Commit Graph
158 Commits
Author SHA1 Message Date
ScottW514 d8dfdcdd18 docs: bench back on SD dev; Can't-open-blockdev root cause pinned 2026-08-08 13:14:50 -04:00
ScottW514 0f5dec57e9 probes: reuse existing slot mounts; explicit -t ext4
The image's fstab keeps the factory slots mounted under /factory, and
busybox mount's auto-type iteration against an already-mounted ext4
device provokes a cosmetic kernel 'Can't open blockdev' for each
foreign-type claim (reproduced and pinned on the bench: ext3-typed
mount of an ext4-held device prints it; ext4-typed does not). Probes
now reuse an existing mountpoint from /proc/mounts and mount fresh
targets with an explicit -t ext4.
2026-08-08 13:13:20 -04:00
ScottW514 42a01940f1 docs: Phase 2 slot install bench-proven end-to-end 2026-08-08 13:05:28 -04:00
ScottW514 9c1d0c5073 INSTALL.md: single-stage slot install flow
Documents the new installer: A/B slot install with no repartitioning,
factory archives to /data, signature-verified forgefirm.fw, ffboot
switching, offline install, and the automatic legacy-layout
migration.
2026-08-08 13:04:58 -04:00
ScottW514 cea0439e17 slotmigrate: sector counts from sysfs; log to kmsg
The image's busybox has no blockdev applet, so the grow path silently
skipped. Sector counts now come from /sys/class/block (no external
tool); log lines also go to /dev/kmsg so migration results are visible
in dmesg after boot.
2026-08-08 12:59:21 -04:00
ScottW514 63792a8ed2 installer: select the fw_env config the way ffboot does
Newer factory firmware's generic /etc/fw_env.config points at the
wrong device; its per-device /etc/fw_env_mmcblk2.config is the correct
one for the eMMC environment. The read-back verify caught the failed
write and aborted before the flip, as designed.
2026-08-08 12:55:13 -04:00
ScottW514 39a973df02 installer: live progress for the archive steps
dd|gzip runs backgrounded while the installer prints compressed MB
every few seconds (old busybox dd has no status=progress); dd's exit
status is captured through a file so a device read failure is not
masked by gzip succeeding on truncated input.
2026-08-08 12:53:33 -04:00
ScottW514 b9a63e677f docs: fuse-identity viewer in the offline-verified panel record 2026-08-08 12:49:39 -04:00
ScottW514 6c9cce3184 gfhome: derive the service hostname from the effective serial
The gf_hostname override is gone (the forgectrl UI no longer offers
it): the hostname is a pure derivation of the serial - base 23 over
the factory consonant alphabet - so a gf_serial override re-derives
MACHINE.HOSTNAME and the fuse derivation stands otherwise. BRINGUP
records the panel rework (units, fuse identity, always-on position)
as offline-verified; board deploy and pin bumps held during the
firmware-upgrade bench testing.
2026-08-08 12:44:56 -04:00
ScottW514 882a1b1b2d installer: probe slots under /tmp; tolerate offline ffboot refresh
Newer factory firmware (2024) has no /factory/imgN mounts and a
read-only rootfs, so slot probing and post-write verification mount
under /tmp, with the active slot read from the running root. The
target-slot unmount sweeps /proc/mounts (older firmware DOES mount the
slots). A failed ffboot download keeps an existing /data/ffboot
instead of aborting, so a local-.fw install works fully offline.
2026-08-08 12:43:17 -04:00
ScottW514 1097184e13 installer v2: single-stage slot install; slotmigrate legacy reclaim
install-forgefirm.sh is now single-stage and never repartitions: run
from factory firmware, it archives every factory slot version plus the
recovery boot partitions to /data/forgefirm/archive (manifest with
md5s), verifies the signed forgefirm.fw against the embedded ForgeFIRM
pubkey (raw 32-byte form for the factory's fwup 0.14.2; dev key until
the production key ceremony), applies it to the INACTIVE slot with the
factory's own fwup, post-verifies the written rootfs, installs
/data/ffboot, and flips the saved env with read-back verification. The
booted factory slot stays installed and bootable; /data is untouched
beyond the archive. Fixed release asset name forgefirm.fw (version in
the fwup metadata and release tag).

slotmigrate (new recipe, rcS before mountall) reclaims the legacy
layout on eMMC-slot boots: deletes p4, grows p3 to the end of the
disk (sfdisk + partx BLKPG - works with a sibling partition as root),
then e2fsck+resize2fs. Every step is keyed off the actual disk state,
so interrupted runs resume and factory-layout disks are a no-op; SD
boots never touch the eMMC.
2026-08-08 12:26:33 -04:00
ScottW514 5035b2744e docs: TEC ships on Pro per published specs, not verified per unit
Basic/Plus share the passive closed-loop cooling and the 60-75 F
window per Glowforge's tech specs and owners-forum consensus; the
Pro's solid-state TEC buys 60-81 F. Spec-level only - tec_present
stays a user setting regardless, since tec_on has no readback.
2026-08-08 12:18:11 -04:00
ScottW514 55fdaebf69 docs: Phase 1 (ffboot v2) complete and hardware-verified 2026-08-08 12:14:37 -04:00
ScottW514 63dffdc596 docs: laser-milestone specs for low-temp gates/warm-up and TEC handling
Low side: factory floors (CM* window minimums ~1-4 C, the ~16 C
'warming up' operating floor) and the planned cool_temp_min /
cool_temp_start keys with a heater-driven warm-up phase. TEC:
presence is undetectable (tec_on is write-only, Pro-only hardware on
a common board) so tec_present becomes a user setting, with
hysteresis control toward the factory ~18 C setpoints when enabled.
2026-08-08 12:11:57 -04:00
ScottW514 3fdb0c1636 docs: bench eMMC slot contents (ffboot -l probe)
Slot 1 = factory 20240612194245 (newest, the factory-archive
candidate), slot 2 = factory 20220810204015, legacy p4 = ForgeFIRM
v0.1.0. Factory /etc/version is a numeric datetime stamp.
2026-08-08 12:10:46 -04:00
ScottW514 11fec891ed ffboot v2: slot inventory, verified atomic env flips, target probe
-l inventories every bootable partition (SD, eMMC slots 1/2, legacy
p4) as machine-parsable key=value lines: firmware type
(forgefirm/factory), version, kernel presence, booted/next markers,
plus the saved-env selection - the shared probe for the installer and
the forgectrl update manager.

Boot switching now writes all four selection variables (mmcdev,
mmchwpart, mmcpart, mmcroot) in one fw_setenv -s transaction and
read-back verifies, falling back from the libubootenv script format
to the classic u-boot-tools format to per-variable writes - the same
script works on factory firmware and ForgeFIRM. mmchwpart was
previously never set and a mixed env could survive a mid-flip power
cut. Switch targets must pass a content probe (rootfs mounts, kernel
present) unless -f. -e picks the newest factory slot by probing,
excluding slots occupied by ForgeFIRM.

The new ffboot recipe installs it as /usr/sbin/ffboot with
/etc/fw_env.config (factory-identical redundant env layout at eMMC
0x80000/0x82000) - previously the image shipped fw_setenv with no
config. Added to forgefirm-image.
2026-08-08 12:08:14 -04:00
ScottW514 9d410c646a docs: Phase 0 of the update system complete and hardware-verified
Slot-agnostic boot proven on the bench: the same release ext4 boots
from SD and from eMMC p4 steered by the saved env alone. fwup
cross-version compatibility proven; slot-sized rootfs, size gate,
ext4 artifact and mkfw.sh in place. Found for Phase 1: the image
ships no /etc/fw_env.config.
2026-08-08 12:01:45 -04:00
ScottW514 b7eb5fdac5 docs: cooling GUI + diagnostics; bump forgectrl and grblhal
BRINGUP: the conf-backed cooling tunables, the Diagnostics runner
model and both cooling tools, and the 2026-08-08 bench record
(conf re-read drill, takeover semantics, flow-verify PASS 2:42,
flow-calibrate 8:45 recommending 14.8 vs the hand-derived 14.4).
Pins: forgectrl -> 86ff78b (Machine-tab cooling card + Diagnostics
tab + diag runner), grblhal -> ae85682 (cool_* conf keys re-read
per flood start).
2026-08-08 11:48:15 -04:00
ScottW514 2aac59e0e4 image: slot-sized release rootfs, ext4 artifact, fwup, mkfw.sh
The release image now targets the 200 MiB factory eMMC slot: content
plus 40 MiB working space, hard build failure past the slot size. The
raw ext4 is deployed alongside the wic; scripts/mkfw.sh packs it into
a signed .fw with factory-pattern upgrade.a/upgrade.b tasks. fwup
1.16.0 recipe (applies ForgeFIRM and Glowforge-signed archives on
device) is installed in both images. Dev images stay SD-sized with a
256 MiB working margin and no ceiling.

