Level-six engineering validation protocol · 04

MuJoCo simulation asset reproducibility and transfer-validation protocol

A sixth-level engineering protocol for turning a robot model that merely loads into a pinned, rebuildable and reviewable simulation evidence baseline—with any physical-transfer claim kept inside measured boundaries.

Evidence statusSimulation evidence protocol · does not establish physical fidelity or robot safetyPrimary sources checked 5 August 2026

Protocol scope

Define what will be evidenced—and what this protocol does not authorise.

For one declared MuJoCo Menagerie model, scene and runtime used to reproduce structural, numerical and behavioural experiments, with a bounded physical comparison only when a matching robot and measured signals exist. It excludes manufacturing release, system safety approval, certification and autonomous deployment.

Configuration baseline

Before motion, freeze the physical system, software environment and operating envelope.

01

Asset, provenance and rights identity

Record

Menagerie commit, exact model directory, XML and mesh checksums, scene file, local changes, upstream source, per-directory README, licence and copyright notices.

Reject when

Do not begin when files, provenance, local edits or applicable licence notices cannot be reconciled.

02

Compiler and runtime identity

Record

MuJoCo release or commit, minimum model version, platform, architecture, dependency lock, loader path, compiler options and clean-environment rebuild instructions.

Reject when

Reject a result that only runs in an unrecorded workstation state.

03

Numerical physics contract

Record

Units, timestep, integrator, solver, iteration and tolerance settings, gravity, contacts, friction, equality constraints, actuator dynamics and sensor definitions.

Reject when

Reject hidden defaults, unit ambiguity or a time-step and solver combination that has not been declared and stress-tested.

04

Experiment and claim contract

Record

Scene, controller, initial state, random seeds, perturbation distribution, run count, logged signals, comparison metric, tolerance and the exact claim being tested.

Reject when

Do not accept a replay whose success rule or comparison window was chosen after results were seen.

Staged verification

Open only one new energy, motion or autonomy envelope at a time.

  1. 01 · Rights and immutable asset identity

    Advancement needs evidence; stopping needs an owner.
    Method

    Freeze the upstream commit and exact asset subset; inventory XML, meshes, textures and support files; record modifications separately; preserve the notices that apply to the selected model.

    Evidence to preserve

    Source manifest, file tree, checksums, modification patch and licence-notice bundle.

    Advance when

    A reviewer can resolve every loaded file to an immutable source or declared local change.

    Stop immediately

    Missing source files, unexplained binary assets, incompatible notices or unrecorded substitutions.

  2. 02 · Clean-room load and dependency closure

    Advancement needs evidence; stopping needs an owner.
    Method

    Build the declared environment from scratch, load and compile the model and scene, capture warnings, then repeat on a second clean runner where practicable.

    Evidence to preserve

    Dependency lock, build log, compiler output, warnings register and machine-readable environment report.

    Advance when

    The exact asset loads without undeclared files, unresolved warnings or manual workstation fixes.

    Stop immediately

    A missing dependency, silent asset fallback, version-sensitive failure or manual edit that is absent from the record.

  3. 03 · Structural, unit and static review

    Advancement needs evidence; stopping needs an owner.
    Method

    Inspect body and joint trees, frames, limits, inertials, masses, collision geometry, contacts, actuator and sensor maps, then run declared static-pose and gravity checks.

    Evidence to preserve

    Compiled structural report, unit table, parameter dictionary, annotated frame map and exception register.

    Advance when

    Every material parameter has a unit, meaning and provenance; static checks match the declared model intent.

    Stop immediately

    Impossible inertia, inverted axes, undeclared scaling, interpenetration, missing collision coverage or actuator/sensor mismatch.

  4. 04 · Numerical sensitivity and stability

    Advancement needs evidence; stopping needs an owner.
    Method

    Run the declared experiment while perturbing timestep, integrator, solver, iterations, tolerances and contact parameters inside a predeclared diagnostic matrix.

    Evidence to preserve

    Sensitivity matrix, solver statistics, energy and constraint traces, divergence cases and retained failure logs.

    Advance when

    The result remains inside its declared tolerance or its sensitivity is explicitly bounded and explained.

    Stop immediately

    Unexplained instability, materially different conclusions under reasonable settings, concealed warnings or cherry-picked stable runs.

  5. 05 · Deterministic and statistical replay

    Advancement needs evidence; stopping needs an owner.
    Method

    Replay fixed-state, fixed-seed golden runs, then repeat the declared seed and perturbation distribution; compare raw traces and outcome distributions against frozen tolerances.

    Evidence to preserve

    Golden traces, replay hashes, seed manifest, run matrix, outcome distribution and all failed replays.

    Advance when

    A second operator reproduces the stated result without changing code, thresholds or the trial distribution.

    Stop immediately

    Post-hoc threshold changes, missing seeds, nondeterminism without a statistical account or failure runs removed from the package.

  6. 06 · Bounded physical-transfer comparison

    Advancement needs evidence; stopping needs an owner.
    Method

    Only when a matching physical system exists, replay a guarded low-energy task and compare predeclared observables such as joint states, contact timing, currents or task outcomes; model residuals rather than hiding them.

    Evidence to preserve

    Robot configuration identity, calibrated sensor records, time-aligned simulation/physical traces, residual analysis, interventions and unresolved mismatch register.

    Advance when

    Transfer evidence is stated only for the measured observables, configuration, task, environment and tolerance.

    Stop immediately

    Unsafe motion, unmatched hardware, unsynchronised data, uncalibrated sensors or an attempt to infer safety from simulation agreement.

Acceptance claims

Every conclusion carries both a measurement and an applicability boundary.

01

The asset is rebuildable

How it is measured

A clean environment retrieves the pinned sources and compiles the exact model without undeclared intervention.

Claim boundary

Rebuildability does not establish correctness, quality or permission for every downstream use.

02

The model is structurally reviewable

How it is measured

A reviewer can trace units, frames, inertials, collision, actuator and sensor parameters to declared sources or assumptions.

Claim boundary

A complete parameter table is not proof of physical identification.

03

The experiment is replayable

How it is measured

A second operator reproduces frozen traces or distributions inside predeclared numerical tolerances.

Claim boundary

A reproducible simulation can still reproduce the same modeling error.

04

Any transfer statement is bounded

How it is measured

The report names the exact physical configuration, measured observables, residuals, environment and expiry or retest trigger.

Claim boundary

Agreement on selected observables is not a general digital-twin, safety or deployment claim.

Evidence pack & boundaries

Enable the next engineer to review, reproduce, reject or approve the next step.

Minimum evidence pack

  • Pinned source, licence-notice and checksum manifest
  • Runtime, compiler and dependency lock with clean-build logs
  • Compiled structure, units, frames and parameter-provenance report
  • Golden, sensitivity and perturbation traces including failures
  • Physical-comparison traces and residual report when applicable
  • Decision, known unknowns, validity boundary and retest triggers

This protocol cannot replace

  • Not manufacturing drawings, a BOM or production release
  • Not proof of system identification, universal physical fidelity or a complete digital twin
  • Not a robot safety case, certification or compliance conclusion
  • Not a legal determination that every bundled or upstream asset is cleared for a proposed use

FUURAA analysis

The reusable product is decision evidence—not one successful demonstration.

A model loading successfully—or producing a persuasive video—is only an entry condition. Credible simulation evidence requires an immutable asset identity, an explicit numerical contract, replayable traces, sensitivity testing and, where physical transfer is claimed, visible residuals tied to one measured system. FUURAA therefore treats simulation as a bounded evidence instrument, not a shortcut to physical truth.

Primary sources

The protocol starts with primary sources; every physical adoption still requires fresh validation.

Google DeepMind · MuJoCo MenageriePrimary curated model collection, directory structure, minimum-version, provenance and per-model licence guidanceRepository created 5 September 2022; active collection checked 5 August 2026MuJoCo · Modeling guidePrimary semantics for model compilation, defaults, coordinates, solver options and timestep-dependent stabilityLiving documentation for MuJoCo 3.11.0, released 28 July 2026; checked 5 August 2026MuJoCo · XML referencePrimary MJCF elements, attributes, defaults, units, contacts, actuators and sensorsLiving documentation for MuJoCo 3.11.0, released 28 July 2026; checked 5 August 2026MuJoCo · ComputationPrimary numerical pipeline, dynamics, constraint and integration referenceLiving documentation for MuJoCo 3.11.0, released 28 July 2026; checked 5 August 2026
Return to the related level-five technical dossier →