openspec/changes/archive/2026-09-10-add-camera-interconnect/reviews/2026-09-10-advise.md
advise add-camera-interconnect
ADVISE: send-back READER: sol-arch-review SPAWN: /Users/dukejones/work/ClientProjects/AllSystemsGo/AICamera/.spawns/add-camera-interconnect-1789035858-24944-699a01be
Independent take (blind pass)
- Pin the plant boundary: the body sensor may emit RAW only on the CSI/GMSL hop into Thor, while every routed or stored picture stream is HEVC.
- Pin ownership of encoding: T4000 NVENC owns the body master, and each satellite owns its H.265 encode so the bring-up trio does not exceed two HQ 4Kp30 NVENC sessions.
- Pin the bring-up load as one body plus two 4K30 satellites at roughly 0.24 Gbps of HEVC payload, with 5GbE as sufficient aggregate uplink capacity.
- Pin that PoE names power delivery, not link bitrate, and require the selected satellite PHY plus switch uplink to carry the declared HEVC streams with overhead.
- Pin the independent-lane limitation: Thor QSFP/MGBE lanes must not be presented as a single aggregated 100GbE interface.
- Pin clock domains and metadata alignment explicitly enough that body hardware timing, satellite PTP, picture timecode, and Cooke /i-class JSONL can be reconciled per frame.
- Refuse any v1 architecture that makes USB-C the satellite trunk, assumes Thor supplies PoE, or silently promotes a hero uncompressed satellite into the baseline plant.
- Refuse a failure mode in which loss of AI/decode/remux can interrupt recording; satellite camera masters and the body NVENC-to-ring path must remain record-first.
- Require the change to distinguish verified constraints from open procurement choices, especially PoE class/switch SKU and the unresolved product clock source.
- Accept the compression tradeoff: camera-side satellite HEVC gives up centralized RAW control to keep cabling, power, NVENC count, and 5GbE bring-up honest.
Comparison and steelman
The design answers the central topology correctly: body CSI/GMSL, satellite PoE H.265, a separate PoE switch, satellite-side encode for the T4000 bring-up case, and independent MGBE lanes. The strongest case for acceptance is that docs/INTERCONNECT.md and docs/STREAM-BUDGET.md already state those constraints clearly, while the exact switch and clock source are intentionally open.
That case does not survive folding. The delta is the future living contract, but its two requirements retain only topology, H.265 recording, and the 0.24 Gbps/5GbE estimate. It does not preserve the design decisions that prevent incompatible camera, switch, or QSFP purchases—the exact failure named in the proposal’s Why.
Required corrections
- Make satellite-side H.265 encoding normative for the T4000 1+2 HQ bring-up case.
RAW SHALL NOT be requiredis weaker than the decided satellite HEVC transport and does not protect the two-session NVENC ceiling. - Specify the network boundary: PoE supplies satellite power, the satellite Ethernet PHY carries H.265, an external PoE switch is required because Thor has no PoE, and its data/uplink capacity is evaluated separately from the PoE class.
- Preserve the MGBE constraint in the delta: QSFP lanes are independent controllers and must not be treated as one aggregated 100GbE link.
- Close the clock-shaped procurement gap at the capability level. The exact master may remain open, but satellite PTP support, body hardware timing, and frame/timecode alignment to the existing Cooke /i-class sidecar contract need a testable requirement.
- Add a record-first scenario showing that AI decode/overlay load can be dropped without interrupting HEVC recording or its metadata sidecars.
These are delta omissions, not a rejection of the hybrid design. Once they are expressed as testable requirements and scenarios, the architecture is positioned for acceptance.