OTA: keep new images on Probation; Arduino validated them before setup()

Arduino-ESP32's initArduino() marks a PENDING_VERIFY image valid unless
the sketch overrides the weak verifyRollbackLater(). Every update was
therefore VALID before bootGuard() or Probation ever ran (otadata read
back state 0x2 on a crash-looping test build), and nothing rolled back.
The bootloader was never the problem. Override it to return true, so
Probation decides.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-04 02:12:45 +02:00
co-authored by Claude Opus 5.5
parent 45542dcbff
commit 7afe6b7d17
2 changed files with 5 additions and 1 deletions
+1 -1
View File
@@ -14,7 +14,7 @@ class Probation {
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
// boots of this image on Probation; a second start means the first one died before confirming.
// (The prebuilt bootloader doesn't roll back by itself, so the firmware does.)
// (A second line behind the bootloader's own rollback, which aborts an image still pending.)
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
+4
View File
@@ -90,6 +90,10 @@ static StatusInfo currentStatus() {
return s;
}
// Arduino-ESP32 marks a new image valid before setup() unless this returns true. Probation
// (UpdateService::tick) decides instead, and an unconfirmed image stays PENDING_VERIFY.
extern "C" bool verifyRollbackLater() { return true; } // C linkage, or the weak default wins
void setup() {
nvs.begin();
UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware