feat(k1): add offline control execution gate

This commit is contained in:
DCCONSTRUCTIONS
2026-07-18 14:14:30 +03:00
parent d7749208a7
commit ea811ff370
17 changed files with 916 additions and 44 deletions
+6 -2
View File
@@ -145,8 +145,12 @@ the response supplies live vendor identity, serial, model, activation and
version facts for the BLE-selected K1. Static and wire evidence identify OpenAPI
as one private application-level value in the observed client, not a manual
per-scanner profile. The whole pre-START order and START/STOP payloads are
byte-matched offline, but there is no MQTT publisher, `vendor_writes_enabled`
remains false, and no application command is sent.
byte-matched offline. A fixed macOS Keychain loader now supplies the exact
application authority without env/file/browser fallback, and a five-batch
orchestrator passes all retained response barriers. The installed publisher
boundary is structurally write-disabled and cannot call its sink. There is no
MQTT publisher, `vendor_writes_enabled` remains false, and no application
command is sent.
This locked bootstrap is repeatable in the current workspace, not yet a
standalone release install. The frontend consumes sibling `file:` packages from