Harden Stackchan controls and release authority - #220
Draft
RobVanProd wants to merge 46 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This draft is the repository-truth and release-authority lane for Stackchan: Alive. It preserves emergency-stop-only containment, the public motion-off-at-boot correction, exact-host release controls, current hardware truth, and a sealed passive no-motion recorder for real-device qualification.
Current head:
6de75980(Record physical recorder diagnostics).Latest physical checkpoint
Installed private
stackchan_release_forensicsfirmware is source-bound toa0f56b76, SHA-2562e9924e621e305b10642c2a0db395ed6aee7bdbd9766ea90faca7760a971fb62, confirmed onapp0. Live motion request, autonomous motion, servo power, rail, and torque are off. The preserved first boot reports ESP panic reset code 4 with no PMIC boot event; no power, firmware, USB, or board cause is inferred. P1 and P2 remain on hold, and the candidate has camera/host vision compiled out.A supervised current-image speech attempt failed before STT: 81 chunks / 129,600 bytes (4.05 seconds PCM) arrived across 18.436 seconds of wall capture; one firmware capture-service call took 7.504 seconds; VAD produced no endpoint; no
utterance_end, STT, model, TTS, or reply followed. The operator had not finished speaking. The expected-vs-Whisper diagnostic remains unconsumed, so no WER is claimed. The evidence points to discontinuous capture/terminal delivery, not another silence-tail tuning problem.New evidence controls
GET /debug; its only write is mandatoryGET /motion-stopafter an observed authority breach.BRANCH_LEDGER.md:output/worktrees/aliveness-repository-truthis the sole qualification worktree; the primary checkout is not a qualification host;agent/away-cloudflare-bridgeis explicitly quarantined because it predates SEC-001/SEC-002 and currentemergency_stop_onlyreview.Real-device recorder evidence
output/pc-brain/passive-no-motion-diagnostic-edd519f9-20260805-203820is an ignored/private exact-source packet from committed recorder sourceedd519f9:This validates recorder mechanics against the physical robot. It is short expected-fail diagnostic evidence, not P1 or long-term stability.
Validation
git diff --check: PASSHolds and next work