docs(simulation): accept S1B real provider lifecycle
This commit is contained in:
parent
6cb14954d4
commit
a78c8c83f5
26
README.md
26
README.md
|
|
@ -151,20 +151,23 @@ a new linked run/episode. This is repository-level lifecycle acceptance only;
|
|||
PX4 command delivery, watchdog/failsafe behavior, navigation behavior and real
|
||||
actuator control remain unaccepted.
|
||||
|
||||
The next S1B repository increment adds the transport-neutral
|
||||
The S1B repository increment adds the transport-neutral
|
||||
`SimulationApplicationService`, an exact-S0/D-only worker admission guard and a
|
||||
POSIX process supervisor. Start is idempotent, a second active owner is
|
||||
rejected, provider processes receive dedicated PGIDs and run-scoped logs, and
|
||||
shutdown follows the S0 dependency order with residue reported as failure.
|
||||
Pause/resume/step/reset/stop are owned by the application service through a
|
||||
worker port. Stock-rover provider specs, target-worker execution and PX4/Gazebo
|
||||
control mapping are still pending factual acceptance.
|
||||
worker port.
|
||||
|
||||
Commit `630d1ae` has passed the first D-only `MissionCore-Sim` bootstrap
|
||||
(`20 passed`, no retained test process). The first visible milestone is now
|
||||
split explicitly: UI-0 is a read-only direct run view after real target
|
||||
start/stop/recovery is proven; the top-level Polygon control surface remains
|
||||
gated on S1 command and safety acceptance.
|
||||
Commit `6cb1495` has now passed the real D-only `MissionCore-Sim` S1B lifecycle:
|
||||
the exact immutable source generation started Micro XRCE-DDS Agent and the PX4
|
||||
v1.17.0/Gazebo Harmonic stock Ackermann rover in a fresh loopback-only
|
||||
namespace, admitted the run only after world/startup/DDS-writer health markers,
|
||||
and stopped both owned PGIDs with zero residue. The persisted run reached
|
||||
`completed`, contains eight lifecycle events and zero control commands. This
|
||||
opens UI-0 implementation; live pause/resume/step/reset, canonical telemetry,
|
||||
PX4 command mapping, watchdog/failsafe evidence and the top-level Polygon
|
||||
control surface remain gated.
|
||||
|
||||
See the [Polygon product/SRS](docs/12_SIMULATION_POLYGON_PRODUCT_AND_SRS.md),
|
||||
[ADR 0015](docs/adr/0015-simulation-polygon-qualification-boundary.md) and the
|
||||
|
|
@ -268,9 +271,10 @@ standalone release install. The frontend consumes sibling `file:` packages from
|
|||
revision or content hash. Publishing/vendoring those packages or enforcing an
|
||||
immutable donor revision remains a packaging and CI prerequisite.
|
||||
|
||||
Polygon is planned as a seventh section, but UI delivery is gated on the
|
||||
accepted clock/frame/authority contracts and a proven S1 backend lifecycle with
|
||||
persisted run history. It is not present in the current shell.
|
||||
Polygon is planned as a seventh section. The read-only direct UI-0 run view is
|
||||
now permitted by the accepted S1B backend lifecycle and persisted run history,
|
||||
but is not yet present in the current shell. Top-level Polygon navigation and
|
||||
control remain gated on accepted clock/frame/command/safety behavior.
|
||||
|
||||
The Observation spatial workspace embeds the open-source Rerun Web Viewer
|
||||
inside the Mission Core shell. It can open a compatible RRD over same-origin
|
||||
|
|
|
|||
|
|
@ -24,7 +24,7 @@ Each gate produces evidence and an explicit GO, PAUSE or BLOCKED result.
