Pre-execution policy evaluation
Entity, operator, environment, tool, and action are checked against authority policy.
OPERATING-SYSTEM MODEL
Fenrua is organized as kernel space and user space, with stable machine-readable interfaces and public evidence boundaries.
CONTROL FLOW
IDENTITY · AUTHORITY · INTEGRITY · POLICY · EVIDENCE · VERIFICATION · CONTAINMENT · RECOVERY
Entity, operator, environment, tool, and action are checked against authority policy.
Allowed, denied, scoped, and human-approval actions are explicit.
Source, build, lockfile, image, model, policy, and deployment manifests are compared.
Inputs, outputs, decisions, commands, findings, hashes, and limitations become records.
Invalid, stale, drifted, revoked, or incomplete evidence fails closed.
Research observations are promoted only through claims, non-claims, tests, evidence, utilities, and regressions.
VIEWPOINTS
These routes use semantic diagrams and explicit state labels. They distinguish current public records, reference designs, specifications, research, planned work, agreement-specific delivery, and external dependencies.
This view separates the public evidence interface, local technical work, agreement-specific services, and external systems. It is a scope map, not a deployment inventory.
Open viewpointLogical components are presented as distinct evidence, policy, verification, and recovery responsibilities. A component label does not establish a deployed service.
Open viewpointThe reference sequence explains how a local workflow can evaluate supplied artifacts. It describes a design boundary, not a live multi-tenant runtime.
Open viewpointThe complete reference profile is chain-free and local-first. Optional signed observations are publication or ordering inputs only; they do not create authorization or prove deployment correctness.
Open viewpointTrust is scoped to named artifacts, signatures, policies, public records, and review boundaries. The page never collapses a signed observation into general system assurance.
Open viewpointThis view distinguishes public static records, bounded observation fields, agreement-specific information, and protected operational material. Public evidence is point-in-time and limitation-aware.
Open viewpointFailure handling is designed around explicit invalid, stale, revoked, incomplete, or superseded states. The site publishes the decision boundary, not an invented incident history.
Open viewpointEvery major surface is labelled by its actual state so that public documentation cannot be mistaken for a production capability roadmap.
Open viewpoint