Skip to content

G0 current action packet — refreshed 2026-08-16

Status: CURRENT_PUBLIC_DRAFT_HANDOFF / NO_E2_E3_E4_ACTION_TAKEN

Repository: rsasaki0109/lidar_slam_ros2

Draft PR: #427

Capture-time public Draft baseline: 3ed632e6f6aa1e3ca7f32d893773de1079086ffb

Capture-time exact public Draft head and CI audit: c1fc2847fb06637cbcd2aac61f4fde318364dfd2

Latest exact public Draft head before this local increment: 4163b8c6f0ebb63504a0de398d9654333bf3919e

Exact reviewed product-candidate tip: 3d64ed556aca8a680f09e0f7e8c12a3c8d3e6a6d

Latest product/community follow-up tip: 0d102e016717d2def3db3a99525755837461f759

Latest G0 product-Draft dependency audit tip: e08ec9cd28a59acb550556238e7ba6acb3b63cc6

Latest copy-ready G0 slice verification tip: 297115d14ea0a979ee0043e24d55a2a80746e382

Latest S1 rejected-map-update threshold recovery tip: 99cce93a07a7cc136eb925c446dd705bdcd7b37c

Latest S6 ordinary-shell review recovery tip: 0633c2a604489538e0f087c02385e7c6467540c3

Latest S6 review evidence carrier: 72a8c9e77eba33c1578a3cd9c8afe8fbe6933e33

Latest distribution-audit follow-up tip: ca7c5b5b991e5624ca16e46ffd1a057e3a9f6ee9

Latest canonical-NDT publication-preflight tip: 856e59987018578963a7afdf13402200eab62bf8

Latest fail-closed NDT reviewer-response gate tip: 3e11f307eb2ccea1d33bbe9a2d1b37ae7ed699db

Latest claim-bounded social-media generator tip: d0c84bb9bb7bef37d7e318000e3071a7f536d631

Latest Docker publication-authority tip: 3225d9db357caa1150081ac61281ae4b0d281a2a

Latest immutable-candidate gate tip: c70c18d32e0dd860969dbd050fa3a92632f1106e

Latest candidate-gate CI follow-up tip: 87f8f8d1bcdccb80235b8ae1832f9bc716c31d36

Latest tag-free candidate-observer tip: 363a971bfeb2a5ddf0b99fb9b20f5a201134a520

Latest one-command candidate-trial preparation tip: f5ed80e11e3735b7a72ba458f740d0117711be6c

Latest one-command candidate-row execution tip: feed0ba7a12135099b9eef299e914605ab2947e1

Latest one-command candidate-session tip: 8bc5ea4036277de1a1819008183f989a2c4bcb76

Latest guided candidate-readiness tip: a286c6551f976c48d508ee7e9ecd7d9d4a30e734

Latest protected-environment preflight tip: adecca6e19c38e6a682253d66516379bbface46d

Latest operator-handoff and GLIM parse-safety tip: e2d916a66a57146b0efe4c74e57218d56342ed37

Latest content-verified GLIM comparison tip: 3de7f84bb51acd2bd1c2b40724529be9c281d2fe

Latest public-docs deployment-provenance tip: 5b8c8c477cceb4955184a64afa874712b9dea5aa

Latest public-docs evidence-refresh baseline: ac22a3ff1e49c1dae3fcde47f52ae8bf8ccdb1eb

Latest receipt-bound onboarding-evidence tip: 3c19824daeb5c61715fe52887e5e0e6abe6c0051

Latest exact-head CI import-order repair tip: b87c1936c1799834288d6d2c39aa616ab15c348d

Latest public publication-inventory tip: ac22a3ff1e49c1dae3fcde47f52ae8bf8ccdb1eb

Latest published-onboarding-identity tip: 289f7675a242b00f342528483cde3e5f602a11fc

Latest paired usability recorder tip: 0575fb6d67dc0b2069d9e41029a767bf3608687c

Latest actionable release-evidence UX tip: 45cfdcb1c10756d1c33068fcd9594f612bf6ccca

Latest live contributor next-action tip: 3543a71bde958278388aa8481330166d125944b9

Latest dependency-gated contributor next-action tip: 76be89576ae544d77e661bc5d098b5087b497c5c

Latest independent starter-review tip: e4ce0aa6eb7d53423423a02af65f923472708f44

Latest exact starter-publication-handoff tip: 0a34e724875d53b8ef74acd8a51fd500ce014ff5

Latest public-base-gated starter-publication tip: 5dc04198549341b33becdeb2bc058117db9fe78f

Latest unified public-product-transition tip: 4404f877263157d09ae6c451dae55f5ddbbd03af

Latest goal-based README chooser tip: 8a8876a2d26c09cc92ad330b99d1fa217db1bd8d

Latest canonical three-goal onboarding chooser tip: 1e56431161d3dea417d5d800bb1eedc3cdb51907

Latest honest FAIL-without-receipt intake tip: da99c7ef82136449727ef97a58c1a2db4ffd6955

Latest pre-session bug-intake tip: 4b1707cdbc2dc41f3d7b52aa8c598841fc925767

Latest location-safe Autoware-intake tip: 51496ca576b668d9e7dc0e7fda39ebdc21b7e1c8

Latest redaction-first first-map reporting tip: a0aaadc80b952d92074f45499c29a5103a2ad479

Latest redaction-first benchmark reporting tip: 940195b75ea6aff648171b120539a9ab01a0248e

Latest path-free public doctor evidence tip: 6a1dd87e85b966492ebefea84e87a46917885669

Latest privacy-first doctor support handoff tip: 71cbf7e776664d40c59157fbfbad4d5611ceae03

Latest one-action bag-doctor handoff tip: 387a002dc7826be267fe600db906f80460e6f270

Latest compact product bag-doctor card tip: fc87cf86cabba5f55fec47316c6a9a3a4e4cb90f

Latest single-prompt interactive start tip: 90c508eef4c6ce6868582bda80e684f14223ea4a

Latest direct-to-progress start tip: 2d0bb84a447e29b940adda4bd432e3d5725c9cc0

Latest single-card map completion tip: 8a620e54a121f5ac45913791b40b5239a59f5885

Latest one-action failed-map recovery tip: 14081ea101744b868b80d900bb5a1c42b4ad5046

Latest bounded long-stage heartbeat tip: e2043c0f324ba8fb855b3a723cb670acd40cb2ad

Latest safe map-interruption tip: 8370ac511f29eaf3861569103cd5389035c7412a

Latest quiet product bag-reader implementation and evidence tip: d0e33613f4531988ac4fc3ac0687927d164690eb

Latest concise guided-start implementation tip: 3dcca0c75c25565cc244207711bb45a56beee38a

Latest complete guided-map implementation tip: 8e67ab7f50bb78767b4bc7674137eb4ecdf3e16b

Latest explicit first-map report implementation tip: cb2218fc24861088526bd2373bed3376218beb94

Latest first-class first-map report command tip: e15ddab85d44a9aba7105667ab7b175cd655c271

Latest default-storage interruption evidence carrier: edff76df06e7a7c86a6adbde454270664ee4d126

Latest copy-ready low-storage recovery tip: d01652080485bc68354f354043e4b2e732439223

Latest single-action system-doctor recovery tip: a83bbfeaea8196a19513c7a26772d500fe8419b8

Latest exact-head Leo Drive rerun evidence carrier: 4163b8c6f0ebb63504a0de398d9654333bf3919e

Latest Odometry-to-TF bag-preflight tip: 402c23765fe125a2f42d7fd245d2a1c972a1ab34

Latest other-PointCloud2 self-service tip: 6950764154dfe0a2159f701d8d01cd55ce5907af

Latest bounded map-quality symptom triage implementation tip: ee453532a70d2d4b82a6c50c65f19b22d76c239f

Bounded map-quality symptom validation carrier: 9f8a2058a3c702f69d159079568ced8433ee3377

Bounded map-quality symptom candidate-bundle SHA-256: 51c025064de769d1f0c362f51718c52a0beed8492f0881c0e02403b33498e997

Latest privacy-safe symptom support-handoff implementation tip: 0d102e016717d2def3db3a99525755837461f759

Latest complete local validation carrier: 72a8c9e77eba33c1578a3cd9c8afe8fbe6933e33

Publication-inventory synchronization: this handoff captures public c1fc2847fb06637cbcd2aac61f4fde318364dfd2, binds the local media generator at d0c84bb9bb7bef37d7e318000e3071a7f536d631, and adds no publication authority.

This reviewed tip is the code-bearing product-candidate revision; later docs-only handoff synchronization and product UX follow-up commits must remain identified separately.

This is the current, read-only handoff for the G0 release-hygiene decision. It was first captured on 2026-08-14 and refreshed on 2026-08-16 after the dashboard UX, CI-registration, version-priority, final PR-head CI, packet-command-contract, fail-closed usability-worksheet, paired scorecard, safe observer-packet-output, safe first-map-dry-run-plan-output, Docker JSON own-bag-plan, source JSON quickstart-plan, custom PointCloud2 onboarding, supported g2o recovery, canonical C2/C3 drift detection, contributor C1–C4 local-retirement, bounded contributor C5–C9 replenishment, and publication-inventory follow-ups. The latest activation repair also turns doctor/demo low-storage rejection into an exact shortage plus copy-ready retry without lowering the 8 GiB safety floor. The current release observer follow-up derives the tag commit and both ROS-distribution image digests from one schema-valid published-release report, then generates an exact live identity preflight instead of accepting four manually entered values. The latest observer UX follow-up also turns four artifact downloads, independent remote byte audit, and JSON/Markdown packet generation into one fail-closed command with atomic local output. The single-action doctor follow-up at a83bbfe… retains all stable findings and their machine recovery text while selecting one dependency-ordered top-level next_action and one human Do this now action. Its exact unconfigured-shell observation selected source-build-required from five findings and performed no network access or write; it creates no external first-attempt or GLIM parity claim. The latest onboarding-evidence trust follow-up retains the exact schema-valid, privacy-bounded first-map validation receipt beside each candidate trial and requires its bytes, SHA-256, PASS state, manifest identity, product version, fixed profile, and source commit to agree before any row is comparable. Old rows without that retained receipt remain useful PASS evidence but cannot open the matrix gate. The exact-head CI repair at b87c193… only restores the Jazzy-required standard-library import order in that probe's regression test; it changes no runtime or evidence semantics. The paired usability follow-up at 0575fb6… similarly removes hand-edited trial JSON: it records both fixed six-task worksheets in declared order, derives command totals, keeps blanks explicitly incomplete, validates privacy and pair identity, and atomically publishes neither or both local records. It does not create an external observation or a GLIM parity claim. The actionable release-evidence follow-up at 45cfdcb… keeps the stable-release gate fail-closed while removing its empty-root dead end: it evaluates all release profiles, retains Markdown/CSV/log output, separates five blocking NO_DATA rows from report-only canaries, prints each tracked remediation, and still exits 2 without evidence from the exact candidate commit. The latest contributor follow-up at 3543a71… adds one GET-only --next card that combines live published starter availability, the five-task local queue, and open-PR duplicate freshness into one contributor action and one maintainer action. It exposes no user identity or raw body, performs no remote mutation, and keeps all C5–C9 tasks unpublished. The dependency follow-up at 76be895… closes the remaining false-ready path: #422 is retained for audit but no longer recommended unless the first-map cohort derives exactly READY_FOR_NEXT_ATTEMPT. The JSON card has its own strict schema, the cohort check command is allowlisted, unrelated starters remain eligible, and gate failure or claimed write authority fails closed. The latest independent-queue follow-up at e4ce0aa… also prevents that issue-specific gate from suppressing all local community preparation: potential PR duplicates remain first, then one duplicate-free local C5 task becomes the maintainer preview, while contributors still wait and #422 remains blocked. No issue, label, assignment, comment, or PR is created or authorized. The latest publication-handoff follow-up at 0a34e72… binds the selected task title, sorted labels, heading-free body, and canonical task/queue/body digests into the same live report. Body or cross-task tampering fails closed, while maintainer confirmation, separate external write, and false issue-creation authority remain explicit. Public-base follow-up 5dc0419… additionally requires PR #427 merged and the canonical queue SHA matched on public develop before publication review. Current authenticated GET-only state is WAITING_FOR_PRODUCT_MERGE with the public queue ABSENT, so the action is post-merge preparation and no issue or pull-request mutation is performed or authorized. The latest public-docs follow-up at 5b8c8c4… also validates the complete generated deployment manifest against its Draft 7 schema before exclusive artifact creation. The Pages workflow installs the validator explicitly and reruns when the shared validator changes, so schema/output drift cannot be uploaded and discovered only after deployment. This does not deploy Pages. The issue-driven self-service follow-up at 6950764… replaces the old "which launch/YAML file should I edit?" handoff with the existing read-only doctor then guided start path. It keeps detected topics, frames, fields, timestamps, maintained-profile selection, and calibration review visible, while explicitly refusing to turn PointCloud2 detection into a vendor-support or accuracy claim. The update changes no profile, transform, parameter, mapping algorithm, or GitHub issue state. The map-quality symptom follow-up at ee45353… addresses the next recurring support burden without adding another doctor or tuning surface. A user can add one of five observed symptoms to the retained-run inspect command and receive ordered sensor/time/calibration/TF/runtime/save/viewer checks plus shell-safe product commands. Its evidence basis remains explicitly user-reported: it does not edit parameters, start mapping, upload a bundle, diagnose a root cause, claim sensor support, or claim accuracy. The original run remains preserved. The privacy-bounded handoff follow-up at 0d102e0… closes the remaining clarification gap between that retained card and support. The generated JSON and issue body carry only one fixed symptom code plus the explicit user-reported evidence basis. They exclude symptom titles, checks, commands, free text, and all existing private artifacts; malformed or automatically attributed claims fail closed as invalid diagnosis evidence. This preserves context for a maintainer without converting a visual report into a root cause. The latest distribution slices also scope optional GitHub authentication to read-only API requests, make explicit or unknown NDT PR mergeability fail closed, restore exact-tip source-route preflight under shared-IP quota exhaustion, and bind package-manager workflow evidence to the exact immutable source tag commit. The package audit now keeps missing refs, absent attempts, running attempts, failed attempts, and API or identity failures separate. It does not print a dispatch command while the required tag is absent. The NDT review audit now also binds all check runs to each rosdistro PR's exact head, blocks failed, pending, absent, inconsistent, or truncated check evidence, and keeps unanswered-review actions visible beside a CI blocker. The separate canonical-upstream publication preflight binds one clean local candidate commit to the checked-in binary patch, verifies its exact parent and subject, reads the current upstream branch and expected fork identity, and fails closed if the proposed branch already exists, GitHub inspection fails, or any open upstream PR matches the branch or semantic duplicate terms. Its 30 / 30 PASS result is technical evidence only: GitHub write authority remains false and no upstream branch or PR was created. The fail-closed response gate at 3e11f30… now keeps both prepared rosdistro replies null until an open canonical koide3/ndt_omp Draft PR resolves to exact local upstream candidate 618f02f6… and both recorded rosdistro heads plus unanswered review URLs remain unchanged. The live packet is therefore BLOCKED only on the absent canonical Draft URL; it neither posts nor authorizes either reply. The Docker workflow now separates verification from publication at the job and token boundary. Pull requests and manual dispatches have contents-read permission, build with push: false, load only into the disposable runner, and cannot log in, attest, publish a package, or move a tag. Only the separate job gated to a develop push can update the moving convenience tags. This closes an accidental-publication path. The separate immutable-candidate gate is now implemented at c70c18d…: it has no workflow_dispatch, runs its write-capable path only from a default-branch repository_dispatch, validates the exact same-repository PR head, VERSION, nine successful checks, maintain/admin role, literal E2 approval, and a required-reviewer environment restricted to develop, then publishes Humble/Jazzy by digest without tags. Its request, per-image, and pair records preserve exact identity and state that registry retention still requires a remote audit. The workflow is not yet on develop, the live candidate-images environment is absent, no dispatch was sent, and no candidate digest was published. The capture-time public baseline also contains the CTest registration and cross-distro import-order repair for the gate regression; both default workflows pass at that exact revision. The tag-free candidate-observer follow-up at 363a971… now requires one canonical four-file evidence directory, re-derives both image records from the authorized request and the set from those records, and hashes every retained file. Remote mode re-downloads the exact four workflow artifacts into a temporary directory, byte-compares them, removes the copies, and then checks both manifests and attestations. Observer packet v3 and each candidate trial record retain both bundle and set SHA-256 values plus source/run/image identity, without inventing a release tag. This is local contract readiness only: no candidate evidence bundle exists yet, no remote audit was run, and no trial was executed. The one-command preparation at f5ed80e… accepts only one exact repository Actions run URL and one new output directory. It downloads all four canonical artifacts, invokes the remote audit (which independently downloads all four again), requires REMOTE_AUDIT_PASS, builds packet v3, and publishes the artifacts, audit, JSON/Markdown packet, and schema-backed preparation receipt as one directory. Any acquisition, identity, byte, registry, or attestation failure removes staging and leaves the requested output absent. The contract records network reads and local writes, but trial_executed, GitHub/registry write authority, and remote mutations remain false. The one-command row runner at feed0ba… consumes that complete handoff with one row ID and one new output directory. It rebuilds the packet from artifact bytes, runs only the selected row's live preflight, derives probe arguments from structured identity, prompts for human observations only on a TTY, and atomically distinguishes blocked preflight, valid PASS/FAIL evidence, and a harness error. It neither creates candidate evidence nor expands E2/E3/E4 authority. The one-command session at 8bc5ea4… removes the remaining transfer/copy step when a disposable row host can read the exact Actions run directly. It prepares the authenticated handoff, runs one selected structured row, verifies the retained child receipt bytes, and atomically publishes handoff/, execution/, and a schema-backed session.json. Docker rows derive a local observer tag from the exact Dockerfile SHA-256, build it only when absent and before timing, then require contract, Ubuntu, and recipe labels plus its immutable local image ID. It does not replace an existing tag or expand remote-write authority. The guided readiness follow-up at a286c65… keeps that single command surface and adds a read-only --check-readiness mode. It validates the exact request, Ubuntu/ROS row, x86_64 host, measured filesystem and free-space floor, local Docker or source runtime, source RX counter, neutral-observer measurement mode, and explicit isolation confirmation before any network read, image build, source mutation, evidence write, or trial. Its schema distinguishes BLOCKED, CONFIRMATION_REQUIRED, runnable-but-READY_NONCOMPARABLE, and READY, then prints one shell-safe next command. It neither proves human isolation nor turns local host readiness into comparable evidence. The protected-environment preflight at adecca6… first reads the complete repository environment inventory, then reads the exact environment and deployment-policy documents only when candidate-images is present. It shares its reviewer, Prevent self-review, known-rule, and exact develop policy validator with the publication authorization job. The authenticated live inventory contains only github-pages, so the stable result is ABSENT, not an inference from a 404. Its schema and the G0 dashboard keep environment writes, artifact publication, remote mutation, and E2 dispatch authority false even when the result eventually becomes READY_FOR_SEPARATE_E2_REVIEW. The status-specific operator handoff at e2d916a… now prints the trusted settings URL and exact creation/repair checklist only when complete evidence justifies it; BLOCKED requests read-access recovery instead. It always preserves a copy-ready GET-only verification command and writes_performed: false, so the administrator still performs and independently reviews any settings change outside this packet. The G0 product-Draft audit now closes the dependency-order gap before that handoff. Its bounded GitHub GETs require PR #427's canonical repository, develop base, public head branch, full local/public commit, mergeable state, and latest exact-head check runs to agree. A green Draft is reported as DRAFT_REVIEW_REQUIRED, not as merge readiness. On a clean exact checkout it emits one schema-bound overview → P0/P1/P2 → S1–S7 handoff with exact head and 396-path / three-phase / seven-slice coverage. A dirty checkout instead selects only git status --short; uncommitted bytes cannot be mislabeled as the public review. This sequence precedes repository settings; only a later observed MERGED state lets the dashboard advance to candidate-images. Every result retains merge_authorized: false, performs no remote mutation, and keeps mark-ready, merge, settings, E2, E3, and E4 actions separate. The branch-drift path now couples that exact non-force handoff to a second schema-bound, no-write PR-description refresh. The canonical body is generated only from one clean exact tip and current machine counts, includes the whole-PR and P2 review budgets, and carries both observed and desired SHA-256 values. The separately authorized description edit must follow the branch update and GET-only head verification, must keep the PR Draft, and cannot submit a review, mark ready, merge, or grant any other write. Once heads match, a stale body still blocks the review handoff until its digest matches. That canonical body now includes exact P0–P2 GitHub compare links and a compact S1–S7 focus/path/check/publication-gate table. The dashboard derives both from the validated overview and rejects disconnected phase lineage, wrong commit or path composition, unsafe Markdown-bearing titles, or any source claim of command execution/GitHub authority. The final P2 link intentionally resolves publicly only after the branch update that the same handoff orders first. The same exact packet groups S1–S7 into four role-based capability lanes: runtime safety, operator UX, distribution, and integration/publication. Its two-reviewer target is advisory rather than a merge gate. No username, email, or organization is collected, and reviewer request, review submission, mark-ready, merge, and remote-mutation authority remain false. An optional local review ledger now binds append-only R1–R4 PASS/BLOCKED events to the same exact clean tip and routing-contract digest. The ledger remains outside the source tree, stores no identity or timestamp, requires every finding path to belong to its declared slice, rejects identity/URL/private-path detail, retains superseded blockers as history, and prevents an earlier-lane rereview from silently staling downstream results. COMPLETE_LOCAL_REVIEW still performs no check and grants no GitHub review, ready, or merge authority. Unified transition follow-up 4404f87… removes the remaining mixed-version partial-audit loop. One --include-public-transition option reads the exact Draft, complete protected-environment inventory, and v0.9.1 publication state together. Its schema-bound handoff distinguishes AUDIT_REQUIRED, PUBLICATION_REQUIRED, AUDIT_BLOCKED, and READY_FOR_FRESH_MATRIX_PACKET; only the last selects a fresh observer packet, and old 0.9.0/0.9.1 measurements are never reusable. The authenticated live result finds local tip 4404f87… a verified fast-forward from public Draft head 4b2ab514…, candidate-images absent, and the v0.9.1 tag, Release, and both GHCR tags absent. Dependency order therefore selects exact non-force Draft-update review first. All network operations are GET-only and every write authority remains false. The code-bearing packet tip is required to be an ancestor of the current checkout revision; later synchronization and product UX follow-up commits must remain described in this handoff. It replaces neither the historical 2026-08-11 decision packet nor any maintainer approval. Its purpose is to prevent an old commit, old version, or one external action gate from being mistaken for the current state.

Current evidence

Check Current result Meaning
Draft PR #427 open, draft, and mergeable; capture-time public baseline 3ed632e… remains the frozen review anchor; the 2026-08-17 GET-only refresh observes exact public head 4b2ab514…, 300 commits, 374 changed files, and zero submitted reviews, conversation comments, or inline review threads no merge, Pages deployment, cohort launch, or E2 authority is implied; the GET-only audit grants no review submission, mark-ready, or merge authority
Exact public PR-head CI capture-time public baseline remains PASS for 3ed632e…: 10 successful checks plus 4 intentionally skipped non-publication jobs, 0 failures; exact public 4b2ab514… is also PASS with 10 successful / 4 intentional skips / 0 failures / 0 pending Humble/Jazzy default workflows, Docker verification builds, upgrade checks, docs/metadata, candidate contract, and release-readiness guards all passed; publication jobs stayed skipped by design
G0 product-Draft and public-transition audit exact Draft implementation e08ec9c… plus unified transition 4404f87…, current description, role-routing UX, and anonymous-ledger follow-up; 25 focused regressions cover local/public identity, bounded latest-check selection, fail-closed drift/CI/authority cases, divergent or unavailable history, verified fast-forward handoff, canonical body hashing, stale-body review blocking, exact compare lineage, safe review-map labels, tamper-resistant capability lanes, optional anonymous exact-head ledger summaries, retained-path exclusion, one-option three-audit expansion, release-state-to-handoff mapping, unsafe/mismatched version refusal, fresh-packet eligibility, and refusal to inherit review authority; authenticated GET rehearsal observes public head 4b2ab514…, local 4404f87…, candidate-images absent, and v0.9.1 not published head drift no longer loops back to the same audit: dependency order selects exact non-force Draft-update review before environment and release; only observed PUBLISHED may select a new same-version packet and mixed rows remain non-reusable; no push/edit command, review, mark-ready, merge, environment, release, or other write is authorized
Role-based Draft review routing four capability lanes cover all seven slices, 349 paths, and 34 verification groups exactly once; six focused routing regressions and the G0 schema reject lane drift, duplicate scope, unsafe labels, stale counts, personal-identity fields, authority claims, and bundle omission two reviewers is an advisory capacity target, not a merge gate; the packet stores no username/email/organization and cannot request a reviewer, submit a review, mark ready, merge, or mutate GitHub
Anonymous Draft review ledger nine focused ledger regressions cover empty, blocked, recovered, complete, dependency-stale, out-of-scope, identity-bearing, noncanonical, atomic-output, authority, and bundle boundaries; G0 optionally summarizes the exact ledger digest and current lane/blocker counts without retaining its path append-only events preserve history outside the repository; the tool records a human claim but executes no review command, proves no reviewer identity or independence, and grants no GitHub review/ready/merge authority
G0 publication-slice verification all seven review cards plus one compact PR overview pass exact three-phase lineage, commit composition, 396-path union, schema, authority, and Git-numstat inventory checks; 34 checker regressions cover exact slice-budget composition, top-three textual hotspots, named binary review paths, malformed/stale numstat rejection, bounded human/JSON output, mutually exclusive modes, missing/extra phase paths, ordinary-shell ROS recovery, clean-checkout build-before-test enforcement, separate package pytest processes, cache suppression, and recognized direct remote-write CLI refusal; the exact S6 product-shell command passes 42 / 42 and its separate support/installed-contract command passes 25 / 25 from an ordinary shell, while the copy-ready S1 command builds from a clean checkout and reports 3,076 cases / 0 errors / 0 failures / 126 skips the overview makes the large Draft scannable without dumping 349 follow-up paths into its summary and tells a reviewer where the largest textual and binary deltas are; line volume is an effort hint, not proof of correctness or review completion, and the local review still grants no push, review submission, mark-ready, merge, environment, release, posting, or community authority
S1 rejected-map-update recovery exact implementation 99cce93…; one pure commit-state regression and the real asynchronous component prove that an unsafe update crossing a positive 0.02 m threshold leaves the threshold available to the same-geometry safe retry; the component case passes 10 / 10 independent Jazzy processes, and exact public 7b3cb99… runs the recovery target successfully on Humble and Jazzy within 4,241-case and 4,355-case default workflows map position and cumulative submap distance advance only after success; worker setup, future, and map-update exceptions remain inside the component boundary; issue #69 remains open for an accurate response and named release, not for missing exact-head public CI
English support cards docs entrypoint tests 25 passed C1 g2o recovery is implemented; existing C2 empty-map and C3 Odometry/TF cards remain copy-ready and safety-bounded; Docker convenience and candidate-digest authority boundaries are both regression-bound; every tracked shell entry point now also has a parse regression
Goal-based README chooser exact implementation 8a8876a…; the first Quickstart decision is now three rows—stable Docker demo, read-only own-bag diagnosis before start, or candidate source dry-run—with Docker the explicit default when unsure; README remains 219 lines, 29 focused entrypoint regressions and the 36-test S6 docs/product command pass, and strict MkDocs builds this reduces GitHub landing-page choice cost without adding a fourth workflow, changing stable/candidate claims, collecting telemetry, publishing a release, or making a GLIM parity claim
Canonical three-goal onboarding chooser exact implementation 1e56431…; Getting Started now exposes the same three first goals and boundaries as README, keeps seven installed/continuation actions in a correctly rendered collapsed section, and changes the Docs Home v0.9.0 label from release candidate to stable release; 30 focused entrypoint and 37 S6 docs/product regressions plus strict rendered-site inspection pass this removes a 12-option first decision without deleting advanced workflows or changing any runtime, public identity, release, telemetry, recruitment, or GitHub state
Honest first-map FAIL intake exact implementation da99c7e…; the parsed issue form retains PASS/FAIL results, makes the receipt field optional only so a FAIL with no generated receipt can be submitted, and requires one privacy attestation that either reviews the sole attachment or confirms FAIL/no-receipt/no-file; PASS still requires a reviewed receipt, all three privacy checks remain required, 31 focused and 38 S6 docs/product regressions plus strict MkDocs pass failed onboarding can now enter the public repair loop without a false receipt claim; no PASS, acceptance, cohort attempt, recruitment, issue creation, upload, or GitHub write is fabricated or authorized
Pre-session bug intake exact implementation 4b1707c…; Bug report keeps preflight, diagnostics, and all four checklist items required, but now accepts either one reviewed support ZIP from an existing session or an explicit no-session/no-ZIP report with doctor output and the first actionable finding; SUPPORT and the issue-selector card state the same boundary, and 32 focused plus 39 S6 docs/product regressions and strict MkDocs pass startup and preflight failures can enter support without a fake attachment-review claim; the no-session path does not weaken ZIP review when a session exists and performs no upload, issue creation, or GitHub write
Location-safe Autoware issue intake exact implementation 51496ca…; the form keeps environment, redacted command shape, verifier result, GNSS state, projector summary, behavior, and all three privacy attestations required; precise latitude/longitude/altitude/MGRS/grid/origin values become REDACTED, while map bundles, pointcloud/lanelet geometry, bags, raw private logs, and private-place screenshots are prohibited; SUPPORT and canonical map-authoring docs agree, and 33 focused plus 40 S6 docs/product regressions and strict MkDocs pass useful type/status diagnostics remain reportable without soliciting a private site or map; no attachment, issue, acceptance, or GitHub write is performed
Redaction-first first-map reporting exact implementation a0aaadc…; the issue form now asks for a redacted command shape, requires literal REDACTED placeholders for credentials/private paths/host or user names/precise locations, preserves executable/options/non-private values, and prohibits map geometry; support --first-map renders four field-by-field completion lines using only safe environment hints; 34 focused docs and 25 support/installed-contract regressions pass this reduces public-report ambiguity without changing first-map-handoff-v1, weakening PASS evidence, uploading a receipt, creating an issue, accepting a cohort report, or performing a GitHub write
Redaction-first benchmark reporting exact implementation 940195b…; the issue form requires a public dataset identity/license or redacted custom-input summary, redacted command shape, tracked/public configuration summary, key metrics, and three privacy attestations; only one reviewed metrics.json or public aggregate report is optional, while bags, maps, trajectories, raw logs/data, local paths, complete custom YAML, and private-site evidence are prohibited; CONTRIBUTING, SUPPORT, Benchmarking, and Autoware guidance agree; 42 docs/product regressions and strict MkDocs pass comparable public metrics remain available without soliciting private run contents; no upload, issue, benchmark execution, acceptance, or GitHub write is performed
Path-free public bug evidence exact implementation 6a1dd87…; doctor <bag> --public-json emits schema-valid type/count/check/profile/finding-code evidence without bag paths, topic/frame names, local commands, raw data/logs, or free-text messages, and unreadable input returns the same path-free bag-preflight-input-error schema; Bug report, SUPPORT, CONTRIBUTING, CLI docs/contract, and selector card agree; 31 preflight regressions pass with 2 dependency skips, plus 12 doctor, 21 option-contract, 42 docs/product, 25 support/installed, 331 broad S6 regressions, and strict MkDocs pre-session failures remain actionable without asking users to publish the private local automation report; no upload, issue, network access, or GitHub write is performed
Privacy-first doctor support discovery exact implementation 71cbf7e…; every ready or action-required human bag report keeps the full report local and displays one shell-safe exact-input --public-json command through both the source script and top-level product wrapper; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, and strict MkDocs safe public evidence is discoverable at the failure point without exposing the private report; no upload, issue, network access, or GitHub write is performed
One-action bag-doctor handoff exact implementation 387a002…; a ready product-dispatched report preserves the selected profile and reasons but replaces lower-level scripts and compatible-path alternatives with one shell-safe exact-input start; a finding-bearing report withholds start and returns to the exact-input doctor after the first finding; direct preflight and JSON contracts remain detailed and unchanged; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, changed-code ament_flake8, and strict MkDocs own-bag diagnosis now ends in one safe product action without hiding expert evidence or starting an unsafe run; no mapping, upload, network access, issue, or GitHub write is performed
Compact product bag-doctor card exact implementation fc87cf8…; the ready card is regression-bounded to at most 26 lines and shows status, duration/count, input types without topic/frame names, selected profile, check statuses, and one start; a finding card shows only the first message/action plus remaining stable codes and exact retry; one exact private --json command retains full detail, while direct preflight remains the complete expert report; 32 preflight regressions pass with 2 dependency skips, plus 42 docs/product, 25 support/installed, 21 option-contract, 331 broad S6 regressions, changed-code ament_flake8, and strict MkDocs first-time users can scan the default diagnosis without losing machine or expert evidence; no mapping, upload, network access, issue, or GitHub write is performed
Single-prompt interactive start exact implementation 90c508e…; interactive RKO start shows calibration once and leads into its fail-closed confirmation without presenting a second --yes command; non-interactive start, setup, and dry-run preserve the exact reviewed rerun command; 35 sensor-setup, 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs own-bag onboarding loses one misleading copy-paste detour while decline, EOF, and unreviewed calibration remain non-starting; no real mapping, upload, network access, issue, or GitHub write is performed
Direct-to-progress confirmed start exact implementation 2d0bb84…; a confirmed live start skips the repeated READY setup card and enters its start/progress card directly, while setup-only, dry-run, and unconfirmed non-RKO review preserve complete sensor/calibration/command detail; 36 sensor-setup regressions, exact S3 lifecycle 71 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs topics, transforms, delegated command, and setup path are no longer rendered twice on the confirmed path; durable session/progress/recovery contracts remain unchanged, and no real mapping, upload, network access, issue, or GitHub write is performed
Single-card map completion original card 8a620e5…, concise complete-map follow-up 8e67ab7…; an exact-installed guided start completed the 50-second MID360 fixture in 23.45 seconds with succeeded / complete / 0 / 0, 7 / 7 receipt PASS, one VERIFIED / Next / Share card, a 4,015,933-byte map.pcd, 92 tiles, and 124 manifest-bound checksums; successful terminal output fell 51 lines / 3,791 bytes → 23 lines / 1,399 bytes (63.10%), while all 16 hidden post-process lines remain in the checksum-bound map_workflow.log; the baseline and corrected runs produced byte-identical map, Lanelet2, raw trajectory, and corrected trajectory outputs; runner 54, sensor 42, dogfood 15, exact S3 77 + 15, S2 43 + 43, docs/product 42, support/installed 25, option 21, and broad S6 332 regressions pass a real successful guided run now ends in one product-owned status and one next action without deleting expert output or evidence; the controlled mixed overlay means clean-host/package-manager, public-fixture, external-user, paired GLIM, parity/superiority, upload, network, issue, and GitHub-write claims remain unavailable
Explicit first-map report preparation exact implementation cb2218f…; the verified completion/session UI says Report: / Prepare a first-map report, while the compatibility-keyed structured action remains share; a fresh exact install reproduced the 50-second MID360 result in 23.42 seconds with byte-identical map/Lanelet2/raw/corrected outputs, then the displayed command produced a 22-line / 1,279-byte review handoff with issue URL, copy fields, receipt path, and privacy boundary; four installed schemas and 124 manifest checksums pass, the complete session path/size/mtime snapshot is unchanged across human and JSON reads, no archive is created, and strace observes no network syscall; focused support 17, sensor 42, history 11, S3 77 + 15, support/installed 25, docs/product 42, option 21, broad S6 332, publication plan 34, G0 25, strict MkDocs, and changed-code style pass users are told they are preparing—not automatically sharing or uploading—a reviewed report; this is local controlled-overlay evidence and does not create an issue, upload a receipt, establish an external first map, or grant GitHub write authority
First-class first-map report command exact implementation e15ddab…; verified completion/history now emits lidarslam-map report SESSION, while support SESSION --first-map remains byte-identical compatibility; report --help exposes only help and read-only JSON, with no ZIP output option; a fresh exact install passes the complete installed-product validator, then emits a 22-line / 1,327-byte report and schema-valid JSON identical to the legacy spelling; the fixture path/type/size/mtime tree is unchanged and strace observes no network syscall; focused 175, S3 78 + 15, docs/product 42, support/installed 26, broad S6 333, cohort 33, plan 34, G0 25, strict MkDocs, and changed-code style pass a validator has one short, purpose-named command without weakening receipt revalidation, privacy, legacy automation, or no-write/no-network behavior; no map run, archive, browser, upload, issue, acceptance, or GitHub write is performed
One-action failed-map recovery exact implementation 14081ea…; the default ACTION REQUIRED card is bounded to the first reason, remaining stable codes, exactly one safe Next, and one detail path; every finding/action, retry, inspect alternative, and evidence path remains in recovery JSON/session evidence; 38 sensor-setup regressions, exact S3 lifecycle 73 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8 and strict MkDocs failed mapping no longer presents competing repair commands while safe resume/fresh-output rules remain unchanged; no real mapping, upload, network access, issue, or GitHub write is performed
