OPERATING-SYSTEM MODEL

Architecture

Fenrua is organized as kernel space and user space, with stable machine-readable interfaces and public evidence boundaries.

CONTROL FLOW

Security workflow

01

Pre-execution policy evaluation

Entity, operator, environment, tool, and action are checked against authority policy.

02

Tool-call authorization

Allowed, denied, scoped, and human-approval actions are explicit.

03

Runtime-integrity verification

Source, build, lockfile, image, model, policy, and deployment manifests are compared.

04

Evidence-bundle creation

Inputs, outputs, decisions, commands, findings, hashes, and limitations become records.

05

Revocation and quarantine

Invalid, stale, drifted, revoked, or incomplete evidence fails closed.

06

Research-to-kernel translation

Research observations are promoted only through claims, non-claims, tests, evidence, utilities, and regressions.

VIEWPOINTS

Inspect the boundary from each relevant angle

These routes use semantic diagrams and explicit state labels. They distinguish current public records, reference designs, specifications, research, planned work, agreement-specific delivery, and external dependencies.

01

System context

This view separates the public evidence interface, local technical work, agreement-specific services, and external systems. It is a scope map, not a deployment inventory.

Open viewpoint
02

Logical components

Logical components are presented as distinct evidence, policy, verification, and recovery responsibilities. A component label does not establish a deployed service.

Open viewpoint
03

Runtime sequence

The reference sequence explains how a local workflow can evaluate supplied artifacts. It describes a design boundary, not a live multi-tenant runtime.

Open viewpoint
04

Deployment profiles

The complete reference profile is chain-free and local-first. Optional signed observations are publication or ordering inputs only; they do not create authorization or prove deployment correctness.

Open viewpoint
05

Trust boundaries

Trust is scoped to named artifacts, signatures, policies, public records, and review boundaries. The page never collapses a signed observation into general system assurance.

Open viewpoint
06

Data and provenance

This view distinguishes public static records, bounded observation fields, agreement-specific information, and protected operational material. Public evidence is point-in-time and limitation-aware.

Open viewpoint
07

Recovery and containment

Failure handling is designed around explicit invalid, stale, revoked, incomplete, or superseded states. The site publishes the decision boundary, not an invented incident history.

Open viewpoint
08

Evolution states

Every major surface is labelled by its actual state so that public documentation cannot be mistaken for a production capability roadmap.

Open viewpoint