NODEDC_MISSION_CORE/docs/adr/0005-owner-controlled-lixel...

3.3 KiB

ADR 0005: Owner-controlled LixelGO/iPhone observation

  • Status: accepted
  • Date: 2026-07-16
  • Supersedes: only the unavailable-phone assumption in ADR 0001

Context

ADR 0001 correctly described the original stand: no phone and no LixelGO were available, so they could not be dependencies or test oracles. An owner-controlled iPhone with LixelGO is now available for a new, evidence-only experiment. The previous no-phone results remain valid historical evidence.

An ordinary third client on the mesh Wi-Fi cannot normally observe unicast traffic between the iPhone and K1. Apple's native Remote Virtual Interface path requires rvictl, which is installed by full Xcode and is absent from the current Mac. Installing full Xcode solely for the first capture is unnecessary.

Decision

The XGRIDS plugin may use a pinned, isolated pymobiledevice3 lab environment to read the iPhone pcapd service over a trusted USB connection. This mirrors the iPhone IP stack while the phone remains connected to K1 over Wi-Fi. It is a lab subprocess, not a root Mission Core dependency.

The experiment is evidence-only:

  • no TLS interception or MITM certificate;
  • no app automation;
  • no new BLE or MQTT write;
  • no router, firmware, device-file, or application mutation;
  • no camera or command semantic claim until bounded decode and a controlled physical correlation are both present.

Network capture does not include BLE HCI. Bluetooth capture is a separate gate that requires Apple's diagnostic logging profile, explicit operator approval, and removal of that profile after the experiment.

All captures are sensitive, mode 0600, bounded in duration, stored under ignored sessions/, hashed, and represented in Git/Ops only by redacted facts. No device ID, credential, SSID, router metadata, or raw packet payload enters normal Git history.

Entry gate

LixelGO/iPhone observation starts only after ADR 0004's post-refactor physical regression succeeds on exact firmware 3.0.2 and direct-LAN:

  1. operator attestation;
  2. prepare the receiver;
  3. physical double-click start;
  4. first real point frame and pose through the new normalizer/viewer path;
  5. raw evidence finalization;
  6. operator-confirmed physical stop;
  7. verification that Mission Core emitted no K1 application command.

Consequences

Full Xcode, rvictl, Wireshark, and system/Homebrew changes are not required for the first IP capture. TLS or proprietary encryption may remain opaque; endpoint, port, size, timing, interface, process, and plaintext local protocol evidence are still useful. Any discovered state-changing contract requires a new profile revision and its own acceptance gate before implementation.

Outcome recorded on 2026-07-16

Lab 002 completed the bounded observation. It found a plaintext local MQTT data and control plane plus two RTSP/H.264 camera preview endpoints. Owner-operated LixelGO start and stop were correlated with bounded protobuf action values 1 and 2, device success responses, physical K1 transitions and start/stop of the high-rate streams. No LixelGO WAN flow was observed in either principal window.

This outcome updates descriptive evidence only. Mission Core still emits no modeling request: private header/settings construction, save-complete semantics, timeouts and rollback remain unresolved. See docs/lab/002_LIXELGO_IPHONE_LOCAL_PROTOCOL_20260716.redacted.md.