openspec/changes/archive/2026-09-10-add-thor-carrier/reviews/2026-09-10-re-advise.md
Re-advise: add-thor-carrier
ADVISE: accept READER: fable-5-1-arch-review SPAWN: /Users/dukejones/work/ClientProjects/AllSystemsGo/AICamera/.spawns/add-thor-carrier-1789039096-36084-2847b11c
Second-pass read after Grok’s send-back amend (f8f76b9). Sol’s two blocking
findings from 2026-09-10-advise.md are the frame. Blind take was written
from proposal Why, living hardware-kit spec, the cited delta, and docs/references/T4000.md before design.md, tasks.md, or the prior
reviews were opened.
Blind take
- Pin: rails are DS table 3-1 verbatim: HV 7–20 V (22 A @ 20 V), MV 5 V (6 A), PMIC_BBATT coin; SV 3.3 V absent on T4000. Delta numbers match T4000.md.
- Pin: T4000 default; hybrid (Thor encodes body only, sats camera-side H.265) is the only T4000-safe path: 1 HQ 4Kp30 used of 2 available.
- Pin: the T5000 escape must state its cost. T5000 needs SV 3.3 V and defaults 120 W / TTP 80 °C. A carrier built to “SV absent” and a lid built to the living T4000 thermal ceiling cannot seat it. As written the escape is a module choice with no THEN on carrier or lid, which is the exact lock the Why warns about.
- Pin: “validated T4000 hybrid budget” cannot be measured on the lab brick (T5000, 2× NVENC) unless encode is confined to one NVENC or the figure is labeled datasheet-derived.
- Refuse: production dependence on CAN, HSB/USB ingest, or any 3.3 V SV consumer on the carrier.
- Refuse: reading the escape as licence to buy T5000 for headroom. Its only trigger is a satellite class that cannot encode camera-side, which the living PoE-satellite requirement already forbids.
- Tradeoff: SV 3.3 V DNP footprint plus a ≤ 90 W T5000 power mode keeps the escape real at the cost of carrier area and a second BOM variant; or declare the escape a carrier+lid respin and accept that. Either is fine. Silence is not.
- Wording: “SHALL NOT require T4000 SYS_VIN_SV” reads as if T4000 has one. Say “SHALL NOT require SYS_VIN_SV (T5000-only rail)“.
- Accept if design.md answers 3 explicitly (escape cost on carrier and lid).
- Send back if the escape is silent on carrier and thermal consequence.
Comparison and steelman
Sol finding 1 (rails descriptive, not normative) is closed. The
production-ceiling requirement now carries a SHALL for SYS_VIN_HV 7–20 V
and SYS_VIN_MV 5 V, a SHALL NOT for SYS_VIN_SV, and a rails scenario
that tests them at the seated SOM. I checked the numbers against the
DS-11945-001 v1.4 text (section 3.1 and table 3-1): HV 7–20 V, MV 5 V,
SV 3.3 V “Jetson T5000 only”, PMIC_BBATT 1.85–5.5 V. The delta is correct.
PMIC_BBATT is not in the SHALL; that is an RTC coin cell, not a purchase
lock, and does not belong in a lean delta.
Sol finding 2 (no normative escape criterion) is closed. T4000 is
now the default in normative text, and the T5000 escape scenario pins
the trigger to the datasheet figure (1× NVENC, HQ 2× 4Kp30) and to
satellite encode that cannot stay camera-side. That is the right
boundary: it is an NVENC-count decision, not a bandwidth or headroom
decision, and it cannot be read as licence to overbuild.
My take item 3 (escape cost on the carrier) is answered by the
design, not the delta. I assumed a T4000-only carrier. docs/CARRIER.md already prefers Connect Tech Rogue-T5, which seats both T4000 and T5000
and therefore supplies SV. Under that choice the escape costs no carrier
respin; the cost is the 92 × 108 mm board versus the 87 × 100 mm module,
which Sol’s take 10 already named and the design accepted. “SHALL NOT
require SYS_VIN_SV” is compatible with a carrier that provides it; the
requirement forbids depending on the rail, not populating it. So the
delta does not need the DNP-footprint clause I would have pinned.
My take item 4 (validation on the wrong module) does not survive steelman. The hybrid budget is one HQ 4Kp30 body encode against a capacity of two. A single NVENC session on the T5000 kit is a conservative measurement of that, with no need to confine hardware. The real trigger is the satellite class, which is a spec decision the living PoE-satellites requirement already makes (camera-side H.265, no RAW payload). “Validated” is slightly generous wording, not a hole.
My take item 7 (thermal cost of a T5000 body) is out of this change’s
scope. The living T4000 thermal ceiling requirement is scoped to “a
T4000 body”, so a T5000 body is unspecified rather than contradicted.
The production metal body is not yet a change; the first-article lid
wraps the AGX kit. If the escape is ever taken, the body change must
state the T5000 power mode and TTP, and this delta does not prevent
that.
Design.md is consistent with the delta: it names the same rails, the same absence of SV and CAN, and keeps the software and encode budget inside T4000 HQ. Tasks are all [x] and each maps to a visible artifact.
Notes for fold (not blocking)
- Wording: “It SHALL NOT require T4000 SYS_VIN_SV (T5000-only)” reads as if T4000 has such a rail. Fold as “It SHALL NOT require SYS_VIN_SV (a T5000-only rail)“.
- The
railsscenario’s “SYS_VIN_SV is absent” should be read at the module interface. A strict carrier-side reading would reject the preferred Rogue-T5. One clause, “absent at the module”, removes the ambiguity. - When the production metal body change opens, its thermal requirement should say what a T5000 escape runs at (power mode and TTP), because the living ceiling is T4000-scoped.
Verdict
Accept. Both send-back findings are now normative and datasheet-true, the escape has a decidable trigger, and the one concern the delta does not state (carrier cost of the escape) is settled by the dual-module carrier the design already chose.