Compare commits

...
78 Commits
Author SHA1 Message Date
twislaandClaude Opus 5.5 9f65c75f01 Merge branch 'notes': the Notes App
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:11:31 +02:00
twislaandClaude Opus 5.5 a35d82c654 F1 plan: Notes ships as v0.10.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:11:31 +02:00
twislaandClaude Opus 5.5 e8a654a15f Notes: plain text notes on the SD card, with an editor that saves by itself (#19)
The Notes App lists the files of /notes by their first line, newest first:
n starts a note, Enter opens it, r renames its file, d deletes it after
asking, s sorts by name. A new note's file is named after its first line.

The editor wraps at spaces, 38 columns by 8 rows; Fn+arrows move through
the wrapped text, Ctrl+A and Ctrl+E go to the ends of the line. There is no
save key: the note is written five seconds after the last key, on Back, on
leaving the App, when the screen turns off and before the device powers
off. A save writes a temporary file and puts it in the note's place; a save
cut short is put back, or offered, the next time.

A note is up to 16 KB, held in one buffer reserved when it's opened: the
file is read straight into it and typing never makes it grow. A failed
allocation aborts on this device, and with IRC connected the largest free
block is about 31 KB: a first version that copied the note once on loading
restarted the device when a full note was opened with IRC connected.
Editing files of any size is #47.

The Storage App's text viewer gets `e`, which edits a text file up to 16 KB
with the same editor unless the file is read-only.

439 host tests. Checked on the device: docs/milestones/F1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:08:10 +02:00
twislaandClaude Opus 5.5 c868977f1c A key sent through the Debug Console could turn the screen "off" for a tick
The `key` command stamps the power timer from millis(); the power tick
then compared with its pass's older time, and the unsigned difference read
as 49 days without a key. The screen state went Off for one tick, and the
next key was swallowed as a wake-up: about one remote key in twenty-five.
Keys from the keyboard pass the loop's own time and were never affected.
The same shape as #46. PowerPolicy::update now treats a stamp from the
future as "just now", with a test.

rdbg.py: piped lines written while it was still connecting stayed in
Python's read buffer until the next line arrived (readline() behind
select()). It reads the descriptor directly now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 10:08:10 +02:00
twislaandClaude Opus 5.5 4ab873e9f8 F1 plan: the Notes design round (Q141-Q150)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:29:38 +02:00
twislaandClaude Opus 5.5 50fcf6b7a3 Merge branch 'f1': the Storage App
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:03:50 +02:00
twislaandClaude Opus 5.5 80d68ccfd7 F1 plan: the Storage App ships as v0.9.0; the SNTP panic is #46
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 09:03:49 +02:00
twislaandClaude Opus 5.5 e14eb304b5 Wi-Fi: SNTP could be started twice at a join, and ESP-IDF asserts on that
At every join the DNS and NTP setup ran twice in the same pass: the
"check now and then" timer compared this pass's time with a stamp taken
from millis() a moment later, and the unsigned difference underflowed.
Starting SNTP is only queued for the network task, so when the second run
looked before the first had been carried out, it queued a second start:
"Operating mode must not be set while SNTP client is running", a panic
nine seconds after boot. Rare (once in the dozen or so boots of this
branch's testing), there since v0.7.0. Rollback caught it: the update
was on Probation and the device went back to the build before.

The service now remembers that it started SNTP instead of asking
esp_sntp_enabled(), and the timer compares signed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 08:52:54 +02:00
twislaandClaude Opus 5.5 b7aed8e91c F1 steps 2-6: the Storage App, its viewers, and Maintenance moved in (#3)
The Storage App browses the SD card: folders first with sizes and dates,
three sorts, one item at a time with a clipboard (c, x, v), rename, delete
after counting what's inside, new folder, details. A listing holds 256
entries and says when a folder has more.

FileOps does the card's work for the App and the console alike, one
operation at a time on the storage task in turns of about 150 ms, so Logs
and Captures are still written during a long copy. A copy shows progress,
can be cancelled (what it wrote is taken back) and compares sizes after.
The read-only rules are checked there: the firmware's top-level folders,
/gemini/cache, and files being written (a Track, a Capture, an upload,
today's IRC Logs). A listing reads the folder straight from FatFs: through
the Arduino File, 329 entries took over two seconds.

Viewers by type: text read a screen at a time whatever the file's size
(logs open at the end), a hex dump, a Capture's packets as the LoRa Scanner
lists them, a Track's summary, and an Update File checked as an install
would check it, without writing anything. Tab shows any file as hex or text.

Settings > Storage is gone: usage, Storage Clean-up and Erase are the App's
Maintenance, behind a warning. The Storage Warning points there.

The Clock sets the system time whatever its source, so files are dated
correctly with a GNSS Fix alone (Q137).

Console: cp, mv, mkdir, du, cancel; rm takes folders and follows the rules;
ls shows dates; Debug Builds get `sd fill`.

424 host tests. Checked on the device: docs/milestones/F1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 08:45:43 +02:00
twislaandClaude Opus 5.5 7ab8f043d0 F1 step 1: names, read-only rules and the packed listing (host-tested)
lib/files: path parts; names checked for rename and new folder; why
something can't be renamed, moved or deleted (the Gemini cache, a file
being written or a folder holding one, the firmware's top-level
folders), and why it can't go into a folder; the viewer for a file by
its name, with a sniff for text. FileList keeps a folder's entries
packed, 256 at most, the first 256 by name whatever order the card lists
them in, and sorts by name, date or size with folders first.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 07:37:36 +02:00
twislaandClaude Opus 5.5 63bae576ef F1 plan: the Storage App's design round (Q128-Q140)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 07:34:43 +02:00
twislaandClaude Opus 5.5 77ace09c64 Merge branch 's1': the main loop rests, and GNSS can pause for the radio
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 06:42:33 +02:00
twislaandClaude Opus 5.5 c4465675a0 S1 plan: the resting loop and the GNSS pause ship in v0.8.1
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 06:42:33 +02:00
twislaandClaude Opus 5.5 70fb37ebb5 The radio's noise: the GNSS receiver costs 8 dB; a setting pauses it (#20)
Debug Builds: `lora noise test` changes one thing at a time, Sweeps the
band, and reports the floor under each condition; it runs on the device
by itself, since one condition pauses Wi-Fi (not saved, so a restart
brings it back). Result, at 125 kHz: -117 dBm with the antenna switched
off, -106 with the GNSS receiver in standby, -98 with it running. The
receiver's serial line isn't it (one sentence a second changes nothing),
and neither are the main loop, the CPU frequency, Wi-Fi, the screen or
the radio's own regulator, all within 1 dB.

Settings > "Pause GNSS for LoRa", off by default: the receiver waits in
standby while the radio listens or sweeps, except during a Track, and
has a Fix again about 7 s after. The GNSS App says it's paused.

11 dB remain between the antenna with GNSS quiet and the chip alone,
untouched by anything that can be switched from the firmware.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 03:41:15 +02:00
twislaandClaude Opus 5.5 06a593293d The main loop rests between passes (#40)
It made 50,000 passes a second and kept core 1 100 % busy at rest. Keys
are buffered by the keyboard controller, the consoles and the radio have
their own tasks, and no Service ticks more often than every 50 ms, so
the loop now rests 5 ms after a pass with the screen on and 20 ms with
it off; never during a serial file transfer. Safe Mode's loop too.

Screen off: 50 passes a second and core 1 at 1 %; screen on: 167 and
10 %. The chip settles 4 C cooler (34.3 against 38.3). GNSS, Gemini, an
upload, the Sweep and the radio's interrupt all checked at the new pace.
`tasks` shows the loop's passes; Debug Builds: `loop spin on|off`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 03:08:02 +02:00
twislaandClaude Opus 5.5 9078ab9c39 Merge branch 's1': the System App, and traffic counted per service
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:32:01 +02:00
twislaandClaude Opus 5.5 06aa3fe28b S1 plan: the System App ships in v0.8.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:32:01 +02:00
twislaandClaude Opus 5.5 e36aa50922 S1 #11: the System App: tasks, memory, network and system, live
Five views, Tab between them: Overview (each core's load, memory,
traffic, battery, two minutes of load), Tasks (share of a core over the
last second, lowest free stack, flagged under 512 bytes; `s` sorts),
Memory (free heap against the floors of Q86), Network (bytes per
service, and what's moving now), System (what `info` prints, plus
battery, card, radio, GNSS). It samples once a second and keeps history
only while open.

The arithmetic is host-tested, including the trap found on the device: a
task's run-time counter only moves when it's switched out, so the task
that samples (the main loop, alone on its core) gets what's left of its
core. `tasks` now samples across a second of normal running instead of
inside its own wait. The main loop uses 100 % of core 1 at rest (#40).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:28:26 +02:00
twislaandClaude Opus 5.5 70bb2a4137 S1 #11: bytes read and written, counted per network service
A Counted<> wrapper around the network clients adds what goes through
their buffer read and write to a per-service counter (IRC, Gemini, Debug
Console, Updates); the single-byte calls and print() end up there, so
each byte counts once. `net` prints the totals. For TLS it's the plain
text the service sees.

Checked on the device: a Gemini fetch counts 164,986 in (a 164,970-byte
page and its 16-byte header) and 42 out (the URL and CRLF).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:10:55 +02:00
twislaandClaude Opus 5.5 1df94b684a S1 #11: the System Monitor's design round (Q117-Q127)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 01:04:41 +02:00
twislaandClaude Opus 5.5 00f69e8d53 S1 plan: fixed IPv4 shipped in v0.7.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:55:32 +02:00
twislaandClaude Opus 5.5 f834095ee3 Merge branch 's1': fixed IPv4 addresses, DNS and NTP servers
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:48:41 +02:00
twislaandClaude Opus 5.5 acf7697bdc S1 #7 step 4: fixed IPv4, DNS and NTP in Settings
Enter on a Saved Network opens its page instead of asking to forget it:
"IP address" switches between Automatic and Fixed, with an address, a
prefix and an optional gateway. Fixed starts from what the network is
giving the device; the draft is checked and applied on leaving the page,
so a half-typed address is never used. "DNS and NTP" holds the two DNS
servers, "Always use my DNS" and the two NTP servers. Enter on Status
shows the connection's details and where each value came from. Address
fields take digits and dots only; refusals show as Toasts.

Checked on the device through the screens: Fixed 10.39.39.13 applied and
reverted to Automatic, a prefix of 99 refused. Measurements in
docs/milestones/S1.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 00:04:53 +02:00
twislaandClaude Opus 5.5 3e279738b6 S1 #7 step 3: the Wi-Fi Service applies IP, DNS and NTP settings
Joining a Saved Network uses its Fixed address, mask and gateway, or
DHCP. DNS comes from Settings on Fixed networks and when "Always use my
DNS" is on; NTP servers come from Settings, after any that DHCP offered.
Both are re-checked every 30 s, since a DHCP renewal puts DHCP's DNS back
and clears the NTP slots it didn't fill. `wifi status` shows what's in
use, where it came from, and which NTP servers answered; `wifi ip`,
`wifi dns`, `wifi ntp`. Debug Builds: `wifi ip ... try <s>` reverts
unless kept.

On knbg-guests (10.39.39.0/24, gateway .1): Fixed .12 and .13 both reach
the internet through 9.9.9.9; a wrong gateway on trial cut the device off
and came back by itself; back to DHCP; both NTP servers answer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:52:22 +02:00
twislaandClaude Opus 5.5 bdd027cb50 S1 #7 steps 1-2: IPv4 checks, the IP setting per Saved Network, DNS and NTP settings
The plan and decisions Q105 to Q116 (docs/milestones/S1.md). lib/net:
strict IPv4 parsing, prefix and mask, and the checks a Fixed setting must
pass, each refusal with its reason. A Saved Network is Automatic or Fixed
(address/prefix and an optional gateway), kept with it in flash. Settings:
two DNS servers (9.9.9.9, 1.1.1.1), "Always use my DNS", two NTP servers
(pool.ntp.org, time.cloudflare.com). Host-tested: 383 tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:39:07 +02:00
twislaandClaude Opus 5.5 7e8882d9cb Merge branch 's1': the SD driver's ready test, and sd card
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:25:55 +02:00
twislaandClaude Opus 5.5 7b2cf88a0a ADR 0007: link the upstream report and the issue that follows it
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:16:17 +02:00
twislaandClaude Opus 5.5 370f067fbf sd card: what the card says it is, from its CID register
Type, size, and the identity register read by our SD driver (CMD10):
manufacturer, OEM, product name, revision, serial and date, decoded by a
host-tested parser. Needed for the upstream report of #21: nothing else
here could read the card's identity. This one is a Samsung 8 GB SDHC
from June 2013.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 23:15:29 +02:00
twislaandClaude Opus 5.5 3f2650c56e SD driver: a dummy byte before the ready test; say why a write failed (#21)
The card "refused" a write about once in 2,000 multi-block writes: three
1.7 MB uploads in ten. Measured with a driver that records where it gives
up: every time, all blocks were accepted, and the status check after Stop
Tran came back as 0xFF or 0x1F. The driver tests for ready with the first
byte after selecting the card, which reads 0xFF before the card has
signalled busy, so CMD13 went out mid-programming. A dummy byte first, as
in ChaN's reference driver, and one after Stop Tran.

30 uploads in a row since, each read back by SHA-256, ten with the radio
listening: no fault. 10 MHz made no difference; the card stays at 20 MHz.

`info` shows the driver's write faults; `put` prints the step and the
card's answer when one happens. ADR 0007.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 22:55:02 +02:00
twislaandClaude Opus 5.5 3ee7ae1097 lib/SD: Arduino-ESP32 3.3.12's SD library, as it comes
A project library named SD takes the framework's place at link time.
Unchanged here (Apache-2.0), so that the next commit shows exactly what
roro9stack changes in it, and a later framework update can be compared.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 22:51:59 +02:00
twislaandClaude Opus 5.5 60cec80fa4 Merge branch 'm3': the LoRa radio, receive only, and the LoRa Scanner
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 21:40:43 +02:00
twislaandClaude Opus 5.5 4744163683 M3 done: the listening hour heard nothing; a reference node is needed for M4
Outside, on battery, an hour on LongFast with a Capture running: 0
packets, 0 headers. The noise is no lower than at the desk and its peaks
follow the device, so about 15 dB of the floor is the Cardputer's own
(issue #20). With IRC on TLS and the radio listening, 52.6 KB free. One
"Done when" item is half met: Sweep was never tried against a known
transmitter. The card's refused writes are issue #21.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 21:40:30 +02:00
twislaandClaude Opus 5.5 b1de0f8804 M3 step 5: Sweep, the band's signal strength as bars and a waterfall
Tab in the LoRa Scanner sweeps 863-870 MHz in 100 kHz steps (the
strongest of three RSSI readings at each, at 125 kHz), shown as bars with
peak hold over a waterfall, the Sniffer's frequency marked (Q98). The
Sweep pauses the Sniffer and keeps its packets; Tab resumes it (Q99).
Status Bar: SW. The floor, top and peaks are host-tested; `lora sweep
on|off|dump` prints them on the console.

At the desk: about 607 ms a pass, a flat floor at -100 to -102 dBm
(15 dB above the chip's own) and a steady carrier at 863.2 MHz.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 20:28:46 +02:00
twislaandClaude Opus 5.5 2fce79aebd M3 step 4: the LoRa Scanner App, Sniffer and Captures
The Sniffer lists packets newest first (time, RSSI, SNR, and for
Meshtastic the sender, receiver and hops), with the clear header and a
hex dump on Enter (Q96); `p` picks an EU868 preset, kept in Settings
(Q95). `c` starts a Capture: pcap with LoRaTap in /captures/lora, its own
Clean-up category, recorded by a small Service so it carries on with the
App closed (Q97, Q100). The Status Bar shows L while listening, bright on
each packet, and CAP while capturing (Q101). StorageService gains raw
appends for binary files. Debug Builds get `lora inject` to test all of
this with no transmitter in range: a Capture made on the device reads
back in TShark field for field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 20:14:58 +02:00
twislaandClaude Opus 5.5 594748e99a M3 step 3: the Radio Service, receive only
One task owns the SX1262 and does all its SPI behind the card's bus lock;
the main loop posts requests and DIO1 only wakes the task. It listens
while a client asks (App, Capture, Console) and sleeps otherwise, with a
ring of the last 32 packets (9.8 KB, freed when idle). No transmit path.
The Cap's antenna switch (expander P0) is set on the main loop, which
owns the I2C bus. `lora probe` now runs on the radio task and checks the
DIO1 interrupt with a receive timeout; `lora status`, `lora rx on|off`,
`lora preset`, and `lora custom` for other LoRa settings.

Measured: DIO1 works (timeout after 105 ms); four 1.7 MB uploads and
Gemini pages to the card while listening, no radio or card errors; task
stack peak 2.0 KB. Twenty minutes on LongFast and LoRaWAN: no packets,
and a noise floor of -83 to -94 dBm at the desk.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:49:46 +02:00
twislaandClaude Opus 5.5 30a827070b Gemini: count the App's per-line tables in the page budget
Found in M3 while checking floors with the radio on: a windowed page left
1.5 to 3 KB less than the 40 KB steady floor (Q86), radio or not. The
budget counted TextBuffer's index (8 B/line) but not the App's tables,
which also grew by doubling. Now 16 B/line, and the App sizes them
exactly. The FAQ (1051 lines, windowed): 38.5 -> 39.6 KB after, radio
asleep; 37.1 -> 39.0 KB with the radio listening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:19:52 +02:00
twislaandClaude Opus 5.5 a0e3868934 Debug Console put: verify the card's copy, never zero-fill after a failed write
Found by M3's shared-bus test: when the card refused a write, the retry
closed the file (losing up to 3 KB of earlier chunks still in the write
buffer), then truncate() extended it back with zeros. The checksum only
covered the received bytes, so `put` reported success with 3 KB of zeros
on the card. Now a retry gives up if the card lost data, and the finished
file is read back and must hash the same before it's renamed.

The card refuses a write about once in five 1.7 MB uploads, with the
radio asleep as often as listening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 19:13:25 +02:00
twislaandClaude Opus 5.5 3242475699 M3 step 2: Meshtastic header and presets, pcap with LoRaTap (host-tested)
The 16-byte clear header (hops away, channel hash, relay node), the EU_868
presets and their frequency slots, and the channel hash, all checked
against Meshtastic's source. Captures are pcap with LoRaTap v0, read back
with TShark 4.2.5; packet RSSI is plain dBm, as Wireshark reads it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:59:23 +02:00
twislaandClaude Opus 5.5 fed065a6f9 M3 step 1: RadioLib and lora probe
The probe finds the SX1262 (TCXO 1.8 V works) and measures the antenna
path: the Cap's PI4IOE5V6408 at 0x43 must drive P0 high, or the receiver
is deaf (-111.9 dBm flat vs -87 to -94 dBm with P0 high). DIO2 makes no
difference to reception. Receive only; the radio is left asleep.

RadioLib 7.8.1 + probe: +23.6 KB flash, +656 B static RAM (release).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:52:38 +02:00
twislaandClaude Opus 5.5 6485f277b5 M3 plan: radio bring-up, receive only (Q89-Q104)
The Radio Service owns the SX1262 and shares the SPI bus with the card;
the LoRa Scanner shows packets (Sniffer) and the band (Sweep). Nothing in
M3 can transmit. Notes and the File Browser move to issues #19 and #3.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 18:44:25 +02:00
twislaandClaude Opus 5.5 0a2f46b428 Merge branch 'g1': a Gemini client, with Saved Pages for offline reading
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:49:13 +02:00
twislaandClaude Opus 5.5 dafbdaddf6 G1 done: Saved Pages read offline, checked by hand
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:49:12 +02:00
twislaandClaude Opus 5.5 fe886e2c1d G1: accept a ~12 KB heap dip during a fetch with IRC connected (Q86 revised)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:47:59 +02:00
twislaandClaude Opus 5.5 9ca9a16de8 Gemini: read big pages from the card as you scroll (Q88)
A page larger than memory allows is now windowed instead of cut: one
pass over its file (cache or Saved Page) counts lines, indexes every
64th (offset, and the preformatted state there in bit 31: about 1 KB
for a 1 MB page) and loads the first window. Scrolling near either end
reads the next or previous window on the Gemini task; the line on top
of the screen stays put, the scrollbar follows the whole page, and Tab
at a window's edge pages on instead of wrapping. Window budgets count
the memory the old window gives back.

Display pages alternate between two cache files so the one on screen
is never overwritten by the next fetch; jobs use a third.

On the device, Cosmos with IRC connected: 226 of 419 lines at first,
then lines 192-419, back to 64 and 0 while scrolling. `key space` added
to the console's key command.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:44:01 +02:00
twislaandClaude Opus 5.5 fd306d5013 G1 steps 5-6: input prompts, bookmarks, downloads, Saved Pages
Everything touching the network or the card is a job on the Gemini
task (a missing card can block 5 s, past the main loop's watchdog):
about:start is composed from /gemini/bookmarks.gmi and the Saved Pages
(by capsule, newest first); file:// opens a Saved Page; s, S, r, d, b
and downloads report one line to the URL bar, S with progress Toasts.

A Saved Page is the cached body with a first line "> Saved from <url>
on <date>": it shows as a quote and gives relative links their base;
inside one, links to other Saved Pages open the saved copy, others go
online or say "Not saved, and offline". Input prompts (11 masked)
request the same URL with the answer as its query.

Fixed on the way: re-wrapping indented lines rebuilt the text from its
rows, inserting a space where a long word had been cut; refreshing
loaded the whole Saved Page next to a TLS connection (heap down to 436
bytes), now it reads one line and every fetch checks the 55 KB floor.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:24:29 +02:00
twislaandClaude Opus 5.5 10f3ff7a4c G1 step 4: the Gemini App (rendering, links, history, address line)
Gemtext as Q75 has it: headings bold (# in the accent colour), lists
with a middle dot, quotes muted, links as » labels, preformatted lines
unwrapped and scrolled sideways together; other text/* as is. Pages are
wrapped once for each line's first row (4 bytes a line) and only the
lines on screen are wrapped again to draw. Tab and Shift+Tab move
between links, Enter follows (relative links resolved), Back or Delete
go back to where the page was scrolled, g opens the address line.
Non-Gemini links say so in the URL bar; a changed certificate opens a
dialog; errors and refusals get a page with a "Try again" link; a page
only partly in memory says why at its end.

A status message timed with millis() after the loop's clock read was
cleared before it was drawn (unsigned wrap): now a signed comparison,
as for the toasts in M0.

Verified on the device: start page, Project Gemini, its relative news/
link, Back with the scroll restored, and the YouTube link refused.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 01:07:23 +02:00
twislaandClaude Opus 5.5 7b8d9391a4 G1 step 3: the Gemini fetcher (TOFU, redirects, floors, pages via the card)
GeminiService fetches on a short-lived task and hands the App a
GeminiPage: header, the body as lines in 4 KB chunks (TextBuffer: no
large block, no doubling copies), the final URL after up to 5
redirects. Certificates are pinned on first use per host and port; a
change comes back as its own outcome with both fingerprints. No fetch
starts below 55 KB free (Q86).

With a card, the body streams to /gemini/cache/page.gmi in 1 KB pieces
while the connection is open, then loads into RAM once its memory is
back (Q87); StorageService::runAndWait (moved from the Debug Console)
keeps every card access on the storage task. Without a card: RAM, with
the steady and transient floors.

Measured with IRC connected: Cosmos (31.6 KB) went from 4.6 KB to the
whole page on the card and 20 KB on screen; lowest free heap 19.5 KB
in transfer, 43 KB once loaded. `gemini get` and `gemini trust` on the
console. 14 Gemini tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 00:58:01 +02:00
twislaandClaude Opus 5.5 babb1d114e G1 step 2: Gemini parsers (host-tested), and the memory decision (Q86)
lib/gemini: URLs split per RFC 3986 appendix B and resolved per section
5.2 (all 32 reference examples of 5.4 pass, with gemini:// for http://),
the request form (no fragment, lower-case host, never an empty path),
query encoding for input prompts, Saved Page paths; the response header
(status, category, MIME type and parameters, 1024-byte meta limit);
gemtext's line types; and display text for the Latin-1 fonts. 12 tests.

Q86, decided after step 1: free heap stays above 40 KB in steady state
and 20 KB during a handshake; a fetch won't start below 55 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 00:29:55 +02:00
twislaandClaude Opus 5.5 2d384f5cff G1 step 1: gemini get, and two TLS connections measured
`gemini get <url>` fetches on a short-lived task (a handshake would trip
the main loop's watchdog; an idle client should cost no stack) and
reports the header, size, certificate fingerprint and heap. First page:
geminiprotocol.net, 20 text/gemini, 1,184 bytes in 0.7-1.1 s.

With IRC connected over TLS, a fetch dips to about 24 KB free during its
handshake, about 36-40 KB after it; nothing leaks. Antenna is down, so
the default aggregator becomes Cosmos.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 00:27:05 +02:00
twislaandClaude Opus 5.5 dc9b0e14ce G1 design: Gemini client plan, glossary (Capsule, Saved Page)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-05 00:18:01 +02:00
twislaandClaude Opus 5.5 dc4b49755a Merge branch 'm2': GNSS, and the memory back
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 23:42:41 +02:00
twislaandClaude Opus 5.5 fff28af961 Rebuild the framework with smaller TLS buffers (ADR 0006)
custom_sdkconfig makes pioarduino regenerate the ESP-IDF libraries:
asymmetric TLS buffers (16 KB in, 4 KB out) and dynamic buffers that
free handshake-only data once connected. The rebuild also follows the
board: no PSRAM, 8 MB flash. The project now carries the partition
table the hybrid build needs (identical to the framework's: the app
slots must not move under updates over the air). Generated files are
ignored.

Debug Build, GNSS on, IRC on TLS: 78 KB free and a 59 KB low (M2 began
at 31 KB and 12.6 KB; the floor is 40 KB). The full stress set passes
on it: refused installs over Wi-Fi and from SD, put/get, screenshot,
core dump decode, Probation; under all of it at once, the low is 46 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 23:32:29 +02:00
twislaandClaude Opus 5.5 4e439410cd Stop IRC by hand; remove mDNS
IrcService::disconnect() stops the session from any state: QUIT if
connected, then no more retries. /quit goes through it (before, it only
stopped a connected session; while waiting for Wi-Fi or retrying it did
nothing), and so does the new `irc stop` command. Stopped by hand,
opening the IRC App no longer reconnects; typing a line does.

mDNS is gone: it never crossed the dev box's routed network, and it
cost about 7.5 KB of RAM. Pushes go to the IP shown in Settings ->
Firmware, which drops its Name row. OTA Q54 records the change.

On the device, Debug Build: 105.6 KB free with Wi-Fi (was 98); with IRC
on TLS 54 KB free (was 46); after `irc stop`, back to 99 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 23:17:48 +02:00
twislaandClaude Opus 5.5 db265fb757 Trim task stacks and buffers by measurement: +15 KB with IRC up
Peak stack use was measured through each task's worst case (an
ECDSA-checked install over Wi-Fi and from SD, get/put, a core dump
fetch, an IRC TLS handshake); stacks are now peak plus about 2 KB: loop
8 -> 6 KB, update 8 -> 5, storage 10 -> 6, irc 8 -> 6. The Debug Build's
console ring goes 6 -> 4 KB, serial TX 2 -> 1 KB, the GNSS UART buffer
1 KB -> 512 B.

On the device, with IRC on TLS: 46 KB free (was 31), an 18 KB low (was
9.4). The re-run of every worst case left at least 1.6 KB of stack free
in each task.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 23:02:35 +02:00
twislaandClaude Opus 5.5 578a39d3c1 M2: record cold-start time to first fix and the heap measurement
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:52:07 +02:00
twislaandClaude Opus 5.5 d7952612dd M2 step 6: Tracks, recorded to GPX in the background
`r` in the GNSS App (or `gnss track start|stop`) records a Track to
/gnss/tracks/YYYYMMDD-HHMMSS.gpx: a point every 5 s once moved 5 m
(lib/gnss/track, 7 tests: haversine, the rule, GPX text, the file name).
It keeps recording with the App closed, shows REC in the Status Bar, and
announces start and stop with a Toast. It needs a card and the time;
switching GNSS off stops it. Tracks are written like Captures: past 90 %
card usage, until full. Storage Clean-up gets a GNSS tracks category.

A Track cut short by a reset or power loss has no GPX footer; the GNSS
Service closes such files at the next boot.

Verified on the device: a recorded Track and one interrupted by a reset
both parse as GPX 1.1 on the PC.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:46:57 +02:00
twislaandClaude Opus 5.5 463ed2dda8 M2 step 5: GNSS App, with the Position and Sky views
Position: the Fix line (or how long it has been searching), latitude and
longitude in decimal degrees or degrees-minutes-seconds (Settings ->
Coordinates), the Maidenhead locator, altitude, speed and course, HDOP
and UTC. Sky: the satellites by azimuth and elevation, coloured by
constellation, filled when used in the Fix, with used/in-view counts.
Tab switches. lib/gnss/geo_format holds the formatting, the locator and
the sky projection, host-tested (6 tests; locators checked against
FN31pr and JN58td).

Verified on the device by a window: 3D Fix from GPS, GLONASS, Galileo
and BeiDou.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:38:06 +02:00
twislaandClaude Opus 5.5 d408bada07 M2 step 4: GNSS mark in the Status Bar; the clock follows the Fix
Q61: a muted G while searching (or the receiver is silent), G with a 2D
Fix, G and the satellite count with a 3D Fix; nothing when GNSS is off.
Verified on the device by a window: 3D Fix, 9 of 11 satellites used
(GPS, GLONASS, BeiDou), HDOP 1.3, Status Bar "G9", and "gnss: clock set".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:29:20 +02:00
twislaandClaude Opus 5.5 988253ef02 M2 step 3: GNSS Service, with standby and the clock from a Fix
The GNSS Service reads the receiver (UART 15/13, 115200, 1 KB buffer)
from its 50 ms tick and feeds the NMEA parser. With a Fix it sets the
clock (GNSS is the most trusted TimeSource) and refreshes it every 10
min. Settings gets GNSS On/Off and the coordinate format (Q64).

Off puts the receiver in standby with $PCAS12,65535, renewed hourly; On
wakes it with a hot start, $PCAS10,0. Both measured on the device: the
output stops within a second, and a command wakes it within a second.

Commands: gnss status (Fix, satellites per constellation, bytes and
sentences), gnss nmea on|off, gnss send <sentence>, gnss restart. The
probe is gone; never drive GPIO 15 (the receiver's output): the first
probe's swapped-pin attempt silenced it until a power cycle.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:26:53 +02:00
twislaandClaude Opus 5.5 c9b1ecb772 M2 step 2: NMEA parser (host-tested)
lib/gnss: RMC, GGA, GSA and GSV into one GnssState: Fix type, position,
altitude, speed, course, HDOP, UTC time (trusted only with a Fix) and the
satellites in view across constellations. GSV sequences are kept per
constellation and signal band and merged per satellite with the stronger
SNR; GSA's system ID marks which satellites are used. 16 tests, using
lines captured from the device.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:05:01 +02:00
twislaandClaude Opus 5.5 f812c62a3d M2 step 1: gnss probe finds the receiver on RX 15 / TX 13 at 115200
A temporary `gnss probe` command listens on both pin orders at 115200
and 9600. Only RX 15 / TX 13 at 115200 carries NMEA, as Meshtastic's
board file says; M5Stack's GPIO 8/9 are the keyboard's I2C bus. The
output format (NMEA 4.10, GSA system IDs, GSV per signal) is recorded in
docs/milestones/M2.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:05:01 +02:00
twislaandClaude Opus 5.5 9c30d47982 M2 design: GNSS plan, glossary (GNSS Service, Fix, Track), ADR 0001 note
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 22:00:09 +02:00
twislaandClaude Opus 5.5 634a20c339 key command: del and tab
The serial and Debug Console `key` command could type characters but not
erase them, so text typed into a field by mistake couldn't be cleared
remotely. `key del` and `key tab` inject Delete and Tab.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 21:27:40 +02:00
twislaandClaude Opus 5.5 2c63e9fd6e Merge branch 'ota': Firmware Updates, Debug Builds, Safe Mode
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 18:14:26 +02:00
twislaandClaude Opus 5.5 388e847cd4 Debug Console: files, screenshots and Update from SD over Wi-Fi
New commands everywhere: ls, rm and install <path> (Update from SD
without the Firmware page), all as Storage Service jobs. In Debug
Builds the console task answers get and put (one storage job per
transfer, file kept open, TCP flow control: about 300 KB/s, against
55 KB/s over serial) and screenshot (the RGB332 frame the UI composes
into). rdbg.py turns those into files and PNGs.

A failed put closes the connection: the rest of the file had been
parsed as commands. Card writes are retried 3 times after closing,
truncating to the last good byte and reopening, since FATFS keeps a
file in error after one failed write (seen once at 1.3 MB on this card).
onStorage() decides with one compare-and-swap whether the job or the
timeout wins, so an abandoned job can't touch a returned stack frame.

Verified on the device: screenshot; a get round trip byte-identical;
4 puts in a row; a tampered .ota refused by install; a good one put,
installed from SD, confirmed on Probation. The retry path itself has
not fired since it was added.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 03:18:23 +02:00
twislaandClaude Opus 5.5 14ff13f634 Safe Mode, crash reports, and a watched main loop
Every build now records at boot which version runs and, after a crash
restart, which one crashed (even across a Rollback). The core dump
summary (task, PC, reason, backtrace) is printed and raised as a
Notification; `crash` shows it later. After 3 crash restarts in a row
the firmware starts in Safe Mode: clock, Wi-Fi, Update Service and Debug
Console only (SafeMode, 2 host tests). A normal restart or a minute up
resets the count.

The main loop is now on the task watchdog (enableLoopWDT): Arduino only
watched core 0's idle task, so a stuck loop hung the device for good.
The Update Service restarts into an installed update by itself if the
main loop hasn't after 90 s.

Debug Builds: `coredump get` and `reset` are answered by the console's
own task; rdbg.py crash decodes the backtrace and rdbg.py coredump runs
esp-coredump, against ELFs archived by version and digest in .pio/elves.

The StorageService mutex is now made in the constructor: Safe Mode never
starts that Service, and `info` crashed on the null mutex, 29 times in a
row before the fix was pushed into Safe Mode over Wi-Fi.

Verified on the device: crash report and full core dump decoded over
Wi-Fi; Safe Mode at exactly 3 crashes, left by `reboot`; a hung loop
caught by the watchdog in 5 s; `reset` from the console task. ADR 0005.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 03:07:56 +02:00
twislaandClaude Opus 5.5 0fb7f4e9d5 Debug Builds: the console over Wi-Fi (Debug Console, TCP 2323)
cardputer-adv-debug (-DRORO_DEBUG, version +debug) adds a Debug Console:
after a token line, a client gets the last 6 KB of console output, live
lines (ESP-IDF logs included) and the serial commands. The socket task
only queues lines; the main loop runs them. Release builds compile none
of it. The token lives in ~/.config/roro9stack/debug-token, created by
_docker.sh and passed into the container.

All output now goes through `console`, which never waits for USB: a host
that was attached but not reading stalled the main loop up to 2 s per
line. New commands everywhere: info (slots with their versions from NVS,
since the framework stamps its own into each image), tasks, reboot,
boot other, log level, help. scripts/rdbg.py is the client; flash.sh
--debug builds it; CI builds both variants. ADR 0004.

Verified on the device: USB-flashed, then updated over Wi-Fi to a Debug
Build that confirmed on Probation; both slots hold Debug Builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 02:44:14 +02:00
twislaandClaude Opus 5.5 5b199c2436 sd put: copy a file to the SD card over USB serial
scripts/sd_put.sh <file> [card path] sends a file (by default into
/updates, for Update from SD) without taking the card out. The serial
driver drops bytes once its receive buffer is full, so the transfer is
stop-and-wait: 1 KB chunks, each acknowledged once the Storage Service
has written it, into a 2 KB receive buffer. The device checks the
SHA-256 before renaming <path>.part into place, and gives up after 5 s
of silence or a card job that never returns. FileReceiver holds the
logic, with 12 host tests. About 55 KB/s: 1.6 MB in under 30 s.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 02:31:19 +02:00
twislaandClaude Opus 5.5 8ec4e9e449 ADR 0003: the bootloader does roll back; Arduino had validated the image
Verified on the device: a crashing update pushed over Wi-Fi died once,
and the next boot was the previous firmware, with the "Update ... failed"
Toast. bootGuard() stays as a second line.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 02:15:38 +02:00
twislaandClaude Opus 5.5 7afe6b7d17 OTA: keep new images on Probation; Arduino validated them before setup()
Arduino-ESP32's initArduino() marks a PENDING_VERIFY image valid unless
the sketch overrides the weak verifyRollbackLater(). Every update was
therefore VALID before bootGuard() or Probation ever ran (otadata read
back state 0x2 on a crash-looping test build), and nothing rolled back.
The bootloader was never the problem. Override it to return true, so
Probation decides.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 02:12:45 +02:00
twislaandClaude Opus 5.5 45542dcbff OTA: the firmware rolls itself back; the bootloader doesn't
A deliberately crashing update looped forever on the device: the
prebuilt bootloader ignores ESP_OTA_IMG_PENDING_VERIFY despite the
app-side rollback config. UpdateService::bootGuard() now runs first in
setup(): it counts starts on Probation in NVS and, on the second
unconfirmed start, marks the image invalid and reboots into the
previous one. Confirming (or the Wi-Fi rollback) resets the counter.
ADR 0003 records the limit: a crash in the first milliseconds still
needs USB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:48:39 +02:00
twislaandClaude Opus 5.5 de5931210f OTA: clean refusal report in ota_push.py; shorter signature error
The device refuses at the header and hangs up mid-transfer; the push
client now says so instead of crashing on the reset. The error fits a
Toast (47 characters).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:43:03 +02:00
twislaandClaude Opus 5.5 08b59eb203 OTA: answer once the announced image size has arrived
The Arduino network client treats a half-closed connection as closed,
so the device's reply after the sender's EOF was lost. The header
already carries the image size: UpdateParser::complete() lets the
device finish and answer while the connection is open. ota_push.py
half-closes only if no answer comes within 3 s, for older firmware.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:39:35 +02:00
twislaandClaude Opus 5.5 fa62a07993 README: Firmware Updates over Wi-Fi and from the SD card
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:37:29 +02:00
twislaandClaude Opus 5.5 21b3d9e422 OTA steps 3-5: Update Service, Probation and Rollback, Update from SD
- EcdsaVerifier (mbedTLS, embedded public key) and EspOtaSink (writes
  the inactive app slot, esp_ota_end validates the image, then sets
  the boot partition)
- UpdateService: listens on TCP 3232 (and mDNS roro9stack-<id>) while
  Wi-Fi is Connected; streams into UpdateParser; replies OK/ERR to the
  sender; remembers the pending version so a Rollback is reported
  after the reboot
- Probation (host-tested): confirm after the first frame + 30 s + Wi-Fi
  (if configured); roll back if configured Wi-Fi never connects in 3 min
- Main loop: full-screen progress while receiving; restart once
  installed, waiting up to 60 s for Text Entry to end
- Settings > Firmware: version, Probation status, push address and
  name, and the .ota files in /updates on the SD card to install
- StorageService.runJob() runs work on the storage task (SD installs)
- wifi status prints IP and running version; RORO_TEST_CRASH test hook

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:35:33 +02:00
twislaandClaude Opus 5.5 90cb6ef9b2 OTA step 2: signing key, Update File builder, push client
- scripts/ota_keygen.sh: ECDSA P-256 key pair; the private key goes to
  ~/.config/roro9stack/ (0600), the public key to keys/ and
  src/platform/ota_public_key.h; .gitignore refuses *key.pem
- scripts/make_ota.py: wraps firmware.bin into a signed .ota (openssl)
- scripts/ota_push.py: sends it over TCP 3232, prints the device's answer
- scripts/flash.sh --ota <host>: build, sign, push

