STP-SIM-001 Deterministic Simulation Protocol
Status: Final draft prepared for handoff (pending review; pod-sim scenario slice expanded)
Version: 0.22
Owner: BionicLoop engineering
Prepared by: BionicLoop engineering
Reviewer: ____
Approver: ____
Decision date: ____
Effective date: ____
Baseline freeze SHA: ____
Last updated: 2026-06-23 13:19 EDT
Revision History
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 0.1 | 2026-03-27 | Engineering | Initial deterministic simulation protocol draft |
| 0.9 | 2026-04-06 | BionicLoop engineering | Added handoff-ready document-control metadata for the software package |
| 0.10 | 2026-06-23 | BionicLoop engineering | Added provisional pod-simulation scaffold coverage IDs and evidence-suite expectations |
| 0.11 | 2026-06-23 | BionicLoop engineering | Added first pod-simulation scenario-campaign slice for issued-dose live attribution, replacement-pod assumed delivery, and schedule-weighted fallback replay |
| 0.12 | 2026-06-23 | BionicLoop engineering | Expanded pod-simulation scenario slice for lost final meal response before refresh, stale cached idle rejection, old-pod replacement dosing, and meal/fallback delta partitioning |
| 0.13 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for canceled and consecutive-canceled meal evidence into next meal announcements, user-escaped unavailable-pod assumed delivery, fallback-maintenance live-command blocking, and relaunch fallback replay with unavailable CGM |
| 0.14 | 2026-06-23 | BionicLoop engineering | Added explicit pod-simulation coverage for unresolved correction-only and basal-only doses without recoverable pod identity |
| 0.15 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for ambiguous fallback restore without replay or modeled-dose injection |
| 0.16 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption |
| 0.17 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state |
| 0.18 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure |
| 0.19 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row |
| 0.20 | 2026-06-23 | BionicLoop engineering | Added app-layer recent-dose persistence/display coverage for merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units |
| 0.21 | 2026-06-23 | BionicLoop engineering | Added local step CSV export coverage for replay evidence source, disposition, and failure-reason fields on fallback replay rows |
| 0.22 | 2026-06-23 | BionicLoop engineering | Added runtime cloud step-event emission parity coverage for merged fallback replay evidence fields |
1. Purpose
Define the protocol for deterministic medium-fidelity simulation runs used to verify runtime safety logic before real-device execution.
2. Scope
This protocol owns:
TV-SIM-001TV-SIM-002TV-SIM-003TV-SIM-004TV-SIM-005- provisional pod-simulation scaffold/scenario rows
TV-SIM-POD-001..004
It complements, but does not replace, real-device validation.
3. References
4. Roles
- Author: BionicLoop engineering
- Executor: engineering or QA delegate
- Reviewer: quality / design assurance
- Approver: submission-quality owner
5. Prerequisites
- Deterministic simulation harness is buildable and runnable
- Scenario fixtures are locked for the run label
- Output directory is defined in formal or working STR lane before execution
6. Environment
- Host: macOS development workstation
- Tooling: simulation harness scripts and checked-in project/package state
- No live hardware required
7. Procedure
7.1 Setup
- Record git SHA, harness script version, and output path.
- Select formal vs working evidence lane.
- Record scenario seed and fixture set for the run.
7.2 Execution
- Execute the simulation harness for all required
TV-SIM-*scenarios. - Capture generated:
- run context
- expected outputs
- actual outputs
- diffs
- summarized results
- Review failures for determinism, not just exit-code status.
7.3 Failure / Deviation Handling
- If output is nondeterministic, record as harness/protocol failure before accepting behavioral conclusions.
- If a scenario is missing required artifacts, rerun is required.
8. Expected Results
- Each
TV-SIM-*scenario produces a complete STR-style artifact bundle. - Runtime cadence, degraded-input, BG/meal interplay, and alert churn expectations match stored expected outputs.
- Pod-simulation scaffold/scenario rows produce suite-level STR artifacts for stateful pod ledger math, first reconciliation paths, same-pod live attribution without replay, replacement-pod assumed-delivered replay, and schedule-weighted fallback replay. The expanded scenario slice also covers lost final meal response before status refresh, stale cached idle rejection, old-pod replacement dosing, unresolved correction-only and basal-only assumed-delivered replacement-pod dosing, and meal/fallback delta partitioning, reservoir-capped partial meal delivery using actual delivered units, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, meal/fallback overlap coordinator replay that merges the partitioned meal dose into the first fallback-active replay row, plus ambiguous fallback restore that produces no replay rows and no aggregate modeled fallback dose on the live step, assumed old-pod fallback replay with no replay pump commands before replacement-pod live dosing, missing-status/nonreplayable fallback-plan clearing, and cleanup of matching pending meal-progress state when issued-dose evidence is consumed. App-layer recent-dose coverage also preserves and displays merged meal/fallback replay source, disposition, request step, requested units, and delivered units after local telemetry reload; local step CSV export also preserves replay evidence source, disposition, and failure-reason fields, and runtime cloud step-event emission publishes the same replay evidence fields before the resumed live row. Detailed per-scenario pod ledger traces remain a planned extension before these rows can be treated as a complete pod-simulation campaign.
If cloud-log review support is used for a simulation run, start an Integration Log Session in Home Settings before the scenario begins and stop it immediately after completion.
9. Pass / Fail Criteria
- Pass when all selected simulation scenarios pass and generate complete traceable artifacts.
- Fail when any scenario output diverges without approved rationale or artifacts are incomplete.
10. Evidence to Capture
run-contextresultsexpectedactualdiff- scenario-to-test trace map
- if cloud-log review support was used:
test_run_id- UTC time window
- selected upload threshold
- explicit note that the session was started before execution and stopped after execution
- STR target path:
Docs/Quality/Evidence/Formal/STR-SIM-001/<run-label>/
11. Traceability
TV-* ID |
Purpose |
|---|---|
TV-SIM-001 |
Anchored cadence across reconnect/relaunch |
TV-SIM-002 |
Step-0 gate and degraded CGM execution |
TV-SIM-003 |
Pump-unavailable command-block behavior |
TV-SIM-004 |
Meal/BG/reconnect timing interplay |
TV-SIM-005 |
Alert lifecycle churn / dedupe / clear |
TV-SIM-POD-001 |
Stateful pod ledger bolus, fallback-mask, expiry, and replacement math |
TV-SIM-POD-002 |
Issued-dose restoration/replay through simulated pod status |
TV-SIM-POD-003 |
Fallback delta partition safety when a meal completed before fallback baseline |
TV-SIM-POD-004 |
First high-risk pod scenario slice: canceled and consecutive-canceled meal evidence into next meal announcements, force-quit/relaunch in-flight meal restoration, lost final response before status refresh, same-pod live attribution, reservoir-capped partial meal attribution, different/new-pod, user-escaped unavailable-pod, and unresolved correction-only/basal-only assumed delivery, stale cached idle rejection, fallback-maintenance bolus blocking, meal/fallback partitioning, schedule-weighted fallback replay, pending fallback replay on relaunch with unavailable CGM, ambiguous fallback restore with no replay or modeled-dose injection, assumed old-pod fallback replay with replacement-pod live dosing, missing-status/nonreplayable fallback-plan clearing, pending meal-progress cleanup after matching issued-dose evidence consumption, and app-layer recent-dose, local step CSV, and runtime cloud step-event evidence-label persistence/display for merged meal/fallback replay |