Skip to content

Phase-1: close the OCP backup and OVP latch protection gaps (firmware 0.2 + OVP_TRIP to PB4) - #13

Merged
udaravima merged 3 commits into
developmentfrom
claude/phase1-protections-vzysax
Sep 28, 2026
Merged

udaravima merged 3 commits into
developmentfrom
claude/phase1-protections-vzysax

Conversation

@udaravima

Copy link
Copy Markdown
Owner

Requested by Udara Vimarsha · project thread

Before: two rows of the protection matrix (docs/04) did not work as specified. The backup overcurrent latch (row 2) waited on the INA228 ALERT pin, but no alert limit was ever programmed, so it could never fire. The hardware overvoltage comparator (row 4) opened the output disconnect, but its signal reached nothing else: the LM5145 kept running and nothing latched.

After: row 2 latches OCP_BACKUP when the output current stays above 110 % of I_max (8.8 A) for more than 5 ms, seen either by the INA240 on the ADC or by the INA228 alert, which is now programmed to the same limit. Row 4 still opens the disconnect in hardware, and now also kills the converter within microseconds and latches OVP_HW until RESET(0x5A).

Row 4 needed one hardware change: the comparator output (OVP_TRIP) is now also routed to the MCU's spare PB4 pin, where an EXTI interrupt kills EN and the firmware holds the latch. No parts are added, so the BOM and placement file are unchanged.

How

  • module_core: new lb_core_ocp_sample() (host-tested: 5 ms threshold, a dip resets the count, alert-only trip, no trip while the output is open).
  • ina228.c: SOVL = 14080 (1.25 µV/LSB at ADCRANGE=1, checked against the INA228 datasheet, Table 7-17); DIAG_ALRT transparent, active low.
  • main.c: PB4 input with pull-down plus an EXTI4 rising-edge handler (sets PS_OFF, clears OUT_REQ, ignores edges already gone at ISR entry). The 1 ms tick latches the fault and re-latches after a reset while the comparator is still high. Firmware version is now 0.2.
  • Schematic: surgical edits only (the sheets are hand-owned). The two OVP_TRIP labels became global, and the PB4 no-connect became an OVP_TRIP label. gen_phase1.py and sheets_common.py mirror this; check_netlist and check_footprints pass.
  • Board: 21 signal nets around U10 and U7 were ripped up and re-routed (Freerouting 1.9 + finish_routes.py), then fb_reroute.py was re-run and three overlap stubs were trimmed. DRC: 0 unconnected, 0 errors, 10 silk warnings (was 11). The fab zip is regenerated. The new trace stays more than 20 mm from the switch node.
  • Docs: 04, 07, 12 (bench-test predictions for rows 2 and 4) and HANDOVER.

🤖 Generated with Claude Code

https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW


Generated by Claude Code

Row 2: lb_core_ocp_sample latches OCP_BACKUP when the INA240 current
(ADC, every 1 ms) exceeds 110 % of i_max, or the INA228 ALERT is low,
for more than 5 ms with the output closed. ina228.c now programs SOVL
to the same limit (1.25 uV/LSB at ADCRANGE=1) and DIAG_ALRT to
transparent, active-low, per-conversion compare. Host-tested.

Row 4: PB4 reads OVP_TRIP (TLV7011 output). Its EXTI4 rising edge sets
PS_OFF and clears OUT_REQ within microseconds; the 1 ms tick latches
OVP_HW, and re-latches after RESET while the comparator is still high.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
The TLV7011 output only reached Q9 (disconnect), so an overvoltage
opened the output but left the LM5145 running and nothing latched.
OVP_TRIP now also goes to U10 pin 41 (PB4, a spare pin), where the
firmware 0.2 EXTI handler kills EN and latches OVP_HW.

Schematic: surgical edits (OVP_TRIP local labels -> global, PB4
no-connect -> OVP_TRIP label); gen_phase1.py / sheets_common.py
mirror it (ovp_to_mcu param, EXPECTED_NETS). check_netlist and
check_footprints pass.

Board: 21 signal nets in the U10-U7 region ripped and re-routed with
Freerouting 1.9 + finish_routes, fb_reroute rerun, three overlap stubs
trimmed. DRC: 0 unconnected, 0 errors, 10 silk warnings (was 11).
Fab zip regenerated; placement and BOM unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
docs/04 matrix rows 2 and 4 and a design note on where the OVP latch
lives; docs/07 pin map (PB4) and tick order; docs/12 bench-test
predictions for rows 2 and 4 now expect a latch; HANDOVER firmware row.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NmR2rbcK8CFj3PgzqsaRtW
@udaravima udaravima self-assigned this Sep 28, 2026
@udaravima
udaravima marked this pull request as ready for review September 28, 2026 20:16
@udaravima
udaravima merged commit df4d6dd into development Sep 28, 2026
3 checks passed
@udaravima
udaravima deleted the claude/phase1-protections-vzysax branch September 29, 2026 03:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants