Skip to content

feat(eval): audit regional ALPR camera data - #427

Open
Medformatik wants to merge 3 commits into
mainfrom
feat/regional-camera-audit
Open

Medformatik wants to merge 3 commits into
mainfrom
feat/regional-camera-audit

Conversation

@Medformatik

Copy link
Copy Markdown
Collaborator

Summary

  • Add a bounded, local-file ALPR audit and attributed unverified awareness GeoJSON. Partial responses, invalid coordinates/dates/identities, stale review versions, inactive/planned cameras and nonregular/oversized inputs fail closed. No network/polling, production overlay, reporting editor or route option is added.
  • Pin the Aachen pilot: 239 source objects, two explicit ALPR records; one excluded because its source note says actual position is unknown, one retained as an unverified parking camera with two direction values. Prototype export go; production awareness and avoidance no-go. OSM edit/snapshot dates are separate from physical observation.
  • Document licenses, hashes, geographic limits, request costs, exposure versus avoidance semantics and the independent-data/engine-proof gates. Add a CI type step for the private tool and link the existing map baseline. Synthetic fixtures only in Git.

Reproduction archive is stored outside Git as a collapsed Base64 ZIP with checksum/decoding instructions; the CLI rejects ZIP attachments and the browser is signed out. The posted bytes were retrieved, decoded and verified against the original archive.

Related issues

Refs #407. The audited regional decision and reusable tooling are delivered; independent physical checks and any actual production map/routing surface remain follow-ups.

How was this tested?

  • Regression-first classifier/provenance/validation and real CLI tests. Initial 22 behavioral failures became green; review lifecycle and FIFO findings reproduced RED (three eligible removed/planned devices and an indefinite read timeout), then fixed. Actual-byte cap and stale-stat growth/exact-boundary checks included.
  • 45 focused tests passed, plus 44 preservation tests covering existing webcams, routing alerts and CI contracts. Fresh independent reviewer independently ran 39 pre-fix cases and reproduced the pilot; one fix pass followed.
  • Final mandatory pre-push suite: 1,612 files / 17,712 tests passed, 30 files / 138 opt-in tests skipped. All 30 workspace type projects, explicit script type project, root lint (0 errors; 282 existing warnings), policy/translations/OpenAPI and docs production build passed.
  • Original archived pilot and reviewed CLI produce byte-identical audit/GeoJSON outputs. All ten pairwise git merge-tree probes across overnight branches are clean; the new baseline link was moved to avoid the earlier evaluation PR's appended paragraph.

No UI changes or screenshots. No real-world camera precision/recall, route comparisons, detour result, current camera presence or surveillance-free-route claim. The captured source is 70.965 days old; it is a research snapshot, not a live feed.

Rulings: offline audit instead of premature live overlay (cost: no user-facing capability); exclude unknown actual position by source/version (cost: a potentially useful approximate point is absent); external archive/synthetic repo tests (cost: archive availability depends on GitHub); bound eligible ALPR/pairs to 1,000 with explicit pair truncation (cost: dense regions require partitioning); separate existing CI type step to avoid root-script conflict with #424 (cost: local root types alone needs the additional tsc command); cleanup only newly created output on ordinary write failure (cost: partial debugging files removed, inputs preserved); regrade FIFO read as important to uphold actual resource bounds (cost: regular-file check/capped buffer); relocate crosslink (cost: link position only).

Review boundaries and costs: physical existence/location/type/recall remain unknown; production overlay/cache/editor/exposure/avoidance are absent; old live provider reliability was not remeasured; recorded historical HTTP timing/policy-wait depends on the capture record; query/response hashes establish artifact identity, not execution linkage; operator-supplied URL paths can contain sensitive strings despite credential/query/fragment rejection; hostile concurrent filesystem replacement/abrupt termination has no adversarial or crash-atomic guarantee; post-publication archive access is verified by the parent; full-suite/CI are parent gates, not independently repeated; no automatic merging, viewing cone, imagery interpretation or parking-to-road promotion (cost: conservative reduced usability).

Deferred minor: an empty present primary/legacy direction tag can bypass invalid-evidence handling. This affects only vector metadata, not any viewing cone/avoidance claim, and does not affect the archived sample.

Checklist

  • Conventional Commits title
  • pnpm lint && pnpm check-types && pnpm test pass locally; private script types also pass
  • No publishable package changed; changeset not applicable
  • New audit documentation and existing baseline updated
  • Code remains in the existing AGPL license tier; exported OSM data retains ODbL attribution
  • No secrets, API keys, .env, raw snapshot or screenshots committed
  • Contributor License Agreement already recorded

@Medformatik Medformatik added documentation Improvements or additions to documentation enhancement New feature or request javascript Pull requests that update javascript code labels Oct 7, 2026
@Medformatik Medformatik self-assigned this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation enhancement New feature or request javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant