pollen-robotics/microduck
64.1
Adequate · 29 September 2026
104.5k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a comprehensive software stack for a small, quadruped robot named 'Microduck', providing the core infrastructure for its movement, perception, and interaction. It manages low-level hardware control through a 50 Hz loop for walking and balancing, while handling sensor fusion from IMUs, ToF depth sensors, and cameras to enable features like fall prediction and object detection. The platform also supports high-level capabilities such as multi-robot audio synchronization, gamepad remote control, and over-the-air updates with automatic health-based rollback.
Features
Add systemd unit and user configuration for the BLE transport daemon (btd)
Introduces the systemd service file and system user configuration for btd, the new BLE front-door daemon that exposes the robot API over Bluetooth. The service runs as an unprivileged user (btd) with strict security hardening (NoNewPrivileges, ProtectSystem=strict, restricted address families) to safely parse incoming radio bytes, while ensuring it starts independently of robotd or updaterd to support recovery scenarios. It relies on bluetoothd for D-Bus communication and uses a retry loop to handle late hardware initialization on specific boards like the Radxa.
btd/systemd · high confidence
Duck chorale: multi-duck singing with score-based synchronization and MIDI import
The sounds module now supports a 'chorale' mode where multiple ducks sing together in harmony. This introduces a text-based score format (.duckscore) for defining musical pieces, a MIDI importer to convert standard notation files into duck arrangements, and a BLE-based synchronization system that uses a 'conductor' beacon to keep the ensemble in time without requiring a shared clock. The system handles voice casting (Bass, Tenor, Alto, Soprano) based on each duck's unique personality and pitch range, allowing for realistic multi-voice performances.
sounds · high confidence
Enable hardware I2C and NPU for audio and AI capabilities
The deployment now includes device-tree overlays to switch the audio codec (TLV320AIC3104) from bit-banged GPIO to the hardware I2C3 bus, which reduces CPU overhead and supports higher-speed peripherals like the ToF sensor. Additionally, an overlay is provided to enable the RK3566 NPU, which was previously disabled in the base device tree, allowing the robot to run NPU-accelerated models such as the duck detector.
deploy · high confidence
Extracted BLE wire contract into a shared library
The \duck-ble\ crate now exposes the platform-independent BLE wire contract as a standalone library, allowing external clients (such as the mobile app or \duckctl\) to implement the protocol without depending on the Linux-specific \btd\ daemon. This library defines the GATT service and RPC UUIDs, the NDJSON framing logic for chunking and reassembling messages over BLE notifications, and the advertisement format for broadcasting the robot's IPv4 address, ensuring that any client implementation agrees on these critical details.
duck-ble · high confidence
Introduce duck-control crate with hardware abstraction and fall prediction
The \duck-control\ crate provides the core robot control logic, including a \DynamixelIo\ bus implementation that uses fast sync reads to efficiently fetch IMU and servo data, a \FallPredictor\ that anticipates falls using IMU gravity derivatives to trigger limp-fall mode early, and an \Observation\ builder that constructs the 61-D state vector for ONNX policies. It also includes a \policy-rehearsal\ example for offline inference benchmarking and a \FakeIo\ implementation for testing without hardware.
duck-control · high confidence
Introduce pet-detect: on-device audio classifier for head-scratch detection
Adds a new pet-detect crate that enables the robot to detect when its head is being scratched using an onboard microphone. The crate includes a streaming PettingDetector library with hysteresis, a live binary (pet-detect) that reads raw PCM from stdin and outputs petting probability and state, and a feature-extraction binary (pet-features) to ensure training and inference use identical log-mel processing. A background worker (worker.rs) manages the arecord subprocess, implements an ambient sound sentry to gate inference and detect noise/voice events, and emits PettingEvent::Start/End. The system ships with a \~20 KB ONNX CNN model and a Python training script (training/train.py) that uses the Rust feature extractor to maintain train/infer parity.
pet-detect · high confidence
Introduce systemd service for the gamepad intent client
Users can now run the gamepad daemon (padd) as a persistent, unprivileged system service that starts at boot and automatically handles gamepad pairing and intent submission. The service runs under a dedicated 'padd' user with minimal group permissions (input, robot) and exposes a raw input socket for monitoring, replacing the previous manual SSH-based setup.
