Step 2b: firmware upload (/api/ota) with image checks and rollback self-test

- aes67_ota: GET /api/ota (version, project, build_date, idf, running,
  previous, previous_version, pending_verify, can_rollback), POST
  /api/ota streamed into the inactive slot (4 KiB chunks), POST
  /api/ota/confirm and /api/ota/rollback.
- Rejected before any flash write: bad magic, wrong chip, wrong
  project_name, chip revision outside the image's min/max range.
  esp_ota_end verifies the whole image.
- Self-test on a pending image: IP address plus HTTP 200 from our own
  /api/status within 60 s marks it valid; otherwise mark invalid and
  reboot into the previous slot. A crash before that is rolled back by
  the bootloader.
- CONFIG_AES67_OTA_SELFTEST_FORCE_FAIL (test builds only) forces a
  failed self-test.
- aes67_web: web_reboot_later() shared by /api/reboot and OTA.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-24 23:20:04 +10:00
parent cbfc37cde6
commit 2403a6b64b
8 changed files with 301 additions and 10 deletions
+2
View File
@@ -1,6 +1,7 @@
#include "aes67_board.h"
#include "aes67_health.h"
#include "aes67_net.h"
#include "aes67_ota.h"
#include "aes67_ptp.h"
#include "aes67_syslog.h"
#include "aes67_tx.h"
@@ -33,5 +34,6 @@ void app_main(void)
ESP_ERROR_CHECK(aes67_tx_init());
ESP_ERROR_CHECK(aes67_syslog_init());
project_cfg_register();
ESP_ERROR_CHECK(aes67_ota_init());
ESP_ERROR_CHECK(aes67_web_start());
}