Public Access
OTA: the firmware rolls itself back; the bootloader doesn't
A deliberately crashing update looped forever on the device: the prebuilt bootloader ignores ESP_OTA_IMG_PENDING_VERIFY despite the app-side rollback config. UpdateService::bootGuard() now runs first in setup(): it counts starts on Probation in NVS and, on the second unconfirmed start, marks the image invalid and reboots into the previous one. Confirming (or the Wi-Fi rollback) resets the counter. ADR 0003 records the limit: a crash in the first milliseconds still needs USB. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -12,6 +12,11 @@ class Probation {
|
||||
static constexpr uint32_t kHealthyAfterMs = 30000;
|
||||
static constexpr uint32_t kWifiDeadlineMs = 180000;
|
||||
|
||||
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
|
||||
// boots of this image on Probation; a second start means the first one died before confirming.
|
||||
// (The prebuilt bootloader doesn't roll back by itself, so the firmware does.)
|
||||
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
|
||||
|
||||
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
|
||||
if (wifiConfigured && !wifiConnected && uptimeMs >= kWifiDeadlineMs) return Verdict::RollBack;
|
||||
if (uptimeMs < kHealthyAfterMs || !firstFrameDrawn) return Verdict::Wait;
|
||||
|
||||
Reference in New Issue
Block a user