Skip to content

Acquire Cortex-M0 halting debug and control execution. - #73

Merged
jon merged 4 commits into
mainfrom
jon/cortexm-control
Sep 26, 2026
Merged

jon merged 4 commits into
mainfrom
jon/cortexm-control

Conversation

@jon

@jon jon commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Add Cortex-M0 acquisition, halt, resume, and release over borrowed word memory. Acquisition enables halting debug without requesting a halt. Resume refuses an inherited halt, and release restores the control changed by this target before its memory owner is closed.

dap.MemAP.WriteWord writes an aligned 32-bit word and waits for AP completion:

// Write only to an address selected by the application for this purpose.
err := memory.WriteWord(ctx, address, value)

The target uses that memory directly:

core, err := cortexm.Acquire(ctx, memory)
if err == nil {
    err = core.Halt(ctx)
}
var halted bool
if err == nil {
    halted, err = core.Halted(ctx)
}
if err == nil && halted {
    // Do halted things.
    err = core.Resume(ctx)
}
cleanupCtx, cancel := context.WithTimeout(ctx, 5*time.Second)
cleanupErr := core.Release(cleanupCtx)
cancel()
err = errors.Join(err, cleanupErr)
// Retain core and its memory owner when cleanupErr != nil.
// Release the memory owner only after target release succeeds.

Halted reports whether the processor is stopped. Reading that status does not acquire ownership of the halt; Resume accepts only a halt requested by this target.

Each operation is capped at five seconds or the caller's earlier deadline. Failed acquisition attempts restoration with an independent context and returns a non-nil target if cleanup remains pending. Failed control writes block ordinary calls until release. A resume remains unconfirmed until readback shows that the halt request cleared; cleanup does not replay it. A completed resume is never replayed if the processor halts again. If readback shows that the halt request was lost, the target relinquishes halt ownership. An uncertain control write, or a new halt when restoring initially disabled debug, can leave cleanup pending until execution resumes. Restoration requires usable memory; it cannot repair a poisoned transport or an invalidated MEM-AP, undo executed instructions, or restore the sticky status consumed by DHCSR reads.

Why

The Cortex-M package previously exposed CPUID identification only. The acquired target keeps halt ownership and restoration state together while leaving probe, DAP, and memory ownership in their existing layers. Control accepts Cortex-M0 and rejects inherited stepping or interrupt masking before writes.

Documentation

The Cortex-M guide describes effects, ownership, and cleanup. The architecture, composition, capability, and README pages now distinguish Cortex-M identification from Cortex-M0 execution control. The cortexm-control example requires an exact provider and serial, an AP selection, and -allow-control before it enables debug or changes execution state. The control, Arm identity, and CoreSight examples default to 1 MHz and accept -clock in Hz. The default meets the micro:bit nRF51's startup clock requirement. The FTDI SWD examples and ost commands also request 1 MHz.

Hardware evidence

On Nostalgia (macOS), the CMSIS-DAP v2 micro:bit with serial 9900360140124e4500279015000000360000000097969901 completed two control sessions through SWD at a requested 1 MHz, AP0, with Cortex-M0 CPUID 0x410cc200. OpenOCD 0.12.0 had programmed and verified the CPU counter firmware using target/cortexm/testdata/counter/README.md. Its Intel HEX SHA-256 was ee294cc06ab6e8228161b49506675b065c0148b26421cf1f83c8e45e35cd4e5d. After a physical replug, Ostiole's read-only test connected first at 1 MHz; the control test followed without an intervening OpenOCD session.

OSTIOLE_CORTEXM_HIL_CONTROL=1 \
OSTIOLE_CORTEXM_HIL_COUNTER=0x20000000 \
OSTIOLE_CORTEXM_HIL_PROGRAM=sha256:ee294cc06ab6e8228161b49506675b065c0148b26421cf1f83c8e45e35cd4e5d \
go test -tags integration ./target/cortexm -run '^TestHILCortexM0Control$' -count=1 -v

In both sessions, the counter advanced before acquisition, stayed fixed across ten samples 20 milliseconds apart while halted, and advanced after resume and after release from a second halt. The halted values were 0x0d8abd3d and 0x0db618ae. Target release and Arm debug owner close completed in both sessions. DHCSR was 0x01000000 before acquisition and after release: acquisition enabled initially disabled debug, and release restored disabled debug with the processor running. Earlier sessions after OpenOCD initialization preserved initially enabled debug.

The original 100 kHz bench setting failed on a freshly plugged micro:bit in both Ostiole and OpenOCD. Nordic specifies at least 125 kHz during nRF51 debug activation (reference manual, §11.1.2). Ostiole passed as the first client after replug when only its requested clock changed to 1 MHz. The micro:bit HIL tests and programming procedure now use 1 MHz; the CMSIS-DAP driver is unchanged. This is one board and firmware revision, without a measurement of the attained clock.

