GAL-2™ Application Time Governance

Governed Time for Application State

Your timing stack delivers time. GAL-2 adds a governed application layer: the GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs when it is safe to use.

GAL-2 API creates GAL-2 Time GAL-2 Node makes it locally consumable Time Contract governs its use

Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Checking GAL-2 API status…
Latest Public Release Evidence

GAL-2 Node v1.0.0-rc10

GAL-2 Node v1.0.0-rc10 is the current signed limited release of the application-facing GAL-2 Node for Linux ARM64. It makes GAL-2 Time locally consumable through the Time Contract, SHM, and SDK Provider while preserving bounded continuity, controlled recovery, fail-closed behavior, and host-clock non-interference.

Current public release GAL2_NODE_V1_0_0_RC10_LIMITED_RELEASE

Available now: Linux ARM64 · Next platform: macOS Apple Silicon

GAL-2 Node release RC10
Time Contract rc.4
Hard holdover policy boundary 72h
Current platform Linux ARM64
Release integrity GPG Signed
Unsafe fallback behavior FAIL CLOSED

Why this release matters

RC10 moves GAL-2 from the earlier standalone Time Contract evaluator lineage into the current GAL-2 Node product surface. Applications can consume GAL-2 locally through 127.0.0.1:9095/contract, SHM, or the SDK Provider rather than rebuilding timing-failure handling inside every application.

The Node exposes gal2_time, safe_to_consume, mode, reason, validity, uncertainty, holdover age, monotonic sequence, and source lineage before time becomes application state.

During upstream GAL-2 interruption, the Node can continue from the last valid GAL-2 state under bounded HOLDOVER policy. When upstream access returns, recovery may return directly to LIVE or use controlled REJOIN when reconciliation is required.

If the declared safe-consumption boundary is exhausted, the protected path transitions to FAIL_CLOSED rather than silently substituting raw host time. GAL-2 Node does not discipline, steer, or replace the host system clock.

This matters because GAL-2 is not asking teams to replace UTC, GNSS, PTP, NTP, chrony, grandmasters, atomic references, hardware clocks, or operating-system time. GAL-2 adds a governed application-consumption boundary where time becomes software state.

Available now Linux ARM64

GAL-2 Node v1.0.0-rc10 current signed release.

Coming next macOS Apple Silicon

Native GAL-2 Node platform release planned next.

Public handoff SHA-256

080a17dc6f477a6a707e78efe14412d3a0f15d38cc2829cda0ddd9bf8024ac6b

Signing fingerprint

802C 8978 FF85 7550 60B6 D6BC 8AB8 59E4 D705 822F

Time Contract Policy

View Time Contract Policy

Current release validation
Clean-slate Linux ARM64 install PASS
GAL-2 Node doctor PASS
Host timing state unchanged PASS
Bounded continuity PASS
Controlled recovery PASS
No silent raw host fallback PASS
Public evidence lineage

RC10 builds on an existing GAL-2 validation record.

The current Node release does not erase the earlier Time Contract work. RC5.x remains part of the public GAL-2 evidence lineage, including macOS notarized packaging, Linux ARM64 evaluator packaging, Time Contract semantics, IXOYE advisory observation, long-duration continuity experiments, and DOI-published evidence.

LIVE operation

Active paid GAL-2 API access is required.

The GAL-2 API delivers GAL-2 Time to the Node. The Professional plan is recommended for one continuously running GAL-2 Node at the standard 30-second polling interval. Application reads from the local Node do not each consume an upstream API request.

Get GAL-2 API Access
Scope boundary: GAL-2 Node v1.0.0-rc10 is the current signed limited release for Linux ARM64. It is not a metrology certification, universal precision guarantee, or replacement for UTC, GNSS, PTP, NTP, chrony, grandmasters, atomic references, hardware clocks, operating-system time, or existing timing infrastructure. GAL-2 governs a different layer: application-side consumption of GAL-2 Time before time becomes committed state. HOLDOVER is bounded by declared policy and uncertainty. The Node does not recreate the Protected Core locally during HOLDOVER, does not discipline the host clock, and does not silently fall back to raw host time when the protected GAL-2 path becomes unsafe. Earlier RC5.x releases remain part of the historical GAL-2 evidence lineage but are not the current Node release.

Public Evidence Chain

5-Day Time Contract Adversarial Characterization

Pre-registered adversarial run with public results package

GAL-2 Time Contract v1.0 completed a 5-day adversarial characterization under controlled upstream interruption conditions.

The run evaluated application-facing temporal governance behavior, including LIVE, HOLDOVER, DEGRADED, REJOIN, and FAIL_CLOSED states.

The official collector completed cleanly with 14,397 contract samples and 14,397 consumer rows. During the hard interruption phase, GAL-2 entered FAIL_CLOSED with health=red and safe_to_consume=false after hard policy expiration.

0 fetch failures
0 monotonic_sequence backward steps
0 gal2_time backward steps
Secret scan PASS
Public pre-registration
Public results package

Claim boundary: This evidence evaluates application-facing Time Contract behavior under controlled upstream interruptions. It is not a UTC replacement claim, GNSS/PTP/NTP replacement claim, metrological accuracy claim, or long-duration autonomous holdover claim.

Validation evidence

Real Daemon Impairment Test v0.1

A controlled upstream impairment test using the installed GAL-2 local daemon and the real application-facing Time Contract endpoint.

Result: PASS
Phase order Baseline LIVE → Upstream impairment → Recovery
Modes observed LIVE · HOLDOVER · DEGRADED · FAIL_CLOSED
Mode distribution 36 LIVE · 9 HOLDOVER · 20 DEGRADED · 7 FAIL_CLOSED
Records 72 contract snapshots
Fail-closed samples 7 safe_to_consume=false records
Backward steps 0 monotonic_sequence · 0 gal2_time steps
Secret scan PASS · 0 findings
Claim type Application-facing Time Contract impairment evidence

When upstream access was impaired, GAL-2 did not fail silently. The daemon exposed explicit Time Contract states including HOLDOVER, DEGRADED, and FAIL_CLOSED. When safe consumption could no longer be justified, safe_to_consume became false.

Zenodo DOI 10.5281/zenodo.20213086
Public-safe package SHA256 85db223e2f4273777f371f5ad5d25187e318c06e1f91e24781aae4bac62fa14e
Claim boundary: application-facing Time Contract impairment evidence. Not a metrology accuracy test. Not a UTC replacement claim. Not a nanosecond or microsecond precision claim. Not a claim that GAL-2 replaces GNSS, PTP, NTP, chrony, atomic clocks, grandmasters, timing receivers, or national metrology references.
Close-up view of a microscope lens focusing on a digital touchscreen interface with colorful icons.
APPLICATION-FACING TIME VALIDATION

API-Backed Contract Source Isolation

A general-purpose Mac client consumed a local SNTP feed derived from the GAL-2 Time Contract used in this test and backed by the live GAL-2 API.

60m
SUSTAINED MONITOR
61/61
CLIENT SAMPLES
79/79
SAFE RESPONSES
PASS
ADOPTION RESULT

In this controlled two-Mac demonstration, Mac A ran the GAL-2 daemon used for this evidence record and exposed a local SNTP-compatible bridge derived from the GAL-2 Time Contract. Mac B was configured to use Mac A as its macOS Network Time Server.

This version extended the earlier source-isolation evidence by replacing the prior local protected-core path with the live API-backed Time Contract path.

Tested Chain GAL-2 API → GAL-2 daemon → Time Contract → Mac A SNTP Bridge → Mac B Network Time
Mac A Bridge 192.168.6.143
Mac B Client 192.168.6.243
Source Lineage gal2_api → gal2_daemon → contract_v1
Mac B Monitor 61 samples, PASS
Bridge Responses 79 SNTP responses
Modes Observed LIVE, REJOIN
Monotonic Sequence 30284 to 30362
Master Archive SHA256 ce63a8e26d38e61ef8d0d1d7e5d101631087f59fb80537fb42e568fcca169f85
What this demonstrated

The Mac client did not consume the GAL-2 API directly. It consumed a local SNTP-compatible feed derived from the application-facing GAL-2 Time Contract path.

Across the sustained 60-minute monitor, all 61 client observations completed successfully and the bridge recorded 79 safe responses.

This evidence demonstrated that GAL-2 governed output could be carried through a conventional local network-time consumption path while preserving an explicit GAL-2 source lineage behind that path.

Evidence Boundary

This test supports 60-minute operational source isolation and contract-gated local time consumption using the GAL-2 Time Contract and live GAL-2 API path exercised by this evidence record.

It does not claim physical oscillator control, metrological replacement of UTC, UTC traceability certification, universal production readiness, universal compatibility, or clock accuracy superiority.

Previous source-isolation evidence used an earlier local protected-core path. This evidence record documents the later API-backed Time Contract path. It remains part of the public GAL-2 validation lineage and should be interpreted according to the exact architecture and artifact documented by this test.

Application-Facing Time Safety

Red Light Test v2 Live Demo

Raw time keeps going. GAL-2 knows when to stop. This live demo shows the GAL-2 Time Contract blocking unsafe operations before time becomes committed application state.

21 Raw commits
6 Raw unsafe commits
6 GAL-2 blocked unsafe operations
0 GAL-2 unsafe commits
What this test demonstrates

The raw application path continued committing through the declared unsafe window. The GAL-2 Time Contract-aware path blocked the 6 unsafe operations before they became committed state, resulting in 0 GAL-2 unsafe commits.

This test measures application-facing temporal safety behavior, not clock accuracy. It is controlled technical evidence and should be interpreted within its stated test boundary.

Evidence boundary: this test demonstrates application-facing commit-gating behavior under the declared Red Light Test conditions. It is not metrology evidence, UTC traceability evidence, a GNSS/PTP/NTP replacement claim, or proof of clock-accuracy superiority.

Historic API correction record

Historic GAL-2 API correction output

Early technical record from the original GAL-2 API correction pathway.

On July 28, 2025, GAL-2™ was tested through its API correction pathway using an externally supplied UNIX timestamp. The system returned a governed correction output in real time: gal2_corrected: 1722283734.

This record is preserved as early engineering evidence that a submitted timestamp entered the GAL-2 API path and produced a corrected output rather than simply echoing raw time.

Submitted timestamp 1722283745
GAL-2 output 1722283734
Observed correction -11 seconds
Claim boundary: This is a historic API correction record. It is not a metrology certification, not a UTC replacement claim, not an NTP replacement claim, and not a nanosecond or microsecond precision claim. Current validation evidence is documented below through the GAL-2 Time Contract, 5-Day Adversarial run, Real Daemon Impairment Test, Red Light Test, Y2038 Evidence Corpus, and other sealed validation artifacts.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Y2038 Evidence Corpus

From corrected time to protected state.

A layered public evidence trail showing how GAL-2 moves from legacy mediated-time continuity into application-boundary commit protection, local multi-substrate durability, local Postgres gating, local latency characterization, and controlled GAL-2 Time authority beyond the signed 32-bit Unix time boundary. The model is not “GAL-2 patches every legacy machine.” The model is: keep the minimum substrate alive, move operational time authority to GAL-2, and protect the workflow before broken time becomes committed state.

Operational continuity model

GAL-2 does not claim to keep a failed 32-bit kernel, firmware, filesystem, database engine, or host operating system alive by itself.

GAL-2 operates where a protected workflow can still execute, or where a bridge, wrapper, gateway, daemon, or external integration layer can consume the Time Contract.

Under that model, GAL-2 moves operational time authority away from signed-32 Unix time and into governed GAL-2 Time.

Minimum substrate stays alive. GAL-2 governs time authority. Protected workflows keep operating.

Layer 1
Legacy binary continuity
Layer 2
SQLite protected commit
Layer 3
SQLite + JSONL durability
Layer 4
Local Postgres gating
Layer 5
Latency characterization
Layer 1 Legacy boundary Published

Legacy Binary Continuity

Post-2038 continuity for tested legacy execution paths

Legacy 32-bit execution paths were evaluated beyond the raw Y2038 boundary using GAL-2 API-seeded temporal continuity.

This package documents mediated-time behavior in legacy post-2038 scenarios where tested legacy-style execution paths continued operating in cases where raw execution paths failed.

Interpretation: evidence of legacy survivability and continuity for tested binary execution paths. Not a universal claim for every legacy binary, operating system, or execution environment.

Layer 2 SQLite PASS

Application-Boundary Protected Commit

GAL-2 Y2038 Protected Commit Test v1.1.1

This package extends the prior Y2038 corpus from legacy mediated-time behavior into application-boundary protected commit behavior.

