diff --git a/docs/13_LIDAR_WORKER_PRODUCT_AND_ROADMAP.md b/docs/13_LIDAR_WORKER_PRODUCT_AND_ROADMAP.md index a7b39c0..b804623 100644 --- a/docs/13_LIDAR_WORKER_PRODUCT_AND_ROADMAP.md +++ b/docs/13_LIDAR_WORKER_PRODUCT_AND_ROADMAP.md @@ -7,7 +7,8 @@ local-surface temporal qualification, operator triage and prior-plane residual explainability implemented; L2.6e recorded-source-paced bounded shadow qualified; E28 complete worker replay accepted; E29 camera-first semantic and parallel geometry-only replay implemented; E30–E35 source-scoped qualification -accepted; E36 transfer gate next +accepted; RAVNOVES00 reference-source product maturation active; E36 transfer +deferred by ADR 0030 Scope: passively received real-time K1 point/pose evidence, immutable replay and future live shadow processing Explicitly out of scope: K1 firmware modification, a new onboard exporter, new @@ -647,9 +648,12 @@ The E36 catalog-admission audit is complete in immutable result `e36-source-catalog-audit-c5a7b259f043c0a4f3be38f869af1e675dfaa43743e45fd4f43fac166d07f849`. TEST007 passes the camera, LiDAR, pose, host-time, device-identity and minimum camera-window checks, but lacks calibration and physical-mount identities bound -to its source session. The transfer replay remains blocked; no LAB E36 page, -retuning or automatic collection was created. ADR 0029 records the admission -contract and exact unblocking evidence. +to its source session under that audit profile. The transfer replay was not +created. ADR 0030 subsequently deferred TEST007 and E36 as current priorities: +RAVNOVES00 source-scoped quality, product workflow and a reference release +candidate now come first. No new capture is required or authorized by default. +The active gates are defined in +`docs/20_RAVNOVES00_REFERENCE_SOURCE_PRODUCT_PLAN.md`. The current E30 AI-assisted engineering generation is `e30-engineering-generation-62a4fea10dea9b77f69ceac1af5bf0e4928d9c7716083c22258a03670fe5bd4f`. diff --git a/docs/15_LABORATORY_RUN_CANON.md b/docs/15_LABORATORY_RUN_CANON.md index 7413cb4..809b6b5 100644 --- a/docs/15_LABORATORY_RUN_CANON.md +++ b/docs/15_LABORATORY_RUN_CANON.md @@ -24,6 +24,24 @@ consumer must request an explicit catalog scope: Deleting, renaming or moving source payloads to make the UI look clean is forbidden. Product separation is expressed by typed projections. +## Current reference-source policy + +RAVNOVES00 is the sole active physical reference source for the current +product-maturation cycle defined by ADR 0030. Until its source-scoped release +candidate is accepted: + +- new perception and product iterations use RAVNOVES00; +- each iteration creates a new immutable LAB and never rewrites an older one; +- TEST007, E36 and new physical collection are deferred, not required gates; +- no agent may initiate or imply a new capture without explicit operator + authorization; +- the active quality target is at least `90%` on each frozen task-level + validation dimension, never one unqualified aggregate accuracy number. + +This policy is a development priority, not a universality claim. Later +second-source transfer remains required before any cross-route or cross-camera +generalization statement. + ## Immutable identity Every LAB run is one append-only result with: diff --git a/docs/16_ARCHITECTURE_AUDIT_EXECUTION_ROADMAP.md b/docs/16_ARCHITECTURE_AUDIT_EXECUTION_ROADMAP.md index 243ee43..6ef779d 100644 --- a/docs/16_ARCHITECTURE_AUDIT_EXECUTION_ROADMAP.md +++ b/docs/16_ARCHITECTURE_AUDIT_EXECUTION_ROADMAP.md @@ -32,16 +32,38 @@ generation, the Polygon SRS or any authority boundary. | A6 — E32 full replay | Camera-first geometry v2 over all 4,489 source frames | A4–A5 | E29/E32 comparison by cause, class, range and scene; no hidden source loss or false free space | | A7 — E33 worker shadow | Persistent recorded-source-paced execution with channel-specific deadlines and resource telemetry | A6 | Closed queue/drop/recovery accounting; diagnostic/shadow only | | A8 — E34/E35 local model | Short-TTL occupied/unknown layers and deterministic degradation suite | A7 | Explicit current/held/unknown aging and safe degradation; planner authority remains false | -| A9 — E36 transfer | Frozen-profile replay on a mounted second real source | A8 and eligible source | Generalization decision without retuning; blocked if no eligible source exists | +| A9 — E36 transfer | Frozen-profile replay on a mounted second real source | Accepted RAVNOVES00 reference release candidate and later eligible source | Generalization decision without retuning; deferred by ADR 0030 | -The strict critical path is: +The completed source-contract path is: ```text -A0 → A1 → A2 → A3 → A4 → A5 → A6 → A7 → A8 → A9 +A0 → A1 → A2 → A3 → A4 → A5 → A6 → A7 → A8 ``` A5 contract design may start before E31 closes, but the accepted E31 time/calibration/mount identities must be bindable before E32 publication. +A9 remains a later generalization gate. It is no longer the current product +critical path. + +## Workstream R — RAVNOVES00 reference-source maturation + +ADR 0030 makes this the active path before A9: + +```text +R0 acceptance contract + → R1 perception quality + → R2 temporal product state + → R3 product workflow + → R4 reference release candidate + → R5 later transfer +``` + +R0–R4 use only immutable RAVNOVES00 evidence. The target is `>= 90%` +separately for reviewed object/background decisions, camera↔geometry +association and current/stale decisions, plus complete accounting and zero +false-free claims. R5 is a later operator-authorized capture and transfer +cycle. The detailed gate is +`docs/20_RAVNOVES00_REFERENCE_SOURCE_PRODUCT_PLAN.md`. ## Workstream B — Simulation Polygon @@ -208,14 +230,15 @@ Six deterministic variants each replay all 4,489 frames; the result records 26,934 terminal outcomes and 360 injections. Maximum recovery is `0.102 s` against the `0.25 s` gate. Hidden success, false free-space, unsupported semantic/metric claims, timing-mismatch `agree`, late-result return and -upstream changes are all zero. A0–A8 are closed. A9/E36 is now the critical -path. Its immutable catalog-admission audit +upstream changes are all zero. A0–A8 are closed. At the time A8 closed, A9/E36 +was the next architecture gate. Its immutable catalog-admission audit `e36-source-catalog-audit-c5a7b259f043c0a4f3be38f869af1e675dfaa43743e45fd4f43fac166d07f849` checked all 11 physical source rows. TEST007 is a real 206.073-second candidate with camera, LiDAR, pose, host time and device identity, but no calibration or mount identity is bound to that source session. A9 transfer therefore remains -blocked without publishing an empty LAB. ADR 0029 defines the exact unblocking -contract. +unexecuted without publishing an empty LAB. ADR 0029 retains the audit. +ADR 0030 now defers TEST007/E36 and makes RAVNOVES00 source-scoped quality and +product closure the active critical path. - [x] Reproduce all 4,489 immutable E29 frames with the exact frozen profile before applying E31/E30 changes. @@ -231,10 +254,15 @@ contract. E33 worker input with complete artifact digests. - [x] Audit all 11 physical source rows through the frozen E36 eligibility contract without creating an empty LAB. -- [ ] Bind TEST007 calibration and physical mount identities to its exact - source session using primary evidence. -- [ ] Run and compare the frozen E32–E35 profile on an eligible second source - without retuning. +- [x] Defer TEST007, E36 and new collection until the RAVNOVES00 reference + release candidate is accepted. +- [ ] Freeze the RAVNOVES00 task ontology, reviewed denominator and + development/validation split. +- [ ] Reach `>= 90%` separately for presence, geometry association and + freshness decisions while retaining complete accounting and zero false-free + claims. +- [ ] Complete the reusable product workflow and source-scoped reference + release candidate before returning to second-source transfer. - [x] Replay all 4,489 frames at recorded `1.0×` pace through independent bounded latest-wins work/result queues. - [x] Close every frame as delivered, input-superseded or result-superseded diff --git a/docs/20_RAVNOVES00_REFERENCE_SOURCE_PRODUCT_PLAN.md b/docs/20_RAVNOVES00_REFERENCE_SOURCE_PRODUCT_PLAN.md new file mode 100644 index 0000000..17eeac8 --- /dev/null +++ b/docs/20_RAVNOVES00_REFERENCE_SOURCE_PRODUCT_PLAN.md @@ -0,0 +1,90 @@ +# RAVNOVES00 