Files
cnc_wams/text4.txt

671 lines
25 KiB
Plaintext

HAL/UI/full-process standalone/browser boundary design and next plan
Generated: 2026-06-10 CST
This plan follows `text3.txt`. The `configs/sim` inventory/matrix work is now
complete for the current definition. This file defines the next boundary before
any previously blocked HAL/UI/full-process family is promoted into standalone,
Node, or browser execution.
Goal
- Preserve LinuxCNC as the CNC semantic source of truth.
- Make HAL/UI/full-process dependencies machine-readable before attempting
execution.
- Promote only the subpaths that can run through vendored LinuxCNC source plus
explicit standalone runtime adapters.
- Keep task, HAL process launch, UI driver process launch, linuxcncrsh, Python
remap, and tool-database process behavior blocked until each has a deliberate
LinuxCNC-owned runtime boundary.
Non-goals
- Do not implement HAL, task, linuxcncrsh, GUI, Python remap, or tool-database
semantics in JavaScript.
- Do not make blocked `configs/sim` programs pass by editing upstream G-code,
changing SDK behavior, or adding project-owned interpreter semantics.
- Do not treat native LinuxCNC GUI code as implementation code for the browser
UI.
Current implementation added by this batch
1. SDK runtime-boundary classifier
Added:
```text
wasm-port/runtime/sdk/src/sim-config-staging.js
analyzeIniRuntimeBoundaries()
```
Exported through:
```text
wasm-port/runtime/sdk/src/index.js
```
The classifier reads INI text, manifest text, source-root metadata, and
optional execution text. It reports:
- declared `HAL` process inputs: `HALFILE`, `HALCMD`, `POSTGUI_HALFILE`,
`HALUI`;
- declared UI process inputs: `DISPLAY`, `PYVCP`, `GLADEVCP`,
`EMBED_TAB_COMMAND`;
- `HALUI` MDI command dependencies;
- `[EMCIO]DB_PROGRAM` tool-database process dependencies;
- Python references in UI, DB, `[PYTHON]`, or Python remap declarations;
- `[RS274NGC]USER_M_PATH` plus whether the current execution text calls
unstaged external `M100..M199` process codes.
It returns a policy recommendation for hard Layer 4 blocks:
- `L4-TOOL-DB` when `[EMCIO]DB_PROGRAM` is present;
- `L4-USER-M-PROCESS` when the current execution chain calls unstaged
external user-M process codes;
- `L4-PYTHON-REMAP` for Python remap runtime declarations;
- `-` when the dependency is only a declared process dependency already
represented by a narrower standalone adapter or class representative.
This is policy/accounting only. It does not execute or emulate HAL, task,
UI, Python, user-M, or tool-database behavior.
2. Node coverage for the classifier
Updated:
```text
wasm-port/tests/wasm/node/verify_sim_configs_wasm.mjs
```
Covered cases:
- synthetic INI with vendored `M123` user-M file remains unblocked;
- `axis/db_demo/db_nonran.ini` reports `L4-TOOL-DB`;
- `axis/vismach/millturn/millturn.ini` plus its remap execution chain
reports `L4-USER-M-PROCESS` because `M428/M429` call unstaged `M128/M129`;
- `axis/vismach/puma/puma_cube.ini` declares HAL/UI/HALUI process
dependencies but remains unblocked for the current representative program
because the promoted execution path does not call unstaged external
user-M process codes;
- `axis/gladevcp/gladevcp_panel.ini` declares UI/Python UI process
dependencies but remains unblocked for the current `probe.ngc`
representative.
3. Inventory policy guard
Updated:
```text
wasm-port/tests/wasm/node/verify_sim_configs_inventory_wasm.mjs
```
The Node inventory now checks vendored INI rows against
`analyzeIniRuntimeBoundaries()` before execution/skipping:
- `L4-TOOL-DB` rows must declare `DB_PROGRAM`;
- `L4-USER-M-PROCESS` rows must be backed by an execution chain that calls
unstaged external user-M process codes;
- generated/tracked blocked policy drift fails the inventory.
Boundary model
Layer A: declaration classification
- Input: INI text, manifest text, optional execution text.
- Output: dependency list and recommended blocked kind.
- Owner: SDK host-boundary code.
- Validation: Node unit/smoke assertions and Node inventory policy checks.
Layer B: standalone adapter execution
- Allowed only when a narrow runtime edge already exists and CNC behavior still
comes from vendored LinuxCNC source.
- Current examples:
- HAL named-parameter lookup and switchkins M68/M66 synchronization through
the standalone HAL adapter;
- deterministic `USER_M_COMMAND` canonical events for already vendored
M110/M111-style user-M registration;
- five-axis remap execution through vendored LinuxCNC remap/O-word paths;
- OPFS/file/parameter/tool-table persistence as host storage boundaries.
Layer C: browser/UI representation
- Browser UI may present standalone simulation state and user controls.
- Browser UI must not execute native LinuxCNC GUI code.
- Browser UI must call SDK/WASM boundaries that are already validated in Node
or native probes.
- Full LinuxCNC GUI actions remain blocked unless expressed as a deliberate
standalone command boundary with LinuxCNC-owned behavior underneath.
Layer D: full-process blocked boundary
Keep blocked until explicitly designed:
- LinuxCNC task process lifecycle;
- HAL process/module loading and realtime scheduling;
- HALUI/linuxcncrsh command queues;
- external userspace components;
- native GUI driver processes;
- Python remap/prolog/epilog runtime;
- tool database process startup and protocol/state behavior.
Follow-on implementation completed after this plan
Batch 1: durable boundary reports
- Complete. The Node inventory now writes:
```text
wasm-port/build/wasm/sim-configs-inventory/boundary-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/ini-boundary-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/blocked-dependency-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/boundary-phase-completion-summary.tsv
```
- `boundary-summary.tsv` records the path, INI, tracked blocked kind,
classifier recommendation, dependency evidence, user-M execution codes,
unstaged user-M codes, vendored user-M count, DB program, HAL/UI/HALUI
process flags, and Python UI/remap process flags.
- The inventory fails if a hard blocked row and the classifier recommendation
drift, if `L4-TOOL-DB` lacks `DB_PROGRAM`, if `L4-USER-M-PROCESS` lacks
unstaged external user-M execution codes, or if `L4-PYTHON-REMAP` lacks
Python remap process evidence.
Batch 2: safe HAL/UI representatives
- Complete. The inventory keeps these safe representatives as Node/browser
`REP` rows while recording declared process dependencies:
- `axis/gladevcp/probe.ngc`
- `woodpecker/on_abort.ngc`
- `axis/vismach/puma/puma_cube.ngc`
- `axis/vismach/melfa-sim/example.ngc`
- These rows remain file/remap execution representatives only. They do not
claim full HAL/UI process coverage.
- `axis/vismach/millturn/example.ngc` remains blocked as
`L4-USER-M-PROCESS` because its remap chain calls unstaged `M128/M129`.
Batch 3: external user-M process boundary
- Complete as a design-and-gate phase, still blocked for execution.
- Generated artifacts now identify LinuxCNC ownership and state targets for
millturn `M128/M129`:
```text
wasm-port/build/wasm/sim-configs-inventory/user-m-process-boundary-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/user-m-process-state-targets.tsv
wasm-port/build/wasm/sim-configs-inventory/user-m-process-transition-plan.tsv
wasm-port/build/wasm/sim-configs-inventory/user-m-process-native-runtime-state-plan.tsv
wasm-port/build/wasm/sim-configs-inventory/user-m-process-native-runtime-readiness.tsv
wasm-port/build/wasm/sim-configs-inventory/user-m-process-native-runtime-probe-gate.tsv
```
- The native probe entry point exists:
```text
wasm-port/tests/native/probe_millturn_user_m_runtime.sh
```
- The probe is disabled by default and currently reports
`skipped_missing_host_runtime` on this host because `halrun`, `halcmd`, and
`linuxcnc` are unavailable. Promotion remains locked.
Batch 4: tool DB boundary
- Complete as a design-and-gate phase, still blocked for execution.
- Generated artifacts now describe the `DB_PROGRAM` v2.1 protocol, get/load/
put/unload transactions, persistence state, native readiness, and promotion
lock:
```text
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-boundary-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-protocol-gates.tsv
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-transaction-plan.tsv
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-native-runtime-readiness.tsv
```
- The native probe entry point exists:
```text
wasm-port/tests/native/probe_tool_db_runtime.sh
```
- The probe is disabled by default and currently reports
`skipped_missing_host_runtime` because `linuxcnc`, `milltask`, and `halcmd`
are unavailable. `axis/db_demo/base.ngc` remains `L4-TOOL-DB`.
Batch 5: Python remap/full-process family plan
- Complete as dependency inventory plus a minimal native lifecycle fixture
plan, still blocked for execution.
- Generated artifacts now inventory Python remap families, LinuxCNC owner
sources, configured modules, callable/prolog/epilog expectations, runtime
phases, readiness, and the selected `stop-lookahead` fixture:
```text
wasm-port/build/wasm/sim-configs-inventory/python-remap-boundary-summary.tsv
wasm-port/build/wasm/sim-configs-inventory/python-remap-runtime-contract.tsv
wasm-port/build/wasm/sim-configs-inventory/python-remap-native-runtime-readiness.tsv
wasm-port/build/wasm/sim-configs-inventory/python-remap-native-runtime-state-plan.tsv
wasm-port/build/wasm/sim-configs-inventory/python-remap-native-runtime-fixture-plan.tsv
```
- The native probe entry point exists:
```text
wasm-port/tests/native/probe_python_remap_runtime.sh
```
- The probe is disabled by default and currently reports
`skipped_missing_host_runtime` because `linuxcnc` is unavailable. Python
remap families remain inventory-only and are not promoted.
Batch 6: Python remap host/source readiness gate
- Complete as a readiness-and-gate phase, still blocked for execution.
- Generated artifacts now explicitly separate ordinary `python3` availability
from LinuxCNC interpreter-owned Python remap runtime readiness:
```text
wasm-port/build/wasm/sim-configs-inventory/python-remap-native-runtime-readiness.tsv
wasm-port/build/wasm/sim-configs-inventory/python-remap-native-runtime-probe-gate.tsv
```
- `python-remap-native-runtime-probe-gate.tsv` records the selected
`axis/remap/stop-lookahead/nc_files` fixture, `python3`, `linuxcnc`,
`interp_python.cc`, `python_plugin.cc`, and representative module import
inputs:
```text
import:axis/remap/stop-lookahead/python/remap.py
import:axis/remap/stop-lookahead/python/toplevel.py
```
- The gate records `python3_sufficient=0`. On this host, `python3` is present
but `linuxcnc` is missing, so the gate remains:
```text
runtime_ready=0
source_proof_ready=1
gate_status=blocked_missing_host_runtime
execution_enabled=0
promotion_allowed=0
```
- Node inventory and browser smoke now require the Python remap runtime probe
gate artifact. The browser gate checks the same policy without executing
Python remap code or claiming browser/full-process coverage.
Batch 7: tool DB host/source readiness gate
- Complete as a readiness-and-gate phase, still blocked for execution.
- Generated artifacts now explicitly separate ordinary `python3` availability
and tool-table fallback from LinuxCNC `DB_PROGRAM` process readiness:
```text
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-native-runtime-readiness.tsv
wasm-port/build/wasm/sim-configs-inventory/tool-db-process-native-runtime-probe-gate.tsv
```
- `tool-db-process-native-runtime-probe-gate.tsv` records the selected
`axis/db_demo/base.ngc` fixture, `DB_PROGRAM=./db_nonran.py`, required host
commands, DB program source, LinuxCNC Python modules, and the v2.1 protocol
transaction contract.
