Goal
Deliver a bounded local USB maintenance interface without bypassing platform ownership, application lifecycle or security policy.
Scope
Static commands, USB session, typed owner-context dispatcher, copied status results, bounded log/input streams, confirmed mutations and hardware qualification.
Non-goals
An OS shell, scripting, arbitrary memory/files/peripherals, command plug-ins, BLE terminal text, direct service calls from the CLI task or a public SDK event bus.
Dependencies
Independent of M5 and R1. Read-only work can proceed beside C1. Connectivity mutations require the applicable C1 authorization contract.
Acceptance criteria
docs/MAINTENANCE_CLI_CONTRACT.md is implemented and remains consistent with code.
- CLI task performs terminal work only; platform work executes at the application-owner safe point.
- Fixed capacities, explicit failure, cooperative cancellation and authority policy are tested.
- Android maintenance uses typed protocol requests and does not carry CLI text.
- All software gates and the real Note4 USB/hardware gate pass.
Automated evidence
Host semantic tests, dispatcher concurrency tests, architecture/SDK checks, ESP-IDF clean build and command golden transcripts.
Hardware evidence
USB connect/reconnect, read-only commands, confirmation, Ctrl+C, log/input streams, sleep/wake and shutdown without panic, watchdog or unexpected reset.
Closure condition
Close after all D1 child Issues pass and their evidence is attached to pushed main.
Goal
Deliver a bounded local USB maintenance interface without bypassing platform ownership, application lifecycle or security policy.
Scope
Static commands, USB session, typed owner-context dispatcher, copied status results, bounded log/input streams, confirmed mutations and hardware qualification.
Non-goals
An OS shell, scripting, arbitrary memory/files/peripherals, command plug-ins, BLE terminal text, direct service calls from the CLI task or a public SDK event bus.
Dependencies
Independent of M5 and R1. Read-only work can proceed beside C1. Connectivity mutations require the applicable C1 authorization contract.
Acceptance criteria
docs/MAINTENANCE_CLI_CONTRACT.mdis implemented and remains consistent with code.Automated evidence
Host semantic tests, dispatcher concurrency tests, architecture/SDK checks, ESP-IDF clean build and command golden transcripts.
Hardware evidence
USB connect/reconnect, read-only commands, confirmation,
Ctrl+C, log/input streams, sleep/wake and shutdown without panic, watchdog or unexpected reset.Closure condition
Close after all D1 child Issues pass and their evidence is attached to pushed
main.