Software Verification and Validation Plan (SVVP)¶
Status: Frozen-baseline verification plan and evidence approved for IDE submission
Version: 1.91
Owner: BionicLoop engineering
Prepared by: BionicLoop engineering
Approval reference: Edward R. Damiano, PhD, Build 843 evidence acceptance and
final software-package approval, controlled email dated 2026-09-07 EDT
Baseline freeze SHA: 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e
Last updated: 2026-09-08
Revision History¶
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 0.1 | 2026-04-05 | Engineering | Initial controlled verification draft |
| 0.9 | 2026-04-06 | BionicLoop engineering | Added document-control metadata and clarified the in-scope local security verification row |
| 0.91 | 2026-04-08 | BionicLoop engineering | Added fallback-event persistence and Recent Dose Steps review-state coverage |
| 0.92 | 2026-04-08 | BionicLoop engineering | Added pump basal-schedule interface coverage for masked offline fallback |
| 0.93 | 2026-04-08 | BionicLoop engineering | Added blocking coverage for disruptive programmed basal-schedule replacement during active bolus and active temp-basal states |
| 0.94 | 2026-04-08 | BionicLoop engineering | Added masked-fallback maintenance/disarm verification rows, active-session gating coverage, and restore-event review coverage |
| 0.95 | 2026-04-08 | BionicLoop engineering | Clarified 20-minute renewal-window verification, deferred-maintenance coverage, and pre-step masked-fallback renewal expectations |
| 0.96 | 2026-04-14 | BionicLoop engineering | Added verification rows and evidence notes for reconciliation-required blocked state after offline mask expiry |
| 0.97 | 2026-04-14 | BionicLoop engineering | Added reconnect restore/disarm retry and explicit fresh re-arm verification notes for masked-fallback recovery |
| 0.98 | 2026-04-14 | BionicLoop engineering | Updated masked-fallback reconnect-recovery verification notes for fresh-session auto-arm and preserved fallback review history |
| 0.99 | 2026-04-14 | BionicLoop engineering | Updated masked-fallback reconnect-recovery verification notes for same-session unreconciled resume on the current due slot after successful restore |
| 1.00 | 2026-04-15 | BionicLoop engineering | Added basal-only reconnect evidence, modeled-vs-pump-reported fallback review, and pre-step missing-fallback arm verification notes |
| 1.01 | 2026-04-15 | BionicLoop engineering | Added confirmed/corrected basal-only reconnect replay verification notes, coordinator replay tests, and replay-specific Home timeline review coverage |
| 1.02 | 2026-04-15 | BionicLoop engineering | Added dedicated cloud fallback telemetry verification for structured loop.fallback.event emission, duplicate suppression, and backend-facing payload mapping |
| 1.03 | 2026-04-15 | BionicLoop engineering | Added verification coverage for replayed-step propagation into local per-step telemetry / CSV export with explicit replay markers |
| 1.04 | 2026-04-27 | BionicLoop engineering | Added verification coverage that missing pump-reported delivered-insulin delta prevents fallback replay and keeps modeled expected delivery logging-only |
| 1.05 | 2026-05-06 | BionicLoop engineering | Added q5 nominal-basal profile, safety-track four-bucket fallback schedule, schedule-aware exposure, and fallback profile/schedule telemetry verification coverage |
| 1.06 | 2026-06-02 | BionicLoop engineering | Updated masked-fallback verification to pump-delta missed-step algorithm replay and added repeated no-active-pod alert coverage |
| 1.07 | 2026-06-08 | BionicLoop engineering | Added verification coverage for persisted-schedule-weighted pump-delta replay allocation, zero-weight suppression, and zero-delta replay rows |
| 1.08 | 2026-06-12 | BionicLoop engineering | Added verification coverage for generalized issued-dose attribution, replay, unresolved block, and different/new-pod no-replay disposition |
| 1.09 | 2026-06-13 | BionicLoop engineering | Added verification coverage for issued-dose delivered-unit credibility, replacement-pod live-step input scrubbing, and automatic resume blocking under active holds |
| 1.10 | 2026-06-15 | BionicLoop engineering | Updated different/new-pod issued-dose verification to assumed-delivered replay/live attribution, nonblocking replacement-pod dosing, legacy hold clearance, and meal progress modal resolution |
| 1.11 | 2026-06-17 | BionicLoop engineering | Added verification coverage for user-confirmed pod replacement from unresolved meal delivery progress with assumed-delivered evidence and non-meal suppression |
| 1.12 | 2026-06-18 | BionicLoop engineering | Added verification coverage for retired/expired/no-active-pod fallback recovery using assumed modeled fallback exposure when pump-counter evidence is no longer recoverable. |
| 1.13 | 2026-06-23 | BionicLoop engineering | Added provisional pod-simulation scenario coverage for issued-dose live attribution, lost final meal response before refresh, replacement-pod assumed-delivered replay, stale cached idle rejection, meal/fallback partitioning, stale fallback evidence suppression, and schedule-weighted fallback replay allocation. |
| 1.14 | 2026-06-23 | BionicLoop engineering | Expanded pod-simulation coverage for canceled and consecutive-canceled meal evidence feeding subsequent meal announcements, user-escaped unavailable-pod assumed evidence, fallback-maintenance command blocking before live bolus delivery, and relaunch fallback replay with unavailable CGM. |
| 1.15 | 2026-06-23 | BionicLoop engineering | Added explicit pod-simulation coverage for unresolved correction-only and basal-only issued doses without recoverable pod identity. |
| 1.16 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for ambiguous fallback restore without replay or modeled-dose injection. |
| 1.17 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption. |
| 1.18 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state. |
| 1.19 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure. |
| 1.20 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row. |
| 1.21 | 2026-06-23 | BionicLoop engineering | Added app-layer recent-dose persistence/display verification for merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units. |
| 1.22 | 2026-06-23 | BionicLoop engineering | Added local step CSV export verification for merged replay evidence source, disposition, and failure-reason fields. |
| 1.23 | 2026-06-23 | BionicLoop engineering | Added runtime cloud step-event emission verification for merged replay evidence source, disposition, request-step, requested-unit, and delivered-unit fields. |
| 1.24 | 2026-07-08 | BionicLoop engineering | Added reference-host M4 no-boundary-cancel liveness-bound coverage for DASH bolus completion, disconnect/unknown delivery state, and fresh idle issued-dose consumption. |
| 1.25 | 2026-07-08 | BionicLoop engineering | Replaced merged-overlap issued-dose coverage with pre-fallback confirm row + sentinel + seam-echo coverage (incident regression, wider-gap sentinels, echoed-ask no-room merge) plus real-C++ characterization of the bug shape, fixed shapes, and the full confirm/sentinel/fallback sequence. |
| 1.26 | 2026-07-09 | BionicLoop engineering | Replaced carousel-navigation coverage with Home alert-stack root-cause suppression coverage (generic-alert hiding, safety-critical never suppressed, unrelated untouched). |
| 1.27 | 2026-07-09 | BionicLoop engineering | Added open-composer revalidation coverage: in-place re-arm, inline fresh-reason blocked messaging, cancel-delivery precedence, continue-on-available. |
| 1.28 | 2026-07-09 | BionicLoop engineering | Added simulated-preview meal-progress exemption coverage (runtime auto-resolution never dismisses UI-test/IFU-capture preview progress; production resolution semantics unchanged). |
| 1.29 | 2026-07-09 | BionicLoop engineering | Added hidden-related-alert count coverage for the Home alert stack (SRS-ALERT-011 amendment: suppressed alerts must be counted and pointed at Alert Center). |
| 1.30 | 2026-07-09 | BionicLoop engineering | Corrected legacy evidence citations to the controlled working-evidence location and clarified that formal closure requires execution in the formal lane at the freeze SHA with required metadata. |
| 1.31 | 2026-07-10 | BionicLoop engineering | Added dual-instance isolation coverage: primary and safety algorithm copies share no state, and the 60-minute CGM-dropout window is pinned against the real C++. |
| 1.32 | 2026-07-10 | BionicLoop engineering | Independent review aligned TV-ALG-004 with the dual-instance isolation contract and SRS-ALG-008, corrected coverage placement and broken family links, aligned TV-ALERT-010 with the alert stack, aligned TV-SEC-001 with the RA-009 investigational export posture, and removed obsolete feasibility wording. |
| 1.33 | 2026-07-14 | BionicLoop engineering | Added fingerstick-BG dropout-clock characterization coverage (real C++): BG clears forced-open and restarts the full 60-minute window; design input for the CGM-outage BG-run policy (ANOM-003/RA-018). |
| 1.34 | 2026-07-14 | BionicLoop engineering | Added fingerstick-supported CGM-outage verification rows TV-OUTAGE-001..003 and pump-command-watchdog row TV-PUMP-010. Formal-lane execution was deferred to the subsequent freeze candidate. |
| 1.35 | 2026-07-14 | BionicLoop engineering | Clinical-feedback rows: TV-CLIN-014 (first-launch defaults Standard/120/75%/40) and TV-CLIN-015 (New Participant Reset store-clearing matrix + armed/active-pod refusal), covered by BionicLoopClinicalSettingsRuntimeTests and BionicLoopRuntimeEngineSessionInfrastructureTests. |
| 1.36 | 2026-07-14 | BionicLoop engineering | TV-CLIN-014/015 coverage extended: empty-store defaults-without-persist and legacy-migration-preserved pins, per-mode wizard target defaults, and post-reset first-launch-gate assertions (BionicLoopClinicalSettingsRuntimeTests, BionicLoopRuntimeEngineSessionInfrastructureTests). |
| 1.37 | 2026-07-14 | BionicLoop engineering | Independent review corrected stale test citations, aligned TV-CLIN-015 with guided stop-then-reset, clarified that TV-OUTAGE-002 uses existing fallback-replay evidence, and aligned reset terminology. |
| 1.38 | 2026-07-15 | BionicLoop engineering | TV-LOG-010 added (build-designated cloud-log profile: parse + launch-reconcile pins in the cloud-log policy and session infrastructure test classes); Scout-side ingest coverage noted (CT_J5_013 pins session-metadata preservation and app_version/build_number on the CloudWatch line). |
| 1.39 | 2026-07-15 | BionicLoop engineering | Added STP-INT-001 formative real-device integration exercises with machine-checkable signatures, telemetry and application-log evaluation, and supporting working-evidence bundles. Checker behavior was validated for empty windows and positive signature matching. |
| 1.40 | 2026-07-16 | BionicLoop engineering | TV-LOG-011 added (remote logging config parse/apply/precedence) and TV-LOG-004 reworked to the no-in-app-control posture; working-coverage bullet for the 2026-07-16 diagnostics additions (scheduler authorization-status enrichment, watchdog timeout observer, Scout route tests). |
| 1.41 | 2026-07-16 | BionicLoop engineering | TV-LOG-011 extended for the SRS-LOG-011 v1.34 amendment: periodic re-fetch loop coverage and the read-only Settings effective-state status text (precedence + source attribution), with the three new test names listed. |
| 1.42 | 2026-07-16 | BionicLoop engineering | SRS-LOG-010 supersession: TV-LOG-010 rescinded (profile/session tests deleted with the code), TV-LOG-011 re-stated for the sole-lever posture (legacy-storage-ignored, logger-honors-remote, change-observer, renamed status test), build-profile working-coverage bullet retired. |
| 1.43 | 2026-07-16 | BionicLoop engineering | TV-UI-011 added (SRS-UI-009 server-configurable investigational badge): captured-fixture parse pins, three-state effectiveText, refresh semantics, shared periodic loop over both server configs; Scout-side route/panel/badge coverage noted. |
| 1.44 | 2026-07-16 | BionicLoop engineering | TV-OUTAGE-003 extended for the SRS-OUTAGE-002 v1.37 amendment: outage-active gate truth table pinned (offline mode / relaunch blip / fingerstick / mid-BG-run / recovery / skip). |
| 1.45 | 2026-07-16 | BionicLoop engineering | Extended TV-OUTAGE-002 for SRS-OUTAGE-006 v1.38 release-window quantification under RA-020. |
| 1.46 | 2026-07-17 | BionicLoop engineering | TV-CLIN-016 added (SRS-CLIN-015 weight plausibility bounds): save-gate range, store top-clamp semantics, and algorithm last-rail clamp pinned by BionicLoopClinicalSettingsSavePolicyRuntimeTests, BionicLoopClinicalConfigStoreRuntimeTests, and RealBUDosingAlgorithmStateTests. |
| 1.47 | 2026-07-17 | BionicLoop engineering | RA-009 closure: TV-SEC-001 rewritten to the implemented sealed-export controls with concrete test symbols; TV-LOG-012 added for sequence-numbered envelopes (SRS-LOG-012; renumbered same-day from a duplicate -011 assignment). |
| 1.48 | 2026-07-17 | BionicLoop engineering | Coverage review corrected stale test-class and method citations in the deferred-validation block and TV-MEAL-009. |
| 1.461 | 2026-07-17 | BionicLoop engineering | Extended TV-CLIN-015 for the SRS-CLIN-014 telemetry drain guard: outbox counts, drain-then-count behavior, discard marker and erasure, discard-before-wipe ordering, confirmation copy, and upload-rejection alert lifecycle. (Renumbered 2026-07-21 from duplicate 1.46.) |
| 1.49 | 2026-07-18 | BionicLoop engineering | TV-OUTAGE-002 extended for the SRS-OUTAGE-006 v1.42 amendment (2026-07-18 field incident): released-window pod-away gap reconciliation via the standard bounded replay - seven scenario-suite pins covering crossover, both-links-down horizon behavior, force-quit relaunch seams, identity mismatch, zero-delta retraction replay, and insulin conservation; also added the measured real-C++ chunk-vs-replay divergence suite and the released-outage classifier-parity test. |
| 1.50 | 2026-07-18 | BionicLoop engineering | Extended TV-OUTAGE-002 after independent safety review with mid-save termination recovery, drift-skip re-synthesis, non-flat quantized weighting, profile-timezone weighting, and real-C++ ledger-conservation checks; added the Algo2015 diagnostic-artifact protection regression to TV-SEC-001. |
| 1.51 | 2026-07-18 | BionicLoop engineering | TV-ALERT-017 extended to pin the revised check-BG body copy and Home presentation policy: no inline Enter BG action, separate Home BG-entry emphasis retained, and unrelated login primary action preserved. |
| 1.52 | 2026-07-19 | BionicLoop engineering | TV-MEAL-002 and TV-ALERT-002/010 extended for exact-step pending-BG meal execution across primary/safety tracks, real-C++ forced-open recovery with combined BG + meal input, invalid/stale/pump-unavailable negative cases, and pump-signal precedence over same-severity check-BG without overriding safety-critical alerts. |
| 1.53 | 2026-07-20 | BionicLoop engineering | TV-BG-008/UI-006 extended for spatially separate exact-value BG review, value-preserving Change, and rapid-repeat-tap protection; TV-ALERT-017/OUTAGE-003 extended for direct fingerstick-request Home emphasis policy. |
| 1.54 | 2026-07-20 | BionicLoop engineering | TV-ALERT-017 extended with a rendering-regression pin proving the repeating manual-BG request emphasis changes only the localized halo while card-shadow properties remain static, including the static Reduce Motion presentation. |
| 1.55 | 2026-07-20 | BionicLoop engineering | TV-MEAL-007 extended for the SRS-MEAL-006 v1.49 consumed-carve-out amendment: decision-level pins for the consumed-carve-out inline message vs the generic backup-basal copy across both routing branches, unreconciled-issued-dose non-repaint, end-to-end pure pins for the re-closed-loop re-arm and persisting-forced-open sub-shapes (including the backupBasalRunning submit-availability passthrough), recovery re-arm/continue rows, and the carve-out capture/consumption helper truth tables (ten new test names listed in the TV-MEAL-007 coverage bullet). |
| 1.56 | 2026-07-20 | BionicLoop engineering | TV-MEAL-007 reworked for the SRS-MEAL-006 v1.50 sponsor correction: the consumed-carve-out rows now pin the transient waiting hold (passive applying notice, composer armed) while BG consumption is in flight across both routing branches, the generic backup-basal fallback once the consuming step has published, the in-flight helper truth table (cleared value plus unpublished captured target), the submit-time hold predicate, and the unchanged recovery/unreconciled pins (twelve test names listed in the TV-MEAL-007 coverage bullet, replacing the v1.49 list). |
| 1.57 | 2026-07-20 | BionicLoop engineering | Extended TV-PUMP-009 after a force-quit mid-bolus field incident: fresh same-pod post-completion evidence may upgrade capped in-progress or assumed evidence, while canceled partial, early-read, active-delivery, and different-pod cases remain guarded. (Renumbered 2026-07-21 from duplicate 1.55.) |
| 1.58 | 2026-07-21 | BionicLoop engineering | TV-LOG-009 extended for SRS-LOG-009 v1.51 (steady-cadence fallback schedule visibility): unchanged-check lean payload, per-bucket observed-slot counts, and Recent Dose Steps outcome-label/provenance rows pinned by testUnchangedScheduleCheckEventCarriesScheduleAndProfileCoverageWithoutBulkRates, testArmedEventCarriesPerBucketObservedSlotCounts, testScheduleRefreshEventCarriesFullProfilePayloadWithPerBucketCounts (new BionicLoopFallbackSchedulePayloadTests), testRecentDoseTimelineFallbackScheduleRowsShowOutcomeLabels, testRecentDoseTimelineFallbackUnchangedRowShowsScheduleSegmentsCoverageAndProvenance, testRecentDoseTimelineFallbackProvenanceMarksAllImputedAndSingleObservedBuckets (new BionicLoopRecentDoseFallbackProvenanceTests), and the extended testCloudTelemetryReporterSendsStructuredFallbackEventPayload pin; core per-bucket truth table in Q5NominalBasalProfileTests (testObservedSlotCountsByBucketAreAllZeroForEmptyProfile, testFourBucketScheduleCarriesPerBucketObservedSlotCounts, testFullyObservedDayReportsFullPerBucketObservedSlotCounts). (Corrected 2026-07-21 from erroneous 1.47.) |
| 1.59 | 2026-07-21 | BionicLoop engineering | TV-PUMP-009 fresh-completion safety regression expanded: exact cancel + relaunch + zero bolusNotDelivered adapter and engine shapes remain partial; explicit in-progress provenance still permits completion upgrade; cancellation provenance is labeled; legacy evidence without the optional context decodes and remains conservative. TV-ALERT-017 truth-synced to the accepted centered shadow bloom and no-glow Reduce Motion behavior. |
| 1.60 | 2026-07-21 | BionicLoop engineering | TV-MEAL-002 expanded for the borrowed-step forced-open transition: pure boundary tests pin blind steps 12/13, app availability pins prospective blocking and fresh-CGM/exact-BG exceptions, coordinator tests prove rejection occurs before meal persistence/algorithm/pump activity, and outage-context tests pin the qualifying-step anchor plus legacy decode compatibility. |
| 1.61 | 2026-07-22 | BionicLoop engineering | TV-MEAL-002 extended with connected-active-delivery precedence regressions: live .delivering status must map to pumpDelivering over pending meal/issued-dose attribution, while idle unresolved attribution keeps reconciliation guidance. |
| 1.62 | 2026-07-22 | BionicLoop engineering | TV-MEAL-007 extended for the intermediate-publication field regression: helper truth-table coverage pins lastExecutedStep == capturedTarget with a lagging qualifying-glucose marker as still in flight, final marker publication as complete, and a pump-delivering revalidation as replacing the transient BG/backup-basal state with connected busy-pump guidance. |
| 1.63 | 2026-07-24 | BionicLoop engineering | Added TV-CLIN-017/018 and TV-LOG-013 for Temporary Target lifecycle, primary/safety separation, replay-time target resolution, participant UI/notification behavior, Standard-to-Pregnancy meal defaulting, app telemetry, and BionicScout projection. Physical-device and formal evidence remain pending. |
| 1.64 | 2026-07-28 | BionicLoop engineering | Revised STP-INT-001 for the next formative field round: retained INT-01..10, added Temporary Target exercises INT-11/12, added pre-distribution safety checks, and required exact install identity plus signature calibration. |
| 1.65 | 2026-07-30 | BionicLoop engineering | Extended TV-CLIN-017 and alert coverage for direct suspend/resume ownership, duplicate suppression, delivery-state policy, reminders, and alert routing; added saline-Pod field drill INT-13. |
| 1.66 | 2026-07-30 | BionicLoop engineering | Extended TV-SEC-008 with persistent signed-out Home login access, actionable Alert Center and Account & Session routes, login-specific notification routing, and UI tests that preserve the active local-therapy path while returning to authentication. |
| 1.67 | 2026-07-30 | BionicLoop engineering | Extended TV-CLIN-017 with target-only and duration-only draft-loss warnings, explicit keep/discard behavior, Settings ordering, participant-reset-copy removal, and app-standard Temporary Target selector-state verification. |
| 1.68 | 2026-07-30 | BionicLoop engineering | Extended TV-UI-005 with a scroll-position regression proving Manual BG and Meal Announcement remain visible, hittable, and fixed while an expanded multi-alert Home surface scrolls. |
| 1.69 | 2026-07-30 | BionicLoop engineering | Extended TV-LOG-012 for permanent-rejection structured evidence, no generic participant alert, Subject ID Conflict alert isolation, retryable 429 behavior, backward-compatible outbox decode, and one-time launch migration of earlier-build generic alerts/notifications; removed the superseded alert-latch claim from TV-CLIN-015. |
| 1.70 | 2026-07-30 | BionicLoop engineering | Extended TV-CLIN-017 and alert verification for direct Resume Insulin action, duplicate-command suppression, retryable failure, pump-confirmed alert clearing, exact 15-minute severity escalation, relaunch recovery, non-downgrade on repeated source issue, and fresh safety-critical notification. |
| 1.71 | 2026-07-30 | BionicLoop engineering | Extended TV-MEAL-002/TV-PUMP-009 and UI coverage for suspension preflight, no algorithm/cadence/persistence side effects, immediate post-resume availability, matching-only definitive-block cache cleanup, uncertain-outcome retention, paused Home status, and the field-observed step-20 fabricated-feedback regression. |
| 1.72 | 2026-07-30 | BionicLoop engineering | Added TV-CGM-006, TV-ALERT-019, and TV-LOG-014 for explicit/persistent G7 replacement acquisition, staleness non-adoption, timed guidance, alert routing/clear behavior, and durably deduplicated stall/adoption telemetry. |
| 1.73 | 2026-07-31 | BionicLoop engineering | Extended TV-ALERT-013 with the July 31 suspension/fallback-recovery field sequence, stale blocker replacement, successful-step clearing, single-alert content transition, and suspend-ended Home precedence; extended TV-CLIN-015 with asynchronous G7 acquisition persistence/telemetry invalidation during New Participant Reset. |
| 1.74 | 2026-08-06 | BionicLoop engineering | Extended TV-LOG-001 with Recent Dose Steps verification for fingerstick provenance, exact manual BG value, concurrent CGM retention, and absent-sentinel behavior. |
| 1.75 | 2026-08-11 | BionicLoop engineering | Added TV-ALG-012 for reference-host total-insulin command construction and accepted next-step reconciliation of combined meal/basal/bolus output. |
| 1.76 | 2026-08-11 | BionicLoop engineering | Extended TV-CLIN-001 to verify the initial-configuration unlock exception closes after first save and that later Clinical Settings access/edits remain offline-unlock gated. |
| 1.77 | 2026-08-13 | BionicLoop engineering | Extended TV-LOG-012 with the August telemetry-backlog incident regressions: lossless v1-to-v2 migration, incremental writes, retained-first drain, coalesced chatter-drop markers, passive backlog status, and relaunch-stable notification-clear deduplication. |
| 1.78 | 2026-08-17 | BionicLoop engineering | Extended TV-LOG-001/012 for complete active-session step archiving and SQLite telemetry-ledger migration, uncapped retained evidence, durable-enqueue/network separation, retry liveness, 10,000-row exact-once load, and backward-compatible batch ingest. |
| 1.79 | 2026-08-20 | BionicLoop engineering | Added TV-BG-013 for the persisted pending-to-used fingerstick chart transition, original-time stability, same-step deduplication, and omission of invalid or discarded pending state. |
| 1.80 | 2026-08-20 | BionicLoop engineering | Added TV-LOG-015 for session-grouped, byte-faithful legacy Algo2015 artifact export, including partial/empty sets, live-file append boundaries, matrix-file association, ZIP naming, and presentation text. |
| 1.81 | 2026-08-20 | BionicLoop engineering | Extended TV-LOG-015 with stable single-presentation transition coverage across session selection, confirmation, preparation, share readiness, failure, and empty inventory. |
| 1.82 | 2026-08-20 | BionicLoop engineering | Replaced TV-LOG-015's obsolete Settings presentation tests with combined CSV/algorithm ZIP, exact-session isolation, CSV-only mismatch, and bounded CSV snapshot coverage through the existing Recent Dose Steps share path. |
| 1.83 | 2026-08-20 | BionicLoop engineering | Extended TV-ALERT-013 with fresh-idle-after-unavailable recovery copy, stale/non-idle/no-Pod rejection, no-work status refresh, relaunch retention, unknown-state regression, and next-success clearing. |
| 1.84 | 2026-08-20 | BionicLoop engineering | Extended TV-UI-010 with a point-only CGM presentation regression proving the connector stroke and connected area fill remain disabled. |
| 1.85 | 2026-08-21 | BionicLoop engineering | Bound the SVVP to the immutable 2026-08-21 software freeze, recorded that primary execution is complete while approval remains pending, and replaced workstation-specific script paths with controlled identifiers. No verification method or result changed. |
| 1.86 | 2026-08-21 | BionicLoop engineering | Added candidate dependency-control characterization and verification for the exact CryptoSwift 1.10.0 requirement and tracked app-workspace resolution. Recorded the passing working results without changing or promoting the exact-freeze TV-SEC-001 evidence. |
| 1.87 | 2026-08-27 | BionicLoop engineering | Replaced internal development labels, test-device shorthand, and colloquial field-test terminology with reviewer-neutral descriptions and updated the approval role. No verification method or result changed. |
| 1.88 | 2026-08-27 | BionicLoop engineering | Aligned the deferred cloud-verification condition with the approved supportive Scout scope. No verification method, result, or product behavior changed. |
| 1.89 | 2026-08-28 | BionicLoop engineering | Replaced stale draft/proposed/provisional labels with the controlled protocol and implemented simulation status, added the exact-freeze execution boundary, and corrected the canonical serial UI/app commands and requirement-family markup. No verification method, result, or product behavior changed. |
| 1.90 | 2026-09-03 | Software Developer | Recorded the post-freeze RA-023 coverage limitation: the passing G7 acquisition tests cover direct manager restoration and a single candidate, but not CGM-screen setup reentry, concurrent candidates, automatic-trigger isolation, or first-reading use before staff comparison. The exact-freeze result is unchanged; these scenarios remain open under D06. |
| 1.91 | 2026-09-03 | Software Developer | Aligned Build 843 designation, exact-freeze coverage, test identifiers, deferred claims, and controlled evidence references with the reviewer-style package audit. No test method, result, or frozen software behavior changed. |
The interim identifier 1.461 preserves the original correction of a duplicate
1.46 entry and is not a chronological renumbering error.
Working verification for revision 1.60 is pinned by MealAnnouncementOfflinePolicyTests, BionicLoopMealAnnouncementOfflineAvailabilityTests, LoopRuntimeCoordinatorMealExecutionTests.testMealAnnounceBlocksBorrowIntoProspectiveThirteenthBlindStepBeforePersistence, ...testMealAnnounceAllowsBorrowIntoTwelfthBlindStep, ...testExactStepManualBGAllowsMealOnProspectiveThirteenthBlindStep, ...testFreshCGMAllowsMealOnProspectiveThirteenthBlindStep, OutageBGRunPolicyTests.testContextRoundTripsThroughCodable, ...testContextDecodesLegacyStateWithoutQualifyingGlucoseStep, and BionicLoopRuntimeEngineOutageBGRunTests.testAcceptedCGMReanchorsTheSchedule / ...testAcceptedFingerstickReanchorsWithEscalationForHighValue.
1. Test Document Acronyms¶
Common structure used here:
SVVP: Software Verification and Validation PlanSTP: Software Test Protocol (test procedures and expected results)STR: Software Test Report (actual execution evidence)
2. Verification Strategy¶
Verification is split into:
- Unit tests (core logic, algorithm mapping, policy gates)
- Integration tests (runtime + adapters + persistence)
- System/manual tests (real-device behavior, BLE reconnection, onboarding flows)
Controlled protocol and reporting set:
STP-ALG-001STP-AUTO-001STP-SIM-001STP-HW-001STP-ALERT-001STP-TV-Ownership-MapSTR-Execution-and-Reporting-Guide
Submission-scope note:
- Device-to-cloud / BionicScout verification is not a relied-upon current submission claim and remains outside the controlled verification set unless submission scope is explicitly revised.
- For the current software package,
TV-SEC-001remains the only in-scope security verification row;TV-SEC-002..008are deferred from claimed closure in this pass.
3. Test Environments¶
- iOS Simulator for deterministic unit/integration tests.
- Physical iPhone + Dexcom G7 + OmniPod DASH for formative use and any retained connection, cadence, or physical-delivery claim. The current package does not retain a separate formal hardware-validation-study claim.
4. Entry and Exit Criteria¶
Entry:
- SRS and SDD IDs updated for proposed change.
- Risk impacts reviewed for affected paths.
Exit:
- All planned
TV-*tests pass or deviations documented. - Traceability matrix updated with evidence links (
STR-*artifacts, logs, screenshots). - No unresolved
Highseverity regressions.
4.1 Exact-Freeze Execution Boundary¶
| Lane | Current result |
|---|---|
STP-ALG-001 |
Behavioral verification passed; the 6/6 exact-freeze linkage companion closed the documentary deviation |
STP-AUTO-001 |
997 app tests: 996 passed, one intentional IFU reference-table generation helper skip gated by an export directory, zero failed; the corrected serial UI companion passed 44/44 and closed the three original harness deviations |
STP-SIM-001 |
Core, Pod, alert, and real-engine simulation lanes passed |
TV-SEC-001 |
68/68 scoped local controls passed |
The Formal Evidence Index and Freeze Execution Report govern execution details and evidence classification. Working or formative records are not promoted by inclusion in this plan.
5. Seed Test Inventory¶
| Test ID | Level | Purpose | SRS Link |
|---|---|---|---|
| TV-RUN-001 | Unit | Expected step math anchored to first successful run, including one-step algorithm/runtime cadence reconciliation without schedule re-anchor | SRS-RUN-001, SRS-RUN-002 |
| TV-RUN-002 | Integration | Duplicate step prevention (stepNotDue), live executed-step/request-step alignment with algorithm input stepTime after cadence reconciliation, single-flight FIFO work-pass serialization with start-time state loads, and monotonic same-anchor step-base persistence (superseded stale passes abort benignly instead of regressing the base and tripping a false drift-block) |
SRS-RUN-002 |
| TV-RUN-003 | Unit/Integration | Runtime doWork dispatch is constrained to allowed wake causes (cgmUpdate, bgCheck, mealAnnounce, guarded pumpReconnect) |
SRS-RUN-003 |
| TV-RUN-004 | Unit/Integration | Reconnect fallback executes only after an anchored session exists and only when accepted CGM receipt age exceeds the approved fallback freshness limit | SRS-RUN-004, SRS-CGM-005 |
| TV-RUN-005 | Unit/Integration | Reconnect fallback does not execute step 0, does not re-anchor cadence, and does not replay multiple missed slots |
SRS-RUN-001, SRS-RUN-002, SRS-RUN-005 |
| TV-RUN-006 | Unit/Integration | Fresh accepted CGM receipt suppresses reconnect fallback and same-slot CGM/reconnect triggers coalesce to one execution | SRS-RUN-002, SRS-RUN-004, SRS-RUN-005 |
| TV-RUN-007 | System/Hardware | Real-device reconnect fallback validates current-due-step execution after CGM interruption without duplicate command application | SRS-RUN-004, SRS-RUN-005, SRS-CGM-005 |
| TV-RUN-008 | Unit/Integration | Masked fallback does not arm or refresh without an active algorithm session, arms after the current step first computes a valid fallback candidate but before applying that same step's pump command when refreshed pump status is known/available, skips that pre-command maintenance hook when pump status is unavailable/unknown, arms before the next loop execution when a valid candidate was already persisted and no fallback is currently programmed, derives the programmed fallback schedule from the secondary/safety q5 nominal-basal profile when available, renews an existing mask only inside the 20-minute renewal window, suppresses same-cycle post-execution retry after a pre-command fallback event, suppresses ordinary loop execution after offline mask expiry until reconciliation-required recovery is resolved, re-schedules a reconnect recovery attempt from wakes blocked by the pending recovery state, requeues recovery triggers that arrive while an attempt is in flight, bounds pump-evidence exposure windows to the pod-total measurement time with post-restore totals preferred, degrades stale-baseline amount-fitting deltas to corrected pump-anchored replay, raises a safety-critical alert when an unreconciled resume may drop nonzero fallback insulin, realigns an ahead algorithm counter as the adopted step base without re-anchor and resumes dosing automatically at the adopted counter with an informational auto-clearing note (no dosing block, no manual reset demand), and holds the conservation sweep property (every recovery outcome replays or alerts) | SRS-RUN-006, SRS-RUN-007, SRS-PUMP-006, SRS-PUMP-008 |
| TV-ALG-001 | Unit (Bridge) | Bridge null-pointer guards and edge-state reset behavior | SRS-ALG-003 |
| TV-ALG-002 | Unit (Bridge) | Input mapping and sentinel behavior (requestTime, pump availability, subject-id boundaries) |
SRS-ALG-003 |
| TV-ALG-003 | Unit (Bridge) | Output/state handoff and step increment continuity at bridge boundary | SRS-ALG-003, SRS-ALG-004 |
| TV-ALG-004 | Unit (Algorithm) | Deterministic nominal golden-vector replay, plus per-instance state-isolation regression for the primary/safety dual-instance contract (buffer clock, CGM-dropout window, CGM-acceptance density) | SRS-ALG-001, SRS-ALG-008 |
| TV-ALG-005 | Unit (Algorithm) | Degraded/unavailable-input golden-vector replay | SRS-ALG-001, SRS-ALG-003 |
| TV-ALG-006 | Unit (Algorithm) | Meal/BG/intervention golden-vector replay | SRS-ALG-001, SRS-ALG-005 |
| TV-ALG-007 | Unit/Integration | Stateful continuity across persistence/reload/reset boundaries | SRS-ALG-004 |
| TV-ALG-008 | Unit (Algorithm) | Boundary/sentinel cases (CGM, BG, pump) remain deterministic and safe | SRS-ALG-003, SRS-ALG-004 |
| TV-ALG-009 | Differential | Pregnancy config differential replay (target, upfront, TMAX) vs baseline |
SRS-ALG-005 |
| TV-ALG-010 | Coverage | Structural coverage generation for Algo2015 and the bridge. Nominal targets are 100% bridge function/line/branch coverage and at least 98% Algo2015 function, 95% line, and 90% branch coverage; any shortfall requires a controlled reachability, safety-impact, mitigation, and disposition record in the STR exception package. | SRS-ALG-002 |
| TV-ALG-011 | Toolchain/Process | Static-analysis quality lane execution, and MISRA policy evidence closure as either linked report+deviations or explicit not-applicable decision rationale | SRS-ALG-006, SRS-ALG-007 |
| TV-ALG-012 | Unit/Integration | A meal step with concurrent bolus/basal/meal output commands their exact sum, persists that total as the issued request, and accepts matching next-step pump feedback through Reconcile_I_Dose (I present, ~I absent); basal-only behavior remains unchanged |
SRS-ALG-009 |
| TV-OUTAGE-001 | Unit | Outage BG-due scheduling: 120/60-minute interval selection at the >200/<80 thresholds, qualifying-glucose re-anchoring (CGM and fingerstick), blind-step/skip preservation, Codable persistence | SRS-OUTAGE-001, SRS-OUTAGE-005 |
| TV-OUTAGE-002 | Unit/Integration | Backup-basal bridge transitions: active mask cancel on connected forced-open, renewal suppression while released, pre-command re-arm on re-close, cancel-failure retry, re-arm-failure command block, full cancel-hold-renew sequence order; bridged-exposure reconciliation itself (SRS-OUTAGE-006) is deliberately covered by the existing fallback-replay rows (TV-PUMP-008/TV-RUN-008 family) - the bridge introduces no new reconciliation evidence class, and release-window quantification at re-arm (engaged event updated in place with window duration + modeled schedule exposure, status resumed_without_reconciliation; rearm-failure keeps the window open - testRecloseQuantifiesTheReleasedWindowOnTheEngagedEvent). Released-window pod-away gap reconciliation (SRS-OUTAGE-006 v1.42, sponsor-directed 2026-07-18): reconnect after skipped steps builds the standard bounded schedule-weighted replay instead of a single chunk tuple - end-to-end scenario pins SimulatedDashPodOutageBridgeScenarioTests, including insulin conservation across gap lengths and rates; independent safety-review coverage in SimulatedDashPodOutageGapReplayReviewScenarioTests verifies persisted-credit conservation across force quit, exactly-once re-synthesis after a cadence-drift discard, quantized weighting for non-flat schedules, and engaged-event time-zone weighting; real-C++ chunk-vs-replay divergence measured and pinned in Algo2015OutageGapPodAwayReplayCharacterizationTests, whose engine-ledger conservation pins hold the C++'s booked row totals equal to the measured delta under the 0.01 U-quantized largest-remainder allocation; classifier row R-046 + testClassifierMatchesRuntimeForReleasedOutagePodAwayReconnectGapReplay keep the decision matrix and runtime in parity (plan-stamp authorization under the pending engaged event) |
SRS-OUTAGE-004, SRS-OUTAGE-006 |
| TV-OUTAGE-003 | Unit | Outage alert tiers and countdown surfaces: pre-scheduled due-soon/overdue monitoring (immediate upsert past deadlines, clearing on disable), preview-catalog copy pins, backup-basal informational supersession of the forced-open note, and the outage-active gate (offline-mode blind step true, relaunch-blip blind step false, fingerstick-fed step true, mid-BG-run persistence, accepted CGM ends it, skip preserves state - BionicLoopRuntimeEngineOutageBGRunTests incl. testRelaunchBlipBlindStepIsNotAnOutage) |
SRS-OUTAGE-002, SRS-OUTAGE-003 |
| TV-PUMP-010 | Unit | Pump-command watchdog: completion wins, timeout throws the supplied uncertain error, late completion after timeout is ignored safely, double completion ignored; pump-event delegate synchronous-completion contract pinned | SRS-PUMP-011 |
| TV-CGM-001 | Unit | Out-of-range CGM -> unavailable (-1) mapping |
SRS-CGM-001 |
| TV-CGM-002 | Unit | Step-0 fresh/in-range gating | SRS-CGM-002 |
| TV-CGM-003 | Unit | Step>0 degraded run with unavailable CGM | SRS-CGM-003 |
| TV-CGM-004 | Unit/UI | Step-0 blocked-for-CGM path exposes explicit reason/state messaging to user surfaces | SRS-CGM-004, SRS-UI-002 |
| TV-CGM-005 | Integration/System | Armed-loop absence of successful step execution beyond the approved interruption threshold is detected as a stalled-step condition using last-success/session-start timing | SRS-CGM-005 |
| TV-CGM-006 | Unit/Integration/UI | A stale bound G7 and a routine disconnect do not enter replacement mode; explicit replacement synchronously offers start/prior-ID/trigger evidence for persistence before returning to BLE acquisition; the remote-disconnect-during-authentication end-of-session heuristic enters persistent replacement mode; repeated triggers preserve the original episode clock; direct manager reconstruction restores replacement mode; authenticated adoption records old/new identity and trigger, then clears replacement mode. Settings distinguishes routine BLE scanning from replacement acquisition, keeps Scan for new sensor visible and actionable throughout, and adds Scanning for new sensor... progress while replacement acquisition is active; retry restarts discovery without resetting the original evidence clock. The exact-freeze unit result remains unchanged. The September 3 adversarial review found that this method does not cover CGM-screen setup reentry, concurrent candidate ordering/single-winner behavior, automatic-trigger isolation, or first-reading algorithm use before staff comparison; those scenarios are not represented as passed. Under D06, they are covered by a controlled exercise required before first participant deployment. |
SRS-CGM-006 |
| TV-BG-001 | Unit/Integration | bgCheck creates/uses a single pending BG candidate without borrowing future slots beyond immediate next-step policy |
SRS-BG-002 |
| TV-BG-002 | Unit/Integration | Submit after due-step execution rolls BG candidate to immediate next step and uses it there | SRS-BG-003 |
| TV-BG-003 | Unit/Integration | BG value maps to algorithm BGval while CGM mapping remains independent |
SRS-BG-004 |
| TV-BG-004 | Unit/Integration | Pump unavailable during bgCheck blocks command application without overriding degraded policy |
SRS-BG-005, SRS-PUMP-001 |
| TV-BG-005 | Unit/UI | Stale manual BG is rejected with explicit user-visible reason | SRS-BG-006 |
| TV-BG-006 | Unit/Integration | Telemetry records manualBG source, value, timestamps, and execution outcome |
SRS-BG-007, SRS-LOG-001 |
| TV-BG-007 | Unit/Integration | Deferred from current software baseline. If step-0 BG rescue is enabled in a future accepted baseline, verify it executes only when policy gates pass. | SRS-BG-008 |
| TV-BG-008 | Unit/UI | Manual BG entry rejects values outside 20...600 mg/dL with explicit validation messaging, shows that manual BG is used for algorithm dosing decisions and does not calibrate CGM, and requires a spatially separate exact-value review confirmation whose Change action preserves the entered digits and whose entry action cannot submit under rapid repeated taps |
SRS-BG-001 |
| TV-BG-009 | Unit/Integration | Pending BG candidate expires if not consumed on the immediate next target step | SRS-BG-009 |
| TV-BG-010 | Unit/Integration | New BG submission replaces existing pending candidate before execution | SRS-BG-010 |
| TV-BG-011 | Unit/Integration | Manual BG submit while loop is disarmed or masked-fallback reconciliation is pending does not dispatch runtime execution (bgCheck) or create pending BG state |
SRS-BG-011 |
| TV-BG-012 | Unit/Integration | Manual BG submit before first successful anchored step is rejected and does not create pending BG state | SRS-BG-012 |
| TV-BG-013 | Unit/Integration/UI | Accepted persisted manual BG renders immediately as one unfilled marker at submission time, survives persistence/relaunch, becomes filled only from completed algorithm-input evidence, retains its original time without duplication, and omits incomplete, invalid, out-of-window, expired, replaced, or discarded unconsumed state | SRS-BG-002, SRS-BG-004, SRS-BG-009, SRS-BG-010, SRS-BG-013 |
| TV-CLIN-001 | Unit/UI/Integration | While no usable subject configuration exists, initial clinical setup can be reviewed and saved without an unlock; that exception closes after first save. Subsequent Clinical Settings access/edits are gated by the offline clinical unlock verifier; material installation validates and stores verifier material, material refresh preserves accepted-counter state while clearing active unlock state, malformed/invalid/reused/non-ASCII codes block entry, accepted future counters unlock settings locally for the provisioned duration without requiring network access, and manual-lock storage failure does not falsely present a locked state | SRS-CLIN-001, SRS-CLIN-002, SRS-CLIN-013 |
| TV-CLIN-002 | UI/Smoke | Subject ID, Weight, Start Algo, and Same-Participant Reset (formerly Reset Algo) are presented in Clinical Settings and not in participant-facing settings sections |
SRS-CLIN-003 |
| TV-CLIN-003 | Unit/UI | Target selector enforces allowed values (90, 100, 110, 120, 130 mg/dL) and rejects out-of-set values |
SRS-CLIN-004 |
| TV-CLIN-004 | Unit/UI | Meal upfront selector enforces two-option set (75%, 90%) and maps selected value into runtime config |
SRS-CLIN-005 |
| TV-CLIN-005 | Unit/UI | TMAX selector enforces 40...70 inclusive with 5-minute increments |
SRS-CLIN-006 |
| TV-CLIN-006 | Unit/Integration | Clinical settings persistence restores values across relaunch with deterministic default/migration behavior | SRS-CLIN-007 |
| TV-CLIN-007 | Unit/Integration | Start Algo and Same-Participant Reset (formerly Reset Algo) behavior remains unchanged after relocation into Clinical Settings |
SRS-CLIN-008 |
| TV-CLIN-008 | Unit | Weight conversion and validation path stores kg from integer lbs UI input | SRS-VAL-001, SRS-CLIN-003 |
| TV-CLIN-009 | Unit/Integration | Clinical save-review semantics hold: no persisted/runtime config mutation before Save+OK, cancel keeps prior applied config, and persisted update appears in next step telemetry snapshot |
SRS-CLIN-007, SRS-CLIN-008, SRS-LOG-001 |
| TV-CLIN-010 | Unit/UI | Participant-facing settings and the clinician target selector expose only the target set enabled by the clinician-selected target-access profile (Pregnancy vs Standard) |
SRS-CLIN-009, SRS-CLIN-010 |
| TV-CLIN-011 | Unit/UI | Participant target change requires approval capture and blocks apply until approving staff name and approximate approval time are both recorded | SRS-CLIN-011 |
| TV-CLIN-012 | Unit/UI | Clinical Settings normalizes the draft target to an allowed profile value when the clinician changes the target-access profile | SRS-CLIN-012, SRS-CLIN-010 |
| TV-CLIN-013 | Unit/Integration | Target-access profile persists across save/relaunch/migration and is reflected consistently in both participant and clinician settings views | SRS-CLIN-007, SRS-CLIN-009, SRS-CLIN-010 |
| TV-CLIN-014 | Unit | First-launch defaults are Standard/120/75%/40 (clinical direction 2026-07-14) and normalization fallbacks track them; persisted participant values are never rewritten by defaults | SRS-CLIN-013 |
| TV-CLIN-015 | Unit/Integration | New Participant Reset clears every participant-scoped store (config, session keys, pump events, outbox, subject-scoped keychain unlock material) and returns to first-launch setup; refused while a pod is active (stores untouched); an armed session proceeds only through the guided stop-then-reset flow (explicit session stop, then the erase confirmation), with the engine-level stop-then-reset transition regression-pinned. Device-state isolation proves pending G7 replacement-acquisition persistence callbacks, alert work, and in-flight stall/adoption telemetry are invalidated before raw manager state is removed, so late completion cannot recreate outgoing-participant state (testNewParticipantResetInvalidatesAcquisitionPersistenceAndInFlightTelemetry). Telemetry drain-guard (SRS-CLIN-014 v1.41): undelivered/rejected outbox counts, drain-attempt-then-count summary, discarded-marker emission on the reserved-sequence path (offline-silent, skipped when nothing is pending), sequence-continuity-preserving spool erasure, discard-before-wipe ordering with no discard on blocked outcomes, and the pending-count consent line in the erase confirmation copy |
SRS-CLIN-014 |
| TV-CLIN-016 | Unit | Weight plausibility bounds (SRS-CLIN-015): configurations with weight outside 50...500 lbs are not usable for arming (testClinicalSettingsSavePolicyRejectsImplausibleWeightEntries); the store top-clamps persisted weight at 500 lbs, preserves 0-as-unset, and never raises a lower entry (testClinicalAlgorithmConfigStoreTopClampsWeightAndPreservesUnsetAndSubPlausible); the algorithm layer clamps consumed weight into 20...230 kg with telemetry visibility (testRealBUDosingAlgorithmClampsImplausibleWeightIntoSafetyRailInTelemetry) |
SRS-CLIN-015 |
| TV-CLIN-017 | Unit/UI/Integration | Temporary Target verification shall cover explicit target/duration selection and allowed-value rejection; target-only, duration-only, and complete unactivated draft-loss detection; keep-editing and explicit discard navigation; app-standard selected-state presentation; placement above User and absence of unrelated participant-reset guidance; Pregnancy/armed/active-Pod/recovery activation gates; persistence, concurrent mutation serialization, deterministic replacement, early end, exact expiry, relaunch restoration, profile/session/reset clearing, New Participant Reset erasure, and historical execution-time lookup; primary-only target use with the safety target/fallback basis pinned to the permanent configuration; no session restart or immediate Pod command; notification schedule/cancel semantics; active Home/Settings state; and the specified physical-device Temporary Target and suspension/resumption scenarios. The combined-screen verification shall additionally prove that the existing suspend/resume command is directly available there, absent from normal Pod Settings, offers the unchanged four reminder choices without automatic resume, and disables action for unusable or transitioning Pod states. The suspend-ended alert shall expose the same resume command on Home and Alert Center, suppress duplicate in-flight commands, remain retryable after command failure, clear only through pump lifecycle confirmation, and escalate exactly once from actionable to safety-critical at 15 minutes with update telemetry and a fresh notification, including after relaunch; repeated source issue shall not restart or downgrade the escalation. Working automated symbols include testTemporaryTargetSelectionRequiresExplicitTargetAndDuration, testTemporaryTargetDraftWarnsWhenEitherSelectionWouldBeLost, testTemporaryTargetStorePersistsActiveOverrideWithoutMutatingClinicalConfig, testTemporaryTargetStoreSerializesConcurrentStateMutations, testTemporaryTargetStoreExpiresAtExactDeadlineAndRecordsDispositionOnce, testTemporaryTargetHistoryResolvesReplayRowsAcrossExpiry, testTemporaryTargetSessionStopClearsActiveOverrideButRetainsHistoricalExecutionContext, testCurrentLoopConfigUsesTemporaryTargetOnlyForPrimaryController, testTemporaryTargetActivationEligibilityRequiresPregnancyArmedAndActivePod, testTemporaryTargetRelaunchRestoresReminderAndForegroundExpiresAtDeadline, testBionicLoopPodSettingsHideDuplicateInsulinSuspensionControl, testInsulinSuspensionPresentationUsesSuspendForActiveDelivery, testInsulinSuspensionPresentationUsesResumeForSuspendedDelivery, testInsulinSuspensionPresentationDisablesTransitionsAndUnavailablePod, testSuspendEndedAlertOffersDirectResumeAction, testResumeInsulinActionRunsOneCommandAtATimeAndRefreshesAfterSuccess, testResumeInsulinActionLeavesRetryAvailableAndSurfacesFailure, testSuspendEndedAlertEscalatesAfterFifteenMinutesAndRenotifiesOnce, testSuspendEndedAlertEscalatesImmediatelyAfterRelaunchPastDeadline, testRepeatedSuspendEndedIssueDoesNotDowngradeEscalatedAlert, testUI003a_TemporaryTargetRequiresExplicitSelectionAndConfirmsActivation, testUI003b_ExerciseScreenOwnsInsulinSuspensionControl, testUI003c_TemporaryTargetWarnsBeforeDiscardingPartialSelection, and testUI006a_SuspendEndedAlertOffersResumeInsulinAction. Suspend alert normalization is pinned by BionicLoopPumpAlertMapperTests; notification destination is pinned by BionicLoopAlertCenterRuntimeTests.testShowPreviewAlertsSupportsMultipleTypesAndPrecedence. |
SRS-CLIN-016, SRS-ALERT-002, SRS-ALERT-006 |
| TV-CLIN-018 | Unit/UI | The explicit Standard-to-Pregnancy draft transition initializes meal upfront to 90%, Pregnancy-to-Standard and same-profile changes preserve the current valid value, 75% remains selectable before save, cancel leaves persisted state unchanged, and an existing Pregnancy configuration is not migrated (testStandardToPregnancyTransitionDefaultsMealUpfrontToNinetyOnlyForThatTransition plus existing save/cancel persistence coverage). |
SRS-CLIN-017, SRS-CLIN-005 |
| TV-PUMP-001 | Unit | Pump unavailable -> run step, block command application | SRS-PUMP-001 |
| TV-PUMP-002 | Integration | Signal-loss policy persistence and clear behavior | SRS-PUMP-001, SRS-UI-002 |
| TV-PUMP-003 | Integration | Delivery reconciliation and min-dose quantization behavior | SRS-PUMP-003 |
| TV-PUMP-004 | System | Home pod card updates on connect/disconnect without entering settings | SRS-PUMP-004 |
| TV-PUMP-005 | Integration/System | Delivery-state clears from delivering via auto-refresh without opening Pump settings |
SRS-PUMP-005 |
| TV-PUMP-006 | UI/Integration | Closed-loop surfaces do not expose manual bolus command paths | SRS-PUMP-002 |
| TV-PUMP-007 | Unit/Integration | Masked fallback maintenance blocks disruptive schedule writes during unsafe pump states, arms newly computed missing fallback before the same step's pump command only when refreshed pump status is known/available, arms persisted missing fallback before the next loop execution once a valid candidate exists, programs the secondary/safety q5 nominal-basal four six-hour fallback schedule when available, renews the 0 U/hr mask inside the 20-minute renewal window, permits the normal step command after a clean first-arm block with no schedule mutation, prevents same-cycle post-execution first-arm retry after a pre-command fallback event, blocks the normal step command when first-arm remask failure creates reconciliation-required recovery, treats post-schedule mask blocking/failure as recovery-required remask failure, defers maintenance when pump state or late bolus-in-progress command races block renewal but the current mask is still active, records offline fallback activation plus reconciliation-required recovery state when the mask later expires, and performs schedule refresh using reprogram-and-immediate-remask semantics |
SRS-PUMP-006, SRS-PUMP-007, SRS-PUMP-008 |
| TV-PUMP-008 | Unit/Integration | Session reset/disarm attempts to restore the original programmed basal schedule, preserves recovery context when restore fails, retries connected restore/disarm when masked-fallback recovery remains pending on reconnect/start/foreground, preserves the existing session/cadence anchor after successful offline-expiry recovery while the loop remained armed, allocates credible same-pod pump-reported fallback delivery delta across missed primary/secondary algorithm replay steps with CGM=-1 and no catch-up pump commands, weights replay-step delivery by the persisted programmed fallback schedule including equal-rate, six-hour-window, partial-slot, and midnight-wrap cases while keeping the pump delta authoritative, suppresses replay for positive pump delta with no usable schedule weight, preserves zero-delivery replay rows when the authoritative pump delta is 0 U, suppresses replay for ambiguous, different/new pod, unknown identity, or history-discontinuous evidence while keeping same-session unreconciled continuation, records assumed-delivered modeled fallback exposure and queues bounded replay when the previous pod is known retired/inactive or past hard service-stop and pump-counter evidence is unrecoverable, stamps recovery-completion timing after restore finishes, captures basal-only reconnect evidence plus modeled-vs-pump-reported fallback delivery when compatible baseline data exist, and keeps explicit reset/loop-off recovery from silently turning the loop back on |
SRS-PUMP-009, SRS-STATE-004, SRS-STATE-005 |
| TV-PUMP-009 | Unit/Integration | Applied or uncertain automatic bolus commands persist issued-dose attribution; active delivery blocks live step advancement for the original/current pod; accepted no-boundary-cancel liveness coverage verifies DASH bolus completion/status convergence before the next 5-minute step for supported automatic bolus sizes and unavailable/unknown state on disconnect; matching same-request same-pod pump evidence replays missed primary/secondary algorithm steps before the live step with delivered insulin injected only at the first missed attribution step and CGM=-1; delivered-unit evidence outside 0...requested is non-credible and does not replay or advance; combined same-pod pump-total evidence is partitioned into pending issued-dose evidence plus fallback-basal residual only when the request, pod identity, completion timing, and residual fallback exposure are credible, while raw pump-total delivery remains telemetry/operator-review evidence; fallback replay overlap is monotonic and non-duplicating and uses the same delivered-unit credibility rule; absent, mismatched, non-credible, missing-identity outside the user-confirmed unavailable-pod clinical-policy path, or non-partitionable evidence skips live advancement without clearing the pending attribution; user-confirmed unavailable-pod meal evidence may be consumed without pod identity only when request step, units, delivered bounds, and non-active pump status match; and different/new pod evidence, including replacement-pod active-delivery status, records different_or_new_pod, preserves the current algorithm session, assumes the issued dose was delivered, feeds the assumed delivered amount into the first eligible attribution step by replay or live input, scrubs unrelated replacement-pod lastDelivery from the resumed live algorithm input, clears the old-pod pending attribution after consumption, and allows later insulin-adding automatic commands including automatic resume under the new clinical-policy disposition; fresh-completion upgrade rule (SRS v1.48, field incident 2026-07-20): the post-relaunch persisted-evidence deferral/suppression is superseded by a fresh same-pod settled status at/after expected physical completion with bolusNotDelivered = 0, surfacing the pump-observed completed delivery so a frozen capped-in-progress or assumed figure cannot under-report the meal evidence, while canceled partials (nonzero register), pre-completion early-reads, active delivery, and different/unproven pods keep the deferral, and matching non-assumed sub-requested evidence is replaced by the strictly-higher same-pod post-completion observation before consumption - pinned end-to-end with the incident telemetry in BionicLoopPumpEvidenceRelaunchUpgradeTests |
SRS-PUMP-010, SRS-STATE-004, SRS-STATE-005 |
| TV-MEAL-001 | Unit | Meal announce borrow-window gating after cadence reconciliation against algorithm-reported next step | SRS-MEAL-001, SRS-RUN-002 |
| TV-MEAL-002 | Unit/Integration/Characterization | Meal announce is blocked when pump is delivering, suspended, or unknown; when the primary algorithm is already forced-open without an exact-step pending BG; or when the selected borrowed/due step would be the characterized 13th glucose-blind step. A connected active .delivering status maps to pump-busy, .suspended maps to resume-before-meal guidance, and an idle unresolved attribution remains blocked with reconciliation guidance. Suspended-path coordinator coverage proves rejection occurs before meal persistence, either algorithm, cadence advancement, or pump command, and subsequent live input contains no rejected meal request/delivery; a fresh idle refresh after Resume makes availability immediate without a loop step. The 12th blind step remains eligible; fresh CGM or a valid 20...600 mg/dL BG targeting the prospective step permits execution. Combined BG + meal still feeds both primary and safety algorithms exactly once and clears forced-open in the real C++; stale/future/invalid BG and pump signal loss remain blocked. |
SRS-MEAL-002, SRS-BG-004 |
| TV-MEAL-003 | Unit/Integration | Meal announce executes on current due step when slot is already due/missed | SRS-MEAL-004 |
| TV-MEAL-004 | Unit | Meal announce rejected before first successful anchored step | SRS-MEAL-005 |
| TV-MEAL-005 | Unit | Meal unavailable reason precedence reports noPump before signalLoss when no active pod is present |
SRS-MEAL-002, SRS-UI-002 |
| TV-MEAL-006 | Unit/UI | Meal unavailable messaging includes explicit actionable reason and retry timing when blocked, including reconnect/recovery-required guidance while masked-fallback reconciliation is pending | SRS-MEAL-003, SRS-UI-002 |
| TV-MEAL-007 | Unit/UI | Meal composer revalidates availability on foreground refresh, qualifying-glucose publication, live pump-status change, and immediately before submit so stale available or blocked state cannot dispatch an invalid meal request or retain incorrect guidance; open-composer revalidation re-arms in place or renders inline blocked messaging, and when a loop step consumes the pending fingerstick BG that unlocked the composer it holds the armed composer on a passive waiting notice until the exact step's qualifying-glucose marker publishes (including an intermediate checkpoint that already reports the step executed), never demanding another fingerstick within the BG validity window; connected active delivery promptly presents pump-busy guidance | SRS-MEAL-006, SRS-UI-002 |
| TV-MEAL-008 | Unit/UI/Integration | Meal submit does not present success until runtime result is known; blocked/rejected and uncertain outcomes surface explicit user-facing recovery messaging | SRS-MEAL-007, SRS-UI-002 |
| TV-MEAL-009 | Integration | Pending or uncertain meal request state, including correlated flow ID, persists across relaunch and prevents duplicate meal entry until resolved | SRS-MEAL-008, SRS-MEAL-009, SRS-STATE-001 |
| TV-MEAL-010 | Integration/System | Command-outcome uncertainty (timeout/error with unresolved delivery state) blocks repeat meal announce and surfaces explicit operator guidance until reconciliation; immediate-success and reconciled meal lifecycle closure remain replayable across terminate/relaunch windows until resolved telemetry is emitted |
SRS-MEAL-008, SRS-MEAL-009, SRS-PUMP-001 |
| TV-MEAL-011 | Integration/System | Competing-trigger slot conflict does not silently lose or reinterpret meal intent; user receives explicit slot-conflict blocked/retry feedback and no hidden reassignment to a different borrowed step | SRS-MEAL-010, SRS-RUN-002, SRS-UI-002 |
| TV-MEAL-012 | Unit/UI/Integration | When meal entry is opened during active bolus delivery, the app presents a destructive Home inline cancel-delivery flow, keeps that flow visible while active meal delivery remains in progress, reports actual delivered insulin after cancellation in the Home summary region, retains that summary until both the next later algorithm step and a 5-minute minimum display window have passed, renders active in-progress meal delivery in the normal meal-dose color while reserving caution color for actual interrupted delivery, and preserves the delivered amount for subsequent algorithm-step accounting | SRS-MEAL-011, SRS-PUMP-003, SRS-UI-002 |
| TV-MEAL-013 | Unit/UI/Integration | When meal delivery progress cannot be confirmed for the original pod, the app offers an explicit pod-replacement escape only after known old-pod unavailability or expected-completion timeout, suppresses that escape for non-meal issued-dose attributions and already matched evidence, records assumed-delivered evidence with user_abandoned_unavailable_pod, clears only meal-progress UI state, preserves issued-dose attribution for replay/live-step accounting, and routes the operator to pod setup |
SRS-MEAL-012, SRS-PUMP-010, SRS-UI-002 |
| TV-STATE-001 | Integration | Relaunch restores cadence and algorithm state | SRS-STATE-001 |
| TV-STATE-002 | Integration | Reset clears all session state and starts fresh | SRS-STATE-002 |
| TV-STATE-003 | Integration/System | Pump and CGM manager state persistence supports reconnect without forced re-pairing on relaunch | SRS-STATE-003 |
| TV-STATE-004 | Integration | Masked fallback persistence retains original/fallback schedules, maintenance timestamps, active safety target, connected pod identity and total-delivery baseline, restore-failed or reconciliation-required recovery context, primary and secondary/safety q5 nominal-basal profiles, and any pending pump-delta reconciliation state needed for later refresh, restore, reconnect recovery retry, confirmed/corrected missed-step algorithm replay, or ambiguous unreconciled resume | SRS-STATE-004 |
| TV-STATE-005 | Unit/Integration | Runtime recovery, pump reconnect, pod replacement, CGM recovery, fallback reconciliation failure, launch, foreground, scheduler wake, telemetry replay, and cloud/auth state do not stop/start/reset the algorithm or create a replacement algorithm session without explicit operator action; unreconciled fallback recovery preserves the existing session/cadence state while suppressing replay | SRS-STATE-005 |
| TV-LOG-001 | Unit | Step telemetry contains explicit step_executed_at plus input/output/command fields; Recent Dose Steps identifies a valid persisted manual BG as Fingerstick, shows the exact value used, preserves concurrent CGM, and shows no fingerstick marker when the BG sentinel is absent. The current-session SQLite archive retains and exports every step beyond the 576-row presentation cache, restores the newest cache rows after relaunch, supports historical-row update, reads the full archive for CSV generation off the main actor, and clears on explicit algorithm-session reset; byte-marker and queue-affinity regressions verify that archive database artifacts no longer contain the cleared participant marker and full-history export cannot block the main actor (LoopTelemetryStoreTests.testClinicalStepArchiveKeepsFullHistoryWhileUICacheAndRelaunchStayBounded, testClinicalStepArchiveCSVReadRunsOffMainActor, testAlgorithmSessionResetClearsFullClinicalStepArchive, testAlgorithmSessionResetRemovesArchivedClinicalBytesFromDatabaseArtifacts). |
SRS-LOG-001 |
| TV-LOG-002 | Integration | CSV export schema and row append behavior, including masked-fallback missed-step algorithm replay rows from credible pump delta with CGM=-1, per-step delivered-insulin input including explicit 0 U input for replay steps with no pump allocation, and no catch-up pump command rows |
SRS-LOG-002 |
| TV-LOG-003 | Unit/Integration | Async export avoids main-actor blocking | SRS-LOG-003 |
| TV-LOG-004 | Unit | Cloud-log upload filter is inclusive (selected level and higher severities) with default Error; no in-app logging control exists (UI removed 2026-07-16); effective-threshold precedence session > remote override > default is pinned |
SRS-LOG-004 |
| TV-LOG-011 | Unit | Remote logging config as the sole lever: response parsing (apply valid including the dashboard's fractional-milliseconds toISOString expiry shape, clear on null/expired server config, ignore malformed or unknown level), persistence apply/clear/ignore-preserves, override activation via the effective-threshold policy with legacy session storage ignored, upload-logger threshold honoring the server config, change-observer notification (fires on apply/clear change, silent on unchanged re-fetch), periodic re-fetch loop (re-fetches on interval, applies the fetched config, stops on cancel), and the read-only Settings status text (server config > default precedence with source attribution; legacy session bytes never shown; phone-set non-default level surfaced) - BionicLoopCloudLogPolicyInfrastructureTests incl. testCloudLogUploadPolicyIgnoresLegacyIntegrationSessionStorage, testCloudLogUploadLoggerHonorsRemoteOverrideLevel, testRemoteConfigRefreshNotifiesObserverOnlyWhenStoredOverrideChanges, testStartPeriodicRefreshKeepsRefetchingUntilCancelled, testStatusDescriptionShowsRemoteConfigThenDefault, testStatusDescriptionShowsPhoneSetLevelWhenNoOverrides |
SRS-LOG-011 |
| TV-LOG-005 | Unit | Clinical Settings save flow emits deterministic ui.critical telemetry (state_viewed, submit, cancel, blocked) with stable element IDs and old/new value details |
SRS-LOG-005 |
| TV-LOG-006 | Unit/Integration | App lifecycle telemetry includes timezone and clock-check context fields with correct trigger semantics (launch, foreground >24h gate, timezone_or_time_changed) |
SRS-LOG-006 |
| TV-LOG-007 | Unit/Integration | Meal-request telemetry exposes the implemented lifecycle transitions (submitted, accepted, success, blocked, uncertain, resolved) without optimistic-success duplication, with replay durability across terminate/relaunch windows, and loop-command telemetry preserves explicit command outcome semantics (applied, blocked, uncertain) |
SRS-LOG-007, SRS-MEAL-007 |
| TV-LOG-008 | Unit/UI | Target-access-profile and participant approval-capture telemetry emit stable ui.critical events with required detail fields (target_range_profile, requested/applied target, approval metadata, and blocked/cancelled reason) |
SRS-LOG-008 |
| TV-LOG-009 | Unit/UI/Integration | Fallback review telemetry persists and renders fallback arm, maintenance-deferred, renew, schedule-unchanged check, refresh, mask-expiry, disarm, and restore/remask failure events with rate/source/target/duration/reconciliation/pod-continuity detail in Recent Dose Steps; resolved recovery rows include modeled expected delivery, same-pod pump-reported delivered insulin when available, and pump-delta reconciliation detail when confirmed/corrected recovery occurs; executed step rows render both primary and secondary algorithm summaries (step count, suggested dose, nominal basal, instant basal) from persisted per-step telemetry; confirmed/corrected reconnect recovery records no-command missed-step primary/secondary algorithm replay rows with CGM=-1 and persisted-schedule-weighted per-step pump delivery including explicit 0 U replay steps when no pump allocation belongs to a missed step, and the resumed live step uses actual refreshed pump status without duplicate recovered-delivery injection; and cloud telemetry emits a structured loop.fallback.event family with stable fallback_event_id, delivery/reconciliation summary fields including pod_continuity, programmed schedule entries, safety q5 profile metadata including per-six-hour-segment observed-slot counts on arm/refresh/unchanged events, the lean unchanged-check payload (schedule + coverage without the bulk 288-rate array) at the steady 6-hour cadence, Recent Dose Steps schedule-row outcome labels and per-segment observed/imputed provenance, and duplicate suppression for unchanged fallback review state |
SRS-LOG-009 |
| TV-LOG-010 | Unit | Rescinded 2026-07-16 with the SRS-LOG-010 supersession (build-baked profile and on-phone session layer removed pre-ship; the covering tests were deleted with the code). Row retained for ID stability; legacy-storage-ignored behavior is covered under TV-LOG-011. | SRS-LOG-010 |
| TV-LOG-012 | Unit/Integration/Load | Sequence-numbered envelopes and rejection/recovery evidence (SRS-LOG-012): envelope bytes and durable sequence match; SQLite migration preserves prior rows/counters/retry state, purges the source only after commit, and imports a later fallback spool idempotently; retained clinical rows are never count-evicted while chatter rotates; interrupted inflight rows normalize after relaunch; durable emit returns before suspended network drain; immediate work does not cancel an older retry; and 10,000 retained events survive relaunch and drain exactly once in 200 bounded batches. Batch tests pin unchanged embedded envelope bytes, 50-event/512-KiB bounds, duplicate acknowledgement, mixed retryable/permanent outcomes, subject-conflict routing, large-event single upload, and HTTP 404/405/501 fallback to the unchanged single-event route. Existing coverage continues to pin retained-first recovery, aggregate chatter-drop evidence, passive Settings status, notification deduplication, file protection/backup exclusion, reset erasure including absence of a prior-participant byte marker from the recreated database/WAL/shared-memory artifacts, required envelope identity, structured permanent 4xx evidence, retryable 429, isolated Subject ID Conflict, legacy decode, and retired-alert migration. Working symbols are in BionicLoopTelemetryOutboxRecoveryTests, BionicLoopCloudTelemetryInfrastructureTests, and BionicLoopTelemetrySpoolRetentionTests; the Scout producer fixtures come from the real batch handler. The local transport contract is verified; Scout observations are supportive and are not a formal closure condition. |
SRS-LOG-012 |
| TV-LOG-013 | Unit/Integration/System | Temporary Target telemetry verification shall cover durable exactly-once lifecycle enqueue with subject override, first-use application evidence, per-step permanent/applied/safety target fields, execution-time identity on replay rows, reset drain/erasure behavior, real app payload fixture ingestion, BionicScout active/awaiting/in-use/inactive projection, and delayed/out-of-order terminal-state protection. Working app symbols include testTemporaryTargetLifecycleTelemetryEmitsDurableContextAndClearsAfterEnqueue, testLoopStepTelemetryIdentifiesTemporaryTargetUseAndPermanentSafetyBasis, testReplayTelemetryDoesNotLabelPermanentBasisSafetyInputAsTemporaryTargetUse, testReplayTelemetryRetainsExpiredTemporaryTargetIdentityByExecutionTime, and Temporary Target cloud-envelope infrastructure tests. Captured app payload fixtures support the local contract checks; Scout projection observations are corroborative and are not a formal closure condition. |
SRS-LOG-013, SRS-CLIN-016 |
| TV-LOG-014 | Unit/Integration | Acquisition-stall telemetry uses stable reason/threshold/start/trigger/prior-sensor fields and successful-adoption telemetry uses stable old/new/trigger/time fields. Both use stable event IDs through cgm.state.changed, suppress concurrent in-flight duplicates, persist a marker only after durable enqueue, survive relaunch without reserving a second wire sequence, permit retry after failed enqueue, and allow a later acquisition/adoption event. Scout observation is corroborative and is not a formal closure condition. |
SRS-LOG-014 |
| TV-LOG-015 | Unit/Integration/UI | LegacyAlgorithmArtifactExportTests shall verify documented-artifact discovery/grouping, matrix epoch association, historical selection integrity, export-time re-discovery, byte-exact stored ZIP entries and CRC, bounded live append/growth behavior, archive naming, and empty algorithm-set handling. RecentDoseRecoveryArchiveTests shall verify that the complete CSV and only the exact requested algorithm epoch enter one ZIP, an unavailable explicit epoch produces CSV-only output, absent inspection state selects only the newest valid grouped epoch, bytes appended to the CSV during copy remain outside the snapshot, and a missing CSV produces no archive. App integration shall verify the existing Recent Dose Steps ShareLink remains DEBUG-visible and otherwise clinical-unlock-gated, prepares the archive off the main actor without another modal/sheet/activity-controller wrapper, and removes temporary staging on both completed-view dismissal and canceled preparation. No separate physical share/open claim is retained in the current submission package. |
SRS-LOG-015, SRS-SEC-001 |
| TV-UI-001 | UI/System | Home loop-state precedence rendering and cadence-phase age classification (nextDueAt-based Active/Aging/Stale) |
SRS-UI-001 |
| TV-UI-002 | UI/System | Availability messaging matches runtime outcomes | SRS-UI-002 |
| TV-UI-003 | UI/System | CGM/Pod setup modal Cancel dismisses directly and does not force settings on no-active-pod startup |
SRS-UI-003 |
| TV-UI-004 | Unit/UI | Meal announcement composer auto-cancels on app background transition | SRS-UI-004 |
| TV-UI-005 | UI/Smoke | Home primary controls are present and actionable in deterministic launch mode (settings, manual BG, Let's Eat); Manual BG and Meal Announcement remain visible, hittable, and screen-position-stable while expanded alert/status/chart content scrolls |
SRS-UI-002 |
| TV-UI-006 | UI/Smoke | Home settings and manual-BG sheets can be opened and dismissed without dead-end navigation | SRS-UI-002, SRS-BG-001 |
| TV-UI-007 | Unit/UI | CGM display masks stale (>11m) or unreliable (hasReliableGlucose == false) readings as -- and hides trend arrow |
SRS-UI-005 |
| TV-UI-008 | Unit/Integration | UTC clock-drift warning behavior: >600s skew emits non-blocking actionable warning with 24h rate limit, <=600s shows no warning, and unavailable checks do not spam warnings |
SRS-UI-006 |
| TV-UI-009 | Unit/UI | CGM value formatting maps boundaries to textual LOW/HIGH across display surfaces and suppresses unit suffix for those states |
SRS-UI-007 |
| TV-UI-010 | Unit/UI | Home CGM chart uses bounded dynamic y-axis maxima (300/350/400) based on displayed peak values and a point-only trace presentation with connector stroke and connected area fill disabled |
SRS-UI-008 |
| TV-UI-011 | Unit | Server-configurable investigational badge: parse pinned against the captured deployed-lambda response (apply text, apply explicit blank, clear on null, ignore missing-text/malformed), three-state effectiveText (absent -> built-in default, text verbatim, blank -> nil/no capsule, clear -> default), refresh apply/clear/failure-inert, and the shared periodic loop fetching both server configs - BionicLoopCloudBannerConfigTests + testStartPeriodicRefreshKeepsRefetchingUntilCancelled; Scout-side route coverage test_banner_config.py (7) and dashboard badge/panel coverage monitoringChromeBadges.test.tsx / bannerConfigApi.test.ts (BionicScout repo) |
SRS-UI-009 |
| TV-ALERT-001 | Unit | Alert normalization maps Omni/G7/runtime events to canonical model fields | SRS-ALERT-001, SRS-ALERT-002 |
| TV-ALERT-002 | Unit/Integration | Alert precedence keeps critical alerts visible when lower-severity alerts coexist and places active pump signal loss above a newer same-severity check-BG prompt while safety-critical severity remains dominant | SRS-ALERT-003, SRS-ALERT-011 |
| TV-ALERT-003 | Integration | Transient reconnect events are debounced/coalesced without suppressing persistent faults | SRS-ALERT-004 |
| TV-ALERT-004 | Integration/System | Alert clear/ack rules behave per alert type and update UI state correctly | SRS-ALERT-005 |
| TV-ALERT-005 | System/Manual | Protocol-required alerts and wording are present and actionable in app flows | SRS-ALERT-006 |
| TV-ALERT-006 | Unit/Integration | High-priority non-CGM alerts emit background local notifications with dedupe/cooldown, while CGM alerts and informational alerts do not | SRS-ALERT-007 |
| TV-ALERT-007 | Unit/UI | Alert Center shows active and recently-cleared alerts with deterministic sorting and acknowledge path for required-ack alerts | SRS-ALERT-008, SRS-ALERT-005 |
| TV-ALERT-008 | Integration | Pump/CGM persisted-alert lifecycle hooks preserve issued/unretracted/retracted state across relaunch and restore active alert visibility | SRS-ALERT-009 |
| TV-ALERT-009 | Unit/Integration | Time-sensitive alert state refreshes at minute cadence while active: countdown wording updates without notification spam, and persisted suspend-ended state escalates once at its 15-minute deadline with a fresh safety-critical notification | SRS-ALERT-010, SRS-ALERT-007, SRS-CLIN-016 |
| TV-ALERT-010 | Unit/UI | Home alert-stack presentation preserves severity, condition-rank, then recency ordering (including pump signal loss above same-severity check-BG), renders the top alert with compressed peek and explicit expansion, applies the root-cause suppression matrix (Home surface only, never safety-critical), and surfaces the hidden related-alert count line whenever suppression hides any active alert | SRS-ALERT-003, SRS-ALERT-011 |
| TV-ALERT-011 | Unit/Integration | No-active-pod cleanup retracts only non-critical pod-tied alerts while retaining ALERT-PUMP-FAULT and ALERT-PUMP-INCOMPATIBLE until explicit closure |
SRS-ALERT-005, SRS-ALERT-012 |
| TV-ALERT-012 | Integration/System | Algorithm Stepping Interrupted issues an actionable alert, clears on resumed successful stepping or loop disarm, and remains distinct from informational G7 unavailable/failed status surfaces |
SRS-ALERT-013, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005 |
| TV-ALERT-013 | Unit/Integration/System | Algorithm Stepping Interrupted issues after >15 minutes without successful step execution while armed, carries blocker/root-cause detail from the latest unresolved runtime outcome/current authoritative pump condition, and clears on next successful step or loop disarm. Verification shall cover stale persisted CGM/pump blocker restoration, fallback-recovery replacement of stale CGM detail even with a broad CGM lifecycle alert active, suspension precedence while the suspend-ended alert remains active, fallback-specific copy after resume, relaunch persistence without a newer result, one-dedupe-key content transition, successful-publication blocker/alert clearing, and Home suppression of the redundant interruption banner while retaining the stronger suspension alert. Pump-status recovery coverage shall additionally prove that a newer active-Pod idle refresh after a pumpStatusUnavailable attempt updates the same alert to communication-restored/waiting-for-glucose copy without triggering doWork; repeated newer idle polls leave the alert timestamp unchanged; stale, unknown, delivering, suspended, and no-active-Pod states do not claim recovery; recovered-waiting state persists across relaunch; a later unknown status restores unavailable guidance; and the next successful step clears both blocker and alert. |
SRS-ALERT-014, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005, SRS-UI-002 |
| TV-ALERT-014 | Unit/Integration | CGM availability/failure normalized alerts remain informational in-app status only, do not expose required-ack behavior, and never schedule background local notifications | SRS-ALERT-015 |
| TV-ALERT-015 | Unit/Integration | App-derived CGM urgent-low review alert issues only for trustworthy G7 readings <55 mg/dL, preserves reviewed state while active, auto-clears on trustworthy recovery >=55 mg/dL, persists acknowledged active state across reset/reattach, and never schedules background local notifications |
SRS-ALERT-016, SRS-ALERT-005, SRS-ALERT-007 |
| TV-ALERT-016 | Unit/Integration | No-active-pod conditions raise a safety-critical pump alert after debounce, repeat background local notification attempts at the approved 30 minute cadence while the condition remains true, and stop repeating when active pod state is restored |
SRS-ALERT-017, SRS-ALERT-007, SRS-ALERT-005 |
| TV-ALERT-017 | Unit/Integration/UI | Algo2015 checkBG output surfaces a deduped prompt stating that either a fingerstick BG check or sensor read is needed for automated dosing to resume, with foreground haptic feedback and Home BG-button emphasis but no inline Enter BG action; it clears on BG entry or flag clear, suppresses repeat alerts while active, does not restore stale active state after relaunch, and preserves unrelated alert actions. The shared emphasis policy includes check-BG/due-soon/overdue direct requests and excludes generic backup-basal/pump/sensor alerts. The accepted breathing state changes only the BG control's centered caution-amber shadow bloom while its ordinary card shadow remains static; Reduce Motion disables the bloom and retains the static border/wash (testAlgorithmCheckBGRequestSurfacesDedupedHapticAlertAndClears, testHomeAlertBannerPrimaryActionPolicyOmitsCheckBGButtonAndRetainsLogin, testManualBGRequestEmphasisCoversOnlyDirectFingerstickRequests, testManualBGRequestPulseAnimatesOnlyLocalizedHalo) |
SRS-ALERT-018, SRS-ALERT-005, SRS-ALERT-007, SRS-UI-002 |
Controlled clarification for TV-PUMP-009 (v1.59): the fresh-completion regression set includes testCanceledPartialBolusEvidenceSurvivesZeroNotDeliveredRegisterAfterRelaunch, testExplicitInProgressCapAllowsPostCompletionUpgrade, testEngineKeepsCanceledPartialEvidenceUnchanged, testEngineKeepsAssumedEvidenceUnchanged, testIssuedDoseEvidencePersistsCanceledObservationContext, testIssuedDoseEvidenceDecodesLegacyRecordWithoutObservationContext, and testIssuedDoseEvidencePersistsCanceledObservationContext. Together they pin that a zero bolusNotDelivered register is not completion proof after cancellation; only explicitly persisted in-progress-capped provenance may authorize a higher settled observation, while canceled and legacy-unclassified partial evidence remains authoritative.
