mirror of
https://github.com/ruvnet/RuView
synced 2026-07-23 17:33:20 +00:00
f06d0c6ab5
* fix(firmware): move defensive node_id capture before wifi_init_sta()
The original defensive copy in csi_collector_init() (line 172 of main.c)
runs AFTER wifi_init_sta() (line 147), which on some ESP32-S3 devices
corrupts g_nvs_config.node_id back to the Kconfig default of 1.
Reproduced on device 80:b5:4e:c1:be:b8 (ESP32-S3 QFN56 rev v0.2):
- NVS provisioned with node_id=5
- Release firmware (no fix): seed receives node_id=1 (clobbered)
- This patch: seed receives node_id=5 (correct)
Changes:
- Add csi_collector_set_node_id() called from main.c immediately
after nvs_config_load(), before wifi_init_sta() runs
- csi_collector_init() now detects and logs the clobber if early
capture disagrees with current g_nvs_config value
- Fallback path preserved: if set_node_id() is never called,
init() still captures from g_nvs_config (backwards compatible)
Co-Authored-By: claude-flow <ruv@ruv.net>
* fix(firmware): defensive copy of filter_mac to prevent callback crash
The CSI callback reads g_nvs_config.filter_mac_set and filter_mac on
every invocation (100-500 Hz). If wifi_init_sta() corrupts g_nvs_config
(same root cause as the node_id clobber), the callback reads garbage
from the struct, leading to Core 0 LoadProhibited panic after ~2400
callbacks (~70 seconds of operation).
Extends the early-capture pattern from the node_id fix to also copy
filter_mac_set and filter_mac into module-local statics before WiFi
init runs. Adds canary logging to detect filter_mac corruption.
Observed on device 80:b5:4e:c1:be:b8 via serial:
CSI cb #2400 → Guru Meditation Error: Core 0 panic'ed (LoadProhibited)
→ TG0WDT_SYS_RST → reboot → crash again at ~2900 callbacks
Refs #232 #375 #385 #386 #390
Co-Authored-By: Ruflo & AQE
* fix(firmware): MGMT-only promiscuous filter to prevent SPI cache crash
The WiFi driver's wDev_ProcessFiq interrupt handler crashes with
LoadProhibited in cache_ll_l1_resume_icache when promiscuous mode
captures MGMT+DATA frames (100-500 interrupts/sec). The high interrupt
rate races with SPI flash cache operations, corrupting cache state.
Changes:
- Promiscuous filter: MGMT+DATA → MGMT-only (~10 Hz beacons)
- CSI config: disable htltf_en and stbc_htltf2_en (LLTF-only)
LLTF provides 64 subcarriers (HT20) — sufficient for presence,
breathing, and fall detection. The 10 Hz beacon rate eliminates
the SPI flash cache contention that caused the crash.
Verified on device 80:b5:4e:c1:be:b8:
- Before: LoadProhibited crash at ~1600-2400 callbacks (every ~70s)
- After: 2700+ callbacks over 4.7 minutes, zero crashes
Backtrace decode confirmed crash in ESP-IDF closed-source WiFi blob:
_xt_lowint1 → wDev_ProcessFiq → spi_flash_restore_cache
→ cache_ll_l1_resume_icache → EXCVADDR=0x00000004 (NULL deref)
Co-Authored-By: Ruflo & AQE
* fix(provision): write-flash → write_flash for esptool v5 compat
esptool v5+ rejects hyphenated subcommands. The provision script
used 'write-flash' which fails with "invalid choice". Changed to
'write_flash' (underscore) which works with both old and new esptool.
Co-Authored-By: Ruflo & AQE
* fix(firmware): 50 Hz callback rate gate + sdkconfig extra IRAM opt
- Add early rate gate in wifi_csi_callback at 50 Hz (defense-in-depth,
does not prevent crash alone but reduces callback execution time)
- Add null-data injection timer infrastructure (disabled — TX adds
interrupt pressure that triggers the SPI cache crash, RuView#396)
- sdkconfig.defaults: add CONFIG_ESP_WIFI_EXTRA_IRAM_OPT=y
- sdkconfig.defaults: document SPIRAM XIP attempt (crashes differently)
Co-Authored-By: Ruflo & AQE
* fix(firmware): address PR #397 review feedback
Applies @ruvnet's five review requests on PR #397 (RuView#397 comment
4289417527):
1. **Inline comment on `provision.py` `write_flash`** — ESP-IDF v5.4
bundles esptool 4.10.0 (underscore-only). #391's hyphen swap broke
the documented venv flow; kept the underscore form and added a
three-line comment warning future maintainers not to "re-fix" it.
2. **Correct `edge_processing.c` sample_rate** (blocking) — changed
hard-coded `20.0f` → `10.0f` at line 718 so
`estimate_bpm_zero_crossing()` matches the MGMT-only CSI rate.
Without this, breathing and heart-rate reports were 2× the true
value. Added a comment tying the constant to the callback rate gate.
3. **Removed disabled probe-injection infrastructure** — dropped the
forward declaration, the `CSI_PROBE_INTERVAL_MS` define, six static
variables (`s_probe_timer`, `s_probe_tx_count`, `s_probe_tx_fail`,
`s_ap_bssid`, `s_ap_bssid_known`), and three functions
(`csi_send_probe_request`, `probe_timer_cb`,
`csi_collector_start_probe_timer`). None were reachable.
`csi_inject_ndp_frame()` reverted to the original ADR-029 stub.
Can be revived from this commit's parent if needed.
4. **Cleaned `sdkconfig.defaults`** — removed the SPIRAM prose and
commented-out `# CONFIG_SPIRAM is not set` line. Kept only the live
`CONFIG_ESP_WIFI_EXTRA_IRAM_OPT=y` with a concise rationale.
5. **Bumped firmware version 0.6.1 → 0.6.2** and added four
`[Unreleased]` CHANGELOG entries covering the SPI cache crash fix,
the `filter_mac` / `node_id` clobber defense, the sample-rate
correction, and the `write_flash` command-form revert.
Net: +39 / -128 across six files.
Validation in this devcontainer:
- Static sanity on modified C files: braces balance (csi_collector.c
59/59; edge_processing.c 96/96), zero dangling references to removed
probe-injection symbols.
- Rust workspace tests and Python proof not executed here — cargo not
installed and pip blocked by PEP 668. Deferring hardware build +
flash + miniterm verification to @ruvnet's COM7 per his offer in
the review comment.
Co-Authored-By: claude-flow <ruv@ruv.net>
---------
Co-authored-by: Dragan Spiridonov <spiridonovdragan@gmail.com>
127 lines
4.0 KiB
C
127 lines
4.0 KiB
C
/**
|
|
* @file csi_collector.h
|
|
* @brief CSI data collection and ADR-018 binary frame serialization.
|
|
*/
|
|
|
|
#ifndef CSI_COLLECTOR_H
|
|
#define CSI_COLLECTOR_H
|
|
|
|
#include <stdint.h>
|
|
#include <stddef.h>
|
|
#include "esp_err.h"
|
|
#include "esp_wifi_types.h"
|
|
|
|
/** ADR-018 magic number. */
|
|
#define CSI_MAGIC 0xC5110001
|
|
|
|
/** ADR-018 header size in bytes. */
|
|
#define CSI_HEADER_SIZE 20
|
|
|
|
/** Maximum frame buffer size (header + 4 antennas * 256 subcarriers * 2 bytes). */
|
|
#define CSI_MAX_FRAME_SIZE (CSI_HEADER_SIZE + 4 * 256 * 2)
|
|
|
|
/** Maximum number of channels in the hop table (ADR-029). */
|
|
#define CSI_HOP_CHANNELS_MAX 6
|
|
|
|
/**
|
|
* Initialize CSI collection.
|
|
* Registers the WiFi CSI callback.
|
|
*/
|
|
void csi_collector_init(void);
|
|
|
|
/**
|
|
* Capture node_id BEFORE wifi_init_sta() or any other heavy init.
|
|
*
|
|
* Must be called from app_main() immediately after nvs_config_load().
|
|
* WiFi driver initialization can corrupt g_nvs_config.node_id (confirmed
|
|
* on device 80:b5:4e:c1:be:b8, NVS=3 but post-WiFi reads as 1).
|
|
* This early capture shields s_node_id from that corruption window.
|
|
*
|
|
* @param node_id Value from g_nvs_config.node_id, read right after NVS load.
|
|
*/
|
|
void csi_collector_set_node_id(uint8_t node_id);
|
|
|
|
/**
|
|
* Get the runtime node_id (early capture if available, otherwise init-time).
|
|
*
|
|
* Other modules (edge_processing, wasm_runtime, display_ui) should prefer
|
|
* this accessor over reading g_nvs_config.node_id directly.
|
|
*
|
|
* @return Node ID (0-255) as loaded from NVS at boot.
|
|
*/
|
|
uint8_t csi_collector_get_node_id(void);
|
|
|
|
/**
|
|
* Serialize CSI data into ADR-018 binary frame format.
|
|
*
|
|
* @param info WiFi CSI info from the ESP-IDF callback.
|
|
* @param buf Output buffer (must be at least CSI_MAX_FRAME_SIZE bytes).
|
|
* @param buf_len Size of the output buffer.
|
|
* @return Number of bytes written, or 0 on error.
|
|
*/
|
|
size_t csi_serialize_frame(const wifi_csi_info_t *info, uint8_t *buf, size_t buf_len);
|
|
|
|
/**
|
|
* Configure the channel-hop table for multi-band sensing (ADR-029).
|
|
*
|
|
* When hop_count == 1 the collector stays on the single configured channel
|
|
* (backward-compatible with the original single-channel mode).
|
|
*
|
|
* @param channels Array of WiFi channel numbers (1-14 for 2.4 GHz, 36-177 for 5 GHz).
|
|
* @param hop_count Number of entries in the channels array (1..CSI_HOP_CHANNELS_MAX).
|
|
* @param dwell_ms Dwell time per channel in milliseconds (>= 10).
|
|
*/
|
|
void csi_collector_set_hop_table(const uint8_t *channels, uint8_t hop_count, uint32_t dwell_ms);
|
|
|
|
/**
|
|
* Advance to the next channel in the hop table.
|
|
*
|
|
* Called by the hop timer callback. If hop_count <= 1 this is a no-op.
|
|
* Calls esp_wifi_set_channel() internally.
|
|
*/
|
|
void csi_hop_next_channel(void);
|
|
|
|
/**
|
|
* Start the channel-hop timer.
|
|
*
|
|
* Creates an esp_timer periodic callback that fires every dwell_ms
|
|
* milliseconds, calling csi_hop_next_channel(). If hop_count <= 1
|
|
* the timer is not started (single-channel backward-compatible mode).
|
|
*/
|
|
void csi_collector_start_hop_timer(void);
|
|
|
|
/**
|
|
* Inject an NDP (Null Data Packet) frame for sensing.
|
|
*
|
|
* Uses esp_wifi_80211_tx() to send a preamble-only frame (~24 us airtime)
|
|
* that triggers CSI measurement at all receivers. This is the "sensing-first"
|
|
* TX mechanism described in ADR-029.
|
|
*
|
|
* @return ESP_OK on success, or an error code.
|
|
*
|
|
* @note TODO: Full NDP frame construction. Currently sends a minimal
|
|
* null-data frame as a placeholder.
|
|
*/
|
|
esp_err_t csi_inject_ndp_frame(void);
|
|
|
|
/**
|
|
* Get the recent CSI callback rate (per second).
|
|
*
|
|
* Computed as a sliding 1-second window over the internal s_cb_count
|
|
* counter. Used by the ADR-081 radio abstraction layer to fill the
|
|
* pkt_yield_per_sec field of rv_radio_health_t.
|
|
*
|
|
* @return Callbacks observed in the trailing ~1 second.
|
|
*/
|
|
uint16_t csi_collector_get_pkt_yield_per_sec(void);
|
|
|
|
/**
|
|
* Get the cumulative UDP send-failure counter since boot.
|
|
*
|
|
* @return Number of stream_sender_send() failures recorded by the
|
|
* CSI callback path.
|
|
*/
|
|
uint16_t csi_collector_get_send_fail_count(void);
|
|
|
|
#endif /* CSI_COLLECTOR_H */
|