Skip to content

Support Cortex-M33 architectural stepping. - #80

Merged
jon merged 1 commit into
mainfrom
jon/m33-step
Sep 30, 2026
Merged

jon merged 1 commit into
mainfrom
jon/m33-step

Conversation

@jon

@jon jon commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Allow Target.Step on an acquired Cortex-M33 from a halt owned by that target. It returns halted with stepping disabled and retains ownership for register access, another step, or resume. The caller controls cancellation and deadlines. Permission, snap-stall, and restart checks preserve the M33 cleanup rules.

Previously this call rejected M33, even after acquiring its debug state and requesting a halt:

err := core.Step(ctx)

The same call now performs an architectural step. Through a borrowed core-0 MEM-AP selected with dap.APAt(0x2000), the complete sequence is:

core, err := cortexm.Acquire(ctx, memory)
if err == nil {
    err = core.Halt(ctx)
}
if err == nil {
    err = core.Step(ctx)
}
if err == nil {
    var pc uint32
    pc, err = core.ReadRegister(ctx, cortexm.PC)
    if err == nil {
        fmt.Printf("stepped; PC=%#x\n", pc)
    }
}
if err == nil {
    err = core.Resume(ctx)
}
cleanupErr := core.Release(cleanupCtx)
err = errors.Join(err, cleanupErr)
// Release the memory owner only if cleanupErr is nil.
// Otherwise retain core and its memory owner for another release attempt.

The caller supplies ctx and a live cleanupCtx, including after operation cancellation. An inherited halt grants no permission to step or resume. A step can enter an exception handler instead of retiring an instruction; it preserves DFSR flags and rejects competing debug events. Instruction effects are not rolled back.

Why

M33 halt/resume and register access were available, but stepping still required M0. The existing step lifecycle supports M33 with additional state checks. The step's own restart is expected while execution is pending; a further restart after observing the completed halt prevents automatic cleanup, even if the processor has already halted again. Before clearing C_STEP, the target rereads DHCSR to confirm the halt and check permission, snap-stall, and restart status. An uncertain launch is never replayed.

Hardware evidence

On Nostalgia, two fresh sessions used J-Link EDU Mini V2 000802011345, 1 MHz SWD, and RP2350 core 0 at AP 0x2000, CPUID 0x411fd210. The already-running RAM counter was exercised with:

OSTIOLE_RP2350_HIL_CONTROL=1 \
OSTIOLE_RP2350_HIL_STEP=1 \
OSTIOLE_RP2350_HIL_PROGRAM=c20737e61153b272322548e8e6db5c420f0c148d6707ca4412c309f70415065a \
go test -tags integration ./target/cortexm -run '^TestHILRP2350Step$' -count=1 -v

Both sessions checked 13 steps each, with PC/R0/RAM matching the increment, store, and branch effects. The counter stayed unchanged while halted and advanced after resume and release from another stepped halt. DSCSR remained 0x00030000 across the first twelve steps. Initially disabled debug and running state were restored before Arm owner close; both owners closed successfully.

The counter runs in Secure state with configurable interrupts disabled. Exception entry, competing events, permission loss, snap-stall, restart after completion, and failure cleanup have behavioral coverage. Sleeping instructions, Non-secure execution, core-1 control, and cross-core coordination were not exercised. State after Arm owner close was not measured. Flash was untouched; the existing RAM program remains running.

Documentation

Update the stepping API, Cortex-M guide, architecture and composition guides, capability table, and README for M33 stepping. The Cortex-M guide includes the gated hardware procedure, instruction observations, and cleanup limits.

M33 halt/resume and register access were available, but stepping still
rejected the architecture. Extend the existing step lifecycle with M33
permission, snap-stall, and restart checks while preserving competing
stop evidence and caller deadlines.

A step itself sets restart status. Accept it while execution is pending,
but prevent automatic cleanup if restart status appears again after
observing completion. Recheck the halt before clearing stepping so
cleanup cannot claim a later independent stop. Never replay an uncertain
launch.

Two fresh RP2350 core-0 sessions verified PC, R0, and RAM across
thirteen steps each, then restored inherited debug state through
resume/release.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T07:03:45.688836Z 08c7d9d Manual request
🔒 Security Review ✅ Completed 2026-09-30T07:07:19.713841Z 08c7d9d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jon

jon commented Sep 30, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 08c7d9d735

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jon
jon merged commit dfe63f1 into main Sep 30, 2026
9 checks passed
@jon
jon deleted the jon/m33-step branch September 30, 2026 07:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant