Week 15 · Build: Bounded recovery
Session 2 of 4 · React reliably · Phase 4
Plan about 15 minutes for explanation, 30 minutes for practical work and 10–15 minutes for documentation. A longer build may continue into the next session: stop safely, commit the current state and record the next check. Desktop simulations count as software evidence; label them clearly and record physical validation separately.
Engineering challenge
Can your robot respond to contact without becoming trapped in an endless recovery loop? This session focuses on bounded recovery.
Before you start
The previous week’s recorded baseline and Week 14, Improve. For later sessions this week, retain the preceding session’s files and predictions.
Equipment: Desktop Python, editor, paper and ruler; for physical work, the configured 3pi+ 2040, clear floor mat and hardware checklist. Week 3 additionally uses the separate low-voltage LED circuit described in its procedure.
For any motion, verify the stop button, short time limit and clear floor area first. Keep the wheels raised for a new device program until its commands and stop behaviour are checked. A hazard or uncertain input is a reason to stop and document, not to force the trial to finish.
Theory and mathematics
Bounded recovery
A recovery manoeuvre should first stop, then take a short verified action and reevaluate. Backing away can create a rear hazard because this robot has no rear bumper; perform it only in the cleared test enclosure and cap distance/time. A front contact is evidence about the front, not the full surroundings. Repeated recovery can trap the robot in a loop, so include a retry budget and a terminal failure state. Use software replay first to verify event priority and timeouts before enabling motor outputs.
Worked example — illustrative values
A state trace FORWARD → STOPPED → BACKUP → TURN → STOPPED can be checked without hardware. If backup is bounded to 0.2 s and turn to 0.3 s, the maximum planned moving recovery time is 0.5 s, but actual travel still depends on measured speed and stop response.
Write the calculation in your notebook before running code. State which values you measured, which you assumed and which the program calculates. A correct numerical calculation cannot rescue an incorrect physical assumption.
Run and explain the model
The following is desktop Python, not a ready-to-run motor program. Download this week’s example, save it in your student repository and run python3 code/w15.py from the repository root. The same small model is reused across the week so you can learn it, build with it, test it and revise it.
# Desktop Python teaching example. Numerical inputs are illustrative.
def next_state(state, event):
if event in {"operator_stop", "invalid", "timeout"}:
return "STOPPED"
transitions = {("FORWARD", "contact"): "STOPPED",
("STOPPED", "recover"): "BACKUP",
("BACKUP", "done"): "TURN",
("TURN", "done"): "STOPPED"}
return transitions.get((state, event), state)
state = "FORWARD"
for event in ["contact", "recover", "done", "operator_stop"]:
state = next_state(state, event)
print(event, state)
Run the example on desktop Python before adapting it. Change one valid input and check the result; keep device-only calls in a separate adapter. If an exception appears, read its final line, identify the input or assumption that caused it and make the smallest explained correction. Do not delete validation merely to obtain output.
Understanding the model and its limits
The transition lookup represents logical state changes only; it issues no motor commands or timing guarantees. A contact stops forward travel; a separately authorized recovery event enters BACKUP, then TURN, then STOPPED. Operator/invalid/timeout events override ordinary transitions. A physical implementation needs a latched stop, explicit rearm, bounded state durations and a verified clear recovery area; rear sensing is limited, so manual repositioning is the core alternative. Trace each event on paper and add the time/attempt guards before adapting any recovery movement. A state label alone does not make a procedure safe.
Practical instructions
- Implement the transition function as a pure desktop function.
- Keep elapsed-time checks and motor output in separate wrappers.
- Create a transition log with time,state,event,left_command,right_command.
- Require a retry budget and a final STOPPED/failed outcome when exhausted.
Experiment
Test normal, held-contact and exhausted-retry sequences. Count moving updates and verify each time/retry bound.
Before testing, record your prediction, changed factor, measured response, fixed conditions and stopping rule. Save every attempted run, including failures, with a condition and source version. If hardware is unavailable, use an explicitly labelled synthetic/replay dataset and list the physical question it cannot answer. Do not invent completed trials.
Deliverable
A deterministic transition function and retry-limited wrapper with a readable log.
Save notebook/w15-s2.md, the relevant code revision, raw CSV or test-case records, and one labelled diagram/plot/table. Link the files relatively from your notebook. Use the entry template and report guide.
Completion criteria
- Explain bounded recovery in your own words using this session’s example and its units/assumptions.
- Produce the specific evidence above: A deterministic transition function and retry-limited wrapper with a readable log.
- Keep predictions and raw outcomes, distinguish observations from interpretation, and explain one limitation or unresolved failure.
- Review the Git diff, commit the session’s intended files and state the next experiment or safe continuation point.
A documented failed prediction can meet the learning criteria. A missing physical trial must remain marked untested; software success alone does not validate the robot.
Reading and video
- Focused reading: Python tutorial: conditions and functions. Study task: Explain how a state variable and elapsed time select a transition.
- Video/lecture option: MathWorks: What is PID control?. Study task: Draw the closed-loop signal path and label the measured quantity. Watch a relevant 5–10 minute excerpt or use the linked notes if video is inaccessible. This is supporting conceptual material; hardware in a demonstration may differ from yours.
- Practical reference: Engineering handbook and hardware setup. Manufacturer/API references and video metadata were checked on 2026-10-09; recheck the actual firmware before transferring code.
Reflection and next step
Which assumption most affected your result? Point to one observation that supports your explanation and one alternative explanation the evidence has not ruled out. Write a specific next test with a changed factor and measurable outcome, then proceed through the week’s Learn → Build → Experiment → Improve cycle.