When the connection breaks during a release download (issue #54), the device waits up to a minute for Wi-Fi, asks for the rest of the file with a Range request and carries on: the slot and the hash so far are kept. It gives up after three tries in a row that bring nothing. Nothing is kept across a restart. Carrying on asks for 64 KB free, not 80: between two connections of an install 78 KB is free, and the first attempt on the device was refused for that. update damage cut now breaks every connection after n bytes. Tried on the device: v0.23.0 installed over four connections, and a download that brought nothing given up with nothing switched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162FokPdvY2KsS4NBfwyWPk
4.8 KiB
+++ title = "Flash and update" description = "Put the firmware on a Cardputer over USB, then update it over Wi-Fi or from the SD card, and from the project's releases." weight = 2
[extra] docs = true source = "README.md" tag = "Flash" +++
Flash
-
Connect the Cardputer by USB-C.
-
Run:
scripts/flash.sh # auto-detects the port; or: scripts/flash.sh /dev/ttyACM1This uploads the firmware, then opens the serial monitor. Quit the monitor with
Ctrl+C.
If the upload can't connect, put the device in download mode: hold G0 (the button next to the screen) while plugging in USB, or while pressing reset. Then retry.
If you get "permission denied" on the port, your user needs access to the serial device. Run this once, then log out and back in:
sudo usermod -aG dialout "$USER"
Firmware Updates over Wi-Fi (OTA)
Once the Cardputer runs an OTA-capable firmware (flashed once over USB), updates can go over Wi-Fi:
scripts/ota_keygen.sh # once: creates the signing key (see ADR 0003)
scripts/flash.sh --ota 10.39.39.12 # build, sign and push; or set RORO_OTA_HOST
The device shows the push address in Settings → System → Firmware. It installs a correctly signed update right away, restarts (waiting up to 60 s if you're typing), and runs the new firmware on Probation. If the new firmware crashes, or can't reconnect Wi-Fi within 3 minutes, it rolls back to the previous one and says so.
To install from the SD card instead, copy the .ota file from .pio/build/cardputer-adv/ into /updates on the card, then use Settings → System → Firmware. With the Cardputer on USB, the card can stay in: scripts/sd_put.sh <file.ota> sends it over the serial console into /updates (about 30 s for 1.6 MB, checked with SHA-256 before it's renamed into place; SD_PUT_DEBUG=1 shows the console while it runs).
The private key lives in ~/.config/roro9stack/ota-key.pem and must never be committed. If it's lost, generate a new pair and flash once over USB. (CI signs releases with a copy kept as a repository secret, ADR 0008.)
Updates from Gitea
With no PC and no card, the device can install the project's releases itself (docs/milestones/R1.md). In Settings → System → Firmware:
- Latest release checks the server (Enter, or
c) and saysv0.11.0 (new)or(current). Enter again opens the release: its version, date, size and the tag's message, with Install when it's newer. The download goes straight into the inactive slot, so no card is needed; the signature is checked after the first 160 bytes, before anything is written, and the image's hash at the end. The new firmware then runs on Probation as for any update. A download that breaks is carried on from where it was (issue #54): the device waits up to a minute for Wi-Fi, asks for the rest of the file, and gives up only after three tries in a row that bring nothing. - Older releases lists the last ten, newest first. Opening an older one offers to go back to it, with a different question.
- Settings → System → Check for updates (on by default): once a day, with Wi-Fi up and the clock set, the device looks at the latest release and says
v0.11.0 is out: see Settings > System > Firmware, once per version. It installs nothing by itself, and doesn't announce a version that already failed and rolled back on this device. - Settings → System → Install updates (
When askedby default;By itself, issue #52): a newer release found by the daily check is installed without being asked for. The device waits until no key was pressed for 2 minutes and nothing would be cut by a restart (a Track, a Capture, a copy, an upload, an SSH session, a web share), then asks on the screen for 30 seconds, lighting it if it was off: Cancel leaves it until the next day's check; Accept, or no answer, installs it and restarts. What was installed and when, and what was undone, is written in/system/updates.logon the card.
The connection is checked against the two ISRG roots Let's Encrypt chains end in (ADR 0009), not the usual bundle of about 130 authorities. Whatever the connection, the Update File's own signature is what decides what gets installed.
IRC steps aside. A secure connection takes about 52 KB of memory at its peak, and IRC's own takes 40 KB of the 107 KB there is. A check or an install you ask for makes IRC disconnect for the few seconds it takes and reconnect afterwards. The daily check never does that: with IRC connected it waits for a moment when IRC isn't, so while IRC stays connected for days it doesn't run, and Latest release is the way to check.
There is no separate Debug Build any more (ADR 0010): every firmware installs releases, and the Debug Console is a setting, which an update leaves as it was.