# 2026-09-19 — Qingtian PAL Development Detailed Record

## 1. Architecture Decision
EAGLE is the authoritative Qingtian PAL development and future runtime host.

Development workflow:
- Home: AORUS -> SSH -> EAGLE
- Outside: VICTUS -> Tailscale -> SSH -> EAGLE

The authoritative PAL source tree and Git repository live on EAGLE.
AORUS and VICTUS are development terminals/clients rather than separate authoritative source hosts.

IEI is shut down and excluded from PAL v0.1 development.

## 2. Foundation Discovery
Discovery completed successfully on EAGLE.

Important decisions:
- PAL repository: /home/foo/qingtian-pal
- development endpoint reserved conceptually around loopback 127.0.0.1:8780
- no real PAL listener during current foundation gates
- PAL Core owns PAL-specific state, device identity, presence, sessions, activity/form selection and event distribution
- PAL Core does not duplicate Qingtian Memory, Home Assistant entity storage or FRO state
- future Qingtian Memory access should be read-only through qingtian-mcp rather than direct database/filesystem access
- future Home Assistant access should use a dedicated adapter and credential, read-only first

## 3. Gate v0.1.1 — Repository Bootstrap
Status: PASS

Repository:
/home/foo/qingtian-pal

Independent Git repository established with server, client, shared schema, documentation, scripts and test structure.

Accepted checkpoint:
7e49e7d13146992b66b23b7cb00f146af8970785

No dependencies installed.
No PAL process/listener/database/secrets.
Production unchanged.

## 4. Gate v0.1.2 — Python Toolchain
Status: PASS

Isolated virtual environment:
/home/foo/qingtian-pal/.venv

Python:
3.12.3

Key package versions:
- FastAPI 0.141.1
- MCP 2.2.0
- Pydantic 2.13.5
- Uvicorn 0.53.0
- HTTPX 0.28.1
- Pytest 8.4.2

Dependency freeze:
/home/foo/qingtian-pal/server/requirements.freeze.txt

Freeze SHA-256:
e371018f288840da37dda8812f018b8c96e2e03436a8f9c27d7df37a8001ac46

Accepted checkpoint:
08487c3aee3c703f726fd9721491c6b1fcd5b884

No listener/database/secrets/production changes.

## 5. Gate v0.1.3 — PAL Core Skeleton
Status: PASS

Tests:
18 passed

Accepted checkpoint:
1352174e77a970a84f06a500b3137ca0dd48bb78

Implemented foundation:
- Presence: online / away / offline
- Activity: idle / listening / thinking / working / speaking / sleeping / error
- Form: sun / human
- authoritative state coordinator
- deterministic state transitions
- monotonic revision behavior
- side-effect-free FastAPI app factory
- /health
- /v1/state
- /v1/events WebSocket contract
- in-process testing only

No real network listener.
No persistent database.
No production integration.

## 6. Gate v0.1.4 — Device Registration, Heartbeat & Session Lifecycle
Status: PASS

Tests:
31 passed / 0 failed

Accepted checkpoint:
b842c764823309a3da417df552cc1a5cb9dca765

Implemented:
- in-memory device registry
- server-issued immutable device UUID
- device labels/classes/capabilities
- duplicate labels allowed; label is not identity
- device registration
- device inventory
- heartbeat
- server-derived presence
- session creation
- session closure
- deterministic active device/session policy
- lifecycle events

Presence policy foundation:
- online: recent heartbeat
- away: >=60 seconds
- offline: >=300 seconds

### v0.1.4 Production Safety Check
Codex did not have Docker socket permission and correctly stopped rather than escalating privileges.

Decision:
- do NOT add foo to docker group
- do NOT change Docker socket permissions
- use bounded human-assisted read-only sudo Docker telemetry

Pre-flight authoritative snapshot:
homeassistant:
ID=1be6df0baed9b82c93e85fa9c9e64b391b15a4b37517000981f47db7565db437
STATUS=running
STARTED_AT=2026-09-19T14:09:18.27641325Z
RESTART_COUNT=0

remoteoffice:
ID=6067acac87488a0149f35c7044cf6b13e80428dbd7b11dbc7b8bca9d2e7946ad
STATUS=running
STARTED_AT=2026-09-19T08:34:58.86869673Z
RESTART_COUNT=0

qingtian-mcp:
ID=7f9bedde5df1154c89c8d0b3073d4aea43c41ee7cfb298660afcbeaaf9dcc1ed
STATUS=running
STARTED_AT=2026-09-19T05:09:43.312876553Z
RESTART_COUNT=0

Post-flight snapshot was identical.

Conclusion:
Production services were unchanged.

No Docker permissions/group changes were made.

## 7. Gate v0.1.5 — Device Authentication & Enrollment Foundation
Status: PASS

Final results:
- Enrollment authority: PASS
- Device credential generation: PASS
- Raw credential retention: NONE
- Credential verification: PASS
- Device authentication: PASS
- Device authorization: PASS
- Credential revocation: PASS
- Session revocation: PASS
- Tests: 39 passed / 0 failed
- Persistent credentials created: NO
- Real production credentials created: NO
- Real network listener started: NO
- New dependencies: NO
- Production integration accessed: NO
- Secrets written to disk: NO
- Production modified: NO

Accepted Git checkpoint:
0f7781461627999013f27143f140ab8cc66ec3f8

Worktree:
CLEAN

Authentication foundation now establishes:
credential -> credential record -> immutable device UUID

Human-readable labels such as AORUS, VICTUS and S24 are not authentication identity.

The foundation includes one-time enrollment semantics, server-generated credentials, verification without retaining raw credentials, authorization boundaries and revocation behavior.

## 8. Current PAL Development Position
At the end of today, PAL has progressed through:

Environment/Foundation
-> Core State
-> Device Registry
-> Heartbeat/Presence
-> Sessions
-> Enrollment
-> Authentication
-> Authorization
-> Revocation

PAL remains deliberately isolated from real production exposure.

Not yet implemented:
- persistent PAL database
- persistent production credentials
- real PAL network service
- systemd/Docker PAL deployment
- real AORUS/VICTUS/S24 enrollment
- Home Assistant control
- Qingtian Memory integration
- voice/wake phrase
- LLM runtime
- final desktop Pet/avatar
- mobile client

## 9. Tomorrow's Starting Point
NEXT BOUNDED GATE:

Gate v0.1.6A — Persistent PAL State & Credential Store Design

Important:
This should begin as DESIGN ONLY.

Before any database is created, review:
1. Which PAL state must survive restart.
2. Which state is ephemeral and should never be persisted.
3. Credential verification material storage.
4. Raw-secret prohibition.
5. SQLite suitability and schema boundaries.
6. Database location.
7. ownership and file permissions.
8. transactions/atomicity.
9. corruption and recovery strategy.
10. schema versioning/migrations.
11. backup policy.
12. revocation persistence.
13. device/session persistence rules.
14. production deployment implications.

Do not automatically create the database during the design gate.

## 10. End-of-Day Checkpoint
Official stop point:
Gate v0.1.5 PASS

Repository:
/home/foo/qingtian-pal

Branch:
main

HEAD:
0f7781461627999013f27143f140ab8cc66ec3f8

Tests:
39 passed / 0 failed

Worktree:
CLEAN

Production:
UNCHANGED

Tomorrow:
Start Gate v0.1.6A persistence design and review only.
