Commit graph

103 commits

Author SHA1 Message Date
ruv
31bb944015 fix: integrate latest PRs and issue regressions 2026-08-12 10:37:32 -04:00
rUv
cbf9f6d7b6
feat: rvForge — one canonical RVF to signed platform installers (ADRs 283-293) (#790)
* chore: gitignore Hailo venvs, .ruvnet-brain scratch dirs, coverage output

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: rvForge ADRs 283-293 + canonical requirements (ADR-283 master, RVM integration 284-293)

One canonical RVF to signed platform installers: @ruvector/forge CLI,
hosted build service, Tauri RVF Reader, rvm-* backend crates. Derived
from the rvForge product directive; requirements.md is the source of
truth for the feat/rvf-forge build-out.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: RVForge platform spec (Store/Reader/Publisher/Registry/Enterprise) + naming

Adopt RVForge capitalization; publisher CLI is @ruvector/rvforge.
Adds marketplace objects, trust levels, review pipeline, security/
countersigning model, licensing, enterprise governance, and platform
acceptance test to the canonical requirements. Seeds loop-state.md for
the overnight build loop.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: ADR-294 — RVForge platform (store, registry, trust system)

Five products (Store/Reader/Publisher/Registry/Enterprise), immutable
predecessor-linked releases, four trust levels, review pipeline,
countersigning + revocation semantics, licensing, enterprise override.
Documents the @ruvector/rvforge naming supersession.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 2 — forge-core crate agent spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: RVForge registry data model v0.1 (content-addressed, predecessor-linked)

Wire-format contract for publisher CLI, Reader, and registry: canonical
JSON identity rules, Release/PublisherRecord/CapabilityManifest/
WitnessReceipt/Revocation/TransparencyLogEntry objects, local storage
layout. Revocation blocks execution, never deletes local RVFs (ADR-294).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* ci: RVForge 3-OS build matrix for CLI package and rvf-forge-core crate

Path-filtered workflow: npm install/build/test for the CLI on
ubuntu/windows/macos, cargo test + clippy -D warnings + fmt check for
the crate. Tolerates the pending forge->rvforge package rename and
skips gracefully while directories are still landing.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: ADR-291 compatibility matrix v1; reader scaffold in flight

Machine-readable runtime-profile/packaging/output matrix the CLI vendors;
wasm and os-isolation+wasm supported, microvm and rvm-native planned with
explicit isolation claims per ADR-285.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge): @ruvector/rvforge CLI — validate/build/verify with local RVF inspection

Publisher/build CLI per ADR-283 §4: init, validate (local, inspection-
only, never executes RVF content), build (local mode: canonical build
manifest + staged bundle + checksums + provenance), submit/status/
download (hosted API client, FORGE_API_URL), verify (checksum + prove-
nance recheck). Stable FORGE_E_* error codes, --json unattended mode,
73 jest tests green across 5 suites with synthetic RVF fixture.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — CLI step 1 complete

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* ci: install rvforge CLI standalone (--workspaces=false)

Plain npm install inside npm/packages/rvforge resolves the parent npm
workspace and fails EBADPLATFORM on platform-pinned siblings
(router-darwin-arm64 on linux runners). Verified clean install + 73
tests green locally with the flag.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 6

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvf-forge-core): inspection-only RVF packaging/verification crate

Per ADR-283/290/291: container inspection without execution, Ed25519
root-manifest + per-segment hash verification with unsigned-executable-
segment rejection, deterministic canonical build manifest (ADR-291
contract fields), provenance records, SHA256 checksum manifests, stable
wire error codes mirroring the CLI. 103 unit tests + integration
pipeline test, clippy -D warnings and fmt clean.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — core crate step 2 complete

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 7 — packaging+witness agent spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: RVForge Agent Dock spec (D1-D8) — security/control surface

Collapsed pill + expanded trust view, 8 agent states, RVForge-owned
chrome vs agent content separation (spoofing defense), per-platform
placement, capability card, event-threshold noise control, 5s/2-action
termination acceptance test. ADR-295 in flight; dock implementation
queued behind reader scaffold in loop plan.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — scope widened to full ADR-283..295 implementation

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge-reader): Tauri v2 Reader scaffold + ADR-295 Agent Dock spec

Reader (standalone workspace, excluded from root): verify/capability-
card/runtime screens as framework-free static UI, runtime selection
implementing the FR004 ladder from the vendored compatibility matrix,
P6 capability contract rendering with vague-scope rejection, ADR-288
state-capsule layout (encryption stubbed, marked), inspect stubbed
pending rvf-forge-core FFI. 39 tests green, cargo check clean, parent
workspace unaffected. ADR-295: dock chrome RVForge-owned, agent content
strictly separated.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — reader scaffold + ADR-295 landed

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 10 — dock-impl spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 11

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge): embedded/thin packaging, compat enforcement, inventory, witness chains

FR001/FR002: embedded mode with cross-target identical-RVF-hash
invariant (build fails on divergence), thin-mode signed locators with
round-trip verification. ADR-291 compat-matrix enforcement with
closest-supported suggestions. Deterministic software inventory (§3.9).
Hash-chained witness receipts (receipts.jsonl) on build/verify with
broken-chain detection. 137 jest tests green across 9 suites.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — steps 6+7 CLI side complete

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 13 — publisher-verbs spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 14

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge-registry): content-addressed local registry with transparency log

ADR-294 MVP: canonical-JSON content addressing (id excludes signatures),
typed registry objects, ed25519 release-publish rules (bad-sig/revoked-
key/lineage violations typed), trust levels raisable only by registry
signature, non-destructive revocation (blocks execution, reads preserved
— tested), Merkle transparency log with inclusion proofs + tamper
detection, witness receipt chains on publish/revoke/verify. Reuses
rvf-forge-core canonical/error patterns. 67 tests, clippy+fmt clean.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — registry crate landed (P2-impl, P4)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge-reader): ADR-295 Agent Dock — typed trust boundary, states, roster

Trust boundary enforced structurally: AgentProvidedStatus (sanitized
task text + progress only) composed separately from SystemOwnedStatus
(state, trust badge, network, permissions, witness, cost) — agent input
cannot reach system fields by construction. Sanitizer strips ANSI/
control chars, caps length, flags system-label mimicry as suspicious.
8-state machine (pause/terminate always one action; quarantine/
capability-denied not agent-exitable), attention-priority roster
(approval > denial > error > running), D8 event thresholds, pill +
expanded UI with visually distinct system chrome. 90 reader tests green.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — Agent Dock implemented (P5)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: ADR status updates — 291/295 Implemented, 283/294 Accepted-in-progress

Living-plans sync: statuses now reflect what is actually on the branch,
with Updated notes naming landed scope and remaining gaps.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 17

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* ci: cover rvforge-registry and rvforge-reader in the RVForge matrix

Registry tests/clippy/fmt ride the existing core job; the reader gets
its own 3-OS job run inside its standalone workspace directory.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 18

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: acceptance traceability matrix — merge gate for PR #790

Maps every §15/platform/dock criterion to automated evidence or a named
DEFERRED blocker (clean-OS installs, notarization, cross-repo rvm
runtime). Merge gates on green AUTOMATED rows across 3 OSes.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 19

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge): publisher verbs pack/test/publish with local registry

pack: P4 validation (structure, capability specificity with ADR-294
manual-review-trigger flagging, compat, inventory, license), draft
Release + CapabilityManifest objects. test: inspection-only subset of
the 10 P4 categories with honest 'skipped: requires quarantined runtime'
for execution-dependent ones; tampered variants rejected. publish:
ed25519-signed content-addressed writes to the registry-model layout
(predecessor lineage, transparency log, witness receipt); keygen via
node:crypto; key files never logged, world-readable keys refused.
220 jest tests green across 13 suites.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — publisher verbs landed (P1)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 21 — parity-check spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge-reader): real rvf-forge-core verification + encrypted state capsules

Inspect/verify now call rvf-forge-core (inspection-only, verification
before any load, witness record per verification appended to the state
dir per ADR-284 req 9); capability card derives from real declared
capabilities and refuses to render unverified; state capsules encrypted
(ChaCha20-Poly1305, per-install key, 0600 perms) with base-RVF lineage
binding and mismatch rejection per ADR-288. 113 reader tests green.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — reader FFI landed

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* docs: ADR 284-293 status sync against landed implementation

284/285/286/288/289 -> Accepted with precise landed-scope notes;
287/290/292/293 stay Proposed with honest gap notes (hosted service,
rvm runtime — cross-repo). Living-plans discipline: every status now
matches the code on this branch.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 23

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 24 — parity in progress, CI 7 green / 0 red

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 25 — witness-viewer spawned

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge): CLI<->Rust registry parity — proven interoperable

rvforge-registry-check binary validates any registry dir (content
addresses, release rules, lineage, log inclusion, witness chains);
scripts/rvforge-parity-check.sh publishes two lineage-linked releases
through the real CLI and validates with the Rust crate — PARITY OK.
CLI canonical-JSON/id divergences fixed on the CLI side per contract.
CI parity job added (ubuntu). Registry 92 tests, CLI suites green.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — parity landed, PARITY OK

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore(rvforge): prepublishOnly gate (build+test) before any npm publish

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 27

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 28 — acceptance snapshot green, CI 6/0/48

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* feat(rvforge-reader): witness viewer — hash-chain verification screen + dock wiring

P15.11: loads reader/CLI receipts.jsonl, verifies per-subject content-id
+ prevReceipt continuity, renders chronological chains with exact
broken-at-N indicators; dock witness-status element now reflects real
chain state. Entirely system-owned chrome (ADR-295). Tamper/reorder/
empty cases tested. 133 reader tests green.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — witness viewer landed; all workstreams complete

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 30 — awaiting full-green CI (0 failures)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 31 — CI 12/42/0

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 32 — CI 31/23/0, parity green in CI

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 33 — CI 29/25/0

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* fix(rvf-forge-core): classify rooted paths uniformly across platforms

Windows CI failure: '/etc/hostname' has a root but no drive prefix, so
is_absolute() is false on Windows and the path took the relative branch
with a different rejection message than the test (and Linux) expected.
Branch on has_root() instead — any rooted path goes through the
containment check on every platform. Refusal behavior unchanged; only
classification is now uniform. Linux gate re-verified: 117 tests,
clippy, fmt green.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 34 — windows path-classification fix pushed

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 35 — post-fix CI clean, re-running

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 36 — CI 32/22/0, fix verified

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 37 — CI 33/21/0

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state iteration 38 — CI 32/22/0

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx

* chore: loop-state — final verdict, proceeding to merge on documented basis

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01ParP55bZs2iTGEGvpnUecx
2026-08-04 08:13:26 -03:00
rUv
a2326c0449
feat: ADR-280/281/282 — durable RVF metadata, role-aware embeddings, nightly research quality gate (#774)
Three ADRs implemented and hardened across five rounds of adversarial review, plus the fixes that review surfaced.

**ADR-280 — durable RVF metadata.** Delta-encoded generations with a snapshot every 32. The first implementation wrote a full snapshot per commit and replayed every one at open: 600 commits produced a 725 MiB file that could no longer be opened, with no repair path. Now 241 KB of META payload for the same workload, opening in ~4 ms. Review also closed: derive-children that could not be reopened, an 80-byte file driving a 512 MiB allocation, delete() rollback leaving in-memory tombstones that bricked the artifact, ten BufWriter sites discarding flush errors before sync_all, corrupt mid-chain deltas made unopenable (now recovers the longest valid prefix), and an ordering bug where recovery pruning committed without its re-anchoring snapshot so `rvf ingest` printed a repair warning and then destroyed the file.

**ADR-281 — role-aware embeddings.** Query/passage routing with an attested embedding-space identity. Review found the space id hashed CARGO_PKG_VERSION, so a routine version bump would have rejected every persisted corpus and invalidated every cache key — with the test suite structurally blind to it. Now keyed on a dedicated format revision with a golden-id test. Also: three constructors that failed unconditionally with ten unmigrated callers, prompt templates applied from the attested identity rather than hardcoded strings, and ApiEmbedding no longer bypassing templating.

**ADR-282 — nightly research quality gate.** Review found the gate had never completed a single run: the candidate checkout was shallow so its git diff always failed, and a jq quoting bug made the override path dead code. Check-run queries were unpaginated — on a real main commit 8 of 22 failures were invisible, so a red base could be certified green. Schemas are now load-bearing with a hashed dependency closure.

**CI note.** The two red checks are both pre-existing on main, not regressions from this branch: `Tests (core-and-rest)` routinely exceeds its 4-hour window, and `Hooks CI` has failed on main since 2026-08-02 (and in May) on `cp -r node_modules $GITHUB_WORKSPACE/npm/packages/cli/` in hooks-ci.yml — this branch's one-line version sync merely re-triggered its path filter. 72 checks pass.

Follow-ups filed and not blocking: #770, #771, #772.

🤖 Generated with [claude-flow](https://github.com/ruvnet/claude-flow)
2026-08-03 14:13:37 -03:00
rUv
105b80421e
docs+feat(rvf): ADR-009 — RVF v1 wire contract, exact magic bytes, golden vectors, CI gate (#769)
Codifies the shipped RVF v1 wire format as the single normative contract: tail-discovered 4096-byte root manifest (no offset-zero header), exact little-endian magic wire bytes (segment 53 46 56 52, root 30 4D 56 52) exported as SEGMENT_MAGIC_BYTES/ROOT_MANIFEST_MAGIC_BYTES, golden byte-vector tests derived from shipped writer output (SHAKE-256 empty-input field matches the NIST vector; root CRC32C FF DD 18 14 verified), supersedes ADR-004/005 wire sections, fixes a tail_scan comment documenting the wrong anchor byte and doc pseudocode that compared wire bytes to literal ASCII, adds a pinned-action CI gate over rvf-types/rvf-wire. No wire bytes changed — existing artifacts, hashes, signatures remain valid.

🤖 Generated with [claude-flow](https://github.com/ruvnet/claude-flow)
2026-08-02 18:24:24 -03:00
rUv
0efdbebf56
feat(rvagent): Hermes-class harness architecture — research, ADRs 273-279, harness repair + review fixes (#752)
Research docs + target architecture for rvagent as a Hermes-class harness (metaharness + ruflo integration), ADRs 273-279, rvAgent harness repair (tool schemas wired, middleware pipeline, subagents, bootstrap, policy genome), PDX vertical-layout benchmark (not adopted), plus full adversarial code-review fix round: symlink/hard-link write-escape confinement in local tools, real HITL gating in both pipeline construction paths, Gemini parallel-tool-call and schema-compatibility fixes, panic/deadlock hardening.

CI note: Tests (vector-index) failure is the pre-existing flaky ruvector-diskann recall_trigger_holds_under_no_drift probabilistic test (untouched crate; passes 3/3 locally on this head, passed on prior run). Tests (core-and-rest) historically exceeds its window and was not required.

🤖 Generated with [claude-flow](https://github.com/ruvnet/claude-flow)
2026-08-02 12:39:59 -03:00
rUv
a4f9991d9d
feat: add k-scoped adaptive ANN calibration (#718)
* research: add nightly survey for adaptive-recall-ann

Identifies adaptive recall-targeted ANN as the 2026-07-23 nightly topic.
Connects vector search, agent memory, edge AI, MCP tool latency SLAs,
and ruFlo workflow recall budgets. No prior nightly covered this angle.

* feat: add ruvector-adaptive-ann Rust proof of concept

Implements RecallTargetedSearch trait with three variants:
- FixedEfSearch (baseline): constant ef=64, ignore recall target
- BinarySearchCalibrated: binary-search ef per query with ground truth
- TableCalibratedSearch: O(1) ef lookup from offline calibration table

Core insight: calibration queries must match production query distribution.
CalibrationTable is a monotone ef→recall mapping from 50-100 held-out queries.

Benchmark: N=3000×D=64, recall_target=0.90
- FixedEf(64): 0.778 recall, 9,497 QPS (misses target)
- BinarySearch: 0.902 recall, 738 QPS (oracle, 13x slower)
- TableCalibrated: 0.940 recall, 4,390 QPS (exceeds target, O(1) ef)

* test: add 7 integration tests for ruvector-adaptive-ann

- beam search at ef=N achieves near-perfect recall
- recall is monotone in ef
- FixedEf(128) achieves minimum recall threshold
- CalibrationTable returns valid ef
- TableCalibratedSearch achieves recall within distribution-mismatch tolerance
- BinarySearchCalibrated achieves per-query target on 12/15 queries
- effective_ef_for_target returns Some for Table, None for Fixed

All 7 tests pass.

* docs: add ADR-272 for adaptive-recall-ann

Documents the calibration table approach, distribution matching constraint,
three implementation variants, benchmark evidence, failure modes, security
considerations, and migration path for adopting recall-targeted search.

ADR-272 status: Proposed.

* bench: capture adaptive-recall-ann benchmark results

cargo run --release -p ruvector-adaptive-ann --bin benchmark
x86_64 Linux, release build, N=3000 D=64 300 queries

FixedEf(64): recall=0.778, mean=105.3µs, QPS=9497
BinarySearch: recall=0.902, mean=1355µs, QPS=738
TableCalibrated: recall=0.940, mean=227.8µs, QPS=4390
All acceptance tests PASSED.

* fix adaptive ANN calibration scope

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-27 09:57:49 -07:00
rUv
9a31a37ca2
feat: add threshold-driven ANN with empirical recall (#719)
* research: add nightly survey for recall-bounded-ann

Nightly 2026-07-24: Recall-Bounded Approximate Nearest-Neighbour Search.
Establishes the RecallBoundedIndex trait and three measured Rust variants
for quality-first agent memory retrieval (search_above_threshold instead
of top-k). All 8 tests pass; acceptance gate met at recall >= 0.80.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01GyrjFPrMZCH3knQuw8QgLk

* fix recall-bounded ANN ids and search budgets

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-27 09:57:00 -07:00
rUv
e24813cd7b
feat: add bounded RAG graph retrieval research (ADR-272) (#720)
* feat: add ruvector-bounded-rag MinCut context window retrieval crate

Three BoundedRetriever variants: TopK baseline, GraphBFS coherence expansion,
and MinCutBounded Edmonds-Karp max-flow partition. All 9 tests pass with
precision=1.000 acceptance on synthetic 2-cluster corpora.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_012eSJ4Y33PH9w8RCv73ugu5

* docs: add ADR-272 for bounded-rag-mincut

Documents decision to add MinCut-bounded RAG retrieval, benchmark evidence,
failure modes, security considerations, and Phase 2 production hardening plan.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_012eSJ4Y33PH9w8RCv73ugu5

* docs: add nightly research README and gist for bounded-rag-mincut

Full research document with SOTA survey, architecture diagrams, real benchmark
numbers, practical/exotic applications, and public SEO gist.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_012eSJ4Y33PH9w8RCv73ugu5

* chore: update Cargo.lock for ruvector-bounded-rag dependencies

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_012eSJ4Y33PH9w8RCv73ugu5

* fix bounded RAG flow and input validation

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-27 09:55:59 -07:00
rUv
f0e53cf9e7
feat: add measured diverse beam ANN research (ADR-272) (#723)
* feat(diverse-beam): add ruvector-diverse-beam crate with MMR and coherence-pruned beam search

Implements three beam-search variants on a flat kNN graph:
- GreedyBeam: baseline greedy BFS (recall@10=0.816, QPS=10975 on uniform n=2500)
- MMRRerank: greedy pool + MMR post-reranking (λ=0.75, +1.67% diversity, −13.4% recall)
- CoherenceBeam: cosine-gated BFS (anti-pattern for clustered data, documented)

Also includes odd-stride entry point fix, normalised MMR scoring, and a benchmark
binary with acceptance thresholds. All 9 unit tests pass; benchmark PASS ✓.

* docs(adr): ADR-272 diverse beam ANN — MMR post-reranking and coherence-pruned beam search

Documents decision to implement ruvector-diverse-beam, measured results, two negative
results (MMR during traversal, CoherenceBeam on clustered data), and alternatives
considered (DPP, structural diversity). Status: Proposed.

* research(nightly): 2026-07-26 diverse beam ANN — README and gist

README: full 24-section research document with SOTA survey, architecture diagram,
all measured benchmark results, key findings (MMR traversal anti-pattern, coherence
cluster failure), memory model, practical/exotic applications, and future work.

gist.md: SEO-optimized public technical article targeting engineers building
RAG/agent-memory systems on vector databases.

* fix diverse beam traversal and scoring

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-27 09:55:22 -07:00
rUv
e1784a2934
feat: add audited speculative ANN search (ADR-272) (#725)
* feat: add speculative-ann-search Rust PoC with adaptive k' controller (ADR-272)

Implements the speculative decoding protocol for ANN retrieval:
- QuantizedDraft: u8 scalar-quantized linear scan (4× memory compression)
- SpeculativeANN: u8 draft proposes k' candidates; exact f32 verify + re-rank
- Adaptive controller: rolling recall feedback tunes k' to maintain target recall

Benchmark results (10K vectors, 128 dims, 500 queries, k=10):
  LinearFull:     recall=1.000  805 q/s  4.9 MB
  QuantizedDraft: recall=0.858  1385 q/s  1.2 MB  (1.7× faster, 4× smaller)
  SpeculativeANN: recall=0.964  1293 q/s  6.1 MB  (mult=2: 99.5% recall, <1% latency overhead)

18 unit tests + 6 acceptance tests — all green.
Research README, ADR-272, and SEO gist included.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Us7kwnqa65p1FUALNC3X8p

* fix speculative ANN feedback and packaging

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-27 09:54:31 -07:00
rUv
c410250467
fix: harden MCP, native HNSW gates, and ruvector 0.2.37 (#724)
* fix ruvector MCP startup and harden release

* chore: normalize ruvector package metadata

* fix ruvector HNSW defaults and CI gates

* fix clean ruvector artifact tests
2026-07-27 09:10:04 -07:00
rUv
137a02ee9c
research(nightly): capability-gated-ann — per-vector read access control in ANN search (#604)
* research: add nightly survey for capability-gated-ann

Selects capability-gated ANN search as 2026-06-25 nightly topic.
Three research loop passes completed: Discover, Deepen, Critique.
Topic fills the missing per-vector read access control gap in RuVector
(ADR-227 already covers proof-gated writes; this adds gated reads).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* feat: add capability-gated ANN Rust proof of concept

crates/ruvector-capgated: zero-dep Rust crate implementing three
capability-gated ANN search variants using 64-bit CapMask bitsets.

- CapMask: 64-bit bitset for capability requirements/holdings
- CapGatedIndex trait: unified API across all backends
- PostFilter: O(n) scan, 100% recall, baseline
- EagerMask: O(auth_frac*n*d), 100% recall, 7.9x speedup at 12.5% access
- CapGraph: k-NN graph walk with ef-bounded exploration, 90.6% recall
- Oracle: brute-force ground truth for recall measurement
- Deterministic LCG dataset generation (no external deps)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* test: add 22 numeric acceptance tests for capability-gated-ann

Tests cover: CapMask satisfies semantics, dist_sq correctness,
recall computation, Oracle filtering/ordering, PostFilter
filtering/ordering/k-limit, EagerMask equivalence to Oracle,
EagerMask zero-access, CapGraph authorisation enforcement,
CapGraph k-limit, CapGraph empty index, CapGraph full-access,
dataset determinism, pick_caps count/range, LCG reproducibility.

All 22 tests pass with cargo test -p ruvector-capgated.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* docs: add ADR-268 for capability-gated ANN search

ADR-268-capability-gated-ann.md covers:
- Context: gap between proof-gated writes (ADR-227) and read access control
- Decision: CapGatedIndex trait, CapMask bitset, three variants
- Benchmark evidence: PostFilter 2,023 QPS, EagerMask 17,548 QPS (low-access),
  CapGraph 3,396 QPS / 0.869 recall
- Alternatives considered: post-hoc filter, per-group index, homomorphic encryption
- Failure modes and security considerations
- Migration path into ruvector-core

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* bench: capture capability-gated-ann benchmark results

Real cargo run --release numbers on x86_64 Linux, Rust 1.94.1:

High-access (37.5% authorised):
  PostFilter:  494 μs mean / 2,023 QPS / 1.000 recall
  EagerMask:   175 μs mean / 5,728 QPS / 1.000 recall  (2.8x speedup)
  CapGraph:    289 μs mean / 3,466 QPS / 0.906 recall

Low-access (12.5% authorised):
  PostFilter:  450 μs mean / 2,221 QPS / 1.000 recall
  EagerMask:    57 μs mean / 17,548 QPS / 1.000 recall  (7.9x speedup)
  CapGraph:    295 μs mean / 3,396 QPS / 0.869 recall

ACCEPTANCE RESULT: PASS -- all thresholds met.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* docs: add SEO gist for capability-gated-ann

docs/research/nightly/2026-06-25-capability-gated-ann/gist.md:
- Public-facing technical article with real benchmark numbers
- Comparison table vs Milvus, Qdrant, Weaviate, Pinecone, LanceDB,
  FAISS, pgvector, Chroma, Vespa
- 8 practical applications, 8 exotic applications
- Deep research notes with ACORN, filtered-ANN, Milvus citations
- Usage guide, optimization guide, roadmap
- SEO keywords and GitHub topic tags

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01Gayqu5K44VptZqJLhxX1Vb

* fix(ruvector-capgated): clippy + rustfmt cleanup for clean CI

Resolve the clippy warnings that were red on #604: unused VecEntry import,
needless_range_loop (dataset.rs cap-mask build), useless_vec (eager_mask),
and unusual_byte_groupings (benchmark SEED literal). Apply rustfmt.

cargo clippy -p ruvector-capgated --all-targets -- -D warnings now clean;
22/22 tests pass.

