Requirements Traceability Matrix (RTM)
Status: Submission-candidate trace matrix (formal evidence promotion and freeze metadata pending) Version: 1.28 Owner: BionicLoop engineering Prepared by: BionicLoop engineering Reviewer: ____ Approver: ____ Decision date: ____ Effective date: ____ Baseline freeze SHA: ____ Last updated: 2026-06-23
Revision History
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 0.1 | 2026-04-05 | Engineering | Initial controlled RTM draft |
| 0.9 | 2026-04-06 | BionicLoop engineering | Added handoff-ready metadata and refined RA-009 cybersecurity trace mapping for the software-only handoff package |
| 0.91 | 2026-04-07 | BionicLoop engineering | Narrowed RA-009 to the current local-security claim set, aligned RA-013 and RA-015 evidence notes with the implemented baseline, and changed high-risk freeze blockers to Rerun needed status |
| 0.92 | 2026-04-08 | BionicLoop engineering | Added masked offline-fallback maintenance/disarm trace links for the active feasibility branch |
| 0.93 | 2026-04-08 | BionicLoop engineering | Clarified masked-fallback renewal-window, deferred-maintenance, and restore-context trace links for the active feasibility branch |
| 0.94 | 2026-04-14 | BionicLoop engineering | Added trace notes for reconciliation-required blocked state after offline mask expiry |
| 0.95 | 2026-04-14 | BionicLoop engineering | Added trace notes for reconnect restore/disarm retry and explicit fresh re-arm after successful masked-fallback recovery |
| 0.96 | 2026-04-14 | BionicLoop engineering | Updated reconnect recovery trace notes for fresh-session auto-arm and preserved fallback review history after successful masked-fallback recovery |
| 0.97 | 2026-04-14 | BionicLoop engineering | Tightened reconnect recovery trace notes so explicit reset/loop-off keeps the loop off after restore and recovery timing reflects restore completion |
| 0.98 | 2026-04-14 | BionicLoop engineering | Updated reconnect recovery trace notes to show same-session unreconciled resume on the current due slot after successful masked-fallback restore |
| 0.99 | 2026-04-15 | BionicLoop engineering | Added trace notes for modeled-vs-pump-reported fallback review, pod total-delivery baseline persistence, and pre-step missing-fallback arm behavior |
| 1.00 | 2026-04-15 | BionicLoop engineering | Added trace notes for confirmed/corrected same-session basal-only replay, persisted replay-plan state, and replay-detail Recent Dose Steps coverage |
| 1.01 | 2026-04-15 | BionicLoop engineering | Added trace notes for dedicated loop.fallback.event cloud telemetry emission and fallback-event payload verification for BionicScout contract support |
| 1.02 | 2026-04-15 | BionicLoop engineering | Added trace notes for replayed-step propagation into local per-step telemetry / CSV export with explicit replay markers |
| 1.03 | 2026-04-27 | BionicLoop engineering | Added trace notes that fallback replay requires pump-reported delivered-insulin delta and does not substitute modeled expected delivery when pump reconciliation is unavailable |
| 1.04 | 2026-05-06 | BionicLoop engineering | Added trace notes for safety q5 nominal-basal profile persistence, four-bucket fallback schedule programming, schedule-aware exposure modeling, and fallback profile/schedule cloud telemetry |
| 1.05 | 2026-06-02 | BionicLoop engineering | Updated trace notes for pump-delta fallback missed-step algorithm replay and repeated no-active-pod critical alert verification |
| 1.06 | 2026-06-06 | BionicLoop engineering | Added trace notes for same-pod continuity replay gating, different/new pod no-replay continuation, pod-continuity telemetry, and explicit-operator-only session lifecycle |
| 1.07 | 2026-06-08 | BionicLoop engineering | Added trace notes for persisted-schedule-weighted pump-delta replay allocation and zero-weight replay suppression |
| 1.08 | 2026-06-10 | BionicLoop engineering | Added trace notes for current-step masked-fallback first-arm ordering before same-step pump command application |
| 1.09 | 2026-06-11 | BionicLoop engineering | Clarified that confirmed/corrected fallback replay is bounded to fallback-active missed slots and excludes pre-activation disconnected gaps |
| 1.10 | 2026-06-11 | BionicLoop engineering | Added trace notes for fresh-status pre-execution fallback maintenance gating, existing-mask remask-failure recovery, pending replay-plan cleanup, and cached-idle refresh-failure regression coverage |
| 1.11 | 2026-06-12 | BionicLoop engineering | Added trace mapping for generalized issued-dose attribution and different/new-pod no-replay disposition |
| 1.12 | 2026-06-15 | BionicLoop engineering | Updated issued-dose different/new-pod trace mapping to assumed-delivered attribution, nonblocking replacement-pod dosing, and deferred adaptation-forget question |
| 1.13 | 2026-06-17 | BionicLoop engineering | Added trace notes for one-step algorithm/runtime cadence reconciliation before meal-step selection and live executed-step/request-step alignment with algorithm stepTime. |
| 1.14 | 2026-06-18 | BionicLoop engineering | Added trace notes for fallback-only replay request-step attribution and evidence-gated issued-dose attribution clearing. |
| 1.15 | 2026-06-18 | BionicLoop engineering | Clarified resolved issued-dose attribution when the dose precedes fallback-active replay: merge into the first fallback replay row rather than replaying pre-fallback disconnected slots. |
| 1.16 | 2026-06-18 | BionicLoop engineering | Added trace notes for retired/expired/no-active-pod fallback recovery using assumed modeled fallback exposure when pump-counter reconciliation evidence is unrecoverable. |
| 1.17 | 2026-06-23 | BionicLoop engineering | Added provisional pod-simulation scaffold trace note and TV-SIM-POD-* working coverage expectations. |
| 1.18 | 2026-06-23 | BionicLoop engineering | Added first pod-simulation scenario slice for shared-invariant same-pod live attribution, replacement-pod assumed delivery, and schedule-weighted fallback replay coverage. |
| 1.19 | 2026-06-23 | BionicLoop engineering | Expanded pod-simulation trace note for canceled and consecutive-canceled meal live attribution, user-escaped unavailable-pod assumed delivery, fallback-maintenance command blocking, and relaunch fallback replay with unavailable CGM. |
| 1.20 | 2026-06-23 | BionicLoop engineering | Added explicit pod-simulation trace coverage for unresolved correction-only and basal-only assumed-delivered replacement-pod dosing. |
| 1.21 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for ambiguous fallback restore without replay or modeled-dose injection. |
| 1.22 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption. |
| 1.23 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state. |
| 1.24 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure. |
| 1.25 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row. |
| 1.26 | 2026-06-23 | BionicLoop engineering | Added trace coverage for app recent-dose persistence/display of merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units. |
| 1.27 | 2026-06-23 | BionicLoop engineering | Added trace coverage for local step CSV export of merged fallback replay evidence source, disposition, and failure-reason fields. |
| 1.28 | 2026-06-23 | BionicLoop engineering | Added trace coverage for runtime cloud step-event emission of merged fallback replay evidence source, disposition, request-step, requested-unit, and delivered-unit fields. |
This matrix links risk hazards, requirements, design elements, and verification artifacts.
Current fallback replay trace note: SRS-RUN-006, SRS-PUMP-006, SRS-PUMP-008, SRS-PUMP-009, and SRS-LOG-009 remain mapped to RA-003, RA-006, RA-008, SDD-PUMP-001, SDD-LOG-001, SDD-DATA-003, TV-RUN-008, TV-PUMP-008, TV-STATE-004, and TV-LOG-009. The active replay claim is explicitly limited to missed steps whose delivery interval overlaps confirmed or explicitly assumed fallback-active time; disconnected gaps before offline fallback activation are not replayed, while explicit 0 U rows remain allowed inside the fallback-active replay interval. Pump-counter fallback replay remains limited to credible same-pod confirmed/corrected evidence. The retired/expired/no-active-pod exception records persisted-schedule modeled exposure as assumed_delivered_per_clinical_policy only when the old pod can no longer provide connected pump-counter evidence, and UI/telemetry must preserve that assumed-vs-confirmed distinction. Fallback-only replay rows feed the replayed fallback basal amount into the replay step with the algorithm input request step set to the prior step (replayStep - 1, clamped at 0 for step 0); rows may clear pending issued-dose attribution only when they include matching resolved issued-dose evidence for the original request. If a resolved meal/correction issued dose predates the first fallback-active replay row, runtime merges the resolved issued-dose requested/delivered units into that first fallback replay row and does not create pre-fallback issued-dose-only replay rows. App recent-dose rows, local step CSV export, and runtime cloud step-event emission now preserve replay evidence source/disposition/failure-reason fields for merged fallback replay evidence. Current review-fix coverage adds fresh idle pump-status gating before pre-execution masked-fallback arm/renew/refresh maintenance, reconciliation-required recovery for existing-mask remask failures, single-use cleanup for invalid/not-required/stale pending replay plans, and a cached-idle/refresh-failure regression proving runtime does not trust stale pump state. General issued-dose attribution is tracked separately through SRS-PUMP-010, SDD-POL-029, RA-017, and TV-PUMP-009.
Issued-dose missing-identity trace note: missing pod identity remains a
no-guess/no-replay condition except for the explicit SRS-MEAL-012
user-confirmed unavailable-pod escape. That path may consume
assumed-delivered clinical-policy evidence without pod identity only when the
request step, requested units, delivered-unit bounds, and non-active pump
status match.
Current cadence trace note: SRS-RUN-002 remains mapped to RA-001, SDD-POL-001, TV-RUN-001, TV-RUN-002, and TV-SIM-001. Current working coverage adds StepCadencePolicyTests.testReconcileWithAlgorithmAdvancesRuntimeWhenAlgorithmAlreadyConsumedDueStep, LoopRuntimeCoordinatorMealExecutionTests.testMealAnnounceAlignsWithAlgorithmStepWhenRuntimeIsOneStepBehind, and LoopRuntimeCoordinatorCadenceExecutionTests.testDoWorkSkipsOrdinaryWakeAfterAlgorithmAlreadyConsumedDueStep, proving persisted runtime cadence advances to the algorithm-implied last executed step before meal-step selection or ordinary wake duplicate evaluation so live executedStep, pump request-step attribution, and algorithm input stepTime remain aligned without re-running an already consumed step.
Current pod-simulation trace note: provisional TV-SIM-POD-001..004
coverage extends STP-SIM-001 with a stateful test-only DASH pod ledger.
The scaffold currently supports working evidence for bolus progress/cancel
math, pending issued-dose restoration, fallback 0 U/hr mask expiry/renewal,
pod expiry/replacement identity transitions, production-coordinator replay from
simulated pump status, and the safety rule that meal/correction delivery
completed before a fallback baseline is not subtracted from fallback pump-total
delta. The first shared-invariant scenario slice adds canceled and
consecutive-canceled meal evidence feeding subsequent meal announcements
without replay or stale evidence reuse, same-pod completed-meal live
attribution without replay, reservoir-capped partial meal delivery feeding
actual delivered units without replay or unresolved meal-progress state,
reservoir-capped fallback replay using observed pump delta instead of modeled
exposure, meal/fallback overlap coordinator replay that partitions the pump
delta and merges the meal dose into the first fallback-active replay row,
different/new-pod and user-escaped
unavailable-pod assumed-delivered replay without blocking replacement-pod live
dosing, explicit unresolved correction-only and basal-only assumed-delivered
replay when pod identity cannot be recovered and policy allows, replacement
after an unresolved old-pod meal dose, lost final meal response before status
refresh, stale cached idle rejection when fresh refresh fails, meal/fallback
pump-delta partitioning, fallback-maintenance failure blocking the live bolus
command before pod ledger delivery, stale fallback evidence suppression while
disconnected, ambiguous fallback restore without replay or aggregate modeled
fallback-dose injection into the live step, missing-status/nonreplayable fallback
plan clearing without replay rows, assumed old-pod fallback replay with no
replay pump commands before replacement-pod live dosing, and
persisted-schedule-weighted
fallback replay allocation only after the 0 U/hr mask expires, reservoir-capped
fallback replay using observed pump delta instead of modeled exposure, relaunch
fallback replay with unavailable CGM after step 0, and force-quit/relaunch
restoration of in-flight meal delivery knowledge before the next CGM without
creating a step-0 insulin artifact. Matching pending meal-progress state is
also cleared, with correlated resolved telemetry, when issued-dose evidence is
consumed on same-pod reconnect, fallback-merge replay, or user-escaped old-pod
recovery. These rows
support RA-003, RA-004, RA-006, RA-008, and RA-017 as working
evidence only until the remaining POD-SIM-* matrix is implemented and formal
artifacts are promoted.
Matrix
| RA-ID | SRS ID | SDD ID | Verification (TV-ID) | Evidence (STR/Logs) | Status |
|---|---|---|---|---|---|
| RA-001 | SRS-RUN-001, SRS-RUN-002, SRS-RUN-003 | SDD-POL-001, SDD-APP-003 | TV-RUN-001, TV-RUN-002, TV-RUN-003, TV-SIM-001 | Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/) |
In progress |
| RA-002 | SRS-CGM-001, SRS-CGM-002, SRS-CGM-003, SRS-CGM-004 | SDD-POL-002, SDD-CGM-001 | TV-CGM-001, TV-CGM-002, TV-CGM-003, TV-CGM-004, TV-SIM-002 | Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/) |
In progress |
| RA-003 | SRS-PUMP-001, SRS-PUMP-002, SRS-PUMP-005, SRS-PUMP-006, SRS-PUMP-007, SRS-PUMP-008, SRS-PUMP-009, SRS-RUN-006, SRS-STATE-005 | SDD-POL-003, SDD-POL-028, SDD-PUMP-001, SDD-DATA-003 | TV-PUMP-001, TV-PUMP-002, TV-PUMP-005, TV-PUMP-006, TV-PUMP-007, TV-PUMP-008, TV-STATE-005, TV-RUN-008, TV-SIM-003 | Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; current branch feasibility verification: BionicLoopRuntimeEngineMaskedFallbackMaintenanceTests, BionicLoopRuntimeEngineMaskedFallbackUnacknowledgedTests, BionicLoopRuntimeEngineFallbackRecoveryInfrastructureTests, BionicLoopRuntimeEngineReconnectInfrastructureTests, BionicLoopRuntimeEngineSessionInfrastructureTests, BionicLoopRecentDoseTimelineTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopMealAnnouncementRuntimeTests, BionicLoopRuntimeEnginePrePumpCommandMaintenanceTests, Q5NominalBasalProfileTests, FallbackBasalExposureReconcilerTests, FallbackBasalReplayPlannerTests, LoopRuntimeCoordinatorFallbackReplayTests, LoopRuntimeCoordinatorPumpAvailabilityExecutionTests, LoopRuntimeCoordinatorExecutionTelemetryTests, LoopRuntimeCoordinatorPumpCommandClassificationTests, and BionicLoopRuntimeEngineReconnectEvidenceTests, including arm-before-step behavior for missing fallback state, current-step masked-fallback first-arm ordering before the same step's pump command when the first fallback candidate is produced at step 0 or another first successful step, pre-command first-arm skip when refreshed pump status is unavailable/unknown, pre-execution fresh idle status deferral for arm/renew/refresh maintenance, clean bolus/unsafe-state first-arm block behavior that does not suppress the normal command, same-cycle post-execution first-arm retry suppression after a pre-command fallback event, recovery-required remask failure behavior including post-schedule mask/pump blocking and existing-mask renewal/refresh remask failures that suppress ordinary stepping before additional pod mutation, stale cached-idle refresh-failure command blocking, secondary/safety q5 nominal profile-derived four six-hour schedule programming, deferred bolus-blocked renewal classification, offline-expiry blocking plus reconnect restore/disarm retry, retired/no-active-pod assumed modeled fallback exposure recovery, schedule-aware modeled exposure, confirmed/corrected no-command missed-step primary/secondary algorithm replay with CGM=-1 and per-step pump delivery weighted by the persisted programmed fallback schedule only when credible same-pod pump-reported delivered-insulin delta spans the outage or the retired-pod assumption rule explicitly records modeled exposure as assumed delivered, single-use cleanup for stale/invalid/not-required pending replay plans, equal-rate / six-hour-window / partial-slot / midnight-wrap replay allocation tests, positive-delta zero-weight no-replay behavior, zero-delta zero-row replay behavior, different/new pod and unknown pod identity no-replay continuation, ambiguous/unverified recovery without delivery reconciliation, and basal-only modeled-vs-pump-reported reconnect evidence) |
In progress |
| RA-004 | SRS-MEAL-001, SRS-MEAL-002, SRS-MEAL-003, SRS-MEAL-004, SRS-MEAL-005, SRS-MEAL-006 | SDD-POL-004, SDD-APP-001 | TV-MEAL-001, TV-MEAL-002, TV-MEAL-003, TV-MEAL-004, TV-MEAL-005, TV-MEAL-006, TV-MEAL-007, TV-SIM-004 | Partial (BUG-001 real-device closure evidence 2026-02-11: Docs/Quality/Evidence/STR-BUG-001/2026-02-11-relaunch-meal/; simulation: Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; current branch feasibility verification adds reconnect/recovery-required meal blocking in BionicLoopMealAnnouncementPersistenceRuntimeTests and BionicLoopMealAnnouncementRuntimeTests) |
In progress |
| RA-005 | SRS-PUMP-003, SRS-LOG-001 | SDD-PUMP-001, SDD-LOG-001 | TV-PUMP-003, TV-LOG-001 | Partial (LoopRuntimeCoordinatorPumpExecutionTests.testDoWorkFeedsBackRequestedAndDeliveredWhenBelowDashMinimumQuantum) |
In progress |
| RA-006 | SRS-STATE-001, SRS-STATE-002, SRS-STATE-003, SRS-STATE-004, SRS-STATE-005 | SDD-DATA-001, SDD-DATA-002, SDD-DATA-003, SDD-DATA-004, SDD-POL-005, SDD-POL-028, SDD-PUMP-001 | TV-STATE-001, TV-STATE-002, TV-STATE-003, TV-STATE-004, TV-STATE-005 | Partial (current branch feasibility verification includes recoverable reset/disarm restore-state coverage plus persisted offline-expiry and restore-failed reconnect-retry coverage in BionicLoopRuntimeEngineSessionInfrastructureTests, BionicLoopRuntimeEngineReconnectInfrastructureTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopRuntimeEngineMaskedFallbackMaintenanceTests, Q5NominalBasalProfileTests, LoopRuntimeCoordinatorNominalBasalProfileTests, FallbackBasalExposureReconcilerTests, BionicLoopRuntimeEngineReconnectEvidenceTests, and LoopRuntimeCoordinatorFallbackReplayTests, including persisted primary/safety q5 nominal profiles, persisted pod identity plus total-delivery baseline/timestamp, pending pump-delta reconciliation state for later reconnect comparison, confirmed/corrected missed-step algorithm replay, and different/new pod no-replay continuation without replacing the algorithm session) |
In progress |
| RA-007 | SRS-PUMP-004, SRS-PUMP-005 | SDD-PUMP-001 | TV-PUMP-004, TV-PUMP-005 | Pending | In progress |
| RA-008 | SRS-LOG-001, SRS-LOG-002, SRS-LOG-003, SRS-LOG-004, SRS-LOG-005, SRS-LOG-006, SRS-LOG-007, SRS-LOG-008, SRS-LOG-009 | SDD-LOG-001, SDD-POL-017, SDD-POL-018, SDD-POL-024, SDD-POL-025, SDD-APP-007, SDD-DATA-003 | TV-LOG-001, TV-LOG-002, TV-LOG-003, TV-LOG-004, TV-LOG-005, TV-LOG-006, TV-LOG-007, TV-LOG-008, TV-LOG-009 | Partial (implemented baseline: authenticated cloud telemetry envelope + persistent outbox with retry/permanent-failure handling + queue-cap drop policy + non-blocking upload + expanded runtime/CGM/pump/alert emitters + structured app.log.batch; envelope now carries auth_user_sub from ID-token sub with UNSET fallback. Lifecycle telemetry now includes timezone + UTC-check context (device_timezone_id, device_utc_offset_seconds, clock_check_result, optional skew/rtt/check timestamp) with launch/foreground/time-change trigger semantics. Meal announce telemetry now records deterministic submitted, accepted, success, blocked, uncertain, and resolved lifecycle transitions without optimistic-success duplication, with flow_id + target-step correlation preserved across relaunch/session-reset closure. Clinical target telemetry now captures target-range profile changes and participant approval-capture details with stable ui.critical event contracts. The active offline-fallback feasibility branch additionally records structured fallback lifecycle review events for Home Recent Dose Steps, including arm, maintenance-deferred, renew, refresh, offline-expiry, disarm, restore/remask failure detail, pod-continuity result, modeled-vs-pump-reported reconnect recovery detail, and pump-delta reconciliation detail when confirmed/corrected recovery uses no-command missed-step primary/secondary algorithm replay. The same branch now keeps local step telemetry and CSV export anchored to real algorithm executions; confirmed/corrected reconnect recovery records replay rows with CGM=-1 and persisted-schedule-weighted per-step delivered-insulin input, then resumes the live step with actual refreshed pump status and no duplicate recovered-delivery injection, with coverage in FallbackBasalReplayPlannerTests, LoopRuntimeCoordinatorFallbackReplayTests, and BionicLoopRuntimeEngineReconnectEvidenceTests. App-side cloud telemetry now also emits dedicated loop.fallback.event payloads for BionicScout contract consumption, with stable fallback_event_id, pod-continuity, modeled-vs-actual delivery summary fields, reconciliation summary fields, programmed schedule entries, safety q5 profile metadata/rates on arm/refresh events, and duplicate suppression coverage in LoopTelemetryStoreTests and BionicLoopCloudTelemetryInfrastructureTests.) |
In progress |
| RA-009 | SRS-SEC-001, SRS-SEC-002 | SDD-LOG-001, SDD-POL-015, CybersecurityPlan.md, Cybersecurity_Handoff_Register.md | TV-SEC-001 | Support: Cybersecurity_Local_File_and_Permission_Review.md, Cybersecurity_Baseline_Acceptability_Recommendation.md, Cybersecurity_Handoff_Register.md. Formal: TV-SEC-001 / STR-SEC-001 required for freeze. Current package does not claim closure of SRS-SEC-003..009. |
Deferred (partial scope) |
| RA-010 | SRS-UI-001, SRS-UI-002, SRS-UI-003, SRS-UI-004, SRS-UI-005, SRS-UI-006, SRS-UI-007, SRS-UI-008, SRS-VAL-001, SRS-BG-001 | SDD-POL-006, SDD-POL-007, SDD-POL-009, SDD-POL-014, SDD-POL-018, SDD-POL-019 | TV-UI-001, TV-UI-002, TV-UI-003, TV-UI-004, TV-UI-005, TV-UI-006, TV-UI-007, TV-UI-008, TV-UI-009, TV-UI-010 | Partial (Docs/Quality/Evidence/STR-UI-AUTO-001/2026-02-12-f5-ui-smoke/, plus BUG-001 real-device closure evidence in Docs/Quality/Evidence/STR-BUG-001/2026-02-11-relaunch-meal/; clock-sync coverage in BionicLoopInfrastructureTests.testDeviceClockSyncMonitorFlagsSkewAndPublishesWarningAtThresholdBreach, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorWithinThresholdReportsOKWithoutWarning, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorRetriesAndReturnsUnavailableWithoutWarningOnNetworkFailures, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorLimitsSkewWarningsToOncePer24Hours, boundary/axis coverage in BionicLoopInfrastructureTests.testG7ViewModelDisplayFormattingMapsExtremeValuesToHighLow and BionicLoopHomeStateTests.testInlineCGMChartDerivationDynamicYAxisMaximumAndValues) |
In progress |
| RA-011 | SRS-ALERT-001, SRS-ALERT-002, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005, SRS-ALERT-006, SRS-ALERT-007, SRS-ALERT-008, SRS-ALERT-009, SRS-ALERT-010, SRS-ALERT-011, SRS-ALERT-012, SRS-ALERT-015, SRS-ALERT-016, SRS-ALERT-017 | SDD-ALERT-001, SDD-POL-008, SDD-POL-026, SDD-DATA-005 | TV-ALERT-001, TV-ALERT-002, TV-ALERT-003, TV-ALERT-004, TV-ALERT-005, TV-ALERT-006, TV-ALERT-007, TV-ALERT-008, TV-ALERT-009, TV-ALERT-010, TV-ALERT-011, TV-ALERT-014, TV-ALERT-015, TV-ALERT-016, TV-SIM-005 | Partial (implemented: AppAlertCenter + Home alert carousel + Home bell + Settings Alert Center + signal-loss debounce/clear + pump/cgm normalized mapping + delegate persisted-alert lifecycle hooks + app-level active/recent persistence + background local notification channel for non-CGM alerts with dedupe/cooldown plus repeated no-active-pod notification attempts while the condition remains true + minute-refresh time-sensitive countdown updates; CGM availability/failure alerts remain informational in-app only and do not schedule OS notifications; app-derived ALERT-CGM-URGENT-LOW now issues only from trustworthy live G7 <55 mg/dL, preserves reviewed state while active, persists acknowledged active state across reset / reattach, and auto-clears on trustworthy recovery >=55 mg/dL; evidence: testTopAlertPrefersHigherSeverityThenMostRecent, testSortedAlertsOrdersBySeverityRecencyAndStableDedupeKey, testHomeAlertCarouselNavigatorClampsAndWrapsIndexes, testNoActivePodDebounceAddsAndClearsAlert, testNoActivePodConditionRepeatsBackgroundNotificationUntilRecovered, testHomeAlertSyncEvaluatorReflectsCombinedPumpConditions, testSignalLossDebounceAddsAndClearsAlert, testSignalLossDebounceSuppressesTransientCondition, testShowPreviewAlertsSupportsMultipleTypesAndPrecedence, testCGMAlertsNeverScheduleBackgroundNotifications, testUrgentLowAcknowledgeMarksAlertReviewedWithoutClearingActiveState, testCGMUrgentLowAcknowledgePersistsAcrossAlertCenterResetUntilRecovery, testCGMUrgentLowAlertMapperIssuesForReliableReadingBelow55, testCGMUrgentLowAlertMapperClearsAt55OrAbove, testAlertCenterTracksRecentlyClearedAlerts, testAlertCenterRestoresPersistedActiveAndClearedAlerts, testPumpPersistedAlertStoreReturnsIssuedAndRetractedAlerts, testCGMPersistedAlertStoreReturnsIssuedAndRetractedAlerts, testPumpExpirationAlertSyncPlannerReturnsRetractsWhenNoExpirationAlertsApply, testPumpAlertMapperExpiringIncludesCountdownDeadline, testTimeSensitivePumpExpiringAlertRefreshesMessageWithoutReschedulingNotification, testIssueAndRetractPumpAlertUpdatesAppAlertCenter, testIssueAndRetractIncompatiblePumpAlertUpdatesAppAlertCenter, testIssueAndRetractCGMAlertUpdatesAppAlertCenter, testUI007_HomeAlertCenterButtonOpensAlertCenter, testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared, testUI009_AlertCenterPersistsAcrossRelaunch, testAlertCenterClearsNotificationsWhenRetractingAbsentAlert, testRetractingAbsentAlertStillClearsNotificationRequests; simulation evidence: Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; source mapping baseline: Docs/Quality/AlertInventoryAndMapping.md) |
In progress |
| RA-012 | SRS-BG-001, SRS-BG-002, SRS-BG-003, SRS-BG-004, SRS-BG-005, SRS-BG-006, SRS-BG-007, SRS-BG-008, SRS-BG-009, SRS-BG-010, SRS-BG-011, SRS-BG-012 | SDD-BG-001, SDD-POL-010, SDD-POL-011, SDD-POL-012, SDD-LOG-001 | TV-BG-001, TV-BG-002, TV-BG-003, TV-BG-004, TV-BG-005, TV-BG-006, TV-BG-007, TV-BG-008, TV-BG-009, TV-BG-010, TV-BG-011, TV-BG-012 | Partial (current branch feasibility verification adds blocked manual-BG execution coverage while masked-fallback reconciliation is pending in BionicLoopRuntimeEngineSessionInfrastructureTests) |
In progress |
| RA-013 | SRS-CLIN-001, SRS-CLIN-002, SRS-CLIN-003, SRS-CLIN-004, SRS-CLIN-005, SRS-CLIN-006, SRS-CLIN-007, SRS-CLIN-008, SRS-CLIN-009, SRS-CLIN-010, SRS-CLIN-011, SRS-CLIN-012, SRS-VAL-001, SRS-LOG-008 | SDD-CLIN-001, SDD-POL-013, SDD-POL-017, SDD-POL-025, SDD-DATA-006 | TV-CLIN-001, TV-CLIN-002, TV-CLIN-003, TV-CLIN-004, TV-CLIN-005, TV-CLIN-006, TV-CLIN-007, TV-CLIN-008, TV-CLIN-009, TV-CLIN-010, TV-CLIN-011, TV-CLIN-012, TV-CLIN-013, TV-LOG-008 | Support evidence demonstrates offline HMAC unlock contract-vector coverage, Keychain-backed material installation/refresh, local counter burn/expiry semantics, manual-lock storage-failure handling, UI unlock success/failure/reuse handling, selector bounds, profile gating, and approval capture. Production role-based authorization is not claimed in the current baseline. Formal clinical-settings evidence promotion is still required for freeze. | Rerun needed |
| RA-014 | SRS-ALG-001, SRS-ALG-002, SRS-ALG-003, SRS-ALG-004, SRS-ALG-005, SRS-ALG-006, SRS-ALG-007 | SDD-ALG-001, SDD-QA-001 | TV-ALG-001, TV-ALG-002, TV-ALG-003, TV-ALG-004, TV-ALG-005, TV-ALG-006, TV-ALG-007, TV-ALG-008, TV-ALG-009, TV-ALG-010, TV-ALG-011 | Support package exists in Docs/Quality/Evidence/Working/STR-ALG-001/...; formal STR-ALG-001 execution and promotion are required for freeze. |
Rerun needed |
| RA-015 | SRS-CGM-005, SRS-RUN-004, SRS-RUN-005, SRS-ALERT-013, SRS-ALERT-014, SRS-UI-001, SRS-UI-002 | SDD-POL-020, SDD-POL-021, SDD-POL-022, SDD-POL-008, SDD-APP-003, SDD-CGM-001 | TV-CGM-005, TV-RUN-004, TV-RUN-005, TV-RUN-006, TV-RUN-007, TV-ALERT-012, TV-ALERT-013, TV-UI-001 | Support evidence exists for interruption deadline, alerting, and fresh-CGM suppression. Current implementation also permits reconnect fallback when CGM freshness is unavailable. Formal runtime evidence promotion and required live-device reconnect confirmation are still required for freeze. | Rerun needed |
| RA-016 | SRS-MEAL-007, SRS-MEAL-008, SRS-MEAL-009, SRS-MEAL-010, SRS-MEAL-011, SRS-MEAL-012, SRS-LOG-007, SRS-UI-002 | SDD-POL-023, SDD-POL-024, SDD-POL-027, SDD-POL-029, SDD-APP-001, SDD-LOG-001 | TV-MEAL-008, TV-MEAL-009, TV-MEAL-010, TV-MEAL-011, TV-MEAL-012, TV-MEAL-013, TV-LOG-007, TV-PUMP-003 | Support automated evidence exists for pending/uncertain meal state, duplicate blocking, reconciliation, cancel-delivery handling, and user-confirmed pod replacement for unconfirmed old-pod meal delivery. Formal meal-lifecycle evidence promotion is still required for freeze. | Rerun needed |
| RA-017 | SRS-PUMP-010, SRS-MEAL-012, SRS-STATE-004, SRS-STATE-005, SRS-LOG-001 | SDD-POL-029, SDD-PUMP-001, SDD-DATA-003, SDD-LOG-001 | TV-PUMP-009, TV-MEAL-013, TV-STATE-004, TV-STATE-005, TV-LOG-001 | Working evidence exists in FallbackBasalExposureReconcilerTests, LoopRuntimeCoordinatorMealAttributionReplayTests, LoopRuntimeCoordinatorMealAttributionLiveStepTests, LoopRuntimeCoordinatorIssuedDoseNewPodTests, LoopRuntimeCoordinatorFallbackReplayTests, BionicLoopRuntimeEngineReconnectEvidenceTests, BionicLoopRecentDoseTimelineTests, BionicLoopCloudTelemetryInfrastructureTests, BionicLoopAlgorithmInspectionTelemetryRuntimeTests, BionicLoopMealAnnouncementAvailabilityTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopMealAnnouncementResolutionRuntimeTests, BionicLoopMealAnnouncementPodReplacementEscapeTests, BionicLoopMealDeliveryProgressPolicyTests, and the SimulatedDashPod*ScenarioTests pod-simulation slice for correction/meal issued-dose attribution, active delivery skip, same-request/same-pod missed-step replay, reservoir-capped partial meal delivery using actual delivered units, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, pump-total partition of a known in-flight issued dose from fallback-basal residual, persisted partition evidence live-step consumption when replay is not required, app recent-dose persistence/display, local step CSV export, and runtime cloud step-event emission of merged meal/fallback replay source, disposition, request step, requested units, and delivered units after reload, raw pump-total telemetry without claiming fallback residual on ambiguous recovery, delivered-unit credibility rejection, fallback replay overlap, resolved issued-dose merge into the first fallback-active replay row when the issued dose predates fallback activation, fallback-only prior request-step attribution, evidence-gated pending attribution clearing, non-credible merge rejection, unresolved no-guess live-advance skip, mismatched/missing-identity no-replay, different/new pod assumed-delivered attribution with replacement-pod live input scrubbing, user-abandoned unavailable-pod meal assumed-delivered evidence, future insulin-adding command allowance including automatic resume, legacy different/new-pod hold nonblocking behavior for commands and meal availability, meal progress modal resolution after runtime consumes matching pending meal attribution including fallback-merge and user-escaped old-pod paths, and meal-availability blocking/mapping. Formal evidence promotion is still required for freeze. |
Rerun needed |
Usage
For each PR or change batch:
- Add/update impacted
SRS-*. - Update
SDD-*references. - Add/update
TV-*and run tests. - Attach evidence references in this table.
Notes
Statusvalues:Planned,In progress,Rerun needed,Complete,Blocked,Deferred (current software handoff package), andDeferred (partial scope)when only a subset of a mapped hazard/row is intentionally claimed in the current package.- Evidence can reference CI run IDs, local test logs, or manual protocol records.