Obtain authenticated Swarm75 evidence without interrupting normal input #5

Open
opened 2026-09-21 04:57:54 +00:00 by xavierk · 5 comments
Owner

Question

Collect the evidence needed to decide which controls v1 can safely implement for the current USB presentation: confirm device signature/descriptor and precise physical layout, perform a read-only official Kontrol session, record authentication/readback framing, and document readback coverage for a full backup. Preserve input kernel ownership. No guessed packets, feature-report-5 probes, firmware operations, or configuration writes. Trace only the vendor-control interface and separate/redact unrelated device data; a recording must be scoped before sharing. Raw configuration captures can contain sensitive macro content: retain raw captures privately, review contents before publishing fixtures, and preserve protocol structure in sanitized fixtures. Record kernel/hidraw/permissions checks and exact firmware/transport identity. This is HITL where interaction with the physical keyboard or vendor UI is needed; close only when the required evidence actually exists, otherwise retain concrete blockers.

Parent map: Find the way to VoidKontrol v1: complete verified Swarm75 control on Void Linux

## Question Collect the evidence needed to decide which controls v1 can safely implement for the current USB presentation: confirm device signature/descriptor and precise physical layout, perform a read-only official Kontrol session, record authentication/readback framing, and document readback coverage for a full backup. Preserve input kernel ownership. No guessed packets, feature-report-5 probes, firmware operations, or configuration writes. Trace only the vendor-control interface and separate/redact unrelated device data; a recording must be scoped before sharing. Raw configuration captures can contain sensitive macro content: retain raw captures privately, review contents before publishing fixtures, and preserve protocol structure in sanitized fixtures. Record kernel/hidraw/permissions checks and exact firmware/transport identity. This is HITL where interaction with the physical keyboard or vendor UI is needed; close only when the required evidence actually exists, otherwise retain concrete blockers. Parent map: [Find the way to VoidKontrol v1: complete verified Swarm75 control on Void Linux](https://git.bongbetic.com/xavierk/voidkontrol/issues/1)
xavierk added the wayfinder:taskwayfinder:child-of-1 labels 2026-09-21 04:57:54 +00:00
xavierk self-assigned this 2026-09-21 05:00:46 +00:00
Author
Owner

Progress — discovery only; capture remains open

A read-only recheck confirms CONFIG_HIDRAW=y, both Swarm HID interfaces remain bound to hid-generic, and interface 1 has the vendor usage and 519-byte report-6 feature payload described in the spec. Its current root:root / 0600 node is inaccessible to the desktop user. A failed modprobe hidraw was not evidence of absent support because the kernel option is boolean.

Read-only host and descriptor evidence records the measurements and limits. The original spec now contains the dated correction.

No HID feature reports or setting writes were sent. Authentication, firmware/layout identity, readback coverage, and protocol captures are still missing; this ticket is not resolved. Release the exploratory claim so a later session can take the capture work with the human.

## Progress — discovery only; capture remains open A read-only recheck confirms `CONFIG_HIDRAW=y`, both Swarm HID interfaces remain bound to `hid-generic`, and interface 1 has the vendor usage and 519-byte report-6 feature payload described in the spec. Its current `root:root` / `0600` node is inaccessible to the desktop user. A failed `modprobe hidraw` was not evidence of absent support because the kernel option is boolean. [Read-only host and descriptor evidence](https://git.bongbetic.com/xavierk/voidkontrol/src/commit/f90df8aba1c7c5a41634bdf6e02beb1a1a6653c1/docs/evidence/2026-09-21-swarm75.md) records the measurements and limits. The original spec now contains the dated correction. No HID feature reports or setting writes were sent. Authentication, firmware/layout identity, readback coverage, and protocol captures are still missing; this ticket is not resolved. Release the exploratory claim so a later session can take the capture work with the human.
xavierk removed their assignment 2026-09-21 05:06:24 +00:00
xavierk self-assigned this 2026-09-21 05:21:25 +00:00
Author
Owner

Progress - authenticated capture remains a human-operated blocker

Read-only discovery establishes the USB signature match, intact hid-generic input ownership, interface-1 vendor collection, and report-6 size. It does not establish authenticated device identity, firmware/layout identity, command framing, checksums, configuration-read coverage, or any safe write.

Required capture, with no settings writes

  1. Use the observed USB presentation only; do not test Bluetooth, a receiver, or another cable mode. Confirm normal typing and media keys work before and after the session.
  2. Scope the recording to the Swarm vendor-control interface and the official Kreo Kontrol site. Do not capture general USB traffic, normal input events, browser content, or unrelated devices.
  3. In the official UI, select the matching keyboard and perform its normal connection/authentication flow plus device-information and configuration reads only. Do not open or invoke apply/save/reset/firmware actions, alter a control, send hand-crafted reports, probe report 5, unbind a driver, or open/grab /dev/input/event*.
  4. Record the USB transport identity, exact time, browser/Kontrol version or asset hash, device/firmware values the UI exposes, physical key layout and special controls, and the ordered vendor request/response exchange for authentication and each readback category: attributes, layers/key map, lighting/custom light, macros, power, and any advanced-key data.
  5. Keep the raw capture private and access-restricted. Macro reads may expose personal text or shortcuts. Do not paste raw packets into this issue or chat. First review the capture, then publish only a sanitized structural fixture plus a coverage table identifying which fields were read and which remain unavailable.
  6. Report whether the official UI completed every read, any permission/pairing failure, and whether typing remained uninterrupted. A failed capture is still useful evidence if it includes the exact safe blocker.

The next decision tickets remain blocked until this evidence exists. This task is not resolved.

## Progress - authenticated capture remains a human-operated blocker Read-only discovery establishes the USB signature match, intact `hid-generic` input ownership, interface-1 vendor collection, and report-6 size. It does **not** establish authenticated device identity, firmware/layout identity, command framing, checksums, configuration-read coverage, or any safe write. ### Required capture, with no settings writes 1. Use the observed USB presentation only; do not test Bluetooth, a receiver, or another cable mode. Confirm normal typing and media keys work before and after the session. 2. Scope the recording to the Swarm vendor-control interface and the official Kreo Kontrol site. Do not capture general USB traffic, normal input events, browser content, or unrelated devices. 3. In the official UI, select the matching keyboard and perform its normal connection/authentication flow plus device-information and configuration **reads only**. Do not open or invoke apply/save/reset/firmware actions, alter a control, send hand-crafted reports, probe report 5, unbind a driver, or open/grab `/dev/input/event*`. 4. Record the USB transport identity, exact time, browser/Kontrol version or asset hash, device/firmware values the UI exposes, physical key layout and special controls, and the ordered vendor request/response exchange for authentication and each readback category: attributes, layers/key map, lighting/custom light, macros, power, and any advanced-key data. 5. Keep the raw capture private and access-restricted. Macro reads may expose personal text or shortcuts. Do not paste raw packets into this issue or chat. First review the capture, then publish only a sanitized structural fixture plus a coverage table identifying which fields were read and which remain unavailable. 6. Report whether the official UI completed every read, any permission/pairing failure, and whether typing remained uninterrupted. A failed capture is still useful evidence if it includes the exact safe blocker. The next decision tickets remain blocked until this evidence exists. This task is not resolved.
xavierk removed their assignment 2026-09-21 05:23:52 +00:00
xavierk self-assigned this 2026-09-21 05:29:16 +00:00
Author
Owner

Progress — awaiting the human-operated capture

I verified that the current evidence and the existing safe-capture checklist remain sufficient to run this prerequisite. No device command, capture, configuration write, input grab, driver change, or browser session was initiated in this pass.

The ticket remains blocked on the physical-keyboard interaction described in the prior progress comment: a scoped, read-only official Kontrol capture on the observed USB presentation, followed by private review and a sanitized structural fixture plus coverage table. It must remain open until that evidence (or a concrete safe blocker) is recorded.

## Progress — awaiting the human-operated capture I verified that the current evidence and the existing safe-capture checklist remain sufficient to run this prerequisite. No device command, capture, configuration write, input grab, driver change, or browser session was initiated in this pass. The ticket remains blocked on the physical-keyboard interaction described in the prior progress comment: a scoped, read-only official Kontrol capture on the observed USB presentation, followed by private review and a sanitized structural fixture plus coverage table. It must remain open until that evidence (or a concrete safe blocker) is recorded.
xavierk removed their assignment 2026-09-21 05:30:04 +00:00
xavierk self-assigned this 2026-09-21 05:31:35 +00:00
Author
Owner

Progress — official read-only attempt blocked before device access

At 2026-09-21, I revalidated the attached USB signature (258a:010c) and the intact hid-generic binding. The vendor interface remains /dev/hidraw5, root:root mode 0600, so the desktop Chrome process cannot open it.

I opened the official Kontrol site, kept its optional analytics, crash reporting, and session replay disabled, and selected Connect your Kreo device. I did not run the page-proposed curl | sh udev installer. The flow remains visibly at Connecting…; it did not expose a device selector, browser permission request, authenticated session, firmware/layout identity, or any configuration readback.

No HID feature report, configuration write, input-device read/grab, driver change, host configuration change, or raw packet capture occurred. The host has usbhid-dump, but no tshark/dumpcap and no user-accessible usbmon debugfs endpoint, so there is no available scoped capture path for the required authentication/readback framing.

Concrete blockers: (1) explicit authorization and a reviewed narrowly scoped udev access rule, rather than the third-party pipe-to-shell installer; (2) an authorized capture method that isolates only the Swarm vendor-control traffic; and (3) acceptance of the browser's device-permission prompt once it can enumerate the device. This ticket remains open.

## Progress — official read-only attempt blocked before device access At 2026-09-21, I revalidated the attached USB signature (`258a:010c`) and the intact `hid-generic` binding. The vendor interface remains `/dev/hidraw5`, `root:root` mode `0600`, so the desktop Chrome process cannot open it. I opened the official Kontrol site, kept its optional analytics, crash reporting, and session replay disabled, and selected **Connect your Kreo device**. I did not run the page-proposed `curl | sh` udev installer. The flow remains visibly at **Connecting…**; it did not expose a device selector, browser permission request, authenticated session, firmware/layout identity, or any configuration readback. No HID feature report, configuration write, input-device read/grab, driver change, host configuration change, or raw packet capture occurred. The host has `usbhid-dump`, but no `tshark`/`dumpcap` and no user-accessible `usbmon` debugfs endpoint, so there is no available scoped capture path for the required authentication/readback framing. Concrete blockers: (1) explicit authorization and a reviewed narrowly scoped udev access rule, rather than the third-party pipe-to-shell installer; (2) an authorized capture method that isolates only the Swarm vendor-control traffic; and (3) acceptance of the browser's device-permission prompt once it can enumerate the device. This ticket remains open.
xavierk removed their assignment 2026-09-21 05:36:32 +00:00
xavierk self-assigned this 2026-09-21 05:55:17 +00:00
Author
Owner

Progress — reviewed desktop access installed; capture remains pending

With explicit authorization, I installed /etc/udev/rules.d/70-voidkontrol-swarm75.rules. It invokes udev's usb_id builtin and grants soubarna:soubarna mode 0600 access only when the hidraw device identifies as 258a:010c on USB interface 01. udevadm test and a targeted change event verified that /dev/hidraw5 is readable/writable by soubarna, while the boot-keyboard /dev/hidraw4 remains root:root 0600.

I also prepared a bus-003/device-004 control-transfer-only usbmon collector in a root-only directory. Kontrol did not reach the device: the collector recorded zero lines. The collector, debugfs mount, and usbmon module were then cleanly stopped and removed; the empty root-only artifact is retained as evidence of zero traffic. No feature report or configuration write occurred.

The official page is now left at Connecting… after requesting the device. The remaining next action is accepting Chrome's device permission for kontrol.kreo-tech.com to access the identified Kreo Swarm. That permission is required before restarting the scoped collector and performing the read-only authentication/readback capture. This ticket remains open.

## Progress — reviewed desktop access installed; capture remains pending With explicit authorization, I installed `/etc/udev/rules.d/70-voidkontrol-swarm75.rules`. It invokes udev's `usb_id` builtin and grants `soubarna:soubarna` mode `0600` access only when the hidraw device identifies as `258a:010c` on USB interface `01`. `udevadm test` and a targeted change event verified that `/dev/hidraw5` is readable/writable by `soubarna`, while the boot-keyboard `/dev/hidraw4` remains `root:root 0600`. I also prepared a bus-003/device-004 control-transfer-only usbmon collector in a root-only directory. Kontrol did not reach the device: the collector recorded zero lines. The collector, debugfs mount, and `usbmon` module were then cleanly stopped and removed; the empty root-only artifact is retained as evidence of zero traffic. No feature report or configuration write occurred. The official page is now left at **Connecting…** after requesting the device. The remaining next action is accepting Chrome's device permission for `kontrol.kreo-tech.com` to access the identified Kreo Swarm. That permission is required before restarting the scoped collector and performing the read-only authentication/readback capture. This ticket remains open.
xavierk removed their assignment 2026-09-21 06:08:40 +00:00
Sign in to join this conversation.