feat(lab): add isolated iPhone capture evidence
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
# ADR 0005: Owner-controlled LixelGO/iPhone observation
|
||||
|
||||
- Status: accepted
|
||||
- Date: 2026-07-16
|
||||
- Supersedes: only the unavailable-phone assumption in ADR 0001
|
||||
|
||||
## Context
|
||||
|
||||
ADR 0001 correctly described the original stand: no phone and no LixelGO were
|
||||
available, so they could not be dependencies or test oracles. An
|
||||
owner-controlled iPhone with LixelGO is now available for a new, evidence-only
|
||||
experiment. The previous no-phone results remain valid historical evidence.
|
||||
|
||||
An ordinary third client on the mesh Wi-Fi cannot normally observe unicast
|
||||
traffic between the iPhone and K1. Apple's native Remote Virtual Interface path
|
||||
requires `rvictl`, which is installed by full Xcode and is absent from the
|
||||
current Mac. Installing full Xcode solely for the first capture is unnecessary.
|
||||
|
||||
## Decision
|
||||
|
||||
The XGRIDS plugin may use a pinned, isolated `pymobiledevice3` lab environment
|
||||
to read the iPhone `pcapd` service over a trusted USB connection. This mirrors
|
||||
the iPhone IP stack while the phone remains connected to K1 over Wi-Fi. It is a
|
||||
lab subprocess, not a root Mission Core dependency.
|
||||
|
||||
The experiment is evidence-only:
|
||||
|
||||
- no TLS interception or MITM certificate;
|
||||
- no app automation;
|
||||
- no new BLE or MQTT write;
|
||||
- no router, firmware, device-file, or application mutation;
|
||||
- no camera or command semantic claim until bounded decode and a controlled
|
||||
physical correlation are both present.
|
||||
|
||||
Network capture does not include BLE HCI. Bluetooth capture is a separate gate
|
||||
that requires Apple's diagnostic logging profile, explicit operator approval,
|
||||
and removal of that profile after the experiment.
|
||||
|
||||
All captures are sensitive, mode `0600`, bounded in duration, stored under
|
||||
ignored `sessions/`, hashed, and represented in Git/Ops only by redacted facts.
|
||||
No device ID, credential, SSID, router metadata, or raw packet payload enters
|
||||
normal Git history.
|
||||
|
||||
## Entry gate
|
||||
|
||||
LixelGO/iPhone observation starts only after ADR 0004's post-refactor physical
|
||||
regression succeeds on exact firmware `3.0.2` and direct-LAN:
|
||||
|
||||
1. operator attestation;
|
||||
2. prepare the receiver;
|
||||
3. physical double-click start;
|
||||
4. first real point frame and pose through the new normalizer/viewer path;
|
||||
5. raw evidence finalization;
|
||||
6. operator-confirmed physical stop;
|
||||
7. verification that Mission Core emitted no K1 application command.
|
||||
|
||||
## Consequences
|
||||
|
||||
Full Xcode, `rvictl`, Wireshark, and system/Homebrew changes are not required for
|
||||
the first IP capture. TLS or proprietary encryption may remain opaque; endpoint,
|
||||
port, size, timing, interface, process, and plaintext local protocol evidence are
|
||||
still useful. Any discovered state-changing contract requires a new profile
|
||||
revision and its own acceptance gate before implementation.
|
||||
|
||||
## Outcome recorded on 2026-07-16
|
||||
|
||||
Lab 002 completed the bounded observation. It found a plaintext local MQTT data
|
||||
and control plane plus two RTSP/H.264 camera preview endpoints. Owner-operated
|
||||
LixelGO start and stop were correlated with bounded protobuf action values `1`
|
||||
and `2`, device success responses, physical K1 transitions and start/stop of the
|
||||
high-rate streams. No LixelGO WAN flow was observed in either principal window.
|
||||
|
||||
This outcome updates descriptive evidence only. Mission Core still emits no
|
||||
modeling request: private header/settings construction, save-complete semantics,
|
||||
timeouts and rollback remain unresolved. See
|
||||
`docs/lab/002_LIXELGO_IPHONE_LOCAL_PROTOCOL_20260716.redacted.md`.
|
||||
Reference in New Issue
Block a user