Hardware e-stop¶
The e-stop is a fail-safe input shared by motion-capable components. A valid heartbeat is required before a production motion entry point may command an arm; a pressed, disconnected, malformed, or timed-out signal must stop motion.
Public contract¶
The stop path fails closed: loss of signal is treated as a stop.
Motion consumers must hold or safely retract according to their local hardware contract; they must not continue stale targets.
Recovery must re-seed command state from measured state before resuming.
The e-stop is a motion stop, not a guarantee that power is removed.
The firmware and consumer implementations are in
firmware/estop_pico/, cpp/teleop/, and
python/lerobot_robot_tatbot/. Keep their protocol and timeout tests together
with code changes.
The active C++ or Python monitor also publishes tatbot.estop-status/1 as an
atomic runtime snapshot. A separate writer publishes it so slow or failed
filesystem writes cannot stall heartbeat consumption. tatbot status reads that snapshot instead of opening
the serial device a second time. It accepts health only when the device matches,
the producer PID is alive, the state and heartbeat fields are internally consistent, and the snapshot
is at most one second old. Missing or stale telemetry is reported as unknown;
pressed and fault are reported as failed. The snapshot is observability only
and is never an input to the motion safety path.
Observers discover the same user’s snapshot in the desktop runtime directory
or the login-session fallback under /tmp, so separate terminal environments
can share one monitor. Multiple snapshot locations are reported as ambiguous;
invalid snapshots remain rejected. An explicit TATBOT_ESTOP_STATUS path stays
authoritative and never falls back to another monitor.
Testing boundary¶
Run parser, timeout, reconnect, and launcher tests with no arm connected. A motion entry point validates its live heartbeat; this document adds no separate per-command operator confirmation. The remaining physical-test boundaries are in Safety scope.