00 // VFM là gì?
VFM là một Cross-GIS interoperability protocol. Nó chuẩn hóa cách các tập liệu không gian hiểu nhau, không bắt mọi tập liệu phải được lưu giống nhau.
Liên kết nhiều native ID vào cùng một thực thể vật lý hoặc logic.
CRS, vertical reference, axis order, đơn vị, local/world frame và transform.
Phân biệt thực thể ổn định với observation và trạng thái biến đổi theo thời gian.
Topology, network, BIM, sensor, trajectory và cross-dataset relationships.
Binding schema/ontology mà không phá native schema của nguồn.
Nguồn, thời điểm, transform history, license, validation và hashes.
GeoJSON / GeoParquet / GPKG ----\ COG / imagery -------------------\ LAS / LAZ ------------------------> VFM Protocol ---> WebGIS / BIM IFC / BIM -----------------------/ Digital Twin 3D Tiles / CityGML -------------/ GeoAI / Robot Sensors / SLAM / trajectories --/
Bài toán gốc rễ: nhiều hệ thống có thể cùng mô tả một cây cầu, con đường, thửa đất hay tòa nhà nhưng không có cơ chế chắc chắn để biết đó là cùng một thực thể, trong cùng không gian và thời gian. VFM đặt lớp hợp đồng liên thông ở giữa các nguồn đó.
Protocol ≠ file
VFM Protocol
|
+-- Logical interoperability model
| identity / space / time / relations / provenance
|
+-- Domain Profiles
| Feature / Raster / Point Cloud / 3D / BIM / Sensor / GeoAI
|
+-- Encodings / transports
.vfm binary / API / stream / database representation
VFM != .vfm. Tệp .vfm là một encoding/container của protocol. Binary Core 1.3 ở các phần dưới được đóng băng để bảo đảm deterministic interoperability, trong khi domain semantics tiếp tục mở rộng bằng profile.
Đọc Cross-GIS Protocol Model · Đọc Core Binary Specification
00A // Operational Scope
VFM tập trung vào vòng đời dữ liệu, không thay thế GIS. Dữ liệu được tạo ở survey/GIS/BIM/IoT/DB; VFM tiếp nhận để chuẩn hóa và chuyển tiếp sang các hệ tiêu thụ.
DATA PRODUCERS
survey / GIS / BIM / IoT / imagery / databases
|
v
VFM
convert · package · chunk · index · protect
distribute · visualize · version · preserve
|
v
DATA CONSUMERS
WebGIS / GIS / BIM / Twin / AI / archive
Convert · normalize · package · index · LOD · integrity · encrypt/sign · distribute · preview · preserve.
Field capture · digitize/edit · cartographic authoring · buffer/overlay/network analysis · general GIS analytics.
Architecture rule: storage, gateway, renderer và blockchain đều có thể thay thế; VFM Dataset Identity và frozen Core contract mới là phần phải ổn định.
00B // WebGIS Reference Stack
Hiển thị WebGIS là reference path quan trọng nhất, nhưng được giữ rất mỏng để không làm VFM phụ thuộc vào một hệ thống lớn.
VFM Dataset
|
v
dataset.vfmm ONE LOGICAL ENTRY
|
v
VFM Web Profile
|
+--> PMTiles / MVT delivery profile
|
v
HTTP Range + cache
|
v
R2 / S3-compatible storage
|
v
MapLibre GL JS
|
v
WebGIS
Reference stack 1.0: MapLibre GL JS = renderer; PMTiles/MVT = Web delivery profile; Cloudflare R2 = current reference object-store deployment. Chỉ HTTP-compatible behavior là contract; tên nhà cung cấp không phải một phần của VFM.
One Dataset → One Manifest → One Runtime API → One Data Domain.
Critical-path invariant: VFM WebGIS phải tiếp tục render khi IPFS, blockchain, AI, MCP hoặc GIS server không tồn tại. IPFS/content addressing và blockchain registry thuộc trust/archive adapters, không thuộc render path.
