Commit Graph
100 Commits
Author SHA1 Message Date
twislaandClaude Opus 5.5 d17d10948d Shell: Tab completes a path on the SD card (#67)
CI / build (pull_request) Successful in 1m48s
Site / build (pull_request) Successful in 10s
Past the command's name, Tab completes the word being typed as a path: a
folder keeps its slash to go on from, a file completed whole gets a space,
several candidates are listed. Any case typed, the name's own is taken.
After a file command the first slash is understood (`cat no` is /no).
The folder is read on the storage task, bounded to 400 entries looked at
and 24 candidates.

489 host tests (2 new). Checked on the device: a folder, a file inside it,
several candidates, no slash, another case, nothing matching.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 12:03:44 +02:00
twislaandClaude Opus 5.5 7b5df713ad Shell: only its own replies, Apps by their names, and rm as Unix has it (#67)
CI / build (pull_request) Successful in 1m38s
Site / build (pull_request) Successful in 10s
The Shell shows the replies to its own commands and nothing else. The
console knows who each line is printed for (Console::As, Console::origin):
a command run from the Shell prints as the Shell's, and what answers it
later from another task carries that along (ls, tasks, du, cp, update
check, sd list, screenshot, gemini get). Ctrl+b shows everything instead.
This replaces the ten-second window, which was a guess.

An App's name with a capital opens it (Notes, Irc, Wifi, Gnss, Gemini, Lora,
Storage, Shell, System, Settings), from the Shell and from the consoles.

rm needs -r for a folder, here and over the consoles. In the Shell a file,
or a folder with something in it, is asked about unless -f; an empty folder
with -r goes without a word.

The Shell now hands its line to the main loop to run: run from inside the
key handler, rm on a folder overflowed the loop's stack and crashed the
device. `info` says which App is in front.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 11:35:29 +02:00
twislaandClaude Opus 5.5 3863d28593 Shell: the console's commands on the device's own screen and keyboard (#67)
CI / build (pull_request) Successful in 1m48s
Site / build (pull_request) Successful in 9s
An App in the Launcher that runs the same commands as USB serial and the
Debug Console, trusted like the first. It shows what the console prints
while it is open, through a second ring of the console's that exists only
meanwhile; Ctrl+b keeps only what follows your own commands. Tab completes
a command's name from the firmware's help text, Fn with up and down recalls
earlier lines, Alt with up and down scrolls back. `rm` asks first in the
Shell, `rm -f` doesn't. Nothing is kept once the App is left.

`screenshot [seconds]` saves the screen as a PNG in /screenshots on the
card, now or after a pause: written a row at a time, indexed colour with
RGB332 as the palette, in one stored deflate block.

487 host tests (11 new: the PNG writer, the Shell's log filter, Tab).
Checked on the device over the Debug Console: commands, Tab, history, a
screenshot fetched and decoded on the PC, rm with and without the question,
a delayed screenshot of another screen. 12 KB of flash; 7 KB of heap while
open. Decisions Q204 to Q212 in docs/milestones/S1.md. Safe Mode: #77.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 10:53:31 +02:00
twisla c278a06ca1 Merge pull request 'CI: stop rebuilding the framework at every run; a build cache and ccache (#74)' (#76) from ci-speed into main
Site / build (push) Successful in 9s
CI / build (push) Successful in 2m42s
2026-10-07 02:08:49 +00:00
twislaandClaude Opus 5.5 828f7ce821 R1: the CI timings measured on the runner
CI / build (pull_request) Successful in 1m17s
Site / build (pull_request) Successful in 8s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 02:22:15 +02:00
twislaandClaude Opus 5.5 ca5874fe70 CI: say how to start the caches again from nothing
Site / build (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m6s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 02:18:05 +02:00
twislaandClaude Opus 5.5 07ac7ba457 CI: stop rebuilding the framework at every run; a build cache, ccache, and the version out of the compiler flags (#74)
CI / build (pull_request) Successful in 7m11s
Site / build (pull_request) Successful in 9s
A pull request's firmware step took 358 s: 260 of them rebuilding the
framework that was already in the volume, because the platform decides by
sdkconfig.defaults in the project folder, which is generated and not in git,
so no fresh checkout had it. It is now kept in the volume, inside the
libraries it describes, and copied into the checkout; the platform still
checks its hash against platformio.ini.

The version was a -D on every command line: each commit recompiled
everything, and no cache could help. scripts/version.py now writes one
generated header, read by one file.

PlatformIO's build cache in the volume for pull requests' firmware, ccache
for the host tests (built for coverage, which the build cache can't keep),
the tools in a venv in the volume, and a tag builds its firmware once.
A release still compiles its own sources from nothing.

Measured on fresh copies of the tree: the firmware step 358 s to 27 s (a new
version and one changed file), tests and coverage 49 s to 33 s, a local
rebuild with nothing changed 77 s to 13 s.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 02:10:34 +02:00
twisla 942725a047 Merge pull request 'Keys: one table file for the device's help panel and the website's key tables (#72)' (#75) from keys-tables into main
CI / build (push) Successful in 1m11s
Site / build (push) Successful in 9s
2026-10-06 23:50:58 +00:00
twislaandClaude Opus 5.5 34e6714785 Keys: one table file for the device's help panel and the website's key tables (#72)
CI / build (pull_request) Successful in 7m14s
Site / build (pull_request) Successful in 8s
Every screen's keys are constant tables in lib/core/src/app_keys.h (52 of
them, each under an `// id: Title` comment). An App's help() picks the table
of the state it is in. site/tools/gen_dev_docs.py reads the same file and
writes site/data/keys.toml; the `keys` shortcode shows a screen's tables on
its guide page, and /guide/keys/ shows all of them.

