Files
roro9stack/scripts/_docker.sh
twislaandClaude Opus 5.5 c68741cc46
CI / build (pull_request) Successful in 7m20s
Site / build (pull_request) Successful in 9s
One firmware: the Debug Console in every build, off until switched on, with the device's own token
There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The
console and the test commands are compiled into every firmware. It listens
only while Settings > Debug Console is on, which isn't the default; off,
neither its task nor its 4 KB ring exists. The token is made by the device
and shown on that page; a client proves it knows it by answering a challenge
with an HMAC, so it never crosses the network, and five wrong answers close
the console for a minute. DBG in the Status Bar while it listens.

Over USB serial only: debug on, debug token <value>, debug token new.
scripts/flash.sh --debug uses them to set a device up with the developer's
token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the
file, answers the challenge, and fetches a release's ELF to decode a crash.

Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version,
scripts/debug_flags.py, update install ... force, and the rule that a Debug
Build doesn't install releases. Old clients and old firmwares don't talk to
each other.

Against the builds it replaces: 30 KB more flash and 88 bytes more static
RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests.
Checked on the device: off by default, login, the pause after wrong tokens,
Safe Mode with the console, the setting surviving an update, debug off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 22:59:35 +02:00

31 lines
1.2 KiB
Bash
Executable File

# Shared helper: run a command inside the roro9stack build container.
# With RORO_NO_DOCKER set, the caller is in such a container already (a CI job): the command runs
# right here, in the checkout.
IMAGE=roro9stack-build
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
[ -n "${RORO_NO_DOCKER:-}" ] || docker build -q -t "$IMAGE" "$ROOT/docker" >/dev/null
# The Debug Console token of the developer's device (ADR 0010): made once, kept with the OTA key, never
# committed and never compiled in. scripts/flash.sh --debug gives it to a device over USB, and
# scripts/rdbg.py answers the device's challenge with it.
DEBUG_TOKEN_FILE="$HOME/.config/roro9stack/debug-token"
if [ ! -s "$DEBUG_TOKEN_FILE" ]; then
mkdir -p "$(dirname "$DEBUG_TOKEN_FILE")"
(umask 077 && od -An -tx1 -N16 /dev/urandom | tr -d ' \n' > "$DEBUG_TOKEN_FILE")
fi
run_in_container() {
if [ -n "${RORO_NO_DOCKER:-}" ]; then
(cd "$ROOT" && RORO_DEBUG_TOKEN="$(cat "$DEBUG_TOKEN_FILE")" "$@")
return
fi
docker run --rm \
-u "$(id -u):$(id -g)" -e HOME=/tmp \
-e RORO_DEBUG_TOKEN="$(cat "$DEBUG_TOKEN_FILE")" \
-v "$ROOT:/work" \
-v roro9stack-pio:/pio \
"${DOCKER_EXTRA[@]}" \
"$IMAGE" "$@"
}