Skip to content

[PIR][WP8] Conform promotion records to ruflo ADR-322C for anchoring into rvm witness chains #10

Description

@ruvnet

Epic: #12 · Cross-repo counterparts: ruvnet/rvm#35 (anchor chain), ruvnet/ruflo#3066 (the contract) · Program epic: ruvnet/RuVector#837 · Plan: 03-program-plan.md in ruvnet/ruvector

⚠️ Two premise corrections — this issue has been reframed twice

(1) This crate is not a duplicate, and its original title was wrong. An earlier program pass said this repo's witness crate duplicates rvm-witness and should be refactored to depend on it. Source verification found that framing is wrong, and this issue no longer asks for it:

this repo's witness rvm-witness
Size ~302 LOC ~4,405 LOC
Crypto SHA-256 / Ed25519 ratcheted MAC
Structure service-side records no_std ring buffer
Layer application / service hypervisor

Architecturally different by design. A 302-LOC service-side signing layer taking a dependency on a 4,405-LOC no_std hypervisor ring buffer would be a mistake, not a cleanup. Neither should merge into or depend on the other.

(2) The shared contract already exists — do not design a new one. This issue previously asked for a new shared schema. ruvnet/ruflo ADR-322 (Status: Accepted, phases 0–2 implemented) already specifies the 322C verification stack — JCS canonicalization, SHA-256, Ed25519 with domain separation, and independent statistical recomputation — plus proposer/promoter separation of powers. See also ruflo ADR-381. PIR adopts it as the canonical cross-repo contract (ruvnet/ruflo#3066).

⚠️ Citation correction that originates in this repo

ADR-400 and ADR-401 in this repo cite a "metaharness ADR-322." That is a misattribution. ADR-322 is ruvnet/ruflo's ADR, not MetaHarness's — and MetaHarness's own ADR series tops out at 250, so no ADR-322 can exist there. Correcting this at the source is an acceptance criterion below, because the program has already had to route around it once.

Goal

Make promotion records produced here conform to ruflo ADR-322C, so they can be anchored into an RVM witness chain (ruvnet/rvm#35) and independently verified against it.

Same chain of custody, two implementations, one already-accepted contract. This repo keeps its own implementation.

Why the program needs this

PIR's acceptance test requires every promoted mutation across a 30-day run to be traceable end-to-end in a single witness-chain query: proposal → evaluation → promotion → resulting state. Anchoring against a shared contract makes that query writable without either side giving up its architecture.

Grounding note

The real implementation here is TypeScript in packages/radio-moe/ (~6.2K LOC source + 3.2K LOC test), not the Rust crate listing an earlier program pass pointed at. Scope this work against the TypeScript.

This repo is PIR's primary prior art, not a downstream consumer: ADR-401 "The Perpetual Intelligence Machine" (Accepted, 2026-08-16), ADR-400 (Accepted — implemented, first flywheel turn measured), and ADR-403 (Accepted) already define the concept PIR extends.

Acceptance criteria

  • Promotion records emitted here conform to ruflo ADR-322C — JCS canonicalization, SHA-256, Ed25519 with the specified domain separation — and carry what the independent statistical recomputation step requires.
  • Records are verifiably anchorable into an RVM chain, demonstrated by a cross-repo test with [PIR][WP8] Anchor autogenous promotion records into rvm-witness chains via ruflo ADR-322C rvm#35.
  • No dependency edge on rvm-witness is introduced, and none in reverse. A review criterion confirms this.
  • ADR-322C's proposer/promoter separation of powers is preserved across the repo boundary.
  • lineage, ledger, and promotion continue to work unchanged from their callers' perspective.
  • Existing records are either convertible to ADR-322C or explicitly declared non-portable, with consequences for historical audit stated rather than discovered later.
  • The anchored record's assurance level is documented honestly — a service-side record anchored into a hypervisor chain does not thereby acquire hypervisor-side guarantees (per rvm ADR-285's discipline).
  • Rollback via the existing promotion/rollback controller still fires correctly with anchored records — verified by an injected failure, not unit tests alone, since WP12 depends on that path working live.
  • ADR-400 and ADR-401's "metaharness ADR-322" citations are corrected to point at ruvnet/ruflo's ADR-322.
  • Both maintainer teams sign off.

Dependencies

ruvnet/ruflo#3066 (the contract) and WP1. Paired with ruvnet/rvm#35. Blocks WP11 (#11).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cross-repoCoordination-dependent across reposphase-2PIR Phase 2pirRuV Perpetual Intelligence Runtime programsecurityTouches witness/proof-gate/capability/quarantine

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions