Define dual-OTA partition table with dsp blob slot.

Replace factory with ota_0/ota_1, otadata, and a dsp data partition on 4 MB flash; enable bootloader app rollback for future OTA work.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-07-07 08:57:05 +02:00
co-authored by Cursor
parent 2e44a166e1
commit 11ad6b43ad
5 changed files with 20 additions and 11 deletions
+1 -1
View File
@@ -517,7 +517,7 @@ Software/
├── AGENTS.md Doxyfile instructions.md
├── CMakeLists.txt top-level ESP-IDF project
├── sdkconfig.defaults C++23, exceptions off, flash/NVS encryption
├── partitions.csv includes an encrypted NVS partition
├── partitions.csv nvs, otadata, ota_0/ota_1, dsp blob, nvs_keys
├── .cursor/rules/*.mdc
├── main/ imperative shell entry (app_main)
├── components/
+1 -1
View File
@@ -120,7 +120,7 @@ Wire schemas: [`docs/manual/ch-api.tex`](docs/manual/ch-api.tex) · C++ API:
| `components/secure_store/` | Encrypted NVS: credentials, profiles, presets |
| `components/net/` | Wi-Fi, HTTP server, gzipped web UI |
| `sdkconfig.defaults` | C++23, NVS + flash encryption (dev mode) |
| `partitions.csv` | `nvs` + `nvs_keys` partitions |
| `partitions.csv` | `nvs`, `otadata`, dual OTA (`ota_0`/`ota_1`), `dsp` blob, `nvs_keys` |
| `docs/manual/` | LaTeX technical manual |
| `docs/security-flash-nvs.md` | Encryption + device HIL checklist |
| `docs/TODO.md` | Completed tasks + HIL backlog |
+1 -1
View File
@@ -8,7 +8,7 @@ preset index in the `digiradio` NVS namespace. Firmware **0.8.3+** enables:
| Flash encryption | `CONFIG_SECURE_FLASH_ENC_ENABLED` | On-chip transparent flash ciphertext |
| Mode (default) | `CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT` | Plaintext download still allowed for bring-up |
| NVS encryption | `CONFIG_NVS_ENCRYPTION` | XTS-AES over NVS entries; keys in `nvs_keys` partition |
| Partition table | `partitions.csv` | `nvs` @ 0x9000, `nvs_keys` @ 0xf000 |
| Partition table | `partitions.csv` | `nvs`, `otadata`, `ota_0`/`ota_1`, `dsp`, `nvs_keys` |
Implementation: `secure_store::initEncryptedStorage()` (called from
`NetBootstrap` before any `NvsSecureStore` access). With `CONFIG_NVS_ENCRYPTION`,
+11 -5
View File
@@ -1,7 +1,13 @@
# DigiRadio partition table
# nvs_keys supports NVS encryption (enable in secure-store slice).
# DigiRadio partition table (4 MB flash — ESP32-S3-WROOM-1)
# ota_0 + ota_1: dual OTA app slots (equal size, 64 KiB aligned).
# dsp: updatable ADAU1701 program blob (task 3.1).
# nvs_keys: NVS encryption keys (secure-store slice).
# First flash after this layout: idf.py erase-flash flash (wired), not OTA.
# Name, Type, SubType, Offset, Size, Flags
nvs, data, nvs, 0x9000, 0x6000,
nvs_keys, data, nvs_keys, 0xf000, 0x1000,
phy_init, data, phy, 0x10000, 0x1000,
factory, app, factory, 0x20000, 0x180000,
otadata, data, ota, 0xf000, 0x2000,
nvs_keys, data, nvs_keys, 0x11000, 0x1000,
phy_init, data, phy, 0x12000, 0x1000,
ota_0, app, ota_0, 0x20000, 0x1B0000,
ota_1, app, ota_1, 0x1D0000, 0x1B0000,
dsp, data, 0x40, 0x380000, 0x40000,
1 # DigiRadio partition table # DigiRadio partition table (4 MB flash — ESP32-S3-WROOM-1)
2 # nvs_keys supports NVS encryption (enable in secure-store slice). # ota_0 + ota_1: dual OTA app slots (equal size, 64 KiB aligned).
3 # dsp: updatable ADAU1701 program blob (task 3.1).
4 # nvs_keys: NVS encryption keys (secure-store slice).
5 # First flash after this layout: idf.py erase-flash flash (wired), not OTA.
6 # Name, Type, SubType, Offset, Size, Flags # Name, Type, SubType, Offset, Size, Flags
7 nvs, data, nvs, 0x9000, 0x6000, nvs, data, nvs, 0x9000, 0x6000,
8 nvs_keys, data, nvs_keys, 0xf000, 0x1000, otadata, data, ota, 0xf000, 0x2000,
9 phy_init, data, phy, 0x10000, 0x1000, nvs_keys, data, nvs_keys, 0x11000, 0x1000,
10 factory, app, factory, 0x20000, 0x180000, phy_init, data, phy, 0x12000, 0x1000,
11 ota_0, app, ota_0, 0x20000, 0x1B0000,
12 ota_1, app, ota_1, 0x1D0000, 0x1B0000,
13 dsp, data, 0x40, 0x380000, 0x40000,
+4 -1
View File
@@ -4,10 +4,13 @@
CONFIG_IDF_TARGET="esp32s3"
# Custom partition table (nvs + nvs_keys for encrypted storage)
# Custom partition table (nvs, otadata, OTA slots, dsp blob, nvs_keys)
CONFIG_PARTITION_TABLE_CUSTOM=y
CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="partitions.csv"
# OTA rollback: mark app valid only after esp_ota_mark_app_valid_cancel_rollback()
CONFIG_BOOTLOADER_APP_ROLLBACK_ENABLE=y
# Flash encryption — DEVELOPMENT mode (re-flash plaintext until eFuse policy set)
CONFIG_SECURE_FLASH_ENC_ENABLED=y
CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT=y