The Site job fails when the data file is out of date or a page asks for a
table that doesn't exist, and now also runs when app_keys.h changes. A key
added to an App shows up on the website without anyone editing a page.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 01:42:48 +02:00
twisla 82023d36b3 Merge pull request 'Help: Fn+h lists the keys of the screen you're on; no screen names its keys any more (#69)' (#73) from help-key into main
CI / build (push) Successful in 1m19s
Site / build (push) Successful in 16s
2026-10-06 23:38:49 +00:00
twislaandClaude Opus 5.5 7fe8b3d22a Help: Fn+h lists the keys of the screen you're on, and no screen names its keys any more (#69)
CI / build (pull_request) Successful in 7m22s
Site / build (pull_request) Successful in 14s
Fn+h on any screen, text fields included, and ? outside Text Entry, open a
panel over the content area: the screen's own keys, then the ones that work
everywhere. Every App declares its keys for the state it is in (pages,
viewers, dialogs and text fields answer for themselves); the App manager
opens the panel and takes every key while it is open.

About 30 hint lines are gone, from every App. What stays on a screen is
state. The first-start Setup keeps its hints and teaches the key; a device
set up before gets one Toast, once. The guide and the FAQ open with it.
`key help` over the consoles.

476 host tests (8 new). Checked on the device with key help and screenshots:
the Launcher, all nine Apps and several of their states. 8.5 KB of flash and
40 bytes of static RAM. Decisions Q196 to Q203 in docs/milestones/U1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 01:29:51 +02:00
twisla 1c6ae0e04f Merge pull request 'Devlog: "It was off" (the website, and one firmware with the Debug Console in it)' (#71) from devlog-console into main
Site / build (push) Successful in 9s
Reviewed-on: #71
2026-10-06 22:20:56 +00:00
twislaandClaude Opus 5.5 74b7713553 Devlog: "It was off", the website and the one firmware with the Debug Console in it (v0.12.0)
Site / build (pull_request) Successful in 9s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 00:06:47 +02:00
twisla 6be05b782d Merge pull request 'One firmware: the Debug Console in every build, off until switched on (#68)' (#70) from console-setting into main
Site / build (push) Successful in 12s
CI / build (push) Successful in 13m11s
Reviewed-on: #70
2026-10-06 21:58:23 +00:00
twislaandClaude Opus 5.5 1874a1b586 Debug Console: the listener is checked and retried, and debug off <seconds> comes back by itself
CI / build (pull_request) Successful in 7m10s
Site / build (pull_request) Successful in 14s
The framework's server begin() fails without a word: the console's task now
asks whether it listens, says so, and tries again. `debug off <seconds>`
closes the console and reopens it after the pause, which is the only way to
test its closing and reopening from afar.

Checked on the device: 25 closings and reopenings, each back a second after
the pause. Free heap dips about 270 bytes for each connection the device
closes and is all back two minutes later (TCP keeps a closed connection that
long): not a leak.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 23:50:41 +02:00
twislaandClaude Opus 5.5 c68741cc46 One firmware: the Debug Console in every build, off until switched on, with the device's own token
CI / build (pull_request) Successful in 7m20s
Site / build (pull_request) Successful in 9s
There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The
console and the test commands are compiled into every firmware. It listens
only while Settings > Debug Console is on, which isn't the default; off,
neither its task nor its 4 KB ring exists. The token is made by the device
and shown on that page; a client proves it knows it by answering a challenge
with an HMAC, so it never crosses the network, and five wrong answers close
the console for a minute. DBG in the Status Bar while it listens.

Over USB serial only: debug on, debug token <value>, debug token new.
scripts/flash.sh --debug uses them to set a device up with the developer's
token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the
file, answers the challenge, and fetches a release's ELF to decode a crash.

Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version,
scripts/debug_flags.py, update install ... force, and the rule that a Debug
Build doesn't install releases. Old clients and old firmwares don't talk to
each other.

Against the builds it replaces: 30 KB more flash and 88 bytes more static
RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests.
Checked on the device: off by default, login, the pause after wrong tokens,
Safe Mode with the console, the setting surviving an update, debug off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 22:59:35 +02:00
twisla 1353e6a5f9 Merge pull request 'Site: the developer docs (phase 4), Debug Builds and the Debug Console first' (#66) from site-dev into main
CI / build (push) Successful in 1m9s
Site / build (push) Successful in 10s
Reviewed-on: #66
2026-10-06 19:34:40 +00:00
twislaandClaude Sonnet 5.5 3b4100dc6a Site: the developer docs (phase 4), with the Debug Builds and the Debug Console first
CI / build (pull_request) Successful in 8m38s
Site / build (pull_request) Successful in 9s
/dev/ has Debug Builds and the Debug Console (builds and the token, the
console and its protocol, files and screenshots, driving the UI, crashes and
Safe Mode, the command reference), Build, test and release (including how an
update works), the architecture decisions and the milestone plans.

Generated from the repository by site/tools/gen_dev_docs.py: the ADRs, the
milestones, the README's sections, and the command reference, read from the
firmware's own `help` text. The pages are committed (Zola cannot read outside
its folder); the Site workflow checks they are current, and now also runs
when src/main.cpp changes. M0, M1 and CONTEXT.md are not published.
README: the gnss commands that the table lacked.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 21:25:33 +02:00
twisla 8f95bee744 Merge pull request 'Site: how-tos and the FAQ (phase 3)' (#65) from site-howto into main
Site / build (push) Successful in 8s
Reviewed-on: #65
2026-10-06 19:08:42 +00:00
twislaandClaude Sonnet 5.5 b2bc556f6e Site: how-tos and the FAQ (phase 3)
Eight how-to recipes and a FAQ page with a list of its questions, from the
README, the milestone documents and the Apps' source. The guide templates
become generic (the parent section gives the eyebrow, title and pager).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 19:08:42 +00:00
twisla 362fbc2c0e Merge pull request 'Site: the devlog (the blog's roro9stack posts), Devlog replaces Blog in the navigation' (#64) from site-devlog into main
Site / build (push) Successful in 9s
Reviewed-on: #64
2026-10-06 18:59:43 +00:00
twislaandClaude Sonnet 5.5 b5bb3ab7d1 Site: the posts link to each other wherever they refer to one; check_site.py checks every link of the site
Site / build (pull_request) Successful in 8s
"The last post" and "the first post" in the LoRa, Gemini and S1 posts are
now links. check_site.py follows every link to another page of the site and
the #fragment it names, so a broken one fails the Site job.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 20:55:27 +02:00
twislaandClaude Sonnet 5.5 6e54658ba4 Site: the devlog, the blog's roro9stack posts in the site's style; Devlog replaces Blog in the navigation
Site / build (pull_request) Successful in 9s
Seven posts imported into site/content/devlog/ with their text unchanged,
links between them pointing to /devlog/, and shortcodes (sign, cast, steps,
asides, folded sections, diagrams, captions) restyled in the site's palette.
The 17 inline SVG diagrams carried <style> blocks and style attributes the
site's Content-Security-Policy refuses: their rules moved to
devlog-diagrams.css, and a diagram's minimum width is a class. An Atom feed
at /devlog/atom.xml.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 20:51:33 +02:00
twisla 2729f2e218 Merge pull request 'Site: the user guide (phase 2)' (#63) from site-guide into main
Site / build (push) Successful in 8s
Reviewed-on: #63
2026-10-06 18:39:59 +00:00
twislaandClaude Sonnet 5.5 2f1befa7f5 Site: the user guide (phase 2): the basics, one page per App, Settings and Updates
Site / build (pull_request) Successful in 8s
Eleven pages under /guide/, written from the README, the milestone documents
and the Apps' own source: the keys, the Launcher, the Status Bar and the first
start; the LoRa Scanner, GNSS, Gemini, IRC, Wi-Fi tools, Notes, Storage and
System; Settings (with Wi-Fi) and Updates. Real screenshots where the site has
them, a Guide link in the navigation, and the home page points to it.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 20:38:40 +02:00
twisla 5e36e69d76 Merge pull request 'Site: security.txt, robots.txt, favicon fallbacks' (#62) from site-security-txt into main
Site / build (push) Successful in 8s
Reviewed-on: #62
2026-10-06 18:16:48 +00:00
twislaandClaude Sonnet 5.5 492d8bb187 Site: security.txt, robots.txt, and favicon fallbacks (ICO, touch icon)
Site / build (pull_request) Successful in 9s
security.txt (RFC 9116) under .well-known with the mailbox as contact and an
expiry in September 2027. robots.txt allows everything and points to the
sitemap. The pixel 9 gets a favicon.ico (32 and 48 px) and an
apple-touch-icon.png, drawn by tools/make_favicons.py from the same
rectangles as favicon.svg.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 20:12:54 +02:00
twisla 821949e3f8 Merge pull request 'Site: roro9stack.net phase 1 (home, Install with a browser flasher, Downloads), and a CI split for site changes' (#61) from site into main
CI / build (push) Successful in 1m8s
Site / build (push) Successful in 7s
Reviewed-on: #61
2026-10-06 16:33:07 +00:00
twislaandClaude Sonnet 5.5 9415c62132 Site: the build goes to public/ at the repository root, which git ignores
CI / build (pull_request) Canceled after 38s
Site / build (pull_request) Successful in 8s
output_dir in site/config.toml, so zola build in site/ and zola --root site
build from the root both write ./public. The ignore is /public/, not
site/public/.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 18:31:57 +02:00
twislaandClaude Sonnet 5.5 6680b752af W1: what was built and checked in phase 1; the site in the README
CI / build (pull_request) Successful in 8m27s
Site / build (pull_request) Successful in 8s
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 18:20:18 +02:00
twislaandClaude Sonnet 5.5 8f4b5e0ddc Site: roro9stack.net, phase 1 (the home page, Install with a browser flasher, Downloads)
A Zola site in site/, from the design: both themes on the device's
palette, notched shapes, self-hosted fonts, the wordmark and icons, two
generated hero drawings, nine App cards (the mesh messenger marked
planned), real screenshots, the updates and build sections. The Install
page builds ESP Web Tools' manifest in the browser from the Gitea API (it
needs Caddy to allow the origin), refuses any download that isn't on the
project's server, and falls back to the esptool steps. Downloads lists the
releases. The focus ring shows on notched controls. A page checker fails
the build if a page loads from another origin.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 18:20:18 +02:00
twislaandClaude Sonnet 5.5 b92fc6e2e5 CI: a Site workflow, and the firmware workflow skips changes that touch only the site and its documents
site.yml builds the site with a Zola pinned by its checksum and checks the
pages when site/, docs/, README.md or CONTEXT.md change. ci.yml gets
paths-ignore for the same files on pushes to main and on pull requests; a
tag always runs it (Gitea doesn't apply path filters to tags). A change
touching both runs both.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 18:20:18 +02:00
twislaandClaude Sonnet 5.5 a0939bf741 W1 plan: the flasher reads the release from Gitea behind Caddy's CORS header, no firmware copy
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 17:54:02 +02:00
twislaandClaude Sonnet 5.5 748890deb8 W1 plan: the project website at roro9stack.net (issue #12), the design round
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 17:35:25 +02:00
twisla 4f0918ceae Merge pull request 'v0.11.0 polish: the Debug Build message, the release badge on tags, the CI timings' (#56) from fix-release-polish into main
CI / build (push) Successful in 1m10s
Reviewed-on: #56
2026-10-06 15:21:42 +00:00
twislaandClaude Sonnet 5.5 12006bdf94 CI: the release badge follows a tag, not only a push to main
CI / build (pull_request) Successful in 8m6s
After v0.11.0 was published the badge still said v0.10.0 until the next
push to main. Tag runs run the tests and coverage already; they now
publish the badges too.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 17:01:04 +02:00
twislaandClaude Sonnet 5.5 148611ff4c Updates: the Debug Build message fits on one line of the screen
"A Debug Build keeps its console: update it from your PC" ran off the
edge of the release page. It now reads "Debug Build: update from the PC".

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 17:01:04 +02:00
twislaandClaude Sonnet 5.5 325e7755ad R1 plan: the CI timings, measured from the jobs' own start and end times
The first full run took 11.4 minutes, not 17: that was the waiting time.
A pull request takes about 8.7, a release build alone 5.5, a push to main
1.1.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 17:01:04 +02:00
twisla df2aaddbc8 Merge pull request 'Updates from Gitea: check, list and install releases from the device (#6)' (#55) from gitea-updates into main
CI / build (push) Successful in 14m4s
Reviewed-on: #55
2026-10-06 14:29:01 +00:00
twislaandClaude Sonnet 5.5 e2f00e93c2 CI: a branch's pushes run nothing, its pull request runs once
CI / build (pull_request) Successful in 8m43s
A branch with an open pull request ran twice per push: once for the push,
once for the pull request. Pushes to main still run the tests and publish
the badges; every other branch is tested by its pull request.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 16:17:52 +02:00
twislaandClaude Sonnet 5.5 d490a18b9a Updates from Gitea, step 5: the daily check's announcement, the docs, ADR 0009
The announcement was cut at the notification's 48 bytes; it now reads
"v0.11.0 is out: see Settings > Firmware". README: Updates from Gitea
and its limits. ADR 0009: the device trusts the two ISRG roots. R1.md:
what was built and the checks on the device, with what wasn't checked.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 16:16:32 +02:00
twislaandClaude Sonnet 5.5 4ef41347ab Updates from Gitea, step 4: the Firmware page shows the project's releases
Latest release (checked on Enter, or c), Older releases (the last ten,
newest first), a release page with the tag's message, and an install
dialog; going back to an older release asks differently. A failed check
someone asked for shows a Toast. A Debug Build shows the latest release
and says it can't install it: it would take its console away.

Tried on the device: a check, the list, the release page, the dialog
(Cancel is the default; Back cancels), and the install from the screen
with its progress screen, then the restart into the release build and its
confirmation.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 16:06:49 +02:00
twislaandClaude Sonnet 5.5 510ce42a99 Updates from Gitea, step 3: install from Gitea, and IRC steps aside for it
A release downloads straight into the inactive slot through the existing
install path: the signature is checked after 160 bytes, before anything
is written, the hash at the end. Tried on the device against the real
server: a download cut short, a flipped byte in the signature and one in
the image are each refused with the running firmware untouched; the real
v0.10.0 installed, restarted, and confirmed itself on Probation.

A TLS connection to Gitea peaks at about 52 KB of heap whether or not the
certificate is verified. With IRC connected (66 KB free) a check left 3 KB
and a download 836 bytes. A check, list or install a person asks for now
makes IRC step aside (holdForUpdate) and come back after: the lowest free
heap during a full download with IRC connected is 38 KB. The daily check
never interrupts IRC; with IRC up it waits. A TLS connection starts with
80 KB free (it was 55).

Debug Builds get test knobs: update probe <host>, update damage cut|flip,
update pretend <version>.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 15:51:10 +02:00
twislaandClaude Sonnet 5.5 5754ae5b57 Updates from Gitea, step 2: the connection (check and list work on the device)
The roots (ISRG X1 and X2), an HTTPS client that reads the answer as a
stream, GiteaReleases (the latest and a list of ten), the Update
Service's requests, install from Gitea through the existing install path,
the daily check's schedule, the Check for updates setting, and console
commands: update check | list | status | install <tag>.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 15:20:58 +02:00
twislaandClaude Sonnet 5.5 b0e8226943 Updates from Gitea, step 1: the model (host-tested)
A streaming JSON scanner (a 33 KB list of releases costs a few hundred
bytes), the release reader built on it, HTTP response heads and chunked
bodies, URLs, and the decisions: which release is an update, whether to
announce it, and which download URLs the device takes. Tested against the
real answers of git.twis.la.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 15:11:58 +02:00
twislaandClaude Sonnet 5.5 6b7e90765f R1 plan: updates from Gitea, the design round (Q162-Q174)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 15:08:33 +02:00
twisla 3120c63b4b Merge pull request 'CI: coverage and badges; tests on a push, builds on a pull request' (#51) from coverage into main
CI / build (push) Successful in 1m7s
Reviewed-on: #51
2026-10-06 12:39:25 +00:00
twislaandClaude Opus 5.5 873af31e21 R1 plan: pull requests, merged by rebase then a merge commit (Q161)
CI / build (push) Successful in 1m6s
CI / build (pull_request) Successful in 8m17s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 14:37:44 +02:00
twislaandClaude Opus 5.5 16345ed6b3 CI: the badges are published from main only
CI / build (push) Successful in 1m5s
CI / build (pull_request) Successful in 8m19s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 14:23:08 +02:00
twislaandClaude Opus 5.5 86ddb87f54 CI: a push runs the tests, a pull request also builds the firmware
CI / build (push) Successful in 1m6s
Rebuilding both firmwares on every push was more than anyone looked at.
A push now runs the host tests with their coverage (under two minutes);
a pull request adds the release firmware and the Debug Build, and is how
changes reach main; a tag still does everything before it releases.
Pull requests from forks don't run. scripts/ci.sh takes 'tests' or
'builds' for one half; coverage.sh now fails when a test fails.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 14:19:56 +02:00
twislaandClaude Opus 5.5 5ecd5d003f Coverage of lib/ by the host tests, and badges in the README
CI / build (push) Successful in 9m9s
scripts/coverage.sh builds the host tests with coverage counters and
reports with gcovr: 94.6% of the 3,193 lines of lib/ today (lib/SD and
src/ have no host tests and aren't counted). CI runs it on every push,
puts the figure in the job's summary, and on main publishes a coverage
badge and a latest-release badge to the branch 'badges'. The README shows
them next to Gitea's own badge for the workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 13:56:08 +02:00
twislaandClaude Opus 5.5 edc140e30c Merge branch 'ci': CI on every push, a signed release on every tag
CI / build (push) Successful in 8m10s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 13:51:19 +02:00
twislaandClaude Opus 5.5 6459ca5446 R1 plan: CI and releases are in place
CI / build (push) Successful in 8m8s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 13:51:18 +02:00
twislaandClaude Opus 5.5 a94c14f000 R1 plan: CI as built on the container runner
CI / build (push) Successful in 8m5s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:52:43 +02:00
twislaandClaude Opus 5.5 db7e6ccc18 CI: jobs run in a container, PlatformIO directly in it, the toolchains in a volume
CI / build (push) Successful in 8m5s
The runner now gives each job a container. The workflow asks for
python:3.12-slim, installs git, a compiler and PlatformIO, and mounts the
roro9stack-pio volume as the cache; the scripts skip their own docker run
when RORO_NO_DOCKER says they're in the build container already. A tag
from before the framework was rebuilt gets the stock framework libraries
back before it builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:39:37 +02:00
twislaandClaude Opus 5.5 ababfaf993 Release build: tags from before Firmware Updates carry no public key to check against
CI / build (push) Failing after 12m51s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:25:20 +02:00
twislaandClaude Opus 5.5 6b6bb975f5 R1 plan and ADR 0008: CI signs releases; README section on CI
CI / build (push) Successful in 8m0s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:19:00 +02:00
twislaandClaude Opus 5.5 1fade6287b CI: tests and builds on every push, a signed release on a tag (#5)
CI / build (push) Successful in 11m26s
The workflow runs on the runner's host and builds in the project's Docker
image through scripts/ci.sh, as on a developer's machine. A tag v*, or a
run by hand for an older tag, builds that tag's sources, signs the Update
File with the key held in the repository's secrets, checks the signature
against the public key in the sources, and publishes a Gitea release with
the .ota, the factory image, the ELF and checksums.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:06:57 +02:00
twislaandClaude Opus 5.5 661227cd2d CI: try the runner's label as it is registered
CI / probe (push) Successful in 0s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 11:58:53 +02:00
twislaandClaude Opus 5.5 c481bb5191 CI: a first workflow, to see what the runner gives a job (#5)
CI / probe (push) Successful in 19s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 11:56:10 +02:00
twislaandClaude Opus 5.5 9f65c75f01 Merge branch 'notes': the Notes App
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:11:31 +02:00
twislaandClaude Opus 5.5 a35d82c654 F1 plan: Notes ships as v0.10.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:11:31 +02:00
twislaandClaude Opus 5.5 e8a654a15f Notes: plain text notes on the SD card, with an editor that saves by itself (#19)
The Notes App lists the files of /notes by their first line, newest first:
n starts a note, Enter opens it, r renames its file, d deletes it after
asking, s sorts by name. A new note's file is named after its first line.

The editor wraps at spaces, 38 columns by 8 rows; Fn+arrows move through
the wrapped text, Ctrl+A and Ctrl+E go to the ends of the line. There is no
save key: the note is written five seconds after the last key, on Back, on
leaving the App, when the screen turns off and before the device powers
off. A save writes a temporary file and puts it in the note's place; a save
cut short is put back, or offered, the next time.

A note is up to 16 KB, held in one buffer reserved when it's opened: the
file is read straight into it and typing never makes it grow. A failed
allocation aborts on this device, and with IRC connected the largest free
block is about 31 KB: a first version that copied the note once on loading
restarted the device when a full note was opened with IRC connected.
Editing files of any size is #47.

The Storage App's text viewer gets `e`, which edits a text file up to 16 KB
with the same editor unless the file is read-only.

439 host tests. Checked on the device: docs/milestones/F1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:08:10 +02:00
twislaandClaude Opus 5.5 c868977f1c A key sent through the Debug Console could turn the screen "off" for a tick
The `key` command stamps the power timer from millis(); the power tick
then compared with its pass's older time, and the unsigned difference read
as 49 days without a key. The screen state went Off for one tick, and the
next key was swallowed as a wake-up: about one remote key in twenty-five.
Keys from the keyboard pass the loop's own time and were never affected.
The same shape as #46. PowerPolicy::update now treats a stamp from the
future as "just now", with a test.

rdbg.py: piped lines written while it was still connecting stayed in
Python's read buffer until the next line arrived (readline() behind
select()). It reads the descriptor directly now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:08:10 +02:00
twislaandClaude Opus 5.5 4ab873e9f8 F1 plan: the Notes design round (Q141-Q150)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:29:38 +02:00
twislaandClaude Opus 5.5 50fcf6b7a3 Merge branch 'f1': the Storage App
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:03:50 +02:00
twislaandClaude Opus 5.5 80d68ccfd7 F1 plan: the Storage App ships as v0.9.0; the SNTP panic is #46
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:03:49 +02:00
twislaandClaude Opus 5.5 e14eb304b5 Wi-Fi: SNTP could be started twice at a join, and ESP-IDF asserts on that
At every join the DNS and NTP setup ran twice in the same pass: the
"check now and then" timer compared this pass's time with a stamp taken
from millis() a moment later, and the unsigned difference underflowed.
Starting SNTP is only queued for the network task, so when the second run
looked before the first had been carried out, it queued a second start:
"Operating mode must not be set while SNTP client is running", a panic
nine seconds after boot. Rare (once in the dozen or so boots of this
branch's testing), there since v0.7.0. Rollback caught it: the update
was on Probation and the device went back to the build before.

The service now remembers that it started SNTP instead of asking
esp_sntp_enabled(), and the timer compares signed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 08:52:54 +02:00
twislaandClaude Opus 5.5 b7aed8e91c F1 steps 2-6: the Storage App, its viewers, and Maintenance moved in (#3)
The Storage App browses the SD card: folders first with sizes and dates,
three sorts, one item at a time with a clipboard (c, x, v), rename, delete
after counting what's inside, new folder, details. A listing holds 256
entries and says when a folder has more.

FileOps does the card's work for the App and the console alike, one
operation at a time on the storage task in turns of about 150 ms, so Logs
and Captures are still written during a long copy. A copy shows progress,
can be cancelled (what it wrote is taken back) and compares sizes after.
The read-only rules are checked there: the firmware's top-level folders,
/gemini/cache, and files being written (a Track, a Capture, an upload,
today's IRC Logs). A listing reads the folder straight from FatFs: through
the Arduino File, 329 entries took over two seconds.

Viewers by type: text read a screen at a time whatever the file's size
(logs open at the end), a hex dump, a Capture's packets as the LoRa Scanner
lists them, a Track's summary, and an Update File checked as an install
would check it, without writing anything. Tab shows any file as hex or text.

Settings > Storage is gone: usage, Storage Clean-up and Erase are the App's
Maintenance, behind a warning. The Storage Warning points there.

The Clock sets the system time whatever its source, so files are dated
correctly with a GNSS Fix alone (Q137).

Console: cp, mv, mkdir, du, cancel; rm takes folders and follows the rules;
ls shows dates; Debug Builds get `sd fill`.

424 host tests. Checked on the device: docs/milestones/F1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 08:45:43 +02:00
twislaandClaude Opus 5.5 7ab8f043d0 F1 step 1: names, read-only rules and the packed listing (host-tested)
lib/files: path parts; names checked for rename and new folder; why
something can't be renamed, moved or deleted (the Gemini cache, a file
being written or a folder holding one, the firmware's top-level
folders), and why it can't go into a folder; the viewer for a file by
its name, with a sniff for text. FileList keeps a folder's entries
packed, 256 at most, the first 256 by name whatever order the card lists
them in, and sorts by name, date or size with folders first.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 07:37:36 +02:00
twislaandClaude Opus 5.5 63bae576ef F1 plan: the Storage App's design round (Q128-Q140)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 07:34:43 +02:00
twislaandClaude Opus 5.5 77ace09c64 Merge branch 's1': the main loop rests, and GNSS can pause for the radio
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 06:42:33 +02:00
twislaandClaude Opus 5.5 c4465675a0 S1 plan: the resting loop and the GNSS pause ship in v0.8.1
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 06:42:33 +02:00
twislaandClaude Opus 5.5 70fb37ebb5 The radio's noise: the GNSS receiver costs 8 dB; a setting pauses it (#20)
Debug Builds: `lora noise test` changes one thing at a time, Sweeps the
band, and reports the floor under each condition; it runs on the device
by itself, since one condition pauses Wi-Fi (not saved, so a restart
brings it back). Result, at 125 kHz: -117 dBm with the antenna switched
off, -106 with the GNSS receiver in standby, -98 with it running. The
receiver's serial line isn't it (one sentence a second changes nothing),
and neither are the main loop, the CPU frequency, Wi-Fi, the screen or
the radio's own regulator, all within 1 dB.

Settings > "Pause GNSS for LoRa", off by default: the receiver waits in
standby while the radio listens or sweeps, except during a Track, and
has a Fix again about 7 s after. The GNSS App says it's paused.

11 dB remain between the antenna with GNSS quiet and the chip alone,
untouched by anything that can be switched from the firmware.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 03:41:15 +02:00
twislaandClaude Opus 5.5 06a593293d The main loop rests between passes (#40)
It made 50,000 passes a second and kept core 1 100 % busy at rest. Keys
are buffered by the keyboard controller, the consoles and the radio have
their own tasks, and no Service ticks more often than every 50 ms, so
the loop now rests 5 ms after a pass with the screen on and 20 ms with
it off; never during a serial file transfer. Safe Mode's loop too.

Screen off: 50 passes a second and core 1 at 1 %; screen on: 167 and
10 %. The chip settles 4 C cooler (34.3 against 38.3). GNSS, Gemini, an
upload, the Sweep and the radio's interrupt all checked at the new pace.
`tasks` shows the loop's passes; Debug Builds: `loop spin on|off`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 03:08:02 +02:00
twislaandClaude Opus 5.5 9078ab9c39 Merge branch 's1': the System App, and traffic counted per service
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:32:01 +02:00
twislaandClaude Opus 5.5 06aa3fe28b S1 plan: the System App ships in v0.8.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:32:01 +02:00
twislaandClaude Opus 5.5 e36aa50922 S1 #11: the System App: tasks, memory, network and system, live
Five views, Tab between them: Overview (each core's load, memory,
traffic, battery, two minutes of load), Tasks (share of a core over the
last second, lowest free stack, flagged under 512 bytes; `s` sorts),
Memory (free heap against the floors of Q86), Network (bytes per
service, and what's moving now), System (what `info` prints, plus
battery, card, radio, GNSS). It samples once a second and keeps history
only while open.

The arithmetic is host-tested, including the trap found on the device: a
task's run-time counter only moves when it's switched out, so the task
that samples (the main loop, alone on its core) gets what's left of its
core. `tasks` now samples across a second of normal running instead of
inside its own wait. The main loop uses 100 % of core 1 at rest (#40).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:28:26 +02:00
twislaandClaude Opus 5.5 70bb2a4137 S1 #11: bytes read and written, counted per network service
A Counted<> wrapper around the network clients adds what goes through
their buffer read and write to a per-service counter (IRC, Gemini, Debug
Console, Updates); the single-byte calls and print() end up there, so
each byte counts once. `net` prints the totals. For TLS it's the plain
text the service sees.

Checked on the device: a Gemini fetch counts 164,986 in (a 164,970-byte
page and its 16-byte header) and 42 out (the URL and CRLF).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:10:55 +02:00
twislaandClaude Opus 5.5 1df94b684a S1 #11: the System Monitor's design round (Q117-Q127)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:04:41 +02:00
twislaandClaude Opus 5.5 00f69e8d53 S1 plan: fixed IPv4 shipped in v0.7.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:55:32 +02:00
twislaandClaude Opus 5.5 f834095ee3 Merge branch 's1': fixed IPv4 addresses, DNS and NTP servers
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:48:41 +02:00
twislaandClaude Opus 5.5 acf7697bdc S1 #7 step 4: fixed IPv4, DNS and NTP in Settings
Enter on a Saved Network opens its page instead of asking to forget it:
"IP address" switches between Automatic and Fixed, with an address, a
prefix and an optional gateway. Fixed starts from what the network is
giving the device; the draft is checked and applied on leaving the page,
so a half-typed address is never used. "DNS and NTP" holds the two DNS
servers, "Always use my DNS" and the two NTP servers. Enter on Status
shows the connection's details and where each value came from. Address
fields take digits and dots only; refusals show as Toasts.

Checked on the device through the screens: Fixed 10.39.39.13 applied and
reverted to Automatic, a prefix of 99 refused. Measurements in
docs/milestones/S1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:04:53 +02:00
twislaandClaude Opus 5.5 3e279738b6 S1 #7 step 3: the Wi-Fi Service applies IP, DNS and NTP settings
Joining a Saved Network uses its Fixed address, mask and gateway, or
DHCP. DNS comes from Settings on Fixed networks and when "Always use my
DNS" is on; NTP servers come from Settings, after any that DHCP offered.
Both are re-checked every 30 s, since a DHCP renewal puts DHCP's DNS back
and clears the NTP slots it didn't fill. `wifi status` shows what's in
use, where it came from, and which NTP servers answered; `wifi ip`,
`wifi dns`, `wifi ntp`. Debug Builds: `wifi ip ... try <s>` reverts
unless kept.

On knbg-guests (10.39.39.0/24, gateway .1): Fixed .12 and .13 both reach
the internet through 9.9.9.9; a wrong gateway on trial cut the device off
and came back by itself; back to DHCP; both NTP servers answer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:52:22 +02:00
twislaandClaude Opus 5.5 bdd027cb50 S1 #7 steps 1-2: IPv4 checks, the IP setting per Saved Network, DNS and NTP settings
The plan and decisions Q105 to Q116 (docs/milestones/S1.md). lib/net:
strict IPv4 parsing, prefix and mask, and the checks a Fixed setting must
pass, each refusal with its reason. A Saved Network is Automatic or Fixed
(address/prefix and an optional gateway), kept with it in flash. Settings:
two DNS servers (9.9.9.9, 1.1.1.1), "Always use my DNS", two NTP servers
(pool.ntp.org, time.cloudflare.com). Host-tested: 383 tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:39:07 +02:00
twislaandClaude Opus 5.5 7e8882d9cb Merge branch 's1': the SD driver's ready test, and sd card
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:25:55 +02:00
twislaandClaude Opus 5.5 7b2cf88a0a ADR 0007: link the upstream report and the issue that follows it
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:16:17 +02:00
twislaandClaude Opus 5.5 370f067fbf sd card: what the card says it is, from its CID register
Type, size, and the identity register read by our SD driver (CMD10):
manufacturer, OEM, product name, revision, serial and date, decoded by a
host-tested parser. Needed for the upstream report of #21: nothing else
here could read the card's identity. This one is a Samsung 8 GB SDHC
from June 2013.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:15:29 +02:00
twislaandClaude Opus 5.5 3f2650c56e SD driver: a dummy byte before the ready test; say why a write failed (#21)
The card "refused" a write about once in 2,000 multi-block writes: three
1.7 MB uploads in ten. Measured with a driver that records where it gives
up: every time, all blocks were accepted, and the status check after Stop
Tran came back as 0xFF or 0x1F. The driver tests for ready with the first
byte after selecting the card, which reads 0xFF before the card has
signalled busy, so CMD13 went out mid-programming. A dummy byte first, as
in ChaN's reference driver, and one after Stop Tran.

30 uploads in a row since, each read back by SHA-256, ten with the radio
listening: no fault. 10 MHz made no difference; the card stays at 20 MHz.

`info` shows the driver's write faults; `put` prints the step and the
card's answer when one happens. ADR 0007.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 22:55:02 +02:00
twislaandClaude Opus 5.5 3ee7ae1097 lib/SD: Arduino-ESP32 3.3.12's SD library, as it comes
A project library named SD takes the framework's place at link time.
Unchanged here (Apache-2.0), so that the next commit shows exactly what
roro9stack changes in it, and a later framework update can be compared.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 22:51:59 +02:00
twislaandClaude Opus 5.5 60cec80fa4 Merge branch 'm3': the LoRa radio, receive only, and the LoRa Scanner
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 21:40:43 +02:00
twislaandClaude Opus 5.5 4744163683 M3 done: the listening hour heard nothing; a reference node is needed for M4
Outside, on battery, an hour on LongFast with a Capture running: 0
packets, 0 headers. The noise is no lower than at the desk and its peaks
follow the device, so about 15 dB of the floor is the Cardputer's own
(issue #20). With IRC on TLS and the radio listening, 52.6 KB free. One
"Done when" item is half met: Sweep was never tried against a known
transmitter. The card's refused writes are issue #21.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 21:40:30 +02:00
twislaandClaude Opus 5.5 b1de0f8804 M3 step 5: Sweep, the band's signal strength as bars and a waterfall
Tab in the LoRa Scanner sweeps 863-870 MHz in 100 kHz steps (the
strongest of three RSSI readings at each, at 125 kHz), shown as bars with
peak hold over a waterfall, the Sniffer's frequency marked (Q98). The
Sweep pauses the Sniffer and keeps its packets; Tab resumes it (Q99).
Status Bar: SW. The floor, top and peaks are host-tested; `lora sweep
on|off|dump` prints them on the console.

At the desk: about 607 ms a pass, a flat floor at -100 to -102 dBm
(15 dB above the chip's own) and a steady carrier at 863.2 MHz.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 20:28:46 +02:00
twislaandClaude Opus 5.5 2fce79aebd M3 step 4: the LoRa Scanner App, Sniffer and Captures
The Sniffer lists packets newest first (time, RSSI, SNR, and for
Meshtastic the sender, receiver and hops), with the clear header and a
hex dump on Enter (Q96); `p` picks an EU868 preset, kept in Settings
(Q95). `c` starts a Capture: pcap with LoRaTap in /captures/lora, its own
Clean-up category, recorded by a small Service so it carries on with the
App closed (Q97, Q100). The Status Bar shows L while listening, bright on
each packet, and CAP while capturing (Q101). StorageService gains raw
appends for binary files. Debug Builds get `lora inject` to test all of
this with no transmitter in range: a Capture made on the device reads
back in TShark field for field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 20:14:58 +02:00
twislaandClaude Opus 5.5 594748e99a M3 step 3: the Radio Service, receive only
One task owns the SX1262 and does all its SPI behind the card's bus lock;
the main loop posts requests and DIO1 only wakes the task. It listens
while a client asks (App, Capture, Console) and sleeps otherwise, with a
ring of the last 32 packets (9.8 KB, freed when idle). No transmit path.
The Cap's antenna switch (expander P0) is set on the main loop, which
owns the I2C bus. `lora probe` now runs on the radio task and checks the
DIO1 interrupt with a receive timeout; `lora status`, `lora rx on|off`,
`lora preset`, and `lora custom` for other LoRa settings.

Measured: DIO1 works (timeout after 105 ms); four 1.7 MB uploads and
Gemini pages to the card while listening, no radio or card errors; task
stack peak 2.0 KB. Twenty minutes on LongFast and LoRaWAN: no packets,
and a noise floor of -83 to -94 dBm at the desk.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:49:46 +02:00
twislaandClaude Opus 5.5 30a827070b Gemini: count the App's per-line tables in the page budget
Found in M3 while checking floors with the radio on: a windowed page left
1.5 to 3 KB less than the 40 KB steady floor (Q86), radio or not. The
budget counted TextBuffer's index (8 B/line) but not the App's tables,
which also grew by doubling. Now 16 B/line, and the App sizes them
exactly. The FAQ (1051 lines, windowed): 38.5 -> 39.6 KB after, radio
asleep; 37.1 -> 39.0 KB with the radio listening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:19:52 +02:00
twislaandClaude Opus 5.5 a0e3868934 Debug Console put: verify the card's copy, never zero-fill after a failed write
Found by M3's shared-bus test: when the card refused a write, the retry
closed the file (losing up to 3 KB of earlier chunks still in the write
buffer), then truncate() extended it back with zeros. The checksum only
covered the received bytes, so `put` reported success with 3 KB of zeros
on the card. Now a retry gives up if the card lost data, and the finished
file is read back and must hash the same before it's renamed.

The card refuses a write about once in five 1.7 MB uploads, with the
radio asleep as often as listening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:13:25 +02:00
twislaandClaude Opus 5.5 3242475699 M3 step 2: Meshtastic header and presets, pcap with LoRaTap (host-tested)
The 16-byte clear header (hops away, channel hash, relay node), the EU_868
presets and their frequency slots, and the channel hash, all checked
against Meshtastic's source. Captures are pcap with LoRaTap v0, read back
with TShark 4.2.5; packet RSSI is plain dBm, as Wireshark reads it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:59:23 +02:00
twislaandClaude Opus 5.5 fed065a6f9 M3 step 1: RadioLib and lora probe
The probe finds the SX1262 (TCXO 1.8 V works) and measures the antenna
path: the Cap's PI4IOE5V6408 at 0x43 must drive P0 high, or the receiver
is deaf (-111.9 dBm flat vs -87 to -94 dBm with P0 high). DIO2 makes no
difference to reception. Receive only; the radio is left asleep.

RadioLib 7.8.1 + probe: +23.6 KB flash, +656 B static RAM (release).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:52:38 +02:00
twislaandClaude Opus 5.5 6485f277b5 M3 plan: radio bring-up, receive only (Q89-Q104)
The Radio Service owns the SX1262 and shares the SPI bus with the card;
the LoRa Scanner shows packets (Sniffer) and the band (Sweep). Nothing in
M3 can transmit. Notes and the File Browser move to issues #19 and #3.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:44:25 +02:00