Skip to content

[Research] LAB-004: fresh protected-oracle ceremony with closed artifact roles #89

Description

@jacklv-coder

Goal

Evaluate one fresh, project-owned DemoLab 1.0 (4) tuple and produce a reproducible Go or No-Go answer for the protected-to-plaintext oracle prerequisite that blocks DEVICE-001.

This is a new experiment, not a retry or reinterpretation of the closed DemoLab 1.0 (3) LAB-002 evidence. It must use the LAB-003 three-role layout and must not modify, consume, or publish retained LAB-002 private artifacts.

Activation boundary

Creating this Issue and its documentation-only activation PR authorizes only design, public documentation, and device-free synthetic validation. It does not authorize signing, App Store Connect access, TestFlight upload, installation, launch, authorization-envelope creation or consumption, device queries, device observation, a backend implementation, or IPA decryption.

Every later external or device action requires its preceding reviewed checkpoint to be merged and fresh explicit operator authorization immediately before that action.

Exact public scope

  • first-party DemoLab marketing version 1.0, fresh build 4
  • main app, DemoFramework, and DemoShareExtension, including every frozen device slice
  • one later-selected owned iPhone and exact sanitized iOS/model tuple
  • one internal-TestFlight upload only; no external testers, public link, Beta App Review, or App Store submission
  • fixed predeclared __TEXT,__oprobe ranges and independent pre-upload plaintext digests
  • LAB-003 experiments, external-inputs, and diagnostics roles for every future Host preflight and closure

No third-party or proprietary app, user IPA, executable byte export, stable device identifier, credential, receipt content, private path, or raw private log may enter GitHub or CI.

Ordered checkpoints

  1. Activation and successor design — add LAB-004 to the bilingual execution ledger and review the closed experiment contract.
  2. Device-free integration — adapt the existing guarded Host/operator flow to require LAB-003 role preflight before authorization creation/consumption; add synthetic regressions; keep every external/device lane closed.
  3. Exact signed candidate and frozen oracle — after separate authorization, create exactly one DemoLab 1.0 (4) candidate from a clean reviewed commit and freeze its complete build/oracle tuple; no upload or device action.
  4. Single internal upload and installation enrollment — after separate authorization, upload that exact candidate once, reconcile Apple processing, install independently through TestFlight, and close installed lineage using a fresh one-shot envelope and external Receipt role.
  5. Two clean observations — after separate authorization before each run, collect two distinct signed exports through the external-input role and close each Host binding without reclassifying inventory or ranges.
  6. Sanitized result — publish only non-secret Go/No-Go evidence, update the bilingual ledger and technical/user status, and close this Issue.

A checkpoint may begin only after the previous checkpoint PR is merged. A failed or indeterminate external action is retained and reconciled; it is never silently retried.

Go criteria

A Go requires all of the following for the exact frozen tuple:

  • every expected role and slice is independently bound to the installed build;
  • every fixed range is covered by installed encryption metadata and its installed on-disk digest differs from the frozen plaintext digest;
  • the same predeclared mapped range equals the independently frozen plaintext digest;
  • two cleared executions bind to the same physical device, installation, hardware model, and exact iOS version/build and yield identical normalized evidence;
  • every LAB-003 path, identity, inventory, size, ownership, permission, alias, retention, and redaction check passes before authorization creation/consumption and at closure; and
  • no private value or executable byte is exposed outside the owner-only experiment roots.

Any missing, extra, changed, unobservable, partially verified, expired, replayed, or ambiguously placed item is a No-Go.

Exit

Close with one of:

  • Go: the protected-oracle prerequisite is established only for the exact first-party DemoLab 1.0 (4)/device tuple, allowing a separate DEVICE-001 activation proposal; or
  • No-Go: record the failed assumption and keep DEVICE-001 blocked.

Even a Go does not establish a device backend, general IPA decryption, a user-facing oprobe decrypt workflow, or a compatibility-matrix claim.

Metadata

Metadata

Assignees

No one assigned

    Labels

    compatibilityVerified or reported host/device/backend compatibilitydocumentationImprovements or additions to documentation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions