Commit Graph
246 Commits
Author SHA1 Message Date
ScottW514 e232adbe4f BRINGUP: the hygiene-sweep binaries are installed on the bench 2026-08-15 06:50:10 -04:00
ScottW514 c985991cda Bump pins to the hygiene-sweep heads; record the sweep in BRINGUP
forgectrl ed2934b, grblHAL da4c8eb, forgefirm-app (gfhardware) 6c7534a -
all pushed and fetch-verified, license population checked for the
multi-license recipes.
2026-08-15 06:41:26 -04:00
ScottW514 0a05b6b114 docs: present-state build and update docs; fix the ring-size arithmetic
- kas/README.md: the real-time rationale rests on the feeder's bounded
  queue depth, not ring size; the ring is 16 MiB (~84 s at 200 kHz,
  ~28 min at the 10 kHz cloud tick), a capacity for cloud-mode preload.
- BUILD.md, kas config, release checklist, cold-build workflow: only
  forgefirm and meta-openglow (branch scarthgap) are cloned as
  siblings; every ForgeFIRM source repo is fetched by pinned SRCREV.
- UPDATE-SYSTEM.md reads as the present-state design: the cloud-mode
  compatibility baseline is the cloud client's configured firmware
  version, not release metadata; decisions and open items listed
  plainly.
- README.md states what GRBL mode still needs the Glowforge service
  for (camera-referenced homing) and what runs without it.
- BRINGUP.md: generic build-host and fwup-lab references, the retained
  reproductions of the no-fire drill, the System tab.
- LIGHTBURN.md: the arm-window timeouts are machine settings.
- forgefirm-image.bb describes forgectrl as the machine-services
  daemon and points at the right backlog entry.
- American spelling throughout.
2026-08-15 06:12:51 -04:00
ScottW514 ee25b89799 Bump grblHAL pin to b2cad8d (parked-state pacing fix) + pacing bench test
Pulls in the coarse-pacing fix for parked wait-for-operator states (a
machine left in Door or Hold no longer pins ~28% of the core), plus
P10's grblHAL CI/tests and the mlockall-root-only change. Fetch-verified.
Adds pacing_test.py (dry hold/resume + CPU measurement) and records the
diagnosis and bench validation in BRINGUP.
2026-08-14 22:06:46 -04:00
ScottW514 b18cb15072 Record G-4 and X-2 host unit tests closing the deferred bench items 2026-08-14 21:38:56 -04:00
ScottW514 55b940e702 Note forgectrl pin bump in the liveness-fix bench record 2026-08-14 21:18:18 -04:00
ScottW514 ea0642f942 Record live-fire drill results: emission witness, HV, lid-IR, X-3, G-10
Phase 5 A-1 emission witness and A-5 HV telemetry pass on live burns;
A-2 lid-IR characterized as a weak signal at 40% (gate left watch-only);
pgood confirmed unusable as a witness on this PSU. Phase 4 X-3 (0.1s
job-based disarm on M2) and G-10 (disarm counts down in Hold) pass.
Adds live_fire_drills.py (arm-lifecycle sampler over TCP + HTTP).
2026-08-14 21:14:57 -04:00
ScottW514 97a4cae346 Record GATE A closure: kernel drills pass, liveness guard defect found and fixed
K1/K2/K3 pass on image 20260814223300 with software witnesses
(fire_test A/B/U reproduce the scope-pinned reference); GATE A is
closed and live fire permitted. The campaign caught the liveness
probe's inverted doors-bit guard (forgectrl 424f185, hot-deployed,
probe live-verified MOTION OK).
2026-08-14 20:41:00 -04:00
ScottW514 3afd64dbc7 Add GATE A kernel drill script and lid-IR ambient baseline
gate_a_kernel_drills.py stages the three remaining GATE A kernel
drills (controlled-stop deceleration floor, resume waypoint with the
latch locked, mid-ramp latch unlock) with software witnesses and the
PSU-connector scope point. lid_ir_ambient_baseline.csv is the
fire-watch ambient anchor (600 samples, lid closed, machine idle);
BRINGUP records the baseline statistics and the idle verification of
the emission/fire/HV evidence plumbing.
2026-08-14 20:18:58 -04:00
ScottW514 572ee8a3d7 BRINGUP: record audit Phase 10 - the safety rules are CI-enforced
grblHAL CI runs the emission harness, the new armed-window lifecycle
harness, and the switch-map truth table on every push; forgectrl and
the kernel module build -Werror in CI. All three pipelines green.
2026-08-14 19:16:07 -04:00
ScottW514 2aa92bc63a BRINGUP: image 20260814223300 built - all audit rows aboard
Pins pushed/bumped/fetch-verified; built-image checks pass (locked
root on release, no watchdog daemon, logrotate, K-link order, pinned
kernel config, console-only DTB fallback, hardened glowforge.ko).
Bench campaign is next.
2026-08-14 18:48:17 -04:00
ScottW514 aee0d18baa BRINGUP: record audit Phase 9 - all image rows are complete
Build/BSP/release engineering landed; the image build + flash now
carries every kernel and image fix across all phases. Bench items
listed.
2026-08-14 18:23:59 -04:00
ScottW514 cbabf7d111 BRINGUP: record audit Phase 8 - the kernel rows are complete
All kernel/image fixes across the audit phases now wait on the one
image build + flash; Phase 8 bench items listed.
2026-08-14 17:53:57 -04:00
ScottW514 341c6399a0 BRINGUP: record audit Phases 6 and 7
Motion integrity (mid-run fault detection, homing-anchor lifecycle,
kernel ring/backtrack/fault-recovery hardening riding the image flash)
and cloud-mode robustness (fail toward stopped-and-safe, input clamps,
log hygiene); bench items listed.
2026-08-14 17:37:08 -04:00
ScottW514 e41b10d655 BRINGUP: record audit Phase 5 (physical-evidence instrumentation)
Emission witness, lid IR fire watch (watch-only until characterized),
faults/HV telemetry, measure-laser cleanup, and the head I2C error fix
(rides the pending image flash); bench items listed.
2026-08-14 17:12:03 -04:00
ScottW514 ea3fce2efd Record audit Phase 4; LIGHTBURN: the armed window is job-based
BRINGUP gains the Phase 4 (stale-gate cluster) record - code-complete,
host-verified, hot-deployable, bench drills listed. LIGHTBURN.md now
describes the job-based armed window: relock at program end, on a
sender change, or after the spindle-off grace (counting even in Hold).
2026-08-14 16:58:35 -04:00
ScottW514 daa76ca828 BRINGUP: record audit Phase 3 (broker ownership / dead-man second pass)
Code-complete and host-verified across forgectrl, the GRBL controller,
the cloud clients, and the kernel module; kernel rows ride the pending
image flash, bench drills listed.
2026-08-14 16:41:38 -04:00
ScottW514 e9443a60ef Keep debug-tweaks out of release images; harden the installer
- Move the passwordless-root debug-tweaks image feature out of the
  shared kas config into forgefirm-image-dev.bb, so the release
  forgefirm-image built from the same config is not passwordless-root.
  release.sh gains a gate that reads the built rootfs /etc/shadow and
  fails on an empty root password, plus a config-level guard that
  debug-tweaks is not present in the resolved kas dump. (B-1)
- The installer copies ffboot out of the signature-verified new rootfs
  it already mounts, instead of fetching and executing it from a mutable
  GitHub raw ref. (B-2)
- Record audit remediation Phase 2 (GATE B) status in BRINGUP.md,
  including the bench pass still required to close the gate.
2026-08-14 16:20:02 -04:00
ScottW514 cc927aca5f Add laser-safety and regulatory documentation; scrub bench identity
- LIGHTBURN.md: mandatory "Before you cut" safety section; the
  walkthrough now reflects the firing machine (dry runs need the
  layer output off or M5; live first-cut instructions); the homing
  entry documents homing_mode and the gfcloud method; the machine
  address is a placeholder.
- README.md: condensed safety section linking the full text and the
  regulatory notes.
- INSTALL.md: "Regulatory and legal" section ahead of the install
  steps; routine updates route through the panel updater rather than
  the installer.
- BRINGUP.md: the release signing key is described as held offline
  (no on-disk path); bench address and credential notes removed;
  Next-work item 7 corrected (the installer embeds the production
  release key); status entry for audit remediation Phases 0-1; the
  GATE A kernel drills join the pending image-flash checklist.
- bench scripts: the target host comes from GF_HOST (or argv) instead
  of a hardcoded address.
- laser_stream_test.py: per-session controller runs with a hermetic
  cooling-verdict publisher; new assertions that every stream
  terminates with FIRE clear (including M3 held to stream end) and
  that no FIRE bit rides a zero-step gap; a cycle-churn session
  exercises the stop/start seams.

Audit findings D-1, D-2, D-3, D-5, D-10, D-12, B-10, and the harness
half of D-4/G-1.
2026-08-14 15:38:24 -04:00
ScottW514 5dddea12ee docs: track the kernel platform-hygiene batch in BRINGUP
Add Next work item 9: the panic handler, control_12v removal, decay-mode
state tracking, module build hygiene, SDMA/EPIT/GPIO probe guards and
head_make_safe are code-complete and build-verified, with the bench check
each one still needs and a note that the batch ships with a full image
flash rather than a module hot-swap.

kas/README: drop the control_12v residue (the node is gone), state that
the buzzer driver is not part of ForgeFIRM, and record that the pre-SPDX
LICENSE strings remain only in layers this build does not use.
2026-08-13 15:41:09 -04:00
ScottW514 89ba97e310 docs: BRINGUP.md - safety mapping implemented; pin grblhal e616548, forgectrl e779554
The controller now maps the door pair and the interlock loop onto the core's
safety-door signal, with the e-stop bit behind a machine setting. Records what
is gated and what is deliberately not, the answer to the audit's latch-reset
question, and the bench items the change still needs.
2026-08-13 13:51:23 -04:00
ScottW514 08c83917af docs: BRINGUP.md - close the interlock readback and trip-recovery items
The interlock_circuit bitmask is fully mapped: b0/b1/b3 from the scope
experiment already recorded in the gate section, b2/b4 from the factory decode
the attributes were ported from, and the armed kill-mid-FIRE drills read the
mask consistently across armed, firing, idle and disarmed states. Trip recovery
was exercised in commissioning runs.

The safety-mapping item now says what is actually left of it: door and e-stop
evdev into the controller's feed-hold and halt path, plus the question of a
software reset path for the laser latch.
2026-08-13 13:40:54 -04:00
ScottW514 e92e500d91 docs: BRINGUP.md - no idle-rail-off in the rail item; forgectrl c099a28 2026-08-13 12:02:58 -04:00
ScottW514 2c1d73880a docs: BRINGUP.md - shared machine services closed out; forgectrl 96027b1
Record the finished shared-services state: forgectrl is the one
machine-services daemon behind both controller modes, both controllers
are cooling-engine clients, and the drill and soak coverage that proves
it. Attribute the cooling policy records to the engine's present home.
Add the remaining polish as Next work item 8 - diagnostics as engine
modes, the rail-policy remainder, cloud per-job fan profile
confirmation, /cool/status cosmetics, and button edge detection.
2026-08-13 12:00:01 -04:00
ScottW514 683511f563 BRINGUP: present-state sweep for the shared-services architecture
The runbook operational sections now describe the machine as it runs:
forgectrl as the machine-services daemon (supervisor, pulse-device
broker, motion-liveness gate, cooling engine, cameras), controllers
spawned and supervised rather than init-started, standalone driver
runs as the bench/debug exception, diagnostics suspending the active
controller through the supervisor, the cooling engine as the thermal
owner with the drivers as thin clients, and the new /mode and /cool
endpoints. A dated correction closes the no-motion record with the
DRV8825 wedge diagnosis and the liveness/homing hardening; the
cold-start section gains the first-light and shared-services
milestones.
2026-08-11 20:07:24 -04:00
ScottW514 1e3b2716b7 BRINGUP: DRV8825 rail-glitch wedge, accel liveness, probe direction
Hardware facts from the 2026-08-11 bench session: the DRV8825 drivers
can come out of a 40 V rail power-up unserviceable (playback and
counters run, motors dead; recovery is a longer true power-off, at
worst a machine power cycle) - so counters/anchors are never proof of
motion and the rail stays up. The head accelerometer is the motion
truth (device mapping, bench-characterized thresholds, read-rate
limits), and every probe move goes +X first - a cable lives at the
end of left travel.
2026-08-11 20:01:24 -04:00
ScottW514 6063b93683 BRINGUP: first GRBL-mode burn landed 2026-08-11 2026-08-11 16:58:40 -04:00
ScottW514 1c1830ae8d grblhal: bump to b7264bf (40V rail settle); BRINGUP: no-motion root cause record 2026-08-11 16:46:28 -04:00
ScottW514 3c095ccbd1 laser milestone: grblhal SRCREV -> 09bc882, host stream test, docs
BRINGUP item 2: grbl-mode laser software implemented + bench-verified
without fire (record in the gate list); first light pending.
LIGHTBURN.md: arming/button-press operation, S-max 1000, fire gates.
scripts/bench/laser_stream_test.py: host-side stream-dump contract
verification against the null-sink build.
2026-08-09 16:13:03 -04:00
ScottW514 25f2721500 forgectrl: wireless radio-policy revision; runbook: regulatory record
Bump to the forgectrl revision whose startup pass reloads
regulatory.db (required while the flashed kernel still has built-in
cfg80211 - its boot-time load fails pre-mount and stays failed
without a reload), hints a region only when one is set (unset =
automatic: the AP's 802.11d country, else world; a 00 hint over the
kernel's own world default reports the confusing intersection alias
"country 98"), and pins wlan0 power save off.

BRINGUP.md: bench record for the wireless-regulatory diagnosis and
the live-verified wifi_country / power-save flow; the kernel-batch
note now carries CFG80211/MAC80211=m, DEFAULT_PS off, and the lm75
vs-supply.
2026-08-08 16:51:06 -04:00
ScottW514 419710ef4b installer: production release-signing key
The embedded pubkey is the production key from the signing ceremony;
release.sh's key-match gate now refuses any other signer. Verified:
production-signed archives pass fwup 1.16 and the factory's 0.14.2;
dev-signed archives are rejected.
2026-08-08 13:48:39 -04:00
ScottW514 96c96b63c6 docs: decision-gate statuses; key-ceremony procedure defined (gate 8) 2026-08-08 13:38:50 -04:00
ScottW514 6c418bfb92 docs: no bench-machine identity in public documents; re-pin forgectrl
The runbook no longer records the bench machine's fuse identity (a
fuse identity cannot be rotated, so a public document must never
carry it); the forgectrl pin follows that repo's history rewrite.
2026-08-08 13:37:22 -04:00
ScottW514 4f13d8a43f docs: panel rework live-verified; fuse identity confirmed on hardware 2026-08-08 13:27:59 -04:00
ScottW514 d8dfdcdd18 docs: bench back on SD dev; Can't-open-blockdev root cause pinned 2026-08-08 13:14:50 -04:00
ScottW514 42a01940f1 docs: Phase 2 slot install bench-proven end-to-end 2026-08-08 13:05:28 -04:00
ScottW514 b9a63e677f docs: fuse-identity viewer in the offline-verified panel record 2026-08-08 12:49:39 -04:00
ScottW514 6c9cce3184 gfhome: derive the service hostname from the effective serial
The gf_hostname override is gone (the forgectrl UI no longer offers
it): the hostname is a pure derivation of the serial - base 23 over
the factory consonant alphabet - so a gf_serial override re-derives
MACHINE.HOSTNAME and the fuse derivation stands otherwise. BRINGUP
records the panel rework (units, fuse identity, always-on position)
as offline-verified; board deploy and pin bumps held during the
firmware-upgrade bench testing.
2026-08-08 12:44:56 -04:00
ScottW514 5035b2744e docs: TEC ships on Pro per published specs, not verified per unit
Basic/Plus share the passive closed-loop cooling and the 60-75 F
window per Glowforge's tech specs and owners-forum consensus; the
Pro's solid-state TEC buys 60-81 F. Spec-level only - tec_present
stays a user setting regardless, since tec_on has no readback.
2026-08-08 12:18:11 -04:00
ScottW514 55fdaebf69 docs: Phase 1 (ffboot v2) complete and hardware-verified 2026-08-08 12:14:37 -04:00
ScottW514 63dffdc596 docs: laser-milestone specs for low-temp gates/warm-up and TEC handling
Low side: factory floors (CM* window minimums ~1-4 C, the ~16 C
'warming up' operating floor) and the planned cool_temp_min /
cool_temp_start keys with a heater-driven warm-up phase. TEC:
presence is undetectable (tec_on is write-only, Pro-only hardware on
a common board) so tec_present becomes a user setting, with
hysteresis control toward the factory ~18 C setpoints when enabled.
2026-08-08 12:11:57 -04:00
ScottW514 3fdb0c1636 docs: bench eMMC slot contents (ffboot -l probe)
Slot 1 = factory 20240612194245 (newest, the factory-archive
candidate), slot 2 = factory 20220810204015, legacy p4 = ForgeFIRM
v0.1.0. Factory /etc/version is a numeric datetime stamp.
2026-08-08 12:10:46 -04:00
ScottW514 9d410c646a docs: Phase 0 of the update system complete and hardware-verified
Slot-agnostic boot proven on the bench: the same release ext4 boots
from SD and from eMMC p4 steered by the saved env alone. fwup
cross-version compatibility proven; slot-sized rootfs, size gate,
ext4 artifact and mkfw.sh in place. Found for Phase 1: the image
ships no /etc/fw_env.config.
2026-08-08 12:01:45 -04:00
ScottW514 b7eb5fdac5 docs: cooling GUI + diagnostics; bump forgectrl and grblhal
BRINGUP: the conf-backed cooling tunables, the Diagnostics runner
model and both cooling tools, and the 2026-08-08 bench record
(conf re-read drill, takeover semantics, flow-verify PASS 2:42,
flow-calibrate 8:45 recommending 14.8 vs the hand-derived 14.4).
Pins: forgectrl -> 86ff78b (Machine-tab cooling card + Diagnostics
tab + diag runner), grblhal -> ae85682 (cool_* conf keys re-read
per flood start).
2026-08-08 11:48:15 -04:00
ScottW514 2aac59e0e4 image: slot-sized release rootfs, ext4 artifact, fwup, mkfw.sh
The release image now targets the 200 MiB factory eMMC slot: content
plus 40 MiB working space, hard build failure past the slot size. The
raw ext4 is deployed alongside the wic; scripts/mkfw.sh packs it into
a signed .fw with factory-pattern upgrade.a/upgrade.b tasks. fwup
1.16.0 recipe (applies ForgeFIRM and Glowforge-signed archives on
device) is installed in both images. Dev images stay SD-sized with a
256 MiB working margin and no ceiling.

Verified on the 20260808153331 build: release ext4 180.8 MiB; signed
.fw applies byte-exact with fwup 1.16.0 and with the factory's 0.14.2
(raw-format pubkey), and 0.14.2 -V verifies the signature.
2026-08-08 11:37:19 -04:00
ScottW514 888e51d84e docs: eMMC boot/recovery architecture + install/update system plan
BRINGUP: the measured eMMC map (factory MBR, U-Boot in boot0 at 1KiB,
saved env at user-area 0x80000/0x82000, default-env recovery boot, the
boot0/boot1 recovery images, factory .fw/fwup internals) and the traced
SD kernel-load path.

UPDATE-SYSTEM: phased plan for the factory A/B slot scheme end-to-end -
fwup-packaged signed releases, single-stage installer, GUI update
manager, offline factory restore, legacy-p4 migration, recovery
refresh; invariants and decision gates.
2026-08-08 11:34:08 -04:00
ScottW514 af3a693c0b bench+docs: flow suspicion drills, coolant-flow triage record
flow_confirm_drill.py walks the driver's suspicion/confirmation state
machine through every verdict with real pump-off transients in one M8
session; flow_escalate_drill.py exercises the starved-re-check
escalation against a short GFCOOL_CONFIRM_MAX_S. BRINGUP records the
triage resolution (the 2026-08-03 faults were a real transient
stagnation, probable pump airlock - the check was right), the slug/
circulation measurements, and the new check semantics.
2026-08-08 10:59:47 -04:00
ScottW514 3ba1d9c769 docs: SD images 20260808011035 built 2026-08-07 21:12:39 -04:00
ScottW514 2f1cb88452 docs: mode selector + idle settings lock in the panel runbook 2026-08-07 20:56:49 -04:00
ScottW514 85914c16d0 Bump forgectrl (remote-interlock semantics); bench model + interlock facts in the runbook 2026-08-07 20:48:26 -04:00