Commit Graph

4 Commits

Author SHA1 Message Date
ruv 8ce3bd090b fix(ruview-unified): panics, NaN corruption, entity-conflation, and wrong center-freq found in review
Deep review of PR #1437 (ADR-273..282 unified RF spatial world model)
plus hardware-in-the-loop testing against a live ESP32-C6 CSI node
turned up several real defects, fixed here:

- pretrain.rs: sample_mask panicked (usize::clamp(1, 0)) on any
  single-token window, reachable from a valid RfTensor via a perfectly
  normal tokenizer output. eval() now skips empty masks instead of
  averaging in NaN.
- math.rs: resample_complex(x, 1) with x.len() > 1 divided by zero
  (m - 1 == 0), silently poisoning the output with NaN. Now returns
  the mean.
- gaussian/map.rs: merge_overlapping had no entity-kind guard (unlike
  insert()), so an unlabeled Room-linked Gaussian and an unlabeled
  PersonClass-linked Gaussian within each other's merge gate would be
  silently conflated. Added the same same_kind check insert() uses.
  Also hardened decay()'s tau_eff against a post-construction
  decay_tau_s of 0 (NaN instead of merely-fast decay).
- adapters.rs: WifiCsiAdapter used the frequency band's fixed
  per-band constant (e.g. 2437 MHz) instead of the frame's real
  channel, misreporting center_freq_hz for every channel except the
  one that happens to match the constant. Confirmed against a live
  ESP32-C6 node on channel 4: pre-fix would report 2437000000 Hz,
  post-fix correctly reports 2427000000 Hz, matching the hardware
  parser's independently-computed frequency exactly. Added
  examples/esp32_live_hardware_test.rs, a hardware-in-the-loop test
  that bridges real ADR-018 UDP captures through the adapter (also
  confirms no panic on real 256-subcarrier HE-SU frames, well beyond
  CANONICAL_BINS=56).
- control.rs: admit_task didn't validate requested_resolution_m,
  maximum_latency_ms, or modalities, so a task with 0/NaN resolution,
  0ms latency, or zero modalities passed admission. Added boundary
  checks.
- control.rs + security_boundaries.rs: validate_representation's only
  test coverage (unit test and proptest) hardcoded
  SensingPurpose::Presence, leaving the other three purpose-ceiling
  branches (Activity/Localization at P3, Vitals/PoseTracking at P4,
  IdentityRecognition at P5 — the higher-risk representations)
  completely unverified. Added coverage for all branches in both.

Also fixed pre-existing issues surfaced while validating the above:
- wifi-densepose-core: 7 clippy warnings (cast_possible_truncation/
  wrap, single_match_else, suboptimal_flops) in the canonical
  encode/decode path, now using try_from/from_le_bytes/mul_add.
- wifi-densepose-hardware: a test missing #[cfg(unix)] that used
  std::os::unix::fs::PermissionsExt unconditionally, breaking
  Windows builds of ruview-auth's test suite; a manual Default impl
  clippy flagged as derivable; two tests using field-reassignment
  instead of struct-update syntax after ::default().
- wifi-densepose-sensing-server: auth_wiring.rs's free_port() /
  child-process bind race (documented as "mildly racy" by design)
  now retries up to 3x specifically on an AddrInUse-shaped failure,
  preserving the original fail-loud behavior for genuine wiring
  regressions.

All touched crates re-verified: ruview-unified 99 tests (was 98),
wifi-densepose-core 37+40, wifi-densepose-hardware 483+1(ignored),
ruview-auth builds and tests on Windows, sensing-server auth_wiring
7/7. ruview-unified remains clippy-clean under -D warnings; the
pre-existing dependency warnings that -D warnings surfaced are fixed
too.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-07-26 17:08:27 -04:00
Claude 42485495ed feat(ruview-unified): complete Gaussian update loop, separable delay-Doppler, property-tested boundary hardening
Third increment: closes the remaining implementable ADR-275 update-loop
steps, optimizes the delay-Doppler transform, and hardens every boundary
surface with property testing that found and fixed three real
input-controlled defects.

