Files
Enelix-EMS/docs/netplan-v4-corrected-feedback.md
T

109 lines
6.4 KiB
Markdown

# V4 corrected physical feedback -> local bounded control
## Scope of this delivery
The shared physical feedback reader is now connected to the actual Manager preview,
the existing explicit bounded-trial command path, and an independent reread in the
Battery module immediately before hardware output. This is not a new observer.
The installer leaves both local trial permissions disabled and cannot arm a server
trial. Normal operation continues through the existing local controller.
Lihrenmoos binding: Manager 17004, Battery 44234, virtual asset
`anlage01-virtual-ev`. Effective 161.44 kWh / 39 kW unchanged. Source definitions
come from the existing versioned capture config and current saved topology, not
from new guessed device models. No old histories, sender cursors, virtual energy
accounts, SDL requests, archive policies or inverter polling are changed.
## Feedback and meaning
`NetzfahrplanV4Rueckmeldung` checks original value timestamps and object identities
in two read passes. Live max age is bounded to 60s and inter-source skew to 30s.
History interpolation/publication estimates are not accepted as live feedback.
The mapping fingerprint normalizes numbers and ordering, so a JSON property round
trip does not create a new identity. A mapping change cancels an active session.
Two adapters exist: sum of explicitly assigned physical meters, and a virtual
EV/SDL partition model. For the latter, gateway state and current requests are
read but unchanged zero commands are not mistaken for failed sensor heartbeats.
When SDL request is exactly zero, current physical battery power is used rather
than the filtered virtual EV display. A new EV request does not invent an immediate
physical response or force the measured sign toward the desired sign.
When SDL is nonzero, source timestamps must cover the latest request change and
physical tracking error must remain within the configured small tolerance. The
partition is explicitly estimated, not separately measured. Opposing EV/SDL flows
cannot be uniquely identified; they remain ineligible for trial control. Unknown
or stale physical sources never fall back to held filtered EV values.
`allowEstimatedForTrial` is false in the prepared Lihrenmoos config. Configuring
feedback or seeing a valid preview therefore does NOT accept the estimate for a
trial and does NOT satisfy accounting/device-watchdog evidence or other gates.
This adapter does not claim to resolve arbitrary simultaneous SDL activity.
## Actual control integration
The same coherent grid/battery snapshot is used in the Manager. Battery command
is a TOTAL power, not a delta added to the existing command. Planned changes in
other consumers are counted once and remain explicitly separate from measured grid.
A separate explicit server authority, both local consents, accounting evidence,
device-watchdog evidence, a deliberate session start and fresh plan remain required.
The existing trial is limited to 1800s / 5000W per direction; individual command
leases remain <=10s and cannot be renewed by replay or ordinary manager messages.
The local feedback mapping fingerprint and grid caps are bound to the session.
Immediately before writing, Battery rereads physical feedback and applies current
SOC, reserve, hysteresis, availability and change-lock constraints. Its resulting
command must still meet the bound grid limits; an unreachable target revokes the
trial rather than claiming that the planned grid value was achieved. It cannot
claim physical performance merely because a register call returned successfully.
Abort revokes the lease and attempts zero, and the Manager wrapper then runs at
most one fresh ordinary allocation, clearing cached pre-trial targets. It does
not recurse forever or revive an old plan. A failed stop stays explicitly failed.
The watchdog still requires a functioning kernel. Independent hardware failure
behavior is NOT certified by software tests.
Outside a V4 session the existing battery power path is unchanged. The compatible
BatterieRegler library includes the already developed optional reserve charging
limit; with its default (maximal charge) 13,824 old/new ordinary-offer test cases
match exactly. That comparison is not an on-device dynamics test.
## Installation
A single prepared Symcon script is the next runtime action:
require '/srv/agent/netplan-v4-feedback-stage/install.php';
It hash-checks nine changed files and all version-matched dependencies, backs up
existing source, installs dependencies before modules and reloads the ENELIX
library. Reload/ApplyChanges may execute existing initialization routines; this
is not promised to be a zero-effect library reload. It configures only the new
feedback mapping on Battery. No server redeployment is required. No shared classes
are included from staging, avoiding the earlier duplicate-class problem.
A delayed module-registration result requests one repeat. A valid installation
can still report an unavailable feedback sample; that is not reinterpreted as zero.
Any preexisting trial permission, unsaved change, or concurrent source change stops
the installer. Source write failure rolls back its own changed files; reload errors
are reported for review and do not automatically authorize anything.
## Validation and remaining acceptance
125 isolated PHP functional checks cover the reader, real receiver, actual trial
traits with a simulated register driver, the extracted actual Manager fallback
wrapper, and the real Battery message builder with optional diagnostic variables absent.
Source quality is stored internally; a last partition estimate is not relabelled as a
measured value just because a trial ends or a diagnostic variable is hidden. Four full module linkage checks and ten isolated installer scenarios also
pass. Full PHP syntax and dependency hashes are checked. Neither these fixtures nor
the ordinary-offer comparison run the real Symcon kernel or an inverter.
Evidence: test host `/srv/agent/netplan-v4-feedback-stage/PREPARATION.json`,
`TEST_RESULTS.txt`, `INSTALLER_TEST_RESULTS.json`, `ORDINARY_OFFER_TEST.json`.
Runtime installation, real feedback reception, and a separately authorized field
trial remain outstanding. This finishes the code connection for bounded control;
it is NOT an unrestricted continuous-production controller or a hardware
commissioning certificate. Corrected model selection and actual real-world savings
must be checked against their own data. Existing safety gates are not bypassed.