Updates from Gitea, step 1: the model (host-tested)

A streaming JSON scanner (a 33 KB list of releases costs a few hundred
bytes), the release reader built on it, HTTP response heads and chunked
bodies, URLs, and the decisions: which release is an update, whether to
announce it, and which download URLs the device takes. Tested against the
real answers of git.twis.la.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 15:11:58 +02:00
co-authored by Claude Sonnet 5.5
parent 6b7e90765f
commit b0e8226943
13 changed files with 1058 additions and 0 deletions
+158
View File
@@ -0,0 +1,158 @@
#include "http_head.h"
#include <algorithm>
#include <cctype>
#include <cstdlib>
namespace roro::release {
namespace {
std::string lower(std::string s) {
for (char& c : s) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
return s;
}
} // namespace
size_t HttpHeadParser::feed(const char* data, size_t len) {
size_t used = 0;
while (used < len && !complete_ && !failed_) {
char c = data[used++];
total_++;
if (total_ > kMaxBytes) {
failed_ = true;
break;
}
if (c == '\n') {
if (!line_.empty() && line_.back() == '\r') line_.pop_back();
line();
line_.clear();
} else {
line_ += c;
}
}
return used;
}
void HttpHeadParser::line() {
if (first_) { // "HTTP/1.1 200 OK"
first_ = false;
if (line_.compare(0, 5, "HTTP/") != 0) {
failed_ = true;
return;
}
size_t space = line_.find(' ');
head_.status = space == std::string::npos ? 0 : std::atoi(line_.c_str() + space + 1);
if (head_.status < 100 || head_.status > 599) failed_ = true;
return;
}
if (line_.empty()) {
complete_ = true;
return;
}
size_t colon = line_.find(':');
if (colon == std::string::npos) return; // not a header: ignored
std::string name = lower(line_.substr(0, colon));
size_t from = line_.find_first_not_of(" \t", colon + 1);
std::string value = from == std::string::npos ? "" : line_.substr(from);
if (name == "content-length") head_.contentLength = std::atol(value.c_str());
else if (name == "transfer-encoding") head_.chunked = lower(value).find("chunked") != std::string::npos;
else if (name == "location") head_.location = value;
else if (name == "content-type") head_.contentType = value;
}
size_t ChunkedDecoder::decode(const uint8_t* in, size_t len, uint8_t* out) {
size_t written = 0;
for (size_t i = 0; i < len && !failed_ && state_ != State::Done; i++) {
uint8_t c = in[i];
switch (state_) {
case State::Size: {
int digit = c >= '0' && c <= '9' ? c - '0' : c >= 'a' && c <= 'f' ? c - 'a' + 10 : c >= 'A' && c <= 'F' ? c - 'A' + 10 : -1;
if (digit >= 0) {
if (remaining_ > (SIZE_MAX >> 5)) failed_ = true;
remaining_ = remaining_ * 16 + digit;
anyDigit_ = true;
} else if (c == ';' && anyDigit_) {
state_ = State::Extension;
} else if (c == '\r' && anyDigit_) {
state_ = State::SizeLf;
} else {
failed_ = true;
}
break;
}
case State::Extension:
if (c == '\r') state_ = State::SizeLf;
break;
case State::SizeLf:
if (c != '\n') {
failed_ = true;
} else if (remaining_ == 0) {
state_ = State::Trailer;
trailerLine_ = 0;
} else {
state_ = State::Data;
}
break;
case State::Data: {
size_t take = std::min(remaining_, len - i);
for (size_t k = 0; k < take; k++) out[written + k] = in[i + k];
written += take;
remaining_ -= take;
i += take - 1;
if (remaining_ == 0) state_ = State::DataCr;
break;
}
case State::DataCr:
if (c != '\r') failed_ = true;
else state_ = State::DataLf;
break;
case State::DataLf:
if (c != '\n') {
failed_ = true;
} else {
state_ = State::Size;
anyDigit_ = false;
}
break;
case State::Trailer: // header lines after the last chunk, until an empty one
if (c == '\n') {
if (trailerLine_ == 0) state_ = State::Done;
trailerLine_ = 0;
} else if (c != '\r') {
trailerLine_++;
}
break;
case State::Done: break;
}
}
return written;
}
Url parseUrl(const std::string& url) {
Url u;
size_t scheme = url.find("://");
if (scheme == std::string::npos) return u;
std::string s = lower(url.substr(0, scheme));
if (s != "http" && s != "https") return u;
u.https = s == "https";
size_t hostStart = scheme + 3, pathStart = url.find('/', hostStart);
std::string authority = url.substr(hostStart, pathStart == std::string::npos ? std::string::npos : pathStart - hostStart);
u.path = pathStart == std::string::npos ? "/" : url.substr(pathStart);
if (authority.empty() || authority.find('@') != std::string::npos) return u; // no credentials in a URL
size_t colon = authority.rfind(':');
u.port = u.https ? 443 : 80;
if (colon != std::string::npos) {
u.port = std::atoi(authority.c_str() + colon + 1);
authority.resize(colon);
if (u.port <= 0 || u.port > 65535) return u;
}
for (unsigned char c : authority)
if (!(std::isalnum(c) || c == '.' || c == '-')) return u;
for (unsigned char c : u.path)
if (c <= ' ' || c == 0x7F) return u;
u.host = lower(authority);
u.ok = !u.host.empty();
return u;
}
} // namespace roro::release
+62
View File
@@ -0,0 +1,62 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
namespace roro::release {
// The status line and headers of an HTTP/1.1 response, read as bytes arrive.
struct HttpHead {
int status = 0;
long contentLength = -1; // -1: not given
bool chunked = false;
std::string location, contentType;
};
class HttpHeadParser {
public:
static constexpr size_t kMaxBytes = 4096;
// Takes bytes up to and including the blank line that ends the head; returns how many it used.
// What follows is the body.
size_t feed(const char* data, size_t len);
bool complete() const { return complete_; }
bool failed() const { return failed_; }
const HttpHead& head() const { return head_; }
private:
void line();
HttpHead head_;
std::string line_;
size_t total_ = 0;
bool first_ = true, complete_ = false, failed_ = false;
};
// Takes the chunks of "Transfer-Encoding: chunked" apart as they arrive.
class ChunkedDecoder {
public:
// `out` has room for `len` bytes (the body is never longer than what carried it).
size_t decode(const uint8_t* in, size_t len, uint8_t* out);
bool done() const { return state_ == State::Done; }
bool failed() const { return failed_; }
private:
enum class State : uint8_t { Size, Extension, SizeLf, Data, DataCr, DataLf, Trailer, Done };
State state_ = State::Size;
size_t remaining_ = 0;
bool anyDigit_ = false, failed_ = false;
size_t trailerLine_ = 0;
};
// "https://git.twis.la/twisla/x/releases/download/v1/a.ota" taken apart. Only http and https.
struct Url {
bool ok = false;
bool https = false;
std::string host, path; // path from the first "/", with its query; "/" if none
int port = 0;
};
Url parseUrl(const std::string& url);
} // namespace roro::release
+202
View File
@@ -0,0 +1,202 @@
#include "json_scan.h"
namespace roro::release {
namespace {
bool space(char c) { return c == ' ' || c == '\t' || c == '\r' || c == '\n'; }
bool continuation(char c) { return (static_cast<uint8_t>(c) & 0xC0) == 0x80; }
} // namespace
void JsonScanner::feed(const char* data, size_t len) {
for (size_t i = 0; i < len && !failed_; i++) step(data[i]);
}
std::string JsonScanner::path() const {
std::string p;
for (const Frame& f : stack_) {
if (f.isObject) {
if (!p.empty()) p += '.';
p += f.key;
} else {
p += '[' + std::to_string(f.index) + ']';
}
}
return p;
}
void JsonScanner::append(const char* bytes, size_t n) {
if (text_.size() + n > max_) {
truncated_ = true;
return;
}
text_.append(bytes, n);
}
void JsonScanner::appendCodePoint(uint32_t cp) {
char b[4];
size_t n;
if (cp < 0x80) {
b[0] = static_cast<char>(cp);
n = 1;
} else if (cp < 0x800) {
b[0] = static_cast<char>(0xC0 | (cp >> 6));
b[1] = static_cast<char>(0x80 | (cp & 0x3F));
n = 2;
} else if (cp < 0x10000) {
b[0] = static_cast<char>(0xE0 | (cp >> 12));
b[1] = static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
b[2] = static_cast<char>(0x80 | (cp & 0x3F));
n = 3;
} else {
b[0] = static_cast<char>(0xF0 | (cp >> 18));
b[1] = static_cast<char>(0x80 | ((cp >> 12) & 0x3F));
b[2] = static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
b[3] = static_cast<char>(0x80 | (cp & 0x3F));
n = 4;
}
append(b, n);
}
void JsonScanner::startString(bool key) {
inString_ = true;
isKey_ = key;
escape_ = false;
unicodeLeft_ = 0;
highSurrogate_ = 0;
truncated_ = false;
text_.clear();
}
void JsonScanner::stringChar(char c) {
if (unicodeLeft_ > 0) {
int digit = c >= '0' && c <= '9' ? c - '0' : c >= 'a' && c <= 'f' ? c - 'a' + 10 : c >= 'A' && c <= 'F' ? c - 'A' + 10 : -1;
if (digit < 0) return fail();
unicode_ = unicode_ * 16 + digit;
if (--unicodeLeft_ == 0) {
if (unicode_ >= 0xD800 && unicode_ < 0xDC00) {
highSurrogate_ = unicode_; // the low half comes next
} else if (unicode_ >= 0xDC00 && unicode_ < 0xE000 && highSurrogate_) {
appendCodePoint(0x10000 + ((highSurrogate_ - 0xD800) << 10) + (unicode_ - 0xDC00));
highSurrogate_ = 0;
} else {
appendCodePoint(unicode_);
highSurrogate_ = 0;
}
}
return;
}
if (escape_) {
escape_ = false;
switch (c) {
case 'n': append("\n", 1); break;
case 't': append("\t", 1); break;
case 'r': append("\r", 1); break;
case 'b': append("\b", 1); break;
case 'f': append("\f", 1); break;
case 'u': unicodeLeft_ = 4; unicode_ = 0; break;
default: append(&c, 1); break; // \" \\ \/
}
return;
}
if (c == '\\') {
escape_ = true;
} else if (c == '"') {
endString();
} else {
append(&c, 1);
}
}
void JsonScanner::endString() {
inString_ = false;
// A cut can leave half a character at the end.
while (truncated_ && !text_.empty()) {
size_t k = text_.size();
while (k > 0 && continuation(text_[k - 1])) k--;
if (k == 0) break;
uint8_t lead = static_cast<uint8_t>(text_[k - 1]);
size_t want = lead >= 0xF0 ? 4 : lead >= 0xE0 ? 3 : lead >= 0xC0 ? 2 : 1;
if (text_.size() - (k - 1) < want) text_.resize(k - 1);
break;
}
if (isKey_) {
stack_.back().key = text_;
expect_ = Expect::Colon;
return;
}
sink_(path(), text_, true, truncated_);
valueDone();
}
void JsonScanner::endLiteral() {
inLiteral_ = false;
sink_(path(), text_, false, false);
valueDone();
}
void JsonScanner::valueDone() {
if (stack_.empty()) {
done_ = true;
return;
}
expect_ = Expect::CommaOrEnd;
}
void JsonScanner::step(char c) {
if (inString_) return stringChar(c);
if (inLiteral_) {
if (space(c) || c == ',' || c == '}' || c == ']') {
endLiteral(); // and the character that ended it is read again below
} else {
if (text_.size() < max_) text_ += c;
return;
}
}
if (space(c)) return;
switch (expect_) {
case Expect::Value:
if (c == '{') {
stack_.push_back({true, "", 0});
expect_ = Expect::KeyOrEnd;
} else if (c == '[') {
stack_.push_back({false, "", 0});
expect_ = Expect::Value;
} else if (c == ']' && !stack_.empty() && !stack_.back().isObject && stack_.back().index == 0) {
stack_.pop_back(); // an empty array
valueDone();
} else if (c == '"') {
startString(false);
} else if (c == '-' || (c >= '0' && c <= '9') || c == 't' || c == 'f' || c == 'n') {
inLiteral_ = true;
text_.assign(1, c);
} else {
fail();
}
return;
case Expect::KeyOrEnd:
if (c == '"') startString(true);
else if (c == '}') {
stack_.pop_back();
valueDone();
} else fail();
return;
case Expect::Colon:
if (c == ':') expect_ = Expect::Value;
else fail();
return;
case Expect::CommaOrEnd:
if (c == ',') {
if (stack_.back().isObject) expect_ = Expect::KeyOrEnd;
else {
stack_.back().index++;
expect_ = Expect::Value;
}
} else if ((c == '}' && stack_.back().isObject) || (c == ']' && !stack_.back().isObject)) {
stack_.pop_back();
valueDone();
} else fail();
return;
}
}
} // namespace roro::release
+57
View File
@@ -0,0 +1,57 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <functional>
#include <string>
#include <vector>
namespace roro::release {
// Reads JSON as it arrives, a chunk at a time, and reports each plain value (a string, a number,
// true, false, null) with where it was found: "tag_name", "assets[1].name", "[2].draft". Nothing
// is kept but the path, so a 33 KB list of releases costs a few hundred bytes. A value longer than
// `maxValueBytes` is cut (never in the middle of a character) and reported as truncated.
// Meant for a server's answer, not for validating JSON: it only refuses what it can't follow.
class JsonScanner {
public:
using Sink = std::function<void(const std::string& path, const std::string& value, bool isString, bool truncated)>;
explicit JsonScanner(Sink sink, size_t maxValueBytes = 300) : sink_(std::move(sink)), max_(maxValueBytes) {}
void feed(const char* data, size_t len);
bool failed() const { return failed_; }
bool done() const { return done_ && !failed_; } // the top-level value is complete
private:
enum class Expect : uint8_t { Value, KeyOrEnd, Colon, CommaOrEnd };
struct Frame {
bool isObject;
std::string key;
int index;
};
void step(char c);
void startString(bool key);
void stringChar(char c);
void appendCodePoint(uint32_t cp);
void endString();
void endLiteral();
void valueDone();
void append(const char* bytes, size_t n);
std::string path() const;
void fail() { failed_ = true; }
Sink sink_;
size_t max_;
std::vector<Frame> stack_;
Expect expect_ = Expect::Value;
bool inString_ = false, isKey_ = false, escape_ = false, inLiteral_ = false;
int unicodeLeft_ = 0;
uint32_t unicode_ = 0, highSurrogate_ = 0;
bool truncated_ = false;
std::string text_;
bool failed_ = false, done_ = false;
};
} // namespace roro::release
+80
View File
@@ -0,0 +1,80 @@
#include "release_info.h"
#include <cstdlib>
namespace roro::release {
namespace {
bool endsWith(const std::string& s, const char* tail) {
size_t n = std::char_traits<char>::length(tail);
return s.size() >= n && s.compare(s.size() - n, n, tail) == 0;
}
} // namespace
std::string firstParagraph(const std::string& text, bool truncated) {
size_t end = text.find("\n\n");
size_t crlf = text.find("\r\n\r\n");
if (crlf != std::string::npos && (end == std::string::npos || crlf < end)) end = crlf;
std::string p = text.substr(0, end);
size_t first = p.find_first_not_of(" \t\r\n");
if (first == std::string::npos) return "";
p.erase(0, first);
while (!p.empty() && (p.back() == ' ' || p.back() == '\t' || p.back() == '\r' || p.back() == '\n')) p.pop_back();
if (truncated && end == std::string::npos) p += "...";
return p;
}
ReleaseReader::ReleaseReader(size_t maxReleases)
: scanner_([this](const std::string& path, const std::string& text, bool isString, bool truncated) {
value(path, text, isString, truncated);
}),
max_(maxReleases) {}
void ReleaseReader::end() { flushAsset(); }
void ReleaseReader::flushAsset() {
if (assetRelease_ >= 0 && assetRelease_ < static_cast<int>(releases_.size()) && endsWith(assetName_, ".ota") && !assetUrl_.empty()) {
releases_[assetRelease_].otaUrl = assetUrl_;
releases_[assetRelease_].otaSize = assetSize_;
}
assetRelease_ = assetIndex_ = -1;
assetName_.clear();
assetUrl_.clear();
assetSize_ = 0;
}
void ReleaseReader::value(const std::string& path, const std::string& text, bool isString, bool truncated) {
size_t index = 0;
std::string rest = path;
if (!path.empty() && path[0] == '[') { // a list: "[2].tag_name"
char* end;
index = static_cast<size_t>(std::strtol(path.c_str() + 1, &end, 10));
rest = *end == ']' ? std::string(end + 1) : "";
if (!rest.empty() && rest[0] == '.') rest.erase(0, 1);
}
if (index >= max_) return;
if (releases_.size() <= index) releases_.resize(index + 1);
Release& r = releases_[index];
if (rest == "tag_name") r.tag = text;
else if (rest == "published_at") r.published = text;
else if (rest == "body") r.notes = firstParagraph(text, truncated);
else if (rest == "draft") r.draft = text == "true";
else if (rest == "prerelease") r.prerelease = text == "true";
else if (rest.compare(0, 7, "assets[") == 0) {
char* end;
int j = static_cast<int>(std::strtol(rest.c_str() + 7, &end, 10));
if (static_cast<int>(index) != assetRelease_ || j != assetIndex_) {
flushAsset();
assetRelease_ = static_cast<int>(index);
assetIndex_ = j;
}
std::string field = *end == ']' && end[1] == '.' ? std::string(end + 2) : "";
if (field == "name") assetName_ = text;
else if (field == "size") assetSize_ = static_cast<uint32_t>(std::strtoul(text.c_str(), nullptr, 10));
else if (field == "browser_download_url") assetUrl_ = text;
}
(void)isString;
}
} // namespace roro::release
+52
View File
@@ -0,0 +1,52 @@
#pragma once
#include <cstdint>
#include <string>
#include <vector>
#include "json_scan.h"
namespace roro::release {
// What the device needs to know about one Gitea release (docs/milestones/R1.md, #6).
struct Release {
std::string tag; // "v0.10.0"
std::string published; // "2026-10-06T08:11:31Z"
std::string notes; // the first paragraph of the text: the tag's message
std::string otaUrl; // where the signed Update File is
uint32_t otaSize = 0;
bool draft = false, prerelease = false;
// Something that can be installed and that the project meant to publish (drafts and
// pre-releases are left out for now: a release channel is #53).
bool usable() const { return !draft && !prerelease && !tag.empty() && !otaUrl.empty(); }
std::string date() const { return published.substr(0, 10); } // "2026-10-06"
};
// Reads Gitea's answer as it arrives: `releases/latest` (one object) or `releases?limit=N` (a list).
class ReleaseReader {
public:
explicit ReleaseReader(size_t maxReleases = 10);
void feed(const char* data, size_t len) { scanner_.feed(data, len); }
void end(); // after the last chunk
bool ok() const { return !scanner_.failed(); }
bool complete() const { return scanner_.done(); }
const std::vector<Release>& releases() const { return releases_; }
private:
void value(const std::string& path, const std::string& text, bool isString, bool truncated);
void flushAsset();
JsonScanner scanner_;
size_t max_;
std::vector<Release> releases_;
int assetRelease_ = -1, assetIndex_ = -1;
std::string assetName_, assetUrl_;
uint32_t assetSize_ = 0;
};
// The first paragraph of a release's text, trimmed; "..." if the text was cut before it ended.
std::string firstParagraph(const std::string& text, bool truncated);
} // namespace roro::release
+15
View File
@@ -0,0 +1,15 @@
#include "update_check.h"
#include "http_head.h"
namespace roro::release {
bool trustedAssetUrl(const std::string& url, const std::string& host, const std::string& repo) {
Url u = parseUrl(url);
if (!u.ok || !u.https || u.port != 443 || u.host != host) return false;
std::string prefix = "/" + repo + "/releases/download/";
return u.path.compare(0, prefix.size(), prefix) == 0 && u.path.find("..") == std::string::npos &&
u.path.find('?') == std::string::npos && u.path.find('#') == std::string::npos;
}
} // namespace roro::release
+38
View File
@@ -0,0 +1,38 @@
#pragma once
#include <string>
#include "release_info.h"
#include "version_compare.h"
namespace roro::release {
// Where the project's releases are (Q164). A fork changes these, and its own signing key.
constexpr const char* kGiteaHost = "git.twis.la";
constexpr const char* kGiteaRepo = "twisla/roro9stack";
inline bool versionNewer(const std::string& a, const std::string& b) { return versionOlder(b, a); }
// "v0.10.0+debug": the Debug Build says so wherever the version shows (scripts/version.py).
inline bool isDebugBuild(const std::string& version) {
static const std::string tail = "+debug";
return version.size() >= tail.size() && version.compare(version.size() - tail.size(), tail.size(), tail) == 0;
}
// Is `release` a newer one than what runs?
inline bool isNewer(const Release& release, const std::string& running) {
return release.usable() && versionNewer(release.tag, running);
}
// Should the background check say so (Q166, Q168)? Not for a version that failed on this device
// before (it rolled back), and not twice for the same one.
inline bool shouldAnnounce(const Release& latest, const std::string& running, const std::string& failed, const std::string& announced) {
return isNewer(latest, running) && latest.tag != failed && latest.tag != announced;
}
// Is `url` a download this device takes from the project's server, for this repository? Whatever
// the API says, the device only fetches from where it asked (a redirected or rewritten answer
// can't send it elsewhere).
bool trustedAssetUrl(const std::string& url, const std::string& host = kGiteaHost, const std::string& repo = kGiteaRepo);
} // namespace roro::release