GAL-2 Node · Application-facing Time Contract

GAL-2 Node v1.0.0-rc10 · Limited Release · Linux ARM64 · Signed

Time your application can consume with a contract.

GAL-2 Node brings GAL-2 Time to the application boundary and exposes the Time Contract locally before time becomes committed state.

Your existing timing infrastructure stays in place. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract tells enrolled applications whether that time is safe to use — including continuity through upstream loss, controlled recovery, uncertainty, validity, lineage, and explicit refusal when policy can no longer justify safe consumption.

Current Limited Release

GAL-2 Node v1.0.0-rc10

Linux ARM64

The current release is distributed as a signed release handoff containing the frozen GAL-2 Node RC10 payload, release signature, signing public key, checksums, release identity, and operator documentation.

Signed release Frozen runtime Local SHM + SDK consumption Bounded HOLDOVER Controlled recovery FAIL_CLOSED No raw host-time fallback Host clock unchanged

An active paid GAL-2 API plan is required for normal LIVE operation. Keep your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure.

Evidence lineage

GAL-2 Node builds on the existing public GAL-2 continuity and application-time governance evidence. Earlier daemon and evaluator artifacts remain historical evidence lineage; the current locally installable product surface is GAL-2 Node.

RC4 120-Hour Time Contract Characterization: 14,279 contract samples, 0 gal2_time backward steps, 0 monotonic_sequence backward steps, one documented FAIL_CLOSED boundary row at the declared 72-hour hard HOLDOVER policy boundary, followed by clean LIVE_RESTORED recovery.
DOI: 10.5281/zenodo.20582981

5-Day Time Contract Adversarial Characterization: 14,397 contract samples, 0 fetch failures, 0 monotonic_sequence backward steps, and 0 gal2_time backward steps. During the hard interruption phase, GAL-2 entered FAIL_CLOSED with health=red and safe_to_consume=false after hard policy expiration.
Results DOI: 10.5281/zenodo.20357131
Pre-registration: 10.5281/zenodo.20262207

Solstice 7D: the GAL-2 API-backed governed timeline maintained strict monotonicity across 508,548 observed samples during a full-week run on commodity hardware under real-world network conditions.
DOI: 10.5281/zenodo.18018704

Earlier evaluator releases: RC5.1 and RC5.8 remain part of the historical GAL-2 public evidence chain. They are no longer the current downloadable product surface.
RC5.1 public evaluator evidence

This is application-facing continuity and consumption-governance evidence. It is not UTC metrology certification, a navigation timing claim, oscillator-control evidence, or a claim that GAL-2 replaces UTC, GNSS, PTP, NTP, chrony, grandmasters, atomic clocks, or operating-system time.

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Representative Local Time Contract

GET http://127.0.0.1:9095/contract
{
  "schema": "gal2-daemon-time-contract-v1",
  "version": "1.2.0-contract-rc.4",

  "gal2_time": "2026-08-14T15:56:43.395737Z",

  "safe_to_consume": true,
  "mode": "LIVE",
  "health": "green",
  "reason": "fresh_api_sync",

  "valid_until":
    "2026-08-14T15:57:21.115406Z",

  "monotonic_sequence": 1,

  "uncertainty_ms": 574.518,
  "uncertainty_ms_basis":
    "conservative_model_v1_not_external_metrology_validated",

  "holdover_age_sec": null,
  "max_holdover_sec": 259200.0,

  "source_lineage": [
    "gal2_api",
    "gal2_daemon_rc3_base",
    "rc4_72h_holdover_policy",
    "rc5_ixoye_witness_contract"
  ],

  "witness_ref": {
    "layer": "IXOYE",
    "role": "out_of_band_attestation",
    "policy": "advisory_only",
    "effect_on_safe_to_consume": "none"
  }
}

Runtime lineage note: identifiers such as gal2-daemon-time-contract-v1 and the historical entries in source_lineage preserve the contract/runtime lineage. The current public product name is GAL-2 Node.

1
GAL-2 API

Creates GAL-2 Time.

2
GAL-2 Node

Makes it locally consumable.

3
Time Contract

Governs its use.

IXOYE remains advisory and out-of-band. It does not create GAL-2 Time, act as a fallback time source, or decide safe_to_consume.

GAL-2 Node · Limited Release

Run GAL-2 in your environment.

