Software Verification and Validation Plan (SVVP)
Status: Final draft prepared for handoff (pending review)
Version: 1.23
Owner: BionicLoop engineering
Prepared by: BionicLoop engineering
Reviewer: ____
Approver: ____
Decision date: ____
Effective date: ____
Baseline freeze SHA: ____
Last updated: 2026-06-23
Revision History
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 0.1 | 2026-04-05 | Engineering | Initial controlled verification draft |
| 0.9 | 2026-04-06 | BionicLoop engineering | Added handoff-ready metadata, software-handoff disposition language, and clarified the in-scope local security verification row |
| 0.91 | 2026-04-08 | BionicLoop engineering | Added fallback-event persistence and Recent Dose Steps review-state coverage notes for ongoing offline-fallback feasibility scaffolding |
| 0.92 | 2026-04-08 | BionicLoop engineering | Added pump basal-schedule seam coverage for masked offline-fallback feasibility scaffolding |
| 0.93 | 2026-04-08 | BionicLoop engineering | Added blocking coverage for disruptive programmed basal-schedule replacement during active bolus and active temp-basal states |
| 0.94 | 2026-04-08 | BionicLoop engineering | Added masked-fallback maintenance/disarm verification rows, active-session gating coverage, and restore-event review coverage |
| 0.95 | 2026-04-08 | BionicLoop engineering | Clarified 20-minute renewal-window verification, deferred-maintenance coverage, and pre-step masked-fallback renewal expectations |
| 0.96 | 2026-04-14 | BionicLoop engineering | Added verification rows and evidence notes for reconciliation-required blocked state after offline mask expiry |
| 0.97 | 2026-04-14 | BionicLoop engineering | Added reconnect restore/disarm retry and explicit fresh re-arm verification notes for masked-fallback recovery |
| 0.98 | 2026-04-14 | BionicLoop engineering | Updated masked-fallback reconnect-recovery verification notes for fresh-session auto-arm and preserved fallback review history |
| 0.99 | 2026-04-14 | BionicLoop engineering | Updated masked-fallback reconnect-recovery verification notes for same-session unreconciled resume on the current due slot after successful restore |
| 1.00 | 2026-04-15 | BionicLoop engineering | Added basal-only reconnect evidence, modeled-vs-pump-reported fallback review, and pre-step missing-fallback arm verification notes for the active feasibility branch |
| 1.01 | 2026-04-15 | BionicLoop engineering | Added confirmed/corrected basal-only reconnect replay verification notes, coordinator replay tests, and replay-specific Home timeline review coverage |
| 1.02 | 2026-04-15 | BionicLoop engineering | Added dedicated cloud fallback telemetry verification for structured loop.fallback.event emission, duplicate suppression, and backend-facing payload mapping |
| 1.03 | 2026-04-15 | BionicLoop engineering | Added verification coverage for replayed-step propagation into local per-step telemetry / CSV export with explicit replay markers |
| 1.04 | 2026-04-27 | BionicLoop engineering | Added verification coverage that missing pump-reported delivered-insulin delta prevents fallback replay and keeps modeled expected delivery logging-only |
| 1.05 | 2026-05-06 | BionicLoop engineering | Added q5 nominal-basal profile, safety-track four-bucket fallback schedule, schedule-aware exposure, and fallback profile/schedule telemetry verification coverage |
| 1.06 | 2026-06-02 | BionicLoop engineering | Updated masked-fallback verification to pump-delta missed-step algorithm replay and added repeated no-active-pod alert coverage |
| 1.07 | 2026-06-08 | BionicLoop engineering | Added verification coverage for persisted-schedule-weighted pump-delta replay allocation, zero-weight suppression, and zero-delta replay rows |
| 1.08 | 2026-06-12 | BionicLoop engineering | Added verification coverage for generalized issued-dose attribution, replay, unresolved block, and different/new-pod no-replay disposition |
| 1.09 | 2026-06-13 | BionicLoop engineering | Added verification coverage for issued-dose delivered-unit credibility, replacement-pod live-step input scrubbing, and automatic resume blocking under active holds |
| 1.10 | 2026-06-15 | BionicLoop engineering | Updated different/new-pod issued-dose verification to assumed-delivered replay/live attribution, nonblocking replacement-pod dosing, legacy hold clearance, and meal progress modal resolution |
| 1.11 | 2026-06-17 | BionicLoop engineering | Added verification coverage for user-confirmed pod replacement from unresolved meal delivery progress with assumed-delivered evidence and non-meal suppression |
| 1.12 | 2026-06-18 | BionicLoop engineering | Added verification coverage for retired/expired/no-active-pod fallback recovery using assumed modeled fallback exposure when pump-counter evidence is no longer recoverable. |
| 1.13 | 2026-06-23 | BionicLoop engineering | Added provisional pod-simulation scenario coverage for issued-dose live attribution, lost final meal response before refresh, replacement-pod assumed-delivered replay, stale cached idle rejection, meal/fallback partitioning, stale fallback evidence suppression, and schedule-weighted fallback replay allocation. |
| 1.14 | 2026-06-23 | BionicLoop engineering | Expanded pod-simulation coverage for canceled and consecutive-canceled meal evidence feeding subsequent meal announcements, user-escaped unavailable-pod assumed evidence, fallback-maintenance command blocking before live bolus delivery, and relaunch fallback replay with unavailable CGM. |
| 1.15 | 2026-06-23 | BionicLoop engineering | Added explicit pod-simulation coverage for unresolved correction-only and basal-only issued doses without recoverable pod identity. |
| 1.16 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for ambiguous fallback restore without replay or modeled-dose injection. |
| 1.17 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption. |
| 1.18 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state. |
| 1.19 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure. |
| 1.20 | 2026-06-23 | BionicLoop engineering | Added pod-simulation coordinator coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row. |
| 1.21 | 2026-06-23 | BionicLoop engineering | Added app-layer recent-dose persistence/display verification for merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units. |
| 1.22 | 2026-06-23 | BionicLoop engineering | Added local step CSV export verification for merged replay evidence source, disposition, and failure-reason fields. |
| 1.23 | 2026-06-23 | BionicLoop engineering | Added runtime cloud step-event emission verification for merged replay evidence source, disposition, request-step, requested-unit, and delivered-unit fields. |
1. Test Document Acronyms
Common structure used here:
SVVP: Software Verification and Validation PlanSTP: Software Test Protocol (test procedures and expected results)STR: Software Test Report (actual execution evidence)
2. Verification Strategy
Verification is split into:
- Unit tests (core logic, algorithm mapping, policy gates)
- Integration tests (runtime + adapters + persistence)
- System/manual tests (real-device behavior, BLE reconnection, onboarding flows)
Initial STP draft set:
- STP-ALG-001
- STP-AUTO-001
- STP-SIM-001
- STP-HW-001
- STP-ALERT-001
- STP-TV-Ownership-Map
- STR-Execution-and-Reporting-Guide
Submission-scope note:
- Device-to-cloud / BionicScout verification is not included in the current submission-scope STP draft set and should be treated as deferred/out-of-scope unless submission scope is explicitly revised.
- For the current engineering software handoff package,
TV-SEC-001remains the only in-scope security verification row;TV-SEC-002..008are deferred from claimed closure in this pass.
3. Test Environments
- iOS Simulator for deterministic unit/integration tests.
- Physical iPhone + Dexcom G7 + OmniPod DASH for connection/cadence and delivery behavior.
4. Entry and Exit Criteria
Entry:
- SRS and SDD IDs updated for proposed change.
- Risk impacts reviewed for affected paths.
Exit:
- All planned
TV-*tests pass or deviations documented. - Traceability matrix updated with evidence links (
STR-*artifacts, logs, screenshots). - No unresolved
Highseverity regressions.
5. Seed Test Inventory
| Test ID | Level | Purpose | SRS Link |
|---|---|---|---|
| TV-RUN-001 | Unit | Expected step math anchored to first successful run, including one-step algorithm/runtime cadence reconciliation without schedule re-anchor | SRS-RUN-001, SRS-RUN-002 |
| TV-RUN-002 | Integration | Duplicate step prevention (stepNotDue) and live executed-step/request-step alignment with algorithm input stepTime after cadence reconciliation |
SRS-RUN-002 |
| TV-RUN-003 | Unit/Integration | Runtime doWork dispatch is constrained to allowed wake causes (cgmUpdate, bgCheck, mealAnnounce, guarded pumpReconnect) |
SRS-RUN-003 |
| TV-RUN-004 | Unit/Integration | Reconnect fallback executes only after an anchored session exists and only when accepted CGM receipt age exceeds the approved fallback freshness limit | SRS-RUN-004, SRS-CGM-005 |
| TV-RUN-005 | Unit/Integration | Reconnect fallback does not execute step 0, does not re-anchor cadence, and does not replay multiple missed slots |
SRS-RUN-001, SRS-RUN-002, SRS-RUN-005 |
| TV-RUN-006 | Unit/Integration | Fresh accepted CGM receipt suppresses reconnect fallback and same-slot CGM/reconnect triggers coalesce to one execution | SRS-RUN-002, SRS-RUN-004, SRS-RUN-005 |
| TV-RUN-007 | System/Hardware | Real-device reconnect fallback validates current-due-step execution after CGM interruption without duplicate command application | SRS-RUN-004, SRS-RUN-005, SRS-CGM-005 |
| TV-RUN-008 | Unit/Integration | Masked fallback does not arm or refresh without an active algorithm session, arms after the current step first computes a valid fallback candidate but before applying that same step's pump command when refreshed pump status is known/available, skips that pre-command maintenance hook when pump status is unavailable/unknown, arms before the next loop execution when a valid candidate was already persisted and no fallback is currently programmed, derives the programmed fallback schedule from the secondary/safety q5 nominal-basal profile when available, renews an existing mask only inside the 20-minute renewal window, suppresses same-cycle post-execution retry after a pre-command fallback event, and suppresses ordinary loop execution after offline mask expiry until reconciliation-required recovery is resolved | SRS-RUN-006, SRS-PUMP-006, SRS-PUMP-008 |
| TV-ALG-001 | Unit (Bridge) | Bridge null-pointer guards and edge-state reset behavior | SRS-ALG-003 |
| TV-ALG-002 | Unit (Bridge) | Input mapping and sentinel behavior (requestTime, pump availability, subject-id boundaries) |
SRS-ALG-003 |
| TV-ALG-003 | Unit (Bridge) | Output/state handoff and step increment continuity at bridge boundary | SRS-ALG-003, SRS-ALG-004 |
| TV-ALG-004 | Unit (Algorithm) | Deterministic nominal golden-vector replay | SRS-ALG-001 |
| TV-ALG-005 | Unit (Algorithm) | Degraded/unavailable-input golden-vector replay | SRS-ALG-001, SRS-ALG-003 |
| TV-ALG-006 | Unit (Algorithm) | Meal/BG/intervention golden-vector replay | SRS-ALG-001, SRS-ALG-005 |
| TV-ALG-007 | Unit/Integration | Stateful continuity across persistence/reload/reset boundaries | SRS-ALG-004 |
| TV-ALG-008 | Unit (Algorithm) | Boundary/sentinel cases (CGM, BG, pump) remain deterministic and safe | SRS-ALG-003, SRS-ALG-004 |
| TV-ALG-009 | Differential | Pregnancy config differential replay (target, upfront, TMAX) vs baseline |
SRS-ALG-005 |
| TV-ALG-010 | Coverage | Structural coverage report generation and threshold compliance for Algo2015 + bridge | SRS-ALG-002 |
| TV-ALG-011 | Toolchain/Process | Static-analysis quality lane execution, and MISRA policy evidence closure as either linked report+deviations or explicit not-applicable decision rationale | SRS-ALG-006, SRS-ALG-007 |
| TV-CGM-001 | Unit | Out-of-range CGM -> unavailable (-1) mapping |
SRS-CGM-001 |
| TV-CGM-002 | Unit | Step-0 fresh/in-range gating | SRS-CGM-002 |
| TV-CGM-003 | Unit | Step>0 degraded run with unavailable CGM | SRS-CGM-003 |
| TV-CGM-004 | Unit/UI | Step-0 blocked-for-CGM path exposes explicit reason/state messaging to user surfaces | SRS-CGM-004, SRS-UI-002 |
