This commit is contained in:
mikecarper
2026-08-13 07:38:45 +00:00
parent ae629417ec
commit 27a2fb66a4
3 changed files with 13 additions and 5 deletions
+11 -3
View File
@@ -2309,7 +2309,9 @@ OTA_LEAVES: manifest_id[4] frag_idx(1) frag_total(1) bytes[] # up
removes the burst, so there is nothing to collide with. The block/manifest mask matches the 16-bit
reassembly bitmap (&lt;=16 fragments/block; 1 KB blocks = 7). <code>OTA_PROOF</code> is a single packet and needs no mask.</li>
<li><strong>Data and proof are separate phases.</strong> <code>OTA_DATA</code> carries no proof; the proof is fetched once per block
via <code>OTA_REQ_PROOF</code>/<code>OTA_PROOF</code> after the block's data is complete.</li>
via <code>OTA_REQ_PROOF</code>/<code>OTA_PROOF</code> after that block's data is complete. The receiver keeps a bounded two-block
window, so one block can await its proof or flash commit while DATA for the next block arrives. Slots retry
independently and only one stalled slot is retried per service tick.</li>
</ul>
<h3 id="85-sizing-against-max_packet_payload-184">8.5 Sizing against <code>MAX_PACKET_PAYLOAD = 184</code></h3>
<table>
@@ -2347,12 +2349,18 @@ OTA_LEAVES: manifest_id[4] frag_idx(1) frag_total(1) bytes[] # up
payload); larger self-images pass a bigger scratch buffer.</p>
<h3 id="86-temporary-radio-and-transfer-boundary">8.6 Temporary-radio and transfer boundary</h3>
<p>OTA packets may cross normal mesh relay hops, but each participating node processes or relays them only while
its <code>tempradio</code> window is actually running. A receiver requests missing blocks in serial order from the offered
firmware source. It never serves partial blocks. A normal install receiver never re-advertises its completed
its <code>tempradio</code> window is actually running. A receiver selects missing blocks in serial order into a bounded
two-block pipeline. It never serves partial blocks. A normal install receiver never re-advertises its completed
download. An SD archive node is the deliberate exception: after a fully proof-verified container is published
to its persistent archive, it registers that complete file as a MotaSource and advertises it as a new seeder.
This keeps each active transfer as one transmitter and one receiver while still allowing active temporary-radio
repeaters between them and persistent archive nodes to improve future availability.</p>
<p>Because TempRadio is a bounded channel dedicated to this transfer, an accepted OTA flood normally relays after
a randomized 0.25 to 0.5 packet-airtime delay. Repeated requests for the same manifest block or proof provide
congestion feedback without changing the wire format. Frequent retries widen the local relay window through
0.5-1.0, 0.75-2.0, and finally 1.0-3.0 airtimes. The maximum is hard-capped at three packet airtimes. Each
30-second interval without another observed retry lowers the window one level. Other flood payloads retain the
role's normal randomized delay, and CAD still applies when enabled.</p>
<hr />
<h2 id="9-identity-trust-versioning">9. Identity, trust &amp; versioning</h2>
<ul>
+1 -1
View File
@@ -1568,7 +1568,7 @@ no guessing. <strong><code>validate</code> is the switch:</strong> a plain <code
re-running a <code>validate</code> pull re-begins fresh (it never resumes a stale partial). Nothing about the seed is
trusted - every kept block is checked against the target's own fingerprints, so a mismatched or missing seed
just means those blocks are fetched over the radio (correct result, only slower).</p>
<p>The node fetches from one source, <strong>at low priority</strong>, one block at a time. Mesh repeaters may carry the
<p>The node fetches from one source, <strong>at low priority</strong>, with a bounded two-block receive window. Mesh repeaters may carry the
packets, but only while their temporary-radio windows are active. Check progress with <code>ota status</code>.</p>
<p>If a <code>folder</code> pull loses its link mid-transfer, <code>ota status</code> shows <strong>paused</strong> - the host keeps the
partial and the pull resumes (filling only what's missing) the moment you reconnect motatool; it never
File diff suppressed because one or more lines are too long