The SSH App opens one session to a shell, over libssh (LibSSH-ESP32 5.10.0) on mbedTLS. A server is trusted the first time on its fingerprint, and a changed key is a warning with Cancel selected. The password is typed each time and kept nowhere; or the device makes itself an Ed25519 key, whose public half is shown, written to /ssh/id_ed25519.pub and printed by `ssh status`. lib/term is the terminal: what a shell, less, top, nano and vim send, with sixteen colours, scroll regions, the alternate screen and 100 lines of scrollback. Five text sizes with Ctrl and + or -, from 60x20 to 26x8, told to the far end. The session goes on when the App is left; SSH shows in the Status Bar. `ssh user@host` in the Shell opens the App. Also: - Keys that aren't characters carry Shift, Ctrl and Alt. The terminal needs it, and it makes Ctrl+Fn+up/down in a note and Shift+Tab in Gemini work from the real keyboard. - IRC doesn't try to connect under 60 KB free: started with a session open, its TLS handshake took the heap down to 236 bytes. - libssh's own curve25519 is left out of the build (scripts/libssh_filter.py): libsodium's has the same names. Costs 292 KB of flash and about 50 KB of heap while a session is open; not started under 75 KB free. Docs: guide page, how-to, FAQ, home page, Status Bar, SD card folders, the memory how-to, README, glossary, N1 notes with Q254 to Q266 and the checks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
The roro9stack site
Source of https://roro9stack.net (docs/milestones/W1.md): a Zola site. The home page, an Install page with a browser flasher, and the list of releases so far; the user guide, how-tos, FAQ and developer docs come next.
config.toml base_url, the repository and API addresses
content/ the pages (Markdown, with their template named in the front matter)
templates/ base, home, install, downloads, 404; illustrations/ is generated
data/ the App cards and the screenshots' captions
static/ css, js, fonts (self-hosted), img, screens (real screenshots), vendor/esp-web-tools
tools/ make_illustrations.py, check_site.py
Build and look
docker run --rm -u "$(id -u):$(id -g)" -v "$PWD:/repo" -w /repo/site ghcr.io/getzola/zola:v0.22.0 build # writes ./public
docker run --rm -u "$(id -u):$(id -g)" -p 1111:1111 -v "$PWD:/repo" -w /repo/site ghcr.io/getzola/zola:v0.22.0 serve --interface 0.0.0.0
python3 site/tools/check_site.py public # what the pages promise, kept
Or zola build with a Zola of your own, in site/ (or zola --root site build from the root). The output goes to public/ at the root of the repository, not into site/: output_dir in config.toml, and git ignores that directory. The build reads the latest release and the list of releases from the Gitea API (load_data); if the server can't be reached, the pages say so instead of failing.
Publishing
The web server pulls main and runs zola build, as for the blog. CI (.gitea/workflows/site.yml) builds the site and runs the checks when site/, docs/, README.md or CONTEXT.md change; the firmware workflow skips a change that touches only those.
Things to know
-
The Install page needs Caddy's help. Gitea's release downloads carry no CORS header, so the page asks the API from the browser only if Caddy, in front of Gitea, allows this origin:
@releases { method GET HEAD path /twisla/roro9stack/releases/download/* /api/v1/repos/twisla/roro9stack/releases* } header @releases Access-Control-Allow-Origin "https://roro9stack.net" header @releases Vary OriginWithout it the page says it can't reach the release server and points to the esptool steps.
-
No third-party requests. Fonts and the flasher library are served from here;
tools/check_site.pyfails the build if a page loads anything from another origin. -
Illustrations.
templates/illustrations/*.htmlare generated bytools/make_illustrations.py; run it again rather than editing them. -
Updating the flasher library: see
static/vendor/esp-web-tools/README.txt. -
Fonts are DM Mono and Hanken Grotesk, under the SIL Open Font License (the licences are in
static/fonts/).