Early release for comment
DOCAAED-CH01
REV2026.10
STATUS1 OF 14 RELEASED
SIDEBAND v1 · UART 8N1 · TX bridge / RX targetreal framing, illustrative values · unsolicited frames in orange

AI coding meets hardware reality.

1 Features

  • A verification-first workflow for coding agents
  • Evidence bound to the image that ships
  • Field incidents from real benches, anonymized

2 Applications

  • Firmware teams adopting AI coding agents
  • Bring-up, drivers, and HIL validation
  • Leads who sign off on agent-written code

3 Description

Most AI coding advice assumes instant deploys, unlimited resources, and tests that run on a laptop. Firmware has different ground truth. This book teaches a workflow built around targets, timing, evidence, and the cost of getting it wrong.

course-correction-memo.yamlsize gate
CellLangDriversFlash (B)SRAM (B)
stubC11/C++17stub HAL?16
cell1C11HAL1224232
cell2C++17HAL1236232
cell3C++17custom45616
cell4 ◆C11custom45216

DEV-01Decision rule frozen against a stub's numbers.

Exhibit 1Size gate after correction. The struck row is what the gate measured first. ◆ marks the Pareto frontier.
chain_summary.jsonrun_20260512T185225Z
all_passed ..................... true
command_id ..................... 45 · 46 · 47
backend_command_status ......... acked ×3
terminal_state ................. IDLE ×3
bench / fleet sensors .......... 2/2 · 3/3 · 5/5
fleet_extra_sensor_ids ......... [] ×3
seam_manual_reset_count_delta .. 0 ×3
Exhibit 2HIL chain receipt. Host status, device event log, and link counters agree for all three programs, with zero manual interventions.

Excerpts from field evidence. Project and device names anonymized; field names and values verbatim.

4

Operating conditions

Your coding agent can write C. The hard part is getting useful help without letting plausible code outrun physical reality. In embedded work, correctness lives on the target, and every assumption needs a route to evidence.

ParameterGeneric AI workflows assumeFirmware work demands
Test loopTests are fast, local, and always observableHardware is the final source of truth
ResourcesCompute, memory, and storage are elasticBytes, cycles, buses, and power are budgets
FailureA bad deployment rolls back in secondsObservability is scarce and failure is physical
ProgressA clean compile counts as progressEvidence must outlive the chat window
5

Contents

Fourteen chapters in four parts that turn a coding agent from an eager code generator into a constrained collaborator. Each chapter is anchored in an incident from real firmware projects. Open a part to see its chapters.

I

Before You Trust the Machine

The constraints that shape everything, how AI is confidently wrong, and a tour of a real benchCH 1–3CH 1 RELEASED
  1. 01The Constraints That Shape Everything
  2. 02Confidently Wrong: A Field Guide to AI Nonsense
  3. 03My Bench, Warts and All
II

The Workflow: Fail Closed

The loop that says no, the checklist, evidence on target, and the router that decides sim or siliconCH 4–7OUTLINED
  1. 04The Loop That Says No for a Living
  2. 05Scar Tissue, Formalized
  3. 06The 48-Byte Evidence Slice That Took Four Minutes
  4. 07Sim or Silicon?
III

War Stories

Drivers on real buses, seven ways to break a debug probe, and fault injection on purposeCH 8–11OUTLINED
  1. 08The Driver That Looked Perfect Until It Met a Real Bus
  2. 09Seven Ways I Broke My Own Debug Probe
  3. 10Seventeen Samples, Sixteen Slots
  4. 11Decisions AI Never Makes Alone
IV

From Bench to Production

Team policy, the model changing under you, and an end-to-end case studyCH 12–14OUTLINED
  1. 12Policy as Code, Not Vibes
  2. 13The Model Under You Changed Last Night
  3. 14What I Built, What Broke, What Shipped
CHAPTER 1 · FREE
The physics cannot change. The workflow can.
The chapter's closing line
6

The Constraints That Shape Everything

Why agents optimize for the gate instead of the requirement, and what to do about it. The chapter works a real bench bug, a reply credited to the wrong request, from claim to verdict, then gives you thirteen operating rules and a day-one repository baseline you can adopt now.

  • BINARY IDENTITY
  • RESOURCE BUDGETS
  • TIMING
  • OBSERVABILITY
  • FAIL-CLOSED LOOP

You'll get a download link for the PDF and EPUB. It's an early release for comment, so reply with anything that's wrong or didn't land. I'll only write again about the book.

7

Revision history

RevChange
2026.10Chapter 1 released: The Constraints That Shape Everything
nextChapters 2 to 14 outlined. Chapter 1 readers hear first as each one is written.
launchFull book, fourteen chapters in four parts.
8

About the author

Chris Slothouber builds embedded systems because he's passionate about the process and about seeing a thing go from imagination to reality.

He takes boards from schematic through fabrication and bring-up, and he's spent enough evenings with a scope on an SPI or I2C bus to trust the wire over the status line. When AI coding agents turned up at his bench, he started writing rules for them, then wrote more every time an agent got around the last batch. Those rules grew into the governance framework and debug-probe tooling behind this book, and the near-misses became its Facepalm Files.

His day jobs mostly didn't have titles yet. He ran bare-metal web hosting across several points of presence and worked at a broadband ISP, and he was streaming live concerts from the venue back when nobody had heard of YouTube. He also picked up ISO 9001 discipline at BlackBerry, kept remote facilities running in Northern Canada, and ended up on the board of a community nonprofit ISP, which means he's been both the person holding the pager and the person asking why it went off.

He lives and works in Seattle.

Use AI on firmware without asking the hardware to absorb the risk.

Read the first chapter and see the workflow. Then decide whether the full book belongs on your bench.

Get the free chapter