Epic: #12 · Cross-repo counterparts: ruvnet/rvm#35 (anchor chain), ruvnet/ruflo#3066 (the contract) · Program epic: ruvnet/RuVector#837 · Plan: 03-program-plan.md in ruvnet/ruvector
⚠️ Two premise corrections — this issue has been reframed twice
(1) This crate is not a duplicate, and its original title was wrong. An earlier program pass said this repo's witness crate duplicates rvm-witness and should be refactored to depend on it. Source verification found that framing is wrong, and this issue no longer asks for it:
|
this repo's witness |
rvm-witness |
| Size |
~302 LOC |
~4,405 LOC |
| Crypto |
SHA-256 / Ed25519 |
ratcheted MAC |
| Structure |
service-side records |
no_std ring buffer |
| Layer |
application / service |
hypervisor |
Architecturally different by design. A 302-LOC service-side signing layer taking a dependency on a 4,405-LOC no_std hypervisor ring buffer would be a mistake, not a cleanup. Neither should merge into or depend on the other.
(2) The shared contract already exists — do not design a new one. This issue previously asked for a new shared schema. ruvnet/ruflo ADR-322 (Status: Accepted, phases 0–2 implemented) already specifies the 322C verification stack — JCS canonicalization, SHA-256, Ed25519 with domain separation, and independent statistical recomputation — plus proposer/promoter separation of powers. See also ruflo ADR-381. PIR adopts it as the canonical cross-repo contract (ruvnet/ruflo#3066).
⚠️ Citation correction that originates in this repo
ADR-400 and ADR-401 in this repo cite a "metaharness ADR-322." That is a misattribution. ADR-322 is ruvnet/ruflo's ADR, not MetaHarness's — and MetaHarness's own ADR series tops out at 250, so no ADR-322 can exist there. Correcting this at the source is an acceptance criterion below, because the program has already had to route around it once.
Goal
Make promotion records produced here conform to ruflo ADR-322C, so they can be anchored into an RVM witness chain (ruvnet/rvm#35) and independently verified against it.
Same chain of custody, two implementations, one already-accepted contract. This repo keeps its own implementation.
Why the program needs this
PIR's acceptance test requires every promoted mutation across a 30-day run to be traceable end-to-end in a single witness-chain query: proposal → evaluation → promotion → resulting state. Anchoring against a shared contract makes that query writable without either side giving up its architecture.
Grounding note
The real implementation here is TypeScript in packages/radio-moe/ (~6.2K LOC source + 3.2K LOC test), not the Rust crate listing an earlier program pass pointed at. Scope this work against the TypeScript.
This repo is PIR's primary prior art, not a downstream consumer: ADR-401 "The Perpetual Intelligence Machine" (Accepted, 2026-08-16), ADR-400 (Accepted — implemented, first flywheel turn measured), and ADR-403 (Accepted) already define the concept PIR extends.
Acceptance criteria
Dependencies
ruvnet/ruflo#3066 (the contract) and WP1. Paired with ruvnet/rvm#35. Blocks WP11 (#11).
Epic: #12 · Cross-repo counterparts: ruvnet/rvm#35 (anchor chain), ruvnet/ruflo#3066 (the contract) · Program epic: ruvnet/RuVector#837 · Plan:
03-program-plan.mdinruvnet/ruvector(1) This crate is not a duplicate, and its original title was wrong. An earlier program pass said this repo's
witnesscrate duplicatesrvm-witnessand should be refactored to depend on it. Source verification found that framing is wrong, and this issue no longer asks for it:witnessrvm-witnessno_stdring bufferArchitecturally different by design. A 302-LOC service-side signing layer taking a dependency on a 4,405-LOC
no_stdhypervisor ring buffer would be a mistake, not a cleanup. Neither should merge into or depend on the other.(2) The shared contract already exists — do not design a new one. This issue previously asked for a new shared schema.
ruvnet/rufloADR-322 (Status: Accepted, phases 0–2 implemented) already specifies the 322C verification stack — JCS canonicalization, SHA-256, Ed25519 with domain separation, and independent statistical recomputation — plus proposer/promoter separation of powers. See also ruflo ADR-381. PIR adopts it as the canonical cross-repo contract (ruvnet/ruflo#3066).ADR-400 and ADR-401 in this repo cite a "metaharness ADR-322." That is a misattribution. ADR-322 is
ruvnet/ruflo's ADR, not MetaHarness's — and MetaHarness's own ADR series tops out at 250, so no ADR-322 can exist there. Correcting this at the source is an acceptance criterion below, because the program has already had to route around it once.Goal
Make promotion records produced here conform to ruflo ADR-322C, so they can be anchored into an RVM witness chain (ruvnet/rvm#35) and independently verified against it.
Same chain of custody, two implementations, one already-accepted contract. This repo keeps its own implementation.
Why the program needs this
PIR's acceptance test requires every promoted mutation across a 30-day run to be traceable end-to-end in a single witness-chain query: proposal → evaluation → promotion → resulting state. Anchoring against a shared contract makes that query writable without either side giving up its architecture.
Grounding note
The real implementation here is TypeScript in
packages/radio-moe/(~6.2K LOC source + 3.2K LOC test), not the Rust crate listing an earlier program pass pointed at. Scope this work against the TypeScript.This repo is PIR's primary prior art, not a downstream consumer: ADR-401 "The Perpetual Intelligence Machine" (Accepted, 2026-08-16), ADR-400 (Accepted — implemented, first flywheel turn measured), and ADR-403 (Accepted) already define the concept PIR extends.
Acceptance criteria
rvm-witnessis introduced, and none in reverse. A review criterion confirms this.lineage,ledger, andpromotioncontinue to work unchanged from their callers' perspective.rvmADR-285's discipline).ruvnet/ruflo's ADR-322.Dependencies
ruvnet/ruflo#3066 (the contract) and WP1. Paired with ruvnet/rvm#35. Blocks WP11 (#11).