Updates: check Gitea for new releases and install them #6

Closed
opened 2026-10-05 09:37:58 +00:00 by twisla · 1 comment
Owner

Idea

The device checks the project's latest Gitea release, says when a newer version is out, and installs it on request. It uses the same signed Update Files and the same Probation and rollback as Wi-Fi and SD updates.

Why

This is the end of the OTA story: no computer needed at all.

What's known

  • It's blocked by #5: there are no releases to check yet.

  • GET /repos/twisla/roro9stack/releases/latest gives the tag and the asset URLs. Compare that with the running version and the version in the other slot.

  • The download is about 1.7 MB over HTTPS. Two options:

    • Stream it to /updates/ on the card, then install it with the existing Update from SD path.
    • Write it straight into the inactive slot, as UpdateService does over TCP.

    Either way, the signature is checked before anything boots it.

  • The TLS root of trust is the same as in #4. That part should be built once and shared.

  • A Debug Build should be offered the +debug image, and a release build the release image.

Questions for the design round

  1. Should it check when asked, at boot, or once a day while on Wi-Fi?
  2. Should it download to the card first (safer, and you can retry) or straight into the slot (no card needed)?
  3. Should it offer only newer versions, or also let you go back to an older release?
  4. Should it be in Settings > Firmware, or the Issues App (#4), or both?
## Idea The device checks the project's latest Gitea release, says when a newer version is out, and installs it on request. It uses the same signed Update Files and the same Probation and rollback as Wi-Fi and SD updates. ## Why This is the end of the OTA story: no computer needed at all. ## What's known - It's blocked by #5: there are no releases to check yet. - `GET /repos/twisla/roro9stack/releases/latest` gives the tag and the asset URLs. Compare that with the running version and the version in the other slot. - The download is about 1.7 MB over HTTPS. Two options: - Stream it to `/updates/` on the card, then install it with the existing Update from SD path. - Write it straight into the inactive slot, as UpdateService does over TCP. Either way, the signature is checked before anything boots it. - The TLS root of trust is the same as in #4. That part should be built once and shared. - A Debug Build should be offered the `+debug` image, and a release build the release image. ## Questions for the design round 1. Should it check when asked, at boot, or once a day while on Wi-Fi? 2. Should it download to the card first (safer, and you can retry) or straight into the slot (no card needed)? 3. Should it offer only newer versions, or also let you go back to an older release? 4. Should it be in Settings > Firmware, or the Issues App (#4), or both?
twisla added a new dependency 2026-10-05 09:37:58 +00:00
twisla added this to the R1 Releases milestone 2026-10-05 20:14:09 +00:00
twisla added
status
needs-design
and removed
status
blocked
labels 2026-10-06 11:51:31 +00:00
Author
Owner

No longer blocked: #5 is done. Every tag has a Gitea release with a signed roro9stack-<version>.ota, and GET /repos/twisla/roro9stack/releases/latest answers. Ready for its design round.

No longer blocked: #5 is done. Every tag has a Gitea release with a signed `roro9stack-<version>.ota`, and `GET /repos/twisla/roro9stack/releases/latest` answers. Ready for its design round.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: twisla/roro9stack#6