109 lines
6.4 KiB
Markdown
109 lines
6.4 KiB
Markdown
# V4 corrected physical feedback -> local bounded control
|
|
|
|
## Scope of this delivery
|
|
|
|
The shared physical feedback reader is now connected to the actual Manager preview,
|
|
the existing explicit bounded-trial command path, and an independent reread in the
|
|
Battery module immediately before hardware output. This is not a new observer.
|
|
The installer leaves both local trial permissions disabled and cannot arm a server
|
|
trial. Normal operation continues through the existing local controller.
|
|
|
|
Lihrenmoos binding: Manager 17004, Battery 44234, virtual asset
|
|
`anlage01-virtual-ev`. Effective 161.44 kWh / 39 kW unchanged. Source definitions
|
|
come from the existing versioned capture config and current saved topology, not
|
|
from new guessed device models. No old histories, sender cursors, virtual energy
|
|
accounts, SDL requests, archive policies or inverter polling are changed.
|
|
|
|
## Feedback and meaning
|
|
|
|
`NetzfahrplanV4Rueckmeldung` checks original value timestamps and object identities
|
|
in two read passes. Live max age is bounded to 60s and inter-source skew to 30s.
|
|
History interpolation/publication estimates are not accepted as live feedback.
|
|
The mapping fingerprint normalizes numbers and ordering, so a JSON property round
|
|
trip does not create a new identity. A mapping change cancels an active session.
|
|
|
|
Two adapters exist: sum of explicitly assigned physical meters, and a virtual
|
|
EV/SDL partition model. For the latter, gateway state and current requests are
|
|
read but unchanged zero commands are not mistaken for failed sensor heartbeats.
|
|
When SDL request is exactly zero, current physical battery power is used rather
|
|
than the filtered virtual EV display. A new EV request does not invent an immediate
|
|
physical response or force the measured sign toward the desired sign.
|
|
|
|
When SDL is nonzero, source timestamps must cover the latest request change and
|
|
physical tracking error must remain within the configured small tolerance. The
|
|
partition is explicitly estimated, not separately measured. Opposing EV/SDL flows
|
|
cannot be uniquely identified; they remain ineligible for trial control. Unknown
|
|
or stale physical sources never fall back to held filtered EV values.
|
|
|
|
`allowEstimatedForTrial` is false in the prepared Lihrenmoos config. Configuring
|
|
feedback or seeing a valid preview therefore does NOT accept the estimate for a
|
|
trial and does NOT satisfy accounting/device-watchdog evidence or other gates.
|
|
This adapter does not claim to resolve arbitrary simultaneous SDL activity.
|
|
|
|
## Actual control integration
|
|
|
|
The same coherent grid/battery snapshot is used in the Manager. Battery command
|
|
is a TOTAL power, not a delta added to the existing command. Planned changes in
|
|
other consumers are counted once and remain explicitly separate from measured grid.
|
|
|
|
A separate explicit server authority, both local consents, accounting evidence,
|
|
device-watchdog evidence, a deliberate session start and fresh plan remain required.
|
|
The existing trial is limited to 1800s / 5000W per direction; individual command
|
|
leases remain <=10s and cannot be renewed by replay or ordinary manager messages.
|
|
The local feedback mapping fingerprint and grid caps are bound to the session.
|
|
|
|
Immediately before writing, Battery rereads physical feedback and applies current
|
|
SOC, reserve, hysteresis, availability and change-lock constraints. Its resulting
|
|
command must still meet the bound grid limits; an unreachable target revokes the
|
|
trial rather than claiming that the planned grid value was achieved. It cannot
|
|
claim physical performance merely because a register call returned successfully.
|
|
|
|
Abort revokes the lease and attempts zero, and the Manager wrapper then runs at
|
|
most one fresh ordinary allocation, clearing cached pre-trial targets. It does
|
|
not recurse forever or revive an old plan. A failed stop stays explicitly failed.
|
|
The watchdog still requires a functioning kernel. Independent hardware failure
|
|
behavior is NOT certified by software tests.
|
|
|
|
Outside a V4 session the existing battery power path is unchanged. The compatible
|
|
BatterieRegler library includes the already developed optional reserve charging
|
|
limit; with its default (maximal charge) 13,824 old/new ordinary-offer test cases
|
|
match exactly. That comparison is not an on-device dynamics test.
|
|
|
|
## Installation
|
|
|
|
A single prepared Symcon script is the next runtime action:
|
|
|
|
require '/srv/agent/netplan-v4-feedback-stage/install.php';
|
|
|
|
It hash-checks nine changed files and all version-matched dependencies, backs up
|
|
existing source, installs dependencies before modules and reloads the ENELIX
|
|
library. Reload/ApplyChanges may execute existing initialization routines; this
|
|
is not promised to be a zero-effect library reload. It configures only the new
|
|
feedback mapping on Battery. No server redeployment is required. No shared classes
|
|
are included from staging, avoiding the earlier duplicate-class problem.
|
|
|
|
A delayed module-registration result requests one repeat. A valid installation
|
|
can still report an unavailable feedback sample; that is not reinterpreted as zero.
|
|
Any preexisting trial permission, unsaved change, or concurrent source change stops
|
|
the installer. Source write failure rolls back its own changed files; reload errors
|
|
are reported for review and do not automatically authorize anything.
|
|
|
|
## Validation and remaining acceptance
|
|
|
|
125 isolated PHP functional checks cover the reader, real receiver, actual trial
|
|
traits with a simulated register driver, the extracted actual Manager fallback
|
|
wrapper, and the real Battery message builder with optional diagnostic variables absent.
|
|
Source quality is stored internally; a last partition estimate is not relabelled as a
|
|
measured value just because a trial ends or a diagnostic variable is hidden. Four full module linkage checks and ten isolated installer scenarios also
|
|
pass. Full PHP syntax and dependency hashes are checked. Neither these fixtures nor
|
|
the ordinary-offer comparison run the real Symcon kernel or an inverter.
|
|
|
|
Evidence: test host `/srv/agent/netplan-v4-feedback-stage/PREPARATION.json`,
|
|
`TEST_RESULTS.txt`, `INSTALLER_TEST_RESULTS.json`, `ORDINARY_OFFER_TEST.json`.
|
|
|
|
Runtime installation, real feedback reception, and a separately authorized field
|
|
trial remain outstanding. This finishes the code connection for bounded control;
|
|
it is NOT an unrestricted continuous-production controller or a hardware
|
|
commissioning certificate. Corrected model selection and actual real-world savings
|
|
must be checked against their own data. Existing safety gates are not bypassed.
|