6.4 KiB
V4 corrected physical feedback -> local bounded control
Scope of this delivery
The shared physical feedback reader is now connected to the actual Manager preview, the existing explicit bounded-trial command path, and an independent reread in the Battery module immediately before hardware output. This is not a new observer. The installer leaves both local trial permissions disabled and cannot arm a server trial. Normal operation continues through the existing local controller.
Lihrenmoos binding: Manager 17004, Battery 44234, virtual asset
anlage01-virtual-ev. Effective 161.44 kWh / 39 kW unchanged. Source definitions
come from the existing versioned capture config and current saved topology, not
from new guessed device models. No old histories, sender cursors, virtual energy
accounts, SDL requests, archive policies or inverter polling are changed.
Feedback and meaning
NetzfahrplanV4Rueckmeldung checks original value timestamps and object identities
in two read passes. Live max age is bounded to 60s and inter-source skew to 30s.
History interpolation/publication estimates are not accepted as live feedback.
The mapping fingerprint normalizes numbers and ordering, so a JSON property round
trip does not create a new identity. A mapping change cancels an active session.
Two adapters exist: sum of explicitly assigned physical meters, and a virtual EV/SDL partition model. For the latter, gateway state and current requests are read but unchanged zero commands are not mistaken for failed sensor heartbeats. When SDL request is exactly zero, current physical battery power is used rather than the filtered virtual EV display. A new EV request does not invent an immediate physical response or force the measured sign toward the desired sign.
When SDL is nonzero, source timestamps must cover the latest request change and physical tracking error must remain within the configured small tolerance. The partition is explicitly estimated, not separately measured. Opposing EV/SDL flows cannot be uniquely identified; they remain ineligible for trial control. Unknown or stale physical sources never fall back to held filtered EV values.
allowEstimatedForTrial is false in the prepared Lihrenmoos config. Configuring
feedback or seeing a valid preview therefore does NOT accept the estimate for a
trial and does NOT satisfy accounting/device-watchdog evidence or other gates.
This adapter does not claim to resolve arbitrary simultaneous SDL activity.
Actual control integration
The same coherent grid/battery snapshot is used in the Manager. Battery command is a TOTAL power, not a delta added to the existing command. Planned changes in other consumers are counted once and remain explicitly separate from measured grid.
A separate explicit server authority, both local consents, accounting evidence, device-watchdog evidence, a deliberate session start and fresh plan remain required. The existing trial is limited to 1800s / 5000W per direction; individual command leases remain <=10s and cannot be renewed by replay or ordinary manager messages. The local feedback mapping fingerprint and grid caps are bound to the session.
Immediately before writing, Battery rereads physical feedback and applies current SOC, reserve, hysteresis, availability and change-lock constraints. Its resulting command must still meet the bound grid limits; an unreachable target revokes the trial rather than claiming that the planned grid value was achieved. It cannot claim physical performance merely because a register call returned successfully.
Abort revokes the lease and attempts zero, and the Manager wrapper then runs at most one fresh ordinary allocation, clearing cached pre-trial targets. It does not recurse forever or revive an old plan. A failed stop stays explicitly failed. The watchdog still requires a functioning kernel. Independent hardware failure behavior is NOT certified by software tests.
Outside a V4 session the existing battery power path is unchanged. The compatible BatterieRegler library includes the already developed optional reserve charging limit; with its default (maximal charge) 13,824 old/new ordinary-offer test cases match exactly. That comparison is not an on-device dynamics test.
Installation
A single prepared Symcon script is the next runtime action:
require '/srv/agent/netplan-v4-feedback-stage/install.php';
It hash-checks nine changed files and all version-matched dependencies, backs up existing source, installs dependencies before modules and reloads the ENELIX library. Reload/ApplyChanges may execute existing initialization routines; this is not promised to be a zero-effect library reload. It configures only the new feedback mapping on Battery. No server redeployment is required. No shared classes are included from staging, avoiding the earlier duplicate-class problem.
A delayed module-registration result requests one repeat. A valid installation can still report an unavailable feedback sample; that is not reinterpreted as zero. Any preexisting trial permission, unsaved change, or concurrent source change stops the installer. Source write failure rolls back its own changed files; reload errors are reported for review and do not automatically authorize anything.
Validation and remaining acceptance
125 isolated PHP functional checks cover the reader, real receiver, actual trial traits with a simulated register driver, the extracted actual Manager fallback wrapper, and the real Battery message builder with optional diagnostic variables absent. Source quality is stored internally; a last partition estimate is not relabelled as a measured value just because a trial ends or a diagnostic variable is hidden. Four full module linkage checks and ten isolated installer scenarios also pass. Full PHP syntax and dependency hashes are checked. Neither these fixtures nor the ordinary-offer comparison run the real Symcon kernel or an inverter.
Evidence: test host /srv/agent/netplan-v4-feedback-stage/PREPARATION.json,
TEST_RESULTS.txt, INSTALLER_TEST_RESULTS.json, ORDINARY_OFFER_TEST.json.
Runtime installation, real feedback reception, and a separately authorized field trial remain outstanding. This finishes the code connection for bounded control; it is NOT an unrestricted continuous-production controller or a hardware commissioning certificate. Corrected model selection and actual real-world savings must be checked against their own data. Existing safety gates are not bypassed.