Files
AutoFilm-ESP32/docs/megaplans/audit/A02-auto-advance.md
gronod 8f7db974fa
ci / test (push) Successful in 1m10s
ci / firmware (wroom, sdkconfig.wroom, esp32) (push) Successful in 3m32s
ci / firmware (jc4827w543, sdkconfig.s3, esp32s3) (push) Successful in 3m42s
Mark A02 status DONE
2026-09-17 07:30:48 +01:00

3.6 KiB

A02 — restore auto-advance (auto-arm next step after complete)

STATUS: DONE DEPENDS: A01 Notes: stop_disables_motor_and_resume final assertion updated to ST_ARMED — the "unchanged" list cannot hold once auto-advance is on (resume-to-complete auto-arms step 1).

READ: this file, docs/megaplans/AUDIT-MEGAPLAN.md, docs/audit_remediation_plan.md item 3, docs/CURRENT_STATE.md §Runtime behaviour, components/app_machine/app_machine.c, tests/host/test_machine.c

Semantics (implement exactly): legacy run==1 in src/menu.cpp chained startProcessing(), which displayed Ent:start Esc:quit for the next step — i.e. auto-ARM, never auto-run. maybe_auto_advance() already implements this: on the completing tick it moves to ST_ARMED for s_step+1 (emitting EVT_STEP_ARMED), or ST_IDLE + EVT_PROCESS_IDLE after the last step. ST_COMPLETE becomes transient inside the completing tick — the alarm (hal_audio_alarm_complete, ~7.5 s async, self-terminating) plays while the next step sits armed. That is acceptable and intentional: do not add alarm_cancel to start_running and do not block on the melody.

IN:

  1. app_machine.c: set s_auto_advance = true in app_machine_init. Nothing else in the state machine changes.
  2. Keep the ST_COMPLETE + CMD_STOP alarm-cancel branch in app_machine_handle_cmd — it becomes unreachable while auto-advance is on, but stays as a defensive path.
  3. Rework tests/host/test_machine.c for transient COMPLETE (Custom has 4 steps, ECN-2 RemJet is step 1, C41 Prewarm is step 0):
    • arm_start_complete_custom_10s: after tick(10000) expect ST_ARMED and step_index == 1 (auto-armed next step); drop the tick(10001) "stays complete" assertion.
    • Replace stop_during_complete_cancels_alarm with auto_advance_last_step_goes_idle: select Custom, cmd_arm(3), cmd_start(3), tick(0), tick(10000) → ST_IDLE; drain events and assert EVT_PROCESS_IDLE present.
    • ecn2_remjet_zero_time: after tick(0) expect ST_ARMED at step index 2.
    • c41_clock: after tick(180000) expect ST_ARMED at step index 1.
    • All other cases unchanged (select_c41_step_view, adjust_does_not_mutate_const, stop_disables_motor_and_resume, return_from_stopped, stop_ignored_meaningless_in_idle).
    • Note: complete_step still emits EVT_STEP_COMPLETE before EVT_STEP_ARMED/EVT_PROCESS_IDLE; tests may assert that ordering via pop_ids if convenient.
  4. docs/megaplans/REFACTOR-MEGAPLAN.md: add a one-line Notes entry recording that the auto_advance default-false freeze is superseded by AUDIT A02 (owner-approved via audit item 3). Do not rewrite the frozen-constraint text itself.

OUT: CMD_TOGGLE_AUTO_ADVANCE (rejected by owner), any UI/input changes, NVS, recipe values.

FORBIDDEN: auto-starting the next step's motor; removing the ST_COMPLETE STOP branch; changing recipe tables; editing the frozen-constraint lines of REFACTOR-MEGAPLAN.

VERIFY:

cmake -S tests/host -B build/host && cmake --build build/host && ctest --test-dir build/host --output-on-failure

All green, including the new auto_advance_last_step_goes_idle. Firmware builds run in CI on push.

COMMITS:

  1. Restore auto-advance to arm next step after step complete
  2. Update machine tests for auto-advance

DoD checkboxes:

  • s_auto_advance = true; auto-ARM only, never auto-run.
  • Last step completes → ST_IDLE + EVT_PROCESS_IDLE.
  • ST_COMPLETE + CMD_STOP branch retained.
  • REFACTOR-MEGAPLAN supersede note added.
  • Host ctest green.
  • STATUS → DONE here and in the megaplan table.