docs/design_intent_register.md v1.5:
- New DIR-13 — widget-to-hardware ownership map. W1 is a two-stage health
gate: RPi4 FC-heartbeat MUST pass first (implemented, 86b2728), then RPi5
autonomy-stack self-health (not yet built) — only when both pass is W1
GREEN. W5 reflects the RPi4-connected battery. W2/W3/W4/W6/W8 reflect the
RPi5 stack; W6 deliberately kept RPi5-direct per the standalone-autonomy
principle. W7 specced, not built. Cross-references DIR-12.
- New DIR-14 — depth as a dual-source, operator-selectable input: RPi4
sensor (via the FC), an RPi5-direct sensor, or a blend, selected at
mission setup (W4) and carried in the resolved mode profile like
health_role. Redundancy plus operator choice. Design-captured, not yet
specified in detail.
docs/handover.md v2.27:
- New §9 widget-to-hardware wiring table matching the DIR-13 ownership map.
- Test-data/fault-injection capability flagged as an approaching required
workstream, not optional — the failsafe logic (and the pending count-
based FSM rework) cannot be properly tested without injecting sensor
states and simulating running-vs-failed conditions. Incremental approach
agreed: altitude/depth/sonar first. Near-term prerequisite for validating
the FSM rework; added to §0 PARKED/NEXT and §16.
- FSM rework to the corrected count-based model (255096f) reconfirmed as
top build priority — 2a3e577/bf815cc's condition-clear commit logic
remains known-wrong pending that rework. Recorded as related to, and to
be planned alongside, W1's RPi5-side health gating (DIR-13) and the
fault-injection capability above.
- Confirmed and recorded: W2 reflects live mission state (observed ABORTED
after a live abort); W3's label change to RETURN TO SAFE is complete
(9aa5b5d) — stale references to this as outstanding work corrected in
§0 Blocked/Open Items/NEXT and §16. argonaut-api.service manual-start
reminder recorded for rov_api/backend testing.
- DIR pointer section bumped to DIR-1 through DIR-14.
Documentation only — no code, widget, or diagram files touched. Not
uploaded to Claude project knowledge; that remains a manual step.
v2.26, same-day continuation of v2.25:
- Records the DIR-7 in-mission-recovery intent correction just made in
docs/design_intent_register.md v1.4 (255096f): the condition-clear-commits-
to-recovery entry trigger built earlier today (2a3e577) is KNOWN-WRONG —
it produced a contradictory live state (W1 GREEN while the vehicle sat in
RETURN_TO_SAFE). Corrected model (pointer to the DIR, not duplicated):
GREEN is unconditionally a working state; committed recovery is triggered
by fault persistence/recurrence, never by condition-clear.
- Marks the FSM entry-trigger rework as the new top-priority NEXT item,
ahead of everything previously listed. Confirmed Working, Open Items, and
PARKED sections rewritten so nothing claims mode-aware recovery works
correctly end to end — the mode-awareness mechanism (2a3e577) and the
safe-zone-reached arrival exit (bf815cc) are both confirmed correct and
unaffected; only entry into committed recovery was wrong.
- Records the W1 safe-zone-reached button as PAUSED, not abandoned: the
rov_api endpoint and external/rov-failsafe-state variable are built and
committed (2def2b1), the pre-edit W1 widget backup exists, but the widget
edit itself was not started since the FSM state it would surface is
currently known-wrong.
- Records a recurring rov_mission build failure, root-caused and fixed:
stray nested build/install/log directories inside src/rov-autonomy
(from colcon being run from the wrong directory) collided with the real
workspace at /data/ros2_ws. Local filesystem cleanup only, no git change.
Durable guard recorded: colcon build only ever from /data/ros2_ws.
New §15g narrative section; Recent Commits, Version History, and Changelog
all updated. Documentation only — no code, widget, or DIR file touched in
this commit. Not uploaded to Claude project knowledge; that remains a
manual step.
docs/handover.md v2.25:
- mode_profile_loader found never wired into rov_full.launch.py despite being
committed 7 Jul (4e48dc2) — /rov/mode/profile had zero publishers at
runtime since; fixed with respawn (464e17e), verified live (0->1)
- failsafe_monitor's mode-aware recovery (2a3e577) surfaced a second gap:
gate-mode RETURN_TO_SAFE was a terminal trap; closed by the new permanent
/rov/nav/safe_zone_reached interface (bf815cc), verified live end-to-end
on the bench; today's publisher is temporary bench scaffolding only
- new §15f narrative section; §0 Confirmed Working, PARKED, NEXT, Recent
Commits, Version History, and Changelog all updated accordingly
- two pre-existing failsafe_monitor defects found this session (not caused
by it), flagged in §0 Open Items and §15f: flag_manual_abort is a
one-way latch never reset (shadows all lower-priority handling after any
manual abort — field-deployment concern); failsafe_monitor produces no
log output in journalctl (cost diagnostic time this session)
docs/design_intent_register.md v1.3:
- new Parked Design Item: mode-aware safe-zone-reached arrival event —
permanent /rov/nav/safe_zone_reached interface, mode-aware/sensor-derived
arrival judgement (GPS at surface + EKF/dead-reckoning underwater), GPS
recorded as first-class across mission types (not hull/jacket-specific),
gate-only scope, temporary W1-button bench-scaffolding publisher pending
navigation — cross-referenced to the DIR-7 "in-mission recovery is
mode-dependent" addendum, whose Implementation note is updated to record
the mechanism is no longer mode-blind (2a3e577)
Not uploaded to Claude project knowledge — that remains a manual step.