Safe Mode, crash reports, and a watched main loop

Every build now records at boot which version runs and, after a crash
restart, which one crashed (even across a Rollback). The core dump
summary (task, PC, reason, backtrace) is printed and raised as a
Notification; `crash` shows it later. After 3 crash restarts in a row
the firmware starts in Safe Mode: clock, Wi-Fi, Update Service and Debug
Console only (SafeMode, 2 host tests). A normal restart or a minute up
resets the count.

The main loop is now on the task watchdog (enableLoopWDT): Arduino only
watched core 0's idle task, so a stuck loop hung the device for good.
The Update Service restarts into an installed update by itself if the
main loop hasn't after 90 s.

Debug Builds: `coredump get` and `reset` are answered by the console's
own task; rdbg.py crash decodes the backtrace and rdbg.py coredump runs
esp-coredump, against ELFs archived by version and digest in .pio/elves.

The StorageService mutex is now made in the constructor: Safe Mode never
starts that Service, and `info` crashed on the null mutex, 29 times in a
row before the fix was pushed into Safe Mode over Wi-Fi.

Verified on the device: crash report and full core dump decoded over
Wi-Fi; Safe Mode at exactly 3 crashes, left by `reboot`; a hung loop
caught by the watchdog in 5 s; `reset` from the console task. ADR 0005.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-04 03:07:56 +02:00
co-authored by Claude Opus 5.5
parent 0fb7f4e9d5
commit 14ff13f634
16 changed files with 452 additions and 21 deletions
+11
View File
@@ -28,6 +28,7 @@ class UpdateSource {
namespace {
constexpr uint32_t kStallMs = 10000;
constexpr uint32_t kForceRestartMs = 90000; // the main loop waits up to 60 s for someone typing
constexpr size_t kChunk = 4096;
class NetSource : public UpdateSource {
@@ -190,6 +191,7 @@ void UpdateService::taskEntry(void* self) { static_cast<UpdateService*>(self)->l
void UpdateService::listen() {
NetworkServer server(kPort);
bool listening = false;
uint32_t installedAt = 0;
for (;;) {
bool connected = wifi_.state() == WifiController::State::Connected;
if (connected && !listening) {
@@ -201,6 +203,15 @@ void UpdateService::listen() {
MDNS.end();
listening = false;
}
// The main loop restarts into an installed update when it's safe. If it never does (stuck,
// or waiting on someone typing for too long), restart from here: the update must not wait.
if (phase_ == Phase::Installed) {
if (!installedAt) installedAt = millis();
if (millis() - installedAt > kForceRestartMs) {
ESP_LOGW("update", "the main loop never restarted into the update: restarting");
esp_restart();
}
}
if (listening && phase_ == Phase::Idle) {
NetworkClient client = server.accept();
if (client) {