pureboot moves to its own repo

pureboot is at git.blackmark.me/avr/pureboot now, with its own history: the
files it kept in pureboot/ sit at the top level there, its CMakeLists is the
merged whole of that unit and the build around it, and the v1..v8 tags moved
with it - each one checks out and compiles to exactly the .text it compiled to
here. The loader that repo builds is byte-identical to the one this commit
removes, verified before the removal rather than after.

Nothing is rewritten on this side. The history and the tags are untouched, so
every commit before this one still has pureboot in it and still builds it;
this is one commit that stops carrying it forward.

What goes with it: the four pureboot files, the thirteen pb*.py protocol
drivers and their four host-side unit tests, pbapp and the pureboot simavr
runner, check_pi.py, pbhw.py, pbrig.py, sizes.py, and the Studio project.
check_unit.cmake goes too - it had no caller left once the unit tests moved.

What is left is the four TinySafeBoot tiers, and the build shrinks to fit
them: 757 lines of CMakeLists to 137, and the preset matrix from 37 chips to
one, because the tiers reimplement an ATmega328P-only protocol and every other
chip in that list was there for pureboot. check.sh loses its size-table pass -
the table it checked was pureboot's README - and the Studio solution loses the
project that is now in the other repo.

Gate green: nine tests, four tiers at their section sizes and each one's
protocol suite against the simulator.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-23 06:05:45 +02:00
parent bf9b86d2fc
commit 7c1a6a140b
35 changed files with 44 additions and 10815 deletions

View File

@@ -1,22 +1,19 @@
# Atmel Studio
`master` carries `bootloader.atsln`, so this branch does too: `ide/bootloader.atsln`
builds the loaders from the same sources Ninja does, to a **byte-identical
`.text`** — the stock 328P pureboot deployment and the `tsb_asm` tier in its
512-byte section (`check-flags.py` below is what holds the flag sets equal, so
the sizes are Ninja's own). CMake remains the build system; the solution is
here so the port opens in Studio as its predecessor did.
builds the loader from the same source Ninja does, to a **byte-identical
`.text`** — the `tsb_asm` tier in its 512-byte section (`check-flags.py` below
is what holds the flag sets equal, so the size is Ninja's own). CMake remains
the build system; the solution is here so the port opens in Studio as its
predecessor did.
## The two projects, and why two
## One project, of four tiers
pureboot is a chip × backend × clock × baud matrix — `pureboot_add_loader()`
resolves a deployment into compile definitions — and a `.cppproj` is one binary
at one set of flags, so a project can only ever be one point of it. `pureboot`
is that point: the stock 328P deployment, USART0 at 115200 on a 16 MHz crystal,
an 8-second activation window. `tsb_asm` is the TinySafeBoot tier that occupies
the same 512-byte section `master`'s `tsb` project targeted.
A `.cppproj` is one binary at one set of flags. `tsb_asm` is the tier that
occupies the same 512-byte section `master`'s `tsb` project targeted, which is
the one worth opening in Studio.
The other three tsb tiers (`tsb_pure`, `tsb_tricks`, `tsb_policy`) are not here.
The other three tiers (`tsb_pure`, `tsb_tricks`, `tsb_policy`) are not here.
They differ from `tsb_asm` in their source file, their section size, and — for
`tsb_policy` — two loop flags; nothing about that is a Studio concern, and what
they exist to demonstrate is a size gradient only the CMake size tests measure.
@@ -32,12 +29,9 @@ says, and two projects sharing a directory would share one object file.
Both configurations compile at `-Os`; Debug adds only `-gdwarf-4`. The `.text`
is therefore identical in both, which is the point — a loader's section is a
**correctness** bound and not a budget. `-Og` builds this same source to 590 B,
and linking it at `--section-start=.text=0x7e00` on a 32 KiB part puts 78 bytes
past flash end **without a diagnostic**: `rcall`/`rjmp` targets there wrap
modulo flash size, so the image dies right after activation. A debug
configuration that silently produces that is worse than none, and DWARF costs no
flash, so the optimisation level stays where correctness needs it.
**correctness** bound and not a budget. A debug configuration that silently
overruns the section is worse than none, and DWARF costs no flash, so the
optimisation level stays where correctness needs it.
## What Studio needs from the machine
@@ -54,25 +48,20 @@ reaching `-std=c++26`.
## Generating and gating
One generated file is required before a project will load at all, and one command
per project checks the flags have not drifted (both from libavr's
One generated file is required before the project will load at all, and one
command checks the flags have not drifted (both from libavr's
`tools/atmelstudio/`):
```sh
for name in pureboot tsb_asm; do
python libavr/tools/atmelstudio/componentinfo.py \
"ide/$name/$name.componentinfo.xml" --device ATmega328P
python libavr/tools/atmelstudio/check-flags.py \
--solution ide/bootloader.atsln --project "$name" --target "$name" \
--compile-commands build/atmega328p-generated/compile_commands.json \
--log "build/as-$name.log"
done
python libavr/tools/atmelstudio/componentinfo.py \
ide/tsb_asm/tsb_asm.componentinfo.xml --device ATmega328P
python libavr/tools/atmelstudio/check-flags.py \
--solution ide/bootloader.atsln --project tsb_asm --target tsb_asm \
--compile-commands build/atmega328p-generated/compile_commands.json \
--log build/as-tsb_asm.log
```
`--project` because one reference describes one binary; `--target` because
`pureboot.cpp` is compiled by every point of the size matrix and the flags
differ per point, so the basename alone does not name a reference. Release is
what the gate compares — the presets define no debug build, and Debug differs
from Release only in `-gdwarf-4`.
Release is what the gate compares — the presets define no debug build, and
Debug differs from Release only in `-gdwarf-4`.
Legacy (the yazoalfa-era submodules) stays on `master`.