245 lines
14 KiB
Markdown
245 lines
14 KiB
Markdown
# Large-ring offline qualification — 21 September 2026
|
||
|
||
## Scope and retained authority
|
||
|
||
The owner supplied `JA-STROITEL-SUN-RING-002`, session
|
||
`20260921T134309Z_viewer_live`, and requested source, drift, correction and
|
||
offline-localization testing without another physical capture. The finish was
|
||
approximately 3–5 m beyond the physical start. Endpoint equality is therefore
|
||
specifically prohibited as a fitting constraint.
|
||
|
||
All geometry, detailed results, scripts and SHA-256 inventories are private under
|
||
`.runtime/audits/2026-09-21-large-ring-002/`. No hardware command, source overwrite,
|
||
map activation, planner mutation, production-code edit, service restart or motor
|
||
authority is part of this audit. Earlier unrelated uncommitted work is retained.
|
||
|
||
## Source acceptance
|
||
|
||
- Saved capture: 1,446.684 s; catalog and RRD preparation are ready.
|
||
- Spatial trajectory: 1,595.409 m over 1,362.429 s of pose receipts.
|
||
- 13,608 cloud frames, 13,624 poses, 49,217,854 decoded points.
|
||
- All 31,450 metadata records cover the complete 573,728,851-byte transport.
|
||
- Every payload SHA-256, topic, length and frame offset was checked against
|
||
metadata: 31,450/31,450 agree, zero mismatches.
|
||
- Transport SHA-256 agrees with its capture manifest. Cloud/pose sequences have
|
||
no missing numbers or resets; decoded geometry and receipt order are valid.
|
||
- No capture reconnect, rejected transport message or recovery gap. Maximum
|
||
cloud receipt gap is 1.344 s; maximum pose receipt gap is 1.189 s.
|
||
- No pose discontinuity under the existing live criterion; largest successive
|
||
position step is 0.1515 m. Single-receipt speed is not physical velocity:
|
||
transport bursts compress receipt intervals. Five-second travel averages
|
||
reach 1.501 m/s. Hardware synchronization is not established by these checks.
|
||
- Nearest pose-to-cloud receipt gap: p95 42.7 ms, maximum 180.8 ms. These are
|
||
host-clock observations, not per-point LiDAR firing-time reconstruction.
|
||
|
||
The raw endpoint displacement is 4.000 m horizontally and +1.5875 m vertically,
|
||
4.3034 m in 3D. This includes real operator displacement and is NOT a surveyed
|
||
drift measurement. The corrected result must retain the real overshoot.
|
||
|
||
The control-plane acquisition ended with
|
||
`acquisition.stop.accepted_physical_outcome_unknown`, cleanup pending false.
|
||
This is a separate physical-stop confirmation issue. The receiver reports
|
||
`external_stop`, no transport error, and the saved recording is ready; do not
|
||
misreport that control state as corruption of the completed cloud.
|
||
|
||
## Existing recipe failure and diagnostic variant
|
||
|
||
The unchanged `recorded-ring-experiment/v1` recipe stopped before producing a
|
||
correction. Its first-20-s/last-5-s fit converged: overlap 95.317%, inlier RMSE
|
||
0.1641 m, correction at the patch center 4.2176 m / 2.6199 degrees. Rejection was
|
||
solely the ordinary local-tracking correction guard of 3 m.
|
||
|
||
Merely changing that guard is insufficient. Four disjoint five-second tail
|
||
probes using the existing coarse acquisition policy failed the unchanged
|
||
bidirectional-consistency gate. The first fit's cycle was 0.0280 m / 0.6007
|
||
degrees, against the existing 0.1 m / 0.2-degree limits.
|
||
|
||
A declared training-only grid of first windows [10, 20, 40] s and last windows
|
||
[10, 20, 30] s was evaluated without using withheld frames. Two of nine passed
|
||
the existing quality and cycle gates: 20/30 and 40/30. The larger 40/30 support
|
||
was selected before held-out evaluation. It yields 72.777% overlap, 0.1875 m
|
||
inlier RMSE and a 0.0194 m / 0.0973-degree bidirectional cycle. Its lower overlap
|
||
reflects a different, larger point population; it is not comparable to the
|
||
short-window 95% as an identical-denominator score.
|
||
|
||
This private adapter uses the already defined route-acquisition registration
|
||
policy for the first coarse seam fit only. Ordinary local registration,
|
||
shape/information gates, overlap/RMSE thresholds, reverse consistency, solver and
|
||
validation policy remain unchanged. Production modules were not patched.
|
||
|
||
All 80 attempted neighboring-window links failed overlap and RMSE gates; ten
|
||
also failed convergence. None was admitted. The reconstruction is therefore
|
||
one measured closure plus a smoothness prior, NOT recovery of a densely
|
||
measured drift history. The input is K1 mapped increments, not native LiDAR
|
||
sweeps from which a new independent SLAM solution was reconstructed.
|
||
|
||
## Frozen candidate and held-out evaluation
|
||
|
||
The existing `smooth-map-correction-experiment/v2` spline solver and full-frame
|
||
materializer produced a separate experimental candidate. Every ten seconds,
|
||
the two-second phase 4–6 interval was withheld: 2,855 frames, with 10,753 retained
|
||
for fitting. Shared upstream K1 mapping means this split is not independent
|
||
survey truth, despite disjoint frame membership.
|
||
|
||
| Measurement | Original | Diagnostic corrected candidate |
|
||
| --- | ---: | ---: |
|
||
| Local held-out windows accepted | 134/136 | 136/136 |
|
||
| Median local overlap, 0.5 m radius | 98.077% | 98.081% |
|
||
| Median local inlier RMSE | 0.16495 m | 0.16563 m |
|
||
| Cross-visit held-out overlap | 22.723% | 95.093% |
|
||
| Cross-visit median all-point distance | 1.2018 m | 0.1186 m |
|
||
| Cross-visit p95 all-point distance | 2.5941 m | 0.4914 m |
|
||
| Endpoint XY separation | 4.000 m | 2.801 m |
|
||
| Endpoint Z difference | +1.5875 m | −0.0112 m |
|
||
| Trajectory length | 1,595.409 m | 1,599.807 m |
|
||
|
||
Cross-visit evaluation fixes the same 7,499 source points in 18 held-out tail
|
||
frames, compares them only to retained first-20-s geometry, and performs no
|
||
additional fit. Those query frames did not enter closure selection or fitting.
|
||
The source and corrected failed-window checks use the same frozen priors;
|
||
fresh one-second halves in original failure groups 74 and 120 all qualify.
|
||
|
||
The remaining 2.8 m endpoint separation is compatible with, but does not survey,
|
||
the operator's 3–5 m overshoot. Near-zero endpoint Z is not centimetre absolute
|
||
accuracy. A fit between coincident-looking endpoints was never imposed.
|
||
|
||
Maximum trajectory displacement is 8.164 m, maximum displacement gradient
|
||
0.04123 m per travelled metre (p95 0.03768). Changing regularizer strength by
|
||
0.5×/2× changes trajectory positions by at most 0.009 mm; this is numerical
|
||
prior stability, NOT proof of the actual spatial distribution of drift.
|
||
Using the other qualifying 20/30-second closure measurement instead changes
|
||
the corrected trajectory by up to 0.2483 m (p95 0.2262 m). This measurement-window
|
||
sensitivity is materially larger than regularizer sensitivity and is retained
|
||
as model uncertainty, not hidden by the visually closed seam.
|
||
|
||
All 49,217,854 materialized points and all 13,624 corrected poses were reproduced
|
||
from the frozen field. Within-frame motion is rigid. Maximum coordinate
|
||
serialization error is 0.0306 mm; sampled intra-frame pair-distance error is
|
||
0.0601 mm. No count, intensity, frame order or raw source was discarded.
|
||
|
||
## Independent archived passes and complete-route search
|
||
|
||
The production versioned-map extractor and tiled reference builder were reused
|
||
through a private adapter, not through an admitted catalog generation. The
|
||
whole route yields 1,924,498 original and 1,940,166 corrected registration
|
||
points. Preparation took 25.48 / 26.67 s. No 30 m crop or whole-map point-count
|
||
cap was introduced. Presentation's 80 m envelope is not the local numerical
|
||
matching profile.
|
||
|
||
The first independent query is the original cold prefix from study
|
||
`473870e0-5210-452c-b9e4-9d7937e93646`, captured in a different session. Only its
|
||
original query points and sensor origin are loaded, not its old reference or
|
||
accepted transform. Full production v7 search tests all 2,034 fits: 108 dense
|
||
start hypotheses and 1,926 route hypotheses.
|
||
|
||
| Same independent cold input | Original atlas | Corrected atlas |
|
||
| --- | ---: | ---: |
|
||
| Complete search | 2,034/2,034 | 2,034/2,034 |
|
||
| Result | Candidate | Candidate |
|
||
| Time | 320.41 s | 317.07 s |
|
||
| Overlap | 98.899% | 98.978% |
|
||
| Inlier RMSE | 0.1493 m | 0.1449 m |
|
||
|
||
This does not demonstrate a material speedup or inability to localize against
|
||
the original. Correction's demonstrated benefit is cross-visit map agreement.
|
||
|
||
The corrected atlas then accepts all 29 stored fresh snapshots over the
|
||
101.633 m independent walk using a causal previous-accepted-transform chain.
|
||
Overlap is 98.546–99.823%, inlier RMSE 0.1181–0.1501 m; measured local calculation
|
||
time is 0.073–0.105 s. Real recorded request/receipt clocks are retained; measured
|
||
rerun calculation duration is substituted. This is an archived-snapshot replay,
|
||
NOT a live ingress, camera, scheduler, motion-stationarity or recovery test.
|
||
|
||
The original atlas also accepts all 29 snapshots of that short pass. Thus this
|
||
test proves compatibility of the corrected version, not a general superiority
|
||
claim for every metric.
|
||
|
||
A second independent cold prefix from study
|
||
`0324337e-b590-4561-b19a-8fbc7835b888` also qualifies after all 2,034 fits:
|
||
352.94 s, 99.108% overlap, 0.1438 m inlier RMSE. Replaying its entire old smaller
|
||
ring against the new larger one is **not all-positive**: 30/101 snapshots qualify,
|
||
with first rejection at 132.265 m. Reference-path proximity under the last
|
||
accepted transform grows from 12.2 m at the last positive window to 18.2 m at
|
||
first rejection, then approximately 72 m. This supports a different-route /
|
||
out-of-localization-coverage explanation, not a claim that the two rings cover
|
||
the same corridor. It is not ground truth during the lost interval.
|
||
|
||
Near the old pass's return to the shared area, overlap again reaches 99.25–99.64%
|
||
and inlier RMSE about 0.139 m, but correcting the obsolete local prior requires
|
||
3.15–3.20 m and is correctly rejected by ordinary tracking policy. This replay
|
||
deliberately has no complete recovery/bootstrap state machine. It neither proves
|
||
nor disproves physical reinitialization after returning; a fresh stationary
|
||
relocalization is a separate operation, not continued green tracking on the old
|
||
hint. The original and failed cases are retained in full.
|
||
|
||
The middle-route probe selects held-out time group 68 without looking for a
|
||
favorable fit: source progress 794.812 m, 11,625 query points. All 2,855 held-out
|
||
frames are excluded from the atlas; query coordinates are translated to a new
|
||
origin and rotated 90 degrees. The generating correction is used only to
|
||
measure post-fit model consistency, never as the search seed.
|
||
|
||
Complete search qualifies after 2,034/2,034 fits in 452.16 s: overlap 98.545%,
|
||
inlier RMSE 0.1625 m, selected retrieval anchor at 800 m. Fitted sensor position
|
||
is 0.0461 m from the generating model, NOT surveyed truth. This is a same-source
|
||
numeric place-retrieval test with shared upstream K1 mapping. The source query
|
||
spans 3.804 m of motion; it is explicitly not a valid stationary bootstrap
|
||
prefix and must not be presented as live cold-start acceptance at the midpoint.
|
||
|
||
In total, four complete cold numerical searches performed 8,136 fits. Runtime
|
||
on this Mac ranges from 5.28 to 7.54 minutes. These are measured functional
|
||
experiments, not a stress test or a guarantee for larger routes or the onboard
|
||
computer. The full finite queue and ambiguity checks remain intact.
|
||
|
||
## Negative controls and software regressions
|
||
|
||
On real query geometry, local initial-X perturbations 0/1 m converge; 3 m is
|
||
rejected by the unchanged correction guard; 5/10/20 m fail numeric-quality
|
||
criteria and 1,000 m has no target coverage. These are software initial-guess
|
||
perturbations, NOT physical scanner-displacement acceptance. Full-route search
|
||
is a different operation and is not restricted by those local outcomes.
|
||
|
||
The fixed halfway wrong-region comparison is rejected on surface RMSE.
|
||
Applying real positive geometry with future, nine-second-old or prior-segment
|
||
receipt metadata is rejected in all three cases. Zero false confirmations in
|
||
this small set is not a false-acceptance-rate estimate.
|
||
|
||
All 178 focused software regressions pass: correction, registration, full-route
|
||
coverage/ambiguity/worker ownership, bootstrap freshness, recovery, replay,
|
||
live lifetime/multiple traversals, reference preparation and map-version/default
|
||
boundaries. A pre-existing Starlette/httpx deprecation warning remains. These
|
||
fixtures do not constitute physical multi-lap or onboard-computer acceptance.
|
||
|
||
## Decision boundary
|
||
|
||
The data support an experimental correction of this larger loop without
|
||
forcing the real endpoints together. The existing automatic recipe is NOT
|
||
qualified unchanged: seam acquisition and window-support selection require a
|
||
separate production change. Do not lower tracking-quality gates to conceal
|
||
that distinction.
|
||
|
||
Not proven: independent repeat accuracy throughout the newly added territory,
|
||
absolute map/pose error, correct internal drift distribution, arbitrary-loop
|
||
discovery, seasonal transfer, simultaneous live latency, target-board budget,
|
||
physical multiple laps, navigation safety or motor authority. No further live
|
||
scanner trial is needed to reproduce the present offline evidence.
|
||
|
||
The next production increment should separate offline closure acquisition from
|
||
local tracking correction, qualify window-support selection and preserve the
|
||
measured quality/cycle/holdout gates. Do not ship the experiment by silently
|
||
changing the global live 3 m guard or forcing final coordinates onto the start.
|
||
Only after that separate change and versioned admission should the candidate
|
||
be offered as the recording's corrected default. The current default is not
|
||
changed by this audit.
|
||
|
||
## Runtime and final evidence seal
|
||
|
||
Heavy checks ran sequentially with a single numerical worker on the operator
|
||
Mac; no stress workload or second application server was introduced. The final
|
||
seal verifies 311 input files unchanged and inventories 62 private artifacts.
|
||
The only non-ignored repository addition from this audit is this report.
|
||
Production modules, original experiment scripts and raw capture remain intact.
|
||
|
||
The canonical service remains the same PID 73593 on port 8000. Final health is
|
||
operational with zero consecutive reconciler failures; no temporary audit/search
|
||
worker or port-8765 listener remains. No restart or hardware action was taken.
|