- The gate records:
```text
python3_sufficient=0
tool_table_fallback_sufficient=0
db_program_source_ready=1
linuxcnc_python_modules_ready=1
protocol_contract_ready=1
source_proof_ready=1
```
- On this host, `python3` is present but `linuxcnc`, `milltask`, and `halcmd`
are missing, so the gate remains:
```text
runtime_ready=0
gate_status=blocked_missing_host_runtime
execution_enabled=0
promotion_allowed=0
```
- Node inventory and browser smoke now require the tool DB runtime probe gate
artifact. The browser gate checks the same policy without executing
`DB_PROGRAM`, starting LinuxCNC processes, or falling back to `.tbl`
semantics.
Batch 8: native runtime probe/gate alignment
- Complete as a cross-artifact consistency gate, still blocked for execution.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/runtime-probe-gate-alignment.tsv
```
- This artifact aligns the native runtime probe summary with the generated
runtime probe gates for:
- `axis/vismach/millturn/example.ngc`
- `axis/db_demo/base.ngc`
- `axis/remap/stop-lookahead/nc_files`
- The alignment requires matching `runtime_ready`, `source_proof_ready`,
missing host requirements, execution-disabled state, promotion-disabled
state, and compatible native/gate statuses.
- Node inventory and browser smoke now require this alignment before any
blocked boundary can be considered for promotion.
Batch 9: native runtime probe opt-in metadata
- Complete as a native/WASM/browser schema hardening phase, still blocked for
execution.
- `native-runtime-probe-summary.tsv` now records the proof key and opt-in
switch for each disabled native runtime probe:
```text
required_native_proof
opt_in_env
probe_note
```
- The current rows explicitly require:
- `native_runtime_state_probe_required` with
`ENABLE_MILLTURN_USER_M_RUNTIME_PROBE=1`;
- `native_db_process_protocol_probe_required` with
`ENABLE_TOOL_DB_RUNTIME_PROBE=1`;
- `linuxcnc_python_runtime_lifecycle_probe_required` with
`ENABLE_PYTHON_REMAP_RUNTIME_PROBE=1`.
- The native probe scripts now emit a `runtime_probe_note` for missing source,
missing host runtime, disabled-ready, pass, and fail states. On this host the
notes still report missing LinuxCNC host runtime and keep promotion disabled.
- `runtime-probe-gate-alignment.tsv` now compares the gate
`required_native_proof` with the native runtime summary proof key and records
`native_opt_in_env`, so a ready host cannot silently drift from the intended
opt-in probe.
- Native, Node inventory, and browser smoke all require these fields while
keeping `execution_enabled=0` and `promotion_allowed=0`.
Batch 10: native runtime opt-in execution plan
- Complete as a generated runbook/gate artifact, still blocked for execution on
this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/native-runtime-probe-execution-plan.tsv
```
- The artifact records the exact opt-in command, current runtime readiness,
current native probe status, expected pass status, missing requirements, gate
alignment status, and promotion prerequisites for:
- `axis/vismach/millturn/example.ngc`;
- `axis/db_demo/base.ngc`;
- `axis/remap/stop-lookahead/nc_files`.
- Current opt-in commands are:
- `ENABLE_MILLTURN_USER_M_RUNTIME_PROBE=1 bash wasm-port/tests/native/probe_millturn_user_m_runtime.sh`;
- `ENABLE_TOOL_DB_RUNTIME_PROBE=1 bash wasm-port/tests/native/probe_tool_db_runtime.sh`;
- `ENABLE_PYTHON_REMAP_RUNTIME_PROBE=1 bash wasm-port/tests/native/probe_python_remap_runtime.sh`.
- The expected native pass statuses are:
- `runtime_state_probe_passed`;
- `runtime_protocol_probe_passed`;
- `runtime_lifecycle_probe_passed`.
- On this host all three rows remain:
```text
runtime_ready=0
gate_alignment_ok=1
execution_enabled=0
promotion_allowed=0
plan_status=blocked_missing_host_runtime
```
- Promotion remains explicitly gated on native pass status, subsequent Node
inventory gate alignment, browser smoke gate alignment, and a manual promotion
lock update. The opt-in command alone does not promote any blocked row.
- Node inventory, browser smoke, and the boundary phase completion summary now
require this execution plan.
Batch 11: native runtime pass evidence contract
- Complete as a generated stdout-evidence contract, still blocked for execution
on this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/native-runtime-probe-pass-evidence-contract.tsv
```
- The artifact records the native stdout evidence keys that must be present
after each opt-in native runtime probe reports its expected pass status.
- Current required pass statuses and evidence include:
- millturn user-M:
`runtime_state_probe_passed`,
`millturn_user_m_M128_runtime_state_ok=1`,
`millturn_user_m_M129_runtime_state_ok=1`;
- tool DB:
`runtime_protocol_probe_passed`,
`tool_db_protocol_version=v2.1`,
`tool_db_runtime_protocol_probe_ok=1`,
`tool_db_persistence_state_ok=1`;
- Python remap:
`runtime_lifecycle_probe_passed`,
`python_remap_lifecycle_generator_first_yield=2`,
`python_remap_runtime_lifecycle_probe_ok=1`.
- On this host all three rows remain:
```text
evidence_required_now=0
observed_evidence_ready=0
missing_evidence_keys=-
evidence_status=pending_until_native_pass
execution_enabled=0
promotion_allowed=0
```
- If a future opt-in probe reports its expected pass status, Node inventory will
require all declared stdout evidence keys before any Node/browser promotion
work can proceed. Browser smoke checks the same contract and still treats it
as non-promoting evidence.
- The boundary phase completion summary now requires this evidence contract.
Batch 12: runtime boundary promotion readiness summary
- Complete as a generated final promotion-readiness gate, still blocked for
execution and promotion on this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/runtime-boundary-promotion-readiness.tsv
```
- The artifact combines:
- native runtime execution plan status;
- native pass evidence status;
- blocked runtime promotion lock state;
- Node inventory gate completion state;
- browser smoke gate completion state;
- manual lock update requirement.
- Current rows remain:
```text
native_pass_ready=0
native_evidence_ready=0
node_inventory_gate_complete=0
browser_smoke_gate_complete=0
promotion_lock_active=1
manual_lock_update_required=1
promotion_ready=0
execution_enabled=0
promotion_allowed=0
blocking_reason=awaiting_native_runtime_probe_pass
```
- This gives each blocked runtime family one machine-readable final decision:
even if a native probe later passes, promotion still requires native evidence,
Node/browser promotion gates, and an explicit manual promotion lock update.
- Node inventory, browser smoke, and the boundary phase completion summary now
require this readiness summary.
Batch 13: runtime boundary promotion blockers
- Complete as a generated blocker-summary gate, still blocked for execution and
promotion on this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/runtime-boundary-promotion-blockers.tsv
```
- The artifact expands each `promotion_ready=0` decision into concrete blocker
keys and the next unblock action. Current blocker keys include:
- `host_runtime_requirements_missing`;
- `native_runtime_probe_not_passed`;
- `native_pass_evidence_not_ready`;
- `node_inventory_gate_not_complete`;
- `browser_smoke_gate_not_complete`;
- `promotion_lock_active`;
- `manual_lock_update_required`.
- Current missing runtime requirements are:
- millturn user-M: `halrun,halcmd,linuxcnc`;
- tool DB: `linuxcnc,milltask,halcmd`;
- Python remap: `linuxcnc`.
- The current next unblock action is to provide the missing host runtime
requirements for each family. The artifact remains summary-only:
```text
promotion_ready=0
execution_enabled=0
promotion_allowed=0
```
- Node inventory, browser smoke, and the boundary phase completion summary now
require this blocker summary.
Batch 14: post-native-pass promotion gates
- Complete as a generated post-native-pass gate, still blocked for execution
and promotion on this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/runtime-boundary-post-native-pass-gates.tsv
```
- The artifact records, for each blocked runtime family, the native pass
status, native evidence readiness, required Node proof, required browser
proof, Node gate status, browser gate status, manual lock requirement, and
active promotion lock state.
- Current rows remain:
```text
native_pass_ready=0
native_evidence_ready=0
node_gate_status=blocked_until_native_pass_evidence
browser_gate_status=blocked_until_node_gate_complete
manual_lock_update_required=1
promotion_lock_active=1
execution_enabled=0
promotion_allowed=0
gate_status=blocked_before_native_pass
```
- This closes the next machine-readable step after a future native probe pass:
native evidence must exist first, then Node inventory proof, then browser
smoke proof, then a manual promotion-lock update. Native pass alone still
cannot promote `L4-USER-M-PROCESS`, `L4-TOOL-DB`, or
`L4-PYTHON-REMAP`.
- Node inventory, browser smoke, and the boundary phase completion summary now
require this post-native-pass gate.
Batch 15: blocked runtime host preflight
- Complete as a generated host-preflight summary, still blocked for execution
and promotion on this host.
- Generated artifact:
```text
wasm-port/build/wasm/sim-configs-inventory/runtime-boundary-host-preflight.tsv
```
- The artifact aggregates the three runtime probe gates into one host-facing
preflight table with:
- boundary class/kind/target;
- required LinuxCNC runtime family;
- full runtime requirement availability vector;
- missing host requirements;
- source proof readiness;
- required native proof key;
- opt-in environment variable;
- exact opt-in command;
- current native probe status;
- preflight status.
- Current rows remain:
```text
source_proof_ready=1
runtime_ready=0
current_probe_status=skipped_missing_host_runtime
preflight_status=blocked_missing_host_runtime
execution_enabled=0
promotion_allowed=0
```
- Current missing runtime requirements are summarized in one artifact:
- millturn user-M: `halrun,halcmd,linuxcnc`;
- tool DB: `linuxcnc,milltask,halcmd`;
- Python remap: `linuxcnc`.
- This preflight does not run probes and does not relax promotion locks. It
only records when a future host is ready to run the already declared opt-in
native probe commands.
- Node inventory, browser smoke, and the boundary phase completion summary now
require this host-preflight artifact.
Current next implementation recommendations
Generated recommendation source:
```text
wasm-port/build/wasm/sim-configs-inventory/next-boundary-recommendations.tsv
```
1. Implement and run the LinuxCNC-owned millturn `M128/M129` HAL/Tcl state
runtime probe after a host runtime with `tclsh`, `halrun`, `halcmd`, and
`linuxcnc` is available. Keep the row blocked until the native state probe
passes and Node/browser coverage can prove a narrow standalone boundary
without full-process claims.
2. Implement and run the tool DB protocol probe after
`tool-db-process-native-runtime-probe-gate.tsv` reports `runtime_ready=1`
with `python3`, `linuxcnc`, `milltask`, and `halcmd` available. The proof
must cover v2.1 handshake, `g`, `p`, `l`, `u`, state changes, and
persistence before `axis/db_demo/base.ngc` can move out of `L4-TOOL-DB`.
3. Implement the minimal Python remap lifecycle proof for
`axis/remap/stop-lookahead` after the new native runtime probe gate reports
`runtime_ready=1` with both `python3` and `linuxcnc` available. Keep all
Python-remap families blocked until the LinuxCNC Python runtime lifecycle is
proven without JavaScript CNC semantics.
Validation gates
Run after each batch:
```bash
wasm-port/tests/wasm/node/verify_sim_configs_wasm.sh
wasm-port/tests/wasm/node/verify_sim_configs_inventory_wasm.sh
wasm-port/tests/browser/verify_interp_browser.sh
wasm-port/tests/host/verify_host_smokes.sh
wasm-port/tools/verify_vendor_sync.sh
wasm-port/tools/verify_no_standalone_cnc_semantics.sh
```
Completion criteria for this boundary phase
- Every vendored sim-config INI used by Node inventory has a machine-readable
runtime-boundary report.
- Hard blocked rows have a dependency-backed reason rather than path-only
classification.
- Safe representatives can declare HAL/UI process dependencies without being
mislabeled as full-process coverage.
- No blocked family is promoted until a LinuxCNC-owned runtime boundary exists
and is validated native, Node, and browser where appropriate.