G0 current action packet — refreshed 2026-08-16
Status: CURRENT_PUBLIC_DRAFT_HANDOFF / NO_E2_E3_E4_ACTION_TAKEN
Repository:
rsasaki0109/lidar_slam_ros2Draft PR: #427
Capture-time public Draft baseline:
3ed632e6f6aa1e3ca7f32d893773de1079086ffbCapture-time exact public Draft head and CI audit:
c1fc2847fb06637cbcd2aac61f4fde318364dfd2Latest exact public Draft head before this local increment:
4163b8c6f0ebb63504a0de398d9654333bf3919eExact reviewed product-candidate tip:
3d64ed556aca8a680f09e0f7e8c12a3c8d3e6a6dLatest product/community follow-up tip:
0d102e016717d2def3db3a99525755837461f759Latest G0 product-Draft dependency audit tip:
e08ec9cd28a59acb550556238e7ba6acb3b63cc6Latest copy-ready G0 slice verification tip:
297115d14ea0a979ee0043e24d55a2a80746e382Latest S1 rejected-map-update threshold recovery tip:
99cce93a07a7cc136eb925c446dd705bdcd7b37cLatest S6 ordinary-shell review recovery tip:
0633c2a604489538e0f087c02385e7c6467540c3Latest S6 review evidence carrier:
72a8c9e77eba33c1578a3cd9c8afe8fbe6933e33Latest distribution-audit follow-up tip:
ca7c5b5b991e5624ca16e46ffd1a057e3a9f6ee9Latest canonical-NDT publication-preflight tip:
856e59987018578963a7afdf13402200eab62bf8Latest fail-closed NDT reviewer-response gate tip:
3e11f307eb2ccea1d33bbe9a2d1b37ae7ed699dbLatest claim-bounded social-media generator tip:
d0c84bb9bb7bef37d7e318000e3071a7f536d631Latest Docker publication-authority tip:
3225d9db357caa1150081ac61281ae4b0d281a2aLatest immutable-candidate gate tip:
c70c18d32e0dd860969dbd050fa3a92632f1106eLatest candidate-gate CI follow-up tip:
87f8f8d1bcdccb80235b8ae1832f9bc716c31d36Latest tag-free candidate-observer tip:
363a971bfeb2a5ddf0b99fb9b20f5a201134a520Latest one-command candidate-trial preparation tip:
f5ed80e11e3735b7a72ba458f740d0117711be6cLatest one-command candidate-row execution tip:
feed0ba7a12135099b9eef299e914605ab2947e1Latest one-command candidate-session tip:
8bc5ea4036277de1a1819008183f989a2c4bcb76Latest guided candidate-readiness tip:
a286c6551f976c48d508ee7e9ecd7d9d4a30e734Latest protected-environment preflight tip:
adecca6e19c38e6a682253d66516379bbface46dLatest operator-handoff and GLIM parse-safety tip:
e2d916a66a57146b0efe4c74e57218d56342ed37Latest content-verified GLIM comparison tip:
3de7f84bb51acd2bd1c2b40724529be9c281d2feLatest public-docs deployment-provenance tip:
5b8c8c477cceb4955184a64afa874712b9dea5aaLatest public-docs evidence-refresh baseline:
ac22a3ff1e49c1dae3fcde47f52ae8bf8ccdb1ebLatest receipt-bound onboarding-evidence tip:
3c19824daeb5c61715fe52887e5e0e6abe6c0051Latest exact-head CI import-order repair tip:
b87c1936c1799834288d6d2c39aa616ab15c348dLatest public publication-inventory tip:
ac22a3ff1e49c1dae3fcde47f52ae8bf8ccdb1ebLatest published-onboarding-identity tip:
289f7675a242b00f342528483cde3e5f602a11fcLatest paired usability recorder tip:
0575fb6d67dc0b2069d9e41029a767bf3608687cLatest actionable release-evidence UX tip:
45cfdcb1c10756d1c33068fcd9594f612bf6cccaLatest live contributor next-action tip:
3543a71bde958278388aa8481330166d125944b9Latest dependency-gated contributor next-action tip:
76be89576ae544d77e661bc5d098b5087b497c5cLatest independent starter-review tip:
e4ce0aa6eb7d53423423a02af65f923472708f44Latest exact starter-publication-handoff tip:
0a34e724875d53b8ef74acd8a51fd500ce014ff5Latest public-base-gated starter-publication tip:
5dc04198549341b33becdeb2bc058117db9fe78fLatest unified public-product-transition tip:
4404f877263157d09ae6c451dae55f5ddbbd03afLatest goal-based README chooser tip:
8a8876a2d26c09cc92ad330b99d1fa217db1bd8dLatest canonical three-goal onboarding chooser tip:
1e56431161d3dea417d5d800bb1eedc3cdb51907Latest honest FAIL-without-receipt intake tip:
da99c7ef82136449727ef97a58c1a2db4ffd6955Latest pre-session bug-intake tip:
4b1707cdbc2dc41f3d7b52aa8c598841fc925767Latest location-safe Autoware-intake tip:
51496ca576b668d9e7dc0e7fda39ebdc21b7e1c8Latest redaction-first first-map reporting tip:
a0aaadc80b952d92074f45499c29a5103a2ad479Latest redaction-first benchmark reporting tip:
940195b75ea6aff648171b120539a9ab01a0248eLatest path-free public doctor evidence tip:
6a1dd87e85b966492ebefea84e87a46917885669Latest privacy-first doctor support handoff tip:
71cbf7e776664d40c59157fbfbad4d5611ceae03Latest one-action bag-doctor handoff tip:
387a002dc7826be267fe600db906f80460e6f270Latest compact product bag-doctor card tip:
fc87cf86cabba5f55fec47316c6a9a3a4e4cb90fLatest single-prompt interactive start tip:
90c508eef4c6ce6868582bda80e684f14223ea4aLatest direct-to-progress start tip:
2d0bb84a447e29b940adda4bd432e3d5725c9cc0Latest single-card map completion tip:
8a620e54a121f5ac45913791b40b5239a59f5885Latest one-action failed-map recovery tip:
14081ea101744b868b80d900bb5a1c42b4ad5046Latest bounded long-stage heartbeat tip:
e2043c0f324ba8fb855b3a723cb670acd40cb2adLatest safe map-interruption tip:
8370ac511f29eaf3861569103cd5389035c7412aLatest quiet product bag-reader implementation and evidence tip:
d0e33613f4531988ac4fc3ac0687927d164690ebLatest concise guided-start implementation tip:
3dcca0c75c25565cc244207711bb45a56beee38aLatest complete guided-map implementation tip:
8e67ab7f50bb78767b4bc7674137eb4ecdf3e16bLatest explicit first-map report implementation tip:
cb2218fc24861088526bd2373bed3376218beb94Latest first-class first-map report command tip:
e15ddab85d44a9aba7105667ab7b175cd655c271Latest default-storage interruption evidence carrier:
edff76df06e7a7c86a6adbde454270664ee4d126Latest copy-ready low-storage recovery tip:
d01652080485bc68354f354043e4b2e732439223Latest single-action system-doctor recovery tip:
a83bbfeaea8196a19513c7a26772d500fe8419b8Latest exact-head Leo Drive rerun evidence carrier:
4163b8c6f0ebb63504a0de398d9654333bf3919eLatest Odometry-to-TF bag-preflight tip:
402c23765fe125a2f42d7fd245d2a1c972a1ab34Latest other-PointCloud2 self-service tip:
6950764154dfe0a2159f701d8d01cd55ce5907afLatest bounded map-quality symptom triage implementation tip:
ee453532a70d2d4b82a6c50c65f19b22d76c239fBounded map-quality symptom validation carrier:
9f8a2058a3c702f69d159079568ced8433ee3377Bounded map-quality symptom candidate-bundle SHA-256:
51c025064de769d1f0c362f51718c52a0beed8492f0881c0e02403b33498e997Latest privacy-safe symptom support-handoff implementation tip:
0d102e016717d2def3db3a99525755837461f759Latest complete local validation carrier:
72a8c9e77eba33c1578a3cd9c8afe8fbe6933e33Publication-inventory synchronization: this handoff captures public
c1fc2847fb06637cbcd2aac61f4fde318364dfd2, binds the local media generator atd0c84bb9bb7bef37d7e318000e3071a7f536d631, and adds no publication authority.
