NoahandClaude Fable 5.1 8a57057053 Bridge warden-ui's debug channel out of the qemu VM
The rig could drive the UI and detect one outcome: the process died. Nothing
could ask the UI what page it was on or what a tap would land on, because
that channel is a FIFO inside the guest and the initramfs is busybox-only
with no sshd. Scenarios therefore asserted nothing and screenshots went
unread.

run.sh --ctl exposes a second pci-serial port as a unix socket, the same
device the RS485 bridge already rides, listed first so it is always ttyS0.
It also puts warden.ctl on the kernel command line, and init bridges only
when that marker is present: a VM launched with --rs485 alone has a ttyS0
too, and that one is the Modbus wire. The bridge relays one command line in
and the FIFO's reply out, then a sentinel so the reader needs no timeout.

qmp.py gains the channel verbs (nav, page, stats, hit, assert_page,
assert_hit), records every step to results.jsonl as ok/fail/fatal, continues
past an assertion mismatch so one run reports every broken expectation, and
checks the console after EVERY step for the stage-2 init's EXITED line so a
crash is pinned to the step that caused it. assert_hit matches the widget's
bounding box: an icon has no usable caption and two list rows share a class,
but the geometry the UI itself resolved is exact.

The vocabulary is what tools/warden-ctl already speaks over SSH to a real
panel, so a script that runs here runs there. Verified end to end on the rig
(11/11 verbs round-tripped) and against the bench panel, where the same
commands returned byte-identical results.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aHKWzT5EF86RFKRMtAv9n
2026-09-07 21:54:52 -06:00
2026-08-31 22:32:07 +00:00
2026-09-03 18:16:37 -06:00
2026-08-30 07:44:32 -06:00

bfe-core1106-sdk

ci Lines of code Tests Coverage Code quality

A modern, open development environment for the Luckfox Pico 86 Panel (Rockchip RV1106), replacing the vendor SDK, and honest about what runs on real silicon versus what is simulated.

Vendor SDK This repo
Kernel 5.10.160, twice-forked, frozen 6.18.46: a reviewable, subsystem-split patch series onto pristine upstream; full peripheral set (display, touch, wifi, audio, NPU, ...) hardware-verified on a bench panel
Build ~2 GB tree, absolute paths baked in, Kconfig options silently dropped one hermetic script: sha256-pinned source fetch, fail-closed patch apply and config fragments
Off-device testing none; every change means flashing a panel register-level hardware models (sim/) plus a QEMU device VM booting the real kernel, real daemons, and the real UI with display + touch
Config safety memory-map mistakes reach hardware (one bricked a bench unit) static gates (tools/config-lint) catch them before any flash
CI none hosted pipeline: tests, coverage, benchmarks, patch-apply gate, kernel build with an in-CI QEMU boot smoke
Flashing tools closed (upgrade_tool) open (rkdeveloptool)
License mixed GPL-2.0-only, with a per-driver provenance ledger

Quick Start

Requirements: gcc-arm-linux-gnueabihf, qemu-system-arm, curl, cpio, mkfs.ext4, a bare python on PATH (Debian/Ubuntu: python-is-python3), gcc >= 14 (driver harnesses), and Rust (for the simulators' tests).

# 1. Build the kernel: fetch pinned pristine 6.18.46, apply patches/, emit
#    zImage + rv1106-warden.dtb. WORK must sit outside any git checkout.
WORK=$HOME/kbuild-out CROSS_COMPILE=arm-linux-gnueabihf- bash build/build-kernel.sh

# 2. Boot it in the QEMU device simulator (no hardware needed):
bash qemu/mkinitramfs.sh
bash qemu/mkimage.sh
bash qemu/run.sh --kernel $HOME/kbuild-out/linux-6.18.46/arch/arm/boot/zImage --shell

# 3. Run the test suites:
for d in sim tools/config-lint qemu/rs485-bridge; do
  (cd "$d" && cargo test)
done
for d in drivers/*/test; do make -C "$d" check; done  # driver harnesses (gcc >= 14)

Add WARDEN_KCONFIG_FRAGMENT=qemu/configs/virt.fragment to step 1 for the kernel variant with the simulator's extra devices; qemu/README.md has the scenario tests (portal, OTA apply, display + touch, watchdog).

Layout

Directory Contents
patches/ the RV1106 forward-port onto pristine linux-6.18.46, subsystem-split
build/ hermetic kernel build: pinned fetch -> apply patches -> zImage + dtb
qemu/ device simulator: QEMU -M virt boots the real kernel and real userspace
sim/ register-level hardware models (Rust): membus, HPMCU, CRU, Modbus, RGA, NPU
drivers/ hardened hardware-facing drivers: HAL seams, test harnesses
kernel/ forward-port provenance and bring-up records (patches/ is canonical)
tools/ config-lint (static memory-map gates) and dev tooling
build/vendor.manifest the third-party trees this platform builds against (LVGL, the vendor RV1106 SDK), pinned to exact commits; build/fetch-vendor.sh obtains and verifies them
docs/ architecture, ADRs (decisions/), CI/CD

Architecture

One thin hardware abstraction seam per block (a trait in Rust, a function table in C): firmware logic talks to the seam; the seam binds a real backend on the device or a simulated backend on the host. The driver test harnesses measure against the same seam the simulator implements, so the two reinforce each other. Full detail: docs/architecture.md.

Simulator Runs Proves
sim/ register-level Rust models driver and supervisor logic, with fault injection
qemu/ the real kernel + userspace on -M virt boot, init, daemons, networking, OTA, watchdog, display + touch
lvglsim (downstream) the LVGL UI on SDL rendering and UI flows

With the production UI binary in qemu/payload/, run.sh --display on opens the panel's 720x720 screen in a window, mouse clicks landing as touch: device and UI in one VM. Emulation results are never on-silicon evidence; the simulators narrow which claims need a panel.

Principles

  • Open: open tools over closed ones; GPL-2.0-only.
  • Hard: every seam has a fault-injection path; recovery code is tested against failure, not just success.
  • Modern: the newest kernel the hardware can run, current toolchains, Rust for new host-testable code, reproducible builds.

License

GPL-2.0-only, repo-wide (LICENSE; a per-file SPDX identifier governs where present). patches/ and kernel/ are derivative of the Linux kernel and GPL-2.0 vendor code; per-driver origin is tracked in kernel/rv1106-enablement/PROVENANCE.md. Contributions are accepted under the same license (inbound = outbound).

S
Description
No description provided
Readme GPL-2.0
2.1 MiB
Languages
C 52%
Rust 22.9%
Shell 15.9%
Python 4.2%
Makefile 2.4%
Other 2.6%