diff --git a/REQUIREMENTS.md b/REQUIREMENTS.md index dbda913..e8663fb 100644 --- a/REQUIREMENTS.md +++ b/REQUIREMENTS.md @@ -277,6 +277,29 @@ the daily unlock is needed on this path are both answered: it is, and this is th > key it never agreed, or a firmware path nobody meant to reach, is unknown. It is > recoverable: the pod came back on its own by the next session. > +> **Settled with one write, 2026-08-27.** `--variant play-rideon` on a clean session: key +> offer at +5.31 s, our `RideOn 01 02` + 64-byte key sent, the pod's `RideOn 02 03` + 64 +> zero bytes back at +5.40 s, and the stream all zeros from +5.49 s. That single frame +> causes both. The zero frames are **7 bytes** — the exact length of a button frame — so the +> pod is emitting correctly-shaped frames with the contents blanked, which is a refusal +> mode rather than a crash. +> +> **The gate is a credential, not a format.** The v2 understands the handshake, answers in +> the right shape, and returns a zeroed key. No framing we can construct changes that: we +> tried the protobuf envelope four ways and the Play format verbatim, and the device +> declined all five in two distinct, deliberate ways. What the Zwift app presents that we +> cannot — an account token, a signed blob, or a correctly *computed* field 3 — is the +> thing being checked, and it cannot be inferred from the device half of the conversation. +> +> **So this line is closed until someone captures the app's side.** One HCI snoop of one +> real unlock would settle it; nothing short of that will. Until then the workarounds stand: +> the `+` pod, which reportedly never needed the blessing, or re-linking the `−` pod inside +> its ~50 s window. + +> **Do not send `play-rideon` casually.** It reliably blanks the pod's output stream and +> costs a recovery wait. It is kept in the probe because reproducing a finding matters, not +> because it is safe to leave running. + > **Attribution is not yet sound.** All five variants went out inside six seconds and every > reply arrived in one burst at +11.37 s, so which write triggered the zeros is not > established. `probe unlock --variant ` sends exactly one per connection, which is