Locus Is Not Its Carrier
A locus is not the thread running it; the thread is a replaceable embodiment.
- Standing
- STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- never run
- Source
- none — this record cites no check
- Limit
- The tree's statement is a standing rule (computedriven/receipts/R7-OPEN.md §0), not a measured result. Nothing here measures a locus surviving a carrier change; the measured neighbour is carrier-multiplexing, which is a weaker fact.
- Next rung
in_tree— A run in which one locus's identity is observed before and after its carrier is replaced, with both observations receipted. computedriven/ has no git origin (R8), so today nothing could pin that receipt.
Why this page says STATED — the derivation, not the word
- ✗ a witness is named
- ✗ its evidence kind is one the ledger already uses
- ✗ the witness path resolves in this tree
- ✗ its rung is in_tree or above
- ✗ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✗ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
Everything a locus is — its seal, its state, its admissible transitions — is defined without reference to the carrier currently executing it. Swap the thread for a core, the core for a machine, and nothing the locus is has changed. This is a standing rule in ComputeDriven, and the measured fact beside it is Carrier Multiplexing.
Technical register
R7-OPEN §0, permanent standing rules from R2.1 and the R6 freeze: 'A Locus is not a thread; a Carrier is a replaceable embodiment.' There is no THREAD in the progress model's §4. A locus's context (KERNELLET-R1: admission + finality warden + possession) is the locus's; possession is a field that says which carrier, if any, holds it now.
Problem
Most runtimes define the unit of computation as the thing that executes: a thread, a process, a container. Identity then dies with the carrier: a restart is a death, a migration is a copy, and 'the same agent' has to be re-asserted by convention rather than established by a seal.
Solution
Give every locus a seal (Identity Is a Seal) and a context that lives outside any carrier. Model possession as a field with three states — vacant, attached, suspended — on the context, not as the carrier's opinion. Make carrier replacement a floor command that moves possession, and forbid every read of the context from asking which carrier holds it.
Real-world analogy
A chess game is not the board it is played on. Move the pieces to a new board, or play by post, and it is the same game at the same position; the board never had an opinion about which game it was.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 3 of 32 — the fragment _patterns/wrl/chain/locus-is-not-its-carrier.wrl, sealed alone by wrl.js
; LOCUS IS NOT ITS CARRIER — one signal through three carriers; the locus's state is unchanged by which relay
; carried it. lc_thread is this chapter's ENTRY (open port); thread → core → machine are relays: replaceable
; embodiments — and, in the chain, ROUTERS other chapters draw from.
[relay:lc_thread]{sig_in, sig_out}
[relay:lc_core]{sig_in, sig_out}
[relay:lc_machine]{sig_in, sig_out}
[spinner:lc_locus](w=16, n=8, rotor=quarter_turn_z){sig_in, socket}
[orb:lc_view]{pose}
[lc_thread] --sig--> [lc_core]
[lc_core] --sig--> [lc_machine]
[lc_machine] --sig--> [lc_locus]
[lc_locus] --socket--> [lc_view]Its test bench _patterns/wrl/chain/locus-is-not-its-carrier.bench.wrl — drives the entry for this chapter's own film; never part of the chain
; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:lc_bench](every 1){sig_out}
[lc_bench] --sig--> [lc_thread]module + bench seal to → sem-e0d0aa48334d29ba521a834eb134c2d93d9b89124a2ee51bf2769f5a3a466639
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-593d7a01fdf3418bb76… (the run inputs' own identity, computed by the forge)
No claims: the world runs on its clocks alone for 9 epochs.
Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (58.814s).
The Film, epoch by epoch (9)
epoch 1 · sha256:2f1f075d48c771c8502467ef17a50186868d60181fd0cf7bb976a462b6fb2908
FILM v0.7 t=1 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=0,next_out=0 relay:lc_machine:cur_out=0,next_out=0 relay:lc_thread:cur_out=0,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=0,nxt=0 wire:w__lc_machine__lc_locus:cur=0,nxt=0 wire:w__lc_thread__lc_core:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 2 · sha256:7e5a5a30181357431a19cc37d70d2f7cbfe543d19b015076d03cb4d791b22c4c
FILM v0.7 t=2 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=0,next_out=0 relay:lc_machine:cur_out=0,next_out=0 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=0,nxt=0 wire:w__lc_machine__lc_locus:cur=0,nxt=0 wire:w__lc_thread__lc_core:cur=0,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 3 · sha256:b1e23bdf54b17a244489f4c7d0a2dbdc48a3b2e16b4378978638af8998f74840
FILM v0.7 t=3 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=0,next_out=1 relay:lc_machine:cur_out=0,next_out=0 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=0,nxt=0 wire:w__lc_machine__lc_locus:cur=0,nxt=0 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 4 · sha256:b99a1f77293bba8433a3e1613a0149ca76685bcf3920b7d06d3bc9d60b604579
FILM v0.7 t=4 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=0,next_out=0 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=0,nxt=1 wire:w__lc_machine__lc_locus:cur=0,nxt=0 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 5 · sha256:7c207e0077acc5d22cdfd8f68feaad88a6d6161454977130d4153c894164686a
FILM v0.7 t=5 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=0,next_out=1 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=1,nxt=1 wire:w__lc_machine__lc_locus:cur=0,nxt=0 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 6 · sha256:078cfe3dfbbf15d324c4218b55496cc991ee50fca2323189e6effcf247b4d610