|
|||
| Plugin isolation | GO (laboratory control plane) — vendor backend/frontend and optional scene controls are plugin-owned; manifest/runtime descriptor parity, versioned handshake, lifecycle health and transport correlation fail closed while execution remains in-process |
|
||||
| K1 application control | GO (physical staged cycle) — after fixing the PCAP-proven `sint64` time field, one explicit UI launch completed all 14 canonical operations on one control session, reached live `SCANNING + project + init_ready`, displayed real points, then one explicit STOP returned K1 to unbound `READY`. No retry or fallback command was sent. Native-project reuse through LixelGO/USB remains an independent verification |
|
||||
| Stage 8 product storage | PAUSE — retention, replication, encryption, capacity monitoring and long-run browser/WASM stress remain deployment gates |
|
||||
| Simulation Polygon | SIM S0 GO; S1A complete; S1B ownership foundation passed target bootstrap — exact commit `630d1ae` runs inside D-only `MissionCore-Sim` with 20 target tests and zero test-process residue. Target stock-rover provider specs/execution, PX4 command delivery, telemetry/frames, watchdog/failsafe evidence, navigation/safety acceptance and real actuator authority remain absent. UI-0 is planned after target lifecycle; top-level Polygon remains gated |
|
||||
| Simulation Polygon | SIM S0 GO; S1A complete; S1B real-provider lifecycle PASS — exact commit `6cb1495` passed 25 target tests and one D-only loopback stock-Ackermann run. Mission Core admitted world/startup/DDS health, persisted eight events, sent zero commands and stopped both PGIDs with zero residue. UI-0 implementation is now unblocked. Pause/resume/step/reset, PX4 command delivery, canonical telemetry/frames, watchdog/failsafe, navigation/safety acceptance and real actuator authority remain absent; top-level Polygon remains gated |
|
||||
|
||||
USB project copying remains optional ground truth rather than a blocker for the
|
||||
now-verified network path. Owner-operated LixelGO traffic verifies the MQTT
|
||||
|
|
@ -152,11 +152,15 @@ Without the exact admitted target-worker evidence its correct result remains
|
|||
`INCOMPLETE`. S1 starts from the accepted S0 version/storage/time/process
|
||||
boundary. Its S1A increment implements server-owned immutable run identity,
|
||||
legal lifecycle transitions, canonical rover command envelopes, authority/TTL
|
||||
admission, append-only artifacts and restart reconciliation. The local S1B
|
||||
increment adds idempotent application lifecycle, single active ownership, an
|
||||
exact-profile/D-only worker guard and deterministic POSIX PGID supervision.
|
||||
Target provider launch/control, PX4 delivery, heartbeat/watchdog execution and
|
||||
captured failsafe outcomes remain the next S1 increments.
|
||||
admission, append-only artifacts and restart reconciliation. The S1B increment
|
||||
adds idempotent application lifecycle, single active ownership, an
|
||||
exact-profile/D-only worker guard, health-gated real provider specs and
|
||||
deterministic POSIX PGID supervision. Exact generation `6cb1495` passed on
|
||||
`MissionCore-Sim`: Micro XRCE-DDS Agent and PX4/Gazebo stock rover ran inside a
|
||||
fresh loopback-only namespace, the run reached `completed`, and both provider
|
||||
groups stopped without residue. Live world control, PX4 command delivery,
|
||||
heartbeat/watchdog execution and captured failsafe outcomes remain the next S1
|
||||
increments.
|
||||
|
||||
## Stage 0 — repository and host baseline
|
||||
|
||||
|
|
|
|||
|
|
@ -62,6 +62,10 @@ Polygon is now a parallel product branch. As of this document:
|
|||
- all nine digest-bound S0 evidence claims validate and the target doctor
|
||||
returns `GO` for profile SHA-256
|
||||
`aeecf5005301db230e1340b85215cbbd862b72974a22b8c43767c28be8453e2f`;
|
||||
- S1B exact generation `6cb1495` has passed a product-owned real-provider
|
||||
lifecycle in a fresh loopback-only namespace: two provider PGIDs, explicit
|
||||
world/startup/DDS-writer readiness, eight persisted events, zero commands,
|
||||
terminal `completed` and zero process residue;
|
||||
- `actuator_authority=false`;
|
||||
- `navigation_or_safety_accepted=false`.
|
||||
|
||||
|
|
@ -557,17 +561,28 @@ The next local increment implements the provider-neutral ownership boundary:
|
|||
- failure, profile drift or process residue becomes a persisted terminal
|
||||
failure rather than a successful stop.
|
||||
|
||||
This is a tested local foundation, not S1B target acceptance. Concrete
|
||||
Gazebo/PX4/XRCE/ROS provider specs, loopback namespace creation, target
|
||||
health probes, post-restart PID identity reconciliation and live
|
||||
pause/step/reset evidence remain open. The application service's port can be
|
||||
implemented worker-locally without turning SSH or an operator shell into the
|
||||
product data plane.
|
||||
The first target adapter now supplies concrete Micro XRCE-DDS Agent and combined
|
||||
PX4/Gazebo stock-rover specs. Readiness is an executable contract: the Agent
|
||||
must be listening, while PX4 must report the exact rover world/model, completed
|
||||
startup and a `vehicle_status_v1` DDS writer. PX4 stdin remains open without
|
||||
sending a command, so its shell cannot enter an EOF prompt loop. Provider logs
|
||||
are read incrementally, all argv are shell-free, and every provider owns a
|
||||
dedicated PGID.
|
||||
|
||||
The exact commit `630d1ae` has passed the first target bootstrap inside
|
||||
`MissionCore-Sim`: its immutable Git archive was admitted under D, both S1 test
|
||||
modules returned `20 passed`, and no test process residue remained. This proves
|
||||
target executability of the ownership foundation, not the real provider graph.
|
||||
The exact commit `6cb1495` passed `25` target tests and the real
|
||||
`s1b-6cb1495-20260724t1535z` lifecycle inside `MissionCore-Sim`. Its immutable
|
||||
Git archive SHA-256 is
|
||||
`37da47744e855bb1031734893a6f2dd82bb4eb92b7e15edd70794c29b2dfb451`.
|
||||
Mission Core persisted the admitted/starting/running/stopping/completed history,
|
||||
started `micro-xrce-dds-agent` plus `px4-gazebo-stock-rover`, observed an XRCE
|
||||
session and PX4 DDS writer, sent zero control commands, and stopped with no
|
||||
registry or `/proc` residue. Evidence is D-only and digest indexed under
|
||||
`/mnt/d/NDC_MISSIONCORE/simulation/artifacts/s1/lifecycle/`.
|
||||
|
||||
This accepts the S1B target start/health/stop boundary and unlocks UI-0. It does
|
||||
not accept restart-safe PID/start-token reconciliation, live
|
||||
pause/resume/step/reset, canonical VehicleState, frame conversion, rover command
|
||||
mapping, watchdog/failsafe cases, repeatability or S1 as a whole.
|
||||
|
||||
### S2
|
||||
|
||||
|
|
@ -609,8 +624,8 @@ Two UI gates are intentionally distinct.
|
|||
|
||||
### UI-0 — early read-only run view
|
||||
|
||||
After target S1B proves persisted start/stop/recovery history, a direct internal
|
||||
run view may expose:
|
||||
Target S1B now proves persisted start/health/stop history. A direct internal run
|
||||
view may expose:
|
||||
|
||||
- run identity, lifecycle and terminal reason;
|
||||
- authoritative clock and current pause/running state;
|
||||
|
|
|
|||
|
|
@ -2,9 +2,9 @@
|
|||
|
||||
## Status
|
||||
|
||||
Accepted for architecture; SIM S0 qualification returned `GO` on 2026-07-24.
|
||||
Navigation behavior, safety behavior and real actuator authority are not
|
||||
accepted.
|
||||
Accepted for architecture; SIM S0 qualification returned `GO` and the S1B
|
||||
real-provider start/health/stop boundary passed on 2026-07-24. Navigation
|
||||
behavior, safety behavior and real actuator authority are not accepted.
|
||||
|
||||
## Context
|
||||
|
||||
|
|
@ -102,6 +102,22 @@ resolved/accepted pins and all required evidence. On the accepted profile
|
|||
generation and nine-claim confined evidence set it returned `GO`; it cannot
|
||||
infer that result from repository state alone.
|
||||
|
||||
## S1B target lifecycle
|
||||
|
||||
Exact generation `6cb1495` is the first product-owned real-provider acceptance.
|
||||
`SimulationApplicationService` persisted the lifecycle while the worker adapter
|
||||
created a fresh loopback-only namespace and `PosixProcessSupervisor` owned two
|
||||
dedicated PGIDs: Micro XRCE-DDS Agent and the combined PX4/Gazebo stock
|
||||
Ackermann launch. The run became `running` only after the exact world/model,
|
||||
PX4 startup and DDS-writer markers existed. No arm, setpoint or other PX4 shell
|
||||
command was sent. Stop produced `completed`, eight events, zero commands and no
|
||||
process residue.
|
||||
|
||||
This decision accepts UI-0 implementation against persisted run history. It
|
||||
does not widen command authority or accept pause/step/reset, canonical
|
||||
telemetry, frame conversion, watchdog/failsafe behavior, navigation or physical
|
||||
control.
|
||||
|
||||
## S1A implementation
|
||||
|
||||
`k1link.simulation.contracts` now defines the first product-owned
|
||||
|
|
|
|||
|
|
@ -0,0 +1,110 @@
|
|||
# SIM S1B real-provider acceptance — 2026-07-24
|
||||
|
||||
## Result
|
||||
|
||||
`PASS` for the product-owned stock-rover start/health/stop boundary on the
|
||||
accepted `MissionCore-Sim` worker.
|
||||
|
||||
This is not S1 acceptance. It does not prove live world control, rover command
|
||||
mapping, canonical telemetry/frames, watchdog/failsafe behavior, repeatability,
|
||||
navigation behavior or real actuator safety.
|
||||
|
||||
## Accepted source generation
|
||||
|
||||
- Branch: `feat/simulation-polygon-s1`.
|
||||
- Mission Core commit:
|
||||
`6cb14954d4696270e12d4adb800bc337251dc631`.
|
||||
- Archive: `NODEDC_MISSION_CORE-s1-6cb1495.tgz`.
|
||||
- Archive SHA-256:
|
||||
`37da47744e855bb1031734893a6f2dd82bb4eb92b7e15edd70794c29b2dfb451`.
|
||||
- Source:
|
||||
`/mnt/d/NDC_MISSIONCORE/simulation/source/NODEDC_MISSION_CORE-6cb1495`.
|
||||
- Target test evidence:
|
||||
`/mnt/d/NDC_MISSIONCORE/simulation/artifacts/s1/bootstrap/20260724T153453Z-6cb1495`.
|
||||
- Target test result: `25 passed`.
|
||||
|
||||
The source was produced with `git archive` from the exact commit and an
|
||||
explicit path set. Existing S0 and earlier S1 source/evidence generations were
|
||||
not modified.
|
||||
|
||||
## Accepted run
|
||||
|
||||
- Run: `s1b-6cb1495-20260724t1535z`.
|
||||
- Evidence:
|
||||
`/mnt/d/NDC_MISSIONCORE/simulation/artifacts/s1/lifecycle/s1b-6cb1495-20260724t1535z`.
|
||||
- Host profile:
|
||||
`ai-worker-px4-gazebo-v1`.
|
||||
- Host profile SHA-256:
|
||||
`aeecf5005301db230e1340b85215cbbd862b72974a22b8c43767c28be8453e2f`.
|
||||
- Lifecycle profile SHA-256:
|
||||
`06fadcd1b55b70c9a53556dadc65d15a35d8d73f7664ebf766b9986cbe19a883`.
|
||||
- Scenario SHA-256:
|
||||
`49e8f4009bc96c40964a5657fef5c2e035f22fa567a2247b0e40571cb5e4ee5e`.
|
||||
- Network interfaces inside the run: `lo` only.
|
||||
- Provider owners:
|
||||
`micro-xrce-dds-agent`, `px4-gazebo-stock-rover`.
|
||||
- Terminal state: `completed`.
|
||||
- Terminal reason: `operator-stop-clean`.
|
||||
- Persisted events: `8`.
|
||||
- Control commands: `0`.
|
||||
- Registry residue: none.
|
||||
- Independent exact-process check after the run: no `px4`,
|
||||
`MicroXRCEAgent` or `gz`.
|
||||
- D free bytes after the run: `392023871488`, above the accepted 200 GiB stop
|
||||
floor.
|
||||
|
||||
Provider readiness was not inferred from PIDs. The admitted log evidence
|
||||
contains:
|
||||
|
||||
```text
|
||||
world: rover, model: rover_ackermann_0
|
||||
Startup script returned successfully
|
||||
successfully created rt/fmu/out/vehicle_status_v1 data writer
|
||||
session established
|
||||
```
|
||||
|
||||
PX4 stdin remained open to prevent an EOF prompt loop, but Mission Core wrote no
|
||||
PX4 shell command. The worker received no arm or actuator/setpoint request.
|
||||
|
||||
## Failed generations retained as negative evidence
|
||||
|
||||
`01ec122` stopped before starting providers because the first namespace check
|
||||
read WSL sysfs rather than the current namespace through netlink. The transient
|
||||
namespace itself contained only loopback. Source was corrected in a new
|
||||
generation; the failed generation was not retried.
|
||||
|
||||
`b4e3b3b` reached the real stock rover and XRCE session but ended
|
||||
`orchestrator-start-failed`. Its declared profile incorrectly required
|
||||
`Running, connected`, a line emitted by the S0 diagnostic CLI command rather
|
||||
than spontaneous provider health, while PX4 stdin was closed. The full failed
|
||||
run, provider logs, terminal process registry and digest index remain under:
|
||||
|
||||
```text
|
||||
/mnt/d/NDC_MISSIONCORE/simulation/artifacts/s1/lifecycle/s1b-b4e3b3b-20260724t1531z
|
||||
```
|
||||
|
||||
That generation was not retried. `6cb1495` replaced repeated full-file polling
|
||||
with incremental log readers, kept PX4 stdin open without writing commands and
|
||||
used the factual DDS-writer marker.
|
||||
|
||||
## Accepted and open boundaries
|
||||
|
||||
Accepted:
|
||||
|
||||
- exact S0 generation and D-only admission;
|
||||
- product-owned loopback namespace;
|
||||
- shell-free real provider specifications;
|
||||
- readiness-gated Mission Core start;
|
||||
- persisted run lifecycle and provider registry;
|
||||
- deterministic real-provider stop with no residue;
|
||||
- zero command/actuator authority.
|
||||
|
||||
Open:
|
||||
|
||||
- restart-safe PID/start-token reconciliation after orchestrator process loss;
|
||||
- live pause/resume/single-step/reset;
|
||||
- PX4/ROS canonical VehicleState and ENU/NED/FLU/FRD golden conversion;
|
||||
- Ackermann and Differential command mapping;
|
||||
- TTL/heartbeat/watchdog and provider-loss cases;
|
||||
- repeatability verdict and complete S1 QualificationReport;
|
||||
- UI-0 implementation, S1C/S1D and S2.
|
||||
Loading…
Reference in New Issue