Commit 34c5974d by PLN (Algolia)

design: the Go Live wizard, and where an alert has to land

Detection stopped being the problem at 6a94b47b. What failed on 2026-09-24 is
that every dot was green and nobody was looking at any of them: at T-2 the
eyes are on Pulsar and the hands are on the LCXL, and neither surface said a
word. So this is attention routing, not checking.

Three principles, then the shape. One source of truth (check-gig --json; no
surface grows its own check). An alert lands on the surface the eyes are
already on, which is a different surface at T-30, T-5 and T-2. And a wizard
is ordered and blocking where a dashboard is neither: one blocker, its fix,
a re-check of that ONE probe because the full gate costs 16 s and a
16-second wait per fix is how a wizard gets skipped.

It never converges on its own. Arming a track, raising a fader and saving are
things only PLN's hands in Ardour can do, and a tool that edits the session
he is performing from is a tool that fights him.

Also records the one alert that earns the right to interrupt a set - Ardour
not recording while Tidal plays - and pins it to the FILES lens, because the
OSC surface claimed arm:false for all 76 minutes it was actually recording.

Three open questions left for PLN rather than answered here: which surface
the T-2 alert lands on, whether an at-my-own-risk skip is acceptable, and
how long the during-set silence window is. The last one needs one rehearsal,
not an opinion.

Retention and the Mix audit are marked done in the belt-and-braces list, and
Tidal 08 is ticked: PLN armed it at 17:38 and the saved session now reads
rec-enable=1 on all twelve.
parent 674c3b0b
# Design: the "Go Live" wizard, and where an alert has to land
**Status**: proposal, PLN's call on the three open questions at the bottom.
**Asked for**: PLN, 2026-09-25, after arming `Tidal 08` by hand:
*"indeed ardour t8 was not armed. done. how to alert for me in the 'Go Live'
Wizard/GUI? we def need to design"*.
## The problem is not detection any more
As of `6a94b47` the rig can detect an unarmed orbit. `check-mix.py --arm`
reads the saved session, `check-gig.py` carries it as a blocking probe, and
the Bridge renders the result. Nothing was missing on the detection side
after that commit.
What is still missing is the part that failed on 2026-09-24: **every dot was
green, and nobody was looking at any of them.** The gate existed. The Bridge
existed. The set still lost 17m44s and a whole orbit, because at T-2 minutes
PLN's eyes are on Pulsar and his hands are on the LCXL, and neither of those
surfaces said a word.
So this is an attention-routing problem, not a checking problem. Three
principles fall out of it.
### 1. One source of truth, many renderers
`check-gig.py --json` is the only thing that decides GO or NO-GO. No surface
grows its own copy of a check. This is already true of the Bridge GATE panel
(`dd851bc`) and it stays true of everything below. The 2026-08-02 lesson
holds: a check with two owners is a check that quietly disagrees with itself.
### 2. An alert lands on the surface the eyes are already on
| When | Eyes are on | So the alert goes to |
|------|-------------|----------------------|
| T-30 min, setup | the terminal running `gig-up` | the wizard (below) |
| T-5 min, patching | the Bridge, on the second screen | the GATE panel (exists) |
| T-2 min, hands down | the LCXL and Pulsar | the OLED, and a Pulsar notification |
| during the set | the code | nothing, except one thing (below) |
A dashboard on a screen nobody is watching is not an alert. It is a log.
### 3. A wizard is ordered and blocking; a dashboard is neither
The GATE panel shows 43 rows at once, which is the right shape for "what is
the state of this rig". It is the wrong shape for "I have four minutes, what
do I do first". A wizard shows **one blocker, its fix, and a re-check**, and
does not let you past it.
## The wizard
`tools/gig-up.sh --converge` already ends by calling the gate. Today that
prints a table and a verdict. The proposal is that on a non-zero verdict it
enters a loop instead:
```
NO-GO - 1 blocker
[1/1] ardour armed
Tidal 08 is NOT ARMED. That orbit records no stem.
In Ardour: click the record button on Tidal 08, then Ctrl+S.
(This reads the session as last SAVED, so the save is the fix.)
[enter] re-check [s] skip, at my own risk [q] quit
```
Four properties, each paying for something measured:
- **One at a time, ordered by cost of being wrong.** An unarmed orbit costs a
stem you find out about the next day. A closed fader costs a sound you can
hear going missing while you play. The first is worse and goes first.
- **Re-check the ONE probe, not the gate.** `check-mix.py --arm` takes about
0.2 s; the full gate takes about 16 s, and a 16-second wait per fix is how a
wizard gets skipped.
- **Skipping is allowed, and recorded.** A gate that cannot be overridden gets
worked around, and then it is not a gate. `[s]` writes the skip into the
gig-log so the next morning's reconstruction knows it was a choice.
- **It never converges on its own.** The wizard does not arm the track, raise
the fader, or save the session. Every fix above is a thing only PLN's hands
in Ardour can do, and a tool that edits the session PLN is performing from
is a tool that fights him. (`gig_gate.mutations()` already fences this,
enforced by `test_check_gig.py`.)
## The surface alert (the belt to the wizard's braces)
The wizard is at T-30. The LCXL is in his hands at T-2, and it has an OLED and
96 LEDs. The proposal, smallest version that works:
- on a NO-GO, the driver paints **one** button red and writes the single
highest-cost blocker to OLED row 3, truncated to what fits.
- one press of that button re-runs the gate and repaints.
- on GO, the button goes green and row 3 returns to its normal job.
Cost: the driver already owns the OLED and the LED painter, and
`reference_lcxl3-oled-repaint` records how to write it without ghosting. It
needs the gate's verdict, which is a JSON read, not a new check.
## The one alert that runs DURING the set
Everything above is pre-flight. Exactly one thing deserves to interrupt a
performance, and it is the thing that cost 17m44s: **Ardour is not recording
while Tidal is playing.**
The detector, stated precisely because a wrong one is worse than none:
- fires when the gig-log has seen an `eval` **and** the files lens shows no
byte growth in any `Tidal NN` stem for N seconds.
- keys on the **files lens only**. Ardour's OSC surface reported
`arm:false roll:false` for all 76 minutes it was actually recording on the
24th, with `conflict:true` on every `rec` record (see item 7 in
`2026-09-25-post-gig-belt-and-braces.md`). A reminder built on OSC would
have nagged through a perfectly good take, which is how a reminder gets
muted forever.
- surfaces once, then goes quiet. A repeating alarm during a set is worse
than the thing it is warning about.
