Skip to content

TRACKER — Device architecture: remaining work and acceptance #1448

Description

@timohueser

Status checked 2026-09-15 against linked issue states, merged PRs and recorded acceptance. This is a tracker audit, not a new source audit or device run. The earlier full source audit remains at d42e2e3a.

One DeviceCore owns product policy and each lifecycle. Board, simulator and web use the common flat store. Platform executors do physical work and return typed results. This tracker owns order and closure; child issues own implementation scope and evidence.

The main architecture and runtime conversions are delivered. Remaining work is update/rollback storage and FAT removal, bounded platform and failure contracts, missing entry-point and large-map evidence, and final physical acceptance. Future features and deferred desktop distribution remain in #1518 and follow this closeout. The owner's OTA distribution work (#773) remains separate and open.

Complete — do not schedule again

Area Completed scope and evidence
Foundations and domain ownership Flat-store foundations FS2–FS8, DeviceCore DC1–DC7, app core #1397, screen vocabulary #1396 and settings #1399 are complete. Ride R1–R3 and recovery #1591 are complete.
Ride durability and recording Atomic iOS archives #1677 / #1680; card metadata #1681 / #1683; shared commit fencing #1686 / #1688; route retention #1687 / #1689; exact archive receipts #1691 / #1692; live ride retention #1696 / #1701; iOS receipt delivery/retry #1697 / #1699. Save draining #1706 / #1709, accepted-boundary checkpoints #1712 / #1714 and unused route codec deletion #1715 / #1716 are complete. Physical archive acceptance remains with #1398.
Runtime store conversions Persistent Unix card ownership #1682 / #1684, native routes/trips #1698 / #1702, native weather #1707 / #1711, native recording/recovery #1713 / #1718, browser recording/reset #1720 / #1723 and native embedded terrain #1719 / #1721 are complete. Actual native reopen/recovery and browser Save/reset traces are recorded in the children. Browser storage is explicitly page-local; browser trips are absent and are not required demo content. Unavailable route-distance display #1722 / #1724 is complete.
Planner and typed outcomes Shared planner pacing/release #1690 / #1695 and board detours #1700 / #1705 are implemented. ForgetBond typed outcomes and mailbox removal #1678 / #1679 are complete. Their remaining contracts and physical checks are listed below.
Navigation optimization Evaluation #1735 is closed. Table-probe optimization #1783 is merged. Browser cache change #1781 / #1792 is complete: separate 4 KiB input and 64 KiB verification blocks, with a 41.5% total-time reduction on the pinned comparison. Direct-reference evaluation #1782 / #1793 is complete: retain the production format because the tested candidate increased browser assembly cost. Validation and packing were measured; they are not unfinished tasks. Full cell blocks remain an unmeasured alternative, not an approved implementation requirement. Wider acceptance remains #1162 / #1503 / #1420.
Test system and storage audit TS1–TS5 and TS7 are complete under #1449. TS5 #1784 / #1789 supplies native results and five accepted critical coverage baselines. TS7 #1785 / #1790 / #1794 supplies cadence separation and an actual 68-test weekly application pass. Python reports #1726 / #1730, Chromium demo #1728 / #1731 and Linux release launch #1727 / #1729 are complete. The absolute storage line-budget audit #1786 / #1787 is complete; FS11 still checks the final source.
Drawer UI #1515 is closed. The 2026-09-13 session records the owner's on-glass verdicts and measured behavior; #1685 fixes the defects found. Do not repeat the complete items 1–37 list as pending. The recorded omissions remain explicit below.

Remaining work

Work Owner Required outcome
Firmware update and rollback, then FAT removal #1391 → #1393 under #1256; client gate #1392 Deliver updates as flat-store objects, allocate rollback space in the app, pass both extent lists to the bootloader, and prove install/rollback. Then remove the remaining FAT/update users, obsolete adapters and temporary ingest path after shipping USB upload works. The line-budget tool already exists; check its 6,000-line limit on the final source.
Ride closeout and archive acceptance #1398 Add the bounded receipt/timestamp observation and metadata-readback seam needed for exact acceptance. Prove interrupted receipt response/reconnect retry, duplicate without clock restart, remount survival and changed-source refusal through board/iOS. Finish concrete R5 audit findings and link runtime parity/docs. Preserve RetentionMachine ownership, 32 full menu rows and 128 compact retention records.
Platform contracts and client acceptance #1433, #1392 Finish the Windows host-card creation durability contract. Verify real clients and runtimes for full identity/revision, replacement, leases, failed commits, disconnect/retry, recovery and ordered effect delivery. The client/transport/object-kind evidence inventory is complete in #1808 after independent review and green CI; use its explicit gaps for the remaining acceptance. Completed native/browser conversions above are not pending implementation.
ForgetBond #1433; reconnect defect #481 Controller resolving-list cleanup still has no completion receipt; the UI asks for a restart. Resolve live acknowledgment and radio-idle coordination, and supply paired-phone deletion, reset and failure evidence.
Planner and navigation closeout #1400 Prove physical cancellation, faults, arena handoff, timing and current stack high-water. Finish board/host success and failure parity and dispose of residual host policy. Give N2–N4 a current disposition: fix only a demonstrated defect or justified simplification. No general geometry/projection merger is required.
Storage failure bounds and resources #1166, #1501 Establish a whole-pass blocking bound against the watchdog and bound repeated failed peripheral boots; individual I/O deadlines are insufficient. Set an explicit resident-RAM slack policy and update current deep-ride stack evidence. Static parser correction #1708 / #1710 is complete; physical high-water is not.
Remaining test entry points (TS6) #1449, #994, #1177 Cover Windows release launch, real-browser builder assembly/download, scripted assemble/upload/reboot observation, and captured waypoint-bearing provider imports. Reuse the completed Chromium, Linux and iOS journeys. Physical USB and device presentation remain separate. One incidental Swift failure-test delay is removed in #1807 after independent review, a 274-test local target pass and green CI. Remaining Swift setup cost and waits stay in #1788; TS5/TS7 are not reopened.
Large-map performance, memory and delivery #1162, #1503, #1420 Compare country-scale native/browser assembly, measure actual browser memory with a registered gate, and prove DACH-class single-file bake → delivery → upload → render/route acceptance. The completed cache optimization and small-map device pass do not close these requirements.

Physical acceptance still owed

Physical checks resume when the owner has the board. The next scoped session remains Save/recovery, navigation and current stack high-water. Exact archive receipt/timestamp checks need the #1398 observation seam first. These sessions do not replace the final integrated campaign.

TS5 is complete; remaining TS6 gates precede final integrated acceptance. TS7 is complete. Existing physical evidence remains valid within its recorded scope. The no-device allowance for ordinary refactoring does not waive final physical gates.

Close this tracker when

  • Board, simulator and web use one DeviceCore policy and one runtime store; planner parity, durable metadata and ForgetBond outcomes are complete.
  • Obsolete host policy, repository adapters and FAT/update paths are removed; FS9–FS11 and domain closeout audits pass.
  • EPIC — Test system: coverage, entry-point gates and remaining test health #1449 and the required resource, fault, transport and hardware gates have linked evidence, including the explicit omissions above.
  • Public architecture and protocol documents match the final code.

A completed GET or local archive alone must not enable ride expiry. Device proof names the exact finalized ride; only its first trusted timestamp can start expiry. Preserve existing cache policies, exact request correlation and physical ownership boundaries. No universal cache or messaging wrapper is required.

Recovery must preserve the map and all unrelated objects: only an explicitly confirmed damaged RECORDING entry can be removed. Persistent media errors remain typed failures; whole-card FORMAT is not a recovery step.

Maintenance

Update the relevant row when scope, dependencies or a gate changes. Keep PR logs, measurements and transcripts in children. Follow CONTRIBUTING.md, docs/testing.md and the AGENTS.md verification budget. Use one independent review round, with later review limited to the delta. Report checks and deliberate omissions.

This status update checked live GitHub issue/PR states and recorded closure evidence. No code, builds, tests, benchmarks or physical sessions were changed or rerun.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions