Skip to content

Add boot monitor, move HalBootController into hal-adapters directory#20

Open
chrysh wants to merge 3 commits into
add-boot-reset-control_v2from
add-boot-monitor
Open

Add boot monitor, move HalBootController into hal-adapters directory#20
chrysh wants to merge 3 commits into
add-boot-reset-control_v2from
add-boot-monitor

Conversation

@chrysh

@chrysh chrysh commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator

This patch can only be applied after the boot reset control patch is done.

chrysh added 3 commits July 17, 2026 10:44
Introduce the Boot Orchestrator's actuation capability: the BootControl
trait (hold_in_reset / release) and HalBootControl, which binds one HAL
ResetControl line to a managed device. Includes a host unit test verifying
that holding a device in reset asserts exactly its configured line.

Includes tests that release deasserts the device's configured line and that a
controller error surfaces through BootControl unchanged. Extend the fake
reset controller with opt-in failure injection to drive the error case.

Closes: #2

Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Christina Quast <christina.quast@9elements.com>
Split the concrete adapter out of the api trait crate: api keeps only the
BootControl contract and loses its HAL dependency, becoming a contract-only
leaf that everything can depend on without inheriting the stack behind an
adapter. The new fwmanager-hal-adapters crate holds HalBootControl with its
tests in hal_boot_control.rs, named after the adapter type it defines.

The moved code is unchanged apart from importing the trait from fwmanager_api.

Assisted-by: Claude:claude-fable-5
Add the Boot Orchestrator's observation capability: the BootMonitor trait
(boot_status) reporting boot liveness as BootStatus lands in the api leaf
crate, and GpioBootMonitor, binding one HAL GpioPort input line to a managed
device's boot-complete signal, lands in the hal-adapters crate as
gpio_boot_monitor.rs. Liveness only: it reports that a device came up, never
what booted (attestation is a separate step), and a stuck boot is caught by the
orchestrator's timeout, not by this enum.

Includes host unit tests covering active-high and active-low polarity, that an
unrelated line is ignored, that a deasserted line reads as Booting rather than a
failure, and that a port read error surfaces through BootMonitor unchanged.

Closes: #6
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Christina Quast <christina.quast@9elements.com>
@chrysh
chrysh force-pushed the add-boot-monitor branch from 34908f1 to a4c31ae Compare July 17, 2026 13:24
/// into device implementations.
pub trait BootMonitor {
/// The error type reported by this device's boot monitor.
type Error: core::fmt::Debug;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chrysh
chrysh force-pushed the add-boot-reset-control_v2 branch from e10f4c6 to daa9aa7 Compare July 21, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants