Review story 1.5: provisioning execution passes all ACs — Epic 1 complete
Fix portal.py error handling so validate_cache failures return retry HTML while kill_wifi ProvisioningError propagates (re-raise) per AC4. All 56 tests pass. Update sprint-status.yaml: 1-5 → done, epic-1 → done. Append story 1.5 deferred items to deferred-work.md. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -54,3 +54,32 @@ Description: Nominatim geocoding verified in tests with mocks only; real geocodi
|
||||
Story: `1-4-location-resolution-icao-and-address`
|
||||
Category: Technical debt
|
||||
Description: ICAO heuristic (`len(query) == 4 and query.isalpha()`) may misclassify 4-letter words (e.g. "BATH", "YORK") as ICAO codes, causing them to be looked up in `airports.csv` before falling back to Nominatim. Acceptable for MVP given the provisioning context, but noted for future hardening (e.g. validate against a known ICAO prefix list).
|
||||
|
||||
---
|
||||
|
||||
## Story 1.5: Provisioning Execution — Tile Download, Cache Validation & WiFi Kill
|
||||
|
||||
### [1-5] nmcli / NetworkManager dependency
|
||||
Story: `1-5-provisioning-execution-tile-download-cache-validation-and-wifi-kill`
|
||||
Category: Infrastructure/environment
|
||||
Description: `nmcli` requires NetworkManager to be installed and running on the Pi; the `wlan0` interface must support managed mode. Raspberry Pi OS Lite uses `dhcpcd` by default — NetworkManager must be installed and enabled before `join_home_wifi()` will work.
|
||||
|
||||
### [1-5] rfkill permission requirement
|
||||
Story: `1-5-provisioning-execution-tile-download-cache-validation-and-wifi-kill`
|
||||
Category: Infrastructure/environment
|
||||
Description: `rfkill block wifi` requires the process to have permission to block the WiFi interface. The user running the provisioning service must be root or have the `CAP_NET_ADMIN` capability. The systemd unit must be configured accordingly.
|
||||
|
||||
### [1-5] OSM tile download and OpenAIP API runtime verification
|
||||
Story: `1-5-provisioning-execution-tile-download-cache-validation-and-wifi-kill`
|
||||
Category: Runtime verification
|
||||
Description: OSM tile download, OpenAIP API call, and the full provisioning sequence (WiFi join → tile download → airspace download → validate → write config → rfkill) can only be end-to-end verified on device with real network access. All tests use mocks only.
|
||||
|
||||
### [1-5] provision.py port 80 requires root
|
||||
Story: `1-5-provisioning-execution-tile-download-cache-validation-and-wifi-kill`
|
||||
Category: Infrastructure/environment
|
||||
Description: `provision.py` calls `app.run(port=80)` which requires root privileges or the `CAP_NET_BIND_SERVICE` capability to bind to a port below 1024. The systemd unit for the provisioning service must run as root or be granted the appropriate capability.
|
||||
|
||||
### [1-5] Synchronous POST /submit — browser waits during provisioning
|
||||
Story: `1-5-provisioning-execution-tile-download-cache-validation-and-wifi-kill`
|
||||
Category: Technical debt
|
||||
Description: The `POST /submit` handler is fully synchronous — the browser connection stays open while tile download, airspace download, and cache validation complete (potentially 2–5 minutes). This is acceptable for MVP but a streaming response (using `flask.stream_with_context` or a background thread with server-sent events) would improve UX by allowing the browser to render progress feedback without holding an open connection.
|
||||
|
||||
Reference in New Issue
Block a user