| TV-CGM-005 | Integration/System | Armed-loop absence of successful step execution beyond the approved interruption threshold is detected as a stalled-step condition using last-success/session-start timing | SRS-CGM-005 |
| TV-BG-001 | Unit/Integration | bgCheck creates/uses a single pending BG candidate without borrowing future slots beyond immediate next-step policy |
SRS-BG-002 |
| TV-BG-002 | Unit/Integration | Submit after due-step execution rolls BG candidate to immediate next step and uses it there | SRS-BG-003 |
| TV-BG-003 | Unit/Integration | BG value maps to algorithm BGval while CGM mapping remains independent |
SRS-BG-004 |
| TV-BG-004 | Unit/Integration | Pump unavailable during bgCheck blocks command application without overriding degraded policy |
SRS-BG-005, SRS-PUMP-001 |
| TV-BG-005 | Unit/UI | Stale manual BG is rejected with explicit user-visible reason | SRS-BG-006 |
| TV-BG-006 | Unit/Integration | Telemetry records manualBG source, value, timestamps, and execution outcome |
SRS-BG-007, SRS-LOG-001 |
| TV-BG-007 | Unit/Integration | Deferred from current software handoff baseline. If step-0 BG rescue is enabled in a future accepted baseline, verify it executes only when policy gates pass. | SRS-BG-008 |
| TV-BG-008 | Unit/UI | Manual BG entry rejects values outside 20...600 mg/dL with explicit validation messaging and shows that manual BG is used for algorithm dosing decisions and does not calibrate CGM |
SRS-BG-001 |
| TV-BG-009 | Unit/Integration | Pending BG candidate expires if not consumed on the immediate next target step | SRS-BG-009 |
| TV-BG-010 | Unit/Integration | New BG submission replaces existing pending candidate before execution | SRS-BG-010 |
| TV-BG-011 | Unit/Integration | Manual BG submit while loop is disarmed or masked-fallback reconciliation is pending does not dispatch runtime execution (bgCheck) or create pending BG state |
SRS-BG-011 |
| TV-BG-012 | Unit/Integration | Manual BG submit before first successful anchored step is rejected and does not create pending BG state | SRS-BG-012 |
| TV-CLIN-001 | Unit/UI/Integration | Clinical settings access is gated by the offline clinical unlock verifier; material installation validates and stores verifier material, material refresh preserves accepted-counter state while clearing active unlock state, malformed/invalid/reused/non-ASCII codes block entry, accepted future counters unlock settings locally for the provisioned duration without requiring network access, and manual-lock storage failure does not falsely present a locked state | SRS-CLIN-001, SRS-CLIN-002 |
| TV-CLIN-002 | UI/Smoke | Subject ID, Weight, Start Algo, and Reset Algo are presented in Clinical Settings and not in participant-facing settings sections |
SRS-CLIN-003 |
| TV-CLIN-003 | Unit/UI | Target selector enforces allowed values (90, 100, 110, 120, 130 mg/dL) and rejects out-of-set values |
SRS-CLIN-004 |
| TV-CLIN-004 | Unit/UI | Meal upfront selector enforces two-option set (75%, 90%) and maps selected value into runtime config |
SRS-CLIN-005 |
| TV-CLIN-005 | Unit/UI | TMAX selector enforces 40...70 inclusive with 5-minute increments |
SRS-CLIN-006 |
| TV-CLIN-006 | Unit/Integration | Clinical settings persistence restores values across relaunch with deterministic default/migration behavior | SRS-CLIN-007 |
| TV-CLIN-007 | Unit/Integration | Start Algo and Reset Algo behavior remains unchanged after relocation into Clinical Settings |
SRS-CLIN-008 |
| TV-CLIN-008 | Unit | Weight conversion and validation path stores kg from integer lbs UI input | SRS-VAL-001, SRS-CLIN-003 |
| TV-CLIN-009 | Unit/Integration | Clinical save-review semantics hold: no persisted/runtime config mutation before Save+OK, cancel keeps prior applied config, and persisted update appears in next step telemetry snapshot |
SRS-CLIN-007, SRS-CLIN-008, SRS-LOG-001 |
| TV-CLIN-010 | Unit/UI | Participant-facing settings and the clinician target selector expose only the target set enabled by the clinician-selected target-access profile (Pregnancy vs Standard) |
SRS-CLIN-009, SRS-CLIN-010 |
| TV-CLIN-011 | Unit/UI | Participant target change requires approval capture and blocks apply until approving staff name and approximate approval time are both recorded | SRS-CLIN-011 |
| TV-CLIN-012 | Unit/UI | Clinical Settings normalizes the draft target to an allowed profile value when the clinician changes the target-access profile | SRS-CLIN-012, SRS-CLIN-010 |
| TV-CLIN-013 | Unit/Integration | Target-access profile persists across save/relaunch/migration and is reflected consistently in both participant and clinician settings views | SRS-CLIN-007, SRS-CLIN-009, SRS-CLIN-010 |
| TV-PUMP-001 | Unit | Pump unavailable -> run step, block command application | SRS-PUMP-001 |
| TV-PUMP-002 | Integration | Signal-loss policy persistence and clear behavior | SRS-PUMP-001, SRS-UI-002 |
| TV-PUMP-003 | Integration | Delivery reconciliation and min-dose quantization behavior | SRS-PUMP-003 |
| TV-PUMP-004 | System | Home pod card updates on connect/disconnect without entering settings | SRS-PUMP-004 |
| TV-PUMP-005 | Integration/System | Delivery-state clears from delivering via auto-refresh without opening Pump settings |
SRS-PUMP-005 |
| TV-PUMP-006 | UI/Integration | Closed-loop surfaces do not expose manual bolus command paths | SRS-PUMP-002 |
| TV-PUMP-007 | Unit/Integration | Masked fallback maintenance blocks disruptive schedule writes during unsafe pump states, arms newly computed missing fallback before the same step's pump command only when refreshed pump status is known/available, arms persisted missing fallback before the next loop execution once a valid candidate exists, programs the secondary/safety q5 nominal-basal four six-hour fallback schedule when available, renews the 0 U/hr mask inside the 20-minute renewal window, permits the normal step command after a clean first-arm block with no schedule mutation, prevents same-cycle post-execution first-arm retry after a pre-command fallback event, blocks the normal step command when first-arm remask failure creates reconciliation-required recovery, treats post-schedule mask blocking/failure as recovery-required remask failure, defers maintenance when pump state or late bolus-in-progress command races block renewal but the current mask is still active, records offline fallback activation plus reconciliation-required recovery state when the mask later expires, and performs schedule refresh using reprogram-and-immediate-remask semantics |
SRS-PUMP-006, SRS-PUMP-007, SRS-PUMP-008 |
| TV-PUMP-008 | Unit/Integration | Session reset/disarm attempts to restore the original programmed basal schedule, preserves recovery context when restore fails, retries connected restore/disarm when masked-fallback recovery remains pending on reconnect/start/foreground, preserves the existing session/cadence anchor after successful offline-expiry recovery while the loop remained armed, allocates credible same-pod pump-reported fallback delivery delta across missed primary/secondary algorithm replay steps with CGM=-1 and no catch-up pump commands, weights replay-step delivery by the persisted programmed fallback schedule including equal-rate, six-hour-window, partial-slot, and midnight-wrap cases while keeping the pump delta authoritative, suppresses replay for positive pump delta with no usable schedule weight, preserves zero-delivery replay rows when the authoritative pump delta is 0 U, suppresses replay for ambiguous, different/new pod, unknown identity, or history-discontinuous evidence while keeping same-session unreconciled continuation, records assumed-delivered modeled fallback exposure and queues bounded replay when the previous pod is known retired/inactive or past hard service-stop and pump-counter evidence is unrecoverable, stamps recovery-completion timing after restore finishes, captures basal-only reconnect evidence plus modeled-vs-pump-reported fallback delivery when compatible baseline data exist, and keeps explicit reset/loop-off recovery from silently turning the loop back on |
SRS-PUMP-009, SRS-STATE-004, SRS-STATE-005 |
| TV-PUMP-009 | Unit/Integration | Applied or uncertain automatic bolus commands persist issued-dose attribution; active delivery blocks live step advancement for the original/current pod; matching same-request same-pod pump evidence replays missed primary/secondary algorithm steps before the live step with delivered insulin injected only at the first missed attribution step and CGM=-1; delivered-unit evidence outside 0...requested is non-credible and does not replay or advance; combined same-pod pump-total evidence is partitioned into pending issued-dose evidence plus fallback-basal residual only when the request, pod identity, completion timing, and residual fallback exposure are credible, while raw pump-total delivery remains telemetry/operator-review evidence; fallback replay overlap is monotonic and non-duplicating and uses the same delivered-unit credibility rule; absent, mismatched, non-credible, missing-identity outside the user-confirmed unavailable-pod clinical-policy path, or non-partitionable evidence skips live advancement without clearing the pending attribution; user-confirmed unavailable-pod meal evidence may be consumed without pod identity only when request step, units, delivered bounds, and non-active pump status match; and different/new pod evidence, including replacement-pod active-delivery status, records different_or_new_pod, preserves the current algorithm session, assumes the issued dose was delivered, feeds the assumed delivered amount into the first eligible attribution step by replay or live input, scrubs unrelated replacement-pod lastDelivery from the resumed live algorithm input, clears the old-pod pending attribution after consumption, and allows later insulin-adding automatic commands including automatic resume under the new clinical-policy disposition |
SRS-PUMP-010, SRS-STATE-004, SRS-STATE-005 |
| TV-MEAL-001 | Unit | Meal announce borrow-window gating after cadence reconciliation against algorithm-reported next step | SRS-MEAL-001, SRS-RUN-002 |
| TV-MEAL-002 | Unit | Meal announce blocked when pump delivering/unknown | SRS-MEAL-002 |
| TV-MEAL-003 | Unit/Integration | Meal announce executes on current due step when slot is already due/missed | SRS-MEAL-004 |
| TV-MEAL-004 | Unit | Meal announce rejected before first successful anchored step | SRS-MEAL-005 |
| TV-MEAL-005 | Unit | Meal unavailable reason precedence reports noPump before signalLoss when no active pod is present |
SRS-MEAL-002, SRS-UI-002 |
| TV-MEAL-006 | Unit/UI | Meal unavailable messaging includes explicit actionable reason and retry timing when blocked, including reconnect/recovery-required guidance while masked-fallback reconciliation is pending | SRS-MEAL-003, SRS-UI-002 |
| TV-MEAL-007 | Unit/UI | Meal composer revalidates availability on foreground refresh and immediately before submit so stale available state cannot dispatch an invalid meal request | SRS-MEAL-006, SRS-UI-002 |
| TV-MEAL-008 | Unit/UI/Integration | Meal submit does not present success until runtime result is known; blocked/rejected and uncertain outcomes surface explicit user-facing recovery messaging | SRS-MEAL-007, SRS-UI-002 |
| TV-MEAL-009 | Integration | Pending or uncertain meal request state, including correlated flow ID, persists across relaunch and prevents duplicate meal entry until resolved | SRS-MEAL-008, SRS-MEAL-009, SRS-STATE-001 |
| TV-MEAL-010 | Integration/System | Command-outcome uncertainty (timeout/error with unresolved delivery state) blocks repeat meal announce and surfaces explicit operator guidance until reconciliation; immediate-success and reconciled meal lifecycle closure remain replayable across terminate/relaunch windows until resolved telemetry is emitted |
SRS-MEAL-008, SRS-MEAL-009, SRS-PUMP-001 |
| TV-MEAL-011 | Integration/System | Competing-trigger slot conflict does not silently lose or reinterpret meal intent; user receives explicit slot-conflict blocked/retry feedback and no hidden reassignment to a different borrowed step | SRS-MEAL-010, SRS-RUN-002, SRS-UI-002 |
