Files
AutoFilm-ESP32/docs/megaplans/AUDIT-MEGAPLAN.md
gronod cfd047a0ac
ci / test (push) Successful in 1m24s
ci / firmware (wroom, sdkconfig.wroom, esp32) (push) Failing after 7m23s
ci / firmware (jc4827w543, sdkconfig.s3, esp32s3) (push) Failing after 7m24s
Mark A04 status DONE
2026-09-17 09:47:01 +01:00

4.4 KiB
Raw Permalink Blame History

AUDIT MEGAPLAN — develop-branch defect remediation

Audience: coding agent. One phase = one session. Do not start the next phase in the same session.

Source

Implements docs/audit_remediation_plan.md — five defects found in the post-refactor develop tree: step deadline computed from a fake now, non-thread-safe UI event ring, auto-advance regression, implicit task-watchdog setup, and a blocking DS18B20 conversion in hal_temp_tick.

Protocol (every session)

  1. git checkout feature/audit-remediation && git pull --ff-only
  2. Read only: AGENTS.md, this file (status table), the assigned phase file, and the audit doc items it cites. Open docs/CURRENT_STATE.md / docs/TARGET_ARCHITECTURE.md / docs/CICD.md only if the phase READ: list says so.
  3. Execute IN only. Honour OUT and FORBIDDEN.
  4. Run VERIFY exactly. Do not push if any verify item fails. Local verify = host ctest; firmware builds run in Gitea CI on push (feature/** is a push trigger — see .gitea/workflows/ci.yml).
  5. Commits: messages listed in the phase. Imperative. One concern per commit.
  6. Push origin feature/audit-remediation. PR target is develop, not main.
  7. Set phase STATUS: to DONE in the phase file and this table. One-line Notes if you diverged (API name only — do not silently change behaviour).

If blocked: stop, commit nothing broken, write BLOCKED: at top of the phase file with the exact error.

Frozen constraints (never reinterpret)

  • Recipe values (times s, CW, CCW, temp min/pref/max) for C41 E6 ECN-2 B&W Custom B&WREV = components/app_process/app_process.c / docs/CURRENT_STATE.md. Changing values requires explicit user order + doc update in the same commit.
  • Stop while running: Esc 'X' (keypad r4c4) and touch STOP on S3 → immediate motor EN disabled, then Resume or ReturnToStepSelect. hal_motor_request_stop runs before any other work on the stop path.
  • UI never blocks on motor, OneWire, or audio.
  • No Arduino types in ui_cmd, app_process, app_machine public headers.
  • Watchdog stays on — A03 makes setup explicit, it does not disable anything. No vTaskDelete of long-lived workers.
  • Session time edits ±5 s are RAM overlays only. No NVS profiles. No pumps/valves/heaters.
  • Auto-advance: REFACTOR-MEGAPLAN froze auto_advance default false "unless a later phase says so" — A02 is that phase (audit item 3, owner-approved). Semantics = legacy run==1 chain: auto-ARM the next step, never auto-run; the operator still presses Start per step.
  • Event queue semantics change (accepted): a full event queue now drops the newest event (xQueueSend timeout 0); the old ring overwrote the oldest. UI drains at 40 Hz vs ≤~1.3 Hz producers — overflow is not expected.

Branch

feature/audit-remediation cut from develop → PRs into develop. (feature/** is required for the CI push trigger.)

Working-tree note

The branch was cut with uncommitted components/app_machine/app_machine.c changes present: they implement audit items 1–2 plus the item-3 flag flip. A01 lands items 1–2 with s_auto_advance reverted to false; A02 lands the flag. Do not commit the whole dirty file in one go — split per concern (git add -p or re-apply in order).

Status

ID File Session goal STATUS
A00 audit/A00-docs.md Land audit doc + megaplan + phase files DONE
A01 audit/A01-machine-timing-queue.md Deadline fix + FreeRTOS event queue + host queue shim DONE
A02 audit/A02-auto-advance.md Restore auto-arm after step complete + test rework DONE
A03 audit/A03-task-wdt.md Explicit TWDT init/reconfigure + add() failure logging DONE
A04 audit/A04-temp-nonblocking.md OPTIONAL: non-blocking DS18B20 conversion DONE

Dependency

A00 → A01 → A02    (same file; A02 builds on A01's queue + tests)
A03 is independent of A01/A02 (main.c only) — run any time after A00
A04 runs after A03 (shares temp_task in main.c); OPTIONAL — skipping is acceptable

Do not

  • Expand scope: no CMD_TOGGLE_AUTO_ADVANCE (rejected by owner), no UI changes, no NVS, no pumps/heater, no recipe edits.
  • Commit sdkconfig (generated), build/, build_host/, tokens.
  • Batch unrelated fixes into a phase.
  • Reduce the TWDT timeout below the blocking bound while hal_temp_tick still blocks (~750 ms); A04 removes that constraint.