Skip to content

Honor caller deadlines in Cortex-M and J-Link operations. - #75

Merged
jon merged 2 commits into
mainfrom
jon/caller-deadlines
Sep 27, 2026
Merged

jon merged 2 commits into
mainfrom
jon/caller-deadlines

Conversation

@jon

@jon jon commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Cortex-M acquisition, halt/resume/status, register access, and release now use the caller's context without adding a five-second deadline. J-Link configuration inspection also uses the caller's context, removing its one-second deadline and 101-attempt limit. It still retries only usb.ErrNotConfigured, with 10 ms between attempts.

For an already acquired, halted target, the call stays the same. Before, a thirty-second allowance was cut to five seconds:

readCtx, cancel := context.WithTimeout(ctx, 30*time.Second)
pc, err := core.ReadRegister(readCtx, cortexm.PC)
cancel()

After, the same call can use the full thirty seconds, unless ctx ends sooner:

readCtx, cancel := context.WithTimeout(ctx, 30*time.Second)
pc, err := core.ReadRegister(readCtx, cortexm.PC)
cancel()

The target still needs Release before its memory owner is closed. A failed transfer may leave cleanup pending; retain both owners and supply a usable context for restoration.

Likewise, before this change jlink.Open(ctx, device) stopped retrying an unconfigured device after one second or 101 attempts. Afterward, jlink.Open(ctx, device) retries until configuration appears or ctx ends. Ownership is unchanged: close the session on success, or the supplied device on error. A failed session close may need another attempt.

Why

The library was shortening caller deadlines even when the caller had deliberately allowed more time. Callers now choose their own limits. A context without a deadline or cancellation can wait indefinitely for a target transition or USB configuration.

Failed Cortex-M acquisition still attempts restoration with an independent five-second context. That cleanup must remain possible after cancellation; a non-nil target returned with an error retains any cleanup obligation for a later Release.

Documentation

The Cortex-M guide and API comments describe caller-owned deadlines, including release. The architecture guide and J-Link capability table describe configuration retries under the caller's context.

Hardware evidence

On macOS, two fresh CMSIS-DAP v2 sessions on the nRF51822 micro:bit at 1 MHz/AP0 read all 19 supported registers, wrote and restored R4/SP/MSP/PSP/PC, and resumed the counter program. The counter stopped while halted and advanced after resume and release. Both sessions restored initially disabled debug and running state before closing the Arm debug owner; both owners closed successfully. The bench used serial 9900360140124e4500279015000000360000000097969901 and the retained counter firmware:

OSTIOLE_CORTEXM_HIL_CONTROL=1 \
OSTIOLE_CORTEXM_HIL_REGISTERS=1 \
OSTIOLE_CORTEXM_HIL_PROGRAM=sha256:ee294cc06ab6e8228161b49506675b065c0148b26421cf1f83c8e45e35cd4e5d \
go test -tags integration ./target/cortexm \
  -run '^TestHILCortexM0Registers$' -count=1 -v

The J-Link EDU Mini V2 returned the same firmware metadata and selected interface across close and immediate reopen. Both sessions closed successfully:

OSTIOLE_JLINK_HIL=1 OSTIOLE_JLINK_HIL_SERIAL=000802011345 \
go test -tags integration ./jlink \
  -run '^TestHILJLinkMetadataSurvivesReopen$' -count=1 -v

These runs exercised ordinary operation after removing the limits; they did not provoke a slow target or prolonged unconfigured USB state. Deadline propagation, extended retries, and cancellation have behavioral-test coverage. No firmware was reloaded, and target state after the Arm owner closed was not measured.

jon added 2 commits September 26, 2026 17:44
Cortex-M operations imposed a five-second limit even when their caller
allowed more time. Pass the supplied context through acquisition,
run control, register access, and release so the caller chooses the
operation deadline.

Keep the independent five-second restoration attempt after failed
acquisition. Cancellation must not prevent that cleanup, and a retained
target still permits the caller to retry release with its own context.
J-Link inspection stopped after one second or 101 attempts even when
the open context allowed more time. Retry an unconfigured USB device
until configuration appears or the caller's context ends, preserving
both cancellation and the unconfigured-state error when waiting fails.
Other inspection errors still return immediately, and retries retain
their ten-millisecond spacing.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T00:54:06.265034Z 84c5fe3 Manual request
🔒 Security Review ✅ Completed 2026-09-27T00:54:43.968722Z 84c5fe3 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jon

jon commented Sep 27, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 84c5fe38bd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jon
jon merged commit 30b4c67 into main Sep 27, 2026
9 checks passed
@jon
jon deleted the jon/caller-deadlines branch September 27, 2026 19:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant