Define dual-OTA partition table with dsp blob slot.

Replace factory with ota_0/ota_1, otadata, and a dsp data partition on 4 MB flash; enable bootloader app rollback for future OTA work.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-07-07 08:57:05 +02:00
co-authored by Cursor
parent 2e44a166e1
commit 11ad6b43ad
5 changed files with 20 additions and 11 deletions
+1 -1
View File
@@ -517,7 +517,7 @@ Software/
├── AGENTS.md Doxyfile instructions.md ├── AGENTS.md Doxyfile instructions.md
├── CMakeLists.txt top-level ESP-IDF project ├── CMakeLists.txt top-level ESP-IDF project
├── sdkconfig.defaults C++23, exceptions off, flash/NVS encryption ├── sdkconfig.defaults C++23, exceptions off, flash/NVS encryption
├── partitions.csv includes an encrypted NVS partition ├── partitions.csv nvs, otadata, ota_0/ota_1, dsp blob, nvs_keys
├── .cursor/rules/*.mdc ├── .cursor/rules/*.mdc
├── main/ imperative shell entry (app_main) ├── main/ imperative shell entry (app_main)
├── components/ ├── components/
+1 -1
View File
@@ -120,7 +120,7 @@ Wire schemas: [`docs/manual/ch-api.tex`](docs/manual/ch-api.tex) · C++ API:
| `components/secure_store/` | Encrypted NVS: credentials, profiles, presets | | `components/secure_store/` | Encrypted NVS: credentials, profiles, presets |
| `components/net/` | Wi-Fi, HTTP server, gzipped web UI | | `components/net/` | Wi-Fi, HTTP server, gzipped web UI |
| `sdkconfig.defaults` | C++23, NVS + flash encryption (dev mode) | | `sdkconfig.defaults` | C++23, NVS + flash encryption (dev mode) |
| `partitions.csv` | `nvs` + `nvs_keys` partitions | | `partitions.csv` | `nvs`, `otadata`, dual OTA (`ota_0`/`ota_1`), `dsp` blob, `nvs_keys` |
| `docs/manual/` | LaTeX technical manual | | `docs/manual/` | LaTeX technical manual |
| `docs/security-flash-nvs.md` | Encryption + device HIL checklist | | `docs/security-flash-nvs.md` | Encryption + device HIL checklist |
| `docs/TODO.md` | Completed tasks + HIL backlog | | `docs/TODO.md` | Completed tasks + HIL backlog |
+1 -1
View File
@@ -8,7 +8,7 @@ preset index in the `digiradio` NVS namespace. Firmware **0.8.3+** enables:
| Flash encryption | `CONFIG_SECURE_FLASH_ENC_ENABLED` | On-chip transparent flash ciphertext | | Flash encryption | `CONFIG_SECURE_FLASH_ENC_ENABLED` | On-chip transparent flash ciphertext |
| Mode (default) | `CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT` | Plaintext download still allowed for bring-up | | Mode (default) | `CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT` | Plaintext download still allowed for bring-up |
| NVS encryption | `CONFIG_NVS_ENCRYPTION` | XTS-AES over NVS entries; keys in `nvs_keys` partition | | NVS encryption | `CONFIG_NVS_ENCRYPTION` | XTS-AES over NVS entries; keys in `nvs_keys` partition |
| Partition table | `partitions.csv` | `nvs` @ 0x9000, `nvs_keys` @ 0xf000 | | Partition table | `partitions.csv` | `nvs`, `otadata`, `ota_0`/`ota_1`, `dsp`, `nvs_keys` |
Implementation: `secure_store::initEncryptedStorage()` (called from Implementation: `secure_store::initEncryptedStorage()` (called from
`NetBootstrap` before any `NvsSecureStore` access). With `CONFIG_NVS_ENCRYPTION`, `NetBootstrap` before any `NvsSecureStore` access). With `CONFIG_NVS_ENCRYPTION`,
+13 -7
View File
@@ -1,7 +1,13 @@
# DigiRadio partition table # DigiRadio partition table (4 MB flash — ESP32-S3-WROOM-1)
# nvs_keys supports NVS encryption (enable in secure-store slice). # ota_0 + ota_1: dual OTA app slots (equal size, 64 KiB aligned).
# Name, Type, SubType, Offset, Size, Flags # dsp: updatable ADAU1701 program blob (task 3.1).
nvs, data, nvs, 0x9000, 0x6000, # nvs_keys: NVS encryption keys (secure-store slice).
nvs_keys, data, nvs_keys, 0xf000, 0x1000, # First flash after this layout: idf.py erase-flash flash (wired), not OTA.
phy_init, data, phy, 0x10000, 0x1000, # Name, Type, SubType, Offset, Size, Flags
factory, app, factory, 0x20000, 0x180000, nvs, data, nvs, 0x9000, 0x6000,
otadata, data, ota, 0xf000, 0x2000,
nvs_keys, data, nvs_keys, 0x11000, 0x1000,
phy_init, data, phy, 0x12000, 0x1000,
ota_0, app, ota_0, 0x20000, 0x1B0000,
ota_1, app, ota_1, 0x1D0000, 0x1B0000,
dsp, data, 0x40, 0x380000, 0x40000,
1 # DigiRadio partition table # DigiRadio partition table (4 MB flash — ESP32-S3-WROOM-1)
2 # nvs_keys supports NVS encryption (enable in secure-store slice). # ota_0 + ota_1: dual OTA app slots (equal size, 64 KiB aligned).
3 # Name, Type, SubType, Offset, Size, Flags # dsp: updatable ADAU1701 program blob (task 3.1).
4 nvs, data, nvs, 0x9000, 0x6000, # nvs_keys: NVS encryption keys (secure-store slice).
5 nvs_keys, data, nvs_keys, 0xf000, 0x1000, # First flash after this layout: idf.py erase-flash flash (wired), not OTA.
6 phy_init, data, phy, 0x10000, 0x1000, # Name, Type, SubType, Offset, Size, Flags
7 factory, app, factory, 0x20000, 0x180000, nvs, data, nvs, 0x9000, 0x6000,
8 otadata, data, ota, 0xf000, 0x2000,
9 nvs_keys, data, nvs_keys, 0x11000, 0x1000,
10 phy_init, data, phy, 0x12000, 0x1000,
11 ota_0, app, ota_0, 0x20000, 0x1B0000,
12 ota_1, app, ota_1, 0x1D0000, 0x1B0000,
13 dsp, data, 0x40, 0x380000, 0x40000,
+4 -1
View File
@@ -4,10 +4,13 @@
CONFIG_IDF_TARGET="esp32s3" CONFIG_IDF_TARGET="esp32s3"
# Custom partition table (nvs + nvs_keys for encrypted storage) # Custom partition table (nvs, otadata, OTA slots, dsp blob, nvs_keys)
CONFIG_PARTITION_TABLE_CUSTOM=y CONFIG_PARTITION_TABLE_CUSTOM=y
CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="partitions.csv" CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="partitions.csv"
# OTA rollback: mark app valid only after esp_ota_mark_app_valid_cancel_rollback()
CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE=y
# Flash encryption — DEVELOPMENT mode (re-flash plaintext until eFuse policy set) # Flash encryption — DEVELOPMENT mode (re-flash plaintext until eFuse policy set)
CONFIG_SECURE_FLASH_ENC_ENABLED=y CONFIG_SECURE_FLASH_ENC_ENABLED=y
CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT=y CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT=y