FILM v0.7 t=6 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=1,next_out=1 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=1,nxt=1 wire:w__lc_machine__lc_locus:cur=0,nxt=1 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 7 · sha256:d65fd3ba3b452c3403c6a8713db462cd90acf5db87bddd55ee8e3ef5ab6424a4
FILM v0.7 t=7 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=1,next_out=1 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=1,nxt=1 wire:w__lc_machine__lc_locus:cur=1,nxt=1 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 8 · sha256:f64762a8dfc3861cb9f43750daf5cf789d2cfeb3aa95e5d18655f85785e46148
FILM v0.7 t=8 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,0000,00ff,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=1,next_out=1 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=1,nxt=1 wire:w__lc_machine__lc_locus:cur=1,nxt=1 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 9 · sha256:4c937db9efb2fe179a4074d782257f14eecc9424267a73bd91c41f9288c43c30
FILM v0.7 t=9 spinner:lc_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=lc_view,config=fixed orb:lc_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff4c,0000,0000,00b4,controller=lc_locus,fault=0 pulser:lc_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:lc_core:cur_out=1,next_out=1 relay:lc_machine:cur_out=1,next_out=1 relay:lc_thread:cur_out=1,next_out=1 wire:w__lc_bench__lc_thread:cur=1,nxt=1 wire:w__lc_core__lc_machine:cur=1,nxt=1 wire:w__lc_machine__lc_locus:cur=1,nxt=1 wire:w__lc_thread__lc_core:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
Composes with the 2 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-cbc58d7b3cb6bf9ad161b22af3db6939718f04a6d2a6462a08b9db17a394a897: 9 objects, 8 edges (was 4 / 3; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
; the root clock drives the carrier chain [al_world] --sig--> [lc_thread]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The standing rule, verbatim (R7-OPEN §0, permanent) computedriven/receipts/R7-OPEN.md:18
2. A Locus is not a thread; a Carrier is a replaceable embodiment.
What a context holds — and note that possession is a field, not a thread computedriven/receipts/KERNELLET-R1.md:33
A context is one Locus Core Context — admission (80) + finality warden (32) + possession (vacant / attached / suspended, one of; 64) = 176 B in `TABLE` — plus, since R4-P, an Authority Working Set of 133 B (the 4-entry worker-authority evidence ring + length, `Option<AuthorityRow<4>>`) in the private `ROWS` sidecar: 309 B/context, semantically one Locus, physically two statics that never travel together. The historical `ring` profile carries the ring inside the lineage (132 + 1, padded) for 312 B. The semantic part is the 168 B cd-floor measured.
Forces
It is convenient to store a locus's state on its thread's stack. It is fast. It also makes every carrier replacement a serialization problem and every serialization a chance to make a Replica. The rule costs a level of indirection on every access to the context and buys carrier independence as a property rather than a promise.
Applicability
Any system that must survive its own restarts, migrations or hardware: agent runtimes, durable workflows, the T&R shell's windows, FPLA elements. It is a rule to adopt at design time; retrofitting it means finding every place a thread-local was used as identity.
Transformations
- replacing the carrier while possession moves atomically
- running the same locus on a thread today and a machine tomorrow
- suspending possession with no carrier at all (Dormant But Alive)
- deriving identity, authority or state from the carrier
- serializing a context by copying and calling the copy the locus
- treating loss of a carrier as loss of the locus
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
The system stops asking 'is the thread alive?' and starts asking 'is the locus established?'. That is the whole shift of Part I, and it is why the agency definition on this site says models and harnesses are components a locus reasons through, not identity criteria.
Failure mode it answers
Carrier Identity — Treating a thing as the process, thread or container currently executing it.
Witness
No witness. This pattern is STATED — the tree has no check for its invariant.
Counterexample
No counterexample shipped (required only when WITNESSED).
What to take away
- from the animationAcross three carriers the seal never changed, because nothing about the locus was defined by a carrier.
- from the syntaxPossession is a field on the context — vacant / attached / suspended — so 'which carrier' is data the locus owns, not a fact the carrier asserts.
- from the literatureBEAM got here first for processes; what the rule adds is that identity is a seal, so continuity is checkable rather than conventional.
- from the witnessThis is STATED: a standing rule, not a measurement. The measured neighbour is Carrier Multiplexing.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| M:N scheduling; green threads | realization | many schedulable entities over fewer OS threads | an implementation technique; here it is the invariant the technique happens to satisfy |
| BEAM processes | realization | processes are not OS threads and never were | the BEAM asserts it by construction; this pattern asks what must hold for the assertion to survive migration |
Novelty not claimed. Nothing about the separation is new. The tree's own statement is a standing rule (computedriven/receipts/R7-OPEN.md §0), not a measured result — the measured fact is carrier-multiplexing, which is a different chapter.
Realizations in the tree
- computedriven/receipts/R7-OPEN.md:18
Relations with other patterns
Active Locus definition↩ · Carrier Multiplexing WITNESSED · Dormant But Alive STATED
A ↩ marks a relation named on the other page. Relations are symmetric here and the reverse is derived, so neither side can go missing by being written once.