This reviewed tip is the code-bearing product-candidate revision; later docs-only handoff synchronization and product UX follow-up commits must remain identified separately.
This is the current, read-only handoff for the G0 release-hygiene decision.
It was first captured on 2026-08-14 and refreshed on 2026-08-16 after the
dashboard UX, CI-registration, version-priority, final PR-head CI,
packet-command-contract, fail-closed usability-worksheet, paired scorecard,
safe observer-packet-output, safe first-map-dry-run-plan-output, Docker JSON
own-bag-plan, source JSON quickstart-plan, custom PointCloud2 onboarding,
supported g2o recovery, canonical C2/C3 drift detection, contributor C1–C4
local-retirement, bounded contributor C5–C9 replenishment, and
publication-inventory follow-ups. The latest activation repair also turns
doctor/demo low-storage rejection into an exact shortage plus copy-ready retry
without lowering the 8 GiB safety floor. The current release observer follow-up
derives the tag commit and both ROS-distribution image digests from one
schema-valid published-release report, then generates an exact live identity
preflight instead of accepting four manually entered values. The latest
observer UX follow-up also turns
four artifact downloads, independent remote byte audit, and JSON/Markdown
packet generation into one fail-closed command with atomic local output. The
single-action doctor follow-up at a83bbfe… retains all stable findings and
their machine recovery text while selecting one dependency-ordered top-level
next_action and one human Do this now action. Its exact unconfigured-shell
observation selected source-build-required from five findings and performed
no network access or write; it creates no external first-attempt or GLIM parity
claim. The
latest onboarding-evidence trust follow-up retains the exact schema-valid,
privacy-bounded first-map validation receipt beside each candidate trial and
requires its bytes, SHA-256, PASS state, manifest identity, product version,
fixed profile, and source commit to agree before any row is comparable. Old
rows without that retained receipt remain useful PASS evidence but cannot open
the matrix gate. The exact-head CI repair at b87c193… only restores the
Jazzy-required standard-library import order in that probe's regression test;
it changes no runtime or evidence semantics.
The paired usability follow-up at 0575fb6… similarly removes hand-edited trial
JSON: it records both fixed six-task worksheets in declared order, derives
command totals, keeps blanks explicitly incomplete, validates privacy and pair
identity, and atomically publishes neither or both local records. It does not
create an external observation or a GLIM parity claim. The actionable
release-evidence follow-up at 45cfdcb… keeps the stable-release gate
fail-closed while removing its empty-root dead end: it evaluates all release
profiles, retains Markdown/CSV/log output, separates five blocking NO_DATA
rows from report-only canaries, prints each tracked remediation, and still
exits 2 without evidence from the exact candidate commit. The latest
contributor follow-up at 3543a71… adds one GET-only --next card that
combines live published starter availability, the five-task local queue, and
open-PR duplicate freshness into one contributor action and one maintainer
action. It exposes no user identity or raw body, performs no remote mutation,
and keeps all C5–C9 tasks unpublished. The dependency follow-up at
76be895… closes the remaining false-ready path: #422 is retained for audit
but no longer recommended unless the first-map cohort derives exactly
READY_FOR_NEXT_ATTEMPT. The JSON card has its own strict schema, the cohort
check command is allowlisted, unrelated starters remain eligible, and gate
failure or claimed write authority fails closed. The latest
independent-queue follow-up at e4ce0aa… also prevents that issue-specific
gate from suppressing all local community preparation: potential PR duplicates
remain first, then one duplicate-free local C5 task becomes the maintainer
preview, while contributors still wait and #422 remains blocked. No issue,
label, assignment, comment, or PR is created or authorized. The latest
publication-handoff follow-up at 0a34e72… binds the selected task title,
sorted labels, heading-free body, and canonical task/queue/body digests into
the same live report. Body or cross-task tampering fails closed, while
maintainer confirmation, separate external write, and false issue-creation
authority remain explicit. Public-base follow-up 5dc0419… additionally
requires PR #427 merged and the canonical queue SHA matched on public
develop before publication review. Current authenticated GET-only state is
WAITING_FOR_PRODUCT_MERGE with the public queue ABSENT, so the action is
post-merge preparation and no issue or pull-request mutation is performed or
authorized. The latest
public-docs follow-up at 5b8c8c4… also validates the complete generated
deployment manifest against its Draft 7 schema before exclusive artifact
creation. The Pages workflow installs the validator explicitly and reruns when
the shared validator changes, so schema/output drift cannot be uploaded and
discovered only after deployment. This does not deploy Pages.
The issue-driven self-service follow-up at 6950764… replaces the old
"which launch/YAML file should I edit?" handoff with the existing read-only
doctor then guided start path. It keeps detected topics, frames, fields,
timestamps, maintained-profile selection, and calibration review visible,
while explicitly refusing to turn PointCloud2 detection into a vendor-support
or accuracy claim. The update changes no profile, transform, parameter,
mapping algorithm, or GitHub issue state.
The map-quality symptom follow-up at ee45353… addresses the next recurring
support burden without adding another doctor or tuning surface. A user can add
one of five observed symptoms to the retained-run inspect command and receive
ordered sensor/time/calibration/TF/runtime/save/viewer checks plus shell-safe
product commands. Its evidence basis remains explicitly user-reported: it does
not edit parameters, start mapping, upload a bundle, diagnose a root cause,
claim sensor support, or claim accuracy. The original run remains preserved.
The privacy-bounded handoff follow-up at 0d102e0… closes the remaining
clarification gap between that retained card and support. The generated JSON
and issue body carry only one fixed symptom code plus the explicit
user-reported evidence basis. They exclude symptom titles, checks, commands,
free text, and all existing private artifacts; malformed or automatically
attributed claims fail closed as invalid diagnosis evidence. This preserves
context for a maintainer without converting a visual report into a root cause.
The latest distribution slices also scope
optional GitHub authentication to read-only API requests, make explicit or
unknown NDT PR mergeability fail closed, restore exact-tip source-route
preflight under shared-IP quota exhaustion, and bind package-manager workflow
evidence to the exact immutable source tag commit. The package audit now keeps
missing refs, absent attempts, running attempts, failed attempts, and API or
identity failures separate. It does not print a dispatch command while the
required tag is absent.
The NDT review audit now also binds all check runs to each rosdistro PR's exact
head, blocks failed, pending, absent, inconsistent, or truncated check
evidence, and keeps unanswered-review actions visible beside a CI blocker.
The separate canonical-upstream publication preflight binds one clean local
candidate commit to the checked-in binary patch, verifies its exact parent and
subject, reads the current upstream branch and expected fork identity, and
fails closed if the proposed branch already exists, GitHub inspection fails,
or any open upstream PR matches the branch or semantic duplicate terms. Its
30 / 30 PASS result is technical evidence only: GitHub write authority remains
false and no upstream branch or PR was created.
The fail-closed response gate at 3e11f30… now keeps both prepared rosdistro
replies null until an open canonical koide3/ndt_omp Draft PR resolves to
exact local upstream candidate 618f02f6… and both recorded rosdistro heads
plus unanswered review URLs remain unchanged. The live packet is therefore
BLOCKED only on the absent canonical Draft URL; it neither posts nor
authorizes either reply.
The Docker workflow now separates verification from publication at the job
and token boundary. Pull requests and manual dispatches have contents-read
permission, build with push: false, load only into the disposable runner,
and cannot log in, attest, publish a package, or move a tag. Only the separate
job gated to a develop push can update the moving convenience tags. This
closes an accidental-publication path. The separate immutable-candidate gate
is now implemented at c70c18d…: it has no workflow_dispatch, runs its
write-capable path only from a default-branch repository_dispatch, validates
the exact same-repository PR head, VERSION, nine successful checks,
maintain/admin role, literal E2 approval, and a required-reviewer environment
restricted to develop, then publishes Humble/Jazzy by digest without tags.
Its request, per-image, and pair records preserve exact identity and state that
registry retention still requires a remote audit. The workflow is not yet on
develop, the live candidate-images environment is absent, no dispatch was
sent, and no candidate digest was published. The capture-time public baseline
also contains the CTest registration and cross-distro import-order repair for
the gate regression; both default workflows pass at that exact revision.
The tag-free candidate-observer follow-up at 363a971… now requires one
canonical four-file evidence directory, re-derives both image records from the
authorized request and the set from those records, and hashes every retained
file. Remote mode re-downloads the exact four workflow artifacts into a
temporary directory, byte-compares them, removes the copies, and then checks
both manifests and attestations. Observer packet v3 and each candidate trial
record retain both bundle and set SHA-256 values plus source/run/image
identity, without inventing a release tag. This is local contract readiness
only: no candidate evidence bundle exists yet, no remote audit was run, and no
trial was executed.
The one-command preparation at f5ed80e… accepts only one exact repository
Actions run URL and one new output directory. It downloads all four canonical
artifacts, invokes the remote audit (which independently downloads all four
again), requires REMOTE_AUDIT_PASS, builds packet v3, and publishes the
artifacts, audit, JSON/Markdown packet, and schema-backed preparation receipt as
one directory. Any acquisition, identity, byte, registry, or attestation
failure removes staging and leaves the requested output absent. The contract
records network reads and local writes, but trial_executed, GitHub/registry
write authority, and remote mutations remain false.
The one-command row runner at feed0ba… consumes that complete handoff with one
row ID and one new output directory. It rebuilds the packet from artifact
bytes, runs only the selected row's live preflight, derives probe arguments
from structured identity, prompts for human observations only on a TTY, and
atomically distinguishes blocked preflight, valid PASS/FAIL evidence, and a
harness error. It neither creates candidate evidence nor expands E2/E3/E4
authority.
The one-command session at 8bc5ea4… removes the remaining transfer/copy step
when a disposable row host can read the exact Actions run directly. It prepares
the authenticated handoff, runs one selected structured row, verifies the
retained child receipt bytes, and atomically publishes handoff/, execution/,
and a schema-backed session.json. Docker rows derive a local observer tag from
the exact Dockerfile SHA-256, build it only when absent and before timing, then
require contract, Ubuntu, and recipe labels plus its immutable local image ID.
It does not replace an existing tag or expand remote-write authority.
The guided readiness follow-up at a286c65… keeps that single command surface
and adds a read-only --check-readiness mode. It validates the exact request,
Ubuntu/ROS row, x86_64 host, measured filesystem and free-space floor, local
Docker or source runtime, source RX counter, neutral-observer measurement mode,
and explicit isolation confirmation before any network read, image build,
source mutation, evidence write, or trial. Its schema distinguishes BLOCKED,
CONFIRMATION_REQUIRED, runnable-but-READY_NONCOMPARABLE, and READY, then
prints one shell-safe next command. It neither proves human isolation nor turns
local host readiness into comparable evidence.
The protected-environment preflight at adecca6… first reads the complete
repository environment inventory, then reads the exact environment and
deployment-policy documents only when candidate-images is present. It shares
its reviewer, Prevent self-review, known-rule, and exact develop policy
validator with the publication authorization job. The authenticated live
inventory contains only github-pages, so the stable result is ABSENT, not
an inference from a 404. Its schema and the G0 dashboard keep environment
writes, artifact publication, remote mutation, and E2 dispatch authority
false even when the result eventually becomes READY_FOR_SEPARATE_E2_REVIEW.
The status-specific operator handoff at e2d916a… now prints the trusted settings URL and
exact creation/repair checklist only when complete evidence justifies it;
BLOCKED requests read-access recovery instead. It always preserves a
copy-ready GET-only verification command and writes_performed: false, so the
administrator still performs and independently reviews any settings change
outside this packet.
The G0 product-Draft audit now closes the dependency-order gap before that
handoff. Its bounded GitHub GETs require PR #427's canonical repository,
develop base, public head branch, full local/public commit, mergeable state,
and latest exact-head check runs to agree. A green Draft is reported as
DRAFT_REVIEW_REQUIRED, not as merge readiness. On a clean exact checkout it
emits one schema-bound overview → P0/P1/P2 → S1–S7 handoff with exact head and
396-path / three-phase / seven-slice coverage. A dirty checkout instead selects
only git status --short; uncommitted bytes cannot be mislabeled as the public
review. This sequence precedes repository settings; only a later observed
MERGED state lets the dashboard advance to candidate-images. Every result
retains merge_authorized: false, performs no remote mutation, and keeps
mark-ready, merge, settings, E2, E3, and E4 actions separate.
The branch-drift path now couples that exact non-force handoff to a second
schema-bound, no-write PR-description refresh. The canonical body is generated
only from one clean exact tip and current machine counts, includes the whole-PR
and P2 review budgets, and carries both observed and desired SHA-256 values.
The separately authorized description edit must follow the branch update and
GET-only head verification, must keep the PR Draft, and cannot submit a review,
mark ready, merge, or grant any other write. Once heads match, a stale body
still blocks the review handoff until its digest matches.
That canonical body now includes exact P0–P2 GitHub compare links and a compact
S1–S7 focus/path/check/publication-gate table. The dashboard derives both from the
validated overview and rejects disconnected phase lineage, wrong commit or
path composition, unsafe Markdown-bearing titles, or any source claim of
command execution/GitHub authority. The final P2 link intentionally resolves
publicly only after the branch update that the same handoff orders first.
The same exact packet groups S1–S7 into four role-based capability lanes:
runtime safety, operator UX, distribution, and integration/publication. Its
two-reviewer target is advisory rather than a merge gate. No username, email,
or organization is collected, and reviewer request, review submission,
mark-ready, merge, and remote-mutation authority remain false.
An optional local review ledger now binds append-only R1–R4 PASS/BLOCKED events
to the same exact clean tip and routing-contract digest. The ledger remains
outside the source tree, stores no identity or timestamp, requires every
finding path to belong to its declared slice, rejects identity/URL/private-path
detail, retains superseded blockers as history, and prevents an earlier-lane
rereview from silently staling downstream results. COMPLETE_LOCAL_REVIEW
still performs no check and grants no GitHub review, ready, or merge authority.
Unified transition follow-up 4404f87… removes the remaining mixed-version
partial-audit loop. One --include-public-transition option reads the exact
Draft, complete protected-environment inventory, and v0.9.1 publication state
together. Its schema-bound handoff distinguishes AUDIT_REQUIRED,
PUBLICATION_REQUIRED, AUDIT_BLOCKED, and
READY_FOR_FRESH_MATRIX_PACKET; only the last selects a fresh observer packet,
and old 0.9.0/0.9.1 measurements are never reusable. The authenticated live
result finds local tip 4404f87… a verified fast-forward from public Draft
head 4b2ab514…, candidate-images absent, and the v0.9.1 tag, Release, and
both GHCR tags absent. Dependency order therefore selects exact non-force
Draft-update review first. All network operations are GET-only and every write
authority remains false.
The code-bearing packet tip is required to be an ancestor of the current
checkout revision; later synchronization and product UX follow-up commits
must remain described in this handoff. It replaces
neither the historical 2026-08-11 decision packet nor any maintainer approval.
Its purpose is to prevent an old commit, old version, or one external action
gate from being mistaken for the current state.
