AEROSIM-TS-95
Prove camera switching cannot mutate flight or control state
Trace and browser checks show supported, rapid, repeated, and invalid selections leave aircraft state, attempt identity, and control ownership unchanged.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-14
- Component
- Web Application / R3F flight scene and Deterministic flight runtime — camera isolation harness
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Implement applications/web/test/flight/secondary-camera-state-guard.browser.spec.ts, applications/web/test/fixtures/camera-state-traces.json. Consume only the inputs listed in this contract, publish only its listed outputs, enforce every failure boundary before commit, and prove the listed exclusions remain unchanged through the verification steps.
Implementation contract
Implementation artifacts
- applications/web/test/flight/secondary-camera-state-guard.browser.spec.ts
- applications/web/test/fixtures/camera-state-traces.json
Inputs
- A deterministic active-flight fixture with seeded initial state, fixed control-command trace, and the complete supported SecondaryCameraId list.
- Camera selection sequences covering each view, repeated selections, rapid changes, unsupported IDs, and injected rig failures.
Outputs
- Per-step paired baseline/switch traces containing attemptId, stepIndex, pose, velocity, forces, inputOwnerId, controlCommand, activeCameraId, and selection-to-present latency.
- A comparison report that identifies the first differing protected flight/control field or confirms equality for all protected fields and checks every latency against the configured limit.
Failure boundaries
- Fail on any difference in attemptId, stepIndex, pose, velocity, forces, input owner, or applied control command between baseline and camera-switch traces.
- Fail if an unsupported/failed selection changes the active valid camera or if more than one rig remains live after settling.
- Fail if any selection lacks a presented-frame sample or exceeds the configured camera-selection latency limit.
Excluded scope
- Changing camera product behavior or aircraft dynamics to make traces pass.
- Visual-quality assessment beyond the deterministic state and configured timing assertions in this harness.
Verification steps
- Run applications/web/test/flight/secondary-camera-state-guard.browser.spec.ts twice from the same seed: once without switches and once with the complete selection sequence.
- Compare protected fields at every step with exact equality for identifiers/discrete values and the flight-core configured numeric tolerance for vectors; report the first mismatch.
- Inject unsupported IDs and rig failures, repeat and rapidly reorder selections, then assert the previous valid camera survives, exactly one rig remains, and every valid selection meets the configured latency limit.
Traceability
Dependencies
- AEROSIM-TS-94Canonical ID: TASK-0094
Acceptance evidence
Verified delivery: application PR #171 reviewed head 96a84e1cdab93696fe4fee0b227eb233537a7652 merged as 4468005729ffc5f7539efaa2fca073ac0da2f5cb. Deterministic camera-state traces prove all supported, repeated, rapid, unsupported, and failed selections preserve attempt identity, simulation step, pose, velocity, forces, input ownership, and applied controls; every valid selection has a presented-frame sample within the 50 ms limit and exactly one rig remains live. Focused camera-state tests pass 3/3; full tests, browser matrices, security, lint, format, typecheck, build, workflow/container/Helm contracts, and production audit passed. Candidate CI run 4771 attempt 2, integration run 4773, and immutable publication run 4772 passed. Harbor readback resolved Nebula digest sha256:ce06e9d0e179817cddf85363665be92ef2a2f891701a7d95d495d14e7bce4097 and Singularity digest sha256:2df8342a75d29e73d548f7100f916520f810a1d3b84e089d60c02492fd7309ee for the exact integration revision. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.