Signed Dual-Slot OTA Needed an Acceptance State, Not Just a Boot Flag
A new image should become permanent only after the device proves it can boot, verify, connect and report healthy.
A new image should become permanent only after the device proves it can boot, verify, connect and report healthy.
A device should decide whether firmware is authorized, not merely whether the download completed successfully.
Transport security alone does not prove an artifact should be trusted after download.