# ATLAS X — System Architecture & Engineering Specification

**Document ID:** AX-ARCH-001  
**Revision:** A / Baseline 0.2  
**Date:** 2026-08-02  
**Status:** Architecture frozen for schematic development

## 1. Product definition

ATLAS X is a separate, modular intelligent computer that works beside a MacBook Air M1.
It contains an HP 250 G6 motherboard as a headless Windows/Linux computer, a deterministic
hardware supervisor based on ESP32-S3, a powered USB hub, direct Ethernet connectivity,
and an AI software stack installed on the HP.

The Mac remains intact and removable. One USB-C cable connects ATLAS X to the Mac for data
only; it must not charge or back-feed the Mac. ATLAS X also has one external certified DC
power input.

### Frozen product roles

| Element | Official role |
|---|---|
| MacBook Air M1 | Primary user computer, ATLAS app, chat/control UI, remote desktop client |
| HP 250 G6 motherboard | Headless compute node, Windows/Linux programs, ATLAS Core services and local AI |
| ESP32-S3 control board | Deterministic power control, state sensing, temperature monitoring and safety |
| Internal powered USB hub | One-cable data fan-out from the Mac; kept separate from the custom PCB |
| Direct Ethernet link | Mac-to-HP data path through a USB Ethernet adapter; no Ethernet traffic on the control PCB |
| External DC supply | Single certified low-voltage source for ATLAS X; no mains voltage inside the case |

The old variants that removed the HP motherboard, added a case-fan circuit, required an
external OLED/buttons panel, or described a USB-C connector on the ESP32-S3-DevKitC-1 v1.1
are superseded by this document.

## 2. System block diagram

```mermaid
flowchart TD
    MAC["MacBook Air M1\nATLAS app"]
    HUB["Powered USB 3 hub\ndata only upstream"]
    ETH["USB–Gigabit Ethernet\nadapter"]
    HP["HP 250 G6\nATLAS Core + local AI"]
    MCU["ATLAS Control Board\nESP32-S3 Sentinel"]
    ISO["Isolated HP interface\nPOWER + state sense"]
    PSU["Certified external DC supply"]
    DCDC["Protected isolated 5 V branch"]

    MAC -->|"one USB-C cable"| HUB
    HUB -->|USB| ETH
    ETH -->|Ethernet| HP
    HUB -->|USB serial| MCU
    MCU --> ISO
    ISO --> HP
    PSU --> HP
    PSU --> DCDC
    DCDC --> HUB
```

### Electrical domains

1. **HP domain:** HP motherboard and its original power-input circuitry.
2. **Mac/control domain:** self-powered hub, USB Ethernet adapter and ESP32 carrier.
3. **Isolation boundary:** only optical components may cross between the HP domain and the
   ESP32 control domain.

The Ethernet connection relies on the normal transformer isolation of compliant Ethernet
ports. The custom PCB must not create a parallel ground connection between HP and Mac.

## 3. Power architecture

### 3.1 System-level power tree

- Use one external certified DC brick. Its output voltage, named `V_HP`, must match the
  rating printed on the original HP adapter and be verified before ordering.
- Feed the HP through a dedicated fused/protected branch that preserves the original HP
  power connector and identification requirements.
- Feed the hub and controller through a separate, galvanically isolated `V_HP → 5 V`
  DC/DC module.
- Size the final supply for measured worst-case HP consumption plus the 5 V branch,
  conversion losses and at least 25% engineering margin.
- Keep mains voltage, lithium charging, battery management and HP high-current distribution
  off the Revision A control PCB.
- Use reverse-polarity protection, a replaceable fuse or e-fuse on each branch, and a chassis
  DC disconnect accessible without opening the electronics compartment.

### 3.2 USB power rules

- The Mac-facing USB-C connection is upstream data only and does not provide product power.
- Select a self-powered hub with documented upstream VBUS isolation/no-backfeed behavior.
- The ESP32-S3-DevKitC-1-N8R8 v1.1 is powered internally from the hub through one of its
  Micro-USB ports. The carrier must not inject a second 5 V or 3.3 V source into the DevKit.
- Both DevKit Micro-USB connectors remain mechanically accessible for service.

## 4. Control Board — Revision A

### 4.1 Scope

The control PCB is a low-voltage carrier and supervisor. It does not carry HP operating
power, USB 3 traffic, Ethernet traffic, storage buses or laptop-internal data buses.

Use an official removable **ESP32-S3-DevKitC-1-N8R8 hardware v1.1** on two female socket
headers. The N8R8 module has 8 MB flash and 8 MB PSRAM. On this board revision, the RGB LED
uses GPIO38; GPIO35–37 are unavailable because they are used by the octal flash/PSRAM path.

### 4.2 Frozen GPIO allocation

| GPIO | Net / function | Direction | Revision A rule |
|---:|---|---|---|
| 4 | `HP_STATE_IN` | Input | Active-high output of the non-contact optical power-LED pickup |
| 5 | `FUTURE_KEY_1` | Input | Unpopulated future panel header only |
| 6 | `FUTURE_KEY_2` | Input | Unpopulated future panel header only |
| 7 | `HP_PWR_CTRL` | Output | Active high; 100 kΩ pull-down; safe LOW at reset |
| 8 | `FUTURE_I2C_SDA` | I/O | Unpopulated OLED/expansion header |
| 9 | `FUTURE_I2C_SCL` | I/O | Unpopulated OLED/expansion header |
| 10 | `FUTURE_KEY_3` | Input | Unpopulated future panel header only |
| 15 | `STATUS_LED` | Output | Internal service LED |
| 16 | `TEMP_1W` | I/O | DS18B20 data with 4.7 kΩ pull-up to 3.3 V |
| 17 | `EXP_GPIO17` | I/O | Future-only expansion |
| 18 | `EXP_GPIO18` | I/O | Future-only expansion |
| 19 | `USB_D-` | Reserved | Never allocate; native USB |
| 20 | `USB_D+` | Reserved | Never allocate; native USB |

GPIO0, GPIO3, GPIO45 and GPIO46 are treated as boot/strapping-sensitive and are not exposed
for ordinary expansion. GPIO38 is not used by the carrier because it drives the onboard RGB
LED. GPIO43/44 are reserved for the DevKit USB-to-UART bridge and servicing.

### 4.3 HP power-button output

- Use a genuine Panasonic `AQY212EH`, normally-open 1 Form A PhotoMOS relay in DIP-4.
- Drive its input from the safety-gated `GPIO7` path through a calculated 1% resistor that
  guarantees operation at the logic gate's minimum `VOH` and the PhotoMOS maximum `VF`, while
  keeping nominal LED current near 5–8 mA and below the Panasonic input limit.
- Add a 100 kΩ pull-down from `HP_PWR_CTRL` to ESP32 ground.
- Connect its isolated output only to `HP_PWR_SW_A` and `HP_PWR_SW_B` on a 2-pin JST XH
  carrier connector.
- The HP-side cable remains `TBD-HARNESS` until the two momentary-switch contacts are found
  with the motherboard unpowered and verified by continuity testing.
- Do not add ground fills, test points, pull resistors or protection parts from either
  isolated output net to the ESP32 domain.
- Silkscreen: `HP POWER SW — ISOLATED`.

**Hardware safety limit:** place a non-retriggerable maximum-on timer and logic gate before the
PhotoMOS input. Use an `LTC6993-1` rising-edge one-shot at 3.3 V followed by an
`SN74LVC1G08` AND gate, or a provably equivalent non-retriggerable circuit. The command path is
allowed only while both raw `HP_PWR_CTRL` and the time-limited hardware window are high. Configure
the nominal window to approximately 7.1 s; `NDIV = 2^21` and `RSET = 169 kΩ, 1%` are the starting
calculation. Verify the DIV network and worst-case tolerance from the current Analog Devices
datasheet. A normal 500 ms command passes unchanged, a manual emergency hold may last 6 s, and a
stuck-high GPIO is cut off before 8 s. The circuit must re-arm only after GPIO7 returns LOW.

### 4.4 Galvanically isolated HP state input

- Revision A uses a non-contact visible-light pickup over the original HP power LED. There is no
  electrical tap into the HP LED board or ribbon.
- Use a remote Vishay `TEPT4400` phototransistor inside an opaque shroud, connected to a two-pin
  carrier connector as `HP_LIGHT_RAW` and control-domain GND.
- On the carrier, provide a fixed minimum pull-up plus an adjustable pull-up, RC filtering and a
  3.3 V Schmitt-trigger inverter such as `SN74LVC1G14`. The conditioned output is active-high
  `HP_STATE_IN` on GPIO4.
- Verify sensor lead identity, trimmer footprint and filter values from primary datasheets. The
  adjustment must remain accessible with the carrier installed.
- Require a stable state for at least 100 ms in firmware.
- This input is evidence of electrical state, not evidence that the operating system is ready.

### 4.5 Monitoring and service provisions

- One external DS18B20 probe connector for internal case temperature.
- `POWER` LED connected to the true 3.3 V rail through its resistor.
- `STATUS` LED controlled by GPIO15.
- Test points: `3V3`, `GND`, `HP_PWR_CTRL`, `HP_STATE_IN`, `TEMP_1W`, `I2C_SDA`, `I2C_SCL`.
- Unpopulated headers for a future OLED and three low-risk menu buttons; no front panel or
  physical HP power control is fitted in Revision A.
- No fan driver, fan connector, display or user buttons are populated in Revision A.

### 4.6 Mechanical PCB rules

- Two layers, 1.6 mm FR-4, 1 oz copper, target envelope no larger than 100 × 80 mm.
- Four 3.2 mm M3 holes, rounded corners and clear connector/polarity labels.
- Put the ESP32 antenna at the PCB edge and implement the complete Espressif keep-out on all
  copper layers, traces and components.
- Keep both Micro-USB ports, BOOT and RESET accessible.
- Use through-hole connectors where practical; small logic/safety ICs may be assembled SMD.
- Add `ATLAS X — CONTROL REV A` and the board revision to silkscreen.
- Create a visible no-copper isolation corridor beneath and around the PhotoMOS boundary.

## 5. Software and AI architecture

ATLAS X has three cooperating software layers. The AI is part of the product, but it is not
allowed to replace deterministic safety logic.

### 5.1 ATLAS Sentinel — ESP32 firmware

Responsibilities:

- hardware state machine and watchdog;
- isolated HP power-button control;
- isolated HP state input and temperature acquisition;
- USB serial protocol with framing, version, CRC and command acknowledgements;
- persistent desired-state record in NVS;
- event and fault log;
- safe startup with all dangerous outputs disabled.

Wi-Fi and Bluetooth are disabled by default in Revision A. USB serial is the authoritative
control channel.

### 5.2 ATLAS Core — service installed on the HP

Responsibilities:

- local AI agent, conversation memory and system knowledge;
- hardware/software monitoring and diagnostics;
- safe operating-system shutdown;
- heartbeat and readiness API on the direct Ethernet link;
- controlled opening of files and programs on the HP;
- automation tasks with an auditable action log;
- model-backend abstraction for future acceleration.

The base system remains useful offline. A small local model and deterministic tools run on
the HP; larger inference may optionally use the Mac M1 or a cloud backend, but loss of those
backends must not disable hardware control, monitoring or safe shutdown. The exact local
model is selected only after recording the HP CPU, RAM, GPU and available SSD capacity.

Use a local SQLite database for memory, settings, events and action audit. Bind the Core API
to the direct ATLAS network interface and require an application token; do not expose it to
public networks by default.

### 5.3 ATLAS App — macOS

Responsibilities:

- primary chat and system-control interface;
- USB serial link to Sentinel;
- Ethernet heartbeat to Core;
- display of electrical, OS and AI state;
- automatic remote-desktop launch after the HP reaches `ONLINE`;
- cancellation of a pending disconnect shutdown when valid heartbeat returns;
- two-phase confirmation for emergency forced shutdown.

### 5.4 AI privilege boundary

The AI may monitor, diagnose, prepare workflows and execute ordinary approved software
actions. It may request an HP start or safe OS shutdown through the app policy layer.
It may never independently issue the emergency long press, bypass confirmation, alter
firmware safety limits or rewrite the persistent desired state.

## 6. Power and lifecycle state machine

```mermaid
stateDiagram-v2
    [*] --> SELF_TEST
    SELF_TEST --> STANDBY: desired OFF
    SELF_TEST --> RESTORE: desired ON
    RESTORE --> STARTING: HP confirmed OFF
    RESTORE --> ONLINE: HP already ON
    STARTING --> ONLINE: LED + heartbeat valid
    STARTING --> FAULT: startup timeout
    ONLINE --> SHUTDOWN_PENDING: heartbeat lost
    SHUTDOWN_PENDING --> ONLINE: heartbeat restored within 2 min
    SHUTDOWN_PENDING --> SHUTTING_DOWN: 2 min expired
    SHUTTING_DOWN --> STANDBY: HP confirmed OFF
    FAULT --> STANDBY: app clears fault
```

### 6.1 Normal startup

1. The user starts ATLAS X only from the Mac app.
2. Sentinel confirms that the isolated HP state is OFF.
3. Sentinel generates one nominal 500 ms PhotoMOS pulse.
4. The app waits for both the stable HP state input and the ATLAS Core network heartbeat.
5. Only after both are valid does the system enter `ONLINE` and open remote desktop.

### 6.2 Blackout recovery

- Store `desired_state`, not a guessed last electrical sample.
- On power return, run self-test and wait for power stability.
- If `desired_state = ON`, check the HP state before acting.
- If the HP is off, perform exactly one automatic normal-start attempt.
- If readiness fails, enter `FAULT`; do not retry until the app explicitly clears the fault.
- If the HP BIOS has already restarted the machine, do not send a power pulse.

### 6.3 Loss of Mac/app

- The Mac app sends independent authenticated heartbeats to HP Core over Ethernet and to
  Sentinel over USB serial.
- After loss of heartbeat, start a 2-minute countdown.
- A valid heartbeat during the countdown cancels shutdown automatically.
- If the timeout expires, Core requests a normal operating-system shutdown while Sentinel
  records `desired_state = OFF`; Sentinel does not press the HP power button.
- The ESP32 does not simulate a power-button press merely because USB disappears.
- For an ordinary app-requested shutdown, the app first records `desired_state = OFF` in
  Sentinel and then asks Core to shut down the operating system.

### 6.4 Emergency forced shutdown

- Available only in the Mac app when HP electrical state is ON.
- Require two distinct confirmations and a two-phase `PREPARE` / `COMMIT` exchange within a
  short validity window.
- Sentinel then allows one 6 s hold, bounded by the independent hardware timer below 8 s.
- Never execute this command automatically, through AI text alone, at boot or during recovery.

## 7. Serial protocol baseline

Use a versioned binary or CBOR-framed protocol, not free-form text commands. Every frame has:

- magic/version;
- message type;
- monotonically increasing sequence number;
- payload length;
- payload;
- CRC32;
- acknowledgement or explicit error code.

Minimum commands: `GET_INFO`, `GET_STATE`, `GET_TELEMETRY`, `START_HP`, `PREPARE_FORCE_OFF`,
`COMMIT_FORCE_OFF`, `CANCEL`, `CLEAR_FAULT`, `GET_LOG`. Duplicate sequence numbers must be
idempotent and may not create a second power pulse.

## 8. Physical product and 3D assembly plan

The final 3D model will be a parametric assembly, not a decorative shell. It must include:

- HP motherboard outline, original heat sink, fan and complete exhaust/air-intake clearance;
- SSD, power-input board, power-button/LED harness and every retained HP daughterboard;
- ATLAS control PCB with connector keep-outs and ESP32 antenna keep-out;
- powered hub, USB Ethernet adapter, isolated DC/DC module and protected power distribution;
- cable bend radii, connector insertion space and service loops;
- future AI accelerator bay with a reserved direct HP USB 3 data path (not routed through
  the control PCB or Mac-side hub) and a removable mounting plate;
- M2/M2.5/M3 standoffs using only verified original motherboard mounting holes;
- removable top/bottom panels and a defined assembly/disassembly sequence.

The master CAD should be a FreeCAD parametric assembly with STEP exports for manufacturing
and STL exports only for printable case parts. Dimensions enter the model from a controlled
component table; no dimension is estimated from a photograph.

