Acquire Cortex-M0 halting debug and control execution. - #73
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8221c90477
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please run the standard review again at |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8221c90477
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
8221c90 to
e31cd54
Compare
|
@codex review Please review final head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e31cd54143
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
e31cd54 to
af068b3
Compare
|
@codex review Please review final head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af068b3369
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
af068b3 to
5d1b773
Compare
|
@codex review Please review final head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5d1b773542
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5d1b773 to
3a67a03
Compare
|
@codex review Please review final head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3a67a03c38
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Processor identity alone gives callers no owner for halting debug state. Enable Cortex-M0 halting debug through borrowed word memory, preserve its inherited control, and retain restoration state for release retries. Reject unsupported cores and debug modes before writes; failed setup uses an independent cleanup deadline.
3a67a03 to
684da80
Compare
|
@codex review Please review final head |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Enabling debug does not distinguish a halt requested by this owner from one it inherited. Add bounded halt, status, and resume operations with ownership retained through readback failures and release. Do not replay a completed resume when execution immediately halts again. An unconfirmed control write cannot establish the origin of an observed stop, so cleanup refuses to resume that halt.
Identity reads cannot establish that execution stops and restarts. Supply a Cortex-M0 counter program and an explicitly gated micro:bit test which checks progress around halt, resume, and release in fresh sessions. Keep firmware programming separate from the Ostiole control path, and provide a small executable composition with ordered target cleanup.
The micro:bit tests requested 100 kHz, below the nRF51's documented 125 kHz minimum for entering debug mode after power-on. At 100 kHz, they passed after OpenOCD activated the interface but failed when Ostiole connected first after a physical replug. Default the SWD tools and micro:bit benches to 1 MHz and document the cold-start observation. Let the probe-based inspection and control examples accept a clock ceiling for targets that need another rate. Keep clock selection with the caller; the CMSIS-DAP driver is unchanged.
684da80 to
efe53fd
Compare
|
@codex review Please review final head |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Add Cortex-M0 acquisition, halt, resume, and release over borrowed word memory. Acquisition enables halting debug without requesting a halt. Resume refuses an inherited halt, and release restores the control changed by this target before its memory owner is closed.
dap.MemAP.WriteWordwrites an aligned 32-bit word and waits for AP completion:The target uses that memory directly:
Haltedreports whether the processor is stopped. Reading that status does not acquire ownership of the halt;Resumeaccepts only a halt requested by this target.Each operation is capped at five seconds or the caller's earlier deadline. Failed acquisition attempts restoration with an independent context and returns a non-nil target if cleanup remains pending. Failed control writes block ordinary calls until release. A resume remains unconfirmed until readback shows that the halt request cleared; cleanup does not replay it. A completed resume is never replayed if the processor halts again. If readback shows that the halt request was lost, the target relinquishes halt ownership. An uncertain control write, or a new halt when restoring initially disabled debug, can leave cleanup pending until execution resumes. Restoration requires usable memory; it cannot repair a poisoned transport or an invalidated MEM-AP, undo executed instructions, or restore the sticky status consumed by DHCSR reads.
Why
The Cortex-M package previously exposed CPUID identification only. The acquired target keeps halt ownership and restoration state together while leaving probe, DAP, and memory ownership in their existing layers. Control accepts Cortex-M0 and rejects inherited stepping or interrupt masking before writes.
Documentation
The Cortex-M guide describes effects, ownership, and cleanup. The architecture, composition, capability, and README pages now distinguish Cortex-M identification from Cortex-M0 execution control. The
cortexm-controlexample requires an exact provider and serial, an AP selection, and-allow-controlbefore it enables debug or changes execution state. The control, Arm identity, and CoreSight examples default to 1 MHz and accept-clockin Hz. The default meets the micro:bit nRF51's startup clock requirement. The FTDI SWD examples andostcommands also request 1 MHz.Hardware evidence
On Nostalgia (macOS), the CMSIS-DAP v2 micro:bit with serial
9900360140124e4500279015000000360000000097969901completed two control sessions through SWD at a requested 1 MHz, AP0, with Cortex-M0 CPUID0x410cc200. OpenOCD 0.12.0 had programmed and verified the CPU counter firmware usingtarget/cortexm/testdata/counter/README.md. Its Intel HEX SHA-256 wasee294cc06ab6e8228161b49506675b065c0148b26421cf1f83c8e45e35cd4e5d. After a physical replug, Ostiole's read-only test connected first at 1 MHz; the control test followed without an intervening OpenOCD session.In both sessions, the counter advanced before acquisition, stayed fixed across ten samples 20 milliseconds apart while halted, and advanced after resume and after release from a second halt. The halted values were
0x0d8abd3dand0x0db618ae. Target release and Arm debug owner close completed in both sessions. DHCSR was0x01000000before acquisition and after release: acquisition enabled initially disabled debug, and release restored disabled debug with the processor running. Earlier sessions after OpenOCD initialization preserved initially enabled debug.The original 100 kHz bench setting failed on a freshly plugged micro:bit in both Ostiole and OpenOCD. Nordic specifies at least 125 kHz during nRF51 debug activation (reference manual, §11.1.2). Ostiole passed as the first client after replug when only its requested clock changed to 1 MHz. The micro:bit HIL tests and programming procedure now use 1 MHz; the CMSIS-DAP driver is unchanged. This is one board and firmware revision, without a measurement of the attained clock.
Failure cleanup remains covered only by behavioral tests. State was checked before closing the Arm debug owner, not afterward. These runs do not establish peripheral behavior, register preservation, reset, or stepping.