## What is already built, so it is not re-litigated here
| Thing | Commit | State |
|-------|--------|-------|
| `check-mix --arm`, blocking probe | `6a94b47` | done |
| Bridge GATE panel | `dd851bc` | done, needs a Bridge restart to appear |
| black box unit + target check | `83ced8f`, `c6d298e` | done, unit not linked yet |
| `check-mix --mix` (Mix capture track) | `7a88f1d` | done, the track itself is PLN's call |
| `gig_record.sh prune` + gate advisory | `674c3b0` | done |
## Open questions (PLN's call)
1. **Where does the T-2 alert go: the OLED, or a Pulsar notification, or
both?** The OLED cannot be missed but holds about 15 characters. Pulsar
holds a paragraph and is now polite about it (`3a24802`), but it is one
window among his tabs.
2. **Is `[s] skip` acceptable?** The alternative is a gate that only advises,
which is what we had on the 24th.
3. **How long is N** for the during-set reminder? 30 s is two tracks' worth of
silence at worst; 120 s is a third of a track. Neither is obviously right
without measuring one rehearsal.
...@@ -27,18 +27,32 @@ Each line pays off a `TODO_GIG` "NOT TONIGHT" entry or a loss measured in ...@@ -27,18 +27,32 @@ Each line pays off a `TODO_GIG` "NOT TONIGHT" entry or a loss measured in
laptop card while Master was hand-linked to the UMC. laptop card while Master was hand-linked to the UMC.
- [x] **5. Tableau de bord.** The Bridge should render `check-gig.py --json`, - [x] **5. Tableau de bord.** The Bridge should render `check-gig.py --json`,
not grow a bespoke "armed" tile. One source of truth. not grow a bespoke "armed" tile. One source of truth.
- [ ] **6. `recordings/` has no retention.** The black box writes ~72 MB/hour of - [x] **6. `recordings/` has no retention.** Done `674c3b0`: `gig_record.sh
opus, gitignored. A rehearsal week is >5 GB and the >500 MB rule bites prune [DAYS]`, dry by default, `--yes` to delete, 14-day window. Never
after one. Decide the policy — keep N days, or prune once a take is in the segment the recorder holds open (read from `/proc/PID/fd`, not
`../Prod/` — before it is a surprise. Nothing deletes anything today, guessed from mtime), never a `slice_*` you cut on purpose. No timer and
which is the safe half of the problem. no `ExecStopPost`: an automatic sweep is the one mechanism that could
delete the take nobody meant to keep. The gate advises at 500 MB and
names the command.
- [ ] **7. Ardour's OSC arm lens is broken** — `arm:false roll:false` for 76 - [ ] **7. Ardour's OSC arm lens is broken** — `arm:false roll:false` for 76
recorded minutes, `conflict:true` on every record. Find out whether the recorded minutes, `conflict:true` on every record. Find out whether the
OSC surface is even enabled before anything reads it. A REC reminder must OSC surface is even enabled before anything reads it. A REC reminder must
key on the FILES lens only. key on the FILES lens only.
- [ ] **8. Propose, PLN's call:** a `Mix` track inside Ardour (input = - [~] **8. A `Mix` track inside Ardour** (input `Master/audio_out 1+2`, armed)
`Master/audio_out 1+2`, armed) so the mix lands in the same take at stem so the mix lands in the same take at stem grade. Solves "one orbit
grade. Solves "one orbit unarmed", not "forgot REC". unarmed", not "forgot REC".
The AUDIT is built (`7a88f1d`): `check-mix.py --mix` exits 4 when there
is no such route and prints the 30-second Add Track recipe; once it
exists it blocks on the four ways it can be present and useless, the
first being an output still wired to Master, which is a feedback loop
through the PA and is what you get by following Ardour's own dialog and
stopping. Two gate probes, ADVISE for absent and BLOCK for broken.
The TRACK itself is PLN's, in Ardour, by hand. Deliberately not scripted:
hand-editing the one session this rig performs from, to save thirty
seconds of clicking, is a screw with no nut — and Ardour's Add Track
allocates the ids, playlist and diskstream correctly.
--- ---
...@@ -47,9 +61,12 @@ Each line pays off a `TODO_GIG` "NOT TONIGHT" entry or a loss measured in ...@@ -47,9 +61,12 @@ Each line pays off a `TODO_GIG` "NOT TONIGHT" entry or a loss measured in
Commits `ce66317` · `6a94b47` · `187b17c` · `83ced8f` · `dd851bc`. Commits `ce66317` · `6a94b47` · `187b17c` · `83ced8f` · `dd851bc`.
Log: `armada/tasks/049-four-green-lights-and-a-dead-lens.md`. Log: `armada/tasks/049-four-green-lights-and-a-dead-lens.md`.
- [ ] **Arm `Tidal 08` in Ardour, then Ctrl+S.** The gate says NO-GO until you - [x] **Arm `Tidal 08` in Ardour, then Ctrl+S.** Done by PLN 2026-09-25 17:38.
do. Same pass: raise the nine faders sitting at −∞ and save, so the Verified in the saved session: all 12 orbits read `rec-enable="1"`, and
session boots the mix you play. `check-mix.py --arm` exits 0 for the first time.
- [ ] **Raise the nine faders sitting at −∞ and save**, so the session boots
the mix you play. Not a bug (see `project_ardour-faders-are-post-gig`) —
just where the hands were at the last save.
- [ ] **`systemctl --user restart gig-log`.** The rebind only helps a reader - [ ] **`systemctl --user restart gig-log`.** The rebind only helps a reader
started after it. The current one is still holding the dead subscription started after it. The current one is still holding the dead subscription
from the 24th — `tools/gig-log.py status` now says so in words. from the 24th — `tools/gig-log.py status` now says so in words.
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment