Files
roro9stack/lib/ota/src/probation.h
T
twislaandClaude Opus 5.5 7afe6b7d17 OTA: keep new images on Probation; Arduino validated them before setup()
Arduino-ESP32's initArduino() marks a PENDING_VERIFY image valid unless
the sketch overrides the weak verifyRollbackLater(). Every update was
therefore VALID before bootGuard() or Probation ever ran (otadata read
back state 0x2 on a crash-looping test build), and nothing rolled back.
The bootloader was never the problem. Override it to return true, so
Probation decides.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-04 02:12:45 +02:00

29 lines
1.2 KiB
C++

#pragma once
#include <cstdint>
namespace roro {
// Decides when new firmware on Probation (see CONTEXT.md) has proven healthy, or has failed in a
// way that would leave no means to push a fix (Wi-Fi configured but never connecting).
class Probation {
public:
enum class Verdict { Wait, Confirm, RollBack };
static constexpr uint32_t kHealthyAfterMs = 30000;
static constexpr uint32_t kWifiDeadlineMs = 180000;
// Checked first thing at boot, before anything that could crash. `attemptsBefore` counts earlier
// boots of this image on Probation; a second start means the first one died before confirming.
// (A second line behind the bootloader's own rollback, which aborts an image still pending.)
static bool rollBackAtBoot(bool onProbation, int attemptsBefore) { return onProbation && attemptsBefore >= 1; }
static Verdict judge(uint32_t uptimeMs, bool firstFrameDrawn, bool wifiConfigured, bool wifiConnected) {
if (wifiConfigured && !wifiConnected && uptimeMs >= kWifiDeadlineMs) return Verdict::RollBack;
if (uptimeMs < kHealthyAfterMs || !firstFrameDrawn) return Verdict::Wait;
if (wifiConfigured && !wifiConnected) return Verdict::Wait;
return Verdict::Confirm;
}
};
} // namespace roro