Current evidence
| Check | Current result | Meaning |
|---|---|---|
| Draft PR #427 | open, draft, and mergeable; capture-time public baseline 3ed632e… remains the frozen review anchor; the 2026-08-17 GET-only refresh observes exact public head 4b2ab514…, 300 commits, 374 changed files, and zero submitted reviews, conversation comments, or inline review threads |
no merge, Pages deployment, cohort launch, or E2 authority is implied; the GET-only audit grants no review submission, mark-ready, or merge authority |
| Exact public PR-head CI | capture-time public baseline remains PASS for 3ed632e…: 10 successful checks plus 4 intentionally skipped non-publication jobs, 0 failures; exact public 4b2ab514… is also PASS with 10 successful / 4 intentional skips / 0 failures / 0 pending |
Humble/Jazzy default workflows, Docker verification builds, upgrade checks, docs/metadata, candidate contract, and release-readiness guards all passed; publication jobs stayed skipped by design |
| G0 product-Draft and public-transition audit | exact Draft implementation e08ec9c… plus unified transition 4404f87…, current description, role-routing UX, and anonymous-ledger follow-up; 25 focused regressions cover local/public identity, bounded latest-check selection, fail-closed drift/CI/authority cases, divergent or unavailable history, verified fast-forward handoff, canonical body hashing, stale-body review blocking, exact compare lineage, safe review-map labels, tamper-resistant capability lanes, optional anonymous exact-head ledger summaries, retained-path exclusion, one-option three-audit expansion, release-state-to-handoff mapping, unsafe/mismatched version refusal, fresh-packet eligibility, and refusal to inherit review authority; authenticated GET rehearsal observes public head 4b2ab514…, local 4404f87…, candidate-images absent, and v0.9.1 not published |
head drift no longer loops back to the same audit: dependency order selects exact non-force Draft-update review before environment and release; only observed PUBLISHED may select a new same-version packet and mixed rows remain non-reusable; no push/edit command, review, mark-ready, merge, environment, release, or other write is authorized |
| Role-based Draft review routing | four capability lanes cover all seven slices, 349 paths, and 34 verification groups exactly once; six focused routing regressions and the G0 schema reject lane drift, duplicate scope, unsafe labels, stale counts, personal-identity fields, authority claims, and bundle omission | two reviewers is an advisory capacity target, not a merge gate; the packet stores no username/email/organization and cannot request a reviewer, submit a review, mark ready, merge, or mutate GitHub |
| Anonymous Draft review ledger | nine focused ledger regressions cover empty, blocked, recovered, complete, dependency-stale, out-of-scope, identity-bearing, noncanonical, atomic-output, authority, and bundle boundaries; G0 optionally summarizes the exact ledger digest and current lane/blocker counts without retaining its path | append-only events preserve history outside the repository; the tool records a human claim but executes no review command, proves no reviewer identity or independence, and grants no GitHub review/ready/merge authority |
| G0 publication-slice verification | all seven review cards plus one compact PR overview pass exact three-phase lineage, commit composition, 396-path union, schema, authority, and Git-numstat inventory checks; 34 checker regressions cover exact slice-budget composition, top-three textual hotspots, named binary review paths, malformed/stale numstat rejection, bounded human/JSON output, mutually exclusive modes, missing/extra phase paths, ordinary-shell ROS recovery, clean-checkout build-before-test enforcement, separate package pytest processes, cache suppression, and recognized direct remote-write CLI refusal; the exact S6 product-shell command passes 42 / 42 and its separate support/installed-contract command passes 25 / 25 from an ordinary shell, while the copy-ready S1 command builds from a clean checkout and reports 3,076 cases / 0 errors / 0 failures / 126 skips | the overview makes the large Draft scannable without dumping 349 follow-up paths into its summary and tells a reviewer where the largest textual and binary deltas are; line volume is an effort hint, not proof of correctness or review completion, and the local review still grants no push, review submission, mark-ready, merge, environment, release, posting, or community authority |
| S1 rejected-map-update recovery | exact implementation 99cce93…; one pure commit-state regression and the real asynchronous component prove that an unsafe update crossing a positive 0.02 m threshold leaves the threshold available to the same-geometry safe retry; the component case passes 10 / 10 independent Jazzy processes, and exact public 7b3cb99… runs the recovery target successfully on Humble and Jazzy within 4,241-case and 4,355-case default workflows |
map position and cumulative submap distance advance only after success; worker setup, future, and map-update exceptions remain inside the component boundary; issue #69 remains open for an accurate response and named release, not for missing exact-head public CI |
| English support cards | docs entrypoint tests 25 passed | C1 g2o recovery is implemented; existing C2 empty-map and C3 Odometry/TF cards remain copy-ready and safety-bounded; Docker convenience and candidate-digest authority boundaries are both regression-bound; every tracked shell entry point now also has a parse regression |
| Goal-based README chooser | exact implementation 8a8876a…; the first Quickstart decision is now three rows—stable Docker demo, read-only own-bag diagnosis before start, or candidate source dry-run—with Docker the explicit default when unsure; README remains 219 lines, 29 focused entrypoint regressions and the 36-test S6 docs/product command pass, and strict MkDocs builds |
this reduces GitHub landing-page choice cost without adding a fourth workflow, changing stable/candidate claims, collecting telemetry, publishing a release, or making a GLIM parity claim |
| Canonical three-goal onboarding chooser | exact implementation 1e56431…; Getting Started now exposes the same three first goals and boundaries as README, keeps seven installed/continuation actions in a correctly rendered collapsed section, and changes the Docs Home v0.9.0 label from release candidate to stable release; 30 focused entrypoint and 37 S6 docs/product regressions plus strict rendered-site inspection pass |
this removes a 12-option first decision without deleting advanced workflows or changing any runtime, public identity, release, telemetry, recruitment, or GitHub state |
| Honest first-map FAIL intake | exact implementation da99c7e…; the parsed issue form retains PASS/FAIL results, makes the receipt field optional only so a FAIL with no generated receipt can be submitted, and requires one privacy attestation that either reviews the sole attachment or confirms FAIL/no-receipt/no-file; PASS still requires a reviewed receipt, all three privacy checks remain required, 31 focused and 38 S6 docs/product regressions plus strict MkDocs pass |
failed onboarding can now enter the public repair loop without a false receipt claim; no PASS, acceptance, cohort attempt, recruitment, issue creation, upload, or GitHub write is fabricated or authorized |
| Pre-session bug intake | exact implementation 4b1707c…; Bug report keeps preflight, diagnostics, and all four checklist items required, but now accepts either one reviewed support ZIP from an existing session or an explicit no-session/no-ZIP report with doctor output and the first actionable finding; SUPPORT and the issue-selector card state the same boundary, and 32 focused plus 39 S6 docs/product regressions and strict MkDocs pass |
startup and preflight failures can enter support without a fake attachment-review claim; the no-session path does not weaken ZIP review when a session exists and performs no upload, issue creation, or GitHub write |
| Location-safe Autoware issue intake | exact implementation 51496ca…; the form keeps environment, redacted command shape, verifier result, GNSS state, projector summary, behavior, and all three privacy attestations required; precise latitude/longitude/altitude/MGRS/grid/origin values become REDACTED, while map bundles, pointcloud/lanelet geometry, bags, raw private logs, and private-place screenshots are prohibited; SUPPORT and canonical map-authoring docs agree, and 33 focused plus 40 S6 docs/product regressions and strict MkDocs pass |
useful type/status diagnostics remain reportable without soliciting a private site or map; no attachment, issue, acceptance, or GitHub write is performed |
| Redaction-first first-map reporting | exact implementation a0aaadc…; the issue form now asks for a redacted command shape, requires literal REDACTED placeholders for credentials/private paths/host or user names/precise locations, preserves executable/options/non-private values, and prohibits map geometry; support --first-map renders four field-by-field completion lines using only safe environment hints; 34 focused docs and 25 support/installed-contract regressions pass |
this reduces public-report ambiguity without changing first-map-handoff-v1, weakening PASS evidence, uploading a receipt, creating an issue, accepting a cohort report, or performing a GitHub write |
| Redaction-first benchmark reporting | exact implementation 940195b…; the issue form requires a public dataset identity/license or redacted custom-input summary, redacted command shape, tracked/public configuration summary, key metrics, and three privacy attestations; only one reviewed metrics.json or public aggregate report is optional, while bags, maps, trajectories, raw logs/data, local paths, complete custom YAML, and private-site evidence are prohibited; CONTRIBUTING, SUPPORT, Benchmarking, and Autoware guidance agree; 42 docs/product regressions and strict MkDocs pass |
comparable public metrics remain available without soliciting private run contents; no upload, issue, benchmark execution, acceptance, or GitHub write is performed |
| Path-free public bug evidence | exact implementation 6a1dd87…; doctor <bag> --public-json emits schema-valid type/count/check/profile/finding-code evidence without bag paths, topic/frame names, local commands, raw data/logs, or free-text messages, and unreadable input returns the same path-free bag-preflight-input-error schema; Bug report, SUPPORT, CONTRIBUTING, CLI docs/contract, and selector card agree; 31 preflight regressions pass with 2 dependency skips, plus 12 doctor, 21 option-contract, 42 docs/product, 25 support/installed, 331 broad S6 regressions, and strict MkDocs |
pre-session failures remain actionable without asking users to publish the private local automation report; no upload, issue, network access, or GitHub write is performed |
| Privacy-first doctor support discovery | exact implementation 71cbf7e…; every ready or action-required human bag report keeps the full report local and displays one shell-safe exact-input --public-json command through both the source script and top-level product wrapper; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, and strict MkDocs |
safe public evidence is discoverable at the failure point without exposing the private report; no upload, issue, network access, or GitHub write is performed |
| One-action bag-doctor handoff | exact implementation 387a002…; a ready product-dispatched report preserves the selected profile and reasons but replaces lower-level scripts and compatible-path alternatives with one shell-safe exact-input start; a finding-bearing report withholds start and returns to the exact-input doctor after the first finding; direct preflight and JSON contracts remain detailed and unchanged; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, changed-code ament_flake8, and strict MkDocs |
own-bag diagnosis now ends in one safe product action without hiding expert evidence or starting an unsafe run; no mapping, upload, network access, issue, or GitHub write is performed |
| Compact product bag-doctor card | exact implementation fc87cf8…; the ready card is regression-bounded to at most 26 lines and shows status, duration/count, input types without topic/frame names, selected profile, check statuses, and one start; a finding card shows only the first message/action plus remaining stable codes and exact retry; one exact private --json command retains full detail, while direct preflight remains the complete expert report; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, changed-code ament_flake8, and strict MkDocs |
first-time users can scan the default diagnosis without losing machine or expert evidence; no mapping, upload, network access, issue, or GitHub write is performed |
| Single-prompt interactive start | exact implementation 90c508e…; interactive RKO start shows calibration once and leads into its fail-closed confirmation without presenting a second --yes command; non-interactive start, setup, and dry-run preserve the exact reviewed rerun command; 35 sensor-setup, 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs |
own-bag onboarding loses one misleading copy-paste detour while decline, EOF, and unreviewed calibration remain non-starting; no real mapping, upload, network access, issue, or GitHub write is performed |
| Direct-to-progress confirmed start | exact implementation 2d0bb84…; a confirmed live start skips the repeated READY setup card and enters its start/progress card directly, while setup-only, dry-run, and unconfirmed non-RKO review preserve complete sensor/calibration/command detail; 36 sensor-setup regressions, exact S3 lifecycle 71 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs |
topics, transforms, delegated command, and setup path are no longer rendered twice on the confirmed path; durable session/progress/recovery contracts remain unchanged, and no real mapping, upload, network access, issue, or GitHub write is performed |
| Single-card map completion | original card 8a620e5…, concise complete-map follow-up 8e67ab7…; an exact-installed guided start completed the 50-second MID360 fixture in 23.45 seconds with succeeded / complete / 0 / 0, 7 / 7 receipt PASS, one VERIFIED / Next / Share card, a 4,015,933-byte map.pcd, 92 tiles, and 124 manifest-bound checksums; successful terminal output fell 51 lines / 3,791 bytes → 23 lines / 1,399 bytes (63.10%), while all 16 hidden post-process lines remain in the checksum-bound map_workflow.log; the baseline and corrected runs produced byte-identical map, Lanelet2, raw trajectory, and corrected trajectory outputs; runner 54, sensor 42, dogfood 15, exact S3 77 + 15, S2 43 + 43, docs/product 42, support/installed 25, option 21, and broad S6 332 regressions pass |
a real successful guided run now ends in one product-owned status and one next action without deleting expert output or evidence; the controlled mixed overlay means clean-host/package-manager, public-fixture, external-user, paired GLIM, parity/superiority, upload, network, issue, and GitHub-write claims remain unavailable |
| Explicit first-map report preparation | exact implementation cb2218f…; the verified completion/session UI says Report: / Prepare a first-map report, while the compatibility-keyed structured action remains share; a fresh exact install reproduced the 50-second MID360 result in 23.42 seconds with byte-identical map/Lanelet2/raw/corrected outputs, then the displayed command produced a 22-line / 1,279-byte review handoff with issue URL, copy fields, receipt path, and privacy boundary; four installed schemas and 124 manifest checksums pass, the complete session path/size/mtime snapshot is unchanged across human and JSON reads, no archive is created, and strace observes no network syscall; focused support 17, sensor 42, history 11, S3 77 + 15, support/installed 25, docs/product 42, option 21, broad S6 332, publication plan 34, G0 25, strict MkDocs, and changed-code style pass |
users are told they are preparing—not automatically sharing or uploading—a reviewed report; this is local controlled-overlay evidence and does not create an issue, upload a receipt, establish an external first map, or grant GitHub write authority |
| First-class first-map report command | exact implementation e15ddab…; verified completion/history now emits lidarslam-map report SESSION, while support SESSION --first-map remains byte-identical compatibility; report --help exposes only help and read-only JSON, with no ZIP output option; a fresh exact install passes the complete installed-product validator, then emits a 22-line / 1,327-byte report and schema-valid JSON identical to the legacy spelling; the fixture path/type/size/mtime tree is unchanged and strace observes no network syscall; focused 175, S3 78 + 15, docs/product 42, support/installed 26, broad S6 333, cohort 33, plan 34, G0 25, strict MkDocs, and changed-code style pass |
a validator has one short, purpose-named command without weakening receipt revalidation, privacy, legacy automation, or no-write/no-network behavior; no map run, archive, browser, upload, issue, acceptance, or GitHub write is performed |
| One-action failed-map recovery | exact implementation 14081ea…; the default ACTION REQUIRED card is bounded to the first reason, remaining stable codes, exactly one safe Next, and one detail path; every finding/action, retry, inspect alternative, and evidence path remains in recovery JSON/session evidence; 38 sensor-setup regressions, exact S3 lifecycle 73 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs |
failed mapping no longer presents competing repair commands while safe resume/fresh-output rules remain unchanged; no real mapping, upload, network access, issue, or GitHub write is performed |
| Bounded long-stage heartbeat | exact implementation e2043c0…; an unchanged non-complete mapping stage prints at most one heartbeat every 30 seconds with its existing label and monotonic elapsed time; stage changes remain the only trigger for session.json/session.html writes, and the terminal claims no percentage, ETA, or delegated forward progress; 39 sensor-setup regressions, exact S3 lifecycle 74 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8, bytecode/JSON/patch hygiene, plan validation, and strict MkDocs |
long stages no longer look silent while durable evidence semantics and artifact-write boundaries remain unchanged; this is a mocked monitor-boundary regression, not a real long mapping run, clean-host timing result, paired GLIM observation, or parity/superiority claim; no upload, network access, issue, or GitHub write is performed |
| Safe operator interruption | original implementation 6d1249e…, process correction 0301a0d…, timeout-label correction 181b251…, evidence-bound summary 8370ac5…, quiet native-reader follow-up d0e3361…, concise completion follow-up 8e67ab7…; guided workflow stdout is durably captured and only exact ready status is relayed, while warning/error stderr remains live and a normal failure replays a bounded 80-line stdout tail; the exact-installed real-node Ctrl-C trial passed the unchanged 5 GiB gate, returned 130 in 1.317 seconds, reaped both observed nodes and every descendant, sealed five schemas and 19 checksums, and retained one ACTION REQUIRED / Next / Details with no traceback, false timeout, or hidden failure diagnosis |
success and expected stops stay concise without weakening process-group cleanup, ordinary failure, warning, direct expert logging, or genuine timeout diagnosis; controlled-overlay and external/publication limits remain unchanged |
| Odometry-to-TF bag preflight | exact implementation 402c237…; preflight v5 scans one deterministic Odometry topic and every TFMessage topic with a 100,000-record per-topic bound, accepts a dynamic multi-hop path, and emits separate invalid-frame, missing-path, static-only, and reader-unavailable actions without hiding an otherwise compatible mapping profile; focused 68, graph 1,483 / 13 skipped, lidarslam 1,040, strict MkDocs, changed-file Jazzy ament_flake8, and the 319-path plan pass |
read-only evidence came from #112 and the distinct timing burden in #64; the bag check does not prove live freshness/interpolation, add a broadcaster, change an issue, or grant publication authority |
| Odometry TF timing preflight | exact implementation 4bdd7ec…; preflight v6 retains v5 connectivity, exposes selected path edges, and makes a second 100,000-record-per-topic replay-order pass that reports startup gaps and every positive PointCloud2-to-limiting-dynamic-TF future gap; the fixed #64 regression measures 20.346 s → 20.364 s as exactly 18,000,000 ns; focused 74, graph 1,489 / 13 skipped, lidarslam 1,040, strict MkDocs/style, the 321-path plan, and a reproducible 271-file candidate bundle pass |
#64 was inspected read-only; the diagnostic does not alter scan matching, silence warnings, increase a timeout, use stale TF, prove live scheduling/DDS/clock/buffer/interpolation, change the issue, or grant publication authority |
| Custom PointCloud2 onboarding | implemented in the reviewed product UX tip | bounded topic/frame/time/TF/range/launch readiness guidance; it does not claim hardware support or accuracy |
| Other-PointCloud2 self-service | exact implementation 6950764…; the TTY home, system doctor, README, canonical map-authoring page, Japanese quickstart, and candidate release notes all route another LiDAR bag through doctor then start without tracked launch/YAML edits; focused docs/home/doctor tests pass 45, S6 groups pass 34 + 199 + 47, and the complete gate passes 2,469 / 13 skipped |
read-only evidence came from open issues #95, #98, #103, #106, #111, and #115; no issue was changed, no vendor preset was added, and detection remains distinct from hardware support or accuracy |
| Retained-run visual symptom triage | exact implementation ee45353…, Bash-completion follow-up and validation carrier 9f8a205…; inspect --symptom accepts five bounded user reports, emits ordered review checks and only shell-safe doctor/inspect/view/support commands, and preserves the run; 50 focused graph regressions, 21 CLI-contract regressions, 2 completion regressions, S6 groups 35 + 200 + 5, strict MkDocs, and the complete 2,474 / 13-skipped gate pass |
read-only evidence came from recurring open issues #89, #92, #93, #94, #96, #100, #101, #104, #105, and #124; no issue was changed, and a reported symptom remains neither an automatic root-cause nor a sensor-support or accuracy claim |
| Privacy-safe symptom support handoff | exact implementation 0d102e0…; support-report.json and issue-body.md retain only the five-code enum and user-reported basis, while title/check/command/free-text content remains local; unknown, mismatched, and automatic-cause claims fail closed; 56 focused regressions, strict MkDocs, changed-file Jazzy ament_flake8, and the complete 2,478 / 13-skipped gate pass |
this reduces repeated clarification on the same recurring visual-symptom issue set without uploading evidence, changing an issue, diagnosing a cause, or claiming a repair |
| Contributor starter queue | exact independent-review e4ce0aa…, publication-handoff 0a34e72…, and public-base gate 5dc0419…; C5–C9 remain READY_LOCAL_ONLY; 71 queue regressions, focused C5/C6 strict-MkDocs profiles, the exact 331-test S6 integration command, and 65 plan/routing/G0 regressions pass; current authenticated GET-only output finds 1 published good first issue (#422), 0 eligible starters, 1 blocked starter, 1 open PR, 0 potential task matches, PR #427 open/Draft/unmerged, the public develop queue absent, and one digest-bound C5 post-merge preparation handoff |
the contributor still waits instead of entering the closed cohort; WAITING_FOR_PRODUCT_MERGE cannot become publication review until PR #427 is merged and the canonical queue SHA matches public develop; title, sorted labels, heading-free body, and task/queue/body digests remain locally reviewable, but issue creation is a separately confirmed external write; no issue, label, assignment, comment, PR, Pages deployment, or community post was changed |
| Issue-triage application packet | local follow-up converts the still-valid 29-row proposal into ordered, source- and evidence-hashed review actions: 23 closure drafts, 4 reproduction requests, 9 dependency reviews, and 1 monitor-only row (#422); the #69 draft explains both leaf parameters and their resolution tradeoff, retains the historical-bag limit, and now requires exact public Draft head 4b2ab514, open/Draft/mergeable state, 10 successful checks, 4 intentional skips, zero pending/failing checks, latest stable v0.9.0 at 0df0c4a exactly 52 commits behind reviewed fix a2368c4, and no v0.9.1 tag/release; 34 application and 19 proposal regressions, the 1,075-test lidarslam gate, 35 graph docs/CLI regressions, strict MkDocs, and a complete authenticated GET-only live drift audit pass |
stdout-only review aid; linked #69 head/state/CI, stable ancestry, candidate publication, or GET-only-authority drift emits no packet; every GitHub write authority remains false, no issue body, comment body, check name, raw release payload, or author identity is retained, and no issue, label, comment, release, tag, or state was changed |
| Fixed-demo low-storage recovery | exact implementation d016520…; real local rejection reports exact additional_bytes_required, rounds 1.76 GiB upward for the human card, keeps system JSON path-free, and preserves the full shell-quoted demo retry; default floor remains 8 GiB |
this removes one locally reproduced activation burden; it is not a public clean-host completion, paired GLIM observation, or authority to lower the storage gate |
| Single-action system doctor | exact implementation a83bbfe…; a real unconfigured source shell retains five stable findings but exposes one schema-bound source-build-required top-level action and one human Do this now recovery; 51 focused, 35 graph docs/product, 321 integrated S6, and 21 G0 tests pass with strict MkDocs and ROS lint |
rerunning doctor reprioritizes remaining blockers; the observed run is read-only and creates no clean-host timing, external first map, paired GLIM scorecard, or parity claim |
| Distribution preflights | source route READY at exact public 3ed632e…; rosdistro NDT remains BLOCKED: Humble #52949 and Jazzy #52950 each have 5 / 6 exact-head checks passing, one stale-base rosdep failure, and an unanswered review; Humble RKO-LIO 0.3.2 is in main/testing, Jazzy 0.3.2 is in testing while main remains 0.2.0; package-manager E2E is SOURCE_REF_MISSING because v0.9.1 does not resolve |
canonical collision-free NDT convergence and a current-base green replacement precede package sync and clean-install E2E; do not merge the overlapping registrations or treat Jazzy main as ready |
| v1 authenticated live audit | current local increment returns valid NOT_READY, 8 / 10, with exact NDT / package-manager / stable-release tuple BLOCKED / SOURCE_REF_MISSING / PUBLISHED; all six schema-valid package-manager states are preserved in the parent JSON and 18 focused regressions pass |
a missing v0.9.1 source ref is an actionable distribution blocker, not malformed child evidence or permission to create the tag; unauthenticated shared-rate-limit exhaustion may still make network child audits fail closed |
| Canonical NDT upstream Draft preflight | refreshed 2026-08-17 as READY_FOR_DRAFT_PR, 30 / 30 PASS; exact upstream 5495fd9…, exact candidate 618f02f6…, expected fork verified, proposed branch absent, 4 open PRs inspected, 0 duplicates, 0 API errors, and write authority false; the schema-bound handoff fixes the create-only branch, base/head identities, exact Draft copy, and four-step verification route while every remote authority and write result remains false; the 3e11f30… response packet is BLOCKED solely because that Draft URL is absent and emits no reply body |
the local candidate and replies are technically bound but unpublished; non-ready states emit no handoff, and this ready handoff neither creates nor authorizes an upstream branch, PR, or rosdistro comment |
| Docker publication boundary | convenience PR/manual runs remain verification-only; the candidate gate at c70c18d… uses trusted default-branch tooling, exact-head CI/identity checks, a protected candidate-images environment, digest-only output, disabled container networking during smoke tests, SBOM/provenance/attestation checks, and 30-day schema-backed evidence |
the gate can create no tag or Release; complete authenticated inventory at adecca6… proves only github-pages exists, so authorization must stop until a separate environment/E2 decision |
| Candidate environment and gate regressions | 29 focused tests, actionlint v1.7.12, Python style, CTest 2 / 2, GET-only transport, shared authorization semantics, release-bundle inclusion, and exact-tip Humble/Jazzy default workflows pass | the live result is ABSENT; workflow-facing CLIs persist one request, two distinct image records, and one pair report exactly once; no workflow dispatch, environment mutation, or GHCR mutation occurred |
| Candidate observer contract | atomic preparation through f5ed80e…, exact row runner feed0ba…, one-command session 8bc5ea4…, guided local readiness a286c65…, and receipt-bound comparability at 3c19824…; four-file semantic derivation, exact remote artifact-byte comparison, content-bound Docker observer bootstrap, retained child/session receipts, exact first-map validation-receipt bytes, structured row execution, four-state host guidance, release-bundle inclusion, and strict docs pass with 189 focused candidate/onboarding regressions |
remote status is still NOT_CHECKED because no authorized bundle exists; local readiness and runner tests are not REMOTE_AUDIT_PASS, a trial, E2, or E4 authority |
| Neutral GLIM usability workflow | recorder implementation 0575fb6…, evidence sync and public CI through ac22a3f…, plus the current local GET-only pair-identity and receipt-chain follow-up; the paired preparer rejects manual public Booleans, binds both canonical GitHub/tag or registry identities and approved docs redirects, SHA-binds both worksheets, persists a schema-valid receipt, and rolls back all three outputs on failure; the recorder requires the shared receipt and retains the untouched triplet under preparation/; the final checker and evidence index reject receipt-less, archive-tampered, or identity-drifted records; 16 preparer, 10 recorder, 17 checker, graph 1,489 / 13 skipped, and lidar_slam 1,094 tests pass, while a real GET preflight resolves Draft 4b2ab514… and GLIM v1.2.2 → faa264a1… with both docs at HTTP 200 |
the checked-in scorecard remains NOT_READY with 0 / 2 product records and 0 / 6 comparable tasks; a content-bound preparation chain and safer recording are not an external observation, parity result, or winner claim |
| Claim-bounded short demo media | generator implementation d0c84bb…; one contract now binds version, canonical commands, slide copy, and three source-image hashes; the generated 10.666-second H.264 candidate carries four-cue English WebVTT, exact-revision Japanese/English copy, and a schema-valid byte manifest; 11 focused and 25 docs/release entrypoint tests pass |
the former release inventory's v0.2.2 post, retired commands, and unbound numerical copy are removed from the active path; the replacement remains PUBLICATION_CANDIDATE / NOT_PUBLISHED, grants no posting or release authority, and is not user evidence |
| Public documentation deployment provenance | pre-upload schema enforcement and 9 focused regressions PASS at 5b8c8c4…; strict MkDocs emits a schema-valid source/version/route/page-byte manifest, both Pages jobs and the live environment branch policy are develop-only, and the clean candidate release bundle contains the generator, auditor, schemas, and evidence; live exact-public audit is BLOCKED because the manifest URL returns HTTP 404 |
URL shape alone cannot launch the independent cohort; the current Pages deployment remains unverified until a separately reviewed develop deployment publishes matching bytes |
| Complete maintained product gate | Odometry-TF timing carrier 4bdd7ec…: source-explicit graph 1,489 passed / 13 skipped / 11 existing ImageIO warnings; source-explicit lidarslam 1,040 passed; 2,529 total; 74 focused checks, strict MkDocs, and changed-file Jazzy ament_flake8 pass; the canonical two-build bundle rehearsal passes with 271 manifest files, 11,965,449 archive bytes, and SHA-256 735a3683be43cfb2e2638e466b02b140339beb9da573bc5642872219090fc6a9 |
this is local commit-bound evidence, not a published release asset; the later evidence-sync/public candidate must rerun and may not reuse this checksum |
| Actionable stable-release profile gate | clean public Draft carrier 4163b8c… reruns Leo Drive at 0.139152 m aligned Applanix cross-validation APE RMSE, 571 matched poses, and TARGET_MET; its schema-valid metrics.json has SHA-256 76d6465729a7c48a46919d2b1029996393be6d0e615a893fee28440637963627, the map passes 8 checks with one informational warning, and the hard gate now exits 2 with four blocking NO_DATA rows—Newer College Maths, NTU VIRAL, and both RTK-SLAM Construction sequences |
exact carrier evidence; this evidence synchronization creates a later docs-only commit, so that later exact candidate must rerun rather than relabel the carrier; no tag, Release, image, or E4 authority is granted |
| NTU VIRAL acquisition recovery | exact implementation 8a856f5…, registration 657746f…, and byte-reporting follow-up d6e8bad…; a fresh plan requires 49,209,878,965 bytes, observed 6,326,681,600 bytes free, reported a 42,883,197,365-byte shortfall, and identified the attached unmounted 2,000,397,795,328-byte /dev/sda1; one mount action plus --dest-device replaces manual discovery/path substitution, preserves requested phases, and rechecks actual free space |
exact evidence; no automatic mount, authorization bypass, archive download, extraction, conversion, benchmark, or release-profile claim occurred; the curated bundle now contains the documented NTU command and resolver |
| RTK-SLAM acquisition recovery | exact attached-storage implementation 0c3f588…; all four official DB3/metadata identities and one detached eval commit remain pinned, regular partial files are resumable, and text/JSON plans are write- and network-free; the real smallest-profile request required 11,886,726,027 bytes, observed 6,339,293,184 bytes free, reported a 5,547,432,843-byte root-FS shortfall, then identified the attached unmounted 2,000,397,795,328-byte /dev/sda1 ext4 partition and selected udisksctl mount -b /dev/sda1 as its single next action; --dest-device removes mount-path substitution and rechecks actual free space after mounting |
exact evidence; no automatic mount, authorization bypass, large download, or release-profile claim occurred; Construction Seq2 remains one mount, dry-run, verified acquisition, and measured suite away |
