Skip to content

Harden Stackchan controls and release authority - #220

Draft
RobVanProd wants to merge 46 commits into
mainfrom
codex/aliveness-repository-truth
Draft

Harden Stackchan controls and release authority#220
RobVanProd wants to merge 46 commits into
mainfrom
codex/aliveness-repository-truth

Conversation

@RobVanProd

@RobVanProd RobVanProd commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

This draft is the repository-truth and release-authority lane for Stackchan: Alive. It preserves emergency-stop-only containment, the public motion-off-at-boot correction, exact-host release controls, current hardware truth, and a sealed passive no-motion recorder for real-device qualification.

Current head: 6de75980 (Record physical recorder diagnostics).

Latest physical checkpoint

Installed private stackchan_release_forensics firmware is source-bound to a0f56b76, SHA-256 2e9924e621e305b10642c2a0db395ed6aee7bdbd9766ea90faca7760a971fb62, confirmed on app0. Live motion request, autonomous motion, servo power, rail, and torque are off. The preserved first boot reports ESP panic reset code 4 with no PMIC boot event; no power, firmware, USB, or board cause is inferred. P1 and P2 remain on hold, and the candidate has camera/host vision compiled out.

A supervised current-image speech attempt failed before STT: 81 chunks / 129,600 bytes (4.05 seconds PCM) arrived across 18.436 seconds of wall capture; one firmware capture-service call took 7.504 seconds; VAD produced no endpoint; no utterance_end, STT, model, TTS, or reply followed. The operator had not finished speaking. The expected-vs-Whisper diagnostic remains unconsumed, so no WER is claimed. The evidence points to discontinuous capture/terminal delivery, not another silence-tail tuning problem.

New evidence controls

  • Added a dedicated passive recorder whose ordinary robot surface is exactly GET /debug; its only write is mandatory GET /motion-stop after an observed authority breach.
  • Motion breach is checked before identity binding, and all motion, servo, power, actuator, and camera-gaze authority fields fail closed.
  • Candidate firmware/source, installed identity, host runtime/PID/root, socket owner, runner/checker Git blobs, preflight, polls, summary, and optional complete post-stop debug are sealed into one run-ID packet.
  • Qualification cadence is pinned to 2 seconds with a 4-second timeout; monotonic elapsed time is recorded and any gap above 8 seconds fails.
  • Reset/boot, power forensics, voltage, temperature, display timing, readiness, conversation lifecycle, camera activity, and zero-motion counters are independently recomputed from sealed polls.
  • Malformed boolean types, stale run IDs, packet tampering, unbounded gaps, source-blob mismatch, power events, panic reset, missing conversation lifecycle, and missing camera activity have expected-red fixtures.
  • Updated BRANCH_LEDGER.md: output/worktrees/aliveness-repository-truth is the sole qualification worktree; the primary checkout is not a qualification host; agent/away-cloudflare-bridge is explicitly quarantined because it predates SEC-001/SEC-002 and current emergency_stop_only review.
  • Repaired the firmware HTTP policy contract's exact post-SEC-002 pins and reviewed commit/file scopes. All 19 Wi-Fi environments pass.

Real-device recorder evidence

output/pc-brain/passive-no-motion-diagnostic-edd519f9-20260805-203820 is an ignored/private exact-source packet from committed recorder source edd519f9:

  • 10/10 successful real polls over 6.058 seconds
  • 5.172 seconds monotonic sample coverage; maximum gap 1.157 seconds
  • exact installed firmware and live host/socket identity throughout
  • zero motion breaches; no safety-stop call
  • motion-stop, enable, refresh, rail-enable, power-grant, and actuator-write counters unchanged at zero
  • motion, rail, and torque off afterward
  • all checker gates passed except clean reset and the summary fields truthfully carrying the preserved panic hold

This validates recorder mechanics against the physical robot. It is short expected-fail diagnostic evidence, not P1 or long-term stability.

Validation

  • Passive no-motion evidence contract: PASS
  • Firmware HTTP emergency-stop-only policy contract: PASS for all 19 Wi-Fi environments
  • Full-system soak evidence contract: PASS
  • Existing exact-source candidate gates before install: native 304/304, bridge 577/577, focused transcript/LAN 124/124, silent trusted-facts smoke, DirectML launcher contract, public build, and private build
  • git diff --check: PASS

Holds and next work

  • The preserved panic reset and camera-disabled image prevent P1 from passing.
  • P2 motor emergency-stop proof remains prohibited until an exact full P1 packet passes independent review.
  • Speech capture needs bounded phase timing, reliable end/cancel delivery, and a host capture-commit lease longer than the 12-second firmware ceiling while retaining a non-refreshable privacy cap.
  • Person/pet identity, naming/removal, following, and emotional motion remain preregistered and disabled. No model owns actuator authority.

@RobVanProd RobVanProd changed the title Harden bridge and firmware controls for Stackchan Alive Harden Stackchan controls and release authority Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant