Public Access
Safe Mode, crash reports, and a watched main loop
Every build now records at boot which version runs and, after a crash restart, which one crashed (even across a Rollback). The core dump summary (task, PC, reason, backtrace) is printed and raised as a Notification; `crash` shows it later. After 3 crash restarts in a row the firmware starts in Safe Mode: clock, Wi-Fi, Update Service and Debug Console only (SafeMode, 2 host tests). A normal restart or a minute up resets the count. The main loop is now on the task watchdog (enableLoopWDT): Arduino only watched core 0's idle task, so a stuck loop hung the device for good. The Update Service restarts into an installed update by itself if the main loop hasn't after 90 s. Debug Builds: `coredump get` and `reset` are answered by the console's own task; rdbg.py crash decodes the backtrace and rdbg.py coredump runs esp-coredump, against ELFs archived by version and digest in .pio/elves. The StorageService mutex is now made in the constructor: Safe Mode never starts that Service, and `info` crashed on the null mutex, 29 times in a row before the fix was pushed into Safe Mode over Wi-Fi. Verified on the device: crash report and full core dump decoded over Wi-Fi; Safe Mode at exactly 3 crashes, left by `reboot`; a hung loop caught by the watchdog in 5 s; `reset` from the console task. ADR 0005. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -120,6 +120,10 @@ _Avoid_: trial, test mode
|
||||
Returning automatically to the previous firmware when new firmware resets or crashes during Probation.
|
||||
_Avoid_: revert, downgrade (a downgrade is installing an older version on purpose)
|
||||
|
||||
**Safe Mode**:
|
||||
What the firmware starts instead of everything else after 3 crash restarts in a row: Wi-Fi and Firmware Updates (and the Debug Console in a Debug Build), so it can be fixed without a cable. A normal restart leaves it.
|
||||
_Avoid_: recovery mode, failsafe
|
||||
|
||||
**Debug Build**:
|
||||
A firmware built with the remote debugging aids compiled in (`+debug` in its version). Release builds have none of them.
|
||||
_Avoid_: dev build, test build (a test build is one made to fail on purpose, such as a crashing update)
|
||||
@@ -139,6 +143,7 @@ _Avoid_: telnet, remote shell
|
||||
- Every transmission is bounded by the **Region** and its **Duty Cycle Budget**.
|
||||
- Past 90% SD usage, **Logs** stop being written; the remaining space is kept for **Captures**. Nothing is deleted without the user's confirmation.
|
||||
- A **Firmware Update** installs an **Update File**; the new firmware runs on **Probation**, and fails back by **Rollback**.
|
||||
- **Rollback** covers new firmware; **Safe Mode** covers confirmed firmware that keeps crashing.
|
||||
- A **Node** may be in several **Channels**. A **Direct Message** targets exactly one **Node**.
|
||||
|
||||
## Flagged ambiguities
|
||||
|
||||
Reference in New Issue
Block a user