- OTA: the player now ends the Spotify session (spotify_suspend: stop
flag, waits until the session's tasks are gone, refuses new ones)
instead of pausing it, and suspends HLS. Pausing was not enough (an
upload still failed once with a paused session). Verified twice with a
session running for minutes: "Disconnecting mercury session / session
ended / suspended", installed in ~26 s, clean reboot.
- Volume: createFromBlob() starts cspot at volume 0, which the app
showed while we played at 100 %. The session now starts with the
player's volume (spotify_set_volume); volumes coming from the app are
stored exactly, without echo. Verified: slider starts at 100 %.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- spotify_init() sets up the logger, zeroconf routes and session task
once; spotify_apply() (at boot and on every source save) enables or
disables: enabled = mode spotify/auto + credentials. Disable removes
the mDNS entry, zeroconf answers 404 and a running session ends
(loop exits within 200 ms, SpircHandler::disconnect stops the queue
and player tasks). A new device name ends the session and
re-advertises. The login blob is swapped under a mutex.
- Verified: hls/spotify/rename switch the mDNS entry and /spotify_info
(404/200) live; switching to hls during Spotify playback ended the
session in < 2 s, HLS played after ~5 s, internal heap 221 -> 365 KB
(cspot frees everything).
- CLAUDE.md: OTA-with-session findings (intermittent, flash-write stalls
seen as TX resyncs during uploads), serial-port reset caveat.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An upload during an active Spotify session crawled (~10 kB/s, 197 s)
and ended in a reset (seen twice). Workaround:
- aes67_ota_on_update(cb): cb(true) right before an accepted upload
writes flash, cb(false) if it then fails.
- The player pauses Spotify (spotify_pause -> SpircHandler::setPause, the
app follows) and suspends HLS fetching (hls_suspend); resumed if the
upload fails. AES67 TX keeps running (silence).
- Verified: upload during Spotify playback paused the session and
installed in 25.8 s (normal for 2 MB), clean reboot and self-test.
Root cause still open (noted in CLAUDE.md with the other cspot items).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- spotify_init(pcm_cb, event_cb): cspot's data callback hands 44.1 kHz
stereo s16 PCM to the player and returns what was taken; the player's
blocking ring write paces decoding to playback speed.
- Events: FLUSH/SEEK/PLAYBACK_START empty the ring (skip/seek sound at
once); PLAY_PAUSE pauses output (silence, buffer kept, no underrun);
VOLUME logged (applied in b4).
- player: Spotify via its own audio_out converter (44.1 -> 48 kHz);
source_state playing / paused / buffering.
- Verified from a Mac: music on the AES67 stream (10 s: 0 gaps, no
silent packets, RMS -9.6 dBFS, peak 0.0 dBFS), buffer 4.0 s full,
0 underruns, pause/play/skip/seek events.
Seen: first 3 connects "Can't connect to spotify servers", 4th worked.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Zeroconf on our httpd (GET/POST /spotify_info, form body URL-decoded)
and _spotify-connect._tcp via our mDNS (VERSION, CPath, Stack TXT).
- Session task: waits for the app's login blob, connects with the
user's client ID/secret and the configured bitrate (96/160/320 ->
OGG_VORBIS_*), SpircHandler, events logged; cspot exceptions caught.
Starts when source.mode is spotify/auto and credentials are set.
- bell::bellGlobalLogger was NULL: every CSPOT_LOG crashed the board
right after addUser (Load access fault in Session.cpp:67 /
LoginBlob.cpp:58). cspot/bell logs now go to esp_log (UART + syslog);
signed CDN URL tokens are cut from the log.
- esp_audio_codec's own Vorbis decoder clashed with bell's Tremor
symbols: CONFIG_AUDIO_DECODER_VORBIS_SUPPORT / SIMPLE_DEC_OGG off.
- status.spotify_state from the session (waiting / connecting /
connected / login failed / error / disabled / no client credentials).
- Verified from a Mac: device appears, "connected as <user>", access
token fetched with the user's client credentials, track info, audio
key, CDN URL (the step broken upstream), PCM decoded. Without
backpressure a track decodes in ~26 s (b3 feeds the ring).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Core config: cfg_mark_secret(group, key). GET /api/config returns ""
for secret keys; a POST with "" keeps the stored value, null clears it;
cfg_get() returns the real value. Documented in aes67-core-base.md.