Verified on the 20260808153331 build: release ext4 180.8 MiB; signed
.fw applies byte-exact with fwup 1.16.0 and with the factory's 0.14.2
(raw-format pubkey), and 0.14.2 -V verifies the signature.
2026-08-08 11:37:19 -04:00
ScottW514 888e51d84e docs: eMMC boot/recovery architecture + install/update system plan
BRINGUP: the measured eMMC map (factory MBR, U-Boot in boot0 at 1KiB,
saved env at user-area 0x80000/0x82000, default-env recovery boot, the
boot0/boot1 recovery images, factory .fw/fwup internals) and the traced
SD kernel-load path.

UPDATE-SYSTEM: phased plan for the factory A/B slot scheme end-to-end -
fwup-packaged signed releases, single-stage installer, GUI update
manager, offline factory restore, legacy-p4 migration, recovery
refresh; invariants and decision gates.
2026-08-08 11:34:08 -04:00
ScottW514 75e0eb24da Bump grblhal (flow suspicion state machine) 2026-08-08 10:59:47 -04:00
ScottW514 af3a693c0b bench+docs: flow suspicion drills, coolant-flow triage record
flow_confirm_drill.py walks the driver's suspicion/confirmation state
machine through every verdict with real pump-off transients in one M8
session; flow_escalate_drill.py exercises the starved-re-check
escalation against a short GFCOOL_CONFIRM_MAX_S. BRINGUP records the
triage resolution (the 2026-08-03 faults were a real transient
stagnation, probable pump airlock - the check was right), the slug/
circulation measurements, and the new check semantics.
2026-08-08 10:59:47 -04:00
ScottW514 548d25a4ff Bump forgectrl (firmware version in the panel) 2026-08-07 21:32:59 -04:00
ScottW514 8baed9aa93 images: version stamp in /etc, shown at console and SSH login
Every image writes /etc/forgefirm-version and echoes "ForgeFIRM
<version>" on the serial-console login prompt (/etc/issue, beneath the
OpenGlow banner) and at SSH login (motd). Release images carry
v${FORGEFIRM_RELEASE}; the dev image stamps the build timestamp - the
same DATETIME as the artifact name - tagged (dev) so a bench machine
is never mistaken for a release.
2026-08-07 21:19:50 -04:00
ScottW514 3ba1d9c769 docs: SD images 20260808011035 built 2026-08-07 21:12:39 -04:00
ScottW514 4da39f6131 grblhal init: boot-time controller-mode dispatch
The init script consults controller_mode in /data/forgefirm.conf:
'cloud' (once that mode exists, with its own service reading the same
key) keeps grblHAL down; grbl, unset, or a missing config starts it.
Board-verified both ways: cloud in the conf leaves the controller
stopped with a clear message, grbl starts and serves normally.
2026-08-07 20:59:43 -04:00
ScottW514 2f1cb88452 docs: mode selector + idle settings lock in the panel runbook 2026-08-07 20:56:49 -04:00
ScottW514 607ceb32e7 Bump forgectrl (controller-mode selector, idle settings lock) 2026-08-07 20:56:16 -04:00
ScottW514 85914c16d0 Bump forgectrl (remote-interlock semantics); bench model + interlock facts in the runbook 2026-08-07 20:48:26 -04:00
ScottW514 4184e84558 Bump forgectrl and grblhal-glowforge to the OpenGlow-identity release
forgectrl ad0b441: OpenGlow branding, operational /status dashboard.
grblHAL-glowforge c472a13: position anchor at homing for the status
readers. Runbook updated.
2026-08-07 20:27:46 -04:00
ScottW514 bcf476be74 Bump forgectrl and grblhal-glowforge to the control-panel release 2026-08-07 20:06:17 -04:00
ScottW514 8cd98de605 gfhome: identity overrides from the shared config; budget from env
Non-empty gf_serial / gf_password / gf_hostname in /data/forgefirm.conf
(set from the forgectrl GF Cloud tab) are applied with set_cfg before
Machine() is built, so they beat the OCOTP fuse identity - Machine sets
its fuse values with keep_value. The --timeout default comes from
GFHOME_TIMEOUT_S when the controller provides it, so one GUI setting
governs the whole session. Docs: control-panel runbook notes.
2026-08-07 20:05:49 -04:00
ScottW514 8ba0ce84f3 docs: repos pushed and recipe pins bumped for the homing release 2026-08-07 19:29:54 -04:00
ScottW514 c1d781a137 Bump forgectrl and grblhal-glowforge to the homing release
forgectrl 0b05e48: /settings homing-mode store + UI, snapshot lamp
override. grblHAL-glowforge 948f1c7: runtime-selectable $H with the
Glowforge web-service homing session (stream suspend/resume, gfhome
runner orchestration).
2026-08-07 19:27:52 -04:00
ScottW514 bb3dedcd68 docs: live gfcloud homing verified; estop-during-motion hardware fact 2026-08-07 19:14:25 -04:00
ScottW514 cf24bf3200 gfhome: capture through forgectrl; factory-board machine config
The runner's Machine subclass fetches lid/head images from the
forgectrl snapshot endpoint - forgectrl owns the imx-media pipeline
whenever a stream client (LightBurn) is connected, so direct V4L2
grabs fail busy. Head captures request lamp=0 (the cloud's focus
analysis needs torch-off images); the HCil measure-laser LED is still
driven directly. Direct capture remains the fallback when the daemon
is unreachable.

