Repository navigation
Commit c560df9
committed
Fix OTA silently transferring a zero-length image
DfuService::OnServiceData arms the 10s one-shot inactivity timer before
dispatching each access. The image-size write then calls DfuImage::Erase(),
which erases the whole image slot a sector at a time and takes tens of
seconds. That timer runs on the FreeRTOS timer task, so it fires part-way
through the erase and calls Reset(), zeroing applicationSize.
The erase then finishes and the handler carries on regardless: it sets
state = Init and reports success. ReceiveFirmwareImage later calls
dfuImage.Init(20, 0, crc), so IsComplete() -- totalWriteIndex == totalSize,
now 0 == 0 -- is already true when the first data packet arrives. The watch
tells the host the entire image has been received, emits no packet-receipt
notifications, writes nothing to flash, and validation CRCs zero bytes.
From the host side this looks like an instant "whole image received" reply
a fraction of a second after Begin DFU, followed by a validation failure -
with no indication that the erase timed out. Recovery mode is unaffected
because its erase is fast enough to finish inside the 10s window, which is
why OTA can fail from the running firmware while succeeding from recovery.
Stop the timer around the erase and restart it afterwards.
Tested on a PineTime: before this change every OTA update from the running
firmware failed as described; after it, updates complete and validate
normally without needing recovery mode.1 parent 71d1f5b commit c560df9
1 file changed
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
148 | 153 | | |
| 154 | + | |
149 | 155 | | |
150 | 156 | | |
151 | 157 | | |
| |||
0 commit comments