Files
roro9stack/lib/release/src/update_check.h
T
twislaandClaude Opus 5.5 c68741cc46
CI / build (pull_request) Successful in 7m20s
Site / build (pull_request) Successful in 9s
One firmware: the Debug Console in every build, off until switched on, with the device's own token
There is no Debug Build any more (ADR 0010, issue #68, Q188 to Q195). The
console and the test commands are compiled into every firmware. It listens
only while Settings > Debug Console is on, which isn't the default; off,
neither its task nor its 4 KB ring exists. The token is made by the device
and shown on that page; a client proves it knows it by answering a challenge
with an HMAC, so it never crosses the network, and five wrong answers close
the console for a minute. DBG in the Status Bar while it listens.

Over USB serial only: debug on, debug token <value>, debug token new.
scripts/flash.sh --debug uses them to set a device up with the developer's
token. scripts/rdbg.py takes the token from -t, $RORO_DEBUG_TOKEN or the
file, answers the challenge, and fetches a release's ELF to decode a crash.

Gone: the cardputer-adv-debug environment, RORO_DEBUG, the +debug version,
scripts/debug_flags.py, update install ... force, and the rule that a Debug
Build doesn't install releases. Old clients and old firmwares don't talk to
each other.

Against the builds it replaces: 30 KB more flash and 88 bytes more static
RAM than the release, 4 KB less RAM than the Debug Build. 468 host tests.
Checked on the device: off by default, login, the pause after wrong tokens,
Safe Mode with the console, the setting surviving an update, debug off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 22:59:35 +02:00

33 lines
1.3 KiB
C++

#pragma once
#include <string>
#include "release_info.h"
#include "version_compare.h"
namespace roro::release {
// Where the project's releases are (Q164). A fork changes these, and its own signing key.
constexpr const char* kGiteaHost = "git.twis.la";
constexpr const char* kGiteaRepo = "twisla/roro9stack";
inline bool versionNewer(const std::string& a, const std::string& b) { return versionOlder(b, a); }
// Is `release` a newer one than what runs?
inline bool isNewer(const Release& release, const std::string& running) {
return release.usable() && versionNewer(release.tag, running);
}
// Should the background check say so (Q166, Q168)? Not for a version that failed on this device
// before (it rolled back), and not twice for the same one.
inline bool shouldAnnounce(const Release& latest, const std::string& running, const std::string& failed, const std::string& announced) {
return isNewer(latest, running) && latest.tag != failed && latest.tag != announced;
}
// Is `url` a download this device takes from the project's server, for this repository? Whatever
// the API says, the device only fetches from where it asked (a redirected or rewritten answer
// can't send it elsewhere).
bool trustedAssetUrl(const std::string& url, const std::string& host = kGiteaHost, const std::string& repo = kGiteaRepo);
} // namespace roro::release