chore(openspec): archive edge-host-enrollment
Tests / Test passed: 794

Sync delta specs into main specs before archiving: modified
cloud-control-plane, device-pool, and host-agent-protocol; created
new edge-host-enrollment capability spec. openspec validate --specs
reports 18/18 passing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-07-14 21:01:47 +08:00
co-authored by Claude Opus 4.6
parent 30f09b6268
commit 989fdbf878
12 changed files with 159 additions and 20 deletions
+32 -6
View File
@@ -48,15 +48,19 @@ The system SHALL allow looking up a single `PooledDevice` by `device_id` regardl
- **THEN** the pool returns a not-found result (e.g. `None`) rather than raising an unhandled exception
### Requirement: Authenticated network synchronization feeds the device pool
The system SHALL expose an authenticated Host Agent operation that validates a host device snapshot and delegates it to the existing device-pool synchronization behavior.
The system SHALL expose an authenticated Host Agent operation that validates a host device snapshot against its authentication mode and durable device enrollments before delegating it to the existing device-pool synchronization behavior.
#### Scenario: Valid remote snapshot
- **WHEN** an authenticated Host Agent submits a valid complete snapshot for its bound host id
- **THEN** the device pool refreshes that host and its devices with the same replacement and staleness semantics as an in-process synchronization call
#### Scenario: Valid managed remote snapshot
- **WHEN** an authenticated enrollment-managed Host submits a complete snapshot containing only non-revoked device IDs enrolled to that Host with matching driver types
- **THEN** the device pool refreshes that Host and its devices with the same replacement and staleness semantics as an in-process synchronization call
#### Scenario: Valid legacy remote snapshot
- **WHEN** an authenticated statically configured Host submits a valid complete snapshot
- **THEN** the device pool preserves the existing compatible synchronization and ownership-conflict behavior
#### Scenario: Invalid snapshot is rejected atomically
- **WHEN** a Host Agent snapshot contains invalid device identifiers, driver types, statuses, or capability tags
- **THEN** the control plane rejects the snapshot without partially replacing the host's previously stored devices
- **WHEN** a Host Agent snapshot contains invalid identifiers, unowned cloud device IDs, conflicting driver metadata, statuses, or capability tags
- **THEN** the control plane rejects the snapshot without partially replacing the Host's previous pooled devices or heartbeat timestamp
### Requirement: Device identity ownership conflicts are explicit
The device pool SHALL reject a snapshot that claims a `device_id` actively owned by a different non-stale host, rather than silently transferring ownership.
@@ -68,3 +72,25 @@ The device pool SHALL reject a snapshot that claims a `device_id` actively owned
#### Scenario: Previous owner is stale
- **WHEN** a configured ownership-recovery policy permits takeover and the prior owning host is stale beyond the recovery threshold
- **THEN** the new host may claim the device id and the ownership transition is recorded
### Requirement: Durable device enrollment identity is independent of pool presence
The cloud repository SHALL retain a Host-scoped device enrollment and its assigned `device_id` independently of whether the device appears in the Host's latest heartbeat snapshot.
#### Scenario: Enrolled device disconnects
- **WHEN** a Host submits a heartbeat that no longer includes a previously enrolled device
- **THEN** the pooled-device projection removes that device while its durable enrollment remains available for later idempotent re-enrollment
#### Scenario: Enrolled device reconnects
- **WHEN** the Host later enrolls or reports the same local device reference again
- **THEN** the control plane reuses the existing cloud `device_id`
### Requirement: Managed device identity cannot be claimed by another Host
The device pool SHALL derive managed device ownership from durable enrollment rather than accepting a caller-selected cloud device ID.
#### Scenario: Host reports another Host's managed device
- **WHEN** Host B includes a cloud device ID enrolled to Host A in its heartbeat
- **THEN** the control plane rejects Host B's snapshot and Host A retains ownership
#### Scenario: Prior Host becomes stale
- **WHEN** Host A becomes stale and Host B presents Host A's cloud device ID
- **THEN** the control plane still rejects implicit takeover because managed device transfer requires a future explicit operation