mirror of
https://github.com/alexhopeoconnor/firmware.git
synced 2026-10-04 03:18:10 +10:00
* docs(nodedb): make the native node cap unambiguous The native node cap was stated in four places that disagreed, and the disagreement already caused a wrong diagnosis: a saturated 200-node database looked arithmetically impossible because the cap had been read as 248, computed from a header that does not apply on this platform. The real value is 198. On portduino MAX_NUM_NODES is not a compile-time constant at all - the variant defines it as `portduino_config.MaxNodes`, resolved at runtime, default 200 and settable per host with `General: MaxNodes`. variant.h is reached before mesh-pb-constants.h, so that header's ARCH_PORTDUINO branch never fires and its plausible-looking 250 is dead code. - #error-guard the dead branch rather than leave a wrong number where people grep. The guard found a real defect: seven translation units reach mesh-pb-constants.h without configuration.h (SerialConsole.cpp, StreamAPI.cpp, PacketAPI.cpp, ServerAPI.cpp, PiWebServer.cpp, ServiceEnvelope.cpp, MeshtasticOTA.cpp, and test/TestUtil.cpp), so each was compiling with a different MAX_NUM_NODES - and therefore a different PACKETHISTORY_MAX - than the rest of the build. Each now includes configuration.h first. It cannot be included from mesh-pb-constants.h itself: that reaches SerialConsole.h through DebugConfiguration.h and closes a cycle. - Name the bare 250 in getMaxNodesAllocatedSize() NODEDB_MIGRATION_LOAD_CEILING. It is a decode allowance for files written by larger-cap firmware, not a cap, and it read like one. - Fix docs/node_info_stores.md, which named the wrong source and a "10-250" range that is wrong for native, and the copilot-instructions tunables line that said "portduino 250". * test(harness): give each suite its own scratch HOME and report leftovers Native suites shared one directory. Every suite that constructs a NodeDB loads and saves ~/.portduino/default/prefs/ - nodes.proto, config.proto, channels.proto, module.proto, device.proto, warm.dat, transmit_history.dat - and nothing cleared it, so state leaked suite -> suite within a run and run -> every run after it. A test run could also rewrite a real meshtasticd node database on the same machine. Per-run isolation does not fix this: the leak is generated inside a single run, so the boundary has to be per suite. bin/pio-test-isolate.sh runs each suite in its own scratch $HOME, registered as test_testing_command for env:native and env:coverage so a bare `pio test` and CI get the same boundary, not just bin/run-tests.sh. It runs the binary unchanged and exits with its exit code, so PlatformIO's pass/fail is untouched. Overriding HOME here rather than around `pio` also sidesteps the blocker that a bare HOME= breaks pio's own ~/.platformio/penv/bin/pio lookup. Leftovers are reported as a second axis, PASS/FAIL x CLEAN/DIRTY, because an unintended write has no matching assertion by definition - nobody writes TEST_ASSERT for a save they do not know is happening. The harness asserts it from outside, so it applies to every suite without the author opting in. - Only the *set of changed paths* is asserted, never contents. Hashes answer the boolean "did this change?" and nothing more; content baselines over protobuf bytes would churn on every NodeInfoLite field added, which is how snapshot suites become noise. - Deliberate writes are declared in test/state-manifest.tsv - one central file, suite / flags / mandatory reason. run-tests.sh prints the opt-out count on every run. - Granularity follows the state flag, so the two ship together: per-test by default (TestUtil redefines RUN_TEST to checkpoint after each test, naming the exact test that dirtied things), suite boundary for state=per-suite, where carrying state across test cases is the declared behaviour. - A declared write that does NOT happen is reported as MISSING, not folded into DIRTY. It catches silently broken persistence; a warning for now, since some are conditional. - Graded AMBER, not RED. With isolation in place DIRTY means "undeclared", not "dangerous", and a check that lands red on day one gets switched off. Guard the guard, both halves: state_assert_empty() refuses to run a suite against a sandbox that is not empty (otherwise the after-diff measures against the wrong baseline and reports CLEAN while meaning nothing), and bin/test-state-check.sh drives the real wrapper with fixtures asserting CLEAN / CLEAN / DIRTY / MISSING plus both directions of the empty assertion. A checker that silently matches everything would otherwise pass forever. --write-manifest proposes entries for a human to paste and justify; it never applies them, and neither does CI. * test(harness): stop reporting Unity's exit code as a signal A native suite ends in exit(UNITY_END()), and UNITY_END() returns the failure count. PlatformIO's native runner reads that non-zero exit code as a POSIX signal number, so four failures print "Program received signal SIGILL", five print "SIGTRAP", and the suite is classified [ERRORED] rather than [FAILED]. There is no crash. The signal name tracks the failure count and nothing else - it moved SIGILL -> SIGTRAP when a diagnostic probe added a fifth failure - and it cost hours of hunting a memory bug that did not exist, on an env (native) that carries no sanitizer at all. It also explains the phantom extra test case in the totals: the runner adds a synthetic entry for the signal it thinks it saw. run-tests.sh now says so inline whenever a signal line appears, and the three agent-facing docs say it too. * test(admin): isolate NodeDB and globals per test setUp() did `if (!nodeDB) nodeDB = new NodeDB();` and never deleted it, so 83 of the 85 tests shared one never-reset database and never restored config, owner, devicestate or channelFile. The fixture that does restore them was opt-in and armed by exactly two tests. The setUp comment claiming the rest "set their own config/region state and are unaffected" was not true - the admin handlers under test write all four globals. Route every test through the fixture instead: setUp saves the globals and installs a fresh NodeDB, tearDown restores and deletes it. The two tests that armed it themselves no longer need to. All 85 pass, so nothing was silently relying on the shared state. It costs about 7% of the suite's runtime (a NodeDB construction is a loadFromDisk plus, with a region set, key generation) - worth paying to write the phase 3 tests against a clean fixture rather than 83 tests' residue. Also cap the per-test attribution in the run summary at five entries; the full list stays in the suite's sandbox. * test(fs): cover the bounded file-manifest walk getFiles() runs on every phone sync via STATE_SEND_FILEMANIFEST, and nothing asserted any of its bounding behaviour. It does execute unasserted from test_stream_api's handshakes, but the cap, the depth limit, the wasLimited paths, overlong-path rejection and capacity release were all unguarded. Eight tests, all describing what the code does today: today's code is already correct here, since #10778 landed the by-reference collectFiles(), the 64-entry cap, the strlcpy bounds and the swap-idiom release. They pass on arrival, which is the point - this is the baseline a later change has to leave alone. Two things they do not cover, and cannot: - Moving reserve() outside the __cpp_exceptions guard. Exceptions are on natively, so the #else branch is not compiled. The suite's job there is to prove that change alters nothing observable. - The file.name() null guard. No in-tree backend returns null; the guard is defensive. The manifest-release test pins the swap idiom rather than calling PhoneAPI's releaseFilesManifest(), which is file-local. It asserts capacity() == 0, not just size() == 0 - a size-only check passes on clear(), which is the bug #7924 shipped. Suite count 43 -> 44, recounted against the directories rather than copied. * test(admin): assert node-DB metadata saves skip the radio reload set_favorite_node, set_ignored_node and toggle_muted_node each persist a NodeInfoLite bit and nothing else. MeshService::reloadConfig() gates its region re-derivation and configChanged notification on saveWhat & (SEGMENT_CONFIG | SEGMENT_CHANNELS), so a SEGMENT_NODEDATABASE-only save already skips the live radio reconfigure. Pure characterization - all three pass on develop. Worth pinning because that reconfigure is the path implicated in the WisMesh Tag favourite-node crash, and develop asserts nothing about it: widening the saveWhat mask or reordering the check would currently go unnoticed. Ported from the config-save series along with ConfigChangedCounter (an Observer<void *> counting configChanged notifications, the only externally visible signal that the reload branch was taken) and TEST_NODE_NUM. They join the existing suite, so no suite-count change. * refactor(menu): extract the mute toggle into a named function The node menu's mute action was inline in a banner-callback lambda, and that lambda only ever runs via screen->showOverlayBanner() - which is why nothing in MenuHandler.cpp was reachable from a test. Lift the `selected == Mute` branch into menuHandler::toggleNodeMuted(uint32_t) and call it from the lambda. Behaviour-neutral by construction: same statements, same order, same bare saveToDisk(). The null check moves into the function, so the call site no longer needs its own lookup. Verified by the native build and suite; the byte-identical-image check on a headroom-constrained nRF52 board was not run locally - CI's firmware-size comment covers it. Three tests come with it, all describing today's behaviour: - the bit flips both ways and no configChanged fires (develop never calls reloadConfig on this path); - an unknown node is a no-op rather than a write; - and the segment mask. Flipping one NodeInfoLite bit currently rewrites all five segments via bare saveToDisk(). That is asserted deliberately, with the comment naming it as characterization of a known defect: a pending fix narrows it to SEGMENT_NODEDATABASE, and when it lands this assertion is expected to change, which makes the improvement visible in the diff instead of silent. saveToDisk() is not virtual, so the mask is observed through its effect - remove the five prefs files, toggle, and see which reappear. * docs(test): make every suite count a pointer to the canonical one test/native-suite-count is the registered total and is machine-checked against test/test_* on every full run and by the suite-count-check CI job. Every other statement of the count is a copy that drifts: copilot-instructions said 12, AGENTS.md said 19, and the real number is 44. Replace both literals with a pointer to the file, say explicitly that no document should state the count as a literal, and reframe the two suite listings as descriptions rather than inventories - they carry per-suite information the count does not, so they stay, but nothing should infer completeness from their length. Register the new FS suite in both. * test(harness): randomise suite order, reproducibly Landed last, deliberately. Randomising an order-dependent suite set does not find bugs so much as convert a silent pass into intermittent red, and the first instinct is to revert the randomisation rather than fix the coupling. Phases 