Public Access
OTA: keep new images on Probation; Arduino validated them before setup()
Arduino-ESP32's initArduino() marks a PENDING_VERIFY image valid unless the sketch overrides the weak verifyRollbackLater(). Every update was therefore VALID before bootGuard() or Probation ever ran (otadata read back state 0x2 on a crash-looping test build), and nothing rolled back. The bootloader was never the problem. Override it to return true, so Probation decides. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -14,7 +14,7 @@ class Probation {
|
||||
|
||||
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
|
||||
// boots of this image on Probation; a second start means the first one died before confirming.
|
||||
// (The prebuilt bootloader doesn't roll back by itself, so the firmware does.)
|
||||
// (A second line behind the bootloader's own rollback, which aborts an image still pending.)
|
||||
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
|
||||
|
||||
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
|
||||
|
||||
@@ -90,6 +90,10 @@ static StatusInfo currentStatus() {
|
||||
return s;
|
||||
}
|
||||
|
||||
// Arduino-ESP32 marks a new image valid before setup() unless this returns true. Probation
|
||||
// (UpdateService::tick) decides instead, and an unconfirmed image stays PENDING_VERIFY.
|
||||
extern "C" bool verifyRollbackLater() { return true; } // C linkage, or the weak default wins
|
||||
|
||||
void setup() {
|
||||
nvs.begin();
|
||||
UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware
|
||||
|
||||
Reference in New Issue
Block a user