Files
AutoFilm-ESP32/docs/megaplans/audit/A04-temp-nonblocking.md
gronod ce9d729027
ci / test (push) Successful in 1m11s
ci / firmware (jc4827w543, sdkconfig.s3, esp32s3) (push) Successful in 3m51s
ci / firmware (wroom, sdkconfig.wroom, esp32) (push) Successful in 3m53s
Tick A04 DoD checkbox after CI green
2026-09-17 10:08:33 +01:00

2.8 KiB

A04 — (OPTIONAL) non-blocking DS18B20 conversion in hal_temp

STATUS: DONE DEPENDS: A03 (shares temp_task in main/main.c)

READ: this file, docs/megaplans/AUDIT-MEGAPLAN.md, docs/audit_remediation_plan.md item 5, components/hal_temp/hal_temp.c, main/main.c

Context: hal_temp_tick() currently blocks temp_task for ~750 ms per conversion (plus 750 ms on each error path). It is safely isolated from the UI, so this is a robustness/latency improvement only — the audit itself allows keeping the block if the WDT constraint is documented (A03 does that). Implement only if the phase session chooses to spend it.

IN:

  1. components/hal_temp/hal_temp.c: turn hal_temp_tick() into a two-state machine driven by a deadline (esp_timer_get_time() / 1000, or xTaskGetTickCount()):
    • T_START: onewire_bus_reset + CMD_SKIP_ROM/CMD_CONVERT_T; on success record s_deadline_ms = now + 750 and move to T_WAIT. On any bus error: s_last_ok = false, set a ~750 ms retry deadline, stay in T_START (preserves the current retry cadence).
    • T_WAIT: if now < s_deadline_ms return immediately; else onewire_bus_reset + CMD_SKIP_ROM/CMD_READ_SCRATCH, read 9 bytes, CRC-check via existing scratch_valid, update s_last_c/s_last_ok, move back to T_START (next conversion starts on the next tick).
    • The s_bus == NULL path must also be non-blocking (s_last_ok = false, return).
    • Keep TEMP_OFFSET, scratch_valid, hal_temp_init, and hal_temp_read_c semantics unchanged.
  2. main/main.c temp_task: hal_temp_tick no longer blocks, so add vTaskDelay(pdMS_TO_TICKS(100)) at the end of the loop (~10 Hz poll) so the task always sleeps. Calling app_machine_on_temp every loop is acceptable (16-deep event queue drained at 40 Hz by ui_task); keep it unconditional to keep the diff small.
  3. Host stub components/hal_temp/stub/hal_temp.c / tests/host/stubs/hal_temp.c: no signature change — leave as-is unless the implementation forces otherwise.

OUT: additional sensors, temperature alarms, heater control, hal_temp_read_c contract changes.

FORBIDDEN: changing TEMP_OFFSET or the CRC; any vTaskDelay ≥ 750 ms left inside hal_temp_tick; blocking the UI task; removing the watchdog.

VERIFY:

cmake -S tests/host -B build/host && cmake --build build/host && ctest --test-dir build/host --output-on-failure

plus CI firmware builds for both targets.

COMMITS:

  1. Make DS18B20 conversion non-blocking in hal_temp

DoD checkboxes:

  • No vTaskDelay(750) inside hal_temp_tick; conversion waits via deadline.
  • temp_task always blocks (explicit 100 ms delay).
  • TEMP_OFFSET, CRC, and read semantics unchanged.
  • Host ctest green; both CI firmware builds green.
  • STATUS → DONE here and in the megaplan table (or noted SKIPPED with reason).