feat: OTA relay, TLS serving, and wss migration for the realtime server #19
Loading…
Reference in a new issue
No description provided.
Delete branch "devel"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
OTA relay, TLS serving, and wss migration for the realtime server
Implements the computer-side of the OTA design
(
docs/specs/2026-09-10-ota-design.md, crew repo) — plan 2 of 4(crew, computer, communicator-esp32, communicator-sailfish).
What this adds
server.ota.schedulerelay (spec 6.3): aftersession.created, for adevice with an identity (
device_id) and a pending firmware update, theserver sends one
{"type": "server.ota.schedule", "data": {"version", "url"}}event. The lookup is bounded to 2 s, never blocks the session, anda crew outage degrades to "no update event" — it can never break the
session. The firmware image never transits this WebSocket.
firmware_versiondevice identity (spec 6.2): the device query stringgains
?device_id=<id>&device_type=esp32&firmware_version=<X.Y.Z>;DeviceRegistrystores and surfacesfirmware_versiononGET /internal/devices.--ws_tls_cert/--ws_tls_keyon the realtime/websocket server (uvicorn +WebSocketStreamer); partial cert/key config degrades to plaintext.gain
--ca-bundle/STARFLEET_CA_BUNDLE, switching towss://with ansslcontext pinned to the local CA (hostname validation preserved) whenset; plaintext defaults unchanged.
CONFORMANCE.mdand the conformance fake server gains theserver.ota.schedulescenario before the router work.Notes
local_audio_streamer.pyis in the spec change matrix but needs no change(pure sounddevice path, no network code).
tests/test_realtime_client.pyand a mypy annotation fix insrc/computer/TTS/omnivoice_flashinfer.py.firmware_version;the field defaults to empty and has no effect.
Follow-ups in the design still to land:
communicator-esp32(partitions, ota module, wss + embedded CA, release tooling) and
communicator-sailfish(wss migration).