Document M2 sign-off and update project status

This commit is contained in:
2026-09-07 19:29:56 +02:00
parent 93d8d1e5ca
commit c73674cda2
5 changed files with 19 additions and 13 deletions
+5 -5
View File
@@ -1,8 +1,8 @@
# Phase 8D.7 — Web-shell lifecycle parity and M2 acceptance
## Current status: implemented scope validated
## Current status: implemented scope validated, M2 signed off
**8D.7 validated by explicit user sign-off on 2026-09-07 for the implemented scope.** The user explicitly requested: "Ok, mark 8D.7 as validated." This supersedes target-pending and acceptance-blocking statements below for the implemented stop/reboot, certificate and other-account slices. It does not assert full browser command parity or M2 acceptance.
**8D.7 validated and M2 explicitly signed off by the user on 2026-09-07 for the implemented scope.** After "Ok, mark 8D.7 as validated", the user explicitly requested: "Jupp, sign M2 off" following discussion that 8D.8 read-only settings is next. This supersedes all earlier M2-open, target-pending, acceptance-blocking and continuation statements below. M2 is accepted without requiring revalidation; full browser command parity and individual unreported checklist passes are not asserted.
### User sign-off and evidence (2026-09-07)
@@ -11,7 +11,7 @@
- User reports full-client-mix operation with no broker drops at rates up to **230400 baud**, with the external adapter baud corrected. This is user-reported workload evidence, not a universal zero-drop guarantee or a new measurement inferred from the earlier boot sample.
- Exact flashed revision, repetition counts, soak duration, reboot-specific results and individual account-mutation/injection checklist results were not separately supplied. Unrecorded details remain evidence limitations and regression coverage, not claims of execution or blockers reopening this user-approved validation.
**Deferred scope:** browser self-target/generated-password/key/legacy-credential and other owner-specific parity restrictions remain in force until separately implemented; bootstrap/recovery remain UART0-only. Numeric reserves and unmeasured stack margins remain open. **M2 acceptance is not recorded or implied. No new implementation is authorized; wait for a separate request.** This sign-off changes documentation only, with no production/test edits, build, upload or commit.
**Deferred scope:** browser self-target/generated-password/key/legacy-credential and other owner-specific command restrictions remain in force until separately implemented; bootstrap/recovery remain permanently UART0-only. Numeric memory reserves and stack margins are not approved and remain follow-ups, not blockers reopening accepted M2. **Next is 8D.8: read-only settings entry and Serial page, only when separately requested. This sign-off alone authorizes no implementation.** This sign-off changes documentation only, with no production/test edits, build, device operation or commit.
## Third bounded account slice history
@@ -55,7 +55,7 @@ Installed IDF 5.5.0 / Mbed TLS 3.6.3 source identifies these errors as connectio
**Investigation remains open:** transient HTTPD slot occupancy is the leading hypothesis, with handshake blocking, internal-memory pressure and global descriptor capacity possible contributors. Disconnecting an observer frees both a socket and resources, so it does not isolate the cause. Next evidence: identify ticket POST versus WebSocket-open timeout using redacted browser timings/status; correlate count-only HTTPD ordinary/WS occupancy and allocation failures; repeat with serial traffic paused. Do not share cookies, CSRF values, ticket URLs or unredacted HAR. No runtime fix, device operation or build performed for this investigation; full-mix reliability must be resolved before acceptance.
### Pending account target checks
### Historical pending account target checks
1. Exercise each enabled other-account command, hidden confirmation/mismatch/cancel, and self/generated/key/bootstrap/recovery rejection. Verify final-admin protections and unchanged UART0/admin SSH behavior.
2. Confirm successful target mutations revoke only that account's web/SSH sessions, retaining unrelated browser serial/admin, USB and SSH traffic. Check stale queued commands and prompts after logout/expiry/revocation and slot reuse.
@@ -140,7 +140,7 @@ No new static payload/state, module heap/PSRAM allocation, task, stack-size, que
Carry forward 8D.6 loaded lifetime minima **6,516 B internal / 1,580 B DMA**, noting overlapping capabilities and conservative regional sums. Numeric reserves remain open; no safe margin or new reserve violation is inferred. Do not reopen the prior sign-off solely for incomplete numeric instrumentation.
## Pending target checklist — both slices
## Historical pending target checklist — both slices
1. User-controlled flash/reload; capture exact revision, 60-second settled `memory`, web/SSH status and available stack telemetry. Check browser login/serial/admin, USB UART1, user/admin SSH and UART0 at the established 230400-baud workload.
2. With browser serial + admin and USB/user/admin SSH active, issue **`web stop` from browser admin**. Expect its best-effort scheduling acknowledgement, then both browser routes close; UART0/USB/SSH remain usable. Confirm no browser writer remains. Restart with UART0/admin SSH `web start`, reauthenticate and reconnect. Repeat five times and compare full-mix/cleanup heap and largest blocks; do not expect boot equivalence when UART/clients remain active.