feat: add FDIR fault counter and wire it into the MGM device handler #277

Merged
muellerr merged 1 commits from fdir-addition into main 2026-09-16 13:57:51 +02:00
Owner

Add satrs::fdir::FaultCounter, an FSFW-style error threshold counter:
counts faults, decrements over time when faults stop, and reports
when a threshold is exceeded. Two variants for now, mirroring the
hk.rs helper pattern:

  • FaultCounterStd, backed by std::time::Instant
  • FaultCounterEmbassy, backed by embassy_time::Instant (embassy-time
    feature), with an optional defmt::Format impl gated on the defmt
    feature

Add satrs::health::HealthTableMapSync::default() for easy construction
of a shared, global health table.

Wire both into the example app's MGM device handler as the first real
FDIR use case:

  • the minisim MGM model gains SpiFaultMode (None/AllZeros/AllOnes) and
    a SetSpiFault request, so a stuck SPI bus can be injected for testing,
    independent of switch state
  • MgmHandlerLis3Mdl::poll_sensor checks the SPI transfer result: a
    comm timeout or an all-1s stuck-bus reply (the same pattern the sim
    already uses for "device off") counts as a fault. Above threshold,
    the component is marked Faulty in a HealthTableMapSync shared from
    main.rs. This logic lives in the device handler, not the SPI comm
    layer, since deciding what a failed transfer means for FDIR is a
    handler concern.
  • an all-0s reply is deliberately not treated as a fault, since it
    collides with a legitimate zero-field reading

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01BaKjBjnxaHJ6vzficJcjN4

Add satrs::fdir::FaultCounter, an FSFW-style error threshold counter: counts faults, decrements over time when faults stop, and reports when a threshold is exceeded. Two variants for now, mirroring the hk.rs helper pattern: - FaultCounterStd, backed by std::time::Instant - FaultCounterEmbassy, backed by embassy_time::Instant (embassy-time feature), with an optional defmt::Format impl gated on the defmt feature Add satrs::health::HealthTableMapSync::default() for easy construction of a shared, global health table. Wire both into the example app's MGM device handler as the first real FDIR use case: - the minisim MGM model gains SpiFaultMode (None/AllZeros/AllOnes) and a SetSpiFault request, so a stuck SPI bus can be injected for testing, independent of switch state - MgmHandlerLis3Mdl::poll_sensor checks the SPI transfer result: a comm timeout or an all-1s stuck-bus reply (the same pattern the sim already uses for "device off") counts as a fault. Above threshold, the component is marked Faulty in a HealthTableMapSync shared from main.rs. This logic lives in the device handler, not the SPI comm layer, since deciding what a failed transfer means for FDIR is a handler concern. - an all-0s reply is deliberately not treated as a fault, since it collides with a legitimate zero-field reading Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BaKjBjnxaHJ6vzficJcjN4
muellerr force-pushed fdir-addition from 70345e5e94 to 3414c0ba35 2026-09-14 15:55:17 +02:00 Compare
muellerr force-pushed fdir-addition from 3414c0ba35 to f9da3d6ba7 2026-09-15 13:16:13 +02:00 Compare
muellerr force-pushed fdir-addition from 2b52d1c882 to 1256c6b07f 2026-09-16 13:15:10 +02:00 Compare
muellerr force-pushed fdir-addition from c6fe161180 to fe970ad881 2026-09-16 13:23:15 +02:00 Compare
muellerr added 1 commit 2026-09-16 13:56:54 +02:00
Add satrs::fdir::FaultCounter, an FSFW-style error threshold counter:
counts faults, decrements over time when faults stop, and reports
when a threshold is exceeded. Two variants for now, mirroring the
hk.rs helper pattern:
- FaultCounterStd, backed by std::time::Instant
- FaultCounterEmbassy, backed by embassy_time::Instant (embassy-time
  feature), with an optional defmt::Format impl gated on the defmt
  feature

Add satrs::health::HealthTableMapSync::default() for easy construction
of a shared, global health table.

Wire both into the example app's MGM device handler as the first real
FDIR use case:
- the minisim MGM model gains SpiFaultMode (None/AllZeros/AllOnes) and
  a SetSpiFault request, so a stuck SPI bus can be injected for testing,
  independent of switch state
- MgmHandlerLis3Mdl::poll_sensor checks the SPI transfer result: a
  comm timeout or an all-1s stuck-bus reply (the same pattern the sim
  already uses for "device off") counts as a fault. Above threshold,
  the component is marked Faulty in a HealthTableMapSync shared from
  main.rs. This logic lives in the device handler, not the SPI comm
  layer, since deciding what a failed transfer means for FDIR is a
  handler concern.
- an all-0s reply is deliberately not treated as a fault, since it
  collides with a legitimate zero-field reading
muellerr force-pushed fdir-addition from fe970ad881 to 86d8528d21 2026-09-16 13:56:54 +02:00 Compare
muellerr merged commit 76074d69e4 into main 2026-09-16 13:57:51 +02:00
muellerr deleted branch fdir-addition 2026-09-16 13:57:51 +02:00
Sign in to join this conversation.