From ba396daafb4f37a0635a448eec5a001861914884 Mon Sep 17 00:00:00 2001 From: Luke Hoersten Date: Sun, 14 Jun 2026 16:51:17 -0500 Subject: http_api: bump httpd stack to 8 KiB — POST /config was overflowing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit POST /config has ~2.4 KiB of stack locals (2 KiB body buffer + the scrypted URL + viewport name + cJSON parser frames) which overran the default 4 KiB httpd task stack and tripped the stack-protect canary mid-handler. The request body was applied to RAM + NVS, but the handler crashed before sending the response, so curl saw a connection reset and the device rebooted into "Stack protection fault". M4 + M6 ✅ verified 2026-06-14 after the bump: - POST /config full / partial → 204; survives reboot via NVS - 5 validation failure modes → 400 - POST /state wake/sleep → 204; idempotent repeats → 204 - POST /frame while asleep → 409 with expected body - idle timer fires after idle_timeout_ms; 0 correctly disables --- TESTING.md | 8 ++++---- main/http_api.c | 5 +++++ 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/TESTING.md b/TESTING.md index a0c0a19..43bbe75 100644 --- a/TESTING.md +++ b/TESTING.md @@ -23,9 +23,9 @@ Status legend: | M1 | Board Bring-Up — Ethernet + DHCP | ✅ | ✅ | | M2 | HTTP + mDNS (`GET /state`) | ✅ | ✅ | | M3 | Display Bring-Up (Hosyond panel) | ✅ | ✅ | -| M4 | Config Persistence (NVS, partial updates) | ✅ | 🟡 | +| M4 | Config Persistence (NVS, partial updates) | ✅ | ✅ | | M5 | JPEG Frame Push (`POST /frame`) | ✅ | 🟡 | -| M6 | State + Idle Timer (`POST /state`, 409 guard) | ✅ | 🟡 | +| M6 | State + Idle Timer (`POST /state`, 409 guard) | ✅ | ✅ | | M7 | Touch + Outbound `/state` POST | ✅ | ✅ | | M8 | Local Screens + touch long-press | ✅ | ✅ | | M9 | Live Stream (`POST /stream`) | ⬜ | ⬜ | @@ -302,7 +302,7 @@ Side-effects to confirm: - After `POST /config` with `viewport` or `orientation`: mDNS TXT records update; `viewport-.local` resolves; browse shows new TXT. - After `POST /config` with both `viewport` and `scrypted` (any order, on any subsequent call): `GET /state` shows `configured: true`, `state: "asleep"`. -**Status**: 🟡 builds clean against ESP-IDF 5.4. Logic exercised in code but unverified on hardware. +**Status**: ✅ verified 2026-06-14. Full POST + partial POST + 5 validation failure modes all returned correctly. Config survives reboot (NVS persistence). `configured: true` was set automatically once both `viewport` and `scrypted` were supplied. Required raising httpd stack from 4 KiB to 8 KiB — the handler's 2 KiB body buffer plus locals were overflowing into the protect page. --- @@ -486,7 +486,7 @@ curl -i -X POST -d 'not json' \ **Known gap (M7 closes this)**: when the idle timer fires the device transitions to ASLEEP locally but does NOT yet POST `{viewport,state:sleep}` to `/state`. That outbound POST lands with `state_client` in M7. -**Status**: 🟡 builds clean against ESP-IDF 5.4. Awaiting hardware. +**Status**: ✅ verified 2026-06-14. Wake/sleep toggle 204, idempotent repeats 204, `/frame` while asleep returns 409 with expected body, bad inputs 400, idle timer fires after `idle_timeout_ms`, `idle_timeout_ms:0` correctly disables the timer. --- diff --git a/main/http_api.c b/main/http_api.c index b3378b5..5b5769a 100644 --- a/main/http_api.c +++ b/main/http_api.c @@ -451,6 +451,11 @@ esp_err_t http_api_start(void) cfg.server_port = 80; cfg.max_uri_handlers = 8; cfg.lru_purge_enable = true; + // Default 4 KiB is tight: /config alone has ~2.4 KiB of stack locals + // (2 KiB body buffer + 256 B scrypted URL + 64 B name + cJSON frames) + // and POST /frame pushes a JPEG header onto the stack too. 8 KiB gives + // both handlers comfortable headroom without doubling RAM usage. + cfg.stack_size = 8192; httpd_handle_t server = NULL; ESP_RETURN_ON_ERROR(httpd_start(&server, &cfg), TAG, "httpd_start"); -- cgit v1.2.3