From 8ba998c3ef82d6f2d3fde4ff61b039e9ed1d2484 Mon Sep 17 00:00:00 2001 From: ScottW514 Date: Mon, 31 Aug 2026 15:43:26 -0400 Subject: [PATCH] Retire next-work item 3: the K-11 badly-answering head is proven A head reset (its own 0xc9<-0x5a register) made the present head NAK through its reboot; the witness reads errored (K-11 propagation) with no spoofed positive, and the head recovered on a driver rebind (CAMPAIGN-LOG has the drill). BRINGUP: the last physical-evidence negative closes, items 4 and up move down one. --- docs/BRINGUP.md | 36 ++++++++++++++++-------------------- docs/CAMPAIGN-LOG.md | 35 +++++++++++++++++++++++++++++++++++ 2 files changed, 51 insertions(+), 20 deletions(-) diff --git a/docs/BRINGUP.md b/docs/BRINGUP.md index 8454884..abb4db0 100644 --- a/docs/BRINGUP.md +++ b/docs/BRINGUP.md @@ -355,7 +355,7 @@ factory 2.6.0-2228 session; measured numbers in the facts bank). alike: the retrace is sized to `cnc/max_backtrack` and the lead follows it, so a pause with little history behind it shortens both rather than failing. GRBL mode uses feed hold / cycle start, so a resumed GRBL cut picks up where - the deceleration ended (item 9). A pause is not a cancel: the latch + the deceleration ended (item 8). A pause is not a cancel: the latch stays unlocked and the window open across it. There is no resume dwell: the safing chain re-arms ~216 ms before the first step (facts bank). - **`lid_policy = hold`** selects stock grblHAL door behavior instead (park in @@ -1115,18 +1115,14 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. reachable-mode reasoning and the factory fallback configuration are in the headers of kernel patches 0011-0013 (`meta-glowforge-bsp`, `recipes-kernel/linux/`). -3. **Physical-evidence negative still open.** A present head answering I²C - badly (the K-11 runtime case) needs the head connected and the fault - injected: flood the head's bus from userspace while the driver talks, one - bench slot. -4. **Debug-kernel checks.** Module load/unload under `CONFIG_DEBUG_MUTEXES` +3. **Debug-kernel checks.** Module load/unload under `CONFIG_DEBUG_MUTEXES` and a forced `-EPROBE_DEFER` unwind still need a debug kernel build. Both drills cycle what the rail policy avoids: a module unload powers the 40 V rail off (a stepper driver can come out of the power-up unserviceable), and a forced defer needs the 40 V regulator or the SDMA device unbound under the module's probe. This is a bench slot with the rail-cycle gamble accepted, not a quick check. -5. **Release acceptance follow-through.** The campaign is the release gate +4. **Release acceptance follow-through.** The campaign is the release gate and runs as designed: dev image `20260824230512`, 45 of 45 from nothing, 36 of them unattended with the bench actuator in the loop, release authorized (the export is on the board at `/data/forgetest/export/`). @@ -1142,16 +1138,16 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. stay host-side by design, and the registry marks them so. The deferred emulator homing-image smoke is tool work here too, now that the emulator can be pointed at live snapshots. The first - release is item 6. -6. **Publish.** The first release: `releases/v/acceptance.json` + release is item 5. +5. **Publish.** The first release: `releases/v/acceptance.json` from the authorized export, `scripts/release.sh`, the kas flip and the first GitHub release, per the site (Developers, "Release flow"), once ready to publish. Repoint the core submodule to upstream if the `step_us_min` sizing fix merges. -7. **Update system Phase 5 — recovery refresh.** The remaining phase of +6. **Update system Phase 5 — recovery refresh.** The remaining phase of `docs/UPDATE-SYSTEM.md` (a refreshed recovery image in boot0); Phases 0–4 are done. -8. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not +7. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not gating).** The EV_SW `head` bit (GPIO3_22, factory pad HEAD_IRQ) is the head MCU's attention line — idle LOW with a healthy head, pulsing on head reboot, floating to the SoC pull-up with no head — so the raw level is not a @@ -1167,7 +1163,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. log EV_SW head-bit edges plus `head/beam_detect_digital|_analog` while firing. -9. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark +8. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark in the cut. With laser mode on, the core stops the beam at the start of the hold (`disable_laser_during_hold`, on by default), so the head travels the whole deceleration dark, and the resume re-accelerates from a standstill at @@ -1201,7 +1197,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. line does to it, and how it composes with the armed window's disarm grace across a long hold. -10. **Head crash and rail-contact detector (planned).** The head +9. **Head crash and rail-contact detector (planned).** The head accelerometer is the motion-liveness probe and nothing more; the factory runs two tiers off the same sensor (a per-axis alert that pauses, a per-axis abort), and its thresholds arrive in every pulse @@ -1213,7 +1209,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. are established. A pause on contact, on the factory's shape, would be the first use. -11. **A sender change while a job runs: discussion.** Today a sender that +10. **A sender change while a job runs: discussion.** Today a sender that disconnects mid-job leaves the motion running to the end of what the controller holds, with the window closed and fire suppressed (the consent belonged to the displaced session), so the job finishes dark @@ -1230,9 +1226,9 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. a hold parks the head over hot material with the assist air on the run profile, and the grace then closes the window in Hold as it does today; running on leaves a clean stop position but wastes the piece. Decide - with the gapless pause and resume item (9), which owns the resume + with the gapless pause and resume item (8), which owns the resume mechanics. -12. **The flow check while the tube is lit.** The arm-time heater check +11. **The flow check while the tube is lit.** The arm-time heater check starts at the session open, so with a prompt press the tube is lit for most of its window, and a lit CW window adds about 1.5 C to the rise (0.5 C at 45 % density) against a 1.6 C margin; on top of that the @@ -1265,7 +1261,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. remains; a scope on the two sensor lines during a cut is the next instrument. It sits inside the ceiling's 2 C hysteresis and the flow check reads means, so it is a measurement item, not a gate item. -13. **Laser power-good: what the line means.** `cnc/laser_pgood` and its +12. **Laser power-good: what the line means.** `cnc/laser_pgood` and its sampled count are defined in the UAPI (active low, one sample every ~3.9 ms), the facts bank records that the sampled count reads 0 through real cutting, and the cooling engine warns @@ -1277,7 +1273,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`. scope against `hv_current` through an armed cut, its meaning written into the facts bank and the UAPI, and then either a warning that means something or no warning. -14. **Initial commissioning: measure and set the machine's own numbers +13. **Initial commissioning: measure and set the machine's own numbers methodically.** Every tunable that was measured on the bench machine and shipped as a default varies from machine to machine: the flow check's bands and `cool_flow_rise`, the tube's heat coefficients @@ -1313,8 +1309,8 @@ covers the warm-up hold), the supply temperature window (the service sends the whole ADC range and the factory binds it to nothing; the supply is watched per job instead), the head, lid, interconnect and fused temperature ceilings (no sensor at those locations; the chassis is watched per job), the -head accelerometer thresholds (item 10), the lid IR thresholds (the fire +head accelerometer thresholds (item 9), the lid IR thresholds (the fire watch runs on local knobs; the header values stay ignored), the HV current caps (the sampled emission witness covers the idle case, and HV current is ranged per job), the thermal report upload conditions and the -pump flag. Beam detect stays with item 8. +pump flag. Beam detect stays with item 7. diff --git a/docs/CAMPAIGN-LOG.md b/docs/CAMPAIGN-LOG.md index 88d7281..79b3ff0 100644 --- a/docs/CAMPAIGN-LOG.md +++ b/docs/CAMPAIGN-LOG.md @@ -4955,6 +4955,30 @@ recovery lever is documented in the UAPI; nothing is held open for it. What remains of the item is the K-11 runtime case, one bench slot with the head's bus flooded from userspace. +## 2026-08-31: the K-11 runtime case, a badly-answering present head + +The last physical-evidence negative, proven on the bench with the head +connected and the fault injected in software. The injection is the +head's own reset register (`0xc9` <- `0x5a`, forced past the bound +driver under the adapter lock): the MCU reboots, and through the reboot +window its I2C reads NAK - a present head answering badly, the one +condition unreachable with the head unplugged. A tight poll of the four +witness attributes (`beam_detect_analog`, `accel_irq`, `hall_sensor`, +`beam_detect_digital`) over the window took 3596 samples; 8 returned an +errno (the K-11 propagation: `head_read_bit_ascii` and +`head_read_dword_ascii` return the negative i2c result rather than +formatting a value), and none returned a spoof-shaped positive (the old +`beam_detect_analog=65531` / `accel_irq=1`). The head was restored by a +`glowforge_head` rebind (re-probe rewrites the lambda/theta calibration) +and recovered fully: witnesses read clean, `info` `id=044c`, +`head_probe: done` in dmesg, and forgectrl's `/status` `head: true`. +This closes item 3; the drill's script was staged in `/tmp` and removed. + +Note on injection: on the i.MX i2c adapter the kernel driver and +userspace i2c-dev serialize under the adapter lock, so flooding the bus +does not collide on the wire - the head reset is the reachable way to +make a present head answer badly. + ## Superseded status notes ### Shared machine services — remaining polish, as listed 2026-08-13 @@ -6646,6 +6670,17 @@ entry above). Items 4 and up move down one. media-ctl cannot stall the request thread. Changing the MHD start flags touches the streaming model, so this wants a bench slot of its own. +### Physical-evidence negatives (item 3), closed 2026-08-31 + +Closed: the failed-head-capture negative and the K-11 badly-answering +head are both proven (the entries above); the STATE_FAULT-recovery note +was dropped by operator decision. Items 4 and up move down one. + +3. **Physical-evidence negative still open.** A present head answering I²C + badly (the K-11 runtime case) needs the head connected and the fault + injected: flood the head's bus from userspace while the driver talks, one + bench slot. + ## Reference notes ### Head-IRQ source validation — the beam-emission hypothesis