- aes67_ota: GET /api/ota (version, project, build_date, idf, running,
previous, previous_version, pending_verify, can_rollback), POST
/api/ota streamed into the inactive slot (4 KiB chunks), POST
/api/ota/confirm and /api/ota/rollback.
- Rejected before any flash write: bad magic, wrong chip, wrong
project_name, chip revision outside the image's min/max range.
esp_ota_end verifies the whole image.
- Self-test on a pending image: IP address plus HTTP 200 from our own
/api/status within 60 s marks it valid; otherwise mark invalid and
reboot into the previous slot. A crash before that is rolled back by
the bootloader.
- CONFIG_AES67_OTA_SELFTEST_FORCE_FAIL (test builds only) forces a
failed self-test.
- aes67_web: web_reboot_later() shared by /api/reboot and OTA.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>