One firmware: the Debug Console in every build, off until switched on, with the device's own token
CI / build (pull_request) Successful in 7m20s
Site / build (pull_request) Successful in 9s

There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The
console and the test commands are compiled into every firmware. It listens
only while Settings > Debug Console is on, which isn't the default; off,
neither its task nor its 4 KB ring exists. The token is made by the device
and shown on that page; a client proves it knows it by answering a challenge
with an HMAC, so it never crosses the network, and five wrong answers close
the console for a minute. DBG in the Status Bar while it listens.

Over USB serial only: debug on, debug token <value>, debug token new.
scripts/flash.sh --debug uses them to set a device up with the developer's
token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the
file, answers the challenge, and fetches a release's ELF to decode a crash.

Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version,
scripts/debug_flags.py, update install ... force, and the rule that a Debug
Build doesn't install releases. Old clients and old firmwares don't talk to
each other.

Against the builds it replaces: 30 KB more flash and 88 bytes more static
RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests.
Checked on the device: off by default, login, the pause after wrong tokens,
Safe Mode with the console, the setting surviving an update, debug off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 22:59:35 +02:00
co-authored by Claude Opus 5.5
parent 1353e6a5f9
commit c68741cc46
65 changed files with 1245 additions and 374 deletions
+11 -7
View File
@@ -7,18 +7,23 @@
namespace roro {
// Where the firmware's console output goes: the USB serial port, and in a Debug Build also a ring
// buffer the Debug Console sends over Wi-Fi (with what came before the connection, so boot messages
// aren't lost). Use `console` instead of Serial for anything a human should be able to read remotely.
// Where the firmware's console output goes: the USB serial port, and while the Debug Console is
// switched on (ADR 0010) also a ring buffer it sends over Wi-Fi, with what came before the connection.
// Use `console` instead of Serial for anything a human should be able to read remotely.
class Console : public Print {
public:
size_t write(uint8_t c) override { return write(&c, 1); }
size_t write(const uint8_t* data, size_t len) override;
using Print::write;
#ifdef RORO_DEBUG
static constexpr size_t kRingBytes = 4096;
// The ring exists only while the Debug Console is on: 4 KB of heap a device that never uses it
// keeps. False if there's no memory for it.
bool openRing();
void closeRing();
bool ringOpen() const { return ring_ != nullptr; }
// Also copies ESP-IDF's own log lines into the ring (they still reach the serial port).
void captureEspLogs();
// Copies bytes written since `pos` into `out`, and advances `pos`. A reader that fell more than
@@ -30,9 +35,8 @@ class Console : public Print {
void toRing(const uint8_t* data, size_t len);
private:
uint8_t ring_[kRingBytes];
uint32_t head_ = 0; // total bytes ever written; the ring holds the last kRingBytes of them
#endif
uint8_t* ring_ = nullptr;
uint32_t head_ = 0; // total bytes written since the ring opened; it holds the last kRingBytes of them
};
extern Console console;