Intervention records for Linux and ROS 2 robots.
RoboCairn is a logging component for Linux and ROS 2 robots, at design stage. It is designed to record changes to the software and configuration you declare as safety-relevant, and to keep those records readable for an authority that asks for them.
Status: In development
01The problem
Regulation (EU) 2023/1230 applies from 20 January 2027.
- Annex III, 1.1.9
- The machinery or related product “shall collect evidence of a legitimate or illegitimate intervention in the software or a modification of the software installed on the machinery or related product or its configuration”.
- Annex III, 1.2.1, second paragraph, point (f)
- Control systems shall be designed and constructed so that “the tracing log of the data generated in relation to an intervention and of the versions of safety software uploaded after the machinery or related product has been placed on the market or put into service is enabled for five years after such upload”.
The regulation does not say where the evidence is stored. It does not say whether the evidence itself must be protected.
02What we provide
-
Clause mapping
A table from 1.1.9 and 1.2.1, second paragraph, point (f), to the clauses of prEN 50742:2025 (enquiry draft).
Drafted, not published
-
Minimal reference implementation
A service on the robot's Linux host that records declared changes, and a tool that exports them with reading instructions.
Design drafted, under review. No code yet.
-
Notes for your technical file
Text you can adapt for the technical documentation of your machine.
Planned
03What it covers
- Changes to software and configuration that your risk assessment marks as safety-relevant. You declare the list; we do not decide it.
- Parameter changes, human-machine interface settings, safety-indication software, and deletion of the log itself.
- Retention as in clause 7.3.4 of the draft: it keeps the latest record of each type and does not delete records on its own. Whether each record lasts five years also depends on the robot's storage. Records are plain text and come with reading instructions.
- Optional, off by default: hash-chained records. Checked against a chain value kept off the robot, they show whether records were changed or removed. Someone with administrator access to the robot can rebuild the chain. A hash chain does not prove when a record was written and does not show that the data is genuine. Clause 7.3.5 of the draft asks for log protection under its Approach A. That clause is not listed in the draft's Annex ZZ table. We have not checked what Approach B requires.
04What it does not cover
- It is designed to stay outside the safety function chain. It only reads. It does not block or roll back a change.
- It does not verify software integrity, secure boot, or signatures.
- It does not replace a CE assessment or a notified body.
- It does not manage PLCs.
05Limits
prEN 50742:2025 is a draft. It is not a harmonised standard and gives no presumption of conformity. A later draft, FprEN 50742:2026, is in the approval stage at CENELEC. We have not read it.
Installing this component does not make a machine conform. The manufacturer assesses the whole machine.
The component records identifiers of the files and settings you declare: a version, a hash, or a checksum the controller reports. It does not show what code is running, who made a change, or whether the change was legitimate. A change made while the component is not running shows up only as a difference at the next start.
Nothing has been built or tested yet. We have no customers. This page is not legal advice.
06Why “cairn”
A cairn is a stack of stones that marks a path someone has already walked. RoboCairn works the same way. Each recorded change is one stone: what changed, and in what order.