BUILDS / ENFORCER / V1

enforcer

v1 · draftversions v1

Holds a supply's output under the limits in lab/limits.toml, below any agent. It measures the output itself, sends the supply only setpoints within the limits, and drives a switch that is open unless it holds it closed. A comparator opens the switch by itself if the supply rises past its threshold, whatever the firmware does.

Parts

QTYPARTFORM
1RP2350board with the Pico 2 pinoutauthorized sellers only
1INA239VSSOP-10 on an adapter boardauthorized sellers only
1TLV3011BSOT-23-6 on an adapter boardauthorized sellers only
1AO3401ASOT-23 on an adapter boardauthorized sellers only
1AO3400ASOT-23 on an adapter boardauthorized sellers only
1resistor, 0.1 Ohm, 1 %, 0.25 W, the shunt
1resistor, 18.2 kOhm, 0.1 %
1resistor, 10 kOhm, 0.1 %
1resistor, 100 kOhm, 1 %
1resistor, 4.7 kOhm, 1 %
1resistor, 1 kOhm, 1 %
2capacitor, 100 nF, ceramic
1push button, momentary, normally open
1perfboard, 0.1 inch pitch
1wire, 22 AWG, solid

Used in

Pins

PINBOARD PINNET
GP46UART1 TX, to the DPS5005's serial RXrequired
GP57UART1 RX, from the DPS5005's serial TXrequired
GP1621SPI0 RX, from the INA239's MISOrequired
GP1722SPI0 CSn, to the INA239's CSrequired
GP1824SPI0 SCK, to the INA239's SCLKrequired
GP1925SPI0 TX, to the INA239's MOSIrequired
GP2026EN, through 1 kOhm: high closes the switchrequired
GP2229the button, to GND; pulled up by the RP2350required
3V3(OUT)363V3, powering the INA239 and the TLV3011Brequired
GND38GNDrequired

Walkthrough

At your own risk: not certified or calibrated test equipment. Legal

  1. Build the circuit above on perfboard, with no firmware on the Pico and nothing connected to OUT+.

  2. With the Pico unplugged, set the DPS5005 to 3.3 V (builds/supply) and measure OUT+.

    EXPECT0 V: nothing pulls the switch's gate down.

    AGENTSSetting the DPS5005 is a hardware action: within lab/limits.toml, and logged.

  3. Plug the Pico into the lab computer while holding BOOTSEL, so no firmware runs, and measure OUT+ again.

    EXPECT0 V: GP20 is not driven, and 4.7 kOhm holds EN low.

  4. Still in BOOTSEL, jumper the GP20 end of the 1 kOhm resistor to 3V3, and measure OUT+.

    EXPECTOUT+ follows SUPPLY, less at most the switch's drop.

  5. With the jumper in place and nothing connected to OUT+, raise the DPS5005 in 10 mV steps from 3.3 V until OUT+ falls to 0 V, and note SUPPLY at that step.

    EXPECTSUPPLY between 3.386 V and 3.617 V (the claim hardware-cut).

    AGENTSSetting the supply above lab/limits.toml's 3.4 V needs a person's approval in the session (CLAUDE.md), with nothing on OUT+. Log every setpoint, and record the result as a measurement record citing those entries.

  6. Lower the DPS5005 to 3.3 V, then remove the jumper.

    EXPECTOUT+ returns once SUPPLY falls back below the cut, and falls to 0 V when the jumper comes out.

Claims

CLAIMSIMULATIONON THE BENCH
Its limit logic sends the DPS5005 a setpoint and current limit only when both are within [supply.dps]'s, as asked, and refuses any others rather than clamping themchecked tentzhen-enforcer nothing_above_the_limits_reaches_the_dps; Kani 0.67.0; one input from any stateunknown
An input its limit logic refuses changes nothingchecked tentzhen-enforcer a_refused_input_changes_nothing; Kani 0.67.0; one input from any stateunknown
Its limit logic opens the switch at a reading above [supply]'s ceilings, a failed read, or a tick with no reading since the tick before, in any statechecked tentzhen-enforcer a_bad_reading_or_a_silent_tick_trips_the_output_at_once; Kani 0.67.0; one input from any stateunknown
Its limit logic closes the switch only on the host's On, from off, once a setpoint has been sentchecked tentzhen-enforcer the_output_turns_on_only_by_on_from_off_with_a_setpoint; Kani 0.67.0; one input from any stateunknown
In its limit logic a trip ends only by the button or, under reenable = "agent", the host's clear, and either leaves the switch openchecked tentzhen-enforcer only_the_button_or_an_agent_s_clear_ends_a_trip; Kani 0.67.0; one input from any stateunknown
Whatever the firmware does, the switch opens when SUPPLY rises past a threshold between 3.386 V and 3.617 V, set by a divider of 18200 Ω over 10000 Ω in resistors within 0.001 of their value, in a room within 10 K of 25 degrees Ctested tentzhen-records the_enforcer_s_numbers_follow_from_its_partstrusted maker-datasheets
It reads SUPPLY within 0.00997 V at 3.4 V, and the current within 0.00226 A at 0.2 A, up to 0.4096 A, through a 0.1 Ω shunt within 0.01 of its valuetested tentzhen-records the_enforcer_s_numbers_follow_from_its_partstrusted maker-datasheets
Its switch blocks up to 30 V, above what [supply.upstream] feeds the DPS5005tested tentzhen-records the_enforcer_s_numbers_follow_from_its_partstrusted maker-datasheets
Its switch closes with less than 0.085 Ω only while SUPPLY is at least 2.5 V; below that it may not close fullyunknowntrusted maker-datasheets
With GP20 not driven, 4700 Ω from EN to ground holds the switch open, and GP20's pad sees ground through it and the series resistor, within what erratum E9 needstested tentzhen-records the_enforcer_s_numbers_follow_from_its_partstrusted silicon
GP20 at 3.3 V holds EN at 2.72 V, at least the AO3400A's specified drive, and the comparator pulls EN to at most 0.2 V, below its lowest thresholdtested tentzhen-records the_enforcer_s_numbers_follow_from_its_partstrusted maker-datasheets
Only the enforcer's own setpoint commands reach the DPS5005's serial port: nothing from the host passes throughunknownunknown