feat(app_update): Add auto-confirmation of OTA updates

Enable rollback auto-confirmation by default
This commit is contained in:
Konstantin Kondrashov
2026-09-01 12:53:21 +03:00
committed by Konstantin Kondrashov
parent dce5812654
commit de1e5035b5
27 changed files with 351 additions and 70 deletions
@@ -1,6 +1,7 @@
# Generic config
CONFIG_BOOTLOADER_SKIP_VALIDATE_IN_DEEP_SLEEP=y
CONFIG_EXAMPLE_EXT1_WAKEUP=n
CONFIG_PARTITION_TABLE_OFFSET=0x9000
CONFIG_LIBC_TIME_SYSCALL_USE_RTC_HRT=y
CONFIG_RTC_CLK_SRC_INT_RC=y
+2 -2
View File
@@ -138,9 +138,9 @@ If you want to rollback to the `factory` app after the upgrade (or to the first
## Supporting Rollback
This feature allows you to roll back to a previous firmware if new image is not usable. The menuconfig option `CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE` allows you to track the first boot of the application (see the ``Over The Air Updates (OTA)`` article).
This feature allows you to roll back to a previous firmware if new image is not usable. The menuconfig option `CONFIG_BOOTLOADER_APP_ROLLBACK_CONFIRM_BY_APP` allows you to track the first boot of the application (see the ``Over The Air Updates (OTA)`` article).
The ``native_ota_example`` contains code to demonstrate how a rollback works. To use it, enable the `CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE` option in the `Example Configuration` submenu of menuconfig to set `Number of the GPIO input for diagnostic` to manipulate the rollback process.
The ``native_ota_example`` contains code to demonstrate how a rollback works. To use it, enable the `CONFIG_BOOTLOADER_APP_ROLLBACK_CONFIRM_BY_APP` option in the `Example Configuration` submenu of menuconfig to set `Number of the GPIO input for diagnostic` to manipulate the rollback process.
To trigger a rollback, this GPIO must be pulled low while the message `Diagnostics (5 sec)...` is displayed during the first boot.
@@ -379,7 +379,7 @@ void app_main(void)
*/
ESP_ERROR_CHECK(example_connect());
#if defined(CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE)
#if defined(CONFIG_BOOTLOADER_APP_ROLLBACK_CONFIRM_BY_APP)
/**
* We are treating successful WiFi connection as a checkpoint to cancel rollback
* process and mark newly updated firmware image as active. For production cases,
@@ -8,7 +8,7 @@ CONFIG_PARTITION_TABLE_FILENAME="anti_rollback_partition.csv"
CONFIG_PARTITION_TABLE_OFFSET=0xd000
CONFIG_ESPTOOLPY_FLASHSIZE_4MB=y
CONFIG_ESPTOOLPY_FLASHSIZE="4MB"
CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE=y
CONFIG_BOOTLOADER_APP_ROLLBACK_CONFIRM_BY_APP=y
CONFIG_BOOTLOADER_APP_ANTI_ROLLBACK=y
CONFIG_BOOTLOADER_APP_SECURE_VERSION=1
CONFIG_EXAMPLE_CONNECT_ETHERNET=y
@@ -141,7 +141,7 @@ static esp_err_t unsafe_bootloader_ota_update(esp_https_ota_config_t *ota_config
const esp_partition_t *primary_bootloader;
ESP_ERROR_CHECK(register_partition(ESP_PRIMARY_BOOTLOADER_OFFSET, ESP_BOOTLOADER_SIZE, "PrimaryBTLDR", ESP_PARTITION_TYPE_BOOTLOADER, ESP_PARTITION_SUBTYPE_BOOTLOADER_PRIMARY, &primary_bootloader));
const esp_partition_t *ota_partition = esp_ota_get_next_update_partition(NULL); // free app ota partition will be used for downloading a new image
#if CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE
#if CONFIG_BOOTLOADER_APP_ROLLBACK_CONFIRM_BY_APP
// Check if the passive OTA app partition is not needed for rollback before using it for other partitions.
// The same can be done for partition table and storage updates.
esp_ota_img_states_t ota_state;