EXECUTABLE REFERENCE ADAPTER · PROTOCOL 0.2

Robot to valid stream.
Fifteen minutes.

Keep the native controller. WANTED adds one narrow evidence layer: six event helpers, a hardware-backed Ed25519 signer, a durable sink, and a local verifier. The adapter orders and signs each event; the independent verifier rejects structural drift, broken chains, invalid signatures, and ineligible keys before evidence leaves your infrastructure.

0RUNTIME DEPENDENCIES
6EVENT HELPERS
1DURABLE CHAIN
0PRIVATE KEYS EXPORTED
01 / MINIMUM INTEGRATION

Three pieces.
One ordered truth.

The adapter needs identity, a signing callback, and an accepted-event sink. Sequence and chain state advance only after the sink succeeds.

01Identify

Freeze deployment, environment, robot, and signing-key identifiers in the preregistration.

deploymentId · environmentId · robotId
02Sign

Pass canonical bytes to a TPM, HSM, secure enclave, or equivalent non-exportable key.

sign(bytes) → signature
03Commit

Persist or POST each accepted event, then durably store the returned restart checkpoint.

sink(event) → accepted
02 / COPY, CONNECT, VERIFY

The whole
evidence surface.

The production signer stays outside the adapter and the verifier performs no network requests. Private keys and raw event evidence remain inside infrastructure approved by the robot operator.

QUICKSTART / JAVASCRIPT ESMRUNNABLE
import { WantedClient, createHttpSink } from "./wanted-sdk.mjs";

const wanted = new WantedClient({
  deploymentId: "dep_7f2",
  environmentId: "env_104",
  robotId: "robot_07",
  signingKeyId: "key_prod_07",
  sign: bytes => secureModule.sign(bytes),
  sink: createHttpSink("https://collector.example/v1/events"),
  checkpoint: await durableStore.load()
});

await wanted.intervention(
  "remote_guidance", 43, "task_recovery", {
    actor_role: "operator",
    person_count: 1,
    resolution: "robot_resumed",
    support_session_sha256: "…"
  }
);
await durableStore.save(wanted.checkpoint());
WEB CRYPTO · RFC 8785 · SHA-256SINGLE WRITER
03 / VERIFY BEFORE HANDOFF

Fail locally.
Before the audit does.

Run the independent module against exported JSONL and the frozen public-key manifest. It verifies every signature, chain link, timestamp, key boundary, and payload; then binds each stream’s activation and terminal event to the exposure ledger. Profile 0.2-RC1 separately proves those root commitments were disclosed on schedule to two independent witness organizations before outcome analysis.

CI CHECK / NODE 22+LOCAL ONLY
node wanted-telemetry-verifier.mjs \
  events.jsonl telemetry-key-manifest.json

# stdout: self-digested JSON verification report
# exit 0: every check passed
# exit 1: evidence failed verification
# exit 2: usage, file, or input error

# The same file remains importable JavaScript ESM:
import { verifyTelemetryJsonl } from
  "./wanted-telemetry-verifier.mjs";
NO NETWORK · NO RAW EVENT UPLOAD0.2-TS4 · 0.2-TX1
04 / SIX REQUIRED EVENTS

Small API.
Complete evidence.

Native ROS 2 topics, simulator callbacks, task planners, and operator consoles map into the same six calls.

01lifecyclewanted.lifecycle("activation", { participant_acceptance_ref: "controlled://acceptance/42", activation_record_sha256: "…" })
02statewanted.state("available", { autonomous_service_capable: true })
03requestwanted.request("privacy", { evidence_ref: "local://request/42" })
04actionwanted.action("put mug in dishwasher", { proactive: false })
05interventionwanted.intervention("remote_guidance", 43, "task_recovery", { person_count: 1, resolution: "robot_resumed" })
06incidentwanted.incident("L1", "Brief hallway obstruction")
COMMON MAPPINGSROS 2 node → helper callsIsaac / MuJoCo callbacks → helper callsOperator console → intervention + incidentParticipant UI → request
04 / ROOTS + INDEPENDENT WITNESSES

Prefixes committed.
Keys stay sovereign.

RE1 binds each root to a verified signed telemetry prefix, REB1 reproduces the cross-deployment collection, and 10 REBC1 vectors prove implementation parity before RC1 witnesses establish chronology. Raw events and signing keys stay local.

ROOT + KEY BOUNDARYLOCAL ONLY
events  → verified signed prefix
envelope → prefix + prior-root digest
prepare → canonical receipt bytes
sign    → witness HSM / TPM / KMS
attach  → signature self-verification
verify  → registered key + lifecycle

No private-key flag. No network request.
One receipt still requires full RC1 quorum.
0.2-RE1 · 0.2-RIS1 · ED25519NO UPLOAD
05 / 10,000-HOUR CONTINUITY

Restarts happen.
Evidence must survive.

A benchmark this long cannot depend on process memory. Persist the checkpoint after every accepted event and test crash recovery before human exposure.

ONE WRITER

Only one process may issue the next sequence for a deployment. Fail over with a lease or fencing token.

ACCEPT, THEN ADVANCE

The SDK advances sequence and chain state only after the sink acknowledges the event.

DURABLE CHECKPOINT

Store next_sequence, previous_event_hash, and last_occurred_at before another event can be emitted.

RECONCILE RESTARTS

After a crash, recover the collector’s accepted tail before emitting. Event IDs make retries idempotent.