Repository navigation
Phase-1: close the OCP backup and OVP latch protection gaps (firmware 0.2 + OVP_TRIP to PB4) - #13
Merged
Merged
Conversation
Row 2: lb_core_ocp_sample latches OCP_BACKUP when the INA240 current (ADC, every 1 ms) exceeds 110 % of i_max, or the INA228 ALERT is low, for more than 5 ms with the output closed. ina228.c now programs SOVL to the same limit (1.25 uV/LSB at ADCRANGE=1) and DIAG_ALRT to transparent, active-low, per-conversion compare. Host-tested. Row 4: PB4 reads OVP_TRIP (TLV7011 output). Its EXTI4 rising edge sets PS_OFF and clears OUT_REQ within microseconds; the 1 ms tick latches OVP_HW, and re-latches after RESET while the comparator is still high. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
The TLV7011 output only reached Q9 (disconnect), so an overvoltage opened the output but left the LM5145 running and nothing latched. OVP_TRIP now also goes to U10 pin 41 (PB4, a spare pin), where the firmware 0.2 EXTI handler kills EN and latches OVP_HW. Schematic: surgical edits (OVP_TRIP local labels -> global, PB4 no-connect -> OVP_TRIP label); gen_phase1.py / sheets_common.py mirror it (ovp_to_mcu param, EXPECTED_NETS). check_netlist and check_footprints pass. Board: 21 signal nets in the U10-U7 region ripped and re-routed with Freerouting 1.9 + finish_routes, fb_reroute rerun, three overlap stubs trimmed. DRC: 0 unconnected, 0 errors, 10 silk warnings (was 11). Fab zip regenerated; placement and BOM unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
docs/04 matrix rows 2 and 4 and a design note on where the OVP latch lives; docs/07 pin map (PB4) and tick order; docs/12 bench-test predictions for rows 2 and 4 now expect a latch; HANDOVER firmware row. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Udara Vimarsha · project thread
Before: two rows of the protection matrix (docs/04) did not work as specified. The backup overcurrent latch (row 2) waited on the INA228 ALERT pin, but no alert limit was ever programmed, so it could never fire. The hardware overvoltage comparator (row 4) opened the output disconnect, but its signal reached nothing else: the LM5145 kept running and nothing latched.
After: row 2 latches
OCP_BACKUPwhen the output current stays above 110 % of I_max (8.8 A) for more than 5 ms, seen either by the INA240 on the ADC or by the INA228 alert, which is now programmed to the same limit. Row 4 still opens the disconnect in hardware, and now also kills the converter within microseconds and latchesOVP_HWuntilRESET(0x5A).Row 4 needed one hardware change: the comparator output (OVP_TRIP) is now also routed to the MCU's spare PB4 pin, where an EXTI interrupt kills EN and the firmware holds the latch. No parts are added, so the BOM and placement file are unchanged.
How
module_core: newlb_core_ocp_sample()(host-tested: 5 ms threshold, a dip resets the count, alert-only trip, no trip while the output is open).ina228.c: SOVL = 14080 (1.25 µV/LSB at ADCRANGE=1, checked against the INA228 datasheet, Table 7-17); DIAG_ALRT transparent, active low.main.c: PB4 input with pull-down plus an EXTI4 rising-edge handler (sets PS_OFF, clears OUT_REQ, ignores edges already gone at ISR entry). The 1 ms tick latches the fault and re-latches after a reset while the comparator is still high. Firmware version is now 0.2.gen_phase1.pyandsheets_common.pymirror this;check_netlistandcheck_footprintspass.finish_routes.py), thenfb_reroute.pywas re-run and three overlap stubs were trimmed. DRC: 0 unconnected, 0 errors, 10 silk warnings (was 11). The fab zip is regenerated. The new trace stays more than 20 mm from the switch node.🤖 Generated with Claude Code
https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
Generated by Claude Code