Install GAL-2 Node alongside your existing timing infrastructure. An active paid GAL-2 API plan is required for the Node to enter LIVE operation and receive GAL-2 Time. The Node then makes GAL-2 Time locally consumable and exposes the Time Contract to your application.

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Recommended for GAL-2 Node Professional · 100,000 API requests / month

Designed for one continuously running GAL-2 Node at the standard 30-second API polling interval. At that cadence, one Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month.

Application reads from the local GAL-2 Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume the Time Contract locally.

Paid API access required: GAL-2 Node requires an active GAL-2 API key for LIVE operation.

Starter is intended for development, API testing, and intermittent Node use. Professional is the recommended plan for one continuously running Node.

v1.0.0-rc10 Linux ARM64 Signed release Local Time Contract 30s standard polling Bounded holdover Fail closed

GAL-2 Node runs alongside your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure. It does not replace or discipline the host clock.

GAL-2 API Creates GAL-2 Time

The protected GAL-2 API creates the governed GAL-2 Time trajectory. It is the upstream source consumed by the GAL-2 Node — not a replacement for your existing UTC, NTP, PTP, or GNSS infrastructure.

GAL-2 Node Makes It Local

GAL-2 Node brings GAL-2 Time to the application boundary and exposes the local Time Contract. It manages LIVE operation, bounded holdover, controlled recovery, uncertainty, validity, lineage, and fail-closed behavior.

Keep Your Timing Stack

GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, and operating-system clocks. It does not discipline the host clock. The Time Contract governs whether enrolled applications should consume time before committing state.

GAL-2 API · GAL-2 Node · Time Contract

How GAL-2 works

GAL-2 adds an application-level consumption layer to your existing timing infrastructure. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs its use before time becomes application state.

01

Get GAL-2 API access

An active GAL-2 API key gives the Node access to GAL-2 Time. Your existing NTP, PTP, GNSS, chrony, cloud timing, and operating-system clock remain in place. GAL-2 does not replace or discipline them.

02

Install the GAL-2 Node

Deploy GAL-2 Node beside your application on a compatible Linux ARM64 system. The Node maintains the upstream GAL-2 connection and makes the governed trajectory available locally through the Time Contract, SHM, and application Provider interfaces.

03

Connect the application once

Your enrolled application consumes GAL-2 locally and checks safe_to_consume, mode, reason, valid_until, uncertainty, and lineage before committing time-dependent state.

Local contract surface GAL-2 Node exposes the Time Contract locally.
curl -s http://127.0.0.1:9095/contract

The Time Contract answers the question raw clocks do not.

Not only “what time is it?” but whether GAL-2 Time is currently safe for an enrolled application to consume, why that decision was made, and how long that decision remains valid.

gal2_time safe_to_consume mode reason valid_until uncertainty_ms holdover_age_sec monotonic_sequence source_lineage
LIVE

Fresh GAL-2 synchronization is available.

HOLDOVER

The Node continues from the last valid GAL-2 state under bounded policy.

REJOIN

Controlled reconciliation is used when recovery requires it.

FAIL_CLOSED

If safe consumption can no longer be guaranteed, GAL-2 refuses rather than silently falling back to raw host time.

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Why it matters

Raw time can become application state silently.

Timing infrastructure tells systems what time it believes it is. GAL-2 adds a governed consumption boundary before time is trusted, written, ordered, logged, or committed by an enrolled application. The GAL-2 Node exposes that decision locally through the Time Contract, while the Protected Core that creates GAL-2 Time remains protected.

Without GAL-2

Timing faults can pass directly into application state.

  • Clock discontinuities or unexpected steps can disrupt ordering, sequencing, and time-dependent logic.
  • Stale or degraded timing may still appear consumable to the application.
  • Recovery events can reach software without an application-level reconciliation policy.
  • A timing problem may be discovered only after time-dependent state has already been committed.
With GAL-2 Node

Time is governed before the application consumes it.

  • Enrolled applications check safe_to_consume before committing time-dependent state.
  • The GAL-2 Node makes GAL-2 Time locally consumable together with validity, uncertainty, reason, policy state, and lineage.
  • LIVE, HOLDOVER, REJOIN, and FAIL_CLOSED behavior is explicit rather than hidden from the application.
  • When safe consumption can no longer be guaranteed, the protected application path refuses rather than silently falling back to raw host time.
Protected Core

Contract-visible. Core-protected. Evidence-backed.

The GAL-2 API delivers GAL-2 Time created by the Protected Core. The GAL-2 Node makes that trajectory locally consumable, while the Time Contract exposes the decision an enrolled application needs: whether time is safe to consume, why, for how long, and under what continuity state. The underlying GAL-2 governance model remains protected.

Current release GAL-2 Node v1.0.0-rc10 Platform Linux ARM64 Local contract 127.0.0.1:9095/contract Local consumption SHM + SDK Provider Upstream GAL-2 API Protected Core Policy lineage visible in Time Contract Signed release with GPG identity Release artifacts with SHA-256 Public evidence on Zenodo DOI Host clock not disciplined No silent raw host-time fallback
Close-up of a dark digital audio workstation interface showing audio and MIDI tracks with waveforms and block patterns.

Time-boundary failures

Built for the moments when timing faults can become application faults.

GAL-2 Node is designed for enrolled application paths that should not blindly consume time during discontinuities, reference loss, stale state, recovery events, legacy timestamp boundaries, or other timing conditions that can affect ordering, transactions, logs, expirations, coordination, and committed state.

Clock discontinuities

Do not let an unexpected time jump silently become state.

Leap-second-like events, clock steps, and other discontinuities can create brittle application behavior when software assumes that every timestamp is automatically safe to consume. GAL-2 Node gives enrolled applications a governed path through gal2_time, safe_to_consume, validity, uncertainty, mode, reason, sequence, lineage, and fail-closed behavior.

Y2038-style application boundaries

Protect the application boundary around legacy timestamp failures.

GAL-2 does not patch legacy binaries, kernels, firmware, database engines, schemas, operating systems, or 32-bit time_t implementations. Those require platform-level remediation.

GAL-2 operates at a different boundary: where an enrolled application is deciding whether time should become committed state. When the underlying platform can execute the GAL-2 integration path, the Time Contract can expose an unsafe condition and allow the protected application path to refuse, degrade, hold over, or fail closed instead of silently committing time it should not consume.

Reference loss and recovery

Continue when policy allows. Refuse when it does not.

When the GAL-2 API becomes temporarily unavailable, the Node can continue from the last valid GAL-2 state under bounded holdover policy while uncertainty grows explicitly. When upstream access returns, recovery may return directly to LIVE or use controlled REJOIN when reconciliation is required.

If the declared safety boundary is exhausted, the protected path transitions to FAIL_CLOSED rather than silently substituting raw host time.

Claim boundary GAL-2 does not replace platform-level Y2038 remediation, operating-system updates, firmware replacement, database schema migration, legacy binary remediation, UTC infrastructure, or clock synchronization systems.

It operates at the application-consumption boundary: GAL-2 API creates GAL-2 Time, GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it.

Platform remediation fixes platform limitations. GAL-2 governs whether time is safe to become application state.
GAL-2 API Creates GAL-2 Time
GAL-2 Node Makes it locally consumable
Time Contract Governs its use

GAL-2 Node · Limited Release

Run GAL-2 locally.

GAL-2 Node connects to the GAL-2 API, makes GAL-2 Time locally consumable, and exposes the application-facing Time Contract through local interfaces including /contract, SHM, and the SDK Provider.

GAL-2 Node v1.0.0-rc10

Available now: Linux ARM64

Next platform: macOS Apple Silicon
Available now Linux ARM64

Current GAL-2 Node v1.0.0-rc10 release.

Coming next macOS Apple Silicon

Native GAL-2 Node platform release in development.

Linux ARM64 available now macOS Apple Silicon coming next Local endpoint: 127.0.0.1:9095/contract Local consumption: SHM + SDK Provider Contract: 1.2.0-contract-rc.4 LIVE · HOLDOVER · REJOIN · FAIL_CLOSED Bounded holdover No silent raw host-time fallback Host clock not disciplined GPG-signed release Paid API access required for LIVE
Recommended for GAL-2 Node Professional · 100,000 API requests / month

GAL-2 Node requires an active paid GAL-2 API key for LIVE operation. Professional is the recommended plan for one continuously running Node at the standard 30-second polling interval.

At the standard cadence, one continuously running Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month. Application reads from the local Node do not each consume an API request.

GAL-2 API: creates and delivers GAL-2 Time from the protected GAL-2 governance core. Backend entitlement determines whether the Node has access to the upstream GAL-2 service.

GAL-2 Node: makes GAL-2 Time locally consumable by enrolled applications. It provides local continuity, bounded holdover, controlled recovery, uncertainty tracking, SHM publication, and SDK Provider access.

Time Contract: governs whether the enrolled application should consume GAL-2 Time. Applications can inspect safe_to_consume, mode, reason, valid_until, uncertainty_ms, monotonic_sequence, and source_lineage.

Failure behavior: if upstream GAL-2 access becomes unavailable, the Node can continue from the last valid GAL-2 state under bounded policy. Recovery may return directly to LIVE or use REJOIN when reconciliation is required. If the declared safety boundary is exhausted, the protected path fails closed rather than silently substituting raw host time.

Existing timing infrastructure stays in place: GAL-2 runs alongside NTP, PTP, GNSS, chrony, grandmasters, cloud timing, and operating-system clocks. The GAL-2 Node does not discipline the host clock.

Platform availability: GAL-2 Node v1.0.0-rc10 is currently available for Linux ARM64. A native macOS Apple Silicon GAL-2 Node is the next planned platform release and is not included in RC10.

Release verification

RC10 public handoff SHA-256 080a17dc6f477a6a707e78efe14412d3a0f15d38cc2829cda0ddd9bf8024ac6b

Signing fingerprint: 802C 8978 FF85 7550 60B6 D6BC 8AB8 59E4 D705 822F

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Validation Evidence

Raw time keeps going. GAL-2 knows when to stop.

The Red Light Test compares a raw-time application path against a GAL-2-aware path that commits state through the Time Contract. When time is declared unsafe, the GAL-2 path blocks protected operations before unsafe time becomes application state.

Raw application path

Committed through unsafe time

20 total events
20 raw commits
6 unsafe commits
GAL-2 Time Contract path

Governed before commit

14 allowed commits
6 unsafe operations blocked
0 unsafe GAL-2 commits
Result: PASS

Under the declared unsafe window, the raw path kept committing. The GAL-2 path allowed safe operations, blocked unsafe operations, and produced zero unsafe commits.

The Time Contract answers the operational question:

Can this governed time safely become application state right now?

This is application-facing temporal safety evidence, not a UTC accuracy or metrology claim.

Claim Boundary

Where GAL-2 sits in the timing stack.

GAL-2 is an application time-consumption governance layer. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it before time becomes application state.

What GAL-2 does not claim
  • Not a metrology certification or external calibration claim.
  • Not a universal nanosecond or microsecond accuracy guarantee.
  • Not a replacement for UTC, GNSS, PTP, NTP, chrony, atomic clocks, grandmasters, timing receivers, or operating-system clocks.
  • Not a claim that physical reference infrastructure is no longer needed.
  • Not a mechanism for disciplining, steering, or modifying the host system clock.
  • Not a replacement for platform-level Y2038 remediation such as 64-bit time migration, operating-system updates, firmware replacement, database schema changes, or legacy binary remediation.
What GAL-2 governs
  • Application-facing consumption of gal2_time.
  • An explicit safe_to_consume decision before time-dependent state is committed.
  • Monotonic consumption behavior for enrolled application paths.
  • Bounded HOLDOVER when upstream GAL-2 access is temporarily unavailable and policy still permits safe continuation.
  • Controlled recovery through LIVE or REJOIN behavior when upstream synchronization returns.
  • FAIL_CLOSED behavior when the declared safe-consumption boundary can no longer be maintained.
  • Y2038 application-state remediation at the commit boundary.
  • Auditable runtime state including mode, reason, validity, uncertainty, monotonic sequence, and source lineage.
Y2038 Remediation Boundary
Platform-level remediation

Fix the underlying time representation.

Platform remediation includes work such as 64-bit time migration, operating-system and kernel updates, firmware replacement, database schema changes, runtime changes, and remediation of legacy binaries or 32-bit time_t dependencies.

GAL-2 application-state remediation

Govern what happens before unsafe time becomes state.

GAL-2 operates at a different layer. For enrolled application paths, the Time Contract governs whether time should be consumed before a Y2038-style timestamp failure can become committed application state.

Depending on the declared policy and current contract state, the protected application path can continue under bounded policy, degrade, hold over, recover under controlled rules, or fail closed instead of silently accepting unsafe time.