Controlled clarification for TV-PUMP-009 (v1.71): LoopRuntimeCoordinatorPumpCommandClassificationTests.testDoWorkMapsBlockedPumpCommandExecutionErrorToBlockedOutcome reproduces a locally started request that is definitively rejected and otherwise appears as a fabricated full delivery; it verifies matching cleanup and no surviving lastDelivery. The uncertain-outcome companion verifies no cleanup. BionicLoopPumpServiceAdapterDisconnectTests.testDefinitivelyBlockedBolusClearsOnlyMatchingCachedRequest pins request-step/unit matching so cleanup cannot erase a newer request.
| TV-ALERT-018 | Unit/Integration/Characterization | Algo2015 forced-open-loop output is reachable under sustained missing-CGM characterization, blocks automated pump commands after pre-command fallback maintenance, records algorithm telemetry, surfaces a safety-critical recovery alert, persists that alert across skipped/no-telemetry publications, and clears only on explicit later inactive forced-open output | SRS-ALERT-019, SRS-ALERT-003, SRS-ALERT-005, SRS-ALERT-007 |
| TV-ALERT-019 | Unit/Integration | G7 replacement acquisition has no alert before ten minutes, raises the approved actionable copy at the exact boundary, routes alert navigation to CGM Settings, does not restore stale LoopKit alert payloads, and auto-clears when replacement mode ends. The delayed evaluation task is canceled on manager detach/deletion and the condition does not generate a BionicLoop background CGM notification. | SRS-ALERT-020, SRS-ALERT-015 |
| TV-SEC-001 | Unit/Integration | Local export controls: file-sharing keys absent from the built bundle (testAppInfoPlistDoesNotEnableDocumentsFileSharing), CSV export in Application Support with complete-protection writing options + backup exclusion + legacy Documents cleanup (LoopTelemetryStoreTests), spool until-first-unlock protection + backup exclusion (testFileStoreSpoolCarriesUntilFirstUnlockProtectionAndBackupExclusion), and protection/backup-exclusion application to enumerated Algo2015 diagnostic artifacts (testAlgo2015TailReadAppliesArtifactProtectionToDiscoveredFiles) | SRS-SEC-001, SRS-SEC-002 |
Controlled Build 843 clarification (v1.91): the dependency-control companion
checks CryptoSwift's official source URL, exact 1.10.0 project requirement,
resolved revision, and tracked lockfile status. Build 843 is the IDE submission
build designated on 2026-09-03. Build 843 evidence and traceability were
accepted under D08 on 2026-09-07 EDT.
| TV-SEC-002 | Integration/System | Deferred from current software package. If Scout becomes relied upon for required study data or safety decisions, verify the defined phone-to-cloud telemetry contract, upload control behavior, completeness, and failure handling. | SRS-SEC-001 |
| TV-SEC-003 | Integration/System | Deferred from current software package. If protected cloud API access is re-entered into scope, verify it requires valid authenticated session. | SRS-SEC-003, SRS-SEC-006 |
| TV-SEC-004 | UI/Integration | Deferred from current software package. If multi-provider onboarding is re-entered into scope, verify allowed sign-in entry points and failure states. | SRS-SEC-004, SRS-SEC-006 |
| TV-SEC-005 | Integration/System | Deferred from current software package. If authorization-role enforcement is re-entered into scope, verify unauthorized telemetry/dashboard actions are denied. | SRS-SEC-005, SRS-SEC-006 |
| TV-SEC-006 | Unit/Integration | Deferred from current software package. If password-recovery workflow is re-entered into scope, verify reset-code request and confirm-reset success/failure handling. | SRS-SEC-007, SRS-SEC-006 |
| TV-SEC-007 | Unit/Integration | Deferred from current software package. If launch session restore is re-entered into scope, verify authenticated UX is preserved when token recovery succeeds. | SRS-SEC-008, SRS-SEC-006 |
| TV-SEC-008 | Unit/UI | Deferred from current software package. If auth-failure Home-bypass continuity is re-entered into scope, verify signed-out active therapy keeps persistent top-level Home login access independent of alert order; Home/Alert Center/Account & Session and notification routes enter login; and recovery presentation does not stop/reset the local algorithm session. | SRS-SEC-009, SRS-SEC-006 |
5.0 Algo2015 Structural-Coverage Campaign¶
-
Algo2015DualInstanceIsolationTests(testInterleavedSafetyStepsDoNotAdvancePrimaryBufferPosition,testPrimaryDropoutClockRunsOnWallStepsWithSafetyTrackInterleaved,testPrimaryCGMAcceptanceTrackingStaysDenseWithSafetyTrackInterleaved) pins the two-live-instance isolation contract against the real C++ pairing: the primary's buffer position advances exactly one per primary step with the safety track interleaved, the CGM-dropout tolerance forces open loop exactly on the 13th blind step (65 min > the 60-minuteDropout_LimitT), and CGM-acceptance tracking stays dense (TV-ALG-004supporting evidence and shared-state regression guard). -
Algo2015ManualBGDropoutClockCharacterizationTests(testManualBGAfterForcedOpenClearsAndRestartsTheFullWindow,testManualBGMidDropoutRestartsTheWindowFromTheBGStep) characterizes the fingerstick-BG dropout-clock contract against the real C++: an accepted BG clears forced-open on its own step, catches the acceptance index up to the buffer position, and restarts the full 60-minute window (12 further blind steps tolerated; forced-open on the 13th after the BG). This supportsSRS-OUTAGE-001..006,SDD-OUTAGE-001, andTV-ALG-004. -
Fingerstick-supported CGM-outage working coverage (2026-07-14):
OutageBGRunPolicyTests(11),MaskedFallbackMaintenancePolicyTestsreleased-for-outage gates (2),BionicLoopRuntimeEnginePrePumpCommandMaintenanceTestsbridge transitions + full sequence (5),BionicLoopRuntimeEngineOutageBGRunTestscontext/outage-detection/alert tiers (11),BionicLoopAppAlertDomainSupportTestsoutage preview pins,PumpCommandWatchdogTests(5),BionicLoopPumpDelegateContractTests(2). -
Build-profile working coverage (2026-07-15) - retired 2026-07-16 with the SRS-LOG-010 supersession: the parse and launch-reconcile pins were deleted with the profile/session code (the former cloud-log session infrastructure test class was removed; its threshold-filter coverage moved into
BionicLoopCloudLogPolicyInfrastructureTests). The Scout-sidetest_CT_J5_013...ingest pin remains valid forapp_version/build_numberon the CloudWatch line and tolerates the now-unused session metadata keys. -
Remote-config + diagnostics working coverage (2026-07-16):
BionicLoopCloudLogPolicyInfrastructureTestsremote-config parsing/apply pins (2),BionicLoopUserNotificationAppAlertSchedulerTestsauthorization-status enrichment pins (2),PumpCommandWatchdogTeststimeout-observer pins (2); Scout-side route coveragetest_logging_config.py(5: null read, group guard, write/read/clear roundtrip, expired-null, invalid-input 400s). -
Real-device observations are retained as supporting engineering evidence only. The submission does not claim a separate formal hardware-validation study; any future physical claim requires a controlled protocol, acceptance criteria, retained operator record, and evidence disposition.
TV-ALG-010 uses the thresholds stated in its verification row above. The
controlled STR must retain the baseline identity, execution environment,
executor, checksums, coverage reports, and an exception package for every
shortfall. The exact-freeze results and controlled locators are summarized in
Appendix A07, the Formal Evidence Index.
5.1 Deterministic Simulation Campaign¶
This campaign adds deterministic scenario replay (medium-fidelity mocks) as a required verification layer for runtime safety logic. It complements hardware-in-the-loop testing and does not replace real-device validation.
| Test ID | Level | Purpose | SRS Link |
|---|---|---|---|
| TV-SIM-001 | Integration (deterministic sim) | Reproduce anchored cadence across reconnect/relaunch windows and assert step index continuity (expected, executed, skipReason) |
SRS-RUN-001, SRS-RUN-002, SRS-STATE-001 |
| TV-SIM-002 | Integration (deterministic sim) | Validate step-0 hard gate and step>0 degraded CGM execution (-1) across stale/out-of-range/noisy sensor sequences |
SRS-CGM-001, SRS-CGM-002, SRS-CGM-003 |
| TV-SIM-003 | Integration (deterministic sim) | Validate pump-unknown/unavailable execution with command-block and no false delivery application | SRS-PUMP-001, SRS-PUMP-005 |
| TV-SIM-004 | Integration (deterministic sim) | Validate meal and BG trigger interplay under missed-step, reconnect, and degraded-input conditions | SRS-MEAL-001, SRS-MEAL-002, SRS-BG-002, SRS-BG-003 |
| TV-SIM-005 | Integration (deterministic sim) | Validate alert lifecycle, countdown refresh progression, dedupe, and clear behavior during state churn | SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-010 |
| TV-SIM-POD-001 | Integration (deterministic pod simulation) | Validate stateful pod ledger math for bolus progress/cancel, fallback mask expiry/renewal, pod expiry, and pod replacement identity continuity without live pod burn | SRS-PUMP-006, SRS-PUMP-008, SRS-RUN-006 |
| TV-SIM-POD-002 | Integration (deterministic pod simulation) | Validate pending issued-dose restoration and replay through simulated pump status using production runtime coordinator logic | SRS-STATE-005, SRS-MEAL-005, SRS-LOG-009 |
| TV-SIM-POD-003 | Integration (deterministic pod simulation) | Validate that meal/correction delivery completed before the fallback baseline is not subtracted from fallback pump-total delta | SRS-PUMP-008, SRS-PUMP-009, SRS-LOG-009 |
| TV-SIM-POD-004 | Integration (deterministic pod simulation) | Validate high-risk pod scenarios using shared invariants: canceled and consecutive-canceled meal evidence feed subsequent meal announcements without replay or stale evidence reuse, force-quit/relaunch restores in-flight meal delivery knowledge before the next CGM, relaunch with pending fallback replay after step 0 can replay with unavailable CGM inputs without dropping the plan, lost final meal response before status refresh is preserved until same-pod reconnect, same-pod completed meal and reservoir-capped partial meal evidence feed the live attribution step without replay, different/new-pod, user-escaped unavailable-pod, and unresolved correction-only/basal-only issued doses are assumed delivered without blocking replacement-pod dosing when policy allows, stale cached idle is not trusted when fresh refresh fails, fallback maintenance block prevents the live bolus command, meal/fallback delta partitioning separates issued dose from fallback residual, fallback replay allocation follows the programmed schedule weights only after mask expiry, reservoir-capped fallback replay uses observed pump delta instead of modeled exposure, ambiguous fallback restore does not replay or inject modeled fallback insulin into the live step, assumed old-pod fallback replay emits no pump commands and allows replacement-pod live dosing, missing-status/nonreplayable fallback plans are cleared without row emission, matching pending meal-progress state clears when issued-dose evidence is consumed, and app recent-dose rows, local step CSV export, and runtime cloud step-event emission preserve/display merged replay evidence source, disposition, request step, requested units, and delivered units | SRS-PUMP-008, SRS-PUMP-009, SRS-PUMP-010, SRS-MEAL-005, SRS-LOG-009 |
Controlled evidence:
- STR-SIM-* scenario reports with script file, expected output snapshot, actual output snapshot, and pass/fail deltas.
- Controlled simulation harness: emits run-context, results, trace-map, and suite logs.
- Risk-based merge gate: runs TV-SIM-* / pod-sim rows when high-risk runtime, pump, fallback, or reconciliation paths are touched.
- Exact-freeze result: Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/.
Future extension (high-fidelity): - After medium-fidelity stability, add BLE/session-level emulation cases for hardware-specific transport faults and timing jitter that mock services cannot represent.
Current implemented deterministic simulation coverage:
- testTVSIM001_AnchoredCadenceAcrossReconnectAndRelaunch (TV-SIM-001)
- testTVSIM002_StepZeroGateAndStepGreaterThanZeroDegradedCGMExecution (TV-SIM-002)
- testTVSIM003_PumpUnavailableAndUnknownStatesBlockLiveExecution (TV-SIM-003)
- testTVSIM004_MealAndBGInterplayAcrossMissedStepsAndReconnectChurn (TV-SIM-004)
- testTVSIM005_AlertLifecycleChurnCountdownDedupeAndClearTransitions (TV-SIM-005)
- testSimulatedDashPodReportsBolusProgressAndCancelPartialDelivery (TV-SIM-POD-001)
- testSimulatedDashPodAccruesFallbackBasalOnlyAfterMaskExpires (TV-SIM-POD-001)
- testSimulatedDashPodDoesNotExposeFreshFallbackDeltaWhileDisconnected (TV-SIM-POD-001, TV-SIM-POD-003)
- testSimulatedDashPodMaskRenewalExtendsZeroBasalSuppression (TV-SIM-POD-001)
- testSimulatedDashPodExpiryStopsDeliveryAndReportsUnknownState (TV-SIM-POD-001)
- testSimulatedDashPodReplacementResetsCountersAndRejectsOldPodAttribution (TV-SIM-POD-001)
- testSimulatedDashPodReplacementClearsSuspendedState (TV-SIM-POD-001)
- testSimulatedDashPodCapsBolusDeliveryAtReservoirRemaining (TV-SIM-POD-001)
- testScriptedPodPumpServiceDoesNotReportStartForPreStartBolusFailure (TV-SIM-POD-001)
- testSimulatedDashPodRestoresPersistedPendingDoseFromPastRequestTime (TV-SIM-POD-002)
- testSimulatedDashPodDoesNotAdvanceClockForFuturePendingAttributionRestore (TV-SIM-POD-002)
- testScriptedPodPumpServiceFeedsCompletedIssuedDoseIntoReplayWithoutHardwareFixtures (TV-SIM-POD-002)
- testCompletedMealBeforeFallbackBaselineDoesNotPolluteFallbackDelta (TV-SIM-POD-003)
- testMealDoseOverlappingFallbackWindowPartitionsPumpDeltaBeforeFallbackReplay (TV-SIM-POD-003, TV-SIM-POD-004)
- testPodScenarioCanceledMealEvidenceFeedsNextMealAnnouncementWithoutReplay (TV-SIM-POD-004)
- testPodScenarioConsecutiveCanceledMealsConsumeLatestEvidenceWithoutReplay (TV-SIM-POD-004)
- testPodScenarioForceQuitRelaunchRestoresInFlightMealBeforeNextCGM (TV-SIM-POD-004)
- testPodScenarioLostFinalMealResponseDisconnectsBeforeRefreshThenReconcilesOnSamePodReconnect (TV-SIM-POD-004)
- testPodScenarioSamePodCompletedMealFeedsLiveAttributionStepWithoutReplay (TV-SIM-POD-004)
- testPodScenarioReservoirCappedMealFeedsActualDeliveredUnitsWithoutReplay (TV-SIM-POD-004)
- testPodScenarioDifferentOrNewPodAssumesIssuedDoseAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioReplacementAfterUnreconciledOldPodDoseAssumesOldDoseAndAllowsNewPodLiveDose (TV-SIM-POD-004)
- testPodScenarioUserEscapedUnavailableOldPodConsumesAssumedEvidenceAndAllowsNewPodDose (TV-SIM-POD-004)
- testPodScenarioUnresolvedCorrectionWithoutPodIdentityAssumesDeliveredAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioUnresolvedBasalMicrodoseAssumesDeliveredAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioStaleCachedIdleDoesNotAuthorizeBolusWhenFreshRefreshFails (TV-SIM-POD-004)
- testPodScenarioFallbackMaintenanceBlockPreventsLiveBolus (TV-SIM-POD-004)
- testPodScenarioFallbackReplayUsesScheduleWeightsOnlyAfterMaskExpiry (TV-SIM-POD-004)
- testPodScenarioReservoirCappedFallbackReplayUsesObservedPumpDelta (TV-SIM-POD-004)
- testPodScenarioMealOverlapPartitionsPumpDeltaAndMergesIntoFallbackReplay (TV-SIM-POD-004)
- testPodScenarioPendingFallbackReplayRunsOnRelaunchWithoutFreshCGMAfterStepZero (TV-SIM-POD-004)
- testPodScenarioAmbiguousFallbackRestoreDoesNotReplayOrInjectModeledDose (TV-SIM-POD-004)
- testPodScenarioAssumedFallbackReplayFromUnavailableOldPodAllowsReplacementDose (TV-SIM-POD-004)
- testPodScenarioNonReplayableFallbackPlanClearsWithoutReplayOrModeledDoseInjection (TV-SIM-POD-004)
- testRecentDoseTimelinePersistsMergedMealFallbackReplayEvidenceLabels (TV-SIM-POD-004)
- testCSVExportIncludesFallbackReplayRows (TV-SIM-POD-004, TV-LOG-002, TV-LOG-009)
- testEmitExecutionTelemetryPublishesReplayAndLiveAlgorithmStepSnapshots (TV-SIM-POD-004, TV-LOG-009)
Current implemented alert-test coverage:
- testTopAlertPrefersHigherSeverityThenMostRecent and testSortedAlertsOrdersBySeverityRecencyAndStableDedupeKey cover deterministic alert ordering precedence (TV-ALERT-002 subset).
