Retire next-work item 3: the debug-kernel drills passed

Load/unload under DEBUG_MUTEXES (three clean cycles) and the forced
-EPROBE_DEFER unwind both passed on the debug-kernel image, no lock
splat, machine recovered (CAMPAIGN-LOG has the run). BRINGUP: the item
closes, items 4 and up move down one.
This commit is contained in:
ScottW514
2026-08-31 16:43:54 -04:00
parent 2319735e60
commit a3127c29cd
2 changed files with 56 additions and 22 deletions
+15 -22
View File
@@ -355,7 +355,7 @@ factory 2.6.0-2228 session; measured numbers in the facts bank).
alike: the retrace is sized to `cnc/max_backtrack` and the lead follows it, alike: the retrace is sized to `cnc/max_backtrack` and the lead follows it,
so a pause with little history behind it shortens both rather than failing. so a pause with little history behind it shortens both rather than failing.
GRBL mode uses feed hold / cycle start, so a resumed GRBL cut picks up where GRBL mode uses feed hold / cycle start, so a resumed GRBL cut picks up where
the deceleration ended (item 8). A pause is not a cancel: the latch the deceleration ended (item 7). A pause is not a cancel: the latch
stays unlocked and the window open across it. There is no resume dwell: the stays unlocked and the window open across it. There is no resume dwell: the
safing chain re-arms ~216 ms before the first step (facts bank). safing chain re-arms ~216 ms before the first step (facts bank).
- **`lid_policy = hold`** selects stock grblHAL door behavior instead (park in - **`lid_policy = hold`** selects stock grblHAL door behavior instead (park in
@@ -1115,14 +1115,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
reachable-mode reasoning and the factory fallback configuration are in reachable-mode reasoning and the factory fallback configuration are in
the headers of kernel patches 0011-0013 (`meta-glowforge-bsp`, the headers of kernel patches 0011-0013 (`meta-glowforge-bsp`,
`recipes-kernel/linux/`). `recipes-kernel/linux/`).
3. **Debug-kernel checks.** Run the module load/unload and forced 3. **Release acceptance follow-through.** The campaign is the release gate
`-EPROBE_DEFER` drills (`scripts/bench/debug_kernel_drills.py`) on the
debug-kernel image (`kas/forgefirm-glowforge-debug.yml`, built beside the
closing image). Both cycle the 40 V rail: a module unload powers it off (a
stepper driver can come out of the power-up unserviceable), and the forced
defer needs the 40 V regulator unbound under the probe. It is a bench slot
with the rail-cycle gamble accepted, and it rides the closing burn.
4. **Release acceptance follow-through.** The campaign is the release gate
and runs as designed: dev image `20260824230512`, 45 of 45 from nothing, and runs as designed: dev image `20260824230512`, 45 of 45 from nothing,
36 of them unattended with the bench actuator in the loop, release 36 of them unattended with the bench actuator in the loop, release
authorized (the export is on the board at `/data/forgetest/export/`). authorized (the export is on the board at `/data/forgetest/export/`).
@@ -1138,16 +1131,16 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
stay host-side by design, and the registry marks them so. The deferred stay host-side by design, and the registry marks them so. The deferred
emulator homing-image smoke is tool work here too, now that the emulator homing-image smoke is tool work here too, now that the
emulator can be pointed at live snapshots. The first emulator can be pointed at live snapshots. The first
release is item 5. release is item 4.
5. **Publish.** The first release: `releases/v<version>/acceptance.json` 4. **Publish.** The first release: `releases/v<version>/acceptance.json`
from the authorized export, `scripts/release.sh`, the kas flip and the from the authorized export, `scripts/release.sh`, the kas flip and the
first GitHub release, per the site (Developers, "Release flow"), once first GitHub release, per the site (Developers, "Release flow"), once
ready to publish. Repoint the core submodule to ready to publish. Repoint the core submodule to
upstream if the `step_us_min` sizing fix merges. upstream if the `step_us_min` sizing fix merges.
6. **Update system Phase 5 — recovery refresh.** The remaining phase of 5. **Update system Phase 5 — recovery refresh.** The remaining phase of
`docs/UPDATE-SYSTEM.md` (a refreshed recovery image in boot0); Phases 0–4 `docs/UPDATE-SYSTEM.md` (a refreshed recovery image in boot0); Phases 0–4
are done. are done.
7. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not 6. **Head-IRQ source validation — beam-emission hypothesis (exploratory, not
gating).** The EV_SW `head` bit (GPIO3_22, factory pad HEAD_IRQ) is the head gating).** The EV_SW `head` bit (GPIO3_22, factory pad HEAD_IRQ) is the head
MCU's attention line — idle LOW with a healthy head, pulsing on head reboot, MCU's attention line — idle LOW with a healthy head, pulsing on head reboot,
floating to the SoC pull-up with no head — so the raw level is not a floating to the SoC pull-up with no head — so the raw level is not a
@@ -1163,7 +1156,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
log EV_SW head-bit edges plus `head/beam_detect_digital|_analog` while log EV_SW head-bit edges plus `head/beam_detect_digital|_analog` while
firing. firing.
8. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark 7. **Gapless pause and resume in GRBL mode (planned).** A pause leaves a mark
in the cut. With laser mode on, the core stops the beam at the start of the in the cut. With laser mode on, the core stops the beam at the start of the
hold (`disable_laser_during_hold`, on by default), so the head travels the hold (`disable_laser_during_hold`, on by default), so the head travels the
whole deceleration dark, and the resume re-accelerates from a standstill at whole deceleration dark, and the resume re-accelerates from a standstill at
@@ -1197,7 +1190,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
line does to it, and how it composes with the armed window's disarm grace line does to it, and how it composes with the armed window's disarm grace
across a long hold. across a long hold.
9. **Head crash and rail-contact detector (planned).** The head 8. **Head crash and rail-contact detector (planned).** The head
accelerometer is the motion-liveness probe and nothing more; the accelerometer is the motion-liveness probe and nothing more; the
factory runs two tiers off the same sensor (a per-axis alert that factory runs two tiers off the same sensor (a per-axis alert that
pauses, a per-axis abort), and its thresholds arrive in every pulse pauses, a per-axis abort), and its thresholds arrive in every pulse
@@ -1209,7 +1202,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
are established. A pause on contact, on the factory's shape, would be are established. A pause on contact, on the factory's shape, would be
the first use. the first use.
10. **A sender change while a job runs: discussion.** Today a sender that 9. **A sender change while a job runs: discussion.** Today a sender that
disconnects mid-job leaves the motion running to the end of what the disconnects mid-job leaves the motion running to the end of what the
controller holds, with the window closed and fire suppressed (the controller holds, with the window closed and fire suppressed (the
consent belonged to the displaced session), so the job finishes dark consent belonged to the displaced session), so the job finishes dark
@@ -1226,9 +1219,9 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
a hold parks the head over hot material with the assist air on the run a hold parks the head over hot material with the assist air on the run
profile, and the grace then closes the window in Hold as it does today; profile, and the grace then closes the window in Hold as it does today;
running on leaves a clean stop position but wastes the piece. Decide running on leaves a clean stop position but wastes the piece. Decide
with the gapless pause and resume item (8), which owns the resume with the gapless pause and resume item (7), which owns the resume
mechanics. mechanics.
11. **The flow check while the tube is lit.** The arm-time heater check 10. **The flow check while the tube is lit.** The arm-time heater check
starts at the session open, so with a prompt press the tube is lit starts at the session open, so with a prompt press the tube is lit
for most of its window, and a lit CW window adds about 1.5 C to the for most of its window, and a lit CW window adds about 1.5 C to the
rise (0.5 C at 45 % density) against a 1.6 C margin; on top of that the rise (0.5 C at 45 % density) against a 1.6 C margin; on top of that the
@@ -1261,7 +1254,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
remains; a scope on the two sensor lines during a cut is the next remains; a scope on the two sensor lines during a cut is the next
instrument. It sits inside the ceiling's 2 C hysteresis and the flow instrument. It sits inside the ceiling's 2 C hysteresis and the flow
check reads means, so it is a measurement item, not a gate item. check reads means, so it is a measurement item, not a gate item.
12. **Laser power-good: what the line means.** `cnc/laser_pgood` and its 11. **Laser power-good: what the line means.** `cnc/laser_pgood` and its
sampled count are defined in the UAPI (active low, one sample every sampled count are defined in the UAPI (active low, one sample every
~3.9 ms), the facts bank records that the sampled count reads 0 through ~3.9 ms), the facts bank records that the sampled count reads 0 through
real cutting, and the cooling engine warns real cutting, and the cooling engine warns
@@ -1273,7 +1266,7 @@ Open items only. Anything closed is in `CAMPAIGN-LOG.md`.
scope against `hv_current` through an armed cut, its meaning written scope against `hv_current` through an armed cut, its meaning written
into the facts bank and the UAPI, and then either a warning that means into the facts bank and the UAPI, and then either a warning that means
something or no warning. something or no warning.
13. **Initial commissioning: measure and set the machine's own numbers 12. **Initial commissioning: measure and set the machine's own numbers
methodically.** Every tunable that was measured on the bench machine methodically.** Every tunable that was measured on the bench machine
and shipped as a default varies from machine to machine: the flow and shipped as a default varies from machine to machine: the flow
check's bands and `cool_flow_rise`, the tube's heat coefficients check's bands and `cool_flow_rise`, the tube's heat coefficients
@@ -1309,8 +1302,8 @@ covers the warm-up hold), the supply temperature window (the service sends
the whole ADC range and the factory binds it to nothing; the supply is the whole ADC range and the factory binds it to nothing; the supply is
watched per job instead), the head, lid, interconnect and fused temperature watched per job instead), the head, lid, interconnect and fused temperature
ceilings (no sensor at those locations; the chassis is watched per job), the ceilings (no sensor at those locations; the chassis is watched per job), the
head accelerometer thresholds (item 9), the lid IR thresholds (the fire head accelerometer thresholds (item 8), the lid IR thresholds (the fire
watch runs on local knobs; the header values stay ignored), the watch runs on local knobs; the header values stay ignored), the
HV current caps (the sampled emission witness covers the idle case, and HV HV current caps (the sampled emission witness covers the idle case, and HV
current is ranged per job), the thermal report upload conditions and the current is ranged per job), the thermal report upload conditions and the
pump flag. Beam detect stays with item 7. pump flag. Beam detect stays with item 6.
+41
View File
@@ -4979,6 +4979,33 @@ userspace i2c-dev serialize under the adapter lock, so flooding the bus
does not collide on the wire - the head reset is the reachable way to does not collide on the wire - the head reset is the reachable way to
make a present head answer badly. make a present head answer badly.
## 2026-08-31: the debug-kernel drills, on the lock-debugging image
Both drills passed on the debug-kernel image
(forgefirm-image-dev-debug-glowforge.rootfs-20260831203241, kernel
`DEBUG_MUTEXES=y PROVE_LOCKING=y LOCKDEP=y DEBUG_ATOMIC_SLEEP=y
DEBUG_SPINLOCK=y`, verified in /proc/config.gz).
**Load/unload.** forgectrl stopped, `glowforge.ko` unloaded and reloaded
three times with a rail-settle between; each cycle clean, and the kernel
log over the three carried no lock splat.
**Forced `-EPROBE_DEFER`.** The cnc device unbound, its 40 V regulator
(`regulators:40v` on `reg-fixed-voltage`) unbound, then cnc re-bound:
the probe deferred (cnc did not bind while the regulator was gone) and
its devm unwind left the log free of splats; restoring the regulator
let the deferred probe complete and cnc bind again.
The machine ended healthy: cnc idle, the GRBL controller running with
motion verified, the head present, and no BUG/WARNING/lockdep splat
anywhere after the first drill mark. Both drills cycle the 40 V rail (5
`40V on` events across the session) and the drivers came back each time.
Three bench facts hardened the drill in the running (forgefirm 2319735):
the splat filter ignores the benign lockdep boot banner, the regulator
search reaches the `reg-fixed-voltage` driver, and the idle gate waits
out the transient `running` a forgectrl restart passes through. The
debug image and the drill scripts were staged in `/tmp` and removed.
## Superseded status notes ## Superseded status notes
### Shared machine services — remaining polish, as listed 2026-08-13 ### Shared machine services — remaining polish, as listed 2026-08-13
@@ -6681,6 +6708,20 @@ was dropped by operator decision. Items 4 and up move down one.
injected: flood the head's bus from userspace while the driver talks, one injected: flood the head's bus from userspace while the driver talks, one
bench slot. bench slot.
### Debug-kernel checks (item 3), closed 2026-08-31
Closed: both drills passed on the debug-kernel image (the entry above);
the variant and the drill tool are in the tree. Items 4 and up move
down one.
3. **Debug-kernel checks.** Run the module load/unload and forced
`-EPROBE_DEFER` drills (`scripts/bench/debug_kernel_drills.py`) on the
debug-kernel image (`kas/forgefirm-glowforge-debug.yml`, built beside the
closing image). Both cycle the 40 V rail: a module unload powers it off (a
stepper driver can come out of the power-up unserviceable), and the forced
defer needs the 40 V regulator unbound under the probe. It is a bench slot
with the rail-cycle gamble accepted, and it rides the closing burn.
## Reference notes ## Reference notes
### Head-IRQ source validation — the beam-emission hypothesis ### Head-IRQ source validation — the beam-emission hypothesis