fix(batm3): get cash-in working — EBDS escrow latch + correct serial device paths #79
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/ebds-escrow-stack-latch"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Cash-in ("Buy Bitcoin") did not work on the batm3: the bill validator refused notes, and once it did read one the note hung in escrow, was never credited, and was not returned. Diagnosed live on the machine — it was two stacked bugs, both fixed here and validated end-to-end on real hardware.
1. Wrong validator device path (
fix(config),eafdce3)The batm3 preset pointed the EBDS validator at
/dev/ttyACM0(assuming a CDC-ACM BNR Advance). The actual MEI acceptor enumerates as a USB-serial device and is exposed via the stable udev symlink/dev/ttyMEI(batm3.nix, serialA9YW78OC). Because/dev/ttyACM0never existed,hal-servicesilently skipped the validator and logged[HAL] No validator — cash-in disabled, so inserted bills were ignored.2. EBDS stack/return never latched (
fix(hal),4d0e42f)In EBDS the stack/return decision is carried as bits in the omnibus poll command, but the driver sent
stack()/reject()as a one-shot frame while a free-running 100 ms poller kept sending plain polls. The lone stack frame raced/collided and got dropped, so the device held the note in escrow indefinitely;disable()didn't release it either (inactivity timeout stranded the bill).pendingAction) into the poll command byte and re-assert it every poll until the device leaves escrow (cleared in_processon!escrowed). A dropped frame is simply retried next poll.disableValidator()(cancel / inactivity timeout / leaving the insert screen).3. Robustness: stable dispenser path (
fix(config),2c71d9d)Dispenser used the raw
/dev/ttyUSB0(enumeration-order dependent). Switched to the stable/dev/ttyF56symlink so both peripherals bind by identity and survive re-enumeration — including on an internal-SATA flash (the udev rules live in the sharedbatm3.nix, so both the USB and SATA images get them).Also
[ATM] Sending event/[ATM] Statelogs — they printed[object Object], which blinded the cash-in trace.Validation (on the batm3)
Return path also confirmed: cancel/timeout →
Returning escrowed bill on disable→escrowed → returning → returned, bill physically ejected.Verified:
@bitSpire/halbuilds, machine appvue-tsctypechecks clean. No unit tests exist for this serial driver; behaviour confirmed on hardware.Follow-ups (not in this PR)
[EBDS] … autonomously returning — watch for torn billsheuristic false-positives when we command a return on disable.🤖 Generated with Claude Code