padd/systemd · high confidence
Introduce the microduck policy playground Space
Adds a new Hugging Face Space that lets users sign in with their Hugging Face account, select their robot duck, and install or run policy tricks. The Space is deployed as a Docker container that serves a self-contained HTML page, injecting OAuth credentials at runtime to enable secure sign-in without exposing secrets.
spaces/policy-playground · high confidence
Introduces duck-ether, a configurable simulated radio for testing duck chorale behavior
Adds a new \duck-ether\ tool that replaces the previous \btd\ radio implementation to simulate wireless beacon propagation between simulated ducks. This tool allows testers to configure radio range, simulate discovery delays and packet loss, and rotate duck addresses to reproduce real-world hardware conditions like split-brain scenarios and address changes, ensuring the chorale election logic is tested against imperfect network conditions rather than ideal ones.
duck-ether · high confidence
New BLE transport daemon (btd) for robot control
Introduces the \btd\ daemon, which serves as the Bluetooth Low Energy front door to the robot's API. It exposes a GATT service that transports JSON-RPC requests and responses, allowing a phone or laptop to control the robot, trigger updates, and configure Wi-Fi. The implementation includes a chorale beacon for multi-robot synchronization, a just-works pairing flow with a PIN-based authentication check, and specific tuning for advertising intervals and notification backpressure to ensure reliable communication on the target hardware.
btd/src · high confidence
New development and simulation tooling for local robot iteration
Added scripts to streamline local development and simulation workflows. \dev-push.sh\ and \dev-build.Dockerfile\ enable building and deploying daemon updates directly from a laptop to a board, supporting both cross-compilation and native Docker-based builds to simplify the development loop. \bake-duck-mesh.py\ introduces a tool to optimize the robot's 3D visual model for terminal-based monitoring. Additionally, \migrate-network.sh\ automates the transition from netplan to NetworkManager for improved Wi-Fi management, and \pad-link-test.sh\ provides diagnostics to measure Bluetooth link reliability and latency between the gamepad and the robot.
scripts · high confidence
New diagnostic tool and CLI client for robot management
Introduces \duckctl\, a new command-line interface for managing robots via Bluetooth, and \advwatch\, a diagnostic example for monitoring advertisement reliability. \duckctl\ allows users to scan for robots, view status, manage Wi-Fi connections, execute remote commands (such as \robot.health\), and view logs. The \advwatch\ tool continuously monitors Bluetooth advertisement arrival patterns to help distinguish between robot advertising issues, interference, and client-side problems.
duckctl · high confidence
New duck-detect library and benchmarking tool for NPU-based detection
The \duck-detect\ crate now provides the core logic for detecting other Microducks using a quantized INT8 model on Rockchip NPUs, including a letterbox preprocessor, an ONNX Runtime fallback for CPU-only boards, and a Rust binding to the Rockchip NPU runtime (\librknnrt.so\) via dynamic loading. A new \duck-bench\ binary allows users to validate detector functionality, measure inference latency and CPU cost, and verify detection accuracy against a directory of JPEG frames without interfering with the live camera daemon.
duck-detect · high confidence
New head ToF sensor daemon with integrated head IMU support
The \tofd\ daemon is introduced to manage the head Time-of-Flight (ToF) sensor (VL53L5CX or VL53L8CX) and the head IMU (BMI088). This change adds a dedicated Linux-only driver that vendors ST's Ultra Lite Drivers, automatically detecting the sensor generation at runtime and publishing 8x8 depth frames. Additionally, the daemon now reads the BMI088 IMU, fusing the data to provide orientation, and exposes both streams via a Unix socket. The IMU functionality is controlled by a new \\[head\_imu\]\ configuration section in \robotd.toml\, which defaults to disabled to ensure backward compatibility and safe operation on boards without the sensor fitted.
