VFM // 1.3CROSS-GIS DATA PROTOCOL
VIETFLEX MAP FORMAT // 27-09-2026

VFM Cross-GIS Data Protocol

VFM là lớp dữ liệu giữa thế giới vật lý và hệ thống khai thác dữ liệu: chuyển đổi, đóng gói, định danh, lập chỉ mục, bảo vệ, phân phối, trực quan hóa và bảo tồn. VFM không chỉ phục vụ GIS/WebGIS mà còn hướng tới biểu diễn world-state có cấu trúc cho Digital Twin, GeoAI, Agent và Physical World Model.

Protocol first. File second.
VFM != GIS editor · VFM != analysis engine · VFM != one storage provider

Thin runtime. Stable WebGIS.
One Dataset → One Manifest → PMTiles/MVT → HTTP Range → MapLibre

00 // VFM là gì?

VFM là một Cross-GIS interoperability protocol. Nó chuẩn hóa cách các tập liệu không gian hiểu nhau, không bắt mọi tập liệu phải được lưu giống nhau.

Identity
Liên kết nhiều native ID vào cùng một thực thể vật lý hoặc logic.
Space / Frames
CRS, vertical reference, axis order, đơn vị, local/world frame và transform.
Time / State
Phân biệt thực thể ổn định với observation và trạng thái biến đổi theo thời gian.
Relations
Topology, network, BIM, sensor, trajectory và cross-dataset relationships.
Semantics
Binding schema/ontology mà không phá native schema của nguồn.
Provenance
Nguồn, thời điểm, transform history, license, validation và hashes.
GeoJSON / GeoParquet / GPKG ----\
COG / imagery -------------------\
LAS / LAZ ------------------------> VFM Protocol ---> WebGIS / BIM
IFC / BIM -----------------------/                  Digital Twin
3D Tiles / CityGML -------------/                   GeoAI / Robot
Sensors / SLAM / trajectories --/

Bài toán gốc rễ: nhiều hệ thống có thể cùng mô tả một cây cầu, con đường, thửa đất hay tòa nhà nhưng không có cơ chế chắc chắn để biết đó là cùng một thực thể, trong cùng không gian và thời gian. VFM đặt lớp hợp đồng liên thông ở giữa các nguồn đó.

Protocol ≠ file

VFM Protocol
    |
    +-- Logical interoperability model
    |     identity / space / time / relations / provenance
    |
    +-- Domain Profiles
    |     Feature / Raster / Point Cloud / 3D / BIM / Sensor / GeoAI
    |
    +-- Encodings / transports
          .vfm binary / API / stream / database representation

VFM != .vfm. Tệp .vfm là một encoding/container của protocol. Binary Core 1.3 ở các phần dưới được đóng băng để bảo đảm deterministic interoperability, trong khi domain semantics tiếp tục mở rộng bằng profile.

Đọc Cross-GIS Protocol Model · Đọc Core Binary Specification

00A // Operational Scope

VFM tập trung vào vòng đời dữ liệu, không thay thế GIS. Dữ liệu được tạo ở survey/GIS/BIM/IoT/DB; VFM tiếp nhận để chuẩn hóa và chuyển tiếp sang các hệ tiêu thụ.

DATA PRODUCERS
survey / GIS / BIM / IoT / imagery / databases
        |
        v
VFM
convert · package · chunk · index · protect
distribute · visualize · version · preserve
        |
        v
DATA CONSUMERS
WebGIS / GIS / BIM / Twin / AI / archive
VFM DOES
Convert · normalize · package · index · LOD · integrity · encrypt/sign · distribute · preview · preserve.
VFM DOES NOT
Field capture · digitize/edit · cartographic authoring · buffer/overlay/network analysis · general GIS analytics.

Architecture rule: storage, gateway, renderer và blockchain đều có thể thay thế; VFM Dataset Identity và frozen Core contract mới là phần phải ổn định.

00B // WebGIS Reference Stack

Hiển thị WebGIS là reference path quan trọng nhất, nhưng được giữ rất mỏng để không làm VFM phụ thuộc vào một hệ thống lớn.

VFM Dataset
    |
    v
dataset.vfmm             ONE LOGICAL ENTRY
    |
    v
VFM Web Profile
    |
    +--> PMTiles / MVT   delivery profile
    |
    v
HTTP Range + cache
    |
    v
R2 / S3-compatible storage
    |
    v
MapLibre GL JS
    |
    v
WebGIS

Reference stack 1.0: MapLibre GL JS = renderer; PMTiles/MVT = Web delivery profile; Cloudflare R2 = current reference object-store deployment. Chỉ HTTP-compatible behavior là contract; tên nhà cung cấp không phải một phần của VFM.

One Dataset → One Manifest → One Runtime API → One Data Domain.

Critical-path invariant: VFM WebGIS phải tiếp tục render khi IPFS, blockchain, AI, MCP hoặc GIS server không tồn tại. IPFS/content addressing và blockchain registry thuộc trust/archive adapters, không thuộc render path.

Đọc VFM Web Runtime Profile

00C // Physical World Data Layer

VFM không phải raster-only, vector-only, LLM, RAG hay World Model. VFM là lớp biểu diễn dữ liệu có cấu trúc mà các hệ đó có thể dùng để lưu, truy xuất, kiểm chứng và học về thế giới vật lý.

VFM WORLD STATE =
Space + Time + Object + State + Sensor + History + Relation
+ Semantics + Provenance + Confidence

Optional physical-dynamics profiles:
+ Dynamics + Constraints + Actions + Uncertainty
World Memory
Lưu lịch sử trạng thái, quan sát, biến đổi và provenance của thực thể.
World State
Biểu diễn trạng thái hiện tại theo không gian-thời gian, object ID và quan hệ.
AI Dataset
Cung cấp training samples, multimodal context và dữ liệu có version/hash rõ ràng.
Retrieval Layer
Spatial/Temporal/Semantic retrieval cho RAG, Agent và tool-using AI.

Seven VFM principles

PrincipleMeaning
AccessRead only what you need — random access, chunk, index, byte range.
UniversalOne logical dataset across local, Web, cloud, CDN and offline.
IntegrityDeterministic bytes, hashes, signatures and provenance.
DeltaUpdate only what changed; avoid rewriting the whole world.
TimeSpace and time are explicit and native to state/observation profiles.
SemanticsStable IDs, schema bindings, units, relations and quality travel with data.
LODResolution follows need through progressive and adaptive access.

Performance invariant: session_cost = f(area, time, layers, fields, LOD), không phải f(total_dataset_size). Một dataset logic 500 GB có thể chỉ cần vài MB cho một view hoặc AI batch nếu profile/index cho phép selective access.

Multi-model by design

VFM
 +-- Vector / topology / network
 +-- Raster / imagery / DEM
 +-- Point cloud / LiDAR
 +-- 3D / BIM / mesh
 +-- Sensor / time-series
 +-- Semantic / metadata / relations
 +-- Future profile-defined payloads

Boundary: Frozen Core 1.3 chỉ giữ container/addressing/integrity/profile discovery. World-state semantics, AI, dynamics và multimodal payloads phải mở rộng bằng profile — không làm nở Core.

REAL WORLD
   ↓
GIS / BIM / Sensors / Imagery / IoT / LiDAR
   ↓
VFM WORLD DATA
   ├── Training Dataset
   ├── Spatial / Multimodal Retrieval
   └── Live World State
   ↓
AI / LLM / WORLD MODEL
   ↓
Reasoning / Simulation / Planning / Agent
   ↓
ACTION → REAL WORLD

Định vị dài hạn: VFM là một structured spatiotemporal representation layer for the physical world — phục vụ storage, retrieval, verification, versioning và machine intelligence.

01 // Core Freeze Contract

Core Binary là Layer 1 của VFM: deterministic container, addressing, integrity và profile discovery. Định vị Cross-GIS Protocol ở Layer 2 không thay đổi bất kỳ byte nào của Frozen Core 1.3.

Magic
56 46 4D 00 0D 0A 1A 0A
Endian
Little-endian ONLY
Header
256 bytes
Directory Entry
64 bytes
Chunk Descriptor
128 bytes
HashRecord
48 bytes
Integrity
CRC32C + SHA-256
META/PROF
Deterministic CBOR

Core 1.x invariant: đổi byte order, kích thước Header/Directory/Chunk Descriptor hoặc nghĩa field đã đóng băng phải lên major version mới. Reserved bits/bytes trong 1.x luôn bằng 0.

02 // Frozen Wire Layout

Byte 0
+-----------------------------+
| Fixed Header        256 B   |
+-----------------------------+
| Root Directory      64 B*N  |  offset=256, end <= 16384
+-----------------------------+
| zero padding / HOT sections |
| META / PROF / root indexes  |
+-----------------------------+
| section/chunk payloads      |
+-----------------------------+

Fixed Header — 256 bytes

OffSizeFieldFrozen semantics
08magic56 46 4D 00 0D 0A 1A 0A
82format_major1
102format_minor3
122header_size256
142directory_entry_size64
161byte_order1=little-endian
171header_revision1
181core_hash_algorithm1=SHA-256
191meta_codec1=deterministic CBOR
204header_flagsbits 0..7 assigned; 8..31 zero
244section_count0..252; useful Core has META/HASH/PROF
284reserved00
328directory_offset256
408directory_lengthsection_count*64
488manifest_offsetMETA offset
568manifest_lengthMETA stored/raw length
648bootstrap_end0 unless Fast-Open declared
728footer_offset0 in Core 1.3
808declared_file_sizeartifact bytes
8816dataset_uuidnon-zero logical identity
1048generation0
11232content_root_digestSHA256(decoded HASH payload)
14432directory_digestSHA256(exact Directory bytes)
17632manifest_digestSHA256(decoded canonical META)
20816build_idzero for deterministic build
2248artifact_created_unix_mszero for deterministic build
2328reserved_time0
24012reserved1zero
2524header_crc32cCRC32C bytes 0..251

Header flags

bit0 FASTOPEN_CONFORMANT
bit1 HASH_TABLE_PRESENT
bit2 PROFILE_TABLE_PRESENT
bit3 SIGNATURE_PRESENT
bit4 ENCRYPTED_CONTENT_PRESENT
bit5 DETERMINISTIC_BUILD
bit6 STRICT_INTEGRITY
bit7 IMMUTABLE_RELEASE
bits8..31 RESERVED=0

Root Directory Entry — 64 bytes

OffSizeField
04type FourCC
44flags
88logical_id
168offset
248stored_length
328raw_length
402profile_id
422section_version
442compression_id
462encryption_id
484crc32c
524hash_ref; FFFFFFFF=none
568aux

Required Core sections: META=1, HASH=2, PROF=3. Section flag bits 0..9 are CRITICAL, CONTENT_SIGNIFICANT, HOT, CHUNKED, INDEX, COMPRESSED, ENCRYPTED, IMMUTABLE, PROFILE_PRIVATE, ORDERED.

Chunk Descriptor — 128 bytes

OffSizeField
08chunk_id
88parent_section_id
168logical_key_hi
248logical_key_lo
328offset
408stored_length
488raw_length
564flags
604crc32c
642compression_id
662encryption_id
684hash_ref
728aux0
808aux1
888aux2
9632reserved=0

Codec registry

Compression IDs: 0 NONE, 1 ZSTD, 2 GZIP, 3 BROTLI, 4 raw DEFLATE, 0x8000..0xFFFE private, 0xFFFF invalid. Core encryption baseline supports only 0 NONE; cryptographic envelopes belong to security profiles.

03 // Integrity & Identity

HashRecord — 48 bytes

OffSizeField
01object_kind: 1 SECTION / 2 CHUNK
11hash_algorithm=1 SHA-256
21digest_length=32
31flags: ROOT_INCLUDED | RAW_LOGICAL
48object_id
1232digest(raw logical bytes)
444reserved=0
stored bytes -> CRC32C -> decrypt -> decompress -> raw logical bytes -> SHA-256

content_root_digest = SHA256(exact decoded HASH payload)
directory_digest    = SHA256(exact Directory bytes)
manifest_digest     = SHA256(decoded canonical META)
artifact identity   = SHA256(entire .vfm file)  // external, avoids self-reference

Compression level, physical offset and zero padding may change without changing logical content identity, provided decoded logical bytes are identical.

04 // Failure Behavior

CodeNameClass / behavior
E0001BAD_MAGICFATAL_OPEN
E0005HEADER_CRC_MISMATCHFATAL_OPEN
E0006RESERVED_NONZEROFATAL_OPEN
E0012DIRECTORY_DIGEST_MISMATCHFATAL_OPEN
E0014OVERLAPPING_RANGESFATAL_OPEN
E0015UNALIGNED_OFFSETFATAL_OPEN
E0020UNKNOWN_CRITICAL_SECTIONfail Core/profile operation
E0021UNKNOWN_NONCRITICAL_SECTIONSECTION_SKIPPED warning
E0022UNSUPPORTED_COMPRESSIONPROFILE_UNAVAILABLE
E0023UNSUPPORTED_ENCRYPTIONPROFILE_UNAVAILABLE
E0030STORED_CRC_MISMATCHINTEGRITY_FAILED
E0031RAW_LENGTH_MISMATCHINTEGRITY_FAILED
E0032HASH_REF_OUT_OF_RANGEFATAL/INTEGRITY
E0033CONTENT_HASH_MISMATCHINTEGRITY_FAILED
E0034ROOT_DIGEST_MISMATCHFATAL_OPEN
E0040DECODE_LIMIT_EXCEEDEDresource protection

05 // Independent Implementation Proof

Repository này chứa hai code path độc lập: Rust reference writer/reader và Python generator. CI yêu cầu cả hai sinh chính xác cùng artifact tối thiểu.

VFM 1.3 wire spec
       |
   +---+---+
   |       |
 Rust    Python
   |       |
   +---+---+
       |
 byte-for-byte cmp
       |
 core-minimal.vfm
core-minimal.vfm
584 bytes
META@448/27
PROF@480/1
HASH@488/96
Artifact SHA-256
5b65b13e2ae03aa3697dc869edf5168e6601be7465b1eba10331c145ebaaeefc
Content root
63978b1b7d47f8be14cf981d6eb0329c0378ff3dd186c1b51cc0e991fa695340

Run it

cargo test --all-targets
cargo run --bin vfm -- build-minimal /tmp/rust.vfm
python tools/python_reference.py --output /tmp/python.vfm
cmp /tmp/rust.vfm /tmp/python.vfm
cmp /tmp/rust.vfm fixtures/golden/core-minimal.vfm
cargo run --bin vfm -- validate fixtures/golden/core-minimal.vfm

Rust source · Python independent generator · Conformance tests

06 // Golden & Malformed Fixtures

core-minimal.vfm
Required META/HASH/PROF.
core-chunked.vfm
Exercises frozen 128-byte ChunkDescriptor + chunk hash.
malformed manifest
Expected stable error code per corrupted file.
core-binary.md
Text form of the frozen wire contract.

Malformed corpus currently includes

bad-magic.vfm                 -> E0001
bad-header-crc.vfm            -> E0005
reserved-nonzero.vfm          -> E0006
bad-directory-digest.vfm      -> E0012
overlap.vfm                   -> E0014
unaligned-offset.vfm          -> E0015
hash-ref-out-of-range.vfm     -> E0032
bad-content-hash.vfm          -> E0033
bad-root-digest.vfm           -> E0034

Status: Core Freeze Candidate, chưa phải chuẩn OGC/ISO/IETF. Golden vectors tiếp theo nên tập trung Fast-Open, ZSTD và fuzz corpus nhưng không được thay đổi Frozen Core 1.x structs.