3.3 KiB
ADR 0005: Owner-controlled LixelGO/iPhone observation
- Status: accepted
- Date: 2026-07-16
- Supersedes: only the unavailable-phone assumption in ADR 0001
Context
ADR 0001 correctly described the original stand: no phone and no LixelGO were available, so they could not be dependencies or test oracles. An owner-controlled iPhone with LixelGO is now available for a new, evidence-only experiment. The previous no-phone results remain valid historical evidence.
An ordinary third client on the mesh Wi-Fi cannot normally observe unicast
traffic between the iPhone and K1. Apple's native Remote Virtual Interface path
requires rvictl, which is installed by full Xcode and is absent from the
current Mac. Installing full Xcode solely for the first capture is unnecessary.
Decision
The XGRIDS plugin may use a pinned, isolated pymobiledevice3 lab environment
to read the iPhone pcapd service over a trusted USB connection. This mirrors
the iPhone IP stack while the phone remains connected to K1 over Wi-Fi. It is a
lab subprocess, not a root Mission Core dependency.
The experiment is evidence-only:
- no TLS interception or MITM certificate;
- no app automation;
- no new BLE or MQTT write;
- no router, firmware, device-file, or application mutation;
- no camera or command semantic claim until bounded decode and a controlled physical correlation are both present.
Network capture does not include BLE HCI. Bluetooth capture is a separate gate that requires Apple's diagnostic logging profile, explicit operator approval, and removal of that profile after the experiment.
All captures are sensitive, mode 0600, bounded in duration, stored under
ignored sessions/, hashed, and represented in Git/Ops only by redacted facts.
No device ID, credential, SSID, router metadata, or raw packet payload enters
normal Git history.
Entry gate
LixelGO/iPhone observation starts only after ADR 0004's post-refactor physical
regression succeeds on exact firmware 3.0.2 and direct-LAN:
- operator attestation;
- prepare the receiver;
- physical double-click start;
- first real point frame and pose through the new normalizer/viewer path;
- raw evidence finalization;
- operator-confirmed physical stop;
- verification that Mission Core emitted no K1 application command.
Consequences
Full Xcode, rvictl, Wireshark, and system/Homebrew changes are not required for
the first IP capture. TLS or proprietary encryption may remain opaque; endpoint,
port, size, timing, interface, process, and plaintext local protocol evidence are
still useful. Any discovered state-changing contract requires a new profile
revision and its own acceptance gate before implementation.
Outcome recorded on 2026-07-16
Lab 002 completed the bounded observation. It found a plaintext local MQTT data
and control plane plus two RTSP/H.264 camera preview endpoints. Owner-operated
LixelGO start and stop were correlated with bounded protobuf action values 1
and 2, device success responses, physical K1 transitions and start/stop of the
high-rate streams. No LixelGO WAN flow was observed in either principal window.
This outcome updates descriptive evidence only. Mission Core still emits no
modeling request: private header/settings construction, save-complete semantics,
timeouts and rollback remain unresolved. See
docs/lab/002_LIXELGO_IPHONE_LOCAL_PROTOCOL_20260716.redacted.md.