Add the DeviceManager-owned safety coordinator, shared sensor/control policies, command ledger, service guards, generalized StopAll, and RecoverSafetyState. Preserve device-side hardware checks and AUBO hardware E-stop release reconciliation while keeping software E-stop independently latched.
83 lines
2.6 KiB
Protocol Buffer
83 lines
2.6 KiB
Protocol Buffer
syntax = "proto3";
|
|
package cmvr.config;
|
|
|
|
message ArmTeleopBackendConfig {
|
|
// Two independent gates are required: this service-level switch and the
|
|
// RobotArm implementation's teleop group-servo capability.
|
|
bool enable = 1;
|
|
// Also becomes RobotManifest.robot_id and the process-wide control lease
|
|
// resource. It must exactly match RobotArm.id().
|
|
string device_id = 2;
|
|
string model_sha256 = 3;
|
|
string calibration_sha256 = 4;
|
|
string base_frame = 5;
|
|
string tool_frame = 6;
|
|
double servo_period_s = 7;
|
|
// Maximum wall time allowed for one RobotArm::servoJ call.
|
|
uint32 max_apply_duration_us = 8;
|
|
// Omission is interpreted as true by the backend. Explicit false is intended
|
|
// only for simulation and independently supervised commissioning.
|
|
optional bool require_powered = 9;
|
|
// Bounds the first target relative to the cached measured position.
|
|
double max_initial_position_step_rad = 10;
|
|
// Bounds every later target relative to the last accepted target.
|
|
double max_position_step_rad = 11;
|
|
}
|
|
|
|
message GRPCSecurityConfig {
|
|
enum TransportMode {
|
|
TRANSPORT_MODE_UNSPECIFIED = 0;
|
|
INSECURE = 1;
|
|
SERVER_TLS = 2;
|
|
MUTUAL_TLS = 3;
|
|
}
|
|
|
|
enum AuthenticationMode {
|
|
AUTHENTICATION_MODE_UNSPECIFIED = 0;
|
|
DISABLED = 1;
|
|
STATIC_TOKEN = 2;
|
|
JWT = 3;
|
|
TLS_CLIENT_CERTIFICATE = 4;
|
|
}
|
|
|
|
enum RecoveryExposure {
|
|
RECOVERY_EXPOSURE_UNSPECIFIED = 0;
|
|
RECOVERY_DISABLED = 1;
|
|
RECOVERY_LOCAL_ONLY = 2;
|
|
RECOVERY_AUTHORIZED = 3;
|
|
}
|
|
|
|
TransportMode transport_mode = 1;
|
|
AuthenticationMode authentication_mode = 2;
|
|
RecoveryExposure recovery_exposure = 3;
|
|
bool allow_insecure_non_loopback = 4;
|
|
|
|
// Reserved for optional providers. Selecting an unsupported provider causes
|
|
// startup to fail; it never falls back to DISABLED.
|
|
string server_certificate_file = 5;
|
|
string server_private_key_file = 6;
|
|
string client_ca_file = 7;
|
|
string static_token_file = 8;
|
|
string jwt_issuer = 9;
|
|
string jwt_audience = 10;
|
|
string audit_file = 11;
|
|
}
|
|
|
|
message GRPCServerConfig {
|
|
string host = 1;
|
|
string port = 2;
|
|
bool enable_reflection = 3;
|
|
string id = 4;
|
|
// Bounds the continuity-oriented media queue before the gRPC stream skips
|
|
// ahead and waits for a new key frame. Zero uses the service default.
|
|
uint32 camera_stream_max_pending_frames = 5;
|
|
// Frames older than this monotonic age are not sent. Zero uses the service
|
|
// default so configurations written before these fields remain low-latency.
|
|
uint32 camera_stream_max_frame_age_ms = 6;
|
|
ArmTeleopBackendConfig arm_teleop_backend = 7;
|
|
GRPCSecurityConfig security = 8;
|
|
}
|
|
message GRPCServerRootConfig {
|
|
GRPCServerConfig grpc_server = 1;
|
|
}
|