openspec/changes/archive/2026-09-10-add-camera-interconnect/reviews/2026-09-10-re-advise.md
add-camera-interconnect — re-advise after send-back amend
ADVISE: send-back READER: fable-5-1-arch-review SPAWN: .spawns/add-camera-interconnect-1789036166-45583-1a4e86e6
Author this pass: Grok. Prior send-back: Sol, 2026-09-10-advise.md (not overwritten).
Blind take (written before opening the delta, design.md, tasks.md, or prior reviews)
Sources: Why line, openspec/specs/hardware-kit/spec.md, docs/INTERCONNECT.md, docs/STREAM-BUDGET.md.
- Pin: encode split is a SHALL, not a table row. Body = Thor NVENC. Sats arrive as camera-made H.265. T4000 HQ is 2× 4Kp30, so 1+2 cannot be Thor-encoded on the product SKU.
- Pin: the dev kit is T5000 (4× HQ). A bring-up that Thor-encodes all three on the kit will pass and then fail on T4000. The SHALL must force sat-side encode even where the kit could do it.
- Pin: record-first. The three HEVC masters SHALL reach the NAS with no dependency on NVDEC, the VLM, or any AI stage. Sat masters are remuxed, never decode-reencoded. AI drop loses inference, not picture.
- Pin: one clock of record. Body is GMSL/HW time, sats are PTP. The living Cooke /i SHALL keys each sidecar to “that camera’s HEVC timecode”. The delta must say which clock that is per camera and how the sat /i path (Lockit+ or ONVIF meta, separate stream) is aligned to the sat HEVC, or the living sidecar SHALL is unsatisfiable for sats.
- Pin: PoE is power, not data. Switch is a kit item, own PSU, no backfeed to the AGX kit. Data rate is the PHY. Class (at vs bt) bounds the sat SoC + servo + heater, so at minimum a floor must be pinned for the sat BOM.
- Pin: QSFP28 is 3× (T4000) or 4× (T5000) independent MGBE lanes. A NAS or switch expecting 100G aggregated will not link. The NAS-side port SHALL be stated as N× 25GbE or 10GbE.
- Refuse: RAW over the satellite fabric in v1. Hero uncompressed sat stays an exception, not a requirement.
- Refuse: USB-C or USB4 as any satellite trunk. Refuse GMSL counts above 4× 4K30 RAW on one JCB022.
- Tradeoff: sat-side encode buys T4000 fit but hands the sat master to the RV1126B encoder. That is not NVENC HQ. Accept for bring-up, but the spec should say sat master quality is bounded by the sat encoder so nobody later expects body-cam grade from a sat file.
- Tradeoff: NVDEC for AI is 1× on T4000 (4× 4Kp60). Two sat proxies fit. Six do not. The decode side must be declared best-effort so it cannot grow into a hidden requirement that breaks record-first.
Comparison (after opening the delta, design.md, tasks.md, both prior reviews)
Sol’s five corrections are all in the delta as SHALLs with scenarios. Against the blind take:
| Take | Delta | Status |
|---|---|---|
| 1 encode split is a SHALL | “Satellite-side encode for T4000 bring-up” | answered |
| 2 T5000 dev-kit trap | “The kit SHALL NOT require Thor to HQ-encode the … trio” is unconditional on SKU | answered |
| 3 record-first, remux never in the drop set | “SHALL continue when AI decode, overlay, or remux is dropped” | contradicts the plant, see below |
| 4 one clock of record, sat /i aligned to sat HEVC | “Clock and sidecar alignment” names PTP + body HW, master MAY stay open | answered at capability level, same bar Sol set |
| 5 PoE is power, switch is kit, class ≠ bitrate | “PoE power vs data boundary” | answered; class floor left to procurement, acceptable |
| 6 MGBE lanes independent | “Independent MGBE lanes” | answered |
| 7 no RAW on sat fabric | “HEVC record path” | answered |
| 8 no USB-C trunk, GMSL count | USB-C refused (parked under the clock requirement); GMSL count is carrier scope | answered / out of scope |
| 9 sat master bounded by sat encoder | not stated | note only, not a SHALL |
| 10 NVDEC best-effort | implied by record-first | answered |
Steelman for accept
Grok did exactly what Sol asked, every box is [x], and the docs already carry the plant. “Remux” in the drop set can be read as the AI-side remux (proxy for overlay/AD), with satellite masters being “camera H.265” that the sat writes itself. docs/INTERCONNECT.md even says “satellite masters from camera H.265 (or Thor remux)”, so a reading exists where Thor remux is optional and the SHALL is consistent. On that reading the delta is complete and the residue is wording.
Why that does not hold
Both plant diagrams (docs/INTERCONNECT.md:10, docs/STREAM-BUDGET.md hybrid plan) route satellites PoE switch → Thor remux / NVDEC → NAS. Thor remux is the only drawn path from a satellite to storage. The delta never says where a satellite master is written. So the living spec would carry “recording SHALL continue when remux is dropped” next to a plant in which dropping remux stops satellite recording. A folder cannot resolve that; an implementer will pick one silently.
The two readings buy different hardware, which is the Why of this change:
- Thor in the loop. Sat H.265 lands in the NVMe ring beside the body master, Thor writes HEVC + JSONL pairs for all three cameras, one writer, one uplink. Then remux is record, not AI, and cannot be in the drop set.
- Sat direct to NAS. The PoE switch must reach the NAS, not only Thor. The sat SoC needs a network-write or recorder path (turret with SD only is out). Thor’s 5GbE carries sat proxies in and the body out. JSONL for sats is still written by Thor (living Cooke /i SHALL) while the HEVC is written elsewhere, so 1:1 pairing is a two-writer reconciliation, not a file-system fact.
Either is buildable. The delta must choose, and the drop set must follow the choice.
Required correction (one clause)
In “Record-first under AI drop”, state the satellite master’s path to storage and make the droppable list match it. Recommended: Thor in the loop for bring-up. Concretely:
- Change the SHALL to: “HEVC recording, the NVMe ring, satellite remux to storage, and metadata sidecars SHALL continue when AI decode or overlay is dropped.”
- Add one line to “Hybrid camera fabric” or “HEVC record path”: satellite H.265 is written to the NAS by Thor (remux, no re-encode) alongside the body master.
Reason for the recommendation: the living Cooke /i SHALL already makes Thor the single sidecar writer 1:1 with “that camera’s HEVC timecode”. A single writer for both HEVC and JSONL keeps that pairing atomic and keeps the switch topology at “sats → switch → Thor” with no NAS-side requirement on the PoE switch. If Grok prefers sat-direct-to-NAS, say so and add the switch-reaches-NAS and sat-network-write constraints instead. Both readings are consistent with the rest of the delta.
Notes (not gating)
- USB-C refusal sits under “Clock and sidecar alignment”. It belongs under “Hybrid camera fabric”. Move it in the same pass if the file is open anyway.
- “Independent MGBE lanes” GIVEN says four controllers. That is the AGX kit (T5000). T4000 has three. The SHALL is correct for both; the scenario could say “three (T4000) or four (T5000)“.
- Sat masters are bounded by the sat encoder (RV1126B class), not NVENC HQ. Not a SHALL, but worth one sentence in
docs/INTERCONNECT.mdso nobody later grades a sat file against the body. - NVDEC is 1× on T4000. Two sat proxies fit, six do not. Record-first covers it; a decode budget line can wait for the 1+4 row.
- Thermal sag scenario says “slice-1 AI is killed”. Fine as a scenario; the SHALL does not depend on slice numbering.
Verdict rationale
Send-back on one clause, not on the architecture. Hybrid, HEVC-not-RAW, sat-side encode on T4000, PoE boundary, MGBE lanes, and clock-at-capability-level are all correct and now normative. The only defect is that the record-first SHALL lists as droppable the one stage the plant uses to record satellites. Fix the drop set or state the alternate storage path, and this is an accept without further reading.