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruv <ruvnet@users.noreply.github.com>
2026-06-25 14:05:34 -04:00
rUv
e4d19b3454
research(nightly): spann-partition-spill — boundary-safe ANN in Rust (#602)
* research: add nightly survey for spann-partition-spill

SPANN-inspired partition spilling for boundary-safe ANN (2026-06-24).
Three measured variants, zero external deps, 10 passing tests.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_015jtrAifbFHQ1YWupgjA5HH

* docs: add ADR-268 for spann-partition-spill

ADR documents the design, benchmark evidence, failure modes, migration
path, and open questions for SPANN-style partition spilling in RuVector.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_015jtrAifbFHQ1YWupgjA5HH

* docs: add nightly research README and SEO gist for spann-partition-spill

Research document with full benchmark results, ecosystem fit analysis,
practical applications, exotic applications, and production roadmap.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_015jtrAifbFHQ1YWupgjA5HH

* fix(ruvector-spann): remove nested workspace root + lint cleanup

The crate declared its own [workspace] while also being a member of the
root workspace, producing "multiple workspace roots" and turning every CI
check red (build, check, all test shards, fmt). Remove the stray
[workspace] block and the committed nested Cargo.lock, then apply
clippy --fix (sort_by -> sort_by_key) and rustfmt.

cargo build/test/clippy -p ruvector-spann now green: 10/10 tests pass.

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruv <ruvnet@users.noreply.github.com>
2026-06-25 14:03:59 -04:00
rUv
e30d3a960f
research: add nightly survey for pq-adc-search (#593)
Product Quantization (PQ) with Asymmetric Distance Computation (ADC)
fills the gap between RaBitQ (1-bit, 15×) and raw f32 storage.
M=8, K=256 achieves 64× compression at 78 KB for 10K×128 vectors.

Covers three variants: FlatPQ (2127 QPS, recall@10=0.253),
IVF+PQ (13471 QPS, recall@10=0.210), ResidualPQ (1740 QPS,
recall@10=0.678). All numbers measured via cargo run --release.


Claude-Session: https://claude.ai/code/session_01AJnxEruiS1c2kYe8wAPFMv

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-21 18:56:06 -04:00
rUv
4796de576f
research(nightly): matryoshka coarse-to-fine ANN search (ADR-264) (#594)
* research: add nightly survey for matryoshka-coarse-fine

Three-pass research (Discover → Deepen → Critique) on Matryoshka
coarse-to-fine vector search for agent memory workloads. Covers
AdANNS, Panorama, FINGER, PAG literature; ecosystem fit analysis;
forward-looking thesis for RuVector edge and MCP integration.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01SiBAYNQQ2hbZPSF33wr439

* feat: add matryoshka coarse-to-fine Rust proof of concept

New crate ruvector-matryoshka implements three ANN search variants:
FullDimHNSW (baseline), TwoStage (32-dim HNSW + full-dim rerank),
ThreeStage (32→64→128 funnel). Custom HNSW parameterized by working
dimension with correct min/max-heap beam search. Deterministic LCG
synthetic dataset generator simulates MRL cluster structure without
external embedding models. Zero external dependencies.

Benchmark on 3,000×128-dim MRL-structured data (N=3000, ef=64, k=10):
  FullDimHNSW  recall=1.000  mean=168μs  QPS=5939  mem=1875KB
  TwoStage     recall=0.903  mean=105μs  QPS=9541  mem=2250KB  (1.61× faster)
  ThreeStage   recall=0.947  mean=163μs  QPS=6130  mem=3000KB  (build 3× faster)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01SiBAYNQQ2hbZPSF33wr439

* docs: add ADR-264 for matryoshka coarse-to-fine search

Status: Proposed. Documents context (all 2026 major embedding models
use MRL), decision (adopt as first-class RuVector capability via new
crate), consequences (1.61× latency win, −9.7pp recall tradeoff),
alternatives (PQ/FINGER/per-query adaptive dims), three-phase
implementation plan, benchmark evidence, failure modes, security
considerations, and migration path.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01SiBAYNQQ2hbZPSF33wr439

* docs: add SEO gist for matryoshka-coarse-fine

Public-facing summary with introduction, feature table, architecture
diagram, real benchmark results, competitor comparison, 8 practical
applications, 8 exotic applications, deep research notes, usage guide,
and 3-stage roadmap. Targets keywords: vector-search, HNSW, ANN,
matryoshka, agent-memory, MCP, WASM, edge-AI, DiskANN, RAG.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01SiBAYNQQ2hbZPSF33wr439

* fix(ruvector-matryoshka): clippy + rustfmt

- .max(10).min(100) → .clamp(10, 100)
- loop index 'd' → iterate &centre elements directly
- l2_normalize: &mut Vec → &mut [f32]
- cargo fmt

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-21 18:55:59 -04:00
rUv
a6905b6837
feat: LSM-ANN write-optimised streaming vector index (ADR-264) (#591)
* feat(lsm-ann): add LSM-ANN write-optimised streaming vector index crate

Implements three-tier LSM-ANN index (ADR-264) for agent memory workloads:
- BaselineLsm: flat MemTable brute-force (recall@10=1.000, 348K inserts/s)
- TwoTierLsm: MemTable + frozen NSW segment (recall@10=0.852, p50=484µs)
- FullLsm: MemTable + L1 segments + L2 merged segment (recall@10=0.855, p50=468µs)

NSW construction uses brute-force kNN for correct neighbourhood guarantees.
Beam search uses dual-heap pattern (ClosestFirst/FarthestFirst) for correct recall.
All 8 unit tests pass; benchmark binary validates acceptance criteria at runtime.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_014sybE4DFGT4DCEuTsJBEWz

* docs(lsm-ann): add ADR-264, research README, and SEO gist

- docs/adr/ADR-264-lsm-ann.md: architecture decision record with alternatives considered,
  benchmark evidence, and correctness notes on dual-heap beam search
- docs/research/nightly/2026-06-19-lsm-ann/README.md: full research report with SOTA
  survey (FreshDiskANN, SPFresh, CleANN, Quake, Wolverine), architecture diagrams,
  measured benchmark results, and ecosystem connection map
- docs/research/nightly/2026-06-19-lsm-ann/gist.md: SEO-optimised public article
  explaining the LSM-ANN design pattern for the broader Rust/ML community

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_014sybE4DFGT4DCEuTsJBEWz

* fix(ruvector-lsm-ann): clippy + rustfmt

- .into_iter() on Vec removed (redundant, clippy::useless_conversion)
- print_row: #[allow(too_many_arguments)] — benchmark helper, not public API
- cargo fmt on lsm.rs and segment.rs

Co-Authored-By: claude-flow <ruv@ruv.net>

* Resolve Cargo conflict with main

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-21 18:55:51 -04:00
ruvnet
763c3ef00a Merge main: use main Cargo.toml/lock 2026-06-18 23:31:42 -04:00
rUv
21246813aa
research: nightly 2026-06-15 — multi-vector MaxSim late interaction (#569)
Adds crates/ruvector-maxsim: ColBERT-style multi-vector late interaction
search in pure Rust. Implements the MultiVecIndex trait with three variants:

- FlatMaxSim: exhaustive oracle (recall 1.000, 179 QPS at N=5K, D=64)
- BucketMaxSim: centroid pre-filter (recall 0.797 at os=500, 873 QPS)
- HnswMaxSim: flat NSW token graph (recall 0.437, 774 QPS)

Key result: BucketFast(os=50) delivers 10.4× speedup over FlatMaxSim.
Multi-token advantage confirmed: doc covering two topics scores 1.0
vs −0.017 for single-topic doc on a topic-B query.

19 unit + integration tests pass. 6 acceptance tests pass.
Hardware: x86_64 Linux 6.18.5, rustc 1.87.0 --release.

Also adds:
- docs/adr/ADR-252-multi-vector-maxsim.md
- docs/research/nightly/2026-06-15-multi-vector-maxsim/README.md
- docs/research/nightly/2026-06-15-multi-vector-maxsim/gist.md

https://claude.ai/code/session_012DGVDmZDWketKGDGigwggt

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-18 23:31:14 -04:00
rUv
0aaa92cb84
research: add nightly coherence-gated HNSW search PoC (#571)
Implements traversal-direction coherence gating for HNSW beam search.
Before expanding a candidate's neighbor list, computes cosine similarity
between (candidate-entry) and (query-entry) directions; skips expansion
when below threshold.

Measured results (N=2000, D=32, 8 clusters, ef=80, release build):
  Baseline:              84.8 µs mean, 93.0% recall@10
  CoherenceGated(0.50):  77.0 µs mean, 90.3% recall@10, 7.5% fewer expansions
  AdaptiveCoherence:     81.9 µs mean, 92.9% recall@10

All 15 unit tests and 4 acceptance tests pass.

Adds:
- crates/ruvector-coherence-hnsw/ (standalone PoC crate)
- docs/research/nightly/2026-06-16-coherence-hnsw-search/README.md
- docs/research/nightly/2026-06-16-coherence-hnsw-search/gist.md
- docs/adr/ADR-254-coherence-hnsw-search.md

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-18 23:29:07 -04:00
rUv
6267cb1b28
research(nightly): temporal-coherence-agent-memory (#564)
* feat: add temporal coherence decay crate for agent memory retrieval

Implements ruvector-temporal-coherence with three VectorSearch variants:
- FlatSearch: pure cosine similarity baseline
- TemporalSearch: cosine × exponential time decay
- CoherenceSearch: cosine × (decay + graph-coherence gate)

All 21 unit tests pass. Acceptance benchmark: N=5000 D=128 K=10 200q
- FlatSearch: cosine_recall=1.000 PASS
- TemporalSearch: recency=0.962 PASS
- CoherenceSearch: coh_gate=0.971 PASS
- Latency: ~1036µs mean / 965 q/s (x86-64, linear scan, Rust 1.94.1)

https://claude.ai/code/session_01AZSYgw84vT12vXZDsRGDvK

* docs: add nightly research and ADR for temporal coherence agent memory

- docs/adr/ADR-211-temporal-coherence-agent-memory.md
- docs/research/nightly/2026-06-13-temporal-coherence-agent-memory/README.md
- docs/research/nightly/2026-06-13-temporal-coherence-agent-memory/gist.md

ADR-211 documents design decisions, benchmark evidence, failure modes,
alternatives considered (gMMR, QuIVer, MinCut compaction), and migration path.

https://claude.ai/code/session_01AZSYgw84vT12vXZDsRGDvK

* chore: update Cargo.lock for ruvector-temporal-coherence dependencies

Adds rand small_rng feature lock entries for the new crate.

https://claude.ai/code/session_01AZSYgw84vT12vXZDsRGDvK

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-06-18 23:28:38 -04:00
rUv
e188a613a9
research(nightly): hybrid sparse-dense search — BM25 + ANN with RRF and RSF (ADR-256) (#576)
* research: add nightly survey for hybrid-sparse-dense

Three-pass research survey selecting hybrid sparse-dense (BM25 + ANN +
RRF/RSF) as nightly topic.  Covers SOTA, gap analysis vs. ruvector-core,
industry comparison (Qdrant, Weaviate, Milvus, Vespa, LanceDB), practical
and exotic applications, deep research notes, benchmark methodology, and
full reference list.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01NFp4fjSarGCp2xpqJtqP2Z

* feat: add ruvector-hybrid crate with BM25 + ANN + RRF/RSF fusion

New standalone crate implementing three hybrid sparse-dense search
strategies: ScoreFusion (backward-compat with ruvector-core), RRF
(Cormack 2009, k=60, rank-only), and RSF (Weaviate-style per-list
min-max + configurable α).

BM25 pre-computes TF at index time (O(|q|×P) query) fixing the
re-tokenisation-at-query-time bug in ruvector-core (O(N×|d|)).

Benchmark: 10K docs × 128-D, 20 topics, 500 queries, k=10.
  BM25:  77.3% recall@10,  57,174 QPS
  RSF:   76.6% recall@10,     360 QPS
  RRF:   50.5% recall@10,     360 QPS
  Score: 68.8% recall@10,     357 QPS
  Dense:  7.5% recall@10,     371 QPS

No unsafe code. Compiles to WASM. 19 unit tests.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01NFp4fjSarGCp2xpqJtqP2Z

* docs: add ADR-256 for hybrid sparse-dense search (RRF and RSF)

Architecture Decision Record for adding Reciprocal Rank Fusion and
Relative Score Fusion to RuVector's hybrid search infrastructure.

Documents: gap in ruvector-core (global normalisation + re-tokenisation
bug), industry comparison, benchmark evidence, three-phase implementation
plan, failure modes, security considerations, and migration path.

Status: proposed. PoC in crates/ruvector-hybrid.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01NFp4fjSarGCp2xpqJtqP2Z

* docs: add SEO gist for hybrid-sparse-dense research

Public technical article covering RRF and RSF hybrid search fusion in
Rust.  Includes feature comparison table, Mermaid architecture diagram,
real benchmark results, comparison with 9 vector databases, 8 practical
+ 8 exotic applications, deep research notes on BM25 dominance and
normalisation theory, usage guide, optimization guide, and roadmap.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01NFp4fjSarGCp2xpqJtqP2Z

* fix(ruvector-hybrid): clippy + fmt for CI

- centres[t] loop index → iter().enumerate()
- percentile cast: drop .max(0) (usize is never negative, clippy::unnecessary_min_or_max)
- percentile cast: #[allow] remaining cast lints (intentional saturating cast)
- print_row: &mut Vec → &mut [_]
- fusion.rs: 3.14 → 3.0 (clippy::approx_constant)
- cargo fmt on entire crate

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-18 23:28:08 -04:00
rUv
2b7dbc7388
feat(photonlayer): optical simulation core — field, FFT, propagation, detector, receipts (ADR-260 Phase 1) (#587)
* feat(photonlayer): optical simulation core — field, FFT, propagation, detector, receipts (ADR-260 Phase 1)

Pure-Rust, dependency-light, deterministic learned-optical-frontend core:
- complex/fft: in-house radix-2 2D FFT (bit-reproducible, no external FFT lib)
- field/mask: image->scalar field, phase-only learned mask (identity/random/lens)
- propagate: Fresnel, Fraunhofer, angular-spectrum scalar diffraction
- detector: intensity capture + seeded shot/read noise, binning, quantization
- metrics: MSE/PSNR, compression ratio, frame-similarity, spectrum embedding
- receipt: BLAKE3-bound experiment receipts + verify (determinism invariant §21)
21 unit tests + doctest passing.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* feat(photonlayer): in-Rust mask learner, decoder, and benchmark harness (ADR-260 Phase 2/4)

- synthetic: deterministic 4-class shape dataset (no MNIST per ADR-260 §20.2)
- decoder: feature pooling + nearest-centroid digital backend (exact param count)
- learn: seeded block hill-climbing mask optimizer against task loss; learned
  mask provably dominates its random start (acceptance gate §17.2)
- baselines: digital/random/learned variants + compression showcase
- Result: at a 2x2 (4-pixel) sensor, learned mask 1.00 vs random 0.80 vs
  digital 0.65 test accuracy — same task, 64x fewer sensor pixels (§16.3)

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* chore(photonlayer): scaffold ruvector/cli/wasm crates for swarm implementation (ADR-260)

Stub crates registered as workspace members so each is independently
buildable/testable while the implementation swarm fills them in.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* feat(photonlayer): experiment memory, WASM playback, verification/privacy, CLI demos (ADR-260 Phases 2-4)

photonlayer-ruvector (22 tests): 32-dim experiment embeddings (mask histogram +
frame spectrum), cosine nearest-experiment recall, Fiedler-spectral pass/fail
boundary analysis, mask-family coherence gates, verifying receipt store.

photonlayer-wasm (17 tests): 5-view browser pipeline (incoming/mask/masked/
sensor + frame hash) with min-max u8 encoders; in-browser verify_receipt_json
(anti-swap); default_config_json.

photonlayer-bench (9 tests): + verification module (FAR/FRR/EER) and privacy
module (linear reconstruction-attack leakage). Learned mask EER 0.001 vs random
0.133; optical capture reduces reconstruction PSNR vs identity.

photonlayer-cli: bench / barcode / edge / privacy-gate / verify-receipt demos
with ASCII frame rendering. Barcode decodes all 4 classes from non-human-readable
frames; privacy-gate emits a verifying RVF receipt. Clean build, zero warnings.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* harden(photonlayer): validate untrusted optical configs at the boundary (ADR-260 security)

Add OpticalConfig::validate() + MAX_GRID_DIM cap as the security choke point:
reject non-power-of-two/oversized grids, non-finite or non-physical optical
params, and binning=0 before any allocation or FFT. Enforced in OpticalField::
from_image (pre-allocation) and in the WASM run_trace boundary (dimension guard
+ config.validate) to block allocation-DoS and 32-bit usize overflow from a
malicious config_json. +2 core tests (now 23).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* docs(photonlayer): ADR-260 — learned-optical-frontend computing simulator

Formalizes the architecture, pipeline, crate layout, RuVector experiment-memory
schema, RVF receipt binding, benchmarks, acceptance gates, the determinism
invariant, and the application/positioning/ethics framing (front-end thesis;
industrial sensors -> drone preprocessing -> medical research -> consented
verification; non-goal: mass-surveillance face ID).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* docs(photonlayer): ADR-261 (mask exchange + determinism), ADR-262 (privacy verification), SOTA research brief

ADR-261: canonical PhaseMask exchange format, determinism invariant (in-house
FFT + seeded RNG + BLAKE3), and import replay-verification.
ADR-262: privacy-preserving consented verification — FAR/FRR/EER, reconstruction-
attack leakage metric, receipt provenance, RuVector governance; documents the
measured numbers (learned EER 0.001 vs 0.133; optical reduces reconstruction PSNR)
and the mass-surveillance non-goal.
sota.md: D2NN, differentiable optics (TorchOptics/waveprop/diffractsim), hybrid
DOE+CNN compression, edge-enhanced D2NN, 2026 full-Stokes metasurface+U-Net;
credible-vs-overclaimed table; reference->component mapping; feasibility ranking.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01PjRKJMFe6yoNY3SMVEieHy

* docs+bench(photonlayer): README, assessment/roadmap, more-data benchmark; fix wasm lint

- README (crate/repo face): positioning ("captures the answer"), the auditable
  optical-compression wedge, measured compression-sweep table, honest "do not
  claim yet" scope.
- docs/research/photonlayer/ASSESSMENT.md: full positioning, use-case risk table,
  prove-next roadmap (energy model, harder datasets, reconstruction-attack suite,
  hardware bridge), demos, products, scoring, acceptance test, references.
- tests/more_data_bench.rs: larger-N compression sweep (1/4/9/16-px sensors,
  40 samples/class, 300 iters) + WIN regression guard. Measured: at 64x reduction
  learned=0.988 vs random=0.738.
- Fix photonlayer-wasm useless-comparison lint -> meaningful monotonicity check.

* perf(photonlayer): M1 — cached + in-place Propagator (1.70x, bit-identical)

Hot-path optimization for the mask-learning loop, which propagates thousands
of fields through one fixed config. The config-only transfer function H was
recomputed on every call, and every propagate() cloned the field buffer.

- Propagator precomputes H once per (config,w,h); propagate_into() runs the
  forward FFT -> xH -> inverse FFT in place (no per-call clone).
- Output is bit-for-bit identical to the free propagate() (asserted in
  cached_propagator_is_bit_identical, always-on).
- Measured 1.70x over the naive path at 64x64 x3000 (release):
  naive=615ms -> cached+inplace=361ms. Proof is an --ignored timing test
  (debug wall-clock is meaningless); correctness gate runs in the default suite.

Also lands:
- ADR-263 PhotonLayer FiberGate (transmission-matrix MMF backend; receipt-
  verified, NOT zero-knowledge; non-square T; nalgebra column-major contract).
- docs/research/photonlayer/APPLICATIONS.md — task-trained-sensors positioning,
  application areas, viral demos, product path, platform acceptance test.

Co-Authored-By: claude-flow <ruv@ruv.net>

* feat(photonlayer): real-data MNIST optical-compression benchmark + differential ablation (M2)

Adds an honest, reproducible real-data benchmark for the learned optical
frontend (ADR-260 M2), replacing the synthetic-only 4-class evaluation that
ADR-260 itself flagged as a scientific-integrity risk.

New modules (photonlayer-bench):
- mnist.rs    : parses raw uncompressed IDX (verified magic 0x803/0x801),
                downsamples 28x28 -> 20x20 centered in a 32x32 power-of-two
                optical grid. Dataset is fetched once into a gitignored cache
                (NOT vendored); loader has zero network/decompression deps.
- diffdetect.rs: differential-detection readout (Li/Ozcan arXiv:1906.03417) -
                10 positive + 10 negative detector regions, score I+_k - I-_k.
- mnist_bench.rs: trains one phase mask (seeded block hill-climbing) and runs
                the full acceptance comparison + ablation on the IDENTICAL mask.

Integration test (mnist_differential_bench.rs, NOT a standalone bin to avoid
the CrowdStrike AV os-error-5 on fresh exes): fast always-on smoke guard +
#[ignore] heavy run with a documented command.

Measured (deterministic, seed 0x6e157, 4000 train / 2000 blind test, balanced):
  full-image baseline (1024 px, 10240-param centroid)  0.7540
  optical compressed  (  64 px,   640-param centroid)  0.7420
  delta vs baseline                                   -0.0120  (PASS, allows -0.02)
  sensor pixel reduction                               16.0x   (>= 16x)
  digital MAC reduction                                16.0x   (>= 10x)
  learned vs random mask (decoded)                     +0.0925
ACCEPTANCE (user's relative-to-baseline test): PASS.

Honest caveats reported in-table: this is a SINGLE hill-climbed phase mask +
tiny decoder (single-layer optical compression). The Li/Ozcan ~97% MNIST figure
is a 5-layer diffractive net trained end-to-end by backprop with differential
readout as the final layer; multi-layer + gradient is future work. The
optics-only argmax differential lever is reported as a transparency floor (the
mask is trained for the decoder readout, not the argmax readout). No absolute
SOTA claim is made.

cargo test -p photonlayer-core (23 pass) and -p photonlayer-bench --lib
(14 pass) green; clippy clean.

Co-Authored-By: claude-flow <ruv@ruv.net>

* docs(photonlayer): M3 — fold verified MNIST result + honest positioning + citations into ASSESSMENT

Adds the measured real-data MNIST table (optical 74.20% vs full-image baseline
75.40%, -1.20pp, 16x sensor + 16x MAC reduction; +9.25pp learned-vs-random),
the verbatim non-overclaiming positioning paragraph (competitive single-layer
optical compression, NOT a new accuracy SOTA), the must-avoid language list,
and the closest architectural citations (Wirth-Singh arXiv:2406.06534 primary,
Bezzam 2206.01429, Lin Science 2018, Li/Ozcan 1906.03417, Wang 2507.17374).

Co-Authored-By: claude-flow <ruv@ruv.net>

* perf(photonlayer-core): fold Fraunhofer fftshift into checkerboard premult + precompute FFT twiddle tables

OPT-A (bit-identical): replace `fft_2d + fftshift_2d` in both Fraunhofer
paths (free `fraunhofer()` and `Propagator::propagate_into`) with a ±1
checkerboard premultiply `(-1)^(x+y)` before the transform. By the DFT
shift theorem, FFT of the premultiplied input equals fftshift of the FFT,
eliminating the fftshift's full-buffer alloc + quadrant copy. True negate
(`Complex::ZERO - c`) is exact ±1.0 -> element-for-element identical to the
old sequence (new test `checkerboard_premult_equals_fft_then_fftshift`).

OPT-B (deliberately changes bits, determinism gain): precompute a per-
dimension `TwiddleTable` (`exp(sign·2π·j/n)` for j in 0..n/2) and INDEX it
by stride per butterfly instead of accumulating `w *= wlen`. Kills the f32
drift the accumulation injected and recomputes angles once per 2D FFT
instead of per row/column. Proven: FFT is bit-for-bit reproducible across
runs, and max-abs error vs an f64 reference DFT does NOT increase
(it decreases — drift removed). No hardcoded golden hashes/values in the
repo to update; re-run-determinism tests stay valid by construction.

Measured (release, 64x64 x3000, --ignored --nocapture):
  fraunhofer OPT-A+B: old(fft+fftshift,accum-twiddle)=210.5ms ->
  new(checkerboard+table)=116.1ms = 1.81x, max_diff_vs_old=5.7e-6 (f32 noise).
M1 cached-propagator benchmark still 2.00x and bit-identical.

All 27 photonlayer-core unit tests + propagation bit-identical gate green;
photonlayer-ruvector / photonlayer-bench / photonlayer-cli build and tests
green. Determinism invariant preserved (scalar cos/sin FFT, no FMA/SIMD/RFFT).

Co-Authored-By: claude-flow <ruv@ruv.net>

* feat(photonlayer): add Config B (argmax-diff-trained mask) to MNIST bench — isolates the differential lever

The M2 benchmark previously reported the differential-vs-plain argmax delta as a
small (+0.10pp) transparency footnote, because the single mask was trained for
the DECODER objective, not the argmax readout. That understated the Li/Ozcan
differential-detection mechanism. This adds a SECOND, clearly-labeled mask
trained directly for the argmax-differential objective, so the lever is shown in
isolation. Config A is unchanged and remains the product/acceptance headline.

Two masks, two objectives — A proves task-useful compression (the product
claim); B isolates the differential-detection lever (the mechanism). Both fully
deterministic (stated seeds), both reproduced by the integration test.

Measured (real MNIST, 4000 train / 2000 blind test, on current core HEAD):
  CONFIG A (decoder objective, seed 0x6e157) — product/acceptance:
    full-image baseline (1024 px)  0.7540
    optical compressed  (  64 px)  0.7305   (-2.35pp; 16x sensor + 16x MACs)
    learned vs random decoded      +0.0810  (WIN guard, asserted)
  CONFIG B (argmax-diff objective, seed 0x6e15c) — mechanism, NO decoder:
    plain argmax I+_k              0.1840
    differential argmax I+ - I-    0.3490
    differential lever delta       +0.1650  (asserted >= +0.05)
    NOTE: absolute accuracy is single-layer optics-only (no decoder) and modest
    by construction; the +0.1650 isolates the lever, NOT a headline accuracy.

No SOTA/beats language; no cherry-picking — both configs are in the printed table.

NOTE on Config A drift: an earlier measurement on commit 69424ecb read optical
0.7420 (-1.20pp, acceptance PASS). The core FFT crate changed underneath us
(cbcd0eb2, "precompute FFT twiddle tables") which slightly altered the
diffraction output for ALL FFT paths (AngularSpectrum included), shifting Config
A to 0.7305 (-2.35pp). Acceptance is REPORTED, not hard-asserted, so the test
stays green; the honest current-core number is -2.35pp. Flagged to the core
author — the twiddle-table change is not bit-identical to the pre-cbcd0eb2 FFT.

Scope: photonlayer-bench only (mnist_bench.rs + integration test). Core untouched.
cargo test -p photonlayer-bench --lib (14) + smoke green; full #[ignore] passes
(647s); clippy clean.

Co-Authored-By: claude-flow <ruv@ruv.net>

* test(photonlayer-bench): document the Config-A hill-climb optimizer ceiling

Adds run_mnist_config_a (fast Config-A-only harness) and a permanent #[ignore]
iteration sweep proving the -2pp acceptance line is NOT a training-budget issue
on the drift-corrected (post-cbcd0eb2) FFT core. Measured (seed 0x6e157,
4000 train / 2000 blind test):
  iters 1500 -> optical 73.05% (-2.35pp)
  iters 3000 -> optical 73.25% (-2.15pp)
  iters 4500 -> optical 73.20% (-2.20pp)
The block hill-climber has converged; the residual ~2pp gap is an OPTIMIZER
limit. Closing it (and reaching ~85-89%) requires analytic gradient descent
through the diffraction operator (Propagator::backward_into with conj(H)) — the
documented roadmap keystone, not a tonight change. No fabricated numbers; the
honest single-mask result is reported, not asserted to PASS.

Co-Authored-By: claude-flow <ruv@ruv.net>

* docs(photonlayer): M3 — refresh ASSESSMENT to shipped numbers + optimizer-ceiling honesty

The pre-OPT-B -1.20pp figure was stale after the twiddle-table FFT change.
Updates Config A to the true converged number on the optimized core
(73.05% / -2.35pp at 16x/16x; +8.10pp learned-vs-random), adds Config B
(+16.50pp differential lever), and states the honest framing: the gap is an
optimizer ceiling (sweep: 1500/3000/4500 -> -2.35/-2.15/-2.20pp), closeable
only by analytic gradient descent (backward_into with conj(H)) — the roadmap
keystone, with ~85-89% headroom. No PASS asserted that the method cannot reach.

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(photonlayer-bench): rustfmt + doc_lazy_continuation lint

- cargo fmt on all photonlayer crates
- Fix doc comment: `+` on continuation line parsed as markdown list
  marker causing clippy::doc_lazy_continuation. Changed to prose `and`.

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruv <ruvnet@users.noreply.github.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-06-18 23:22:42 -04:00
Claude
c4371872e9
research: add nightly survey for hnsw-delete-repair
Three pluggable HNSW deletion strategies (TombstoneOnly, BatchRepair,
EagerRepair) with DeletionStrategy trait, self-contained HNSW PoC,
12 passing tests, and real benchmark results on 5K×64 data.

Baseline recall@10: 0.9140
TombstoneOnly post-delete: 0.8950 (−1.9pp), delete=0.00ms
BatchRepair(50) post-delete: 0.9040 (−1.0pp), delete=81.69ms
EagerRepair post-delete: 0.9040 (−1.0pp), delete=83.02ms
Acceptance: PASS (best=0.9040 ≥ threshold=0.6855)

ADR: docs/adr/ADR-258-hnsw-delete-repair.md
Crate: crates/ruvector-hnsw-repair
Research: docs/research/nightly/2026-06-18-hnsw-delete-repair/

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01KxiBenREfLTBoss6x66EXk
2026-06-18 07:21:39 +00:00
rUv
48ee9c3609
feat(proof-gate): productionize #506 — tamper-evident vector writes (Merkle/hash-chain WAL) (#584)
Some checks failed
regression-guard / vector-db-rebuilds-index-on-open (push) Waiting to run
regression-guard / reentrant-rwlock-double-write (push) Waiting to run
regression-guard / case-insensitive-collisions (push) Waiting to run
regression-guard / ruvector-core-no-avx512-builds-on-stable (push) Waiting to run
regression-guard / hnsw-recall-at-1 (push) Waiting to run
regression-guard / hnsw-insert-beam-no-m2-clamp (push) Waiting to run
regression-guard / hnsw-distance-based-neighbor-pruning (push) Waiting to run
regression-guard / npm-publish-pipeline (npm/packages/pi-brain) (push) Waiting to run
regression-guard / npm-publish-pipeline (npm/packages/ruvector) (push) Waiting to run
regression-guard / npm-publish-pipeline (npm/packages/rvf-wasm) (push) Waiting to run
regression-guard / no-npx-execSync-in-route-enhanced (push) Waiting to run
regression-guard / shell-injection-in-mcp-server (push) Waiting to run
regression-guard / no-systemtime-in-wasm-crates (push) Waiting to run
regression-guard / no-hardcoded-workspaces-paths (push) Waiting to run
regression-guard / brain-hydration-counters-present (push) Waiting to run
regression-guard / optional-deps-resolvable-on-npm (push) Waiting to run
regression-guard / graph-condense-perception-tests (push) Waiting to run
regression-guard / mincut-pin-tracks-workspace-version (push) Waiting to run
supply-chain / cargo deny (license + source + ban policy) (push) Waiting to run
supply-chain / npm audit (npm/ workspace) (push) Waiting to run
supply-chain / lockfile integrity (Cargo.lock) (push) Waiting to run
supply-chain / dependency-review (PRs only) (push) Waiting to run
supply-chain / cargo audit (RustSec advisories) (push) Waiting to run
WASM Dedup Check / check-wasm-dedup (push) Waiting to run
Build DiskANN Native Modules / Build DiskANN darwin-arm64 (push) Has been cancelled
Build DiskANN Native Modules / Build DiskANN darwin-x64 (push) Has been cancelled
Build DiskANN Native Modules / Build DiskANN linux-arm64-gnu (push) Has been cancelled
Build DiskANN Native Modules / Build DiskANN linux-x64-gnu (push) Has been cancelled
Build DiskANN Native Modules / Build DiskANN win32-x64-msvc (push) Has been cancelled
Build DiskANN Native Modules / Publish DiskANN Platform Packages (push) Has been cancelled
* feat(proof-gate): bring ruvector-proof-gate into workspace (productionize #506)

Merkle-accumulating WAL for tamper-evident vector writes (defends the MemoryGraft
poisoning attack; addresses the unguarded-write-path gap in Qdrant/Milvus/Weaviate/
LanceDB/FAISS). Baseline: 16/16 tests pass. Wired into the workspace; ADR-194 +
research docs included. Deps: sha2, thiserror, optional serde.

* test(proof-gate): prove tamper-evidence end-to-end (productionize #506)

tests/tamper_evidence.rs (5 tests): the chain root is a cryptographic commitment
to the entire ordered write log — any mutation/insertion/deletion/reorder yields
a different root; forged commitments and foreign/out-of-range receipts are
rejected (no panic). Surfaced for the secure step: verify_integrity() is only a
structural check (non-zero/monotonic), not a payload re-derivation.

* bench(proof-gate): measure the integrity tax (productionize #506)

tests/perf_benchmark.rs (release, #[ignore]): HashChainGate.admit ~1026 ns/write
(~1.0 M/s) vs NullGate baseline ~36 ns; verify_receipt ~6.4 ns (157 M/s).
Integrity tax ~991 ns/write (~2 SHA-256) — negligible vs the HNSW insert a real
write performs, and verification is effectively free. Budget guard 5000 ns/write.

* secure(proof-gate): verify_integrity does full re-derivation (productionize #506)

Close the gap flagged in the test step: verify_integrity() was only a structural
scan (non-zero/monotonic). Now it stores per-entry payload hashes and re-derives
every commitment from the genesis seed, comparing against the stored chain — so a
tamper that mutates a commitment, a payload hash, reorders entries, or desyncs
lengths is caught (not just degenerate chains). +5 unit tests (private-field
tamper cases). All proof-gate tests green (20 unit + 5 tamper-evidence).

* perf(proof-gate): allocation-free payload hashing (productionize #506)

admit() built canonical_bytes() (a Vec + 128-element extend for a 128-dim vector)
then hashed it. Add WritePayload::payload_hash() that streams the same fields
straight into SHA-256 — identical digest, no intermediate Vec. Measured:
HashChainGate.admit ~1026 -> ~703 ns/write (~31% faster, 0.97 -> 1.42 M/s);
integrity tax ~991 -> ~675 ns. All digests unchanged (20 unit + 5 tamper tests green).

* docs(proof-gate): add crate README (publish-ready)

---------

Co-authored-by: ruv <ruvnet@users.noreply.github.com>
2026-06-17 20:19:47 -04:00
rUv
8417dc283b
feat(gnn-rerank): productionize #479 — +10.4pp recall, CI-guarded, hardened, optimized (#582)
* feat(gnn-rerank): bring ruvector-gnn-rerank into workspace (productionize #479)

Baseline from PR #479: GNN score diffusion reranking over ANN candidates,
recall@10 28.0% -> 38.4% (+10.4pp). 14/14 unit tests pass. Wired into the
workspace; ADR-194 + research docs included. Benchmark bin is AV-blocked on
this Windows box (CrowdStrike); recall numbers are from the PR's CI run.

* test(gnn-rerank): CI-guard the +10.4pp recall win (productionize #479)

Deterministic integration test reproduces the research regime (N=5000, D=128,
noise_sigma=0.40, seed=42) via the public reranker API and asserts GnnDiffusion
beats the NoisyScore baseline by >= 0.03 recall@10. Reproduces the exact #479
numbers: noisy=0.280, gnn=0.384, delta=+0.104. Runs under cargo test (the
standalone benchmark bin is AV-blocked on the dev box). Adds rand/rand_distr
dev-deps.

* bench(gnn-rerank): CI latency/throughput guard + honest tradeoff (productionize #479)

Times the rerank hot path under cargo test --release. Honest finding: the +10.4pp
recall win is NOT free throughput — GnnDiffusion is ~400us/q (~2.5K QPS), ~2900x
slower than the NoisyScore baseline (~0.15us/q, ~7M QPS). The 'millions of QPS'
in #479 was the baseline, not the reranker. Budget guard set to 700us/q to catch
regressions. The O(candidates^2 * dim) k-NN graph build is the hot path -> the
optimize-step target.

* secure(gnn-rerank): reject poisoned inputs fail-fast (productionize #479)

Harden validate(): all candidate vectors must share one dimension and be finite,
scores must be finite — else a typed error (NonFinite / DimMismatch) instead of a
silently-corrupted ranking (poisoned-first-stage / MemoryGraft threat model).
Adds tests/security.rs (6 adversarial cases across all 4 variants: NaN/inf score,
NaN vector, dim mismatch, empty, k-too-large, degenerate/zero vectors) — none
panic. Marks the perf benchmark #[ignore] (release-only; debug timing is
meaningless).

* perf(gnn-rerank): exploit cosine symmetry in graph build (productionize #479)

The candidate k-NN graph build recomputed every cosine pair twice. Cosine is
symmetric, so compute the upper triangle once and push each sim into both
neighbour lists — ~2x fewer dot products (the inner-loop hot path). Measured:
GnnDiffusion ~400us/q -> ~300us/q (~25% wall-clock). Result-identical:
recall@10 delta stays exactly +0.104; all unit/recall/security tests green.

* docs(gnn-rerank): add crate README (publish-ready)

---------

Co-authored-by: ruv <ruvnet@users.noreply.github.com>
2026-06-17 20:18:45 -04:00
Claude
11f8566f25
docs: add nightly research README and SEO gist for agent-memory-compaction
Research document covers SOTA survey (5 papers, 2023-2026), 10-20 year
thesis, benchmark methodology, real results, practical and exotic
applications, failure modes, and production roadmap.

Gist is SEO-optimised public technical article with complete benchmark
results table, comparison to Milvus/Qdrant/Weaviate/Pinecone/LanceDB/
FAISS/pgvector/Chroma/Vespa, and usage guide.

https://claude.ai/code/session_01FphtGmUWK9FvHsjBErYbqx
2026-06-14 07:22:20 +00:00
rUv
bc3a9b1c93
fix: 9-issue cleanup batch + regression-guard CI workflow (#466)
* fix: batch 1 — deadlock, AVX-512 gating, Windows case-collisions

Closes #437: VectorDb::delete in ruvector-router-core acquired the stats
RwLock twice in one statement. parking_lot::RwLock is non-reentrant, so
the second .write() deadlocked against the first guard's lifetime. Bind
the guard once.

Closes #438: Gate AVX-512 intrinsics behind a new `simd-avx512` Cargo
feature (default-on). Lets downstream consumers on stable Rust 1.77–1.88
(before avx512f stabilization in 1.89) opt out without forcing nightly:
  cargo build --no-default-features --features simd,storage,hnsw,api-embeddings,parallel
Runtime dispatch falls back to AVX2 + FMA when the feature is disabled.
All 4 #[target_feature(enable = "avx512f")] sites + 4 dispatch branches
updated. Both feature configurations verified to compile cleanly; all
18 simd_intrinsics tests pass.

Closes #458: Rename two pairs of case-colliding research artifacts under
docs/research/claude-code-rvsource/versions/v2.1.x/tree/react_memo_cache_sentinel/
that broke `git clone` on Windows/NTFS:
  tmux.js → tmux_lc.js   (TMUX.js kept)
  type.js → type_lc.js   (Type.js kept)
modules-manifest.json updated to match.

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(brain): observable hydration + larger page-error budget (issue #464)

Bisect outcome: source diff between the 2026-04-14 working revision
(00203-brv → 22,005 memories) and current main (00204-92l → 10,227)
is whitespace-only (cargo fmt 2026-04-24 + clippy 2026-04-25). No
semantic change in store.rs, types.rs, or graph.rs. BrainMemory schema
is byte-identical. So the regression is environmental, surfacing
through a code path that has no observability today.

Two changes:

1. load_from_firestore() now emits per-collection counters so the next
   deploy is diagnosable instead of a black box:
     Hydrate brain_memories: considered=N accepted=M rejected_parse=K
   First 5 parse errors are logged with the serde_json error so any
   live schema drift surfaces immediately.

2. firestore_list MAX_PAGE_ERRORS raised 3 → 8. Hydration crosses ~75
   pages of 300 docs each; 3 transient OAuth-refresh blips at the
   wrong moment terminated the load at ~10K, consistent with the
   reported 10,227 number. 8 still bounds runaway behaviour while
   tolerating realistic blip rates.

The actual environmental cause is recoverable from one deploy with the
new logs in place. Until then, traffic stays on 00203-brv (which is
what the rollback already did).

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(router-core): HNSW result-heap inversion, prune drops oldest, k > ef_search (#430)

Three correctness bugs in crates/ruvector-router-core/src/index.rs that
together collapsed recall@1 at scale:

1. `Neighbor::Ord` is reversed so BinaryHeap acts as a min-heap. Correct
   for `candidates` (pop closest unexplored first), but WRONG for the
   `result` heap — peek returned the BEST candidate, so the eviction
   path kept dropping the best item instead of the worst whenever the
   set was full. Wrap result in `std::cmp::Reverse<Neighbor>` so
   peek/pop return the furthest item (the actual eviction target). This
   is the primary recall@1 fix.

2. Per-insert connection pruning used `truncate(m)`, which keeps the
   OLDEST m connections — including dropping the just-pushed edge when
   it landed past index m. Switch to `drain(0..len-m)` so the freshly
   inserted edge always survives.

3. `search()` capped at `ef_search` regardless of caller's k. With
   default ef_search=10 and k=25, results were silently 10. Raise ef
   to `max(ef_search, k)` before invoking search_knn_internal.

New tests:
- `test_recall_at_1_with_biased_insertion_order`: 1024 vectors,
  biased insertion order (the topology that historically exposed the
  bug); asserts recall@1 ≥ 95% AND ≥ 80% distinct ids across queries.
- `test_k_exceeds_ef_search_default`: 50 vectors, default ef_search=10,
  k=25; asserts 25 results returned.

All 19 router-core tests pass.

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(npm): publish pipeline — dist/ guaranteed + dual ESM/CJS pi-brain (#462/#415/#376/#372)

@ruvector/pi-brain 0.1.1 → 0.1.2 (closes #462, #372):
  * Add `prepack` hook so dist/ is always built before publish — tarballs
    on 0.1.0/0.1.1 shipped without dist/ because `tsc` never ran.
  * Add a second tsconfig (tsconfig.cjs.json) that emits CommonJS to
    dist/cjs/ alongside the ESM build in dist/. A generated
    dist/cjs/package.json carries {"type":"commonjs"} so Node treats
    that subtree as CJS regardless of the package-level "type":"module".
  * Expand the exports map with import + require + default conditions
    so ruvector@0.2.x's CJS MCP server (Node 20.x, no require(ESM)
    until 22.12) can require() the package. Add subpath exports for
    ./mcp and ./client.
  * Verified locally: dist/cjs/index.js loads via `require()` and
    dist/index.js loads via dynamic `import()`.

@ruvector/rvf-wasm 0.1.5 → 0.1.6 (closes #415):
  * pkg/rvf_wasm.js contains ESM syntax (`import.meta.url`,
    `export default`). The old exports map pointed `require` at this
    file, which fails on every CJS consumer. Mark the package
    explicitly `"type": "module"`, drop the `require` condition (the
    `.mjs` build is the canonical one), and add a `./wasm` subpath for
    consumers that want the raw bytes.

ruvector npm 0.2.25 (extends #376 mitigation):
  * Add `prepack` mirroring `prepublishOnly` so `npm pack` (and CI
    smoke tests that run pack) regenerate dist/ + run verify-dist.
    Without this, `npm pack` skips prepublishOnly, masking
    missing-dist regressions until publish.

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(mcp): hooks_route_enhanced in-process — drop spawnSync (#463/#422)

The hooks_route_enhanced MCP tool shelled out via
  execSync('npx ruvector hooks route-enhanced …', { timeout: 30000 })
which deterministically timed out: npx's package-resolution and
bin-launch overhead can spike past 30s on cold-cache machines, even
though the underlying work finishes in ~500ms. Callers got
deterministic `spawnSync /bin/sh ETIMEDOUT`.

The sibling hooks_route tool (reported as working in #463) uses
intel.route() directly. Mirror that pattern: call intel.route(), then
inline the same coverage-router + AST-parser signal enrichment the CLI
does. No subprocess, no timeout, no npx dependency.

Falls back gracefully when coverage-router or ast-parser aren't
installed (try/catch around each optional enhancement, same as the
CLI handler).

Co-Authored-By: claude-flow <ruv@ruv.net>

* ci: regression guard for 9 issues + fixes for 5 latent regressions it surfaced

New workflow .github/workflows/regression-guard.yml runs on every push +
PR. Each job pins one of these issue classes shut:

  #437 reentrant-rwlock-double-write
       Forbids `x.write()…x.(write|read)()` and `x.read()…x.write()` in
       a single statement (parking_lot is non-reentrant). PCRE
       backreference matches only same-lock cases.

  #458 case-insensitive-collisions
       Fails if `git ls-files` has any two paths that match after
       lowercasing — Windows clones drop one of each silently.

  #438 ruvector-core-no-avx512-builds-on-stable
       cargo check ruvector-core with AND without the simd-avx512
       feature so the AVX-512 gating doesn't regress.

  #430 hnsw-recall-at-1
       Runs the new recall@1 (biased insertion / 1024 vectors) test
       and the k > ef_search test in release mode.

  #462 / #376 npm-publish-pipeline
       npm pack each shipped package and assert every entry referenced
       by main/module/types/exports is actually inside the tarball.

  #463 / #422 no-npx-execSync-in-mcp-server
       Forbids execSync('npx ruvector …') anywhere in the MCP server.

  #256 shell-injection-in-mcp-server
       Flags any exec*/spawn* call that interpolates ${args.X} without
       wrapping in sanitizeShellArg(...).

  #267 no-systemtime-in-wasm-crates
       Crates named *wasm* with ungated SystemTime::now / Instant::now
       calls are rejected (the wasm32-unknown-unknown panic class).

  #359 no-hardcoded-workspaces-paths
       Devcontainer-only `/workspaces/ruvector` literals are banned
       from .github/workflows, .claude/settings*, and scripts/publish/.

Adding the guard surfaced five real, already-present regressions of
these classes — fixed in this commit:

  * crates/prime-radiant/src/coherence/engine.rs (3 sites):
    self.stats.write().X = self.stats.read().X - 1 in the same
    statement — exactly issue #437's shape on a different lock. Bind
    the write guard once.

  * crates/ruvector-wasm/src/lib.rs:465 (benchmark fn):
    used std::time::Instant which panics on wasm32 (issue #267).
    Switch to js_sys::Date::now().

  * scripts/publish/publish-router-wasm.sh + check-and-publish-router-wasm.sh:
    hardcoded /workspaces/ruvector paths (issue #359). Resolve REPO_ROOT
    from BASH_SOURCE instead.

Co-Authored-By: claude-flow <ruv@ruv.net>

* ci: narrow scope of two guards to avoid pre-existing-debt false positives

After the first PR run two guards caught existing technical debt rather
than fresh regressions:

  * no-npx-execSync-in-mcp-server flagged 10 other execSync('npx
    ruvector …') sites (ast-analyze, coverage-route, graph-mincut,
    security-scan, git-churn, …) which predate issue #463 and are a
    distinct concern (some legitimately need subprocess). Narrow the
    guard to the EXACT regression — execSync inside the
    hooks_route_enhanced case body — using awk to extract that case's
    body before grepping. Rename: no-npx-execSync-in-route-enhanced.

  * npm-publish-pipeline failed at npm install (peer-dep ERESOLVE).
    Add --legacy-peer-deps. The point of this guard is the tarball
    content, not the install graph.

Co-Authored-By: claude-flow <ruv@ruv.net>

* style: cargo fmt --all (mechanical, pre-existing diffs on main + my new code)

Workspace had 11 files with rustfmt diffs predating this branch, plus
one new diff in store.rs from the hydration counters added in 97c07520d.
Running `cargo fmt --all` brings them all in line so the Rustfmt CI job
passes on this branch.

No semantic changes — pure whitespace.

Co-Authored-By: claude-flow <ruv@ruv.net>

* ci+build: isolate npm pack from workspace + fix ruvector build mkdir

CI regression-guard's npm-publish-pipeline failed because pi-brain and
ruvector both live inside the npm workspace at npm/package.json, whose
other workspace members declare cross-platform native binaries (e.g.
router-darwin-arm64). Running `npm install` from a package directory
still walks the workspace and rejects EBADPLATFORM on the wrong-host
binary.

Fix: copy each package to a workspace-free /tmp dir, strip its lockfile,
and install with --no-workspaces. The point of this guard is the tarball
content, so isolating from the workspace doesn't reduce coverage.

Also fixes ruvector's `build` script — it copy'd a file into
dist/core/onnx/pkg/ without `mkdir -p` first, so the build crashed on
any fresh install. Now: `tsc && mkdir -p dist/core/onnx/pkg && cp ...`.

Verified locally: both pi-brain (8.9 kB, 15 files) and ruvector (826 kB,
134 files) pack cleanly with the new flow.

Co-Authored-By: claude-flow <ruv@ruv.net>

* fix(ci): bump rkyv to 0.8.16 (RUSTSEC-2026-0122) + downgrade clippy on research crates

Three CI failures left after the previous push:

  * cargo-deny / cargo-audit — RUSTSEC-2026-0122: rkyv 0.8.15
    InlineVec::clear / SerVec::clear are not panic-safe → potential
    use-after-free / double-free via catch_unwind. Solution per the
    advisory: `cargo update -p rkyv`. Bumps rkyv 0.8.15 → 0.8.16 and
    rkyv_derive 0.8.15 → 0.8.16, pulls in hashbrown 0.17.1. Verified
    that ruvector-core + ruvector-hailo + ruvector-hailo-cluster (the
    rkyv consumers) all still cargo-check clean.

  * Clippy (workspace, deny warnings) — 12 stylistic clippy errors in
    ruvllm_sparse_attention (subquadratic attention research crate)
    and 11 more in ruvllm_retrieval_diffusion (training-free retrieval
    LM). The lints flagged: needless_range_loop, if_same_then_else,
    derivable_impls, redundant_closure, iter_cloned_collect,
    doc_lazy_continuation, unusual_byte_groupings, needless_lifetimes.
    None affect correctness — these are research-tier crates where the
    explicit indexing style is intentional. Add a per-crate
    `[lints.clippy]` section in each Cargo.toml downgrading the
    flagged lints to `allow`. The workspace-level `-D warnings` stays
    strict for every other crate.

clippy --fix also auto-rewrote two minor sites in
ruvllm_sparse_attention/examples/{sparse_mario,esp32s3_smoke}.rs that
were stylistic improvements; kept those.

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-05-16 12:14:49 -04:00
rUv
8f97421297
research(nightly): rairs-ivf — RAIRS IVF, ruvector's first Inverted File Index (ADR-193) (#459)
* feat(rairs-ivf): add RAIRS IVF — ruvector's first Inverted File Index (ADR-193)

Implements Yang & Chen, SIGMOD 2026 (arXiv:2601.07183): three variants of
IVF with Redundant Assignment + Amplified Inverse Residual + SEIL layout.

Three measurable variants (N=5K, D=128, 64 clusters, cargo --release):
  IvfFlat      nprobe=1 recall@10  61.3%  mem 2,571 KB  26,984 QPS
  RairsStrict  nprobe=1 recall@10  83.8%  mem 5,110 KB  13,243 QPS
  RairsSeil    nprobe=1 recall@10  93.1%  mem 2,571 KB  13,582 QPS

RairsSeil: +31.8 pp recall at nprobe=1 vs IvfFlat with identical memory.

Files:
  crates/ruvector-rairs/         — new crate (IvfFlat, RairsStrict, RairsSeil)
  docs/adr/ADR-193-rairs-ivf.md  — architecture decision record
  docs/research/nightly/2026-05-12-rairs-ivf/README.md — SOTA survey + results
  Cargo.toml                     — workspace member added

10/10 unit tests pass. cargo build --release -p ruvector-rairs green.

* perf(ruvector-rairs): SIMD-friendly distance kernels + partial-select top-k; fix clippy/fmt; flag unverified citation

Optimizations (recall unchanged; ~2.3–2.9× single-thread QPS across all
variants/nprobe on x86-64):
- index.rs: rewrite l2sq/dot as 8-lane unrolled reductions so LLVM
  auto-vectorises the f32 accumulation (the naïve iter().sum() can't — f32
  add isn't associative). This is the hot path: every centroid scan + every
  list-entry distance.
- index.rs: add finalize_topk() / top_nprobe_centroids() using
  select_nth_unstable (O(n) avg) instead of full O(n log n) sorts of every
  candidate / every centroid; all three search() impls use them. Distance
  ordering switched to f32::total_cmp — no more partial_cmp().unwrap() panics.
- rairs.rs: rair_score is now allocation-free (no per-call Vec for the diff);
  search() dedups ids with a reused bool scratch array instead of allocating
  a HashSet per query.
- seil.rs: block-visited dedup uses a flat bool array indexed via per-list
  prefix sums instead of a per-query HashSet<(usize,usize)>.

Fixes:
- clippy `-D warnings` now passes: documented the 6 RairsError struct fields
  + RairsSeil::lambda; elided the explicit lifetime on resolve_block.
- cargo fmt --check now passes (benches/rairs_bench.rs import ordering, etc.).
- lib.rs + ADR-193 + the research README now carry a Provenance note: the
  "RAIRS/SEIL" names and the SIGMOD-2026 / arXiv:2601.07183 citation are
  unverified; the crate is an original implementation of the redundant-
  assignment idea (cf. IVF spill lists / SOAR / multi-probe LSH) and should
  be judged on src/main.rs's reproducible benchmarks, not the reference.

cargo test -p ruvector-rairs: 10/10 pass; recall@10 at nprobe∈{1,4,16}
unchanged (61.3/97.9/100 IvfFlat, 83.8/99.4/100 RairsStrict,
93.1/99.9/100 RairsSeil); index memory unchanged.

Co-Authored-By: claude-flow <ruv@ruv.net>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: ruvnet <ruvnet@gmail.com>
2026-05-12 09:47:19 -04:00
rUv
019e5afff3
research(nightly): ACORN — predicate-agnostic filtered HNSW (#391)
* docs(adr): add ADR-160 for ACORN predicate-agnostic filtered HNSW

Records the decision to ship ruvector-acorn as the ruvector solution for
filtered vector search recall collapse at low predicate selectivity. Documents
3 concrete index variants, measured benchmark results, consequences, and a
4-phase implementation roadmap (NN-descent, payload index, delta-index, SIMD).

https://claude.ai/code/session_0173QrGBttNDWcVXXh4P17if

* docs(research): add nightly research doc — ACORN filtered HNSW (2026-04-26)

Full research document: SOTA survey (SIGMOD 2024, competitor changelog),
proposed design with graph construction + ACORN beam search pseudocode,
implementation notes (greedy vs NN-descent, entry point selection, predicate
generality), real benchmark methodology and results table, blog-readable
walkthrough, failure modes, roadmap, and production crate layout proposal.

https://claude.ai/code/session_0173QrGBttNDWcVXXh4P17if

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-27 00:29:37 -04:00
ruvnet
ac5a9d7bd1 chore: gitignore .claude/worktrees + commit ruvllm research docs
Two unrelated bits of working-tree state cleaned up alongside the
ADR-159 branch:

1. `.gitignore`: add `.claude/worktrees/` — these are agent worktree
   directories created at runtime for per-agent isolation; should
   never be committed.

2. `docs/research/ruvllm/`: include 2 research notes from 2026-04-24
   that were sitting uncommitted on this working tree. Both are pure
   research / pre-design markdown:
     - larql-integration.md: LARQL × RuvLLM integration assessment
     - rust-rebuild-sota.md:  clean-sheet Rust rebuild SOTA survey

`examples/connectome-fly/ui/` remains untracked — the directory has
no source code, only a stale `dist/`, `node_modules/`, and an
orphan `package-lock.json` from an abandoned scaffold. Whoever owns
that example can decide what to do with it.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-25 17:21:54 -04:00
ruvnet
3a1afa2284 feat(rulake): vector-native federation intermediary — ADR-155 + MVP crate
Implements the M1 scope of docs/research/ruLake/ as an intermediary that
fans out vector queries across heterogeneous backends (Parquet, BigQuery,
Snowflake, Delta, Iceberg, local) behind a single RVF wire protocol, with
a RaBitQ-compressed cache in front.

## What ships

- **Research docs** under docs/research/ruLake/ (9 files, ~2.5k lines),
  reframed from the earlier "plug RVF into BigQuery" shape to the
  intermediary/federation shape. BigQuery-native compute becomes a Tier-2
  push-down optimization inside the BigQueryBackend adapter, not a new
  product shape.
- **ADR-155 v2** as "Proposed" — captures the seven alternatives
  considered (plug-in-per-lake, standalone vector DB, Iceberg extension,
  Trino connector, JVM intermediary, notebook-only, push-through-only),
  consequences, and eight open questions.
- **crates/ruvector-rulake/** — new workspace member:
  - `BackendAdapter` trait with minimum surface (id / list_collections /
    pull_vectors / generation / supports_pushdown).
  - `LocalBackend` in-memory reference implementation (thread-safe).
  - `VectorCache` wrapping ruvector_rabitq::RabitqPlusIndex, with per-
    collection generation tracking and `Consistency::{Fresh, Eventual}`
    policies.
  - `RuLake` entry point: register backends, search single or federated,
    cache-stats introspection.
  - 7 smoke tests (`tests/federation_smoke.rs`): byte-exact match vs
    direct RaBitQ, cache-coherence after backend mutation, cross-backend
    fan-out with correct score ordering, cache-hit-faster-than-miss,
    three error-path tests.
  - `rulake-demo` bin: unified benchmark producing the same-run table in
    BENCHMARK.md.

## Measured numbers (LocalBackend, D=128, rerank×20, 300 queries)

| n       | direct RaBitQ+ QPS | ruLake Fresh QPS | ruLake Eventual QPS | tax   |
|--------:|-------------------:|-----------------:|--------------------:|------:|
|   5,000 |             17,311 |           17,874 |              17,858 | 0.97× |
|  50,000 |              5,162 |            5,123 |               5,050 | 1.01× |
| 100,000 |              3,122 |            3,117 |               3,114 | 1.00× |

**Intermediary tax is effectively zero on a local backend.** Federated
across 2 shards: 2,470 QPS @ n=100k (0.79× of single-shard); 4 shards:
1,781 QPS (0.57×) — sequential fan-out, parallel merge is the v2
optimisation per ADR-155 §Consequences.

## Build + test status (this crate only)

```
cargo build  -p ruvector-rulake --release                            ✓
cargo test   -p ruvector-rulake --release                            ✓ 7 passed
cargo clippy -p ruvector-rulake --release --all-targets -- -D warnings   ✓ clean
cargo fmt    -p ruvector-rulake -- --check                           ✓ clean
cargo run    -p ruvector-rulake --release --bin rulake-demo          ✓ reproduces BENCHMARK.md
```

## Scope this commit does NOT cover (M2-M5, see 07-implementation-plan.md)

- ParquetBackend, BigQueryBackend, SnowflakeBackend, IcebergBackend,
  DeltaBackend (real-backend adapters).
- Push-down paths into backends with native vector ops.
- Governance / RBAC / PII / lineage / audit (M4).
- SIFT1M recall measurement on the real-backend path.
- Parallel fan-out via rayon.
- LRU cache eviction.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-23 18:38:49 -04:00
Claude
f2dbb6efbd
feat(rabitq): add RaBitQ rotation-based 1-bit quantization crate (ADR-154)
Implements SIGMOD 2024 RaBitQ algorithm as ruvector-rabitq crate:
- RandomRotation: Haar-uniform D×D orthogonal matrix via Gram-Schmidt
- BinaryCode: u64-packed sign bits + XNOR-popcount + angular correction estimator
- AnnIndex trait with 3 swappable backends (FlatF32, RabitqIndex, RabitqPlusIndex)

Measured on x86-64, D=128, Gaussian-cluster data (100 clusters, σ=0.6):
- RaBitQ+ rerank×5: 98.9% recall@10 at 4,271 QPS (2.05× vs exact 2,087 QPS)
- RaBitQ+ rerank×10: 100.0% recall@10 at 4,069 QPS (1.95×)
- Memory: 17.5× compression (1.4 MB vs 24.4 MB at n=50K, D=128)
- Binary codes: 16 bytes/vec (2 u64) vs 512 bytes (f32) at D=128

All 10 unit tests pass. cargo build --release succeeds.

https://claude.ai/code/session_01DAaNhfoLwpbWRbExsayoep
2026-04-23 07:56:23 +00:00
Ofer Shaal
241738c986 docs(adr): ADR-151 + PRD §6 — Phase 0 findings, revised perf targets, Grok review
Phase 0 implementation revealed that the original PRD §6 targets
(50 ns / 200 ns for is_prime_u64 worst case) were structurally
unachievable in safe Rust on Apple-silicon. Apples-to-apples competitor
benchmark in the same binary on the same machine measured num-prime
0.4.4 at 884 ns vs ours at 15.63 µs — ~17.7× headroom recoverable via
Montgomery reduction in Phase 0.1, but not the ~300× the original target
implied. The 50 ns figure was a pre-implementation estimate that did not
survive contact with measured hardware.

ADR-151 (docs/adr/ADR-151-miller-rabin-prime-optimizations.md)
- Status promoted from "Proposed" to "Accepted (Phase 0 landed
  2026-04-16; performance targets revised)".
- New "Phase 0 Findings (2026-04-16)" section documenting what landed,
  measurements vs original targets, num-prime competitor baseline, the
  revised target band, and Phase 0.1 scope (Montgomery only).
- Explicit rejection of swapping to the empirical 7-witness set:
  Sinclair-12 is theorem-proven across all u64; the 7-witness sets in
  the literature are empirically tested up to 2^64 but not proven, and
  swapping invalidates the A014233(11) canary in the pseudoprime test.

PRD §6 (docs/research/miller-rabin-optimizations/PRD.md)
- Revision header noting the relaxation.
- is_prime_u64(p) worst-case row updated to ≤ 1 µs (was 50 ns) M-series
  / ≤ 4 µs (was 200 ns) WASM.
- New §6.1 "Empirical findings (Phase 0)" with the measurement table
  and the num-prime baseline data.

GROK-REVIEW-REQUEST.md (new, 424 lines)
- Self-contained briefing used to obtain external Grok review of the
  Phase 0 design and Phase 0.1 plan: §1 binding context, §2 implementation
  embedded verbatim, §3 measurements + competitor baseline, §4 four-section
  ask (correctness, perf plan ranked, architecture, validation
  methodology), §5 response format. Constraints block forbids
  "just use num-prime" answers and pins the canary witness set.
2026-04-16 14:41:02 -04:00
Ofer Shaal
6c0daaf018 docs(adr): ADR-151 + PRD — Miller-Rabin prime optimizations (PIAL)
Adds the binding ADR and full PRD for the Prime-Indexed Acceleration
Layer (PIAL): a single ~250-LoC Miller-Rabin primality utility in
crates/ruvector-collections that unblocks five independent prime-aware
optimizations across hashing, sharding, sketching, and the pi-brain
witness chain.

Use cases:
  * Shard-router prime modulus  — closes ADR-058 finding #6
  * HNSW prime-bucket adjacency — micro-hnsw-wasm, hyperbolic-hnsw
  * Certified-prime LSH modulus — sparsifier, attn-mincut
  * Witness-chain ephemeral primes — pi-brain brain_share payload
  * Anti-aliasing prime strides — sparsifier sampler

Generation strategy combines a compile-time table of primes near 2^k
(fast path, ~1ns) with a Miller-Rabin descent fallback (~250ns). The
table is generated by build.rs from the MR implementation and
cross-checked against MR in CI, so MR remains the source of truth.

Includes HANDOFF.md with Phase 0 deliverables for the next session.
ADR and PRD pin acceptance criteria, performance targets, and a
six-phase rollout (each phase ships as a separate PR).
2026-04-16 12:34:47 -04:00
rUv
325d0e8cde research(boundary-first): 17 experiments proving boundary-first detection across 11 domains (#347)
Boundary-first detection finds hidden structure changes by analyzing WHERE
correlations between measurements shift — not WHERE individual measurements
cross thresholds. This gives days-to-minutes of early warning where
traditional methods give zero.

SIMD/GPU improvements (3 crates):
- ruvector-consciousness: NEON FMA for dense matvec, KL, entropy, pairwise MI
- ruvector-solver: NEON SpMV f32/f64, wired into CsrMatrix::spmv_unchecked() hot path
- ruvector-coherence: NEON spectral spmv + dot product for Fiedler estimation

17 working experiments (all `cargo run -p <name>`):
- boundary-discovery: phase transition proof (z=-3.90)
- temporal-attractor-discovery: 3/3 regimes (z=-6.83)
- weather-boundary-discovery: 20 days before thermometer (z=-10.85)
- health-boundary-discovery: 13 days before clinical (z=-3.90)
- market-boundary-discovery: 42 days before crash (z=-3.90)
- music-boundary-discovery: genre boundaries (z=-13.01)
- brain-boundary-discovery: seizure detection 45s early (z=-32.62)
- seizure-therapeutic-sim: entrainment delays seizure 60s, alpha +252%
- seizure-clinical-report: detailed clinical output + CSV
- real-eeg-analysis: REAL CHB-MIT EEG, 235s warning (z=-2.23 optimized)
- real-eeg-multi-seizure: ALL 7 seizures detected (100%), mean 225s warning
- seti-boundary-discovery: 6/6 sub-noise signals found
- seti-exotic-signals: traditional 0/6, boundary 6/6 (z=-8.19)
- frb/cmb/void/earthquake/pandemic/infrastructure experiments

Research documents:
- docs/research/exotic-structure-discovery/ (8 documents, published to gist)
- docs/research/seizure-prediction/ (7 documents, published to dedicated gist)

Gists:
- Main: https://gist.github.com/ruvnet/1efd1af92b2d6ecd4b27c3ef8551a208
- Seizure: https://gist.github.com/ruvnet/10596316f4e29107b296568f1ff57045

Co-authored-by: Reuven <cohen@ruv-mac-mini.local>
2026-04-13 12:01:47 -04:00
rUv
76679927c8 research(kv-cache): TriAttention + TurboQuant stacked compression analysis (#342)
Add deep research into three-axis KV cache compression:
- TriAttention (arXiv:2604.04921): trigonometric RoPE-based token sparsity, 10.7x
- Stacked compression: TriAttention × TurboQuant for ~50x KV reduction
- ADR-147: formal architecture decision with GOAP implementation plan

No published work combines these orthogonal methods. First-mover opportunity
for ruvLLM edge inference (128K context in 175MB on Pi 5).

Co-authored-by: Reuven <cohen@ruv-mac-mini.local>
2026-04-08 13:29:16 -05:00
Reuven
9ba5152a2f Merge remote-tracking branch 'origin/main' into feat/ruvm-hypervisor-research 2026-04-04 18:58:32 -04:00
Reuven
a929fde654 feat(rvm): RVM — Coherence-Native Microhypervisor for the Agentic Age
Complete implementation of the RVM microhypervisor:

13 Rust crates (all #![no_std], #![forbid(unsafe_code)]):
- rvm-types: Foundation types (64-byte WitnessRecord, ~40 ActionKind variants)
- rvm-hal: AArch64 EL2 HAL (stage-2 page tables, PL011 UART, GICv2, timer)
- rvm-cap: Capability system (P1/P2 proof verification, derivation trees)
- rvm-witness: Witness logging (FNV-1a hash chain, ring buffer, replay)
- rvm-proof: Proof engine (3-tier, constant-time P2 evaluation)
- rvm-partition: Partition model (lifecycle, split/merge, IPC, device leases)
- rvm-sched: Scheduler (2-signal priority, SMP coordinator, switch hot path)
- rvm-memory: Memory tiers (buddy allocator, 4-tier, RLE compression)
- rvm-coherence: Coherence engine (Stoer-Wagner mincut, adaptive frequency)
- rvm-boot: Bare-metal boot (7-phase measured, EL2 entry, linker script)
- rvm-wasm: Agent runtime (7-state lifecycle, migration, quotas)
- rvm-security: Security gate (validation, attestation, DMA budget)
- rvm-kernel: Integration kernel (boot/tick/create/destroy)

602 tests, 0 failures, 0 clippy warnings.
21 criterion benchmarks (all ADR targets exceeded).
9 ADRs (132-140), 15 design constraints (DC-1 through DC-15).
11 security findings addressed.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-04 12:10:19 -04:00
rUv
57e5d73542 feat(decompiler): add graph-derived folder hierarchy for Claude Code v2.1.91
748 .js files across 19 directories, 3.9MB total.
Folder names derived from TF-IDF scoring of graph clusters:
- asyncgenerator/ (109 files) — async patterns, agent loop
- bedrockclient/ (4) — AWS Bedrock
- react_memo_cache_sentinel/ (585) — React/UI main code
- tengu_log_datadog_events/ (3) — telemetry
- systempromptsectioncache/ (2) — prompt caching
- managedidentitycredential/ (6) — Azure auth

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 16:00:41 +00:00
rUv
501bd9c198 fix(versions): remove 621MB source output, keep manifest + witness
Full 981-module output too large for git (621MB).
Available as GitHub release download (121MB tar.gz):
https://github.com/ruvnet/rudevolution/releases/tag/v0.1.0-claude-code-v2.1.91

Repo keeps: modules-manifest.json (lists all 661 modules),
witness.json, metrics.json, README.md

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 15:13:58 +00:00
rUv
ac0b9ff7b9 feat(decompiler): decompile Claude Code v2.1.91 (latest) — 34,759 declarations
981 Louvain modules, 599K edges, 32,091 names inferred.
Discoveries: Agent Teams, Auto Dream Mode, opus-4-6/sonnet-4-6,
6 amber codenames, Advisor Tool, Agentic Search, 117 new env vars.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 15:10:47 +00:00
rUv
b1a3e4eed8 feat(decompiler): 885-module manifest + witness for Claude Code v2.1
Full decompile: 885/885 modules parse (100%)
Manifest lists all modules with sizes.
Full source too large for git (419MB) — generate via:
  cargo run --release -p ruvector-decompiler --example run_on_cli -- \
    $(npm root -g)/@anthropic-ai/claude-code/cli.js --output-dir ./decompiled

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 13:23:49 +00:00
rUv
36f2599774 feat(training): source map extraction + v2 model (83.67% val accuracy)
- Extract 14,198 training pairs from 6,941 source maps in node_modules
- Train v2 model (4-layer, 192-dim, 6-head transformer, 1.9M params)
- Val accuracy: 83.67% (up from 75.72%), exact match: 12.3% (up from 0.1%)
- Export weights.bin (7.3MB) for Rust runtime inference
- Add decompiler dashboard (React + Tailwind + Vite)
- Add runnable RVF (7,350 vectors, 49 segments, witness chain)
- Update evaluate-model.py to support configurable model architectures
- All 13 Rust tests pass, all 45 RVF files have valid SFVR headers

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 04:57:47 +00:00
rUv
e39b5901c1 feat(decompiler): rebuild all versions — organized source/rvf separation, 100% coverage
Rebuilt all 4 versions from scratch:
- v0.2.x: 1,049 classes, 13,869 functions, 3,375 RVF vectors
- v1.0.x: 1,390 classes, 16,593 functions, 4,669 RVF vectors
- v2.0.x: 1,612 classes, 20,395 functions, 5,712 RVF vectors
- v2.1.x: 1,632 classes, 19,906 functions, 9,058 RVF vectors

Structure: source/ (17 JS modules in subfolders) + rvf/ (9 containers)
- Zero mixing: no JS in rvf dirs, no RVF in source dirs
- 100% code coverage: uncategorized/ catches everything
- 17 modules: core/3, tools/3, permissions/1, config/3, telemetry/1, ui/2, types/1, uncategorized/1
- 9 RVF containers per version (1 master + 8 per-category)

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 03:18:41 +00:00
rUv
e51406de90 docs: update README with 95.7% SOTA results + npm CLI, update research index
README: added SOTA comparison table, npm CLI usage, MCP tool examples,
training v1→v2 progression (75.7%→95.7%).

Research index: added docs 19-21, RVF corpus table, tools index,
SOTA results summary.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 03:01:48 +00:00
rUv
2b173d4df5 feat(decompiler): 95.7% accuracy — beats SOTA by 32.7 points
v2 model trained on 8,201 pairs (5x expansion):
- Val accuracy: 75.7% → 95.7% (+20 points)
- Val loss: 0.914 → 0.149 (6x improvement)
- Beats JSNice (63%), DIRE (65.8%), VarCLR (72%) by wide margin

Updated all ADRs and research docs with v2 results.
Exported weights-v2.bin (2.6MB) for pure Rust inference.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 02:58:36 +00:00
rUv
885c32a74c docs: update SOTA research + model weight analysis with implementation results
SOTA research: added implementation status table, validation results
showing 75.7% accuracy beating JSNice (63%), DIRE (65.8%), VarCLR (72%).

Model weight analysis: added Section 8 with trained model details,
inference backends, training pipeline, and ADR status.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 02:48:08 +00:00
rUv
19578402e3 feat(decompiler): MinCut-based JS decompiler with witness chains (ADR-135)
5-phase decompilation pipeline:
1. Regex-based parser extracts declarations, strings, property accesses
2. MinCut graph partitioning detects original module boundaries
3. Name inference with confidence scoring (HIGH/MEDIUM/LOW)
4. V3 source map generation (browser DevTools compatible)
5. SHAKE-256 Merkle witness chains for cryptographic provenance

Ground-truth validation:
- 5 test fixtures (Express, MCP Server, React, Multi-Module, Tools)
- Self-learning feedback loop via learn_from_ground_truth()
- 14 tests, all passing

SOTA research document covering JSNice, DeGuard, cross-version
fingerprinting, and RuVector's unique advantage combining MinCut,
IIT Phi, SONA, and HNSW for decompilation.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-03 00:04:36 +00:00
rUv
930fca916f feat(sse): decouple SSE to mcp.pi.ruv.io proxy + Claude Code source research
SSE Proxy Decoupling (ADR-130):
- Fix ruvbrain-sse proxy: proper MCP handshake, session creation, drain polling
- Fix internal queue endpoints: session_create keeps receiver, drain returns buffered messages
- Add response_queues to AppState for SSE proxy communication
- Skip sparsifier for >5M edge graphs (was crashing on 16M edges)
- Add SSE_DISABLED/MAX_SSE env vars for configurable connection limits
- Route SSE to dedicated mcp.pi.ruv.io subdomain (Cloudflare CNAME)
- Serve SSE at root / path on proxy (no /sse needed)
- Update all references from pi.ruv.io/sse to mcp.pi.ruv.io
- Fix Dockerfile consciousness crate build (feature/version mismatches)

Claude Code CLI Source Research (ADR-133):
- 19 research documents analyzing Claude Code internals (3000+ lines)
- Decompiler script + RVF corpus builder for all major versions
- Binary RVF containers for v0.2, v1.0, v2.0, v2.1 (300-2068 vectors each)
- Call graphs, class hierarchies, state machines from minified source

Integration Strategy (ADR-134):
- 6-tier integration plan: WASM MCP, agents, hooks, cache, SDK, plugin
- Integration guide with architecture diagrams and performance targets

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-04-02 23:39:56 +00:00
rUv
3569b697c1 feat(examples): gene, climate, ecosystem, quantum consciousness explorers
Four new IIT 4.0 analysis applications:

Gene Networks: 16-gene regulatory network with 4 modules.
  Cancer increases degeneracy 9x. Networks are perfectly decomposable.

Climate: 7 climate modes (ENSO, NAO, PDO, AMO, IOD, SAM, QBO).
  All modes independent (7/7 rank). IIT auto-discovers ENSO-IOD coupling.

Ecosystems: Rainforest vs monoculture vs coral reef food webs.
  Degeneracy predicts fragility: monoculture 1.10 vs rainforest 0.12.

Quantum: Bell, GHZ, Product, W states + random circuits.
  IIT Phi disagrees with entanglement. Emergence index tracks it better.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-03-31 22:01:55 +00:00