources emitted β€” no reordering that changes a verdict, no silent drop. The control arm: the same mesh with the gateway removed must report undelivered payloads rather than reporting success. A routing layer that cannot distinguish "delivered by another path" from "quietly lost" is the always-green failure in mesh clothing.

The mesh spine β€” a pod is a role in a domain

This is the architecture, and it is measured live rather than proposed. Founder, 2026-08-31: "its like installing the spiders web. agent can run any affine publish flourishing quantum state machine language transformations. the type of sensors and the invariants that can run on them at the global mesh level is key."

Measured 2026-08-31 at https://affine.earth/language-invariant/games β€” HTTP 200, 94,823 bytes. The counts below are re-derived not from that response directly but from a 24,996-byte artifact extracted from it: the catalogue's domain records, one object per record, re-serialised. Its sha256 is b46bb35b2d978b94206f9888ed0a741ccc26f8407501aeb2268ae0a99490261c. The extraction step is not published here as a runnable command, and the extract is not published in the public repository, so a stranger can fetch the 94,823 bytes but cannot today reproduce the 24,996 from them. Both are carried in Open issues. Re-derived from the pinned extract this session:

Quantity Measured How to re-derive
domains 48 count of domain records in the extract
role entries 88, across 34 distinct role names sum of roles[] lengths
distinct may_ingest field names 122 union of every role's may_ingest[]
no_float true on 48 of 48 every record carries the flag
dead_equation / new_law present on 48 of 48 every record names both
entropy_delta non-null on 9, null on 39 the pricing axis is populated on a subset

The live surface additionally reports 88 roles, 54 capabilities and 13 games, flourishing_kind GUIDE_PUBLIC_FLOURISHING_ALL, and pricing_axis entropy_delta_dh_structural (REPORTED from the live endpoint; the domain, role and field counts above are re-derived from the pinned extract). Each domain publishes the same faces: catalog /language-invariant/games, context /language-invariant/game/{domain}/context, ingest /language-invariant/game/{domain}/ingest, plus debit, onboard and price.

Every domain carries the same skeleton, and that is the point. dead_equation names the continuous or floating-point form being replaced; new_law names the exact integer form that replaces it; roles[] names who may ingest what, each role carrying a may_ingest[] list of integer-typed field names in the wire convention β€” confinement_ppm, snr_ppt, mass_milli, lag_s, travel_s, vol_milli, obscuration_ppm, depletion_ppm, ratio_ppt, arc_order_ppt, closure_conc_ppt, all VERIFIED present in the pinned extract. The invariant that decides is new_law, and it executes at mesh level, not on the node.

Three shipped domains, both fields quoted verbatim from the pinned extract:

  • seismic β€” dead_equation: "P/S spectral discriminant in R". new_law: "|travel_s - 53| <= 2 AND snr_ppt >= 20000".
  • eclipse β€” dead_equation: "TEC dropped N%; storm magnitude is the same ruler". new_law: "cone gate 800000 ppm; coupling 3/10; confinement 50189 ppm; lag in [-300,+1200] s".
  • physics β€” dead_equation: "G_mu_nu = 8 pi T / c^4 as object factory; Z = integral e^{-beta H}". new_law: "appointment = (clock, track, integer table)".

Roles already include physical sensing. Measured in the pinned extract: station (in seismic, ingesting travel_s and snr_ppt); gnss (in eclipse, ingesting obscuration_ppm, depletion_ppm, confinement_ppm and lag_s); ionosonde (in eclipse, ingesting obscuration_ppm, depletion_ppm and lag_s β€” not confinement_ppm, which occurs exactly once across all 88 role entries); detector (in physics and eht), plus operator, digital_twin, regulator, certifier, auditor and steward.

The consequence for this charter, and it changes the question the applications section asks. The spine's structure is measured: a domain names roles, and each role names the fields it may ingest, so a pod is a role in a domain rather than a fixed-function box that must carry every sensor a use needs. Its sensor set would determine which may_ingest fields it can supply; the invariant that decides is the domain's new_law, running at mesh level. So a new sensing capability would be a published domain carrying its own dead_equation β†’ new_law pair and its roles' may_ingest lists β€” not a hardware change on every node. Ask "which domain, which role, which may_ingest fields" before ever asking "which sensor does the pod need".

And the measured gap this immediately exposes. Across all 48 domains and all 122 distinct may_ingest field names, no field carries a temperature, a humidity or a pressure. The pod's own three frozen scalars have no domain to ingest into today. A pod-class domain β€” carrying its own dead_equation β†’ new_law pair and a role whose may_ingest names milli-Β°C, milli-%RH and Pa β€” does not exist and would have to be published. That is the work, and it is publishing a domain rather than reflashing hardware.

What the instrument is for

The honest limit first, and it governs every sentence in this section: no pod exists. This section states what the chartered instrument would make measurable, never an outcome it achieves. Every tier in Section zero is what would establish that a built pod can hold even that much, and no tier on this page grades any application outcome at all. Every third-party figure is attributed inline with source, year and venue, and tagged VERIFIED where the primary source was read this session or REPORTED where it was not.

Five properties established above are used in the lanes below, and no lane uses all five: the frozen 60 s ingest cadence, the 42-byte wire frame, the 3.2404909 J/hour binding energy budget at 60 tx/hr, the |change| < 32,768 recoverability bound, and the delta-driven wake. On the last of those: a pod in a static environment is chartered to spend the 83.16 mJ/hour quiet floor and transmit nothing. The wake threshold that decides "static" is unfrozen, so that floor is a bound the specification carries, not a consumption figure, and no deployment duration follows from it on this page.

Land use and desertification

What the framework is. SDG Indicator 15.3.1 is "Proportion of land that is degraded over total land area", integrated from three sub-indicators β€” trends in land cover, trends in land productivity, and trends in carbon stocks above and below ground, with soil organic carbon (SOC) in the 0–30 cm layer as the surrogate for the third. The UNCCD's Good Practice Guidance calls land cover "a transformational variable", land productivity "a 'fast' ecological variable" and carbon stocks "a 'slow' ecological variable", integrates them by a one-out-all-out rule in which a significant negative change in any one makes the unit degraded, and states that "The Indicator is reported as a binary quantification (i.e., degraded/not degraded)" (VERIFIED β€” UNCCD, Good Practice Guidance. SDG Indicator 15.3.1, Version 2, 2021, Β§Β§1.1–1.2 and Appendix C; PDF fetched and text-extracted 2026-08-31).

The cadence and the resolutions, exactly. Reporting is four-yearly β€” "The UNCCD has approved a four-year reporting frequency, and therefore a four-year reporting period", by decision 15/COP.13, every four years beginning 2018 β€” against a fixed baseline of "the 16 years from 1 January 2000 to 31 December 2015" (VERIFIED β€” same source). The default global datasets in the GPG's Table 2-1 are ESA-CCI land cover at 300 m, JRC Land Productivity Dynamics at 1 km, and ISRIC SoilGrids at 250 m (VERIFIED β€” same source, Table 2-1). The coarsest leg is 1 km. Pixel areas, as arithmetic over those published resolutions: a 300 m cell is 9.00 ha, a 250 m cell 6.25 ha, a 1 km cell 100 ha β€” so the default productivity cell is 16Γ— the area of a 250 m cell and 11.1Γ— that of a 300 m cell.

The framework names the binding constraint itself, and names it as resolution against the variability of the thing measured. Verbatim: "The level of confidence is related to the sub-indicator's absolute spatial resolution, the spatial resolution of the map relative to the typical variability of the object of interest in the environment…", followed immediately by the observation that finer local calibration "is a highly specialized and expensive task however, and may not be realistically achievable by some countries" (VERIFIED β€” same source). Its data-selection table adds: "Large pixels (coarse spatial resolution) represent average conditions over a larger land area, which may not be desirable in landscapes with very complex or heterogeneous structures" (VERIFIED). And on its own slow variable: "For slow changing variables such as SOC, reporting every four years may not be practical or offer reliable change detection for many countries" (VERIFIED).

The management unit against the pixel. Half of all fields in Africa's smallholder-dominated agricultural systems are smaller than 1 ha, and smallholder farms occupy up to 40% of agricultural areas globally, mapped from 130,000 crowdsourced locations interpreted on high-resolution imagery (VERIFIED β€” Lesiv, Laso Bayas, See et al. and Fritz, Global Change Biology 25(1):174–186, 2019, doi:10.1111/gcb.14492). Combining that with the resolutions above as arithmetic, not measurement: at a 1 ha median field, one default 300 m land-cover pixel spans about nine such fields and one default 1 km productivity pixel about a hundred. The caveat travels with the number: 1 ha is a median for African smallholder systems and not a global constant, and field boundaries do not tile a pixel exactly, so this is an order-of-magnitude statement about how many management units share one reported verdict β€” never a count of fields in any particular pixel.

What in-situ adds, with the size of the gap measured by the people who mapped it. "These climatic grids do not reflect conditions below vegetation canopies and near the ground surface, where critical ecosystem functions occur", and mean annual soil temperature differs from gridded air temperature "by up to 10Β°C (mean = 3.0 Β± 2.1Β°C)", with soils in cold and dry biomes +3.6 Β± 2.3 Β°C warmer β€” the dry-biome offset being the desertification lane's own regime β€” built from over 1,200 1-kmΒ² pixels summarised from 8,519 sensors (VERIFIED β€” Lembrechts, van den Hoogen, Aalto et al., Global Change Biology 28:3110–3144, 2022, doi:10.1111/gcb.16060; published-version PDF fetched and read 2026-08-31; repository records disagree on issue number, so volume and pages are cited and the issue is not). The same paper states that ERA5-Land at 0.08Β° "remain[s] too coarse for most ecological applications" (VERIFIED).

What the pod would make measurable, and it is one thing. The frozen 60 s ingest period yields 1,440 samples per day, and the daily minimum and maximum of those 1,440 instantaneous samples are exact integers rather than interpolated values. They are the extremes of a sample, not the day's extremes β€” the same specification under-samples extremes by about 12Γ— against WMO's own sampling rule, as the farming lane below measures, and that gap is carried in Open issues. Those two integers are the inputs the UNCCD's own aridity analysis uses for potential evapotranspiration, and the reason it uses them is stated in its own voice: PET is computed by Hargreaves-Samani from minimum and maximum temperature because the better Penman-Monteith method "needs more climatic input data, which are not easily retrievable at high spatial resolutions, particularly for multi-scenario projections" (VERIFIED β€” Vicente-Serrano, Pricope, Toreti et al., The Global Threat of Drying Lands, UNCCD Science-Policy Interface Technical Series No. 09, 2024, ISBN 978-92-95128-16-3, Chapter 1 methodology; PDF fetched and text-extracted 2026-08-31). The aridity index is used here only in ratio form β€” AI = P/PET with the dryland threshold at 0.65 β€” because the same report's glossary states the relation as a percentage that does not follow from its own ratio, and the ratio form is both exact and free of that discrepancy.

Scale, attributed. "More than three-quarters of all land on Earth (77.6 per cent) experienced a drier climate during the three decades leading up to 2020"; drylands rose from 37.5 to 40.6 per cent of land excluding Antarctica; dryland population doubled to 2.3 billion in 2020 (VERIFIED β€” UNCCD SPI Technical Series No. 09, 2024, Key Messages and Β§2.1). Separately, at least 100 million hectares of healthy and productive land were lost each year over 2015–2019 from national reporting compiled from 126 countries (REPORTED β€” UNCCD press release, 24 October 2023). Three different country counts are in circulation β€” 141 Parties responding to the GPG, 127 reporting in 2018, 126 in the 2023 dashboard β€” and they are three different populations at three different dates; this page does not fuse them.

What the pod does not do, stated as absent channels rather than as limitations to be worked around.

  • It measures none of the three sub-indicators. A T/RH/P point sensor produces no land-cover class, no vegetation index and no biomass. On SOC the GPG is explicit: "The determination of SOC stock requires measurements of SOC concentration, soil bulk density and gravel content", and adds that "Short-range spatial variation is typically large and can be easily confused with temporal variation" (VERIFIED β€” GPG v2, 2021). The pod measures none of those three quantities.
  • It carries no soil-moisture channel at all. The frozen HAL takes three scalars and a timestamp; the axis allocation assigns xβ‚„/xβ‚…/x₆ to T, H and P, x₇ to the flux derivative and xβ‚ˆ to Ο„, leaving no axis free. Adding soil moisture is a HAL signature change, a new BOM line, a T2 re-scope and a change to what the frozen 42-byte frame means.
  • A Stevenson screen measures screen-height air. WMO-No. 8 specifies screen sensors mounted 1.25–2.0 m above ground, so the pod as chartered measures the very quantity Lembrechts et al. show differs from soil temperature by a mean of 3.0 Β± 2.1 Β°C. What it would make observable is screen-height air microclimate at a point.
  • No precipitation, no radiation, no wind. The aridity index needs precipitation and PET; the pod supplies inputs to the PET half and none of the precipitation half. The GPG's two climate-correction methods for the productivity sub-indicator, Rainfall Use Efficiency and RESTREND, both regress productivity on rainfall (VERIFIED β€” GPG v2, Appendix B.2), an input the pod does not carry.
  • Reference network density, for the comparison a reader will reach for. WMO's Global Basic Observing Network states "The typical distance between stations at standard horizontal spacing is 200 km for surface land stations… but less distance is preferred down to 100 km" (VERIFIED β€” WMO, MeteoWorld, 1 June 2023). As arithmetic, a 200 km cell is 40,000 kmΒ² and a 100 km cell 10,000 kmΒ². The widely repeated "Africa is eight times below WMO density" figure is not used here: no primary source for it was retrieved.

The admissible claim, stated once and in full. SDG 15.3.1 is reported every four years on a binary one-out-all-out verdict from default products at 300 m, 1 km and 250 m, against a framework that says confidence depends on resolution relative to the variability of the object of interest, and that provides a named national ground-verification step β€” the GPG's own Β§2.2.2, "Identifying false positives and false negatives", and its statement that determination "should be contextualized with other data and information for ground-based verification" (VERIFIED). A pod mesh at the frozen cadence would make a daily sample minimum and maximum available as exact integers at whatever spacing pods were deployed at. This page specifies no pod spacing, no pods per hectare, no mesh extent and no gateway radius, so it makes no density claim. Its role would be verification input to the framework's own ground-truth step, never a substitute for the indicator, and no tier on this page grades that role.

Water use and irrigation

The share, with its year and its denominator. Agriculture accounted for 71 per cent of total freshwater withdrawals globally in 2022, against 15 per cent industry and 13 per cent municipal (REPORTED β€” FAO, AQUASTAT Water Data Snapshot 2025, published 19 December 2025, reference year 2022, reported via UN-Water; the FAO PDF host refused connection at time of measurement). Those three shares sum to 99, not 100, as published β€” third-party rounding, carried as printed and not normalised here. Withdrawal is not consumption. And the same organisation's own methodology page gives 69 per cent by aggregated volume and 59 per cent by averaging country ratios, qualifying the first as "biased strongly by the few countries which have very high water withdrawals" (VERIFIED β€” FAO AQUASTAT "Water use" page, no reference year printed, read 2026-08-31). Two numbers for one question, separated only by the denominator: state the denominator or do not state the ratio.

And the most-cited figure in this lane has been audited and found thin. Tracing the "irrigation withdraws 70 per cent of global freshwater" and "produces 40 per cent of global crops" claims through 3,693 unique documents published 1966–2024, only about 1.5 per cent of the documents cited in support provide original data; the authors' own re-derivation puts irrigation's share of withdrawals at 45–90 per cent and of grain production at 18–50 per cent, and states those ranges "should be understood as lower bounds on the true uncertainty" (REPORTED β€” Puy, Linga, Wei et al., PNAS Nexus 4(11):pgaf323, November 2025, doi:10.1093/pnasnexus/pgaf323).

How irrigation decisions are actually made, from the primary census file. USDA NASS Table 25, "Methods Used in Deciding When to Irrigate: 2023", United States row, 212,714 farms reporting any method: condition of crop by observation or experience 164,779; feel of soil 85,093; personal calendar schedule 44,349; scheduled by water supplier 31,192; soil-moisture sensing device 27,831; commercial or government scheduling service 17,533; daily crop-water evapotranspiration reports 15,484; when neighbours begin to irrigate 10,228; plant-moisture sensing device 5,282; computer simulation models 1,627. The published footnote reads "Respondents could choose more than one method", so the rows do not sum to the total. As shares of 212,714 β€” arithmetic on the published integers β€” crop observation 77.5%, feel of soil 40.0%, soil-moisture sensor 13.1%, computer models 0.8% (VERIFIED β€” USDA NASS, 2023 Irrigation and Water Management Survey, AC-22-SS-1, October 2024, Table 25; 4,464,836-byte file downloaded and read). The instrument in commonest use is a person looking at the crop, by a factor of six over any sensor.

The scale at which the decision is made. 212,714 irrigated farms in 2023 holding 53,135,170 irrigated acres, against 231,474 farms and 55,938,795 acres in 2018 β€” both the farm count and the acreage fell. Mean irrigated area per farm, as arithmetic on those integers, 249.8 acres (101.1 ha). The distribution is heavily skewed: 127,975 farms (60.2%) irrigate 1–49 acres and together hold 1,336,140 acres, 2.5% of the irrigated total (VERIFIED β€” same source, Table 6; means and shares computed here). Any claim about "the" spatial scale of an irrigation decision has to carry that skew.

The temporal scale. FAO-56 schedules irrigation by tracking root-zone depletion on a daily soil water balance, and the reference implementations follow that time step (VERIFIED β€” Allen, Pereira, Raes & Smith, Crop evapotranspiration, FAO Irrigation and Drainage Paper 56, 1998, Ch. 8; daily-step implementation confirmed in Thorp, SoftwareX 19:101208, 2022). The 60 s cadence therefore over-samples this decision by roughly 1,440 to 1. That over-sampling is not automatically a defect β€” it is what makes threshold crossings and delta-driven wake possible β€” but a 60 s cadence must not be presented as if the decision needed 60 s resolution.

What a T/RH/P pod supplies for evapotranspiration, mapped against the requirement list. FAO-56 Penman-Monteith reference ET requires four measured meteorological quantities: daily maximum and minimum air temperature, actual vapour pressure, net radiation, and wind speed at 2 m (VERIFIED β€” FAO-56, Ch. 3). Mapping the pod's channels onto that list β€” this is a derivation performed here, not a third-party conclusion β€” the pod supplies two of the four: Tmax and Tmin directly, and actual vapour pressure directly from temperature and humidity rather than by FAO-56's dew-point substitution. It supplies neither net radiation nor wind speed β€” the radiation and aerodynamic halves of the combination equation. It additionally carries barometric pressure, which is not one of FAO-56's four measured quantities but lets the psychrometric constant be measured rather than derived from elevation β€” a real but small refinement, since FAO-56 already computes it from altitude in closed form. FAO-56 provides a documented fallback: estimating the missing terms and using Penman-Monteith "will provide somewhat more accurate estimates as compared to estimating ETo directly using Equation 52", and where no wind data exist "a value of 2 m/s can be used as a temporary estimate. This value is the average over 2000 weather stations around the globe" (VERIFIED β€” FAO-56, Ch. 3). An ETo computed from temperature and humidity alone is admissible under FAO-56 and carries an assumed global-mean wind and an inferred radiation, and a page publishing one must say which inputs were measured and which were assumed.

The band this lane must publish rather than its flattering end. The systematic review of US soil-water-sensor scheduling reports that sensor-based scheduling used on average 38 per cent less water than traditional/grower scheduling, 20 per cent less than evapotranspiration-replacement, 16 per cent less than computer models, and 1 per cent less than canopy-temperature scheduling, across 49 papers over two decades, with yield larger or similar in every comparison (REPORTED β€” Datta & Taghvaeian, Agricultural Water Management 278:108148, March 2023, doi:10.1016/j.agwat.2023.108148; full text paywalled, percentages read from the publisher abstract). The honest reading is a 1–38 per cent band whose value is set by what you compare against, not by the sensor, and the 38 per cent is the comparison with the least-defined baseline. The control arm is the negative one: a multi-study review of soil-moisture-sensor controllers reports savings of 42–72 per cent in rainy periods but βˆ’1 per cent to 64 per cent in dry periods β€” the lower bound is negative β€” with turf quality sometimes below the minimum acceptable level (REPORTED β€” CΓ‘rdenas-Lailhacar & Dukes, Transactions of the ASABE 55(2):581–590, 2012, doi:10.13031/2013.41392; citation confirmed against Crossref, percentages from secondary summaries; the trials are turfgrass and landscape, not a field crop). Every one of those numbers belongs to a probe buried in the root zone. Placing them next to a T/RH/P pod would attribute to an atmospheric instrument a result earned by a soil instrument, and this page does not do that.

Where the supply-side gap actually is, and it is not resolution. OpenET publishes evapotranspiration "at a spatial resolution of 30m x 30m (0.22 acres)" β€” against the 249.8-acre mean irrigated farm derived above, roughly 1,120 pixels per farm, finer than any variable-rate control zone. Over the contiguous US the field-scale-versus-satellite-scale gap is therefore not primarily spatial. The gaps its own operators name are cadence, latency and scope: it "currently provides data at monthly and yearly timesteps", with "daily data prior to 2024 … of limited availability"; on latency it states a two-day target as a target and not as a delivered figure; models degrade under dense cloud; and most decisively, "OpenET is not intended to be a new irrigation scheduling tool" (VERIFIED β€” OpenET FAQ, read 2026-08-31). Accuracy against flux towers at cropland sites: mean absolute error 15.8 mm per month (17% of mean observed ET), mean bias βˆ’5.3 mm per month, rΒ² 0.9 (REPORTED β€” Volk et al., Nature Water 2(2):193–205, 2024, doi:10.1038/s44221-023-00181-7; publisher returned 403, figures from release summaries). The product covers the contiguous United States; no equivalent 30 m operational ET product is stated to exist for the regions where agriculture takes above 80 per cent of withdrawals, and that geographic asymmetry β€” not resolution β€” is the honest opening for a ground mesh.

The finding a specialist will raise. Washington State University's variable-rate-irrigation fact sheet states that crop water use "is largely independent of the soil type", so applying different amounts to different areas "only makes sense if the crops are getting water from another source besides where the center pivot irrigation system is applying it, or if the crops are using less water in some areas of the field due to disease or pest pressure", and concludes that in low-rainfall areas buying variable-rate irrigation in response to variable soils "has little opportunity to increase profitability" against managing the whole field uniformly for the problem soil (VERIFIED β€” Peters, Molaei & Flury, WSU/IAREC irrigation fact sheet, PDF downloaded and read 2026-08-31; no publication date printed). The one case the authors name where denser in-field data earns its keep is leaving room in high-water-holding soils to capture forecast rainfall, which "requires additional data collection of the soil water content in the different areas of the field" β€” a soil channel the pod does not have.

The admissible claim. At the frozen 60 s cadence and the 42-byte frame, a T/RH/P mesh would make near-surface microclimate observable continuously and unattended, and would supply two of the four measured FAO-56 ETo inputs as measurements rather than assumptions. At what spacing is not specified anywhere on this page, so no claim is made that it matches the density irrigation is managed at. It would not make soil water content observable, and soil water content is what the scheduling decision reads. If the pod is to carry the irrigation lane rather than the microclimate lane, the honest version is that the HAL would need a soil channel, and that channel is not in this specification.

Farming microclimate

The decision object in this lane is a threshold crossing with a dwell, and that is what a daily aggregate cannot represent at all. The published critical temperatures growers use are defined as what buds or developing fruit withstand for thirty minutes before permanent damage, tabulated per phenological stage at the 10 per cent and 90 per cent damage levels (VERIFIED β€” Murray, Critical Temperatures for Frost Damage on Fruit Trees, Utah State University Extension fact sheet IPM-012-11, March 2020, table attributed on the sheet to Washington State University). The frozen 60 s ingest cadence resolves that dwell into exactly 30 consecutive samples. No daily gridded product of any resolution represents a dwell.

The thresholds are already whole integers, and so is the accumulation law. Every value in the USU/WSU table is a whole integer degree Fahrenheit β€” apple silver tip 15/2, green tip 18/10, tight cluster 27/21, full bloom 28/25; peach swollen bud 18/1, pink 25/15, full bloom 27/24; and so on across pear, plum, cherry and apricot (VERIFIED β€” same source, pp. 1–2). The standard growing-degree-day form is the 86/50 system: daily GDD = (Tmax + Tmin)/2 βˆ’ 50 Β°F with Tmax capped at 86 Β°F and Tmin floored at 50 Β°F, all four constants whole integers, base 50 Β°F for corn and 41 Β°F for forages (VERIFIED β€” Ohio State University Extension AGF-0101, revised 19 September 2023; NDAWN, NDSU; Cornell NRCCA Competency Area 2, PO 9, whose own caveat is that "GDD is a valuable but rough guide to maturity time"). So the integer wire is the agronomy's own representation, not a substrate preference imposed on it. As arithmetic derived here and stated as such β€” no cited agronomy source puts it this way, and no program in this repository computes it β€” with the clamps applied to integer inputs, 2Β·GDD_daily = (Tmax + Tmin) βˆ’ 100 is exactly an integer in Fahrenheit degree-days, so a whole-season accumulation is exact in half-degree-day units with no rounding anywhere.

The same law restated on the pod's wire changes units, and the change is stated rather than absorbed. The wire unit is 10⁻³ Β°C, not Β°F, so base 50 Β°F re-expresses as 10 Β°C = 10,000 milli-Β°C and the 86/50 clamps re-express as 30,000 and 10,000 milli-Β°C. On that wire, 2Β·GDD_daily in milli-degree-days = (T_max_milli + T_min_milli) βˆ’ 20,000, exact in Int32/Int64 throughout. The quantity that comes out is a Celsius degree-day, 9/5 different from the Fahrenheit degree-day the cited OSU/NDAWN/Cornell standard defines, so it is not comparable to a published Β°F GDD threshold unless that conversion is stated at the point of comparison. And the method choice is itself contested: two distinct methods for computing daily thermal time from daily extremes are in wide use, differing on whether the base is applied before or after averaging, and they give different totals β€” naming "GDD" alone does not pin an integer (VERIFIED β€” McMaster & Wilhelm, Agricultural and Forest Meteorology 87(4):291–300, 1997, doi:10.1016/S0168-1923(97)00027-0).

The cadence lands on the meteorological standard, and the standard also names a gap this specification has. WMO recommends that atmospheric pressure, air temperature and air humidity "be reported as 1 to 10 min averages" and that "One-minute averages, as far as applicable, are suggested for most variables as suitable instantaneous values" (VERIFIED β€” WMO-No. 8, Part II, Ch. 1, Β§1.3.2.4). The frozen 60 s ingest period is the WMO-recommended reporting interval for exactly the three quantities the frozen wire carries. That is a coincidence and nothing more; it establishes nothing about the pod. The gap is in the same guide: samples used to compute averages must be taken at intervals not exceeding the sensor time constant, and "samples to be used in estimating extremes of fluctuations should be taken at least four times as often"; Annex 1.D gives air temperature a 20 s time constant, so WMO's own rule asks for ≀20 s sampling for averages and ≀5 s for extremes β€” about 3 and 12 samples per minute (VERIFIED β€” WMO-No. 8, Part II Β§1.3.2.2 and Part I Annex 1.D; the per-minute counts are arithmetic on those two rules). A 60 s ingest period as frozen is one instantaneous sample per minute, not a WMO one-minute average, and it under-samples extremes by about 12Γ— against WMO's own rule β€” and daily Tmax and Tmin, the exact inputs the GDD standard consumes, are extremes. The gap is fixable inside the existing frame β€” an integer accumulator sampling faster and publishing one 60 s aggregate per frame, still one 42-byte frame per minute β€” and it is carried in Open issues rather than left to imply a compliance the specification has not earned.

The wire unit against the standard. WMO-No. 8 Annex 1.D, row 1.1: air temperature range βˆ’80 to +60 Β°C, reported resolution 0.1 K, required measurement uncertainty 0.1 K in the βˆ’40…+40 band, sensor time constant 20 s, output averaging time 1 min, achievable measurement uncertainty 0.2 K; row 1.2 gives extremes a 0.3 K required uncertainty (VERIFIED). The frozen wire unit is 10⁻³ Β°C β€” 100Γ— finer than the reported resolution and 200Γ— finer than the achievable uncertainty. Those extra digits are headroom, not accuracy, and the numbers that actually bind a frost decision are WMO's 0.1 K and the 1 Β°C alarm margin below. This page pins no sensor part, so the quantiser check remains stated and owed rather than performed.

What density is worth, measured. On a freeze night the authors of the FAO frost manual "observed spatial differences of 1.0 Β°C or more within a couple of hundred metres in an orchard … measured at the same height above the ground on flat terrain", and conclude "it is somewhat questionable that Tc values from shelter temperatures are universally applicable" (VERIFIED β€” Snyder & de Melo-Abreu, Frost Protection: fundamentals, practice and economics, Vol. 1, FAO, 2005, ISBN 92-5-105328-6, Ch. 4, p. 73). Flat terrain, same height β€” so that 1.0 Β°C is the irreducible floor, not a topographic pooling figure, and it is the same magnitude as the margin growers are told to pre-pay: "When using a frost alarm, set the alarm about 1 Β°C higher than the starting air temperature identified in Table 7.5 to ensure sufficient time to start the sprinklers", and 1–2 Β°C higher for a thermostat, "depending on thermostat accuracy" (VERIFIED β€” same source, Ch. 7, p. 170). The margin exists to pay for detection latency and instrument uncertainty, and it is spent on the crop.

How fast the event moves. In FAO's worked example, "most of the temperature drop occurs in a few hours around sunset": the temperature fell about 10 Β°C in the first hour after net radiation turned negative, then about 10 Β°C more over the entire remainder of the night, at less than 1.0 Β°C h⁻¹ from two hours after sunset until sunrise (VERIFIED β€” same source, Ch. 1, p. 6 and Fig. 1.4). As arithmetic on those published figures: ~10 Β°C/hour is ~0.17 Β°C per 60 s sample, so FAO's 1 Β°C alarm margin is worth about six minutes of start time on the steep limb and roughly an hour on the shallow limb. Two regimes an hour apart in rate, and a daily statistic represents neither.

In-canopy against the station, and the GDD consequence. A Washington State University vineyard instrumented with 7 in-canopy thermistors, 6 berry-cluster thermocouples and 2 weather-station sensors measured, in summer, average daily minimum air temperature within the canopy 1.2 Β°C lower and average daily maximum 2.0 Β°C higher than at the station, with west-facing clusters 4.0 Β°C higher; the authors conclude that models assuming station air temperature resembles canopy air temperature "could have greater uncertainty" (VERIFIED β€” PeΓ±a QuiΓ±ones, Hoogenboom, Salazar GutiΓ©rrez, StΓΆckle & Keller, PLOS ONE 15(6):e0234436, 2020, doi:10.1371/journal.pone.0234436). The canopy minimum is the colder one, which is the frost-relevant sign. At production scale, a 731-station in-orchard network plus 34 CIMIS stations across California's Central Valley on 10-minute records measured individual reference stations departing by up to 3.3 Β°C from the average of surrounding in-orchard stations, within-20 km discrepancies of 0.17–0.84 Β°C by quarter, discrepancies of over 300 GDD in accumulated thermal time between interpolating all stations and using only the nearest reference station, and phenology prediction errors of 8.3 days for almond flowering (VERIFIED β€” MartΓ­nez-LΓΌscher, Teitelbaum, Mele, Ma, Frewin & Hazell, PLOS ONE 17(5):e0267607, 2022, doi:10.1371/journal.pone.0267607).

And the honest limit on gridded products, read in both directions. Comparing Daymet and PRISM against measured weather for maize simulation, the authors found small biases for temperature and growing-degree-days and close agreement in phase duration (RMSE 3–7 days), while simulated yields diverged at RMSE 18% (Daymet) and 24% (PRISM) of average yield; interpolation from a dense station network beat every gridded product on both phenology and yield, and the conclusion is that "gridded weather data cannot replace measured weather data as a basis for field-scale agricultural applications" (VERIFIED β€” Mourtzinis, Rattalino Edreira, Conley & Grassini, European Journal of Agronomy 82(A):163–172, 2017, doi:10.1016/j.eja.2016.10.013). So a claim that a pod materially improves GDD accuracy over a gridded product is not supported by this source and is not made here. For context on what a daily gridded average is: gridMET ~4 km daily (Abatzoglou, International Journal of Climatology 33:121–131, 2013), Daymet 1 km daily, PRISM 4 km in the free daily product and 800 m native β€” and the 1.0 Β°C within-200 m orchard difference and the 3.3 Β°C station-to-orchard departure both sit entirely inside a single cell of every one of them.

What is not admissible in this lane. An air-temperature threshold crossing is not a damage verdict. FAO states that critical temperatures are bud, flower or small-fruit tissue temperatures, that these "are likely to differ from air temperature, which is what growers typically measure", that active protection must therefore start and stop at higher air temperatures than the tables indicate, and that "using temperatures from a weather shelter only provides a rough guideline for expected damage" (VERIFIED β€” same source, Ch. 2 p. 17 and Ch. 4 p. 73). Note also that FAO's own T10/T90 are "the temperatures where 10 percent and 90 percent of the marketable crop production is likely to be damaged" β€” a different quantity from the USU/WSU bud table, and the two conventions are not interchangeable (VERIFIED β€” same source, Ch. 2, p. 17). One further owed item: FAO's sprinkler start and stop rules are stated on the wet-bulb temperature and its published equations (7.2–7.5) are floating-point transcendental expressions. The pod's frozen T/H/P triple is sufficient input and this program already holds an exact psychrometric key β€” Study 28 pins the Alduchov–Eskridge saturation form and the moist-air enhancement factor as exact rationals with a bounded-interval exp β€” but no integer or rational form of FAO's four equations is pinned in this charter, so the wet-bulb lane is owed rather than carried.

Loss magnitude, with its denominator. Freezes, cold, wet weather and frost together accounted for $854 million in US crop damages in 2024, within over $20.3 billion in total crop and rangeland damage, from USDA Risk Management Agency indemnity data adjusted for uninsured acreage (REPORTED β€” Munch, American Farm Bureau Federation Market Intel, 18 February 2025). It is a single-year US figure for a fused category, not a frost-only number and not a global one.

The admissible claim. The frost decision object is a threshold crossing with a 30-minute dwell; the published thresholds and the GDD accumulation are already integer laws; the frozen 60 s cadence resolves the dwell into 30 samples and matches the WMO reporting interval; the measured within-orchard spread on a freeze night is 1.0 Β°C over 200 m on flat terrain at the same height, the same magnitude as the alarm margin FAO tells growers to pre-pay, and entirely inside one cell of every daily gridded product. A frost night is a delta-driven event, so the binding 3.2404909 J/hour figure bounds this lane's hour from above; what an actual hour costs is a property of the environment and is measured nowhere on this page. Not admissible, and no tier grades any of it: that the pod prevents frost damage, improves yield, detects tissue damage, improves GDD accuracy over gridded products, or saves a stated fraction of anything.

Safety from predators, and the mesh spine reframes the question

Frame it as detection and early warning that protects the herd and the animal at once. Persecution arising from livestock conflict is a named driver of large-carnivore decline: of the 31 largest mammalian carnivores, 61 per cent are IUCN-listed as threatened and 77 per cent are undergoing continuing population declines, with range estimates for 17 species showing they "currently occupy on average only 47% (minimum <1%, maximum 73%) of their historical ranges"; the named mechanism is that wide-ranging behaviour "bringing them into conflict with humans and livestock, is what makes them vulnerable and poorly able to respond to persecution" (VERIFIED β€” Ripple, Estes, Beschta et al., Science 343:1241484, 2014, doi:10.1126/science.1241484; author accepted manuscript PDF fetched and read 2026-08-31 β€” the fetched manuscript prints "VOL 000", so the volume is carried from the published record and not from the bytes read). Reducing the encounter reduces the loss to the herd and the pressure on the animal, and that is the whole value proposition.

The wrong question, and why the spine section above is where this lane is decided. Asked of a fixed-function node, "can a T/RH/P pod detect a predator?" has one answer on the evidence available: no source found in this pass reports predator detection from ambient T/RH/P β€” and that is a search result from this pass, never a proof of absence. The closest published sensor study runs the other way β€” on-animal GPS collars measured sheep travelling 11.6 Β± 3.12 km/day with a wild dog present against 9.2 Β± 2.73 km/day after removal. Those two raw means differ by 2.4 km/day, which is 26.1 per cent of the 9.2 baseline and 20.7 per cent of the 11.6 figure; the paper separately reports an overall 12.63 (Β±0.90) per cent change in distance travelled, which is a model coefficient over a different base and is not either of those two ratios. The temperature-humidity index entered the same model as a nuisance covariate at "a βˆ’2.17 (Β±0.10) percent change in distance travelled" per unit of maximum THI, with the predator-present period carrying the lower mean THI (VERIFIED β€” Evans, Trotter & Manning, Animals 12(3):219, 2022, doi:10.3390/ani12030219; PMC8833745 fetched and read 2026-08-31; single-property case study in Western Queensland, and the paper says so). In the only published sensor study on point, temperature and humidity move opposite to the predator effect and had to be controlled out. A T/RH channel asked to read "predator" from that would be reading weather.

The question the spine actually asks. A web does not detect prey with a prey-detector; it detects disturbance propagating through a structure, and the web is the sensor. Under the spine architecture the lane needs a domain whose new_law decides on ingested integer deltas, plus at least one role whose may_ingest carries a field that moves when a predator is near. Measured against the pinned extract: no such domain exists today. The closest shapes already shipped are seismic's station role, whose new_law is a threshold on an arrival time and a signal-to-noise ratio in parts-per-thousand β€” the shape an acoustic detection would take β€” and physics's detector role, ingesting clock, track and table_counts. Neither is a proximity domain, and none of the 122 may_ingest field names is a proximity field. Publishing the domain is the work; reflashing pods is not. What the pod's frozen properties would then contribute is exact carriage: a fixed-width integer displacement, the |change| < 32,768 bound making a detection event an exact integer rather than a stream, T3's 42-byte frame length, and T4's byte-identical replay grading whether the alert a herder acted on is the alert the sensor emitted.

And a detection modality is a re-scope, not a footnote. Every detection route for a predator near livestock found in this pass uses acoustic, optical/thermal, or on-animal sensing β€” a search result from this pass, never an enumeration of the literature. A microphone or an imager streams at a data rate orders of magnitude above three int32 scalars every 60 s, and a 42-byte frame carries an eight-axis integer displacement, not a classification. Naming the modality and re-deriving T2's ingest set, T3's frame length and the hourly energy budget against it is the work this lane owes before any predator claim can be made β€” and that sentence is charter reasoning by this pass with no external source, published as reasoning.

Where the strongest evidence in this field actually sits, because it is not on instruments. Five randomized controlled trials with crossover designs across four countries support confidence in two deployments: "The first is the deployment of herders using low-stress livestock-handling techniques" and "The second is the deployment of light deterrents when wild carnivores are not already habituated to human lights". The same authors add a third intervention on a different evidence class β€” "Our confidence in fladry … enhanced by independent replications" rather than by those trials (VERIFIED β€” Treves, Fergus, Hermanstorfer, Louchouarn, Ohrens & Pineda-Guerrero, Animal Frontiers 14(1):40–52, 2024, doi:10.1093/af/vfad072; PMC10873015 fetched and read). Not one of those three endorsed interventions is a sensor. And the evidence base as a whole is thin in its own authors' words: a synthesis of 114 studies drawn from four reviews that screened over 27,000 candidates states that "scarce quantitative comparisons of interventions and scarce comparisons against experimental controls preclude strong inference about the effectiveness of methods" and that "many widely used methods have not been evaluated using controlled experiments" (VERIFIED β€” van Eeden, Eklund, Miller et al., PLOS Biology 16(9):e2005577, 2018, doi:10.1371/journal.pbio.2005577); an earlier systematic review of 562 publications found only 21 carrying evidence of effectiveness for any intervention (REPORTED β€” Eklund, LΓ³pez-Bao, Tourani, Chapron & Frank, Scientific Reports 7:2097, 2017, doi:10.1038/s41598-017-02323-w; both nature.com and PMC were unreachable this pass, so the counts come from search summaries).

The measured both-sides outcomes, each with its scope. Over 25 years, 634 livestock guarding dogs placed on Namibian farmlands (1994–2018), with questionnaire data for 472 dogs across 1,567 surveys: "LGDs reduced livestock losses for 91% of respondents", losses to jackal reduced by 45 per cent, to cheetah 16 per cent, to caracal 15 per cent β€” and the coexistence half, verbatim: "Before the placement of an LGD, 13% of farmers reported to have used lethal control methods against predators on their farm. This number dropped to 8% after the placement of an LGD." (VERIFIED β€” Marker, Pfeiffer, Siyaya et al., Journal of Vertebrate Biology 69(3):20115, 2020, doi:10.25225/jvb.20115; open-access PDF fetched and read 2026-08-31. Survey-based and uncontrolled, and the page says so.) Over seven years on Idaho public grazing land, a protected area running herders, guardian dogs, fladry, noisemakers and lights against an adjacent unprotected area: sheep losses to wolves 3.5 times higher in the unprotected area, protected-area losses 0.02 per cent of total sheep present, and no wolves lethally controlled within the protected area (REPORTED for the figures β€” Stone, Breck, Timberlake et al., Journal of Mammalogy 98(1):33–44, 2017, doi:10.1093/jmammal/gyw188; citation VERIFIED via Crossref, figures read from the abstract; absolute counts were not retrieved and are not stated). At Nairobi National Park, of the incidents recorded at 43 flashlight-equipped enclosures, "184 (96%) attacks took place prior to flashlight installation and 7 (4%) after flashlight installation" β€” and the displacement finding travels with it: mean incident distance from the park boundary rose by roughly 2 km per 3 years from 2012, and "Of the 105 diurnal predation cases, 21 (20%) occurred prior to flashlight installation (2007–2011) and 84 (80%) after" (VERIFIED β€” Lesilau, Fonck, Gatta et al., PLOS ONE 13(1):e0190898, 2018, doi:10.1371/journal.pone.0190898). Protection at one enclosure displaced pressure toward unequipped ones and toward daylight; printing the 96 per cent without the displacement would be exactly the overclaim this program exists to catch. A randomized crossover trial of portable flashing lights on the Chilean Andean plateau deterred puma incidents and did not deter Andean fox predation (design VERIFIED β€” Ohrens, Bonacic & Treves, Frontiers in Ecology and the Environment 17(1):32–38, 2019, doi:10.1002/fee.1952, citation confirmed via Crossref; the loss counts are REPORTED from summaries because the publisher returned 403 on every attempt) β€” a deterrent that works on one predator and not another is not a general instrument.

The modalities that are established, with their measured error rates, and what they are for. Automated acoustic wolf detection: a CNN correctly classified 77 per cent of howling examples at a 1.74 per cent false-positive rate, retrieving 81.3 per cent of observed events with a 15-fold reduction in operator time (REPORTED β€” Campos, Krofel, Rio-Maior & Renna, Remote Sensing in Ecology and Conservation 12(1):58–70, 2025, doi:10.1002/rse2.70024; citation VERIFIED via Crossref, figures from summaries after a 403); benchmarking three AI systems on Danish recordings gave individual recall 59.6–78.5 per cent while "a combined approach utilizing all three models achieved a 96.2% recall", the authors concluding the tools function as "powerful human-aided data reduction tools" rather than autonomous detectors (REPORTED β€” Jacobsen, Orlando, Jensen, Pagh & Pertoldi, Animals 16(2):175, 2026, doi:10.3390/ani16020175; Crossref record and abstract read, full text not). Both papers are about population monitoring, and no measured livestock outcome is attached to either. On the actuator side, virtual fencing is measured and works as containment β€” 25 collared cows through 14 days of training and 18 of testing gave containment of 99.44 and 99.75 per cent in training and β‰₯99.97 per cent in testing, with a time-dependent fall in the pulse-to-warning ratio (VERIFIED β€” Campa Madrid et al., Animals 15(15):2178, 2025, doi:10.3390/ani15152178; PMC12345423 fetched and read) β€” but it establishes no predator outcome; it moves stock and detects nothing wild.

The negative result. No peer-reviewed evaluation of an automated, real-time predator early-warning alert system delivering a measured reduction in livestock losses was found in this pass. What exists is collar-derived situational awareness on a daily cycle and geofence alerting under development, neither published with a measured depredation outcome (REPORTED β€” programme descriptions from search summaries; no primary source fetched). That is a search result from this pass and not a proof that none exists, and it is stated in exactly that form β€” because a page that applies this discipline to its own unbuilt pod owes the same discipline to everyone else's.

The admissible claim. A pod mesh at the frozen cadence, frame and budget would make the microclimate of a grazing block observable continuously and unattended. At what spacing is not specified anywhere on this page, so no claim is made about the density the block is worked at. It would not make a predator observable. Making one observable is a published domain plus a role whose may_ingest carries a proximity field, and neither exists today. No tier on this page grades a coexistence outcome at all.

The two readings and where they disagree

Reading What it holds constant The observation that separates it Sourcing
Orbital uplink β€” terrestrial sensing is a bandwidth problem; put a broadband link at every node and ship the raw stream The magnitude: it genuinely delivers megabits per node, and for workloads that need megabits there is no substitute and this page does not pretend there is It is a metered subscription on hardware and spectrum the local entity does not own β€” one per node, or one per aggregation group. Energy follows the same shape: a tracking terminal at the 60 W class spends ~2.16 Γ— 10⁡ J per hour of availability regardless of how few integers crossed. REPORTED (terminal power class); arithmetic VERIFIED
Terrestrial integer lattice β€” the mesh needs a displacement, not a stream; publish an 8-tuple and own the hardware The shape: what crosses is a fixed-width integer displacement whose size does not grow with sensor count The frame is 42 B whatever the pod is sensing. Airtime falls accordingly on this link, node energy is budgeted below, and under this charter the hardware, spectrum use and telemetry would stay with the local entity. The delta is the whole export. Airtime VERIFIED as arithmetic; hardware drafted
The null β€” the transport advantage is an encoding artifact, not a geometric one: it predicts that a protocol engineer swapping verbose JSON for a tight binary encoding gets the same ratio, and that the torus contributes nothing Nothing; it predicts the ratio survives replacing the lattice with any compact binary schema Section zero does not retire it β€” the measurement below concedes it. The 3.49Γ— airtime ratio is largely an encoding result and is published as such. What the geometry is chartered to contribute is fixed width: the payload does not grow when the pod grows a sensor, and T4 is decidable because the arithmetic over it is exact. A compact binary re-encoding of a growing record buys the ratio once and loses it again as the record grows. Sufficiency is not claimed: the spine census above measures that no domain carries a temperature, humidity or pressure field, so the 8-tuple's contents have no domain to ingest into today. Design statement of this charter

The readings are to be separated on shape, never magnitude; separating on size is forbidden by the program recipe. The orbital reading is not the adversary because its numbers are bad β€” for the workloads it is built for they are excellent. It is the adversary here because its shape is wrong for this workload: a metered per-node subscription on non-owned hardware standing in for a fixed-width displacement on hardware the local entity owns.

Computed airtime β€” this workload, this link budget

SX1262, SF9, 125 kHz bandwidth, CR 4/5, 8-symbol preamble, explicit header, CRC on, LDRO off. These are computed from the closed-form time-on-air expression, not measured on a radio. Re-derived in exact integer microseconds: symbol time 2⁹/125000 s = 4096 ¡s exactly; preamble (8 + 4.25) symbols = 50,176 ¡s.

Frame Payload Symbols Airtime Transmissions/hour at 1% duty
Float JSON telemetry frame 201 B 233 1004.544 ms 35
The frozen wire frame β€” 16 B delta + 26 B header 42 B 58 287.744 ms 125
Ξ” int32 Γ— 8, payload only 32 B 48 246.784 ms 145
Ξ” int16 Γ— 8, payload only 16 B 28 164.864 ms 218
A 90 B frame, printed by the program and carried by no argument here 90 B 113 513.024 ms 70

The 201 B float-JSON row is a reference frame whose field-by-field composition is not published on this page. It is the numerator of both operational ratios below, so those two ratios rest on an unstated numerator, and that is carried in Open issues rather than papered over.

The frozen wire frame is 42 bytes: a 16-byte displacement of eight int16 axes plus a 26-byte header (16-byte site id, 8-byte monotonic sequence, 2-byte schema version). The header is load-bearing rather than overhead β€” T3 grades a published subject and T4 grades duplicate rejection and ordered replay, and neither is decidable without it. The payload-only rows are the displacement alone and are not gradeable under T3 or T4; the operational ratios are the 42 B row's.

Counts floor; they never round, as every derived integer on this page does. One percent of 3600 s is 36.000 s of airtime per hour, and the count is floor(36 s Γ· airtime) in every row. The two rows where the distinction decides the integer:

  • 36 Γ— 1004.544 ms = 36.16 s β†’ breach. 35 is correct.
  • 146 Γ— 246.784 ms = 36.03 s β†’ breach. 145 is correct.

A regulated budget floors. Rounding a duty cycle up is a breach expressed as a rounding convention.

The operational ratios, on the real 42 B frame against the 201 B JSON frame: airtime 1004.544 : 287.744 = 3.49Γ—; transmissions per hour 125 : 35 = 3.57Γ—. Both are derived here from the printed airtimes and counts; lora-time-on-air.swift prints five airtimes and five floored counts and the payload-only ratios, and does not print these two β€” a reader re-derives them from the table above. The two differ because of the floor, and publishing both rather than smoothing them to one number is the point. The airtime ratio sits below the payload-only ratio because preamble and header are fixed cost that no payload shrink removes.

The sub-band is named, because every count above is specific to it. Airtime is what a 1% sub-band actually meters β€” duty cycle is regulated in time, not in bytes (REPORTED β€” the EU 868.0–868.6 MHz sub-band, band g1, under ERC Recommendation 70-03 / ETSI EN 300 220). Other sub-bands in the same regime carry 0.1% and 10% limits, so a count computed at g1 does not transfer.

And the frozen cadence never reaches this ceiling. T1 freezes the ingest period at 60 s, so at most 60 samples per hour exist to transmit. The 125 transmissions/hour figure is the regulatory limit on this sub-band at this frame size; the binding rate is 60 tx/hr, and the energy section prices that.

Scope, stated rather than left to be inferred: this is a claim about this workload on this link budget β€” a fixed 8-tuple at SF9/125 kHz on a 1% sub-band. It is not a claim that megabit uplinks are unnecessary in general. A workload that needs a megabit needs a megabit, and no lattice changes that.

Delta-driven compute β€” the pod does not poll

The architecture is specified as event-driven, and that is what the energy table means. Continuous polling spends power holding a static environment under observation. The specification ties the low-power sensors to hardware interrupts on the ESP32-C6 and holds the core in deep sleep while environmental state is unchanged. Compute is specified to be proportional to displacement: on wake the node is to compute the geometric displacement, and if the change is below threshold the cycle is to terminate before touching the NVS buffer or powering the radio, so that energy is expended when reality changes. The per-axis threshold that decides "below threshold" is not frozen on this page, so the sentence describes an architecture and decides nothing yet.

So the hourly totals below are bounded on both ends and measured at neither. A delta-driven pod in a quiet environment would spend the sleep term and nothing else β€” the true quiet floor of a genuinely silent hour, 3,600 s Γ— 23.1 Β΅W = 83.16 mJ, printed at full precision on this page so the daily rows below reproduce from it. The true consumption is a property of the environment, not of the pod, which is why this page publishes bounds and no single figure between them. T1 is where they become numbers.

The falsifiable criterion this adds, and it is a chartered criterion outside the four-tier gate: a pod held in a deliberately static environment for a full diurnal cycle must show a transmission count of zero and a mean supply current within Β±3 Β΅A of whatever T1 measures as that board's own quiescent draw β€” the window is on the delta above the measured board floor, never against the 7 Β΅A chip specification, because a board at the 72 Β΅A measured elsewhere on this page would fail a 10 Β΅A ceiling on leakage rather than on behaviour, and an arm that fails on leakage cannot discriminate polling. The control arm: the same pod given one threshold-crossing stimulus must wake, transmit exactly once, and return to sleep. A node that transmits on a static bench is polling with extra steps; a node that stays silent through a real excursion is a broken sensor. Both failures are observable in the same trace. The per-axis wake threshold is not frozen on this page β€” it is carried in Open issues as owed at build stage β€” so this criterion is chartered and not yet decidable, and neither arm is measured, because no pod exists.

Energy β€” a budget from datasheet currents, not a measurement

No pod exists, so this is a computed budget. Every input is printed here so a reader can substitute their own and re-derive (VERIFIED as arithmetic; the currents REPORTED from datasheets).

Term Value Source
Rail 3300 mV design
SX1262 TX current @ +14 dBm 45 mA Semtech SX1262 datasheet, typ (revision not pinned on this page)
MCU active (sense + quantise, radio off) 60 mA Espressif ESP32-C6 class figure (revision not pinned on this page)
Deep sleep 7 Β΅A Espressif ESP32-C6 chip figure
Airtime per report 287,744 Β΅s the 42 B frame, computed exactly above
MCU wake window 50,000 Β΅s design
Sleep power 23.1 Β΅W 7 Β΅A Γ— 3300 mV
Reports per hour, binding 60 one per frozen 60,000,000,000 ns ingest period
Reports per hour, regulatory ceiling 125 floor(36 s Γ· 287.744 ms) β€” never reached at the frozen cadence

Per transmission 42.729984 mJ (0.045 A Γ— 3.3 V Γ— 0.287744 s); per wake 9.900 mJ (0.060 A Γ— 3.3 V Γ— 0.050 s). Both are printed at full precision because the hourly rows multiply them by 60 and by 125, and a rounded multiplicand does not reproduce a printed product.

Operating point Transmissions Wakes Sleep across the remainder Hourly total Per delivered report
Binding β€” 60 tx/hr at the frozen 60 s cadence 60 Γ— 42.729984 = 2,563.79904 mJ 60 Γ— 9.900 = 594.000 mJ 3,579.73536 s Γ— 23.1 Β΅W = 82.69189 mJ 3,240.4909 mJ = 3.2404909 J 54.008 mJ
Regulatory ceiling β€” 125 tx/hr 125 Γ— 42.729984 = 5,341.248 mJ 125 Γ— 9.900 = 1,237.500 mJ 3,557.782 s Γ— 23.1 Β΅W = 82.18476 mJ 6,660.9328 mJ = 6.6609328 J 53.287 mJ
A genuinely silent hour 0 0 3,600 s Γ— 23.1 Β΅W = 83.16 mJ 83.16 mJ β€”

The three sleep terms are three different quantities and this table keeps them apart. 82.69 mJ and 82.18 mJ are the sleep remainders inside transmitting hours; 83.16 mJ is the floor of an hour in which nothing was transmitted. Only the third prices silence.

Path Energy per hour Basis
A.E.P-1 pod at the binding 60 reports/hour 3.2404909 J the budget above
A.E.P-1 pod at the 125 reports/hour ceiling 6.6609328 J the same budget at a rate the frozen cadence never reaches
Tracking terminal, 60 W class 2.16 Γ— 10⁡ J 60 W Γ— 3600 s. The 60 W is a class figure attributed to no vendor, and it is the denominator's counterpart in the ratio below β€” a reader substituting a measured terminal draw must recompute rather than inherit it.

The ratios, each with its denominator named and each computed from the full-precision totals printed above: 2.16 Γ— 10⁡ J Γ· 3.2404909 J = 66,656 : 1 at the binding rate, and Γ· 6.6609328 J = 32,427 : 1 at the regulatory ceiling (floored, like every derived integer on this page). The denominator on the other side is an hour of availability, never a delivered measurement. The two paths move very different data volumes in that hour, so a per-measurement label would compare two different quantities. Both are budgets, and T1 is the tier that would convert them into measurements.

One deep-sleep caveat the budget cannot absorb. The 7 Β΅A is the chip figure. Measured commercial dev boards run to 72 Β΅A from board-level leakage. The pod's own PCB must be measured, not inherited. At 72 Β΅A the sleep power is 237.6 Β΅W, a genuinely silent hour costs 855.36 mJ, and the binding 60 tx/hr total rises to 4.008 J/hour β€” which does not change the shape of the argument and is exactly why T1 measures it instead of this page asserting it.

The power chain β€” and the panel, sized to the rating

The PMIC input rating is pinned to the current revision. The BQ25570's SLUSBH2G carries Peak Input Power 510 mW in Absolute Maximum Ratings, and Electrical Characteristics gives PIN 0.005–510 mW. The datasheet's own revision history reads: Peak Input Power changed From MAX = 400 mW To MAX = 510 mW. A ≀ 400 mW qualifier appears as a footnote on Recommended Operating Conditions after cold start (REPORTED β€” TI SLUSBH2G, document number pinned; the Espressif and Semtech revisions are not pinned and are named as unpinned).

Gate 1, addressed by specification: keep the BQ25570, size the panel to the PMIC. The specified panel is monocrystalline at ~400 mW nominal, and it is a proposal rather than a purchase.

Panel nominal against the PMIC ceiling. A panel nameplate is an STC figure at 25 Β°C, and monocrystalline power rises as temperature falls, at 0.30–0.45 %/Β°C. The tested rows, printed by gate-checks-panel-and-flux.swift:

Panel nominal 0 Β°C βˆ’20 Β°C Sourcing
500 mW, mildest coefficient 0.30 %/Β°C 537 mW 567 mW printed by the program
500 mW, harshest coefficient 0.45 %/Β°C 556 mW 601 mW printed by the program
450 mW, harshest coefficient β€” 541 mW printed by the program
400 mW, harshest coefficient 445 mW 481 mW arithmetic on this page β€” no program tests 400 mW

The program sweeps three coefficients (0.300, 0.380, 0.450 %/Β°C) at three temperatures for 500 mW, and one coefficient at one temperature for 450 mW; the table above prints the mildest and the harshest. Every combination it tests exceeds 510 mW. A 500 mW nominal panel breaches the PMIC's rated input on a cold clear morning, which is precisely the condition a solar-powered outdoor node is built for. The ~400 mW nominal specification is derived by arithmetic from the tested 450/500 mW rows and is not itself a printed program arm: 400 mW Γ— 1.2025 = 481 mW at βˆ’20 Β°C on the harshest coefficient, under the 510 mW ceiling with 29 mW of margin. Adding a 400 mW arm across both temperatures and all three coefficients is owed and is carried in Open issues. Spec a panel by its worst-case deliverable power, never by its nameplate.

And the margin is unaffected, which is why the resize costs nothing. Supply against demand, scaled linearly to 400 mW nominal from the program's 500 mW overcast case and labelled as arithmetic, not as a printed arm: a 400 mW panel yielding 80 mW through a 24 h overcast day gives 1.92 Wh.

Demand Daily energy Margin against 1.92 Wh
A fully quiet day at the 83.16 mJ/hour floor 24 Γ— 83.16 mJ = 1.99584 J = 0.00055440 Wh 3,463Γ—
The binding 60 tx/hr rate, every hour 24 Γ— 3.2404909 J = 77.7717816 J = 0.02160327 Wh 88Γ—
The 125 tx/hr regulatory ceiling, every hour 24 Γ— 6.6609328 J = 159.8623872 J = 0.04440622 Wh 43Γ—

Even 40 mW for 4 h in deep winter gives 0.16 Wh β€” 3Γ— the full regulatory ceiling. Every margin in this section floors, like every other derived integer on this page: the four quotients are 3,463.2, 88.876, 43.237 and 3.603, and a margin rounded up would overstate headroom in the unsafe direction. The panel was never the constraint; the PMIC's input rating was. (panel-energy-margin.swift prints 54Γ— at 500 mW nominal against the ceiling; gate-checks-panel-and-flux.swift prints a 48Γ— at 450 mW that is a string literal beside a computed mW value, not a computed figure β€” the arithmetic is right, 2.16 Wh Γ· 0.04440622 Wh = 48.64 β†’ 48, and it is stated here as this page's arithmetic. The 43Γ—, 88Γ— and 3,463Γ— rows above are likewise this page's arithmetic at the specified 400 mW.)

The second limit, and the topology it forces. The BQ25570's buck output is rated 110 mA typical, while the ESP32-C6 draws 295–382 mA during a 2.4 GHz transmit burst. The ESP-NOW path cannot be sourced from VOUT. The chosen topology is stated as chosen: MPPT charges storage β€” a LiFePO4 cell or a 500 F supercapacitor bank β€” and the accumulated charge drives the burst, with the PMIC as charger and never as burst supply. What is not shown here is the arithmetic that would earn it. No line on this page shows that an unpinned LiFePO4 cell or a 500 F bank sources 295–382 mA within its own discharge limit, what the burst duration is, or what the resulting rail sag is. That derivation is owed and is carried in Open issues; the problem is computed from two datasheet ratings and the answer is a topology choice, not a result.

A third specification, stated at its printed values. Cold-start VIN(CS) is 600 mV typ / 700 mV max. Continuous harvesting after cold start goes down to VIN = 100 mV.

And the part is single-source. TI listed it out of stock at the time of checking β€” a supply risk in an open-hardware BOM whose premise is that anyone can build it.

Reversibility buys computational integrity, not heat

A reversibility argument is available here, and its thermodynamic version does not survive arithmetic.

At 300 K, kT ln 2 = 2.871 Γ— 10⁻²¹ J/bit. On this page's own two widths: erasing the 128-bit displacement has a Landauer bound of 3.67 Γ— 10⁻¹⁹ J, and erasing the 336-bit wire frame has a bound of 9.65 Γ— 10⁻¹⁹ J. Against the budget above, the four pairings are: the 9.9 mJ wake window over the frame bound, 1.03 Γ— 10¹⁢; the wake window over the displacement bound, 2.69 Γ— 10¹⁢; a whole 54.008 mJ delivered report over the frame bound, 5.60 Γ— 10¹⁢; and the delivered report over the displacement bound, 1.47 Γ— 10¹⁷. Three of the four land at 10¹⁢ and the fourth at 10¹⁷ β€” the choice of width and term moves the exponent by one at most, and that is the entire point.

Sixteen orders of magnitude is not a margin tidier logic closes. Logical reversibility executed on irreversible CMOS yields no thermodynamic saving; the bound is not what any of that energy is spent against. Realising it would need adiabatic hardware, which the A.E.P-1 is not and does not claim to be.

The float exception, named because the page's own discipline applies to the page. This paragraph is the only arithmetic on this page computed in floating point, because ln 2 is irrational. It decides nothing: no verdict, no tier, no frozen integer depends on it, and only its exponent carries the argument. Every program in the reproduce section is integer-only and declares no float type. This one quantity is prose arithmetic, and it is labelled as such rather than left to be discovered.

Where reversibility actually pays, and it is the payoff the substrate uses: computational integrity. T4 grades whether a cell can replay the delta stream and re-derive the verdict; the transform over that stream is a bijection, which is the property that makes the replay decidable. That is Bennett reversibility as this substrate consumes it β€” the property that would let two cells that were never simultaneously online reach the same answer. Reversibility belongs in the integrity argument. It does not belong in a heat argument, and it is not put in one here.

Cost β€” measured arithmetic under stated assumptions

This section is arithmetic, not a verdict. It is not the sealed object of this study, and it does not appear in the status line. The sealed object is the four-tier protocol.

10,000 sites over 10 years, both sides paying for backhaul. The service-tier names are one commercial operator's published plan names read mid-2026; the operator is not named on this page, the tiers are carried as published plan names with no vendor attribution, and the prices are REPORTED (VERIFIED as arithmetic on those reported prices).

Architecture Backhaul assumption 10-year total
Orbital, one terminal per site, US Standard + MAX 10,000 subscriptions $159.49M
Orbital, one terminal per site, US Mini + Residential 10,000 subscriptions $67.99M
Orbital, one terminal per site, Kenya Mini + 50 GB 10,000 subscriptions $12.53M
Orbital, 1 terminal : 10 sites, US Standard + MAX 1,000 subscriptions $15.95M
Orbital, 1 terminal : 100 sites, US Standard + MAX 100 subscriptions $1.59M
Orbital, 1 terminal : 100 sites, Kenya Mini + 50 GB 100 subscriptions $0.125M
A.E.P-1, 10,000 pods @ $25 + 100 gateways on US MAX uplinks 100 subscriptions $1.83M
A.E.P-1, 10,000 pods @ $30 + 100 gateways on US MAX uplinks 100 subscriptions $1.88M

The two rows a reader is invited to compare, published as their line items so they reconcile. The orbital 1:100 US row is $1,594,900 = CapEx $34,900 (100 terminals at $349) + OpEx $1,560,000. The A.E.P-1 $25 row is $1,825,000 = pods $250,000 + gateway hardware $15,000 + gateway uplink $1,560,000. The gateway hardware assumption is $150 per unit, and a $150 gateway is not a $349 Standard terminal β€” that is why adding $0.25M of pods to the $1.59M orbital row gives $1.84M and not $1.83M. Naming the assumption is what makes the two rows comparable at all.

Read the rows that share an assumption, and read the market column before the architecture column. At like-for-like 1:100 aggregation on identical US uplinks the rows are what they are. Measured on this table's own rows, the market chosen moves the answer by an order of magnitude: US $1,594,900 against Kenya $125,280 at the same 1:100 aggregation is 12.7Γ—, and per-site $159.49M against $12.53M is the same 12.7Γ—. The ~100Γ— spreads in this table come from aggregation (1:1 β†’ 1:100), not from market. Either way, a single headline ratio drawn from this table would be an artifact of an assumption rather than a property of a design.

No cost advantage is claimed by this study. At 1:100 aggregation on identical uplinks the orbital row is the cheaper one, and this page says so plainly. What this study does claim, and will defend:

  • Sovereignty. Under aggregation, the orbital path still routes every site's telemetry through one commercial operator's ground segment. Under this charter the pod mesh would publish an 8-tuple displacement and retain the rest locally. That is an ownership property of the specification, not a price, and T3 is the tier that would show a built pod honours it.
  • Deployability, held to the budget. The budget is 3.2404909 J/hour at the binding rate, 6.6609328 J/hour at the regulatory ceiling and 83.16 mJ/hour at the quiet floor; the tracking-terminal class figure is 2.16 Γ— 10⁡ J per hour of availability. Both are budgets. Whether a site without grid power can be instrumented on those numbers is what T1 measures.
  • Single-operator exposure at a different granularity. 100 subscriptions to one company is 100 fewer than 10,000, and still one company. The property is granularity of exposure, and it is stated at that size rather than as an absence of dependency.
  • Failure granularity. The charter's exposure unit is the gateway cell; the orbital path's is the operator relationship. Neither blast radius has been exercised, and no tier on this page grades it.

The pod as drafted β€” A.E.P-1

Element Drafted part / choice Status
MCU ESP32-C6 (RISC-V), Wi-Fi 6 / BLE 5 / 802.15.4, ESP-NOW for pod-to-pod Capability claims SUPPORTED by the Espressif datasheet (REPORTED; revision not pinned)
Sub-GHz radio SX1262 LoRa transceiver Capability claims SUPPORTED by the Semtech datasheet (REPORTED; revision not pinned)
Power management BQ25570 solar harvester / charger, MPPT charge only Rated input pinned to TI SLUSBH2G; single-source, listed out of stock at checking
Panel ~400 mW nominal monocrystalline Sized by arithmetic from the tested 450/500 mW rows to stay under 510 mW; proposed, not purchased; the 400 mW arm is owed
Storage LiFePO4 cell or 500 F supercapacitor bank; specified to drive the TX burst Cell not pinned β€” T1's charge-window integer is therefore not frozen, and the burst-sourcing arithmetic is owed
Enclosure Louvered Stevenson screen, ASA or PETG Drafted; Ξ”K criterion pins at build stage; mounting height not pinned
Sensing T / RH / P only, integer milli-units at the HAL No soil-moisture, precipitation, radiation, wind, acoustic or optical channel
Hardware licence CERN-OHL Drafted
Transport licence Apache-2.0 Drafted
vQbit state machine + UUM-8D quantiser Proprietary, behind the HAL Header published above

Bill of materials β€” all lines read August 2026 at the 1,000-unit break, distributor named per line

Part DigiKey Mouser
ESP32-C6-WROOM-1-N4 $2.88 β€”
SX1262IMLTRT $5.70 $4.87
BQ25570RGRR $4.68 $4.82

One quote per line would hide the spread, and the spread is on the largest line. The SX1262 quotes differ by $0.83, which is 17.0% of the lower quote ($4.87) and 14.6% of the higher ($5.70) β€” a ratio in a section whose subject is hidden spread has to state its denominator. Taking the cheaper quote on each line gives $12.43 ($2.88 + $4.87 + $4.68); the dearer gives $13.40 ($2.88 + $5.70 + $4.82).

Still unpriced and unavoidable: LiFePO4 cell ~$2–4; panel ~$1.50–4; T/RH/P sensor ~$1–3; PCB ~$1–2; RF matching, crystals, antenna and passives ~$1.50–3; ASA/PETG filament ~$1–3; plus assembly and test, for which no figure is given at all.

What the line items sum to, and it is the number this page publishes. The six unpriced ranges total $8.00–$19.00, so the components on this page give $20.43–$32.40 before assembly and test. That is the range the line items produce; it is not a build quote, and its upper end is above $30. The cost table above is computed at $25 and $30, both of which sit inside that range, and $15 is a target naming a class, never a measured build cost, reachable only by changing the parts list.

The cleanest route to the target is worth naming, because it is a different deployment rather than a cheaper version of the same one. The ESP32-C6 already carries 802.15.4 and Wi-Fi, so a pod that meshes over ESP-NOW or Thread and reaches the gateway through its neighbours needs no SX1262 at all, leaving MCU + PMIC at $7.56 on the cheaper quotes ($2.88 + $4.68) and $7.70 on the dearer ($2.88 + $4.82). What it costs is the long single hop: LoRa reaches a gateway kilometres away; a 2.4 GHz mesh needs neighbours. Both topologies are admissible under this charter β€” dense-mesh and sparse-star β€” and this page does not choose between them. Other routes: LLCC68 or third-party SX1262 modules at $2–4; a commodity charger in place of the BQ25570. Each changes what T1 and T3 grade.

Every silicon line above is a distributor price at a stated quantity break with a date. An undated, unqualified "$15" is the one number on this page a reader can falsify in ten minutes, which is why it is labelled a target everywhere it appears β€” and the same standard is why the six unpriced ranges are published as ranges and summed in the open rather than compressed into a single confident figure.

What this charter is built to protect

Local ownership of local measurement. Zero extraction is a property of the wire format: what crosses is a displacement on a torus, so the global mesh would receive what it needs to compute and no stream that could be resold. T3 is the tier that grades whether a built pod holds that line. The hardware is CERN-OHL and the transport Apache-2.0, so ownership of the pods would stay with the local entity by licence.

Replayable verdicts. T4 exists because two cells re-deriving the same verdict from the same deltas is the property that would make a distributed measurement checkable by a stranger β€” the same discipline Study 11 β€” Ehrhart volume shear carries in arithmetic and Study 28 carries at a survivability line. Exact integer arithmetic has no last bit to disagree about, where a float pipeline's last bit is a property of a machine. Cross-host byte-identity of the programs in the reproduce section is not measured here β€” they were run on one host β€” so the property is stated as the reason T4 is decidable, never as a result this page has demonstrated.

Instrumentation where the grid is not. The budget is 3.2404909 J/hour at the binding rate and 83.16 mJ/hour at the quiet floor, against a small panel and a cell. Whether that closes on a built pod is T1's question, and it is the question that decides whether a site off the grid can be instrumented at all.

An enumerable boundary instead of a trusted one. A tool surface that enumerates to a ring buffer can be audited by anyone with a packet capture. That is a smaller claim than an unbreakable one and it is checkable, which an unchecked assurance is not.

A sensing capability that would be a published law, not a hardware refresh. The spine's measured structure β€” a domain names roles, and each role names the fields it may ingest β€” is what makes a pod a role in a domain. On that structure a new capability would be a dead_equation β†’ new_law pair and a may_ingest list rather than a field visit to every node. No pod-class domain exists today, so the pod's three scalars have nowhere to ingest, and publishing that domain is the work.

What this study does not judge

  • Orbital broadband as a technology. For workloads that need megabits it delivers megabits, and the readings table says so. The comparison is scoped to this workload on this link budget.
  • Which architecture wins. The cost table is arithmetic under stated assumptions. It renders no verdict, and the study claims no cost advantage.
  • Any built pod's performance. No pod exists. Every hardware row is a drawing, and the four tiers are what would convert a drawing into a measurement.
  • The physical state behind a delta. The R β†’ Z⁸ ingest is many-to-one. The delta carries the lattice point, not the air.
  • Guest isolation inside the WASM sandbox. No tier on this page grades whether a guest can reach registers, thread contexts or host memory maps. T3 grades a packet capture, which is a different question.
  • Any application outcome. The applications section states what would become measurable. No tier on this page grades land degradation, water saved, a crop protected, or an encounter avoided, and this page claims none of them.

Honest limits

  • No pod has been built and no tier has been run. This is a charter. Nothing on this page is a hardware measurement.
  • T1 cannot be run today. Its cell charge ceiling pins when a cell is named by manufacturer and part number; its enclosure Ξ”K criterion pins at build stage, before the first soak, and not after. The harvester bound is addressed by a proposed panel that has not been purchased and that no program arm tests, so it is proposed rather than resolved.
  • T3 is not fully runnable. Its subject allow-list and its ack-inbox subject are not frozen anywhere on this page, so two of its four arms cannot be scored against strings that do not exist. The inbound-frame and 42-byte-length arms are decidable from a capture today.
  • The scaling constants k_T, k_H, k_P are unfrozen. N and N_Ο„ are pinned at 65,536 by the int16 wire width, and the bound |change| < 32,768 follows; the three scalings do not follow from anything on this page, and neither does any bound on a displacement's magnitude.
  • The energy figures are budgets bounded on both ends and measured at neither. 3.2404909 J/hour prices the binding cadence, 6.6609328 J/hour prices a regulatory ceiling the frozen cadence never reaches, 83.16 mJ/hour prices a silent hour. True consumption is a property of the environment. T1 is where all three become numbers.
  • Deep-sleep current is a chip figure, not a board figure. 7 Β΅A is the specification; commercial boards measure to 72 Β΅A from board-level leakage, which lifts the binding hourly total to 4.008 J. The static-diurnal criterion is therefore written against the board's own measured quiescent draw and not against the chip figure.
  • The 400 mW panel specification is arithmetic, not a printed program arm. gate-checks-panel-and-flux.swift is the program that prints panel output in mW against the 510 mW ceiling, and every row it prints at 500 and 450 mW nominal is over that ceiling. panel-energy-margin.swift prints Wh supply against Wh demand and makes no ceiling comparison at all. The 400 mW rows on this page are scaled from the tested rows.
  • pod-energy-budget.swift truncates its Β΅W intermediate, computing the sleep power as 23 Β΅W rather than 23.1 Β΅W, so the sleep term it prints is a lower bound about 0.43% low. The figures published above are exact arithmetic on the printed inputs, not the program's output, and the program is the lower bound until its helper is fixed.
  • The airtime result is an encoding result as much as a geometry result, and the null row says so. 3.49Γ— on airtime and 3.57Γ— on transmissions per hour, on this workload, this link budget, and the g1 sub-band, and both derived on this page rather than printed by the program. Both have the 201 B float-JSON frame as their numerator, and that frame's composition is not published on this page. What the geometry contributes is fixed width and exact replay, not the ratio.
  • The $15 BOM does not close. $12.43–13.40 of silicon at 1k, plus six unpriced ranges totalling $8.00–$19.00, gives $20.43–$32.40 from the line items before assembly and test. The cost table's $25 and $30 sit inside that range; neither is a build quote.
  • The quantiser resolution is not checked against a named sensor's noise floor. The check is one comparison and it is stated; the sensor part is not pinned, so it is owed rather than performed.
  • The PMIC is single-source and was listed out of stock at checking, and the burst-sourcing topology chosen against its 110 mA output is stated without the discharge arithmetic that would earn it.
  • The NVS ring bounds the tolerable outage. 34.1 h at the frozen depth and the frozen 60 s cadence. An outage longer than that breaks the chain rather than degrading gracefully, and the gap marker is what keeps the break visible.
  • T2's float arm is chartered but unimplemented, and its control arm β€” a probe build carrying one deliberate float parameter β€” has not been run.
  • The 60 s ingest period as frozen is one sample per minute, not a WMO one-minute average. WMO-No. 8's own sampling rule asks for ≀20 s sampling for averages and ≀5 s for extremes on a 20 s-time-constant temperature sensor, so the specification under-samples extremes by about 12Γ— against that rule, and daily Tmin and Tmax are extremes. Where this page says the pod would make a daily minimum and maximum available, it means the extremes of 1,440 instantaneous samples.
  • The pod's mounting height is not pinned, and the frost literature makes height load-bearing.
  • No pod spacing, no pods per hectare, no mesh extent and no gateway radius are specified anywhere on this page, so no application lane makes a density claim.
  • The mesh-spine extract is not reproducible from the live URL by a stranger today. The live response measured 94,823 bytes; the 24,996-byte extract the counts are re-derived from is the catalogue's domain records re-serialised, and neither the extraction command nor the extract itself is published.
  • No integer or rational form of FAO's wet-bulb sprinkler equations is pinned here, so that lane is owed rather than carried, even though Study 28 already holds the psychrometric coefficients as exact rationals.
  • The applications section states what would become measurable and never an outcome. Every figure in it is third-party and attributed inline with a VERIFIED or REPORTED tag; several load-bearing figures are REPORTED because the publisher was unreachable this pass, and each says so at its own point of use.
  • "No such thing was found in this pass" is not "no such thing exists." Three search results in the applications section β€” no reported predator detection from ambient T/RH/P, no evaluated real-time predator early-warning system with a measured loss reduction, and the enumeration of detection modalities as acoustic, optical/thermal or on-animal β€” are results from this pass and are published in exactly that form.
  • The life-cycle comparison is owed. Manufacturing footprint, one LiFePO4 cell per node, and end-of-life for 10,000 outdoor units are quantified nowhere on this page.
  • Third-party figures are carried as REPORTED β€” datasheets, distributor listings and published papers read, not archives re-derived by this program. What is tagged VERIFIED is what was re-derived this session: the shipped quotient map read in source and reported by behaviour, the unimodular arms, the mesh-spine counts from the pinned extract, the airtimes and floored counts, the energy and panel arithmetic, and the cost rows on the reported prices.
  • The Espressif and Semtech datasheet revisions are not pinned and are named as unpinned rather than guessed. The TI revision is pinned: SLUSBH2G.
  • The audited boundary is chartered as auditable, and nothing has been audited. T3 would grade a configuration on a session. It would not establish that no configuration could ever leak, and no proof-by-signature is claimed anywhere on this page.

Open issues β€” carried on the face of the charter

These sit here rather than in a footnote, because several of them gate the tiers above.

  1. No pod exists and no tier has been run. Every hardware row is a drawing. The four-tier protocol is what would convert it into a measurement.
  2. T3's frozen subject allow-list and ack-inbox subject are not pinned. Until they are, two of T3's four arms are conditional and the tier is not fully runnable.
  3. k_T, k_H and k_P are not frozen. N = N_Ο„ = 65,536 and |change| < 32,768 follow from the int16 wire width; the three scaling constants do not, and xβ‚„, xβ‚…, x₆ are not reproducible without them.
  4. The per-axis wake threshold that gates a transmission is not frozen, so the static-diurnal criterion is chartered and not yet decidable, and nothing on this page bounds a displacement's magnitude.
  5. The LiFePO4 cell is not pinned, so T1's charge-window integer is not frozen. The boundary is per cell, not per chemistry β€” a representative cell specifies charge 0–55 Β°C and discharge βˆ’20 to +60 Β°C, two different windows, which is the whole content of the criterion.
  6. The T1 enclosure Ξ”K criterion is not pinned to the enclosure geometry. It must be frozen at build stage, before the first soak, and not after.
  7. Deep-sleep current is a chip figure, not a board figure. 7 Β΅A specified; 72 Β΅A measured on commercial boards. The pod's own PCB must be measured, and T1 is where that happens.
  8. A 400 mW nominal arm is owed in gate-checks-panel-and-flux.swift, across both temperatures and all three coefficients. Until it exists the panel specification is arithmetic scaled from the tested rows and the harvester bound is proposed rather than resolved.
  9. The burst-sourcing arithmetic is owed. No line on this page shows that a LiFePO4 cell or a 500 F bank sources the ESP32-C6's 295–382 mA burst within its own discharge limit, for what duration, at what rail sag. The topology is chosen; the derivation is not published.
  10. pod-energy-budget.swift's Β΅W intermediate truncates. Compute in nanojoules or multiply before dividing, re-run, and the printed sleep terms match the exact arithmetic published here.
  11. lora-time-on-air.swift does not print the two operational ratios it is credited with elsewhere. Either add 1004.544 : 287.744 and 125 : 35 as printed lines or leave them derived on the page, as they are here.
  12. The 201 B float-JSON reference frame has no published composition, and it is the numerator of both operational ratios. Publish its fields byte by byte as the 42 B frame is published, or state the ratios against a frame that is.
  13. The quantiser resolution has not been checked against a named sensor's noise floor. The wire units are 10⁻³ °C, 10⁻³ %RH and 1 Pa; the sensor part is not pinned.
  14. The PMIC is single-source and was listed out of stock at checking β€” a supply risk in an open-hardware BOM whose premise is that anyone can build it.
  15. The 60 s ingest period samples rather than averages. An integer accumulator sampling at ≀5 s and publishing one 60 s aggregate per 42-byte frame would satisfy WMO-No. 8's extremes rule at the same frame rate and the same transmission count; it is not specified here.
  16. The pod's mounting height is not pinned, and no pod spacing, pods-per-hectare, mesh extent or gateway radius is specified anywhere, so no density claim can be made in any lane.
  17. The mesh-spine extraction is not published. The live catalogue served 94,823 bytes; the 24,996-byte extract carrying sha256 b46bb35b…0261c is not published in the public repository and no command takes one to the other, so the live-endpoint arm is not runnable by a stranger.
  18. No pod-class domain exists on the mesh spine. None of the 48 published domains carries a temperature, humidity or pressure may_ingest field, so the pod's own three scalars have nowhere to ingest. Publishing that domain β€” its dead_equation, its new_law, its roles and their may_ingest lists β€” is the work.
  19. The predator lane has no domain and no field. It needs a new_law deciding on ingested integer deltas and at least one role whose may_ingest carries a proximity field. Neither exists, and adding a detection modality re-scopes T2's ingest set, T3's frame length and the hourly budget.
  20. Guest isolation in the WASM sandbox is ungraded. No tier on this page decides whether a guest can reach registers, thread contexts or host memory maps; T3 grades a packet capture and says nothing about guest memory access.
  21. The $15 target requires a parts-list change, and the two candidate topologies β€” LoRa sparse-star and 2.4 GHz dense-mesh β€” are different deployments. This page does not choose between them, and each changes what T1 and T3 grade.
  22. No cost advantage is claimed. The cost table is arithmetic under stated assumptions; at 1:100 aggregation on identical uplinks the orbital row is cheaper, and the market chosen moves the answer by an order of magnitude (12.7Γ— on this table's own rows) before architecture is considered.
  23. The life-cycle comparison is owed. Manufacturing footprint, one LiFePO4 cell per node, and end-of-life for 10,000 outdoor units are quantified nowhere.
  24. T2's float arm is chartered but unimplemented, and its control arm has not been run.

Reproduce every number

Self-contained Swift programs, no imports, each printing the table it backs. None of them declares a float type. The Landauer paragraph above is prose arithmetic that decides nothing, and it is the page's only floating-point quantity.

They live under reproduce/ in this public repository, alongside the corpora they read, which are pinned by sha256 under corpus/. That is deliberate: a program a reader cannot run is not a reproduction instruction, and until this split the programs sat in a private repository while the pages told public readers to run them.

Build each with:

xcrun swiftc -O -swift-version 6 <file>.swift -o /tmp/out && /tmp/out
File Reproduces Carries its own control arm
reproduce/unimodular-control-arms.swift det = 1 by fraction-free Bareiss; the 4,000-point run; the det = 2 and det = 0 arms; the reachability arm Yes β€” and it is the arm that shows image count does not discriminate while reachability does
reproduce/lora-time-on-air.swift five airtimes in exact integer microseconds and five floored counts β€” the four rows the argument uses plus a 90 B / 113 sym / 513.024 ms / 70 row it does not β€” the 42 B frame, and the payload-only ratios. It does not print the 3.49Γ— and 3.57Γ— operational ratios, which are derived on this page from its printed airtimes and counts the payload-only rows are the arm that shows what the frame does not deliver
reproduce/pod-energy-budget.swift the per-transmission and per-wake terms and the 125 tx/hr ceiling row. Its Β΅W intermediate truncates 23.1 Β΅W to 23 Β΅W, so its sleep term is a lower bound; the hourly totals published above are exact arithmetic on its printed inputs every datasheet input is printed so a reader substitutes their own
reproduce/cost-matrix.swift every row of the cost table at four markets and three aggregation ratios, including the pods / gateway-hardware / gateway-uplink line items the per-site and 1:100 rows are each other's arm
reproduce/panel-energy-margin.swift Wh supply against Wh demand at 500 mW nominal, all conditions. It prints no panel-output row in mW and makes no comparison against the 510 mW ceiling the deep-winter row is the arm against the overcast-day row
reproduce/gate-checks-panel-and-flux.swift the cold-day panel overshoot at 500 mW across three temperature coefficients and three temperatures, and at 450 mW at one coefficient and one temperature; the x₇ ring-delta defect at N = 65,536 and its fix. Its "48Γ—" is a string literal beside a computed mW value, not a computed figure Yes β€” it prints the naive 65,525 beside the true 11
the live catalogue at https://affine.earth/language-invariant/games measured 94,823 bytes. The mesh-spine counts on this page are re-derived from a 24,996-byte extract of it, sha256 b46bb35b2d978b94206f9888ed0a741ccc26f8407501aeb2268ae0a99490261c: 48 domains, 88 role entries, 34 role names, 122 distinct may_ingest fields, no_float true on 48 of 48. The extract is not published and the extraction step is not a runnable command, so this row is not reproducible by a stranger today the pinned extract would be the arm against the live endpoint, which is rewritten as domains are published
reproduce/reentry-alumina-ledger.swift, reproduce/z8-vs-e8-lattice.swift belong to Study 29; noted here only as cross-links β€”

The energy, panel and cost programs are budgets, not measurements, and print their inputs for that reason. The unimodular and airtime programs are integer-only in every law path and carry no float operation, which is the condition for byte-identical output across hosts; cross-host byte-identity is not measured here, because the programs were run on one host.

Cross-links

  • Study 29 β€” the reentry-mass ledger court β€” the sibling lane, split from this page on 2026-08-31: Ferreira against Maloney, the exact rational counting ledger, the units artifact. Pure epistemological shear on a contested continuous model.
  • Study 28 β€” Wet-bulb threshold court β€” the Section-zero precedent this charter instantiates for an artifact: per-criterion failing observations, control arms in both directions, losses published as losses. It also holds the exact-rational psychrometric coefficients this page's farming lane names as owed.
  • Zero Float Β· Zero Shear β€” why the HAL takes integers, stated as program doctrine.
  • Study 26 β€” Master regulator bonds β€” the precedent this page inherits: a gate frozen at charter stage before any byte is scored, plus a "Claim posture" section under 21 CFR 801.4 in which the page's own wording is treated as the boundary of what it claims.
  • Study 11 β€” Ehrhart volume shear β€” the arithmetic cousin: exact lattice counting against float evaluation of the same quantity.
  • Study 09 β€” Global convective bond β€” the terrestrial-sensing lane this charter supplies instruments for; frozen integer thresholds, REFUSED β‰  clear sky.
  • Shear Studies Index β€” the program board and the four-piece recipe every charter must instantiate.

Status: OPEN β€” hardware and protocol validation charter; no pod built, no tier run. OPEN is taken on the Study 26 / Study 27 precedent for the ingest half β€” no corpus ingested, no pod built, no tier scored; the gate integers that are frozen are frozen and printed and the ones that are not are named as unfrozen at every point of use, which departs from the index's wording. Four tiers frozen 2026-09-01, each with its failing observation and its control arm; T2 and T4 runnable against a built pod, T3 runnable on its inbound-frame and 42-byte-length arms with its subject allow-list and its ack inbox both unfrozen, T1 not runnable β€” its cell charge ceiling pins when a cell is named and its enclosure Ξ”K pins at build stage. The binding operating point is 60 tx/hr at the frozen 60,000,000,000 ns ingest period: 3.2404909 J/hour, 54.008 mJ per report, 66,656 : 1 against a 60 W terminal-class hour of availability; the 125 tx/hr regulatory ceiling is 6.6609328 J/hour at 32,427 : 1 and is never reached; a genuinely silent hour is 83.16 mJ. Every derived count, ratio and margin on this page floors. The PMIC input is pinned to 510 mW (TI SLUSBH2G, revised up from 400 mW) and the panel is proposed at ~400 mW nominal by arithmetic scaled from the tested 450/500 mW rows β€” 481 mW worst case at βˆ’20 Β°C, at 43Γ— the daily regulatory ceiling and 88Γ— the binding rate β€” a proposal, not a purchase, and no program arm tests it. Shipped and measured, reported by behaviour because the substrate source is not public: the live spatial quotient map emits an explicit winding for the three spatial axes only, with every other record component unwrapped, so the eight-axis T⁸ map is the design and not the shipped instance. A det = 1 unimodular 8Γ—8 maps 4,000 distinct Z⁸ points to 4,000 distinct integral images, and the discriminating control arm is reachability, not image count. The mesh spine's live response measured 94,823 bytes; the 24,996-byte extract the counts rest on carries sha256 b46bb35b…0261c β€” 48 domains, 88 role entries, 122 distinct may_ingest fields, no_float true on 48 of 48 β€” and no domain carries a temperature, humidity or pressure field, so the pod-class domain does not exist yet. The wire frame is 42 bytes, N = 65,536 is fixed by the int16 axis width, and the duty-cycle counts floor. The transform is lossless; the R β†’ Z⁸ ingest is not. The line items give $20.43–$32.40 before assembly and test. Applications state what would become measurable and no outcome; no tier grades one, and no lane makes a density claim because no pod spacing is specified. Not a shear study: one of the recipe's four pieces, and the three it lacks are named. No cost advantage is claimed β€” at 1:100 aggregation on identical uplinks the orbital row is cheaper.

🧬 CURES β€” read in this order

Each step is the reason the next one exists. Nothing here is medical advice, and no page calls any medicine safe or unsafe.

1 Β· Why an exact safety screen at all

2 Β· The three libraries, which grow rather than close

3 Β· The maps β€” every place a molecule could act, counted

4 Β· One medicine at a time

  • Zilganersen β€” the first treatment for Alexander disease, screened on the real approved sequence
  • A drug an AI designed β€” rentosertib for pulmonary fibrosis, and exactly what our instruments reach
  • CAR-T, halted β€” the verdict a regulator could re-derive
  • N-of-1 antisense β€” the only safety net at a population of one
  • VERVE-102 β€” the off-target lattice a stranger can re-derive
  • PM359 β€” prime editing, certified before anyone is dosed
  • Del-Zota β€” the one safety question that can be made exact

5 Β· What keeps a disease alive, and what moves it

βš–οΈ How to read any page here

πŸ”¬ The method β€” exact against float, domain by domain

The same move every time: take a domain where a floating-point model is the accepted instrument, compute the same quantity in exact integers, and seal the cases where the two render opposite verdicts. The subject under grading is always the instrument, never the phenomenon.

⚑ Fusion β€” the energy case

🌍 The planet, and the sky

πŸ› Markets, money and risk

βš›οΈ Run a court yourself

πŸ“’ Program ledger β€” every study by lifecycle

A study appears here under the state its evidence has earned, and above under the question it answers. The two are different filings of the same work, on purpose.

βœ… LAW FROZEN Β· DATA SEALED

πŸ”΄ LIVE CLAIM β€” standing, not sealed

🌊 CHARTER Β· OPEN β€” the findings, published either way

β˜€οΈπŸŒ‘ Eclipse 2026 β€” Study 01, DATA SEALED

πŸ”¬ Discoveries and flows

Clone this wiki locally