- source.spotify_client_id / spotify_client_secret (secret write-only):
each user's own Spotify developer app, needed by the maintained cspot
fork (philippe44/cspot) since Spotify's 2025 API restrictions.
- UI: client ID field, password field for the secret ("leave empty to
keep"), link to developer.spotify.com; enabled for spotify/auto modes.
- status.spotify_state: "no client credentials" while either is missing.
- Verified: secret never appears in GET; UI-style re-save keeps it;
survives reboot; null clears it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- As TimeReceiver in ptp.mode hybrid: Delay_Req unicast to the GM (IP
from its Announce, MAC recorded by the RX hook from its Sync frames),
unicastFlag set.
- As TimeTransmitter: a Delay_Req with the unicastFlag gets a unicast
Delay_Resp; multicast requests get multicast replies.
- EMAC timestamps every received frame (en_ts4all): its PTP filter left
unicast Delay_Req unstamped ("no HW RX timestamp").
- A unicast Delay_Resp's logMessageInterval 0x7F is ignored (use
ptp.log_delay_req); log_us() clamps to -7..6 (the shift was undefined).
- Verified vs ptp4l --hybrid_e2e 1: board hybrid TimeReceiver 18
Delay_Req in 20 s, all answered, locked; board TimeTransmitter
(p1 100): tcpdump shows Sync/Follow_Up/Announce to 224.0.1.129,
Delay_Req 192.168.192.233 -> .244 [unicast] and Delay_Resp .244 ->
.233 [unicast] within 0.4 ms; ptp4l s2.
- Docs: TimeTransmitter/hybrid notes; step 6 ticked.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_cfg: cfg_set_number(group, key, value, apply) for firmware-side
changes, stored in NVS like a POST; apply can be skipped.
- aes67_sdp_sap: once a second, a change of the PTP GM (ts-refclk) bumps
aes67.session_ver without re-applying the aes67 group (no stream
restart); SAP then re-announces. Runs whether or not SAP is on.
- Verified with ptp4l as a normal clock (p1 128): board auto (p1 250)
steps down to SLAVE (session_ver 1->2); role master p1 100 via API ->
board MASTER at once (->3); back to auto p1 250 -> ptp4l takes over
within ~1 s, board SLAVE again (->4).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Own dataset from config: slave -> class 255, never TimeTransmitter;
auto/master -> class 248 with ptp.priority1/2; accuracy 0xFE, variance
0xFFFF, timeSource 0xA0, clockIdentity EUI-64 from MAC.
- BMCA: a foreign TimeTransmitter is followed only if its Announce beats
our dataset (always for slave-only); if the followed one turns worse we
take over; a better one makes us step down. LISTENING -> MASTER after
announceReceiptTimeout x our announce interval.
- MASTER: Announce (PTP timescale flag) every 2^log_announce, two-step
Sync every 2^log_sync (raw frame, HW TX time in Follow_Up), Delay_Resp
for each Delay_Req with its HW RX time and logMessageInterval =
log_delay_req. Frequency correction kept (holdover).
- ptp config applies live (role, priorities, intervals, domain, DSCP).
- status.ptp: state MASTER, gm_id = own, TX Sync/Announce intervals,
Delay_Req/Resp counters; locked is true as master so AES67 TX keeps
running; SDP ts-refclk and SAP follow.
- Verified: with ptp4l GM p1 128 the board (auto, p1 250) stays SLAVE;
ptp4l stopped -> board MASTER; ptp4l -s --priority1 255 locks to it
(s2) in ~4 s, offset within +-320 ns, path delay 10.3 us.
Known: Sync send times jitter ~10 ms (FreeRTOS tick); accuracy is not
affected (two-step Follow_Up carries the exact HW time).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_health: status.temps = [{name, c, min_c, max_c, warn_c}]
(0.1 °C), sampled every 2 s by a health task. On-die "SoC" sensor via
driver/temperature_sensor.h, range 20..100 °C, warn at 85 °C.
health_temp_register(name, read_cb, warn_c) for board sensors.
Warning logged when crossing warn_c, cleared below warn_c - 5 °C.
- Verified: SoC 26-28 °C at idle with min/max since boot; with a
temporary 27 °C threshold the warning was logged and arrived via
syslog as <132>, status carried warn_c 27.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
httpd_txrx warned on every client reset (errno 104) and httpd_uri on
every 404 (the UI polls /api/player every 2 s until step 7), flooding
syslog. Both set to error level; our handlers log the 4xx that matter.
Remaining known line: 'httpd_resp_send_err: error calling setsockopt :
22' (error level) when a client closes right after a 4xx; a harmless
race in IDF's CONFIG_HTTPD_ERR_RESP_NO_DELAY handling, the response is
already delivered.
Verified via syslog: 10 status + 10 /api/player requests, no httpd lines.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
After a clock step, status.ptp showed the whole step (~1.79e18 ns) as
offset_ns until the next Sync, and the 60 s summary reported it as
max |offset|. Offset is reset to 0 and the summary restarts on a step.
Verified: status goes 0 -> pull-in values; first summary max 24960 ns.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_syslog: esp_log_set_vprintf hook chained to the UART; formats
into a static buffer under a zero-timeout mutex (drop and count when
busy), strips ANSI codes, parses level/tag, filters by log.level and
queues (48 messages, non-blocking). Low-priority sender task: RFC 5424
(<PRI>1 - HOST APP - - - MSG, no timestamp yet) or RFC 3164
(<PRI>HOST TAG: MSG), PRI = facility*8 + severity; log.host as IP or
resolved name; config applies live. Messages wait in the queue until
the interface has an IP. POST /api/log/test sends an info message
regardless of the level filter.
- Initialised first in app_main so boot messages are captured; the UDP
socket is created only once the interface is up (creating it before
esp_netif_init crashed at boot and the bootloader rolled back).
- Verified with a UDP listener: 5424 and 3164 formats, PRI 134/132,
boot messages delivered after the IP came up, shutdown messages sent
before reboot, level filter, test message, host by DNS name.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_sdp_sap: SAP (RFC 2974) announcer task. SAPv1 to
239.255.255.255:9875 every 30 s and within 1 s of any SDP change
(config save, GM change), with the old hash deleted first. Active while
aes67.discovery = sap, the stream is enabled, the AES67 interface has
an IP and a PTP GM is known. Deletion when that stops and at shutdown
(reboot/OTA) via a shutdown handler. TTL = aes67.ttl.
- Docs: SAP implementation notes; session_ver bump on GM change still open.
- Verified with a SAP listener: 30 s repeats with a stable hash; rename
-> delete old + announce new (o= version follows); manual -> delete;
sap -> announce; reboot and OTA -> delete at shutdown, first announce
after boot only once the GM is known.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The periodic TX timer had an arbitrary phase against packet boundaries,
so packets waited up to one packet time (different after every restart).
- One-shot esp_timer aimed at the next packet's due time from PTP, with
the clock re-read after sending.
- 1 kHz tone from a per-rate lookup table (one period = rate/1000
samples) instead of sinf() per sample.
Measured (RTP time - arrival, 4 ms vs 1 ms packets, expected -3.07 ms
incl. wire time): -3.3 ms extra before, now -3.14 ms. Tone within
1.0 LSB of the ideal PTP-phased sine, no gaps.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_tx: TX task woken by an esp_timer every packet time; sends every
packet whose last sample is in the past (PTP time), RTP ts =
(sample index from PTP + clk_offset) mod 2^32, packets aligned to
multiples of the packet size. Sends only while PTP is locked; resyncs
on lock, clock step or > 20 ms lag. L24/L16 big-endian, TTL/DSCP/
multicast IF from config; a config save restarts TX.
- Built-in 1 kHz tone at -18 dBFS, phase from the PTP sample index;
aes67_tx_set_source() pull callback for later sources (underruns
counted, padded with silence). status: tx_packets, underruns.
- Verified with a receiver script on the PC: 1 ms L24 stereo 1000/s,
0 gaps, ts step 48, tone -18.00 dBFS within 1.2 LSB of the ideal
PTP-phased sine; also L16 mono 0.333 ms, 0.125 ms (8000/s) and 4 ms.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_sdp_sap: aes67_sdp_build() builds the AES67 SDP (RFC 4566 +
RFC 7273) with the same lines and order as the web UI preview;
GET /stream.sdp serves it as application/sdp.
- aes67_ptp: public aes67_ptp_gm_id(), aes67_ptp_locked(),
aes67_ptp_now_ns(). Clock IDs are now uppercase (RFC 7273 style), also
in status.ptp, which the UI copies into ts-refclk.
- aes67_net: aes67_net_netif() returns the AES67 interface.
- Verified on board: /stream.sdp byte-identical to the UI's sdp() for
the same config/status; mono, L16, ptime 0.333, ttl 8, clk_offset
4294967295 and session_ver all follow the config.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ptp_clock_status() adds status.ptp: state (LISTENING / UNCALIBRATED /
SLAVE), locked, gm_id, offset_ns, freq_ppb, path_delay_ns +
path_delay_sd_ns (window of 64, from lock on), steps_removed,
gm_time/freq_traceable, version, own_class (255 slave / 248 auto,
master), clock_id, gm_class/accuracy/p1/p2, sync_avg/min/max_ms and
sync_jitter_us (HW Sync intervals), announce_avg_ms, delay_req/resp
counters, hw_ts, window. Snapshot under a mutex shared with the PTP task.
- Per-Sync log moved to debug; info level logs state changes plus a
60 s summary (max |offset|, freq, delay).
- Verified vs ptp4l: LISTENING -> UNCALIBRATED -> SLAVE in ~35 s;
locked offset within a few hundred ns, delay 10.27 us +-0.20 us,
Delay_Req/Resp 69/69, Sync avg 1000.097 ms, Announce avg 2000 ms.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ptp_hw: ptp_hw_adj_freq() (ETH_MAC_ESP_CMD_ADJ_PTP_TIME, absolute ppb
vs nominal, clamped +-500 ppm, retried while the addend update is
busy) and ptp_hw_step() (read + write time).
- ptp_clock: first Sync after a GM is selected seeds the integral with
the measured rate and steps the clock; then linuxptp-style PI (kp/ki
from the Sync interval: 0.7/0.3 at 1 s). Re-step above 1 ms. Locked
after 8 Syncs with |offset| < 1 us, unlocked after 3 above; GM change
or loss unlocks and keeps the frequency (holdover).
- Verified vs ptp4l: stepped to GM time, locked after ~19 s; locked
offset within +-510 ns (mostly < 300 ns), correction +39.9 ppm
(crystal -39.8 ppm), path delay ~10.2 us.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ptp_clock.c replaces the 3.1 logger: UDP/IPv4 multicast, E2E.
Announce: IEEE 1588 dataset comparison picks the best GM, dropped after
announceReceiptTimeout x its announce interval. Sync/Follow_Up (two-step
and one-step) with HW t2 and correctionField. Delay_Req sent as a raw
frame (DSCP ptp.dscp, TTL 1, clockIdentity = EUI-64 from MAC) with HW
TX timestamp t3, randomised at the GM's Delay_Resp interval; Delay_Resp
matched on requestingPortIdentity + seq.
- Path delay corrected for offset drift between t2 and t3 (rate from
consecutive Syncs) so it is right before the clock is syntonised.
- ptp_hw: ptp_hw_send_event() builds Eth/IPv4/UDP 319 and returns the HW
TX timestamp.
- Verified vs ptp4l (i210 GM, HP 2530 non-PTP switch, PC 1G / board 100M):
GM selected, path delay settles at ~10.3 us and stays flat, rate
-39.8 +-0.4 ppm, offset drifts at -40 us/s (no servo yet).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_ptp/ptp_hw.c: start the EMAC IEEE 1588 clock (IDF
ETH_MAC_ESP_CMD_PTP_ENABLE) and additionally enable snapshots for
PTP over UDP/IPv4 (IDF only enables PTP over Ethernet/L2). An RX hook
on the driver's info input path records {type, seq, sourcePortId, HW
timestamp} of port-319 PTPv2 event messages, then hands every frame to
lwIP unchanged.
- aes67_ptp.c: temporary 3.1 logger joins 224.0.1.129:319/320 and pairs
Sync HW RX timestamps with Follow_Up origin timestamps.
- Checked against linuxptp ptp4l (-4 -E -H, Intel igb) as GM: every Sync
has a HW timestamp; HW Sync intervals track the GM intervals with a
constant -39.8 us/s (+-0.3 us), i.e. local clock -39.8 ppm vs GM.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GET /api/ota listed a half-written upload or a rolled-back image as
'previous'. Only report it when esp_ota_check_rollback_is_possible().
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_ota: GET /api/ota (version, project, build_date, idf, running,
previous, previous_version, pending_verify, can_rollback), POST
/api/ota streamed into the inactive slot (4 KiB chunks), POST
/api/ota/confirm and /api/ota/rollback.
- Rejected before any flash write: bad magic, wrong chip, wrong
project_name, chip revision outside the image's min/max range.
esp_ota_end verifies the whole image.
- Self-test on a pending image: IP address plus HTTP 200 from our own
/api/status within 60 s marks it valid; otherwise mark invalid and
reboot into the previous slot. A crash before that is rolled back by
the bootloader.
- CONFIG_AES67_OTA_SELFTEST_FORCE_FAIL (test builds only) forces a
failed self-test.
- aes67_web: web_reboot_later() shared by /api/reboot and OTA.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_net: esp_netif_set_hostname() before the interface starts, and
in the net apply callback (takes effect at the next lease renewal).
- Verified: the router's DNS (lan.apointless.space) resolves p4-aes67
to 192.168.192.244.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_net/lldp.c: IEEE 802.1AB LLDPDU sent as a raw frame with
esp_eth_transmit every 30 s (TTL 120 s) and immediately on a new IP
or hostname change. TLVs: chassis/port ID (MAC), port description,
system name (net.hostname), system description (project + version),
capabilities station-only, IPv4 management address.
- Docs: LLDP in the core Network section; step 2a ticked.
- Verified on an HP 2530-8G-PoE+ (show lldp info remote-device 2): all
fields shown, management address 192.168.192.244.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_net: espressif/mdns 1.13.1 (managed component, pinned in
dependencies.lock). Advertises <net.hostname>.local and the web UI as
_http._tcp port 80. net apply callback renames live.
- First config value actually applied: net.hostname.
- Docs: mDNS in the core Network section; build order gets step 2a
(mDNS, then LLDP).
- Verified on board: p4-aes67.local resolves via raw mDNS and getent,
http://p4-aes67.local/ answers, service shows in _http._tcp browse;
live rename to p4-rename and back works (after ~1 s probing).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_web/cfg.c: cfg_register(group, defaults, validate, apply),
cfg_override_defaults() for project defaults, cfg_get(). Stored values
are loaded on register and merged over defaults (known keys, matching
types). NVS keeps only keys that differ from defaults, one JSON string
per group, so new firmware defaults still reach untouched settings.
- POST /api/config: type check against defaults, per-group validation,
nothing stored unless every group passes; 400 "group.key: reason".
Unknown keys/groups are ignored. Returns the new config.
- Core groups registered by their components with the UI's ranges:
ptp (aes67_ptp), aes67 (aes67_tx, incl. multicast range and mono_sum
=> 1 channel), net/inet (aes67_net), log (aes67_syslog).
- Project: PROJECT.def overrides (hostname p4-aes67, name P4 AES67) and
the "source" group in main/project_cfg.c.
- Config is stored only; nothing is applied live yet.
- Verified on board: defaults, valid save, 8 rejected values (nothing
stored), persistence across reboot, restore to defaults.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_web: httpd (wildcard URI matching), serves web/index.html embedded
via EMBED_TXTFILES, status registry (status_register) and route registry
(web_register_uri), GET /api/status, POST /api/reboot (restarts 0.5 s
after the response).
- Status fields come from each core component: aes67_net (ip, aes67_ip,
mac, link), aes67_health (fw, uptime_s, heap_free, psram_free),
aes67_tx stub (tx_packets, underruns = 0). No ptp object yet, so the UI
shows "no data".
- Verified on board: / serves index.html byte-identical (27601 B),
/api/status returns live values, reboot via API returns in ~12 s.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- aes67_board: Waveshare ESP32-P4-ETH pin profile and EMAC + IP101 driver
install (PHY addr 1, reset GPIO51, ref clock in on GPIO50).
- aes67_net: Ethernet netif with DHCP client; logs link up/down (speed,
duplex, MAC) and the DHCP lease.
- Verified on board: 100 Mbps full duplex, DHCP lease in ~8 s, ping
0% loss, ~0.2 ms RTT.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Board checked with esptool: ESP32-P4 rev v1.3 (engineering silicon),
32 MB GigaDevice flash. Rev <3 support and 32 MB set in sdkconfig.defaults.
- OTA partition layout: nvs, otadata, phy_init, ota_0/ota_1 (6 MB each,
below 16 MB), coredump; no factory app. Partition table at 0x10000 so
the bootloader can grow.
- App rollback enabled in the bootloader from the start.
- PROJECT_VER from git describe --tags --always --dirty.
- Empty stubs for the nine aes67_* core components; main logs version
and chip revision.
- Built with ESP-IDF v5.5.5; not yet flashed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>