## 9. Finite engineering gates

The project advances through six gates. A gate is repeated only when a measurable failure is
found; there is no open-ended questionnaire or test loop.

| Gate | Deliverable | Pass condition |
|---|---|---|
| G0 | This architecture | No unresolved functional contradiction |
| G1 | One physical inventory/measurement sheet | HP part number, power rating, switch/LED pins and all critical dimensions recorded |
| G2 | Complete schematic + preliminary BOM | ERC passes; isolation audit passes; every safety component has a verified footprint |
| G3 | Bench prototype | 100 start cycles, state sensing, disconnect shutdown and fault recovery pass without false pulses |
| G4 | PCB Rev A | Assembly inspection, rail checks and interface tests pass before HP connection |
| G5 | Full parametric CAD assembly | No collisions; airflow, service access and cable clearances verified |
| G6 | Integrated prototype | Thermal soak, power cycling, software recovery and final acceptance checklist pass |

## 10. Decisions I may make autonomously

Within this specification, implementation decisions do not require a user confirmation:

- component reference designators and equivalent parts that meet or exceed the requirements;
- firmware/software structure, naming, logging, error handling and test automation;
- safer GPIO routing, decoupling, filtering, ESD protection and PCB placement improvements;
- trace widths, clearances and mechanical tolerances supported by calculation or datasheets;
- internal cable routing and non-visible mounting improvements that do not cut original HP parts;
- AI software modules and model substitutions within measured hardware limits.

A user decision is required only before an irreversible cut/drill to original hardware, a
material cost increase, any mains/battery/HP power-rail redesign, or a change to the product's
frozen behavior.

## 11. Items to resolve by measurement, not by repeated questions

These are scheduled for Gate G1 as one consolidated physical session:

1. exact HP motherboard spare/part number and installed CPU, RAM, GPU and SSD;
2. original HP adapter voltage, current, wattage, plug and identification behavior;
3. exact power-button contacts plus the physical location and visible behavior of the retained
   HP power LED for the optical pickup;
4. motherboard/daughterboard outlines, hole coordinates and component heights;
5. original cooling inlet/exhaust envelopes and measured temperatures;
6. measured load of hub, Ethernet adapter, ESP32 and future expansion reserve.

No schematic value, harness or CAD dimension may be invented before these measurements.

## 12. Preliminary component direction

| Function | Direction | Status |
|---|---|---|
| Controller | Espressif ESP32-S3-DevKitC-1-N8R8, hardware v1.1 | Frozen |
| HP switch isolation | Panasonic AQY212EH, DIP-4, 1 Form A PhotoMOS | Frozen |
| HP switch connector | JST B2B-XH-A(LF)(SN); mating XHP-2 + SXH-001T-P0.6 | Frozen |
| Hardware pulse limit | LTC6993-1 non-retriggerable one-shot + SN74LVC1G08 AND gate | Architecture frozen; values/footprints verified at G2 |
| HP state isolation | Remote Vishay TEPT4400 + adjustable pull-up/filter + SN74LVC1G14 | Frozen; optical shroud geometry after G1 |
| Temperature | DS18B20 3-wire probe, 4.7 kΩ pull-up | Frozen |
| Hub | Self-powered USB 3 hub with upstream no-backfeed behavior | Exact module after power/fit validation |
| Network | USB Gigabit Ethernet adapter with supported macOS chipset | Exact module after compatibility validation |
| Logic power | Certified/approved isolated `V_HP → 5 V` DC/DC | Exact rating after load measurement |

## 13. Authoritative references

- Espressif, *ESP32-S3-DevKitC-1 v1.1 User Guide*:  
  https://docs.espressif.com/projects/esp-dev-kits/en/latest/esp32s3/esp32-s3-devkitc-1/user_guide_v1.1.html
- Espressif, *ESP32-S3 serial/native USB guidance*:  
  https://docs.espressif.com/projects/esp-idf/en/stable/esp32s3/get-started/establish-serial-connection.html
- Panasonic Industry, *AQY21xEH PhotoMOS datasheet*:  
  https://industry.panasonic.com/ac/e_download/control/relay/photomos/catalog/semi_eng_ge1a_aqy21_e.pdf
- Analog Devices, *LTC6993 TimerBlox one-shot datasheet*:  
  https://www.analog.com/media/en/technical-documentation/data-sheets/ltc6993-6993-1-6993-2-6993-3-6993-4.pdf
- Vishay, *TEPT4400 visible-light phototransistor datasheet*:  
  https://www.vishay.com/docs/81341/tept4400.pdf
- HP, *HP 250 G6 setup, maintenance and service guides*:  
  https://support.hp.com/us-en/product/setup-user-guides/hp-250-g6-notebook-pc/15747807

---

**Next controlled deliverable:** AX-MEAS-001, a single physical inventory and measurement
sheet for Gate G1. After it is filled once, schematic capture proceeds without additional
architecture questionnaires.
