Files
NODEDC_MISSION_CORE/plugins/xgrids-k1/packaging
DCCONSTRUCTIONS e515ab1b8c feat(planning): consolidate recorded-route localization and spatial scene
Preserve the completed teach-and-repeat laboratory stage: reference preparation, cascaded acquisition, local tracking and recovery, recording lifecycle, replay qualification, and persistent Rerun scene controls. Document the open grid-picking regression and Rerun upgrade contract. No autonomous driving or loop-closure optimization is claimed.
2026-09-21 08:47:19 +03:00
..

Onboard K1 distribution

The accepted target is the owner's current activated K1, FW 3.0.2, on Ubuntu 24.04 amd64. Another physical scanner or firmware is not included in this acceptance. The same prepared installer can be used on another supported onboard host without a Mac, Keychain export, new packet capture or typed key.

mission-core-node 0.8.0 contains the host, shared SDK, existing RealSense support and statically composed sensor UI. mission-core-xgrids-k1 is an optional package containing the K1 service, its reviewed Python dependencies, platform adapters and application-material preparation. The optional package depends on the host; the host does not depend on the optional package.

The old 0.7.1 monolithic installation is migrated using Debian Breaks and Replaces. Existing filesystem paths, device identity, encrypted material, recordings and physical-command journals remain in place. Package scripts require a safe idle state and stop the worker before replacing its modules. Removing the optional package preserves recordings, journals and material.

Private autonomous installer

The public code package contains no key. The private edition 0.1.1+private.1 carries the reviewed application material in one root-owned mode-0600 member. The resulting .deb is itself private (mode 0600); distribute it only as the owner's prepared installer, never through Git or a public package registry. File permissions on the installed member do not encrypt the distributable archive. This is a deliberate private distribution boundary, not a claim that a client application's embedded material is unextractable.

At installation, the fixed root-owned helper reads that member and uses systemd-creds --with-key=host to encrypt it for the destination computer. The worker gets only LoadCredentialEncrypted=k1-application. Reinstalling identical material is idempotent; a different existing value fails before replacement and requires explicit rotation. There is no plaintext runtime fallback, browser secret, environment variable, cloud service or per-scanner key derivation. The administrative protected-stdin importer remains supported.

Building the private edition reads the material only from protected stdin:

python plugins/xgrids-k1/packaging/build_deb.py
  --wheel-root <reviewed-wheel-cache>
  --output <private-output-directory>/mission-core-xgrids-k1_0.1.1+private.1_amd64.deb
  --private-authority-stdin

This is an engineering build interface, not an operator prompt to type the key. An authorized build can read the existing fixed Keychain item once and supply those bytes in memory. No key value or key fingerprint enters public provenance. The build refuses to overwrite an existing artifact. Destination paths and credential values do not occur in source/runtime manifests.

Python wheels and application material are included. A fresh Ubuntu machine may still need its normal package repositories for declared OS dependencies; autonomous credential preparation does not claim an air-gapped OS installer.

Runtime composition boundary

runtime-files.json declares the complete onboard Python import closure (85 modules at this increment). The builder rejects changed imports until the list is reviewed. It includes shared session/viewer contracts that the existing K1 runtime still consumes; it does not pretend those dependencies have disappeared. composition.py owns local Core/LAB router and archive composition. Its factory was moved from the facade without changing its AST. The onboard worker does not import it. Laboratory public exports are lazy to keep a leaf migration check from loading all laboratory runners on the board.

This finishes a separately installable onboard package boundary, not the entire device-plugin architecture. The local Core backend remains in-process, frontend composition remains static, and the internal K1 facade still requires further decomposition. No network protocol, recovery transition, START/STOP transcript, camera producer or LAB/recorded/live Rerun settings were changed here.

The source for application-level identity is the retained LixelGO static/wire analysis in docs/05_K1_MQTT_STREAM_PROFILE.md and ADR 0012. It distinguishes the application value from the scanner's live vendor ID and serial. Current vendor release notes also document a protocol change at FW 3.0.2 paired with LixelGO 1.2.0; software-version compatibility must therefore remain explicit: https://www.xgrids.com/intl/support/download?page=K1