01 · GAL-2 API Creates GAL-2 Time

Delivers the protected upstream GAL-2 trajectory and controls service access through backend entitlement.

02 · GAL-2 Node Makes it locally consumable

Provides local delivery, continuity, bounded holdover, controlled recovery, SHM publication, and SDK Provider access beside the application.

03 · Time Contract Governs its use

Tells enrolled software whether GAL-2 Time is safe to consume, why that decision was made, and under what validity and policy state.

The distinction

GAL-2 does not claim to repair a broken 32-bit operating system, kernel, firmware image, database engine, or legacy binary. Those remain platform-remediation responsibilities.

GAL-2 provides a separate layer of application-state remediation at the commit boundary: it gives an enrolled application an explicit governed decision before time becomes trusted, written, ordered, logged, expired, transacted, or otherwise committed as application state.

Platform remediation fixes the underlying time representation.
GAL-2 provides application-state remediation at the commit boundary.

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Evidence integrity

Validation artifacts are sealed, scanned, and reproducible.

GAL-2 public validation packages are prepared with SHA-256 manifests, secret scans, public-safe artifacts, and reproducible evidence trails for technical review.

Public-safe artifacts

Scanned

SHA-256 manifests

Sealed

Validation packages

Published

Application-facing time governance

Continuity when time becomes unsafe.

GAL-2 Node helps enrolled applications preserve ordering, continuity, and state safety across LIVE operation, bounded HOLDOVER, controlled REJOIN, degraded timing conditions, FAIL_CLOSED behavior, and restart continuity.

Your timing stack delivers time. GAL-2 governs whether software should consume it before time becomes state.

What is the core benefit?

GAL-2 gives enrolled applications an explicit Time Contract before time-dependent state is committed. Instead of assuming that every available timestamp is automatically safe to consume, software can make a governed decision before time becomes durable application state.

How does GAL-2 govern time consumption?

The Protected Core creates the governed GAL-2 Time trajectory and the GAL-2 API delivers it upstream. GAL-2 Node makes GAL-2 Time locally consumable, while the Time Contract exposes fields including gal2_time, safe_to_consume, mode, reason, validity, uncertainty, monotonic sequence, and source lineage before an enrolled application acts.

What happens when upstream GAL-2 access is lost or timing degrades?

GAL-2 Node can continue from the last valid GAL-2 state under bounded HOLDOVER policy while uncertainty grows explicitly. When upstream access returns, the Node may return directly to LIVE when reconciliation is not required, or use controlled REJOIN when it is.

If the declared safe-consumption boundary is exhausted, GAL-2 transitions the protected path to FAIL_CLOSED rather than silently substituting raw host time.

What happens across Node restarts?

Restart continuity is treated as a governed decision, not an automatic assumption. GAL-2 evaluates continuity state before the Provider accepts a new publication path, including generation identity, GAL-2 progression, sequence state, freshness, validity, uncertainty, monotonic context, implementation compatibility, and source lineage.

A Provider does not silently accept an unexpected generation change as if nothing happened.

Does GAL-2 replace existing timing infrastructure?

No. GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, operating-system clocks, atomic references, and existing timing infrastructure. Those systems continue performing their own timing and synchronization functions. GAL-2 adds governance at the application-consumption boundary and does not discipline the host clock.

Who is GAL-2 designed for?

Teams operating distributed or stateful applications where ordering, transactions, ledgers, logs, caches, authorization, expirations, workflows, audit trails, recovery behavior, or Y2038 application-state boundaries depend on safe time consumption.

Is integration straightforward?

Yes. Install GAL-2 Node beside the application, provide active GAL-2 API access, and connect the protected application path to the local Node through the Time Contract, SHM, or SDK Provider. GAL-2 is designed to protect specific application workflows without requiring replacement of the existing timing stack.

Does GAL-2 Node require API access?

Yes. An active paid GAL-2 API key is required for the Node to receive GAL-2 Time and operate in LIVE mode. The Professional plan is recommended for one continuously running Node at the standard 30-second polling interval.

Application reads from the local Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume GAL-2 locally.

Which platforms are supported?

GAL-2 Node v1.0.0-rc10 is currently available for Linux ARM64. A native macOS Apple Silicon GAL-2 Node is the next planned platform release.