Checked: a generated .ota has the documented layout and its signature
verifies with openssl against the committed public key.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:31:39 +02:00
twislaandClaude Opus 5.5 326e864264 OTA step 1: Update File format and streaming parser (host-tested)
lib/ota: a 160-byte header (magic, format, image size and SHA-256,
version, ECDSA signature over the first 80 bytes) then the image.
UpdateParser checks the header and signature before writing anything,
hashes the image as it streams into an UpdateSink, and only finishes
the sink when the hash matches. Downgrades are flagged, not refused.
Includes a dependency-free SHA-256 and semver comparison.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:30:13 +02:00
twislaandClaude Opus 5.5 e9efbcca4d OTA design: glossary, ADR 0003 (own signature check), plan
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-03 21:27:04 +02:00
188 changed files with 18691 additions and 210 deletions
+8
View File
@@ -1,3 +1,11 @@
.pio/
.vscode/
*.pyc
# Private signing keys never belong in the repository (ADR 0003)
*key.pem
# Generated by pioarduino's hybrid compile from custom_sdkconfig (platformio.ini)
.dummy/
managed_components/
sdkconfig.*
+71 -4
View File
@@ -20,6 +20,10 @@ _Avoid_: daemon, task, driver
The Service that keeps the device participating in a mesh network at all times: receiving, relaying, and sending on behalf of Apps.
_Avoid_: radio, LoRa app
**Radio Service**:
The Service that owns the LoRa radio on the Cap: it configures it, shares the SPI bus with the SD card, and receives in the background. The LoRa Scanner uses it directly; the Mesh Service sits on top of it.
_Avoid_: LoRa driver, modem
**Mesh Protocol**:
One on-air language the Mesh Service can speak (Meshtastic first; others may follow). The Mesh Service speaks Mesh Protocols; Apps don't.
_Avoid_: stack, mode
@@ -40,16 +44,36 @@ _Avoid_: DM (in docs), private message
Rebroadcasting another Node's packet so it travels further across the mesh.
_Avoid_: forwarding, repeating
**Capsule**:
A Gemini site: everything served by one host on Geminispace.
_Avoid_: site, server (when the content is meant)
**Saved Page**:
A Gemini page kept on the SD card to read offline, with the URL it came from and when it was saved. Kept until the user deletes it; Storage Clean-up never offers it.
_Avoid_: cache, download (a download is a non-text file saved from Gemini)
**GNSS Service**:
The Service that owns the GNSS receiver on the Cap: it reads its NMEA sentences in the background and holds the current Fix, position, time and satellites.
_Avoid_: GPS (GPS is one constellation among several)
**Fix**:
What the receiver currently knows: none, 2D (position without altitude) or 3D (with altitude), from how many satellites, at what HDOP.
_Avoid_: lock, signal
**Track**:
A route recorded from GNSS positions to a GPX file on the SD card, started and stopped by the user.
_Avoid_: trace, log (a Log is recorded on its own)
**Wi-Fi Service**:
The Service that owns the Wi-Fi radio. It's always in exactly one mode: *Off*, *Connected* (joined to a Saved Network) or *Monitoring* (passively observing). When Wi-Fi is enabled in Settings, it stays Connected whenever a Saved Network is in range. It goes Monitoring only while Wi-Fi Tools needs it, then reconnects.
_Avoid_: network manager
**Saved Network**:
A Wi-Fi network the device may join on its own (name, password). When several are in range, the strongest wins.
A Wi-Fi network the device may join on its own: its name, its password, and how it gets its address, *Automatic* (DHCP) or *Fixed* (an address, a prefix and an optional gateway typed in Settings). When several are in range, the strongest wins.
_Avoid_: profile, known network
**IRC Service**:
The Service that keeps the IRC connection alive in the background once the IRC App has started it, until the user disconnects. It reconnects after drops, and pauses while the Wi-Fi Service is Monitoring. It does not start by itself after a reboot.
The Service that keeps the IRC connection alive in the background once the IRC App has started it, until the user stops it (`/quit`, or `irc stop` on the console). Once stopped by hand, opening the App again doesn't reconnect; typing a line does. It reconnects after drops, and pauses while the Wi-Fi Service is Monitoring. It does not start by itself after a reboot.
_Avoid_: IRC client (that's the App)
**Buffer**:
@@ -99,10 +123,50 @@ Data the user explicitly starts recording, such as Wi-Fi packet captures and LoR
_Avoid_: dump, log
**Storage Warning**:
The Notification raised once per boot when the SD card passes 80% full. Selecting it opens Storage Clean-up.
The Notification raised once per boot when the SD card passes 80% full. It points at the Storage App, where Maintenance holds Storage Clean-up.
**Storage Clean-up**:
The screen where the user deletes old Logs and Captures by category and age, with a preview of the space freed. Notes are never offered for deletion.
The screen where the user deletes old Logs and Captures by category and age, with a preview of the space freed. Notes are never offered for deletion. It lives in the Storage App, under Maintenance.
**Note**:
A plain text file in `/notes`, written on the device in the Notes App. Listed by its first line. Saved without being asked; never offered by Storage Clean-up.
_Avoid_: memo, document
**Storage App**:
The App that browses the SD card: folders and files, a clipboard for one item at a time (copy, cut, paste), rename, delete, new folder, and a viewer for each kind of file the firmware writes. The top-level folders, `/gemini/cache` and files being written are read-only.
_Avoid_: file manager, Files, explorer
**Maintenance**:
The part of the Storage App that deletes in bulk: the card's usage, Storage Clean-up and erasing the card. Reached through a warning.
_Avoid_: Settings > Storage
**Firmware Update**:
Installing a new firmware image without a USB cable: pushed over Wi-Fi from the developer's PC, or read from the SD card.
_Avoid_: flash, upgrade (alone)
**Update File**:
One signed file (`.ota`) that carries a firmware version, its image and a signature. The same file works over Wi-Fi and from the SD card. Anything not signed with the project's key is refused.
_Avoid_: binary, bin
**Probation**:
The state of newly installed firmware until it proves healthy: booted, UI drawn, Services started, 30 s without a crash, and Wi-Fi connected if it's configured. Then it's confirmed for good.
_Avoid_: trial, test mode
**Rollback**:
Returning automatically to the previous firmware when new firmware resets or crashes during Probation.
_Avoid_: revert, downgrade (a downgrade is installing an older version on purpose)
**Safe Mode**:
What the firmware starts instead of everything else after 3 crash restarts in a row: Wi-Fi and Firmware Updates (and the Debug Console in a Debug Build), so it can be fixed without a cable. A normal restart leaves it.
_Avoid_: recovery mode, failsafe
**Debug Build**:
A firmware built with the remote debugging aids compiled in (`+debug` in its version). Release builds have none of them.
_Avoid_: dev build, test build (a test build is one made to fail on purpose, such as a crashing update)
**Debug Console**:
The console of a Debug Build over Wi-Fi: live log lines and the serial commands, behind a token.
_Avoid_: telnet, remote shell
## Relationships
@@ -111,9 +175,12 @@ The screen where the user deletes old Logs and Captures by category and age, wit
- The **Mesh Service** speaks one or more **Mesh Protocols** and tracks the known **Nodes**.
- The **Wi-Fi Service** is either Connected or Monitoring, never both. Monitoring pauses the **IRC Service**, which reconnects and rejoins its **Buffers** afterwards.
- **Services** raise **Notifications**; the **Status Bar** summarises **Service** state.
- The **Radio Service** owns the radio; the **Mesh Service** and the LoRa Scanner use it.
- A **Sweep** pauses the **Mesh Service**; a **Sniffer** does not.
- Every transmission is bounded by the **Region** and its **Duty Cycle Budget**.
- Past 90% SD usage, **Logs** stop being written; the remaining space is kept for **Captures**. Nothing is deleted without the user's confirmation.
- A **Firmware Update** installs an **Update File**; the new firmware runs on **Probation**, and fails back by **Rollback**.
- **Rollback** covers new firmware; **Safe Mode** covers confirmed firmware that keeps crashing.
- A **Node** may be in several **Channels**. A **Direct Message** targets exactly one **Node**.
## Flagged ambiguities
+137 -1
View File
@@ -18,6 +18,8 @@ scripts/ci.sh
This runs the host-side unit tests (`test/`, `native` environment), then builds the firmware. The output is `.pio/build/cardputer-adv/firmware.factory.bin`.
The framework is rebuilt with the TLS settings in `platformio.ini` (`custom_sdkconfig`, ADR 0006), so the first build after a fresh checkout takes about 4 minutes; later builds take under a minute.
## Flash
1. Connect the Cardputer by USB-C.
@@ -37,6 +39,84 @@ This runs the host-side unit tests (`test/`, `native` environment), then builds
sudo usermod -aG dialout "$USER"
```
## Firmware Updates over Wi-Fi (OTA)
Once the Cardputer runs an OTA-capable firmware (flashed once over USB), updates can go over Wi-Fi:
```sh
scripts/ota_keygen.sh # once: creates the signing key (see ADR 0003)
scripts/flash.sh --ota 10.39.39.12 # build, sign and push; or set RORO_OTA_HOST
```
The device shows the push address in **Settings → Firmware**. It installs a correctly signed update right away, restarts (waiting up to 60 s if you're typing), and runs the new firmware on **Probation**. If the new firmware crashes, or can't reconnect Wi-Fi within 3 minutes, it rolls back to the previous one and says so.
To install from the SD card instead, copy the `.ota` file from `.pio/build/cardputer-adv/` into `/updates` on the card, then use **Settings → Firmware**. With the Cardputer on USB, the card can stay in: `scripts/sd_put.sh <file.ota>` sends it over the serial console into `/updates` (about 30 s for 1.6 MB, checked with SHA-256 before it's renamed into place; `SD_PUT_DEBUG=1` shows the console while it runs).
**The private key** lives in `~/.config/roro9stack/ota-key.pem` and must never be committed. If it's lost, generate a new pair and flash once over USB.
## Networks without DHCP
Each Saved Network gets its address automatically (DHCP) or has a Fixed one (docs/milestones/S1.md): in Settings > Wi-Fi, Enter on a network opens its page, where "IP address" switches between Automatic and Fixed, with an address, a prefix length (24 is 255.255.255.0) and an optional gateway. Switching to Fixed starts from what the network is giving the device at that moment. The setting is checked and applied when you leave the page. IPv4 only.
"DNS and NTP" on the same screen holds two DNS servers (9.9.9.9 and 1.1.1.1 by default), used on Fixed networks, or on every network with "Always use my DNS"; and two NTP servers (pool.ntp.org and time.cloudflare.com), used after any the network's DHCP offers. Enter on "Status" shows what's in use and where each value came from.
## System
The System App (docs/milestones/S1.md) shows what the device is doing, live and read-only, in any build. Tab moves between five views:
- **Overview:** each core's load, free memory, network traffic, battery, uptime and chip temperature, and both cores' load over the last two minutes.
- **Tasks:** every FreeRTOS task with its core, its share of a core over the last second, and the least stack it ever had left (in the warning colour under 512 bytes). `s` sorts by share, stack or name.
- **Memory:** free heap, the lowest since boot and the largest free block, with two minutes of free heap drawn against the three memory floors (55, 40 and 20 KB).
- **Network:** the connection, then for IRC, Gemini, the Debug Console and Firmware Updates the bytes read and written since boot and what's moving now. For TLS connections these are the bytes the service sees, without the encryption overhead.
- **System:** what `info` prints, plus the battery, the SD card with its write faults, the radio and the GNSS receiver.
It samples once a second and keeps its history only while it's open.
## Gemini
The Gemini App browses Geminispace (docs/milestones/G1.md): Tab and Shift+Tab pick a link, Enter follows it, Back returns (to where the page was scrolled), Space pages down, `g` types an address. Certificates are trusted on first use; a changed one stops the page and asks.
On a page, `b` bookmarks it, `s` saves it to the SD card to read offline (a non-text file goes to `/gemini/downloads/`), `S` saves it with the pages it links to on the same capsule (up to 30). The start page lists bookmarks and Saved Pages; inside a Saved Page, `r` refreshes it and `d` deletes it. With a card, every page streams through `/gemini/cache/` so a large one arrives whole even with IRC connected; what doesn't fit in memory stays on the card.
## LoRa Scanner
The LoRa Scanner (docs/milestones/M3.md) listens with the Cap's radio and **never transmits**. The Sniffer lists what it hears, newest first: time, RSSI, SNR, and for Meshtastic packets the sender and receiver (their last 4 hex digits) and hops. Enter shows a packet's details: the Meshtastic header (which is never encrypted) and a hex dump. `p` picks one of the 7 Meshtastic presets allowed in EU868 (LongFast by default), `c` starts or stops a Capture: a pcap file with LoRaTap headers in `/captures/lora/`, for Wireshark. A Capture keeps recording with the App closed; otherwise the radio sleeps when the App isn't open. Tab switches to **Sweep**: the signal strength across 863–870 MHz in 100 kHz steps, as bars with peak hold and a waterfall, with the Sniffer's frequency marked; the Sniffer is paused meanwhile and picks up where it was. The GNSS receiver on the same Cap raises the radio's noise floor by 8 dB while it runs: Settings > "Pause GNSS for LoRa" (off by default) puts it in standby while the radio listens, except during a Track. The Status Bar shows `L` while the radio listens (bright for a moment on each packet), `SW` while sweeping, and `CAP` while capturing.
## Storage
The Storage App (docs/milestones/F1.md) shows what's on the SD card: each folder's entries with their size and date, folders first. Enter opens a folder, Back goes up; `s` sorts by name, date or size. It works on one item at a time, with a clipboard:
| Key | Does |
|---|---|
| `c` / `x` | Copies or cuts the selected file or folder; the footer shows what `v` would paste |
| `v` | Pastes it into the folder shown. A copy next to its original is named `name (2).txt`; anything in the way is asked about first |
| `r` | Renames |
| `d` | Deletes, after saying what's inside: "Delete saved and its 42 files (1.2 MB)?" |
| `n` | Makes a folder |
| `i` | Details: type, exact size, date, and why an item is read-only if it is |
A copy runs in the background of the card (about 400 KB a second) in short turns, so Logs and Captures keep being written; it shows its progress, Back cancels it and takes back what was copied, and each file's size is checked afterwards. Three things can't be changed: the top-level folders the firmware keeps its files in (what's inside them can), `/gemini/cache`, and any file being written right now (today's IRC Logs, a Track or a Capture being recorded). The App says why when it refuses. A folder with more than 256 entries shows the first 256 by name and says so.
Enter on a file opens it by type; Tab switches to the same file as a hex dump or as text:
- **Text** (`.txt`, `.log`, `.gmi`, `.csv`, and anything that looks like text): only the screen's worth is read from the card, so a file of any size opens at once. Logs open at the end. Up and Down move a line, Left and Right a page, `t` and `b` go to the top and the end, `e` edits it (up to 16 KB, see Notes).
- **Captures** (`.pcap`): the packets as the LoRa Scanner lists them; Enter shows one with its Meshtastic header and bytes.
- **Tracks** (`.gpx`): the number of points, the start, the duration and the distance.
- **Update Files** (`.ota`): the version, and whether the file would install: it's checked as an install checks it (signature and contents) without writing anything. Enter then installs it.
- **Anything else:** a hex dump.
At the top of the card the last row, **Maintenance** (also `m`), holds the card's usage, Storage Clean-up and "Erase SD card", behind a warning: those delete for good. It replaces Settings > Storage.
## Notes
The Notes App (docs/milestones/F1.md) keeps plain text notes in `/notes` on the SD card. The list shows each note's first line and its date, newest first; `s` switches to by file name. `n` starts a note, Enter opens one, `r` renames its file, `d` deletes it after asking.
In the editor, type. Enter starts a line, Del deletes backwards, Fn with the arrows moves the cursor through the wrapped text, Ctrl+A and Ctrl+E go to the start and the end of the line, Tab types two spaces, and the Compose Key gives accents as everywhere. **There's no save key:** the note is written five seconds after the last key, on Back, on leaving the App, when the screen turns off and before the device powers off. The top line says "typing" or "saved". Each save writes a temporary file and then puts it in the note's place, so a power cut costs a few seconds of typing and never the note; if a save was cut short, opening the note offers its copy back.
A new note has no file until something is typed; its file is then named after its first line (`shopping-list.txt`), or `note-<date>-<time>.txt`.
A note holds up to 16 KB while it's edited. A bigger text file opens read-only in the Storage App (editing any size is issue #47). The Storage App's text viewer has `e` to edit a file with the same editor, anywhere on the card, unless the file is read-only.
## Development aids
`scripts/serial_log.sh [seconds] [command…]` records the serial output, and can send commands to the firmware first. For example, `scripts/serial_log.sh 30 short sleep:12 burst` sets short screen timeouts, waits 12 s, then sends a burst of Toasts.
@@ -48,12 +128,68 @@ sudo usermod -aG dialout "$USER"
| `sound on` / `sound off` | Toggles the Sound setting (beep + LED) |
| `short` / `normal` | Screen timeouts 5 s / 10 s, or 30 s / 60 s |
| `wifi add <ssid><TAB><password>` | Adds a Saved Network (so credentials stay out of the repo) |
| `wifi ip <ssid> dhcp` / `wifi ip <ssid> <address>/<prefix> [gateway]` | A Saved Network's IP setting: Automatic, or Fixed. Debug Builds: add `try <seconds>` to go back to the previous setting unless `wifi ip keep` follows |
| `wifi dns <a> [b]` / `wifi dns always on\|off` / `wifi ntp <a> [b]` | DNS servers (used on Fixed networks, or always), and NTP servers |
| `log <text>` | Appends a line to a test IRC Log (`/irc/dev/#test/<date>.log`) |
| `sd card` | What the SD card says it is: type, size, and its identity register (maker, name, revision, serial, date) |
| `sd list` | Lists the files of each Storage Clean-up category |
| `sd fill <folder> <count>` | Debug Builds: makes that many small files in a folder, to test a crowded one |
| `cat <path>` | Prints the first ~1.2 KB of a file on the SD card |
| `irc start` | Starts the IRC Service (normally done by opening the IRC App) |
| `irc stop` | Stops it, as `/quit` does: QUIT if connected, no more retries, and the App stays disconnected until you type |
| `gemini get <url>` | Fetches a Gemini page and prints its header, size, certificate fingerprint and heap use |
| `gemini trust <host> <port> <sha256>` | Pins a certificate by hand (the Gemini App asks when one changes) |
| `irc say <buffer> <text>` | Types into a Buffer, commands included (`irc say 0 /join #test`) |
| `irc dump` | Prints IRC status, memory, and the last lines of each Buffer |
| `wifi status` | Prints Wi-Fi state, network, signal, clock and free heap |
| `wifi status` | Prints Wi-Fi state, network, signal, clock and free heap, then the address, gateway, DNS and NTP servers in use and where each came from |
| `info` | Firmware, uptime, last start reason, memory, Wi-Fi, the SD card and its write faults since boot, and both app slots with their versions and OTA states |
| `tasks` | FreeRTOS tasks over the next second: state, priority, lowest free stack, share of a core, each core's load, and how many passes the main loop made |
| `net` | Bytes each network service has read and written since boot |
| `reboot` / `boot other` | Restart, or restart into the other app slot (a manual Rollback) |
| `log level <0-5>` | ESP-IDF log level |
| `ls [folder]` / `du <path>` | Lists a folder of the SD card with sizes and dates, or counts the files and bytes under a path |
| `cp [-f] <from> <to>` / `mv [-f] <from> <to>` / `rm <path>` / `mkdir <path>` / `cancel` | What the Storage App does, with its rules: copy (folders too), move or rename, delete (a folder with what's in it), new folder. `-f` replaces a file that's in the way; a tab separates paths that hold spaces; `cancel` stops a copy or a delete |
| `install <path>` | Update from SD with that `.ota` file, as Settings → Firmware does |
| `lora probe` | Finds the radio: chip, oscillator, antenna switch, DIO1 interrupt, noise floor |
| `lora status` | Radio settings, who's listening, packet and error counters, noise floor, task stack |
| `lora rx on` / `lora rx off` | Listens and prints each packet on the console |
| `lora preset <name>` / `lora custom <MHz> <BW kHz> <SF> <CR> <sync hex> [preamble]` | Receive settings: a Meshtastic preset, or anything else (`lora custom 868.1 125 7 5 34 8` for LoRaWAN) |
| `lora capture start` / `lora capture stop` | A LoRa Capture, as `c` in the App |
| `lora sweep on [from MHz] [to MHz] [step kHz]` / `lora sweep off` / `lora sweep dump` | Sweep a band (863 870 100 by default), with a summary every 2 s (floor, strongest, peaks), or print the latest pass |
| `gnss quiet on` / `gnss quiet off` | The "Pause GNSS for LoRa" setting |
| `lora noise test [gnss\|quiet]` / `lora noise report` | Debug Builds: Sweep under one changed condition at a time to find what raises the noise floor (Wi-Fi goes off for a few seconds); then the result |
| `lora inject <hex> [rssi] [snr]` | Debug Builds: a packet into the Scanner as if received (nothing is sent) |
| `crash` | The last crash: which firmware, why, task, PC and backtrace (from the core dump in flash) |
| `coredump erase` | Forgets the core dump |
| `loop spin on` / `loop spin off` | Debug Builds: make the main loop spin without resting, to compare load and radio noise |
| `crash abort` / `crash wdt` | Debug Builds: crash on purpose, or hang the main loop until the watchdog fires |
| `help` | Lists the commands |
`scripts/flash.sh` stops a running serial log first, since it would hold the port.
### Debug Builds and the Debug Console
`scripts/flash.sh --debug` (USB) or `scripts/flash.sh --debug --ota <ip>` (Wi-Fi) installs a Debug Build: the same firmware plus the Debug Console on TCP 2323 (ADR 0004). Then, with `RORO_OTA_HOST` set to the device's IP:
```sh
scripts/rdbg.py # interactive: the console backlog, live lines, and commands
scripts/rdbg.py info # one command and its reply
scripts/rdbg.py -b tasks # the same, after the backlog (boot messages and so on)
```
Every command above works there too, plus a few handled by the PC side or the console's own task:
```sh
scripts/rdbg.py crash # the last crash, its backtrace decoded against that exact build's ELF
scripts/rdbg.py coredump # fetch the core dump and decode it all (registers, every task) with esp-coredump
scripts/rdbg.py reset # restart at once, even if the main loop is stuck
scripts/rdbg.py screenshot # the screen as a PNG (2x)
scripts/rdbg.py put <file> [card path] # to the SD card (default /updates/<name>), SHA-256 checked, ~300 KB/s
scripts/rdbg.py get <card path> [file] # from the SD card
```
So a Firmware Update can also go `rdbg.py put roro9stack-….ota` then `rdbg.py install /updates/roro9stack-….ota`: the Update from SD path, without touching the device.
Every build keeps its ELF in `.pio/elves/` (version and digest in the name) for that; `scripts/decode_backtrace.sh <version|digest> <addresses>` decodes any backtrace by hand.
After 3 crash restarts in a row the firmware starts in **Safe Mode** (ADR 0005): only Wi-Fi, Firmware Updates and the Debug Console, so a fix can be pushed as usual. `reboot` leaves it. The token is in `~/.config/roro9stack/debug-token`, made by the first build; keep developing on Debug Builds, so the firmware a Rollback returns to always has the console.
+7
View File
@@ -0,0 +1,7 @@
# Name, Type, SubType, Offset, Size, Flags
nvs, data, nvs, 0x9000, 0x5000,
otadata, data, ota, 0xe000, 0x2000,
app0, app, ota_0, 0x10000, 0x330000,
app1, app, ota_1, 0x340000,0x330000,
spiffs, data, spiffs, 0x670000,0x180000,
coredump, data, coredump,0x7F0000,0x10000,
1 # Name Type SubType Offset Size Flags
2 nvs data nvs 0x9000 0x5000
3 otadata data ota 0xe000 0x2000
4 app0 app ota_0 0x10000 0x330000
5 app1 app ota_1 0x340000 0x330000
6 spiffs data spiffs 0x670000 0x180000
7 coredump data coredump 0x7F0000 0x10000
@@ -9,3 +9,7 @@ A fork would give full compatibility on day one, but its architecture is built a
- We accept partial Meshtastic compatibility at first: text on channels, Direct Messages, node list, position and relaying.
- The phone-app (BLE) API and PKI-encrypted Direct Messages are deferred, and we must re-implement protocol details ourselves.
- Multi-boot with stock Meshtastic via a launcher was rejected: it gives none of our own UX.
## Note (2026-10-04, M2)
NMEA is parsed by our own small, host-tested parser instead of TinyGPSPlus: the GNSS App's Sky view needs the satellite list (GSV) across several constellations, which TinyGPSPlus doesn't track. See docs/milestones/M2.md, Q66.
@@ -0,0 +1,12 @@
# Signed Update Files checked by the firmware, not ESP32 Secure Boot
Firmware Updates are accepted only when their Update File carries a valid ECDSA P-256 signature over the image's SHA-256. The firmware itself checks it, against a public key compiled into it, before switching the boot partition. The private key lives outside the repository, in `~/.config/roro9stack/ota-key.pem`.
We chose this over the ESP32's hardware Secure Boot. Secure Boot is enforced by the chip, but it burns eFuses one-way: a mistake bricks the device, and the device can never run unsigned firmware again, which makes recovery over USB harder. On a single development device, a software check that refuses unsigned pushes is enough, and it stays reversible: a new firmware can carry a new public key.
## Consequences
- Someone with physical USB access can still flash anything. Only Wi-Fi and SD card updates are guarded.
- **Losing the private key** means the next update has to go over USB, carrying a new public key.
- P-256 rather than Ed25519, because the firmware's TLS library (mbedTLS) already verifies it, so it costs no extra code.
- **Rollback: the bootloader first, the firmware as a second line.** Arduino-ESP32 marks a new image valid before `setup()` unless the sketch overrides `verifyRollbackLater()`, which once made every update look good and hid the bootloader's rollback (it had looked like the prebuilt bootloader ignored it). With the override, an image stays pending until Probation confirms it, and the bootloader reverts one that restarts unconfirmed, however early it crashes. The firmware also counts its own boots on Probation, very first thing in `setup()`, and reverts itself on the second unconfirmed start.
@@ -0,0 +1,23 @@
# A Debug Console over Wi-Fi, in Debug Builds only
The goal of Firmware Updates is to manage the device without a cable, and that includes finding out what went wrong. So a **Debug Build** (`cardputer-adv-debug`, `-DRORO_DEBUG`, version suffix `+debug`) adds a **Debug Console** on TCP 2323: the serial console, over Wi-Fi. A client sends a token as its first line, then gets the last 4 KB of console output (boot messages included), every new line live, and runs the same commands as the serial port, plus a few that only make sense remotely. ESP-IDF's own log lines are teed into it.
It's compiled out of release builds entirely, rather than switched off by a setting. A console that runs commands is a remote control: in a release build, nothing listens.
## How it fits
- **Console, not Serial.** All human-readable output goes through `console`, which writes to the USB port and, in a Debug Build, to a ring buffer the Debug Console drains. Writes never wait for USB: a host that's attached but not reading used to stall the main loop for up to 2 s per line.
- **Commands run on the main loop.** The socket lives on the Debug Console's own task, which only queues command lines. The main loop runs them, as it does serial commands, so they touch Apps and Services from the one task allowed to.
- **The token** is 128 random bits in `~/.config/roro9stack/debug-token`, made by the first build and passed into the container. It's never committed; a Debug Build refuses to compile without one. Like the OTA key, it guards against the network, not against someone holding the device.
- **One client at a time**, to keep memory flat (4 KB for the ring since M2, 6 KB of task stack).
- **Binary commands are answered on the console's own task**, not queued: `get`/`put` (SD card files, run as one Storage Service job each so card access stays on the storage task, with TCP doing the flow control), `screenshot` (the 32 KB RGB332 frame the UI composes into, read as it stands, so it may tear), `coredump get` and `reset`. These keep working when the main loop is stuck. A failed `put` closes the connection, so the rest of the file is never read as commands.
## Keep a Debug Build in the fallback slot
Rollback returns to the previous firmware, whatever it is. As long as development goes through Debug Builds, the firmware a crash falls back to has the Debug Console, so a bad update never costs remote access. A release build pushed over a Debug Build leaves the Debug Build in the other slot until the next update overwrites it.
## Consequences
- Anyone on the same network with the token can read the console, inject keys and reboot the device. The console never prints stored secrets (Wi-Fi and IRC passwords), but the IRC traffic it shows is readable.
- The TCP stream is plain text: fine on a home network, not across the internet.
- `+debug` versions compare equal to their release counterparts, so moving between the two is never refused as a downgrade.
@@ -0,0 +1,13 @@
# Safe Mode, crash reports and a watched main loop, in every build
Rollback protects against new firmware that fails Probation. It does nothing for firmware that was confirmed and crashes later: a corrupt setting, a server that sends something unexpected, a bug that takes an hour to show. Without a cable, such a device would restart forever. Three measures, in release and Debug Builds alike, keep it reachable:
- **Safe Mode.** The firmware counts starts that follow a crash (panic or watchdog) in NVS, first thing at boot. After 3 in a row, it starts only the clock, Wi-Fi, the Update Service and, in a Debug Build, the Debug Console: no Apps, no IRC, no SD card, and a screen that says so with the address to push an update to. Any normal restart (a `reboot`, an update), or a minute of uptime, resets the count.
- **Crash reports.** The same boot record keeps which version was running, so after a crash the firmware knows which one crashed, even when a Rollback has switched slots since. ESP-IDF already writes a core dump to its flash partition on a panic; after the restart the firmware prints its summary (task, PC, reason, backtrace) and raises a Notification. The `crash` command shows it again later. In a Debug Build, `scripts/rdbg.py crash` decodes the backtrace and `scripts/rdbg.py coredump` fetches the whole dump for `esp-coredump`, against the ELF of that exact build (`.pio/elves/`, named by version and ELF digest).
- **The main loop is watched.** Arduino-ESP32 subscribes only core 0's idle task to the task watchdog, and the main loop runs on core 1: a stuck loop used to hang the device for good, with the screen frozen and the Debug Console unable to run commands. `enableLoopWDT()` makes a loop stuck for 5 s a panic, with a core dump, counted towards Safe Mode. And an installed update no longer depends on the main loop: the Update Service restarts into it by itself after 90 s.
## Consequences
- Nothing in the main loop may block for 5 s. Network and card work already run on their own tasks.
- Safe Mode can't help when Wi-Fi or the Update Service itself is what crashes; that still needs USB.
- Three crashes within a minute of each restart are needed to reach Safe Mode, so a crash loop costs about half a minute before the device becomes reachable.
@@ -0,0 +1,19 @@
# The framework is rebuilt with our own SDK settings, for smaller TLS buffers
Arduino-ESP32 ships its ESP-IDF libraries prebuilt, with one `sdkconfig` for every ESP32-S3 board. Its TLS settings give every connection a 16 KB receive buffer and a 16 KB send buffer for its whole life. On a device with no PSRAM and about 340 KB of RAM, an IRC connection over TLS left a 12.6 KB low in M2, against a 40 KB floor.
Those settings are compiled into the libraries, so changing them means rebuilding them. pioarduino supports this as a "hybrid compile": `custom_sdkconfig` in `platformio.ini` lists the settings, and the build regenerates the framework's libraries from ESP-IDF (the same 5.5.5 the prebuilt ones come from) before building the app. We set:
- `MBEDTLS_ASYMMETRIC_CONTENT_LEN`, with 16 KB to receive (servers send full TLS records) and **4 KB to send** (IRC lines are short): 12 KB less per connection.
- `MBEDTLS_DYNAMIC_BUFFER`, `DYNAMIC_FREE_CONFIG_DATA`, `DYNAMIC_FREE_CA_CERT`: buffers allocated when needed, and handshake-only data (the CA chain) freed once connected.
The rebuild also follows the board definition instead of the generic one: PSRAM support is off (the Cardputer ADV has none) and the flash size is 8 MB.
## Consequences
- With IRC connected over TLS, a Debug Build has 78 KB free and a 59 KB low (it was 31 KB and 12.6 KB), and 46 KB at the lowest under the heaviest combined load measured (IRC, two refused installs, a 1.6 MB put and get).
- The first build after a fresh checkout, or after changing `custom_sdkconfig`, takes about 4 minutes instead of 45 s: it downloads ESP-IDF into the PlatformIO volume and compiles it. Later builds reuse it.
- Everything the firmware depends on was checked in the regenerated `sdkconfig`: app rollback, core dumps to flash (ELF), the 5 s task watchdog, FreeRTOS run-time stats, the certificate bundle.
- The project now owns its partition table (`default_8MB.csv`, identical to the framework's), which the hybrid build requires. Changing it would break updates over the air: the app slots must stay where they are.
- Generated files (`sdkconfig.*`, `managed_components/`, `.dummy/`) are ignored by git.
- A TLS server that sends records over 16 KB would still fail, as before; one that needs us to send records over 4 KB would now fail. Neither happens with IRC.
@@ -0,0 +1,20 @@
# Our own copy of the SD driver, for one missing byte
Arduino-ESP32's `SD` library talks to the card over SPI through `sd_diskio.cpp`. That driver gives up on a write without saying why, and about once in 1,500 multi-block writes it gave up on one that had worked (issue #21). A 1.7 MB upload failed about three times in ten; before M3, the retry on top of it then filled the gap with zeros.
The cause, measured with a driver that records where it stops: after the "Stop Tran" token that ends a multi-block write, a card takes about a byte of clock to signal busy. The driver deselects, selects again, and reads one byte to see whether the card is ready. Read too early, that byte is 0xFF, "ready"; the status check (CMD13) then goes out while the card is still programming, and its answer (0xFF, 0x1F) is taken for an error. Every failure seen was this one: all blocks accepted, then a status that isn't one. ChaN's reference driver, which FatFs ships as its example, sends a dummy byte after selecting the card for this reason. Arduino's doesn't.
PlatformIO links the framework's library objects directly, so one file can't be replaced from `src`. A project library with the same name takes its place: **`lib/SD` is Arduino-ESP32 3.3.12's SD library (Apache-2.0), with `sd_diskio.cpp` changed** and the other files as they came. The changes are marked `roro:`:
- A dummy byte after selecting the card, before the ready test, and one after Stop Tran.
- Each place a write gives up records the step and the card's answer (`sd_fault.h`): `info` shows the count, and the Debug Console's `put` prints the detail.
Halving the SPI clock to 10 MHz didn't change the failure rate, so the card stays at 20 MHz.
## Consequences
- 30 uploads of 1.7 MB in a row, each read back and compared by SHA-256, ten of them with the LoRa radio listening on the same bus: no write fault. Before: 3 failures in 10.
- Every writer gains: Logs, Tracks, Gemini pages, Saved Pages, Captures and Update Files installed from the card all go through this driver, and none of them checked.
- **The copy has to follow the framework.** When the platform is updated, compare `lib/SD` with the new `libraries/SD` and carry the `roro:` changes over. If upstream fixes the ready test, drop the copy. Reported as [arduino-esp32#12970](https://github.com/espressif/arduino-esp32/issues/12970); issue #39 follows it.
- One more defect was read in the code and left alone, because nothing here exercises it: the driver tests the card's answer to a data block against 0x0A and 0x0C, values it can't take (accepted is 0x05, CRC error 0x0B, write error 0x0D), so a block rejected for a CRC error is never resent. No such rejection was seen in any failure. If `DataToken` faults ever show in `info`, that's the next fix.
- A fault is now counted and explained instead of silent, so the next cause, if there is one, starts with evidence.
+161
View File
@@ -0,0 +1,161 @@
# F1 — Files and Notes
**Status:** in progress. The Storage App (issue #3) shipped as **v0.9.0** on 2026-10-06. Notes (#19) shipped as **v0.10.0** the same day. The card as a USB drive (#1) comes after.
**Goal:** get at what's on the SD card from the device itself: browse it, look inside the files the firmware writes, copy, move, rename and delete, and keep notes. A side milestone, like G1 and S1; Files and Notes were M3's original second half (Q30, Q89).
## The Storage App (issue #3)
Until now the card could be looked at only through the Debug Console (`ls`, `get`, `put`), and Settings > Storage could only delete whole categories by age.
**On the card today:** six top-level folders, `irc`, `wifi`, `updates`, `gnss`, `gemini` and `captures`. No `notes` yet; settings are in flash, not on the card.
### Decisions (design round 2026-10-06)
| # | Decision |
|---|---|
| Q128 | An App of its own, **Storage**, in the Launcher. **Settings > Storage goes away:** its usage figures, Storage Clean-up and "Erase SD card" move into the App, under **Maintenance**, behind a warning that these delete things for good. |
| Q129 | A row shows the name, then the size or "folder", then the date modified. Folders first, then by name; `s` cycles the sort (name, date, size). The top line shows the path and the card's free space. |
| Q130 | Nothing is hidden. **Read-only:** `/gemini/cache`; any file the firmware has open right now (today's IRC log, a Track or Capture being recorded, a file being received); and the top-level folders themselves, which can't be renamed or deleted though their contents can. **Everything else, the user's own data included, can be renamed, moved or deleted**, always after a confirmation. |
| Q131 | One item at a time, with a clipboard: Enter opens; Back goes up, and leaves the App at the top; `c` copy, `x` cut, `v` paste into the current folder; `r` rename; `d` delete; `n` new folder; `i` details. |
| Q132 | Copy, move and delete work on folders too, recursively. The confirmation says what's inside: "Delete *saved* and its 42 files?". |
| Q133 | A copy is a job on the storage task in 4 KB pieces, with a progress Toast; Back cancels it. It checks free space first and asks before replacing anything. **Afterwards the sizes are compared**, not the contents: the driver is trusted since v0.6.1 (ADR 0007). A move within the card is a rename. |
| Q134 | Viewers by type. **Text** (`.txt`, `.log`, `.gmi`, `.csv`, `.gpx`, and anything that looks like text): read from the card as you scroll, so size doesn't matter; logs open at the end. **`.pcap`:** the LoRa Scanner's packet list. **`.gpx`:** a summary (start, duration, points, distance), Tab for the text. **`.ota`:** version, size, whether the signature is valid; Enter installs through Update from SD. **Anything else:** a hex dump. |
| Q135 | No editing: that comes with Notes (#19). |
| Q136 | A listing holds **up to 256 entries**, packed, about 10 KB; a bigger folder shows the first 256 by name and says how many more there are. The App refuses to open below the memory floors (Q86). |
| Q137 | **The Clock also sets the system time**, so files are dated correctly with GNSS alone and not only after NTP. A file dated before 2020 shows "-". |
| Q138 | Console: `cp`, `mv` and `mkdir`, next to `ls` and `rm`. |
| Q139 | Left out, each with its issue: selecting several items (#41), finding files by name (#42), opening a `.gmi` in the Gemini App (#43), a table view for `.csv` (#44), images (#45). |
| Q140 | Ships as **v0.9.0** when done and checked. |
### Done when
- The Storage App lists any folder of the card with sizes and dates, sorted three ways, and says so when a folder has more than 256 entries.
- A file can be copied, moved, renamed and deleted, and a folder too; a new folder can be made. Each destructive action asks first; a copy shows progress and can be cancelled.
- The read-only rules of Q130 hold, with a reason given when something is refused.
- Each viewer of Q134 opens its type, and a 1 MB text file scrolls without loading whole.
- Maintenance shows the card's usage and does what Settings > Storage did, behind its warning; Settings no longer has a Storage row; the Storage Warning points at the Storage App.
- A file written with only a GNSS Fix (no Wi-Fi) is dated correctly.
- Free heap stays above the floors with the App open, Wi-Fi and IRC on TLS.
### Work breakdown
1. **Model** (host-tested): paths and names, the read-only rules, the packed listing and its sorts, file types, sizes and dates for display, the GPX summary.
2. **Card operations:** listing a folder, copy, move, delete (recursive, counted), new folder, as storage jobs with progress and cancel; `cp`, `mv`, `mkdir`; the Clock sets the system time.
3. **The App:** browsing, the clipboard, dialogs, details.
4. **Maintenance:** usage, Clean-up and Erase moved in from Settings, with the warning.
5. **Viewers:** text, hex, `.pcap`, `.gpx`, `.ota`.
6. **Checks on the device**, recorded here.
### As built
- **`FileOps`** (`src/services/file_ops`) does the card's work for the App and for the console alike: list, count, copy, move, delete, new folder. One operation at a time on the storage task, **in turns of about 150 ms** that queue themselves again, so Log lines and a Capture are written in between. The rules of Q130 are checked there, whoever asks.
- **A listing reads the folder straight from FatFs.** Through the Arduino `File`, every entry was looked up by name again for its size and again for its date: 329 entries took over two seconds. One pass now, and it's there before the screen has redrawn. Counting, copying and deleting still walk with `File`; they show progress and can be stopped.
- **A copy shows its progress in a box in the App**, not a Toast (Q133): it has a bar and says Back cancels. A cancelled or failed copy deletes what it had written. The copy gets today's date, like `cp`.
- **The viewers** (`src/apps/file_viewer`, models in `lib/files`): text through `TextPager`, which reads about a kilobyte around the screen and wraps at spaces, 38 columns; going back a line wraps the paragraph before again, so a file reads the same in both directions. A `.pcap`, a `.gpx` and an `.ota` are read through once by a storage job, in the same 150 ms turns. An Update File is fed to the installer's own parser with a sink that writes nothing, so "would it install" is the same answer an install gives.
- **Tab** in a viewer shows the same file as hex, or as text (not in Q134).
- **Maintenance** is the last row at the top of the card, and `m` anywhere in the App. It's the old Settings > Storage page behind a dialog.
- **The Storage Warning** was only ever a Toast; "selecting it opens Storage Clean-up" (CONTEXT.md) was never built. It now reads "SD card over 80% full: see Storage".
- **Console:** `cp`, `mv`, `mkdir` (Q138), and `rm` and `du` through the same code, so `rm` now takes folders and follows the rules; `ls` shows dates. Debug Builds: `sd fill <folder> <count>` makes test files.
### Checks on the device (2026-10-06, v0.8.1-2 Debug Build)
All in a scratch folder, `/f1test`, removed afterwards.
| Check | Result |
|---|---|
| Host tests | 424 pass (411 before the viewers' models) |
| Browsing | Folders first, sizes and dates, the three sorts; a 300-file and a 329-file folder show "first 256 of 300" and "of 329" |
| New folder, rename, copy, cut and paste, delete | Each works on a file and on a folder; a copy next to its original is named `(2)`; a name in the way asks "Replace it?" |
| A folder of 11 files, 8.4 MB, copied | 19.4 s, 435 KB/s, the bar moving; two Log lines queued meanwhile were written |
| The same copy cancelled at 1.8 MB | "Cancelled: nothing was copied", and nothing was left behind |
| Delete | 341 files in 9.7 s; the dialog had counted them first |
| Read-only rules | `/irc`, `/gnss` (top-level folders), `/`, `/gemini/cache` and a folder made inside it, a folder into itself, a name with `:`; a Capture being recorded and the folder holding it; a folder under `/irc` while IRC runs. Each refused with its reason; the Capture could still be copied |
| Text | A 1 MB log opens at its last line at once; top, pages, lines; a file without an extension that looks like text opens as text |
| Hex | A 5 KB binary file; Tab from any other viewer |
| `.pcap` | A LoRa Capture: 3 packets as the Scanner lists them, Enter shows the Meshtastic header and bytes |
| `.gpx` | 400 points: start, 33 min 15 s, 4.68 km; Tab shows the text |
| `.ota` | A signed file: version, "intact", "older than what's running", Enter asks to install (not confirmed). A tampered one: "image corrupted (hash mismatch)" |
| Maintenance | The warning, then usage, Clean-up's categories and Erase (not run) |
| Date with GNSS only | NTP pointed at an address that doesn't answer, restart: the Clock came from the Fix, and a folder made then is dated 2026-10-06 08:39. A Track from the day before, written the same way by v0.8.1, shows "-" |
| Memory | IRC connected, the App open on 256 entries: 61 KB free (70 KB before opening). Lowest since boot 29.7 KB, during IRC's TLS handshake |
| Stacks | `storage` 3.1 KB free of 6 KB at worst, `loopTask` 1.5 KB |
**Not checked by hand:** how the keys feel on the device itself; everything above was driven through the Debug Console's `key` command and screenshots.
**One slip during the checks:** a scripted key sequence ran in the wrong folder and renamed `/gemini/saved` to `saved2`, then copied it to the top of the card. Both were put right at once (renamed back, the copy deleted; 7 files, 53,798 bytes, as before).
**Found on the way:** a panic at Wi-Fi join, there since v0.7.0 (SNTP started twice, issue #46). Fixed in v0.9.0.
## Notes (issue #19)
Plain text notes on the SD card, written on the device. Q30 settled the base: `.txt` files in `/notes`, created, edited and deleted from the device, never offered by Storage Clean-up.
### Decisions (design round 2026-10-06)
| # | Decision |
|---|---|
| Q141 | A **Notes** App in the Launcher. One row per note: its first line as the title, then the date. Newest first; `s` switches to by name. `n` new, Enter opens, `d` deletes after a confirmation, `r` renames the file. |
| Q142 | A new note's file name is never typed: it comes from the first line when the note is first saved (`shopping-list.txt`), or `note-20261006-0919.txt` if that line is empty. It doesn't change afterwards unless the note is renamed. |
| Q143 | **Autosave, no "discard changes?" prompt:** five seconds after the last key, on leaving the note or the App, and when the screen turns off. A save writes a temporary file and renames it over the note, so a power cut loses the last few seconds at most. A temporary file left behind is offered back at the next open. |
| Q144 | The whole note is in memory while it's edited, up to **16 KB**. A bigger text file opens read-only in the Storage App's viewer. The App refuses to open below the memory floors (Q86). **Editing files of any size must come in a later release: issue #47.** |
| Q145 | The editor wraps at spaces, 38 columns by 8 rows, with a line for the name and the state. Enter is a new line, Del deletes backwards, Fn+arrows move (the Text Entry rule), Ctrl+A and Ctrl+E go to the start and the end of the line, Tab types two spaces, Back saves and returns. The Compose Key works as elsewhere. |
| Q146 | The Storage App's text viewer gets `e`: edit this file with the same editor, for a text file up to 16 KB that isn't read-only. That lifts Q135 without Apps opening each other (#43 stays). |
| Q147 | The list is flat: the files directly in `/notes`. Sub-folders are reached through the Storage App. |
| Q148 | UTF-8, LF line ends; a file with CRLF is saved back with LF. Characters the font lacks are kept on save. |
| Q149 | Left out, each with its issue: editing files of any size (#47), searching inside notes (#48), undo (#49), selecting and copying text (#50). |
| Q150 | Ships as **v0.10.0** when built and checked on the device. |
### Done when
- A note can be started, typed with accents, left and found again in the list under its first line; renamed; deleted after a confirmation.
- What's typed is on the card five seconds after the last key, and after Back, Home, or the screen turning off, without a prompt.
- Pulling the power while typing loses a few seconds at most, and the note is never left empty or half-written.
- The cursor moves by character and by line through wrapped text, and the screen follows it; a 16 KB note edits without lag.
- A note at 16 KB refuses more text and says so; a bigger file opens read-only.
- `e` in the Storage App's text viewer edits a file; a read-only one is refused with its reason.
- Free heap stays above the floors with a 16 KB note open and IRC connected.
### Work breakdown
1. **Model** (host-tested): the text buffer with its cursor, wrapping and scrolling; file names from first lines.
2. **The editor on the device:** loading, drawing, keys, autosave through a temporary file, recovery.
3. **The Notes App:** the list with titles, new, rename, delete.
4. **`e` in the Storage App.**
5. **Checks on the device**, recorded here.
### As built
- **`NoteText`** (`lib/notes`, host-tested) is the text, its cursor and the screen around it. A line owns the space or the newline it ends with, so every byte is on exactly one line and the cursor has one place for each. **No index of lines is kept:** a note of newlines alone would need twice its own size for one. Where a line starts is worked out from the start of its paragraph.
- **One buffer, 16 KB, for as long as the editor is open.** It's reserved when the note is opened, the file is read straight into it, and typing never makes it grow. On this device a failed allocation is an abort, and with IRC connected the largest free block is about 31 KB whatever the total says: the first version read the file into one string and copied it into another, and opening a full note with IRC connected restarted the device. The editor now also refuses to open without a free block of 24 KB.
- **`NoteEditor`** (`src/apps/note_editor`) is shared by the Notes App and the Storage App's `e`. A save runs on the storage task while the main loop waits for it: no second copy of the note, and at 16 KB the wait is a fraction of a second at a moment when nobody has typed for five.
- **A save** writes `<note>.tmp`, checks its size, deletes the note and renames the temporary file (FAT can't rename onto a file). A cut between the last two steps leaves only the `.tmp`: the Notes list puts such a file back under its name. A `.tmp` next to its note is an unfinished save: opening the note offers it.
- **Titles** in the list are read from the card for the eight rows on screen, when the list moves.
- **Before powering off**, the firmware now leaves the foreground App (`PowerService::beforePowerOff`), which makes the editor save.
- Shift or Alt with Fn+Up and Fn+Down moves a page (not in Q145).
### Found on the way
- **The screen could go "off" for one tick after a key sent through the Debug Console**, and the next key was then swallowed as a wake-up: the `key` command stamps the power timer from `millis()`, the power tick compares with its pass's older time, and the unsigned difference read as 49 days idle. The same shape as #46. Fixed in `PowerPolicy::update` with a test. Keys from the keyboard were never affected. It explains remote keys "lost" in earlier sessions.
- **`scripts/rdbg.py` held back piped lines** written while it was still connecting, until the next line came (a buffered `readline()` behind `select()`). Fixed.
### Checks on the device (2026-10-06, Debug Build of branch `notes`)
Test notes were made in `/notes` and removed afterwards; the folder is left, empty.
| Check | Result |
|---|---|
| Host tests | 439 pass |
| A first note | "No notes yet", `n`, typed three lines: the top line says "typing", then "saved" five seconds after the last key, under `shopping-list.txt`. 63 keys in a row all arrived |
| Leaving | Back saves and returns to the list, which shows the note under its first line. Home in the middle of a new note saved it as `ideas.txt` |
| The cursor | Down, Right, an insertion in the middle of a line; the screen scrolls through a note of about 230 lines |
| A power cut | Typed, waited seven seconds, typed more and restarted the device at once (`reset`): the note has what was saved, whole, and not the last keys |
| An unfinished save | A `.tmp` next to its note: "Unsaved copy... Keep the note / Use the copy"; using it brings its text back and saves it. A `.tmp` alone was put back under its name when the list opened |
| 16 KB | A note of exactly 16,384 bytes opens and scrolls; one more character: "This note is full: 16 KB". A file of 16,398 bytes: "Too big to edit: 16 KB at most" |
| Rename, delete, sort | `r` renamed `orphan.txt` to `orphan2.txt`; `d` asked, then deleted; `s` switched between newest first and by file name |
| `e` in the Storage App | A note opened from the text viewer, edited, saved on Back; the listing shows its new size |
| Memory | IRC connected, the full 16 KB note open: 55 KB free, largest block 31.7 KB (72 KB free before opening) |
**Not checked:** accents through the Compose Key and Ctrl+A / Ctrl+E (the remote `key` command can't send them; the model's tests cover both), the power button's save (it needs a hand on the device), a missing card, and how typing feels on the keyboard itself.
**One slip during the checks:** a key sequence sent right after a restart opened IRC instead of Notes, and the test letters went into IRC's input line. Nothing was sent: the line was cleared and the App left. IRC connected to Libera as it does when opened.
+61
View File
@@ -0,0 +1,61 @@
# G1 — Gemini client
**Status:** done, tagged v0.5.0. Every step was checked on the device; reading Saved Pages with Wi-Fi off was checked by hand (2026-10-05).
**Goal:** browse Geminispace from the Cardputer: fetch and read gemtext over TLS, follow links, answer input prompts, keep bookmarks, and save pages to the SD card to read later, offline. A side milestone between M2 and M3, tagged v0.5.0 when done.
Gemini (geminiprotocol.net): one request per TLS connection on port 1965, the request is the URL and CRLF, the response a `<status> <meta>` header line, then the body. Most capsules use self-signed certificates: trust on first use is the norm.
## Decisions (design round 2026-10-05)
| # | Decision |
|---|---|
| Q70 | A milestone of its own, **G1**, before M3: plan, tests first, measured on the device, tagged v0.5.0. |
| Q71 | **TOFU:** the first certificate seen for a host is pinned (SHA-256, in NVS). If it changes, the page isn't shown; a dialog shows both fingerprints and asks whether to trust the new one. Self-signed or expired certificates are fine; only a change counts. |
| Q72 | Responses: 1x input (11 hidden, for passwords), 2x content, up to 5 redirects (3x), 4x/5x errors with the server's message. 6x (client certificates): "not supported". |
| Q73 | `text/gemini` is rendered, other `text/*` shown as plain text. Anything else can be saved to `/gemini/downloads/`, not shown. |
| Q74 | Up to **64 KB on screen**, larger pages truncated with a notice. Saving streams to the card, so a larger page is saved whole. |
| Q75 | Gemtext rendering: text wrapped to the 40-column screen; `#`/`##`/`###` headings in bold and accent; `*` lists with bullets; `>` quotes indented and muted; preformatted blocks unwrapped, Left/Right to scroll; `=>` links with their label, numbered. |
| Q76 | Up/Down scroll; Tab and Shift+Tab move between links; Enter follows; Backspace goes back; `g` opens the address line. Links to other protocols show their URL and aren't followed. |
| Q77 | Back history of 20 URLs in RAM, with scroll positions; going back refetches (or reopens a Saved Page). **Bookmarks** in `/gemini/bookmarks.gmi` (a gemtext page, shown on the start page); `b` adds the current page. Without a card, a built-in start page. |
| Q78 | Start page: bookmarks, then Saved Pages, then defaults: geminiprotocol.net, a search engine (kennedy.gemi.dev), an aggregator (Cosmos; Antenna was down when measured). |
| Q79 | UTF-8 decoded; characters outside the Latin-1 fonts shown as `?`. |
| Q80 | IRC and Gemini can run together: each fetch opens one connection, reads and closes it. If there isn't memory for a second TLS connection, the fetch fails with a clear message and IRC is untouched. Measured in step 1. |
| Q81 | Debug aid: `gemini get <url>` prints the status, MIME type, size, certificate fingerprint and the first lines. URL resolution (RFC 3986), the response header and gemtext parsing are host-tested. |
| Q82 | `s` saves the page on screen as a **Saved Page**: `/gemini/saved/<host>/<path>.gmi`, the gemtext as received plus a first line with its URL and save date. Saving again replaces it, and says so. |
| Q83 | `S` saves the page and the pages it links to, one level deep: gemtext only, same host only, at most 30 pages, in the background with a progress Toast. |
| Q84 | The start page lists Saved Pages, newest first, grouped by capsule; they open with no network. In a Saved Page, a link to another Saved Page opens the saved copy; other links fetch online if Wi-Fi is up, or say "not saved, offline". A Saved Page shows when it was saved; `r` refreshes it. |
| Q86 | *Decided after step 1, revised after Q88.* **Two floors:** free heap stays above 40 KB in steady state; a fetch refuses to start below **55 KB** free ("not enough memory: stop IRC or retry"). The firmware's own allocations during a fetch (a page in RAM, a window) keep 20 KB free. With IRC connected, the TLS connection itself can briefly take the heap lower, depending on the server's record sizes: measured 24, 19.5, 15.5 and **13 KB**. *Accepted:* about 12 KB for a moment during a fetch with IRC up, rather than refusing most fetches (a 70 KB start floor) or dropping IRC's connection for each page. |
| Q87 | *Decided in step 3.* **With a card, every page streams to `/gemini/cache/page.gmi`** in 1 KB pieces while its TLS connection is open; once the connection closes and its ~45 KB is back, the page is loaded into RAM as far as the 40 KB floor allows. The whole page stays on the card (Saved Pages copy it). Without a card, the page goes straight to RAM under the same two floors. Pages are held as lines in 4 KB chunks, never one large block (the largest free block with IRC connected is about 31 KB). |
| Q88 | *Added after step 6.* **A page bigger than memory allows is read from the card as you scroll.** Opening it, one pass over its file counts the lines, records where every 64th starts (and whether it's inside a preformatted block), and loads the first window. Scrolling near either end of the window reads the next or previous one in the background, keeping the line on top of the screen where it is; the scrollbar follows the whole page. Display pages alternate between two cache files, so the one on screen is never overwritten by the next fetch; background jobs use a third. |
| Q85 | Saved Pages are deleted from the App only (`d`, with confirmation), never by Storage Clean-up's age rules, like Notes. |
## Measured (step 1)
- `gemini://geminiprotocol.net/`: `20 text/gemini`, 1,184 bytes, TLS handshake 0.7–1.1 s, whole fetch 0.7–1.1 s; kennedy.gemi.dev 1.9 s. The fetch task's stack peaks at about 3.6 KB of 6.
- **Heap, Debug Build, IRC connected over TLS:** about 68 KB free before a fetch. After the handshake the fetch holds about 32 KB (36–40 KB left); the handshake itself (certificate chain parsed with the 16 KB receive buffer allocated) dips to about **24 KB** for a second or two. Nothing leaks: the heap after matches the heap before.
- **Step 3, Cosmos (31.6 KB) with IRC connected:** first stopped at 4.6 KB (RAM only, the transfer's 20 KB floor). Streamed to the card: the whole page on the card, 20 KB of it loaded, lowest free heap 19.5 KB during the transfer and 43 KB once loaded. Without IRC: the whole page in RAM. Redirects (Cosmos `31`), input (`10`), not found (`51`) and a changed certificate (refused, both fingerprints shown) all checked on the device.
- **Steps 4–6 on the device:** Project Gemini and its relative links, Back with the scroll restored, a refused YouTube link; `b` bookmarks, `s` saves (and says when it replaced an older copy), `S` saved 6 of 6 pages, the start page lists both; a Saved Page opens from the card with its origin, its saved links open saved copies, `r` refreshes, `d` asks first; Kennedy's input prompt sent "cardputer" and got 87 results; emoji drawn as `?`.
- **A bug found there:** refreshing first loaded the whole Saved Page into RAM just to read its origin, next to the App's copy and a TLS connection: the heap fell to 436 bytes. Now only the first line is read, and every fetch (pages, saves, refreshes) checks the 55 KB start floor. Lowest since boot afterwards: 53.8 KB.
- **Windowed pages (Q88), Cosmos with IRC connected:** 226 of 419 lines in memory at first; paging down loaded lines 192–419 in one window, scrolling back up loaded 64 onwards, then 0 onwards. Window budgets count the memory the old window gives back.
- **Heap during a fetch with IRC connected:** lowest 13–15.5 KB in later runs (24 and 19.5 KB earlier), the TLS receive buffers varying with the server's records. Accepted (Q86, revised).
- Antenna (`warmedal.se`) doesn't answer, from the PC either; the default aggregator becomes Cosmos (`gemini://skyjake.fi/~Cosmos/`, which redirects to `cosmos.skyjake.fi`).
## Done when
- `gemini get gemini://geminiprotocol.net/` prints the header, size and fingerprint on the console.
- The Gemini App opens the start page, follows links (relative ones included), goes back, and follows redirects.
- An input prompt (e.g. a search) takes a query and shows the results.
- A changed certificate stops the page and asks.
- `s` saves a page, `S` a page and its links; with Wi-Fi off, Saved Pages open and their saved links work.
- Bookmarks are added with `b` and listed on the start page.
- With IRC connected over TLS, a fetch still works, and the free heap stays above 40 KB.
## Work breakdown
1. **Two TLS connections:** measure the heap with IRC connected while a Gemini fetch runs.
2. **Parsers** (host-tested): URL parsing and relative resolution, the response header, gemtext lines.
3. **Fetch** on its own task, with TOFU and `gemini get`.
4. **Gemini App:** rendering, scrolling, links, history, the address line.
5. **Input prompts, redirects, bookmarks, downloads.**
6. **Saved Pages,** then saving with linked pages.
+59
View File
@@ -0,0 +1,59 @@
# M2 — GNSS
**Status:** done on the device (branch `m2`): every "Done when" item below is met.
## Measured
- **Cold start** (`$PCAS10,2`) to a 3D Fix, by a window: **73 s**, 5 satellites used of 8 in view. A restart of the ESP32 alone keeps the receiver's Fix (the Cap stays powered).
- By a window: 3D Fix from GPS, GLONASS, Galileo and BeiDou, up to 14 of 17 satellites used, HDOP 1.0–1.3.
- **Heap, Debug Build, GNSS on, IRC on TLS** (floor 40 KB; v0.2.1 had a 79 KB low):
| | Free | Lowest |
|---|---|---|
| Start of M2 | 31 KB | 12.6 KB |
| Stacks and buffers trimmed by measurement | 46 KB | 18 KB |
| mDNS removed | 54 KB | 34 KB |
| Framework rebuilt with smaller TLS buffers (ADR 0006) | **78 KB** | **59 KB** |
Under the heaviest combined load measured (IRC, two refused installs, a 1.6 MB put and get), the low is 46 KB. The cost had come mostly from the OTA and Debug Build work, not GNSS. Stacks were set to measured peak plus about 2 KB (loop 6 KB, update 5, storage 6, irc 6); after a TLS handshake the irc task has 1.7 KB left. IRC can now be stopped by hand (`/quit` in any state, `irc stop`), which frees its TLS memory.
**Goal:** the device knows where it is and what time it is without a network: a GNSS Service in the background, a GNSS App with the position and a sky view of the satellites, the clock set from satellites when there's no NTP, and Tracks recorded to the SD card.
**Hardware:** the Cap LoRa-1262 carries an ATGM336H-6N (AT6668), multi-constellation (GPS, BeiDou, Galileo, GLONASS, QZSS), with a ceramic antenna. NMEA over UART, 115200 8N1. **Measured (step 1, `gnss probe`): RX GPIO 15, TX GPIO 13, 115200 8N1**, as in Meshtastic's board file; M5Stack's page names GPIO 8 and 9, which are the internal I2C bus the keyboard controller sits on. Output is NMEA 4.10 style: `GN` RMC, VTG and GGA, one GSA per constellation with the system ID (1 GPS, 2 GLONASS, 3 Galileo, 4 BeiDou, 5 QZSS) in its last field, and a GSV sequence per constellation and signal (`GP`, `GL`, `GA`, …) with the signal ID last. RMC carries a time even without a Fix (status `V`), so only a Fix makes it trustworthy.
## Decisions (design round 2026-10-04)
| # | Decision |
|---|---|
| Q58 | Settings has a GNSS On/Off switch, **On by default**. Off puts the receiver in standby. *Measured:* `$PCAS12,<seconds>` (CASIC) stops its output within a second, for up to at least 65535 s, and any command wakes it within a second; Off sends `PCAS12,65535` (renewed hourly), On sends a hot start, `PCAS10,0`. |
| Q59 | The **GNSS App** has two views, switched with Tab. *Position*: latitude, longitude, altitude, speed, course, Fix (none / 2D / 3D), satellites used and in view, HDOP, UTC time. *Sky*: the satellites placed by azimuth and elevation, coloured by constellation, filled when used in the Fix. |
| Q60 | "Radar" in M2 means the Sky view. A radar of other Nodes by distance and bearing needs the mesh: M4. |
| Q61 | The **Status Bar** shows a GNSS mark: absent when off, muted while searching, normal with a 2D Fix, with the satellite count with a 3D Fix. |
| Q62 | GNSS time **sets the clock once there's a Fix**, and refreshes it every 10 minutes. *Revised in step 3:* the clock's trust order from M0 (Mesh < NTP < GNSS) already ranks GNSS above NTP, which is right: GNSS time is at least as accurate. So GNSS also corrects a clock NTP set, not only an unset one. |
| Q63 | A **Track** is started and stopped in the GNSS App. It's written as GPX to `/gnss/tracks/<YYYYMMDD-HHMMSS>.gpx`, a point every 5 s when the position moved more than 5 m. It keeps recording with the App closed, with a Toast on start and stop and a Status Bar mark, and gets its own Storage Clean-up category. |
| Q64 | Coordinates in **decimal degrees plus the Maidenhead locator**; a Settings switch for degrees, minutes and seconds. Metric units only. |
| Q65 | **The position never leaves the device in M2.** Sharing it over the mesh, and at what precision, is decided in M4. |
| Q66 | **Our own NMEA parser**, host-tested: RMC, GGA, GSA and GSV, with each talker ID mapped to its constellation. TinyGPSPlus (named in ADR 0001) doesn't track the satellite list across constellations, which the Sky view needs. |
| Q67 | The receiver keeps its **defaults** (all constellations, 1 Hz). No receiver settings. Time to first fix is measured and recorded here. |
| Q68 | Debug aids: `gnss status`, and `gnss nmea on/off` to stream the raw sentences to the console (USB serial and Debug Console). Raw NMEA is never written to the card. |
**Lesson (step 3):** the first probe also tried the pins swapped, driving the receiver's output line from the ESP32 for about a second. The receiver then went silent until a full power cycle (an ESP32 restart doesn't cut the Cap's power). Never drive GPIO 15.
## Done when
- The GNSS Service reads NMEA in the background whatever App is on screen, and a 3D Fix appears outdoors.
- The GNSS App shows the Position and Sky views, both live.
- The Status Bar shows the GNSS mark per Q61.
- With no Wi-Fi, the clock is set from GNSS after the first Fix.
- A Track records while the App is closed, survives the screen turning off, and opens as valid GPX on the PC.
- Settings → GNSS Off stops it (and the Status Bar mark goes away); On brings it back.
- Free heap stays above about 40 KB with GNSS, Wi-Fi, IRC on TLS and the UI running.
## Work breakdown
1. **Hardware check:** a `gnss probe` command reads the candidate UART pins and reports which carries NMEA, at what baud rate, and which talker IDs. Then the standby command (Q58) and a first time to first fix.
2. **NMEA parser** (host-tested): checksum, RMC, GGA, GSA, GSV across constellations, merged into one GNSS state (Fix, position, time, satellites).
3. **GNSS Service:** UART on its own task, the parser, `gnss status` and `gnss nmea`, Settings On/Off.
4. **Clock from GNSS** (Q62), and the Status Bar mark (Q61).
5. **GNSS App:** Position view, Maidenhead and coordinate formats (host-tested), then the Sky view.
6. **Tracks:** the 5 s / 5 m rule and GPX writing (host-tested), background recording, Clean-up category.
+69
View File
@@ -0,0 +1,69 @@
# M3 — Radio bring-up: the LoRa Scanner
**Status:** done, tagged v0.6.0. Everything was checked on the device except one "Done when" item: Sweep was never tried against a known transmitter (see below). The listening hour heard nothing, so by Q104 **a reference Meshtastic node is a requirement for M4**.
**Goal:** the LoRa radio on the Cap works, receive only: a Radio Service owns it and shares the SPI bus with the SD card safely, and a LoRa Scanner App shows what's on the air, either packets (Sniffer) or energy across the band (Sweep). Nothing in M3 can transmit. The mesh comes on top of this in M4 (receive) and M5 (transmit).
**Hardware:** the Cap LoRa-1262 carries an SX1262 (868–923 MHz, +22 dBm) with an RP-SMA antenna. Pins, as in Meshtastic's board file for the Cardputer ADV: **NSS 5, RST 3, DIO1 (IRQ) 4, BUSY 6**, on the SPI bus shared with the microSD card (SCK 40, MISO 39, MOSI 14; card CS 12). Meshtastic uses DIO2 as the RF switch and DIO3 for a 1.8 V TCXO, marked optional. M5Stack's page adds an FM8625H antenna switch enabled by P0 of a PI4IOE5V6408 I/O expander on the internal I2C bus, address not given; Meshtastic doesn't mention it. Step 1 measures which is true.
**No other LoRa device yet.** meshmap.net (2026-10-05) lists two Meshtastic nodes within 10 km of the desk and six within 30 km, with positions blurred by a few km; none is known to be in range. M3 needs none: it only receives.
## Measured
- **Internal I2C bus (8/9):** 0x18 (ES8311 codec), 0x34 (TCA8418 keyboard), **0x43 (PI4IOE5V6408, ID register 0xA2)**, 0x69 (BMI270 IMU).
- **The SX1262 answers** on NSS 5, RST 3, DIO1 4, BUSY 6. Its version string reads `SX1261 V2D 2D02`, which SX1262 chips report too. **The 1.8 V TCXO works** on the first try; the radio is ready 38 ms after `begin`.
- **The expander's P0 connects the antenna; it's required.** At power-on P0 is an input (direction 0x00, high-impedance 0xFF), and the receiver reads a flat **-111.9 dBm** at 869.525 MHz, BW 250 kHz: the chip's own floor, deaf. With P0 driven high, the noise floor is **-87 to -94 dBm**: the antenna hearing the room. So the Radio Service drives P0 high at boot (Q91).
- **DIO2 doesn't change reception** (within ±2 dB over three runs, P0 high). It likely selects TX versus RX in the FM8625H; it stays the RF switch, as in Meshtastic.
- **The noise floor at the desk is high** (-87 to -94 dBm, varying run to run), about 25 dB above thermal noise for 250 kHz. Something nearby is loud, possibly the Cardputer itself or the PC; Sweep (step 5) should show where it sits.
- **Step 2:** presets, frequencies and the channel hash are checked against Meshtastic's source (`MeshRadio.h`, `RadioInterface.cpp`): LongFast and the default key give hash 8, MediumFast 31, as Meshtastic shows. Captures were checked with TShark 4.2.5: every LoRaTap field reads back. Wireshark ignores the spec's quarter-dB packet RSSI below 0 dB SNR, so packet RSSI is plain dBm.
- **Step 3:** the DIO1 interrupt works (a 100 ms receive timeout wakes the task after 105 ms). While listening: four 1.7 MB uploads and Gemini pages to the card, no radio or card errors (the card refuses a write about once in five uploads with the radio asleep too; `put` now catches it, and issue #21 follows the cause). The ring takes 9.8 KB while listening; the radio task's stack peaks at 2.0 KB.
- **No packets yet, and a loud desk.** Twenty minutes on LongFast and on LoRaWAN's three uplink frequencies (SF7, SF9, SF12): no packet and no header, valid or not. The noise floor reads -83 to -94 dBm, against -112 dBm with the antenna switched off: 20 to 30 dB lost to something nearby, not the screen and not the GNSS receiver. Preamble detections are false alarms at this noise level (more on an empty frequency, 869.0 MHz, than on LongFast).
- **Step 4:** a Capture made on the device reads back in TShark field for field (time, frequency, SF, RSSI, SNR, payload). A Capture keeps the radio listening with the App closed; stopping it puts the radio back to sleep.
- **Step 5:** a pass across 863–870 MHz (71 steps, the strongest of three RSSI readings at each, measured at 125 kHz) takes about 607 ms. At the desk the band is **flat at -100 to -102 dBm**, about 15 dB above the chip's own floor at 125 kHz, with a steady carrier at 863.2 MHz (-89 dBm at its strongest) and fainter lines elsewhere: broadband noise from nearby electronics rather than a transmitter. Sweep's waterfall takes 2.6 KB while shown; 91.9 KB free during a Sweep. The radio task's stack peaks at 1.9 KB.
- **Outside, on battery (step 6).** The noise is no lower than at the desk: a Sweep floor of -96 to -99 dBm (median -97) with Wi-Fi on, -99 to -100 with Wi-Fi off, so Wi-Fi accounts for 2 or 3 dB. The same narrow peaks come back on every pass, at 863.2, 863.6, 864.4, 864.8, 865.9, 866.3, 867.8, 869.0 and 869.4 MHz (-88 to -91 dBm), several of them 400 kHz apart; 869.4 MHz is the lower edge of LongFast's channel. A source that follows the device outside and onto its battery is the device: **about 15 dB of the floor is the Cardputer's own** (issue #20). At SF11 that puts the weakest decodable packet near -114 dBm on LongFast, against about -130 dBm for a quiet receiver.
- **The listening hour (step 6, Q104):** 20:33 to 21:34 on 2026-10-05, outside, on battery, LongFast, with a Capture running. **0 packets, 0 headers**, 0 radio errors; noise -85 to -87 dBm at 250 kHz throughout; 860 preamble detections, all false alarms. The Capture holds its 24-byte header and nothing else. No restart in 1 h 10 min.
- **Floors (Q86):** with the radio listening, Wi-Fi and IRC connected over TLS, 52.6 KB free (lowest 22.7 KB during the TLS handshake, the dip accepted in G1). Without IRC, 93 KB.
- **Receive only:** nothing in `src` or `lib` calls a transmit function.
- **Cost:** RadioLib 7.8.1 and the probe add 23.6 KB of flash and 656 bytes of static RAM to the release firmware (1,679,843 bytes of 3,342,336). The whole milestone: 51.8 KB of flash (1,708,091 bytes), 365 tests (27 new).
## Decisions (design round 2026-10-05)
| # | Decision |
|---|---|
| Q89 | **M3 is the radio only:** Radio Service, Sniffer, Sweep. Notes and the File Browser (Q30) move out to issue #3 and a Notes issue, as a later side milestone. |
| Q90 | **RadioLib**, pinned (ADR 0001). SX1262 on NSS 5, RST 3, DIO1 4, BUSY 6; DIO2 as RF switch; TCXO at 1.8 V tried first, falling back to the crystal (Meshtastic's `TCXO_OPTIONAL`). |
| Q91 | Step 1 is `lora probe`: chip status and version, which oscillator setting worked, and an I2C scan of the internal bus for the PI4IOE5V6408. If present, its P0 is set high at boot (harmless) and DIO2 stays the switch. A wrong switch receives deaf, so compare noise floors. |
| Q92 | A **Radio Service** owns the SX1262: driver, bus lock, IRQ task. The LoRa Scanner uses it in M3; the Mesh Service sits on top of it in M4. |
| Q93 | Every radio transfer takes the shared bus lock (`SPI.beginTransaction`, as the card does). DIO1's interrupt only wakes the task; no SPI in the ISR. **Done when** a Gemini page streams to the card while the Sniffer receives, with no lost packets and no card errors (`lora status` counters). |
| Q94 | **Receive only:** the Radio Service has no transmit function in M3. It doesn't exist, rather than being unused. |
| Q95 | Sniffer defaults: **EU868 LongFast**, 869.525 MHz, BW 250 kHz, SF 11, CR 4/5, sync word 0x2B, preamble 16 (Q19). The other Meshtastic presets are offered, plus custom settings. |
| Q96 | The Sniffer lists packets (time, RSSI, SNR, frequency error, length; hex dump on Enter) **and decodes the Meshtastic header**: the first 16 bytes are never encrypted (destination, sender, packet ID, hop limit and hop start, channel hash, next hop, relay node). Host-tested. Payload decryption is M4. |
| Q97 | A Sniffer **Capture** is pcap with **LoRaTap** headers (link type 270), for Wireshark. Started by hand, Status Bar mark, its own Clean-up category, the 90% rule. |
| Q98 | **Sweep** steps across the Region's band (863–870 MHz) in 100 kHz steps by default, reading instant RSSI: bars with peak hold, and a waterfall, Wi-Fi Tools style. Optionally CAD on the preset's frequency to tell LoRa traffic from noise. |
| Q99 | Sweep takes the radio and pauses the Sniffer, visibly (Q18). From M4 it pauses the Mesh Service the same way. |
| Q100 | The Sniffer runs while the App is open **or a Capture is recording**; otherwise the radio sleeps. From M4 the Mesh Service keeps it on. |
| Q101 | **Status Bar:** a radio mark while receiving, flashing on each packet; muted during a Sweep. |
| Q102 | Debug aids: `lora status` (settings, counters, last RSSI/SNR, noise floor), `lora probe`, `lora rx on/off` (packets on the consoles). Raw packets are never written to the card outside a Capture. |
| Q103 | A ring of the **last 32 packets** in RAM (about 9 KB at full length); older ones are dropped unless capturing. IRQ task stack trimmed by measurement; RadioLib's flash and RAM measured in step 1 against the floors. |
| Q104 | **Done when** (below) includes an hour of listening on LongFast by a window. Real packets heard become M4 test fixtures. If none are heard, M3 still closes, and a reference Meshtastic node (Q21) becomes a requirement for M4. |
## Done when
- `lora probe` reports the SX1262, its oscillator setting and the RF switch arrangement, and the result is written here.
- The Sniffer receives on LongFast with the App open or a Capture running, and the radio sleeps otherwise.
- Sweep shows the noise floor across 863–870 MHz, and a known signal (a remote key fob, a 868 MHz sensor, anything) stands out. *Half met: the floor and the device's own steady peaks show; no known transmitter was tried.*
- The shared-bus test passes (Q93): a Gemini page to the card while the Sniffer receives, no lost packets, no card errors.
- A Capture opens in Wireshark with LoRaTap fields.
- The Status Bar mark follows Q101.
- One hour of LongFast listening by a window has been run and its result recorded here. *Run outside, on battery.*
- Free heap stays above the floors (Q86) with the Sniffer, Wi-Fi, IRC on TLS and the UI running.
- Nothing in the firmware can transmit.
## Work breakdown
1. **Hardware check:** RadioLib in the build, `lora probe` (Q91), flash and RAM cost measured.
2. **Meshtastic header and LoRaTap** (host-tested): header parsing, presets and their radio settings, pcap/LoRaTap writing.
3. **Radio Service:** receive on its own task behind the bus lock, the packet ring, `lora status` and `lora rx`, the shared-bus test.
4. **LoRa Scanner App, Sniffer:** the packet list, details, preset choice, Captures, Status Bar mark.
5. **Sweep:** the RSSI sweep, bars and waterfall, pausing the Sniffer.
6. **Listening hour** and the measurements above, recorded here.
+33
View File
@@ -0,0 +1,33 @@
# OTA — Firmware Updates over Wi-Fi and from the SD card
**Goal:** install new firmware without a USB cable. Push it from the PC over Wi-Fi, or drop it on the SD card. Unsigned images are refused, and a broken update rolls back by itself.
## Decisions (design round 2026-10-03)
| # | Decision |
|---|---|
| Q52 | Two sources: **push over Wi-Fi** from the PC, and **from the SD card**. Pulling from Gitea releases is deferred. |
| Q53 | **Signed Update Files** (ECDSA P-256 over SHA-256). The private key stays in `~/.config/roro9stack/`, and the firmware embeds the public key (ADR 0003). |
| Q54 | The device **always listens** for pushes on the LAN while Wi-Fi is Connected. *Revised in M2:* it was announced over mDNS as `roro9stack-<id>.local`; mDNS was removed to save RAM (it never crossed the dev box's routed network anyway). Pushes go to the IP shown in Settings → Firmware. |
| Q55 | New firmware runs on **Probation**. It's confirmed once booted, UI drawn, Services started, 30 s without a crash, and Wi-Fi connected (if configured). Otherwise **Rollback**. A Toast reports either outcome. |
| Q56 | **Downgrades are allowed**, with "older than the installed version" shown. |
| Q57 | A valid push **installs right away**: progress screen, then reboot. The reboot waits for Text Entry to end, 60 s at most. |
## Done when
- `scripts/ota_keygen.sh` creates the key pair once. The public key is committed; the private key never is.
- `scripts/flash.sh --ota` builds, signs and pushes to `roro9stack-<id>.local`. The device shows progress, reboots, and a Toast confirms the new version.
- An Update File with a bad signature, a truncated or corrupted image, or no signature is refused, and the device keeps running.
- Settings → About → **Update from SD** lists the `.ota` files in `/updates` and installs one.
- A firmware that crashes during Probation rolls back to the previous version, and says so after the reboot.
## Work breakdown
1. **Update File format** (host-tested): header (magic, format, version, image size, SHA-256), signature, image. A streaming parser that hashes as it goes and decides accept / refuse / downgrade. The signature verifier sits behind an interface, so tests can inject one.
2. **PC side:** key generation, `make_ota.py` (wraps `firmware.bin` into a signed `.ota`), and the push client. `flash.sh --ota` ties them together.
3. **Device:** the Update Service.
- A listener on TCP 3232 plus mDNS.
- Writes the image to the inactive app slot, with the ECDSA check through mbedTLS.
- A progress screen, and a reboot that waits out Text Entry.
4. **Probation and Rollback:** the health checks, confirming the image, and detecting a rollback after reboot to report it.
5. **Update from SD:** the same parser, fed from the Storage Service's task (all card access stays there).
+138
View File
@@ -0,0 +1,138 @@
# S1 — System basics
**Status:** the three planned items are done: the SD driver fix in v0.6.1 (issue #21, ADR 0007), fixed IPv4 settings in v0.7.0 (issue #7), the System App in v0.8.0 (issue #11). v0.8.1 adds the resting main loop (issue #40) and the GNSS pause for the radio's noise (issue #20, still open for the 11 dB that remain). Still open in the milestone: #39, following the SD driver upstream.
**Goal:** the device works on any network, the card can be trusted, and you can see what the system is doing. A side milestone, like G1.
## Fixed IPv4, DNS and NTP (issue #7)
Not every network has a DHCP server: a lab bench, a direct link to a router, a network where addresses are handed out by hand. Until now every Saved Network used DHCP, DNS always came from DHCP, and the NTP server was `pool.ntp.org`, hard-coded.
**IPv4 only.** IPv6 isn't part of this, now or as a planned follow-up.
### Decisions (design round 2026-10-05)
| # | Decision |
|---|---|
| Q105 | The IP setting is **per Saved Network**: *Automatic* (DHCP, as before) or *Fixed*, with its own address, prefix and gateway. New networks start Automatic. |
| Q106 | The subnet is entered as a **prefix length** (`24`), with the mask shown next to it. |
| Q107 | The **gateway is optional**: left empty, the device talks to its own subnet only. |
| Q108 | **DNS is global:** two servers in Settings, used on every Fixed network. On Automatic networks DHCP's DNS is used, unless **"Always use my DNS"** is on. |
| Q109 | DNS defaults: **9.9.9.9** (Quad9), then **1.1.1.1** (Cloudflare). |
| Q110 | **NTP is global:** two servers in Settings, names or addresses, defaulting to `pool.ntp.org` and `time.cloudflare.com`. NTP servers offered by DHCP are used first. GNSS still outranks NTP for the clock. |
| Q111 | What's typed is checked, host-tested in `lib/wifi`: an address is four numbers from 0 to 255; a prefix is 1 to 30; the address isn't the subnet's network or broadcast address; the gateway is inside the subnet and isn't the device's own address. Refusals say why. |
| Q112 | Addresses are typed in the line editor, limited to digits and dots. |
| Q113 | Enter on a Saved Network opens **its page** (IP, Address, Prefix, Gateway, Forget) instead of asking to forget it. Settings > Wi-Fi gains DNS servers, "Always use my DNS" and NTP servers. The Status row opens **connection details**: address, mask, gateway, DNS and NTP in use, and where each came from. |
| Q114 | A change applies **at once**: the network in use reconnects with the new settings. No automatic way back; the keyboard still works if Wi-Fi is cut. |
| Q115 | Console: `wifi status` shows address, gateway, DNS, NTP and their sources; `wifi ip <ssid> dhcp`, `wifi ip <ssid> <address>/<prefix> [gateway]`, `wifi dns <a> [b]`, `wifi ntp <a> [b]`. Debug Builds: `wifi ip … try 60` goes back to the previous setting after 60 s unless confirmed with `wifi ip keep`. |
| Q116 | Left out: checking whether the address is already taken, and per-network DNS. |
The SDK already allows 3 NTP servers and 3 DNS servers and can take NTP servers from DHCP (`CONFIG_LWIP_SNTP_MAX_SERVERS=3`, `CONFIG_LWIP_DHCP_GET_NTP_SRV=y`), so the framework isn't rebuilt for this.
### Done when
- A Saved Network set to Fixed joins with that address, mask and gateway, and the device reaches the internet (IRC, Gemini, NTP) through the DNS servers from Settings.
- Set back to Automatic, it gets its address from DHCP again.
- With "Always use my DNS" on, an Automatic network resolves through the servers from Settings.
- The NTP servers from Settings set the clock.
- Wrong entries are refused with a reason, in Settings and on the console.
- Connection details show what's in use and where it came from.
- Tested on `knbg-guests` with 10.39.39.12 (the device's DHCP lease) and 10.39.39.13 (free: the device is alone on that network).
### Measured (2026-10-05 and 06, on `knbg-guests`)
The network is 10.39.39.0/24, gateway 10.39.39.1; DHCP gives 10.39.39.1 as DNS and offers no NTP server.
- **Fixed 10.39.39.12/24** (the device's own lease) and **Fixed 10.39.39.13/24**, gateway 10.39.39.1: the device joins with that address, DNS is 9.9.9.9 and 1.1.1.1 from Settings, and a Gemini page loads (name resolution, routing, TLS). On .13, .12 no longer answers.
- **A wrong gateway** (10.39.39.254) on a 60 s trial: the device stops answering from another subnet, and comes back by itself with the previous setting.
- **Back to Automatic:** 10.39.39.12 by DHCP again, DNS 10.39.39.1 from DHCP.
- **"Always use my DNS"** on an Automatic network: DNS becomes 9.9.9.9 and 1.1.1.1; switched off, the device joins again and has DHCP's DNS back.
- **NTP:** `pool.ntp.org` answers; set to `time.cloudflare.com` alone, that one answers within 25 s.
- **Refusals**, on the console and in Settings: the network's own address, a gateway outside the subnet, a prefix of 31 or 99, 10.39.39.300, an unknown network, a DNS name where an address is needed, a host name with an underscore.
- **In Settings:** the network's page pre-fills Fixed with the address, prefix and gateway in use; leaving the page applies it; connection details show each value and where it came from.
- **Not tested:** NTP servers offered by DHCP (this network offers none), and a Fixed network with no gateway.
### Work breakdown
1. **IPv4 logic** (host-tested): parsing and formatting addresses, prefix and mask, the checks of Q111.
2. **Storage:** the IP setting in each Saved Network; DNS, "Always use my DNS" and NTP in Settings.
3. **Wi-Fi Service:** apply it when joining; DNS and NTP; `wifi status` and the console commands.
4. **Settings:** the network page, the DNS and NTP rows, connection details.
5. **Tests on the device**, recorded here.
## System Monitor (issue #11)
Every milestone so far was driven by measurements, heap floors, stack sizes, TLS dips, that needed a Debug Build and a computer. The System App shows them on the device, in any build.
### Decisions (design round 2026-10-06)
| # | Decision |
|---|---|
| Q117 | An App of its own, **System**, in release builds too. Read-only. |
| Q118 | Four views, switched with Tab: **Overview** (CPU per core, memory, network, battery), **Tasks**, **Memory**, **System**. |
| Q119 | Sampled once a second. A task's share is its run time over the last second; a core's load is 100 % minus its idle task's share. |
| Q120 | **History only while the App is open:** two minutes at one sample a second, about 1 KB. The system already keeps what matters afterwards: the lowest free heap since boot and each task's lowest free stack. |
| Q121 | **Bytes are counted per service:** IRC, Gemini, the Debug Console and Firmware Updates add what they read and write to a shared counter. The network view shows the connection details, each service's bytes in and out, and the signal strength. |
| Q122 | Tasks: name, core, share, state and lowest free stack, sorted by share; `s` cycles the sort (share, stack, name). **Under 512 bytes of stack left shows in the warning colour.** |
| Q123 | Memory: free heap, lowest since boot, largest free block, and a two-minute graph of free heap **with the floors of Q86 drawn as lines** (55, 40 and 20 KB). |
| Q124 | System: uptime and why it last started, firmware and both app slots, chip temperature and CPU frequency, battery voltage and percentage, SD usage and write faults, the radio's and the GNSS receiver's state. |
| Q125 | `info` and `tasks` are split into a **snapshot** that the console and the App share; the arithmetic (shares from two samples, sorting, the stack warning) is host-tested. |
| Q126 | Left out: acting on tasks, an event log, exporting snapshots to the card. |
| Q127 | The main loop uses about 81 % of a core. The App shows it; fixing it is issue #40, not part of #11. |
The App has five views, not four: Q121's network view is one of its own (Overview, Tasks, Memory, Network, System).
### Measured (2026-10-06)
- **Traffic counters are exact.** A Gemini fetch of a 164,970-byte page counts 164,986 bytes in (the page and its 16-byte header line) and 42 out (the 40-character URL and CRLF). A 1,797,760-byte upload counts 1,798,123 in for the Debug Console, commands included.
- **The Memory view shows a TLS dip as it happens.** Starting IRC and a 165 KB Gemini fetch together: free heap falls from about 100 KB through the three floors to a low of 12.1 KB, then settles near 50 KB. That's the dip accepted in G1 (Q86).
- **A run-time counter only moves when its task is switched out.** FreeRTOS adds to a task's run time at the context switch. The main loop takes the samples, and with core 1 to itself it's never switched out: its counter said 2 % while the core's idle task had 0 %. So the task that samples gets what's left of its core. With that: **the main loop uses 100 % of core 1 at rest** (issue #40 said 81 %, an average since boot).
- **`tasks` on the console** sampled twice inside one command at first, a quarter second apart, and showed the loop at 1 %: it was asleep in the command's own wait. It now samples, lets the loop run for a second, and prints.
- **Low stack, flagged:** `IDLE0` (232 bytes left), `IDLE1` (328 to 352) and `spk_task` (256 to 264), all the framework's own tasks.
- **Cost:** 15.6 KB of flash for the App and the counters (1,742,723 bytes, release). Nothing while it's closed; about 2 KB of history and samples while it's open.
## The main loop rests (issue #40)
The loop polled the keyboard, ticked the Services, ran the consoles and redrew when needed, then came straight back: 50,000 passes a second, and core 1 100 % busy with the device idle and the screen off.
Nothing needs that. The keyboard controller buffers key events; the consoles and the radio have their own tasks or interrupts; no Service asks for a tick more often than every 50 ms. So after each pass the loop now rests: **5 ms with the screen on, 20 ms with it off**, and not at all during a serial file transfer (`sd put`), which reads its bytes from the loop. Safe Mode's loop rests 5 ms too. Debug Builds have `loop spin on|off` to bring the old behaviour back for comparison.
### Measured (2026-10-06, Debug Build, Wi-Fi connected, GNSS on, on USB power)
| | Spinning | Resting |
|---|---|---|
| Passes a second, screen off | 50,160 | 50 |
| Core 1 load, screen off | 100 % | 1 % |
| Passes a second, screen on (Launcher) | 1,203 | 167 |
| Core 1 load, screen on | 62 % | 10 % |
| Chip temperature at rest, settled | 38.3 C | 34.3 C |
| A 1.8 MB upload over the Debug Console | about 230 KB/s | 288 KB/s |
- Still working at this pace: GNSS (a 3D Fix, 22 satellites), a Gemini fetch (52 KB), the upload read back by SHA-256, the Sweep (still 606 to 610 ms a pass), the radio's DIO1 interrupt.
- **Not measured:** the current drawn (no meter on the battery line), and how typing feels on the real keyboard: a key now waits up to 5 ms for the loop, 20 ms if it's the one that wakes the screen.
- **The radio's noise floor didn't move** (-97 to -99 dBm at 125 kHz either way): the spinning loop wasn't the source (issue #20).
- **Not done:** real sleep. The framework is built without power management (`CONFIG_PM_ENABLE` is off), so an idle core only halts until the next interrupt. Automatic light sleep would need the framework rebuilt with it, Wi-Fi in modem sleep, and the USB serial port's behaviour checked. A next step if battery life calls for it.
## The radio's noise: the GNSS receiver (issue #20)
M3 found the LoRa radio's noise floor about 15 dB above what the chip hears alone, and that the source travels with the device. Which part? Debug Builds got a self-test, `lora noise test`: it changes one thing at a time, Sweeps the band eight passes (568 readings), records the median as the floor, and puts the thing back. It runs on the device by itself, because one condition switches Wi-Fi off, and `lora noise report` prints the result afterwards.
### Measured (2026-10-06, indoors, on USB power, dBm at 125 kHz)
| Condition | Floor |
|---|---|
| Antenna switched off (the chip alone) | -117 |
| Antenna on, GNSS in standby | -106 |
| Antenna on, GNSS running (as shipped) | -98 |
- **The GNSS receiver, while it runs, raises the floor by 8 dB.** Three runs: -98 or -99 with it running, -106 in standby, every time. On LongFast (250 kHz) the Sniffer's own reading goes from about -93.5 to -101.5 dBm.
- **It's the receiver working, not its serial line:** with one NMEA sentence a second instead of twenty (`PCAS03`), the receiver still tracking, the floor stays at -98.
- **Nothing else moves it by more than 1 dB**, with GNSS running or in standby: the main loop spinning or resting, the CPU at 240, 160 or 80 MHz, Wi-Fi on or off, the screen on or off, the radio chip's regulator as DC-DC or LDO, its receive gain boosted or not.
- **11 dB remain** between the antenna connected with GNSS quiet (-106) and the chip alone (-117). It comes in through the antenna and none of those switches changes it: the surroundings, or parts of the Cardputer that can't be switched off. Not separated: that needs another place, or the antenna on a cable away from the case.
- M3's quick check had GNSS at "1 or 2 dB": it read one frequency for a few seconds, in a noisier spot. The median over the band is the better measure.
### What the firmware does about it
**Settings > Pause GNSS for LoRa**, off by default: while the LoRa radio listens or sweeps, the GNSS receiver waits in standby, and wakes when the radio goes back to sleep (a Fix again after about 7 s here). Never during a Track. The GNSS App says "GNSS is paused" meanwhile. `gnss quiet on|off` on the console.
It's off by default because GNSS on by default was decided in M2 (Q58), and from M4 the radio listens all the time: then "pause while listening" means GNSS mostly off, which is a decision about position, the clock and Tracks, for M4's design round (issue #23).
+4
View File
@@ -0,0 +1,4 @@
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEIWzT07fvTpQxWjTdewMipYH6f42+
mM8niHm+T8y+Mvjanb3H8hpYXg3VjuJGFtcHw/hFX0Q2f2AiSHMF0DhMbQ==
-----END PUBLIC KEY-----
+7
View File
@@ -0,0 +1,7 @@
{
"name": "SD",
"version": "3.3.12",
"description": "roro9stack's copy of Arduino-ESP32's SD library (Apache-2.0), shadowing the framework's. Only sd_diskio.cpp is changed (marked \"roro:\"): it records why a write failed and resends a block the card rejects. See issue #21.",
"frameworks": "arduino",
"platforms": "espressif32"
}
+134
View File
@@ -0,0 +1,134 @@
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
#include "vfs_api.h"
#include "sd_diskio.h"
#include "ff.h"
#include "FS.h"
#include "SD.h"
using namespace fs;
SDFS::SDFS(FSImplPtr impl) : FS(impl), _pdrv(0xFF) {}
SDFS::~SDFS() {
end();
}
bool SDFS::begin(uint8_t ssPin, SPIClass &spi, uint32_t frequency, const char *mountpoint, uint8_t max_files, bool format_if_empty) {
if (_pdrv != 0xFF) {
return true;
}
if (!spi.begin()) {
return false;
}
_pdrv = sdcard_init(ssPin, &spi, frequency);
if (_pdrv == 0xFF) {
return false;
}
if (!sdcard_mount(_pdrv, mountpoint, max_files, format_if_empty)) {
sdcard_unmount(_pdrv);
sdcard_uninit(_pdrv);
_pdrv = 0xFF;
return false;
}
_impl->mountpoint(mountpoint);
return true;
}
void SDFS::end() {
if (_pdrv != 0xFF) {
_impl->mountpoint(NULL);
sdcard_unmount(_pdrv);
sdcard_uninit(_pdrv);
_pdrv = 0xFF;
}
}
sdcard_type_t SDFS::cardType() {
if (_pdrv == 0xFF) {
return CARD_NONE;
}
return sdcard_type(_pdrv);
}
uint64_t SDFS::cardSize() {
if (_pdrv == 0xFF) {
return 0;
}
size_t sectors = sdcard_num_sectors(_pdrv);
size_t sectorSize = sdcard_sector_size(_pdrv);
return (uint64_t)sectors * sectorSize;
}
size_t SDFS::numSectors() {
if (_pdrv == 0xFF) {
return 0;
}
return sdcard_num_sectors(_pdrv);
}
size_t SDFS::sectorSize() {
if (_pdrv == 0xFF) {
return 0;
}
return sdcard_sector_size(_pdrv);
}
uint64_t SDFS::totalBytes() {
FATFS *fsinfo;
DWORD fre_clust;
char drv[3] = {(char)(48 + _pdrv), ':', 0};
if (f_getfree(drv, &fre_clust, &fsinfo) != 0) {
return 0;
}
uint64_t size = ((uint64_t)(fsinfo->csize)) * (fsinfo->n_fatent - 2)
#if _MAX_SS != 512
* (fsinfo->ssize);
#else
* 512;
#endif
return size;
}
uint64_t SDFS::usedBytes() {
FATFS *fsinfo;
DWORD fre_clust;
char drv[3] = {(char)(48 + _pdrv), ':', 0};
if (f_getfree(drv, &fre_clust, &fsinfo) != 0) {
return 0;
}
uint64_t size = ((uint64_t)(fsinfo->csize)) * ((fsinfo->n_fatent - 2) - (fsinfo->free_clst))
#if _MAX_SS != 512
* (fsinfo->ssize);
#else
* 512;
#endif
return size;
}
bool SDFS::readRAW(uint8_t *buffer, uint32_t sector) {
return sd_read_raw(_pdrv, buffer, sector);
}
bool SDFS::writeRAW(uint8_t *buffer, uint32_t sector) {
return sd_write_raw(_pdrv, buffer, sector);
}
SDFS SD = SDFS(FSImplPtr(new VFSImpl()));
+55
View File
@@ -0,0 +1,55 @@
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
#ifndef _SD_H_
#define _SD_H_
#include "FS.h"
#include "SPI.h"
#include "sd_defines.h"
namespace fs {
class SDFS : public FS {
protected:
uint8_t _pdrv;
public:
SDFS(FSImplPtr impl);
~SDFS();
bool begin(
uint8_t ssPin = SS, SPIClass &spi = SPI, uint32_t frequency = 4000000, const char *mountpoint = "/sd", uint8_t max_files = 5, bool format_if_empty = false
);
void end();
sdcard_type_t cardType();
uint64_t cardSize();
size_t numSectors();
size_t sectorSize();
uint64_t totalBytes();
uint64_t usedBytes();
bool readRAW(uint8_t *buffer, uint32_t sector);
bool writeRAW(uint8_t *buffer, uint32_t sector);
};
} // namespace fs
#if !defined(NO_GLOBAL_INSTANCES) && !defined(NO_GLOBAL_SD)
extern fs::SDFS SD;
#endif
using namespace fs;
typedef fs::File SDFile;
typedef fs::SDFS SDFileSystemClass;
#define SDFileSystem SD
#endif /* _SD_H_ */
+25
View File
@@ -0,0 +1,25 @@
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
#ifndef _SD_DEFINES_H_
#define _SD_DEFINES_H_
typedef enum {
CARD_NONE,
CARD_MMC,
CARD_SD,
CARD_SDHC,
CARD_UNKNOWN
} sdcard_type_t;
#endif /* _SD_DISKIO_H_ */
+949
View File
@@ -0,0 +1,949 @@
// roro9stack's copy of the SD-over-SPI driver from Arduino-ESP32 3.3.12 (libraries/SD/src/
// sd_diskio.cpp), linked instead of the framework's: defining every function the SD class needs
// keeps the library's file out of the link. Changes are marked "roro:". Why (issue #21): the
// original gives up on a write without saying why, and never resends a block the card rejects.
//
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Disable the automatic pin remapping of the API calls in this file
#define ARDUINO_CORE_BUILD
#include "Arduino.h"
#include "sd_diskio.h"
#include "esp_system.h"
#include "esp32-hal-periman.h"
extern "C" {
#include "ff.h"
#include "diskio.h"
#if ESP_IDF_VERSION_MAJOR > 3
#include "diskio_impl.h"
#endif
//#include "esp_vfs.h"
#include "esp_vfs_fat.h"
char CRC7(const char *data, int length);
unsigned short CRC16(const char *data, int length);
}
// roro: why the last write failed.
#include "sd_fault.h"
static roro::SdFault s_fault;
static bool sdFault(roro::SdFault::Step step, uint8_t token = 0, uint32_t resp = 0) {
s_fault.step = step;
s_fault.token = token;
s_fault.resp = resp;
s_fault.count++;
return false;
}
namespace roro {
SdFault sdLastFault() { return s_fault; }
} // namespace roro
typedef enum {
GO_IDLE_STATE = 0,
SEND_OP_COND = 1,
SEND_CID = 2,
SEND_RELATIVE_ADDR = 3,
SEND_SWITCH_FUNC = 6,
SEND_IF_COND = 8,
SEND_CSD = 9,
STOP_TRANSMISSION = 12,
SEND_STATUS = 13,
SET_BLOCKLEN = 16,
READ_BLOCK_SINGLE = 17,
READ_BLOCK_MULTIPLE = 18,
SEND_NUM_WR_BLOCKS = 22,
SET_WR_BLK_ERASE_COUNT = 23,
WRITE_BLOCK_SINGLE = 24,
WRITE_BLOCK_MULTIPLE = 25,
APP_OP_COND = 41,
APP_CLR_CARD_DETECT = 42,
APP_CMD = 55,
READ_OCR = 58,
CRC_ON_OFF = 59
} ardu_sdcard_command_t;
// Align with ESP-IDF sdmmc SPI init (ACMD41 timeout must be >1s per SD spec)
static constexpr uint32_t sd_go_idle_delay_ms = 20;
static constexpr uint32_t sd_op_cond_timeout_ms = 3000;
typedef struct {
uint8_t ssPin;
SPIClass *spi;
int frequency;
char *base_path;
sdcard_type_t type;
unsigned long sectors;
bool supports_crc;
int status;
} ardu_sdcard_t;
static ardu_sdcard_t *s_cards[FF_VOLUMES] = {NULL};
#if ARDUHAL_LOG_LEVEL >= ARDUHAL_LOG_LEVEL_ERROR
const char *fferr2str[] = {
"(0) Succeeded",
"(1) A hard error occurred in the low level disk I/O layer",
"(2) Assertion failed",
"(3) The physical drive cannot work",
"(4) Could not find the file",
"(5) Could not find the path",
"(6) The path name format is invalid",
"(7) Access denied due to prohibited access or directory full",
"(8) Access denied due to prohibited access",
"(9) The file/directory object is invalid",
"(10) The physical drive is write protected",
"(11) The logical drive number is invalid",
"(12) The volume has no work area",
"(13) There is no valid FAT volume",
"(14) The f_mkfs() aborted due to any problem",
"(15) Could not get a grant to access the volume within defined period",
"(16) The operation is rejected according to the file sharing policy",
"(17) LFN working buffer could not be allocated",
"(18) Number of open files > FF_FS_LOCK",
"(19) Given parameter is invalid"
};
#endif
/*
* SD SPI
* */
bool sdWait(uint8_t pdrv, int timeout) {
char resp;
uint32_t start = millis();
do {
resp = s_cards[pdrv]->spi->transfer(0xFF);
} while (resp == 0x00 && (millis() - start) < (unsigned int)timeout);
if (!resp) {
log_w("Wait Failed");
}
return (resp > 0x00);
}
void sdStop(uint8_t pdrv) {
s_cards[pdrv]->spi->write(0xFD);
}
void sdDeselectCard(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
digitalWrite(card->ssPin, HIGH);
}
bool sdSelectCard(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
digitalWrite(card->ssPin, LOW);
// roro: one dummy byte before asking whether the card is ready, as ChaN's reference driver does.
// A card that has just been given a write takes about a byte of clock to signal busy; without
// this, that first byte reads 0xFF, "ready", and the next command (the status check after a
// write) goes out while the card is still programming and comes back as garbage (#21).
card->spi->transfer(0xFF);
bool s = sdWait(pdrv, 500);
if (!s) {
log_e("Select Failed");
digitalWrite(card->ssPin, HIGH);
return false;
}
return true;
}
char sdCommand(uint8_t pdrv, char cmd, unsigned int arg, unsigned int *resp) {
char token;
ardu_sdcard_t *card = s_cards[pdrv];
for (int f = 0; f < 3; f++) {
if (cmd == SEND_NUM_WR_BLOCKS || cmd == SET_WR_BLK_ERASE_COUNT || cmd == APP_OP_COND || cmd == APP_CLR_CARD_DETECT) {
token = sdCommand(pdrv, APP_CMD, 0, NULL);
sdDeselectCard(pdrv);
if (token > 1) {
break;
}
if (!sdSelectCard(pdrv)) {
token = 0xFF;
break;
}
}
char cmdPacket[7];
cmdPacket[0] = cmd | 0x40;
cmdPacket[1] = arg >> 24;
cmdPacket[2] = arg >> 16;
cmdPacket[3] = arg >> 8;
cmdPacket[4] = arg;
if (card->supports_crc || cmd == GO_IDLE_STATE || cmd == SEND_IF_COND) {
cmdPacket[5] = (CRC7(cmdPacket, 5) << 1) | 0x01;
} else {
cmdPacket[5] = 0x01;
}
cmdPacket[6] = 0xFF;
card->spi->writeBytes((uint8_t *)cmdPacket, (cmd == STOP_TRANSMISSION) ? 7 : 6);
for (int i = 0; i < 9; i++) {
token = card->spi->transfer(0xFF);
if (!(token & 0x80)) {
break;
}
}
if (token == 0xFF) {
log_w("no token received");
sdDeselectCard(pdrv);
delay(100);
sdSelectCard(pdrv);
continue;
} else if (token & 0x08) {
log_w("crc error");
sdDeselectCard(pdrv);
delay(100);
sdSelectCard(pdrv);
continue;
} else if (token > 1) {
log_w("token error [%u] 0x%x", cmd, token);
break;
}
if (cmd == SEND_STATUS && resp) {
*resp = card->spi->transfer(0xFF);
} else if ((cmd == SEND_IF_COND || cmd == READ_OCR) && resp) {
*resp = card->spi->transfer32(0xFFFFFFFF);
}
break;
}
if (token == 0xFF) {
log_e("Card Failed! cmd: 0x%02x", cmd);
card->status = STA_NOINIT;
}
return token;
}
bool sdReadBytes(uint8_t pdrv, char *buffer, int length) {
char token;
unsigned short crc;
ardu_sdcard_t *card = s_cards[pdrv];
uint32_t start = millis();
do {
token = card->spi->transfer(0xFF);
} while (token == 0xFF && (millis() - start) < 500);
if (token != 0xFE) {
return false;
}
card->spi->transferBytes(NULL, (uint8_t *)buffer, length);
crc = card->spi->transfer16(0xFFFF);
return (!card->supports_crc || crc == CRC16(buffer, length));
}
char sdWriteBytes(uint8_t pdrv, const char *buffer, char token) {
ardu_sdcard_t *card = s_cards[pdrv];
unsigned short crc = (card->supports_crc) ? CRC16(buffer, 512) : 0xFFFF;
if (!sdWait(pdrv, 500)) {
return 0;
}
card->spi->write(token);
card->spi->writeBytes((uint8_t *)buffer, 512);
card->spi->write16(crc);
return (card->spi->transfer(0xFF) & 0x1F);
}
/*
* SPI SDCARD Communication
* */
char sdTransaction(uint8_t pdrv, char cmd, unsigned int arg, unsigned int *resp) {
if (!sdSelectCard(pdrv)) {
return 0xFF;
}
char token = sdCommand(pdrv, cmd, arg, resp);
sdDeselectCard(pdrv);
return token;
}
bool sdReadSector(uint8_t pdrv, char *buffer, unsigned long long sector) {
for (int f = 0; f < 3; f++) {
if (!sdSelectCard(pdrv)) {
return false;
}
if (!sdCommand(pdrv, READ_BLOCK_SINGLE, (s_cards[pdrv]->type == CARD_SDHC) ? sector : sector << 9, NULL)) {
bool success = sdReadBytes(pdrv, buffer, 512);
sdDeselectCard(pdrv);
if (success) {
return true;
}
} else {
break;
}
}
sdDeselectCard(pdrv);
return false;
}
bool sdReadSectors(uint8_t pdrv, char *buffer, unsigned long long sector, int count) {
for (int f = 0; f < 3;) {
if (!sdSelectCard(pdrv)) {
return false;
}
if (!sdCommand(pdrv, READ_BLOCK_MULTIPLE, (s_cards[pdrv]->type == CARD_SDHC) ? sector : sector << 9, NULL)) {
do {
if (!sdReadBytes(pdrv, buffer, 512)) {
f++;
break;
}
sector++;
buffer += 512;
f = 0;
} while (--count);
if (sdCommand(pdrv, STOP_TRANSMISSION, 0, NULL)) {
log_e("command failed");
break;
}
sdDeselectCard(pdrv);
if (count == 0) {
return true;
}
} else {
break;
}
}
sdDeselectCard(pdrv);
return false;
}
bool sdWriteSector(uint8_t pdrv, const char *buffer, unsigned long long sector) {
using roro::SdFault;
for (int f = 0; f < 3; f++) {
if (!sdSelectCard(pdrv)) {
return sdFault(SdFault::Select); // roro: say why
}
if (!sdCommand(pdrv, WRITE_BLOCK_SINGLE, (s_cards[pdrv]->type == CARD_SDHC) ? sector : sector << 9, NULL)) {
char token = sdWriteBytes(pdrv, buffer, 0xFE);
sdDeselectCard(pdrv);
if (token == 0x0A) {
continue;
} else if (token == 0x0C) {
return sdFault(SdFault::DataToken, token);
}
unsigned int resp;
char status = sdTransaction(pdrv, SEND_STATUS, 0, &resp);
if (status || resp) {
return token != 0x05 ? sdFault(SdFault::DataToken, token, resp) : sdFault(SdFault::Status, status, resp);
}
return true;
} else {
break;
}
}
sdDeselectCard(pdrv);
return sdFault(SdFault::Command);
}
bool sdWriteSectors(uint8_t pdrv, const char *buffer, unsigned long long sector, int count) {
using roro::SdFault;
char token;
const char *currentBuffer = buffer;
unsigned long long currentSector = sector;
int currentCount = count;
ardu_sdcard_t *card = s_cards[pdrv];
SdFault::Step why = SdFault::Command; // roro: what stopped it, for the last return
uint8_t whyToken = 0;
for (int f = 0; f < 3;) {
if (card->type != CARD_MMC) {
char refused = sdTransaction(pdrv, SET_WR_BLK_ERASE_COUNT, currentCount, NULL);
if (refused) {
return sdFault(SdFault::EraseCount, refused);
}
}
if (!sdSelectCard(pdrv)) {
return sdFault(SdFault::Select);
}
if (!sdCommand(pdrv, WRITE_BLOCK_MULTIPLE, (card->type == CARD_SDHC) ? currentSector : currentSector << 9, NULL)) {
do {
token = sdWriteBytes(pdrv, currentBuffer, 0xFC);
if (token != 0x05) {
f++;
break;
}
currentBuffer += 512;
f = 0;
} while (--currentCount);
if (!sdWait(pdrv, 500)) {
why = SdFault::BusyAfter;
break;
}
if (currentCount == 0) {
sdStop(pdrv);
card->spi->transfer(0xFF); // roro: the byte the card takes to go busy after Stop Tran (#21)
sdDeselectCard(pdrv);
unsigned int resp;
char status = sdTransaction(pdrv, SEND_STATUS, 0, &resp);
if (status || resp) {
return sdFault(SdFault::Status, status, resp);
}
return true;
} else {
if (sdCommand(pdrv, STOP_TRANSMISSION, 0, NULL)) {
why = SdFault::StopCommand;
whyToken = token;
break;
}
if (token == 0x0A) {
sdDeselectCard(pdrv);
unsigned int writtenBlocks = 0;
if (card->type != CARD_MMC && sdSelectCard(pdrv)) {
if (!sdCommand(pdrv, SEND_NUM_WR_BLOCKS, 0, NULL)) {
char acmdData[4];
if (sdReadBytes(pdrv, acmdData, 4)) {
writtenBlocks = acmdData[0] << 24;
writtenBlocks |= acmdData[1] << 16;
writtenBlocks |= acmdData[2] << 8;
writtenBlocks |= acmdData[3];
}
}
sdDeselectCard(pdrv);
}
currentBuffer = buffer + (writtenBlocks << 9);
currentSector = sector + writtenBlocks;
currentCount = count - writtenBlocks;
continue;
} else {
why = SdFault::DataToken;
whyToken = token;
break;
}
}
} else {
break;
}
}
sdDeselectCard(pdrv);
return sdFault(why, whyToken);
}
unsigned long sdGetSectorsCount(uint8_t pdrv) {
for (int f = 0; f < 3; f++) {
if (!sdSelectCard(pdrv)) {
return 0;
}
if (!sdCommand(pdrv, SEND_CSD, 0, NULL)) {
char csd[16];
bool success = sdReadBytes(pdrv, csd, 16);
sdDeselectCard(pdrv);
if (success) {
if ((csd[0] >> 6) == 0x01) {
unsigned long size = (((unsigned long)(csd[7] & 0x3F) << 16) | ((unsigned long)csd[8] << 8) | csd[9]) + 1;
return size << 10;
}
unsigned long size = (((unsigned long)(csd[6] & 0x03) << 10) | ((unsigned long)csd[7] << 2) | ((csd[8] & 0xC0) >> 6)) + 1;
size <<= ((((csd[9] & 0x03) << 1) | ((csd[10] & 0x80) >> 7)) + 2);
size <<= (csd[5] & 0x0F);
return size >> 9;
}
} else {
break;
}
}
sdDeselectCard(pdrv);
return 0;
}
namespace {
struct AcquireSPI {
ardu_sdcard_t *card;
explicit AcquireSPI(ardu_sdcard_t *card) : card(card) {
card->spi->beginTransaction(SPISettings(card->frequency, MSBFIRST, SPI_MODE0));
}
AcquireSPI(ardu_sdcard_t *card, int frequency) : card(card) {
card->spi->beginTransaction(SPISettings(frequency, MSBFIRST, SPI_MODE0));
}
~AcquireSPI() {
card->spi->endTransaction();
}
private:
AcquireSPI(AcquireSPI const &);
AcquireSPI &operator=(AcquireSPI const &);
};
} // namespace
/*
* FATFS API
* */
/**
* @brief Initialize an SD card for use with FatFs
*
* This function implements the complete SD card initialization sequence according to
* the SD card specification. It performs card detection, type identification,
* and configuration for SPI mode operation.
*
* The initialization sequence follows the SD card protocol (SPI mode, aligned with IDF):
* 1. Power-up sequence with 74+ clock cycles
* 2. Two GO_IDLE_STATE attempts to enter SPI mode
* 3. CRC_ON_OFF to enable CRC checking (with retry)
* 4. SEND_IF_COND to identify SDHC/SDXC cards
* 5. APP_OP_COND / SEND_OP_COND (SPI args; timeout >1s)
* 6. Card type detection (SD/SDHC/MMC)
* 7. Final configuration and sector count retrieval
*
* @param pdrv Physical drive number (0-9)
* @return DSTATUS Status of the initialization (0 = success, STA_NOINIT = failed)
*/
DSTATUS ff_sd_initialize(uint8_t pdrv) {
char token;
unsigned int resp;
unsigned int start;
// Get the card structure for the given drive number
ardu_sdcard_t *card = s_cards[pdrv];
// If the card is already initialized, return its current status
if (!(card->status & STA_NOINIT)) {
return card->status;
}
// Lock the SPI bus and set it to a low frequency (400kHz) for initialization
// Low frequency is required during initialization for reliable communication
AcquireSPI card_locked(card, 400000);
// Step 1: Power-up sequence - Send at least 74 clock cycles with CS high and MOSI high
// This is required by the SD card specification to ensure proper card state reset
// We send 20 bytes (160 clock cycles) to exceed the minimum requirement
digitalWrite(card->ssPin, HIGH);
for (uint8_t i = 0; i < 20; i++) {
card->spi->transfer(0XFF);
}
// Step 2: Perform two GO_IDLE_STATE (CMD0) attempts in SPI mode.
// Per SD Simplified Spec (figure 4-1) / IDF: some cards enter SD mode on the
// first attempt, so the first response may fail; the second must succeed.
// (sdCommand may also retry internally on no-token/CRC errors.)
// Fix mount issue - sdWait fail ignored before each CMD0 attempt
digitalWrite(card->ssPin, LOW);
if (!sdWait(pdrv, 500)) {
log_w("sdWait fail ignored, card initialize continues");
}
(void)sdCommand(pdrv, GO_IDLE_STATE, 0, NULL);
sdDeselectCard(pdrv);
delay(sd_go_idle_delay_ms);
digitalWrite(card->ssPin, LOW);
if (!sdWait(pdrv, 500)) {
log_w("sdWait fail ignored, card initialize continues");
}
if (sdCommand(pdrv, GO_IDLE_STATE, 0, NULL) != 1) {
sdDeselectCard(pdrv);
log_w("GO_IDLE_STATE failed");
goto unknown_card;
}
sdDeselectCard(pdrv);
delay(sd_go_idle_delay_ms);
// Step 3: Configure CRC checking
// Enable CRC for data transfers in SPI mode (required for reliable communication).
// Some cards reject the first CRC_ON_OFF; retry once (same as IDF).
token = sdTransaction(pdrv, CRC_ON_OFF, 1, NULL);
if (token != 1 && token != 0x5) {
delay(10);
token = sdTransaction(pdrv, CRC_ON_OFF, 1, NULL);
}
if (token == 0x5) {
// Old card that doesn't support CRC - disable CRC checking
card->supports_crc = false;
} else if (token != 1) {
log_w("CRC_ON_OFF failed: %u", token);
goto unknown_card;
}
// Step 4: Card type detection and initialization
// Try to identify SDHC/SDXC cards using SEND_IF_COND command
if (sdTransaction(pdrv, SEND_IF_COND, 0x1AA, &resp) == 1) {
// Card responded to SEND_IF_COND - likely SDHC/SDXC
if ((resp & 0xFFF) != 0x1AA) {
log_w("SEND_IF_COND failed: %03" PRIX32, (uint32_t)(resp & 0xFFF));
goto unknown_card;
}
// Read Operating Conditions Register to check card capabilities
if (sdTransaction(pdrv, READ_OCR, 0, &resp) != 1 || !(resp & (1 << 20))) {
log_w("READ_OCR failed: %X", resp);
goto unknown_card;
}
// Send APP_OP_COND to set operating conditions for SDHC/SDXC.
// In SPI mode only HCS (bit 30) is valid; voltage bits must be 0 (same as IDF).
// Timeout must be >1s per SD spec (IDF uses ~3s).
start = millis();
do {
token = sdTransaction(pdrv, APP_OP_COND, 0x40000000, NULL);
} while (token == 1 && (millis() - start) < sd_op_cond_timeout_ms);
if (token) {
log_w("APP_OP_COND failed: %u", token);
goto unknown_card;
}
// Determine if it's SDHC (high capacity) or regular SD
if (!sdTransaction(pdrv, READ_OCR, 0, &resp)) {
if (resp & (1 << 30)) {
card->type = CARD_SDHC; // High capacity card (SDHC/SDXC)
} else {
card->type = CARD_SD; // Standard capacity card
}
} else {
log_w("READ_OCR failed: %X", resp);
goto unknown_card;
}
} else {
// Card didn't respond to SEND_IF_COND - try SD or MMC initialization
if (sdTransaction(pdrv, READ_OCR, 0, &resp) != 1 || !(resp & (1 << 20))) {
log_w("READ_OCR failed: %X", resp);
goto unknown_card;
}
// Try SD card initialization first (SPI mode: ACMD41 arg must be 0)
start = millis();
do {
token = sdTransaction(pdrv, APP_OP_COND, 0, NULL);
} while (token == 0x01 && (millis() - start) < sd_op_cond_timeout_ms);
if (!token) {
card->type = CARD_SD; // Standard SD card
} else {
// Try MMC card initialization (SPI mode: CMD1 arg must be 0)
start = millis();
do {
token = sdTransaction(pdrv, SEND_OP_COND, 0, NULL);
} while (token != 0x00 && (millis() - start) < sd_op_cond_timeout_ms);
if (token == 0x00) {
card->type = CARD_MMC; // MMC card
} else {
log_w("SEND_OP_COND failed: %u", token);
goto unknown_card;
}
}
}
// Step 5: Clear card detection for SD cards (not needed for MMC)
if (card->type != CARD_MMC) {
if (sdTransaction(pdrv, APP_CLR_CARD_DETECT, 0, NULL)) {
log_w("APP_CLR_CARD_DETECT failed");
goto unknown_card;
}
}
// Step 6: Set block length for non-SDHC cards
// SDHC cards have fixed 512-byte blocks, others need explicit block length setting
if (card->type != CARD_SDHC) {
if (sdTransaction(pdrv, SET_BLOCKLEN, 512, NULL) != 0x00) {
log_w("SET_BLOCKLEN failed");
goto unknown_card;
}
}
// Step 7: Get card capacity and finalize initialization
card->sectors = sdGetSectorsCount(pdrv);
// Limit frequency to 25MHz for compatibility (SD spec maximum for non-UHS cards)
if (card->frequency > 25000000) {
card->frequency = 25000000;
}
// Mark card as initialized
card->status &= ~STA_NOINIT;
return card->status;
unknown_card:
// Mark card as unknown type if initialization failed
card->type = CARD_UNKNOWN;
return card->status;
}
DSTATUS ff_sd_status(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
AcquireSPI lock(card);
if (sdTransaction(pdrv, SEND_STATUS, 0, NULL)) {
log_e("Check status failed");
return STA_NOINIT;
}
return s_cards[pdrv]->status;
}
DRESULT ff_sd_read(uint8_t pdrv, uint8_t *buffer, DWORD sector, UINT count) {
ardu_sdcard_t *card = s_cards[pdrv];
if (card->status & STA_NOINIT) {
return RES_NOTRDY;
}
DRESULT res = RES_OK;
AcquireSPI lock(card);
if (count > 1) {
res = sdReadSectors(pdrv, (char *)buffer, sector, count) ? RES_OK : RES_ERROR;
} else {
res = sdReadSector(pdrv, (char *)buffer, sector) ? RES_OK : RES_ERROR;
}
return res;
}
DRESULT ff_sd_write(uint8_t pdrv, const uint8_t *buffer, DWORD sector, UINT count) {
ardu_sdcard_t *card = s_cards[pdrv];
if (card->status & STA_NOINIT) {
return RES_NOTRDY;
}
if (card->status & STA_PROTECT) {
return RES_WRPRT;
}
DRESULT res = RES_OK;
AcquireSPI lock(card);
if (count > 1) {
res = sdWriteSectors(pdrv, (const char *)buffer, sector, count) ? RES_OK : RES_ERROR;
} else {
res = sdWriteSector(pdrv, (const char *)buffer, sector) ? RES_OK : RES_ERROR;
}
return res;
}
DRESULT ff_sd_ioctl(uint8_t pdrv, uint8_t cmd, void *buff) {
switch (cmd) {
case CTRL_SYNC:
{
AcquireSPI lock(s_cards[pdrv]);
if (sdSelectCard(pdrv)) {
sdDeselectCard(pdrv);
return RES_OK;
}
}
return RES_ERROR;
case GET_SECTOR_COUNT: *((unsigned long *)buff) = s_cards[pdrv]->sectors; return RES_OK;
case GET_SECTOR_SIZE: *((WORD *)buff) = 512; return RES_OK;
case GET_BLOCK_SIZE: *((uint32_t *)buff) = 1; return RES_OK;
}
return RES_PARERR;
}
bool sd_read_raw(uint8_t pdrv, uint8_t *buffer, DWORD sector) {
return ff_sd_read(pdrv, buffer, sector, 1) == ESP_OK;
}
bool sd_write_raw(uint8_t pdrv, uint8_t *buffer, DWORD sector) {
return ff_sd_write(pdrv, buffer, sector, 1) == ESP_OK;
}
/*
* Public methods
* */
uint8_t sdcard_uninit(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
if (pdrv >= FF_VOLUMES || card == NULL) {
return 1;
}
{
AcquireSPI lock(card);
sdTransaction(pdrv, GO_IDLE_STATE, 0, NULL);
} // lock is destructed here
ff_diskio_register(pdrv, NULL);
s_cards[pdrv] = NULL;
esp_err_t err = ESP_OK;
if (card->base_path) {
err = esp_vfs_fat_unregister_path(card->base_path);
free(card->base_path);
}
free(card);
return err;
}
uint8_t sdcard_init(uint8_t cs, SPIClass *spi, int hz) {
uint8_t pdrv = 0xFF;
if (ff_diskio_get_drive(&pdrv) != ESP_OK || pdrv == 0xFF) {
return pdrv;
}
ardu_sdcard_t *card = (ardu_sdcard_t *)malloc(sizeof(ardu_sdcard_t));
if (!card) {
return 0xFF;
}
card->base_path = NULL;
card->frequency = hz;
card->spi = spi;
card->ssPin = digitalPinToGPIONumber(cs);
card->supports_crc = true;
card->type = CARD_NONE;
card->status = STA_NOINIT;
pinMode(card->ssPin, OUTPUT);
digitalWrite(card->ssPin, HIGH);
perimanSetPinBusExtraType(card->ssPin, "SD_SS");
s_cards[pdrv] = card;
static const ff_diskio_impl_t sd_impl = {
.init = &ff_sd_initialize, .status = &ff_sd_status, .read = &ff_sd_read, .write = &ff_sd_write, .ioctl = &ff_sd_ioctl
};
ff_diskio_register(pdrv, &sd_impl);
return pdrv;
}
uint8_t sdcard_unmount(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
if (pdrv >= FF_VOLUMES || card == NULL) {
return 1;
}
card->status |= STA_NOINIT;
card->type = CARD_NONE;
char drv[3] = {(char)('0' + pdrv), ':', 0};
f_mount(NULL, drv, 0);
return 0;
}
bool sdcard_mount(uint8_t pdrv, const char *path, uint8_t max_files, bool format_if_empty) {
ardu_sdcard_t *card = s_cards[pdrv];
if (pdrv >= FF_VOLUMES || card == NULL) {
return false;
}
if (card->base_path) {
free(card->base_path);
}
card->base_path = strdup(path);
FATFS *fs;
char drv[3] = {(char)('0' + pdrv), ':', 0};
#if ESP_IDF_VERSION < ESP_IDF_VERSION_VAL(6, 0, 0)
esp_err_t err = esp_vfs_fat_register(path, drv, max_files, &fs);
#else
esp_vfs_fat_conf_t conf = {.base_path = path, .fat_drive = drv, .max_files = max_files};
esp_err_t err = esp_vfs_fat_register(&conf, &fs);
#endif
if (err == ESP_ERR_INVALID_STATE) {
log_e("esp_vfs_fat_register failed 0x(%x): SD is registered.", err);
return false;
} else if (err != ESP_OK) {
log_e("esp_vfs_fat_register failed 0x(%x)", err);
return false;
}
FRESULT res = f_mount(fs, drv, 1);
if (res != FR_OK) {
log_e("f_mount failed: %s", fferr2str[res]);
if (res == 13 && format_if_empty) {
BYTE *work = (BYTE *)malloc(sizeof(BYTE) * FF_MAX_SS);
if (!work) {
log_e("alloc for f_mkfs failed");
return false;
}
//FRESULT f_mkfs (const TCHAR* path, const MKFS_PARM* opt, void* work, UINT len);
const MKFS_PARM opt = {(BYTE)FM_ANY, 0, 0, 0, 0};
res = f_mkfs(drv, &opt, work, sizeof(BYTE) * FF_MAX_SS);
free(work);
if (res != FR_OK) {
log_e("f_mkfs failed: %s", fferr2str[res]);
esp_vfs_fat_unregister_path(path);
return false;
}
res = f_mount(fs, drv, 1);
if (res != FR_OK) {
log_e("f_mount failed: %s", fferr2str[res]);
esp_vfs_fat_unregister_path(path);
return false;
}
} else {
esp_vfs_fat_unregister_path(path);
return false;
}
}
AcquireSPI lock(card);
card->sectors = sdGetSectorsCount(pdrv);
return true;
}
uint32_t sdcard_num_sectors(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
if (pdrv >= FF_VOLUMES || card == NULL) {
return 0;
}
return card->sectors;
}
uint32_t sdcard_sector_size(uint8_t pdrv) {
if (pdrv >= FF_VOLUMES || s_cards[pdrv] == NULL) {
return 0;
}
return 512;
}
// roro: the card's CID. CMD10 in SPI mode (the enum's SEND_CID, 2, is the SD-mode command).
namespace roro {
bool sdReadCid(uint8_t cid[16]) {
for (uint8_t pdrv = 0; pdrv < FF_VOLUMES; ++pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
if (!card) {
continue;
}
AcquireSPI lock(card);
if (!sdSelectCard(pdrv)) {
return false;
}
bool ok = !sdCommand(pdrv, 10, 0, NULL) && sdReadBytes(pdrv, (char *)cid, 16);
sdDeselectCard(pdrv);
return ok;
}
return false;
}
} // namespace roro
sdcard_type_t sdcard_type(uint8_t pdrv) {
ardu_sdcard_t *card = s_cards[pdrv];
if (pdrv >= FF_VOLUMES || card == NULL) {
return CARD_NONE;
}
return card->type;
}
+34
View File
@@ -0,0 +1,34 @@
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
#ifndef _SD_DISKIO_H_
#define _SD_DISKIO_H_
#include "Arduino.h"
#include "SPI.h"
#include "sd_defines.h"
// #include "diskio.h"
uint8_t sdcard_init(uint8_t cs, SPIClass *spi, int hz);
uint8_t sdcard_uninit(uint8_t pdrv);
bool sdcard_mount(uint8_t pdrv, const char *path, uint8_t max_files, bool format_if_empty);
uint8_t sdcard_unmount(uint8_t pdrv);
sdcard_type_t sdcard_type(uint8_t pdrv);
uint32_t sdcard_num_sectors(uint8_t pdrv);
uint32_t sdcard_sector_size(uint8_t pdrv);
bool sd_read_raw(uint8_t pdrv, uint8_t *buffer, uint32_t sector);
bool sd_write_raw(uint8_t pdrv, uint8_t *buffer, uint32_t sector);
#endif /* _SD_DISKIO_H_ */
+61
View File
@@ -0,0 +1,61 @@
/* SD/MMC File System Library
* Copyright (c) 2014 Neil Thiessen
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
const char m_CRC7Table[] = {0x00, 0x09, 0x12, 0x1B, 0x24, 0x2D, 0x36, 0x3F, 0x48, 0x41, 0x5A, 0x53, 0x6C, 0x65, 0x7E, 0x77, 0x19, 0x10, 0x0B, 0x02, 0x3D, 0x34,
0x2F, 0x26, 0x51, 0x58, 0x43, 0x4A, 0x75, 0x7C, 0x67, 0x6E, 0x32, 0x3B, 0x20, 0x29, 0x16, 0x1F, 0x04, 0x0D, 0x7A, 0x73, 0x68, 0x61,
0x5E, 0x57, 0x4C, 0x45, 0x2B, 0x22, 0x39, 0x30, 0x0F, 0x06, 0x1D, 0x14, 0x63, 0x6A, 0x71, 0x78, 0x47, 0x4E, 0x55, 0x5C, 0x64, 0x6D,
0x76, 0x7F, 0x40, 0x49, 0x52, 0x5B, 0x2C, 0x25, 0x3E, 0x37, 0x08, 0x01, 0x1A, 0x13, 0x7D, 0x74, 0x6F, 0x66, 0x59, 0x50, 0x4B, 0x42,
0x35, 0x3C, 0x27, 0x2E, 0x11, 0x18, 0x03, 0x0A, 0x56, 0x5F, 0x44, 0x4D, 0x72, 0x7B, 0x60, 0x69, 0x1E, 0x17, 0x0C, 0x05, 0x3A, 0x33,
0x28, 0x21, 0x4F, 0x46, 0x5D, 0x54, 0x6B, 0x62, 0x79, 0x70, 0x07, 0x0E, 0x15, 0x1C, 0x23, 0x2A, 0x31, 0x38, 0x41, 0x48, 0x53, 0x5A,
0x65, 0x6C, 0x77, 0x7E, 0x09, 0x00, 0x1B, 0x12, 0x2D, 0x24, 0x3F, 0x36, 0x58, 0x51, 0x4A, 0x43, 0x7C, 0x75, 0x6E, 0x67, 0x10, 0x19,
0x02, 0x0B, 0x34, 0x3D, 0x26, 0x2F, 0x73, 0x7A, 0x61, 0x68, 0x57, 0x5E, 0x45, 0x4C, 0x3B, 0x32, 0x29, 0x20, 0x1F, 0x16, 0x0D, 0x04,
0x6A, 0x63, 0x78, 0x71, 0x4E, 0x47, 0x5C, 0x55, 0x22, 0x2B, 0x30, 0x39, 0x06, 0x0F, 0x14, 0x1D, 0x25, 0x2C, 0x37, 0x3E, 0x01, 0x08,
0x13, 0x1A, 0x6D, 0x64, 0x7F, 0x76, 0x49, 0x40, 0x5B, 0x52, 0x3C, 0x35, 0x2E, 0x27, 0x18, 0x11, 0x0A, 0x03, 0x74, 0x7D, 0x66, 0x6F,
0x50, 0x59, 0x42, 0x4B, 0x17, 0x1E, 0x05, 0x0C, 0x33, 0x3A, 0x21, 0x28, 0x5F, 0x56, 0x4D, 0x44, 0x7B, 0x72, 0x69, 0x60, 0x0E, 0x07,
0x1C, 0x15, 0x2A, 0x23, 0x38, 0x31, 0x46, 0x4F, 0x54, 0x5D, 0x62, 0x6B, 0x70, 0x79};
char CRC7(const char *data, int length) {
char crc = 0;
for (int i = 0; i < length; i++) {
crc = m_CRC7Table[(crc << 1) ^ data[i]];
}
return crc;
}
const unsigned short m_CRC16Table[256] = {
0x0000, 0x1021, 0x2042, 0x3063, 0x4084, 0x50A5, 0x60C6, 0x70E7, 0x8108, 0x9129, 0xA14A, 0xB16B, 0xC18C, 0xD1AD, 0xE1CE, 0xF1EF, 0x1231, 0x0210, 0x3273,
0x2252, 0x52B5, 0x4294, 0x72F7, 0x62D6, 0x9339, 0x8318, 0xB37B, 0xA35A, 0xD3BD, 0xC39C, 0xF3FF, 0xE3DE, 0x2462, 0x3443, 0x0420, 0x1401, 0x64E6, 0x74C7,
0x44A4, 0x5485, 0xA56A, 0xB54B, 0x8528, 0x9509, 0xE5EE, 0xF5CF, 0xC5AC, 0xD58D, 0x3653, 0x2672, 0x1611, 0x0630, 0x76D7, 0x66F6, 0x5695, 0x46B4, 0xB75B,
0xA77A, 0x9719, 0x8738, 0xF7DF, 0xE7FE, 0xD79D, 0xC7BC, 0x48C4, 0x58E5, 0x6886, 0x78A7, 0x0840, 0x1861, 0x2802, 0x3823, 0xC9CC, 0xD9ED, 0xE98E, 0xF9AF,
0x8948, 0x9969, 0xA90A, 0xB92B, 0x5AF5, 0x4AD4, 0x7AB7, 0x6A96, 0x1A71, 0x0A50, 0x3A33, 0x2A12, 0xDBFD, 0xCBDC, 0xFBBF, 0xEB9E, 0x9B79, 0x8B58, 0xBB3B,
0xAB1A, 0x6CA6, 0x7C87, 0x4CE4, 0x5CC5, 0x2C22, 0x3C03, 0x0C60, 0x1C41, 0xEDAE, 0xFD8F, 0xCDEC, 0xDDCD, 0xAD2A, 0xBD0B, 0x8D68, 0x9D49, 0x7E97, 0x6EB6,
0x5ED5, 0x4EF4, 0x3E13, 0x2E32, 0x1E51, 0x0E70, 0xFF9F, 0xEFBE, 0xDFDD, 0xCFFC, 0xBF1B, 0xAF3A, 0x9F59, 0x8F78, 0x9188, 0x81A9, 0xB1CA, 0xA1EB, 0xD10C,
0xC12D, 0xF14E, 0xE16F, 0x1080, 0x00A1, 0x30C2, 0x20E3, 0x5004, 0x4025, 0x7046, 0x6067, 0x83B9, 0x9398, 0xA3FB, 0xB3DA, 0xC33D, 0xD31C, 0xE37F, 0xF35E,
0x02B1, 0x1290, 0x22F3, 0x32D2, 0x4235, 0x5214, 0x6277, 0x7256, 0xB5EA, 0xA5CB, 0x95A8, 0x8589, 0xF56E, 0xE54F, 0xD52C, 0xC50D, 0x34E2, 0x24C3, 0x14A0,
0x0481, 0x7466, 0x6447, 0x5424, 0x4405, 0xA7DB, 0xB7FA, 0x8799, 0x97B8, 0xE75F, 0xF77E, 0xC71D, 0xD73C, 0x26D3, 0x36F2, 0x0691, 0x16B0, 0x6657, 0x7676,
0x4615, 0x5634, 0xD94C, 0xC96D, 0xF90E, 0xE92F, 0x99C8, 0x89E9, 0xB98A, 0xA9AB, 0x5844, 0x4865, 0x7806, 0x6827, 0x18C0, 0x08E1, 0x3882, 0x28A3, 0xCB7D,
0xDB5C, 0xEB3F, 0xFB1E, 0x8BF9, 0x9BD8, 0xABBB, 0xBB9A, 0x4A75, 0x5A54, 0x6A37, 0x7A16, 0x0AF1, 0x1AD0, 0x2AB3, 0x3A92, 0xFD2E, 0xED0F, 0xDD6C, 0xCD4D,
0xBDAA, 0xAD8B, 0x9DE8, 0x8DC9, 0x7C26, 0x6C07, 0x5C64, 0x4C45, 0x3CA2, 0x2C83, 0x1CE0, 0x0CC1, 0xEF1F, 0xFF3E, 0xCF5D, 0xDF7C, 0xAF9B, 0xBFBA, 0x8FD9,
0x9FF8, 0x6E17, 0x7E36, 0x4E55, 0x5E74, 0x2E93, 0x3EB2, 0x0ED1, 0x1EF0
};
unsigned short CRC16(const char *data, int length) {
unsigned short crc = 0;
for (int i = 0; i < length; i++) {
crc = (crc << 8) ^ m_CRC16Table[((crc >> 8) ^ data[i]) & 0x00FF];
}
return crc;
}
+33
View File
@@ -0,0 +1,33 @@
#pragma once
#include <cstdint>
namespace roro {
// Why the SD driver last gave up on a write (see sd_diskio.cpp, issue #21). The framework's driver
// fails without saying why; ours records it.
struct SdFault {
enum Step : uint8_t {
None,
EraseCount, // ACMD23 before a multi-block write was refused
Select, // the card stayed busy for 500 ms
Command, // the write command itself was refused
DataToken, // the card's answer to a data block: 0x0B CRC error, 0x0D write error
BusyAfter, // still busy 500 ms after the last block
Status, // CMD13 after the write reported an error (resp)
StopCommand, // CMD12 after a rejected block was refused
};
Step step = None;
uint8_t token = 0; // the driver's or the card's answer at that step
uint32_t resp = 0; // CMD13's status bits, for Status
uint32_t count = 0; // failed writes since boot
uint32_t retried = 0; // blocks resent after a CRC error, since boot
};
SdFault sdLastFault();
// The mounted card's identity register (CID, CMD10): who made it, its name, serial and date.
// Call it where card access is allowed (the storage task).
bool sdReadCid(uint8_t cid[16]);
} // namespace roro
+9 -1
View File
@@ -20,8 +20,10 @@ const RowDef kRows[] = {
{Row::Region, Kind::Choice, "Region"}, {Row::Timezone, Kind::Choice, "Timezone"},
{Row::Brightness, Kind::Slider, "Brightness"}, {Row::DimTimeout, Kind::Choice, "Dim after"},
{Row::OffTimeout, Kind::Choice, "Screen off after"}, {Row::Sound, Kind::Toggle, "Sound & LED"},
{Row::Gnss, Kind::Toggle, "GNSS"}, {Row::GnssQuiet, Kind::Toggle, "Pause GNSS for LoRa"},
{Row::Coordinates, Kind::Toggle, "Coordinates"},
{Row::ProbeMacs, Kind::Toggle, "Probe MACs"}, {Row::Wifi, Kind::Page, "Wi-Fi"},
{Row::Storage, Kind::Page, "Storage"},
{Row::Firmware, Kind::Page, "Firmware"},
{Row::About, Kind::Page, "About"},
};
@@ -78,6 +80,9 @@ std::string SettingsMenu::value(int i) const {
case Row::DimTimeout: return formatSeconds(settings_.getInt(Setting::DimTimeoutS));
case Row::OffTimeout: return formatSeconds(settings_.getInt(Setting::OffTimeoutS));
case Row::Sound: return settings_.getBool(Setting::Sound) ? "On" : "Off";
case Row::Gnss: return settings_.getBool(Setting::GnssEnabled) ? "On" : "Off";
case Row::GnssQuiet: return settings_.getBool(Setting::GnssQuietForLora) ? "On" : "Off";
case Row::Coordinates: return settings_.getBool(Setting::CoordinatesDms) ? "Deg min sec" : "Decimal";
case Row::ProbeMacs: return settings_.getBool(Setting::ProbeMacRaw) ? "Raw" : "Pseudonymised";
case Row::Wifi: return settings_.getBool(Setting::WifiEnabled) ? "On" : "Off";
default: return "";
@@ -121,6 +126,9 @@ std::string SettingsMenu::choose(int i, int c) {
void SettingsMenu::toggle(int i) {
if (row(i) == Row::Sound) settings_.setBool(Setting::Sound, !settings_.getBool(Setting::Sound));
if (row(i) == Row::Gnss) settings_.setBool(Setting::GnssEnabled, !settings_.getBool(Setting::GnssEnabled));
if (row(i) == Row::GnssQuiet) settings_.setBool(Setting::GnssQuietForLora, !settings_.getBool(Setting::GnssQuietForLora));
if (row(i) == Row::Coordinates) settings_.setBool(Setting::CoordinatesDms, !settings_.getBool(Setting::CoordinatesDms));
if (row(i) == Row::ProbeMacs) settings_.setBool(Setting::ProbeMacRaw, !settings_.getBool(Setting::ProbeMacRaw));
}
+1 -1
View File
@@ -11,7 +11,7 @@ namespace roro {
// values, choice lists and validation messages. Rendering and navigation live in the App.
class SettingsMenu {
public:
enum class Row { LongName, ShortName, Region, Timezone, Brightness, DimTimeout, OffTimeout, Sound, ProbeMacs, Wifi, Storage, About };
enum class Row { LongName, ShortName, Region, Timezone, Brightness, DimTimeout, OffTimeout, Sound, Gnss, GnssQuiet, Coordinates, ProbeMacs, Wifi, Firmware, About };
enum class Kind { Text, Choice, Toggle, Slider, Page };
explicit SettingsMenu(Settings& settings) : settings_(settings) {}
+137
View File
@@ -0,0 +1,137 @@
#include "file_list.h"
#include <algorithm>
#include <cctype>
#include <cstdio>
#include <cstring>
#include <ctime>
namespace roro::files {
namespace {
// Names compare letters only, whatever the case; ties by the bytes, so the order is total.
int compareNames(const char* a, const char* b) {
for (const char *x = a, *y = b;; ++x, ++y) {
int cx = std::tolower(static_cast<unsigned char>(*x)), cy = std::tolower(static_cast<unsigned char>(*y));
if (cx != cy) return cx < cy ? -1 : 1;
if (!cx) break;
}
return std::strcmp(a, b);
}
constexpr uint32_t kYear2020 = 1577836800;
std::string sizeText(uint32_t bytes) {
char s[16];
if (bytes < 1024) std::snprintf(s, sizeof s, "%u B", static_cast<unsigned>(bytes));
else if (bytes < 10 * 1024) std::snprintf(s, sizeof s, "%.1f KB", bytes / 1024.0);
else if (bytes < 1024 * 1024) std::snprintf(s, sizeof s, "%u KB", static_cast<unsigned>(bytes / 1024));
else if (bytes < 10u * 1024 * 1024) std::snprintf(s, sizeof s, "%.1f MB", bytes / 1048576.0);
else if (bytes < 1024u * 1024 * 1024) std::snprintf(s, sizeof s, "%u MB", static_cast<unsigned>(bytes / 1048576));
else std::snprintf(s, sizeof s, "%.1f GB", bytes / 1073741824.0);
return s;
}
} // namespace
void FileList::clear() {
std::vector<Entry>().swap(entries_);
std::vector<uint16_t>().swap(order_);
std::vector<char>().swap(names_);
more_ = wasted_ = 0;
}
bool FileList::before(const Entry& a, const Entry& b, FileSort by) const {
if (a.folder != b.folder) return a.folder;
if (!a.folder) {
if (by == FileSort::Date && a.modified != b.modified) return a.modified > b.modified;
if (by == FileSort::Size && a.size != b.size) return a.size > b.size;
}
return compareNames(names_.data() + a.name, names_.data() + b.name) < 0;
}
void FileList::add(const char* name, uint32_t size, uint32_t modified, bool folder) {
size_t len = std::strlen(name) + 1;
if (entries_.size() >= kMax) {
// Full: the new entry takes the place of the one that sorts last by name, if it sorts
// before it. The old name's bytes stay in the buffer until there's enough waste to pack.
more_++;
size_t last = 0;
for (size_t i = 1; i < entries_.size(); i++)
if (before(entries_[last], entries_[i], FileSort::Name)) last = i;
Entry candidate{static_cast<uint32_t>(names_.size()), size, modified, folder};
names_.insert(names_.end(), name, name + len);
if (!before(candidate, entries_[last], FileSort::Name)) {
names_.resize(names_.size() - len);
return;
}
wasted_ += std::strlen(names_.data() + entries_[last].name) + 1;
entries_[last] = candidate;
if (wasted_ > 2048) compact();
return;
}
if (entries_.empty()) {
entries_.reserve(32);
names_.reserve(512);
}
entries_.push_back({static_cast<uint32_t>(names_.size()), size, modified, folder});
names_.insert(names_.end(), name, name + len);
order_.push_back(static_cast<uint16_t>(order_.size()));
}
void FileList::compact() {
std::vector<char> packed;
packed.reserve(names_.size() - wasted_);
for (Entry& e : entries_) {
const char* n = names_.data() + e.name;
e.name = static_cast<uint32_t>(packed.size());
packed.insert(packed.end(), n, n + std::strlen(n) + 1);
}
names_.swap(packed);
wasted_ = 0;
}
void FileList::sort(FileSort by) {
if (wasted_) compact();
names_.shrink_to_fit();
entries_.shrink_to_fit();
order_.resize(entries_.size());
for (size_t i = 0; i < order_.size(); i++) order_[i] = static_cast<uint16_t>(i);
std::sort(order_.begin(), order_.end(), [&](uint16_t a, uint16_t b) { return before(entries_[a], entries_[b], by); });
}
int FileList::find(const std::string& name) const {
for (size_t i = 0; i < order_.size(); i++)
if (name == this->name(i)) return static_cast<int>(i);
return -1;
}
size_t FileList::bytes() const {
return entries_.capacity() * sizeof(Entry) + order_.capacity() * sizeof(uint16_t) + names_.capacity();
}
std::string formatStamp(uint32_t modified) {
if (modified < kYear2020) return "-";
time_t t = static_cast<time_t>(modified);
struct tm local;
localtime_r(&t, &local);
char s[20];
std::snprintf(s, sizeof s, "%04d-%02d-%02d %02d:%02d", local.tm_year + 1900, local.tm_mon + 1, local.tm_mday, local.tm_hour,
local.tm_min);
return s;
}
std::string rowDetail(bool folder, uint32_t size, uint32_t modified) {
if (folder) return "folder";
std::string stamp = formatStamp(modified);
return sizeText(size) + " " + (stamp == "-" ? stamp : stamp.substr(0, 10));
}
std::string fitName(const std::string& name, size_t maxChars) {
if (name.size() <= maxChars || maxChars < 8) return name.substr(0, maxChars);
size_t tail = std::min<size_t>(6, maxChars / 3), head = maxChars - tail - 2;
return name.substr(0, head) + ".." + name.substr(name.size() - tail);
}
} // namespace roro::files
+55
View File
@@ -0,0 +1,55 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::files {
enum class FileSort : uint8_t { Name, Date, Size };
// A folder's entries for the Storage App (F1, Q129, Q136): 256 at most, the names packed into
// one buffer, about 10 KB when full. A bigger folder keeps the first 256 by name, whatever order
// the card lists them in, and counts the rest.
class FileList {
public:
static constexpr size_t kMax = 256;
void clear();
void add(const char* name, uint32_t size, uint32_t modified, bool folder);
void sort(FileSort by); // folders first, by name; then files by name, newest or biggest first
size_t count() const { return entries_.size(); }
size_t more() const { return more_; } // entries that didn't fit
// By position after sort().
const char* name(size_t i) const { return names_.data() + entries_[order_[i]].name; }
uint32_t size(size_t i) const { return entries_[order_[i]].size; }
uint32_t modified(size_t i) const { return entries_[order_[i]].modified; } // Unix time, 0 if unknown
bool folder(size_t i) const { return entries_[order_[i]].folder; }
int find(const std::string& name) const; // position, or -1
size_t bytes() const; // memory held
private:
struct Entry {
uint32_t name; // offset into names_
uint32_t size, modified;
bool folder;
};
bool before(const Entry& a, const Entry& b, FileSort by) const;
void compact();
std::vector<Entry> entries_;
std::vector<uint16_t> order_;
std::vector<char> names_;
size_t more_ = 0, wasted_ = 0;
};
// What a row shows on the right (Q129): "folder", or "1.2 KB 2026-10-05". A file dated before
// 2020 was written before the clock was set: "-" (Q137). Local time.
std::string rowDetail(bool folder, uint32_t size, uint32_t modified);
std::string formatStamp(uint32_t modified);
// A name cut to `maxChars` for a row, from the middle: the start and the extension stay readable.
std::string fitName(const std::string& name, size_t maxChars); // "2026-10-05 20:00", or "-"
} // namespace roro::files
+99
View File
@@ -0,0 +1,99 @@
#include "file_names.h"
#include <cctype>
namespace roro::files {
const char* const kFirmwareFolders[] = {"/irc", "/wifi", "/updates", "/gnss", "/gemini", "/captures", "/notes"};
const size_t kFirmwareFolderCount = sizeof kFirmwareFolders / sizeof kFirmwareFolders[0];
std::string parentOf(const std::string& path) {
size_t slash = path.rfind('/');
return slash == std::string::npos || slash == 0 ? "/" : path.substr(0, slash);
}
std::string baseName(const std::string& path) {
size_t slash = path.rfind('/');
return slash == std::string::npos ? path : path.substr(slash + 1);
}
std::string joinPath(const std::string& folder, const std::string& name) {
return folder == "/" ? "/" + name : folder + "/" + name;
}
std::string extensionOf(const std::string& name) {
size_t dot = name.rfind('.');
if (dot == std::string::npos || dot == 0) return "";
std::string ext = name.substr(dot + 1);
for (char& c : ext) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
return ext;
}
bool isInside(const std::string& path, const std::string& folder) {
if (folder == "/") return true;
if (path.compare(0, folder.size(), folder) != 0) return false;
return path.size() == folder.size() || path[folder.size()] == '/';
}
std::string checkName(const std::string& name) {
if (name.empty()) return "A name can't be empty";
if (name == "." || name == "..") return "\".\" and \"..\" aren't names";
if (name.size() > 64) return "A name can be 64 characters at most";
for (char c : name) {
if (static_cast<unsigned char>(c) < 0x20) return "A name can't contain control characters";
for (char bad : std::string("/\\:*?\"<>|"))
if (c == bad) return std::string("A name can't contain ") + c;
}
if (name.back() == '.' || name.back() == ' ') return "A name can't end with a dot or a space";
return "";
}
std::string whyReadOnly(const std::string& path, const std::vector<std::string>& inUse) {
if (path == "/" || path.empty()) return "That's the card itself";
if (isInside(path, kGeminiCache)) return std::string(kGeminiCache) + " is the Gemini App's working space";
for (const std::string& open : inUse) {
if (open == path) return "It's being written right now";
if (isInside(open, path)) return "It holds a file that's being written right now";
}
for (size_t i = 0; i < kFirmwareFolderCount; i++)
if (path == kFirmwareFolders[i]) return std::string("The firmware keeps its files in ") + path;
return "";
}
std::string whyNotInto(const std::string& source, const std::string& into) {
if (isInside(into, kGeminiCache)) return std::string(kGeminiCache) + " is the Gemini App's working space";
if (isInside(into, source)) return "A folder can't go inside itself";
if (parentOf(source) == into) return "It's already there";
return "";
}
std::string copyName(const std::string& name, int n) {
size_t dot = name.rfind('.');
std::string suffix = " (" + std::to_string(n) + ")";
if (dot == std::string::npos || dot == 0) return name + suffix;
return name.substr(0, dot) + suffix + name.substr(dot);
}
FileKind kindOf(const std::string& name) {
std::string ext = extensionOf(name);
if (ext == "gpx") return FileKind::Gpx;
if (ext == "pcap") return FileKind::Pcap;
if (ext == "ota") return FileKind::Ota;
for (const char* text : {"txt", "log", "gmi", "csv", "md", "json", "ini", "conf", "ir"})
if (ext == text) return FileKind::Text;
return FileKind::Unknown;
}
bool opensAtEnd(const std::string& name) { return extensionOf(name) == "log"; }
bool looksLikeText(const uint8_t* data, size_t len) {
size_t odd = 0;
for (size_t i = 0; i < len; i++) {
uint8_t b = data[i];
if (b == 0) return false;
if (b < 0x20 && b != '\n' && b != '\r' && b != '\t') odd++;
}
return odd * 20 <= len; // a stray control character or two is still text
}
} // namespace roro::files
+42
View File
@@ -0,0 +1,42 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::files {
// Paths on the SD card are absolute and use '/': "/gemini/saved/index.gmi".
std::string parentOf(const std::string& path); // "/" for a top-level entry and for "/"
std::string baseName(const std::string& path); // "" for "/"
std::string joinPath(const std::string& folder, const std::string& name);
std::string extensionOf(const std::string& name); // lower case, without the dot; "" if none
bool isInside(const std::string& path, const std::string& folder); // a folder is inside itself
// A name typed for rename or a new folder (F1, Q131): "" if FAT and this App can take it, or why not.
std::string checkName(const std::string& name);
// The top-level folders the firmware keeps its files in. They can't be renamed or deleted;
// what's in them can (Q130).
extern const char* const kFirmwareFolders[];
extern const size_t kFirmwareFolderCount;
constexpr const char* kGeminiCache = "/gemini/cache";
// Why `path` can't be renamed, moved or deleted, or "" if it can (Q130). `inUse`: the files the
// firmware has open right now.
std::string whyReadOnly(const std::string& path, const std::vector<std::string>& inUse);
// Why `source` can't be copied or moved into the folder `into`, or "" if it can.
std::string whyNotInto(const std::string& source, const std::string& into);
// "a (2).gmi": the name of a copy made next to its original.
std::string copyName(const std::string& name, int n);
// Which viewer opens a file (Q134), from its name. Unknown: look at the first bytes.
enum class FileKind : uint8_t { Text, Gpx, Pcap, Ota, Unknown };
FileKind kindOf(const std::string& name);
bool opensAtEnd(const std::string& name); // logs
bool looksLikeText(const uint8_t* data, size_t len);
} // namespace roro::files
+143
View File
@@ -0,0 +1,143 @@
#include "file_views.h"
#include <cstdio>
#include <cstdlib>
#include <cstring>
#include "file_list.h"
#include "track.h"
namespace roro::files {
std::string hexRow(uint32_t offset, const uint8_t* data, size_t len) {
char head[8];
std::snprintf(head, sizeof head, "%05X", static_cast<unsigned>(offset));
std::string row = head, text;
for (size_t i = 0; i < 8; i++) {
if (i % 2 == 0) row += ' ';
char hex[3] = " ";
if (i < len) {
std::snprintf(hex, sizeof hex, "%02x", data[i]);
text += data[i] >= 0x20 && data[i] < 0x7F ? static_cast<char>(data[i]) : '.';
}
row += hex;
}
return row + " " + text;
}
namespace {
// Days since 1970-01-01 (Howard Hinnant's days_from_civil): no timegm() everywhere.
int64_t daysFromCivil(int y, int m, int d) {
y -= m <= 2;
int64_t era = (y >= 0 ? y : y - 399) / 400;
int yoe = static_cast<int>(y - era * 400);
int doy = (153 * (m + (m > 2 ? -3 : 9)) + 2) / 5 + d - 1;
int doe = yoe * 365 + yoe / 4 - yoe / 100 + doy;
return era * 146097 + doe - 719468;
}
bool attribute(const std::string& element, const char* name, double& out) {
size_t at = element.find(name);
if (at == std::string::npos) return false;
const char* from = element.c_str() + at + std::strlen(name);
char* end = nullptr;
out = std::strtod(from, &end);
return end != from;
}
} // namespace
void GpxSummary::point(const std::string& element) {
double lat, lon;
if (!attribute(element, "lat=\"", lat) || !attribute(element, "lon=\"", lon)) return;
if (points_ > 0) meters_ += gnss::distanceMeters(lat_, lon_, lat, lon);
lat_ = lat;
lon_ = lon;
points_++;
size_t at = element.find("<time>");
int y, mo, d, h, mi, s;
if (at != std::string::npos && std::sscanf(element.c_str() + at + 6, "%d-%d-%dT%d:%d:%d", &y, &mo, &d, &h, &mi, &s) == 6) {
int64_t t = daysFromCivil(y, mo, d) * 86400 + h * 3600 + mi * 60 + s;
if (first_ == 0) first_ = t;
last_ = t;
}
}
void GpxSummary::feed(const char* data, size_t len) {
carry_.append(data, len);
size_t done = 0;
for (;;) {
size_t open = carry_.find("<trkpt", done);
if (open == std::string::npos) {
// Nothing begun, except perhaps the first letters of a tag at the very end.
done = carry_.size() > 6 ? carry_.size() - 6 : done;
break;
}
size_t close = carry_.find("</trkpt>", open);
size_t next = carry_.find("<trkpt", open + 6); // a point with nothing inside: <trkpt .../>
if (close == std::string::npos && next == std::string::npos) {
done = open;
break;
}
size_t end = close != std::string::npos && (next == std::string::npos || close < next) ? close + 8 : next;
point(carry_.substr(open, end - open));
done = end;
}
carry_.erase(0, done);
if (carry_.size() > 2048) carry_.erase(0, carry_.size() - 6); // not a GPX point: don't keep it
}
std::string formatDuration(int64_t seconds) {
char s[24];
if (seconds < 60) std::snprintf(s, sizeof s, "%d s", static_cast<int>(seconds));
else if (seconds < 3600) std::snprintf(s, sizeof s, "%d min %02d s", static_cast<int>(seconds / 60), static_cast<int>(seconds % 60));
else std::snprintf(s, sizeof s, "%d h %02d min", static_cast<int>(seconds / 3600), static_cast<int>(seconds % 3600 / 60));
return s;
}
std::vector<std::string> GpxSummary::lines() const {
std::vector<std::string> out;
out.push_back(std::to_string(points_) + (points_ == 1 ? " point" : " points"));
if (first_ > 0) {
out.push_back("Started " + formatStamp(static_cast<uint32_t>(first_)));
out.push_back("Lasted " + formatDuration(last_ - first_));
}
char s[32];
if (meters_ < 1000) std::snprintf(s, sizeof s, "Distance %.0f m", meters_);
else std::snprintf(s, sizeof s, "Distance %.2f km", meters_ / 1000);
out.push_back(s);
return out;
}
namespace {
uint32_t le32(const uint8_t* p) { return p[0] | p[1] << 8 | p[2] << 16 | static_cast<uint32_t>(p[3]) << 24; }
} // namespace
PcapHeader parsePcapHeader(const uint8_t* data, size_t len) {
PcapHeader h;
if (len < kPcapHeaderSize || le32(data) != 0xA1B2C3D4) return h; // little-endian, microseconds: what we write
h.ok = true;
h.linkType = le32(data + 20);
return h;
}
bool parsePcapRecord(const uint8_t* data, size_t len, PcapRecord& out) {
if (len < kPcapRecordSize) return false;
out.seconds = le32(data);
out.micros = le32(data + 4);
out.length = le32(data + 8);
return out.length <= 65535;
}
bool parseLoraTap(const uint8_t* d, size_t len, lora::RxInfo& out) {
if (len < lora::kLoraTapSize || d[0] != 0) return false;
out.frequencyHz = static_cast<uint32_t>(d[4]) << 24 | d[5] << 16 | d[6] << 8 | d[7];
out.bandwidthKHz = d[8] * 125.0f;
out.spreadingFactor = d[9];
out.rssi = d[10] - 139.0f;
out.noiseFloor = d[12] - 139.0f;
out.snr = static_cast<int8_t>(d[13]) / 4.0f;
out.syncWord = d[14];
return true;
}
} // namespace roro::files
+57
View File
@@ -0,0 +1,57 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
#include "loratap.h"
namespace roro::files {
// What the Storage App's viewers show of the files the firmware writes (F1, Q134).
// One row of a hex dump, eight bytes: "00010 4865 6c6c 6f2c 2077 Hello, w".
std::string hexRow(uint32_t offset, const uint8_t* data, size_t len);
// A Track (.gpx) read a piece at a time: its points, when it started and ended, how far it went.
class GpxSummary {
public:
void feed(const char* data, size_t len);
uint32_t points() const { return points_; }
int64_t start() const { return first_; } // UTC seconds, 0 if no point carried a time
int64_t end() const { return last_; }
double meters() const { return meters_; }
std::vector<std::string> lines() const; // for the screen
private:
void point(const std::string& element);
std::string carry_; // the part of a point cut by the end of a piece
uint32_t points_ = 0;
int64_t first_ = 0, last_ = 0;
double meters_ = 0, lat_ = 0, lon_ = 0;
};
// "1 h 02 min", "4 min 10 s", "12 s".
std::string formatDuration(int64_t seconds);
// A Capture (.pcap): the file's header, then one record after another.
struct PcapHeader {
bool ok = false;
uint32_t linkType = 0; // 270: LoRaTap, what the LoRa Scanner writes
};
constexpr size_t kPcapHeaderSize = 24, kPcapRecordSize = 16;
constexpr uint32_t kLinkLoraTap = 270;
PcapHeader parsePcapHeader(const uint8_t* data, size_t len);
struct PcapRecord {
uint32_t seconds = 0, micros = 0, length = 0; // length: the bytes that follow in the file
};
bool parsePcapRecord(const uint8_t* data, size_t len, PcapRecord& out); // false: not a record, stop there
// The LoRaTap header a packet starts with; false if `len` is too short for one.
bool parseLoraTap(const uint8_t* data, size_t len, lora::RxInfo& out);
} // namespace roro::files
+121
View File
@@ -0,0 +1,121 @@
#include "text_pager.h"
#include <algorithm>
namespace roro::files {
TextPager::TextPager(ReadAt read, uint32_t size, int cols, int rows)
: read_(std::move(read)), size_(size), cols_(std::max(1, cols)), rows_(std::max(1, rows)) {}
const uint8_t* TextPager::bytes(uint32_t at, size_t& len) {
len = 0;
if (at >= size_) return nullptr;
bool cached = at >= cacheAt_ && at < cacheAt_ + cache_.size();
// Wanted: a line's worth ahead, unless the cache already reaches the end of the file.
size_t ahead = cached ? cacheAt_ + cache_.size() - at : 0;
if (!cached || (ahead < kBlock / 4 && cacheAt_ + cache_.size() < size_)) {
cacheAt_ = at - std::min<uint32_t>(at, kBlock / 2); // room behind too: scrolling back is common
cache_.resize(std::min<uint32_t>(kBlock, size_ - cacheAt_));
cache_.resize(read_(cacheAt_, cache_.data(), cache_.size()));
if (at >= cacheAt_ + cache_.size()) return nullptr; // the file got shorter, or the card failed
}
len = cacheAt_ + cache_.size() - at;
return cache_.data() + (at - cacheAt_);
}
int TextPager::byteAt(uint32_t at) {
size_t len;
const uint8_t* p = bytes(at, len);
return p ? *p : -1;
}
uint32_t TextPager::nextLine(uint32_t at, std::string* text) {
size_t len;
const uint8_t* p = bytes(at, len);
if (text) text->clear();
if (!p) return size_;
size_t end = len, next = len; // the line is [0, end); the one after starts at `next`
int count = 0;
size_t lastSpace = 0;
for (size_t i = 0; i < len; i++) {
uint8_t b = p[i];
if (b == '\n') {
end = i;
next = i + 1;
break;
}
if ((b & 0xC0) == 0x80) continue; // inside a UTF-8 character
if (count == cols_) { // one character too many: wrap
if (b == ' ') end = i, next = i + 1;
else if (lastSpace > 0) end = lastSpace, next = lastSpace + 1;
else end = next = i;
break;
}
count++;
if (b == ' ') lastSpace = i;
}
if (text) {
size_t n = end > 0 && p[end - 1] == '\r' ? end - 1 : end;
text->reserve(n);
for (size_t i = 0; i < n; i++) text->push_back(p[i] == '\t' ? ' ' : (p[i] < 0x20 || p[i] == 0x7F) ? '.' : static_cast<char>(p[i]));
}
return at + static_cast<uint32_t>(std::max<size_t>(next, 1));
}
uint32_t TextPager::lineBefore(uint32_t at) {
if (at == 0) return 0;
at = std::min(at, size_);
// The paragraph the line before `at` belongs to starts after the newline before it. The byte
// just before `at` may be that line's own newline.
uint32_t from = at - 1;
if (from > 0 && byteAt(from) == '\n') from--;
uint32_t limit = at > kLookBack ? at - kLookBack : 0, start = limit;
for (uint32_t i = from + 1; i-- > limit;) {
if (byteAt(i) == '\n' && i < at - 1) {
start = i + 1;
break;
}
}
// No newline that near: any character boundary will do as a place to wrap from.
while (start > 0 && start < at && (byteAt(start) & 0xC0) == 0x80) start++;
for (uint32_t a = start;;) {
uint32_t next = nextLine(a, nullptr);
if (next >= at) return a;
a = next;
}
}
bool TextPager::atEnd() {
uint32_t a = top_;
for (int i = 0; i < rows_; i++) {
a = nextLine(a, nullptr);
if (a >= size_) return true;
}
return false;
}
void TextPager::down(int n) {
for (; n > 0 && !atEnd(); n--) top_ = nextLine(top_, nullptr);
}
void TextPager::up(int n) {
for (; n > 0 && top_ > 0; n--) top_ = lineBefore(top_);
}
void TextPager::toEnd() {
top_ = size_;
up(rows_);
}
std::vector<std::string> TextPager::lines() {
std::vector<std::string> out;
uint32_t a = top_;
for (int i = 0; i < rows_ && a < size_; i++) {
std::string text;
a = nextLine(a, &text);
out.push_back(std::move(text));
}
return out;
}
} // namespace roro::files
+50
View File
@@ -0,0 +1,50 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <functional>
#include <string>
#include <vector>
namespace roro::files {
// A text file of any size, shown a screen at a time (F1, Q134): only the part on screen is read,
// through `read`, about a kilobyte at once. Lines wrap at spaces, `cols` characters wide. Going
// back a line means finding where the paragraph before started and wrapping it again, so a file
// reads the same whichever way it was scrolled.
class TextPager {
public:
// Reads up to `len` bytes at `offset`; returns how many it got.
using ReadAt = std::function<size_t(uint32_t offset, uint8_t* into, size_t len)>;
TextPager(ReadAt read, uint32_t size, int cols, int rows);
void toStart() { top_ = 0; }
void toEnd(); // the last line at the bottom of the screen
void down(int lines = 1);
void up(int lines = 1);
std::vector<std::string> lines(); // what's on screen: tabs as spaces, control characters as dots
uint32_t top() const { return top_; }
uint32_t size() const { return size_; }
bool atEnd(); // the file's last line is on screen
int percent() const { return size_ ? static_cast<int>(static_cast<uint64_t>(top_) * 100 / size_) : 0; }
private:
static constexpr size_t kBlock = 1024; // read at once
static constexpr uint32_t kLookBack = 1024; // how far back a paragraph's start is looked for
const uint8_t* bytes(uint32_t at, size_t& len); // what's cached from `at` on
int byteAt(uint32_t at); // -1 past the end
uint32_t nextLine(uint32_t at, std::string* text); // where the line after the one at `at` starts
uint32_t lineBefore(uint32_t at);
ReadAt read_;
uint32_t size_;
int cols_, rows_;
uint32_t top_ = 0;
std::vector<uint8_t> cache_;
uint32_t cacheAt_ = 0;
};
} // namespace roro::files
+59
View File
@@ -0,0 +1,59 @@
#include "gemini_response.h"
#include <cctype>
namespace roro::gemini {
namespace {
std::string trim(const std::string& s) {
size_t a = s.find_first_not_of(" \t"), b = s.find_last_not_of(" \t");
return a == std::string::npos ? "" : s.substr(a, b - a + 1);
}
std::string lower(std::string s) {
for (auto& c : s) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
return s;
}
} // namespace
bool parseHeader(const std::string& line, Header& out) {
if (line.size() < 2 || !std::isdigit(static_cast<unsigned char>(line[0])) ||
!std::isdigit(static_cast<unsigned char>(line[1])))
return false;
if (line.size() > 2 && line[2] != ' ') return false;
std::string meta = line.size() > 3 ? line.substr(3) : "";
if (meta.size() > 1024) return false;
out.status = (line[0] - '0') * 10 + (line[1] - '0');
out.meta = meta;
return true;
}
Category Header::category() const {
switch (status / 10) {
case 1: return Category::Input;
case 2: return Category::Success;
case 3: return Category::Redirect;
case 4: return Category::TemporaryFailure;
case 5: return Category::PermanentFailure;
case 6: return Category::ClientCertificate;
default: return Category::Unknown;
}
}
std::string Header::mimeType() const {
std::string type = lower(trim(meta.substr(0, meta.find(';'))));
return type.empty() ? "text/gemini" : type;
}
std::string Header::parameter(const std::string& name) const {
size_t pos = meta.find(';');
while (pos != std::string::npos) {
size_t next = meta.find(';', pos + 1);
std::string item = trim(meta.substr(pos + 1, next == std::string::npos ? std::string::npos : next - pos - 1));
size_t eq = item.find('=');
if (eq != std::string::npos && lower(trim(item.substr(0, eq))) == lower(name)) return trim(item.substr(eq + 1));
pos = next;
}
return "";
}
} // namespace roro::gemini
+23
View File
@@ -0,0 +1,23 @@
#pragma once
#include <string>
namespace roro::gemini {
enum class Category { Input, Success, Redirect, TemporaryFailure, PermanentFailure, ClientCertificate, Unknown };
// The response header: "<two digits> <meta>", at most 1024 bytes of meta.
struct Header {
int status = 0;
std::string meta;
Category category() const;
bool sensitiveInput() const { return status == 11; }
// 2x: the MIME type, lower-cased, without parameters ("text/gemini" when meta is empty).
std::string mimeType() const;
std::string parameter(const std::string& name) const; // e.g. "charset"
};
bool parseHeader(const std::string& line, Header& out);
} // namespace roro::gemini
+215
View File
@@ -0,0 +1,215 @@
#include "gemini_url.h"
#include <cctype>
#include <cstdio>
#include <cstdlib>
#include <vector>
#include "storage_paths.h"
namespace roro::gemini {
namespace {
// RFC 3986, appendix B: ^(([^:/?#]+):)?(//([^/?#]*))?([^?#]*)(\?([^#]*))?(#(.*))?
struct Parts {
std::string scheme, authority, path, query, fragment;
bool hasScheme = false, hasAuthority = false, hasQuery = false, hasFragment = false;
};
Parts split(const std::string& s) {
Parts p;
size_t i = 0;
size_t colon = s.find(':');
size_t stop = s.find_first_of("/?#");
if (colon != std::string::npos && colon > 0 && (stop == std::string::npos || colon < stop)) {
p.scheme = s.substr(0, colon);
p.hasScheme = true;
i = colon + 1;
}
if (s.compare(i, 2, "//") == 0) {
size_t end = s.find_first_of("/?#", i + 2);
if (end == std::string::npos) end = s.size();
p.authority = s.substr(i + 2, end - i - 2);
p.hasAuthority = true;
i = end;
}
size_t end = s.find_first_of("?#", i);
if (end == std::string::npos) end = s.size();
p.path = s.substr(i, end - i);
i = end;
if (i < s.size() && s[i] == '?') {
end = s.find('#', i);
if (end == std::string::npos) end = s.size();
p.query = s.substr(i + 1, end - i - 1);
p.hasQuery = true;
i = end;
}
if (i < s.size() && s[i] == '#') {
p.fragment = s.substr(i + 1);
p.hasFragment = true;
}
return p;
}
std::string lower(std::string s) {
for (auto& c : s) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
return s;
}
// RFC 3986, section 5.2.4.
std::string removeDotSegments(std::string in) {
std::string out;
while (!in.empty()) {
if (in.compare(0, 3, "../") == 0) in.erase(0, 3);
else if (in.compare(0, 2, "./") == 0) in.erase(0, 2);
else if (in.compare(0, 3, "/./") == 0) in.replace(0, 3, "/");
else if (in == "/.") in = "/";
else if (in.compare(0, 4, "/../") == 0 || in == "/..") {
in = in == "/.." ? "/" : in.substr(3);
size_t slash = out.rfind('/');
out.erase(slash == std::string::npos ? 0 : slash);
} else if (in == "." || in == "..") in.clear();
else {
size_t next = in.find('/', in[0] == '/' ? 1 : 0);
if (next == std::string::npos) next = in.size();
out += in.substr(0, next);
in.erase(0, next);
}
}
return out;
}
// RFC 3986, section 5.2.3.
std::string merge(const Parts& base, const std::string& refPath) {
if (base.hasAuthority && base.path.empty()) return "/" + refPath;
size_t slash = base.path.rfind('/');
return slash == std::string::npos ? refPath : base.path.substr(0, slash + 1) + refPath;
}
// RFC 3986, section 5.3.
std::string recompose(const Parts& p) {
std::string out;
if (p.hasScheme) out += p.scheme + ":";
if (p.hasAuthority) out += "//" + p.authority;
out += p.path;
if (p.hasQuery) out += "?" + p.query;
if (p.hasFragment) out += "#" + p.fragment;
return out;
}
} // namespace
bool parseUrl(const std::string& text, Url& out) {
Parts p = split(text);
if (!p.hasScheme || !p.hasAuthority) return false;
out = Url();
out.scheme = lower(p.scheme);
out.authority = p.authority;
std::string hostPort = p.authority.substr(p.authority.find('@') == std::string::npos ? 0 : p.authority.find('@') + 1);
size_t colon = hostPort.rfind(':');
if (colon != std::string::npos && hostPort.find(']', colon) == std::string::npos) {
out.port = std::atoi(hostPort.c_str() + colon + 1);
hostPort = hostPort.substr(0, colon);
}
out.host = lower(hostPort);
if (out.host.empty()) return false;
out.path = p.path;
out.query = p.query;
out.fragment = p.fragment;
out.hasAuthority = true;
out.hasQuery = p.hasQuery;
out.hasFragment = p.hasFragment;
return true;
}
bool isGemini(const std::string& url) {
Parts p = split(url);
return p.hasScheme && lower(p.scheme) == "gemini";
}
std::string resolve(const std::string& baseText, const std::string& refText) {
Parts base = split(baseText), r = split(refText), t;
if (r.hasScheme) {
t = r;
t.path = removeDotSegments(r.path);
} else {
if (r.hasAuthority) {
t.authority = r.authority;
t.hasAuthority = true;
t.path = removeDotSegments(r.path);
t.query = r.query;
t.hasQuery = r.hasQuery;
} else {
if (r.path.empty()) {
t.path = base.path;
t.query = r.hasQuery ? r.query : base.query;
t.hasQuery = r.hasQuery || base.hasQuery;
} else {
t.path = removeDotSegments(r.path[0] == '/' ? r.path : merge(base, r.path));
t.query = r.query;
t.hasQuery = r.hasQuery;
}
t.authority = base.authority;
t.hasAuthority = base.hasAuthority;
}
t.scheme = base.scheme;
t.hasScheme = base.hasScheme;
}
t.fragment = r.fragment;
t.hasFragment = r.hasFragment;
return recompose(t);
}
std::string requestUrl(const std::string& url) {
Url u;
if (!parseUrl(url, u)) return url;
std::string out = u.scheme + "://" + u.host;
if (u.port > 0 && u.port != 1965) out += ":" + std::to_string(u.port);
out += u.path.empty() ? "/" : u.path;
if (u.hasQuery) out += "?" + u.query;
return out;
}
std::string encodeQuery(const std::string& text) {
std::string out;
for (unsigned char c : text) {
if (std::isalnum(c) || c == '-' || c == '_' || c == '.' || c == '~') out += static_cast<char>(c);
else {
char buf[4];
std::snprintf(buf, sizeof buf, "%%%02X", c);
out += buf;
}
}
return out;
}
std::string savedPath(const std::string& url) {
Url u;
if (!parseUrl(url, u)) return "/gemini/saved/unknown.gmi";
std::string out = "/gemini/saved/" + storage::sanitize(u.host + (u.port > 0 && u.port != 1965 ? "_" + std::to_string(u.port) : ""));
std::string path = u.path.empty() ? "/" : u.path;
std::vector<std::string> parts;
size_t start = 1;
while (start <= path.size()) {
size_t slash = path.find('/', start);
if (slash == std::string::npos) slash = path.size();
parts.push_back(path.substr(start, slash - start));
start = slash + 1;
}
if (parts.empty() || parts.back().empty()) {
if (!parts.empty()) parts.pop_back();
parts.push_back("index");
}
for (size_t i = 0; i < parts.size(); i++) {
std::string name = parts[i];
if (i + 1 == parts.size()) {
if (u.hasQuery) name += "~" + u.query;
if (name.size() < 4 || name.compare(name.size() - 4, 4, ".gmi") != 0) name += ".gmi";
}
out += "/" + storage::sanitize(name);
}
return out;
}
} // namespace roro::gemini
+28
View File
@@ -0,0 +1,28 @@
#pragma once
#include <string>
namespace roro::gemini {
// A URL split per RFC 3986 (appendix B). For Gemini, the host is lower-cased and the port
// defaults to 1965.
struct Url {
std::string scheme, authority, host, path, query, fragment;
int port = -1;
bool hasAuthority = false, hasQuery = false, hasFragment = false;
int portOrDefault() const { return port > 0 ? port : 1965; }
};
// False unless it has a scheme and a host: only absolute URLs are fetched.
bool parseUrl(const std::string& text, Url& out);
bool isGemini(const std::string& url);
// `ref` against `base`, per RFC 3986 section 5.2 (dot segments included).
std::string resolve(const std::string& base, const std::string& ref);
// What goes on the wire: no fragment, lower-case host, never an empty path.
std::string requestUrl(const std::string& url);
// For input prompts: everything but unreserved characters percent-encoded (UTF-8 bytes).
std::string encodeQuery(const std::string& text);
// Where a Saved Page lives (Q82): /gemini/saved/<host>[_<port>]/<path>[~<query>].gmi
std::string savedPath(const std::string& url);
} // namespace roro::gemini
+100
View File
@@ -0,0 +1,100 @@
#include "gemtext.h"
#include <cstdint>
namespace roro::gemini {
namespace {
std::string trim(const std::string& s) {
size_t a = s.find_first_not_of(" \t"), b = s.find_last_not_of(" \t");
return a == std::string::npos ? "" : s.substr(a, b - a + 1);
}
} // namespace
GemLine parseGemLine(const std::string& line, bool& pre) {
GemLine g;
if (line.compare(0, 3, "```") == 0) {
g.type = LineType::PreToggle;
g.text = trim(line.substr(3));
pre = !pre;
} else if (pre) {
g.type = LineType::Preformatted;
g.text = line;
} else if (line.compare(0, 2, "=>") == 0) {
g.type = LineType::Link;
std::string rest = trim(line.substr(2));
size_t gap = rest.find_first_of(" \t");
g.url = rest.substr(0, gap);
g.text = gap == std::string::npos ? "" : trim(rest.substr(gap));
if (g.text.empty()) g.text = g.url;
} else if (line.compare(0, 3, "###") == 0) {
g.type = LineType::Heading3;
g.text = trim(line.substr(3));
} else if (line.compare(0, 2, "##") == 0) {
g.type = LineType::Heading2;
g.text = trim(line.substr(2));
} else if (line.compare(0, 1, "#") == 0) {
g.type = LineType::Heading1;
g.text = trim(line.substr(1));
} else if (line.compare(0, 2, "* ") == 0) {
g.type = LineType::ListItem;
g.text = trim(line.substr(2));
} else if (line.compare(0, 1, ">") == 0) {
g.type = LineType::Quote;
g.text = trim(line.substr(1));
} else {
g.text = line;
}
return g;
}
std::vector<GemLine> parseGemtext(const std::string& document) {
std::vector<GemLine> lines;
bool pre = false;
size_t start = 0;
while (start < document.size()) {
size_t end = document.find('\n', start);
if (end == std::string::npos) end = document.size();
std::string line = document.substr(start, end - start);
if (!line.empty() && line.back() == '\r') line.pop_back();
start = end + 1;
lines.push_back(parseGemLine(line, pre));
}
return lines;
}
std::string displayText(const std::string& s) {
std::string out;
size_t column = 0;
for (size_t i = 0; i < s.size();) {
unsigned char c = static_cast<unsigned char>(s[i]);
if (c == '\t') {
do out += ' ';
while (++column % 4);
i++;
continue;
}
if (c < 0x80) {
out += static_cast<char>(c);
i++;
} else {
int len = (c & 0xE0) == 0xC0 ? 2 : (c & 0xF0) == 0xE0 ? 3 : (c & 0xF8) == 0xF0 ? 4 : 0;
bool valid = len > 0 && i + len <= s.size();
for (int k = 1; valid && k < len; k++) valid = (static_cast<unsigned char>(s[i + k]) & 0xC0) == 0x80;
if (!valid) {
out += '?';
i++;
} else {
uint32_t cp = len == 2 ? (c & 0x1F) : len == 3 ? (c & 0x0F) : (c & 0x07);
for (int k = 1; k < len; k++) cp = (cp << 6) | (static_cast<unsigned char>(s[i + k]) & 0x3F);
if (cp <= 0xFF) out.append(s, i, len); // Latin-1: the fonts have it
else out += '?';
i += len;
}
}
column++;
}
return out;
}
} // namespace roro::gemini
+25
View File
@@ -0,0 +1,25 @@
#pragma once
#include <string>
#include <vector>
namespace roro::gemini {
enum class LineType { Text, Link, Heading1, Heading2, Heading3, ListItem, Quote, PreToggle, Preformatted };
// One gemtext line. Link: `url` and its label in `text` (the URL itself without a label).
// PreToggle: the ``` line, with its alt text. Preformatted: kept exactly.
struct GemLine {
LineType type = LineType::Text;
std::string text, url;
};
// One line; `preformatted` carries the ``` state from line to line (start with false).
GemLine parseGemLine(const std::string& line, bool& preformatted);
std::vector<GemLine> parseGemtext(const std::string& document);
// For the Latin-1 fonts (Q79): valid UTF-8 up to U+00FF kept, anything else '?', and tabs
// expanded to 4-column stops.
std::string displayText(const std::string& utf8);
} // namespace roro::gemini
+47
View File
@@ -0,0 +1,47 @@
#include "text_buffer.h"
#include <algorithm>
namespace roro::gemini {
void TextBuffer::append(const char* data, size_t len) {
bytes_ += len;
for (size_t i = 0; i < len; i++) {
if (data[i] == '\n') endLine();
else partial_ += data[i];
}
}
void TextBuffer::finish() {
if (!partial_.empty()) endLine();
}
void TextBuffer::endLine() {
if (!partial_.empty() && partial_.back() == '\r') partial_.pop_back();
size_t len = std::min<size_t>(partial_.size(), 0xFFFF);
// A line never spans two chunks: a new chunk when it doesn't fit (bigger if the line is).
if (chunks_.empty() || chunks_.back().size() + len > chunks_.back().capacity()) {
chunks_.emplace_back();
chunks_.back().reserve(std::max(kChunk, len));
}
std::string& chunk = chunks_.back();
lines_.push_back({static_cast<uint16_t>(chunks_.size() - 1), static_cast<uint16_t>(chunk.size()),
static_cast<uint16_t>(len)});
chunk.append(partial_, 0, len);
partial_.clear();
}
std::string TextBuffer::line(size_t i) const {
if (i >= lines_.size()) return "";
const Ref& r = lines_[i];
return chunks_[r.chunk].substr(r.offset, r.length);
}
void TextBuffer::clear() {
chunks_.clear();
lines_.clear();
partial_.clear();
bytes_ = 0;
}
} // namespace roro::gemini
+38
View File
@@ -0,0 +1,38 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::gemini {
// A page's text, kept as lines in 4 KB chunks: no large contiguous block (with IRC connected the
// largest free block is about 31 KB) and no copy when it grows. About 4 bytes per line on top of
// the text itself. Bytes are fed as they arrive; lines end at LF, a CR before it is dropped.
class TextBuffer {
public:
static constexpr size_t kChunk = 4096;
void append(const char* data, size_t len);
void finish(); // the last line, if it has no line end
size_t lineCount() const { return lines_.size(); }
std::string line(size_t i) const;
size_t bytes() const { return bytes_; }
void clear();
private:
struct Ref {
uint16_t chunk;
uint16_t offset;
uint16_t length;
};
void endLine();
std::vector<std::string> chunks_;
std::vector<Ref> lines_;
std::string partial_; // the line being received
size_t bytes_ = 0;
};
} // namespace roro::gemini
+50
View File
@@ -0,0 +1,50 @@
#include "geo_format.h"
#include <cmath>
#include <cstdio>
namespace roro::gnss {
namespace {
const char* hemisphere(double degrees, bool latitude) {
return latitude ? (degrees < 0 ? "S" : "N") : (degrees < 0 ? "W" : "E");
}
} // namespace
std::string formatDecimal(double degrees, bool latitude) {
char buf[32];
std::snprintf(buf, sizeof buf, "%.5f\xC2\xB0 %s", std::fabs(degrees), hemisphere(degrees, latitude));
return buf;
}
std::string formatDms(double degrees, bool latitude) {
// Work in tenths of a second, so rounding carries into minutes and degrees.
long tenths = std::lround(std::fabs(degrees) * 36000.0);
long d = tenths / 36000, m = tenths / 600 % 60, s10 = tenths % 600;
char buf[40];
std::snprintf(buf, sizeof buf, "%ld\xC2\xB0 %02ld' %02ld.%ld\" %s", d, m, s10 / 10, s10 % 10,
hemisphere(degrees, latitude));
return buf;
}
std::string maidenhead(double latitude, double longitude) {
double lon = std::fmin(std::fmax(longitude + 180.0, 0.0), 359.999999);
double lat = std::fmin(std::fmax(latitude + 90.0, 0.0), 179.999999);
std::string out;
out += static_cast<char>('A' + static_cast<int>(lon / 20));
out += static_cast<char>('A' + static_cast<int>(lat / 10));
out += static_cast<char>('0' + static_cast<int>(std::fmod(lon, 20) / 2));
out += static_cast<char>('0' + static_cast<int>(std::fmod(lat, 10)));
out += static_cast<char>('a' + static_cast<int>(std::fmod(lon, 2) * 12));
out += static_cast<char>('a' + static_cast<int>(std::fmod(lat, 1) * 24));
return out;
}
SkyPoint skyPosition(int azimuthDeg, int elevationDeg, int cx, int cy, int radius) {
int elevation = elevationDeg < 0 ? 0 : elevationDeg > 90 ? 90 : elevationDeg;
double r = radius * (90 - elevation) / 90.0;
double az = azimuthDeg * M_PI / 180.0;
return {cx + static_cast<int>(std::lround(r * std::sin(az))), cy - static_cast<int>(std::lround(r * std::cos(az)))};
}
} // namespace roro::gnss
+21
View File
@@ -0,0 +1,21 @@
#pragma once
#include <string>
namespace roro::gnss {
// "50.86920° N": five decimals, about a metre.
std::string formatDecimal(double degrees, bool latitude);
// "50° 52' 09.1\" N" (Settings → Coordinates, Q64).
std::string formatDms(double degrees, bool latitude);
// The 6-character Maidenhead locator ("JO20ef"), as radio amateurs give their square.
std::string maidenhead(double latitude, double longitude);
// Where a satellite goes on the Sky view: the zenith in the centre, the horizon on the circle,
// north up and east right (as seen looking at the sky from above, like a map).
struct SkyPoint {
int x, y;
};
SkyPoint skyPosition(int azimuthDeg, int elevationDeg, int cx, int cy, int radius);
} // namespace roro::gnss
+234
View File
@@ -0,0 +1,234 @@
#include "nmea_parser.h"
#include <cstdlib>
namespace roro::gnss {
namespace {
constexpr double kKmhPerKnot = 1.852;
int hexValue(char c) {
if (c >= '0' && c <= '9') return c - '0';
if (c >= 'A' && c <= 'F') return c - 'A' + 10;
if (c >= 'a' && c <= 'f') return c - 'a' + 10;
return -1;
}
Constellation fromTalker(const std::string& t) {
if (t == "GP") return Constellation::Gps;
if (t == "GL") return Constellation::Glonass;
if (t == "GA") return Constellation::Galileo;
if (t == "GB" || t == "BD") return Constellation::BeiDou;
if (t == "GQ" || t == "QZ") return Constellation::Qzss;
if (t == "GI") return Constellation::Navic;
return Constellation::Unknown; // GN: combined
}
// GSA's system ID field (NMEA 4.10).
Constellation fromSystemId(int id) {
switch (id) {
case 1: return Constellation::Gps;
case 2: return Constellation::Glonass;
case 3: return Constellation::Galileo;
case 4: return Constellation::BeiDou;
case 5: return Constellation::Qzss;
case 6: return Constellation::Navic;
default: return Constellation::Unknown;
}
}
bool number(const std::string& s, double& out) {
if (s.empty()) return false;
char* end;
out = std::strtod(s.c_str(), &end);
return *end == '\0';
}
int integer(const std::string& s, int fallback = 0) {
double v;
return number(s, v) ? static_cast<int>(v) : fallback;
}
// "ddmm.mmmm" / "dddmm.mmmm" with its hemisphere letter.
bool coordinate(const std::string& value, const std::string& hemisphere, double& out) {
double raw;
if (!number(value, raw) || hemisphere.empty()) return false;
int degrees = static_cast<int>(raw / 100);
out = degrees + (raw - degrees * 100) / 60.0;
if (hemisphere == "S" || hemisphere == "W") out = -out;
return true;
}
// Days since 1970-01-01 for a civil date (Howard Hinnant's algorithm).
int64_t daysFromCivil(int y, int m, int d) {
y -= m <= 2;
const int64_t era = (y >= 0 ? y : y - 399) / 400;
const unsigned yoe = static_cast<unsigned>(y - era * 400);
const unsigned doy = (153 * (m + (m > 2 ? -3 : 9)) + 2) / 5 + d - 1;
const unsigned doe = yoe * 365 + yoe / 4 - yoe / 100 + doy;
return era * 146097 + static_cast<int64_t>(doe) - 719468;
}
} // namespace
const char* constellationName(Constellation c) {
switch (c) {
case Constellation::Gps: return "GPS";
case Constellation::Glonass: return "GLONASS";
case Constellation::Galileo: return "Galileo";
case Constellation::BeiDou: return "BeiDou";
case Constellation::Qzss: return "QZSS";
case Constellation::Navic: return "NavIC";
default: return "?";
}
}
int64_t GnssState::utcSeconds() const {
return daysFromCivil(year, month, day) * 86400 + hour * 3600 + minute * 60 + second;
}
void NmeaParser::feed(const char* data, size_t len) {
for (size_t i = 0; i < len; i++) {
char c = data[i];
if (c == '\n') {
if (!overflow_ && !line_.empty()) {
if (onLine) onLine(line_);
sentence(line_);
}
line_.clear();
overflow_ = false;
} else if (c != '\r') {
if (line_.size() >= kMaxLine) overflow_ = true;
else line_ += c;
}
}
}
bool NmeaParser::sentence(const std::string& line) {
size_t star = line.rfind('*');
if (line.size() < 7 || line[0] != '$' || star == std::string::npos || star + 3 != line.size()) {
bad_++;
return false;
}
uint8_t sum = 0;
for (size_t i = 1; i < star; i++) sum ^= static_cast<uint8_t>(line[i]);
int hi = hexValue(line[star + 1]), lo = hexValue(line[star + 2]);
if (hi < 0 || lo < 0 || sum != (hi << 4 | lo)) {
bad_++;
return false;
}
good_++;
Fields f;
size_t start = 1;
for (size_t i = 1; i <= star; i++)
if (i == star || line[i] == ',') {
f.push_back(line.substr(start, i - start));
start = i + 1;
}
if (f[0].size() < 5) return true;
std::string talker = f[0].substr(0, 2), type = f[0].substr(f[0].size() - 3);
if (type == "RMC") rmc(f);
else if (type == "GGA") gga(f);
else if (type == "GSA") gsa(f, fromTalker(talker));
else if (type == "GSV") gsv(f, fromTalker(talker));
return true;
}
void NmeaParser::rmc(const Fields& f) {
if (f.size() < 10) return;
bool active = f[2] == "A";
double lat, lon;
state_.positionValid = active && coordinate(f[3], f[4], lat) && coordinate(f[5], f[6], lon);
if (state_.positionValid) {
state_.latitude = lat;
state_.longitude = lon;
}
double knots, course;
state_.speedKmh = active && number(f[7], knots) ? static_cast<float>(knots * kKmhPerKnot) : 0;
state_.courseValid = active && number(f[8], course);
if (state_.courseValid) state_.courseDeg = static_cast<float>(course);
const std::string &t = f[1], &d = f[9];
state_.timeValid = active && t.size() >= 6 && d.size() == 6;
if (state_.timeValid) {
state_.hour = integer(t.substr(0, 2));
state_.minute = integer(t.substr(2, 2));
state_.second = integer(t.substr(4, 2));
state_.day = integer(d.substr(0, 2));
state_.month = integer(d.substr(2, 2));
state_.year = 2000 + integer(d.substr(4, 2));
}
}
void NmeaParser::gga(const Fields& f) {
if (f.size() < 10) return;
int quality = integer(f[6]);
double lat, lon, hdop, alt;
state_.positionValid = quality > 0 && coordinate(f[2], f[3], lat) && coordinate(f[4], f[5], lon);
if (state_.positionValid) {
state_.latitude = lat;
state_.longitude = lon;
}
state_.satellitesUsed = integer(f[7]);
if (number(f[8], hdop)) state_.hdop = static_cast<float>(hdop);
state_.altitudeValid = quality > 0 && number(f[9], alt);
if (state_.altitudeValid) state_.altitudeM = static_cast<float>(alt);
}
void NmeaParser::gsa(const Fields& f, Constellation talker) {
if (f.size() < 18) return;
int mode = integer(f[2], 1);
state_.fix = mode == 3 ? FixType::ThreeD : mode == 2 ? FixType::TwoD : FixType::None;
Constellation system = f.size() > 18 ? fromSystemId(integer(f[18])) : talker;
if (system == Constellation::Unknown) return; // can't tell whose satellites these are
std::set<int>& used = used_[static_cast<int>(system)];
used.clear();
for (size_t i = 3; i <= 14; i++)
if (!f[i].empty()) used.insert(integer(f[i]));
rebuildSatellites();
}
void NmeaParser::gsv(const Fields& f, Constellation talker) {
if (f.size() < 4 || talker == Constellation::Unknown) return;
int total = integer(f[1]), number = integer(f[2]);
size_t extra = f.size() - 4;
int signal = extra % 4 == 1 ? integer(f.back()) : 0; // NMEA 4.10 signal ID, last
auto key = std::make_pair(static_cast<int>(talker), signal);
std::vector<Satellite>& pending = pending_[key];
if (number == 1) pending.clear();
for (size_t i = 4; i + 3 < f.size(); i += 4) {
Satellite s;
s.system = talker;
s.prn = integer(f[i]);
s.elevation = integer(f[i + 1]);
s.azimuth = integer(f[i + 2]);
s.snr = integer(f[i + 3], -1);
if (s.prn > 0) pending.push_back(s);
}
if (number == total) {
inView_[key] = pending;
pending.clear();
rebuildSatellites();
}
}
void NmeaParser::rebuildSatellites() {
std::vector<Satellite> merged;
for (auto& [key, list] : inView_)
for (const Satellite& s : list) {
Satellite* same = nullptr;
for (auto& m : merged)
if (m.system == s.system && m.prn == s.prn) same = &m;
if (!same) merged.push_back(s);
else if (s.snr > same->snr) same->snr = s.snr;
}
for (auto& s : merged) {
auto it = used_.find(static_cast<int>(s.system));
s.used = it != used_.end() && it->second.count(s.prn) > 0;
}
state_.satellites = std::move(merged);
}
} // namespace roro::gnss
+82
View File
@@ -0,0 +1,82 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <functional>
#include <map>
#include <set>
#include <string>
#include <utility>
#include <vector>
namespace roro::gnss {
enum class Constellation : uint8_t { Unknown, Gps, Glonass, Galileo, BeiDou, Qzss, Navic };
const char* constellationName(Constellation c);
enum class FixType : uint8_t { None, TwoD, ThreeD };
struct Satellite {
Constellation system = Constellation::Unknown;
int prn = 0;
int elevation = 0; // degrees above the horizon
int azimuth = 0; // degrees from north, clockwise
int snr = -1; // dB-Hz; -1 when not tracked
bool used = false; // part of the current Fix
};
// Everything the receiver has said, as of the last sentence (see CONTEXT.md: Fix).
struct GnssState {
FixType fix = FixType::None;
bool positionValid = false;
double latitude = 0, longitude = 0; // degrees, south and west negative
bool altitudeValid = false;
float altitudeM = 0; // above mean sea level
float speedKmh = 0;
bool courseValid = false;
float courseDeg = 0;
int satellitesUsed = 0;
float hdop = 99.9f;
// UTC, trusted only with a Fix: the receiver reports a time without one, from its own clock.
bool timeValid = false;
int year = 0, month = 0, day = 0, hour = 0, minute = 0, second = 0;
std::vector<Satellite> satellites; // in view, all constellations, one entry per satellite
int64_t utcSeconds() const; // seconds since 1970-01-01 UTC; meaningful when timeValid
};
// NMEA 0183 (4.10 style, as the Cap's AT6668 sends it): RMC, GGA, GSA and GSV, with the
// constellation taken from the talker ID or GSA's system ID field. Host-tested; no hardware here.
class NmeaParser {
public:
// Raw bytes from the UART, in any chunks.
void feed(const char* data, size_t len);
// One sentence without its line end. False if malformed or its checksum is wrong.
bool sentence(const std::string& line);
// Called with every complete line fed in, valid or not (`gnss nmea on` echoes them).
std::function<void(const std::string&)> onLine;
const GnssState& state() const { return state_; }
uint32_t goodSentences() const { return good_; }
uint32_t badSentences() const { return bad_; }
private:
using Fields = std::vector<std::string>;
void rmc(const Fields& f);
void gga(const Fields& f);
void gsa(const Fields& f, Constellation talker);
void gsv(const Fields& f, Constellation talker);
void rebuildSatellites();
static constexpr size_t kMaxLine = 120;
std::string line_;
bool overflow_ = false;
uint32_t good_ = 0, bad_ = 0;
GnssState state_;
// GSV sequences per (constellation, signal): pending until their last message.
std::map<std::pair<int, int>, std::vector<Satellite>> pending_, inView_;
std::map<int, std::set<int>> used_; // per constellation, from GSA
};
} // namespace roro::gnss
+76
View File
@@ -0,0 +1,76 @@
#include "track.h"
#include <cmath>
#include <cstdio>
#include <ctime>
namespace roro::gnss {
namespace {
constexpr double kEarthRadiusM = 6371000.0;
double radians(double degrees) { return degrees * M_PI / 180.0; }
// UTC fields from seconds since 1970 (gmtime_r works on the device and the PC alike).
struct tm utc(int64_t seconds) {
time_t t = static_cast<time_t>(seconds);
struct tm out;
gmtime_r(&t, &out);
return out;
}
} // namespace
double distanceMeters(double lat1, double lon1, double lat2, double lon2) {
double dLat = radians(lat2 - lat1), dLon = radians(lon2 - lon1);
double h = std::sin(dLat / 2) * std::sin(dLat / 2) +
std::cos(radians(lat1)) * std::cos(radians(lat2)) * std::sin(dLon / 2) * std::sin(dLon / 2);
return 2 * kEarthRadiusM * std::asin(std::sqrt(h));
}
bool TrackRule::due(uint32_t nowMs, double lat, double lon) {
if (any_ && (nowMs - lastMs_ < kEveryMs || distanceMeters(lat_, lon_, lat, lon) < kMinMeters)) return false;
any_ = true;
lastMs_ = nowMs;
lat_ = lat;
lon_ = lon;
return true;
}
std::string trackPath(int64_t utcSeconds) {
struct tm t = utc(utcSeconds);
char buf[48];
std::snprintf(buf, sizeof buf, "/gnss/tracks/%04d%02d%02d-%02d%02d%02d.gpx", t.tm_year + 1900, t.tm_mon + 1,
t.tm_mday, t.tm_hour, t.tm_min, t.tm_sec);
return buf;
}
namespace gpx {
std::string header(const std::string& name) {
return "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n"
"<gpx version=\"1.1\" creator=\"roro9stack\" xmlns=\"http://www.topografix.com/GPX/1/1\">\n"
"<trk><name>" + name + "</name><trkseg>";
}
std::string point(double lat, double lon, bool hasElevation, float elevationM, int64_t utcSeconds) {
struct tm t = utc(utcSeconds);
char buf[160], ele[32] = "";
if (hasElevation) std::snprintf(ele, sizeof ele, "<ele>%.1f</ele>", elevationM);
std::snprintf(buf, sizeof buf,
"<trkpt lat=\"%.7f\" lon=\"%.7f\">%s<time>%04d-%02d-%02dT%02d:%02d:%02dZ</time></trkpt>", lat, lon,
ele, t.tm_year + 1900, t.tm_mon + 1, t.tm_mday, t.tm_hour, t.tm_min, t.tm_sec);
return buf;
}
std::string footer() { return "</trkseg></trk></gpx>"; }
bool finished(const std::string& tail) {
size_t end = tail.find_last_not_of(" \r\n\t");
return end != std::string::npos && end + 1 >= 6 && tail.compare(end + 1 - 6, 6, "</gpx>") == 0;
}
} // namespace gpx
} // namespace roro::gnss
+40
View File
@@ -0,0 +1,40 @@
#pragma once
#include <cstdint>
#include <string>
namespace roro::gnss {
// Great-circle distance in metres (haversine, mean Earth radius).
double distanceMeters(double lat1, double lon1, double lat2, double lon2);
// When a Track takes its next point (Q63): the first one always, then at least every 5 s and only
// after moving at least 5 m, so standing still doesn't fill the card.
class TrackRule {
public:
static constexpr uint32_t kEveryMs = 5000;
static constexpr double kMinMeters = 5.0;
// True if this position should be recorded (and is then remembered as the last point).
bool due(uint32_t nowMs, double lat, double lon);
void reset() { any_ = false; }
private:
bool any_ = false;
uint32_t lastMs_ = 0;
double lat_ = 0, lon_ = 0;
};
// "/gnss/tracks/YYYYMMDD-HHMMSS.gpx", from the UTC start time (Storage Clean-up reads its date).
std::string trackPath(int64_t utcSeconds);
// GPX 1.1, written a line at a time: the header when a Track starts, a point per line, the footer
// when it stops. A file whose footer never came (power lost) is closed at the next boot.
namespace gpx {
std::string header(const std::string& name);
std::string point(double lat, double lon, bool hasElevation, float elevationM, int64_t utcSeconds);
std::string footer();
bool finished(const std::string& tail); // the end of a file: does it close the GPX?
} // namespace gpx
} // namespace roro::gnss
+64
View File
@@ -0,0 +1,64 @@
#include "loratap.h"
#include <algorithm>
#include <cmath>
#include <cstdio>
#include <ctime>
namespace roro::lora {
static void le16(std::vector<uint8_t>& o, uint16_t v) { o.insert(o.end(), {uint8_t(v), uint8_t(v >> 8)}); }
static void le32(std::vector<uint8_t>& o, uint32_t v) {
o.insert(o.end(), {uint8_t(v), uint8_t(v >> 8), uint8_t(v >> 16), uint8_t(v >> 24)});
}
// LoRaTap's dBm encoding: -139 dBm plus the byte, clamped to what a byte holds.
static uint8_t dbmByte(float dbm) {
long v = std::lround(dbm + 139);
return static_cast<uint8_t>(std::clamp(v, 0L, 255L));
}
std::string capturePath(int64_t utcSeconds) {
time_t t = static_cast<time_t>(utcSeconds);
struct tm u;
gmtime_r(&t, &u);
char buf[48];
std::snprintf(buf, sizeof buf, "/captures/lora/%04d%02d%02d-%02d%02d%02d.pcap", u.tm_year + 1900, u.tm_mon + 1,
u.tm_mday, u.tm_hour, u.tm_min, u.tm_sec);
return buf;
}
void appendPcapHeader(std::vector<uint8_t>& out) {
le32(out, 0xA1B2C3D4);
le16(out, 2);
le16(out, 4);
le32(out, 0); // time zone
le32(out, 0); // timestamp accuracy
le32(out, 65535); // snap length
le32(out, 270); // LINKTYPE_LORATAP
}
void appendRecord(std::vector<uint8_t>& out, uint32_t seconds, uint32_t micros, const RxInfo& rx, const uint8_t* data,
size_t len) {
uint32_t captured = static_cast<uint32_t>(kLoraTapSize + len);
le32(out, seconds);
le32(out, micros);
le32(out, captured);
le32(out, captured);
uint32_t f = rx.frequencyHz;
// The spec puts packet RSSI in quarter dB below 0 dB SNR (an SX127x formula), but Wireshark
// reads it as -139 dBm plus the byte either way, and the SX1262 already gives dBm.
uint8_t packetRssi = dbmByte(rx.rssi);
long snr = std::clamp(std::lround(rx.snr * 4), -128L, 127L);
out.insert(out.end(), {
0, 0, 0, uint8_t(kLoraTapSize), // version 0, padding, length
uint8_t(f >> 24), uint8_t(f >> 16), uint8_t(f >> 8), uint8_t(f),
uint8_t(std::lround(rx.bandwidthKHz / 125)), rx.spreadingFactor,
packetRssi, dbmByte(rx.rssi), dbmByte(rx.noiseFloor),
static_cast<uint8_t>(static_cast<int8_t>(snr)), rx.syncWord,
});
if (len) out.insert(out.end(), data, data + len);
}
} // namespace roro::lora
+33
View File
@@ -0,0 +1,33 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::lora {
// What the radio knew about one received packet.
struct RxInfo {
uint32_t frequencyHz = 0;
float bandwidthKHz = 0;
uint8_t spreadingFactor = 0;
float rssi = 0; // dBm
float snr = 0; // dB
float noiseFloor = 0; // dBm, instantaneous RSSI just before the packet, when known
uint8_t syncWord = 0;
};
// A Capture file (M3, Q97): pcap with LoRaTap v0 headers (LINKTYPE_LORATAP, 270), which Wireshark
// reads. pcap fields are little-endian, LoRaTap fields big-endian.
void appendPcapHeader(std::vector<uint8_t>& out);
void appendRecord(std::vector<uint8_t>& out, uint32_t seconds, uint32_t micros, const RxInfo& rx, const uint8_t* data,
size_t len);
// "/captures/lora/YYYYMMDD-HHMMSS.pcap" in UTC, dated like Tracks so Storage Clean-up can age it.
std::string capturePath(int64_t utcSeconds);
constexpr size_t kLoraTapSize = 15;
constexpr size_t kRecordOverhead = 16 + kLoraTapSize;
} // namespace roro::lora
+83
View File
@@ -0,0 +1,83 @@
#include "packet_view.h"
#include <cmath>
#include <cstdio>
#include "meshtastic_header.h"
#include "meshtastic_presets.h"
namespace roro::lora {
using namespace meshtastic;
std::string row(const PacketSummary& p, const std::string& time) {
char s[64];
int n = std::snprintf(s, sizeof s, "%s %ld %.1f ", time.c_str(), std::lround(p.rssi), p.snr);
std::string out(s, n);
PacketHeader h;
if (!p.crcOk) return out + "bad CRC, " + std::to_string(p.len) + " B";
if (!p.meshtastic || !parseHeader(p.data, p.len, h)) return out + std::to_string(p.len) + " B";
auto shortId = [](uint32_t node) {
if (node == kBroadcast) return std::string("all");
char id[8];
std::snprintf(id, sizeof id, "%04x", static_cast<unsigned>(node & 0xFFFF));
return std::string(id);
};
out += shortId(h.from) + ">" + shortId(h.to);
if (h.hopsAway() >= 0) out += " " + std::to_string(h.hopsAway()) + "/" + std::to_string(h.hopStart());
return out;
}
std::vector<std::string> hexDump(const uint8_t* data, size_t len) {
std::vector<std::string> lines;
for (size_t at = 0; at < len; at += 8) {
char s[48];
int n = std::snprintf(s, sizeof s, "%04x", static_cast<unsigned>(at));
std::string text;
for (size_t i = 0; i < 8; ++i) {
if (at + i < len) {
n += std::snprintf(s + n, sizeof s - n, " %02x", data[at + i]);
uint8_t b = data[at + i];
text += b >= 0x20 && b < 0x7F ? static_cast<char>(b) : '.';
} else {
n += std::snprintf(s + n, sizeof s - n, " ");
}
}
lines.push_back(std::string(s, n) + " " + text);
}
return lines;
}
std::vector<std::string> headerLines(const uint8_t* data, size_t len) {
PacketHeader h;
if (!parseHeader(data, len, h)) return {};
char s[64];
std::vector<std::string> lines;
lines.push_back("From " + nodeId(h.from) + " to " + nodeId(h.to));
std::snprintf(s, sizeof s, "Packet %08x%s%s", static_cast<unsigned>(h.id), h.wantAck() ? ", wants an ack" : "",
h.viaMqtt() ? ", via MQTT" : "");
lines.push_back(s);
if (h.hopsAway() >= 0)
std::snprintf(s, sizeof s, "Hops %d of %u, limit %u left", h.hopsAway(), h.hopStart(), h.hopLimit());
else
std::snprintf(s, sizeof s, "Hop limit %u left (old firmware)", h.hopLimit());
lines.push_back(s);
// Which preset's default Channel (named after it, with the public key) has this hash.
std::string channel;
for (size_t i = 0; i < kEu868PresetCount && channel.empty(); ++i)
if (channelHash(kEu868Presets[i].name, kDefaultKey, sizeof kDefaultKey) == h.channelHash)
channel = std::string(" (") + kEu868Presets[i].name + ", default key)";
std::snprintf(s, sizeof s, "Channel 0x%02x%s", h.channelHash, channel.c_str());
lines.push_back(s);
if (h.relayNode) {
std::snprintf(s, sizeof s, "Relayed by ..%02x", h.relayNode);
lines.push_back(s);
}
if (h.nextHop) {
std::snprintf(s, sizeof s, "Next hop ..%02x", h.nextHop);
lines.push_back(s);
}
return lines;
}
} // namespace roro::lora
+29
View File
@@ -0,0 +1,29 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::lora {
// What the LoRa Scanner shows of one packet (M3, Q96).
struct PacketSummary {
const uint8_t* data;
size_t len;
float rssi, snr;
bool crcOk;
bool meshtastic; // received on Meshtastic settings (sync word 0x2B): read its clear header
};
// One list row, at most about 36 characters: "21:45:07 -97 6.2 5678>all 1/3". Nodes by their default
// short name (the last 4 hex digits); headerLines() has the full numbers.
std::string row(const PacketSummary& p, const std::string& time);
// Eight bytes a line, with the printable ones: "0000 ff ff ff ff 78 56 34 12 ....xV4.".
std::vector<std::string> hexDump(const uint8_t* data, size_t len);
// The Meshtastic header, one field a line; empty when the packet is too short to have one.
std::vector<std::string> headerLines(const uint8_t* data, size_t len);
} // namespace roro::lora
+48
View File
@@ -0,0 +1,48 @@
#include "sweep_view.h"
#include <algorithm>
namespace roro::lora {
namespace {
constexpr int kPeakAboveFloorDb = 10;
constexpr size_t kMaxPeaks = 3;
} // namespace
SweepStats summarize(const int8_t* dbm, size_t steps, uint32_t fromHz, uint32_t stepHz) {
SweepStats s;
if (!steps) return s;
std::vector<int8_t> sorted(dbm, dbm + steps);
std::nth_element(sorted.begin(), sorted.begin() + steps / 2, sorted.end());
s.floor = sorted[steps / 2];
s.top = *std::max_element(dbm, dbm + steps);
for (size_t i = 0; i < steps; ++i) {
int v = dbm[i];
bool localMax = (i == 0 || v >= dbm[i - 1]) && (i + 1 == steps || v > dbm[i + 1]);
if (localMax && v >= s.floor + kPeakAboveFloorDb) s.peaks.push_back({fromHz + static_cast<uint32_t>(i) * stepHz, v});
}
std::stable_sort(s.peaks.begin(), s.peaks.end(), [](const SweepPeak& a, const SweepPeak& b) { return a.dbm > b.dbm; });
if (s.peaks.size() > kMaxPeaks) s.peaks.resize(kMaxPeaks);
return s;
}
uint8_t heatLevel(int dbm, int low, int high) {
if (dbm <= low) return 0;
if (dbm >= high) return 255;
return static_cast<uint8_t>((dbm - low) * 255 / (high - low) + ((dbm - low) * 255 % (high - low) ? 1 : 0));
}
uint16_t heatColor(uint8_t level) {
// Five segments of 51 steps each.
auto rgb = [](int r, int g, int b) { return static_cast<uint16_t>((r >> 3) << 11 | (g >> 2) << 5 | (b >> 3)); };
int seg = std::min(level / 51, 4), t = (level - seg * 51) * 255 / 51;
switch (seg) {
case 0: return rgb(0, 0, t); // black to blue
case 1: return rgb(0, t, 255); // blue to cyan
case 2: return rgb(0, 255, 255 - t); // cyan to green
case 3: return rgb(t, 255, 0); // green to yellow
default: return rgb(255, 255 - t, 0); // yellow to red
}
}
} // namespace roro::lora
+27
View File
@@ -0,0 +1,27 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <vector>
namespace roro::lora {
// What a Sweep pass says about the band (M3, Q98): one RSSI reading (dBm) per step.
struct SweepPeak {
uint32_t hz;
int dbm;
};
struct SweepStats {
int floor = 0; // the median: the band's noise floor, whatever a few signals do
int top = 0; // the strongest reading
std::vector<SweepPeak> peaks; // at most 3, strongest first, each a local maximum >= 10 dB above the floor
};
SweepStats summarize(const int8_t* dbm, size_t steps, uint32_t fromHz, uint32_t stepHz);
// The waterfall's colours: a reading between `low` and `high` dBm as 0..255, then RGB565 along
// black, blue, cyan, green, yellow, red.
uint8_t heatLevel(int dbm, int low, int high);
uint16_t heatColor(uint8_t level);
} // namespace roro::lora
+28
View File
@@ -0,0 +1,28 @@
#include "meshtastic_header.h"
#include <cstdio>
namespace roro::meshtastic {
static uint32_t le32(const uint8_t* p) { return p[0] | p[1] << 8 | p[2] << 16 | static_cast<uint32_t>(p[3]) << 24; }
bool parseHeader(const uint8_t* data, size_t len, PacketHeader& out) {
if (!data || len < kHeaderSize) return false;
out.to = le32(data);
out.from = le32(data + 4);
out.id = le32(data + 8);
out.flags = data[12];
out.channelHash = data[13];
out.nextHop = data[14];
out.relayNode = data[15];
return true;
}
std::string nodeId(uint32_t node) {
if (node == kBroadcast) return "all";
char s[10];
std::snprintf(s, sizeof s, "!%08x", static_cast<unsigned>(node));
return s;
}
} // namespace roro::meshtastic
+36
View File
@@ -0,0 +1,36 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
namespace roro::meshtastic {
constexpr uint32_t kBroadcast = 0xFFFFFFFF;
// The 16 bytes every Meshtastic packet starts with, sent in clear (little-endian). The payload
// after it is encrypted with the Channel's key.
struct PacketHeader {
uint32_t to = 0, from = 0, id = 0;
uint8_t flags = 0;
uint8_t channelHash = 0; // the Channel's name and key folded into a byte (see channelHash())
uint8_t nextHop = 0; // last byte of the Node meant to relay it next; 0 when flooding
uint8_t relayNode = 0; // last byte of the Node that relayed it to us
uint8_t hopLimit() const { return flags & 0x07; }
bool wantAck() const { return flags & 0x08; }
bool viaMqtt() const { return flags & 0x10; }
uint8_t hopStart() const { return flags >> 5; }
bool broadcast() const { return to == kBroadcast; }
// How many times it was relayed before we heard it; -1 when the sender didn't say (hop start 0).
int hopsAway() const { return hopStart() == 0 ? -1 : hopStart() - hopLimit(); }
};
constexpr size_t kHeaderSize = 16;
bool parseHeader(const uint8_t* data, size_t len, PacketHeader& out);
// "!12345678", as Meshtastic writes node numbers; "all" for broadcast.
std::string nodeId(uint32_t node);
} // namespace roro::meshtastic
+47
View File
@@ -0,0 +1,47 @@
#include "meshtastic_presets.h"
#include <cmath>
#include <cstring>
namespace roro::meshtastic {
const uint8_t kDefaultKey[16] = {0xd4, 0xf1, 0xbb, 0x3a, 0x20, 0x29, 0x07, 0x59,
0xf0, 0xbc, 0xff, 0xab, 0xcf, 0x4e, 0x69, 0x01};
// firmware src/mesh/MeshRadio.h (modemPresetToParams) and RadioInterface.cpp (PRESETS_EU_868).
const Preset kEu868Presets[] = {
{"LongFast", 250, 11, 5}, {"LongSlow", 125, 12, 8}, {"MediumSlow", 250, 10, 5}, {"MediumFast", 250, 9, 5},
{"ShortSlow", 250, 8, 5}, {"ShortFast", 250, 7, 5}, {"LongMod", 125, 11, 8},
};
const size_t kEu868PresetCount = sizeof kEu868Presets / sizeof kEu868Presets[0];
const Preset* findPreset(const char* name) {
for (const Preset& p : kEu868Presets)
if (std::strcmp(p.name, name) == 0) return &p;
return nullptr;
}
uint32_t djb2(const char* s) {
uint32_t h = 5381;
for (; *s; ++s) h = (h << 5) + h + static_cast<unsigned char>(*s);
return h;
}
uint8_t channelHash(const char* name, const uint8_t* key, size_t keyLen) {
uint8_t h = 0;
for (; *name; ++name) h ^= static_cast<uint8_t>(*name);
for (size_t i = 0; i < keyLen; ++i) h ^= key[i];
return h;
}
uint32_t eu868FrequencyHz(const Preset& preset, const char* channelName) {
constexpr double kStartMHz = 869.4, kEndMHz = 869.65;
double slotMHz = preset.bwKHz / 1000.0;
uint32_t slots = static_cast<uint32_t>(std::lround((kEndMHz - kStartMHz) / slotMHz));
const char* name = channelName && *channelName ? channelName : preset.name;
uint32_t slot = slots ? djb2(name) % slots : 0;
double mhz = kStartMHz + slotMHz / 2 + slot * slotMHz;
return static_cast<uint32_t>(std::lround(mhz * 1e6));
}
} // namespace roro::meshtastic
+38
View File
@@ -0,0 +1,38 @@
#pragma once
#include <cstddef>
#include <cstdint>
namespace roro::meshtastic {
// Radio settings shared by every Meshtastic preset (firmware src/mesh/RadioInterface.h).
constexpr uint8_t kSyncWord = 0x2B;
constexpr uint16_t kPreambleLength = 16;
// The default Channel key ("AQ==", expanded): public, so the default Channel is readable by anyone.
extern const uint8_t kDefaultKey[16];
// A modem preset: bandwidth, spreading factor and coding rate (4/cr). Named as Meshtastic shows them.
struct Preset {
const char* name;
float bwKHz;
uint8_t sf;
uint8_t cr;
};
// The presets Meshtastic allows in EU_868, its order, LongFast (the default) first.
extern const Preset kEu868Presets[];
extern const size_t kEu868PresetCount;
const Preset* findPreset(const char* name); // nullptr when EU_868 doesn't allow it
// djb2, as Meshtastic hashes a Channel's name to pick a frequency slot.
uint32_t djb2(const char* s);
// The byte in every packet header naming its Channel: the name's bytes XORed with the key's.
uint8_t channelHash(const char* name, const uint8_t* key, size_t keyLen);
// EU_868 is 869.4 to 869.65 MHz: the slot comes from the Channel's name (the preset's name for
// an unnamed Channel, which is the default).
uint32_t eu868FrequencyHz(const Preset& preset, const char* channelName = nullptr);
} // namespace roro::meshtastic
+97
View File
@@ -0,0 +1,97 @@
#include "ipv4.h"
#include <cstdio>
namespace roro::net {
bool parseIpv4(const std::string& text, uint32_t& out) {
uint32_t value = 0;
int parts = 0, digits = 0, part = 0;
for (char c : text) {
if (c >= '0' && c <= '9') {
if (++digits > 3) return false;
part = part * 10 + (c - '0');
if (part > 255) return false;
} else if (c == '.') {
if (digits == 0 || ++parts > 3) return false;
value = value << 8 | part;
part = digits = 0;
} else {
return false;
}
}
if (digits == 0 || parts != 3) return false;
out = value << 8 | part;
return true;
}
std::string formatIpv4(uint32_t a) {
char s[16];
std::snprintf(s, sizeof s, "%u.%u.%u.%u", static_cast<unsigned>(a >> 24), static_cast<unsigned>(a >> 16 & 255),
static_cast<unsigned>(a >> 8 & 255), static_cast<unsigned>(a & 255));
return s;
}
uint32_t maskOf(int prefix) { return prefix <= 0 ? 0 : prefix >= 32 ? 0xFFFFFFFFu : ~0u << (32 - prefix); }
std::string checkFixed(const FixedIp& f) {
if (f.prefix < 1 || f.prefix > 30) return "The prefix must be 1 to 30";
if (f.address == 0) return "0.0.0.0 isn't an address a device can have";
uint32_t mask = maskOf(f.prefix), network = f.address & mask, broadcast = network | ~mask;
if (f.address == network) return formatIpv4(f.address) + " is the network's own address";
if (f.address == broadcast) return formatIpv4(f.address) + " is the broadcast address";
if (f.gateway == 0) return "";
if (f.gateway == f.address) return "The gateway can't be this device's address";
if ((f.gateway & mask) != network)
return "The gateway " + formatIpv4(f.gateway) + " isn't in " + formatIpv4(network) + "/" + std::to_string(f.prefix);
if (f.gateway == broadcast) return "The gateway " + formatIpv4(f.gateway) + " is the broadcast address";
if (f.gateway == network) return "The gateway " + formatIpv4(f.gateway) + " is the network's own address";
return "";
}
std::string parseFixed(const std::string& text, FixedIp& out) {
size_t slash = text.find('/');
if (slash == std::string::npos) return "Write it as address/prefix, then the gateway if there is one";
size_t space = text.find(' ', slash);
std::string address = text.substr(0, slash);
std::string prefix = text.substr(slash + 1, space == std::string::npos ? std::string::npos : space - slash - 1);
std::string gateway = space == std::string::npos ? "" : text.substr(space + 1);
FixedIp f;
if (!parseIpv4(address, f.address)) return address + " isn't an IPv4 address";
int p = 0;
if (prefix.empty() || prefix.size() > 2) return "The prefix must be 1 to 30";
for (char c : prefix) {
if (c < '0' || c > '9') return "The prefix must be 1 to 30";
p = p * 10 + (c - '0');
}
f.prefix = static_cast<uint8_t>(p);
if (!gateway.empty() && !parseIpv4(gateway, f.gateway)) return gateway + " isn't an IPv4 address";
std::string why = checkFixed(f);
if (why.empty()) out = f;
return why;
}
std::string formatFixed(const FixedIp& f) {
std::string s = formatIpv4(f.address) + "/" + std::to_string(f.prefix);
if (f.gateway) s += " " + formatIpv4(f.gateway);
return s;
}
bool validHost(const std::string& text) {
if (text.empty() || text.size() > 63) return false;
uint32_t ignored;
if (parseIpv4(text, ignored)) return true;
bool allNumeric = true; // digits and dots only, but not an address: "1.2.3", "999.1.1.1"
char previous = '.';
for (char c : text) {
bool letter = (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z'), digit = c >= '0' && c <= '9';
if (!letter && !digit && c != '-' && c != '.') return false;
if (c == '.' && (previous == '.' || previous == '-')) return false; // empty label, or one ending in '-'
if (c == '-' && previous == '.') return false; // a label starting with '-'
if (letter || c == '-') allNumeric = false;
previous = c;
}
return previous != '.' && previous != '-' && !allNumeric;
}
} // namespace roro::net
+30
View File
@@ -0,0 +1,30 @@
#pragma once
#include <cstdint>
#include <string>
namespace roro::net {
// IPv4 addresses as 32-bit numbers, most significant byte first: 10.39.39.12 is 0x0A27270C.
bool parseIpv4(const std::string& text, uint32_t& out); // strict: four decimal numbers, 0 to 255
std::string formatIpv4(uint32_t address);
uint32_t maskOf(int prefix); // 24 -> 255.255.255.0
// A Saved Network's Fixed setting (S1, Q105 to Q107). gateway 0: none.
struct FixedIp {
uint32_t address = 0;
uint8_t prefix = 24;
uint32_t gateway = 0;
};
// "" when a device can use it, otherwise why not, for a human (Q111).
std::string checkFixed(const FixedIp& f);
// "address/prefix [gateway]", as typed on the console and kept in flash. parseFixed() also checks.
std::string parseFixed(const std::string& text, FixedIp& out);
std::string formatFixed(const FixedIp& f);
// An IPv4 address or a host name, as an NTP server may be (Q110).
bool validHost(const std::string& text);
} // namespace roro::net
+46
View File
@@ -0,0 +1,46 @@
#include "traffic.h"
#include <atomic>
#include <cstdio>
namespace roro::net {
namespace {
constexpr size_t kUsers = static_cast<size_t>(User::Count);
std::atomic<uint32_t> in_[kUsers], out_[kUsers];
} // namespace
const char* userName(User user) {
switch (user) {
case User::Irc: return "IRC";
case User::Gemini: return "Gemini";
case User::DebugConsole: return "Debug Console";
case User::Updates: return "Updates";
default: return "?";
}
}
void received(User user, size_t bytes) { in_[static_cast<size_t>(user)] += static_cast<uint32_t>(bytes); }
void sent(User user, size_t bytes) { out_[static_cast<size_t>(user)] += static_cast<uint32_t>(bytes); }
Traffic traffic(User user) { return {in_[static_cast<size_t>(user)], out_[static_cast<size_t>(user)]}; }
void resetTraffic() {
for (size_t i = 0; i < kUsers; i++) in_[i] = out_[i] = 0;
}
uint32_t bytesPerSecond(uint32_t before, uint32_t now, uint32_t elapsedMs) {
if (!elapsedMs) return 0;
return static_cast<uint32_t>(static_cast<uint64_t>(now - before) * 1000 / elapsedMs); // wraps with the counter
}
std::string formatTraffic(uint32_t bytes) {
char s[16];
if (bytes < 1000) std::snprintf(s, sizeof s, "%u B", static_cast<unsigned>(bytes));
else if (bytes < 10 * 1024) std::snprintf(s, sizeof s, "%.1f KB", bytes / 1024.0);
else if (bytes < 1000 * 1024) std::snprintf(s, sizeof s, "%u KB", static_cast<unsigned>(bytes / 1024));
else if (bytes < 10u * 1024 * 1024) std::snprintf(s, sizeof s, "%.1f MB", bytes / 1048576.0);
else std::snprintf(s, sizeof s, "%u MB", static_cast<unsigned>(bytes / 1048576));
return s;
}
} // namespace roro::net
+26
View File
@@ -0,0 +1,26 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
namespace roro::net {
// Bytes each network service has read and written since boot (S1, Q121), as the service sees
// them: for TLS connections that's the plain text, without the handshake or record overhead.
// Counted from the services' own tasks, read from the main loop.
enum class User : uint8_t { Irc, Gemini, DebugConsole, Updates, Count };
const char* userName(User user);
struct Traffic {
uint32_t in = 0, out = 0;
};
void received(User user, size_t bytes);
void sent(User user, size_t bytes);
Traffic traffic(User user);
void resetTraffic(); // for tests
uint32_t bytesPerSecond(uint32_t before, uint32_t now, uint32_t elapsedMs);
std::string formatTraffic(uint32_t bytes); // "999 B", "1.5 KB", "12 KB", "1.7 MB"
} // namespace roro::net
+329
View File
@@ -0,0 +1,329 @@
#include "note_text.h"
#include <algorithm>
namespace roro::notes {
namespace {
bool continuation(char c) { return (static_cast<uint8_t>(c) & 0xC0) == 0x80; }
} // namespace
NoteText::NoteText(int cols, int rows) : cols_(std::max(1, cols)), rows_(std::max(1, rows)) { text_.reserve(kMaxBytes); }
NoteText::NoteText(int cols, int rows, std::string&& text) : cols_(std::max(1, cols)), rows_(std::max(1, rows)), text_(std::move(text)) {
dropCarriageReturns();
if (text_.size() > kMaxBytes) text_.resize(kMaxBytes); // the caller checks sizes: not reached
text_.reserve(kMaxBytes);
}
void NoteText::dropCarriageReturns() {
size_t kept = 0;
for (size_t i = 0; i < text_.size(); i++)
if (!(text_[i] == '\r' && i + 1 < text_.size() && text_[i + 1] == '\n')) text_[kept++] = text_[i];
text_.resize(kept);
}
bool NoteText::setText(const std::string& text) {
size_t kept = text.size();
for (size_t i = 0; i + 1 < text.size(); i++)
if (text[i] == '\r' && text[i + 1] == '\n') kept--;
if (kept > kMaxBytes) return false;
text_.assign(text);
dropCarriageReturns();
cursor_ = top_ = 0;
goal_ = -1;
revision_++;
return true;
}
size_t NoteText::nextLine(size_t start) const {
size_t size = text_.size();
int count = 0;
size_t lastSpace = 0;
bool space = false;
for (size_t i = start; i < size; i++) {
char c = text_[i];
if (c == '\n') return i + 1;
if (continuation(c)) continue;
if (count == cols_) { // one character too many: wrap
if (c == ' ') return i + 1; // the space stays at the end of this line
if (space) return lastSpace + 1; // after the last space that fits
return i; // a word longer than the screen is cut
}
count++;
if (c == ' ') {
lastSpace = i;
space = true;
}
}
return size;
}
size_t NoteText::lineOf(size_t pos) const {
size_t size = text_.size();
pos = std::min(pos, size);
size_t a = pos; // the start of the paragraph: after the newline before `pos`
while (a > 0 && text_[a - 1] != '\n') a--;
while (a < size) {
size_t n = nextLine(a);
if (n > pos) return a;
// The end of the text is on the last line, unless that line ended with a newline: then
// it's on an empty line of its own.
if (n == size && pos == size && text_[size - 1] != '\n') return a;
a = n;
}
return a;
}
bool NoteText::hasLineAfter(size_t start) const {
size_t n = nextLine(start), size = text_.size();
if (n < size) return true;
return start < size && lineOf(size) != start; // the empty line after a final newline
}
size_t NoteText::lastSpot(size_t start) const {
size_t n = nextLine(start), size = text_.size();
if (n == start) return start; // the empty line at the end
if (n == size && lineOf(size) == start) return size;
size_t p = n - 1; // before the newline, the space or the last character the line ends with
while (p > start && continuation(text_[p])) p--;
return p;
}
int NoteText::columnOf(size_t start, size_t pos) const {
int col = 0;
for (size_t i = start; i < pos && i < text_.size(); i++)
if (!continuation(text_[i])) col++;
return col;
}
size_t NoteText::atColumn(size_t start, int col) const {
size_t last = lastSpot(start), p = start;
while (p < last && col > 0) {
p++;
while (p < last && continuation(text_[p])) p++;
col--;
}
return p;
}
void NoteText::moved(bool keepGoal) {
if (!keepGoal) goal_ = -1;
}
bool NoteText::insertText(const std::string& s) {
if (text_.size() + s.size() > kMaxBytes) return false;
text_.insert(cursor_, s);
cursor_ += s.size();
revision_++;
moved();
return true;
}
bool NoteText::insert(uint32_t cp) {
std::string s;
if (cp < 0x80) s += static_cast<char>(cp);
else if (cp < 0x800) {
s += static_cast<char>(0xC0 | (cp >> 6));
s += static_cast<char>(0x80 | (cp & 0x3F));
} else if (cp < 0x10000) {
s += static_cast<char>(0xE0 | (cp >> 12));
s += static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
s += static_cast<char>(0x80 | (cp & 0x3F));
} else {
s += static_cast<char>(0xF0 | (cp >> 18));
s += static_cast<char>(0x80 | ((cp >> 12) & 0x3F));
s += static_cast<char>(0x80 | ((cp >> 6) & 0x3F));
s += static_cast<char>(0x80 | (cp & 0x3F));
}
return insertText(s);
}
void NoteText::backspace() {
if (cursor_ == 0) return;
size_t from = cursor_ - 1;
while (from > 0 && continuation(text_[from])) from--;
text_.erase(from, cursor_ - from);
cursor_ = from;
revision_++;
moved();
}
void NoteText::left() {
if (cursor_ == 0) return;
cursor_--;
while (cursor_ > 0 && continuation(text_[cursor_])) cursor_--;
moved();
}
void NoteText::right() {
if (cursor_ >= text_.size()) return;
cursor_++;
while (cursor_ < text_.size() && continuation(text_[cursor_])) cursor_++;
moved();
}
void NoteText::up() {
size_t line = lineOf(cursor_);
if (goal_ < 0) goal_ = columnOf(line, cursor_);
if (line == 0) return;
cursor_ = atColumn(lineOf(line - 1), goal_);
moved(true);
}
void NoteText::down() {
size_t line = lineOf(cursor_);
if (goal_ < 0) goal_ = columnOf(line, cursor_);
if (!hasLineAfter(line)) return;
size_t next = nextLine(line);
cursor_ = next >= text_.size() ? text_.size() : atColumn(next, goal_);
moved(true);
}
void NoteText::pageUp() {
for (int i = 1; i < rows_; i++) up();
}
void NoteText::pageDown() {
for (int i = 1; i < rows_; i++) down();
}
void NoteText::lineStart() {
cursor_ = lineOf(cursor_);
moved();
}
void NoteText::lineEnd() {
cursor_ = lastSpot(lineOf(cursor_));
moved();
}
void NoteText::toStart() {
cursor_ = 0;
moved();
}
void NoteText::toEnd() {
cursor_ = text_.size();
moved();
}
void NoteText::follow() {
size_t line = lineOf(cursor_);
top_ = lineOf(std::min(top_, text_.size())); // an edit above may have moved where lines start
if (line < top_) {
top_ = line;
return;
}
size_t a = top_;
for (int i = 0; i < rows_; i++) {
if (a == line) return; // on screen
if (!hasLineAfter(a)) return;
a = nextLine(a);
}
// Below the screen: the cursor's line becomes the last row.
top_ = line;
for (int i = 1; i < rows_ && top_ > 0; i++) top_ = lineOf(top_ - 1);
}
std::vector<std::string> NoteText::rows() {
follow();
std::vector<std::string> out;
size_t a = top_, size = text_.size();
for (int i = 0; i < rows_; i++) {
size_t n = nextLine(a);
std::string row = text_.substr(a, n - a);
if (!row.empty() && row.back() == '\n') row.pop_back();
for (char& c : row)
if (c == '\t') c = ' ';
out.push_back(std::move(row));
if (!hasLineAfter(a)) break;
a = n >= size ? size : n;
}
return out;
}
int NoteText::cursorRow() {
follow();
size_t line = lineOf(cursor_), a = top_;
for (int i = 0; i < rows_; i++) {
if (a == line) return i;
a = nextLine(a);
}
return rows_ - 1;
}
int NoteText::cursorCol() { return columnOf(lineOf(cursor_), cursor_); }
// At most a screen's worth of it: a note that is one line of 16 KB must not be copied whole.
std::string NoteText::firstLine() const { return text_.substr(0, std::min<size_t>(text_.find('\n'), 160)); }
namespace {
// U+00C0 to U+00FF as the plain letters a file name gets; 0: left out.
const char kPlain[64] = {
'a', 'a', 'a', 'a', 'a', 'a', 0, 'c', 'e', 'e', 'e', 'e', 'i', 'i', 'i', 'i', // À..Ï
0, 'n', 'o', 'o', 'o', 'o', 'o', 0, 'o', 'u', 'u', 'u', 'u', 'y', 0, 's', // Ð..ß
'a', 'a', 'a', 'a', 'a', 'a', 0, 'c', 'e', 'e', 'e', 'e', 'i', 'i', 'i', 'i', // à..ï
0, 'n', 'o', 'o', 'o', 'o', 'o', 0, 'o', 'u', 'u', 'u', 'u', 'y', 0, 'y'}; // ð..ÿ
// Drops a character the end of the string cuts in two.
void dropPartial(std::string& s) {
size_t k = s.size();
while (k > 0 && continuation(s[k - 1]) && s.size() - k < 3) k--;
if (k == 0) return;
uint8_t lead = static_cast<uint8_t>(s[k - 1]);
size_t want = lead >= 0xF0 ? 4 : lead >= 0xE0 ? 3 : lead >= 0xC0 ? 2 : 1;
if (s.size() - (k - 1) < want) s.resize(k - 1);
}
} // namespace
std::string nameFromFirstLine(const std::string& firstLine, const std::string& stamp) {
std::string out;
bool dash = false;
for (size_t i = 0; i < firstLine.size() && out.size() < 32; i++) {
uint8_t c = static_cast<uint8_t>(firstLine[i]);
char letter = 0;
if (c < 0x80) {
if (c >= 'A' && c <= 'Z') letter = static_cast<char>(c + 32);
else if ((c >= 'a' && c <= 'z') || (c >= '0' && c <= '9')) letter = static_cast<char>(c);
} else if (c == 0xC3 && i + 1 < firstLine.size()) { // U+00C0..U+00FF
letter = kPlain[static_cast<uint8_t>(firstLine[++i]) & 0x3F];
} else {
while (i + 1 < firstLine.size() && continuation(firstLine[i + 1])) i++; // anything else is left out
}
if (letter) {
if (dash && !out.empty()) out += '-';
dash = false;
out += letter;
} else {
dash = true;
}
}
return out.empty() ? "note-" + stamp : out;
}
std::string titleFrom(const std::string& head, size_t maxChars) {
for (size_t at = 0; at < head.size();) {
size_t end = head.find('\n', at);
bool cut = end == std::string::npos; // the line goes on past what was read
if (cut) end = head.size();
std::string line = head.substr(at, end - at);
if (cut) dropPartial(line);
while (!line.empty() && (line.back() == '\r' || line.back() == ' ' || line.back() == '\t')) line.pop_back();
size_t first = line.find_first_not_of(" \t");
if (first != std::string::npos) {
line.erase(0, first);
size_t bytes = 0;
for (size_t chars = 0; bytes < line.size() && chars < maxChars; chars++) {
bytes++;
while (bytes < line.size() && continuation(line[bytes])) bytes++;
}
line.resize(bytes);
return line;
}
at = end + 1;
}
return "";
}
} // namespace roro::notes
+81
View File
@@ -0,0 +1,81 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
namespace roro::notes {
// The text of a note while it's edited (F1, Q144, Q145): UTF-8 held whole in memory, a cursor, and
// the part of it on screen. Lines wrap at spaces, `cols` characters wide; a line owns the space or
// the newline it ends with, so every byte of the text belongs to exactly one line. No index of
// lines is kept (a note of newlines alone would need twice its size): where a line starts is
// worked out from the start of its paragraph, which is never far.
class NoteText {
public:
static constexpr size_t kMaxBytes = 16 * 1024;
// Room for a full note is reserved once, so typing never has to find a bigger block of memory:
// on the device a failed allocation is the end. The second form takes over a string the
// caller filled (and reserved): a note is never in memory twice.
NoteText(int cols, int rows);
NoteText(int cols, int rows, std::string&& text);
// Copied into the buffer already held. CRLF becomes LF (Q148). False, and nothing changes, if
// it's over kMaxBytes.
bool setText(const std::string& text);
const std::string& text() const { return text_; }
size_t cursor() const { return cursor_; }
uint32_t revision() const { return revision_; } // changes with every edit: is it saved?
bool insert(uint32_t codePoint); // false: the note is full
bool insertText(const std::string& s); // all of it or nothing
void backspace();
void left();
void right();
void up();
void down();
void pageUp();
void pageDown();
void lineStart();
void lineEnd();
void toStart();
void toEnd();
// The screen, kept around the cursor: its rows (tabs as spaces, the ending newline left out),
// and where the cursor is on it, in rows and characters.
std::vector<std::string> rows();
int cursorRow();
int cursorCol();
int percent() const { return text_.empty() ? 0 : static_cast<int>(top_ * 100 / text_.size()); }
std::string firstLine() const; // without its newline, for the title and the file's name
private:
size_t nextLine(size_t start) const; // where the line after the one at `start` starts
size_t lineOf(size_t pos) const; // the start of the line `pos` is on
size_t lastSpot(size_t start) const; // the last place the cursor can be on that line
size_t atColumn(size_t start, int col) const;
int columnOf(size_t start, size_t pos) const;
bool hasLineAfter(size_t start) const;
void moved(bool keepGoal = false);
void follow(); // scrolls so the cursor is on screen
void dropCarriageReturns();
int cols_, rows_;
std::string text_;
size_t cursor_ = 0, top_ = 0;
int goal_ = -1; // the column Up and Down aim for, across short lines
uint32_t revision_ = 0;
};
// The file a new note is saved as (Q142): from its first line, "Shopping list!" -> "shopping-list",
// or "note-<stamp>" when that gives nothing. No extension, no folder.
std::string nameFromFirstLine(const std::string& firstLine, const std::string& stamp);
// A row's title in the Notes list, from the first bytes of a file: its first line that isn't
// blank, cut to `maxChars`; "" if there's none.
std::string titleFrom(const std::string& head, size_t maxChars);
} // namespace roro::notes
+119
View File
@@ -0,0 +1,119 @@
#include "file_receiver.h"
#include <algorithm>
#include <cstdlib>
#include <cstring>
namespace roro {
namespace {
int hexDigit(char c) {
if (c >= '0' && c <= '9') return c - '0';
if (c >= 'a' && c <= 'f') return c - 'a' + 10;
if (c >= 'A' && c <= 'F') return c - 'A' + 10;
return -1;
}
// Splits on spaces (no iostreams: they cost about 200 KB of flash on the device).
std::vector<std::string> words(const std::string& s) {
std::vector<std::string> out;
size_t i = 0;
while (i < s.size()) {
if (s[i] == ' ') {
i++;
continue;
}
size_t end = s.find(' ', i);
if (end == std::string::npos) end = s.size();
out.push_back(s.substr(i, end - i));
i = end;
}
return out;
}
} // namespace
std::string FileReceiver::begin(const std::string& args, uint32_t nowMs) {
reset();
std::vector<std::string> w = words(args);
if (w.size() != 3) return "usage: sd put <path> <size> <sha256>";
const std::string &path = w[0], &size = w[1], &sha = w[2];
if (path.empty() || path[0] != '/' || path.size() > 128 || path.find("..") != std::string::npos)
return "the path must be absolute, without ..";
if (size.empty() || size.size() > 9 || size.find_first_not_of("0123456789") != std::string::npos)
return "bad size";
uint32_t bytes = static_cast<uint32_t>(std::strtoul(size.c_str(), nullptr, 10));
if (bytes == 0 || bytes > kMaxBytes) return "bad size";
if (sha.size() != 64) return "bad sha256";
for (size_t i = 0; i < 32; i++) {
int hi = hexDigit(sha[2 * i]), lo = hexDigit(sha[2 * i + 1]);
if (hi < 0 || lo < 0) return "bad sha256";
expected_[i] = static_cast<uint8_t>(hi << 4 | lo);
}
path_ = path;
size_ = bytes;
lastActivityMs_ = nowMs;
chunk_.reserve(kChunk);
state_ = State::Receiving;
return "";
}
size_t FileReceiver::wanted() const {
if (state_ != State::Receiving) return 0;
return std::min<size_t>(kChunk, size_ - received_) - chunk_.size();
}
size_t FileReceiver::feed(const uint8_t* data, size_t len, uint32_t nowMs) {
if (state_ != State::Receiving || len == 0) return 0;
size_t take = std::min(len, wanted());
chunk_.insert(chunk_.end(), data, data + take);
sha_.update(data, take);
lastActivityMs_ = nowMs;
if (wanted() > 0) return take;
if (received_ + chunk_.size() == size_) {
// The last chunk: refuse it before writing if the file arrived damaged.
uint8_t got[32];
sha_.finish(got);
if (std::memcmp(got, expected_, sizeof got) != 0) {
fail("checksum mismatch");
return take;
}
}
state_ = State::Writing;
return take;
}
void FileReceiver::chunkWritten(bool ok, uint32_t nowMs) {
if (state_ != State::Writing) return;
if (!ok) return fail("write failed");
received_ += static_cast<uint32_t>(chunk_.size());
chunk_.clear();
lastActivityMs_ = nowMs;
state_ = received_ == size_ ? State::Finishing : State::Receiving;
}
void FileReceiver::cardChecked(const uint8_t digest[32]) {
if (state_ != State::Finishing) return;
if (std::memcmp(digest, expected_, sizeof expected_) != 0) fail("the copy on the card differs");
}
void FileReceiver::finished(bool ok) {
if (state_ != State::Finishing) return;
if (!ok) return fail("rename failed");
state_ = State::Done;
}
void FileReceiver::tick(uint32_t nowMs) {
if (state_ != State::Receiving && state_ != State::Writing && state_ != State::Finishing) return;
if (nowMs - lastActivityMs_ >= kTimeoutMs) fail(state_ == State::Receiving ? "timed out" : "card not writable");
}
void FileReceiver::fail(const char* why) {
error_ = why;
chunk_.clear();
state_ = State::Failed;
}
} // namespace roro
+69
View File
@@ -0,0 +1,69 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include <vector>
#include "sha256.h"
namespace roro {
// One file sent over the USB serial console (scripts/sd_put.py), to put an Update File on the SD
// card without taking the card out. The sender writes `sd put <path> <size> <sha256>`, then the raw
// bytes, one chunk at a time, and waits for each chunk to be written before sending the next: the
// serial driver drops bytes once its receive buffer is full. The file lands as `<path>.part` and is
// renamed to `<path>` only once every byte has arrived and the checksum matches.
class FileReceiver {
public:
static constexpr size_t kChunk = 1024; // must stay below the serial receive buffer
static constexpr uint32_t kTimeoutMs = 5000; // silence, or a card job that never completes
static constexpr uint32_t kMaxBytes = 8u << 20; // larger than any app partition
enum class State {
Idle,
Receiving, // waiting for bytes of the current chunk
Writing, // chunk() is complete: write it to partPath(), then call chunkWritten()
Finishing, // everything written and checked: rename partPath() to path(), then finished()
Done,
Failed, // error() says why; partPath() should be removed
};
// Parses "<path> <size> <sha256 hex>". Returns "" when the transfer starts, or what's wrong.
std::string begin(const std::string& args, uint32_t nowMs);
// Takes bytes for the current chunk; returns how many were used (none while a chunk waits).
size_t feed(const uint8_t* data, size_t len, uint32_t nowMs);
void chunkWritten(bool ok, uint32_t nowMs);
// While Finishing: the SHA-256 of the file as read back from the card. The checksum on the
// received bytes doesn't prove the card kept them (a failed write can lose buffered data).
void cardChecked(const uint8_t digest[32]);
void finished(bool ok);
void tick(uint32_t nowMs);
void reset() { *this = FileReceiver(); }
State state() const { return state_; }
bool active() const { return state_ != State::Idle; }
// Bytes still missing from the current chunk: read no more than this from the serial port.
size_t wanted() const;
const std::vector<uint8_t>& chunk() const { return chunk_; }
const std::string& path() const { return path_; }
std::string partPath() const { return path_ + ".part"; }
uint32_t size() const { return size_; }
uint32_t received() const { return received_; }
const std::string& error() const { return error_; }
private:
void fail(const char* why);
State state_ = State::Idle;
std::string path_;
uint32_t size_ = 0;
uint32_t received_ = 0; // bytes in chunks already written
uint8_t expected_[32] = {};
Sha256 sha_;
std::vector<uint8_t> chunk_;
uint32_t lastActivityMs_ = 0;
std::string error_;
};
} // namespace roro
+28
View File
@@ -0,0 +1,28 @@
#pragma once
#include <cstdint>
namespace roro {
// Decides when new firmware on Probation (see CONTEXT.md) has proven healthy, or has failed in a
// way that would leave no means to push a fix (Wi-Fi configured but never connecting).
class Probation {
public:
enum class Verdict { Wait, Confirm, RollBack };
static constexpr uint32_t kHealthyAfterMs = 30000;
static constexpr uint32_t kWifiDeadlineMs = 180000;
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
// boots of this image on Probation; a second start means the first one died before confirming.
// (A second line behind the bootloader's own rollback, which aborts an image still pending.)
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
if (wifiConfigured && !wifiConnected && uptimeMs >= kWifiDeadlineMs) return Verdict::RollBack;
if (uptimeMs < kHealthyAfterMs || !firstFrameDrawn) return Verdict::Wait;
if (wifiConfigured && !wifiConnected) return Verdict::Wait;
return Verdict::Confirm;
}
};
} // namespace roro
+21
View File
@@ -0,0 +1,21 @@
#pragma once
#include <cstdint>
namespace roro {
// Safe Mode (CONTEXT.md): after kCrashLimit starts in a row that ended in a crash, the firmware
// starts only what it takes to be fixed over the air (Wi-Fi, Firmware Updates, the Debug Console).
// Rollback covers new firmware; this covers firmware that was confirmed and crashes anyway.
struct SafeMode {
static constexpr int kCrashLimit = 3;
static constexpr uint32_t kStableAfterMs = 60000; // then the count starts over
// Called first thing at boot with the count so far; returns the new count.
static int countAtBoot(bool lastStartWasCrash, int crashesBefore) {
return lastStartWasCrash ? crashesBefore + 1 : 0;
}
static bool active(int crashes) { return crashes >= kCrashLimit; }
};
} // namespace roro
+85
View File
@@ -0,0 +1,85 @@
#include "sha256.h"
#include <cstring>
namespace roro {
namespace {
const uint32_t K[64] = {
0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2};
inline uint32_t rotr(uint32_t x, int n) { return (x >> n) | (x << (32 - n)); }
} // namespace
Sha256::Sha256() {
const uint32_t init[8] = {0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a,
0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19};
std::memcpy(h_, init, sizeof(h_));
}
void Sha256::block(const uint8_t* p) {
uint32_t w[64];
for (int i = 0; i < 16; i++)
w[i] = (uint32_t(p[4 * i]) << 24) | (uint32_t(p[4 * i + 1]) << 16) | (uint32_t(p[4 * i + 2]) << 8) | p[4 * i + 3];
for (int i = 16; i < 64; i++) {
uint32_t s0 = rotr(w[i - 15], 7) ^ rotr(w[i - 15], 18) ^ (w[i - 15] >> 3);
uint32_t s1 = rotr(w[i - 2], 17) ^ rotr(w[i - 2], 19) ^ (w[i - 2] >> 10);
w[i] = w[i - 16] + s0 + w[i - 7] + s1;
}
uint32_t a = h_[0], b = h_[1], c = h_[2], d = h_[3], e = h_[4], f = h_[5], g = h_[6], h = h_[7];
for (int i = 0; i < 64; i++) {
uint32_t t1 = h + (rotr(e, 6) ^ rotr(e, 11) ^ rotr(e, 25)) + ((e & f) ^ (~e & g)) + K[i] + w[i];
uint32_t t2 = (rotr(a, 2) ^ rotr(a, 13) ^ rotr(a, 22)) + ((a & b) ^ (a & c) ^ (b & c));
h = g;
g = f;
f = e;
e = d + t1;
d = c;
c = b;
b = a;
a = t1 + t2;
}
h_[0] += a; h_[1] += b; h_[2] += c; h_[3] += d;
h_[4] += e; h_[5] += f; h_[6] += g; h_[7] += h;
}
void Sha256::update(const uint8_t* data, size_t len) {
bits_ += static_cast<uint64_t>(len) * 8;
while (len > 0) {
size_t take = 64 - used_ < len ? 64 - used_ : len;
std::memcpy(buf_ + used_, data, take);
used_ += take;
data += take;
len -= take;
if (used_ == 64) {
block(buf_);
used_ = 0;
}
}
}
void Sha256::finish(uint8_t out[32]) {
uint64_t bits = bits_;
uint8_t pad = 0x80;
update(&pad, 1);
uint8_t zero = 0;
while (used_ != 56) update(&zero, 1);
uint8_t len[8];
for (int i = 0; i < 8; i++) len[i] = static_cast<uint8_t>(bits >> (56 - 8 * i));
update(len, 8);
for (int i = 0; i < 8; i++) {
out[4 * i] = h_[i] >> 24;
out[4 * i + 1] = h_[i] >> 16;
out[4 * i + 2] = h_[i] >> 8;
out[4 * i + 3] = h_[i];
}
}
} // namespace roro
+30
View File
@@ -0,0 +1,30 @@
#pragma once
#include <cstddef>
#include <cstdint>
namespace roro {
// Plain SHA-256 (FIPS 180-4), streaming. Small and dependency-free, so the same code runs in the
// PC tests and on the device.
class Sha256 {
public:
Sha256();
void update(const uint8_t* data, size_t len);
void finish(uint8_t out[32]);
static void hash(const uint8_t* data, size_t len, uint8_t out[32]) {
Sha256 s;
s.update(data, len);
s.finish(out);
}
private:
void block(const uint8_t* p);
uint32_t h_[8];
uint8_t buf_[64];
size_t used_ = 0;
uint64_t bits_ = 0;
};
} // namespace roro
+87
View File
@@ -0,0 +1,87 @@
#include "update_parser.h"
#include <cstring>
#include "version_compare.h"
namespace roro {
namespace {
uint16_t u16(const uint8_t* p) { return p[0] | (p[1] << 8); }
uint32_t u32(const uint8_t* p) { return p[0] | (p[1] << 8) | (p[2] << 16) | (uint32_t(p[3]) << 24); }
} // namespace
void UpdateParser::fail(const std::string& why) {
if (state_ == State::Image) sink_.abort();
state_ = State::Failed;
error_ = why;
}
void UpdateParser::parseHeader() {
const uint8_t* h = header_;
if (std::memcmp(h, update::kMagic, 8) != 0) return fail("not an update file");
if (u16(h + 8) != update::kFormat || u16(h + 10) != update::kHeaderSize) return fail("unsupported update format");
imageSize_ = u32(h + 12);
if (imageSize_ == 0 || imageSize_ > maxImage_) return fail("image doesn't fit the update slot");
std::memcpy(expectedHash_, h + 16, 32);
version_.assign(reinterpret_cast<const char*>(h + 48), strnlen(reinterpret_cast<const char*>(h + 48), 32));
size_t sigLen = u16(h + 80);
if (sigLen == 0 || sigLen > update::kMaxSignature) return fail("missing signature");
uint8_t digest[32];
Sha256::hash(h, update::kSignedBytes, digest);
if (!verifier_.verify(digest, h + 82, sigLen)) return fail("bad signature (wrong key)");
downgrade_ = versionOlder(version_, installed_);
if (!sink_.begin(imageSize_)) return fail("could not prepare the update slot");
state_ = State::Image;
}
void UpdateParser::feed(const uint8_t* data, size_t len) {
while (len > 0 && (state_ == State::Header || state_ == State::Image)) {
if (state_ == State::Header) {
size_t take = std::min(len, update::kHeaderSize - headerUsed_);
std::memcpy(header_ + headerUsed_, data, take);
headerUsed_ += take;
data += take;
len -= take;
if (headerUsed_ == update::kHeaderSize) parseHeader();
} else {
size_t take = std::min(len, imageSize_ - received_);
if (take == 0) return fail("data after the end of the image");
hash_.update(data, take);
if (!sink_.write(data, take)) return fail("writing the update failed");
received_ += take;
data += take;
len -= take;
}
}
if (len > 0 && state_ == State::Image) fail("data after the end of the image");
}
bool UpdateParser::end() {
if (state_ == State::Done) return true;
if (state_ != State::Image) {
if (state_ == State::Header) fail("update file too short");
return false;
}
if (received_ != imageSize_) {
fail("update file too short");
return false;
}
uint8_t got[32];
hash_.finish(got);
if (std::memcmp(got, expectedHash_, 32) != 0) {
fail("image corrupted (hash mismatch)");
return false;
}
if (!sink_.finish()) {
state_ = State::Failed;
error_ = "could not switch to the new image";
return false;
}
state_ = State::Done;
return true;
}
} // namespace roro
+82
View File
@@ -0,0 +1,82 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <string>
#include "sha256.h"
namespace roro {
// The Update File (see CONTEXT.md): a 160-byte header, then the firmware image. All integers are
// little-endian.
// 0 magic "RORO-OTA" 8 u16 format (1) 10 u16 header size (160) 12 u32 image size
// 16 image SHA-256[32] 48 version, NUL-padded [32]
// 80 u16 signature length 82 signature (DER, up to 72 bytes) 154 reserved
// The signature covers SHA-256 of bytes 0..79, which include the image's hash, so a bad signature
// is caught before anything is written, and a bad image when its hash is checked at the end.
namespace update {
constexpr char kMagic[] = "RORO-OTA";
constexpr uint16_t kFormat = 1;
constexpr size_t kHeaderSize = 160;
constexpr size_t kSignedBytes = 80;
constexpr size_t kMaxSignature = 72;
} // namespace update
class SignatureVerifier {
public:
virtual ~SignatureVerifier() = default;
virtual bool verify(const uint8_t digest[32], const uint8_t* signature, size_t len) = 0;
};
// Where the image goes (the inactive app slot on the device).
class UpdateSink {
public:
virtual ~UpdateSink() = default;
virtual bool begin(size_t imageSize) = 0;
virtual bool write(const uint8_t* data, size_t len) = 0;
virtual bool finish() = 0; // make it the image to boot next
virtual void abort() = 0;
};
// Streams an Update File into a sink: checks the header and signature first, then hashes the image
// as it passes through, and only finishes the sink if everything matches.
class UpdateParser {
public:
enum class State { Header, Image, Done, Failed };
UpdateParser(SignatureVerifier& verifier, UpdateSink& sink, size_t maxImageSize, std::string installedVersion)
: verifier_(verifier), sink_(sink), maxImage_(maxImageSize), installed_(std::move(installedVersion)) {}
void feed(const uint8_t* data, size_t len);
bool end(); // no more data: true if the update was installed
// The whole image the header announced has arrived (the sender need not close the connection).
bool complete() const { return state_ == State::Image && received_ == imageSize_; }
State state() const { return state_; }
const std::string& error() const { return error_; }
const std::string& version() const { return version_; }
bool isDowngrade() const { return downgrade_; }
int percent() const { return imageSize_ ? static_cast<int>(received_ * 100 / imageSize_) : 0; }
private:
void parseHeader();
void fail(const std::string& why);
SignatureVerifier& verifier_;
UpdateSink& sink_;
size_t maxImage_;
std::string installed_;
State state_ = State::Header;
uint8_t header_[update::kHeaderSize];
size_t headerUsed_ = 0;
uint8_t expectedHash_[32];
size_t imageSize_ = 0;
size_t received_ = 0;
Sha256 hash_;
std::string version_, error_;
bool downgrade_ = false;
};
} // namespace roro
+33
View File
@@ -0,0 +1,33 @@
#pragma once
#include <cstdlib>
#include <string>
namespace roro {
// True if `a` is an older release than `b`, comparing "vMAJOR.MINOR.PATCH" and ignoring any
// git-describe suffix ("-3-gabc1234-dirty"). Anything that doesn't parse is never called older.
inline bool parseVersion(const std::string& s, int out[3]) {
size_t pos = s.size() > 0 && s[0] == 'v' ? 1 : 0;
for (int i = 0; i < 3; i++) {
if (pos >= s.size() || s[pos] < '0' || s[pos] > '9') return false;
char* end;
out[i] = static_cast<int>(std::strtol(s.c_str() + pos, &end, 10));
pos = end - s.c_str();
if (i < 2) {
if (pos >= s.size() || s[pos] != '.') return false;
pos++;
}
}
return true;
}
inline bool versionOlder(const std::string& a, const std::string& b) {
int x[3], y[3];
if (!parseVersion(a, x) || !parseVersion(b, y)) return false;
for (int i = 0; i < 3; i++)
if (x[i] != y[i]) return x[i] < y[i];
return false;
}
} // namespace roro
+4 -1
View File
@@ -10,7 +10,10 @@ bool PowerPolicy::activity(uint32_t nowMs) {
}
ScreenState PowerPolicy::update(uint32_t nowMs) {
uint32_t idle = nowMs - lastActivityMs_;
// Activity stamped from a clock read after this pass's nowMs (the Debug Console's `key`) is in
// the future, not 49 days ago: unsigned, the screen went off for a tick and ate the next key.
int32_t since = static_cast<int32_t>(nowMs - lastActivityMs_);
uint32_t idle = since < 0 ? 0 : static_cast<uint32_t>(since);
state_ = idle >= offMs_ ? ScreenState::Off : idle >= dimMs_ ? ScreenState::Dimmed : ScreenState::On;
if (notifying_) {
if (static_cast<int32_t>(nowMs - notifyUntilMs_) >= 0)
+16
View File
@@ -1,5 +1,7 @@
#include "settings.h"
#include "ipv4.h"
namespace roro {
namespace {
@@ -29,6 +31,15 @@ const Definition kDefinitions[] = {
{"sound", Kind::Bool, 1, nullptr, 0, 1},
{"probe_mac_raw", Kind::Bool, 1, nullptr, 0, 1},
{"wifi_on", Kind::Bool, 1, nullptr, 0, 1},
{"gnss_on", Kind::Bool, 1, nullptr, 0, 1},
{"coord_dms", Kind::Bool, 0, nullptr, 0, 1},
{"lora_preset", Kind::Int, 0, nullptr, 0, 6}, // LongFast first
{"dns1", Kind::String, 0, "9.9.9.9", 7, 15}, // Quad9
{"dns2", Kind::String, 0, "1.1.1.1", 0, 15}, // Cloudflare
{"dns_always", Kind::Bool, 0, nullptr, 0, 1},
{"ntp1", Kind::String, 0, "pool.ntp.org", 1, 63},
{"ntp2", Kind::String, 0, "time.cloudflare.com", 0, 63},
{"gnss_quiet", Kind::Bool, 0, nullptr, 0, 1}, // off: GNSS stays on, as decided in M2 (Q58)
};
static_assert(sizeof(kDefinitions) / sizeof(kDefinitions[0]) == static_cast<size_t>(Setting::Count),
"every Setting needs a definition");
@@ -81,6 +92,11 @@ bool Settings::validString(Setting s, const std::string& value) const {
if (value == region) return true;
return false;
}
uint32_t address;
if (s == Setting::Dns1) return net::parseIpv4(value, address);
if (s == Setting::Dns2) return value.empty() || net::parseIpv4(value, address);
if (s == Setting::Ntp1) return net::validHost(value);
if (s == Setting::Ntp2) return value.empty() || net::validHost(value);
return true;
}
+9
View File
@@ -21,6 +21,15 @@ enum class Setting : uint8_t {
Sound, // bool
ProbeMacRaw, // bool: probe-request Logs keep raw MAC addresses
WifiEnabled, // bool: the Wi-Fi Service stays Connected when a Saved Network is in range
GnssEnabled, // bool: the GNSS Service reads the receiver (M2, Q58)
CoordinatesDms, // bool: show degrees, minutes and seconds instead of decimal degrees (Q64)
LoraPreset, // int: the LoRa Scanner's Meshtastic preset, an index into the EU868 list (M3, Q95)
Dns1, // string: the first DNS server, an IPv4 address (S1, Q108, Q109)
Dns2, // string: the second, or empty
DnsAlways, // bool: use them on Automatic (DHCP) networks too, instead of DHCP's
Ntp1, // string: the first NTP server, a host name or an IPv4 address (S1, Q110)
Ntp2, // string: the second, or empty
GnssQuietForLora, // bool: put the GNSS receiver in standby while the LoRa radio listens (issue #20)
Count
};
+1 -1
View File
@@ -24,7 +24,7 @@ void StorageMonitor::update(bool present, uint64_t totalBytes, uint64_t usedByte
if (next.present && next.level >= 80 && !warned_) {
warned_ = true;
bus_.publish(Event::withText(EventType::Notification, "SD card over 80% full",
bus_.publish(Event::withText(EventType::Notification, "SD card over 80% full: see Storage",
static_cast<int32_t>(NotificationLevel::Warning)));
}
}
+2
View File
@@ -20,6 +20,8 @@ inline const CleanupCategory kCleanupCategories[] = {
{"IRC logs", "/irc"},
{"Wi-Fi scan logs", "/wifi/scans"},
{"Wi-Fi captures", "/captures/wifi"},
{"LoRa captures", "/captures/lora"},
{"GNSS tracks", "/gnss/tracks"},
};
enum class CleanupAge { OneMonth, ThreeMonths, SixMonths, OneYear, Everything };
+53
View File
@@ -0,0 +1,53 @@
#include "sd_card_id.h"
#include <cstdio>
namespace roro {
namespace {
char printable(uint8_t b) { return b >= 0x20 && b < 0x7F ? static_cast<char>(b) : '?'; }
} // namespace
SdCardId parseSdCid(const uint8_t cid[16]) {
SdCardId id;
id.manufacturer = cid[0];
for (int i = 0; i < 2; ++i) id.oem[i] = printable(cid[1 + i]);
for (int i = 0; i < 5; ++i) id.product[i] = printable(cid[3 + i]);
id.revisionMajor = cid[8] >> 4;
id.revisionMinor = cid[8] & 0x0F;
id.serial = static_cast<uint32_t>(cid[9]) << 24 | cid[10] << 16 | cid[11] << 8 | cid[12];
// 4 reserved bits, 8 bits of year since 2000, 4 bits of month.
id.year = 2000 + (((cid[13] & 0x0F) << 4) | (cid[14] >> 4));
id.month = cid[14] & 0x0F;
return id;
}
const char* sdManufacturerName(uint8_t id) {
switch (id) {
case 0x01: return "Panasonic";
case 0x02: return "Toshiba/Kioxia";
case 0x03: return "SanDisk";
case 0x1B: return "Samsung";
case 0x1D: return "ADATA";
case 0x27: return "Phison";
case 0x28: return "Lexar";
case 0x31: return "Silicon Power";
case 0x41: return "Kingston";
case 0x74: return "Transcend";
case 0x76: return "Patriot";
case 0x82: return "Sony";
case 0x9C: return "Angelbird/Hoodman";
case 0xAD: return "Longsys/Lexar";
default: return "unknown";
}
}
std::string sdCardSummary(const SdCardId& id) {
char s[112];
std::snprintf(s, sizeof s, "%s (0x%02X) \"%s\" \"%s\" rev %u.%u, serial %08x, made %04d-%02d",
sdManufacturerName(id.manufacturer), id.manufacturer, id.oem, id.product, id.revisionMajor,
id.revisionMinor, static_cast<unsigned>(id.serial), id.year, id.month);
return s;
}
} // namespace roro
+27
View File
@@ -0,0 +1,27 @@
#pragma once
#include <cstdint>
#include <string>
namespace roro {
// What an SD card says it is: its CID register, 16 bytes (SD Physical Layer spec, 5.2).
struct SdCardId {
uint8_t manufacturer = 0; // assigned by the SD Association; see sdManufacturerName()
char oem[3] = {}; // two characters
char product[6] = {}; // five characters
uint8_t revisionMajor = 0, revisionMinor = 0;
uint32_t serial = 0;
int year = 0, month = 0; // manufactured
};
SdCardId parseSdCid(const uint8_t cid[16]);
// The usual holder of a manufacturer ID. The SD Association doesn't publish its list: these are
// the commonly reported ones, and resold or counterfeit cards carry whatever their maker chose.
const char* sdManufacturerName(uint8_t id);
// "SanDisk (0x03) "SD" "SU08G" rev 8.0, serial 1234abcd, made 2014-03".
std::string sdCardSummary(const SdCardId& id);
} // namespace roro
+72
View File
@@ -0,0 +1,72 @@
#include "task_stats.h"
#include <algorithm>
#include <cctype>
#include <cstring>
namespace roro {
std::vector<TaskRow> taskRows(const std::vector<TaskSample>& before, uint32_t totalBefore,
const std::vector<TaskSample>& now, uint32_t totalNow) {
uint32_t elapsed = totalNow - totalBefore; // unsigned: right across one wrap
std::vector<TaskRow> rows;
rows.reserve(now.size());
for (const TaskSample& t : now) {
uint32_t ran = t.runtime; // a task that wasn't there before ran all of it since
for (const TaskSample& b : before)
if (b.id == t.id) {
ran = t.runtime - b.runtime;
break;
}
TaskRow r;
r.name = t.name;
r.core = t.core;
r.state = t.state;
r.priority = t.priority;
r.stackFree = t.stackFree;
r.permille = elapsed ? static_cast<uint16_t>(std::min<uint64_t>(1000, static_cast<uint64_t>(ran) * 1000 / elapsed)) : 0;
r.lowStack = t.stackFree < kLowStackBytes;
r.idle = std::strncmp(t.name, "IDLE", 4) == 0;
rows.push_back(r);
}
// The task that took the sample is running, and FreeRTOS counts a task's time when it's
// switched out: with its core to itself it never was, and its counter hardly moved. Give it
// what's left of its core once the idle task and the other tasks pinned there are counted.
for (TaskRow& r : rows) {
if (r.state != 0 || r.idle || r.core < 0) continue; // 0: eRunning
int others = 0;
bool idleSeen = false;
for (const TaskRow& o : rows) {
if (&o == &r || o.core != r.core) continue;
others += o.permille;
idleSeen |= o.idle;
}
if (idleSeen && elapsed && 1000 - others > r.permille) r.permille = static_cast<uint16_t>(std::max(0, 1000 - others));
}
return rows;
}
int coreLoad(const std::vector<TaskRow>& rows, int core) {
for (const TaskRow& r : rows)
if (r.idle && r.core == core) return 100 - (r.permille + 5) / 10;
return -1;
}
void sortTasks(std::vector<TaskRow>& rows, TaskSort by) {
auto lower = [](const std::string& s) {
std::string l = s;
for (char& c : l) c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
return l;
};
std::stable_sort(rows.begin(), rows.end(), [&](const TaskRow& a, const TaskRow& b) {
switch (by) {
case TaskSort::Share:
if (a.idle != b.idle) return !a.idle; // idle tasks last
return a.permille > b.permille;
case TaskSort::Stack: return a.stackFree < b.stackFree;
default: return lower(a.name) < lower(b.name);
}
});
}
} // namespace roro
+65
View File
@@ -0,0 +1,65 @@
#pragma once
#include <cstddef>
#include <cstdint>
#include <cstdio>
#include <string>
#include <vector>
namespace roro {
// One task as FreeRTOS reports it at one moment.
struct TaskSample {
uint32_t id = 0; // unique per task: a new task with an old name has another
char name[17] = {};
uint32_t runtime = 0; // microseconds on a CPU since it started; 32 bits, so it wraps every 71 minutes
uint16_t stackFree = 0; // the least it ever had left, bytes
int8_t core = -1; // -1: not pinned
uint8_t state = 0; // eTaskState
uint8_t priority = 0;
};
// What the System App and `tasks` show for a task (S1, Q119, Q122).
struct TaskRow {
std::string name;
int core = -1;
uint8_t state = 0, priority = 0;
uint16_t stackFree = 0;
uint16_t permille = 0; // share of one core over the interval, in tenths of a percent
bool lowStack = false;
bool idle = false; // a core's idle task: what's left over
};
constexpr uint16_t kLowStackBytes = 512;
// Shares from two samples: each task's run time between them over the time that passed. The
// 32-bit counters may have wrapped once in between. The task that took the samples (the one
// running) gets what's left of its core: see the .cpp.
std::vector<TaskRow> taskRows(const std::vector<TaskSample>& before, uint32_t totalBefore,
const std::vector<TaskSample>& now, uint32_t totalNow);
// A core's load in percent: what its idle task didn't use. -1 without that task in the rows.
int coreLoad(const std::vector<TaskRow>& rows, int core);
enum class TaskSort : uint8_t { Share, Stack, Name };
void sortTasks(std::vector<TaskRow>& rows, TaskSort by);
// The last N samples, oldest first (Q120).
template <typename T, size_t N>
class History {
public:
void push(T value) {
values_[(first_ + size_) % N] = value;
if (size_ < N) size_++;
else first_ = (first_ + 1) % N;
}
size_t size() const { return size_; }
T at(size_t i) const { return values_[(first_ + i) % N]; } // 0: the oldest kept
void clear() { first_ = size_ = 0; }
private:
T values_[N] = {};
size_t first_ = 0, size_ = 0;
};
} // namespace roro
+23 -1
View File
@@ -17,6 +17,8 @@ void SavedNetworks::load() {
int32_t hidden = 0;
store_.getInt(key(i, "hid").c_str(), hidden);
net.hidden = hidden != 0;
std::string ip; // "address/prefix [gateway]", or empty for Automatic
net.fixed = store_.getString(key(i, "ip").c_str(), ip) && !ip.empty() && net::parseFixed(ip, net.ip).empty();
networks_.push_back(net);
}
}
@@ -40,11 +42,30 @@ std::string SavedNetworks::add(const std::string& ssid, const std::string& passw
}
}
if (count() >= kMax) return "Already 8 saved networks: forget one first";
networks_.push_back({ssid, password, hidden});
SavedNetwork added;
added.ssid = ssid;
added.password = password;
added.hidden = hidden;
networks_.push_back(added);
save();
return "";
}
std::string SavedNetworks::setIp(const std::string& ssid, const net::FixedIp* fixed) {
for (auto& n : networks_) {
if (n.ssid != ssid) continue;
if (fixed) {
std::string why = net::checkFixed(*fixed);
if (!why.empty()) return why;
n.ip = *fixed;
}
n.fixed = fixed != nullptr;
save();
return "";
}
return "Not a saved network";
}
void SavedNetworks::forget(const std::string& ssid) {
for (auto it = networks_.begin(); it != networks_.end(); ++it) {
if (it->ssid == ssid) {
@@ -60,6 +81,7 @@ void SavedNetworks::save() {
store_.putString(key(i, "ssid").c_str(), networks_[i].ssid);
store_.putString(key(i, "pass").c_str(), networks_[i].password);
store_.putInt(key(i, "hid").c_str(), networks_[i].hidden ? 1 : 0);
store_.putString(key(i, "ip").c_str(), networks_[i].fixed ? net::formatFixed(networks_[i].ip) : "");
}
store_.putInt("net_count", count());
}
+5
View File
@@ -3,6 +3,7 @@
#include <string>
#include <vector>
#include "ipv4.h"
#include "key_value_store.h"
namespace roro {
@@ -11,6 +12,8 @@ struct SavedNetwork {
std::string ssid;
std::string password; // empty for an open network
bool hidden = false; // doesn't broadcast its name, so never shows up in scans
bool fixed = false; // S1, Q105: Fixed address (`ip`), or Automatic (DHCP)
net::FixedIp ip;
};
// The Saved Networks the Wi-Fi Service may join (see CONTEXT.md), persisted in internal flash.
@@ -28,6 +31,8 @@ class SavedNetworks {
// Adds, or updates the password of an existing SSID. Empty on success, otherwise why not.
std::string add(const std::string& ssid, const std::string& password, bool hidden = false);
void forget(const std::string& ssid);
// The IP setting: Fixed with these values, or Automatic (DHCP) for nullptr. Empty, or why not.
std::string setIp(const std::string& ssid, const net::FixedIp* fixed);
private:
void save();
+20
View File
@@ -19,7 +19,27 @@ build_flags =
-DARDUINO_USB_MODE=1
lib_deps =
m5stack/M5Cardputer @ 1.1.1
jgromes/RadioLib @ 7.8.1
test_ignore = *
; Smaller TLS buffers (M2): the framework is rebuilt with these settings (pioarduino "hybrid
; compile"). Receive stays 16 KB (servers send full TLS records); send drops to 4 KB (IRC lines are
; short); buffers are allocated as needed and handshake-only data is freed once connected.
custom_sdkconfig =
CONFIG_MBEDTLS_ASYMMETRIC_CONTENT_LEN=y
CONFIG_MBEDTLS_SSL_IN_CONTENT_LEN=16384
CONFIG_MBEDTLS_SSL_OUT_CONTENT_LEN=4096
CONFIG_MBEDTLS_DYNAMIC_BUFFER=y
CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA=y
CONFIG_MBEDTLS_DYNAMIC_FREE_CA_CERT=y
; Debug Build: the same firmware plus the Debug Console on TCP 2323 (see ADR 0004). The token comes
; from ~/.config/roro9stack/debug-token, passed in by scripts/_docker.sh; it's never committed.
[env:cardputer-adv-debug]
extends = env:cardputer-adv
extra_scripts = pre:scripts/version.py, pre:scripts/debug_flags.py
build_flags =
${env:cardputer-adv.build_flags}
-DRORO_DEBUG
; Host-side unit tests for pure logic (no hardware).
[env:native]
+8
View File
@@ -4,9 +4,17 @@ ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
docker build -q -t "$IMAGE" "$ROOT/docker" >/dev/null
# The Debug Console token (ADR 0004): made once, kept with the OTA key, never committed.
DEBUG_TOKEN_FILE="$HOME/.config/roro9stack/debug-token"
if [ ! -s "$DEBUG_TOKEN_FILE" ]; then
mkdir -p "$(dirname "$DEBUG_TOKEN_FILE")"
(umask 077 && od -An -tx1 -N16 /dev/urandom | tr -d ' \n' > "$DEBUG_TOKEN_FILE")
fi
run_in_container() {
docker run --rm \
-u "$(id -u):$(id -g)" -e HOME=/tmp \
-e RORO_DEBUG_TOKEN="$(cat "$DEBUG_TOKEN_FILE")" \
-v "$ROOT:/work" \
-v roro9stack-pio:/pio \
"${DOCKER_EXTRA[@]}" \
+1 -1
View File
@@ -4,4 +4,4 @@ set -euo pipefail
source "$(dirname "$0")/_docker.sh"
DOCKER_EXTRA=()
run_in_container bash -c 'git config --global --add safe.directory /work && pio test -e native && pio run -e cardputer-adv'
run_in_container bash -c 'git config --global --add safe.directory /work && pio test -e native && pio run -e cardputer-adv -e cardputer-adv-debug'
+12
View File
@@ -0,0 +1,12 @@
# Debug Builds only: compiles in the Debug Console token from $RORO_DEBUG_TOKEN (set by _docker.sh
# from ~/.config/roro9stack/debug-token). Refuses to build without one rather than use a default.
import os
import re
import sys
Import("env") # noqa: F821 (provided by PlatformIO)
token = os.environ.get("RORO_DEBUG_TOKEN", "").strip()
if not re.fullmatch(r"[0-9a-f]{32}", token):
sys.exit("debug build: RORO_DEBUG_TOKEN is missing; build through scripts/ci.sh or scripts/flash.sh --debug")
env.Append(CPPDEFINES=[("RORO_DEBUG_TOKEN", '\\"%s\\"' % token)]) # noqa: F821
+12
View File
@@ -0,0 +1,12 @@
#!/usr/bin/env bash
# Turns crash addresses into functions and source lines, using the archived ELF of the build that
# crashed (.pio/elves/, kept by scripts/version.py).
# Usage: scripts/decode_backtrace.sh <version or ELF sha256 prefix> <address>...
set -euo pipefail
source "$(dirname "$0")/_docker.sh"
[ $# -ge 2 ] || { echo "Usage: scripts/decode_backtrace.sh <version|sha> <address>..." >&2; exit 1; }
ELF="$(ls -t "$ROOT"/.pio/elves/*"$1"*.elf 2>/dev/null | head -1 || true)"
[ -n "$ELF" ] || { echo "No archived ELF matches '$1' in .pio/elves/" >&2; exit 1; }
echo "using ${ELF#$ROOT/}" >&2
DOCKER_EXTRA=()
run_in_container /pio/tools/toolchain-xtensa-esp-elf/bin/xtensa-esp32s3-elf-addr2line -pfiaC -e "/work/${ELF#$ROOT/}" "${@:2}"
+15
View File
@@ -0,0 +1,15 @@
#!/usr/bin/env bash
# Full post-mortem of a core dump fetched with `scripts/rdbg.py coredump`: every task's backtrace,
# registers and the crashed task's stack, via esp-coredump and GDB in the container.
# Usage: scripts/decode_coredump.sh <core.bin> <version or ELF sha256 prefix>
set -euo pipefail
source "$(dirname "$0")/_docker.sh"
[ $# -eq 2 ] || { echo "Usage: scripts/decode_coredump.sh <core.bin> <version|sha>" >&2; exit 1; }
CORE="$(realpath "$1")"
ELF="$(ls -t "$ROOT"/.pio/elves/*"$2"*.elf 2>/dev/null | head -1 || true)"
[ -n "$ELF" ] || { echo "No archived ELF matches '$2' in .pio/elves/" >&2; exit 1; }
echo "using ${ELF#$ROOT/}" >&2
DOCKER_EXTRA=(-v "$(dirname "$CORE"):/core:ro")
run_in_container /pio/penv/bin/esp-coredump --chip esp32s3 info_corefile -t raw \
-g /pio/tools/tool-xtensa-esp-elf-gdb/bin/xtensa-esp32s3-elf-gdb \
-c "/core/$(basename "$CORE")" "/work/${ELF#$ROOT/}"
+24 -2
View File
@@ -1,11 +1,33 @@
#!/usr/bin/env bash
# Flash the firmware over USB, then open the serial monitor.
# Usage: scripts/flash.sh [port] (default: the first Espressif device found)
# Usage: scripts/flash.sh [--debug] [port] USB (default: the first Espressif device found)
# scripts/flash.sh [--debug] --ota [host] Wi-Fi: build, sign and push a Firmware Update
# (host: the device's IP from Settings > About, or $RORO_OTA_HOST)
# --debug builds the Debug Build (cardputer-adv-debug): the Debug Console on TCP 2323, see ADR 0004.
set -euo pipefail
ENV=cardputer-adv
if [ "${1:-}" = "--debug" ]; then
ENV=cardputer-adv-debug
shift
fi
if [ "${1:-}" = "--ota" ]; then
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
HOST="${2:-${RORO_OTA_HOST:-}}"
[ -n "$HOST" ] || { echo "Usage: scripts/flash.sh --ota <device IP> (or set RORO_OTA_HOST)" >&2; exit 1; }
source "$(dirname "$0")/_docker.sh"
DOCKER_EXTRA=()
run_in_container bash -c "git config --global --add safe.directory /work && pio run -e $ENV" | tail -3
VERSION="$(git -C "$ROOT" describe --tags --always --dirty)"
[ "$ENV" = cardputer-adv-debug ] && VERSION="$VERSION+debug" # as scripts/version.py names it
OUT="$ROOT/.pio/build/$ENV/roro9stack-$VERSION.ota"
"$ROOT/scripts/make_ota.py" "$ROOT/.pio/build/$ENV/firmware.bin" "$VERSION" "$OUT"
exec "$ROOT/scripts/ota_push.py" "$OUT" "$HOST"
fi
PORT="${1:-$(readlink -f /dev/serial/by-id/*Espressif* 2>/dev/null | head -1)}"
[ -n "$PORT" ] || { echo "No Cardputer found on USB (is it plugged in / attached to the VM?)" >&2; exit 1; }
source "$(dirname "$0")/_docker.sh"
docker rm -f roro9stack-serial >/dev/null 2>&1 || true # a serial log would hold the port
DOCKER_EXTRA=(--device "$PORT" --group-add "$(stat -c %g "$PORT")" -it)
run_in_container bash -c "git config --global --add safe.directory /work && pio run -e cardputer-adv -t upload --upload-port $PORT && pio device monitor -p $PORT -b 115200"
run_in_container bash -c "git config --global --add safe.directory /work && pio run -e $ENV -t upload --upload-port $PORT && pio device monitor -p $PORT -b 115200"
+50
View File
@@ -0,0 +1,50 @@
#!/usr/bin/env python3
"""Wraps a firmware image into a signed Update File (.ota). See lib/ota/src/update_parser.h.
Usage: scripts/make_ota.py <firmware.bin> <version> <out.ota> [private key]
Signs with openssl (ECDSA P-256 over SHA-256 of the header's first 80 bytes).
"""
import hashlib
import os
import struct
import subprocess
import sys
import tempfile
HEADER_SIZE = 160
SIGNED_BYTES = 80
MAX_SIGNATURE = 72
def main():
if len(sys.argv) < 4:
sys.exit(__doc__)
image_path, version, out_path = sys.argv[1:4]
key = sys.argv[4] if len(sys.argv) > 4 else os.environ.get(
"RORO_OTA_KEY", os.path.expanduser("~/.config/roro9stack/ota-key.pem"))
if not os.path.exists(key):
sys.exit(f"No signing key at {key}: run scripts/ota_keygen.sh first.")
image = open(image_path, "rb").read()
version_bytes = version.encode()[:31]
signed = (b"RORO-OTA" + struct.pack("<HHI", 1, HEADER_SIZE, len(image)) +
hashlib.sha256(image).digest() + version_bytes.ljust(32, b"\0"))
assert len(signed) == SIGNED_BYTES
with tempfile.NamedTemporaryFile() as f:
f.write(signed)
f.flush()
signature = subprocess.run(["openssl", "dgst", "-sha256", "-sign", key, f.name],
check=True, capture_output=True).stdout
if len(signature) > MAX_SIGNATURE:
sys.exit("unexpected signature size")
header = signed + struct.pack("<H", len(signature)) + signature
header = header.ljust(HEADER_SIZE, b"\0")
with open(out_path, "wb") as out:
out.write(header + image)
print(f"{out_path}: {version}, {len(image)} bytes, signed")
if __name__ == "__main__":
main()
+31
View File
@@ -0,0 +1,31 @@
#!/usr/bin/env bash
# Creates the Firmware Update signing key pair, once (ADR 0003).
# The private key stays in ~/.config/roro9stack/ and must never be committed; the public key is
# written into the firmware source. Losing the private key means the next update goes over USB.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
KEY="${RORO_OTA_KEY:-$HOME/.config/roro9stack/ota-key.pem}"
PUB_PEM="$ROOT/keys/ota-public.pem"
PUB_H="$ROOT/src/platform/ota_public_key.h"
if [ -e "$KEY" ]; then
echo "A signing key already exists at $KEY; not overwriting it." >&2
exit 1
fi
mkdir -p "$(dirname "$KEY")" "$ROOT/keys"
( umask 077; openssl ecparam -name prime256v1 -genkey -noout -out "$KEY" )
openssl ec -in "$KEY" -pubout -out "$PUB_PEM" 2>/dev/null
{
echo "#pragma once"
echo ""
echo "// Public key that Firmware Updates must be signed for (ECDSA P-256). Generated by"
echo "// scripts/ota_keygen.sh; the private key is not in this repository (ADR 0003)."
echo "namespace roro {"
echo "inline constexpr char kOtaPublicKeyPem[] ="
sed 's/^/ "/; s/$/\\n"/' "$PUB_PEM"
echo " ;"
echo "} // namespace roro"
} > "$PUB_H"
echo "Private key: $KEY (keep it safe)"
echo "Public key: $PUB_PEM and $PUB_H (commit these)"
+63
View File
@@ -0,0 +1,63 @@
#!/usr/bin/env python3
"""Pushes a signed Update File to a Cardputer over Wi-Fi (TCP 3232) and reports the result.
Usage: scripts/ota_push.py <file.ota> <host>
<host> is the device's IP (shown in Settings > Firmware).
"""
import socket
import sys
PORT = 3232
def main():
if len(sys.argv) < 3:
sys.exit(__doc__)
path, host = sys.argv[1:3]
data = open(path, "rb").read()
try:
reply = push(data, host)
except (ConnectionResetError, BrokenPipeError):
# The device checks the header first and hangs up on a refused update mid-transfer.
print()
print("device: refused the update and closed the connection (the reason is on its screen)")
sys.exit(1)
print(f"device: {reply or '(no answer)'}")
sys.exit(0 if reply.startswith("OK") else 1)
def push(data, host):
with socket.create_connection((host, PORT), timeout=15) as s:
s.settimeout(60)
sent, last = 0, -1
while sent < len(data):
chunk = data[sent:sent + 4096]
s.sendall(chunk)
sent += len(chunk)
pct = sent * 100 // len(data)
if pct != last:
print(f"\rsending {pct:3d}%", end="", flush=True)
last = pct
# The header announces the image size, so current firmware answers once it has it all.
# Firmware from before that change only knows the file ended when we half-close.
reply = b""
s.settimeout(3)
try:
reply = s.recv(256)
except socket.timeout:
s.shutdown(socket.SHUT_WR)
s.settimeout(60)
while reply == b"" or not reply.endswith(b"\n"):
try:
part = s.recv(256)
except socket.timeout:
break
if not part:
break
reply += part
print()
return reply.decode(errors="replace").strip()
if __name__ == "__main__":
main()
+286
View File
@@ -0,0 +1,286 @@
#!/usr/bin/env python3
"""The Debug Console of a Debug Build, over Wi-Fi (TCP 2323, see ADR 0004).
Usage: scripts/rdbg.py [-H host] [-b] [command ...]
no command interactive: type commands, see every console line live; Ctrl-D or `quit` leaves
command runs it and prints what follows, until the console has been quiet for a moment
-H host the device's IP (Settings > Firmware), default $RORO_OTA_HOST
-b also print the backlog the device sends on connecting (boot messages and so on)
Commands handled here as well as on the device:
crash the last crash, with its backtrace decoded (scripts/decode_backtrace.sh)
coredump [file] fetch the core dump (default core-<date>.bin) and decode it with esp-coredump
get <card path> [file] copy a file from the SD card
put <file> [card path] copy a file to the SD card (default /updates/<name>), checked with SHA-256
screenshot [file.png] what the screen shows (default screen-<date>.png), at 2x
reset restart at once, even if the main loop is stuck
The token is read from ~/.config/roro9stack/debug-token (made by the first build).
"""
import hashlib
import os
import re
import select
import struct
import subprocess
import zlib
import socket
import sys
import time
PORT = 2323
TOKEN_FILE = os.path.expanduser("~/.config/roro9stack/debug-token")
def read_until(sock, marker, timeout):
"""Everything up to and including `marker`, or None on a timeout or a closed connection."""
sock.settimeout(timeout)
data = b""
while marker not in data:
try:
chunk = sock.recv(4096)
except socket.timeout:
return None
if not chunk:
return None
data += chunk
return data
def read_until_quiet(sock, quiet, out):
"""Copies everything the device sends to `out` until nothing has arrived for `quiet` seconds."""
sock.settimeout(quiet)
while True:
try:
data = sock.recv(4096)
except socket.timeout:
return True
if not data:
return False
if out:
out.write(data.decode(errors="replace"))
out.flush()
SCRIPTS = os.path.dirname(os.path.abspath(__file__))
def run(sock, command, out=sys.stdout):
"""Sends one command and returns its reply (also copied to `out`)."""
sock.sendall((command + "\n").encode())
# The main loop echoes "> command" when it runs it; the reply follows.
echoed = read_until(sock, f"> {command}\n".encode(), 15)
if echoed is None:
sys.exit("device: the command never ran")
reply = echoed.decode(errors="replace").split(f"> {command}\n", 1)[1]
class Tee:
def write(self, text):
nonlocal reply
reply += text
if out:
out.write(text)
def flush(self):
if out:
out.flush()
if out:
out.write(reply)
try:
read_until_quiet(sock, 1.5, Tee())
except BrokenPipeError: # e.g. piped into head
pass
return reply
def crash_firmware(reply):
"""The archived-ELF key for the crashed firmware: its ELF digest, or else its version."""
sha = re.search(r"elf sha256 ([0-9a-f]{8,})", reply)
if sha:
return sha.group(1)
version = re.search(r"last one in (\S+)", reply)
return version.group(1) if version else None
def crash(sock):
reply = run(sock, "crash")
trace = re.search(r"backtrace((?: 0x[0-9a-f]+)+)", reply)
key = crash_firmware(reply)
if trace and key:
print()
subprocess.call([os.path.join(SCRIPTS, "decode_backtrace.sh"), key] + trace.group(1).split())
def coredump(sock, path):
info = run(sock, "crash", out=None)
sock.sendall(b"coredump get\n")
# One buffer throughout: the header, the size and the first bytes often share a packet.
buf = b""
sock.settimeout(15)
while b"coredump: none" not in buf and not re.search(rb"coredump: data (\d+)\n", buf):
chunk = sock.recv(65536)
if not chunk:
sys.exit("device: closed the connection")
buf += chunk
header = re.search(rb"coredump: data (\d+)\n", buf)
if not header:
sys.exit("device: no core dump in flash")
size = int(header.group(1))
data = buf[header.end():]
while len(data) < size:
chunk = sock.recv(65536)
if not chunk:
sys.exit(f"device: the connection closed after {len(data)} of {size} bytes")
data += chunk
data = data[:size]
path = path or time.strftime("core-%Y%m%d-%H%M%S.bin")
open(path, "wb").write(data)
print(f"saved {path} ({size} bytes)")
key = crash_firmware(info)
if key:
subprocess.call([os.path.join(SCRIPTS, "decode_coredump.sh"), path, key])
def binary(sock, command, tag):
"""Sends a binary command; returns (header words, payload) or exits with the device's error."""
sock.sendall((command + "\n").encode())
buf = b""
sock.settimeout(30)
pattern = re.compile(tag.encode() + rb": (data|ready|rgb332|error)([^\n]*)\n")
while not (m := pattern.search(buf)):
chunk = sock.recv(65536)
if not chunk:
sys.exit("device: closed the connection")
buf += chunk
if m.group(1) == b"error":
sys.exit(f"device: {tag}: error{m.group(2).decode()}")
return m.group(1).decode(), m.group(2).decode().split(), buf[m.end():]
def receive(sock, have, size):
while len(have) < size:
chunk = sock.recv(65536)
if not chunk:
sys.exit(f"device: the connection closed after {len(have)} of {size} bytes")
have += chunk
return have[:size]
def get(sock, remote, local):
_, words, rest = binary(sock, f"get {remote}", "get")
start, size = time.time(), int(words[0])
data = receive(sock, rest, size)
local = local or os.path.basename(remote)
open(local, "wb").write(data)
print(f"saved {local} ({size} bytes, {size / 1024 / max(time.time() - start, 0.001):.0f} KB/s)")
def put(sock, local, remote):
data = open(local, "rb").read()
remote = remote or "/updates/" + os.path.basename(local)
digest = hashlib.sha256(data).hexdigest()
binary(sock, f"put {remote} {len(data)} {digest}", "put")
start = time.time()
sock.sendall(data)
answer = read_until(sock, b"\n", 30) or b"put: error no answer"
answer = answer.decode(errors="replace").strip().splitlines()[-1]
print(f"device: {answer} ({len(data) / 1024 / max(time.time() - start, 0.001):.0f} KB/s)")
if " error " in answer:
sys.exit(1)
def png(path, width, height, rgb, scale):
rows = b""
for y in range(height):
row = b"".join(rgb[(y * width + x) * 3:(y * width + x) * 3 + 3] * scale for x in range(width))
rows += (b"\x00" + row) * scale
def chunk(kind, body):
return struct.pack(">I", len(body)) + kind + body + struct.pack(">I", zlib.crc32(kind + body))
header = struct.pack(">IIBBBBB", width * scale, height * scale, 8, 2, 0, 0, 0)
with open(path, "wb") as f:
f.write(b"\x89PNG\r\n\x1a\n" + chunk(b"IHDR", header) + chunk(b"IDAT", zlib.compress(rows)) + chunk(b"IEND", b""))
def screenshot(sock, path):
_, words, rest = binary(sock, "screenshot", "screenshot")
width, height = int(words[0]), int(words[1])
pixels = receive(sock, rest, width * height)
# RGB332, as M5GFX stores an 8-bit sprite: RRRGGGBB.
rgb = b"".join(bytes(((v >> 5) * 255 // 7, ((v >> 2) & 7) * 255 // 7, (v & 3) * 255 // 3)) for v in pixels)
path = path or time.strftime("screen-%Y%m%d-%H%M%S.png")
png(path, width, height, rgb, 2)
print(f"saved {path} ({width * 2}x{height * 2})")
def interactive(sock):
sock.setblocking(False)
while True:
ready, _, _ = select.select([sock, sys.stdin], [], [])
if sock in ready:
data = sock.recv(4096)
if not data:
print("\n(connection closed)")
return
sys.stdout.write(data.decode(errors="replace"))
sys.stdout.flush()
if sys.stdin in ready:
# Straight from the descriptor: readline() takes every waiting line into Python's own
# buffer and hands over one, and select() then sees nothing more to read. Piped input
# written while we were still connecting got stuck until the next line came.
data = os.read(sys.stdin.fileno(), 4096)
if not data:
return
sock.setblocking(True)
sock.sendall(data)
sock.setblocking(False)
def main():
args = sys.argv[1:]
host, backlog = os.environ.get("RORO_OTA_HOST"), False
while args and args[0].startswith("-"):
flag = args.pop(0)
if flag == "-H" and args:
host = args.pop(0)
elif flag == "-b":
backlog = True
else:
sys.exit(__doc__)
if not host:
sys.exit("No device: pass -H <ip> or set RORO_OTA_HOST\n\n" + __doc__)
token = open(TOKEN_FILE).read().strip()
with socket.create_connection((host, PORT), timeout=10) as sock:
sock.sendall((token + "\n").encode())
# The device may still be finishing a previous client: wait for this connection's banner.
banner = read_until(sock, b"Backlog follows.\n", 15)
if banner is None:
sys.exit("device: no banner (wrong token, or another client is connected)")
show = sys.stdout if backlog or not args else None
if show:
show.write(banner.decode(errors="replace"))
read_until_quiet(sock, 0.5, show) # the backlog
if not args:
return interactive(sock)
if args == ["crash"]:
return crash(sock)
if args[0] == "get" and len(args) >= 2:
return get(sock, args[1], args[2] if len(args) > 2 else None)
if args[0] == "put" and len(args) >= 2:
return put(sock, args[1], args[2] if len(args) > 2 else None)
if args[0] == "screenshot":
return screenshot(sock, args[1] if len(args) > 1 else None)
if args == ["reset"]: # answered by the console's own task, not the main loop
sock.sendall(b"reset\n")
print((read_until(sock, b"restarting now\n", 10) or b"device: no answer").decode().strip().splitlines()[-1])
return
if args[0] == "coredump" and args[1:2] != ["erase"]:
return coredump(sock, args[1] if len(args) > 1 else None)
run(sock, " ".join(args))
if __name__ == "__main__":
try:
main()
except (ConnectionResetError, BrokenPipeError):
sys.exit("device: the connection dropped (restarting?)")
+79
View File
@@ -0,0 +1,79 @@
#!/usr/bin/env python3
"""Copies a file to the Cardputer's SD card over the USB serial console (the `sd put` command).
Usage: scripts/sd_put.sh <file> [card path]
The card path defaults to /updates/<file name>, where Settings > Firmware finds Update Files.
The device acknowledges each chunk once it's on the card, checks the SHA-256 of the whole file,
and only then renames <card path>.part to <card path>.
"""
import glob
import hashlib
import os
import sys
import time
import serial
DEBUG = bool(os.environ.get("SD_PUT_DEBUG")) # also show the console lines in between
def find_port():
ports = sorted(glob.glob("/dev/serial/by-id/*Espressif*"))
return os.path.realpath(ports[0]) if ports else None
def reply(port, timeout):
"""The next `sd put:` line from the device; everything else on the console is skipped."""
deadline = time.time() + timeout
while time.time() < deadline:
line = port.readline().decode(errors="replace").strip()
if line.startswith("sd put:"):
return line[len("sd put:"):].strip()
if line and DEBUG:
print(f"\n console: {line}", file=sys.stderr)
return "error no answer from the device"
def fail(answer):
print()
sys.exit(f"device: {answer}")
def main():
if len(sys.argv) < 2:
sys.exit(__doc__)
path = sys.argv[1]
dest = sys.argv[2] if len(sys.argv) > 2 else "/updates/" + os.path.basename(path)
port_name = find_port()
if not port_name:
sys.exit("No Cardputer found on USB")
data = open(path, "rb").read()
sha = hashlib.sha256(data).hexdigest()
with serial.Serial(port_name, 115200, timeout=0.5) as port:
port.reset_input_buffer()
# The leading newline ends any half-typed command.
port.write(f"\nsd put {dest} {len(data)} {sha}\n".encode())
answer = reply(port, 10)
if not answer.startswith("ready "):
fail(answer)
chunk = int(answer.split()[1])
start, sent = time.time(), 0
while sent < len(data):
port.write(data[sent:sent + chunk])
sent = min(sent + chunk, len(data))
print(f"\rsending {sent * 100 // len(data):3d}%", end="", flush=True)
if sent < len(data):
answer = reply(port, 10)
if answer != f"ok {sent}":
fail(answer)
answer = reply(port, 15)
if not answer.startswith("done "):
fail(answer)
seconds = time.time() - start
print(f"\rdevice: {answer}, {seconds:.1f} s ({len(data) / 1024 / seconds:.0f} KB/s)")
if __name__ == "__main__":
main()
+10
View File
@@ -0,0 +1,10 @@
#!/usr/bin/env bash
# Copy a file to the Cardputer's SD card over USB serial, e.g. an Update File into /updates.
# Usage: scripts/sd_put.sh <file> [card path] (default card path: /updates/<file name>)
set -euo pipefail
source "$(dirname "$0")/_docker.sh"
[ -f "${1:-}" ] || { echo "Usage: scripts/sd_put.sh <file> [card path]" >&2; exit 1; }
docker rm -f roro9stack-serial >/dev/null 2>&1 || true # a serial log would hold the port
FILE="$(realpath "$1")"
DOCKER_EXTRA=(-e SD_PUT_DEBUG="${SD_PUT_DEBUG:-}" --group-add "$(getent group dialout | cut -d: -f3)" --privileged -v /dev:/dev -v "$(dirname "$FILE"):/in:ro")
run_in_container /pio/penv/bin/python scripts/sd_put.py "/in/$(basename "$FILE")" "${@:2}"
+20
View File
@@ -10,4 +10,24 @@ try:
except Exception:
version = "unknown"
if env["PIOENV"].endswith("-debug"): # noqa: F821
version += "+debug" # a Debug Build says so wherever the version shows
env.Append(CPPDEFINES=[("RORO_VERSION", '\\"%s\\"' % version)]) # noqa: F821
# Keep every build's ELF, named by version and the first 16 hex digits of its SHA-256 (the core dump
# names the crashed firmware by the same digest), so a crash can be decoded after later builds.
def archive_elf(source, target, env):
import hashlib
import os
import shutil
elf = str(target[0])
digest = hashlib.sha256(open(elf, "rb").read()).hexdigest()[:16]
folder = os.path.join(env.subst("$PROJECT_DIR"), ".pio", "elves")
os.makedirs(folder, exist_ok=True)
shutil.copy(elf, os.path.join(folder, "%s.%s.elf" % (version, digest)))
env.AddPostAction("$BUILD_DIR/${PROGNAME}.elf", archive_elf) # noqa: F821
+470
View File
@@ -0,0 +1,470 @@
#include "file_viewer.h"
#include <Arduino.h>
#include <SD.h>
#include <algorithm>
#include <atomic>
#include <cstdio>
#include <ctime>
#include "cleanup_plan.h"
#include "file_list.h"
#include "file_names.h"
#include "file_views.h"
#include "meshtastic_presets.h"
#include "packet_view.h"
#include "platform/ota_device.h"
#include "ui/fonts.h"
#include "ui/widgets.h"
#include "update_parser.h"
#include "version.h"
namespace roro {
namespace {
constexpr uint32_t kSliceMs = 150; // like the Storage App's operations: the Logs get their turn
constexpr size_t kPiece = 1024;
constexpr size_t kMaxPackets = 1000; // their places in the file, 4 KB
constexpr size_t kMaxPacketBytes = 271; // LoRaTap and the longest LoRa packet
// Checks an Update File as an install would, writing nothing.
struct NoSink : UpdateSink {
bool begin(size_t) override { return true; }
bool write(const uint8_t*, size_t) override { return true; }
bool finish() override { return true; }
void abort() override {}
};
std::string clockTime(uint32_t utcSeconds) {
time_t t = static_cast<time_t>(utcSeconds);
struct tm local;
localtime_r(&t, &local);
char s[12];
std::snprintf(s, sizeof s, "%02d:%02d:%02d", local.tm_hour, local.tm_min, local.tm_sec);
return s;
}
} // namespace
struct FileViewer::Scan {
std::atomic<bool> done{false}, stop{false};
std::atomic<int> percent{0};
Mode what = Mode::Gpx;
std::string path;
// Touched by the storage task until `done`, by the viewer after.
fs::File file;
bool opened = false;
uint32_t at = 0, size = 0;
std::string error;
files::GpxSummary gpx;
files::PcapHeader pcap;
std::vector<uint32_t> packets; // where each record starts
bool morePackets = false;
std::unique_ptr<EcdsaVerifier> verifier;
NoSink sink;
std::unique_ptr<UpdateParser> parser;
std::string version;
bool genuine = false, older = false;
bool slice(); // true when there's nothing more to read
static void run(StorageService* storage, std::shared_ptr<Scan> self) {
bool over = self->stop || self->slice();
if (over) {
if (self->file) self->file.close();
self->parser.reset();
self->verifier.reset();
self->done = true;
} else {
storage->runJob([storage, self]() { run(storage, self); });
}
}
};
bool FileViewer::Scan::slice() {
uint32_t t0 = millis();
if (!opened) {
opened = true;
file = SD.open(path.c_str(), FILE_READ);
if (!file) {
error = "The card refused to open it";
return true;
}
size = static_cast<uint32_t>(file.size());
if (what == Mode::Ota) {
verifier.reset(new EcdsaVerifier());
parser.reset(new UpdateParser(*verifier, sink, EspOtaSink().capacity(), versionString()));
}
}
std::unique_ptr<uint8_t[]> piece(new uint8_t[kPiece]);
while (millis() - t0 < kSliceMs) {
if (stop) return true;
if (what == Mode::Pcap) {
if (at == 0) {
int n = file.read(piece.get(), files::kPcapHeaderSize);
pcap = files::parsePcapHeader(piece.get(), n < 0 ? 0 : n);
if (!pcap.ok) {
error = "Not a pcap file this viewer reads";
return true;
}
at = files::kPcapHeaderSize;
}
files::PcapRecord r;
if (!file.seek(at)) return true;
int n = file.read(piece.get(), files::kPcapRecordSize);
if (n < 0 || !files::parsePcapRecord(piece.get(), n, r) || at + files::kPcapRecordSize + r.length > size) return true;
if (packets.size() >= kMaxPackets) {
morePackets = true;
return true;
}
packets.push_back(at);
at += files::kPcapRecordSize + r.length;
continue;
}
int n = file.read(piece.get(), kPiece);
if (n <= 0) break;
at += n;
percent = size ? static_cast<int>(static_cast<uint64_t>(at) * 100 / size) : 100;
if (what == Mode::Gpx) {
gpx.feed(reinterpret_cast<const char*>(piece.get()), n);
} else {
parser->feed(piece.get(), n);
if (parser->state() == UpdateParser::State::Failed) break;
}
}
if (at < size && !(parser && parser->state() == UpdateParser::State::Failed) && millis() - t0 >= kSliceMs) return false;
if (parser) {
genuine = parser->end();
version = parser->version();
older = parser->isDowngrade();
error = parser->error();
}
return true;
}
size_t FileViewer::readAt(uint32_t offset, uint8_t* into, size_t len) {
size_t got = 0;
auto file = file_;
std::string path = path_;
storage_.runAndWait([&, file, path]() {
if (!*file) *file = SD.open(path.c_str(), FILE_READ);
if (!*file || !file->seek(offset)) return;
int n = file->read(into, len);
got = n < 0 ? 0 : n;
});
return got;
}
void FileViewer::open(const std::string& path, uint32_t size) {
close();
path_ = path;
size_ = size;
file_ = std::make_shared<fs::File>();
std::string name = files::baseName(path);
files::FileKind kind = files::kindOf(name);
if (kind == files::FileKind::Unknown) { // what do its first bytes look like?
uint8_t head[256];
size_t n = readAt(0, head, sizeof head);
kind = files::looksLikeText(head, n) ? files::FileKind::Text : files::FileKind::Unknown;
}
switch (kind) {
case files::FileKind::Text: base_ = Mode::Text; break;
case files::FileKind::Gpx: base_ = Mode::Gpx; break;
case files::FileKind::Pcap: base_ = Mode::Pcap; break;
case files::FileKind::Ota: base_ = Mode::Ota; break;
default: base_ = Mode::Hex; break;
}
pager_.reset(new files::TextPager([this](uint32_t offset, uint8_t* into, size_t len) { return readAt(offset, into, len); }, size_,
kCols, kRows));
if (files::opensAtEnd(name)) pager_->toEnd();
hexTop_ = 0;
show(base_);
if (base_ == Mode::Gpx || base_ == Mode::Pcap || base_ == Mode::Ota) startScan(base_);
}
void FileViewer::startScan(Mode mode) {
scan_ = std::make_shared<Scan>();
scan_->what = mode;
scan_->path = path_;
scanShown_ = false;
shownPercent_ = -1;
auto scan = scan_;
StorageService* storage = &storage_;
storage_.runJob([storage, scan]() { Scan::run(storage, scan); });
}
void FileViewer::close() {
if (scan_) scan_->stop = true; // its job ends at the next piece and frees itself
scan_.reset();
if (file_) {
auto file = file_;
storage_.runJob([file]() {
if (*file) file->close();
});
}
file_.reset();
pager_.reset();
confirm_.reset();
message_.clear();
std::vector<std::string>().swap(shown_);
std::vector<std::string>().swap(details_);
packets_.setCount(0);
rowsFrom_ = -1;
}
void FileViewer::show(Mode mode) {
mode_ = mode;
stale_ = true;
rowsFrom_ = -1;
}
void FileViewer::say(const std::string& text) {
message_ = text;
messageMs_ = millis();
}
std::string FileViewer::title() const { return files::fitName(files::baseName(path_), 24); }
void FileViewer::scroll(int lines) {
if (mode_ == Mode::Text && pager_) {
if (lines > 0) pager_->down(lines);
else pager_->up(-lines);
} else if (mode_ == Mode::Hex) {
uint32_t rows = (size_ + 7) / 8, last = rows > static_cast<uint32_t>(kRows) ? rows - kRows : 0;
int64_t to = static_cast<int64_t>(hexTop_) + lines;
hexTop_ = static_cast<uint32_t>(std::clamp<int64_t>(to, 0, last));
}
stale_ = true;
}
void FileViewer::openPacket(int index) {
if (!scan_ || !scan_->done || index < 0 || index >= static_cast<int>(scan_->packets.size())) return;
uint8_t buf[files::kPcapRecordSize + kMaxPacketBytes];
size_t n = readAt(scan_->packets[index], buf, sizeof buf);
files::PcapRecord r;
if (!files::parsePcapRecord(buf, n, r)) return;
const uint8_t* body = buf + files::kPcapRecordSize;
size_t have = std::min<size_t>(r.length, n - files::kPcapRecordSize);
details_.clear();
char line[64];
lora::RxInfo rx;
bool tap = scan_->pcap.linkType == files::kLinkLoraTap && files::parseLoraTap(body, have, rx);
size_t skip = tap ? lora::kLoraTapSize : 0;
std::snprintf(line, sizeof line, "%s, %u bytes", clockTime(r.seconds).c_str(), static_cast<unsigned>(r.length - skip));
details_.push_back(line);
if (tap) {
std::snprintf(line, sizeof line, "%.0f dBm, SNR %.1f dB, noise %.0f", rx.rssi, rx.snr, rx.noiseFloor);
details_.push_back(line);
std::snprintf(line, sizeof line, "%.4f MHz, SF%u, %.0f kHz", rx.frequencyHz / 1e6, rx.spreadingFactor, rx.bandwidthKHz);
details_.push_back(line);
if (rx.syncWord == meshtastic::kSyncWord)
for (auto& l : lora::headerLines(body + skip, have - skip)) details_.push_back(l);
}
for (auto& l : lora::hexDump(body + skip, have - skip)) details_.push_back(l);
if (have < r.length) details_.push_back("(the first bytes only)");
detailsTop_ = 0;
mode_ = Mode::Packet;
}
bool FileViewer::onKey(const KeyEvent& e) {
if (confirm_) {
confirm_->onKey(e);
if (confirm_->result() == 1) update_.installFromSd(path_);
if (confirm_->result() != DialogModel::kPending) confirm_.reset();
return true;
}
if (mode_ == Mode::Packet) {
int last = std::max(0, static_cast<int>(details_.size()) - (kRows + 1));
if (e.key == Key::Up) detailsTop_ = std::max(0, detailsTop_ - 1);
else if (e.key == Key::Down) detailsTop_ = std::min(last, detailsTop_ + 1);
else if (e.key == Key::Back || e.key == Key::Select) mode_ = Mode::Pcap;
return true;
}
if (e.key == Key::Back) return false;
if (e.key == Key::Tab) {
// The file's own view, or what it's made of: text for a Track, bytes for the others.
if (mode_ != base_) show(base_);
else show(base_ == Mode::Hex || base_ == Mode::Gpx ? Mode::Text : Mode::Hex);
return true;
}
uint32_t ch = e.key == Key::Char ? e.ch : 0;
switch (mode_) {
case Mode::Text:
case Mode::Hex:
if (e.key == Key::Up) scroll(-1);
else if (e.key == Key::Down) scroll(1);
else if (e.key == Key::Left) scroll(-(kRows - 1));
else if (e.key == Key::Right) scroll(kRows - 1);
else if (ch == 't' || ch == 'T') {
if (pager_) pager_->toStart();
hexTop_ = 0;
stale_ = true;
} else if (ch == 'b' || ch == 'B') {
if (mode_ == Mode::Text && pager_) pager_->toEnd();
else scroll(INT32_MAX / 2);
stale_ = true;
}
break;
case Mode::Pcap:
if (e.key == Key::Up) packets_.up();
else if (e.key == Key::Down) packets_.down();
else if (e.key == Key::Left) packets_.pageUp();
else if (e.key == Key::Right) packets_.pageDown();
else if (e.key == Key::Select) openPacket(packets_.selected());
break;
case Mode::Ota:
if (e.key == Key::Select && scan_ && scan_->done && scan_->genuine) confirm_.reset(new DialogModel({"Cancel", "Install"}));
break;
default: break;
}
return true;
}
bool FileViewer::update(uint32_t) {
if (!message_.empty() && millis() - messageMs_ >= 4000) {
message_.clear();
return true;
}
if (!scan_) return false;
if (scan_->done && !scanShown_) {
scanShown_ = true;
if (scan_->what == Mode::Pcap) packets_.setCount(static_cast<int>(scan_->packets.size()));
return true;
}
int percent = scan_->percent;
if (!scan_->done && percent != shownPercent_) {
shownPercent_ = percent;
return true;
}
return false;
}
void FileViewer::refresh() {
if (mode_ == Mode::Text && stale_ && pager_) {
shown_ = pager_->lines();
stale_ = false;
} else if (mode_ == Mode::Hex && stale_) {
uint8_t buf[kRows * 8];
size_t n = readAt(hexTop_ * 8, buf, sizeof buf);
shown_.clear();
for (size_t at = 0; at < n; at += 8) shown_.push_back(files::hexRow(hexTop_ * 8 + at, buf + at, std::min<size_t>(8, n - at)));
stale_ = false;
} else if (mode_ == Mode::Pcap && scan_ && scan_->done && rowsFrom_ != packets_.firstVisible()) {
// The rows on screen, read from the card once each time the list moves.
rowsFrom_ = packets_.firstVisible();
shown_.clear();
bool tap = scan_->pcap.linkType == files::kLinkLoraTap;
for (int i = rowsFrom_; i < rowsFrom_ + kRows && i < static_cast<int>(scan_->packets.size()); i++) {
uint8_t buf[files::kPcapRecordSize + kMaxPacketBytes];
size_t n = readAt(scan_->packets[i], buf, sizeof buf);
files::PcapRecord r;
lora::RxInfo rx;
if (!files::parsePcapRecord(buf, n, r)) {
shown_.push_back("(unreadable)");
continue;
}
const uint8_t* body = buf + files::kPcapRecordSize;
size_t have = std::min<size_t>(r.length, n - files::kPcapRecordSize);
if (tap && files::parseLoraTap(body, have, rx)) {
shown_.push_back(lora::row({body + lora::kLoraTapSize, have - lora::kLoraTapSize, rx.rssi, rx.snr, true,
rx.syncWord == meshtastic::kSyncWord},
clockTime(r.seconds)));
} else {
shown_.push_back(clockTime(r.seconds) + " " + std::to_string(r.length) + " bytes");
}
}
}
}
void FileViewer::draw(Canvas& c) {
const auto& area = theme::kContent;
refresh();
c.setTextDatum(top_left);
theme::Rect body{area.x, area.y + 10, area.w, kRows * theme::kLineHeight};
std::string right, keys = "Tab: hex";
bool scanning = scan_ && !scan_->done;
switch (mode_) {
case Mode::Text:
case Mode::Hex: {
c.setFont(&fonts::body);
c.setTextColor(size_ == 0 ? theme::kMuted : theme::kText);
if (size_ == 0) c.drawString("(empty)", 4, body.y + 1);
for (size_t i = 0; i < shown_.size(); i++) c.drawString(shown_[i].c_str(), 4, body.y + 1 + static_cast<int>(i) * theme::kLineHeight);
uint32_t at = mode_ == Mode::Text && pager_ ? pager_->top() : hexTop_ * 8;
if (size_ > 0) { // where in the file the screen is
int barH = 12, barY = body.y + static_cast<int>(static_cast<uint64_t>(body.h - barH) * at / size_);
c.fillRect(area.w - 2, barY, 2, barH, theme::kMuted);
}
right = formatBytes(size_);
keys = std::string("Tab: ") + (mode_ != base_ ? "back" : mode_ == Mode::Text ? "hex" : "text") + " t: top b: end";
if (mode_ == Mode::Text) keys += " e: edit";
break;
}
case Mode::Gpx: {
std::vector<std::string> lines;
if (scanning) lines.push_back("Reading the Track... " + std::to_string(scan_->percent.load()) + "%");
else if (scan_ && !scan_->error.empty()) lines.push_back(scan_->error);
else if (scan_) lines = scan_->gpx.lines();
widgets::textLines(c, lines, 0, body);
right = formatBytes(size_);
keys = "Tab: the file as text";
break;
}
case Mode::Pcap: {
c.setFont(&fonts::body);
c.setTextColor(theme::kMuted);
if (scanning) c.drawString("Reading the Capture...", 4, body.y + 1);
else if (scan_ && !scan_->error.empty()) c.drawString(scan_->error.c_str(), 4, body.y + 1);
else if (scan_ && scan_->packets.empty()) c.drawString("No packets in this Capture.", 4, body.y + 1);
else if (scan_) {
int from = rowsFrom_;
widgets::list(c, packets_, body, [&](int i) {
size_t row = static_cast<size_t>(i - from);
return row < shown_.size() ? shown_[row] : std::string();
});
right = std::to_string(scan_->packets.size()) + (scan_->morePackets ? "+ packets" : " packets");
keys = "Enter: the packet Tab: hex";
}
break;
}
case Mode::Packet: widgets::textLines(c, details_, detailsTop_, {area.x + 2, area.y + 2, area.w - 2, area.h - 2}); return;
case Mode::Ota: {
std::vector<std::string> lines;
bool ok = scan_ && scan_->done && scan_->genuine;
if (scanning) {
lines.push_back("Checking it as an install would:");
lines.push_back("signature and contents, " + std::to_string(scan_->percent.load()) + "%");
} else if (scan_) {
if (!scan_->version.empty()) lines.push_back("Version " + scan_->version);
lines.push_back(std::string("Running ") + versionString());
if (ok) {
lines.push_back("Signed with the project's key, intact.");
if (scan_->older) lines.push_back("Older than what's running.");
} else {
lines.push_back("Not installable:");
lines.push_back(scan_->error.empty() ? "it ends too early" : scan_->error);
}
}
widgets::textLines(c, lines, 0, body);
right = formatBytes(size_);
keys = ok ? "Enter: install Tab: hex" : "Tab: hex";
if (confirm_) {
widgets::dialog(c, "Install update?", "The device restarts into " + scan_->version + " once it's written.", *confirm_);
return;
}
break;
}
}
c.setFont(&fonts::small);
c.setTextColor(theme::kMuted);
c.setTextDatum(top_left);
c.drawString(title().c_str(), 4, area.y + 1);
c.setTextDatum(top_right);
c.drawString(right.c_str(), area.w - 3, area.y + 1);
c.setTextDatum(top_left);
if (!message_.empty()) c.setTextColor(theme::kWarning);
c.drawString(message_.empty() ? keys.c_str() : message_.c_str(), 4, area.y + area.h - 9);
}
} // namespace roro

Some files were not shown because too many files have changed in this diff Show More