- ADR-275 update loop: GaussianMap::merge_overlapping (step 5 — mutual
  Mahalanobis + semantic-compatibility dedup catching drift the
  insert-time ±1-cell gate misses; orthogonal semantics stay separate)
  and lifetime-aware decay (step 7 — tau_eff = tau*(1+ln(1+lifetime/tau))
  so confirmed structures outlive transients at equal nominal tau).
- Separable delay-Doppler (ADR-281): O(B^2*S + S^2*B) instead of
  O(B^2*S^2), proven equivalent to the direct reference to <1e-10 and
  measured 8.3x faster (520us vs 4.34ms at 56x8). Direct form kept as
  the benchmark baseline + equivalence oracle.
- Security property tests (tests/security_boundaries.rs, 8 proptest
  properties over arbitrary values incl. NaN/inf via f64::from_bits).
  Found and fixed:
  * ble_cs_range unwrap infinite loop on non-finite phase (+inf) and
    ~1e299-iteration loop on finite-huge phase -> O(1) modular unwrap +
    plausibility bound (|phase| <= 1e6 rad);
  * subnormal Gaussian scale (5e-324) overflowing 1/sigma^2 to NaN
    density -> physical bounds (sigma in [1e-6, 1e4] m, occupancy in
    [0, 1e6] nepers/m).
  Properties proven: tensor/Gaussian/BoundedEvent constructors never
  panic; policy engine fail-closed for every (purpose,grants,zone);
  raw export structurally unreachable; coherent fusion rejects every
  non-finite/out-of-bounds sync state; occupancy reps never retain
  identity.
- New criterion benches for all increment-2/3 hot paths (to_canonical
  38us, ble_cs_range 481ns, AoI planner 647ns/200 regions, coherent
  fusion 1.5us/32 members, factorized pose 521ns, delay-Doppler
  separable vs direct).

Validation: ruview-unified 98 tests (87 lib + 3 acceptance + 8
security), 0 failed, clippy-clean; Python proof VERDICT PASS. Witness
bundle regeneration still blocked on the desktop/Tauri crate's GTK dev
headers (unavailable in this container) — pre-existing environment
limitation, flagged for the release owner.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
2026-07-26 20:29:58 +00:00
Claude 9aae7f04ff feat(ruview-unified): native frame contract + programmable perception (ADR-279..282)
Second increment of the unified RF spatial world model, applying the
architectural correction that the 56-bin canonical tensor must not be
the authoritative format, and moving the control plane from passive
sensing to programmable perception.

- RfFrameV2 (ADR-279): authoritative native RF record — native complex
  IQ preserved (proven byte-untouched by the derived view), explicit
  validity masks, declared PhaseState, TX/RX poses + antenna geometry,
  calibration/quality state, and construction-time provenance rules:
  Synthetic ⇒ L0Simulation, Measured ⇒ ≥ L1CapturedReplay (the L0–L5
  evidence ladder is now a type). Canonical tensor demoted to a
  mask-aware derived view through the shared adapter normalization.
  New modalities: WifiCir, WifiBfReport, FmcwRangeAzimuth,
  FmcwDopplerAzimuth. IEEE P3162 synthetic-aperture import profile.
- Active sensing control plane (ADR-280, control.rs): SensingTask
  admission (raw export always refused; identity requires consent),
  SensingAction/InformationGoal, age-of-information planner with
  measured 95% sensing-traffic reduction vs uniform refresh,
  fail-closed CoherentSensorGroup fusion (time/phase/geometry bounds,
  five denial paths tested), policy-authorized RIS actuation receipts,
  purpose-scoped TaskSufficientRepresentation leakage validation.
- BLE Channel Sounding (ADR-281): adapter + ble_cs_range with
  phase-slope and RTT as separate cross-validated evidence — exact
  recovery on synthetic tones, relay-style divergence flagged instead
  of averaged. Delay-Doppler-native FieldAxis + delay_doppler_map
  (unit-peak tone test).
- Factorized pose (ADR-281, RePos): relative skeleton on the content
  representation, root on the geometry-conditioned one, calibrated
  per-joint uncertainties; room-shortcut leakage experiment: held-out
  MPJPE 0.0003 m vs 0.2534 m monolithic; 740 params (<2% structured
  budget). Age gate input now log(1+age_ms); gradient check re-proven.
- Gaussian primitives: first_seen_ns, doppler_variance, bounded
  source_receipts lineage merged on fusion. PartitionKey gains a
  session dimension; SplitManifest certifies disjointness across all
  seven leakage dimensions.
- ADR-282: ecosystem positioning — RuView as the edge RF perception
  runtime under RuField/RuVector/MetaHarness; evidence-ladder policy.

Validation: ruview-unified 84 unit + 3 acceptance tests, 0 failed,
clippy-clean; workspace 3,789 passed 0 failed (--exclude
wifi-densepose-desktop, GTK headers unavailable in container); Python
proof VERDICT PASS. Docker images unaffected: no shipped binary
consumes this crate yet (Dockerfile.rust builds sensing-server /
cog-ha-matter / homecore-server only; Dockerfile.python builds
untouched archive/v1).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
2026-07-26 19:29:18 +00:00
Claude a1a59baf72 feat(ruview-unified): unified RF spatial world model P1 (ADR-273..278)
One shared representation instead of another isolated RF classifier: new
v2 leaf crate ruview-unified implementing all five ADR-273 pillars, plus
six ADRs with measured, grade-labeled results.

- Canonical RfTensor + fail-closed hardware adapter registry (802.11 CSI
  via wifi-densepose-core::CsiFrame, FMCW radar cubes, UWB CIR, 5G SRS);
  shared layout/gain/phase normalization proven by tests (ADR-274).
- Universal RF foundation encoder: CFO-aligned, median-scaled tokenizer;
  masked-reconstruction pretraining with hand-derived backprop verified
  against central finite differences (max rel err 1.31e-5 over all 12
  parameter groups); fusion contract z = Enc ⊙ σ(AgeEnc) + GeomEnc;
  task adapters under the 1% budget (129/268/387/2 params vs 40,856
  backbone), enforced by test.
- RF-aware Gaussian spatial memory: anisotropic primitives with per-band
  reflectivity, confidence-weighted fusion, decay, spatial-hash/semantic
  queries, closed-form Beer-Lambert channel gain (exact Friis on empty
  map), inverse gain updates (unseen 6.1 dB wall learned to <0.5 dB in
  20 observations), task-gated scene graph (ADR-275).
- Physics-guided synthetic RF worlds: image-method multipath (order ≤2),
  complex-permittivity Fresnel materials, emergent Doppler proven against
  the analytic phase rate, seeded ChaCha20 randomization of physics and
  hardware nuisances; byte-deterministic per seed (ADR-276).
- Edge sensing control plane: 802.11bf/ETSI-ISAC-aligned purposes/zones,
  fail-closed authorization, double-gated identity, retention bounds;
  BoundedEvent-only trust boundary makes raw RF export unrepresentable
  (ADR-277). Radar inverse rendering stays a gated research program
  (ADR-278, no code by design).

Anti-leakage acceptance pipeline (strict splits by room/day/person/
chipset/firmware/layout with independent disjointness verification):
presence F1 1.00 on held-out rooms and held-out chipset, degradation
0.0, ECE 0.012, p95 latency 2.0 ms debug / 105 µs release — ALL
SYNTHETIC until P2 real-data validation.

Benchmarks + optimization pass: channel_gain 139→27 µs (O(1) in map
size via segment-corridor AABB sweep), observe_link 305→74 µs, DFT
twiddle plan 4.9x; hash/linear crossover (~4k Gaussians) reported
honestly.

Tests: ruview-unified 66 unit + 3 acceptance, 0 failed; workspace
3,771 passed 0 failed (--exclude wifi-densepose-desktop: GTK headers
unavailable in this container). Python proof: VERDICT PASS. Also
gitignore sensing-server test-run artifacts (incl. generated
session-secret).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Q1R5zhz6sSfXGRXpgBwpFX
2026-07-26 19:03:39 +00:00