Support Cortex-M33 acquisition and halt/resume. - #78
Merged
Merged
Conversation
Acquisition rejected the RP2350's Cortex-M33 even though its MEM-AP and identity paths were usable. Admit M33 with Secure invasive debug permission and retain the existing halt ownership and release rules. Reject snap-stall state and never automatically resume after observing it; clearing the bit cannot repair the affected memory-system state. Relinquish halt ownership when M33 restart status reveals a new stop. Keep register access and stepping limited to Cortex-M0. Exercise core-0 control with a RAM counter and retain the program, preparation procedure, and explicit hardware test. Fresh RP2350/J-Link sessions stop the counter during halt and observe counter progress after resume and release, restoring initially disabled debug. This does not establish cross-core control or recovery from restricted debug permissions.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Owner
Author
|
@codex review |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Allow
target/cortexm.Acquireto own Cortex-M33 halting debug when Secure invasive debug is permitted.Halt,Halted,Resume, andReleaseuse the existing halt-ownership and restoration rules. Register access and stepping remain Cortex-M0-only and reject M33 before further memory traffic.Previously, this call rejected the RP2350's CPUID
0x411fd210:It now permits the same control sequence used on M0. Here
memoryis borrowed from the RP2350 core-0 MEM-AP selected withdap.APAt(0x2000). The caller suppliesctxfor the operation and a livecleanupCtxfor restoration, including after operation cancellation:Why
M33 has security-dependent debug access and snap-stall control that the M0 path did not handle. Require DHCSR.S_SDE, reject inherited snap-stall, and stop control if either permission is lost or snap-stall is observed. Observed snap-stall permanently prevents automatic resume because clearing its bit does not repair the memory-system state. The target relinquishes its halt claim when it observes M33 restart status, even if the processor has already halted again. No authentication, security-bank, reset, or cross-core control is added.
Hardware evidence
On Nostalgia, OpenOCD 0.12.0 loaded and verified the supplied RAM counter on RP2350 core 0 through J-Link EDU Mini V2
000802011345. The bench procedure builds the image and selects that probe at 1 MHz. The binary SHA-256 isc20737e61153b272322548e8e6db5c420f0c148d6707ca4412c309f70415065a.Two fresh sessions at 1 MHz through AP
0x2000observed counter progress before acquisition, no changes during halt, and progress after resume and release from a second halt. Both restored initially disabled debug and running state before Arm owner close; target release and owner close succeeded. Two earlier sessions also preserved initially enabled debug.This covers core 0 with Secure invasive debug permitted and configurable interrupts disabled. Failure recovery and restricted-debug cases are covered only by behavioral tests. No M33 register or step support or cross-core coordination is claimed. State after closing the Arm debug owner was not measured. Flash was untouched; the RAM counter remains running, and the previous program state was not restored.
Documentation
Update the control guide, architecture and capability descriptions, and API comments with the M33 boundary. Include the RAM counter source, linker script, OpenOCD preparation, and opt-in hardware procedure.