Skip to content

feat(ruview-unified): Unified RF spatial world model — ADR-273..282: native frame contract, encoder, Gaussian memory, synthetic worlds, programmable perception - #1437

Merged
ruvnet merged 4 commits into
mainfrom
claude/unified-rf-spatial-model-vdf6n8
Jul 26, 2026
Merged

Conversation

@ruvnet

@ruvnet ruvnet commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Summary

Implements the unified RF spatial world model (ADR-273): one shared representation where WiFi CSI, cellular SRS, FMCW radar, UWB CIR, BLE Channel Sounding, geometry, semantics, uncertainty, and time all update the same persistent scene memory — instead of another isolated RF classifier. Ten ADRs (273–282) plus a new pure-Rust v2 workspace crate ruview-unified, delivered in three commits.

Commit 1 — P1 pillars (ADR-273..278)

  • Universal RF encoder + adapter registry (ADR-274): canonical RfTensor; fail-closed AdapterRegistry (802.11 CSI via wifi-densepose-core::CsiFrame, FMCW cubes, UWB CIR, 5G SRS); tokenizer with measured hardware invariance (window-median scaling + CFO alignment); fusion contract z = Encoder(tokens) ⊙ σ(AgeEncoder(age)) + GeometryEncoder(pose); masked-reconstruction pretraining with a hand-derived backward pass verified against central finite differences (174 params, max rel err 1.31e-5); scalar adapters under a 1 % budget (129/268/387/2 vs 40,856 backbone).
  • RF-aware Gaussian spatial memory (ADR-275): anisotropic primitives w/ per-band×angle reflectivity; confidence-weighted fusion, decay, spatial-hash/semantic queries; channel gain as a query (closed-form erf Beer–Lambert; empty map ⇒ exact Friis <1e-15); inverse updates learning an unseen 6.1 dB obstruction to <0.5 dB in 20 observations; task-gated scene graph.
  • Physics-guided synthetic RF worlds (ADR-276): Allen–Berkley image method (order ≤2), Fresnel materials, emergent Doppler vs analytic phase rate; reciprocity <1e-12; per-seed byte determinism; physics + hardware-nuisance randomization.
  • Edge sensing control plane (ADR-277): 802.11bf/ETSI-ISAC zones/purposes, fail-closed auth, double-gated identity; BoundedEvent the only exportable type — raw RF export unrepresentable.
  • Radar inverse rendering (ADR-278): ADR-only gated RISE → DiffRadar → GeRaF reproduction program.

Commit 2 — native contract + programmable perception (ADR-279..282)

  • RfFrameV2 (ADR-279): the architectural correction — canonical tensor demoted to a derived view; authoritative record preserves native complex IQ (proven byte-untouched), validity masks, declared PhaseState, poses, and construction-enforced provenance: Synthetic ⇒ L0, Measured ⇒ ≥ L1 (the L0–L5 evidence ladder is a type). SplitManifest certifies disjointness across all seven leakage dimensions incl. session.
  • Active sensing control plane (ADR-280): SensingTask admission (raw export refused; identity needs consent); age-of-information planner with measured 95 % traffic reduction; fail-closed coherent-aperture fusion; policy-authorized RIS actuation receipts; purpose-scoped TaskSufficientRepresentation leakage validation.
  • BLE Channel Sounding (ADR-281): phase-slope vs RTT as separate cross-validated evidence — exact synthetic recovery, relay-style divergence flagged not averaged. Delay-Doppler-native FieldAxis + delay_doppler_map. IEEE P3162 import profile.
  • Factorized pose (ADR-281, RePos): relative skeleton on the content rep, root on the geometry-conditioned rep, calibrated uncertainties. Room-shortcut leakage experiment: held-out MPJPE 0.0003 m vs 0.2534 m monolithic. <2 % structured budget.
  • Ecosystem positioning (ADR-282): RuView = edge RF perception runtime under RuField/RuVector/MetaHarness; evidence-ladder policy.

