Step 2b: firmware upload (/api/ota) with image checks and rollback self-test
- aes67_ota: GET /api/ota (version, project, build_date, idf, running, previous, previous_version, pending_verify, can_rollback), POST /api/ota streamed into the inactive slot (4 KiB chunks), POST /api/ota/confirm and /api/ota/rollback. - Rejected before any flash write: bad magic, wrong chip, wrong project_name, chip revision outside the image's min/max range. esp_ota_end verifies the whole image. - Self-test on a pending image: IP address plus HTTP 200 from our own /api/status within 60 s marks it valid; otherwise mark invalid and reboot into the previous slot. A crash before that is rolled back by the bootloader. - CONFIG_AES67_OTA_SELFTEST_FORCE_FAIL (test builds only) forces a failed self-test. - aes67_web: web_reboot_later() shared by /api/reboot and OTA. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -80,16 +80,20 @@ static void reboot_cb(void *arg)
|
||||
esp_restart();
|
||||
}
|
||||
|
||||
void web_reboot_later(uint32_t ms)
|
||||
{
|
||||
const esp_timer_create_args_t args = { .callback = reboot_cb, .name = "reboot" };
|
||||
esp_timer_handle_t t;
|
||||
if (esp_timer_create(&args, &t) == ESP_OK) {
|
||||
esp_timer_start_once(t, ms * 1000ULL);
|
||||
}
|
||||
}
|
||||
|
||||
static esp_err_t reboot_post(httpd_req_t *req)
|
||||
{
|
||||
ESP_LOGW(TAG, "reboot requested via API");
|
||||
httpd_resp_sendstr(req, "");
|
||||
// Let the response go out before restarting.
|
||||
const esp_timer_create_args_t args = { .callback = reboot_cb, .name = "reboot" };
|
||||
esp_timer_handle_t t;
|
||||
if (esp_timer_create(&args, &t) == ESP_OK) {
|
||||
esp_timer_start_once(t, 500 * 1000);
|
||||
}
|
||||
web_reboot_later(500); // let the response go out first
|
||||
return ESP_OK;
|
||||
}
|
||||
|
||||
|
||||
@@ -16,5 +16,8 @@ esp_err_t web_register_uri(const httpd_uri_t *uri);
|
||||
// Start httpd on port 80 with the core routes (/, /api/status, /api/config, /api/reboot).
|
||||
esp_err_t aes67_web_start(void);
|
||||
|
||||
// Restart after ms (lets an HTTP response go out first).
|
||||
void web_reboot_later(uint32_t ms);
|
||||
|
||||
// Send a cJSON object as the response body (application/json).
|
||||
esp_err_t web_send_json(httpd_req_t *req, const cJSON *json);
|
||||
|
||||
Reference in New Issue
Block a user