In the tested single-host SQLite scenario, the raw path committed unsafe Y2038-style time-derived state. The GAL-2 protected path checked the Time Contract gate and the declared Y2038 safety policy gate before durable commit, blocking unsafe inputs before they became durable application state.

Main test
PASS
Oracle verifier
PASS
Secret scan
PASS
Archive smoke
PASS

Claim boundary: application-boundary protected commit evidence. Not universal Y2038 remediation, not operating system, kernel, filesystem, database engine, or distributed-system remediation, not production throughput or latency evidence, not metrology, and not UTC, GNSS, PTP, NTP, or chrony replacement.

Layer 3 SQLite + JSONL PASS

Local Multi-Substrate Protected Commit

GAL-2 Y2038 Multi-Substrate Protected Commit Test v1.2

This package extends protected commit evidence from a single SQLite substrate to a local multi-substrate scenario using SQLite and an append-only JSONL ledger.

The raw path committed unsafe Y2038-style state into both tested substrates. The GAL-2 protected path produced zero unsafe commits across SQLite and JSONL.

Cross-substrate consistency means data parity: the same logical safe commits appear in both tested substrates, and unsafe inputs are absent from both GAL-2 protected substrates. It does not claim transactional atomicity, two-phase commit, rollback coordination, distributed transactions, or atomic cross-substrate recovery.

Total cases
30
Raw unsafe commits
40
GAL-2 unsafe commits
0
Backward steps
0

Claim boundary: local multi-substrate application-boundary protected commit evidence using SQLite and append-only JSONL. Not universal Y2038 remediation, not distributed-system remediation, not production throughput or latency evidence, not transactional atomicity evidence, not metrology, and not UTC, GNSS, PTP, NTP, or chrony replacement.

Layer 4 Postgres PASS

Local Postgres Protected Commit

GAL-2 Y2038 Postgres Protected Commit Test v1.3

This package extends the protected commit evidence into a local Postgres database substrate. It evaluates whether unsafe Y2038-style time-derived state can be blocked before becoming durable Postgres application state.

In the tested single-host local Postgres scenario, the raw path committed unsafe Y2038-style records into Postgres. The GAL-2 protected path blocked all unsafe inputs and committed all safe inputs.

Postgres rows
60
Raw unsafe commits
20
GAL-2 unsafe commits
0
False-positive blocks
0

Claim boundary: local Postgres application-boundary protected commit evidence. Not universal Y2038 remediation, not operating system, kernel, filesystem, database engine, or distributed-system remediation, not replication evidence, not multi-node behavior, not multi-writer behavior, not transactional atomicity across multiple systems, not production performance evidence, not metrology, and not UTC, GNSS, PTP, NTP, or chrony replacement.

Layer 5 Latency PASS

Local Latency Characterization

GAL-2 Protected Commit Latency Characterization v1.4

This package characterizes local raw path latency, GAL-2 protected path latency, local Time Contract fetch latency, safe commit latency, unsafe block latency, and p50 / p95 / p99 behavior across SQLite, append-only JSONL, and local Docker Postgres.

The Contract measurement uses the real local GAL-2 Time Contract surface at 127.0.0.1:9095/contract. It measures local daemon latency, not a direct public API round-trip to api-v2.gal-2.com.
For Postgres, the meaningful interpretation is protected path versus raw path under the same local method. Absolute Postgres latency values include docker exec psql overhead and should not be interpreted as production libpq, connection-pooled, or networked database latency.
SQLite / JSONL
PASS
Postgres
PASS
Combined summary
PASS
Archive audit
PASS

Claim boundary: local latency and throughput characterization only. Not production throughput evidence, not production latency evidence, not distributed-system performance evidence, not a capacity benchmark, not metrology, and not UTC, GNSS, PTP, NTP, or chrony replacement evidence.

A layered evidence record.

The Y2038 corpus documents a progression from mediated-time continuity to protected application-state behavior, local multi-substrate durability, Postgres commit gating, local latency characterization, and controlled GAL-2 Time authority beyond the signed 32-bit Unix time boundary. Each layer is published with a strict claim boundary, independent verification artifacts, public-safe packaging, and reproducible evidence records.

Compared to standard NTP, GAL-2™ compresses offsets and increases stability across servers worldwide.

demonstrating application-facing temporal safety behavior under declared policy, while complementing existing timing infrastructure.

Historical integrity records

Public hashes for earlier sealed validation artifacts.

These public hashes are preserved as integrity records for specific historical GAL-2 validation artifacts. They are not standalone performance claims. Each hash should be read as evidence that the referenced artifact existed in a sealed form at the time of publication.

Historical record: the following hashes preserve earlier GAL-2 validation artifacts and should be interpreted together with the dated package, manifest, or record they identify.
September 29, 2025

File

verify_20250929T203008Z.txt

SHA512

8b262ed2970a5afc7d041181be581c4c304eb2c1aa7bd6fbe6e47b6f6e4cd79829c0848e0861da679402756fe5a3ad16c6c4b6647791f246b769e8d7c0cd50a4

S3 VersionId

DeSp8N0Gal8gvXJrafguMiBbgl7J9nyR

File

gal2_nopano_manifest_20250929.json

SHA512

43c99d07810f76ff4fff79b3035fd710639067fda5362c9fa1e2a2cc48abdbb4d3aef5ee60fa4a894c2eaff6419309ea

S3 VersionId

aSmv9u3z_QciikmHVZ68fQuBvd9mguiu
September 30, 2025

File

verify_20250930T151405Z.txt

SHA512

a48467f3bbd8968953614080eb0330333962a987704de1c2fbe75779d60b4e79b0f3ca6df732aad5610a9c6bf88bc005

S3 VersionId

y0A0_spIptQtdTgGyrS.3JKOy.5Wccpx

File

gal2_manifest_2025-09-30_151423Z.json

SHA512

f6ad0ccfb8c8cffb8166e4d59a8d878f

S3 VersionId

CFShof.AOaRnU_fdtiFoQJ1GShOTfy3Z

Verification

Verify downloaded artifacts locally.

Anyone can verify a referenced file by downloading the manifest or evidence artifact, calculating its SHA512 hash, and comparing the result to the value published here.

sha512sum <file>
Close-up view of a microscope lens focusing on a digital touchscreen interface with colorful icons.

The full 7-day GNSS-denied dataset is publicly archived on Zenodo for independent review and replication.
https://doi.org/10.5281/zenodo.18018704
Dataset content is immutable and independently hosted.

10.5281/zenodo.18018704


Local Daemon Continuity Pack-Monotonic application-facing continuity observed across restart, holdover, and rejoin conditions

On 2026-04-21, GAL-2 local daemon tests on macOS showed 0 backward steps across sequential reads, concurrent reads, forced daemon restarts, and induced upstream-loss holdover testing. The daemon remained continuously available through holdover and returned to live mode without temporal rollback.Highlights5,000 sequential reads, 0 backward steps
10,000 parallel reads, 0 backward steps
5 forced daemon restarts, 0 backward steps
300/300 successful holdover test responses
600/600 successful 10-minute daemon probe responsesDOIDOI: 10.5281/zenodo.19684054IntegritySHA-256: 0eb2fcb347e3025443aaa224340c45d0e179a666fe41ae70cc98ac0b58a3c142Honest noteThis package supports continuity and resilience claims.

10.5281/zenodo.19684054

72h steady-state observation: node-specific GAL-2-to-UTC relation held within 1 μsIn the 72-hour steady-state dataset, the observed GAL-2-to-UTC relation remained stable within 1 μs per node while preserving a node-specific constant offset.This is evidence of node-specific steady-state relation stability under the tested conditions. It is not a public claim of universal one-microsecond absolute accuracy, certified UTC traceability, or replacement of metrology-grade timing references.Honest note:
The result supports steady-state stability of the observable GAL-2-to-UTC relation, not a universal precision guarantee.

10.5281/zenodo.19546807


Strict ordering preserved under leap-second-like discontinuities

GAL-2 preserved a strictly increasing consumer path across 27 historical events under controlled authority-side raw_stepand backward_jump injection, with 54/54 passing runs, 0 backward steps, 0 duplicate steps, and 0 errors. Independent observation confirmed the same result. In separate production testing, the real GAL-2 API remained strictly increasing across 2000 direct polls with 0 backward steps, 0 duplicate steps, and 0 request errors.
Evidence: https://doi.org/10.5281/zenodo.19687840
Scope: Controlled architectural evidence plus real production API strict-ordering probe.

10.5281/zenodo.19687840