64 lines
4.4 KiB
Markdown
64 lines
4.4 KiB
Markdown
# AUDIT MEGAPLAN — develop-branch defect remediation
|
||
|
||
Audience: coding agent. One phase = one session. Do not start the next phase in the same session.
|
||
|
||
## Source
|
||
|
||
Implements `docs/audit_remediation_plan.md` — five defects found in the post-refactor `develop` tree: step deadline computed from a fake `now`, non-thread-safe UI event ring, auto-advance regression, implicit task-watchdog setup, and a blocking DS18B20 conversion in `hal_temp_tick`.
|
||
|
||
## Protocol (every session)
|
||
|
||
1. `git checkout feature/audit-remediation && git pull --ff-only`
|
||
2. Read only: `AGENTS.md`, this file (status table), **the assigned phase file**, and the audit doc items it cites. Open `docs/CURRENT_STATE.md` / `docs/TARGET_ARCHITECTURE.md` / `docs/CICD.md` only if the phase `READ:` list says so.
|
||
3. Execute `IN` only. Honour `OUT` and `FORBIDDEN`.
|
||
4. Run `VERIFY` exactly. Do not push if any verify item fails. Local verify = host ctest; firmware builds run in Gitea CI on push (`feature/**` is a push trigger — see `.gitea/workflows/ci.yml`).
|
||
5. Commits: messages listed in the phase. Imperative. One concern per commit.
|
||
6. Push `origin feature/audit-remediation`. PR target is `develop`, not `main`.
|
||
7. Set phase `STATUS:` to `DONE` in the phase file **and** this table. One-line `Notes` if you diverged (API name only — do not silently change behaviour).
|
||
|
||
If blocked: stop, commit nothing broken, write `BLOCKED:` at top of the phase file with the exact error.
|
||
|
||
## Frozen constraints (never reinterpret)
|
||
|
||
- Recipe **values** (times s, CW, CCW, temp min/pref/max) for C41 E6 ECN-2 B&W Custom B&WREV = `components/app_process/app_process.c` / `docs/CURRENT_STATE.md`. Changing values requires explicit user order + doc update in the same commit.
|
||
- Stop while running: Esc `'X'` (keypad r4c4) and touch STOP on S3 → immediate motor **EN disabled**, then Resume or ReturnToStepSelect. `hal_motor_request_stop` runs before any other work on the stop path.
|
||
- UI never blocks on motor, OneWire, or audio.
|
||
- No Arduino types in `ui_cmd`, `app_process`, `app_machine` public headers.
|
||
- Watchdog stays **on** — A03 makes setup explicit, it does not disable anything. No `vTaskDelete` of long-lived workers.
|
||
- Session time edits ±5 s are RAM overlays only. No NVS profiles. No pumps/valves/heaters.
|
||
- **Auto-advance**: REFACTOR-MEGAPLAN froze `auto_advance` default `false` "unless a later phase says so" — **A02 is that phase** (audit item 3, owner-approved). Semantics = legacy `run==1` chain: auto-**ARM** the next step, never auto-run; the operator still presses Start per step.
|
||
- Event queue semantics change (accepted): a full event queue now drops the **newest** event (`xQueueSend` timeout 0); the old ring overwrote the oldest. UI drains at 40 Hz vs ≤~1.3 Hz producers — overflow is not expected.
|
||
|
||
## Branch
|
||
|
||
`feature/audit-remediation` cut from `develop` → PRs into `develop`. (`feature/**` is required for the CI push trigger.)
|
||
|
||
## Working-tree note
|
||
|
||
The branch was cut with uncommitted `components/app_machine/app_machine.c` changes present: they implement audit items 1–2 **plus** the item-3 flag flip. A01 lands items 1–2 with `s_auto_advance` reverted to `false`; A02 lands the flag. Do not commit the whole dirty file in one go — split per concern (`git add -p` or re-apply in order).
|
||
|
||
## Status
|
||
|
||
| ID | File | Session goal | STATUS |
|
||
| --- | --- | --- | --- |
|
||
| A00 | `audit/A00-docs.md` | Land audit doc + megaplan + phase files | DONE |
|
||
| A01 | `audit/A01-machine-timing-queue.md` | Deadline fix + FreeRTOS event queue + host queue shim | DONE |
|
||
| A02 | `audit/A02-auto-advance.md` | Restore auto-arm after step complete + test rework | DONE |
|
||
| A03 | `audit/A03-task-wdt.md` | Explicit TWDT init/reconfigure + `add()` failure logging | DONE |
|
||
| A04 | `audit/A04-temp-nonblocking.md` | OPTIONAL: non-blocking DS18B20 conversion | DONE |
|
||
|
||
## Dependency
|
||
|
||
```
|
||
A00 → A01 → A02 (same file; A02 builds on A01's queue + tests)
|
||
A03 is independent of A01/A02 (main.c only) — run any time after A00
|
||
A04 runs after A03 (shares temp_task in main.c); OPTIONAL — skipping is acceptable
|
||
```
|
||
|
||
## Do not
|
||
|
||
- Expand scope: no `CMD_TOGGLE_AUTO_ADVANCE` (rejected by owner), no UI changes, no NVS, no pumps/heater, no recipe edits.
|
||
- Commit `sdkconfig` (generated), `build/`, `build_host/`, tokens.
|
||
- Batch unrelated fixes into a phase.
|
||
- Reduce the TWDT timeout below the blocking bound while `hal_temp_tick` still blocks (~750 ms); A04 removes that constraint.
|