Keep backup safe.
A battery gets told to send power to the grid. What if that instruction arrives twice?
Each square is one simulated battery.
Without safeguards
…
Preparing the experiment
With safeguards
…
Preparing the experiment
Loading the experiment…
Simulated batteries. Recorded Texas prices. No real batteries are controlled.
Restart evidence Loading saved checks…
A worker restarts and receives the same instruction. Does it act twice?
| Crash point | No durable receipt | Durable receipt | Retry decision |
|---|
An uncertain receipt pauses this command. That can miss delivery. This tests real process exits with a fake actuator, not hardware or power loss.
Engineer details
Dispatch means telling a battery when to charge or send power to the grid. This replay compares those instructions under simulated failures.
Loading the recorded ERCOT day…
Choose the experiment
All batteries: assumed 25 kWh / 5 kW. Initially at reserve. Failure exposure is seeded (42), so runs repeat exactly. Failure window: 4–10 PM. These are simulated devices, not Base equipment.
Same day. Four policies.
Preparing the replay…
The guard checks command identity, expiry, fresh telemetry, and local backup reserve. The unguarded comparison has physical power and capacity limits, but omits those four checks. The clock baseline also omits those checks.
| Policy | Cash proxy | Inventory mark | Adjusted proxy | Exported | Reserve breaches |
|---|
Cash proxy = hourly exports minus imports at the recorded hub price. Inventory mark values the change in stored energy at the last hour's price, after discharge losses. Adjusted proxy includes that mark; it is not executed revenue or a customer bill saving. Compare both money and the remaining energy.
Schedule versus delivery
Power at the grid connection: positive exports, negative imports. Hourly kWh equals average kW for these one-hour intervals.
PlannedDelivered
Every device has a trace
Each row is one simulated battery; each column is one hour. Select a device to inspect its command ledger.
| Arrived (HE) | Scheduled (HE) | Attempt | Requested | Applied | Stored after | Outcome |
|---|
What this experiment establishes
It tests an inspectable command contract in a small deterministic replay. A fleet or markets engineer could use this shape of test to compare the cost of conservative dispatch with violations caused by a faulty command path.
Open the model, fault rules, and limits
- Price planning reuses Megawatt's corrected single charge-then-discharge optimizer. Known day-ahead prices are an idealized supplied schedule input, not a real-time forecast. The timing-error case is synthetic.
- Physical losses split equally between charge and discharge: each leg uses the square root of round-trip efficiency. Hourly power, stored energy, and reserve are enforced independently in replay.
- For exposed devices, lost ACKs duplicate commands once; delays move commands two hours; telemetry ages from the last report at 3 PM. Commands expire after their scheduled hour. The guard holds when telemetry is over one hour old.
- Idempotency is held in memory. This hourly replay has no real workers, networks, durable queues, authentication or batteries. The separate restart fixture uses actual local child processes and SQLite with a synthetic actuator. Neither is a production controller.
- One recorded day and identical devices do not establish annual performance. No home load, outages, market impact, tariffs, degradation, ancillary services, settlement rules, or Base control logic are modeled. Reserve breaches here mean scheduled grid dispatch consumed reserved energy.
Independent work, not affiliated with Base Power. Inspired by the September 2026 hackathon and Base's public telemetry engineering post. No claim of having entered or won.