4.9 KiB
ADR 0040: Dual-evidence replay threat boundary
Date: 2026-08-05 Status: accepted and implemented for M4.6
Context
Historical camera-first experiments correctly kept camera semantics separate from LiDAR metric support, but the phrase "camera-first" is not an acceptable product threat architecture. The RAVNOVES00 camera detector visibly misses some unclassified occupied structures, while camera proposals without qualified LiDAR support cannot establish metric clearance. Making either sensor a gate for the other would discard useful evidence.
The portable RAVNOVES00 recording also has no admitted measured vehicle body or qualified LiDAR-to-body mount. A recorded threat experiment therefore needs an explicit virtual geometry without weakening the physical rig contract in ADR 0035.
The first M4.6 implementation incorrectly treated the instantaneous LiDAR frame
as the virtual body frame. The K1 calibration proves that camera-forward is near
LiDAR -Y, not +X, and the handheld pose contains real roll and pitch. That
made the replay corridor approximately 90 degrees off the route and rotated the
SLAM world with the operator's hand. Result m4-threat-replay-7e1613... is
superseded and is not admissible M4.6 evidence.
Decision
Mission Core threat assessment consumes two independent evidence paths:
camera proposals ---------------------> camera-only uncertainty
| |
+---- optional association ----+ |
v v
LiDAR occupied geometry ----------> LocalObstacleMap ---> ThreatAssessment
Neither path is called first:
- camera publishes image-space object proposals and optional semantics;
- LiDAR publishes metric occupied components, including geometry with no class;
- association enriches evidence but is not an admission gate;
- current metric geometry may produce
threatornot-threatfrom corridor geometry and bounded relative motion; - camera-only, held, expired or otherwise incomplete evidence produces
unknown, never a safe decision; - semantic class, detector ID and persistent identity are excluded from the threat calculation.
M4.6 fixes a versioned replay hypothesis: body length 1.0 m, width 0.6 m,
nominal sensor height 1.25 m, forward corridor 8 m, rear margin 0.5 m,
lateral clearance 0.2 m and prediction horizon 5 s. These values may be used
only with replay-simulated authority. They do not populate or qualify
missioncore.rig-geometry/v1, and they cannot support physical collision,
navigation, safety or actuation claims.
The virtual collision frame is a gravity-stable base_footprint, not the
instantaneous sensor frame:
- the K1 vendor SLAM map remains the stable world in which mapped points live;
- the rolling local-surface model supplies only the vertical ground origin and a quality check, not a permanent level-world assumption;
- forward is the smoothed SLAM trajectory tangent and is independently checked against the calibrated camera optical axis;
- unavailable height, excessive local slope or camera/route disagreement makes that frame unqualified instead of silently rotating the corridor;
- a mounted vehicle replaces this replay-only derivation with one measured,
rigid
T_body_from_sensor; the detector, obstacle map and threat policy do not change.
The sensor may therefore be mounted at a non-level angle or noncentral position
as long as it is rigid and its one-time body extrinsic is known. Vehicle roll
and pitch do not corrupt the SLAM map; a future 3D swept-volume planner may use
base_link, while the current 2D corridor remains explicitly tied to
base_footprint.
Evidence and presentation
The accepted replay must publish immutable frame, fixture, report and visual ledgers. Visual evidence uses the common LAB viewer and reusable renderers:
- full recorded camera video with synchronized proposal boxes;
- exact camera samples with metric range or explicit missing range;
- synchronized point cloud, occupied cells, virtual body and corridor in 3D and plan view;
- mandatory regression frames
138and274, which exposed the original sensor/body-axis failure; - visible threat/not-threat/unknown and
replay-simulatedauthority.
Visuals are an inspection surface, not ground truth. Independent object-centric labels remain a separate gate.
Consequences
- Unclassified concrete, vegetation or road furniture can remain visible to the metric path without inventing a semantic label.
- A camera detection cannot become safe merely because LiDAR support is absent.
- New detectors and LiDAR geometry providers may replace either side behind the existing contracts without changing the threat provider.
- Physical body/mount qualification and live acceptance remain intentional debt.
- ADR 0035 remains valid for ownership of semantics, metric support and physical rig qualification; this ADR supersedes camera-first wording for the canonical product decision graph.