Skip to main content

AEROSIM-TS-84

Project task

Restore a safe aircraft state or conclude the boundary violation

A hard-limit or governed collision event restores the last safe state/configured recovery point or explicitly concludes the session without leaving an unexplained aircraft state.

AEROSIM-TS-84Canonical ID TASK-0084
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web flight session — safe-state store and recovery coordinator
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Maintain SafeAircraftSnapshot {sessionId,simulationTick,state,stateDigest} only from INSIDE boundary state with no unsafe contact. On recoverable HARD_LIMIT_REACHED, atomically restore the latest snapshot and reset controls to neutral; on unsafe collision, repeated hard limit, missing/stale/corrupt snapshot, or non-finite aircraft state, emit InvalidFlightEvent for FT-11 and stop physics advancement.

Implementation contract

Implementation artifacts

  • applications/web/src/flight/recovery/safe-aircraft-snapshot.ts
  • applications/web/src/flight/recovery/recover-or-conclude.ts
  • applications/web/test/flight/recovery-coordinator.spec.ts

Inputs

  • RecoveryRequest {sessionId,currentTick,trigger:ContactClassification|BoundaryTransition,currentState,currentControls}, latest SafeAircraftSnapshot, and RecoveryPolicyV1 {maxSnapshotAgeTicks,maxAutomaticRecoveries}.

Outputs

  • RecoveryDecision {kind:'RESTORED'|'CONCLUDED',reasonCode,recoverySequence,restoredState|null,restoredStateDigest|null,controlsAfter,invalidFlightEvent|null}; RESTORED commits state and neutral controls in one transaction.

Failure boundaries

  • Conclude with RECOVERY_SNAPSHOT_MISSING when no snapshot exists, RECOVERY_SNAPSHOT_STALE when its age exceeds maxSnapshotAgeTicks, and RECOVERY_SNAPSHOT_CORRUPT when its digest or finite-state validation fails.
  • Conclude with UNSAFE_CONTACT for UNSAFE_TERRAIN_IMPACT or SOLID_OBSTACLE_IMPACT; these events never trigger automatic restore.
  • Conclude with RECOVERY_LIMIT_EXCEEDED after maxAutomaticRecoveries; duplicate trigger eventIds return the existing decision without incrementing recoverySequence.
  • If atomic restore fails, roll back state and controls, stop the simulation clock, and conclude with RECOVERY_COMMIT_FAILED.

Excluded scope

  • Checkpoint selection UI, rewind history, saved-game persistence, aircraft repair, scoring penalties, retry/session creation, and outcome-screen rendering are excluded.

Verification steps

  • Run applications/web/test/flight/recovery-coordinator.spec.ts.
  • Verify snapshot capture only in safe state, atomic restore on first recoverable hard limit, neutral controls, monotonic recoverySequence, and no next physics tick before commit.
  • Exercise unsafe contact, repeated violation, missing/stale/corrupt snapshot, non-finite state, duplicate trigger, and injected commit failure; assert exact decisions and rollback.
  • Assert every CONCLUDED decision contains one InvalidFlightEvent with sessionId, triggerEventId, tick, reasonCode, and lastSafeStateDigest when present.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #105 merged as 20fa375864e68145d3dfdfa0dcb9b31c9eb734f2; integration run 4046 and immutable publication run 4047 passed for the safe-state recovery implementation. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.