First recursive code-review-harness pass over the authored SDK code (sim/,
config-lint, flowgen, drivers/{relays,freshness}, build/, ci.yml). Four parallel
dimension reviewers; all findings at every severity corrected per workspace rule.
Correctness / reliability:
- freshness.c min_budget_ms: use a `seen` flag, not `best==0`, as the empty
sentinel — a zero-tolerance (max_stale_ms==0) binding was silently widened to a
looser neighbour's budget. Regression test added; still 66/66 MC/DC.
- config-lint parse_reserved_ranges: match `reg` as a whole property token (ident
boundary before, `=` after) so `reg-names` / a `region-*` label no longer
mis-parses into a bogus reserved range.
- config-lint loader check: fail closed — flag any loader with a LOAD_ADDR that is
not a known-safe boot component, instead of only known MCU names, so a future
coprocessor ("Rtos"/"Bl32") can't slip past the 0x40000-brick gate.
- build-kernel.sh: sha256 verification is now mandatory (refuse to build if the pin
is missing) and the mktemp scratch tree is removed on exit (trap), while a
caller-provided WORK is left intact for CI artifact upload.
Test quality:
- freshness: added the age==max_stale boundary case and a clock-wraparound
(now < last_ok) fail-safe-to-UNKNOWN test.
- relays: unsetenv(WARDEN_GPIO_ROOT) at main() so the NULL-env arm is hermetic.
Security / CI:
- ci.yml: top-level `permissions: contents: read` (badges overrides to write);
pin taiki-e/install-action to commit SHA (v2.86.7).
Maintainability / docs:
- drivers/enforce-mcdc.sh: one shared, name-derived gate replaces the two
copy-pasted per-driver scripts; Makefiles call ../../enforce-mcdc.sh.
- docs/architecture.md: §3/§4/§6/§7 rewritten to match reality — NPU/RGA models,
config-lint, and the relays+freshness MC/DC harnesses are done; kernel §6 now
reflects the 5.10->6.18.46 forward-port (ADR-0001), not the superseded plan44/6.6.
- README: status blurb + layout table corrected (kernel/, .github/; stale ci/ and
patches/ descriptions fixed). hpmcu "8 tests" -> 7 in docs.
- freshness.{c,h}: ADR reference points at flare-edge ADR-0004 (warden-sdk's
ADR-0004 is the CI runner — number collision).
- normalize rustfmt drift across sim/ + config-lint.
All green: sim 37 tests, config-lint 8 tests, both drivers 100% MC/DC (relays
40/40, freshness 66/66), clippy clean under -D warnings, gitleaks clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017wB8KB3MMQztRDXCMCkPrf
42 lines
1.4 KiB
Makefile
42 lines
1.4 KiB
Makefile
# MC/DC unit harness for drivers/relays/relays.c.
|
|
#
|
|
# make check — build, run, and FAIL unless relays.c hits 100% MC/DC
|
|
# (condition) coverage and every unit check passes.
|
|
# make report — per-condition gcov annotation (build/relays.c.gcov).
|
|
# make clean
|
|
#
|
|
# Requires gcc >= 14 (for -fcondition-coverage) and its matching gcov.
|
|
CC ?= gcc
|
|
GCOV ?= gcov
|
|
CFLAGS := -O0 -g -Wall -Wextra -I..
|
|
COVFLAGS := --coverage -fcondition-coverage
|
|
BUILD := build
|
|
|
|
.PHONY: check report clean
|
|
.DEFAULT_GOAL := check
|
|
|
|
$(BUILD):
|
|
@mkdir -p $(BUILD)
|
|
|
|
# relays.c carries the coverage flags; the test driver is plain.
|
|
$(BUILD)/test: test_relays.c ../relays.c ../relays.h | $(BUILD)
|
|
@$(CC) $(CFLAGS) $(COVFLAGS) -c ../relays.c -o $(BUILD)/relays.o
|
|
@$(CC) $(CFLAGS) -c test_relays.c -o $(BUILD)/test_relays.o
|
|
@$(CC) $(COVFLAGS) $(BUILD)/relays.o $(BUILD)/test_relays.o -o $(BUILD)/test
|
|
|
|
check: $(BUILD)/test
|
|
@echo "== running relays MC/DC harness =="
|
|
@rm -f $(BUILD)/relays.gcda
|
|
@$(BUILD)/test; echo $$? > $(BUILD)/test.rc
|
|
@echo
|
|
@echo "== MC/DC (condition) coverage of relays.c =="
|
|
@$(GCOV) --conditions --branch-probabilities -o $(BUILD) ../relays.c >$(BUILD)/gcov.log 2>&1 || true
|
|
@mv -f *.gcov $(BUILD)/ 2>/dev/null || true
|
|
@bash ../../enforce-mcdc.sh $(BUILD)/gcov.log $(BUILD)/relays.c.gcov $(BUILD)/test.rc
|
|
|
|
report: check
|
|
@grep -nE "condition.*not covered|conditions covered" $(BUILD)/relays.c.gcov || true
|
|
|
|
clean:
|
|
@rm -rf $(BUILD)
|