00C // Physical World Data Layer
VFM không phải raster-only, vector-only, LLM, RAG hay World Model. VFM là lớp biểu diễn dữ liệu có cấu trúc mà các hệ đó có thể dùng để lưu, truy xuất, kiểm chứng và học về thế giới vật lý.
VFM WORLD STATE = Space + Time + Object + State + Sensor + History + Relation + Semantics + Provenance + Confidence Optional physical-dynamics profiles: + Dynamics + Constraints + Actions + Uncertainty
Lưu lịch sử trạng thái, quan sát, biến đổi và provenance của thực thể.
Biểu diễn trạng thái hiện tại theo không gian-thời gian, object ID và quan hệ.
Cung cấp training samples, multimodal context và dữ liệu có version/hash rõ ràng.
Spatial/Temporal/Semantic retrieval cho RAG, Agent và tool-using AI.
Seven VFM principles
| Principle | Meaning |
|---|---|
| Access | Read only what you need — random access, chunk, index, byte range. |
| Universal | One logical dataset across local, Web, cloud, CDN and offline. |
| Integrity | Deterministic bytes, hashes, signatures and provenance. |
| Delta | Update only what changed; avoid rewriting the whole world. |
| Time | Space and time are explicit and native to state/observation profiles. |
| Semantics | Stable IDs, schema bindings, units, relations and quality travel with data. |
| LOD | Resolution follows need through progressive and adaptive access. |
Performance invariant: session_cost = f(area, time, layers, fields, LOD), không phải f(total_dataset_size). Một dataset logic 500 GB có thể chỉ cần vài MB cho một view hoặc AI batch nếu profile/index cho phép selective access.
Multi-model by design
VFM +-- Vector / topology / network +-- Raster / imagery / DEM +-- Point cloud / LiDAR +-- 3D / BIM / mesh +-- Sensor / time-series +-- Semantic / metadata / relations +-- Future profile-defined payloads
Boundary: Frozen Core 1.3 chỉ giữ container/addressing/integrity/profile discovery. World-state semantics, AI, dynamics và multimodal payloads phải mở rộng bằng profile — không làm nở Core.
REAL WORLD ↓ GIS / BIM / Sensors / Imagery / IoT / LiDAR ↓ VFM WORLD DATA ├── Training Dataset ├── Spatial / Multimodal Retrieval └── Live World State ↓ AI / LLM / WORLD MODEL ↓ Reasoning / Simulation / Planning / Agent ↓ ACTION → REAL WORLD
Định vị dài hạn: VFM là một structured spatiotemporal representation layer for the physical world — phục vụ storage, retrieval, verification, versioning và machine intelligence.
01 // Core Freeze Contract
Core Binary là Layer 1 của VFM: deterministic container, addressing, integrity và profile discovery. Định vị Cross-GIS Protocol ở Layer 2 không thay đổi bất kỳ byte nào của Frozen Core 1.3.
56 46 4D 00 0D 0A 1A 0A
Little-endian ONLY
256 bytes
64 bytes
128 bytes
48 bytes
CRC32C + SHA-256
Deterministic CBOR
Core 1.x invariant: đổi byte order, kích thước Header/Directory/Chunk Descriptor hoặc nghĩa field đã đóng băng phải lên major version mới. Reserved bits/bytes trong 1.x luôn bằng 0.
02 // Frozen Wire Layout
Byte 0 +-----------------------------+ | Fixed Header 256 B | +-----------------------------+ | Root Directory 64 B*N | offset=256, end <= 16384 +-----------------------------+ | zero padding / HOT sections | | META / PROF / root indexes | +-----------------------------+ | section/chunk payloads | +-----------------------------+
Fixed Header — 256 bytes
| Off | Size | Field | Frozen semantics |
|---|---|---|---|
| 0 | 8 | magic | 56 46 4D 00 0D 0A 1A 0A |
| 8 | 2 | format_major | 1 |
| 10 | 2 | format_minor | 3 |
| 12 | 2 | header_size | 256 |
| 14 | 2 | directory_entry_size | 64 |
| 16 | 1 | byte_order | 1=little-endian |
| 17 | 1 | header_revision | 1 |
| 18 | 1 | core_hash_algorithm | 1=SHA-256 |
| 19 | 1 | meta_codec | 1=deterministic CBOR |
| 20 | 4 | header_flags | bits 0..7 assigned; 8..31 zero |
| 24 | 4 | section_count | 0..252; useful Core has META/HASH/PROF |
| 28 | 4 | reserved0 | 0 |
| 32 | 8 | directory_offset | 256 |
| 40 | 8 | directory_length | section_count*64 |
| 48 | 8 | manifest_offset | META offset |
| 56 | 8 | manifest_length | META stored/raw length |
| 64 | 8 | bootstrap_end | 0 unless Fast-Open declared |
| 72 | 8 | footer_offset | 0 in Core 1.3 |
| 80 | 8 | declared_file_size | artifact bytes |
| 88 | 16 | dataset_uuid | non-zero logical identity |
| 104 | 8 | generation | 0 |
| 112 | 32 | content_root_digest | SHA256(decoded HASH payload) |
| 144 | 32 | directory_digest | SHA256(exact Directory bytes) |
| 176 | 32 | manifest_digest | SHA256(decoded canonical META) |
| 208 | 16 | build_id | zero for deterministic build |
| 224 | 8 | artifact_created_unix_ms | zero for deterministic build |
| 232 | 8 | reserved_time | 0 |
| 240 | 12 | reserved1 | zero |
| 252 | 4 | header_crc32c | CRC32C bytes 0..251 |
Header flags
bit0 FASTOPEN_CONFORMANT bit1 HASH_TABLE_PRESENT bit2 PROFILE_TABLE_PRESENT bit3 SIGNATURE_PRESENT bit4 ENCRYPTED_CONTENT_PRESENT bit5 DETERMINISTIC_BUILD bit6 STRICT_INTEGRITY bit7 IMMUTABLE_RELEASE bits8..31 RESERVED=0
Root Directory Entry — 64 bytes
| Off | Size | Field |
|---|---|---|
| 0 | 4 | type FourCC |
| 4 | 4 | flags |
| 8 | 8 | logical_id |
| 16 | 8 | offset |
| 24 | 8 | stored_length |
| 32 | 8 | raw_length |
| 40 | 2 | profile_id |
| 42 | 2 | section_version |
| 44 | 2 | compression_id |
| 46 | 2 | encryption_id |
| 48 | 4 | crc32c |
| 52 | 4 | hash_ref; FFFFFFFF=none |
| 56 | 8 | aux |
Required Core sections: META=1, HASH=2, PROF=3. Section flag bits 0..9 are CRITICAL, CONTENT_SIGNIFICANT, HOT, CHUNKED, INDEX, COMPRESSED, ENCRYPTED, IMMUTABLE, PROFILE_PRIVATE, ORDERED.
Chunk Descriptor — 128 bytes
| Off | Size | Field |
|---|---|---|
| 0 | 8 | chunk_id |
| 8 | 8 | parent_section_id |
| 16 | 8 | logical_key_hi |
| 24 | 8 | logical_key_lo |
| 32 | 8 | offset |
| 40 | 8 | stored_length |
| 48 | 8 | raw_length |
| 56 | 4 | flags |
| 60 | 4 | crc32c |
| 64 | 2 | compression_id |
| 66 | 2 | encryption_id |
| 68 | 4 | hash_ref |
| 72 | 8 | aux0 |
| 80 | 8 | aux1 |
| 88 | 8 | aux2 |
| 96 | 32 | reserved=0 |
Codec registry
Compression IDs: 0 NONE, 1 ZSTD, 2 GZIP, 3 BROTLI, 4 raw DEFLATE, 0x8000..0xFFFE private, 0xFFFF invalid. Core encryption baseline supports only 0 NONE; cryptographic envelopes belong to security profiles.
03 // Integrity & Identity
HashRecord — 48 bytes
| Off | Size | Field |
|---|---|---|
| 0 | 1 | object_kind: 1 SECTION / 2 CHUNK |
| 1 | 1 | hash_algorithm=1 SHA-256 |
| 2 | 1 | digest_length=32 |
| 3 | 1 | flags: ROOT_INCLUDED | RAW_LOGICAL |
| 4 | 8 | object_id |
| 12 | 32 | digest(raw logical bytes) |
| 44 | 4 | reserved=0 |
stored bytes -> CRC32C -> decrypt -> decompress -> raw logical bytes -> SHA-256 content_root_digest = SHA256(exact decoded HASH payload) directory_digest = SHA256(exact Directory bytes) manifest_digest = SHA256(decoded canonical META) artifact identity = SHA256(entire .vfm file) // external, avoids self-reference
Compression level, physical offset and zero padding may change without changing logical content identity, provided decoded logical bytes are identical.
04 // Failure Behavior
| Code | Name | Class / behavior |
|---|---|---|
| E0001 | BAD_MAGIC | FATAL_OPEN |
| E0005 | HEADER_CRC_MISMATCH | FATAL_OPEN |
| E0006 | RESERVED_NONZERO | FATAL_OPEN |
| E0012 | DIRECTORY_DIGEST_MISMATCH | FATAL_OPEN |
| E0014 | OVERLAPPING_RANGES | FATAL_OPEN |
| E0015 | UNALIGNED_OFFSET | FATAL_OPEN |
| E0020 | UNKNOWN_CRITICAL_SECTION | fail Core/profile operation |
| E0021 | UNKNOWN_NONCRITICAL_SECTION | SECTION_SKIPPED warning |
| E0022 | UNSUPPORTED_COMPRESSION | PROFILE_UNAVAILABLE |
| E0023 | UNSUPPORTED_ENCRYPTION | PROFILE_UNAVAILABLE |
| E0030 | STORED_CRC_MISMATCH | INTEGRITY_FAILED |
| E0031 | RAW_LENGTH_MISMATCH | INTEGRITY_FAILED |
| E0032 | HASH_REF_OUT_OF_RANGE | FATAL/INTEGRITY |
| E0033 | CONTENT_HASH_MISMATCH | INTEGRITY_FAILED |
| E0034 | ROOT_DIGEST_MISMATCH | FATAL_OPEN |
| E0040 | DECODE_LIMIT_EXCEEDED | resource protection |
05 // Independent Implementation Proof
Repository này chứa hai code path độc lập: Rust reference writer/reader và Python generator. CI yêu cầu cả hai sinh chính xác cùng artifact tối thiểu.
VFM 1.3 wire spec
|
+---+---+
| |
Rust Python
| |
+---+---+
|
byte-for-byte cmp
|
core-minimal.vfm584 bytes
META@448/27
PROF@480/1
HASH@488/96
5b65b13e2ae03aa3697dc869edf5168e6601be7465b1eba10331c145ebaaeefc
63978b1b7d47f8be14cf981d6eb0329c0378ff3dd186c1b51cc0e991fa695340
Run it
cargo test --all-targets cargo run --bin vfm -- build-minimal /tmp/rust.vfm python tools/python_reference.py --output /tmp/python.vfm cmp /tmp/rust.vfm /tmp/python.vfm cmp /tmp/rust.vfm fixtures/golden/core-minimal.vfm cargo run --bin vfm -- validate fixtures/golden/core-minimal.vfm
Rust source · Python independent generator · Conformance tests
06 // Golden & Malformed Fixtures
Required META/HASH/PROF.
Exercises frozen 128-byte ChunkDescriptor + chunk hash.
Expected stable error code per corrupted file.
Text form of the frozen wire contract.
Malformed corpus currently includes
bad-magic.vfm -> E0001 bad-header-crc.vfm -> E0005 reserved-nonzero.vfm -> E0006 bad-directory-digest.vfm -> E0012 overlap.vfm -> E0014 unaligned-offset.vfm -> E0015 hash-ref-out-of-range.vfm -> E0032 bad-content-hash.vfm -> E0033 bad-root-digest.vfm -> E0034
Status: Core Freeze Candidate, chưa phải chuẩn OGC/ISO/IETF. Golden vectors tiếp theo nên tập trung Fast-Open, ZSTD và fuzz corpus nhưng không được thay đổi Frozen Core 1.x structs.