Skip to content

STP-SIM-001 Deterministic Simulation Protocol

Status: Final draft prepared for handoff (pending review; pod-sim scenario slice expanded) Version: 0.22 Owner: BionicLoop engineering Prepared by: BionicLoop engineering Reviewer: ____
Approver: ____
Decision date: ____
Effective date: ____
Baseline freeze SHA: ____
Last updated: 2026-06-23 13:19 EDT

Revision History

Version Date Author Summary of Changes
0.1 2026-03-27 Engineering Initial deterministic simulation protocol draft
0.9 2026-04-06 BionicLoop engineering Added handoff-ready document-control metadata for the software package
0.10 2026-06-23 BionicLoop engineering Added provisional pod-simulation scaffold coverage IDs and evidence-suite expectations
0.11 2026-06-23 BionicLoop engineering Added first pod-simulation scenario-campaign slice for issued-dose live attribution, replacement-pod assumed delivery, and schedule-weighted fallback replay
0.12 2026-06-23 BionicLoop engineering Expanded pod-simulation scenario slice for lost final meal response before refresh, stale cached idle rejection, old-pod replacement dosing, and meal/fallback delta partitioning
0.13 2026-06-23 BionicLoop engineering Added pod-simulation coverage for canceled and consecutive-canceled meal evidence into next meal announcements, user-escaped unavailable-pod assumed delivery, fallback-maintenance live-command blocking, and relaunch fallback replay with unavailable CGM
0.14 2026-06-23 BionicLoop engineering Added explicit pod-simulation coverage for unresolved correction-only and basal-only doses without recoverable pod identity
0.15 2026-06-23 BionicLoop engineering Added pod-simulation coordinator coverage for ambiguous fallback restore without replay or modeled-dose injection
0.16 2026-06-23 BionicLoop engineering Added pod-simulation coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption
0.17 2026-06-23 BionicLoop engineering Added pod-simulation coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state
0.18 2026-06-23 BionicLoop engineering Added pod-simulation coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure
0.19 2026-06-23 BionicLoop engineering Added pod-simulation coordinator coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row
0.20 2026-06-23 BionicLoop engineering Added app-layer recent-dose persistence/display coverage for merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units
0.21 2026-06-23 BionicLoop engineering Added local step CSV export coverage for replay evidence source, disposition, and failure-reason fields on fallback replay rows
0.22 2026-06-23 BionicLoop engineering Added runtime cloud step-event emission parity coverage for merged fallback replay evidence fields

1. Purpose

Define the protocol for deterministic medium-fidelity simulation runs used to verify runtime safety logic before real-device execution.

2. Scope

This protocol owns:

  • TV-SIM-001
  • TV-SIM-002
  • TV-SIM-003
  • TV-SIM-004
  • TV-SIM-005
  • provisional pod-simulation scaffold/scenario rows TV-SIM-POD-001..004

It complements, but does not replace, real-device validation.

3. References

4. Roles

  • Author: BionicLoop engineering
  • Executor: engineering or QA delegate
  • Reviewer: quality / design assurance
  • Approver: submission-quality owner

5. Prerequisites

  • Deterministic simulation harness is buildable and runnable
  • Scenario fixtures are locked for the run label
  • Output directory is defined in formal or working STR lane before execution

6. Environment

  • Host: macOS development workstation
  • Tooling: simulation harness scripts and checked-in project/package state
  • No live hardware required

7. Procedure

7.1 Setup

  1. Record git SHA, harness script version, and output path.
  2. Select formal vs working evidence lane.
  3. Record scenario seed and fixture set for the run.

7.2 Execution

  1. Execute the simulation harness for all required TV-SIM-* scenarios.
  2. Capture generated:
  3. run context
  4. expected outputs
  5. actual outputs
  6. diffs
  7. summarized results
  8. Review failures for determinism, not just exit-code status.

7.3 Failure / Deviation Handling

  1. If output is nondeterministic, record as harness/protocol failure before accepting behavioral conclusions.
  2. If a scenario is missing required artifacts, rerun is required.

8. Expected Results

  • Each TV-SIM-* scenario produces a complete STR-style artifact bundle.
  • Runtime cadence, degraded-input, BG/meal interplay, and alert churn expectations match stored expected outputs.
  • Pod-simulation scaffold/scenario rows produce suite-level STR artifacts for stateful pod ledger math, first reconciliation paths, same-pod live attribution without replay, replacement-pod assumed-delivered replay, and schedule-weighted fallback replay. The expanded scenario slice also covers lost final meal response before status refresh, stale cached idle rejection, old-pod replacement dosing, unresolved correction-only and basal-only assumed-delivered replacement-pod dosing, and meal/fallback delta partitioning, reservoir-capped partial meal delivery using actual delivered units, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, meal/fallback overlap coordinator replay that merges the partitioned meal dose into the first fallback-active replay row, plus ambiguous fallback restore that produces no replay rows and no aggregate modeled fallback dose on the live step, assumed old-pod fallback replay with no replay pump commands before replacement-pod live dosing, missing-status/nonreplayable fallback-plan clearing, and cleanup of matching pending meal-progress state when issued-dose evidence is consumed. App-layer recent-dose coverage also preserves and displays merged meal/fallback replay source, disposition, request step, requested units, and delivered units after local telemetry reload; local step CSV export also preserves replay evidence source, disposition, and failure-reason fields, and runtime cloud step-event emission publishes the same replay evidence fields before the resumed live row. Detailed per-scenario pod ledger traces remain a planned extension before these rows can be treated as a complete pod-simulation campaign.

If cloud-log review support is used for a simulation run, start an Integration Log Session in Home Settings before the scenario begins and stop it immediately after completion.

9. Pass / Fail Criteria

  • Pass when all selected simulation scenarios pass and generate complete traceable artifacts.
  • Fail when any scenario output diverges without approved rationale or artifacts are incomplete.

10. Evidence to Capture

  • run-context
  • results
  • expected
  • actual
  • diff
  • scenario-to-test trace map
  • if cloud-log review support was used:
  • test_run_id
  • UTC time window
  • selected upload threshold
  • explicit note that the session was started before execution and stopped after execution
  • STR target path:
  • Docs/Quality/Evidence/Formal/STR-SIM-001/<run-label>/

11. Traceability

TV-* ID Purpose
TV-SIM-001 Anchored cadence across reconnect/relaunch
TV-SIM-002 Step-0 gate and degraded CGM execution
TV-SIM-003 Pump-unavailable command-block behavior
TV-SIM-004 Meal/BG/reconnect timing interplay
TV-SIM-005 Alert lifecycle churn / dedupe / clear
TV-SIM-POD-001 Stateful pod ledger bolus, fallback-mask, expiry, and replacement math
TV-SIM-POD-002 Issued-dose restoration/replay through simulated pod status
TV-SIM-POD-003 Fallback delta partition safety when a meal completed before fallback baseline
TV-SIM-POD-004 First high-risk pod scenario slice: canceled and consecutive-canceled meal evidence into next meal announcements, force-quit/relaunch in-flight meal restoration, lost final response before status refresh, same-pod live attribution, reservoir-capped partial meal attribution, different/new-pod, user-escaped unavailable-pod, and unresolved correction-only/basal-only assumed delivery, stale cached idle rejection, fallback-maintenance bolus blocking, meal/fallback partitioning, schedule-weighted fallback replay, pending fallback replay on relaunch with unavailable CGM, ambiguous fallback restore with no replay or modeled-dose injection, assumed old-pod fallback replay with replacement-pod live dosing, missing-status/nonreplayable fallback-plan clearing, pending meal-progress cleanup after matching issued-dose evidence consumption, and app-layer recent-dose, local step CSV, and runtime cloud step-event evidence-label persistence/display for merged meal/fallback replay