Files
voidkontrol/docs/evidence/2026-09-21-swarm75.md
T

3.7 KiB
Raw Blame History

Swarm75: read-only host and descriptor recheck

Observed on 2026-09-21 during initial VoidKontrol wayfinding. This is discovery evidence, not an authenticated control session or a hardware acceptance result.

Findings

Observation Evidence
Host /etc/os-release: Void Linux; uname -r: 7.2.6_1; getconf GNU_LIBC_VERSION: glibc 2.41
hidraw support /boot/config-7.2.6_1: CONFIG_HIDRAW=y, CONFIG_HID_GENERIC=m, CONFIG_USB_HID=m
Swarm identity Both relevant sysfs HID devices report HID_ID=0003:0000258A:0000010C, HID_NAME=BY Tech Kreo Swarm
Input ownership Both sysfs devices report DRIVER=hid-generic; nothing was unbound or grabbed
Interface 0 Present as /dev/hidraw4 at observation time
Interface 1 Present as /dev/hidraw5 at observation time; sysfs USB interface suffix :1.1
Access Interface 1 node is root:root, mode 0600; desktop-user test -r and test -w both fail
Vendor usage Interface 1 descriptor includes vendor application collections with usage page 0xff00, usage 0x01
Descriptor 240 bytes, SHA-256 04f6ae259d80ba5828ae7f6b81cdcb2d31acf0b20dc93b473561cd8b3c930ab0

The node numbers are observations, not persistent identifiers. Discovery must reselect and revalidate the matching interface each time.

Parsing the descriptor's report-size and report-count items gives these payload sizes (excluding the report ID byte):

Report ID Input payload Feature payload
1 1 byte including padding —
2 2 bytes —
3 3 bytes —
4 15 bytes —
5 — 5 bytes
6 7 bytes 519 bytes
7 7 bytes —

Report 1 includes three meaningful system-control bits and padding, consistent with the original specification's description. The descriptor agrees with the declared report-6 transport size; that agreement does not establish authentication, command semantics, checksums, firmware identity, or safe persistence behavior.

Correction to the initial specification

The earlier inference from modprobe hidraw was incorrect. Linux declares CONFIG_HIDRAW as bool, so CONFIG_HIDRAW=m is not an alternative and a missing standalone module is not proof that the running kernel lacks hidraw. Current kernel configuration and existing nodes directly establish its presence here.

Reproduction and boundaries

Inspect /sys/class/hidraw/*/device/uevent and resolve their symlink targets to identify the Swarm interfaces. Read the selected device's report_descriptor attribute, sum report-size × report-count bits by report ID and main-item type, and hash the descriptor with SHA-256. Query node properties with udevadm info and inspect access without opening the device for control.

Only kernel configuration, sysfs metadata, descriptor bytes, and filesystem permissions were read. No feature reports were sent, no normal input events were read, no permission rules were installed, and no device settings changed. Ordinary typing continuity was not measured by an interactive acceptance test.

Evidence still required

  • Confirm the physical connection and keyboard layout, including special controls.
  • A deliberately scoped official Kontrol authentication and configuration-read capture for this device and transport.
  • Exact framing/authentication/checksum and complete configuration-read coverage.
  • Later, explicit reversible write/readback/persistence/restore verification for every feature advertised as supported.

Tracked by Obtain authenticated Swarm75 evidence without interrupting normal input.