Adom Custom Electronic Load
Public Made by Adomby adom
Independent compact digitally controlled load design for 3rdPartyFab; research and AIFlow evidence in progress
10054d3
55m ago
Firmware and control-panel contract — R0 engineering draft
The portable C safety-policy core is implemented and host-tested. There is no flashable STM32 firmware yet. USB descriptors, HAL, interrupts, hardware validation of the register drivers, ADC calibration, persistence and the hardware adapter remain open. No hardware operation has been demonstrated.
USB CDC ACM is the preferred link to the control panel. The board is self-powered from auxiliary 5 V; USB VBUS is detected but does not power the fan or logic. D+/D− and ground connect to the panel USB host. UART at 3.3 V is an alternative through the molecule contacts; it is not a power interface and must not be wired to 5 V GPIO. Never enable a load by connecting a raw GPIO wire alone.
Proposed transport: newline-delimited JSON, protocol adom.load/1, maximum 256 bytes per line, explicit request ID and success/error response. Commands: identify, status, set_current (amperes), arm, off, clear_fault, heartbeat. One exclusive controlling session; monotonic sequence numbers; stale/replayed commands rejected. Disconnect, parser overflow, invalid framing or heartbeat loss disables the load. off must have priority over queued commands. The panel must show requested and applied current separately.
Every boot starts disabled: configure MCU_ENABLE low and ARM_CLK low before peripheral initialization, keep DAC at zero, and verify the hardware clear/clamp path. arm is allowed only with fresh valid telemetry, healthy fan, safe temperature/voltage, a verified assembly configuration and a live host lease. Write DAC zero, pulse ARM_CLK, verify LATCH_Q, then enable; missing latch acknowledgement must time out. Fault clearing never automatically re-arms.
The 1.6 s nominal external watchdog has a 1.12–2.24 s specified timeout. Firmware toggles WDI only after a complete healthy control cycle, never from an unconditional timer interrupt. The independent comparator/latch chain handles case-sensor open/short, overtemperature, overcurrent and overvoltage. The software host lease is 1 s; sensor age limit 50 ms. These timings require hardware acceptance tests.
The policy core starts with a 5 W bring-up ceiling, 3 A maximum, 24 V maximum and 1 A/s upward slew. Raising the ceiling toward the 25 W design target requires verified cooling and assembly qualification. The assembly_qualified input is a trusted build/calibration configuration, not a serial command. Upward steps are limited; downward power limiting is immediate. Fan tach timeout and thermistor thresholds are provisional and must be confirmed against the assembled fan/sensor.
Telemetry should include DUT voltage/current/power, case temperature, tach RPM, DAC code, requested/applied current, state, latched faults, firmware revision, calibration ID, sample timestamp and link status. Measured power is V*I; input/output buck efficiency requires a separate input-side measurement. USB and UART share the same state machine and cannot independently own the load.
Host test: gcc -std=c11 -Wall -Wextra -Werror -fsanitize=address,undefined firmware/load_core.c tests/test_load_core.c -lm -o /tmp/test-adom-load && /tmp/test-adom-load. The test covers rejected nonfinite/range commands, bring-up power limiting, immediate downward limiting, hardware fault latching, clear/re-arm separation, stale samples, nonfinite sensors, host loss and 32-bit clock wrap. It does not validate the MCU binary, USB transport, actual pin polarity or physical watchdog response.
Register drivers in firmware/instruments.c explicitly set DAC GAIN=0x0101: divide the internal reference by two and use buffer gain two. This is necessary on the 3.3 V supply; divide-disabled operation with a 2.5 V reference violates the DAC reference headroom requirement. Exact DAC identity, gain readback, reference alarm and INA226 identity are checked before enabling. Register drivers compile with strict warnings, but I2C operation is untested on hardware.
# Firmware and control-panel contract — R0 engineering draft
The portable C safety-policy core is implemented and host-tested. There is no flashable STM32 firmware yet. USB descriptors, HAL, interrupts, hardware validation of the register drivers, ADC calibration, persistence and the hardware adapter remain open. No hardware operation has been demonstrated.
USB CDC ACM is the preferred link to the control panel. The board is self-powered from auxiliary 5 V; USB VBUS is detected but does not power the fan or logic. D+/D− and ground connect to the panel USB host. UART at 3.3 V is an alternative through the molecule contacts; it is not a power interface and must not be wired to 5 V GPIO. Never enable a load by connecting a raw GPIO wire alone.
Proposed transport: newline-delimited JSON, protocol `adom.load/1`, maximum 256 bytes per line, explicit request ID and success/error response. Commands: `identify`, `status`, `set_current` (amperes), `arm`, `off`, `clear_fault`, `heartbeat`. One exclusive controlling session; monotonic sequence numbers; stale/replayed commands rejected. Disconnect, parser overflow, invalid framing or heartbeat loss disables the load. `off` must have priority over queued commands. The panel must show requested and applied current separately.
Every boot starts disabled: configure MCU_ENABLE low and ARM_CLK low before peripheral initialization, keep DAC at zero, and verify the hardware clear/clamp path. `arm` is allowed only with fresh valid telemetry, healthy fan, safe temperature/voltage, a verified assembly configuration and a live host lease. Write DAC zero, pulse ARM_CLK, verify LATCH_Q, then enable; missing latch acknowledgement must time out. Fault clearing never automatically re-arms.
The 1.6 s nominal external watchdog has a 1.12–2.24 s specified timeout. Firmware toggles WDI only after a complete healthy control cycle, never from an unconditional timer interrupt. The independent comparator/latch chain handles case-sensor open/short, overtemperature, overcurrent and overvoltage. The software host lease is 1 s; sensor age limit 50 ms. These timings require hardware acceptance tests.
The policy core starts with a **5 W bring-up ceiling**, 3 A maximum, 24 V maximum and 1 A/s upward slew. Raising the ceiling toward the 25 W design target requires verified cooling and assembly qualification. The `assembly_qualified` input is a trusted build/calibration configuration, not a serial command. Upward steps are limited; downward power limiting is immediate. Fan tach timeout and thermistor thresholds are provisional and must be confirmed against the assembled fan/sensor.
Telemetry should include DUT voltage/current/power, case temperature, tach RPM, DAC code, requested/applied current, state, latched faults, firmware revision, calibration ID, sample timestamp and link status. Measured power is `V*I`; input/output buck efficiency requires a separate input-side measurement. USB and UART share the same state machine and cannot independently own the load.
Host test: `gcc -std=c11 -Wall -Wextra -Werror -fsanitize=address,undefined firmware/load_core.c tests/test_load_core.c -lm -o /tmp/test-adom-load && /tmp/test-adom-load`. The test covers rejected nonfinite/range commands, bring-up power limiting, immediate downward limiting, hardware fault latching, clear/re-arm separation, stale samples, nonfinite sensors, host loss and 32-bit clock wrap. It does not validate the MCU binary, USB transport, actual pin polarity or physical watchdog response.
Register drivers in `firmware/instruments.c` explicitly set DAC GAIN=0x0101: divide the internal reference by two and use buffer gain two. This is necessary on the 3.3 V supply; divide-disabled operation with a 2.5 V reference violates the DAC reference headroom requirement. Exact DAC identity, gain readback, reference alarm and INA226 identity are checked before enabling. Register drivers compile with strict warnings, but I2C operation is untested on hardware.