Public Access
OTA: the firmware rolls itself back; the bootloader doesn't
A deliberately crashing update looped forever on the device: the prebuilt bootloader ignores ESP_OTA_IMG_PENDING_VERIFY despite the app-side rollback config. UpdateService::bootGuard() now runs first in setup(): it counts starts on Probation in NVS and, on the second unconfirmed start, marks the image invalid and reboots into the previous one. Confirming (or the Wi-Fi rollback) resets the counter. ADR 0003 records the limit: a crash in the first milliseconds still needs USB. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
+3
-1
@@ -91,12 +91,14 @@ static StatusInfo currentStatus() {
|
||||
}
|
||||
|
||||
void setup() {
|
||||
nvs.begin();
|
||||
UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware
|
||||
|
||||
auto cfg = M5.config();
|
||||
M5Cardputer.begin(cfg, true);
|
||||
M5Cardputer.Display.setRotation(1);
|
||||
Serial.begin(115200);
|
||||
|
||||
nvs.begin();
|
||||
settings.load();
|
||||
|
||||
battery = new BatteryService(bus);
|
||||
|
||||
Reference in New Issue
Block a user