| TV-MEAL-012 | Unit/UI/Integration | When meal entry is opened during active bolus delivery, the app presents a destructive Home inline cancel-delivery flow, keeps that flow visible while active meal delivery remains in progress, reports actual delivered insulin after cancellation in the Home summary region, retains that summary until both the next later algorithm step and a 5-minute minimum display window have passed, renders active in-progress meal delivery in the normal meal-dose color while reserving caution color for actual interrupted delivery, and preserves the delivered amount for subsequent algorithm-step accounting | SRS-MEAL-011, SRS-PUMP-003, SRS-UI-002 |
| TV-MEAL-013 | Unit/UI/Integration | When meal delivery progress cannot be confirmed for the original pod, the app offers an explicit pod-replacement escape only after known old-pod unavailability or expected-completion timeout, suppresses that escape for non-meal issued-dose attributions and already matched evidence, records assumed-delivered evidence with user_abandoned_unavailable_pod, clears only meal-progress UI state, preserves issued-dose attribution for replay/live-step accounting, and routes the operator to pod setup |
SRS-MEAL-012, SRS-PUMP-010, SRS-UI-002 |
| TV-STATE-001 | Integration | Relaunch restores cadence and algorithm state | SRS-STATE-001 |
| TV-STATE-002 | Integration | Reset clears all session state and starts fresh | SRS-STATE-002 |
| TV-STATE-003 | Integration/System | Pump and CGM manager state persistence supports reconnect without forced re-pairing on relaunch | SRS-STATE-003 |
| TV-STATE-004 | Integration | Masked fallback persistence retains original/fallback schedules, maintenance timestamps, active safety target, connected pod identity and total-delivery baseline, restore-failed or reconciliation-required recovery context, primary and secondary/safety q5 nominal-basal profiles, and any pending pump-delta reconciliation state needed for later refresh, restore, reconnect recovery retry, confirmed/corrected missed-step algorithm replay, or ambiguous unreconciled resume | SRS-STATE-004 |
| TV-STATE-005 | Unit/Integration | Runtime recovery, pump reconnect, pod replacement, CGM recovery, fallback reconciliation failure, launch, foreground, scheduler wake, telemetry replay, and cloud/auth state do not stop/start/reset the algorithm or create a replacement algorithm session without explicit operator action; unreconciled fallback recovery preserves the existing session/cadence state while suppressing replay | SRS-STATE-005 |
| TV-LOG-001 | Unit | Step telemetry contains explicit step_executed_at plus input/output/command fields |
SRS-LOG-001 |
| TV-LOG-002 | Integration | CSV export schema and row append behavior, including masked-fallback missed-step algorithm replay rows from credible pump delta with CGM=-1, per-step delivered-insulin input including explicit 0 U input for replay steps with no pump allocation, and no catch-up pump command rows |
SRS-LOG-002 |
| TV-LOG-003 | Unit/Integration | Async export avoids main-actor blocking | SRS-LOG-003 |
| TV-LOG-004 | Unit/UI | Debug-only cloud-log threshold control persists selected level and upload filter remains inclusive (selected level and higher severities) with default fallback to Error |
SRS-LOG-004 |
| TV-LOG-005 | Unit | Clinical Settings save flow emits deterministic ui.critical telemetry (state_viewed, submit, cancel, blocked) with stable element IDs and old/new value details |
SRS-LOG-005 |
| TV-LOG-006 | Unit/Integration | App lifecycle telemetry includes timezone and clock-check context fields with correct trigger semantics (launch, foreground >24h gate, timezone_or_time_changed) |
SRS-LOG-006 |
| TV-LOG-007 | Unit/Integration | Meal-request telemetry exposes the implemented lifecycle transitions (submitted, accepted, success, blocked, uncertain, resolved) without optimistic-success duplication, with replay durability across terminate/relaunch windows, and loop-command telemetry preserves explicit command outcome semantics (applied, blocked, uncertain) |
SRS-LOG-007, SRS-MEAL-007 |
| TV-LOG-008 | Unit/UI | Target-access-profile and participant approval-capture telemetry emit stable ui.critical events with required detail fields (target_range_profile, requested/applied target, approval metadata, and blocked/cancelled reason) |
SRS-LOG-008 |
| TV-LOG-009 | Unit/UI/Integration | Fallback review telemetry persists and renders fallback arm, maintenance-deferred, renew, schedule-unchanged check, refresh, mask-expiry, disarm, and restore/remask failure events with rate/source/target/duration/reconciliation/pod-continuity detail in Recent Dose Steps; resolved recovery rows include modeled expected delivery, same-pod pump-reported delivered insulin when available, and pump-delta reconciliation detail when confirmed/corrected recovery occurs; executed step rows render both primary and secondary algorithm summaries (step count, suggested dose, nominal basal, instant basal) from persisted per-step telemetry; confirmed/corrected reconnect recovery records no-command missed-step primary/secondary algorithm replay rows with CGM=-1 and persisted-schedule-weighted per-step pump delivery including explicit 0 U replay steps when no pump allocation belongs to a missed step, and the resumed live step uses actual refreshed pump status without duplicate recovered-delivery injection; and cloud telemetry emits a structured loop.fallback.event family with stable fallback_event_id, delivery/reconciliation summary fields including pod_continuity, programmed schedule entries, safety q5 profile metadata, and duplicate suppression for unchanged fallback review state |
SRS-LOG-009 |
| TV-UI-001 | UI/System | Home loop-state precedence rendering and cadence-phase age classification (nextDueAt-based Active/Aging/Stale) |
SRS-UI-001 |
| TV-UI-002 | UI/System | Availability messaging matches runtime outcomes | SRS-UI-002 |
| TV-UI-003 | UI/System | CGM/Pod setup modal Cancel dismisses directly and does not force settings on no-active-pod startup |
SRS-UI-003 |
| TV-UI-004 | Unit/UI | Meal announcement composer auto-cancels on app background transition | SRS-UI-004 |
| TV-UI-005 | UI/Smoke | Home primary controls are present and actionable in deterministic launch mode (settings, manual BG, Let's Eat) |
SRS-UI-002 |
| TV-UI-006 | UI/Smoke | Home settings and manual-BG sheets can be opened and dismissed without dead-end navigation | SRS-UI-002, SRS-BG-001 |
| TV-UI-007 | Unit/UI | CGM display masks stale (>11m) or unreliable (hasReliableGlucose == false) readings as -- and hides trend arrow |
SRS-UI-005 |
| TV-UI-008 | Unit/Integration | UTC clock-drift warning behavior: >600s skew emits non-blocking actionable warning with 24h rate limit, <=600s shows no warning, and unavailable checks do not spam warnings |
SRS-UI-006 |
| TV-UI-009 | Unit/UI | CGM value formatting maps boundaries to textual LOW/HIGH across display surfaces and suppresses unit suffix for those states |
SRS-UI-007 |
| TV-UI-010 | Unit/UI | Home CGM chart uses bounded dynamic y-axis maxima (300/350/400) based on displayed peak values |
SRS-UI-008 |
| TV-ALERT-001 | Unit | Alert normalization maps Omni/G7/runtime events to canonical model fields | SRS-ALERT-001, SRS-ALERT-002 |
| TV-ALERT-002 | Unit/Integration | Alert precedence keeps critical alert visible when lower-severity alerts coexist | SRS-ALERT-003 |
| TV-ALERT-003 | Integration | Transient reconnect events are debounced/coalesced without suppressing persistent faults | SRS-ALERT-004 |
| TV-ALERT-004 | Integration/System | Alert clear/ack rules behave per alert type and update UI state correctly | SRS-ALERT-005 |
| TV-ALERT-005 | System/Manual | Protocol-required alerts and wording are present and actionable in app flows | SRS-ALERT-006 |
| TV-ALERT-006 | Unit/Integration | High-priority non-CGM alerts emit background local notifications with dedupe/cooldown, while CGM alerts and informational alerts do not | SRS-ALERT-007 |
| TV-ALERT-007 | Unit/UI | Alert Center shows active and recently-cleared alerts with deterministic sorting and acknowledge path for required-ack alerts | SRS-ALERT-008, SRS-ALERT-005 |
| TV-ALERT-008 | Integration | Pump/CGM persisted-alert lifecycle hooks preserve issued/unretracted/retracted state across relaunch and restore active alert visibility | SRS-ALERT-009 |
| TV-ALERT-009 | Unit/Integration | Time-sensitive alert countdown text refreshes at minute cadence while active without notification spam | SRS-ALERT-010, SRS-ALERT-007 |
| TV-ALERT-010 | Unit/UI | Home active-alert vertical carousel preserves severity/recency ordering, shows multiplicity, and allows deterministic navigation through active alerts | SRS-ALERT-003, SRS-ALERT-011 |
| TV-ALERT-011 | Unit/Integration | No-active-pod cleanup retracts only non-critical pod-tied alerts while retaining ALERT-PUMP-FAULT and ALERT-PUMP-INCOMPATIBLE until explicit closure |
SRS-ALERT-005, SRS-ALERT-012 |
| TV-ALERT-012 | Integration/System | Algorithm Stepping Interrupted issues an actionable alert, clears on resumed successful stepping or loop disarm, and remains distinct from informational G7 unavailable/failed status surfaces |
SRS-ALERT-013, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005 |
| TV-ALERT-013 | Unit/Integration/System | Algorithm Stepping Interrupted issues after >15 minutes without successful step execution while armed, carries blocker/root-cause detail, clears on next successful step or loop disarm, and preserves stronger pump/source-native alert precedence while leaving CGM state as informational context |
SRS-ALERT-014, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005, SRS-UI-002 |
| TV-ALERT-014 | Unit/Integration | CGM availability/failure normalized alerts remain informational in-app status only, do not expose required-ack behavior, and never schedule background local notifications | SRS-ALERT-015 |
| TV-ALERT-015 | Unit/Integration | App-derived CGM urgent-low review alert issues only for trustworthy G7 readings <55 mg/dL, preserves reviewed state while active, auto-clears on trustworthy recovery >=55 mg/dL, persists acknowledged active state across reset/reattach, and never schedules background local notifications |
SRS-ALERT-016, SRS-ALERT-005, SRS-ALERT-007 |
| TV-ALERT-016 | Unit/Integration | No-active-pod conditions raise a safety-critical pump alert after debounce, repeat background local notification attempts at the approved 30 minute cadence while the condition remains true, and stop repeating when active pod state is restored |
SRS-ALERT-017, SRS-ALERT-007, SRS-ALERT-005 |
| TV-SEC-001 | Integration | Local export controls and file handling behavior, including development-only CSV export and the current file-sharing / open-in-place surface | SRS-SEC-002 |
| TV-SEC-002 | Integration/System | Deferred from current software handoff package. If secure cloud upload primary-path closure is re-entered into scope, verify cloud telemetry upload control behavior and failure handling. | SRS-SEC-001 |
| TV-SEC-003 | Integration/System | Deferred from current software handoff package. If protected cloud API access is re-entered into scope, verify it requires valid authenticated session. | SRS-SEC-003, SRS-SEC-006 |
| TV-SEC-004 | UI/Integration | Deferred from current software handoff package. If multi-provider onboarding is re-entered into scope, verify allowed sign-in entry points and failure states. | SRS-SEC-004, SRS-SEC-006 |
| TV-SEC-005 | Integration/System | Deferred from current software handoff package. If authorization-role enforcement is re-entered into scope, verify unauthorized telemetry/dashboard actions are denied. | SRS-SEC-005, SRS-SEC-006 |
| TV-SEC-006 | Unit/Integration | Deferred from current software handoff package. If password-recovery workflow is re-entered into scope, verify reset-code request and confirm-reset success/failure handling. | SRS-SEC-007, SRS-SEC-006 |
| TV-SEC-007 | Unit/Integration | Deferred from current software handoff package. If launch session restore is re-entered into scope, verify authenticated UX is preserved when token recovery succeeds. | SRS-SEC-008, SRS-SEC-006 |
| TV-SEC-008 | Unit/UI | Deferred from current software handoff package. If auth-failure Home-bypass continuity is re-entered into scope, verify the login-required alert and recovery action. | SRS-SEC-009, SRS-SEC-006 |
5.0 Algo2015 Structural-Coverage Campaign
The detailed campaign definition, thresholds, and required STR artifact set are maintained in Algo2015 Verification Plan. Execution progress and phase-level closure tracking are maintained in Algo2015 Execution Roadmap.
5.1 Proposed Simulation Campaign (Workstream H)
This campaign adds deterministic scenario replay (medium-fidelity mocks) as a required verification layer for runtime safety logic. It complements hardware-in-the-loop testing and does not replace real-device validation.
| Test ID | Level | Purpose | SRS Link |
|---|---|---|---|
| TV-SIM-001 | Integration (deterministic sim) | Reproduce anchored cadence across reconnect/relaunch windows and assert step index continuity (expected, executed, skipReason) |
SRS-RUN-001, SRS-RUN-002, SRS-STATE-001 |
| TV-SIM-002 | Integration (deterministic sim) | Validate step-0 hard gate and step>0 degraded CGM execution (-1) across stale/out-of-range/noisy sensor sequences |
SRS-CGM-001, SRS-CGM-002, SRS-CGM-003 |
| TV-SIM-003 | Integration (deterministic sim) | Validate pump-unknown/unavailable execution with command-block and no false delivery application | SRS-PUMP-001, SRS-PUMP-005 |
| TV-SIM-004 | Integration (deterministic sim) | Validate meal and BG trigger interplay under missed-step, reconnect, and degraded-input conditions | SRS-MEAL-001, SRS-MEAL-002, SRS-BG-002, SRS-BG-003 |
| TV-SIM-005 | Integration (deterministic sim) | Validate alert lifecycle, countdown refresh progression, dedupe, and clear behavior during state churn | SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-010 |
| TV-SIM-POD-001 | Integration (deterministic pod sim, provisional scaffold) | Validate stateful pod ledger math for bolus progress/cancel, fallback mask expiry/renewal, pod expiry, and pod replacement identity continuity without live pod burn | SRS-PUMP-006, SRS-PUMP-008, SRS-RUN-006 |
| TV-SIM-POD-002 | Integration (deterministic pod sim, provisional scaffold) | Validate pending issued-dose restoration and replay through simulated pump status using production runtime coordinator logic | SRS-STATE-005, SRS-MEAL-005, SRS-LOG-009 |
| TV-SIM-POD-003 | Integration (deterministic pod sim, provisional scaffold) | Validate that meal/correction delivery completed before the fallback baseline is not subtracted from fallback pump-total delta | SRS-PUMP-008, SRS-PUMP-009, SRS-LOG-009 |
| TV-SIM-POD-004 | Integration (deterministic pod sim, provisional scenario slice) | Validate first high-risk pod scenarios using shared invariants: canceled and consecutive-canceled meal evidence feed subsequent meal announcements without replay or stale evidence reuse, force-quit/relaunch restores in-flight meal delivery knowledge before the next CGM, relaunch with pending fallback replay after step 0 can replay with unavailable CGM inputs without dropping the plan, lost final meal response before status refresh is preserved until same-pod reconnect, same-pod completed meal and reservoir-capped partial meal evidence feed the live attribution step without replay, different/new-pod, user-escaped unavailable-pod, and unresolved correction-only/basal-only issued doses are assumed delivered without blocking replacement-pod dosing when policy allows, stale cached idle is not trusted when fresh refresh fails, fallback maintenance block prevents the live bolus command, meal/fallback delta partitioning separates issued dose from fallback residual, fallback replay allocation follows the programmed schedule weights only after mask expiry, reservoir-capped fallback replay uses observed pump delta instead of modeled exposure, ambiguous fallback restore does not replay or inject modeled fallback insulin into the live step, assumed old-pod fallback replay emits no pump commands and allows replacement-pod live dosing, missing-status/nonreplayable fallback plans are cleared without row emission, matching pending meal-progress state clears when issued-dose evidence is consumed, and app recent-dose rows, local step CSV export, and runtime cloud step-event emission preserve/display merged replay evidence source, disposition, request step, requested units, and delivered units | SRS-PUMP-008, SRS-PUMP-009, SRS-PUMP-010, SRS-MEAL-005, SRS-LOG-009 |
Planned evidence:
- STR-SIM-* scenario reports with script file, expected output snapshot, actual output snapshot, and pass/fail deltas.
- Script baseline: /Users/jcostik/BionicLoop/Scripts/run_sim_harness_verification.sh (emits run-context, results, trace-map, and suite logs).
- Merge-gate helper: /Users/jcostik/BionicLoop/Scripts/check_sim_merge_gate.sh (runs TV-SIM-* / pod-sim rows only when high-risk runtime, pump, fallback, or reconciliation paths are touched).
Future extension (high-fidelity): - After medium-fidelity stability, add BLE/session-level emulation cases for hardware-specific transport faults and timing jitter that mock services cannot represent.
Current implemented deterministic simulation coverage:
- testTVSIM001_AnchoredCadenceAcrossReconnectAndRelaunch (TV-SIM-001)
- testTVSIM002_StepZeroGateAndStepGreaterThanZeroDegradedCGMExecution (TV-SIM-002)
- testTVSIM003_PumpUnavailableAndUnknownStatesBlockLiveExecution (TV-SIM-003)
- testTVSIM004_MealAndBGInterplayAcrossMissedStepsAndReconnectChurn (TV-SIM-004)
- testTVSIM005_AlertLifecycleChurnCountdownDedupeAndClearTransitions (TV-SIM-005)
- testSimulatedDashPodReportsBolusProgressAndCancelPartialDelivery (TV-SIM-POD-001)
- testSimulatedDashPodAccruesFallbackBasalOnlyAfterMaskExpires (TV-SIM-POD-001)
- testSimulatedDashPodDoesNotExposeFreshFallbackDeltaWhileDisconnected (TV-SIM-POD-001, TV-SIM-POD-003)
- testSimulatedDashPodMaskRenewalExtendsZeroBasalSuppression (TV-SIM-POD-001)
- testSimulatedDashPodExpiryStopsDeliveryAndReportsUnknownState (TV-SIM-POD-001)
- testSimulatedDashPodReplacementResetsCountersAndRejectsOldPodAttribution (TV-SIM-POD-001)
- testSimulatedDashPodReplacementClearsSuspendedState (TV-SIM-POD-001)
- testSimulatedDashPodCapsBolusDeliveryAtReservoirRemaining (TV-SIM-POD-001)
- testScriptedPodPumpServiceDoesNotReportStartForPreStartBolusFailure (TV-SIM-POD-001)
- testSimulatedDashPodRestoresPersistedPendingDoseFromPastRequestTime (TV-SIM-POD-002)
- testSimulatedDashPodDoesNotAdvanceClockForFuturePendingAttributionRestore (TV-SIM-POD-002)
- testScriptedPodPumpServiceFeedsCompletedIssuedDoseIntoReplayWithoutHardwareFixtures (TV-SIM-POD-002)
- testCompletedMealBeforeFallbackBaselineDoesNotPolluteFallbackDelta (TV-SIM-POD-003)
- testMealDoseOverlappingFallbackWindowPartitionsPumpDeltaBeforeFallbackReplay (TV-SIM-POD-003, TV-SIM-POD-004)
- testPodScenarioCanceledMealEvidenceFeedsNextMealAnnouncementWithoutReplay (TV-SIM-POD-004)
- testPodScenarioConsecutiveCanceledMealsConsumeLatestEvidenceWithoutReplay (TV-SIM-POD-004)
- testPodScenarioForceQuitRelaunchRestoresInFlightMealBeforeNextCGM (TV-SIM-POD-004)
- testPodScenarioLostFinalMealResponseDisconnectsBeforeRefreshThenReconcilesOnSamePodReconnect (TV-SIM-POD-004)
- testPodScenarioSamePodCompletedMealFeedsLiveAttributionStepWithoutReplay (TV-SIM-POD-004)
- testPodScenarioReservoirCappedMealFeedsActualDeliveredUnitsWithoutReplay (TV-SIM-POD-004)
- testPodScenarioDifferentOrNewPodAssumesIssuedDoseAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioReplacementAfterUnreconciledOldPodDoseAssumesOldDoseAndAllowsNewPodLiveDose (TV-SIM-POD-004)
- testPodScenarioUserEscapedUnavailableOldPodConsumesAssumedEvidenceAndAllowsNewPodDose (TV-SIM-POD-004)
- testPodScenarioUnresolvedCorrectionWithoutPodIdentityAssumesDeliveredAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioUnresolvedBasalMicrodoseAssumesDeliveredAndAllowsLiveDose (TV-SIM-POD-004)
- testPodScenarioStaleCachedIdleDoesNotAuthorizeBolusWhenFreshRefreshFails (TV-SIM-POD-004)
- testPodScenarioFallbackMaintenanceBlockPreventsLiveBolus (TV-SIM-POD-004)
- testPodScenarioFallbackReplayUsesScheduleWeightsOnlyAfterMaskExpiry (TV-SIM-POD-004)
- testPodScenarioReservoirCappedFallbackReplayUsesObservedPumpDelta (TV-SIM-POD-004)
- testPodScenarioMealOverlapPartitionsPumpDeltaAndMergesIntoFallbackReplay (TV-SIM-POD-004)
- testPodScenarioPendingFallbackReplayRunsOnRelaunchWithoutFreshCGMAfterStepZero (TV-SIM-POD-004)
- testPodScenarioAmbiguousFallbackRestoreDoesNotReplayOrInjectModeledDose (TV-SIM-POD-004)
- testPodScenarioAssumedFallbackReplayFromUnavailableOldPodAllowsReplacementDose (TV-SIM-POD-004)
- testPodScenarioNonReplayableFallbackPlanClearsWithoutReplayOrModeledDoseInjection (TV-SIM-POD-004)
- testRecentDoseTimelinePersistsMergedMealFallbackReplayEvidenceLabels (TV-SIM-POD-004)
- testCSVExportIncludesFallbackReplayRows (TV-SIM-POD-004, TV-LOG-002, TV-LOG-009)
- testEmitExecutionTelemetryPublishesReplayAndLiveAlgorithmStepSnapshots (TV-SIM-POD-004, TV-LOG-009)
Current implemented alert-test coverage:
- testTopAlertPrefersHigherSeverityThenMostRecent and testSortedAlertsOrdersBySeverityRecencyAndStableDedupeKey cover deterministic alert ordering precedence (TV-ALERT-002 subset).
- testHomeAlertCarouselNavigatorClampsAndWrapsIndexes covers Home vertical-carousel paging invariants (clamp + wrap) used for deterministic multi-alert navigation (TV-ALERT-010 subset).
- testNoActivePodDebounceAddsAndClearsAlert, testNoActivePodConditionRepeatsBackgroundNotificationUntilRecovered, and testHomeAlertSyncEvaluatorReflectsCombinedPumpConditions cover no-active-pod alert path, repeated safety-critical background notification attempts while the condition remains true, clear-on-recovery behavior, and suppression of competing signal-loss state when no pod is present (TV-ALERT-003, TV-ALERT-004, TV-ALERT-016 subset).
- testSignalLossDebounceAddsAndClearsAlert covers debounce + auto-clear behavior, actionable background notification cooldown/dedupe, and clear-on-retract notification cleanup (TV-ALERT-003, TV-ALERT-004, TV-ALERT-006 subset).
- testSignalLossDebounceSuppressesTransientCondition covers transient suppression and notification authorization priming dedupe (TV-ALERT-003, TV-ALERT-006 subset).
- testShowPreviewAlertsSupportsMultipleTypesAndPrecedence covers severity-filtered background notification routing (critical not informational), alert-category route mapping, and safety-critical acknowledge behavior (TV-ALERT-002, TV-ALERT-004, TV-ALERT-006 subset).
- testCloudTelemetryReporterSurfacesSubjectIDConflictAndStopsRetryFor409Conflict, testHomeSettingsViewClearsResolvedSubjectIDConflictAlert, testSubjectIDConflictAutoResolutionPolicyRequiresActiveAlertNonEmptySubjectAndNoInFlightCheck, and testSubjectIDConflictAutoResolutionPolicyThrottlesSameSubjectAndAllowsChangedSubject cover the app-policy subject-ID conflict alert lifecycle: issue on permanent cloud claim conflict, explicit retract after successful corrected Clinical Settings save, and throttled Home auto-revalidation of the currently persisted subject ID when a stale conflict alert remains active (TV-ALERT-005 subset).
- testCGMAlertsNeverScheduleBackgroundNotifications, testCGMAlertMapperFailedFromSensorFailedState, testCGMAlertMapperUnavailableFromWarmupState, and testCGMFailedAlertRestoresFromLiveStateAcrossAlertCenterResetUntilRecovery cover the CGM availability/failure policy: informational in-app status only, no required-ack path, and no background local notifications (TV-ALERT-014, TV-ALERT-006 subset).
- testCGMUrgentLowAlertMapperIssuesForReliableReadingBelow55, testCGMUrgentLowAlertMapperClearsAt55OrAbove, testCGMUrgentLowAlertMapperSkipsUnreliableReading, testCGMUrgentLowAlertMapperSkipsStaleReading, testUrgentLowAcknowledgeMarksAlertReviewedWithoutClearingActiveState, testCGMUrgentLowAcknowledgePersistsAcrossAlertCenterResetUntilRecovery, and testCGMAlertsNeverScheduleBackgroundNotifications cover the app-derived urgent-low review alert trigger, trustworthy-data gate, reviewed-state retention, reset/reattach persistence, recovery auto-clear, and no-OS-notification policy (TV-ALERT-015, TV-ALERT-006 subset).
- testAlertCenterTracksRecentlyClearedAlerts and testAlertCenterRestoresPersistedActiveAndClearedAlerts cover in-app Alert Center active/recent behavior and persistence restore path (TV-ALERT-007, TV-ALERT-008 subset).
- testPumpAlertMapperExpiringIncludesCountdownDeadline, testPumpAlertMapperExpiredForPodExpiringAlert, and testTimeSensitivePumpExpiringAlertRefreshesMessageWithoutReschedulingNotification cover pod-expiration countdown mapping (expiring and expired paths) plus minute-refresh text updates without extra background notification scheduling (TV-ALERT-009, TV-ALERT-006 subset).
- UI automation now covers Home-to-Alert-Center routing, acknowledge-to-recent flow, and relaunch persistence visibility (testUI007_HomeAlertCenterButtonOpensAlertCenter, testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared, testUI009_AlertCenterPersistsAcrossRelaunch) (TV-ALERT-007, TV-ALERT-008 subset).
- testPumpPersistedAlertStoreReturnsIssuedAndRetractedAlerts and testCGMPersistedAlertStoreReturnsIssuedAndRetractedAlerts cover delegate PersistedAlertStore issue/retract lookup behavior (TV-ALERT-008 subset).
- testPumpExpirationAlertSyncPlannerReturnsRetractsWhenNoExpirationAlertsApply covers no-active-pod retract-set safety boundary by excluding critical fault/incompatible alerts from auto-retract cleanup (TV-ALERT-011 subset).
- testCGMAlertMapperPrioritizesUnavailableOverFailedKeywordCollision and testCGMAlertMapperDoesNotClassifyMessageOnlyFailedAsSensorFailure verify CGM fallback keyword mapping cannot escalate transient/message-only text into ALERT-CGM-FAILED-OR-EXPIRED (TV-ALERT-001 subset).
Current implemented runtime-refactor regression coverage:
- testMealPumpUnavailableReasonMapping verifies meal-unavailable reason precedence (noPump over signalLoss when no active pod exists) (TV-MEAL-005 subset).
- testMealAnnouncementSheetLifecycleRevalidatesOnlyOnForeground and testHomeRuntimeActionCoordinatorMealComposerContinuationDecision verify the foreground revalidation gate and stale-composer availability remapping used before meal submit dispatch (TV-MEAL-007 subset).
- testMealAnnouncementAvailabilityBlocksPersistedPendingMealRequestAcrossRelaunch, testMealAnnouncementAvailabilityReconcilesResolvedPendingMealRequestOnLaunch, testMealAnnouncementAvailabilityConsumesPersistedResolvedTelemetryReplayStateOnLaunch, testReconciledPendingMealAnnouncementStateClearsWhenTargetStepAlreadyExecuted, testMealAnnouncementResolutionEventUsesPersistedFlowIDForResolvedPendingState, and testMealAnnouncementResolvedEventUsesPersistedResolvedTelemetryReplayState verify persisted pending meal-request durability, relaunch duplicate blocking, replay-token consumption, target-step reconciliation, and correlated flow-ID closure for resolved lifecycle telemetry (TV-MEAL-009 subset, TV-LOG-007 subset).
- LoopRuntimeCoordinatorMealAnnouncementTests.testMealAnnouncePersistsPendingMealOnlyAfterExecutionStepAccepted and LoopRuntimeCoordinatorMealAnnouncementTests.testMealAnnounceRejectedBeforeAcceptanceDoesNotPersistPendingMealState verify that pending meal state is written only after the coordinator has accepted a concrete execution step and is not left behind for rejected meal attempts (TV-MEAL-009 subset).
- testAnnounceMealReturnsBlockedWhenLoopIsOff, testAnnounceMealReturnsBlockedWhenPersistedPendingMealExists, testReconciledUncertainPendingMealAnnouncementStateClearsWhenPumpDeliveryMatchesTargetStep, testMealAnnouncementResolutionEventUsesReconciledAfterUncertainForUncertainClear, testMealAnnouncePersistsPendingMealOnlyAfterExecutionStepAccepted, testMealAnnounceRejectedBeforeAcceptanceDoesNotPersistPendingMealState, testMealAnnounceUncertainDeliveryRetainsPendingMealState, and testHomeMealAnnouncementSubmitPolicyEventsAndBlockedContent verify that meal submit no longer reports optimistic success, that blocked runtime outcomes map to explicit blocked results, and that Home/runtime expose deterministic submitted/accepted/success/uncertain/resolved telemetry closure with explicit uncertain reconciliation semantics (TV-MEAL-008, TV-MEAL-010, TV-LOG-007 subset).
- testHomeRuntimeActionCoordinatorRoutesPumpDeliveringToCancelDeliveryFlow, testMealAnnouncementCancelledDeliverySummaryUsesPartialDeliveryCopy, testMealAnnouncementCancelledDeliverySummaryHandlesNoDeliveredInsulin, testMealAnnouncementCancelledDeliverySummaryIncludesCancelDetails, testMealAnnouncementCancelledDeliveryPolicyRequiresFiveMinutesAndNextStep, testMealAnnouncementCancelledDeliveryPolicyUsesNextStepThreshold, testMealAnnouncementDisplaySupportMapsMealContext, testPumpServiceAdapterCancellationDeliveryStatusUsesRequestedAndDeliveredUnits, testPumpServiceAdapterCancellationDeliveryStatusInfersPartialWhenDeliveredUnitsAreMissing, testPumpServiceAdapterResolvedBolusDeliveredUnitsPrefersPodCompletionWhenEventHistoryLags, testPumpServiceAdapterResolvedBolusDeliveredUnitsUsesBestAvailableProgressWhileBolusing, testPumpServiceAdapterAuthoritativeCompletedDeliveryPrefersCanceledUnitsWhenIdle, testCanceledMealDeliveryRecordsEvidenceAndClearsPendingMealBlock, testMealAnnouncementAvailabilityAllowsPersistedMealAttributionWithMatchingEvidence, testMealDeliveryProgressRestorePolicyDoesNotRestoreAfterMatchingEvidenceIsStored, testMealDeliveryProgressRestorePolicyRequiresMatchingPodIdentity, testRecordDoWorkResultMarksSuccessfulBolusAsDeliveringBeforePumpRefresh, testReconcilePumpStatusUpdatesInterruptedDeliveryToCompletedAfterLaterRefresh, testReconcileCanceledDeliveryUsesDeliveredUnitsForInterruptedMealBar, testPumpStatusObserverRefreshReconcilesSharedTelemetryStoreUntilDeliveryCompletes, testPumpStatusObserverApplyCanceledBolusDeliveryReconcilesSharedTelemetry, testInsulinChartPointFlagsInterruptedDeliveryWhenDeliveredLessThanRequested, testInsulinChartPointDoesNotFlagActiveDeliveryAsInterrupted, testInlineInsulinChartStylingUsesCautionColorForInterruptedDelivery, testInlineInsulinPointCompactorPreservesDeliveringStateWhenCollapsingPoints, testHomeViewStateBuilderActiveMealDeliveryCancellationContextUsesOnlyDeliveringMealStep, and testUI002b_MealCancelDeliveryFlowShowsPartialDeliverySummaryAndComposer verify the meal cancel-delivery path: active-delivery routing into a destructive Home inline cancel flow, automatic visibility of the cancel control while a meal bolus is still actively delivering, requested/delivered-unit reporting after cancellation, orange partial-delivery context in Home's alert-summary region above the chart, cancel-time plus meal-context summary detail, optimistic active-delivery chart state immediately after a successful bolus command, explicit canceled-delivery reconciliation into shared step telemetry so interrupted bar height matches actual delivered insulin, normal meal-color chart rendering while delivery is still active, compactor preservation of delivering state when bars visually collapse, caution-color rendering only for actual interrupted delivery derived from requested-vs-delivered telemetry, later pump-refresh reconciliation back to completed delivery when the bolus finishes normally, pod-status flooring when event-history delivery lags, immediate persisted cancellation evidence for runtime meal-unblock/replay accounting, restore suppression only for attribution/evidence with matching pod identity, and preservation of delivered insulin accounting for the next algorithm step when the operator later reopens meal announce (TV-MEAL-012 subset, TV-PUMP-003 supporting coverage).
- BionicLoopMealAnnouncementRuntimeTests and BionicLoopMealAnnouncementPodReplacementEscapeTests cover testMealDeliveryPodReplacementEscapePolicyRequiresMealAndElapsedCompletionWindow, testMealDeliveryPodReplacementEscapePolicyAllowsKnownUnavailablePodWithoutWaitingForGrace, testMealDeliveryPodReplacementEscapePolicySuppressesEscapeAfterMatchingEvidence, testUserAbandonedMealDeliveryRecordsAssumedDeliveredEvidenceForPodReplacement, and testUserAbandonedMealDeliveryDoesNotResolveNonMealIssuedDose, verifying the explicit user-confirmed pod-replacement escape: availability only for matching meal-linked attribution, timeout/known-unavailable gating, suppression after matching evidence, assumed-delivered evidence persistence with user_abandoned_unavailable_pod, meal-progress field clearing, issued-dose attribution preservation for replay/live accounting, and correction-only suppression (TV-MEAL-013, TV-PUMP-009 supporting coverage).
- testCorrectionDeliveryCreatesPendingIssuedDoseAttribution, testPendingIssuedCorrectionDoesNotAdvanceWhilePumpStillDelivering, testReconciledCorrectionDeliveryReplaysFirstMissedPostDoseStepBeforeLiveResume, testReconciledMealDeliveryReplaysFirstMissedPostMealStepBeforeLiveResume, testIssuedDoseAttributionDoesNotReplayOrAdvanceWithNonCredibleDeliveredUnits, testFallbackBasalExposureReconcilerPartitionsIssuedDoseFromPumpDeltaBeforeCredibilityCheck, testFallbackBasalExposureReconcilerRejectsPendingIssuedDoseWhenPumpDeltaCannotCoverRequest, testFallbackBasalExposureReconcilerRejectsPartitionWhenResidualDoesNotMatchFallbackExposure, testFallbackBasalExposureReconcilerAcceptsLowerResidualAfterIssuedDosePartition, testFallbackBasalExposureReconcilerPartitionsPersistedIssuedDoseEvidence, testPartitionedIssuedDoseEvidenceReplaysWhenPumpLastDeliveryIsUnavailable, testPartitionedIssuedDoseEvidenceMergesWithFallbackReplayWhenPumpLastDeliveryIsUnavailable, testPartitionedIssuedDoseEvidenceFeedsLiveFirstAttributionStepWhenReplayIsNotRequired, testReconnectRecoveryPartitionsPendingIssuedDoseBeforeFallbackReplayPlanning, testReconnectRecoveryUsesLowerFallbackResidualAfterIssuedDosePartition, testAmbiguousPartitionCarriesPumpTotalWithoutClaimingFallbackActualDelivery, testRecentDoseTimelineFallbackReconnectRecoveryTextDoesNotClaimResidualForPumpTotalOnly, testMealDeliveryAttributionDoesNotDuplicateFallbackReplaySteps, testMealDeliveryAttributionMergesWithFallbackReplayWhenFirstMissedStepOverlaps, testFallbackReplayPumpStatusDoesNotMergeNonCredibleIssuedDoseDelivery, testMealDeliveryAttributionDoesNotReplayWithoutMatchingPumpEvidence, testMealDeliveryAttributionDoesNotReplayWhenRequestedUnitsMismatch, testUnresolvedIssuedDoseDoesNotAdvanceLiveStepWithoutClearingPendingAttribution, testIssuedDoseAttributionDoesNotReplayOrAdvanceWithoutPodIdentity, testIssuedDoseAttributionAssumesDeliveredForDifferentOrNewPodAndReplaysBeforeLive, testIssuedDoseAttributionAssumesDeliveredForDifferentOrNewPodEvenWhenObservedPodIsDelivering, testPersistedAssumedDeliveredEvidenceKeepsClinicalPolicyReplayDisposition, testAssumedDeliveredDifferentOrNewPodFallbackMergeScrubsReplacementPodDeliveryFromLiveStep, testAssumedDeliveredDifferentOrNewPodAllowsFutureAutomaticInsulinCommand, testLegacyDifferentOrNewPodDispositionDoesNotBlockAutomaticResumeCommand, testRuntimeResolutionDismissesWhenMatchingPendingMealAttributionClears, testMealAnnouncementAvailabilityIgnoresLegacyDifferentNewPodHoldAcrossRelaunch, testMealAnnouncementAvailabilityBlocksActiveIssuedDoseReconciliationHold, and testBlockedMealAnnouncementAvailabilityMapsIssuedDoseReconciliationPending verify generalized issued-dose attribution, active-delivery step blocking, same-request/same-pod missed-step replay, pump-total partition of known in-flight issued dose from fallback basal residual, acceptance of lower pump-reported fallback residuals after issued-dose subtraction, persisted partition evidence consumption on the live first attribution step when replay is not required, raw pump-total telemetry without claiming fallback residual in ambiguous/unresolved recovery, delivered-unit credibility rejection for over-modeled residuals, fallback replay overlap handling after mask expiry, no-guess unresolved behavior, missing-identity no-replay/no-live-advance behavior, different/new-pod assumed-delivered attribution with replacement-pod live-step insulin-input scrubbing including fallback-replay merge overlap, retained clinical-policy replay disposition for persisted assumed-delivered evidence, future command allowance including automatic resume, meal progress modal resolution when runtime consumes a pending meal attribution without original-pod pump confirmation, fallback-merge cleanup of matching pending meal-progress state, legacy hold nonblocking meal availability, and meal availability blocking/mapping (TV-PUMP-009, TV-STATE-004, TV-STATE-005).
- testLoopRuntimeEngineResetAlgorithmSessionKeepsClinicalSettings also confirms session reset clears runtime carry-over while preserving unrelated clinical settings; pending meal-request fields are included in that cleared runtime state (TV-MEAL-009 supporting coverage).
- testDoWorkFeedsBackRequestedAndDeliveredWhenBelowDashMinimumQuantum verifies delivery reconciliation preserves requested-vs-delivered values across steps when request is below DASH minimum deliverable quantum (TV-PUMP-003).
- testLoopRuntimeWorkExecutorRecordsLatestReadingBeforeOperation, testLoopRuntimeWorkExecutorSkipsRecordReadingWhenNoLatestReading, and testLoopRuntimeWorkExecutorReturnsOperationResultWithoutMutation verify behavior-preserving extraction for doWork execution snapshot sequencing.
- testPumpBasalScheduleRejectsEntriesMissingMidnightAnchor, testPumpBasalScheduleRejectsNonIncreasingEntries, testPumpBasalScheduleReturnsCurrentRateForOffset, testPumpServiceAdapterMapsOmniBasalScheduleToCoreSchedule, and testPumpServiceAdapterMapsCoreBasalScheduleToOmniSchedule verify the new domain-level programmed basal-schedule seam used for masked offline-fallback feasibility work: schedule validation at the core boundary, rate lookup behavior for a 24-hour repeating schedule, and adapter conversion between core PumpBasalSchedule and OmniBLE basal schedule persistence formats (TV-PUMP-004 supporting feasibility coverage).
- testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementDuringActiveTempBasal, testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementDuringActiveBolus, and testPumpServiceAdapterBlocksProgrammedBasalScheduleReplacementWhenBasalStateIsUnknown verify that disruptive programmed-schedule replacement is rejected while a temp basal mask or bolus is active and also when basal-delivery state is unknown, so masked fallback arming/disarming cannot silently cancel active delivery or proceed without a confirmed steady-basal boundary (TV-PUMP-004 supporting feasibility coverage).
- testPumpServiceAdapterAllowsMaskedFallbackMaintenanceDuringZeroTempBasalMask, testPumpServiceAdapterBlocksMaskedFallbackMaintenanceDuringNonzeroTempBasal, testPumpServiceAdapterBlocksMaskedFallbackMaintenanceWhenBasalStateIsUnknown, testPumpServiceAdapterMapsLateMaskedFallbackBlockedReasonFromPumpManagerCommunicationError, testPumpServiceAdapterMapsPostScheduleMaskBlockedErrorToRemaskFailure, and testPumpServiceAdapterMapsPostSchedulePumpBlockToRemaskFailure verify that the dedicated masked-fallback maintenance/disarm seam allows the expected connected zero-mask steady state while still blocking disruptive schedule replacement during unsafe or unknown pump-delivery conditions, normalizing late bolus-blocked renewal errors into deferred maintenance, and classifying post-schedule mask blocking/failure as recovery-required remask failure rather than a clean first-arm block (TV-PUMP-007, TV-PUMP-008).
- testMaskedFallbackMaintenanceSkipsWithoutActiveAlgorithmSession, testMaskedFallbackMaintenanceArmsFallbackImmediatelyForNewSession, testMaskedFallbackMaintenanceProgramsFourBucketSafetyNominalScheduleWhenAvailable, testPrePumpCommandMaintenanceReceivesStepZeroFallbackCandidateBeforeBolus, testPrePumpCommandMaintenanceBlockReasonSuppressesPumpCommand, testPrePumpCommandFallbackArmCleanBlockAllowsPumpCommand, testPrePumpCommandFallbackArmRemaskFailureBlocksPumpCommandForRecovery, testPrePumpCommandFallbackArmSkipsWhenPumpStatusUnavailable, testPostExecutionFallbackMaintenanceSkipsSameCycleAfterPreCommandAttempt, testPostExecutionFallbackMaintenanceSkipsUnavailablePumpStatus, testPostExecutionFallbackMaintenanceRunsForAvailableStepWithoutPreCommandAttempt, testPreExecutionMaskedFallbackMaintenanceArmsMissingFallbackBeforeNextStep, testPreExecutionMaskedFallbackMaintenanceDefersArmWhenFreshPumpStatusUnavailable, testMaskedFallbackArmBlockedLeavesFallbackUnarmedAndEmitsArmFailure, testMaskedFallbackMaintenanceDoesNotRenewMaskBeforeEnteringTwentyMinuteWindow, testPreExecutionMaskedFallbackMaintenanceRenewsMaskWithinTwentyMinuteWindow, testPreExecutionMaskedFallbackMaintenanceDefersExistingRenewalWhenFreshPumpStatusUnavailable, testPostExecutionMaskedFallbackMaintenanceDoesNotRenewExistingMaskedFallbackWithinWindow, testPreExecutionMaskedFallbackMaintenanceDefersRefreshWhenScheduleWriteIsBlockedAndMaskStillActive, testPreExecutionMaskedFallbackScheduleRefreshRemaskFailureRequiresImmediateReconciliation, and testPreExecutionMaskedFallbackMaintenanceRecordsFailureWhenMaskRenewalIsUnacknowledged verify active-session gating, immediate programming when no fallback is currently armed, four six-hour fallback schedule programming from the secondary/safety q5 nominal profile, same-step arm-before-bolus behavior when step 0 or another current step first produces the fallback candidate, skipped pre-command maintenance when pump status is unavailable/unknown, fresh idle pump-status gating before pre-execution arm/renew/refresh maintenance, clean blocked first-arm behavior that leaves fallback unarmed while allowing the normal step command, same-cycle post-execution retry suppression after a pre-command fallback event, remask-failure behavior that enters reconciliation-required recovery and blocks the normal step command, pre-step arm-before-bolus behavior when a valid candidate already exists, explicit unarmed failure when the first arm is blocked, the 20-minute renewal window, pre-step renewal before the next loop execution, suppression of redundant post-step renewal for an already-masked fallback, deferred schedule refresh when a late blocked maintenance race occurs while the current mask is still active, and recovery-required handling for existing masked-fallback renewal or schedule-refresh remask failures (TV-RUN-008, TV-PUMP-007, TV-STATE-004, TV-LOG-009).
- testLoopRuntimeEngineResetAlgorithmSessionPreservesMaskedFallbackRecoveryContextWhenRestoreFails, testLoopRuntimeEngineArmAlgorithmBlockedWhenMaskedFallbackRestoreIsPending, testLoopRuntimeEnginePumpReconnectRecoveryAfterResetRestoresFallbackButKeepsLoopOff, testLoopRuntimeEngineStartResolvesPendingMaskedFallbackRecoveryByPreservingExistingSession, testLoopRuntimeEnginePumpReconnectRecoveryResumesExistingSessionEvenWhenLatestCGMReceiptIsFresh, and testLoopRuntimeEnginePumpReconnectRecoveryMarksConfirmedFallbackExposureWhenSnapshotMatchesFallbackSchedule verify failed restore recovery is preserved across reset, reconnect recovery honors explicit reset/loop-off intent instead of auto-rearming, delayed restore completion drives the persisted recovery timestamp/exposure window, successful reconnect preserves the existing session/cadence anchor, and confirmed/corrected basal-only recovery creates pending pump-delta reconciliation state plus modeled-vs-pump-reported exposure detail needed for missed-step algorithm replay (TV-PUMP-008, TV-STATE-004, TV-LOG-009).
- testPreExecutionMaskedFallbackMaintenanceDefersRenewalWhenBolusBlocksMaskAndMaskStillActive, testMaskedFallbackMaintenanceEmitsMaskExpiredWithoutRemaskingOnNoStepWake, testLoopRuntimeEngineArmAlgorithmBlockedWhenMaskedFallbackReconciliationIsPending, and testLoopRuntimeEngineTriggerDoWorkPublishesBlockedResultWhenMaskedFallbackReconciliationIsPending verify that blocked renewal is treated as deferred while the current mask is still active, true mask expiry records reconciliation-required recovery state without immediate remasking, a new session cannot arm while that recovery is pending, and ordinary loop doWork is suppressed until recovery resolves (TV-RUN-008, TV-PUMP-007, TV-STATE-004, TV-LOG-009).
- testLoopRuntimeEngineManualBGRunBlockedWhenMaskedFallbackReconciliationIsPending, testMealAnnouncementAvailabilityBlocksMaskedFallbackReconciliationAcrossRelaunch, and testMealAnnouncementPresentationFallbackReconciliationRequired verify that the same offline-expiry recovery state blocks manual BG execution and meal announce while surfacing reconnect/recovery-required guidance through user-facing availability messaging (TV-BG-011, TV-MEAL-006, TV-STATE-004, TV-UI-002).
- testMaskedFallbackDisarmRestoresOriginalScheduleAndEmitsDisarmedEvent and testMaskedFallbackDisarmFailsWithoutActivePumpService verify reset/disarm restore behavior produces explicit success/failure review events instead of silently dropping the underlying programmed basal schedule state (TV-PUMP-008, TV-LOG-009).
- testReconnectRecoveryAssumesModeledFallbackDeliveryForRetiredPodWithoutPumpEvidence, testFallbackReplayPlanDecisionAllowsAssumedDeliveredRetiredPodRecovery, and testLoopRuntimeEnginePumpReconnectRecoveryAssumesFallbackDeliveredWhenRetiredPodCannotRestore verify that an inactive/retired or service-stopped old pod can resolve masked-fallback recovery by recording modeled fallback exposure as assumed_delivered_per_clinical_policy, queueing bounded no-command replay, clearing the recovery state, and preserving the existing algorithm session (TV-PUMP-008, TV-STATE-004, TV-LOG-009).
- Q5NominalBasalProfileTests and LoopRuntimeCoordinatorNominalBasalProfileTests verify q5 nominal-basal profile imputation after the first observation, local-time slot indexing, seven-observation slot history, four six-hour bucket generation, and separate primary versus secondary/safety profile persistence from algorithm telemetry (TV-STATE-004, TV-PUMP-007).
- FallbackBasalExposureReconcilerTests, FallbackBasalReplayPlannerTests, and LoopRuntimeCoordinatorFallbackReplayTests verify the core-owned basal-only reconnect evidence classification, replay-plan/pump-delta math (including scaling to pump-reported delivered insulin), coordinator replay of fallback-active missed primary/secondary algorithm steps in the bounded replay range with CGM=-1, per-step delivered insulin, explicit 0 U inputs for fallback-active missed steps without pump allocation, exclusion of pre-activation disconnected missed slots from replay, single-use cleanup of invalid/not-required/stale pending replay plans, and suppression of catch-up pump commands or duplicate aggregate live-step delivery (TV-PUMP-008, TV-STATE-004). The reconnect recovery suite now additionally verifies that reconnect schedule mismatch upgrades to a corrected reconciled result only when reconnect evidence is credible (fresh connected delivery baseline, delivery measurement that spans the outage, monotonic pod total, and close agreement between modeled and pump-reported delivered insulin), that stale or weak delivery evidence remains unreconciled, that missing pump-reported delivered-insulin delta prevents reconciliation except for the explicit retired/no-active-pod assumed-delivered policy path, that same-pod issued-dose evidence is subtracted from raw pod-total delta before fallback residual replay only when the pending dose is fully covered by the fallback baseline-to-recovery pump-total measurement window, that pre-baseline issued-dose timing remains unreconciled/no-replay, that lower pump-reported residuals after issued-dose subtraction are replayed as corrected fallback evidence while over-modeled residuals remain ambiguous, that historical CGM samples are not required for pump-delta reconciliation, that modeled fallback exposure integrates persisted multi-entry fallback schedules across bucket boundaries, and that reconnect diagnostics always log the persisted fallback schedule, the cached programmed schedule from manager state, the original programmed schedule, and the cached schedule source for later CloudWatch review.
- testDoWorkDoesNotTrustCachedIdlePumpStatusWhenRefreshFails verifies that a stale cached idle pump status cannot allow recommendation or command application when a fresh status refresh fails, reinforcing that runtime pump availability is determined by the current refresh result rather than UI/cache state (TV-PUMP-001, TV-RUN-008 supporting coverage).
- testLoopSessionStorePersistsAlgorithmArmedAndRuntimeState and testLoopSessionStoreClearRuntimeStateReturnsEmptyState verify session persistence boundaries.
- testLoopWorkSchedulerOnlyTriggersForNewTimestampWhileArmed verifies CGM timestamp dedupe/arm/reset behavior.
- testLoopAlertMediatorReportsSignalLossUntilKnownRefresh and testLoopAlertMediatorKeepsSignalLossForUnknownRefresh verify signal-loss policy mediation behavior.
- testRecordDoWorkResultStoresSecondaryAlgorithmTelemetry, testUserDefaultsLoopRuntimeStateStorePersistsLatestFallbackBasalEvent, testResetSessionClearsTelemetry, testCloudTelemetryReporterSendsStructuredFallbackEventPayload, testLoopTelemetryStoreEmitsFallbackCloudTelemetryForNewAndChangedEventsOnly, testRecentDoseTimelineIncludesPersistedFallbackEventsAheadOfOlderSteps, testRecentDoseTimelineFallbackMetadataIncludesSourceTargetDurationAndStatus, testRecentDoseTimelineFallbackScheduleUpdateTextIncludesRateMaskAndNextRefresh, testRecentDoseTimelineFallbackUnchangedScheduleTextIncludesRetainedRateMaskAndNextRefresh, testRecentDoseTimelineFallbackReconnectRecoveryTextIncludesExposureAndUnreconciledResume, testRecentDoseTimelineFallbackReconnectRecoveryTextKeepsLoopOffAfterExplicitReset, testRecentDoseTimelineFallbackReconnectRecoveryTextIncludesReplayDetails, testRecentDoseTimelineStepSummariesIncludePrimaryAndSecondaryAlgorithmDetails, testRecentDoseTimelineFallbackFailureTextIncludesKindAndReason, and testRecentDoseTimelineFallbackRestoreTitlesCoverDisarmLifecycle verify that fallback-basal review events can be persisted through runtime/user-default state, mirrored into the shared telemetry store/cloud emitter, cleared on session reset, and rendered in Home Recent Dose Steps with source, target, duration, schedule-refresh update/unchanged detail, maintenance-deferred status, restore/remask failure detail, modeled-vs-pump-reported recovery detail, pump-delta reconciliation detail when confirmed/corrected recovery occurs, disarm lifecycle wording, per-step primary/secondary algorithm summaries, and fallback profile/schedule cloud payload fields during offline-fallback feasibility work (TV-LOG-009).
- testCSVExportIncludesAlgorithmInputOutputHeadersAndRowValues verifies the local step CSV export keeps stable schema and persisted algorithm input/output snapshots; masked-fallback reconnect recovery is now covered by coordinator, CSV, and runtime cloud emission tests that assert fallback-active missed-step algorithm replay rows are emitted from credible pump delta with CGM=-1, per-step delivered-insulin input, replay evidence source/disposition/failure-reason columns, including explicit 0 U algorithm inputs when no pump allocation belongs to a replayed fallback-active step and no synthetic replay rows for pre-activation disconnected gaps (TV-LOG-002, TV-LOG-009 subsets).
Current implemented clock-sync telemetry safety coverage:
- testDeviceClockSyncMonitorFlagsSkewAndPublishesWarningAtThresholdBreach verifies midpoint skew calculation and warning emission when absolute skew exceeds 600 seconds (TV-UI-008, TV-LOG-006 subset).
- testDeviceClockSyncMonitorWithinThresholdReportsOKWithoutWarning verifies <=600s skew reports ok and does not emit warning alerts (TV-UI-008 subset).
- testDeviceClockSyncMonitorForegroundCheckUses24HourSuccessfulCheckGate verifies foreground checks are gated by 24-hour successful-check interval (TV-LOG-006 subset).
- testDeviceClockSyncMonitorTimezoneChangeForcesFreshCheckInsideForegroundGate verifies timezone/time-change trigger bypasses the foreground gate and performs a fresh UTC check (TV-LOG-006, TV-UI-008 subset).
- testDeviceClockSyncMonitorRetriesAndReturnsUnavailableWithoutWarningOnNetworkFailures and testDeviceClockSyncMonitorLimitsSkewWarningsToOncePer24Hours verify retry/unavailable behavior and warning cooldown control (TV-UI-008 subset).
Current implemented CGM UI stale-display safety coverage:
- testG7ViewModelMasksStaleReadingAndHidesTrendWhenTimestampOlderThanElevenMinutes verifies stale CGM masking to -- and hidden trend arrow when reading age exceeds 11 minutes (TV-UI-007).
- testG7ViewModelMasksUnreliableCurrentReadingAndDoesNotFallbackToHistoryValue verifies unreliable current CGM readings are masked to --, trend is hidden, and UI does not fallback-display historical value while current state is unreliable (TV-UI-007).
- testG7ViewModelMasksUnreliableCurrentReadingWithoutTimestampAndDoesNotFallback verifies unreliable current reading masking remains enforced when latestReadingTimestamp is missing (restore/partial-state edge), preventing fallback numeric display (TV-UI-007).
- testG7ViewModelMasksStalePersistedHistoryWhenNoLiveReadingExists verifies stale persisted-history fallback is also masked to -- (TV-UI-007).
- testG7ViewModelUsesFreshPersistedHistoryWhenLatestReadingIsUnavailable verifies non-stale persisted-history fallback still displays glucose value (control case for TV-UI-007 boundary behavior).
- testG7ViewModelDisplayFormattingMapsExtremeValuesToHighLow verifies boundary formatting (<=39 -> LOW, >=401 -> HIGH) and unit-label suppression semantics for boundary text (TV-UI-009).
- testInlineCGMChartDerivationDynamicYAxisMaximumAndValues verifies stepped CGM y-axis scaling behavior (300/350/400) and corresponding tick derivation (TV-UI-010).
Current implemented Algo2015 verification coverage:
- Algo2015BridgeContractTests methods cover initial bridge contract behavior for null-guard paths, state-reset edge handling (stateData == nil && timeStep > 0), subject-id nil/long boundary handling, and state handoff continuity (TV-ALG-001, TV-ALG-002, TV-ALG-003 baseline subset).
- Algo2015GoldenVectorTests.testNominalCGMSequenceMatchesGoldenOutputs locks a deterministic nominal replay vector for drift detection (TV-ALG-004 baseline subset).
- Algo2015GoldenVectorTests.testUnavailableCGMSequenceProducesFiniteDeterministicOutputs adds degraded/unavailable-CGM replay coverage (TV-ALG-005 baseline subset).
- Algo2015GoldenVectorTests.testMealAndManualBGInputsProduceDeterministicMealPathSignals adds meal/manual-BG intervention replay coverage (TV-ALG-006 baseline subset).
- Algo2015GoldenVectorTests.testPersistedStateReloadMatchesContinuousExecution and Algo2015GoldenVectorTests.testResetToFreshStateProducesDeterministicStepZeroOutput add persistence/reload/reset continuity verification (TV-ALG-007).
- Algo2015GoldenVectorTests.testCGMBoundaryValuesRemainFiniteAndBounded adds CGM boundary/sentinel replay coverage (TV-ALG-008 baseline subset).
- Algo2015GoldenVectorTests.testHigherTargetProducesLessInsulinForSameHyperglycemicSequence adds differential target-behavior verification (TV-ALG-009 baseline subset).
- Algo2015OracleSupport now provides a reusable oracle framework for deterministic replay, snapshot assertions, and continuity checks across Algo2015 test suites (TV-ALG-004, TV-ALG-005, TV-ALG-006, TV-ALG-007, TV-ALG-008).
- Algo2015MetamorphicTests adds property/metamorphic checks for deterministic replay identity and monotonic sensitivity to target/CGM transforms (TV-ALG-004, TV-ALG-009 supporting evidence).
- Algo2015DifferentialReplayTests adds staged differential replay with JSON report output (differential-report.json) and now asserts all pregnancy parameters are consumed (targetMgDL, mealUpfrontPercent, tmaxMinutes) with deterministic checks for target monotonicity, applied meal-upfront profile, and TMAX-driven output variation (TV-ALG-009).
- Algo2015DifferentialReplayTests.testPregnancyDifferentialReplayProducesDeterministicReport now additionally asserts that 90% upfront meal profile front-loads more meal insulin than 75% at meal step and in immediate post-meal cumulative window (TV-ALG-009).
- Evidence artifact path: Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-001-004/.
- Additional evidence artifact path: Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-005-006-008/.
- Continuity evidence artifact path: Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-007/.
- Scripts/run_algo2015_coverage.sh now generates llvm-profdata/llvm-cov artifacts for Algo2015/Algorithm_2015_10_13.cpp and bridge sources (TV-ALG-010 baseline subset), with focused branch-closure scenarios for Adapt_MB_Rs, Meal_Bolus, Highs_Lows, Set_Target, SaveData, Trim_Arrays, Pumps_CGM_UI_Fields, Extract_CGM_Adapt, and MB history save/load loops.
- Coverage script now supports explicit exception-package signoff metadata (reviewerName, reviewerRole, decisionDate, decisionStatus, decisionNotes) via CLI flags or environment variables for formal STR runs.
- Coverage packaging now includes hardened branch exception artifacts:
- branch-exception-package.md with reviewer sign-off section
- branch-exception-package.json with machine-readable sign-off fields and per-symbol rationale/safety/mitigation/disposition records
- Scripts/run_algo2015_verification.sh provides staged deterministic orchestration (prepare, coverage, run, evaluate, package, all) with immutable run context + manifest packaging for STR reproducibility.
- InputFields automated suite (TV-ALG-001, TV-ALG-002, TV-ALG-003, TV-ALG-008, TV-ALG-009 subset) now runs as part of staged execution and emits structured assertions (results.json) plus observations (inputfields-observations.tsv).
- CoreReqs requirement-tagged suite now runs as part of staged execution and maps assertion outcomes directly to SRS-ALG-001...005 with structured results (suites/core-reqs/results.json).
- Differential requirement-tagged suite now runs as part of staged execution and emits structured assertions + JSON report (suites/differential/results.json, suites/differential/differential-report.json).
- ToolVerification boundary-transfer suite now runs as part of staged execution and verifies bridge-to-core parity for deterministic boundary cases (suites/tool-verification/results.json).
- StaticAnalysis suite now runs as part of staged execution and verifies clang build/analyze lane execution, CodeReviewLog run-SHA linkage, and MISRA-policy linkage metadata (suites/static-analysis/results.json).
- MISRA is treated as a risk-based conditional quality lane for this host-side investigational path: formal evidence must close the lane either with linked MISRA report/deviation artifacts (when applicable) or with explicit not-applicable decision rationale captured in the STR decision package.
- Package manifest includes quality-lane linkage fields (qualityLanes.codeReviewLinkage, qualityLanes.misraLinkage) for STR audit traceability.
- Submission-grade packaging outputs now include:
- str-template-check.json (required artifact completeness check)
- suite-assertion-trace-map.{json,md} (assertion-level TV-ALG-* + SRS-ALG-* mapping)
- reproducibility-recipe.md (single-command rerun + checksum verification recipe)
- Coverage artifact paths:
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-010-coverage/
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-010-coverage-clean-01/
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-011-verification-rerun/
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/
- Current coverage snapshot (2026-02-18, latest run tv-alg-012-verification-b2-b3-final):
- Algorithm_2015_10_13.cpp: function 100.00%, line 95.13%, branch 88.02%
- Algo2015Bridge.c: function 100.00%, line 100.00%, branch 100.00%
- Latest local working snapshot (2026-02-19, non-formal run):
- Algorithm_2015_10_13.cpp: function 100.00%, line 97.33%, branch 90.58%
- Algo2015Bridge.c: function 100.00%, line 100.00%, branch 100.00%
- Branch-rationale artifact path:
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/coverage/uncovered-branch-gap-map.md
- Exception package (legacy baseline): Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-010-coverage-clean-01/branch-exception-package.md
- Staged run summary artifacts:
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/evaluation-summary.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/manifest.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/inputfields/results.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/core-reqs/results.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/differential/results.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/differential/differential-report.json
- Docs/Quality/Evidence/STR-ALG-001/2026-02-18-tv-alg-012-verification-b2-b3-final/suites/tool-verification/results.json
6. Evidence
Expected evidence package per change:
- test command output (
xcodebuild,swift test) - failing/passing test IDs
- device test logs where applicable
- screenshots for UI safety behavior
- link to changed requirement and risk IDs
7. Deferred/Planned Validation
- Extended overnight cadence reliability runs.
- Real hardware fault-injection scenarios (disconnects, stale CGM, unavailable pump).
- Real hardware no-new-CGM-data interruption runs to verify threshold breach, alert timing, and clear-on-recovery behavior distinct from G7 failed/expired states.
- Planned reconnect-fallback hardware runs after policy implementation to verify
>5 minuteaccepted-CGM-receipt gating, current-due-step-only execution, and restored CGM priority after data flow resumes. Algorithm Stepping Interruptedunit/integration validation is now implemented for step-based timing, no-alert-when-disarmed behavior, and clear-on-success/disarm behavior. Remaining planned validation is real-device/background confirmation for non-CGM blocker coverage and rendered root-cause messaging under live pump/CGM conditions.
Current automated coverage for CGM interruption behavior:
- BionicLoopAlertTests.testAlgorithmSteppingInterruptionMonitoringSchedulesFutureNotificationAndRaisesAlertAtDeadline
- BionicLoopAlertTests.testAlgorithmSteppingInterruptionMonitoringClearsActiveAlertWhenSteppingResumes
- BionicLoopInfrastructureTests.testLoopRuntimeEngineArmedSessionSchedulesStepInterruptionMonitoringAndResetClearsIt
- BionicLoopInfrastructureTests.testLoopRuntimeEngineForegroundRefreshShowsStepInterruptionWhenThresholdExceededBeforeFirstStep
- BionicLoopInfrastructureTests.testLoopRuntimeEngineForegroundRefreshUsesLastSuccessfulRunDeadlineWhenAvailable
- BionicLoopInfrastructureTests.testLoopRuntimeEngineForegroundRefreshDoesNotShowStepInterruptionWhenDisarmed
- BionicLoopInfrastructureTests.testLoopRuntimeEngineForegroundRefreshDoesNotShowCGMInterruptionWhenDisarmed
- Formal usability/human-factors sessions for meal announcement and safety messaging.
8. Xcode Automated UI Testing Strategy
Purpose:
- Use XCTest UI automation as repeatable verification evidence for deterministic UI behavior and requirement conformance.
Best leverage areas: - Navigation and modal routing correctness. - Presence/enabled-state of safety-critical controls. - State-to-message rendering for known inputs. - Regression checks for setup flows and dismiss paths. - Non-hardware-dependent interaction logic (for example meal sheet presentation/cancel behavior).
Not a primary tool for: - BLE transport reliability and reconnect behavior. - Background wake cadence and overnight timing reliability. - Real pump delivery confirmation and physical device alert timing.
Execution model: - Run UI tests on Simulator with deterministic launch fixtures. - Use app launch arguments/environment to force reproducible runtime states. - Use stable accessibility identifiers for controls, labels, and state badges. - Keep one fast smoke suite as release gate; keep extended suite for nightly runs.
9. UI Automation Verification Mapping
- Automated UI evidence is acceptable for
[SRS-UI](SoftwareRequirementsSpecification.md#srs-ui)-*and portions of[SRS-MEAL](SoftwareRequirementsSpecification.md#srs-meal)-*and[SRS-ALERT](SoftwareRequirementsSpecification.md#srs-alert)-*where behavior is deterministic and fixture-driven. - Hardware-coupled requirements still require integration/system evidence from real-device runs.
- Preferred command:
xcodebuild -scheme BionicLoop -destination 'platform=iOS Simulator,name=iPhone 17' -only-testing:BionicLoopUITests test- Evidence artifacts:
- test logs, pass/fail results, captured screenshots/attachments, and linked
TV-*IDs inRTM.
Current Automated UI Suite Mapping (F5)
| XCTest Method | TV-ID Link | Requirement Link | Notes |
|---|---|---|---|
testUI001_HomeShowsPrimaryControls |
TV-UI-005 | SRS-UI-002 | Smoke check for Home control availability using deterministic fixtures. |
testUI002_MealUnavailableWhenLoopOff |
TV-UI-002 | SRS-UI-002 | Verifies unavailable-state messaging path and dismissal UX. |
testUI003_SettingsSheetCanDismiss |
TV-UI-006 | SRS-UI-002 | Guards against modal navigation traps in settings entry path. |
testUI004_ManualBGSheetCanOpenAndCancel |
TV-UI-006 | SRS-BG-001 | Verifies explicit cancel path for manual BG entry UX. |
testUI005_HomeShowsAlertBannerPreview |
TV-ALERT-002 | SRS-ALERT-003 | Verifies deterministic top-alert preview rendering on Home. |
testUI006_HomeShowsCriticalAlertPreview |
TV-ALERT-002 | SRS-ALERT-003 | Verifies critical alert preview path and title rendering. |
testUI007_HomeAlertCenterButtonOpensAlertCenter |
TV-ALERT-007 | SRS-ALERT-008 | Verifies Home alert-center bell entry and active-alert visibility in Alert Center. |
testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared |
TV-ALERT-007 | SRS-ALERT-005, SRS-ALERT-008 | Verifies acknowledge transition from active alert state to recently-cleared timeline. |
testUI009_AlertCenterPersistsAcrossRelaunch |
TV-ALERT-008 | SRS-ALERT-009 | Verifies persisted active alert visibility after relaunch (UI_TEST_PRESERVE_DEFAULTS). |
testUI010_ClinicalSettingsNavigatesAndKeepsUnlockUntilManualLock |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies clinical unlock success, local unlock persistence across Clinical Settings navigation within the unlock duration, and manual lock. |
testUI011_ClinicalSettingsSaveDismissesSettingsSheet |
TV-CLIN-009 | SRS-CLIN-007, SRS-CLIN-008 | Verifies Save+OK closes settings flow after review-confirmation path. |
testUI012_ClinicalSettingsInvalidCodeBlocksUnlock |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies invalid unlock-code path shows explicit error and keeps clinician controls hidden. |
testUI013c_ClinicalUnlockAcceptsGroupedDigitsAndRejectsRepeatedCode |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies grouped/pasted-style numeric input is normalized and that a locally burned counter cannot be reused on the same device. |
testUI013d_ClinicalUnlockUsesOfflineProvisionedVerifierMaterial |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies Clinical Settings unlock is satisfied by locally provisioned verifier material and does not depend on an online verification call. |
testUI013_ClinicalControlsVisibleOnlyInsideUnlockedClinicalSettings |
TV-CLIN-002 | SRS-CLIN-003 | Verifies relocated Start/Reset controls are absent in general settings and present only in unlocked Clinical Settings. |
testUI014_RegularTargetChangeRequiresApprovalCaptureAndPersists |
TV-CLIN-011, TV-CLIN-013 | SRS-CLIN-011, SRS-CLIN-007 | Verifies regular-settings target changes block until approval fields are completed, then persist into clinician-visible applied target state. |
testUI015_ClinicalTargetPickerFollowsSelectedProfileRange |
TV-CLIN-010 | SRS-CLIN-009, SRS-CLIN-010 | Verifies the clinician target picker only exposes the targets enabled by the selected Pregnancy/Standard profile. |
testUI016_ClinicalProfileChangeNormalizesTargetAndPersists |
TV-CLIN-012, TV-CLIN-013 | SRS-CLIN-012, SRS-CLIN-009, SRS-CLIN-010 | Verifies changing the clinician-selected profile snaps an inherited out-of-range draft target to the nearest allowed value and persists the normalized result. |
Evidence reference: - STR-UI-AUTO-001 / 2026-02-12-f5-ui-smoke
Current Clinical Unit Mapping (K1/K2 baseline)
| XCTest Method | TV-ID Link | Requirement Link | Notes |
|---|---|---|---|
ClinicalUnlockVerifierTests |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies the backend contract HMAC vectors, ASCII/grouped-code normalization, non-ASCII digit rejection, wrong-subject rejection, same/lower counter rejection, lookahead rejection, and unsupported-version rejection. |
BionicLoopClinicalUnlockRuntimeTests |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies app-side secure-state semantics: verifier material installation, subject/material mismatch rejection, material refresh preserving accepted counter while clearing active unlock/lockout state, accepted counter persisted before success returns, repeated code rejected after burn, missing verifier material blocks unlock, failed attempts lock out temporarily, unlock expiration enforced locally, and manual-lock storage failure surfaced without falsely closing clinician controls. |
testClinicalSettingsPolicyNormalizationAndDefaults |
TV-CLIN-003, TV-CLIN-004, TV-CLIN-005 | SRS-CLIN-004, SRS-CLIN-005, SRS-CLIN-006 | Verifies allowed-option enforcement and deterministic fallback defaults for target/upfront/TMAX selectors. |
testClinicalSettingsSavePolicyPrepareSaveReviewBlockedStates |
TV-CLIN-001 | SRS-CLIN-001, SRS-CLIN-002 | Verifies locked/invalid/no-change save attempts are blocked with deterministic reasons/messages. |
testClinicalSettingsSavePolicyPrepareSaveReviewBuildsChangedFieldList |
TV-CLIN-009 | SRS-CLIN-007 | Verifies review model includes complete changed-field set for old/new clinical config diff. |
testClinicalSettingsSavePolicySaveApplySemantics |
TV-CLIN-009 | SRS-CLIN-007, SRS-CLIN-008, SRS-LOG-001 | Verifies no persisted change before save confirmation, cancel preserves applied config, and saved config appears in next-step telemetry snapshot fields. |
testClinicalSettingsSavePolicyUICriticalEvents |
TV-LOG-005 | SRS-LOG-005 | Verifies deterministic ui.critical event mapping and detail payload for state_viewed/submit/cancel/blocked paths. |
testClinicalSettingsPolicyTargetRangeProfiles |
TV-CLIN-010, TV-CLIN-012 | SRS-CLIN-009, SRS-CLIN-010, SRS-CLIN-012 | Verifies Pregnancy/Standard profile subsets and nearest-allowed normalization behavior when the active profile changes. |
testRegularTargetChangeApprovalPolicyPrepareAndValidate |
TV-CLIN-011 | SRS-CLIN-011 | Verifies participant target changes require approver name and approval timestamp before apply. |
testRegularTargetChangeApprovalPolicyBlocksNoChangeAndOutOfProfileSelection |
TV-CLIN-010, TV-CLIN-011 | SRS-CLIN-010, SRS-CLIN-011 | Verifies participant target-change flow rejects no-op requests and targets outside the clinician-selected profile. |
testRegularTargetChangeApprovalTelemetryEvents |
TV-LOG-008 | SRS-LOG-008 | Verifies participant approval-capture telemetry includes target profile, requested/current target, approver name, and approval timestamp. |
Current regression command used in development for this slice:
- xcodebuild -scheme BionicLoop -project BionicLoop.xcodeproj -destination 'platform=iOS Simulator,name=iPhone 17' -only-testing:BionicLoopTests test
UI execution note for this slice:
- BionicLoopUITests are wired into the current scheme and targeted UI cases can be launched with xcodebuild ... -only-testing:BionicLoopUITests/... test.
- Focused UI verification for testUI014_RegularTargetChangeRequiresApprovalCaptureAndPersists, testUI015_ClinicalTargetPickerFollowsSelectedProfileRange, and testUI016_ClinicalProfileChangeNormalizesTargetAndPersists passed on 2026-03-25 against simulator device 21A8EB79-294B-4DB2-8AB5-9166F5B375A8 (Test-BionicLoop-2026.03.25_11-55-08--0400.xcresult).
- Local simulator/xctrunner instability may still require rerunning the focused UI lane in future environments, but this slice now has a captured green UI pass.
10. Manual Screenshot UI Review Protocol
Scope: - Required for all user-facing changes, especially safety-state messaging, alert presentation, and clinical controls.
Capture set: - Light mode and dark mode screenshots. - Changed screen in: baseline state, interactive state, blocked/error state, and post-action state. - If applicable, include one large-text (Dynamic Type) capture for key screens.
Review rubric: - Typography and text integrity: - no clipping, truncation, overlap, or ambiguous wording. - units/values formatting is consistent (mg/dL, U, %, min, timestamps). - Spacing and alignment: - consistent spacing rhythm and card/control alignment. - safe-area compliance; no accidental edge clipping. - Visual hierarchy: - critical safety states and primary actions are immediately distinguishable. - secondary text does not compete with critical signals. - Accessibility and contrast: - sufficient contrast in both themes. - color is supplemented by text/icon/position cues. - tappable controls remain legible and touch-accessible. - Motion and transitions: - state transitions are smooth and non-jarring. - no stale labels/icons during animated or async state changes.
Evidence and traceability:
- Save screenshots and review notes under the applicable STR-* evidence path.
- Link that path in:
- Docs/Quality/TraceabilityMatrix.md
- Docs/Quality/CodeReviewLog.md entry for the commit
- any related bug entry in Docs/Quality/Bugs/BugTracker.md.