tof · high confidence
New interactive configuration editor for robotd.toml
The \robotd-params\ crate now includes a lossless editor (\edit.rs\) that allows users to modify \robotd.toml\ via \robotctl configure\ without losing comments, ordering, or unknown keys. This tool validates changes against the schema before writing, supports migrating renamed sections (such as \\[imu\_head\]\ to \\[pad\_imu\_head\_control\]\ and \\[detect\]\ to \\[duck\_detector\]\), and exposes new configurable options including pad button bindings (\pad\ section), IMU-based head control (\pad\_imu\_head\_control\), and fast sync read settings (\bus.fast\_sync\_read\).
robotd-params · high confidence
New kinematics module with MJCF-driven forward kinematics and ToF sensor processing
The kinematics subsystem has been rewritten to parse the robot's MJCF model (robot\_walk.xml) at startup, compiling joint names and site chains for efficient, allocation-free forward kinematics queries in the control loop. This new module introduces a robust hand-tracking algorithm for the ToF sensor that uses configurable status bytes and a hold timer to stabilize distance readings for the Theremin instrument, replacing previous unstable background-subtraction approaches. It also provides head-chain forward kinematics with proper frame transformations (MJCF to cv2 and sensor frames), gaze inverse kinematics for aiming the camera, and ToF reprojection logic that filters floor returns and near-field noise using the robot's posture and IMU data.
kinematics · high confidence
New pad-imu crate for gamepad IMU orientation tracking
Added a new \pad-imu\ library that processes raw inertial measurement unit (IMU) data from gamepads (such as Switch Pro Controller clones) into stable orientation quaternions. The implementation uses a complementary filter to integrate gyroscopic data while correcting pitch and roll using accelerometer gravity readings, and includes automatic gyro bias calibration during periods of stillness to prevent yaw drift. This module provides the core attitude computation used by \padd\ to pose robot heads and \robotctl monitor\ to visualize pad tilting.
pad-imu · high confidence
New padd daemon for gamepad-driven robot control and raw input monitoring
A new \padd\ process has been introduced to handle gamepad input, acting as an unprivileged intent client that sends drive and skill commands to \robotd\ via a socket. This daemon allows users to drive the robot, toggle head/body-pose modes, and trigger one-shot skills (configurable via \robotd.toml\) using standard gamepad buttons. It also exposes a read-only socket (\pad.input\) that streams the raw, unfiltered evdev event stream from the gamepad, enabling tools like \robotctl monitor\ to diagnose connection issues by observing the actual hardware events rather than just the smoothed intents sent to the robot. The daemon supports pairing via \robotctl\, handles pad dropouts gracefully, and includes specific logic for roller-mode robots and IMU-based head control on compatible pads.
padd/src · high confidence
New robotctl monitor blocks for camera, 3D robot view, and odometry map
The \robotctl monitor\ command now includes several new visual blocks: a live camera feed (toggled with \c\) that fetches and renders frames from \mediad\ on demand to minimize overhead; a 3D view of the robot's kinematic model (toggled with \v\) rendered in terminal cells using a baked mesh; and a top-down odometry path map (toggled with \m\) that tracks the robot's movement history. These additions enhance the monitoring experience by providing visual context for the robot's perception, pose, and location, complementing the existing joint and health data.
robotctl · high confidence
New test-support fixtures for minting signed releases and systemd environments
The test-support module now includes dedicated examples to generate test fixtures: \fake-release\ creates signed release trees without systemd units for driving the updater engine logic, while \systemd-fixture\ generates releases containing real systemd units (including stand-ins for robotd and btd) to verify restart and recovery machinery. These tools allow manual and automated tests to exercise end-to-end update scenarios, including rollback on bad hooks, broken units, and user-account provisioning, using the same signing and packaging logic as the production engine.
test-support · high confidence
Remote console sign-in via Hugging Face Space
The mediad webclient now supports remote access through a Hugging Face Space, enabling users to sign in with Hugging Face OAuth to drive a robot outside their local network. This change introduces a Docker-based Space deployment (including a Dockerfile, entrypoint script, and README) that injects OAuth credentials into the console page, allowing the browser to authenticate with the rendezvous service. The console page itself has been updated with a proper HTML structure to support this injection, fixes for alert visibility and layout wrapping, and CSS for rotating the video feed to match the camera's physical orientation.
