Source:
FirmwareUpdateModule.h
FirmwareUpdateModule¶
The install's live progress, shared by every path that can start one.
Functions¶
| Return | Name | Description |
|---|---|---|
bool |
otaInFlight inline |
Whether an install is running, which both flash paths gate their refusal on. |
otaInFlight¶
inline
Whether an install is running, which both flash paths gate their refusal on.
Variables¶
| Return | Name | Description |
|---|---|---|
constexpr const char * |
kReleaseRepo constexpr |
Where this project's releases live, tried FIRST so a device needs no redirect. |
constexpr const char * |
kFallbackRepo constexpr |
The repository's earlier name, which GitHub redirects, tried where the address above does not answer: one repository in both constants leaves a device nowhere to look. |
constexpr const char * |
kReleaseAssetUrlFormat constexpr |
The release-asset URL a device updates itself from: repository, version, firmware variant, version. |
char |
g_otaStatus |
the phase the install is in, shared by every unit |
uint32_t |
g_otaBytesRead |
how much has been written |
uint32_t |
g_otaBytesTotal |
the image size, zero until it is known |
kReleaseRepo¶
constexpr
Where this project's releases live, tried FIRST so a device needs no redirect.
kFallbackRepo¶
constexpr
The repository's earlier name, which GitHub redirects, tried where the address above does not answer: one repository in both constants leaves a device nowhere to look.
kReleaseAssetUrlFormat¶
constexpr
constexpr const char * kReleaseAssetUrlFormat =
"https://github.com/%s/releases/download/v%s/firmware-%s-v%s.bin"
The release-asset URL a device updates itself from: repository, version, firmware variant, version.
g_otaStatus¶
the phase the install is in, shared by every unit
g_otaBytesRead¶
how much has been written
g_otaBytesTotal¶
the image size, zero until it is known
FirmwareUpdateModule¶
src/core/system/FirmwareUpdateModule.h:86Inherits:
MoonModule
The status surface for over-the-air flashing: what is installed, and how an install goes.
The flash itself is driven by the web route, which hands a URL to the platform task. This module polls that task's progress once a second into its own controls.

@moreinfo
What the controls describe¶
The version is pure semver, so the channel is derivable rather than mixed into it. The build carries the git id first, since that answers which code is on a board. The partition bar shows the image filling its slot, or the incoming one mid-install. Where a device carries two images, a selector says which the rest describe.
Progress is not a control: it drives the overlay raised during an install. The phase is not one either, surfacing through the shared status slot.
Installing¶
The task downloads, writes the next slot, flips the boot pointer, and restarts. The pause before that restart is long enough for the response to reach the browser. Every failure reports through the status slot and stays until the next attempt. A wrong image fails at the start or at boot, and is recoverable over USB. On a device with one app slot the recovery image installs and reboots back.
Public Methods¶
virtual inline bool respectsEnabled() const override
: Keep reporting whatever the toggle says, as the other fixed modules do.
virtual inline void setup() override
: Prime the buffers from the shared globals, then read the firmware identity.
inline void readMoonBaseVersion()
: Read which recovery image this device carries, since it drifts and a mismatch matters.
virtual inline void defineControls() override
: Declare one set of controls, describing whichever image the selector names.
virtual inline void onControlChanged(const char * controlName) override
: Rebuild the controls when the selector changes which image they describe.
virtual inline void tick1s() override
: Poll the install task's progress and phase into the bound buffers.
inline void publishStatus()
: Publish the phase on the shared slot, taking its severity from the text's own prefix.
More info¶
The status and the byte counters are inline globals rather than module state. The flash route and the platform's own task both write them, and both must see one instance. A module reading them reports the same install a socket handler started.
Two addresses, because a rename has to survive in the field¶
A device flashed before v5.0.0 asks the repository's earlier name forever, and GitHub's rename redirect is what carries it across. The update path names both addresses and takes whichever answers, so an in-field update rests on more than that redirect. The current name comes first: every device reaches it directly, and the earlier one is a second chance when that request fails. Fetching another project's firmware is prevented separately. The OTA compares an incoming image's own ESP-IDF descriptor against the names in FirmwareImage.h before a byte is written. An address answering with a stranger's release is refused rather than flashed.