* NodeDB: 3-tier node store with persistent warm tier (long-tail identity retention)
Introduces a tiered NodeDB so the device retains identity (public key,
last_heard) for far more nodes than fit in the full-record hot store,
without growing heap or the persisted nodes.proto unboundedly.
- Hot store: full NodeInfoLite, MAX_NUM_NODES (120 on nRF52).
- Satellite maps: position/telemetry/environment/status capped at
MAX_SATELLITE_NODES (40 freshest); eviction via enforceSatelliteCaps /
evictSatelliteOverCap.
- Warm tier (WarmNodeStore): 40 B {num,last_heard,public_key} records for
evicted nodes so DMs to/from long-tail nodes keep encrypting/decrypting.
Persisted to /prefs/warm.dat, or on nRF52840 a dedicated 12 KB raw-flash
record-ring below LittleFS (3x4 KB pages; see linker scripts + the
nrf52_warm_region.py post-link guard).
NodeDB::getOrCreateMeshNode now demotes evicted nodes into the warm tier and
re-admits them (restoring key/last_heard). Router PKI decrypt/encode resolve
the peer key via NodeDB::copyPublicKey (hot store, then warm tier).
NodeInfoLite gains snr_q4 (sint32, Q4-encoded dB); the float snr is zeroed on
disk. NodeInfoLite grows 105 -> 112 B; backup 2432 -> 2468 B.
Note: the snr_q4 .proto change still needs to land in the protobufs submodule
(generated header is updated here; submodule pointer left at upstream).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* NodeDB: robust receive + retention for blocked (ignored) nodes
Hardens how ignored/favourite nodes are received over admin and retained,
closing paths where a block could be lost or accidentally cleared.
- Blocking keeps the node's public key (admin set_ignored_node and
addFromContact no longer zero it / drop the warm-tier key), so a blocked
peer stays a verifiable identity.
- set_ignored_node creates the node if absent, so a block by node ID sticks
even for a node we've never heard from (e.g. pushed by a remote admin) with
no NodeInfo or key.
- Eviction protection (favourite/ignored/manually-verified) now also applies to
the load-time hot-store migration and is never undone by cleanupMeshDB, which
previously purged ignored nodes that lacked user info.
- The hot-store migration leaves our own node (index 0) in place and prefers to
demote non-protected nodes, like the runtime eviction scan.
Caps the protected set (favourite + ignored + verified) at MAX_NUM_NODES-2 via
NodeDB::setProtectedFlag(), so at least two evictable slots always remain and
getOrCreateMeshNode can always make room — replacing the previous unconditional
append that could run off the end of the node vector when every node was
protected. A locally-set favourite/ignore that hits the cap reports back to the
phone via a ClientNotification.
Adds test_nodedb_blocked covering the migration, favourite/ignored eviction
protection, ignored-survives-cleanup, and the protected-node cap. The
maintenance methods stay private in production; the test reaches them through a
PIO_UNIT_TESTING-guarded friend shim.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
# Conflicts:
# src/mesh/NodeDB.h
* fix copilot comments
* once again
* WarmNodeStore: fix cppcheck warnings (uninitvar, constVariablePointer)
Zero-initialise `stranded[]` and `seqs[]/order[]` VLAs so cppcheck can
verify there are no unguarded reads of uninitialised memory (the guards
exist but are not visible to static analysis). Mark two local pointers
`const` where the pointed-to entry is never mutated after assignment.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* self-care added to assist 2.7 and 2.8 nodedb migration
* Tidy warm-store/self-care: comments, guards, log + flash cleanup
Style/cleanup pass over the branch (no behavior change except the noted
preprocessor simplifications, which are semantically identical):
- Comments: move function descriptions to the headers, cap in-function
comments at ~3-4 lines, drop leading-number step markers, label stacked
#endif blocks, de-decorate banner comments.
- dumpToLog: fully gate decl + definition + AdminModule call site behind
MESHTASTIC_NODEDB_MIGRATION_VERBOSE so it compiles out when disabled
(~1.2 KB when off).
- mesh-pb-constants: drop the dead nRF52832 WARM_NODE_COUNT branch and trim
the macro docs.
- WarmNodeStore: simplify the redundant `ARCH_NRF52 && NRF52840_XXAA` guards
to `NRF52840_XXAA`, add a kNoPage sentinel for the ring page state.
- Shorten the always-on LOG_WARN strings (~120 B flash).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* more tidying up, aligning with docs and undoing other-arch regressions
* Update protobufs (#19)
Co-authored-by: NomDeTom <116762865+NomDeTom@users.noreply.github.com>
* made the migration pathway cleareer
* address copilot review
* fixed a copilot review on a downstream PR.
* Address Copilot review comments for PR #10705 (warmstore/nodedb)
- WarmNodeStore.h: default MIGRATION_VERBOSE to 0 (suppress info-level
chatter on production builds; opt in with =1)
- WarmNodeStore.cpp load(): move memset to top of function so all
failure paths (header-read fail, invalid header) leave entries clear
- WarmNodeStore.cpp save(): replace manual spiLock lock/unlock around
mkdir with LockGuard covering the full SafeFile sequence, matching
the lock discipline in load()
- Router.cpp: memcpy(&p->public_key.bytes, ...) -> memcpy(p->public_key.bytes,
...) — pass decayed uint8_t* rather than pointer-to-array
- AdminModule.cpp: check setProtectedFlag return for PKC auto-favorite;
log cap-refusal warning instead of unconditional "auto-favoriting"
- nrf52_warm_region.py: error message references both v6.ld and v7.ld
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* NodeDB: formatting cleanup (blank lines after preprocessor blocks)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Lukewarm store
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Meadors <benmmeadors@gmail.com>
71 lines
2.9 KiB
Python
71 lines
2.9 KiB
Python
#!/usr/bin/env python3
|
|
# trunk-ignore-all(ruff/F821)
|
|
# trunk-ignore-all(flake8/F821): For SConstruct imports
|
|
#
|
|
# Post-link guard for the warm-node-store raw-flash region on nRF52840.
|
|
#
|
|
# The 3 app-region pages below LittleFS (0xEA000-0xED000, reclaimed by whole-image
|
|
# LTO) are reserved for the WarmNodeStore record-ring (see WarmNodeStore.h). Our
|
|
# linker scripts (nrf52840_s140_v6.ld and nrf52840_s140_v7.ld) cap the image at
|
|
# 0xEA000, but boards on the framework-default script (FLASH ending at 0xED000) could
|
|
# silently place code in those pages — the first warm-store save would then brick the
|
|
# device. This turns that into a build failure.
|
|
#
|
|
# Image flash end = __etext + sizeof(.data) (loaded at LMA __etext); symbols from
|
|
# the framework's nrf52_common.ld.
|
|
import os
|
|
|
|
Import("env")
|
|
|
|
WARM_REGION_BASE = 0xEA000 # keep in sync with WARM_FLASH_REGION_BASE in WarmNodeStore.h (3 x 4 KB record-ring)
|
|
|
|
_tc = env.PioPlatform().get_package_dir("toolchain-gccarmnoneeabi") or ""
|
|
_NM = os.path.join(_tc, "bin", "arm-none-eabi-nm")
|
|
if not os.path.isfile(_NM):
|
|
_NM = "arm-none-eabi-nm" # fall back to PATH
|
|
|
|
|
|
def _assert_warm_region_clear(source, target, env):
|
|
import subprocess
|
|
import sys
|
|
|
|
try:
|
|
elf = env.subst("$BUILD_DIR/${PROGNAME}.elf")
|
|
out = subprocess.check_output([_NM, elf], universal_newlines=True)
|
|
except Exception as exc: # tooling hiccup: warn loudly, don't wedge the build
|
|
print("nrf52_warm_region: WARNING - guard skipped (nm failed: %s)" % exc)
|
|
return
|
|
|
|
syms = {}
|
|
for line in out.split("\n"):
|
|
f = line.split()
|
|
if len(f) >= 3 and f[-1] in ("__etext", "__data_start__", "__data_end__"):
|
|
syms[f[-1]] = int(f[0], 16)
|
|
if len(syms) != 3:
|
|
print("nrf52_warm_region: WARNING - guard skipped (linker symbols not found)")
|
|
return
|
|
|
|
flash_end = syms["__etext"] + (syms["__data_end__"] - syms["__data_start__"])
|
|
if flash_end > WARM_REGION_BASE:
|
|
sys.stderr.write(
|
|
"\n*** nrf52 warm-region guard: image ends at 0x%X, past the reserved "
|
|
"warm-store region at 0x%X ***\n"
|
|
"The 12 KB region at 0xEA000 holds the WarmNodeStore record-ring; a warm-store\n"
|
|
"save would overwrite this firmware's tail. Shrink the image, or shrink/move\n"
|
|
"the region (WARM_FLASH_REGION_BASE in src/mesh/WarmNodeStore.h, the FLASH\n"
|
|
"LENGTH in src/platform/nrf52/nrf52840_s140_v6.ld and _v7.ld, and this guard).\n\n"
|
|
% (flash_end, WARM_REGION_BASE)
|
|
)
|
|
from SCons.Script import Exit
|
|
|
|
Exit(1)
|
|
print(
|
|
"nrf52_warm_region: guard OK -- image ends at 0x%X, %d KB clear of the warm region"
|
|
% (flash_end, (WARM_REGION_BASE - flash_end) // 1024)
|
|
)
|
|
|
|
|
|
# Attach to the phony "buildprog" alias (not the .elf node) so the guard runs
|
|
# on incremental relinks too -- same reasoning as nrf52_lto.py's guard.
|
|
env.AddPostAction("buildprog", _assert_warm_region_clear)
|