Failure cleanup remains covered only by behavioral tests. State was checked before closing the Arm debug owner, not afterward. These runs do not establish peripheral behavior, register preservation, reset, or stepping.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T22:39:44.654084Z efe53fd Manual request
🔒 Security Review ✅ Completed 2026-09-26T21:36:01.375175Z 8221c90 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8221c90477

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/control.go
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please run the standard review again at 8221c90477d408efb4964f1179797f12c7c641c3. The size finding applies the per-commit checkpoint to the aggregate PR diff; the reply on that thread lists the four existing commits and their individual counts. The branch has not changed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8221c90477

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/run.go
@jon
jon force-pushed the jon/cortexm-control branch from 8221c90 to e31cd54 Compare September 26, 2026 21:51
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head e31cd54143a2913214e658dcc44c294de02e1a59. The lost halt-request ownership fix is folded into the run-control commit with regression coverage and documentation. The four commits add 190, 187, 89, and 28 non-test Go lines respectively.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e31cd54143

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/run.go Outdated
@jon
jon force-pushed the jon/cortexm-control branch from e31cd54 to af068b3 Compare September 26, 2026 21:58
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head af068b33691eb31f66c4a3e9ea3ddd7100904916. The cancellation fix and regression are folded into the run-control commit. The four commits still add 190, 187, 89, and 28 non-test Go lines respectively.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af068b3369

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/control.go Outdated
@jon
jon force-pushed the jon/cortexm-control branch from af068b3 to 5d1b773 Compare September 26, 2026 22:06
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head 5d1b7735429960290993823cfe440d5d80fbad8b. Acquisition now preserves event-induced inherited halts; the acquisition and run-control regressions are folded into their respective commits. The four commits add 190, 187, 89, and 28 non-test Go lines.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5d1b773542

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/control.go Outdated
@jon
jon force-pushed the jon/cortexm-control branch from 5d1b773 to 3a67a03 Compare September 26, 2026 22:13
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head 3a67a03c380a67b63fbbe0acea9ea22abee2a064. The acquisition cancellation fix and regression are folded into the first commit. The four commits add 191, 187, 89, and 28 non-test Go lines.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3a67a03c38

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread target/cortexm/restore.go Outdated
Comment thread target/cortexm/control.go
Processor identity alone gives callers no owner for halting debug state.
Enable Cortex-M0 halting debug through borrowed word memory, preserve
its inherited control, and retain restoration state for release retries.
Reject unsupported cores and debug modes before writes; failed setup
uses an independent cleanup deadline.
@jon
jon force-pushed the jon/cortexm-control branch from 3a67a03 to 684da80 Compare September 26, 2026 22:23
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head 684da80c2f34fc6cecce1ec873f2674e5bdd2f19. Acquisition and cleanup now finish restoration when readback confirms the saved disabled-debug state, with regressions folded into acquisition. The four commits add 197, 187, 89, and 28 non-test Go lines.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 684da80c2f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

jon added 3 commits September 26, 2026 15:33
Enabling debug does not distinguish a halt requested by this owner from
one it inherited. Add bounded halt, status, and resume operations with
ownership retained through readback failures and release.

Do not replay a completed resume when execution immediately halts again.
An unconfirmed control write cannot establish the origin of an observed
stop, so cleanup refuses to resume that halt.
Identity reads cannot establish that execution stops and restarts.
Supply a Cortex-M0 counter program and an explicitly gated micro:bit
test which checks progress around halt, resume, and release in fresh
sessions. Keep firmware programming separate from the Ostiole control
path, and provide a small executable composition with ordered target
cleanup.
The micro:bit tests requested 100 kHz, below the nRF51's documented
125 kHz minimum for entering debug mode after power-on. At 100 kHz,
they passed after OpenOCD activated the interface but failed when
Ostiole connected first after a physical replug.

Default the SWD tools and micro:bit benches to 1 MHz and document the
cold-start observation. Let the probe-based inspection and control
examples accept a clock ceiling for targets that need another rate.
Keep clock selection with the caller; the CMSIS-DAP driver is unchanged.
@jon
jon force-pushed the jon/cortexm-control branch from 684da80 to efe53fd Compare September 26, 2026 22:35
@jon

jon commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review final head efe53fd77dcfd37aa4e6d7c1799f823d28cc1e93. Resume keeps cleanup pending until readback confirms that the halt request cleared, without replaying an ambiguous resume. The correction, regressions, and documentation are folded into the run-control commit. The four commits add 197, 188, 89, and 28 non-test Go lines.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: efe53fd77d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jon
jon merged commit 049be3e into main Sep 26, 2026
9 of 15 checks passed
@jon
jon deleted the jon/cortexm-control branch September 26, 2026 22:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant