IF-05 · Data/content interface

Content manifest, package and activation lifecycle

Carry signed content identity, compatibility, lineage, rollout and last-known-good state from Map Content Cloud into device runtimes.

Name the source—and name what it cannot prove.

The same message can be observation, projection, plan, receipt or physical evidence. This contract keeps those meanings separate.

Authority

The signed manifest and package digest define offered content; each device owns verified, staged, active and last-known-good state.

Degraded behavior

Interrupted download resumes safely, signature or compatibility failure blocks staging, and failed health returns to last known good.

Outcome boundary

Offer, download, verification, activation and healthy population remain distinct; none implies every vehicle updated.

Producer and consumer responsibilities are explicit.

A product can appear on both sides when it transforms one authority into another; each transformation retains its own evidence.

Choose transport after semantics are fixed.

The program can select one or more transports without changing the source authority or failure contract.

Signed manifest APIResumable package deliveryDevice activation journal

Compatibility vector

  • schema or ABI version
  • producer release
  • consumer release
  • policy and entitlement revision
  • content/configuration revision
  • territory/platform profile

Acceptance evidence

  • contract compatibility
  • nominal and negative scenarios
  • ordering, replay and idempotency
  • latency, capacity and resource bounds
  • security, privacy and role enforcement
  • offline, recovery and rollback
  • target or operational acceptance
OEM program workshop

Freeze the Content manifest, package and activation lifecycle contract before integration.

Allocate owners, transport, schema, releases, policy, content, degradation, replay and target acceptance in one controlled baseline.