mediad/webclient · high confidence
Robotd daemon now implements full 50 Hz control loop, health monitoring, and audio features
The robotd daemon has moved from a skeleton health-checker to a fully functional control system. It now runs a 50 Hz control loop that processes sensor data, executes ONNX policies for walking and balancing, and manages one-shot skills like ground-picking and sitting. Health reporting has been upgraded to verify the loop meets its timing deadlines, enabling safe auto-rollback during updates. The daemon also introduces new audio capabilities, including a ToF-based theremin that converts hand distance into pitch, a multi-robot 'chorale' for synchronized singing, and a sound system for voice and effects. Additionally, it now monitors board temperature and CPU throttling to provide comprehensive hardware health status.
robotd/src · high confidence
configd introduces dedicated services for robot identity, gamepad pairing, and system logging
The \configd\ daemon now manages the robot's unique identity by deriving a stable default name from the SoC serial number, handles gamepad pairing via BlueZ with transport-specific ordering for LE and BR/EDR devices, and provides a secure interface for reading daemon logs via \journalctl\. It also manages WiFi configuration through NetworkManager without storing credentials, ensuring these critical configuration tasks remain available even when the main robot daemon is offline.
configd · high confidence
mediad: new camera geometry, auto-exposure, duck detection, and local frame endpoint
The mediad daemon now publishes camera intrinsics (focal length, principal point, and distortion) so that consumers can map pixels to directions for SLAM or visual odometry, with geometry derived from the sensor's 62° horizontal field of view and scaled to the delivered frame resolution. It implements software-based auto-exposure that samples luma twice a second and adjusts shutter, analogue gain, and digital gain to maintain a target brightness, compensating for the board's 3A engine which only converges once at stream start. A new duck detection module runs inference on raw frames at 2 Hz on a dedicated thread to avoid blocking the WebRTC signalling path, supporting both NPU (.rknn) and CPU (.onnx) backends. Additionally, a local Unix socket endpoint (media.frame) allows on-robot processes to request raw camera frames on demand without copying pixels through the WebRTC control channel.
mediad/src · high confidence
updaterd: new account, policy, and safety subsystems with improved update reliability
The updater daemon now includes several new capabilities and reliability improvements. It supports Hugging Face account integration for remote access, allowing the robot to sign in and be reachable from outside the LAN. A configurable policy library enables fetching and managing policy sets from the Hub without requiring a full daemon release. To prevent update failures caused by orphaned systemd units, the updater now checks for and refuses releases that would leave installed units with missing executables. Additionally, the updater verifies that scheduled restarts actually occurred and restarts any stale units on startup, and it handles transient 'Text file busy' errors during process spawning to prevent intermittent update failures.
updater/src · high confidence
Removals
Removal of robot-proto IPC contract definitions
The \robot-proto\ crate, which previously defined the JSON-RPC 2.0 wire format and API contracts (including methods like \update.apply\ and \robot.health\) for communication between \robotd\ and \updaterd\, has been removed. This eliminates the shared protocol definitions and associated error codes that clients and services relied on for update and health status interactions.
robot-proto · high confidence
Removal of updater playground example
The \updater/examples/playground.rs\ file has been removed. This example previously allowed users to drive the update engine locally without a daemon for hands-on testing of initialization, publishing, and application workflows. Its removal indicates a shift away from this specific local testing mechanism, likely in favor of the board tests that exercise the shipped binaries directly.
updater/examples · high confidence
Behavioural changes
Automated boot recovery and daemon identity publishing
The system now includes a new boot-check mechanism that automatically verifies whether the newly booted release is healthy; if the release fails to start within 180 seconds, the system falls back to the golden release via a new \robot-boot-check\ service and timer. Additionally, the \updaterd\ service now publishes its running release identity to \/run/updaterd/identity.json\, enabling health checks to verify which version is active, and its restart logic has been updated to use a systemd transient unit for post-update restarts rather than relying on the previous configuration.
updater/systemd · high confidence
Automated installation of system units and hardware dependencies via update hooks
The update process now automatically installs systemd units, GStreamer plugins, the RKAIQ camera engine, and the NPU runtime during updates, ensuring that new services and hardware capabilities are enabled without manual intervention. A new postinstall hook copies service files and enables them, while a preinstall hook verifies and installs required dependencies like ONNX Runtime and GStreamer before the update is applied, preventing failures caused by missing components on previously provisioned boards.
hooks · high confidence
Centralized camera frame rotation and conversion
The \uyvy\ crate now provides a unified library for handling raw camera frames, performing rotation and color-space conversion in a single pass to optimize performance. This change consolidates logic previously scattered across consumers like \duck-detect\ and \mediad\, ensuring consistent upright orientation for all users. It introduces efficient sampling algorithms that rotate the image while downsizing, avoiding the significant CPU overhead and thermal throttling caused by previous pipeline-based rotation methods.
uyvy · high confidence
Contact odometry now uses mesh-sampled anchor points for improved accuracy
The odometry module has been rewritten to derive foot contact points directly from the robot's MJCF mesh rather than using hand-transcribed bounding boxes. This change introduces a new \anchors\ module defining three anchor sets: \V15\ (legacy bounding box), \ALPHA4\ (four sole corners), and \ALPHA16\ (a 4x4 grid over the sole). The default production estimator (\Odometry::alpha\) now uses \ALPHA16\, which reduces drift to 9 mm over a 3.2 m walk compared to 17 mm for the legacy \V15\ set, while also correcting height estimation errors. The implementation optimizes performance by evaluating the kinematic chain once per tick instead of per corner.
odometry · high confidence
New control-only transport for Space-to-robot communication
Spaces can now communicate with robots using a lightweight HTTP-based protocol (JSON-RPC over the rendezvous relay) instead of relying on WebRTC datachannels. This change introduces \spaces/shared/control.py\ for JSON-RPC handling, \spaces/shared/rendezvous.py\ for robot status and listing, and \spaces/shared/wire.py\ for the control-only session management. This transport is more reliable in restricted network environments (e.g., data centers) as it avoids WebRTC ICE/SDP negotiation, though it does not support video streaming. It also includes improved error handling for rate limits and authentication, and ensures the client identifies itself properly to avoid being blocked by edge proxies.
spaces/shared · high confidence
Protocol version bump to v26 with new robot capabilities
The IPC protocol version has been bumped to v26, introducing several new robot control methods including \robot.look\ for gaze aiming, \robot.skills\ for managing skill slots, and \robot.setSkill\/\robot.removeSkill\ for adding or removing skills via API. The update also adds \robot.rebootMotors\ for servo rebooting, \robot.sitting\ and \robot.homed\ status publications, and exposes camera intrinsics through \robot.model\. Additionally, the \update.show\ method is now available to retrieve update transcripts, and the protocol now strictly refuses unknown parameters with \INVALID\_PARAMS\ errors instead of silently ignoring them.
duck-ipc-proto · high confidence
Release tooling: stable promotion decoupling, zstd optimization, and preinstall hook automation
The release packaging and promotion workflow has been updated to improve reliability and CI performance. The \promote\ command now requires a \--stable-tag\ argument, ensuring that stable releases host their own artifact copies rather than pointing to staging tags, which prevents broken links if staging releases are deleted. The \package\ command now accepts a \--zstd-level\ argument (defaulting to 19) to allow lower compression for throwaway CI artifacts, significantly reducing build times. Additionally, the packaging process now automatically generates and includes a \hooks/preinstall\ script to assert board prerequisites, removing the need for manual inclusion and ensuring this check is always present in every release.
xtask/src · high confidence
Robotd daemon now publishes runtime identity and adjusts logging guidance
The robotd systemd unit now creates a runtime directory at /run/robotd to publish an identity file (identity.json), which is read by robotctl health and the updater startup check. The unit also clarifies that configuration parameters are loaded from the default /etc/robot/robotd.toml path (omitting an explicit --params flag to keep the config optional) and updates the logging rationale to explain why per-tick debug logs are avoided at 50 Hz to prevent log eviction under journald's size cap.
robotd/systemd · high confidence
Updater adds staging channel support and improves GitHub asset retrieval
The updater now supports a dedicated staging channel for release candidates via the \--staging\ flag, allowing users to install pre-release builds from GitHub. It also enables installing specific branches by name using \--ref\, which is supported by both the GitHub and local directory sources. To fix issues with private repositories and improve reliability, the GitHub source now fetches release assets via the API using the \application/octet-stream\ header instead of browser download URLs, and includes a fallback mechanism to resolve empty asset lists. Additionally, error messages for network failures and 404s have been enhanced to provide clearer diagnostics, such as suggesting the use of a token for private repos.
updater/src/source · high confidence
Vision demo now receives robot frames via outbound WebSocket
The vision-demo Space has been redesigned to receive camera frames directly from the robot via an outbound WebSocket connection, replacing the previous WebRTC pull model. This change eliminates the need for a media relay, allowing the Space to scale more efficiently and bypass NAT issues that previously prevented connections from home networks. The Space now hosts a FastAPI server with a custom \/frames\ WebSocket route and Gradio UI, processing incoming H.264 or JPEG streams locally on Hugging Face hardware. Additionally, a new 'hello duck' Space was added as a minimal test environment to validate the Docker setup, WebSocket routing, and Gradio integration without OAuth complexity.
spaces/vision-demo · high confidence
mediad is now a managed systemd service with automatic startup
The mediad daemon is now installed as a systemd unit (mediad.service) with an \[Install\] section, meaning it is automatically enabled and started on boot and during updates without manual intervention. The service runs under a dedicated unprivileged 'mediad' user, granted access to hardware devices (VPU, NPU, video nodes) and internal sockets via supplementary groups (video, render, robot). It includes hardening measures, automatic restarts on failure, and relies on configuration in /etc/robot/robotd.toml for video settings rather than command-line flags.
mediad/systemd · high confidence
Test coverage
Added integration tests for release packaging, boot recovery, and sideloading paths; Added integration tests for robotd startup locking and health-gate behavior; Refactored updater test infrastructure and added coverage for degraded and starting robot states.
Dependencies
Workspace restructure and dependency updates for new robot services
The workspace has been restructured to include new crates for robot control, kinematics, odometry, and configuration, alongside the existing daemons. This change introduces several key dependencies: \btleplug\ 0.13 for the \duckctl\ client to prevent process aborts on macOS, \ort\ 2.0.0-rc.11 for ONNX Runtime support in control and detection, \bluer\ 0.17.4 for Linux Bluetooth transport, and \zbus\ 5 for Linux configuration services. It also adds \gstreamer\ 0.24 for media streaming, \axum\ 0.8.9 for the mediad console, and \reqwest\ 0.13.4 for relay communication. The \robot-proto\ crate was renamed to \duck-ipc-proto\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 61 → 64 (+3.1)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 80 → 80 (-0.0)
- Architecture 67 → 70 (+3.8)
- Maturity 70 → 68 (-2.2)
- Readiness 56 → 57 (+1.5)
- Security 60 → 70 (+10.6)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 68 → 68 (+0.0)
- Performance 100 (new)
Resolved (29)
- Documentation: no architecture or design documentation (README.md)
- Documentation: written for insiders (docs/project/tof-on-demand.md)
- Documentation: written for insiders (docs/project/update-over-ble.md)
- Documentation: written for insiders (docs/robot/install-by-hand.md)
- Documentation: written for insiders (docs/robot/pair-a-gamepad.md)
- Duplicated block (18 lines × 2) (padd/src/tap.rs)
- Duplicated block (21 lines × 2) (duck-detect/src/lib.rs)
- Duplicated block (5 lines × 2) (padd/src/tap.rs)
- Edited copy of a member (17 corresponding lines) (pad-imu/src/lib.rs)
- Engine::recover_on_start (cyclomatic 16) (updater/src/engine.rs)
- FileTooLong: policy-shop/app.py (spaces/policy-shop/app.py)
- Hotspot: duck-ether/src/main.rs (duck-ether/src/main.rs)
- Hotspot: mediad/src/stream.rs (mediad/src/stream.rs)
- Hotspot: robotctl/src/show.rs (robotctl/src/show.rs)
- Hotspot: robotd-params/src/edit.rs (robotd-params/src/edit.rs)
- Link._open (cognitive 30) (spaces/policy-shop/app.py)
- Link._open (cyclomatic 18) (spaces/policy-shop/app.py)
- Link.describe (cognitive 16) (spaces/policy-shop/app.py)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 9 more
New (67)
- Config::validate (cyclomatic 16) (updater/src/config.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: no project overview (README.md)
- Duplicate method signature with different parameter names (one uses _lines/_boot, the other uses lines/boot). This suggests an accidental overload or copy-paste error in the API definition.
- Duplicated block (11 lines × 2) (spaces/shared/control.py)
- Duplicated block (11–16 lines × 2) (duckctl/src/main.rs)
- Duplicated block (12 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (14 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (14 lines × 2) (spaces/shared/wire.py)
- Duplicated block (18 lines × 3) (mediad/src/frame.rs)
- Duplicated block (19 lines × 2) (spaces/shared/wire.py)
- Duplicated block (21 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (21 lines × 2) (uyvy/src/lib.rs)
- Duplicated block (24 lines × 2) (spaces/shared/wire.py)
- Duplicated block (32 lines × 2) (spaces/shared/control.py)
- Duplicated block (34 lines × 2) (spaces/shared/wire.py)
- Duplicated block (38 lines × 2) (spaces/shared/control.py)
- Duplicated block (38 lines × 2) (spaces/shared/wire.py)
- Duplicated block (39 lines × 2) (spaces/shared/wire.py)
- Duplicated block (42 lines × 2) (spaces/shared/wire.py)
- …and 47 more
Changes since last survey
- 189 commits — 189 feature/other, 0 fixes
By area
- (repo) — 79 commits
- docs/design — 17 commits
- mediad/src — 12 commits
- (root) — 10 commits
- spaces/policy-playground — 9 commits
- btd/src — 8 commits
- updater/src — 8 commits
- spaces/policy-playground-next — 7 commits
- scripts/duck-sim — 6 commits
- duck-ipc-proto/src — 4 commits
- robotctl/src — 4 commits
- .github/workflows — 3 commits
- mediad/webclient — 3 commits
- docs/robot — 2 commits
- duck-control/src — 2 commits
- odometry/src — 2 commits
- spaces/shared — 2 commits
- deploy/updater.toml — 1 commit
- docs/README.md — 1 commit
- docs/project — 1 commit
Notable commits
- change: "Already serves this" was indistinguishable from success
- change: Merge branch 'duck-sim-finds-the-sim-repo' into a-simulated-duck-is-a-duck
- change: Merge branch 'duck-sim-finds-the-sim-repo' into a-simulated-duck-is-a-duck
- change: Merge branch 'main' into padd-reset-holds-on-pad-loss
- change: Merge branch 'main' into safety-limit-journal
- change: Merge branch 'main' into updater-rollback-journal-and-apply-action
- change: Merge main
- change: Merge main
- change: Merge main into a-mode-switch-waits-for-a-policy-load
- change: Merge main: the version this entry claims moved 28 -> 35
- change: Merge main: v35 was taken, so this is v36
- change: Merge pull request #107 from pollen-robotics/docs-mobile-app-approach
- change: Merge pull request #179 from Nixxx19/auto-exposure-digital-gain-back-to-1x
- change: Merge pull request #195 from Nixxx19/mode-switch-waits-and-never-stands-a-limp-robot-up
- change: Merge pull request #197 from Nixxx19/boot-recovery-waits-for-a-robot-that-is-still-starting
- change: Merge pull request #198 from hadelan/updater-rollback-journal-and-apply-action
- change: Merge pull request #216 from yunloong-Y/safety-limit-journal
- change: Merge pull request #226 from Nixxx19/refuse-a-non-socket-path-before-bind
- change: Merge pull request #228 from Nixxx19/a-mode-switch-waits-for-a-policy-load
- change: Merge pull request #241 from larai-w/feat/media-frame
- …and 169 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pollen-robotics/microduck was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f0d934e761a0bc96a6a7d1b5bc1260ce5a4120e5 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-705631bb727e.