Public Access
One firmware: the Debug Console in every build, off until switched on, with the device's own token
There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The console and the test commands are compiled into every firmware. It listens only while Settings > Debug Console is on, which isn't the default; off, neither its task nor its 4 KB ring exists. The token is made by the device and shown on that page; a client proves it knows it by answering a challenge with an HMAC, so it never crosses the network, and five wrong answers close the console for a minute. DBG in the Status Bar while it listens. Over USB serial only: debug on, debug token <value>, debug token new. scripts/flash.sh --debug uses them to set a device up with the developer's token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the file, answers the challenge, and fetches a release's ELF to decode a crash. Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version, scripts/debug_flags.py, update install ... force, and the rule that a Debug Build doesn't install releases. Old clients and old firmwares don't talk to each other. Against the builds it replaces: 30 KB more flash and 88 bytes more static RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests. Checked on the device: off by default, login, the pause after wrong tokens, Safe Mode with the console, the setting surviving an update, debug off. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -185,6 +185,41 @@ void test_dns_and_ntp_are_checked() {
|
||||
TEST_ASSERT_TRUE(s.setString(Setting::Ntp2, ""));
|
||||
}
|
||||
|
||||
// ADR 0010: off, and no token, until the owner switches the console on. A stored value that isn't
|
||||
// valid counts as missing, so a damaged store can't switch it on or leave a weak token.
|
||||
void test_the_debug_console_is_off_and_has_no_token_by_default() {
|
||||
MemoryStore store;
|
||||
EventBus bus;
|
||||
Settings s(store, bus);
|
||||
s.load();
|
||||
TEST_ASSERT_FALSE(s.getBool(Setting::DebugConsole));
|
||||
TEST_ASSERT_EQUAL_STRING("", s.getString(Setting::DebugToken).c_str());
|
||||
|
||||
MemoryStore damaged;
|
||||
damaged.ints["debug_on"] = 7; // not a bool
|
||||
damaged.strings["debug_token"] = "1234"; // too short
|
||||
Settings d(damaged, bus);
|
||||
d.load();
|
||||
TEST_ASSERT_FALSE(d.getBool(Setting::DebugConsole));
|
||||
TEST_ASSERT_EQUAL_STRING("", d.getString(Setting::DebugToken).c_str());
|
||||
}
|
||||
|
||||
void test_a_debug_token_must_be_valid_or_empty() {
|
||||
MemoryStore store;
|
||||
EventBus bus;
|
||||
Settings s(store, bus);
|
||||
s.load();
|
||||
TEST_ASSERT_FALSE(s.setString(Setting::DebugToken, "1234"));
|
||||
TEST_ASSERT_FALSE(s.setString(Setting::DebugToken, "k7qf-3m2x-9wbd-ht4p-6rnc")); // not tidied
|
||||
TEST_ASSERT_TRUE(s.setString(Setting::DebugToken, "K7QF3M2X9WBDHT4P6RNC"));
|
||||
TEST_ASSERT_TRUE(s.setBool(Setting::DebugConsole, true));
|
||||
Settings again(store, bus);
|
||||
again.load();
|
||||
TEST_ASSERT_TRUE(again.getBool(Setting::DebugConsole));
|
||||
TEST_ASSERT_EQUAL_STRING("K7QF3M2X9WBDHT4P6RNC", again.getString(Setting::DebugToken).c_str());
|
||||
TEST_ASSERT_TRUE(again.setString(Setting::DebugToken, "")); // forgotten
|
||||
}
|
||||
|
||||
int main() {
|
||||
UNITY_BEGIN();
|
||||
RUN_TEST(test_defaults_when_store_is_empty);
|
||||
@@ -201,5 +236,7 @@ int main() {
|
||||
RUN_TEST(test_storage_keys_fit_nvs_limit);
|
||||
RUN_TEST(test_dns_and_ntp_defaults);
|
||||
RUN_TEST(test_dns_and_ntp_are_checked);
|
||||
RUN_TEST(test_the_debug_console_is_off_and_has_no_token_by_default);
|
||||
RUN_TEST(test_a_debug_token_must_be_valid_or_empty);
|
||||
return UNITY_END();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user