Developer docs · firmware integration

Seven edge runtimes. No hidden authority hand-offs.

Each Mappls Auto firmware product owns a bounded state machine and explicit evidence. The platform supervisor joins version, freshness, compatibility and health without activating routes or content, installing firmware, publishing horizons, uploading telemetry or issuing vehicle commands.

Authority, bounds and failure behavior for FW-01 through FW-07.

Every package is independently buildable in C++20 with warnings-as-errors and assertions retained in Release tests.

FW-01Buildable reference

Location & Map-Matching Runtime

Authority

Qualified GNSS/DR evidence and a versioned road graph

Fixed bounds
3 match candidatesMonotonic observationFinite DR age
Degraded states
  • GNSS-only
  • Ambiguous level
  • DR expired
  • Stale
Terminal boundary

Does not persist a raw trace, read a physical vehicle or claim a physical outcome.

FW-02Buildable reference

Navigation & Guidance Runtime

Authority

Signed entitled content, qualified position and one route revision

Fixed bounds
3 alternatives16 maneuversOne active route
Degraded states
  • Held position
  • Inactive
  • Content incompatible
Terminal boundary

Does not activate a physical route, play audio or instruct a driver.

FW-03Buildable reference

Vehicle Signal Abstraction

Authority

Signed signal policy, source identity, units, range and freshness

Fixed bounds
8 propertiesPer-property sequenceAllowlisted units
Degraded states
  • Stale
  • Unavailable
  • Invalid
  • Moving unknown
Terminal boundary

Exposes no raw bus access and issues no vehicle command.

FW-04Buildable reference

Connectivity & Telemetry Agent

Authority

Signed purpose policy, durable journal and cloud acknowledgement

Fixed bounds
16 journal records6-record batches32 dedupe IDs12 nonces
Degraded states
  • Offline
  • Constrained
  • Retry exhausted
  • Overflow
Terminal boundary

Offered telemetry is not uploaded evidence; routed downlink is not physical action.

FW-05Buildable reference

Content & Map Update Manager

Authority

Signed manifest, entitlement, compatibility, hash and consumer health

Fixed bounds
One active versionOne staged candidateOne last-known-good
Degraded states
  • Deferred
  • Failed
  • Rollback pending
  • Rolled back
Terminal boundary

Download, verification, staging and activation are distinct; UI intent never updates a device.

FW-06Buildable reference

Device Lifecycle & OTA Agent

Authority

Signed compatible update, safe state, candidate health and last-known-good

Fixed bounds
One candidateOne active versionOne recovery baseline
Degraded states
  • Pending health
  • Failed
  • Rollback pending
  • Rolled back
Terminal boundary

An offer or activation request never proves firmware was physically installed.

FW-07Buildable reference

eHorizon & ADAS Map Runtime

Authority

Signed qualified content, consumer profile, current localization and path

Fixed bounds
3 probable paths12 segments6 attributes
Degraded states
  • Ambiguous path
  • Stale content
  • Low confidence
  • Unavailable
Terminal boundary

Map context does not replace perception, decide a vehicle function or make control safe.

One release decision, seven retained authorities.

The integration harness evaluates readiness without taking over product state or implying a physical result.

Exact versions

Every required runtime presents the interface revision declared by the signed program policy.

Current evidence

Monotonic sequence, signature, integrity and freshness are verified before platform use.

Isolated authority

Location, route, signals, journal, content, lifecycle and horizon remain separate authorities.

Safe degradation

Location or content loss changes consumer availability; it never fabricates continuity.

Recoverable lifecycle

A healthy active baseline remains distinct from a candidate, health receipt and rollback.

Replayable release

A deterministic fingerprint binds program, policy, runtime, configuration and content versions.

The runtime graph degrades by consumer—not by wishful continuity.

A fault is contained at the authority that can prove or recover it.

Stale locationNavigation holds/degradeseHorizon blocksNo position is fabricated
Incompatible contentNavigation blockseHorizon blocksActive baseline stays named
Healthy-baseline updateEssential navigation may degradeeHorizon blocks until stableNo install is claimed
Telemetry failureNavigation may remain readyeHorizon may remain readyPlatform reports degraded
Target assurance boundary

Host-compiled deterministic behavior is not target timing, memory, BSP/RTOS integration, HIL, vehicle-network approval, functional safety or cybersecurity acceptance. Those gates require the frozen ECU, process allocation and program evidence.

OEM program workshop

Bring us the vehicle. Leave with the program shape.

Choose the surfaces, modules, deployment and lifecycle that fit your next RFQ. We will turn it into a focused discovery brief.