2026-10-11 18:01 UTC

JosΓ© Luis Pino claims his released Hard Stop reference implementation deterministically freezes misbehaving agents in under 0.154 ms via out-of-band kernel-level preemption, establishing OS-layer containment as a complement to app-layer agent policy gates.

state: seedheat: lowuncertainty: highconvergesscott: mediumagentic-security runtime-containment kernel-enforcementJosΓ© Luis Pino

What is this?

José Luis Pino has released a reference implementation titled 'Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution,' claiming that an out-of-band sentinel at the kernel level can deterministically freeze a misbehaving AI agent in under 0.154 ms — i.e., a kill path that does not depend on the agent's own runtime or app-layer policy gates cooperating. The supplied web results do not surface Pino or Hard Stop directly, so his specific claims (including the latency figure) cannot be independently verified from these snippets; they show only the surrounding 2026 landscape, which is crowded with adjacent containment work — EU-AI-Act-anchored kill-switch primitives (agentmodeai.com), Cursor's OS-level sandboxing and Docker microVM shell sandboxes (Victorino Group), a firecracker→gVisor→bwrap→namespace isolation waterfall (dev.to), and policy-enforcement proxies like Parapet, PolicyLayer, and agentsh that intercept tool calls or syscalls below the model. None of these describe in-process kernel-level preemption as Hard Stop claims, which supports the case's 'genuinely distinct claim' framing, but the snippets leave the artifact's provenance and traction unconfirmed.

Why it matters to Scott

Pino independently arrives where Architecture Not Vibes and Manners vs Physics already argue β€” enforcement that cannot be defeated by the agent's own cooperation β€” and positions Hard Stop as a complement to exactly the app-layer policy gates DAI specifies; but the artifact adds a mechanism Scott's canon does not carry: out-of-band kernel preemption that halts a rogue agent mid-flight, where SiloOS's OS cell only isolates and DAI only gates before consequence. That prevention-vs-preemption distinction is a concrete design prompt for the SiloOS spec (should a padded cell include an external freeze path the way dead-man's-switch externalises liveness?), and it joins K3I-Core, Grith and Aegis as further independent arrivals at below-app-layer enforcement β€” though with an unknown author, zero traction and the 0.154 ms claim unverified, this is territory validation and a primitive to evaluate, not a dated-receipts publishing moment.
ip:framework.architecture-not-vibesip:concept.manners-vs-physicsip:framework.decision-authority-infrastructureip:framework.siloosdev:project.silo-osip:concept.dead-mans-switchradar:k3i-kernel-agent-vetoradar:grith-syscall-agent-supervisionradar:aegis-inline-ebpf-agent-containment
queries asked of Scott's wikis
  • agent containment enforcement layer harness vs OS vs model
  • prompt injection defense deterministic guardrails not prompt instructions
  • coding agent sandbox isolation runtime security
  • agent kill switch fail-safe termination pattern
  • policy enforcement below the model architecture claim
  • local agent execution trust boundary

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 410h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-24 16:54 (minted)⭐ origin echo-reconstructedReference implementation for 'Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution' claiming out-of-band sentinel
joseluispino (JosΓ© Luis Pino) on github (echo) Β· attributed from hn.story.49830567 Β· published time unknown
β€”
09-24 13:50first on hacker news Β· published Β· lag ?Hard Stop: Out-of-band kernel preemption for rogue AI agents
joseluispino
β€”
09-24 13:50amplified on hacker newshn.story.49830567
joseluispino
peak 1 Β· 0 comments Β· 35% of case engagement
09-25 13:01amplified on hacker news πŸ‘‘hn.story.49844056
joseluispino
peak 2 Β· 0 comments Β· 65% of case engagement
09-24 15:21our radar first saw it Β· lag ?discovery anchor: hn.story.49830567β€”
pace: p32 vs 1032 stories at the 336h mark (now 410h old) β€” ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)

Evidence (3) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHard Stop: Out-of-band kernel preemption for rogue AI agents
Retrieved article excerpt

Open article Β· Retrieved 2026-09-24T16:38:23.912087+00:00

# Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution

[Paper](https://github.com/joseluispino/hardstop/blob/main/paper/hard_stop.pdf)
[arXiv](https://arxiv.org)
[ORCID](https://orcid.org/0009-0005-4854-3914)
[License](https://opensource.org/licenses/Apache-2.0)
[Python 3.10+](https://www.python.org/downloads/)
[Status: Patent Pending](https://github.com/joseluispino/hardstop#patent-and-statutory-notice)

> **Abstract:** An autonomous generative AI operating in a continuous execution loop without an out-of-band **Epistemic Andon Cord** is an existential operational hazard. *Hard Stop* introduces a dual-plane supervisory control architecture combining out-of-band Discrete Event System (DES) supervision, Synchronous Reactive (SR) sentinels, and sub-millisecond (<0.154 ms) POSIX/eBPF preemption busesβ€”demonstrating deterministic process freezes before off-target socket traffic or unauthorized system calls traverse hypervisor boundaries.

---

## The Core Invariant: Epistemic Self-Referential Invalidation

> **Principle:** A stochastic language model cannot serve as its own deterministic safety arbiter.

Formally, any internal self-evaluating safety loop composed of a probabilistic model $M$ with non-zero error rate $\epsilon &gt; 0$ inherits compounded error probability $P(\text{error}) \ge 1 - (1 - \epsilon)^k$. Deterministic safety guarantees strictly require an **out-of-band supervisory control architecture** operating directly at the runtime, cgroup, and kernel boundaries.

---

## Architectural Overview

```
                         [ Agent Generative Loop ]
                                    β”‚
                            Tool Dispatch Stream
                                    β”‚
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚                 Out-of-Band Epistemic Sentinel Bus                  β”‚
 β”‚  β€’ Egress Domain Meet (D ∩ D_eval = βˆ…)                              β”‚
 β”‚  β€’ Path Traversal & SSTI Lexical/LSM Tripwires                      β”‚
 β”‚  β€’ Execution Surface Boundary Verification                          β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                    β”‚ Invariant Breach (<0.154 ms)
                                    β–Ό
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚               Sub-Millisecond Physical Preemption Bus               β”‚
 β”‚  1. Immediate Non-Cooperative SIGSTOP / Cgroup Freeze (<0.026 ms)   β”‚
 β”‚  2. Out-of-Band Lock-Free Write-Ahead Log (WAL) State Extraction    β”‚
 β”‚  3. Asynchronous LangGraph interrupt() Snapshot (0 Leaked Tokens)   β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
```

---

## Empirical Systems Telemetry

Benchmarks conducted under the **Kalibera & Jones (2013) two-level hierarchical protocol**: E=15 independent OS process launches (fresh ASLR per launch), I=50/3 warmup iterations discarded, M=100/20 measured iterations per process, B=2,000 hierarchical bootstrap resamplings. Statistics are non-parametric medians with 95% CI.

| Evaluation Metric | Unmitigated Baseline | Hard Stop Architecture | Systems Significance |
| --- | --- | --- | --- |
| **Total Actions Executed** | 17,600 (4.5-Day Runaway) | **Preempted at Action 1** | Complete attack surface elimination |
| **AWS IMDS Compromise** | Complete Credential Exfiltration | **Blocked (< 0.026 ms)** | Zero IAM credential exposure |
| **Tailscale Mesh Ingress** | 181 Sandbox Nodes Enrolled | **Blocked (< 0.026 ms)** | Corporate mesh VPN egress prevented |
| **Host Secrets Harvested** | 136 Production Secrets | **0 Secrets Leaked** | Complete air-gap preservation |
| **Tripwire Evaluation (median)** | ∞ (Failed to Halt) | **0.40 ¡s** [95% CI: 0.40, 0.41 ¡s] | Sub-microsecond deterministic check |
| **Tripwire Evaluation (p99)** | ∞ | **0.55 Β΅s** [95% CI: 0.50, 0.62 Β΅s] | Tail latency β‰ͺ 0.100 ms |
| **SIGSTOP Freeze (median)** | N/A | **0.0048 ms** [95% CI: 0.0042, 0.0057 ms] | Non-cooperative process group halt |
| **SIGSTOP Freeze (p99)** | N/A | **0.0171 ms** [95% CI: 0.0128, 0.0252 ms] | 6Γ— within architectural 0.154 ms bound |
| **Compute Idle Overhead** | 100% CPU Runaway | **0 ms CPU Spin** | Durable WAL state serialization |

> **Methodology**: Kalibera, T., & Jones, R. (2013). Rigorous benchmarking in reasonable time. *ISMM '13*. <https://doi.org/10.1145/2464157.2464160>  
> Run `python benchmark_latency.py` to reproduce. Results logged to `benchmark_results.jsonl`.

---

## Quickstart & Verification

Run the empirical benchmark runner and verification suite to reproduce the sub-millisecond preemption timings:

```
# Clone the repository
git clone https://github.com/joseluispino/hardstop.git
cd hardstop

# Install requirements
pip install -r requirements.txt

# 1. Run live sub-millisecond preemption and sentinel latency benchmarks
python benchmark_latency.py

# 2. Run the empirical verification test suite (20 tests, 100% pass rate in <0.25s)
pytest -v test_andon_circuit_breaker.py
```

> **Platform Requirement:** Linux kernel 5.15+ (Ubuntu, Debian, Fedora, Arch) or Windows Subsystem for Linux (WSL2). Physical preemption utilizes Linux process group signalling (`os.killpg`) and POSIX shared-memory WAL verification.

### Verified Test Suites (20 Tests across 8 Suites)

- **Execution Surface Guards**: Validates baseline and custom domain, path, and syscall allowlists.
- **Egress Domain Meet Containment**: Blocks unauthorized external domains and link-local AWS IMDS (`169.254.169.254`) probes.
- **Lexical & SSTI Tripwires**: Intercepts Jinja2 template injection, `/proc/`, `/sys/`, and shadow file traversal sequences.
- **Sandbox Path Traversal**: Canonicalizes paths via `Path.resolve()` to catch directory escape sequences.
- **Command Surface Verification**: Enforces binary allowlists and blocks prohibited tools (`curl`, `nc`, `kubectl`, `tailscale`).
- **Process Group Isolation**: Verifies non-cooperative `SIGSTOP`/`SIGKILL` process tree halts and torn-read WAL recovery.
- **LangGraph Node Integration**: Confirms zero-token-leak state snapshots and durable interrupt handling.
- **WCET Bound Invariant**: Verifies that empirical K&J bootstrap p99 upper confidence limit clears the 0.154 ms bound with 6Γ— margin.

---

## Repository Structure

- `andon_circuit_breaker.py`: Core reference implementation of `PosixProcessSupervisor`, `ExecutionSurfaceGuard`, and `AndonCircuitBreaker`.
- `benchmark_latency.py`: Standalone empirical benchmark measuring sub-millisecond p50/p95/p99 tripwire and preemption latency.
- `test_andon_circuit_breaker.py`: Executable verification testbed (20 unit test assertions across 8 suites).
- `requirements.txt`: Minimal runtime dependencies (`pydantic`, `pytest`).
- `LICENSE`: Apache License, Version 2.0 (with Section 3 Patent Retaliation Protection).

---

## Citation

If you reference this architecture or reference implementation in your research, please cite:

```
@article{pino2026hardstop,
  title={Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution},
  author={Pino, Jos{\'e} Luis},
  journal={arXiv preprint arXiv:2026.XXXXX},
  year={2026}
}
```

---

## Patent and Statutory Notice

Technologies and architectural methods described herein are subject to pending patent applications filed with the United States Patent and Trademark Office (USPTO). *Patent Pending*.

## Author & Contact

**JosΓ© Luis Pino**  
*Independent Researcher* β€” Westlake Village, CA, USA

- **Email**: [email protected]
- **ORCID**: [0009-0005-4854-3914](https://orcid.org/0009-0005-4854-3914)
- **LinkedIn**: [linkedin.com/in/joseluispino](https://www.linkedin.com/in/joseluispino/)
- **X / Twitter**: [@joseluispino](https://x.com/joseluispino)
joseluispino10
🟧 echo.github ⭐Reference implementation for 'Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution' claiming out-of-band sentinel joseluispino (JosΓ© Luis Pino)β€”β€”
🟧 hnShow HN: Hard Stop: Kernel-level preemption for autonomous AI agentsjoseluispino20

Interpretation history

Decision trace