Files
AutoFilm-ESP32/docs/megaplans/AUDIT-MEGAPLAN.md
gronod cfd047a0ac
ci / test (push) Successful in 1m24s
ci / firmware (wroom, sdkconfig.wroom, esp32) (push) Failing after 7m23s
ci / firmware (jc4827w543, sdkconfig.s3, esp32s3) (push) Failing after 7m24s
Mark A04 status DONE
2026-09-17 09:47:01 +01:00

64 lines
4.4 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# AUDIT MEGAPLAN — develop-branch defect remediation
Audience: coding agent. One phase = one session. Do not start the next phase in the same session.
## Source
Implements `docs/audit_remediation_plan.md` — five defects found in the post-refactor `develop` tree: step deadline computed from a fake `now`, non-thread-safe UI event ring, auto-advance regression, implicit task-watchdog setup, and a blocking DS18B20 conversion in `hal_temp_tick`.
## Protocol (every session)
1. `git checkout feature/audit-remediation && git pull --ff-only`
2. Read only: `AGENTS.md`, this file (status table), **the assigned phase file**, and the audit doc items it cites. Open `docs/CURRENT_STATE.md` / `docs/TARGET_ARCHITECTURE.md` / `docs/CICD.md` only if the phase `READ:` list says so.
3. Execute `IN` only. Honour `OUT` and `FORBIDDEN`.
4. Run `VERIFY` exactly. Do not push if any verify item fails. Local verify = host ctest; firmware builds run in Gitea CI on push (`feature/**` is a push trigger — see `.gitea/workflows/ci.yml`).
5. Commits: messages listed in the phase. Imperative. One concern per commit.
6. Push `origin feature/audit-remediation`. PR target is `develop`, not `main`.
7. Set phase `STATUS:` to `DONE` in the phase file **and** this table. One-line `Notes` if you diverged (API name only — do not silently change behaviour).
If blocked: stop, commit nothing broken, write `BLOCKED:` at top of the phase file with the exact error.
## Frozen constraints (never reinterpret)
- Recipe **values** (times s, CW, CCW, temp min/pref/max) for C41 E6 ECN-2 B&W Custom B&WREV = `components/app_process/app_process.c` / `docs/CURRENT_STATE.md`. Changing values requires explicit user order + doc update in the same commit.
- Stop while running: Esc `'X'` (keypad r4c4) and touch STOP on S3 → immediate motor **EN disabled**, then Resume or ReturnToStepSelect. `hal_motor_request_stop` runs before any other work on the stop path.
- UI never blocks on motor, OneWire, or audio.
- No Arduino types in `ui_cmd`, `app_process`, `app_machine` public headers.
- Watchdog stays **on** — A03 makes setup explicit, it does not disable anything. No `vTaskDelete` of long-lived workers.
- Session time edits ±5 s are RAM overlays only. No NVS profiles. No pumps/valves/heaters.
- **Auto-advance**: REFACTOR-MEGAPLAN froze `auto_advance` default `false` "unless a later phase says so" — **A02 is that phase** (audit item 3, owner-approved). Semantics = legacy `run==1` chain: auto-**ARM** the next step, never auto-run; the operator still presses Start per step.
- Event queue semantics change (accepted): a full event queue now drops the **newest** event (`xQueueSend` timeout 0); the old ring overwrote the oldest. UI drains at 40 Hz vs ≤~1.3 Hz producers — overflow is not expected.
## Branch
`feature/audit-remediation` cut from `develop` → PRs into `develop`. (`feature/**` is required for the CI push trigger.)
## Working-tree note
The branch was cut with uncommitted `components/app_machine/app_machine.c` changes present: they implement audit items 1–2 **plus** the item-3 flag flip. A01 lands items 1–2 with `s_auto_advance` reverted to `false`; A02 lands the flag. Do not commit the whole dirty file in one go — split per concern (`git add -p` or re-apply in order).
## Status
| ID | File | Session goal | STATUS |
| --- | --- | --- | --- |
| A00 | `audit/A00-docs.md` | Land audit doc + megaplan + phase files | DONE |
| A01 | `audit/A01-machine-timing-queue.md` | Deadline fix + FreeRTOS event queue + host queue shim | DONE |
| A02 | `audit/A02-auto-advance.md` | Restore auto-arm after step complete + test rework | DONE |
| A03 | `audit/A03-task-wdt.md` | Explicit TWDT init/reconfigure + `add()` failure logging | DONE |
| A04 | `audit/A04-temp-nonblocking.md` | OPTIONAL: non-blocking DS18B20 conversion | DONE |
## Dependency
```
A00 → A01 → A02 (same file; A02 builds on A01's queue + tests)
A03 is independent of A01/A02 (main.c only) — run any time after A00
A04 runs after A03 (shares temp_task in main.c); OPTIONAL — skipping is acceptable
```
## Do not
- Expand scope: no `CMD_TOGGLE_AUTO_ADVANCE` (rejected by owner), no UI changes, no NVS, no pumps/heater, no recipe edits.
- Commit `sdkconfig` (generated), `build/`, `build_host/`, tokens.
- Batch unrelated fixes into a phase.
- Reduce the TWDT timeout below the blocking bound while `hal_temp_tick` still blocks (~750 ms); A04 removes that constraint.