- main/audio_out: one converter instance per source (own rate converter
state): s16 any rate/channels -> 48 kHz stereo int32 -> ring.
- player_write(src, ...) only writes for the active source, drops the
rest; player_src_t is public in player.h.
- HLS decoder uses audio_out (no behaviour change).
- Verified: HLS still sample exact (441344 -> 480375 frames per
10.008 s segment), buffer ~4 s, 0 underruns.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Zeroconf on our httpd (GET/POST /spotify_info, form body URL-decoded)
and _spotify-connect._tcp via our mDNS (VERSION, CPath, Stack TXT).
- Session task: waits for the app's login blob, connects with the
user's client ID/secret and the configured bitrate (96/160/320 ->
OGG_VORBIS_*), SpircHandler, events logged; cspot exceptions caught.
Starts when source.mode is spotify/auto and credentials are set.
- bell::bellGlobalLogger was NULL: every CSPOT_LOG crashed the board
right after addUser (Load access fault in Session.cpp:67 /
LoginBlob.cpp:58). cspot/bell logs now go to esp_log (UART + syslog);
signed CDN URL tokens are cut from the log.
- esp_audio_codec's own Vorbis decoder clashed with bell's Tremor
symbols: CONFIG_AUDIO_DECODER_VORBIS_SUPPORT / SIMPLE_DEC_OGG off.
- status.spotify_state from the session (waiting / connecting /
connected / login failed / error / disabled / no client credentials).
- Verified from a Mac: device appears, "connected as <user>", access
token fetched with the user's client credentials, track info, audio
key, CDN URL (the step broken upstream), PCM decoded. Without
backpressure a track decodes in ~26 s (b3 feeds the ring).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Core config: cfg_mark_secret(group, key). GET /api/config returns ""
for secret keys; a POST with "" keeps the stored value, null clears it;
cfg_get() returns the real value. Documented in aes67-core-base.md.
- source.spotify_client_id / spotify_client_secret (secret write-only):
each user's own Spotify developer app, needed by the maintained cspot
fork (philippe44/cspot) since Spotify's 2025 API restrictions.
- UI: client ID field, password field for the secret ("leave empty to
keep"), link to developer.spotify.com; enabled for spotify/auto modes.
- status.spotify_state: "no client credentials" while either is missing.
- Verified: secret never appears in GET; UI-style re-save keeps it;
survives reboot; null clears it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- decoder: s16 PCM -> stereo int32 -> esp_ae_rate_cvt 44.1 -> 48 kHz
(32-bit, complexity 3; bypassed at 48 kHz; mono duplicated) -> ring.
esp_audio_effects pinned to ~1.3.0 (1.4+ needs P4 rev >= 3).
- hls: each segment is downloaded completely into PSRAM (max 4 MB), then
decoded; the connection is not held open while the decoder waits for
ring space at playback speed.
- player: player_write() blocks while the ring is full and gives up when
the source changes; the temporary 440 Hz producer is removed.
- Verified with Triple J Hottest: 441344 -> 480375 frames (10.008 s) and
440320 -> 479260 (9.985 s) per segment; RTP 15000 packets, 0 gaps,
peak -10 dBFS / RMS -22 dBFS; ring ~4.0 s, 0 underruns over ~50 s;
heap 422 KB, PSRAM 27.5 MB free.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- main/decoder: MPEG-TS demux (packets reassembled across HTTP chunks,
PAT -> PMT -> first ADTS-AAC PID, PES headers stripped) feeding the
esp_audio_codec simple AAC decoder (ADTS, AAC-Plus enabled for HE-AAC
v1/v2 variants). 7.3 only counts and logs PCM per segment.
- esp_audio_codec pinned to ~2.5.0: 2.6+ needs P4 rev >= 3 (this board
is rev 1.3). Noted in CLAUDE.md, also for esp_audio_effects < 1.4.
- The library's combined TS decoder lost ~8% of the frames (segments
decoded to 7.9-9.6 s, "decode error -1"); with the own demux every
segment is sample exact: 441344 / 440320 frames = 10.008 / 9.985 s,
matching EXTINF 10.0078 / 9.9846 (431 / 430 AAC frames), no errors.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- main/hls: task active while source.mode is hls/auto and hls_url is
set. esp_http_client over HTTPS (IDF certificate bundle), redirects
followed (max 5), streamed reads in 4 KB chunks to a sink callback.
- Master playlist: highest BANDWIDTH variant; URL resolution for
absolute, host-relative and path-relative references; CRLF tolerant.
- Media playlist: TARGETDURATION, MEDIA-SEQUENCE, segments; start 3
segments behind the live edge, fetch each new one in order, skip ahead
if the window moved past us, reload after target/2 when nothing is new.
- Verified with Triple J Hottest (ABC, Akamai): 252 kbit/s AAC-LC
variant chosen, 3 back-fill segments then one new ~10 s segment at a
time, ~303 KB in ~1.25 s each; heap 439 KB, PSRAM 31.9 MB free.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- main/audio_ring: SPSC ring of interleaved int32 frames in PSRAM
(4 s at 48 kHz stereo), lock-free with acquire/release counters; the
TX pull callback never blocks.
- main/player: source selection from source.mode and the pull callback
for aes67_tx. tone -> the core's PTP-phased 1 kHz tone; off -> silence;
hls/spotify -> ring with 1 s prefill (silence while buffering is not an
underrun; running dry is, and prefills again). Status fields
active_source, source_state, spotify_state, buffer_ms. source config
applies live.
- New source.mode "tone" (validation, UI dropdown, doc) for commissioning.
- Temporary 440 Hz producer in hls mode (until the HLS player exists).
- Verified: tone 999.7 Hz -18 dBFS; off silent; hls 440.0 Hz with max
sample step 60816 (ideal sine 60825, i.e. no discontinuities), buffer
3983 ms, 0 underruns; spotify silent/not implemented.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_syslog: esp_log_set_vprintf hook chained to the UART; formats
into a static buffer under a zero-timeout mutex (drop and count when
busy), strips ANSI codes, parses level/tag, filters by log.level and
queues (48 messages, non-blocking). Low-priority sender task: RFC 5424
(<PRI>1 - HOST APP - - - MSG, no timestamp yet) or RFC 3164
(<PRI>HOST TAG: MSG), PRI = facility*8 + severity; log.host as IP or
resolved name; config applies live. Messages wait in the queue until
the interface has an IP. POST /api/log/test sends an info message
regardless of the level filter.
- Initialised first in app_main so boot messages are captured; the UDP
socket is created only once the interface is up (creating it before
esp_netif_init crashed at boot and the bootloader rolled back).
- Verified with a UDP listener: 5424 and 3164 formats, PRI 134/132,
boot messages delivered after the IP came up, shutdown messages sent
before reboot, level filter, test message, host by DNS name.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_tx: TX task woken by an esp_timer every packet time; sends every
packet whose last sample is in the past (PTP time), RTP ts =
(sample index from PTP + clk_offset) mod 2^32, packets aligned to
multiples of the packet size. Sends only while PTP is locked; resyncs
on lock, clock step or > 20 ms lag. L24/L16 big-endian, TTL/DSCP/
multicast IF from config; a config save restarts TX.
- Built-in 1 kHz tone at -18 dBFS, phase from the PTP sample index;
aes67_tx_set_source() pull callback for later sources (underruns
counted, padded with silence). status: tx_packets, underruns.
- Verified with a receiver script on the PC: 1 ms L24 stereo 1000/s,
0 gaps, ts step 48, tone -18.00 dBFS within 1.2 LSB of the ideal
PTP-phased sine; also L16 mono 0.333 ms, 0.125 ms (8000/s) and 4 ms.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_sdp_sap: aes67_sdp_build() builds the AES67 SDP (RFC 4566 +
RFC 7273) with the same lines and order as the web UI preview;
GET /stream.sdp serves it as application/sdp.
- aes67_ptp: public aes67_ptp_gm_id(), aes67_ptp_locked(),
aes67_ptp_now_ns(). Clock IDs are now uppercase (RFC 7273 style), also
in status.ptp, which the UI copies into ts-refclk.
- aes67_net: aes67_net_netif() returns the AES67 interface.
- Verified on board: /stream.sdp byte-identical to the UI's sdp() for
the same config/status; mono, L16, ptime 0.333, ttl 8, clk_offset
4294967295 and session_ver all follow the config.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_ptp/ptp_hw.c: start the EMAC IEEE 1588 clock (IDF
ETH_MAC_ESP_CMD_PTP_ENABLE) and additionally enable snapshots for
PTP over UDP/IPv4 (IDF only enables PTP over Ethernet/L2). An RX hook
on the driver's info input path records {type, seq, sourcePortId, HW
timestamp} of port-319 PTPv2 event messages, then hands every frame to
lwIP unchanged.
- aes67_ptp.c: temporary 3.1 logger joins 224.0.1.129:319/320 and pairs
Sync HW RX timestamps with Follow_Up origin timestamps.
- Checked against linuxptp ptp4l (-4 -E -H, Intel igb) as GM: every Sync
has a HW timestamp; HW Sync intervals track the GM intervals with a
constant -39.8 us/s (+-0.3 us), i.e. local clock -39.8 ppm vs GM.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_ota: GET /api/ota (version, project, build_date, idf, running,
previous, previous_version, pending_verify, can_rollback), POST
/api/ota streamed into the inactive slot (4 KiB chunks), POST
/api/ota/confirm and /api/ota/rollback.
- Rejected before any flash write: bad magic, wrong chip, wrong
project_name, chip revision outside the image's min/max range.
esp_ota_end verifies the whole image.
- Self-test on a pending image: IP address plus HTTP 200 from our own
/api/status within 60 s marks it valid; otherwise mark invalid and
reboot into the previous slot. A crash before that is rolled back by
the bootloader.
- CONFIG_AES67_OTA_SELFTEST_FORCE_FAIL (test builds only) forces a
failed self-test.
- aes67_web: web_reboot_later() shared by /api/reboot and OTA.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_web/cfg.c: cfg_register(group, defaults, validate, apply),
cfg_override_defaults() for project defaults, cfg_get(). Stored values
are loaded on register and merged over defaults (known keys, matching
types). NVS keeps only keys that differ from defaults, one JSON string
per group, so new firmware defaults still reach untouched settings.
- POST /api/config: type check against defaults, per-group validation,
nothing stored unless every group passes; 400 "group.key: reason".
Unknown keys/groups are ignored. Returns the new config.
- Core groups registered by their components with the UI's ranges:
ptp (aes67_ptp), aes67 (aes67_tx, incl. multicast range and mono_sum
=> 1 channel), net/inet (aes67_net), log (aes67_syslog).
- Project: PROJECT.def overrides (hostname p4-aes67, name P4 AES67) and
the "source" group in main/project_cfg.c.
- Config is stored only; nothing is applied live yet.
- Verified on board: defaults, valid save, 8 rejected values (nothing
stored), persistence across reboot, restore to defaults.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_web: httpd (wildcard URI matching), serves web/index.html embedded
via EMBED_TXTFILES, status registry (status_register) and route registry
(web_register_uri), GET /api/status, POST /api/reboot (restarts 0.5 s
after the response).
- Status fields come from each core component: aes67_net (ip, aes67_ip,
mac, link), aes67_health (fw, uptime_s, heap_free, psram_free),
aes67_tx stub (tx_packets, underruns = 0). No ptp object yet, so the UI
shows "no data".
- Verified on board: / serves index.html byte-identical (27601 B),
/api/status returns live values, reboot via API returns in ~12 s.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_board: Waveshare ESP32-P4-ETH pin profile and EMAC + IP101 driver
install (PHY addr 1, reset GPIO51, ref clock in on GPIO50).
- aes67_net: Ethernet netif with DHCP client; logs link up/down (speed,
duplex, MAC) and the DHCP lease.
- Verified on board: 100 Mbps full duplex, DHCP lease in ~8 s, ping
0% loss, ~0.2 ms RTT.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Board checked with esptool: ESP32-P4 rev v1.3 (engineering silicon),
32 MB GigaDevice flash. Rev <3 support and 32 MB set in sdkconfig.defaults.
- OTA partition layout: nvs, otadata, phy_init, ota_0/ota_1 (6 MB each,
below 16 MB), coredump; no factory app. Partition table at 0x10000 so
the bootloader can grow.
- App rollback enabled in the bootloader from the start.
- PROJECT_VER from git describe --tags --always --dirty.
- Empty stubs for the nine aes67_* core components; main logs version
and chip revision.
- Built with ESP-IDF v5.5.5; not yet flashed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>