Skip to content

Verification fidelity: audit safety-behavior campaigns for idealized-harness blind spots #257

Description

@avrabe

Systemic lesson from the v1.114 rotor-out flip

The rotor-out recovery was "verified" (FV-FALCON-FAULT-002) and dispersed over thousands of Monte-Carlo trials, yet flipped on the real plant. Root cause of the miss: the campaign and the point-test both ran an idealized attitude-only sim (constant thrust, true-state feedback, no estimator, no rotational drag) — the campaign header even says so. Dispersion gives breadth, not fidelity; thousands of trials of a gap-blind model cannot falsify a bug the model can't express. The failure lived in a coupling (parasitic lean → descent → estimator divergence + thrust collapse) whose ingredients none existed in the harness.

v1.114 closed this for rotor-out with run_fullloop_motor_out_campaign (full production loop). This issue tracks the audit of the other safety-behavior campaigns/point-tests for the same blind spot:

  • Which "verified" behaviors are exercised only with true-state feedback / constant thrust / no estimator?
  • Promote the safety-critical ones to full-production-loop guards where the gap is real.

Deliverable: an audit note + follow-up requirements for any behavior found to be idealized-harness-only. This is the direct, honest answer to "we do a lot of Monte Carlo — how did this happen?"

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions