GNSS-denied positioning · private repo · 9 packages
Positioning that knows how wrong it might be.
Every satellite-free navigation method has the same failure mode: it produces a confident number that is wrong, and nothing downstream can tell. pnt-stack is nine packages built on the opposite rule: each layer passes its uncertainty upward, and refuses to assert a position it cannot support.
the idea
A refusal is a first-class output.
A depth sounding that arrives without its datum is not a number to be used cautiously. it is a refusal that names what is missing. That shape repeats at every layer, and it is what lets the top of the stack say ACT, CAUTION or REFUSE and mean it.
Uncertainty travels upward
`celnav` returns a position and a covariance, an error ellipse and a protection level. A fix with no bound is not a fix.
Sources that fail differently
Celestial, magnetic and bathymetric errors are uncorrelated, so `pntfuse` can cross-check them and exclude a faulty one rather than average it in.
Supported ≠ safe to trust
The `CAUTION` state exists because a position can be perfectly well supported by the evidence and still be the wrong thing to act on.
nine packages · 12,725 lines · 3,923 lines of tests
The chain, end to end.
sense
NMEA 0183 in. Every quantity carries its age, its datum, and the reason it cannot be believed.
celnav
Celestial sight reduction, weighted least squares, error ellipse, protection level, chi-square fault detection.
magnav
Aeromagnetic compensation and terrain-aided navigation, both on real flight data.
pntfuse
Cross-source integrity monitoring and fault exclusion, combining sources that fail in different ways.
envelope
Pre-authorised capability envelopes and a tamper-evident, hash-chained decision log, signed Ed25519.
underway
The watch that runs for a week across a restart, writing a journal that survives the power cut.
helm
ACT / CAUTION / REFUSE. Its 26 tests are honesty rules, not layout.
integrity
Calibrated to 4.915% against a true 5% before it was allowed to measure anything.
bridge
The seam between the estimators and the thing that has to decide.
skymaths is a submodule, not a copy. it stays canonical in its own public repo because TerraFirma and Starwheel depend on it too. Vendoring a copy is what left TerraFirma eleven pixels out for a year.
the part most projects leave out
What is measured, and what is only written.
This table is copied from the project's own
SYSTEM.md, which exists specifically to keep the two apart. The
unflattering rows are the point.
| Layer | State | Evidence |
|---|---|---|
magnav compensation | measured | 22.8× cross-flight on real DAF-MIT flight data |
magnav navigation | measured | 6.64 m DRMS post-processed / ~28.5 m causal, four flights, one held out |
skymaths | measured | Sun 0.01 nm, Moon 0.17, planets 0.02 against Meeus worked examples |
integrity | calibrated | 4.915% against a true 5%, before it was allowed to measure anything |
| bathymetric matcher | validated vs twin | peaks identical on 30 shared legs of the real chart, refusals 1:1, DRMS 12.76 m both sides |
pntfuse | logic tested | 55 tests; the magnetic error model is real, the fix is synthesised |
envelope | logic tested | 24 tests, Ed25519, hash-chained |
sense | never met a bus | 48 tests; 7 of 9 injected faults refused, 2 shown undetectable. Every sentence synthetic |
underway | never met a boat | 39 tests; no serial port has been opened |
celnav | never seen an observation | Correct mathematics, zero sights |
| the vertical reference | no hardware at all | and it dominates every celestial fix |
The honest state: nothing in this stack has touched reality. The magnetic results are real measurements on someone else's flight data using someone else's maps. Everything celestial is correct mathematics that has never seen an observation. The gap that matters most costs about £25 to close.
Same rule as everything else here.
PANTHEON refuses to let an agent act without authority. This refuses to assert a position it cannot support. It is the same instinct: a system that declines is more useful than one that guesses, applied to a problem with no customers and no deadline.
Ask about this project: what is measured, and what is only written.
- What is actually measured here?
- What has never been tested?