feat(machine): add renderer watchdog for kiosk resilience

After 6 days of uptime the Electron renderer silently crashed while the
main process kept running (blank screen, no recovery). Three-layer
detection: render-process-gone (instant), unresponsive (Chromium), and
IPC heartbeat (30s ping, 2 missed = reload). Reloads renderer via
loadFile/loadURL preserving HAL hardware state in main process.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-19 17:27:58 -04:00
commit 3ab03d05ac
4 changed files with 77 additions and 0 deletions

View file

@ -26,6 +26,13 @@ const formattedBtcPrice = computed(() => {
})
onMounted(async () => {
// Watchdog: respond to heartbeat pings from main process
if (window.electronAPI?.onWatchdogPing) {
window.electronAPI.onWatchdogPing(() => {
window.electronAPI!.watchdogPong()
})
}
try {
if (isElectron) {
await atmStore.initializeForProduction()

View file

@ -60,6 +60,8 @@ declare global {
onHalBillInserted: (callback: (denomination: number) => void) => void
onHalBillRejected: (callback: (reason: string) => void) => void
onHalError: (callback: (error: string) => void) => void
onWatchdogPing: (callback: () => void) => void
watchdogPong: () => Promise<void>
platform: NodeJS.Platform
}
}