LOUP Engineering: Provisioning & Backend · advanced
OTA Required Is a Policy State, Not Just a Notification
Some firmware updates are optional improvements; others must gate service because compatibility or security changed.
The acceptance condition for OTA Required Is a Policy State, Not Just a Notification only became clear after the system was split into boundaries. The LOUP lifecycle includes ota_required so backend policy can distinguish a mandatory update from a normal available release.
A forced update can be justified when server protocol, security generation or persistent schema no longer supports the installed version. The device should still retain enough connectivity to fetch and verify the required artifact while withholding incompatible product behaviour.
The design became clearer when configuration, runtime state and recovery behaviour were specified separately instead of being implied by implementation details. Evidence marker: ota-required-state.
Firmware compatibility is part of service policy. Mandatory update state makes that dependency explicit instead of failing later in a less understandable path. Once that contract is written down, firmware and server changes can be reviewed against the same expectation instead of relying on memory.
Project evidence
LOUP engineering marker: ota-required-state. This note records the design or debugging lesson without publishing device credentials, private keys, customer data or manufacturing secrets.