Wiki · The Estate — root, plan and operator surfaces
HUD chaos + edge test matrix
The Estate — root, plan and operator surfaces · viewer/hud/tests/chaos_scenarios.md @ 44baf03d5041 (gen2-runtime) — opens the published snapshot ac338733bbba
1 value was removed from this page. Each one is marked in place as
[redacted: category] — 1 internal hostname. Nothing else was altered. The document is otherwise exactly as it is written in the repository, and the sha256 below is of the original, so what was ingested stays checkable.How to read this page
A Plain and a Clear version of this page have not been written yet. What follows is the document itself.
Precise — the source document
This is the document. Rendered from the repository at the commit above, with nothing rewritten for the web. A gate re-renders it on every deploy and fails the build if a single byte differs.
Companion doc to viewer/hud/hud_chaos.cjs. Each scenario is a real drill that
must be run and its verbatim log captured into
docs/receipts/hud_apocalypse_survival_<date>.md.
Chaos (running processes)
| Drill | Scenario | Green condition |
|---|---|---|
| T0 | 3 concurrent hud_watchdog.ps1 -MutexProbe |
Exactly 1 acquires HELD, 2 report BUSY, obs64 spawns = 0 |
| T1 | Stop-Process hud-server.exe -Force (or node hud_server.cjs) |
Watchdog restarts within IntervalSec (default 5 s); :8100 back up |
| T2 | nssm stop UNI-HUD |
Watchdog fallback leg takes over within IntervalSec |
| T3 | POST malformed body (empty, 10 MB, non-UTF-8, deeply nested JSON) | Server 400s cleanly, does not crash |
| T4 | Upstream :8090/api/mission returns 500 |
HUD renders "SOURCE UNREACHABLE" for that panel, other panels still render |
| T5 | Upstream :8096/api/gaia/drift returns malformed envelope |
HUD renders drift as "empty" honestly, does not crash |
| T6 | 100 concurrent /api/hud/snapshot polls |
Throughput >= 20 rps, p95 < 500 ms, no 5xx |
| T7 | Audience POST flood: 1000 rows/s x 30 s | Ring wraps cleanly, oldest evicted, process RSS stays flat |
Edge (unit-level)
- Ring buffer at exact cap boundary (N inserts, then N+1) -- covered by hud_ring_test.cjs
- Empty snapshot (all upstreams down) -- HUD renders "ALL SOURCES UNREACHABLE" and stays up
- Clock skew (system time jumps +/-10 min) -- ring monotonic guard covered by hud_ring_test.cjs
- Stub-mode fixture with malformed NDJSON row -- row skipped + counted (hud_fixtures_stub Stub.stats.skipped increments)
- Service account has no read on user's Documents -- HUD only reads from viewer/hud/ + via HTTP; verified LocalService can start
- Audience POST body at exact content-length limit; 1 byte over -- 413 payload-too-large
- Non-UTF-8 audience
text-- 400 code: text-not-utf8
Happy path (hand-driven)
- Cold boot Windows -> SCM starts
UNI-HUD->:8100binds within 30 s - Open
http://[redacted: internal-hostname]:8100/hudon a phone on the LAN -> page renders in < 2 s - Push 10 stub audience rows via
curl POST /api/hud/audience/publish-> all appear in feed within 3 s Stop-Process launcher-> HUD shows source unreachable for stack/journey panels within 6 s (2 polls) -> HUD stays up- Restart launcher -> HUD recovers within 6 s
Integration (in the 5-stage broadcast test)
- Stage 0 (PREFLIGHT_HUD):
verify_hud.cjsexit 0 asserts hud is bound + healthy + gates gate green - Add
hudhealth check tohealthChecks()incommand_center.cjsso stage 1 catches HUD-down
sha256 a8cf64de4d2333d7 — of the original file, so what was ingested stays checkable.