Source:
FirmwareImage.h
FirmwareImage¶
What an ESP32 firmware image says about itself, read without ESP-IDF.
Classes¶
| Name | Description |
|---|---|
ImageInfo |
What an image says about itself. Empty strings when the descriptor is absent or unreadable. |
ImageInfo¶
src/core/util/FirmwareImage.h:72What an image says about itself. Empty strings when the descriptor is absent or unreadable.
Public Attributes¶
bool valid = false
: begins with the image magic
bool described = false
: carries a readable app descriptor
ChipId chip = ChipId::Invalid
: which chip the image header names
char project = {}
: one of kAppImageNames or kMoonBaseImageNames
char version = {}
: the app version string the descriptor carries
More info¶
Why the layout is redefined here¶
The layout is a fixed on-disk format the bootloader parses: magic, chip id, then the app descriptor carrying the project name and version. Those are the same bytes whether they arrive on a device or in a test. Defining it here rather than including esp_app_format.h is what lets the vetting run in a host test, which matters because the code it guards erases a device's only recovery image. unit_FirmwareImage pins the layout against real binaries built by the ESP32 toolchain.
The three ways an image can be wrong¶
moonBaseRejection tests them in the order they are cheapest to detect:
| Reason | What it usually is |
|---|---|
| not an image | a 404 body, an HTML error page, a .zip |
| the wrong chip | one MoonBase per chip, one paste apart, and a checksum will not catch it |
| not MoonBase | an app image, which sits beside it on the releases page |
Two names, because a device refuses a name it does not know¶
An image carries its ESP-IDF project name in its descriptor, and every install path checks it before a byte is written. A device accepts only the names compiled into it, so a build that ships under a new name is refused by everything in the field. The name therefore changes in two releases: this one knows both and still ships under the first, and the next one ships under the second. kAppImageNames and kMoonBaseImageNames hold the pair, first the name a build carries today.
A download that goes silent¶
ESP-IDF's OTA read reports a timeout as "still in progress", so a connection that stops delivering bytes without closing keeps an install waiting for good. Both install loops, the app's and MoonBase's, therefore abort once no byte has arrived for kDownloadStallMs.