src.nth.io/

summaryrefslogtreecommitdiff
path: root/main/ota.h
diff options
context:
space:
mode:
authorLuke Hoersten <[email protected]>2026-06-20 13:03:23 -0500
committerLuke Hoersten <[email protected]>2026-06-20 13:03:23 -0500
commit175dd50ba2a2a6c8d033a9fd4e91f4823f9e210a (patch)
tree2f41235b0a4792822f737953e6fa553383a7bd36 /main/ota.h
parent3729f04458e358fab7872b9590d9fdb012f5ddf9 (diff)
firmware: OTA firmware updates via POST /firmware + rollback
Streams the raw .bin to the inactive ota_0/ota_1 slot via esp_ota_*, flips otadata, replies 200, reboots after 500 ms. Single-shot guarded by atomic_flag (409 on concurrent). CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE armed: new images boot pending-verify and ota_arm_healthy_timer marks them valid after 30 s of healthy uptime; otherwise the bootloader reverts on next reset. /state gains ota_state.
Diffstat (limited to 'main/ota.h')
-rw-r--r--main/ota.h14
1 files changed, 14 insertions, 0 deletions
diff --git a/main/ota.h b/main/ota.h
new file mode 100644
index 0000000..a6f7c9b
--- /dev/null
+++ b/main/ota.h
@@ -0,0 +1,14 @@
+#pragma once
+
+#include "esp_err.h"
+
+// Arms a 30 s one-shot timer; on fire, if the running image is in
+// PENDING_VERIFY, calls esp_ota_mark_app_valid_cancel_rollback() so the
+// bootloader stops considering this image revertible. Safe to call when
+// rollback is disabled or when the image is already marked valid — both
+// are no-ops. Call once from app_main after http_api_start.
+void ota_arm_healthy_timer(void);
+
+// Returns a short tag for the running image's OTA state, suitable for
+// /state JSON. Never NULL.
+const char *ota_running_state_str(void);