- testHomeSurfaceHidesSteppingInterruptedWhileASpecificPauseExplainsIt, testHomeSurfaceHidesCommandBlockedDuringPumpOutage, testHomeSurfaceNeverSuppressesSafetyCriticalAlerts, testHomeSurfaceKeepsUnrelatedAlertsUntouched, and testHomeHiddenAlertCountReportsSuppressedAlertsSoHomeCanPointAtAlertCenter cover the Home alert-stack root-cause suppression matrix: generic stepping-interrupted/command-blocked alerts hidden only while a specific active alert explains them, safety-critical alerts never suppressed, unrelated alerts untouched, and the hidden-related-alert count that drives the Home "related alert in Alert Center" affordance so the bell badge and Home surface never silently disagree (TV-ALERT-010 subset).
- testNoActivePodDebounceAddsAndClearsAlert, testNoActivePodConditionRepeatsBackgroundNotificationUntilRecovered, and testHomeAlertSyncEvaluatorReflectsCombinedPumpConditions cover no-active-pod alert path, repeated safety-critical background notification attempts while the condition remains true, clear-on-recovery behavior, and suppression of competing signal-loss state when no pod is present (TV-ALERT-003, TV-ALERT-004, TV-ALERT-016 subset).
- testSignalLossDebounceAddsAndClearsAlert covers debounce + auto-clear behavior, actionable background notification cooldown/dedupe, and clear-on-retract notification cleanup (TV-ALERT-003, TV-ALERT-004, TV-ALERT-006 subset).
- testSignalLossDebounceSuppressesTransientCondition covers transient suppression and notification authorization priming dedupe (TV-ALERT-003, TV-ALERT-006 subset).
- testShowPreviewAlertsSupportsMultipleTypesAndPrecedence covers severity-filtered background notification routing (critical not informational), alert-category route mapping, and safety-critical acknowledge behavior (TV-ALERT-002, TV-ALERT-004, TV-ALERT-006 subset).
- testCloudTelemetryReporterSurfacesSubjectIDConflictAndStopsRetryFor409Conflict, testHomeSettingsViewClearsResolvedSubjectIDConflictAlert, testSubjectIDConflictAutoResolutionPolicyRequiresActiveAlertNonEmptySubjectAndNoInFlightCheck, and testSubjectIDConflictAutoResolutionPolicyThrottlesSameSubjectAndAllowsChangedSubject cover the app-policy subject-ID conflict alert lifecycle: issue on permanent cloud claim conflict, explicit retract after successful corrected Clinical Settings save, and throttled Home auto-revalidation of the currently persisted subject ID when a stale conflict alert remains active (TV-ALERT-005 subset).
- testCGMAlertsNeverScheduleBackgroundNotifications, testCGMAlertMapperFailedFromSensorFailedState, testCGMAlertMapperUnavailableFromWarmupState, and testCGMFailedAlertRestoresFromLiveStateAcrossAlertCenterResetUntilRecovery cover the CGM availability/failure policy: informational in-app status only, no required-ack path, and no background local notifications (TV-ALERT-014, TV-ALERT-006 subset).
- testCGMUrgentLowAlertMapperIssuesForReliableReadingBelow55, testCGMUrgentLowAlertMapperClearsAt55OrAbove, testCGMUrgentLowAlertMapperSkipsUnreliableReading, testCGMUrgentLowAlertMapperSkipsStaleReading, testUrgentLowAcknowledgeMarksAlertReviewedWithoutClearingActiveState, testCGMUrgentLowAcknowledgePersistsAcrossAlertCenterResetUntilRecovery, and testCGMAlertsNeverScheduleBackgroundNotifications cover the app-derived urgent-low review alert trigger, trustworthy-data gate, reviewed-state retention, reset/reattach persistence, recovery auto-clear, and no-OS-notification policy (TV-ALERT-015, TV-ALERT-006 subset).
- testAlgorithmCheckBGRequestSurfacesDedupedHapticAlertAndClears, testAlgorithmCheckBGRequestDoesNotRestoreAfterRelaunch, and testLoopRuntimeEngineSurfacesAndClearsCheckBGRequestFromAlgorithmOutput cover the Algo2015 checkBG nudge: prompt creation, haptic-on-new-request behavior, dedupe while active, clear on flag clear, runtime publication, and stale-relaunch suppression (TV-ALERT-017 subset).
- testForcedOpenLoopOutputIsReachableAfterSustainedMissingCGM, testForcedOpenLoopOutputBlocksAutomatedPumpCommandAfterMaintenance, and testLoopRuntimeEngineSurfacesAndClearsForcedOpenLoopOutput cover the Algo2015 forced-open-loop path: C++ reachability after sustained missing CGM, pre-command maintenance preservation, automated-command block, telemetry retention, safety-critical alert issue/retention across skipped publications, and explicit clear on a later non-forced-open algorithm output (TV-ALERT-018 subset).
- testAlertCenterTracksRecentlyClearedAlerts and testAlertCenterRestoresPersistedActiveAndClearedAlerts cover in-app Alert Center active/recent behavior and persistence restore path (TV-ALERT-007, TV-ALERT-008 subset).
- testPumpAlertMapperExpiringIncludesCountdownDeadline, testPumpAlertMapperExpiredForPodExpiringAlert, and testTimeSensitivePumpExpiringAlertRefreshesMessageWithoutReschedulingNotification cover pod-expiration countdown mapping (expiring and expired paths) plus minute-refresh text updates without extra background notification scheduling (TV-ALERT-009, TV-ALERT-006 subset).
- UI automation now covers Home-to-Alert-Center routing, acknowledge-to-recent flow, and relaunch persistence visibility (testUI007_HomeAlertCenterButtonOpensAlertCenter, testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared, testUI009_AlertCenterPersistsAcrossRelaunch) (TV-ALERT-007, TV-ALERT-008 subset).
- testPumpPersistedAlertStoreReturnsIssuedAndRetractedAlerts and testCGMPersistedAlertStoreReturnsIssuedAndRetractedAlerts cover delegate PersistedAlertStore issue/retract lookup behavior (TV-ALERT-008 subset).
- testPumpExpirationAlertSyncPlannerReturnsRetractsWhenNoExpirationAlertsApply covers no-active-pod retract-set safety boundary by excluding critical fault/incompatible alerts from auto-retract cleanup (TV-ALERT-011 subset).
- testCGMAlertMapperPrioritizesUnavailableOverFailedKeywordCollision and testCGMAlertMapperDoesNotClassifyMessageOnlyFailedAsSensorFailure verify CGM fallback keyword mapping cannot escalate transient/message-only text into ALERT-CGM-FAILED-OR-EXPIRED (TV-ALERT-001 subset).
Current implemented runtime-refactor regression coverage:
- testMealPumpUnavailableReasonMapping verifies meal-unavailable reason precedence (noPump over signalLoss when no active pod exists) (TV-MEAL-005 subset).
- testMealAnnouncementSheetLifecycleRevalidatesOnlyOnForeground, testHomeRuntimeActionCoordinatorMealComposerContinuationDecision, testMealComposerRevalidationRearmsInPlaceWhenSlotConflictButFreshCheckIsAvailable, testMealComposerRevalidationShowsInlineUnavailableUsingFreshReasonAfterSlotConflict, testMealComposerRevalidationShowsInlineUnavailableForNonConflictReasons, testMealComposerRevalidationPrefersCancelDeliveryWhenPumpDeliveringWithContext, and testMealComposerRevalidationContinuesWhenSubmitAvailabilityIsAvailable verify the foreground revalidation gate, the entry-time stale-composer remapping, and the open-composer revalidation policy: in-place re-arm on stale observed step with an available fresh check, inline blocked messaging using the fresh reason, cancel-delivery precedence, and continue-on-available (TV-MEAL-007 subset).
- testMealComposerRevalidationShowsWaitingNoticeWhenBackupBasalWhileCarveOutBGConsumptionInFlight, testMealComposerRevalidationShowsGenericBackupBasalMessageWithoutCarveOutConsumption, testMealComposerRevalidationShowsWaitingNoticeForFreshBackupBasalAfterSlotConflict, testMealComposerRevalidationStillBlocksUnreconciledIssuedDoseWhenCarveOutBGConsumptionInFlight, testPumpDeliveringRevalidationReplacesTransientBGWaitingNotice, testReclosedLoopStepAfterCarveOutConsumptionRearmsComposerInPlace, testForcedOpenAvailabilityDuringInFlightCarveOutConsumptionRoutesToWaitingNotice, testForcedOpenAvailabilityAfterConsumingStepPublishedShowsGenericBackupBasalMessage, testMealComposerRevalidationRearmsFromConsumedCarveOutWhenFreshAvailabilityRecovers, testMealComposerRevalidationContinuesFromConsumedCarveOutWhenSubmitAvailabilityIsAvailable, testMealComposerCarveOutBGTargetStepCapturedOnlyWithPendingValue, testMealComposerCarveOutBGConsumptionInFlightRequiresClearedValueAndUnpublishedQualifyingStep, and testMealComposerSubmitHoldsForCarveOutBGConsumptionOnlyWhenBackupBasalAndInFlight verify SRS-MEAL-006 v1.55: the transient waiting hold when a loop step has cleared the pending fingerstick but its qualifying-glucose marker has not published, including the field shape where a pre-command checkpoint already reports lastExecutedStep == capturedTarget; completion on the matching marker; immediate connected pump-busy presentation; generic backup-basal fallback after completed/nonqualifying passage; unreconciled-issued-dose isolation; recovery re-arm/continue; and the submit-time hold predicate. testSubmitAvailabilityPreservesHigherPriorityRuntimeBlocks additionally pins the backupBasalRunning passthrough (TV-MEAL-007 subset).
- testMealAnnouncementAvailabilityBlocksPersistedPendingMealRequestAcrossRelaunch, testMealAnnouncementAvailabilityReconcilesResolvedPendingMealRequestOnLaunch, testMealAnnouncementAvailabilityConsumesPersistedResolvedTelemetryReplayStateOnLaunch, testReconciledPendingMealAnnouncementStateClearsWhenTargetStepAlreadyExecuted, testMealAnnouncementResolutionEventUsesPersistedFlowIDForResolvedPendingState, and testMealAnnouncementResolvedEventUsesPersistedResolvedTelemetryReplayState verify persisted pending meal-request durability, relaunch duplicate blocking, replay-token consumption, target-step reconciliation, and correlated flow-ID closure for resolved lifecycle telemetry (TV-MEAL-009 subset, TV-LOG-007 subset).
- LoopRuntimeCoordinatorMealAnnouncementDurabilityTests.testMealAnnouncePersistsPendingMealOnlyAfterExecutionStepAccepted and LoopRuntimeCoordinatorMealAnnouncementDurabilityTests.testMealAnnounceRejectedBeforeAcceptanceDoesNotPersistPendingMealState verify that pending meal state is written only after the coordinator has accepted a concrete execution step and is not left behind for rejected meal attempts (TV-MEAL-009 subset).
- testAnnounceMealReturnsBlockedWhenLoopIsOff, testAnnounceMealReturnsBlockedWhenPersistedPendingMealExists, testReconciledUncertainPendingMealAnnouncementStateClearsWhenPumpDeliveryMatchesTargetStep, testMealAnnouncementResolutionEventUsesReconciledAfterUncertainForUncertainClear, testMealAnnouncePersistsPendingMealOnlyAfterExecutionStepAccepted, testMealAnnounceRejectedBeforeAcceptanceDoesNotPersistPendingMealState, testMealAnnounceUncertainDeliveryRetainsPendingMealState, and testHomeMealAnnouncementSubmitPolicyBuildsSubmissionContext, testHomeMealAnnouncementSubmitPolicyEmitsLifecycleEvents, testHomeMealAnnouncementSubmitPolicyRequiresFlowIDForLifecycleEvents verify that meal submit no longer reports optimistic success, that blocked runtime outcomes map to explicit blocked results, and that Home/runtime expose deterministic submitted/accepted/success/uncertain/resolved telemetry closure with explicit uncertain reconciliation semantics (TV-MEAL-008, TV-MEAL-010, TV-LOG-007 subset).
- testHomeRuntimeActionCoordinatorRoutesActiveMealDeliveryToCancelDeliveryFlow, testMealAnnouncementCancelledDeliverySummaryUsesPartialDeliveryCopy, testMealAnnouncementCancelledDeliverySummaryHandlesNoDeliveredInsulin, testMealAnnouncementCancelledDeliverySummaryIncludesCancelDetails, testMealAnnouncementCancelledDeliveryPolicyRequiresFiveMinutesAndNextStep, testMealAnnouncementCancelledDeliveryPolicyUsesNextStepThreshold, testMealAnnouncementDisplaySupportMapsMealContext, testPumpServiceAdapterCancellationDeliveryStatusUsesRequestedAndDeliveredUnits, testPumpServiceAdapterCancellationDeliveryStatusInfersPartialWhenDeliveredUnitsAreMissing, testPumpServiceAdapterResolvedBolusDeliveredUnitsPrefersPodCompletionWhenEventHistoryLags, testPumpServiceAdapterResolvedBolusDeliveredUnitsUsesBestAvailableProgressWhileBolusing, testPumpServiceAdapterAuthoritativeCompletedDeliveryPrefersCanceledUnitsWhenIdle, testCanceledMealDeliveryRecordsEvidenceAndClearsPendingMealBlock, testMealAnnouncementAvailabilityAllowsPersistedMealAttributionWithMatchingEvidence, testMealDeliveryProgressRestorePolicyDoesNotRestoreAfterMatchingEvidenceIsStored, testMealDeliveryProgressRestorePolicyRequiresMatchingPodIdentity, testRecordDoWorkResultMarksSuccessfulBolusAsDeliveringBeforePumpRefresh, testReconcilePumpStatusUpdatesInterruptedDeliveryToCompletedAfterLaterRefresh, testReconcileCanceledDeliveryUsesDeliveredUnitsForInterruptedMealBar, testPumpStatusObserverRefreshReconcilesSharedTelemetryStoreUntilDeliveryCompletes, testPumpStatusObserverApplyCanceledBolusDeliveryReconcilesSharedTelemetry, testInsulinChartPointFlagsInterruptedDeliveryWhenDeliveredLessThanRequested, testInsulinChartPointDoesNotFlagActiveDeliveryAsInterrupted, testInlineInsulinChartStylingUsesCautionColorForInterruptedDelivery, testInlineInsulinPointCompactorPreservesDeliveringStateWhenCollapsingPoints, testHomeViewStateBuilderActiveMealDeliveryCancellationContextUsesOnlyDeliveringMealStep, and testUI002b_MealCancelDeliveryFlowShowsPartialDeliverySummaryAndComposer verify the meal cancel-delivery path: active-delivery routing into a destructive Home inline cancel flow, automatic visibility of the cancel control while a meal bolus is still actively delivering, requested/delivered-unit reporting after cancellation, orange partial-delivery context in Home's alert-summary region above the chart, cancel-time plus meal-context summary detail, optimistic active-delivery chart state immediately after a successful bolus command, explicit canceled-delivery reconciliation into shared step telemetry so interrupted bar height matches actual delivered insulin, normal meal-color chart rendering while delivery is still active, compactor preservation of delivering state when bars visually collapse, caution-color rendering only for actual interrupted delivery derived from requested-vs-delivered telemetry, later pump-refresh reconciliation back to completed delivery when the bolus finishes normally, pod-status flooring when event-history delivery lags, immediate persisted cancellation evidence for runtime meal-unblock/replay accounting, restore suppression only for attribution/evidence with matching pod identity, and preservation of delivered insulin accounting for the next algorithm step when the operator later reopens meal announce (TV-MEAL-012 subset, TV-PUMP-003 supporting coverage).
- BionicLoopMealAnnouncementRuntimeTests and BionicLoopMealAnnouncementPodReplacementEscapeTests cover testMealDeliveryPodReplacementEscapePolicyRequiresMealAndElapsedCompletionWindow, testMealDeliveryPodReplacementEscapePolicyAllowsKnownUnavailablePodWithoutWaitingForGrace, testMealDeliveryPodReplacementEscapePolicySuppressesEscapeAfterMatchingEvidence, testUserAbandonedMealDeliveryRecordsAssumedDeliveredEvidenceForPodReplacement, and testUserAbandonedMealDeliveryDoesNotResolveNonMealIssuedDose, verifying the explicit user-confirmed pod-replacement escape: availability only for matching meal-linked attribution, timeout/known-unavailable gating, suppression after matching evidence, assumed-delivered evidence persistence with user_abandoned_unavailable_pod, meal-progress field clearing, issued-dose attribution preservation for replay/live accounting, and correction-only suppression (TV-MEAL-013, TV-PUMP-009 supporting coverage).
- testCorrectionDeliveryCreatesPendingIssuedDoseAttribution, testPendingIssuedCorrectionDoesNotAdvanceWhilePumpStillDelivering, testFreshIdleStatusAfterPhysicalCompletionConsumesPendingIssuedDose, testThreeUnitBolusLeavesDeliveringBeforeNextFiveMinuteStep, testDisconnectedPodDoesNotReportDeliveringDuringBolusOutage, testReconciledCorrectionDeliveryReplaysFirstMissedPostDoseStepBeforeLiveResume, testReconciledMealDeliveryReplaysFirstMissedPostMealStepBeforeLiveResume, testIssuedDoseAttributionWithNonCredibleDeliveredUnitsAssumesRequestedDoseAndReplays, testFallbackBasalExposureReconcilerPartitionsIssuedDoseFromPumpDeltaBeforeCredibilityCheck, testFallbackBasalExposureReconcilerRejectsPendingIssuedDoseWhenPumpDeltaCannotCoverRequest, testFallbackBasalExposureReconcilerRejectsPartitionWhenResidualDoesNotMatchFallbackExposure, testFallbackBasalExposureReconcilerAcceptsLowerResidualAfterIssuedDosePartition, testFallbackBasalExposureReconcilerPartitionsPersistedIssuedDoseEvidence, testPartitionedIssuedDoseEvidenceReplaysWhenPumpLastDeliveryIsUnavailable, testPartitionedIssuedDoseEvidenceMergesWithFallbackReplayWhenPumpLastDeliveryIsUnavailable, testPartitionedIssuedDoseEvidenceFeedsLiveFirstAttributionStepWhenReplayIsNotRequired, testReconnectRecoveryPartitionsPendingIssuedDoseBeforeFallbackReplayPlanning, testReconnectRecoveryUsesLowerFallbackResidualAfterIssuedDosePartition, testAmbiguousPartitionCarriesPumpTotalWithoutClaimingFallbackActualDelivery, testRecentDoseTimelineFallbackReconnectRecoveryTextDoesNotClaimResidualForPumpTotalOnly, testMealDeliveryAttributionMergesWithEchoedAskWhenNoPreFallbackRoomExists, testMealDeliveryAttributionPrecedingFallbackReplaysPureConfirmRowBeforeFallbackRows, testMealDeliveryAttributionPrecedingFallbackRetractsSentinelAsksAcrossWiderDeadGap, testPreActivationIssuedDoseReplaysConfirmRowAndSentinelsBeforeFallbackRows, testFallbackReplayPumpStatusDoesNotMergeNonCredibleIssuedDoseDelivery, testMealDeliveryAttributionAssumesDeliveredWithoutMatchingPumpEvidence, testMealDeliveryAttributionAssumesDeliveredWhenPumpEvidenceMismatchesRequest, testUnresolvedIssuedDoseAssumesDeliveredAndReplaysBeforeLiveStep, testIssuedDoseAttributionWithoutPodIdentityAssumesDeliveredAndReplays, testIssuedDoseAttributionAssumesDeliveredForDifferentOrNewPodAndReplaysBeforeLive, testIssuedDoseAttributionAssumesDeliveredForDifferentOrNewPodEvenWhenObservedPodIsDelivering, testPersistedAssumedDeliveredEvidenceKeepsClinicalPolicyReplayDisposition, testAssumedDeliveredDifferentOrNewPodFallbackMergeScrubsReplacementPodDeliveryFromLiveStep, testAssumedDeliveredDifferentOrNewPodAllowsFutureAutomaticInsulinCommand, testRuntimeResolutionDismissesWhenMatchingPendingMealAttributionClears, testRuntimeResolutionNeverDismissesSimulatedPreviewProgress, testMealAnnouncementAvailabilityIgnoresLegacyDifferentNewPodHoldAcrossRelaunch, testMealAnnouncementAvailabilityBlocksBlockingIssuedDoseAttribution, and testBlockedMealAnnouncementAvailabilityMapsIssuedDoseReconciliationPending verify generalized issued-dose attribution, active-delivery step blocking, the accepted DASH no-boundary-cancel liveness bound and fresh idle unblock path, same-request/same-pod missed-step replay, pump-total partition of known in-flight issued dose from fallback basal residual, acceptance of lower pump-reported fallback residuals after issued-dose subtraction, persisted partition evidence consumption on the live first attribution step when replay is not required, raw pump-total telemetry without claiming fallback residual in ambiguous/unresolved recovery, delivered-unit credibility rejection for over-modeled residuals, fallback replay overlap handling after mask expiry (pre-fallback confirm row + zero-delivery echo sentinels + seam ask echo when the attribution step precedes the fallback window; echoed-ask no-room merge otherwise), assumed-delivered-per-clinical-policy resolution of unresolved, mismatched, non-credible, and missing-identity evidence once a fresh settled post-request pump status exists (assumed-requested amount consumed by replay or live-step input), different/new-pod assumed-delivered attribution with replacement-pod live-step insulin-input scrubbing including fallback-replay merge overlap, retained clinical-policy replay disposition for persisted assumed-delivered evidence, future command allowance including automatic resume, meal progress modal resolution when runtime consumes a pending meal attribution without original-pod pump confirmation (with simulated preview progress - reachable only via UI-test launch arguments - exempt from runtime auto-resolution because it has no real delivery to observe), fallback-merge cleanup of matching pending meal-progress state, legacy hold nonblocking meal availability, and meal availability blocking/mapping (TV-PUMP-009, TV-STATE-004, TV-STATE-005).
- testLoopRuntimeEngineResetAlgorithmSessionKeepsClinicalSettings also confirms session reset clears runtime carry-over while preserving unrelated clinical settings; pending meal-request fields are included in that cleared runtime state (TV-MEAL-009 supporting coverage).
- testDoWorkFeedsBackRequestedAndDeliveredWhenBelowDashMinimumQuantum verifies delivery reconciliation preserves requested-vs-delivered values across steps when request is below DASH minimum deliverable quantum (TV-PUMP-003).
- testLoopRuntimeWorkExecutorRecordsLatestReadingBeforeOperation, testLoopRuntimeWorkExecutorSkipsRecordReadingWhenNoLatestReading, and testLoopRuntimeWorkExecutorReturnsOperationResultWithoutMutation verify behavior-preserving extraction for doWork execution snapshot sequencing.
- testPumpBasalScheduleRejectsEntriesMissingMidnightAnchor, testPumpBasalScheduleRejectsNonIncreasingEntries, testPumpBasalScheduleReturnsCurrentRateForOffset, testPumpServiceAdapterMapsOmniBasalScheduleToCoreSchedule, and testPumpServiceAdapterMapsCoreBasalScheduleToOmniSchedule verify the new domain-level programmed basal-schedule seam used by the masked offline-fallback subsystem: schedule validation at the core boundary, rate lookup behavior for a 24-hour repeating schedule, and adapter conversion between core PumpBasalSchedule and OmniBLE basal schedule persistence formats (TV-PUMP-004 supporting fallback coverage).
- testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementDuringActiveTempBasal, testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementDuringActiveBolus, and testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementWhenBasalStateIsUnknown verify that disruptive programmed-schedule replacement is rejected while a temp basal mask or bolus is active and also when basal-delivery state is unknown, so masked fallback arming/disarming cannot silently cancel active delivery or proceed without a confirmed steady-basal boundary (TV-PUMP-004 supporting fallback coverage).
- testPumpServiceAdapterAllowsMaskedFallbackMaintenanceDuringZeroTempBasalMask, testPumpServiceAdapterBlocksMaskedFallbackMaintenanceDuringNonzeroTempBasal, testPumpServiceAdapterBlocksMaskedFallbackMaintenanceWhenBasalStateIsUnknown, testPumpServiceAdapterMapsLateMaskedFallbackBlockedReasonFromPumpManagerCommunicationError, testPumpServiceAdapterMapsPostScheduleMaskBlockedErrorToRemaskFailure, and testPumpServiceAdapterMapsPostSchedulePumpBlockToRemaskFailure verify that the dedicated masked-fallback maintenance/disarm seam allows the expected connected zero-mask steady state while still blocking disruptive schedule replacement during unsafe or unknown pump-delivery conditions, normalizing late bolus-blocked renewal errors into deferred maintenance, and classifying post-schedule mask blocking/failure as recovery-required remask failure rather than a clean first-arm block (TV-PUMP-007, TV-PUMP-008).
- testMaskedFallbackMaintenanceSkipsWithoutActiveAlgorithmSession, testMaskedFallbackMaintenanceArmsFallbackImmediatelyForNewSession, testMaskedFallbackMaintenanceProgramsFourBucketSafetyNominalScheduleWhenAvailable, testPrePumpCommandMaintenanceReceivesStepZeroFallbackCandidateBeforeBolus, testPrePumpCommandMaintenanceBlockReasonSuppressesPumpCommand, testPrePumpCommandFallbackArmCleanBlockAllowsPumpCommand, testPrePumpCommandFallbackArmRemaskFailureBlocksPumpCommandForRecovery, testPrePumpCommandFallbackArmSkipsWhenPumpStatusUnavailable, testPostExecutionFallbackMaintenanceSkipsSameCycleAfterPreCommandAttempt, testPostExecutionFallbackMaintenanceSkipsUnavailablePumpStatus, testPostExecutionFallbackMaintenanceRunsForAvailableStepWithoutPreCommandAttempt, testPreExecutionMaskedFallbackMaintenanceArmsMissingFallbackBeforeNextStep, testPreExecutionMaskedFallbackMaintenanceDefersArmWhenFreshPumpStatusUnavailable, testMaskedFallbackArmBlockedLeavesFallbackUnarmedAndEmitsArmFailure, testMaskedFallbackMaintenanceDoesNotRenewMaskBeforeEnteringTwentyMinuteWindow, testPreExecutionMaskedFallbackMaintenanceRenewsMaskWithinTwentyMinuteWindow, testPreExecutionMaskedFallbackMaintenanceDefersExistingRenewalWhenFreshPumpStatusUnavailable, testPostExecutionMaskedFallbackMaintenanceDoesNotRenewExistingMaskedFallbackWithinWindow, testPreExecutionMaskedFallbackMaintenanceDefersRefreshWhenScheduleWriteIsBlockedAndMaskStillActive, testPreExecutionMaskedFallbackScheduleRefreshRemaskFailureRequiresImmediateReconciliation, and testPreExecutionMaskedFallbackMaintenanceRecordsFailureWhenMaskRenewalIsUnacknowledged verify active-session gating, immediate programming when no fallback is currently armed, four six-hour fallback schedule programming from the secondary/safety q5 nominal profile, same-step arm-before-bolus behavior when step 0 or another current step first produces the fallback candidate, skipped pre-command maintenance when pump status is unavailable/unknown, fresh idle pump-status gating before pre-execution arm/renew/refresh maintenance, clean blocked first-arm behavior that leaves fallback unarmed while allowing the normal step command, same-cycle post-execution retry suppression after a pre-command fallback event, remask-failure behavior that enters reconciliation-required recovery and blocks the normal step command, pre-step arm-before-bolus behavior when a valid candidate already exists, explicit unarmed failure when the first arm is blocked, the 20-minute renewal window, pre-step renewal before the next loop execution, suppression of redundant post-step renewal for an already-masked fallback, deferred schedule refresh when a late blocked maintenance race occurs while the current mask is still active, and recovery-required handling for existing masked-fallback renewal or schedule-refresh remask failures (TV-RUN-008, TV-PUMP-007, TV-STATE-004, TV-LOG-009).
- testLoopRuntimeEngineResetAlgorithmSessionPreservesMaskedFallbackRecoveryContextWhenRestoreFails, testLoopRuntimeEngineArmAlgorithmBlockedWhenMaskedFallbackRestoreIsPending, testLoopRuntimeEnginePumpReconnectRecoveryAfterResetRestoresFallbackButKeepsLoopOff, testLoopRuntimeEngineStartResolvesPendingMaskedFallbackRecoveryByPreservingExistingSession, testLoopRuntimeEnginePumpReconnectRecoveryResumesExistingSessionEvenWhenLatestCGMReceiptIsFresh, and testLoopRuntimeEnginePumpReconnectRecoveryMarksConfirmedFallbackExposureWhenSnapshotMatchesFallbackSchedule verify failed restore recovery is preserved across reset, reconnect recovery honors explicit reset/loop-off intent instead of auto-rearming, delayed restore completion drives the persisted recovery timestamp/exposure window, successful reconnect preserves the existing session/cadence anchor, and confirmed/corrected basal-only recovery creates pending pump-delta reconciliation state plus modeled-vs-pump-reported exposure detail needed for missed-step algorithm replay (TV-PUMP-008, TV-STATE-004, TV-LOG-009).
- testPreExecutionMaskedFallbackMaintenanceDefersRenewalWhenBolusBlocksMaskAndMaskStillActive, testMaskedFallbackMaintenanceEmitsMaskExpiredWithoutRemaskingOnNoStepWake, testLoopRuntimeEngineArmAlgorithmBlockedWhenMaskedFallbackReconciliationIsPending, and testLoopRuntimeEngineTriggerDoWorkPublishesBlockedResultWhenMaskedFallbackReconciliationIsPending verify that blocked renewal is treated as deferred while the current mask is still active, true mask expiry records reconciliation-required recovery state without immediate remasking, a new session cannot arm while that recovery is pending, and ordinary loop doWork is suppressed until recovery resolves (TV-RUN-008, TV-PUMP-007, TV-STATE-004, TV-LOG-009).
- testLoopRuntimeEngineManualBGRunBlockedWhenMaskedFallbackReconciliationIsPending, testMealAnnouncementAvailabilityBlocksMaskedFallbackReconciliationAcrossRelaunch, and testMealAnnouncementPresentationFallbackReconciliationRequired verify that the same offline-expiry recovery state blocks manual BG execution and meal announce while surfacing reconnect/recovery-required guidance through user-facing availability messaging (TV-BG-011, TV-MEAL-006, TV-STATE-004, TV-UI-002).
- testMaskedFallbackDisarmRestoresOriginalScheduleAndEmitsDisarmedEvent and testMaskedFallbackDisarmFailsWithoutActivePumpService verify reset/disarm restore behavior produces explicit success/failure review events instead of silently dropping the underlying programmed basal schedule state (TV-PUMP-008, TV-LOG-009).
- testReconnectRecoveryAssumesModeledFallbackDeliveryForRetiredPodWithoutPumpEvidence, testFallbackReplayPlanDecisionAllowsAssumedDeliveredRetiredPodRecovery, and testLoopRuntimeEnginePumpReconnectRecoveryAssumesFallbackDeliveredWhenRetiredPodCannotRestore verify that an inactive/retired or service-stopped old pod can resolve masked-fallback recovery by recording modeled fallback exposure as assumed_delivered_per_clinical_policy, queueing bounded no-command replay, clearing the recovery state, and preserving the existing algorithm session (TV-PUMP-008, TV-STATE-004, TV-LOG-009).
- Q5NominalBasalProfileTests and LoopRuntimeCoordinatorNominalBasalProfileTests verify q5 nominal-basal profile imputation after the first observation, local-time slot indexing, seven-observation slot history, four six-hour bucket generation, per-bucket observed-slot counts (testObservedSlotCountsByBucketAreAllZeroForEmptyProfile, testFourBucketScheduleCarriesPerBucketObservedSlotCounts, testFullyObservedDayReportsFullPerBucketObservedSlotCounts: empty profile reports all-zero counts, partial observation reports exact per-bucket counts on the generated schedule snapshot, full day reports 72 per bucket), and separate primary versus secondary/safety profile persistence from algorithm telemetry (TV-STATE-004, TV-PUMP-007, TV-LOG-009).
- FallbackBasalExposureReconcilerTests, FallbackBasalReplayPlannerTests, and LoopRuntimeCoordinatorFallbackReplayTests verify the core-owned basal-only reconnect evidence classification, replay-plan/pump-delta math (including scaling to pump-reported delivered insulin), coordinator replay of fallback-active missed primary/secondary algorithm steps in the bounded replay range with CGM=-1, per-step delivered insulin, explicit 0 U inputs for fallback-active missed steps without pump allocation, exclusion of pre-activation disconnected missed slots from replay, single-use cleanup of invalid/not-required/stale pending replay plans, and suppression of catch-up pump commands or duplicate aggregate live-step delivery (TV-PUMP-008, TV-STATE-004). The reconnect recovery suite now additionally verifies that reconnect schedule mismatch upgrades to a corrected reconciled result only when reconnect evidence is credible (fresh connected delivery baseline, delivery measurement that spans the outage, monotonic pod total, and close agreement between modeled and pump-reported delivered insulin), that stale or weak delivery evidence remains unreconciled, that missing pump-reported delivered-insulin delta prevents reconciliation except for the explicit retired/no-active-pod assumed-delivered policy path, that same-pod issued-dose evidence is subtracted from raw pod-total delta before fallback residual replay only when the pending dose is fully covered by the fallback baseline-to-recovery pump-total measurement window, that pre-baseline issued-dose timing remains unreconciled/no-replay, that lower pump-reported residuals after issued-dose subtraction are replayed as corrected fallback evidence while over-modeled residuals remain ambiguous, that historical CGM samples are not required for pump-delta reconciliation, that modeled fallback exposure integrates persisted multi-entry fallback schedules across bucket boundaries, and that reconnect diagnostics always log the persisted fallback schedule, the cached programmed schedule from manager state, the original programmed schedule, and the cached schedule source for later CloudWatch review.
- testDoWorkDoesNotTrustCachedIdlePumpStatusWhenRefreshFails verifies that a stale cached idle pump status cannot allow recommendation or command application when a fresh status refresh fails, reinforcing that runtime pump availability is determined by the current refresh result rather than UI/cache state (TV-PUMP-001, TV-RUN-008 supporting coverage).
- testLoopSessionStorePersistsAlgorithmArmedAndRuntimeState and testLoopSessionStoreClearRuntimeStateReturnsEmptyState verify session persistence boundaries.
- testLoopWorkSchedulerOnlyTriggersForNewTimestampWhileArmed verifies CGM timestamp dedupe/arm/reset behavior.
- testLoopAlertMediatorReportsSignalLossUntilKnownRefresh and testLoopAlertMediatorKeepsSignalLossForUnknownRefresh verify signal-loss policy mediation behavior.
- testRecordDoWorkResultStoresSecondaryAlgorithmTelemetry, testUserDefaultsLoopRuntimeStateStorePersistsLatestFallbackBasalEvent, testResetSessionClearsTelemetry, testCloudTelemetryReporterSendsStructuredFallbackEventPayload, testLoopTelemetryStoreEmitsFallbackCloudTelemetryForNewAndChangedEventsOnly, testRecentDoseTimelineIncludesPersistedFallbackEventsAheadOfOlderSteps, testRecentDoseTimelineFallbackMetadataIncludesSourceTargetDurationAndStatus, testRecentDoseTimelineFallbackScheduleUpdateTextIncludesRateMaskAndNextRefresh, testRecentDoseTimelineFallbackUnchangedScheduleTextIncludesRetainedRateMaskAndNextRefresh, testRecentDoseTimelineFallbackReconnectRecoveryTextIncludesExposureAndUnreconciledResume, testRecentDoseTimelineFallbackReconnectRecoveryTextKeepsLoopOffAfterExplicitReset, testRecentDoseTimelineFallbackReconnectRecoveryTextIncludesReplayDetails, testRecentDoseTimelineStepSummariesIncludePrimaryAndSecondaryAlgorithmDetails, testRecentDoseTimelineFallbackFailureTextIncludesKindAndReason, testRecentDoseTimelineFallbackRestoreTitlesCoverDisarmLifecycle, testUnchangedScheduleCheckEventCarriesScheduleAndProfileCoverageWithoutBulkRates, testArmedEventCarriesPerBucketObservedSlotCounts, testScheduleRefreshEventCarriesFullProfilePayloadWithPerBucketCounts, testRecentDoseTimelineFallbackScheduleRowsShowOutcomeLabels, testRecentDoseTimelineFallbackUnchangedRowShowsScheduleSegmentsCoverageAndProvenance, and testRecentDoseTimelineFallbackProvenanceMarksAllImputedAndSingleObservedBuckets verify that fallback-basal review events can be persisted through runtime/user-default state, mirrored into the shared telemetry store/cloud emitter, cleared on session reset, and rendered in Home Recent Dose Steps with source, target, duration, schedule-refresh update/unchanged detail, maintenance-deferred status, restore/remask failure detail, modeled-vs-pump-reported recovery detail, pump-delta reconciliation detail when confirmed/corrected recovery occurs, disarm lifecycle wording, per-step primary/secondary algorithm summaries, and fallback profile/schedule cloud payload fields for the masked offline-fallback subsystem, including the steady-cadence schedule_checked_unchanged payload (programmed schedule + coverage + per-bucket observed-slot counts, no bulk 288-rate array), per-bucket counts on arm/refresh events (profile_observed_slot_counts_by_bucket, pinned in testCloudTelemetryReporterSendsStructuredFallbackEventPayload and testArmedEventCarriesPerBucketObservedSlotCounts), and schedule-row outcome labels plus per-segment observed/imputed provenance with the below-50%-observed imputed marking (TV-LOG-009).
- testCSVExportIncludesAlgorithmInputOutputHeadersAndRowValues verifies the local step CSV export keeps stable schema and persisted algorithm input/output snapshots; masked-fallback reconnect recovery is now covered by coordinator, CSV, and runtime cloud emission tests that assert fallback-active missed-step algorithm replay rows are emitted from credible pump delta with CGM=-1, per-step delivered-insulin input, replay evidence source/disposition/failure-reason columns, including explicit 0 U algorithm inputs when no pump allocation belongs to a replayed fallback-active step and no synthetic replay rows for pre-activation disconnected gaps (TV-LOG-002, TV-LOG-009 subsets).
Current implemented clock-sync telemetry safety coverage:
- testDeviceClockSyncMonitorFlagsSkewAndPublishesWarningAtThresholdBreach verifies midpoint skew calculation and warning emission when absolute skew exceeds 600 seconds (TV-UI-008, TV-LOG-006 subset).
- testDeviceClockSyncMonitorWithinThresholdReportsOKWithoutWarning verifies <=600s skew reports ok and does not emit warning alerts (TV-UI-008 subset).
- testDeviceClockSyncMonitorForegroundCheckUses24HourSuccessfulCheckGate verifies foreground checks are gated by 24-hour successful-check interval (TV-LOG-006 subset).
- testDeviceClockSyncMonitorTimezoneChangeForcesFreshCheckInsideForegroundGate verifies timezone/time-change trigger bypasses the foreground gate and performs a fresh UTC check (TV-LOG-006, TV-UI-008 subset).
- testDeviceClockSyncMonitorRetriesAndReturnsUnavailableWithoutWarningOnNetworkFailures and testDeviceClockSyncMonitorLimitsSkewWarningsToOncePer24Hours verify retry/unavailable behavior and warning cooldown control (TV-UI-008 subset).
Current implemented CGM UI stale-display safety coverage:
- testG7ViewModelMasksStaleReadingAndHidesTrendWhenTimestampOlderThanElevenMinutes verifies stale CGM masking to -- and hidden trend arrow when reading age exceeds 11 minutes (TV-UI-007).
- testG7ViewModelMasksUnreliableCurrentReadingAndDoesNotFallbackToHistoryValue verifies unreliable current CGM readings are masked to --, trend is hidden, and UI does not fallback-display historical value while current state is unreliable (TV-UI-007).
- testG7ViewModelMasksUnreliableCurrentReadingWithoutTimestampAndDoesNotFallback verifies unreliable current reading masking remains enforced when latestReadingTimestamp is missing (restore/partial-state edge), preventing fallback numeric display (TV-UI-007).
- testG7ViewModelMasksStalePersistedHistoryWhenNoLiveReadingExists verifies stale persisted-history fallback is also masked to -- (TV-UI-007).
- testG7ViewModelUsesFreshPersistedHistoryWhenLatestReadingIsUnavailable verifies non-stale persisted-history fallback still displays glucose value (control case for TV-UI-007 boundary behavior).
- testG7ViewModelDisplayFormattingMapsExtremeValuesToHighLow verifies boundary formatting (<=39 -> LOW, >=401 -> HIGH) and unit-label suppression semantics for boundary text (TV-UI-009).
- testInlineCGMChartDerivationDynamicYAxisMaximumAndValues verifies stepped CGM y-axis scaling behavior (300/350/400) and corresponding tick derivation (TV-UI-010).
- testInlineCGMChartUsesPointOnlyPresentation verifies the CGM chart's connector stroke and connected area fill remain disabled while the dot layer remains the trace presentation (TV-UI-010).
Current implemented Algo2015 verification coverage:
- Algo2015BridgeContractTests methods cover initial bridge contract behavior for null-guard paths, state-reset edge handling (stateData == nil && timeStep > 0), subject-id nil/long boundary handling, and state handoff continuity (TV-ALG-001, TV-ALG-002, TV-ALG-003 baseline subset).
- Algo2015GoldenVectorTests.testNominalCGMSequenceMatchesGoldenOutputs locks a deterministic nominal replay vector for drift detection (TV-ALG-004 baseline subset).
- Algo2015GoldenVectorTests.testUnavailableCGMSequenceProducesFiniteDeterministicOutputs adds degraded/unavailable-CGM replay coverage (TV-ALG-005 baseline subset).
- Algo2015GoldenVectorTests.testMealAndManualBGInputsProduceDeterministicMealPathSignals adds meal/manual-BG intervention replay coverage (TV-ALG-006 baseline subset).
- Algo2015GoldenVectorTests.testPersistedStateReloadMatchesContinuousExecution and Algo2015GoldenVectorTests.testResetToFreshStateProducesDeterministicStepZeroOutput add persistence/reload/reset continuity verification (TV-ALG-007).
- Algo2015GoldenVectorTests.testCGMBoundaryValuesRemainFiniteAndBounded adds CGM boundary/sentinel replay coverage (TV-ALG-008 baseline subset).
- Algo2015GoldenVectorTests.testHigherTargetProducesLessInsulinForSameHyperglycemicSequence adds differential target-behavior verification (TV-ALG-009 baseline subset).
- Algo2015OracleSupport now provides a reusable oracle framework for deterministic replay, snapshot assertions, and continuity checks across Algo2015 test suites (TV-ALG-004, TV-ALG-005, TV-ALG-006, TV-ALG-007, TV-ALG-008).
- Algo2015MetamorphicTests adds property/metamorphic checks for deterministic replay identity and monotonic sensitivity to target/CGM transforms (TV-ALG-004, TV-ALG-009 supporting evidence).
- Algo2015DifferentialReplayTests adds staged differential replay with JSON report output (differential-report.json) and now asserts all pregnancy parameters are consumed (targetMgDL, mealUpfrontPercent, tmaxMinutes) with deterministic checks for target monotonicity, applied meal-upfront profile, and TMAX-driven output variation (TV-ALG-009).
- Algo2015DifferentialReplayTests.testPregnancyDifferentialReplayProducesDeterministicReport now additionally asserts that 90% upfront meal profile front-loads more meal insulin than 75% at meal step and in immediate post-meal cumulative window (TV-ALG-009).
- The exact-freeze STR-ALG-001 bundle executed coverage, input-field,
core-requirement, differential, boundary-transfer, and static-analysis lanes.
- Frozen structural results are Algo2015 96.12% line / 87.77% branch and
bridge 90.27% line / 65.85% branch. The controlled exception package
records the threshold shortfalls and their required dispositions.
- The controlled bundle also contains immutable run context, checksums,
assertion-to-SRS/TV mapping, analyzer output, branch-gap mapping, and a
reproducibility recipe. Appendix A07 is the authoritative evidence locator.
6. Evidence¶
Expected evidence package per change:
- test command output (
xcodebuild,swift test) - failing/passing test IDs
- device test logs where applicable
- screenshots for UI safety behavior
- link to changed requirement and risk IDs
7. Deferred or Unclaimed Validation¶
The current package does not retain separate formal claims for Scout round trips, physical ZIP inspection, hardware fault-injection, or summative human-factors validation. Supporting observations may corroborate automated evidence but do not become formal evidence unless promoted through the controlled evidence process. A later retained claim requires a controlled protocol, acceptance criteria, execution record, and disposition.
Current automated coverage for CGM interruption behavior:
- BionicLoopStepInterruptionAlertCenterTests.testAlgorithmSteppingInterruptionMonitoringSchedulesFutureNotificationAndRaisesAlertAtDeadline
- BionicLoopStepInterruptionAlertCenterTests.testAlgorithmSteppingInterruptionMonitoringClearsActiveAlertWhenSteppingResumes
- BionicLoopRuntimeEngineSessionInfrastructureTests.testLoopRuntimeEngineArmedSessionSchedulesStepInterruptionMonitoringAndResetClearsIt
- BionicLoopRuntimeEngineStepInterruptionInfrastructureTests.testLoopRuntimeEngineForegroundRefreshShowsStepInterruptionWhenThresholdExceededBeforeFirstStep
- BionicLoopRuntimeEngineStepInterruptionInfrastructureTests.testLoopRuntimeEngineForegroundRefreshUsesLastSuccessfulRunDeadlineWhenAvailable
- BionicLoopRuntimeEngineStepInterruptionInfrastructureTests.testLoopRuntimeEngineForegroundRefreshDoesNotShowStepInterruptionWhenDisarmed
8. Xcode Automated UI Testing Strategy¶
Purpose:
- Use XCTest UI automation as repeatable verification evidence for deterministic UI behavior and requirement conformance.
Highest-value coverage areas: - Navigation and modal routing correctness. - Presence/enabled-state of safety-critical controls. - State-to-message rendering for known inputs. - Regression checks for setup flows and dismiss paths. - Non-hardware-dependent interaction logic (for example meal sheet presentation/cancel behavior).
Not a primary tool for: - BLE transport reliability and reconnect behavior. - Background wake cadence and overnight timing reliability. - Real pump delivery confirmation and physical device alert timing.
Execution model: - Run UI tests on Simulator with deterministic launch fixtures. - Use app launch arguments/environment to force reproducible runtime states. - Use stable accessibility identifiers for controls, labels, and state badges. - Keep one fast smoke suite as release gate; keep extended suite for nightly runs.
9. UI Automation Verification Mapping¶
- Automated UI evidence is acceptable for
SRS-UI-*and portions ofSRS-MEAL-*andSRS-ALERT-*where behavior is deterministic and fixture-driven. - Hardware-coupled behavior is represented by supporting real-device observations unless a separate formal hardware claim is explicitly retained and approved.
- Preferred command:
xcodebuild -project BionicLoop.xcodeproj -scheme BionicLoop -destination 'platform=iOS Simulator,name=iPhone 17' -only-testing:<UI-test-target> -parallel-testing-enabled NO test- Evidence artifacts:
- test logs, pass/fail results, captured screenshots/attachments, and linked
TV-*IDs inRTM.
Current Automated UI Suite Mapping¶
| XCTest Method | TV-ID Link | Requirement Link | Notes |
|---|---|---|---|
testUI001_HomeShowsPrimaryControls |
TV-UI-005 | SRS-UI-002 | Smoke check for Home control availability using deterministic fixtures. |
testUI001b_HomePrimaryActionsRemainVisibleWhileContentScrolls |
TV-UI-005 | SRS-UI-002 | Expands a multi-alert Home stack, scrolls the reserved content region, and verifies Manual BG and Meal Announcement remain hittable at fixed screen coordinates. |
testUI002_MealUnavailableWhenLoopOff |
TV-UI-002 | SRS-UI-002 | Verifies unavailable-state messaging path and dismissal UX. |
testUI003_SettingsSheetCanDismiss |
TV-UI-006 | SRS-UI-002 | Guards against modal navigation traps in settings entry path. |
testUI004_ManualBGSheetCanOpenAndCancel |
TV-UI-006 | SRS-BG-001 | Verifies explicit cancel path for manual BG entry UX. |
testUI004b_ManualBGReviewRequiresExplicitAlertConfirmation |
TV-BG-008 | SRS-BG-001 | Verifies native exact-value review, value-preserving Change, and explicit confirmed submission. |
testUI004c_ManualBGRapidDoubleTapCannotSubmitWithoutAlertConfirmation |
TV-BG-008 | SRS-BG-001 | Verifies repeated taps at the entry action cannot bypass the spatially separate confirmation. |
testUI005_HomeShowsAlertBannerPreview |
TV-ALERT-002 | SRS-ALERT-003 | Verifies deterministic top-alert preview rendering on Home. |
testUI006_HomeShowsCriticalAlertPreview |
TV-ALERT-002 | SRS-ALERT-003 | Verifies critical alert preview path and title rendering. |
testUI007_HomeAlertCenterButtonOpensAlertCenter |
TV-ALERT-007 | SRS-ALERT-008 | Verifies Home alert-center bell entry and active-alert visibility in Alert Center. |
testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared |
TV-ALERT-007 | SRS-ALERT-005, SRS-ALERT-008 | Verifies acknowledge transition from active alert state to recently-cleared timeline. |
testUI009_AlertCenterPersistsAcrossRelaunch |
TV-ALERT-008 | SRS-ALERT-009 | Verifies persisted active alert visibility after relaunch (UI_TEST_PRESERVE_DEFAULTS). |
testUI021_SignedOutActiveTherapyKeepsLoginProminentAcrossHomeAndAlertCenter |
TV-SEC-008 | SRS-SEC-009 | Verifies persistent Home login access during signed-out active therapy and the actionable Alert Center route back to authentication. |
testUI022_SignedOutAccountAndSessionOffersLogin |
TV-SEC-008 | SRS-SEC-009 | Verifies signed-out Account & Session presents Log In rather than a misleading Log Out action and returns to authentication. |
testUI010_ClinicalSettingsNavigatesAndKeepsUnlockUntilManualLock |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies clinical unlock success, local unlock persistence across Clinical Settings navigation within the unlock duration, and manual lock. |
testUI011_ClinicalSettingsSaveDismissesSettingsSheet |
TV-CLIN-009 | SRS-CLIN-007, SRS-CLIN-008 | Verifies Save+OK closes settings flow after review-confirmation path. |
testUI012_ClinicalSettingsInvalidCodeBlocksUnlock |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies invalid unlock-code path shows explicit error and keeps clinician controls hidden. |
testUI013c_ClinicalUnlockAcceptsGroupedDigitsAndRejectsRepeatedCode |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies grouped/pasted-style numeric input is normalized and that a locally burned counter cannot be reused on the same device. |
testUI013d_ClinicalUnlockUsesOfflineProvisionedVerifierMaterial |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies Clinical Settings unlock is satisfied by locally provisioned verifier material and does not depend on an online verification call. |
testUI013_ClinicalControlsVisibleOnlyInsideUnlockedClinicalSettings |
TV-CLIN-002 | SRS-CLIN-003 | Verifies relocated Start/Reset controls are absent in general settings and present only in unlocked Clinical Settings. |
testUI014_RegularTargetChangeRequiresApprovalCaptureAndPersists |
TV-CLIN-011, TV-CLIN-013 | SRS-CLIN-011, SRS-CLIN-007 | Verifies regular-settings target changes block until approval fields are completed, then persist into clinician-visible applied target state. |
testUI015_ClinicalTargetPickerFollowsSelectedProfileRange |
TV-CLIN-010 | SRS-CLIN-009, SRS-CLIN-010 | Verifies the clinician target picker only exposes the targets enabled by the selected Pregnancy/Standard profile. |
testUI016_ClinicalProfileChangeNormalizesTargetAndPersists |
TV-CLIN-012, TV-CLIN-013 | SRS-CLIN-012, SRS-CLIN-009, SRS-CLIN-010 | Verifies changing the clinician-selected profile snaps an inherited out-of-range draft target to the nearest allowed value and persists the normalized result. |
Evidence reference: - The controlled UI automation evidence is indexed in Appendix A07.
Current Clinical Unit Mapping¶
| XCTest Method | TV-ID Link | Requirement Link | Notes |
|---|---|---|---|
ClinicalUnlockVerifierTests |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies the backend contract HMAC vectors, ASCII/grouped-code normalization, non-ASCII digit rejection, wrong-subject rejection, same/lower counter rejection, lookahead rejection, and unsupported-version rejection. |
BionicLoopClinicalUnlockRuntimeTests |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies app-side secure-state semantics: verifier material installation, subject/material mismatch rejection, material refresh preserving accepted counter while clearing active unlock/lockout state, accepted counter persisted before success returns, repeated code rejected after burn, missing verifier material blocks unlock, failed attempts lock out temporarily, unlock expiration enforced locally, and manual-lock storage failure surfaced without falsely closing clinician controls. |
testClinicalSettingsPolicyNormalizationAndDefaults |
TV-CLIN-003, TV-CLIN-004, TV-CLIN-005 | SRS-CLIN-004, SRS-CLIN-005, SRS-CLIN-006 | Verifies allowed-option enforcement and deterministic fallback defaults for target/upfront/TMAX selectors. |
testClinicalSettingsSavePolicyAllowsInitialUnsetConfigWithoutUnlock, testClinicalSettingsSavePolicyPrepareSaveReviewBlockedStates |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002, SRS-CLIN-013 | Verifies initial unset configuration can reach review without an unlock, while locked subsequent edits and invalid/no-change saves remain blocked with deterministic reasons/messages. |
testClinicalSettingsSavePolicyPrepareSaveReviewBuildsChangedFieldList |
TV-CLIN-009 | SRS-CLIN-007 | Verifies review model includes complete changed-field set for old/new clinical config diff. |
testClinicalSettingsSavePolicySaveApplySemantics |
TV-CLIN-009 | SRS-CLIN-007, SRS-CLIN-008, SRS-LOG-001 | Verifies no persisted change before save confirmation, cancel preserves applied config, and saved config appears in next-step telemetry snapshot fields. |
testClinicalSettingsSavePolicyUICriticalEvents |
TV-LOG-005 | SRS-LOG-005 | Verifies deterministic ui.critical event mapping and detail payload for state_viewed/submit/cancel/blocked paths. |
testClinicalSettingsPolicyTargetRangeProfiles |
TV-CLIN-010, TV-CLIN-012 | SRS-CLIN-009, SRS-CLIN-010, SRS-CLIN-012 | Verifies Pregnancy/Standard profile subsets and nearest-allowed normalization behavior when the active profile changes. |
testRegularTargetChangeApprovalPolicyPrepareAndValidate |
TV-CLIN-011 | SRS-CLIN-011 | Verifies participant target changes require approver name and approval timestamp before apply. |
testRegularTargetChangeApprovalPolicyBlocksNoChangeAndOutOfProfileSelection |
TV-CLIN-010, TV-CLIN-011 | SRS-CLIN-010, SRS-CLIN-011 | Verifies participant target-change flow rejects no-op requests and targets outside the clinician-selected profile. |
testRegularTargetChangeApprovalTelemetryEvents |
TV-LOG-008 | SRS-LOG-008 | Verifies participant approval-capture telemetry includes target profile, requested/current target, approver name, and approval timestamp. |
Current regression command used in development for this slice:
- xcodebuild -project BionicLoop.xcodeproj -scheme BionicLoop -destination 'platform=iOS Simulator,name=iPhone 17' -only-testing:BionicLoopTests -parallel-testing-enabled NO test
UI execution note for this slice:
- The BionicLoop UI-test target is wired into the current scheme and targeted UI cases can be launched with xcodebuild ... -only-testing:<UI-test-target>/<UI-test-case> test.
- Focused UI verification for testUI014_RegularTargetChangeRequiresApprovalCaptureAndPersists, testUI015_ClinicalTargetPickerFollowsSelectedProfileRange, and testUI016_ClinicalProfileChangeNormalizesTargetAndPersists passed on 2026-03-25; the controlled result is indexed in Appendix A07.
- Local simulator/xctrunner instability may still require rerunning the focused UI lane in future environments, but this slice now has a captured green UI pass.
10. Manual Screenshot UI Review Protocol¶
Scope: - Required for all user-facing changes, especially safety-state messaging, alert presentation, and clinical controls.
Capture set: - Light mode and dark mode screenshots. - Changed screen in: baseline state, interactive state, blocked/error state, and post-action state. - If applicable, include one large-text (Dynamic Type) capture for key screens.
Review rubric: - Typography and text integrity: - no clipping, truncation, overlap, or ambiguous wording. - units/values formatting is consistent (mg/dL, U, %, min, timestamps). - Spacing and alignment: - consistent spacing rhythm and card/control alignment. - safe-area compliance; no accidental edge clipping. - Visual hierarchy: - critical safety states and primary actions are immediately distinguishable. - secondary text does not compete with critical signals. - Accessibility and contrast: - sufficient contrast in both themes. - color is supplemented by text/icon/position cues. - tappable controls remain legible and touch-accessible. - Motion and transitions: - state transitions are smooth and non-jarring. - no stale labels/icons during animated or async state changes.
Evidence and traceability:
- Save screenshots and review notes under the applicable STR-* evidence path.
- Link accepted evidence through the controlled RTM, formal evidence index, and
applicable anomaly or deviation record.