_Europe · 2026-09-14_
PL0069 stood on the "Accessing server" screen for 9.5 hours. The screen is left only by a state change, and after a failed server call none followed. A watchdog now returns the machine to the start screen when it has been on that screen for more than three minutes with no reason to be.
The AI/CCTV panel can show a grid with two red reference points that are placed exactly on the belt edges. It gives the technician a repeatable target for aligning the camera instead of judging by eye. The switch and the grid sit above the video, not behind it.
A service function sweeps one container along the belt and records every frame with its box. The recording is the data the size model is fitted to, so a re-calibration no longer depends on hand-measured single shots.
The tomrobots visitor login was sent on every machine, including ones that report to a third-party backend only. It is now sent only where the machine actually reports, which removes a pointless call and its error handling from those machines.
validContainer was set when the door closed instead of when it opened. A container that passed the door while the flow was already moving on was counted as rejected although it was accepted and in the bin. It is now set at door-open, where the decision is actually made.
The reference image for the blocked-door check was taken while the OpenCV library was not loaded, so every transaction start threw an UnsatisfiedLinkError and the check never had a reference. Loading and taking the image now run under the same setting, so either both happen or neither does.
A 46 MB GIF that nothing displayed made up 40 % of the APK. Removed; the installation package drops from 115 MB to 69 MB, which shortens every update over a thin line.
A five-second network hiccup cost PL0069 17 minutes out of service: the fault cleared after three seconds, but the machine only leaves FAULT on a state change, and the five-second check reported "normal" from then on, so no change ever came. A machine that has been in FAULT for more than three minutes while nothing is wrong now returns to the start screen on its own.
The maintenance screen always read TOMROBOTS. The name now comes from the build parameter brandName, and a machine whose backend sends settingsMap.brandingName in rvmInit uses that instead — so it can be set per installation without a new build.
The preview draws the calculated length and height next to each recognised container, as the Singapore installation does. A camera that measures wrong is visible on the spot instead of only in a rejected transaction.
The camera height is set to the measured 320 mm, and the panel reports the scale the grid implies, so an alignment can be checked against the 465 mm belt reference without a calculation. The width ratio itself is unchanged — the field data did not support the value the reference alone suggested.
Length and height were derived from a correction table that ignored how far a container stands off the belt. The Singapore pinhole model is now used, fitted to our own calibration run: each box edge is projected separately, so a tall container is no longer measured as a long one. Over the calibration set the error stays within 15 mm.
A DM code the database did not know was queried again and again — 86 times a second — which blocked the scan window, so the next container went in without being registered. An unknown code is now dropped after the first look, and if it carries an EAN that EAN is used. The code itself is kept on the attempt even where nothing checks it.
Type S means the code must be present, readable and known for this article; it is not blacklisted, so the same code may return any number of times. The check first accepted any readable code and then any listed one. It now demands both: a code was read, and the database pairs it with this barcode. N and B demand nothing.
A jammed compactor keeps turning at idle current and the machine keeps accepting containers into a bin that no longer takes any. The phase current is now watched around each accepted container; four in a row without a load peak produce a warning in the log and the audit log. Switched on per machine with enableCompactorMonitoring in the rvm init settings.
Every attempt image is written to disk and recorded for upload, but nothing ever collected what a restart left queued — PL0035 carried 17 such images. An idle pass now sends them, registers files no record knows about, and drops records whose file is gone.
The audit queue lived in memory only. A machine that was offline and then restarted lost everything waiting — PL0069 lost 9.5 hours of entries. The queue is now written to disk and restored at startup, and it is capped at 10,000 entries so a long outage cannot fill the storage.
Three threads take their work from the same table, so the same picture could be uploaded twice at once; whichever finished first deleted the file under the other. Uploads are now claimed per picture, with the claim expiring after five minutes so a callback that never arrives cannot hold a picture back for good.
An EWP registration printout was lost although the printer reported ready: the optional bottom logo was read from a ticket configuration that is not set on every machine, and the resulting error took the whole printout down. The same path carries the payment receipt. A missing logo now means a printout without a logo, and a printout that does not come out is reported to the log and the audit log instead of failing silently.
Every attempt ever posted reported NA for the DM code: the two fields were filled when the attempt was created and never updated, not even after a successful check. The attempt now carries whether a code was read and accepted, and the code itself, so it is visible in the dashboard.