Commit Graph

4 Commits

Author SHA1 Message Date
Grant
406bad8fbe docs: record corrected in-mission recovery intent, top-priority FSM rework, paused W1 button, build fix
v2.26, same-day continuation of v2.25:

- Records the DIR-7 in-mission-recovery intent correction just made in
  docs/design_intent_register.md v1.4 (255096f): the condition-clear-commits-
  to-recovery entry trigger built earlier today (2a3e577) is KNOWN-WRONG —
  it produced a contradictory live state (W1 GREEN while the vehicle sat in
  RETURN_TO_SAFE). Corrected model (pointer to the DIR, not duplicated):
  GREEN is unconditionally a working state; committed recovery is triggered
  by fault persistence/recurrence, never by condition-clear.

- Marks the FSM entry-trigger rework as the new top-priority NEXT item,
  ahead of everything previously listed. Confirmed Working, Open Items, and
  PARKED sections rewritten so nothing claims mode-aware recovery works
  correctly end to end — the mode-awareness mechanism (2a3e577) and the
  safe-zone-reached arrival exit (bf815cc) are both confirmed correct and
  unaffected; only entry into committed recovery was wrong.

- Records the W1 safe-zone-reached button as PAUSED, not abandoned: the
  rov_api endpoint and external/rov-failsafe-state variable are built and
  committed (2def2b1), the pre-edit W1 widget backup exists, but the widget
  edit itself was not started since the FSM state it would surface is
  currently known-wrong.

- Records a recurring rov_mission build failure, root-caused and fixed:
  stray nested build/install/log directories inside src/rov-autonomy
  (from colcon being run from the wrong directory) collided with the real
  workspace at /data/ros2_ws. Local filesystem cleanup only, no git change.
  Durable guard recorded: colcon build only ever from /data/ros2_ws.

New §15g narrative section; Recent Commits, Version History, and Changelog
all updated. Documentation only — no code, widget, or DIR file touched in
this commit. Not uploaded to Claude project knowledge; that remains a
manual step.
2026-07-13 18:13:14 +02:00
Grant
255096f20b docs(dir): correct inverted DIR-7 in-mission-recovery intent to count-based fault-persistence model
The 11 Jul DIR-7 addendum "In-mission recovery is mode-dependent" stated
that AUV gate mode commits to recovery ON CONDITION-CLEAR. That was
inverted and wrong — it produced a contradictory GREEN-while-in-
RETURN_TO_SAFE state observed live.

Corrected intent (v1.4, 13 Jul 2026, attributed to Grant):
- GREEN is unconditionally a working state. A cleared fault returns the
  vehicle to GREEN and the mission continues/resumes; a cleared condition
  must never trigger or commit a recovery. Committed recovery is triggered
  by a fault PERSISTING or RECURRING, never by it clearing.
- Three-tier fault model: (1) uncontrollable — power loss / anything that
  disables the safety logic itself, out of scope for the FSM, adjacent to
  shelved DIR-6; (2) transient/self-resetting — system attempts restore,
  returns to GREEN and resumes on success, each failure increments a raw
  count (deliberately no time window/duration), commits to RETURN_TO_SAFE
  only once the count exceeds a configured acceptable number; (3)
  hard/persistent — a RED that doesn't clear, commits immediately without
  waiting on a count.
- All thresholds (acceptable count, transient-vs-hard classification) are
  configuration-driven via the resolved mode profile, same as health_role,
  never hardcoded.
- Survives, correct: health_role mode-awareness (2a3e577); the
  safe-zone-reached arrival-exit mechanism (bf815cc) — its role (completing
  a committed recovery) is unchanged. Retired, known-wrong: 2a3e577's
  condition-clear entry logic, which bf815cc built its exit on top of —
  pending next-session rework into the count-based model. Only the ENTRY
  into committed recovery was wrong, not the exit.

New Parked Design Item: adaptive restart-timing — monitor own restore
count/duration per fault, log it, weigh future restart attempts against
observed history rather than a fixed time. Deliberately holds all
time/duration sophistication kept out of the count-based correction;
depends on the count-based retry machinery existing first. Design-captured,
not yet specified for build.

Changelog and known-implementation-drift callout updated accordingly —
failsafe_monitor's current condition-clear logic is now flagged as a known
implementation gap pending rework, not merely an unimplemented addendum.

Documentation only — no code or widget files touched. Not uploaded to
Claude project knowledge; that remains a manual step.
2026-07-13 18:02:42 +02:00
Grant
0eca8fef11 docs: record 13 Jul session — mode-system launch fix, gate-mode arrival event, safe-zone-reached parked item
docs/handover.md v2.25:
- mode_profile_loader found never wired into rov_full.launch.py despite being
  committed 7 Jul (4e48dc2) — /rov/mode/profile had zero publishers at
  runtime since; fixed with respawn (464e17e), verified live (0->1)
- failsafe_monitor's mode-aware recovery (2a3e577) surfaced a second gap:
  gate-mode RETURN_TO_SAFE was a terminal trap; closed by the new permanent
  /rov/nav/safe_zone_reached interface (bf815cc), verified live end-to-end
  on the bench; today's publisher is temporary bench scaffolding only
- new §15f narrative section; §0 Confirmed Working, PARKED, NEXT, Recent
  Commits, Version History, and Changelog all updated accordingly
- two pre-existing failsafe_monitor defects found this session (not caused
  by it), flagged in §0 Open Items and §15f: flag_manual_abort is a
  one-way latch never reset (shadows all lower-priority handling after any
  manual abort — field-deployment concern); failsafe_monitor produces no
  log output in journalctl (cost diagnostic time this session)

docs/design_intent_register.md v1.3:
- new Parked Design Item: mode-aware safe-zone-reached arrival event —
  permanent /rov/nav/safe_zone_reached interface, mode-aware/sensor-derived
  arrival judgement (GPS at surface + EKF/dead-reckoning underwater), GPS
  recorded as first-class across mission types (not hull/jacket-specific),
  gate-only scope, temporary W1-button bench-scaffolding publisher pending
  navigation — cross-referenced to the DIR-7 "in-mission recovery is
  mode-dependent" addendum, whose Implementation note is updated to record
  the mechanism is no longer mode-blind (2a3e577)

Not uploaded to Claude project knowledge — that remains a manual step.
2026-07-13 11:55:52 +02:00
Grant
5551173b7a docs: restructure into docs/, CLAUDE.md rules-only, DIR v1.2, handover v2.24 2026-07-11 18:46:58 +02:00