1-2 removed the coupling; this keeps it removed. Both runners previously hid order dependence behind a fixed order that happened to differ between them, and neither order was chosen: CI's area rules put admin first, PlatformIO's local discovery is reverse alphabetical and put it last. CI was green by accident. - bin/run-tests.sh --shuffle / --seed <n>. The seed defaults to HEAD's short SHA: one order per commit, so a red is replayable and attributable to the diff instead of flaky, while the project keeps exploring orders. Printed at the start and carried into the RESULT line, so a verdict is replayable from that line alone; the full order is printed on failure, because for an order-dependent failure the order is the diagnostic. - The shuffle is a Fisher-Yates over a MINSTD generator rather than awk's rand(), whose sequence differs between gawk and mawk. A seed that does not reproduce the same order on another machine is not a seed. - Shuffling needs one `pio test -f <suite>` invocation per suite - PlatformIO orders by its own os.walk() over test/ and filters only select - which measures at about 4.7s per suite of extra startup. - CI shuffles its area order, seeded from GITHUB_SHA and printed with the command to replay it locally. Intra-area order stays PlatformIO's; controlling it there would mean per-suite invocations, which is a cost worth deciding separately. Also records the 16 measured entries in test/state-manifest.tsv, each with its reason, taken from a full run's --write-manifest output rather than guessed. * test(default): cover the region-throttle interval overload getConfiguredOrDefaultMsScaled(configured, default, nodes, TrafficType) is the overload every telemetry and position module actually calls, and nothing referenced TrafficType anywhere under test/. All four of its behaviours were unguarded: the no-region guard, the throttle <= 1 short-circuit, the multiply, and the 64-bit overflow clamp. The throttles are real, not hypothetical - EU_866 carries PROFILE_LITE, which sets both positionThrottle and telemetryThrottle to 10, so a change here moves broadcast spacing in that region by an order of magnitude. Each test pins numOnlineNodes at the congestion threshold and uses ROUTER, which never congestion-scales, so the coefficient is 1 and the throttle is the only variable. The overflow case needs a base above INT32_MAX/10, hence three days rather than one. * ci(test): keep pull-request suite order fixed, seed the rest Shuffling the area order on every run - including pull_request - would turn a contributor's PR red for an ordering they did not choose, which is how a randomisation gets reverted instead of the coupling being fixed. That is the exact dynamic the ordering work was sequenced last to avoid, and the previous commit walked straight into it. - pull_request keeps the fixed declared area order. - push and schedule shuffle, seeded from the commit SHA: deterministic per commit, printed, attributable, and never blocking someone else's PR. - A suite_order_seed input on workflow_call and workflow_dispatch overrides both, so a specific failing order can be replayed anywhere, including on a PR. The run log prints which mode it took, the resulting order, and the local command to replay it. * ci(test): satisfy CKV_GHA_7 and yamllint on the seed input The seed is reachable through workflow_call, which callers can pass programmatically. The workflow_dispatch copy tripped checkov's "workflow_dispatch inputs MUST be empty" rule, and suppressing it was not worth it: replaying a specific order is a local operation, and the run log already prints the exact bin/run-tests.sh command to do it. * style(menu): apply the node-ID format convention RadioInterface.cpp documents the rule: 0x%08x in logs, !%08x in user-facing display. MenuHandler held every remaining exception - seven logs printing bare %08X, and two display labels doing the same. Repo-wide there are now no bare %08X node IDs left in log calls. * ci(test): pass workflow inputs through env, not shell interpolation suite_order_seed and github.event_name were spliced into the run: script as ${{ }} text, so a value carrying shell metacharacters would execute as code on the runner rather than being read as data. semgrep (run-shell-injection) and zizmor (template-injection) both flag it. Both now arrive as environment variables and are read as "$VAR". * refactor(test): share the seeded shuffle between the harness and CI bin/run-tests.sh and test_native.yml each carried a byte-identical copy of the MINSTD Fisher-Yates awk. The workflow prints "replay locally: ./bin/run-tests.sh --shuffle --seed $seed" after a shuffled CI run, and that instruction is only true while the two agree - drift would be announced by a replay quietly reproducing a different order than the one that failed. Extract shuffle_suites() to bin/lib/shuffle.sh and source it from both. Permutations verified identical across seeds before and after the move. * fix(test): correct the shared-state MISSING check and summary join Three defects in the new harness: state_classify() matched declarations two different ways - state_path_declared() for "undeclared", a hand-rolled regex for "missing". Interpolating an entry into an ERE also let a metacharacter in a manifest name match a file that is not the declared one. Both directions now go through the one helper. `paste -sd'; '` does not join with "; ": with -s, paste cycles through a multi-character delimiter one character per join, so paths rendered as "a;b c;d e". Replaced with an awk join. test-state-check.sh ran on after a failed cd instead of stopping (SC2164). ./bin/test-state-check.sh: 6/6 fixtures pass, MISSING included. * fix(portduino): bound General.MaxNodes MaxNodes was validated only for <= 0. Any positive value, including a typo'd or pasted-in one, propagates to MAX_NUM_NODES and scales both the node DB and the nodes.proto decode ceiling - failing at boot with no obvious cause. The ceiling is a sanity bound, not a capability limit; raise it if a host genuinely needs more. * docs(nodedb): reconcile the capacity tables The property matrix omitted the ESP32-S3 100-node flash tier that the platform table above it lists, and neither mentioned that the WASM build overrides MaxNodes to 80 in wasm_config_apply(). * fix(nodedb): make mesh-pb-constants.h self-sufficient on portduino The ARCH_PORTDUINO #error assumed it was unreachable in a normal build. It is not: the vendored device-ui sources include this header without configuration.h, which broke both native-tft docker builds. Include configuration.h here instead, ahead of every compile-time default - variant.h overrides MAX_RX_TOPHONE as well as MAX_NUM_NODES, so placing it lower in the file just moves the divergence to a redefinition. The #error stays as a backstop for the case where that include genuinely stops providing the cap. Verified with the native env's own flags: a TU including only this header now compiles, normal-order use of both macros compiles, and NodeDB.cpp compiles. * fix(portduino): raise the MaxNodes ceiling to 16000 Marked artificial: nothing in the node DB fails at 16001. 16000 sits just under the 16384 (128 x 128) population where HopScalingModule saturates its sampling denominator and starts dropping nodes, so a host inside the bound still gets meaningful hop recommendations. * lint(trunk): advise on node IDs logged as bare %08x RadioInterface.cpp documents the convention - 0x%08x in logs, !%08x in display - but nothing enforced it, which is how the MenuHandler cluster drifted. 22 call sites in PacketHistory, NodeInfoModule and PositionModule are still off it. A trunk linter rather than a CI grep job, because trunk checks changed files: new violations get flagged without a 22-site cleanup landing in an unrelated PR. Modelled on the existing too-many-defined definition. Scoped to values it can tell are IDs - an ID-shaped argument (->num, .from, getNodeNum) or message text naming one. A 32-bit hex that is not an ID is out of scope, so the CRC32 logs in ethOTA.cpp are correctly ignored. Emits "note", trunk's only non-blocking level: "warning" and "info" both exit non-zero and would gate CI, which is not what a log-format nit deserves. The pre-existing sites are line-scoped in the allowlist, so a new bad call in those same files is still caught. * lint(trunk): stop exempting the known node-id-format sites The seeded allowlist made the rule green by declaring the backlog acceptable. Empty it instead, so the 22 pre-existing sites are reported and get cleaned up by whoever next edits those files. Costs nothing to do: the rule emits "note", so these are non-blocking either way. The allowlist stays for its real purpose - a value the linter misreads as an ID. * style: log node and packet IDs as 0x%08x Clears the 22 sites the node-id-format linter reports, so the rule starts from zero rather than from a backlog nobody can see - trunk suppresses pre-existing findings by default, so left alone these would not have surfaced on edit the way an empty allowlist implies. Format strings only; no argument or control flow changes. The !%08x user-facing display forms are deliberately untouched - that is the other half of the same convention. * test(harness): build once up front, so suite timings mean something run-tests.sh fused build and run in a single pio invocation, so whichever suite PlatformIO's directory walk reached first absorbed the entire src compile and reported it as its own duration. On a real run that made a 0.03s suite report 13m21s, and hid the build cost from every other number in the summary. Do what .github/workflows/test_native.yml already does: one --without-testing build pass, then run with --without-building. Measured on a full 44-suite run - the build is now a single reported figure and 968 test cases execute in 1.9s, with no suite above 0.084s. Build output goes to its own log rather than $LOG: the outcome regexes match "error:" and "[ERRORED]", so a compiler diagnostic sharing that file would read as a test failure. Both red paths now keep the log they quote from. $LOG and the build log are mktemps the EXIT trap removes, so the three grepped lines were previously all anyone ever saw - and the cause is usually further up than the first [FAILED]. * test(harness): keep the run log on every red path bin/pio-test-isolate.sh already keeps a failing or DIRTY suite's sandbox and log under .pio/test-state/<suite>/. What was missing is the cross-suite view: $LOG is a mktemp the EXIT trap deletes, so run-tests.sh quoted three grepped lines from a file that no longer existed by the time anyone looked. Preserve it as .pio/build/<env>/test-failure.log from both red paths - including "no success summary found", which said "see log" while preserving nothing, and which is exactly the case where the build died before any suite ran and so left no per-suite sandbox either. Cleared at the start of every run, so a green run cannot leave a red one's log lying around looking current. * fix(test): report the real failure count on a shuffled red A shuffled run is one `pio test` invocation per suite, all appending to the same log, so the log carries one PlatformIO "N test cases:" summary per suite. verdict_red() took `tail -1`, which reports whatever the LAST suite did: a failure in suite 3 printed a "0 failed" summary from suite 44 directly under "RED - failures detected:". Sum the summaries instead. A single summary line - every unshuffled run - is passed through verbatim, so the familiar output is byte-identical. The patterns are passed to the awk helper as strings rather than /regex/ literals: awk evaluates a regex literal in argument position as `$0 ~ /re/`, so the callee would receive 0 or 1 and silently sum garbage. * fix(test): do not emit an empty suite name for an empty shuffle `printf '%s\n' "$@"` with no arguments still writes one empty line, and both callers read shuffle_suites through mapfile, so an empty suite list arrived as a single suite named "". Return before the printf when there is nothing to shuffle. * test(harness): state and enforce the Linux host requirement The native harness is a Linux tool: bash 4+ (mapfile), GNU coreutils and GNU find (-printf, md5sum, -executable). Most of that predates this branch - mapfile and both find predicates are already on develop - but none of it was written down, so the requirement was there to be discovered rather than read. Refuse to start on a non-Linux uname instead of degrading. On a BSD userland this would not fail cleanly: it would mis-hash the sandbox and mis-read the suite list, and still print a verdict. A state check that silently measures the wrong thing is worse than one that declines to run. Carrying a per-host fallback was the alternative, and it buys a second code path that nothing in CI exercises. bin/test-native-docker.sh already exists for macOS and non-Linux hosts, and the native-macos PlatformIO env is a build target for meshtasticd, not a test host - the isolation wrapper is registered for env:native and env:coverage only. Documented in the script header, test/README.md, and both agent docs. * fix(test): terminate every suite with exit(UNITY_END()) Two sites across two suites ended on a bare UNITY_END(). That ends the reporting, not the suite: setup() returns, the runtime goes on calling loop(), and the process runs forever. PlatformIO does not notice - it reports a suite from its Unity output, not from process exit - so the suite passes, the run goes green, and the binary stays resident. Thirteen of them had accumulated on one dev box, the oldest 19 hours old. The costs are quiet by construction: - the per-suite sandbox is deleted underneath a live process, so its CLEAN/DIRTY verdict describes what the suite had written when the harness stopped looking, not what it left behind; - .gcda coverage and LeakSanitizer's report both flush from atexit handlers, so a suite that never exits contributes no coverage and gets no leak check; - each survivor pins its own deleted 94 MB binary, which du cannot see. One of the two is the #else of an architecture guard, which is the easiest one to get wrong - it looks like there is nothing to clean up. test_mqtt has a correct exit(UNITY_END()) in its live branch, so a "does this file call exit() anywhere" check passes the file whole. test_serial had two more. develop's serial-config validation rework restructured that suite - the architecture guard is gone and both remaining branches now exit correctly - so this commit no longer has anything to change there; bin/lint-unity-exit.sh, added later on this branch, is what keeps it that way. test/README.md gets a section on it, since the skeleton showing the right shape had not stopped this happening. * test(harness): detect and reap suites that outlive their run A suite that never exits was invisible: PlatformIO reports a suite from its Unity output, so the run stayed green while the binary kept running. Two checks, because they fail differently. Runtime, in bin/pio-test-isolate.sh: the sandbox $HOME is mktemp-unique per suite, so any process still holding it is a survivor of that suite. Matching on the environment rather than a remembered PID identifies one whatever its parentage - a fork, a grandchild, a process already reparented to init - none of which a $! comparison catches. Reaped before the after-fingerprint is taken, so that fingerprint measures a tree nobody is still writing to, and so a run cannot leave processes accumulating on the host. Recorded as a sixth summary column and graded AMBER: the tests did pass, but the CLEAN verdict and the coverage were measured under a false assumption. Author-time, as bin/lint-unity-exit.sh, wired into trunk at "note" like node-id-format: every UNITY_END() must be wrapped in exit(). The rule is per occurrence, and that is the point - a file-level "calls exit() somewhere" check passes test_serial and test_mqtt, which have a correct one in their live branch and a bare one in the #else. Running it over the tree turned up test_mqtt, which the file-level pass had missed. It allows `int rc = UNITY_END(); ...; exit(rc)`, used by test_packet_signing to restore globals between the summary and the exit. That is where the rule gives ground: capturing and never exiting would leak and is not flagged. Flagging a correct idiom would push someone to "fix" working code. bin/test-state-check.sh gains a survivor fixture, asserting the wrapper both reports and reaps - a detector that only reports leaves the host accumulating processes, which is half the harm. 8/8. * fix(lint): make the unity-exit scanner statement-aware The rule judged one physical line at a time, which reports two kinds of correct code as bare: /* a comment that happens to mention UNITY_END() */ <- interior lines were never stripped exit( UNITY_END()); <- exit( and the macro never met On a probe of both, two of three findings were wrong. This is a note-level rule whose whole job is advice, and bin/lint-node-id-format.sh already says why that matters: a false positive costs more than a miss. One that cries wolf gets ignored, and the real finding goes with it. Carry /* ... */ state across lines and accumulate logical statements before testing, with a 12-line cap so one unclosed call cannot swallow the rest of the file - the same structure lint-node-id-format.sh uses, so the two custom linters in bin/ work alike rather than each having its own idea. Verified both directions: the develop-era sources still produce the same four findings, the fixed tree produces none, and a probe covering block-comment interiors, wrapped exit(), line comments, return UNITY_END() and capture-then- exit reports only the genuinely bare calls - including a complete block comment followed by real bare code on the same line, which the state machine has to keep live. Reported by CodeRabbit on #11322. * fix(lint): tokenise instead of pattern-matching, and self-test it Second round of review findings on the same scanner, all confirmed by direct test before changing anything. Six defects, one root cause: layered regexes cannot tokenise C++. False positives (correct code reported): - UNITY_END() inside a string literal read as code False negatives (real leaks missed): - a string containing "/*" opened comment state and swallowed later lines - greedy .* removed everything between two block comments on one line, taking a bare call with it - myexit(UNITY_END()) matched the exit() exemption as a substring - x == UNITY_END() and total += UNITY_END() matched the assignment exemption Replaced with a character-level scan carrying comment state, and token-bounded exemptions: exit must be a whole identifier, and the capture form must be a plain `=`. Raw string literals are still not modelled - there are none under test/, and delimiter tracking for a case that does not occur would be untested code guarding untested code, so it is documented rather than guessed at. Also drops the `return UNITY_END()` exemption. It only terminates from main(), there is no main() under test/, and from a helper it just returns a count. bin/test-lint-unity-exit.sh pins all fifteen cases, every false positive and false negative found in review among them. The rule has been wrong twice in a way that looked fine by inspection; it needed a self-test more than it needed another careful reading. Two further findings in the same review: - bin/run-tests.sh dropped PASSTHRU in shuffled mode, so `--shuffle -vvv` built verbosely and then ran quietly. The shuffled loop now forwards EXTRA_ARGS, which is PASSTHRU minus the -f pair it supplies per suite. - bin/run-tests.sh did not guard `cd "$ROOT_DIR"`. And one that did not reproduce: the survivor fixture's glob does find the pid file (verified with the lookup instrumented - the earlier failure was an artifact of running the script from /tmp, where SCRIPT_DIR cannot resolve). The assertion was still weak, because an empty pid took the "not running" branch and passed vacuously. It now fails if the pid was never recorded, and finds the file by search rather than assuming a directory depth. Reported by CodeRabbit on #11322. * fix(lint): report each UNITY_END occurrence at its own location The self-test only asked "did the linter say anything", so it could not have caught a wrong line, a wrong column, or a missing second finding. Fixtures now assert the exact diagnostics as line:col, and the first run of that assertion found two real problems. The caret pointed at the wrong occurrence. For `exit(UNITY_END()); UNITY_END();` the verdict was right but the column was 17 - the wrapped call - because the scanner stripped terminating forms out of the whole statement and then reported the first occurrence it had seen. Two bare calls on one line reported once. Judged per occurrence now, by looking back through whitespace at what wraps it, so both the count and the caret are right. That also needed a position map from strip_noncode(): removing a comment or collapsing a literal shifts every later column, and counting occurrences in the raw line does not recover it either - TEST_MESSAGE("... UNITY_END() ..."); UNITY_END(); has two occurrences in the raw text and one in the code. Four of the expected columns I wrote by hand were also wrong, off by one. The linter was right in every case; the assertions were not. They are computed from the fixture text now rather than pasted from output, because a baseline accepted from the tool it is testing asserts nothing. 17 fixtures, including the two-on-one-line case from review and its mirror. Reported by CodeRabbit on #11322.
834 lines
41 KiB
C++
834 lines
41 KiB
C++
#pragma once
|
|
|
|
#include "Observer.h"
|
|
#include <Arduino.h>
|
|
#include <algorithm>
|
|
#include <assert.h>
|
|
#include <map>
|
|
#include <pb_encode.h>
|
|
#include <string>
|
|
#include <vector>
|
|
|
|
#include "MeshTypes.h"
|
|
#include "NodeStatus.h"
|
|
#include "WarmNodeStore.h"
|
|
#include "concurrency/Lock.h"
|
|
#include "configuration.h"
|
|
#include "mesh-pb-constants.h"
|
|
#include "mesh/generated/meshtastic/mesh.pb.h" // For CriticalErrorCode
|
|
|
|
#if ARCH_PORTDUINO
|
|
#include "PortduinoGlue.h"
|
|
#endif
|
|
|
|
/// Decode-stream ceiling for a `nodes.proto` written by *other* firmware - a migration allowance,
|
|
/// **not this build's node cap**. That is `MAX_NUM_NODES`, which on portduino is a runtime value
|
|
/// (`portduino_config.MaxNodes`, default 200) rather than a compile-time constant. 250 is the
|
|
/// largest hot cap any shipped firmware has used (ESP32-S3 top flash tier), so a file from any of
|
|
/// them still decodes here; the excess is trimmed after load.
|
|
static constexpr size_t NODEDB_MIGRATION_LOAD_CEILING = 250;
|
|
|
|
#if !defined(MESHTASTIC_EXCLUDE_PKI)
|
|
// E3B0C442 is the blank hash
|
|
static const uint8_t LOW_ENTROPY_HASHES[][32] = {
|
|
{0xf4, 0x7e, 0xcc, 0x17, 0xe6, 0xb4, 0xa3, 0x22, 0xec, 0xee, 0xd9, 0x08, 0x4f, 0x39, 0x63, 0xea,
|
|
0x80, 0x75, 0xe1, 0x24, 0xce, 0x05, 0x36, 0x69, 0x63, 0xb2, 0xcb, 0xc0, 0x28, 0xd3, 0x34, 0x8b},
|
|
{0x5a, 0x9e, 0xa2, 0xa6, 0x8a, 0xa6, 0x66, 0xc1, 0x5f, 0x55, 0x00, 0x64, 0xa3, 0xa6, 0xfe, 0x71,
|
|
0xc0, 0xbb, 0x82, 0xc3, 0x32, 0x3d, 0x7a, 0x7a, 0xe3, 0x6e, 0xfd, 0xdd, 0xad, 0x3a, 0x66, 0xb9},
|
|
{0xb3, 0xdf, 0x3b, 0x2e, 0x67, 0xb6, 0xd5, 0xf8, 0xdf, 0x76, 0x2c, 0x45, 0x5e, 0x2e, 0xbd, 0x16,
|
|
0xc5, 0xf8, 0x67, 0xaa, 0x15, 0xf8, 0x92, 0x0b, 0xdf, 0x5a, 0x66, 0x50, 0xac, 0x0d, 0xbb, 0x2f},
|
|
{0x3b, 0x8f, 0x86, 0x3a, 0x38, 0x1f, 0x77, 0x39, 0xa9, 0x4e, 0xef, 0x91, 0x18, 0x5a, 0x62, 0xe1,
|
|
0xaa, 0x9d, 0x36, 0xea, 0xce, 0x60, 0x35, 0x8d, 0x9d, 0x1f, 0xf4, 0xb8, 0xc9, 0x13, 0x6a, 0x5d},
|
|
{0x36, 0x7e, 0x2d, 0xe1, 0x84, 0x5f, 0x42, 0x52, 0x29, 0x11, 0x0a, 0x25, 0x64, 0x54, 0x6a, 0x6b,
|
|
0xfd, 0xb6, 0x65, 0xff, 0x15, 0x1a, 0x51, 0x71, 0x22, 0x40, 0x57, 0xf6, 0x91, 0x9b, 0x64, 0x58},
|
|
{0x16, 0x77, 0xeb, 0xa4, 0x52, 0x91, 0xfb, 0x26, 0xcf, 0x8f, 0xd7, 0xd9, 0xd1, 0x5d, 0xc4, 0x68,
|
|
0x73, 0x75, 0xed, 0xc5, 0x95, 0x58, 0xee, 0x90, 0x56, 0xd4, 0x2f, 0x31, 0x29, 0xf7, 0x8c, 0x1f},
|
|
{0x31, 0x8c, 0xa9, 0x5e, 0xed, 0x3c, 0x12, 0xbf, 0x97, 0x9c, 0x47, 0x8e, 0x98, 0x9d, 0xc2, 0x3e,
|
|
0x86, 0x23, 0x90, 0x29, 0xc8, 0xb0, 0x20, 0xf8, 0xb1, 0xb0, 0xaa, 0x19, 0x2a, 0xcf, 0x0a, 0x54},
|
|
{0xa4, 0x8a, 0x99, 0x0e, 0x51, 0xdc, 0x12, 0x20, 0xf3, 0x13, 0xf5, 0x2b, 0x3a, 0xe2, 0x43, 0x42,
|
|
0xc6, 0x52, 0x98, 0xcd, 0xbb, 0xca, 0xb1, 0x31, 0xa0, 0xd4, 0xd6, 0x30, 0xf3, 0x27, 0xfb, 0x49},
|
|
{0xd2, 0x3f, 0x13, 0x8d, 0x22, 0x04, 0x8d, 0x07, 0x59, 0x58, 0xa0, 0xf9, 0x55, 0xcf, 0x30, 0xa0,
|
|
0x2e, 0x2f, 0xca, 0x80, 0x20, 0xe4, 0xde, 0xa1, 0xad, 0xd9, 0x58, 0xb3, 0x43, 0x2b, 0x22, 0x70},
|
|
{0x40, 0x41, 0xec, 0x6a, 0xd2, 0xd6, 0x03, 0xe4, 0x9a, 0x9e, 0xbd, 0x6c, 0x0a, 0x9b, 0x75, 0xa4,
|
|
0xbc, 0xab, 0x6f, 0xa7, 0x95, 0xff, 0x2d, 0xf6, 0xe9, 0xb9, 0xab, 0x4c, 0x0c, 0x1c, 0xd0, 0x3b},
|
|
{0x22, 0x49, 0x32, 0x2b, 0x00, 0xf9, 0x22, 0xfa, 0x17, 0x02, 0xe9, 0x64, 0x82, 0xf0, 0x4d, 0x1b,
|
|
0xc7, 0x04, 0xfc, 0xdc, 0x8c, 0x5e, 0xb6, 0xd9, 0x16, 0xd6, 0x37, 0xce, 0x59, 0xaa, 0x09, 0x49},
|
|
{0x48, 0x6f, 0x1e, 0x48, 0x97, 0x88, 0x64, 0xac, 0xe8, 0xeb, 0x30, 0xa3, 0xc3, 0xe1, 0xcf, 0x97,
|
|
0x39, 0xa6, 0x55, 0x5b, 0x5f, 0xbf, 0x18, 0xb7, 0x3a, 0xdf, 0xa8, 0x75, 0xe7, 0x9d, 0xe0, 0x1e},
|
|
{0x09, 0xb4, 0xe2, 0x6d, 0x28, 0x98, 0xc9, 0x47, 0x66, 0x46, 0xbf, 0xff, 0x58, 0x17, 0x91, 0xaa,
|
|
0xc3, 0xbf, 0x4a, 0x9d, 0x0b, 0x88, 0xb1, 0xf1, 0x03, 0xdd, 0x61, 0xd7, 0xba, 0x9e, 0x64, 0x98},
|
|
{0x39, 0x39, 0x84, 0xe0, 0x22, 0x2f, 0x7d, 0x78, 0x45, 0x18, 0x72, 0xb4, 0x13, 0xd2, 0x01, 0x2f,
|
|
0x3c, 0xa1, 0xb0, 0xfe, 0x39, 0xd0, 0xf1, 0x3c, 0x72, 0xd6, 0xef, 0x54, 0xd5, 0x77, 0x22, 0xa0},
|
|
{0x0a, 0xda, 0x5f, 0xec, 0xff, 0x5c, 0xc0, 0x2e, 0x5f, 0xc4, 0x8d, 0x03, 0xe5, 0x80, 0x59, 0xd3,
|
|
0x5d, 0x49, 0x86, 0xe9, 0x8d, 0xf6, 0xf6, 0x16, 0x35, 0x3d, 0xf9, 0x9b, 0x29, 0x55, 0x9e, 0x64},
|
|
{0x08, 0x56, 0xF0, 0xD7, 0xEF, 0x77, 0xD6, 0x11, 0x1C, 0x8F, 0x95, 0x2D, 0x3C, 0xDF, 0xB1, 0x22,
|
|
0xBF, 0x60, 0x9B, 0xE5, 0xA9, 0xC0, 0x6E, 0x4B, 0x01, 0xDC, 0xD1, 0x57, 0x44, 0xB2, 0xA5, 0xCF},
|
|
{0x2C, 0xB2, 0x77, 0x85, 0xD6, 0xB7, 0x48, 0x9C, 0xFE, 0xBC, 0x80, 0x26, 0x60, 0xF4, 0x6D, 0xCE,
|
|
0x11, 0x31, 0xA2, 0x1E, 0x33, 0x0A, 0x6D, 0x2B, 0x00, 0xFA, 0x0C, 0x90, 0x95, 0x8F, 0x5C, 0x6B},
|
|
{0xFA, 0x59, 0xC8, 0x6E, 0x94, 0xEE, 0x75, 0xC9, 0x9A, 0xB0, 0xFE, 0x89, 0x36, 0x40, 0xC9, 0x99,
|
|
0x4A, 0x3B, 0xF4, 0xAA, 0x12, 0x24, 0xA2, 0x0F, 0xF9, 0xD1, 0x08, 0xCB, 0x78, 0x19, 0xAA, 0xE5},
|
|
{0x6E, 0x42, 0x7A, 0x4A, 0x8C, 0x61, 0x62, 0x22, 0xA1, 0x89, 0xD3, 0xA4, 0xC2, 0x19, 0xA3, 0x83,
|
|
0x53, 0xA7, 0x7A, 0x0A, 0x89, 0xE2, 0x54, 0x52, 0x62, 0x3D, 0xE7, 0xCA, 0x8C, 0xF6, 0x6A, 0x60},
|
|
{0x20, 0x27, 0x2F, 0xBA, 0x0C, 0x99, 0xD7, 0x29, 0xF3, 0x11, 0x35, 0x89, 0x9D, 0x0E, 0x24, 0xA1,
|
|
0xC3, 0xCB, 0xDF, 0x8A, 0xF1, 0xC6, 0xFE, 0xD0, 0xD7, 0x9F, 0x92, 0xD6, 0x8F, 0x59, 0xBF, 0xE4},
|
|
{0x91, 0x70, 0xb4, 0x7c, 0xfb, 0xff, 0xa0, 0x59, 0x6a, 0x25, 0x1c, 0xa9, 0x9e, 0xe9, 0x43, 0x81,
|
|
0x5d, 0x74, 0xb1, 0xb1, 0x09, 0x28, 0x00, 0x4a, 0xaf, 0xe3, 0xfc, 0xa9, 0x4e, 0x27, 0x76, 0x4c},
|
|
{0x85, 0xfe, 0x7c, 0xec, 0xb6, 0x78, 0x74, 0xc3, 0xec, 0xe1, 0x32, 0x7f, 0xb0, 0xb7, 0x02, 0x74,
|
|
0xf9, 0x23, 0xd8, 0xe7, 0xfa, 0x14, 0xe6, 0xee, 0x66, 0x44, 0xb1, 0x8c, 0xa5, 0x2f, 0x7e, 0xd2},
|
|
{0x8e, 0x66, 0x65, 0x7b, 0x3b, 0x6f, 0x7e, 0xcc, 0x57, 0xb4, 0x57, 0xea, 0xcc, 0x83, 0xf5, 0xaa,
|
|
0xf7, 0x65, 0xa3, 0xce, 0x93, 0x72, 0x13, 0xc1, 0xb6, 0x46, 0x7b, 0x29, 0x45, 0xb5, 0xc8, 0x93},
|
|
{0xcc, 0x11, 0xfb, 0x1a, 0xab, 0xa1, 0x31, 0x87, 0x6a, 0xc6, 0xde, 0x88, 0x87, 0xa9, 0xb9, 0x59,
|
|
0x37, 0x82, 0x8d, 0xb2, 0xcc, 0xd8, 0x97, 0x40, 0x9a, 0x5c, 0x8f, 0x40, 0x55, 0xcb, 0x4c, 0x3e}};
|
|
static const char LOW_ENTROPY_WARNING[] = "Compromised keys were detected and regenerated.";
|
|
#endif
|
|
static const char LICENSED_IDENTITY_MIGRATION_WARNING[] =
|
|
"Licensed signing generated a new identity key; this node identity changed.";
|
|
/*
|
|
DeviceState versions used to be defined in the .proto file but really only this function cares. So changed to a
|
|
#define here.
|
|
*/
|
|
|
|
#define SEGMENT_CONFIG 1
|
|
#define SEGMENT_MODULECONFIG 2
|
|
#define SEGMENT_DEVICESTATE 4
|
|
#define SEGMENT_CHANNELS 8
|
|
#define SEGMENT_NODEDATABASE 16
|
|
|
|
#define DEVICESTATE_CUR_VER 25
|
|
// Lowest on-disk version we still know how to load. v24 saves are migrated
|
|
// at boot via the parallel deviceonly_legacy descriptor and re-saved as v25.
|
|
#define DEVICESTATE_MIN_VER 24
|
|
|
|
// One-time behavioral migration marker for the 2.8 position/telemetry opt-in flip.
|
|
// Deliberately kept separate from DEVICESTATE_CUR_VER: that constant also drives the
|
|
// NodeDatabase slim-schema legacy gate (NodeDB.cpp, `nodeDatabase.version < CUR_VER`),
|
|
// so bumping it would wrongly re-run the v24 legacy decoder on already-migrated v25
|
|
// node DBs. This watermark is stamped only onto channelFile.version / moduleConfig.version
|
|
// once the opt-in migration has run. RESERVES 26 - the next real on-disk schema change
|
|
// should raise DEVICESTATE_CUR_VER to 27, not 26.
|
|
#define POSITION_TELEMETRY_OPTIN_VER 26
|
|
|
|
extern meshtastic_DeviceState devicestate;
|
|
extern meshtastic_NodeDatabase nodeDatabase;
|
|
extern meshtastic_ChannelFile channelFile;
|
|
extern meshtastic_MyNodeInfo &myNodeInfo;
|
|
extern meshtastic_LocalConfig config;
|
|
extern meshtastic_DeviceUIConfig uiconfig;
|
|
extern meshtastic_LocalModuleConfig moduleConfig;
|
|
extern meshtastic_User &owner;
|
|
extern meshtastic_Position localPosition;
|
|
|
|
static constexpr const char *deviceStateFileName = "/prefs/device.proto";
|
|
static constexpr const char *legacyPrefFileName = "/prefs/db.proto";
|
|
static constexpr const char *nodeDatabaseFileName = "/prefs/nodes.proto";
|
|
// Event builds isolate radio profiles so normal firmware resumes its config and channels after OTA.
|
|
static constexpr const char *STANDARD_CONFIG_FILE_NAME = "/prefs/config.proto";
|
|
static constexpr const char *STANDARD_CHANNEL_FILE_NAME = "/prefs/channels.proto";
|
|
static constexpr const char *EVENT_CONFIG_FILE_NAME = "/prefs/event-config.proto";
|
|
static constexpr const char *EVENT_CHANNEL_FILE_NAME = "/prefs/event-channels.proto";
|
|
static constexpr const char *STANDARD_BACKUP_FILE_NAME = "/backups/backup.proto";
|
|
static constexpr const char *EVENT_BACKUP_FILE_NAME = "/backups/event-backup.proto";
|
|
|
|
struct RadioProfileStoragePaths {
|
|
const char *config;
|
|
const char *channels;
|
|
const char *backup;
|
|
};
|
|
|
|
constexpr RadioProfileStoragePaths radioProfileStoragePaths(bool eventMode)
|
|
{
|
|
return eventMode ? RadioProfileStoragePaths{EVENT_CONFIG_FILE_NAME, EVENT_CHANNEL_FILE_NAME, EVENT_BACKUP_FILE_NAME}
|
|
: RadioProfileStoragePaths{STANDARD_CONFIG_FILE_NAME, STANDARD_CHANNEL_FILE_NAME, STANDARD_BACKUP_FILE_NAME};
|
|
}
|
|
|
|
// Reserve event files and their atomic temporaries before seeding, preventing retry formatting on full storage.
|
|
static constexpr size_t EVENT_PROFILE_STORAGE_RESERVATION_BYTES = 2 * (meshtastic_LocalConfig_size + meshtastic_ChannelFile_size);
|
|
|
|
constexpr bool hasEventProfileStorageSpace(size_t totalBytes, size_t usedBytes)
|
|
{
|
|
return usedBytes <= totalBytes && totalBytes - usedBytes >= EVENT_PROFILE_STORAGE_RESERVATION_BYTES;
|
|
}
|
|
|
|
constexpr bool shouldDeferBootPersistence(bool bootInitializationInProgress, bool configLoadComplete, bool configDecodeFailed)
|
|
{
|
|
return bootInitializationInProgress && (!configLoadComplete || configDecodeFailed);
|
|
}
|
|
|
|
#if USERPREFS_EVENT_MODE
|
|
static constexpr auto RADIO_PROFILE_STORAGE = radioProfileStoragePaths(true);
|
|
#else
|
|
static constexpr auto RADIO_PROFILE_STORAGE = radioProfileStoragePaths(false);
|
|
#endif
|
|
static constexpr const char *configFileName = RADIO_PROFILE_STORAGE.config;
|
|
static constexpr const char *channelFileName = RADIO_PROFILE_STORAGE.channels;
|
|
static constexpr const char *backupFileName = RADIO_PROFILE_STORAGE.backup;
|
|
static constexpr const char *uiconfigFileName = "/prefs/uiconfig.proto";
|
|
static constexpr const char *moduleConfigFileName = "/prefs/module.proto";
|
|
|
|
// An unverified config load only endangers the radio profile, so only these files take part in
|
|
// boot-write deferral. Lives next to the path table above so the two cannot drift apart.
|
|
inline bool isRadioProfileFile(const char *filename)
|
|
{
|
|
return strcmp(filename, configFileName) == 0 || strcmp(filename, channelFileName) == 0 ||
|
|
strcmp(filename, backupFileName) == 0;
|
|
}
|
|
|
|
/// "No trustworthy arrival time", as distinct from "zero seconds ago". Deliberately huge so the
|
|
/// display formatters fall into their existing unknown-age branches ("unknown age" / "?").
|
|
inline constexpr uint32_t SINCE_UNKNOWN = UINT32_MAX;
|
|
|
|
/// Given a node, return how many seconds in the past (vs now) that we last heard from it
|
|
uint32_t sinceLastSeen(const meshtastic_NodeInfoLite *n);
|
|
|
|
/// Given a packet, return how many seconds in the past (vs now) it was received,
|
|
/// or SINCE_UNKNOWN if it carries no trustworthy rx_time.
|
|
uint32_t sinceReceived(const meshtastic_MeshPacket *p);
|
|
|
|
/// Outcome of mapping a single on-wire last-byte (next_hop / relay_node) back to a full NodeNum.
|
|
/// Because the wire only carries the last byte of a 32-bit node number, the mapping is ambiguous on
|
|
/// dense meshes (the "birthday problem"). Callers must treat Ambiguous and None as "don't trust it".
|
|
enum class LastByteResolution : uint8_t {
|
|
None, ///< no relevant candidate node has this last byte
|
|
Unique, ///< exactly one relevant candidate -> `num` is valid
|
|
Ambiguous, ///< two or more relevant candidates collide on this byte
|
|
};
|
|
|
|
struct ResolvedNode {
|
|
LastByteResolution status = LastByteResolution::None;
|
|
NodeNum num = 0; ///< valid only when status == Unique
|
|
};
|
|
|
|
/// Given a packet, return the number of hops used to reach this node.
|
|
/// Returns defaultIfUnknown if the number of hops couldn't be determined.
|
|
int8_t getHopsAway(const meshtastic_MeshPacket &p, int8_t defaultIfUnknown = -1);
|
|
|
|
enum class HopStartStatus : uint8_t { VALID = 0, MISSING_OR_UNKNOWN, INVALID };
|
|
|
|
/// Classify hop_start validity for forwarding decisions.
|
|
HopStartStatus classifyHopStart(const meshtastic_MeshPacket &p);
|
|
|
|
inline bool shouldDropPacketForPreHop(const meshtastic_MeshPacket &p)
|
|
{
|
|
#if !MESHTASTIC_PREHOP_DROP
|
|
(void)p;
|
|
return false;
|
|
#else
|
|
if (isFromUs(&p)) {
|
|
return false; // local-originated packets should never be dropped by pre-hop drop policy
|
|
}
|
|
// Pre-decode: the channel-encrypted bitfield isn't readable yet, so a missing/unknown hop_start can't be
|
|
// distinguished from a modern packet. Only drop the provably-corrupt case here; the bitfield-dependent
|
|
// verdict is re-checked post-decode in Router::handleReceived.
|
|
return classifyHopStart(p) == HopStartStatus::INVALID;
|
|
#endif
|
|
}
|
|
|
|
/// Rate-limited debug log when hop_start is invalid/missing and packet is dropped.
|
|
void logHopStartDrop(const meshtastic_MeshPacket &p, const char *context);
|
|
|
|
/// 2.8 position/telemetry opt-in migration (pure field mutators; exposed for native tests).
|
|
/// Disable position broadcast on every PUBLIC/default-PSK channel (precision -> 0); private-PSK
|
|
/// channels (deliberate trusted groups) are left untouched.
|
|
void optInDisablePositionSharing(meshtastic_ChannelFile &cf);
|
|
/// Force all mesh-broadcast device telemetry (and the MQTT map-report location) back to opt-in/off.
|
|
void optInDisableTelemetryBroadcast(meshtastic_LocalModuleConfig &mc);
|
|
|
|
enum LoadFileResult {
|
|
// Successfully opened the file
|
|
LOAD_SUCCESS = 1,
|
|
// File does not exist
|
|
NOT_FOUND = 2,
|
|
// Device does not have a filesystem
|
|
NO_FILESYSTEM = 3,
|
|
// File exists, but could not decode protobufs
|
|
DECODE_FAILED = 4,
|
|
// File exists, but open failed for some reason
|
|
OTHER_FAILURE = 5
|
|
};
|
|
|
|
enum UserLicenseStatus { NotKnown, NotLicensed, Licensed };
|
|
|
|
class NodeDB
|
|
{
|
|
// NodeNum provisionalNodeNum; // if we are trying to find a node num this is our current attempt
|
|
|
|
// A NodeInfo for every node we've seen
|
|
// Eventually use a smarter datastructure
|
|
// HashMap<NodeNum, NodeInfo> nodes;
|
|
// Note: these two references just point into our static array we serialize to/from disk
|
|
|
|
public:
|
|
std::vector<meshtastic_NodeInfoLite> *meshNodes;
|
|
bool updateGUI = false; // we think the gui should definitely be redrawn, screen will clear this once handled
|
|
meshtastic_NodeInfoLite *updateGUIforNode = NULL; // if currently showing this node, we think you should update the GUI
|
|
Observable<const meshtastic::NodeStatus *> newStatus;
|
|
pb_size_t numMeshNodes;
|
|
|
|
// Satellite per-NodeNum maps. std::map avoids unordered_map's bucket-array
|
|
// preallocation; O(log N) lookup is fine at these sizes.
|
|
#if !MESHTASTIC_EXCLUDE_POSITIONDB
|
|
std::map<NodeNum, meshtastic_PositionLite> nodePositions;
|
|
#endif
|
|
#if !MESHTASTIC_EXCLUDE_TELEMETRYDB
|
|
std::map<NodeNum, meshtastic_DeviceMetrics> nodeTelemetry;
|
|
#endif
|
|
#if !MESHTASTIC_EXCLUDE_ENVIRONMENTDB
|
|
std::map<NodeNum, meshtastic_EnvironmentMetrics> nodeEnvironment;
|
|
#endif
|
|
#if !MESHTASTIC_EXCLUDE_STATUSDB
|
|
std::map<NodeNum, meshtastic_StatusMessage> nodeStatus;
|
|
#endif
|
|
|
|
bool keyIsLowEntropy = false;
|
|
bool hasWarned = false;
|
|
bool licensedIdentityMigrationPending = false;
|
|
|
|
/// don't do mesh based algorithm for node id assignment (initially)
|
|
/// instead just store in flash - possibly even in the initial alpha release do this hack
|
|
NodeDB();
|
|
|
|
/// write to flash
|
|
/// @return true if the save was successful
|
|
bool saveToDisk(int saveWhat = SEGMENT_CONFIG | SEGMENT_MODULECONFIG | SEGMENT_DEVICESTATE | SEGMENT_CHANNELS |
|
|
SEGMENT_NODEDATABASE);
|
|
|
|
/** Reinit radio config if needed, because either:
|
|
* a) sometimes a buggy android app might send us bogus settings or
|
|
* b) the client set factory_reset
|
|
*
|
|
* @param factory_reset if true, reset all settings to factory defaults
|
|
* @param is_fresh_install set to true after a fresh install, to trigger NodeInfo/Position requests
|
|
* @return true if the config was completely reset, in that case, we should send it back to the client
|
|
*/
|
|
void resetRadioConfig(bool is_fresh_install = false);
|
|
|
|
/// given a subpacket sniffed from the network, update our DB state
|
|
/// we updateGUI and updateGUIforNode if we think our this change is big enough for a redraw
|
|
void updateFrom(const meshtastic_MeshPacket &p);
|
|
|
|
void addFromContact(const meshtastic_SharedContact);
|
|
|
|
/** Update position info for this node based on received position data
|
|
*/
|
|
void updatePosition(uint32_t nodeId, const meshtastic_Position &p, RxSource src = RX_SRC_RADIO);
|
|
|
|
/** Update telemetry info for this node based on received metrics
|
|
*/
|
|
void updateTelemetry(uint32_t nodeId, const meshtastic_Telemetry &t, RxSource src = RX_SRC_RADIO);
|
|
|
|
/** Update user info and channel for this node based on received user data.
|
|
* A known signer's identity is only learned when xeddsaSigned; defaults false so callers fail closed. */
|
|
bool updateUser(uint32_t nodeId, meshtastic_User &p, uint8_t channelIndex = 0, bool xeddsaSigned = false);
|
|
|
|
/*
|
|
* Sets a node either favorite or unfavorite. Returns true if the node ends
|
|
* up in the requested state; false if the node is unknown or favouriting
|
|
* was refused by the protected-node cap (MAX_NUM_NODES - 2).
|
|
*/
|
|
bool set_favorite(bool is_favorite, uint32_t nodeId);
|
|
|
|
/// Count of eviction-protected (favourite/ignored/manually-verified) nodes.
|
|
int numProtectedNodes() const;
|
|
|
|
/// printf-style warning emitted when setProtectedFlag() refuses a node at
|
|
/// the cap. %s = verb (favorite/ignore), 0x%08x = node, %d = cap. Shared by
|
|
/// LOG_WARN here and AdminModule::sendWarning so the wording stays in sync.
|
|
static constexpr const char *PROTECTED_CAP_WARN_FMT = "Can't %s 0x%08x: protected-node limit (%d) reached";
|
|
|
|
/// Turn an eviction-protection flag (favourite/ignored/verified) on/off. Off
|
|
/// always succeeds; on returns false (no change) once the protected set hits
|
|
/// the cap (MAX_NUM_NODES-2), keeping >=2 always-evictable slots. Callers
|
|
/// surface the refusal to the user.
|
|
bool setProtectedFlag(meshtastic_NodeInfoLite *node, uint32_t mask, bool on);
|
|
|
|
/*
|
|
* Returns true if the node is in the NodeDB and marked as favorite
|
|
*/
|
|
bool isFavorite(uint32_t nodeId);
|
|
|
|
/*
|
|
* Returns true if p->from or p->to is a favorited node
|
|
*/
|
|
bool isFromOrToFavoritedNode(const meshtastic_MeshPacket &p);
|
|
|
|
/**
|
|
* Other functions like the node picker can request a pause in the node sorting
|
|
*/
|
|
void pause_sort(bool paused);
|
|
|
|
/// @return our node number
|
|
NodeNum getNodeNum() { return myNodeInfo.my_node_num; }
|
|
|
|
/// @return our node ID as a string in the format "!xxxxxxxx"
|
|
std::string getNodeId() const;
|
|
|
|
// @return last byte of a NodeNum, 0xFF if it ended at 0x00
|
|
uint8_t getLastByteOfNodeNum(NodeNum num) { return (uint8_t)((num & 0xFF) ? (num & 0xFF) : 0xFF); }
|
|
|
|
/// if returns false, that means our node should send a DenyNodeNum response. If true, we think the number is okay for use
|
|
// bool handleWantNodeNum(NodeNum n);
|
|
|
|
/* void handleDenyNodeNum(NodeNum FIXME read mesh proto docs, perhaps picking a random node num is not a great idea
|
|
and instead we should use a special 'im unconfigured node number' and include our desired node number in the wantnum message.
|
|
the unconfigured node num would only be used while initially joining the mesh so low odds of conflicting (especially if we
|
|
randomly select from a small number of nodenums which can be used temporarily for this operation). figure out what the lower
|
|
level mesh sw does if it does conflict? would it be better for people who are replying with denynode num to just broadcast
|
|
their denial?)
|
|
*/
|
|
|
|
// get channel channel index we heard a nodeNum on, defaults to 0 if not found
|
|
uint8_t getMeshNodeChannel(NodeNum n);
|
|
|
|
/* Return the number of nodes we've heard from recently (within the last 2 hrs?)
|
|
* @param localOnly if true, ignore nodes heard via MQTT
|
|
*/
|
|
size_t getNumOnlineMeshNodes(bool localOnly = false);
|
|
|
|
void initConfigIntervals(), initModuleConfigIntervals(), resetNodes(bool keepFavorites = false),
|
|
removeNodeByNum(NodeNum nodeNum);
|
|
|
|
bool factoryReset(bool eraseBleBonds = false);
|
|
|
|
LoadFileResult loadProto(const char *filename, size_t protoSize, size_t objSize, const pb_msgdesc_t *fields,
|
|
void *dest_struct);
|
|
bool saveProto(const char *filename, size_t protoSize, const pb_msgdesc_t *fields, const void *dest_struct,
|
|
bool fullAtomic = true);
|
|
|
|
void installRoleDefaults(meshtastic_Config_DeviceConfig_Role role);
|
|
|
|
const meshtastic_NodeInfoLite *readNextMeshNode(uint32_t &readIndex);
|
|
|
|
meshtastic_NodeInfoLite *getMeshNodeByIndex(size_t x)
|
|
{
|
|
assert(x < numMeshNodes);
|
|
return &meshNodes->at(x);
|
|
}
|
|
|
|
virtual meshtastic_NodeInfoLite *getMeshNode(NodeNum n);
|
|
size_t getNumMeshNodes() { return numMeshNodes; }
|
|
/// Find a node in our DB, create an empty NodeInfoLite if missing (evicting
|
|
/// the oldest non-protected node when full). Public so admin handlers can
|
|
/// register a node we have not heard from yet (e.g. to block it by ID).
|
|
meshtastic_NodeInfoLite *getOrCreateMeshNode(NodeNum n);
|
|
|
|
#if WARM_NODE_COUNT > 0
|
|
// Warm ("long-tail") tier: minimal {num, last_heard, public_key} records
|
|
// for nodes evicted from the hot store. See WarmNodeStore.h.
|
|
WarmNodeStore warmStore;
|
|
#endif
|
|
|
|
/// Copy the 32-byte public key for node n - hot store first, then the warm
|
|
/// tier. Returns false if we don't know a key for n.
|
|
bool copyPublicKey(NodeNum n, meshtastic_NodeInfoLite_public_key_t &out);
|
|
|
|
/// Copy the 32-byte key for n from the AUTHORITATIVE tiers only (hot, then warm; never
|
|
/// opportunistic caches) - the pin reference for caches that mirror NodeDB's key hygiene.
|
|
bool copyPublicKeyAuthoritative(NodeNum n, meshtastic_NodeInfoLite_public_key_t &out);
|
|
|
|
/// Key for the inbound-decrypt path: authoritative (hot/warm), or a cold-tier cache key only when
|
|
/// it is key-proven. Keeps unverified TOFU cache keys from backing pki_encrypted attribution.
|
|
bool copyPublicKeyForDecrypt(NodeNum n, meshtastic_NodeInfoLite_public_key_t &out);
|
|
|
|
/// True if n is a known XEdDSA signer for exactly `key32` (hot signed bitfield or warm
|
|
/// xeddsa-signed bit); the key match stops a rotated key inheriting a stale signer verdict.
|
|
bool isVerifiedSignerForKey(NodeNum n, const uint8_t *key32);
|
|
|
|
/// Key-agnostic "should n's signable traffic arrive signed", per hot bitfield or warm
|
|
/// xeddsa-signed bit - hot-only gates would let a warm-evicted signer be impersonated with unsigned frames.
|
|
bool isKnownXeddsaSigner(NodeNum n);
|
|
|
|
/// Provenance of a bare-key commit that deliberately bypasses updateUser()'s
|
|
/// User-payload / TOFU-pin path. Maps to the TrafficManagement cache's `proven` flag:
|
|
/// only ManuallyVerified vouches for possession of exactly this key.
|
|
enum class KeyCommitTrust : uint8_t {
|
|
AdminChannelProven, // possession shown to the admin channel (AEAD) - TOFU-grade for signing
|
|
ManuallyVerified, // the user confirmed possession of exactly this key
|
|
};
|
|
|
|
/// THE primitive for key writes that bypass updateUser() (no User payload; provenance
|
|
/// differs from a received NodeInfo): writes the 32-byte key to the hot store and
|
|
/// write-through to the TrafficManagement NodeInfo cache. Any future direct key-write
|
|
/// site must call this rather than assigning info->public_key, or the TrafficManagement
|
|
/// cache silently diverges until the next hourly reconcile.
|
|
void commitRemoteKey(NodeNum n, const uint8_t key32[32], KeyCommitTrust trust);
|
|
|
|
/// Resolve a node's device role - hot store (with user) first, then the role
|
|
/// cached in the warm tier, else CLIENT. Lets role-aware policy keep firing for
|
|
/// nodes that have aged out of the hot store.
|
|
meshtastic_Config_DeviceConfig_Role getNodeRole(NodeNum n);
|
|
|
|
/// last_heard of a hot-store node, or 0 if absent. Plain scan of meshNodes
|
|
/// with no allocation side effects (unlike getOrCreateMeshNode).
|
|
uint32_t hotNodeLastHeard(NodeNum n) const;
|
|
|
|
/**
|
|
* Resolve a single on-wire last-byte (e.g. next_hop / relay_node) back to a unique full NodeNum,
|
|
* detecting last-byte collisions instead of silently picking the first match. A 1-byte id only
|
|
* needs to be unique among a node's plausible relays, not the whole mesh, so we scope the search:
|
|
* - requireDirectNeighbor == true : candidates are direct neighbors (hops_away==0) heard within
|
|
* NEXTHOP_NEIGHBOR_FRESH_SECS. Use on the SEND path.
|
|
* - requireDirectNeighbor == false : also accept favorites and router-role nodes (unknown hop
|
|
* distance allowed). Use when learning / preserving hops.
|
|
* Ignored nodes, our own node, and the broadcast/0 sentinels are never candidates. On a tie the
|
|
* result is Ambiguous (no tie-break) so callers fall back to flooding rather than misroute.
|
|
*/
|
|
ResolvedNode resolveLastByte(uint8_t lastByte, bool requireDirectNeighbor);
|
|
|
|
/// Convenience wrapper around resolveLastByte(): true iff exactly one relevant candidate matches.
|
|
/// Ambiguous and None both return false (the safe answer for learning / hop preservation).
|
|
bool resolveUniqueLastByte(uint8_t lastByte, bool requireDirectNeighbor, NodeNum *outNum = nullptr);
|
|
|
|
// Thread-safe satellite-map accessors. Return false if absent or the
|
|
// corresponding DB is compiled out.
|
|
bool copyNodePosition(NodeNum n, meshtastic_PositionLite &out) const;
|
|
bool copyNodeTelemetry(NodeNum n, meshtastic_DeviceMetrics &out) const;
|
|
bool copyNodeEnvironment(NodeNum n, meshtastic_EnvironmentMetrics &out) const;
|
|
bool copyNodeStatus(NodeNum n, meshtastic_StatusMessage &out) const;
|
|
std::vector<NodeNum> snapshotPositionNodeNums(NodeNum exclude) const;
|
|
std::vector<NodeNum> snapshotTelemetryNodeNums(NodeNum exclude) const;
|
|
std::vector<NodeNum> snapshotEnvironmentNodeNums(NodeNum exclude) const;
|
|
std::vector<NodeNum> snapshotStatusNodeNums(NodeNum exclude) const;
|
|
|
|
void setNodeStatus(NodeNum n, const meshtastic_StatusMessage &status);
|
|
void touchNodePositionTime(NodeNum n, uint32_t time);
|
|
|
|
bool hasNodePosition(NodeNum n) const
|
|
{
|
|
meshtastic_PositionLite scratch;
|
|
return copyNodePosition(n, scratch);
|
|
}
|
|
bool hasNodeTelemetry(NodeNum n) const
|
|
{
|
|
meshtastic_DeviceMetrics scratch;
|
|
return copyNodeTelemetry(n, scratch);
|
|
}
|
|
bool hasNodeEnvironment(NodeNum n) const
|
|
{
|
|
meshtastic_EnvironmentMetrics scratch;
|
|
return copyNodeEnvironment(n, scratch);
|
|
}
|
|
bool hasNodeStatus(NodeNum n) const
|
|
{
|
|
meshtastic_StatusMessage scratch;
|
|
return copyNodeStatus(n, scratch);
|
|
}
|
|
|
|
void eraseNodeSatellites(NodeNum n);
|
|
|
|
UserLicenseStatus getLicenseStatus(uint32_t nodeNum);
|
|
|
|
size_t getMaxNodesAllocatedSize()
|
|
{
|
|
meshtastic_NodeDatabase emptyNodeDatabase;
|
|
emptyNodeDatabase.version = DEVICESTATE_CUR_VER;
|
|
size_t nodeDatabaseSize;
|
|
pb_get_encoded_size(&nodeDatabaseSize, meshtastic_NodeDatabase_fields, &emptyNodeDatabase);
|
|
// Decode-stream size ceiling only - no buffer this big is allocated (load
|
|
// streams from the file). Sized for the largest file any prior firmware
|
|
// could write, so capacity downgrades / peer backups still decode; excess
|
|
// is trimmed after load. See NODEDB_MIGRATION_LOAD_CEILING above - it is a
|
|
// migration allowance, not this build's cap.
|
|
// (not constexpr: portduino resolves MAX_NUM_NODES from runtime config)
|
|
const size_t loadCeiling =
|
|
((size_t)MAX_NUM_NODES > NODEDB_MIGRATION_LOAD_CEILING) ? (size_t)MAX_NUM_NODES : NODEDB_MIGRATION_LOAD_CEILING;
|
|
return nodeDatabaseSize + (loadCeiling * meshtastic_NodeInfoLite_size) +
|
|
(loadCeiling * meshtastic_NodePositionEntry_size) + (loadCeiling * meshtastic_NodeTelemetryEntry_size) +
|
|
(loadCeiling * meshtastic_NodeEnvironmentEntry_size) + (loadCeiling * meshtastic_NodeStatusEntry_size);
|
|
}
|
|
|
|
// returns true if the maximum number of nodes is reached or we are running low on memory
|
|
bool isFull();
|
|
|
|
void clearLocalPosition();
|
|
|
|
void setLocalPosition(meshtastic_Position position, bool timeOnly = false)
|
|
{
|
|
if (timeOnly) {
|
|
LOG_DEBUG("Set local position time only: time=%u timestamp=%u", position.time, position.timestamp);
|
|
localPosition.time = position.time;
|
|
localPosition.timestamp = position.timestamp > 0 ? position.timestamp : position.time;
|
|
return;
|
|
}
|
|
LOG_DEBUG("Set local position: lat=%i lon=%i time=%u timestamp=%u", position.latitude_i, position.longitude_i,
|
|
position.time, position.timestamp);
|
|
localPosition = position;
|
|
if (position.latitude_i != 0 || position.longitude_i != 0) {
|
|
localPositionUpdatedSinceBoot = true;
|
|
}
|
|
}
|
|
|
|
bool hasValidPosition(const meshtastic_NodeInfoLite *n);
|
|
bool hasLocalPositionSinceBoot() const { return localPositionUpdatedSinceBoot; }
|
|
|
|
#if !defined(MESHTASTIC_EXCLUDE_PKI)
|
|
bool checkLowEntropyPublicKey(const meshtastic_Config_SecurityConfig_public_key_t &keyToTest);
|
|
#endif
|
|
|
|
/// Consolidate crypto key generation logic used across multiple modules
|
|
/// @param privateKey Optional 32-byte private key to use. If nullptr, generates new random keys.
|
|
bool generateCryptoKeyPair(const uint8_t *privateKey = nullptr);
|
|
|
|
bool notifyPendingLicensedIdentityMigration();
|
|
|
|
bool createNewIdentity();
|
|
|
|
bool backupPreferences(meshtastic_AdminMessage_BackupLocation location);
|
|
bool restorePreferences(meshtastic_AdminMessage_BackupLocation location,
|
|
int restoreWhat = SEGMENT_CONFIG | SEGMENT_MODULECONFIG | SEGMENT_DEVICESTATE | SEGMENT_CHANNELS);
|
|
|
|
/// Notify observers of changes to the DB
|
|
void notifyObservers(bool forceUpdate = false)
|
|
{
|
|
// Notify observers of the current node state
|
|
const meshtastic::NodeStatus status = meshtastic::NodeStatus(getNumOnlineMeshNodes(), getNumMeshNodes(), forceUpdate);
|
|
newStatus.notifyObservers(&status);
|
|
}
|
|
|
|
#ifdef MESHTASTIC_ENCRYPTED_STORAGE
|
|
/// Re-run loadFromDisk() after the encrypted storage is unlocked at runtime.
|
|
/// Trigger: PhoneAPI::handleLockdownAuthInline sets lockdownReloadPending
|
|
/// on a successful provisionPassphrase / unlockWithPassphrase; the main
|
|
/// loop in main.cpp services the flag and calls this method on the main
|
|
/// thread. The transport callback stack (BLE/USB) is too small for the
|
|
/// file IO + MAX_NUM_NODES vector reserve + proto decode this triggers.
|
|
///
|
|
/// Returns true iff every encrypted file decrypted and decoded cleanly.
|
|
/// On false the caller MUST treat the storage as corrupt: leave the
|
|
/// connection unauthenticated, emit a LOCKED(storage_corrupt) status,
|
|
/// and refuse to call setAdminAuthorized - otherwise a subsequent
|
|
/// set_config would re-encrypt a wrong baseline (the locked-default
|
|
/// values still resident in `config` / `channelFile` / `nodeDatabase`)
|
|
/// and overwrite the operator's persisted state.
|
|
bool reloadFromDisk();
|
|
|
|
/// Disable lockdown: decrypt every encrypted pref file back to plaintext,
|
|
/// then remove the DEK / token / counter / backoff artifacts. Requires
|
|
/// EncryptedStorage to be unlocked (DEK in RAM). Returns false if any
|
|
/// file failed to revert - in which case the DEK is still present and the
|
|
/// device remains in lockdown so the operator can retry. APPROTECT is not
|
|
/// reversed. Called from the main loop via lockdownDisablePending.
|
|
bool disableLockdownToPlaintext();
|
|
|
|
/// Set by loadProto when any encrypted file fails to decrypt or decode.
|
|
/// Tracked across an entire loadFromDisk pass so reloadFromDisk can
|
|
/// surface the condition without callers re-walking each loadProto
|
|
/// result. Cleared at the top of every loadFromDisk run.
|
|
bool storageCorruptThisLoad = false;
|
|
#endif
|
|
|
|
private:
|
|
mutable concurrency::Lock satelliteMutex;
|
|
bool duplicateWarned = false;
|
|
bool localPositionUpdatedSinceBoot = false;
|
|
bool migrationSavePending = false;
|
|
/// Set when loadFromDisk() hit a present-but-undecodable config (DECODE_FAILED). The ctor uses it to
|
|
/// skip boot keygen and skip persisting defaults, so a transient read failure can't change our NodeNum
|
|
/// or overwrite the on-disk config. Cleared at the top of every loadFromDisk() run.
|
|
bool configDecodeFailed = false;
|
|
// Defer automatic writes until config load is healthy to protect device and node data from damaged configs.
|
|
bool bootInitializationInProgress = true;
|
|
bool configLoadComplete = false;
|
|
#if USERPREFS_EVENT_MODE
|
|
// The active event profile is intentionally non-durable when there was not
|
|
// enough room to create it safely at boot. A later boot retries the check.
|
|
bool eventProfileStorageUnavailable = false;
|
|
#endif
|
|
uint32_t lastNodeDbSave = 0; // when we last saved our db to flash
|
|
uint32_t lastFullEvictionMs = 0; // when we last evicted to admit a new node, once the db is full
|
|
uint32_t lastBackupAttempt = 0; // when we last tried a backup automatically or manually
|
|
uint32_t lastSort = 0; // When last sorted the nodeDB
|
|
|
|
/*
|
|
* Internal boolean to track sorting paused
|
|
*/
|
|
bool sortingIsPaused = false;
|
|
|
|
/// pick a provisional nodenum we hope no one is using
|
|
void pickNewNodeNum();
|
|
|
|
/// read our db from flash
|
|
void loadFromDisk();
|
|
|
|
#ifdef PIO_UNIT_TESTING
|
|
// Grant the unit-test shim access to the private maintenance paths below
|
|
// (migration / cleanup / eviction) without relaxing production access.
|
|
friend class NodeDBTestShim;
|
|
friend class MockNodeDB;
|
|
#endif
|
|
|
|
/// purge db entries without user info
|
|
void cleanupMeshDB();
|
|
|
|
/// Trim each satellite map down to MAX_SATELLITE_NODES, dropping the
|
|
/// stalest entries (used after loading files written before the cap, or by
|
|
/// a build with a larger cap). Returns true iff anything was trimmed.
|
|
bool enforceSatelliteCaps();
|
|
|
|
/// Node-DB self-care; call only once identity is established (getNodeNum()
|
|
/// valid). Confirms self is present, trims/demotes only NON-self overflow, and
|
|
/// rewrites the store once when something changed (never while storage locked).
|
|
void nodeDBSelfCare();
|
|
|
|
#if WARM_NODE_COUNT > 0
|
|
/// A database from a larger-cap build (e.g. the pre-fork 150-node nRF52 store)
|
|
/// can exceed MAX_NUM_NODES on load. Rank the hot store, demote the oldest
|
|
/// overflow into the warm tier preserving {num, last_heard, public_key} so PKI
|
|
/// DMs survive instead of dropping on truncation.
|
|
void demoteOldestHotNodesToWarm();
|
|
#endif
|
|
|
|
/// Reinit device state from scratch (not loading from disk)
|
|
void installDefaultDeviceState(), installDefaultNodeDatabase(), installDefaultChannels(),
|
|
installDefaultConfig(bool preserveKey), installDefaultModuleConfig();
|
|
|
|
/// write to flash
|
|
/// @return true if the save was successful
|
|
bool saveToDiskNoRetry(int saveWhat);
|
|
|
|
bool saveChannelsToDisk();
|
|
bool saveDeviceStateToDisk();
|
|
bool saveNodeDatabaseToDisk();
|
|
void sortMeshDB();
|
|
|
|
// Defined in NodeDBLegacyMigration.cpp. Decodes /prefs/nodes.proto via
|
|
// the legacy descriptor and copies entries into the v25 layout. Caller
|
|
// is responsible for save / install-default on the result.
|
|
bool migrateLegacyNodeDatabase();
|
|
|
|
// Route satellite-store decode entries straight into our maps instead of
|
|
// temp vectors. Must be paired - disarm before any other NodeDatabase decode.
|
|
void armNodeDatabaseDecodeTargets();
|
|
void disarmNodeDatabaseDecodeTargets();
|
|
};
|
|
|
|
extern NodeDB *nodeDB;
|
|
|
|
/*
|
|
If is_router is set, we use a number of different default values
|
|
|
|
# FIXME - after tuning, move these params into the on-device defaults based on is_router and is_power_saving
|
|
|
|
# prefs.position_broadcast_secs = FIXME possibly broadcast only once an hr
|
|
prefs.wait_bluetooth_secs = 1 # Don't stay in bluetooth mode
|
|
# try to stay in light sleep one full day, then briefly wake and sleep again
|
|
|
|
prefs.ls_secs = oneday
|
|
|
|
prefs.position_broadcast_secs = 12 hours # send either position or owner every 12hrs
|
|
|
|
# get a new GPS position once per day
|
|
prefs.gps_update_interval = oneday
|
|
|
|
prefs.is_power_saving = True
|
|
*/
|
|
|
|
/** The current change # for radio settings. Starts at 0 on boot and any time the radio settings
|
|
* might have changed is incremented. Allows others to detect they might now be on a new channel.
|
|
*/
|
|
extern uint32_t radioGeneration;
|
|
|
|
extern meshtastic_CriticalErrorCode error_code;
|
|
|
|
/*
|
|
* A numeric error address (nonzero if available)
|
|
*/
|
|
extern uint32_t error_address;
|
|
// Bit assignments for meshtastic_NodeInfoLite.bitfield.
|
|
#define NODEINFO_BITFIELD_IS_KEY_MANUALLY_VERIFIED_SHIFT 0
|
|
#define NODEINFO_BITFIELD_IS_KEY_MANUALLY_VERIFIED_MASK (1u << NODEINFO_BITFIELD_IS_KEY_MANUALLY_VERIFIED_SHIFT)
|
|
#define NODEINFO_BITFIELD_IS_MUTED_SHIFT 1
|
|
#define NODEINFO_BITFIELD_IS_MUTED_MASK (1u << NODEINFO_BITFIELD_IS_MUTED_SHIFT)
|
|
#define NODEINFO_BITFIELD_VIA_MQTT_SHIFT 2
|
|
#define NODEINFO_BITFIELD_VIA_MQTT_MASK (1u << NODEINFO_BITFIELD_VIA_MQTT_SHIFT)
|
|
#define NODEINFO_BITFIELD_IS_FAVORITE_SHIFT 3
|
|
#define NODEINFO_BITFIELD_IS_FAVORITE_MASK (1u << NODEINFO_BITFIELD_IS_FAVORITE_SHIFT)
|
|
#define NODEINFO_BITFIELD_IS_IGNORED_SHIFT 4
|
|
#define NODEINFO_BITFIELD_IS_IGNORED_MASK (1u << NODEINFO_BITFIELD_IS_IGNORED_SHIFT)
|
|
#define NODEINFO_BITFIELD_HAS_USER_SHIFT 5
|
|
#define NODEINFO_BITFIELD_HAS_USER_MASK (1u << NODEINFO_BITFIELD_HAS_USER_SHIFT)
|
|
#define NODEINFO_BITFIELD_IS_LICENSED_SHIFT 6
|
|
#define NODEINFO_BITFIELD_IS_LICENSED_MASK (1u << NODEINFO_BITFIELD_IS_LICENSED_SHIFT)
|
|
#define NODEINFO_BITFIELD_IS_UNMESSAGABLE_SHIFT 7
|
|
#define NODEINFO_BITFIELD_IS_UNMESSAGABLE_MASK (1u << NODEINFO_BITFIELD_IS_UNMESSAGABLE_SHIFT)
|
|
#define NODEINFO_BITFIELD_HAS_IS_UNMESSAGABLE_SHIFT 8
|
|
#define NODEINFO_BITFIELD_HAS_IS_UNMESSAGABLE_MASK (1u << NODEINFO_BITFIELD_HAS_IS_UNMESSAGABLE_SHIFT)
|
|
#define NODEINFO_BITFIELD_HAS_XEDDSA_SIGNED_SHIFT 9
|
|
#define NODEINFO_BITFIELD_HAS_XEDDSA_SIGNED_MASK (1u << NODEINFO_BITFIELD_HAS_XEDDSA_SIGNED_SHIFT)
|
|
// snr_q4 (persisted, sint32) is proto3 singular, so 0 == "never written", but 0 dB is valid.
|
|
// This bit disambiguates: whenever snr_q4 is written from a genuine RF measurement.
|
|
// Use this instead of `if (snr_q4)`. Legacy records (bit clear) are unambiguously "unknown".
|
|
#define NODEINFO_BITFIELD_HAS_SNR_SHIFT 10
|
|
#define NODEINFO_BITFIELD_HAS_SNR_MASK (1u << NODEINFO_BITFIELD_HAS_SNR_SHIFT)
|
|
// Bits 11..31 reserved for future single-bit flags.
|
|
|
|
// Convenience accessors so call sites read like the old struct fields.
|
|
inline bool nodeInfoLiteHasUser(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_HAS_USER_MASK);
|
|
}
|
|
inline bool nodeInfoLiteViaMqtt(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_VIA_MQTT_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsFavorite(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_FAVORITE_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsIgnored(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_IGNORED_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsLicensed(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_LICENSED_MASK);
|
|
}
|
|
inline bool nodeInfoLiteHasIsUnmessagable(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_HAS_IS_UNMESSAGABLE_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsUnmessagable(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_UNMESSAGABLE_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsMuted(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_MUTED_MASK);
|
|
}
|
|
inline bool nodeInfoLiteIsKeyManuallyVerified(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_IS_KEY_MANUALLY_VERIFIED_MASK);
|
|
}
|
|
inline bool nodeInfoLiteHasXeddsaSigned(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_HAS_XEDDSA_SIGNED_MASK);
|
|
}
|
|
/// True if this node's snr_q4 was written from a genuine RF measurement (including a real
|
|
/// 0 dB reading). False means "never measured" - do not treat 0 as data.
|
|
inline bool nodeInfoLiteHasSnr(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return n && (n->bitfield & NODEINFO_BITFIELD_HAS_SNR_MASK);
|
|
}
|
|
/// A node that the eviction/migration paths must not drop: a favourite, an
|
|
/// ignored (blocked) node, or a manually-verified key.
|
|
inline bool nodeInfoLiteIsProtected(const meshtastic_NodeInfoLite *n)
|
|
{
|
|
return nodeInfoLiteIsFavorite(n) || nodeInfoLiteIsIgnored(n) || nodeInfoLiteIsKeyManuallyVerified(n);
|
|
}
|
|
|
|
inline void nodeInfoLiteSetBit(meshtastic_NodeInfoLite *n, uint32_t mask, bool value)
|
|
{
|
|
if (!n)
|
|
return;
|
|
if (value)
|
|
n->bitfield |= mask;
|
|
else
|
|
n->bitfield &= ~mask;
|
|
}
|
|
|
|
#define Module_Config_size \
|
|
(ModuleConfig_CannedMessageConfig_size + ModuleConfig_ExternalNotificationConfig_size + ModuleConfig_MQTTConfig_size + \
|
|
ModuleConfig_RangeTestConfig_size + ModuleConfig_SerialConfig_size + ModuleConfig_StoreForwardConfig_size + \
|
|
ModuleConfig_TelemetryConfig_size + ModuleConfig_size)
|
|
|
|
// Please do not remove this comment, it makes trunk and compiler happy at the same time.
|