Keep the local pressure loop visible when supervision fails.
Replay the difference between holding a pump-speed command and continuing a local pressure loop. Inspect reference changes, stale sensors and missing acknowledgements in a retained synthetic experiment.
A simulation replay for engineering review. The kit runs locally on CPU with NumPy; it contains no plant connection or control-write interface.
Loading retained experiment…
Tracking error includes lag from the ramped, held or default reference. It is measured against the requested schedule, so it does not isolate pressure-loop regulation error.
The chart shows one retained seed, sampled every second. Complete 0.1-second commands and supervisory events are in the study. The shaded interval marks the injected fault; pressure samples are taken after each local step.
Conventional references remain visible
| Policy | Whole-run error | Fault-window error | Speed held |
|---|
The preloaded recipe has the complete local schedule. The fresh-supervision reference has uninterrupted telemetry, current context and readback. These references have more information than the faulted fallback policies.
What continues locally
The pressure PI loop runs at a modelled 0.1-second interval when its declared qualified local sensor remains usable. Supervisory proposals arrive every 5 seconds. Both tested policies have a 20-second reference watchdog, followed by a ramp toward the configured 8-bar local default.
These are synthetic experiment settings. The paper, a digest or sensor agreement does not qualify a real fallback configuration.
What the failures show
Continuing regulation produced small, mixed tracking changes. A stale local sensor stopped every tested pressure loop. Common-mode bias passed the cross-sensor check. Missing readback blocked new supervisory proposals while the local watchdog continued.
Finite sampled trajectories establish neither plant safety nor an available protection function. No full LLM recovery agent or robust-MPC safety theorem was executed.
Reproducibility and transition assumptions
432 confirmation episodes, 518,400 local steps, 25 local and included Linux checks. The same selected PI gains are used by every method. Separate simulated authority binds the exact target, units, configuration, context and reference version; unknown old outcomes remain unknown after a current-state synchronization.