Anulum Overview Host analysis AMP simulation Validation Python API Rust API C/C++ API

Threat model

The model separates implemented software and simulated RTL from physical instrument qualification. Current surfaces include validation and host analysis, C/Rust/RTL controllers, native Linux run control, UIO/IIO adapters, workload processes, contracts and workflow definitions. Hardware access code exists; successful board operation remains unverified. The second part covers the controls needed for a qualified physical instrument.

Part 1 — current repository

Assets

Asset Why it matters
measurement-domain.json and its schema define what a future measurement means; a silent change would change every later result
run-manifest.schema.json and the host analysis tool bind run files to provenance and calculations; accepting an invented source or silently dropped event would falsify a result
capability-inventory.json the public statement that no board capability is qualified or measured
Non-claims in the manifest and README prevent the repository from being cited for results that do not exist
requirements-dev.txt and development-dependency-licences.json hash-bound Python development dependencies; native prerequisites are recorded in VALIDATION.md
Workflow definitions execute only with declared per-job hosted permissions after separately authorised publication
Native configuration, source snapshots and receipts identify actual controller inputs, executable, loaded parent project context and completed observations
Workload processes and pipes affect host resources and admit a native run only after bounded, owned-worker readiness
UIO/IIO adapters and raw power journal contain physical access paths whose successful operation is unqualified
Licensing and provenance metadata legal integrity of the repository

Trust boundaries and actors

Misuse paths and mitigations

Misuse path Mitigation
Adding a capability, claim or hardware verification without evidence validator refuses non-empty capabilities or claims and verified_on_hardware: true at architecture_only; the inventory is generated and drift-checked
Editing the inventory by hand to imply capability the inventory embeds the manifest SHA-256 and must equal a fresh generation byte for byte
Shadowing a manifest field with a repeated key every JSON reader rejects repeated member names; workflow YAML is parsed with repeated-key rejection
Changing the event record or buffer so that data is silently lost validator checks record contiguity and size, unique numeric event codes, cycle count and counter width, and buffer fill time against the slowest drain
Supplying malformed or substituted run data the host rejects duplicate-key or nonfinite JSON numbers, invalid schema versions, escaping paths, missing or mismatched source/artefact/input hashes, malformed binary records and inconsistent CSV series
Creating a report destination during staging the Linux writer checks native publication capability before staging and uses renameat2(RENAME_NOREPLACE) to preserve a competing directory, file or symlink; a dangling symlink is also refused before staging
Presenting RTL simulation as board measurement run manifests label source kind; reports preserve simulation_only independently of internal series validity; board input requires declared acceptance state and complete artefacts
Shadowing worker readiness or receipt fields strict UTF-8 object parsing rejects repeated members, including nested counters; readiness checks exact Boolean/PID types and the owned PID
Holding a partial readiness frame open one deadline covers all chunks and the inclusive 4096-byte frame limit; native execution is refused until the complete frame validates
Worker policy drift or premature exit actual CPU/scheduler readback and owned-process exit status are verified; incomplete collection does not produce a completed load receipt
Claiming more load than was observed actual operation counters and worker/native time brackets remain bound to the capture; loopback UDP is not NIC traffic and fsync is not proof of uncached storage
Closing a reused descriptor or signalling an unrelated process owned pipe endpoints close once; production cleanup retains process-group leader identity until reaping; tracing tests retain owned pidfds and verify live parent relationships
Accepting a foreign device or writing over evidence adapters check actual kernel device identity, ownership and ABI before use; native output files are created exclusively
Substituting a development dependency pip install --require-hashes refuses any file whose hash is not in the lock; the licence guard refuses a package or version without a reviewed record
Tampering with a workflow towards write authority top-level permissions must be empty, the only allowed write scope is code-scanning upload, write-authority workflows are refused, actions must be commit-pinned, privileged triggers are refused
Leaking a secret through a commit secret scan of the publishable file set locally and of the whole history in CI; private-key detection hook
Publishing private notes docs/internal/ is ignored; the documentation guard refuses links into ignored paths

Fail-closed behaviour

Every tool exits non-zero on any finding and treats a missing file, unreadable or repeated-key JSON, an unknown schema identifier or an unparsable workflow as a failure. The preflight runner fails a gate whose tool is missing, cannot run or is not the pinned version.

Residual risks

Part 2 — planned instrument

Assets

Asset Why it matters
Bitstream and job files define the witness; a modified witness produces plausible but wrong timestamps
Firmware, operating-system images and controller binaries define the system under measurement
Event, power and manifest files the evidence; tampering changes conclusions
Safe-state behaviour an actuator path that fails unsafe would matter as soon as a physical plant replaces the emulator
Host link carries run control and data

Misuse paths and planned mitigations

Misuse path Planned mitigation
A run recorded with a different bitstream or image than reported manifest records SHA-256 of bitstream, firmware, images and controller binary; host analysis refuses a run whose hashes are missing or inconsistent
Event or power files edited after the run SHA-256 of every file in the manifest; analysis verifies before decoding
Silent event loss buffer overflow counter in fabric; any overflow marks the run invalid
Witness defect producing systematic error known-period, injected-delay and bus-offset tests on the same bitstream before any result
Host-link spoofing or interception on a shared network direct cable or isolated network for runs; the run manifest and file hashes are verified on the host, not trusted from transfer
Safe-state failure hardware deadline monitor independent of the processors; safe-state tests with injected faults; the emulated plant is never replaced by a physical machine inside this project
Redistribution of licensed vendor IP Libero projects generated by scripts; licensed and encrypted IP is never committed

Residual risks

Dedicated-hart ISA capture

The public ISA capture boundary admits original topology, reserved firmware/telemetry ranges, PLIC contexts, strict linked firmware and tool identities before execution. Exclusive capture output preserves failures. It snapshots the verified original inputs and rejects byte drift in either captured artifacts or executed tools. Analysis refuses contradictions between the capture receipt, executed tool identities, complete native/model compiler dependency and link roles, captured original source/header bytes, verified image, configuration, observed tracking and full fabric event history. Completion requires actual stream drain and logger acknowledgement. Plugin generation inputs and actual tools are frozen before Verilator runs. Actual compiler preprocessing freezes native/model source and system-header dependencies before compilation; post-build reconciliation refuses source, generated build-file, dependency-record or tool drift. Final receipts must agree with their original preparation, which is retained in capture sources.

The functional clock map and parked companion harts do not establish physical U54 latency, Linux coexistence, HSS configuration or PMP isolation. A malicious compiler, simulator, plugin or host can forge self-consistent data; artifact hashes do not authenticate those components. The capture remains simulation evidence under its public contract.