Updates from Gitea, step 3: install from Gitea, and IRC steps aside for it

A release downloads straight into the inactive slot through the existing
install path: the signature is checked after 160 bytes, before anything
is written, the hash at the end. Tried on the device against the real
server: a download cut short, a flipped byte in the signature and one in
the image are each refused with the running firmware untouched; the real
v0.10.0 installed, restarted, and confirmed itself on Probation.

A TLS connection to Gitea peaks at about 52 KB of heap whether or not the
certificate is verified. With IRC connected (66 KB free) a check left 3 KB
and a download 836 bytes. A check, list or install a person asks for now
makes IRC step aside (holdForUpdate) and come back after: the lowest free
heap during a full download with IRC connected is 38 KB. The daily check
never interrupts IRC; with IRC up it waits. A TLS connection starts with
80 KB free (it was 55).

Debug Builds get test knobs: update probe <host>, update damage cut|flip,
update pretend <version>.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 15:51:10 +02:00
co-authored by Claude Sonnet 5.5
parent 5754ae5b57
commit 510ce42a99
10 changed files with 120 additions and 10 deletions
+1 -2
View File
@@ -12,7 +12,6 @@
namespace roro {
namespace {
constexpr size_t kFloor = 55 * 1024; // Q86, Q172: no connection below this
constexpr time_t kClockSetAfter = 1700000000; // 2023-11: anything earlier is the clock's default
// What mbedTLS says in the way it says it, for the cases a person can act on.
@@ -30,7 +29,7 @@ std::string whyNotConnected(NetworkClientSecure& tls, const std::string& host) {
std::string HttpsGet::open(const std::string& host, const std::string& path, const char* accept) {
close();
if (time(nullptr) < kClockSetAfter) return "The clock isn't set yet: certificates can't be checked";
if (esp_get_free_heap_size() < kFloor) return "Not enough memory: close IRC or a Gemini page";
if (esp_get_free_heap_size() < kNeedFree) return "Not enough memory for a secure connection";
tls_.setCACert(kTrustedRootsPem);
tls_.setTimeout(15);