Skip to content

feat(dektis): qualify the production RTL-SDR V4 scan path #402

Description

@forkwright

Finding

The superseded Phase 04 execution prompts contain two acceptance boundaries
not yet explicit in the living plan: a production akroasis sdr scan path and
real RTL-SDR V4 discovery/open/tune/stream qualification. Library-only DSP
components cannot satisfy either boundary.

Desired correction

Ship an end-to-end SDR operator path behind an injectable device backend, then
qualify the supported RTL-SDR V4 behavior in an operator-scheduled hardware
window.

  • Software acceptance covers discovery, open, tuner configuration, bounded
    sample streaming, cancellation, disconnect/reconnect, short transfer,
    malformed transfer, and device-loss errors through fake/replay backends.
  • akroasis sdr scan uses the production runtime and emits typed activity into
    accepted Semaino ingestion; it must not be a demo-only library call or a
    pre-audit broadcast bypass.
  • Direct-human discover/open/tune/scan/record/external-audio effects consume
    accepted security(runtime): authorize direct effects through one validated caller context #409 caller context; accepted scheduled or Praxis workflows instead
    carry typed source, capability, freshness/expiry/revocation, and policy-epoch
    authority. Dektis immediately rechecks artifact/use, persona, capability,
    scope, and current policy. Invalid human/workflow authority performs zero
    device/sink I/O.
  • Minimized intent/outcome receipts name the canonical caller or workflow and
    exclude raw I/Q, audio, protected tuning, paths, and credentials. I/Q and
    derived audio enforce their classified storage/sink/access/retention/export
    policy.
  • Protected I/Q/audio read, playback, and export consume accepted security(runtime): authorize direct effects through one validated caller context #409 caller
    context; non-human retention/export carries typed authority from the owning
    accepted workflow/policy epoch. Invalid authority yields zero content/sink
    I/O, and bounded coalescible accepted/denied receipts exclude I/Q, voice,
    tuning, path, location, and secrets.
  • Unsupported or ambiguous devices remain read-only/unavailable. No tuning
    action follows from VID:PID alone.
  • Real-device acceptance records the device/firmware identity and proves
    discover, open, tune, stream, stop, and reopen without importing archived
    numeric tables as authority.

Done when

  • Deterministic, hardware-free tests cover the full CLI/runtime/dataflow path,
    caller denials, audit failure/recovery, disclosure policy, and all named
    failure/cancellation cases.
  • An operator-authorized device qualification later proves the supported
    RTL-SDR V4 path and records reproducible evidence.
  • The Phase 04 plan links this issue as the Dektis production-path and
    device-qualification owner while security(runtime): authorize direct effects through one validated caller context #409 remains only the shared caller
    type/resolver contract.

Boundary

The operator has excluded hardware use from this session. This issue records
the gate; it does not authorize probing or opening any SDR device now.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions