feat(cassettes): persist the machine's counts-uncertain marker
The machine has been publishing counts_uncertain_since since v1 of the state document and spirekeeper has been parsing it into a field nobody read. That defeats the point of the marker: it exists so a human opens the bay and recounts. A dispenser can throw, or time out, after notes have physically moved. The machine cannot know how many left, so rather than decrement a number it would be guessing at, it stamps the moment (bitspire ADR-004, decision 3). m014 gives that stamp a home on dca_machines, and the consumer mirrors it on every state event. Stored on the machine rather than the bay because the uncertainty is about the dispense as a whole; a multi-bay dispense that fails midway gives no reliable way to attribute it to one position. Written through even when the machine reports None. The machine clearing the marker is as important as setting it — the operator recounted, the bay is trustworthy again — and a banner that never goes away is a banner nobody reads.
This commit is contained in:
parent
2ac3e2064e
commit
c76a1bb125
5 changed files with 112 additions and 1 deletions
32
tasks.py
32
tasks.py
|
|
@ -339,6 +339,7 @@ async def _cassette_consumer_tick(current_filter_key: str | None) -> str:
|
|||
get_machine_by_atm_pubkey_hex,
|
||||
list_all_active_machines,
|
||||
mark_cassette_ops_acked,
|
||||
set_machine_counts_uncertain,
|
||||
)
|
||||
|
||||
machines = await list_all_active_machines()
|
||||
|
|
@ -375,6 +376,7 @@ async def _cassette_consumer_tick(current_filter_key: str | None) -> str:
|
|||
get_machine_by_atm_pubkey_hex,
|
||||
apply_reported_state,
|
||||
mark_cassette_ops_acked,
|
||||
set_machine_counts_uncertain,
|
||||
)
|
||||
except Exception as exc:
|
||||
logger.warning(
|
||||
|
|
@ -410,11 +412,38 @@ async def _record_op_acknowledgements(
|
|||
)
|
||||
|
||||
|
||||
async def _record_counts_uncertainty(
|
||||
machine_id: str, payload, set_machine_counts_uncertain
|
||||
) -> None:
|
||||
"""Mirror the machine's counts-uncertain marker onto its registry row.
|
||||
|
||||
The machine sets this when a dispense ended without a reliable count of
|
||||
what physically left the bay — a dispenser throw, or a timeout. It cannot
|
||||
know how many notes moved, so it says so instead of decrementing a number
|
||||
it would be guessing at.
|
||||
|
||||
Written on every state event, including when it is None, because the
|
||||
machine clearing the marker is exactly as important as setting it: the
|
||||
operator has recounted, the bay is trustworthy again, and a banner that
|
||||
never goes away is a banner nobody reads.
|
||||
"""
|
||||
from datetime import datetime as _datetime
|
||||
from datetime import timezone as _timezone
|
||||
|
||||
since = None
|
||||
if payload.counts_uncertain_since is not None:
|
||||
since = _datetime.fromtimestamp(
|
||||
int(payload.counts_uncertain_since), tz=_timezone.utc
|
||||
)
|
||||
await set_machine_counts_uncertain(machine_id, since)
|
||||
|
||||
|
||||
async def _handle_cassette_state_event(
|
||||
event_message,
|
||||
get_machine_by_atm_pubkey_hex,
|
||||
apply_reported_state,
|
||||
mark_cassette_ops_acked,
|
||||
set_machine_counts_uncertain,
|
||||
) -> None:
|
||||
"""Verify signature, resolve the operator's signer, decrypt via the
|
||||
signer abstraction (bunker round-trip for RemoteBunkerSigner; direct
|
||||
|
|
@ -526,5 +555,6 @@ async def _handle_cassette_state_event(
|
|||
)
|
||||
|
||||
# Acknowledgement runs regardless of whether the counts were newer — see
|
||||
# _record_op_acknowledgements for why.
|
||||
# _record_op_acknowledgements for why. Same for the uncertainty marker.
|
||||
await _record_op_acknowledgements(machine.id, payload, mark_cassette_ops_acked)
|
||||
await _record_counts_uncertainty(machine.id, payload, set_machine_counts_uncertain)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue