verify(micromate): the uint32 chunk offset is confirmed -- 72,560 B in 71 chunks

UM20147's event 055d4a83 downloaded at exactly its promised size over USB,
exercising the carry into params[1] on chunks 64-70.  The uint32 reading was
inference for one commit; it is now evidence, and the 64 KB cap that would have
made this event unfetchable is closed.

Worth noting what the same run prices: 71 chunks x ~0.65 s is roughly 46 SECONDS
for one 72 KB histogram over cellular, against 0.2 s over USB.  That is the
round-trip cost model doing real work -- the bytes are nothing, the commands are
everything.  A unit holding several events this size is a multi-minute call, so
the untested single-request offset_hi = 0x10 streaming mode (which would collapse
a download to one round trip) moves up the list.

Docstrings and the protocol reference downgraded from "inference" to "confirmed"
only where the hardware actually settled it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ru8Lg9HkkYvX9VWWo65SmL
This commit is contained in:
2026-10-01 16:18:30 -04:00
co-authored by Claude Opus 5
parent 0cfec2f098
commit faac59b283
3 changed files with 23 additions and 7 deletions
+11 -3
View File
@@ -1006,9 +1006,17 @@ key there. Writing the offset as a uint32 BE in the same slot is **byte-identica
for every offset below 65,536** — so it changes nothing that was verified against for every offset below 65,536** — so it changes nothing that was verified against
THOR's 74 captured frames — and extends the range to 4 GB. THOR's 74 captured frames — and extends the range to 4 GB.
⚠ **Above 64 KB this is inference.** No capture exercises a carry into ✅ **Confirmed on hardware 2026-10-01.** UM20147's 72,560-byte event
`params[1]`. The field's width is established; the device's handling of a (`055d4a83`) downloaded in **71 chunks** at exactly its promised size — chunks
non-zero high byte is not. 64–70 carry a `0x01` in `params[1]`, and the device served them without
complaint. The field is a uint32; it was inference for one commit.
🔑 **And it prices a large event over cellular.** 71 chunks × ~0.65 s ≈ **46
seconds** for one 72 KB histogram, against 0.2 s over USB. That is the
round-trip cost model doing real work: the bytes are nothing, the commands are
everything. A unit holding several events this size is a multi-minute call, and
the untested single-request `offset_hi = 0x10` streaming mode would collapse it
to one round trip — which moves that two-minute bench test up the list.
⚠ **At offset 1 MiB `params[1]` is `0x10`**, which must be escaped on the wire as ⚠ **At offset 1 MiB `params[1]` is `0x10`**, which must be escaped on the wire as
`10 10`. Unreachable below 64 KB, so the uint32 change is what first makes that `10 10`. Unreachable below 64 KB, so the uint32 change is what first makes that
+6 -3
View File
@@ -182,9 +182,12 @@ def chunk_params(key4: bytes, byte_offset: int) -> bytes:
A uint32 here is **byte-identical for every offset below 65,536**, so it A uint32 here is **byte-identical for every offset below 65,536**, so it
changes nothing that was verified against THOR's frames (the replay test changes nothing that was verified against THOR's frames (the replay test
asserts all 74 of them) and extends the range to 4 GB. Above 64 KB it is asserts all 74 of them) and extends the range to 4 GB.
**inference**: `params[0:4]` is demonstrably one 4-byte field, because chunk 0
puts a 4-byte key in it, but no capture exercises a carry into `params[1]`. ✅ **Confirmed on hardware 2026-10-01.** UM20147's 72,560-byte event
downloaded in **71 chunks** at the exact promised size, which exercises the
carry into `params[1]` on chunks 64–70. It was inference for one commit and
is now evidence.
⚠ This is the **Series III 64 KB page-boundary bug in a new guise** — there, ⚠ This is the **Series III 64 KB page-boundary bug in a new guise** — there,
`parse_strt_end_offset()` discards the key's page byte and the `5A` walk `parse_strt_end_offset()` discards the key's page byte and the `5A` walk
+6 -1
View File
@@ -442,7 +442,12 @@ def test_a_chunk_offset_with_0x10_in_it_is_escaped_on_the_wire():
def test_a_72kb_event_downloads_in_71_chunks(): def test_a_72kb_event_downloads_in_71_chunks():
"""UM20147's event 055d4a83, the one that broke the uint16 assumption.""" """UM20147's event 055d4a83, the one that broke the uint16 assumption.
✅ Confirmed against the real unit 2026-10-01: 71 chunks, exact size, with
chunks 64-70 carrying 0x01 in params[1]. This test pins the arithmetic the
hardware agreed with.
"""
size = 72560 size = 72560
n = 71 n = 71
responses = [] responses = []