Commit 3 — update-loop completion, optimization, boundary hardening

  • ADR-275 update loop closed: merge_overlapping (mutual-Mahalanobis + semantic dedup) and lifetime-aware decay (τ_eff = τ·(1+ln(1+lifetime/τ)) — confirmed structures outlive transients).
  • Separable delay-Doppler: O(B²S+S²B) vs O(B²S²), equivalence-proven to <1e-10, measured 8.3× faster (520 µs vs 4.34 ms).
  • Security property tests (tests/security_boundaries.rs, 8 proptest properties over NaN/±inf inputs) — found & fixed three input-controlled defects: BLE-CS unwrap infinite loop on non-finite phase + ~1e299-iteration loop on finite-huge phase (→ O(1) modular unwrap + plausibility bound), and a subnormal Gaussian scale → NaN density (→ physical σ/occupancy bounds). Proven: constructors never panic, policy fail-closed, raw export unreachable, fusion rejects non-finite sync, occupancy reps never retain identity.

Measured results (all SYNTHETIC / L0 — honest labeling is structural)

Gate Result
Presence F1, held-out rooms / chipset 1.0000 / 1.0000
Known→unknown degradation 0.0000 (<0.20)
Held-out ECE 0.0122
p95 tokenize+encode latency 2.0 ms debug / 105 µs release (<50 ms)
Pose leakage (held-out MPJPE) factorized 0.0003 m vs 0.2534 m monolithic
AoI planner traffic reduction 95 % vs uniform
BLE CS ranging exact recovery; relay divergence flagged

Benchmarks + optimization (criterion, release): channel_gain 139→27 µs; observe_link 305→74 µs; delay-Doppler 4.34 ms→520 µs (8.3×); DFT plan 4.9×; to_canonical 38 µs, ble_cs_range 481 ns, AoI planner 647 ns, coherent fusion 1.5 µs, factorized pose 521 ns. Hash/linear crossover (~4k Gaussians) and one discarded-as-worse corridor attempt reported honestly (ADR-275 §6).

Validation

  • cargo test -p ruview-unified98 tests (87 lib + 3 acceptance + 8 security), 0 failed; crate clippy-clean
  • cargo test --workspace --no-default-features --exclude wifi-densepose-desktopgreen (1805+ observed; desktop/Tauri crate cannot build here: GTK dev headers absent — pre-existing environment limitation, run unexcluded in CI)
  • python archive/v1/data/proof/verify.pyVERDICT: PASS
  • Docs: CLAUDE.md, README + docs/adr/README.md index, CHANGELOG [Unreleased]; .gitignore excludes proptest regression caches

What this is NOT / what remains (hardware- and data-gated)

  • No real-world accuracy claim: every number is generator-produced (L0). P2 = real .csi.jsonl replay + measured-data strict splits (ADR-273 §7) — needs captured data.
  • P3 = wire GaussianMap into the live sensing server behind the ADR-277 boundary; P4 = O-RAN SRS xApp (adapter seam ships here) — need the testbeds.
  • ADR-278 radar inverse rendering stays a gated research program (needs mmWave hardware + reproduction).
  • Witness-bundle regeneration blocked on the desktop crate's GTK headers in this container — flagged for the release owner (CI with GTK regenerates it).

🤖 Generated with claude-flow

https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX

claude and others added 2 commits July 26, 2026 19:03
One shared representation instead of another isolated RF classifier: new
v2 leaf crate ruview-unified implementing all five ADR-273 pillars, plus
six ADRs with measured, grade-labeled results.

- Canonical RfTensor + fail-closed hardware adapter registry (802.11 CSI
  via wifi-densepose-core::CsiFrame, FMCW radar cubes, UWB CIR, 5G SRS);
  shared layout/gain/phase normalization proven by tests (ADR-274).
- Universal RF foundation encoder: CFO-aligned, median-scaled tokenizer;
  masked-reconstruction pretraining with hand-derived backprop verified
  against central finite differences (max rel err 1.31e-5 over all 12
  parameter groups); fusion contract z = Enc ⊙ σ(AgeEnc) + GeomEnc;
  task adapters under the 1% budget (129/268/387/2 params vs 40,856
  backbone), enforced by test.
- RF-aware Gaussian spatial memory: anisotropic primitives with per-band
  reflectivity, confidence-weighted fusion, decay, spatial-hash/semantic
  queries, closed-form Beer-Lambert channel gain (exact Friis on empty
  map), inverse gain updates (unseen 6.1 dB wall learned to <0.5 dB in
  20 observations), task-gated scene graph (ADR-275).
- Physics-guided synthetic RF worlds: image-method multipath (order ≤2),
  complex-permittivity Fresnel materials, emergent Doppler proven against
  the analytic phase rate, seeded ChaCha20 randomization of physics and
  hardware nuisances; byte-deterministic per seed (ADR-276).
- Edge sensing control plane: 802.11bf/ETSI-ISAC-aligned purposes/zones,
  fail-closed authorization, double-gated identity, retention bounds;
  BoundedEvent-only trust boundary makes raw RF export unrepresentable
  (ADR-277). Radar inverse rendering stays a gated research program
  (ADR-278, no code by design).

Anti-leakage acceptance pipeline (strict splits by room/day/person/
chipset/firmware/layout with independent disjointness verification):
presence F1 1.00 on held-out rooms and held-out chipset, degradation
0.0, ECE 0.012, p95 latency 2.0 ms debug / 105 µs release — ALL
SYNTHETIC until P2 real-data validation.

Benchmarks + optimization pass: channel_gain 139→27 µs (O(1) in map
size via segment-corridor AABB sweep), observe_link 305→74 µs, DFT
twiddle plan 4.9x; hash/linear crossover (~4k Gaussians) reported
honestly.

Tests: ruview-unified 66 unit + 3 acceptance, 0 failed; workspace
3,771 passed 0 failed (--exclude wifi-densepose-desktop: GTK headers
unavailable in this container). Python proof: VERDICT PASS. Also
gitignore sensing-server test-run artifacts (incl. generated
session-secret).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
… (ADR-279..282)

Second increment of the unified RF spatial world model, applying the
architectural correction that the 56-bin canonical tensor must not be
the authoritative format, and moving the control plane from passive
sensing to programmable perception.

- RfFrameV2 (ADR-279): authoritative native RF record — native complex
  IQ preserved (proven byte-untouched by the derived view), explicit
  validity masks, declared PhaseState, TX/RX poses + antenna geometry,
  calibration/quality state, and construction-time provenance rules:
  Synthetic ⇒ L0Simulation, Measured ⇒ ≥ L1CapturedReplay (the L0–L5
  evidence ladder is now a type). Canonical tensor demoted to a
  mask-aware derived view through the shared adapter normalization.
  New modalities: WifiCir, WifiBfReport, FmcwRangeAzimuth,
  FmcwDopplerAzimuth. IEEE P3162 synthetic-aperture import profile.
- Active sensing control plane (ADR-280, control.rs): SensingTask
  admission (raw export always refused; identity requires consent),
  SensingAction/InformationGoal, age-of-information planner with
  measured 95% sensing-traffic reduction vs uniform refresh,
  fail-closed CoherentSensorGroup fusion (time/phase/geometry bounds,
  five denial paths tested), policy-authorized RIS actuation receipts,
  purpose-scoped TaskSufficientRepresentation leakage validation.
- BLE Channel Sounding (ADR-281): adapter + ble_cs_range with
  phase-slope and RTT as separate cross-validated evidence — exact
  recovery on synthetic tones, relay-style divergence flagged instead
  of averaged. Delay-Doppler-native FieldAxis + delay_doppler_map
  (unit-peak tone test).
- Factorized pose (ADR-281, RePos): relative skeleton on the content
  representation, root on the geometry-conditioned one, calibrated
  per-joint uncertainties; room-shortcut leakage experiment: held-out
  MPJPE 0.0003 m vs 0.2534 m monolithic; 740 params (<2% structured
  budget). Age gate input now log(1+age_ms); gradient check re-proven.
- Gaussian primitives: first_seen_ns, doppler_variance, bounded
  source_receipts lineage merged on fusion. PartitionKey gains a
  session dimension; SplitManifest certifies disjointness across all
  seven leakage dimensions.
- ADR-282: ecosystem positioning — RuView as the edge RF perception
  runtime under RuField/RuVector/MetaHarness; evidence-ladder policy.

Validation: ruview-unified 84 unit + 3 acceptance tests, 0 failed,
clippy-clean; workspace 3,789 passed 0 failed (--exclude
wifi-densepose-desktop, GTK headers unavailable in container); Python
proof VERDICT PASS. Docker images unaffected: no shipped binary
consumes this crate yet (Dockerfile.rust builds sensing-server /
cog-ha-matter / homecore-server only; Dockerfile.python builds
untouched archive/v1).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
@ruvnet ruvnet changed the title feat(ruview-unified): Unified RF spatial world model P1 — ADR-273..278, encoder + Gaussian memory + synthetic worlds + sensing policy feat(ruview-unified): Unified RF spatial world model — ADR-273..282: native frame contract, encoder, Gaussian memory, synthetic worlds, programmable perception Jul 26, 2026
claude and others added 2 commits July 26, 2026 20:29
…Doppler, property-tested boundary hardening

Third increment: closes the remaining implementable ADR-275 update-loop
steps, optimizes the delay-Doppler transform, and hardens every boundary
surface with property testing that found and fixed three real
input-controlled defects.

- ADR-275 update loop: GaussianMap::merge_overlapping (step 5 — mutual
  Mahalanobis + semantic-compatibility dedup catching drift the
  insert-time ±1-cell gate misses; orthogonal semantics stay separate)
  and lifetime-aware decay (step 7 — tau_eff = tau*(1+ln(1+lifetime/tau))
  so confirmed structures outlive transients at equal nominal tau).
- Separable delay-Doppler (ADR-281): O(B^2*S + S^2*B) instead of
  O(B^2*S^2), proven equivalent to the direct reference to <1e-10 and
  measured 8.3x faster (520us vs 4.34ms at 56x8). Direct form kept as
  the benchmark baseline + equivalence oracle.
- Security property tests (tests/security_boundaries.rs, 8 proptest
  properties over arbitrary values incl. NaN/inf via f64::from_bits).
  Found and fixed:
  * ble_cs_range unwrap infinite loop on non-finite phase (+inf) and
    ~1e299-iteration loop on finite-huge phase -> O(1) modular unwrap +
    plausibility bound (|phase| <= 1e6 rad);
  * subnormal Gaussian scale (5e-324) overflowing 1/sigma^2 to NaN
    density -> physical bounds (sigma in [1e-6, 1e4] m, occupancy in
    [0, 1e6] nepers/m).
  Properties proven: tensor/Gaussian/BoundedEvent constructors never
  panic; policy engine fail-closed for every (purpose,grants,zone);
  raw export structurally unreachable; coherent fusion rejects every
  non-finite/out-of-bounds sync state; occupancy reps never retain
  identity.
- New criterion benches for all increment-2/3 hot paths (to_canonical
  38us, ble_cs_range 481ns, AoI planner 647ns/200 regions, coherent
  fusion 1.5us/32 members, factorized pose 521ns, delay-Doppler
  separable vs direct).

Validation: ruview-unified 98 tests (87 lib + 3 acceptance + 8
security), 0 failed, clippy-clean; Python proof VERDICT PASS. Witness
bundle regeneration still blocked on the desktop/Tauri crate's GTK dev
headers (unavailable in this container) — pre-existing environment
limitation, flagged for the release owner.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
…rong center-freq found in review

Deep review of PR #1437 (ADR-273..282 unified RF spatial world model)
plus hardware-in-the-loop testing against a live ESP32-C6 CSI node
turned up several real defects, fixed here:

- pretrain.rs: sample_mask panicked (usize::clamp(1, 0)) on any
  single-token window, reachable from a valid RfTensor via a perfectly
  normal tokenizer output. eval() now skips empty masks instead of
  averaging in NaN.
- math.rs: resample_complex(x, 1) with x.len() > 1 divided by zero
  (m - 1 == 0), silently poisoning the output with NaN. Now returns
  the mean.
- gaussian/map.rs: merge_overlapping had no entity-kind guard (unlike
  insert()), so an unlabeled Room-linked Gaussian and an unlabeled
  PersonClass-linked Gaussian within each other's merge gate would be
  silently conflated. Added the same same_kind check insert() uses.
  Also hardened decay()'s tau_eff against a post-construction
  decay_tau_s of 0 (NaN instead of merely-fast decay).
- adapters.rs: WifiCsiAdapter used the frequency band's fixed
  per-band constant (e.g. 2437 MHz) instead of the frame's real
  channel, misreporting center_freq_hz for every channel except the
  one that happens to match the constant. Confirmed against a live
  ESP32-C6 node on channel 4: pre-fix would report 2437000000 Hz,
  post-fix correctly reports 2427000000 Hz, matching the hardware
  parser's independently-computed frequency exactly. Added
  examples/esp32_live_hardware_test.rs, a hardware-in-the-loop test
  that bridges real ADR-018 UDP captures through the adapter (also
  confirms no panic on real 256-subcarrier HE-SU frames, well beyond
  CANONICAL_BINS=56).
- control.rs: admit_task didn't validate requested_resolution_m,
  maximum_latency_ms, or modalities, so a task with 0/NaN resolution,
  0ms latency, or zero modalities passed admission. Added boundary
  checks.
- control.rs + security_boundaries.rs: validate_representation's only
  test coverage (unit test and proptest) hardcoded
  SensingPurpose::Presence, leaving the other three purpose-ceiling
  branches (Activity/Localization at P3, Vitals/PoseTracking at P4,
  IdentityRecognition at P5 — the higher-risk representations)
  completely unverified. Added coverage for all branches in both.