| Publication slice and whole-PR review plan | PLAN_VALID_LOCAL_ONLY; 349 follow-up paths / 7 slices from frozen baseline 3ed632e…, composed with the original 116-path audit and exact two-commit / 11-path CI bridge into 396 whole-PR paths / 3 sequential phases; 0 uncovered, 0 extraneous, and 0 merge commits |
the machine gate binds both follow-up inventory and whole-PR union rather than silently skipping 6a8727a..3f4dd70; every displayed verification group remains self-contained for an ordinary terminal; exact coverage adds no mount, GitHub, release, posting, or community authority |
| Published onboarding identity | v0.9.0 exact release commit plus Humble/Jazzy digests return READY, but its source route is NOT_READY with source-route-contract-missing; v0.9.1 report-to-packet fails closed at NOT_PUBLISHED |
the old release cannot be reused for same-version Docker/source evidence, and the new version cannot produce a release packet before E4 publication |
| v0.9.1 release audit | NOT_PUBLISHED | no v0.9.1 tag or GitHub Release was found |
| v0.9.1 GHCR images | ABSENT for v0.9.1-humble and v0.9.1-jazzy |
no immutable candidate image identity exists |
| Onboarding matrix | 4 / 4 product PASS; 0 / 4 comparable; BLOCKED | Docker is v0.9.0, source is v0.9.1, human measurements are missing, and all four historical rows lack retained first-map validation-receipt bytes; a hash string alone no longer counts as comparable evidence |
| v1 readiness | 8 / 10 | distribution and independent adoption remain incomplete |
| Accepted independent maps | 0 / 3 | cohort remains closed |
The exact public checks are intentionally re-runnable:
gh pr checks 427 --repo rsasaki0109/lidar_slam_ros2
python3 scripts/check_publication_slice_plan.py --json
python3 scripts/check_product_draft_review_routing.py --json
bash scripts/run_release_readiness_checks.sh \
--skip-default-ci --fail-on-profiles
python3 scripts/check_ndt_omp_release_readiness.py --json
GITHUB_TOKEN="$(gh auth token)" \
python3 scripts/check_canonical_ndt_convergence.py \
--upstream-checkout "${NDT_UPSTREAM_CHECKOUT:?}" \
--candidate-checkout "${NDT_CANDIDATE_CHECKOUT:?}" \
--online --require-ready-for-draft-pr --json
python3 scripts/check_package_manager_release_readiness.py \
--version 0.9.1 --json
python3 scripts/run_source_onboarding_probe.py \
--public-preflight \
--source-commit 3ed632e6f6aa1e3ca7f32d893773de1079086ffb \
--product-version 0.9.1
python3 scripts/check_public_docs_deployment.py \
--expected-revision 3ed632e6f6aa1e3ca7f32d893773de1079086ffb \
--expected-product-version 0.9.1 \
--route source-quickstart \
--json
GITHUB_TOKEN="$(gh auth token)" \
python3 scripts/check_candidate_environment.py --json --require-ready
python3 scripts/check_published_release.py --version 0.9.1 --json
python3 scripts/check_published_release.py \
--version 0.9.1 --json --require-published \
| python3 scripts/prepare_onboarding_matrix_packet.py \
--published-release-report - --render
python3 scripts/check_onboarding_trial_matrix.py --json
python3 scripts/check_v1_readiness.py --json
python3 scripts/first_map_validator_cohort.py --json
python3 scripts/check_g0_readiness.py \
--include-public-transition \
--published-release-version 0.9.1
These commands perform read-only inspection. The last command must remain
WAITING_FOR_PUBLIC_GATES while the matrix is not comparable; --render must
not be used as a reason to recruit.
Separated action gates
| Gate | Current state | Authorized scope |
|---|---|---|
| L0 local preparation | complete for this packet | code, tests, docs, offline audits, and read-only inspection |
| E1 source review | product Draft #427 is public and exact-head CI PASS; canonical NDT Draft remains local READY_FOR_DRAFT_PR with an exact create-only/no-write handoff |
publishing the third-party upstream branch/PR and later replies requires a separate exact-revision decision; no force-push, mark-ready, or merge is implied |
| E2 artifact hosting | GATE_IMPLEMENTED_LOCAL / ENVIRONMENT_ABSENT / NOT_AUTHORIZED / NOT_PUBLISHED | after the workflow is reviewed on develop, separately configure and review the protected environment; only a later exact E2 event may request digest-only candidate evidence |
| E3 community mutation | NOT_AUTHORIZED | no issue labels, comments, closures, starter issues, Discussions, or recruitment |
| E4 stable release | HOLD / NOT_AUTHORIZED | no tag, GitHub Release, package, image promotion, or announcement |
Approval of one row never approves another. In particular, green CI does not authorize E2, E3, or E4, and a published identity would not by itself create a comparable human trial.
Safe transition order
- Run the GET-only product-Draft audit, verify the composed initial / CI-bridge / follow-up review coverage, then choose one of the four capability lanes and review the exact matching head by its assigned publication slices. Stop on branch, commit, mergeability, CI, phase lineage, or inventory drift. Mark-ready and merge remain separate maintainer decisions; do not measure mixed-version rows.
- Only after the dashboard observes the exact PR as merged, review the
dedicated candidate workflow at
c70c18d…and shared environment preflight atadecca6…. Do not merge it or configurecandidate-imagesas an implication of E1; the environment and its required reviewer/develop-only policy are a separate repository-admin decision. Never use the convenience-image manual dispatch as a substitute. - If E2 is separately chosen after the gate is on
developand the protected environment passes the read-only audit, send one exacte2-publish-candidate-imageevent. Publish only the two untagged candidate digests. On each prepared disposable row host, preferstart_candidate_trial.py --workflow-run-url ... --row ... --output-dir ... --acknowledge-dedicated-trial-host --check-readinessand requireREADYbefore running the exact command it prints. Require the session's retainedREADY_FOR_OBSERVERhandoff,REMOTE_AUDIT_PASS, and terminalsession.json; a comparable PASS also requires the exact boundedfirst-map-validation-receipt.json. A missing output on pre-contract failure is intentional. - If E4 is separately chosen later, follow
RELEASING.md; before tagging, require the exact candidate commit's four remaining blocking release profiles to passrun_release_readiness_checks.sh --fail-on-profiles. After publication, requirecheck_published_release.py --require-publishedand record both image digests before using them in a trial. - If the handoff must be reviewed or transferred separately, use
prepare_candidate_trial.pyfollowed byrun_candidate_trial.py. Both the combined and split routes revalidate structured identity, bootstrap the content-bound Docker observer when selected, and preserve blocked, FAIL, and harness outcomes without inventing human measurements. Keep the generated packet, trial record, first-map validation receipt, audit, exactartifacts/bytes, and execution receipt together. For a separately published release, use its exact public source commit and both published image digests. Do not mix the modes or reuse the current v0.9.0/v0.9.1 matrix. - Run fresh dedicated Humble/Jazzy Docker and source trials with a human observer. Record active operator time, command count, workflow download, peak disk, wall time, and output size, and retain the exact privacy-bounded validation receipt beside the trial record; blank measurements or a missing receipt remain non-comparable.
- For the separate GLIM comparison, prepare the exact public pair with
prepare_usability_scorecard_pair.py --verify-public, then record it withrecord_usability_scorecard_pair.py --require-ready. Publish task-level evidence only; do not infer one overall winner. - Only after at least one comparable Docker PASS and one comparable source PASS may the E3 cohort decision be reconsidered. Three accepted independent reports are still required for the v1 gate.
Current decision
E2 artifact host: DEFER — no host or upload authorized
E2 candidate images: DEFER — gate at c70c18d, atomic preparation at f5ed80e, row execution at feed0ba, one-command session at 8bc5ea4, guided readiness at a286c65, and GET-only environment preflight at adecca6; workflow not on develop, candidate-images ABSENT from the complete inventory, no dispatch, digest publication, remote audit, or trial
E3 community mutation: DEFER — cohort and issue operations remain closed
E4 v0.9.1 release/images: DEFER — G0 matrix and distribution gates remain open; four exact-head blocking benchmark profiles currently have NO_DATA
This packet is evidence and handoff text only. It performs no release, image, fixture, issue, branch, review, or community mutation.