docs: point the reboot repair at the milestone that actually owns it

The roadmap puts the BOOT_COMPLETED and TIME_SET receivers, the ringing
service and the full-screen intent in M3; ARCHITECTURE.md credited them
to M6 and M7, which are Timers and Stopwatch.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-11 13:53:11 +02:00
co-authored by Claude Opus 5
parent efd88e3060
commit 971ee4f7a3
+7 -6
View File
@@ -267,7 +267,7 @@ consulting the wall clock to decide staleness — would let a user moving the
system clock warp a running timer, which `PLAN.md` §5 forbids outright.
Closing it properly needs a persisted boot identifier, which is not in this
schema. **M6's `BOOT_COMPLETED` receiver is the authoritative repair:** it runs
schema. **M3's `BOOT_COMPLETED` receiver is the authoritative repair:** it runs
at the top of every boot, before the new uptime can climb past any stored
anchor, and rewrites every running timer from `endsAtWallClock`.
@@ -299,9 +299,10 @@ timer, and inherits the same blind spot: once the new boot's uptime passes the
stored `startedAtElapsedRealtime`, the reboot goes unnoticed and the run reports
`accumulated + (elapsedRealtime - startedAtElapsedRealtime)` as **live and not
stale** — a segment it never actually ran. So the discarding above is what
happens when the reboot *is* detected, not a guarantee; until M6's
`BOOT_COMPLETED` receiver pauses the run at boot, a stopwatch that spanned a
reboot can show a fabricated segment.
happens when the reboot *is* detected, not a guarantee; until a
`BOOT_COMPLETED` receiver pauses the run at boot — the receiver itself arrives
in M3, the stopwatch's own repair in M7 — a stopwatch that spanned a reboot can
show a fabricated segment.
---
@@ -444,8 +445,8 @@ metadata holder service.
| `AlarmScheduler`, the exact-alarm plumbing, snooze state (schema **v2**, with a tested migration) | M3 |
| Any UI, ViewModel or navigation beyond the theme | M4+ |
| Alarm edit surface, ringtone picker, per-alarm override UI | M5 |
| `BOOT_COMPLETED` / `TIME_SET` receivers — the authoritative repair after a reboot | M6 |
| The ringing foreground service, full-screen intent, notifications | M6/M7 |
| `BOOT_COMPLETED` / `TIME_SET` receivers — the authoritative repair after a reboot | M3 |
| The ringing foreground service, full-screen intent, notifications | M3 (timers reuse its audio path in M6) |
| Stopwatch presentation, best/worst lap analysis | M7 |
| ICU city and zone display names, offsets, day differences | M8 |
| The `android.provider.AlarmClock` intent surface and its hostile-extra validation (`TimeOfDay.clamped` and `Zones.normalise` exist so M9 has something to call) | M9 |