Files
NODEDC_MISSION_CORE/docs/audits/2026-09-07-k1-causal-diagnostics-r8.md
T

3.7 KiB

Onboard K1 causal diagnostics R8

The owner screenshot after R7 corresponds to a new network.provision operation, not connection.verify. The operation failed at connect-failed in approximately 68 ms with BleakError, side_effect_status=none and network_not_applied. It did not cross the Wi-Fi dispatch boundary. The service remained active without a restart. This is distinct from the Linux route-probe TypeError corrected in R7. The Bluetooth failure origin remains unproven; a missing BlueZ device object is only a hypothesis and is not grounds for an automatic rescan or write retry.

The existing journal logger only recorded PluginExecutionError and the facade wrapper stack. The facade retains the native exception as cause, but the logger did not follow it. The new bounded causal logger records exception class and basename/function/line for up to six causes and ten frames per cause. It respects suppressed context and terminates cycles. It never renders exception messages, source lines, frame locals or payloads. Both journalled and outer HTTP failure paths use it. Error responses and device admission are unchanged.

A regression now passes through the actual NodeBridge and plugin facade with only the service endpoint replaced. It verifies that the native BleakError location survives the real PluginExecutionError wrapper, exactly one connect is followed by state observation, and generated secret material is absent from logs and the response. A second test covers cyclic and suppressed chains. The earlier test substituted NodeBridge.invoke and therefore never exercised the wrapper that obscured the installed failure.

The existing wireless modal also distinguishes its two actions more clearly. Check K1 state appears before the network fields; the provisioning action is now labelled Apply Wi-Fi and check. No new controls, permissions, retries, state machine, profiles or host-network changes are introduced. Final Connect continues to require current device/session proof.

Validation: 20 NodeBridge/package lifecycle tests, 23 focused frontend and architecture checks, 794 full Core frontend tests, Core TypeScript/production build and scoped Ruff passed. Node 0.8.6 and optional K1 0.1.5 are reserved for this source. Package, installation and owner UI results will be recorded after they are observed. This increment improves diagnosis and action clarity; it does not claim to fix the physical Bluetooth failure.

The owner screenshot and exact operation result are preserved with UTC and monotonic collection timestamps and SHA-256 hashes under private/acceptance/ k1-node085-20260907-bluetooth-1355. Browser cache clearing for that attempt has not been confirmed. No hardware commands were issued by the agent. The next physical check remains through the owner UI after clearing browser cache.

Prepared and staged release

Source 4f715e41d2 produced Node 0.8.6 (109814516 bytes, SHA256 0d7e313dedefdb6609cfec5b6b7fa983d7886349255b19bb61e3f6a3201af916) and private K1 0.1.5+private.1 (318107944 bytes, SHA256 9b271a418b7a64c336e70164d1592e41798afb29fc7de813abff026309772d53). Node TypeScript/build, Go packaging and its UI boundary test passed. The Design Guideline pin remains 5b882bc; existing application material is unchanged. The private release is retained in private/releases/mission-core-node-k1-20260907-r8, with previous releases kept.

Transfer checksums matched. APT simulation selected two upgrades and no removals. Fleet reported an idle, disconnected K1 and the same terminal failed attempt before the single Ubuntu GUI installer was opened. It awaits owner sudo authentication. Installed versions, physical Bluetooth cause and read-only control readiness remain pending, not accepted.