Bounded long-stage heartbeat exact implementation e2043c0…; an unchanged non-complete mapping stage prints at most one heartbeat every 30 seconds with its existing label and monotonic elapsed time; stage changes remain the only trigger for session.json/session.html writes, and the terminal claims no percentage, ETA, or delegated forward progress; 39 sensor-setup regressions, exact S3 lifecycle 74 and edit/merge 15, plus 42 docs/product, 25 support/installed, 21 option-contract, and 331 broad S6 regressions pass with changed-code ament_flake8, bytecode/JSON/patch hygiene, plan validation, and strict MkDocs long stages no longer look silent while durable evidence semantics and artifact-write boundaries remain unchanged; this is a mocked monitor-boundary regression, not a real long mapping run, clean-host timing result, paired GLIM observation, or parity/superiority claim; no upload, network access, issue, or GitHub write is performed
Safe operator interruption original implementation 6d1249e…, process correction 0301a0d…, timeout-label correction 181b251…, evidence-bound summary 8370ac5…, quiet native-reader follow-up d0e3361…, concise completion follow-up 8e67ab7…; guided workflow stdout is durably captured and only exact ready status is relayed, while warning/error stderr remains live and a normal failure replays a bounded 80-line stdout tail; the exact-installed real-node Ctrl-C trial passed the unchanged 5 GiB gate, returned 130 in 1.317 seconds, reaped both observed nodes and every descendant, sealed five schemas and 19 checksums, and retained one ACTION REQUIRED / Next / Details with no traceback, false timeout, or hidden failure diagnosis success and expected stops stay concise without weakening process-group cleanup, ordinary failure, warning, direct expert logging, or genuine timeout diagnosis; controlled-overlay and external/publication limits remain unchanged
Odometry-to-TF bag preflight exact implementation 402c237…; preflight v5 scans one deterministic Odometry topic and every TFMessage topic with a 100,000-record per-topic bound, accepts a dynamic multi-hop path, and emits separate invalid-frame, missing-path, static-only, and reader-unavailable actions without hiding an otherwise compatible mapping profile; focused 68, graph 1,483 / 13 skipped, lidarslam 1,040, strict MkDocs, changed-file Jazzy ament_flake8, and the 319-path plan pass read-only evidence came from #112 and the distinct timing burden in #64; the bag check does not prove live freshness/interpolation, add a broadcaster, change an issue, or grant publication authority
Odometry TF timing preflight exact implementation 4bdd7ec…; preflight v6 retains v5 connectivity, exposes selected path edges, and makes a second 100,000-record-per-topic replay-order pass that reports startup gaps and every positive PointCloud2-to-limiting-dynamic-TF future gap; the fixed #64 regression measures 20.346 s → 20.364 s as exactly 18,000,000 ns; focused 74, graph 1,489 / 13 skipped, lidarslam 1,040, strict MkDocs/style, the 321-path plan, and a reproducible 271-file candidate bundle pass #64 was inspected read-only; the diagnostic does not alter scan matching, silence warnings, increase a timeout, use stale TF, prove live scheduling/DDS/clock/buffer/interpolation, change the issue, or grant publication authority
Custom PointCloud2 onboarding implemented in the reviewed product UX tip bounded topic/frame/time/TF/range/launch readiness guidance; it does not claim hardware support or accuracy
Other-PointCloud2 self-service exact implementation 6950764…; the TTY home, system doctor, README, canonical map-authoring page, Japanese quickstart, and candidate release notes all route another LiDAR bag through doctor then start without tracked launch/YAML edits; focused docs/home/doctor tests pass 45, S6 groups pass 34 + 199 + 47, and the complete gate passes 2,469 / 13 skipped read-only evidence came from open issues #95, #98, #103, #106, #111, and #115; no issue was changed, no vendor preset was added, and detection remains distinct from hardware support or accuracy
Retained-run visual symptom triage exact implementation ee45353…, Bash-completion follow-up and validation carrier 9f8a205…; inspect --symptom accepts five bounded user reports, emits ordered review checks and only shell-safe doctor/inspect/view/support commands, and preserves the run; 50 focused graph regressions, 21 CLI-contract regressions, 2 completion regressions, S6 groups 35 + 200 + 5, strict MkDocs, and the complete 2,474 / 13-skipped gate pass read-only evidence came from recurring open issues #89, #92, #93, #94, #96, #100, #101, #104, #105, and #124; no issue was changed, and a reported symptom remains neither an automatic root-cause nor a sensor-support or accuracy claim
Privacy-safe symptom support handoff exact implementation 0d102e0…; support-report.json and issue-body.md retain only the five-code enum and user-reported basis, while title/check/command/free-text content remains local; unknown, mismatched, and automatic-cause claims fail closed; 56 focused regressions, strict MkDocs, changed-file Jazzy ament_flake8, and the complete 2,478 / 13-skipped gate pass this reduces repeated clarification on the same recurring visual-symptom issue set without uploading evidence, changing an issue, diagnosing a cause, or claiming a repair
Contributor starter queue exact independent-review e4ce0aa…, publication-handoff 0a34e72…, and public-base gate 5dc0419…; C5–C9 remain READY_LOCAL_ONLY; 71 queue regressions, focused C5/C6 strict-MkDocs profiles, the exact 331-test S6 integration command, and 65 plan/routing/G0 regressions pass; current authenticated GET-only output finds 1 published good first issue (#422), 0 eligible starters, 1 blocked starter, 1 open PR, 0 potential task matches, PR #427 open/Draft/unmerged, the public develop queue absent, and one digest-bound C5 post-merge preparation handoff the contributor still waits instead of entering the closed cohort; WAITING_FOR_PRODUCT_MERGE cannot become publication review until PR #427 is merged and the canonical queue SHA matches public develop; title, sorted labels, heading-free body, and task/queue/body digests remain locally reviewable, but issue creation is a separately confirmed external write; no issue, label, assignment, comment, PR, Pages deployment, or community post was changed
Issue-triage application packet local follow-up converts the still-valid 29-row proposal into ordered, source- and evidence-hashed review actions: 23 closure drafts, 4 reproduction requests, 9 dependency reviews, and 1 monitor-only row (#422); the #69 draft explains both leaf parameters and their resolution tradeoff, retains the historical-bag limit, and now requires exact public Draft head 4b2ab514, open/Draft/mergeable state, 10 successful checks, 4 intentional skips, zero pending/failing checks, latest stable v0.9.0 at 0df0c4a exactly 52 commits behind reviewed fix a2368c4, and no v0.9.1 tag/release; 34 application and 19 proposal regressions, the 1,075-test lidarslam gate, 35 graph docs/CLI regressions, strict MkDocs, and a complete authenticated GET-only live drift audit pass stdout-only review aid; linked #69 head/state/CI, stable ancestry, candidate publication, or GET-only-authority drift emits no packet; every GitHub write authority remains false, no issue body, comment body, check name, raw release payload, or author identity is retained, and no issue, label, comment, release, tag, or state was changed
Fixed-demo low-storage recovery exact implementation d016520…; real local rejection reports exact additional_bytes_required, rounds 1.76 GiB upward for the human card, keeps system JSON path-free, and preserves the full shell-quoted demo retry; default floor remains 8 GiB this removes one locally reproduced activation burden; it is not a public clean-host completion, paired GLIM observation, or authority to lower the storage gate
Single-action system doctor exact implementation a83bbfe…; a real unconfigured source shell retains five stable findings but exposes one schema-bound source-build-required top-level action and one human Do this now recovery; 51 focused, 35 graph docs/product, 321 integrated S6, and 21 G0 tests pass with strict MkDocs and ROS lint rerunning doctor reprioritizes remaining blockers; the observed run is read-only and creates no clean-host timing, external first map, paired GLIM scorecard, or parity claim
Distribution preflights source route READY at exact public 3ed632e…; rosdistro NDT remains BLOCKED: Humble #52949 and Jazzy #52950 each have 5 / 6 exact-head checks passing, one stale-base rosdep failure, and an unanswered review; Humble RKO-LIO 0.3.2 is in main/testing, Jazzy 0.3.2 is in testing while main remains 0.2.0; package-manager E2E is SOURCE_REF_MISSING because v0.9.1 does not resolve canonical collision-free NDT convergence and a current-base green replacement precede package sync and clean-install E2E; do not merge the overlapping registrations or treat Jazzy main as ready
v1 authenticated live audit current local increment returns valid NOT_READY, 8 / 10, with exact NDT / package-manager / stable-release tuple BLOCKED / SOURCE_REF_MISSING / PUBLISHED; all six schema-valid package-manager states are preserved in the parent JSON and 18 focused regressions pass a missing v0.9.1 source ref is an actionable distribution blocker, not malformed child evidence or permission to create the tag; unauthenticated shared-rate-limit exhaustion may still make network child audits fail closed
Canonical NDT upstream Draft preflight refreshed 2026-08-17 as READY_FOR_DRAFT_PR, 30 / 30 PASS; exact upstream 5495fd9…, exact candidate 618f02f6…, expected fork verified, proposed branch absent, 4 open PRs inspected, 0 duplicates, 0 API errors, and write authority false; the schema-bound handoff fixes the create-only branch, base/head identities, exact Draft copy, and four-step verification route while every remote authority and write result remains false; the 3e11f30… response packet is BLOCKED solely because that Draft URL is absent and emits no reply body the local candidate and replies are technically bound but unpublished; non-ready states emit no handoff, and this ready handoff neither creates nor authorizes an upstream branch, PR, or rosdistro comment
Docker publication boundary convenience PR/manual runs remain verification-only; the candidate gate at c70c18d… uses trusted default-branch tooling, exact-head CI/identity checks, a protected candidate-images environment, digest-only output, disabled container networking during smoke tests, SBOM/provenance/attestation checks, and 30-day schema-backed evidence the gate can create no tag or Release; complete authenticated inventory at adecca6… proves only github-pages exists, so authorization must stop until a separate environment/E2 decision
Candidate environment and gate regressions 29 focused tests, actionlint v1.7.12, Python style, CTest 2 / 2, GET-only transport, shared authorization semantics, release-bundle inclusion, and exact-tip Humble/Jazzy default workflows pass the live result is ABSENT; workflow-facing CLIs persist one request, two distinct image records, and one pair report exactly once; no workflow dispatch, environment mutation, or GHCR mutation occurred
Candidate observer contract atomic preparation through f5ed80e…, exact row runner feed0ba…, one-command session 8bc5ea4…, guided local readiness a286c65…, and receipt-bound comparability at 3c19824…; four-file semantic derivation, exact remote artifact-byte comparison, content-bound Docker observer bootstrap, retained child/session receipts, exact first-map validation-receipt bytes, structured row execution, four-state host guidance, release-bundle inclusion, and strict docs pass with 189 focused candidate/onboarding regressions remote status is still NOT_CHECKED because no authorized bundle exists; local readiness and runner tests are not REMOTE_AUDIT_PASS, a trial, E2, or E4 authority
Neutral GLIM usability workflow recorder implementation 0575fb6…, evidence sync and public CI through ac22a3f…, plus the current local GET-only pair-identity and receipt-chain follow-up; the paired preparer rejects manual public Booleans, binds both canonical GitHub/tag or registry identities and approved docs redirects, SHA-binds both worksheets, persists a schema-valid receipt, and rolls back all three outputs on failure; the recorder requires the shared receipt and retains the untouched triplet under preparation/; the final checker and evidence index reject receipt-less, archive-tampered, or identity-drifted records; 16 preparer, 10 recorder, 17 checker, graph 1,489 / 13 skipped, and lidar_slam 1,094 tests pass, while a real GET preflight resolves Draft 4b2ab514… and GLIM v1.2.2faa264a1… with both docs at HTTP 200 the checked-in scorecard remains NOT_READY with 0 / 2 product records and 0 / 6 comparable tasks; a content-bound preparation chain and safer recording are not an external observation, parity result, or winner claim
Claim-bounded short demo media generator implementation d0c84bb…; one contract now binds version, canonical commands, slide copy, and three source-image hashes; the generated 10.666-second H.264 candidate carries four-cue English WebVTT, exact-revision Japanese/English copy, and a schema-valid byte manifest; 11 focused and 25 docs/release entrypoint tests pass the former release inventory's v0.2.2 post, retired commands, and unbound numerical copy are removed from the active path; the replacement remains PUBLICATION_CANDIDATE / NOT_PUBLISHED, grants no posting or release authority, and is not user evidence
Public documentation deployment provenance pre-upload schema enforcement and 9 focused regressions PASS at 5b8c8c4…; strict MkDocs emits a schema-valid source/version/route/page-byte manifest, both Pages jobs and the live environment branch policy are develop-only, and the clean candidate release bundle contains the generator, auditor, schemas, and evidence; live exact-public audit is BLOCKED because the manifest URL returns HTTP 404 URL shape alone cannot launch the independent cohort; the current Pages deployment remains unverified until a separately reviewed develop deployment publishes matching bytes
Complete maintained product gate Odometry-TF timing carrier 4bdd7ec…: source-explicit graph 1,489 passed / 13 skipped / 11 existing ImageIO warnings; source-explicit lidarslam 1,040 passed; 2,529 total; 74 focused checks, strict MkDocs, and changed-file Jazzy ament_flake8 pass; the canonical two-build bundle rehearsal passes with 271 manifest files, 11,965,449 archive bytes, and SHA-256 735a3683be43cfb2e2638e466b02b140339beb9da573bc5642872219090fc6a9 this is local commit-bound evidence, not a published release asset; the later evidence-sync/public candidate must rerun and may not reuse this checksum
Actionable stable-release profile gate clean public Draft carrier 4163b8c… reruns Leo Drive at 0.139152 m aligned Applanix cross-validation APE RMSE, 571 matched poses, and TARGET_MET; its schema-valid metrics.json has SHA-256 76d6465729a7c48a46919d2b1029996393be6d0e615a893fee28440637963627, the map passes 8 checks with one informational warning, and the hard gate now exits 2 with four blocking NO_DATA rows—Newer College Maths, NTU VIRAL, and both RTK-SLAM Construction sequences exact carrier evidence; this evidence synchronization creates a later docs-only commit, so that later exact candidate must rerun rather than relabel the carrier; no tag, Release, image, or E4 authority is granted
NTU VIRAL acquisition recovery exact implementation 8a856f5…, registration 657746f…, and byte-reporting follow-up d6e8bad…; a fresh plan requires 49,209,878,965 bytes, observed 6,326,681,600 bytes free, reported a 42,883,197,365-byte shortfall, and identified the attached unmounted 2,000,397,795,328-byte /dev/sda1; one mount action plus --dest-device replaces manual discovery/path substitution, preserves requested phases, and rechecks actual free space exact evidence; no automatic mount, authorization bypass, archive download, extraction, conversion, benchmark, or release-profile claim occurred; the curated bundle now contains the documented NTU command and resolver
RTK-SLAM acquisition recovery exact attached-storage implementation 0c3f588…; all four official DB3/metadata identities and one detached eval commit remain pinned, regular partial files are resumable, and text/JSON plans are write- and network-free; the real smallest-profile request required 11,886,726,027 bytes, observed 6,339,293,184 bytes free, reported a 5,547,432,843-byte root-FS shortfall, then identified the attached unmounted 2,000,397,795,328-byte /dev/sda1 ext4 partition and selected udisksctl mount -b /dev/sda1 as its single next action; --dest-device removes mount-path substitution and rechecks actual free space after mounting exact evidence; no automatic mount, authorization bypass, large download, or release-profile claim occurred; Construction Seq2 remains one mount, dry-run, verified acquisition, and measured suite away
Publication slice and whole-PR review plan PLAN_VALID_LOCAL_ONLY; 349 follow-up paths / 7 slices from frozen baseline 3ed632e…, composed with the original 116-path audit and exact two-commit / 11-path CI bridge into 396 whole-PR paths / 3 sequential phases; 0 uncovered, 0 extraneous, and 0 merge commits the machine gate binds both follow-up inventory and whole-PR union rather than silently skipping 6a8727a..3f4dd70; every displayed verification group remains self-contained for an ordinary terminal; exact coverage adds no mount, GitHub, release, posting, or community authority
Published onboarding identity v0.9.0 exact release commit plus Humble/Jazzy digests return READY, but its source route is NOT_READY with source-route-contract-missing; v0.9.1 report-to-packet fails closed at NOT_PUBLISHED the old release cannot be reused for same-version Docker/source evidence, and the new version cannot produce a release packet before E4 publication
v0.9.1 release audit NOT_PUBLISHED no v0.9.1 tag or GitHub Release was found
v0.9.1 GHCR images ABSENT for v0.9.1-humble and v0.9.1-jazzy no immutable candidate image identity exists
Onboarding matrix 4 / 4 product PASS; 0 / 4 comparable; BLOCKED Docker is v0.9.0, source is v0.9.1, human measurements are missing, and all four historical rows lack retained first-map validation-receipt bytes; a hash string alone no longer counts as comparable evidence
v1 readiness 8 / 10 distribution and independent adoption remain incomplete
Accepted independent maps 0 / 3 cohort remains closed

The exact public checks are intentionally re-runnable:

gh pr checks 427 --repo rsasaki0109/lidar_slam_ros2
python3 scripts/check_publication_slice_plan.py --json
python3 scripts/check_product_draft_review_routing.py --json
bash scripts/run_release_readiness_checks.sh \
  --skip-default-ci --fail-on-profiles
python3 scripts/check_ndt_omp_release_readiness.py --json
GITHUB_TOKEN="$(gh auth token)" \
python3 scripts/check_canonical_ndt_convergence.py \
  --upstream-checkout "${NDT_UPSTREAM_CHECKOUT:?}" \
  --candidate-checkout "${NDT_CANDIDATE_CHECKOUT:?}" \
  --online --require-ready-for-draft-pr --json
python3 scripts/check_package_manager_release_readiness.py \
  --version 0.9.1 --json
python3 scripts/run_source_onboarding_probe.py \
  --public-preflight \
  --source-commit 3ed632e6f6aa1e3ca7f32d893773de1079086ffb \
  --product-version 0.9.1
python3 scripts/check_public_docs_deployment.py \
  --expected-revision 3ed632e6f6aa1e3ca7f32d893773de1079086ffb \
  --expected-product-version 0.9.1 \
  --route source-quickstart \
  --json
GITHUB_TOKEN="$(gh auth token)" \
python3 scripts/check_candidate_environment.py --json --require-ready
python3 scripts/check_published_release.py --version 0.9.1 --json
python3 scripts/check_published_release.py \
  --version 0.9.1 --json --require-published \
  | python3 scripts/prepare_onboarding_matrix_packet.py \
      --published-release-report - --render
python3 scripts/check_onboarding_trial_matrix.py --json
python3 scripts/check_v1_readiness.py --json
python3 scripts/first_map_validator_cohort.py --json
python3 scripts/check_g0_readiness.py \
  --include-public-transition \
  --published-release-version 0.9.1

These commands perform read-only inspection. The last command must remain WAITING_FOR_PUBLIC_GATES while the matrix is not comparable; --render must not be used as a reason to recruit.

Separated action gates

Gate Current state Authorized scope
L0 local preparation complete for this packet code, tests, docs, offline audits, and read-only inspection
E1 source review product Draft #427 is public and exact-head CI PASS; canonical NDT Draft remains local READY_FOR_DRAFT_PR with an exact create-only/no-write handoff publishing the third-party upstream branch/PR and later replies requires a separate exact-revision decision; no force-push, mark-ready, or merge is implied
E2 artifact hosting GATE_IMPLEMENTED_LOCAL / ENVIRONMENT_ABSENT / NOT_AUTHORIZED / NOT_PUBLISHED after the workflow is reviewed on develop, separately configure and review the protected environment; only a later exact E2 event may request digest-only candidate evidence
E3 community mutation NOT_AUTHORIZED no issue labels, comments, closures, starter issues, Discussions, or recruitment
E4 stable release HOLD / NOT_AUTHORIZED no tag, GitHub Release, package, image promotion, or announcement

Approval of one row never approves another. In particular, green CI does not authorize E2, E3, or E4, and a published identity would not by itself create a comparable human trial.

Safe transition order

  1. Run the GET-only product-Draft audit, verify the composed initial / CI-bridge / follow-up review coverage, then choose one of the four capability lanes and review the exact matching head by its assigned publication slices. Stop on branch, commit, mergeability, CI, phase lineage, or inventory drift. Mark-ready and merge remain separate maintainer decisions; do not measure mixed-version rows.
  2. Only after the dashboard observes the exact PR as merged, review the dedicated candidate workflow at c70c18d… and shared environment preflight at adecca6…. Do not merge it or configure candidate-images as an implication of E1; the environment and its required reviewer/develop-only policy are a separate repository-admin decision. Never use the convenience-image manual dispatch as a substitute.
  3. If E2 is separately chosen after the gate is on develop and the protected environment passes the read-only audit, send one exact e2-publish-candidate-image event. Publish only the two untagged candidate digests. On each prepared disposable row host, prefer start_candidate_trial.py --workflow-run-url ... --row ... --output-dir ... --acknowledge-dedicated-trial-host --check-readiness and require READY before running the exact command it prints. Require the session's retained READY_FOR_OBSERVER handoff, REMOTE_AUDIT_PASS, and terminal session.json; a comparable PASS also requires the exact bounded first-map-validation-receipt.json. A missing output on pre-contract failure is intentional.
  4. If E4 is separately chosen later, follow RELEASING.md; before tagging, require the exact candidate commit's four remaining blocking release profiles to pass run_release_readiness_checks.sh --fail-on-profiles. After publication, require check_published_release.py --require-published and record both image digests before using them in a trial.
  5. If the handoff must be reviewed or transferred separately, use prepare_candidate_trial.py followed by run_candidate_trial.py. Both the combined and split routes revalidate structured identity, bootstrap the content-bound Docker observer when selected, and preserve blocked, FAIL, and harness outcomes without inventing human measurements. Keep the generated packet, trial record, first-map validation receipt, audit, exact artifacts/ bytes, and execution receipt together. For a separately published release, use its exact public source commit and both published image digests. Do not mix the modes or reuse the current v0.9.0/v0.9.1 matrix.
  6. Run fresh dedicated Humble/Jazzy Docker and source trials with a human observer. Record active operator time, command count, workflow download, peak disk, wall time, and output size, and retain the exact privacy-bounded validation receipt beside the trial record; blank measurements or a missing receipt remain non-comparable.
  7. For the separate GLIM comparison, prepare the exact public pair with prepare_usability_scorecard_pair.py --verify-public, then record it with record_usability_scorecard_pair.py --require-ready. Publish task-level evidence only; do not infer one overall winner.
  8. Only after at least one comparable Docker PASS and one comparable source PASS may the E3 cohort decision be reconsidered. Three accepted independent reports are still required for the v1 gate.

Current decision

E2 artifact host: DEFER — no host or upload authorized
E2 candidate images: DEFER — gate at c70c18d, atomic preparation at f5ed80e, row execution at feed0ba, one-command session at 8bc5ea4, guided readiness at a286c65, and GET-only environment preflight at adecca6; workflow not on develop, candidate-images ABSENT from the complete inventory, no dispatch, digest publication, remote audit, or trial
E3 community mutation: DEFER — cohort and issue operations remain closed
E4 v0.9.1 release/images: DEFER — G0 matrix and distribution gates remain open; four exact-head blocking benchmark profiles currently have NO_DATA

This packet is evidence and handoff text only. It performs no release, image, fixture, issue, branch, review, or community mutation.