Files
chimera-gfx-Public/docs/phase1/HARDWARE_TEST_PLAN.md
T
Chimera GFX release export fee37cd9b5
phase0-ci / build-and-audit (push) Failing after 1m41s
Publish Chimera GFX source
2026-09-03 02:53:36 +02:00

2.5 KiB

Phase-1 hardware test plan

Preconditions

Every item must be complete before transfer:

  • exact firmware is recorded and allowlisted for one artifact;
  • the discovery-only capability probe has already completed on that firmware;
  • source commit, SDK/SDL commits, artifact SHA-256, and static imports match the reviewed manifest;
  • the console has no unsaved work and automatic retry/boot integration is off;
  • an operator and observer have the redacted JSON-stage log visible;
  • the bounded-wait blocker below has an accepted resolution.

Proposed timeline

  1. Verify digest again immediately before transfer.
  2. Transfer manually using an existing approved userland loader workflow.
  3. Start once, manually. No boot hook or retry.
  4. Require firmware_gate, video_init, window_create, surface_acquire, and cpu_fill within five seconds total.
  5. Permit exactly one single_present and a one-second hold.
  6. Require cleanup and process exit within five seconds after present.
  7. Preserve logs and mark the firmware row pass, fail, or anomalous.

Watchdog and timeout

The application stages are bounded except the pinned SDL call SDL_UpdateWindowSurface, whose backend waits for a flip event without a publicly proven finite timeout. A cooperative application thread cannot safely cancel it. Force-killing a thread while it owns VideoOut or direct-memory state is prohibited.

Before authorization, one of these must be proven and separately reviewed:

  1. a public, licensed SDL/VideoOut change that supplies a bounded wait and returns control for cleanup; or
  2. a userland process supervisor whose termination semantics guarantee OS cleanup of VideoOut, equeue, and direct-memory ownership.

Until then, the operator wall-clock limit is a detection mechanism only, not a safe watchdog, and the hardware test remains blocked.

Cleanup, rollback, and emergency stop

Normal cleanup is SDL_DestroyWindow followed by SDL_Quit; the pinned backend then closes VideoOut, releases direct memory, and deletes its equeue. No second flip is attempted during cleanup.

On any error, missing stage, display anomaly, or deadline:

  • do not retry;
  • request normal userland process termination only if responsive;
  • do not kill an individual worker thread;
  • if display ownership does not return, use the console's normal controlled restart procedure; never patch firmware, registers, clocks, or fans;
  • after restart, use the existing SDL software path and mark the artifact and firmware combination failed/unknown pending review.