feat(cassettes): consume the machine's operation acknowledgements
The machine echoes the operation ids it has applied in its state document, and this records them. That echo is the only acknowledgement this transport can carry: an addressable event gives its publisher no failure signal at all, since the relay returns OK for an event it then discards. Without it the dashboard could only ever show an operation as sent, never as delivered. Deliberately not gated on whether the state event advanced the counts. The machine echoes its applied ids on every publish, heartbeats included, so an event carrying nothing new about the counts can still be the first one to tell us an operation landed. The consumer goes in before the producer on purpose. The machine does not send applied_ops yet, and every new field on the state payload defaults to a value meaning "this machine does not report that yet" rather than to one that would be wrong — an absent list reads as nothing acknowledged, which is exactly right for a machine that has applied nothing. Also picks up seq and counts_uncertain_since, which the machine already publishes and this side was dropping on the floor. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
90bd43d6da
commit
3d8368bcc4
3 changed files with 124 additions and 13 deletions
37
models.py
37
models.py
|
|
@ -721,22 +721,41 @@ class CassettePayloadRow(BaseModel):
|
|||
|
||||
|
||||
class PublishCassettesPayload(BaseModel):
|
||||
"""The decrypted JSON content of a kind-30078 cassette event, both
|
||||
directions:
|
||||
- operator → ATM (d-tag `bitspire-cassettes:<atm_pubkey_hex>`)
|
||||
- ATM → operator (d-tag `bitspire-cassettes-state:<atm_pubkey_hex>`)
|
||||
"""The decrypted content of the ATM → operator state document
|
||||
(d-tag `bitspire-cassettes-state:<atm_pubkey_hex>`).
|
||||
|
||||
Wire shape: `{"positions": {"<pos_str>": {"denomination", "count"}}}`.
|
||||
JSON object keys are always strings; the validator coerces back to
|
||||
int on parse. The position key set MUST match what the receiver
|
||||
already has (slot count is hardware-fixed; no add/remove from this
|
||||
payload).
|
||||
It carried the operator → ATM direction too until v2 moved that to
|
||||
PublishCassetteOpsPayload. This is now the machine reporting what it
|
||||
holds, and the machine is the only writer of those counts.
|
||||
|
||||
Wire shape: `{"positions": {"<pos_str>": {"denomination", "count"}}}`
|
||||
plus the optional fields below. JSON object keys are always strings; the
|
||||
validator coerces back to int on parse.
|
||||
|
||||
No denomination-unique constraint: multiple same-denom cassettes are
|
||||
operationally valid (cash-out throughput on a popular denom).
|
||||
|
||||
The optional fields are all absent on older machines, so every one of them
|
||||
defaults to a value meaning "this machine does not report that yet" rather
|
||||
than to a value that would be wrong:
|
||||
|
||||
- `applied_ops`: operation ids the machine has applied. This is the
|
||||
acknowledgement, and the only one an addressable event can carry — a
|
||||
relay returns OK for an event it then discards, so the publisher is
|
||||
never told anything. An empty list reads as "nothing acknowledged",
|
||||
which is correct for a machine that has not yet applied any.
|
||||
- `seq`: the machine's own monotonic counter, bumped on every local count
|
||||
change. Regression detection independent of created_at, which is only
|
||||
second-granular and can be forced by a bad clock.
|
||||
- `counts_uncertain_since`: set when a dispense ended without the
|
||||
dispenser reporting what it moved, so the counts above are the
|
||||
machine's best guess rather than a measurement.
|
||||
"""
|
||||
|
||||
positions: dict[int, CassettePayloadRow]
|
||||
applied_ops: list[str] = []
|
||||
seq: int | None = None
|
||||
counts_uncertain_since: int | None = None
|
||||
|
||||
@validator("positions", pre=True)
|
||||
def coerce_string_keys_to_int(cls, v):
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue