Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,10 @@ compose the public packages explicitly without duplicating their framing. The
`target/cortexm` package reads and decodes the architectural CPUID value through
any compatible target-word reader. It also provides acquired Cortex-M0 and
Cortex-M33 halt/resume control, halted register access, and architectural
stepping over word memory; see [Cortex-M control](docs/cortexm.md).
stepping over word memory; see [Cortex-M control](docs/cortexm.md). Independent
RP2350 targets can share one Arm owner with serialized calls; the
[two-core bench](docs/cortexm.md#rp2350-independent-core-bench) records halt,
step, peer progress, and cleanup observations.

The FTDI path uses the standard H-series MPSSE port and endpoint layout.
Descriptor-driven FTDI port binding is not implemented yet. J-Link instead
Expand Down
7 changes: 7 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,11 @@ banking, AP identification, raw AP addresses, power ownership, and MEM-AP state
stay in `dap`. Higher layers should call these packages rather than reproduce
their framing.

A target owns one processor. Several targets may borrow distinct MEM-APs from
one `armdebug.Conn`; all calls over that shared owner remain serialized.
Independent RP2350 core control has [physical evidence][dual-core]. It does not
provide group ownership, CTI routing, or a simultaneous memory snapshot.

## Discovery and opening

`discover.Registry` stores immutable transport providers. Registration is
Expand Down Expand Up @@ -409,3 +414,5 @@ The layers are not entirely passive:

Callers should always complete the documented release sequence, including when
the primary operation fails.

[dual-core]: cortexm.md#rp2350-independent-core-bench
7 changes: 4 additions & 3 deletions docs/capabilities.md
Original file line number Diff line number Diff line change
Expand Up @@ -301,6 +301,7 @@ skips have hardware-independent test coverage.
| Cortex-M33 step | HIL | Two fresh RP2350 core-0/J-Link sessions at 1 MHz checked PC/R0/RAM across 13 steps each, resume, and release with disabled debug restored. Secure counter state and DSCSR were preserved. Permission, snap-stall, restart after completion, and failure cleanup have behavioral coverage; see the [RP2350 step bench](cortexm.md#rp2350-step-bench). |
| Register reads | Yes | Halted Cortex-M0/M33 R0–R12, SP, LR, PC, XPSR, MSP, and PSP through `ReadRegister`. Two fresh sessions each on CMSIS-DAP/micro:bit and J-Link/RP2350 core 0 read all 19 registers; transfer failures and cleanup have behavioral coverage. |
| Register writes | Yes | Halted Cortex-M0/M33 writes except XPSR; aligned SP/MSP/PSP and even PC values. Writes persist after release. Behavioral tests cover staging, uncertain selection, and pending cleanup. Two sessions each on micro:bit and RP2350 core 0 wrote and restored R4, SP, MSP, PSP, and PC before resuming; see the [micro:bit](cortexm.md#register-bench) and [RP2350](cortexm.md#rp2350-register-bench) register benches. |
| Independent RP2350 cores | HIL | Two fresh J-Link sessions borrowed core-0/core-1 MEM-APs under one Arm owner. Each core halted and stepped while its peer advanced; both restored disabled debug and running state with inactive CTIs unchanged. See the [independent-core bench](cortexm.md#rp2350-independent-core-bench). This provides serialized per-core control, without group or CTI ownership. |
| Reset | No | No architectural or pin-reset operation exists. |
| Breakpoints or watchpoints | No | No target instrumentation API exists. |
| Firmware or runtime loading | No | No ELF loader, image-placement policy, or flash driver exists. |
Expand Down Expand Up @@ -345,9 +346,9 @@ SWD, and use the volatile DAP and MEM-AP state described above.
## Not currently provided

There is no CMSIS-DAP HID/v1 transport, automatic probe discovery policy,
multi-core or SoC attachment, general target control, semihosting, trace,
debugger protocol server, firmware flashing, FPGA programming, or Windows host
implementation.
automatic SoC attachment, group or CTI control, general target control,
semihosting, trace, debugger protocol server, firmware flashing, FPGA
programming, or Windows host implementation.

Treat an absent capability as an explicit boundary. Do not infer it from the
project description or recreate its lower-level protocol inside an application.
Expand Down
6 changes: 6 additions & 0 deletions docs/composition.md
Original file line number Diff line number Diff line change
Expand Up @@ -744,6 +744,12 @@ target tracks transfer completion but does not roll back writes. Release it
before its memory owner and retain both after failed target restoration. See
[Cortex-M control](cortexm.md) for the full composition and effects.

For independent RP2350 processors, borrow both MEM-APs from one Arm owner and
acquire a separate target for each. Serialize calls over that connection and
release both targets before closing their memory owner. The
[two-core composition and bench](cortexm.md#independent-rp2350-cores) show the
per-core ownership boundary and physical observations.

## Release in reverse order

A complete Cortex-M identity composition acquires and releases state in one of
Expand Down
104 changes: 104 additions & 0 deletions docs/cortexm.md
Original file line number Diff line number Diff line change
Expand Up @@ -246,6 +246,68 @@ Hardware-independent tests model DHCSR control and execution state, including
partial writes, canceled operations, ignored writes, failed cleanup, and retry.
They do not establish physical halt/resume behavior on a bench program.

## Independent RP2350 cores

One `armdebug.Conn` can lend core 0's MEM-AP at `0x2000` and core 1's MEM-AP at
`0x4000`. Acquire a separate `cortexm.Target` for each. Serialize all calls over
the shared connection, including memory reads, target operations, and cleanup.
Each target owns only its processor's debug state and halt requests. Halting one
target does not claim ownership of a stop on the other.

For an already-open Arm owner `c`, the caller supplies operation `ctx` and a
live `cleanupCtx`, including after cancellation:

```go
var cores [2]*cortexm.Target
var err error
for i, base := range []uint64{0x2000, 0x4000} {
ap, e := dap.APAt(base)
if e != nil {
err = e
break
}
memory, e := c.OpenMemAP(ctx, ap)
if e != nil {
err = e
break
}
cores[i], err = cortexm.Acquire(ctx, memory)
if err != nil {
break
}
}
if err == nil {
err = cores[0].Halt(ctx)
}
if err == nil {
var halted bool
halted, err = cores[1].Halted(ctx)
if err == nil {
fmt.Printf("core 1 halted=%v\n", halted)
}
}
if err == nil {
err = cores[0].Resume(ctx)
}
var releaseErr error
for i := len(cores) - 1; i >= 0; i-- {
releaseErr = errors.Join(releaseErr, cores[i].Release(cleanupCtx))
}
err = errors.Join(err, releaseErr)
if releaseErr == nil {
err = errors.Join(err, c.Close())
}
// Retain targets and c if target cleanup fails; retain c if Close fails.
```

A failed acquisition can return a non-nil target, so store it before handling
the error. Release every retained target before closing its memory owner; a
failed release leaves that owner live for retry. A target acquired while its
processor is halted cannot resume that inherited halt. Existing cross-trigger
routing can couple stops: inspect the bench's routing before expecting
independent progress. This composition provides per-core control, without group
ownership, coordinated stopping, or a simultaneous snapshot.

## Hardware procedure

The opt-in integration test selects the CMSIS-DAP micro:bit with serial
Expand Down Expand Up @@ -475,3 +537,45 @@ after a completed halt, and failure cleanup have behavioral coverage. These
sessions do not establish sleeping-instruction behavior, Non-secure execution,
core-1 control, or cross-core coordination. State after Arm owner close was not
independently measured. Flash was untouched and the counter remains running.

## RP2350 independent-core bench

`TestHILRP2350IndependentCores` selects J-Link EDU Mini V2 `000802011345` at 1
MHz, opens one Arm owner, and borrows AP `0x2000` and AP `0x4000`. Prepare the
[separate RAM counters][dual-counter] first. That procedure replaces both cores'
volatile execution state, resets core 1, and disables its Secure MPU for RAM
entry; it does not change flash or CTI routing.

```sh
OSTIOLE_RP2350_HIL_DUAL_CORE=1 \
OSTIOLE_RP2350_HIL_PROGRAM=bf878b47815bc5eaf6afb5279efaa6ff163832bd178c5b7b1604f80e6ad6cde9 \
go test -tags integration ./target/cortexm -run '^TestHILRP2350IndependentCores$' -count=1 -v
```

The test requires the known instruction words, running Secure counters, and
inactive CTIs before acquiring either target. It checks CTI architecture and
geometry, disabled control and integration mode, zero application triggers,
output and input-channel status, and all eight input/output routes. It reads and
preserves CTIGATE. It never writes routing or acknowledgements.

On Nostalgia, two fresh sessions read all 19 registers on each core and checked
one architectural step per core against PC, R0, and its counter word. Core 0's
counter stayed unchanged during its halt and after its step while core 1
advanced; the reverse held when core 1 was halted and stepped. Both counters
stopped after sequential halt requests. Resuming only core 0 left core 1
stopped; release from an owned halt restored progress on each core.

Both sessions restored initially disabled halting debug and running state on
both cores before Arm owner close, with DHCSR `0x01100000` before/after and
DSCSR `0x00030000` unchanged. Both CTIs remained disabled and unrouted, with
zero pending output/input-channel status and CTIGATE `0x0f` unchanged. Both
targets released and the shared owner closed successfully.

This covers the prepared Secure counter programs and serialized per-core
operations. It does not establish simultaneous stopping, CTI propagation,
Non-secure execution, sleeping instructions, or cross-core failure recovery.
Per-target cleanup failures have behavioral coverage; this bench does not inject
failures. State after Arm owner close was not independently measured. Both loops
remain running; preparation and instruction effects are not undone.

[dual-counter]: ../target/cortexm/testdata/rp2350-dual-counter/README.md
Loading
Loading