Debug Console put: verify the card's copy, never zero-fill after a failed write

Found by M3's shared-bus test: when the card refused a write, the retry
closed the file (losing up to 3 KB of earlier chunks still in the write
buffer), then truncate() extended it back with zeros. The checksum only
covered the received bytes, so `put` reported success with 3 KB of zeros
on the card. Now a retry gives up if the card lost data, and the finished
file is read back and must hash the same before it's renamed.

The card refuses a write about once in five 1.7 MB uploads, with the
radio asleep as often as listening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-05 19:13:25 +02:00
co-authored by Claude Opus 5.5
parent 3242475699
commit a0e3868934
4 changed files with 57 additions and 1 deletions
+5
View File
@@ -94,6 +94,11 @@ void FileReceiver::chunkWritten(bool ok, uint32_t nowMs) {
state_ = received_ == size_ ? State::Finishing : State::Receiving;
}
void FileReceiver::cardChecked(const uint8_t digest[32]) {
if (state_ != State::Finishing) return;
if (std::memcmp(digest, expected_, sizeof expected_) != 0) fail("the copy on the card differs");
}
void FileReceiver::finished(bool ok) {
if (state_ != State::Finishing) return;
if (!ok) return fail("rename failed");