3.6 KiB
A02 — restore auto-advance (auto-arm next step after complete)
STATUS: DONE
DEPENDS: A01
Notes: stop_disables_motor_and_resume final assertion updated to ST_ARMED — the "unchanged" list cannot hold once auto-advance is on (resume-to-complete auto-arms step 1).
READ: this file, docs/megaplans/AUDIT-MEGAPLAN.md, docs/audit_remediation_plan.md item 3, docs/CURRENT_STATE.md §Runtime behaviour, components/app_machine/app_machine.c, tests/host/test_machine.c
Semantics (implement exactly): legacy run==1 in src/menu.cpp chained startProcessing(), which displayed Ent:start Esc:quit for the next step — i.e. auto-ARM, never auto-run. maybe_auto_advance() already implements this: on the completing tick it moves to ST_ARMED for s_step+1 (emitting EVT_STEP_ARMED), or ST_IDLE + EVT_PROCESS_IDLE after the last step. ST_COMPLETE becomes transient inside the completing tick — the alarm (hal_audio_alarm_complete, ~7.5 s async, self-terminating) plays while the next step sits armed. That is acceptable and intentional: do not add alarm_cancel to start_running and do not block on the melody.
IN:
app_machine.c: sets_auto_advance = trueinapp_machine_init. Nothing else in the state machine changes.- Keep the
ST_COMPLETE+CMD_STOPalarm-cancel branch inapp_machine_handle_cmd— it becomes unreachable while auto-advance is on, but stays as a defensive path. - Rework
tests/host/test_machine.cfor transient COMPLETE (Custom has 4 steps, ECN-2 RemJet is step 1, C41 Prewarm is step 0):arm_start_complete_custom_10s: aftertick(10000)expectST_ARMEDandstep_index == 1(auto-armed next step); drop thetick(10001)"stays complete" assertion.- Replace
stop_during_complete_cancels_alarmwithauto_advance_last_step_goes_idle: select Custom,cmd_arm(3),cmd_start(3),tick(0),tick(10000)→ST_IDLE; drain events and assertEVT_PROCESS_IDLEpresent. ecn2_remjet_zero_time: aftertick(0)expectST_ARMEDat step index 2.c41_clock: aftertick(180000)expectST_ARMEDat step index 1.- All other cases unchanged (
select_c41_step_view,adjust_does_not_mutate_const,stop_disables_motor_and_resume,return_from_stopped,stop_ignored_meaningless_in_idle). - Note:
complete_stepstill emitsEVT_STEP_COMPLETEbeforeEVT_STEP_ARMED/EVT_PROCESS_IDLE; tests may assert that ordering viapop_idsif convenient.
docs/megaplans/REFACTOR-MEGAPLAN.md: add a one-lineNotesentry recording that theauto_advancedefault-false freeze is superseded by AUDIT A02 (owner-approved via audit item 3). Do not rewrite the frozen-constraint text itself.
OUT: CMD_TOGGLE_AUTO_ADVANCE (rejected by owner), any UI/input changes, NVS, recipe values.
FORBIDDEN: auto-starting the next step's motor; removing the ST_COMPLETE STOP branch; changing recipe tables; editing the frozen-constraint lines of REFACTOR-MEGAPLAN.
VERIFY:
cmake -S tests/host -B build/host && cmake --build build/host && ctest --test-dir build/host --output-on-failure
All green, including the new auto_advance_last_step_goes_idle. Firmware builds run in CI on push.
COMMITS:
Restore auto-advance to arm next step after step completeUpdate machine tests for auto-advance
DoD checkboxes:
s_auto_advance = true; auto-ARM only, never auto-run.- Last step completes →
ST_IDLE+EVT_PROCESS_IDLE. ST_COMPLETE+CMD_STOPbranch retained.- REFACTOR-MEGAPLAN supersede note added.
- Host ctest green.
- STATUS → DONE here and in the megaplan table.