Silicon Bring-up · All levels
Boot ROM Execution and Firmware Stage Handoff: Debug Playbook
Debug Playbook for Boot ROM Execution and Firmware Stage Handoff.
Debug playbook
Debug Playbook for Boot ROM Execution and Firmware Stage Handoff is anchored on Instruction-retire progression per boot stage, handoff latency between ROM and first-stage firmware, and first-pass peripheral init success rate.. Convert observed behavior into mechanism-backed and owner-bound actions.
Freeze setup metadata and preserve first-failure state.
Locate first persistent boundary where behavior diverges.
Classify mechanism: dependency, margin, protocol, software, or silicon.
Apply one focused reproducer and one bounded fix.
Re-run replay, corner, and soak confidence matrix.
Review memo template
BRING-UP REVIEW MEMO - Boot Flow Bring-up / Boot ROM Execution and Firmware Stage Handoff
1. Symptom
- Failing metric: Instruction-retire progression per boot stage, handoff latency between ROM and first-stage firmware, and first-pass peripheral init success rate.
- Trigger context: <board/firmware/corner/test window>
- First failing boundary: <power/reset/clock/interface/firmware>
2. Mechanism hypothesis
- Candidate mechanism: Boot ROM is the trust anchor for first instruction fetch and must establish straps, memory map windows, stack setup, and minimal debug telemetry before loading external firmware. Bring-up teams validate stage boundaries explicitly: ROM initialization, memory training or SRAM path, boot media discovery, image authentication (if enabled), and transfer to first-stage loader and later runtime firmware. Failures often stem from subtle contract mismatches such as wrong link address, cache/MMU state mismatch at handoff, stale ABI assumptions in register usage, or timeout constants that fail on cold silicon. Effective methodology builds stage-specific breadcrumbs in scratch registers and retention RAM, allowing lab scripts to reconstruct the last completed milestone even after watchdog resets. The goal is a reproducible, versioned boot contract where each stage declares required hardware state and validates preconditions before proceeding.
- Competing hypotheses: setup, dependency, margin, software path, silicon defect
- Missing evidence: <trace/scope/register/report>
3. Proposed action
- Smallest reversible change: <setup/script/config/firmware>
- Expected movement: <repro rate/latency/pass trend>
- Regression risk: stability, safety, release timeline, ownership handoff
4. Signoff
- Required artifact: Stage contract document with ROM-to-firmware ABI table, milestone breadcrumb map, and recovery decision tree.
- Required owners: boot ROM owner, platform firmware lead, memory subsystem bring-up owner, validation automation owner, system architecture lead
- Final decision: ship, bounded rollout, rollback, respin escalationSilicon bring-up deep dive
Boot closure depends on stage-level checkpoints and explicit transition evidence from reset release to runtime handoff.
Concept diagram
BOOT CLOSURE FLOW
POR -> ROM -> stage-1 -> stage-2 -> runtime
| | | |
checkpoints and traces define first failing handoffMetric graph
BOOT STABILITY SIGNALS
ROM handoff stalls ████
stage repeat failures █████
clean progression ████████Metrics and artifacts to collect
boot stage progression heatmap
checkpoint latency distribution
boot failure signature classifier
firmware-hardware ownership map
Mini case study
A persistent boot hang was resolved only after aligning reset and clock-domain checkpoints with firmware stage logs.
Debug branches
Lock metadata and confirm first missing checkpoint.
Differentiate auth, transport, and dependency failures.
Validate one bounded fix against cold and warm boot paths.
Senior review question
Ask: what is the first failing boundary, which artifact proves it, and who owns bounded closure?
Key takeaways
Tie every bring-up claim to one reproducible setup state and one proving artifact.
Prefer bounded fixes with clear owner and rollback trigger over broad multi-variable edits.
Common pitfalls
Running parallel uncontrolled experiments and losing causality.
Declaring closure without replaying across representative corners.
Escalating severity before bench/setup hypotheses are disproven.
Debug ladder
Sequence: reproduce -> classify -> isolate -> instrument -> bounded fix -> replay.
Avoid parallel broad edits before first root-cause class is proven.