Public Access
OTA: keep new images on Probation; Arduino validated them before setup()
Arduino-ESP32's initArduino() marks a PENDING_VERIFY image valid unless the sketch overrides the weak verifyRollbackLater(). Every update was therefore VALID before bootGuard() or Probation ever ran (otadata read back state 0x2 on a crash-looping test build), and nothing rolled back. The bootloader was never the problem. Override it to return true, so Probation decides. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -14,7 +14,7 @@ class Probation {
|
|||||||
|
|
||||||
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
|
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
|
||||||
// boots of this image on Probation; a second start means the first one died before confirming.
|
// boots of this image on Probation; a second start means the first one died before confirming.
|
||||||
// (The prebuilt bootloader doesn't roll back by itself, so the firmware does.)
|
// (A second line behind the bootloader's own rollback, which aborts an image still pending.)
|
||||||
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
|
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
|
||||||
|
|
||||||
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
|
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
|
||||||
|
|||||||
@@ -90,6 +90,10 @@ static StatusInfo currentStatus() {
|
|||||||
return s;
|
return s;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Arduino-ESP32 marks a new image valid before setup() unless this returns true. Probation
|
||||||
|
// (UpdateService::tick) decides instead, and an unconfirmed image stays PENDING_VERIFY.
|
||||||
|
extern "C" bool verifyRollbackLater() { return true; } // C linkage, or the weak default wins
|
||||||
|
|
||||||
void setup() {
|
void setup() {
|
||||||
nvs.begin();
|
nvs.begin();
|
||||||
UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware
|
UpdateService::bootGuard(nvs); // first: before anything that could crash on new firmware
|
||||||
|
|||||||
Reference in New Issue
Block a user