Skip to content

Board's handle arrays are positionally bound to the device table #529

Description

@chrysh

The device table now states each component once and the chain is derived from it (#526). What is left is the binding from a component to its hardware: Board holds six parallel arrays, images, boot_controls, boot_watches, svn_floors, updatables, recovery, each indexed by component id and each authored by hand. Nothing ties their order to the table, and bring_up cannot check it, because a handle has no identity to compare.

Transpose any one of them and the eRoT resets the wrong device, which is the same failure #375 described, reached a different way.

Worth considering:

  • A per-device struct holding one component's handles, split into the arrays at Board construction. That collapses six independent error axes into one. Check what it costs the driver's disjoint borrows first.
  • DeviceConfig::reset_signal already carries identity and its doc says it is passed to HalBootControl::new, but no board does that today. Deriving the reset binding from the table is the one axis available now.

This gets exercised the first time a real bring-up composes hardware, so it belongs with the composition-root work. Refs #375.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions