Retire next-work item 3: the shared-services polish is closed as a set

Diagnostics run as an engine mode behind cool_diag_take/release, the
HTTP surface carries its accept caps with bounded camera setup
children, and the busy-state arbitration is declined with its reasoning
(CAMPAIGN-LOG has the proof runs and the two cross-check lessons the
queue taught). BRINGUP: the item closed, items 4 and up move down one.
This commit is contained in:
ScottW514
2026-08-31 15:13:08 -04:00
parent f4de5cdbfd
commit 99902a1579
2 changed files with 92 additions and 33 deletions
+17 -33
View File
@@ -355,7 +355,7 @@ factory 2.6.0-2228 session; measured numbers in the facts bank).
alike: the retrace is sized to `cnc/max_backtrack` and the lead follows it,
so a pause with little history behind it shortens both rather than failing.
GRBL mode uses feed hold / cycle start, so a resumed GRBL cut picks up where
the deceleration ended (item 10). A pause is not a cancel: the latch
the deceleration ended (item 9). A pause is not a cancel: the latch
stays unlocked and the window open across it. There is no resume dwell: the
safing chain re-arms ~216 ms before the first step (facts bank).
- **`lid_policy = hold`** selects stock grblHAL door behavior instead (park in
@@ -1110,35 +1110,19 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
reachable-mode reasoning and the factory fallback configuration are in
the headers of kernel patches 0011-0013 (`meta-glowforge-bsp`,
`recipes-kernel/linux/`).
3. **Shared machine services — remaining polish.** None of it blocking:
- **Diagnostics as engine modes.** The flow tools still drive the thermal
hardware themselves while the engine suspends its writes; the check
parameters are already shared (`cool.h`), so what remains is folding the
tools into the engine and retiring the suspend/resume dance.
- **Busy-state arbitration under one lock.** The idle/busy gates (`POST
/settings`, `/mode`, diagnostics start, upload/apply) each cross-check
`machine_is_idle()` and `update_job_running()` at their own call sites.
They fail closed and are drilled, but a single arbiter would close the
remaining request-interleaving windows by construction.
- **HTTP surface caps.** An explicit `MHD_OPTION_CONNECTION_LIMIT` plus a
per-IP cap is the right hardening (a 500-connection flood plateaued at 379
fds under the raised 4096 `RLIMIT_NOFILE`, no crash), and the camera
`ensure_engine` `popen()`s should move out of the HTTP callback so a slow
media-ctl cannot stall the request thread. Changing the MHD start flags
touches the streaming model, so this wants a bench slot of its own.
4. **Physical-evidence negatives still open.** A present head answering I²C
3. **Physical-evidence negatives still open.** A present head answering I²C
badly (the K-11 runtime case) and a failed head capture leaving the measure
laser off — both need the head connected and a fault injected. Opportunistic:
`STATE_FAULT` recovery via `enable` the next time a DRV8825 fault line
actually trips.
5. **Debug-kernel checks.** Module load/unload under `CONFIG_DEBUG_MUTEXES`
4. **Debug-kernel checks.** Module load/unload under `CONFIG_DEBUG_MUTEXES`
and a forced `-EPROBE_DEFER` unwind still need a debug kernel build. Both
drills cycle what the rail policy avoids: a module unload powers the 40 V
rail off (a stepper driver can come out of the power-up unserviceable),
and a forced defer needs the 40 V regulator or the SDMA device unbound
under the module's probe. This is a bench slot with the rail-cycle gamble
accepted, not a quick check.
6. **Release acceptance follow-through.** The campaign is the release gate
5. **Release acceptance follow-through.** The campaign is the release gate
and runs as designed: dev image `20260824230512`, 45 of 45 from nothing,
36 of them unattended with the bench actuator in the loop, release
authorized (the export is on the board at `/data/forgetest/export/`).
@@ -1154,16 +1138,16 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
stay host-side by design, and the registry marks them so. The deferred
emulator homing-image smoke is tool work here too, now that the
emulator can be pointed at live snapshots. The first
release is item 7.
7. **Publish.** The first release: `releases/v<version>/acceptance.json`
release is item 6.
6. **Publish.** The first release: `releases/v<version>/acceptance.json`
from the authorized export, `scripts/release.sh`, the kas flip and the
first GitHub release, per the site (Developers, "Release flow"), once
ready to publish. Repoint the core submodule to
upstream if the `step_us_min` sizing fix merges.
8. **Update system Phase 5 — recovery refresh.** The remaining phase of
7. **Update system Phase 5 — recovery refresh.** The remaining phase of
`docs/UPDATE-SYSTEM.md` (a refreshed recovery image in boot0); Phases 0–4
are done.
9. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not
8. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not
gating).** The EV_SW `head` bit (GPIO3_22, factory pad HEAD_IRQ) is the head
MCU's attention line — idle LOW with a healthy head, pulsing on head reboot,
floating to the SoC pull-up with no head — so the raw level is not a
@@ -1179,7 +1163,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
log EV_SW head-bit edges plus `head/beam_detect_digital|_analog` while
firing.
10. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark
9. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark
in the cut. With laser mode on, the core stops the beam at the start of the
hold (`disable_laser_during_hold`, on by default), so the head travels the
whole deceleration dark, and the resume re-accelerates from a standstill at
@@ -1213,7 +1197,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
line does to it, and how it composes with the armed window's disarm grace
across a long hold.
11. **Head crash and rail-contact detector (planned).** The head
10. **Head crash and rail-contact detector (planned).** The head
accelerometer is the motion-liveness probe and nothing more; the
factory runs two tiers off the same sensor (a per-axis alert that
pauses, a per-axis abort), and its thresholds arrive in every pulse
@@ -1225,7 +1209,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
are established. A pause on contact, on the factory's shape, would be
the first use.
12. **A sender change while a job runs: discussion.** Today a sender that
11. **A sender change while a job runs: discussion.** Today a sender that
disconnects mid-job leaves the motion running to the end of what the
controller holds, with the window closed and fire suppressed (the
consent belonged to the displaced session), so the job finishes dark
@@ -1242,9 +1226,9 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
a hold parks the head over hot material with the assist air on the run
profile, and the grace then closes the window in Hold as it does today;
running on leaves a clean stop position but wastes the piece. Decide
with the gapless pause and resume item (10), which owns the resume
with the gapless pause and resume item (9), which owns the resume
mechanics.
13. **The flow check while the tube is lit.** The arm-time heater check
12. **The flow check while the tube is lit.** The arm-time heater check
starts at the session open, so with a prompt press the tube is lit
for most of its window, and a lit CW window adds about 1.5 C to the
rise (0.5 C at 45 % density) against a 1.6 C margin; on top of that the
@@ -1277,7 +1261,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
remains; a scope on the two sensor lines during a cut is the next
instrument. It sits inside the ceiling's 2 C hysteresis and the flow
check reads means, so it is a measurement item, not a gate item.
14. **Laser power-good: what the line means.** `cnc/laser_pgood` and its
13. **Laser power-good: what the line means.** `cnc/laser_pgood` and its
sampled count are defined in the UAPI (active low, one sample every
~3.9 ms), the facts bank records that the sampled count reads 0 through
real cutting, and the cooling engine warns
@@ -1289,7 +1273,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
scope against `hv_current` through an armed cut, its meaning written
into the facts bank and the UAPI, and then either a warning that means
something or no warning.
15. **Initial commissioning: measure and set the machine's own numbers
14. **Initial commissioning: measure and set the machine's own numbers
methodically.** Every tunable that was measured on the bench machine
and shipped as a default varies from machine to machine: the flow
check's bands and `cool_flow_rise`, the tube's heat coefficients
@@ -1325,8 +1309,8 @@ covers the warm-up hold), the supply temperature window (the service sends
the whole ADC range and the factory binds it to nothing; the supply is
watched per job instead), the head, lid, interconnect and fused temperature
ceilings (no sensor at those locations; the chassis is watched per job), the
head accelerometer thresholds (item 11), the lid IR thresholds (the fire
head accelerometer thresholds (item 10), the lid IR thresholds (the fire
watch runs on local knobs; the header values stay ignored), the
HV current caps (the sampled emission witness covers the idle case, and HV
current is ranged per job), the thermal report upload conditions and the
pump flag. Beam detect stays with item 9.
pump flag. Beam detect stays with item 8.
+75
View File
@@ -4888,6 +4888,58 @@ the watch read `armed` at OK. A first run failed only on its own log
check racing rsyslog by a second; the checks now poll the tail
(forgefirm 678a155).
## 2026-08-31: the shared-services polish, closed as a set
The three leftovers of the 2026-08-13 consolidation are done or decided
(forgectrl c930b41 and 4d3abd4, pinned in forgefirm 78c40ef).
**Diagnostics as an engine mode.** A tool owns the thermal hardware
between `cool_diag_take` and `cool_diag_release`: take succeeds only
from an idle engine, every write goes through guarded engine helpers
(one owner; the air-assist writes now ride the tracked path, so the
coolant-offset correction stays true through a diagnostic), the tick
publishes phase `diag` and touches nothing, and the release reasserts
the idle posture in one place. The polled suspend/resume dance and the
tool's own attribute writers are gone. The tools keep their airflow
profile exactly as the flow bands were characterized: exhaust and
intake at the run duty, the air assist untouched.
**HTTP surface caps.** The daemon starts MHD through ulfius'
with-options call with the flags ulfius computes reproduced verbatim,
plus a 64-connection ceiling and 16 per client address, so a flood is
bounded at the accept side. The first deploy taught the call's footgun:
the option array must carry ulfius' own connection plumbing
(`mhd_request_completed`, `ulfius_uri_logger`, both externalized for
this call), or the dispatcher answers every request with MHD's internal
error - the bench caught it inside a minute and the fix rode the next
deploy. The camera pipeline's setup children (media-ctl, v4l2-ctl) run
in their own process groups under a 10 s deadline and are killed past
it: a wedged V4L2 pipeline costs one bounded error, never a pinned
request thread. Moving the setup out of the callback entirely was
considered and not taken: the bound removes the hazard at a fraction
of the risk.
**Busy-state arbitration, declined.** With diagnostics folded into the
engine, the remaining idle/busy gates (`POST /settings`, `/mode`,
upload/apply) are independent 409 checks that fail closed and are
drilled; a single arbiter would rearrange them without closing a
reachable window, so it is not built.
The proof ran on the hot-deployed board through three passes of the
unattended queue plus a directed set. Along the way the queue itself
caught two rigid cross-checks the day's gates had introduced (a start
gate pinned under the ceiling refused the gate-off trip leg, a TEC off
threshold pinned above the floor refused the floor leg's raised floor);
both relations came out in favor of the bench patterns, with the
engine's runtime behavior as the enforcement (forgectrl de1f755 and
c77f040). The final queue ran 9 of 9 green (the always core,
floor-and-warm-up, tec-drive, critical-tier, fan-gate-trips), with
flow-verify, aa-offset-calibrate, gate-off and fans-quiet-after-motion
green earlier in the same campaign through the folded diagnostics, and
the directed set - panel-serves, snapshot, sensor-profile, h264-stream,
frame-health, lid-privacy - green on the capped server with the bounded
setup children.
## Superseded status notes
### Shared machine services — remaining polish, as listed 2026-08-13
@@ -6556,6 +6608,29 @@ Items 7 and up move down one.
`max-frequency = <25000000>` on `&usdhc1` (halves Wi-Fi throughput — last
resort; the factory ran 50 MHz on these pads).
### Shared machine services, remaining polish (item 3), closed 2026-08-31
Closed: the diagnostics fold and the HTTP caps are implemented and
bench-proven, the arbitration is declined with its reasoning (the
entry above). Items 4 and up move down one.
3. **Shared machine services — remaining polish.** None of it blocking:
- **Diagnostics as engine modes.** The flow tools still drive the thermal
hardware themselves while the engine suspends its writes; the check
parameters are already shared (`cool.h`), so what remains is folding the
tools into the engine and retiring the suspend/resume dance.
- **Busy-state arbitration under one lock.** The idle/busy gates (`POST
/settings`, `/mode`, diagnostics start, upload/apply) each cross-check
`machine_is_idle()` and `update_job_running()` at their own call sites.
They fail closed and are drilled, but a single arbiter would close the
remaining request-interleaving windows by construction.
- **HTTP surface caps.** An explicit `MHD_OPTION_CONNECTION_LIMIT` plus a
per-IP cap is the right hardening (a 500-connection flood plateaued at 379
fds under the raised 4096 `RLIMIT_NOFILE`, no crash), and the camera
`ensure_engine` `popen()`s should move out of the HTTP callback so a slow
media-ctl cannot stall the request thread. Changing the MHD start flags
touches the streaming model, so this wants a bench slot of its own.
## Reference notes
### Head-IRQ source validation — the beam-emission hypothesis