# Large-ring offline qualification — 21 September 2026 ## Scope and retained authority The owner supplied `JA-STROITEL-SUN-RING-002`, session `20260921T134309Z_viewer_live`, and requested source, drift, correction and offline-localization testing without another physical capture. The finish was approximately 3–5 m beyond the physical start. Endpoint equality is therefore specifically prohibited as a fitting constraint. All geometry, detailed results, scripts and SHA-256 inventories are private under `.runtime/audits/2026-09-21-large-ring-002/`. No hardware command, source overwrite, map activation, planner mutation, production-code edit, service restart or motor authority is part of this audit. Earlier unrelated uncommitted work is retained. ## Source acceptance - Saved capture: 1,446.684 s; catalog and RRD preparation are ready. - Spatial trajectory: 1,595.409 m over 1,362.429 s of pose receipts. - 13,608 cloud frames, 13,624 poses, 49,217,854 decoded points. - All 31,450 metadata records cover the complete 573,728,851-byte transport. - Every payload SHA-256, topic, length and frame offset was checked against metadata: 31,450/31,450 agree, zero mismatches. - Transport SHA-256 agrees with its capture manifest. Cloud/pose sequences have no missing numbers or resets; decoded geometry and receipt order are valid. - No capture reconnect, rejected transport message or recovery gap. Maximum cloud receipt gap is 1.344 s; maximum pose receipt gap is 1.189 s. - No pose discontinuity under the existing live criterion; largest successive position step is 0.1515 m. Single-receipt speed is not physical velocity: transport bursts compress receipt intervals. Five-second travel averages reach 1.501 m/s. Hardware synchronization is not established by these checks. - Nearest pose-to-cloud receipt gap: p95 42.7 ms, maximum 180.8 ms. These are host-clock observations, not per-point LiDAR firing-time reconstruction. The raw endpoint displacement is 4.000 m horizontally and +1.5875 m vertically, 4.3034 m in 3D. This includes real operator displacement and is NOT a surveyed drift measurement. The corrected result must retain the real overshoot. The control-plane acquisition ended with `acquisition.stop.accepted_physical_outcome_unknown`, cleanup pending false. This is a separate physical-stop confirmation issue. The receiver reports `external_stop`, no transport error, and the saved recording is ready; do not misreport that control state as corruption of the completed cloud. ## Existing recipe failure and diagnostic variant The unchanged `recorded-ring-experiment/v1` recipe stopped before producing a correction. Its first-20-s/last-5-s fit converged: overlap 95.317%, inlier RMSE 0.1641 m, correction at the patch center 4.2176 m / 2.6199 degrees. Rejection was solely the ordinary local-tracking correction guard of 3 m. Merely changing that guard is insufficient. Four disjoint five-second tail probes using the existing coarse acquisition policy failed the unchanged bidirectional-consistency gate. The first fit's cycle was 0.0280 m / 0.6007 degrees, against the existing 0.1 m / 0.2-degree limits. A declared training-only grid of first windows [10, 20, 40] s and last windows [10, 20, 30] s was evaluated without using withheld frames. Two of nine passed the existing quality and cycle gates: 20/30 and 40/30. The larger 40/30 support was selected before held-out evaluation. It yields 72.777% overlap, 0.1875 m inlier RMSE and a 0.0194 m / 0.0973-degree bidirectional cycle. Its lower overlap reflects a different, larger point population; it is not comparable to the short-window 95% as an identical-denominator score. This private adapter uses the already defined route-acquisition registration policy for the first coarse seam fit only. Ordinary local registration, shape/information gates, overlap/RMSE thresholds, reverse consistency, solver and validation policy remain unchanged. Production modules were not patched. All 80 attempted neighboring-window links failed overlap and RMSE gates; ten also failed convergence. None was admitted. The reconstruction is therefore one measured closure plus a smoothness prior, NOT recovery of a densely measured drift history. The input is K1 mapped increments, not native LiDAR sweeps from which a new independent SLAM solution was reconstructed. ## Frozen candidate and held-out evaluation The existing `smooth-map-correction-experiment/v2` spline solver and full-frame materializer produced a separate experimental candidate. Every ten seconds, the two-second phase 4–6 interval was withheld: 2,855 frames, with 10,753 retained for fitting. Shared upstream K1 mapping means this split is not independent survey truth, despite disjoint frame membership. | Measurement | Original | Diagnostic corrected candidate | | --- | ---: | ---: | | Local held-out windows accepted | 134/136 | 136/136 | | Median local overlap, 0.5 m radius | 98.077% | 98.081% | | Median local inlier RMSE | 0.16495 m | 0.16563 m | | Cross-visit held-out overlap | 22.723% | 95.093% | | Cross-visit median all-point distance | 1.2018 m | 0.1186 m | | Cross-visit p95 all-point distance | 2.5941 m | 0.4914 m | | Endpoint XY separation | 4.000 m | 2.801 m | | Endpoint Z difference | +1.5875 m | −0.0112 m | | Trajectory length | 1,595.409 m | 1,599.807 m | Cross-visit evaluation fixes the same 7,499 source points in 18 held-out tail frames, compares them only to retained first-20-s geometry, and performs no additional fit. Those query frames did not enter closure selection or fitting. The source and corrected failed-window checks use the same frozen priors; fresh one-second halves in original failure groups 74 and 120 all qualify. The remaining 2.8 m endpoint separation is compatible with, but does not survey, the operator's 3–5 m overshoot. Near-zero endpoint Z is not centimetre absolute accuracy. A fit between coincident-looking endpoints was never imposed. Maximum trajectory displacement is 8.164 m, maximum displacement gradient 0.04123 m per travelled metre (p95 0.03768). Changing regularizer strength by 0.5×/2× changes trajectory positions by at most 0.009 mm; this is numerical prior stability, NOT proof of the actual spatial distribution of drift. Using the other qualifying 20/30-second closure measurement instead changes the corrected trajectory by up to 0.2483 m (p95 0.2262 m). This measurement-window sensitivity is materially larger than regularizer sensitivity and is retained as model uncertainty, not hidden by the visually closed seam. All 49,217,854 materialized points and all 13,624 corrected poses were reproduced from the frozen field. Within-frame motion is rigid. Maximum coordinate serialization error is 0.0306 mm; sampled intra-frame pair-distance error is 0.0601 mm. No count, intensity, frame order or raw source was discarded. ## Independent archived passes and complete-route search The production versioned-map extractor and tiled reference builder were reused through a private adapter, not through an admitted catalog generation. The whole route yields 1,924,498 original and 1,940,166 corrected registration points. Preparation took 25.48 / 26.67 s. No 30 m crop or whole-map point-count cap was introduced. Presentation's 80 m envelope is not the local numerical matching profile. The first independent query is the original cold prefix from study `473870e0-5210-452c-b9e4-9d7937e93646`, captured in a different session. Only its original query points and sensor origin are loaded, not its old reference or accepted transform. Full production v7 search tests all 2,034 fits: 108 dense start hypotheses and 1,926 route hypotheses. | Same independent cold input | Original atlas | Corrected atlas | | --- | ---: | ---: | | Complete search | 2,034/2,034 | 2,034/2,034 | | Result | Candidate | Candidate | | Time | 320.41 s | 317.07 s | | Overlap | 98.899% | 98.978% | | Inlier RMSE | 0.1493 m | 0.1449 m | This does not demonstrate a material speedup or inability to localize against the original. Correction's demonstrated benefit is cross-visit map agreement. The corrected atlas then accepts all 29 stored fresh snapshots over the 101.633 m independent walk using a causal previous-accepted-transform chain. Overlap is 98.546–99.823%, inlier RMSE 0.1181–0.1501 m; measured local calculation time is 0.073–0.105 s. Real recorded request/receipt clocks are retained; measured rerun calculation duration is substituted. This is an archived-snapshot replay, NOT a live ingress, camera, scheduler, motion-stationarity or recovery test. The original atlas also accepts all 29 snapshots of that short pass. Thus this test proves compatibility of the corrected version, not a general superiority claim for every metric. A second independent cold prefix from study `0324337e-b590-4561-b19a-8fbc7835b888` also qualifies after all 2,034 fits: 352.94 s, 99.108% overlap, 0.1438 m inlier RMSE. Replaying its entire old smaller ring against the new larger one is **not all-positive**: 30/101 snapshots qualify, with first rejection at 132.265 m. Reference-path proximity under the last accepted transform grows from 12.2 m at the last positive window to 18.2 m at first rejection, then approximately 72 m. This supports a different-route / out-of-localization-coverage explanation, not a claim that the two rings cover the same corridor. It is not ground truth during the lost interval. Near the old pass's return to the shared area, overlap again reaches 99.25–99.64% and inlier RMSE about 0.139 m, but correcting the obsolete local prior requires 3.15–3.20 m and is correctly rejected by ordinary tracking policy. This replay deliberately has no complete recovery/bootstrap state machine. It neither proves nor disproves physical reinitialization after returning; a fresh stationary relocalization is a separate operation, not continued green tracking on the old hint. The original and failed cases are retained in full. The middle-route probe selects held-out time group 68 without looking for a favorable fit: source progress 794.812 m, 11,625 query points. All 2,855 held-out frames are excluded from the atlas; query coordinates are translated to a new origin and rotated 90 degrees. The generating correction is used only to measure post-fit model consistency, never as the search seed. Complete search qualifies after 2,034/2,034 fits in 452.16 s: overlap 98.545%, inlier RMSE 0.1625 m, selected retrieval anchor at 800 m. Fitted sensor position is 0.0461 m from the generating model, NOT surveyed truth. This is a same-source numeric place-retrieval test with shared upstream K1 mapping. The source query spans 3.804 m of motion; it is explicitly not a valid stationary bootstrap prefix and must not be presented as live cold-start acceptance at the midpoint. In total, four complete cold numerical searches performed 8,136 fits. Runtime on this Mac ranges from 5.28 to 7.54 minutes. These are measured functional experiments, not a stress test or a guarantee for larger routes or the onboard computer. The full finite queue and ambiguity checks remain intact. ## Negative controls and software regressions On real query geometry, local initial-X perturbations 0/1 m converge; 3 m is rejected by the unchanged correction guard; 5/10/20 m fail numeric-quality criteria and 1,000 m has no target coverage. These are software initial-guess perturbations, NOT physical scanner-displacement acceptance. Full-route search is a different operation and is not restricted by those local outcomes. The fixed halfway wrong-region comparison is rejected on surface RMSE. Applying real positive geometry with future, nine-second-old or prior-segment receipt metadata is rejected in all three cases. Zero false confirmations in this small set is not a false-acceptance-rate estimate. All 178 focused software regressions pass: correction, registration, full-route coverage/ambiguity/worker ownership, bootstrap freshness, recovery, replay, live lifetime/multiple traversals, reference preparation and map-version/default boundaries. A pre-existing Starlette/httpx deprecation warning remains. These fixtures do not constitute physical multi-lap or onboard-computer acceptance. ## Decision boundary The data support an experimental correction of this larger loop without forcing the real endpoints together. The existing automatic recipe is NOT qualified unchanged: seam acquisition and window-support selection require a separate production change. Do not lower tracking-quality gates to conceal that distinction. Not proven: independent repeat accuracy throughout the newly added territory, absolute map/pose error, correct internal drift distribution, arbitrary-loop discovery, seasonal transfer, simultaneous live latency, target-board budget, physical multiple laps, navigation safety or motor authority. No further live scanner trial is needed to reproduce the present offline evidence. The next production increment should separate offline closure acquisition from local tracking correction, qualify window-support selection and preserve the measured quality/cycle/holdout gates. Do not ship the experiment by silently changing the global live 3 m guard or forcing final coordinates onto the start. Only after that separate change and versioned admission should the candidate be offered as the recording's corrected default. The current default is not changed by this audit. ## Runtime and final evidence seal Heavy checks ran sequentially with a single numerical worker on the operator Mac; no stress workload or second application server was introduced. The final seal verifies 311 input files unchanged and inventories 62 private artifacts. The only non-ignored repository addition from this audit is this report. Production modules, original experiment scripts and raw capture remain intact. The canonical service remains the same PID 73593 on port 8000. Final health is operational with zero consecutive reconciler failures; no temporary audit/search worker or port-8765 listener remains. No restart or hardware action was taken.