OTA: quiet the audio sources during a firmware upload

An upload during an active Spotify session crawled (~10 kB/s, 197 s)
and ended in a reset (seen twice). Workaround:
- aes67_ota_on_update(cb): cb(true) right before an accepted upload
  writes flash, cb(false) if it then fails.
- The player pauses Spotify (spotify_pause -> SpircHandler::setPause, the
  app follows) and suspends HLS fetching (hls_suspend); resumed if the
  upload fails. AES67 TX keeps running (silence).
- Verified: upload during Spotify playback paused the session and
  installed in 25.8 s (normal for 2 MB), clean reboot and self-test.
  Root cause still open (noted in CLAUDE.md with the other cspot items).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-25 19:02:03 +10:00
parent cd747aec40
commit 8ba4de5eda
8 changed files with 90 additions and 2 deletions
+28
View File
@@ -23,6 +23,26 @@
static const char *TAG = "ota";
#define MAX_UPDATE_CBS 4
static aes67_ota_update_cb_t s_update_cbs[MAX_UPDATE_CBS];
static int s_update_n;
esp_err_t aes67_ota_on_update(aes67_ota_update_cb_t cb)
{
if (s_update_n >= MAX_UPDATE_CBS) {
return ESP_ERR_NO_MEM;
}
s_update_cbs[s_update_n++] = cb;
return ESP_OK;
}
static void notify_update(bool starting)
{
for (int i = 0; i < s_update_n; i++) {
s_update_cbs[i](starting);
}
}
static bool is_pending(void)
{
esp_ota_img_states_t st;
@@ -114,6 +134,7 @@ static esp_err_t ota_post(httpd_req_t *req)
esp_ota_handle_t ota = 0;
size_t total = 0, fill = 0;
const char *err_msg = NULL;
bool notified = false;
int64_t t0 = esp_timer_get_time();
while (total < req->content_len) {
@@ -137,6 +158,8 @@ static esp_err_t ota_post(httpd_req_t *req)
}
const esp_app_desc_t *d = (const esp_app_desc_t *)(buf + DESC_OFFSET);
ESP_LOGI(TAG, "image %.32s %.32s", d->project_name, d->version);
notify_update(true); // project quiets streaming/decoding before the flash writes
notified = true;
if (esp_ota_begin(dst, OTA_WITH_SEQUENTIAL_WRITES, &ota) != ESP_OK) {
err_msg = "ota begin failed";
break;
@@ -154,15 +177,20 @@ static esp_err_t ota_post(httpd_req_t *req)
if (ota) {
esp_ota_abort(ota);
}
if (notified) {
notify_update(false);
}
// Rejected before the whole body was read: close instead of draining it.
httpd_resp_set_hdr(req, "Connection", "close");
return reject(req, err_msg);
}
esp_err_t err = esp_ota_end(ota); // verifies the image (checksum/hash, chip)
if (err != ESP_OK) {
notify_update(false);
return reject(req, err == ESP_ERR_OTA_VALIDATE_FAILED ? "image verification failed" : "ota end failed");
}
if (esp_ota_set_boot_partition(dst) != ESP_OK) {
notify_update(false);
return httpd_resp_send_err(req, HTTPD_500_INTERNAL_SERVER_ERROR, "could not set boot partition");
}
ESP_LOGW(TAG, "installed to %s in %.1f s, rebooting", dst->label,
+8
View File
@@ -2,8 +2,16 @@
// Core component: must not depend on main/ (project code).
#pragma once
#include <stdbool.h>
#include "esp_err.h"
// Registers /api/ota routes. If the running image is pending verification, starts the
// self-test: IP address + own web server answering within 60 s, else roll back.
esp_err_t aes67_ota_init(void);
// Called with true right before an accepted upload starts writing flash, and with false if that
// upload then fails (on success the device reboots). Lets the project quiet heavy work (streaming,
// decoding) during the flash writes. Up to 4 callbacks.
typedef void (*aes67_ota_update_cb_t)(bool starting);
esp_err_t aes67_ota_on_update(aes67_ota_update_cb_t cb);