Also fixed pre-existing issues surfaced while validating the above:
- wifi-densepose-core: 7 clippy warnings (cast_possible_truncation/
  wrap, single_match_else, suboptimal_flops) in the canonical
  encode/decode path, now using try_from/from_le_bytes/mul_add.
- wifi-densepose-hardware: a test missing #[cfg(unix)] that used
  std::os::unix::fs::PermissionsExt unconditionally, breaking
  Windows builds of ruview-auth's test suite; a manual Default impl
  clippy flagged as derivable; two tests using field-reassignment
  instead of struct-update syntax after ::default().
- wifi-densepose-sensing-server: auth_wiring.rs's free_port() /
  child-process bind race (documented as "mildly racy" by design)
  now retries up to 3x specifically on an AddrInUse-shaped failure,
  preserving the original fail-loud behavior for genuine wiring
  regressions.

All touched crates re-verified: ruview-unified 99 tests (was 98),
wifi-densepose-core 37+40, wifi-densepose-hardware 483+1(ignored),
ruview-auth builds and tests on Windows, sensing-server auth_wiring
7/7. ruview-unified remains clippy-clean under -D warnings; the
pre-existing dependency warnings that -D warnings surfaced are fixed
too.

Co-Authored-By: claude-flow <ruv@ruv.net>
@ruvnet

ruvnet commented Jul 26, 2026

Copy link
Copy Markdown
Owner Author

Deep review + hardware-in-the-loop test

Reviewed ruview-unified end to end (adapters/frame contract, RF math/encoder,
Gaussian memory/security boundaries) and tested the WifiCsiAdapter against a
live ESP32-C6 CSI node, not just synthetic data. Full write-up: https://gist.github.com/ruvnet/89795f3c4b8ea166cff5ac35ae4c7651

Fixed in 8ce3bd090 (pushed to this branch):

  • pretrain.rs: guaranteed panic on any single-token window (usize::clamp(1, 0)).
  • math.rs: resample_complex silently produced NaN when downsampling to 1 sample.
  • gaussian/map.rs: merge_overlapping was missing the entity-kind guard insert() enforces — could silently conflate a Room Gaussian with a PersonClass Gaussian.
  • adapters.rs: WifiCsiAdapter used the frequency band's fixed constant instead of the real per-frame channel. Confirmed live: a real ESP32-C6 node on channel 4 was misreported as 2437 MHz pre-fix; post-fix it correctly reports 2427 MHz, matching the hardware parser's independently-computed frequency exactly. Added examples/esp32_live_hardware_test.rs as a standing hardware-in-the-loop check (also confirms no panic on real 256-subcarrier HE-SU frames, beyond CANONICAL_BINS=56).
  • control.rs: admit_task didn't validate resolution/latency/modalities.
  • validate_representation's only test coverage (unit + proptest) hardcoded Presence, leaving the P3/P4/P5 purpose branches unverified — added coverage for all of them.

Also fixed pre-existing issues surfaced while validating (unrelated to this PR's diff): 7 clippy warnings in wifi-densepose-core's canonical encode/decode path, a Windows-breaking test in ruview-auth missing #[cfg(unix)], and a port-collision flake in sensing-server's auth_wiring.rs integration test.

All touched crates re-verified post-fix: ruview-unified 99/99 tests (clippy-clean under -D warnings), wifi-densepose-core 37+40, wifi-densepose-hardware 483+1(ignored), ruview-auth builds/tests on Windows, sensing-server auth_wiring 7/7.

A few of the PR's headline "MEASURED" numbers are narrower than they read (detailed in the gist) — worth a look before citing them elsewhere, though none are code bugs: the RePos leakage-resistance test never exercises the actual encoder, the "empty map ⇒ exact Friis" test never invokes the erf path it's named for, and the "6.1 dB obstruction learned in 20 observations" is 20 repeats of one measurement converging a single scalar.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants