Schema Migration Policy Belongs in the OTA Safety Model
Rollback is only safe when persistent data remains readable by the previous firmware or a migration policy accounts for the change.
TOPIC
Lessons, explainers, experiments, and implementation notes.
Rollback is only safe when persistent data remains readable by the previous firmware or a migration policy accounts for the change.
Release metadata is safer when it comes from authoritative device capabilities instead of copied operator input.
Success evidence loses meaning if failed or rolled-back assignments are ignored during promotion.
A release should not become stable merely because an administrator clicked a promotion button.
If a token only needs to be checked, retaining the plaintext creates unnecessary breach impact.
Rollback and validation failure are too important to infer from an unscoped status string.
Telemetry from a previous release must not be allowed to mutate the state of a newly assigned release.
A full OTA progress bar proves that a file transfer completed. It does not yet prove that the device booted the image successfully or that the required product functions still work. Update success spans several states.
A firmware artifact can be newer and still be unsafe for the target partition table, bootloader or hardware revision.
A release promoted to STABLE was still carrying old channel metadata, creating two competing sources of truth.