feat(control): connect physical feedback to bounded V4 command and fallback paths
This commit is contained in:
@@ -0,0 +1,108 @@
|
||||
# V4 corrected physical feedback -> local bounded control
|
||||
|
||||
## Scope of this delivery
|
||||
|
||||
The shared physical feedback reader is now connected to the actual Manager preview,
|
||||
the existing explicit bounded-trial command path, and an independent reread in the
|
||||
Battery module immediately before hardware output. This is not a new observer.
|
||||
The installer leaves both local trial permissions disabled and cannot arm a server
|
||||
trial. Normal operation continues through the existing local controller.
|
||||
|
||||
Lihrenmoos binding: Manager 17004, Battery 44234, virtual asset
|
||||
`anlage01-virtual-ev`. Effective 161.44 kWh / 39 kW unchanged. Source definitions
|
||||
come from the existing versioned capture config and current saved topology, not
|
||||
from new guessed device models. No old histories, sender cursors, virtual energy
|
||||
accounts, SDL requests, archive policies or inverter polling are changed.
|
||||
|
||||
## Feedback and meaning
|
||||
|
||||
`NetzfahrplanV4Rueckmeldung` checks original value timestamps and object identities
|
||||
in two read passes. Live max age is bounded to 60s and inter-source skew to 30s.
|
||||
History interpolation/publication estimates are not accepted as live feedback.
|
||||
The mapping fingerprint normalizes numbers and ordering, so a JSON property round
|
||||
trip does not create a new identity. A mapping change cancels an active session.
|
||||
|
||||
Two adapters exist: sum of explicitly assigned physical meters, and a virtual
|
||||
EV/SDL partition model. For the latter, gateway state and current requests are
|
||||
read but unchanged zero commands are not mistaken for failed sensor heartbeats.
|
||||
When SDL request is exactly zero, current physical battery power is used rather
|
||||
than the filtered virtual EV display. A new EV request does not invent an immediate
|
||||
physical response or force the measured sign toward the desired sign.
|
||||
|
||||
When SDL is nonzero, source timestamps must cover the latest request change and
|
||||
physical tracking error must remain within the configured small tolerance. The
|
||||
partition is explicitly estimated, not separately measured. Opposing EV/SDL flows
|
||||
cannot be uniquely identified; they remain ineligible for trial control. Unknown
|
||||
or stale physical sources never fall back to held filtered EV values.
|
||||
|
||||
`allowEstimatedForTrial` is false in the prepared Lihrenmoos config. Configuring
|
||||
feedback or seeing a valid preview therefore does NOT accept the estimate for a
|
||||
trial and does NOT satisfy accounting/device-watchdog evidence or other gates.
|
||||
This adapter does not claim to resolve arbitrary simultaneous SDL activity.
|
||||
|
||||
## Actual control integration
|
||||
|
||||
The same coherent grid/battery snapshot is used in the Manager. Battery command
|
||||
is a TOTAL power, not a delta added to the existing command. Planned changes in
|
||||
other consumers are counted once and remain explicitly separate from measured grid.
|
||||
|
||||
A separate explicit server authority, both local consents, accounting evidence,
|
||||
device-watchdog evidence, a deliberate session start and fresh plan remain required.
|
||||
The existing trial is limited to 1800s / 5000W per direction; individual command
|
||||
leases remain <=10s and cannot be renewed by replay or ordinary manager messages.
|
||||
The local feedback mapping fingerprint and grid caps are bound to the session.
|
||||
|
||||
Immediately before writing, Battery rereads physical feedback and applies current
|
||||
SOC, reserve, hysteresis, availability and change-lock constraints. Its resulting
|
||||
command must still meet the bound grid limits; an unreachable target revokes the
|
||||
trial rather than claiming that the planned grid value was achieved. It cannot
|
||||
claim physical performance merely because a register call returned successfully.
|
||||
|
||||
Abort revokes the lease and attempts zero, and the Manager wrapper then runs at
|
||||
most one fresh ordinary allocation, clearing cached pre-trial targets. It does
|
||||
not recurse forever or revive an old plan. A failed stop stays explicitly failed.
|
||||
The watchdog still requires a functioning kernel. Independent hardware failure
|
||||
behavior is NOT certified by software tests.
|
||||
|
||||
Outside a V4 session the existing battery power path is unchanged. The compatible
|
||||
BatterieRegler library includes the already developed optional reserve charging
|
||||
limit; with its default (maximal charge) 13,824 old/new ordinary-offer test cases
|
||||
match exactly. That comparison is not an on-device dynamics test.
|
||||
|
||||
## Installation
|
||||
|
||||
A single prepared Symcon script is the next runtime action:
|
||||
|
||||
require '/srv/agent/netplan-v4-feedback-stage/install.php';
|
||||
|
||||
It hash-checks nine changed files and all version-matched dependencies, backs up
|
||||
existing source, installs dependencies before modules and reloads the ENELIX
|
||||
library. Reload/ApplyChanges may execute existing initialization routines; this
|
||||
is not promised to be a zero-effect library reload. It configures only the new
|
||||
feedback mapping on Battery. No server redeployment is required. No shared classes
|
||||
are included from staging, avoiding the earlier duplicate-class problem.
|
||||
|
||||
A delayed module-registration result requests one repeat. A valid installation
|
||||
can still report an unavailable feedback sample; that is not reinterpreted as zero.
|
||||
Any preexisting trial permission, unsaved change, or concurrent source change stops
|
||||
the installer. Source write failure rolls back its own changed files; reload errors
|
||||
are reported for review and do not automatically authorize anything.
|
||||
|
||||
## Validation and remaining acceptance
|
||||
|
||||
125 isolated PHP functional checks cover the reader, real receiver, actual trial
|
||||
traits with a simulated register driver, the extracted actual Manager fallback
|
||||
wrapper, and the real Battery message builder with optional diagnostic variables absent.
|
||||
Source quality is stored internally; a last partition estimate is not relabelled as a
|
||||
measured value just because a trial ends or a diagnostic variable is hidden. Four full module linkage checks and ten isolated installer scenarios also
|
||||
pass. Full PHP syntax and dependency hashes are checked. Neither these fixtures nor
|
||||
the ordinary-offer comparison run the real Symcon kernel or an inverter.
|
||||
|
||||
Evidence: test host `/srv/agent/netplan-v4-feedback-stage/PREPARATION.json`,
|
||||
`TEST_RESULTS.txt`, `INSTALLER_TEST_RESULTS.json`, `ORDINARY_OFFER_TEST.json`.
|
||||
|
||||
Runtime installation, real feedback reception, and a separately authorized field
|
||||
trial remain outstanding. This finishes the code connection for bounded control;
|
||||
it is NOT an unrestricted continuous-production controller or a hardware
|
||||
commissioning certificate. Corrected model selection and actual real-world savings
|
||||
must be checked against their own data. Existing safety gates are not bypassed.
|
||||
Reference in New Issue
Block a user