Public Access
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
df2aaddbc8 | ||
|
|
e2f00e93c2 | ||
|
|
d490a18b9a | ||
|
|
4ef41347ab | ||
|
|
510ce42a99 | ||
|
|
5754ae5b57 | ||
|
|
b0e8226943 | ||
|
|
6b7e90765f | ||
|
|
3120c63b4b | ||
|
|
873af31e21 | ||
|
|
16345ed6b3 | ||
|
|
86ddb87f54 | ||
|
|
5ecd5d003f | ||
|
|
edc140e30c |
+33
-8
@@ -1,6 +1,9 @@
|
||||
# CI and releases (docs/milestones/R1.md).
|
||||
# Any push: host tests, then the release firmware and the Debug Build.
|
||||
# A tag v*: the same, then a Gitea release with the signed Update File.
|
||||
# A push to main: the host tests, with their coverage of lib/, and the README's badges
|
||||
# published to the branch `badges`.
|
||||
# A pull request: the same tests and coverage, then the release firmware and the Debug Build.
|
||||
# A branch's pushes run nothing by themselves: its pull request runs, once.
|
||||
# A tag v*: all of it, then a Gitea release with the signed Update File.
|
||||
# Run by hand: the release of a tag that exists already (the ones from before CI).
|
||||
#
|
||||
# The job runs in a plain Python image, as scripts/ci.sh does on a developer's machine, with the
|
||||
@@ -9,8 +12,9 @@
|
||||
name: CI
|
||||
on:
|
||||
push:
|
||||
branches: ['**']
|
||||
branches: [main] # other branches are tested by their pull request: one run, not two
|
||||
tags: ['v*']
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
@@ -20,6 +24,8 @@ on:
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu
|
||||
# A pull request from a fork would run someone else's code on our runner: not without us (Q154).
|
||||
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
||||
container:
|
||||
image: python:3.12-slim
|
||||
volumes:
|
||||
@@ -32,7 +38,7 @@ jobs:
|
||||
run: |
|
||||
apt-get update -qq
|
||||
apt-get install -y -qq --no-install-recommends git build-essential openssl >/dev/null
|
||||
pip install -q --no-cache-dir --root-user-action=ignore platformio
|
||||
pip install -q --no-cache-dir --root-user-action=ignore platformio gcovr
|
||||
pio --version; df -h /pio | tail -1; ls /pio | head
|
||||
|
||||
- name: Check out
|
||||
@@ -41,13 +47,32 @@ jobs:
|
||||
git config --global --add safe.directory '*'
|
||||
git init -q .
|
||||
git remote add origin "${{ github.server_url }}/${{ github.repository }}.git"
|
||||
git fetch -q --tags origin '+refs/heads/*:refs/remotes/origin/*'
|
||||
git fetch -q --tags origin '+refs/heads/*:refs/remotes/origin/*' '+refs/pull/*/head:refs/remotes/pull/*'
|
||||
git checkout -q --detach "${{ github.sha }}"
|
||||
git describe --tags --always
|
||||
|
||||
- name: Host tests and both builds
|
||||
if: github.event_name == 'push'
|
||||
run: scripts/ci.sh
|
||||
- name: Host tests, and their coverage of lib/
|
||||
if: github.event_name != 'workflow_dispatch'
|
||||
run: scripts/coverage.sh
|
||||
|
||||
- name: The release firmware and the Debug Build
|
||||
if: github.event_name == 'pull_request' || github.ref_type == 'tag'
|
||||
run: scripts/ci.sh builds
|
||||
|
||||
# The README's badges are files on a branch of their own, replaced at each push to main.
|
||||
- name: Publish the badges
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
env:
|
||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
run: |
|
||||
rm -rf /tmp/badges && mkdir /tmp/badges
|
||||
cp .pio/coverage/coverage.svg .pio/coverage/summary.json /tmp/badges/
|
||||
scripts/coverage_badge.py --plain release "$(git describe --tags --abbrev=0)" /tmp/badges/release.svg
|
||||
cd /tmp/badges
|
||||
git init -q -b badges .
|
||||
git add .
|
||||
git -c user.name="roro9stack CI" -c user.email="ci@git.twis.la" commit -q -m "Coverage of ${{ github.ref_name }} at ${{ github.sha }}"
|
||||
git push -q --force "$(echo "${{ github.server_url }}" | sed "s#://#://ci:${GITEA_TOKEN}@#")/${{ github.repository }}.git" badges
|
||||
|
||||
- name: Which release
|
||||
id: release
|
||||
|
||||
+4
-1
@@ -141,7 +141,10 @@ The part of the Storage App that deletes in bulk: the card's usage, Storage Clea
|
||||
_Avoid_: Settings > Storage
|
||||
|
||||
**Firmware Update**:
|
||||
Installing a new firmware image without a USB cable: pushed over Wi-Fi from the developer's PC, or read from the SD card.
|
||||
Installing a new firmware image without a USB cable: pushed over Wi-Fi from the developer's PC, read from the SD card, or downloaded from the project's Gitea **Release**.
|
||||
|
||||
**Release**:
|
||||
A tag `v*` on the project's Gitea with a signed **Update File**, a factory image for USB, the ELF to decode crashes and checksums, built and published by CI. The device reads them to look for updates. Debug Builds aren't published.
|
||||
_Avoid_: flash, upgrade (alone)
|
||||
|
||||
**Update File**:
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# roro9stack
|
||||
|
||||
[](https://git.twis.la/twisla/roro9stack/actions?workflow=ci.yml) [](#build-and-test-local-ci) [](https://git.twis.la/twisla/roro9stack/releases/latest)
|
||||
|
||||
A multi-app firmware for the **M5Stack Cardputer ADV** with the **Cap LoRa-1262**. It's a Meshtastic-compatible mesh messenger, plus Wi-Fi tools, IRC, GNSS and more. Licensed GPL-3.0.
|
||||
|
||||
- Domain language: [CONTEXT.md](CONTEXT.md)
|
||||
@@ -18,11 +20,13 @@ scripts/ci.sh
|
||||
|
||||
This runs the host-side unit tests (`test/`, `native` environment), then builds the firmware. The output is `.pio/build/cardputer-adv/firmware.factory.bin`.
|
||||
|
||||
`scripts/coverage.sh` runs the same tests with coverage counters and writes a line-by-line report to `.pio/coverage/index.html`. The badge above is its figure for `main`: the share of the lines of `lib/` that the host tests run. `lib/` is the logic that compiles on a PC; `lib/SD` (the card's driver) and `src/` (the Apps, the Services, everything that needs the device) have no host tests and aren't in that figure.
|
||||
|
||||
The framework is rebuilt with the TLS settings in `platformio.ini` (`custom_sdkconfig`, ADR 0006), so the first build after a fresh checkout takes about 4 minutes; later builds take under a minute.
|
||||
|
||||
## CI and releases
|
||||
|
||||
Gitea Actions runs the same thing on every push (`.gitea/workflows/ci.yml`, docs/milestones/R1.md). Pushing a tag `v*` also publishes a release on Gitea with:
|
||||
Gitea Actions (`.gitea/workflows/ci.yml`, docs/milestones/R1.md) runs the host tests on every push to `main`, and on a pull request also builds the release firmware and the Debug Build: changes reach `main` through pull requests. Pushing a tag `v*` runs all of it and publishes a release on Gitea with:
|
||||
|
||||
- `roro9stack-<version>.ota`, the signed Update File;
|
||||
- `roro9stack-<version>-factory.bin`, the whole flash image for a first install over USB;
|
||||
@@ -65,7 +69,21 @@ The device shows the push address in **Settings → Firmware**. It installs a co
|
||||
|
||||
To install from the SD card instead, copy the `.ota` file from `.pio/build/cardputer-adv/` into `/updates` on the card, then use **Settings → Firmware**. With the Cardputer on USB, the card can stay in: `scripts/sd_put.sh <file.ota>` sends it over the serial console into `/updates` (about 30 s for 1.6 MB, checked with SHA-256 before it's renamed into place; `SD_PUT_DEBUG=1` shows the console while it runs).
|
||||
|
||||
**The private key** lives in `~/.config/roro9stack/ota-key.pem` and must never be committed. If it's lost, generate a new pair and flash once over USB.
|
||||
**The private key** lives in `~/.config/roro9stack/ota-key.pem` and must never be committed. If it's lost, generate a new pair and flash once over USB. (CI signs releases with a copy kept as a repository secret, ADR 0008.)
|
||||
|
||||
### Updates from Gitea
|
||||
|
||||
With no PC and no card, the device can install the project's releases itself (docs/milestones/R1.md). In **Settings → Firmware**:
|
||||
|
||||
- **Latest release** checks the server (Enter, or `c`) and says `v0.11.0 (new)` or `(current)`. Enter again opens the release: its version, date, size and the tag's message, with **Install** when it's newer. The download goes straight into the inactive slot, so no card is needed; the signature is checked after the first 160 bytes, before anything is written, and the image's hash at the end. The new firmware then runs on Probation as for any update.
|
||||
- **Older releases** lists the last ten, newest first. Opening an older one offers to go back to it, with a different question.
|
||||
- **Settings → Check for updates** (on by default): once a day, with Wi-Fi up and the clock set, the device looks at the latest release and says `v0.11.0 is out: see Settings > Firmware`, once per version. It installs nothing by itself, and doesn't announce a version that already failed and rolled back on this device.
|
||||
|
||||
The connection is checked against the two ISRG roots Let's Encrypt chains end in (ADR 0009), not the usual bundle of about 130 authorities. Whatever the connection, the Update File's own signature is what decides what gets installed.
|
||||
|
||||
**IRC steps aside.** A secure connection takes about 52 KB of memory at its peak, and IRC's own takes 40 KB of the 107 KB there is. A check or an install you ask for makes IRC disconnect for the few seconds it takes and reconnect afterwards. The daily check never does that: with IRC connected it waits for a moment when IRC isn't, so while IRC stays connected for days it doesn't run, and **Latest release** is the way to check.
|
||||
|
||||
**A Debug Build** shows the latest release but doesn't install it: releases have no Debug Console (they aren't built with one, so that nobody's console token is published), and installing one would take it away. A Debug Build is updated from the PC with `scripts/flash.sh --debug --ota`.
|
||||
|
||||
## Networks without DHCP
|
||||
|
||||
@@ -163,6 +181,8 @@ A note holds up to 16 KB while it's edited. A bigger text file opens read-only i
|
||||
| `ls [folder]` / `du <path>` | Lists a folder of the SD card with sizes and dates, or counts the files and bytes under a path |
|
||||
| `cp [-f] <from> <to>` / `mv [-f] <from> <to>` / `rm <path>` / `mkdir <path>` / `cancel` | What the Storage App does, with its rules: copy (folders too), move or rename, delete (a folder with what's in it), new folder. `-f` replaces a file that's in the way; a tab separates paths that hold spaces; `cancel` stops a copy or a delete |
|
||||
| `install <path>` | Update from SD with that `.ota` file, as Settings → Firmware does |
|
||||
| `update check` / `update list` / `update status` / `update install <tag>` | The project's releases on Gitea: look at the latest, list the last ten, say what's known, or download and install one (not on a Debug Build) |
|
||||
| `update pretend <version>` / `update probe <host>` / `update damage cut\|flip <n>` / `update daily` | Debug Builds: pretend to run another version (so a release counts as an update), see whether a server's certificate is accepted, cut or damage the next download, run the daily check again |
|
||||
| `lora probe` | Finds the radio: chip, oscillator, antenna switch, DIO1 interrupt, noise floor |
|
||||
| `lora status` | Radio settings, who's listening, packet and error counters, noise floor, task stack |
|
||||
| `lora rx on` / `lora rx off` | Listens and prints each packet on the console |
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@ RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends git build-essential \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
RUN pip install --no-cache-dir platformio
|
||||
RUN pip install --no-cache-dir platformio gcovr
|
||||
|
||||
# Toolchains and libraries are cached in a named volume mounted here.
|
||||
RUN mkdir -p /pio && chmod 777 /pio
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
# The device trusts the two ISRG roots for what it fetches
|
||||
|
||||
The firmware talks to the project's Gitea over HTTPS (issue #6, and #4 after it). A TLS client has to decide whose certificates it believes. Three ways were possible:
|
||||
|
||||
- **The framework's bundle**, about 130 certificate authorities (about 60 KB of flash). Any of them could vouch for `git.twis.la`.
|
||||
- **Pin the server's certificate**, as the Gemini App does for capsules. The server's certificate is replaced every few months, so a pin would ask the question again at every renewal.
|
||||
- **Carry the roots the server's chain ends in:** `ISRG Root X1` (RSA 4096) and `ISRG Root X2` (ECDSA P-384), the Let's Encrypt roots, about 2.7 KB of flash (`src/platform/ca_roots.h`).
|
||||
|
||||
We chose the third. The chain and the name are checked by mbedTLS during the handshake. It trusts one organisation's two roots, valid until 2035 and 2040, and a renewal changes nothing.
|
||||
|
||||
## What it costs
|
||||
|
||||
- **If the server moves to another CA, the device can no longer reach it**, and the next firmware, carrying that CA's root, has to come from the PC or the SD card. Both still work; they don't use TLS.
|
||||
- The roots are public data checked against the published fingerprints (listed in the file), refreshed by hand if Let's Encrypt ever changes them.
|
||||
|
||||
## What it doesn't change
|
||||
|
||||
The Update File's own signature (ADR 0003) is what decides what gets installed. A hijacked connection could hide a release, or serve an older signed one, but never make the device install firmware that isn't ours. The TLS check matters more for #4, where a token will travel over it.
|
||||
|
||||
## Measured while building it
|
||||
|
||||
A TLS connection to this server peaks at about 52 KB of heap, **the same whether the certificate is checked or not**, so skipping the check would have saved nothing. The cost is the connection itself (record buffers and handshake), not the trust decision.
|
||||
+86
-2
@@ -1,6 +1,6 @@
|
||||
# R1 — Releases
|
||||
|
||||
**Status:** in progress. CI and signed releases on Gitea (issue #5) are in place since 2026-10-06: every tag from v0.1.0 to v0.10.0 has its release. Next: updates from Gitea (#6), which waited for this, and the Issues App (#4).
|
||||
**Status:** in progress. CI and signed releases on Gitea (issue #5) are in place since 2026-10-06: every tag from v0.1.0 to v0.10.0 has its release. Updates from Gitea (issue #6) is built and checked on the device, on branch `gitea-updates`, not merged yet. The Issues App (#4) comes after.
|
||||
|
||||
**Goal:** a tag is a release, built the same way every time and published where a device can find it.
|
||||
|
||||
@@ -12,7 +12,7 @@ Until now the tests, the builds, the signing and the flashing all happened on on
|
||||
|
||||
| # | Decision |
|
||||
|---|---|
|
||||
| Q151 | Every push, to any branch: the host tests and both builds. A tag `v*`: the same, then a release. |
|
||||
| Q151 | A push to `main`: the host tests (with their coverage). A push to another branch: nothing, its pull request is what runs (a branch with an open pull request ran twice, once for each). A pull request: the same and both builds; changes reach `main` through pull requests. A tag `v*`: all of it, then a release. (First: everything on every push, which rebuilt the firmware far more often than anyone looked at it.) |
|
||||
| Q152 | **CI signs.** The signing key is the repository secret `OTA_SIGNING_KEY`; a tag push makes a complete, signed release with no manual step (ADR 0008). |
|
||||
| Q153 | The Debug Build is built in CI with a token of the runner's own, to prove it compiles, and **isn't published**: it would hand everyone its Debug Console token. |
|
||||
| Q154 | Pull requests from forks don't start a run. |
|
||||
@@ -22,6 +22,7 @@ Until now the tests, the builds, the signing and the flashing all happened on on
|
||||
| Q158 | Reproducible builds aren't needed for signing any more (Q152); not pursued here. |
|
||||
| Q159 | **The tags from before CI get their releases too**, v0.1.0 to v0.10.0, built from each tag's own sources by running the workflow by hand. |
|
||||
| Q160 | Actions is switched on for the repository. |
|
||||
| Q161 | **Changes reach `main` through pull requests, merged as "rebase, then a merge commit"**, the only style the repository allows: the branch's commits keep their messages, the merge commit marks the pull request, and what CI tested is what lands. No squash, no fast-forward. |
|
||||
|
||||
### As built
|
||||
|
||||
@@ -39,3 +40,86 @@ Until now the tests, the builds, the signing and the flashing all happened on on
|
||||
- **The runner's label took three tries.** Registered as `ubuntu://docker:ubuntu:resolute` and then as `ubuntu::docker://...`, Gitea took the whole string for the label's name; with the first, jobs ran on the runner's host itself. The first version of the workflow was written for that (plain shell, `docker run` for the build) and published v0.10.0 that way. `ubuntu:docker://docker.gitea.com/runner-images:ubuntu-latest` is the form that works.
|
||||
- **Gitea 1.27's API can't cancel a run that isn't finished**, only delete a finished one; switching Actions off and on for the repository doesn't either. Runs queued for a label that no longer exists stay queued until cancelled in the web UI.
|
||||
- **CI's image isn't byte-identical to a local build of the same tag** (same size, different bytes). Not pursued (Q158).
|
||||
|
||||
## Updates from Gitea (issue #6)
|
||||
|
||||
The device looks at the project's Gitea for a newer release, says so, and installs it on request, with the same signed Update Files, Probation and rollback as a push from the PC or an install from the card.
|
||||
|
||||
### What the server gives (checked 2026-10-06)
|
||||
|
||||
- **Its certificate** is Let's Encrypt, all ECDSA: leaf `git.twis.la` (renewed every few months, next expiry 2026-12-14) under the intermediate YE2, Root YE and ISRG Root X2, which X1 cross-signs. Pinning the leaf would ask a question at every renewal.
|
||||
- **The API** answers over HTTP/1.1, chunked: `releases/latest` is 3.2 KB (about 350 bytes of it matter), a list of ten releases is 33 KB.
|
||||
- **A download** is a direct 200 with `Content-Length` and no redirect; ranges work.
|
||||
|
||||
### Decisions (design round 2026-10-06)
|
||||
|
||||
| # | Decision |
|
||||
|---|---|
|
||||
| Q162 | **Trust:** the firmware carries ISRG Root X1 and X2 and checks the server's chain and name against them, not the framework's bundle of about 130 CAs (ADR 0009). Shared with #4. If the server moves to another CA, the next firmware comes from the PC. |
|
||||
| Q163 | The Update File's own signature stays the real guard. A hijacked connection could hide a release or offer an older signed one, never install firmware that isn't ours. |
|
||||
| Q164 | The source, `git.twis.la` and `twisla/roro9stack`, is a constant in the firmware. A fork changes it, and has its own key. |
|
||||
| Q165 | **When:** on request in Settings > Firmware, and once a day in the background while Wi-Fi is up and the Clock is set (certificate dates need it). A setting, **Check for updates**, on by default. It installs nothing by itself; it skips quietly below the memory floor and never runs during an install. |
|
||||
| Q166 | A Toast, "Update v0.11.0 available: see Settings > Firmware", once per version per boot. |
|
||||
| Q167 | **The download goes straight into the inactive slot,** no card needed. A truncated or tampered file is refused after 160 bytes or at its end, and the running firmware is untouched. A failed download starts over. |
|
||||
| Q168 | A version that failed (rolled back) isn't announced again by the background check until a newer one exists; it can still be installed by hand. |
|
||||
| Q169 | **Older releases:** a list of the last ten, newest first, the running one marked. Installing an older one asks with a stronger warning. |
|
||||
| Q170 | Enter on a release shows its version, date, size and the tag message, with Install. |
|
||||
| Q171 | **Debug Builds** check and show the latest release, but don't install it: it would replace the Debug Build and its console (Q153: Debug Builds aren't published). Their updates come from the PC. |
|
||||
| Q172 | **Memory, as measured:** a TLS connection peaks at about 52 KB of heap, with or without checking the certificate, so it starts with 80 KB free (Q86's 20 KB spare on top), not 55 KB. **A check, list or install someone asked for makes IRC step aside** and come back after; the daily check never does, and with IRC connected it waits. (First: 55 KB and nothing else. With IRC connected a check left 3 KB and a download 836 bytes.) |
|
||||
| Q173 | Left out, each with its issue: installing automatically (#52), a release channel (#53), resuming a download (#54). |
|
||||
| Q174 | Ships as **v0.11.0**. Tested on the device with the real signed releases; a Debug Build command pretends the device runs an older version, so v0.10.0 counts as an update. |
|
||||
|
||||
### Done when
|
||||
|
||||
- A check, by hand or daily, tells the right thing: up to date, newer available, no network, bad certificate, no clock, too little memory.
|
||||
- A newer release installs from the Firmware page with no card and no PC, and the device restarts into it and confirms it.
|
||||
- A tampered or truncated download is refused and the running firmware keeps running.
|
||||
- The Older releases list shows ten, and installing one asks first.
|
||||
- A release that rolled back isn't announced again.
|
||||
- A Debug Build shows the latest release and doesn't install it.
|
||||
- The daily check never runs below the memory floor, during an install, or without a clock.
|
||||
|
||||
### Work breakdown
|
||||
|
||||
1. **Model** (host-tested): a streaming JSON scanner, the release list read from it, HTTP response heads and chunked bodies, URLs, which release counts as an update.
|
||||
2. **The connection:** the root certificates, an HTTPS client, a check and a list from the Update Service's task; console commands to try them.
|
||||
3. **The download:** an HTTPS source for the existing install path.
|
||||
4. **The screens:** the Firmware page's release rows, the release page, Older releases, the setting, the daily check and its Toast.
|
||||
5. **Checks on the device**, recorded here.
|
||||
|
||||
### As built
|
||||
|
||||
- **`lib/release`** (host-tested): a streaming JSON scanner, the release reader built on it, HTTP heads and chunked bodies, URLs, and the decisions (which release is an update, whether to announce it, which download URLs are taken). A list of ten releases is 33 KB of JSON and costs a few hundred bytes of memory, because nothing is kept but the path.
|
||||
- **`HttpsGet`** (`src/platform`): one GET, the answer read as a stream, redirects not followed. **`GiteaReleases`** keeps the latest and the list. **The Update Service** serves the requests on its own task (about 5.4 KB of its 7 KB stack at the peak) and installs through the install path that already existed, with an HTTPS source in place of the card or the TCP port.
|
||||
- **The daily check** is scheduled from the Update Service's tick: Wi-Fi up, the Clock set, no Probation, nothing else going on, memory for a connection. The day it last succeeded is kept in flash.
|
||||
- **A version that failed** (rolled back) is remembered as `ota_failed`, and isn't announced again by the daily check.
|
||||
- **The screens:** the Firmware page's Latest release and Older releases rows, a release page with the tag's message, and the install dialog.
|
||||
- **Debug Builds** get knobs to try what can't be tried otherwise: `update pretend`, `probe`, `damage` and `daily`.
|
||||
- **The first message,** `... available: see Settings > Firmware`, was cut at 48 bytes by the notification's own limit; it now reads `v0.11.0 is out: see Settings > Firmware`.
|
||||
|
||||
### Checks on the device (2026-10-06, Debug Builds of branch `gitea-updates`)
|
||||
|
||||
| Check | Result |
|
||||
|---|---|
|
||||
| Host tests | 456 pass |
|
||||
| Check and list against the live server | The certificate is accepted against the two embedded roots; `releases/latest` read; a list of ten (33 KB) streamed |
|
||||
| Servers that must be refused | github.com, example.com, expired.badssl.com, self-signed.badssl.com, wrong.host.badssl.com, untrusted-root.badssl.com and the router: each "isn't accepted" or a TLS error |
|
||||
| A download cut short at 800,000 bytes | Refused, "update file too short"; the running firmware untouched |
|
||||
| One byte flipped in the signature | Refused after 160 bytes, "bad signature"; the image isn't read further |
|
||||
| One byte flipped in the image | Downloaded in full, refused at its end, "image corrupted (hash mismatch)" |
|
||||
| The real v0.10.0, from the console and then from the screen | Downloaded, restarted, confirmed on Probation: the slot table read `v0.10.0, valid` both times. The Debug Build was pushed back from the PC after each |
|
||||
| The screens | Latest release (checking, then `(current)` or `(new)`), the release page with the tag's message, Older releases with ten rows, the install dialog (Cancel by default, Back cancels), the progress screen at 28% |
|
||||
| IRC connected, before the hold | A check left 3 KB of heap; a full download, 836 bytes |
|
||||
| IRC connected, with the hold | The lowest free heap during a full download: 38 KB. IRC reconnected afterwards (its counters kept growing) |
|
||||
| The daily check | It ran by itself, announced `v0.10.0 is out: see Settings > Firmware` once; with IRC connected (68 KB free) it didn't run |
|
||||
| Speed | 1.9 MB in about 46 s, 40 KB/s, over the guest Wi-Fi at -65 dBm; not investigated further |
|
||||
|
||||
**Not checked:** the certificate's **name** on its own. Connecting by IP makes the server end the handshake before it shows its certificate, so that test proved nothing; the library sets the name it verifies, and OpenSSL on the PC refused the wrong name against the same chain. A failed daily check retrying, the clock not being set, the release that failed before not being announced (host-tested, not on the device), and the hold when IRC isn't connected but Gemini holds memory.
|
||||
|
||||
**Limits worth knowing:**
|
||||
- **With IRC connected for days, the daily check doesn't run.** It would have to take IRC down to make room. Opening Latest release does.
|
||||
- **A server that changes CA can't be reached** until a firmware carrying the new root comes from the PC (ADR 0009).
|
||||
- **No resuming:** a broken download starts over (#54).
|
||||
- **A key press during the hold:** Back on the Firmware page while a check is going doesn't cancel it.
|
||||
|
||||
**Two slips during the checks:** a blind sequence of keys on the Firmware page opened the SD card's install dialog (the page keeps its selection between visits); it was cancelled with Back, nothing installed. And my port-polling while waiting for a restart took the Debug Console's only client slot, which made the first install attempt look like a failure.
|
||||
|
||||
@@ -23,7 +23,7 @@ const RowDef kRows[] = {
|
||||
{Row::Gnss, Kind::Toggle, "GNSS"}, {Row::GnssQuiet, Kind::Toggle, "Pause GNSS for LoRa"},
|
||||
{Row::Coordinates, Kind::Toggle, "Coordinates"},
|
||||
{Row::ProbeMacs, Kind::Toggle, "Probe MACs"}, {Row::Wifi, Kind::Page, "Wi-Fi"},
|
||||
{Row::Firmware, Kind::Page, "Firmware"},
|
||||
{Row::CheckUpdates, Kind::Toggle, "Check for updates"}, {Row::Firmware, Kind::Page, "Firmware"},
|
||||
{Row::About, Kind::Page, "About"},
|
||||
};
|
||||
|
||||
@@ -82,6 +82,7 @@ std::string SettingsMenu::value(int i) const {
|
||||
case Row::Sound: return settings_.getBool(Setting::Sound) ? "On" : "Off";
|
||||
case Row::Gnss: return settings_.getBool(Setting::GnssEnabled) ? "On" : "Off";
|
||||
case Row::GnssQuiet: return settings_.getBool(Setting::GnssQuietForLora) ? "On" : "Off";
|
||||
case Row::CheckUpdates: return settings_.getBool(Setting::CheckUpdates) ? "Daily" : "Off";
|
||||
case Row::Coordinates: return settings_.getBool(Setting::CoordinatesDms) ? "Deg min sec" : "Decimal";
|
||||
case Row::ProbeMacs: return settings_.getBool(Setting::ProbeMacRaw) ? "Raw" : "Pseudonymised";
|
||||
case Row::Wifi: return settings_.getBool(Setting::WifiEnabled) ? "On" : "Off";
|
||||
@@ -128,6 +129,7 @@ void SettingsMenu::toggle(int i) {
|
||||
if (row(i) == Row::Sound) settings_.setBool(Setting::Sound, !settings_.getBool(Setting::Sound));
|
||||
if (row(i) == Row::Gnss) settings_.setBool(Setting::GnssEnabled, !settings_.getBool(Setting::GnssEnabled));
|
||||
if (row(i) == Row::GnssQuiet) settings_.setBool(Setting::GnssQuietForLora, !settings_.getBool(Setting::GnssQuietForLora));
|
||||
if (row(i) == Row::CheckUpdates) settings_.setBool(Setting::CheckUpdates, !settings_.getBool(Setting::CheckUpdates));
|
||||
if (row(i) == Row::Coordinates) settings_.setBool(Setting::CoordinatesDms, !settings_.getBool(Setting::CoordinatesDms));
|
||||
if (row(i) == Row::ProbeMacs) settings_.setBool(Setting::ProbeMacRaw, !settings_.getBool(Setting::ProbeMacRaw));
|
||||
}
|
||||
|
||||
@@ -11,7 +11,7 @@ namespace roro {
|
||||
// values, choice lists and validation messages. Rendering and navigation live in the App.
|
||||
class SettingsMenu {
|
||||
public:
|
||||
enum class Row { LongName, ShortName, Region, Timezone, Brightness, DimTimeout, OffTimeout, Sound, Gnss, GnssQuiet, Coordinates, ProbeMacs, Wifi, Firmware, About };
|
||||
enum class Row { LongName, ShortName, Region, Timezone, Brightness, DimTimeout, OffTimeout, Sound, Gnss, GnssQuiet, Coordinates, ProbeMacs, Wifi, CheckUpdates, Firmware, About };
|
||||
enum class Kind { Text, Choice, Toggle, Slider, Page };
|
||||
|
||||
explicit SettingsMenu(Settings& settings) : settings_(settings) {}
|
||||
|
||||
@@ -0,0 +1,158 @@
|
||||
#include "http_head.h"
|
||||
|
||||
#include <algorithm>
|
||||
#include <cctype>
|
||||
#include <cstdlib>
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
namespace {
|
||||
std::string lower(std::string s) {
|
||||
for (char& c : s) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
|
||||
return s;
|
||||
}
|
||||
} // namespace
|
||||
|
||||
size_t HttpHeadParser::feed(const char* data, size_t len) {
|
||||
size_t used = 0;
|
||||
while (used < len && !complete_ && !failed_) {
|
||||
char c = data[used++];
|
||||
total_++;
|
||||
if (total_ > kMaxBytes) {
|
||||
failed_ = true;
|
||||
break;
|
||||
}
|
||||
if (c == '\n') {
|
||||
if (!line_.empty() && line_.back() == '\r') line_.pop_back();
|
||||
line();
|
||||
line_.clear();
|
||||
} else {
|
||||
line_ += c;
|
||||
}
|
||||
}
|
||||
return used;
|
||||
}
|
||||
|
||||
void HttpHeadParser::line() {
|
||||
if (first_) { // "HTTP/1.1 200 OK"
|
||||
first_ = false;
|
||||
if (line_.compare(0, 5, "HTTP/") != 0) {
|
||||
failed_ = true;
|
||||
return;
|
||||
}
|
||||
size_t space = line_.find(' ');
|
||||
head_.status = space == std::string::npos ? 0 : std::atoi(line_.c_str() + space + 1);
|
||||
if (head_.status < 100 || head_.status > 599) failed_ = true;
|
||||
return;
|
||||
}
|
||||
if (line_.empty()) {
|
||||
complete_ = true;
|
||||
return;
|
||||
}
|
||||
size_t colon = line_.find(':');
|
||||
if (colon == std::string::npos) return; // not a header: ignored
|
||||
std::string name = lower(line_.substr(0, colon));
|
||||
size_t from = line_.find_first_not_of(" \t", colon + 1);
|
||||
std::string value = from == std::string::npos ? "" : line_.substr(from);
|
||||
if (name == "content-length") head_.contentLength = std::atol(value.c_str());
|
||||
else if (name == "transfer-encoding") head_.chunked = lower(value).find("chunked") != std::string::npos;
|
||||
else if (name == "location") head_.location = value;
|
||||
else if (name == "content-type") head_.contentType = value;
|
||||
}
|
||||
|
||||
size_t ChunkedDecoder::decode(const uint8_t* in, size_t len, uint8_t* out) {
|
||||
size_t written = 0;
|
||||
for (size_t i = 0; i < len && !failed_ && state_ != State::Done; i++) {
|
||||
uint8_t c = in[i];
|
||||
switch (state_) {
|
||||
case State::Size: {
|
||||
int digit = c >= '0' && c <= '9' ? c - '0' : c >= 'a' && c <= 'f' ? c - 'a' + 10 : c >= 'A' && c <= 'F' ? c - 'A' + 10 : -1;
|
||||
if (digit >= 0) {
|
||||
if (remaining_ > (SIZE_MAX >> 5)) failed_ = true;
|
||||
remaining_ = remaining_ * 16 + digit;
|
||||
anyDigit_ = true;
|
||||
} else if (c == ';' && anyDigit_) {
|
||||
state_ = State::Extension;
|
||||
} else if (c == '\r' && anyDigit_) {
|
||||
state_ = State::SizeLf;
|
||||
} else {
|
||||
failed_ = true;
|
||||
}
|
||||
break;
|
||||
}
|
||||
case State::Extension:
|
||||
if (c == '\r') state_ = State::SizeLf;
|
||||
break;
|
||||
case State::SizeLf:
|
||||
if (c != '\n') {
|
||||
failed_ = true;
|
||||
} else if (remaining_ == 0) {
|
||||
state_ = State::Trailer;
|
||||
trailerLine_ = 0;
|
||||
} else {
|
||||
state_ = State::Data;
|
||||
}
|
||||
break;
|
||||
case State::Data: {
|
||||
size_t take = std::min(remaining_, len - i);
|
||||
for (size_t k = 0; k < take; k++) out[written + k] = in[i + k];
|
||||
written += take;
|
||||
remaining_ -= take;
|
||||
i += take - 1;
|
||||
if (remaining_ == 0) state_ = State::DataCr;
|
||||
break;
|
||||
}
|
||||
case State::DataCr:
|
||||
if (c != '\r') failed_ = true;
|
||||
else state_ = State::DataLf;
|
||||
break;
|
||||
case State::DataLf:
|
||||
if (c != '\n') {
|
||||
failed_ = true;
|
||||
} else {
|
||||
state_ = State::Size;
|
||||
anyDigit_ = false;
|
||||
}
|
||||
break;
|
||||
case State::Trailer: // header lines after the last chunk, until an empty one
|
||||
if (c == '\n') {
|
||||
if (trailerLine_ == 0) state_ = State::Done;
|
||||
trailerLine_ = 0;
|
||||
} else if (c != '\r') {
|
||||
trailerLine_++;
|
||||
}
|
||||
break;
|
||||
case State::Done: break;
|
||||
}
|
||||
}
|
||||
return written;
|
||||
}
|
||||
|
||||
Url parseUrl(const std::string& url) {
|
||||
Url u;
|
||||
size_t scheme = url.find("://");
|
||||
if (scheme == std::string::npos) return u;
|
||||
std::string s = lower(url.substr(0, scheme));
|
||||
if (s != "http" && s != "https") return u;
|
||||
u.https = s == "https";
|
||||
size_t hostStart = scheme + 3, pathStart = url.find('/', hostStart);
|
||||
std::string authority = url.substr(hostStart, pathStart == std::string::npos ? std::string::npos : pathStart - hostStart);
|
||||
u.path = pathStart == std::string::npos ? "/" : url.substr(pathStart);
|
||||
if (authority.empty() || authority.find('@') != std::string::npos) return u; // no credentials in a URL
|
||||
size_t colon = authority.rfind(':');
|
||||
u.port = u.https ? 443 : 80;
|
||||
if (colon != std::string::npos) {
|
||||
u.port = std::atoi(authority.c_str() + colon + 1);
|
||||
authority.resize(colon);
|
||||
if (u.port <= 0 || u.port > 65535) return u;
|
||||
}
|
||||
for (unsigned char c : authority)
|
||||
if (!(std::isalnum(c) || c == '.' || c == '-')) return u;
|
||||
for (unsigned char c : u.path)
|
||||
if (c <= ' ' || c == 0x7F) return u;
|
||||
u.host = lower(authority);
|
||||
u.ok = !u.host.empty();
|
||||
return u;
|
||||
}
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,62 @@
|
||||
#pragma once
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
// The status line and headers of an HTTP/1.1 response, read as bytes arrive.
|
||||
struct HttpHead {
|
||||
int status = 0;
|
||||
long contentLength = -1; // -1: not given
|
||||
bool chunked = false;
|
||||
std::string location, contentType;
|
||||
};
|
||||
|
||||
class HttpHeadParser {
|
||||
public:
|
||||
static constexpr size_t kMaxBytes = 4096;
|
||||
|
||||
// Takes bytes up to and including the blank line that ends the head; returns how many it used.
|
||||
// What follows is the body.
|
||||
size_t feed(const char* data, size_t len);
|
||||
bool complete() const { return complete_; }
|
||||
bool failed() const { return failed_; }
|
||||
const HttpHead& head() const { return head_; }
|
||||
|
||||
private:
|
||||
void line();
|
||||
|
||||
HttpHead head_;
|
||||
std::string line_;
|
||||
size_t total_ = 0;
|
||||
bool first_ = true, complete_ = false, failed_ = false;
|
||||
};
|
||||
|
||||
// Takes the chunks of "Transfer-Encoding: chunked" apart as they arrive.
|
||||
class ChunkedDecoder {
|
||||
public:
|
||||
// `out` has room for `len` bytes (the body is never longer than what carried it).
|
||||
size_t decode(const uint8_t* in, size_t len, uint8_t* out);
|
||||
bool done() const { return state_ == State::Done; }
|
||||
bool failed() const { return failed_; }
|
||||
|
||||
private:
|
||||
enum class State : uint8_t { Size, Extension, SizeLf, Data, DataCr, DataLf, Trailer, Done };
|
||||
State state_ = State::Size;
|
||||
size_t remaining_ = 0;
|
||||
bool anyDigit_ = false, failed_ = false;
|
||||
size_t trailerLine_ = 0;
|
||||
};
|
||||
|
||||
// "https://git.twis.la/twisla/x/releases/download/v1/a.ota" taken apart. Only http and https.
|
||||
struct Url {
|
||||
bool ok = false;
|
||||
bool https = false;
|
||||
std::string host, path; // path from the first "/", with its query; "/" if none
|
||||
int port = 0;
|
||||
};
|
||||
Url parseUrl(const std::string& url);
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,202 @@
|
||||
#include "json_scan.h"
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
namespace {
|
||||
bool space(char c) { return c == ' ' || c == '\t' || c == '\r' || c == '\n'; }
|
||||
bool continuation(char c) { return (static_cast<uint8_t>(c) & 0xC0) == 0x80; }
|
||||
} // namespace
|
||||
|
||||
void JsonScanner::feed(const char* data, size_t len) {
|
||||
for (size_t i = 0; i < len && !failed_; i++) step(data[i]);
|
||||
}
|
||||
|
||||
std::string JsonScanner::path() const {
|
||||
std::string p;
|
||||
for (const Frame& f : stack_) {
|
||||
if (f.isObject) {
|
||||
if (!p.empty()) p += '.';
|
||||
p += f.key;
|
||||
} else {
|
||||
p += '[' + std::to_string(f.index) + ']';
|
||||
}
|
||||
}
|
||||
return p;
|
||||
}
|
||||
|
||||
void JsonScanner::append(const char* bytes, size_t n) {
|
||||
if (text_.size() + n > max_) {
|
||||
truncated_ = true;
|
||||
return;
|
||||
}
|
||||
text_.append(bytes, n);
|
||||
}
|
||||
|
||||
void JsonScanner::appendCodePoint(uint32_t cp) {
|
||||
char b[4];
|
||||
size_t n;
|
||||
if (cp < 0x80) {
|
||||
b[0] = static_cast<char>(cp);
|
||||
n = 1;
|
||||
} else if (cp < 0x800) {
|
||||
b[0] = static_cast<char>(0xC0 | (cp >> 6));
|
||||
b[1] = static_cast<char>(0x80 | (cp & 0x3F));
|
||||
n = 2;
|
||||
} else if (cp < 0x10000) {
|
||||
b[0] = static_cast<char>(0xE0 | (cp >> 12));
|
||||
b[1] = static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
|
||||
b[2] = static_cast<char>(0x80 | (cp & 0x3F));
|
||||
n = 3;
|
||||
} else {
|
||||
b[0] = static_cast<char>(0xF0 | (cp >> 18));
|
||||
b[1] = static_cast<char>(0x80 | ((cp >> 12) & 0x3F));
|
||||
b[2] = static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
|
||||
b[3] = static_cast<char>(0x80 | (cp & 0x3F));
|
||||
n = 4;
|
||||
}
|
||||
append(b, n);
|
||||
}
|
||||
|
||||
void JsonScanner::startString(bool key) {
|
||||
inString_ = true;
|
||||
isKey_ = key;
|
||||
escape_ = false;
|
||||
unicodeLeft_ = 0;
|
||||
highSurrogate_ = 0;
|
||||
truncated_ = false;
|
||||
text_.clear();
|
||||
}
|
||||
|
||||
void JsonScanner::stringChar(char c) {
|
||||
if (unicodeLeft_ > 0) {
|
||||
int digit = c >= '0' && c <= '9' ? c - '0' : c >= 'a' && c <= 'f' ? c - 'a' + 10 : c >= 'A' && c <= 'F' ? c - 'A' + 10 : -1;
|
||||
if (digit < 0) return fail();
|
||||
unicode_ = unicode_ * 16 + digit;
|
||||
if (--unicodeLeft_ == 0) {
|
||||
if (unicode_ >= 0xD800 && unicode_ < 0xDC00) {
|
||||
highSurrogate_ = unicode_; // the low half comes next
|
||||
} else if (unicode_ >= 0xDC00 && unicode_ < 0xE000 && highSurrogate_) {
|
||||
appendCodePoint(0x10000 + ((highSurrogate_ - 0xD800) << 10) + (unicode_ - 0xDC00));
|
||||
highSurrogate_ = 0;
|
||||
} else {
|
||||
appendCodePoint(unicode_);
|
||||
highSurrogate_ = 0;
|
||||
}
|
||||
}
|
||||
return;
|
||||
}
|
||||
if (escape_) {
|
||||
escape_ = false;
|
||||
switch (c) {
|
||||
case 'n': append("\n", 1); break;
|
||||
case 't': append("\t", 1); break;
|
||||
case 'r': append("\r", 1); break;
|
||||
case 'b': append("\b", 1); break;
|
||||
case 'f': append("\f", 1); break;
|
||||
case 'u': unicodeLeft_ = 4; unicode_ = 0; break;
|
||||
default: append(&c, 1); break; // \" \\ \/
|
||||
}
|
||||
return;
|
||||
}
|
||||
if (c == '\\') {
|
||||
escape_ = true;
|
||||
} else if (c == '"') {
|
||||
endString();
|
||||
} else {
|
||||
append(&c, 1);
|
||||
}
|
||||
}
|
||||
|
||||
void JsonScanner::endString() {
|
||||
inString_ = false;
|
||||
// A cut can leave half a character at the end.
|
||||
while (truncated_ && !text_.empty()) {
|
||||
size_t k = text_.size();
|
||||
while (k > 0 && continuation(text_[k - 1])) k--;
|
||||
if (k == 0) break;
|
||||
uint8_t lead = static_cast<uint8_t>(text_[k - 1]);
|
||||
size_t want = lead >= 0xF0 ? 4 : lead >= 0xE0 ? 3 : lead >= 0xC0 ? 2 : 1;
|
||||
if (text_.size() - (k - 1) < want) text_.resize(k - 1);
|
||||
break;
|
||||
}
|
||||
if (isKey_) {
|
||||
stack_.back().key = text_;
|
||||
expect_ = Expect::Colon;
|
||||
return;
|
||||
}
|
||||
sink_(path(), text_, true, truncated_);
|
||||
valueDone();
|
||||
}
|
||||
|
||||
void JsonScanner::endLiteral() {
|
||||
inLiteral_ = false;
|
||||
sink_(path(), text_, false, false);
|
||||
valueDone();
|
||||
}
|
||||
|
||||
void JsonScanner::valueDone() {
|
||||
if (stack_.empty()) {
|
||||
done_ = true;
|
||||
return;
|
||||
}
|
||||
expect_ = Expect::CommaOrEnd;
|
||||
}
|
||||
|
||||
void JsonScanner::step(char c) {
|
||||
if (inString_) return stringChar(c);
|
||||
if (inLiteral_) {
|
||||
if (space(c) || c == ',' || c == '}' || c == ']') {
|
||||
endLiteral(); // and the character that ended it is read again below
|
||||
} else {
|
||||
if (text_.size() < max_) text_ += c;
|
||||
return;
|
||||
}
|
||||
}
|
||||
if (space(c)) return;
|
||||
switch (expect_) {
|
||||
case Expect::Value:
|
||||
if (c == '{') {
|
||||
stack_.push_back({true, "", 0});
|
||||
expect_ = Expect::KeyOrEnd;
|
||||
} else if (c == '[') {
|
||||
stack_.push_back({false, "", 0});
|
||||
expect_ = Expect::Value;
|
||||
} else if (c == ']' && !stack_.empty() && !stack_.back().isObject && stack_.back().index == 0) {
|
||||
stack_.pop_back(); // an empty array
|
||||
valueDone();
|
||||
} else if (c == '"') {
|
||||
startString(false);
|
||||
} else if (c == '-' || (c >= '0' && c <= '9') || c == 't' || c == 'f' || c == 'n') {
|
||||
inLiteral_ = true;
|
||||
text_.assign(1, c);
|
||||
} else {
|
||||
fail();
|
||||
}
|
||||
return;
|
||||
case Expect::KeyOrEnd:
|
||||
if (c == '"') startString(true);
|
||||
else if (c == '}') {
|
||||
stack_.pop_back();
|
||||
valueDone();
|
||||
} else fail();
|
||||
return;
|
||||
case Expect::Colon:
|
||||
if (c == ':') expect_ = Expect::Value;
|
||||
else fail();
|
||||
return;
|
||||
case Expect::CommaOrEnd:
|
||||
if (c == ',') {
|
||||
if (stack_.back().isObject) expect_ = Expect::KeyOrEnd;
|
||||
else {
|
||||
stack_.back().index++;
|
||||
expect_ = Expect::Value;
|
||||
}
|
||||
} else if ((c == '}' && stack_.back().isObject) || (c == ']' && !stack_.back().isObject)) {
|
||||
stack_.pop_back();
|
||||
valueDone();
|
||||
} else fail();
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,57 @@
|
||||
#pragma once
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <functional>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
// Reads JSON as it arrives, a chunk at a time, and reports each plain value (a string, a number,
|
||||
// true, false, null) with where it was found: "tag_name", "assets[1].name", "[2].draft". Nothing
|
||||
// is kept but the path, so a 33 KB list of releases costs a few hundred bytes. A value longer than
|
||||
// `maxValueBytes` is cut (never in the middle of a character) and reported as truncated.
|
||||
// Meant for a server's answer, not for validating JSON: it only refuses what it can't follow.
|
||||
class JsonScanner {
|
||||
public:
|
||||
using Sink = std::function<void(const std::string& path, const std::string& value, bool isString, bool truncated)>;
|
||||
|
||||
explicit JsonScanner(Sink sink, size_t maxValueBytes = 300) : sink_(std::move(sink)), max_(maxValueBytes) {}
|
||||
|
||||
void feed(const char* data, size_t len);
|
||||
bool failed() const { return failed_; }
|
||||
bool done() const { return done_ && !failed_; } // the top-level value is complete
|
||||
|
||||
private:
|
||||
enum class Expect : uint8_t { Value, KeyOrEnd, Colon, CommaOrEnd };
|
||||
struct Frame {
|
||||
bool isObject;
|
||||
std::string key;
|
||||
int index;
|
||||
};
|
||||
|
||||
void step(char c);
|
||||
void startString(bool key);
|
||||
void stringChar(char c);
|
||||
void appendCodePoint(uint32_t cp);
|
||||
void endString();
|
||||
void endLiteral();
|
||||
void valueDone();
|
||||
void append(const char* bytes, size_t n);
|
||||
std::string path() const;
|
||||
void fail() { failed_ = true; }
|
||||
|
||||
Sink sink_;
|
||||
size_t max_;
|
||||
std::vector<Frame> stack_;
|
||||
Expect expect_ = Expect::Value;
|
||||
bool inString_ = false, isKey_ = false, escape_ = false, inLiteral_ = false;
|
||||
int unicodeLeft_ = 0;
|
||||
uint32_t unicode_ = 0, highSurrogate_ = 0;
|
||||
bool truncated_ = false;
|
||||
std::string text_;
|
||||
bool failed_ = false, done_ = false;
|
||||
};
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,80 @@
|
||||
#include "release_info.h"
|
||||
|
||||
#include <cstdlib>
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
namespace {
|
||||
bool endsWith(const std::string& s, const char* tail) {
|
||||
size_t n = std::char_traits<char>::length(tail);
|
||||
return s.size() >= n && s.compare(s.size() - n, n, tail) == 0;
|
||||
}
|
||||
} // namespace
|
||||
|
||||
std::string firstParagraph(const std::string& text, bool truncated) {
|
||||
size_t end = text.find("\n\n");
|
||||
size_t crlf = text.find("\r\n\r\n");
|
||||
if (crlf != std::string::npos && (end == std::string::npos || crlf < end)) end = crlf;
|
||||
std::string p = text.substr(0, end);
|
||||
size_t first = p.find_first_not_of(" \t\r\n");
|
||||
if (first == std::string::npos) return "";
|
||||
p.erase(0, first);
|
||||
while (!p.empty() && (p.back() == ' ' || p.back() == '\t' || p.back() == '\r' || p.back() == '\n')) p.pop_back();
|
||||
if (truncated && end == std::string::npos) p += "...";
|
||||
return p;
|
||||
}
|
||||
|
||||
ReleaseReader::ReleaseReader(size_t maxReleases)
|
||||
: scanner_([this](const std::string& path, const std::string& text, bool isString, bool truncated) {
|
||||
value(path, text, isString, truncated);
|
||||
}),
|
||||
max_(maxReleases) {}
|
||||
|
||||
void ReleaseReader::end() { flushAsset(); }
|
||||
|
||||
void ReleaseReader::flushAsset() {
|
||||
if (assetRelease_ >= 0 && assetRelease_ < static_cast<int>(releases_.size()) && endsWith(assetName_, ".ota") && !assetUrl_.empty()) {
|
||||
releases_[assetRelease_].otaUrl = assetUrl_;
|
||||
releases_[assetRelease_].otaSize = assetSize_;
|
||||
}
|
||||
assetRelease_ = assetIndex_ = -1;
|
||||
assetName_.clear();
|
||||
assetUrl_.clear();
|
||||
assetSize_ = 0;
|
||||
}
|
||||
|
||||
void ReleaseReader::value(const std::string& path, const std::string& text, bool isString, bool truncated) {
|
||||
size_t index = 0;
|
||||
std::string rest = path;
|
||||
if (!path.empty() && path[0] == '[') { // a list: "[2].tag_name"
|
||||
char* end;
|
||||
index = static_cast<size_t>(std::strtol(path.c_str() + 1, &end, 10));
|
||||
rest = *end == ']' ? std::string(end + 1) : "";
|
||||
if (!rest.empty() && rest[0] == '.') rest.erase(0, 1);
|
||||
}
|
||||
if (index >= max_) return;
|
||||
if (releases_.size() <= index) releases_.resize(index + 1);
|
||||
Release& r = releases_[index];
|
||||
|
||||
if (rest == "tag_name") r.tag = text;
|
||||
else if (rest == "published_at") r.published = text;
|
||||
else if (rest == "body") r.notes = firstParagraph(text, truncated);
|
||||
else if (rest == "draft") r.draft = text == "true";
|
||||
else if (rest == "prerelease") r.prerelease = text == "true";
|
||||
else if (rest.compare(0, 7, "assets[") == 0) {
|
||||
char* end;
|
||||
int j = static_cast<int>(std::strtol(rest.c_str() + 7, &end, 10));
|
||||
if (static_cast<int>(index) != assetRelease_ || j != assetIndex_) {
|
||||
flushAsset();
|
||||
assetRelease_ = static_cast<int>(index);
|
||||
assetIndex_ = j;
|
||||
}
|
||||
std::string field = *end == ']' && end[1] == '.' ? std::string(end + 2) : "";
|
||||
if (field == "name") assetName_ = text;
|
||||
else if (field == "size") assetSize_ = static_cast<uint32_t>(std::strtoul(text.c_str(), nullptr, 10));
|
||||
else if (field == "browser_download_url") assetUrl_ = text;
|
||||
}
|
||||
(void)isString;
|
||||
}
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,52 @@
|
||||
#pragma once
|
||||
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
#include "json_scan.h"
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
// What the device needs to know about one Gitea release (docs/milestones/R1.md, #6).
|
||||
struct Release {
|
||||
std::string tag; // "v0.10.0"
|
||||
std::string published; // "2026-10-06T08:11:31Z"
|
||||
std::string notes; // the first paragraph of the text: the tag's message
|
||||
std::string otaUrl; // where the signed Update File is
|
||||
uint32_t otaSize = 0;
|
||||
bool draft = false, prerelease = false;
|
||||
|
||||
// Something that can be installed and that the project meant to publish (drafts and
|
||||
// pre-releases are left out for now: a release channel is #53).
|
||||
bool usable() const { return !draft && !prerelease && !tag.empty() && !otaUrl.empty(); }
|
||||
std::string date() const { return published.substr(0, 10); } // "2026-10-06"
|
||||
};
|
||||
|
||||
// Reads Gitea's answer as it arrives: `releases/latest` (one object) or `releases?limit=N` (a list).
|
||||
class ReleaseReader {
|
||||
public:
|
||||
explicit ReleaseReader(size_t maxReleases = 10);
|
||||
|
||||
void feed(const char* data, size_t len) { scanner_.feed(data, len); }
|
||||
void end(); // after the last chunk
|
||||
bool ok() const { return !scanner_.failed(); }
|
||||
bool complete() const { return scanner_.done(); }
|
||||
const std::vector<Release>& releases() const { return releases_; }
|
||||
|
||||
private:
|
||||
void value(const std::string& path, const std::string& text, bool isString, bool truncated);
|
||||
void flushAsset();
|
||||
|
||||
JsonScanner scanner_;
|
||||
size_t max_;
|
||||
std::vector<Release> releases_;
|
||||
int assetRelease_ = -1, assetIndex_ = -1;
|
||||
std::string assetName_, assetUrl_;
|
||||
uint32_t assetSize_ = 0;
|
||||
};
|
||||
|
||||
// The first paragraph of a release's text, trimmed; "..." if the text was cut before it ended.
|
||||
std::string firstParagraph(const std::string& text, bool truncated);
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,15 @@
|
||||
#include "update_check.h"
|
||||
|
||||
#include "http_head.h"
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
bool trustedAssetUrl(const std::string& url, const std::string& host, const std::string& repo) {
|
||||
Url u = parseUrl(url);
|
||||
if (!u.ok || !u.https || u.port != 443 || u.host != host) return false;
|
||||
std::string prefix = "/" + repo + "/releases/download/";
|
||||
return u.path.compare(0, prefix.size(), prefix) == 0 && u.path.find("..") == std::string::npos &&
|
||||
u.path.find('?') == std::string::npos && u.path.find('#') == std::string::npos;
|
||||
}
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -0,0 +1,38 @@
|
||||
#pragma once
|
||||
|
||||
#include <string>
|
||||
|
||||
#include "release_info.h"
|
||||
#include "version_compare.h"
|
||||
|
||||
namespace roro::release {
|
||||
|
||||
// Where the project's releases are (Q164). A fork changes these, and its own signing key.
|
||||
constexpr const char* kGiteaHost = "git.twis.la";
|
||||
constexpr const char* kGiteaRepo = "twisla/roro9stack";
|
||||
|
||||
inline bool versionNewer(const std::string& a, const std::string& b) { return versionOlder(b, a); }
|
||||
|
||||
// "v0.10.0+debug": the Debug Build says so wherever the version shows (scripts/version.py).
|
||||
inline bool isDebugBuild(const std::string& version) {
|
||||
static const std::string tail = "+debug";
|
||||
return version.size() >= tail.size() && version.compare(version.size() - tail.size(), tail.size(), tail) == 0;
|
||||
}
|
||||
|
||||
// Is `release` a newer one than what runs?
|
||||
inline bool isNewer(const Release& release, const std::string& running) {
|
||||
return release.usable() && versionNewer(release.tag, running);
|
||||
}
|
||||
|
||||
// Should the background check say so (Q166, Q168)? Not for a version that failed on this device
|
||||
// before (it rolled back), and not twice for the same one.
|
||||
inline bool shouldAnnounce(const Release& latest, const std::string& running, const std::string& failed, const std::string& announced) {
|
||||
return isNewer(latest, running) && latest.tag != failed && latest.tag != announced;
|
||||
}
|
||||
|
||||
// Is `url` a download this device takes from the project's server, for this repository? Whatever
|
||||
// the API says, the device only fetches from where it asked (a redirected or rewritten answer
|
||||
// can't send it elsewhere).
|
||||
bool trustedAssetUrl(const std::string& url, const std::string& host = kGiteaHost, const std::string& repo = kGiteaRepo);
|
||||
|
||||
} // namespace roro::release
|
||||
@@ -40,6 +40,7 @@ const Definition kDefinitions[] = {
|
||||
{"ntp1", Kind::String, 0, "pool.ntp.org", 1, 63},
|
||||
{"ntp2", Kind::String, 0, "time.cloudflare.com", 0, 63},
|
||||
{"gnss_quiet", Kind::Bool, 0, nullptr, 0, 1}, // off: GNSS stays on, as decided in M2 (Q58)
|
||||
{"check_updates", Kind::Bool, 1, nullptr, 0, 1}, // on: it only looks, and says so (R1, Q165)
|
||||
};
|
||||
static_assert(sizeof(kDefinitions) / sizeof(kDefinitions[0]) == static_cast<size_t>(Setting::Count),
|
||||
"every Setting needs a definition");
|
||||
|
||||
@@ -30,6 +30,7 @@ enum class Setting : uint8_t {
|
||||
Ntp1, // string: the first NTP server, a host name or an IPv4 address (S1, Q110)
|
||||
Ntp2, // string: the second, or empty
|
||||
GnssQuietForLora, // bool: put the GNSS receiver in standby while the LoRa radio listens (issue #20)
|
||||
CheckUpdates, // bool: look for a newer release on Gitea once a day (R1, Q165)
|
||||
Count
|
||||
};
|
||||
|
||||
|
||||
@@ -46,3 +46,14 @@ build_flags =
|
||||
platform = native
|
||||
lib_ldf_mode = deep+
|
||||
build_flags = -std=gnu++17
|
||||
|
||||
; The same tests, built to count which lines of lib/ they run (scripts/coverage.sh).
|
||||
[env:native-coverage]
|
||||
extends = env:native
|
||||
build_flags =
|
||||
${env:native.build_flags}
|
||||
--coverage
|
||||
-O0
|
||||
extra_scripts =
|
||||
${env.extra_scripts}
|
||||
pre:scripts/coverage_link.py
|
||||
|
||||
+8
-1
@@ -1,7 +1,14 @@
|
||||
#!/usr/bin/env bash
|
||||
# Local CI: run host unit tests, then build the firmware.
|
||||
# Usage: scripts/ci.sh [tests|builds] one half only; both by default
|
||||
set -euo pipefail
|
||||
source "$(dirname "$0")/_docker.sh"
|
||||
DOCKER_EXTRA=()
|
||||
|
||||
run_in_container bash -c 'git config --global --add safe.directory "$PWD" && pio test -e native && pio run -e cardputer-adv -e cardputer-adv-debug'
|
||||
case "${1:-all}" in
|
||||
tests) STEPS='pio test -e native' ;;
|
||||
builds) STEPS='pio run -e cardputer-adv -e cardputer-adv-debug' ;;
|
||||
all) STEPS='pio test -e native && pio run -e cardputer-adv -e cardputer-adv-debug' ;;
|
||||
*) echo "Usage: scripts/ci.sh [tests|builds]" >&2; exit 1 ;;
|
||||
esac
|
||||
run_in_container bash -c 'git config --global --add safe.directory "$PWD" && '"$STEPS"
|
||||
|
||||
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/usr/bin/env bash
|
||||
# Runs the host tests and says how much of lib/ they run: they're built with coverage counters.
|
||||
# Usage: scripts/coverage.sh [out folder, default .pio/coverage]
|
||||
# Out: summary.json (gcovr), coverage.svg (the README's badge), index.html (line by line).
|
||||
# What it measures: the lines of lib/ that compile on a PC. Not lib/SD (the card's driver) and not
|
||||
# src/ (the Apps, the Services, everything that needs the device): those have no host tests.
|
||||
set -euo pipefail
|
||||
source "$(dirname "$0")/_docker.sh"
|
||||
DOCKER_EXTRA=()
|
||||
OUT="${1:-.pio/coverage}"
|
||||
|
||||
run_in_container bash -c '
|
||||
set -eo pipefail # a failing test fails this script, tail or not
|
||||
git config --global --add safe.directory "$PWD"
|
||||
rm -rf .pio/build/native-coverage "'"$OUT"'"
|
||||
mkdir -p "'"$OUT"'"
|
||||
pio test -e native-coverage | tail -1
|
||||
gcovr -r . --filter "lib/" --object-directory .pio/build/native-coverage \
|
||||
--json-summary "'"$OUT"'/summary.json" --html-details "'"$OUT"'/index.html" --print-summary | tail -4
|
||||
python3 scripts/coverage_badge.py "'"$OUT"'/summary.json" "'"$OUT"'/coverage.svg"
|
||||
'
|
||||
Executable
+46
@@ -0,0 +1,46 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Draws the README's coverage badge from gcovr's summary.
|
||||
|
||||
Usage: scripts/coverage_badge.py <summary.json> <out.svg>
|
||||
scripts/coverage_badge.py --plain <label> <value> <out.svg> any other badge, in blue
|
||||
Also prints one line, and appends a short table to $GITHUB_STEP_SUMMARY when CI sets it.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
|
||||
|
||||
def badge(label, value, color, title):
|
||||
left, right = 6 * len(label) + 12, 7 * len(value) + 12
|
||||
return f'''<svg xmlns="http://www.w3.org/2000/svg" width="{left + right}" height="20" role="img" aria-label="{label}: {value}">
|
||||
<title>{title}</title>
|
||||
<linearGradient id="s" x2="0" y2="100%"><stop offset="0" stop-color="#bbb" stop-opacity=".1"/><stop offset="1" stop-opacity=".1"/></linearGradient>
|
||||
<clipPath id="r"><rect width="{left + right}" height="20" rx="3" fill="#fff"/></clipPath>
|
||||
<g clip-path="url(#r)"><rect width="{left}" height="20" fill="#555"/><rect x="{left}" width="{right}" height="20" fill="{color}"/><rect width="{left + right}" height="20" fill="url(#s)"/></g>
|
||||
<g fill="#fff" text-anchor="middle" font-family="Verdana,Geneva,DejaVu Sans,sans-serif" font-size="11">
|
||||
<text x="{left / 2}" y="14">{label}</text><text x="{left + right / 2}" y="14">{value}</text></g></svg>
|
||||
'''
|
||||
|
||||
|
||||
def main():
|
||||
if sys.argv[1] == "--plain": # any other badge: --plain <label> <value> <out.svg>
|
||||
label, value, out = sys.argv[2:5]
|
||||
open(out, "w").write(badge(label, value, "#007ec6", f"{label}: {value}"))
|
||||
return
|
||||
summary = json.load(open(sys.argv[1]))
|
||||
lines, branches = summary["line_percent"], summary["branch_percent"]
|
||||
label, value = "lib coverage", f"{lines:.0f}%"
|
||||
color = "#4c1" if lines >= 90 else "#a4a61d" if lines >= 75 else "#dfb317" if lines >= 60 else "#e05d44"
|
||||
svg = badge(label, value, color, f"{label}: {value} of the lines of lib/ are run by the host tests")
|
||||
open(sys.argv[2], "w").write(svg)
|
||||
print(f"coverage of lib/: {lines:.1f}% of {summary['line_total']} lines, {branches:.1f}% of branches, {len(summary['files'])} files")
|
||||
step = os.environ.get("GITHUB_STEP_SUMMARY")
|
||||
if step:
|
||||
worst = sorted((f["line_percent"], f["filename"]) for f in summary["files"] if f["line_total"] >= 10)[:5]
|
||||
with open(step, "a") as out:
|
||||
out.write(f"### Coverage of `lib/` by the host tests\n\n**{lines:.1f}%** of {summary['line_total']} lines, {branches:.1f}% of branches.\n\n")
|
||||
out.write("| Least covered | Lines |\n|---|---|\n" + "".join(f"| `{name}` | {pct:.0f}% |\n" for pct, name in worst))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,4 @@
|
||||
# The coverage build must also link with --coverage (build_flags only reaches the compiler).
|
||||
Import("env") # noqa: F821 (provided by PlatformIO)
|
||||
|
||||
env.Append(LINKFLAGS=["--coverage"]) # noqa: F821
|
||||
+184
-1
@@ -2,7 +2,14 @@
|
||||
|
||||
#include <SD.h>
|
||||
|
||||
#include <algorithm>
|
||||
|
||||
#include "cleanup_plan.h"
|
||||
|
||||
#include "text_wrap.h"
|
||||
#include "ui/fonts.h"
|
||||
#include "ui/widgets.h"
|
||||
#include "update_check.h"
|
||||
#include "version.h"
|
||||
|
||||
namespace roro {
|
||||
@@ -17,6 +24,9 @@ bool endsWith(const std::string& s, const std::string& suffix) {
|
||||
|
||||
void FirmwarePage::enter() {
|
||||
confirm_.reset();
|
||||
ask_ = Ask::None;
|
||||
view_ = View::Main;
|
||||
message_.clear();
|
||||
{
|
||||
std::lock_guard<std::mutex> g(lock_);
|
||||
files_.clear();
|
||||
@@ -40,7 +50,76 @@ std::vector<std::string> FirmwarePage::files() {
|
||||
return files_;
|
||||
}
|
||||
|
||||
void FirmwarePage::say(const std::string& text) {
|
||||
message_ = text;
|
||||
messageMs_ = millis();
|
||||
}
|
||||
|
||||
// The row for the latest release: what's known, in a few words.
|
||||
std::string FirmwarePage::latestText(bool& warn) const {
|
||||
warn = false;
|
||||
GiteaReleases& g = update_.gitea();
|
||||
if (update_.giteaBusy() || g.status() == GiteaReleases::Status::Busy) return "checking...";
|
||||
release::Release r;
|
||||
if (g.status() == GiteaReleases::Status::Failed && !g.latest(r)) {
|
||||
warn = true;
|
||||
return "failed: Enter retries";
|
||||
}
|
||||
if (!g.latest(r)) return "Enter: check";
|
||||
return r.tag + (release::isNewer(r, update_.runningVersion()) ? " (new)" : " (current)");
|
||||
}
|
||||
|
||||
void FirmwarePage::openRelease(const release::Release& r) {
|
||||
shown_ = r;
|
||||
shownTop_ = 0;
|
||||
view_ = View::Release;
|
||||
}
|
||||
|
||||
// Can the release on the page be installed from here, and if not, why (in words for the screen)?
|
||||
bool FirmwarePage::installable(std::string& why) const {
|
||||
std::string running = update_.runningVersion();
|
||||
if (!shown_.usable()) why = "Nothing to install in it";
|
||||
else if (!release::versionNewer(shown_.tag, running) && !versionOlder(shown_.tag, running)) why = "That's the version running";
|
||||
else if (release::isDebugBuild(running)) why = "A Debug Build keeps its console: update it from your PC";
|
||||
else if (wifi_.state() != WifiController::State::Connected) why = "Not connected to Wi-Fi";
|
||||
else return true;
|
||||
return false;
|
||||
}
|
||||
|
||||
bool FirmwarePage::onKey(const KeyEvent& e) {
|
||||
if (view_ != View::Main) {
|
||||
if (confirm_) {
|
||||
confirm_->onKey(e);
|
||||
if (confirm_->result() == 1 && ask_ == Ask::Release) {
|
||||
std::string why = update_.requestInstall(shown_.tag);
|
||||
if (!why.empty()) say(why);
|
||||
}
|
||||
if (confirm_->result() != DialogModel::kPending) confirm_.reset();
|
||||
return true;
|
||||
}
|
||||
if (view_ == View::Release) {
|
||||
if (e.key == Key::Back) view_ = olderReleases_.empty() || older_.count() == 0 ? View::Main : View::Older;
|
||||
else if (e.key == Key::Up) shownTop_ = std::max(0, shownTop_ - 1);
|
||||
else if (e.key == Key::Down) shownTop_++; // clamped when drawn
|
||||
else if (e.key == Key::Char && (e.ch == 'c' || e.ch == 'C') && !update_.giteaBusy()) update_.requestCheck();
|
||||
else if (e.key == Key::Select) {
|
||||
std::string why;
|
||||
if (!installable(why)) return say(why), true;
|
||||
ask_ = Ask::Release;
|
||||
confirm_.reset(new DialogModel({"Cancel", "Install"}));
|
||||
}
|
||||
return true;
|
||||
}
|
||||
// The older releases.
|
||||
if (e.key == Key::Back) view_ = View::Main;
|
||||
else if (e.key == Key::Up) older_.up();
|
||||
else if (e.key == Key::Down) older_.down();
|
||||
else if (e.key == Key::Char && (e.ch == 'c' || e.ch == 'C') && !update_.giteaBusy()) update_.requestList();
|
||||
else if (e.key == Key::Select && older_.selected() >= 0 && older_.selected() < static_cast<int>(olderReleases_.size()))
|
||||
openRelease(olderReleases_[older_.selected()]);
|
||||
return true;
|
||||
}
|
||||
|
||||
auto found = files();
|
||||
if (confirm_) {
|
||||
confirm_->onKey(e);
|
||||
@@ -54,8 +133,22 @@ bool FirmwarePage::onKey(const KeyEvent& e) {
|
||||
case Key::Up: list_.up(); break;
|
||||
case Key::Down: list_.down(); break;
|
||||
case Key::Back: return false;
|
||||
case Key::Char:
|
||||
if ((e.ch == 'c' || e.ch == 'C') && !update_.giteaBusy()) update_.requestCheck();
|
||||
break;
|
||||
case Key::Select:
|
||||
if (list_.selected() >= kFixed) confirm_.reset(new DialogModel({"Cancel", "Install"}));
|
||||
if (list_.selected() == kLatest) {
|
||||
release::Release r;
|
||||
if (update_.giteaBusy()) break;
|
||||
if (update_.gitea().latest(r)) openRelease(r);
|
||||
else update_.requestCheck();
|
||||
} else if (list_.selected() == kOlder) {
|
||||
view_ = View::Older;
|
||||
if (olderReleases_.empty() && !update_.giteaBusy()) update_.requestList();
|
||||
} else if (list_.selected() >= kFixed) {
|
||||
ask_ = Ask::SdFile;
|
||||
confirm_.reset(new DialogModel({"Cancel", "Install"}));
|
||||
}
|
||||
break;
|
||||
default: break;
|
||||
}
|
||||
@@ -63,6 +156,89 @@ bool FirmwarePage::onKey(const KeyEvent& e) {
|
||||
}
|
||||
|
||||
void FirmwarePage::draw(Canvas& c) {
|
||||
if (!message_.empty() && millis() - messageMs_ > 4000) message_.clear();
|
||||
// What the last answer left: the list of older releases.
|
||||
if (update_.gitea().seq() != olderSeq_ && !update_.giteaBusy()) {
|
||||
olderSeq_ = update_.gitea().seq();
|
||||
olderReleases_ = update_.gitea().list();
|
||||
older_.setCount(static_cast<int>(olderReleases_.size()));
|
||||
}
|
||||
switch (view_) {
|
||||
case View::Main: drawMain(c); break;
|
||||
case View::Release: drawRelease(c); break;
|
||||
case View::Older: drawOlder(c); break;
|
||||
}
|
||||
if (confirm_ && view_ != View::Main) {
|
||||
std::string running = update_.runningVersion();
|
||||
bool older = versionOlder(shown_.tag, running);
|
||||
widgets::dialog(c, older ? "Go back?" : "Install update?",
|
||||
older ? shown_.tag + " is older than " + running + ". Install it anyway? The device restarts."
|
||||
: shown_.tag + " replaces " + running + ". The device restarts once it's written.",
|
||||
*confirm_);
|
||||
}
|
||||
if (!message_.empty() && !confirm_) {
|
||||
c.setFont(&fonts::small);
|
||||
c.setTextColor(theme::kWarning);
|
||||
c.setTextDatum(top_left);
|
||||
c.drawString(message_.c_str(), 4, theme::kContent.y + theme::kContent.h - 9);
|
||||
}
|
||||
}
|
||||
|
||||
void FirmwarePage::drawRelease(Canvas& c) {
|
||||
const auto& area = theme::kContent;
|
||||
std::string running = update_.runningVersion();
|
||||
std::vector<std::string> lines;
|
||||
lines.push_back(shown_.tag + (shown_.tag == running ? " (running)" : ""));
|
||||
lines.push_back("Published " + shown_.date() + ", " + formatBytes(shown_.otaSize));
|
||||
if (versionOlder(shown_.tag, running)) lines.push_back("Older than what's running");
|
||||
auto measure = widgets::bodyMeasure(c);
|
||||
lines.push_back("");
|
||||
for (auto& l : wrapText(shown_.notes, area.w - 12, measure)) lines.push_back(l);
|
||||
int rows = (area.h - 12) / theme::kLineHeight;
|
||||
shownTop_ = std::clamp(shownTop_, 0, std::max(0, static_cast<int>(lines.size()) - rows));
|
||||
widgets::textLines(c, lines, shownTop_, {area.x + 2, area.y + 2, area.w - 2, area.h - 12});
|
||||
|
||||
std::string why;
|
||||
bool ok = installable(why);
|
||||
c.setFont(&fonts::small);
|
||||
c.setTextDatum(top_left);
|
||||
c.setTextColor(theme::kMuted);
|
||||
c.drawString(ok ? "Enter: install c: check again" : (why + " c: check again").c_str(), 4, area.y + area.h - 9);
|
||||
}
|
||||
|
||||
void FirmwarePage::drawOlder(Canvas& c) {
|
||||
const auto& area = theme::kContent;
|
||||
GiteaReleases& g = update_.gitea();
|
||||
c.setTextDatum(top_left);
|
||||
if (update_.giteaBusy() || g.status() == GiteaReleases::Status::Busy) {
|
||||
c.setFont(&fonts::body);
|
||||
c.setTextColor(theme::kMuted);
|
||||
c.drawString("Looking at the server...", 4, area.y + 4);
|
||||
return;
|
||||
}
|
||||
if (olderReleases_.empty()) {
|
||||
c.setFont(&fonts::body);
|
||||
c.setTextColor(g.status() == GiteaReleases::Status::Failed ? theme::kWarning : theme::kMuted);
|
||||
c.drawString(g.status() == GiteaReleases::Status::Failed ? g.error().c_str() : "No releases known.", 4, area.y + 4);
|
||||
c.setFont(&fonts::small);
|
||||
c.setTextColor(theme::kMuted);
|
||||
c.drawString("c: look again", 4, area.y + area.h - 9);
|
||||
return;
|
||||
}
|
||||
std::string running = update_.runningVersion();
|
||||
widgets::list(
|
||||
c, older_, {area.x, area.y, area.w, area.h - 11},
|
||||
[&](int i) {
|
||||
const auto& r = olderReleases_[i];
|
||||
return r.tag + (r.tag == running ? " (running)" : release::versionNewer(r.tag, running) ? " (new)" : "");
|
||||
},
|
||||
[&](int i) { return olderReleases_[i].date(); });
|
||||
c.setFont(&fonts::small);
|
||||
c.setTextColor(theme::kMuted);
|
||||
c.drawString("Enter: details c: look again", 4, area.y + area.h - 9);
|
||||
}
|
||||
|
||||
void FirmwarePage::drawMain(Canvas& c) {
|
||||
auto found = files();
|
||||
bool listed;
|
||||
{
|
||||
@@ -78,6 +254,8 @@ void FirmwarePage::draw(Canvas& c) {
|
||||
case kVersion: return "Version";
|
||||
case kStatus: return "Status";
|
||||
case kAddress: return "Push to";
|
||||
case kLatest: return "Latest release";
|
||||
case kOlder: return "Older releases";
|
||||
case kSdHeader: return listed ? (found.empty() ? "No .ota files in /updates" : "On the SD card:") : "Looking on the SD card...";
|
||||
default: return " " + found[i - kFixed].substr(std::string(kUpdatesFolder).size() + 1);
|
||||
}
|
||||
@@ -87,6 +265,11 @@ void FirmwarePage::draw(Canvas& c) {
|
||||
case kVersion: return versionString();
|
||||
case kStatus: return update_.onProbation() ? "on probation" : "confirmed";
|
||||
case kAddress: return ip.empty() ? "Wi-Fi not connected" : ip + ":" + std::to_string(UpdateService::kPort);
|
||||
case kLatest: {
|
||||
bool warn;
|
||||
return latestText(warn);
|
||||
}
|
||||
case kOlder: return ">";
|
||||
case kSdHeader: return "";
|
||||
default: return "install >";
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
#include "dialog_model.h"
|
||||
#include "key_event.h"
|
||||
#include "list_model.h"
|
||||
#include "release_info.h"
|
||||
#include "services/storage_service.h"
|
||||
#include "services/update_service.h"
|
||||
#include "services/wifi_service.h"
|
||||
@@ -16,8 +17,9 @@
|
||||
|
||||
namespace roro {
|
||||
|
||||
// Settings → Firmware: the running version and its Probation, where to push Firmware Updates, and
|
||||
// the Update Files on the SD card (in /updates) to install from.
|
||||
// Settings → Firmware: the running version and its Probation, where to push Firmware Updates, the
|
||||
// project's releases on Gitea (the latest, and the ten before it), and the Update Files on the SD
|
||||
// card (in /updates) to install from.
|
||||
class FirmwarePage {
|
||||
public:
|
||||
FirmwarePage(UpdateService& update, WifiService& wifi, StorageService& storage)
|
||||
@@ -28,15 +30,34 @@ class FirmwarePage {
|
||||
void draw(Canvas& c);
|
||||
|
||||
private:
|
||||
enum Row { kVersion, kStatus, kAddress, kSdHeader, kFixed };
|
||||
enum Row { kVersion, kStatus, kAddress, kLatest, kOlder, kSdHeader, kFixed };
|
||||
enum class View { Main, Release, Older };
|
||||
enum class Ask { None, SdFile, Release };
|
||||
|
||||
std::vector<std::string> files();
|
||||
std::string latestText(bool& warn) const;
|
||||
void openRelease(const release::Release& r);
|
||||
bool installable(std::string& why) const; // the shown release: can it be installed from here?
|
||||
void drawMain(Canvas& c);
|
||||
void drawRelease(Canvas& c);
|
||||
void drawOlder(Canvas& c);
|
||||
void say(const std::string& text);
|
||||
|
||||
UpdateService& update_;
|
||||
WifiService& wifi_;
|
||||
StorageService& storage_;
|
||||
ListModel list_{theme::kContent.h / theme::kLineHeight};
|
||||
ListModel older_{(theme::kContent.h - 11) / theme::kLineHeight}; // above the hint line
|
||||
std::unique_ptr<DialogModel> confirm_;
|
||||
Ask ask_ = Ask::None;
|
||||
|
||||
View view_ = View::Main;
|
||||
release::Release shown_; // the release page
|
||||
std::vector<release::Release> olderReleases_;
|
||||
uint32_t olderSeq_ = 0;
|
||||
int shownTop_ = 0;
|
||||
std::string message_;
|
||||
uint32_t messageMs_ = 0;
|
||||
|
||||
// Filled on the storage task.
|
||||
std::mutex lock_;
|
||||
|
||||
@@ -16,7 +16,7 @@ const char* statusText(Status s) {
|
||||
case Status::Connecting: return "connecting...";
|
||||
case Status::Registering: return "logging in...";
|
||||
case Status::Online: return "";
|
||||
case Status::Paused: return "paused (Wi-Fi monitoring)";
|
||||
case Status::Paused: return "paused (Wi-Fi monitoring or an update)";
|
||||
case Status::Retrying: return "retrying soon";
|
||||
}
|
||||
return "";
|
||||
|
||||
@@ -38,6 +38,7 @@
|
||||
#include "services/clock_service.h"
|
||||
#include "services/debug_console.h"
|
||||
#include "services/file_ops.h"
|
||||
#include "update_check.h"
|
||||
#include "services/gemini_service.h"
|
||||
#include "services/gnss_service.h"
|
||||
#include "services/power_service.h"
|
||||
@@ -182,6 +183,8 @@ void setup() {
|
||||
wifi = new WifiService(settings, *savedNetworks, *clockService);
|
||||
update = new UpdateService(nvs, *wifi, *savedNetworks, *storageService, bus, settings);
|
||||
fileOps = new FileOps(*storageService, filesInUse);
|
||||
update->enableDailyCheck();
|
||||
update->holdMemory = [](bool hold) { irc->holdForUpdate(hold); }; // see UpdateService::holdMemory
|
||||
irc = new IrcService(nvs, "roro_" + identity::defaultShortName(), *wifi, *storageService, *clockService, bus);
|
||||
notifier = new Notifier(bus, settings);
|
||||
notifier->onShow = [](uint32_t now, uint32_t until) { power->onNotification(now, until); };
|
||||
@@ -441,6 +444,84 @@ static void fileOpsStep() {
|
||||
else console.printf("%s: ok\n", name);
|
||||
}
|
||||
|
||||
// `update ...`: the project's releases on Gitea (R1, #6). The answers come from the Update Service's
|
||||
// task a moment later; updateStep() prints them.
|
||||
static int updateWatch = 0; // 1: a check, 2: a list
|
||||
|
||||
static void printReleases(bool list) {
|
||||
GiteaReleases& g = update->gitea();
|
||||
if (g.status() == GiteaReleases::Status::Failed) return (void)console.printf("update: %s\n", g.error().c_str());
|
||||
std::string running = update->runningVersion();
|
||||
if (!list) {
|
||||
release::Release r;
|
||||
if (!g.latest(r)) return (void)console.println("update: nothing known yet");
|
||||
console.printf("update: latest %s of %s, %u bytes: %s (running %s)\n", r.tag.c_str(), r.date().c_str(), (unsigned)r.otaSize,
|
||||
release::isNewer(r, running) ? "newer" : "not newer", running.c_str());
|
||||
console.printf("update: %s\n", r.notes.c_str());
|
||||
return;
|
||||
}
|
||||
for (auto& r : g.list())
|
||||
console.printf("update: %-8s %s %8u B %s\n", r.tag.c_str(), r.date().c_str(), (unsigned)r.otaSize, r.notes.substr(0, 60).c_str());
|
||||
console.println("update: end of list");
|
||||
}
|
||||
|
||||
static void updateStep() {
|
||||
if (!updateWatch || update->giteaBusy()) return;
|
||||
#ifdef RORO_DEBUG
|
||||
if (updateWatch == 3) {
|
||||
console.printf("update: probe: %s\n", update->probeResult().c_str());
|
||||
updateWatch = 0;
|
||||
return;
|
||||
}
|
||||
#endif
|
||||
printReleases(updateWatch == 2);
|
||||
updateWatch = 0;
|
||||
}
|
||||
|
||||
static void updateCommand(const String& args) {
|
||||
if (args == "check" || args == "list") {
|
||||
if (update->giteaBusy()) return (void)console.println("update: busy");
|
||||
args == "check" ? update->requestCheck() : update->requestList();
|
||||
updateWatch = args == "check" ? 1 : 2;
|
||||
} else if (args == "status") {
|
||||
GiteaReleases& g = update->gitea();
|
||||
console.printf("update: running %s, failed here before: %s, daily check %s, heap %u\n", update->runningVersion().c_str(),
|
||||
update->failedVersion().empty() ? "none" : update->failedVersion().c_str(),
|
||||
settings.getBool(Setting::CheckUpdates) ? "on" : "off", (unsigned)ESP.getFreeHeap());
|
||||
console.printf("update: gitea %s %s\n", g.status() == GiteaReleases::Status::Done ? "done" : g.status() == GiteaReleases::Status::Failed ? "failed" : g.status() == GiteaReleases::Status::Busy ? "busy" : "never asked", g.error().c_str());
|
||||
printReleases(false);
|
||||
} else if (args.startsWith("install ")) {
|
||||
String rest = args.substring(8);
|
||||
bool force = rest.endsWith(" force");
|
||||
if (force) rest.remove(rest.length() - 6);
|
||||
#ifndef RORO_DEBUG
|
||||
force = false; // only the Debug Console may install on a Debug Build, which a release isn't
|
||||
#endif
|
||||
std::string why = update->requestInstall(rest.c_str(), force);
|
||||
console.printf("update: %s\n", why.empty() ? "installing" : why.c_str());
|
||||
#ifdef RORO_DEBUG
|
||||
} else if (args.startsWith("probe ")) { // update probe <host> [path]: is that server's certificate accepted?
|
||||
String rest = args.substring(6);
|
||||
int space = rest.indexOf(' ');
|
||||
update->requestProbe((space < 0 ? rest : rest.substring(0, space)).c_str(), space < 0 ? "/" : rest.substring(space + 1).c_str());
|
||||
updateWatch = 3;
|
||||
} else if (args.startsWith("damage ")) { // update damage cut <bytes> | flip <offset>: for the next download
|
||||
long n = args.substring(args.lastIndexOf(' ') + 1).toInt();
|
||||
args.startsWith("damage cut") ? update->damageNextDownload(n, -1) : update->damageNextDownload(-1, n);
|
||||
console.printf("update: the next download will be %s at byte %ld\n", args.startsWith("damage cut") ? "cut" : "damaged", n);
|
||||
|
||||
} else if (args == "daily") { // forget today's check: the daily one runs again at once, if it may
|
||||
update->forgetToday();
|
||||
console.println("update: the daily check will run at the next tick if Wi-Fi, the clock and memory allow");
|
||||
} else if (args.startsWith("pretend ")) { // update pretend v0.9.0 | off: what the comparisons take as running
|
||||
update->pretendVersion(args.substring(8) == "off" ? "" : args.substring(8).c_str());
|
||||
console.printf("update: running %s\n", update->runningVersion().c_str());
|
||||
#endif
|
||||
} else {
|
||||
console.println("update: check | list | status | install <tag>");
|
||||
}
|
||||
}
|
||||
|
||||
static void fileCommand(const String& line) {
|
||||
int space = line.indexOf(' ');
|
||||
std::string command = line.substring(0, space).c_str(), rest = line.substring(space + 1).c_str();
|
||||
@@ -507,6 +588,7 @@ static const char* const kHelp =
|
||||
"gemini get <url> fetch a Gemini page and report header, size, certificate, heap\n"
|
||||
"irc start | irc stop | irc dump | irc say <buffer> <text>\n"
|
||||
"install <path.ota> Update from SD\n"
|
||||
"update check | list | status | install <tag> the project's releases on Gitea\n"
|
||||
"sd card | sd list | cat <path> | log <text> | burst | sound on|off | short | normal\n"
|
||||
#ifdef RORO_DEBUG
|
||||
"crash abort|wdt crash on purpose (to test crash reports and Safe Mode)\n"
|
||||
@@ -571,6 +653,7 @@ static void runCommand(String line) {
|
||||
esp_log_level_set("*", static_cast<esp_log_level_t>(constrain(level, 0, 5)));
|
||||
console.printf("log level: %d\n", constrain(level, 0, 5));
|
||||
}
|
||||
if (line.startsWith("update ")) updateCommand(line.substring(7));
|
||||
if (line.startsWith("cp ") || line.startsWith("mv ") || line.startsWith("rm ") || line.startsWith("mkdir ") ||
|
||||
line.startsWith("du ") || line == "cancel")
|
||||
fileCommand(line);
|
||||
@@ -1010,6 +1093,7 @@ static void loopPass() {
|
||||
if (noiseTest) noiseTest->step(now);
|
||||
#endif
|
||||
noteStableOnce(now);
|
||||
updateStep();
|
||||
fileOpsStep();
|
||||
uploadStep();
|
||||
printListingWhenReady();
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
#pragma once
|
||||
|
||||
namespace roro {
|
||||
|
||||
// The roots this device trusts for what it fetches over HTTPS (docs/milestones/R1.md, Q162): the two
|
||||
// ISRG roots Let's Encrypt chains end in, not the framework's bundle of about 130 CAs. Public
|
||||
// certificates, from https://letsencrypt.org/certs/ (SHA-256 fingerprints below).
|
||||
//
|
||||
// ISRG Root X1 RSA 4096 valid until 2035-06-04
|
||||
// 96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6
|
||||
// ISRG Root X2 ECDSA P-384 valid until 2040-09-17
|
||||
// 69:72:9B:8E:15:A8:6E:FC:17:7A:57:AF:B7:17:1D:FC:64:AD:D2:8C:2F:CA:8C:F1:50:7E:34:45:3C:CB:14:70
|
||||
//
|
||||
// If the server's CA ever changes, the next firmware has to carry the new root and come from the PC.
|
||||
inline constexpr char kTrustedRootsPem[] =
|
||||
"-----BEGIN CERTIFICATE-----\n"
|
||||
"MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw\n"
|
||||
"TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh\n"
|
||||
"cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4\n"
|
||||
"WhcNMzUwNjA0MTEwNDM4WjBPMQswCQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJu\n"
|
||||
"ZXQgU2VjdXJpdHkgUmVzZWFyY2ggR3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBY\n"
|
||||
"MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK3oJHP0FDfzm54rVygc\n"
|
||||
"h77ct984kIxuPOZXoHj3dcKi/vVqbvYATyjb3miGbESTtrFj/RQSa78f0uoxmyF+\n"
|
||||
"0TM8ukj13Xnfs7j/EvEhmkvBioZxaUpmZmyPfjxwv60pIgbz5MDmgK7iS4+3mX6U\n"
|
||||
"A5/TR5d8mUgjU+g4rk8Kb4Mu0UlXjIB0ttov0DiNewNwIRt18jA8+o+u3dpjq+sW\n"
|
||||
"T8KOEUt+zwvo/7V3LvSye0rgTBIlDHCNAymg4VMk7BPZ7hm/ELNKjD+Jo2FR3qyH\n"
|
||||
"B5T0Y3HsLuJvW5iB4YlcNHlsdu87kGJ55tukmi8mxdAQ4Q7e2RCOFvu396j3x+UC\n"
|
||||
"B5iPNgiV5+I3lg02dZ77DnKxHZu8A/lJBdiB3QW0KtZB6awBdpUKD9jf1b0SHzUv\n"
|
||||
"KBds0pjBqAlkd25HN7rOrFleaJ1/ctaJxQZBKT5ZPt0m9STJEadao0xAH0ahmbWn\n"
|
||||
"OlFuhjuefXKnEgV4We0+UXgVCwOPjdAvBbI+e0ocS3MFEvzG6uBQE3xDk3SzynTn\n"
|
||||
"jh8BCNAw1FtxNrQHusEwMFxIt4I7mKZ9YIqioymCzLq9gwQbooMDQaHWBfEbwrbw\n"
|
||||
"qHyGO0aoSCqI3Haadr8faqU9GY/rOPNk3sgrDQoo//fb4hVC1CLQJ13hef4Y53CI\n"
|
||||
"rU7m2Ys6xt0nUW7/vGT1M0NPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNV\n"
|
||||
"HRMBAf8EBTADAQH/MB0GA1UdDgQWBBR5tFnme7bl5AFzgAiIyBpY9umbbjANBgkq\n"
|
||||
"hkiG9w0BAQsFAAOCAgEAVR9YqbyyqFDQDLHYGmkgJykIrGF1XIpu+ILlaS/V9lZL\n"
|
||||
"ubhzEFnTIZd+50xx+7LSYK05qAvqFyFWhfFQDlnrzuBZ6brJFe+GnY+EgPbk6ZGQ\n"
|
||||
"3BebYhtF8GaV0nxvwuo77x/Py9auJ/GpsMiu/X1+mvoiBOv/2X/qkSsisRcOj/KK\n"
|
||||
"NFtY2PwByVS5uCbMiogziUwthDyC3+6WVwW6LLv3xLfHTjuCvjHIInNzktHCgKQ5\n"
|
||||
"ORAzI4JMPJ+GslWYHb4phowim57iaztXOoJwTdwJx4nLCgdNbOhdjsnvzqvHu7Ur\n"
|
||||
"TkXWStAmzOVyyghqpZXjFaH3pO3JLF+l+/+sKAIuvtd7u+Nxe5AW0wdeRlN8NwdC\n"
|
||||
"jNPElpzVmbUq4JUagEiuTDkHzsxHpFKVK7q4+63SM1N95R1NbdWhscdCb+ZAJzVc\n"
|
||||
"oyi3B43njTOQ5yOf+1CceWxG1bQVs5ZufpsMljq4Ui0/1lvh+wjChP4kqKOJ2qxq\n"
|
||||
"4RgqsahDYVvTH9w7jXbyLeiNdd8XM2w9U/t7y0Ff/9yi0GE44Za4rF2LN9d11TPA\n"
|
||||
"mRGunUHBcnWEvgJBQl9nJEiU0Zsnvgc/ubhPgXRR4Xq37Z0j4r7g1SgEEzwxA57d\n"
|
||||
"emyPxgcYxn/eR44/KJ4EBs+lVDR3veyJm+kXQ99b21/+jh5Xos1AnX5iItreGCc=\n"
|
||||
"-----END CERTIFICATE-----\n"
|
||||
"-----BEGIN CERTIFICATE-----\n"
|
||||
"MIICGzCCAaGgAwIBAgIQQdKd0XLq7qeAwSxs6S+HUjAKBggqhkjOPQQDAzBPMQsw\n"
|
||||
"CQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJuZXQgU2VjdXJpdHkgUmVzZWFyY2gg\n"
|
||||
"R3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBYMjAeFw0yMDA5MDQwMDAwMDBaFw00\n"
|
||||
"MDA5MTcxNjAwMDBaME8xCzAJBgNVBAYTAlVTMSkwJwYDVQQKEyBJbnRlcm5ldCBT\n"
|
||||
"ZWN1cml0eSBSZXNlYXJjaCBHcm91cDEVMBMGA1UEAxMMSVNSRyBSb290IFgyMHYw\n"
|
||||
"EAYHKoZIzj0CAQYFK4EEACIDYgAEzZvVn4CDCuwJSvMWSj5cz3es3mcFDR0HttwW\n"
|
||||
"+1qLFNvicWDEukWVEYmO6gbf9yoWHKS5xcUy4APgHoIYOIvXRdgKam7mAHf7AlF9\n"
|
||||
"ItgKbppbd9/w+kHsOdx1ymgHDB/qo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0T\n"
|
||||
"AQH/BAUwAwEB/zAdBgNVHQ4EFgQUfEKWrt5LSDv6kviejM9ti6lyN5UwCgYIKoZI\n"
|
||||
"zj0EAwMDaAAwZQIwe3lORlCEwkSHRhtFcP9Ymd70/aTSVaYgLXTWNLxBo1BfASdW\n"
|
||||
"tL4ndQavEi51mI38AjEAi/V3bNTIZargCyzuFJ0nN6T5U6VR5CmD1/iQMVtCnwr1\n"
|
||||
"/q4AaOeMSQ+2b1tbFfLn\n"
|
||||
"-----END CERTIFICATE-----\n";
|
||||
|
||||
} // namespace roro
|
||||
@@ -0,0 +1,111 @@
|
||||
#include "platform/https_get.h"
|
||||
|
||||
#include <Arduino.h>
|
||||
#include <esp_heap_caps.h>
|
||||
|
||||
#include <algorithm>
|
||||
#include <ctime>
|
||||
|
||||
#include "platform/ca_roots.h"
|
||||
#include "version.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
namespace {
|
||||
constexpr time_t kClockSetAfter = 1700000000; // 2023-11: anything earlier is the clock's default
|
||||
|
||||
// What mbedTLS says in the way it says it, for the cases a person can act on.
|
||||
std::string whyNotConnected(NetworkClientSecure& tls, const std::string& host) {
|
||||
char text[100] = "";
|
||||
int err = tls.lastError(text, sizeof text);
|
||||
std::string detail = text;
|
||||
if (detail.find("X509") != std::string::npos || detail.find("certificate") != std::string::npos)
|
||||
return "The certificate of " + host + " isn't accepted";
|
||||
if (err != 0 && !detail.empty()) return "TLS to " + host + ": " + detail;
|
||||
return "Can't connect to " + host;
|
||||
}
|
||||
} // namespace
|
||||
|
||||
std::string HttpsGet::open(const std::string& host, const std::string& path, const char* accept) {
|
||||
close();
|
||||
if (time(nullptr) < kClockSetAfter) return "The clock isn't set: can't check certificates";
|
||||
if (esp_get_free_heap_size() < kNeedFree) return "Not enough memory for a secure connection";
|
||||
|
||||
tls_.setCACert(kTrustedRootsPem);
|
||||
tls_.setTimeout(15);
|
||||
if (!tls_.connect(host.c_str(), 443)) return whyNotConnected(tls_, host);
|
||||
|
||||
raw_.reset(new (std::nothrow) uint8_t[kRaw]);
|
||||
if (!raw_) return "Not enough memory";
|
||||
tls_.print(("GET " + path + " HTTP/1.1\r\nHost: " + host + "\r\nUser-Agent: roro9stack/" + versionString() +
|
||||
"\r\nAccept: " + accept + "\r\nAccept-Encoding: identity\r\nConnection: close\r\n\r\n")
|
||||
.c_str());
|
||||
|
||||
release::HttpHeadParser parser;
|
||||
while (!parser.complete()) {
|
||||
int n = readRaw(raw_.get(), kRaw);
|
||||
if (n <= 0) return "The server " + host + " stopped answering";
|
||||
size_t used = parser.feed(reinterpret_cast<const char*>(raw_.get()), n);
|
||||
if (parser.failed()) return host + " didn't answer with HTTP";
|
||||
if (parser.complete() && used < static_cast<size_t>(n)) early_.assign(reinterpret_cast<const char*>(raw_.get()) + used, n - used);
|
||||
}
|
||||
head_ = parser.head();
|
||||
if (head_.status != 200) return host + " answered " + std::to_string(head_.status) + (head_.status / 100 == 3 ? " (a redirect)" : "");
|
||||
left_ = head_.chunked ? -1 : head_.contentLength;
|
||||
return "";
|
||||
}
|
||||
|
||||
int HttpsGet::readRaw(uint8_t* into, size_t len) {
|
||||
uint32_t since = millis();
|
||||
while (!tls_.available()) {
|
||||
if (!tls_.connected()) return 0;
|
||||
if (millis() - since > kStallMs) return -1;
|
||||
delay(5);
|
||||
}
|
||||
return tls_.read(into, len);
|
||||
}
|
||||
|
||||
int HttpsGet::read(uint8_t* buf, size_t len) {
|
||||
if (done_ || len == 0) return 0;
|
||||
if (!head_.chunked && left_ == 0) return done_ = true, 0;
|
||||
|
||||
for (;;) {
|
||||
// Raw bytes: first those that came with the head, then the connection's.
|
||||
size_t want = head_.chunked ? std::min(len, kRaw) : len;
|
||||
if (!head_.chunked && left_ > 0) want = std::min<size_t>(want, left_);
|
||||
int n;
|
||||
if (earlyAt_ < early_.size()) {
|
||||
n = static_cast<int>(std::min(want, early_.size() - earlyAt_));
|
||||
std::copy(early_.data() + earlyAt_, early_.data() + earlyAt_ + n, head_.chunked ? raw_.get() : buf);
|
||||
earlyAt_ += n;
|
||||
} else {
|
||||
n = readRaw(head_.chunked ? raw_.get() : buf, want);
|
||||
}
|
||||
if (n < 0) return -1;
|
||||
if (n == 0) { // the server closed: the end, if it's where it said it would be
|
||||
done_ = true;
|
||||
bool whole = head_.chunked ? chunks_.done() : left_ <= 0;
|
||||
return whole ? 0 : -1;
|
||||
}
|
||||
if (!head_.chunked) {
|
||||
if (left_ > 0) left_ -= n;
|
||||
return n;
|
||||
}
|
||||
size_t out = chunks_.decode(raw_.get(), n, buf);
|
||||
if (chunks_.failed()) return -1;
|
||||
if (out > 0) return static_cast<int>(out);
|
||||
if (chunks_.done()) return done_ = true, 0;
|
||||
}
|
||||
}
|
||||
|
||||
void HttpsGet::close() {
|
||||
tls_.stop();
|
||||
raw_.reset();
|
||||
std::string().swap(early_);
|
||||
earlyAt_ = 0;
|
||||
done_ = false;
|
||||
head_ = release::HttpHead();
|
||||
chunks_ = release::ChunkedDecoder();
|
||||
}
|
||||
|
||||
} // namespace roro
|
||||
@@ -0,0 +1,51 @@
|
||||
#pragma once
|
||||
|
||||
#include <NetworkClientSecure.h>
|
||||
|
||||
#include <memory>
|
||||
#include <string>
|
||||
|
||||
#include "http_head.h"
|
||||
#include "platform/counted_client.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
// One HTTPS GET, read as a stream: the connection checks the server's chain and name against the
|
||||
// roots in ca_roots.h, the head is parsed, and the body comes out whole whether the server sent it
|
||||
// with a length or in chunks. Used by the Update Service to read Gitea's answers and to download a
|
||||
// release. Redirects aren't followed: the device only goes where it was told to (Q163).
|
||||
class HttpsGet {
|
||||
public:
|
||||
// A TLS connection to Gitea peaks at about 52 KB of heap (measured: the same with or without
|
||||
// checking the certificate); with Q86's 20 KB to spare, it starts with at least this much free.
|
||||
static constexpr size_t kNeedFree = 80 * 1024;
|
||||
|
||||
explicit HttpsGet(net::User user) : tls_(user) {}
|
||||
~HttpsGet() { close(); }
|
||||
|
||||
// Connects and reads the head. "" when a 200 is on its way, or why not, in words for the screen.
|
||||
std::string open(const std::string& host, const std::string& path, const char* accept);
|
||||
long contentLength() const { return head_.contentLength; } // -1: not known
|
||||
|
||||
// Body bytes into `buf`: how many, 0 at the end, -1 when the connection broke or stalled
|
||||
// before the end.
|
||||
int read(uint8_t* buf, size_t len);
|
||||
void close();
|
||||
|
||||
private:
|
||||
static constexpr size_t kRaw = 1024;
|
||||
static constexpr uint32_t kStallMs = 10000;
|
||||
|
||||
int readRaw(uint8_t* into, size_t len); // from the connection, waiting up to kStallMs
|
||||
|
||||
Counted<NetworkClientSecure> tls_;
|
||||
release::HttpHead head_;
|
||||
release::ChunkedDecoder chunks_;
|
||||
std::unique_ptr<uint8_t[]> raw_;
|
||||
std::string early_; // body bytes that arrived with the head
|
||||
size_t earlyAt_ = 0;
|
||||
long left_ = -1; // body bytes still to come, if the server said how many
|
||||
bool done_ = false;
|
||||
};
|
||||
|
||||
} // namespace roro
|
||||
@@ -0,0 +1,137 @@
|
||||
#include "services/gitea_releases.h"
|
||||
|
||||
#include <memory>
|
||||
|
||||
#include "platform/https_get.h"
|
||||
#include "update_check.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
namespace {
|
||||
struct Guard {
|
||||
explicit Guard(SemaphoreHandle_t l) : l_(l) { xSemaphoreTake(l_, portMAX_DELAY); }
|
||||
~Guard() { xSemaphoreGive(l_); }
|
||||
SemaphoreHandle_t l_;
|
||||
};
|
||||
|
||||
std::string api(const std::string& what) { return std::string("/api/v1/repos/") + release::kGiteaRepo + "/releases" + what; }
|
||||
} // namespace
|
||||
|
||||
bool GiteaReleases::fetch(const std::string& path, size_t max, std::vector<release::Release>& out) {
|
||||
HttpsGet get(net::User::Updates);
|
||||
std::string why = get.open(release::kGiteaHost, path, "application/json");
|
||||
if (!why.empty()) {
|
||||
finish(false, why);
|
||||
return false;
|
||||
}
|
||||
release::ReleaseReader reader(max);
|
||||
std::unique_ptr<uint8_t[]> buf(new (std::nothrow) uint8_t[512]);
|
||||
if (!buf) {
|
||||
finish(false, "Not enough memory");
|
||||
return false;
|
||||
}
|
||||
for (;;) {
|
||||
int n = get.read(buf.get(), 512);
|
||||
if (n < 0) {
|
||||
finish(false, "The connection broke off");
|
||||
return false;
|
||||
}
|
||||
if (n == 0) break;
|
||||
reader.feed(reinterpret_cast<const char*>(buf.get()), n);
|
||||
if (!reader.ok()) break;
|
||||
}
|
||||
reader.end();
|
||||
if (!reader.ok() || !reader.complete()) {
|
||||
finish(false, "Gitea's answer isn't what was expected");
|
||||
return false;
|
||||
}
|
||||
out = reader.releases();
|
||||
return true;
|
||||
}
|
||||
|
||||
void GiteaReleases::finish(bool ok, const std::string& error) {
|
||||
Guard g(lock_);
|
||||
status_ = ok ? Status::Done : Status::Failed;
|
||||
error_ = error;
|
||||
seq_++;
|
||||
}
|
||||
|
||||
bool GiteaReleases::fetchLatest() {
|
||||
{
|
||||
Guard g(lock_);
|
||||
status_ = Status::Busy;
|
||||
error_.clear();
|
||||
}
|
||||
std::vector<release::Release> got;
|
||||
if (!fetch(api("/latest"), 1, got)) return false;
|
||||
if (got.empty() || !got[0].usable()) {
|
||||
finish(false, "No release to install on the server");
|
||||
return false;
|
||||
}
|
||||
{
|
||||
Guard g(lock_);
|
||||
latest_ = got[0];
|
||||
haveLatest_ = true;
|
||||
}
|
||||
finish(true, "");
|
||||
return true;
|
||||
}
|
||||
|
||||
bool GiteaReleases::fetchList() {
|
||||
{
|
||||
Guard g(lock_);
|
||||
status_ = Status::Busy;
|
||||
error_.clear();
|
||||
}
|
||||
std::vector<release::Release> got;
|
||||
if (!fetch(api("?limit=" + std::to_string(kListSize) + "&draft=false&pre-release=false"), kListSize, got)) return false;
|
||||
std::vector<release::Release> usable;
|
||||
for (auto& r : got)
|
||||
if (r.usable()) usable.push_back(std::move(r));
|
||||
{
|
||||
Guard g(lock_);
|
||||
list_ = std::move(usable);
|
||||
if (!list_.empty() && (!haveLatest_ || release::versionNewer(list_[0].tag, latest_.tag))) {
|
||||
latest_ = list_[0];
|
||||
haveLatest_ = true;
|
||||
}
|
||||
}
|
||||
finish(true, "");
|
||||
return true;
|
||||
}
|
||||
|
||||
GiteaReleases::Status GiteaReleases::status() const {
|
||||
Guard g(lock_);
|
||||
return status_;
|
||||
}
|
||||
|
||||
std::string GiteaReleases::error() const {
|
||||
Guard g(lock_);
|
||||
return error_;
|
||||
}
|
||||
|
||||
uint32_t GiteaReleases::seq() const {
|
||||
Guard g(lock_);
|
||||
return seq_;
|
||||
}
|
||||
|
||||
bool GiteaReleases::latest(release::Release& out) const {
|
||||
Guard g(lock_);
|
||||
if (haveLatest_) out = latest_;
|
||||
return haveLatest_;
|
||||
}
|
||||
|
||||
std::vector<release::Release> GiteaReleases::list() const {
|
||||
Guard g(lock_);
|
||||
return list_;
|
||||
}
|
||||
|
||||
bool GiteaReleases::find(const std::string& tag, release::Release& out) const {
|
||||
Guard g(lock_);
|
||||
for (const auto& r : list_)
|
||||
if (r.tag == tag) return out = r, true;
|
||||
if (haveLatest_ && latest_.tag == tag) return out = latest_, true;
|
||||
return false;
|
||||
}
|
||||
|
||||
} // namespace roro
|
||||
@@ -0,0 +1,48 @@
|
||||
#pragma once
|
||||
|
||||
#include <freertos/FreeRTOS.h>
|
||||
#include <freertos/semphr.h>
|
||||
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
#include "release_info.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
// What the device knows of the project's releases on Gitea (docs/milestones/R1.md, #6): the latest,
|
||||
// and a list of the last ten. The fetching runs on the Update Service's task; the screens read what
|
||||
// came out, from the main loop.
|
||||
class GiteaReleases {
|
||||
public:
|
||||
enum class Status : uint8_t { Never, Busy, Done, Failed };
|
||||
static constexpr size_t kListSize = 10;
|
||||
|
||||
GiteaReleases() : lock_(xSemaphoreCreateMutex()) {}
|
||||
|
||||
// On the Update Service's task. True when the answer was read; otherwise error() says why.
|
||||
bool fetchLatest();
|
||||
bool fetchList();
|
||||
|
||||
void fail(const std::string& error) { finish(false, error); } // something stopped it before it began
|
||||
Status status() const;
|
||||
std::string error() const;
|
||||
uint32_t seq() const; // grows with every answer that changed something
|
||||
bool latest(release::Release& out) const; // false: not fetched yet
|
||||
std::vector<release::Release> list() const;
|
||||
bool find(const std::string& tag, release::Release& out) const; // in the list, or the latest
|
||||
|
||||
private:
|
||||
bool fetch(const std::string& path, size_t max, std::vector<release::Release>& out);
|
||||
void finish(bool ok, const std::string& error);
|
||||
|
||||
mutable SemaphoreHandle_t lock_;
|
||||
Status status_ = Status::Never;
|
||||
std::string error_;
|
||||
uint32_t seq_ = 0;
|
||||
bool haveLatest_ = false;
|
||||
release::Release latest_;
|
||||
std::vector<release::Release> list_;
|
||||
};
|
||||
|
||||
} // namespace roro
|
||||
@@ -224,6 +224,14 @@ void IrcService::loop() {
|
||||
if (!wanted_) {
|
||||
if (open_) close("disconnected");
|
||||
status_ = Status::Stopped;
|
||||
} else if (held_) {
|
||||
if (open_) {
|
||||
conn_->print("QUIT :updating\r\n");
|
||||
vTaskDelay(pdMS_TO_TICKS(300));
|
||||
close("paused while the device updates");
|
||||
}
|
||||
status_ = Status::Paused;
|
||||
retryAtMs_ = now; // back at once when released
|
||||
} else if (!wifiUp) {
|
||||
if (open_) close(monitoring ? "paused for Wi-Fi monitoring" : "Wi-Fi lost");
|
||||
status_ = monitoring ? Status::Paused : Status::WaitingForWifi;
|
||||
|
||||
@@ -38,6 +38,11 @@ class IrcService : public Service {
|
||||
void disconnect();
|
||||
bool running() const { return wanted_; }
|
||||
bool stoppedByUser() const { return stoppedByUser_; }
|
||||
|
||||
// A TLS connection to Gitea needs more memory than is left beside this one (#6, Q172): the
|
||||
// Update Service asks IRC to step aside while it talks to the server, and to come back after.
|
||||
// Unlike disconnect(), nothing is remembered as "stopped by the user".
|
||||
void holdForUpdate(bool hold) { held_ = hold; }
|
||||
Status status() const { return status_; }
|
||||
|
||||
// Read or act on the session while holding its lock: withSession([](IrcSession& s) { ... }).
|
||||
@@ -86,6 +91,7 @@ class IrcService : public Service {
|
||||
volatile bool stopRequested_ = false;
|
||||
bool quitSent_ = false; // /quit already queued its QUIT
|
||||
volatile bool restart_ = false;
|
||||
volatile bool held_ = false; // stepping aside for an update
|
||||
volatile Status status_ = Status::Stopped;
|
||||
bool open_ = false;
|
||||
uint32_t retryAtMs_ = 0;
|
||||
|
||||
@@ -7,6 +7,10 @@
|
||||
|
||||
#include <memory>
|
||||
|
||||
#include <ctime>
|
||||
|
||||
#include "http_head.h"
|
||||
#include "platform/https_get.h"
|
||||
#include "platform/ota_device.h"
|
||||
#include "platform/system_info.h"
|
||||
#include "probation.h"
|
||||
@@ -60,6 +64,25 @@ class FileSource : public UpdateSource {
|
||||
File& f_;
|
||||
};
|
||||
|
||||
// A release being downloaded from Gitea: the same bytes a push or a card would give.
|
||||
class GiteaSource : public UpdateSource {
|
||||
public:
|
||||
GiteaSource(HttpsGet& get, long cutAfter, long flipAt) : get_(get), cut_(cutAfter), flip_(flipAt) {}
|
||||
int read(uint8_t* buf, size_t len) override {
|
||||
if (cut_ >= 0 && pos_ >= cut_) return -1; // Debug Builds: the connection "breaks" here
|
||||
int n = get_.read(buf, len);
|
||||
if (n > 0 && flip_ >= pos_ && flip_ < pos_ + n) buf[flip_ - pos_] ^= 1; // and a byte "arrives wrong"
|
||||
if (n > 0) pos_ += n;
|
||||
return n;
|
||||
}
|
||||
|
||||
private:
|
||||
HttpsGet& get_;
|
||||
long cut_, flip_, pos_ = 0;
|
||||
};
|
||||
|
||||
constexpr time_t kClockSetAfter = 1700000000; // anything earlier is the clock's default
|
||||
|
||||
} // namespace
|
||||
|
||||
UpdateService::UpdateService(KeyValueStore& store, WifiService& wifi, SavedNetworks& saved, StorageService& storage,
|
||||
@@ -85,10 +108,11 @@ void UpdateService::start() {
|
||||
store_.getString("ota_from", from);
|
||||
if (!pending.empty() && pending != versionString()) {
|
||||
notify("Update to " + pending + " failed, back on " + versionString(), NotificationLevel::Warning);
|
||||
store_.putString("ota_failed", pending); // not announced again until there's a newer one (Q168)
|
||||
store_.putString("ota_pending", "");
|
||||
}
|
||||
|
||||
if (!task_) xTaskCreate(taskEntry, "update", 5120, this, 1, &task_); // peak 3.4 KB (ECDSA check, M2)
|
||||
if (!task_) xTaskCreate(taskEntry, "update", 7168, this, 1, &task_); // peak 5.4 KB: TLS to Gitea and the signature check (#6)
|
||||
}
|
||||
|
||||
void UpdateService::bootGuard(KeyValueStore& store) {
|
||||
@@ -106,6 +130,7 @@ void UpdateService::bootGuard(KeyValueStore& store) {
|
||||
}
|
||||
|
||||
void UpdateService::tick(uint32_t nowMs) {
|
||||
scheduleDailyCheck(nowMs);
|
||||
if (!probation_) return;
|
||||
bool wifiConfigured = settings_.getBool(Setting::WifiEnabled) && saved_.count() > 0;
|
||||
bool wifiUp = wifi_.state() == WifiController::State::Connected;
|
||||
@@ -184,6 +209,134 @@ void UpdateService::installFromSd(const std::string& path) {
|
||||
});
|
||||
}
|
||||
|
||||
std::string UpdateService::failedVersion() const {
|
||||
std::string failed;
|
||||
store_.getString("ota_failed", failed);
|
||||
return failed;
|
||||
}
|
||||
|
||||
std::string UpdateService::requestInstall(const std::string& tag, bool force) {
|
||||
if (phase_ != Phase::Idle || giteaBusy()) return "Busy with something else";
|
||||
if (!force && release::isDebugBuild(runningVersion())) return "A Debug Build keeps its console: update it from your PC";
|
||||
if (wifi_.state() != WifiController::State::Connected) return "No Wi-Fi";
|
||||
release::Release r;
|
||||
if (!gitea_.find(tag, r)) return "Look for releases first";
|
||||
if (!release::trustedAssetUrl(r.otaUrl)) return "That download isn't on the project's server";
|
||||
installTag_ = tag;
|
||||
request_ = Request::Install;
|
||||
return "";
|
||||
}
|
||||
|
||||
// Once a day while Wi-Fi is up and the Clock is set (Q165). Skipped, and tried again later, when
|
||||
// something else is going on or memory is short; never during Probation or an install.
|
||||
void UpdateService::scheduleDailyCheck(uint32_t nowMs) {
|
||||
if (!dailyCheck_ || !settings_.getBool(Setting::CheckUpdates)) return;
|
||||
if (static_cast<int32_t>(nowMs - nextCheckMs_) < 0 || probation_ || phase_ != Phase::Idle || giteaBusy()) return;
|
||||
if (wifi_.state() != WifiController::State::Connected) return;
|
||||
time_t now = time(nullptr);
|
||||
if (now < kClockSetAfter) return;
|
||||
int32_t today = static_cast<int32_t>(now / 86400), last = 0;
|
||||
store_.getInt("rel_day", last);
|
||||
if (today == last) {
|
||||
nextCheckMs_ = nowMs + 3600000; // look again in an hour, in case the day has turned
|
||||
return;
|
||||
}
|
||||
// Never at IRC's expense: with IRC connected there isn't the room (Q172), so this waits.
|
||||
if (esp_get_free_heap_size() < HttpsGet::kNeedFree) {
|
||||
nextCheckMs_ = nowMs + 600000;
|
||||
return;
|
||||
}
|
||||
nextCheckMs_ = nowMs + 1800000; // if this one fails
|
||||
request_ = Request::BackgroundCheck;
|
||||
}
|
||||
|
||||
// What a person asked for (a check, a list, an install) may take IRC offline for a few seconds:
|
||||
// a TLS connection needs about 80 KB and IRC's own holds 40 KB of what there is (R1, Q172).
|
||||
bool UpdateService::makeRoom() {
|
||||
if (esp_get_free_heap_size() >= HttpsGet::kNeedFree) return true;
|
||||
if (!holdMemory) return false;
|
||||
held_ = true;
|
||||
holdMemory(true);
|
||||
for (int i = 0; i < 40 && esp_get_free_heap_size() < HttpsGet::kNeedFree; i++) delay(100); // its TLS session goes
|
||||
return esp_get_free_heap_size() >= HttpsGet::kNeedFree;
|
||||
}
|
||||
|
||||
void UpdateService::serve() {
|
||||
Request r = request_;
|
||||
if (r == Request::None) return;
|
||||
request_ = Request::None;
|
||||
serving_ = true;
|
||||
held_ = false;
|
||||
if (r != Request::BackgroundCheck && r != Request::None) {
|
||||
bool ok = makeRoom();
|
||||
if (!ok) {
|
||||
gitea_.fail("Not enough memory: close a Gemini page");
|
||||
if (r == Request::Install) notify("Update refused: not enough memory", NotificationLevel::Warning);
|
||||
r = Request::None;
|
||||
}
|
||||
}
|
||||
switch (r) {
|
||||
case Request::Check:
|
||||
case Request::BackgroundCheck: {
|
||||
if (!gitea_.fetchLatest()) break;
|
||||
time_t now = time(nullptr);
|
||||
if (now >= kClockSetAfter) store_.putInt("rel_day", static_cast<int32_t>(now / 86400));
|
||||
release::Release latest;
|
||||
if (r == Request::BackgroundCheck && gitea_.latest(latest) &&
|
||||
release::shouldAnnounce(latest, runningVersion(), failedVersion(), announced_)) {
|
||||
announced_ = latest.tag;
|
||||
notify(latest.tag + " is out: see Settings > Firmware", NotificationLevel::Info); // 48 bytes at most
|
||||
}
|
||||
break;
|
||||
}
|
||||
case Request::List: gitea_.fetchList(); break;
|
||||
case Request::Install: {
|
||||
release::Release release;
|
||||
if (gitea_.find(installTag_, release)) installFromGitea(release);
|
||||
break;
|
||||
}
|
||||
#ifdef RORO_DEBUG
|
||||
case Request::Probe: {
|
||||
HttpsGet get(net::User::Updates);
|
||||
std::string why = get.open(probeHost_, probePath_, "*/*");
|
||||
probeResult_ = why.empty() ? "accepted, the server answered 200" : why;
|
||||
break;
|
||||
}
|
||||
#endif
|
||||
case Request::None: break;
|
||||
}
|
||||
// A check or a list someone asked for that failed says so; the daily one stays quiet.
|
||||
if ((r == Request::Check || r == Request::List) && gitea_.status() == GiteaReleases::Status::Failed)
|
||||
notify(gitea_.error(), NotificationLevel::Warning);
|
||||
// IRC comes back, unless the device is about to restart into an update.
|
||||
if (held_ && phase_ != Phase::Installed && holdMemory) holdMemory(false);
|
||||
held_ = false;
|
||||
serving_ = false;
|
||||
}
|
||||
|
||||
void UpdateService::installFromGitea(const release::Release& r) {
|
||||
release::Url url = release::parseUrl(r.otaUrl);
|
||||
incoming_ = r.tag;
|
||||
percent_ = 0;
|
||||
phase_ = Phase::Receiving;
|
||||
HttpsGet get(net::User::Updates);
|
||||
std::string why = get.open(url.host, url.path, "application/octet-stream");
|
||||
if (why.empty() && r.otaSize && get.contentLength() >= 0 && static_cast<uint32_t>(get.contentLength()) != r.otaSize)
|
||||
why = "The file isn't the size the server listed";
|
||||
if (!why.empty()) {
|
||||
phase_ = Phase::Idle;
|
||||
notify("Update refused: " + why, NotificationLevel::Warning);
|
||||
return;
|
||||
}
|
||||
#ifdef RORO_DEBUG
|
||||
GiteaSource source(get, damageCut_, damageFlip_);
|
||||
damageCut_ = damageFlip_ = -1;
|
||||
#else
|
||||
GiteaSource source(get, -1, -1);
|
||||
#endif
|
||||
install(source, "Gitea");
|
||||
}
|
||||
|
||||
void UpdateService::taskEntry(void* self) { static_cast<UpdateService*>(self)->listen(); }
|
||||
|
||||
void UpdateService::listen() {
|
||||
@@ -208,6 +361,7 @@ void UpdateService::listen() {
|
||||
esp_restart();
|
||||
}
|
||||
}
|
||||
if (phase_ == Phase::Idle) serve();
|
||||
if (listening && phase_ == Phase::Idle) {
|
||||
Counted<NetworkClient> client(server.accept(), net::User::Updates);
|
||||
if (client) {
|
||||
|
||||
@@ -2,11 +2,16 @@
|
||||
|
||||
#include <freertos/FreeRTOS.h>
|
||||
|
||||
#include <functional>
|
||||
#include <string>
|
||||
|
||||
#include "update_check.h"
|
||||
#include "version.h"
|
||||
|
||||
#include "event_bus.h"
|
||||
#include "key_value_store.h"
|
||||
#include "service.h"
|
||||
#include "services/gitea_releases.h"
|
||||
#include "services/storage_service.h"
|
||||
#include "services/wifi_service.h"
|
||||
|
||||
@@ -39,12 +44,46 @@ class UpdateService : public Service {
|
||||
// Installs an Update File from the SD card (runs on the storage task).
|
||||
void installFromSd(const std::string& path);
|
||||
|
||||
// Updates from Gitea (docs/milestones/R1.md, #6). The requests are done on this Service's task;
|
||||
// the answers are read from gitea().
|
||||
GiteaReleases& gitea() { return gitea_; }
|
||||
void requestCheck() { request_ = Request::Check; }
|
||||
void requestList() { request_ = Request::List; }
|
||||
// Downloads `tag` (a release known from the last check or list) into the inactive slot and
|
||||
// installs it. "" when it started, or why not. A Debug Build doesn't install a release (Q171,
|
||||
// it would take its Debug Console away) unless `force`, which only the Debug Console passes.
|
||||
std::string requestInstall(const std::string& tag, bool force = false);
|
||||
bool giteaBusy() const { return request_ != Request::None || serving_; }
|
||||
// Asked to make room for a TLS connection (R1, Q172): IRC steps aside while the Update Service
|
||||
// talks to Gitea. Set by the main loop; `true` to step aside, `false` to come back.
|
||||
std::function<void(bool)> holdMemory;
|
||||
// The daily check (Q165) only runs once the main loop says it may: not in Safe Mode.
|
||||
void enableDailyCheck() { dailyCheck_ = true; }
|
||||
// The version that counts as running for comparisons: a Debug Build can pretend to be older.
|
||||
std::string runningVersion() const { return fakeVersion_.empty() ? versionString() : fakeVersion_; }
|
||||
void pretendVersion(const std::string& v) { fakeVersion_ = v; }
|
||||
std::string failedVersion() const; // a release that rolled back here, "" if none
|
||||
#ifdef RORO_DEBUG
|
||||
// Debug Builds only, to try the refusals on the real network path: one HTTPS GET to any host
|
||||
// (is its certificate accepted?), and a download cut short or with one byte flipped.
|
||||
void requestProbe(const std::string& host, const std::string& path) { probeHost_ = host; probePath_ = path; probeResult_ = "..."; request_ = Request::Probe; }
|
||||
std::string probeResult() const { return probeResult_; }
|
||||
void damageNextDownload(long cutAfter, long flipAt) { damageCut_ = cutAfter; damageFlip_ = flipAt; }
|
||||
void forgetToday() { store_.putInt("rel_day", 0); nextCheckMs_ = 0; announced_.clear(); } // the daily check runs at the next tick
|
||||
#endif
|
||||
|
||||
// The main loop calls this once it has drawn a frame (part of Probation).
|
||||
void firstFrameDrawn() { firstFrame_ = true; }
|
||||
// True when an installed update is waiting to reboot; the main loop reboots when it's safe.
|
||||
bool rebootPending() const { return phase_ == Phase::Installed; }
|
||||
|
||||
private:
|
||||
enum class Request : uint8_t { None, Check, BackgroundCheck, List, Install, Probe };
|
||||
|
||||
void serve(); // on this task: one request
|
||||
bool makeRoom(); // true when a TLS connection can start; may have asked holdMemory
|
||||
void installFromGitea(const release::Release& release);
|
||||
void scheduleDailyCheck(uint32_t nowMs); // from tick()
|
||||
static void taskEntry(void* self);
|
||||
void listen();
|
||||
void install(class UpdateSource& source, const char* via);
|
||||
@@ -62,6 +101,19 @@ class UpdateService : public Service {
|
||||
std::string incoming_;
|
||||
bool probation_ = false;
|
||||
volatile bool firstFrame_ = false;
|
||||
|
||||
GiteaReleases gitea_;
|
||||
volatile Request request_ = Request::None;
|
||||
volatile bool serving_ = false;
|
||||
bool held_ = false; // IRC was asked to step aside, on this task
|
||||
std::string installTag_, fakeVersion_, announced_;
|
||||
bool dailyCheck_ = false;
|
||||
uint32_t nextCheckMs_ = 90000; // not before the device has settled
|
||||
#ifdef RORO_DEBUG
|
||||
std::string probeHost_, probePath_;
|
||||
volatile long damageCut_ = -1, damageFlip_ = -1;
|
||||
std::string probeResult_;
|
||||
#endif
|
||||
};
|
||||
|
||||
} // namespace roro
|
||||
|
||||
@@ -0,0 +1,121 @@
|
||||
#include <unity.h>
|
||||
|
||||
#include <string>
|
||||
|
||||
#include "http_head.h"
|
||||
|
||||
using namespace roro::release;
|
||||
|
||||
void setUp() {}
|
||||
void tearDown() {}
|
||||
|
||||
void test_a_head_in_pieces() {
|
||||
std::string response =
|
||||
"HTTP/1.1 200 OK\r\nContent-Type: application/json;charset=utf-8\r\nTransfer-Encoding: chunked\r\n"
|
||||
"X-Other: a: b\r\n\r\n5\r\nhello\r\n0\r\n\r\n";
|
||||
for (size_t piece : {size_t(1), size_t(9), response.size()}) {
|
||||
HttpHeadParser p;
|
||||
size_t used = 0;
|
||||
for (size_t at = 0; at < response.size() && !p.complete(); at += piece)
|
||||
used += p.feed(response.data() + at, std::min(piece, response.size() - at));
|
||||
TEST_ASSERT_TRUE(p.complete());
|
||||
TEST_ASSERT_FALSE(p.failed());
|
||||
TEST_ASSERT_EQUAL_INT(200, p.head().status);
|
||||
TEST_ASSERT_TRUE(p.head().chunked);
|
||||
TEST_ASSERT_EQUAL_STRING("application/json;charset=utf-8", p.head().contentType.c_str());
|
||||
TEST_ASSERT_EQUAL(std::string("HTTP/1.1 200 OK\r\nContent-Type: application/json;charset=utf-8\r\nTransfer-Encoding: chunked\r\nX-Other: a: b\r\n\r\n").size(), used);
|
||||
}
|
||||
}
|
||||
|
||||
void test_a_download_head() {
|
||||
std::string head = "HTTP/1.1 200 OK\r\ncontent-length: 1885712\r\nCONTENT-DISPOSITION: inline; filename=a.ota\r\n\r\n\x01\x02";
|
||||
HttpHeadParser p;
|
||||
size_t used = p.feed(head.data(), head.size());
|
||||
TEST_ASSERT_EQUAL_size_t(head.size() - 2, used); // the body isn't touched
|
||||
TEST_ASSERT_EQUAL_INT(200, p.head().status);
|
||||
TEST_ASSERT_EQUAL_INT(1885712, p.head().contentLength);
|
||||
TEST_ASSERT_FALSE(p.head().chunked);
|
||||
std::string redirect = "HTTP/1.1 302 Found\r\nLocation: https://elsewhere.example/x\r\n\r\n";
|
||||
HttpHeadParser r;
|
||||
r.feed(redirect.data(), redirect.size());
|
||||
TEST_ASSERT_EQUAL_INT(302, r.head().status);
|
||||
TEST_ASSERT_EQUAL_STRING("https://elsewhere.example/x", r.head().location.c_str());
|
||||
}
|
||||
|
||||
void test_a_head_that_is_not_http() {
|
||||
HttpHeadParser p;
|
||||
std::string junk = "\x16\x03\x01 not http at all\r\n\r\n";
|
||||
p.feed(junk.data(), junk.size());
|
||||
TEST_ASSERT_TRUE(p.failed());
|
||||
HttpHeadParser big;
|
||||
std::string endless = "HTTP/1.1 200 OK\r\n" + std::string(5000, 'x');
|
||||
big.feed(endless.data(), endless.size());
|
||||
TEST_ASSERT_TRUE(big.failed());
|
||||
HttpHeadParser odd;
|
||||
std::string status = "HTTP/1.1 999 What\r\n\r\n";
|
||||
odd.feed(status.data(), status.size());
|
||||
TEST_ASSERT_TRUE(odd.failed());
|
||||
}
|
||||
|
||||
static std::string unchunk(const std::string& in, size_t piece, bool* done = nullptr, bool* failed = nullptr) {
|
||||
ChunkedDecoder d;
|
||||
std::string out;
|
||||
for (size_t at = 0; at < in.size(); at += piece) {
|
||||
size_t n = std::min(piece, in.size() - at);
|
||||
std::string buf(n, '\0');
|
||||
size_t w = d.decode(reinterpret_cast<const uint8_t*>(in.data() + at), n, reinterpret_cast<uint8_t*>(&buf[0]));
|
||||
out.append(buf, 0, w);
|
||||
}
|
||||
if (done) *done = d.done();
|
||||
if (failed) *failed = d.failed();
|
||||
return out;
|
||||
}
|
||||
|
||||
void test_chunked_bodies() {
|
||||
std::string body = "5\r\nhello\r\n6;ext=1\r\n, worl\r\n1\r\nd\r\n0\r\nTrailer: x\r\n\r\n";
|
||||
for (size_t piece : {size_t(1), size_t(2), size_t(5), body.size()}) {
|
||||
bool done, failed;
|
||||
TEST_ASSERT_EQUAL_STRING("hello, world", unchunk(body, piece, &done, &failed).c_str());
|
||||
TEST_ASSERT_TRUE(done);
|
||||
TEST_ASSERT_FALSE(failed);
|
||||
}
|
||||
bool done;
|
||||
TEST_ASSERT_EQUAL_STRING("abc12345", unchunk("3\r\nabc\r\nA\r\n12345", 4, &done).c_str()); // cut short: what came is given
|
||||
TEST_ASSERT_FALSE(done);
|
||||
std::string hex = "1F\r\n" + std::string(31, 'x') + "\r\n0\r\n\r\n";
|
||||
TEST_ASSERT_EQUAL_size_t(31, unchunk(hex, 3).size());
|
||||
bool failed;
|
||||
unchunk("zz\r\n", 1, nullptr, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
unchunk("3\r\nabcXX", 1, nullptr, &failed); // no CRLF after the data
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
unchunk("FFFFFFFFFFFFFFFFFFFF\r\n", 1, nullptr, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
}
|
||||
|
||||
void test_urls() {
|
||||
Url u = parseUrl("https://git.twis.la/api/v1/repos/x?limit=10");
|
||||
TEST_ASSERT_TRUE(u.ok);
|
||||
TEST_ASSERT_TRUE(u.https);
|
||||
TEST_ASSERT_EQUAL_STRING("git.twis.la", u.host.c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("/api/v1/repos/x?limit=10", u.path.c_str());
|
||||
TEST_ASSERT_EQUAL_INT(443, u.port);
|
||||
u = parseUrl("http://Example.COM:8080");
|
||||
TEST_ASSERT_TRUE(u.ok);
|
||||
TEST_ASSERT_EQUAL_STRING("example.com", u.host.c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("/", u.path.c_str());
|
||||
TEST_ASSERT_EQUAL_INT(8080, u.port);
|
||||
for (const char* bad : {"", "git.twis.la/x", "ftp://a/b", "https:///x", "https://u:p@host/x", "https://host:0/x", "https://ho st/x", "https://host/a b",
|
||||
"https://host:99999/x", "https://ho_st/x"})
|
||||
TEST_ASSERT_FALSE_MESSAGE(parseUrl(bad).ok, bad);
|
||||
}
|
||||
|
||||
int main() {
|
||||
UNITY_BEGIN();
|
||||
RUN_TEST(test_a_head_in_pieces);
|
||||
RUN_TEST(test_a_download_head);
|
||||
RUN_TEST(test_a_head_that_is_not_http);
|
||||
RUN_TEST(test_chunked_bodies);
|
||||
RUN_TEST(test_urls);
|
||||
return UNITY_END();
|
||||
}
|
||||
@@ -0,0 +1,125 @@
|
||||
#include <unity.h>
|
||||
|
||||
#include <map>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
#include "json_scan.h"
|
||||
|
||||
using namespace roro::release;
|
||||
|
||||
void setUp() {}
|
||||
void tearDown() {}
|
||||
|
||||
struct Seen {
|
||||
std::vector<std::string> paths;
|
||||
std::map<std::string, std::string> values;
|
||||
std::map<std::string, bool> strings, cut;
|
||||
};
|
||||
|
||||
static Seen scan(const std::string& json, size_t piece, size_t max = 300, bool* failed = nullptr, bool* done = nullptr) {
|
||||
Seen seen;
|
||||
JsonScanner s(
|
||||
[&](const std::string& path, const std::string& value, bool isString, bool truncated) {
|
||||
seen.paths.push_back(path);
|
||||
seen.values[path] = value;
|
||||
seen.strings[path] = isString;
|
||||
seen.cut[path] = truncated;
|
||||
},
|
||||
max);
|
||||
for (size_t at = 0; at < json.size(); at += piece) s.feed(json.data() + at, std::min(piece, json.size() - at));
|
||||
if (failed) *failed = s.failed();
|
||||
if (done) *done = s.done();
|
||||
return seen;
|
||||
}
|
||||
|
||||
void test_paths_and_kinds() {
|
||||
std::string json = R"({"tag_name":"v0.10.0","draft":false,"size":1885712,"ratio":-1.5e3,"none":null,
|
||||
"assets":[{"name":"a.ota","size":12},{"name":"b.bin","size":3,"tags":[]},{"name":"c","nested":{"deep":[true,"x"]}}],
|
||||
"empty":{},"last":"end"})";
|
||||
for (size_t piece : {size_t(1), size_t(3), size_t(7), json.size()}) {
|
||||
bool failed, done;
|
||||
Seen s = scan(json, piece, 300, &failed, &done);
|
||||
TEST_ASSERT_FALSE(failed);
|
||||
TEST_ASSERT_TRUE(done);
|
||||
TEST_ASSERT_EQUAL_STRING("v0.10.0", s.values["tag_name"].c_str());
|
||||
TEST_ASSERT_TRUE(s.strings["tag_name"]);
|
||||
TEST_ASSERT_EQUAL_STRING("false", s.values["draft"].c_str());
|
||||
TEST_ASSERT_FALSE(s.strings["draft"]);
|
||||
TEST_ASSERT_EQUAL_STRING("1885712", s.values["size"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("-1.5e3", s.values["ratio"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("null", s.values["none"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("a.ota", s.values["assets[0].name"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("3", s.values["assets[1].size"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("true", s.values["assets[2].nested.deep[0]"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("x", s.values["assets[2].nested.deep[1]"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("end", s.values["last"].c_str());
|
||||
TEST_ASSERT_EQUAL_size_t(0, s.values.count("assets[1].tags")); // empty containers report nothing
|
||||
TEST_ASSERT_EQUAL_size_t(0, s.values.count("empty"));
|
||||
}
|
||||
}
|
||||
|
||||
void test_top_level_array_and_scalars() {
|
||||
Seen s = scan(R"([{"a":1},{"a":2},"x"])", 4);
|
||||
TEST_ASSERT_EQUAL_STRING("2", s.values["[1].a"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("x", s.values["[2]"].c_str());
|
||||
bool done;
|
||||
s = scan("42", 1, 300, nullptr, &done); // a number ends only when something follows it
|
||||
TEST_ASSERT_FALSE(done);
|
||||
s = scan("42 ", 1, 300, nullptr, &done);
|
||||
TEST_ASSERT_TRUE(done);
|
||||
TEST_ASSERT_EQUAL_STRING("42", s.values[""].c_str());
|
||||
}
|
||||
|
||||
void test_escapes_and_unicode() {
|
||||
std::string json = R"({"s":"line1\nline2\t\"q\" \\ \/ caf\u00e9 \u20ac \ud83d\ude00 end"})";
|
||||
for (size_t piece : {size_t(1), size_t(5), json.size()}) {
|
||||
Seen s = scan(json, piece);
|
||||
TEST_ASSERT_EQUAL_STRING("line1\nline2\t\"q\" \\ / caf\xC3\xA9 \xE2\x82\xAC \xF0\x9F\x98\x80 end", s.values["s"].c_str());
|
||||
}
|
||||
std::string key = R"({"a\"b":1})";
|
||||
TEST_ASSERT_EQUAL_STRING("1", scan(key, 2).values["a\"b"].c_str());
|
||||
}
|
||||
|
||||
void test_long_values_are_cut_on_a_character() {
|
||||
std::string json = "{\"body\":\"" + std::string(20, 'a') + "\xC3\xA9\xC3\xA9\"}"; // 24 bytes
|
||||
Seen s = scan(json, 3, 21); // room for 21: the é would be cut
|
||||
TEST_ASSERT_EQUAL_STRING(std::string(20, 'a').c_str(), s.values["body"].c_str());
|
||||
TEST_ASSERT_TRUE(s.cut["body"]);
|
||||
s = scan(json, 3, 22);
|
||||
TEST_ASSERT_EQUAL_size_t(22, s.values["body"].size());
|
||||
s = scan(json, 3, 100);
|
||||
TEST_ASSERT_FALSE(s.cut["body"]);
|
||||
// What follows a cut value is still read.
|
||||
s = scan(R"({"a":"0123456789","b":"ok"})", 2, 4);
|
||||
TEST_ASSERT_EQUAL_STRING("0123", s.values["a"].c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("ok", s.values["b"].c_str());
|
||||
}
|
||||
|
||||
void test_what_it_can_not_follow() {
|
||||
bool failed;
|
||||
scan("{\"a\" 1}", 1, 300, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
scan("{\"a\":1,,}", 1, 300, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
scan("[1,2}", 1, 300, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
scan("<html>not json</html>", 1, 300, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
scan("{\"a\":\"\\u12G4\"}", 1, 300, &failed);
|
||||
TEST_ASSERT_TRUE(failed);
|
||||
bool done;
|
||||
scan("{\"a\":[1,2", 2, 300, &failed, &done); // cut short: not an error, not done
|
||||
TEST_ASSERT_FALSE(failed);
|
||||
TEST_ASSERT_FALSE(done);
|
||||
}
|
||||
|
||||
int main() {
|
||||
UNITY_BEGIN();
|
||||
RUN_TEST(test_paths_and_kinds);
|
||||
RUN_TEST(test_top_level_array_and_scalars);
|
||||
RUN_TEST(test_escapes_and_unicode);
|
||||
RUN_TEST(test_long_values_are_cut_on_a_character);
|
||||
RUN_TEST(test_what_it_can_not_follow);
|
||||
return UNITY_END();
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
{"id":18,"tag_name":"v0.10.0","target_commitish":"","name":"roro9stack v0.10.0","body":"v0.10.0: the Notes App (plain text notes in /notes, an editor that saves by itself, up to 16 KB); e in the Storage App's text viewer; keys sent through the Debug Console are no longer swallowed now and then\n\n\n## Files\n\n- `roro9stack-v0.10.0.ota`: the signed Update File. Copy it to `/updates` on the SD card and install it from Settings > Firmware or the Storage App, or push it over Wi-Fi with `scripts/ota_push.py`.\n- `roro9stack-v0.10.0-factory.bin`: the whole flash image, for a first install over USB at offset 0.\n- `roro9stack-v0.10.0.elf.gz`: the symbols, to decode a crash report from this build.\n- `SHA256SUMS`: checksums of the three.\n\n## Changes since v0.9.0\n\n- F1 plan: Notes ships as v0.10.0\n- Notes: plain text notes on the SD card, with an editor that saves by itself (#19)\n- A key sent through the Debug Console could turn the screen \"off\" for a tick\n- F1 plan: the Notes design round (Q141-Q150)\n","url":"https://git.twis.la/api/v1/repos/twisla/roro9stack/releases/18","html_url":"https://git.twis.la/twisla/roro9stack/releases/tag/v0.10.0","tarball_url":"https://git.twis.la/twisla/roro9stack/archive/v0.10.0.tar.gz","zipball_url":"https://git.twis.la/twisla/roro9stack/archive/v0.10.0.zip","upload_url":"https://git.twis.la/api/v1/repos/twisla/roro9stack/releases/18/assets","draft":false,"prerelease":false,"created_at":"2026-10-06T08:11:31Z","published_at":"2026-10-06T08:11:31Z","author":{"id":1,"login":"twisla","login_name":"","source_id":0,"full_name":"Cl\u00e9ment Martin","email":"1+twisla@noreply.git.twis.la","avatar_url":"https://git.twis.la/avatars/db0ad25f6a366bc836e69290433c81ec","html_url":"https://git.twis.la/twisla","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2021-08-17T07:22:50Z","restricted":false,"active":false,"prohibit_login":false,"location":"Earth","website":"https://git.twis.la","description":"Owner of this nice gitea instance.","visibility":"public","followers_count":0,"following_count":0,"starred_repos_count":0,"username":"twisla"},"assets":[{"id":2,"name":"SHA256SUMS","size":278,"download_count":2,"created_at":"2026-10-06T10:24:35Z","uuid":"b72c1ea7-af35-4563-917a-9ab56a649219","browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.10.0/SHA256SUMS"},{"id":3,"name":"roro9stack-v0.10.0-factory.bin","size":1951088,"download_count":1,"created_at":"2026-10-06T10:24:35Z","uuid":"75163ae2-f495-4d5d-9883-ff773321c688","browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.10.0/roro9stack-v0.10.0-factory.bin"},{"id":4,"name":"roro9stack-v0.10.0.elf.gz","size":14345572,"download_count":0,"created_at":"2026-10-06T10:24:35Z","uuid":"8b04e7fb-fee0-46bd-8be4-3bd67a8f8804","browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.10.0/roro9stack-v0.10.0.elf.gz"},{"id":5,"name":"roro9stack-v0.10.0.ota","size":1885712,"download_count":2,"created_at":"2026-10-06T10:24:36Z","uuid":"4b827c6e-a57a-4436-b6e5-b8947e66d5ae","browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.10.0/roro9stack-v0.10.0.ota"}]}
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,146 @@
|
||||
#include <unity.h>
|
||||
|
||||
#include <cstdio>
|
||||
#include <string>
|
||||
|
||||
#include "update_check.h"
|
||||
|
||||
using namespace roro::release;
|
||||
|
||||
void setUp() {}
|
||||
void tearDown() {}
|
||||
|
||||
static std::string file(const char* name) {
|
||||
std::string path = std::string("test/test_release/fixtures/") + name;
|
||||
FILE* f = std::fopen(path.c_str(), "rb");
|
||||
TEST_ASSERT_NOT_NULL_MESSAGE(f, path.c_str());
|
||||
std::string s;
|
||||
char buf[4096];
|
||||
size_t n;
|
||||
while ((n = std::fread(buf, 1, sizeof buf, f)) > 0) s.append(buf, n);
|
||||
std::fclose(f);
|
||||
return s;
|
||||
}
|
||||
|
||||
static std::vector<Release> read(const std::string& json, size_t piece, size_t max = 10, bool* complete = nullptr) {
|
||||
ReleaseReader r(max);
|
||||
for (size_t at = 0; at < json.size(); at += piece) r.feed(json.data() + at, std::min(piece, json.size() - at));
|
||||
r.end();
|
||||
TEST_ASSERT_TRUE(r.ok());
|
||||
if (complete) *complete = r.complete();
|
||||
return r.releases();
|
||||
}
|
||||
|
||||
// The answers of git.twis.la, as they were on 2026-10-06.
|
||||
void test_latest_as_the_server_sends_it() {
|
||||
std::string json = file("latest.json");
|
||||
for (size_t piece : {size_t(1), size_t(17), size_t(1000), json.size()}) {
|
||||
bool complete;
|
||||
auto releases = read(json, piece, 10, &complete);
|
||||
TEST_ASSERT_TRUE(complete);
|
||||
TEST_ASSERT_EQUAL_size_t(1, releases.size());
|
||||
const Release& r = releases[0];
|
||||
TEST_ASSERT_EQUAL_STRING("v0.10.0", r.tag.c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("2026-10-06", r.date().c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("https://git.twis.la/twisla/roro9stack/releases/download/v0.10.0/roro9stack-v0.10.0.ota", r.otaUrl.c_str());
|
||||
TEST_ASSERT_EQUAL_UINT32(1885712, r.otaSize);
|
||||
TEST_ASSERT_TRUE(r.notes.rfind("v0.10.0: the Notes App", 0) == 0);
|
||||
TEST_ASSERT_TRUE(r.notes.find("\n\n") == std::string::npos); // the tag's message only
|
||||
TEST_ASSERT_TRUE(r.usable());
|
||||
TEST_ASSERT_TRUE(trustedAssetUrl(r.otaUrl));
|
||||
}
|
||||
}
|
||||
|
||||
void test_a_list() {
|
||||
std::string json = file("list3.json");
|
||||
for (size_t piece : {size_t(1), size_t(64), json.size()}) {
|
||||
auto releases = read(json, piece);
|
||||
TEST_ASSERT_EQUAL_size_t(3, releases.size());
|
||||
TEST_ASSERT_EQUAL_STRING("v0.10.0", releases[0].tag.c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("v0.9.0", releases[1].tag.c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("v0.8.1", releases[2].tag.c_str());
|
||||
for (auto& r : releases) {
|
||||
TEST_ASSERT_TRUE(r.usable());
|
||||
TEST_ASSERT_TRUE(r.otaUrl.find("/" + r.tag + "/roro9stack-" + r.tag + ".ota") != std::string::npos);
|
||||
TEST_ASSERT_TRUE(r.otaSize > 1000000);
|
||||
}
|
||||
}
|
||||
TEST_ASSERT_EQUAL_size_t(2, read(json, 100, 2).size()); // no more than asked for
|
||||
}
|
||||
|
||||
void test_what_makes_a_release_usable() {
|
||||
auto releases = read(R"([
|
||||
{"tag_name":"v1.0.0","draft":true,"prerelease":false,"assets":[{"name":"roro9stack-v1.0.0.ota","size":5,"browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v1.0.0/roro9stack-v1.0.0.ota"}]},
|
||||
{"tag_name":"v0.9.0-rc1","draft":false,"prerelease":true,"assets":[{"name":"roro9stack-v0.9.0-rc1.ota","size":5,"browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.9.0-rc1/roro9stack-v0.9.0-rc1.ota"}]},
|
||||
{"tag_name":"v0.8.0","draft":false,"prerelease":false,"assets":[{"size":9,"browser_download_url":"https://git.twis.la/x/SHA256SUMS","name":"SHA256SUMS"}]},
|
||||
{"assets":[{"browser_download_url":"https://git.twis.la/twisla/roro9stack/releases/download/v0.7.0/roro9stack-v0.7.0.ota","size":7,"name":"roro9stack-v0.7.0.ota"},{"name":"x.bin","size":1,"browser_download_url":"https://git.twis.la/x.bin"}],"draft":false,"tag_name":"v0.7.0","prerelease":false}
|
||||
])", 5);
|
||||
TEST_ASSERT_EQUAL_size_t(4, releases.size());
|
||||
TEST_ASSERT_FALSE(releases[0].usable()); // a draft
|
||||
TEST_ASSERT_FALSE(releases[1].usable()); // a pre-release
|
||||
TEST_ASSERT_FALSE(releases[2].usable()); // nothing to install in it
|
||||
TEST_ASSERT_TRUE(releases[3].usable()); // the fields in any order
|
||||
TEST_ASSERT_EQUAL_UINT32(7, releases[3].otaSize);
|
||||
}
|
||||
|
||||
void test_notes() {
|
||||
TEST_ASSERT_EQUAL_STRING("one two", firstParagraph(" one two \n\nsecond", false).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("one\ntwo", firstParagraph("one\ntwo\r\n\r\nthree", false).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("only", firstParagraph("only", false).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("cut...", firstParagraph("cut", true).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("whole", firstParagraph("whole\n\nrest", true).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("", firstParagraph("\n\n", false).c_str());
|
||||
}
|
||||
|
||||
void test_which_releases_are_updates() {
|
||||
Release r;
|
||||
r.tag = "v0.11.0";
|
||||
r.otaUrl = "https://git.twis.la/twisla/roro9stack/releases/download/v0.11.0/roro9stack-v0.11.0.ota";
|
||||
TEST_ASSERT_TRUE(isNewer(r, "v0.10.0"));
|
||||
TEST_ASSERT_TRUE(isNewer(r, "v0.10.0-14-gabc1234-dirty+debug")); // between releases: the next one is still newer
|
||||
TEST_ASSERT_FALSE(isNewer(r, "v0.11.0"));
|
||||
TEST_ASSERT_FALSE(isNewer(r, "v0.11.0-3-gabc1234")); // a build after the release isn't older than it
|
||||
TEST_ASSERT_FALSE(isNewer(r, "v0.12.0"));
|
||||
TEST_ASSERT_FALSE(isNewer(r, "unknown")); // a build that doesn't know its version isn't offered anything
|
||||
r.tag = "v0.10.1";
|
||||
TEST_ASSERT_TRUE(isNewer(r, "v0.10.0"));
|
||||
r.tag = "v0.9.9";
|
||||
TEST_ASSERT_FALSE(isNewer(r, "v0.10.0"));
|
||||
r.tag = "v0.11.0";
|
||||
r.draft = true;
|
||||
TEST_ASSERT_FALSE(isNewer(r, "v0.10.0"));
|
||||
r.draft = false;
|
||||
|
||||
TEST_ASSERT_TRUE(shouldAnnounce(r, "v0.10.0", "", ""));
|
||||
TEST_ASSERT_FALSE(shouldAnnounce(r, "v0.10.0", "v0.11.0", "")); // it rolled back here before
|
||||
TEST_ASSERT_FALSE(shouldAnnounce(r, "v0.10.0", "", "v0.11.0")); // already said so
|
||||
TEST_ASSERT_TRUE(shouldAnnounce(r, "v0.10.0", "v0.10.5", "v0.10.9"));
|
||||
TEST_ASSERT_TRUE(isDebugBuild("v0.10.0-3-gabc+debug"));
|
||||
TEST_ASSERT_FALSE(isDebugBuild("v0.10.0"));
|
||||
}
|
||||
|
||||
void test_only_the_projects_downloads_are_fetched() {
|
||||
const char* good = "https://git.twis.la/twisla/roro9stack/releases/download/v0.11.0/roro9stack-v0.11.0.ota";
|
||||
TEST_ASSERT_TRUE(trustedAssetUrl(good));
|
||||
TEST_ASSERT_TRUE(trustedAssetUrl("https://GIT.twis.la/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("http://git.twis.la/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la:8443/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://evil.example/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la.evil.example/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la@evil.example/twisla/roro9stack/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la/other/repo/releases/download/v1/a.ota"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la/twisla/roro9stack/releases/download/../../../x"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl("https://git.twis.la/twisla/roro9stack/releases/download/v1/a.ota?x=1"));
|
||||
TEST_ASSERT_FALSE(trustedAssetUrl(""));
|
||||
}
|
||||
|
||||
int main() {
|
||||
UNITY_BEGIN();
|
||||
RUN_TEST(test_latest_as_the_server_sends_it);
|
||||
RUN_TEST(test_a_list);
|
||||
RUN_TEST(test_what_makes_a_release_usable);
|
||||
RUN_TEST(test_notes);
|
||||
RUN_TEST(test_which_releases_are_updates);
|
||||
RUN_TEST(test_only_the_projects_downloads_are_fetched);
|
||||
return UNITY_END();
|
||||
}
|
||||
@@ -120,6 +120,18 @@ void test_pause_gnss_for_lora_is_off_by_default() {
|
||||
TEST_ASSERT_TRUE(f.settings.getBool(Setting::GnssEnabled)); // the GNSS switch itself is untouched
|
||||
}
|
||||
|
||||
// R1, Q165: the device looks for a newer release once a day. It installs nothing by itself, so it
|
||||
// is on unless switched off.
|
||||
void test_check_for_updates_is_on_by_default() {
|
||||
Fixture f;
|
||||
int row = f.row(SettingsMenu::Row::CheckUpdates);
|
||||
TEST_ASSERT_EQUAL_STRING("Check for updates", f.menu.label(row).c_str());
|
||||
TEST_ASSERT_EQUAL_STRING("Daily", f.menu.value(row).c_str());
|
||||
f.menu.toggle(row);
|
||||
TEST_ASSERT_FALSE(f.settings.getBool(Setting::CheckUpdates));
|
||||
TEST_ASSERT_EQUAL_STRING("Off", f.menu.value(row).c_str());
|
||||
}
|
||||
|
||||
void test_gnss_and_coordinate_rows_toggle() {
|
||||
Fixture f;
|
||||
int gnss = f.row(SettingsMenu::Row::Gnss), coords = f.row(SettingsMenu::Row::Coordinates);
|
||||
@@ -145,6 +157,7 @@ int main() {
|
||||
RUN_TEST(test_wifi_is_a_page);
|
||||
RUN_TEST(test_names_are_text_rows_with_their_byte_limits);
|
||||
RUN_TEST(test_pause_gnss_for_lora_is_off_by_default);
|
||||
RUN_TEST(test_check_for_updates_is_on_by_default);
|
||||
RUN_TEST(test_gnss_and_coordinate_rows_toggle);
|
||||
return UNITY_END();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user