feat: OTA firmware updates (A/B partitions, signed manifests, wss) #11
Loading…
Reference in a new issue
No description provided.
Delete branch "devel"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
OTA firmware updates: A/B partitions, signed manifests, wss
Implements the communicator-esp32 side of the OTA design
(
starfleet/crew:docs/specs/2026-09-10-ota-design.md, §7-8) — plan 3 of 4(crew, computer, communicator-esp32, communicator-sailfish).
The device can now be updated over the air: it downloads a signed release
from crew over HTTPS, verifies an Ed25519 signature over the manifest and a
SHA-256 over the image, installs into the inactive A/B slot, and lets the
bootloader roll back if the new app does not confirm.
What this adds
partitions_ota16m.csv):otadata+ two 3 MB appslots (
ota_0/ota_1) + the existingmwwmodel partition (5000K). Theprevious single-slot table is kept as
partitions_sr16m.csvfor recovery.CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE=y.main/ota.c): HTTPS fetch ofmanifest.json+manifest.sig; the Ed25519 signature is checked over theexact manifest bytes before any flash write. The vendored
components/ed25519/provides the verify (this ESP-IDF's mbedTLS has noEd25519). The image is streamed in chunks into the update slot while a
SHA-256 is accumulated; size + digest must match the signed manifest before
the slot is marked bootable.
newer than both the running firmware and an NVS high-water mark, and only
when the URL is
https://.PENDING_VERIFYapp is marked valid on the firstIDLE entry or after 120 s; otherwise the bootloader rolls back.
main/ws_client.c): the realtime connectionuses
wss://with the embedded local CA, and reports?device_id=<mac>&device_type=esp32&firmware_version=<v>so crew canschedule updates.
tools/gen_ota_trust.sh(regeneratesmain/ota_trust.hfrom gitignoredtools/ota-keys/),tools/release_firmware.sh(builds, signs, publishes to crew), and aCONFIG_WS_TLStoggle withCONFIG_APP_PROJECT_VER.One-time migration (existing devices)
The partition layout changed, so each device needs a one-time USB reflash —
see the "One-time migration to A/B OTA" section added to
README.md(erase-flash +
idf.py flash+tools/flash_models.sh). After that,updates are over the air.
Notes
esp_app_updatedoes not exist in this ESP-IDF; the install usesesp_ota_begin/write/enddirectly.mwwmodel partition is untouched by app OTA and still updates viatools/flash_models.sh.project(... VERSION ...); the implementation usesCONFIG_APP_PROJECT_VER(release-time override), recorded insdkconfig.defaults.Rollout
Keys, the USB baseline flash and the TLS cutover are operational steps from
spec §10 and happen after this lands.