Skip to content

Support Cortex-M33 acquisition and halt/resume. - #78

Merged
jon merged 1 commit into
mainfrom
work/rp2350-control
Sep 28, 2026
Merged

jon merged 1 commit into
mainfrom
work/rp2350-control

Conversation

@jon

@jon jon commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Allow target/cortexm.Acquire to own Cortex-M33 halting debug when Secure invasive debug is permitted. Halt, Halted, Resume, and Release use the existing halt-ownership and restoration rules. Register access and stepping remain Cortex-M0-only and reject M33 before further memory traffic.

Previously, this call rejected the RP2350's CPUID 0x411fd210:

core, err := cortexm.Acquire(ctx, memory)

It now permits the same control sequence used on M0. Here memory is borrowed from the RP2350 core-0 MEM-AP selected with dap.APAt(0x2000). The caller supplies ctx for the operation and a live cleanupCtx for restoration, including after operation cancellation:

core, err := cortexm.Acquire(ctx, memory)
if err == nil {
    err = core.Halt(ctx)
}
if err == nil {
    var halted bool
    halted, err = core.Halted(ctx)
    if err == nil {
        fmt.Printf("halted=%v\n", halted)
    }
}
if err == nil {
    err = core.Resume(ctx)
}
cleanupErr := core.Release(cleanupCtx)
err = errors.Join(err, cleanupErr)
// Close the memory owner only after cleanupErr is nil.
// Otherwise retain core and its memory owner for a later release attempt.

Why

M33 has security-dependent debug access and snap-stall control that the M0 path did not handle. Require DHCSR.S_SDE, reject inherited snap-stall, and stop control if either permission is lost or snap-stall is observed. Observed snap-stall permanently prevents automatic resume because clearing its bit does not repair the memory-system state. The target relinquishes its halt claim when it observes M33 restart status, even if the processor has already halted again. No authentication, security-bank, reset, or cross-core control is added.

Hardware evidence

On Nostalgia, OpenOCD 0.12.0 loaded and verified the supplied RAM counter on RP2350 core 0 through J-Link EDU Mini V2 000802011345. The bench procedure builds the image and selects that probe at 1 MHz. The binary SHA-256 is c20737e61153b272322548e8e6db5c420f0c148d6707ca4412c309f70415065a.

OSTIOLE_RP2350_HIL_CONTROL=1 \
OSTIOLE_RP2350_HIL_COUNTER=0x20040000 \
OSTIOLE_RP2350_HIL_PROGRAM=c20737e61153b272322548e8e6db5c420f0c148d6707ca4412c309f70415065a \
go test -tags integration ./target/cortexm -run '^TestHILRP2350Control$' -count=1 -v

Two fresh sessions at 1 MHz through AP 0x2000 observed counter progress before acquisition, no changes during halt, and progress after resume and release from a second halt. Both restored initially disabled debug and running state before Arm owner close; target release and owner close succeeded. Two earlier sessions also preserved initially enabled debug.

This covers core 0 with Secure invasive debug permitted and configurable interrupts disabled. Failure recovery and restricted-debug cases are covered only by behavioral tests. No M33 register or step support or cross-core coordination is claimed. State after closing the Arm debug owner was not measured. Flash was untouched; the RAM counter remains running, and the previous program state was not restored.

Documentation

Update the control guide, architecture and capability descriptions, and API comments with the M33 boundary. Include the RAM counter source, linker script, OpenOCD preparation, and opt-in hardware procedure.

Acquisition rejected the RP2350's Cortex-M33 even though its MEM-AP
and identity paths were usable. Admit M33 with Secure invasive debug
permission and retain the existing halt ownership and release rules.
Reject snap-stall state and never automatically resume after
observing it; clearing the bit cannot repair the affected
memory-system state. Relinquish halt ownership when M33 restart
status reveals a new stop. Keep register access and stepping limited
to Cortex-M0.

Exercise core-0 control with a RAM counter and retain the program,
preparation procedure, and explicit hardware test. Fresh
RP2350/J-Link sessions stop the counter during halt and observe
counter progress after resume and release, restoring initially
disabled debug. This does not establish cross-core control or
recovery from restricted debug permissions.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T03:46:39.565659Z 9f2b809 Manual request
🔒 Security Review ✅ Completed 2026-09-28T03:47:28.088616Z 9f2b809 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jon

jon commented Sep 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 9f2b8090f3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jon
jon merged commit 3120dfd into main Sep 28, 2026
9 checks passed
@jon
jon deleted the work/rp2350-control branch September 28, 2026 04:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant