fix(dev): bound the thermal freeze and poll fast under the guard - #89
Merged
Merged
Conversation
Dreamcoder08
force-pushed
the
fix/safe-run-liveness
branch
from
September 29, 2026 05:16
00672b0 to
9e1c77b
Compare
After SAFE_MAX_FREEZE, a zone whose reading never fell by 2 C gets a SAFE_GRACE window in which only SAFE_TEMP_HARD re-freezes, so a stuck-hot sensor can no longer pause a run indefinitely. At or above the hard ceiling there is no forced thaw. A rise of 8 C within three polls above RESUME pauses early. A failing thaw warns once and never claims to resume. New settings are validated (exit 2), and the thermal read and validation move to scripts/lib/safe-run-lib.sh to keep the script within budget.
…uck hot Covers the stuck-hot grace, no grace for a load-related zone, the hard ceiling staying frozen, the early pause on a fast rise and a single warning on thaw failure, all against fake zone files.
A real-heat check measured the sensor jumping from 67 C to 95 C in under a second (critical trip 103 C), so a 1 s poll left only ~8 C of margin. The watchdog now polls every SAFE_POLL seconds (default 0.25) and measures the freeze cap, the grace and the 8 C rise window on the wall clock, so they mean the same at any poll rate. SAFE_CPU defaults to 100% (one core-equivalent) and SAFE_TEMP_HARD to 85000. Zones are read with the read builtin to avoid a fork per zone per poll. Tests pin SAFE_POLL=1, validate SAFE_POLL, and rerun the stuck-hot progress case at 0.1 s.
…rd ceiling A zone that stays at or above SAFE_TEMP_HARD never thaws, which is right for safety but hung the caller forever on a stuck sensor. After SAFE_HARD_ABORT seconds (default 600) frozen at or above the ceiling, the scope is killed without ever being thawed and safe-run exits 75 (EX_TEMPFAIL). Behaviour below the ceiling is unchanged. The rise window, rise delta and fall check are now named readonly constants.
Dreamcoder08
force-pushed
the
fix/safe-run-liveness
branch
from
September 29, 2026 05:17
9e1c77b to
feb01f8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #61. Hardens
scripts/safe-run.sh(the dev laptop's thermal guard), calibrated with real-heat measurements.Behavior
SAFE_TEMP_HARD(85 °C) freezes at once, even in a grace window; afterSAFE_MAX_FREEZE(180 s) a freeze is forced open with aSAFE_GRACE(60 s) window unless the reading fell ≥ 2 °C (then it is load-related and no grace is granted) — a stuck-hot sensor can no longer stall a run indefinitelySAFE_POLL(0.25 s), wall-clock timing independent of the poll rate; rise guard = ≥ 8 °C within ~1 sSAFE_CPUdefault 100%; thaw failures warn once; thresholds validated (exit 2); unreadable zones skipped; thermal glob documented and paths with spaces handledscripts/lib/safe-run-lib.sh(safe-run.sh 130 lines)Evidence
thawwarns once, six invalid-setting cases, signals leave no scope)Reviewed follow-ups from #85/#86 are unrelated to this PR.