Deep review of PR #1437 (ADR-273..282 unified RF spatial world model)
plus hardware-in-the-loop testing against a live ESP32-C6 CSI node
turned up several real defects, fixed here:
- pretrain.rs: sample_mask panicked (usize::clamp(1, 0)) on any
single-token window, reachable from a valid RfTensor via a perfectly
normal tokenizer output. eval() now skips empty masks instead of
averaging in NaN.
- math.rs: resample_complex(x, 1) with x.len() > 1 divided by zero
(m - 1 == 0), silently poisoning the output with NaN. Now returns
the mean.
- gaussian/map.rs: merge_overlapping had no entity-kind guard (unlike
insert()), so an unlabeled Room-linked Gaussian and an unlabeled
PersonClass-linked Gaussian within each other's merge gate would be
silently conflated. Added the same same_kind check insert() uses.
Also hardened decay()'s tau_eff against a post-construction
decay_tau_s of 0 (NaN instead of merely-fast decay).
- adapters.rs: WifiCsiAdapter used the frequency band's fixed
per-band constant (e.g. 2437 MHz) instead of the frame's real
channel, misreporting center_freq_hz for every channel except the
one that happens to match the constant. Confirmed against a live
ESP32-C6 node on channel 4: pre-fix would report 2437000000 Hz,
post-fix correctly reports 2427000000 Hz, matching the hardware
parser's independently-computed frequency exactly. Added
examples/esp32_live_hardware_test.rs, a hardware-in-the-loop test
that bridges real ADR-018 UDP captures through the adapter (also
confirms no panic on real 256-subcarrier HE-SU frames, well beyond
CANONICAL_BINS=56).
- control.rs: admit_task didn't validate requested_resolution_m,
maximum_latency_ms, or modalities, so a task with 0/NaN resolution,
0ms latency, or zero modalities passed admission. Added boundary
checks.
- control.rs + security_boundaries.rs: validate_representation's only
test coverage (unit test and proptest) hardcoded
SensingPurpose::Presence, leaving the other three purpose-ceiling
branches (Activity/Localization at P3, Vitals/PoseTracking at P4,
IdentityRecognition at P5 — the higher-risk representations)
completely unverified. Added coverage for all branches in both.
Also fixed pre-existing issues surfaced while validating the above:
- wifi-densepose-core: 7 clippy warnings (cast_possible_truncation/
wrap, single_match_else, suboptimal_flops) in the canonical
encode/decode path, now using try_from/from_le_bytes/mul_add.
- wifi-densepose-hardware: a test missing #[cfg(unix)] that used
std::os::unix::fs::PermissionsExt unconditionally, breaking
Windows builds of ruview-auth's test suite; a manual Default impl
clippy flagged as derivable; two tests using field-reassignment
instead of struct-update syntax after ::default().
- wifi-densepose-sensing-server: auth_wiring.rs's free_port() /
child-process bind race (documented as "mildly racy" by design)
now retries up to 3x specifically on an AddrInUse-shaped failure,
preserving the original fail-loud behavior for genuine wiring
regressions.
All touched crates re-verified: ruview-unified 99 tests (was 98),
wifi-densepose-core 37+40, wifi-densepose-hardware 483+1(ignored),
ruview-auth builds and tests on Windows, sensing-server auth_wiring
7/7. ruview-unified remains clippy-clean under -D warnings; the
pre-existing dependency warnings that -D warnings surfaced are fixed
too.
Co-Authored-By: claude-flow <ruv@ruv.net>