01Reset, startup, memory, and linked-image control
Provide the processor and ABI, boot source, reset causes, startup file, vector table, ROM and RAM regions, initialized and zeroed data, retained memory, stacks, heap policy, linker script, map file, generated image and one reset-before-main failure. Ask for the first valid instruction and every assumption after it.
Confirm: The person traces reset state through vector fetch, stack setup, early platform initialization, runtime data copy and zeroing, constructors where applicable, privilege and execution transitions and the application entry; reconciles processor manuals, board records and actual memory; assigns every section to an owned region; accounts for alignment, permissions, no-load and retained areas, boot headers and reserved storage; protects vectors and data from linker garbage collection where required; inspects map and disassembly; bounds stack and heap use; identifies toolchain, ABI and optimization effects; and reproduces the exact binary rather than treating source success as image proof.
02Registers, interrupts, DMA, and driver boundaries
Provide a peripheral with clock, reset, pin, memory-mapped registers, interrupt and DMA paths, a datasheet and erratum, two board revisions, concurrent access, malformed traffic, a timeout and a hard fault. Ask which observation would disprove the code's hardware model.
Confirm: The person checks address, width, alignment, access type, reset values, reserved bits, read and write side effects, masks, sequence, endianness and required barriers against the exact silicon; separates board description from reusable driver logic; owns clock, reset, pin, power and interrupt ordering; acknowledges and clears interrupts correctly; keeps handler work bounded and shares state safely; treats DMA buffers, cache coherence and ownership explicitly where relevant; parses external input within fixed bounds; handles timeout and partial transfer; decodes exception status and captures useful context; and confirms critical behavior with traces, instruments and identified targets rather than headers alone.
03Boot chain, provisioning, signed update, and recovery
Provide immutable and mutable boot stages, two image slots, manifests and versions, signing roles, manufacturing and owner identity, lifecycle and debug states, an incompatible image, interrupted power, failed confirmation, rollback attempt, compromised key and independent recovery path. Ask what can become executable and who may authorize it.
Confirm: The person maps each root of trust, verification key, manifest, measurement, security counter, privilege change and writable region; distinguishes integrity and origin from compatibility and safe behavior; binds image identity to hardware, configuration, dependencies and persistent-data rules; separates build signing, production signing, provisioning and fleet authorization; constrains debug by lifecycle state; handles key rotation and revocation; defines staged installation, power-loss behavior, health confirmation, revert and downgrade policy; tests corrupt, old, partial and wrong-target images; protects recovery from the failing runtime; and records device, image and decision identities without claiming a bootloader option alone creates security.
04Build, target, manufacturing, and field evidence
Provide source and generated inputs, pinned tools, two hardware variants, a probe and trace path, unit and target tests, production programming and test, noisy power and repeated resets, a field-only failure, bounded logs, fault state, exact symbols and a receiving team. Ask for the evidence chain from commit to repaired device.
Confirm: The person records compiler assembler linker and image tools, flags, generated headers, board configuration, libraries, map, disassembly, hashes, manifests and symbols; uses warnings, static analysis and host tests without confusing them with target execution; layers emulation, on-target, interface, fault-injection, power-cycle, soak and hardware-variation evidence by risk; verifies programming, readback policy, identity, provisioning, calibration and test traceability; preserves reset causes, breadcrumbs, trace and fault frames within privacy and timing limits; matches dumps to exact symbols; distinguishes hardware from firmware hypotheses; reproduces and contains field faults; and hands off fixtures, recovery procedures, known limits and support ownership.