One firmware: the Debug Console in every build, off until switched on, with the device's own token
CI / build (pull_request) Successful in 7m20s
Site / build (pull_request) Successful in 9s

There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The
console and the test commands are compiled into every firmware. It listens
only while Settings > Debug Console is on, which isn't the default; off,
neither its task nor its 4 KB ring exists. The token is made by the device
and shown on that page; a client proves it knows it by answering a challenge
with an HMAC, so it never crosses the network, and five wrong answers close
the console for a minute. DBG in the Status Bar while it listens.

Over USB serial only: debug on, debug token <value>, debug token new.
scripts/flash.sh --debug uses them to set a device up with the developer's
token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the
file, answers the challenge, and fetches a release's ELF to decode a crash.

Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version,
scripts/debug_flags.py, update install ... force, and the rule that a Debug
Build doesn't install releases. Old clients and old firmwares don't talk to
each other.

Against the builds it replaces: 30 KB more flash and 88 bytes more static
RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests.
Checked on the device: off by default, login, the pause after wrong tokens,
Safe Mode with the console, the setting surviving an update, debug off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 22:59:35 +02:00
co-authored by Claude Opus 5.5
parent 1353e6a5f9
commit c68741cc46
65 changed files with 1245 additions and 374 deletions
+42 -21
View File
@@ -2,19 +2,16 @@
#include <Arduino.h>
#ifdef RORO_DEBUG
#include <esp_log.h>
#include <freertos/FreeRTOS.h>
#include <algorithm>
#include <cstdio>
#endif
namespace roro {
Console console;
#ifdef RORO_DEBUG
namespace {
// Any task may write (ESP-IDF logs come from everywhere), so the ring is behind a spinlock, held
@@ -34,7 +31,28 @@ int teeEspLog(const char* format, va_list args) {
} // namespace
void Console::captureEspLogs() { espLogNext = esp_log_set_vprintf(teeEspLog); }
void Console::captureEspLogs() {
if (!espLogNext) espLogNext = esp_log_set_vprintf(teeEspLog); // once: it stays, and costs nothing with the ring closed
}
bool Console::openRing() {
if (ring_) return true;
auto* fresh = static_cast<uint8_t*>(malloc(kRingBytes));
if (!fresh) return false;
portENTER_CRITICAL(&ringLock);
head_ = 0;
ring_ = fresh;
portEXIT_CRITICAL(&ringLock);
return true;
}
void Console::closeRing() {
portENTER_CRITICAL(&ringLock);
uint8_t* old = ring_;
ring_ = nullptr;
portEXIT_CRITICAL(&ringLock);
free(old);
}
void Console::toRing(const uint8_t* data, size_t len) {
if (len > kRingBytes) {
@@ -42,11 +60,13 @@ void Console::toRing(const uint8_t* data, size_t len) {
len = kRingBytes;
}
portENTER_CRITICAL(&ringLock);
size_t at = head_ % kRingBytes;
size_t first = std::min(len, kRingBytes - at);
memcpy(ring_ + at, data, first);
memcpy(ring_, data + first, len - first);
head_ += len;
if (ring_) {
size_t at = head_ % kRingBytes;
size_t first = std::min(len, kRingBytes - at);
memcpy(ring_ + at, data, first);
memcpy(ring_, data + first, len - first);
head_ += len;
}
portEXIT_CRITICAL(&ringLock);
}
@@ -59,24 +79,25 @@ uint32_t Console::oldest() const {
size_t Console::readSince(uint32_t& pos, uint8_t* out, size_t max, uint32_t& skipped) {
portENTER_CRITICAL(&ringLock);
uint32_t from = head_ > kRingBytes ? head_ - kRingBytes : 0;
skipped = pos < from ? from - pos : 0;
if (pos < from) pos = from;
size_t n = std::min<size_t>(max, head_ - pos);
size_t at = pos % kRingBytes;
size_t first = std::min(n, kRingBytes - at);
memcpy(out, ring_ + at, first);
memcpy(out + first, ring_, n - first);
pos += n;
size_t n = 0;
skipped = 0;
if (ring_) {
uint32_t from = head_ > kRingBytes ? head_ - kRingBytes : 0;
skipped = pos < from ? from - pos : 0;
if (pos < from) pos = from;
n = std::min<size_t>(max, head_ - pos);
size_t at = pos % kRingBytes;
size_t first = std::min(n, kRingBytes - at);
memcpy(out, ring_ + at, first);
memcpy(out + first, ring_, n - first);
pos += n;
}
portEXIT_CRITICAL(&ringLock);
return n;
}
#endif
size_t Console::write(const uint8_t* data, size_t len) {
#ifdef RORO_DEBUG
toRing(data, len);
#endif
// Never wait for the USB host. One that's attached but not reading (a VM, a closed terminal)
// would stall the caller for up to 2 s per write while HWCDC retries; the ring keeps it anyway.
if (Serial.availableForWrite() >= static_cast<int>(len)) Serial.write(data, len);