Offline-first architecture
User-initiated signed updates
Updates are signed packages, applied only when the user asks, from a static server manifest or a file passed by USB or messenger. No background service, no silent check, no telemetry.
Designed in a document, no code yet
What to plan for
- Power loss mid-update
- Rollback
- Wrong-platform package
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- Offline license key (signed) LIC-0001
- Optional yearly update plan LIC-0003
- Entitlement manifest LIC-0005
- Update delivery by file/USB LIC-0010
- Update delivery by direct download (opt-in) LIC-0011
- Update signature verification LIC-0012
- Update rollback LIC-0013
- Staged update (canary on one device) LIC-0014
- Co-op tier counter LIC-0016
- Referral code redemption (signed token) LIC-0022
- Clock rollback block for fiscal docs FAIL-0035
- App update mid-shift FAIL-0103
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.