This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
# Phase-1 hardware test plan
|
||||
|
||||
## Preconditions
|
||||
|
||||
Every item must be complete before transfer:
|
||||
|
||||
- exact firmware is recorded and allowlisted for one artifact;
|
||||
- the discovery-only capability probe has already completed on that firmware;
|
||||
- source commit, SDK/SDL commits, artifact SHA-256, and static imports match the
|
||||
reviewed manifest;
|
||||
- the console has no unsaved work and automatic retry/boot integration is off;
|
||||
- an operator and observer have the redacted JSON-stage log visible;
|
||||
- the bounded-wait blocker below has an accepted resolution.
|
||||
|
||||
## Proposed timeline
|
||||
|
||||
1. Verify digest again immediately before transfer.
|
||||
2. Transfer manually using an existing approved userland loader workflow.
|
||||
3. Start once, manually. No boot hook or retry.
|
||||
4. Require `firmware_gate`, `video_init`, `window_create`, `surface_acquire`,
|
||||
and `cpu_fill` within five seconds total.
|
||||
5. Permit exactly one `single_present` and a one-second hold.
|
||||
6. Require `cleanup` and process exit within five seconds after present.
|
||||
7. Preserve logs and mark the firmware row pass, fail, or anomalous.
|
||||
|
||||
## Watchdog and timeout
|
||||
|
||||
The application stages are bounded except the pinned SDL call
|
||||
`SDL_UpdateWindowSurface`, whose backend waits for a flip event without a
|
||||
publicly proven finite timeout. A cooperative application thread cannot safely
|
||||
cancel it. Force-killing a thread while it owns VideoOut or direct-memory state
|
||||
is prohibited.
|
||||
|
||||
Before authorization, one of these must be proven and separately reviewed:
|
||||
|
||||
1. a public, licensed SDL/VideoOut change that supplies a bounded wait and
|
||||
returns control for cleanup; or
|
||||
2. a userland process supervisor whose termination semantics guarantee OS
|
||||
cleanup of VideoOut, equeue, and direct-memory ownership.
|
||||
|
||||
Until then, the operator wall-clock limit is a detection mechanism only, not a
|
||||
safe watchdog, and the hardware test remains blocked.
|
||||
|
||||
## Cleanup, rollback, and emergency stop
|
||||
|
||||
Normal cleanup is `SDL_DestroyWindow` followed by `SDL_Quit`; the pinned
|
||||
backend then closes VideoOut, releases direct memory, and deletes its equeue.
|
||||
No second flip is attempted during cleanup.
|
||||
|
||||
On any error, missing stage, display anomaly, or deadline:
|
||||
|
||||
- do not retry;
|
||||
- request normal userland process termination only if responsive;
|
||||
- do not kill an individual worker thread;
|
||||
- if display ownership does not return, use the console's normal controlled
|
||||
restart procedure; never patch firmware, registers, clocks, or fans;
|
||||
- after restart, use the existing SDL software path and mark the artifact and
|
||||
firmware combination failed/unknown pending review.
|
||||
Reference in New Issue
Block a user