feat(ruview-unified): Unified RF spatial world model — ADR-273..282: native frame contract, encoder, Gaussian memory, synthetic worlds, programmable perception - #1437
Conversation
One shared representation instead of another isolated RF classifier: new v2 leaf crate ruview-unified implementing all five ADR-273 pillars, plus six ADRs with measured, grade-labeled results. - Canonical RfTensor + fail-closed hardware adapter registry (802.11 CSI via wifi-densepose-core::CsiFrame, FMCW radar cubes, UWB CIR, 5G SRS); shared layout/gain/phase normalization proven by tests (ADR-274). - Universal RF foundation encoder: CFO-aligned, median-scaled tokenizer; masked-reconstruction pretraining with hand-derived backprop verified against central finite differences (max rel err 1.31e-5 over all 12 parameter groups); fusion contract z = Enc ⊙ σ(AgeEnc) + GeomEnc; task adapters under the 1% budget (129/268/387/2 params vs 40,856 backbone), enforced by test. - RF-aware Gaussian spatial memory: anisotropic primitives with per-band reflectivity, confidence-weighted fusion, decay, spatial-hash/semantic queries, closed-form Beer-Lambert channel gain (exact Friis on empty map), inverse gain updates (unseen 6.1 dB wall learned to <0.5 dB in 20 observations), task-gated scene graph (ADR-275). - Physics-guided synthetic RF worlds: image-method multipath (order ≤2), complex-permittivity Fresnel materials, emergent Doppler proven against the analytic phase rate, seeded ChaCha20 randomization of physics and hardware nuisances; byte-deterministic per seed (ADR-276). - Edge sensing control plane: 802.11bf/ETSI-ISAC-aligned purposes/zones, fail-closed authorization, double-gated identity, retention bounds; BoundedEvent-only trust boundary makes raw RF export unrepresentable (ADR-277). Radar inverse rendering stays a gated research program (ADR-278, no code by design). Anti-leakage acceptance pipeline (strict splits by room/day/person/ chipset/firmware/layout with independent disjointness verification): presence F1 1.00 on held-out rooms and held-out chipset, degradation 0.0, ECE 0.012, p95 latency 2.0 ms debug / 105 µs release — ALL SYNTHETIC until P2 real-data validation. Benchmarks + optimization pass: channel_gain 139→27 µs (O(1) in map size via segment-corridor AABB sweep), observe_link 305→74 µs, DFT twiddle plan 4.9x; hash/linear crossover (~4k Gaussians) reported honestly. Tests: ruview-unified 66 unit + 3 acceptance, 0 failed; workspace 3,771 passed 0 failed (--exclude wifi-densepose-desktop: GTK headers unavailable in this container). Python proof: VERDICT PASS. Also gitignore sensing-server test-run artifacts (incl. generated session-secret). Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
… (ADR-279..282) Second increment of the unified RF spatial world model, applying the architectural correction that the 56-bin canonical tensor must not be the authoritative format, and moving the control plane from passive sensing to programmable perception. - RfFrameV2 (ADR-279): authoritative native RF record — native complex IQ preserved (proven byte-untouched by the derived view), explicit validity masks, declared PhaseState, TX/RX poses + antenna geometry, calibration/quality state, and construction-time provenance rules: Synthetic ⇒ L0Simulation, Measured ⇒ ≥ L1CapturedReplay (the L0–L5 evidence ladder is now a type). Canonical tensor demoted to a mask-aware derived view through the shared adapter normalization. New modalities: WifiCir, WifiBfReport, FmcwRangeAzimuth, FmcwDopplerAzimuth. IEEE P3162 synthetic-aperture import profile. - Active sensing control plane (ADR-280, control.rs): SensingTask admission (raw export always refused; identity requires consent), SensingAction/InformationGoal, age-of-information planner with measured 95% sensing-traffic reduction vs uniform refresh, fail-closed CoherentSensorGroup fusion (time/phase/geometry bounds, five denial paths tested), policy-authorized RIS actuation receipts, purpose-scoped TaskSufficientRepresentation leakage validation. - BLE Channel Sounding (ADR-281): adapter + ble_cs_range with phase-slope and RTT as separate cross-validated evidence — exact recovery on synthetic tones, relay-style divergence flagged instead of averaged. Delay-Doppler-native FieldAxis + delay_doppler_map (unit-peak tone test). - Factorized pose (ADR-281, RePos): relative skeleton on the content representation, root on the geometry-conditioned one, calibrated per-joint uncertainties; room-shortcut leakage experiment: held-out MPJPE 0.0003 m vs 0.2534 m monolithic; 740 params (<2% structured budget). Age gate input now log(1+age_ms); gradient check re-proven. - Gaussian primitives: first_seen_ns, doppler_variance, bounded source_receipts lineage merged on fusion. PartitionKey gains a session dimension; SplitManifest certifies disjointness across all seven leakage dimensions. - ADR-282: ecosystem positioning — RuView as the edge RF perception runtime under RuField/RuVector/MetaHarness; evidence-ladder policy. Validation: ruview-unified 84 unit + 3 acceptance tests, 0 failed, clippy-clean; workspace 3,789 passed 0 failed (--exclude wifi-densepose-desktop, GTK headers unavailable in container); Python proof VERDICT PASS. Docker images unaffected: no shipped binary consumes this crate yet (Dockerfile.rust builds sensing-server / cog-ha-matter / homecore-server only; Dockerfile.python builds untouched archive/v1). Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
…Doppler, property-tested boundary hardening
Third increment: closes the remaining implementable ADR-275 update-loop
steps, optimizes the delay-Doppler transform, and hardens every boundary
surface with property testing that found and fixed three real
input-controlled defects.
- ADR-275 update loop: GaussianMap::merge_overlapping (step 5 — mutual
Mahalanobis + semantic-compatibility dedup catching drift the
insert-time ±1-cell gate misses; orthogonal semantics stay separate)
and lifetime-aware decay (step 7 — tau_eff = tau*(1+ln(1+lifetime/tau))
so confirmed structures outlive transients at equal nominal tau).
- Separable delay-Doppler (ADR-281): O(B^2*S + S^2*B) instead of
O(B^2*S^2), proven equivalent to the direct reference to <1e-10 and
measured 8.3x faster (520us vs 4.34ms at 56x8). Direct form kept as
the benchmark baseline + equivalence oracle.
- Security property tests (tests/security_boundaries.rs, 8 proptest
properties over arbitrary values incl. NaN/inf via f64::from_bits).
Found and fixed:
* ble_cs_range unwrap infinite loop on non-finite phase (+inf) and
~1e299-iteration loop on finite-huge phase -> O(1) modular unwrap +
plausibility bound (|phase| <= 1e6 rad);
* subnormal Gaussian scale (5e-324) overflowing 1/sigma^2 to NaN
density -> physical bounds (sigma in [1e-6, 1e4] m, occupancy in
[0, 1e6] nepers/m).
Properties proven: tensor/Gaussian/BoundedEvent constructors never
panic; policy engine fail-closed for every (purpose,grants,zone);
raw export structurally unreachable; coherent fusion rejects every
non-finite/out-of-bounds sync state; occupancy reps never retain
identity.
- New criterion benches for all increment-2/3 hot paths (to_canonical
38us, ble_cs_range 481ns, AoI planner 647ns/200 regions, coherent
fusion 1.5us/32 members, factorized pose 521ns, delay-Doppler
separable vs direct).
Validation: ruview-unified 98 tests (87 lib + 3 acceptance + 8
security), 0 failed, clippy-clean; Python proof VERDICT PASS. Witness
bundle regeneration still blocked on the desktop/Tauri crate's GTK dev
headers (unavailable in this container) — pre-existing environment
limitation, flagged for the release owner.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
…rong center-freq found in review Deep review of PR #1437 (ADR-273..282 unified RF spatial world model) plus hardware-in-the-loop testing against a live ESP32-C6 CSI node turned up several real defects, fixed here: - pretrain.rs: sample_mask panicked (usize::clamp(1, 0)) on any single-token window, reachable from a valid RfTensor via a perfectly normal tokenizer output. eval() now skips empty masks instead of averaging in NaN. - math.rs: resample_complex(x, 1) with x.len() > 1 divided by zero (m - 1 == 0), silently poisoning the output with NaN. Now returns the mean. - gaussian/map.rs: merge_overlapping had no entity-kind guard (unlike insert()), so an unlabeled Room-linked Gaussian and an unlabeled PersonClass-linked Gaussian within each other's merge gate would be silently conflated. Added the same same_kind check insert() uses. Also hardened decay()'s tau_eff against a post-construction decay_tau_s of 0 (NaN instead of merely-fast decay). - adapters.rs: WifiCsiAdapter used the frequency band's fixed per-band constant (e.g. 2437 MHz) instead of the frame's real channel, misreporting center_freq_hz for every channel except the one that happens to match the constant. Confirmed against a live ESP32-C6 node on channel 4: pre-fix would report 2437000000 Hz, post-fix correctly reports 2427000000 Hz, matching the hardware parser's independently-computed frequency exactly. Added examples/esp32_live_hardware_test.rs, a hardware-in-the-loop test that bridges real ADR-018 UDP captures through the adapter (also confirms no panic on real 256-subcarrier HE-SU frames, well beyond CANONICAL_BINS=56). - control.rs: admit_task didn't validate requested_resolution_m, maximum_latency_ms, or modalities, so a task with 0/NaN resolution, 0ms latency, or zero modalities passed admission. Added boundary checks. - control.rs + security_boundaries.rs: validate_representation's only test coverage (unit test and proptest) hardcoded SensingPurpose::Presence, leaving the other three purpose-ceiling branches (Activity/Localization at P3, Vitals/PoseTracking at P4, IdentityRecognition at P5 — the higher-risk representations) completely unverified. Added coverage for all branches in both. Also fixed pre-existing issues surfaced while validating the above: - wifi-densepose-core: 7 clippy warnings (cast_possible_truncation/ wrap, single_match_else, suboptimal_flops) in the canonical encode/decode path, now using try_from/from_le_bytes/mul_add. - wifi-densepose-hardware: a test missing #[cfg(unix)] that used std::os::unix::fs::PermissionsExt unconditionally, breaking Windows builds of ruview-auth's test suite; a manual Default impl clippy flagged as derivable; two tests using field-reassignment instead of struct-update syntax after ::default(). - wifi-densepose-sensing-server: auth_wiring.rs's free_port() / child-process bind race (documented as "mildly racy" by design) now retries up to 3x specifically on an AddrInUse-shaped failure, preserving the original fail-loud behavior for genuine wiring regressions. All touched crates re-verified: ruview-unified 99 tests (was 98), wifi-densepose-core 37+40, wifi-densepose-hardware 483+1(ignored), ruview-auth builds and tests on Windows, sensing-server auth_wiring 7/7. ruview-unified remains clippy-clean under -D warnings; the pre-existing dependency warnings that -D warnings surfaced are fixed too. Co-Authored-By: claude-flow <ruv@ruv.net>
Deep review + hardware-in-the-loop testReviewed Fixed in
Also fixed pre-existing issues surfaced while validating (unrelated to this PR's diff): 7 clippy warnings in All touched crates re-verified post-fix: A few of the PR's headline "MEASURED" numbers are narrower than they read (detailed in the gist) — worth a look before citing them elsewhere, though none are code bugs: the RePos leakage-resistance test never exercises the actual encoder, the "empty map ⇒ exact Friis" test never invokes the erf path it's named for, and the "6.1 dB obstruction learned in 20 observations" is 20 repeats of one measurement converging a single scalar. |
