Files
agentic-mobile-control/openspec/changes/edge-host-enrollment/specs/device-pool/spec.md
T

2.7 KiB

MODIFIED Requirements

Requirement: Authenticated network synchronization feeds the device pool

The system SHALL expose an authenticated Host Agent operation that validates a host device snapshot against its authentication mode and durable device enrollments before delegating it to the existing device-pool synchronization behavior.

Scenario: Valid managed remote snapshot

  • WHEN an authenticated enrollment-managed Host submits a complete snapshot containing only non-revoked device IDs enrolled to that Host with matching driver types
  • THEN the device pool refreshes that Host and its devices with the same replacement and staleness semantics as an in-process synchronization call

Scenario: Valid legacy remote snapshot

  • WHEN an authenticated statically configured Host submits a valid complete snapshot
  • THEN the device pool preserves the existing compatible synchronization and ownership-conflict behavior

Scenario: Invalid snapshot is rejected atomically

  • WHEN a Host Agent snapshot contains invalid identifiers, unowned cloud device IDs, conflicting driver metadata, statuses, or capability tags
  • THEN the control plane rejects the snapshot without partially replacing the Host's previous pooled devices or heartbeat timestamp

ADDED Requirements

Requirement: Durable device enrollment identity is independent of pool presence

The cloud repository SHALL retain a Host-scoped device enrollment and its assigned device_id independently of whether the device appears in the Host's latest heartbeat snapshot.

Scenario: Enrolled device disconnects

  • WHEN a Host submits a heartbeat that no longer includes a previously enrolled device
  • THEN the pooled-device projection removes that device while its durable enrollment remains available for later idempotent re-enrollment

Scenario: Enrolled device reconnects

  • WHEN the Host later enrolls or reports the same local device reference again
  • THEN the control plane reuses the existing cloud device_id

Requirement: Managed device identity cannot be claimed by another Host

The device pool SHALL derive managed device ownership from durable enrollment rather than accepting a caller-selected cloud device ID.

Scenario: Host reports another Host's managed device

  • WHEN Host B includes a cloud device ID enrolled to Host A in its heartbeat
  • THEN the control plane rejects Host B's snapshot and Host A retains ownership

Scenario: Prior Host becomes stale

  • WHEN Host A becomes stale and Host B presents Host A's cloud device ID
  • THEN the control plane still rejects implicit takeover because managed device transfer requires a future explicit operation