reference-source product plan + +Date: 2026-07-27 + +Status: active + +ADR 0030 makes RAVNOVES00 the sole physical reference source for the current +Mission Core product-maturation cycle. This plan turns that decision into +bounded gates. It does not claim cross-route generalization or authorize +commands, navigation or safety. + +## Product objective + +Build a readable, reproducible and operationally conservative perception +product for a known near-industrial location and simple low-speed transport +missions. Mission Core should answer: + +- what the camera observes; +- which current LiDAR evidence belongs to that observation; +- whether the evidence is current, held, stale, conflicting or unavailable; +- what changed between two immutable methods; +- why a result passed, failed or remained uncertain. + +The product is not being designed for adversarial, tactical or continuously +novel environments. + +## Acceptance meaning + +`90%` is a target for reviewed task-level correctness on RAVNOVES00, not a +generic marketing accuracy score. + +The next acceptance contract must freeze a validation set before further +tuning and measure at least: + +| Dimension | Question | Source-scoped target | +| --- | --- | ---: | +| Presence decision | Is the task-relevant object/obstacle real rather than background or detector noise? | `>= 90%` | +| Geometry association | Are the admitted current points attached to the correct observation or independent occupied component? | `>= 90%` | +| Freshness decision | Is current, held, stale or unavailable state represented correctly? | `>= 90%` | +| Evidence accounting | Does every admitted source item receive an explicit terminal outcome? | `100%` | +| False free space | Does missing or rejected evidence ever become asserted free space? | `0` | + +Targets apply separately. A strong presence score cannot compensate for bad +geometry association or hidden stale evidence. + +The reviewed denominator, sampling strata and severity classes must be frozen +before the next tuning cycle. Development items may be used for diagnosis and +changes; sealed validation items may only be used for evaluation. High-impact +failures remain blocking even when an aggregate percentage passes. + +## Current path + +| Gate | Deliverable | Exit | +| --- | --- | --- | +| R0 — acceptance contract | Freeze task ontology, reviewed denominator, development/validation split, metrics, severity and error budget over RAVNOVES00 | Reproducible evaluation with no post-result denominator changes | +| R1 — perception quality | Iterate detector, camera↔geometry association, source-time handling and conservative corrections as new immutable LABs | Each task-level validation dimension reaches `>= 90%` or has an explicit bounded exception | +| R2 — temporal product state | Refine current/held/stale/unknown presentation and bounded occupied telemetry without polluting the persistent reconstruction | Stable task-relevant state, closed accounting and deterministic degradation | +| R3 — product workflow | Complete reusable source/LAB selection, method summary, visual evidence, comparison, controls and conclusion templates | A non-expert can understand the run; an engineer can inspect exact provenance and metrics | +| R4 — reference release candidate | Replay the complete RAVNOVES00 source through the accepted pipeline at recorded pace with regression, resource and recovery evidence | Source-scoped release decision for the known-location product envelope | +| R5 — later transfer | Record a new route/camera only after explicit operator authorization and run the frozen release candidate unchanged | Generalization decision; no retuning before comparison | + +R0–R4 are the active path. R5 is intentionally deferred. + +## Experiment rules + +1. RAVNOVES00 remains immutable and is never relabelled as a LAB result. +2. Every iteration creates a new LAB identity, method profile and conclusion. +3. Existing E29–E35 results remain historical evidence and are not overwritten. +4. Metrics are computed from server-owned artifacts; the UI does not invent + acceptance state. +5. The compact LAB summary explains the task, method, relevant models, + algorithms, result and limitation. The full engineering report is recorded + in Ops and the repository report. +6. New product controls must use the accepted component and Design Guideline + systems. A new component or page anatomy requires explicit agreement. +7. No run claims universal accuracy, planner fitness, navigation or safety + acceptance merely because its source-scoped target passes. + +## Deferred work + +Until R4 closes, the following are not current blockers: + +- TEST007 qualification; +- E36 second-source transfer; +- a new physical route or camera capture; +- second K1 or changed mount generalization; +- open-world and adversarial evaluation. + +The existing E36 audit and its Ops card remain retained so transfer work can +resume later without reconstructing history. diff --git a/docs/adr/0029-e36-second-source-catalog-admission.md b/docs/adr/0029-e36-second-source-catalog-admission.md index b2fd089..b37b74d 100644 --- a/docs/adr/0029-e36-second-source-catalog-admission.md +++ b/docs/adr/0029-e36-second-source-catalog-admission.md @@ -2,7 +2,11 @@ Date: 2026-07-27 -Status: accepted; transfer replay blocked by missing source provenance +Status: accepted audit; transfer priority deferred by ADR 0030 + +Program update: ADR 0030 makes RAVNOVES00 reference-source maturation the +current critical path. This audit remains immutable planning evidence for a +later transfer cycle; TEST007 and E36 are not current product blockers. ## Context @@ -58,9 +62,10 @@ contain the required camera modality or accepted physical-source provenance. - A9 has completed its catalog-admission sub-gate, but E36 transfer remains blocked. -- The next admissible action is provenance recovery or a new explicit binding - artifact for TEST007, based only on primary evidence. It is not threshold - tuning and does not rerun E32–E35. +- When ADR 0030 later reactivates transfer work, the admissible action is + provenance recovery or a new explicit binding artifact for TEST007, based + only on primary evidence. It is not threshold tuning and does not rerun + E32–E35. - If both bindings become available, the same audit can be rerun. Only an eligible result authorizes packaging the frozen E32–E35 transfer replay. - Until then, Mission Core publishes no LAB E36 page and claims no diff --git a/docs/adr/0030-ravnoves00-reference-source-before-transfer.md b/docs/adr/0030-ravnoves00-reference-source-before-transfer.md new file mode 100644 index 0000000..250ff4d --- /dev/null +++ b/docs/adr/0030-ravnoves00-reference-source-before-transfer.md @@ -0,0 +1,78 @@ +# ADR 0030 — RAVNOVES00 reference-source maturation before transfer + +Date: 2026-07-27 + +Status: accepted + +## Context + +Mission Core has completed A0–A8 on the immutable RAVNOVES00 source and has a +source-catalog audit for the later E36 transfer gate. The immediate product +objective is not open-world autonomy or cross-route generalization. It is a +bounded near-industrial transport product operating at low speed in a known +location on known routes, with simple tasks such as movement from point A to +point B. + +Attempting second-source transfer now would split effort before the +source-scoped perception architecture, evidence workflow and operator product +have reached a useful quality level. A new route and another camera view can be +recorded later, after the current reference path is stable enough to make that +transfer test meaningful. + +## Decision + +1. RAVNOVES00 is the only active physical reference source for the current + product-maturation cycle. +2. E36 and TEST007 are deferred. The existing E36 catalog audit remains valid + historical planning evidence, but transfer is no longer the current + critical-path gate. +3. No new physical route or camera capture is required until RAVNOVES00 reaches + the source-scoped product acceptance defined below. +4. All changes remain append-only immutable LAB results over the same + RAVNOVES00 source. Accepted generations are never rewritten. +5. The next gate must define and freeze a reviewed development/validation split + inside RAVNOVES00 before any new quality tuning. +6. The target is at least `90%` on each task-relevant validation dimension: + object-versus-background decision correctness, camera↔geometry association + correctness and current-versus-stale state correctness. +7. The `90%` target is source-scoped. It is not a claim of universal detector + accuracy, cross-site generalization, safety certification or open-world + autonomy. +8. Average quality cannot waive hard invariants: source accounting remains + complete, missing evidence remains unknown, false free-space claims remain + forbidden and degraded input must fail visibly. +9. The same reference cycle may extend reusable product controls, evidence + viewers, LAB templates and comparison workflows under the existing Design + Guideline and component architecture canons. +10. A second capture becomes the transfer gate only after the source-scoped + release candidate is accepted and the operator explicitly authorizes new + collection. + +## Product envelope + +The current product assumption is intentionally bounded: + +- known or pre-mapped industrial location; +- declared routes and simple logistics missions; +- low-speed motion and conservative stopping on uncertainty; +- no adversarial environment, tactical autonomy or strategic replanning; +- no implication that a `90%` perception score alone authorizes actuation. + +This narrower envelope reduces unnecessary complexity, but it does not remove +the requirement for explicit unknown/stale states, watchdogs, command expiry or +independent physical safety controls. + +## Consequences + +- The active critical path moves from E36 transfer to RAVNOVES00 + reference-source quality and product closure. +- The immediate next experiment is a source-scoped acceptance-contract LAB, + not another data collection or another transfer audit. +- Future quality iterations may change algorithms, models and thresholds only + through new immutable profiles and results evaluated against the frozen + validation split. +- Product UI work is justified when it exposes a reusable task, method, + evidence, result or comparison contract. Run-specific decorative or + temporary interfaces remain forbidden. +- Generalization remains explicitly unproved until a later independently + recorded source is admitted and replayed. diff --git a/experiments/perception/E36_SOURCE_CATALOG_AUDIT_2026-07-27.md b/experiments/perception/E36_SOURCE_CATALOG_AUDIT_2026-07-27.md index de8090e..7d9d50f 100644 --- a/experiments/perception/E36_SOURCE_CATALOG_AUDIT_2026-07-27.md +++ b/experiments/perception/E36_SOURCE_CATALOG_AUDIT_2026-07-27.md @@ -106,3 +106,12 @@ rerun this admission audit and then package E32–E35 unchanged for transfer. If they cannot be proven, A9 remains blocked until an operator separately authorizes a new capture with calibration and mount identities recorded at acquisition time. + +## Program priority update + +ADR 0030 was accepted after this audit. It preserves the audit and its blocked +result but defers TEST007 provenance recovery, E36 replay and new physical +collection. The active path is now RAVNOVES00 source-scoped quality, product +workflow and reference release acceptance. This report remains the immutable +record of the catalog decision; its “next admissible step” applies only when +transfer work is explicitly resumed. diff --git a/experiments/perception/LAB_E35_REPORT_2026-07-27.md b/experiments/perception/LAB_E35_REPORT_2026-07-27.md index 5e20159..0992a85 100644 --- a/experiments/perception/LAB_E35_REPORT_2026-07-27.md +++ b/experiments/perception/LAB_E35_REPORT_2026-07-27.md @@ -151,3 +151,11 @@ retuning on an eligible second mounted real source. The source catalog must be audited first. If no recording contains the required camera, LiDAR, pose, time, calibration and mount identities, E36 remains explicitly blocked; no empty LAB, fabricated result or new capture is created by default. + +## Later program priority update + +ADR 0030 supersedes the sequencing statement above without changing this +immutable E35 result. RAVNOVES00 reference-source quality and product closure +is now the active path. TEST007, E36 and new physical collection are deferred +until the RAVNOVES00 reference release is accepted and transfer work is +explicitly resumed.