# Swarm75: read-only host and descriptor recheck Observed on 2026-09-21 during initial VoidKontrol wayfinding. This is discovery evidence, not an authenticated control session or a hardware acceptance result. ## Findings | Observation | Evidence | | --- | --- | | Host | `/etc/os-release`: Void Linux; `uname -r`: `7.2.6_1`; `getconf GNU_LIBC_VERSION`: `glibc 2.41` | | hidraw support | `/boot/config-7.2.6_1`: `CONFIG_HIDRAW=y`, `CONFIG_HID_GENERIC=m`, `CONFIG_USB_HID=m` | | Swarm identity | Both relevant sysfs HID devices report `HID_ID=0003:0000258A:0000010C`, `HID_NAME=BY Tech Kreo Swarm` | | Input ownership | Both sysfs devices report `DRIVER=hid-generic`; nothing was unbound or grabbed | | Interface 0 | Present as `/dev/hidraw4` at observation time | | Interface 1 | Present as `/dev/hidraw5` at observation time; sysfs USB interface suffix `:1.1` | | Access | Interface 1 node is `root:root`, mode `0600`; desktop-user `test -r` and `test -w` both fail | | Vendor usage | Interface 1 descriptor includes vendor application collections with usage page `0xff00`, usage `0x01` | | Descriptor | 240 bytes, SHA-256 `04f6ae259d80ba5828ae7f6b81cdcb2d31acf0b20dc93b473561cd8b3c930ab0` | The node numbers are observations, not persistent identifiers. Discovery must reselect and revalidate the matching interface each time. Parsing the descriptor's report-size and report-count items gives these payload sizes (excluding the report ID byte): | Report ID | Input payload | Feature payload | | --- | --- | --- | | 1 | 1 byte including padding | — | | 2 | 2 bytes | — | | 3 | 3 bytes | — | | 4 | 15 bytes | — | | 5 | — | 5 bytes | | 6 | 7 bytes | 519 bytes | | 7 | 7 bytes | — | Report 1 includes three meaningful system-control bits and padding, consistent with the original specification's description. The descriptor agrees with the declared report-6 transport size; that agreement does not establish authentication, command semantics, checksums, firmware identity, or safe persistence behavior. ## Correction to the initial specification The earlier inference from `modprobe hidraw` was incorrect. Linux declares [`CONFIG_HIDRAW` as `bool`](https://github.com/torvalds/linux/blob/master/drivers/hid/Kconfig), so `CONFIG_HIDRAW=m` is not an alternative and a missing standalone module is not proof that the running kernel lacks hidraw. Current kernel configuration and existing nodes directly establish its presence here. ## Reproduction and boundaries Inspect `/sys/class/hidraw/*/device/uevent` and resolve their symlink targets to identify the Swarm interfaces. Read the selected device's `report_descriptor` attribute, sum report-size × report-count bits by report ID and main-item type, and hash the descriptor with SHA-256. Query node properties with `udevadm info` and inspect access without opening the device for control. Only kernel configuration, sysfs metadata, descriptor bytes, and filesystem permissions were read. No feature reports were sent, no normal input events were read, no permission rules were installed, and no device settings changed. Ordinary typing continuity was not measured by an interactive acceptance test. ## Evidence still required - Confirm the physical connection and keyboard layout, including special controls. - A deliberately scoped official Kontrol authentication and configuration-read capture for this device and transport. - Exact framing/authentication/checksum and complete configuration-read coverage. - Later, explicit reversible write/readback/persistence/restore verification for every feature advertised as supported. Tracked by [Obtain authenticated Swarm75 evidence without interrupting normal input](https://git.bongbetic.com/xavierk/voidkontrol/issues/5).