Files
chanora/docs/governance/product-decision-register.md
T
EdisonJwa a0d1c35461 docs(governance): owner confirmation on remaining 17 decisions (register v0.9.5)
Closes the 'Proposed / Owner Confirmation Required' state for every
decision in the register except DEC-020 (license, explicitly deferred
and now the only public-release-gating decision outstanding).

Accepted as recommended:
  DEC-001 (Alpha → Beta → Public release sequence),
  DEC-002 (all five platforms as MVP target, staged release allowed),
  DEC-003 (iOS minimum: iOS 13),
  DEC-005 (Android target SDK: Play-required API on upload date),
  DEC-006 (single active server connection in MVP),
  DEC-007/008/009/010 (AEC + AGC + NS + HPF defaults),
  DEC-011 (platform-native audio first),
  DEC-012 (legal/trademark/licensing review as a release gate),
  DEC-013 (SQLite or equivalent for non-secret state),
  DEC-016 (no automatic diagnostics upload),
  DEC-017 (crash reporting disabled for MVP),
  DEC-018 (product name: Chanora),
  DEC-019 (drafted non-affiliation wording),
  DEC-021 (Apple App Store SDK gate: Xcode 26+ / iOS 26 SDK+ on/after 2026-04-28).

Modified from the original recommendation by explicit owner ruling:
  - DEC-004: Android minimum raised to API 28 (Android 9.0) from the
    recommended API 24. Rationale: simpler audio path (AAudio stable
    from API 28), narrower compatibility / privacy / scoped-storage
    surface. Affects the Android spike's minSdk=24 in product code:
    apps/chanora_flutter will need minSdk=28.
  - DEC-015: MVP product language expanded to English + Chinese
    (Simplified) from the recommended English-only. Rationale: the
    demonstrated TS3-compatible-server audience (verified live against
    cn.teamspeak.app) and broader TS3 audience include substantial
    Chinese-speaking users. Adds zh-Hans translation, font, and
    text-length-budget work to MVP. Server-provided content is still
    preserved verbatim per ADR-008.

Still Open / Deferred:
  - DEC-020 license model. The only remaining release-gating decision.

Documentation updates:
  - product-decision-register.md → v0.9.5. §3 statuses updated, §4
    renamed Recommended → Accepted with MODIFIED rows annotated,
    §6 collapsed to DEC-020 only, §7 dated and statused for every
    decision, change-history entry added.
  - poc-results-summary.md → v0.3.0. §4 expanded with the
    2026-05-14 owner-confirmation pass table. RISK-PoC-004 closed.
    New RISK-PoC-006 (Android minSdk move 24 → 28) and RISK-PoC-007
    (MVP language expansion to en + zh-Hans) added.
  - CHANGELOG entry under [Unreleased].
2026-05-14 20:46:29 +08:00

20 KiB

CHANORA_CFG_Product_Decision_Register_v0.9.5.0.0

Document type: Configuration / Product Decision Register
Version: 0.9.5
Status: Baseline Candidate
Language: English
Product: Chanora
Repo path: docs/governance/product-decision-register.md ---

1. Purpose

This document records key product, architecture, release, legal, and engineering decisions that affect Chanora scope, testing, architecture, app store eligibility, and release readiness.

A decision marked Proposed / Owner Confirmation Required is a recommended decision that should be confirmed by the owner before Final / Approved Baseline.

2. Decision Status Legend

Status Meaning
Proposed / Owner Confirmation Required Recommended decision; owner must confirm before Final.
Accepted Confirmed and part of baseline.
Deferred Not decided for this release; must not block scope if explicitly deferred.
Rejected Not selected.

3. Key Blocking Decisions

Decision ID Decision Recommended decision Status Owner Why it matters
DEC-001 Release type Internal Alpha first, then External Beta, then MVP Public / Store Release Accepted Product Owner Controls release gate, verification bar, legal/privacy requirements, and platform scope.
DEC-002 MVP platform scope MVP target remains Windows, macOS, Linux, Android, and iOS; first release may be staged by channel/platform Accepted Product Owner + Engineering Owner Controls verification matrix, build artifacts, store readiness, and support load.
DEC-003 Minimum iOS version iOS 13 minimum for Flutter support baseline; test latest iOS release separately Accepted Product Owner + iOS Owner Controls iOS compatibility, test devices, and app store eligibility.
DEC-004 Minimum Android version Android API 28 (Android 9.0) minimum, raised from the original recommendation of API 24 by explicit owner ruling on 2026-05-14. Rationale: simplifies the audio path (AAudio is unconditionally available from API 26+ and stable from API 28), narrows the TLS / privacy / scoped-storage compatibility surface, and matches typical 2026 Android baselines. The cpal-on-Oboe Android spike was built with minSdk = 24 and cargo-ndk -P 26; product code in apps/chanora_flutter must move minSdk to 28 and may simplify the AAudio-vs-OpenSL-ES fallback logic accordingly. Accepted Product Owner + Android Owner Controls Android device support, runtime permissions, and Play Store eligibility.
DEC-005 Android target SDK Target the Google Play-required API level on the upload date; current release gate uses API 35+ unless newer Google policy applies Accepted Android Owner + Release Manager Required for new apps and updates submitted to Google Play after the current policy date.
DEC-006 Multiple server connections in MVP Not in MVP; support one active server connection per client instance Accepted Product Owner + Software Architect Reduces state synchronization, audio routing, UI complexity, and verification scope.
DEC-007 AEC default state Enabled by default on platforms/audio backends where supported and stable Accepted Audio Owner + Product Owner Affects echo quality, CPU usage, platform behavior, and user experience.
DEC-008 AGC default state Enabled by default, with user setting to disable Accepted Audio Owner + Product Owner Affects perceived loudness consistency and may affect advanced user preference.
DEC-009 Noise suppression default state Enabled by default, with user setting to disable Accepted Audio Owner + Product Owner Improves typical voice quality but may affect voice naturalness and CPU usage.
DEC-010 High-pass filter default state Enabled by default Accepted Audio Owner Removes low-frequency rumble and usually improves speech capture.
DEC-011 Audio processing implementation path Use platform-native audio processing first where available; use Rust/WebRTC-style processing as controlled fallback or later architecture option Accepted Software Architect + Audio Owner Controls architecture, latency, CPU use, platform compatibility, and testing.
DEC-011.1 Audio crate choice cpal for desktop (empirically verified on Linux/PipeWire by poc/audio-capture-playback-spike on 2026-05-13) and for Android (cpal-on-Oboe, empirically verified on a Motorola Moto G Stylus 5G (2023) running Android 14 arm64-v8a by poc/audio-capture-playback-android-spike on 2026-05-13); iOS crate TBD pending an iOS spike that requires macOS + Xcode hardware Accepted (desktop + Android) / Deferred (iOS) Software Architect + Audio Owner Pins the desktop and Android audio dependencies; iOS remains an open risk surface.
DEC-012 Official SDK / trademark / licensing review Public/store release is blocked until legal confirms TeamSpeak non-affiliation wording, trademark usage, OSS licenses, and tsclientlib license posture Accepted (as a release gate) Legal / Compliance + Product Owner Public release risk and store metadata risk. Owner accepted the gate on 2026-05-14; the legal review itself is still to be performed and remains a public-release blocker.
DEC-013 Local database choice Use SQLite or equivalent embedded local database for non-secret local state; secrets remain in platform secure storage Accepted Software Architect + Storage Owner Controls storage schema, migrations, backup/delete policy, and portability.
DEC-013.1 SQLite crate rusqlite with the bundled feature (SQLite statically linked into the binary; no system libsqlite3 dependency); verified by poc/sqlite-storage-spike on 2026-05-13 Accepted Software Architect + Storage Owner Pins the embedded-DB dependency; locks reproducibility.
DEC-013.2 Linux secure-storage backend policy Prefer Secret Service (libsecret / gnome-keyring / kwallet / KeePassXC) on Linux; if the default collection is locked or D-Bus is unavailable, fall back to kernel keyutils with a clear user notice. Both backends are "equivalent" per SysRS-053 / SysRS-162; verified by poc/secure-storage-spike on 2026-05-13 Accepted Software Architect + Storage Owner + Security Reviewer Closes the SysRS-162 ambiguity surfaced by the secure-storage PoC.
DEC-014 Bridge choice Use a stable typed Flutter/Rust bridge with generated or schema-controlled DTOs; flutter_rust_bridge 2.x pinned (empirically verified at 2.12.0 by poc/flutter_rust_bridge_hello on 2026-05-13) Accepted Software Architect Controls API stability, maintainability, async event flow, and long-term code generation.
DEC-015 Product language for MVP English + Chinese (Simplified) for MVP, raised from the original recommendation of English-only by explicit owner ruling on 2026-05-14. Rationale: the demonstrated test-server population (verified live against cn.teamspeak.app) and broader TS3 audience include substantial Chinese-speaking users; shipping zh-Hans alongside en at MVP avoids a launch-window UX gap. Architecture remains i18n-ready so additional languages can be added later mechanically. Server-provided content is preserved verbatim and never translated (ADR-008 UTF-8 boundary, DEC-015 server-content rule retained). Accepted Product Owner Controls localization scope and release schedule.
DEC-016 Diagnostics upload policy No automatic upload for MVP; user-initiated local diagnostic export only Accepted Product Owner + Legal + Security Controls privacy policy, support workflow, and security review scope.
DEC-017 Crash reporting Disabled for MVP unless explicit opt-in provider and privacy policy are approved Accepted Product Owner + Legal + Security Avoids privacy/legal complexity before public release.
DEC-018 Public product name Chanora Accepted Product Owner Branding and legal identity. Trademark / registrability check remains under DEC-012 legal review before public release.
DEC-019 Public non-affiliation statement Use legal-approved wording; drafted text accepted as working copy: "Chanora is independent and is not affiliated with, endorsed by, sponsored by, or officially associated with TeamSpeak." Subject to final legal review under DEC-012 before public release. Accepted (drafted wording) Legal / Compliance Required for public release and store metadata.
DEC-021 Apple App Store submission SDK Use Xcode 26 or later and the iOS 26 / iPadOS 26 SDK or later for App Store submission on or after 2026-04-28, unless Apple publishes a newer applicable requirement before upload Accepted iOS Owner + Release Manager Controls App Store Connect upload eligibility and release pipeline.
DEC-020 License model TBD by owner; no public release until license model and OSS obligations are confirmed Open Product Owner + Legal Business and OSS compliance decision. Explicitly deferred on 2026-05-13 by owner; remains a public-release blocker.
DEC-022 Canonical implementation directory layout Accept the README's sketch as canonical: apps/chanora_flutter/, core/chanora_core/, crates/chanora_protocol/, crates/chanora_audio/, crates/chanora_state/, crates/chanora_storage/, crates/chanora_diagnostics/, crates/chanora_bridge/. Matches SAD §7.2 module decomposition Accepted Software Architect Unblocks product-crate scaffolding; was not formalised by any prior doc.

4. Accepted MVP Defaults

The "Recommended" defaults below have all been confirmed by the owner; two were modified from the original recommendation (marked MODIFIED).

Area Accepted MVP default
Release sequence Internal Alpha → External Beta → MVP Public
MVP platforms Windows, macOS, Linux, Android, iOS (staged release allowed)
Active connections One active server connection
UI design system Material 3 + Chanora Design System
Product language MODIFIED — English + Chinese (Simplified) at MVP; i18n-ready architecture
Server content Preserve and display Unicode; do not translate
Diagnostics Local, user-initiated export only
Telemetry None
Crash reporting None unless later approved
Secret storage Platform secure storage
Non-secret local storage SQLite (rusqlite bundled)
Audio processing Platform-native first; fallback strategy documented
AEC Enabled by default where supported
AGC Enabled by default (user-toggleable)
Noise suppression Enabled by default (user-toggleable)
High-pass filter Enabled by default
Android minimum MODIFIED — API 28 (Android 9.0), raised from the original recommendation of API 24
Android target API 35 or newer per current Google Play policy on upload date
iOS minimum iOS 13
Apple App Store SDK gate Xcode 26+ / iOS 26 SDK+ for uploads on or after 2026-04-28
Audio crate cpal (desktop, Android); iOS deferred
Bridge Stable typed Flutter/Rust bridge; flutter_rust_bridge 2.x pinned
Implementation directory layout apps/chanora_flutter/, core/chanora_core/, crates/chanora_*
License Still Open — DEC-020; blocks public release

5. Decision Impact Matrix

Decision Affects SysRS Affects SysDes Affects SRS Affects SAD Affects SDD Affects Verification Affects Release
Minimum iOS / Android versions Yes Yes Yes Yes Yes Yes Yes
Android target SDK No No Yes No No Yes Yes
Multiple active connections Yes Yes Yes Yes Yes Yes Yes
AEC/AGC/NS/HPF defaults Yes Yes Yes Yes Yes Yes Yes
Audio implementation path No if behavior unchanged Yes Possibly Yes Yes Yes Yes
SDK/trademark/legal review Yes No No No No Yes Yes
SQLite/equivalent choice Possibly Yes Yes Yes Yes Yes Yes
Bridge choice No if API behavior unchanged Yes Possibly Yes Yes Yes Yes
Apple App Store SDK gate Yes Yes Yes Yes Yes Yes Yes
Diagnostics upload policy Yes Yes Yes Yes Yes Yes Yes
Crash reporting Yes if included Yes if included Yes if included Yes if included Yes if included Yes Yes

6. Decisions That Must Be Confirmed By You

All previously listed P0/P1 owner-confirmation items were addressed on 2026-05-14 in a single owner-review session; their final status is reflected in §3 and §7. The only remaining open item is:

Priority Decision Status
P0 DEC-020 — License model. Open / Deferred — blocks any public/store release.

The release-gate legal review (DEC-012) is itself Accepted as a gate, but the legal review work has not yet been performed and remains a public-release blocker until completed.

7. Open Decision Log

Decision ID Owner Decision Status Date Notes
DEC-001 Product Owner Release type sequence Accepted 2026-05-14 Internal Alpha → External Beta → MVP Public.
DEC-002 Product Owner / Engineering MVP platform strategy Accepted 2026-05-14 All five platforms as target; staged release allowed.
DEC-003 Product Owner / iOS Owner Minimum iOS version Accepted 2026-05-14 iOS 13.
DEC-004 Product Owner / Android Owner Minimum Android version Accepted 2026-05-14 API 28 (modified from the recommendation of API 24).
DEC-005 Android Owner / Release Manager Android target SDK Accepted 2026-05-14 Google Play-required API on upload date (currently API 35+).
DEC-006 Product Owner / Software Architect Multiple server connections in MVP Accepted 2026-05-14 Single connection in MVP.
DEC-007 Audio Owner / Product Owner AEC default Accepted 2026-05-14 Enabled by default where supported.
DEC-008 Audio Owner / Product Owner AGC default Accepted 2026-05-14 Enabled by default with user toggle.
DEC-009 Audio Owner / Product Owner Noise suppression default Accepted 2026-05-14 Enabled by default with user toggle.
DEC-010 Audio Owner High-pass filter default Accepted 2026-05-14 Enabled by default.
DEC-011 Software Architect / Audio Owner Audio processing path Accepted 2026-05-14 Platform-native first; Rust/WebRTC-style fallback.
DEC-011.1 Software Architect / Audio Owner Audio crate (desktop / mobile) Accepted (desktop: cpal; Android: cpal-on-Oboe) / Deferred (iOS) 2026-05-13 Closed by poc/audio-capture-playback-spike (desktop) and poc/audio-capture-playback-android-spike (Android). iOS crate TBD pending iOS spike.
DEC-012 Legal / Compliance SDK/trademark/licensing review Accepted as a release gate 2026-05-14 Required before public/store release; legal review work still to be performed.
DEC-013 Software Architect / Storage Owner Local database Accepted 2026-05-14 SQLite or equivalent for non-secret state.
DEC-013.1 Software Architect / Storage Owner SQLite crate Accepted (rusqlite bundled) 2026-05-13 Closed by poc/sqlite-storage-spike 11/11.
DEC-013.2 Software Architect / Storage Owner / Security Reviewer Linux secure-storage backend policy Accepted (Secret Service preferred, keyutils fallback) 2026-05-13 Closed by poc/secure-storage-spike 6/6. Resolves SysRS-053 / SysRS-162 ambiguity.
DEC-014 Software Architect Bridge choice Accepted (flutter_rust_bridge 2.x pinned) 2026-05-13 Closed by poc/flutter_rust_bridge_hello 3/3.
DEC-015 Product Owner Product language for MVP Accepted 2026-05-14 English + Chinese (Simplified) (modified from the recommendation of English-only).
DEC-016 Product Owner / Legal / Security Diagnostics upload policy Accepted 2026-05-14 User-initiated local export only; no automatic upload.
DEC-017 Product Owner / Legal / Security Crash reporting Accepted 2026-05-14 Disabled for MVP.
DEC-018 Product Owner Public product name Accepted 2026-05-14 Chanora. Trademark check still required under DEC-012.
DEC-019 Legal / Compliance Public non-affiliation statement Accepted (drafted wording) 2026-05-14 Final legal sign-off still required under DEC-012.
DEC-020 Product Owner / Legal License model Open / Deferred 2026-05-13 Explicitly deferred by owner; remains a public-release blocker.
DEC-021 iOS Owner / Release Manager Apple App Store SDK gate Accepted 2026-05-14 Xcode 26+ / iOS 26 SDK+ on or after 2026-04-28.
DEC-022 Software Architect Canonical implementation directory layout Accepted (README sketch) 2026-05-13 Closes the absence flagged during PoC review.

8. Change History

Version Date Description
0.9.0 2026-05-14 Updated decision register with proposed decisions for mobile minimum versions, audio defaults, audio implementation path, legal review, local database, bridge choice, diagnostics policy, and MVP release scope.

Baseline Candidate 0.9.1 Update

Version Date Description
0.9.1 2026-05-14 Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ for App Store Connect upload on or after 2026-04-28, platform baselines and decision traceability propagated across the document set.

Baseline Candidate 0.9.2 Update

Version Date Description
0.9.2 2026-05-14 Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage.

Baseline Candidate 0.9.3 Update

Version Date Description
0.9.3 2026-05-14 Recorded owner-confirmed decisions surfaced during the initial PoC phase: DEC-014 Accepted (flutter_rust_bridge 2.x pinned); added DEC-011.1 Accepted for desktop (cpal) / Deferred for mobile; added DEC-013.1 Accepted (rusqlite bundled); added DEC-013.2 Accepted (Linux Secret Service preferred with keyutils fallback); added DEC-022 Accepted (canonical implementation directory layout per README sketch and SAD §7.2); DEC-020 explicitly Deferred and remains a public-release blocker. Evidence pointers: poc/flutter_rust_bridge_hello/VERIFICATION.md, poc/secure-storage-spike/VERIFICATION.md, poc/sqlite-storage-spike/VERIFICATION.md, poc/audio-capture-playback-spike/VERIFICATION.md.

Baseline Candidate 0.9.4 Update

Version Date Description
0.9.4 2026-05-14 Promoted DEC-011.1 mobile half from Deferred to Accepted (Android), keeping iOS Deferred. Evidence: poc/audio-capture-playback-android-spike/VERIFICATION.md records empirical playback (22,050 frames at 44.1 kHz mono out of the device speaker) and capture (42,624 frames written to a valid 85,292-byte RIFF/WAVE mono 16-bit PCM file) on a physical Motorola Moto G Stylus 5G (2023) running Android 14 arm64-v8a, verifying the full Rust → cpal → Oboe → AAudio → Android audio HAL path.

Baseline Candidate 0.9.5 Update

Version Date Description
0.9.5 2026-05-14 Owner confirmation pass on all previously-Proposed decisions. Accepted: DEC-001, DEC-002, DEC-003, DEC-005, DEC-006, DEC-007, DEC-008, DEC-009, DEC-010, DEC-011, DEC-012 (as a release gate), DEC-013, DEC-015, DEC-016, DEC-017, DEC-018, DEC-019 (drafted wording), DEC-021. Two decisions modified from their original recommendations: DEC-004 Android minimum raised from API 24 to API 28 (simpler audio path, narrower compatibility surface); DEC-015 product language expanded from English-only to English + Chinese (Simplified) for MVP (reflects the demonstrated TS3-compatible-server audience). DEC-020 license model remains Open / Deferred — the only public-release blocker outstanding. §4 renamed from "Recommended MVP Defaults" to "Accepted MVP Defaults" with MODIFIED rows annotated. §6 collapsed to the single remaining DEC-020 item. §7 dated and statused.