The sample config gains the factory-board settings: the estop motion
gate stays off (the board's estop sense reads low during any motion),
and the forgectrl URL is configurable.
2026-08-07 19:13:28 -04:00
ScottW514 2108b9706b docs: homing runbook - gfcloud mode implemented, live run pending 2026-08-07 18:33:53 -04:00
ScottW514 f2a5d0f6b6 gfhome: one-shot Glowforge web-service homing runner
New recipe installing /usr/sbin/gfhome.py and /etc/gfhome.conf.sample
(copied to /data/etc/gfhome.conf on first run). The runner signs the
machine in with its fused identity, opens the WSS control channel with
a held client reference (a clean disconnect is impossible through
ws_connect), and drives the GFUIService dispatch table itself - minus
print - so the service's camera homing sequence (settings -> hunt ->
lid image -> corner move -> lid image) runs against the real hardware
Machine. The service ends the sequence silently, so completion is a
hunt plus at least one motion followed by a configurable quiet window;
the lens is then re-referenced against the hall sensor for a
deterministic Z. Lid/e-stop are checked before the session, print
actions are refused, and exit codes distinguish configuration and
connection failures from an incomplete homing.

Installed in both images; invoked by the grblHAL controller for $H
when homing_mode = gfcloud in /data/forgefirm.conf.
2026-08-07 18:32:53 -04:00
ScottW514 fcfa4e6d65 BRINGUP: whole-image boot verified on flashed SD - both services healthy from image binaries 2026-08-07 17:50:59 -04:00
ScottW514 ad865bb3c3 grblhal-glowforge SRCREV 683a36a (comment-free core fix); BRINGUP cites the fork commit hash-free 2026-08-07 17:42:53 -04:00
ScottW514 4d22905c2f grblhal-glowforge SRCREV bdab31c: core tracks upstream master (PR 999 merged) + step_us_min fix 2026-08-07 17:31:15 -04:00
ScottW514 b30afd7171 grblhal-glowforge SRCREV 26298a3: fd-blocking pacing, step_us_min fix, accel homing removed 2026-08-07 17:22:36 -04:00
ScottW514 d7f7318e5d BRINGUP: accelerometer homing retired - limit-switch homing planned; $22=0, $H rejected 2026-08-07 17:21:29 -04:00
ScottW514 a12ef810f4 BRINGUP: fd-blocking protocol pacing (~2% idle); fortify step_us_min overflow fixed - pre-fix images boot with a dead controller 2026-08-07 17:10:01 -04:00
ScottW514 392bf49e5b forgectrl SRCREV 73283b6; BRINGUP: cached capture path bench-verified on flashed image 2026-08-07 16:43:47 -04:00
ScottW514 e791475703 BRINGUP: cached capture buffers + stream FPS cap; fallback and cap bench-verified 2026-08-07 16:11:21 -04:00
ScottW514 29e0c588c9 BRINGUP: homing rework state of play - soak incomplete, idle-death investigation open 2026-08-03 18:40:12 -04:00
ScottW514 51161703b4 BRINGUP: homing tuned to 23 s; pull-off arming rule and sd guard 2026-08-03 17:56:53 -04:00
ScottW514 980176ecc7 BRINGUP: homing timing from mid-bed; status-silence and TCP stale-session notes 2026-08-03 17:38:26 -04:00
ScottW514 061def2343 grblhal-glowforge: recipe with boot autostart
gitsm-pinned build of the controller with a sysvinit script (defaults 92, after forgectrl), installed in both images. Reboot-verified on the bench: controller and forgectrl come up unattended and Grbl answers on TCP:23.
2026-08-03 17:22:07 -04:00