Genetic Trust Inheritance: How Linux fork() + seccomp Physically Enforces the ANKR Spawn Invariant

Fuente: Zenodo
Saved in:
Bibliographic Details
Main Author: Sharma, Anil Kumar
Format: Recurso digital
Published: Zenodo 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866902040809046016
author Sharma, Anil Kumar
author_facet Sharma, Anil Kumar
contents We observe that the Linux kernel has enforced a biologically complete genetic inheritance model for process capabilities since 2012. When an agent runs as a Linux process and carries its trust mask encoded as a seccomp-bpf filter, a child process spawned via fork() inherits that filter and cannot expand it. This is not a software rule — it is a kernel invariant enforced at the CPU privilege ring level. This paper maps the full biological genetics vocabulary onto the ANKR trust bitmask + KavachOS + AEGIS governance stack. The mapping is structurally complete: genotype (seccomp filter), phenotype (expressed syscall surface), epigenome (SCMP_ACT_NOTIFY supervisor), immune system (AEGIS 5-lock gate), and genealogy (process tree + Merkle ledger). We state and prove the Genetic Trust Invariance Theorem: for any OS-process agent spawned within a KavachOS-governed process tree, the spawn invariant child_mask is a subset of parent_mask is enforced by the Linux kernel without application-level code. FreightBox Zero (6 NVOCC agents) is demonstrated as the reference system. CHETNA AGENT_GENOME is proposed as the genealogy persistence layer for the full 225-service ANKR universe. The key insight: you do not need to build genetic inheritance for AI agents. It already exists. You need to run agents as OS processes.
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_20050707
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Genetic Trust Inheritance: How Linux fork() + seccomp Physically Enforces the ANKR Spawn Invariant
Sharma, Anil Kumar
agent trust
seccomp-bpf
capability inheritance
spawn invariant
KavachOS
AI governance
EU AI Act
Linux security
process isolation
bitmask
genetic inheritance
FreightBox
CHETNA
We observe that the Linux kernel has enforced a biologically complete genetic inheritance model for process capabilities since 2012. When an agent runs as a Linux process and carries its trust mask encoded as a seccomp-bpf filter, a child process spawned via fork() inherits that filter and cannot expand it. This is not a software rule — it is a kernel invariant enforced at the CPU privilege ring level. This paper maps the full biological genetics vocabulary onto the ANKR trust bitmask + KavachOS + AEGIS governance stack. The mapping is structurally complete: genotype (seccomp filter), phenotype (expressed syscall surface), epigenome (SCMP_ACT_NOTIFY supervisor), immune system (AEGIS 5-lock gate), and genealogy (process tree + Merkle ledger). We state and prove the Genetic Trust Invariance Theorem: for any OS-process agent spawned within a KavachOS-governed process tree, the spawn invariant child_mask is a subset of parent_mask is enforced by the Linux kernel without application-level code. FreightBox Zero (6 NVOCC agents) is demonstrated as the reference system. CHETNA AGENT_GENOME is proposed as the genealogy persistence layer for the full 225-service ANKR universe. The key insight: you do not need to build genetic inheritance for AI agents. It already exists. You need to run agents as OS processes.
title Genetic Trust Inheritance: How Linux fork() + seccomp Physically Enforces the ANKR Spawn Invariant
topic agent trust
seccomp-bpf
capability inheritance
spawn invariant
KavachOS
AI governance
EU AI Act
Linux security
process isolation
bitmask
genetic inheritance
FreightBox
CHETNA
url https://doi.org/10.5281/zenodo.20050707