Skip to content

TRACKER — Device architecture: remaining work and acceptance #1448

Description

@timohueser

Status updated 2026-09-15. The software-only children #1726 / #1730 (Python results), #1728 / #1731 (Chromium demo) and #1727 / #1729 (Linux release launch) are merged after independent review, green CI and actual artifact inspection. The earlier full source audit remains at d42e2e3a.

Future product features and deferred desktop distribution live only in #1518. Complete this closeout before starting them. TS5 #1784 / #1789 and TS7 #1785 / #1790 / #1794 are complete after independent review, green CI and actual native artifact inspection. The storage line-budget audit #1786 / #1787 is complete after independent review and green CI. Physical checks resume when the owner has the board. The final integrated acceptance campaign and the owner's OTA work (#773) remain separate; their requirements stay open.

One DeviceCore owns product policy and each lifecycle. Board, simulator and web use the same flat store. Platform executors do physical work and report typed results. This tracker owns order and closure; linked issues own implementation scope and evidence.

Start here

Current wave complete: native embedded terrain #1719 / #1721, browser card recording/reset #1720 / #1723 and unavailable route-distance display #1722 / #1724 are merged after independent review and green CI. Actual native/browser checks and the final shipping resource guards pass. The next recommended gate is a scoped on-device Save/recovery, navigation and current stack high-water session. Exact receipt/timestamp capture still needs the observation/readback seam recorded under #1398.

Completed wave: recorder Save draining #1706 / #1709 is merged after review and green CI; Resource parser correction #1708 / #1710 is merged after review and green CI. Recorder checkpoint context #1712 / #1714 is merged after review and green CI; native card recording #1713 / #1718 is merged after review, an actual process recovery/Save trace and green CI. Unused route sidecar codec deletion #1715 / #1716 is merged after review and green CI. The previous wave is merged after independent review and green CI: live ride retention #1701, iOS receipt delivery #1699, native route/trip composition #1702 and board detours #1705. Corrected shipping-image analysis clears the detour stack blocker; physical acceptance remains open. Exact device proof #1692 and shared planner pacing #1695 are merged after independent review and green CI. Shared commit fencing is complete in #1686 / #1688. Typed route retention and board/flat-host metadata execution are complete in #1687 / #1689: exact card and loaded-catalog scope, checked commits, reload before resident stamps, stale expiry refusal and bounded failure handling. Receipt proof now commits exact finalized-ride identity with timestamp zero. Live ride policy now consumes validated durable proof, fills only the first trusted timestamp and checks exact-family expiry. No route-policy UI or wire command was added.

Card metadata storage is complete in #1681 / #1683, and atomic local archives are complete in #1677 / #1680. A completed GET or local archive alone must not enable ride expiry. Persistent native Unix card ownership is complete in #1682 / #1684; runtime conversion remains open. ForgetBond typed outcomes and mailbox removal are complete in #1678 / #1679.

The wave fixes partial-Save data loss, moves recording to the shared card, corrects stack-entry measurement, aligns checkpoint totals with accepted samples, and removes unused route codecs. These source changes do not require a device session before merge. Resource limits remain unchanged, and static checks do not close physical stack acceptance. Keep later recorder and map work in separately scoped children; final integrated physical acceptance remains open below.

Remaining implementation

Work Owner Next outcome and dependency
Ride metadata and durability (R4 → R5) #1398 Atomic client archives and exact identity are complete in #1677 / #1680. Card-metadata storage is complete in #1681 / #1683. Shared commit fencing is complete in #1686 / #1688. Typed route policy/board and flat-host commits are complete in #1687 / #1689; exact archive-proof ingress is complete in #1691 / #1692. Live ride policy #1696 / #1701 is complete; iOS receipt delivery/retry #1697 / #1699 is complete. Keep RetentionMachine as policy owner, 32 full menu rows and 128 compact retention records. Acknowledged Save draining is complete in #1706 / #1709. Accepted-boundary checkpoint context is complete in #1712 / #1714, native recording in #1713 / #1718, and unused route codec deletion in #1715 / #1716. Physical archive acceptance and further concrete R5 findings remain open.
Runtime store convergence #1433, client acceptance #1392 Maps already use the flat store in simulator and web; browser routes share that owner. Native routes and trips are complete in #1702. Checkpoint context is complete in #1712 / #1714 and native card recording in #1713 / #1718. Browser recording is complete in #1720 / #1723 with explicit memory-only lifetime, truthful checkpoint support and acknowledged reset cleanup. Native embedded planner terrain is complete in #1719 / #1721. Browser trips are explicitly absent; adding demo content is not required for convergence. Persistent Unix host-card ownership is complete in #1682 / #1684. Native route/trip composition #1698 / #1702 is complete; Windows creation still needs a directory-durability contract. Actual browser Save/reset and native terrain reopen traces now cover those runtime paths. #1722 / #1724 completes unavailable route-distance display after read failure. Verify identity, replacement, failure, durability and recovery through actual runtime paths.
Planner parity (N5) #1400 Shared typed pacing and acknowledged release are complete in #1690 / #1695, including exact source checks and safe publication cancellation. Host planning no longer advances or commits without Navigator effects. Board detour workspace/commit support is complete in #1700 / #1705, including independently checked corrected-image stack evidence. Physical cancellation, arena handoff and timing remain open.
Navigation graph optimization #1781, #1782; evaluation #1735 Initial bounded evaluation #1773#1775 is complete. Follow-up #1783 merged after review and green CI: one table search per insertion, 6.83% dense-route host improvement with unchanged routes/workspace. Browser cache tuning measured 43.7% on the pinned workload; #1781 owns the default change. #1782 evaluates integrated aligned direct references; complete validation and packing remain open. Full cell blocks remain unmeasured. #1162 / #1503 / #1420 retain wider acceptance.
ForgetBond closeout #1433 Typed outcomes and mailbox removal are complete in #1678 / #1679. Controller resolving-list cleanup remains unconfirmed; the UI asks for a restart. Live acknowledgment and physical paired-phone/failure acceptance remain. The separate reconnect bug remains #481.
Firmware update and FAT removal (FS9 → FS11) #1391, #1393 under #1256 Move update delivery and app-allocated rollback onto flat-store extent lists; prove install and rollback. Then remove the remaining FAT/update users and audit the storage line budget. FS10 acceptance (#1392) also gates FS11. OBC2 and retired wire-v3 deletion are already complete.

The flat-store foundations (FS2–FS8), DeviceCore foundation (DC1–DC7), app pass and domain ownership cutovers are complete. App core #1397, screen vocabulary #1396, and settings #1399 are closed. R1–R3 and recovery #1591 are complete. Their linked issues retain completion evidence.

Refine only where a current problem remains

Verification and physical acceptance still owed

Test system — #1449: TS1–TS4 are complete. TS5 #1784 / #1789 is complete after independent adversarial review and green CI, with native results, explicit coverage exclusions and five accepted critical baselines. TS7 #1785 / #1790 / #1794 is complete: cadence separation and cost reporting are merged, and the actual weekly application run passed all 68 tests after reviewed UI-state test fixes. Bounded Swift waits and measured simulator cost stay explicit in #1788. TS6 has the shipping Chromium gate in #1728 / #1731 and Linux release launch in #1727 / #1729; remaining critical entry points and physical acceptance stay open. Desktop launch #994, empirical map memory #1503 and upload smoke #1177 retain their acceptance obligations.

Physical evidence remains separate from source completion:

TS5/TS6 must be complete before the final integrated acceptance campaign; TS7 must be complete before closure. Existing physical evidence remains valid within its recorded scope. The no-device allowance for ordinary refactoring does not waive final physical gates.

Close this tracker when

  • Board, simulator and web use one DeviceCore policy and one runtime store; planner parity, durable metadata and ForgetBond outcomes are complete.
  • Obsolete host policy, repository adapters and FAT/update paths are removed; FS9–FS11 and domain closeout audits pass.
  • EPIC — Test system: coverage, entry-point gates and remaining test health #1449 and the required resource, fault, transport, hardware and on-glass gates have linked evidence.
  • Public architecture and protocol documents match the final code.

Recovery must preserve the map and all unrelated objects: only an explicitly confirmed damaged RECORDING entry can be removed. Persistent media failures remain typed failures; whole-card FORMAT is not a recovery step.

Keep this tracker short

Update the relevant row when scope, dependencies or a gate changes. Put PR logs, measurements and test transcripts in the child issue or PR; do not append batch summaries here. Refine children with exact scope, deletions and acceptance. Follow CONTRIBUTING.md, docs/testing.md and the AGENTS.md verification budget; report checks and deliberate omissions. Use one independent review round, with later review limited to the delta.

Software-only closeout — 2026-09-14

All three software-only children are complete: Python reports #1726 / #1730, Chromium demo journey #1728 / #1731, and Linux release launch/catalog/shutdown #1727 / #1729. Each merged after independent review, current-head green CI and inspection of its actual artifacts. No board, phone or physical acceptance run occurred. TS5 and TS7 are complete as recorded above. The next device session and remaining TS6 obligations stay open.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions