diff --git a/lib/ota/src/probation.h b/lib/ota/src/probation.h index d507cfe..e5cb3d5 100644 --- a/lib/ota/src/probation.h +++ b/lib/ota/src/probation.h @@ -14,7 +14,7 @@ class Probation { // Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier // boots of this image on Probation; a second start means the first one died before confirming. - // (The prebuilt bootloader doesn't roll back by itself, so the firmware does.) + // (A second line behind the bootloader's own rollback, which aborts an image still pending.) static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; } static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) { diff --git a/src/main.cpp b/src/main.cpp index 7ee1b70..f11cdc0 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -90,6 +90,10 @@ static StatusInfo currentStatus() { return s; } +// Arduino-ESP32 marks a new image valid before setup() unless this returns true. Probation +// (UpdateService::tick) decides instead, and an unconfirmed image stays PENDING_VERIFY. +extern "C" bool verifyRollbackLater() { return true; } // C linkage, or the weak default wins + void setup() { nvs.begin(); UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware