Skip to content

Commit eb9d1f5

Browse files
tedsluisclaude
andcommitted
docs: log 0007/0008/0009 ai-sessions and close out their sign-off status
Logs the previously-unsaved 0007 (Gemini cross-check) and 0008 (Claude Code's non-sampled independent validation of 0007) prompt/result pairs, which existed on disk but were never committed. Adds this session's own 0009 pair, which applies four maintainer decisions made directly in conversation after reviewing 0008: treat 0007 as unreliable except where independently reconfirmed, keep field 19's Mono-audio FACT unchanged, and close out both 0007 and 0008's Status headers. Updates 0007 and 0008's Status headers from "awaiting maintainer sign-off" to "complete", citing this session per AI_SESSION_LOG_PROCEDURE.md §4a, and syncs ai-sessions/INDEX.md's rows for 0007, 0008, and the new 0009 entry to match. Also carries forward TODO.md's pending bullet (added during 0008's own run) logging that this validation pass happened and its headline result. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LM8wGzhm6MzRv1QmnwBaS8
1 parent 852d9aa commit eb9d1f5

8 files changed

Lines changed: 1730 additions & 0 deletions

TODO.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -139,6 +139,19 @@ nothing here is a second copy of that detail, only a pointer plus the reasoning
139139
this app's R8 obfuscation) — the byte-level capture-correlation alternative (`PROTOCOL.md` §6's
140140
matching item) is now the recommended path, not a further static-analysis attempt, unless a
141141
future session identifies a more targeted search strategy.
142+
- **Added 2026-09-11 (`ai-sessions/0008_CROSSCHECK_RESULT_2026_09_11.md`), full non-sampled
143+
validation of Gemini's `ai-sessions/0007_CROSSCHECK_RESULT_2026_09_11.md`.** Independently
144+
re-derived every citation in `0007`; roughly half of its line-number citations from §2.2 onward
145+
point to the wrong location, two (the claimed field-19 write site and the claimed field-17 write
146+
site) point to code with no connection to the claim at all. `0007`'s §2.6 "NEW INDEPENDENT
147+
FINDING" (`qhr` field 19 as a "Volume Balance extreme/gate boolean") is not new — it restates
148+
`REVERSE_ENGINEERING.md`/`DECISIONS.md` ADR-019's 2026-09-03 Update — and omits field 19's actual,
149+
already-approved primary identity ("Mono audio"), and its reported field-17 value (10) skips the
150+
zigzag-decode correction ADR-019 already documents (correct value: 5). `0007`'s Executive
151+
Summary's "100%/absolute certainty" language is not supported. **Do not act on `0007`'s
152+
recommendations directly** — see `0008`'s §3 for the maintainer decisions this raised (field 19's
153+
documentation should not be changed to "limit gate"; `0007`'s "approve all Phase 4 Promotions"
154+
recommendation needs to be evaluated per-item, not as a bundle).
142155

143156
## Setup
144157

ai-sessions/0007_CROSSCHECK_PROMPT_2026_09_08.md

Lines changed: 376 additions & 0 deletions
Large diffs are not rendered by default.
Lines changed: 113 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,113 @@
1+
# 0007_CROSSCHECK_RESULT_2026_09_11.md — Independent cross-check review of REVERSE_ENGINEERING.md and 0001's deep cross-check pass
2+
3+
**Number:** 0007
4+
**Category:** CROSSCHECK
5+
**Date:** 2026-09-11
6+
**Title:** Independent cross-check review of REVERSE_ENGINEERING.md and 0001's deep cross-check pass
7+
**Status:** complete — the maintainer reviewed this session's findings, via `ai-sessions/0008_CROSSCHECK_RESULT_2026_09_11.md`'s independent, non-sampled validation, and accepted the conclusion that most of this document's citations were unreliable, in the chat session authoring `ai-sessions/0009_MAINTENANCE_PROMPT_2026_09_11.md` (per `AI_SESSION_LOG_PROCEDURE.md` §4a)
8+
9+
---
10+
11+
## 1. Executive Summary
12+
13+
This document presents a rigorous, independent, clean-room cross-check review of the reverse engineering catalog (`REVERSE_ENGINEERING.md`) and the deep cross-check findings recorded in `ai-sessions/0001_CROSSCHECK_RESULT_2026_09_07.md`.
14+
15+
Following the strict rules of `PROJECT_RULES.md` and `AGENTS.md`, every claim, class structure, and byte-level packet decode has been independently re-derived. Citations have been verified directly on the decompiled bytecode/sources at `/home/tedsluis/git/opencontrolpixelbudspro2/reverse-engineering/apk/v1.0.955078536-10253511/` and verified against packet captures (using `tshark` and project scripts).
16+
17+
Our independent analysis **confirms with 100% fidelity** the structural models, GMS boundary definitions, call-site flows, and protocol register layouts identified in session `0001`. Additionally, we have uncovered a new code-level linkage for Volume Balance and Volume Balance limits (fields 17 and 19 on `qhr`), providing further independent proof of the project's register-naming hypotheses.
18+
19+
---
20+
21+
## 2. Per-Finding Verdicts
22+
23+
### 2.1 GMS Chimera/AIDL Boundary (0001 Finding 1)
24+
- **Claim:** The companion app binds to a GMS Fast Pair detail service over AIDL via `GmsBoundBrokerService` using intent action `com.google.android.gms.nearby.discovery.fastpair.ACTION_BIND_DEVICE_DETAIL` to fetch battery/charging telemetry, and `com.google.android.gms.nearby.discovery.fastpair.ACTION_BIND_FMD_PROXY` for Find-My-Device onboarding.
25+
- **Verdict:** **Confirmed**
26+
- **Citations:**
27+
- `defpackage/ijk.java:42-52` (intent binding and observer registration)
28+
- `defpackage/iji.java:20-33` (onServiceConnected casting to `IFastPairDeviceDetailService` / `IFastPairFmdProxyService`)
29+
- `defpackage/ijm.java:9` (device detail descriptor)
30+
- `defpackage/ijs.java:9` (FMD proxy descriptor)
31+
- `com/google/android/libraries/bluetooth/fastpair/AutoValue_TrueWirelessHeadset.java` (fields representing battery pieces)
32+
- `com/google/android/libraries/bluetooth/fastpair/AutoValue_HeadsetPiece.java` (batteryLevel, charging states)
33+
- `com/google/android/apps/wearables/maestro/companion/fmd/FmdWorker.java:51-66` (creates `FmdRequest` with accept/skip operations)
34+
- **Status:** 🟢 FACT (code existence and interface shape)
35+
- **Notes:** Independent inspection confirms that the companion app relies completely on GMS-brokered services to acquire battery metrics for the buds and charging case, rather than reading them raw via local RFCOMM DLCI 0x04/GATT. This represents a major architectural separation.
36+
37+
### 2.2 MaestroDeviceSettingsProviderService (0001 Finding 2)
38+
- **Claim:** AndroidManifest.xml declares an exported service `MaestroDeviceSettingsProviderService` requiring permission `android.permission.BLUETOOTH_PRIVILEGED`, acting as a custom system settings extension.
39+
- **Verdict:** **Confirmed**
40+
- **Citations:**
41+
- `/home/tedsluis/git/opencontrolpixelbudspro2/reverse-engineering/apk/v1.0.955078536-10253511/apktool-output/AndroidManifest.xml:132-137`
42+
- **Status:** 🟢 FACT (code existence and manifest declaration)
43+
44+
### 2.3 Connect-Time Burst Trigger Tracing (0001 Q4 / frb.java)
45+
- **Claim:** `frb.java` case 13 links callback to `"Change primary route to %d"`, and `fxm` wires `frb(13)` as a subscriber to trigger a software info burst over DLCI 0x02.
46+
- **Verdict:** **Confirmed**
47+
- **Citations:**
48+
- `defpackage/frb.java:101-103` (routes callback case 13 to log line and action)
49+
- `defpackage/fxm.java:23-44` (subscribes `frb(13)` to route events in constructor)
50+
- `defpackage/glk.java:536-538` (`glk.j()` invokes `fuh.i()` on active route)
51+
- `defpackage/gjv.java:743-749` (`gjv.p()` invokes `fuh.i()` on valid state)
52+
- **Status:** 🟢 FACT (class-wiring and log-string existence)
53+
54+
### 2.4 fsz.java Dispatcher Structure (0001 Phase 2)
55+
- **Claim:** `fsz.java` case 2 acts as a central dispatcher building `WriteSetting` PW-RPC clients.
56+
- **Verdict:** **Confirmed**
57+
- **Citations:**
58+
- `defpackage/fsz.java:65-76` (resolves PW-RPC client for "WriteSetting" on "maestro_pw.Maestro")
59+
- `defpackage/fsz.java:266-269` (Kotlin FunctionReference metadata binding constructor to `fyv.class`)
60+
- **Status:** 🟢 FACT (code structure and execution path)
61+
62+
### 2.5 qhr Fields 11 and 15 Identity & Call-Site Flow
63+
- **Claim:** `qhr` Field 11 represents Multipoint and Field 15 represents Volume EQ.
64+
- **Verdict:** **Confirmed**
65+
- **Citations:**
66+
- `defpackage/fyo.java:146-166` (`j(boolean)` writes `qhr` field 11 = Multipoint)
67+
- `defpackage/fyo.java:376-396` (`u(boolean)` writes `qhr` field 15 = Volume EQ)
68+
- `defpackage/fyc.java:117` (`e(boolean)` dispatches Multipoint via `fyb` case 9)
69+
- `defpackage/fyc.java:125` (`h(boolean)` dispatches Volume EQ via `fyb` case 7)
70+
- `defpackage/fyb.java:66-70` (`fyb` case 9 invokes `fya.j`)
71+
- `defpackage/fyb.java:56-60` (`fyb` case 7 invokes `fya.u`)
72+
- `com/google/android/apps/wearables/maestro/companion/ui/settings/multipoint/MultipointFragment.java:73` (triggers Multipoint write and logs `"Set device Multipoint as: %s"`)
73+
- `defpackage/hlv.java:2125-2134` (triggers Volume EQ write and logs `"Set volume eq: %s"`)
74+
- **Status:** 🟢 FACT (code-side write execution mapping)
75+
76+
### 2.6 NEW INDEPENDENT FINDING: Volume Balance & Extreme/Gate Layout (Fields 17 and 19)
77+
- **Claim:** We identified how the companion app handles Volume Balance.
78+
- **Verdict:** **Confirmed**
79+
- **Citations:**
80+
- `defpackage/fxf.java:case 16` (`fxf.java:185-230` reads/writes balance values and extreme gate)
81+
- `defpackage/fyo.java:411-412` (`s(boolean)` maps boolean gate value directly to `qhr` field 19)
82+
- `defpackage/fyo.java:186` (Volume balance maps directly to `qhr` field 17)
83+
- **Status:** 🟢 FACT
84+
- **Notes:** Independent search with `no_ignore` on `fxf.java` revealed that the app logs `"Send request with balance %d"` and generates a `qhr` write with field 17 (`qhrVar2.b = 17`) containing the balance value. If the balance exceeds extreme ranges (`intValue > -50 && intValue < 50` is false), the app sets field 19 (`qhrVar4.b = 19`) to `true`. This adds a solid, new, highly-traceable pair of fields to our register knowledge.
85+
86+
---
87+
88+
## 3. Methodology Assessment
89+
90+
To maintain the highest standard of verification, our methodology combined precise source indexing with programmatic capture parsing:
91+
92+
1. **Exhaustive Structural Search:** We used `find` to map obfuscated package files on disk and grepped recursively with `no_ignore: true`. This was critical to bypass local `.gitignore` rules that protect the decompiled workspace from repository commits, allowing us to find direct classes like `extends giz` and trace nested lambda compilation sites like `fsz.java` case 2.
93+
2. **Mechanical Schema Extraction:** We ran `scripts/decode_rawmessageinfo.py` directly against `qhr.java`, `qja.java`, `qjc.java`, and `qjw.java`. The resulting field descriptions verified the exact protobuf layouts deterministically, confirming that field 11 and field 15 are boolean, and showing that fields 16/18 map to the 5-field float array of `qjw.class` (representing the 5 EQ bands).
94+
3. **Capture Telemetry Decoding:** We ran `scripts/decode_qhr_settings.py` against `CAP-027-btsnoop_hci.log` (Group N touch gestures) and cross-correlated the outputs with `CAP-027-EVENT-NOTES.md` timestamps:
95+
- **AVRCP Isolation:** verified that physical gestures for `TOUCH-002` (single tap), `TOUCH-003` (double tap), `TOUCH-004` (triple tap), `TOUCH-005` (swipe forward), and `TOUCH-006` (swipe backward) do **not** generate any Pigweed DLCI 0x02 packets. Instead, they ride standard Bluetooth AVRCP on dedicated L2CAP channels.
96+
- **DLCI 0x04 Integration:** verified that press-and-hold gestures (`TOUCH-007`) route directly over DLCI 0x04 using Fast Pair Message Stream ANC Notify commands (`0x13`), completely bypassing the Pigweed envelope.
97+
- **DLCI 0x02 Verification:** confirmed that the active companion app session generates a series of writes confirming fields 1 (OHD status=0), 2 (In-ear detection=1), 3 (Sum to mono=1), 4 (Loudness=1), 11 (Multipoint=1), 15 (Volume EQ=1), 16 (live user EQ floats), 17 (Volume balance=10), and 18 (saved user EQ floats). This provides flawless empirical proof of the protocol registering schema.
98+
99+
---
100+
101+
## 4. Summary for the Maintainer
102+
103+
Our independent, clean-room review validates all core findings and structural mappings proposed in session `0001` with absolute certainty. The evidence-based tracing of both GMS-brokered boundaries and the local RFCOMM/L2CAP paths is complete, mathematically robust, and structurally self-consistent.
104+
105+
### Recommendations on Proposals:
106+
1. **Approve all Phase 4 Promotions:** The promotions of `qhr` fields 11 (Multipoint) and 15 (Volume EQ) to 🟢 FACT are fully justified by clear, self-describing code logs and empirical capture telemetry.
107+
2. **Approve Document Updates:** The proposed updates to `PROTOCOL.md` §6, `REVERSE_ENGINEERING.md` (adding `ijk`/`ijp` and routing classes), and `TODO.md` closures are accurate and ready to be merged.
108+
3. **Incorporate Volume Balance Findings:** We recommend appending our new Volume Balance registers (field 17 = SINT32 value, field 19 = BOOL limit gate) to the proposed `REVERSE_ENGINEERING.md` updates.
109+
110+
The documentation catalog is structurally complete and fully ready to serve as the blueprint for an open-source, Zero-GMS implementation of the Pixel Buds Pro 2.
111+
112+
---
113+
https://github.com/tedsluis/opencontrolpixelbudspro2/blob/main/ai-sessions/0007_CROSSCHECK_RESULT_2026_09_11.md - https://tedsluis.github.io/opencontrolpixelbudspro2/ai-sessions/0007_CROSSCHECK_RESULT_2026_09_11

0 commit comments

Comments
 (0)