For the Execution Boundary to function as an effective Governance Control, it must maintain safe behavior not only during normal Constraint Enforcement, but also when Enforcement State is modified, missing, or affected by Enforcement Failure. Two fundamental requirements are therefore Tamper Resistance and Fail-Safe Enforcement.
Tamper Resistance prevents Unauthorized Modification of Enforcement State held in mechanisms such as BPF Maps. Even if the upstream Decision is “DENY external transmission,” the Execution Boundary could be circumvented if an Agent or Application were able to modify the State referenced at Runtime.
Updates and revocations of Enforcement State must therefore be restricted to Authorized paths. This does not mean making the State permanently immutable. Rather, it means allowing legitimate changes based on valid Governance Decisions while preventing Unauthorized Modification.
The second requirement is Fail-Safe Enforcement. If the required Enforcement State cannot be verified because it is missing, invalid, expired, corrupted, or otherwise unavailable, it must not be treated as an implicit Allow.
In such cases, the Kernel does not infer missing Governance information or independently form an Allow or Deny Decision. Instead, Execution must not proceed when valid Enforcement State cannot be verified. Where necessary, control returns to the upstream Governance Process for State retrieval or the formation of a new Decision. This principle is also consistent with Structural Silence and the Silent Domain.
Together, these requirements ensure that the Execution Boundary does not function only under normal conditions, but remains difficult to circumvent when State is modified, missing, unverifiable, or affected by Enforcement Failure.
Specific implementations of Tamper Resistance and Fail-Safe Enforcement may vary across environments. The structure presented here is an exploratory Reference Model for concretizing these principles.