Summary
Implements the unified RF spatial world model (ADR-273): one shared representation where WiFi CSI, cellular SRS, FMCW radar, UWB CIR, BLE Channel Sounding, geometry, semantics, uncertainty, and time all update the same persistent scene memory — instead of another isolated RF classifier. Ten ADRs (273–282) plus a new pure-Rust v2 workspace crate
ruview-unified, delivered in three commits.Commit 1 — P1 pillars (ADR-273..278)
RfTensor; fail-closedAdapterRegistry(802.11 CSI viawifi-densepose-core::CsiFrame, FMCW cubes, UWB CIR, 5G SRS); tokenizer with measured hardware invariance (window-median scaling + CFO alignment); fusion contractz = Encoder(tokens) ⊙ σ(AgeEncoder(age)) + GeometryEncoder(pose); masked-reconstruction pretraining with a hand-derived backward pass verified against central finite differences (174 params, max rel err 1.31e-5); scalar adapters under a 1 % budget (129/268/387/2 vs 40,856 backbone).BoundedEventthe only exportable type — raw RF export unrepresentable.Commit 2 — native contract + programmable perception (ADR-279..282)
RfFrameV2(ADR-279): the architectural correction — canonical tensor demoted to a derived view; authoritative record preserves native complex IQ (proven byte-untouched), validity masks, declaredPhaseState, poses, and construction-enforced provenance:Synthetic ⇒ L0,Measured ⇒ ≥ L1(the L0–L5 evidence ladder is a type).SplitManifestcertifies disjointness across all seven leakage dimensions incl. session.SensingTaskadmission (raw export refused; identity needs consent); age-of-information planner with measured 95 % traffic reduction; fail-closed coherent-aperture fusion; policy-authorized RIS actuation receipts; purpose-scopedTaskSufficientRepresentationleakage validation.FieldAxis+delay_doppler_map. IEEE P3162 import profile.Commit 3 — update-loop completion, optimization, boundary hardening
merge_overlapping(mutual-Mahalanobis + semantic dedup) and lifetime-aware decay (τ_eff = τ·(1+ln(1+lifetime/τ))— confirmed structures outlive transients).O(B²S+S²B)vsO(B²S²), equivalence-proven to <1e-10, measured 8.3× faster (520 µs vs 4.34 ms).tests/security_boundaries.rs, 8 proptest properties over NaN/±inf inputs) — found & fixed three input-controlled defects: BLE-CS unwrap infinite loop on non-finite phase + ~1e299-iteration loop on finite-huge phase (→ O(1) modular unwrap + plausibility bound), and a subnormal Gaussian scale → NaN density (→ physical σ/occupancy bounds). Proven: constructors never panic, policy fail-closed, raw export unreachable, fusion rejects non-finite sync, occupancy reps never retain identity.Measured results (all SYNTHETIC / L0 — honest labeling is structural)
Benchmarks + optimization (criterion, release):
channel_gain139→27 µs;observe_link305→74 µs; delay-Doppler 4.34 ms→520 µs (8.3×); DFT plan 4.9×;to_canonical38 µs,ble_cs_range481 ns, AoI planner 647 ns, coherent fusion 1.5 µs, factorized pose 521 ns. Hash/linear crossover (~4k Gaussians) and one discarded-as-worse corridor attempt reported honestly (ADR-275 §6).Validation
cargo test -p ruview-unified— 98 tests (87 lib + 3 acceptance + 8 security), 0 failed; crate clippy-cleancargo test --workspace --no-default-features --exclude wifi-densepose-desktop— green (1805+ observed; desktop/Tauri crate cannot build here: GTK dev headers absent — pre-existing environment limitation, run unexcluded in CI)python archive/v1/data/proof/verify.py— VERDICT: PASSdocs/adr/README.mdindex, CHANGELOG[Unreleased];.gitignoreexcludes proptest regression cachesWhat this is NOT / what remains (hardware- and data-gated)
.csi.jsonlreplay + measured-data strict splits (ADR-273 §7) — needs captured data.GaussianMapinto the live sensing server behind the ADR-277 boundary; P4 = O-RAN SRS xApp (adapter seam ships here) — need the testbeds.🤖 Generated with claude-flow
https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX