Debug Console: files, screenshots and Update from SD over Wi-Fi

New commands everywhere: ls, rm and install <path> (Update from SD
without the Firmware page), all as Storage Service jobs. In Debug
Builds the console task answers get and put (one storage job per
transfer, file kept open, TCP flow control: about 300 KB/s, against
55 KB/s over serial) and screenshot (the RGB332 frame the UI composes
into). rdbg.py turns those into files and PNGs.

A failed put closes the connection: the rest of the file had been
parsed as commands. Card writes are retried 3 times after closing,
truncating to the last good byte and reopening, since FATFS keeps a
file in error after one failed write (seen once at 1.3 MB on this card).
onStorage() decides with one compare-and-swap whether the job or the
timeout wins, so an abandoned job can't touch a returned stack frame.

Verified on the device: screenshot; a get round trip byte-identical;
4 puts in a row; a tampered .ota refused by install; a good one put,
installed from SD, confirmed on Probation. The retry path itself has
not fired since it was added.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-04 03:18:23 +02:00
co-authored by Claude Opus 5.5
parent 14ff13f634
commit 388e847cd4
6 changed files with 275 additions and 14 deletions
+141 -9
View File
@@ -8,6 +8,13 @@
#include <esp_core_dump.h>
#include <esp_flash.h>
#include <SD.h>
#include <unistd.h>
#include <atomic>
#include <memory>
#include "file_receiver.h"
#include "platform/console.h"
#include "version.h"
@@ -67,7 +74,8 @@ void sendCoreDump(NetworkClient& client) {
} // namespace
DebugConsole::DebugConsole(WifiService& wifi) : wifi_(wifi), lock_(xSemaphoreCreateMutex()) {}
DebugConsole::DebugConsole(WifiService& wifi, StorageService& storage)
: wifi_(wifi), storage_(storage), lock_(xSemaphoreCreateMutex()) {}
void DebugConsole::start() {
console.captureEspLogs();
@@ -147,14 +155,7 @@ void DebugConsole::serve(NetworkClient& client) {
client.stop();
break;
}
if (line == "reset") { // answered here: works even when the main loop is stuck
client.print("debug: restarting now\n");
client.flush();
delay(200);
esp_restart();
}
if (line == "coredump get") { // binary: answered here, not by the main loop
sendCoreDump(client);
if (binaryCommand(client, line)) {
line.clear();
continue;
}
@@ -171,6 +172,137 @@ void DebugConsole::serve(NetworkClient& client) {
console.println("debug: client disconnected");
}
bool DebugConsole::binaryCommand(NetworkClient& client, const std::string& line) {
if (line == "reset") { // works even when the main loop is stuck
client.print("debug: restarting now\n");
client.flush();
delay(200);
esp_restart();
}
if (line == "coredump get") sendCoreDump(client);
else if (line.rfind("get ", 0) == 0) get(client, line.substr(4));
else if (line.rfind("put ", 0) == 0) put(client, line.substr(4));
else if (line == "screenshot") screenshot(client);
else return false;
return true;
}
bool DebugConsole::onStorage(std::function<void()> job) {
// Shared with the job, which outlives this wait if the card is missing and it never starts.
// Exactly one side wins the state change: the job (Queued -> Running) or the wait giving up
// (Queued -> Abandoned), so an abandoned job can never touch this stack frame.
enum : int { Queued, Running, Abandoned };
struct Run {
std::atomic<int> state{Queued};
SemaphoreHandle_t done = xSemaphoreCreateBinary();
~Run() { vSemaphoreDelete(done); }
};
auto run = std::make_shared<Run>();
storage_.runJob([run, job]() {
int expected = Queued;
if (!run->state.compare_exchange_strong(expected, Running)) return;
job();
xSemaphoreGive(run->done);
});
for (int waited = 0; xSemaphoreTake(run->done, pdMS_TO_TICKS(500)) != pdTRUE; waited += 500) {
int expected = Queued;
if (waited >= 5000 && run->state.compare_exchange_strong(expected, Abandoned)) return false;
}
return true;
}
void DebugConsole::get(NetworkClient& client, const std::string& path) {
bool ran = onStorage([&]() {
File f = SD.open(path.c_str());
if (!f || f.isDirectory()) return (void)client.printf("get: error cannot open %s\n", path.c_str());
size_t size = f.size();
client.printf("get: data %u\n", (unsigned)size);
uint8_t buf[1024];
for (size_t sent = 0; sent < size;) {
int n = f.read(buf, std::min(sizeof buf, size - sent));
if (n <= 0 || client.write(buf, n) != static_cast<size_t>(n)) break; // the host sees it short
sent += n;
}
f.close();
client.print("get: end\n");
});
if (!ran) client.print("get: error no SD card\n");
}
// The same checks as `sd put` over serial (FileReceiver), but TCP does the flow control, so the
// file is written in one job with the file kept open.
void DebugConsole::put(NetworkClient& client, const std::string& args) {
FileReceiver r;
std::string error = r.begin(args, millis());
StorageState card = storage_.state();
if (error.empty() && !card.present) error = "no SD card";
if (error.empty() && card.totalBytes - card.usedBytes < r.size() + 64 * 1024) error = "not enough space";
if (!error.empty()) return (void)client.printf("put: error %s\n", error.c_str());
bool ran = onStorage([&]() {
std::string part = r.partPath();
for (size_t slash = part.find('/', 1); slash != std::string::npos; slash = part.find('/', slash + 1)) {
std::string dir = part.substr(0, slash);
if (!SD.exists(dir.c_str())) SD.mkdir(dir.c_str());
}
File f = SD.open(part.c_str(), FILE_WRITE);
if (!f) return (void)client.print("put: error card not writable\n");
client.printf("put: ready %u\n", (unsigned)r.size());
uint8_t buf[1024];
using S = FileReceiver::State;
while (r.state() == S::Receiving || r.state() == S::Writing) {
if (r.state() == S::Writing) {
const auto& c = r.chunk();
bool ok = f.write(c.data(), c.size()) == c.size();
// A card can fail one write and take the next. FATFS keeps a failed file in error,
// so: close, cut back to the last good byte, reopen, try again.
for (int retry = 1; !ok && retry <= 3; retry++) {
console.printf("put: write failed at %u, retry %d\n", (unsigned)r.received(), retry);
f.close();
delay(50 * retry);
truncate(("/sd" + part).c_str(), r.received());
f = SD.open(part.c_str(), FILE_APPEND);
ok = f && f.size() == r.received() && f.write(c.data(), c.size()) == c.size();
}
r.chunkWritten(ok, millis());
continue;
}
int n = client.read(buf, std::min(sizeof buf, r.wanted()));
if (n > 0) r.feed(buf, n, millis());
else if (!client.connected()) break;
else {
delay(2);
r.tick(millis());
}
}
f.close();
if (r.state() == S::Finishing) {
if (SD.exists(r.path().c_str())) SD.remove(r.path().c_str());
r.finished(SD.rename(part.c_str(), r.path().c_str()));
}
if (r.state() == S::Done) client.printf("put: done %s %u B\n", r.path().c_str(), (unsigned)r.size());
else {
SD.remove(part.c_str());
client.printf("put: error %s\n", r.error().empty() ? "connection lost" : r.error().c_str());
// The rest of the file is still on its way: never read it as commands.
client.flush();
client.stop();
}
});
if (!ran) client.print("put: error no SD card\n");
}
// The frame as composed off-screen (RGB332, one byte a pixel). Read while the UI may be drawing,
// so it can tear; it's for looking, not for pixel-exact tests.
void DebugConsole::screenshot(NetworkClient& client) {
const uint8_t* pixels = frame_ ? static_cast<const uint8_t*>(frame_->getBuffer()) : nullptr;
if (!pixels) return (void)client.print("screenshot: error no frame\n");
int w = frame_->width(), h = frame_->height();
client.printf("screenshot: rgb332 %d %d\n", w, h);
for (int y = 0; y < h; y += 16) client.write(pixels + y * w, w * std::min(16, h - y));
client.print("screenshot: end\n");
}
} // namespace roro
#endif
+16 -1
View File
@@ -6,10 +6,13 @@
#include <freertos/semphr.h>
#include <deque>
#include <functional>
#include <string>
#include "service.h"
#include "services/storage_service.h"
#include "services/wifi_service.h"
#include "ui/canvas.h"
class NetworkClient;
@@ -26,7 +29,9 @@ class DebugConsole : public Service {
public:
static constexpr uint16_t kPort = 2323;
explicit DebugConsole(WifiService& wifi);
DebugConsole(WifiService& wifi, StorageService& storage);
// The off-screen frame the UI composes into: `screenshot` sends it as it stands.
void setFrame(Canvas& frame) { frame_ = &frame; }
const char* name() const override { return "debug"; }
void start() override;
@@ -39,8 +44,18 @@ class DebugConsole : public Service {
void listen();
void serve(::NetworkClient& client);
bool authenticate(::NetworkClient& client);
// Binary commands, answered on this task: true if `line` was one.
bool binaryCommand(::NetworkClient& client, const std::string& line);
// Runs `job` on the storage task (where card access is safe) and waits for it. False if the
// card isn't mounted, in which case the storage task never runs it.
bool onStorage(std::function<void()> job);
void get(::NetworkClient& client, const std::string& path);
void put(::NetworkClient& client, const std::string& args);
void screenshot(::NetworkClient& client);
WifiService& wifi_;
StorageService& storage_;
Canvas* frame_ = nullptr;
TaskHandle_t task_ = nullptr;
SemaphoreHandle_t lock_;
std::deque<std::string> commands_;