OTA steps 3-5: Update Service, Probation and Rollback, Update from SD

- EcdsaVerifier (mbedTLS, embedded public key) and EspOtaSink (writes
  the inactive app slot, esp_ota_end validates the image, then sets
  the boot partition)
- UpdateService: listens on TCP 3232 (and mDNS roro9stack-<id>) while
  Wi-Fi is Connected; streams into UpdateParser; replies OK/ERR to the
  sender; remembers the pending version so a Rollback is reported
  after the reboot
- Probation (host-tested): confirm after the first frame + 30 s + Wi-Fi
  (if configured); roll back if configured Wi-Fi never connects in 3 min
- Main loop: full-screen progress while receiving; restart once
  installed, waiting up to 60 s for Text Entry to end
- Settings > Firmware: version, Probation status, push address and
  name, and the .ota files in /updates on the SD card to install
- StorageService.runJob() runs work on the storage task (SD installs)
- wifi status prints IP and running version; RORO_TEST_CRASH test hook

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-03 21:35:33 +02:00
co-authored by Claude Opus 5.5
parent 90cb6ef9b2
commit 21b3d9e422
19 changed files with 655 additions and 10 deletions
+44
View File
@@ -0,0 +1,44 @@
#include "ota_device.h"
#include <cstring>
#include "ota_public_key.h"
namespace roro {
EcdsaVerifier::EcdsaVerifier() {
mbedtls_pk_init(&key_);
// PEM parsing wants the terminating NUL counted in the length.
ready_ = mbedtls_pk_parse_public_key(&key_, reinterpret_cast<const unsigned char*>(kOtaPublicKeyPem),
std::strlen(kOtaPublicKeyPem) + 1) == 0;
}
EcdsaVerifier::~EcdsaVerifier() { mbedtls_pk_free(&key_); }
bool EcdsaVerifier::verify(const uint8_t digest[32], const uint8_t* signature, size_t len) {
return ready_ && mbedtls_pk_verify(&key_, MBEDTLS_MD_SHA256, digest, 32, signature, len) == 0;
}
bool EspOtaSink::begin(size_t imageSize) {
if (!slot_) return false;
open_ = esp_ota_begin(slot_, imageSize, &handle_) == ESP_OK;
return open_;
}
bool EspOtaSink::write(const uint8_t* data, size_t len) {
return open_ && esp_ota_write(handle_, data, len) == ESP_OK;
}
bool EspOtaSink::finish() {
if (!open_) return false;
open_ = false;
// esp_ota_end() also validates the image structure (segments, checksum) for this chip.
return esp_ota_end(handle_) == ESP_OK && esp_ota_set_boot_partition(slot_) == ESP_OK;
}
void EspOtaSink::abort() {
if (open_) esp_ota_abort(handle_);
open_ = false;
}
} // namespace roro